¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181224
Ðû²¼Ê±¼ä 2018-12-24
Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/2¡¢ÐÂÊÖÒÕÖ§³ÖÕ©ÆÒ³Ã潫µ¼ÖÂChromeä¯ÀÀÆ÷¿¨ËÀ

Google ChromeµÄbug±¨¸æÖÐÅû¶ÁËÒ»¸öеÄÊÖÒÕÖ§³Öթƻ£¬£¬£¬£¬£¬¸ÃÕ©ÆÍøÒ³½«Ê¹ÓÃJavaScriptÑ»·ºÄ¾¡ÅÌËã»úµÄCPU×ÊÔ´²¢µ¼ÖÂChrome¿¨ËÀ¡£¡£¡£¡£¡£¸ÃÍøÒ³µÄÎÊÌâΪ¡°Ö÷ÒªÐÅÏ¢¡±£¬£¬£¬£¬£¬Î±×°³ÉÌáÐÑѬȾµÄWindows¹ýʧ¾¯±¨£¬£¬£¬£¬£¬´ËÒ³Ãæ°üÀ¨µÄJavaScript½«Ê¹ä¯ÀÀÖØÊÓ¸´Ìø×ªÖÁ# URL£¬£¬£¬£¬£¬²¢Íù·µµã»÷ÍËÈ´ºÍǰ½ø°´Å¥£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂCPUÕ¼ÓÃ100%¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýɱËÀChromeÀú³ÌÀ´¿¢Ê¿¨ËÀÇéÐΡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-tech-support-scam-causes-chrome-browser-to-use-100-percent-of-the-cpu/3¡¢Õë¶ÔGmailºÍYahooÕÊ»§µÄд¹ÂÚ¹¥»÷¿ÉÈÆ¹ýSMS 2FAÑéÖ¤

ƾ֤¹ú¼ÊÌØÉâ×éÖ¯µÄ±¨¸æ£¬£¬£¬£¬£¬¸Ã×éÖ¯·¢Ã÷Á½ÆðÕë¶ÔÖж«ºÍ·ÇÖÞÖܱߵØÇøµÄÔ¼1000ÃûÈËȨÖ÷ÒåÕߵĴ¹Âڻ¡£¡£¡£¡£¡£ÕâЩ´¹Âڻαװ³ÉÕË»§¾¯±¨£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔʹÓûùÓÚSMSµÄ2FAÑéÖ¤ÒªÁìµÄGmailºÍYahooÕÊ»§¡£¡£¡£¡£¡£ÕâЩ»î¶¯»¹Õë¶ÔÁ˸üΪרҵµÄµç×ÓÓʼþЧÀÍ£¬£¬£¬£¬£¬ÀýÈçProtonMailºÍTutanota£¬£¬£¬£¬£¬Ö»¹ÜËüÃÇĬÈϽÓÄÉÁׯü¸ß¼¶±ðµÄÇå¾²ÐÔºÍÒþ˽ÐÔ¡£¡£¡£¡£¡£Ö¤¾ÝÅúעijЩ°¸ÀýÖÐYahooºÍGmailµÄSMS 2FA±»ÀÖ³ÉÈÆ¹ý£¬£¬£¬£¬£¬µ«Ã»ÓÐProtonMailºÍTutanotaÕË»§Êܵ½Ë𺦡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://nakedsecurity.sophos.com/2018/12/21/more-phishing-attacks-on-yahoo-and-gmail-sms-2fa-authentication/4¡¢Õë¶ÔOrangeµ÷ÖÆ½âµ÷Æ÷µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬£¬£¬£¬£¬ÊÔͼ»ñÈ¡WiFiÃÜÂë

Bad Packets LLCÑо¿Ö°Ô±Troy Mursch·¢Ã÷¹¥»÷ÕßÕýÔÚ´ó¹æÄ£É¨ÃèOrange Livebox ADSLµ÷ÖÆ½âµ÷Æ÷¡£¡£¡£¡£¡£¸ÃɨÃè»î¶¯ÓÚ12ÔÂ21ÈÕÐÇÆÚÎå×îÏÈ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃOrange LiveBox×°±¸ÖеÄÎó²î£¨CVE-2018-20377£©À´»ñÈ¡WiFiÍøÂçµÄSSIDºÍÃÜÂë¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷½ü19.5Íò¸öÒ×Êܹ¥»÷µÄOrangeµ÷ÖÆ½âµ÷Æ÷£¬£¬£¬£¬£¬¾ø´ó´ó¶¼Î»ÓÚ·¨¹úºÍÎ÷°àÑÀ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/over-19000-orange-modems-are-leaking-wifi-credentials/5¡¢Ñо¿Ö°Ô±Åû¶Facebookµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬µ«Facebook²»ÍýÏëÐÞ¸´

²¨À¼Çå¾²Ñо¿Ö°Ô±·¢Ã÷FacebookµÄAndroidÒÆ¶¯°æ±¾±£´æÒ»¸öµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýiframe±êǩʹÓøÃÎó²îÔÚÓû§µÄFacebookÉÏÐû²¼Á´½Ó¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÎó²îÓëFacebookµÄÌØ¶¨APIŲÓúöÂÔÁËX-Frame-Options±êÍ·Óйأ¬£¬£¬£¬£¬¸Ã±êÍ·¿ÉÒÔ֪ͨä¯ÀÀÆ÷ÊÇ·ñ¼ÓÔØiFrameÍøÒ³¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½«ÍøÒ³¼ÓÔØµ½ÓÕ¶üÍøÒ³µÄ¶¥²ãÖУ¨²»¿É¼ûµÄiFrame£©£¬£¬£¬£¬£¬Óû§½«Íû¼ûÓÕ¶üÍøÒ³£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÓë¸ÃiFrame¾ÙÐн»»¥¡£¡£¡£¡£¡£FacebookÒÔΪÕâ²»ÊÇÒ»¸öÇå¾²ÎÊÌ⣬£¬£¬£¬£¬ÓÉÓÚËüûÓÐÓ°Ïìµ½Óû§ÕË»§µÄÍêÕûÐÔ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/the-clickjacking-bug-that-facebook-wont-fix/6¡¢¼ÌÓ¢¹úºÍºÉÀ¼Ö®ºó£¬£¬£¬£¬£¬UberÔÙ±»·¨¹úÊý¾Ý±£»£»£»¤»ú¹¹·£¿£¿£¿î40ÍòÅ·Ôª

2016ÄêUberÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬µ¼ÖÂÈ«ÇòÔ¼5700ÍòÓû§ºÍ˾»úµÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬£¬£¬µ«Ö±µ½Ò»Äê¶àÒÔºóµÄ2017Äê11Ô¸ù«Ë¾²ÅÏòÍâ½çÅû¶ÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£2018Äê9Ô£¬£¬£¬£¬£¬UberÔÞ³ÉÏòÃÀ¹ú¸çÂ×±ÈÑÇÌØÇøÖ§¸¶1.48ÒÚÃÀÔªµÄÏ¢Õù½ð¡£¡£¡£¡£¡£2018Äê11Ô£¬£¬£¬£¬£¬Ó¢¹úºÍºÉÀ¼µÄÊý¾Ý±£»£»£»¤»ú¹¹»®·ÖÏòUber·£¿£¿£¿î38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿£¿£¿î¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬·¨¹úµÄÊý¾Ý±£»£»£»¤»ú¹¹ÔÙ´ÎÏòÆä·£¿£¿£¿î40ÍòÅ·Ôª¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/79104/security/frence-agency-fines-uber.htmlÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí