¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180724

Ðû²¼Ê±¼ä 2018-07-24

¡¾Êý¾Ýй¶¡¿Áè¼Ý100¼ÒÆû³µ³§É̵ÄÉñÃØÊý¾Ýй¶£¬ £¬£¬£¬·áÌï¡¢ÌØË¹À­µÈ¾ùÊÜÓ°Ïì


UpGuardÑо¿Ö°Ô±Chris Vickery·¢Ã÷¹©Ó¦ÉÌLevel OneµÄ²»Çå¾²Êý¾Ý¿â£¬ £¬£¬£¬ÆäÖаüÀ¨½ü47000·ÝÎļþ£¬ £¬£¬£¬º­¸Ç¶à¼ÒÆû³µ³§É̵ĽüÊ®ÄêµÄÏêϸÀ¶Í¼¡¢¹¤³§Ô­Àíͼ¡¢¿Í»§ÖÊÁÏ£¨ÈçÌõÔ¼¡¢·¢Æ±ºÍÊÂÇéÍýÏëµÈ£©£¬ £¬£¬£¬ÒÔ¼°ÖÖÖÖ±£ÃÜЭÒéÎļþµÈ¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý×ÜÁ¿´ï157GB£¬ £¬£¬£¬¸£ÌØ¡¢·áÌͨÓúÍÌØË¹À­µÈ¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£Ð¹Â¶µÄÔµ¹ÊÔ­ÓÉÊÇLevel One¹«Ë¾µÄÓÃÓÚ±¸·ÝÊý¾ÝµÄÎļþ´«ÊäЭÒérsync±»ÉèÖÃΪ¿É¹ûÕæ»á¼û£¬ £¬£¬£¬²¢ÇÒ²»ÐèÒªÈκÎÃÜÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/robotics-suppliers-sloppy-security-leaks-ten-years-worth-of-data-from-major-car-manufacturers/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷AndroidÒøÐÐľÂíExobotµÄÔ´Âëй¶


Ñо¿Ö°Ô±·¢Ã÷AndroidÒøÐÐľÂíExobotµÄÔ´´úÂëÒÑÓÚ5ÔÂй¶£¬ £¬£¬£¬²¢ÇÒÔÚ¶ñÒâÈí¼þÉçÇøÖÐѸËÙÈö²¥¡£¡£¡£¡£¡£ExobotÓÚ2016Äêµ×±»Ê״η¢Ã÷£¬ £¬£¬£¬Æä¹¦Ð§Ê®·Öǿʢ£¬ £¬£¬£¬ÉõÖÁ¿ÉÒÔѬȾ×îеÄAndroid°æ±¾¡£¡£¡£¡£¡£2018Äê1Ô¸öñÒâÈí¼þµÄ×÷Õß×îÏȳöÊÛÆäÔ´´úÂ룬 £¬£¬£¬Õâͨ³£ÒâζןÃ×÷ÕßÒÑתÏòÆäËüµÄ¹¤¾ß¡£¡£¡£¡£¡£ÏÖÔÚй¶µÄ°æ±¾ÊÇExobot 2.5£¬ £¬£¬£¬Ñо¿Ö°Ô±¾¯Ê¾³ÆÕâ¿ÉÄܵ¼ÖÂÐÂÒ»²¨µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/source-code-for-exobot-android-banking-trojan-leaked-online/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ͨ¹ýAndroid ADB¶Ë¿ÚÈö²¥µÄSatoriбäÌå


Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶÓÔÚ7ÔÂ9ÈÕÖÁ10ÈÕºÍ7ÔÂ15ÈÕ¼ì²âµ½Õë¶Ô5555¶Ë¿ÚµÄ¹¥»÷»î¶¯µÄÁ½¸ö·åÖµ£¬ £¬£¬£¬¸Ã¹¥»÷»î¶¯Ê¹Óÿª·ÅµÄADB¶Ë¿ÚÔÚAndroid×°±¸ÖÐÈö²¥SatoriµÄÒ»¸öбäÌå¡£¡£¡£¡£¡£µÚÒ»²¨¹¥»÷µÄÁ÷Á¿Ö÷ÒªÀ´×ÔÓÚÃÀ¹úºÍÖйú£¬ £¬£¬£¬¶øµÚ¶þ²¨Á÷Á¿Ö÷ÒªÀ´×Ôº«¹ú¡£¡£¡£¡£¡£AndroidÓû§¿ÉÒÔͨ¹ý¹Ø±Õ¡°ADB£¨USB£©µ÷ÊÔ¡±ºÍ¡°ÔÊÐí×°ÖÃδ֪ȪԴµÄÓ¦Óá±ÕâÁ½¸öÑ¡ÏîÀ´Ìá·ÀÕâÖÖ¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/open-adb-ports-being-exploited-to-spread-possible-satori-variant-in-android-devices/


¡¾Îó²î²¹¶¡¡¿Î¢ÈíÔÚ7ÔÂÇå¾²¸üÐÂÖÐÔÙ´ÎÐÞ¸´IEÁãÈÕÎó²î£¨CVE-2018-8174£©


΢ÈíÔÚ5ÔÂÐÞ¸´ÁËIEÁãÈÕÎó²î£¨CVE-2018-8174£©£¬ £¬£¬£¬µ«Ñо¿Ö°Ô±ÆÊÎöÁËÐÞ¸´²¹¶¡ºó·¢Ã÷ÈÔ±£´æÁíÍâÁ½¸ö¿Éµ¼ÖÂÔ­Îó²îµÄÎÊÌâ¡£¡£¡£¡£¡£ÕâÁ½¸öÎÊÌâ±»±ê¼ÇΪÎó²î£¨CVE-2018-8242£©£¬ £¬£¬£¬Î¢ÈíÔÚ7ÔÂÇå¾²¸üÐÂÖÐÐû²¼Á˸ÃÎó²îµÄÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹³ÆCVE-2018-8242µÄÐÞ¸´²¹¶¡ÒýÈëÁËÒ»¸öÄÚ´æÐ¹Â¶µÄÐÔÄÜÎÊÌ⣬ £¬£¬£¬µ«Õâ¸öÎÊÌâ²¢²»ÊÇÒ»¸öÇå¾²Îó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/that-ie-zero-day-from-may-needed-a-second-patch-in-july/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Õë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öеÄÐÞ¸´²½·¥


À´×Ô¶àËù´óѧµÄÑо¿Ö°Ô±Õë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öÁËеÄÐÞ¸´²½·¥£¬ £¬£¬£¬ÕâЩ²½·¥ÊÇÔÚÈí¼þ¼¶±ðµÄÐÞ¸´£¬ £¬£¬£¬ÕâÒâζ×ÅCPUºÍRAM¹©Ó¦É̲»ÐèÒªÐÞ¸ÄÆä²úÆ·£¬ £¬£¬£¬²¢ÇÒÕâЩ²½·¥¿ÉÒÔÒÔÈí¼þ¸üÐµķ½·¨Ðû²¼¡£¡£¡£¡£¡£Õë¶ÔSpectre¡¡V1µÄÐÞ¸´Ê¹ÓÃÁËLinuxÄں˲¹¶¡ELFbac£¬ £¬£¬£¬¶øÕë¶ÔRowhammer¹¥»÷µÄ·À»¤²½·¥ÊÇͨ¹ýÒ»ÖÖÐÂÊÖÒÕZebRAM¡£¡£¡£¡£¡£ÏÖÔÚÑо¿Ö°Ô±»¹Ã»ÓÐÅû¶¹ØÓÚÕâÏîÊÖÒյĸü¶àÏêϸÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/academics-announce-new-protections-against-spectre-and-rowhammer-attacks/


¡¾Ö´ÂÉÀýÔò¡¿°£¼°ÐÂÖ´·¨ÑÏ´ò¼ÙÐÂÎÅ£¬ £¬£¬£¬·ÛË¿Êý³¬5000µÄ´«Ò¥Õß½«±»Öذì


7ÔÂ16ÈÕ°£¼°Òé»áͨ¹ýÒ»ÏîÐÂÖ´·¨£¬ £¬£¬£¬¸ÃÖ´·¨½«ÔÚFacebookºÍTwitterµÈÉ罻ýÌåÆ½Ì¨ÓµÓÐÁè¼Ý5000Ãû·ÛË¿µÄÕ˺źͲ©¿ÍÊÓΪýÌ壬 £¬£¬£¬²¢ÔÊÐíÕþ¸®·â½ûÐû²¼¼ÙÐÂÎŵÄÕË»§ÒÔ¼°¶ÔÐû²¼Ö°Ô±¾ÙÐд¦·Ö¡£¡£¡£¡£¡£ÐÂÖ´·¨»¹ÒªÇóÍøÕ¾ÔÚ½¨Éè֮ǰ±ØÐè»ñµÃ×î¸ßίԱ»áµÄÔÊÐí£¬ £¬£¬£¬²¢ÔÊÐí¸ÃίԱ»á¶ÔÏÖÓÐÍøÕ¾¾ÙÐзâ½û»ò·£¿£¿£¿£¿î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/social-media-fake-news-law.html