¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180712

Ðû²¼Ê±¼ä 2018-07-12

¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷еÄCPUÎó²îSpectre 1.1ºÍSpectre 1.2


Ñо¿Ö°Ô±KirianskyºÍWaldspurger·¢Ã÷CPUÎó²îÓÄÁéµÄÁ½¸öбäÖÖ£¬£¬£¬ £¬£¬£¬»®·ÖΪSpecter 1.1£¨CVE-2018-3693£©ºÍSpectre 1.2¡£¡£¡£Ñо¿Ö°Ô±ÒѾ­ÔÚÓ¢ÌØ¶ûx86ºÍARM´¦Öóͷ£Æ÷ÉÏÑéÖ¤ÁËSpectre 1.1ºÍSpectre 1.2¹¥»÷¡£¡£¡£ËäÈ»AMD»¹Î´½ÒÏþÉùÃ÷£¬£¬£¬ £¬£¬£¬µ«ÓÉÓÚËùÓеÄSpectre¹¥»÷¶¼»áÓ°ÏìAMD CPU£¬£¬£¬ £¬£¬£¬Òò´ËAMD CPU¼«ÓпÉÄÜÒ²ÊÜÓ°Ïì¡£¡£¡£Î¢Èí¡¢ºìñºÍ¼×¹ÇÎÄÒ²ÔÚÊÓ²ìÆä²úÆ·ÊÇ·ñÊÜÓ°Ïì¡£¡£¡£ÏÖÔÚ»¹Ã»ÓÐÈκβ¹¶¡Ðû²¼¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-spectre-11-and-spectre-12-cpu-flaws-disclosed/


¡¾Îó²î²¹¶¡¡¿AdobeÐû²¼7ÔÂÇå¾²¸üУ¬£¬£¬ £¬£¬£¬¹²ÐÞ¸´112¸öÇå¾²Îó²î


AdobeÐû²¼2018Äê7ÔµÄÇå¾²¸üУ¬£¬£¬ £¬£¬£¬¹²ÐÞ¸´¶à¸ö²úÆ·ÖеÄ112¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Adobe Flash Player¡¢Adobe Experience Manager¡¢Adobe Connect¡¢Adobe AcrobatÒÔ¼°Reader¡£¡£¡£ÆäÖÐFlash PlayerÖеĸßΣÎó²î£¨CVE-2018-5007£©¿Éµ¼Ö¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£Adobe AcrobatºÍReaderÖй²ÐÞ¸´ÁË104¸öÎó²î£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨51¸ö¸ßΣÎó²î£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/adobe-patch-update-july.html


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±¼ì²âµ½Arch LinuxÈí¼þ¿âAUR±£´æ¶à¸ö¶ñÒâÈí¼þ°ü


Arch LinuxÍŶÓÔÚÆäÓû§Èí¼þ¿âAURÖз¢Ã÷Èý¸ö¶ñÒâÈí¼þ°ü£¬£¬£¬ £¬£¬£¬ÏÖÔÚÕâЩ¶ñÒâÈí¼þ°üÒѱ»É¾³ý¡£¡£¡£AURÊÇÒ»¸ö»ùÓÚÉçÇøµÄÓÉArch LinuxÓû§½¨ÉèºÍÖÎÀíµÄÈí¼þ¿â£¬£¬£¬ £¬£¬£¬6ÔÂ7ÈÕ¶ñÒâÓû§xeactorÌá½»ÁËÒ»¸öÃûΪacroreadµÄÁæØêÈí¼þ°ü£¬£¬£¬ £¬£¬£¬¸ÃÈí¼þÊÇÒ»¸öPDFÉó²éÆ÷£¬£¬£¬ £¬£¬£¬µ«ÆäÖÐÖ²ÈëÁ˶ñÒâ´úÂë¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬ £¬£¬£¬AURÍŶӻ¹É¾³ýÁËÆäËüÁ½¸ö¶ñÒâÈí¼þ°ü£¬£¬£¬ £¬£¬£¬µ«Ã»ÓÐ͸¶¸ü¶àϸ½Ú¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/arch-linux-aur-malware.html


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚ°µÍøÊг¡ÉϵÄRDPÊÐËÁµÄÆÊÎö±¨¸æ


McAfeeÑо¿ÍŶÓÐû²¼¹ØÓÚ°µÍøÉϳöÊÛRDPЧÀ͵ÄÊÐËÁµÄÑо¿±¨¸æ¡£¡£¡£ÔÚÕâЩÊÐËÁÖУ¬£¬£¬ £¬£¬£¬ÓëÖ÷Òª¹ú¼Ê»ú³¡µÄÇå¾²ºÍÂ¥Óî×Ô¶¯»¯ÏµÍ³Ïà¹ØµÄ»á¼ûÖ»Ðè񻮮·Ñ10ÃÀÔª¡£¡£¡£ÕâЩÊÐËÁµÄ¹æÄ£´Ó15¸öRDPÅþÁ¬µ½Áè¼Ý4Íò¸öRDPÅþÁ¬¡£¡£¡£ÍøÂç·¸·¨·Ö×Ó¹ºÖÃRDPЧÀͺó¿ÉÒÔÓÃÓÚ·¢ËÍÀ¬»øÓʼþ¡¢»ñÈ¡Óû§Æ¾Ö¤¡¢ÍÚ¿ó¡¢·Ö·¢ÀÕË÷Èí¼þÒÔ¼°¿´³É¹¥»÷Ìø°åµÈ¡£¡£¡£³öÊÛµÄRDPÅþÁ¬ÉõÖÁ°üÀ¨ÓëÕþ¸®ÏµÍ³¡¢Ò½ÁƱ£½¡»ú¹¹Ïà¹ØµÄÅþÁ¬¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/organizations-leave-backdoors-open-to-cheap-remote-desktop-protocol-attacks/


¡¾¹¥»÷ÊÂÎñ¡¿ÃÀ¾üÎÞÈË»úÎļþÔâÇÔ£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÒÔ150ÃÀÔªµÄ¼ÛÇ®ÍøÉϳöÊÛ


Recorded Future·¢Ã÷ºÚ¿ÍÔÚÍøÉÏÂÛ̳ÒÔ150ÃÀÔª-200ÃÀÔªµÄµÍÁ®¼ÛÇ®³öÊÛÃô¸ÐµÄ¾üÊÂÎļþ£¬£¬£¬ £¬£¬£¬ÕâЩÎļþ°üÀ¨ÃÀ¾üMQ-9 ReaperÎÞÈË»úµÄάÐÞÊֲᡢ¹ØÓÚdzÒ×±¬Õ¨×°Öã¨IED£©°²Åż¼ÇɵÄÅàѵÊֲᡢM1 ABRAMS̹¿Ë²Ù×÷Ö¸ÄÏ¡¢¼ÝʻԱѵÁ·ºÍÉúÑÄÊÖ²áÒÔ¼°Ì¹¿ËÕ½ÊõÊÖ²áµÈ¡£¡£¡£¾Ý³ÆÕâЩÎļþй¶µÄÔµ¹ÊÔ­ÓÉÊÇһЩ¾üÊÂÉèÊ©ÖеÄ·ÓÉÆ÷ʹÓÃÁËĬÈϵÄFTPÃÜÂë¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-steals-military-docs-because-someone-didn-t-change-a-default-ftp-password/

 

¡¾¹¥»÷ÊÂÎñ¡¿Chrome²å¼þHola VPNÔ⺧£¬£¬£¬ £¬£¬£¬Ô­²å¼þ±»Ö²Èë¶ñÒâ´úÂë


Chrome²å¼þHola VPNµÄ¿ª·¢ÕßÕË»§ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬Æä²å¼þ±»Ö²Èë¶ñÒâ´úÂ룬£¬£¬ £¬£¬£¬ÓÃÓÚ½«MyEtherWallet.comÍøÕ¾µÄÓû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾¡£¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚ7ÔÂ9ÈÕ£¬£¬£¬ £¬£¬£¬¹²Ò»Á¬ÁË5¸öСʱ£¬£¬£¬ £¬£¬£¬ÏÖÔڸòå¼þÒѻָ´ÖÁÇå½àµÄ°æ±¾¡£¡£¡£Hola VPNÍŶÓûÓÐ͸¶¹¥»÷ÕßÔõÑù½øÈëÆäChrome¿ª·¢ÕßÕË»§¡£¡£¡£MEWÍŶÓÕýÔÚ´ß´ÙʹÓô˲å¼þµÄÓû§½«Æä¼ÓÃÜÇ®±Ò×ªÒÆÖÁеÄÕË»§£¬£¬£¬ £¬£¬£¬ÒÔÈ·±£Çå¾²¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-breaches-hola-vpn-chrome-extension-to-go-after-cryptocurrency-wallet-site/