¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190110
°ä²¼¹¦·ò 2019-01-10
Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±ÔÚGoogle PlayÉ̵귢ÏÖ85¸ö¸æ°×ÀûÓ㬣¬£¬£¬£¬£¬Ô¼900ÍòAndroidÓû§Êܵ½Ï°È¾¡£¡£¡£¡£¡£ÕâЩapp¼Ù×°³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿£¿£¿£¿£¿£¿£¿£¿ØÆ÷µÈ£¬£¬£¬£¬£¬£¬ÔÚÉ豸ºó¶Ü¾²Ä¬ÔËÐУ¬£¬£¬£¬£¬£¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¸æ°×ºäÕ¨Óû§É豸¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÕâЩappÀ´×ÔÓÚ·ÖÆçµÄ¿ª·¢ÈËÔ±£¬£¬£¬£¬£¬£¬²¢ÇÒÕ¼ÓÐ·ÖÆçµÄAPKÖ¤Ê鹫Կ£¬£¬£¬£¬£¬£¬µ«ËüÃǵĴúÂëºÍ¶¨Ãû·½Ê½¶¼¼«¶ÈÀàËÆ¡£¡£¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩÀûÓᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/android-adware-malware.html2¡¢×êÑÐÍŶӷ¢ÏÖApple Intel HD 5000´æÔÚ¶à¸öÌáȨ·ì϶

Cisco Talos×êÑÐÍŶӷ¢ÏÖApple OSX 10.13.4ÔÚ´¦ÖÃÄÚ²¿Í¼ÐÎ×ÊԴʱ£¬£¬£¬£¬£¬£¬ÆäIntelHD5000ÄÚºËÀ©´óÖдæÔÚ¶à¸öÌáȨ·ì϶£¨CVE-2018-4421ºÍCVE-2018-4456£©¡£¡£¡£¡£¡£Æ¾¾Ý×êÑÐÈËÔ±µÄÃèÊö£¬£¬£¬£¬£¬£¬VLCýÌåÀûÓÃÖеĿâ¿Éµ¼ÖÂKEXTÄÚ²¿µÄÔ½½ç½Ó¼û£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÄÚºËÖеÄuse-after-freeºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£ÕâЩ·ì϶ÊÇÔÚMacBookPro11.4-OS X 10.13.4»·¾³Ï·¢Ïֵġ£¡£¡£¡£¡£ÓÉÓÚ·ì϶¿Éͨ¹ýSafari´¥·¢£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2019/01/vulnerability-spotlight-multiple-apple.html
3¡¢Adobe°ä²¼2019Äê1Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Á½¸ö°²È«·ì϶
AdobeÕë¶ÔAdobe Connect¡¢Adobe Digital EditionsºÍFlash Player°ä²¼ÁË2019Äê1Ô°²È«¸üС£¡£¡£¡£¡£Õë¶ÔFlash PlayerµÄ¸üн«Flash PlayerÉý¼¶µ½Ð°汾32.0.0.114£¬£¬£¬£¬£¬£¬²¢µ¥Ò»µØ½¨¸´ÁË»úÄÜÎÊÌâºÍbug£¬£¬£¬£¬£¬£¬²¢Î´½¨¸´Èκΰ²È«ÎÊÌâ¡£¡£¡£¡£¡£Õë¶ÔDigital EditionsµÄ°²È«¸üн¨¸´ÁËÔ½½ç¶Á·ì϶£¨CVE-2018-12817£©£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿Éµ¼ÖÂÐÅϢй¶¡£¡£¡£¡£¡£Õë¶ÔConnectµÄ°²È«¸üн¨¸´Á˻ỰÁîÅÆÂ¶Â¶Âí½Å£¨CVE-2018-19718£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-releases-january-2019-security-updates-none-for-flash-player/4¡¢¹È¸è°ä²¼2019Äê1ÔÂAndroid°²È«²¼¸æ£¬£¬£¬£¬£¬£¬½¨¸´27¸ö·ì϶

¹È¸è°ä²¼ÁË2019ÄêµÄµÚÒ»¸öÕë¶ÔAndroidµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬¹²½¨¸´ÁË27¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖа²È«²¹¶¡¼¶±ð2019-01-01Öн¨¸´ÁË13¸ö·ì϶£¬£¬£¬£¬£¬£¬Ô̺¬Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-9583£©¡¢FrameworkÖеÄÌáȨ·ì϶£¨CVE-2018-9582£¬£¬£¬£¬£¬£¬Ó°ÏìAndroid°æ±¾8.0¡¢8.1ºÍ9£©µÈ¡£¡£¡£¡£¡£°²È«²¹¶¡¼¶±ð2019-01-05½¨¸´ÁË14¸ö·ì϶£¬£¬£¬£¬£¬£¬Ô̺¬Qualcomm¹ØÔ´×é¼þÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2018-11847£©µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2019-01-01.html5¡¢ÐÂ×Ô¶¯»¯´¹µö¹¤¾ßModlishka£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýË«³É·ÖÈÏÖ¤

²¨À¼°²È«×êÑÐÈËÔ±PiotrDuszy¨½ski°ä²¼ÁËÒ»¸öеÄÉøÈë²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ßÄܹ»ÊµÏÖ´¹µö¹¥»÷µÄ×Ô¶¯»¯ÒÔ¼°ÈƹýË«³É·ÖÈÏÖ¤¡£¡£¡£¡£¡£¸Ã¹¤¾ß±»¶¨ÃûΪModlishka£¨²¨À¼Ó£¬£¬£¬£¬£¬Òâ˼Ϊó«ò룩£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÓÃÓÚ´¦ÖõÇÂ¼Ò³ÃæºÍ´¹µöÁ÷Á¿µÄ·´Ïò´úÀí¡£¡£¡£¡£¡£ËüλÓÚÓû§ºÍÖ¸±êÍøÕ¾£¨Gmail¡¢YahooµÈ£©Ö®¼ä£¬£¬£¬£¬£¬£¬Êܺ¦Õ߽ӹܵ½À´×ÔÓںϷ¨ÍøÕ¾µÄÕæÊµÄÚÈÝ£¬£¬£¬£¬£¬£¬µ«ËùÓÐÁ÷Á¿³ÇÊÐͨ¹ý²¢¼Í¼ÔÚModlishka·þÎñÆ÷ÉÏ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚGithubÉϰ䲼Á˸ù¤¾ß¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-tool-automates-phishing-attacks-that-bypass-2fa/6¡¢Ð±ßÐÅ·¹¥»÷¿ÉÇÔÈ¡WindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ
×êÑÐÍŶӰ䷢ÁËһƪ½éÉÜбßÐÅ·¹¥»÷µÄÂÛÎÄ£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷·½Ê½²»ÊÜÓ²¼þ¼Ü¹¹µÄÏÞ¶È£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔWindowsºÍLinuxϵͳµÄÒ³Ãæ»º´æ¡£¡£¡£¡£¡£²Ù×÷ϵͳµÄÒ³Ãæ»º´æÖпÉÄÜÔ̺¬·¨Ê½¶þ½øÔìÎļþ¡¢¿â¡¢ÎļþºÍÃ÷ÎÄÃô¸ÐÐÅÏ¢µÈ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÀûÓòÙ×÷ϵͳŲÓã¨LinuxÉϵÄmincoreºÍWindowsÉϵÄQueryWorkingSetEx£©À´²é³Ò³Ã滺´æ¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÑÔÚ±¾µØ³¢ÊÔÖб»Ö¤Ã÷£¬£¬£¬£¬£¬£¬²¢ÇÒÔڿ϶¨Ç°ÌáÏÂÒ²¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-side-channel-attack-steals-data-from-windows-linux-page-cache/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ