¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181129

Ðû²¼Ê±¼ä 2018-11-29
1¡¢FBIÍŽáGoogleµÈ¶à¼ÒÇå¾²³§É̴ݻٴó¹æÄ£¹ã¸æÚ²Æ­ÍÅ»ï3ve

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


FBIÍŽáGoogle¡¢White OpsÒÔ¼°ProofpointµÈ¶à¼ÒÇå¾²³§ÉÌÅäºÏ´Ý»ÙÁËÒ»¸ö¹ã¸æÚ²Æ­ÍŻ¸ÃÔÚÏßڲƭÔ˶¯±»³ÆÎª3ve£¬×Ô2014ÄêÆðÒ»Ö±»îÔ¾£¬µ«ÔÚÈ¥ÄêÀ©´óÁËÆäÔ˶¯¹æÄ££¬Îª¹¥»÷Õß´øÀ´ÁËÁè¼Ý3000ÍòÃÀÔªµÄÊÕÈë¡£3veѬȾÁËÁè¼Ý170Íǫ̀ÅÌËã»ú£¬Ê¹ÓÃ80¶ą̀·þÎñÆ÷±¬·¢¶ñÒâÁ÷Á¿£¬²¢¹¹½¨ÁËÁè¼Ý1Íò¸ö´¹ÂÚÍøÕ¾¡£ÔÚÔ˶¯á¯ÁëʱÆÚ£¬3veͬʱ²Ù¿ØÁËÁè¼Ý100Íò¸öIPµØµã£¬ÆäÖðÈÕڲƭ¹ã¸æÍ¶·ÅÁ¿´ï30µ½120ÒڴΡ£±¾ÖܶþÃÀ¹ú˾·¨²¿ÆðËßÁËÓë¸Ã¹ã¸æÚ²Æ­Ô˶¯ÓйصÄ8Ãû·¸·¨ÏÓÒÉÈË¡£

  

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/3ve-ad-fraud-google.html


2¡¢Çå¾²³§ÉÌ·¢Ã÷É­º£Èû¶ûµÄHeadSetupÈí¼þÒ×ÊÜSSLÖÐÐÄÈ˹¥»÷

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Secorvo·¢Ã÷¶ú»ú³§ÉÌÉ­º£Èû¶ûµÄÅäÌ×Èí¼þHeadSetup±£´æÒ»¸öÇå¾²Îó²î£¨CVE-2018-17612£©£¬¿Éµ¼ÖÂSSLÖÐÐÄÈ˹¥»÷¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃÈí¼þÔÚ×°ÖÃʱ»áÔÚÓû§ÅÌËã»úÉÏ×°ÖÃÒ»¸ö¸ùÖ¤ÊéºÍ¼ÓÃܵÄÖ¤Êé˽Կ£¬²¢ÇÒÕâÁ½¸öÎļþ¶ÔËùÓÐÓû§¶¼ÊÇÏàͬµÄ¡£¸ÃÈí¼þÔÚÐ¶ÔØÊ±Ò²²»»áɾ³ýÖ¤ÊéÎļþ£¬Ê¹µÃÓû§¼ÌÐøÒ×Êܹ¥»÷¡£¸ÃÖ¤Êé˽ԿËäÈ»±»¼ÓÃÜÁË£¬µ«Ê¹ÓõÄÊÇAES-128-CBCËã·¨¾ÙÐмÓÃÜ£¬²¢ÇÒÃÜÔ¿ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚ´úÂëÖУ¨WBCCListener.dll£©¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sennheiser-headset-software-could-allow-man-in-the-middle-ssl-attacks/


3¡¢Atrium HealthÔâºÚ¿Í¹¥»÷£¬Ô¼265Íò»¼ÕßÐÅϢй¶

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ·ÇÓªÀûÒ½ÁÆ»ú¹¹Atrium HealthÔâºÚ¿Í¹¥»÷£¬Ô¼265Íò»¼ÕßµÄÐÅϢй¶¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ9ÔÂ22ÈÕÖÁ9ÔÂ29ÈÕʱ´ú£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢°ü¹ÜÐÅÏ¢¡¢·þÎñÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅºÍÕË»§Óà¶îµÈ¡£±ðµÄ£¬ÉÐÓпìÒª70Íò¸öÉç±£ºÅÂëй¶£¬µ«Ã»ÓвÆÎñÐÅϢй¶¡£¸Ã×éÖ¯Òѽ«Ïà¹ØÊÂÎñ֪ͨFBI£¬²¢ÏòÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓÃ¼à¿Ø·þÎñ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/atrium-health-data-breach-exposed-2-65-million-patient-records/


4¡¢ElasticSearch·þÎñÆ÷̻¶Áè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Çå¾²³§ÉÌHackenµÄÑо¿Ö°Ô±Bob Diachenkoͨ¹ýShodan·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄElasticSearch·þÎñÆ÷£¬ÆäÊý¾Ý¿â̻¶ÁËÁè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý¡£ÕâЩÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¼Òͥסַ¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂëºÍIPµØµãµÈÐÅÏ¢¡£Ñо¿Ö°Ô±ÎÞ·¨È·Èϸ÷þÎñÆ÷µÄËùÓÐÕߣ¬µ«ËûÒÔΪ¼ÓÄôóÊý¾Ý¹«Ë¾Data£¦Leads»òÐíÓëÖ®ÓйØ¡£ÏÖÔڸ÷þÎñÆ÷Òѱ»¾ÙÐÐÇå¾²¼Ó¹Ì¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/elasticsearch-server-exposed-the-personal-data-of-over-57-million-us-citizens/


5¡¢¿¨°Í˹»ùÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿¨°Í˹»ùʵÑéÊÒÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ£¬¶ñÒâÍÚ¿óÈí¼þͨ³£Í¨¹ý¹ã¸æÈí¼þ¡¢ÆÆ½âÓÎÏ·»òÆäËüµÁ°æÄÚÈݽøÈëÓû§ºÍÆóÒµµÄÅÌËã»ú£¬²¢ÇÒ½¨Éè¶ñÒâÍÚ¿óÈí¼þµÄÃż÷Ò²Ô½À´Ô½µÍ¡£2018ÄêÍ·¶ñÒâÍÚ¿ó¹¥»÷¿ìËÙÔöÌí£¬ËæºóÅãͬ׿ÓÃÜÇ®±Ò¼ÛÇ®µÄϽµ¶ñÒâÍÚ¿óÔ˶¯ÓÖÏÔÖøÏ½µ£¬µ«¸ÃÍþвÈÔÈ»½ûֹСêï¡£ËäȻһЩ¹ú¼Ò¶Ô¼ÓÃÜÇ®±Ò¾ÙÐÐÁ¢·¨¿ØÖÆ£¬µ«ÕâЩ¹ú¼ÒµÄ¶ñÒâÍÚ¿óÔ˶¯²¢Ã»ÓÐÊܵ½Ó°Ïì¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-2018-story-of-the-year-miners/89096/


6¡¢Î÷ÃÅ×ÓÅû¶SIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²î

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Î÷ÃÅ×ÓÕë¶ÔSIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²îÐû²¼¾¯±¨¡£Æ¾Ö¤Î÷ÃÅ×ÓµÄ˵·¨£¬ÕâЩÎó²îÓ°ÏìÁ˹̼þ°æ±¾ÎªV2.6.0µÄGNU/Linux×Óϵͳ£¬²¢ÇÒ½«ÔÚÏÂÒ»¸ö¹Ì¼þ°æ±¾ÖÐÐÞ¸´¡£Ïà¹ØÎó²îµÄÊýĿΪ21¸ö£¬ÕâЩÎó²î¿Éµ¼Ö¾ܾø·þÎñ¡¢í§Òâ´úÂëÖ´ÐкÍÓû§Ã¶¾ÙµÈÎÊÌâ¡£Ôڹ̼þ¸üÐÂÐû²¼Ö®Ç°£¬Î÷ÃÅ×Ó½¨ÒéÓû§Ó¦ÓÃÎ÷ÃÅ×ÓÉî¶È·ÀÓù²½·¥²¢ÇÒ×èÖ¹ÔËÐв»¿ÉÐÅȪԴµÄ³ÌÐò¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-warns-linux-gnu-flaws-controller-platform



ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí