ÈüÁé˼SoC±£´æÎ´ÐÞ¸´µÄí§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÕ©Æ­Ëðʧ104ÍòÃÀÔª

Ðû²¼Ê±¼ä 2019-08-21
1¡¢¼ÓÄôóÈøË¹¿¨Í¨ÊÐÔâBECÕ©Æ­Ëðʧ104ÍòÃÀÔª

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

¾ÝÍâµØÐÂÎű¨µÀ£¬£¬¼ÓÄôóÈøË¹¿¨Í¨ÊгÉΪBECÕ©Æ­µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£·¸·¨·Ö×Óð³ä°¬Â×ÐÞ½¨¹«Ë¾£¨Allan Construction£©µÄÊ×ϯ²ÆÎñ¹Ù£¬£¬ÏòÊÐÕþ²ÆÎñ²¿·ÖµÄÔ±¹¤·¢Ë͵ç×ÓÓʼþÒªÇó¸ü¸ÄÒøÐÐÕË»§ºÅÂë²¢¸¶¿î¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ç©ÊðÁËÒ»×ùÇÅÁºµÄÐÞ¸´¹¤³ÌÌõÔ¼¡£¡£¡£¡£¡£²ÆÎñÖ°Ô±Òò´ËÔÚ8ÔÂ7ÈÕ»ò8ÈÕ×óÓÒÖ§¸¶ÁË104ÍòÃÀÔª¡£¡£¡£¡£¡£8ÔÂ12ÈÕÕâһȦÌ×±»·¢Ã÷£¬£¬Ö´·¨»ú¹¹ºÍ½ðÈÚÕþ¸®ÊÔͼ×÷·ÏÉúÒâ²¢ÊÕ»Ø×ʽ𣬣¬ÏÖÔÚÒÑÊÕ»ØÔ¼4ÍòÃÀÔª¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/scammer-tricks-city-into-1-million-wire-transfer/


2¡¢ºÚ¿ÍʹÓÃÐéαNordVPNÍøÕ¾·Ö·¢ÒøÐÐľÂíBolik


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÒøÐÐľÂíBolik±³ºóµÄ¹¥»÷ÕßÓÖ»ØÀ´ÁË£¬£¬ÕâÒ»´ÎËûÃÇͨ¹ýÐéαµÄNordVPNÍøÕ¾¼ÌÐø·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸ÃµÁ°æÍøÕ¾nord-vpn[.]clubÏÕЩÍêÉÆµØ¿Ë¡Á˹ٷ½ÍøÕ¾NordVPN.com£¬£¬²¢ÇÒ¾ßÓÐÕýµ±µÄSSLÖ¤Ê飬£¬¸ÃÖ¤ÊéÓÉ¿ª·Åʽ֤Êé½ÒÏþ»ú¹¹Let's EncryptÓÚ8ÔÂ3ÈÕ½ÒÏþ£¬£¬ÓÐÓÃÆÚµ½11ÔÂ1ÈÕ¡£¡£¡£¡£¡£win32.bolik.2ľÂíÊÇbolik.1µÄˢа汾£¬£¬¾ßÓжà×é¼þ¶à̬ÐÔÎļþ²¡¶¾µÄÌØÕ÷£¬£¬¹¥»÷Õß¿ÉʹÓøÃľÂíÖ´ÐÐWeb×¢Èë¡¢Á÷Á¿½Ø»ñ¡¢¼üÅ̼ͼÒÔ¼°´Ó²î±ðµÄÒøÐпͻ§¶ËÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-use-fake-nordvpn-website-to-deliver-banking-trojan/


3¡¢¹È¸èNestÖÇÄÜÉãÏñÍ·±»ÆØ±£´æ8¸öÇå¾²Îó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¹È¸èNest Cam IQÊÒÄÚÉãÏñÍ·±»ÆØ±£´æ8¸öÇå¾²Îó²î£¬£¬¿ÉÓÃÓÚÐ®ÖÆ»òÆÆËð×°±¸¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÓÉ˼¿ÆTalosÑо¿Ö°Ô±Lilith WyattºÍClaudio Bozzato·¢Ã÷µÄ¡£¡£¡£¡£¡£Îó²î¹æÄ£°üÀ¨DoS£¨CVE-2019-5043£©¡¢ÐÅϢй¶£¨CVE-2019-5034ºÍCVE-2019-5040£©¡¢í§Òâ´úÂëÖ´ÐУ¨CVE-2019-5038ºÍCVE-2019-5039£©¡¢¿Éµ¼Ö±©Á¦ÆÆ½â¹¥»÷µÄÎó²î£¨CVE-2019-5035£©ÒÔ¼°Ö¤Êé¼ÓÔØ¹ýʧ£¨CVE-2019-5036ºÍCVE-2019-5037£©¡£¡£¡£¡£¡£¹È¸èÌåÏÖÒѾ­ÐÞ¸´ÁËÕâЩÎó²î£¬£¬ÐÞ¸´²¹¶¡½«×Ô¶¯ÍÆË͵½×°±¸ÖС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/vulnerabilities-in-google-nest-cam-iq-can-be-used-to-hijack-your-camera/


4¡¢VideoLanÐû²¼VLC²¥·ÅÆ÷¸üУ¬£¬ÐÞ¸´13¸öÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


VideoLanÐû²¼VLCýÌå²¥·ÅÆ÷µÄа汾3.0.8£¬£¬ÐÞ¸´ÁË13¸öÇå¾²Îó²î¡£¡£¡£¡£¡£Îó²î¹æÄ£°üÀ¨»º³åÇøÒç³ö¡¢use-after-free¡¢¿ÕÖ¸Õë½âÒýÓÃÒÔ¼°³ýÊýΪ0¡£¡£¡£¡£¡£´ó²¿·ÖÎó²î¶¼ÊÇÓÉVLC¿ª·¢Ö°Ô±Ö±½Ó·¢Ã÷µÄ¡£¡£¡£¡£¡£Æ¾Ö¤VideoLanµÄÇ徲ͨ¸æ£¬£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§·­¿ª¶ñÒâÎļþÀ´´¥·¢±ÀÀ£»£»£»òÔÚµÇÈÎÃü»§µÄÇå¾²ÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¸Ãа汾¿ÉÓÃÓÚWindows¡¢MacºÍLinuxƽ̨£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vlc-media-player-308-released-with-13-security-fixes/

5¡¢ÈüÁé˼SoC±£´æÎ´ÐÞ¸´µÄí§Òâ´úÂëÖ´ÐÐÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


F-Secure·¢Ã÷Xilinx£¨ÈüÁé˼£©µÄZynq UltraScale+SOC±£´æÁ½¸öÎó²î¡£¡£¡£¡£¡£¸ÃϵÁеIJúÆ·°üÀ¨SOC¡¢MPSOCÒÔ¼°RFSOC£¬£¬Í¨³£ÓÃÓÚÆû³µ¡¢º½¿Õ¡¢ÏûºÄµç×Ó¡¢¹¤ÒµÒÔ¼°¾üʲ¿¼þÖС£¡£¡£¡£¡£F-SecureÌåÏÖ£¬£¬ÕâЩSOCµÄ¼ÓÃÜÇå¾²Ö¸µ¼Ä£Ê½°üÀ¨Á½¸öÎó²î£¬£¬ÆäÖÐÒ»¸öÎó²îÎÞ·¨Í¨¹ýÈí¼þ¸üÐÂÐÞ¸´£¬£¬ÐèÒª¹©Ó¦ÉÌÌṩ¡°ÐµÄSilicon°æ±¾¡±¡£¡£¡£¡£¡£Ê¹ÓÃÕâÁ½¸öÎó²îÐèÒªÎïÆÊÎö¼ûȨÏÞ¡£¡£¡£¡£¡£ÈüÁé˼ÌåÏÖËüÐÞ¸ÄÁËÊÖÒÕÊֲᣬ£¬½¨Òé¿Í»§Ê¹ÓøüÇå¾²µÄÓ²¼þ¸ùÐÅÈΣ¨Hwrot£©Çå¾²Ö¸µ¼Ä£Ê½£¬£¬¶ø²»ÊÇֻʹÓýÏÈõµÄ¼ÓÃÜģʽ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/unpatchable-security-flaw-found-in-popular-soc-boards/


6¡¢Ñо¿Ö°Ô±¹ûÕæÐû²¼iOS 12.4µÄÃâ·ÑÔ½Óü¹¤¾ß

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


һλÄäÃûµÄÑо¿Ö°Ô±ÒÔpwn20wndµÄÓÖÃûÔÚGithubÉÏÃâ·ÑÐû²¼ÁËiOS 12.4µÄÔ½Óü¹¤¾ß¡£¡£¡£¡£¡£¸Ã¹¤¾ßʹÓÃÁËiOSÄÚºËÖеÄÒ»¸öUAFÎó²î£¨CVE-2019-8605£©£¬£¬´ËÎó²îÔøÔÚiOS 12.3Öб»ÐÞ¸´£¬£¬µ«Æ»¹ûÔÚiOS 12.4ÖÐÖØÐÂÒýÈëÁ˸ÃÎó²î¡£¡£¡£¡£¡£ÐµÄÔ½Óü¹¤¾ß¿ÉÔÚ¸üеÄiOS×°±¸ÉÏÊÂÇ飬£¬°üÀ¨iphone xs¡¢xs maxºÍxr»ò2019 iPad miniºÍipad air£¬£¬ÆñÂÛ¸Ã×°±¸ÊÇÔËÐÐiOS 12.4ÕÕ¾ÉiOS 12.2»ò¸üÔç°æ±¾£¬£¬µ«ÔÚiOS 12.3ÉÏÎÞ·¨ÊÂÇé¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/ios-iphone-jailbreak.html