Capital Oneй¶1.06ÒÚÓû§ÐÅÏ¢£»Android RCE·ì϶£¬¿Éͨ¹ý²¥·Å¶ñÒâÊÓÆµÈëÇÖÓû§É豸

°ä²¼¹¦·ò 2019-07-30
1¡¢Capital Oneй¶1.06ÒÚÓû§ÐÅÏ¢£¬ÏÓÒÉÈËÒѱ»²¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Capital OneÈ·ÈÏÆäϵͳÓÚ3ÔÂ22ÈÕÖÁ23ÈÕÆÚ¼äÔâδÊÚȨ½Ó¼û£¬µ¼ÖÂ1.06ÒÚÓû§µÄÐÅϢй¶£¬Ô̺¬ÂòÂôÊý¾Ý¡¢ÐÅÓþÆÀ·Ö¡¢Ö§¸¶º¹Çà¡¢Óà¶îÒÔ¼°¹ØÁªµÄÒøÐÐÕË»§ºÍÉç»á°²È«ºÅÂë¡£ÊÜÓ°ÏìµÄÓû§Ô̺¬1ÒÚÃÀ¹úÈ˺Í600Íò¼ÓÄôóÈË¡£Æ¾¾ÝÓйØÖ¤¾Ý£¬FBIÒѾ­¿ÛÁôÁËÏÓÒÉÈËPaige Thompson¡£Capital One°µÊ¾ÓÉÓÚ¿Í»§Í¨Öª¡¢Ãâ·ÑµÄÐÅÓþ¼à¿Ø·þÎñ¡¢°²È«¸Ä½ø³É±¾ÒÔ¼°Ë¾·¨ÓöÈ£¬ÕâÒ»ÊÂÎñ½«µ¼ÖÂÔ¼1ÒÚÖÁ1.5ÒÚÃÀÔªµÄ³É±¾¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/capital-one-data-breach-affects-106-million-people-suspect-arrested/


2¡¢Ë¿Ü½À¼¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬¿Í»§ÒþÖÔÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˿ܽÀ¼¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬µ¼Ö¿ͻ§ÒþÖÔÐÅϢй¶¡£Ë¿Ü½À¼ÊÇÃÀÈݲúÆ·¡¢»¯×±Æ·ºÍ»¤·ôÆ·µÄÔÚÏß¹ºÎïÍøÕ¾£¬Æä¿Í»§ÐÅÏ¢ÔâµÚÈý·½Î´ÊÚȨ½Ó¼û¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÐԱ𡢵ç×ÓÓʼþµØÖ·¡¢ÃÀÈÝÆ«ºÃºÍ¼ÓÃÜÃÜÂ룬µ«²»Éæ¼°ÐÅÓþ¿¨ÐÅÏ¢¡£ÊÜÓ°ÏìµÄµØÓòÔ̺¬ÐÂ¼ÓÆÂ¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹ú¡¢·ÆÂɱö¡¢ÖйúÏã¸Û¡¢°Ä´óÀûÑÇÒÔ¼°ÐÂÎ÷À¼¡£¸Ã¹«Ë¾ÒªÇó¿Í»§¸ü¸ÄÏÖÓÐÃÜÂ룬²¢ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÃâ·ÑµÄÒþÖÔ¼à¿Ø·þÎñ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.stuff.co.nz/business/114597785/kiwi-customers-names-emails-passwords-stolen-in-sephora-data-breach


3¡¢²¨¶àÀè¸÷Á½¼ÒÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£¬²¨¼°52Íò»¼ÕßÐÅÏ¢   


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²¨¶àÀè¸÷Bayam¨®nÒ½ÁÆÖÐÐļ°Æä´ÓÊô¸¾Å®¶ùͯҽԺ³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õߣ¬¸Ã¹¥»÷ÊÂÎñÓ°ÏìÁ˳¬¹ý52ÍòÃû»¼ÕßµÄÊý¾Ý£¬ÆäÖÐÔ̺¬42ÍòBayam¨®nÒ½ÁÆÖÐÐÄ»¼Õߺͽü10Íò¸¾Å®ºÍ¶ùͯҽԺ»¼Õß¡£ÔÚÊÂÎñ²úÉúºó£¬Ò½Ôº½øÐÐÁËÄÚ²¿µ÷²éÒÔÈ·ÈϹ¥»÷µÄÆðÔ´ºÍÊÜËðˮƽ£¬²¢ÀñƸÁ˵ÚÈý·½À´Ô®ÊÖ¸´Ô­¼ÓÃܵÄÎļþ¡£Ò½Ôº°µÊ¾Ä¿Ç°Ã»ÓÐÈκμ£ÏóÅú×¢ÕâЩÐÅÏ¢Òѱ»ÈκÎδ¾­ÊÚȨµÄÓ×ÎÒËùʹÓá£


Ô­ÎÄÁ´½Ó£ºhttp://www.bayamon-medical.com/prwch/docs/comunicado_de_prensa.jpg


4¡¢ÐÝ˹¶ØÑ§ÌÃÔâÀÕË÷Èí¼þ¹¥»÷£¬±»ÆÈÍÆ³Ù¿ªÑ§ÈÕÆÚ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÝ˹¶ØÑ§ÌÃÔâÀÕË÷Èí¼þ¹¥»÷£¬¸ÃѧÌñ»ÆÈ½«¿ªÑ§ÈÕÆÚÏòºóÍÆ³ÙÁË4Ìì¡£¸ÃѧÌÃÔ­¶¨ÓÚ8ÔÂ1ÈÕ¿ªÑ§£¬µ«ÓÉÓÚ¹¥»÷ÕßϰȾÁËѧÌõÄϵͳ·þÎñÆ÷£¬µ¼ÖÂÕû¸öѧÌõÄϵͳְÄÜÊܵ½Ó°Ï죬Òò¶øÑ§Éú½«±»ÍƳٵ½8ÔÂ5ÈÕ¿ªÑ§¡£¸ÃѧÌÃÒªÇóÀÏʦºÍÈËÔ±²»ÒªÊ¹ÓÃѧÌõĵçÄÔ£¬Ö±ÖÁÊÕµ½ÁíÐÐ֪ͨ¡£Ñ§ÌÃÕÆ¹ÜÈËDavid Sewell°µÊ¾»¹ÎÞ·¨È·ÈϹ¥»÷µÄÊÜËðˮƽ¡£¸ÃѧÌöÔÔÚÓëÁª¹ú»ú¹¹¡¢FBIµÈЭͬ½â¾ö¸ÃÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.dothaneagle.com/news/education/officials-can-t-confirm-county-school-system-hack-isn-t/article_f628759e-afd7-11e9-a8aa-eba139975480.html


5¡¢Facebook Widget XSS·ì϶£¬ÏÂÔØÁ¿½ü100Íò


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


WordPress²å¼þFacebook Widget±»ÆØ´æÔÚÒ»¸öXSS·ì϶£¬¸Ã²å¼þµÄÏÂÔØÁ¿´ï½«½ü100Íò¡£Æ¾¾ÝPlugin VulnerabilitiesµÄ»ã±¨£¬¸Ã·ì϶Óë²»×ã¶Ô¶Ì´úÂëÊôÐÔ°²È«ÐÔµÄÕýÈ·´¦ÖÃÓйØ£¬¾ßÌåÀ´Ëµ£¬¶Ì´úÂë¡°fb_widget¡±Ê¹µÃº¯Êýfb_plugin_shortcode()ÔËÐУ¬µ«¸Ãº¯ÊýµÄµÚÒ»ÐдúÂ뽫¶Ì´úÂëÖеÄÊôÐÔÉèÖÃΪ±äÁ¿$defaults¶øÎ´¶ÔÊäÈë½øÐÐËãÕÊ£¬¸Ã´úÂ뻹½«Î´¾­×ªÒåµÄÊä³ö×÷ΪHTML±êÇ©µÄÊôÐÔ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ֲÈë¶ñÒâJavaScript´úÂ룬µ¼Ö¾­¹ýÉí·ÝÑéÖ¤µÄÓÆ¾ÃÐÔXSS¹¥»÷¡£×êÑÐÈËÔ±°ä²¼ÁËÓÃÓÚÑÝʾ¹¥»÷µÄPoC¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/authenticated-xss-found-wordpress-plugin-facebook-widget


6¡¢Android RCE·ì϶£¬¿Éͨ¹ý²¥·Å¶ñÒâÊÓÆµÈëÇÖÓû§É豸


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Android OS°æ±¾7.0ºÍ9.0Ö®¼ä´æÔÚÑϳÁµÄRCE·ì϶£¨CVE-2019-2107£©£¬Òò¶øÓû§µÄAndroidÉ豸¿ÉÄÜÒò²¥·ÅÊÓÆµ¶ø±»ºÚ¿ÍÈëÇÖ¡£¸Ã·ì϶´æÔÚÓÚýÌå¿ò¼Ü×é¼þÖУ¬¹¥»÷Õß¿ÉÀûÓöñÒâÎļþÔÚÌØÈ¨¹ý³ÌµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¹È¸èÔÚ7ÔµÄAndroid°²È«¸üÐÂÖн¨¸´Á˸÷ì϶£¬µ«ÈÔÓдóÁ¿É豸ÔÚÆÚ´ý³§ÉÌÍÆË͸ò¹¶¡¡£×êÑÐÈËÔ±Marcin Kozlowski°ä²¼ÁËÒ»¸ö·ì϶ÑéÖ¤µÄPoC£¬Ê¹ÓÃAndroidµÄÔ­ÉúÊÓÆµ²¥·ÅÆ÷²¥·Å¸ÃHEVC±àÂëµÄÊÓÆµ¿Éµ¼Ö²¥·ÅÆ÷±ÀÀ£¡£µ«ÈôÊÇʹÓÃWhatsApp»òFacebookµÈ¼´Ê±Í¨Ñ¶APP½Ó¹Ü´Ë¶ñÒâÊÓÆµ£¬Ôò¹¥»÷ÎÞЧ£¬ÓÉÓÚѹËõ»á·ÛËéÊÓÆµÖеĶñÒâ´úÂë¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/89027/hacking/android-rce-cve-2019-2107.html