macOSË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂÌáȨ¼°´úÂëÖ´ÐУ»£»£»£»£»£»2018ÄêÓ¢¹úÉí·ÝڲƭÂÊÔöÌí8£¥£¬£¬£¬£¬£¬´´Àúʷиß

Ðû²¼Ê±¼ä 2019-06-24
1.macOSË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂÌáȨ¼°´úÂëÖ´ÐÐ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±ÔÚmacOSÖз¢Ã÷Ò»¸öË«ÖØÊÍ·ÅÎó²î£¨CVE-2019-8635£©¡£¡£¡£¡£¡£¡£ ¡£¸ÃÎó²îÊÇÓÉAMD×é¼þÖеÄÄÚ´æËð»µÎÊÌâÒýÆðµÄ£¬£¬£¬£¬£¬ÈôÊÇÀÖ³ÉʹÓ㬣¬£¬£¬£¬¹¥»÷Õß¿ÉÌáȨÖÁrootȨÏÞ²¢ÔÚϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¸ÃCVE IDº­¸ÇÁ½¸öË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬µÚÒ»¸ö±£´æÓÚAMDRadeonX4000_AMDSIGLContextÀàµÄdiscard_StretchTex2TexÒªÁìÖУ¬£¬£¬£¬£¬µÚ¶þ¸öÊǸÃÀàµÄprocess_StretchTex2TexÒªÁì¡£¡£¡£¡£¡£¡£ ¡£AppleÔÚmacOS Mojave 10.14.4¸üÐÂÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/cve-2019-8635-double-free-vulnerability-in-apple-macos-lets-attackers-escalate-system-privileges-and-execute-arbitrary-code/

2.Torä¯ÀÀÆ÷Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Sandbox EscapeÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Torä¯ÀÀÆ÷Ðû²¼Ð°汾8.5.3£¬£¬£¬£¬£¬ÐÞ¸´FirefoxÖеÄSandbox EscapeÎó²î£¨CVE-2019-11708£©¡£¡£¡£¡£¡£¡£ ¡£¸ÃÎó²îÔÚ×î½üÕë¶Ô¼ÓÃÜÇ®±Ò¹«Ë¾µÄ¹¥»÷Öб»Ê¹Ó㬣¬£¬£¬£¬ÓÉÓÚ·¸·¨·Ö×ÓÕýÔÚÆð¾¢Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéËùÓÐTorÓû§Éý¼¶µ½×îа汾¡£¡£¡£¡£¡£¡£ ¡£´ËǰTorÐû²¼ÁËTor 8.5.2£¬£¬£¬£¬£¬ÐÞ¸´FirefoxÖеÄRCEÎó²î£¨CVE-2019-11707£©£¬£¬£¬£¬£¬ÕâÁ½¸öÎó²îÁ¬ÏµÆðÀ´£¬£¬£¬£¬£¬¿ÉÔÚÊܺ¦ÕßµÄÅÌËã»úÉÏÏÂÔØºÍ×°ÖÃÐÅÏ¢ÇÔȡľÂí¼°Ô¶³Ì»á¼ûÅÌËã»úÍøÂç¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/tor-browser-853-fixes-a-sandbox-escape-vulnerability-in-firefox/

3.Pink Camera APPѬȾ¶ñÒâÈí¼þMobOk£¬£¬£¬£¬£¬ÏÂÔØÁ¿´ï1Íò´Î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¿¨°Í˹»ùÑо¿Ö°Ô±Igor Golovin·¢Ã÷Google PlayÊÐËÁÖеÄPink CameraÓ¦ÓÃѬȾ¶ñÒâÈí¼þMobOk¡£¡£¡£¡£¡£¡£ ¡£Pink CameraºÍPink Camera 2Òѱ»×°ÖÃÁËԼĪ1Íò´Î£¬£¬£¬£¬£¬ÆäÒþ²ØµÄMobOkÖ¼ÔÚÇÔÈ¡Óû§µÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬²¢Ê¹ÓÃÕâЩÐÅÏ¢¾ÙÐи¶·Ñ¶©ÔÄ¡£¡£¡£¡£¡£¡£ ¡£¸ÃÓ¦ÓóÌÐò»áÇëÇó»á¼ûWi-Fi¿Ø¼þºÍ֪ͨ£¬£¬£¬£¬£¬²¢ÔÚ¹¥»÷½×¶Î¹Ø±ÕWi-Fi£¬£¬£¬£¬£¬´Ó¶ø¼¤»îÒÆ¶¯Êý¾ÝºÍ¾ÙÐи¶·Ñ¶©ÔÄ¡£¡£¡£¡£¡£¡£ ¡£ÕâЩÓöȻáÖ±½Ó´ÓÓû§µÄ»°·ÑÖп۳ý£¬£¬£¬£¬£¬¶ø²»ÊÇÐÅÓÿ¨»ò½è¼Ç¿¨¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/mobok-malware-google-photo-editor/145932/

4.ÐÂÀÕË÷Èí¼þLooCipher£¬£¬£¬£¬£¬Ö÷Ҫͨ¹ýÀ¬»øÓʼþÈö²¥


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ô±Petrovic·¢Ã÷ÐÂÀÕË÷Èí¼þLooCipher¡£¡£¡£¡£¡£¡£ ¡£¸ÃÀÕË÷Èí¼þÕýÔÚÒ°Íâ±»Æð¾¢Èö²¥£¬£¬£¬£¬£¬ËäÈ»ÏÖÔÚÉв»ÇåÎúÆä·Ö·¢·½·¨£¬£¬£¬£¬£¬µ«Ò»Ð©ÎļþÅú×¢¸ÃÀÕË÷Èí¼þÊÇͨ¹ýÀ¬»øÓʼþÈö²¥µÄ¡£¡£¡£¡£¡£¡£ ¡£LooCipherͨ¹ýÃûΪInfo_BSV_2019.docmµÄ¶ñÒâWordÎĵµÈö²¥£¬£¬£¬£¬£¬¸ÃÎĵµÖаüÀ¨ÓÃÓÚÏÂÔØºÍÖ´ÐÐpayloadµÄºê´úÂë¡£¡£¡£¡£¡£¡£ ¡£LooCipher»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lcphrÀ©Õ¹Ãû£¬£¬£¬£¬£¬ÆäÀÕË÷µÄÊê½ðΪ300Å·Ôª»òÔ¼330ÃÀÔª¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-loocipher-ransomware-spreads-its-evil-through-spam/

5.2018ÄêÓ¢¹úÉí·ÝڲƭÂÊÔöÌí8£¥£¬£¬£¬£¬£¬´´Àúʷиß


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤·ÇÓªÀû·´Ú²Æ­×éÖ¯CifasµÄ±¨¸æ£¬£¬£¬£¬£¬2018ÄêÓ¢¹úµÄÉí·ÝڲƭÂÊÉÏÉýÁË8%£¬£¬£¬£¬£¬´´Àúʷиߡ£¡£¡£¡£¡£¡£ ¡£±¨¸æÖмͼÁË2018Ä걬·¢µÄ½ü32.4ÍòÆðڲƭ°¸Àý£¬£¬£¬£¬£¬ÕâÒ»Êý×Ö×Ô2017ÄêµÄÏ»¬ºóÓֻص½2015ÄêºÍ2016ÄêµÄ½Ï¸ßˮƽ¡£¡£¡£¡£¡£¡£ ¡£87%µÄÉí·ÝڲƭÊÇͨ¹ýÍøÂç¾ÙÐеġ£¡£¡£¡£¡£¡£ ¡£ÔâÊÜÉí·ÝڲƭµÄ60ËêÒÔÉÏÉú³ÝÔöÌíÁË34%£¬£¬£¬£¬£¬¶ø21ËêÒÔϵÄÉú³ÝÔòÔöÌíÁË26%¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/uk-identity-fraud-jumps-8-to-new-1-1/

6.ÃÀCISAÖÒÑÔÒÁÀʺڿÍÕë¶ÔÃÀ¹ú¹¤ÒµºÍÕþ¸®»ú¹¹µÄÍøÂç¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤ÃÀ¹úÁìÍÁÇå¾²²¿ÍøÂçÇå¾²Óë»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©µÄÒ»·ÝÉùÃ÷£¬£¬£¬£¬£¬ÒÁÀʺڿÍÕë¶ÔÃÀ¹ú¹¤ÒµºÍÕþ¸®»ú¹¹µÄÍøÂç¹¥»÷ÕýÔÚÔöÌí£¬£¬£¬£¬£¬Æä¹¥»÷ÊֶΰüÀ¨£ºÊ¹ÓÃÊý¾Ý²Á³ý¶ñÒâÈí¼þ¡¢×²¿â¹¥»÷¡¢ÃÜÂëÅçÉä¹¥»÷ºÍÓã²æÊ½ÍøÂç´¹ÂÚ¡£¡£¡£¡£¡£¡£ ¡£¸ÃÖÒÑÔÐû²¼ÔÚCISAÖ÷¹ÜChristopher KrebsµÄtweetÉÏ£¬£¬£¬£¬£¬²¢½«ÔÚCISAÍøÕ¾ÉÏÐû²¼¡£¡£¡£¡£¡£¡£ ¡£¸ÃÉùÃ÷Ö¸³ö£¬£¬£¬£¬£¬¡°CISA·¢Ã÷ÒÁÀÊÕë¶ÔÃÀ¹ú¹¤ÒµºÍÕþ¸®»ú¹¹µÄ¶ñÒâÍøÂç»î¶¯ÕýÔÚÔöÌí£¬£¬£¬£¬£¬ÎÒÃǽ«¼ÌÐøÓëÇ鱨ÉçÇøºÍÍøÂçÇå¾²ÏàÖúͬ°éÏàÖú¼à¿ØÒÁÀʵÄÍøÂç»î¶¯¡¢¹²ÏíÐÅÏ¢²¢½ÓÄÉÐж¯ÒÔÈ·±£ÃÀ¹úºÍÃËÓѵÄÇå¾²¡±¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-government-warns-of-data-wipers-used-in-iranian-cyberattacks/