¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180724
°ä²¼¹¦·ò 2018-07-24¡¾Êý¾Ýй¶¡¿³¬¹ý100¼ÒÆû³µ³§É̵ĻúÃÜÊý¾Ýй¶£¬·áÌï¡¢ÌØË¹ÀµÈ¾ùÊÜÓ°Ïì
UpGuard×êÑÐÈËÔ±Chris Vickery·¢ÏÖ¹©¸øÉÌLevel OneµÄ²»°²È«Êý¾Ý¿â£¬ÆäÖÐÔ̺¬½ü47000·ÝÎļþ£¬º¸Ç¶à¼ÒÆû³µ³§É̵ĽüÊ®ÄêµÄ¾ßÌåÀ¶Í¼¡¢¹¤³§µÀÀíͼ¡¢¿Í»§×ÊÁÏ£¨ÈçºÏͬ¡¢·¢Æ±ºÍ¹¤×÷´òËãµÈ£©£¬ÒÔ¼°¸÷Àà±£ÃܺÍ̸ÎļþµÈ¡£Ð¹Â¶µÄÊý¾Ý×ÜÁ¿´ï157GB£¬¸£ÌØ¡¢·áÌͨÓúÍÌØË¹ÀµÈ¾ùÊÜÓ°Ï졣й¶µÄÔÒòÊÇLevel One¹«Ë¾µÄÓÃÓÚ±¸·ÝÊý¾ÝµÄÎļþ´«ÊäºÍ̸rsync±»ÅäÖÃΪ¿É¹«¿ª½Ó¼û£¬²¢ÇÒ²»±ØÒªÈκÎÃÜÂë¡£
ÔÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/robotics-suppliers-sloppy-security-leaks-ten-years-worth-of-data-from-major-car-manufacturers/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±·¢ÏÖAndroidÒøÐÐľÂíExobotµÄÔ´Âëй¶
×êÑÐÈËÔ±·¢ÏÖAndroidÒøÐÐľÂíExobotµÄÔ´´úÂëÒÑÓÚ5ÔÂй¶£¬²¢ÇÒÔÚ¶ñÒâÈí¼þÉçÇøÖÐѸ¿ì´«²¼¡£ExobotÓÚ2016Äêµ×±»³õ´Î·¢ÏÖ£¬ÆäÖ°Äܼ«¶È׳´ó£¬ÉõÖÁÄܹ»Ï°È¾×îеÄAndroid°æ±¾¡£2018Äê1Ô¸öñÒâÈí¼þµÄ×÷Õ߯ðÍ·ÏúÊÛÆäÔ´´úÂ룬Õâͨ³£ÒâζןÃ×÷ÕßÒÑתÏòÆäËüµÄÆ÷²Ä¡£Ä¿Ç°Ð¹Â¶µÄ°æ±¾ÊÇExobot 2.5£¬×êÑÐÈËÔ±¾¯Ê¾³ÆÕâ¿ÉÄܵ¼ÖÂÐÂÒ»²¨µÄ¹¥»÷»î¶¯¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/source-code-for-exobot-android-banking-trojan-leaked-online/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖͨ¹ýAndroid ADB¶Ë¿Ú´«²¼µÄSatoriбäÌå
Ç÷Ïò¿Æ¼¼×êÑÐÍŶÓÔÚ7ÔÂ9ÈÕÖÁ10ÈÕºÍ7ÔÂ15ÈÕ¼ì²âµ½Õë¶Ô5555¶Ë¿ÚµÄ¹¥»÷»î¶¯µÄÁ½¸ö·åÖµ£¬¸Ã¹¥»÷»î¶¯ÀûÓÃÊ¢¿ªµÄADB¶Ë¿ÚÔÚAndroidÉ豸Öд«²¼SatoriµÄÒ»¸öбäÌå¡£µÚÒ»²¨¹¥»÷µÄÁ÷Á¿ÖØÒªÀ´×ÔÓÚÃÀ¹úºÍÖйú£¬¶øµÚ¶þ²¨Á÷Á¿ÖØÒªÀ´×Ôº«¹ú¡£AndroidÓû§Äܹ»Í¨¹ý¹Ø¹Ø¡°ADB£¨USB£©µ÷ÊÔ¡±ºÍ¡°ÔÊÐí×°ÖÃδ֪ÆðÔ´µÄÀûÓá¹ØâÁ½¸öÑ¡ÏîÀ´·À±¸ÕâÖÖ¹¥»÷¡£
ÔÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/open-adb-ports-being-exploited-to-spread-possible-satori-variant-in-android-devices/
¡¾·ì϶²¹¶¡¡¿Î¢ÈíÔÚ7Ô°²È«¸üÐÂÖÐÔٴν¨¸´IEÁãÈÕ·ì϶£¨CVE-2018-8174£©
΢ÈíÔÚ5Ô½¨¸´ÁËIEÁãÈÕ·ì϶£¨CVE-2018-8174£©£¬µ«×êÑÐÈËÔ±·ÖÎöÁ˽¨¸´²¹¶¡ºó·¢ÏÖÈÔ´æÔÚÁí±íÁ½¸ö¿Éµ¼ÖÂÔ·ì϶µÄÎÊÌâ¡£ÕâÁ½¸öÎÊÌâ±»ÏóÕ÷Ϊ·ì϶£¨CVE-2018-8242£©£¬Î¢ÈíÔÚ7Ô°²È«¸üÐÂÖа䲼Á˸÷ì϶µÄ½¨¸´²¹¶¡¡£×êÑÐÈËÔ±»¹³ÆCVE-2018-8242µÄ½¨¸´²¹¶¡ÒýÈëÁËÒ»¸öÄÚ´æÐ¹Â¶µÄ»úÄÜÎÊÌ⣬µ«Õâ¸öÎÊÌâ²¢²»ÊÇÒ»¸ö°²È«·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/that-ie-zero-day-from-may-needed-a-second-patch-in-july/
¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ¹Øë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öеĽ¨¸´´ëÊ©
À´×Ô¶àËù´óѧµÄ×êÑÐÈËÔ¹Øë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öÁËеĽ¨¸´´ëÊ©£¬ÕâЩ´ëÊ©ÊÇÔÚÈí¼þ¼¶´ËÍ⽨¸´£¬ÕâÒâζ×ÅCPUºÍRAM¹©¸øÉ̲»±ØÒªÅú¸ÄÆä²úÆ·£¬²¢ÇÒÕâЩ´ëÊ©Äܹ»ÒÔÈí¼þ¸üеķ½Ê½°ä²¼¡£Õë¶ÔSpectre¡¡V1µÄ½¨¸´ÀûÓÃÁËLinuxÄں˲¹¶¡ELFbac£¬¶øÕë¶ÔRowhammer¹¥»÷µÄ·À»¤´ëÊ©ÊÇͨ¹ýÒ»ÖÖм¼ÊõZebRAM¡£Ä¿Ç°×êÑÐÈËÔ±»¹Ã»ÓÐÅû¶¹ØÓÚÕâÏî¼¼ÊõµÄ¸ü¶à¾ßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/academics-announce-new-protections-against-spectre-and-rowhammer-attacks/
¡¾Ë¾·¨Âɹ桿°£¼°ÐÂ˾·¨ÑÏ´ò¼ÙÐÂÎÅ£¬·ÛË¿Êý³¬5000µÄ´«Ò¥Õß½«±»Öذì
7ÔÂ16ÈÕ°£¼°Òé»áͨ¹ýÒ»ÏîÐÂ˾·¨£¬¸Ã˾·¨½«ÔÚFacebookºÍTwitterµÈÉ罻ýÌåÆ½Ì¨Õ¼Óг¬¹ý5000Ãû·ÛË¿µÄÕ˺źͲ©¿ÍÊÓΪýÌ壬²¢ÔÊÐíµ±¾Ö·â½û°ä²¼¼ÙÐÂÎŵÄÕË»§ÒÔ¼°¶Ô°ä²¼ÈËÔ±½øÐд¦·£¡£ÐÂ˾·¨»¹ÒªÇóÍøÕ¾ÔÚ³ÉÁ¢Ö®Ç°±ØÐë»ñµÃ×î¸ßίԱ»áµÄÐí¿É£¬²¢ÔÊÐí¸ÃίԱ»á¶ÔÏÖÓÐÍøÕ¾½øÐзâ½û»ò·£¿î¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/social-media-fake-news-law.html


¾©¹«Íø°²±¸11010802024551ºÅ