Intel´ø±í¸üн¨¸´¿ÉÈÆ¹ýCPU°²È«ÌìǵµÄReptar·ì϶
°ä²¼¹¦·ò 2023-11-16¾Ý11ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Intel½¨¸´ÁËÒ»¸öÓ°ÏìÆą̈ʽ»ú¡¢Òƶ¯É豸ºÍ·þÎñÆ÷CPUµÄ·ì϶£¨CVE-2023-23583£©¡£¡£¡£¡£¡£¡£ËüÔ´ÓÚ´¦ÖÃÆ÷ÈôºÎÚ¹ÊÍÈßÓàǰ׺µÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÌáÉýȨÏÞ¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢µÄ½Ó¼ûȨÏÞ»ò´¥·¢»Ø¾ø·þÎñ״̬¡£¡£¡£¡£¡£¡£Google·¢ÏÖ²¢Åû¶Á˸÷ì϶µÄϸ½Ú£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǽ«Æä¶¨ÃûΪReptar£¬£¬£¬£¬£¬£¬£¬£¬²¢Ð¹Â©³É¹¦ÀûÓû¹¿ÉÄÜÈÆ¹ýCPUµÄ°²È«Ììǵ¡£¡£¡£¡£¡£¡£Ó¢Ìضû½¨Ò龡¿ì¸üÐÂÊÜÓ°ÏìµÄ´¦ÖÃÆ÷£¬£¬£¬£¬£¬£¬£¬£¬OSVÒ²¿É¾¡¿ìÌṩÔ̺¬´ËÐÂ΢ÂëµÄ¸üС£¡£¡£¡£¡£¡£
https://thehackernews.com/2023/11/reptar-new-intel-cpu-vulnerability.html
2¡¢ÈýÐǵç×ÓÔٴβúÉúÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÓ°ÏìÓ¢¹úµÄ¿Í»§
¾ÝýÌå11ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÈýÐǵç×ÓÏò²¿Ãſͻ§´«µÝÁËһ·Êý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£11ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÈýÐÇ·¢ÏÖÁËÕâ´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬²¢È·¶¨ÕâÊǺڿÍÀûÓøù«Ë¾µÄµÚÈý·½ÀûÓ÷¨Ê½Öеķì϶µ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇδÌṩ¹¥»÷ϸ½Ú¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ½öÓ°ÏìÁËÔÚ2019Äê7ÔÂ1ÈÕÖÁ2020Äê6ÔÂ30ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬£¬´ÓÈýÐÇÓ¢¹úµÄÔÚÏßÉ̵깺ÎïµÄ¿Í»§¡£¡£¡£¡£¡£¡£ÕâÊÇÈýÐÇÔÚÁ½ÄêÄÚÔâµ½µÄµÚÈý´ÎÊý¾Ýй¶¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/samsung-hit-by-new-data-breach-impacting-uk-store-customers/
3¡¢ÃÀ¹úB2BÒ©·¿Æ½Ì¨Truepillй¶230ÍòÓû§µÄÐÅÏ¢
ýÌå11ÔÂ14Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÒ©µê¹©¸øÉÌTruepillй¶ÁË2364359È˵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£TruepillÊÇÒ»¸öרһÓÚB2BµÄÒ©·¿Æ½Ì¨£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃAPIΪÃÀ¹ú50¸öÖݵÄÒ½ÁƱ£½¡»ú¹¹Ìṩ¶©µ¥Ö´Ðкͽ»¸¶·þÎñ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ8ÔÂ31ÈÕ·¢ÏÖδ¾ÊÚȨµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬µ÷²éÏÔʾ¹¥»÷ÕßÔÚǰһÌì»ñµÃÁ˽ӼûȨÏÞ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾¿ÉÄÜÃæ¶Ô˾·¨ºó¹û£¬£¬£¬£¬£¬£¬£¬£¬È«¹ú¸÷µØ¶¼Ôڳﱸ¶àÆð¼¯ÌåËßËÏ¡£¡£¡£¡£¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬Ëüδ¶ÔÆä·þÎñÆ÷ÉÏ´æ´¢µÄÃô¸ÐÒ½ÁÆÐÅÏ¢½øÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬£¬ÑÓ³¤Í¨ÖªÏû·ÑÕߣ¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Í¨ÖªµÄÄÚÈݹýÓÚ³éÏ󡣡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/pharmacy-provider-truepill-data-breach-hits-23-million-customers/
4¡¢VMwareÅû¶ÐµÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶CVE-2023-34060
11ÔÂ15ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬£¬VMwareÅû¶ÁËÆäCloud Director ApplianceÖÐÒ»¸öÑϳÁµÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-34060£©¡£¡£¡£¡£¡£¡£Õ¼ÓÐÉè±¸ÍøÂç½Ó¼ûȨÏ޵Ĺ¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚͨ¹ý¶Ë¿Ú22£¨ssh£©»ò¶Ë¿Ú5480£¨É豸ÖÎÀí½ÚÔį̀£©½øÐÐÉí·ÝÑéÖ¤Ê±ÈÆ¹ýµÇ¼ÏÞ¶È¡£¡£¡£¡£¡£¡£ÔÚ¶Ë¿Ú443£¨VCDÌṩÉ̺Í×â»§µÇ¼£©ºÍÐÂ×°ÖõÄCloud Director Appliance 10.5Éϲ»´æÔÚ´ËÈÆ¹ýÎÊÌâ¡£¡£¡£¡£¡£¡£¹ÌÈ»VMwareÉÐδÕë¶ÔÕâÒ»·ì϶°ä²¼²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾ÌṩÁËһʱ½â¾ö²½Öè¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/154182/security/vmware-cloud-director-appliance-critical-flaw.html
5¡¢WP Fastest Cache²å¼þSQL×¢Èë·ì϶ӰÏì60Íò¸öÍøÕ¾
WPScanÍŶÓÔÚ11ÔÂ14ÈÕÅû¶ÁËWordPress²å¼þWP Fastest CacheÖеÄSQL×¢Èë·ì϶£¨CVE-2023-6063£©¡£¡£¡£¡£¡£¡£Í³¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý60Íò¸öÍøÕ¾ÈÔÔÚÔËÐиòå¼þ´æÔÚ·ì϶µÄ°æ±¾¡£¡£¡£¡£¡£¡£·ì϶´æÔÚÓÚ²å¼þWpFastestCacheCreateCacheÀàµÄis_user_adminº¯ÊýÖУ¬£¬£¬£¬£¬£¬£¬£¬¸Ãº¯Êýͨ¹ý´ÓcookieÖÐÌáÈ¡$usernameÖ·´²é³Óû§ÊÇ·ñÊÇÖÎÀíÔ±¡£¡£¡£¡£¡£¡£ÓÉÓÚ$usernameµÄÊäÈëδ¾¹ý¾»»¯£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áÀûÓôËcookieÖ·´¸ü¸Ä²å¼þÖ´ÐеÄSQL²éÎÊ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¶ÔÊý¾Ý¿âδ¾ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£
https://wpscan.com/blog/unauthenticated-sql-injection-vulnerability-addressed-in-wp-fastest-cache-1-2-2/
6¡¢Kaspersky°ä²¼¹ØÓÚ2024ÄêAPT»î¶¯Ì¬ÊƵÄÔ¤²â»ã±¨
11ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼¹ØÓÚ2024ÄêAPT»î¶¯Ì¬ÊƵÄÔ¤²â»ã±¨¡£¡£¡£¡£¡£¡£¸Ã»ã±¨¶Ô2024ÄêµÄÔ¤²âÔ̺¬£ºÀûÓÃÒÆ¶¯É豸ºÍ¿É´©´÷É豸ÒÔ¼°ÖÇÄÜÉ豸µÄÇé¿öÔö³¤¡¢ÀûÓÃÏû·ÑÕßºÍÆóÒµÈí¼þ¼°É豸¹¹½¨ÐµĽ©Ê¬ÍøÂç¡¢ÄÚºËrootkitÔٴηçÐÓ×¢Óë¹ú¶ÈÓйصÄÍøÂç¹¥»÷Ôö¶à¡¢ÍøÂçÕ½ÖеĺڿÍÐж¯Ôö³¤¡¢¹©¸øÁ´¹¥»÷¼´·þÎñÔö¶à¡¢ÀûÓÿɽӼûµÄÌìÉúʽÈËΪÖÇÄÜÀ©´óÓã²æÊ½´¹µö¹¥»÷µÄÁìÓò¡¢³öÏÖ¸ü¶àÌṩºÚ¿Í¹ÍÓ¶·þÎñµÄ¼¯ÌåÒÔ¼°MFTϵͳ´¦ÓÚÍøÂçÍþвµÄ×îÇ°ÑØµÈ¡£¡£¡£¡£¡£¡£
https://securelist.com/kaspersky-security-bulletin-apt-predictions-2024/111048/


¾©¹«Íø°²±¸11010802024551ºÅ