¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181129

Ðû²¼Ê±¼ä 2018-11-29
1¡¢FBIÁªºÏGoogleµÈ¶à¼ÒÇå¾²³§É̴ݻٴó¹æÄ£¹ã¸æÚ²Æ­ÍÅ»ï3ve

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


FBIÁªºÏGoogle¡¢White OpsÒÔ¼°ProofpointµÈ¶à¼ÒÇå¾²³§ÉÌÅäºÏ´Ý»ÙÁËÒ»¸ö¹ã¸æÚ²Æ­ÍŻ¡£¡£¡£¡£¡£¡£¸ÃÔÚÏßڲƭ»î¶¯±»³ÆÎª3ve£¬£¬£¬£¬£¬£¬×Ô2014ÄêÆðÒ»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬µ«ÔÚÈ¥ÄêÀ©´óÁËÆä»î¶¯¹æÄ££¬£¬£¬£¬£¬£¬Îª¹¥»÷Õß´øÀ´ÁËÁè¼Ý3000ÍòÃÀÔªµÄÊÕÈë¡£¡£¡£¡£¡£¡£¡£3veѬȾÁËÁè¼Ý170Íǫ̀ÅÌËã»ú£¬£¬£¬£¬£¬£¬Ê¹ÓÃ80¶ą̀ЧÀÍÆ÷±¬·¢¶ñÒâÁ÷Á¿£¬£¬£¬£¬£¬£¬²¢¹¹½¨ÁËÁè¼Ý1Íò¸ö´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Ôڻá¯ÁëʱÆÚ£¬£¬£¬£¬£¬£¬3veͬʱ²Ù¿ØÁËÁè¼Ý100Íò¸öIPµØµã£¬£¬£¬£¬£¬£¬ÆäÖðÈÕڲƭ¹ã¸æÍ¶·ÅÁ¿´ï30µ½120ÒڴΡ£¡£¡£¡£¡£¡£¡£±¾ÖܶþÃÀ¹ú˾·¨²¿ÆðËßÁËÓë¸Ã¹ã¸æÚ²Æ­»î¶¯ÓйصÄ8Ãû·¸·¨ÏÓÒÉÈË¡£¡£¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/3ve-ad-fraud-google.html


2¡¢Çå¾²³§ÉÌ·¢Ã÷É­º£Èû¶ûµÄHeadSetupÈí¼þÒ×ÊÜSSLÖÐÐÄÈ˹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Secorvo·¢Ã÷¶ú»ú³§ÉÌÉ­º£Èû¶ûµÄÅäÌ×Èí¼þHeadSetup±£´æÒ»¸öÇå¾²Îó²î£¨CVE-2018-17612£©£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂSSLÖÐÐÄÈ˹¥»÷¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃÈí¼þÔÚ×°ÖÃʱ»áÔÚÓû§ÅÌËã»úÉÏ×°ÖÃÒ»¸ö¸ùÖ¤ÊéºÍ¼ÓÃܵÄÖ¤Êé˽Կ£¬£¬£¬£¬£¬£¬²¢ÇÒÕâÁ½¸öÎļþ¶ÔËùÓÐÓû§¶¼ÊÇÏàͬµÄ¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÔÚÐ¶ÔØÊ±Ò²²»»áɾ³ýÖ¤ÊéÎļþ£¬£¬£¬£¬£¬£¬Ê¹µÃÓû§¼ÌÐøÒ×Êܹ¥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¤Êé˽ԿËäÈ»±»¼ÓÃÜÁË£¬£¬£¬£¬£¬£¬µ«Ê¹ÓõÄÊÇAES-128-CBCËã·¨¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬²¢ÇÒÃÜÔ¿ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚ´úÂëÖУ¨WBCCListener.dll£©¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sennheiser-headset-software-could-allow-man-in-the-middle-ssl-attacks/


3¡¢Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ·ÇÓªÀûÒ½ÁÆ»ú¹¹Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßµÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ9ÔÂ22ÈÕÖÁ9ÔÂ29ÈÕʱ´ú£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢°ü¹ÜÐÅÏ¢¡¢Ð§ÀÍÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅºÍÕË»§Óà¶îµÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÉÐÓпìÒª70Íò¸öÉç±£ºÅÂëй¶£¬£¬£¬£¬£¬£¬µ«Ã»ÓвÆÎñÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯Òѽ«Ïà¹ØÊÂÎñ֪ͨFBI£¬£¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/atrium-health-data-breach-exposed-2-65-million-patient-records/


4¡¢ElasticSearchЧÀÍÆ÷̻¶Áè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²³§ÉÌHackenµÄÑо¿Ö°Ô±Bob Diachenkoͨ¹ýShodan·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄElasticSearchЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÆäÊý¾Ý¿â̻¶ÁËÁè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¼Òͥסַ¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂëºÍIPµØµãµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÎÞ·¨È·ÈϸÃЧÀÍÆ÷µÄËùÓÐÕߣ¬£¬£¬£¬£¬£¬µ«ËûÒÔΪ¼ÓÄôóÊý¾Ý¹«Ë¾Data£¦Leads»òÐíÓëÖ®ÓйØ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃЧÀÍÆ÷Òѱ»¾ÙÐÐÇå¾²¼Ó¹Ì¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/elasticsearch-server-exposed-the-personal-data-of-over-57-million-us-citizens/


5¡¢¿¨°Í˹»ùÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿¨°Í˹»ùʵÑéÊÒÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬¶ñÒâÍÚ¿óÈí¼þͨ³£Í¨¹ý¹ã¸æÈí¼þ¡¢ÆÆ½âÓÎÏ·»òÆäËüµÁ°æÄÚÈݽøÈëÓû§ºÍÆóÒµµÄÅÌËã»ú£¬£¬£¬£¬£¬£¬²¢ÇÒ½¨Éè¶ñÒâÍÚ¿óÈí¼þµÄÃż÷Ò²Ô½À´Ô½µÍ¡£¡£¡£¡£¡£¡£¡£2018ÄêÍ·¶ñÒâÍÚ¿ó¹¥»÷¿ìËÙÔöÌí£¬£¬£¬£¬£¬£¬ËæºóÅãͬ׿ÓÃÜÇ®±Ò¼ÛÇ®µÄϽµ¶ñÒâÍÚ¿ó»î¶¯ÓÖÏÔÖøÏ½µ£¬£¬£¬£¬£¬£¬µ«¸ÃÍþвÈÔÈ»½ûֹСêï¡£¡£¡£¡£¡£¡£¡£ËäȻһЩ¹ú¼Ò¶Ô¼ÓÃÜÇ®±Ò¾ÙÐÐÁ¢·¨¿ØÖÆ£¬£¬£¬£¬£¬£¬µ«ÕâЩ¹ú¼ÒµÄ¶ñÒâÍÚ¿ó»î¶¯²¢Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-2018-story-of-the-year-miners/89096/


6¡¢Î÷ÃÅ×ÓÅû¶SIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Î÷ÃÅ×ÓÕë¶ÔSIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²îÐû²¼¾¯±¨¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Î÷ÃÅ×ÓµÄ˵·¨£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁ˹̼þ°æ±¾ÎªV2.6.0µÄGNU/Linux×Óϵͳ£¬£¬£¬£¬£¬£¬²¢ÇÒ½«ÔÚÏÂÒ»¸ö¹Ì¼þ°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£¡£Ïà¹ØÎó²îµÄÊýĿΪ21¸ö£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼Ö¾ܾøÐ§ÀÍ¡¢í§Òâ´úÂëÖ´ÐкÍÓû§Ã¶¾ÙµÈÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Ôڹ̼þ¸üÐÂÐû²¼Ö®Ç°£¬£¬£¬£¬£¬£¬Î÷ÃÅ×Ó½¨ÒéÓû§Ó¦ÓÃÎ÷ÃÅ×ÓÉî¶È·ÀÓù²½·¥²¢ÇÒ×èÖ¹ÔËÐв»¿ÉÐÅȪԴµÄ³ÌÐò¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-warns-linux-gnu-flaws-controller-platform



ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí