¡¾Çå¾²²¥±¨¡¿AppleÈ϶¨FacebookµÄVPNÓ¦ÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß
Apple³ÆFacebookµÄÒÆ¶¯VPNÓ¦ÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß£¬£¬FacebookÒѾ´ÓApp StoreÖÐϼÜÁ˸ÃÓ¦Óᣡ£¡£¡£Onavo ProtectÊÇÒ»¸öÃâ·ÑµÄVPN¹¤¾ß£¬£¬¸Ã¹¤¾ß¿ÉÒÔ×ÊÖúFacebookÍøÂçÓû§µÄÁ÷Á¿Êý¾Ý£¬£¬ÒÔÏàʶÓû§ÔõÑùʹÓõÚÈý·½app¡£¡£¡£¡£ÏÖÔڸù¤¾ßÒÑÔÚiOSºÍAndroid×°±¸ÉÏÏÂÔØÁËÁè¼Ý3300Íò´Î£¬£¬²¢ÇÒÒÀÈ»±£´æÓÚGoogle PlayÊÐËÁÖС£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/facebook-vpn-app-apple-store.html
¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿ÍŶӷ¢Ã÷ÐÂAndroidÌØ¹¤Èí¼þ¿ò¼ÜTriout
BitdefenderµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеġ¢¹¦Ð§Ç¿Ê¢µÄAndroid¶ñÒâÈí¼þ¿ò¼ÜTriout¡£¡£¡£¡£Triout¿ÉÒÔÂ¼ÖÆÍ¨»°¡¢¼à¿Ø¶ÌÐÅ¡¢ÇÔÈ¡ÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÍøÂ綨λÊý¾ÝµÈ£¬£¬ÆäËÆºõ±»ÓÃÓÚÓÐÕë¶ÔÐÔµÄÌØ¹¤»î¶¯¡£¡£¡£¡£Triout×îÔç·ºÆðÓÚ2018Äê5ÔÂ15ÈÕ£¬£¬Ö÷Òª·ºÆðÔÚÒÔÉ«ÁС£¡£¡£¡£Ñо¿Ö°Ô±»¹²»ÇåÎúTrioutµÄÈö²¥·½·¨ºÍ×°ÖôÎÊý£¬£¬ÒÔ¼°Æä±³ºóµÄ¹¥»÷Õß¡£¡£¡£¡£TrioutûÓÐʹÓûìÏýÊÖÒÕ£¬£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þ¿ÉÄÜ»¹ÔÚ¿ª·¢Àú³ÌÖС£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/android-malware-spyware.html
¡¾¹¥»÷ÊÂÎñ¡¿Ñо¿ÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÉúÒâËù
¿¨°Í˹»ùʵÑéÊÒÑо¿ÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨µÄITϵͳ£¬£¬²¢°²ÅÅÁËÔ¶¿ØÄ¾ÂíFallchillÒÔ¼°Ò»¸öMac¶ñÒâÈí¼þ¡£¡£¡£¡£Õâ¿ÉÄÜÊǸÃ×é֯ʹÓõÄÊ׸öMac¶ñÒâÈí¼þ¡£¡£¡£¡£Ä¾Âí»¯µÄ¸Ã¼ÓÃÜÇ®±ÒÉúÒâÈí¼þÓÉÓÐÓõÄÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû£¬£¬ÕâʹµÃËü¿ÉÒÔÈÆ¹ýÇ徲ɨÃè¡£¡£¡£¡£¿£¿¨°Í˹»ùûÓÐ͸¶±»ÈëÇֵļÓÃÜÇ®±ÒÉúÒâËùµÄÃû³Æ£¬£¬²¢³ÆÃ»ÓÐÈκξ¼ÃËðʧ±¬·¢¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/lazarus-group-deploys-its-first-mac-malware-in-cryptocurrency-exchange-hack/
¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±ÔÚOpenSSHÖз¢Ã÷Ò»±£´æ20ÄêµÄÇå¾²Îó²î
Qualys¹«Ë¾Çå¾²Ñо¿Ö°Ô±·¢Ã÷OpenSSH¿Í»§¶Ë±£´æÒ»¸öÐÝÃßµÄÇå¾²Îó²î£¬£¬¸ÃÎó²î£¨CVE-2018-15473£©Ó°ÏìÁËÒÑÍù¶þÊ®ÄêÐû²¼µÄËùÓÐOpenSSH¿Í»§¶Ë°æ±¾¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÍÆ²âSSHЧÀÍÆ÷ÉϵÄÓÐÓÃÓû§Ãû£¬£¬ÓÉÓÚOpenSSH¿Í»§¶Ë±»Ç¶Èëµ½´ó×ÚÈí¼þºÍÓ²¼þ×°±¸ÖУ¬£¬ÐÞ¸´³ÌÐò¿ÉÄÜ񻮮·ÑÊýÔÂÉõÖÁÊýÄê²Å»ªµÖ´ïËùÓеÄϵͳÖС£¡£¡£¡£Ñо¿Ö°Ô±Åû¶Á˸ÃÎó²îµÄÏà¹ØPoC´úÂë¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vulnerability-affects-all-openssh-versions-released-in-the-past-two-decades/
¡¾Îó²î²¹¶¡¡¿Î¢ÈíÕë¶ÔIntel CPUµÄL1TFÎó²îÐû²¼Î¢´úÂë¸üÐÂ
±¾ÖÜ΢ÈíÌṩÁËIntel CPUµÄÐÂÒ»ÂÖ΢´úÂë¸üУ¬£¬ÓÃÓÚÐÞ¸´×î½üµÄForeshadow/L1TFÎó²î¡£¡£¡£¡£Foreshadow/L1TFÎó²î£¨CVE-2018-3615¡¢CVE-2018-3620ºÍCVE-2018-3646£©¿ÉÔÊÐí¹¥»÷Õß»á¼ûÊܱ£»£»£»£»¤ÄÚ´æÖеÄDZÔÚÃô¸ÐÊý¾Ý£¬£¬IntelµÄXeonºÍCoreϵÁд¦Öóͷ£Æ÷Êܵ½Ó°Ïì¡£¡£¡£¡£Î¢Èí±¾ÖÜÐû²¼ÁËÎå¸ö¸üУ¬£¬°üÀ¨KB4346084¡¢KB4346085¡¢KB4346086¡¢KB4346087ºÍKB4346088¡£¡£¡£¡£ForeshadowÎó²îµÄ²¹¶¡²»»á¶ÔÏûºÄÕßPCµÄÐÔÄܱ¬·¢ÏÔ×ÅÓ°Ï죬£¬µ«Ä³Ð©Êý¾ÝÖÐÐĵÄÊÂÇé¸ºÔØ¿ÉÄ᷺ܻÆðÐÔÄÜϽµ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/microsoft-releases-intel-microcode-patches-foreshadow-flaws
¡¾Êý¾Ýй¶¡¿Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶
Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª°îÕþ¸®µÄÖÒÑÔ£¬£¬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£ÏÖÔÚÔÚ°µÍøÉÏÏúÊÛµÄÏà¹ØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£¡£¡£¡£ÊÓ²ìÅú×¢£¬£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕʱ´úÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£¡£¡£¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ£¬£¬ÕâÒâζ×ÅÄ¿½ñµÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£¡£¡£¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼Óзֵ꣬£¬¸Ã¹«Ë¾ÕýÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/