ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ6ÖÜ
Ðû²¼Ê±¼ä 2019-03-04±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇGoogle PlayÖб£´æ29¿î¶ñÒâÏà»úÓ¦Ó㬣¬£¬£¬×ÜÏÂÔØÁ¿Áè¼Ý400Íò´Î£»£»£»£»ÃÀ¹úÄÜÔ´¹«Ë¾Duke EnergyÒòÎ¥·´CIP±ê×¼±»·£¿£¿£¿£¿î1000ÍòÃÀÔª£»£»£»£»MacOS KeychainÐÂ0day£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÃÜÂëй¶£»£»£»£»°Ä´óÀûÑÇÁª°îÒé»áµÄÅÌËã»úÍøÂçÔâºÚ¿Í¹¥»÷£»£»£»£»AndroidÌØ¹¤Èí¼þ¿ò¼ÜTriout¾íÍÁÖØÀ´£¬£¬£¬£¬ÏÂÔØÁ¿Áè¼Ý5000Íò´Î¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
WIBU-SYSTEMS WibuKey.sys 0x8200E804 IOCTL´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬»ñÈ¡ÄÚºËÄÚ´æÐÅϢй¶¡£¡£¡£¡£¡£¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0657
2. NGINX Unit¶ÑÒç³ö¾Ü¾øÐ§ÀÍÎó²î
Nginx Unit±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£
http://mailman.nginx.org/pipermail/unit/2019-February/000113.html
3. WibuKey Network server management WkbProgramLow¶ÑÒç³öÎó²î
WibuKey Network server management WkbProgramLowº¯Êý±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄTCP±¨ÎÄ£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0659
4. Cisco Aironet Active SensorĬÈÏÕË»§¾²Ì¬ÃÜÂëÎó²î
Cisco Aironet Active SensorĬÈÏÉèÖñ£´æÄ¬ÈÏÃÜÂëÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬Î´ÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190206-aas-creds
5. Forcepoint User ID (FUID) serverí§ÒâÎļþÉÏ´«Îó²î
Forcepoint User ID (FUID) server TCP 5001¶Ë¿Ú±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÉÏ´«ÇëÇ󣬣¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://support.forcepoint.com/KBArticle?id=000016550
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

Google PlayÊÐËÁÖÐÌṩµÄÓ¦Óò¢²»ÁÏζ×ÅËüÊÇÕýµ±Ó¦Óᣡ£¡£¡£¡£¡£Ö»¹Ü¹È¸è×ö³öÁËÔÆÔÆ¶àµÄÆð¾¢£¬£¬£¬£¬µ«Ò»Ð©ÐéαºÍ¶ñÒâµÄÓ¦ÓóÌÐòȷʵDZÈëÁËÊý°ÙÍò²»ÖªÇéµÄÓû§¡£¡£¡£¡£¡£¡£ÍøÂçÇå¾²¹«Ë¾Ç÷ÊÆ¿Æ¼¼·¢Ã÷ÖÁÉÙ29¸öÕÕÆ¬Ó¦ÓóÌÐòÒÑÀֳɽøÈë¹È¸èPlayÊÐËÁ£¬£¬£¬£¬²¢ÇÒÔڹȸè´ÓÆäÓ¦ÓóÌÐòÊÐËÁÖÐɾ³ý֮ǰÒѾÏÂÔØÁËÁè¼Ý400Íò´Î¡£¡£¡£¡£¡£¡£ÓÐÎÊÌâµÄÒÆ¶¯Ó¦ÓóÌÐòαװ³ÉÕÕÆ¬±à¼ºÍÃÀÈÝÓ¦ÓóÌÐò£¬£¬£¬£¬Éù³ÆÊ¹ÓÃÄúµÄÊÖ»úÏà»úÅÄÉã¸üºÃµÄÕÕÆ¬»òÃÀ»¯ÄúÅÄÉãµÄÕÕÆ¬£¬£¬£¬£¬µ«·¢Ã÷ÆäÖб£´æ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/beauty-camera-android-apps.html
2¡¢ÃÀ¹úÄÜÔ´¹«Ë¾Duke EnergyÒòÎ¥·´CIP±ê×¼±»·£¿£¿£¿£¿î1000ÍòÃÀÔª
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/us-energy-firm-fined-10-million-security-failures
3¡¢MacOS KeychainÐÂ0day£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÃÜÂëй¶
ÔÎÄÁ´½Ó£º
https://cyware.com/news/a-new-macos-zero-day-vulnerability-found-in-keychain-password-management-system-3565521d
4¡¢°Ä´óÀûÑÇÁª°îÒé»áµÄÅÌËã»úÍøÂçÔâºÚ¿Í¹¥»÷
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/australian-parliament-computer-network-breached
5¡¢AndroidÌØ¹¤Èí¼þ¿ò¼ÜTriout¾íÍÁÖØÀ´£¬£¬£¬£¬ÏÂÔØÁ¿Áè¼Ý5000Íò´Î
ÔÎÄÁ´½Ó£º
https://labs.bitdefender.com/2019/02/triout-android-spyware-framework-makes-a-comeback-abusing-app-with-50-million-downloads/
ÉùÃ÷£º±¾×ÊѶÓÉ¿Ðý¹ú¼ÊÓÎϷάËûÃüÇ徲С×é·ÒëºÍÕûÀí