HackerOneµÄÔ±¹¤ÇÔÈ¡Îó²î±¨¸æ²¢³öÊÛ¸øÊÜÓ°Ïì¿Í»§

Ðû²¼Ê±¼ä 2022-07-05

1¡¢HackerOneµÄÔ±¹¤ÇÔÈ¡Îó²î±¨¸æ²¢³öÊÛ¸øÊÜÓ°Ïì¿Í»§


¾ÝýÌå7ÔÂ2ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬HackerOneµÄÒ»ÃûÔ±¹¤ÇÔÈ¡ÁËͨ¹ýÎó²îÉͽðƽ̨Ìá½»µÄÎó²î±¨¸æ £¬£¬£¬£¬£¬£¬²¢½«Æäй¶¸øÊÜÓ°ÏìµÄ¿Í»§ÒÔIJȡ¾­¼ÃÀûÒæ¡£¡£¡£¡£¡£¡£¾­ÓÉÊÓ²ì £¬£¬£¬£¬£¬£¬¸ÃÔ±¹¤ÊÇΪÖÚ¶à¿Í»§ÏîÄ¿·ÖÀàÎó²îÅû¶µÄÊÂÇéÖ°Ô±Ö®Ò» £¬£¬£¬£¬£¬£¬×Ô4ÔÂ4ÈÕÖÁ6ÔÂ23ÈÕÒÔÀ´»á¼ûÁË¸ÃÆ½Ì¨ £¬£¬£¬£¬£¬£¬ÒѾ­ÁªÏµÁË7¸ö¿Í»§¡£¡£¡£¡£¡£¡£ËûʹÓÃÁËÃû³Æ"rzlr" £¬£¬£¬£¬£¬£¬ÒÔ¼°ÍþвºÍÏÅ»£ÐÔµÄÓïÑÔÓë¿Í»§½»»¥ £¬£¬£¬£¬£¬£¬ÒÑÀÖ³ÉÊÕµ½Éͽ𡣡£¡£¡£¡£¡£6ÔÂ30ÈÕ £¬£¬£¬£¬£¬£¬HackerOne¿ª³ýÁËÕâÃûÔ±¹¤¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/rogue-hackerone-employee-steals-bug-reports-to-sell-on-the-side/


2¡¢GoogleÐû²¼Çå¾²¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄ0 day


7ÔÂ4ÈÕ £¬£¬£¬£¬£¬£¬GoogleÐû²¼ÎªWindowsÓû§Ðû²¼Chrome 103.0.5060.114 £¬£¬£¬£¬£¬£¬ÐÞ¸´ÁË2022ÄêChromeÖеĵÚ4¸ö0 day¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇWebRTC£¨WebʵʱͨѶ£©×é¼þÖлùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2022-2294£© £¬£¬£¬£¬£¬£¬ÓÉAvastµÄÑо¿ÍŶÓÓÚ7ÔÂ1ÈÕÅû¶¡£¡£¡£¡£¡£¡£Google͸¶¸ÃÎó²îÒѱ»ÔÚҰʹÓà £¬£¬£¬£¬£¬£¬µ«²¢Î´¹ûÕæ¹ØÓÚ¹¥»÷µÄÊÖÒÕϸ½ÚµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËV8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2022-2295£©¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/132863/hacking/4th-chrome-zero-day.html


3¡¢Ñо¿Ö°Ô±Åû¶Zoho²úÆ·ÖÐÎó²îCVE-2022-28219µÄϸ½Ú


ýÌå7ÔÂ1ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Åû¶ÁËZoho ManageEngine ADAudit Plus¹¤¾ßÖÐÎó²î£¨CVE-2022-28219£©µÄÊÖÒÕϸ½ÚºÍ¿´·¨ÑéÖ¤Îó²îʹÓôúÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²îCVSSÆÀ·ÖΪ9.8 £¬£¬£¬£¬£¬£¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃÀ´Ô¶³ÌÖ´ÐдúÂë²¢ÆÆËðActive DirectoryÕÊ»§¡£¡£¡£¡£¡£¡£¸ÃÎó²î°üÀ¨3¸öÎÊÌ⣺²»ÊÜÐÅÈεÄJava·´ÐòÁл¯¡¢Â·¾¶±éÀúºÍäXMLÍⲿʵÌå(XXE)×¢Èë¡£¡£¡£¡£¡£¡£ZohoÔÚ3ÔÂβµÄADAudit Plus build 7060ÖÐÐÞ¸´ÁËÕâÒ»Îó²î¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/zoho-manageengine-adaudit-plus-bug-gets-public-rce-exploit/


4¡¢ReversingLabsÐû²¼¹ØÓÚAstraLocker 2.0µÄÆÊÎö±¨¸æ


ýÌå7ÔÂ1ÈÕ³Æ £¬£¬£¬£¬£¬£¬ReversingLabsÐû²¼Á˹ØÓÚÀÕË÷Èí¼þAstraLocker 2.0µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ £¬£¬£¬£¬£¬£¬ËüÖ÷Òª¾ÙÐпìËÙ¹¥»÷ £¬£¬£¬£¬£¬£¬¿ÉÖ±½Ó´Óµç×ÓÓʼþ¸½¼þÖÐͶ·Åpayload¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓõÄÓÕ¶üÊÇWordÎĵµ £¬£¬£¬£¬£¬£¬Òþ²ØÁË´øÓÐÀÕË÷Èí¼þpayloadµÄOLE ¹¤¾ß £¬£¬£¬£¬£¬£¬Ç¶ÈëµÄ¿ÉÖ´ÐÐÎļþʹÓÃÎļþÃû¡°WordDocumentDOC.exe¡± £¬£¬£¬£¬£¬£¬²¢Ê¹Óá°smash-n-grab¡±Õ½ÂÔ¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÌØÊâÖ®´¦ÊÇʹÓÃÁËSafeEngine Shielder v2.4.0.0À´´ò°ü¿ÉÖ´ÐÐÎļþ £¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸ö¹ýʱµÄ´ò°ü³ÌÐò £¬£¬£¬£¬£¬£¬ÏÕЩ²»¿ÉÄܾÙÐÐÄæÏò¹¤³Ì¡£¡£¡£¡£¡£¡£


https://blog.malwarebytes.com/ransomware/2022/07/astralocker-2-0-ransomware-isnt-going-to-give-you-your-files-back/


5¡¢ÈÕ±¾Òƶ¯ÔËÓªÉÌKDDIÍ»·¢ÖÐÖ¹ £¬£¬£¬£¬£¬£¬3915Íò¸öÓû§Í¨Ñ¶ÊÜ×è


ýÌå7ÔÂ3ÈÕ³Æ £¬£¬£¬£¬£¬£¬ÈÕ±¾Èý´óÒÆ¶¯ÔËÓªÉÌÖ®Ò»µÄKDDI Corp.Í»·¢ÖÐÖ¹ £¬£¬£¬£¬£¬£¬¶à´ï3915Íò¸öÓû§µÄͨѶÊÜ×è¡£¡£¡£¡£¡£¡£ÕⳡÖÐֹʼÓÚÉÏÖÜÁùÆÆÏþ1µã35·Ö×óÓÒ £¬£¬£¬£¬£¬£¬Ó°ÏìÁ˰üÀ¨ÒøÐÐÓªÒµ¡¢ÌìÆøÊý¾Ý¡¢»õÔ˺Ͱü¹üµÝËÍϵͳÒÔ¼°ÁªÍøÆû³µÐ§ÀÍÔÚÄڵĶà¸öÁìÓò¡£¡£¡£¡£¡£¡£KDDIÌåÏÖ £¬£¬£¬£¬£¬£¬ÆäÓïÒôºô½ÐϵͳµÄ¹ÊÕÏÒý·¢ÁËÁ÷Á¿¼¯ÖÐ £¬£¬£¬£¬£¬£¬µ¼ÖÂͨѶÊÜÏÞ £¬£¬£¬£¬£¬£¬KDDIÉ糤ÒѳöÃæ¾Ï¹ªÖÂǸ¡£¡£¡£¡£¡£¡£×èÖ¹ÉÏÖÜÈÕÉÏÎç11µã×óÓÒ £¬£¬£¬£¬£¬£¬KDDIÎ÷ÈÕ±¾Ð§ÀÍÇøµÄÐÞ¸´ÊÂÇéÒѾ­Íê³É £¬£¬£¬£¬£¬£¬ÈÕ±¾¶«²¿»Ö¸´Ð§À͵ÄÊÂÇéÓÚÖÜÈÕÍíÉÏ¿¢Ê¡£¡£¡£¡£¡£¡£


https://www.japantimes.co.jp/news/2022/07/03/business/tech/kddi-au-system-outage/


6¡¢GoogleÖ¸³ö2022ÉϰëÄ걻ʹÓõÄÎó²îÖÐÒ»°ëÓë¾ÉÎó²îÓйØ


¾Ý7ÔÂ3ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Google Project ZeroÑо¿Ö°Ô±Ðû²¼Ò»·Ý±¨¸æ £¬£¬£¬£¬£¬£¬³ÆÔÚ2022ÉϰëÄê £¬£¬£¬£¬£¬£¬¹¥»÷ÖÐʹÓõÄÎó²îÖÐÖÁÉÙÓÐÒ»°ëÓëδ׼ȷÐÞ¸´µÄ¾ÉÎó²îÓйء£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬£¬£¬×èÖ¹2022Äê6ÔÂ15ÈÕ £¬£¬£¬£¬£¬£¬ÒѼì²âµ½18¸ö0 day±»Åû¶²¢ÔÚҰʹÓᣡ£¡£¡£¡£¡£µ±ÆÊÎöÕâЩÎó²îʱ £¬£¬£¬£¬£¬£¬·¢Ã÷ÖÁÉÙ9¸öÊÇÏÈǰÐÞ¸´µÄÎó²îµÄ±äÖÖ¡£¡£¡£¡£¡£¡£ÀýÈç £¬£¬£¬£¬£¬£¬×î½ü·¢Ã÷µÄWindowsÎó²îFollina£¨CVE-2022-30190£© £¬£¬£¬£¬£¬£¬ÊÇMSHTMLÁãÈÕÎó²î£¨CVE-2021-40444£©µÄ±äÖÖ¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/132813/security/h1-2022-zero-day-variants-previous-flaws.html