Intel´øÍâ¸üÐÂÐÞ¸´¿ÉÈÆ¹ýCPUÇå¾²½çÏßµÄReptarÎó²î

Ðû²¼Ê±¼ä 2023-11-16
1¡¢Intel´øÍâ¸üÐÂÐÞ¸´¿ÉÈÆ¹ýCPUÇå¾²½çÏßµÄReptarÎó²î


¾Ý11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬IntelÐÞ¸´ÁËÒ»¸öÓ°ÏìÆą̈ʽ»ú¡¢Òƶ¯×°±¸ºÍЧÀÍÆ÷CPUµÄÎó²î£¨CVE-2023-23583£©¡£¡£¡£¡£¡£¡£¡£¡£ËüÔ´ÓÚ´¦Öóͷ£Æ÷ÔõÑùÚ¹ÊÍÈßÓàǰ׺µÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÌáÉýȨÏÞ¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ»á¼ûȨÏÞ»ò´¥·¢¾Ü¾øÐ§ÀÍ״̬¡£¡£¡£¡£¡£¡£¡£¡£Google·¢Ã÷²¢Åû¶Á˸ÃÎó²îµÄϸ½Ú£¬£¬£¬£¬£¬£¬£¬ËûÃǽ«ÆäÃüÃûΪReptar£¬£¬£¬£¬£¬£¬£¬²¢Í¸Â¶ÀÖ³ÉʹÓû¹¿ÉÄÜÈÆ¹ýCPUµÄÇå¾²½çÏß¡£¡£¡£¡£¡£¡£¡£¡£Ó¢Ìضû½¨Ò龡¿ì¸üÐÂÊÜÓ°ÏìµÄ´¦Öóͷ£Æ÷£¬£¬£¬£¬£¬£¬£¬OSVÒ²¿É¾¡¿ìÌṩ°üÀ¨´ËÐÂ΢ÂëµÄ¸üС£¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/11/reptar-new-intel-cpu-vulnerability.html


2¡¢ÈýÐǵç×ÓÔٴα¬·¢Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÓ¢¹úµÄ¿Í»§


¾ÝýÌå11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÈýÐǵç×ÓÏò²¿·Ö¿Í»§×ª´ïÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£11ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬ÈýÐÇ·¢Ã÷ÁË´Ë´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢È·¶¨ÕâÊǺڿÍʹÓøù«Ë¾µÄµÚÈý·½Ó¦ÓóÌÐòÖеÄÎó²îµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇδÌṩ¹¥»÷ϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñ½öÓ°ÏìÁËÔÚ2019Äê7ÔÂ1ÈÕÖÁ2020Äê6ÔÂ30ÈÕʱ´ú£¬£¬£¬£¬£¬£¬£¬´ÓÈýÐÇÓ¢¹úµÄÔÚÏßÊÐËÁ¹ºÎïµÄ¿Í»§¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÈýÐÇÔÚÁ½ÄêÄÚÔâµ½µÄµÚÈý´ÎÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/samsung-hit-by-new-data-breach-impacting-uk-store-customers/


3¡¢ÃÀ¹úB2BÒ©·¿Æ½Ì¨Truepillй¶230ÍòÓû§µÄÐÅÏ¢


ýÌå11ÔÂ14Èճƣ¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÒ©µê¹©Ó¦ÉÌTruepillй¶ÁË2364359È˵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£TruepillÊÇÒ»¸öרעÓÚB2BµÄÒ©·¿Æ½Ì¨£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃAPIΪÃÀ¹ú50¸öÖݵÄÒ½ÁƱ£½¡»ú¹¹Ìṩ¶©µ¥Ö´Ðкͽ»¸¶Ð§ÀÍ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ8ÔÂ31ÈÕ·¢Ã÷δ¾­ÊÚȨµÄ»á¼û£¬£¬£¬£¬£¬£¬£¬ÊÓ²ìÏÔʾ¹¥»÷ÕßÔÚǰһÌì»ñµÃÁË»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾¿ÉÄÜÃæÁÙÖ´·¨Ð§¹û£¬£¬£¬£¬£¬£¬£¬Ììϸ÷µØ¶¼ÔÚ×¼±¸¶àÆðÕûÌåËßËÏ¡£¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬Ëüδ¶ÔÆäЧÀÍÆ÷ÉÏ´æ´¢µÄÃô¸ÐÒ½ÁÆÐÅÏ¢¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÑÓ³Ù֪ͨÏûºÄÕߣ¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Í¨ÖªµÄÄÚÈݹýÓÚÃÔºý¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/pharmacy-provider-truepill-data-breach-hits-23-million-customers/


4¡¢VMwareÅû¶ÐµÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îCVE-2023-34060


11ÔÂ15ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬VMwareÅû¶ÁËÆäCloud Director ApplianceÖÐÒ»¸öÑÏÖØµÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34060£©¡£¡£¡£¡£¡£¡£¡£¡£ÓµÓÐ×°±¸ÍøÂç»á¼ûȨÏ޵Ĺ¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬¿ÉÔÚͨ¹ý¶Ë¿Ú22£¨ssh£©»ò¶Ë¿Ú5480£¨×°±¸ÖÎÀí¿ØÖÆÌ¨£©¾ÙÐÐÉí·ÝÑéÖ¤Ê±ÈÆ¹ýµÇ¼ÏÞÖÆ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¶Ë¿Ú443£¨VCDÌṩÉ̺Í×â»§µÇ¼£©ºÍÐÂ×°ÖõÄCloud Director Appliance 10.5Éϲ»±£´æ´ËÈÆ¹ýÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»VMwareÉÐδÕë¶ÔÕâÒ»Îó²îÐû²¼²¹¶¡£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾ÌṩÁËÔÝʱ½â¾öÒªÁì¡£¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/154182/security/vmware-cloud-director-appliance-critical-flaw.html


5¡¢WP Fastest Cache²å¼þSQL×¢ÈëÎó²îÓ°Ïì60Íò¸öÍøÕ¾

 

WPScanÍŶÓÔÚ11ÔÂ14ÈÕÅû¶ÁËWordPress²å¼þWP Fastest CacheÖеÄSQL×¢ÈëÎó²î£¨CVE-2023-6063£©¡£¡£¡£¡£¡£¡£¡£¡£Í³¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬Áè¼Ý60Íò¸öÍøÕ¾ÈÔÔÚÔËÐиòå¼þ±£´æÎó²îµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£Îó²î±£´æÓÚ²å¼þWpFastestCacheCreateCacheÀàµÄis_user_adminº¯ÊýÖУ¬£¬£¬£¬£¬£¬£¬¸Ãº¯Êýͨ¹ý´ÓcookieÖÐÌáÈ¡$usernameÖµÀ´¼ì²éÓû§ÊÇ·ñÊÇÖÎÀíÔ±¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ$usernameµÄÊäÈëδ¾­Óɾ»»¯£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áʹÓôËcookieÖµÀ´¸ü¸Ä²å¼þÖ´ÐеÄSQLÅÌÎÊ£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¶ÔÊý¾Ý¿âδ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£¡£


https://wpscan.com/blog/unauthenticated-sql-injection-vulnerability-addressed-in-wp-fastest-cache-1-2-2/


6¡¢KasperskyÐû²¼¹ØÓÚ2024ÄêAPT»î¶¯Ì¬ÊƵÄÕ¹Íû±¨¸æ


11ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬KasperskyÐû²¼¹ØÓÚ2024ÄêAPT»î¶¯Ì¬ÊƵÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ¶Ô2024ÄêµÄÕ¹Íû°üÀ¨£ºÊ¹ÓÃÒÆ¶¯×°±¸ºÍ¿ÉÒÂ×Å×°±¸ÒÔ¼°ÖÇÄÜ×°±¸µÄÇéÐÎÔöÌí¡¢Ê¹ÓÃÏûºÄÕßºÍÆóÒµÈí¼þ¼°×°±¸¹¹½¨ÐµĽ©Ê¬ÍøÂç¡¢ÄÚºËrootkitÔÙ´ÎÊ¢ÐС¢Óë¹ú¼ÒÏà¹ØµÄÍøÂç¹¥»÷Ôö¶à¡¢ÍøÂçÕ½ÖеĺڿÍÐж¯ÔöÌí¡¢¹©Ó¦Á´¹¥»÷¼´Ð§ÀÍÔö¶à¡¢Ê¹Óÿɻá¼ûµÄÌìÉúʽÈ˹¤ÖÇÄÜÀ©´óÓã²æÊ½´¹ÂÚ¹¥»÷µÄ¹æÄ£¡¢·ºÆð¸ü¶àÌṩºÚ¿Í¹ÍӶЧÀ͵ÄÕûÌåÒÔ¼°MFTϵͳ´¦ÓÚÍøÂçÍþвµÄ×îÇ°ÑØµÈ¡£¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/kaspersky-security-bulletin-apt-predictions-2024/111048/