¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190110

Ðû²¼Ê±¼ä 2019-01-10
1¡¢Google PlayϼÜ85¸ö¹ã¸æapp£¬£¬£¬£¬£¬ £¬£¬Ñ¬È¾Ô¼900ÍòAndroidÓû§

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁ·¢Ã÷85¸ö¹ã¸æÓ¦Ó㬣¬£¬£¬£¬ £¬£¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾¡£¡£¡£¡£¡£¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿ £¿£¿£¿£¿ £¿£¿ØÆ÷µÈ£¬£¬£¬£¬£¬ £¬£¬ÔÚ×°±¸ºǫ́¾²Ä¬ÔËÐУ¬£¬£¬£¬£¬ £¬£¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§×°±¸¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩappÀ´×ÔÓÚ²î±ðµÄ¿ª·¢Ö°Ô±£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒÓµÓвî±ðµÄAPKÖ¤Ê鹫Կ£¬£¬£¬£¬£¬ £¬£¬µ«ËüÃǵĴúÂëºÍÃüÃû·½·¨¶¼Ê®·ÖÏàËÆ¡£¡£¡£¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓᣡ£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/android-adware-malware.html


2¡¢Ñо¿ÍŶӷ¢Ã÷Apple Intel HD 5000±£´æ¶à¸öÌáȨÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Cisco TalosÑо¿ÍŶӷ¢Ã÷Apple OSX 10.13.4ÔÚ´¦Öóͷ£ÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬£¬£¬£¬£¬ £¬£¬ÆäIntelHD5000ÄÚºËÀ©Õ¹Öб£´æ¶à¸öÌáȨÎó²î£¨CVE-2018-4421ºÍCVE-2018-4456£©¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÐÎò£¬£¬£¬£¬£¬ £¬£¬VLCýÌåÓ¦ÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç»á¼û£¬£¬£¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÔÚMacBookPro11.4-OS X 10.13.4ÇéÐÎÏ·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²î¿Éͨ¹ýSafari´¥·¢£¬£¬£¬£¬£¬ £¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£

  Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html


3¡¢AdobeÐû²¼2019Äê1ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬ £¬£¬ÐÞ¸´Á½¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash PlayerÐû²¼ÁË2019Äê1ÔÂÇå¾²¸üС£¡£¡£¡£¡£¡£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬£¬£¬£¬£¬ £¬£¬²¢¼òÆÓµØÐÞ¸´ÁËÐÔÄÜÎÊÌâºÍbug£¬£¬£¬£¬£¬ £¬£¬²¢Î´ÐÞ¸´ÈκÎÇå¾²ÎÊÌâ¡£¡£¡£¡£¡£¡£Õë¶ÔDigital EditionsµÄÇå¾²¸üÐÂÐÞ¸´ÁËÔ½½ç¶ÁÎó²î£¨CVE-2018-12817£©£¬£¬£¬£¬£¬ £¬£¬¸ÃÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£¡£¡£¡£¡£¡£Õë¶ÔConnectµÄÇå¾²¸üÐÂÐÞ¸´Á˻ỰÁîÅÆÌ»Â¶Îó²î£¨CVE-2018-19718£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/


4¡¢¹È¸èÐû²¼2019Äê1ÔÂAndroidÇ徲ͨ¸æ£¬£¬£¬£¬£¬ £¬£¬ÐÞ¸´27¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¹È¸èÐû²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄÇå¾²¸üУ¬£¬£¬£¬£¬ £¬£¬¹²ÐÞ¸´ÁË27¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖÐÇå¾²²¹¶¡¼¶±ð2019-01-01ÖÐÐÞ¸´ÁË13¸öÎó²î£¬£¬£¬£¬£¬ £¬£¬°üÀ¨Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨÎó²î£¨CVE-2018-9582£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ¡£¡£¡£¡£¡£¡£Çå¾²²¹¶¡¼¶±ð2019-01-05ÐÞ¸´ÁË14¸öÎó²î£¬£¬£¬£¬£¬ £¬£¬°üÀ¨Qualcomm±ÕÔ´×é¼þÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2018-11847£©µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2019-01-01.html


5¡¢ÐÂ×Ô¶¯»¯´¹ÂÚ¹¤¾ßModlishka£¬£¬£¬£¬£¬ £¬£¬¿ÉÈÆ¹ýË«ÒòËØÈÏÖ¤

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

²¨À¼Çå¾²Ñо¿Ö°Ô±PiotrDuszy¨½skiÐû²¼ÁËÒ»¸öеÄÉøÍ¸²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬ £¬£¬¸Ã¹¤¾ß¿ÉÒÔʵÏÖ´¹ÂÚ¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«ÒòËØÈÏÖ¤¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß±»ÃüÃûΪModlishka£¨²¨À¼Ó£¬£¬£¬£¬ £¬£¬Òâ˼Ϊó«ò룩£¬£¬£¬£¬£¬ £¬£¬ÊÇÒ»¸öÓÃÓÚ´¦Öóͷ£µÇÂ¼Ò³ÃæºÍ´¹ÂÚÁ÷Á¿µÄ·´ÏòÊðÀí¡£¡£¡£¡£¡£¡£ËüλÓÚÓû§ºÍÄ¿µÄÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬£¬£¬£¬£¬ £¬£¬Êܺ¦ÕßÎüÊÕµ½À´×ÔÓÚÕýµ±ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬£¬£¬£¬£¬ £¬£¬µ«ËùÓÐÁ÷Á¿¶¼»áͨ¹ý²¢¼Í¼ÔÚModlishkaЧÀÍÆ÷ÉÏ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼Á˸ù¤¾ß¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/


6¡¢Ð±ßÐŵÀ¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿ÍŶӽÒÏþÁËһƪÏÈÈÝбßÐŵÀ¹¥»÷µÄÂÛÎÄ£¬£¬£¬£¬£¬ £¬£¬¸Ã¹¥»÷·½·¨²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞÖÆ£¬£¬£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄܰüÀ¨³ÌÐò¶þ½øÖÆÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ê¹ÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´¼ì²éÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÑÔÚÍâµØÊµÑéÖб»Ö¤Êµ£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒÔÚÒ»¶¨Ìõ¼þÏÂÒ²¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí