¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180612
°ä²¼¹¦·ò 2018-06-12
Ëæ×Å5G·äÎÑÍøÂç¼¼ÊõºÍIoTµÄ²»ÐÝÀ©´ó£¬ÎÀÐÇÒѾ³ÉΪÎïÁªÍøºÍ»¥ÁªÍø¹Ø¼ü»ù´¡ÉèÊ©µÄ³ÁÒª×é³É²¿ÃÅ£¬È·±£ÎÀÐǵݲȫӵÓгÁÒªµÄÒâ˼¡£Õë¶ÔÎÀÐǵĹ¥»÷ÏòÁ¿¿ÉËùÒÔÌì¿ÕºÍµØÃæÖ®¼ä£¬Ò²¿ÉËùÒÔµØÃæÖÁÎÀÐÇÔÙ´«²¼ÖÁÆäËüÎÀÐÇ£¬»òÕßÎÀÐÇÖÁµØÃæÔÙ´«²¼ÖÁÆäËü´¦Ëù¡£³£¼ûµÄ¹¥»÷ÀàÐÍÔ̺¬µçÐÅڲơ¢¿çÎÀÐǹ¥»÷¡¢ÀÄÓÃÎÀÐǵ绰µÈ£¬¹¥»÷³¡¾°Ô̺¬ÐéαµØÇò»ùÕ¾¡¢¼Ù×°³ÉÎÀÐǵÄͨѶ¡¢ÀûÓÃÎÀÐÇÍøÂç¼äµÄÐÅÀµµÈ¡£
ÔÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/attack-vectors-in-orbit-need-for-satellite-security-in-5g-iot/
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1.5Íò¸öAndroidÉ豸µÄADBµ÷ÊԶ˿ڶ³ö
×êÑÐÈËÔ±Kevin Beaumont³Æ³¬¹ý1.5Íò¸öAndroidÉ豸µÄADB¶Ë¿Ú¶³ö£¬ADB£¨Android Debug Bridge£©ÊÇAndroidϵͳµÄÒ»¸ö¹ÊÕÏÅųý¹¤¾ß£¬Ëü»¹Äܹ»ÊÚȨÓû§½Ó¼ûһЩÃô¸Ð¹¤¾ß£¨Ô̺¬Unix shell£©¡£ÎÊÌâÔÚÓÚһЩ¹©¸øÉ̽«ÆôÓÃÁËADB over WiFiÖ°ÄܵÄÉ豸½»¸¶¸øÓû§Ê¹Óã¬ÕâʹµÃÔÚÓû§²»ÖªÇéµÄÇé¿öÏ£¬ÆäÉ豸¿Éͨ¹ýTCP¶Ë¿Ú5555Ô¶³Ì½Ó¼û£¬²¿ÃÅÉ豸Òò¶øÏ°È¾ÃÅÂÞ±Ò¿ó¹¤ADB.Miner¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/tens-of-thousands-of-android-devices-are-exposing-their-debug-port/
¡¾Íþвµý±¨¡¿×êÑÐÍŶӳƹ¥»÷Õß´Ó²»°²È«µÄÒÔÌ«·»½ÚµãÖÐÇÔÈ¡³¬¹ý2000ÍòÃÀÔª
°²È«×êÑÐÈËÔ±ÖÒ¸æ³ÆÒ»¸öÍøÂç·¸×ï×é֯ͨ¹ý½Ù³ÖÍøÉ϶³öµÄ²»°²È«ÅäÖõÄÒÔÌ«·»½Úµã£¬ÔÚ´Óǰ¼¸¸öÔÂÄÚÇÔÈ¡ÁË38642¸öÒÔÌ«±Ò£¬¼ÛÖµ³¬¹ý2000ÍòÃÀÔª¡£Ò»Ð©ÒÔÌ«·»½ÚµãʹÓÃGeth¿Í»§¶Ë£¬²¢ÇÒÊ¢¿ªÁËJSON-RPC¶Ë¿Ú8545¡£Í¨¹ýJSON-RPCÓû§Äܹ»Ô¶³Ì½Ó¼ûÒÔÌ«·»Çø¿éÁ´ºÍ½ÚµãµÄÖ°ÄÜ£¬Ô̺¬´ÓÒѽâËøÕË»§·¢ËÍÂòÂô¡£¹¥»÷Õßͨ¹ýɨÃ軥ÁªÍøÉÏÊ¢¿ªµÄ8545¶Ë¿ÚÇÔÈ¡Óû§µÄ×ʽð¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/ethereum-geth-hacking.html
¡¾¹¥»÷ÊÂÎñ¡¿º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿ÍÈëÇÖ£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª
ÉÏÖÜÈÕº«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿Í¹¥»÷£¬ÈëÇÖÕßÇÔÈ¡ÁËPundi X£¨NPXS£©¡¢NPER£¨NPER£©ºÍAston£¨ATX£©µÄ²¿ÃÅICO´ú±Ò£¬ÂòÂôËùûÓÐÅû¶Óйر»µÁ×ʽðµÄ¾ßÌåÊý×Ö£¬µ«ÓÐЧ»§¸ú×ÙÁËÈëÇÖÕßµÄÕË»§µØÖ·£¬ÒÔΪÓйر»µÁ×ʽð¼ÛÖµÔÚ3000Íòµ½4000ÍòÃÀÔªÖ®¼ä£¬ÆäÖÐÔ¼Ò»°ëΪNPXS´ú±Ò¡£Coinrail³ÆÕýÓëÊÜÓ°ÏìµÄICO¹«Ë¾ºÏ×÷ÒÔ¶³½á±»µÁµÄ´ú±Ò¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/south-korean-cryptocurrency-exchange-coinrail-gets-hacked/
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖÒ»¼Ó6ÊÖ»ú´æÔÚ°²È«·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÊÕÊÜÉ豸
Edge Security°²È«×êÑÐÈËÔ±Jason Donenfeld·¢ÏÖÒ»¼Ó6ÊÖ»úÉϵÄbootloader²¢Î´ÆëÈ«Ëø¶¨£¬¿ÉÔÊÐí¹¥»÷ÕßдÈë¶ñÒâ¾µÏñºÍÆëÈ«ÊÕÊÜÉ豸¡£¸Ã·ì϶µÄÀûÓñØÒª¶ÔÉ豸µÄÎïÀí½Ó¼û¡£ÔÚÑÝʾÊÓÆµÖУ¬×êÑÐÈËÔ±Ö»ÆÆ·ÑÁ˼¸·ÖÖӾͽ«¶ñÒâ¾µÏñͨ¹ýADBµÄ¼±¾çÊèµ¼ºÅÁîдÈëÉ豸¡£Ò»¼ÓÒѾȷÈÏÁ˸ÃÎÊÌ⣬²¢³Ðŵ½«°ä²¼ÓйØÈí¼þ¸üС£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/oneplus6-bootloader-root.html
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖABBÃŽûϵͳ´æÔÚ¶à¸ö°²È«·ì϶
ERNW×êÑÐÈËÔ±Maxim RuppºÍFlorian GrunowÔÚÈðÊ¿ABB¹«Ë¾µÄÃŽûÖÎÀíϵͳÖз¢ÏÖ¶à¸ö°²È«·ì϶£¬ÊÜÓ°ÏìµÄ×é¼þÊǹ̼þ°æ±¾3.39¼°Ö®Ç°µÄABB IPÍø¹Ø¡£·ì϶ÁìÓòÔ̺¬ÈÏÖ¤ÈÆ¹ý·ì϶£¨CVE-2017-7931£©¡¢Ã÷ÎÄÃÜÂëй¶·ì϶£¨CVE-2017-7933£©¡¢¿çÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶£¨CVE-2017-7906£©ºÍÒ»¸öÔ¶³Ì´úÂë×¢Èë·ì϶¡£ABBÔڹ̼þ°æ±¾3.40Öн¨¸´ÁËÕâЩ·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/critical-flaws-expose-abb-door-communication-systems-attacks


¾©¹«Íø°²±¸11010802024551ºÅ