×êÑÐÈËÔ±³Æ16¸öÀ¶ÑÀ·ì϶BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸:ºÚ¿ÍÏúÊÛ¿ÉÔÚ¶à¸öÆ·ÅÆµÄGPU

°ä²¼¹¦·ò 2021-09-03

×êÑÐÈËÔ±³Æ16¸öÀ¶ÑÀ·ì϶BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸


×êÑÐÈËÔ±³Æ16¸öÀ¶ÑÀ·ì϶BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸.jpg


×êÑÐÈËÔ±¼ì²âÁËÀ´×Ô11¸ö¹©¸øÉ̵Ä13¸öƬÉÏϵͳ (SoC) µÄÀ¶ÑÀÈí¼þ¿â£¬·¢ÏÖÁË16¸öÓ°ÏìÀ¶ÑÀÈí¼þ²Ö¿âµÄ·ì϶²¢Í³³ÆËüÃÇΪBrakTooth¡£¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ʹÉ豸±ÀÀ££¬ÉõÖÁÊÇÖ´ÐжñÒâ´úÂë²¢ÊÕÊÜÕû¸öϵͳ¡£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄΪCVE-2021-28139£¬ÀûÓø÷ì϶Զ³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÀ¶ÑÀLMPÊý¾Ý°üÔÚÖ¸±êÉ豸ÉÏÔËÐжñÒâ´úÂë¡£²¢·ÇËùÓÐËùÓй©¸øÉ̶¼ÊµÊ±°ä²¼Á˲¹¶¡£¬µ½Ä¿Ç°ÎªÖ¹£¬Ö»ÓÐÀÖöΡ¢Ó¢·ÉÁèºÍBluetrum°ä²¼Á˲¹¶¡£¬¶øµÂÖÝÒÇÆ÷Ôò°µÊ¾»Ø¾ø½¨¸´·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/billions-of-devices-impacted-by-new-braktooth-bluetooth-vulnerabilities/


Rapid7·¢ÏÖ¿ÉÔ¶³Ì½ûÓÃFortress WiFi°²ÕûϵͳµÄ·ì϶


Rapid7·¢ÏÖ¿ÉÔ¶³Ì½ûÓÃFortress WiFi°²ÕûϵͳµÄ·ì϶.jpg


Rapid7×êÑÐÈËÔ±ÓÚ8ÔÂ31ÈÕÅû¶ÁËFortress S03 WiFi¼ÒÍ¥°²ÕûϵͳÖеÄ2¸ö·ì϶µÄϸ½Ú¡£¸Ã°²Õûϵͳ¿ÉÒÔΪÓû§¹¹½¨×Ô¼ºµÄ¾¯±¨ÏµÍ³À´±£»¤Æä¼ÒÍ¥£¬ËüÖ§³Ö°²È«¼à¿Ø¡¢ÃÅ´°´«¸ÐÆ÷ÒÔ¼°ÑÌÎí¾¯±¨Æ÷µÈÉ豸¡£ÕâÁ½¸ö·ì϶±ðÀëΪCVE-2021-39276ºÍCVE-2021-39277£¬¹¥»÷ÕßÄܹ»ÏÈÀûÓÃǰÕß²éÎÊAPI²¢»ñȡָ±êÓû§µÄIMEIºÅÂ룬֮ºóÀûÓøúÅÂë¾ÍÄܹ»·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄPOSTÒªÇóÀ´¸ü¸ÄϵͳµÄÅäÖã¬Ô̺¬½ûÓøð²Õûϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121679/hacking/fortress-s03-home-security-system-flaws.html


MarketoÐû³ÆÒÑÇÔÈ¡ÈÕ±¾Í¨Ñ¶¹«Ë¾¸»Ê¿Í¨4GBµÄÊý¾Ý


MarketoÐû³ÆÒÑÇÔÈ¡ÈÕ±¾Í¨Ñ¶¹«Ë¾¸»Ê¿Í¨4GBµÄÊý¾Ý.jpg


MarketoÓÚ8ÔÂ26ÈÕÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䷢£¬ËüÔÚÏúÊÛ´ÓÈÕ±¾Í¨Ñ¶¹«Ë¾¸»Ê¿Í¨ÇÔÈ¡µÄ4GBµÄÊý¾Ý¡£¸ÃÍŻﻹ³ÆÕâЩÐÅÏ¢ÓëËûÃǵĿͻ§ÓйØ£¬Ô̺¬¿Í»§ÐÅÏ¢¡¢¹«Ë¾Êý¾Ý¡¢Ô¤ËãÊý¾Ý¡¢»ã±¨ºÍÏîÄ¿ÐÅÏ¢µÈ¡£¸»Ê¿Í¨½²»°È˰µÊ¾Éв»Ã÷ÏÔÕâЩÊý¾ÝµÄй¶Դ£¬¶øMarketo¹«¿ªµÄ24.5MBµÄÑù±¾Êý¾ÝÖУ¬Ô̺¬Á˲¿ÃÅÓëÁíÒ»¼ÒÈÕ±¾¹«Ë¾Toray IndustriesÓйصÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/data-from-fujitsu-is-being-sold-on-dark.html


ÒÁÀûŵÒÁÖÝÒ½ÔºDMG³ÆÆäÔ¼60Íò»¼ÕßµÄÐÅϢй¶


ÒÁÀûŵÒÁÖÝÒ½ÔºDMG³ÆÆäÔ¼60Íò»¼ÕßµÄÐÅϢй¶.jpg


ÒÁÀûŵÒÁÖÝ×î´óµÄ¶ÀÁ¢Ò½ÁÆ×éÖ¯DuPage Medical Group(DMG)ÓÚ±¾ÖÜÒ»°ä²¼Í¨Öª£¬³ÆÆä60Íò»¼ÕßµÄÐÅϢй¶¡£DMG°µÊ¾Õâ´Îй¶ÊÂÎñÓëÆäÔÚ7ÔÂ13ÈÕ²úÉúµÄÍøÂçÖжÏÓйØ£¬¾­µ÷²é¹¥»÷ÕßÔÚ7ÔÂ12ÈÕÖÁ13ÈÕ½Ó¼ûÁËDMGµÄÍøÂç¡£8ÔÂ17ÈÕ£¬¸Ã×é֯ȷ¶¨²¿ÃÅ»¼ÕßµÄÐÅÏ¢ÒѾ­Ð¹Â¶£¬²¢½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓþ¼à¿ØºÍÉí·ÝµÁÓñ£»¤¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/dupage-medical-data-breach/


ºÚ¿ÍÏúÊÛ¿ÉÔÚ¶à¸öÆ·ÅÆµÄGPUÉÏÖ´Ðеļ¼Êõ²¢°ä²¼PoC


ºÚ¿ÍÏúÊÛ¿ÉÔÚ¶à¸öÆ·ÅÆµÄGPUÉÏÖ´Ðеļ¼Êõ²¢°ä²¼PoC.jpg


¹¥»÷ÕßÀûÓöñÒâÈí¼þÄܹ»´ÓÊÜϰȾϵͳµÄͼÐδ¦Öõ¥Ôª(GPU)ÖÐÖ´ÐдúÂë¡£¹ÌÈ»¸Ã²½Öè²¢²»ÐÂÏÊ£¬µ«Æù½ñΪֹ´ËÀ๥»÷ҪôÀ´×ÔѧÊõ½ç£¬ÒªÃ´ÊÇδ¾­ÃÀÂúµÄ¡£¶ø½ñÄê8Ô£¬ÓкڿÍÔÚÂÛ̳ÖÐÏúÊÛÓйصÄPoC£¬Õâ±ê־ȡ´ËÀ๥»÷¿ÉÄÜÒѹý¶Éµ½Ðµĸ´ÔÓ¼¶±ð¡£Ä¿Ç°£¬Âô¼ÒÖ»ÌṩÁ˸ü¼ÊõµÄ¸ÅÊö£¬ËµËüʹÓÃGPUÄڴ滺³åÇøÀ´´æ´¢¶ñÒâ´úÂë²¢Ö´ÐУ¬²¢°µÊ¾¸Ã¼¼ÊõÓë2015Äê5Ô°䲼µÄ»ùÓÚGPUµÄ¶ñÒâÈí¼þJellyFish²¢²»Ò»Ñù¡£


Ô­ÎÄÁ´½Ó£º

bleepingcomputer.com/news/security/cybercriminal-sells-tool-to-hide-malware-in-amd-nvidia-gpus/


CISAºÍFBI½áºÏ°ä²¼ÓйؽڼÙÈÕÀÕË÷¹¥»÷»î¶¯µÄÔ¤¾¯


CISAºÍFBI½áºÏ°ä²¼ÓйؽڼÙÈÕÀÕË÷¹¥»÷»î¶¯µÄÔ¤¾¯.jpg


CISAºÍFBIÔÚ8ÔÂ31ÈÕ°ä²¼ÁËÒ»·Ý½áºÏ°²È«²¼¸æ£¬ÖÒ¸æÀÕË÷ÔËÓªÍÅ»ïÔÚÖÜÄ©ºÍ¹ú¶¨¼ÙÈÕ·¢Æð¹¥»÷µÄÇ÷Ïò¡£¸Ã»ú¹¹³Æ£¬ÔÚ½üÈýÄêÖÐÀÕË÷ÔËÓªÍÅ»ïÒ»ÏòÔÚ½Ú¼ÙÈÕ·¢Æð¹¥»÷£¬ÈçDarksideÔÚÖÜÁù¹¥»÷ÁËColonial Pipeline£¬ÒÔ¼°REvilÔÚÃÀ¹úÕóÍö½«Ê¿ÁôÏëÈÕ¹¥»÷ÁËJBS FoodsµÈ»î¶¯¡£Õâ¿ÉÄÜÓÉÓÚ·¸×ïÍÅ»ïÒâʶµ½£¬ÔÚIT°²È«ÍŶӷʤijÈËÊý½ÏÉÙʱ¹¥»÷¹«Ë¾µÄÍøÂç»á²»ÈÝÒ×±»·¢ÏÖ¡£FBIºÍCISA½¨ÒéIT°²È«ÈËÔ±ÔÚÕâЩ¹¦·òÄܹ»ËæÊ±´ýÃü¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/cisa-and-the-fbi-warn-of-ransomware-gangs-tendency-of-launching-attacks-over-holidays-and-weekends/