React APPй¶23.8ÍòÓû§Î»ÖÃÐÅÏ¢£»£»£»£»£»Ðá̽Windows BitLockerÃÜÔ¿£»£»£»£»£»AZORultľÂí

Ðû²¼Ê±¼ä 2019-03-25
1¡¢°Ä´óÀûÑÇReact APPÒâÍâй¶23.8ÍòÓû§µÄλÖÃÐÅÏ¢


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±Sanyam Jain·¢Ã÷°Ä´óÀûÑǵÄÒ»¸öÊ¢ÐеļÒÍ¥¸ú×ÙÓ¦ÓÃReact AppÒâÍâй¶Áè¼Ý23.8ÍòÓû§µÄʵʱλÖÃÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¸ÃÓ¦Óõĺǫ́MongoDBÊý¾Ý¿âδÉèÃÜÂë £¬£¬ £¬£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔ¾ÙÐлá¼û¡£¡£¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏÕÕÆ¬¡¢Ã÷ÎÄÃÜÂëÒÔ¼°¼ÒÍ¥³ÉÔ±µÄʵʱλÖÃÐÅÏ¢ £¬£¬ £¬£¬ÕâЩÊý¾Ý¾ùδ¼ÓÃÜ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/a-family-tracking-app-was-leaking-real-time-location-data/

2¡¢Ó¢¹ú¾¯Ô±ÁªºÏ»áPFEW¹ÙÍøÔâÀÕË÷Èí¼þ¹¥»÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ó¢¹ú¾¯Ô±ÁªºÏ»á£¨PFEW£©¹ÙÍøÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬ £¬£¬ÕâÒ»ÊÂÎñ±¬·¢ÔÚ3ÔÂ9ÈÕ £¬£¬ £¬£¬µ«Ö±µ½3ÔÂ21Èղű»Ðû²¼¡£¡£¡£¡£¡£¡£ ¡£Æ¾Ö¤¹Ù·½Ðû²¼µÄÉùÃ÷ £¬£¬ £¬£¬Æäµç×ÓÓʼþЧÀͼ°Îļþϵͳ¾ùÎÞ·¨»á¼û £¬£¬ £¬£¬±¸·ÝÊý¾ÝÒ²±»É¾³ý £¬£¬ £¬£¬ËùÓÐÊý¾Ý¾ù±»¼ÓÃܲ¢ÇÒÎÞ·¨»á¼û¡£¡£¡£¡£¡£¡£ ¡£¸ÃÊÂÎñÒѱ»±¨¸æ¸øÊý¾Ý±£»£»£»£»£»¤î¿Ïµ»ú¹¹£¨ICO£©ºÍ¹ú¼Ò¹¥»÷·¸·¨¾Ö£¨NCA£© £¬£¬ £¬£¬NCAÒÑÕë¶Ô´ËÊÂÕö¿ªÐÌÊÂÊӲ졣¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/uk-police-federation-hit-ransomware

3¡¢AZORultľÂíбäÖÖ £¬£¬ £¬£¬Ö÷ÒªÕë¶Ô¶íÂÞ˹ºÍÓ¡¶È

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

¿¨°Í˹»ùʵÑéÊÒ·¢Ã÷Êý¾ÝÇÔȡľÂíAZORultµÄÒ»¸öбäÖÖ £¬£¬ £¬£¬ÓÉÓڸñäÖÖÊÇÓÃC++¶ø²»ÊÇDelphi±àдµÄ £¬£¬ £¬£¬Òò´Ë¸Ã±äÖÖ±»³ÆÎªAZORult++¡£¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±³ÆAZORult++±È֮ǰµÄ°æ±¾Ô½·¢Î£ÏÕ £¬£¬ £¬£¬³ýÁË¿ÉÒÔÍøÂçÓû§Êý¾Ý£¨°üÀ¨Æ¾Ö¤¡¢ä¯ÀÀÆ÷ÀúÊ·¼Í¼ ºÍCookie£©²¢·¢ËÍÖÁC&CÖ®Íâ £¬£¬ £¬£¬¸Ã±äÖÖ»¹¿ÉÒÔ½¨ÉèÐÂÖÎÀíÔ±ÕË»§²¢½¨ÉèÔ¶³Ì×ÀÃæÅþÁ¬¡£¡£¡£¡£¡£¡£ ¡£AZORult++Ö÷ÒªÓÃÓÚÕë¶Ô¶íÂÞ˹ºÍÓ¡¶ÈµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/new-variant-of-azorult-trojan-1/

4¡¢Facebook¿ªÔ´ÏîÄ¿Fizz±£´æÎó²î £¬£¬ £¬£¬¿Éµ¼ÖÂDoS


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


SemmleÇå¾²Ñо¿Ô±Kevin Backhouse·¢Ã÷FacebookµÄ¿ªÔ´ÏîÄ¿Fizz±£´æÒ»¸öÑÏÖØµÄDoSÎó²î¡£¡£¡£¡£¡£¡£ ¡£FizzÊÇTLS 1.3ЭÒéµÄ¿ªÔ´ÊµÏÖ £¬£¬ £¬£¬Ö÷ÒªÓÃÓÚFacebookµÄ»ù´¡Éèʩ֮ÖС£¡£¡£¡£¡£¡£ ¡£¸ÃÎó²î£¨CVE-2019-3560£©Ô´ÓÚ16λÎÞ·ûºÅÊý¼Ó·¨ÖеÄÕûÊýÒç³ö £¬£¬ £¬£¬¿Éµ¼ÖÂËÀÑ­»· £¬£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍtcp°ü´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£¡£ ¡£FacebookÒÑÔÚFizzа汾2019.02.25.00ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/dos-bug-facebook-fizz-tls/143086/

5¡¢Ñо¿Ö°Ô±·¢Ã÷Ðá̽Windows BitLockerÃÜÔ¿µÄÐÂÒªÁì


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Pulse SecurityÑо¿Ö°Ô±Denis Andzakovic·¢Ã÷Ðá̽Windows BitLocker¼ÓÃÜÃÜÔ¿µÄÐÂÒªÁì¡£¡£¡£¡£¡£¡£ ¡£Õý³£ÇéÐÎÏÂÆô¶¯Bitlocker¾ÙÐмÓÃÜʱֻÐèÒªÊäÈëÃÜÂë £¬£¬ £¬£¬Ñо¿Ö°Ô±Ê¹ÓÃ30ÃÀÔªµÄÏÖ³¡¿É±à³ÌÃÅÕóÁУ¨FPGA£©ÅþÁ¬µ½Ó²ÅÌ £¬£¬ £¬£¬È»ºóͨ¹ýÐá̽¹¤¾ß´ÓLPC×ÜÏßÖлñµÃÃÜÔ¿¡£¡£¡£¡£¡£¡£ ¡£Í¨¹ýÕâÖÖ¹¥»÷ÊÖ·¨ £¬£¬ £¬£¬Ñо¿Ö°Ô±ÀֳɴÓSurface Pro 3µÄTPM 2.0Ä£¿£¿£¿£¿£¿£¿éÖÐÐá̽µ½BitlockerµÄÃÜÔ¿¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2019/03/21/researcher-finds-new-way-to-sniff-windows-bitlocker-encryption-keys/

6¡¢Ñо¿Ö°Ô±ÔÚOracle Java CardÖз¢Ã÷18¸öÇå¾²Îó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Çå¾²Ñо¿Ô±Adam GowdiakÔÚOracleµÄJava CardÊÖÒÕÖз¢Ã÷18¸öÇå¾²Îó²î £¬£¬ £¬£¬ÕâЩÎó²î¿ÉÍ»ÆÆµ×²ãJava Card VMµÄÄÚ´æÇå¾²ÐÔ £¬£¬ £¬£¬ÊµÏÖ¶ÔÖÇÄÜ¿¨ÄÚ´æµÄÍêÈ«»á¼û¡¢Í»ÆÆapplet·À»ðǽ¼°ÍâµØ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£ ¡£Gowdiak³ÆÕâЩÎó²îÊÇÓÉÓÚJava CardµÄʵÏÖ½ÓÄÉÁËÒÑÍùµÄһЩ¼Ü¹¹µ¼ÖµÄ¡£¡£¡£¡£¡£¡£ ¡£ÓÉÓÚJava CardÊÖÒÕÖ÷ÒªÓÃÓÚ½ðÈÚ¡¢Õþ¸®¡¢ÔËÊäºÍµçÐŵÈÁìÓò £¬£¬ £¬£¬Ê¹µÃÕâЩÎó²î¸üΪΣÏÕ¡£¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±³ÆOracleºÍ½ðÑÅÍØÕýÔÚ¶ÔÕâЩÎÊÌâ¾ÙÐÐÊӲ졣¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.scmagazineuk.com/multiple-vulnerabilities-found-java-card/article/1579791

ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí