Android¶ñÒâ¸æ°×Èí¼þVidMate£¬£¬ £¬£¬£¬£¬×°ÖÃÁ¿´ï5ÒڴΣ»£»£»£»£»£»£»£»Windows 10´òË㹤×÷ÖеÄÐÂ0day

°ä²¼¹¦·ò 2019-05-22
1¡¢Android¶ñÒâ¸æ°×Èí¼þVidMate£¬£¬ £¬£¬£¬£¬×°ÖÃÁ¿´ï5ÒÚ´Î

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
ƾ¾ÝUpstream×î½üµÄÒ»·Ý×êÑл㱨£¬£¬ £¬£¬£¬£¬VidMate´æÔÚ¶à¸ö¶ñÒâÐÐΪ£¬£¬ £¬£¬£¬£¬Ô̺¬µã»÷°µ²Ø¸æ°×¡¢ºÄ¾¡µçÁ¿¡¢ÍøÂçÓ×ÎÒÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£VidmateÊÇÒ»¸öAndroidÊÓÆµÀûÓ㬣¬ £¬£¬£¬£¬ÓÃÓÚ´ÓÈȵã·þÎñ£¨ÀýÈçYouTube£©ÏÂÔØºÍ´«ÊäÊÓÆµ£¬£¬ £¬£¬£¬£¬VidmateûÓÐÔÚGoogle PlayÉ̵êÖÐÉϼÜ£¬£¬ £¬£¬£¬£¬¶øÊÇ´ÓCNET¡¢UptodownµÈµÚÈý·½ÀûÓÃÉÌµê½øÐзַ¢£¬£¬ £¬£¬£¬£¬Æä×°ÖÃÁ¿´ï5ÒڴΡ£¡£¡£¡£¡£¡£Upstream°²È«Æ½Ì¨¹²×èÖ¹ÁË1.3ÒÚ´ÎÓÉVidMateÌáÒéµÄ¿ÉÒÉÂòÂô³¢ÊÔ¡£¡£¡£¡£¡£¡£Æ¾¾Ý²âÊÔÁ˾Ö£¬£¬ £¬£¬£¬£¬VidMateÿÔ»á¿÷Ëðµô3GB¶àµÄÊý¾ÝÁ÷Á¿£¬£¬ £¬£¬£¬£¬²¢ÍøÂçÓû§ÐÅÏ¢·¢ËÍÖÁλÓÚÐÂ¼ÓÆÂµÄ·þÎñÆ÷¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://gbhackers.com/vidmate-app/


2¡¢ÅÅÐÐǰ1000µÄdockerÈÝÆ÷ÖÐÓÐ194¸öδÉèrootÃÜÂë

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
Kenna Security×êÑÐÈËÔ±Jerry GamblinɨÃèÁËDockerÉ̵êÖÐ×îÊÜ»¶Ó­µÄ1000¸öÈÝÆ÷£¬£¬ £¬£¬£¬£¬·¢ÏÖÓÐ194¸ö£¨Ô¼Õ¼Îå·ÖÖ®Ò»£©ÈÝÆ÷µÄrootÕË»§ÔÊÐí¿ÕÃÜÂ룬£¬ £¬£¬£¬£¬ÆäÖÐһЩÈÝÆ÷µÄÏÂÔØÁ¿³¬¹ý1000Íò¡£¡£¡£¡£¡£¡£Gamblin°ä²¼ÁËδÉèrootÃÜÂëµÄDockerÈÝÆ÷µÄÅÅÐòÁбí£¬£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬govuk/governmentpaas¡¢hashicorp¡¢microsoft¡¢monsanto¡¢mesosphereºÍkylemanna/openvpnµÈÊÜ»¶Ó­µÄÈÝÆ÷¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/194-of-the-top-1000-docker-containers-don-t-have-root-passwords/


3¡¢×êÑÐÈËÔ±ÔÙÆØWindows 10´òË㹤×÷ÖеÄÐÂ0day

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
×êÑÐÈËÔ±SandboxEscaperÔÙ´ÎÆØ¹âÁËWindows 10´òË㹤×÷ÖеÄÒ»¸öÐÂ0day£¬£¬ £¬£¬£¬£¬ÕâÊÇ×ÔÈ¥Äê8ÔÂÒÔÀ´SandboxEscaperÆØ¹âµÄµÚÎå¸öWindows 0day¡£¡£¡£¡£¡£¡£¸Ã0dayÊÇ´òË㹤×÷·¨Ê½ÖеÄÒ»¸ö±¾µØÌáȨ·ì϶£¨LPE£©£¬£¬ £¬£¬£¬£¬×êÑÐÈËÔ±ÔÚGitHubÉϰ䲼ÁË·ì϶ÀûÓôúÂë¡£¡£¡£¡£¡£¡£¾­¹ý²âÊÔ¸Ã0day¿ÉÔÚWindows 10 32λϵͳÉÏÔËÐУ¬£¬ £¬£¬£¬£¬²¢ÇÒ³ÁбàÒëºóÒ²¿ÉÔÚ64λϵͳÉϹ¤×÷¡£¡£¡£¡£¡£¡£SandboxEscaperÔÚ²©¿ÍÉϳÆËý»¹ÓÐ4¸öδÅû¶µÄ0day£¬£¬ £¬£¬£¬£¬Ô̺¬3¸öLPE·ì϶ºÍ1¸öɳºÐÌÓÒÝ·ì϶¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-zero-day-exploit-for-bug-in-windows-10-task-scheduler/


4¡¢Ó¡¶ÈHCL¶à¸ö×ÓÓòй¶Ա¹¤ÃÜÂë¼°¿Í»§ÏîÄ¿ÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
UpGuard×êÑÐÈËÔ±·¢ÏÖÓ¡¶ÈIT¹«Ë¾HCLµÄ¶à¸ö×ÓÓòй¶ÁËÔ±¹¤ÃÜÂëºÍ¿Í»§ÏîĿϸ½ÚµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâЩÃô¸ÐÐÅϢûÓÐѡȡÈκÎÈÏÖ¤´ëÊ©£¬£¬ £¬£¬£¬£¬²¢Çҿɹ«¿ª½Ó¼û¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸ö×ÓÓòµÄÍøÒ³Ô̺¬HRÓйØÊÂÎñµÄÒDZí°å£¬£¬ £¬£¬£¬£¬ÄÚº¬364ÃûÐÂÔ±¹¤µÄID¡¢ÐÕÃû¡¢ÊÖ»úºÅ¡¢ÈëÖ°ÈÕÆÚ¡¢µØÖ·¡¢ÕÐÆ¸ÈËÔ±ÐÕÃû¡¢Ã÷ÎÄÃÜÂëµÈÃô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬£¬ÁíÒ»¸öÍøÒ³ÔòÔ̺¬³¬¹ý2800ÃûÔ±¹¤µÄSAP´úÂë¡£¡£¡£¡£¡£¡£HCLµÄSmartManage»ã±¨ÏµÍ³Ò²Ð¹Â¶ÁËһЩ»úÃܻ㱨£¬£¬ £¬£¬£¬£¬ÀýÈçÓë¿Í»§ÓйصÄÄÚ²¿ÃÅÎö»ã±¨¡¢Ã¿Öܿͻ§»ã±¨ºÍ×°Öû㱨¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/it-giant-hcl-exposed-employee-passwords-and-customer-project-details-online-6d892058


5¡¢MuddyWaterÔÚ¹¥»÷»î¶¯ÖÐʹÓÃз´Õì²â¼¼Êõ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
˼¿ÆTalos·¢ÏÖAPT×éÖ¯MuddyWaterµÄй¥»÷»î¶¯BlackWater£¬£¬ £¬£¬£¬£¬×êÑÐÈËÔ±³Æ¸Ã×éÖ¯Ò»ÏòÔÚ¸üÐÂÆäÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©£¬£¬ £¬£¬£¬£¬²¢Ôö³¤ÁËÈý¸ö·ÖÆçµÄ²½ÖèÀ´Ìӱܼì²â¡£¡£¡£¡£¡£¡£ÔÚеÄBlackWater»î¶¯ÖУ¬£¬ £¬£¬£¬£¬MuddyWaterÀûÓûìºÏµÄVBAºê½ÅÕý±¾¸ü¸Ä×¢²á±í£¨Ôö³¤Ò»¸öRun Key£©²¢»ñµÃÓÆ¾ÃÐÔ£¬£¬ £¬£¬£¬£¬¶øºóʹÓÃPowerShell¾ç±¾´ÓC2·þÎñÆ÷ÏÂÔØ»ùÓÚPowerShellµÄľÂí¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85897/apt/muddywater-blackwater-campaign.html


6¡¢W97MµÄжñÒâ·Ö·¢»î¶¯£¬£¬ £¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢Ó¡¶ÈºÍÅ·ÖÞ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
×êÑÐÈËÔ±·¢ÏÖ¶ñÒâÈí¼þW97M/DownloaderµÄжñÒâ¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬¸Ã»î¶¯ÖØÒªÕë¶ÔÃÀ¹ú¡¢Ó¡¶È¡¢µÂ¹úºÍÓ¢¹ú¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±¹Û²ìµ½W97M´Ë¿Ìͨ¹ýÒ»¸ö¶¨ÔìµÄPHP dropper´«²¼£¬£¬ £¬£¬£¬£¬¹¥»÷Õßͨ¹ýÊÜϰȾµÄÍøÕ¾ÓÕʹÓû§ÏÂÔØ¶ñÒâW97MÎĵµ£¬£¬ £¬£¬£¬£¬¸ÃÎĵµÖеÄVB¾ç±¾´ÓC£¦C·þÎñÆ÷ÖÐÏÂÔØ²¢Ö´ÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¸ÃDownloaderÍйÜÔÚMagento¡¢WordPressºÍJoomlaµÈ¶à¸öCMSµÄÍøÕ¾ÉÏ£¬£¬ £¬£¬£¬£¬µ«¶ñÒâ´úÂë×ÔÉí²»ÊÇCMSµÄ¡£¡£¡£¡£¡£¡£W97M¿ÉÇÔÈ¡Óû§µÄÒøÐеǼʹ´¦²¢·¢ËÍÖÁ.ruÍøÕ¾¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/w97mdownloader-hosted-on-multiple-cms-like-magento-wordpress-and-joomla-baa66294