¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180817
Ðû²¼Ê±¼ä 2018-08-17¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÇÔÈ¡Office 365ƾ֤µÄPhishPoint¹¥»÷»î¶¯
ÔÆÇå¾²¹«Ë¾AvananµÄÑо¿Ö°Ô±·¢Ã÷Ö÷ÒªÓÃÓÚÇÔÈ¡Office 365Óû§Æ¾Ö¤µÄPhishPoint¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£PhishPointÊÇÒ»ÖÖеÄʹÓÃSharePointµÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬ÆäÔÚÒÑÍùÁ½ÖÜÄÚԼĪӰÏìÁË10%µÄOffice 365Óû§¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ´¹ÂÚÓʼþÖаüÀ¨Ò»¸öSharePointÎĵµµÄÁ´½Ó£¬£¬£¬£¬¶ø¸ÃSharePointÎĵµÉϵĻá¼ûÎĵµ°´Å¥ÏÖʵÉÏÊǽ«Óû§Öض¨ÏòÖÁ´¹ÂÚÍøÒ³µÄ³¬Á´½Ó¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷¿ÉÒÔÈÆ¹ýOffice 365µÄ¸ß¼¶Íþв·À»¤£¨ATP£©»úÖÆ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/microsoft-office365-phishing.html
¡¾ÍþвÇ鱨¡¿Firefox²å¼þWeb SecurityÍøÂçÓû§µÄÊý¾Ý£¬£¬£¬£¬Áè¼Ý22ÍòÓû§ÊÜÓ°Ïì
Ñо¿Ö°Ô±·¢Ã÷Ê¢ÐеÄFirefox²å¼þWeb SecurityÕýÔÚÉñÃØµØ¼ÍÈÎÃü»§µÄÀúÊ·ä¯ÀÀ¼Í¼£¬£¬£¬£¬Õâ¿ÉÄÜÎ¥·´ÁËMozillaµÄ²å¼þ¿ª·¢Ö¸ÄÏ¡£¡£¡£¡£¡£¡£¸Ã²å¼þÖ÷ÒªÓÃÓÚ×ÊÖúÓû§·À»¤¶ñÒâÈí¼þ¼°´¹ÂÚÍøÕ¾µÄÍþв£¬£¬£¬£¬ÆäÏÂÔØ´ÎÊý´ï222746´Î¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¹ØÓÚÓû§»á¼ûµÄÿһ¸öÍøÒ³£¬£¬£¬£¬¸Ã²å¼þ¶¼½«Ïòhttp://136.243.163.73·¢ËÍÒ»¸öPOSTÇëÇ󣬣¬£¬£¬ÆäÖмͼÁËÓû§»á¼ûµÄURLÒÔ¼°´ÓÄÄÒ»¸ö¾ÉURLÌø×ªµ½ÐÂURL¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/firefox-add-on-with-220-000-installs-caught-collecting-users-browsing-history/
¡¾¹¥»÷ÊÂÎñ¡¿InstagramÒÉÔâ¶íÂÞ˹ºÚ¿Í¹¥»÷£¬£¬£¬£¬Êý°ÙÃûÓû§µÄÕË»§±»Ëø¶¨
InstagramÔâµ½ÁËÒÉËÆÀ´×Ô¶íÂÞ˹µÄºÚ¿Í¹¥»÷»î¶¯µÄ¹¥»÷£¬£¬£¬£¬ÒÑÍùÒ»ÖÜÄÚÊý°ÙÃûÓû§±»Ëø¶¨ÔÚËûÃǵÄÕË»§Ö®Íâ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Êܺ¦ÕßµÄ˵·¨£¬£¬£¬£¬ËûÃǵÄÕË»§µÄÃû³Æ¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏͼƬ¡¢ÃÜÂë¡¢¹ØÁªµç×ÓÓʼþµØµãÉõÖÁ¹ØÁªµÄFacebookÕË»§¶¼±»¸ü¸Ä¡£¡£¡£¡£¡£¡£ÏÖÔÚ»¹²»ÖªµÀ¹¥»÷Õß¼òÖ±Ç××Ô·Ý£¬£¬£¬£¬µ«¹¥»÷ÕßʹÓÃÀ´×Ô¶íÂÞ˹µç×ÓÓʼþÌṩÉÌmail.ruµÄµç×ÓÓʼþµØµã£¬£¬£¬£¬Õâ¿ÉÄÜÒâζÕßÊǶíÂÞ˹ºÚ¿ÍËùΪ£¬£¬£¬£¬µ«Ò²ÓпÉÄÜÊǹ¥»÷ÕߵľÓÐÄÎ󵼡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/hack-instagram-accounts.html
¡¾Îó²î²¹¶¡¡¿SAPÐû²¼2018Äê8ÔÂÇå¾²¸üУ¬£¬£¬£¬¹²ÐÞ¸´27¸öÎó²î
±¾ÖܶþSAPÐû²¼2018Äê8ÔµÄÇå¾²¸üУ¬£¬£¬£¬ÆäÖаüÀ¨27¸öÎó²î²¹¶¡£¬£¬£¬£¬µ«²¢²»°üÀ¨ÈκθßΣÎó²î¡£¡£¡£¡£¡£¡£½ÏÑÏÖØµÄÎó²î°üÀ¨BusinessObjectsÖеÄSQL×¢ÈëÎó²î£¨CVE-2018-2447£©¡¢Business Intelligenceƽ̨ÖеĿɵ¼ÖÂí§ÒâÏÂÁîÖ´ÐеÄÎó²î£¨CVE-2015-5237£©ÒÔ¼°SAP SRM MDM Catalog ÖеÄȱÉÙÊÚȨ¼ì²éÎó²î£¨CVE-2018-2449£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÎó²î£¨CVE-2018-2449£©ÔÚûÓÐÊÚȨµÄÇéÐÎÏ»á¼ûЧÀÍ£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÐÅϢй¶»òÌáȨ¹¥»÷µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/sap-releases-august-2018-security-updates
¡¾Îó²î²¹¶¡¡¿LinuxÄں˿ª·¢ÍŶÓÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´Á½¸öÒ×±»DDoS¹¥»÷ʹÓõÄÎó²î
ÕâÁ½¸öÎó²îÊÇSegmentSmack£¨CVE-2018-5390£©ºÍFragmentSmack£¨CVE-2018-5391£©£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâµÄTCPºÍIPÊý¾ÝÁ÷»®·ÖʹÓÃÕâÁ½¸öÎó²î£¬£¬£¬£¬´¥·¢×ÊÔ´ºÄ¾¡£¡£¡£¡£¡£¡£¨ÔöÌíCPUºÍRAMµÄʹÓ㩹¥»÷¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²î¿ÉÒÔ±»Ô¶³ÌʹÓ㬣¬£¬£¬ÕâÒâζ×ÅËüÃǺÜÊÇÊÊÊÊÓÃÓÚDoS»òDDoS¹¥»÷¡£¡£¡£¡£¡£¡£Debian¡¢Red Hat¡¢UbuntuµÈÖ÷ÒªµÄLinux¿¯ÐаæÒÔ¼°Androidϵͳ¶¼ÒѾÐû²¼ÁËÏà¹Ø¸üС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/linux/two-ddos-friendly-bugs-fixed-in-linux-kernel/
¡¾ÆÊÎö±¨¸æ¡¿Ñо¿ÍŶÓÐû²¼2017ÄêÆóÒµÐÅϢϵͳµÄÇå¾²ÆÀ¹À±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼ÁË2017ÄêÆóÒµÐÅϢϵͳµÄÇå¾²ÆÀ¹À±¨¸æ¡£¡£¡£¡£¡£¡£2017Ä꣬£¬£¬£¬¿¨°Í˹»ùʵÑéÊÒΪȫÇò¶à¸öÐÐÒµµÄ¹«Ë¾ÌṩÁËÊýÊ®¸öÍøÂçÇå¾²ÆÀ¹ÀÏîÄ¿£¬£¬£¬£¬°üÀ¨Õþ¸®»ú¹¹¡¢½ðÈÚ»ú¹¹¡¢µçÐŹ«Ë¾¡¢IT¹«Ë¾¡¢ÖÆÔ칫˾ÒÔ¼°ÄÜÔ´¹«Ë¾µÈ¡£¡£¡£¡£¡£¡£Õë¶ÔÿһÖÖÌṩµÄЧÀÍÀàÐÍ£¨Íâ²¿ÉøÍ¸²âÊÔ¡¢ÄÚ²¿ÉøÍ¸²âÊÔºÍwebÓ¦ÓÃÇå¾²ÆÀ¹À£©£¬£¬£¬£¬ÌṩÁËÎó²î¼ì²âЧ¹ûºÍͳ¼ÆÊý¾Ý¡£¡£¡£¡£¡£¡£ÔÚËùÓÐµÄÆÊÎö¹¤¾ßÖУ¬£¬£¬£¬43%µÄÆóÒµÕë¶ÔÍⲿ¹¥»÷Õߵı£»£»£»£»£»£»£»¤ÆÀ¼¶ÎªµÍ»òºÜÊǵͣ¬£¬£¬£¬93%µÄÆóÒµÕë¶ÔÄÚ²¿¹¥»÷Õߵı£»£»£»£»£»£»£»¤ÆÀ¼¶ÎªµÍ»òºÜÊǵ͡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://media.kasperskycontenthub.com/wpcontent/uploads/sites/43/2018/08/16093216/Security_assessment_of_corporate_information_systems_2017_ENG_web.pdf