Ñо¿ÈËÔ±Åû¶Android 13ºÍ14ÖеÄËøÆÁÈƹý©¶´

Ðû²¼Ê±¼ä 2023-12-12
1¡¢Ñо¿ÈËÔ±Åû¶Android 13ºÍ14ÖеÄËøÆÁÈƹý©¶´


¾ÝýÌå12ÔÂ10ÈÕ±¨µÀ £¬Ñо¿ÈËÔ±ÔÚAndroid 13ºÍ14Öз¢ÏÖÁËÒ»¸öËøÆÁÈƹý©¶´ £¬¿ÉÄÜ»áй¶Óû§GoogleÕÊ»§ÖеÄÊý¾Ý¡£Äܹ»ÎïÀí·ÃÎÊÉ豸µÄ¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´¼ì²ìÕÕƬ¡¢ÁªÏµÈ˺Íä¯ÀÀÀúÊ·¼Ç¼µÈ¡£´ËÍâ £¬Â©¶´µÄÓ°ÏìˮƽÒòÓû§¶Ô¹È¸èµØͼµÄ°²×°ºÍÅäÖöøÒì £¬Èç¹û¼¤»îÁ˼Ýʻģʽ £¬ÑÏÖØˮƽ»áÃ÷ÏÔÉý¼¶¡£Ñо¿ÈËÔ±ÓÚ5Ô·ÝÏòGoogle³ÂËßÁ˸ÃÎÊÌâ £¬½ØÖÁ11Ôµ×ÈÔûÓÐÄþ¾²¸üмƻ®¡£


https://securityaffairs.com/155588/hacking/android-14-13-lock-screen-bypass.html


2¡¢·áÌï½ðÈÚ·þÎñ¹«Ë¾¿Í»§µÄ¸öÈ˺ͲÆÕþÐÅÏ¢±»¹ûÈ»


¾Ý12ÔÂ11ÈÕ±¨µÀ £¬·áÌï½ðÈÚ·þÎñ¹«Ë¾(TFS)¿Í»§µÄ¸öÈ˺ͲÆÕþÊý¾ÝÒѱ»¹ûÈ»¡£ÉϸöÔ £¬¸Ã¹«Ë¾Ôâµ½ÁËMedusaµÄ¹¥»÷ £¬²¢±»ÀÕË÷800ÍòÃÀÔª¡£Æäʱ £¬·áÌï·¢ÑÔÈ˳ÆËûÃÇÔÚÅ·Ö޺ͷÇÖ޵IJ¿ÃÅϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ·ÃÎÊ £¬ÒѹرÕÁËijЩϵͳÀ´Í£Ö¹¹¥»÷¡£¾ÝÍƲâ £¬·áÌïδÓë¹¥»÷ÕßЭÉÌÖ§¸¶Êê½ð £¬Ä¿Ç°ËùÓÐÊý¾Ý¾ùÒÑÔÚMedusaµÄÍøÕ¾ÉÏÐû²¼¡£µÂ¹úýÌåHeise͸¶ £¬Ð¹Â¶ÐÅÏ¢°üÂÞÐÕÃû¡¢¾ÓסµØÖ·¡¢ºÏͬÐÅÏ¢¡¢×⹺ÏêÇéºÍIBAN£¨¹ú¼ÊÒøÐÐÕʺţ©µÈ¡£


https://www.bleepingcomputer.com/news/security/toyota-warns-customers-of-data-breach-exposing-personal-financial-info/


3¡¢Barcode to SheetÓ¦ÓÃÅäÖôíÎóй¶368MBµÄÊý¾Ý


ýÌå12ÔÂ8ÈÕ³Æ £¬AndroidÓ¦ÓÃBarcode to SheetÅäÖôíÎóй¶ÁËÓû§ÐÅÏ¢ºÍÆóÒµÊý¾Ý¡£ÕâÊÇÒ»¸öÌõÐÎÂëɨÃ蹤¾ß £¬Ö÷ÒªÃæÏòµç×ÓÉÌÎñ¿Í»§ £¬ÔÚGoogle PlayÉ̵êµÄÏÂÔØÁ¿Áè¼Ý10Íò´Î¡£CybernewsÍŶӷ¢ÏÖÓ¦ÓõĵÄFirebaseÊý¾Ý¿âÅäÖôíÎó £¬°üÂÞÁè¼Ý368MBÊý¾Ý¿É±»ËùÓÐÈË·ÃÎÊ¡£Êý¾Ý¿âй¶ÁËÓйزúÎï¡¢³ÂËß¡¢µç×ÓÓʼþºÍÓû§IDµÄÐÅÏ¢ £¬ÒÔ¼°Web¿Í»§¶ËID¡¢Google APIÃÜÔ¿¡¢GoogleÓ¦Ó÷¨Ê½IDºÍÍß½â³ÂËßÃÜÔ¿µÈ¡£¾ÝϤ £¬¿ª·¢ÈËÔ±ÕýÔÚÑо¿½â¾ö·½°¸¡£


https://securityaffairs.com/155444/mobile-2/android-barcode-scanner-app-exposes-user-passwords.html


4¡¢SafeBreachÑÝʾ¿ÉÈƹýEDRµÄ½ø³Ì×¢ÈëPool Party


Äþ¾²¹«Ë¾SafeBreachÔÚ12ÔÂ6ÈÕ¹ûÈ»ÁËÒ»Ì×ÃûΪPool PartyµÄ½ø³Ì×¢Èë¼¼Êõ £¬¿ÉÒÔÈƹýEDR½â¾ö·½°¸¡£ÕâÊÇ8ÖÖ½ø³Ì×¢ÈëµÄ¼¯ºÏ £¬ÕâЩҪÁìÄܹ»²»ÊÜÈκÎÏÞÖƵؿçËùÓÐÁ÷³ÌÊÂÇé £¬Ê¹µÃËüÃDZÈÏÖÓеÄÁ÷³Ì×¢Èë¼¼ÊõÔ½·¢Áé»î¡£PoolPartyÖ®ËùÒÔµÃÃû £¬ÊÇÒòΪËüÖ²¸ùÓÚÒ»¸öÃûΪWindowsÓû§Ä£Ê½Ï̳߳صÄ×é¼þ £¬ÀûÓÃËü¿ÉÒÔÏòϵͳÖеÄÄ¿±ê½ø³Ì²åÈëÈκÎÀàÐ͵ÄÊÂÇéÏî¡£´ËÍâ £¬ÔÚÕë¶Ô5ÖÖÖ÷ÒªµÄEDR½â¾ö·½°¸½øÐвâÊÔʱ £¬ËüÃÇÍêÈ«ÎÞ·¨±»¼ì²âµ½¡£


https://thehackernews.com/2023/12/new-poolparty-process-injection.html


5¡¢ElasticÐû²¼GuLoader×îз´·ÖÎö¼¼ÊõµÄ·ÖÎö³ÂËß


12ÔÂ6ÈÕ £¬Elastic Security LabsÐû²¼Á˹ØÓÚGuLoader×îз´·ÖÎö¼¼ÊõµÄ·ÖÎö³ÂËß¡£GuLoaderÓÚ2019Äêµ×Ê״α»·¢ÏÖ £¬ÊÇÒ»ÖÖ»ùÓÚshellcodeµÄ¶ñÒâÈí¼þÏÂÔØ·¨Ê½ £¬ÓÃÓÚ·Ö·¢ÖÖÖÖpayload¡£ËäÈ»GuLoaderµÄºËÐĹ¦Ð§ÔÚ¹ýÈ¥¼¸ÄêÖÐûÓз¢Éú¾Þ´ó±ä»¯ £¬µ«»ìÏý¼¼ÊõµÄ²»Í£¸üÐÂʹµÃ·ÖÎöGuLoader³ÉΪһ¸ö·ÑÊÂÇÒºÄÁ¦µÄ¹ý³Ì¡£×î½üµÄ±ä»¯Ö®Ò»ÊÇеĻÖÐÏòÆäʸÁ¿Òì³£´¦Ö÷¨Ê½£¨VEH£©Ìí¼ÓÁËÒì³£ £¬Ê¹·ÖÎö¸ü¾ßÌôÕ½ÐÔ¡£


https://www.elastic.co/security-labs/getting-gooey-with-guloader-downloader


6¡¢SecurityScorecardÐû²¼ÄÜÔ´ÐÐÒµÍøÂçÄþ¾²·çÏÕ³ÂËß


12ÔÂ7ÈÕ±¨µÀ³Æ £¬SecurityScorecardÐû²¼ÁËÄÜÔ´ÐÐÒµµÚÈý·½ÍøÂçÄþ¾²·çÏÕ³ÂËß¡£×îÐÂÊý¾ÝÏÔʾ £¬¹ýÈ¥12¸öÔÂÀï £¬È«Çò48¼Ò×î´óµÄÄÜÔ´¹«Ë¾¼¸ºõÈ«²¿(90%)Ôâµ½¹ý¹©Ó¦Á´Êý¾Ýй¶¡£½öÔÚ¹ýÈ¥90ÌìÄÚ £¬¾Í·¢ÉúÁË264ÆðÓëµÚÈý·½ÈëÇÖÓйصÄÎ¥¹æʼþ¡£ÃÀ¹úÇ°Ê®´óÄÜÔ´¹«Ë¾ÔÚ¹ýÈ¥Ò»ÄêÖж¼·¢Éú¹ýµÚÈý·½¹¥»÷ʼþ¡£Ó¢¹úÄÜÔ´¹«Ë¾µÄƽ¾ùÄþ¾²ÆÀ¼¶×î¸ß £¬80%µÄ¹«Ë¾µ½´ïB»òÒÔÉÏÆÀ¼¶¡£MOVEitÊǹýÈ¥6¸öÔÂÖÐ×îÆÕ±éµÄµÚÈý·½Â©¶´¡£


https://www.infosecurity-magazine.com/news/ninety-percent-energy-companies/