AndroidÏà»ú·ì϶¿É°ÂÃØÅÄÕÕ¼°Â¼ÔìÊÓÆµ£»°Ä´óÀûÑǰ䲼ÎïÁªÍø°²È«Êµ¼Ê×¼Ôò²Ý°¸

°ä²¼¹¦·ò 2019-11-20
1¡¢AndroidÏà»ú·ì϶¿É°ÂÃØÅÄÕÕ¼°Â¼ÔìÊÓÆµ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

CheckmarxµÄ×êÑÐÈËÔ±ÔÚAndroidÏà»úÀûÓÃÖз¢ÏÖÒ»¸öзì϶ £¬¼´APP¿ÉÔÚûÓÐȨÏÞµÄÇé¿öÏÂÅÄÕÕ¡¢Â¼ÔìÊÓÆµ»ò»ñÈ¡É豸µÄµØÎ»¡£¸Ã·ì϶£¨CVE-2019-2234£©Ï൱ΣÏÕ £¬ÓÉÓÚËüÄܹ»Ê¹APPÔÚÊÖ»úËøÆÁµÄ״̬ϰÂÃØÅÄÕպͼÏñ £¬Ò²Äܹ»´Ó´æ´¢µÄÕÕÆ¬ÖÐÌáÈ¡GPSµØÎ»Êý¾Ý £¬»¹Äܹ»½«ÕâЩÊý¾Ý·¢Ëͻع¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷¡£Æ¾¾ÝGoogleµÄ˵·¨ £¬Ïà»úÀûÓÃÒÑÓÚ2019Äê7ÔÂͨ¹ýGoogle PlayÉ̵ê¸üн¨¸´ÁË´Ë·ì϶¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/android-camera-app-bug-lets-apps-record-video-without-permission/

2¡¢Adobe°ä·¢ÖÕÖ¹¶ÔAcrobatºÍReader 2015Ìṩ֧³Ö


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


AdobeÕýʽ°ä·¢ÖÕ³¡¶ÔAcrobat 2015ºÍReader 2015Ìṩ֧³Ö¡£´òËãÖеÄEOLÈÕÆÚÊÇ2020Äê4ÔÂ7ÈÕ £¬µ½ÆÚºóÓû§Äܹ»³ÖÐøÊ¹ÓÃÕâÁ½¸öÀûÓ÷¨Ê½ £¬µ«½«²»ÔÙÊÕµ½Èκθüлò·ì϶½¨¸´¡£Adobeʱʱ°ä²¼ÆäÈí¼þµÄ½¨²¹·¨Ê½ £¬Ô̺¬Flash¡¢Reader¡¢AcrobatµÈ £¬ÈôÊÇûÓÐÕâЩ¸üР£¬Óû§µÄϵͳ¿ÉÄÜ»áÎî¶ÔÔâ·ê¹¥»÷µÄ·çÏÕ¡£¸Ã¹«Ë¾ÍƼöÓû§Éý¼¶µ½Adobe Acrobat DCºÍAdobe Acrobat Reader DCµÄ×îа汾¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-announces-end-of-support-for-acrobat-reader-2015/

3¡¢È«Çòµ±¾ÖÿÄêÒòDNS¹¥»÷¾ùÔÈËðʧ½ü700ÍòÃÀÔª

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ƾ¾ÝEfficientIPµÄ×îÐÂ×êÑÐ £¬È«Çòµ±¾ÖÿÄêÒòDNS¹¥»÷¾ùÔÈËðʧ½ü700ÍòÃÀÔª £¬ÊÇËùÓÐÐÐÒµ/²¿ÃÅÖÐËðʧ×î¶àµÄ¡£DNS°²È«³§ÉÌίÍÐIDC¶ÔÀ´×Ô±±ÃÀ¡¢Å·ÖÞºÍÑÇÌ«µØÓòµÄ½ü1000λITºÍ°²È«¸¨µ¼Õß½øÐе÷²é £¬ÒÔ¼ÙÔìÆä¡¶IDC 2019ÄêÈ«ÇòDNSÍþв»ã±¨¡·¡£»ã±¨ÏÔʾ £¬ÊÀ½ç¸÷µØµÄ¹«¹²²¿ÃÅ×éÖ¯¾ùÔÈÿÄêÔâ·ê12´ÎDNS¹¥»÷ £¬Ã¿´Î¾ùÔÈÔì³É³¬¹ý50ÍòÃÀÔªµÄËðʧ £¬×ܼÆ670ÍòÃÀÔª¡£Í£»úºÍÊý¾Ý͵ÇÔËÆºõÊÇÔì³ÉÓйØËðʧµÄÖØÒªÔ­Òò¡£ºÚ¿Í½«DNSÁ÷Á¿ÓÃÓÚ¶àÖÖÖ÷ÕÅ£ºÓëÊÜϰȾÆóÒµ¿Í»§¶ËµÄC£¦CͨѶ¡¢³¢ÊÔ³Á¶¨Ïòµ½ÍøÂç´¹µöÕ¾µãÒÔ¼°Êý¾Ýй¶µÈ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/governments-lose-millions-to-dns/

4¡¢Ã·Î÷°Ù»õÔâMageCart¹¥»÷Óû§¸¶¿îÐÅÏ¢±»µÁ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


÷Î÷°Ù»õ¹«Ë¾°ä·¢ÆäÍøÕ¾ÓÚ10ÔÂ7ÈÕ±»ºÚ¿Í¹¥»÷ £¬½áÕ˺ÍÎÒµÄÇ®°üÁ½¸öÒ³Ãæ±»Ö²Èë¶ñÒâ´úÂë £¬Óû§µÄ¸¶¿îÐÅÏ¢¿ÉÄÜй¶¡£¸Ã¹«Ë¾ÓÚ10ÔÂ15ÈÕɾ³ýÁËÍøÕ¾ÉϵĶñÒâ´úÂë £¬ÈôÊÇÓû§ÔÚ´ËÆÚ¼äʹÓÃÁ˸ÃÍøÕ¾ £¬ËûÃǵĸ¶¿îÐÅÏ¢¿ÉÄܱ»·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷¡£ÊÜÓ°ÏìµÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢³ÇÊÓ×¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢ÐÅÓþ¿¨ºÅ¡¢°²È«ÂëÒÔ¼°ÓÐЧÆÚ£¨ÔÂ/Ä꣩¡£¸Ã¹«Ë¾ÒÑÆðÍ·ÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨÓʼþ £¬²¢½«ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓþ±£»¤·þÎñ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/macys-customer-payment-info-stolen-in-magecart-data-breach/

5¡¢NVAÔâÀÕË÷Èí¼þRyuk¹¥»÷ £¬400¼ÒÊÞÒ½ÕïËùÊܲ¨¼°


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÃÀ¹ú¹ú¶ÈÊÞҽЭ»á£¨NVA£©Ôâµ½ÀÕË÷Èí¼þRyukµÄ¹¥»÷ £¬È«¹ú400¼ÒÕïËùÊܵ½Ó°Ïì¡£¸ÃÊÂÎñ²úÉúÔÚ10ÔÂ27ÈÕ £¬¸Ã¹«Ë¾°µÊ¾Ò½ÁƼͼ¡¢Ö§¸¶ÏµÍ³ºÍÕïËùÖÎÀíÈí¼þ¶¼ÔÚ¹¥»÷Öб»·ÛËé £¬ÆäÉ豸¿ÉÄܱØÒªÒ»ÖܵŦ·òÄÜÁ¦ÆëÈ«¸´Ô­Õý³£ÔËÐС£NVA CMOÀÍÀ­¡¤¿ÆË¹ÌØ£¨Laura Koester£©Ö¤ÊµÁËÕâ´Î¹¥»÷ £¬µ«»Ø¾øÐ¹Â©ÊÇ·ñÖ§¸¶ÁËÊê½ð¡£NVA¼¼ÊõÕÆ¹ÜÈ˸ñÀ׸ñ¡¤¹þÌØÂü£¨Greg Hartmann£©°µÊ¾ÕâÊÇÒ»´Î¹©¸øÁ´¹¥»÷¡£µ±Ç°ÈÔÓкܶàÕïËùµÄϵͳÎÞ·¨¸´Ô­ £¬¸Ã¹«Ë¾µÄ¼¼ÊõÍŶӽ«Ôڳﱸ³Á½¨·þÎñÆ÷µÄͬʱ³ÖÐøÔÚÿ¸öÊÜÓ°ÏìµÄÕïËùÖгÉÁ¢Ò»Ê±¹¤×÷Õ¾¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/400-vet-locations-ryuk-ransomware/150443/

6¡¢°Ä´óÀûÑǰ䲼ÎïÁªÍø°²È«Êµ¼Ê×¼Ôò²Ý°¸

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°Ä´óÀûÑǰ䲼ÎïÁªÍø°²È«Êµ¼Ê×¼Ôò²Ý°¸ £¬²¢ÖÁ2020Äê3ÔÂ1ÈÕǰ¹«¿ªÕ÷Ç󶨼û¡£¸Ã×¼Ôò½«ºÏÓÃÓÚ°Ä´óÀûÑÇËùÓпÉÓõÄIoTÉ豸 £¬Ô̺¬Ïνӵ½InternetµÄÈÕ³£ÖÇÄÜÉ豸 £¬ÀýÈçÖÇÄܵçÊÓ¡¢Íó±íºÍÖÇÄÜÒôÏäµÈ¡£¸Ã×¼Ôò»ùÓÚ13Ìõ×¼Ôò £¬ÆäÖÐǰÈýÌõΪ×î¸ßÓÅÏȼ¶ £¬Ô̺¬£º²»Ê¹ÓóÁ¸´µÄĬÈÏÃÜÂë»òÈõÃÜÂ룻ÏòÉ豸Ôì×÷ÉÌ¡¢·þÎñÌṩÉ̺ÍAPP¿ª·¢ÈËÔ±Ìṩ·ì϶Åû¶Õþ²ß £¬³ÉÁ¢¹«¹²µÄ½Ó¼û/ÁªÏµÕ¾µã£»È·±£Èí¼þºÍ¹Ì¼þµÄ°²È«¸üС£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/australia-releases-draft-iot-cybersecurity-code-of-practice/