¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181115

°ä²¼¹¦·ò 2018-11-15
1¡¢×êÑÐÍŶÓÅû¶7ÖÖÐÂÈۻٺ͹í»ê¹¥»÷ £¬£¬£¬£¬£¬£¬Intel¡¢AMDºÍARM¾ùÊÜÓ°Ïì

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÓÉ9Ãû×êÑÐÈËÔ±×é³ÉµÄ×êÑÐÓ××éÅû¶ÁË7ÖÖеÄÈۻٺ͹í»ê¹¥»÷ £¬£¬£¬£¬£¬£¬ÆäÖÐ2ÖÖÊÇMeltdown¹¥»÷µÄ±äÖÖ £¬£¬£¬£¬£¬£¬Áí±í5ÖÖÊÇSpectre¹¥»÷µÄ±äÖÖ¡£¡£¡£¡£ ¡£¡£Èý´óÖØÒª´¦ÖÃÆ÷³§ÉÌ-Intel¡¢AMDºÍARM¾ùÊÜÓ°Ïì¡£¡£¡£¡£ ¡£¡£¸Ã×êÑÐÓ××éÏòIntel¡¢AMDºÍARM»ã±¨ÁËÕâЩ·ì϶ £¬£¬£¬£¬£¬£¬ÆäÖÐIntelºÍARMÒѾ­ÈÏ¿ÉÁËËûÃǵÄ×êÑÐÁ˾֡£¡£¡£¡£ ¡£¡£¸ÃÍŶӻ¹°µÊ¾ £¬£¬£¬£¬£¬£¬ÓÉÓÚ¹©¸øÉÌÔÚÖÂÁ¦½¨¸´ÕâЩÎÊÌâ £¬£¬£¬£¬£¬£¬ËûÃǾö¶¨Ôݲ»Åû¶ÓйØPoC¡£¡£¡£¡£ ¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/meltdown-spectre-vulnerabilities.html


2¡¢FacebookÔÙÆØÐ·ì϶ £¬£¬£¬£¬£¬£¬»ò¿Éµ¼ÖÂÓû§¸öÈËÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Imperva×êÑÐÔ±Ron Masas·¢ÏÖFacebookÖеÄÒ»¸öзì϶ £¬£¬£¬£¬£¬£¬»ò¿Éµ¼ÖÂÓû§¼°Æä°éµĸöÈËÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶ÓëFacebookËÑË÷Ö°ÄܵÄÁ˾ÖÏÔʾÓÐ¹Ø £¬£¬£¬£¬£¬£¬Æ¾¾ÝMasasµÄ˵·¨ £¬£¬£¬£¬£¬£¬ÏÔʾÓû§ËÑË÷Á˾ֵÄÒ³ÃæÔ̺¬ÓëÿһÌõËÑË÷Á˾ÖÓйØÁªµÄiFrameÔªËØ £¬£¬£¬£¬£¬£¬¶øÕâЩiFrameÔªËØµÄ¹ØÁªURLÒ×ÊÜCSRF¹¥»÷¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ǿÆÅ×û§Ö´ÐÐËÁÒâËÑË÷²éÎÊ £¬£¬£¬£¬£¬£¬²¢»ñµÃ·µ»ØµÄÓû§ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£FacebookÒѾ­½¨¸´Á˸÷ì϶¡£¡£¡£¡£ ¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/facebook-vulnerability-hack.html


3¡¢°²È«³§Ḛ́䲼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Forcepoint°ä²¼2019ÄêÍøÂ簲ȫÇ÷ÏòÔ¤²â»ã±¨ £¬£¬£¬£¬£¬£¬»ã±¨µÄÖ÷ÌâÔ̺¬£ºÍøÂ簲ȫÖеÄAIÊÇ·ñÒÑÖÁ¶¬Ìì £¿£¿£¿£¿£¿´ó¹æÄ£µÄ¹¤ÒµÎïÁªÍøÖжÏÍþв£»£»£»£» £» £»£»£»ÉúÎï¼ø±ð¼¼ÊõÖеĴ¹µöÍþв£»£»£»£» £» £»£»£»¹ØÓÚ¹¤×÷³¡Ëù°²È«´ëÊ©¼à²âµÄ˾·¨ÂÉ¹æ £¿£¿£¿£¿£¿ÒµÎñÕ½Óë¹ú¶ÈÖ§³ÖµÄ¹¤Òµ¼äµý»î¶¯£»£»£»£» £» £»£»£»±ßÔµÍÆËãµÄÔ¶¾°Óë¹ÊÕÏ£»£»£»£» £» £»£»£»¶ÔºÏ×÷ͬ°éµÄ°²È«ÐÅÀµÆÀ¼¶»ò½«Ô½À´Ô½³ÁÒª¡£¡£¡£¡£ ¡£¡£ÆëÈ«»ã±¨Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.forcepoint.com/blog/insights/2019-forcepoint-cybersecurity-predictions-report


4¡¢ÔÚÏßÉ̵êInfowarsÔâMagecart¹¥»÷ £¬£¬£¬£¬£¬£¬Ô¼1600ÃûÓû§ÒÉÊÜÓ°Ïì

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÉÀ¼°²È«×êÑÐÔ±Willem de Groot·¢´Ë¿ÌÏßÉ̵êInfowarsϰȾÁËÓÃÓÚÇÔÈ¡Óû§ÐÅÓþ¿¨ÐÅÏ¢µÄ¶ñÒâ¾ç±¾Magecart¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâ¾ç±¾ÔÚInfowarsÉÏ´æÔÚÁËԼĪ24¸öÓ×ʱ £¬£¬£¬£¬£¬£¬Ëæºó¾Í±»Infowarsɾ³ý £¬£¬£¬£¬£¬£¬Ô¼1600ÃûÓû§¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±³ÆÕâЩMagecart´úÂë°µ²ØÔÚGoogle Analytics´úÂë¿éÖÐ £¬£¬£¬£¬£¬£¬½öÔÚÓû§½áÕËʱ¼¤»î £¬£¬£¬£¬£¬£¬Ã¿¸ô1.5Ãëץȡһ´Î½áÕË±íµ¥ÖеÄ×Ö¶ÎÄÚÈÝ £¬£¬£¬£¬£¬£¬²¢·¢ËÍÖÁλÓÚÁ¢ÌÕÍðµÄÔ¶³Ì·þÎñÆ÷google-analyitics[.]org¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±»¹³ÆÕâЩ¶ñÒâ´úÂëµÄ·ç¸ñÓëRiskIQºÍFlashpointµÄMagecart¹¥»÷»ã±¨ÖÐÌá¼°µÄ7¸ö·¸×ïÍŻﶼ²»Ò»Ñù¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/card-skimming-malware-removed-from-infowars-online-store/


5¡¢Adobe°ä²¼11Ô°²È«¸üР£¬£¬£¬£¬£¬£¬½¨¸´Flash PlayerµÈ²úÆ·ÖеÄ3¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Adobe°ä²¼2018Äê11ÔµÄÔ¶Ȱ²È«¸üР£¬£¬£¬£¬£¬£¬±ðÀ뽨¸´ÁËAcrobat reader¡¢Flash Player¼°Photoshop CCÖеݲȫ·ì϶¡£¡£¡£¡£ ¡£¡£ÆäÖÐAcrobat readerÖеķì϶£¨CVE-2018-15979£©¿Éµ¼ÖÂÓû§µÄNTLM¹þÏ£ÃÜÂëй¶ £¬£¬£¬£¬£¬£¬²¢ÇҸ÷ì϶µÄPoC¹«¿ª¿ÉÓᣡ£¡£¡£ ¡£¡£Flash PlayerÖеķì϶£¨CVE-2018-15978£©ºÍPhotoshop CCÖеķì϶£¨CVE-2018-15980£©¶¼Êǿɵ¼ÖÂÐÅϢй¶µÄÔ½½ç¶Á·ì϶¡£¡£¡£¡£ ¡£¡£½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-security-update-for-acrobat-vulnerability-with-public-poc/


6¡¢SAP°ä²¼11Ô°²È«¸üР£¬£¬£¬£¬£¬£¬¹²½¨¸´11¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖܶþSAP°ä²¼ÁË2018Äê11Ô°²È«¸üР£¬£¬£¬£¬£¬£¬½¨¸´Á˶à¿î²úÆ·ÖеÄ11¸ö·ì϶¡£¡£¡£¡£ ¡£¡£·ì϶ÁìÓòÔ̺¬´úÂë×¢Èë¡¢XSS¡¢XXE¡¢SSRF¡¢»Ø¾ø·þÎñ¡¢¶ÌȱXMLÑéÖ¤ºÍURL³Á¶¨ÏòµÈ¡£¡£¡£¡£ ¡£¡£ÆäÖнÏÑϳÁµÄ·ì϶Ô̺¬SAP HANA Streaming AnalyticsµÄSpring¿ò¼Ü¿âÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-1270ºÍCVE-2018-1275£©ÒÔ¼°SAP Fiori¿Í»§¶ËÖеÄDoS·ì϶£¨CVE-2018-2488£©µÈ¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/sap-patches-critical-vulnerability-hana-streaming-analytics


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù