¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180816

°ä²¼¹¦·ò 2018-08-16

¡¾·ì϶²¹¶¡¡¿Intel CPUÔÙ±»ÆØ¹â3¸öеıßÐÅ·¹¥»÷·ì϶Foreshadow


°²È«×êÑÐÈËÔ±Åû¶ÁËÈý¸öÓ°ÏìIntel CPUµÄ°²È«·ì϶µÄϸ½Ú£¬£¬£¬£¬£¬£¬ £¬ÕâÈý¸ö·ì϶Óë֮ǰµÄSpectreÊÇͳһÀà·ì϶£¬£¬£¬£¬£¬£¬ £¬¶¼ÊÇÀûÓÃÁËÏÖ´úCPUÆÕ±éÓµÓеĴ§Ä¦Ö´ÐÐÖ°ÄÜÀ´Ö´Ðй¥»÷¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶Ŀǰ±»¶¨ÃûΪL1TF/Foreshadow(NG)£¬£¬£¬£¬£¬£¬ £¬·ì϶±àºÅΪForeshadow£¨CVE-2018-3615£©ÒÔ¼°Foreshadow-NG£¨CVE-2018-3620ºÍCVE-2018-3646£©¡£¡£¡£¡£¡£¡£Ä¿Ç°Ö»ÓÐIntel CPUÊܵ½´ËÈý¸ö·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/foreshadow-intel-processor-vulnerability.html


¡¾·ì϶²¹¶¡¡¿Adobe°ä²¼8Ô°²È«¸üУ¬£¬£¬£¬£¬£¬ £¬¹²½¨¸´11¸ö°²È«·ì϶


AdobeÔÚ2018Äê8Եݲȫ¸üÐÂÖн¨¸´ÁË11¸ö·ì϶£¬£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËFlash Player¡¢Creative Cloud ¡¢Experience ManagerºÍAcrobat ReaderËÄ¿îÊ¢ÐеIJúÆ·¡£¡£¡£¡£¡£¡£ÆäÖÐAcrobat ReaderÖеÄÁ½¸ö·ì϶£¨CVE-2018-12808ºÍCVE-2018-12799£©ÊǸßΣµÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£Ã»Óм£ÏóÅú×¢±¾Ô°²È«¸üн¨¸´µÄ·ì϶ÔÚÒ°±í±»»ý¼«ÀûÓᣡ£¡£¡£¡£¡£Adobe½¨ÒéÓû§ºÍÖÎÀíÔ±¾¡¿ìÏÂÔØºÍ×°ÖÃ×îеĽ¨¸´²¹¶¡¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/adobe-patch-updates.html


¡¾Íþвµý±¨¡¿°²È«×êÑÐÈËÔ±ÑÝʾÈôºÎ´ÓVPNÏνÓÖи´Ô­HTTPÊý¾Ý


°²È«×êÑÐÔ±Ahamed NafeezÑÝʾ¿ÉÔÚijЩǰÌáϸ´Ô­Í¨¹ý¼ÓÃÜVPNÏνӷ¢Ë͵ÄHTTPÁ÷Á¿µÄVORACLE¹¥»÷¼¼Êõ¡£¡£¡£¡£¡£¡£VORACLE×ÔÉí²¢²»ÊÇÒ»ÖÖÐµĹ¥»÷£¬£¬£¬£¬£¬£¬ £¬¶øÊǾɵļÓÃܹ¥»÷£¨ÈçCRIME¡¢TIMEºÍBREACH£©µÄ±äÒìºÍ»ìºÏ¡£¡£¡£¡£¡£¡£Nafeez³Æ¸Ã¹¥»÷½öºÏÓÃÓÚ¹¹½¨ÔÚOpenVPNºÍ̸֮ÉϵÄVPN·þÎñ£¬£¬£¬£¬£¬£¬ £¬ÓÉÓÚ¿ªÔ´µÄOpenVPNºÍ̸µÄĬÈÏÉèÖÃÂú×ã¸Ã¹¥»÷µÄǰÌá¡£¡£¡£¡£¡£¡£OpenVPNÔÚ½Óµ½»ã±¨ºóÔÚÆäÎĵµÖÐÃ÷È·ÖÒ¸æÁ˸÷çÏÕ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/voracle-attack-can-recover-http-data-from-vpn-connections/


¡¾Íþвµý±¨¡¿×êÑÐÍŶÓÅû¶¹ØÓÚIE 0day(CVE-2018-8373)µÄ¸ü¶àϸ½Ú


Ç÷Ïò¿Æ¼¼ZDIÍŶÓÅû¶Á˹ØÓÚIE 0day£¨CVE-2018-8373£©µÄ¸ü¶àϸ½Ú¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ7ÔÂ11ÈÕ·¢ÏÖÁ˸÷ì϶£¬£¬£¬£¬£¬£¬ £¬¹ÌÈ»¸Ã·ì϶ӰÏìÁË×îа汾µÄWindowsÖеÄVBScriptÒýÇæ£¬£¬£¬£¬£¬£¬ £¬µ«IE 11ûÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚÒ°±í·¢ÏÖÁËÀûÓø÷ì϶µÄ¶ñÒâ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ £¬ÆäÑù±¾Óë5Ô·ݽ¨¸´µÄVBScriptÒýÇæRCE·ì϶£¨CVE-2018-8174£©Ê¹ÓÃÁËÒ»ÑùµÄ»ìºÏ¼¼Êõ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪÕâÁ½¸ö·ì϶µÄÀûÓôúÂë¿ÉÄܳö×Ôͳһ×÷ÕßÖ®ÊÖ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/use-after-free-uaf-vulnerability-cve-2018-8373-in-vbscript-engine-affects-internet-explorer-to-run-shellcode/


¡¾Ë¾·¨Âɹ桿ǰ΢Èí¹¤³ÌʦÒò²Î¼ÓÀÕË÷Èí¼þRevetonµÄÏ´Ç®°¸±»ÅÐÐÌ18¸öÔÂ


ǰ΢ÈíÍøÂ繤³ÌʦRaymond Odigie Uadiale£¨41Ë꣩ÒòÉæ¼°ÀÕË÷Èí¼þRevetonµÄÏ´Ç®°¸±»ÅÐÈëÓü18¸öÔ¡£¡£¡£¡£¡£¡£Uadiale²»ÊÇÀÕË÷Èí¼þRevetonµÄÏÖʵ×÷Õߣ¬£¬£¬£¬£¬£¬ £¬µ«ËûÔ®ÊÖÀÕË÷Èí¼þµÄ×÷Õß½«´ÓÊܺ¦ÕßÄÇÀïÊÕÈ¡µÄÊê½ð½øÐÐÏ´Ç®£¬£¬£¬£¬£¬£¬ £¬²¢ÊÕÈ¡30%µÄÓöÈ£¬£¬£¬£¬£¬£¬ £¬Éæ°¸½ð¶îΪ93640ÃÀÔª¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/microsoft-reveton-ransomware.html


¡¾¹¥»÷ÊÂÎñ¡¿Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬ £¬ÈýÌìÄÚËðʧ³¬¹ý1350ÍòÃÀÔª


ÉÏÖÜĩӡ¶ÈÒøÐÐCosmos BankÔâµ½ºÚ¿ÍµÄÈëÇÖ£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚÈýÌìÄÚÇÔÈ¡Á˳¬¹ý9.4ÒÚ¬±È£¨Ô¼1350ÍòÃÀÔª£©µÄ×ʽ𡣡£¡£¡£¡£¡£¾Ý±¾µØÃ½Ì屨·£¬£¬£¬£¬£¬£¬ £¬Ç°Á½´Î͵ÇÔ²úÉúÔÚ8ÔÂ11ÈÕÐÇÆÚÁù£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õßͨ¹ý28¸ö¹ú¶ÈµÄ14849±ÊATMÂòÂôÇÔÈ¡ÁËÔ¼1140ÍòÃÀÔª¡£¡£¡£¡£¡£¡£ËæºóÔÚ8ÔÂ13ÈÕÐÇÆÚÒ»£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÙ´Îͨ¹ýSWIFTϵͳÇÔÈ¡ÁËÔ¼200ÍòÃÀÔª¡£¡£¡£¡£¡£¡£Ä¿Ç°µÄÖ¤¾ÝÅú×¢¹¥»÷À´×Ô¼ÓÄô󣬣¬£¬£¬£¬£¬ £¬¸ÃÒøÐаµÊ¾Õâ´Î¹¥»÷µÄ¼¼Êõϸ½ÚÈÔÔÚ½øÒ»´ëÊ©²éÖ®ÖС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-steal-135-million-across-three-days-from-indian-bank/