Intel´øÍâ¸üÐÂÐÞ¸´¿ÉÈÆ¹ýCPUÄþ¾²½çÏÞµÄReptar©¶´

Ðû²¼Ê±¼ä 2023-11-16
1¡¢Intel´øÍâ¸üÐÂÐÞ¸´¿ÉÈÆ¹ýCPUÄþ¾²½çÏÞµÄReptar©¶´


¾Ý11ÔÂ15ÈÕ±¨µÀ£¬IntelÐÞ¸´ÁËÒ»¸öÓ°ÏìÆą̈ʽ»ú¡¢Òƶ¯É豸ºÍ·þÎñÆ÷CPUµÄ©¶´£¨CVE-2023-23583£©¡£ËüÔ´ÓÚ´¦ÖÃÆ÷ÈçºÎ½âÊÍÈßÓàǰ׺µÄÎÊÌ⣬¿ÉÓÃÀ´ÌáÉýȨÏÞ¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ·ÃÎÊȨÏÞ»ò´¥·¢¾Ü¾ø·þÎñ״̬¡£Google·¢ÏÖ²¢Åû¶Á˸é¶´µÄϸ½Ú£¬ËûÃǽ«ÆäÃüÃûΪReptar£¬²¢Í¸Â¶ÀÖ³ÉÀûÓû¹¿ÉÄÜÈÆ¹ýCPUµÄÄþ¾²½çÏÞ¡£Ó¢Ìضû½¨Ò龡¿ì¸üÐÂÊÜÓ°ÏìµÄ´¦ÖÃÆ÷£¬OSVÒ²¿É¾¡¿ìÌṩ°üÂÞ´ËÐÂ΢ÂëµÄ¸üС£


https://thehackernews.com/2023/11/reptar-new-intel-cpu-vulnerability.html


2¡¢ÈýÐǵç×ÓÔٴη¢ÉúÊý¾Ýй¶£¬Ö÷ÒªÓ°ÏìÓ¢¹úµÄ¿Í»§


¾ÝýÌå11ÔÂ15ÈÕ±¨µÀ£¬ÈýÐǵç×ÓÏò²¿Ãſͻ§Í¨±¨ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ¡£11ÔÂ13ÈÕ£¬ÈýÐÇ·¢ÏÖÁË´Ë´ÎÊý¾Ýй¶Ê¼þ£¬²¢È·¶¨ÕâÊǺڿÍÀûÓøù«Ë¾µÄµÚÈý·½Ó¦Ó÷¨Ê½ÖеÄ©¶´µ¼ÖµÄ£¬µ«ÊÇδÌṩ¹¥»÷ϸ½Ú¡£¸Ã¹«Ë¾ÌåÏÖ£¬´Ë´Îʼþ½öÓ°ÏìÁËÔÚ2019Äê7ÔÂ1ÈÕÖÁ2020Äê6ÔÂ30ÈÕÆÚ¼ä£¬´ÓÈýÐÇÓ¢¹úµÄÔÚÏßÉ̵깺ÎïµÄ¿Í»§¡£ÕâÊÇÈýÐÇÔÚÁ½ÄêÄÚÔâµ½µÄµÚÈý´ÎÊý¾Ýй¶¡£


https://www.bleepingcomputer.com/news/security/samsung-hit-by-new-data-breach-impacting-uk-store-customers/


3¡¢ÃÀ¹úB2BÒ©·¿Æ½Ì¨Truepillй¶230ÍòÓû§µÄÐÅÏ¢


ýÌå11ÔÂ14Èճƣ¬ÃÀ¹úÒ©µê¹©Ó¦ÉÌTruepillй¶ÁË2364359È˵ÄÐÅÏ¢¡£TruepillÊÇÒ»¸öרעÓÚB2BµÄÒ©·¿Æ½Ì¨£¬Ê¹ÓÃAPIΪÃÀ¹ú50¸öÖݵÄÒ½ÁƱ£½¡»ú¹¹Ìṩ¶©µ¥Ö´Ðкͽ»¸¶·þÎñ¡£¸Ã¹«Ë¾ÓÚ8ÔÂ31ÈÕ·¢ÏÖδ¾­ÊÚȨµÄ·ÃÎÊ£¬ÊÓ²ìÏÔʾ¹¥»÷ÕßÔÚǰһÌì»ñµÃÁË·ÃÎÊȨÏÞ¡£¸Ã¹«Ë¾¿ÉÄÜÃæÁÙÖ´·¨ºó¹û£¬È«¹ú¸÷µØ¶¼ÔÚ×¼±¸¶àÆð¼¯ÌåËßËÏ¡£¾ßÌåÀ´Ëµ£¬Ëüδ¶ÔÆä·þÎñÆ÷ÉÏ´æ´¢µÄÃô¸ÐÒ½ÁÆÐÅÏ¢½øÐмÓÃÜ£¬ÑÓ³Ù֪ͨÏû·ÑÕߣ¬ÒÔ¼°Í¨ÖªµÄÄÚÈݹýÓÚº¬ºý¡£


https://www.bleepingcomputer.com/news/security/pharmacy-provider-truepill-data-breach-hits-23-million-customers/


4¡¢VMwareÅû¶ÐµÄÉí·ÝÑéÖ¤ÈÆ¹ý©¶´CVE-2023-34060


11ÔÂ15ÈÕ±¨µÀ³Æ£¬VMwareÅû¶ÁËÆäCloud Director ApplianceÖÐÒ»¸öÑÏÖØµÄÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2023-34060£©¡£ÓµÓÐÉè±¸ÍøÂç·ÃÎÊȨÏ޵Ĺ¥»÷Õߣ¬¿ÉÔÚͨ¹ý¶Ë¿Ú22£¨ssh£©»ò¶Ë¿Ú5480£¨É豸¹ÜÀí¿ØÖÆÌ¨£©½øÐÐÉí·ÝÑéÖ¤Ê±ÈÆ¹ýµÇ¼ÏÞÖÆ¡£ÔÚ¶Ë¿Ú443£¨VCDÌṩÉ̺Í×â»§µÇ¼£©ºÍа²×°µÄCloud Director Appliance 10.5Éϲ»´æÔÚ´ËÈÆ¹ýÎÊÌâ¡£ËäÈ»VMwareÉÐδÕë¶ÔÕâһ©¶´Ðû²¼²¹¶¡£¬µ«¸Ã¹«Ë¾ÌṩÁËÁÙʱ½â¾öÒªÁì¡£


https://securityaffairs.com/154182/security/vmware-cloud-director-appliance-critical-flaw.html


5¡¢WP Fastest Cache²å¼þSQL×¢Èë©¶´Ó°Ïì60Íò¸öÍøÕ¾

 

WPScanÍŶÓÔÚ11ÔÂ14ÈÕÅû¶ÁËWordPress²å¼þWP Fastest CacheÖеÄSQL×¢Èë©¶´£¨CVE-2023-6063£©¡£Í³¼ÆÊý¾ÝÏÔʾ£¬Áè¼Ý60Íò¸öÍøÕ¾ÈÔÔÚÔËÐиòå¼þ´æÔÚ©¶´µÄ°æ±¾¡£Â©¶´´æÔÚÓÚ²å¼þWpFastestCacheCreateCacheÀàµÄis_user_adminº¯ÊýÖУ¬¸Ãº¯Êýͨ¹ý´ÓcookieÖÐÌáÈ¡$usernameÖµÀ´¼ì²éÓû§ÊÇ·ñÊǹÜÀíÔ±¡£ÓÉÓÚ$usernameµÄÊäÈëδ¾­¹ý¾»»¯£¬¹¥»÷Õß¿ÉÄÜ»áÀûÓôËcookieÖµÀ´¸ü¸Ä²å¼þÖ´ÐеÄSQL²éѯ£¬´Ó¶øµ¼Ö¶ÔÊý¾Ý¿âδ¾­ÊÚȨµÄ·ÃÎÊ¡£


https://wpscan.com/blog/unauthenticated-sql-injection-vulnerability-addressed-in-wp-fastest-cache-1-2-2/


6¡¢KasperskyÐû²¼¹ØÓÚ2024ÄêAPT»î¶¯Ì¬ÊƵÄÔ¤²â³ÂËß


11ÔÂ14ÈÕ£¬KasperskyÐû²¼¹ØÓÚ2024ÄêAPT»î¶¯Ì¬ÊƵÄÔ¤²â³ÂËß¡£¸Ã³ÂËß¶Ô2024ÄêµÄÔ¤²â°üÂÞ£ºÀûÓÃÒÆ¶¯É豸ºÍ¿É´©×ÅÉ豸ÒÔ¼°ÖÇÄÜÉ豸µÄÇé¿öÔö¼Ó¡¢ÀûÓÃÏû·ÑÕßºÍÆóÒµÈí¼þ¼°É豸¹¹½¨ÐµĽ©Ê¬ÍøÂç¡¢ÄÚºËrootkitÔÙ´ÎÁ÷ÐС¢Óë¹ú¼ÒÏà¹ØµÄÍøÂç¹¥»÷Ôö¶à¡¢ÍøÂçÕ½ÖеĺڿÍÐж¯Ôö¼Ó¡¢¹©Ó¦Á´¹¥»÷¼´·þÎñÔö¶à¡¢ÀûÓÿɷÃÎʵÄÉú³ÉʽÈ˹¤ÖÇÄÜÀ©´óÓã²æÊ½µöÓã¹¥»÷µÄ·¶Î§¡¢·ºÆð¸ü¶àÌṩºÚ¿Í¹ÍÓ¶·þÎñµÄÍÅÌåÒÔ¼°MFTϵͳ´¦ÓÚÍøÂçÍþвµÄ×îÇ°ÑØµÈ¡£


https://securelist.com/kaspersky-security-bulletin-apt-predictions-2024/111048/