¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180703
°ä²¼¹¦·ò 2018-07-03¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖÀûÓÃPROPagate´úÂë×¢Èë¼¼ÊõµÄ¶ñÒâ¹¥»÷»î¶¯
PROPagate´úÂë×¢Èë¼¼Êõ×îÔçÓÚ2017Äê11ÔÂÓÉHexacorn°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×êÑÐÈËÔ±Ö¤Ã÷ËüÄܹ»ÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõĺϷ¨GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÀûÓ÷¨Ê½ÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬£¬£¬£¬£¬FireEyeµÄר¼Ò·¢ÏÖÁËÒ»¸öÀûÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢Èë¼¼Êõ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±³ÆÐµÄDiameterµç»°ºÍ̸ÓëSS7Ò»ÑùÒ×Êܹ¥»÷
°²È«×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä³ß¶Èһ·ʹÓõÄDiameterºÍ̸ÈÝÒ×Êܵ½Óë¾ÉµÄµç»°³ß¶È£¨Èç3G£¬£¬£¬£¬£¬£¬£¬£¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7³ß¶ÈÒ»ÑùÀàÐ͵ķì϶µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬SS7ÊÇÔÚ20ÊÀ¼Í70Äê´ú¿ª·¢µÄ£¬£¬£¬£¬£¬£¬£¬£¬½«½ü¶þÊ®ÄêÖ¤Ã÷Æä´æÔÚ²»°²È«³É·Ö¡£¡£¡£¡£¡£¡£ÕýÓÉÓÚÈç´Ë£¬£¬£¬£¬£¬£¬£¬£¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂçÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬SS7±»DiameterºÍ̸ËùÈ¡´ú£¬£¬£¬£¬£¬£¬£¬£¬DiameterºÍ̸ÊÇÒ»ÖָĽøµÄÍø¼äºÍÍøÄÚÐÅÁîºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬Ò²½«ÓÃÓÚ¼´½«ÍƳöµÄ5G³ß¶È¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/
¡¾°²È«²¥±¨¡¿ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©ÉÏÖܰ䷢½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼
ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©ÉÏÖܰ䷢£¬£¬£¬£¬£¬£¬£¬£¬ËüÔÚ´óÁ¿É¾³ýÊýÒÚÌõ¿É×·Òäµ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£¡£¡£¡£¡£¡£Ô×ÓÄÜ»ú¹¹°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÃÀ¹ú¹ú¶È°²È«¾Ö·ÖÎöÈËÔ±·¢ÏÖ¡°´ÓµçÕÛ·þÎñÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý´æÔÚ¼¼ÊõÎ¥¹æÐÐΪ¡±ºó£¬£¬£¬£¬£¬£¬£¬£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£¡£¡£¡£¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/
¡¾°²È«²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ½Ó¼ûȨÏÞ
FacebookÒѾÈϿɣ¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÀûÓÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ½ñÄê3Ô°䲼µÄCambridge Analytica³óÎÅÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬£¬Facebook°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ËüÒѾÔÚ2015Äê5ÔÂÖÕ³¡Á˵ÚÈý·½½Ó¼ûÆäÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£È»¶øÔÚ½üÆÚ°ä²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó³ÖÐøÓë61¼ÒÓ²¼þºÍÈí¼þÔì×÷ÉÌÒÔ¼°ÀûÓÿª·¢É̹²ÏíÊý¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html
¡¾°²È«²¥±¨¡¿ÈýÐDz¿ÃÅϵÁÐÊÖ»ú´æÔÚbug£¬£¬£¬£¬£¬£¬£¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË
×îа汾µÄÈýÐǶÌÐŶÌÐÅÀûÓ÷¨Ê½´æÔÚbug£¬£¬£¬£¬£¬£¬£¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬£¬£¬£¬£¬£¬£¬£¬ÈçS9¡¢S9 PlusºÍNote 8£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£¡£¡£¡£¡£¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬Óöµ½bugµÄÓû§Ëµ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃDz»ÖªÂ·ÊÖ»úÒѾ·¢ËÍÁËÕÕÆ¬£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£¡£¡£¡£¡£¡£Ö»Óе¹ØâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃDzŷ¢ÏÖ¡£¡£¡£¡£¡£¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÀûÓ÷¨Ê½Ö±µ½ÈýÐǽ¨¸´ÕâЩÎÊÌâ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/
¡¾·ì϶²¹¶¡¡¿VMware°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄ·ì϶
VMwareÉÏÖÜ֪ͨ¿Í»§£¬£¬£¬£¬£¬£¬£¬£¬Æä½¨²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬£¬£¬£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖгöÏֻؾø·þÎñ£¨DoS£©»òÐÅϢй¶µÄ·ì϶¡£¡£¡£¡£¡£¡£ÓµÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉÀûÓð²È«·ì϶»ñÊØÐÅÏ¢»òʹÐé¹¹»ú±ÀÀ£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»ÁÐΪ³ÁÒª£¬£¬£¬£¬£¬£¬£¬£¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£¡£¡£¡£¡£¡£Cisco TalosµÄ×êÑÐÈËÔ±·¢ÏÖÁËCVE-2018-6965¡£¡£¡£¡£¡£¡£¾ÝVMware³ÆÕâЩȱµã»áÓ°ÏìÔÚÖ°ºÎƽ̨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒѰ䲼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄ½¨²¹·¨Ê½ºÍ¸üС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion


¾©¹«Íø°²±¸11010802024551ºÅ