Lodash¿â±¬³öÑϳÁ°²È«·ì϶£¬²¨¼°400Íò+ÏîÄ¿£»³¬¹ý1300¸öAndroid APP¼´±ã»Ø¾øÊÚÈ¨Ò²ÍøÂçÓû§ÐÅÏ¢

°ä²¼¹¦·ò 2019-07-12
1¡¢Lodash¿â±¬³öÑϳÁ°²È«·ì϶£¬²¨¼°400Íò+ÏîÄ¿

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
×êÑÐÈËÔ±Liran TalÅû¶Lodash¿âÖеĸßΣԭÐÍ´«È¾·ì϶ ¡£LodashÊÇÒ»¸öÊ¢ÐеÄnpm¿â£¬½öÔÚGitHubÉϾÍÓг¬¹ý400Íò¸öÏîĿʹÓà ¡£¸Ã·ì϶£¨CVE-2019-10744£©Ó°ÏìÁË4.17.11°æ±¾Ö®Ç°µÄLodash¿â£¬´óÁ¿Ç°¶ËÏîÄ¿¿ÉÄÜÊÜÓ°Ïì ¡£Ô­ÐÍ´«È¾·ì϶ÔÊÐí¹¥»÷ÕßÅú¸ÄWebÀûÓõÄJavaScript¶ÔÏóÔ­ÐÍ£¬Æ¾¾ÝTalµÄ˵·¨£¬Lodash¿âÖеIJ½Öè¡°defaultsDeep¡±¿É±»ÓÃÓÚÔö³¤»òÅú¸ÄObject.prototypeµÄÊôÐÔ£¬Õâ¿ÉÄܵ¼ÖÂWebÀûÓñÀÀ£»òŤתÆäÐÐΪ ¡£Lodash½«±ÉÈËÒ»¸ö°æ±¾Öн¨¸´¸Ã·ì϶ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/lodash-prototype-pollution.html

2¡¢Appleһʱ½ûÓÃApple Watch¶Ô½²»úÖ°ÄÜ£¬´æÔÚÇÔÌý·çÏÕ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝTechCrunchµÄÒ»·Ý»ã±¨£¬ÓÉÓÚ´æÔÚ¿ÉÇÔÌýËûÈ˵ķì϶£¬AppleÒÑһʱ½ûÓÃÁËApple WatchµÄWalkie-TalkieÖ°ÄÜ ¡£Walkie-TalkieÊÇApple WatchµÄ¶Ô½²»úÖ°ÄÜ£¬ÔÊÐíÓû§ÎÞÐ貦´òµç»°ÊµÊ±Óë°é½øÐн»Ì¸ ¡£¸Ã·ì϶µÄ¾ßÌåϸ½ÚÉÐδÅû¶£¬Apple°µÊ¾ÔÚ¿ª·¢½¨¸´²¹¶¡£¬Apple WatchÉϵÄWalkie-TalkieÀûÓÃÒÀÈ»»á±£Áô£¬µ«ÁÙʱÎÞ·¨Ê¹Óà ¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/apple-disables-walkie-talkie-app-due-to-eavesdropping-flaw/146410/

3¡¢iMessage»Ø¾ø·þÎñ·ì϶£¬¿ÉʹiOS12.2¼°ÒÔϰ汾±äש

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Google Project ZeroÅû¶iMessageÖеĻؾø·þÎñ·ì϶£¨CVE-2019-8664£©£¬¸Ã·ì϶ӰÏìÁËÔËÐоɰ汾£¨iOS 12.2¼°Ö®Ç°£©µÄiPhoneÉ豸£¬¹¥»÷Õßͨ¹ýÏòÒ×Êܹ¥»÷µÄiOSÉ豸·¢ËͶñÒâÐÂÎÅ£¬¿Éµ¼ÖÂÖ¸±êÉ豸ÎÞ·¨²Ù×÷£¨±äש£© ¡£AppleÔÚ2019Äê5ÔÂ13ÈÕ°ä²¼µÄiOS 12.3Öн¨¸´Á˸÷ì϶ ¡£µ«Æ¾¾ÝiOS°æ±¾¸ú×Ù¹«Ë¾StatcounterµÄÊý¾Ý£¬½ØÖÁ6ÔÂÈ«ÇòÈÔÓÐ47£¥µÄiOSÉ豸ÔËÐÐÔÚ12.2¼°ÒÔϰ汾£¬ÕâÒâζ×ÅËüÃÇÒÀÈ»Ò×Êܹ¥»÷ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/apple-patches-imessage-bug/146277/

4¡¢MagecartÀûÓÃÅäÖÃÃýÎóµÄAWS S3ϰȾ³¬¹ý1.7Íò¸öÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝÍþвµý±¨³§ÉÌRiskIQ°ä²¼µÄÒ»·Ý»ã±¨£¬×Ô4Ô·ÝÒÔÀ´MagecartÀûÓÃÅäÖÃÃýÎóµÄAWS S3´æ´¢Í°ÒÑϰȾ³¬¹ý1.7Íò¸öÍøÕ¾£¬ÆäÖÐÔ̺¬AlexaÅÅÃûǰ2000µÄÍøÕ¾ ¡£¹¥»÷ÕßÖØÒªÉ¨Ãè¿É¹«¿ª½Ó¼ûµÄS3´æ´¢Í°£¬²¢ÔÚÍøÕ¾Ê¹ÓõÄJavaScriptÎļþÖÐ×¢Èë¶ñÒâ´úÂë ¡£¹¥»÷Õß²¢²»×ÜÊÇ֪·ÕâЩJSÎļþ±»ÄÄЩÏîÄ¿»òÍøÕ¾Ê¹Ó㬺ܶàÊÜϰȾµÄJSÎļþ²¢²»»áÔÚÖ§¸¶Ò³ÃæÉϼÓÔØ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-magecart-attacks-leverage-misconfigured-s3-buckets-to-infect-over-17k-sites/

5¡¢³¬¹ý1300¸öAndroid APP¼´±ã»Ø¾øÊÚÈ¨Ò²ÍøÂçÓû§ÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

×î½üµÄÒ»Ïî×êÑз¢ÏÖ£¬¼´±ãÓû§»Ø¾øÁËÊÚȨÉêÇ룬³¬¹ý1300¿îAndroid APPÈÔ¾ÉÄܹ»ÍøÂçÓû§µÄÐÅÏ¢ ¡£ÕâÏî×êÑе÷²éÁËÀ´×ÔGoogle PlayÉ̵êµÄ³¬¹ý8.8Íò¸öAPP£¬ÆäÖÐ1325¸öAPP±»·¢ÏÖÈÆ¹ýÁËAndroid²Ù×÷ϵͳÖеÄȨÏÞ½Ó¼û£¬Ê¹Óñäͨ²½Öè»ñÈ¡Óû§µÄÓ×ÎÒÊý¾Ý£¬ÀýÈç´ÓÕÕÆ¬¡¢Wi-FiÏνӵÈÊý¾ÝÔ´ÖлñÈ¡Óû§µÄλÏàÐÅÏ¢ ¡£2018Äê9Ô£¬×êÑÐÈËÔ±¾ÍÏò¹È¸è·´À¡ÁËÕâ¸öÎÊÌ⣬¹È¸è°µÊ¾½«ÔÚAndroid QÖнâ¾öÕâЩÎÊÌâ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/android-permission-bypass.html

6¡¢Pale Moon·þÎñÆ÷ÔâºÚ¿ÍÈëÇÖ£¬×°Öðü±»Ö²Èë¶ñÒâ´úÂë

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Pale Moon ä¯ÀÀÆ÷¿ª·¢ÍŶӰ䷢ÍйܾɰæÈí¼þµÄ´æµµ·þÎñÆ÷Ôâµ½ºÚ¿ÍÈëÇÖ£¬µ¼Ö¾ɰæÈí¼þµÄ×°Öðü±»Ö²Èë¶ñÒâ´úÂë ¡£¸ÃÊÂÎñ¿É×·Òäµ½2017Äê12ÔÂ27ÈÕ£¬µ«¸ÃÍŶÓÔÚ7ÔÂ9Èղŷ¢ÏÖÁËÕâ¸öÎÊÌâ ¡£ÎªÔ¤·À¶ñÒâÈí¼þ½øÒ»²½´«²¼£¬¸ÃÍŶӵ±¼´¶Â½ØÁ˸÷þÎñÆ÷£¨archive.palemoon.org£©µÄËùÓÐÏνÓ ¡£¾ÝϤ´æµµ·þÎñÆ÷ÖÐÍйܵÄËùÓа汾µÄPale Moon£¨×î¸ß°æ±¾Îª 27.6.2£©¾ù±»Ï°È¾£¬µ«¸ÃÍŶÓÇ¿µ÷³ÆÓÃÓÚ·Ö·¢×îа汾Èí¼þµÄ·þÎñÆ÷δÊÜÕâ´Î¹¥»÷ÊÂÎñµÄÓ°Ïì ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-infect-pale-moon-archive-server-with-a-malware-dropper/