HackerOneµÄÔ±¹¤ÇÔÈ¡·ì϶»ã±¨²¢ÏúÊÛ¸øÊÜÓ°Ïì¿Í»§

°ä²¼¹¦·ò 2022-07-05

1¡¢HackerOneµÄÔ±¹¤ÇÔÈ¡·ì϶»ã±¨²¢ÏúÊÛ¸øÊÜÓ°Ïì¿Í»§


¾ÝýÌå7ÔÂ2ÈÕ±¨Â· £¬HackerOneµÄÒ»ÃûÔ±¹¤ÇÔÈ¡ÁËͨ¹ý·ì϶Éͽðƽ̨Ìá½»µÄ·ì϶»ã±¨ £¬²¢½«Æäй¶¸øÊÜÓ°ÏìµÄ¿Í»§ÒÔIJȡ¾­¼ÃÀûÒæ¡£¾­¹ýµ÷²é £¬¸ÃÔ±¹¤ÊÇΪ¶à¶à¿Í»§ÏîÄ¿·ÖÀà·ì϶Åû¶µÄ¹¤×÷ÈËÔ±Ö®Ò» £¬×Ô4ÔÂ4ÈÕÖÁ6ÔÂ23ÈÕÒÔÀ´½Ó¼ûÁË¸ÃÆ½Ì¨ £¬ÒѾ­ÁªÏµÁË7¸ö¿Í»§¡£ËûʹÓÃÁËÃû³Æ"rzlr" £¬ÒÔ¼°ÍþвºÍ¿ÖÏÅÐÔµÄ˵»°Óë¿Í»§½»»¥ £¬Òѳɹ¦ÊÕµ½Éͽð¡£6ÔÂ30ÈÕ £¬HackerOne¿ª³ýÁËÕâÃûÔ±¹¤¡£


https://www.bleepingcomputer.com/news/security/rogue-hackerone-employee-steals-bug-reports-to-sell-on-the-side/


2¡¢Google°ä²¼°²È«¸üР£¬½¨¸´ChromeÖÐÒѱ»ÀûÓõÄ0 day


7ÔÂ4ÈÕ £¬Google°ä²¼ÎªWindowsÓû§°ä²¼Chrome 103.0.5060.114 £¬½¨¸´ÁË2022ÄêChromeÖеĵÚ4¸ö0 day¡£¸Ã·ì϶ÊÇWebRTC£¨WebʵʱͨѶ£©×é¼þÖлùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2022-2294£© £¬ÓÉAvastµÄ×êÑÐÍŶÓÓÚ7ÔÂ1ÈÕÅû¶¡£Googleй©¸Ã·ì϶Òѱ»ÔÚÒ°ÀûÓà £¬µ«²¢Î´¹«¿ª¹ØÓÚ¹¥»÷µÄ¼¼Êõϸ½ÚµÈÐÅÏ¢¡£´Ë±í £¬Õâ´Î¸üл¹½¨¸´ÁËV8ÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2022-2295£©¡£


https://securityaffairs.co/wordpress/132863/hacking/4th-chrome-zero-day.html


3¡¢×êÑÐÈËÔ±Åû¶Zoho²úÆ·Öзì϶CVE-2022-28219µÄϸ½Ú


ýÌå7ÔÂ1ÈÕ±¨Â· £¬×êÑÐÈËÔ±Åû¶ÁËZoho ManageEngine ADAudit Plus¹¤¾ßÖзì϶£¨CVE-2022-28219£©µÄ¼¼Êõϸ½ÚºÍ¸ÅÏëÑéÖ¤·ì϶ÀûÓôúÂë¡£¸Ã·ì϶CVSSÆÀ·ÖΪ9.8 £¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃÀ´Ô¶³ÌÖ´ÐдúÂë²¢·ÛËéActive DirectoryÕÊ»§¡£¸Ã·ì϶Ô̺¬3¸öÎÊÌ⣺²»ÊÜÐÅÀµµÄJava·´ÐòÁл¯¡¢õè¾¶±éÀúºÍäXML±í²¿ÊµÌå(XXE)×¢Èë¡£ZohoÔÚ3Ôµ׵ÄADAudit Plus build 7060Öн¨¸´ÁËÕâÒ»·ì϶¡£


https://www.bleepingcomputer.com/news/security/zoho-manageengine-adaudit-plus-bug-gets-public-rce-exploit/


4¡¢ReversingLabs°ä²¼¹ØÓÚAstraLocker 2.0µÄ·ÖÎö»ã±¨


ýÌå7ÔÂ1ÈÕ³Æ £¬ReversingLabs°ä²¼Á˹ØÓÚÀÕË÷Èí¼þAstraLocker 2.0µÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±°µÊ¾ £¬ËüÖØÒª½øÐм±¾ç¹¥»÷ £¬¿ÉÖ±½Ó´Óµç×ÓÓʼþ¸½¼þÖÐͶ·Åpayload¡£¹¥»÷ÕßʹÓõĵö¶üÊÇWordÎĵµ £¬°µ²ØÁË´øÓÐÀÕË÷Èí¼þpayloadµÄOLE ¶ÔÏó £¬Ç¶ÈëµÄ¿ÉÖ´ÐÐÎļþʹÓÃÎļþÃû¡°WordDocumentDOC.exe¡± £¬²¢Ê¹Óá°smash-n-grab¡±Õ½Êõ¡£ÁíÒ»¸öÌØÊâÖ®´¦ÊÇʹÓÃÁËSafeEngine Shielder v2.4.0.0À´´ò°ü¿ÉÖ´ÐÐÎļþ £¬ÕâÊÇÒ»¸ö¹ýÆÚµÄ´ò°ü·¨Ê½ £¬ÏÕЩ²»³ÉÄܽøÐÐÄæÏò¹¤³Ì¡£


https://blog.malwarebytes.com/ransomware/2022/07/astralocker-2-0-ransomware-isnt-going-to-give-you-your-files-back/


5¡¢ÈÕ±¾Òƶ¯ÔËÓªÉÌKDDIÍ»·¢ÖÐ¶Ï £¬3915Íò¸öÓû§Í¨Ñ¶Åö±Ú


ýÌå7ÔÂ3ÈÕ³Æ £¬ÈÕ±¾Èý´óÒÆ¶¯ÔËÓªÉÌÖ®Ò»µÄKDDI Corp.Í»·¢ÖÐ¶Ï £¬¶à´ï3915Íò¸öÓû§µÄͨѶÅö±Ú¡£ÕⳡÖжÏʼÓÚÉÏÖÜÁùÁ賿1µã35·Ö×óÓÒ £¬Ó°ÏìÁËÔ̺¬ÒøÐÐÒµÎñ¡¢ÆøÏóÊý¾Ý¡¢»õÔ˺Ͱü¹üµÝËÍϵͳÒÔ¼°ÁªÍøÆû³µ·þÎñÔÚÄڵĶà¸öÁìÓò¡£KDDI°µÊ¾ £¬ÆäÓïÒôºô½ÐϵͳµÄ¹ÊÕÏÒý·¢ÁËÁ÷Á¿¼¯ÖÐ £¬µ¼ÖÂͨѶÊÜÏÞ £¬KDDIÉ糤ÒѳöÃæ¾Ï¹ªÖÂǸ¡£½ØÖÁÉÏÖÜÈÕÉÏÎç11µã×óÓÒ £¬KDDIÎ÷ÈÕ±¾·þÎñÇøµÄ½¨¸´¹¤×÷ÒѾ­ÊµÏÖ £¬ÈÕ±¾¶«²¿¸´Ô­·þÎñµÄ¹¤×÷ÓÚÖÜÈÕÍíÉÏʵÏÖ¡£


https://www.japantimes.co.jp/news/2022/07/03/business/tech/kddi-au-system-outage/


6¡¢GoogleÖ¸³ö2022ÉϰëÄê±»ÀûÓõķì϶ÖÐÒ»°ëÓë¾É·ì϶ÓйØ


¾Ý7ÔÂ3ÈÕ±¨Â· £¬Google Project Zero×êÑÐÈËÔ±°ä²¼Ò»·Ý»ã±¨ £¬³ÆÔÚ2022ÉϰëÄê £¬¹¥»÷ÖÐÀûÓõķì϶ÖÐÖÁÉÙÓÐÒ»°ëÓëδÕýÈ·½¨¸´µÄ¾É·ì϶ÓйØ¡£»ã±¨Ö¸³ö £¬½ØÖÁ2022Äê6ÔÂ15ÈÕ £¬ÒѼì²âµ½18¸ö0 day±»Åû¶²¢ÔÚÒ°ÀûÓᣵ±·ÖÎöÕâЩ·ì϶ʱ £¬·¢ÏÖÖÁÉÙ9¸öÊÇÏÈǰ½¨¸´µÄ·ì϶µÄ±äÖÖ¡£ÀýÈç £¬×î½ü·¢ÏÖµÄWindows·ì϶Follina£¨CVE-2022-30190£© £¬ÊÇMSHTMLÁãÈÕ·ì϶£¨CVE-2021-40444£©µÄ±äÖÖ¡£


https://securityaffairs.co/wordpress/132813/security/h1-2022-zero-day-variants-previous-flaws.html