΢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©£»£»£»£»£»ÓÅÒ¿âÔ¼50ÍòÕË»§ÐÅϢй¶

Ðû²¼Ê±¼ä 2019-05-15
1¡¢Î¢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Öܶþ΢ÈíÐû²¼5ÔÂWindowsÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´79¸öÎó²î¡£¡£ ¡£¡£¡£ÆäÖаüÀ¨RDPЧÀÍÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0708£©£¬£¬£¬£¬£¬´ËÎó²îÊÇÔ¤Éí·ÝÑéÖ¤£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룻£»£»£»£»ÌáȨ0day£¨CVE-2019-0863£©£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁÖÎÀíԱȨÏÞ£»£»£»£»£»Õë¶ÔIntel CPU MDS¹¥»÷µÄÎó²îÐÞ¸´£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁË2011ÄêÒÔÀ´ÏÕЩËùÓеÄIntel CPU¡£¡£ ¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/

2¡¢ºÚ¿ÍʹÓÃWhatsapp 0day·Ö·¢Ìع¤Èí¼þPegasus

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
FacebookÐÞ¸´ÁËWhatsAppÖеÄÒ»¸ö0day£¨CVE-2019-3568£©¡£¡£ ¡£¡£¡£Æ¾Ö¤FacebookÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬¸ÃÎó²îÊÇWhatsApp VOIP¿ÍÕ»ÖеĻº³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËͶñÒâSRTCPÊý¾Ý°üÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓ㬣¬£¬£¬£¬¹¥»÷ÕßʹÓøÃÎó²îÔÚÄ¿µÄÓû§µÄÊÖ»úÉÏ×°ÖÃÒÔÉ«ÁÐNSO¹«Ë¾µÄÌØ¹¤Èí¼þPegasus¡£¡£ ¡£¡£¡£Æ¾Ö¤Ïà¹Ø±¨¸æ£¬£¬£¬£¬£¬ÉÏÖÜÈÕһλӢ¹úÈËȨ״ʦ¾ÍÔ⵽ʹÓôËÎó²îµÄ¹¥»÷¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/hack-whatsapp-vulnerability.html

3¡¢AppleÐû²¼5ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
AppleÐû²¼5ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬¶Ô¸÷¸ö²úƷϵͳ¾ÙÐÐÁËÉý¼¶£¬£¬£¬£¬£¬°üÀ¨iOS 12.3¡¢tvOS 12.3¡¢watchOS 5.2.1¡¢macOS 10.14.5ºÍHomePod OS 12.3¡£¡£ ¡£¡£¡£ÐÞ¸´µÄÎó²î°üÀ¨macOS DesktopSevicesÖеÄGatekeeper¼ì²éÈÆ¹ýÎó²î£¨CVE-2019-8589£©¡¢EFIÉí·ÝÑéÖ¤Îó²î£¨CVE-2019-8634£©¡¢iOSÖеÄDoSÎó²î£¨CVE-2019-8626£©¡¢É³ÏäÈÆ¹ýÎó²î£¨CVE-2019-8617£©¡¢Wi-FiÎó²î£¨CVE-2019-8620£©µÈ¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/05/14/apple-may-2019-security-updates-fix-numerous-issues/

4¡¢ÓÅÒ¿âµçÉÌÍøÕ¾ÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬Ô¼50ÍòÕË»§ÐÅÏ¢±»Ð¹Â¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
¾ÝÅí²©ÉçÐÂÎÅ£¬£¬£¬£¬£¬ÈÕ±¾ÁãÊÛÉÌFast RetailingÌåÏÖÆìÏÂÓÅÒ¿âºÍGUÆ·ÅÆµÄÈÕ±¾¹ÙÍøÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ýײ¿â¹¥»÷»á¼ûÁË461091¸ö¿Í»§ÕË»§¡£¡£ ¡£¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚ4ÔÂ23ÈÕÖÁ5ÔÂ10ÈÕʱ´ú£¬£¬£¬£¬£¬ÓÉÓÚÊÓ²ìÉÐδ¿¢Ê£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÕË»§Êý×Ö¿ÉÄܸü¸ß¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢¹ºÖüͼÒÔ¼°²¿·ÖÐÅÓÿ¨ÐÅÏ¢µÈ¡£¡£ ¡£¡£¡£5ÔÂ13ÈÕFast Retailing½ûÓÃÁËÊÜÓ°ÏìµÄ¿Í»§ÕË»§ÃÜÂ룬£¬£¬£¬£¬²¢ÏòÕâЩ¿Í»§·¢ËÍÁËÃÜÂëÖØÖÃÓʼþ¡£¡£ ¡£¡£¡£´Ë´ÎÊÂÎñ²¢Î´Éæ¼°ÖйúµÄÍøÕ¾¼°ÐÅϢƽ̨¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-access-over-461-000-accounts-in-uniqlo-data-breach/

5¡¢Paterson¹«Á¢Ñ§Ð£ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Áè¼Ý2.3ÍòÕË»§Æ¾Ö¤±»µÁ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Paterson¹«Á¢Ñ§Ð£ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬23103¸öÕË»§µÄƾ֤±»µÁ¡£¡£ ¡£¡£¡£ÕâЩƾ֤°üÀ¨×ÀÃæµçÄԵĵǼÕË»§¡¢ÓÊÏäÕË»§ÒÔ¼°Ìõ¼Ç±¾µçÄÔÕË»§µÄµÇ¼ƾ֤£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§°üÀ¨Ñ§ÇøµÄÔ±¹¤¡¢ÖÎÀíÔ±¡¢Î÷ϯµÈÊÂÇéÖ°Ô±¡£¡£ ¡£¡£¡£±»µÁµÄƾ֤´æ´¢ÔÚÒ»¸öÁè¼Ý116000ÐеÄÎļþÖУ¬£¬£¬£¬£¬ÆäÖÐÓû§ÃûÊÇÒÔ´¿Îı¾µÄÐÎʽ´æ´¢µÄ£¬£¬£¬£¬£¬¶øÃÜÂëÊÇÒÔÃÜÎÄÐÎʽ´æ´¢£¬£¬£¬£¬£¬µ«ºÜÈÝÒ×±»ÆÆ½â¡£¡£ ¡£¡£¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþÁªÏµÁËýÌåÅÁÌØÉ­Ê±±¨£¬£¬£¬£¬£¬³ÆÕâЩÐÅÏ¢ÊÇÔÚ2018Äê10Ô±»µÁ£¬£¬£¬£¬£¬²¢ÌáÒ齫ÕâЩÊý¾Ý³öÊÛ¸ø¸ÃýÌ壬£¬£¬£¬£¬µ«Ôâµ½Á˾ܾø¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/paterson-public-schools-suffered-data-breach-compromising-over-23000-school-district-passwords-ac1bf681

6¡¢Linksys WiFi·ÓÉÆ÷ÐÅϢй¶Îó²î£¬£¬£¬£¬£¬²¨¼°È«Çò2.5Íǫ̀װ±¸

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Bad PacketsÇå¾²Ñо¿Ô±Troy Mursch·¢Ã÷È«ÇòÓÐÁè¼Ý2.5Íǫ̀LinksysÖÇÄÜWi-Fi·ÓÉÆ÷Êܵ½Ò»¸öÐÅϢй¶Îó²îµÄÓ°Ïì¡£¡£ ¡£¡£¡£¸ÃÎó²îÀàËÆÓÚ2014ÄêµÄÎó²î£¨CVE-2014-8244£©£¬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»ñÈ¡´ó×Ú×°±¸Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨ÒÑÅþÁ¬×°±¸µÄMACµØµã¡¢×°±¸Ãû³Æ¡¢²Ù×÷ϵͳ¡¢·À»ðǽ״̬¡¢WAN/DDNSÉèÖõÈ¡£¡£ ¡£¡£¡£ËäÈ»¸ÃÎó²îÀíÓ¦ÓÚÎåÄêǰ±»ÐÞ¸´£¬£¬£¬£¬£¬µ«Ä¿½ñÎó²îÈÔÈ»±£´æ£¬£¬£¬£¬£¬²¢ÇÒ±»LinksysÇå¾²ÍŶӱê¼ÇΪ¡°²»ÊÊÓÃ/²»ÐÞ¸´¡±¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/linksys-smart-wi-fi-routers-leak-info-of-connected-devices/