ÈüÁé˼SoC´æÔÚ佨¸´µÄËÁÒâ´úÂëÖ´Ðзì϶£»¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÚ¿Æ­Ëðʧ104ÍòÃÀÔª

°ä²¼¹¦·ò 2019-08-21
1¡¢¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÚ¿Æ­Ëðʧ104ÍòÃÀÔª

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¾Ý±¾µØÐÂÎű¨Â·£¬¼ÓÄôóÈøË¹¿¨Í¨ÊгÉΪBECÚ¿Æ­µÄ×îÐÂÊܺ¦Õß ¡£·¸×ï·Ö×Ó¼ÙÒâ°¬Â×¹¹Öþ¹«Ë¾£¨Allan Construction£©µÄÊ×ϯ²ÆÕþ¹Ù£¬ÏòÊÐÕþ²ÆÕþ²¿ÃŵÄÔ±¹¤·¢Ë͵ç×ÓÓʼþÒªÇó¸ü¸ÄÒøÐÐÕË»§ºÅÂë²¢¸¶¿î ¡£¸Ã¹«Ë¾Ç©¶¨ÁËÒ»×ùÇÅÁºµÄ½¨¸´¹¤³ÌºÏͬ ¡£²ÆÕþÈËÔ±Òò¶øÔÚ8ÔÂ7ÈÕ»ò8ÈÕ×óÓÒÖ§¸¶ÁË104ÍòÃÀÔª ¡£8ÔÂ12ÈÕÕâһȦÌ×±»·¢ÏÖ£¬·¨ÂÉ»ú¹¹ºÍ½ðÈÚµÐÔÖÊÔͼ³·ÏúÂòÂô²¢ÊÕ»Ø×ʽð£¬Ä¿Ç°ÒÑÊÕ»ØÔ¼4ÍòÃÀÔª ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/scammer-tricks-city-into-1-million-wire-transfer/


2¡¢ºÚ¿ÍÀûÓÃÐéαNordVPNÍøÕ¾·Ö·¢ÒøÐÐľÂíBolik


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÒøÐÐľÂíBolik±³ºóµÄ¹¥»÷ÕßÓÖ»ØÀ´ÁË£¬ÕâÒ»´ÎËûÃÇͨ¹ýÐéαµÄNordVPNÍøÕ¾³ÖÐø·Ö·¢¶ñÒâÈí¼þ ¡£¸ÃµÁ°æÍøÕ¾nord-vpn[.]clubÏÕЩÃÀÂúµØ¿Ë¡Á˹ٷ½ÍøÕ¾NordVPN.com£¬²¢ÇÒÓµÓкϷ¨µÄSSLÖ¤Ê飬¸ÃÖ¤ÊéÓÉÊ¢¿ªÊ½Ö¤ÊéÐû¸æ»ú¹¹Let's EncryptÓÚ8ÔÂ3ÈÕÐû¸æ£¬ÓÐЧÆÚµ½11ÔÂ1ÈÕ ¡£win32.bolik.2ľÂíÊÇbolik.1µÄ¸Ä½ø°æ±¾£¬ÓµÓжà×é¼þ¶à̬ÐÔÎļþ²¡¶¾µÄ¸öÐÔ£¬¹¥»÷Õß¿ÉÀûÓøÃľÂíÖ´ÐÐWeb×¢Èë¡¢Á÷Á¿½Ø»ñ¡¢¼üÅ̼ͼÒÔ¼°´Ó·ÖÆçµÄÒøÐпͻ§¶ËÇÔÊØÐÅÏ¢ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-use-fake-nordvpn-website-to-deliver-banking-trojan/


3¡¢¹È¸èNestÖÇÄÜÉãÏñÍ·±»ÆØ´æÔÚ8¸ö°²È«·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹È¸èNest Cam IQÊÒÄÚÉãÏñÍ·±»ÆØ´æÔÚ8¸ö°²È«·ì϶£¬¿ÉÓÃÓÚ½Ù³Ö»ò·ÛËéÉ豸 ¡£ÕâЩ·ì϶ÊÇÓÉ˼¿ÆTalos×êÑÐÈËÔ±Lilith WyattºÍClaudio Bozzato·¢ÏÖµÄ ¡£·ì϶ÁìÓòÔ̺¬DoS£¨CVE-2019-5043£©¡¢ÐÅϢй¶£¨CVE-2019-5034ºÍCVE-2019-5040£©¡¢ËÁÒâ´úÂëÖ´ÐУ¨CVE-2019-5038ºÍCVE-2019-5039£©¡¢¿Éµ¼Ö±©Á¦ÆÆ½â¹¥»÷µÄ·ì϶£¨CVE-2019-5035£©ÒÔ¼°Ö¤Êé¼ÓÔØÃýÎó£¨CVE-2019-5036ºÍCVE-2019-5037£© ¡£¹È¸è°µÊ¾ÒѾ­½¨¸´ÁËÕâЩ·ì϶£¬½¨¸´²¹¶¡½«×Ô¶¯ÍÆË͵½É豸ÖÐ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/vulnerabilities-in-google-nest-cam-iq-can-be-used-to-hijack-your-camera/


4¡¢VideoLan°ä²¼VLC²¥·ÅÆ÷¸üУ¬½¨¸´13¸ö·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


VideoLan°ä²¼VLCýÌå²¥·ÅÆ÷µÄа汾3.0.8£¬½¨¸´ÁË13¸ö°²È«·ì϶ ¡£·ì϶ÁìÓòÔ̺¬»º³åÇøÒç³ö¡¢use-after-free¡¢¿ÕÖ¸Õë½âÒýÓÃÒÔ¼°³ýÊýΪ0 ¡£´ó²¿ÃÅ·ì϶¶¼ÊÇÓÉVLC¿ª·¢ÈËÔ±Ö±½Ó·¢ÏÖµÄ ¡£Æ¾¾ÝVideoLanµÄ°²È«²¼¸æ£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§´ò¿ª¶ñÒâÎļþÀ´´¥·¢±ÀÀ£»òÔڵǼÓû§µÄ°²È«¸ßµÍÎÄÖÐÖ´ÐдúÂë ¡£¸Ãа汾¿ÉÓÃÓÚWindows¡¢MacºÍLinuxƽ̨£¬½¨ÒéÓû§¾¡¿ì¸üР¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vlc-media-player-308-released-with-13-security-fixes/

5¡¢ÈüÁé˼SoC´æÔÚ佨¸´µÄËÁÒâ´úÂëÖ´Ðзì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


F-Secure·¢ÏÖXilinx£¨ÈüÁé˼£©µÄZynq UltraScale+SOC´æÔÚÁ½¸ö·ì϶ ¡£¸ÃϵÁеIJúÆ·Ô̺¬SOC¡¢MPSOCÒÔ¼°RFSOC£¬Í¨³£ÓÃÓÚÆû³µ¡¢º½¿Õ¡¢Ïû·Ñµç×Ó¡¢¹¤ÒµÒÔ¼°¾üʲ¿¼þÖÐ ¡£F-Secure°µÊ¾£¬ÕâЩSOCµÄ¼ÓÃܰ²È«Ê赼ģʽÔ̺¬Á½¸ö·ì϶£¬ÆäÖÐÒ»¸ö·ì϶ÎÞ·¨Í¨¹ýÈí¼þ¸üн¨¸´£¬±ØÒª¹©¸øÉÌÌṩ¡°ÐµÄSilicon°æ±¾¡± ¡£ÀûÓÃÕâÁ½¸ö·ì϶±ØÒªÎïÀí½Ó¼ûȨÏÞ ¡£ÈüÁé˼°µÊ¾ËüÅú¸ÄÁ˼¼ÊõÊֲᣬ½¨Òé¿Í»§Ê¹Óøü°²È«µÄÓ²¼þ¸ùÐÅÀµ£¨Hwrot£©°²È«Ê赼ģʽ£¬¶ø²»ÊÇֻʹÓýÏÈõµÄ¼ÓÃÜģʽ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/unpatchable-security-flaw-found-in-popular-soc-boards/


6¡¢×êÑÐÈËÔ±¹«¿ª°ä²¼iOS 12.4µÄÃâ·ÑÔ½Óü¹¤¾ß

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


һλÄäÃûµÄ×êÑÐÈËÔ±ÒÔpwn20wndµÄ±ðºÅÔÚGithubÉÏÃâ·Ñ°ä²¼ÁËiOS 12.4µÄÔ½Óü¹¤¾ß ¡£¸Ã¹¤¾ßÀûÓÃÁËiOSÄÚºËÖеÄÒ»¸öUAF·ì϶£¨CVE-2019-8605£©£¬´Ë·ìÏ¶ÔøÔÚiOS 12.3Öб»½¨¸´£¬µ«Æ»¹ûÔÚiOS 12.4ÖгÁÐÂÒýÈëÁ˸÷ì϶ ¡£ÐµÄÔ½Óü¹¤¾ß¿ÉÔÚ¸üеÄiOSÉ豸ÉϹ¤×÷£¬Ô̺¬iphone xs¡¢xs maxºÍxr»ò2019 iPad miniºÍipad air£¬²»ÂÛ¸ÃÉ豸ÊÇÔËÐÐiOS 12.4»¹ÊÇiOS 12.2»ò¸üÔç°æ±¾£¬µ«ÔÚiOS 12.3ÉÏÎÞ·¨¹¤×÷ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/ios-iphone-jailbreak.html