¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180724

°ä²¼¹¦·ò 2018-07-24

¡¾Êý¾Ýй¶¡¿³¬¹ý100¼ÒÆû³µ³§É̵ĻúÃÜÊý¾Ýй¶£¬£¬£¬ £¬£¬·áÌï¡¢ÌØË¹À­µÈ¾ùÊÜÓ°Ïì


UpGuard×êÑÐÈËÔ±Chris Vickery·¢ÏÖ¹©¸øÉÌLevel OneµÄ²»°²È«Êý¾Ý¿â£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬½ü47000·ÝÎļþ£¬£¬£¬ £¬£¬º­¸Ç¶à¼ÒÆû³µ³§É̵ĽüÊ®ÄêµÄ¾ßÌåÀ¶Í¼¡¢¹¤³§µÀÀíͼ¡¢¿Í»§×ÊÁÏ£¨ÈçºÏͬ¡¢·¢Æ±ºÍ¹¤×÷´òËãµÈ£©£¬£¬£¬ £¬£¬ÒÔ¼°¸÷Àà±£ÃܺÍ̸ÎļþµÈ¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÊý¾Ý×ÜÁ¿´ï157GB£¬£¬£¬ £¬£¬¸£ÌØ¡¢·áÌͨÓúÍÌØË¹À­µÈ¾ùÊÜÓ°Ïì¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÔ­ÒòÊÇLevel One¹«Ë¾µÄÓÃÓÚ±¸·ÝÊý¾ÝµÄÎļþ´«ÊäºÍ̸rsync±»ÅäÖÃΪ¿É¹«¿ª½Ó¼û£¬£¬£¬ £¬£¬²¢ÇÒ²»±ØÒªÈκÎÃÜÂë¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/robotics-suppliers-sloppy-security-leaks-ten-years-worth-of-data-from-major-car-manufacturers/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±·¢ÏÖAndroidÒøÐÐľÂíExobotµÄÔ´Âëй¶


×êÑÐÈËÔ±·¢ÏÖAndroidÒøÐÐľÂíExobotµÄÔ´´úÂëÒÑÓÚ5ÔÂй¶£¬£¬£¬ £¬£¬²¢ÇÒÔÚ¶ñÒâÈí¼þÉçÇøÖÐѸËÙ´«²¼¡£¡£¡£¡£ ¡£ExobotÓÚ2016Äêµ×±»³õ´Î·¢ÏÖ£¬£¬£¬ £¬£¬ÆäÖ°Äܼ«¶È׳´ó£¬£¬£¬ £¬£¬ÉõÖÁÄܹ»Ï°È¾×îеÄAndroid°æ±¾¡£¡£¡£¡£ ¡£2018Äê1Ô¸öñÒâÈí¼þµÄ×÷Õ߯ðÍ·ÏúÊÛÆäÔ´´úÂ룬£¬£¬ £¬£¬Õâͨ³£ÒâζןÃ×÷ÕßÒÑתÏòÆäËüµÄÆ÷²Ä¡£¡£¡£¡£ ¡£Ä¿Ç°Ð¹Â¶µÄ°æ±¾ÊÇExobot 2.5£¬£¬£¬ £¬£¬×êÑÐÈËÔ±¾¯Ê¾³ÆÕâ¿ÉÄܵ¼ÖÂÐÂÒ»²¨µÄ¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/source-code-for-exobot-android-banking-trojan-leaked-online/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖͨ¹ýAndroid ADB¶Ë¿Ú´«²¼µÄSatoriбäÌå


Ç÷Ïò¿Æ¼¼×êÑÐÍŶÓÔÚ7ÔÂ9ÈÕÖÁ10ÈÕºÍ7ÔÂ15ÈÕ¼ì²âµ½Õë¶Ô5555¶Ë¿ÚµÄ¹¥»÷»î¶¯µÄÁ½¸ö·åÖµ£¬£¬£¬ £¬£¬¸Ã¹¥»÷»î¶¯ÀûÓÃÊ¢¿ªµÄADB¶Ë¿ÚÔÚAndroidÉ豸Öд«²¼SatoriµÄÒ»¸öбäÌå¡£¡£¡£¡£ ¡£µÚÒ»²¨¹¥»÷µÄÁ÷Á¿ÖØÒªÀ´×ÔÓÚÃÀ¹úºÍÖйú£¬£¬£¬ £¬£¬¶øµÚ¶þ²¨Á÷Á¿ÖØÒªÀ´×Ôº«¹ú¡£¡£¡£¡£ ¡£AndroidÓû§Äܹ»Í¨¹ý¹Ø¹Ø¡°ADB£¨USB£©µ÷ÊÔ¡±ºÍ¡°ÔÊÐí×°ÖÃδ֪ÆðÔ´µÄÀûÓá¹ØâÁ½¸öÑ¡ÏîÀ´·À±¸ÕâÖÖ¹¥»÷¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/open-adb-ports-being-exploited-to-spread-possible-satori-variant-in-android-devices/


¡¾·ì϶²¹¶¡¡¿Î¢ÈíÔÚ7Ô°²È«¸üÐÂÖÐÔٴν¨¸´IEÁãÈÕ·ì϶£¨CVE-2018-8174£©


΢ÈíÔÚ5Ô½¨¸´ÁËIEÁãÈÕ·ì϶£¨CVE-2018-8174£©£¬£¬£¬ £¬£¬µ«×êÑÐÈËÔ±·ÖÎöÁ˽¨¸´²¹¶¡ºó·¢ÏÖÈÔ´æÔÚÁí±íÁ½¸ö¿Éµ¼ÖÂÔ­·ì϶µÄÎÊÌâ¡£¡£¡£¡£ ¡£ÕâÁ½¸öÎÊÌâ±»ÏóÕ÷Ϊ·ì϶£¨CVE-2018-8242£©£¬£¬£¬ £¬£¬Î¢ÈíÔÚ7Ô°²È«¸üÐÂÖа䲼Á˸÷ì϶µÄ½¨¸´²¹¶¡¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±»¹³ÆCVE-2018-8242µÄ½¨¸´²¹¶¡ÒýÈëÁËÒ»¸öÄÚ´æÐ¹Â¶µÄ»úÄÜÎÊÌ⣬£¬£¬ £¬£¬µ«Õâ¸öÎÊÌâ²¢²»ÊÇÒ»¸ö°²È«·ì϶¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/that-ie-zero-day-from-may-needed-a-second-patch-in-july/


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ¹Øë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öеĽ¨¸´´ëÊ©


À´×Ô¶àËù´óѧµÄ×êÑÐÈËÔ¹Øë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öÁËеĽ¨¸´´ëÊ©£¬£¬£¬ £¬£¬ÕâЩ´ëÊ©ÊÇÔÚÈí¼þ¼¶´ËÍ⽨¸´£¬£¬£¬ £¬£¬ÕâÒâζ×ÅCPUºÍRAM¹©¸øÉ̲»±ØÒªÅú¸ÄÆä²úÆ·£¬£¬£¬ £¬£¬²¢ÇÒÕâЩ´ëÊ©Äܹ»ÒÔÈí¼þ¸üеķ½Ê½°ä²¼¡£¡£¡£¡£ ¡£Õë¶ÔSpectre¡¡V1µÄ½¨¸´ÀûÓÃÁËLinuxÄں˲¹¶¡ELFbac£¬£¬£¬ £¬£¬¶øÕë¶ÔRowhammer¹¥»÷µÄ·À»¤´ëÊ©ÊÇͨ¹ýÒ»ÖÖм¼ÊõZebRAM¡£¡£¡£¡£ ¡£Ä¿Ç°×êÑÐÈËÔ±»¹Ã»ÓÐÅû¶¹ØÓÚÕâÏî¼¼ÊõµÄ¸ü¶à¾ßÌåÐÅÏ¢¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/academics-announce-new-protections-against-spectre-and-rowhammer-attacks/


¡¾Ë¾·¨Âɹ桿°£¼°ÐÂ˾·¨ÑÏ´ò¼ÙÐÂÎÅ£¬£¬£¬ £¬£¬·ÛË¿Êý³¬5000µÄ´«Ò¥Õß½«±»Öذì


7ÔÂ16ÈÕ°£¼°Òé»áͨ¹ýÒ»ÏîÐÂ˾·¨£¬£¬£¬ £¬£¬¸Ã˾·¨½«ÔÚFacebookºÍTwitterµÈÉ罻ýÌåÆ½Ì¨Õ¼Óг¬¹ý5000Ãû·ÛË¿µÄÕ˺źͲ©¿ÍÊÓΪýÌ壬£¬£¬ £¬£¬²¢ÔÊÐíµ±¾Ö·â½û°ä²¼¼ÙÐÂÎŵÄÕË»§ÒÔ¼°¶Ô°ä²¼ÈËÔ±½øÐд¦·£¡£¡£¡£¡£ ¡£ÐÂ˾·¨»¹ÒªÇóÍøÕ¾ÔÚ³ÉÁ¢Ö®Ç°±ØÐë»ñµÃ×î¸ßίԱ»áµÄÐí¿É£¬£¬£¬ £¬£¬²¢ÔÊÐí¸ÃίԱ»á¶ÔÏÖÓÐÍøÕ¾½øÐзâ½û»ò·£¿£¿£¿£¿£¿î¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/social-media-fake-news-law.html