¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190124
Ðû²¼Ê±¼ä 2019-01-24
ConfiantºÍMalwarebytesµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶ÔMacÓû§µÄ´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯×Ô1ÔÂ11ÈÕÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÒþдÊõÀ´·Ö·¢ShlayerľÂí¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¹²¼ì²âµ½ÁËÁè¼Ý19Íò¸ö¶ñÒâ¹ã¸æ£¬£¬£¬£¬£¬£¬£¬Ô¤¼ÆÔ¼ÓÐ100ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹ã¸æÍ¼Æ¬ÖÐÒþ²ØÁ˶ñÒâµÄJavaScript´úÂ룬£¬£¬£¬£¬£¬£¬²¢Î±×°³ÉFlashÉý¼¶À´ÓÕʹÓû§µã»÷×°Öᣡ£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Æ¾Ö¤ÆäÓòÃû½«¹¥»÷Õß³ÆÎªVeryMal£¬£¬£¬£¬£¬£¬£¬µ«²¢Î´»ñµÃ¹¥»÷Õߵĸü¶àÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/malware-in-ad-based-images-targets-mac-users/141115/2¡¢ÃÀ¹úÁìÍÁÇå¾²²¿Ðû²¼¹ØÓÚ½üÆÚDNSÐ®ÖÆ¹¥»÷µÄÔ¤¾¯
ÃÀ¹úÁìÍÁÇå¾²²¿£¨DHS£©Õë¶Ô½üÆÚµÄDNSÐ®ÖÆ¹¥»÷Ðû²¼½ôÆÈÖ¸Á£¬£¬£¬£¬£¬£¬ÒªÇóËùÓеÄÁª°î»ú¹¹ÔÚδÀ´10¸öÊÂÇéÈÕÄÚ±ØÐèÉóºËÆäDNSµÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£DHS³Æ¶à¸öÕþ¸®ÓòÃûÒѾ³ÉΪDNSÐ®ÖÆ¹¥»÷µÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖØ¶¨ÏòºÍ×èµ²ÕâЩÓòÃûµÄÍøÂçºÍÓʼþÁ÷Á¿¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²¿·Ö»¹´ß´Ù¸÷»ú¹¹¸üÐÂÆäDNSÖÎÀíϵͳµÄÕË»§ÃÜÂëºÍʵÑé¶àÖØÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ö®Ç°FireEyeµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬½üÆÚµÄDNSÐ®ÖÆ»î¶¯ÒÉÓëÒÁÀʺڿÍÓйء£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyber.dhs.gov/ed/19-01/3¡¢PHP°ü¹ÜÀíÆ÷PEAR¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬×°ÖÃÎļþ±»ÎÛȾ

PHP°ü¹ÜÀíÆ÷PEAR£¨go-pear.phar£©µÄ¹ÙÍø£¨pear-php.net£©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Æä×°ÖÃÎļþ±»ÎÛȾ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤PEARÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬°üÀ¨¶ñÒâ´úÂëµÄ×°ÖÃÎļþÖÁÉÙÔÚÆä¹ÙÍøÉϱ£´æÁ˰ëÄêµÄʱ¼ä¡£¡£¡£¡£¡£¡£¡£¡£PEARÍŶÓÌåÏÖÕýÔÚ¾ÙÐÐÊӲ죬£¬£¬£¬£¬£¬£¬ÒÔÈ·ÈϹ¥»÷µÄˮƽºÍÈëÇÖÊÇÔõÑù±¬·¢µÄ¡£¡£¡£¡£¡£¡£¡£¡£Ö»ÓÐPEAR¹ÙÍøÉϵÄ×°ÖðüÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬GitHubÉÏÃæµÄ×°ÖÃÎļþδÊÜË𺦡£¡£¡£¡£¡£¡£¡£¡£Óû§ÏÖÔÚ¿ÉÒÔ´ÓGithubÉÏÏÂÔØÐµÄÇå½à°æ±¾1.10.10¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/php-pear-hacked.html4¡¢ÐÂÀÕË÷Èí¼þ¼Ò×åAnatova±»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞ
McAfeeÑо¿ÍŶӷ¢Ã÷Ò»¸öеÄÀÕË÷Èí¼þ¼Ò×åAnatova¡£¡£¡£¡£¡£¡£¡£¡£AnatovaÊÇÔÚÒ»¸ö˽È˵ã¶ÔµãÍøÂçÖз¢Ã÷µÄ£¬£¬£¬£¬£¬£¬£¬Æäͼ±êαװ³ÉÓÎÏ·»òÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þµÄѬȾ¹æÄ£±é²¼È«Çò£¬£¬£¬£¬£¬£¬£¬µ«Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞ£¨°üÀ¨±ÈÀûʱ¡¢µÂ¹ú¡¢·¨¹úºÍÓ¢¹úµÈ£©¡£¡£¡£¡£¡£¡£¡£¡£Anatova¾ßÓÐǿʢµÄ¾²Ì¬ÆÊÎö±£»£»£»¤ÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬°üÀ¨×Ö·û´®Ê¹Óòî±ðµÄÃÜÔ¿À´¼ÓÃÜ£»£»£»90%µÄŲÓö¼ÊǶ¯Ì¬Å²Ó㻣»£»Ö»Ê¹ÓÃÉÙÁ¿·Ç¿ÉÒɵÄWindows APIºÍC±ê×¼¿âµÈ¡£¡£¡£¡£¡£¡£¡£¡£Anatova»¹Ö§³ÖÄ£¿£¿£¿£¿£¿£¿£¿£¿é»¯µÄ¹¦Ð§À©Õ¹¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/happy-new-year-2019-anatova-is-here/5¡¢AppleÐû²¼iOS¡¢macOSµÈ²úÆ·µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î
AppleÐû²¼¶à¿î²úÆ·µÄÐÂÒ»ÂÖÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬°üÀ¨iCloud¡¢Safari 12.0.3¡¢macOS 10.14.3¡¢watchOS 5.1.3¡¢tvOS 12.1.2ºÍiOS 12.1.3µÈ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐiOS 12.1.3ÐÞ¸´Á˿ɵ¼ÖÂRCEµÄÀ¶ÑÀÎó²î£¨CVE-2019-6200£©¡¢FaceTimeÖеÄRCEÎó²î£¨CVE-2019-6224£©ÒÔ¼°ÃÜÂë×Ô¶¯Ìî³ä¹¦Ð§ÖеÄÎó²î£¨CVE-2019-6206£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£macOS 10.14.3ÐÞ¸´ÁËÌáȨÎó²î£¨CVE-2018-4467£©¡¢IntelͼÐÎÇý¶¯ÖеÄRCEÎó²î£¨CVE-2018-4452£©ÒÔ¼°Í¼ÏñºÍ¶¯»´¦Öóͷ£API QuartzCoreÖеÄÄÚ´æÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2019-6220£©¡£¡£¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-fixes-numerous-security-vulnerabilities-in-ios-macos-and-more/6¡¢AdobeÐû²¼±¾ÔµÚÈý¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öXSSÎó²î
±¾ÖܶþAdobeÐû²¼±¾ÔµÚÈý¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öXSSÎó²î¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²î£¨CVE-2018-19726£©ÊÇÒ»¸ö´æ´¢ÐÍXSS£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËËùÓÐÆ½Ì¨ÉϵÄAdobe Experience Manager°æ±¾6.0-6.4¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2018-19727£©ÊÇÒ»¸ö·´ÉäÐÍXSS£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËExperience Manager°æ±¾6.3ºÍ6.4¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Adobe»¹ÔÚÇ徲ͨ¸æAPSB19-03ÖÐÐÞ¸´ÁËExperience Manager FormsÖеĴ洢ÐÍXSSÎó²î£¨CVE-2018-19724£©£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-releases-third-patch-update-of-the-month-to-squash-xss-bugs/ÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ