΢ÈíÐû²¼Î¢Âë¸üУ¬£¬£¬£¬£¬ÐÞ¸´Intel CPUÖвàÐŵÀÎó²î£»£»£»£»£»£»£»£»¹È¸èÐû²¼Chrome²¹¶¡£¬£¬£¬£¬£¬ÐÞ¸´Á½¸ö±»ÔÚҰʹÓõÄ0day

Ðû²¼Ê±¼ä 2020-11-12
1.΢ÈíÐû²¼Î¢Âë¸üУ¬£¬£¬£¬£¬ÐÞ¸´Intel CPUÖвàÐŵÀÎó²î


1.jpg


΢ÈíÒÑÕë¶ÔWindows 10 20H2¡¢2004¡¢1909Ðû²¼ÁËIntel΢´úÂë¸üУ¬£¬£¬£¬£¬ÒÔÐÞ¸´Intel CPUÖеIJàÐŵÀÎó²îPlatypus¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓɸñÀ­´ÄÊÖÒÕ´óѧ¡¢CISPAº¥Ä·»ô×ÈÐÅÏ¢Çå¾²ÖÐÐĺͲ®Ã÷º²´óѧµÄ×é³ÉµÄÑо¿ÍŶÓÅû¶£¬£¬£¬£¬£¬Î»ÓÚÓ¢ÌØ¶ûµÄÔËÐÐÆ½¾ù¹¦ÂÊÏÞÖÆ£¨RAPL£©½çÃæÖС£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Åú×¢£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃRAPL½Ó¿Ú¼àÊÓ¹¦ºÄ²¢ÍƶÏCPUÕýÔÚÖ´ÐÐÄÄЩָÁ£¬£¬£¬£¬´Ó¶ø´ÓÄÚ´æÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£±ðµÄ´Ë´Î¸üл¹ÐÞ¸´ÁËʸÁ¿¼Ä´æÆ÷²ÉÑù»î¶¯ÖÐÎó²î£¨CVE-2020-8696£©ºÍ¿ìËٴ洢ǰհչÍûÆ÷ÖÐÎó²î£¨CVE-2020-8698£©¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-intel-microcode-released-to-fix-new-cpu-security-bugs/


2.¹È¸èÐû²¼Chrome²¹¶¡£¬£¬£¬£¬£¬ÐÞ¸´Á½¸ö±»ÔÚҰʹÓõÄ0day


2.jpg


¹È¸èÐû²¼Chrome°æ±¾86.0.4240.198£¬£¬£¬£¬£¬ÐÞ¸´Á½¸ö±»ÔÚҰʹÓõÄ0day¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î»®·ÖΪV8Öв»Êʵ±µÄʵÏÖÎó²î£¨CVE-2020-16013£©ºÍSite IsolationÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2020-16017£©£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÕâÁ½¸öÎó²îÊÇÐèÒª×÷ΪÎó²îʹÓÃÁ´µÄÒ»²¿·ÖÒ»ÆðʹÓÃÕվɵ¥¶ÀʹÓᣡ£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²îÊÇÒÑÍùÈýÖÜÄÚGoogleÔÚChromeÖÐÐÞ¸´µÄµÚËĺ͵ÚÎå¸ö0day£¬£¬£¬£¬£¬Ö®Ç°ÉÐÓÐFreeType×ÖÌåäÖȾ¿âÖÐÎó²î£¨CVE-2020-15999£©¡¢V8 JavaScriptÒýÇæÖÐÎó²î£¨CVE-2020-16009£©ºÍUI×é¼þÖÐÎó²î£¨CVE-2020-16010£©¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-two-more-chrome-zero-days/


3.Ñо¿Ö°Ô±·¢Ã÷GNOMEÏÔʾÖÎÀíÆ÷±£´æÍâµØÌáȨÎó²î


3.jpg


Ñо¿Ö°Ô±·¢Ã÷GNOMEÏÔʾÖÎÀíÆ÷£¨gdm£©±£´æÒ×ÓÚʹÓõÄÍâµØÌáȨÎó²î¡£¡£¡£¡£¡£¡£¡£GitHubµÄÇå¾²Ñо¿Ô±Kevin BackhouseÔÚÓÃÀ´¸ú×ÙϵͳÉÏ¿ÉÓÃÓû§µÄ×é¼þAccountsServiceÖз¢Ã÷ÁË Á½¸öÎó²î£¬£¬£¬£¬£¬¿Éµ¼Ö¸Ã×é¼þ¹ÒÆð£¨CVE-2020-16127£©ºÍ·ÅÆúÓû§ÕÊ»§ÌØÈ¨£¨CVE-2020-16126£©£¬£¬£¬£¬£¬¿Éͨ¹ýÏòÆä·¢ËÍÑӳٵķֶιýʧÐźÅÀ´Ê¹ÊØ»¤³ÌÐòÍ߽⡣¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î½¨Éè¾ßÓиü¸ßȨÏÞµÄÕÊ»§£¬£¬£¬£¬£¬²¢ÒÔÖÎÀíԱȨÏÞ£¨root£©ÔËÐдúÂë¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ubuntus-gnome-desktop-could-be-tricked-into-giving-root-access/


4.ºÚ¿ÍÓÃFacebookÁ´½ÓÔ¤ÀÀ¹¦Ð§ÈƹýºÚÃûµ¥À´×¥È¡Êý¾Ý


4.jpg


ºÚ¿ÍʹÓÃFacebookÁ´½ÓÔ¤ÀÀ¹¦Ð§£¬£¬£¬£¬£¬²¢Ê¹ÓÃFacebook APIЧÀÍÆ÷×÷ΪÊðÀíÒÔ×èÖ¹±»ÁÐÈëºÚÃûµ¥£¬£¬£¬£¬£¬À´´Ó»¥ÁªÍøÉÏץȡÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÊÖÒÕÖ®ÒÔÊÇÀֳɣ¬£¬£¬£¬£¬ÊÇÓÉÓÚ´ó´ó¶¼ÍøÕ¾ÔËÓªÉ̶¼ÔÊÐíFacebookЧÀÍÆ÷ץȡÆäÕ¾µãµÄÊý¾Ý£¬£¬£¬£¬£¬ÓÉÓÚÕâЩ±»ÍøÂçµÄÊý¾Ýͨ³£»£»£»£»£»£»£»£»á±»ÓÃÓÚÕýµ±Ä¿µÄ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Çå¾²¹«Ë¾DataDome·¢Ã÷ºÚ¿Í×éÖ¯¿ÉʹÓøù¦Ð§ÒÔÿСʱ10000¸öURLµÄËÙÂʼìË÷Á´½ÓÔ¤ÀÀ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚFacebookÒѾ­¸ÄÉÆÁËMessengerÔ¤ÀÀAPIµÄËÙÂÊÏÞÖÆ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/facebook-link-preview-feature-used-as-a-proxy-in-website-scraping-scheme/


5.ºÚ¿ÍÔÚ°µÍø³öÊÛ580ÍòÌõRedDoorzÂùݿͻ§µÄ¼Í¼


5.jpg


ºÚ¿ÍÔÚ°µÍø³öÊÛ580ÍòÌõRedDoorzÂùݿͻ§µÄ¼Í¼¡£¡£¡£¡£¡£¡£¡£RedDoorzÊÇÐÂ¼ÓÆÂµÄÂùÝÖÎÀíºÍÔ¤¶©Æ½Ì¨£¬£¬£¬£¬£¬ÔÚÕû¸ö¶«ÄÏÑÇÓµÓÐ1000¶à¼ÒÂùÝ¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í±¾ÖÜ×îÏÈÔÚ°µÍø³öÊÛ°üÀ¨580ÍòRedDoorzÓû§¼Í¼µÄÊý¾Ý¿â£¬£¬£¬£¬£¬ÆäÖаüÀ¨Óû§µÄµç×ÓÓʼþ¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢ÐÔ±ð¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏÕÕÆ¬µÄÁ´½Ó¡¢µç»°ºÅÂë¡¢¸¨Öúµç»°ºÅÂë¡¢³öÉúÈÕÆÚºÍÖ°Òµ£¬£¬£¬£¬£¬µ«Ëü²»°üÀ¨ÈκβÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/58-million-reddoorz-user-records-for-sale-on-hacking-forum/


6.ZscalerÐû²¼2020Äê¼ÓÃܹ¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


ZscalerÐû²¼ÁË2020Äê¼ÓÃܹ¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬Õ¹ÏÖÁË»ùÓÚ¼ÓÃܵÄÍþв½«ÔöÌí260£¥¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸ÃÑо¿»¹·¢Ã÷COVID-19ÍÆ¶¯ÁËÀÕË÷Èí¼þ¹¥»÷µÄ¼¤Ôö£¬£¬£¬£¬£¬´Ó3ÔÂ×îÏÈÀÕË÷Èí¼þ¶Ô¼ÓÃÜÁ÷Á¿µÄ¹¥»÷ÔöÌíÁË5±¶£¬£¬£¬£¬£¬ÓëCOVIDÏà¹ØµÄÍþв¼¤ÔöÁË30000£¥£»£»£»£»£»£»£»£»´¹ÂÚ¹¥»÷´ÎÊý¸ß´ï1.93ÒڴΣ¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖÆÔìÒµ£¨38.6£¥£©¡¢Ð§ÀÍÒµ£¨13.8£¥£©ºÍÒ½ÁƱ£½¡£¡£¡£¡£¡£¡£¡£¨Õ¼10.9£¥£©£»£»£»£»£»£»£»£»ºÚ¿ÍÔÚÈÆ¹ý¼ì²â·½ÃæµÄÊÖÒÕ¸üÎªÖØ´ó£¬£¬£¬£¬£¬30£¥µÄ»ùÓÚSSLµÄ¹¥»÷ÓÕÆ­ÁËÊÜÐÅÈεÄÔÆÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zscaler.com/press/new-research-shows-attackers-turning-encrypted-attacks-during-pandemic