Windows¼Çʱ¾´úÂëÖ´ÐÐÎó²î£»Docker¾ºÕùÌõ¼þÎó²î£¬Ó°ÏìËùÓÐDocker°æ±¾£»DuckDuckGoÒ×ÊÜURLÓÕÆ¹¥»÷
Ðû²¼Ê±¼ä 2019-05-30
Ñо¿Ö°Ô±Åû¶DockerÖÐδÐÞ¸´µÄ¾ºÕùÌõ¼þÎó²î£¬¸ÃÎó²îÓ°ÏìÁËËùÓеÄDocker°æ±¾¡£¸ÃÎó²îÀàËÆÓÚCVE-2018-15664£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ³ÌÐò¶Ô×ÊÔ´¾ÙÐвÙ×÷֮ǰÐÞ¸Ä×ÊԴ·¾¶£¬´Ó¶ø¿ÉÄÜ»ñµÃí§ÒâÎļþµÄ¶Áд»á¼ûȨÏÞ£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¸ÃÎó²îµÄ½¹µãÔ´ÓÚFollowSymlinkInScope¹¦Ð§Ò×ÊÜTOCTOU¹¥»÷¡£Ñо¿Ö°Ô±ÒѾÐû²¼ÁËPoC´úÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/unpatched-flaw-affects-all-docker-versions-exploits-ready/2DuckDuckGoÒ×ÊÜURLÓÕÆ¹¥»÷£¬×°ÖÃÁ¿´ï500Íò´Î
Çå¾²Ñо¿Ö°Ô±Dhiraj Mishra·¢Ã÷Android¿ªÔ´ä¯ÀÀÆ÷DuckDuckGo±£´æÒ»¸öURLÓÕÆÎó²î£¨CVE-2019-12329£©£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÓÕÆÓû§ÐÅÍлá¼ûµÄÊÇ¿ÉÐÅÍøÕ¾¡£¸ÃÎó²îÔÊÐíʹÓÃJavaScriptÓÕÆä¯ÀÀÆ÷µÄµØµãÀ¸£¬Í¨¹ýsetIntervalº¯Êýÿ10µ½50ºÁÃëÖØÐ¼ÓÔØÒ»¸öURL¡£DuckDuckGoÇå¾²ÍŶÓÒÔΪ¸ÃÎó²î²»ÐèÒªÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/duckduckgo-android-browser-vulnerable-to-url-spoofing-attacks/3¹È¸èÑо¿Ö°Ô±ÔÚWindows¼Çʱ¾Öз¢Ã÷´úÂëÖ´ÐÐÎó²î
Google Project ZeroÑо¿Ô±Tavis OrmandyÔÚ΢ÈíµÄWindows¼Çʱ¾Öз¢Ã÷Ò»¸ö´úÂëÖ´ÐÐÎó²î£¬OrmandyÒÑÏò΢Èí±¨¸æÁ˸ÃÎÊÌâ¡£Îó²îµÄϸ½ÚÉÐδÅû¶£¬µ«OrmandyÔ¤¼Æ¸ÃÎó²îÊÇÒ»¸öÄÚ´æËð»µÎó²î£¬ËûÔÚTwitterÉÏ·ÖÏíµÄͼƬÑÝʾÁËÔõÑùÔÚ¼Çʱ¾Öе¯³öshell¡£Æ¾Ö¤¹È¸èµÄÎó²îÅû¶Õþ²ß£¬Ormandy½«ÔÚ90Ììºó»ò΢ÈíÐû²¼ÐÞ¸´²¹¶¡ºóÅû¶¸ü¶àÎó²îϸ½Ú¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/86297/hacking/code-execution-flaw-notepad.html4жñÒâÍÚ¿óÀ˳±Nansh0u£¬ÒÑѬȾ5Íǫ̀·þÎñÆ÷
ƾ֤Guardicore LabsµÄ±¨¸æ£¬Ò»¸öеĶñÒâÍÚ¿óÔ˶¯Nansh0uÒѾѬȾÁ˶à´ï5Íǫ̀·þÎñÆ÷¡£¸ÃÍÚ¿óÀ˳±×Ô2ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Êܺ¦Õß´ó´ó¶¼Î»ÓÚÖйú¡¢ÃÀ¹úºÍÓ¡¶È£¬¹²ÁýÕÖÁË90¸ö¹ú¼Ò¡£Êܵ½¹¥»÷µÄÐÐÒµ°üÀ¨Ò½ÁƱ£½¡¡¢µçÐÅ¡¢Ã½ÌåºÍITÁìÓò¡£Êܵ½Ñ¬È¾ºó£¬¹¥»÷Õß»áÔÚÄ¿µÄ·þÎñÆ÷ÉÏ×°ÖüÓÃܿ󹤺ÍÄÚºËģʽrootkit£¬ÒÔÍÚ¾ò¿ªÔ´¼ÓÃÜÇ®±ÒTurtleCoin¡£ÔÚ4Ô·ݣ¬Ñо¿Ö°Ô±ÊӲ쵽Èý´ÎÀàËÆµÄ¹¥»÷£¬ËùÓеÄÔ´IPµØµã¶¼À´×ÔÄÏ·Ç£¬ÇÒʹÓÃÏàͬµÄ¹¥»÷Àú³ÌºÍ¹¥»÷ÒªÁì¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/50k-servers-infected-with-cryptomining-malware-in-nansh0u-campaign/145140/5ÐÂÎ÷À¼²ÆÎñ²¿ÔâºÚ¿ÍÈëÇÖ£¬²ÆÎñÔ¤ËãÐÅϢй¶
ÔÎÄÁ´½Ó£º
https://cyware.com/news/new-zealand-treasury-hacked-and-budget-information-leaked-2fceb79b6Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingÔâºÚ¿ÍÈëÇÖ£¬¿Í»§ÐÅϢй¶
Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingµÄÀñÎï¿¨ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬µ¼Ö¿ͻ§Êý¾Ýй¶¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢Óû§ID¡¢¼ÓÃܵÄÃÜÂë¡¢µØµã¡¢ÓÊÕþ±àÂëºÍÀñÎ│¶©µ¥ºÅ£¬µ«²»°üÀ¨ÈκÎÒøÐп¨Ï¸½Ú»òÖ§¸¶ÐÅÏ¢¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ2019Äê5ÔÂ14ÈÕ£¬¸Ã¹«Ë¾ÒÑÏòÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¼°Æä¿Í»§×ª´ïÁËй¶ÊÂÎñ£¬ÏÖÔÚÊÜÓ°ÏìµÄ¿Í»§ÊýĿδ֪¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uk-pub-chain-greene-king-suffers-data-breach-following-hack-on-its-gift-card-website-1aec5c69


¾©¹«Íø°²±¸11010802024551ºÅ