AndroidÏà»ú·ì϶¿É°ÂÃØÅÄÕÕ¼°Â¼ÔìÊÓÆµ£»£»£»£»£»°Ä´óÀûÑǰ䲼ÎïÁªÍø°²È«Êµ¼Ê×¼Ôò²Ý°¸
°ä²¼¹¦·ò 2019-11-20
CheckmarxµÄ×êÑÐÈËÔ±ÔÚAndroidÏà»úÀûÓÃÖз¢ÏÖÒ»¸öзì϶£¬£¬£¬£¬£¬£¬£¬£¬¼´APP¿ÉÔÚûÓÐȨÏÞµÄÇé¿öÏÂÅÄÕÕ¡¢Â¼ÔìÊÓÆµ»ò»ñÈ¡É豸µÄµØÎ»¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-2234£©Ï൱ΣÏÕ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÄܹ»Ê¹APPÔÚÊÖ»úËøÆÁµÄ״̬ϰÂÃØÅÄÕպͼÏñ£¬£¬£¬£¬£¬£¬£¬£¬Ò²Äܹ»´Ó´æ´¢µÄÕÕÆ¬ÖÐÌáÈ¡GPSµØÎ»Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬»¹Äܹ»½«ÕâЩÊý¾Ý·¢Ëͻع¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Æ¾¾ÝGoogleµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬£¬Ïà»úÀûÓÃÒÑÓÚ2019Äê7ÔÂͨ¹ýGoogle PlayÉ̵ê¸üн¨¸´ÁË´Ë·ì϶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/android-camera-app-bug-lets-apps-record-video-without-permission/2¡¢Adobe°ä·¢ÖÕÖ¹¶ÔAcrobatºÍReader 2015Ìṩ֧³Ö
AdobeÕýʽ°ä·¢ÖÕ³¡¶ÔAcrobat 2015ºÍReader 2015Ìṩ֧³Ö¡£¡£¡£¡£¡£´òËãÖеÄEOLÈÕÆÚÊÇ2020Äê4ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬µ½ÆÚºóÓû§Äܹ»³ÖÐøÊ¹ÓÃÕâÁ½¸öÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬µ«½«²»ÔÙÊÕµ½Èκθüлò·ì϶½¨¸´¡£¡£¡£¡£¡£Adobeʱʱ°ä²¼ÆäÈí¼þµÄ½¨²¹·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Flash¡¢Reader¡¢AcrobatµÈ£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇûÓÐÕâЩ¸üУ¬£¬£¬£¬£¬£¬£¬£¬Óû§µÄϵͳ¿ÉÄÜ»áÎî¶ÔÔâ·ê¹¥»÷µÄ·çÏÕ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÍƼöÓû§Éý¼¶µ½Adobe Acrobat DCºÍAdobe Acrobat Reader DCµÄ×îа汾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-announces-end-of-support-for-acrobat-reader-2015/3¡¢È«Çòµ±¾ÖÿÄêÒòDNS¹¥»÷¾ùÔÈËðʧ½ü700ÍòÃÀÔª
ƾ¾ÝEfficientIPµÄ×îÐÂ×êÑУ¬£¬£¬£¬£¬£¬£¬£¬È«Çòµ±¾ÖÿÄêÒòDNS¹¥»÷¾ùÔÈËðʧ½ü700ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬£¬ÊÇËùÓÐÐÐÒµ/²¿ÃÅÖÐËðʧ×î¶àµÄ¡£¡£¡£¡£¡£DNS°²È«³§ÉÌίÍÐIDC¶ÔÀ´×Ô±±ÃÀ¡¢Å·ÖÞºÍÑÇÌ«µØÓòµÄ½ü1000λITºÍ°²È«¸¨µ¼Õß½øÐе÷²é£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼ÙÔìÆä¡¶IDC 2019ÄêÈ«ÇòDNSÍþв»ã±¨¡·¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬ÊÀ½ç¸÷µØµÄ¹«¹²²¿ÃÅ×éÖ¯¾ùÔÈÿÄêÔâ·ê12´ÎDNS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ã¿´Î¾ùÔÈÔì³É³¬¹ý50ÍòÃÀÔªµÄËðʧ£¬£¬£¬£¬£¬£¬£¬£¬×ܼÆ670ÍòÃÀÔª¡£¡£¡£¡£¡£Í£»£»£»£»£»úºÍÊý¾Ý͵ÇÔËÆºõÊÇÔì³ÉÓйØËðʧµÄÖØÒªÔÒò¡£¡£¡£¡£¡£ºÚ¿Í½«DNSÁ÷Á¿ÓÃÓÚ¶àÖÖÖ÷ÕÅ£ºÓëÊÜϰȾÆóÒµ¿Í»§¶ËµÄC£¦CͨѶ¡¢³¢ÊÔ³Á¶¨Ïòµ½ÍøÂç´¹µöÕ¾µãÒÔ¼°Êý¾Ýй¶µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/governments-lose-millions-to-dns/4¡¢Ã·Î÷°Ù»õÔâMageCart¹¥»÷Óû§¸¶¿îÐÅÏ¢±»µÁ
÷Î÷°Ù»õ¹«Ë¾°ä·¢ÆäÍøÕ¾ÓÚ10ÔÂ7ÈÕ±»ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½áÕ˺ÍÎÒµÄÇ®°üÁ½¸öÒ³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬Óû§µÄ¸¶¿îÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ10ÔÂ15ÈÕɾ³ýÁËÍøÕ¾ÉϵĶñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÓû§ÔÚ´ËÆÚ¼äʹÓÃÁ˸ÃÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǵĸ¶¿îÐÅÏ¢¿ÉÄܱ»·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢³ÇÊÓ×¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢ÐÅÓþ¿¨ºÅ¡¢°²È«ÂëÒÔ¼°ÓÐЧÆÚ£¨ÔÂ/Ä꣩¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÆðÍ·ÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓþ±£»£»£»£»£»¤·þÎñ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/macys-customer-payment-info-stolen-in-magecart-data-breach/
5¡¢NVAÔâÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬400¼ÒÊÞÒ½ÕïËùÊܲ¨¼°
ÃÀ¹ú¹ú¶ÈÊÞҽлᣨNVA£©Ôâµ½ÀÕË÷Èí¼þRyukµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬È«¹ú400¼ÒÕïËùÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÔÚ10ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾Ò½ÁƼͼ¡¢Ö§¸¶ÏµÍ³ºÍÕïËùÖÎÀíÈí¼þ¶¼ÔÚ¹¥»÷Öб»·ÛË飬£¬£¬£¬£¬£¬£¬£¬ÆäÉ豸¿ÉÄܱØÒªÒ»ÖܵŦ·òÄÜÁ¦ÆëÈ«¸´ÔÕý³£ÔËÐÓ×£¡£¡£¡£¡£NVA CMOÀÍÀ¡¤¿ÆË¹ÌØ£¨Laura Koester£©Ö¤ÊµÁËÕâ´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ«»Ø¾øÐ¹Â©ÊÇ·ñÖ§¸¶ÁËÊê½ð¡£¡£¡£¡£¡£NVA¼¼ÊõÕÆ¹ÜÈ˸ñÀ׸ñ¡¤¹þÌØÂü£¨Greg Hartmann£©°µÊ¾ÕâÊÇÒ»´Î¹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£µ±Ç°ÈÔÓкܶàÕïËùµÄϵͳÎÞ·¨¸´Ô£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄ¼¼ÊõÍŶӽ«Ôڳﱸ³Á½¨·þÎñÆ÷µÄͬʱ³ÖÐøÔÚÿ¸öÊÜÓ°ÏìµÄÕïËùÖгÉÁ¢Ò»Ê±¹¤×÷Õ¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/400-vet-locations-ryuk-ransomware/150443/
6¡¢°Ä´óÀûÑǰ䲼ÎïÁªÍø°²È«Êµ¼Ê×¼Ôò²Ý°¸
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/australia-releases-draft-iot-cybersecurity-code-of-practice/


¾©¹«Íø°²±¸11010802024551ºÅ