Mozilla°ä²¼Firefox°²È«¸üн¨¸´ËÁÒâ´úÂëÖ´Ðзì϶£»ºÚ¿ÍÈëÇÖÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬×ÌÈž¯·½»î¶¯
°ä²¼¹¦·ò 2020-06-051.Mozilla°ä²¼Firefox°²È«¸üУ¬½¨¸´¶à¸öËÁÒâ´úÂëÖ´Ðзì϶
MozillaΪFirefox°ä²¼Á˰²È«¸üУ¬½¨¸´ÁË8¸ö°²È«·ì϶¡£ÆäÖÐ3¸ö±»È·ÒÔΪËÁÒâ´úÂëÖ´Ðзì϶£¬Ô̺¬´¦ÖÃNativeTypesʱµÄJavaScriptÀàÐÍ»ìºÏ·ì϶£¨CVE-2020-12406£©¼°ÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-12410ºÍCVE-2020-12411£©¡£ÓÐÒ»¸öºÃÐÂÎÅÊÇ£¬Õâ3¸ö´úÂëÖ´Ðзì϶¶¼ÊÇMozilla¿ª·¢ÈËÔ±ÔÚÄÚ²¿·¢Ïֵ쬲¢Î´ÔÚÒ°ÀûÓá£Õâ´Î½¨¸´µÄÆäËû½ÏΪÑϳÁµÄ·ì϶ÊÇCVE-2020-12399£¬¸Ã·ì϶ÔÚNSSÖ´ÐÐDSAÊðÃûʱÏÔʾʱÐò²î¾à¿Éµ¼ÖÂ˽Կй¶£¬ÒÔ¼°·ì϶CVE-2020-12405£¬´æÔÚSharedWorkService×é¼þÖеÄuse-after-free()ÖУ¬µ±Í¨¹ýwebÒ³ÃæÀûÓÃʱ¿ÉÄܵ¼Ö¿ÉÀûÓñÀÀ£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/06/04/firefox_77_security_fixes/
2.TalosÅû¶ZoomÖÐÁ½¸ö·ì϶£¬¿É±»ÀûÓÃÖ´ÐжñÒâ´úÂë
˼¿ÆTalosµÄ×êÑÐÈËÔ±Åû¶ÁËZoomÖеÄÁ½¸ö·ì϶£¬ÕâЩ·ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì¹¥»÷Õßͨ¹ý̸ÌìÖ°ÄÜÈëÇÖÊܺ¦ÕßµÄϵͳ¡£ÕâÁ½¸ö¾ùΪõè¾¶±éÀú·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶дÈë»òÖ²ÈëËÁÒâÎļþ£¬ÒÔÖ´ÐжñÒâ´úÂë¡£ÆäÖеÚÒ»¸ö·ì϶±»¸ú×ÙΪCVE-2020-6109£¬ÓëZoom´¦Öö¯»GIFµÄ·½Ê½Óйأ¬ZoomûÓвé³GIFÔ´£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»·¢ËÍÌØÔìµÄGIF½øÐй¥»÷¡£µÚ¶þ¸ö·ì϶ÊDZ»¸ú×ÙΪCVE-2020-6110£¬¸Ã·ì϶λÓÚZoom´¦ÖÃÔ̺¬¹²Ïí´úÂë¶ÎÔÚÄÚµÄÐÂÎŵķ½Ê½ÖС£ÕâÁ½¸ö·ì϶¶¼Ó°ÏìÁËZoom 4.6.10°æ±¾£¬²¢ÇҸù«Ë¾ÔÚÆä4.6.12°æ±¾Öн¨¸´ÁËËûÃÇ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/104249/hacking/zoom-security-flaws.html
3.±©ÂÒÆÚ¼äºÚ¿ÍÈëÇÖÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬×ÌÈž¯·½»î¶¯
ÃÀ¹úGeorge FloydÖ®ËÀÒý·¢µÄ±©ÂÒÆÚ¼ä£¬ºÚ¿ÍÈëÇÖÁËÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬²¢¶Ô¾¯·½»î¶¯½øÐÐ×ÌÈÅ¡£ÉÏÖÜÄ©£¬ºÚ¿Í»ñµÃÁËÆäÎÞÏßµçϵÓõĽӼûȨ£¬²¢²¥·Å±©ÂÒ±êÓïºÍ°µÊ¾ÃÀ¹úÖÖ×åÖ÷ÒåµÄ¸èÇú¡£Ö¥¼Ó¸ç¾¯¾ÖÓв¿ÃżÓÃܵÄÎÞÏßµçÆµÂÊ£¬µ«ÊÇ´óÎÞÊýѲÂß¾¯Ô±Ê¹ÓõÄÎÞÏߵ绹ÊÇÒ×±»¹¥»÷µÄ¡£Õâµ¼ÖÂÁ˾¯Ô±ÔÚÖ´Ðй¤×÷ʱÎÞ·¨Ê¹ÓöԽ²»úÓëµ÷¶ÈÔ±ÁªÏµ£¬»òÊÇ×·ÇóÔ®ÊÖ¡£¹«¹²°²È«ÐÅÏ¢¼¼ÊõµÄDan Casey°µÊ¾£¬ÕâÑù×ö¼«¶ÈΣÏÕ¡£Ä¿Ç°£¬´¦ËùºÍÁª¹úµ÷²é¾ÖÒѾ¶Ô´ËÊ·¢Õ¹µ÷²é¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/chicago-police-scanner-jammed-amid/
4.MazeÐû³ÆÒѳɹ¦¹¥»÷Conduent£¬ÇÔȡδ¼ÓÃܵÄÎļþ²¢¼ÓÃÜÆäÉ豸
MazeÀÕË÷Èí¼þÍÅ»ïÐû³ÆÒѾ³É¹¦¹¥»÷ÁËλÓÚÐÂÔóÎ÷ÖݵÄóÒ×·þÎñ¹«Ë¾Conduent£¬ÇÔÈ¡ÁËδ¼ÓÃܵÄÎļþ²¢¼ÓÃÜÁËÆäÉ豸¡£5ÔÂ29ÈÕ£¬Conduent°ä²¼ÉêÃ÷È·ÈÏÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬Õâ´Î¹¥»÷µ¼ÖÂÆäÅ·ÖÞÒµÎñµÄ·þÎñÖжÏ10Ó×ʱ¡£MazeÓÚ6ÔÂ4ÈÕÔÚÆäÊý¾ÝÐ¹Â©ÍøÕ¾°ä²¼Á˰䲼ÁË1GBÎļþÒÔÖ¤Ã÷ÆäÔÚ2020Äê5µÄ¹¥»÷£¬Ð¹Â¶ÎļþΪBusinessIntelligence.zipºÍCompliance1.zip£¬Ô̺¬¸÷Àà²ÆÕþµç×Ó±í¸ñ¡¢¿Í»§É󼯡¢·¢Æ±¡¢Ó¶½ð¶ÔÕʵ¥ºÍÆäËûÔÓÏîÎĵµ¡£Íþвµý±¨¹«Ë¾Bad Packets°µÊ¾£¬ÔÚ2019Äê12ÔÂ17ÈÕÖÁ2020Äê2ÔÂ14ÈÕÖ®¼äµÄÖÁÉÙ°ËÖÜÄÚ£¬ConduentµÄ·þÎñÆ÷Citrix´æÔÚ·ì϶£¨CVE-2019-19781£©£¬¸Ã·ì϶¿É±»ÀûÓÃÖ´ÐÐÔ¶³Ì´úÂë£¬Ôø±»ºÚ¿ÍÀûÓ÷ÛËéÍøÂç²¢²¿ÊðÀÕË÷Èí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/business-services-giant-conduent-hit-by-maze-ransomware/
5.2019ÄêºÚ¿Íй¶50ÒÚÌõÊý¾Ý£¬¸øÃÀ¹úÔì³É1.2ÍòÒÚÃÀÔªËðʧ
¾ÝForgeRockͳ¼ÆÊý¾Ý£¬ºÚ¿ÍÔÚ2019Äêй¶Á˳¬¹ý50Òڱʼͼ£¬¸øÃÀ¹ú×éÖ¯Ôì³ÉÁ˳¬¹ý1.2ÍòÒÚÃÀÔªµÄËðʧ¡£ÆäÖУ¬Ò½ÁƱ£½¡ÐÐÒµÊܵ½¹¥»÷´ÎÊý×î¶à£¬2019Äê×ܹ²»ã±¨ÁË382Æðй¶ÊÂÎñ£¬Ëðʧ³¬¹ý2.45ÒÚÃÀÔª¡£¶ø¼¼Êõ¹«Ë¾±»Ð¹Â¶Êý¾ÝµÄÊýÁ¿×î¶à£¬2019Äêй¶³¬¹ý13.7ÒÚÌõÊý¾Ý£¬×ܼÆËðʧ³¬¹ý2500ÒÚÃÀÔª¡£Ó×ÎÒ¼ø±ðÐÅÏ¢(PII)ÒÀÈ»Êǹ¥»÷Õß×îÖØÒªµÄÖ¸±êÊý¾Ý£¬ÔÚ2019Äê98£¥µÄÊý¾ÝÊÂÎñÖж³öÁ˸ÃÐÅÏ¢£¬ÆäÖÐÉç»á°²È«ºÅÂ루SSN£©ÊÇ×îÈÝÒ×Êܵ½¹¥»÷µÄÊý¾ÝÀàÐÍ¡£ForgeRockÊ×ϯ¼¼Êõ¹ÙEve Maler°µÊ¾£¬ÍøÂç×ï·¸ÔÚ²»ÐÝÃÀÂúÆä¹¥»÷ý½é£¬ÒÔÇÔÈ¡µÞ·ÑÕßÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/06/04/cybercriminals-exposed-5-billion-records-in-2019/
6.ºÚ¿ÍÔÚ°µÍøÏúÊÛ³¬¹ý10ÍòÓ¡¶È¹«ÃñÉí·ÝÖ¤£¬Ä¿Ç°ÆðԴδ֪
ÍøÂçµý±¨¹«Ë¾Cyble±¾ÖÜÈý°µÊ¾£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛ³¬¹ý10ÍòÓ¡¶È¹«ÃñµÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬É¨ÃèµÄÉí·ÝÖ¤¸´Ó¡¼þ¡¢Aadhaar¡¢PAN¿¨ºÍ»¤ÕÕ¡£ÕâЩй¶µÄÓ×ÎÒÊý¾ÝÄܹ»µ¼Ö¸÷Àà¶ñÒâ»î¶¯£¬ÀýÈçÉí·Ý͵ÇÔ¡¢Ú¿ÆºÍÆóÒµ¼äµý»î¶¯¡£Cyble³õ²½·ÖÎöÅú×¢£¬ÕâЩÊý¾ÝËÆºõÀ´×ÔµÚÈý·½¹«Ë¾¶ø²»Êǵ±¾Öϵͳ£¬Ä¿Ç°£¬×êÑÐÈËÔ±ÈÔÔڶԴ˽øÇ°½øÒ»´ëÊ©²é£¬ÒÔÈ·¶¨Êý¾ÝµÄ¾ßÌåÆðÔ´¡£
ÔÎÄÁ´½Ó£º
https://ciso.economictimes.indiatimes.com/news/over-1-lakh-national-ids-of-indians-put-on-dark-net-for-sale-cyber-intelligence-firm/76177587


¾©¹«Íø°²±¸11010802024551ºÅ