ÈüÁé˼SoC±£´æÎ´ÐÞ¸´µÄí§Òâ´úÂëÖ´ÐÐÎó²î£» £»£»£»£»£»¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÕ©Æ­Ëðʧ104ÍòÃÀÔª

Ðû²¼Ê±¼ä 2019-08-21
1¡¢¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÕ©Æ­Ëðʧ104ÍòÃÀÔª

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

¾ÝÍâµØÐÂÎű¨µÀ£¬£¬£¬£¬¼ÓÄôóÈøË¹¿¨Í¨ÊгÉΪBECÕ©Æ­µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£·¸·¨·Ö×Óð³ä°¬Â×ÐÞ½¨¹«Ë¾£¨Allan Construction£©µÄÊ×ϯ²ÆÎñ¹Ù£¬£¬£¬£¬ÏòÊÐÕþ²ÆÎñ²¿·ÖµÄÔ±¹¤·¢Ë͵ç×ÓÓʼþÒªÇó¸ü¸ÄÒøÐÐÕË»§ºÅÂë²¢¸¶¿î¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ç©ÊðÁËÒ»×ùÇÅÁºµÄÐÞ¸´¹¤³ÌÌõÔ¼¡£¡£¡£¡£¡£¡£¡£¡£²ÆÎñÖ°Ô±Òò´ËÔÚ8ÔÂ7ÈÕ»ò8ÈÕ×óÓÒÖ§¸¶ÁË104ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£8ÔÂ12ÈÕÕâһȦÌ×±»·¢Ã÷£¬£¬£¬£¬Ö´·¨»ú¹¹ºÍ½ðÈÚÕþ¸®ÊÔͼ×÷·ÏÉúÒâ²¢ÊÕ»Ø×ʽ𣬣¬£¬£¬ÏÖÔÚÒÑÊÕ»ØÔ¼4ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/scammer-tricks-city-into-1-million-wire-transfer/


2¡¢ºÚ¿ÍʹÓÃÐéαNordVPNÍøÕ¾·Ö·¢ÒøÐÐľÂíBolik


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÒøÐÐľÂíBolik±³ºóµÄ¹¥»÷ÕßÓÖ»ØÀ´ÁË£¬£¬£¬£¬ÕâÒ»´ÎËûÃÇͨ¹ýÐéαµÄNordVPNÍøÕ¾¼ÌÐø·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃµÁ°æÍøÕ¾nord-vpn[.]clubÏÕЩÍêÉÆµØ¿Ë¡Á˹ٷ½ÍøÕ¾NordVPN.com£¬£¬£¬£¬²¢ÇÒ¾ßÓÐÕýµ±µÄSSLÖ¤Ê飬£¬£¬£¬¸ÃÖ¤ÊéÓÉ¿ª·Åʽ֤Êé½ÒÏþ»ú¹¹Let's EncryptÓÚ8ÔÂ3ÈÕ½ÒÏþ£¬£¬£¬£¬ÓÐÓÃÆÚµ½11ÔÂ1ÈÕ¡£¡£¡£¡£¡£¡£¡£¡£win32.bolik.2ľÂíÊÇbolik.1µÄˢа汾£¬£¬£¬£¬¾ßÓжà×é¼þ¶à̬ÐÔÎļþ²¡¶¾µÄÌØÕ÷£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃľÂíÖ´ÐÐWeb×¢Èë¡¢Á÷Á¿½Ø»ñ¡¢¼üÅ̼ͼÒÔ¼°´Ó²î±ðµÄÒøÐпͻ§¶ËÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-use-fake-nordvpn-website-to-deliver-banking-trojan/


3¡¢¹È¸èNestÖÇÄÜÉãÏñÍ·±»ÆØ±£´æ8¸öÇå¾²Îó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¹È¸èNest Cam IQÊÒÄÚÉãÏñÍ·±»ÆØ±£´æ8¸öÇå¾²Îó²î£¬£¬£¬£¬¿ÉÓÃÓÚÐ®ÖÆ»òÆÆËð×°±¸¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÓÉ˼¿ÆTalosÑо¿Ö°Ô±Lilith WyattºÍClaudio Bozzato·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£¡£Îó²î¹æÄ£°üÀ¨DoS£¨CVE-2019-5043£©¡¢ÐÅϢй¶£¨CVE-2019-5034ºÍCVE-2019-5040£©¡¢í§Òâ´úÂëÖ´ÐУ¨CVE-2019-5038ºÍCVE-2019-5039£©¡¢¿Éµ¼Ö±©Á¦ÆÆ½â¹¥»÷µÄÎó²î£¨CVE-2019-5035£©ÒÔ¼°Ö¤Êé¼ÓÔØ¹ýʧ£¨CVE-2019-5036ºÍCVE-2019-5037£©¡£¡£¡£¡£¡£¡£¡£¡£¹È¸èÌåÏÖÒѾ­ÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬ÐÞ¸´²¹¶¡½«×Ô¶¯ÍÆË͵½×°±¸ÖС£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/vulnerabilities-in-google-nest-cam-iq-can-be-used-to-hijack-your-camera/


4¡¢VideoLanÐû²¼VLC²¥·ÅÆ÷¸üУ¬£¬£¬£¬ÐÞ¸´13¸öÎó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


VideoLanÐû²¼VLCýÌå²¥·ÅÆ÷µÄа汾3.0.8£¬£¬£¬£¬ÐÞ¸´ÁË13¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£Îó²î¹æÄ£°üÀ¨»º³åÇøÒç³ö¡¢use-after-free¡¢¿ÕÖ¸Õë½âÒýÓÃÒÔ¼°³ýÊýΪ0¡£¡£¡£¡£¡£¡£¡£¡£´ó²¿·ÖÎó²î¶¼ÊÇÓÉVLC¿ª·¢Ö°Ô±Ö±½Ó·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤VideoLanµÄÇ徲ͨ¸æ£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§·­¿ª¶ñÒâÎļþÀ´´¥·¢Í߽⻠£»£»£»£»£»òÔÚµÇÈÎÃü»§µÄÇå¾²ÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£¸Ãа汾¿ÉÓÃÓÚWindows¡¢MacºÍLinuxƽ̨£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vlc-media-player-308-released-with-13-security-fixes/

5¡¢ÈüÁé˼SoC±£´æÎ´ÐÞ¸´µÄí§Òâ´úÂëÖ´ÐÐÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


F-Secure·¢Ã÷Xilinx£¨ÈüÁé˼£©µÄZynq UltraScale+SOC±£´æÁ½¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃϵÁеIJúÆ·°üÀ¨SOC¡¢MPSOCÒÔ¼°RFSOC£¬£¬£¬£¬Í¨³£ÓÃÓÚÆû³µ¡¢º½¿Õ¡¢ÏûºÄµç×Ó¡¢¹¤ÒµÒÔ¼°¾üʲ¿¼þÖС£¡£¡£¡£¡£¡£¡£¡£F-SecureÌåÏÖ£¬£¬£¬£¬ÕâЩSOCµÄ¼ÓÃÜÇå¾²Ö¸µ¼Ä£Ê½°üÀ¨Á½¸öÎó²î£¬£¬£¬£¬ÆäÖÐÒ»¸öÎó²îÎÞ·¨Í¨¹ýÈí¼þ¸üÐÂÐÞ¸´£¬£¬£¬£¬ÐèÒª¹©Ó¦ÉÌÌṩ¡°ÐµÄSilicon°æ±¾¡±¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÕâÁ½¸öÎó²îÐèÒªÎïÆÊÎö¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£ÈüÁé˼ÌåÏÖËüÐÞ¸ÄÁËÊÖÒÕÊֲᣬ£¬£¬£¬½¨Òé¿Í»§Ê¹ÓøüÇå¾²µÄÓ²¼þ¸ùÐÅÈΣ¨Hwrot£©Çå¾²Ö¸µ¼Ä£Ê½£¬£¬£¬£¬¶ø²»ÊÇֻʹÓýÏÈõµÄ¼ÓÃÜģʽ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/unpatchable-security-flaw-found-in-popular-soc-boards/


6¡¢Ñо¿Ö°Ô±¹ûÕæÐû²¼iOS 12.4µÄÃâ·ÑÔ½Óü¹¤¾ß

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


һλÄäÃûµÄÑо¿Ö°Ô±ÒÔpwn20wndµÄÓÖÃûÔÚGithubÉÏÃâ·ÑÐû²¼ÁËiOS 12.4µÄÔ½Óü¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßʹÓÃÁËiOSÄÚºËÖеÄÒ»¸öUAFÎó²î£¨CVE-2019-8605£©£¬£¬£¬£¬´ËÎó²îÔøÔÚiOS 12.3Öб»ÐÞ¸´£¬£¬£¬£¬µ«Æ»¹ûÔÚiOS 12.4ÖÐÖØÐÂÒýÈëÁ˸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÐµÄÔ½Óü¹¤¾ß¿ÉÔÚ¸üеÄiOS×°±¸ÉÏÊÂÇ飬£¬£¬£¬°üÀ¨iphone xs¡¢xs maxºÍxr»ò2019 iPad miniºÍipad air£¬£¬£¬£¬ÆñÂÛ¸Ã×°±¸ÊÇÔËÐÐiOS 12.4ÕÕ¾ÉiOS 12.2»ò¸üÔç°æ±¾£¬£¬£¬£¬µ«ÔÚiOS 12.3ÉÏÎÞ·¨ÊÂÇé¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/ios-iphone-jailbreak.html