¡¾Êý¾Ýй¶¡¿Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Ô¼23ÍòÓû§µÄÐÅϢй¶
Èðµä¹«Ë¾Flightradar24֤ʵÆäһ̨ЧÀÍÆ÷ÓÚÉÏÖÜÄ©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Ô¼23ÍòÓû§µÄµç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂëй¶¡£¡£¡£Flightradar24ÊÇÒ»¼ÒÌṩº½°à×·×ÙЧÀ͵Ĺ«Ë¾£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ´Ë´Îй¶ӰÏìÁË2016Äê3ÔÂ16ÈÕ֮ǰע²áµÄÓû§¡£¡£¡£Flightradar24ÒÑÏòÓû§·¢ËÍÁ˰üÀ¨ÃÜÂëÖØÖÃÁ´½ÓµÄÓʼþ£¬£¬£¬£¬£¬ÒªÇóÕâЩÓû§¸ü¸ÄÃÜÂë¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/flightradar24-data-breach.html
¡¾Êý¾Ýй¶¡¿Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û
Çå¾²Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öapp£¨°üÀ¨2446¸öAndroid appºÍ600¸öiOS app£©µÄÔ¼2300¸öFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬Áè¼Ý1ÒÚÌõÓû§ÐÅϢй¶£¨Áè¼Ý113GB£©¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨Ã÷ÎÄÃÜÂë¡¢Óû§ID¡¢Î»ÖÃÒÔ¼°²¿·Ö²ÆÎñ¼Í¼£¨ÒøÐС¢¼ÓÃÜÇ®±ÒÉúÒ⣩µÈ¡£¡£¡£GoogleµÄFirebaseÊÇ×îÊܽӴýµÄÒÆ¶¯ºÍWebÓ¦Óõĺó¶Ë¿ª·¢Æ½Ì¨Ö®Ò»£¬£¬£¬£¬£¬ËüΪ¿ª·¢Ö°Ô±ÌṩÁË»ùÓÚÔÆµÄÊý¾Ý¿â£¬£¬£¬£¬£¬²¢ÒÔJSONÃûÌô洢Êý¾Ý¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Ðí¶à¿ª·¢Ö°Ô±Î´Í×ÉÆ±£»£»£»£»£»¤ÆäFirebaseÊý¾Ý¿â£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷ÕßÖ»ÐèÔÚÖ÷»úÃûĩβÌí¼Ó¿ÕÊý¾Ý¿âÃû+¡°/.json¡±¼´¿É»á¼ûÕâЩÊý¾Ý¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/mobile-security-firebase-hosting.html
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þFormBookµÄй¥»÷»î¶¯
˼¿ÆTalosÑо¿ÍŶӷ¢Ã÷¶ñÒâÈí¼þFormBookµÄй¥»÷»î¶¯£¬£¬£¬£¬£¬FormBookÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨¼üÅ̼ͼ¡¢ÇÔÈ¡ÃÜÂ루ÍâµØÃÜÂëºÍweb±íµ¥ÖеÄÃÜÂ룩ÒÔ¼°½ØÆÁµÈ¹¦Ð§¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄй¥»÷»î¶¯ÔÚͳһ·â´¹ÂÚÓʼþÖÐʹÓÃÁË4¸ö²î±ðµÄ¶ñÒâÎĵµ£¨°üÀ¨PDFºÍWordÃûÌã©£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁ½¸ö¹ûÕæµÄOfficeÎó²îʹÓã¨CVE-2017-0199ºÍCVE-2017-11882£©·Ö·¢ÓÐÓúÉÔØ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/06/my-little-formbook.html
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ѬȾÁè¼Ý6Íò¸öÊÖ»úµÄ¶ñÒâÈí¼þScammy
RiskIQÑо¿ÍŶӷ¢Ã÷Ò»¸öжñÒâapp Scammy£¬£¬£¬£¬£¬ScammyÖ÷ÒªÓÃÓÚ×Ô¶¯µã»÷¹ã¸æºÍÇÔÈ¡Óû§µÄÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨IMEI¡¢µç»°ºÅÂë¡¢ÊÖ»úÐÍºÅºÍÆ·ÅÆ¡¢Î»Öõȡ£¡£¡£Ñо¿Ö°Ô±³Æ¸Ã¶ñÒâÈí¼þÖÁÉÙÒÑѬȾÁË6Íò¸öAndroidÊÖ»ú¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄIoCÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/interesting-crawls/battery-saving-mobile-scam-app/
¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±³ÆFireFoxºÍEdge±£´æÎó²îWavethrough£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶
GoogleÑо¿Ö°Ô±Jake Archibald·¢Ã÷ÏÖ´úä¯ÀÀÆ÷±£´æÇå¾²Îó²îWavethrough£¬£¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÇÔÈ¡ÔÚ¸Ãä¯ÀÀÆ÷ÉϵǼ¹ýµÄÆäËüÍøÕ¾µÄÕË»§µÈÃô¸ÐÄÚÈÝ¡£¡£¡£¸ÃÎó²îÓëä¯ÀÀÆ÷´¦Öóͷ£¶ÔÊÓÆµºÍÒôƵÎļþµÄ¿çÓòÇëÇóµÄ·½·¨Óйأ¬£¬£¬£¬£¬ÉõÖÁ¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß¶ÁÈ¡Óû§µÄGmail»òFacebook˽ÈËÐÂÎÅ¡£¡£¡£ChromeºÍSafari²»ÊÜÓ°Ï죬£¬£¬£¬£¬FireFoxºÍEdgeÒ²ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/browser-cross-origin-vulnerability.html
¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐÞ¸´FXOSºÍNX-OSÖеÄ24¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¶à¸öÐͺŵĽ»Á÷»úÊÜÓ°Ïì
±¾ÖÜÈý˼¿ÆÐû²¼FXOSºÍNX-OSµÄÇå¾²¸üУ¬£¬£¬£¬£¬¹²ÐÞ¸´24¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨5¸ö¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеĸßΣÎó²î£¨CVE-2018-0301¡¢CVE-2018-0308¡¢CVE-2018-0304¡¢CVE-2018-0314ºÍCVE-2018-0312£©¡£¡£¡£Îó²î¹æÄ£°üÀ¨Î´ÊÚȨ»á¼û¡¢ÌáȨ¡¢í§Òâ´úÂëÖ´ÐС¢í§ÒâÏÂÁîÖ´ÐС¢Ãô¸ÐÐÅϢй¶ºÍDoS¡£¡£¡£Ë¼¿ÆÈ·ÈϳÆÕâЩÎó²îûÓÐÓ°ÏìCisco IOS»òIOS XE¡£¡£¡£ÏêϸÎó²îÁбíÇë»á¼ûÒÔÏÂÁ´½Ó¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-67770