¹È¸è³Æ³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±£»£»£»£» £»ProtonVPNÓëɱ¶¾Èí¼þ³åÍ» £¬£¬£¬£¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ

Ðû²¼Ê±¼ä 2021-01-27

1.AppleÇå¾²¸üР£¬£¬£¬£¬ÐÞ¸´iOSÖÐ3¸öÒѱ»ÔÚҰʹÓõÄ0day


1.jpg


AppleÐû²¼ÁËÕë¶ÔiOSµÄÇå¾²¸üР£¬£¬£¬£¬ÐÞ¸´ÁË3¸öÒѱ»ÔÚҰʹÓõÄ0day ¡£¡£¡£µÚÒ»¸öΪӰÏìiOS²Ù×÷ϵͳÄں˵ľºÕùÌõ¼þÎó²î£¨CVE-2021-1782£© £¬£¬£¬£¬Ëü¿ÉÒÔʹ¹¥»÷ÕßÌáÉýÆä¹¥»÷´úÂëµÄȨÏÞ ¡£¡£¡£ÁíÍâÁ½¸öΪӰÏìWebKitä¯ÀÀÆ÷ÒýÇæµÄÂß¼­Îó²î£¨CVE-2021-1870ºÍCVE-2021-1871£© £¬£¬£¬£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄSafariä¯ÀÀÆ÷ÖÐÖ´ÐжñÒâ´úÂë ¡£¡£¡£ÔÚÎó²îʹÓÃÁ´ÖÐ £¬£¬£¬£¬Óû§±»ÒýÓÕµ½Ò»¸ö¶ñÒâÍøÕ¾ £¬£¬£¬£¬¸ÃÍøÕ¾Ê¹ÓÃWebKitÎó²îÔËÐдúÂë £¬£¬£¬£¬ËæºóÉý¼¶ÆäÔËÐÐϵͳ¼¶´úÂëµÄȨÏÞ £¬£¬£¬£¬Î£¼°²Ù×÷ϵͳ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/apple-fixes-another-three-ios-zero-days-exploited-in-the-wild/


2.¹È¸è³Æ³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±


2.png


GoogleÍþвÆÊÎöС×é·¢Ã÷³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô± ¡£¡£¡£ºÚ¿ÍÊ×ÏÈÔÚTwitter¡¢LinkedIn¡¢Telegram¡¢DiscordºÍKeybaseµÈÉç½»ÍøÂçÉÏʹÓöàÈ˵ÄСÎÒ˽¼Ò×ÊÁÏ £¬£¬£¬£¬ÒÔαÔìµÄÉí·Ý½Ó´¥Çå¾²Ñо¿Ö°Ô± ¡£¡£¡£ÔÚ½¨ÉèÁËÆðÔ´µÄ½»Á÷Ö®ºó £¬£¬£¬£¬ºÚ¿Í»áѯÎÊÄ¿µÄÑо¿Ö°Ô±ÊÇ·ñÔ¸ÒâÔÚÎó²îÑо¿ÉϾÙÐÐÏàÖú £¬£¬£¬£¬È»ºó¸øÑо¿Ö°Ô±Ò»¸öVisual StudioÏîÄ¿ ¡£¡£¡£¸ÃÏîÄ¿°üÀ¨ÁË×°ÖöñÒâÈí¼þµÄ´úÂë £¬£¬£¬£¬ÀÖ³É×°Öúó¿É³äµ±ºóÃŲ¢ÓëÔ¶³ÌÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷ÁªÏµ £¬£¬£¬£¬ÆÚ´ýÏÂÁî ¡£¡£¡£±ðµÄ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓ볯ÏÊÖøÃûºÚ¿Í×éÖ¯LazarusÓÐ¹Ø ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-north-korean-hackers-have-targeted-security-researchers-via-social-media/


3.°Ä´óÀûÑÇ֤ȯî¿Ïµ»ú¹¹Ð§ÀÍÆ÷ÖÐÎó²î»òÒѵ¼ÖÂÊý¾Ýй¶


3.png


°Ä´óÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©Í¸Â¶Ð§ÀÍÆ÷ÖÐÎó²î»òÒѵ¼ÖÂÊý¾Ýй¶ ¡£¡£¡£ASICÊǰĴóÀûÑÇÕþ¸®µÄ×ÔÁ¦Î¯Ô±»á £¬£¬£¬£¬ÈÏÕæ°ü¹Ü¡¢Ö¤È¯ºÍ½ðÈÚЧÀ͵Äî¿Ïµ £¬£¬£¬£¬ÊǰĴóÀûÑǹú¼Ò¹«Ë¾î¿Ïµ»ú¹¹µÄÏûºÄÕß±£»£»£»£» £»¤×éÖ¯ ¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÓÚ2021Äê1ÔÂ15ÈÕ £¬£¬£¬£¬ÓëÓÃÓÚ´«ÊäÐÅÏ¢µÄAccellionÈí¼þÓÐ¹Ø £¬£¬£¬£¬Îó²îÓ°ÏìÁËһ̨°üÀ¨Á˰ĴóÀûÑÇÐÅ´ûÔÊÐíÖ¤ÉêÇëÏà¹ØÎĵµµÄЧÀÍÆ÷ ¡£¡£¡£ASIC³ÆÊÓ²ìÕýÔÚ¾ÙÐÐÖÐ £¬£¬£¬£¬µ«ºÚ¿Í¿ÉÄÜÒѾ­Éó²é²¿·ÖÐÅÏ¢ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/australian-securities-regulator-discloses-security-breach/


4.WestRockѬȾÀÕË÷Èí¼þ £¬£¬£¬£¬ITºÍOTϵͳ¾ù±»ÆÆËð


4.png


ÃÀ¹ú°ü×°¹«Ë¾WestRockѬȾÀÕË÷Èí¼þ £¬£¬£¬£¬ITºÍOTϵͳ¾ù±»ÆÆËð ¡£¡£¡£¹¥»÷ÓÚ1ÔÂ23ÈÕ±»·¢Ã÷ £¬£¬£¬£¬²¢ÊµÊ±½ÓÄÉÁËÓ¦¼±ÏìÓ¦²½·¥ ¡£¡£¡£WestRockÌåÏÖϵͳÕýÔÚ»Ö¸´ÖÐ £¬£¬£¬£¬µ«¹¥»÷ÒѾ­µ¼Ö¹«Ë¾²¿·ÖÓªÒµµÄÑÓÎó ¡£¡£¡£WestRockûÓÐ͸¶Óйش˴ÎÊÂÎñµÄ¸ü¶àÏêϸÐÅÏ¢ £¬£¬£¬£¬Éв»ÇåÎú¹¥»÷µÄˮƽÒÔ¼°Ê¹ÊÖÐÊܵ½Ó°ÏìµÄOTϵͳÀàÐÍ ¡£¡£¡£¸ÃÊÂÎñ±»Åû¶ºó £¬£¬£¬£¬±¾ÖÜÒ»ÉÏÎçWestRock¹ÉƱµÄ¼ÛֵϵøÁË4£¥ÒÔÉÏ ¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/packaging-giant-westrock-says-ransomware-attack-impacted-ot-systems


5.ProtonVPNÓëɱ¶¾Èí¼þ³åÍ» £¬£¬£¬£¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ


5.png


ProtonVPNÓëδÃüÃûµÄɱ¶¾Èí¼þ½â¾ö¼Æ»®³åÍ» £¬£¬£¬£¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ ¡£¡£¡£ËäÈ»ProtonVPNûÓÐ͸¶ÓйØÀ¶ÆÁÔµ¹ÊÔ­Óɵĸü¶àϸ½Ú £¬£¬£¬£¬µ«Ô¼ÄªÁ½ÖÜǰ £¬£¬£¬£¬Ê¹ÓÃÁË×îа汾ProtonVPNµÄÒ»¸öÊÜÓ°ÏìµÄÓû§ËùÌåÏÖ £¬£¬£¬£¬ÔÚÆô¶¯VPNµÄ¿Í»§¶Ëºó»áÁ¬Ã¦´¥·¢À¶ÆÁ ¡£¡£¡£ÕâÒѲ»ÊǵÚÒ»´ÎÓÐÓû§·´Ó¦ÔÚWindowsϵͳÖÐÔÚʹÓÃProtonVPNʱ»áµ¼ÖÂÀ¶ÆÁ £¬£¬£¬£¬²¢ÇÒÖØÐÂ×°Öÿͻ§¶ËºÍÇý¶¯³ÌÐòÒ²ÎÞ¼ÃÓÚÊ ¡£¡£¡£ProtonVPN½¨ÒéÓû§ÏÈÔÝʱ½ûÓøÃɱ¶¾Èí¼þ £¬£¬£¬£¬»ò½«ProtonVPN½µ¼¶µ½Îȹ̰汾 ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/protonvpn-causes-windows-bsod-crashes-due-to-antivirus-conflicts/


6.kasperskyÐû²¼2021ÄêÍøÂçÇå¾²µÄÕ¹Íû±¨¸æ


6.png


kasperskyÐû²¼ÁË2021ÄêÍøÂçÇå¾²µÄÕ¹Íû±¨¸æ ¡£¡£¡£¸Ã±¨¸æÊÓ²ìÁË31¸ö¹ú¼ÒºÍµØÇøµÄ5266ÃûIT¾öÒéÕß £¬£¬£¬£¬²¢ÌÖÂÛÁËËûÃÇÓöµ½µÄÍþв¡¢ÍøÂçÊÂÎñ»Ö¸´µÄ±¾Ç®ÒÔ¼°×éÖ¯ÄÚ²¿µÄÄ¿½ñÇ徲״̬ ¡£¡£¡£Ñо¿·¢Ã÷Ö»¹ÜÍøÂç¹¥»÷µÄÊýÄ¿¼ÌÐøÔöÌí £¬£¬£¬£¬µ«IT²¿·ÖµÄÇå¾²Ô¤Ëã×ÜÌåÉÏÕýÔÚïÔÌ­ ¡£¡£¡£2020Äê £¬£¬£¬£¬´óÐ͹«Ë¾ITÔ¤ËãϽµÁË26£¥ £¬£¬£¬£¬ÖÐСÐÍÆóҵҲϽµÁËÔ¼10£¥ ¡£¡£¡£±ðµÄ £¬£¬£¬£¬µ½2021ÄêÔÚÔÆÐ§ÀÍÉϵÄÖ§³ö½«ÏûºÄITÔ¤ËãµÄÔ¼32£¥ £¬£¬£¬£¬Òò´Ë¼àÊÓÆ½Ì¨µÄ¼àÊÓºÍÇå¾²ÐÔÖÁ¹ØÖ÷Òª ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/2021-economic-predictions-for-infosec/38553/