¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181206
Ðû²¼Ê±¼ä 2018-12-06
Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶӷ¢Ã÷Ö÷Á÷µÄÁ½¸öM2M£¨»úе¶Ô»úе£©ÐÒé±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ¹¥»÷IoTºÍIIoT×°±¸¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¡¶¹¤ÒµÎïÁªÍøÊý¾ÝÖ÷¸ÉÖеÄųÈõÐÔ¡·±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÐÒé»®·ÖÊÇÐÂÎÅÐÐÁÐÒ£²â´«ÊäÐÒ飨MQTT£©ºÍÔ¼ÊøÓ¦ÓÃÐÒ飨CoAP£©¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöÁËÕâÁ½¸öÐÒéµÄÉè¼ÆºÍʵÏÖÉϱ£´æµÄÎó²î£¬£¬£¬£¬£¬£¬£¬²¢·¢Ã÷ÁËÊýÊ®Íǫ̀ÉèÖò»µ±µÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ÕâЩЧÀÍÆ÷̻¶ÁËÏà¹ØÆ¾Ö¤¡¢Ãô¸ÐÐÅÏ¢ÒÔ¼°¹¤ÒµÁ÷³ÌÏà¹ØµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÄܵ¼ÖÂDoS¡¢í§Òâ´úÂëÖ´ÐÐÒÔ¼°DDoS·Å´ó¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/machine-to-machine-m2m-technology-design-issues-and-implementation-vulnerabilities/2¡¢ÃÀNRCC¹ÙÔ±µÄµç×ÓÓʼþÕË»§±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Êýǧ·âÓʼþ»ò±»ÇÔÈ¡
¾ÝPOLITICO±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¹²ºÍµ³ÌìϹú»áίԱ»á(NRCC)ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Êýǧ·â°üÀ¨Ãô¸ÐÐÅÏ¢µÄµç×ÓÓʼþ±»ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£2018Äê4Ô£¬£¬£¬£¬£¬£¬£¬NRCCµÄ¹©Ó¦ÉÌ£¨MSSP£©¼ì²âµ½NRCCϵͳÔâµÚÈý·½Î´ÊÚȨ»á¼û£¬£¬£¬£¬£¬£¬£¬ËæºóFBI¶Ô¸ÃÊÂÎñ×îÏȾÙÐÐÊӲ졣¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ãµ³¸ß¼¶¹ÙÔ±µÄ˵·¨£¬£¬£¬£¬£¬£¬£¬4Ãû¸ß¼¶ÖúÊÖµÄÓÊÏäÕË»§Ôâµ½Á˳¤´ïÊýÔµļàÊÓ£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹ÙÔ±¾Ü¾øÍ¸Â¶ÈëÇÖÊÂÎñÊǺÎʱ×îÏȵ쬣¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐ͸¶¸ü¶àÏà¹ØÏ¸½Ú¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/national-republican-congressional-committee-hacked-emails-exposed/3¡¢°Ä´óÀûÑÇÁª°îÒøÐпͻ§ÐÅÏ¢»òÔâй¶£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈËÊýδÃ÷
ƾ֤ABC News±¨µÀ£¬£¬£¬£¬£¬£¬£¬2018Äê7ÔÂβ°Ä´óÀûÑÇÁª°îÒøÐÐÔÚ×¼±¸½«°ü¹Ü²¿·Ö³öÊÛ¸øÓѰî°ü¹Ü£¨AIA£©¼¯ÍÅʱ£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÁËDZÔÚµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£²¿·Ö¿Í»§µÄÒ½ÁÆÐÅÏ¢±»Ìá¹©Ó¦ÒøÐÐµÄÆäËü²¿·Ö£¬£¬£¬£¬£¬£¬£¬°üÀ¨¾öÒéÊÇ·ñÅú×¼´û¿îÉêÇëµÄÔ±¹¤¡£¡£¡£¡£¡£¡£¡£ËäȻûÓÐÖ¤¾ÝÅú×¢ÓÐÍⲿְԱ»á¼ûÁ˿ͻ§µÄÒ½ÁÆÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬µ«Áª°îÒøÐÐÈÔȻ֪ͨÁ˰ĴóÀûÑǵÄÊý¾Ý±£»£»£»£»£»£»£»¤î¿Ïµ»ú¹¹¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÒøÐÐûÓÐÌṩ¹ØÓÚ¸ÃÊÂÎñµÄ¸ü¶àÏà¹ØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐ͸¶ÊÜÓ°Ïì¿Í»§µÄÏêϸÊýÄ¿¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/commonwealth-bank-s-customer-medical-info-exposed-following-potential-breach-524106.shtml4¡¢AdobeÐÞ¸´¿çƽ̨Falsh Player 0day£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐÐ
AdobeÐÞ¸´¿çƽ̨Falsh Player 0day£¨CVE-2018-15982£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚWindows¡¢macOSºÍLinuxƽ̨ÉϵÄFlash Player 31.0.0.153¼°¸üÔçµÄ°æ±¾Ö®ÖС£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸ÃÎó²îÒѱ»ÓÃÓÚÕë¶Ô¶íÂÞ˹FSBI "Polyclinic #2"Ò½ÁÆÕïËùµÄ"¶¾Õë»î¶¯"ÖС£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃAPT¹¥»÷ÓëÕþÖÎÄîÍ·Óйء£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Adobe»¹ÐÞ¸´ÁËÒ»¸öDLLÐ®ÖÆÎó²î£¨CVE-2018-15983£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂÌáȨ¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁFlash Player×îа汾32.0.0.101¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/adobe-patches-flash-player-zero-day-and-privilege-escalation-issue-524132.shtml5¡¢KubernetesÐÞ¸´¸ßΣÌáȨÎó²î£¬£¬£¬£¬£¬£¬£¬½¨Ò龡¿ì¸üÐÂ
12ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬redhat¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬Ö¸³öKubernetes£¨K8s£©±£´æÒ»¸öÑÏÖØµÄÌáȨÎó²î£¨CVE-2018-1002105£©£¬£¬£¬£¬£¬£¬£¬ËùÓлùÓÚKubernetesµÄЧÀͺͲúÆ·£¬£¬£¬£¬£¬£¬£¬°üÀ¨Redhat OpenShift Container Platform¡¢Red Hat OpenShift OnlineºÍRed Hat OpenShift Dedicated¶¼Êܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉRancher Labs¹«Ë¾µÄDarren Shepherd·¢Ã÷µÄ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒʹÓÃÄѶȽϵͣ¬£¬£¬£¬£¬£¬£¬²»ÐèÒªÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£KubernetesÔÚа汾v1.10.11¡¢v1.11.5¡¢v1.12.3ºÍv1.13.0-rc.1ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/kubernetes-updates-patch-critical-privilege-escalation-bug/6¡¢GoogleÐû²¼12ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´53¸öÎó²î
GoogleÐû²¼12ÔÂAndroidÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´ÁË53¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ6¸öÎó²îÊÇÓëýÌå¿ò¼ÜºÍϵͳ×é¼þÓйصÄRCEÎó²î¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤GoogleµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬Ã»ÓÐÈκιØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£¡£¡£¡£¡£¡£¡£AndroidýÌå¿ò¼ÜÖеÄ4¸öRCEÎó²î£¨CVE-2018-9549¡¢CVE-2018-9550¡¢CVE-2018-9551ºÍCVE-2018-9552£©Ó°ÏìÁËAndroid 7.0µ½9.0µÄϵͳ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬24¸öÎó²îÓë¸ßͨ¹«Ë¾µÄ×é¼þÓйء£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/google-patches-11-critical-rce-android-vulnerabilities/139612/ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ