Choice Hotelsй¶70ÍòÌõ´î¿ÍÈëס¼Í¼£»¿¨°Í˹»ùɱÈí¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§

°ä²¼¹¦·ò 2019-08-16
1¡¢Choice Hotelsй¶70ÍòÌõ´î¿ÍÈëס¼Í¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Bob Diachenko·¢ÏÖÊôÓÚChoice HotelsµÄÒ»¸öMongoDBÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬ÆäÖÐÔ̺¬70ÍòÌõ´î¿ÍÈëס¼Í¼¡£ÕâЩй¶µÄÐÅÏ¢Ô̺¬´î¿ÍµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëµÈ¡£¸üΪÔã¸âµÄÊÇ£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÀÕË÷µ¥¾Ý£¬¸Ãµ¥¾ÝÐû³ÆËùÓÐ70Íò±Ê¼Í¼Òѱ»ÇÔÈ¡²¢ÀÕË÷0.4¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼4000ÃÀÔª£©µÄÊê½ð¡£ÔÚÊý¾Ý¿â¶³öÁË4Ììºó£¬7ÔÂ2ÈÕChoice Hotels¹Ø¹ØÁ˶ÔÊý¾Ý¿âµÄ¹«¿ª½Ó¼û¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/700000-choice-hotels-records-leaked-in-data-breach/


2¡¢Adobe°ä²¼8Ô°²È«¸üУ¬½¨¸´119¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


AdobeÔÚ8Եݲȫ¸üÐÂÖн¨¸´ÁË119¸ö·ì϶£¬ÆäÖÐÔ̺¬25¸öÑϳÁ·ì϶¡£·ì϶ÁìÓòº­¸ÇÐÅϢй¶¡¢È¨ÏÞÌáÉý¡¢ËÁÒâ´úÂëÖ´ÐÓ×¢Ô¶³Ì´úÂëÖ´ÐÐÒÔ¼°ÄÚ´æÐ¹Â¶µÈ¡£ÆäÖÐAcrobat and ReaderÖн¨¸´ÁË76¸ö·ì϶£¬´óÎÞÊý·ì϶¶¼¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐС£Photoshop CCÖн¨¸´ÁË34¸ö·ì϶£¬½¨ÒéÓû§¸üÐÂÖÁ°æ±¾19.1.9ºÍ20.0.6¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/adobe-releases-security-updates-for-reader-photoshop-and-more/


3¡¢Ç÷Ïò¿Æ¼¼½¨¸´ÆäÃÜÂëÖÎÀíÆ÷ÖеÄÌáȨ·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

SafeBreach°²È«×êÑÐÔ±Peleg Hadar·¢ÏÖÇ÷Ïò¿Æ¼¼µÄÃÜÂëÖÎÀíÆ÷Èí¼þÖдæÔÚÒ»¸öÌáȨ·ì϶¡£¸Ã·ì϶£¨CVE-2019-14684£©ÊÇÓÉÓÚÈí¼þÔÚ¼ÓÔØDLLʱ²»×ãÑéÖ¤»úÔ쵼ֵ쬹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáȨÖÁSYSTEMȨÏÞ£¬ÔÚ¿ÉÐŹý³ÌÖмÓÔØ¶ñÒâDLL¡£ÕâͬÑùÓÐÀûÓÚ¹¥»÷ÕßÌӱܼì²â¡£´Ë±í£¬Ç÷Ïò¿Æ¼¼»¹½ÓÊܵ½ÁíÒ»¸öÀàËÆµÄDLL½Ù³Ö·ì϶£¨CVE-2019-14687£©µÄ»ã±¨¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trend-micro-fixes-privilege-escalation-bug-in-password-manager/


4¡¢¿¨°Í˹»ùɱÈíÖеķì϶¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Ronald Eikenberg·¢ÏÖ¿¨°Í˹»ùµÄɱ¶¾Èí¼þ´æÔÚÒ»¸ö·ì϶£¨CVE-2019-8286£©£¬¿ÉÔÊÐí¶ñÒâÕ¾µã»òµÚÈý·½·þÎñ¿çÕ¾µã¸ú×ÙÓû§¡£¸Ã·ì϶´æÔÚÓÚÒ»¸öÃûΪKaspersky URL AdvisorµÄ꿅წÃèÄ£¿éÖУ¬¸ÃÄ£¿éÔÚÓû§ä¯ÀÀµÄÍøÒ³ÖÐ×¢ÈëUUIDÀ´ÏóÕ÷Óû§£¬µ«¶ñÒâÍøÕ¾¿É»ñÈ¡¸ÃUUID²¢¸ú×ÙÓû§¡£ÔÚ½Óµ½»ã±¨ºó£¬¿¨°Í˹»ù½«¸ÃUUID¸ü¸ÄΪһ¸ö³£Á¿¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/kaspersky-antivirus-online-tracking.html

5¡¢Õë¶Ô°Í¶û¸ÉµÄ¹¥»÷»î¶¯£¬·Ö·¢BalkanDoorºÍBalkanRAT


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ESET×êÑÐÈËÔ±·¢ÏÖÒ»¸öÕë¶Ô°Í¶û¸ÉµØÓòµÄй¥»÷»î¶¯£¬¹¥»÷ÕßÖØÒª·Ö·¢Ô¶¿ØºóÃÅBalkanDoorºÍľÂíBalkanRAT¡£ÕâЩ¶ñÒâpayloadÖØÒªÍ¨¹ý´¹µöÓʼþ½øÐзַ¢£¬ÓʼþµÄÖ÷ÌâÓë˰ÎñÓйØ£¬ÆäÖÐÔ̺¬µö¶üPDFÒÔ¼°¶ñÒâÁ´½ÓµÈ¡£¹¥»÷ÕßÏÔÈ»ÖØÒª¶Ô×¼°Í¶û¸ÉµØÓòµÄ½ðÈÚ²¿ÃÅ£¬ÕâÒâζ×ÅËûÃǵÄÖØÒª¶¯»úÊÇ»ñµÃ½ðÇ®¡£¸Ã¹¥»÷»î¶¯ÖÁÉÙ´Ó2016Äê1ÔÂÆðÍ·£¬Ö±µ½½ñÌìÈÔÔÚ³ÖÐø½øÐÐÖС£×êÑÐÈËÔ±Ôڻ㱨ÖзÖÎöÁËËûÃÇËùʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍÁ÷³Ì£¨TTP£©¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2019/08/14/balkans-businesses-double-barreled-weapon/


6¡¢¹È¸èÆÀ¹À³ÆÈ«Íø1.5%µÄµÇ¼ʹ´¦Òѱ»Ð¹Â¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý¹È¸è°ä²¼µÄÒ»ÏîÐÂ×êÑУ¬¹È¸è¹À¼ÆÈ«ÍøÔ¼1.5%µÄµÇ¼ʹ´¦Ò×Ôâײ¿â¹¥»÷£¬ÓÉÓÚËüÃÇÒÑÔÚ֮ǰµÄÊý¾Ýй¶Öж³ö¡£ÕâÏîÊý¾ÝÊÇÆ¾¾Ý¹È¸èµÄÃÜÂë²é³­²å¼þͳ¼ÆµÃÀ´¡£¸Ã²å¼þ»áÔÚÓû§ÊäÈëµÇ¼ʹ´¦Ê±£¬½«¹þÏ£Öµ·¢ËÍ»á¹È¸è½øÐв鳭£¬ÈôÊǼì²âµ½Æ¥Å䣬Ôò»áÖҸ沢½¨ÒéÓû§¸ü¸ÄÃÜÂ롣ƾ¾Ý¸Ã²å¼þÔÚ2ÔÂ5ÈÕÖÁ3ÔÂ4ÈÕÆÚ¼äµÄͳ¼ÆÊý¾Ý£¬¹È¸è·¢ÏÖ2100¶àÍò¸öµÇ¼ʹ´¦ÖÐÓÐ1.5%µÄÍ´´¦Òѱ»Ð¹Â¶£¬¶øÏÖʵй¶µÄÊý×Ö¿ÉÄܸü¸ß¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/google-estimates-15-percent-of-web-logins-exposed-in-data-breaches/