¹È¸è³Æ³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±£»ProtonVPNÓëɱ¶¾Èí¼þ³åÍ»£¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ

Ðû²¼Ê±¼ä 2021-01-27

1.AppleÇå¾²¸üУ¬ÐÞ¸´iOSÖÐ3¸öÒѱ»ÔÚҰʹÓõÄ0day


1.jpg


AppleÐû²¼ÁËÕë¶ÔiOSµÄÇå¾²¸üУ¬ÐÞ¸´ÁË3¸öÒѱ»ÔÚҰʹÓõÄ0day¡£µÚÒ»¸öΪӰÏìiOS²Ù×÷ϵͳÄں˵ľºÕùÌõ¼þÎó²î£¨CVE-2021-1782£©£¬Ëü¿ÉÒÔʹ¹¥»÷ÕßÌáÉýÆä¹¥»÷´úÂëµÄȨÏÞ¡£ÁíÍâÁ½¸öΪӰÏìWebKitä¯ÀÀÆ÷ÒýÇæµÄÂß¼­Îó²î£¨CVE-2021-1870ºÍCVE-2021-1871£©£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄSafariä¯ÀÀÆ÷ÖÐÖ´ÐжñÒâ´úÂë¡£ÔÚÎó²îʹÓÃÁ´ÖУ¬Óû§±»ÒýÓÕµ½Ò»¸ö¶ñÒâÍøÕ¾£¬¸ÃÍøÕ¾Ê¹ÓÃWebKitÎó²îÔËÐдúÂë£¬ËæºóÉý¼¶ÆäÔËÐÐϵͳ¼¶´úÂëµÄȨÏÞ£¬Î£¼°²Ù×÷ϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/apple-fixes-another-three-ios-zero-days-exploited-in-the-wild/


2.¹È¸è³Æ³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±


2.png


GoogleÍþвÆÊÎöС×é·¢Ã÷³¯ÏʺڿÍÒÑʹÓÃÉç½»ÍøÂçÃé×¼Çå¾²Ñо¿Ö°Ô±¡£ºÚ¿ÍÊ×ÏÈÔÚTwitter¡¢LinkedIn¡¢Telegram¡¢DiscordºÍKeybaseµÈÉç½»ÍøÂçÉÏʹÓöàÈ˵ÄСÎÒ˽¼Ò×ÊÁÏ£¬ÒÔαÔìµÄÉí·Ý½Ó´¥Çå¾²Ñо¿Ö°Ô±¡£ÔÚ½¨ÉèÁËÆðÔ´µÄ½»Á÷Ö®ºó£¬ºÚ¿Í»áѯÎÊÄ¿µÄÑо¿Ö°Ô±ÊÇ·ñÔ¸ÒâÔÚÎó²îÑо¿ÉϾÙÐкÏ×÷£¬È»ºó¸øÑо¿Ö°Ô±Ò»¸öVisual StudioÏîÄ¿¡£¸ÃÏîÄ¿°üÀ¨ÁË×°ÖöñÒâÈí¼þµÄ´úÂ룬ÀÖ³É×°Öúó¿É³äµ±ºóÃŲ¢ÓëÔ¶³ÌÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷ÁªÏµ£¬ÆÚ´ýÏÂÁî¡£±ðµÄ£¬¸Ã¶ñÒâÈí¼þÓ볯ÏÊÖøÃûºÚ¿Í×éÖ¯LazarusÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-north-korean-hackers-have-targeted-security-researchers-via-social-media/


3.°Ä´óÀûÑÇ֤ȯî¿Ïµ»ú¹¹·þÎñÆ÷ÖÐÎó²î»òÒѵ¼ÖÂÊý¾Ýй¶


3.png


°Ä´óÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©Í¸Â¶·þÎñÆ÷ÖÐÎó²î»òÒѵ¼ÖÂÊý¾Ýй¶¡£ASICÊǰĴóÀûÑÇÕþ¸®µÄ×ÔÁ¦Î¯Ô±»á£¬ÈÏÕæ°ü¹Ü¡¢Ö¤È¯ºÍ½ðÈÚ·þÎñµÄî¿Ïµ£¬ÊǰĴóÀûÑǹú¼Ò¹«Ë¾î¿Ïµ»ú¹¹µÄÏûºÄÕß±£»¤×éÖ¯¡£¸ÃÊÂÎñ±¬·¢ÓÚ2021Äê1ÔÂ15ÈÕ£¬ÓëÓÃÓÚ´«ÊäÐÅÏ¢µÄAccellionÈí¼þÓйØ£¬Îó²îÓ°ÏìÁËһ̨°üÀ¨Á˰ĴóÀûÑÇÐÅ´ûÔÊÐíÖ¤ÉêÇëÏà¹ØÎĵµµÄ·þÎñÆ÷¡£ASIC³ÆÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬µ«ºÚ¿Í¿ÉÄÜÒѾ­Éó²é²¿·ÖÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/australian-securities-regulator-discloses-security-breach/


4.WestRockѬȾÀÕË÷Èí¼þ£¬ITºÍOTϵͳ¾ù±»ÆÆËð


4.png


ÃÀ¹ú°ü×°¹«Ë¾WestRockѬȾÀÕË÷Èí¼þ£¬ITºÍOTϵͳ¾ù±»ÆÆËð¡£¹¥»÷ÓÚ1ÔÂ23ÈÕ±»·¢Ã÷£¬²¢ÊµÊ±½ÓÄÉÁËÓ¦¼±ÏìÓ¦²½·¥¡£WestRockÌåÏÖϵͳÕýÔÚ»Ö¸´ÖУ¬µ«¹¥»÷ÒѾ­µ¼Ö¹«Ë¾²¿·ÖÓªÒµµÄÑÓÎó¡£WestRockûÓÐ͸¶Óйش˴ÎÊÂÎñµÄ¸ü¶àÏêϸÐÅÏ¢£¬Éв»ÇåÎú¹¥»÷µÄˮƽÒÔ¼°Ê¹ÊÖÐÊܵ½Ó°ÏìµÄOTϵͳÀàÐÍ¡£¸ÃÊÂÎñ±»Åû¶ºó£¬±¾ÖÜÒ»ÉÏÎçWestRock¹ÉƱµÄ¼ÛֵϵøÁË4£¥ÒÔÉÏ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/packaging-giant-westrock-says-ransomware-attack-impacted-ot-systems


5.ProtonVPNÓëɱ¶¾Èí¼þ³åÍ»£¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ


5.png


ProtonVPNÓëδÃüÃûµÄɱ¶¾Èí¼þ½â¾ö¼Æ»®³åÍ»£¬¿Éµ¼ÖÂϵͳÀ¶ÆÁ¡£ËäÈ»ProtonVPNûÓÐ͸¶ÓйØÀ¶ÆÁÔµ¹ÊÔ­Óɵĸü¶àϸ½Ú£¬µ«Ô¼ÄªÁ½ÖÜǰ£¬Ê¹ÓÃÁË×îа汾ProtonVPNµÄÒ»¸öÊÜÓ°ÏìµÄÓû§ËùÌåÏÖ£¬ÔÚÆô¶¯VPNµÄ¿Í»§¶Ëºó»áÁ¬Ã¦´¥·¢À¶ÆÁ¡£ÕâÒѲ»ÊǵÚÒ»´ÎÓÐÓû§·´Ó¦ÔÚWindowsϵͳÖÐÔÚʹÓÃProtonVPNʱ»áµ¼ÖÂÀ¶ÆÁ£¬²¢ÇÒÖØÐÂ×°Öÿͻ§¶ËºÍÇý¶¯³ÌÐòÒ²ÎÞ¼ÃÓÚÊ¡£ProtonVPN½¨ÒéÓû§ÏÈÔÝʱ½ûÓøÃɱ¶¾Èí¼þ£¬»ò½«ProtonVPN½µ¼¶µ½Îȹ̰汾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/protonvpn-causes-windows-bsod-crashes-due-to-antivirus-conflicts/


6.kasperskyÐû²¼2021ÄêÍøÂçÇå¾²µÄÕ¹Íû±¨¸æ


6.png


kasperskyÐû²¼ÁË2021ÄêÍøÂçÇå¾²µÄÕ¹Íû±¨¸æ¡£¸Ã±¨¸æÊÓ²ìÁË31¸ö¹ú¼ÒºÍµØÇøµÄ5266ÃûIT¾öÒéÕߣ¬²¢ÌÖÂÛÁËËûÃÇÓöµ½µÄÍþв¡¢ÍøÂçÊÂÎñ»Ö¸´µÄ±¾Ç®ÒÔ¼°×éÖ¯ÄÚ²¿µÄÄ¿½ñÇ徲״̬¡£Ñо¿·¢Ã÷Ö»¹ÜÍøÂç¹¥»÷µÄÊýÄ¿¼ÌÐøÔöÌí£¬µ«IT²¿·ÖµÄÇå¾²Ô¤Ëã×ÜÌåÉÏÕýÔÚïÔÌ­¡£2020Ä꣬´óÐ͹«Ë¾ITÔ¤ËãϽµÁË26£¥£¬ÖÐСÐÍÆóҵҲϽµÁËÔ¼10£¥¡£±ðµÄ£¬µ½2021ÄêÔÚÔÆ·þÎñÉϵÄÖ§³ö½«ÏûºÄITÔ¤ËãµÄÔ¼32£¥£¬Òò´Ë¼àÊÓÆ½Ì¨µÄ¼àÊÓºÍÇå¾²ÐÔÖÁ¹ØÖ÷Òª¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/2021-economic-predictions-for-infosec/38553/