΢Èí½¨¸´79¸ö·ì϶£¬Ô̺¬RDPÖеÄRCE·ì϶£¨CVE-2019-0708£©£»ÓÅÒ¿âÔ¼50ÍòÕË»§ÐÅϢй¶
°ä²¼¹¦·ò 2019-05-15
Öܶþ΢Èí°ä²¼5ÔÂWindows°²È«¸üУ¬½¨¸´79¸ö·ì϶¡£ÆäÖÐÔ̺¬RDP·þÎñÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0708£©£¬´Ë·ì϶ÊÇÔ¤Éí·ÝÑéÖ¤£¬ÎÞÐèÓû§½»»¥£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룻ÌáȨ0day£¨CVE-2019-0863£©£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁÖÎÀíԱȨÏÞ£»Õë¶ÔIntel CPU MDS¹¥»÷µÄ·ì϶½¨¸´£¬ÕâЩ·ì϶ӰÏìÁË2011ÄêÒÔÀ´ÏÕЩËùÓеÄIntel CPU¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/
2¡¢ºÚ¿ÍÀûÓÃWhatsapp 0day·Ö·¢¼äµýÈí¼þPegasus
Facebook½¨¸´ÁËWhatsAppÖеÄÒ»¸ö0day£¨CVE-2019-3568£©¡£Æ¾¾ÝFacebook°ä²¼µÄ°²È«²¼¸æ£¬¸Ã·ì϶ÊÇWhatsApp VOIP²Ö¿âÖеĻº³åÇøÒç¶Âí½Å£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËͶñÒâSRTCPÊý¾Ý°üÔÚÖ¸±êÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶ÒÑÔÚÒ°±í±»ÀûÓ㬹¥»÷ÕßÀûÓø÷ì϶ÔÚÖ¸±êÓû§µÄÊÖ»úÉÏ×°ÖÃÒÔÉ«ÁÐNSO¹«Ë¾µÄ¼äµýÈí¼þPegasus¡£Æ¾¾ÝÓйػ㱨£¬ÉÏÖÜÈÕһλӢ¹úÈËȨÂÉʦ¾ÍÔâµ½ÀûÓô˷ì϶µÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/hack-whatsapp-vulnerability.html
3¡¢Apple°ä²¼5Ô°²È«¸üУ¬½¨¸´¶à¸ö°²È«·ì϶
Apple°ä²¼5Ô°²È«¸üУ¬¶Ô¸÷¸ö²úƷϵͳ½øÐÐÁËÉý¼¶£¬Ô̺¬iOS 12.3¡¢tvOS 12.3¡¢watchOS 5.2.1¡¢macOS 10.14.5ºÍHomePod OS 12.3¡£½¨¸´µÄ·ì϶Ô̺¬macOS DesktopSevicesÖеÄGatekeeper²é³Èƹý·ì϶£¨CVE-2019-8589£©¡¢EFIÉí·ÝÑéÖ¤·ì϶£¨CVE-2019-8634£©¡¢iOSÖеÄDoS·ì϶£¨CVE-2019-8626£©¡¢É³ÏäÈÆ¹ý·ì϶£¨CVE-2019-8617£©¡¢Wi-Fi·ì϶£¨CVE-2019-8620£©µÈ¡£
ÔÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/05/14/apple-may-2019-security-updates-fix-numerous-issues/
4¡¢ÓÅÒ¿âµçÉÌÍøÕ¾ÔâºÚ¿Í¹¥»÷£¬Ô¼50ÍòÕË»§ÐÅÏ¢±»Ð¹Â¶
¾ÝÅí²©ÉçÐÂÎÅ£¬ÈÕ±¾ÁãÊÛÉÌFast Retailing°µÊ¾ÆìÏÂÓÅÒ¿âºÍGUÆ·ÅÆµÄÈÕ±¾¹ÙÍøÔâºÚ¿Í¹¥»÷£¬ºÚ¿Íͨ¹ýײ¿â¹¥»÷½Ó¼ûÁË461091¸ö¿Í»§ÕË»§¡£Õâ´Î¹¥»÷²úÉúÔÚ4ÔÂ23ÈÕÖÁ5ÔÂ10ÈÕÆÚ¼ä£¬ÓÉÓÚµ÷²éÉÐδʵÏÖ£¬ÊÜÓ°ÏìµÄÕË»§Êý×Ö¿ÉÄܸü¸ß¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢²É°ì¼Í¼ÒÔ¼°²¿ÃÅÐÅÓþ¿¨ÐÅÏ¢µÈ¡£5ÔÂ13ÈÕFast Retailing½ûÓÃÁËÊÜÓ°ÏìµÄ¿Í»§ÕË»§ÃÜÂ룬²¢ÏòÕâЩ¿Í»§·¢ËÍÁËÃÜÂë³ÁÖÃÓʼþ¡£Õâ´ÎÊÂÎñ²¢Î´Éæ¼°ÖйúµÄÍøÕ¾¼°ÐÅϢƽ̨¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-access-over-461-000-accounts-in-uniqlo-data-breach/
5¡¢Paterson¹«Á¢Ñ§ÌÃÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý2.3ÍòÕË»§Í´´¦±»µÁ
Paterson¹«Á¢Ñ§ÌÃÔâºÚ¿ÍÈëÇÖ£¬23103¸öÕË»§µÄÍ´´¦±»µÁ¡£ÕâЩʹ´¦Ô̺¬×ÀÃæµçÄԵĵǼÕË»§¡¢ÓÊÏäÕË»§ÒÔ¼°±Ê¼Ç±¾µçÄÔÕË»§µÄµÇ¼ʹ´¦£¬ÊÜÓ°ÏìµÄÓû§Ô̺¬Ñ§ÇøµÄÔ±¹¤¡¢ÖÎÀíÔ±¡¢ÀÏʦµÈ¹¤×÷ÈËÔ±¡£±»µÁµÄÍ´´¦´æ´¢ÔÚÒ»¸ö³¬¹ý116000ÐеÄÎļþÖУ¬ÆäÖÐÓû§ÃûÊÇÒÔ´¿Îı¾µÄ´ó¾Ö´æ´¢µÄ£¬¶øÃÜÂëÊÇÒÔÃÜÎÄ´ó¾Ö´æ´¢£¬µ«ºÜÈÝÒ×±»ÆÆ½â¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþÁªÏµÁËýÌåÅÁÌØÉʱ±¨£¬³ÆÕâЩÐÅÏ¢ÊÇÔÚ2018Äê10Ô±»µÁ£¬²¢ÌáÒ齫ÕâЩÊý¾ÝÏúÊÛ¸ø¸ÃýÌ壬µ«Ôâµ½Á˻ؾø¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/paterson-public-schools-suffered-data-breach-compromising-over-23000-school-district-passwords-ac1bf681
6¡¢Linksys WiFi·ÓÉÆ÷ÐÅϢй¶·ì϶£¬²¨¼°È«Çò2.5Íǫ̀É豸
Bad Packets°²È«×êÑÐÔ±Troy Mursch·¢ÏÖÈ«ÇòÓг¬¹ý2.5Íǫ̀LinksysÖÇÄÜWi-Fi·ÓÉÆ÷Êܵ½Ò»¸öÐÅϢй¶·ì϶µÄÓ°Ïì¡£¸Ã·ì϶ÀàËÆÓÚ2014ÄêµÄ·ì϶£¨CVE-2014-8244£©£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»ñÈ¡´óÁ¿É豸Ãô¸ÐÐÅÏ¢£¬Ô̺¬ÒÑÏνÓÉ豸µÄMACµØÖ·¡¢É豸Ãû³Æ¡¢²Ù×÷ϵͳ¡¢·À»ðǽ״̬¡¢WAN/DDNSÅäÖõȡ£¹ÌÈ»¸Ã·ì϶Àíµ±ÓÚÎåÄêǰ±»½¨¸´£¬µ«µ±Ç°·ì϶ÒÀÈ»´æÔÚ£¬²¢ÇÒ±»Linksys°²È«ÍŶÓÏóÕ÷Ϊ¡°²»ºÏÓÃ/²»½¨¸´¡±¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/linksys-smart-wi-fi-routers-leak-info-of-connected-devices/


¾©¹«Íø°²±¸11010802024551ºÅ