macOSË«³Á¿ªÊÍ·ì϶£¬¿Éµ¼ÖÂÌáȨ¼°´úÂëÖ´ÐУ»2018ÄêÓ¢¹úÉí·ÝڲƭÂÊÔö³¤8£¥£¬´´º¹Çàиß

°ä²¼¹¦·ò 2019-06-24
1.macOSË«³Á¿ªÊÍ·ì϶£¬¿Éµ¼ÖÂÌáȨ¼°´úÂëÖ´ÐÐ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±ÔÚmacOSÖз¢ÏÖÒ»¸öË«³Á¿ªÊÍ·ì϶£¨CVE-2019-8635£©¡£¸Ã·ì϶ÊÇÓÉAMD×é¼þÖеÄÄÚ´æ°Ü»µÎÊÌâÒýÆðµÄ£¬ÈôÊdzɹ¦ÀûÓ㬹¥»÷Õß¿ÉÌáȨÖÁrootȨÏÞ²¢ÔÚϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¸ÃCVE IDº­¸ÇÁ½¸öË«³Á¿ªÊÍ·ì϶£¬µÚÒ»¸ö´æÔÚÓÚAMDRadeonX4000_AMDSIGLContextÀàµÄdiscard_StretchTex2Tex²½ÖèÖУ¬µÚ¶þ¸öÊǸÃÀàµÄprocess_StretchTex2Tex²½Öè¡£AppleÔÚmacOS Mojave 10.14.4¸üÐÂÖн¨¸´Á˸÷ì϶¡£

   

Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/cve-2019-8635-double-free-vulnerability-in-apple-macos-lets-attackers-escalate-system-privileges-and-execute-arbitrary-code/

2.Torä¯ÀÀÆ÷°²È«¸üУ¬½¨¸´Sandbox Escape·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Torä¯ÀÀÆ÷°ä²¼Ð°汾8.5.3£¬½¨¸´FirefoxÖеÄSandbox Escape·ì϶£¨CVE-2019-11708£©¡£¸Ã·ì϶ÔÚ×î½üÕë¶Ô¼ÓÃÜÇ®±Ò¹«Ë¾µÄ¹¥»÷Öб»ÀûÓã¬ÓÉÓÚ·¸×ï·Ö×ÓÔÚ»ý¼«ÀûÓô˷ì϶£¬Ç¿ÁÒ½¨ÒéËùÓÐTorÓû§Éý¼¶µ½×îа汾¡£´ËǰTor°ä²¼ÁËTor 8.5.2£¬½¨¸´FirefoxÖеÄRCE·ì϶£¨CVE-2019-11707£©£¬ÕâÁ½¸ö·ì϶½áºÏÆðÀ´£¬¿ÉÔÚÊܺ¦ÕßµÄÍÆËã»ú¸ßµÍÔØºÍ×°ÖÃÐÅÏ¢ÇÔȡľÂí¼°Ô¶³Ì½Ó¼ûÍÆËã»úÍøÂç¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/tor-browser-853-fixes-a-sandbox-escape-vulnerability-in-firefox/

3.Pink Camera APPϰȾ¶ñÒâÈí¼þMobOk£¬ÏÂÔØÁ¿´ï1Íò´Î

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¿¨°Í˹»ù×êÑÐÈËÔ±Igor Golovin·¢ÏÖGoogle PlayÉ̵êÖеÄPink CameraÀûÓÃϰȾ¶ñÒâÈí¼þMobOk¡£Pink CameraºÍPink Camera 2Òѱ»×°ÖÃÁËԼĪ1Íò´Î£¬Æä°µ²ØµÄMobOkÖ¼ÔÚÇÔÈ¡Óû§µÄÓ×ÎÒÊý¾Ý£¬²¢ÀûÓÃÕâЩÐÅÏ¢½øÐи¶·Ñ¶©ÔÄ¡£¸ÃÀûÓ÷¨Ê½»áÒªÇó½Ó¼ûWi-Fi¿Ø¼þºÍ֪ͨ£¬²¢ÔÚ¹¥»÷½×¶Î¹Ø¹ØWi-Fi£¬´Ó¶ø¼¤»îÒÆ¶¯Êý¾ÝºÍ½øÐи¶·Ñ¶©ÔÄ¡£ÕâЩÓöȻáÖ±½Ó´ÓÓû§µÄ»°·ÑÖп۳ý£¬¶ø²»ÊÇÐÅÓþ¿¨»ò½è¼Ç¿¨¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/mobok-malware-google-photo-editor/145932/

4.ÐÂÀÕË÷Èí¼þLooCipher£¬ÖØÒªÍ¨¹ýÀ¬»øÓʼþ´«²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Petrovic·¢ÏÖÐÂÀÕË÷Èí¼þLooCipher¡£¸ÃÀÕË÷Èí¼þÔÚÒ°±í±»»ý¼«´«²¼£¬¹ÌȻĿǰÉв»Ã÷ÏÔÆä·Ö·¢·½Ê½£¬µ«Ò»Ð©ÎļþÅú×¢¸ÃÀÕË÷Èí¼þÊÇͨ¹ýÀ¬»øÓʼþ´«²¼µÄ¡£LooCipherͨ¹ýÃûΪInfo_BSV_2019.docmµÄ¶ñÒâWordÎĵµ´«²¼£¬¸ÃÎĵµÖÐÔ̺¬ÓÃÓÚÏÂÔØºÍÖ´ÐÐpayloadµÄºê´úÂë¡£LooCipher»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lcphrÀ©´óÃû£¬ÆäÀÕË÷µÄÊê½ðΪ300Å·Ôª»òÔ¼330ÃÀÔª¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-loocipher-ransomware-spreads-its-evil-through-spam/

5.2018ÄêÓ¢¹úÉí·ÝڲƭÂÊÔö³¤8£¥£¬´´º¹Çàиß


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý·ÇͶ»ú·´Ú²Æ­×éÖ¯CifasµÄ»ã±¨£¬2018ÄêÓ¢¹úµÄÉí·ÝڲƭÂÊÉÏÉýÁË8%£¬´´º¹Çàиß¡£»ã±¨ÖмͼÁË2018Äê²úÉúµÄ½ü32.4ÍòÆðڲƭ°¸Àý£¬ÕâÒ»Êý×Ö×Ô2017ÄêµÄÏ»¬ºóÓֻص½2015ÄêºÍ2016ÄêµÄ½Ï¸ßˮƽ¡£87%µÄÉí·ÝڲƭÊÇͨ¹ýÍøÂç½øÐеÄ¡£Ôâ·êÉí·ÝڲƭµÄ60ËêÒÔÉÏÈ˶¡Ôö³¤ÁË34%£¬¶ø21ËêÒÔϵÄÈ˶¡ÔòÔö³¤ÁË26%¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/uk-identity-fraud-jumps-8-to-new-1-1/

6.ÃÀCISAÖÒ¸æÒÁÀʺڿÍÕë¶ÔÃÀ¹ú¹¤ÒµºÍµ±¾Ö»ú¹¹µÄÍøÂç¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÃÀ¹úºÓɽ°²È«ÊýÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©µÄÒ»·ÝÉêÃ÷£¬ÒÁÀʺڿÍÕë¶ÔÃÀ¹ú¹¤ÒµºÍµ±¾Ö»ú¹¹µÄÍøÂç¹¥»÷ÔÚÔö³¤£¬Æä¹¥»÷¼¿Á©Ô̺¬£ºÊ¹ÓÃÊý¾Ý²Á³ý¶ñÒâÈí¼þ¡¢×²¿â¹¥»÷¡¢ÃÜÂëÅçÉä¹¥»÷ºÍÓã²æÊ½ÍøÂç´¹µö¡£¸ÃÖÒ¸æ°ä²¼ÔÚCISAÖ÷¹ÜChristopher KrebsµÄtweetÉÏ£¬²¢½«ÔÚCISAÍøÕ¾Éϰ䲼¡£¸ÃÉêÃ÷Ö¸³ö£¬¡°CISA·¢ÏÖÒÁÀÊÕë¶ÔÃÀ¹ú¹¤ÒµºÍµ±¾Ö»ú¹¹µÄ¶ñÒâÍøÂç»î¶¯ÔÚÔö³¤£¬ÎÒÃǽ«³ÖÐøÓëµý±¨ÉçÇøºÍÍøÂ簲ȫºÏ×÷ͬ°éºÏ×÷¼à¿ØÒÁÀʵÄÍøÂç»î¶¯¡¢¹²ÏíÐÅÏ¢²¢²ÉÈ¡Ðж¯ÒÔÈ·±£ÃÀ¹úºÍÃËÓѵݲȫ¡±¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-government-warns-of-data-wipers-used-in-iranian-cyberattacks/