Intel 20GBÔ´´úÂëºÍ»úÃÜÎļþй¶£»£»£»£»£»£»£»£»TIM×êÑÐÈËÔ±ÔÚWowzaÁ÷ýÌåÒýÇæÖз¢ÏÖ4¸öеÄ0day

°ä²¼¹¦·ò 2020-08-07

1.Intel 20GBÔ´´úÂëºÍ»úÃÜÎļþй¶£¬£¬£¬£¬£¬ £¬Ä¿Ç°ÆðԴδ֪


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Intel¹«Ë¾²úÉúÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬ £¬20GBÔ´´úÂëºÍ»úÃÜÎļþÓÚ8ÔÂ6ÈÕ±»ÉÏ´«µ½Á˹«¹²Îļþ¹²Ïí·þÎñ£¬£¬£¬£¬£¬ £¬Ä¿Ç°ÐÂäį´Ô´Î´Öª¡£¡£¡£¡£¡£¡£¡£¡£¿ £¿£¿£¿£¿£¿£¿£¿ª·¢ÈËÔ±°µÊ¾£¬£¬£¬£¬£¬ £¬Ð¹Â¶µÄ´óÎÞÊýÄÚÈÝÒÔǰ´ÓδÔÚÖ°ºÎ´¦Ëù°ä²¼¹ý£¬£¬£¬£¬£¬ £¬²¢ÇÒÆ¾¾ÝNDA»òÓ¢ÌØ¶ûÊÜÏÞ°ÂÃØ¹éΪ»úÃÜ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶ÎļþÔ̺¬Kabylake BIOS²Î¿¼´úÂëºÍʾÀý´úÂëºÍ³õʼ»¯´úÂë¡¢ºÏÓÃÓÚ¸÷ÀàÆ½Ì¨µÄоƬ/ FSPÔ´´úÂë°ü¡¢¸÷ÀàÓ¢ÌØ¶û¿ª·¢ºÍµ÷ÊÔ¹¤¾ß¡¢¸÷Àà·ÏßͼºÍÆäËûÎļþ¡¢Ó¢ÌضûΪSpaceXÔì×÷µÄÏà»úÇý¶¯·¨Ê½µÄ¶þ½øÔìÎļþ¡¢Î´°ä²¼µÄTiger Lakeƽ̨µÄµÀÀíͼºÍ¸÷ÀàµÀÀíͼµÈµÈ¡£¡£¡£¡£¡£¡£¡£¡£Intel°µÊ¾£¬£¬£¬£¬£¬ £¬Êý¾Ý¿ÉÄÜÀ´×ÔÓ¢ÌØ¶û×ÊÔ´ÓëÉè¼ÆÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-leak-20gb-of-source-code-internal-docs-from-alleged-breach/


2.TIM×êÑÐÈËÔ±ÔÚWowzaÁ÷ýÌåÒýÇæÖз¢ÏÖ4¸öеÄ0day


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


TIM RTRµÄ×êÑÐÈËÔ±ÔÚWOWZAÁ÷ÒýÇæ²úÆ·Öз¢ÏÖÁË4¸öеÄÁãÈÕ·ì϶£¬£¬£¬£¬£¬ £¬±ðÀëΪËÁÒâÎļþÏÂÔØ·ì϶£¨CVE-2019-19454£©£¬£¬£¬£¬£¬ £¬õè¾¶±éÀú·ì϶£¨CVE-2019-19455£©ºÍÁ½¸ö¿çÕ¾¾ç±¾·ì϶£¨CVE-2019-19453ºÍCVE-2019-19456£©¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶Äܹ»±»Ô¶³Ì¹¥»÷Õß½áºÏʹÓ㬣¬£¬£¬£¬ £¬ÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬ £¬²¢Äܹ»Í¨¹ýÓû§½çÃæ¶ÔËùº±¼û¾ÝµÄ½øÐнӼû¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍŶÓÔÚÉϸöÔ»¹Åú¶ÁËÁ½¸öÑϳÁµÄ0day£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËOracle Business IntelligenceµÄ²úÆ·¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/106804/hacking/wowza-streaming-engine-zerodays.html?utm_source=rss&utm_medium=rss&utm_campaign=wowza-streaming-engine-zerodays


3.McAfee·¢ÏÖ¸¨Öú»úеÈËTemi´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬ £¬¿É±»½Ù³Ö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


McAfeeµÄ¸ß¼¶Íþв×êÑУ¨ATR£©Ó××é·¢ÏÖ½»»¥Ê½¸¨Öú»úеÈËTemi´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬ £¬±ðÀëΪʹÓÃÓ²±àÂëÆ¾Ö¤£¨ CVE-2020-16170£©¡¢Ô­Ê¼ÑéÖ¤ÃýÎó£¨ CVE-2020-16168£©¡¢¶Ìȱ¹Ø¼üÖ°ÄܵÄÉí·ÝÑéÖ¤£¨ CVE-2020-16167£©ÒÔ¼°Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨ CVE-2020-16169£©¡£¡£¡£¡£¡£¡£¡£¡£McAfee°µÊ¾£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÄܹ»½áºÏÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬ £¬ÎÞÐèÉí·ÝÑéÖ¤±ãÄܼලTemiµÄÊÓÆµÍ¨»°£¬£¬£¬£¬£¬ £¬À¹½ØÓëÁíÒ»¸öÓû§µÄͨ»°£¬£¬£¬£¬£¬ £¬ÉõÖÁÔ¶³Ì²Ù¿ØTemi¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·µÄ³ö²úÉÌÔڵõ½·ì϶»ã±¨ºó£¬£¬£¬£¬£¬ £¬Á¢¼´¶ÔÆä½øÐÐÁ˽¨¸´¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/black-hat-healthcare-senior-living-temi-robots-can-be-hijacked-remotely-by-hackers/#ftag=RSSbaffb68


4.ºÚ¿Í¿ÉÀûÓÃMicrosoft TeamsµÄ¸üз¨Ê½×°ÖöñÒâÈí¼þ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Trustwave SpiderLabs×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬ £¬ºÚ¿Í¿ÉÀûÓÃMicrosoft TeamsµÄ¸üз¨Ê½×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÓÚÈ¥Äê³õ´Î±»¹«¿ª£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»´Ó±í²¿URLÏÂÔØ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬¶øºóÀûÓÃÊÜÐÅÀµ£¨ÊðÃû£©µÄ¿ÉÖ´ÐÐÎļþ½øÐÐ×°Öᣡ£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Jayapaul³ÁÐÂ×êÑÐÁ˸ÃÎÊÌ⣬£¬£¬£¬£¬ £¬·¢ÏÖ¸üз¨Ê½ÔÊÐíͨ¹ý¹²Ïí»ò±¾µØÎļþ¼Ð½øÐб¾µØÏνÓÒÔ½øÐвúÆ·¸üУ¬£¬£¬£¬£¬ £¬Òò¶ø¹¥»÷ÕßÄܹ»³ÉÁ¢Ò»¸öÔÊÐíÔ¶³Ì¹«¹²½Ó¼ûµÄSamba·þÎñÆ÷²¢´´½¨Ô¶³Ì¹²Ïí£¬£¬£¬£¬£¬ £¬ÒÔÈÆ¹ý½«¶ñÒâÈí¼þÏÂÔØµÄ²½Ö裬£¬£¬£¬£¬ £¬Microsoft Teams½«Á¢¿Ì´ÓÔ¶³ÌµØÎ»»ñÈ¡²¢ÔËÐÐÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/microsoft-teams-patch-bypass-rce/158043/


5.Twitter½¨¸´ÆäAndroid°æ±¾·ì϶£¬£¬£¬£¬£¬ £¬¿Éµ¼Ö¸öÈËÊý¾Ýй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Twitter½¨¸´ÆäAndroid°æ±¾·ì϶£¬£¬£¬£¬£¬ £¬¸Ã·ì϶¿Éµ¼Ö¶ñÒâAndroidÀûÓýӼû˽ÓÐTwitterÊý¾Ý£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËAndroid 8£¨Oreo£©ºÍAndroid 9£¨Pie£©µÄÓû§¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶£¬£¬£¬£¬£¬ £¬ÔÚÊÜÓ°ÏìÉ豸ÉÏ×°ÖöñÒâÀûÓ÷¨Ê½ÈƹýAndroidϵͳµÄȨÏÞ£¬£¬£¬£¬£¬ £¬À´½Ó¼ûTwitterÉϵĸöÈËÊý¾Ý£¬£¬£¬£¬£¬ £¬ºÃ±ÈÖ±½ÓÐÂÎÅ£¨DM£©¡£¡£¡£¡£¡£¡£¡£¡£Twitter°µÊ¾¸Ã·ì϶ÊÇÓÉÓÚAndroid²Ù×÷ϵͳ×ÔÉí´æÔڵķì϶µ¼ÖµÄ£¬£¬£¬£¬£¬ £¬µ«ÊDz¢Î´Ð¹Â©Óйطì϶µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/twitter-patches-android-app-to-prevent-exploitation-of-bug-that-can-grant-access-to-dms/#ftag=RSSbaffb68


6.¼ÑÄܹÙÍøÔâµ½Maze¹¥»÷£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÐû³ÆÒÑÇÔÈ¡10 TBÊý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¼ÑÄܹÙÍøÔâµ½MazeÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÐû³ÆÒÑÇÔÈ¡10 TBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁ˼ÑÄܵĵç×ÓÓʼþϵͳ¡¢Microsoft Teams¡¢ÆäÃÀ¹úµÄÍøÕ¾ÒÔ¼°ÆäËûÄÚ²¿ÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬£¬ £¬¼ÑÄܹÙÍøimage.canonÓÚ2020Äê7ÔÂ30ÈÕå´»ú£¬£¬£¬£¬£¬ £¬²¢ÔÚÁùÌìºóµÄ8ÔÂ4ÈղŸ´Ô­£¬£¬£¬£¬£¬ £¬µ«ÊÇMaze×éÖ¯°µÊ¾²¢²»ÊÇÓÉÀÕË÷Èí¼þÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£¡£Maze°µÊ¾ÆäµÁÈ¡ÁË10 TBÊý¾ÝºÍ˽º±¼û¾Ý¿âµÈ£¬£¬£¬£¬£¬ £¬µ«»Ø¾øÐ¹Â©Óйع¥»÷µÄ½øÒ»²½ÐÅÏ¢£¬£¬£¬£¬£¬ £¬Ô̺¬Êê½ðÊý¶î¡¢Êý¾Ý±»µÁÖ¤¾ÝÒÔ¼°¼ÓÃÜÉ豸µÄÊýÁ¿¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/canon-hit-by-maze-ransomware-attack-10tb-data-allegedly-stolen/