¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180724
Ðû²¼Ê±¼ä 2018-07-24¡¾Êý¾Ýй¶¡¿Áè¼Ý100¼ÒÆû³µ³§É̵ÄÉñÃØÊý¾Ýй¶£¬£¬£¬£¬·áÌï¡¢ÌØË¹ÀµÈ¾ùÊÜÓ°Ïì
UpGuardÑо¿Ö°Ô±Chris Vickery·¢Ã÷¹©Ó¦ÉÌLevel OneµÄ²»Çå¾²Êý¾Ý¿â£¬£¬£¬£¬ÆäÖаüÀ¨½ü47000·ÝÎļþ£¬£¬£¬£¬º¸Ç¶à¼ÒÆû³µ³§É̵ĽüÊ®ÄêµÄÏêϸÀ¶Í¼¡¢¹¤³§ÔÀíͼ¡¢¿Í»§ÖÊÁÏ£¨ÈçÌõÔ¼¡¢·¢Æ±ºÍÊÂÇéÍýÏëµÈ£©£¬£¬£¬£¬ÒÔ¼°ÖÖÖÖ±£ÃÜÐÒéÎļþµÈ¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý×ÜÁ¿´ï157GB£¬£¬£¬£¬¸£ÌØ¡¢·áÌͨÓúÍÌØË¹ÀµÈ¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£Ð¹Â¶µÄÔµ¹ÊÔÓÉÊÇLevel One¹«Ë¾µÄÓÃÓÚ±¸·ÝÊý¾ÝµÄÎļþ´«ÊäÐÒérsync±»ÉèÖÃΪ¿É¹ûÕæ»á¼û£¬£¬£¬£¬²¢ÇÒ²»ÐèÒªÈκÎÃÜÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/robotics-suppliers-sloppy-security-leaks-ten-years-worth-of-data-from-major-car-manufacturers/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷AndroidÒøÐÐľÂíExobotµÄÔ´Âëй¶
Ñо¿Ö°Ô±·¢Ã÷AndroidÒøÐÐľÂíExobotµÄÔ´´úÂëÒÑÓÚ5ÔÂй¶£¬£¬£¬£¬²¢ÇÒÔÚ¶ñÒâÈí¼þÉçÇøÖÐѸËÙÈö²¥¡£¡£¡£¡£¡£ExobotÓÚ2016Äêµ×±»Ê״η¢Ã÷£¬£¬£¬£¬Æä¹¦Ð§Ê®·Öǿʢ£¬£¬£¬£¬ÉõÖÁ¿ÉÒÔѬȾ×îеÄAndroid°æ±¾¡£¡£¡£¡£¡£2018Äê1Ô¸öñÒâÈí¼þµÄ×÷Õß×îÏȳöÊÛÆäÔ´´úÂ룬£¬£¬£¬Õâͨ³£ÒâζןÃ×÷ÕßÒÑתÏòÆäËüµÄ¹¤¾ß¡£¡£¡£¡£¡£ÏÖÔÚй¶µÄ°æ±¾ÊÇExobot 2.5£¬£¬£¬£¬Ñо¿Ö°Ô±¾¯Ê¾³ÆÕâ¿ÉÄܵ¼ÖÂÐÂÒ»²¨µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/source-code-for-exobot-android-banking-trojan-leaked-online/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ͨ¹ýAndroid ADB¶Ë¿ÚÈö²¥µÄSatoriбäÌå
Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶÓÔÚ7ÔÂ9ÈÕÖÁ10ÈÕºÍ7ÔÂ15ÈÕ¼ì²âµ½Õë¶Ô5555¶Ë¿ÚµÄ¹¥»÷»î¶¯µÄÁ½¸ö·åÖµ£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯Ê¹Óÿª·ÅµÄADB¶Ë¿ÚÔÚAndroid×°±¸ÖÐÈö²¥SatoriµÄÒ»¸öбäÌå¡£¡£¡£¡£¡£µÚÒ»²¨¹¥»÷µÄÁ÷Á¿Ö÷ÒªÀ´×ÔÓÚÃÀ¹úºÍÖйú£¬£¬£¬£¬¶øµÚ¶þ²¨Á÷Á¿Ö÷ÒªÀ´×Ôº«¹ú¡£¡£¡£¡£¡£AndroidÓû§¿ÉÒÔͨ¹ý¹Ø±Õ¡°ADB£¨USB£©µ÷ÊÔ¡±ºÍ¡°ÔÊÐí×°ÖÃδ֪ȪԴµÄÓ¦Óá±ÕâÁ½¸öÑ¡ÏîÀ´Ìá·ÀÕâÖÖ¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/open-adb-ports-being-exploited-to-spread-possible-satori-variant-in-android-devices/
¡¾Îó²î²¹¶¡¡¿Î¢ÈíÔÚ7ÔÂÇå¾²¸üÐÂÖÐÔÙ´ÎÐÞ¸´IEÁãÈÕÎó²î£¨CVE-2018-8174£©
΢ÈíÔÚ5ÔÂÐÞ¸´ÁËIEÁãÈÕÎó²î£¨CVE-2018-8174£©£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÆÊÎöÁËÐÞ¸´²¹¶¡ºó·¢Ã÷ÈÔ±£´æÁíÍâÁ½¸ö¿Éµ¼ÖÂÔÎó²îµÄÎÊÌâ¡£¡£¡£¡£¡£ÕâÁ½¸öÎÊÌâ±»±ê¼ÇΪÎó²î£¨CVE-2018-8242£©£¬£¬£¬£¬Î¢ÈíÔÚ7ÔÂÇå¾²¸üÐÂÖÐÐû²¼Á˸ÃÎó²îµÄÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹³ÆCVE-2018-8242µÄÐÞ¸´²¹¶¡ÒýÈëÁËÒ»¸öÄÚ´æÐ¹Â¶µÄÐÔÄÜÎÊÌ⣬£¬£¬£¬µ«Õâ¸öÎÊÌâ²¢²»ÊÇÒ»¸öÇå¾²Îó²î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/that-ie-zero-day-from-may-needed-a-second-patch-in-july/
¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Õë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öеÄÐÞ¸´²½·¥
À´×Ô¶àËù´óѧµÄÑо¿Ö°Ô±Õë¶ÔSpecterºÍRowhammer¹¥»÷Ìá³öÁËеÄÐÞ¸´²½·¥£¬£¬£¬£¬ÕâЩ²½·¥ÊÇÔÚÈí¼þ¼¶±ðµÄÐÞ¸´£¬£¬£¬£¬ÕâÒâζ×ÅCPUºÍRAM¹©Ó¦É̲»ÐèÒªÐÞ¸ÄÆä²úÆ·£¬£¬£¬£¬²¢ÇÒÕâЩ²½·¥¿ÉÒÔÒÔÈí¼þ¸üÐµķ½·¨Ðû²¼¡£¡£¡£¡£¡£Õë¶ÔSpectre¡¡V1µÄÐÞ¸´Ê¹ÓÃÁËLinuxÄں˲¹¶¡ELFbac£¬£¬£¬£¬¶øÕë¶ÔRowhammer¹¥»÷µÄ·À»¤²½·¥ÊÇͨ¹ýÒ»ÖÖÐÂÊÖÒÕZebRAM¡£¡£¡£¡£¡£ÏÖÔÚÑо¿Ö°Ô±»¹Ã»ÓÐÅû¶¹ØÓÚÕâÏîÊÖÒյĸü¶àÏêϸÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/academics-announce-new-protections-against-spectre-and-rowhammer-attacks/
¡¾Ö´ÂÉÀýÔò¡¿°£¼°ÐÂÖ´·¨ÑÏ´ò¼ÙÐÂÎÅ£¬£¬£¬£¬·ÛË¿Êý³¬5000µÄ´«Ò¥Õß½«±»Öذì
7ÔÂ16ÈÕ°£¼°Òé»áͨ¹ýÒ»ÏîÐÂÖ´·¨£¬£¬£¬£¬¸ÃÖ´·¨½«ÔÚFacebookºÍTwitterµÈÉ罻ýÌåÆ½Ì¨ÓµÓÐÁè¼Ý5000Ãû·ÛË¿µÄÕ˺źͲ©¿ÍÊÓΪýÌ壬£¬£¬£¬²¢ÔÊÐíÕþ¸®·â½ûÐû²¼¼ÙÐÂÎŵÄÕË»§ÒÔ¼°¶ÔÐû²¼Ö°Ô±¾ÙÐд¦·Ö¡£¡£¡£¡£¡£ÐÂÖ´·¨»¹ÒªÇóÍøÕ¾ÔÚ½¨Éè֮ǰ±ØÐè»ñµÃ×î¸ßίԱ»áµÄÔÊÐí£¬£¬£¬£¬²¢ÔÊÐí¸ÃίԱ»á¶ÔÏÖÓÐÍøÕ¾¾ÙÐзâ½û»ò·£¿£¿£¿£¿î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/social-media-fake-news-law.html


¾©¹«Íø°²±¸11010802024551ºÅ