×êÑÐÈËÔ±Åû¶Android 13ºÍ14ÖеÄËøÆÁÈÆ¹ý·ì϶

°ä²¼¹¦·ò 2023-12-12
1¡¢×êÑÐÈËÔ±Åû¶Android 13ºÍ14ÖеÄËøÆÁÈÆ¹ý·ì϶


¾ÝýÌå12ÔÂ10ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚAndroid 13ºÍ14Öз¢ÏÖÁËÒ»¸öËøÆÁÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ»áй¶Óû§GoogleÕÊ»§ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¿ÉÄÜÎïÀí½Ó¼ûÉ豸µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶²é¿´ÕÕÆ¬¡¢ÁªÏµÈ˺Íä¯ÀÀº¹Çà¼Í¼µÈ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬·ì϶µÄÓ°ÏìˮƽÒòÓû§¶Ô¹È¸èµØÍ¼µÄ×°ÖúÍÅäÖöøÒ죬£¬£¬£¬£¬£¬£¬£¬ÈôÊǼ¤»îÁ˼Ýʻģʽ£¬£¬£¬£¬£¬£¬£¬£¬ÑϳÁˮƽ»áÏÔÖøÉý¼¶¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ5Ô·ÝÏòGoogle»ã±¨Á˸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬½ØÖÁ11Ôµ×ÈÔûÓа²È«¸üдòËã¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/155588/hacking/android-14-13-lock-screen-bypass.html


2¡¢·áÌï½ðÈÚ·þÎñ¹«Ë¾¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢±»¹«¿ª


¾Ý12ÔÂ11ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬·áÌï½ðÈÚ·þÎñ¹«Ë¾(TFS)¿Í»§µÄÓ×ÎҺͲÆÕþÊý¾ÝÒѱ»¹«¿ª¡£¡£¡£¡£¡£¡£¡£ÉϸöÔ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ôâµ½ÁËMedusaµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢±»ÀÕË÷800ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£Æäʱ£¬£¬£¬£¬£¬£¬£¬£¬·áÌï½²»°È˳ÆËûÃÇÔÚÅ·Ö޺ͷÇÖ޵IJ¿ÃÅϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬ÒѹعØÁËijЩϵͳÀ´¶ôÔì¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾Ý´§Ä¦£¬£¬£¬£¬£¬£¬£¬£¬·áÌïδÓë¹¥»÷ÕßЭÉÌÖ§¸¶Êê½ð£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Ëùº±¼û¾Ý¾ùÒÑÔÚMedusaµÄÍøÕ¾Éϰ䲼¡£¡£¡£¡£¡£¡£¡£µÂ¹úýÌåHeiseй©£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢¾ÓסµØÖ·¡¢ºÏͬÐÅÏ¢¡¢×⹺ÏêÇéºÍIBAN£¨¹ú¼ÊÒøÐÐÕʺţ©µÈ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/toyota-warns-customers-of-data-breach-exposing-personal-financial-info/


3¡¢Barcode to SheetÀûÓÃÅäÖÃÃýÎóй¶368MBµÄÊý¾Ý


ýÌå12ÔÂ8Èճƣ¬£¬£¬£¬£¬£¬£¬£¬AndroidÀûÓÃBarcode to SheetÅäÖÃÃýÎóй¶ÁËÓû§ÐÅÏ¢ºÍÆóÒµÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÌõÐÎÂëɨÃ蹤¾ß£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÃæÏòµç×ÓÉÌÎñ¿Í»§£¬£¬£¬£¬£¬£¬£¬£¬ÔÚGoogle PlayÉ̵êµÄÏÂÔØÁ¿³¬¹ý10Íò´Î¡£¡£¡£¡£¡£¡£¡£CybernewsÍŶӷ¢ÏÖÀûÓõĵÄFirebaseÊý¾Ý¿âÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬Ô̺¬³¬¹ý368MBÊý¾Ý¿É±»ËùÓÐÈ˽Ӽû¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âй¶ÁËÓйزúÆ·¡¢»ã±¨¡¢µç×ÓÓʼþºÍÓû§IDµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Web¿Í»§¶ËID¡¢Google APIÃÜÔ¿¡¢GoogleÀûÓ÷¨Ê½IDºÍ±ÀÀ£»ã±¨ÃÜÔ¿µÈ¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬¿ª·¢ÈËÔ¹ØýÔÚ×êÑнâ¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/155444/mobile-2/android-barcode-scanner-app-exposes-user-passwords.html


4¡¢SafeBreachÑÝʾ¿ÉÈÆ¹ýEDRµÄ¹ý³Ì×¢ÈëPool Party


°²È«¹«Ë¾SafeBreachÔÚ12ÔÂ6ÈÕ¹«¿ªÁËÒ»Ì×ÃûΪPool PartyµÄ¹ý³Ì×¢Èë¼¼Êõ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÈƹýEDR½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£ÕâÊÇ8ÖÖ¹ý³Ì×¢ÈëµÄ¼¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ²½Öè¿ÉÄܲ»ÊÜÈκÎÏ޶ȵؿçËùÓÐÁ÷³Ì¹¤×÷£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃËüÃDZÈÏÖÓеÄÁ÷³Ì×¢Èë¼¼ÊõÔ½·¢½Ã½Ý¡£¡£¡£¡£¡£¡£¡£PoolPartyÖ®ËùÒÔµÃÃû£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚËüÖ²¸ùÓÚÒ»¸öÃûΪWindowsÓû§Ä£Ê½Ï̳߳صÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃËüÄܹ»ÏòϵͳÖеÄÖ¸±ê¹ý³Ì²åÈëÈκÎÀàÐ͵Ť×÷Ïî¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÕë¶Ô5ÖÖÖØÒªµÄEDR½â¾ö¹æ»®½øÐвâÊÔʱ£¬£¬£¬£¬£¬£¬£¬£¬ËüÃÇÆëÈ«ÎÞ·¨±»¼ì²âµ½¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/12/new-poolparty-process-injection.html


5¡¢Elastic°ä²¼GuLoader×îз´·ÖÎö¼¼ÊõµÄ·ÖÎö»ã±¨


12ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Elastic Security Labs°ä²¼Á˹ØÓÚGuLoader×îз´·ÖÎö¼¼ÊõµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£GuLoaderÓÚ2019Äêµ×³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖ»ùÓÚshellcodeµÄ¶ñÒâÈí¼þÏÂÔØ·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ·Ö·¢¸÷Ààpayload¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»GuLoaderµÄÖ÷ÌâÖ°ÄÜÔÚ´Óǰ¼¸ÄêÖÐûÓвúÉú¾Þ´ó±ä¶¯£¬£¬£¬£¬£¬£¬£¬£¬µ«»ìºÏ¼¼ÊõµÄ²»ÐݸüÐÂʹµÃ·ÖÎöGuLoader³ÉΪһ¸ö·ÑÊÂÇÒºÄÁ¦µÄ¹ý³Ì¡£¡£¡£¡£¡£¡£¡£×î½üµÄ±ä¶¯Ö®Ò»ÊÇеĻÖÐÏòÆäʸÁ¿Òì³£´¦Ö÷¨Ê½£¨VEH£©Ôö³¤ÁËÒì³££¬£¬£¬£¬£¬£¬£¬£¬Ê¹·ÖÎö¸ü¾ßÌôÕ½ÐÔ¡£¡£¡£¡£¡£¡£¡£


https://www.elastic.co/security-labs/getting-gooey-with-guloader-downloader


6¡¢SecurityScorecard°ä²¼ÄÜÔ´ÐÐÒµÍøÂ簲ȫ·çÏջ㱨


12ÔÂ7ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬£¬SecurityScorecard°ä²¼ÁËÄÜÔ´ÐÐÒµµÚÈý·½ÍøÂ簲ȫ·çÏջ㱨¡£¡£¡£¡£¡£¡£¡£×îÐÂÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬´Óǰ12¸öÔÂÀ£¬£¬£¬£¬£¬£¬£¬È«Çò48¼Ò×î´óµÄÄÜÔ´¹«Ë¾ÏÕЩȫÊý(90%)Ôâµ½¹ý¹©¸øÁ´Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£½öÔÚ´Óǰ90ÌìÄÚ£¬£¬£¬£¬£¬£¬£¬£¬¾Í²úÉúÁË264ÆðÓëµÚÈý·½ÈëÇÖÓйصÄÎ¥¹æÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÃÀ¹úǰʮ´óÄÜÔ´¹«Ë¾ÔÚ´ÓǰһÄêÖж¼²úÉú¹ýµÚÈý·½¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£Ó¢¹úÄÜÔ´¹«Ë¾µÄ¾ùÔȰ²È«ÆÀ¼¶×î¸ß£¬£¬£¬£¬£¬£¬£¬£¬80%µÄ¹«Ë¾´ïµ½B»òÒÔÉÏÆÀ¼¶¡£¡£¡£¡£¡£¡£¡£MOVEitÊÇ´Óǰ6¸öÔÂÖÐ×îÆÕ±éµÄµÚÈý·½·ì϶¡£¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/ninety-percent-energy-companies/