¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181128

Ðû²¼Ê±¼ä 2018-11-28
1¡¢NodeJSÈÈÃÅÄ £¿£¿ £¿éEvent-Stream±»Ö²Èë¶ñÒâ´úÂë

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ò»¸öÆÕ±éʹÓõÄNodeJSÄ £¿£¿ £¿éEvent-Stream±»·¢Ã÷ѬȾÁ˶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡±ÈÌØ±ÒÇ®°üÖеÄ×ʽ𡣡£¡£¡£¡£¡£¡£Event-StreamÊÇÒ»¸öµÚÈý·½¿â£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ´¦Öóͷ£Node.jsÁ÷Êý¾Ý£¬£¬£¬£¬£¬£¬£¬ÆäÒ»ÖܵÄÏÂÔØÁ¿¾Í¿¿½ü200Íò´Î¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ´úÂë±£´æÓÚEvent-Stream°æ±¾3.3.6ÖУ¬£¬£¬£¬£¬£¬£¬ÏÖÔڸð汾Òѱ»É¾³ý£¬£¬£¬£¬£¬£¬£¬Óû§¿É¸üÐÂÖÁ×îа汾4.0.1¡£¡£¡£¡£¡£¡£¡£ÊÂÎñµÄÒòÓÉÊÇEvent-StreamµÄÔ­×÷ÕßDominic Tarr½«ÏîÄ¿µÄ¿ª·¢ºÍά»¤½»¸øÁËÁíÒ»Ãû×÷Õßright9ctrl£¬£¬£¬£¬£¬£¬£¬µ«right9ctrlËæºóÐû²¼Á˰üÀ¨¶ñÒâ´úÂëµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/nodejs-event-stream-module.html


2¡¢Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþ»î¶¯sLoad

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


CERT-Yoroi·¢Ã÷Ò»¸öÕë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþ»î¶¯£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ö÷Òª·Ö·¢sLoadµÄбäÖÖ¡£¡£¡£¡£¡£¡£¡£sLoadµÄ¹¦Ð§Ç¿Ê¢£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔ½ØÈ¡ÆÁÄ»¡¢¶ÁÈ¡Àú³ÌÁÐ±í¡¢»ñÈ¡DNS»º´æ¡¢ÇÔÈ¡outlookÓʼþÄÚÈݵÈ¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÐsLoadͨ¹ýÀ¬»øÓʼþÖеÄzip¸½¼þ¾ÙÐзַ¢¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎú¸Ã»î¶¯ÊÇÒ»¸öÐµķ¸·¨ÍÅ»ïËùΪÕÕ¾ÉÒÑÖªµÄ·¸·¨ÍÅ»ï¸Ä±äÁËËüÃǵÄTTP¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78468/malware/sload-malspam-hit-italy.html


3¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶ÔÖж«µØÇøµÄ¶ñÒâ»î¶¯DNSpionage

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆTalos·¢Ã÷Õë¶ÔÀè°ÍÄۺͰ¢ÁªÇõÕþ¸®ÍøÕ¾ÒÔ¼°Ò»¼ÒÀè°ÍÄÛº½¿Õ¹«Ë¾µÄжñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Talos¶ÔÆä»ù´¡ÉèÊ©ºÍTTPµÄÊÓ²ìЧ¹û£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâ»î¶¯ÎÞ·¨ÓëÈκÎÒÑÖªµÄ¹¥»÷Õß¾ÙÐйØÁª¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ»¹²»¿ÉÈ·¶¨¹¥»÷ÕßµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬Ò²²»ÇåÎú¹¥»÷ÕßÓÃÓÚ·Ö·¢¶ñÒâÎĵµµÄÒªÁ죬£¬£¬£¬£¬£¬£¬µ«×îÓпÉÄܵÄÊÇͨ¹ýÓã²æÊ½´¹Âڻ»òÉ罻ýÌåÆ½Ì¨¾ÙÐзַ¢¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÅû¶Á˸ü¶àµÄÊÖÒÕϸ½ÚºÍ¹¥»÷ʱ¼äÖá¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html


4¡¢ÃÀ¹úiOSÓû§Ôâ´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯¹¥»÷

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²³§ÉÌConfiant·¢Ã÷Ò»¸öÕë¶ÔÃÀ¹úiOSÓû§µÄ´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯¡£¡£¡£¡£¡£¡£¡£11ÔÂ12ÈոöñÒâ»î¶¯²þâ±ì­Éý£¬£¬£¬£¬£¬£¬£¬·¸·¨·Ö×ÓÔÚ48СʱÄÚÐ®ÖÆÁËÁè¼Ý3ÒÚ¸öä¯ÀÀÆ÷»á»°¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ»î¶¯Í¨¹ýÕýµ±ÍøÕ¾ÉϵĶñÒâ¹ã¸æ½«Óû§Öض¨ÏòÖÁһϵÁеÄÔÝÊ±ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬²¢ÏòÓû§ÍÆËͳÉÈËÍøÕ¾»òÀñÎ│Ö÷ÌâµÄÕ©Æ­»î¶¯¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½«¸Ã¶ñÒâ»î¶¯¹ØÁªÖÁ·¸·¨ÍÅ»ïScamClub¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/us-ios-users-targeted-by-massive-malvertising-campaign/


5¡¢¶íº¥¶íÖÝÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¼±ÕïЧÀͱ»ÆÈÖÐÖ¹

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¾ÝThe Times Leader±¨µÀ£¬£¬£¬£¬£¬£¬£¬11ÔÂ23ÈÕÐÇÆÚÎåÍíÉ϶«¶íº¥¶íµØÇøÒ½ÔººÍ¶íº¥¶í¹ÈÒ½ÁÆÖÐÐĵÄÅÌËã»úϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÖÂʹҽԺµÄ¼±ÕïЧÀͱ»ÆÈÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£¸ÃµØÇøµÄ¼±Õï²½¶ÓÒѽ«²¡ÈË×ªÒÆÖÁÆäËüµØÇøµÄÒ½Ôº¡£¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬£¬Ã»Óл¼ÕßµÄÊý¾ÝÔڴ˴ι¥»÷ÊÂÎñÖÐй¶¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78441/breaking-news/ohio-hospital-system-ransomware.html


6¡¢UberÒò2016ÄêÊý¾Ýй¶±»ºÉÀ¼ºÍÓ¢¹ú· £¿£¿ £¿î120ÍòÃÀÔª

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ó¢¹úµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒÔ¼°ºÉÀ¼µÄÊý¾Ý±£»£»£»£»£»£»£»£»¤»ú¹¹Autoriteit Persoonsgegevens»®·ÖÒò2016Äê10ÔµÄÊý¾Ýй¶ÊÂÎñ¶ÔUber´¦ÒÔ38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ· £¿£¿ £¿î¡£¡£¡£¡£¡£¡£¡£ICOÌåÏÖ¸ÃÊÂÎñÓ°ÏìÁËÓ¢¹úµÄ270ÍòUberÓû§ÒÔ¼°8.2Íò˾»ú¡£¡£¡£¡£¡£¡£¡£ºÉÀ¼DPA³ÆÓÐ17.4ÍòºÉÀ¼¹«ÃñÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£· £¿£¿ £¿îµÄÖ÷ÒªÔµ¹ÊÔ­ÓÉÊÇUberÑÓ³ÙÁ˽üÒ»Äê²Å±¨¸æ´Ë´Îй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬ÕâÑÏÖØÎ¥·´ÁËÏà¹ØÖ´·¨ÌõÀý£¬£¬£¬£¬£¬£¬£¬²¢ÇÒʹÊÜÓ°ÏìµÄÓû§ºÍ˾»úÃæÁÙ¸ü¸ßµÄڲƭΣº¦¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uber-fined-for-covering-up-2016-data-breach/



ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí