Windows¼Çʱ¾´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Docker¾ºÕùǰÌá·ì϶£¬£¬£¬£¬£¬Ó°ÏìËùÓÐDocker°æ±¾£»£»£»£»£»£»£»£»DuckDuckGoÒ×ÊÜURLºýŪ¹¥»÷
°ä²¼¹¦·ò 2019-05-30
×êÑÐÈËÔ±Åû¶DockerÖÐ佨¸´µÄ¾ºÕùǰÌá·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËËùÓеÄDocker°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÀàËÆÓÚCVE-2018-15664£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ·¨Ê½¶Ô×ÊÔ´½øÐвÙ×÷֮ǰÅú¸Ä×ÊÔ´õè¾¶£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄÜ»ñµÃËÁÒâÎļþµÄ¶Áд½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄÖ÷ÌâÔ´ÓÚFollowSymlinkInScopeÖ°ÄÜÒ×ÊÜTOCTOU¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒѾ°ä²¼ÁËPoC´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/unpatched-flaw-affects-all-docker-versions-exploits-ready/2DuckDuckGoÒ×ÊÜURLºýŪ¹¥»÷£¬£¬£¬£¬£¬×°ÖÃÁ¿´ï500Íò´Î
°²È«×êÑÐÈËÔ±Dhiraj Mishra·¢ÏÖAndroid¿ªÔ´ä¯ÀÀÆ÷DuckDuckGo´æÔÚÒ»¸öURLºýŪ·ì϶£¨CVE-2019-12329£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ºýŪÓû§ÏàÐŽӼûµÄÊÇ¿ÉÐÅÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐíʹÓÃJavaScriptºýŪä¯ÀÀÆ÷µÄµØÖ·À¸£¬£¬£¬£¬£¬Í¨¹ýsetIntervalº¯Êýÿ10µ½50ºÁÃë³ÁмÓÔØÒ»¸öURL¡£¡£¡£¡£¡£¡£¡£¡£DuckDuckGo°²È«ÍŶÓÒÔΪ¸Ã·ì϶²»±ØÒª½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/duckduckgo-android-browser-vulnerable-to-url-spoofing-attacks/3¹È¸è×êÑÐÈËÔ±ÔÚWindows¼Çʱ¾Öз¢ÏÖ´úÂëÖ´Ðзì϶
Google Project Zero×êÑÐÔ±Tavis OrmandyÔÚ΢ÈíµÄWindows¼Çʱ¾Öз¢ÏÖÒ»¸ö´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬OrmandyÒÑÏò΢Èí»ã±¨Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£·ì϶µÄϸ½ÚÉÐδÅû¶£¬£¬£¬£¬£¬µ«OrmandyÔ¤¼Æ¸Ã·ì϶ÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬£¬£¬£¬£¬ËûÔÚTwitterÉÏ·ÖÏíµÄͼƬÑÝʾÁËÈôºÎÔÚ¼Çʱ¾Öе¯³öshell¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¹È¸èµÄ·ì϶Åû¶Õþ²ß£¬£¬£¬£¬£¬Ormandy½«ÔÚ90Ììºó»ò΢Èí°ä²¼½¨¸´²¹¶¡ºóÅû¶¸ü¶à·ì϶ϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/86297/hacking/code-execution-flaw-notepad.html4жñÒâÍڿ󺣳±Nansh0u£¬£¬£¬£¬£¬ÒÑϰȾ5Íǫ̀·þÎñÆ÷
ƾ¾ÝGuardicore LabsµÄ»ã±¨£¬£¬£¬£¬£¬Ò»¸öеĶñÒâÍÚ¿ó»î¶¯Nansh0uÒѾϰȾÁ˶à´ï5Íǫ̀·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍڿ󺣳±×Ô2ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬Êܺ¦Õß´óÎÞÊýλÓÚÖйú¡¢ÃÀ¹úºÍÓ¡¶È£¬£¬£¬£¬£¬¹²¸²¸ÇÁË90¸ö¹ú¶È¡£¡£¡£¡£¡£¡£¡£¡£Êܵ½¹¥»÷µÄÐÐÒµÔ̺¬Ò½ÁƱ£½¡¡¢µçÐÅ¡¢Ã½ÌåºÍITÁìÓò¡£¡£¡£¡£¡£¡£¡£¡£Êܵ½Ï°È¾ºó£¬£¬£¬£¬£¬¹¥»÷Õß»áÔÚÖ¸±ê·þÎñÆ÷ÉÏ×°ÖüÓÃܿ󹤺ÍÄÚºËģʽrootkit£¬£¬£¬£¬£¬ÒÔÍÚ¾ò¿ªÔ´¼ÓÃÜÇ®±ÒTurtleCoin¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ4Ô·ݣ¬£¬£¬£¬£¬×êÑÐÈËÔ±¹Û²ìµ½Èý´ÎÀàËÆµÄ¹¥»÷£¬£¬£¬£¬£¬ËùÓеÄÔ´IPµØÖ·¶¼À´×ÔÄÏ·Ç£¬£¬£¬£¬£¬ÇÒʹÓÃÒ»ÑùµÄ¹¥»÷¹ý³ÌºÍ¹¥»÷²½Öè¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/50k-servers-infected-with-cryptomining-malware-in-nansh0u-campaign/145140/5ÐÂÎ÷À¼²ÆÕþ²¿ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²ÆÕþÔ¤ËãÐÅϢй¶
ÔÎÄÁ´½Ó£º
https://cyware.com/news/new-zealand-treasury-hacked-and-budget-information-leaked-2fceb79b6Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¿Í»§ÐÅϢй¶
Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingµÄÀñÎï¿¨ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬µ¼Ö¿ͻ§Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Óû§ID¡¢¼ÓÃܵÄÃÜÂë¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍÀñÎ│¶©µ¥ºÅ£¬£¬£¬£¬£¬µ«²»Ô̺¬ÈκÎÒøÐп¨Ï¸½Ú»òÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ2019Äê5ÔÂ14ÈÕ£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÏòÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¼°Æä¿Í»§´«µÝÁËй¶ÊÂÎñ£¬£¬£¬£¬£¬Ä¿Ç°ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿Î´Öª¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uk-pub-chain-greene-king-suffers-data-breach-following-hack-on-its-gift-card-website-1aec5c69


¾©¹«Íø°²±¸11010802024551ºÅ