¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181115

°ä²¼¹¦·ò 2018-11-15
1¡¢×êÑÐÍŶÓÅû¶7ÖÖÐÂÈۻٺ͹í»ê¹¥»÷ £¬Intel¡¢AMDºÍARM¾ùÊÜÓ°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉ9Ãû×êÑÐÈËÔ±×é³ÉµÄ×êÑÐÓ××éÅû¶ÁË7ÖÖеÄÈۻٺ͹í»ê¹¥»÷ £¬ÆäÖÐ2ÖÖÊÇMeltdown¹¥»÷µÄ±äÖÖ £¬Áí±í5ÖÖÊÇSpectre¹¥»÷µÄ±äÖÖ ¡£Èý´óÖØÒª´¦ÖÃÆ÷³§ÉÌ-Intel¡¢AMDºÍARM¾ùÊÜÓ°Ïì ¡£¸Ã×êÑÐÓ××éÏòIntel¡¢AMDºÍARM»ã±¨ÁËÕâЩ·ì϶ £¬ÆäÖÐIntelºÍARMÒѾ­ÈÏ¿ÉÁËËûÃǵÄ×êÑÐÁ˾Ö ¡£¸ÃÍŶӻ¹°µÊ¾ £¬ÓÉÓÚ¹©¸øÉÌÔÚÖÂÁ¦½¨¸´ÕâЩÎÊÌâ £¬ËûÃǾö¶¨Ôݲ»Åû¶ÓйØPoC ¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/meltdown-spectre-vulnerabilities.html


2¡¢FacebookÔÙÆØÐ·ì϶ £¬»ò¿Éµ¼ÖÂÓû§¸öÈËÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Imperva×êÑÐÔ±Ron Masas·¢ÏÖFacebookÖеÄÒ»¸öзì϶ £¬»ò¿Éµ¼ÖÂÓû§¼°Æä°éµĸöÈËÐÅϢй¶ ¡£¸Ã·ì϶ÓëFacebookËÑË÷Ö°ÄܵÄÁ˾ÖÏÔʾÓйØ £¬Æ¾¾ÝMasasµÄ˵·¨ £¬ÏÔʾÓû§ËÑË÷Á˾ֵÄÒ³ÃæÔ̺¬ÓëÿһÌõËÑË÷Á˾ÖÓйØÁªµÄiFrameÔªËØ £¬¶øÕâЩiFrameÔªËØµÄ¹ØÁªURLÒ×ÊÜCSRF¹¥»÷ ¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ǿÆÅ×û§Ö´ÐÐËÁÒâËÑË÷²éÎÊ £¬²¢»ñµÃ·µ»ØµÄÓû§ÐÅÏ¢ ¡£FacebookÒѾ­½¨¸´Á˸÷ì϶ ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/facebook-vulnerability-hack.html


3¡¢°²È«³§Ḛ́䲼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Forcepoint°ä²¼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨ £¬»ã±¨µÄÖ÷ÌâÔ̺¬£ºÍøÂ簲ȫÖеÄAIÊÇ·ñÒÑÖÁ¶¬Ì죿´ó¹æÄ£µÄ¹¤ÒµÎïÁªÍøÖжÏÍþв£»ÉúÎï¼ø±ð¼¼ÊõÖеĴ¹µöÍþв£»¹ØÓÚ¹¤×÷³¡Ëù°²È«´ëÊ©¼à²âµÄ˾·¨Âɹ棿ҵÎñÕ½Óë¹ú¶ÈÖ§³ÖµÄ¹¤Òµ¼äµý»î¶¯£»±ßÔµÍÆËãµÄÔ¶¾°Óë¹ÊÕÏ£»¶ÔºÏ×÷ͬ°éµÄ°²È«ÐÅÀµÆÀ¼¶»ò½«Ô½À´Ô½³ÁÒª ¡£ÆëÈ«»ã±¨Çë²Î¿¼ÒÔÏÂÁ´½Ó ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.forcepoint.com/blog/insights/2019-forcepoint-cybersecurity-predictions-report


4¡¢ÔÚÏßÉ̵êInfowarsÔâMagecart¹¥»÷ £¬Ô¼1600ÃûÓû§ÒÉÊÜÓ°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÉÀ¼°²È«×êÑÐÔ±Willem de Groot·¢´Ë¿ÌÏßÉ̵êInfowarsϰȾÁËÓÃÓÚÇÔÈ¡Óû§ÐÅÓþ¿¨ÐÅÏ¢µÄ¶ñÒâ¾ç±¾Magecart ¡£¸Ã¶ñÒâ¾ç±¾ÔÚInfowarsÉÏ´æÔÚÁËԼĪ24¸öÓ×ʱ £¬Ëæºó¾Í±»Infowarsɾ³ý £¬Ô¼1600ÃûÓû§¿ÉÄÜÊܵ½Ó°Ïì ¡£×êÑÐÈËÔ±³ÆÕâЩMagecart´úÂë°µ²ØÔÚGoogle Analytics´úÂë¿éÖÐ £¬½öÔÚÓû§½áÕËʱ¼¤»î £¬Ã¿¸ô1.5Ãëץȡһ´Î½áÕË±íµ¥ÖеÄ×Ö¶ÎÄÚÈÝ £¬²¢·¢ËÍÖÁλÓÚÁ¢ÌÕÍðµÄÔ¶³Ì·þÎñÆ÷google-analyitics[.]org ¡£×êÑÐÈËÔ±»¹³ÆÕâЩ¶ñÒâ´úÂëµÄ·ç¸ñÓëRiskIQºÍFlashpointµÄMagecart¹¥»÷»ã±¨ÖÐÌá¼°µÄ7¸ö·¸×ïÍŻﶼ²»Ò»Ñù ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/card-skimming-malware-removed-from-infowars-online-store/


5¡¢Adobe°ä²¼11Ô°²È«¸üР£¬½¨¸´Flash PlayerµÈ²úÆ·ÖеÄ3¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Adobe°ä²¼2018Äê11ÔµÄÔ¶Ȱ²È«¸üР£¬±ðÀ뽨¸´ÁËAcrobat reader¡¢Flash Player¼°Photoshop CCÖеݲȫ·ì϶ ¡£ÆäÖÐAcrobat readerÖеķì϶£¨CVE-2018-15979£©¿Éµ¼ÖÂÓû§µÄNTLM¹þÏ£ÃÜÂëй¶ £¬²¢ÇҸ÷ì϶µÄPoC¹«¿ª¿ÉÓà ¡£Flash PlayerÖеķì϶£¨CVE-2018-15978£©ºÍPhotoshop CCÖеķì϶£¨CVE-2018-15980£©¶¼Êǿɵ¼ÖÂÐÅϢй¶µÄÔ½½ç¶Á·ì϶ ¡£½¨ÒéÓû§¾¡¿ì½øÐиüР¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-security-update-for-acrobat-vulnerability-with-public-poc/


6¡¢SAP°ä²¼11Ô°²È«¸üР£¬¹²½¨¸´11¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖܶþSAP°ä²¼ÁË2018Äê11Ô°²È«¸üР£¬½¨¸´Á˶à¿î²úÆ·ÖеÄ11¸ö·ì϶ ¡£·ì϶ÁìÓòÔ̺¬´úÂë×¢Èë¡¢XSS¡¢XXE¡¢SSRF¡¢»Ø¾ø·þÎñ¡¢¶ÌȱXMLÑéÖ¤ºÍURL³Á¶¨ÏòµÈ ¡£ÆäÖнÏÑϳÁµÄ·ì϶Ô̺¬SAP HANA Streaming AnalyticsµÄSpring¿ò¼Ü¿âÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-1270ºÍCVE-2018-1275£©ÒÔ¼°SAP Fiori¿Í»§¶ËÖеÄDoS·ì϶£¨CVE-2018-2488£©µÈ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/sap-patches-critical-vulnerability-hana-streaming-analytics


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù