Ó¢ÌØ¶û°ä²¼11Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´77¸ö·ì϶£»£»£»£»£»£»¸ßͨоƬ×éQSEE·ì϶¿ÉÖÂAndroidÉ豸Êý¾Ýй¶
°ä²¼¹¦·ò 2019-11-151¡¢Ó¢Ìضû°ä²¼11Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´77¸ö·ì϶
Ó¢ÌØ¶ûÔÚ11Ô°²È«¸üÐÂÖн¨¸´ÁË77¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäÖг¬¹ý20¸ö·ì϶µÄµÈ¼¶Îª¸ßΣ»£»£»£»£»£»òÑϳÁ¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÓ¢ÌØ¶ûBMC¹Ì¼þÖеĶѰܻµ·ì϶£¨CVE-2019-11171£©»ñµÃÁËCVSS 9.0·Ö£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿Éµ¼ÖÂδ¾ÊÚȨµÄÔ¶³Ì¹¥»÷Õß½øÐÐÌáȨ¡¢ÐÅϢй¶»ò»Ø¾ø·þÎñ£¬£¬£¬£¬£¬£¬½¨ÒéËùÓÐЧ»§¸üе½BMC¹Ì¼þ2.18»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£Ó¢ÌضûCSME¼°TXEÊܵ½¶ÑÒç¶Âí½Å£¨CVE-2019-0169£©Ó°Ï죬£¬£¬£¬£¬£¬¸Ã·ì϶ͬÑù¿Éµ¼ÖÂÌØÈ¨Éý¼¶¡¢ÐÅϢй¶»ò»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£Ó¢Ìضû»¹½¨¸´ÁËWindowsºÍLinux°æÏÔ¿¨Çý¶¯ÖеÄLPE·ì϶£¨CVE-2019-0155£©¡£¡£¡£¡£¡£¡£¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-patched-77-vulnerabilities-in-november-2019-platform-update/
2¡¢¸ßͨоƬ×éQSEE·ì϶¿ÉÖÂAndroidÉ豸Êý¾Ýй¶
ƾ¾Ý°²È«³§ÉÌCheckPointµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬¸ßͨоƬ×éÖеݲȫִÐл·¾³£¨QSEE£©ÖдæÔÚ·ì϶£¨CVE-2019-10574£©£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂAndroidÉ豸ÖеÄÓ×ÎÒÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£QSEEÊÇ»ùÓÚARM TrustZone¼¼ÊõµÄÊÜÐÅÀµÖ´Ðл·¾³£¨TEE£©µÄʵÏÖ£¬£¬£¬£¬£¬£¬ÊÇÖ÷´¦ÖÃÆ÷ÉϵÄÒ»¸öÓ²¼þ¸ôÀëµÄ°²È«ÇøÓò£¬£¬£¬£¬£¬£¬ÆäÖÐͨ³£Ô̺¬×¨ÓüÓÃÜÃÜÔ¿¡¢ÃÜÂë¡¢ÐÅÓþ¿¨ºÍ½è¼Ç¿¨Í´´¦µÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Check Point×êÑÐÈËÔ±ÄæÏòÁ˸Ãϵͳ£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÍÌͲâÊÔ¶ÔÈýÐÇ¡¢LGºÍĦÍÐÂÞÀÉ豸½øÐÐÁ˲âÊÔ¡£¡£¡£¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÈýÐǵÄÊÜÐÅÀµ´úÂëÔ̺¬Ëĸö·ì϶£¬£¬£¬£¬£¬£¬Ä¦ÍÐÂÞÀºÍLG±ðÀëÔ̺¬Ò»¸ö·ì϶£¬£¬£¬£¬£¬£¬µ«ËùÓдúÂë¾ùÀ´×Ô¸ßͨ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£ÈýÐÇ¡¢¸ßͨºÍLGÒÑÕë¶ÔÕâЩQSEE·ì϶°ä²¼Á˲¹¶¡¸üС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/11/qualcomm-android-hacking.html
3¡¢Ó¢ÌضûPMxÇý¶¯·¨Ê½·ì϶¿ÉÔÊÐíºÚ¿ÍÆëÈ«½ÚÔìÉ豸
Ó¢ÌØ¶û°ä²¼PMxÇý¶¯·¨Ê½µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Ò»×éÓÉEclypsium°²È«×¨¼Ò·¢Ïֵķì϶¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶¿ÉÄܵ¼Ö¹¥»÷Õ߯ëÈ«½ÚÔìÊܺ¦ÕßµÄÉ豸¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ°ËÔ·ÝEclypsium×êÑÐÈËÔ±Åû¶ÁË20¶à¼ÒÓ²¼þ³§É̵ÄÄÚºËÇý¶¯·¨Ê½ÖеÄ40¶à¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäʱֻÓÐÓ¢ÌØ¶ûºÍ»ªÎª°ä²¼Á˲¹¶¡·¨Ê½ºÍ°²È«²¼¸æ£¬£¬£¬£¬£¬£¬ÒÔ¼°PhoenixºÍInsydeΪÆäOEM¿Í»§ÌṩÁ˽¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£Eclypsium´Ë¿Ì°µÊ¾Ó¢ÌضûPMxÇý¶¯·¨Ê½Öеķì϶¿ÉÒÔΪ¹¥»÷ÕßÌṩÏÕЩȫÄܵĽÚÔìȨÏÞ£¬£¬£¬£¬£¬£¬Ô̺¬¶ÁдÎïÀíÄÚ´æ¡¢¶ÁÐ´ÌØ¶¨¼Ä·ÅÆ÷¡¢¶ÁдIDTºÍGDT¡¢»ñµÃËÁÒâI/O½Ó¼ûȨÏÞ¼°PCI½Ó¼ûȨÏ޵ȡ£¡£¡£¡£¡£¡£¡£¡£Eclypsium½¨ÒéÓû§ÎªÖ§³Ö¸ÃÖ°ÄܵÄÉ豸ÆôÓÃHVCIÀ´×èÖ¹·ì϶±»ÀûÓ㬣¬£¬£¬£¬£¬µ«¸ÃÑ¡Ïî½öºÏÓÃÓÚµÚ7´ú»ò¸ü¸ß°æ±¾µÄ´¦ÖÃÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/93826/hacking/pmx-driver-intel-driver-flaw.html
4¡¢2018ÄêÒÔÀ´Ò½ÁÆÐÐҵϰȾ¶ñÒâÈí¼þ´ÎÊýÉÏÉý60%
ƾ¾ÝMalwarebytesµÄµ÷²é£¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×ÓÔ½À´Ô½¶àµØ½«Êý¾ÝÇÔÈ¡ºÍÀÕË÷Èí¼þ¹¥»÷µÄ³Áµã·ÅÔÚÒ½ÁƱ£½¡×éÖ¯£¨HCO£©ÉÏ¡£¡£¡£¡£¡£¡£¡£¡£´Ó2018Äêµ½2019ÄêǰÈý¸ö¼¾¶È£¬£¬£¬£¬£¬£¬ÒѼì²âµ½µÄϰȾ´ÎÊýÔö³¤ÁË60£¥¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÖØÒªÊÇÊܵ½»¼ÕßPII´øÀ´µÄ¸ßͶ×ʻر¨Âʼ°´óÁ¿Öն˼°ÏνÓÉ豸´øÀ´µÄ¿í·º¹¥»÷ÃæµÄÎüÒý¡£¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ¸ÃÐÐÒµÖÐͨ³£´æÔÚϵͳÀϾɡ¢²¹¶¡ÖÎÀí²»ÉÆ¡¢Ô±¹¤°²È«ÖªÊ¶²»¼°ÒÔ¼°É豸δÊܱ£»£»£»£»£»£»¤µÈÎÊÌ⣬£¬£¬£¬£¬£¬Ê¹µÃÒ½Ôº³ÉΪ¸ü¾ßÎüÒýÁ¦µÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ2019ÄêµÚ¶þ¼¾¶ÈºÍµÚÈý¼¾¶ÈÖ®¼ä£¬£¬£¬£¬£¬£¬¼ì²âµ½µÄÍþвÔö³¤ÁË45%£¬£¬£¬£¬£¬£¬ÆäÖÐľÂíÊÇ×îÊÜ»¶ÓµÄ¶ñÒâÈí¼þÀàÐÍ£¨Ôö³¤ÁË82%£¬£¬£¬£¬£¬£¬ÖØÒªÊÇÓÉEmotetºÍTrickBotµ¼Öµģ©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/healthcare-malware-infections-soar/
5¡¢2019Äêǰ9¸öÔ¹²ÓÐ79ÒÚÌõÊý¾ÝÔÚ¹«¿ªµÄÊÂÎñÖмͼ
ƾ¾ÝRisk Based SecurityµÄ2019ÄêµÚÈý¼¾¶ÈÊý¾Ýй¶ËÙÀÀ»ã±¨£¬£¬£¬£¬£¬£¬ÔÚ2019ÄêµÄǰ9¸öÔÂÖй«¿ª»ã±¨ÁË5183´ÎÎ¥¹æÊÂÎñ£¬£¬£¬£¬£¬£¬¹²Â¶³öÁË79Òڱʼͼ£¬£¬£¬£¬£¬£¬Ô¤¼ÆÕûÄêµÄÊý×ÖÓÐÍû´ïµ½85ÒÚÌõ¡£¡£¡£¡£¡£¡£¡£¡£Óë2018ÄêµÚÈý¼¾¶ÈÏà±È£¬£¬£¬£¬£¬£¬2019ÄêµÚÈý¼¾¶ÈµÄÎ¥¹æÊÂÎñÔö³¤ÁË33.3%¡£¡£¡£¡£¡£¡£¡£¡£Ò½ÁÆ·þÎñ¡¢ÁãÊÛÉ̺͹«¹²»ú¹¹Ôâ·êµÄÎ¥¹æÊÂÎñ×î¶à£¬£¬£¬£¬£¬£¬ºÚ¿Í¹¥»÷ÒÀÈ»ÊÇÊýÁ¿×î¶àµÄÊÂÎñÀàÐÍ£¬£¬£¬£¬£¬£¬WebÔòÔÚ½ñÄê¶³öÁË×î¶àµÄ¼Í¼ÌõÊý¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÊý¾Ý¿â¡¢±¸·Ý¡¢Öն˺ͷþÎñµÄÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬½ñÄê¹²Óг¬¹ý60Òڱʼͼ¹«¿ªÂ¶³ö¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/14/breaches-2019/
6¡¢×êÑÐÈËÔ±·¢ÏÖÒÁÀÊAPT33³ÉÁ¢×Ô¼ºµÄVPNÍøÂç
Ç÷Ïò¿Æ¼¼°²È«×êÑÐÈËÔ±·¢ÏÖÒÁÀʺڿÍ×éÖ¯APT33×齨ÁËÓµÓÐ21¸öVPN½ÚµãµÄרÓÃÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÇ÷Ïò¿Æ¼¼µÄÒ»·Ýл㱨£¬£¬£¬£¬£¬£¬2019ÄêÈ·ÈϵÄAPT33ϰȾÊÂÎñÔ̺¬Ò»¼ÒÌṩÓë¹ú¶È°²È«ÓйطþÎñµÄÃÀ¹ú¸öÈ˹«Ë¾¡¢ÃÀ¹úÒ»Ëù´óѧ¡¢ÓëÃÀ¹ú¾ü·½ÓйصÄÊܺ¦ÕßÒÔ¼°Öж«ºÍÑÇÖÞµÄÊýÃûÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ÔÚµ÷²éÕâЩÊÂÎñʱ£¬£¬£¬£¬£¬£¬ËûÃÇ¿ÉÄÜÉî¿ÌÏàʶAPT33ÈôºÎÖÎÀíÆä»ù´¡¼Ü¹¹¡£¡£¡£¡£¡£¡£¡£¡£APT33²Ù×÷Ô±ÓëÆäÖ¸±êÖ®¼äÓÐËIJã¼Ü¹¹£¬£¬£¬£¬£¬£¬Ô̺¬VPN²ã¡¢Bot½ÚÔìÆ÷²ã¡¢C£¦Cºó¶Ë²ã¼°´úÀí²ã¡£¡£¡£¡£¡£¡£¡£¡£APT33²¢Î´Ê¹ÓÃóÒ×VPN·þÎñÆ÷À´°µ²ØÆäµØÎ»£¬£¬£¬£¬£¬£¬¶øÊÇ×齨²¢ÔËÓª×Ô¼ºµÄרÓÃVPNÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£Ç÷Ïò¿Æ¼¼ÁгöÁËËùÓÐÒÑÖªµÄ21¸öVPN³ö¿Ú½Úµã¹ØÁªIPµØÖ·¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iranian-hacking-group-built-its-own-vpn-network/


¾©¹«Íø°²±¸11010802024551ºÅ