MacOS 0day¿ÉÄ£ÄâÊó±êµã»÷ÒÔÖ´ÐжñÒâ´úÂ룻£»£»£»£»£»SUPRAÖÇÄܵçÊÓÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÉ豸±»½Ù³Ö

°ä²¼¹¦·ò 2019-06-04
1MacOS 0day¿ÉÄ£ÄâÊó±êµã»÷ÒÔÖ´ÐжñÒâ´úÂë


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Digita Security×êÑÐÈËÔ±Patrick WardleÅû¶macOSÖеÄÒ»¸ö0day£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷Õßͨ¹ýÄ£ÄâÊó±êµã»÷ÒÔÈÆ¹ýmacOSµÄ°²È«´ëÊ©²¢Ö´ÐжñÒâ´úÂë¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶ÓëmacOSÑéÖ¤ÀûÓ÷¨Ê½µÄ·½Ê½Óйأ¬£¬£¬£¬£¬£¬Ò»Ð©ÀûÓ÷¨Ê½ÔÚ×°ÖÃ֮ǰ²»±ØÒªÈκΡ°ÔÊÐí¡±»ò¡°»Ø¾ø¡±°²È«¶Ô»°¿ò£¬£¬£¬£¬£¬£¬ÀýÈçVLCýÌå²¥·ÅÆ÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâ°æ±¾µÄVLCÀ´Ö´ÐжñÒâÐÐΪ£¬£¬£¬£¬£¬£¬ÀýÈç´ò¿ªÂó¿Ë·ç»òÇÔÈ¡GPD×ø±êÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-zero-day-malicious-code/145259/

2SUPRAÖÇÄܵçÊÓÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÉ豸±»½Ù³Ö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±Dhiraj Mishra·¢ÏÖSUPRAÖÇÄܵçÊÓÊܵ½Î´½¨²¹µÄÔ¶³ÌÎļþÔ̺¬·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2019-12477£©¿ÉÔÊÐíWiFi¹¥»÷ÕßÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öϽٳֵçÊÓÆÁÄ»²¥·ÅÐéαÊÓÆµ¡£¡£¡£ ¡£¡£¡£SUPRAÊÇÒ»¸ö¶íÂÞ˹µç×ÓÆ·ÅÆ£¬£¬£¬£¬£¬£¬Æä²úÆ·ÖØÒªÔÚ¶íÂÞ˹¡¢ÖйúºÍ°¢ÁªÇõÏúÊÛ¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶´æÔÚÓÚSupra Smart Cloud TVµÄ¡°openLiveURL¡±Ö°ÄÜÖУ¬£¬£¬£¬£¬£¬¹ÌÈ»¸Ã·ì϶ÒÑ»ñµÃCVE ID£¬£¬£¬£¬£¬£¬µ«¿ÉÄܲ»»áµÃµ½½¨²¹¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/06/supra-smart-tv-hack.html

3Quest½¨¸´Kace K1000É豸ÖеĶà¸ö°²È«·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ƾ¾Ý¿¨ÄÚ»ù÷¡´óѧCERT/CC°ä²¼µÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬Quest¹«Ë¾µÄKace K1000É豸Êܵ½¶à¸ö·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬Ô̺¬SQLäע·ì϶£¨CVE-2018-5404£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Ãô¸ÐÐÅÏ¢£©¡¢JavaScript´úÂë×¢Èë·ì϶£¨CVE-2018-5405£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷Õß½Ù³ÖÖÎÀíÔ±»á»°£©ÒÔ¼°¿ÉÔÊÐí¹¥»÷ÕßÔö³¤ÖÎÀíÔ¹ØË»§»ò¸ü¸ÄÉ豸ÅäÏàÐÅÏ¢µÄ·ì϶£¨CVE-2018-5406£©µÈ¡£¡£¡£ ¡£¡£¡£QuestÒÑÔÚ9.0.270¼°¸ü¸ß°æ±¾Öн¨¸´ÁËÕâЩ·ì϶¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/serious-vulnerabilities-found-kace-k1000-appliance

4ºÚ¿Íͨ¹ýÈõÃÜÂëÈëÇÖÊý°ÙÃû°£Èû¶í±ÈÑǼéϸÓÊÏä


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°£Èû¶í±ÈÑÇÐÅÏ¢ÍøÂ簲ȫ¾Ö£¨INSA£©µÄÊý°ÙÃû¼éϸµÄµç×ÓÓÊÏäÒòʹÓÃÈõÃÜÂë±»ºÚ¿ÍÈëÇÖ¡£¡£¡£ ¡£¡£¡£Æ¾¾ÝSafety Detective×êÑÐÈËÔ±µÄµ÷²é£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÒ×Óڲ²âµÄÓû§ÃûºÍÃÜÂë»ñµÃÁ˶ÔÕâЩ¼éϸÓÊÏäµÄδÊÚȨ½Ó¼û¡£¡£¡£ ¡£¡£¡£ÔÚÊÜËðµÄ300¸öÍ´´¦ÖУ¬£¬£¬£¬£¬£¬ÓÐ142¸öʹÓÃÁËÈõÃÜÂë¡°p@$$w0rd¡±£¬£¬£¬£¬£¬£¬´Ë±í£¬£¬£¬£¬£¬£¬ÓÐ62¸öÃÜÂëÔ̺¬¡°123¡±ÐòÁÓ×£¡£¡£ ¡£¡£¡£²¢ÇÒINSA²¢Î´¶ÔÃÜÂë½øÐмÓÑκ͹þÏ£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/emails-of-hundreds-of-ethiopias-information-network-security-agency-agents-hacked-due-to-predictable-passwords-40bbc358

5AMCAÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬µ¼ÖÂ1190ÍòQuest Diagnostics»¼ÕßÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úÕ˵¥·þÎñ¹«Ë¾AMCAÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµ¼ÖÂѪҺ¼ì²â¹«Ë¾Quest DiagnosticsµÄ1190Íò»¼ÕßÐÅϢй¶¡£¡£¡£ ¡£¡£¡£Æ¾¾ÝAMCAµÄ²¼¸æ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñ²úÉúÔÚ2018Äê8ÔÂ1ÈÕÖÁ2019Äê3ÔÂ30ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁËAMCAµÄϵͳ£¬£¬£¬£¬£¬£¬¸ÃϵͳÔ̺¬Quest DiagnosticsµÄ»¼ÕßÐÅÏ¢¡£¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÒøÐÐÕË»§Êý¾ÝºÍÐÅÓþ¿¨ºÅµÈ²ÆÕþÐÅÏ¢ÒÔ¼°Ò½ÁÆÐÅÏ¢ºÍÉç»á°²È«ºÅÂëµÈÓ×ÎÒÐÅÏ¢¡£¡£¡£ ¡£¡£¡£QuestºÍAMCAÔÚ¶Ô´ËÊÂÎñ½øÐе÷²é¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/billing-details-for-119m-quest-diagnostics-clients-exposed/

6ÃÀLewes¹«¹²¹¤³ÌίԱ»áÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬¿Í»§ÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝÃÀ¹úºÓɽ°²È«ÊýµÄÖҸ棬£¬£¬£¬£¬£¬Lewes¹«¹²¹¤³ÌίԱ»áÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬²¿Ãſͻ§ÐÅϢй¶¡£¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÐÅÓþ¿¨ÐÅÏ¢¡¢ÒøÐÐÕË»§¾ßÌåÐÅÏ¢¡¢Õ˺š¢Í´´¦ºÍµ½ÆÚÈÕÆÚ¡£¡£¡£ ¡£¡£¡£¸ÃίԱ»áÔÚ5ÔÂ28ÈÕ·¢ÏÖÁËÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢Á¢¿Ì¸ôÀëÁ˿ͻ§ÐÅϢϵͳºÍ֪ͨÓйØÈí¼þ¹©¸øÉÌ¡£¡£¡£ ¡£¡£¡£¸ÃÊÂÎñÔÚ½øÒ»²½µÄµ÷²éÖ®ÖÓ×£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/lewes-board-of-public-works-notifies-customers-of-potential-data-breach-b5f45004