ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ31ÖÜ

Ðû²¼Ê±¼ä 2018-08-07

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


 2018Äê07ÔÂ30ÈÕÖÁ08ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSamsung SmartThings Hub video-core HTTPЧÀÍÆ÷»º³åÇøÒç³öÎó²î£»£»£»£»£»£»Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿£¿£¿£¿éȨÏÞÌáÉýÎó²î£»£»£»£»£»£»Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î£»£»£»£»£»£»Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î£»£»£»£»£»£»SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£

 

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÓ¢¹úµç×ÓÉÌÎñЧÀÍÉÌÊý¾Ý¿âй¶£¬£¬ £¬£¬£¬£¬Ô¼140ÍòÓû§ÊÜÓ°Ï죻£»£»£»£»£»Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶£»£»£»£»£»£»ICS-CERTÐû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ£»£»£»£»£»£»RedditÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶£»£»£»£»£»£»KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ¡£¡£¡£¡£¡£¡£¡£

 

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£

 

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢Samsung SmartThings Hub video-core HTTPЧÀÍÆ÷»º³åÇøÒç³öÎó²î

 

 Samsung SmartThings Hub video-core HTTPЧÀÍÆ÷´¦Öóͷ£¡®clips¡¯±í±£´æ»º³åÇøÒç³ö£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0583


2¡¢Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿£¿£¿£¿éȨÏÞÌáÉýÎó²î

 

Intel Smart Sound TechnologyÇý¶¯Ä£¿£¿£¿£¿é±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬ÒÔÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00163.html


3¡¢Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î

 

Foxit PDF Reader JavaScriptÒýÇæ±£´æÊͷźóʹÓÃÎó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÎļþÇëÇ󣬣¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

 

 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588


4¡¢Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î

 

Apple iOS Wi-Fi×é¼þ±£´æÄÚ´æÆÆËðÎó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÓ¦ÓóÌÐò£¬£¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬£¬¿ÉÈÆ¹ýɳºÐÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://lists.apple.com/archives/security-announce/2018/Jul/msg00001.html


5¡¢SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î

 

SoftNAS Cloud OS webÖÎÀíÔ±¿ØÖÆÌ¨ÖеÄsnserv¾ç±¾Ã»ÓйýÂËÓû§ÊäÈ룬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.softnas.com/docs/softnas/v3/html/updating_to_the_latest_version.html

 

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ó¢¹úµç×ÓÉÌÎñЧÀÍÉÌÊý¾Ý¿âй¶£¬£¬ £¬£¬£¬£¬Ô¼140ÍòÓû§ÊÜÓ°Ïì

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Ñо¿Ö°Ô±Taylor Ralston·¢Ã÷Ó¢¹úµç×ÓÉÌÎñЧÀÍÉÌFashion NexusµÄÒ»¸öÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬ £¬£¬£¬£¬¶à¸ö´ò°çºÍÅäÊÎÍøÕ¾µÄÓû§ÐÅϢй¶£¬£¬ £¬£¬£¬£¬°üÀ¨Jaded London¡¢AX ParisºÍElle Belle AttireµÈÆ·ÅÆ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Ô¼140ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬ £¬£¬£¬£¬°üÀ¨MD5¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£¡£Ã»Óм£ÏóÅú×¢Óû§µÄÒøÐп¨ÐÅÏ¢±£´æÎ£º¦¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/online-fashion-shoppers-exposed-ecommerce-breach/

 

2¡¢Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


 Boys Town¹ú¼ÒÑо¿Ò½ÔºÐû²¼Í¨Öª³Æ¸Ã×éÖ¯ÓÚ2018Äê5ÔÂ23ÈÕÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£Õâ¿ÉÄÜÊÇÓйضùͯҽÁÆÐ§À͵Ä×î´ó¹æÄ£µÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢Õï¶Ï»òÖÎÁÆÐÅÏ¢¡¢ÒøÐÐÕ˺š¢Óû§ÃûºÍÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÈëÇÖÁ˸Ã×éÖ¯Ô±¹¤µÄµç×ÓÓʼþÕÊ»§£¬£¬ £¬£¬£¬£¬²¢Í¨¹ýδÊÚȨ»á¼û»ñÈ¡ÁËÕâЩÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/data-breach-healthcare.html

 

3¡¢ICS-CERTÐû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

 

¹ú¼Ò¹¤Òµ»¥ÁªÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©Ðû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ£¬£¬ £¬£¬£¬£¬±¨¸æ´ÓµØÇøÂþÑÜ¡¢Æ·ÅÆÂþÑÜ¡¢ÍþвÂþÑܵȶà¸ö½Ç¶ÈÐðÊöº£ÄÚÍøÂçÊÓÆµ¼à¿ØÏµÍ³µÄÇå¾²Ì¬ÊÆÇéÐΣ¬£¬ £¬£¬£¬£¬²¢Õë¶Ô½üÄêÀ´±¬·¢µÄÍøÂçÊÓÆµ¼à¿ØÏµÍ³Çå¾²ÊÂÎñÒòÓÉÌá³öÁËÏìÓ¦µÄΣº¦Ìá·ÀºÍÇå¾²Ó¦¶Ô¼Æ»®£¬£¬ £¬£¬£¬£¬¸øÏà¹ØÕþ¸®²¿·Ö¡¢×éÖ¯ºÍÑо¿»ú¹¹Ìṩ²Î¿¼ºÍ½è¼ø¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/be9def54499644afb6ce4b119e5e7d42.html

 

4¡¢RedditÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

 

RedditÐû²¼ÆäÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÈÆ¹ýË«ÒòËØÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§£¬£¬ £¬£¬£¬£¬²¢ÇÔÈ¡Á˲¿·Öµç×ÓÓʼþµØµã¡¢ÈÕÖ¾¼Í¼ÒÔ¼°°üÀ¨¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·Ý°üÀ¨2005ÄêÖÁ2007Äê5ÔÂʱ´úµÄÓû§Êý¾Ý£¬£¬ £¬£¬£¬£¬ÈçÕË»§Æ¾Ö¤£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØµãºÍ¹ûÕæ/˽ÈËÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍÐû²¼µÄÌû×Ó±»ÒÔΪÊÇÇå¾²µÄ¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/

 

5¡¢KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ICOƽ̨KickICOÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬Áè¼Ý7000ÍòKICKÁîÅÆ±»ÇÔ£¨¼ÛÖµÔ¼770ÍòÃÀÔª£©¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤KickICOÊ×ϯִÐйÙAnti DanilevskiµÄ˵·¨£¬£¬ £¬£¬£¬£¬¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ7ÔÂ26ÈÕÐÇÆÚËĵÄUTCʱ¼ä09:04¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»ñÈ¡ÁË¿ª·¢Ö°Ô±µÄ˽Կ£¬£¬ £¬£¬£¬£¬²¢ÐÞ¸ÄÖÇÄܺÏÔ¼µÄÐÐΪ£¬£¬ £¬£¬£¬£¬´Ý»ÙÁË40¸öµØµãÖеÄKICKÁîÅÆÈ»ºóÔÚ40¸ö×Ô¼ºµÄÇ®°üÖн¨ÉèµÈÁ¿µÄÐÂÁîÅÆ¡£¡£¡£¡£¡£¡£¡£KickICO¿ª·¢Ö°Ô±ÏÖÔÚÒÑÖØÐ»ñµÃÖÇÄܺÏÔ¼µÄ»á¼ûȨ¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/kickico-platform-loses-77-million-in-recent-hack/