¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180824

Ðû²¼Ê±¼ä 2018-08-24

¡¾Çå¾²²¥±¨¡¿AppleÈ϶¨FacebookµÄVPNÓ¦ÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß


Apple³ÆFacebookµÄÒÆ¶¯VPNÓ¦ÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß£¬FacebookÒѾ­´ÓApp StoreÖÐϼÜÁ˸ÃÓ¦Óá£Onavo ProtectÊÇÒ»¸öÃâ·ÑµÄVPN¹¤¾ß£¬¸Ã¹¤¾ß¿ÉÒÔ×ÊÖúFacebookÍøÂçÓû§µÄÁ÷Á¿Êý¾Ý£¬ÒÔÏàʶÓû§ÔõÑùʹÓõÚÈý·½app¡£ÏÖÔڸù¤¾ßÒÑÔÚiOSºÍAndroid×°±¸ÉÏÏÂÔØÁËÁè¼Ý3300Íò´Î£¬²¢ÇÒÒÀÈ»±£´æÓÚGoogle PlayÊÐËÁÖС£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/facebook-vpn-app-apple-store.html


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿ÍŶӷ¢Ã÷ÐÂAndroidÌØ¹¤Èí¼þ¿ò¼ÜTriout


BitdefenderµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеġ¢¹¦Ð§Ç¿Ê¢µÄAndroid¶ñÒâÈí¼þ¿ò¼ÜTriout¡£Triout¿ÉÒÔÂ¼ÖÆÍ¨»°¡¢¼à¿Ø¶ÌÐÅ¡¢ÇÔÈ¡ÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÍøÂ綨λÊý¾ÝµÈ£¬ÆäËÆºõ±»ÓÃÓÚÓÐÕë¶ÔÐÔµÄÌØ¹¤Ô˶¯¡£Triout×îÔç·ºÆðÓÚ2018Äê5ÔÂ15ÈÕ£¬Ö÷Òª·ºÆðÔÚÒÔÉ«ÁС£Ñо¿Ö°Ô±»¹²»ÇåÎúTrioutµÄÈö²¥·½·¨ºÍ×°ÖôÎÊý£¬ÒÔ¼°Æä±³ºóµÄ¹¥»÷Õß¡£TrioutûÓÐʹÓûìÏýÊÖÒÕ£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þ¿ÉÄÜ»¹ÔÚ¿ª·¢Àú³ÌÖС£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/android-malware-spyware.html


¡¾¹¥»÷ÊÂÎñ¡¿Ñо¿ÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÉúÒâËù


¿¨°Í˹»ùʵÑéÊÒÑо¿ÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨µÄITϵͳ£¬²¢°²ÅÅÁËÔ¶¿ØÄ¾ÂíFallchillÒÔ¼°Ò»¸öMac¶ñÒâÈí¼þ¡£Õâ¿ÉÄÜÊǸÃ×é֯ʹÓõÄÊ׸öMac¶ñÒâÈí¼þ¡£Ä¾Âí»¯µÄ¸Ã¼ÓÃÜÇ®±ÒÉúÒâÈí¼þÓÉÓÐÓõÄÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû£¬ÕâʹµÃËü¿ÉÒÔÈÆ¹ýÇ徲ɨÃè¡£¿¨°Í˹»ùûÓÐ͸¶±»ÈëÇֵļÓÃÜÇ®±ÒÉúÒâËùµÄÃû³Æ£¬²¢³ÆÃ»ÓÐÈκξ­¼ÃËðʧ±¬·¢¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/lazarus-group-deploys-its-first-mac-malware-in-cryptocurrency-exchange-hack/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±ÔÚOpenSSHÖз¢Ã÷Ò»±£´æ20ÄêµÄÇå¾²Îó²î


Qualys¹«Ë¾Çå¾²Ñо¿Ö°Ô±·¢Ã÷OpenSSH¿Í»§¶Ë±£´æÒ»¸öÐÝÃßµÄÇå¾²Îó²î£¬¸ÃÎó²î£¨CVE-2018-15473£©Ó°ÏìÁËÒÑÍù¶þÊ®ÄêÐû²¼µÄËùÓÐOpenSSH¿Í»§¶Ë°æ±¾¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÍÆ²âSSH·þÎñÆ÷ÉϵÄÓÐÓÃÓû§Ãû£¬ÓÉÓÚOpenSSH¿Í»§¶Ë±»Ç¶Èëµ½´ó×ÚÈí¼þºÍÓ²¼þ×°±¸ÖУ¬ÐÞ¸´³ÌÐò¿ÉÄÜ񻮮·ÑÊýÔÂÉõÖÁÊýÄê²Å»ªµÖ´ïËùÓеÄϵͳÖС£Ñо¿Ö°Ô±Åû¶Á˸ÃÎó²îµÄÏà¹ØPoC´úÂë¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vulnerability-affects-all-openssh-versions-released-in-the-past-two-decades/


¡¾Îó²î²¹¶¡¡¿Î¢ÈíÕë¶ÔIntel CPUµÄL1TFÎó²îÐû²¼Î¢´úÂë¸üÐÂ


±¾ÖÜ΢ÈíÌṩÁËIntel CPUµÄÐÂÒ»ÂÖ΢´úÂë¸üУ¬ÓÃÓÚÐÞ¸´×î½üµÄForeshadow/L1TFÎó²î¡£Foreshadow/L1TFÎó²î£¨CVE-2018-3615¡¢CVE-2018-3620ºÍCVE-2018-3646£©¿ÉÔÊÐí¹¥»÷Õß»á¼ûÊܱ£»¤ÄÚ´æÖеÄDZÔÚÃô¸ÐÊý¾Ý£¬IntelµÄXeonºÍCoreϵÁд¦Öóͷ£Æ÷Êܵ½Ó°Ï졣΢Èí±¾ÖÜÐû²¼ÁËÎå¸ö¸üУ¬°üÀ¨KB4346084¡¢KB4346085¡¢KB4346086¡¢KB4346087ºÍKB4346088¡£ForeshadowÎó²îµÄ²¹¶¡²»»á¶ÔÏûºÄÕßPCµÄÐÔÄܱ¬·¢ÏÔ×ÅÓ°Ï죬µ«Ä³Ð©Êý¾ÝÖÐÐĵÄÊÂÇé¸ºÔØ¿ÉÄ᷺ܻÆðÐÔÄÜϽµ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/microsoft-releases-intel-microcode-patches-foreshadow-flaws


¡¾Êý¾Ýй¶¡¿Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶


Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª°îÕþ¸®µÄÖÒÑÔ£¬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£ÏÖÔÚÔÚ°µÍøÉÏÏúÊÛµÄÏà¹ØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£ÊÓ²ìÅú×¢£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕʱ´úÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ£¬ÕâÒâζ×ÅÄ¿½ñµÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼Óзֵ꣬¸Ã¹«Ë¾ÕýÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»¤·þÎñ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/