¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181115
°ä²¼¹¦·ò 2018-11-15
ÓÉ9Ãû×êÑÐÈËÔ±×é³ÉµÄ×êÑÐÓ××éÅû¶ÁË7ÖÖеÄÈۻٺ͹í»ê¹¥»÷£¬ÆäÖÐ2ÖÖÊÇMeltdown¹¥»÷µÄ±äÖÖ£¬Áí±í5ÖÖÊÇSpectre¹¥»÷µÄ±äÖÖ¡£Èý´óÖØÒª´¦ÖÃÆ÷³§ÉÌ-Intel¡¢AMDºÍARM¾ùÊÜÓ°Ïì¡£¸Ã×êÑÐÓ××éÏòIntel¡¢AMDºÍARM»ã±¨ÁËÕâЩ·ì϶£¬ÆäÖÐIntelºÍARMÒѾÈÏ¿ÉÁËËûÃǵÄ×êÑÐÁ˾֡£¸ÃÍŶӻ¹°µÊ¾£¬ÓÉÓÚ¹©¸øÉÌÔÚÖÂÁ¦½¨¸´ÕâЩÎÊÌ⣬ËûÃǾö¶¨Ôݲ»Åû¶ÓйØPoC¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/meltdown-spectre-vulnerabilities.html2¡¢FacebookÔÙÆØÐ·ì϶£¬»ò¿Éµ¼ÖÂÓû§¸öÈËÐÅϢй¶
Imperva×êÑÐÔ±Ron Masas·¢ÏÖFacebookÖеÄÒ»¸öзì϶£¬»ò¿Éµ¼ÖÂÓû§¼°Æä°éµĸöÈËÐÅϢй¶¡£¸Ã·ì϶ÓëFacebookËÑË÷Ö°ÄܵÄÁ˾ÖÏÔʾÓйأ¬Æ¾¾ÝMasasµÄ˵·¨£¬ÏÔʾÓû§ËÑË÷Á˾ֵÄÒ³ÃæÔ̺¬ÓëÿһÌõËÑË÷Á˾ÖÓйØÁªµÄiFrameÔªËØ£¬¶øÕâЩiFrameÔªËØµÄ¹ØÁªURLÒ×ÊÜCSRF¹¥»÷¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ǿÆÅ×û§Ö´ÐÐËÁÒâËÑË÷²éÎÊ£¬²¢»ñµÃ·µ»ØµÄÓû§ÐÅÏ¢¡£FacebookÒѾ½¨¸´Á˸÷ì϶¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/facebook-vulnerability-hack.html3¡¢°²È«³§Ḛ́䲼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨
Forcepoint°ä²¼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨£¬»ã±¨µÄÖ÷ÌâÔ̺¬£ºÍøÂ簲ȫÖеÄAIÊÇ·ñÒÑÖÁ¶¬Ì죿´ó¹æÄ£µÄ¹¤ÒµÎïÁªÍøÖжÏÍþв£»ÉúÎï¼ø±ð¼¼ÊõÖеĴ¹µöÍþв£»¹ØÓÚ¹¤×÷³¡Ëù°²È«´ëÊ©¼à²âµÄ˾·¨Âɹ棿ҵÎñÕ½Óë¹ú¶ÈÖ§³ÖµÄ¹¤Òµ¼äµý»î¶¯£»±ßÔµÍÆËãµÄÔ¶¾°Óë¹ÊÕÏ£»¶ÔºÏ×÷ͬ°éµÄ°²È«ÐÅÀµÆÀ¼¶»ò½«Ô½À´Ô½³ÁÒª¡£ÆëÈ«»ã±¨Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.forcepoint.com/blog/insights/2019-forcepoint-cybersecurity-predictions-report4¡¢ÔÚÏßÉ̵êInfowarsÔâMagecart¹¥»÷£¬Ô¼1600ÃûÓû§ÒÉÊÜÓ°Ïì
ºÉÀ¼°²È«×êÑÐÔ±Willem de Groot·¢´Ë¿ÌÏßÉ̵êInfowarsϰȾÁËÓÃÓÚÇÔÈ¡Óû§ÐÅÓþ¿¨ÐÅÏ¢µÄ¶ñÒâ¾ç±¾Magecart¡£¸Ã¶ñÒâ¾ç±¾ÔÚInfowarsÉÏ´æÔÚÁËԼĪ24¸öÓ×ʱ£¬Ëæºó¾Í±»Infowarsɾ³ý£¬Ô¼1600ÃûÓû§¿ÉÄÜÊܵ½Ó°Ïì¡£×êÑÐÈËÔ±³ÆÕâЩMagecart´úÂë°µ²ØÔÚGoogle Analytics´úÂë¿éÖУ¬½öÔÚÓû§½áÕËʱ¼¤»î£¬Ã¿¸ô1.5Ãëץȡһ´Î½áÕË±íµ¥ÖеÄ×Ö¶ÎÄÚÈÝ£¬²¢·¢ËÍÖÁλÓÚÁ¢ÌÕÍðµÄÔ¶³Ì·þÎñÆ÷google-analyitics[.]org¡£×êÑÐÈËÔ±»¹³ÆÕâЩ¶ñÒâ´úÂëµÄ·ç¸ñÓëRiskIQºÍFlashpointµÄMagecart¹¥»÷»ã±¨ÖÐÌá¼°µÄ7¸ö·¸×ïÍŻﶼ²»Ò»Ñù¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/card-skimming-malware-removed-from-infowars-online-store/5¡¢Adobe°ä²¼11Ô°²È«¸üУ¬½¨¸´Flash PlayerµÈ²úÆ·ÖеÄ3¸ö·ì϶

Adobe°ä²¼2018Äê11ÔµÄÔ¶Ȱ²È«¸üУ¬±ðÀ뽨¸´ÁËAcrobat reader¡¢Flash Player¼°Photoshop CCÖеݲȫ·ì϶¡£ÆäÖÐAcrobat readerÖеķì϶£¨CVE-2018-15979£©¿Éµ¼ÖÂÓû§µÄNTLM¹þÏ£ÃÜÂëй¶£¬²¢ÇҸ÷ì϶µÄPoC¹«¿ª¿ÉÓá£Flash PlayerÖеķì϶£¨CVE-2018-15978£©ºÍPhotoshop CCÖеķì϶£¨CVE-2018-15980£©¶¼Êǿɵ¼ÖÂÐÅϢй¶µÄÔ½½ç¶Á·ì϶¡£½¨ÒéÓû§¾¡¿ì½øÐиüС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-releases-security-update-for-acrobat-vulnerability-with-public-poc/6¡¢SAP°ä²¼11Ô°²È«¸üУ¬¹²½¨¸´11¸ö·ì϶
±¾ÖܶþSAP°ä²¼ÁË2018Äê11Ô°²È«¸üУ¬½¨¸´Á˶à¿î²úÆ·ÖеÄ11¸ö·ì϶¡£·ì϶ÁìÓòÔ̺¬´úÂë×¢Èë¡¢XSS¡¢XXE¡¢SSRF¡¢»Ø¾ø·þÎñ¡¢¶ÌȱXMLÑéÖ¤ºÍURL³Á¶¨ÏòµÈ¡£ÆäÖнÏÑϳÁµÄ·ì϶Ô̺¬SAP HANA Streaming AnalyticsµÄSpring¿ò¼Ü¿âÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-1270ºÍCVE-2018-1275£©ÒÔ¼°SAP Fiori¿Í»§¶ËÖеÄDoS·ì϶£¨CVE-2018-2488£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/sap-patches-critical-vulnerability-hana-streaming-analyticsÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ