΢Èí°ä²¼Î¢Âë¸üУ¬½¨¸´Intel CPUÖвàÐÅ··ì϶£»¹È¸è°ä²¼Chrome²¹¶¡£¬½¨¸´Á½¸ö±»ÔÚÒ°ÀûÓõÄ0day
°ä²¼¹¦·ò 2020-11-12
΢ÈíÒÑÕë¶ÔWindows 10 20H2¡¢2004¡¢1909°ä²¼ÁËIntel΢´úÂë¸üУ¬ÒÔ½¨¸´Intel CPUÖеIJàÐÅ··ì϶Platypus¡£¸Ã·ì϶ÓɸñÀ´Ä¼¼Êõ´óѧ¡¢CISPAº¥Ä·»ô×ÈÐÅÏ¢°²È«ÖÐÐĺͲ®Ã÷º²´óѧµÄ×é³ÉµÄ×êÑÐÍŶÓÅû¶£¬Î»ÓÚÓ¢ÌØ¶ûµÄÔËÐоùÔȹ¦ÂÊÏÞ¶È£¨RAPL£©½çÃæÖС£×êÑÐÈËÔ±Åú×¢£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃRAPL½Ó¿Ú¼à¶½¹¦ºÄ²¢´§¶ÈCPUÔÚÖ´ÐÐÄÄЩָÁ´Ó¶ø´ÓÄÚ´æÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý¡£´Ë±íÕâ´Î¸üл¹½¨¸´ÁËʸÁ¿¼Ä·ÅÆ÷²ÉÑù»î¶¯Öзì϶£¨CVE-2020-8696£©ºÍ¼±¾ç´æ´¢Ç°Õ°Ô¤²âÆ÷Öзì϶£¨CVE-2020-8698£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-intel-microcode-released-to-fix-new-cpu-security-bugs/
2.¹È¸è°ä²¼Chrome²¹¶¡£¬½¨¸´Á½¸ö±»ÔÚÒ°ÀûÓõÄ0day

¹È¸è°ä²¼Chrome°æ±¾86.0.4240.198£¬½¨¸´Á½¸ö±»ÔÚÒ°ÀûÓõÄ0day¡£Õâ´Î½¨¸´µÄ·ì϶±ðÀëΪV8Öв»Êʵ±µÄʵÏÖ·ì϶£¨CVE-2020-16013£©ºÍSite IsolationÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-16017£©£¬Ä¿Ç°Éв»Ã÷ÏÔÕâÁ½¸ö·ì϶ÊDZØÒª×÷Ϊ·ì϶ÀûÓÃÁ´µÄÒ»²¿ÃÅһ·ʹÓû¹Êǵ¥¶ÀʹÓá£ÕâÁ½¸ö·ì϶ÊÇ´ÓǰÈýÖÜÄÚGoogleÔÚChromeÖн¨¸´µÄµÚËĺ͵ÚÎå¸ö0day£¬Ö®Ç°»¹ÓÐFreeType×ÖÌåäÖȾ¿âÖзì϶£¨CVE-2020-15999£©¡¢V8 JavaScriptÒýÇæÖзì϶£¨CVE-2020-16009£©ºÍUI×é¼þÖзì϶£¨CVE-2020-16010£©¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-patches-two-more-chrome-zero-days/
3.×êÑÐÈËÔ±·¢ÏÖGNOMEÏÔʾÖÎÀíÆ÷´æÔÚ±¾µØÌáȨ·ì϶

×êÑÐÈËÔ±·¢ÏÖGNOMEÏÔʾÖÎÀíÆ÷£¨gdm£©´æÔÚÒ×ÓÚÀûÓõı¾µØÌáȨ·ì϶¡£GitHubµÄ°²È«×êÑÐÔ±Kevin BackhouseÔÚÓÃÀ´¸ú×ÙϵͳÉÏ¿ÉÓÃÓû§µÄ×é¼þAccountsServiceÖз¢ÏÖÁË Á½¸ö·ì϶£¬¿Éµ¼Ö¸Ã×é¼þ¹ÒÆð£¨CVE-2020-16127£©ºÍÉÕ»ÙÓû§ÕÊ»§ÌØÈ¨£¨CVE-2020-16126£©£¬¿Éͨ¹ýÏòÆä·¢ËÍÑÓ³¤µÄ·Ö¶ÎÃýÎóÐźÅÀ´Ê¹ÊØ»¤·¨Ê½±ÀÀ£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶´´½¨ÓµÓиü¸ßȨÏÞµÄÕÊ»§£¬²¢ÒÔÖÎÀíԱȨÏÞ£¨root£©ÔËÐдúÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ubuntus-gnome-desktop-could-be-tricked-into-giving-root-access/
4.ºÚ¿ÍÓÃFacebookÁ´½ÓÔ¤ÀÀÖ°ÄÜÈÆ¹ýºÚÃûµ¥À´×¥È¡Êý¾Ý

ºÚ¿ÍÀûÓÃFacebookÁ´½ÓÔ¤ÀÀÖ°ÄÜ£¬²¢Ê¹ÓÃFacebook API·þÎñÆ÷×÷Ϊ´úÀíÒÔÔ¤·À±»ÁÐÈëºÚÃûµ¥£¬À´´Ó»¥ÁªÍøÉÏץȡÊý¾Ý¡£¸Ã¼¼ÊõÖ®ËùÒԳɹ¦£¬ÊÇÓÉÓÚ´óÎÞÊýÍøÕ¾ÔËÓªÉ̶¼ÔÊÐíFacebook·þÎñÆ÷ץȡÆäÕ¾µãµÄÊý¾Ý£¬ÓÉÓÚÕâЩ±»ÍøÂçµÄÊý¾Ýͨ³£»á±»ÓÃÓںϷ¨Ö÷ÕÅ¡£´Ë±í£¬°²È«¹«Ë¾DataDome·¢ÏÖºÚ¿Í×éÖ¯¿ÉÀûÓøÃÖ°ÄÜÒÔÿÓ×ʱ10000¸öURLµÄ¿ìÂʼìË÷Á´½ÓÔ¤ÀÀ¡£Ä¿Ç°FacebookÒѾ¸ÄÉÆÁËMessengerÔ¤ÀÀAPIµÄ¿ìÂÊÏÞ¶È¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/facebook-link-preview-feature-used-as-a-proxy-in-website-scraping-scheme/
5.ºÚ¿ÍÔÚ°µÍøÏúÊÛ580ÍòÌõRedDoorz¾Æµê¿Í»§µÄ¼Í¼

ºÚ¿ÍÔÚ°µÍøÏúÊÛ580ÍòÌõRedDoorz¾Æµê¿Í»§µÄ¼Í¼¡£RedDoorzÊÇÐÂ¼ÓÆÂµÄ¾ÆµêÖÎÀíºÍԤԼƽ̨£¬ÔÚÕû¸ö¶«ÄÏÑÇÕ¼ÓÐ1000¶à¼Ò¾Æµê¡£ºÚ¿Í±¾ÖÜÆðÍ·ÔÚ°µÍøÏúÊÛÔ̺¬580ÍòRedDoorzÓû§¼Í¼µÄÊý¾Ý¿â£¬ÆäÖÐÔ̺¬Óû§µÄµç×ÓÓʼþ¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢ÐÔ±ð¡¢Ó×ÎÒ×ÊÁÏÕÕÆ¬µÄÁ´½Ó¡¢µç»°ºÅÂë¡¢¸¨Öúµç»°ºÅÂë¡¢µ®ÉúÈÕÆÚºÍÖ°Òµ£¬µ«Ëü²»Ô̺¬ÈκβÆÕþÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/58-million-reddoorz-user-records-for-sale-on-hacking-forum/
6.Zscaler°ä²¼2020Äê¼ÓÃܹ¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨

Zscaler°ä²¼ÁË2020Äê¼ÓÃܹ¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨£¬½ÒʾÁË»ùÓÚ¼ÓÃܵÄÍþв½«Ôö³¤260£¥¡£´Ë±í£¬¸Ã×êÑл¹·¢ÏÖCOVID-19ÍÆ¶¯ÁËÀÕË÷Èí¼þ¹¥»÷µÄ¼¤Ôö£¬´Ó3ÔÂÆðÍ·ÀÕË÷Èí¼þ¶Ô¼ÓÃÜÁ÷Á¿µÄ¹¥»÷Ôö³¤ÁË5±¶£¬ÓëCOVIDÓйصÄÍþв¼¤ÔöÁË30000£¥£»´¹µö¹¥»÷´ÎÊý¸ß´ï1.93ÒڴΣ¬ÖØÒªÕë¶ÔÔì×÷Òµ£¨38.6£¥£©¡¢·þÎñÒµ£¨13.8£¥£©ºÍÒ½ÁƱ£½¡£¨Õ¼10.9£¥£©£»ºÚ¿ÍÔÚÈÆ¹ý¼ì²â·½ÃæµÄ¼¼Êõ¸üΪ¸´ÔÓ£¬30£¥µÄ»ùÓÚSSLµÄ¹¥»÷ºýŪÁËÊÜÐÅÀµµÄÔÆÌṩÉÌ¡£
ÔÎÄÁ´½Ó£º
https://www.zscaler.com/press/new-research-shows-attackers-turning-encrypted-attacks-during-pandemic


¾©¹«Íø°²±¸11010802024551ºÅ