¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190110

Ðû²¼Ê±¼ä 2019-01-10
1¡¢Google PlayϼÜ85¸ö¹ã¸æapp£¬£¬ £¬Ñ¬È¾Ô¼900ÍòAndroidÓû§

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁ·¢Ã÷85¸ö¹ã¸æÓ¦Ó㬣¬ £¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾¡£¡£¡£¡£¡£¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿£¿£¿£¿£¿ £¿ØÆ÷µÈ£¬£¬ £¬ÔÚ×°±¸ºǫ́¾²Ä¬ÔËÐУ¬£¬ £¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§×°±¸¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩappÀ´×ÔÓÚ²î±ðµÄ¿ª·¢Ö°Ô±£¬£¬ £¬²¢ÇÒÓµÓвî±ðµÄAPKÖ¤Ê鹫Կ£¬£¬ £¬µ«ËüÃǵĴúÂëºÍÃüÃû·½·¨¶¼Ê®·ÖÏàËÆ¡£¡£¡£¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓᣡ£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/android-adware-malware.html


2¡¢Ñо¿ÍŶӷ¢Ã÷Apple Intel HD 5000±£´æ¶à¸öÌáȨÎó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Cisco TalosÑо¿ÍŶӷ¢Ã÷Apple OSX 10.13.4ÔÚ´¦Öóͷ£ÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬£¬ £¬ÆäIntelHD5000ÄÚºËÀ©Õ¹Öб£´æ¶à¸öÌáȨÎó²î£¨CVE-2018-4421ºÍCVE-2018-4456£©¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÐÎò£¬£¬ £¬VLCýÌåÓ¦ÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç»á¼û£¬£¬ £¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÔÚMacBookPro11.4-OS X 10.13.4ÇéÐÎÏ·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²î¿Éͨ¹ýSafari´¥·¢£¬£¬ £¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£

  Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html


3¡¢AdobeÐû²¼2019Äê1ÔÂÇå¾²¸üУ¬£¬ £¬ÐÞ¸´Á½¸öÇå¾²Îó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash PlayerÐû²¼ÁË2019Äê1ÔÂÇå¾²¸üС£¡£¡£¡£¡£¡£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬£¬ £¬²¢¼òÆÓµØÐÞ¸´ÁËÐÔÄÜÎÊÌâºÍbug£¬£¬ £¬²¢Î´ÐÞ¸´ÈκÎÇå¾²ÎÊÌâ¡£¡£¡£¡£¡£¡£Õë¶ÔDigital EditionsµÄÇå¾²¸üÐÂÐÞ¸´ÁËÔ½½ç¶ÁÎó²î£¨CVE-2018-12817£©£¬£¬ £¬¸ÃÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£¡£¡£¡£¡£¡£Õë¶ÔConnectµÄÇå¾²¸üÐÂÐÞ¸´Á˻ỰÁîÅÆÌ»Â¶Îó²î£¨CVE-2018-19718£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/


4¡¢¹È¸èÐû²¼2019Äê1ÔÂAndroidÇ徲ͨ¸æ£¬£¬ £¬ÐÞ¸´27¸öÎó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

¹È¸èÐû²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄÇå¾²¸üУ¬£¬ £¬¹²ÐÞ¸´ÁË27¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖÐÇå¾²²¹¶¡¼¶±ð2019-01-01ÖÐÐÞ¸´ÁË13¸öÎó²î£¬£¬ £¬°üÀ¨Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨÎó²î£¨CVE-2018-9582£¬£¬ £¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ¡£¡£¡£¡£¡£¡£Çå¾²²¹¶¡¼¶±ð2019-01-05ÐÞ¸´ÁË14¸öÎó²î£¬£¬ £¬°üÀ¨Qualcomm±ÕÔ´×é¼þÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2018-11847£©µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2019-01-01.html


5¡¢ÐÂ×Ô¶¯»¯´¹ÂÚ¹¤¾ßModlishka£¬£¬ £¬¿ÉÈÆ¹ýË«ÒòËØÈÏÖ¤

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

²¨À¼Çå¾²Ñо¿Ö°Ô±PiotrDuszy¨½skiÐû²¼ÁËÒ»¸öеÄÉøÍ¸²âÊÔ¹¤¾ß£¬£¬ £¬¸Ã¹¤¾ß¿ÉÒÔʵÏÖ´¹ÂÚ¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«ÒòËØÈÏÖ¤¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß±»ÃüÃûΪModlishka£¨²¨À¼Ó£¬ £¬Òâ˼Ϊó«ò룩£¬£¬ £¬ÊÇÒ»¸öÓÃÓÚ´¦Öóͷ£µÇÂ¼Ò³ÃæºÍ´¹ÂÚÁ÷Á¿µÄ·´ÏòÊðÀí¡£¡£¡£¡£¡£¡£ËüλÓÚÓû§ºÍÄ¿µÄÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬£¬ £¬Êܺ¦ÕßÎüÊÕµ½À´×ÔÓÚÕýµ±ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬£¬ £¬µ«ËùÓÐÁ÷Á¿¶¼»áͨ¹ý²¢¼Í¼ÔÚModlishkaЧÀÍÆ÷ÉÏ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼Á˸ù¤¾ß¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/


6¡¢Ð±ßÐŵÀ¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿ÍŶӽÒÏþÁËһƪÏÈÈÝбßÐŵÀ¹¥»÷µÄÂÛÎÄ£¬£¬ £¬¸Ã¹¥»÷·½·¨²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞÖÆ£¬£¬ £¬Ö÷ÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄܰüÀ¨³ÌÐò¶þ½øÖÆÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ê¹ÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´¼ì²éÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÑÔÚÍâµØÊµÑéÖб»Ö¤Êµ£¬£¬ £¬²¢ÇÒÔÚÒ»¶¨Ìõ¼þÏÂÒ²¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/


ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí