UCä¯ÀÀÆ÷ÖÐÑëÈ˹¥»÷£¬²¨¼°5ÒÚÓû§£»ÀÕË÷Èí¼þLockerGoga£»»ªÎªPCManagerÌáȨºÍRCE·ì϶

°ä²¼¹¦·ò 2019-03-27
1¡¢UCä¯ÀÀÆ÷Ò×ÔâÖÐÑëÈ˹¥»÷£¬²¨¼°5ÒÚÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾Ý°²È«³§ÉÌDr. Web°ä²¼µÄÒ»·Ýл㱨£¬UCä¯ÀÀÆ÷ÖÁÉÙ´Ó2016ÄêÆðÍ·¾ÍÓµÓÐÒ»¸ö°µ²ØµÄÖ°ÄÜ£¬¿É´Ó¹«Ë¾µÄ·þÎñÆ÷ÏòÓû§µÄAndroidÉ豸ÏÂÔØ²¢×°ÖÃеĿâºÍÄ £¿é¡£ÓÉÓÚ´ËÖ°ÄÜÊÇ»ùÓÚHTTPºÍ̸£¬Ê¹µÃ¹¥»÷Õß¿ÉÖ´ÐÐMiTM¹¥»÷²¢ÏòÓû§ÍÆËͶñÒâÄ £¿é¡£UCä¯ÀÀÆ÷²¢Î´²é³­²å¼þµÄÊðÃû£¬ÕâÒâζ×ŶñÒâÄ £¿é½«»áÎÞÐèÑéÖ¤¶øÖ±½ÓÆô¶¯¡£´Ë±í£¬ÕâÒ»Ö°ÄÜҲΥ·´ÁËGoogle PlayµÄ°²È«Õþ²ß¡£ËùÓа汾µÄUCä¯ÀÀÆ÷ºÍUC Miniä¯ÀÀÆ÷¾ùÊÜÓ°Ï죬¾Ý³Æ¸Ãä¯ÀÀÆ÷ÔÚÖйúºÍÓ¡¶Å×µÓг¬¹ý5ÒÚÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/uc-browser-android-hacking.html

2¡¢ÃÀ¹úHexionºÍMomentive¹«Ë¾ÔâÀÕË÷Èí¼þLockerGoga¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃÀ¹ú»¯Ñ§Æ·Ôì×÷¹«Ë¾HexionºÍMomentive³ÉΪÀÕË÷Èí¼þLockerGogaµÄ×îÐÂÊܺ¦Õß¡£Æ¾¾ÝMomentiveÄäÃûÔ±¹¤µÄ˵·¨£¬¹¥»÷ÊÂÎñ²úÉúÔÚ3ÔÂ12ÈÕ£¬ÓÉÓÚÕâ´Î¹¥»÷£¬ÏµÍ³ÖеÄËùº±¼û¾Ý¾ùÒÑÃÔʧ¡£Æ¾¾ÝMotherboardµÄ»ã±¨£¬Õâ´Î¹¥»÷ÊÂÎñÖеÄÑù±¾Óë֮ǰÕë¶ÔŲÍþÂÁ³§Norsk HydroµÄ¹¥»÷Ñù±¾ÓµÓÐÒ»ÑùµÄÌØµã¡£MomentiveÈ·ÈÏÁËÕâ´Î¹¥»÷£¬µ«HexionÉÐδÅû¶ÈκÎÓйØÏ¸½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/lockergoga-ransomware-hits-two-more-companies-in-the-manufacturing-sector-c8274160

3¡¢¹È¸è½¨¸´ChromeÖеÄа¶ñ¹â±ê·ì϶£¬Òѱ»¼¼ÊõÖ§³¶à¿Æ­ÀûÓÃ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¹È¸è½¨¸´ÁËChromeÖеÄа¶ñ¹â±ê·ì϶£¬¸Ã·ì϶ĿǰÒѱ»¼¼ÊõÖ§³¶à¿Æ­ÕßÔÚÒ°±í»ý¼«ÀûÓ㬾ßÌåÀ´Ëµ£¬¹¥»÷Õß½«³ß¶ÈµÄ32¡Á32ÏñËØÊó±ê¹â±êͼÐδúÌæ³É128»ò256ÏñËØ´óÓ×µÄͼÐΣ¬Í¨³£µÄ¹â±êÒÀÈ»»á³Ê´Ë¿ÌÆÁÄ»ÉÏ£¬µ«»á³Ê´Ë¿Ì½Ï´óͨÃ÷Ììǵ¿òµÄ½ÇÂ䣬ͨ¹ýÕâÖÖ·½Ê½£¬¹¥»÷ÕßÄܹ»×èÖ¹Óû§¹Ø¹Ø²¢ÍÑÀë¶ñÒâÒ³Ãæ¡£ÔÚ½¨¸´²¹¶¡ÖУ¬µ±Êó±êÐüÍ£ÔÚChromeµÄ±êÇ©À¸¡¢µØÖ·À¸¡¢²Ëµ¥µÈÇøÓòʱ£¬Chrome»á×Ô¶¯½«Êó±ê»¹Ô­Îª³ß¶ÈOSͼÐΡ£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-fixes-chrome-evil-cursor-bug-abused-by-tech-support-scam-sites/

4¡¢GrandstreamÉ豸¶à¸ö°²È«·ì϶£¬¿Éµ¼Ö¶ñÒâÈí¼þ±»×°Öü°ÇÔÌý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝTrustwave SpiderLabs°ä²¼µÄ»ã±¨£¬GrandstreamÃæÏòÖÐÓ×ÐÍÆóÒµµÄ¶à¸öÍøÂçÉ豸£¨IP PBX¡¢»áÒéÉ豸¡¢IPÊÓÆµµç»°ºÍ·ÓÉÆ÷£©´æÔÚ°²È«·ì϶£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶װÖöñÒâÈí¼þ¼°ÇÔÌýÉãÏñÍ·ºÍÂó¿Ë·ç¡£ÓÉÓÚËùÓÐÉ豸¶¼ÒÔrootȨÏÞÔËÐУ¬Òò¶ø¹¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¼°ËÁÒâ²Ù×÷¡£ÕâЩ·ì϶ÓÚ2018Äê12Ô»㱨¸øGrandstream£¬¸Ã¹«Ë¾ÒѾ­°ä²¼ÁËÓйؽ¨¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/grandstream-bugs-smbs-attacks/143141/


5¡¢×êÑÐÍŶӷ¢ÏÖ»ªÎªPCManager´æÔÚÌáȨ¼°´úÂëÖ´Ðзì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢Èí×êÑÐÈËÔ±ÔÚ»ªÎªµÄPCManager¹¤¾ßÖз¢ÏÖÁ½¸ö°²È«·ì϶¡£PCManagerÊÇԤװÔÚMateBook±Ê¼Ç±¾µçÄÔÉϵÄÖÎÀí¹¤¾ß£¬×êÑÐÈËÔ±·¢Ïָù¤¾ßµÄÉ豸ÖÎÀíÇý¶¯·¨Ê½´æÔÚ±¾µØÌáȨ·ì϶£¨CVE-2019-5241£©ºÍËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2019-5242£©¡£»ªÎªÒÑÔÚ1Ô·ݽ¨¸´ÁËÕâÁ½¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/82893/hacking/huawei-tool-flaws.html

6¡¢Æ»¹û°ä²¼iOS 12.2£¬¹²½¨¸´51¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

±¾ÖÜһƻ¹û°ä²¼iOS 12.2£¬½¨¸´ÁË51¸ö°²È«·ì϶£¬ÊÜÓ°ÏìµÄÉ豸Ô̺¬iPhone 5s¼°Ö®ºóµÄ°æ±¾¡¢iPad Air¼°Ö®ºóµÄ°æ±¾ºÍiPod touch 6¡£´óÎÞÊý·ì϶¶¼ÓëWebäÖȾÒýÇæWebKitÓйØ£¬·ì϶ÁìÓòÔ̺¬ËÁÒâ´úÂëÖ´ÐÓ×¢Ãô¸ÐÐÅϢй¶¡¢É³ÏäÈÆ¹ý¼°XSS¹¥»÷µÈ¡£´Ë±í£¬Æ»¹û»¹½¨¸´ÁËiOSÄÚºËÖеÄ6¸ö·ì϶£¬Ô̺¬DoS·ì϶£¨CVE-2019-8527£©ºÍÌáȨ·ì϶£¨CVE-2019-8514£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/ios-update-iphone-security.html

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù