¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180712
Ðû²¼Ê±¼ä 2018-07-12¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷еÄCPUÎó²îSpectre 1.1ºÍSpectre 1.2
Ñо¿Ö°Ô±KirianskyºÍWaldspurger·¢Ã÷CPUÎó²îÓÄÁéµÄÁ½¸öбäÖÖ£¬»®·ÖΪSpecter 1.1£¨CVE-2018-3693£©ºÍSpectre 1.2¡£Ñо¿Ö°Ô±ÒѾÔÚÓ¢ÌØ¶ûx86ºÍARM´¦Öóͷ£Æ÷ÉÏÑéÖ¤ÁËSpectre 1.1ºÍSpectre 1.2¹¥»÷¡£ËäÈ»AMD»¹Î´½ÒÏþÉùÃ÷£¬µ«ÓÉÓÚËùÓеÄSpectre¹¥»÷¶¼»áÓ°ÏìAMD CPU£¬Òò´ËAMD CPU¼«ÓпÉÄÜÒ²ÊÜÓ°Ï졣΢Èí¡¢ºìñºÍ¼×¹ÇÎÄÒ²ÔÚÊÓ²ìÆä²úÆ·ÊÇ·ñÊÜÓ°Ïì¡£ÏÖÔÚ»¹Ã»ÓÐÈκβ¹¶¡Ðû²¼¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-spectre-11-and-spectre-12-cpu-flaws-disclosed/
¡¾Îó²î²¹¶¡¡¿AdobeÐû²¼7ÔÂÇå¾²¸üУ¬¹²ÐÞ¸´112¸öÇå¾²Îó²î
AdobeÐû²¼2018Äê7ÔµÄÇå¾²¸üУ¬¹²ÐÞ¸´¶à¸ö²úÆ·ÖеÄ112¸öÇå¾²Îó²î£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Adobe Flash Player¡¢Adobe Experience Manager¡¢Adobe Connect¡¢Adobe AcrobatÒÔ¼°Reader¡£ÆäÖÐFlash PlayerÖеĸßΣÎó²î£¨CVE-2018-5007£©¿Éµ¼Ö¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£Adobe AcrobatºÍReaderÖй²ÐÞ¸´ÁË104¸öÎó²î£¬ÆäÖаüÀ¨51¸ö¸ßΣÎó²î£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/adobe-patch-update-july.html
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±¼ì²âµ½Arch LinuxÈí¼þ¿âAUR±£´æ¶à¸ö¶ñÒâÈí¼þ°ü
Arch LinuxÍŶÓÔÚÆäÓû§Èí¼þ¿âAURÖз¢Ã÷Èý¸ö¶ñÒâÈí¼þ°ü£¬ÏÖÔÚÕâЩ¶ñÒâÈí¼þ°üÒѱ»É¾³ý¡£AURÊÇÒ»¸ö»ùÓÚÉçÇøµÄÓÉArch LinuxÓû§½¨ÉèºÍÖÎÀíµÄÈí¼þ¿â£¬6ÔÂ7ÈÕ¶ñÒâÓû§xeactorÌá½»ÁËÒ»¸öÃûΪacroreadµÄÁæØêÈí¼þ°ü£¬¸ÃÈí¼þÊÇÒ»¸öPDFÉó²éÆ÷£¬µ«ÆäÖÐÖ²ÈëÁ˶ñÒâ´úÂë¡£³ý´ËÖ®Í⣬AURÍŶӻ¹É¾³ýÁËÆäËüÁ½¸ö¶ñÒâÈí¼þ°ü£¬µ«Ã»ÓÐ͸¶¸ü¶àϸ½Ú¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/arch-linux-aur-malware.html
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚ°µÍøÊг¡ÉϵÄRDPÊÐËÁµÄÆÊÎö±¨¸æ
McAfeeÑо¿ÍŶÓÐû²¼¹ØÓÚ°µÍøÉϳöÊÛRDP·þÎñµÄÊÐËÁµÄÑо¿±¨¸æ¡£ÔÚÕâЩÊÐËÁÖУ¬ÓëÖ÷Òª¹ú¼Ê»ú³¡µÄÇå¾²ºÍÂ¥Óî×Ô¶¯»¯ÏµÍ³Ïà¹ØµÄ»á¼ûÖ»Ðè񻮮·Ñ10ÃÀÔª¡£ÕâЩÊÐËÁµÄ¹æÄ£´Ó15¸öRDPÅþÁ¬µ½Áè¼Ý4Íò¸öRDPÅþÁ¬¡£ÍøÂç·¸·¨·Ö×Ó¹ºÖÃRDP·þÎñºó¿ÉÒÔÓÃÓÚ·¢ËÍÀ¬»øÓʼþ¡¢»ñÈ¡Óû§Æ¾Ö¤¡¢ÍÚ¿ó¡¢·Ö·¢ÀÕË÷Èí¼þÒÔ¼°¿´³É¹¥»÷Ìø°åµÈ¡£³öÊÛµÄRDPÅþÁ¬ÉõÖÁ°üÀ¨ÓëÕþ¸®ÏµÍ³¡¢Ò½ÁƱ£½¡»ú¹¹Ïà¹ØµÄÅþÁ¬¡£
ÔÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/organizations-leave-backdoors-open-to-cheap-remote-desktop-protocol-attacks/
¡¾¹¥»÷ÊÂÎñ¡¿ÃÀ¾üÎÞÈË»úÎļþÔâÇÔ£¬¹¥»÷ÕßÒÔ150ÃÀÔªµÄ¼ÛÇ®ÍøÉϳöÊÛ
Recorded Future·¢Ã÷ºÚ¿ÍÔÚÍøÉÏÂÛ̳ÒÔ150ÃÀÔª-200ÃÀÔªµÄµÍÁ®¼ÛÇ®³öÊÛÃô¸ÐµÄ¾üÊÂÎļþ£¬ÕâЩÎļþ°üÀ¨ÃÀ¾üMQ-9 ReaperÎÞÈË»úµÄάÐÞÊֲᡢ¹ØÓÚdzÒ×±¬Õ¨×°Öã¨IED£©°²Åż¼ÇɵÄÅàѵÊֲᡢM1 ABRAMS̹¿Ë²Ù×÷Ö¸ÄÏ¡¢¼ÝʻԱѵÁ·ºÍÉúÑÄÊÖ²áÒÔ¼°Ì¹¿ËÕ½ÊõÊÖ²áµÈ¡£¾Ý³ÆÕâЩÎļþй¶µÄÔµ¹ÊÔÓÉÊÇһЩ¾üÊÂÉèÊ©ÖеÄ·ÓÉÆ÷ʹÓÃÁËĬÈϵÄFTPÃÜÂë¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-steals-military-docs-because-someone-didn-t-change-a-default-ftp-password/
¡¾¹¥»÷ÊÂÎñ¡¿Chrome²å¼þHola VPNÔ⺧£¬Ô²å¼þ±»Ö²Èë¶ñÒâ´úÂë
Chrome²å¼þHola VPNµÄ¿ª·¢ÕßÕË»§ÔâºÚ¿ÍÈëÇÖ£¬Æä²å¼þ±»Ö²Èë¶ñÒâ´úÂ룬ÓÃÓÚ½«MyEtherWallet.comÍøÕ¾µÄÓû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾¡£´Ë´Î¹¥»÷±¬·¢ÔÚ7ÔÂ9ÈÕ£¬¹²Ò»Á¬ÁË5¸öСʱ£¬ÏÖÔڸòå¼þÒѻָ´ÖÁÇå½àµÄ°æ±¾¡£Hola VPNÍŶÓûÓÐ͸¶¹¥»÷ÕßÔõÑù½øÈëÆäChrome¿ª·¢ÕßÕË»§¡£MEWÍŶÓÕýÔÚ´ß´ÙʹÓô˲å¼þµÄÓû§½«Æä¼ÓÃÜÇ®±Ò×ªÒÆÖÁеÄÕË»§£¬ÒÔÈ·±£Çå¾²¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-breaches-hola-vpn-chrome-extension-to-go-after-cryptocurrency-wallet-site/


¾©¹«Íø°²±¸11010802024551ºÅ