AndroidÏà»ú·ì϶¿É°ÂÃØÅÄÕÕ¼°Â¼ÔìÊÓÆµ£»°Ä´óÀûÑǰ䲼ÎïÁªÍø°²È«Êµ¼Ê×¼Ôò²Ý°¸
°ä²¼¹¦·ò 2019-11-20
CheckmarxµÄ×êÑÐÈËÔ±ÔÚAndroidÏà»úÀûÓÃÖз¢ÏÖÒ»¸öзì϶£¬¼´APP¿ÉÔÚûÓÐȨÏÞµÄÇé¿öÏÂÅÄÕÕ¡¢Â¼ÔìÊÓÆµ»ò»ñÈ¡É豸µÄµØÎ»¡£¸Ã·ì϶£¨CVE-2019-2234£©Ï൱ΣÏÕ£¬ÓÉÓÚËüÄܹ»Ê¹APPÔÚÊÖ»úËøÆÁµÄ״̬ϰÂÃØÅÄÕպͼÏñ£¬Ò²Äܹ»´Ó´æ´¢µÄÕÕÆ¬ÖÐÌáÈ¡GPSµØÎ»Êý¾Ý£¬»¹Äܹ»½«ÕâЩÊý¾Ý·¢Ëͻع¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷¡£Æ¾¾ÝGoogleµÄ˵·¨£¬Ïà»úÀûÓÃÒÑÓÚ2019Äê7ÔÂͨ¹ýGoogle PlayÉ̵ê¸üн¨¸´ÁË´Ë·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/android-camera-app-bug-lets-apps-record-video-without-permission/2¡¢Adobe°ä·¢ÖÕÖ¹¶ÔAcrobatºÍReader 2015Ìṩ֧³Ö
AdobeÕýʽ°ä·¢ÖÕ³¡¶ÔAcrobat 2015ºÍReader 2015Ìṩ֧³Ö¡£´òËãÖеÄEOLÈÕÆÚÊÇ2020Äê4ÔÂ7ÈÕ£¬µ½ÆÚºóÓû§Äܹ»³ÖÐøÊ¹ÓÃÕâÁ½¸öÀûÓ÷¨Ê½£¬µ«½«²»ÔÙÊÕµ½Èκθüлò·ì϶½¨¸´¡£Adobeʱʱ°ä²¼ÆäÈí¼þµÄ½¨²¹·¨Ê½£¬Ô̺¬Flash¡¢Reader¡¢AcrobatµÈ£¬ÈôÊÇûÓÐÕâЩ¸üУ¬Óû§µÄϵͳ¿ÉÄÜ»áÎî¶ÔÔâ·ê¹¥»÷µÄ·çÏÕ¡£¸Ã¹«Ë¾ÍƼöÓû§Éý¼¶µ½Adobe Acrobat DCºÍAdobe Acrobat Reader DCµÄ×îа汾¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-announces-end-of-support-for-acrobat-reader-2015/3¡¢È«Çòµ±¾ÖÿÄêÒòDNS¹¥»÷¾ùÔÈËðʧ½ü700ÍòÃÀÔª
ƾ¾ÝEfficientIPµÄ×îÐÂ×êÑУ¬È«Çòµ±¾ÖÿÄêÒòDNS¹¥»÷¾ùÔÈËðʧ½ü700ÍòÃÀÔª£¬ÊÇËùÓÐÐÐÒµ/²¿ÃÅÖÐËðʧ×î¶àµÄ¡£DNS°²È«³§ÉÌίÍÐIDC¶ÔÀ´×Ô±±ÃÀ¡¢Å·ÖÞºÍÑÇÌ«µØÓòµÄ½ü1000λITºÍ°²È«¸¨µ¼Õß½øÐе÷²é£¬ÒÔ¼ÙÔìÆä¡¶IDC 2019ÄêÈ«ÇòDNSÍþв»ã±¨¡·¡£»ã±¨ÏÔʾ£¬ÊÀ½ç¸÷µØµÄ¹«¹²²¿ÃÅ×éÖ¯¾ùÔÈÿÄêÔâ·ê12´ÎDNS¹¥»÷£¬Ã¿´Î¾ùÔÈÔì³É³¬¹ý50ÍòÃÀÔªµÄËðʧ£¬×ܼÆ670ÍòÃÀÔª¡£Í£»úºÍÊý¾Ý͵ÇÔËÆºõÊÇÔì³ÉÓйØËðʧµÄÖØÒªÔÒò¡£ºÚ¿Í½«DNSÁ÷Á¿ÓÃÓÚ¶àÖÖÖ÷ÕÅ£ºÓëÊÜϰȾÆóÒµ¿Í»§¶ËµÄC£¦CͨѶ¡¢³¢ÊÔ³Á¶¨Ïòµ½ÍøÂç´¹µöÕ¾µãÒÔ¼°Êý¾Ýй¶µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/governments-lose-millions-to-dns/4¡¢Ã·Î÷°Ù»õÔâMageCart¹¥»÷Óû§¸¶¿îÐÅÏ¢±»µÁ
÷Î÷°Ù»õ¹«Ë¾°ä·¢ÆäÍøÕ¾ÓÚ10ÔÂ7ÈÕ±»ºÚ¿Í¹¥»÷£¬½áÕ˺ÍÎÒµÄÇ®°üÁ½¸öÒ³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬Óû§µÄ¸¶¿îÐÅÏ¢¿ÉÄÜй¶¡£¸Ã¹«Ë¾ÓÚ10ÔÂ15ÈÕɾ³ýÁËÍøÕ¾ÉϵĶñÒâ´úÂ룬ÈôÊÇÓû§ÔÚ´ËÆÚ¼äʹÓÃÁ˸ÃÍøÕ¾£¬ËûÃǵĸ¶¿îÐÅÏ¢¿ÉÄܱ»·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷¡£ÊÜÓ°ÏìµÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢³ÇÊÓ×¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢ÐÅÓþ¿¨ºÅ¡¢°²È«ÂëÒÔ¼°ÓÐЧÆÚ£¨ÔÂ/Ä꣩¡£¸Ã¹«Ë¾ÒÑÆðÍ·ÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨÓʼþ£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓþ±£»¤·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/macys-customer-payment-info-stolen-in-magecart-data-breach/
5¡¢NVAÔâÀÕË÷Èí¼þRyuk¹¥»÷£¬400¼ÒÊÞÒ½ÕïËùÊܲ¨¼°
ÃÀ¹ú¹ú¶ÈÊÞҽлᣨNVA£©Ôâµ½ÀÕË÷Èí¼þRyukµÄ¹¥»÷£¬È«¹ú400¼ÒÕïËùÊܵ½Ó°Ïì¡£¸ÃÊÂÎñ²úÉúÔÚ10ÔÂ27ÈÕ£¬¸Ã¹«Ë¾°µÊ¾Ò½ÁƼͼ¡¢Ö§¸¶ÏµÍ³ºÍÕïËùÖÎÀíÈí¼þ¶¼ÔÚ¹¥»÷Öб»·ÛË飬ÆäÉ豸¿ÉÄܱØÒªÒ»ÖܵŦ·òÄÜÁ¦ÆëÈ«¸´ÔÕý³£ÔËÐС£NVA CMOÀÍÀ¡¤¿ÆË¹ÌØ£¨Laura Koester£©Ö¤ÊµÁËÕâ´Î¹¥»÷£¬µ«»Ø¾øÐ¹Â©ÊÇ·ñÖ§¸¶ÁËÊê½ð¡£NVA¼¼ÊõÕÆ¹ÜÈ˸ñÀ׸ñ¡¤¹þÌØÂü£¨Greg Hartmann£©°µÊ¾ÕâÊÇÒ»´Î¹©¸øÁ´¹¥»÷¡£µ±Ç°ÈÔÓкܶàÕïËùµÄϵͳÎÞ·¨¸´Ô£¬¸Ã¹«Ë¾µÄ¼¼ÊõÍŶӽ«Ôڳﱸ³Á½¨·þÎñÆ÷µÄͬʱ³ÖÐøÔÚÿ¸öÊÜÓ°ÏìµÄÕïËùÖгÉÁ¢Ò»Ê±¹¤×÷Õ¾¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/400-vet-locations-ryuk-ransomware/150443/
6¡¢°Ä´óÀûÑǰ䲼ÎïÁªÍø°²È«Êµ¼Ê×¼Ôò²Ý°¸
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/australia-releases-draft-iot-cybersecurity-code-of-practice/


¾©¹«Íø°²±¸11010802024551ºÅ