¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181010
Ðû²¼Ê±¼ä 2018-10-101¡¢GoogleÐÂÕþ²ßÖ»ÔÊÐíAndroidĬÈÏÓ¦Óûá¼ûͨ»°¼Í¼ºÍ¶ÌÐÅ
ΪÁ˱ÜÃâµÚÈý·½Ó¦ÓÃÀÄÓÃÓû§µÄÃô¸ÐÊý¾Ý£¬Google×ö³öÁ˼¸ÏîÖ÷ÒªµÄ¸ü¸Ä¡£GoogleÔÚGoogle PlayµÄ¿ª·¢ÕßÕþ²ßÖÐмÓÈëÁËÒ»Ìõ¹æÔò£¬¸Ã¹æÔòÏÖÔÚ½öÔÊÐíAndroidµÄĬÈÏÓ¦Óûá¼ûÓû§µÄͨ»°¼Í¼ºÍ¶ÌÐÅ¡£Google»¹ÏÞÖÆÁ˶ÔGmail APIµÄ»á¼û£¬ÏÖÔÚÖ»ÓÐÖ±½ÓÔöÇ¿µç×ÓÓʼþ¹¦Ð§µÄÓ¦Óã¨ÈçÓʼþ¿Í»§¶Ë¡¢Óʼþ±¸·Ý·þÎñµÈ£©²Å¿ÉÒÔ»á¼û¸ÃAPI¡£Google»¹¸üÐÂÁËÆäÕË»§È¨ÏÞϵͳ£¬ÏÖÔÚµÚÈý·½Ó¦ÓÃÔÚÉêÇë»á¼ûGoogleÕË»§Êý¾Ýʱ£¬ÏµÍ³»áÕë¶Ôÿһ¸öȨÏÞµ¥¶À¾ÙÐÐÉêÇë¡£¿ª·¢Õß½«ÓÐ90ÌìµÄʱ¼äÀ´¸üÐÂÆäÓ¦ÓúͷþÎñ¡£
https://thehackernews.com/2018/10/android-app-privacy.html
2¡¢½ðÑÅÍØµÄ±¨¸æÅú×¢2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ
ƾ֤½ðÑÅÍØµÄ×îÐÂÑо¿£¬2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ£¬¹²ÓÐ45ÒÚÌõÊý¾Ý¼Í¼Ô⵽й¶¡£Óë2017ÄêͬÆÚÏà±È£¬É¥Ê§¡¢±»ÇÔÒÔ¼°Ð¹Â¶µÄÊý¾ÝÔöÌíÁË133%¡£Ö»¹ÜÊý¾Ýй¶ÊÂÎñµÄÊýÄ¿ÂÔÓÐϽµ£¬µ«ÊÂÎñµÄÑÏÖØË®Æ½ÓÐËùÔöÌí¡£ÆäÖÐ6ÆðÉ罻ýÌåÊý¾Ýй¶ÊÂÎñµ¼ÖÂÁËÁè¼Ý56%µÄÊý¾Ýй¶¡£Êý¾Ýй¶µÄ×î³£¼ûÔµ¹ÊÔÓÉÊÇÍⲿÒòËØ£¨Õ¼56%£©¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2018/10/09/data-breaches-2018/3¡¢Î¢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬¹²ÐÞ¸´49¸öÇå¾²Îó²î
΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬¹²ÐÞ¸´Windows¡¢Edge¡¢IEµÈ¶à¿î²úÆ·ÖеÄ49¸öÎó²î£¬ÆäÖаüÀ¨12¸ö¸ßΣÎó²î¡£½ÏΪÑÏÖØµÄÎó²î°üÀ¨WindowsÖеÄÌáȨÎó²î£¨CVE-2018-8453£©¡¢MSXMLÆÊÎöÆ÷×é¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8494£©¡¢JetÊý¾Ý¿âÒýÇæÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8423£©¡¢WindowsÄÚºËÖеÄÌáȨÎó²î£¨CVE-2018-8497£©ÒÔ¼°Azure IoT Hub SDKÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8531£©¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/microsoft-windows-update.html4¡¢AppleÐû²¼ÐÂÒ»ÂÖiOSºÍiCloudÇå¾²¸üУ¬ÐÞ¸´¶à¸öÎó²î
AppleÐû²¼Õë¶ÔiOSºÍiCloudµÄÐÂÒ»ÂÖÇå¾²¸üУ¬ÐÞ¸´¶à¸öÇå¾²Îó²î¡£ÆäÖÐÔÚiOS 12.0.1ÖÐÐÞ¸´ÁËÁ½¸öÃÜÂëÈÆ¹ýÎó²î£¨CVE-2018-4380ºÍCVE-2018-4379£©¡£Çå¾²Ñо¿Ö°Ô±Jose Rodriguez·¢Ã÷ÁËÕâÁ½¸öÎó²î£¬²¢Ðû²¼ÁËÏà¹ØÎó²îʹÓÃÊÓÆµ¡£Apple»¹ÔÚiCloud for Windows 7.7.12ÖÐÐÞ¸´ÁË19¸öÎó²î£¬ÆäÖаüÀ¨13¸ö¸ßΣµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-releases-security-updates-for-ios-and-icloud-fixes-passcode-bypass/5¡¢Annapolis LibraryÔâÒøÐÐľÂíEmotetѬȾ£¬½ü5000Óû§ÊÜÓ°Ïì
ÃÀ¹úÂíÀïÀ¼Öݰ²Äɲ¨Àû˹ÊеÄÒ»¸ö¹«¹²Í¼Êé¹ÝÔâÒøÐÐľÂíEmotetѬȾ£¬Ô¼5000ÃûÓû§¿ÉÄÜÊܵ½Ó°Ïì¡£Emotet»áÇÔÈ¡Óû§µÄµÇ¼ƾ֤¡¢Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©ÒÔ¼°ÐÅÓÿ¨ÐÅÏ¢µÈ£¬ËäÈ»¸ÃͼÊé¹ÝÌåÏÖûÓпͻ§ÐÅϢй¶£¬µ«ÔÚ9ÔÂ17ÈÕÖÁ10ÔÂ4ÈÕʱ´úʹÓÃÁ˸ÃͼÊé¹ÝµÄ¹«¹²ÅÌËã»úµÄ¿Í»§Ó¦¸ÃСÐÄÆäÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/annapolis-library-computers-infected-with-emotet-almost-5k-customers-affected-523119.shtml6¡¢Ñо¿Ö°Ô±·¢Ã÷ÈëÇÖMikroTik·ÓÉÆ÷µÄй¥»÷ÊÖÒÕ
Tenable ResearchµÄÑо¿Ö°Ô±·¢Ã÷ÈëÇÖMikroTik·ÓÉÆ÷µÄй¥»÷ÊÖÒÕ£¬Ê¹µÃÒ»¸öÒÑÖªµÄÎó²î±äµÃ±ÈÒÔǰÒÔΪµÄÔ½·¢Î£ÏÕ¡£¸ÃÎó²î£¨CVE-2018-14847£©Ó°ÏìWinbox×é¼þ£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔ¶³ÌÖ´ÐдúÂë²¢»ñµÃroot shell¡£»»¾ä»°Ëµ£¬ÐµĹ¥»÷ÊÖÒÕʹµÃδ¾ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔÈëÇÖRouterOS£¬°²ÅŶñÒâÈí¼þ»òÈÆ¹ý·ÓÉÆ÷µÄ·À»ðǽ¡£¸ÃÎó²îÒÑÓÚ2018Äê4Ô±»ÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76940/hacking/mikrotik-routers-attack-poc.htmlÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ