¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181010

Ðû²¼Ê±¼ä 2018-10-10

1¡¢GoogleÐÂÕþ²ßÖ»ÔÊÐíAndroidĬÈÏÓ¦Óûá¼ûͨ»°¼Í¼ºÍ¶ÌÐÅ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ΪÁ˱ÜÃâµÚÈý·½Ó¦ÓÃÀÄÓÃÓû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Google×ö³öÁ˼¸ÏîÖ÷ÒªµÄ¸ü¸Ä¡£¡£¡£¡£GoogleÔÚGoogle PlayµÄ¿ª·¢ÕßÕþ²ßÖÐмÓÈëÁËÒ»Ìõ¹æÔò£¬£¬£¬£¬£¬£¬£¬¸Ã¹æÔòÏÖÔÚ½öÔÊÐíAndroidµÄĬÈÏÓ¦Óûá¼ûÓû§µÄͨ»°¼Í¼ºÍ¶ÌÐÅ¡£¡£¡£¡£Google»¹ÏÞÖÆÁ˶ÔGmail APIµÄ»á¼û£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÖ»ÓÐÖ±½ÓÔöÇ¿µç×ÓÓʼþ¹¦Ð§µÄÓ¦Óã¨ÈçÓʼþ¿Í»§¶Ë¡¢Óʼþ±¸·ÝЧÀ͵ȣ©²Å¿ÉÒÔ»á¼û¸ÃAPI¡£¡£¡£¡£Google»¹¸üÐÂÁËÆäÕË»§È¨ÏÞϵͳ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚµÚÈý·½Ó¦ÓÃÔÚÉêÇë»á¼ûGoogleÕË»§Êý¾Ýʱ£¬£¬£¬£¬£¬£¬£¬ÏµÍ³»áÕë¶Ôÿһ¸öȨÏÞµ¥¶À¾ÙÐÐÉêÇë¡£¡£¡£¡£¿£¿£¿£¿£¿ £¿£¿£¿ª·¢Õß½«ÓÐ90ÌìµÄʱ¼äÀ´¸üÐÂÆäÓ¦ÓúÍЧÀÍ¡£¡£¡£¡£


   Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/android-app-privacy.html

2¡¢½ðÑÅÍØµÄ±¨¸æÅú×¢2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤½ðÑÅÍØµÄ×îÐÂÑо¿£¬£¬£¬£¬£¬£¬£¬2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬¹²ÓÐ45ÒÚÌõÊý¾Ý¼Í¼Ô⵽й¶¡£¡£¡£¡£Óë2017ÄêͬÆÚÏà±È£¬£¬£¬£¬£¬£¬£¬É¥Ê§¡¢±»ÇÔÒÔ¼°Ð¹Â¶µÄÊý¾ÝÔöÌíÁË133%¡£¡£¡£¡£Ö»¹ÜÊý¾Ýй¶ÊÂÎñµÄÊýÄ¿ÂÔÓÐϽµ£¬£¬£¬£¬£¬£¬£¬µ«ÊÂÎñµÄÑÏÖØË®Æ½ÓÐËùÔöÌí¡£¡£¡£¡£ÆäÖÐ6ÆðÉ罻ýÌåÊý¾Ýй¶ÊÂÎñµ¼ÖÂÁËÁè¼Ý56%µÄÊý¾Ýй¶¡£¡£¡£¡£Êý¾Ýй¶µÄ×î³£¼ûÔµ¹ÊÔ­ÓÉÊÇÍⲿÒòËØ£¨Õ¼56%£©¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2018/10/09/data-breaches-2018/

3¡¢Î¢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´49¸öÇå¾²Îó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´Windows¡¢Edge¡¢IEµÈ¶à¿î²úÆ·ÖеÄ49¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨12¸ö¸ßΣÎó²î¡£¡£¡£¡£½ÏΪÑÏÖØµÄÎó²î°üÀ¨WindowsÖеÄÌáȨÎó²î£¨CVE-2018-8453£©¡¢MSXMLÆÊÎöÆ÷×é¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8494£©¡¢JetÊý¾Ý¿âÒýÇæÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8423£©¡¢WindowsÄÚºËÖеÄÌáȨÎó²î£¨CVE-2018-8497£©ÒÔ¼°Azure IoT Hub SDKÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8531£©¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/microsoft-windows-update.html

4¡¢AppleÐû²¼ÐÂÒ»ÂÖiOSºÍiCloudÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


AppleÐû²¼Õë¶ÔiOSºÍiCloudµÄÐÂÒ»ÂÖÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î¡£¡£¡£¡£ÆäÖÐÔÚiOS 12.0.1ÖÐÐÞ¸´ÁËÁ½¸öÃÜÂëÈÆ¹ýÎó²î£¨CVE-2018-4380ºÍCVE-2018-4379£©¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±Jose Rodriguez·¢Ã÷ÁËÕâÁ½¸öÎó²î£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁËÏà¹ØÎó²îʹÓÃÊÓÆµ¡£¡£¡£¡£Apple»¹ÔÚiCloud for Windows 7.7.12ÖÐÐÞ¸´ÁË19¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨13¸ö¸ßΣµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-releases-security-updates-for-ios-and-icloud-fixes-passcode-bypass/

5¡¢Annapolis LibraryÔâÒøÐÐľÂíEmotetѬȾ£¬£¬£¬£¬£¬£¬£¬½ü5000Óû§ÊÜÓ°Ïì


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹úÂíÀïÀ¼Öݰ²Äɲ¨Àû˹ÊеÄÒ»¸ö¹«¹²Í¼Êé¹ÝÔâÒøÐÐľÂíEmotetѬȾ£¬£¬£¬£¬£¬£¬£¬Ô¼5000ÃûÓû§¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£¡£Emotet»áÇÔÈ¡Óû§µÄµÇ¼ƾ֤¡¢Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©ÒÔ¼°ÐÅÓÿ¨ÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬£¬ËäÈ»¸ÃͼÊé¹ÝÌåÏÖûÓпͻ§ÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬µ«ÔÚ9ÔÂ17ÈÕÖÁ10ÔÂ4ÈÕʱ´úʹÓÃÁ˸ÃͼÊé¹ÝµÄ¹«¹²ÅÌËã»úµÄ¿Í»§Ó¦¸ÃСÐÄÆäÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/annapolis-library-computers-infected-with-emotet-almost-5k-customers-affected-523119.shtml

6¡¢Ñо¿Ö°Ô±·¢Ã÷ÈëÇÖMikroTik·ÓÉÆ÷µÄй¥»÷ÊÖÒÕ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Tenable ResearchµÄÑо¿Ö°Ô±·¢Ã÷ÈëÇÖMikroTik·ÓÉÆ÷µÄй¥»÷ÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÒ»¸öÒÑÖªµÄÎó²î±äµÃ±ÈÒÔǰÒÔΪµÄÔ½·¢Î£ÏÕ¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-14847£©Ó°ÏìWinbox×é¼þ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔ¶³ÌÖ´ÐдúÂë²¢»ñµÃroot shell¡£¡£¡£¡£»£»£»£»£»£»»¾ä»°Ëµ£¬£¬£¬£¬£¬£¬£¬ÐµĹ¥»÷ÊÖÒÕʹµÃδ¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔÈëÇÖRouterOS£¬£¬£¬£¬£¬£¬£¬°²ÅŶñÒâÈí¼þ»òÈÆ¹ý·ÓÉÆ÷µÄ·À»ðǽ¡£¡£¡£¡£¸ÃÎó²îÒÑÓÚ2018Äê4Ô±»ÐÞ¸´¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/76940/hacking/mikrotik-routers-attack-poc.html

ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí