¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190110

Ðû²¼Ê±¼ä 2019-01-10
1¡¢Google PlayϼÜ85¸ö¹ã¸æapp£¬£¬£¬ £¬£¬£¬Ñ¬È¾Ô¼900ÍòAndroidÓû§

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁ·¢Ã÷85¸ö¹ã¸æÓ¦Ó㬣¬£¬ £¬£¬£¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾¡£¡£¡£¡£¡£¡£¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿£¿£¿£¿£¿ØÆ÷µÈ£¬£¬£¬ £¬£¬£¬ÔÚ×°±¸ºǫ́¾²Ä¬ÔËÐУ¬£¬£¬ £¬£¬£¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§×°±¸¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩappÀ´×ÔÓÚ²î±ðµÄ¿ª·¢Ö°Ô±£¬£¬£¬ £¬£¬£¬²¢ÇÒÓµÓвî±ðµÄAPKÖ¤Ê鹫Կ£¬£¬£¬ £¬£¬£¬µ«ËüÃǵĴúÂëºÍÃüÃû·½·¨¶¼Ê®·ÖÏàËÆ¡£¡£¡£¡£¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓᣡ£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/android-adware-malware.html


2¡¢Ñо¿ÍŶӷ¢Ã÷Apple Intel HD 5000±£´æ¶à¸öÌáȨÎó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Cisco TalosÑо¿ÍŶӷ¢Ã÷Apple OSX 10.13.4ÔÚ´¦Öóͷ£ÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬£¬£¬ £¬£¬£¬ÆäIntelHD5000ÄÚºËÀ©Õ¹Öб£´æ¶à¸öÌáȨÎó²î£¨CVE-2018-4421ºÍCVE-2018-4456£©¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÐÎò£¬£¬£¬ £¬£¬£¬VLCýÌåÓ¦ÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç»á¼û£¬£¬£¬ £¬£¬£¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÔÚMacBookPro11.4-OS X 10.13.4ÇéÐÎÏ·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²î¿Éͨ¹ýSafari´¥·¢£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£¡£

  Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html


3¡¢AdobeÐû²¼2019Äê1ÔÂÇå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´Á½¸öÇå¾²Îó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash PlayerÐû²¼ÁË2019Äê1ÔÂÇå¾²¸üС£¡£¡£¡£¡£¡£¡£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬£¬£¬ £¬£¬£¬²¢¼òÆÓµØÐÞ¸´ÁËÐÔÄÜÎÊÌâºÍbug£¬£¬£¬ £¬£¬£¬²¢Î´ÐÞ¸´ÈκÎÇå¾²ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Õë¶ÔDigital EditionsµÄÇå¾²¸üÐÂÐÞ¸´ÁËÔ½½ç¶ÁÎó²î£¨CVE-2018-12817£©£¬£¬£¬ £¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£Õë¶ÔConnectµÄÇå¾²¸üÐÂÐÞ¸´Á˻ỰÁîÅÆÌ»Â¶Îó²î£¨CVE-2018-19718£©¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/


4¡¢¹È¸èÐû²¼2019Äê1ÔÂAndroidÇ徲ͨ¸æ£¬£¬£¬ £¬£¬£¬ÐÞ¸´27¸öÎó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

¹È¸èÐû²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄÇå¾²¸üУ¬£¬£¬ £¬£¬£¬¹²ÐÞ¸´ÁË27¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÇå¾²²¹¶¡¼¶±ð2019-01-01ÖÐÐÞ¸´ÁË13¸öÎó²î£¬£¬£¬ £¬£¬£¬°üÀ¨Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨÎó²î£¨CVE-2018-9582£¬£¬£¬ £¬£¬£¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ¡£¡£¡£¡£¡£¡£¡£Çå¾²²¹¶¡¼¶±ð2019-01-05ÐÞ¸´ÁË14¸öÎó²î£¬£¬£¬ £¬£¬£¬°üÀ¨Qualcomm±ÕÔ´×é¼þÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2018-11847£©µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2019-01-01.html


5¡¢ÐÂ×Ô¶¯»¯´¹ÂÚ¹¤¾ßModlishka£¬£¬£¬ £¬£¬£¬¿ÉÈÆ¹ýË«ÒòËØÈÏÖ¤

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

²¨À¼Çå¾²Ñо¿Ö°Ô±PiotrDuszy¨½skiÐû²¼ÁËÒ»¸öеÄÉøÍ¸²âÊÔ¹¤¾ß£¬£¬£¬ £¬£¬£¬¸Ã¹¤¾ß¿ÉÒÔʵÏÖ´¹ÂÚ¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«ÒòËØÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß±»ÃüÃûΪModlishka£¨²¨À¼Ó£¬£¬ £¬£¬£¬Òâ˼Ϊó«ò룩£¬£¬£¬ £¬£¬£¬ÊÇÒ»¸öÓÃÓÚ´¦Öóͷ£µÇÂ¼Ò³ÃæºÍ´¹ÂÚÁ÷Á¿µÄ·´ÏòÊðÀí¡£¡£¡£¡£¡£¡£¡£ËüλÓÚÓû§ºÍÄ¿µÄÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬£¬£¬ £¬£¬£¬Êܺ¦ÕßÎüÊÕµ½À´×ÔÓÚÕýµ±ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬£¬£¬ £¬£¬£¬µ«ËùÓÐÁ÷Á¿¶¼»áͨ¹ý²¢¼Í¼ÔÚModlishkaЧÀÍÆ÷ÉÏ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼Á˸ù¤¾ß¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/


6¡¢Ð±ßÐŵÀ¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿ÍŶӽÒÏþÁËһƪÏÈÈÝбßÐŵÀ¹¥»÷µÄÂÛÎÄ£¬£¬£¬ £¬£¬£¬¸Ã¹¥»÷·½·¨²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞÖÆ£¬£¬£¬ £¬£¬£¬Ö÷ÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄܰüÀ¨³ÌÐò¶þ½øÖÆÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ê¹ÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´¼ì²éÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÑÔÚÍâµØÊµÑéÖб»Ö¤Êµ£¬£¬£¬ £¬£¬£¬²¢ÇÒÔÚÒ»¶¨Ìõ¼þÏÂÒ²¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/


ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí