HackerOneµÄÔ±¹¤ÇÔȡ©¶´³ÂËß²¢³öÊÛ¸øÊÜÓ°Ïì¿Í»§

Ðû²¼Ê±¼ä 2022-07-05

1¡¢HackerOneµÄÔ±¹¤ÇÔȡ©¶´³ÂËß²¢³öÊÛ¸øÊÜÓ°Ïì¿Í»§


¾ÝýÌå7ÔÂ2ÈÕ±¨µÀ£¬HackerOneµÄÒ»ÃûÔ±¹¤ÇÔÈ¡ÁËͨ¹ý©¶´Éͽðƽ̨Ìá½»µÄ©¶´³ÂËߣ¬²¢½«Æäй¶¸øÊÜÓ°ÏìµÄ¿Í»§ÒÔIJȡ¾­¼ÃÀûÒæ¡£¾­¹ýÊӲ죬¸ÃÔ±¹¤ÊÇΪÖÚ¶à¿Í»§ÏîÄ¿·ÖÀà©¶´Åû¶µÄÊÂÇéÈËÔ±Ö®Ò»£¬×Ô4ÔÂ4ÈÕÖÁ6ÔÂ23ÈÕÒÔÀ´·ÃÎÊÁË¸ÃÆ½Ì¨£¬ÒѾ­ÁªÏµÁË7¸ö¿Í»§¡£ËûʹÓÃÁËÃû³Æ"rzlr"£¬ÒÔ¼°ÍþвºÍ¿ÖÏÅÐÔµÄÓïÑÔÓë¿Í»§½»»¥£¬ÒÑÀÖ³ÉÊÕµ½Éͽð¡£6ÔÂ30ÈÕ£¬HackerOne½â¹ÍÁËÕâÃûÔ±¹¤¡£


https://www.bleepingcomputer.com/news/security/rogue-hackerone-employee-steals-bug-reports-to-sell-on-the-side/


2¡¢GoogleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ0 day


7ÔÂ4ÈÕ£¬GoogleÐû²¼ÎªWindowsÓû§Ðû²¼Chrome 103.0.5060.114£¬ÐÞ¸´ÁË2022ÄêChromeÖеĵÚ4¸ö0 day¡£¸Ã©¶´ÊÇWebRTC£¨WebʵʱͨÐÅ£©×é¼þÖлùÓڶѵĻº³åÇøÒç³ö©¶´£¨CVE-2022-2294£©£¬ÓÉAvastµÄÑо¿ÍŶÓÓÚ7ÔÂ1ÈÕÅû¶¡£Google͸¶¸Ã©¶´Òѱ»ÔÚÒ°ÀûÓ㬵«²¢Î´¹ûÈ»¹ØÓÚ¹¥»÷µÄ¼¼Êõϸ½ÚµÈÐÅÏ¢¡£´ËÍ⣬´Ë´Î¸üл¹ÐÞ¸´ÁËV8ÖеÄÀàÐÍ»ìÏý©¶´£¨CVE-2022-2295£©¡£


https://securityaffairs.co/wordpress/132863/hacking/4th-chrome-zero-day.html


3¡¢Ñо¿ÈËÔ±Åû¶Zoho²úÎïÖЩ¶´CVE-2022-28219µÄϸ½Ú


ýÌå7ÔÂ1ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±Åû¶ÁËZoho ManageEngine ADAudit Plus¹¤¾ßÖЩ¶´£¨CVE-2022-28219£©µÄ¼¼Êõϸ½ÚºÍ¿´·¨Ñé֤©¶´ÀûÓôúÂë¡£¸Ã©¶´CVSSÆÀ·ÖΪ9.8£¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃÀ´Ô¶³ÌÖ´ÐдúÂë²¢ÆÆ»µActive DirectoryÕÊ»§¡£¸Ã©¶´°üÂÞ3¸öÎÊÌ⣺²»ÊÜÐÅÈεÄJava·´ÐòÁл¯¡¢Â·¾¶±éÀúºÍäXMLÍⲿʵÌå(XXE)×¢Èë¡£ZohoÔÚ3Ôµ׵ÄADAudit Plus build 7060ÖÐÐÞ¸´ÁËÕâһ©¶´¡£


https://www.bleepingcomputer.com/news/security/zoho-manageengine-adaudit-plus-bug-gets-public-rce-exploit/


4¡¢ReversingLabsÐû²¼¹ØÓÚAstraLocker 2.0µÄ·ÖÎö³ÂËß


ýÌå7ÔÂ1Èճƣ¬ReversingLabsÐû²¼Á˹ØÓÚÀÕË÷Èí¼þAstraLocker 2.0µÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ËüÖ÷Òª½øÐпìËÙ¹¥»÷£¬¿ÉÖ±½Ó´Óµç×ÓÓʼþ¸½¼þÖÐͶ·Åpayload¡£¹¥»÷ÕßʹÓõÄÓÕ¶üÊÇWordÎĵµ£¬Òþ²ØÁË´øÓÐÀÕË÷Èí¼þpayloadµÄOLE ¹¤¾ß£¬Ç¶ÈëµÄ¿ÉÖ´ÐÐÎļþʹÓÃÎļþÃû¡°WordDocumentDOC.exe¡±£¬²¢Ê¹Óá°smash-n-grab¡±¼ÆÄ±¡£ÁíÒ»¸öÌØÊâÖ®´¦ÊÇʹÓÃÁËSafeEngine Shielder v2.4.0.0À´´ò°ü¿ÉÖ´ÐÐÎļþ£¬ÕâÊÇÒ»¸ö¹ýʱµÄ´ò°ü·¨Ê½£¬¼¸ºõ²»ÐÐÄܽøÐÐÄæÏò¹¤³Ì¡£


https://blog.malwarebytes.com/ransomware/2022/07/astralocker-2-0-ransomware-isnt-going-to-give-you-your-files-back/


5¡¢ÈÕ±¾Òƶ¯ÔËÓªÉÌKDDIÍ»·¢ÖжÏ£¬3915Íò¸öÓû§Í¨ÐÅÊÜ×è


ýÌå7ÔÂ3Èճƣ¬ÈÕ±¾Èý´óÒÆ¶¯ÔËÓªÉÌÖ®Ò»µÄKDDI Corp.Í»·¢ÖжÏ£¬¶à´ï3915Íò¸öÓû§µÄͨÐÅÊÜ×è¡£ÕⳡÖжÏʼÓÚÉÏÖÜÁùÁ賿1µã35·Ö×óÓÒ£¬Ó°ÏìÁ˰üÂÞÒøÐÐÒµÎñ¡¢ÌìÆøÊý¾Ý¡¢»õÔ˺Ͱü¹üµÝËÍϵͳÒÔ¼°ÁªÍøÆû³µ·þÎñÔÚÄڵĶà¸öÁìÓò¡£KDDIÌåÏÖ£¬ÆäÓïÒôºô½ÐϵͳµÄ¹ÊÕÏÒý·¢ÁËÁ÷Á¿¼¯ÖУ¬µ¼ÖÂͨÐÅÊÜÏÞ£¬KDDIÉ糤ÒѳöÍ·¾Ï¹ªÖÂǸ¡£½ØÖÁÉÏÖÜÈÕÉÏÎç11µã×óÓÒ£¬KDDIÎ÷ÈÕ±¾·þÎñÇøµÄÐÞ¸´ÊÂÇéÒѾ­Íê³É£¬ÈÕ±¾¶«²¿»Ö¸´·þÎñµÄÊÂÇéÓÚÖÜÈÕÍíÉϽáÊø¡£


https://www.japantimes.co.jp/news/2022/07/03/business/tech/kddi-au-system-outage/


6¡¢GoogleÖ¸³ö2022ÉϰëÄê±»ÀûÓõÄ©¶´ÖÐÒ»°ëÓë¾É©¶´ÓйØ


¾Ý7ÔÂ3ÈÕ±¨µÀ£¬Google Project ZeroÑо¿ÈËÔ±Ðû²¼Ò»·Ý³ÂËߣ¬³ÆÔÚ2022ÉϰëÄ꣬¹¥»÷ÖÐÀûÓõÄ©¶´ÖÐÖÁÉÙÓÐÒ»°ëÓëδÕýÈ·ÐÞ¸´µÄ¾É©¶´ÓйØ¡£³ÂËßÖ¸³ö£¬½ØÖÁ2022Äê6ÔÂ15ÈÕ£¬ÒѼì²âµ½18¸ö0 day±»Åû¶²¢ÔÚÒ°ÀûÓᣵ±·ÖÎöÕâЩ©¶´Ê±£¬·¢ÏÖÖÁÉÙ9¸öÊÇÏÈǰÐÞ¸´µÄ©¶´µÄ±äÖÖ¡£ÀýÈ磬×î½ü·¢ÏÖµÄWindows©¶´Follina£¨CVE-2022-30190£©£¬ÊÇMSHTMLÁãÈÕ©¶´£¨CVE-2021-40444£©µÄ±äÖÖ¡£


https://securityaffairs.co/wordpress/132813/security/h1-2022-zero-day-variants-previous-flaws.html