Ñо¿Ö°Ô±Åû¶Android 13ºÍ14ÖеÄËøÆÁÈÆ¹ýÎó²î

Ðû²¼Ê±¼ä 2023-12-12
1¡¢Ñо¿Ö°Ô±Åû¶Android 13ºÍ14ÖеÄËøÆÁÈÆ¹ýÎó²î


¾ÝýÌå12ÔÂ10ÈÕ±¨µÀ£¬ £¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±ÔÚAndroid 13ºÍ14Öз¢Ã÷ÁËÒ»¸öËøÆÁÈÆ¹ýÎó²î£¬ £¬£¬£¬£¬ £¬£¬£¬¿ÉÄÜ»áй¶Óû§GoogleÕÊ»§ÖеÄÊý¾Ý¡£¡£¡£¡£ ¡£Äܹ»ÎïÆÊÎö¼û×°±¸µÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÉó²éÕÕÆ¬¡¢ÁªÏµÈ˺Íä¯ÀÀÀúÊ·¼Í¼µÈ¡£¡£¡£¡£ ¡£±ðµÄ£¬ £¬£¬£¬£¬ £¬£¬£¬Îó²îµÄÓ°ÏìˮƽÒòÓû§¶Ô¹È¸èµØÍ¼µÄ×°ÖúÍÉèÖöøÒ죬 £¬£¬£¬£¬ £¬£¬£¬ÈôÊǼ¤»îÁ˼Ýʻģʽ£¬ £¬£¬£¬£¬ £¬£¬£¬ÑÏÖØË®Æ½»áÏÔ×ÅÉý¼¶¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±ÓÚ5Ô·ÝÏòGoogle±¨¸æÁ˸ÃÎÊÌ⣬ £¬£¬£¬£¬ £¬£¬£¬×èÖ¹11ÔÂβÈÔûÓÐÇå¾²¸üÐÂÍýÏë¡£¡£¡£¡£ ¡£


https://securityaffairs.com/155588/hacking/android-14-13-lock-screen-bypass.html


2¡¢·áÌï½ðÈÚЧÀ͹«Ë¾¿Í»§µÄСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢±»¹ûÕæ


¾Ý12ÔÂ11ÈÕ±¨µÀ£¬ £¬£¬£¬£¬ £¬£¬£¬·áÌï½ðÈÚЧÀ͹«Ë¾(TFS)¿Í»§µÄСÎÒ˽¼ÒºÍ²ÆÎñÊý¾ÝÒѱ»¹ûÕæ¡£¡£¡£¡£ ¡£ÉϸöÔ£¬ £¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾Ôâµ½ÁËMedusaµÄ¹¥»÷£¬ £¬£¬£¬£¬ £¬£¬£¬²¢±»ÀÕË÷800ÍòÃÀÔª¡£¡£¡£¡£ ¡£Æäʱ£¬ £¬£¬£¬£¬ £¬£¬£¬·áÌï½²»°È˳ÆËûÃÇÔÚÅ·Ö޺ͷÇÖ޵IJ¿·ÖϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ»á¼û£¬ £¬£¬£¬£¬ £¬£¬£¬ÒѹرÕÁËijЩϵͳÀ´×èÖ¹¹¥»÷¡£¡£¡£¡£ ¡£¾ÝÍÆ²â£¬ £¬£¬£¬£¬ £¬£¬£¬·áÌïδÓë¹¥»÷ÕßЭÉÌÖ§¸¶Êê½ð£¬ £¬£¬£¬£¬ £¬£¬£¬ÏÖÔÚËùÓÐÊý¾Ý¾ùÒÑÔÚMedusaµÄÍøÕ¾ÉÏÐû²¼¡£¡£¡£¡£ ¡£µÂ¹úýÌåHeise͸¶£¬ £¬£¬£¬£¬ £¬£¬£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÆÜÉíµØµã¡¢ÌõÔ¼ÐÅÏ¢¡¢×⹺ÏêÇéºÍIBAN£¨¹ú¼ÊÒøÐÐÕʺţ©µÈ¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/toyota-warns-customers-of-data-breach-exposing-personal-financial-info/


3¡¢Barcode to SheetÓ¦ÓÃÉèÖùýʧй¶368MBµÄÊý¾Ý


ýÌå12ÔÂ8Èճƣ¬ £¬£¬£¬£¬ £¬£¬£¬AndroidÓ¦ÓÃBarcode to SheetÉèÖùýʧй¶ÁËÓû§ÐÅÏ¢ºÍÆóÒµÊý¾Ý¡£¡£¡£¡£ ¡£ÕâÊÇÒ»¸öÌõÐÎÂëɨÃ蹤¾ß£¬ £¬£¬£¬£¬ £¬£¬£¬Ö÷ÒªÃæÏòµç×ÓÉÌÎñ¿Í»§£¬ £¬£¬£¬£¬ £¬£¬£¬ÔÚGoogle PlayÊÐËÁµÄÏÂÔØÁ¿Áè¼Ý10Íò´Î¡£¡£¡£¡£ ¡£CybernewsÍŶӷ¢Ã÷Ó¦ÓõĵÄFirebaseÊý¾Ý¿âÉèÖùýʧ£¬ £¬£¬£¬£¬ £¬£¬£¬°üÀ¨Áè¼Ý368MBÊý¾Ý¿É±»ËùÓÐÈË»á¼û¡£¡£¡£¡£ ¡£Êý¾Ý¿âй¶ÁËÓйزúÆ·¡¢±¨¸æ¡¢µç×ÓÓʼþºÍÓû§IDµÄÐÅÏ¢£¬ £¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°Web¿Í»§¶ËID¡¢Google APIÃÜÔ¿¡¢GoogleÓ¦ÓóÌÐòIDºÍÍ߽ⱨ¸æÃÜÔ¿µÈ¡£¡£¡£¡£ ¡£¾ÝϤ£¬ £¬£¬£¬£¬ £¬£¬£¬¿ª·¢Ö°Ô±ÕýÔÚÑо¿½â¾ö¼Æ»®¡£¡£¡£¡£ ¡£


https://securityaffairs.com/155444/mobile-2/android-barcode-scanner-app-exposes-user-passwords.html


4¡¢SafeBreachÑÝʾ¿ÉÈÆ¹ýEDRµÄÀú³Ì×¢ÈëPool Party


Çå¾²¹«Ë¾SafeBreachÔÚ12ÔÂ6ÈÕ¹ûÕæÁËÒ»Ì×ÃûΪPool PartyµÄÀú³Ì×¢ÈëÊÖÒÕ£¬ £¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔÈÆ¹ýEDR½â¾ö¼Æ»®¡£¡£¡£¡£ ¡£ÕâÊÇ8ÖÖÀú³Ì×¢ÈëµÄÜöÝÍ£¬ £¬£¬£¬£¬ £¬£¬£¬ÕâЩҪÁìÄܹ»²»ÊÜÈκÎÏÞÖÆµØ¿çËùÓÐÁ÷³ÌÊÂÇ飬 £¬£¬£¬£¬ £¬£¬£¬Ê¹µÃËüÃDZÈÏÖÓеÄÁ÷³Ì×¢ÈëÊÖÒÕÔ½·¢ÎÞа¡£¡£¡£¡£ ¡£PoolPartyÖ®ÒÔÊǵÃÃû£¬ £¬£¬£¬£¬ £¬£¬£¬ÊÇÓÉÓÚËüÖ²¸ùÓÚÒ»¸öÃûΪWindowsÓû§Ä£Ê½Ï̳߳صÄ×é¼þ£¬ £¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃËü¿ÉÒÔÏòϵͳÖеÄÄ¿µÄÀú³Ì²åÈëÈκÎÀàÐ͵ÄÊÂÇéÏî¡£¡£¡£¡£ ¡£±ðµÄ£¬ £¬£¬£¬£¬ £¬£¬£¬ÔÚÕë¶Ô5ÖÖÖ÷ÒªµÄEDR½â¾ö¼Æ»®¾ÙÐвâÊÔʱ£¬ £¬£¬£¬£¬ £¬£¬£¬ËüÃÇÍêÈ«ÎÞ·¨±»¼ì²âµ½¡£¡£¡£¡£ ¡£


https://thehackernews.com/2023/12/new-poolparty-process-injection.html


5¡¢ElasticÐû²¼GuLoader×îз´ÆÊÎöÊÖÒյįÊÎö±¨¸æ


12ÔÂ6ÈÕ£¬ £¬£¬£¬£¬ £¬£¬£¬Elastic Security LabsÐû²¼Á˹ØÓÚGuLoader×îз´ÆÊÎöÊÖÒյįÊÎö±¨¸æ¡£¡£¡£¡£ ¡£GuLoaderÓÚ2019Äêµ×Ê״α»·¢Ã÷£¬ £¬£¬£¬£¬ £¬£¬£¬ÊÇÒ»ÖÖ»ùÓÚshellcodeµÄ¶ñÒâÈí¼þÏÂÔØ³ÌÐò£¬ £¬£¬£¬£¬ £¬£¬£¬ÓÃÓÚ·Ö·¢ÖÖÖÖpayload¡£¡£¡£¡£ ¡£ËäÈ»GuLoaderµÄ½¹µã¹¦Ð§ÔÚÒÑÍù¼¸ÄêÖÐûÓб¬·¢ÖØ´óת±ä£¬ £¬£¬£¬£¬ £¬£¬£¬µ«»ìÏýÊÖÒÕµÄÒ»Ö±¸üÐÂʹµÃÆÊÎöGuLoader³ÉΪһ¸ö·ÑÊÂÇÒºÄÁ¦µÄÀú³Ì¡£¡£¡£¡£ ¡£×î½üµÄת±äÖ®Ò»ÊÇеĻÖÐÏòÆäʸÁ¿Òì³£´¦Öóͷ£³ÌÐò£¨VEH£©Ìí¼ÓÁËÒì³££¬ £¬£¬£¬£¬ £¬£¬£¬Ê¹ÆÊÎö¸ü¾ßÌôÕ½ÐÔ¡£¡£¡£¡£ ¡£


https://www.elastic.co/security-labs/getting-gooey-with-guloader-downloader


6¡¢SecurityScorecardÐû²¼ÄÜÔ´ÐÐÒµÍøÂçÇ徲Σº¦±¨¸æ


12ÔÂ7ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬ £¬£¬£¬SecurityScorecardÐû²¼ÁËÄÜÔ´ÐÐÒµµÚÈý·½ÍøÂçÇ徲Σº¦±¨¸æ¡£¡£¡£¡£ ¡£×îÐÂÊý¾ÝÏÔʾ£¬ £¬£¬£¬£¬ £¬£¬£¬ÒÑÍù12¸öÔÂÀ £¬£¬£¬£¬ £¬£¬£¬È«Çò48¼Ò×î´óµÄÄÜÔ´¹«Ë¾ÏÕЩËùÓÐ(90%)Ôâµ½¹ý¹©Ó¦Á´Êý¾Ýй¶¡£¡£¡£¡£ ¡£½öÔÚÒÑÍù90ÌìÄÚ£¬ £¬£¬£¬£¬ £¬£¬£¬¾Í±¬·¢ÁË264ÆðÓëµÚÈý·½ÈëÇÖÓйصÄÎ¥¹æÊÂÎñ¡£¡£¡£¡£ ¡£ÃÀ¹úǰʮ´óÄÜÔ´¹«Ë¾ÔÚÒÑÍùÒ»ÄêÖж¼±¬·¢¹ýµÚÈý·½¹¥»÷ÊÂÎñ¡£¡£¡£¡£ ¡£Ó¢¹úÄÜÔ´¹«Ë¾µÄƽ¾ùÇå¾²ÆÀ¼¶×î¸ß£¬ £¬£¬£¬£¬ £¬£¬£¬80%µÄ¹«Ë¾µÖ´ïB»òÒÔÉÏÆÀ¼¶¡£¡£¡£¡£ ¡£MOVEitÊÇÒÑÍù6¸öÔÂÖÐ×îÆÕ±éµÄµÚÈý·½Îó²î¡£¡£¡£¡£ ¡£


https://www.infosecurity-magazine.com/news/ninety-percent-energy-companies/