¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180725
°ä²¼¹¦·ò 2018-07-25¡¾·ÖÎö»ã±¨¡¿×êÑлú¹¹°ä²¼2018ÄêQ2 DDoS¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨
ÔÎÄÁ´½Ó£ºhttps://securelist.com/ddos-report-in-q2-2018/86537/
¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖÐÂÀ¶ÑÀ·ì϶£¨CVE-2018-5383£©£¬Apple¡¢IntelµÈ¾ùÊÜÓ°Ïì
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/bluetooth-hack-vulnerability.html
¡¾·ì϶²¹¶¡¡¿Apache Tomcat°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö°²È«·ì϶
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/apache-tomcat-server.html
¡¾·ì϶²¹¶¡¡¿AVEVA½¨¸´ÆäInTouchºÍInduSoft¹¤¾ßÖеÄ2¸öRCE·ì϶
Ó¢¹ú¹¤ÒµÈí¼þ¹«Ë¾AVEVA½¨¸´ÁËÆäInTouchºÍInduSoft¿ª·¢¹¤¾ßÖеÄ2¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðеݲȫ·ì϶¡£½ñÄêÔçЩʱ³½AVEVAÓëÊ©ÄÍµÂµçÆø¹é²¢£¬²¢ÊÕÊÜÁËAvantisºÍWonderwareÆ·ÅÆ¡£CyberX×êÑÐÈËÔ±George Lashenko·¢ÏÖijЩ°æ±¾µÄInTouch´æÔÚ»º³åÇøÒç¶Âí½Å£¨CVE-2018-10628£©£¬TenableµÄ×êÑÐÈËÔ±·¢ÏÖÁËÁíÒ»¸ö·ì϶£¨CVE-2018-10620£©¡£ÕâЩ·ì϶¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£7ÔÂ13ÈÕAVEVAÔÚHotfix 81.1.00.08Öн¨¸´ÁËÕâЩ·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/aveva-patches-critical-flaws-hmiscada-tools-following-schneider-merger
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖÕë¶ÔOracle WebLogic·þÎñÆ÷µÄй¥»÷»î¶¯
×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔOracle WebLogic·þÎñÆ÷µÄ¹¥»÷»î¶¯£¬ÕâЩ¹¥»÷»î¶¯ÖØÒªÀûÓ÷ì϶£¨CVE-2018-2893£©½øÐй¥»÷¡£OracleÔÚ7ÔÂ18ÈÕ°ä²¼Á˸÷ì϶µÄÓйز¹¶¡£¬7ÔÂ21ÈÕÆäÓйØPoC±»Åû¶¡£×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ2¸ö×éÖ¯ÔÚÀûÓø÷ì϶½øÐй¥»÷£¬½¨Ò黹δ¸üеÄÓû§¾¡¿ì½øÐÐÉý¼¶¡£Ò×Êܹ¥»÷µÄ°æ±¾Ô̺¬10.3.6.0¡¢12.1.3.0¡¢12.2.1.2ºÍ12.2.1.3¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/attacks-on-oracle-weblogic-servers-detected-after-publication-of-poc-code/
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖCPU·ì϶¹í»êµÄбäÖÖSpectreRSB
À´×ÔUCRµÄ×êÑÐÈËÔ±·¢ÏÖCPU·ì϶¹í»êµÄбäÖÖSpectreRSB¡£SpectreRSBͬÑùÀûÓÃÁËCPU´§Ä¦Ö´ÐеĹý³Ì£¬ÓëÆäËû±äÖÖ·ÖÆçµÄÊÇ£¬¸Ã¹¥»÷ÖØÒªÕë¶ÔCPU×é¼þRSB¡£×êÑÐÈËÔ±Ö»²âÊÔÁËIntel CPUÉϵÄSpectreRSB·ì϶£¬µ«ÓÉÓÚAMDºÍARM´¦ÖÃÆ÷ҲʹÓÃRSBÀ´Ô¤²â·µ»ØµØÖ·£¬Òò¶øËüÃǺÜÓпÉÄÜÒ²ÊÜÓ°Ïì¡£SpectreRSB¹¥»÷Äܹ»ÈƹýĿǰËùÓеĽ¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/researchers-detail-new-cpu-side-channel-attack-named-spectrersb/


¾©¹«Íø°²±¸11010802024551ºÅ