¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181129
Ðû²¼Ê±¼ä 2018-11-29
FBIÁªºÏGoogle¡¢White OpsÒÔ¼°ProofpointµÈ¶à¼ÒÇå¾²³§ÉÌÅäºÏ´Ý»ÙÁËÒ»¸ö¹ã¸æÚ²ÆÍŻ¡£¡£¡£¡£¸ÃÔÚÏßڲƻ±»³ÆÎª3ve£¬£¬£¬£¬£¬£¬£¬£¬×Ô2014ÄêÆðÒ»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬µ«ÔÚÈ¥ÄêÀ©´óÁËÆä»î¶¯¹æÄ££¬£¬£¬£¬£¬£¬£¬£¬Îª¹¥»÷Õß´øÀ´ÁËÁè¼Ý3000ÍòÃÀÔªµÄÊÕÈë¡£¡£¡£¡£¡£3veѬȾÁËÁè¼Ý170Íǫ̀ÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃ80¶ą̀ЧÀÍÆ÷±¬·¢¶ñÒâÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬£¬²¢¹¹½¨ÁËÁè¼Ý1Íò¸ö´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£Ôڻá¯ÁëʱÆÚ£¬£¬£¬£¬£¬£¬£¬£¬3veͬʱ²Ù¿ØÁËÁè¼Ý100Íò¸öIPµØµã£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖðÈÕÚ²Æ¹ã¸æÍ¶·ÅÁ¿´ï30µ½120ÒڴΡ£¡£¡£¡£¡£±¾ÖܶþÃÀ¹ú˾·¨²¿ÆðËßÁËÓë¸Ã¹ã¸æÚ²Æ»î¶¯ÓйصÄ8Ãû·¸·¨ÏÓÒÉÈË¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/3ve-ad-fraud-google.html2¡¢Çå¾²³§ÉÌ·¢Ã÷ɺ£Èû¶ûµÄHeadSetupÈí¼þÒ×ÊÜSSLÖÐÐÄÈ˹¥»÷
Secorvo·¢Ã÷¶ú»ú³§ÉÌɺ£Èû¶ûµÄÅäÌ×Èí¼þHeadSetup±£´æÒ»¸öÇå¾²Îó²î£¨CVE-2018-17612£©£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂSSLÖÐÐÄÈ˹¥»÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃÈí¼þÔÚ×°ÖÃʱ»áÔÚÓû§ÅÌËã»úÉÏ×°ÖÃÒ»¸ö¸ùÖ¤ÊéºÍ¼ÓÃܵÄÖ¤Êé˽Կ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÕâÁ½¸öÎļþ¶ÔËùÓÐÓû§¶¼ÊÇÏàͬµÄ¡£¡£¡£¡£¡£¸ÃÈí¼þÔÚÐ¶ÔØÊ±Ò²²»»áɾ³ýÖ¤ÊéÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÓû§¼ÌÐøÒ×Êܹ¥»÷¡£¡£¡£¡£¡£¸ÃÖ¤Êé˽ԿËäÈ»±»¼ÓÃÜÁË£¬£¬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓõÄÊÇAES-128-CBCËã·¨¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÃÜÔ¿ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚ´úÂëÖУ¨WBCCListener.dll£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sennheiser-headset-software-could-allow-man-in-the-middle-ssl-attacks/3¡¢Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßÐÅϢй¶
ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ·ÇÓªÀûÒ½ÁÆ»ú¹¹Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßµÄÐÅϢй¶¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ9ÔÂ22ÈÕÖÁ9ÔÂ29ÈÕʱ´ú£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢°ü¹ÜÐÅÏ¢¡¢Ð§ÀÍÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅºÍÕË»§Óà¶îµÈ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÉÐÓпìÒª70Íò¸öÉç±£ºÅÂëй¶£¬£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓвÆÎñÐÅϢй¶¡£¡£¡£¡£¡£¸Ã×éÖ¯Òѽ«Ïà¹ØÊÂÎñ֪ͨFBI£¬£¬£¬£¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/atrium-health-data-breach-exposed-2-65-million-patient-records/4¡¢ElasticSearchЧÀÍÆ÷̻¶Áè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý
Çå¾²³§ÉÌHackenµÄÑо¿Ö°Ô±Bob Diachenkoͨ¹ýShodan·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄElasticSearchЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäÊý¾Ý¿â̻¶ÁËÁè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¼Òͥסַ¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂëºÍIPµØµãµÈÐÅÏ¢¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÎÞ·¨È·ÈϸÃЧÀÍÆ÷µÄËùÓÐÕߣ¬£¬£¬£¬£¬£¬£¬£¬µ«ËûÒÔΪ¼ÓÄôóÊý¾Ý¹«Ë¾Data£¦Leads»òÐíÓëÖ®Óйء£¡£¡£¡£¡£ÏÖÔÚ¸ÃЧÀÍÆ÷Òѱ»¾ÙÐÐÇå¾²¼Ó¹Ì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/elasticsearch-server-exposed-the-personal-data-of-over-57-million-us-citizens/5¡¢¿¨°Í˹»ùÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÍÚ¿óÈí¼þͨ³£Í¨¹ý¹ã¸æÈí¼þ¡¢ÆÆ½âÓÎÏ·»òÆäËüµÁ°æÄÚÈݽøÈëÓû§ºÍÆóÒµµÄÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½¨Éè¶ñÒâÍÚ¿óÈí¼þµÄÃż÷Ò²Ô½À´Ô½µÍ¡£¡£¡£¡£¡£2018ÄêÍ·¶ñÒâÍÚ¿ó¹¥»÷¿ìËÙÔöÌí£¬£¬£¬£¬£¬£¬£¬£¬ËæºóÅãͬ׿ÓÃÜÇ®±Ò¼ÛÇ®µÄϽµ¶ñÒâÍÚ¿ó»î¶¯ÓÖÏÔÖøÏ½µ£¬£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÍþвÈÔÈ»½ûֹСêï¡£¡£¡£¡£¡£ËäȻһЩ¹ú¼Ò¶Ô¼ÓÃÜÇ®±Ò¾ÙÐÐÁ¢·¨¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÕâЩ¹ú¼ÒµÄ¶ñÒâÍÚ¿ó»î¶¯²¢Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-2018-story-of-the-year-miners/89096/6¡¢Î÷ÃÅ×ÓÅû¶SIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²î
Î÷ÃÅ×ÓÕë¶ÔSIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²îÐû²¼¾¯±¨¡£¡£¡£¡£¡£Æ¾Ö¤Î÷ÃÅ×ÓµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁ˹̼þ°æ±¾ÎªV2.6.0µÄGNU/Linux×Óϵͳ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½«ÔÚÏÂÒ»¸ö¹Ì¼þ°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£Ïà¹ØÎó²îµÄÊýĿΪ21¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼Ö¾ܾøÐ§ÀÍ¡¢í§Òâ´úÂëÖ´ÐкÍÓû§Ã¶¾ÙµÈÎÊÌâ¡£¡£¡£¡£¡£Ôڹ̼þ¸üÐÂÐû²¼Ö®Ç°£¬£¬£¬£¬£¬£¬£¬£¬Î÷ÃÅ×Ó½¨ÒéÓû§Ó¦ÓÃÎ÷ÃÅ×ÓÉî¶È·ÀÓù²½·¥²¢ÇÒ×èÖ¹ÔËÐв»¿ÉÐÅȪԴµÄ³ÌÐò¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-warns-linux-gnu-flaws-controller-platform
ÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ