UCä¯ÀÀÆ÷ÖÐÐÄÈ˹¥»÷ £¬£¬£¬£¬£¬£¬£¬²¨¼°5ÒÚÓû§£»£»£» £» £»£»ÀÕË÷Èí¼þLockerGoga£»£»£» £» £»£»»ªÎªPCManagerÌáȨºÍRCEÎó²î

Ðû²¼Ê±¼ä 2019-03-27
1¡¢UCä¯ÀÀÆ÷Ò×ÔâÖÐÐÄÈ˹¥»÷ £¬£¬£¬£¬£¬£¬£¬²¨¼°5ÒÚÓû§

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ƾ֤Çå¾²³§ÉÌDr. WebÐû²¼µÄÒ»·Ýб¨¸æ £¬£¬£¬£¬£¬£¬£¬UCä¯ÀÀÆ÷ÖÁÉÙ´Ó2016Äê×îÏȾ;ßÓÐÒ»¸öÒþ²ØµÄ¹¦Ð§ £¬£¬£¬£¬£¬£¬£¬¿É´Ó¹«Ë¾µÄЧÀÍÆ÷ÏòÓû§µÄAndroid×°±¸ÏÂÔØ²¢×°ÖÃеĿâºÍÄ£¿ £¿£¿£¿£¿£¿é¡£ ¡£¡£ÓÉÓڴ˹¦Ð§ÊÇ»ùÓÚHTTPЭÒé £¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÖ´ÐÐMiTM¹¥»÷²¢ÏòÓû§ÍÆËͶñÒâÄ£¿ £¿£¿£¿£¿£¿é¡£ ¡£¡£UCä¯ÀÀÆ÷²¢Î´¼ì²é²å¼þµÄÊðÃû £¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ŶñÒâÄ£¿ £¿£¿£¿£¿£¿é½«»áÎÞÐèÑéÖ¤¶øÖ±½ÓÆô¶¯¡£ ¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬£¬ÕâÒ»¹¦Ð§Ò²Î¥·´ÁËGoogle PlayµÄÇå¾²Õþ²ß¡£ ¡£¡£ËùÓа汾µÄUCä¯ÀÀÆ÷ºÍUC Miniä¯ÀÀÆ÷¾ùÊÜÓ°Ïì £¬£¬£¬£¬£¬£¬£¬¾Ý³Æ¸Ãä¯ÀÀÆ÷ÔÚÖйúºÍÓ¡¶ÈÓµÓÐÁè¼Ý5ÒÚÓû§¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/uc-browser-android-hacking.html

2¡¢ÃÀ¹úHexionºÍMomentive¹«Ë¾ÔâÀÕË÷Èí¼þLockerGoga¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÃÀ¹ú»¯Ñ§Æ·ÖÆÔ칫˾HexionºÍMomentive³ÉΪÀÕË÷Èí¼þLockerGogaµÄ×îÐÂÊܺ¦Õß¡£ ¡£¡£Æ¾Ö¤MomentiveÄäÃûÔ±¹¤µÄ˵·¨ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÊÂÎñ±¬·¢ÔÚ3ÔÂ12ÈÕ £¬£¬£¬£¬£¬£¬£¬ÓÉÓڴ˴ι¥»÷ £¬£¬£¬£¬£¬£¬£¬ÏµÍ³ÖеÄËùÓÐÊý¾Ý¾ùÒÑɥʧ¡£ ¡£¡£Æ¾Ö¤MotherboardµÄ±¨¸æ £¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÊÂÎñÖеÄÑù±¾Óë֮ǰÕë¶ÔŲÍþÂÁ³§Norsk HydroµÄ¹¥»÷Ñù±¾¾ßÓÐÏàͬµÄÌØÕ÷¡£ ¡£¡£MomentiveÈ·ÈÏÁ˴˴ι¥»÷ £¬£¬£¬£¬£¬£¬£¬µ«HexionÉÐδÅû¶ÈκÎÏà¹ØÏ¸½Ú¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/lockergoga-ransomware-hits-two-more-companies-in-the-manufacturing-sector-c8274160

3¡¢¹È¸èÐÞ¸´ChromeÖеÄа¶ñ¹â±êÎó²î £¬£¬£¬£¬£¬£¬£¬Òѱ»ÊÖÒÕÖ§³ÖթƭʹÓÃ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¹È¸èÐÞ¸´ÁËChromeÖеÄа¶ñ¹â±êÎó²î £¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÏÖÔÚÒѱ»ÊÖÒÕÖ§³ÖÕ©Æ­ÕßÔÚÒ°ÍâÆð¾¢Ê¹Óà £¬£¬£¬£¬£¬£¬£¬ÏêϸÀ´Ëµ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«±ê×¼µÄ32¡Á32ÏñËØÊó±ê¹â±êͼÐÎÌæ»»³É128»ò256ÏñËØ¾ÞϸµÄͼÐÎ £¬£¬£¬£¬£¬£¬£¬Í¨Ë׵Ĺâ±êÈÔÈ»»á·ºÆðÔÚÆÁÄ»ÉÏ £¬£¬£¬£¬£¬£¬£¬µ«»á·ºÆðÔڽϴó͸Ã÷½çÏß¿òµÄ½ÇÂä £¬£¬£¬£¬£¬£¬£¬Í¨¹ýÕâÖÖ·½·¨ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×èÖ¹Óû§¹Ø±Õ²¢ÍÑÀë¶ñÒâÒ³Ãæ¡£ ¡£¡£ÔÚÐÞ¸´²¹¶¡ÖÐ £¬£¬£¬£¬£¬£¬£¬µ±Êó±êÐüÍ£ÔÚChromeµÄ±êÇ©À¸¡¢µØµãÀ¸¡¢²Ëµ¥µÈÇøÓòʱ £¬£¬£¬£¬£¬£¬£¬Chrome»á×Ô¶¯½«Êó±ê»¹Ô­Îª±ê×¼OSͼÐΡ£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-fixes-chrome-evil-cursor-bug-abused-by-tech-support-scam-sites/

4¡¢Grandstream×°±¸¶à¸öÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¶ñÒâÈí¼þ±»×°Öü°ÇÔÌý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ƾ֤Trustwave SpiderLabsÐû²¼µÄ±¨¸æ £¬£¬£¬£¬£¬£¬£¬GrandstreamÃæÏòÖÐСÐÍÆóÒµµÄ¶à¸öÍøÂç×°±¸£¨IP PBX¡¢¾Û»á×°±¸¡¢IPÊÓÆµµç»°ºÍ·ÓÉÆ÷£©±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×°ÖöñÒâÈí¼þ¼°ÇÔÌýÉãÏñÍ·ºÍÂó¿Ë·ç¡£ ¡£¡£ÓÉÓÚËùÓÐ×°±¸¶¼ÒÔrootȨÏÞÔËÐÐ £¬£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¼°í§Òâ²Ù×÷¡£ ¡£¡£ÕâЩÎó²îÓÚ2018Äê12Ô±¨¸æ¸øGrandstream £¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѾ­Ðû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/grandstream-bugs-smbs-attacks/143141/


5¡¢Ñо¿ÍŶӷ¢Ã÷»ªÎªPCManager±£´æÌáȨ¼°´úÂëÖ´ÐÐÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÑо¿Ö°Ô±ÔÚ»ªÎªµÄPCManager¹¤¾ßÖз¢Ã÷Á½¸öÇå¾²Îó²î¡£ ¡£¡£PCManagerÊÇԤװÔÚMateBookÌõ¼Ç±¾µçÄÔÉϵÄÖÎÀí¹¤¾ß £¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã¹¤¾ßµÄ×°±¸ÖÎÀíÇý¶¯³ÌÐò±£´æÍâµØÌáȨÎó²î£¨CVE-2019-5241£©ºÍí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5242£©¡£ ¡£¡£»£»£» £» £»£»ªÎªÒÑÔÚ1Ô·ÝÐÞ¸´ÁËÕâÁ½¸öÎó²î¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/82893/hacking/huawei-tool-flaws.html

6¡¢Æ»¹ûÐû²¼iOS 12.2 £¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´51¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

±¾ÖÜһƻ¹ûÐû²¼iOS 12.2 £¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁË51¸öÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ×°±¸°üÀ¨iPhone 5s¼°Ö®ºóµÄ°æ±¾¡¢iPad Air¼°Ö®ºóµÄ°æ±¾ºÍiPod touch 6¡£ ¡£¡£´ó´ó¶¼Îó²î¶¼ÓëWebäÖȾÒýÇæWebKitÓÐ¹Ø £¬£¬£¬£¬£¬£¬£¬Îó²î¹æÄ£°üÀ¨í§Òâ´úÂëÖ´ÐС¢Ãô¸ÐÐÅϢй¶¡¢É³ÏäÈÆ¹ý¼°XSS¹¥»÷µÈ¡£ ¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬£¬Æ»¹û»¹ÐÞ¸´ÁËiOSÄÚºËÖеÄ6¸öÎó²î £¬£¬£¬£¬£¬£¬£¬°üÀ¨DoSÎó²î£¨CVE-2019-8527£©ºÍÌáȨÎó²î£¨CVE-2019-8514£©µÈ¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/ios-update-iphone-security.html

ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí