΢ÈíÐû²¼11ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´74¸öÎó²î£»£»£»£»£»£»£»Î¢Èí½«¼ÓÖÝÏûºÄÕßÒþ˽·¨°¸À©Õ¹ÖÁÃÀ¹úËùÓÐÓû§

Ðû²¼Ê±¼ä 2019-11-13

1¡¢Î¢ÈíÐû²¼11ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´74¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚ11ÔµÄWindowsÇå¾²¸üÐÂÖÐÐÞ¸´ÁË74¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨IE¾ç±¾ÒýÇæÖеÄÒ»¸ö0day¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇCVE-2019-1429£¬£¬£¬£¬£¬£¬£¬ÓëIE¾ç±¾ÒýÇæ´¦Öóͷ£Äڴ湤¾ßµÄ·½·¨ÓйØ£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î²»µ«Ó°ÏìÁËIEä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬£¬»¹Ó°ÏìÁËOffice Suite¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§ÔÊÐíÏÔʾ¸»Îı¾£¨ÀýÈç»ùÓÚWebµÄiframe£©£¬£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâOfficeÎĵµÔÚÓû§µÄϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚÒ°Íâ±»¹¥»÷ÕßʹÓᣡ£¡£¡£¡£¡£¡£¸ü¶àÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsofts-november-2019-patch-tuesday-arrives-with-a-patch-for-an-ie-zero-day/


2¡¢MagentoÍŶӱ޲ßÓû§×°ÖýüÆÚRCEÎó²î²¹¶¡


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


MagentoÇå¾²ÍŶӱ޲ßÓû§¾¡¿ì×°ÖÃÆä×îÐÂÐû²¼µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»£»¤ÆäÊÐËÁÃâÊÜ×î½ü±¨¸æµÄRCEÎó²î£¨CVE-2019-8144£©µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚÍøÕ¾ÉÏÖ²Èë¶ñÒâpayload²¢Ö´ÐУ¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁMagento 2.3.3°æ±¾»ò×°ÖÃMagento 2.3.2-p2²¹¶¡¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ»ùÓÚMagentoµÄÔÚÏßÊÐËÁÒ»Ö±ÊÇ·¸·¨ÍÅ»ïMagecartµÄ¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬£¬£¬Òò´ËδʵʱװÖøüеÄÍøÕ¾Î£º¦ºÜ´ó¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/magento-urges-users-to-apply-security-update-for-rce-bug/


3¡¢Î¢Èí½«¼ÓÖÝÏûºÄÕßÒþ˽·¨°¸À©Õ¹ÖÁÃÀ¹úËùÓÐÓû§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÕýÔÚ½«¼ÓÖÝÏûºÄÕßÒþ˽·¨°¸À©Õ¹µ½ÆäÔÚÃÀ¹úµÄËùÓÐÓû§£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»Ïî³öºõÒâÁϵÄÐÐΪ£¬£¬£¬£¬£¬£¬£¬ÏÔʾ³ö¸Ã¹«Ë¾ÔÚ±£»£»£»£»£»£»£»¤ÏûºÄÕßÊý¾ÝÒþ˽·½ÃæµÄ¿ÌÒâºÍÁ¦¶È¡£¡£¡£¡£¡£¡£¡£¼ÓÖÝÏûºÄÕßÒþ˽·¨°¸£¨CCPA£©ÍýÏëÓÚ2020Äê1ÔÂ1ÈÕÉúЧ£¬£¬£¬£¬£¬£¬£¬¸Ã·¨°¸Ö¼ÔÚ±£»£»£»£»£»£»£»¤ÏûºÄÕßµÄÒþ˽£¬£¬£¬£¬£¬£¬£¬ÒªÇó¹«Ë¾ÔÚʹÓúÍÈö²¥Óû§Êý¾Ý·½ÃæÌṩ¸ü¶àµÄ͸Ã÷¶È²¢¸øÓèÏûºÄÕßÍ˳öÑ¡ÔñȨ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÊ×ϯÒþ˽¹ÙÖìÀò?²¼Àï¶û£¨Julie Brill£©ÔÞÃÀÁ˸ÃÏîÖ´·¨£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖËäÈ»CCPAµÄϸ½ÚÒÔ¼°¹«Ë¾ÔõÑù×ñÊØ¸ÃÖ´·¨µÄ·½·¨ÈÔÔÚÌÖÂÛÖУ¬£¬£¬£¬£¬£¬£¬µ«Î¢Èí½«ÔÚÕâЩÕþ²ßÉϼá³Ö×îУ¬£¬£¬£¬£¬£¬£¬²¢È·±£ÔÚËùÓÐÓû§·½Ãæ¶¼×ñÊØÕâЩÕþ²ß¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/microsoft-to-apply-californias-privacy-law-to-all-u-s-users/150101/


4¡¢Ä«Î÷¸çʯÓ͹«Ë¾PemexÔâÀÕË÷Èí¼þRyuk¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ä«Î÷¸ç¹úÓÐʯÓ͹«Ë¾PemexÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖÒѾ­ÀÖ³É×èÖ¹Á˹¥»÷ʵÑ飬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷½öÓ°ÏìÁ˲»µ½5%µÄϵͳ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ê¯ÓÍÉú²úºÍÖü±£´æÄÚµÄÓªÒµ²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¾ÝÅí²©É籨µÀ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÒâÍâµÄ¹Ø±ÕÊÂÎñ£¬£¬£¬£¬£¬£¬£¬ÖÜÄ©PemexÒªÇóÐí¶àÔ±¹¤²»ÒªÊµÑé»á¼û¹«Ë¾ÍøÂç»òITϵͳ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÏÖÔÚÉÐδÅû¶¸ü¶àÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mexicos-pemex-oil-provider-says-attempted-ransomware-hack-neutralized/


5¡¢°®¶ûÀ¼Á½¼Ò¹«Ë¾ÒòBECڲƭËðʧ65ÍòÅ·Ôª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


°®¶ûÀ¼ÖÐСÆóҵЭ»á£¨ISME£©Í¨Öª³ÆÁ½¼Ò¹«Ë¾Ôâµ½BECڲƭ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¼Ò¹«Ë¾Ëðʧ20ÍòÅ·Ôª£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¼ÒËðʧÁË45.3ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£¸ÃЭ»áûÓÐ͸¶¹«Ë¾µÄÃû³Æ£¬£¬£¬£¬£¬£¬£¬µ«ËüÃǶ¼ÎüÊÕµ½ÁËڲƭÐԵĵç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬ÒªÇó½«ÒѼͼµÄ¹©Ó¦ÉÌÒøÐÐÕÊ»§ÐÅÏ¢¸ü¸ÄΪÓÉ·¸·¨·Ö×Ó¿ØÖƵÄÐÂÒøÐÐÕÊ»§¡£¡£¡£¡£¡£¡£¡£Ç徲ר¼ÒDavid WaldronÌåÏÖ·¢Æ±Öض¨ÏòȦÌ׺ÍÉæ¼°µÄ½ð¶î¡°åÇÀ´ÒÑ´ó´óÔöÌí¡±¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÈëÇÖ¹©Ó¦É̵ĵç×ÓÓʼþϵͳ£¬£¬£¬£¬£¬£¬£¬Ê¹Æä¿´ÆðÀ´Ô½·¢Õýµ±ÓÐÓᣡ£¡£¡£¡£¡£¡£ÕâÖÖڲƭÐÐΪ¶ÔÖÐСÆóÒµµÄÓ°Ïì¡°¿ÉÄÜÊÇÔÖÄÑÐԵġ±¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.irishtimes.com/news/ireland/irish-news/warning-as-irish-firms-lose-millions-in-sophisticated-invoice-scams-1.4079003


6¡¢Ó¢¹ú¹¤µ³³ÆÆäÊý×ÖÆ½Ì¨Ôâµ½´ó¹æÄ£ÍøÂç¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹ú¹¤µ³ÌåÏÖÆäÊý×ÖÆ½Ì¨Ôâµ½¡°Öش󡱺͡°´ó¹æÄ£¡±µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¡¶Sky News¡·µÄ±¨µÀ£¬£¬£¬£¬£¬£¬£¬¸Ãµ³½²»°È˳ƹ¥»÷δÄÜÆÆËðÈκÎÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ïà¹ØÏµÍ³ÒѾ­»Ö¸´ÁËÕý³£ÔË×÷¡£¡£¡£¡£¡£¡£¡£¸Ãµ³ÒѾ­½«´Ëʱ¨¸æ¸øÓ¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸Ã¹¥»÷ÊÇDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ã»Óм£ÏóÄܹ»Åú×¢ÕâÖÖ¹¥»÷À´×Ժη½¡£¡£¡£¡£¡£¡£¡£TripwireÇ徲ר¼ÒDean FerrandoÌåÏÖÕþÖÎ×éÖ¯Ó¦¸ÃÔÚÑ¡¾ÙÕâ¸öÃô¸ÐµÄʱÆÚÓÈÎª×¢ÖØÆäϵͳµÄÇå¾²²½·¥ºÍ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/uk-labour-party-cyberattack/