Windows¼Çʱ¾´úÂëÖ´ÐÐÎó²î£»£»£»Docker¾ºÕùÌõ¼þÎó²î£¬£¬£¬Ó°ÏìËùÓÐDocker°æ±¾£»£»£»DuckDuckGoÒ×ÊÜURLÓÕÆ¹¥»÷
Ðû²¼Ê±¼ä 2019-05-30
Ñо¿Ö°Ô±Åû¶DockerÖÐδÐÞ¸´µÄ¾ºÕùÌõ¼þÎó²î£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËËùÓеÄDocker°æ±¾¡£¡£¡£¡£¡£¸ÃÎó²îÀàËÆÓÚCVE-2018-15664£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ³ÌÐò¶Ô×ÊÔ´¾ÙÐвÙ×÷֮ǰÐÞ¸Ä×ÊԴ·¾¶£¬£¬£¬´Ó¶ø¿ÉÄÜ»ñµÃí§ÒâÎļþµÄ¶Áд»á¼ûȨÏÞ£¬£¬£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¡£¡£¡£¡£¸ÃÎó²îµÄ½¹µãÔ´ÓÚFollowSymlinkInScope¹¦Ð§Ò×ÊÜTOCTOU¹¥»÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒѾÐû²¼ÁËPoC´úÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/unpatched-flaw-affects-all-docker-versions-exploits-ready/2DuckDuckGoÒ×ÊÜURLÓÕÆ¹¥»÷£¬£¬£¬×°ÖÃÁ¿´ï500Íò´Î
Çå¾²Ñо¿Ö°Ô±Dhiraj Mishra·¢Ã÷Android¿ªÔ´ä¯ÀÀÆ÷DuckDuckGo±£´æÒ»¸öURLÓÕÆÎó²î£¨CVE-2019-12329£©£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÓÕÆÓû§ÏàÐÅ»á¼ûµÄÊÇ¿ÉÐÅÍøÕ¾¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíʹÓÃJavaScriptÓÕÆä¯ÀÀÆ÷µÄµØµãÀ¸£¬£¬£¬Í¨¹ýsetIntervalº¯Êýÿ10µ½50ºÁÃëÖØÐ¼ÓÔØÒ»¸öURL¡£¡£¡£¡£¡£DuckDuckGoÇå¾²ÍŶÓÒÔΪ¸ÃÎó²î²»ÐèÒªÐÞ¸´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/duckduckgo-android-browser-vulnerable-to-url-spoofing-attacks/3¹È¸èÑо¿Ö°Ô±ÔÚWindows¼Çʱ¾Öз¢Ã÷´úÂëÖ´ÐÐÎó²î
Google Project ZeroÑо¿Ô±Tavis OrmandyÔÚ΢ÈíµÄWindows¼Çʱ¾Öз¢Ã÷Ò»¸ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬OrmandyÒÑÏò΢Èí±¨¸æÁ˸ÃÎÊÌâ¡£¡£¡£¡£¡£Îó²îµÄϸ½ÚÉÐδÅû¶£¬£¬£¬µ«OrmandyÔ¤¼Æ¸ÃÎó²îÊÇÒ»¸öÄÚ´æËð»µÎó²î£¬£¬£¬ËûÔÚTwitterÉÏ·ÖÏíµÄͼƬÑÝʾÁËÔõÑùÔÚ¼Çʱ¾Öе¯³öshell¡£¡£¡£¡£¡£Æ¾Ö¤¹È¸èµÄÎó²îÅû¶Õþ²ß£¬£¬£¬Ormandy½«ÔÚ90Ììºó»ò΢ÈíÐû²¼ÐÞ¸´²¹¶¡ºóÅû¶¸ü¶àÎó²îϸ½Ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/86297/hacking/code-execution-flaw-notepad.html4жñÒâÍÚ¿óÀ˳±Nansh0u£¬£¬£¬ÒÑѬȾ5Íǫ̀ЧÀÍÆ÷
ƾ֤Guardicore LabsµÄ±¨¸æ£¬£¬£¬Ò»¸öеĶñÒâÍÚ¿ó»î¶¯Nansh0uÒѾѬȾÁ˶à´ï5Íǫ̀ЧÀÍÆ÷¡£¡£¡£¡£¡£¸ÃÍÚ¿óÀ˳±×Ô2ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬Êܺ¦Õß´ó´ó¶¼Î»ÓÚÖйú¡¢ÃÀ¹úºÍÓ¡¶È£¬£¬£¬¹²ÁýÕÖÁË90¸ö¹ú¼Ò¡£¡£¡£¡£¡£Êܵ½¹¥»÷µÄÐÐÒµ°üÀ¨Ò½ÁƱ£½¡¡¢µçÐÅ¡¢Ã½ÌåºÍITÁìÓò¡£¡£¡£¡£¡£Êܵ½Ñ¬È¾ºó£¬£¬£¬¹¥»÷Õß»áÔÚÄ¿µÄЧÀÍÆ÷ÉÏ×°ÖüÓÃܿ󹤺ÍÄÚºËģʽrootkit£¬£¬£¬ÒÔÍÚ¾ò¿ªÔ´¼ÓÃÜÇ®±ÒTurtleCoin¡£¡£¡£¡£¡£ÔÚ4Ô·ݣ¬£¬£¬Ñо¿Ö°Ô±ÊӲ쵽Èý´ÎÀàËÆµÄ¹¥»÷£¬£¬£¬ËùÓеÄÔ´IPµØµã¶¼À´×ÔÄÏ·Ç£¬£¬£¬ÇÒʹÓÃÏàͬµÄ¹¥»÷Àú³ÌºÍ¹¥»÷ÒªÁì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/50k-servers-infected-with-cryptomining-malware-in-nansh0u-campaign/145140/5ÐÂÎ÷À¼²ÆÎñ²¿ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²ÆÎñÔ¤ËãÐÅϢй¶
ÔÎÄÁ´½Ó£º
https://cyware.com/news/new-zealand-treasury-hacked-and-budget-information-leaked-2fceb79b6Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¿Í»§ÐÅϢй¶
Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingµÄÀñÎï¿¨ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬µ¼Ö¿ͻ§Êý¾Ýй¶¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢Óû§ID¡¢¼ÓÃܵÄÃÜÂë¡¢µØµã¡¢ÓÊÕþ±àÂëºÍÀñÎ│¶©µ¥ºÅ£¬£¬£¬µ«²»°üÀ¨ÈκÎÒøÐп¨Ï¸½Ú»òÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ2019Äê5ÔÂ14ÈÕ£¬£¬£¬¸Ã¹«Ë¾ÒÑÏòÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¼°Æä¿Í»§×ª´ïÁËй¶ÊÂÎñ£¬£¬£¬ÏÖÔÚÊÜÓ°ÏìµÄ¿Í»§ÊýĿδ֪¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uk-pub-chain-greene-king-suffers-data-breach-following-hack-on-its-gift-card-website-1aec5c69


¾©¹«Íø°²±¸11010802024551ºÅ