¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190228

°ä²¼¹¦·ò 2019-02-28
1¡¢Android°æSHAREit´æÔÚ2¸ö·ì϶ £¬Ó°Ïì5ÒÚ¶àÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±ÔÚSHAREitµÄAndroid APPÖз¢ÏÖÁ½¸ö¸ßΣ·ì϶ £¬¿ÉÔÊÐí¹¥»÷ÕßÈÆ¹ýÉ豸µÄÉí·ÝÑéÖ¤»úÔì²¢ÇÔÈ¡Ô̺¬Ãô¸ÐÐÅÏ¢µÄÎļþ¡£SHAREitÊǺÏÓÃÓÚAndroid¡¢iOS¡¢WindowsºÍMacµÄÊ¢ÐÐÎļþ¹²ÏíÀûÓà £¬Æ¾¾ÝRedForce×êÑÐÈËÔ±µÄ±íÊö £¬Android°æSHAREitÓµÓг¬¹ý5ÒÚÓû§ £¬ÕâЩÓû§¶¼ÈÝÒ×Êܵ½¹¥»÷¡£SHAREitÒÑÔÚ2018Äê3Ô½¨¸´ÁËÕâЩ·ì϶ £¬Ë¼¿¼µ½·ì϶µÄÓ°ÏìÁìÓòÌ«¹ã £¬×êÑÐÈËÔ±ÓÚ±¾ÖÜÒ»²ÅÅû¶ÁËÓйØÏ¸½Ú¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/shareit-android-hacking.html

2¡¢À×µç½Ó¿ÚThunderclap·ì϶Ԥ¾¯ £¬¿É¶ÁÈ¡ÄÚ´æÃô¸ÐÊý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚNDSS 2019°²È«»áÒéÉÏ £¬×êÑÐÈËÔ±Åû¶ÁËÓ°ÏìÀ×µç½Ó¿ÚµÄThunderclap·ì϶ £¬¸Ã·ì϶ÔÊÐí¶ñÒâÉ豸ֱ½Ó´Ó²Ù×÷ϵͳµÄÄÚ´æÖÐÇÔÈ¡Êý¾Ý £¬Õâ¿ÉÄÜÔ̺¬¸ß¶ÈÃô¸ÐµÄÐÅÏ¢¡£Windows¡¢Mac¡¢LinuxºÍFreeBSDϵͳ¶¼Êܵ½Ó°Ïì £¬ÓÈÆäÊÇÆ»¹û×Ô2011ÄêµÄMacBook Pro±Ê¼Ç±¾±ãÆðÍ·²ÎÓëÀ×µç½Ó¿Ú £¬ÏÖ¿îµÄ±Ê¼Ç±¾¸üÊÇÈ«Êý½¨ÉèÁËÀ×µç3½Ó¿Ú¡£Æ»¹ûÔÚ2016Äê±ãͨ¹ýmacOS 10.12.4¸üн¨¸´Á˸÷ì϶ £¬Windows 10Ò²ÔÚ1803Ö®ºóµÄ°æ±¾ÖвÎÓëÁËÀ×µç3½Ó¿ÚµÄÄÚºËDMA± £»¤ £¬´Ë±í £¬Ó¢ÌضûÒ²³Ðŵ»áΪLinuxÄں˵ÄϵͳÌṩ½¨²¹¶¡ £¬½«ÔÚ5.0ÄÚºËʱ·Å³ö¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/thunderclap-flaws-impact-how-windows-mac-linux-handle-thunderbolt-peripherals/

3¡¢NVIDIA°ä²¼GPUÇý¶¯·¨Ê½µÄ°²È«¸üР£¬½¨¸´8¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

NVIDIA°ä²¼ÆäGPUÇý¶¯·¨Ê½µÄ°²È«¸üР£¬½¨¸´ÁËGeForce¡¢Quadro¡¢NVSºÍTeslaµÈ²úÆ·ÖеÄ8¸ö°²È«·ì϶¡£ÕâЩ·ì϶¿Éµ¼Ö´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ¡¢È¨ÏÞÌáÉý»òÐÅϢй¶µÈ £¬½¨ÒéÓû§¾¡¿ì×°ÖøüС£ÆäÖÐ5¸ö·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬Ô̺¬3DÊÓ¾õ×é¼þÖеķì϶£¨CVE?2019?5665£©ºÍÄÚºËģʽ²ãnvlddmkm.sysÖеÄËĸö·ì϶£¨CVE?2019?5666¡«CVE?2019?5669£©¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nvidia-patches-high-risk-vulnerabilities-gpu-display-drivers

4¡¢Ë¼¿ÆWebEx Meetingsзì϶ £¬¿ÉÌáȨÖÁSYSTEM

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

×êÑÐÈËÔ±ÔÚ˼¿ÆWebex MeetingsµÄWindows×ÀÃæÀûÓÃÖз¢ÏÖÒ»¸öÌáȨ·ì϶ £¬¸Ã·ì϶£¨CVE-2019-1674£©¿ÉÔÊÐíÎÞÌØÈ¨µÄ±¾µØ¹¥»÷ÕßÌáȨÖÁSYSTEMȨÏÞ²¢Ö´ÐÐËÁÒâºÅÁî¡£¸Ã·ì϶ӰÏìÁËWebEx°æ±¾33.6.4.15ÖÁ33.8.2.7 £¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö £¬¸Ã·ì϶ÊÇ˼¿ÆÔÚ½¨¸´DLL½Ù³Ö·ì϶£¨CVE-2018-15442£©Ê±ÒýÈëµÄÒ»¸öзì϶¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-elevation-of-privilege-vulnerability-found-in-cisco-webex-meetings/

5¡¢ÃϼÓÀ­´óʹ¹Ý¹ÙÍøÔâºÚ¿ÍÈëÇÖ £¬¹ÙÍø±»Ö²Èë¶ñÒâ´úÂë

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃϼÓÀ­¹úפ¿ªÂÞ´óʹ¹ÝµÄ¹ÙÍøÔâºÚ¿ÍÈëÇÖ £¬µ±Óû§½Ó¼ûÈκÎÒ³ÃæÊ± £¬½«»áÇ¿ÔìÏÂÔØÃûΪConference_Details.docxµÄ¶ñÒâWordÎĵµ¡£Æ¾¾ÝTrustwaveµÄ»ã±¨ £¬¸Ã¶ñÒâÎĵ·ûÓÃÁË·ì϶CVE-2017-0261 £¬²¢ÏòÓû§×°ÖÃMSBuld.exeÎļþ¡£VirusTotalµÄ¼ì²âÁ˾ÖÅú×¢ÕâÊÇÒ»¸öÃÜÂëÇÔȡľÂí¡£ÓÉÓÚTrustwave²¢Î´ÄÜÓëÍøÕ¾ËùÓÐÕßÁªÏµÉÏ £¬Òò¶øµ±Ç°¸ÃÍøÕ¾ÈÔ´¦ÓÚ±»Ï°È¾×´Ì¬¡£
  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/web-site-for-a-bangladesh-embassy-compromised-with-malicious-docs/

6¡¢ä¯ÀÀÆ÷ÍÚ¿ó¾ç±¾Coinhive½«ÓÚ3ÔÂ8ÈÕÖÕ³¡·þÎñ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Coinhive°ä·¢½«ÓÚ3ÔÂ8ÈÕÖÕ³¡·þÎñ¡£CoinhiveÊÇÒ»¸öJavaScriptÍÚ¿ó¾ç±¾ £¬Ö¼ÔÚÔÊÐíÍøÕ¾ÀûÓýӼûÕßµÄCPU×ÊÔ´½øÐÐÍÚ¿ó¡£Æä¼´½«¹Ø¹ØµÄÔ­ÒòÊÇÃÅÂÞ±ÒµÄ×îºóÒ»¸öÓ²·Ö²æµ¼Ö¹þÏ£ÂʽµÂäÁË50% £¬ÒÔ¼°ÃÅÂÞ±ÒÔÚÒ»ÄêÄÚ±áÖµ³¬¹ý85%¡£ÔÚ2019Äê3ÔÂ8ÈÕÖ®ºó £¬¸ÃÍÚ¿ó¾ç±¾½«ÖÕ³¡·þÎñ £¬µ«Óû§ÈÔÄܹ»ÔÚ4ÔÂ30ÈÕ֮ǰ»¨¹âÆäÓà¶î¡£ÕâÒ»ÐÂÎÅÒâζ×Å´óÁ¿ÀûÓÃCoinhive¾ç±¾µÄ¶ñÒâÍÚ¿ó»î¶¯Ò²½«ÖÕ³¡¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/coinhive-in-browser-cryptomining-service-shuts-down-on-march-8/

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù