¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180615

Ðû²¼Ê±¼ä 2018-06-15

¡¾Çå¾²Îó²î¡¿Intel CPUÔÙÆØÐÂLazy FP״̬»¹Ô­Îó²î£¬£¬ £¬£¬£¬£¬£¬Ó°Ïì¶þ´ú¿áî£Ö®ºóµÄCPU


Çå¾²Ñо¿Ö°Ô±ÔÚIntel CPUÖÐÓÖ·¢Ã÷ÁËÒ»¸öÇå¾²Îó²î£¨Lazy FP״̬»¹Ô­Îó²î£©£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2018-3665£©ºÍSpecter/MeltdownÒ»Ñù£¬£¬ £¬£¬£¬£¬£¬Ó°ÏìÁË´¦Öóͷ£Æ÷µÄÍÆ²âÖ´ÐÐÊÖÒÕ£¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË2011Äê¶þ´ú¿áî£Sandy BridgeÖ®ºóµÄËùÓпáÍ־ǿ´¦Öóͷ£Æ÷£¬£¬ £¬£¬£¬£¬£¬IntelÉÐδÐû²¼Óë¸ÃÎó²îÓйصÄÊÖÒÕϸ½Ú£¬£¬ £¬£¬£¬£¬£¬¸÷²Ù×÷ϵͳ³§ÉÌÕýÔÚÍÆ³öÇå¾²¸üÐÂÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£AMD´¦Öóͷ£Æ÷²»ÊÜ´ËÎÊÌâµÄÓ°Ïì¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/intel-processor-vulnerability.html





¡¾ÍþвÇ鱨¡¿Æ¾Ö¤×îеÄÑо¿2018ÄêQ1ʱ´úDNS·Å´ó¹¥»÷ͬ±ÈÔöÌíÔ¼700%


ƾ֤NexusguardµÄÑо¿£¬£¬ £¬£¬£¬£¬£¬2018ÄêµÚÒ»¼¾¶ÈDNS·Å´óÀàÐ͵ÄDDoS¹¥»÷±ÈÉÏÒ»¼¾¶È·­ÁËÒ»·¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒͬ±ÈÔöÌíÁËÔ¼700%¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¹¥»÷ÕßÒ»Ö±×·ÇóеÄÎó²îÒÔÌᳫ¹¥»÷£¬£¬ £¬£¬£¬£¬£¬ÔÚÒÑÍùÁ½¸ö¼¾¶ÈÖÐÖ÷Ҫͨ¹ýųÈõµÄMemcachedЧÀÍÆ÷ºÍÉèÖò»µ±µÄDNSSEC DNSЧÀÍÆ÷Ìᳫ·Å´ó¹¥»÷£¬£¬ £¬£¬£¬£¬£¬Ô¤¼ÆÕâÒ»Ç÷ÊÆ»¹½«Ò»Á¬ÏÂÈ¥¡£¡£¡£¡£¡£µÚÒ»¼¾¶ÈÖÐDDoS¹¥»÷µÄȪԴÅÅÁÐÒ»¶þÃûµÄÊÇÖйú£¨15.2%£©ºÍÃÀ¹ú£¨14.2%£©£¬£¬ £¬£¬£¬£¬£¬Ô½ÄÏ£¨7%£©ÅÊÉýÖÁµÚÈý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2018/06/14/dns-amplification-attacks-q1-2018/





¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÔÚDocker HubÉÏ·¢Ã÷17¸ö±£´æºóÃŵĶñÒâ¾µÏñ


DockerÍŶӴÓDocker¾µÏñµÄ¹Ù·½´æ´¢¿âDocker HubÖÐÒÆ³ýÁË17¸ö±£´æºóÃŵĶñÒâ¾µÏñ¡£¡£¡£¡£¡£ÕâЩ¾µÏñÊÇÓÉͳһ¸öÓû§£¨»òÕßÍŻdocker123321ÉÏ´«µÄ£¬£¬ £¬£¬£¬£¬£¬ÔÚÒÑÍùµÄÒ»ÄêÖÐÕâЩ¶ñÒâ¾µÏñÒ»Ö±±»ÓÃÓÚÔÚÓû§µÄЧÀÍÆ÷ÉÏ×°Ö÷´µ¯shellºÍ¶ñÒâÍÚ¿óÈí¼þ¡£¡£¡£¡£¡£ÆäÖÐһЩ¾µÏñÒѱ»×°ÖÃÁËÁè¼Ý100Íò´Î£¬£¬ £¬£¬£¬£¬£¬ÁíһЩÔò±»×°ÖÃÁËÊýÊ®Íò´Î¡£¡£¡£¡£¡£KromtechÔÚ±¨¸æÖÐÏêϸÆÊÎöÁËÕâ17¸ö¶ñÒâ¾µÏñ¼°Æä¹¦Ð§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/17-backdoored-docker-images-removed-from-docker-hub/





¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷À¬»øÓʼþ½©Ê¬ÍøÂçTrikй¶Áè¼Ý4300Íò¸öµç×ÓÓʼþµØµã


VertekÇå¾²Ñо¿Ö°Ô±·¢Ã÷À¬»øÓʼþ½©Ê¬ÍøÂçTrikµÄÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷й¶Áè¼Ý4300Íò¸öµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ÆTrikµÄC&CЧÀÍÆ÷ÒòÉèÖùýʧʹµÃÈκÎÈ˶¼¿ÉÒÔÖ±½Ó»á¼û£¬£¬ £¬£¬£¬£¬£¬Õą̂ЧÀÍÆ÷ÉϰüÀ¨2201¸öÎı¾Îļþ£¬£¬ £¬£¬£¬£¬£¬Ã¿¸öÎļþ°üÀ¨Ô¼20000¸öµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£ÂÄÀúÖ¤ÆäÖÐ43555741¸öµç×ÓÓʼþµØµãÊÇûÓÐÖØ¸´ÇÒÕýµ±µÄ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¹¥»÷Õßͨ¹ýÕâЩÊÕ¼þÈËÁбíÀ´·Ö·¢À¬»øÓʼþºÍ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trik-spam-botnet-leaks-43-million-email-addresses/





¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±Ðû²¼ÀÕË÷Èí¼þEverbeµÄ½âÃܹ¤¾ß£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý±©Á¦ÆÆ½â»ñÈ¡ÃÜÔ¿


Çå¾²Ñо¿Ö°Ô±Michael GillespieºÍMaxime MeignanÐû²¼ÁËÀÕË÷Èí¼þEverbeµÄ½âÃܹ¤¾ß£¬£¬ £¬£¬£¬£¬£¬¿Éͨ¹ý±©Á¦ÆÆ½â»ñÈ¡½âÃÜÃÜÔ¿£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø×ÊÖúÊܺ¦Õ߻ָ´Îļþ¡£¡£¡£¡£¡£EverbeѬȾĿµÄϵͳºó£¬£¬ £¬£¬£¬£¬£¬»á¼ÓÃÜÓû§µÄÎļþ²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.[everbe@airmail.cc].everbe¡¢.embrace»ò.painÀ©Õ¹Ãû£¬£¬ £¬£¬£¬£¬£¬ÏÖÔÚ»¹²»ÇåÎú¸ÃÀÕË÷Èí¼þµÄÈö²¥·½·¨¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/decryptor-released-for-the-everbe-ransomware/





¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶ÔAndroid×°±¸µÄжñÒâÈí¼þMysteryBot


ThreatFabricµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÍøÂç·¸·¨·Ö×ÓÕýÔÚ¿ª·¢Ò»¸öÖ÷ÒªÕë¶ÔAndroid×°±¸µÄжñÒâÈí¼þMysteryBot¡£¡£¡£¡£¡£MysteryBotÈÚºÏÁËÒøÐÐľÂí¡¢¼üÅ̼ͼÆ÷ºÍmobileÀÕË÷Èí¼þµÄ¹¦Ð§¡£¡£¡£¡£¡£Æ¾Ö¤¶ÔÆä´úÂëµÄÆÊÎö£¬£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪMysteryBotÓëAndroidÒøÐÐľÂíLokiBot±£´æ¹ØÁª¡£¡£¡£¡£¡£MysteryBot»¹¿ÉÒÔÔÚAndroid 7ºÍAndroid 8ÉÏÔËÐС£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-mysterybot-android-malware-packs-a-banking-trojan-keylogger-and-ransomware/