Å·Ã˳ÉÔ±¹ú°ä²¼ÓйØ5GÍøÂ簲ȫµÄ½áºÏ»ã±¨£»Ó¡¶ÈËÑË÷ÒýÇæJustdial API·ì϶£»NitroPDF¶à¸öRCE·ì϶

°ä²¼¹¦·ò 2019-10-11
1¡¢Å·Ã˳ÉÔ±¹ú°ä²¼ÓйØ5GÍøÂ簲ȫµÄ½áºÏ»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Å·ÃË£¨EU£©³ÉÔ±¹ú°ä²¼ÁËÒ»·ÝÓйØ5GÍøÂ簲ȫµÄ·çÏÕÆÀ¹À½áºÏ»ã±¨ £¬È·¶¨ÁË5GÍøÂçµÄÖØÒªÍþв¼°Íþв¹¥»÷Õß¡¢×îÃô¸ÐµÄ×ʲúÒÔ¼°Æä±³ºóµÄÖØÒª·ì϶ ¡£¸Ã»ã±¨Ç¿µ÷ÁËÒÀÀµÓÚµ¥Ò»É豸¹©¸øÉ̵ÄÒþ»¼ÒÔ¼°É豸ǷȱºÍ5G½â¾ö¹æ»®¶àÑùÐÔµÄÎÊÌâ ¡£ÕâЩÎÊÌ⼫´óµØÀ©´óÁËEU¼°¹ú¶È²ãÃæµÄ5G»ù´¡ÉèÊ©µÄÕûÌå´àÈõÐÔ ¡£¹ý¶ÈÒÀÀµµ¥Ò»É豸¹©¸øÉ̵ÄÅ·ÃËÔËÓªÉÌÃæ¶Ôןù©¸øÉÌ´øÀ´µÄ³ÖÐøÃ³Ò×ѹÁ¦ £¬ÎÞÂÛÊÇóÒ×ʧ°Ü¡¢¹é²¢»¹ÊÇÊÕ¹º¡¢»òÊDZ»Ôì²Ã ¡£Å·Ã˵Ļ㱨°µÊ¾ £¬5GÍøÂç±³ºóµÄ°²È«ÌôÕ½»¹ÓëÍøÂçÓëµÚÈý·½ÏµÍ³Ö®¼äµÄÏνÓÒÔ¼°µÚÈý·½¹©¸øÉ̶ÔÅ·ÃË5GÍøÂçµÄ½Ó¼ûȨÏÞµÄÔö³¤ÓÐ¹Ø ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/eu-member-states-publish-joint-report-on-5g-networks-security/

2¡¢Ó¡¶ÈËÑË÷ÒýÇæJustdial API·ì϶µ¼ÖÂ1.56ÒÚÓû§ÕÊ»§Â¶³ö

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¡¶È±¾µØËÑË÷ÒýÇæJustdial´æÔÚ°²È«·ì϶ £¬µ¼ÖºڿÍÄܹ»µÇ¼Æä1.56ÒÚÓû§ÕÊ»§ÖеÄÈκÎÒ»¸ö ¡£³ýÁ˽ӼûÓû§ÐÅÏ¢£¨ÀýÈçÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·£©±í £¬¹¥»÷Õß»¹Äܹ»Í¨¹ý¸Ã¹«Ë¾µÄÖ§¸¶·þÎñJustDial PayÀ´²é¿´Óû§µÄ²ÆÕþÐÅÏ¢ £¬Ô̺¬ÕÊ»§µÄÓà¶îºÍÂòÂô¼Í¼ ¡£¸Ã·ì϶Óɰ²È«×êÑÐÔ±Ehraz Ahmed·¢ÏÖ £¬ËüÀûÓÃÁ˸ÃÍøÕ¾µÄ×¢²áAPI ¡£¹¥»÷ÕßÉõÖÁÄܹ»ÀûÓø÷ì϶¸ü¸ÄÓû§µÄJustDial PayÕË»§ÐÅÏ¢ £¬´Ó¶øµ¼Ö·¢ËÍÖÁ¸ÃÕË»§µÄËùÓÐ×ʽ𶼱»³Á¶¨Ïò £¬µ«¹¥»÷ÕßÎÞ·¨½øÐлã¿î²Ù×÷ £¬ÓÉÓÚÕâ±ØÒª¶î±íµÄPINÂë ¡£JustDialÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾¸Ã·ì϶Òѱ»½¨¸´ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://thenextweb.com/security/2019/10/10/a-bug-in-indian-local-search-app-exposed-over-156-million-accounts/

3¡¢Ó¡µÚ°²ÄÉÖÝijҽԺÔâµ½´¹µö¹¥»÷ £¬»¼ÕßÐÅÏ¢¿ÉÄÜй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ó¡µÚ°²ÄÉÖÝÎÀÀí¹«»áÒ½Ôº°µÊ¾ÆäÁ½ÃûÔ±¹¤Ôâ´¹µö¹¥»÷ £¬6.8Íò»¼ÕßµÄÓ×ÎÒºÍÒ½ÁÆÐÅÏ¢¿ÉÄÜй¶ ¡£Æ¾¾Ýµ÷²é £¬µÚÒ»ÃûÔ±¹¤µÄÕË»§ÔÚ6ÔÂ12ÈÕ¼°7ÔÂ1ÈÕÖÁ7ÔÂ8ÈÕÔâµÚÈý·½Î´ÊÚȨ½Ó¼û £¬µÚ¶þÃûÔ±¹¤µÄÕË»§ÔòÓÚ3ÔÂ13ÈÕÖÁ6ÔÂ12ÈÕÖ®¼ä¶³ö ¡£ÎÀÀí¹«»áÒ½Ôº°µÊ¾¹ÌȻûÓÐÖ¤¾ÝÅú×¢ÏÖʵ»òÊÔͼÀÄÓÃÔ±¹¤ÓÊÏäÕË»§ÖдæÔÚµÄÈκÎÐÅÏ¢ £¬µ«µ÷²é²»ÄÜÅųý½Ó¼ûÕÊ»§ÖдæÔÚµÄÊý¾ÝµÄ¿ÉÄÜÐÔ ¡£ÕâÁ½¸öÓÊÏäÕË»§ÖÐÔ̺¬»¼ÕßµÄÒÔÏÂÐÅÏ¢£ºÐÕÃû¡¢µØÖ·¡¢Éç»á±£Ïպš¢¼ÝÊ»ÅÆÕÕ/ÖݱêʶºÅ¡¢»¤Õպš¢½ðÈÚÕʺš¢ÒøÐп¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Óû§ÃûºÍÃÜÂë¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁƼ°Õï¶ÏÐÅÏ¢µÈ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phishing-incident-exposes-medical-personal-info-of-60k-patients/

4¡¢¹¥»÷ÕßÀûÓÃWindows°æiTunesÖеķì϶·Ö·¢BitPaymer

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þBitPaymer±»·¢´Ë¿Ì¹¥»÷»î¶¯ÖÐÀûÓÃWindows°æiTunesÖеÄ0dayÀ´ÈƹýÊÜϰȾÖ÷»úÉϵķÀ²¡¶¾¼ì²â ¡£°²È«³§ÉÌMorphisecÔÚ8Ô·ÝÕë¶ÔÒ»¼ÒÆû³µÆóÒµµÄBitPaymer¹¥»÷Öз¢ÏÖÁËÕâÖÖÐÐΪ ¡£¸Ã·ì϶´æÔÚÓÚWindows°æiTunesºÍiCloudÖÐ £¬Æ»¹ûÓÚ±¾Öܽ¨¸´Á˸Ã0day ¡£ÏÖʵµÄ·ì϶´æÔÚÓÚ²úÆ·Ëæ¸½µÄBonjour¸üÐÂ×é¼þÖÐ £¬¹¥»÷ÕßÄܹ»Æô¶¯Bonjour×é¼þ²¢½Ù³ÔìäÖ´ÐÐõè¾¶ £¬½«ÆäÖ¸ÏòBitPaymerÀÕË÷Èí¼þ ¡£¸Ã·ì϶²¢²»ÄÜʹBitPaymer»ñµÃÖÎÀíԱȨÏÞ £¬µ«ËüµÄÈ·Äܹ»ºýŪ±¾µØ×°ÖõķÀ²¡¶¾Èí¼þ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-gang-uses-itunes-zero-day/

5¡¢Ë¼¿ÆTalosÍŶӷ¢ÏÖNitroPDF´æÔÚ¶à¸öRCE·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿ÆTalosÅû¶NitroPDFÖеĶà¸öÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£Nitro PDFÔÊÐíÓû§ÔÚÆäÍÆËã»úÉϱ£Áô¡¢ÔĶÁºÍ±à×ëPDFÎļþ £¬¸Ã²úÆ··ÖΪÃâ·Ñ°æºÍÊշѰæ ¡£Õâ´Î·¢Ïֵķì϶¶¼´æÔÚÓÚÊշѵÄPro°æÖÐ ¡£·ì϶Ô̺¬jpeg2000 ssizDepthÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5045£©¡¢Page KidsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5050£©¡¢ICCBasedÉ«²Ê¿Õ¼äÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5048£©¡¢CharProcsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5047£©¡¢ jpeg2000 yTsizÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5046£©¼°Á÷³¤¶È½âÎöÖ°ÄÜÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-5053£© ¡£ÊÜÓ°ÏìµÄ°æ±¾ÎªNitroPDF 12.12.1.522 ¡£NitroPDFÉÐδ°ä²¼Óйؽ¨¸´²¹¶¡ ¡£

Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/10/vuln-spotlight-Nitro-PDF-RCE-bugs-sept-19.html

6¡¢HP½¨¸´Touchpoint AnalyticsÈí¼þÖеÄLPE·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SafeBreach Labs°²È«×êÑÐÔ±Peleg Hadar·¢ÏÖHPµÄTouchPoint Analytics´æÔÚLPE·ì϶£¨CVE-2019-6333 £¬CVSS 3ÆÀ·ÖΪ6.7·Ö£© ¡£HP TouchPoint AnalyticsÒÔWindows·þÎñµÄ´ó¾ÖԤװÔÚ´óÎÞÊýHPÍÆËã»úÉÏ £¬Ö¼ÔÚÄäÃûÍøÂçÓ²¼þ»úÄÜÕï¶ÏÐÅÏ¢ ¡£¸ÃWindows·þÎñÓµÓеÚÒ»Á÷´ËÍâNT AUTHORITY\SYSTEMȨÏÞ ¡£Hadar°µÊ¾¸Ã·ì϶ÊÇÓɲ»°²È«µÄDLL¼ÓÔØËùÒýÆðµÄ £¬Touchpoint Analytics Client°æ±¾4.1.4.2827ÒÔÏÂÊܵ½Ó°Ïì ¡£HPÔÚTouchpoint Analytics Client 4.1.4.2827Öн¨¸´ÁË´Ë·ì϶ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hp-touchpoint-analytics-lpe-vulnerability-affects-most-hp-pcs