¡¾°²È«²¥±¨¡¿AppleÈ϶¨FacebookµÄVPNÀûÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß
Apple³ÆFacebookµÄÒÆ¶¯VPNÀûÓÃOnavo ProtectÎ¥·´ÆäÊý¾ÝÍøÂçÕþ²ß£¬FacebookÒѾ´ÓApp StoreÖÐϼÜÁ˸ÃÀûÓá£Onavo ProtectÊÇÒ»¸öÃâ·ÑµÄVPN¹¤¾ß£¬¸Ã¹¤¾ßÄܹ»Ô®ÊÖFacebookÍøÂçÓû§µÄÁ÷Á¿Êý¾Ý£¬ÒÔÏàʶÓû§ÈôºÎʹÓõÚÈý·½app¡£Ä¿Ç°¸Ã¹¤¾ßÒÑÔÚiOSºÍAndroidÉ豸¸ßµÍÔØÁ˳¬¹ý3300Íò´Î£¬²¢ÇÒÒÀÈ»´æÔÚÓÚGoogle PlayÉ̵êÖС£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/facebook-vpn-app-apple-store.html
¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÍŶӷ¢ÏÖÐÂAndroid¼äµýÈí¼þ¿ò¼ÜTriout
BitdefenderµÄ°²È«×êÑÐÈËÔ±·¢ÏÖÒ»¸öеġ¢Ö°ÄÜ׳´óµÄAndroid¶ñÒâÈí¼þ¿ò¼ÜTriout¡£TrioutÄܹ»Â¼Ôìͨ»°¡¢¼à¿Ø¶ÌÐÅ¡¢ÇÔÈ¡ÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÍøÂ綨λÊý¾ÝµÈ£¬ÆäËÆºõ±»ÓÃÓÚÓÐÕë¶ÔÐԵļäµý»î¶¯¡£Triout×îÔç³öÏÖÓÚ2018Äê5ÔÂ15ÈÕ£¬ÖØÒª³Ê´Ë¿ÌÒÔÉ«ÁС£×êÑÐÈËÔ±»¹²»Ã÷ÏÔTrioutµÄ´«²¼·½Ê½ºÍ×°ÖôÎÊý£¬ÒÔ¼°Æä±³ºóµÄ¹¥»÷Õß¡£TrioutûÓÐʹÓûìºÏ¼¼Êõ£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þ¿ÉÄÜ»¹ÔÚ¿ª·¢¹ý³ÌÖС£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/android-malware-spyware.html
¡¾¹¥»÷ÊÂÎñ¡¿×êÑÐÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÂòÂôËù
¿¨°Í˹»ù³¢ÊÔÊÒ×êÑÐÍŶӳƳ¯ÏÊAPT×éÖ¯Lazarus GroupÈëÇÖÑÇÖÞÒ»¼ÓÃÜÇ®±ÒÂòÂôƽ̨µÄITϵͳ£¬²¢²¿ÊðÁËÔ¶¿ØÄ¾ÂíFallchillÒÔ¼°Ò»¸öMac¶ñÒâÈí¼þ¡£Õâ¿ÉÄÜÊǸÃ×é֯ʹÓõÄÊ׸öMac¶ñÒâÈí¼þ¡£Ä¾Âí»¯µÄ¸Ã¼ÓÃÜÇ®±ÒÂòÂôÈí¼þÓÉÓÐЧµÄÊý×ÖÖ¤Êé½øÐÐÊðÃû£¬ÕâʹµÃËüÄܹ»Èƹý°²È«É¨Ãè¡£¿¨°Í˹»ùûÓÐй©±»ÈëÇֵļÓÃÜÇ®±ÒÂòÂôËùµÄÃû³Æ£¬²¢³ÆÃ»ÓÐÈκξ¼ÃËðʧ²úÉú¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/lazarus-group-deploys-its-first-mac-malware-in-cryptocurrency-exchange-hack/
¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±ÔÚOpenSSHÖз¢ÏÖÒ»´æÔÚ20ÄêµÄ°²È«·ì϶
Qualys¹«Ë¾°²È«×êÑÐÈËÔ±·¢ÏÖOpenSSH¿Í»§¶Ë´æÔÚÒ»¸öÐÝÃߵݲȫ·ì϶£¬¸Ã·ì϶£¨CVE-2018-15473£©Ó°ÏìÁË´Óǰ¶þÊ®Äê°ä²¼µÄËùÓÐOpenSSH¿Í»§¶Ë°æ±¾¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶²Â²âSSH·þÎñÆ÷ÉϵÄÓÐЧÓû§Ãû£¬ÓÉÓÚOpenSSH¿Í»§¶Ë±»Ç¶Èëµ½´óÁ¿Èí¼þºÍÓ²¼þÉ豸ÖУ¬½¨¸´·¨Ê½¿ÉÄÜ񻮮·ÑÊýÔÂÉõÖÁÊýÄêÄÜÁ¦´ïµ½ËùÓеÄϵͳÖС£×êÑÐÈËÔ±Åû¶Á˸÷ì϶µÄÓйØPoC´úÂë¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vulnerability-affects-all-openssh-versions-released-in-the-past-two-decades/
¡¾·ì϶²¹¶¡¡¿Î¢ÈíÕë¶ÔIntel CPUµÄL1TF·ì϶°ä²¼Î¢´úÂë¸üÐÂ
±¾ÖÜ΢ÈíÌṩÁËIntel CPUµÄÐÂÒ»ÂÖ΢´úÂë¸üУ¬ÓÃÓÚ½¨¸´×î½üµÄForeshadow/L1TF·ì϶¡£Foreshadow/L1TF·ì϶£¨CVE-2018-3615¡¢CVE-2018-3620ºÍCVE-2018-3646£©¿ÉÔÊÐí¹¥»÷Õß½Ó¼ûÊܱ£»¤ÄÚ´æÖеÄDZÔÚÃô¸ÐÊý¾Ý£¬IntelµÄXeonºÍCoreϵÁд¦ÖÃÆ÷Êܵ½Ó°Ï졣΢Èí±¾Öܰ䲼ÁËÎå¸ö¸üУ¬Ô̺¬KB4346084¡¢KB4346085¡¢KB4346086¡¢KB4346087ºÍKB4346088¡£Foreshadow·ì϶µÄ²¹¶¡²»»á¶ÔÏû·ÑÕßPCµÄ»úÄܲúÉúÏÔÖøÓ°Ï죬µ«Ä³Ð©Êý¾ÝÖÐÐĵŤ×÷¸ºÔØ¿ÉÄÜ»á³öÏÖ»úÄܽµÂä¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/microsoft-releases-intel-microcode-patches-foreshadow-flaws
¡¾Êý¾Ýй¶¡¿Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶
Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª¹úµ±¾ÖµÄÖҸ棬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£Ä¿Ç°ÔÚ°µÍøÉÏÏúÊÛµÄÓйØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£µ÷²éÅú×¢£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕÆÚ¼äÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ£¬ÕâÒâζ×ŵ±Ç°µÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼Óзֵ꣬¸Ã¹«Ë¾ÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»¤·þÎñ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/