ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ6ÖÜ
Ðû²¼Ê±¼ä 2019-03-04±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇGoogle PlayÖдæÔÚ29¿î¶ñÒâÏà»úÓ¦Óã¬×ÜÏÂÔØÁ¿Áè¼Ý400Íò´Î£»ÃÀ¹úÄÜÔ´¹«Ë¾Duke EnergyÒòÎ¥·´CIP³ß¶È±»·£¿î1000ÍòÃÀÔª£»MacOS KeychainÐÂ0day£¬¿Éµ¼ÖÂÓû§ÃÜÂëй¶£»°Ä´óÀûÑÇÁª°îÒé»áµÄ¼ÆËã»úÍøÂçÔâºÚ¿Í¹¥»÷£»Android¼äµýÈí¼þ¿ò¼ÜTriout¾íÍÁÖØÀ´£¬ÏÂÔØÁ¿Áè¼Ý5000Íò´Î¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
ÖØÒªÄþ¾²Â©¶´Áбí
WIBU-SYSTEMS WibuKey.sys 0x8200E804 IOCTL´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬻ñÈ¡ÄÚºËÄÚ´æÐÅϢй¶¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0657
2. NGINX Unit¶ÑÒç³ö¾Ü¾ø·þÎñ©¶´
Nginx Unit´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬽øÐоܾø·þÎñ¹¥»÷¡£
http://mailman.nginx.org/pipermail/unit/2019-February/000113.html
3. WibuKey Network server management WkbProgramLow¶ÑÒç³ö©¶´
WibuKey Network server management WkbProgramLowº¯Êý´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄTCP±¨ÎÄ£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0659
4. Cisco Aironet Active SensorĬÈÏÕË»§¾²Ì¬ÃÜÂ멶´
Cisco Aironet Active SensorĬÈÏÅäÖôæÔÚĬÈÏÃÜÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨ·ÃÎÊ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190206-aas-creds
5. Forcepoint User ID (FUID) serverÈÎÒâÎļþÉÏ´«Â©¶´
Forcepoint User ID (FUID) server TCP 5001¶Ë¿Ú´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÉÏ´«ÇëÇó£¬Ö´ÐÐÈÎÒâ´úÂë¡£
https://support.forcepoint.com/KBArticle?id=000016550
ÖØÒªÄþ¾²Ê¼þ×ÛÊö

Google PlayÉ̵êÖÐÌṩµÄÓ¦Óò¢²»Òâζ×ÅËüÊǺϷ¨Ó¦Ó᣾¡¹Ü¹È¸è×ö³öÁËÈç´Ë¶àµÄŬÁ¦£¬µ«Ò»Ð©Ðé¼ÙºÍ¶ñÒâµÄÓ¦Ó÷¨Ê½È·ÊµÇ±ÈëÁËÊý°ÙÍò²»ÖªÇéµÄÓû§¡£ÍøÂçÄþ¾²¹«Ë¾Ç÷ÊƿƼ¼·¢ÏÖÖÁÉÙ29¸öÕÕƬӦÓ÷¨Ê½ÒÑÀֳɽøÈë¹È¸èPlayÉ̵꣬¶øÇÒÔڹȸè´ÓÆäÓ¦Ó÷¨Ê½É̵êÖÐɾ³ý֮ǰÒѾÏÂÔØÁËÁè¼Ý400Íò´Î¡£ÓÐÎÊÌâµÄÒƶ¯Ó¦Ó÷¨Ê½Î±×°³ÉÕÕƬ±à¼ºÍÃÀÈÝÓ¦Ó÷¨Ê½£¬Éù³ÆʹÓÃÄúµÄÊÖ»úÏà»úÅÄÉã¸üºÃµÄÕÕƬ»òÃÀ»¯ÄúÅÄÉãµÄÕÕƬ£¬µ«·¢ÏÖÆäÖдæÔÚ¶ñÒâ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/beauty-camera-android-apps.html
2¡¢ÃÀ¹úÄÜÔ´¹«Ë¾Duke EnergyÒòÎ¥·´CIP³ß¶È±»·£¿î1000ÍòÃÀÔª
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/us-energy-firm-fined-10-million-security-failures
3¡¢MacOS KeychainÐÂ0day£¬¿Éµ¼ÖÂÓû§ÃÜÂëй¶
ÔÎÄÁ´½Ó£º
https://cyware.com/news/a-new-macos-zero-day-vulnerability-found-in-keychain-password-management-system-3565521d
4¡¢°Ä´óÀûÑÇÁª°îÒé»áµÄ¼ÆËã»úÍøÂçÔâºÚ¿Í¹¥»÷
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/australian-parliament-computer-network-breached
5¡¢Android¼äµýÈí¼þ¿ò¼ÜTriout¾íÍÁÖØÀ´£¬ÏÂÔØÁ¿Áè¼Ý5000Íò´Î
ÔÎÄÁ´½Ó£º
https://labs.bitdefender.com/2019/02/triout-android-spyware-framework-makes-a-comeback-abusing-app-with-50-million-downloads/
ÉùÃ÷£º±¾×ÊѶÓɶ«Éƽ̨άËûÃüÄþ¾²Ð¡×é·ÒëºÍÕûÀí