MozillaÐû²¼FirefoxÇå¾²¸üÐÂÐÞ¸´í§Òâ´úÂëÖ´ÐÐÎó²î£»ºÚ¿ÍÈëÇÖÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬×ÌÈž¯·½Ô˶¯
Ðû²¼Ê±¼ä 2020-06-051.MozillaÐû²¼FirefoxÇå¾²¸üУ¬ÐÞ¸´¶à¸öí§Òâ´úÂëÖ´ÐÐÎó²î
MozillaΪFirefoxÐû²¼ÁËÇå¾²¸üУ¬ÐÞ¸´ÁË8¸öÇå¾²Îó²î¡£ÆäÖÐ3¸ö±»È·ÒÔΪí§Òâ´úÂëÖ´ÐÐÎó²î£¬°üÀ¨´¦Öóͷ£NativeTypesʱµÄJavaScriptÀàÐÍ»ìÏýÎó²î£¨CVE-2020-12406£©¼°ÄÚ´æËð»µÎó²î£¨CVE-2020-12410ºÍCVE-2020-12411£©¡£ÓÐÒ»¸öºÃÐÂÎÅÊÇ£¬Õâ3¸ö´úÂëÖ´ÐÐÎó²î¶¼ÊÇMozilla¿ª·¢Ö°Ô±ÔÚÄÚ²¿·¢Ã÷µÄ£¬²¢Î´ÔÚҰʹÓᣴ˴ÎÐÞ¸´µÄÆäËû½ÏΪÑÏÖØµÄÎó²îÊÇCVE-2020-12399£¬¸ÃÎó²îÔÚNSSÖ´ÐÐDSAÊðÃûʱÏÔʾʱÐò²î±ð¿Éµ¼ÖÂ˽Կй¶£¬ÒÔ¼°Îó²îCVE-2020-12405£¬±£´æSharedWorkService×é¼þÖеÄuse-after-free()ÖУ¬µ±Í¨¹ýwebÒ³ÃæÊ¹ÓÃʱ¿ÉÄܵ¼Ö¿ÉʹÓÃÍ߽⡣
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/06/04/firefox_77_security_fixes/
2.TalosÅû¶ZoomÖÐÁ½¸öÎó²î£¬¿É±»Ê¹ÓÃÖ´ÐжñÒâ´úÂë
˼¿ÆTalosµÄÑо¿Ö°Ô±Åû¶ÁËZoomÖеÄÁ½¸öÎó²î£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂÔ¶³Ì¹¥»÷Õßͨ¹ý̸Ì칦ЧÈëÇÖÊܺ¦ÕßµÄϵͳ¡£ÕâÁ½¸ö¾ùΪ·¾¶±éÀúÎó²î£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îдÈë»òÖ²Èëí§ÒâÎļþ£¬ÒÔÖ´ÐжñÒâ´úÂë¡£ÆäÖеÚÒ»¸öÎó²î±»¸ú×ÙΪCVE-2020-6109£¬ÓëZoom´¦Öóͷ£¶¯»GIFµÄ·½·¨Óйأ¬ZoomûÓмì²éGIFÔ´£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖÆµÄGIF¾ÙÐй¥»÷¡£µÚ¶þ¸öÎó²îÊDZ»¸ú×ÙΪCVE-2020-6110£¬¸ÃÎó²îλÓÚZoom´¦Öóͷ£°üÀ¨¹²Ïí´úÂë¶ÎÔÚÄÚµÄÐÂÎŵķ½·¨ÖС£ÕâÁ½¸öÎó²î¶¼Ó°ÏìÁËZoom 4.6.10°æ±¾£¬²¢ÇҸù«Ë¾ÔÚÆä4.6.12°æ±¾ÖÐÐÞ¸´ÁËËûÃÇ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/104249/hacking/zoom-security-flaws.html
3.±©¶¯Ê±´úºÚ¿ÍÈëÇÖÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬×ÌÈž¯·½Ô˶¯
ÃÀ¹úGeorge FloydÖ®ËÀÒý·¢µÄ±©¶¯Ê±´ú£¬ºÚ¿ÍÈëÇÖÁËÖ¥¼Ó¸ç¾¯¾ÖÓ¦¼±ÎÞÏßµçϵͳ£¬²¢¶Ô¾¯·½Ô˶¯¾ÙÐÐ×ÌÈÅ¡£ÉÏÖÜÄ©£¬ºÚ¿Í»ñµÃÁËÆäÎÞÏßµçϵÓõĻá¼ûȨ£¬²¢²¥·Å±©¶¯¿ÚºÅºÍÌåÏÖÃÀ¹úÖÖ×åÖ÷ÒåµÄ¸èÇú¡£Ö¥¼Ó¸ç¾¯¾ÖÓв¿·Ö¼ÓÃܵÄÎÞÏßµçÆµÂÊ£¬¿ÉÊÇ´ó´ó¶¼Ñ²Âß¾¯Ô±Ê¹ÓõÄÎÞÏßµçÕÕ¾ÉÒ×±»¹¥»÷µÄ¡£Õâµ¼ÖÂÁ˾¯Ô±ÔÚÖ´ÐÐʹÃüʱÎÞ·¨Ê¹ÓöԽ²»úÓëµ÷ÀíÔ±ÁªÏµ£¬»òÊÇ×·Çó×ÊÖú¡£¹«¹²Çå¾²ÐÅÏ¢ÊÖÒÕµÄDan CaseyÌåÏÖ£¬ÕâÑù×öºÜÊÇΣÏÕ¡£ÏÖÔÚ£¬µØ·½ºÍÁª°îÊÓ²ì¾ÖÒѾ¶Ô´ËÊÂÕö¿ªÊӲ졣
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/chicago-police-scanner-jammed-amid/
4.MazeÉù³ÆÒÑÀֳɹ¥»÷Conduent£¬ÇÔȡδ¼ÓÃܵÄÎļþ²¢¼ÓÃÜÆä×°±¸
MazeÀÕË÷Èí¼þÍÅ»ïÉù³ÆÒѾÀֳɹ¥»÷ÁËλÓÚÐÂÔóÎ÷ÖݵÄÉÌÒµ·þÎñ¹«Ë¾Conduent£¬ÇÔÈ¡ÁËδ¼ÓÃܵÄÎļþ²¢¼ÓÃÜÁËÆä×°±¸¡£5ÔÂ29ÈÕ£¬ConduentÐû²¼ÉùÃ÷È·ÈÏÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬´Ë´Î¹¥»÷µ¼ÖÂÆäÅ·ÖÞÓªÒµµÄ·þÎñÖÐÖ¹10Сʱ¡£MazeÓÚ6ÔÂ4ÈÕÔÚÆäÊý¾Ý×ßÂ©ÍøÕ¾Ðû²¼ÁËÐû²¼ÁË1GBÎļþÒÔ֤ʵÆäÔÚ2020Äê5µÄ¹¥»÷£¬Ð¹Â¶ÎļþΪBusinessIntelligence.zipºÍCompliance1.zip£¬°üÀ¨ÖݪֲÆÎñµç×Ó±í¸ñ¡¢¿Í»§É󼯡¢·¢Æ±¡¢Ó¶½ð¶ÔÕʵ¥ºÍÆäËûÔÓÏîÎĵµ¡£ÍþвÇ鱨¹«Ë¾Bad PacketsÌåÏÖ£¬ÔÚ2019Äê12ÔÂ17ÈÕÖÁ2020Äê2ÔÂ14ÈÕÖ®¼äµÄÖÁÉÙ°ËÖÜÄÚ£¬ConduentµÄ·þÎñÆ÷Citrix±£´æÎó²î£¨CVE-2019-19781£©£¬¸ÃÎó²î¿É±»Ê¹ÓÃÖ´ÐÐÔ¶³Ì´úÂë£¬Ôø±»ºÚ¿ÍʹÓÃÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/business-services-giant-conduent-hit-by-maze-ransomware/
5.2019ÄêºÚ¿Íй¶50ÒÚÌõÊý¾Ý£¬¸øÃÀ¹úÔì³É1.2ÍòÒÚÃÀÔªËðʧ
¾ÝForgeRockͳ¼ÆÊý¾Ý£¬ºÚ¿ÍÔÚ2019Äêй¶ÁËÁè¼Ý50ÒÚÌõ¼Í¼£¬¸øÃÀ¹ú×éÖ¯Ôì³ÉÁËÁè¼Ý1.2ÍòÒÚÃÀÔªµÄËðʧ¡£ÆäÖУ¬Ò½ÁƱ£½¡ÐÐÒµÊܵ½¹¥»÷´ÎÊý×î¶à£¬2019Äê×ܹ²±¨¸æÁË382Æðй¶ÊÂÎñ£¬ËðʧÁè¼Ý2.45ÒÚÃÀÔª¡£¶øÊÖÒÕ¹«Ë¾±»Ð¹Â¶Êý¾ÝµÄÊýÄ¿×î¶à£¬2019Äêй¶Áè¼Ý13.7ÒÚÌõÊý¾Ý£¬×ܼÆËðʧÁè¼Ý2500ÒÚÃÀÔª¡£Ð¡ÎÒ˽¼Òʶ±ðÐÅÏ¢(PII)ÈÔÈ»Êǹ¥»÷Õß×îÖ÷ÒªµÄÄ¿µÄÊý¾Ý£¬ÔÚ2019Äê98£¥µÄÊý¾ÝÊÂÎñÖÐ̻¶Á˸ÃÐÅÏ¢£¬ÆäÖÐÉç»áÇå¾²ºÅÂ루SSN£©ÊÇ×îÈÝÒ×Êܵ½¹¥»÷µÄÊý¾ÝÀàÐÍ¡£ForgeRockÊ×ϯÊÖÒÕ¹ÙEve MalerÌåÏÖ£¬ÍøÂç×ï·¸ÕýÔÚÒ»Ö±ÍêÉÆÆä¹¥»÷ǰÑÔ£¬ÒÔÇÔ×÷·ÏºÄÕßÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/06/04/cybercriminals-exposed-5-billion-records-in-2019/
6.ºÚ¿ÍÔÚ°µÍø³öÊÛÁè¼Ý10ÍòÓ¡¶È¹«ÃñÉí·ÝÖ¤£¬ÏÖÔÚȪԴδ֪
ÍøÂçÇ鱨¹«Ë¾Cyble±¾ÖÜÈýÌåÏÖ£¬ºÚ¿ÍÕýÔÚ°µÍø³öÊÛÁè¼Ý10ÍòÓ¡¶È¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢£¬°üÀ¨É¨ÃèµÄÉí·ÝÖ¤¸´Ó¡¼þ¡¢Aadhaar¡¢PAN¿¨ºÍ»¤ÕÕ¡£ÕâЩй¶µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÒÔµ¼ÖÂÖÖÖÖ¶ñÒâÔ˶¯£¬ÀýÈçÉí·Ý͵ÇÔ¡¢Õ©ÆºÍÆóÒµÌØ¹¤Ô˶¯¡£CybleÆðÔ´ÆÊÎöÅú×¢£¬ÕâЩÊý¾ÝËÆºõÀ´×ÔµÚÈý·½¹«Ë¾¶ø²»ÊÇÕþ¸®ÏµÍ³£¬ÏÖÔÚ£¬Ñо¿Ö°Ô±ÈÔÔڶԴ˾ÙÐнøÒ»³ÌÐò²é£¬ÒÔÈ·¶¨Ãü¾ÝµÄÏêϸȪԴ¡£
ÔÎÄÁ´½Ó£º
https://ciso.economictimes.indiatimes.com/news/over-1-lakh-national-ids-of-indians-put-on-dark-net-for-sale-cyber-intelligence-firm/76177587


¾©¹«Íø°²±¸11010802024551ºÅ