
腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Browser ] ZDI-17-054: Apple Safari SearchInputType Type Confusion Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-17-054/
"ZDI-17-054: Apple Safari SearchInputType Type Confusion Remote Code Execution Vulnerability: https://t.co/jmI1DR11ms"
-
[ iOS ] iOS/MacOS kernel UaF due to lack of locking in host_self_trap https://bugs.chromium.org/p/project-zero/issues/detail?id=1034
"iOS/MacOS kernel UaF due to lack of locking in host_self_trap,来自 Project Zero: https://t.co/8FdFpRatbH"
-
[ iOS ] iOS 10.3 will will stop trusting SHA1 certificates issued by CAs in the default trust store. http://www.redmondpie.com/ios-10.3-release-notes-changelog-whats-new-according-to-apple/
"iOS 10.3 将不再信任默认证书列表中 CA 颁发的 SHA1 证书: https://t.co/0pEl2TP3C6"
-
[ macOS ] MacOS kernel use after free due to bad reference counting when creating new user clients https://bugs.chromium.org/p/project-zero/issues/detail?id=975
"MacOS 内核在 create user client 时因引用计数错误存在一个 UAF 漏洞,来自 Project Zero: https://t.co/7pKMmSoaoG"
-
[ macOS ] macOS 10.12.3 source is out: https://opensource.apple.com/release/macos-10123.html
"macOS 10.12.3 源码公开︰ https://t.co/jkNzkvhXBZ"
-
[ Mitigation ] Cool blog post "Harmful prefetch on Intel" http://blog.ioactive.com/2017/01/harmful-prefetch-on-intel.html by @ kiqueNissim @ IOActive #kernelhacking
" Harmful prefetch on Intel - Intel 的 Prefetch 指令可以被用于 Bypass ASLR: https://t.co/SqyaOFuNxZ "
-
[ Others ] New blog, detecting targeted attacks from #BARIUM and #LEAD in #WDATP https://blogs.technet.microsoft.com/mmpc/2017/01/25/detecting-threat-actors-in-recent-german-industrial-attacks-with-windows-defender-atp/
"通过 Windows Defender ATP 检测最近德国 winnti 背后的攻击者: https://t.co/T5tEutphIq "
-
[ Others ] This book reads you - exploiting services and readers that support the ePub book format https://s1gnalcha0s.github.io/epub/2017/01/25/This-book-reads-you.html
"This book reads you - 攻击支持 ePub 格式的服务和阅读器: https://t.co/utw3AGRCtJ "
-
[ Popular Software ] Oracle WebLogic RMI Registry UnicastRef Object Deserialization of Untrusted Data Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-17-055/
"Oracle WebLogic RMI Registry UnicastRef Object Deserialization of Untrusted Data Remote Code Execution Vulnerability,来自 ZDI: https://t.co/PwVkPk9WNk"
-
[ Tools ] Glazier automating the installation of the Microsoft Windows operating system on various device platforms by @Google https://t.co/njxKsteGnJ
"glazier - 在各设备平台自动化安装 Windows 操作系统的工具: https://t.co/njxKsteGnJ "
-
[ Web Security ] CVE-2016-9838 - Joomla! Account Takeover and RCE writeup https://www.ambionics.io/blog/cve-2016-9838-joomla-account-takeover-and-remote-code-execution
"Joomla CVE-2016-9838 用户提权漏洞的分析: https://t.co/9zjcCXaSRj"