΢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©£»£»ÓÅÒ¿âÔ¼50ÍòÕË»§ÐÅϢй¶

Ðû²¼Ê±¼ä 2019-05-15
1¡¢Î¢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
Öܶþ΢ÈíÐû²¼5ÔÂWindowsÇå¾²¸üУ¬£¬£¬ÐÞ¸´79¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨RDPЧÀÍÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0708£©£¬£¬£¬´ËÎó²îÊÇÔ¤Éí·ÝÑéÖ¤£¬£¬£¬ÎÞÐèÓû§½»»¥£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룻£»ÌáȨ0day£¨CVE-2019-0863£©£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁÖÎÀíԱȨÏÞ£»£»Õë¶ÔIntel CPU MDS¹¥»÷µÄÎó²îÐÞ¸´£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁË2011ÄêÒÔÀ´ÏÕЩËùÓеÄIntel CPU¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/

2¡¢ºÚ¿ÍʹÓÃWhatsapp 0day·Ö·¢Ìع¤Èí¼þPegasus

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
FacebookÐÞ¸´ÁËWhatsAppÖеÄÒ»¸ö0day£¨CVE-2019-3568£©¡£¡£¡£¡£¡£¡£Æ¾Ö¤FacebookÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬¸ÃÎó²îÊÇWhatsApp VOIP¿ÍÕ»ÖеĻº³åÇøÒç³öÎó²î£¬£¬£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËͶñÒâSRTCPÊý¾Ý°üÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓ㬣¬£¬¹¥»÷ÕßʹÓøÃÎó²îÔÚÄ¿µÄÓû§µÄÊÖ»úÉÏ×°ÖÃÒÔÉ«ÁÐNSO¹«Ë¾µÄÌØ¹¤Èí¼þPegasus¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ïà¹Ø±¨¸æ£¬£¬£¬ÉÏÖÜÈÕһλӢ¹úÈËȨ״ʦ¾ÍÔ⵽ʹÓôËÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/hack-whatsapp-vulnerability.html

3¡¢AppleÐû²¼5ÔÂÇå¾²¸üУ¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
AppleÐû²¼5ÔÂÇå¾²¸üУ¬£¬£¬¶Ô¸÷¸ö²úƷϵͳ¾ÙÐÐÁËÉý¼¶£¬£¬£¬°üÀ¨iOS 12.3¡¢tvOS 12.3¡¢watchOS 5.2.1¡¢macOS 10.14.5ºÍHomePod OS 12.3¡£¡£¡£¡£¡£¡£ÐÞ¸´µÄÎó²î°üÀ¨macOS DesktopSevicesÖеÄGatekeeper¼ì²éÈÆ¹ýÎó²î£¨CVE-2019-8589£©¡¢EFIÉí·ÝÑéÖ¤Îó²î£¨CVE-2019-8634£©¡¢iOSÖеÄDoSÎó²î£¨CVE-2019-8626£©¡¢É³ÏäÈÆ¹ýÎó²î£¨CVE-2019-8617£©¡¢Wi-FiÎó²î£¨CVE-2019-8620£©µÈ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/05/14/apple-may-2019-security-updates-fix-numerous-issues/

4¡¢ÓÅÒ¿âµçÉÌÍøÕ¾ÔâºÚ¿Í¹¥»÷£¬£¬£¬Ô¼50ÍòÕË»§ÐÅÏ¢±»Ð¹Â¶

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
¾ÝÅí²©ÉçÐÂÎÅ£¬£¬£¬ÈÕ±¾ÁãÊÛÉÌFast RetailingÌåÏÖÆìÏÂÓÅÒ¿âºÍGUÆ·ÅÆµÄÈÕ±¾¹ÙÍøÔâºÚ¿Í¹¥»÷£¬£¬£¬ºÚ¿Íͨ¹ýײ¿â¹¥»÷»á¼ûÁË461091¸ö¿Í»§ÕË»§¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚ4ÔÂ23ÈÕÖÁ5ÔÂ10ÈÕʱ´ú£¬£¬£¬ÓÉÓÚÊÓ²ìÉÐδ¿¢Ê£¬£¬£¬ÊÜÓ°ÏìµÄÕË»§Êý×Ö¿ÉÄܸü¸ß¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢¹ºÖüͼÒÔ¼°²¿·ÖÐÅÓÿ¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£5ÔÂ13ÈÕFast Retailing½ûÓÃÁËÊÜÓ°ÏìµÄ¿Í»§ÕË»§ÃÜÂ룬£¬£¬²¢ÏòÕâЩ¿Í»§·¢ËÍÁËÃÜÂëÖØÖÃÓʼþ¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ²¢Î´Éæ¼°ÖйúµÄÍøÕ¾¼°ÐÅϢƽ̨¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-access-over-461-000-accounts-in-uniqlo-data-breach/

5¡¢Paterson¹«Á¢Ñ§Ð£ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Áè¼Ý2.3ÍòÕË»§Æ¾Ö¤±»µÁ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
Paterson¹«Á¢Ñ§Ð£ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬23103¸öÕË»§µÄƾ֤±»µÁ¡£¡£¡£¡£¡£¡£ÕâЩƾ֤°üÀ¨×ÀÃæµçÄԵĵǼÕË»§¡¢ÓÊÏäÕË»§ÒÔ¼°Ìõ¼Ç±¾µçÄÔÕË»§µÄµÇ¼ƾ֤£¬£¬£¬ÊÜÓ°ÏìµÄÓû§°üÀ¨Ñ§ÇøµÄÔ±¹¤¡¢ÖÎÀíÔ±¡¢Î÷ϯµÈÊÂÇéÖ°Ô±¡£¡£¡£¡£¡£¡£±»µÁµÄƾ֤´æ´¢ÔÚÒ»¸öÁè¼Ý116000ÐеÄÎļþÖУ¬£¬£¬ÆäÖÐÓû§ÃûÊÇÒÔ´¿Îı¾µÄÐÎʽ´æ´¢µÄ£¬£¬£¬¶øÃÜÂëÊÇÒÔÃÜÎÄÐÎʽ´æ´¢£¬£¬£¬µ«ºÜÈÝÒ×±»ÆÆ½â¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþÁªÏµÁËýÌåÅÁÌØÉ­Ê±±¨£¬£¬£¬³ÆÕâЩÐÅÏ¢ÊÇÔÚ2018Äê10Ô±»µÁ£¬£¬£¬²¢ÌáÒ齫ÕâЩÊý¾Ý³öÊÛ¸ø¸ÃýÌ壬£¬£¬µ«Ôâµ½Á˾ܾø¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/paterson-public-schools-suffered-data-breach-compromising-over-23000-school-district-passwords-ac1bf681

6¡¢Linksys WiFi·ÓÉÆ÷ÐÅϢй¶Îó²î£¬£¬£¬²¨¼°È«Çò2.5Íǫ̀װ±¸

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
Bad PacketsÇå¾²Ñо¿Ô±Troy Mursch·¢Ã÷È«ÇòÓÐÁè¼Ý2.5Íǫ̀LinksysÖÇÄÜWi-Fi·ÓÉÆ÷Êܵ½Ò»¸öÐÅϢй¶Îó²îµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¸ÃÎó²îÀàËÆÓÚ2014ÄêµÄÎó²î£¨CVE-2014-8244£©£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»ñÈ¡´ó×Ú×°±¸Ãô¸ÐÐÅÏ¢£¬£¬£¬°üÀ¨ÒÑÅþÁ¬×°±¸µÄMACµØµã¡¢×°±¸Ãû³Æ¡¢²Ù×÷ϵͳ¡¢·À»ðǽ״̬¡¢WAN/DDNSÉèÖõÈ¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃÎó²îÀíÓ¦ÓÚÎåÄêǰ±»ÐÞ¸´£¬£¬£¬µ«Ä¿½ñÎó²îÈÔÈ»±£´æ£¬£¬£¬²¢ÇÒ±»LinksysÇå¾²ÍŶӱê¼ÇΪ¡°²»ÊÊÓÃ/²»ÐÞ¸´¡±¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/linksys-smart-wi-fi-routers-leak-info-of-connected-devices/