MozillaÐû²¼FirefoxÇå¾²¸üÐÂÐÞ¸´í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£» £»£»£»ºÚ¿ÍÈëÇÖÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬ £¬£¬£¬£¬£¬×ÌÈž¯·½»î¶¯

Ðû²¼Ê±¼ä 2020-06-05

1.MozillaÐû²¼FirefoxÇå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´¶à¸öí§Òâ´úÂëÖ´ÐÐÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


MozillaΪFirefoxÐû²¼ÁËÇå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁË8¸öÇå¾²Îó²î¡£¡£¡£ÆäÖÐ3¸ö±»È·ÒÔΪí§Òâ´úÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬£¬£¬°üÀ¨´¦Öóͷ£NativeTypesʱµÄJavaScriptÀàÐÍ»ìÏýÎó²î£¨CVE-2020-12406£©¼°ÄÚ´æËð»µÎó²î£¨CVE-2020-12410ºÍCVE-2020-12411£©¡£¡£¡£ÓÐÒ»¸öºÃÐÂÎÅÊÇ£¬ £¬£¬£¬£¬£¬Õâ3¸ö´úÂëÖ´ÐÐÎó²î¶¼ÊÇMozilla¿ª·¢Ö°Ô±ÔÚÄÚ²¿·¢Ã÷µÄ£¬ £¬£¬£¬£¬£¬²¢Î´ÔÚҰʹÓᣡ£¡£´Ë´ÎÐÞ¸´µÄÆäËû½ÏΪÑÏÖØµÄÎó²îÊÇCVE-2020-12399£¬ £¬£¬£¬£¬£¬¸ÃÎó²îÔÚNSSÖ´ÐÐDSAÊðÃûʱÏÔʾʱÐò²î±ð¿Éµ¼ÖÂ˽Կй¶£¬ £¬£¬£¬£¬£¬ÒÔ¼°Îó²îCVE-2020-12405£¬ £¬£¬£¬£¬£¬±£´æSharedWorkService×é¼þÖеÄuse-after-free()ÖУ¬ £¬£¬£¬£¬£¬µ±Í¨¹ýwebÒ³ÃæÊ¹ÓÃʱ¿ÉÄܵ¼Ö¿ÉʹÓÃÍ߽⡣¡£¡£    

 

Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/06/04/firefox_77_security_fixes/


2.TalosÅû¶ZoomÖÐÁ½¸öÎó²î£¬ £¬£¬£¬£¬£¬¿É±»Ê¹ÓÃÖ´ÐжñÒâ´úÂë


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


˼¿ÆTalosµÄÑо¿Ö°Ô±Åû¶ÁËZoomÖеÄÁ½¸öÎó²î£¬ £¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂÔ¶³Ì¹¥»÷Õßͨ¹ý̸Ì칦ЧÈëÇÖÊܺ¦ÕßµÄϵͳ¡£¡£¡£ÕâÁ½¸ö¾ùΪ·¾¶±éÀúÎó²î£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îдÈë»òÖ²Èëí§ÒâÎļþ£¬ £¬£¬£¬£¬£¬ÒÔÖ´ÐжñÒâ´úÂë¡£¡£¡£ÆäÖеÚÒ»¸öÎó²î±»¸ú×ÙΪCVE-2020-6109£¬ £¬£¬£¬£¬£¬ÓëZoom´¦Öóͷ£¶¯»­GIFµÄ·½·¨ÓйØ£¬ £¬£¬£¬£¬£¬ZoomûÓмì²éGIFÔ´£¬ £¬£¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖÆµÄGIF¾ÙÐй¥»÷¡£¡£¡£µÚ¶þ¸öÎó²îÊDZ»¸ú×ÙΪCVE-2020-6110£¬ £¬£¬£¬£¬£¬¸ÃÎó²îλÓÚZoom´¦Öóͷ£°üÀ¨¹²Ïí´úÂë¶ÎÔÚÄÚµÄÐÂÎŵķ½·¨ÖС£¡£¡£ÕâÁ½¸öÎó²î¶¼Ó°ÏìÁËZoom 4.6.10°æ±¾£¬ £¬£¬£¬£¬£¬²¢ÇҸù«Ë¾ÔÚÆä4.6.12°æ±¾ÖÐÐÞ¸´ÁËËûÃÇ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/104249/hacking/zoom-security-flaws.html


3.±©¶¯Ê±´úºÚ¿ÍÈëÇÖÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬ £¬£¬£¬£¬£¬×ÌÈž¯·½»î¶¯


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹úGeorge FloydÖ®ËÀÒý·¢µÄ±©¶¯Ê±´ú£¬ £¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁËÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬ £¬£¬£¬£¬£¬²¢¶Ô¾¯·½»î¶¯¾ÙÐÐ×ÌÈÅ¡£¡£¡£ÉÏÖÜÄ©£¬ £¬£¬£¬£¬£¬ºÚ¿Í»ñµÃÁËÆäÎÞÏßµçϵÓõĻá¼ûȨ£¬ £¬£¬£¬£¬£¬²¢²¥·Å±©¶¯¿ÚºÅºÍÌåÏÖÃÀ¹úÖÖ×åÖ÷ÒåµÄ¸èÇú¡£¡£¡£Ö¥¼Ó¸ç¾¯¾ÖÓв¿·Ö¼ÓÃܵÄÎÞÏßµçÆµÂÊ£¬ £¬£¬£¬£¬£¬¿ÉÊÇ´ó´ó¶¼Ñ²Âß¾¯Ô±Ê¹ÓõÄÎÞÏßµçÕÕ¾ÉÒ×±»¹¥»÷µÄ¡£¡£¡£Õâµ¼ÖÂÁ˾¯Ô±ÔÚÖ´ÐÐʹÃüʱÎÞ·¨Ê¹ÓöԽ²»úÓëµ÷ÀíÔ±ÁªÏµ£¬ £¬£¬£¬£¬£¬»òÊÇ×·Çó×ÊÖú¡£¡£¡£¹«¹²Çå¾²ÐÅÏ¢ÊÖÒÕµÄDan CaseyÌåÏÖ£¬ £¬£¬£¬£¬£¬ÕâÑù×öºÜÊÇΣÏÕ¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬µØ·½ºÍÁª°îÊÓ²ì¾ÖÒѾ­¶Ô´ËÊÂÕö¿ªÊӲ졣¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/chicago-police-scanner-jammed-amid/


4.MazeÉù³ÆÒÑÀֳɹ¥»÷Conduent£¬ £¬£¬£¬£¬£¬ÇÔȡδ¼ÓÃܵÄÎļþ²¢¼ÓÃÜÆä×°±¸


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


MazeÀÕË÷Èí¼þÍÅ»ïÉù³ÆÒѾ­Àֳɹ¥»÷ÁËλÓÚÐÂÔóÎ÷ÖݵÄÉÌҵЧÀ͹«Ë¾Conduent£¬ £¬£¬£¬£¬£¬ÇÔÈ¡ÁËδ¼ÓÃܵÄÎļþ²¢¼ÓÃÜÁËÆä×°±¸¡£¡£¡£5ÔÂ29ÈÕ£¬ £¬£¬£¬£¬£¬ConduentÐû²¼ÉùÃ÷È·ÈÏÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬´Ë´Î¹¥»÷µ¼ÖÂÆäÅ·ÖÞÓªÒµµÄЧÀÍÖÐÖ¹10Сʱ¡£¡£¡£MazeÓÚ6ÔÂ4ÈÕÔÚÆäÊý¾Ý×ßÂ©ÍøÕ¾Ðû²¼ÁËÐû²¼ÁË1GBÎļþÒÔ֤ʵÆäÔÚ2020Äê5µÄ¹¥»÷£¬ £¬£¬£¬£¬£¬Ð¹Â¶ÎļþΪBusinessIntelligence.zipºÍCompliance1.zip£¬ £¬£¬£¬£¬£¬°üÀ¨ÖݪֲÆÎñµç×Ó±í¸ñ¡¢¿Í»§É󼯡¢·¢Æ±¡¢Ó¶½ð¶ÔÕʵ¥ºÍÆäËûÔÓÏîÎĵµ¡£¡£¡£ÍþвÇ鱨¹«Ë¾Bad PacketsÌåÏÖ£¬ £¬£¬£¬£¬£¬ÔÚ2019Äê12ÔÂ17ÈÕÖÁ2020Äê2ÔÂ14ÈÕÖ®¼äµÄÖÁÉÙ°ËÖÜÄÚ£¬ £¬£¬£¬£¬£¬ConduentµÄЧÀÍÆ÷Citrix±£´æÎó²î£¨CVE-2019-19781£©£¬ £¬£¬£¬£¬£¬¸ÃÎó²î¿É±»Ê¹ÓÃÖ´ÐÐÔ¶³Ì´úÂ룬 £¬£¬£¬£¬£¬Ôø±»ºÚ¿ÍʹÓÃÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/business-services-giant-conduent-hit-by-maze-ransomware/


5.2019ÄêºÚ¿Íй¶50ÒÚÌõÊý¾Ý£¬ £¬£¬£¬£¬£¬¸øÃÀ¹úÔì³É1.2ÍòÒÚÃÀÔªËðʧ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¾ÝForgeRockͳ¼ÆÊý¾Ý£¬ £¬£¬£¬£¬£¬ºÚ¿ÍÔÚ2019Äêй¶ÁËÁè¼Ý50ÒÚÌõ¼Í¼£¬ £¬£¬£¬£¬£¬¸øÃÀ¹ú×éÖ¯Ôì³ÉÁËÁè¼Ý1.2ÍòÒÚÃÀÔªµÄËðʧ¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬£¬Ò½ÁƱ£½¡ÐÐÒµÊܵ½¹¥»÷´ÎÊý×î¶à£¬ £¬£¬£¬£¬£¬2019Äê×ܹ²±¨¸æÁË382Æðй¶ÊÂÎñ£¬ £¬£¬£¬£¬£¬ËðʧÁè¼Ý2.45ÒÚÃÀÔª¡£¡£¡£¶øÊÖÒÕ¹«Ë¾±»Ð¹Â¶Êý¾ÝµÄÊýÄ¿×î¶à£¬ £¬£¬£¬£¬£¬2019Äêй¶Áè¼Ý13.7ÒÚÌõÊý¾Ý£¬ £¬£¬£¬£¬£¬×ܼÆËðʧÁè¼Ý2500ÒÚÃÀÔª¡£¡£¡£Ð¡ÎÒ˽¼Òʶ±ðÐÅÏ¢(PII)ÈÔÈ»Êǹ¥»÷Õß×îÖ÷ÒªµÄÄ¿µÄÊý¾Ý£¬ £¬£¬£¬£¬£¬ÔÚ2019Äê98£¥µÄÊý¾ÝÊÂÎñÖÐ̻¶Á˸ÃÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÆäÖÐÉç»áÇå¾²ºÅÂ루SSN£©ÊÇ×îÈÝÒ×Êܵ½¹¥»÷µÄÊý¾ÝÀàÐÍ¡£¡£¡£ForgeRockÊ×ϯÊÖÒÕ¹ÙEve MalerÌåÏÖ£¬ £¬£¬£¬£¬£¬ÍøÂç×ï·¸ÕýÔÚÒ»Ö±ÍêÉÆÆä¹¥»÷ǰÑÔ£¬ £¬£¬£¬£¬£¬ÒÔÇÔ×÷·ÏºÄÕßÊý¾Ý¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/06/04/cybercriminals-exposed-5-billion-records-in-2019/


6.ºÚ¿ÍÔÚ°µÍø³öÊÛÁè¼Ý10ÍòÓ¡¶È¹«ÃñÉí·ÝÖ¤£¬ £¬£¬£¬£¬£¬ÏÖÔÚȪԴδ֪


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÍøÂçÇ鱨¹«Ë¾Cyble±¾ÖÜÈýÌåÏÖ£¬ £¬£¬£¬£¬£¬ºÚ¿ÍÕýÔÚ°µÍø³öÊÛÁè¼Ý10ÍòÓ¡¶È¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢£¬ £¬£¬£¬£¬£¬°üÀ¨É¨ÃèµÄÉí·ÝÖ¤¸´Ó¡¼þ¡¢Aadhaar¡¢PAN¿¨ºÍ»¤ÕÕ¡£¡£¡£ÕâЩй¶µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÒÔµ¼ÖÂÖÖÖÖ¶ñÒâ»î¶¯£¬ £¬£¬£¬£¬£¬ÀýÈçÉí·Ý͵ÇÔ¡¢Õ©Æ­ºÍÆóÒµÌØ¹¤»î¶¯¡£¡£¡£CybleÆðÔ´ÆÊÎöÅú×¢£¬ £¬£¬£¬£¬£¬ÕâЩÊý¾ÝËÆºõÀ´×ÔµÚÈý·½¹«Ë¾¶ø²»ÊÇÕþ¸®ÏµÍ³£¬ £¬£¬£¬£¬£¬ÏÖÔÚ£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÈÔÔڶԴ˾ÙÐнøÒ»³ÌÐò²é£¬ £¬£¬£¬£¬£¬ÒÔÈ·¶¨Ãü¾ÝµÄÏêϸȪԴ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ciso.economictimes.indiatimes.com/news/over-1-lakh-national-ids-of-indians-put-on-dark-net-for-sale-cyber-intelligence-firm/76177587