¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181010

Ðû²¼Ê±¼ä 2018-10-10

1¡¢GoogleÐÂÕþ²ßÖ»ÔÊÐíAndroidĬÈÏÓ¦Óûá¼ûͨ»°¼Í¼ºÍ¶ÌÐÅ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ΪÁ˱ÜÃâµÚÈý·½Ó¦ÓÃÀÄÓÃÓû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬Google×ö³öÁ˼¸ÏîÖ÷ÒªµÄ¸ü¸Ä¡£ ¡£¡£GoogleÔÚGoogle PlayµÄ¿ª·¢ÕßÕþ²ßÖÐмÓÈëÁËÒ»Ìõ¹æÔò£¬£¬£¬£¬¸Ã¹æÔòÏÖÔÚ½öÔÊÐíAndroidµÄĬÈÏÓ¦Óûá¼ûÓû§µÄͨ»°¼Í¼ºÍ¶ÌÐÅ¡£ ¡£¡£Google»¹ÏÞÖÆÁ˶ÔGmail APIµÄ»á¼û£¬£¬£¬£¬ÏÖÔÚÖ»ÓÐÖ±½ÓÔöÇ¿µç×ÓÓʼþ¹¦Ð§µÄÓ¦Óã¨ÈçÓʼþ¿Í»§¶Ë¡¢Óʼþ±¸·ÝЧÀ͵ȣ©²Å¿ÉÒÔ»á¼û¸ÃAPI¡£ ¡£¡£Google»¹¸üÐÂÁËÆäÕË»§È¨ÏÞϵͳ£¬£¬£¬£¬ÏÖÔÚµÚÈý·½Ó¦ÓÃÔÚÉêÇë»á¼ûGoogleÕË»§Êý¾Ýʱ£¬£¬£¬£¬ÏµÍ³»áÕë¶Ôÿһ¸öȨÏÞµ¥¶À¾ÙÐÐÉêÇë¡£ ¡£¡£¿£¿£¿£¿£¿£¿ª·¢Õß½«ÓÐ90ÌìµÄʱ¼äÀ´¸üÐÂÆäÓ¦ÓúÍЧÀÍ¡£ ¡£¡£


   Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/android-app-privacy.html

2¡¢½ðÑÅÍØµÄ±¨¸æÅú×¢2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤½ðÑÅÍØµÄ×îÐÂÑо¿£¬£¬£¬£¬2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬¹²ÓÐ45ÒÚÌõÊý¾Ý¼Í¼Ô⵽й¶¡£ ¡£¡£Óë2017ÄêͬÆÚÏà±È£¬£¬£¬£¬É¥Ê§¡¢±»ÇÔÒÔ¼°Ð¹Â¶µÄÊý¾ÝÔöÌíÁË133%¡£ ¡£¡£Ö»¹ÜÊý¾Ýй¶ÊÂÎñµÄÊýÄ¿ÂÔÓÐϽµ£¬£¬£¬£¬µ«ÊÂÎñµÄÑÏÖØË®Æ½ÓÐËùÔöÌí¡£ ¡£¡£ÆäÖÐ6ÆðÉ罻ýÌåÊý¾Ýй¶ÊÂÎñµ¼ÖÂÁËÁè¼Ý56%µÄÊý¾Ýй¶¡£ ¡£¡£Êý¾Ýй¶µÄ×î³£¼ûÔµ¹ÊÔ­ÓÉÊÇÍⲿÒòËØ£¨Õ¼56%£©¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2018/10/09/data-breaches-2018/

3¡¢Î¢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬£¬¹²ÐÞ¸´49¸öÇå¾²Îó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


΢ÈíÐû²¼10ÔÂÇå¾²¸üУ¬£¬£¬£¬¹²ÐÞ¸´Windows¡¢Edge¡¢IEµÈ¶à¿î²úÆ·ÖеÄ49¸öÎó²î£¬£¬£¬£¬ÆäÖаüÀ¨12¸ö¸ßΣÎó²î¡£ ¡£¡£½ÏΪÑÏÖØµÄÎó²î°üÀ¨WindowsÖеÄÌáȨÎó²î£¨CVE-2018-8453£©¡¢MSXMLÆÊÎöÆ÷×é¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8494£©¡¢JetÊý¾Ý¿âÒýÇæÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8423£©¡¢WindowsÄÚºËÖеÄÌáȨÎó²î£¨CVE-2018-8497£©ÒÔ¼°Azure IoT Hub SDKÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8531£©¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/microsoft-windows-update.html

4¡¢AppleÐû²¼ÐÂÒ»ÂÖiOSºÍiCloudÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


AppleÐû²¼Õë¶ÔiOSºÍiCloudµÄÐÂÒ»ÂÖÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î¡£ ¡£¡£ÆäÖÐÔÚiOS 12.0.1ÖÐÐÞ¸´ÁËÁ½¸öÃÜÂëÈÆ¹ýÎó²î£¨CVE-2018-4380ºÍCVE-2018-4379£©¡£ ¡£¡£Çå¾²Ñо¿Ö°Ô±Jose Rodriguez·¢Ã÷ÁËÕâÁ½¸öÎó²î£¬£¬£¬£¬²¢Ðû²¼ÁËÏà¹ØÎó²îʹÓÃÊÓÆµ¡£ ¡£¡£Apple»¹ÔÚiCloud for Windows 7.7.12ÖÐÐÞ¸´ÁË19¸öÎó²î£¬£¬£¬£¬ÆäÖаüÀ¨13¸ö¸ßΣµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-releases-security-updates-for-ios-and-icloud-fixes-passcode-bypass/

5¡¢Annapolis LibraryÔâÒøÐÐľÂíEmotetѬȾ£¬£¬£¬£¬½ü5000Óû§ÊÜÓ°Ïì


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹úÂíÀïÀ¼Öݰ²Äɲ¨Àû˹ÊеÄÒ»¸ö¹«¹²Í¼Êé¹ÝÔâÒøÐÐľÂíEmotetѬȾ£¬£¬£¬£¬Ô¼5000ÃûÓû§¿ÉÄÜÊܵ½Ó°Ïì¡£ ¡£¡£Emotet»áÇÔÈ¡Óû§µÄµÇ¼ƾ֤¡¢Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©ÒÔ¼°ÐÅÓÿ¨ÐÅÏ¢µÈ£¬£¬£¬£¬ËäÈ»¸ÃͼÊé¹ÝÌåÏÖûÓпͻ§ÐÅϢй¶£¬£¬£¬£¬µ«ÔÚ9ÔÂ17ÈÕÖÁ10ÔÂ4ÈÕʱ´úʹÓÃÁ˸ÃͼÊé¹ÝµÄ¹«¹²ÅÌËã»úµÄ¿Í»§Ó¦¸ÃСÐÄÆäÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/annapolis-library-computers-infected-with-emotet-almost-5k-customers-affected-523119.shtml

6¡¢Ñо¿Ö°Ô±·¢Ã÷ÈëÇÖMikroTik·ÓÉÆ÷µÄй¥»÷ÊÖÒÕ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Tenable ResearchµÄÑо¿Ö°Ô±·¢Ã÷ÈëÇÖMikroTik·ÓÉÆ÷µÄй¥»÷ÊÖÒÕ£¬£¬£¬£¬Ê¹µÃÒ»¸öÒÑÖªµÄÎó²î±äµÃ±ÈÒÔǰÒÔΪµÄÔ½·¢Î£ÏÕ¡£ ¡£¡£¸ÃÎó²î£¨CVE-2018-14847£©Ó°ÏìWinbox×é¼þ£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔ¶³ÌÖ´ÐдúÂë²¢»ñµÃroot shell¡£ ¡£¡£»£»£»£»£»»¾ä»°Ëµ£¬£¬£¬£¬ÐµĹ¥»÷ÊÖÒÕʹµÃδ¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔÈëÇÖRouterOS£¬£¬£¬£¬°²ÅŶñÒâÈí¼þ»òÈÆ¹ý·ÓÉÆ÷µÄ·À»ðǽ¡£ ¡£¡£¸ÃÎó²îÒÑÓÚ2018Äê4Ô±»ÐÞ¸´¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/76940/hacking/mikrotik-routers-attack-poc.html

ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí