¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180824

°ä²¼¹¦·ò 2018-08-24

¡¾°²È«²¥±¨¡¿AppleÈ϶¨FacebookµÄVPNÀûÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß


Apple³ÆFacebookµÄÒÆ¶¯VPNÀûÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß£¬ £¬ £¬£¬£¬£¬£¬FacebookÒѾ­´ÓApp StoreÖÐϼÜÁ˸ÃÀûÓᣠ¡£¡£¡£¡£¡£Onavo ProtectÊÇÒ»¸öÃâ·ÑµÄVPN¹¤¾ß£¬ £¬ £¬£¬£¬£¬£¬¸Ã¹¤¾ßÄܹ»Ô®ÊÖFacebookÍøÂçÓû§µÄÁ÷Á¿Êý¾Ý£¬ £¬ £¬£¬£¬£¬£¬ÒÔÏàʶÓû§ÈôºÎʹÓõÚÈý·½app¡£ ¡£¡£¡£¡£¡£Ä¿Ç°¸Ã¹¤¾ßÒÑÔÚiOSºÍAndroidÉ豸¸ßµÍÔØÁ˳¬¹ý3300Íò´Î£¬ £¬ £¬£¬£¬£¬£¬²¢ÇÒÒÀÈ»´æÔÚÓÚGoogle PlayÉ̵êÖС£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/facebook-vpn-app-apple-store.html


¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÍŶӷ¢ÏÖÐÂAndroid¼äµýÈí¼þ¿ò¼ÜTriout


BitdefenderµÄ°²È«×êÑÐÈËÔ±·¢ÏÖÒ»¸öеġ¢Ö°ÄÜ׳´óµÄAndroid¶ñÒâÈí¼þ¿ò¼ÜTriout¡£ ¡£¡£¡£¡£¡£TrioutÄܹ»Â¼Ôìͨ»°¡¢¼à¿Ø¶ÌÐÅ¡¢ÇÔÈ¡ÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÍøÂ綨λÊý¾ÝµÈ£¬ £¬ £¬£¬£¬£¬£¬ÆäËÆºõ±»ÓÃÓÚÓÐÕë¶ÔÐԵļäµý»î¶¯¡£ ¡£¡£¡£¡£¡£Triout×îÔç³öÏÖÓÚ2018Äê5ÔÂ15ÈÕ£¬ £¬ £¬£¬£¬£¬£¬ÖØÒª³Ê´Ë¿ÌÒÔÉ«ÁС£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹²»Ã÷ÏÔTrioutµÄ´«²¼·½Ê½ºÍ×°ÖôÎÊý£¬ £¬ £¬£¬£¬£¬£¬ÒÔ¼°Æä±³ºóµÄ¹¥»÷Õß¡£ ¡£¡£¡£¡£¡£TrioutûÓÐʹÓûìºÏ¼¼Êõ£¬ £¬ £¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þ¿ÉÄÜ»¹ÔÚ¿ª·¢¹ý³ÌÖС£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/android-malware-spyware.html


¡¾¹¥»÷ÊÂÎñ¡¿×êÑÐÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÂòÂôËù


¿¨°Í˹»ù³¢ÊÔÊÒ×êÑÐÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÂòÂôƽ̨µÄITϵͳ£¬ £¬ £¬£¬£¬£¬£¬²¢²¿ÊðÁËÔ¶¿ØÄ¾ÂíFallchillÒÔ¼°Ò»¸öMac¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£Õâ¿ÉÄÜÊǸÃ×é֯ʹÓõÄÊ׸öMac¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£Ä¾Âí»¯µÄ¸Ã¼ÓÃÜÇ®±ÒÂòÂôÈí¼þÓÉÓÐЧµÄÊý×ÖÖ¤Êé½øÐÐÊðÃû£¬ £¬ £¬£¬£¬£¬£¬ÕâʹµÃËüÄܹ»Èƹý°²È«É¨Ãè¡£ ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿¨°Í˹»ùûÓÐй©±»ÈëÇֵļÓÃÜÇ®±ÒÂòÂôËùµÄÃû³Æ£¬ £¬ £¬£¬£¬£¬£¬²¢³ÆÃ»ÓÐÈκξ­¼ÃËðʧ²úÉú¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/lazarus-group-deploys-its-first-mac-malware-in-cryptocurrency-exchange-hack/


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±ÔÚOpenSSHÖз¢ÏÖÒ»´æÔÚ20ÄêµÄ°²È«·ì϶


Qualys¹«Ë¾°²È«×êÑÐÈËÔ±·¢ÏÖOpenSSH¿Í»§¶Ë´æÔÚÒ»¸öÐÝÃߵݲȫ·ì϶£¬ £¬ £¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2018-15473£©Ó°ÏìÁË´Óǰ¶þÊ®Äê°ä²¼µÄËùÓÐOpenSSH¿Í»§¶Ë°æ±¾¡£ ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶²Â²âSSH·þÎñÆ÷ÉϵÄÓÐЧÓû§Ãû£¬ £¬ £¬£¬£¬£¬£¬ÓÉÓÚOpenSSH¿Í»§¶Ë±»Ç¶Èëµ½´óÁ¿Èí¼þºÍÓ²¼þÉ豸ÖУ¬ £¬ £¬£¬£¬£¬£¬½¨¸´·¨Ê½¿ÉÄÜ񻮮·ÑÊýÔÂÉõÖÁÊýÄêÄÜÁ¦´ïµ½ËùÓеÄϵͳÖС£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±Åû¶Á˸÷ì϶µÄÓйØPoC´úÂë¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vulnerability-affects-all-openssh-versions-released-in-the-past-two-decades/


¡¾·ì϶²¹¶¡¡¿Î¢ÈíÕë¶ÔIntel CPUµÄL1TF·ì϶°ä²¼Î¢´úÂë¸üÐÂ


±¾ÖÜ΢ÈíÌṩÁËIntel CPUµÄÐÂÒ»ÂÖ΢´úÂë¸üУ¬ £¬ £¬£¬£¬£¬£¬ÓÃÓÚ½¨¸´×î½üµÄForeshadow/L1TF·ì϶¡£ ¡£¡£¡£¡£¡£Foreshadow/L1TF·ì϶£¨CVE-2018-3615¡¢CVE-2018-3620ºÍCVE-2018-3646£©¿ÉÔÊÐí¹¥»÷Õß½Ó¼ûÊܱ£»£»£» £»£» £»¤ÄÚ´æÖеÄDZÔÚÃô¸ÐÊý¾Ý£¬ £¬ £¬£¬£¬£¬£¬IntelµÄXeonºÍCoreϵÁд¦ÖÃÆ÷Êܵ½Ó°Ïì¡£ ¡£¡£¡£¡£¡£Î¢Èí±¾Öܰ䲼ÁËÎå¸ö¸üУ¬ £¬ £¬£¬£¬£¬£¬Ô̺¬KB4346084¡¢KB4346085¡¢KB4346086¡¢KB4346087ºÍKB4346088¡£ ¡£¡£¡£¡£¡£Foreshadow·ì϶µÄ²¹¶¡²»»á¶ÔÏû·ÑÕßPCµÄ»úÄܲúÉúÏÔÖøÓ°Ï죬 £¬ £¬£¬£¬£¬£¬µ«Ä³Ð©Êý¾ÝÖÐÐĵŤ×÷¸ºÔØ¿ÉÄÜ»á³öÏÖ»úÄܽµÂä¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/microsoft-releases-intel-microcode-patches-foreshadow-flaws


¡¾Êý¾Ýй¶¡¿Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬ £¬ £¬£¬£¬£¬£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶


Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª¹úµ±¾ÖµÄÖҸ棬 £¬ £¬£¬£¬£¬£¬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£ ¡£¡£¡£¡£¡£Ä¿Ç°ÔÚ°µÍøÉÏÏúÊÛµÄÓйØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£ ¡£¡£¡£¡£¡£µ÷²éÅú×¢£¬ £¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕÆÚ¼äÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ£¬ £¬ £¬£¬£¬£¬£¬ÕâÒâζ×ŵ±Ç°µÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£ ¡£¡£¡£¡£¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼Óзֵ꣬ £¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»£»£» £»£» £»¤·þÎñ¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/