Oracle7Ô½¨¸´319¸ö·ì϶£»£»£»£»£»±£¼ÓÀûÑǹú¶È˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£»£»£»£»£»·Ç¹Ù·½°æTelegramÔ̺¬¶ñÒâ´úÂë

°ä²¼¹¦·ò 2019-07-17

1¡¢Oracle°ä²¼7Ô³ÁÒª²¹¶¡¸üУ¬£¬ £¬£¬£¬£¬£¬£¬½¨¸´319¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


OracleµÄ7Ô³ÁÒª²¹¶¡¸üÐÂÔ̺¬319¸ö·ì϶µÄ½¨¸´£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐOracleÊý¾Ý¿â½¨¸´ÁË9¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬Communications Applications½¨¸´ÁË24¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬E-Business Suite½¨¸´ÁË13¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬Financial Services Applications½¨¸´ÁË60¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬Fusion Middleware½¨¸´ÁË33¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬Java SE½¨¸´ÁË10¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬MySQL½¨¸´ÁË45¸ö·ì϶µÈ¡£¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬OracleÔÙ´ÎÇ¿µ÷ÁËÕë¶ÔWebLogic ServerµÄÁ½¸ö°²È«¾¯±¨£ºCVE-2019-2725£¨2019Äê4ÔÂ29ÈÕ£©ºÍCVE-2019-2729£¨2019Äê6ÔÂ18ÈÕ£©¡£¡£¡£¡£ ¡£¡£¡£¡£¾ßÌåÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html


2¡¢WordPress²å¼þAd Inserter RCE·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬Ó°Ïì20¶àÍò¸öÍøÕ¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


WordPress²å¼þAd Inserter½¨¸´Ò»¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðеķì϶¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã·ì϶ԴÓÚʹÓÃcheck_admin_referer£¨£©º¯Êý½øÐÐÊÚȨ£¬£¬ £¬£¬£¬£¬£¬£¬¸Ãº¯ÊýÓÃÓÚ±£»£»£»£»£»¤WordPressÕ¾µãÃâÊÜÀûÓÃnonceµÄCSRF¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ»ñÈ¡nonceºó£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýcheck_admin_referer£¨£©º¯ÊýµÄÊÚȨ²é³­£¬£¬ £¬£¬£¬£¬£¬£¬½Ó¼ûAd Inserter²å¼þÌṩµÄµ÷ÊÔģʽ£¬£¬ £¬£¬£¬£¬£¬£¬×îÖÕÖ´ÐÐËÁÒâPHP´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã²å¼þ±»×°ÖÃÔÚÖÁÉÙ20Íò¸öÍøÕ¾ÉÏ£¬£¬ £¬£¬£¬£¬£¬£¬½¨ÒéÍøÕ¾ÖÎÀíÔ±½«Æä¸üе½°æ±¾2.4.22¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/critical-bug-in-wordpress-plugin-lets-hackers-execute-code/


3¡¢Zoom RCE·ì϶»¹Ó°ÏìÊÓÆµ»áÒéÈí¼þRingCentralºÍZhumu


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±·¢ÏÖmacOS°æZoomÖеÄRCE·ì϶ҲӰÏìÁËÁí±íÁ½¸öÊ¢ÐеÄÊÓÆµ»áÒéÈí¼þRingCentralºÍZhumu¡£¡£¡£¡£ ¡£¡£¡£¡£ÆäÖÐRingCentral±»³¬¹ý35Íò¼ÒÆóҵʹÓ㬣¬ £¬£¬£¬£¬£¬£¬¿ª·¢ÍŶÓÒѾ­°ä²¼ÁËа汾v7.0.151508.0712£¬£¬ £¬£¬£¬£¬£¬£¬Í¨¹ýɾ³ýÒ×Êܹ¥»÷µÄWeb·þÎñÆ÷À´½¨²¹¸Ã·ì϶¡£¡£¡£¡£ ¡£¡£¡£¡£ZhumuÉÐδ°ä²¼½¨¸´²¹¶¡£¡£¡£¡£ ¡£¡£¡£¡£¬£¬ £¬£¬£¬£¬£¬£¬µ«Óû§ÒÀÈ»Äܹ»Í¨¹ýÒ»ÑùµÄºÅÁîÐ¶ÔØ¸Ã·þÎñÆ÷¡£¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬°²È«×êÑÐÔ±Karan»¹·¢ÏÖÁí±í8¿îÈí¼þÒ²ÊÜÓ°Ï죬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬Telus Meetings¡¢BT Cloud Phone Meetings¡¢Office Suite HD Meeting¡¢AT&T Video Meetings¡¢BizConf¡¢Huihui¡¢UMeetingºÍZoom CN¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/zoom-ringcentral-vulnerabilities.html


4¡¢±£¼ÓÀûÑǹú¶È˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾Ýzdnet±¨Â·£¬£¬ £¬£¬£¬£¬£¬£¬Ò»ºÚ¿Í×éÖ¯´Ó±£¼ÓÀûÑǹú¶È˰Îñ¾Ö£¨NRA£©ÖÐÇÔÈ¡ÁËÔ¼110¸öÊý¾Ý¿â£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬½ü21GBµÄÓ×ÎÒÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÈËÊý³¬¹ý500Íò¡£¡£¡£¡£ ¡£¡£¡£¡£ºÚ¿Í½«²¿Ãű»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþ·¢Ë͸ø±¾µØÃ½Ì壬£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÊÂÎñÆØ¹â¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹úÓйز¿ÃÅÒѾ­ÈÏ¿ÉÕâÒ»ÊÂÎñ£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÕýÓë±£¼ÓÀûÑǹú¶È°²È«¾ÖºÏ×÷µ÷²é¡£¡£¡£¡£ ¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬±£¼ÓÀûÑǹ«ÃñµÄÓ×ÎÒ¼ø±ðÂ루PIN£©¡¢ÐÕÃû¡¢¼ÒͥסַºÍ²ÆÕþÊÕÈ룬£¬ £¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý×îÔç¿É×·Òäµ½2007Äê¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9


5¡¢·Ç¹Ù·½°æTelegramÔ̺¬¶ñÒâ´úÂ룬£¬ £¬£¬£¬£¬£¬£¬ÏÂÔØÁ¿³¬10Íò´Î


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±ÔÚGoogle PlayÖз¢ÏÖ¶ñÒâÀûÓÃMobonoGram 2019£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃAPPÊÇÒ»¸ö·Ç¹Ù·½°æTelegram£¬£¬ £¬£¬£¬£¬£¬£¬ËüʹÓùٷ½TelegramµÄ´úÂë²¢Ôö³¤Á˶ñÒâ¾ç±¾ÒÔʵÏÖÓÆ¾ÃÐÔ²¢¼ÓÔØ´ÓC&C½Ó¹ÜµÄURL¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¶ñÒâAPPµÄÏÂÔØÁ¿³¬¹ý10Íò´Î£¬£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÌṩӢÓïºÍ²¨Ë¹Óï°æ±¾¡£¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃAPPµÄ¿ª·¢Õß»¹°ä²¼ÁËÁíÒ»¸öÃûΪWhatsgramµÄÓµÓÐÒ»ÑùÐÐΪµÄ¶ñÒâAPP¡£¡£¡£¡£ ¡£¡£¡£¡£Æ¾¾ÝÈüÃÅÌú¿ËµÄÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚ1ÔÂÖÁ5ÔÂÆÚ¼ä¸Ã¶ñÒâAPPÓÐ1235¸ö¼ì²âÁ˾֣¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃÅλÓÚÃÀ¹ú¡¢ÒÁÀÊ¡¢Ó¡¶ÈºÍ°¢ÁªÇõ¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/unofficial-telegram-app-with-100k-installs-pushed-malicious-sites/


6¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃiOS URL SchemeÖ´ÐÐMITM¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±ÑÝʾÁËÒ»ÖÖеÄAPP-in-the-middle¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬ËüÄܹ»ÔÊÐí×°ÖÃÔÚiOSÉ豸ÉϵĶñÒâAPPÀûÓÃ×Ô½ç˵URL SchemeÇÔÈ¡ÆäËüAPPÖеÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£¡£Ä¬ÈÏÇé¿öÏÂiOSµÄÿ¸öAPP¶¼ÔÚ×Ô¼ºµÄɳÏäÖÐÔËÐУ¬£¬ £¬£¬£¬£¬£¬£¬µ«URL SchemeÔÊÐíÓû§Í¨¹ýURLÆô¶¯ÆäËüAPP£¬£¬ £¬£¬£¬£¬£¬£¬ÓÉÓÚAppleûÓÐÃ÷È·½ç˵ÄĸöÀûÓÃÄܹ»Ê¹ÓÃÄÄЩ¹Ø¼ü×Ö×÷ΪÆä×Ô½ç˵URL Scheme£¬£¬ £¬£¬£¬£¬£¬£¬Òò¶ø¶à¸öAPP¿ÉÄÜʹÓÃÒ»ÑùµÄURL Scheme£¬£¬ £¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÃô¸ÐÊý¾Ý±»´«µÝµ½ÁíÒ»¸ö¶ñÒâAPPÖС£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/ios-custom-url-scheme.html