¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180725
Ðû²¼Ê±¼ä 2018-07-25¡¾ÆÊÎö±¨¸æ¡¿Ñо¿»ú¹¹Ðû²¼2018ÄêQ2 DDoS¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ
ÔÎÄÁ´½Ó£ºhttps://securelist.com/ddos-report-in-q2-2018/86537/
¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±·¢Ã÷ÐÂÀ¶ÑÀÎó²î£¨CVE-2018-5383£©£¬£¬£¬£¬Apple¡¢IntelµÈ¾ùÊÜÓ°Ïì
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/bluetooth-hack-vulnerability.html
¡¾Îó²î²¹¶¡¡¿Apache TomcatÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/apache-tomcat-server.html
¡¾Îó²î²¹¶¡¡¿AVEVAÐÞ¸´ÆäInTouchºÍInduSoft¹¤¾ßÖеÄ2¸öRCEÎó²î
Ó¢¹ú¹¤ÒµÈí¼þ¹«Ë¾AVEVAÐÞ¸´ÁËÆäInTouchºÍInduSoft¿ª·¢¹¤¾ßÖеÄ2¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÇå¾²Îó²î¡£¡£¡£¡£½ñÄêÔçЩʱ¼äAVEVAÓëÊ©ÄÍµÂµçÆøºÏ²¢£¬£¬£¬£¬²¢½ÓÊÜÁËAvantisºÍWonderwareÆ·ÅÆ¡£¡£¡£¡£CyberXÑо¿Ö°Ô±George Lashenko·¢Ã÷ijЩ°æ±¾µÄInTouch±£´æ»º³åÇøÒç³öÎó²î£¨CVE-2018-10628£©£¬£¬£¬£¬TenableµÄÑо¿Ö°Ô±·¢Ã÷ÁËÁíÒ»¸öÎó²î£¨CVE-2018-10620£©¡£¡£¡£¡£ÕâЩÎó²î¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£7ÔÂ13ÈÕAVEVAÔÚHotfix 81.1.00.08ÖÐÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/aveva-patches-critical-flaws-hmiscada-tools-following-schneider-merger
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔOracle WebLogicЧÀÍÆ÷µÄй¥»÷»î¶¯
Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶ÔOracle WebLogicЧÀÍÆ÷µÄ¹¥»÷»î¶¯£¬£¬£¬£¬ÕâЩ¹¥»÷»î¶¯Ö÷ҪʹÓÃÎó²î£¨CVE-2018-2893£©¾ÙÐй¥»÷¡£¡£¡£¡£OracleÔÚ7ÔÂ18ÈÕÐû²¼Á˸ÃÎó²îµÄÏà¹Ø²¹¶¡£¬£¬£¬£¬7ÔÂ21ÈÕÆäÏà¹ØPoC±»Åû¶¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÖÁÉÙ2¸ö×éÖ¯ÕýÔÚʹÓøÃÎó²î¾ÙÐй¥»÷£¬£¬£¬£¬½¨Ò黹δ¸üеÄÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£¡£¡£Ò×Êܹ¥»÷µÄ°æ±¾°üÀ¨10.3.6.0¡¢12.1.3.0¡¢12.2.1.2ºÍ12.2.1.3¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/attacks-on-oracle-weblogic-servers-detected-after-publication-of-poc-code/
¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷CPUÎó²îÓÄÁéµÄбäÖÖSpectreRSB
À´×ÔUCRµÄÑо¿Ö°Ô±·¢Ã÷CPUÎó²îÓÄÁéµÄбäÖÖSpectreRSB¡£¡£¡£¡£SpectreRSBͬÑùʹÓÃÁËCPUÍÆ²âÖ´ÐеÄÀú³Ì£¬£¬£¬£¬ÓëÆäËû±äÖÖ²î±ðµÄÊÇ£¬£¬£¬£¬¸Ã¹¥»÷Ö÷ÒªÕë¶ÔCPU×é¼þRSB¡£¡£¡£¡£Ñо¿Ö°Ô±Ö»²âÊÔÁËIntel CPUÉϵÄSpectreRSBÎó²î£¬£¬£¬£¬µ«ÓÉÓÚAMDºÍARM´¦Öóͷ£Æ÷ҲʹÓÃRSBÀ´Õ¹Íû·µ»ØµØµã£¬£¬£¬£¬Òò´ËËüÃǺÜÓпÉÄÜÒ²ÊÜÓ°Ïì¡£¡£¡£¡£SpectreRSB¹¥»÷¿ÉÒÔÈÆ¹ýÏÖÔÚËùÓеÄÐÞ¸´²¹¶¡¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/researchers-detail-new-cpu-side-channel-attack-named-spectrersb/