GoogleÐÞ¸´AndroidϵͳÖпÉÄÜÒѱ»Ê¹ÓõĶà¸öÎó²î

Ðû²¼Ê±¼ä 2023-07-07

1¡¢GoogleÐÞ¸´AndroidϵͳÖпÉÄÜÒѱ»Ê¹ÓõĶà¸öÎó²î


¾Ý7ÔÂ6ÈÕ±¨µÀ£¬£¬ £¬£¬£¬GoogleÐû²¼ÁËAndroid²Ù×÷ϵͳµÄÇå¾²¸üУ¬£¬ £¬£¬£¬×ܼÆÐÞ¸´ÁË46¸öÎó²î£¬£¬ £¬£¬£¬ÆäÖÐÈý¸ö¿ÉÄÜÒѱ»Ê¹Óᣡ£¡£¡£ÕâЩÎó²î»®·ÖÊÇÄÚ´æÐ¹Â¶Îó²î£¨CVE-2023-26083£©£¬£¬ £¬£¬£¬ÔÚ2022Äê12ÔÂÏòÈýÐÇ×°±¸·Ö·¢Ìع¤Èí¼þµÄÎó²îʹÓÃÁ´Öб»Ê¹Ó㻣»£»ÐÅϢй¶ºÍrootÌáȨÎó²î£¨CVE-2021-29256£©£»£»£»ÒÔ¼°SkiaÖеÄÕûÊýÒç³öÎó²î£¨CVE-2023-2136£©¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÊÇAndroidϵͳ×é¼þÖеÄÒ»¸öÎó²î£¨CVE-2023-21250£©£¬£¬ £¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬ £¬£¬£¬ÇÒÎÞÐèÓû§½»»¥»òÌØÁíÍâÖ´ÐÐȨÏÞ£¬£¬ £¬£¬£¬GoogleûÓÐÌá¹©ÌØÁíÍâϸ½Ú¡£¡£¡£¡£


https://source.android.com/docs/security/bulletin/2023-07-01?hl=zh-cn


2¡¢¶íÂÞ˹¹úÓÐÌú·¹«Ë¾RZDÔâµ½¹¥»÷ÍøÕ¾ºÍÓ¦ÓÃÔÝʱÖÐÖ¹


¾ÝýÌå7ÔÂ6ÈÕ±¨µÀ£¬£¬ £¬£¬£¬¶íÂÞ˹¹úÓÐÌú·¹«Ë¾RZDÔâµ½ÁË´ó¹æÄ£¹¥»÷£¬£¬ £¬£¬£¬ÆäÍøÕ¾ºÍÒÆ¶¯Ó¦ÓóÌÐòÖÐÖ¹ÁËÊý¸öСʱ£¬£¬ £¬£¬£¬ÂÿÍÖ»ÄÜÔÚ»ð³µÕ¾ÂòƱ¡£¡£¡£¡£ÎÚ¿ËÀ¼ºÚ¿ÍÍÅ»ïIT ArmyÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£¡£RZDµÄϵͳÖÐÖ¹ÁËÖÁÉÙÁù¸öСʱ£¬£¬ £¬£¬£¬µ«¸Ã¹«Ë¾ÔÚÖÜÈý³Æ£¬£¬ £¬£¬£¬Ö»¹ÜÈÔÓÐÒ»Á¬µÄ¹¥»÷£¬£¬ £¬£¬£¬µ«ËüÒѾ­»Ö¸´ÁËÔËÓª¡£¡£¡£¡£Ê·¢Ê±£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÔöÌíÁË»ð³µÕ¾ÊÛÆ±´¦µÄÊýÄ¿£¬£¬ £¬£¬£¬ÒÔ±ãËùÓÐÂÿͶ¼ÄÜÂòµ½³µÆ±¡£¡£¡£¡£È¥Äê2Ô£¬£¬ £¬£¬£¬¶íÂÞ˹Ìú·µÄÍøÕ¾ºÍÒÆ¶¯Ó¦ÓÃÒ²ÔøÒòDDoS¹¥»÷¶øÖÐÖ¹¡£¡£¡£¡£


https://therecord.media/russian-railway-site-taken-down-by-ukrainian-hackers


3¡¢Cyber PartisansÉù³ÆÒÑÇÔÈ¡°×¶íÂÞ˹¹úÁ¢´óѧ3TBÊý¾Ý


¾ÝýÌå7ÔÂ6ÈÕ±¨µÀ£¬£¬ £¬£¬£¬Cyber PartisansÉù³Æ¹¥»÷Á˰׶íÂÞ˹¹úÁ¢´óѧ(BSU) £¬£¬ £¬£¬£¬²¢ÒÑÇÔÈ¡3 TBÊý¾Ý¡£¡£¡£¡£ËûÃÇ»¹ÌåÏÖÒѾ­¼ÓÃܺͲÁ³ýÁËÅÌËã»úºÍЧÀÍÆ÷£¬£¬ £¬£¬£¬²¢¹Ø±ÕÁËÈÏÕæÖÎÀíÓû§Éí·ÝÑéÖ¤ºÍÍøÂçÇå¾²µÄÓò¿ØÖÆÆ÷¡£¡£¡£¡£×èÖ¹±¾ÖÜÈý£¬£¬ £¬£¬£¬°×¶íÂÞ˹¹úÁ¢´óÑ§ÍøÕ¾ÈÔ´¦ÓڹرÕ״̬¡£¡£¡£¡£¸Ã´óѧ·ñ¶¨Ôâµ½ÁËÍøÂç¹¥»÷£¬£¬ £¬£¬£¬²¢½«ÏµÍ³Í£»£»£»ú¹éÒòÓÚÊÖÒÕÎÊÌâ¡£¡£¡£¡£»£»£»¹³ÆºÚ¿Í¹ûÕæµÄÕÕÆ¬ºÍ½ØÍ¼ÊÇαÔìµÄ£¬£¬ £¬£¬£¬²¢ÇÒÊǾ­ÓÉÐÞͼµÄ¡£¡£¡£¡£ÔÚBSU½ÒÏþÉùÃ÷·ñ¶¨´Ë´Î¹¥»÷ºó£¬£¬ £¬£¬£¬ºÚ¿ÍÍÅ»ï¾ÙÐÐÁËÅê»÷£¬£¬ £¬£¬£¬¹ûÕæÁË´óѧУ³¤µç×ÓÓʼþµÄ¸ü¶à½ØÍ¼£¬£¬ £¬£¬£¬°üÀ¨ËûµÄÒøÐÐÕË»§µÄժ¼¡£¡£¡£¡£


https://therecord.media/cyber-partisans-belarusian-state-university-attack


4¡¢ÃÀ¹ú¶ùͯµçÊÓÆµµÀNickelodeonÔ¼500 GBÊý¾Ýй¶


ýÌå7ÔÂ6Èճƣ¬£¬ £¬£¬£¬Óд«ÑÔ³ÆÄá¿Ë¶ùͯƵµÀ(Nickelodeon)¶¯»­²¿·Ö±¬·¢ÁËÖØ´óµÄйÃÜÊÂÎñ¡£¡£¡£¡£ËùνÊý¾Ýй¶µÄÖ¤¾Ý×îÏÈÔÚÉ罻ýÌåÉÏÈö²¥£¬£¬ £¬£¬£¬ÏÔʾΪ´ó×ÚÎĵµºÍýÌåÎļþ£¬£¬ £¬£¬£¬¾Ý³Æ¾Þϸ¸ß´ï500 GB¡£¡£¡£¡£Nickelodeon¹«Ë¾ÒѾ­Ö¤Êµ£¬£¬ £¬£¬£¬ÕâÐ©ÉæÏÓÎ¥¹æÐ¹Â¶µÄÊý¾ÝÊÇÕýµ±µÄ£¬£¬ £¬£¬£¬µ«ÆäÖеÄÒ»Ð©ËÆºõÊǼ¸Ê®ÄêǰµÄ¡£¡£¡£¡£¾ÝÍÆ²â£¬£¬ £¬£¬£¬Êý¾Ýй¶ÊÂÎñ±¬·¢ÔÚ½ñÄê1Ô¡£¡£¡£¡£Nickelodeon½²»°ÈËÌåÏÖ£¬£¬ £¬£¬£¬ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬ £¬£¬£¬ÆÊÎö¿ÉÄÜÐèÒªÒ»¶Îʱ¼ä£¬£¬ £¬£¬£¬µ«ËƺõûÓз¢Ã÷ÕæÕýÈëÇֵļ£Ï󡣡£¡£¡£


https://www.theregister.com/2023/07/06/nickelodeon_confirms_data_leak/


5¡¢Zscaler·¢Ã÷Õë¶ÔÄÜÔ´ºÍµçÐÅÐÐÒµµÄRedEnergy Stealer


7ÔÂ5ÈÕ±¨µÀ³Æ£¬£¬ £¬£¬£¬Zscaler·¢Ã÷ÁËÒ»ÖÖÃûΪRedEnergy StealerµÄÐÂÐͶñÒâÈí¼þ£¬£¬ £¬£¬£¬ÓÃÓÚ¹¥»÷ÄÜÔ´¹«ÓÃÊÂÒµ¡¢Ê¯ÓÍ¡¢×ÔÈ»Æø¡¢µçÐźͻúеÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»´ÓÖÖÖÖä¯ÀÀÆ÷ÇÔÊØÐÅÏ¢£¬£¬ £¬£¬£¬Í¬Ê±»¹°üÀ¨ÁËÖ´ÐÐÀÕË÷¹¥»÷µÄ²î±ðÄ£¿£¿£¿é¡£¡£¡£¡£Ëü»¹¶ñÒâÈí¼þ»á¶à½×¶ÎÖ´ÐУ¬£¬ £¬£¬£¬´ÓÖ´ÐÐαװµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþ×îÏÈ¡£¡£¡£¡£È»ºó½¨É賤ÆÚÐÔ£¬£¬ £¬£¬£¬ÓëDNSЧÀÍÆ÷ͨѶ£¬£¬ £¬£¬£¬²¢´ÓÔ¶³ÌÏÂÔØÌØÁíÍâpayload¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬¿ÉÒɵÄFTP½»»¥Åú×¢ÎúDZÔÚµÄÊý¾Ýй¶ºÍδ¾­ÊÚȨµÄÎļþÉÏ´«¡£¡£¡£¡£


https://securityaffairs.com/148193/malware/redenergy-stealer-as-a-ransomware.html


6¡¢Ñо¿Ö°Ô±Åû¶LinuxÄÚºËÎó²îStackRot CVE-2023-3269


Ñо¿Ö°Ô±ÔÚ7ÔÂ6ÈÕÅû¶ÁËLinuxÄÚºËÖеÄÎó²îStackRot(CVE-2023-3269)¡£¡£¡£¡£StackRotÔ´ÓÚLinuxÄÚºËÔÚÆäÄÚ´æÖÎÀí×ÓϵͳÖд¦Öóͷ£¿ÍÕ»À©Õ¹µÄÀú³Ì£¬£¬ £¬£¬£¬ÓëÖÎÀíÐéÄâÄÚ´æÇøÓò(VMA)Ïà¹Ø¡£¡£¡£¡£ÕâÊÇÒ»¸öÊͷźóʹÓã¨UAF£©Îó²î£¬£¬ £¬£¬£¬Î»ÓÚLinuxÄÚºË6.1ÖÐÒýÈëµÄÒ»ÖÖеÄVMAÊý¾Ý½á¹¹ÏµÍ³maple tree£¬£¬ £¬£¬£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£¡£¡£¡£StackRotÓ°ÏìÁËLinux°æ±¾6.1ÖÁ6.4ÉϵÄËùÓÐÄÚºËÉèÖᣡ£¡£¡£Ñо¿Ö°Ô±Ô¤¼ÆÔÚ7ÔÂβ֮ǰÅû¶ÓйØStackRotºÍPoCµÄÍêÕûÊÖÒÕϸ½Ú¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-stackrot-linux-kernel-flaw-allows-privilege-escalation/