React APPй¶23.8ÍòÓû§Î»ÏàÐÅÏ¢£»Ðá̽Windows BitLockerÃÜÔ¿£»AZORultľÂí

°ä²¼¹¦·ò 2019-03-25
1¡¢°Ä´óÀûÑÇReact APPÒâ±íй¶23.8ÍòÓû§µÄλÏàÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Sanyam Jain·¢ÏÖ°Ä´óÀûÑǵÄÒ»¸öÊ¢ÐеļÒÍ¥¸ú×ÙÀûÓÃReact AppÒâ±íй¶³¬¹ý23.8ÍòÓû§µÄʵʱλÏàÐÅÏ¢ ¡£¸ÃÀûÓõĺó¶ÜMongoDBÊý¾Ý¿âδÉèÃÜÂë £¬µ¼ÖÂÈκÎÈ˶¼Äܹ»½øÐнӼû ¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Ó×ÎÒ×ÊÁÏÕÕÆ¬¡¢Ã÷ÎÄÃÜÂëÒÔ¼°¼ÒÍ¥³ÉÔ±µÄʵʱλÏàÐÅÏ¢ £¬ÕâЩÊý¾Ý¾ùδ¼ÓÃÜ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/a-family-tracking-app-was-leaking-real-time-location-data/

2¡¢Ó¢¹ú¾¯Ô±½áºÏ»áPFEW¹ÙÍøÔâÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú¾¯Ô±½áºÏ»á£¨PFEW£©¹ÙÍøÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬ÕâÒ»ÊÂÎñ²úÉúÔÚ3ÔÂ9ÈÕ £¬µ«Ö±µ½3ÔÂ21Èղű»°ä²¼ ¡£Æ¾¾Ý¹Ù·½°ä²¼µÄÉêÃ÷ £¬Æäµç×ÓÓʼþ·þÎñ¼°Îļþϵͳ¾ùÎÞ·¨½Ó¼û £¬±¸·ÝÊý¾ÝÒ²±»É¾³ý £¬Ëùº±¼û¾Ý¾ù±»¼ÓÃܲ¢ÇÒÎÞ·¨½Ó¼û ¡£¸ÃÊÂÎñÒѱ»»ã±¨¸øÊý¾Ý±£»¤¼à¹Ü»ú¹¹£¨ICO£©ºÍ¹ú¶È½ø¹¥·¸×ï¾Ö£¨NCA£© £¬NCAÒÑÕë¶Ô´ËÊ·¢Õ¹ÐÌʵ÷²é ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/uk-police-federation-hit-ransomware

3¡¢AZORultľÂíбäÖÖ £¬ÖØÒªÕë¶Ô¶íÂÞ˹ºÍÓ¡¶È

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¿¨°Í˹»ù³¢ÊÔÊÒ·¢ÏÖÊý¾ÝÇÔȡľÂíAZORultµÄÒ»¸öбäÖÖ £¬ÓÉÓڸñäÖÖÊÇÓÃC++¶ø²»ÊÇDelphi±àдµÄ £¬Òò¶ø¸Ã±äÖÖ±»³ÆÎªAZORult++ ¡£×êÑÐÈËÔ±³ÆAZORult++±È֮ǰµÄ°æ±¾Ô½·¢Î£ÏÕ £¬³ýÁËÄܹ»ÍøÂçÓû§Êý¾Ý£¨Ô̺¬Í´´¦¡¢ä¯ÀÀÆ÷º¹Çà¼Í¼ ºÍCookie£©²¢·¢ËÍÖÁC&CÖ®±í £¬¸Ã±äÖÖ»¹Äܹ»´´½¨ÐÂÖÎÀíÔ¹ØË»§²¢³ÉÁ¢Ô¶³Ì×ÀÃæÏνÓ ¡£AZORult++ÖØÒªÓÃÓÚÕë¶Ô¶íÂÞ˹ºÍÓ¡¶ÈµÄÊܺ¦Õß ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/new-variant-of-azorult-trojan-1/

4¡¢Facebook¿ªÔ´ÏîÄ¿Fizz´æÔÚ·ì϶ £¬¿Éµ¼ÖÂDoS


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Semmle°²È«×êÑÐÔ±Kevin Backhouse·¢ÏÖFacebookµÄ¿ªÔ´ÏîÄ¿Fizz´æÔÚÒ»¸öÑϳÁµÄDoS·ì϶ ¡£FizzÊÇTLS 1.3ºÍ̸µÄ¿ªÔ´ÊµÏÖ £¬ÖØÒªÓÃÓÚFacebookµÄ»ù´¡Éèʩ֮ÖÐ ¡£¸Ã·ì϶£¨CVE-2019-3560£©Ô´ÓÚ16λÎÞ·ûºÅÊý¼Ó·¨ÖеÄÕûÊýÒç³ö £¬¿Éµ¼ÖÂËÀÑ­»· £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍtcp°ü´¥·¢¸Ã·ì϶ ¡£FacebookÒÑÔÚFizzа汾2019.02.25.00Öн¨¸´Á˸÷ì϶ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/dos-bug-facebook-fizz-tls/143086/

5¡¢×êÑÐÈËÔ±·¢ÏÖÐá̽Windows BitLockerÃÜÔ¿µÄв½Öè


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Pulse Security×êÑÐÈËÔ±Denis Andzakovic·¢ÏÖÐá̽Windows BitLocker¼ÓÃÜÃÜÔ¿µÄв½Öè ¡£Õý³£Çé¿öÏÂÆô¶¯Bitlocker½øÐмÓÃÜʱֻ±ØÒªÊäÈëÃÜÂë £¬×êÑÐÈËԱʹÓÃ30ÃÀÔªµÄÏÖ³¡¿É±à³ÌÃÅÕóÁУ¨FPGA£©Ïνӵ½Ó²ÅÌ £¬¶øºóͨ¹ýÐá̽¹¤¾ß´ÓLPC×ÜÏßÖлñµÃÃÜÔ¿ ¡£Í¨¹ýÕâÖÖ¹¥»÷ÊÖ·¨ £¬×êÑÐÈËÔ±³É¹¦´ÓSurface Pro 3µÄTPM 2.0Ä£¿éÖÐÐá̽µ½BitlockerµÄÃÜÔ¿ ¡£


Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2019/03/21/researcher-finds-new-way-to-sniff-windows-bitlocker-encryption-keys/

6¡¢×êÑÐÈËÔ±ÔÚOracle Java CardÖз¢ÏÖ18¸ö°²È«·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Adam GowdiakÔÚOracleµÄJava Card¼¼ÊõÖз¢ÏÖ18¸ö°²È«·ì϶ £¬ÕâЩ·ì϶¿ÉÍ»ÆÆµ×²ãJava Card VMµÄÄڴ氲ȫÐÔ £¬ÊµÏÖ¶ÔÖÇÄÜ¿¨ÄÚ´æµÄÆëÈ«½Ó¼û¡¢Í»ÆÆapplet·À»ðǽ¼°±¾µØ´úÂëÖ´ÐÐ ¡£Gowdiak³ÆÕâЩ·ì϶ÊÇÓÉÓÚJava CardµÄʵÏÖѡȡÁË´ÓǰµÄһЩ¼Ü¹¹µ¼ÖµÄ ¡£ÓÉÓÚJava Card¼¼ÊõÖØÒªÓÃÓÚ½ðÈÚ¡¢µ±¾Ö¡¢ÔËÊäºÍµçÐŵÈÁìÓò £¬Ê¹µÃÕâЩ·ì϶¸üΪΣÏÕ ¡£×êÑÐÈËÔ±³ÆOracleºÍ½ðÑÅÍØÔÚ¶ÔÕâЩÎÊÌâ½øÐе÷²é ¡£


Ô­ÎÄÁ´½Ó£º

https://www.scmagazineuk.com/multiple-vulnerabilities-found-java-card/article/1579791

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù