¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181115
°ä²¼¹¦·ò 2018-11-15
ÓÉ9Ãû×êÑÐÈËÔ±×é³ÉµÄ×êÑÐÓ××éÅû¶ÁË7ÖÖеÄÈۻٺ͹í»ê¹¥»÷£¬£¬£¬£¬£¬£¬ÆäÖÐ2ÖÖÊÇMeltdown¹¥»÷µÄ±äÖÖ£¬£¬£¬£¬£¬£¬Áí±í5ÖÖÊÇSpectre¹¥»÷µÄ±äÖÖ¡£¡£¡£¡£¡£¡£Èý´óÖØÒª´¦ÖÃÆ÷³§ÉÌ-Intel¡¢AMDºÍARM¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¸Ã×êÑÐÓ××éÏòIntel¡¢AMDºÍARM»ã±¨ÁËÕâЩ·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐIntelºÍARMÒѾÈÏ¿ÉÁËËûÃǵÄ×êÑÐÁ˾֡£¡£¡£¡£¡£¡£¸ÃÍŶӻ¹°µÊ¾£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹©¸øÉÌÔÚÖÂÁ¦½¨¸´ÕâЩÎÊÌ⣬£¬£¬£¬£¬£¬ËûÃǾö¶¨Ôݲ»Åû¶ÓйØPoC¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/meltdown-spectre-vulnerabilities.html2¡¢FacebookÔÙÆØÐ·ì϶£¬£¬£¬£¬£¬£¬»ò¿Éµ¼ÖÂÓû§¸öÈËÐÅϢй¶
Imperva×êÑÐÔ±Ron Masas·¢ÏÖFacebookÖеÄÒ»¸öзì϶£¬£¬£¬£¬£¬£¬»ò¿Éµ¼ÖÂÓû§¼°Æä°éµĸöÈËÐÅϢй¶¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓëFacebookËÑË÷Ö°ÄܵÄÁ˾ÖÏÔʾÓйأ¬£¬£¬£¬£¬£¬Æ¾¾ÝMasasµÄ˵·¨£¬£¬£¬£¬£¬£¬ÏÔʾÓû§ËÑË÷Á˾ֵÄÒ³ÃæÔ̺¬ÓëÿһÌõËÑË÷Á˾ÖÓйØÁªµÄiFrameÔªËØ£¬£¬£¬£¬£¬£¬¶øÕâЩiFrameÔªËØµÄ¹ØÁªURLÒ×ÊÜCSRF¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ǿÆÅ×û§Ö´ÐÐËÁÒâËÑË÷²éÎÊ£¬£¬£¬£¬£¬£¬²¢»ñµÃ·µ»ØµÄÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£FacebookÒѾ½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/facebook-vulnerability-hack.html3¡¢°²È«³§Ḛ́䲼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨
Forcepoint°ä²¼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨£¬£¬£¬£¬£¬£¬»ã±¨µÄÖ÷ÌâÔ̺¬£ºÍøÂ簲ȫÖеÄAIÊÇ·ñÒÑÖÁ¶¬Ì죿£¿£¿£¿£¿´ó¹æÄ£µÄ¹¤ÒµÎïÁªÍøÖжÏÍþв£»£»£»£»£»£»£»£»ÉúÎï¼ø±ð¼¼ÊõÖеĴ¹µöÍþв£»£»£»£»£»£»£»£»¹ØÓÚ¹¤×÷³¡Ëù°²È«´ëÊ©¼à²âµÄ˾·¨Âɹ棿£¿£¿£¿£¿ÒµÎñÕ½Óë¹ú¶ÈÖ§³ÖµÄ¹¤Òµ¼äµý»î¶¯£»£»£»£»£»£»£»£»±ßÔµÍÆËãµÄÔ¶¾°Óë¹ÊÕÏ£»£»£»£»£»£»£»£»¶ÔºÏ×÷ͬ°éµÄ°²È«ÐÅÀµÆÀ¼¶»ò½«Ô½À´Ô½³ÁÒª¡£¡£¡£¡£¡£¡£ÆëÈ«»ã±¨Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.forcepoint.com/blog/insights/2019-forcepoint-cybersecurity-predictions-report4¡¢ÔÚÏßÉ̵êInfowarsÔâMagecart¹¥»÷£¬£¬£¬£¬£¬£¬Ô¼1600ÃûÓû§ÒÉÊÜÓ°Ïì
ºÉÀ¼°²È«×êÑÐÔ±Willem de Groot·¢´Ë¿ÌÏßÉ̵êInfowarsϰȾÁËÓÃÓÚÇÔÈ¡Óû§ÐÅÓþ¿¨ÐÅÏ¢µÄ¶ñÒâ¾ç±¾Magecart¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ¾ç±¾ÔÚInfowarsÉÏ´æÔÚÁËԼĪ24¸öÓ×ʱ£¬£¬£¬£¬£¬£¬Ëæºó¾Í±»Infowarsɾ³ý£¬£¬£¬£¬£¬£¬Ô¼1600ÃûÓû§¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³ÆÕâЩMagecart´úÂë°µ²ØÔÚGoogle Analytics´úÂë¿éÖУ¬£¬£¬£¬£¬£¬½öÔÚÓû§½áÕËʱ¼¤»î£¬£¬£¬£¬£¬£¬Ã¿¸ô1.5Ãëץȡһ´Î½áÕË±íµ¥ÖеÄ×Ö¶ÎÄÚÈÝ£¬£¬£¬£¬£¬£¬²¢·¢ËÍÖÁλÓÚÁ¢ÌÕÍðµÄÔ¶³Ì·þÎñÆ÷google-analyitics[.]org¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹³ÆÕâЩ¶ñÒâ´úÂëµÄ·ç¸ñÓëRiskIQºÍFlashpointµÄMagecart¹¥»÷»ã±¨ÖÐÌá¼°µÄ7¸ö·¸×ïÍŻﶼ²»Ò»Ñù¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/card-skimming-malware-removed-from-infowars-online-store/5¡¢Adobe°ä²¼11Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Flash PlayerµÈ²úÆ·ÖеÄ3¸ö·ì϶

Adobe°ä²¼2018Äê11ÔµÄÔ¶Ȱ²È«¸üУ¬£¬£¬£¬£¬£¬±ðÀ뽨¸´ÁËAcrobat reader¡¢Flash Player¼°Photoshop CCÖеݲȫ·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐAcrobat readerÖеķì϶£¨CVE-2018-15979£©¿Éµ¼ÖÂÓû§µÄNTLM¹þÏ£ÃÜÂëй¶£¬£¬£¬£¬£¬£¬²¢ÇҸ÷ì϶µÄPoC¹«¿ª¿ÉÓᣡ£¡£¡£¡£¡£Flash PlayerÖеķì϶£¨CVE-2018-15978£©ºÍPhotoshop CCÖеķì϶£¨CVE-2018-15980£©¶¼Êǿɵ¼ÖÂÐÅϢй¶µÄÔ½½ç¶Á·ì϶¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-releases-security-update-for-acrobat-vulnerability-with-public-poc/6¡¢SAP°ä²¼11Ô°²È«¸üУ¬£¬£¬£¬£¬£¬¹²½¨¸´11¸ö·ì϶
±¾ÖܶþSAP°ä²¼ÁË2018Äê11Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Á˶à¿î²úÆ·ÖеÄ11¸ö·ì϶¡£¡£¡£¡£¡£¡£·ì϶ÁìÓòÔ̺¬´úÂë×¢Èë¡¢XSS¡¢XXE¡¢SSRF¡¢»Ø¾ø·þÎñ¡¢¶ÌȱXMLÑéÖ¤ºÍURL³Á¶¨ÏòµÈ¡£¡£¡£¡£¡£¡£ÆäÖнÏÑϳÁµÄ·ì϶Ô̺¬SAP HANA Streaming AnalyticsµÄSpring¿ò¼Ü¿âÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-1270ºÍCVE-2018-1275£©ÒÔ¼°SAP Fiori¿Í»§¶ËÖеÄDoS·ì϶£¨CVE-2018-2488£©µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/sap-patches-critical-vulnerability-hana-streaming-analyticsÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ