¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190124
°ä²¼¹¦·ò 2019-01-24
ConfiantºÍMalwarebytesµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öÕë¶ÔMacÓû§µÄ´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯×Ô1ÔÂ11ÈÕÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬ÀûÓÃÒþдÊõÀ´·Ö·¢ShlayerľÂí¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±¹²¼ì²âµ½Á˳¬¹ý19Íò¸ö¶ñÒâ¸æ°×£¬£¬£¬£¬£¬Ô¤¼ÆÔ¼ÓÐ100ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£ÕâЩ¸æ°×ͼƬÖаµ²ØÁ˶ñÒâµÄJavaScript´úÂ룬£¬£¬£¬£¬²¢¼Ù×°³ÉFlashÉý¼¶À´ÓÕʹÓû§µã»÷×°Öᣡ£¡£¡£¡£¡£×êÑÐÈËԱƾ¾ÝÆäÓòÃû½«¹¥»÷Õß³ÆÎªVeryMal£¬£¬£¬£¬£¬µ«²¢Î´»ñµÃ¹¥»÷Õߵĸü¶àÓйØÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/malware-in-ad-based-images-targets-mac-users/141115/2¡¢ÃÀ¹úºÓɽ°²È«Êý°ä²¼¹ØÓÚ½üÆÚDNS½Ù³Ö¹¥»÷µÄÔ¤¾¯
ÃÀ¹úºÓɽ°²È«Êý£¨DHS£©Õë¶Ô½üÆÚµÄDNS½Ù³Ö¹¥»÷°ä²¼´¹Î£Ö¸Á£¬£¬£¬£¬ÒªÇóËùÓеÄÁª¹ú»ú¹¹ÔÚ½«À´10¸ö¹¤×÷ÈÕÄÚ±ØÐëÉóºËÆäDNSµÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£DHS³Æ¶à¸öµ±¾ÖÓòÃûÒѾ³ÉΪDNS½Ù³Ö¹¥»÷µÄÖ¸±ê£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»³Á¶¨ÏòºÍÀ¹½ØÕâЩÓòÃûµÄÍøÂçºÍÓʼþÁ÷Á¿¡£¡£¡£¡£¡£¡£¸Ã²¿ÃÅ»¹¶½´Ù¸÷»ú¹¹¸üÐÂÆäDNSÖÎÀíϵͳµÄÕË»§ÃÜÂëºÍÖ´Ðжà³ÁÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£Æ¾¾Ý֮ǰFireEyeµÄ»ã±¨£¬£¬£¬£¬£¬½üÆÚµÄDNS½Ù³Ö»î¶¯ÒÉÓëÒÁÀʺڿÍÓйء£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyber.dhs.gov/ed/19-01/3¡¢PHP°üÖÎÀíÆ÷PEAR¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬×°ÖÃÎļþ±»´«È¾

PHP°üÖÎÀíÆ÷PEAR£¨go-pear.phar£©µÄ¹ÙÍø£¨pear-php.net£©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Æä×°ÖÃÎļþ±»´«È¾¡£¡£¡£¡£¡£¡£Æ¾¾ÝPEAR°ä²¼µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬Ô̺¬¶ñÒâ´úÂëµÄ×°ÖÃÎļþÖÁÉÙÔÚÆä¹ÙÍøÉÏ´æÔÚÁ˰ëÄêµÄ¹¦·ò¡£¡£¡£¡£¡£¡£PEARÍŶӰµÊ¾ÔÚ½øÐе÷²é£¬£¬£¬£¬£¬ÒÔÈ·ÈϹ¥»÷µÄˮƽºÍÈëÇÖÊÇÈôºÎ²úÉúµÄ¡£¡£¡£¡£¡£¡£Ö»ÓÐPEAR¹ÙÍøÉϵÄ×°ÖðüÊܵ½Ó°Ï죬£¬£¬£¬£¬GitHubÉÏÃæµÄ×°ÖÃÎļþδÊÜÇÖº¦¡£¡£¡£¡£¡£¡£Óû§´Ë¿ÌÄܹ»´ÓGithub¸ßµÍÔØÐµĸɾ»°æ±¾1.10.10¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/php-pear-hacked.html4¡¢ÐÂÀÕË÷Èí¼þ¼Ò×åAnatova±»·¢ÏÖ£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞ
McAfee×êÑÐÍŶӷ¢ÏÖÒ»¸öеÄÀÕË÷Èí¼þ¼Ò×åAnatova¡£¡£¡£¡£¡£¡£AnatovaÊÇÔÚÒ»¸ö¸öÈ˵ã¶ÔµãÍøÂçÖз¢Ïֵ쬣¬£¬£¬£¬Æäͼ±ê¼Ù×°³ÉÓÎÏ·»òÀûÓ÷¨Ê½£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þµÄϰȾÁìÓò±é²¼È«Çò£¬£¬£¬£¬£¬µ«ÖØÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞ£¨Ô̺¬±ÈÀûʱ¡¢µÂ¹ú¡¢·¨¹úºÍÓ¢¹úµÈ£©¡£¡£¡£¡£¡£¡£AnatovaÓµÓÐ׳´óµÄ¾²Ì¬·ÖÎö±£»£»£»£»£»£»£»¤¼¼Êõ£¬£¬£¬£¬£¬Ô̺¬×Ö·û´®Ê¹ÓÃ·ÖÆçµÄÃÜÔ¿À´¼ÓÃÜ£»£»£»£»£»£»£»90%µÄŲÓö¼ÊǶ¯Ì¬Å²Ó㻣»£»£»£»£»£»Ö»Ê¹ÓÃÉÙÁ¿·Ç¿ÉÒɵÄWindows APIºÍC³ß¶È¿âµÈ¡£¡£¡£¡£¡£¡£Anatova»¹Ö§³ÖÄ£¿£¿£¿£¿£¿£¿é»¯µÄÖ°ÄÜÀ©´ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/happy-new-year-2019-anatova-is-here/5¡¢Apple°ä²¼iOS¡¢macOSµÈ²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸ö·ì϶
Apple°ä²¼¶à¿î²úÆ·µÄÐÂÒ»ÂÖ°²È«¸üУ¬£¬£¬£¬£¬Ô̺¬iCloud¡¢Safari 12.0.3¡¢macOS 10.14.3¡¢watchOS 5.1.3¡¢tvOS 12.1.2ºÍiOS 12.1.3µÈ£¬£¬£¬£¬£¬½¨¸´¶à¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐiOS 12.1.3½¨¸´Á˿ɵ¼ÖÂRCEµÄÀ¶ÑÀ·ì϶£¨CVE-2019-6200£©¡¢FaceTimeÖеÄRCE·ì϶£¨CVE-2019-6224£©ÒÔ¼°ÃÜÂë×Ô¶¯Ìî³äÖ°ÄÜÖеķì϶£¨CVE-2019-6206£©µÈ¡£¡£¡£¡£¡£¡£macOS 10.14.3½¨¸´ÁËÌáȨ·ì϶£¨CVE-2018-4467£©¡¢IntelͼÐÎÇý¶¯ÖеÄRCE·ì϶£¨CVE-2018-4452£©ÒÔ¼°Í¼ÏñºÍ¶¯»´¦ÖÃAPI QuartzCoreÖеÄÄÚ´æÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2019-6220£©¡£¡£¡£¡£¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-fixes-numerous-security-vulnerabilities-in-ios-macos-and-more/6¡¢Adobe°ä²¼±¾ÔµÚÈý¸ö°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸öXSS·ì϶
±¾ÖܶþAdobe°ä²¼±¾ÔµÚÈý¸ö°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸öXSS·ì϶¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶£¨CVE-2018-19726£©ÊÇÒ»¸ö´æ´¢ÐÍXSS£¬£¬£¬£¬£¬Ó°ÏìÁËËùÓÐÆ½Ì¨ÉϵÄAdobe Experience Manager°æ±¾6.0-6.4¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶£¨CVE-2018-19727£©ÊÇÒ»¸ö·´ÉäÐÍXSS£¬£¬£¬£¬£¬Ó°ÏìÁËExperience Manager°æ±¾6.3ºÍ6.4¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Adobe»¹ÔÚ°²È«²¼¸æAPSB19-03Öн¨¸´ÁËExperience Manager FormsÖеĴ洢ÐÍXSS·ì϶£¨CVE-2018-19724£©£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-releases-third-patch-update-of-the-month-to-squash-xss-bugs/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ