Lodash¿â±¬³öÑϳÁ°²È«·ì϶£¬²¨¼°400Íò+ÏîÄ¿£»³¬¹ý1300¸öAndroid APP¼´±ã»Ø¾øÊÚÈ¨Ò²ÍøÂçÓû§ÐÅÏ¢
°ä²¼¹¦·ò 2019-07-12
×êÑÐÈËÔ±Liran TalÅû¶Lodash¿âÖеĸßΣÔÐÍ´«È¾·ì϶¡£LodashÊÇÒ»¸öÊ¢ÐеÄnpm¿â£¬½öÔÚGitHubÉϾÍÓг¬¹ý400Íò¸öÏîĿʹÓ᣸÷ì϶£¨CVE-2019-10744£©Ó°ÏìÁË4.17.11°æ±¾Ö®Ç°µÄLodash¿â£¬´óÁ¿Ç°¶ËÏîÄ¿¿ÉÄÜÊÜÓ°Ïì¡£ÔÐÍ´«È¾·ì϶ÔÊÐí¹¥»÷ÕßÅú¸ÄWebÀûÓõÄJavaScript¶ÔÏóÔÐÍ£¬Æ¾¾ÝTalµÄ˵·¨£¬Lodash¿âÖеIJ½Öè¡°defaultsDeep¡±¿É±»ÓÃÓÚÔö³¤»òÅú¸ÄObject.prototypeµÄÊôÐÔ£¬Õâ¿ÉÄܵ¼ÖÂWebÀûÓñÀÀ£»òŤתÆäÐÐΪ¡£Lodash½«±ÉÈËÒ»¸ö°æ±¾Öн¨¸´¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/lodash-prototype-pollution.html
2¡¢Appleһʱ½ûÓÃApple Watch¶Ô½²»úÖ°ÄÜ£¬´æÔÚÇÔÌý·çÏÕ
ƾ¾ÝTechCrunchµÄÒ»·Ý»ã±¨£¬ÓÉÓÚ´æÔÚ¿ÉÇÔÌýËûÈ˵ķì϶£¬AppleÒÑһʱ½ûÓÃÁËApple WatchµÄWalkie-TalkieÖ°ÄÜ¡£Walkie-TalkieÊÇApple WatchµÄ¶Ô½²»úÖ°ÄÜ£¬ÔÊÐíÓû§ÎÞÐ貦´òµç»°ÊµÊ±Óë°é½øÐн»Ì¸¡£¸Ã·ì϶µÄ¾ßÌåϸ½ÚÉÐδÅû¶£¬Apple°µÊ¾ÔÚ¿ª·¢½¨¸´²¹¶¡£¬Apple WatchÉϵÄWalkie-TalkieÀûÓÃÒÀÈ»»á±£Áô£¬µ«ÁÙʱÎÞ·¨Ê¹Óá£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/apple-disables-walkie-talkie-app-due-to-eavesdropping-flaw/146410/
3¡¢iMessage»Ø¾ø·þÎñ·ì϶£¬¿ÉʹiOS12.2¼°ÒÔϰ汾±äש
Google Project ZeroÅû¶iMessageÖеĻؾø·þÎñ·ì϶£¨CVE-2019-8664£©£¬¸Ã·ì϶ӰÏìÁËÔËÐоɰ汾£¨iOS 12.2¼°Ö®Ç°£©µÄiPhoneÉ豸£¬¹¥»÷Õßͨ¹ýÏòÒ×Êܹ¥»÷µÄiOSÉ豸·¢ËͶñÒâÐÂÎÅ£¬¿Éµ¼ÖÂÖ¸±êÉ豸ÎÞ·¨²Ù×÷£¨±äש£©¡£AppleÔÚ2019Äê5ÔÂ13ÈÕ°ä²¼µÄiOS 12.3Öн¨¸´Á˸÷ì϶¡£µ«Æ¾¾ÝiOS°æ±¾¸ú×Ù¹«Ë¾StatcounterµÄÊý¾Ý£¬½ØÖÁ6ÔÂÈ«ÇòÈÔÓÐ47£¥µÄiOSÉ豸ÔËÐÐÔÚ12.2¼°ÒÔϰ汾£¬ÕâÒâζ×ÅËüÃÇÒÀÈ»Ò×Êܹ¥»÷¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/apple-patches-imessage-bug/146277/
4¡¢MagecartÀûÓÃÅäÖÃÃýÎóµÄAWS S3ϰȾ³¬¹ý1.7Íò¸öÍøÕ¾
ƾ¾ÝÍþвµý±¨³§ÉÌRiskIQ°ä²¼µÄÒ»·Ý»ã±¨£¬×Ô4Ô·ÝÒÔÀ´MagecartÀûÓÃÅäÖÃÃýÎóµÄAWS S3´æ´¢Í°ÒÑϰȾ³¬¹ý1.7Íò¸öÍøÕ¾£¬ÆäÖÐÔ̺¬AlexaÅÅÃûǰ2000µÄÍøÕ¾¡£¹¥»÷ÕßÖØÒªÉ¨Ãè¿É¹«¿ª½Ó¼ûµÄS3´æ´¢Í°£¬²¢ÔÚÍøÕ¾Ê¹ÓõÄJavaScriptÎļþÖÐ×¢Èë¶ñÒâ´úÂë¡£¹¥»÷Õß²¢²»×ÜÊÇ֪·ÕâЩJSÎļþ±»ÄÄЩÏîÄ¿»òÍøÕ¾Ê¹Ó㬺ܶàÊÜϰȾµÄJSÎļþ²¢²»»áÔÚÖ§¸¶Ò³ÃæÉϼÓÔØ¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-magecart-attacks-leverage-misconfigured-s3-buckets-to-infect-over-17k-sites/
5¡¢³¬¹ý1300¸öAndroid APP¼´±ã»Ø¾øÊÚÈ¨Ò²ÍøÂçÓû§ÐÅÏ¢
×î½üµÄÒ»Ïî×êÑз¢ÏÖ£¬¼´±ãÓû§»Ø¾øÁËÊÚȨÉêÇ룬³¬¹ý1300¿îAndroid APPÈÔ¾ÉÄܹ»ÍøÂçÓû§µÄÐÅÏ¢¡£ÕâÏî×êÑе÷²éÁËÀ´×ÔGoogle PlayÉ̵êµÄ³¬¹ý8.8Íò¸öAPP£¬ÆäÖÐ1325¸öAPP±»·¢ÏÖÈÆ¹ýÁËAndroid²Ù×÷ϵͳÖеÄȨÏÞ½Ó¼û£¬Ê¹Óñäͨ²½Öè»ñÈ¡Óû§µÄÓ×ÎÒÊý¾Ý£¬ÀýÈç´ÓÕÕÆ¬¡¢Wi-FiÏνӵÈÊý¾ÝÔ´ÖлñÈ¡Óû§µÄλÏàÐÅÏ¢¡£2018Äê9Ô£¬×êÑÐÈËÔ±¾ÍÏò¹È¸è·´À¡ÁËÕâ¸öÎÊÌ⣬¹È¸è°µÊ¾½«ÔÚAndroid QÖнâ¾öÕâЩÎÊÌâ¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/android-permission-bypass.html
6¡¢Pale Moon·þÎñÆ÷ÔâºÚ¿ÍÈëÇÖ£¬×°Öðü±»Ö²Èë¶ñÒâ´úÂë
Pale Moon ä¯ÀÀÆ÷¿ª·¢ÍŶӰ䷢ÍйܾɰæÈí¼þµÄ´æµµ·þÎñÆ÷Ôâµ½ºÚ¿ÍÈëÇÖ£¬µ¼Ö¾ɰæÈí¼þµÄ×°Öðü±»Ö²Èë¶ñÒâ´úÂë¡£¸ÃÊÂÎñ¿É×·Òäµ½2017Äê12ÔÂ27ÈÕ£¬µ«¸ÃÍŶÓÔÚ7ÔÂ9Èղŷ¢ÏÖÁËÕâ¸öÎÊÌ⡣ΪԤ·À¶ñÒâÈí¼þ½øÒ»²½´«²¼£¬¸ÃÍŶӵ±¼´¶Â½ØÁ˸÷þÎñÆ÷£¨archive.palemoon.org£©µÄËùÓÐÏνӡ£¾ÝϤ´æµµ·þÎñÆ÷ÖÐÍйܵÄËùÓа汾µÄPale Moon£¨×î¸ß°æ±¾Îª 27.6.2£©¾ù±»Ï°È¾£¬µ«¸ÃÍŶÓÇ¿µ÷³ÆÓÃÓÚ·Ö·¢×îа汾Èí¼þµÄ·þÎñÆ÷δÊÜÕâ´Î¹¥»÷ÊÂÎñµÄÓ°Ïì¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-infect-pale-moon-archive-server-with-a-malware-dropper/


¾©¹«Íø°²±¸11010802024551ºÅ