¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190110

°ä²¼¹¦·ò 2019-01-10
1¡¢Google PlayϼÜ85¸ö¸æ°×app£¬Ï°È¾Ô¼900ÍòAndroidÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±ÔÚGoogle PlayÉ̵귢ÏÖ85¸ö¸æ°×ÀûÓã¬Ô¼900ÍòAndroidÓû§Êܵ½Ï°È¾¡£ÕâЩapp¼Ù×°³ÉÓÎÏ·¡¢Á÷ýÌåµçÊӺͷÂÕÕÒ£¿ØÆ÷µÈ£¬ÔÚÉ豸ºó¶Ü¾²Ä¬ÔËÐУ¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¸æ°×ºäÕ¨Óû§É豸¡£×êÑÐÈËÔ±·¢ÏÖÕâЩappÀ´×ÔÓÚ·ÖÆçµÄ¿ª·¢ÈËÔ±£¬²¢ÇÒÕ¼ÓÐ·ÖÆçµÄAPKÖ¤Ê鹫Կ£¬µ«ËüÃǵĴúÂëºÍ¶¨Ãû·½Ê½¶¼¼«¶ÈÀàËÆ¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩÀûÓá£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/android-adware-malware.html


2¡¢×êÑÐÍŶӷ¢ÏÖApple Intel HD 5000´æÔÚ¶à¸öÌáȨ·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cisco Talos×êÑÐÍŶӷ¢ÏÖApple OSX 10.13.4ÔÚ´¦ÖÃÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬ÆäIntelHD5000ÄÚºËÀ©´óÖдæÔÚ¶à¸öÌáȨ·ì϶£¨CVE-2018-4421ºÍCVE-2018-4456£©¡£Æ¾¾Ý×êÑÐÈËÔ±µÄÃèÊö£¬VLCýÌåÀûÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç½Ó¼û£¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý¡£ÕâЩ·ì϶ÊÇÔÚMacBookPro11.4-OS X 10.13.4»·¾³Ï·¢Ïֵġ£ÓÉÓÚ·ì϶¿Éͨ¹ýSafari´¥·¢£¬½¨ÒéÓû§¾¡¿ì¸üС£

  Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html


3¡¢Adobe°ä²¼2019Äê1Ô°²È«¸üУ¬½¨¸´Á½¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash Player°ä²¼ÁË2019Äê1Ô°²È«¸üС£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬²¢µ¥Ò»µØ½¨¸´ÁË»úÄÜÎÊÌâºÍbug£¬²¢Î´½¨¸´Èκΰ²È«ÎÊÌâ¡£Õë¶ÔDigital EditionsµÄ°²È«¸üн¨¸´ÁËÔ½½ç¶Á·ì϶£¨CVE-2018-12817£©£¬¸Ã·ì϶¿Éµ¼ÖÂÐÅϢй¶¡£Õë¶ÔConnectµÄ°²È«¸üн¨¸´Á˻ỰÁîÅÆÂ¶Â¶Âí½Å£¨CVE-2018-19718£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/


4¡¢¹È¸è°ä²¼2019Äê1ÔÂAndroid°²È«²¼¸æ£¬½¨¸´27¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¹È¸è°ä²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄ°²È«¸üУ¬¹²½¨¸´ÁË27¸ö·ì϶¡£ÆäÖа²È«²¹¶¡¼¶±ð2019-01-01Öн¨¸´ÁË13¸ö·ì϶£¬Ô̺¬Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨ·ì϶£¨CVE-2018-9582£¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ¡£°²È«²¹¶¡¼¶±ð2019-01-05½¨¸´ÁË14¸ö·ì϶£¬Ô̺¬Qualcomm¹ØÔ´×é¼þÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2018-11847£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2019-01-01.html


5¡¢ÐÂ×Ô¶¯»¯´¹µö¹¤¾ßModlishka£¬¿ÉÈÆ¹ýË«³É·ÖÈÏÖ¤

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

²¨À¼°²È«×êÑÐÈËÔ±PiotrDuszy¨½ski°ä²¼ÁËÒ»¸öеÄÉøÈë²âÊÔ¹¤¾ß£¬¸Ã¹¤¾ßÄܹ»ÊµÏÖ´¹µö¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«³É·ÖÈÏÖ¤¡£¸Ã¹¤¾ß±»¶¨ÃûΪModlishka£¨²¨À¼ÓÒâ˼Ϊó«ò룩£¬ÊÇÒ»¸öÓÃÓÚ´¦ÖõÇÂ¼Ò³ÃæºÍ´¹µöÁ÷Á¿µÄ·´Ïò´úÀí¡£ËüλÓÚÓû§ºÍÖ¸±êÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬Êܺ¦Õ߽ӹܵ½À´×ÔÓںϷ¨ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬µ«ËùÓÐÁ÷Á¿³ÇÊÐͨ¹ý²¢¼Í¼ÔÚModlishka·þÎñÆ÷ÉÏ¡£×êÑÐÈËÔ±ÔÚGithubÉϰ䲼Á˸ù¤¾ß¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/


6¡¢Ð±ßÐÅ·¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÍŶӰ䷢ÁËһƪ½éÉÜбßÐÅ·¹¥»÷µÄÂÛÎÄ£¬¸Ã¹¥»÷·½Ê½²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞ¶È£¬ÖØÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄÜÔ̺¬·¨Ê½¶þ½øÔìÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ¡£×êÑÐÈËÔ±ÀûÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´²é³­Ò³Ã滺´æ¡£¸Ã¹¥»÷ÒÑÔÚ±¾µØ³¢ÊÔÖб»Ö¤Ã÷£¬²¢ÇÒÔڿ϶¨Ç°ÌáÏÂÒ²¿ÉÔ¶³ÌÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù