¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180927

Ðû²¼Ê±¼ä 2018-09-27

¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±Åû¶LinuxÄÚºËÖеÄÐÂÌáȨÎó²î£¬£¬ £¬£¬£¬£¬CentOS¡¢DebianºÍRed Hat¾ùÊÜÓ°Ïì


QualysÇå¾²Ñо¿Ö°Ô±·¢Ã÷LinuxÄÚºËÖеÄÒ»¸öÐÂÎó²î£¬£¬ £¬£¬£¬£¬¸ÃÎó²î£¨CVE-2018-14634£©ÊÇÒ»¸öÕûÊýÒç³öÎó²î£¬£¬ £¬£¬£¬£¬¿ÉÔÊÐí·ÇÌØÈ¨Óû§»ñµÃÄ¿µÄϵͳÉϵij¬µÈÓû§È¨ÏÞ¡£ ¡£¡£¡£¡£Ó¦ÍâµØÌáȨÎó²îÓ°ÏìÁË2007Äê7ÔÂÖÁ2017Äê7ÔÂʱ´úµÄËùÓÐÄں˰汾£¬£¬ £¬£¬£¬£¬Red Hat¡¢CentOSºÍDebian¶¼ÊÜÓ°Ïì¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±½«¸ÃÎó²îÃüÃûΪMutagen Astronomy£¬£¬ £¬£¬£¬£¬²¢Ðû²¼ÁËÏà¹ØPoC¡£ ¡£¡£¡£¡£


https://thehackernews.com/2018/09/linux-kernel-vulnerability.html


¡¾ÆÊÎö±¨¸æ¡¿Ë¼¿ÆÐû²¼SMBÍøÂçÇå¾²±¨¸æ£¬£¬ £¬£¬£¬£¬Áè¼ÝÒ»°ëµÄÆóÒµÔøÔâÊÜÊý¾Ýй¶


9ÔÂ26ÈÕ˼¿ÆÐû²¼ÖÐСÐÍÆóÒµ£¨SMB£©ÍøÂçÇå¾²±¨¸æ£¬£¬ £¬£¬£¬£¬¸Ã±¨¸æµÄÊý¾ÝÊÇ»ùÓÚÀ´×Ô26¸ö¹ú¼ÒµÄ1816ÆäÖÐСÐÍÆóÒµ¡£ ¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁËSMBÃæÁÙµÄÇ徲Σº¦²¢ÌṩÁËÏìÓ¦µÄÇå¾²½¨Òé¡£ ¡£¡£¡£¡£Æ¾Ö¤¸Ã±¨¸æ£¬£¬ £¬£¬£¬£¬53%µÄÊÜ·ÃÆóÒµÔøÔâÊÜÊý¾Ýй¶£¬£¬ £¬£¬£¬£¬ÕâЩÊý¾Ýй¶ÊÂÎñͨ³£»£»£»£»á¶Ô¹«Ë¾µÄ²ÆÎñ״̬±¬·¢ºã¾ÃµÄÓ°Ï죬£¬ £¬£¬£¬£¬°üÀ¨ÊÕÈë¡¢¿Í»§ÒÔ¼°ÉÌҵʱ»úµÄËðʧ£¬£¬ £¬£¬£¬£¬ÒÔ¼°Êý¾Ýй¶ºóµÄ»Ö¸´±¾Ç®¡£ ¡£¡£¡£¡£


https://www.cisco.com/c/dam/en/us/products/collateral/security/small-mighty-threat.pdf


¡¾ÆÊÎö±¨¸æ¡¿McAfeeÐû²¼2018ÄêQ2Íþв±¨¸æ£¬£¬ £¬£¬£¬£¬ÖØµã¹Ø×¢ÍÚ¿ó¹¥»÷¡¢Çø¿éÁ´¼°Òƶ¯Çå¾²


McAfee LabsÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÍþв±¨¸æ£¬£¬ £¬£¬£¬£¬±¨¸æÖÐÖØµã¹Ø×¢ÁËÍÚ¿ó¹¥»÷¡¢Çø¿éÁ´ÒÔ¼°Òƶ¯ÍþвµÈ¡£ ¡£¡£¡£¡£ÍþвÇ÷ÊÆµÄÒ»¸öÖ÷ÒªµÄת±äÊÇ£¬£¬ £¬£¬£¬£¬¶ñÒâÍÚ¿ó¹¥»÷ÈÔÔÚÔöÌí£¬£¬ £¬£¬£¬£¬µ«¹Å°åµÄÀÕË÷Èí¼þ¹¥»÷ÕýÔÚïÔÌ­¡£ ¡£¡£¡£¡£ÀÕË÷Èí¼þ¹¥»÷±äµÃÔ½À´Ô½ÓÐÕë¶ÔÐÔ¡£ ¡£¡£¡£¡£ËäÈ»ÀÕË÷Èí¼þÑù±¾µÄ×ÜÊýÒѾ­Ò»Á¬Á½¸ö¼¾¶ÈϽµ£¬£¬ £¬£¬£¬£¬µ«ÈÔÓÐÒ»¸ö¼Ò×壨Scarab£©ÔÚ¼ÌÐø±¬·¢ÐµıäÖÖ¡£ ¡£¡£¡£¡£¶ÔÔÆÇéÐεı£»£»£»£»¤Ò²ÊÇÒ»¸öÌôÕ½¡£ ¡£¡£¡£¡£


https://www.mcafee.com/enterprise/en-us/assets/reports/rp-quarterly-threats-sep-2018.pdf


¡¾ÆÊÎö±¨¸æ¡¿VerizonÐû²¼2018ÄêÖ§¸¶Çå¾²±¨¸æ£¬£¬ £¬£¬£¬£¬ÁùÄêÀ´ÆóÒµ¶ÔPCI DSSµÄºÏ¹æÐÔÊ×´ÎϽµ


ƾ֤VerizonµÄ2018ÄêÖ§¸¶Çå¾²±¨¸æ£¨PSR£©£¬£¬ £¬£¬£¬£¬ÁùÄêÀ´È«ÇòÆóÒµ¶ÔÖ§¸¶¿¨ÐÐÒµÊý¾ÝÇå¾²±ê×¼£¨PCI DSS£©µÄºÏ¹æÐÔÊ×´ÎϽµ¡£ ¡£¡£¡£¡£VerizonÒÑÒ»Á¬ÁùÄ꣨´Ó2012ÄêÖÁ2017Ä꣩¸ú×ÙÖ§¸¶ºÏ¹æÐԵĸÄÉÆ×´Ì¬£¬£¬ £¬£¬£¬£¬Æ¾Ö¤¸Ã¹«Ë¾×îеı¨¸æ£¬£¬ £¬£¬£¬£¬2017Äê52.5%µÄÊÜ·ÃÆóÒµÍêȫ֪×ãPCI DSSºÏ¹æÐÔ£¬£¬ £¬£¬£¬£¬¶øÔÚ2016ÄêÕâÒ»Êý×ÖΪ55.4%¡£ ¡£¡£¡£¡£VerizonÌåÏÖÕâÒ»Ç÷ÊÆ×ª±äÁîÈ˵£ÐÄ¡£ ¡£¡£¡£¡£


https://www.helpnetsecurity.com/2018/09/26/pci-dss-compliance-drop/


¡¾Êý¾Ýй¶¡¿ÔÚÏßÐÂÎÅÍøÕ¾NewsNowÔâµ½ºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬£¬²¿·ÖÓû§µÄ¹þÏ£ÃÜÂëй¶


ÔÚÏßÐÂÎÅÍøÕ¾NewsNowͨ¹ýµç×ÓÓʼþÏòÓû§Í¨ÖªÆäÔâÊÜÊý¾Ýй¶£¬£¬ £¬£¬£¬£¬²¿·ÖÓû§µÄ¹þÏ£ÃÜÂëÊܵ½Ó°Ïì¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ²¿·ÖЧÀÍÆ÷ÉÏ·¢Ã÷ºóÃŶñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬´ËÎÊÌâÏÖÔÚÒÑ»ñµÃÐÞ¸´¡£ ¡£¡£¡£¡£NewsNowÚ¹ÊͳÆÓû§µÄÃÜÂë¶¼ÊǼÓÃÜ´æ´¢µÄ£¬£¬ £¬£¬£¬£¬²¢ÇҸù«Ë¾Ã»Óд洢Óû§µÄÈκÎÃô¸ÐÐÅÏ¢£¨ÈçÖ§¸¶ÐÅÏ¢µÈ£©¡£ ¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ìÐÞ¸ÄÆäÃÜÂë¡£ ¡£¡£¡£¡£


https://www.grahamcluley.com/newsnow-suffers-security-breach-passwords-should-be-considered-compromised/


¡¾Çå¾²²¥±¨¡¿Uber¾ÍÊý¾Ýй¶ÊÂÎñÓëÃÀ¹ú¸÷Öݸ濢1.48ÒÚÃÀÔªµÄÏ¢ÕùЭÒé


ƾ֤ÃÀÁªÉçµÄ±¨µÀ£¬£¬ £¬£¬£¬£¬±¾ÖÜÈýUberÓëÃÀ¹úËùÓÐ50¸öÖݺ͸çÂ×±ÈÑÇÌØÇø¸æ¿¢ÁËÒ»ÏîÏ¢ÕùЭÒ飬£¬ £¬£¬£¬£¬Uber½«ÎªÕÚÑÚ2016ÄêµÄÊý¾Ýй¶ÊÂÎñÖ§¸¶1.48ÒÚÃÀÔªµÄÅâ³¥½ð²¢ÔöÇ¿ÆäÊý¾ÝÇå¾²ÐÔ¡£ ¡£¡£¡£¡£2016Äê11ÔÂUberÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»á¼ûÁËÔ¼60ÍòÃÀ¹ú˾»úµÄСÎÒ˽¼ÒÊý¾Ý£¬£¬ £¬£¬£¬£¬ÒÔ¼°È«ÇòÔ¼5700ÍòÂÿ͵ÄСÎÒ˽¼ÒÊý¾Ý¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ2017Äê11Ô²ÅÈÏ¿ÉÁËÕâÒ»ÊÂÎñ¡£ ¡£¡£¡£¡£


https://www.securityweek.com/uber-agrees-148m-settlement-states-over-data-breach



¡¾¿­·¢k8¼¯ÍÅADLabÕûÀíÐû²¼¡¿