¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190110
Ðû²¼Ê±¼ä 2019-01-10
Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁ·¢Ã÷85¸ö¹ã¸æÓ¦Ó㬣¬£¬£¬£¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾¡£¡£¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿£¿£¿ØÆ÷µÈ£¬£¬£¬£¬£¬ÔÚ×°±¸ºǫ́¾²Ä¬ÔËÐУ¬£¬£¬£¬£¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§×°±¸¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩappÀ´×ÔÓÚ²î±ðµÄ¿ª·¢Ö°Ô±£¬£¬£¬£¬£¬²¢ÇÒÓµÓвî±ðµÄAPKÖ¤Ê鹫Կ£¬£¬£¬£¬£¬µ«ËüÃǵĴúÂëºÍÃüÃû·½·¨¶¼Ê®·ÖÏàËÆ¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓᣡ£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/android-adware-malware.html2¡¢Ñо¿ÍŶӷ¢Ã÷Apple Intel HD 5000±£´æ¶à¸öÌáȨÎó²î

Cisco TalosÑо¿ÍŶӷ¢Ã÷Apple OSX 10.13.4ÔÚ´¦Öóͷ£ÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬£¬£¬£¬£¬ÆäIntelHD5000ÄÚºËÀ©Õ¹Öб£´æ¶à¸öÌáȨÎó²î£¨CVE-2018-4421ºÍCVE-2018-4456£©¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÐÎò£¬£¬£¬£¬£¬VLCýÌåÓ¦ÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç»á¼û£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý¡£¡£¡£ÕâЩÎó²îÊÇÔÚMacBookPro11.4-OS X 10.13.4ÇéÐÎÏ·¢Ã÷µÄ¡£¡£¡£ÓÉÓÚÎó²î¿Éͨ¹ýSafari´¥·¢£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html
3¡¢AdobeÐû²¼2019Äê1ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Á½¸öÇå¾²Îó²î
AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash PlayerÐû²¼ÁË2019Äê1ÔÂÇå¾²¸üС£¡£¡£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬£¬£¬£¬£¬²¢¼òÆÓµØÐÞ¸´ÁËÐÔÄÜÎÊÌâºÍbug£¬£¬£¬£¬£¬²¢Î´ÐÞ¸´ÈκÎÇå¾²ÎÊÌâ¡£¡£¡£Õë¶ÔDigital EditionsµÄÇå¾²¸üÐÂÐÞ¸´ÁËÔ½½ç¶ÁÎó²î£¨CVE-2018-12817£©£¬£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£¡£¡£Õë¶ÔConnectµÄÇå¾²¸üÐÂÐÞ¸´Á˻ỰÁîÅÆÌ»Â¶Îó²î£¨CVE-2018-19718£©¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/4¡¢¹È¸èÐû²¼2019Äê1ÔÂAndroidÇ徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´27¸öÎó²î

¹È¸èÐû²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄÇå¾²¸üУ¬£¬£¬£¬£¬¹²ÐÞ¸´ÁË27¸öÎó²î¡£¡£¡£ÆäÖÐÇå¾²²¹¶¡¼¶±ð2019-01-01ÖÐÐÞ¸´ÁË13¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨÎó²î£¨CVE-2018-9582£¬£¬£¬£¬£¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ¡£¡£¡£Çå¾²²¹¶¡¼¶±ð2019-01-05ÐÞ¸´ÁË14¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨Qualcomm±ÕÔ´×é¼þÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2018-11847£©µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2019-01-01.html5¡¢ÐÂ×Ô¶¯»¯´¹ÂÚ¹¤¾ßModlishka£¬£¬£¬£¬£¬¿ÉÈÆ¹ýË«ÒòËØÈÏÖ¤

²¨À¼Çå¾²Ñо¿Ö°Ô±PiotrDuszy¨½skiÐû²¼ÁËÒ»¸öеÄÉøÍ¸²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬¸Ã¹¤¾ß¿ÉÒÔʵÏÖ´¹ÂÚ¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«ÒòËØÈÏÖ¤¡£¡£¡£¸Ã¹¤¾ß±»ÃüÃûΪModlishka£¨²¨À¼Ó£¬£¬£¬£¬Òâ˼Ϊó«ò룩£¬£¬£¬£¬£¬ÊÇÒ»¸öÓÃÓÚ´¦Öóͷ£µÇÂ¼Ò³ÃæºÍ´¹ÂÚÁ÷Á¿µÄ·´ÏòÊðÀí¡£¡£¡£ËüλÓÚÓû§ºÍÄ¿µÄÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬£¬£¬£¬£¬Êܺ¦ÕßÎüÊÕµ½À´×ÔÓÚÕýµ±ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬£¬£¬£¬£¬µ«ËùÓÐÁ÷Á¿¶¼»áͨ¹ý²¢¼Í¼ÔÚModlishkaЧÀÍÆ÷ÉÏ¡£¡£¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼Á˸ù¤¾ß¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/6¡¢Ð±ßÐŵÀ¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ
Ñо¿ÍŶӽÒÏþÁËһƪÏÈÈÝбßÐŵÀ¹¥»÷µÄÂÛÎÄ£¬£¬£¬£¬£¬¸Ã¹¥»÷·½·¨²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞÖÆ£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ¡£¡£¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄܰüÀ¨³ÌÐò¶þ½øÖÆÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£Ñо¿Ö°Ô±Ê¹ÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´¼ì²éÒ³Ãæ»º´æ¡£¡£¡£¸Ã¹¥»÷ÒÑÔÚÍâµØÊµÑéÖб»Ö¤Êµ£¬£¬£¬£¬£¬²¢ÇÒÔÚÒ»¶¨Ìõ¼þÏÂÒ²¿ÉÔ¶³ÌʹÓᣡ£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ