¹È¸è³Æ³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±£»ProtonVPNÓëɱ¶¾Èí¼þ³åÍ» £¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ

Ðû²¼Ê±¼ä 2021-01-27

1.AppleÇå¾²¸üР£¬ÐÞ¸´iOSÖÐ3¸öÒѱ»ÔÚҰʹÓõÄ0day


1.jpg


AppleÐû²¼ÁËÕë¶ÔiOSµÄÇå¾²¸üР£¬ÐÞ¸´ÁË3¸öÒѱ»ÔÚҰʹÓõÄ0day¡£µÚÒ»¸öΪӰÏìiOS²Ù×÷ϵͳÄں˵ľºÕùÌõ¼þÎó²î£¨CVE-2021-1782£© £¬Ëü¿ÉÒÔʹ¹¥»÷ÕßÌáÉýÆä¹¥»÷´úÂëµÄȨÏÞ¡£ÁíÍâÁ½¸öΪӰÏìWebKitä¯ÀÀÆ÷ÒýÇæµÄÂß¼­Îó²î£¨CVE-2021-1870ºÍCVE-2021-1871£© £¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄSafariä¯ÀÀÆ÷ÖÐÖ´ÐжñÒâ´úÂë¡£ÔÚÎó²îʹÓÃÁ´ÖÐ £¬Óû§±»ÒýÓÕµ½Ò»¸ö¶ñÒâÍøÕ¾ £¬¸ÃÍøÕ¾Ê¹ÓÃWebKitÎó²îÔËÐдúÂë £¬ËæºóÉý¼¶ÆäÔËÐÐϵͳ¼¶´úÂëµÄȨÏÞ £¬Î£¼°²Ù×÷ϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/apple-fixes-another-three-ios-zero-days-exploited-in-the-wild/


2.¹È¸è³Æ³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±


2.png


GoogleÍþвÆÊÎöС×é·¢Ã÷³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±¡£ºÚ¿ÍÊ×ÏÈÔÚTwitter¡¢LinkedIn¡¢Telegram¡¢DiscordºÍKeybaseµÈÉç½»ÍøÂçÉÏʹÓöàÈ˵ÄСÎÒ˽¼Ò×ÊÁÏ £¬ÒÔαÔìµÄÉí·Ý½Ó´¥Çå¾²Ñо¿Ö°Ô±¡£ÔÚ½¨ÉèÁËÆðÔ´µÄ½»Á÷Ö®ºó £¬ºÚ¿Í»áѯÎÊÄ¿µÄÑо¿Ö°Ô±ÊÇ·ñÔ¸ÒâÔÚÎó²îÑо¿ÉϾÙÐÐÏàÖú £¬È»ºó¸øÑо¿Ö°Ô±Ò»¸öVisual StudioÏîÄ¿¡£¸ÃÏîÄ¿°üÀ¨ÁË×°ÖöñÒâÈí¼þµÄ´úÂë £¬ÀÖ³É×°Öúó¿É³äµ±ºóÃŲ¢ÓëÔ¶³ÌÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷ÁªÏµ £¬ÆÚ´ýÏÂÁî¡£±ðµÄ £¬¸Ã¶ñÒâÈí¼þÓ볯ÏÊÖøÃûºÚ¿Í×éÖ¯LazarusÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-north-korean-hackers-have-targeted-security-researchers-via-social-media/


3.°Ä´óÀûÑÇ֤ȯî¿Ïµ»ú¹¹·þÎñÆ÷ÖÐÎó²î»òÒѵ¼ÖÂÊý¾Ýй¶


3.png


°Ä´óÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©Í¸Â¶·þÎñÆ÷ÖÐÎó²î»òÒѵ¼ÖÂÊý¾Ýй¶¡£ASICÊǰĴóÀûÑÇÕþ¸®µÄ×ÔÁ¦Î¯Ô±»á £¬ÈÏÕæ°ü¹Ü¡¢Ö¤È¯ºÍ½ðÈÚ·þÎñµÄî¿Ïµ £¬ÊǰĴóÀûÑǹú¼Ò¹«Ë¾î¿Ïµ»ú¹¹µÄÏûºÄÕß±£»¤×éÖ¯¡£¸ÃÊÂÎñ±¬·¢ÓÚ2021Äê1ÔÂ15ÈÕ £¬ÓëÓÃÓÚ´«ÊäÐÅÏ¢µÄAccellionÈí¼þÓйØ £¬Îó²îÓ°ÏìÁËһ̨°üÀ¨Á˰ĴóÀûÑÇÐÅ´ûÔÊÐíÖ¤ÉêÇëÏà¹ØÎĵµµÄ·þÎñÆ÷¡£ASIC³ÆÊÓ²ìÕýÔÚ¾ÙÐÐÖÐ £¬µ«ºÚ¿Í¿ÉÄÜÒѾ­Éó²é²¿·ÖÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/australian-securities-regulator-discloses-security-breach/


4.WestRockѬȾÀÕË÷Èí¼þ £¬ITºÍOTϵͳ¾ù±»ÆÆËð


4.png


ÃÀ¹ú°ü×°¹«Ë¾WestRockѬȾÀÕË÷Èí¼þ £¬ITºÍOTϵͳ¾ù±»ÆÆËð¡£¹¥»÷ÓÚ1ÔÂ23ÈÕ±»·¢Ã÷ £¬²¢ÊµÊ±½ÓÄÉÁËÓ¦¼±ÏìÓ¦²½·¥¡£WestRockÌåÏÖϵͳÕýÔÚ»Ö¸´ÖÐ £¬µ«¹¥»÷ÒѾ­µ¼Ö¹«Ë¾²¿·ÖÓªÒµµÄÑÓÎó¡£WestRockûÓÐ͸¶Óйش˴ÎÊÂÎñµÄ¸ü¶àÏêϸÐÅÏ¢ £¬Éв»ÇåÎú¹¥»÷µÄˮƽÒÔ¼°Ê¹ÊÖÐÊܵ½Ó°ÏìµÄOTϵͳÀàÐÍ¡£¸ÃÊÂÎñ±»Åû¶ºó £¬±¾ÖÜÒ»ÉÏÎçWestRock¹ÉƱµÄ¼ÛֵϵøÁË4£¥ÒÔÉÏ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/packaging-giant-westrock-says-ransomware-attack-impacted-ot-systems


5.ProtonVPNÓëɱ¶¾Èí¼þ³åÍ» £¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ


5.png


ProtonVPNÓëδÃüÃûµÄɱ¶¾Èí¼þ½â¾ö¼Æ»®³åÍ» £¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ¡£ËäÈ»ProtonVPNûÓÐ͸¶ÓйØÀ¶ÆÁÔµ¹ÊÔ­Óɵĸü¶àϸ½Ú £¬µ«Ô¼ÄªÁ½ÖÜǰ £¬Ê¹ÓÃÁË×îа汾ProtonVPNµÄÒ»¸öÊÜÓ°ÏìµÄÓû§ËùÌåÏÖ £¬ÔÚÆô¶¯VPNµÄ¿Í»§¶Ëºó»áÁ¬Ã¦´¥·¢À¶ÆÁ¡£ÕâÒѲ»ÊǵÚÒ»´ÎÓÐÓû§·´Ó¦ÔÚWindowsϵͳÖÐÔÚʹÓÃProtonVPNʱ»áµ¼ÖÂÀ¶ÆÁ £¬²¢ÇÒÖØÐÂ×°Öÿͻ§¶ËºÍÇý¶¯³ÌÐòÒ²ÎÞ¼ÃÓÚÊ¡£ProtonVPN½¨ÒéÓû§ÏÈÔÝʱ½ûÓøÃɱ¶¾Èí¼þ £¬»ò½«ProtonVPN½µ¼¶µ½Îȹ̰汾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/protonvpn-causes-windows-bsod-crashes-due-to-antivirus-conflicts/


6.kasperskyÐû²¼2021ÄêÍøÂçÇå¾²µÄÕ¹Íû±¨¸æ


6.png


kasperskyÐû²¼ÁË2021ÄêÍøÂçÇå¾²µÄÕ¹Íû±¨¸æ¡£¸Ã±¨¸æÊÓ²ìÁË31¸ö¹ú¼ÒºÍµØÇøµÄ5266ÃûIT¾öÒéÕß £¬²¢ÌÖÂÛÁËËûÃÇÓöµ½µÄÍþв¡¢ÍøÂçÊÂÎñ»Ö¸´µÄ±¾Ç®ÒÔ¼°×éÖ¯ÄÚ²¿µÄÄ¿½ñÇ徲״̬¡£Ñо¿·¢Ã÷Ö»¹ÜÍøÂç¹¥»÷µÄÊýÄ¿¼ÌÐøÔöÌí £¬µ«IT²¿·ÖµÄÇå¾²Ô¤Ëã×ÜÌåÉÏÕýÔÚïÔÌ­¡£2020Äê £¬´óÐ͹«Ë¾ITÔ¤ËãϽµÁË26£¥ £¬ÖÐСÐÍÆóҵҲϽµÁËÔ¼10£¥¡£±ðµÄ £¬µ½2021ÄêÔÚÔÆ·þÎñÉϵÄÖ§³ö½«ÏûºÄITÔ¤ËãµÄÔ¼32£¥ £¬Òò´Ë¼àÊÓÆ½Ì¨µÄ¼àÊÓºÍÇå¾²ÐÔÖÁ¹ØÖ÷Òª¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/2021-economic-predictions-for-infosec/38553/