GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÑëÈ˹¥»÷£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ï죻AMD²¿ÃÅGPU²âÊÔÔ´Âë±»µÁ£¬ºÚ¿ÍÀÕË÷1ÒÚÃÀÔª

°ä²¼¹¦·ò 2020-03-27

1.GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÑëÈ˹¥»÷£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3ÔÂ26ÈÕÓй¥»÷ÕßÕë¶ÔGithubºÍ¾©¶«µÈÍøÕ¾ÌáÒé´ó¹æÄ£ÖÐÑëÈ˹¥»÷£¬Ä¿Ç°ÊÜÓ°ÏìµÄÖØÒªÊDz¿ÃŵØÓòÓû§£¬µ«Éæ¼°ËùÓÐÔËÓªÉÌ£¬ÀýÈçÖйúÒÆ¶¯¡¢ÖйúÁªÍ¨¡¢ÖйúµçÐÅÒÔ¼°½ÌÓýÍø¾ù¿É¸´ÏÖ½Ù³ÖÎÊÌ⣬¶ø¹ú±íÍøÂç½Ó¼ûÕâЩվµã²¢Î´³öÏÖÒì³£Çé¿ö ¡£´ÓÄ¿Ç°ÍøÉϲéÎʵÄÐÅÏ¢Äܹ»¿´µ½Õâ´Î¹¥»÷Éæ¼°×î¹ãµÄÊÇGitHub.io£¬Æä´ÎÓû§½Ó¼û¾©¶«µÈ¹úÄÚ³ÛÃûÍøÕ¾Òà»á±¨´í ¡£²é¿´Ö¤ÊÖÔýÏ¢Äܹ»·¢ÏÖÕâÐ©ÍøÕ¾µÄÖ¤Êé±»¹¥»÷ÕßʹÓõÄ×ÔÊðÃûÖ¤Êé°ü°ì£¬µ¼ÖÂä¯ÀÀÆ÷ÎÞ·¨ÐÅÀµ´Ó¶ø×èÖ¹Óû§½Ó¼û ¡£Ä¿Ç°È«Íø¾ø´óÎÞÊýÍøÕ¾¶¼ÒѾ­¿ªÆô¼ÓÃܼ¼ÊõÆ¥µÐ½Ù³Ö£¬Òò¶øÓû§½Ó¼û»á±»×èÖ¹¶ø²»»á±»Êèµ¼µ½´¹µöÍøÕ¾ÉÏÈ¥ ¡£Õâ´Î¹¥»÷ËÆºõÊÇͨ¹ý¹Ç¸ÉÍøÂç½Ù³Ö443¶Ë¿Ú£¬Ä¿Ç°¾­²âÊÔDNSϵͳ½âÎöÊÇÆëÈ«Õý³£µÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.landiannews.com/archives/71707.html


2.°µÍøÍйܷþÎñÉÌDHÔâºÚ¿Í¹¥»÷£¬½ü7600¸öÍøÕ¾å´»ú


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°µÍø×î´óµÄÃâ·ÑÍйܷþÎñÉÌDaniel's Hosting£¨DH£©ÔÚ16¸öÔÂÄÚµÚ¶þ´ÎÔâµ½ºÚ¿Í¹¥»÷£¬½«½ü7600¸öÍøÕ¾å´»ú ¡£¸Ã·þÎñ±³ºóµÄµÂ¹ú¿ª·¢ÕßDaniel Winzen°µÊ¾£¬¹¥»÷ÊÂÎñ²úÉúÔÚ3ÔÂ10ÈÕÁ賿3µã×óÓÒ£¬ºÚ¿ÍÈëÇÖÁËDHºó¶Ë²¢É¾³ýÁËËùÓÐÓëÍйÜÓйصÄÊý¾Ý¿â£¬²¢É¾³ýÁËWinzenµÄÊý¾Ý¿âÕË»§ºÍ´´½¨ÁËÒ»¸öÐÂÕË»§ ¡£Winzen°µÊ¾DH·þÎñÔÚÉè¼ÆÉϲ¢Î´±£Áô±¸·Ý£¬²¢ÇÒËûÉÐδ·¢ÏÖºÚ¿ÍÈôºÎÈëÇÖDHºó¶Ë£¬Óû§Ó¦½«ÆäDHÕÊ»§µÄÃÜÂëÊÓΪ¡°Ð¹Â¶¡±£¬ÈôÊÇÆäËûÕÊ»§Ê¹ÓÃÒ»ÑùµÄÃÜÂ룬ÔòÓ¦½øÐиü¸Ä ¡£DHÔøÓÚ2018Äê11Ô±»ºÚ¿ÍÈëÇÖ£¬ÆäʱºÚ¿ÍͬÑù·ÛËéÁ˺ó¶ËÊý¾Ý¿â²¢É¾³ýÁËËùÓÐÍøÕ¾£¬ÆäʱÊÜÓ°ÏìµÄÍøÕ¾Îª6500¶à¸ö ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dark-web-hosting-provider-hacked-again-7600-sites-down/


3.ºÚ¿ÍÀûÓÃÐéαChrome¸üзַ¢ºóÃż°¼üÅ̼ͼľÂí


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÔÚÀûÓñ»ÈëÇֵĹ«Ë¾ÃÅ»§ÍøÕ¾ºÍÐÂÎŲ©¿Í£¨»ùÓÚWordPress CMS£©À´´«²¼ºóÃÅ£¬²¢¿ªÊͼüÅ̼ͼľÂí¡¢ÐÅÏ¢ÇÔȡľÂíµÈµÚ¶þ½×¶Îpayload ¡£Æ¾¾ÝDoctor Web×êÑÐÈËÔ±µÄ·ÖÎö£¬¹¥»÷ÕßÀûÓüÙ×°³ÉChrome¸üеÄCritical_Update.exeºÍUpdate.exe·Ö·¢ºóÃÅ£¬ÆäÏÂÔØÁ¿Òѳ¬¹ý2290´Î ¡£ÔÚ»ñµÃÊÜÏ°È¾ÍøÕ¾µÄÖÎÀíÔ±½Ó¼ûȨÏ޺󣬺ڿÍ×¢Èë¶ñÒâJavaScript´úÂ룬½«½Ó¼ûÕß³Á¶¨Ïòµ½´¹µöÍøÕ¾ ¡£ÕâÒ»¹¥»÷±³ºóµÄ×éÖ¯Ôø²ÎͶÈëÇÖ¹ÙÍø·Ö·¢ÐéαVSDCÊÓÆµ±à×ëÆ÷¼°ÀûÓÃÐéαNordVPNÍøÕ¾·Ö·¢BolikÒøÐÐľÂíµÄ¹¥»÷»î¶¯£¬ÆäÖ¸±êÔ̺¬ÃÀ¹ú¡¢¼ÓÄô󡢰ĴóÀûÑÇ¡¢Ó¢¹ú¡¢ÒÔÉ«ÁкÍÍÁ¶úÆä ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malware-disguised-as-google-updates-pushed-via-hacked-news-sites/


4.Apple°ä²¼¶à¿î²úÆ·µÄ°²È«¸üУ¬½¨¸´68¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


AppleÔÚÆäiOSºÍmacOS¡¢Safariä¯ÀÀÆ÷¡¢watchOS¡¢tvOSºÍiTunesÉϰ䲼ÁË´óÁ¿²¹¶¡£¬ÆäÖÐiOSÖн¨¸´ÁË30¸ö·ì϶£¬SafariÖн¨¸´ÁË11¸ö·ì϶£¬macOSÖн¨¸´ÁË27¸ö·ì϶ ¡£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄ·ì϶ÊÇWebKitÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2020-3897£©£¬¸Ã·ì϶´æÔÚÓÚ¶ÔÏóת»»»º´æÖУ¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚµ±Ç°¹ý³ÌµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë ¡£Apple»¹Åû¶ÁËÁ½¸öÓ°ÏìiOSºÍmacOSµÄÄں˷ì϶ ¡£µÚÒ»¸öÊÇÄÚ´æ³õʼ»¯ÎÊÌ⣨CVE-2020-3914£©£¬¸ÃÎÊÌâ¿ÉÄÜÔÊÐíÀûÓ÷¨Ê½¶ÁÈ¡ÊÜÏÞµÄÄÚ´æ ¡£µÚ¶þ¸öÊÇÄÚºËÖеÄÄÚ´æ°Ü»µÎÊÌ⣨CVE-2020-9785£©£¬Ëü¿ÉÄÜÔÊÐí¶ñÒâÀûÓ÷¨Ê½ÒÔÄÚºËÌØÈ¨Ö´ÐÐËÁÒâ´úÂë ¡£½¨ÒéÓû§¸üе½iOS 13.4¡¢Safari 13.1ºÍmacOS Catalina 10.15.3 ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/apple-update-fixes-webkit-flaws-in-ios-safari/154155/


5.×êÑÐÍŶӰ䲼Õë¶ÔICSµÄKwampirs RATµÄ·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ReversingLabs·ÖÎöÁËKwampirs RATµÄ¹¥»÷IOC£¬ÒÔÔ®ÊÖ¹«Ë¾±£»¤Æä×éÖ¯ÃâÊܸöñÒâÈí¼þµÄ¹¥»÷ ¡£FBI×î½üÖÒ¸æ³Æ£¬³ýÁËÕë¶ÔÈí¼þ¹©¸øÁ´¹«Ë¾±í£¬Kwampirs¹¥»÷Õß´Ë¿ÌÒѾ­ÑÝÔì³ÉÕë¶ÔICSÆóÒµ£¬ÓÈÆäÊÇÄÜÔ´ÐÐÒµ ¡£×êÑÐÈËÔ±·¢ÏÖÿ¸öKwampirsÑù±¾¶¼´øÓÐ200¸öC2 URLµÄÓ²±àÂëÁÐ±í£¨ÒÔÓòÃû»òIPµØÖ·µÄ´ó¾Ö£©£¬Kwampirs³¢ÊÔ°´°¤´Î½Ó¼ûÕâЩURL²¢Ê¹ÓõÚÒ»¸ö»î¶¯µÄULR×÷ΪC2·þÎñÆ÷ ¡£ReversingLabs¹²È·¶¨ÁË1586¸öURL ¡£Ñù±¾µÄ±êÍ·ÏÔʾËùÓÐÑù±¾¶¼ÊÇʹÓÃVisual Studio 2010±àÒëµÄ ¡£¹¦·ò´ÁÓëËüÃǵijöÏÖ¹¦·òûÓйØÁª£¬Õâ¿ÉÄÜÒâζ×ÅÑù±¾ÊÇÔÚÓÐÒâ´øÓв»ÕýÈ·¹¦·ò´ÁµÄÐé¹¹»úÖбàÒëµÄ ¡£ReversingLabs´´½¨ÁËIOCÁбí£¬¹«Ë¾Äܹ»Ê¹ÓÃÕâЩIOC´´½¨ÐµķÀ»ðǽºÍÈëÇÖ¼ì²â¹æ¶¨£¬²¢ÔÚSIEMÈÕÖ¾ÖÐËÑË÷ÊÇ·ñÔ⵽ϰȾ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.techrepublic.com/article/boost-security-defenses-against-kwampirs-rat-malware-with-new-list-of-iocs/


6.AMD²¿ÃÅGPU²âÊÔÔ´Âë±»µÁ£¬ºÚ¿ÍÀÕË÷1ÒÚÃÀÔª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


AMD¹Ù·½°ä²¼Ò»·Ý¼ò¶ÌµÄÉêÃ÷£¬°µÊ¾ÓÐÈËÔÚ2019Äê12ÔÂÁªÏµËüÃÇ£¬Ðû³ÆÕ¼ÓÐÓëAMDµ±Ç°ºÍ½«À´²¿ÃÅGPU²úÆ·µÄ²âÊÔÎļþ ¡£ÔÚ×î½üÕâЩÎļþ±»ÉÏ´«µ½ÁËGitHubÖ®ÉÏ£¬¾Ý³ÆÎļþÖÐÔ̺¬NaviºÍArden GPUµÄ²¿ÃÅÔ´Â룬ºóÕßÊÇXbox Series XÉÏGPUµÄ´úºÅ£¬¶øÇ°ÕßÔ̺¬ÉÐδ°ä²¼µÄNavi 20ϵÁкÍÒѾ­°ä²¼µÄNavi 10µÄ²¿ÃÅÓ²¼þÔ´´úÂë ¡£AMDÏòGitHub·¢³öÁËDMCAÒªÇ󣬸ÃRepoËæºó±»³·Ï ¡£¸ÃºÚ¿Í£¨×Ô³ÆÎªÅ®ÐÔ£©Ðû³ÆÔÚÈ¥Äê11Ô·ݴӱ»ºÚµÄÍÆËã»úÖз¢ÏÖÁËAMD Navi GPUµÄÓ²¼þÔ´Â룬¸ÃÍÆËã»úÓû§Ò²Ã»ÓжԴúÂëй©²ÉÈ¡ÈκÎÓÐЧ´ëÊ© ¡£ËýͬʱҲȷÈÏ£¬ÕâЩÎļþÖÐÔ̺¬Navi 10¡¢Navi 21ºÍArdenµÄÔ´Âë ¡£Ëý²¢Ã»ÓоÍй©ÎÊÌâºÍAMDÁªÏµ ¡£²»ÍâAMDÔÚÉêÃ÷ÖгÆÕâЩÎļþûÓд¥¼°µ½GPU²úÆ·µÄÖ÷Ìâ ¡£


Ô­ÎÄÁ´½Ó£º

https://torrentfreak.com/amd-uses-dmca-to-mitigate-massive-gpu-source-code-leak-200325/