ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ8ÖÜ
°ä²¼¹¦·ò 2019-02-25±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿͰµÍøÏúÊÛµÚÈýÅúÓû§Êý¾Ý£¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§£»Wendy'sÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð£»IxigoÔâºÚ¿ÍÈëÇÖ£¬Ô¼1800ÍòÓû§Êý¾Ýй¶£»WinRAR´úÂëÖ´Ðзì϶£¬³¬¹ý5ÒÚÓû§Êܵ½Ó°Ï죻ӡ¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
³ÁÒª°²È«·ì϶Áбí
DrupalÔÚͨ¹ý·Ç±í¸ñ£¨non-form resources£©ÀàÐÍÊäÈëʱδÄÜÕýÈ·¹ýÂËijЩ×ֶΣ¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.drupal.org/sa-core-2019-003
2. WinRAR ACEÎļþËÁÒâ´úÂëÖ´Ðзì϶
WinRAR UNACEV2.dll¿â´¦ÖÃ.aceÎļþ´æÔÚĿ¼´©Ô½ÎÊÌ⣬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
http://win-rar.com/
3. Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉý·ì϶
Intel Data Center Manager SDK×°Ö÷¨Ê½Óû§ÌáÐÑʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÌáÉýȨÏÞ¡£
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.html
4. Adobe Acrobat/Reader CVE-2019-7018ËÁÒâ´úÂëÖ´Ðзì϶
Adobe Acrobat/Reader´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-07.html
5. Huawei Mate20 CVE-2019-5296»º³åÇøÒç¶Âí½Å
Huawei Mate20´æÔÚÔ½½ç¶Á·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÉ豸Òì³£¡£
https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20190220-01-phone-cn
³ÁÒª°²È«ÊÂÎñ×ÛÊö

GnosticplayersÔÚ°µÍøÊг¡Éϰ䲼Á˵ÚÈýÅú´ýÊÛµÄÓû§ÕË»§Êý¾Ý£¬Éæ¼°µ½8¸öÍøÕ¾µÄ9276ÍòÓû§¡£Õâ8¸öÍøÕ¾Ô̺¬£ºLegendas.tv£¨386Íò£©¡¢Jobandtalent£¨1100Íò£©¡¢Onebip£¨260Íò£©¡¢StoryBird£¨400Íò£©¡¢StreetEasy£¨100Íò£©¡¢GfyCat£¨800Íò£©¡¢ClassPass£¨150Íò£©ºÍPizap£¨6080Íò£©¡£ÕâÅúÓû§Êý¾ÝµÄ×ܼÛֵΪ2.6249¸ö±ÈÌØ±Ò£¬¹²Ô¼9400ÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-puts-up-for-sale-third-round-of-hacked-databases-on-the-dark-web/
2¡¢Wendy'sÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/update-wendys-settles-financial-firms-lawsuit-over-data-breach-for-50-mln/
3¡¢IxigoÔâºÚ¿ÍÈëÇÖ£¬Ô¼1800ÍòÓû§Êý¾Ýй¶
ÔÎÄÁ´½Ó£º
https://timesofindia.indiatimes.com/business/india-business/emails-hashed-passwords-of-18m-ixigo-users-stolen/articleshow/68016866.cms
4¡¢WinRAR´úÂëÖ´Ðзì϶£¬³¬¹ý5ÒÚÓû§Êܵ½Ó°Ïì
ÔÎÄÁ´½Ó£º
https://research.checkpoint.com/extracting-code-execution-from-winrar/
5¡¢Ó¡¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄÓ×ÎÒÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/indane-aadhaar-leak.html
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ