Äê¹Ø½«ÖÁ£¡2018£¡
Ðû²¼Ê±¼ä 2019-01-25¡¾Îó²îÔ¤¾¯¡¿WebLogic CVE-2018-2628·´ÐòÁл¯Îó²î¸´ÏÖ
¡¾Ô´´Îó²î¡¿WebLogic·´ÐòÁл¯Îó²îCVE-2018-2893Ô¤¾¯
¡¾Ô´´Îó²î¡¿Weblogic·´ÐòÁл¯Îó²îCVE-2018-3245Ô¤¾¯
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷WebLogic±£´æÉÏÊö·´ÐòÁл¯Îó²î£¬Îó²îÓ°ÏìWebLogic 10.3.6.0¡¢12.1.3.0¡¢12.2.1.2¡¢12.2.1.3¶à¸ö°æ±¾¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýT3ÐÒé¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³Ì¹¥»÷£¬²¢¿É»ñÈ¡Ä¿µÄϵͳËùÓÐȨÏÞ¡£
¡¾Îó²îÔ¤¾¯¡¿ºáºÓµç»úSTARDOM¿ØÖÆÆ÷±£´æ¸ßΣÎó²î
¡¾Îó²îÔ¤¾¯¡¿LinuxÄں˱£´æTCPÇå¾²Îó²î£¨CVE-2018-5390£©
Îó²î¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÎÞÐèÈκÎȨÏÞÔÚÊÜÓ°ÏìµÄLinuxÉè±¹ØÁ¬¼ÖÂÔ¶³Ì¾Ü¾ø·þÎñ¡£ÄÚºË4.9¼°ÒÔÉϵÄLinux°æ±¾¾ùÊÜÎó²îÓ°Ï죬ÊÜÓ°ÏìµÄ×°±¸°üÀ¨×°ÖÃÁËÉÏÊöÄں˵ÄÅÌËã»úƽ̨¼°LinuxǶÈëʽװ±¸¡£
¡¾Îó²îÔ¤¾¯¡¿Apache Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨S2-057£©
¡¾Îó²îÔ¤¾¯¡¿Win10 ±£´æÍâµØÌáȨ0dayÎó²î
Windows 10ϵͳÖÐÒ»¸öÍâµØÌáȨ0dayÎó²î£¬±£´æÓÚWindowsµÄʹÃüµ÷Àí·þÎñÖУ¬ÔÊÐí¹¥»÷Õß´ÓUSERȨÏÞÌáȨµ½SYSTEMȨÏÞ¡£Îó²î¿ÉÓ°ÏìWindows 10ºÍWindows Server 2016¡£
¡¾Îó²îÔ¤¾¯¡¿Adobe ColdFusion ·´ÐòÁл¯Îó²î
ÎïÁªÍøרÌâÆÊÎö
ÖÇÄÜÃÅËøÍøÂçÇå¾²ÆÊÎö±¨¸æ
2017ÄêÖÇÄÜÃÅËø²úÖµÁè¼Ý°ÙÒÚÔª£¬Êг¡¹æÄ£¿¿½ü800Íò°Ñ£¬Ô¤¼Æ2020ÄêÖÇÄÜÃÅËøÊг¡¹æÄ£½«µÖ´ï4000Íò°Ñ¡£ ÖÇÄÜÃÅËøµÄÇå¾²½«»áÖ±½Óµ¼ÖÂСÎÒ˽¼ÒºÍ¼ÒÍ¥µÄÉúÃü¹¤ÒµÇå¾²£¬±¾±¨¸æÖصã¹Ø×¢ÖÇÄÜÃÅËøµÄÍøÂçÇå¾²ÎÊÌâ¡£
VPNFilter£ºÎ£¼°È«Çò¹¤¿Ø×°±¸ºÍ°ì¹«ÍøÂçµÄÎïÁªÍø¸ß¼¶Íþв
VPNFilterÊÇÒ»ÆðÒÔÈëÇÖÎïÁªÍøΪÔØÌå´ÓÊ¿ÉÄÜÓɹú¼ÒÌᳫµÄÈ«ÇòÐԸ߼¶¶ñÒâÈí¼þ¹¥»÷£¬ÖÁÉÙÓÐ50Íǫ̀װ±¸ÔâÊÜѬȾ¡£±¾±¨¸æ¶ÔΣ¼°¹¤¿Ø¼°°ì¹«ÍøÂçµÄÎïÁªÍøÌع¤Èí¼þVPNFilter¾ÙÐÐÉîÈëÆÊÎö£¬ÏêÊöC&C±»¶¯»ñÈ¡µÄSYNËíµÀÊÖÒÕ¡£
ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÔÚºã¾ÃµÄ½©Ê¬Éú̬Ñо¿ÆÊÎöÖз¢Ã÷Ò»¿îÎïÁªÍø½©Ê¬±»ÆÕ±éµØÖ²ÈëÁ˺Úȸ£¬Í¨¹ýËÝÔ´ÆÊÎöÈ·ÈÏÊÇÒ»ÖÖÖ§³Ö¶àCPUƽ̨µÄDdostf½©Ê¬ÍøÂç¼Ò×å±äÖÖ¡£±¾±¨¸æÖصãÏÈÈÝÆäºÚȸ¹¥»÷µÄÔÀíÒÔ¼°¡°¶¾ÉϼӶ¾¡±µÄÕ÷Ïó¡£
ÐÛÂõ¶à¸öÉãÏñÍ·Îó²îÔ¤¾¯¼°ÐÞ¸´£¨¸½¹¤¾ß£©
ºÚ¿Í¹¥»÷ÓëÍþвÆÊÎö
¶ãÔÚP2PÈä³æÍøÂç±³ºóµÄÓÄÁ飺DridexÈä³æÐÂÐͱäÖÖ̽ÃØ£¨¸½×¨É±¹¤¾ß£©
DridexÒÑÐγɼ¯Èä³æ¡¢½©Ê¬¡¢ÇÔÃÜľÂí¡¢ÀÕË÷Èí¼þ¡¢P2PÊðÀíÓÚÒ»ÉíµÄ»ìÏýÐÍÈä³æ²¡¶¾¡£ÔÚÇÔÃܹ¦Ð§ÉÏ£¬Ëü²»µ«¿ÉÇÔÈ¡ÖÖÖÖÖ÷Á÷Óʼþ¿Í»§¶ËÒÔ¼°ä¯ÀÀÆ÷ÉúÑĵĵǼƾ֤£¬»¹»áÍøÂçÒøÐС¢ÐÅÓÿ¨µÈµÇ¼ºÍÖ§¸¶Æ¾Ö¤£¬Î£º¦¼«´ó¡£
Ê׿îʹÓÃFirebaseÔÆÐÂÎÅת´ï»úÖƵĸ߼¶Ìع¤Èí¼þ
¸ÃÌع¤Èí¼þÊÇÏÖÔÚAndroidƽ̨ÉÏ×îΪǿʢµÄ¶ñÒâÓ¦ÓÃÖ®Ò»£¬¿ÉʵÏÖÔ¶³ÌrootÌáÉýµ½×î¸ßȨÏÞ£¬²¢ÇÒʵÏÖÁËAndroid²ãµÄÃô¸ÐÐÅÏ¢ÇÔÈ¡£¬ÉõÖÁʵÏÖÁËLinux²ãÃæµÄ¡°·´µ¯Shell¡±ÒÔµÖ´ïÆä¶ÔÄ¿µÄ×°±¸µÄÍêÈ«¿ØÖÆ¡£±¾ÎÄÖصãÆÊÎöÑù±¾Android¶ËµÄ¸÷¸ö·þÎñºÍ¿ØÖƵÄÂß¼²¿·Ö¡£
Crysis¼Ò×åÀÕË÷²¡¶¾×îбäÖÖÆÊÎö
Crysis¼Ò×åбäÖÖ×åÖ÷Ҫͨ¹ý´¹ÂÚÓʼþºÍʹÓÃRDP±¬ÆƾÙÐÐÈö²¥£¬ÆäʹÓüÓÃܵÄshellcode£¬ÔÚshellcodeÖÐʹÓû»ÌåÊÖÒÕ¶Ô³ÌÐòµØµã¿Õ¼ä¾ÙÐÐÐ޸ģ¬ÒÔµÖ´ï×ÌÈÅɱ¶¾Èí¼þµÄ²éɱºÍ¶Ô¿¹¶þ½øÖÆÆÊÎöµÄÄ¿µÄ¡£
ÐÂÐÍÀÕË÷²¡¶¾BadCkatαװ³É·¨Ôº´«Æ±¾ÙÐй¥»÷
BadCkatÊÇÒ»¿îʹÓá°EDA2¡±¿ªÔ´ÀÕË÷ÏîĿˢжø³ÉµÄÀÕË÷²¡¶¾£¬ÔÚÌìϹæÄ£ÄÚ¾ÙÐÐÆÕ±éµÄ¹¥»÷Ô˶¯¡£¸ÃÀÕË÷²¡¶¾½ö¶ÔÎļþÍ·µÄ²¿·ÖÊý¾Ý¾ÙÐмÓÃÜ£¬Òò´Ë¼ÓÃÜËÙÂʼ«¿ì£¬Í¬Ê±µÖ´ïÁËÆÆËð³ÌÐòÕý³£ÔËÐУ¬Îĵµ¼ÓÃܲ»¿É·¿ªµÄÄ¿µÄ¡£
Ê׿ÀÕË÷¡¢Ìع¤¡¢ÒøÐÐľÂíÓÚÒ»ÌåµÄÐÂÐÍ×ÛºÏÐÍAndroid²¡¶¾Éî¶ÈÆÊÎö
ÐÂÐͲ¡¶¾ÊµÏÖÁ˼ÓÃÜÀÕË÷¡¢¼üÅ̼ͼ¡¢Ô¶³Ì»á¼ûľÂí¡¢¶ÌÐÅ×èµ²¡¢ºô½ÐתÒƺÍËø¶¨ÆÁÄ»µÈ¹¦Ð§£¬¿ÉЮÖÆÏÕЩº¸ÇÌìϸ÷´ó½ðÈÚ»ú¹¹µÄÊÖ»úAPP£¬×ÜÊýÓÐ300¶à¸ö£¬Éæ¼°Öйú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾¡¢ÖйúÏã¸ÛµÈ40¶à¸ö¹ú¼ÒºÍµØÇø¡£
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷´ó×Ú×ÅÃûÈí¼þ×°ÖóÌÐò±»Ö²Èë¡°×°ÖÃÓÄÁ顱Íڿ󲡶¾£¬¸Ã²¡¶¾±³ºóµÄºÚ¿ÍÊÔͼͨ¹ýÈí¼þ¹²ÏíÂÛ̳µÈÇþµÀÐû²¼À¦°óÓиò¡¶¾µÄÊ¢ÐÐÓ¦ÓõÄÆƽâ°æ±¾£¬Éæ¼°Ó¦Óù²¼Æ26ÖÖ£¬Á¬Í¬²î±ðµÄ°æ±¾¹²Ðû²¼ÓÐ99¸öÖ®¶à¡£
Çå¾²Îó²îÆÊÎö
CPU¡°ÓÄÁ顱Îó²îÆÊÎöÓëÑéÖ¤
CPUµ×²ãÎó²îÇå¾²ÊÂÎñÒѲ¨¼°È«ÇòÏÕЩËùÓеÄÊÖ»ú¡¢µçÄÔ¡¢ÔÆÅÌËã²úÆ·¡£¡°ÓÄÁ顱Îó²î¿ÉÔì³ÉÊܱ£»¤µÄÃÜÂë¡¢Ãô¸ÐÐÅϢй¶¡£±¾ÎÄÖصã¶Ô¡°ÓÄÁ顱µÄÎó²îÔÀí¡¢Îó²îÑéÖ¤¡¢Î£º¦¼°·À»¤¾ÙÐÐÏÈÈÝ¡£
WPA2¡°KRACK¡±Îó²î¼ò½éÓëÖØÏÖ
ÎÞÏßÍøÂçÐÒéWPA2±£´æ¸ßΣÎó²î£¬Îó²îÔÊÐí¹¥»÷Õß¼àÌýAPºÍ½ÓÈëµãSTAÖ®¼ä´«ÊäµÄWi-FiÊý¾ÝÁ÷Á¿£¬ÀíÂÛÉÏËùÓÐÖ§³ÖWPA2µÄ¿Í»§¶Ë¶¼½«Êܵ½¡°KRACK¡±¹¥»÷µÄÓ°Ïì¡£ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabͨ¹ý¶ÔÈ«ÁãÃÜÔ¿Îó²îµÄÆÊÎöÀÖ³ÉÖØÏÖ¡°KRACK¡±¹¥»÷¡£
DrupalÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2018-7600)ÆÊÎöÓëÑéÖ¤
Drupal 6.x¡¢7.x¡¢8.x¶à¸ö×Ó°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÎó²î£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂ룬²¢¿ØÖÆʹÓÃDrupalµÄÕ¾µã¡£Îó²î±£´æÓÚÓû§×¢ÊéÒ³Ã棬ÒÔÊÇÈκÎÄäÃû¹¥»÷Õ߶¼¿ÉÒÔ´¥·¢£¬Î£º¦Ë®Æ½½Ï¸ß¡£
WebKitä¯ÀÀÆ÷Îó²îÃæÃæ¹Û
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab¶ÔWebKitÒýÇæ¾ÙÐÐÎó²îÍÚ¾òºÍ´úÂëÉó¼Æʱ£¬·¢Ã÷Webkit±£´æ¶à¸öÇå¾²Îó²î¡£±¾ÎÄÏêϸÆÊÎöWebKit¸÷Ä£¿éµÄÎó²î°¸Àý£¬¶Ô WebKitä¯ÀÀÆ÷Îó²îÃæ¾ÙÐÐÖÜÈ«ÐðÊö¡£
AndroidÀ¶ÑÀ×é¼þÎó²îÁ¬Á¬¿´
AndroidϵͳÖУ¬À¶ÑÀ×é¼þ¿ÉÒÔ˵ÊÇÇå¾²Îó²îÖØÔÖÇø¡£±¾ÎÄÖصãÏÈÈÝÀ¶ÑÀÐÒéÕ»ÖеÄL2CAPÐæźÍSMPÐÒ飬²¢¶ÔCVE-2018-9359ºÍCVE-2018-9365ÕâÁ½¸öÎó²î°¸Àý¾ÙÐÐÏêϸÆÊÎö¡£
ThinkPHP5Ô¶³Ì´úÂëÖ´ÐÐÎó²îÆÊÎö
Îó²îÊÇÓÉÓÚ·ÓÉÆÊÎöȱÏÝËùµ¼Ö£¬Î£º¦Ë®Æ½ºÜÊǸߣ¬Ä¬ÈÏÇéÐÎÉèÖü´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¾ÓÉÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab¶ÔThinkPHPµÄ56¸öС°æ±¾µÄÔ´ÂëÆÊÎöºÍÑéÖ¤£¬È·¶¨ÏêϸÊÜÓ°ÏìµÄ°æ±¾ÎªThinkPHP 5.0.5-5.0.22¡¢5.1.0-5.1.30¡£
ChakraÒýÇæÖÐJIT±àÒëÓÅ»¯Àú³ÌÖеÄÊý×éÀàÐÍ»ìÏýÎó²îÆÊÎö
Çø¿éÁ´×¨ÌâÆÊÎö
СÐÄÖÇÄܺÏÔ¼Îó²î£ºÇø¿éÁ´Éϵġ°¿ÕÆø¡±±Ò
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab½üÄêÀ´Ò»Á¬¹Ø×¢Çø¿éÁ´ÊÖÒÕÇå¾²ÎÊÌ⣬ͨ¹ý¶ÔÒÔÌ«·»Ö÷Á´ÖÇÄܺÏÔ¼¾ÙÐÐÑо¿£¬·¢Ã÷ÁË400¶à¸öCVEÎó²î¡£Ê¹ÓÃÖÇÄܺÏÔ¼Îó²î¹¥»÷Õß¿É¿ØÖÆÊг¡ÉϵÄÇ®±Ò×ÜÁ¿»òí§ÒâÕË»§µÄÇ®±ÒÁ¿£¬Ê¹ÔÀ´¾ÍÎÞêµÄÇ®±Ò³¹µ×ʧȥÐÅÓ㬳ÉΪ¡°¿ÕÆø¡±±Ò¡£
Ê׸öÇø¿éÁ´tokenµÄ×Ô¶¯»¯Þ¶Ñòë¹¥»÷ÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÍŽáµç×ӿƼ¼´óѧ³ÂÌü¸±½ÌÊÚ×·×Ùµ½ÒÔÌ«·»tokenÖеÄÊ׸ö×Ô¶¯»¯Þ¶Ñòë¹¥»÷ÊÂÎñ¡£tokenÃû³ÆΪSimoleon (SIM)£¬Óп¿½ü57ÍòÕË»§³ÖÓиúÏÔ¼µÄtoken¡£¹¥»÷Õßͨ¹ý°²ÅŹ¥»÷ºÏÔ¼»ñµÃÁËÁè¼Ý700ÍòµÄtoken£¬Ò»¾Ù³ÉΪ¸ÃºÏÔ¼tokenµÄµÚËÄ´ó³ÖÓÐÕß¡£
´ÓsolidityÓïÑÔÌØÕ÷Éî¶È½â¶ÁÒÔÌ«·»ÖÇÄܺÏÔ¼Îó²îÔÀíºÍ¹¥»÷ʹÓÃ
ÖÇÄܺÏÔ¼µÄ¿ª·¢ÓïÑÔ¡¢Éè¼Æģʽ¡¢ÔËÐлúÖƶ¼Óë¹Å°åÓ¦ÓÃÓнϴó²î±ð¡£±¾±¨¸æÒÔWCTF2018µÄÒ»µÀÖÇÄܺÏÔ¼Îó²îÈüÌâΪÀý£¬´ÓsolidityÓïÑÔÌØÕ÷³ö·¢£¬Éî¶È½â¶ÁÒÔÌ«·»ÖÇÄܺÏÔ¼Îó²îÔÀíºÍ¹¥»÷ʹÓá£
God.GameÖÇÄܺÏÔ¼¹¥»÷ÊÂÎñÆÊÎö
2018Äê8Ô£¬God.GameÔÚÒÔÌ«·»Çø¿éÁ´ÉÏ°²ÅÅÆäºÏÔ¼ºóµÚ¶þÌì±ã±»ÍµÈ¡ÁË243¸öÒÔÌ«±Ò£¬¼ÛÖµÁè¼Ý6ÍòÃÀÔª¡£¾ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÏêϸÆÊÎöºÍÖØÏÖ£¬·¢Ã÷¹¥»÷ÕßÊÇͨ¹ý¶à´Î´¥·¢GodºÏÔ¼µÄ²î±ðÓªÒµÂß¼×îÖÕÔì³ÉÕûÊýÒç³ö¡£
ÒÔÌ«·»ÖÇÄܺÏÔ¼¶à¸ö¹¥»÷°¸ÀýÆÊÎö
ÔÚÖÚ¶àÖÇÄܺÏÔ¼¹¥»÷°¸ÀýÖУ¬ÓÐЩÎó²î³ÉÒò»ò¹¥»÷ģʽÉÙÓÐÑо¿Éæ¼°£¬Ò²·ºÆðÁËһЩ½ÏÁ¿Òþ²ØµÄ¹¥»÷Á´¡£±¾ÎÄÖصã´ÓʹÓÃOraclize·þÎñµÄÊèºö¡¢ÅÓÊÏ´ú±ÒºÏÔ¼Îó²î¡¢SafeMathʹÓò»µ±µÈ³ÉÒòÈëÊÖÆÊÎöºÚ¿Í¹¥»÷ÐÐΪ¡£