Ñо¿ÈËÔ±³Æ16¸öÀ¶ÑÀ©¶´BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸:ºÚ¿Í³öÊÛ¿ÉÔÚ¶à¸öÆ·ÅƵÄGPU

Ðû²¼Ê±¼ä 2021-09-03

Ñо¿ÈËÔ±³Æ16¸öÀ¶ÑÀ©¶´BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸


Ñо¿ÈËÔ±³Æ16¸öÀ¶ÑÀ©¶´BrakToothÓ°ÏìÊýÊ®ÒÚÉ豸.jpg


Ñо¿ÈËÔ±¼ì²âÁËÀ´×Ô11¸ö¹©Ó¦É̵Ä13¸öƬÉÏϵͳ (SoC) µÄÀ¶ÑÀÈí¼þ¿â £¬·¢ÏÖÁË16¸öÓ°ÏìÀ¶ÑÀÈí¼þ¶ÑÕ»µÄ©¶´²¢Í³³ÆËüÃÇΪBrakTooth ¡£¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ê¹É豸Í߽⠣¬ÉõÖÁÊÇÖ´ÐжñÒâ´úÂë²¢½Ó¹ÜÕû¸öϵͳ ¡£ÕâЩ©¶´ÖÐ×îÑÏÖصÄΪCVE-2021-28139 £¬ÀûÓø鶴Զ³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÀ¶ÑÀLMPÊý¾Ý°üÔÚÄ¿±êÉ豸ÉÏÔËÐжñÒâ´úÂë ¡£²¢·ÇËùÓÐËùÓй©Ó¦É̶¼¼°Ê±Ðû²¼Á˲¹¶¡ £¬µ½Ä¿Ç°ÎªÖ¹ £¬Ö»ÓÐÀÖöΡ¢Ó¢·ÉÁèºÍBluetrumÐû²¼Á˲¹¶¡ £¬¶øµÂÖÝÒÇÆ÷ÔòÌåÏ־ܾøÐÞ¸´Â©¶´ ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/billions-of-devices-impacted-by-new-braktooth-bluetooth-vulnerabilities/


Rapid7·¢ÏÖ¿ÉÔ¶³Ì½ûÓÃFortress WiFiÄþ¾²ÏµÍ³µÄ©¶´


Rapid7·¢ÏÖ¿ÉÔ¶³Ì½ûÓÃFortress WiFiÄþ¾²ÏµÍ³µÄ©¶´.jpg


Rapid7Ñо¿ÈËÔ±ÓÚ8ÔÂ31ÈÕÅû¶ÁËFortress S03 WiFi¼ÒÍ¥Äþ¾²ÏµÍ³ÖеÄ2¸ö©¶´µÄϸ½Ú ¡£¸ÃÄþ¾²ÏµÍ³¿ÉÒÔΪÓû§¹¹½¨×Ô¼ºµÄ¾¯±¨ÏµÍ³À´±£»¤Æä¼ÒÍ¥ £¬ËüÖ§³ÖÄþ¾²¼à¿Ø¡¢ÃÅ´°´«¸ÐÆ÷ÒÔ¼°ÑÌÎí¾¯±¨Æ÷µÈÉ豸 ¡£ÕâÁ½¸ö©¶´·Ö±ðΪCVE-2021-39276ºÍCVE-2021-39277 £¬¹¥»÷Õß¿ÉÒÔÏÈÀûÓÃÇ°Õß²éѯAPI²¢»ñÈ¡Ä¿±êÓû§µÄIMEIºÅÂë £¬Ö®ºóÀûÓøúÅÂë¾Í¿ÉÒÔ·¢ËÍδ¾­Éí·ÝÑéÖ¤µÄPOSTÇëÇóÀ´¸ü¸ÄϵͳµÄÅäÖà £¬°üÂÞ½ûÓøÃÄþ¾²ÏµÍ³ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121679/hacking/fortress-s03-home-security-system-flaws.html


MarketoÉù³ÆÒÑÇÔÈ¡ÈÕ±¾Í¨ÐŹ«Ë¾¸»Ê¿Í¨4GBµÄÊý¾Ý


MarketoÉù³ÆÒÑÇÔÈ¡ÈÕ±¾Í¨ÐŹ«Ë¾¸»Ê¿Í¨4GBµÄÊý¾Ý.jpg


MarketoÓÚ8ÔÂ26ÈÕÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏÐû²¼ £¬ËüÕýÔÚ³öÊÛ´ÓÈÕ±¾Í¨ÐŹ«Ë¾¸»Ê¿Í¨ÇÔÈ¡µÄ4GBµÄÊý¾Ý ¡£¸ÃÍŻﻹ³ÆÕâЩÐÅÏ¢ÓëËûÃǵĿͻ§Ïà¹Ø £¬°üÂÞ¿Í»§ÐÅÏ¢¡¢¹«Ë¾Êý¾Ý¡¢Ô¤ËãÊý¾Ý¡¢³ÂËߺÍÏîÄ¿ÐÅÏ¢µÈ ¡£¸»Ê¿Í¨·¢ÑÔÈËÌåÏÖÉв»Çå³þÕâЩÊý¾ÝµÄй¶Դ £¬¶øMarketo¹ûÈ»µÄ24.5MBµÄÑù±¾Êý¾ÝÖÐ £¬°üÂÞÁ˲¿ÃÅÓëÁíÒ»¼ÒÈÕ±¾¹«Ë¾Toray IndustriesÓйصÄÊý¾Ý ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/data-from-fujitsu-is-being-sold-on-dark.html


ÒÁÀûŵÒÁÖÝÒ½ÔºDMG³ÆÆäÔ¼60Íò»¼ÕßµÄÐÅϢй¶


ÒÁÀûŵÒÁÖÝÒ½ÔºDMG³ÆÆäÔ¼60Íò»¼ÕßµÄÐÅϢй¶.jpg


ÒÁÀûŵÒÁÖÝ×î´óµÄ¶ÀÁ¢Ò½ÁÆ×éÖ¯DuPage Medical Group(DMG)ÓÚ±¾ÖÜÒ»Ðû²¼Í¨Öª £¬³ÆÆä60Íò»¼ÕßµÄÐÅϢй¶ ¡£DMGÌåÏÖ´Ë´Îй¶Ê¼þÓëÆäÔÚ7ÔÂ13ÈÕ·¢ÉúµÄÍøÂçÖжÏÓйØ £¬¾­ÊӲ칥»÷ÕßÔÚ7ÔÂ12ÈÕÖÁ13ÈÕ·ÃÎÊÁËDMGµÄÍøÂç ¡£8ÔÂ17ÈÕ £¬¸Ã×é֯ȷ¶¨²¿ÃÅ»¼ÕßµÄÐÅÏ¢ÒѾ­Ð¹Â¶ £¬²¢½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓüà¿ØºÍÉí·ÝµÁÓñ£»¤ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/dupage-medical-data-breach/


ºÚ¿Í³öÊÛ¿ÉÔÚ¶à¸öÆ·ÅƵÄGPUÉÏÖ´Ðеļ¼Êõ²¢Ðû²¼PoC


ºÚ¿Í³öÊÛ¿ÉÔÚ¶à¸öÆ·ÅƵÄGPUÉÏÖ´Ðеļ¼Êõ²¢Ðû²¼PoC.jpg


¹¥»÷ÕßÀûÓöñÒâÈí¼þ¿ÉÒÔ´ÓÊÜѬȾϵͳµÄͼÐδ¦Öõ¥Ôª(GPU)ÖÐÖ´ÐдúÂë ¡£ËäÈ»¸ÃÒªÁì²¢²»ÐÂÏÊ £¬µ«Æù½ñΪֹ´ËÀ๥»÷ҪôÀ´×ÔѧÊõ½ç £¬ÒªÃ´ÊÇδ¾­ÍêÉÆµÄ ¡£ÏÖÔÚÄê8Ô £¬ÓкڿÍÔÚÂÛ̳ÖгöÊÛÏà¹ØµÄPoC £¬Õâ±êÖ¾×Å´ËÀ๥»÷¿ÉÄÜÒѹý¶Éµ½ÐµÄÅӴ󼶱𠡣Ŀǰ £¬Âô¼ÒÖ»ÌṩÁ˸ü¼ÊõµÄ¸ÅÊö £¬ËµËüʹÓÃGPUÄڴ滺³åÇøÀ´´æ´¢¶ñÒâ´úÂë²¢Ö´ÐÐ £¬²¢ÌåÏָü¼ÊõÓë2015Äê5ÔÂÐû²¼µÄ»ùÓÚGPUµÄ¶ñÒâÈí¼þJellyFish²¢²»Ïàͬ ¡£


Ô­ÎÄÁ´½Ó£º

bleepingcomputer.com/news/security/cybercriminal-sells-tool-to-hide-malware-in-amd-nvidia-gpus/


CISAºÍFBIÁªºÏÐû²¼ÓÐÊàŦ¼ÙÈÕÀÕË÷¹¥»÷»î¶¯µÄÔ¤¾¯


CISAºÍFBIÁªºÏÐû²¼ÓÐÊàŦ¼ÙÈÕÀÕË÷¹¥»÷»î¶¯µÄÔ¤¾¯.jpg


CISAºÍFBIÔÚ8ÔÂ31ÈÕÐû²¼ÁËÒ»·ÝÁªºÏÄþ¾²Í¨¸æ £¬¾¯¸æÀÕË÷ÔËÓªÍÅ»ïÔÚÖÜÄ©ºÍ¹ú¶¨¼ÙÈÕ·¢¶¯¹¥»÷µÄÇ÷ÊÆ ¡£¸Ã»ú¹¹³Æ £¬ÔÚ½üÈýÄêÖÐÀÕË÷ÔËÓªÍÅ»ïÒ»Ö±ÔÚ½Ú¼ÙÈÕ·¢¶¯¹¥»÷ £¬ÈçDarksideÔÚÖÜÁù¹¥»÷ÁËColonial Pipeline £¬ÒÔ¼°REvilÔÚÃÀ¹úÕóÍö½«Ê¿¼ÍÄîÈÕ¹¥»÷ÁËJBS FoodsµÈ»î¶¯ ¡£Õâ¿ÉÄÜÒòΪ·¸×ïÍÅ»ïÒâʶµ½ £¬ÔÚITÄþ¾²ÍŶÓÏ°à»òÈËÊý½ÏÉÙʱ¹¥»÷¹«Ë¾µÄÍøÂç»á²»ÈÝÒ×±»·¢ÏÖ ¡£FBIºÍCISA½¨ÒéITÄþ¾²ÈËÔ±ÔÚÕâЩʱ¼ä¿ÉÒÔËæʱ´ýÃü ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/cisa-and-the-fbi-warn-of-ransomware-gangs-tendency-of-launching-attacks-over-holidays-and-weekends/