¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181129
°ä²¼¹¦·ò 2018-11-29
FBI½áºÏGoogle¡¢White OpsÒÔ¼°ProofpointµÈ¶à¼Ò°²È«³§É̹²Í¬·ÛËéÁËÒ»¸ö¸æ°×Ú²ÆÍŻ¸ÃÔÚÏßڲƻ±»³ÆÎª3ve£¬×Ô2014ÄêÆðÒ»Ïò»îÔ¾£¬µ«ÔÚÈ¥ÄêÀ©´óÁËÆä»î¶¯¹æÄ££¬Îª¹¥»÷Õß´øÀ´Á˳¬¹ý3000ÍòÃÀÔªµÄÊÕÈë¡£3veϰȾÁ˳¬¹ý170ÍòÌ¨ÍÆËã»ú£¬Ê¹ÓÃ80¶ą̀·þÎñÆ÷²úÉú¶ñÒâÁ÷Á¿£¬²¢¹¹½¨Á˳¬¹ý1Íò¸ö´¹µöÍøÕ¾¡£Ôڻ¶¥·åʱÆÚ£¬3veͬʱ²Ù¿ØÁ˳¬¹ý100Íò¸öIPµØÖ·£¬ÆäÖðÈÕڲƸæ°×Ͷ·ÅÁ¿´ï30µ½120ÒڴΡ£±¾ÖܶþÃÀ¹ú˾·¨²¿¸æ×´ÁËÓë¸Ã¸æ°×ڲƻÓйصÄ8Ãû·¸×ïÏÓÒÉÈË¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/3ve-ad-fraud-google.html2¡¢°²È«³§ÉÌ·¢ÏÖɺ£Èû¶ûµÄHeadSetupÈí¼þÒ×ÊÜSSLÖÐÑëÈ˹¥»÷
Secorvo·¢ÏÖ¶ú»ú³§ÉÌɺ£Èû¶ûµÄÅäÌ×Èí¼þHeadSetup´æÔÚÒ»¸ö°²È«·ì϶£¨CVE-2018-17612£©£¬¿Éµ¼ÖÂSSLÖÐÑëÈ˹¥»÷¡£×êÑÐÈËÔ±·¢ÏÖ¸ÃÈí¼þÔÚ×°ÖÃʱ»áÔÚÓû§ÍÆËã»úÉÏ×°ÖÃÒ»¸ö¸ùÖ¤ÊéºÍ¼ÓÃܵÄÖ¤Êé˽Կ£¬²¢ÇÒÕâÁ½¸öÎļþ¶ÔËùÓÐЧ»§¶¼ÊÇÒ»ÑùµÄ¡£¸ÃÈí¼þÔÚÐ¶ÔØÊ±Ò²²»»áɾ³ýÖ¤ÊéÎļþ£¬Ê¹µÃÓû§³ÖÐøÒ×Êܹ¥»÷¡£¸ÃÖ¤Êé˽Կ¹ÌÈ»±»¼ÓÃÜÁË£¬µ«Ê¹ÓõÄÊÇAES-128-CBCËã·¨½øÐмÓÃÜ£¬²¢ÇÒÃÜÔ¿ÒÔÃ÷ÎĵĴó¾Ö´æ´¢ÔÚ´úÂëÖУ¨WBCCListener.dll£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sennheiser-headset-software-could-allow-man-in-the-middle-ssl-attacks/3¡¢Atrium HealthÔâºÚ¿Í¹¥»÷£¬Ô¼265Íò»¼ÕßÐÅϢй¶
ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ·ÇͶ»úÒ½ÁÆ»ú¹¹Atrium HealthÔâºÚ¿Í¹¥»÷£¬Ô¼265Íò»¼ÕßµÄÐÅϢй¶¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚ9ÔÂ22ÈÕÖÁ9ÔÂ29ÈÕÆÚ¼ä£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢¼Òͥסַ¡¢µ®ÉúÈÕÆÚ¡¢±£ÏÕÐÅÏ¢¡¢·þÎñÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅºÍÕË»§Óà¶îµÈ¡£´Ë±í£¬»¹Óн«½ü70Íò¸öÉç±£ºÅÂëй¶£¬µ«Ã»ÓвÆÕþÐÅϢй¶¡£¸Ã×éÖ¯Òѽ«ÓйØÊÂÎñ֪ͨFBI£¬²¢ÏòÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓþ¼à¿Ø·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/atrium-health-data-breach-exposed-2-65-million-patient-records/4¡¢ElasticSearch·þÎñÆ÷¶³ö³¬¹ý5700ÍòÃÀ¹ú¹«ÃñµÄÓ×ÎÒÊý¾Ý
°²È«³§ÉÌHackenµÄ×êÑÐÈËÔ±Bob Diachenkoͨ¹ýShodan·¢ÏÖÁËÒ»¸ö¿É¹«¿ª½Ó¼ûµÄElasticSearch·þÎñÆ÷£¬ÆäÊý¾Ý¿â¶³öÁ˳¬¹ý5700ÍòÃÀ¹ú¹«ÃñµÄÓ×ÎÒÊý¾Ý¡£ÕâЩÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼Òͥסַ¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂëºÍIPµØÖ·µÈÐÅÏ¢¡£×êÑÐÈËÔ±ÎÞ·¨È·Èϸ÷þÎñÆ÷µÄËùÓÐÕߣ¬µ«ËûÒÔΪ¼ÓÄôóÊý¾Ý¹«Ë¾Data£¦Leads»òÐíÓëÖ®Óйء£Ä¿Ç°¸Ã·þÎñÆ÷Òѱ»½øÐа²È«¼Ó¹Ì¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/elasticsearch-server-exposed-the-personal-data-of-over-57-million-us-citizens/5¡¢¿¨°Í˹»ù°ä²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨£¬¶ñÒâÍÚ¿óÈí¼þͨ³£Í¨¹ý¸æ°×Èí¼þ¡¢ÆÆ½âÓÎÏ·»òÆäËüµÁ°æÄÚÈݽøÈëÓû§ºÍÆóÒµµÄÍÆËã»ú£¬²¢ÇÒ´´½¨¶ñÒâÍÚ¿óÈí¼þµÄÃż÷Ò²Ô½À´Ô½µÍ¡£2018Ëê×ï¿ýÒâÍÚ¿ó¹¥»÷¼±¾çÔö³¤£¬ËæºóÅã°é׿ÓÃÜÇ®±Ò¼ÛÖµµÄ½µÂä¶ñÒâÍÚ¿ó»î¶¯ÓÖÏÔÖø½µÂ䣬µ«¸ÃÍþвÒÀÈ»²»ÈÝÓ×êï¡£¹ÌȻһЩ¹ú¶È¶Ô¼ÓÃÜÇ®±Ò½øÐÐÁ¢·¨½ÚÔ죬µ«ÕâЩ¹ú¶ÈµÄ¶ñÒâÍÚ¿ó»î¶¯²¢Ã»ÓÐÊܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-2018-story-of-the-year-miners/89096/6¡¢Î÷ÃÅ×ÓÅû¶SIMATIC S7-1500²úÆ·ÖеĶà¸ö°²È«·ì϶
Î÷ÃÅ×ÓÕë¶ÔSIMATIC S7-1500²úÆ·ÖеĶà¸ö°²È«·ì϶°ä²¼¾¯±¨¡£Æ¾¾ÝÎ÷ÃÅ×ÓµÄ˵·¨£¬ÕâЩ·ì϶ӰÏìÁ˹̼þ°æ±¾ÎªV2.6.0µÄGNU/Linux×Óϵͳ£¬²¢ÇÒ½«±ÉÈËÒ»¸ö¹Ì¼þ°æ±¾Öн¨¸´¡£Óйطì϶µÄÊýÁ¿Îª21¸ö£¬ÕâЩ·ì϶¿Éµ¼Ö»ؾø·þÎñ¡¢ËÁÒâ´úÂëÖ´ÐкÍÓû§Ã¶¾ÙµÈÎÊÌâ¡£Ôڹ̼þ¸üа䲼֮ǰ£¬Î÷ÃÅ×Ó½¨ÒéÓû§ÀûÓÃÎ÷ÃÅ×ÓÉî¶È·ÀÓù´ëÊ©²¢ÇÒÔ¤·ÀÔËÐв»³ÉÐÅÆðÔ´µÄ·¨Ê½¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-warns-linux-gnu-flaws-controller-platform
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ