ÈüÁé˼SoC´æÔÚ佨¸´µÄËÁÒâ´úÂëÖ´Ðзì϶£»¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÚ¿Æ­Ëðʧ104ÍòÃÀÔª

°ä²¼¹¦·ò 2019-08-21
1¡¢¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÚ¿Æ­Ëðʧ104ÍòÃÀÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¾Ý±¾µØÐÂÎű¨Â·£¬¼ÓÄôóÈøË¹¿¨Í¨ÊгÉΪBECÚ¿Æ­µÄ×îÐÂÊܺ¦Õß¡£·¸×ï·Ö×Ó¼ÙÒâ°¬Â×¹¹Öþ¹«Ë¾£¨Allan Construction£©µÄÊ×ϯ²ÆÕþ¹Ù£¬ÏòÊÐÕþ²ÆÕþ²¿ÃŵÄÔ±¹¤·¢Ë͵ç×ÓÓʼþÒªÇó¸ü¸ÄÒøÐÐÕË»§ºÅÂë²¢¸¶¿î¡£¸Ã¹«Ë¾Ç©¶¨ÁËÒ»×ùÇÅÁºµÄ½¨¸´¹¤³ÌºÏͬ¡£²ÆÕþÈËÔ±Òò¶øÔÚ8ÔÂ7ÈÕ»ò8ÈÕ×óÓÒÖ§¸¶ÁË104ÍòÃÀÔª¡£8ÔÂ12ÈÕÕâһȦÌ×±»·¢ÏÖ£¬·¨ÂÉ»ú¹¹ºÍ½ðÈÚµÐÔÖÊÔͼ³·ÏúÂòÂô²¢ÊÕ»Ø×ʽð£¬Ä¿Ç°ÒÑÊÕ»ØÔ¼4ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/scammer-tricks-city-into-1-million-wire-transfer/


2¡¢ºÚ¿ÍÀûÓÃÐéαNordVPNÍøÕ¾·Ö·¢ÒøÐÐľÂíBolik


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒøÐÐľÂíBolik±³ºóµÄ¹¥»÷ÕßÓÖ»ØÀ´ÁË£¬ÕâÒ»´ÎËûÃÇͨ¹ýÐéαµÄNordVPNÍøÕ¾³ÖÐø·Ö·¢¶ñÒâÈí¼þ¡£¸ÃµÁ°æÍøÕ¾nord-vpn[.]clubÏÕЩÃÀÂúµØ¿Ë¡Á˹ٷ½ÍøÕ¾NordVPN.com£¬²¢ÇÒÓµÓкϷ¨µÄSSLÖ¤Ê飬¸ÃÖ¤ÊéÓÉÊ¢¿ªÊ½Ö¤ÊéÐû¸æ»ú¹¹Let's EncryptÓÚ8ÔÂ3ÈÕÐû¸æ£¬ÓÐЧÆÚµ½11ÔÂ1ÈÕ¡£win32.bolik.2ľÂíÊÇbolik.1µÄ¸Ä½ø°æ±¾£¬ÓµÓжà×é¼þ¶à̬ÐÔÎļþ²¡¶¾µÄ¸öÐÔ£¬¹¥»÷Õß¿ÉÀûÓøÃľÂíÖ´ÐÐWeb×¢Èë¡¢Á÷Á¿½Ø»ñ¡¢¼üÅ̼ͼÒÔ¼°´Ó·ÖÆçµÄÒøÐпͻ§¶ËÇÔÊØÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-use-fake-nordvpn-website-to-deliver-banking-trojan/


3¡¢¹È¸èNestÖÇÄÜÉãÏñÍ·±»ÆØ´æÔÚ8¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸èNest Cam IQÊÒÄÚÉãÏñÍ·±»ÆØ´æÔÚ8¸ö°²È«·ì϶£¬¿ÉÓÃÓÚ½Ù³Ö»ò·ÛËéÉ豸¡£ÕâЩ·ì϶ÊÇÓÉ˼¿ÆTalos×êÑÐÈËÔ±Lilith WyattºÍClaudio Bozzato·¢Ïֵġ£·ì϶ÁìÓòÔ̺¬DoS£¨CVE-2019-5043£©¡¢ÐÅϢй¶£¨CVE-2019-5034ºÍCVE-2019-5040£©¡¢ËÁÒâ´úÂëÖ´ÐУ¨CVE-2019-5038ºÍCVE-2019-5039£©¡¢¿Éµ¼Ö±©Á¦ÆÆ½â¹¥»÷µÄ·ì϶£¨CVE-2019-5035£©ÒÔ¼°Ö¤Êé¼ÓÔØÃýÎó£¨CVE-2019-5036ºÍCVE-2019-5037£©¡£¹È¸è°µÊ¾ÒѾ­½¨¸´ÁËÕâЩ·ì϶£¬½¨¸´²¹¶¡½«×Ô¶¯ÍÆË͵½É豸ÖС£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/vulnerabilities-in-google-nest-cam-iq-can-be-used-to-hijack-your-camera/


4¡¢VideoLan°ä²¼VLC²¥·ÅÆ÷¸üУ¬½¨¸´13¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VideoLan°ä²¼VLCýÌå²¥·ÅÆ÷µÄа汾3.0.8£¬½¨¸´ÁË13¸ö°²È«·ì϶¡£·ì϶ÁìÓòÔ̺¬»º³åÇøÒç³ö¡¢use-after-free¡¢¿ÕÖ¸Õë½âÒýÓÃÒÔ¼°³ýÊýΪ0¡£´ó²¿ÃÅ·ì϶¶¼ÊÇÓÉVLC¿ª·¢ÈËÔ±Ö±½Ó·¢Ïֵġ£Æ¾¾ÝVideoLanµÄ°²È«²¼¸æ£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§´ò¿ª¶ñÒâÎļþÀ´´¥·¢±ÀÀ£»òÔڵǼÓû§µÄ°²È«¸ßµÍÎÄÖÐÖ´ÐдúÂë¡£¸Ãа汾¿ÉÓÃÓÚWindows¡¢MacºÍLinuxƽ̨£¬½¨ÒéÓû§¾¡¿ì¸üС£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vlc-media-player-308-released-with-13-security-fixes/

5¡¢ÈüÁé˼SoC´æÔÚ佨¸´µÄËÁÒâ´úÂëÖ´Ðзì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


F-Secure·¢ÏÖXilinx£¨ÈüÁé˼£©µÄZynq UltraScale+SOC´æÔÚÁ½¸ö·ì϶¡£¸ÃϵÁеIJúÆ·Ô̺¬SOC¡¢MPSOCÒÔ¼°RFSOC£¬Í¨³£ÓÃÓÚÆû³µ¡¢º½¿Õ¡¢Ïû·Ñµç×Ó¡¢¹¤ÒµÒÔ¼°¾üʲ¿¼þÖС£F-Secure°µÊ¾£¬ÕâЩSOCµÄ¼ÓÃܰ²È«Ê赼ģʽÔ̺¬Á½¸ö·ì϶£¬ÆäÖÐÒ»¸ö·ì϶ÎÞ·¨Í¨¹ýÈí¼þ¸üн¨¸´£¬±ØÒª¹©¸øÉÌÌṩ¡°ÐµÄSilicon°æ±¾¡±¡£ÀûÓÃÕâÁ½¸ö·ì϶±ØÒªÎïÀí½Ó¼ûȨÏÞ¡£ÈüÁé˼°µÊ¾ËüÅú¸ÄÁ˼¼ÊõÊֲᣬ½¨Òé¿Í»§Ê¹Óøü°²È«µÄÓ²¼þ¸ùÐÅÀµ£¨Hwrot£©°²È«Ê赼ģʽ£¬¶ø²»ÊÇֻʹÓýÏÈõµÄ¼ÓÃÜģʽ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/unpatchable-security-flaw-found-in-popular-soc-boards/


6¡¢×êÑÐÈËÔ±¹«¿ª°ä²¼iOS 12.4µÄÃâ·ÑÔ½Óü¹¤¾ß

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


һλÄäÃûµÄ×êÑÐÈËÔ±ÒÔpwn20wndµÄ±ðºÅÔÚGithubÉÏÃâ·Ñ°ä²¼ÁËiOS 12.4µÄÔ½Óü¹¤¾ß¡£¸Ã¹¤¾ßÀûÓÃÁËiOSÄÚºËÖеÄÒ»¸öUAF·ì϶£¨CVE-2019-8605£©£¬´Ë·ìÏ¶ÔøÔÚiOS 12.3Öб»½¨¸´£¬µ«Æ»¹ûÔÚiOS 12.4ÖгÁÐÂÒýÈëÁ˸÷ì϶¡£ÐµÄÔ½Óü¹¤¾ß¿ÉÔÚ¸üеÄiOSÉ豸ÉϹ¤×÷£¬Ô̺¬iphone xs¡¢xs maxºÍxr»ò2019 iPad miniºÍipad air£¬²»ÂÛ¸ÃÉ豸ÊÇÔËÐÐiOS 12.4»¹ÊÇiOS 12.2»ò¸üÔç°æ±¾£¬µ«ÔÚiOS 12.3ÉÏÎÞ·¨¹¤×÷¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/ios-iphone-jailbreak.html