ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ31ÖÜ
Ðû²¼Ê±¼ä 2018-08-07Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2018Äê07ÔÂ30ÈÕÖÁ08ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSamsung SmartThings Hub video-core HTTPЧÀÍÆ÷»º³åÇøÒç³öÎó²î£»£»£»£»£»Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿£¿£¿£¿£¿éȨÏÞÌáÉýÎó²î£»£»£»£»£»Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î£»£»£»£»£»Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î£»£»£»£»£»SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÓ¢¹úµç×ÓÉÌÎñЧÀÍÉÌÊý¾Ý¿âй¶£¬£¬£¬Ô¼140ÍòÓû§ÊÜÓ°Ï죻£»£»£»£»Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶£»£»£»£»£»ICS-CERTÐû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ£»£»£»£»£»RedditÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶£»£»£»£»£»KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£
¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Samsung SmartThings Hub video-core HTTPЧÀÍÆ÷»º³åÇøÒç³öÎó²î
Samsung SmartThings Hub video-core HTTPЧÀÍÆ÷´¦Öóͷ£¡®clips¡¯±í±£´æ»º³åÇøÒç³ö£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0583
2¡¢Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿£¿£¿£¿£¿éȨÏÞÌáÉýÎó²î
Intel Smart Sound TechnologyÇý¶¯Ä£¿£¿£¿£¿£¿é±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇ󣬣¬£¬ÒÔÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00163.html
3¡¢Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î
Foxit PDF Reader JavaScriptÒýÇæ±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÎļþÇëÇ󣬣¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬ÒÔÓ¦ÓóÌÐòȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588
4¡¢Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î
Apple iOS Wi-Fi×é¼þ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÓ¦ÓóÌÐò£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬¿ÉÈÆ¹ýɳºÐÌáÉýȨÏÞ¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://lists.apple.com/archives/security-announce/2018/Jul/msg00001.html
5¡¢SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î
SoftNAS Cloud OS webÖÎÀíÔ±¿ØÖÆÌ¨ÖеÄsnserv¾ç±¾Ã»ÓйýÂËÓû§ÊäÈ룬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇ󣬣¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.softnas.com/docs/softnas/v3/html/updating_to_the_latest_version.html
Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ó¢¹úµç×ÓÉÌÎñЧÀÍÉÌÊý¾Ý¿âй¶£¬£¬£¬Ô¼140ÍòÓû§ÊÜÓ°Ïì
Ñо¿Ö°Ô±Taylor Ralston·¢Ã÷Ó¢¹úµç×ÓÉÌÎñЧÀÍÉÌFashion NexusµÄÒ»¸öÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬¶à¸ö´ò°çºÍÅäÊÎÍøÕ¾µÄÓû§ÐÅϢй¶£¬£¬£¬°üÀ¨Jaded London¡¢AX ParisºÍElle Belle AttireµÈÆ·ÅÆ¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Ô¼140ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬°üÀ¨MD5¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£¡£¡£Ã»Óм£ÏóÅú×¢Óû§µÄÒøÐп¨ÐÅÏ¢±£´æÎ£º¦¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/online-fashion-shoppers-exposed-ecommerce-breach/
2¡¢Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶
Boys Town¹ú¼ÒÑо¿Ò½ÔºÐû²¼Í¨Öª³Æ¸Ã×éÖ¯ÓÚ2018Äê5ÔÂ23ÈÕÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶¡£¡£¡£Õâ¿ÉÄÜÊÇÓйضùͯҽÁÆÐ§À͵Ä×î´ó¹æÄ£µÄÊý¾Ýй¶¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢Õï¶Ï»òÖÎÁÆÐÅÏ¢¡¢ÒøÐÐÕ˺š¢Óû§ÃûºÍÃÜÂëµÈÐÅÏ¢¡£¡£¡£¹¥»÷ÕßÈëÇÖÁ˸Ã×éÖ¯Ô±¹¤µÄµç×ÓÓʼþÕÊ»§£¬£¬£¬²¢Í¨¹ýδÊÚȨ»á¼û»ñÈ¡ÁËÕâЩÐÅÏ¢¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/data-breach-healthcare.html
3¡¢ICS-CERTÐû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ
¹ú¼Ò¹¤Òµ»¥ÁªÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©Ðû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ£¬£¬£¬±¨¸æ´ÓµØÇøÂþÑÜ¡¢Æ·ÅÆÂþÑÜ¡¢ÍþвÂþÑܵȶà¸ö½Ç¶ÈÐðÊöº£ÄÚÍøÂçÊÓÆµ¼à¿ØÏµÍ³µÄÇå¾²Ì¬ÊÆÇéÐΣ¬£¬£¬²¢Õë¶Ô½üÄêÀ´±¬·¢µÄÍøÂçÊÓÆµ¼à¿ØÏµÍ³Çå¾²ÊÂÎñÒòÓÉÌá³öÁËÏìÓ¦µÄΣº¦Ìá·ÀºÍÇå¾²Ó¦¶Ô¼Æ»®£¬£¬£¬¸øÏà¹ØÕþ¸®²¿·Ö¡¢×éÖ¯ºÍÑо¿»ú¹¹Ìṩ²Î¿¼ºÍ½è¼ø¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/be9def54499644afb6ce4b119e5e7d42.html
4¡¢RedditÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶
RedditÐû²¼ÆäÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶¡£¡£¡£¹¥»÷ÕßÈÆ¹ýË«ÒòËØÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§£¬£¬£¬²¢ÇÔÈ¡Á˲¿·Öµç×ÓÓʼþµØµã¡¢ÈÕÖ¾¼Í¼ÒÔ¼°°üÀ¨¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·Ý°üÀ¨2005ÄêÖÁ2007Äê5ÔÂʱ´úµÄÓû§Êý¾Ý£¬£¬£¬ÈçÕË»§Æ¾Ö¤£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØµãºÍ¹ûÕæ/˽ÈËÐÂÎÅ¡£¡£¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍÐû²¼µÄÌû×Ó±»ÒÔΪÊÇÇå¾²µÄ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/
5¡¢KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ
ICOƽ̨KickICOÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬Áè¼Ý7000ÍòKICKÁîÅÆ±»ÇÔ£¨¼ÛÖµÔ¼770ÍòÃÀÔª£©¡£¡£¡£Æ¾Ö¤KickICOÊ×ϯִÐйÙAnti DanilevskiµÄ˵·¨£¬£¬£¬¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ7ÔÂ26ÈÕÐÇÆÚËĵÄUTCʱ¼ä09:04¡£¡£¡£¹¥»÷Õß»ñÈ¡ÁË¿ª·¢Ö°Ô±µÄ˽Կ£¬£¬£¬²¢ÐÞ¸ÄÖÇÄܺÏÔ¼µÄÐÐΪ£¬£¬£¬´Ý»ÙÁË40¸öµØµãÖеÄKICKÁîÅÆÈ»ºóÔÚ40¸ö×Ô¼ºµÄÇ®°üÖн¨ÉèµÈÁ¿µÄÐÂÁîÅÆ¡£¡£¡£KickICO¿ª·¢Ö°Ô±ÏÖÔÚÒÑÖØÐ»ñµÃÖÇÄܺÏÔ¼µÄ»á¼ûȨ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/kickico-platform-loses-77-million-in-recent-hack/