¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180712

°ä²¼¹¦·ò 2018-07-12

¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖеÄCPU·ì϶Spectre 1.1ºÍSpectre 1.2


×êÑÐÈËÔ±KirianskyºÍWaldspurger·¢ÏÖCPU·ì϶¹í»êµÄÁ½¸öбäÖÖ£¬±ðÀëΪSpecter 1.1£¨CVE-2018-3693£©ºÍSpectre 1.2¡£×êÑÐÈËÔ±ÒѾ­ÔÚÓ¢ÌØ¶ûx86ºÍARM´¦ÖÃÆ÷ÉÏÑéÖ¤ÁËSpectre 1.1ºÍSpectre 1.2¹¥»÷¡£¹ÌÈ»AMD»¹Î´°ä·¢ÉêÃ÷£¬µ«ÓÉÓÚËùÓеÄSpectre¹¥»÷³ÇÊÐÓ°ÏìAMD CPU£¬Òò¶øAMD CPU¼«ÓпÉÄÜÒ²ÊÜÓ°Ï졣΢Èí¡¢ºìñºÍ¼×¹ÇÎÄÒ²ÔÚµ÷²éÆä²úÆ·ÊÇ·ñÊÜÓ°Ï졣Ŀǰ»¹Ã»ÓÐÈκβ¹¶¡°ä²¼¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-spectre-11-and-spectre-12-cpu-flaws-disclosed/


¡¾·ì϶²¹¶¡¡¿Adobe°ä²¼7Ô°²È«¸üУ¬¹²½¨¸´112¸ö°²È«·ì϶


Adobe°ä²¼2018Äê7Եݲȫ¸üУ¬¹²½¨¸´¶à¸ö²úÆ·ÖеÄ112¸ö°²È«·ì϶£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Adobe Flash Player¡¢Adobe Experience Manager¡¢Adobe Connect¡¢Adobe AcrobatÒÔ¼°Reader¡£ÆäÖÐFlash PlayerÖеĸßΣ·ì϶£¨CVE-2018-5007£©¿Éµ¼Ö¹¥»÷ÕßÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£Adobe AcrobatºÍReaderÖй²½¨¸´ÁË104¸ö·ì϶£¬ÆäÖÐÔ̺¬51¸ö¸ßΣ·ì϶£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/adobe-patch-update-july.html


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±¼ì²âµ½Arch LinuxÈí¼þ¿âAUR´æÔÚ¶à¸ö¶ñÒâÈí¼þ°ü


Arch LinuxÍŶÓÔÚÆäÓû§Èí¼þ¿âAURÖз¢ÏÖÈý¸ö¶ñÒâÈí¼þ°ü£¬Ä¿Ç°ÕâЩ¶ñÒâÈí¼þ°üÒѱ»É¾³ý¡£AURÊÇÒ»¸ö»ùÓÚÉçÇøµÄÓÉArch LinuxÓû§´´½¨ºÍÖÎÀíµÄÈí¼þ¿â£¬6ÔÂ7ÈÕ¶ñÒâÓû§xeactorÌá½»ÁËÒ»¸öÃûΪacroreadµÄ¹ÂÁ¢Èí¼þ°ü£¬¸ÃÈí¼þÊÇÒ»¸öPDF²é¿´Æ÷£¬µ«ÆäÖÐÖ²ÈëÁ˶ñÒâ´úÂë¡£³ý´ËÖ®±í£¬AURÍŶӻ¹É¾³ýÁËÆäËüÁ½¸ö¶ñÒâÈí¼þ°ü£¬µ«Ã»ÓÐй©¸ü¶àϸ½Ú¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/arch-linux-aur-malware.html


¡¾Íþвµý±¨¡¿×êÑÐÍŶӰ䲼¹ØÓÚ°µÍøÊг¡ÉϵÄRDPÉ̵êµÄ·ÖÎö»ã±¨


McAfee×êÑÐÍŶӰ䲼¹ØÓÚ°µÍøÉÏÏúÊÛRDP·þÎñµÄÉ̵êµÄ×êÑл㱨¡£ÔÚÕâЩÉ̵êÖУ¬ÓëÖØÒª¹ú¼Ê»ú³¡µÄ°²È«ºÍÂ¥Óî×Ô¶¯»¯ÏµÍ³ÓйصĽӼûÖ»±ØÒªÆÆ·Ñ10ÃÀÔª¡£ÕâЩÉ̵êµÄ¹æÄ£´Ó15¸öRDPÏνӵ½³¬¹ý4Íò¸öRDPÏνÓ¡£ÍøÂç·¸×ï·Ö×ӲɰìRDP·þÎñºóÄܹ»ÓÃÓÚ·¢ËÍÀ¬»øÓʼþ¡¢»ñÈ¡Óû§Í´´¦¡¢ÍÚ¿ó¡¢·Ö·¢ÀÕË÷Èí¼þÒÔ¼°µ±×÷¹¥»÷Ìø°åµÈ¡£ÏúÊÛµÄRDPÏνÓÉõÖÁÔ̺¬Óëµ±¾Öϵͳ¡¢Ò½ÁƱ£½¡»ú¹¹ÓйصÄÏνÓ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/organizations-leave-backdoors-open-to-cheap-remote-desktop-protocol-attacks/


¡¾¹¥»÷ÊÂÎñ¡¿ÃÀ¾üÎÞÈË»úÎļþÔâÇÔ£¬¹¥»÷ÕßÒÔ150ÃÀÔªµÄ¼ÛÖµÍøÉÏÏúÊÛ


Recorded Future·¢ÏÖºÚ¿ÍÔÚÍøÉÏÂÛ̳ÒÔ150ÃÀÔª-200ÃÀÔªµÄ±ãÒ˼ÛÖµÏúÊÛÃô¸ÐµÄ¾üÊÂÎļþ£¬ÕâЩÎļþÔ̺¬ÃÀ¾üMQ-9 ReaperÎÞÈË»úµÄά½¨Êֲᡢ¹ØÓÚ¼òÒ×±¬Õ¨×°Öã¨IED£©²¿Êð¼¼ÇɵÄÅàѵÊֲᡢM1 ABRAMS̹¿Ë²Ù×÷Ö¸ÄÏ¡¢¼ÝʻԱѵÁ·ºÍÉú¼ÆÊÖ²áÒÔ¼°Ì¹¿ËÕ½ÊõÊÖ²áµÈ¡£¾Ý³ÆÕâЩÎļþй¶µÄÔ­ÒòÊÇһЩ¾üÊÂÉèÊ©ÖеÄ·ÓÉÆ÷ʹÓÃÁËĬÈϵÄFTPÃÜÂë¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-steals-military-docs-because-someone-didn-t-change-a-default-ftp-password/

 

¡¾¹¥»÷ÊÂÎñ¡¿Chrome²å¼þHola VPNÔ⺧£¬Ô­²å¼þ±»Ö²Èë¶ñÒâ´úÂë


Chrome²å¼þHola VPNµÄ¿ª·¢ÕßÕË»§ÔâºÚ¿ÍÈëÇÖ£¬Æä²å¼þ±»Ö²Èë¶ñÒâ´úÂ룬ÓÃÓÚ½«MyEtherWallet.comÍøÕ¾µÄÓû§³Á¶¨ÏòÖÁ´¹µöÍøÕ¾¡£Õâ´Î¹¥»÷²úÉúÔÚ7ÔÂ9ÈÕ£¬¹²³ÖÐøÁË5¸öÓ×ʱ£¬Ä¿Ç°¸Ã²å¼þÒѸ´Ô­ÖÁ¸É¾»µÄ°æ±¾¡£Hola VPNÍŶÓûÓÐй©¹¥»÷ÕßÈôºÎ½øÈëÆäChrome¿ª·¢ÕßÕË»§¡£MEWÍŶÓÔÚ¶½´ÙʹÓô˲å¼þµÄÓû§½«Æä¼ÓÃÜÇ®±Ò×ªÒÆÖÁеÄÕË»§£¬ÒÔÈ·±£°²È«¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-breaches-hola-vpn-chrome-extension-to-go-after-cryptocurrency-wallet-site/