¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181129
Ðû²¼Ê±¼ä 2018-11-29
FBIÁªºÏGoogle¡¢White OpsÒÔ¼°ProofpointµÈ¶à¼ÒÇå¾²³§ÉÌÅäºÏ´Ý»ÙÁËÒ»¸ö¹ã¸æÚ²ÆÍŻ¡£¡£¡£¡£¡£¸ÃÔÚÏßڲƻ±»³ÆÎª3ve£¬£¬£¬£¬£¬£¬£¬×Ô2014ÄêÆðÒ»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬µ«ÔÚÈ¥ÄêÀ©´óÁËÆä»î¶¯¹æÄ££¬£¬£¬£¬£¬£¬£¬Îª¹¥»÷Õß´øÀ´ÁËÁè¼Ý3000ÍòÃÀÔªµÄÊÕÈë¡£¡£¡£¡£¡£¡£3veѬȾÁËÁè¼Ý170Íǫ̀ÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃ80¶ą̀ЧÀÍÆ÷±¬·¢¶ñÒâÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬²¢¹¹½¨ÁËÁè¼Ý1Íò¸ö´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£Ôڻá¯ÁëʱÆÚ£¬£¬£¬£¬£¬£¬£¬3veͬʱ²Ù¿ØÁËÁè¼Ý100Íò¸öIPµØµã£¬£¬£¬£¬£¬£¬£¬ÆäÖðÈÕÚ²Æ¹ã¸æÍ¶·ÅÁ¿´ï30µ½120ÒڴΡ£¡£¡£¡£¡£¡£±¾ÖܶþÃÀ¹ú˾·¨²¿ÆðËßÁËÓë¸Ã¹ã¸æÚ²Æ»î¶¯ÓйصÄ8Ãû·¸·¨ÏÓÒÉÈË¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/3ve-ad-fraud-google.html2¡¢Çå¾²³§ÉÌ·¢Ã÷ɺ£Èû¶ûµÄHeadSetupÈí¼þÒ×ÊÜSSLÖÐÐÄÈ˹¥»÷
Secorvo·¢Ã÷¶ú»ú³§ÉÌɺ£Èû¶ûµÄÅäÌ×Èí¼þHeadSetup±£´æÒ»¸öÇå¾²Îó²î£¨CVE-2018-17612£©£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂSSLÖÐÐÄÈ˹¥»÷¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃÈí¼þÔÚ×°ÖÃʱ»áÔÚÓû§ÅÌËã»úÉÏ×°ÖÃÒ»¸ö¸ùÖ¤ÊéºÍ¼ÓÃܵÄÖ¤Êé˽Կ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÕâÁ½¸öÎļþ¶ÔËùÓÐÓû§¶¼ÊÇÏàͬµÄ¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÔÚÐ¶ÔØÊ±Ò²²»»áɾ³ýÖ¤ÊéÎļþ£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÓû§¼ÌÐøÒ×Êܹ¥»÷¡£¡£¡£¡£¡£¡£¸ÃÖ¤Êé˽ԿËäÈ»±»¼ÓÃÜÁË£¬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓõÄÊÇAES-128-CBCËã·¨¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÃÜÔ¿ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚ´úÂëÖУ¨WBCCListener.dll£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sennheiser-headset-software-could-allow-man-in-the-middle-ssl-attacks/3¡¢Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßÐÅϢй¶
ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ·ÇÓªÀûÒ½ÁÆ»ú¹¹Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßµÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ9ÔÂ22ÈÕÖÁ9ÔÂ29ÈÕʱ´ú£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢°ü¹ÜÐÅÏ¢¡¢Ð§ÀÍÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅºÍÕË»§Óà¶îµÈ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÉÐÓпìÒª70Íò¸öÉç±£ºÅÂëй¶£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓвÆÎñÐÅϢй¶¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯Òѽ«Ïà¹ØÊÂÎñ֪ͨFBI£¬£¬£¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/atrium-health-data-breach-exposed-2-65-million-patient-records/4¡¢ElasticSearchЧÀÍÆ÷̻¶Áè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý
Çå¾²³§ÉÌHackenµÄÑо¿Ö°Ô±Bob Diachenkoͨ¹ýShodan·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄElasticSearchЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ÆäÊý¾Ý¿â̻¶ÁËÁè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¼Òͥסַ¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂëºÍIPµØµãµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÎÞ·¨È·ÈϸÃЧÀÍÆ÷µÄËùÓÐÕߣ¬£¬£¬£¬£¬£¬£¬µ«ËûÒÔΪ¼ÓÄôóÊý¾Ý¹«Ë¾Data£¦Leads»òÐíÓëÖ®Óйء£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃЧÀÍÆ÷Òѱ»¾ÙÐÐÇå¾²¼Ó¹Ì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/elasticsearch-server-exposed-the-personal-data-of-over-57-million-us-citizens/5¡¢¿¨°Í˹»ùÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬¶ñÒâÍÚ¿óÈí¼þͨ³£Í¨¹ý¹ã¸æÈí¼þ¡¢ÆÆ½âÓÎÏ·»òÆäËüµÁ°æÄÚÈݽøÈëÓû§ºÍÆóÒµµÄÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½¨Éè¶ñÒâÍÚ¿óÈí¼þµÄÃż÷Ò²Ô½À´Ô½µÍ¡£¡£¡£¡£¡£¡£2018ÄêÍ·¶ñÒâÍÚ¿ó¹¥»÷¿ìËÙÔöÌí£¬£¬£¬£¬£¬£¬£¬ËæºóÅãͬ׿ÓÃÜÇ®±Ò¼ÛÇ®µÄϽµ¶ñÒâÍÚ¿ó»î¶¯ÓÖÏÔÖøÏ½µ£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÍþвÈÔÈ»½ûֹСêï¡£¡£¡£¡£¡£¡£ËäȻһЩ¹ú¼Ò¶Ô¼ÓÃÜÇ®±Ò¾ÙÐÐÁ¢·¨¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬µ«ÕâЩ¹ú¼ÒµÄ¶ñÒâÍÚ¿ó»î¶¯²¢Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-2018-story-of-the-year-miners/89096/6¡¢Î÷ÃÅ×ÓÅû¶SIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²î
Î÷ÃÅ×ÓÕë¶ÔSIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²îÐû²¼¾¯±¨¡£¡£¡£¡£¡£¡£Æ¾Ö¤Î÷ÃÅ×ÓµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁ˹̼þ°æ±¾ÎªV2.6.0µÄGNU/Linux×Óϵͳ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½«ÔÚÏÂÒ»¸ö¹Ì¼þ°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£Ïà¹ØÎó²îµÄÊýĿΪ21¸ö£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼Ö¾ܾøÐ§ÀÍ¡¢í§Òâ´úÂëÖ´ÐкÍÓû§Ã¶¾ÙµÈÎÊÌâ¡£¡£¡£¡£¡£¡£Ôڹ̼þ¸üÐÂÐû²¼Ö®Ç°£¬£¬£¬£¬£¬£¬£¬Î÷ÃÅ×Ó½¨ÒéÓû§Ó¦ÓÃÎ÷ÃÅ×ÓÉî¶È·ÀÓù²½·¥²¢ÇÒ×èÖ¹ÔËÐв»¿ÉÐÅȪԴµÄ³ÌÐò¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-warns-linux-gnu-flaws-controller-platform
ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ