ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ6ÖÜ
°ä²¼¹¦·ò 2019-03-04±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇGoogle PlayÖдæÔÚ29¿î¶ñÒâÏà»úÀûÓã¬×ÜÏÂÔØÁ¿³¬¹ý400Íò´Î£»ÃÀ¹úÄÜÔ´¹«Ë¾Duke EnergyÒòÎ¥·´CIP³ß¶È±»·£¿î1000ÍòÃÀÔª£»MacOS KeychainÐÂ0day£¬¿Éµ¼ÖÂÓû§ÃÜÂëй¶£»°Ä´óÀûÑÇÁª¹úÒé»áµÄÍÆËã»úÍøÂçÔâºÚ¿Í¹¥»÷£»Android¼äµýÈí¼þ¿ò¼ÜTriout¾íÍÁ³ÁÀ´£¬ÏÂÔØÁ¿³¬¹ý5000Íò´Î¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
³ÁÒª°²È«·ì϶Áбí
WIBU-SYSTEMS WibuKey.sys 0x8200E804 IOCTL´¦ÖôæÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬻ñÈ¡ÄÚºËÄÚ´æÐÅϢй¶¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0657
2. NGINX Unit¶ÑÒç³ö»Ø¾ø·þÎñ·ì϶
Nginx Unit´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬽øÐлؾø·þÎñ¹¥»÷¡£
http://mailman.nginx.org/pipermail/unit/2019-February/000113.html
3. WibuKey Network server management WkbProgramLow¶ÑÒç¶Âí½Å
WibuKey Network server management WkbProgramLowº¯Êý´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄTCP±¨ÎÄ£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0659
4. Cisco Aironet Active SensorĬÈÏÕË»§¾²Ì¬ÃÜÂë·ì϶
Cisco Aironet Active SensorĬÈÏÅäÖôæÔÚĬÈÏÃÜÂë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½Ó¼û¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190206-aas-creds
5. Forcepoint User ID (FUID) serverËÁÒâÎļþÉÏ´«·ì϶
Forcepoint User ID (FUID) server TCP 5001¶Ë¿Ú´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÉÏ´«ÒªÇó£¬Ö´ÐÐËÁÒâ´úÂë¡£
https://support.forcepoint.com/KBArticle?id=000016550
³ÁÒª°²È«ÊÂÎñ×ÛÊö
Google PlayÉ̵êÖÐÌṩµÄÀûÓò¢²»ÁÏζ×ÅËüÊǺϷ¨ÀûÓá£Ö»¹Ü¹È¸è×ö³öÁËÈç´Ë¶àµÄÖÂÁ¦£¬µ«Ò»Ð©ÐéαºÍ¶ñÒâµÄÀûÓ÷¨Ê½µÄȷDZÈëÁËÊý°ÙÍò²»ÖªÇéµÄÓû§¡£ÍøÂ簲ȫ¹«Ë¾Ç÷Ïò¿Æ¼¼·¢ÏÖÖÁÉÙ29¸öÕÕÆ¬ÀûÓ÷¨Ê½Òѳɹ¦½øÈë¹È¸èPlayÉ̵꣬²¢ÇÒÔڹȸè´ÓÆäÀûÓ÷¨Ê½É̵êÖÐɾ³ý֮ǰÒѾÏÂÔØÁ˳¬¹ý400Íò´Î¡£ÓÐÎÊÌâµÄÒÆ¶¯ÀûÓ÷¨Ê½¼Ù×°³ÉÕÕÆ¬±à×ëºÍÃÀÈÝÀûÓ÷¨Ê½£¬Ðû³ÆÊ¹ÓÃÄúµÄÊÖ»úÏà»úÅÄÉã¸üºÃµÄÕÕÆ¬»òÃÀ»¯ÄúÅÄÉãµÄÕÕÆ¬£¬µ«·¢ÏÔìäÖдæÔÚ¶ñÒâ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/beauty-camera-android-apps.html
2¡¢ÃÀ¹úÄÜÔ´¹«Ë¾Duke EnergyÒòÎ¥·´CIP³ß¶È±»·£¿î1000ÍòÃÀÔª
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/us-energy-firm-fined-10-million-security-failures
3¡¢MacOS KeychainÐÂ0day£¬¿Éµ¼ÖÂÓû§ÃÜÂëй¶
ÔÎÄÁ´½Ó£º
https://cyware.com/news/a-new-macos-zero-day-vulnerability-found-in-keychain-password-management-system-3565521d
4¡¢°Ä´óÀûÑÇÁª¹úÒé»áµÄÍÆËã»úÍøÂçÔâºÚ¿Í¹¥»÷
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/australian-parliament-computer-network-breached
5¡¢Android¼äµýÈí¼þ¿ò¼ÜTriout¾íÍÁ³ÁÀ´£¬ÏÂÔØÁ¿³¬¹ý5000Íò´Î
ÔÎÄÁ´½Ó£º
https://labs.bitdefender.com/2019/02/triout-android-spyware-framework-makes-a-comeback-abusing-app-with-50-million-downloads/
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ