¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190110
Ðû²¼Ê±¼ä 2019-01-10
Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁ·¢Ã÷85¸ö¹ã¸æÓ¦Ó㬣¬£¬£¬£¬£¬£¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾¡£¡£¡£¡£¡£¡£¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿£¿£¿£¿ØÆ÷µÈ£¬£¬£¬£¬£¬£¬£¬ÔÚ×°±¸ºǫ́¾²Ä¬ÔËÐУ¬£¬£¬£¬£¬£¬£¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§×°±¸¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩappÀ´×ÔÓÚ²î±ðµÄ¿ª·¢Ö°Ô±£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓµÓвî±ðµÄAPKÖ¤Ê鹫Կ£¬£¬£¬£¬£¬£¬£¬µ«ËüÃǵĴúÂëºÍÃüÃû·½·¨¶¼Ê®·ÖÏàËÆ¡£¡£¡£¡£¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/android-adware-malware.html2¡¢Ñо¿ÍŶӷ¢Ã÷Apple Intel HD 5000±£´æ¶à¸öÌáȨÎó²î

Cisco TalosÑо¿ÍŶӷ¢Ã÷Apple OSX 10.13.4ÔÚ´¦Öóͷ£ÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬£¬£¬£¬£¬£¬£¬ÆäIntelHD5000ÄÚºËÀ©Õ¹Öб£´æ¶à¸öÌáȨÎó²î£¨CVE-2018-4421ºÍCVE-2018-4456£©¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÐÎò£¬£¬£¬£¬£¬£¬£¬VLCýÌåÓ¦ÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç»á¼û£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÔÚMacBookPro11.4-OS X 10.13.4ÇéÐÎÏ·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²î¿Éͨ¹ýSafari´¥·¢£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html
3¡¢AdobeÐû²¼2019Äê1ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Á½¸öÇå¾²Îó²î

AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash PlayerÐû²¼ÁË2019Äê1ÔÂÇå¾²¸üС£¡£¡£¡£¡£¡£¡£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬£¬£¬£¬£¬£¬£¬²¢¼òÆÓµØÐÞ¸´ÁËÐÔÄÜÎÊÌâºÍbug£¬£¬£¬£¬£¬£¬£¬²¢Î´ÐÞ¸´ÈκÎÇå¾²ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Õë¶ÔDigital EditionsµÄÇå¾²¸üÐÂÐÞ¸´ÁËÔ½½ç¶ÁÎó²î£¨CVE-2018-12817£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£Õë¶ÔConnectµÄÇå¾²¸üÐÂÐÞ¸´Á˻ỰÁîÅÆÌ»Â¶Îó²î£¨CVE-2018-19718£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/4¡¢¹È¸èÐû²¼2019Äê1ÔÂAndroidÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´27¸öÎó²î

¹È¸èÐû²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´ÁË27¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÇå¾²²¹¶¡¼¶±ð2019-01-01ÖÐÐÞ¸´ÁË13¸öÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨÎó²î£¨CVE-2018-9582£¬£¬£¬£¬£¬£¬£¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ¡£¡£¡£¡£¡£¡£¡£Çå¾²²¹¶¡¼¶±ð2019-01-05ÐÞ¸´ÁË14¸öÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨Qualcomm±ÕÔ´×é¼þÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2018-11847£©µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2019-01-01.html5¡¢ÐÂ×Ô¶¯»¯´¹ÂÚ¹¤¾ßModlishka£¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýË«ÒòËØÈÏÖ¤

²¨À¼Çå¾²Ñо¿Ö°Ô±PiotrDuszy¨½skiÐû²¼ÁËÒ»¸öеÄÉøÍ¸²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß¿ÉÒÔʵÏÖ´¹ÂÚ¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«ÒòËØÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß±»ÃüÃûΪModlishka£¨²¨À¼Ó£¬£¬£¬£¬£¬£¬Òâ˼Ϊó«ò룩£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÓÃÓÚ´¦Öóͷ£µÇÂ¼Ò³ÃæºÍ´¹ÂÚÁ÷Á¿µÄ·´ÏòÊðÀí¡£¡£¡£¡£¡£¡£¡£ËüλÓÚÓû§ºÍÄ¿µÄÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬£¬£¬£¬£¬£¬£¬Êܺ¦ÕßÎüÊÕµ½À´×ÔÓÚÕýµ±ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬µ«ËùÓÐÁ÷Á¿¶¼»áͨ¹ý²¢¼Í¼ÔÚModlishkaЧÀÍÆ÷ÉÏ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼Á˸ù¤¾ß¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/6¡¢Ð±ßÐŵÀ¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ

Ñо¿ÍŶӽÒÏþÁËһƪÏÈÈÝбßÐŵÀ¹¥»÷µÄÂÛÎÄ£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷·½·¨²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄܰüÀ¨³ÌÐò¶þ½øÖÆÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ê¹ÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´¼ì²éÒ³Ãæ»º´æ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÑÔÚÍâµØÊµÑéÖб»Ö¤Êµ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÒ»¶¨Ìõ¼þÏÂÒ²¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí