¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190110

°ä²¼¹¦·ò 2019-01-10
1¡¢Google PlayϼÜ85¸ö¸æ°×app£¬Ï°È¾Ô¼900ÍòAndroidÓû§

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±ÔÚGoogle PlayÉ̵귢ÏÖ85¸ö¸æ°×ÀûÓã¬Ô¼900ÍòAndroidÓû§Êܵ½Ï°È¾ ¡£ÕâЩapp¼Ù×°³ÉÓÎÏ·¡¢Á÷ýÌåµçÊӺͷÂÕÕÒ£¿ØÆ÷µÈ£¬ÔÚÉ豸ºó¶Ü¾²Ä¬ÔËÐУ¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¸æ°×ºäÕ¨Óû§É豸 ¡£×êÑÐÈËÔ±·¢ÏÖÕâЩappÀ´×ÔÓÚ·ÖÆçµÄ¿ª·¢ÈËÔ±£¬²¢ÇÒÕ¼ÓÐ·ÖÆçµÄAPKÖ¤Ê鹫Կ£¬µ«ËüÃǵĴúÂëºÍ¶¨Ãû·½Ê½¶¼¼«¶ÈÀàËÆ ¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩÀûÓà ¡£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/android-adware-malware.html


2¡¢×êÑÐÍŶӷ¢ÏÖApple Intel HD 5000´æÔÚ¶à¸öÌáȨ·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Cisco Talos×êÑÐÍŶӷ¢ÏÖApple OSX 10.13.4ÔÚ´¦ÖÃÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬ÆäIntelHD5000ÄÚºËÀ©´óÖдæÔÚ¶à¸öÌáȨ·ì϶£¨CVE-2018-4421ºÍCVE-2018-4456£© ¡£Æ¾¾Ý×êÑÐÈËÔ±µÄÃèÊö£¬VLCýÌåÀûÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç½Ó¼û£¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý ¡£ÕâЩ·ì϶ÊÇÔÚMacBookPro11.4-OS X 10.13.4»·¾³Ï·¢ÏÖµÄ ¡£ÓÉÓÚ·ì϶¿Éͨ¹ýSafari´¥·¢£¬½¨ÒéÓû§¾¡¿ì¸üР¡£

  Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html


3¡¢Adobe°ä²¼2019Äê1Ô°²È«¸üУ¬½¨¸´Á½¸ö°²È«·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash Player°ä²¼ÁË2019Äê1Ô°²È«¸üР¡£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬²¢µ¥Ò»µØ½¨¸´ÁË»úÄÜÎÊÌâºÍbug£¬²¢Î´½¨¸´Èκΰ²È«ÎÊÌâ ¡£Õë¶ÔDigital EditionsµÄ°²È«¸üн¨¸´ÁËÔ½½ç¶Á·ì϶£¨CVE-2018-12817£©£¬¸Ã·ì϶¿Éµ¼ÖÂÐÅϢй¶ ¡£Õë¶ÔConnectµÄ°²È«¸üн¨¸´Á˻ỰÁîÅÆÂ¶Â¶Âí½Å£¨CVE-2018-19718£© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/


4¡¢¹È¸è°ä²¼2019Äê1ÔÂAndroid°²È«²¼¸æ£¬½¨¸´27¸ö·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¹È¸è°ä²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄ°²È«¸üУ¬¹²½¨¸´ÁË27¸ö·ì϶ ¡£ÆäÖа²È«²¹¶¡¼¶±ð2019-01-01Öн¨¸´ÁË13¸ö·ì϶£¬Ô̺¬Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨ·ì϶£¨CVE-2018-9582£¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ ¡£°²È«²¹¶¡¼¶±ð2019-01-05½¨¸´ÁË14¸ö·ì϶£¬Ô̺¬Qualcomm¹ØÔ´×é¼þÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2018-11847£©µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2019-01-01.html


5¡¢ÐÂ×Ô¶¯»¯´¹µö¹¤¾ßModlishka£¬¿ÉÈÆ¹ýË«³É·ÖÈÏÖ¤

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

²¨À¼°²È«×êÑÐÈËÔ±PiotrDuszy¨½ski°ä²¼ÁËÒ»¸öеÄÉøÈë²âÊÔ¹¤¾ß£¬¸Ã¹¤¾ßÄܹ»ÊµÏÖ´¹µö¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«³É·ÖÈÏÖ¤ ¡£¸Ã¹¤¾ß±»¶¨ÃûΪModlishka£¨²¨À¼ÓÒâ˼Ϊó«ò룩£¬ÊÇÒ»¸öÓÃÓÚ´¦ÖõÇÂ¼Ò³ÃæºÍ´¹µöÁ÷Á¿µÄ·´Ïò´úÀí ¡£ËüλÓÚÓû§ºÍÖ¸±êÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬Êܺ¦Õ߽ӹܵ½À´×ÔÓںϷ¨ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬µ«ËùÓÐÁ÷Á¿³ÇÊÐͨ¹ý²¢¼Í¼ÔÚModlishka·þÎñÆ÷ÉÏ ¡£×êÑÐÈËÔ±ÔÚGithubÉϰ䲼Á˸ù¤¾ß ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/


6¡¢Ð±ßÐÅ·¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÍŶӰ䷢ÁËһƪ½éÉÜбßÐÅ·¹¥»÷µÄÂÛÎÄ£¬¸Ã¹¥»÷·½Ê½²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞ¶È£¬ÖØÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ ¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄÜÔ̺¬·¨Ê½¶þ½øÔìÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ ¡£×êÑÐÈËÔ±ÀûÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´²é³­Ò³Ã滺´æ ¡£¸Ã¹¥»÷ÒÑÔÚ±¾µØ³¢ÊÔÖб»Ö¤Ã÷£¬²¢ÇÒÔڿ϶¨Ç°ÌáÏÂÒ²¿ÉÔ¶³ÌÀûÓà ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù