¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181224
°ä²¼¹¦·ò 2018-12-24
Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹µö¹¥»÷£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄ¹¤×÷ÈËԱʹ´¦½Ó¼ûÁ˸ÃÑ§ÇøµÄÍøÂç·þÎñ£¬³¬¹ý50ÍòѧÉú¡¢¸¸Ä¸ÒÔ¼°¹¤×÷ÈËÔ±µÄÐÅϢй¶¡£SDUSD³Æ¸ÃδÊÚȨ½Ó¼û³ÖÐøÁ˽«½üÒ»ÄêµÄ¹¦·ò£¨2018Äê1Ôµ½11Ô£©£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ÒäÖÁ2008ÖÁ2009ѧÄ꣬Ô̺¬Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ´¹Î£ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄ¹¤×ÊÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/2¡¢Ð¼¼ÊõÖ§³¶à¿ÆÒ³Ã潫µ¼ÖÂChromeä¯ÀÀÆ÷¿¨ËÀ
Google ChromeµÄbug»ã±¨ÖÐÅû¶ÁËÒ»¸öеļ¼ÊõÖ§³¶à¿Æ»î¶¯£¬¸ÃÚ¿ÆÍøÒ³½«Ê¹ÓÃJavaScriptÑ»·ºÄ¾¡ÍÆËã»úµÄCPU×ÊÔ´²¢µ¼ÖÂChrome¿¨ËÀ¡£¸ÃÍøÒ³µÄ±êÌâΪ¡°³ÁÒªÐÅÏ¢¡±£¬¼Ù×°³ÉÌáÐÑϰȾµÄWindowsÃýÎ󾯱¨£¬´ËÒ³ÃæÔ̺¬µÄJavaScript½«ÊÓίÀÀÆ÷³Á¸´Ìø×ªÖÁ# URL£¬²¢À´»Øµã»÷ºóÍ˺Íǰ½ø°´Å¥£¬×îÖÕµ¼ÖÂCPUÕ¼ÓÃ100%¡£Óû§¿Éͨ¹ýɱËÀChrome¹ý³ÌÀ´ÊµÏÖ¿¨ËÀÇé¿ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-tech-support-scam-causes-chrome-browser-to-use-100-percent-of-the-cpu/3¡¢Õë¶ÔGmailºÍYahooÕÊ»§µÄд¹µö¹¥»÷¿ÉÈÆ¹ýSMS 2FAÑéÖ¤
ƾ¾Ý¹ú¼ÊÌØÉâ×éÖ¯µÄ»ã±¨£¬¸Ã×éÖ¯·¢ÏÖÁ½ÆðÕë¶ÔÖж«ºÍ·ÇÖÞÖܱߵØÓòµÄÔ¼1000ÃûÈËȨÖ÷ÒåÕߵĴ¹µö»î¶¯¡£ÕâЩ´¹µö»î¶¯¼Ù×°³ÉÕË»§¾¯±¨£¬ÖØÒªÕë¶ÔʹÓûùÓÚSMSµÄ2FAÑéÖ¤²½ÖèµÄGmailºÍYahooÕÊ»§¡£ÕâЩ»î¶¯»¹Õë¶ÔÁ˸üΪרҵµÄµç×ÓÓʼþ·þÎñ£¬ÀýÈçProtonMailºÍTutanota£¬Ö»¹ÜËüÃÇĬÈÏѡȡÁ˸ü¸ß¼¶´ËÍⰲȫÐÔºÍÒþÖÔÐÔ¡£Ö¤¾ÝÅúעijЩ°¸ÀýÖÐYahooºÍGmailµÄSMS 2FA±»³É¹¦Èƹý£¬µ«Ã»ÓÐProtonMailºÍTutanotaÕË»§Êܵ½ÇÖº¦¡£
ÔÎÄÁ´½Ó£º
https://nakedsecurity.sophos.com/2018/12/21/more-phishing-attacks-on-yahoo-and-gmail-sms-2fa-authentication/4¡¢Õë¶ÔOrangeµ÷Ôì½âµ÷Æ÷µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬ÊÔͼ»ñÈ¡WiFiÃÜÂë
Bad Packets LLC×êÑÐÈËÔ±Troy Mursch·¢ÏÖ¹¥»÷ÕßÔÚ´ó¹æÄ£É¨ÃèOrange Livebox ADSLµ÷Ôì½âµ÷Æ÷¡£¸ÃɨÃè»î¶¯ÓÚ12ÔÂ21ÈÕÐÇÆÚÎåÆðÍ·£¬¹¥»÷ÕßÀûÓÃOrange LiveBoxÉ豸Öеķì϶£¨CVE-2018-20377£©À´»ñÈ¡WiFiÍøÂçµÄSSIDºÍÃÜÂë¡£×êÑÐÈËÔ±·¢ÏÖ½ü19.5Íò¸öÒ×Êܹ¥»÷µÄOrangeµ÷Ôì½âµ÷Æ÷£¬¾ø´óÎÞÊýλÓÚ·¨¹úºÍÎ÷°àÑÀ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/over-19000-orange-modems-are-leaking-wifi-credentials/5¡¢×êÑÐÈËÔ±Åû¶Facebookµã»÷½Ù³Ö·ì϶£¬µ«Facebook²»³ïË㽨¸´
²¨À¼°²È«×êÑÐÈËÔ±·¢ÏÖFacebookµÄAndroidÒÆ¶¯°æ±¾´æÔÚÒ»¸öµã»÷½Ù³Ö·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ýiframe±êÇ©ÀûÓø÷ì϶ÔÚÓû§µÄFacebookÉϰ䲼Á´½Ó¡£×êÑÐÈËÔ±ÒÔΪ¸Ã·ì϶ÓëFacebookµÄÌØ¶¨APIŲÓúöÂÔÁËX-Frame-Options±êÍ·Óйأ¬¸Ã±êÍ·Äܹ»Í¨Öªä¯ÀÀÆ÷ÊÇ·ñ¼ÓÔØiFrameÍøÒ³¡£¹¥»÷ÕßÄܹ»½«ÍøÒ³¼ÓÔØµ½µö¶üÍøÒ³µÄ¶¥²ãÖУ¨²»Ë½¼ûµÄiFrame£©£¬Óû§½«¿´¼ûµö¶üÍøÒ³£¬µ«ÏÖʵÉÏÓë¸ÃiFrame½øÐн»»¥¡£FacebookÒÔΪÕâ²»ÊÇÒ»¸ö°²È«ÎÊÌ⣬ÓÉÓÚËüûÓÐÓ°Ïìµ½Óû§ÕË»§µÄÆëÈ«ÐÔ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/the-clickjacking-bug-that-facebook-wont-fix/6¡¢¼ÌÓ¢¹úºÍºÉÀ¼Ö®ºó£¬UberÔÙ±»·¨¹úÊý¾Ý±£»¤»ú¹¹·£¿î40ÍòÅ·Ôª
2016ÄêUberÔâ·êÊý¾Ýй¶ÊÂÎñ£¬µ¼ÖÂÈ«ÇòÔ¼5700ÍòÓû§ºÍ˾»úµÄÓ×ÎÒÊý¾Ýй¶£¬µ«Ö±µ½Ò»Äê¶àÒÔÀ´µÄ2017Äê11Ô¸ù«Ë¾²ÅÏò±í½çÅû¶ÁËÕâÒ»ÊÂÎñ¡£2018Äê9Ô£¬UberÔÞ³ÉÏòÃÀ¹ú¸çÂ×±ÈÑÇÌØÇøÖ§¸¶1.48ÒÚÃÀÔªµÄºÍ½â½ð¡£2018Äê11Ô£¬Ó¢¹úºÍºÉÀ¼µÄÊý¾Ý±£»¤»ú¹¹±ðÀëÏòUber·£¿î38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿î¡£´Ë¿Ì£¬·¨¹úµÄÊý¾Ý±£»¤»ú¹¹ÔÙ´ÎÏòÆä·£¿î40ÍòÅ·Ôª¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/79104/security/frence-agency-fines-uber.htmlÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ