¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180927

°ä²¼¹¦·ò 2018-09-27

¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±Åû¶LinuxÄÚºËÖеÄÐÂÌáȨ·ì϶£¬CentOS¡¢DebianºÍRed Hat¾ùÊÜÓ°Ïì


Qualys°²È«×êÑÐÈËÔ±·¢ÏÖLinuxÄÚºËÖеÄÒ»¸öзì϶£¬¸Ã·ì϶£¨CVE-2018-14634£©ÊÇÒ»¸öÕûÊýÒç¶Âí½Å£¬¿ÉÔÊÐí·ÇÌØÈ¨Óû§»ñµÃÖ¸±êϵͳÉϵij¬µÈÓû§È¨ÏÞ¡£¸Ã±¾µØÌáȨ·ì϶ӰÏìÁË2007Äê7ÔÂÖÁ2017Äê7ÔÂÆÚ¼äµÄËùÓÐÄں˰汾£¬Red Hat¡¢CentOSºÍDebian¶¼ÊÜÓ°Ïì¡£×êÑÐÈËÔ±½«¸Ã·ì϶¶¨ÃûΪMutagen Astronomy£¬²¢°ä²¼ÁËÓйØPoC¡£


https://thehackernews.com/2018/09/linux-kernel-vulnerability.html


¡¾·ÖÎö»ã±¨¡¿Ë¼¿Æ°ä²¼SMBÍøÂ簲ȫ»ã±¨£¬³¬¹ýÒ»°ëµÄÆóÒµÔøÔâ·êÊý¾Ýй¶


9ÔÂ26ÈÕ˼¿Æ°ä²¼ÖÐÓ×ÐÍÆóÒµ£¨SMB£©ÍøÂ簲ȫ»ã±¨£¬¸Ã»ã±¨µÄÊý¾ÝÊÇ»ùÓÚÀ´×Ô26¸ö¹ú¶ÈµÄ1816¸öÖÐÓ×ÐÍÆóÒµ¡£¸Ã»ã±¨·ÖÎöÁËSMBÃæ¶ÔµÄ°²È«·çÏÕ²¢ÌṩÁËÏàÓ¦µÄ°²È«½¨Ò顣ƾ¾Ý¸Ã»ã±¨£¬53%µÄÊÜ·ÃÆóÒµÔøÔâ·êÊý¾Ýй¶£¬ÕâЩÊý¾Ýй¶ÊÂÎñͨ³£»á¶Ô¹«Ë¾µÄ²ÆÕþÇé¿ö²ú³ÉÓÆ¾ÃµÄÓ°Ï죬Ô̺¬ÊÕÈë¡¢¿Í»§ÒÔ¼°Ã³Ò×»úÓöµÄËðʧ£¬ÒÔ¼°Êý¾Ýй¶ºóµÄ¸´Ô­³É±¾¡£


https://www.cisco.com/c/dam/en/us/products/collateral/security/small-mighty-threat.pdf


¡¾·ÖÎö»ã±¨¡¿McAfee°ä²¼2018ÄêQ2Íþв»ã±¨£¬³Áµã¹Ø×¢ÍÚ¿ó¹¥»÷¡¢Çø¿éÁ´¼°Òƶ¯°²È«


McAfee Labs°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÍþв»ã±¨£¬»ã±¨ÖгÁµã¹Ø×¢ÁËÍÚ¿ó¹¥»÷¡¢Çø¿éÁ´ÒÔ¼°Òƶ¯ÍþвµÈ¡£ÍþвÇ÷ÏòµÄÒ»¸ö³ÁÒªµÄת±äÊÇ£¬¶ñÒâÍÚ¿ó¹¥»÷ÈÔÔÚÔö³¤£¬µ«´«Í³µÄÀÕË÷Èí¼þ¹¥»÷ÔÚÏ÷¼õ¡£ÀÕË÷Èí¼þ¹¥»÷±äµÃÔ½À´Ô½ÓÐÕë¶ÔÐÔ¡£¹ÌÈ»ÀÕË÷Èí¼þÑù±¾µÄ×ÜÊýÒѾ­Â½ÐøÁ½¸ö¼¾¶È½µÂ䣬µ«ÈÔÓÐÒ»¸ö¼Ò×壨Scarab£©ÔÚ³ÖÐø²úÉúеıäÖÖ¡£¶ÔÔÆ»·¾³µÄ±£»¤Ò²ÊÇÒ»¸öÌôÕ½¡£


https://www.mcafee.com/enterprise/en-us/assets/reports/rp-quarterly-threats-sep-2018.pdf


¡¾·ÖÎö»ã±¨¡¿Verizon°ä²¼2018ÄêÖ§¸¶°²È«»ã±¨£¬ÁùÄêÀ´ÆóÒµ¶ÔPCI DSSµÄºÏ¹æÐÔ³õ´Î½µÂä


ƾ¾ÝVerizonµÄ2018ÄêÖ§¸¶°²È«»ã±¨£¨PSR£©£¬ÁùÄêÀ´È«ÇòÆóÒµ¶ÔÖ§¸¶¿¨ÐÐÒµÊý¾Ý°²È«³ß¶È£¨PCI DSS£©µÄºÏ¹æÐÔ³õ´Î½µÂä¡£VerizonÒÑÂ½ÐøÁùÄ꣨´Ó2012ÄêÖÁ2017Ä꣩¸ú×ÙÖ§¸¶ºÏ¹æÐԵĸÄÉÆÇé¿ö£¬Æ¾¾Ý¸Ã¹«Ë¾×îеĻ㱨£¬2017Äê52.5%µÄÊÜ·ÃÆóÒµÆëÈ«Âú×ãPCI DSSºÏ¹æÐÔ£¬¶øÔÚ2016ÄêÕâÒ»Êý×ÖΪ55.4%¡£Verizon°µÊ¾ÕâÒ»Ç÷Ïò±ä¶¯ÁîÈËÓÇÓô¡£


https://www.helpnetsecurity.com/2018/09/26/pci-dss-compliance-drop/


¡¾Êý¾Ýй¶¡¿ÔÚÏßÐÂÎÅÍøÕ¾NewsNowÔâµ½ºÚ¿Í¹¥»÷£¬²¿ÃÅÓû§µÄ¹þÏ£ÃÜÂëй¶


ÔÚÏßÐÂÎÅÍøÕ¾NewsNowͨ¹ýµç×ÓÓʼþÏòÓû§Í¨ÖªÆäÔâ·êÊý¾Ýй¶£¬²¿ÃÅÓû§µÄ¹þÏ£ÃÜÂëÊܵ½Ó°Ïì¡£¸Ã¹«Ë¾ÔÚ²¿ÃÅ·þÎñÆ÷ÉÏ·¢ÏÖºóÃŶñÒâÈí¼þ£¬´ËÎʱêÌâǰÒѵõ½½¨¸´¡£NewsNowÚ¹ÊͳÆÓû§µÄÃÜÂë¶¼ÊǼÓÃÜ´æ´¢µÄ£¬²¢ÇҸù«Ë¾Ã»Óд洢Óû§µÄÈκÎÃô¸ÐÐÅÏ¢£¨ÈçÖ§¸¶ÐÅÏ¢µÈ£©¡£½¨ÒéÓû§¾¡¿ìÅú¸ÄÆäÃÜÂë¡£


https://www.grahamcluley.com/newsnow-suffers-security-breach-passwords-should-be-considered-compromised/


¡¾°²È«²¥±¨¡¿Uber¾ÍÊý¾Ýй¶ÊÂÎñÓëÃÀ¹ú¸÷ÖÝ´ï³É1.48ÒÚÃÀÔªµÄºÍ½âºÍ̸


ƾ¾ÝÃÀÁªÉçµÄ±¨Â·£¬±¾ÖÜÈýUberÓëÃÀ¹úËùÓÐ50¸öÖݺ͸çÂ×±ÈÑÇÌØÇø´ï³ÉÁËÒ»ÏîºÍ½âºÍ̸£¬Uber½«ÎªÒþÂ÷2016ÄêµÄÊý¾Ýй¶ÊÂÎñÖ§¸¶1.48ÒÚÃÀÔªµÄÅâ³¥½ð²¢¼ÓÇ¿ÆäÊý¾Ý°²È«ÐÔ¡£2016Äê11ÔÂUberÔâµ½ºÚ¿ÍÈëÇÖ£¬¹¥»÷Õß½Ó¼ûÁËÔ¼60ÍòÃÀ¹ú˾»úµÄÓ×ÎÒÊý¾Ý£¬ÒÔ¼°È«ÇòÔ¼5700Íò³Ë¿ÍµÄÓ×ÎÒÊý¾Ý¡£¸Ã¹«Ë¾ÓÚ2017Äê11Ô²ÅÈÏ¿ÉÁËÕâÒ»ÊÂÎñ¡£


https://www.securityweek.com/uber-agrees-148m-settlement-states-over-data-breach



¡¾GA»Æ½ð¼×¼¯ÍÅADLabÕû¶Ù°ä²¼¡¿