Intel 20GBÔ´´úÂëºÍÉñÃØÎļþй¶£»£»£»£»£»£»£»TIMÑо¿Ö°Ô±ÔÚWowzaÁ÷ýÌåÒýÇæÖз¢Ã÷4¸öеÄ0day

Ðû²¼Ê±¼ä 2020-08-07

1.Intel 20GBÔ´´úÂëºÍÉñÃØÎļþй¶£¬£¬£¬£¬£¬ £¬ÏÖÔÚȪԴδ֪


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Intel¹«Ë¾±¬·¢Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬ £¬20GBÔ´´úÂëºÍÉñÃØÎļþÓÚ8ÔÂ6ÈÕ±»ÉÏ´«µ½Á˹«¹²Îļþ¹²ÏíЧÀÍ£¬£¬£¬£¬£¬ £¬ÏÖÔÚй¿à´Ô´Î´Öª¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ª·¢Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬ £¬Ð¹Â¶µÄ´ó´ó¶¼ÄÚÈÝÒÔǰ´ÓδÔÚÈκεط½Ðû²¼¹ý£¬£¬£¬£¬£¬ £¬²¢ÇÒÆ¾Ö¤NDA»òÓ¢ÌØ¶ûÊÜÏÞÉñÃØ¹éΪÉñÃØ¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶Îļþ°üÀ¨Kabylake BIOS²Î¿¼´úÂëºÍʾÀý´úÂëºÍ³õʼ»¯´úÂë¡¢ÊÊÓÃÓÚÖÖÖÖÆ½Ì¨µÄоƬ/ FSPÔ´´úÂë°ü¡¢ÖÖÖÖÓ¢ÌØ¶û¿ª·¢ºÍµ÷ÊÔ¹¤¾ß¡¢ÖÖÖÖõ辶ͼºÍÆäËûÎļþ¡¢Ó¢ÌضûΪSpaceXÖÆÔìµÄÏà»úÇý¶¯³ÌÐòµÄ¶þ½øÖÆÎļþ¡¢Î´Ðû²¼µÄTiger Lakeƽ̨µÄÔ­ÀíͼºÍÖÖÖÖÔ­ÀíͼµÈµÈ¡£¡£¡£¡£¡£¡£¡£IntelÌåÏÖ£¬£¬£¬£¬£¬ £¬Êý¾Ý¿ÉÄÜÀ´×ÔÓ¢ÌØ¶û×ÊÔ´ÓëÉè¼ÆÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-leak-20gb-of-source-code-internal-docs-from-alleged-breach/


2.TIMÑо¿Ö°Ô±ÔÚWowzaÁ÷ýÌåÒýÇæÖз¢Ã÷4¸öеÄ0day


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


TIM RTRµÄÑо¿Ö°Ô±ÔÚWOWZAÁ÷ÒýÇæ²úÆ·Öз¢Ã÷ÁË4¸öеÄÁãÈÕÎó²î£¬£¬£¬£¬£¬ £¬»®·ÖΪí§ÒâÎļþÏÂÔØÎó²î£¨CVE-2019-19454£©£¬£¬£¬£¬£¬ £¬Â·¾¶±éÀúÎó²î£¨CVE-2019-19455£©ºÍÁ½¸ö¿çÕ¾¾ç±¾Îó²î£¨CVE-2019-19453ºÍCVE-2019-19456£©¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔ±»Ô¶³Ì¹¥»÷ÕßÁ¬ÏµÊ¹Ó㬣¬£¬£¬£¬ £¬ÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ £¬²¢¿ÉÒÔͨ¹ýÓû§½çÃæÁÙËùÓÐÊý¾ÝµÄ¾ÙÐлá¼û¡£¡£¡£¡£¡£¡£¡£¸ÃÍŶÓÔÚÉϸöÔ»¹Åú¶ÁËÁ½¸öÑÏÖØµÄ0day£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËOracle Business IntelligenceµÄ²úÆ·¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/106804/hacking/wowza-streaming-engine-zerodays.html?utm_source=rss&utm_medium=rss&utm_campaign=wowza-streaming-engine-zerodays


3.McAfee·¢Ã÷¸¨Öú»úеÈËTemi±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬ £¬¿É±»Ð®ÖÆ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


McAfeeµÄ¸ß¼¶ÍþвÑо¿£¨ATR£©Ð¡×é·¢Ã÷½»»¥Ê½¸¨Öú»úеÈËTemi±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬ £¬»®·ÖΪʹÓÃÓ²±àÂëÆ¾Ö¤£¨ CVE-2020-16170£©¡¢Ô­Ê¼ÑéÖ¤¹ýʧ£¨ CVE-2020-16168£©¡¢È±ÉÙÒªº¦¹¦Ð§µÄÉí·ÝÑéÖ¤£¨ CVE-2020-16167£©ÒÔ¼°Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨ CVE-2020-16169£©¡£¡£¡£¡£¡£¡£¡£McAfeeÌåÏÖ£¬£¬£¬£¬£¬ £¬ºÚ¿Í¿ÉÒÔÁ¬ÏµÊ¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬ £¬ÎÞÐèÉí·ÝÑéÖ¤±ãÄܼàÊÓTemiµÄÊÓÆµÍ¨»°£¬£¬£¬£¬£¬ £¬×èµ²ÓëÁíÒ»¸öÓû§µÄͨ»°£¬£¬£¬£¬£¬ £¬ÉõÖÁÔ¶³Ì²Ù¿ØTemi¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·µÄÉú²úÉÌÔÚ»ñµÃÎó²î±¨¸æºó£¬£¬£¬£¬£¬ £¬Á¬Ã¦¶ÔÆä¾ÙÐÐÁËÐÞ¸´¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/black-hat-healthcare-senior-living-temi-robots-can-be-hijacked-remotely-by-hackers/#ftag=RSSbaffb68


4.ºÚ¿Í¿ÉʹÓÃMicrosoft TeamsµÄ¸üгÌÐò×°ÖöñÒâÈí¼þ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Trustwave SpiderLabsÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬ £¬ºÚ¿Í¿ÉʹÓÃMicrosoft TeamsµÄ¸üгÌÐò×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÓÚÈ¥ÄêÊ״α»¹ûÕæ£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔ´ÓÍⲿURLÏÂÔØ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬È»ºóʹÓÃÊÜÐÅÈΣ¨ÊðÃû£©µÄ¿ÉÖ´ÐÐÎļþ¾ÙÐÐ×°Öᣡ£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±JayapaulÖØÐÂÑо¿Á˸ÃÎÊÌ⣬£¬£¬£¬£¬ £¬·¢Ã÷¸üгÌÐòÔÊÐíͨ¹ý¹²Ïí»òÍâµØÎļþ¼Ð¾ÙÐÐÍâµØÅþÁ¬ÒÔ¾ÙÐвúÆ·¸üУ¬£¬£¬£¬£¬ £¬Òò´Ë¹¥»÷Õß¿ÉÒÔ½¨ÉèÒ»¸öÔÊÐíÔ¶³Ì¹«¹²»á¼ûµÄSambaЧÀÍÆ÷²¢½¨ÉèÔ¶³Ì¹²Ïí£¬£¬£¬£¬£¬ £¬ÒÔÈÆ¹ý½«¶ñÒâÈí¼þÏÂÔØµÄ°ì·¨£¬£¬£¬£¬£¬ £¬Microsoft Teams½«Á¬Ã¦´ÓÔ¶³ÌλÖûñÈ¡²¢ÔËÐÐÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/microsoft-teams-patch-bypass-rce/158043/


5.TwitterÐÞ¸´ÆäAndroid°æ±¾Îó²î£¬£¬£¬£¬£¬ £¬¿Éµ¼ÖÂ˽ÈËÊý¾Ýй¶


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


TwitterÐÞ¸´ÆäAndroid°æ±¾Îó²î£¬£¬£¬£¬£¬ £¬¸ÃÎó²î¿Éµ¼Ö¶ñÒâAndroidÓ¦Óûá¼û˽ÓÐTwitterÊý¾Ý£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËAndroid 8£¨Oreo£©ºÍAndroid 9£¨Pie£©µÄÓû§¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²î£¬£¬£¬£¬£¬ £¬ÔÚÊÜÓ°Ïì×°±¸ÉÏ×°ÖöñÒâÓ¦ÓóÌÐòÈÆ¹ýAndroidϵͳµÄȨÏÞ£¬£¬£¬£¬£¬ £¬À´»á¼ûTwitterÉϵÄ˽ÈËÊý¾Ý£¬£¬£¬£¬£¬ £¬ºÃ±ÈÖ±½ÓÐÂÎÅ£¨DM£©¡£¡£¡£¡£¡£¡£¡£TwitterÌåÏÖ¸ÃÎó²îÊÇÓÉÓÚAndroid²Ù×÷ϵͳ×Ô¼º±£´æµÄÎó²îµ¼Öµģ¬£¬£¬£¬£¬ £¬¿ÉÊDz¢Î´Í¸Â¶ÓйØÎó²îµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/twitter-patches-android-app-to-prevent-exploitation-of-bug-that-can-grant-access-to-dms/#ftag=RSSbaffb68


6.¼ÑÄܹÙÍøÔâµ½Maze¹¥»÷£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÉù³ÆÒÑÇÔÈ¡10 TBÊý¾Ý


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


¼ÑÄܹÙÍøÔâµ½MazeÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÉù³ÆÒÑÇÔÈ¡10 TBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ó°ÏìÁ˼ÑÄܵĵç×ÓÓʼþϵͳ¡¢Microsoft Teams¡¢ÆäÃÀ¹úµÄÍøÕ¾ÒÔ¼°ÆäËûÄÚ²¿Ó¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬£¬ £¬¼ÑÄܹÙÍøimage.canonÓÚ2020Äê7ÔÂ30ÈÕå´»ú£¬£¬£¬£¬£¬ £¬²¢ÔÚÁùÌìºóµÄ8ÔÂ4ÈղŻָ´£¬£¬£¬£¬£¬ £¬¿ÉÊÇMaze×éÖ¯ÌåÏÖ²¢²»ÊÇÓÉÀÕË÷Èí¼þÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£MazeÌåÏÖÆä͵ȡÁË10 TBÊý¾ÝºÍ˽ÓÐÊý¾Ý¿âµÈ£¬£¬£¬£¬£¬ £¬µ«¾Ü¾øÍ¸Â¶Óйع¥»÷µÄ½øÒ»²½ÐÅÏ¢£¬£¬£¬£¬£¬ £¬°üÀ¨Êê½ðÊý¶î¡¢Êý¾Ý±»µÁÖ¤¾ÝÒÔ¼°¼ÓÃÜ×°±¸µÄÊýÄ¿¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/canon-hit-by-maze-ransomware-attack-10tb-data-allegedly-stolen/