1¡¢VxWorks½¨¸´11¸ö°²È«·ì϶£¬Ó°Ï쳬¹ý20ÒŲ́É豸
Armis×êÑÐÈËÔ±ÔÚVxWorks RTOSÖз¢ÏÖ11¸ö°²È«·ì϶£¬ÕâЩ·ì϶ӰÏìÁ˺½¿Õº½Ìì¡¢¹ú·À¡¢¹¤Òµ¡¢Ò½ÁÆ¡¢Æû³µ¡¢Ïû·Ñµç×ÓµÈÁìÓòµÄ20¶àÒŲ́É豸¡£ÕâЩ·ì϶±»Í³³ÆÎªURGENT/11£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÈÆ¹ý´«Í³µÄ°²È«½â¾ö¹æ»®²¢ÆëÈ«½ÚÔìÊÜÓ°ÏìµÄÉ豸»òÀàËÆÓÀºãÖ®À¶Ò»Ñùµ¼Ö´ó¹æÄ£µÄÉ豸Öжϣ¬²¢ÇÒÎÞÐèÓû§½»»¥¡£ÕâЩ·ì϶´æÔÚÓÚVxWorks 6.5Ö®ºóµÄTCP/IPºÍ̸ջÖУ¬Ó°ÏìÁË´Óǰ13ÄêÀ´°ä²¼µÄËùÓÐVxWorks°æ±¾¡£¸Ã¹«Ë¾ÒѾÔÚÉϸöÔ°䲼Á˽¨¸´²¹¶¡£¬µ«ÕâЩ²¹¶¡Í¨¹ýÉ豸³§ÉÌ´ïµ½Ïû·ÑÕß¿ÉÄÜ»¹±ØÒª¿Ï¶¨µÄ¹¦·ò¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/vxworks-rtos-vulnerability.html
2¡¢¹È¸è×êÑÐÈËÔ±Åû¶iOSÖеÄ4¸öRCE·ì϶¼°ÆäPoC
¹È¸è×êÑÐÈËÔ±Åû¶iOSÖеÄ4¸ö·ì϶µÄ¾ßÌåÐÅÏ¢ºÍPoC£¬ÕâЩ·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýiMessage·¢ËͶñÒâÐÂÎÅÀ´¹¥»÷Ö¸±êiOSÉ豸¡£·ì϶ÀàÐÍÔ̺¬use-after-free£¨CVE-2019-8647ºÍCVE-2019-8662£©¡¢ÄÚ´æ°Ü»µ£¨CVE-2019-8660£©ÒÔ¼°Ô½½ç¶Á£¨CVE-2019-8646£©£¬ËùÓзì϶¶¼ÎÞÐèÓû§½»»¥£¬²¢Çҿɵ¼ÖÂRCE»òÔ¶³ÌÎļþ¶ÁÈ¡¡£´Ë±í£¬×êÑÐÈËÔ±»¹Åû¶ÁËwatchOSÖеÄÔ½½ç¶Á·ì϶£¨CVE-2019-8624£©µÄPoC¡£ËùÓзì϶¶¼ÒÑÔÚÆ»¹û±¾Ô°䲼µÄ¸üÐÂÖн¨¸´¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/apple-ios-vulnerabilities.html
3¡¢µç×ÓÉÌÎñƽ̨OXID½¨¸´¿Éµ¼ÖÂÍøÕ¾±»ÊÕÊܵķì϶
µç×ÓÉÌÎñƽ̨OXID°ä²¼°²È«¸üУ¬½¨¸´¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÊÕÊÜÍøÕ¾µÄ·ì϶¡£OXIDÊǵ¹úµÄÒ»¸öÊ¢ÐеçÉ̽â¾ö¹æ»®£¬Ô̺¬Ã·ÈüµÂ˹µÈ³ÛÃûÆ·ÅÆ¶¼ÔÚʹÓÃËü£¬ÆäÏÂÔØÁ¿³¬¹ý50Íò´Î¡£¸Ã·ì϶£¨CVE-2019-13026£©ÊÇSQL×¢Èë·ì϶ºÍPHP¶ÔÏó×¢Èë·ì϶µÄ½áºÏ£¬×îÖտɵ¼ÖÂRCE¡£OXID eShop°æ±¾6.0.0µ½6.0.4¡¢6.1.0µ½6.1.3¾ùÊÜÓ°Ï죬½¨ÒéÖÎÀíÔ±¸üÐÂÖÁ°æ±¾6.0.5ºÍ6.1.4¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/oxid-eshop-used-by-mercedes-fixes-remote-takeover-security-bug/
4¡¢ÂåÉ¼í¶¾¯¾Öй¶2500Ãû¾¯Ô±¼°1.75ÍòÉêÇëÈ˵ÄÒþÖÔÐÅÏ¢
¾Ý±¾µØÃ½Ì屨·£¬ÂåÉ¼í¶¾¯¾Ö£¨LAPD£©Ôâ·êÊý¾Ýй¶ÊÂÎñ£¬µ¼ÖÂ2500Ãû¾¯Ô±ºÍÔ¼1.75ÍòÃû¾¯Ô±ÉêÇëÈ˵ÄÓ×ÎÒÐÅÏ¢ÆØ¹â¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂëÒÔ¼°µ®ÉúÈÕÆÚ¡£LAPDÒѾ֤ʵÁËÕâÒ»ÊÂÎñ£¬²¢°µÊ¾ÔÚÈ·¶¨ÊÂÎñÓ°ÏìµÄÁìÓòÒÔ¼°Í¨ÖªÊÜÓ°ÏìµÄÓ×ÎÒ¡£Êг¤Eric GarcettiÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾¸ÃÊÂÎñÓëÈËʲ¿ÃŲ»ÔÙʹÓõÄÒ»¸ö¾ÉÊý¾Ý¿âÓйء£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/lapd-data-breach-exposes-personal-info-of-roughly-25k-officers/
5¡¢×ôÖÎÑÇÖÝѲÂß»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷£¬ÓʼþϵͳÒṈ̃»¾
ƾ¾Ý±¾µØÐÂÎÅ»ú¹¹WHNT±¨Â·£¬7ÔÂ26ÈÕ×ôÖÎÑÇÖÝѲÂß¶Ó£¨GSP£©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¸Ã²¿ÃÅÒѹعØÁË·þÎñÆ÷ºÍÍøÂç×÷ΪԤ·À´ëÊ©¡£GSPÊÇ×ôÖÎÑÇÖݹ«¹²°²È«ÊýµÄÒ»¸ö²¿ÃÅ£¬Ò»ÃûÈËÔ±ÔÚÆäÍÆËã»úÉϵ¯³öÒ»ÌõÆæ¹ÖµÄ֪ͨºó»ã±¨ÁËÕâÒ»ÎÊÌâ¡£GSPÒÑÈ·ÈϸÃÊÂÎñ¿ÉÄÜ»áÂÔ΢ӰÏìÆäÏìÓ¦¹¦·ò£¬µ«²¿ÃųÉÔ±ÈÔÓÐÆäËüͨѶÇþ·£¬ÀýÈçÎÞÏßµçµ÷¶È¡£¸Ã²¿ÃŲ¢Î´ÖÕ³¡ÔËÓª¡£½ØÖÁÖÜÒ»£¬¹¥»÷Õß²¢Î´Ìá³öÈκÎÊê½ðÒªÇó¡£
ÔÎÄÁ´½Ó£ºhttps://www.scmagazine.com/home/security-news/ransomware/georgia-state-patrol-agency-infected-with-ransomware/
6¡¢ÐÂAndroidÀÕË÷Èí¼þFileCoder£¬ÖØÒªÍ¨¹ýÀ¬»ø¶ÌÐÅ´«²¼
ESET×êÑÐÍŶӷ¢ÏÖÐÂAndroidÀÕË÷Èí¼þAndroid/Filecoder.C¡£¸ÃÀÕË÷Èí¼þÔÚ7ÔÂ12ÈÕ±»³õ´Î·¢ÏÖ£¬¹¥»÷Õßͨ¹ýÔÚRedditºÍXDA DevelopersÉçÇøÉϰ䲼Ìû×ÓÀ´·Ö·¢payload¡£ÔÚϰȾÉ豸ºó£¬Filecoder.C»áÏòÓû§µÄÁªÏµÈËÁÐ±í·¢ËÍÔ̺¬¶ñÒâÁ´½ÓµÄ¶ÌÐÅÒÔ½øÐд«²¼¡£¸ÃÀÕË÷Èí¼þÒªÇóµÄÊê½ðΪ94ÖÁ188ÃÀÔªÖ®¼ä¡£ÓÉÓÚ¸ÃÀÕË÷Èí¼þÔÚ´úÂëÖÐÓ²±àÂëÁ˼ÓÃÜ˽ԿµÄÖµ£¬Òò¶øÊܺ¦ÕßÎÞÐèÖ§¸¶Êê½ðÒ²¿É½âÃÜÊý¾Ý¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-android-ransomware-uses-sms-spam-to-infect-its-victims/