¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181102

°ä²¼¹¦·ò 2018-11-02
1¡¢ÐÂÀ¶ÑÀ·ì϶BleedingBitµ¼ÖÂÊý°ÙÍòÉ豸´æÔÚ·çÏÕ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒÔÉ«Áа²È«¹«Ë¾ArmisµÄ×êÑÐÈËÔ±·¢ÏÖµÂÖÝÒÇÆ÷£¨TI£©³ö²úµÄµÍ¹¦ºÄÀ¶ÑÀоƬ£¨BLE£©´æÔÚÁ½¸ö°²È«·ì϶£¬Ë¼¿Æ¡¢MerakiºÍArubaµÈÔì×÷É̵Ķà¸ö²úÏß¶¼Êܵ½Ó°Ïì¡£ÕâÁ½¸ö·ì϶£¨CVE-2018-16986ºÍCVE-2018-7080£©±»³ÆÎªBleedingBit£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë²¢ÆëÈ«ÊÕÊÜÉ豸¡£±¾ÖÜËĵÂÖÝÒÇÆ÷°ä²¼ÁËÓйؽ¨¸´²¹¶¡£¬ÕâЩ²¹¶¡½«Í¨¹ý·ÖÆçµÄOEMÉÌÌṩ¸øÓû§¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/bluetooth-chip-hacking.html


2¡¢ÒÁÀÊÒÉÔâÐÂÒ»´úÕðÍø²¡¶¾¹¥»÷£¬Ä¿Ç°ÉÐδÅû¶¸ü¶àϸ½Ú

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÒÔÉ«ÁÐÍí¼äÐÂÎŹ«±¨HadashotµÄ±¨Â·£¬ÒÁÀÊÈÏ¿ÉÔÚ´Óǰ¼¸ÌìÄÚÔâµ½ÁËÒ»ÖÖÀàËÆÓÚÕðÍø²¡¶¾µÄ¹¥»÷£¬µ«¸Ã±äÌå¸ü¾ß¹¥»÷ÐԺ͸´ÔÓÐÔ£¬ÖØÒª½ø¹¥»ù´¡ÉèÊ©ºÍÕ½ÊõÍøÂ硣ͳһÌìISNAÐÂÎÅÉçÒýÓÃÒÁÀʱ»¶¯·ÀÓù×éÖ¯ÕÆ¹ÜÈËGholamreza JalaliµÄ»°³Æ£¬¸Ã»ú¹¹·¢ÏÖ²¢×èÖ¹ÁËÐÂÒ»´úÕðÍø²¡¶¾µÄ¹¥»÷¡£Ä¿Ç°Ã»ÓйØÓÚÕâ´Î¹¥»÷µÄÈκÎϸ½ÚÆØ³ö¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-stuxnet-variant-allegedly-struck-iran/


3¡¢×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíEmotetÐÂÔöÓʼþÄÚÈÝÇÔȡģ¿é

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Kryptos LogiµÄ°²È«×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíEmotetÐÂÔöÒ»¸öÓʼþÄÚÈÝÇÔȡģ¿é¡£EmotetÒÔǰֻÓÃÓÚÇÔÈ¡Óû§µÄµç×ÓÓʼþµØÖ·¡¢µÇ¼ʹ´¦ÒÔ¼°PIIµÈÐÅÏ¢£¬µ«¸ÃÐÂÄ£¿é¿ÉÓÃÓÚÍøÂçµç×ÓÓʼþµÄÖ÷ÌâºÍÕýÎÄÄÚÈÝ£¬Õâ¿ÉÄܵ¼Ö´óÁ¿µÄÃô¸ÐÄÚÈÝй¶¡£ÓÉÓÚ¹¥»÷ÕßÄܹ»Í¨¹ýC2·þÎñÆ÷²¿Êð¸ÃÄ£¿é£¬Òò¶øËùÓÐϰȾÁËEmotetµÄÊܺ¦Õß¶¼´æÔÚ·çÏÕ¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/emotet-adds-email-exfiltration-module-tens-of-thousands-of-servers-at-risk-523544.shtml


4¡¢Å·ÖÞÖ®ÐǸßÌúÓû§×ÊÁÏÒɱíй£¬ÒªÇóËùÓÐЧ»§³ÁÖÃÃÜÂë

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖܶþÅ·ÖÞÖ®ÐǸßÌú·þÎñÏò¿Í»§·¢ËÍÓʼþ³Æ£¬ËùÓÐЧ»§¶¼±ØÒªÔڵǼeurostar.comʱ³ÁÖÃÆäÃÜÂë¡£²ÉÈ¡¸ÃÔ¤·À´ëÊ©µÄÔ­ÒòÊǸù«Ë¾ÒÉËÆÔâµ½ºÚ¿Í¹¥»÷¡£³ýÁËÏò¿Í»§·¢Ë;¯±¨Ö®±í£¬¸Ã¹«Ë¾Ã»Óа䲼ÈκÎÓйظÃÊÂÎñµÄ¹«¿ªÉêÃ÷£¬Òò¶øÄÑÒÔ¹À¼ÆÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡£µ«¸Ã¹«Ë¾ÔÚÓʼþÖгÆÃ»Óпͻ§µÄÐÅÓþ¿¨»òÖ§¸¶ÐÅÏ¢Êܵ½ÇÖº¦¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/eurostar-resets-users-passwords-after-potential-data-breach-523550.shtml


5¡¢Ò½ÁƱ£½¡¹«Ë¾NorthBayÔâºÚ¿Í¹¥»÷£¬²¿ÃÅÇóÖ°ÕßµÄÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò½ÁƱ£½¡¹«Ë¾Northcay°ä²¼ÉêÃ÷³Æ²¿ÃÅÇóÖ°ÕßµÄÐÅÏ¢Ô⵽й¶£¬Õâ´ÎÊÂÎñÓëµÚÈý·½ºÏ×÷ͬ°éJobscience IncÓйØ¡£Æ¾¾ÝÓйػ㱨£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢¼Òͥסַ¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·¡¢Éç±£ºÅÂëµÈ¡£¹ÌÈ»·¸×ï·Ö×ÓûÄÜ»ñµÃÐÅÓþ¿¨Ö§¸¶ÐÅÏ¢µÈÃô¸ÐÐÅÏ¢£¬µ«ÈÔ¿ÉÀûÓÃй¶µÄÐÅÏ¢ÌáÒéÉí·Ý͵ÇÔ¹¥»÷µÈ¡£ÊÜÓ°ÏìµÄÇóÖ°ÕßÊÇ2012Äê12ÔÂÖÁ2018Äê5ÔÂÆÚ¼äÏò¸Ã¹«Ë¾ÉêÇëְλµÄËùÓÐÈË¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/social-security-numbers-pii-stolen-in-northbay-healthcare-data-breach-523548.shtml


6¡¢Á¬Ëø¾Æµê¼¯ÍÅRadissonÔâºÚ¿Í¹¥»÷£¬²¿ÃÅ»áÔ±µÄÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Á¬Ëø¾Æµê¼¯ÍÅRadissonÔâµ½ºÚ¿Í¹¥»÷£¬²¿ÃÅ»áÔ±¿Í»§µÄÐÅϢй¶£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢¾ÓסµØÖ·£¨¾Óס¹ú¶È£©¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°Ä³Ð©¿Í»§µÄ¹«Ë¾Ãû³Æ¡¢µç»°ºÅÂëºÍ»áÔ±¼Î½±´òËãIDµÈ¡£¸ÃÊÂÎñ²úÉúÔÚ9ÔÂ11ÈÕ£¬µ«RadissonµÄITÔ±¹¤ÔÚ10ÔÂ1ÈÕ·¢ÏÖÁ˸ÃÊÂÎñ£¬²¢ÓÚ10ÔÂ30ÈÕ֪ͨÊÜÓ°ÏìµÄ¿Í»§¡£Ã»ÓÐÃÜÂëÐÅÏ¢ºÍÖ§¸¶ÐÅϢй¶¡£Radisson½²»°È˳ÆÖ»Óв»µ½10%µÄRadisson Rewards»áÔ¹ØË»§Êܵ½Ó°Ïì¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/77530/data-breach/radisson-hotel-group-data-breach.html


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù