Choice Hotelsй¶70ÍòÌõÓοÍÈëס¼Í¼£»£»£»£»¿¨°Í˹»ùɱÈí¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§

Ðû²¼Ê±¼ä 2019-08-16
1¡¢Choice Hotelsй¶70ÍòÌõÓοÍÈëס¼Í¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ô±Bob Diachenko·¢Ã÷ÊôÓÚChoice HotelsµÄÒ»¸öMongoDBÊý¾Ý¿â¿É¹ûÕæ»á¼û £¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨70ÍòÌõÓοÍÈëס¼Í¼¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨Óο͵ÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëµÈ¡£¡£¡£¡£¸üΪÔã¸âµÄÊÇ £¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÀÕË÷Ʊ¾Ý £¬£¬£¬£¬£¬£¬£¬¸ÃƱ¾ÝÉù³ÆËùÓÐ70ÍòÌõ¼Í¼Òѱ»ÇÔÈ¡²¢ÀÕË÷0.4¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼4000ÃÀÔª£©µÄÊê½ð¡£¡£¡£¡£ÔÚÊý¾Ý¿â̻¶ÁË4Ììºó £¬£¬£¬£¬£¬£¬£¬7ÔÂ2ÈÕChoice Hotels¹Ø±ÕÁ˶ÔÊý¾Ý¿âµÄ¹ûÕæ»á¼û¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/700000-choice-hotels-records-leaked-in-data-breach/


2¡¢AdobeÐû²¼8ÔÂÇå¾²¸üР£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´119¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AdobeÔÚ8ÔµÄÇå¾²¸üÐÂÖÐÐÞ¸´ÁË119¸öÎó²î £¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨25¸öÑÏÖØÎó²î¡£¡£¡£¡£Îó²î¹æÄ£º­¸ÇÐÅϢй¶¡¢È¨ÏÞÌáÉý¡¢í§Òâ´úÂëÖ´ÐС¢Ô¶³Ì´úÂëÖ´ÐÐÒÔ¼°ÄÚ´æÐ¹Â¶µÈ¡£¡£¡£¡£ÆäÖÐAcrobat and ReaderÖÐÐÞ¸´ÁË76¸öÎó²î £¬£¬£¬£¬£¬£¬£¬´ó´ó¶¼Îó²î¶¼¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£Photoshop CCÖÐÐÞ¸´ÁË34¸öÎó²î £¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ°æ±¾19.1.9ºÍ20.0.6¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/adobe-releases-security-updates-for-reader-photoshop-and-more/


3¡¢Ç÷ÊÆ¿Æ¼¼ÐÞ¸´ÆäÃÜÂëÖÎÀíÆ÷ÖеÄÌáȨÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

SafeBreachÇå¾²Ñо¿Ô±Peleg Hadar·¢Ã÷Ç÷ÊÆ¿Æ¼¼µÄÃÜÂëÖÎÀíÆ÷Èí¼þÖб£´æÒ»¸öÌáȨÎó²î¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-14684£©ÊÇÓÉÓÚÈí¼þÔÚ¼ÓÔØDLLʱȱ·¦ÑéÖ¤»úÖÆµ¼Ö嵀 £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÖÁSYSTEMȨÏÞ £¬£¬£¬£¬£¬£¬£¬ÔÚ¿ÉÐÅÀú³ÌÖмÓÔØ¶ñÒâDLL¡£¡£¡£¡£ÕâͬÑùÓÐÀûÓÚ¹¥»÷ÕßÌӱܼì²â¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼»¹½ÓÊܵ½ÁíÒ»¸öÀàËÆµÄDLLÐ®ÖÆÎó²î£¨CVE-2019-14687£©µÄ±¨¸æ¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trend-micro-fixes-privilege-escalation-bug-in-password-manager/


4¡¢¿¨°Í˹»ùɱÈíÖеÄÎó²î¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ô±Ronald Eikenberg·¢Ã÷¿¨°Í˹»ùµÄɱ¶¾Èí¼þ±£´æÒ»¸öÎó²î£¨CVE-2019-8286£© £¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÕ¾µã»òµÚÈý·½Ð§ÀÍ¿çÕ¾µã¸ú×ÙÓû§¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚÒ»¸öÃûΪKaspersky URL AdvisorµÄ꿅წÃèÄ£¿£¿£¿ £¿£¿£¿£¿éÖÐ £¬£¬£¬£¬£¬£¬£¬¸ÃÄ£¿£¿£¿ £¿£¿£¿£¿éÔÚÓû§ä¯ÀÀµÄÍøÒ³ÖÐ×¢ÈëUUIDÀ´±ê¼ÇÓû§ £¬£¬£¬£¬£¬£¬£¬µ«¶ñÒâÍøÕ¾¿É»ñÈ¡¸ÃUUID²¢¸ú×ÙÓû§¡£¡£¡£¡£ÔÚ½Óµ½±¨¸æºó £¬£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù½«¸ÃUUID¸ü¸ÄΪһ¸ö³£Á¿¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/kaspersky-antivirus-online-tracking.html

5¡¢Õë¶Ô°Í¶û¸ÉµÄ¹¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬·Ö·¢BalkanDoorºÍBalkanRAT


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ESETÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶Ô°Í¶û¸ÉµØÇøµÄй¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷Òª·Ö·¢Ô¶¿ØºóÃÅBalkanDoorºÍľÂíBalkanRAT¡£¡£¡£¡£ÕâЩ¶ñÒâpayloadÖ÷Ҫͨ¹ý´¹ÂÚÓʼþ¾ÙÐзַ¢ £¬£¬£¬£¬£¬£¬£¬ÓʼþµÄÖ÷ÌâÓë˰ÎñÓÐ¹Ø £¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÓÕ¶üPDFÒÔ¼°¶ñÒâÁ´½ÓµÈ¡£¡£¡£¡£¹¥»÷ÕßÏÔÈ»Ö÷ÒªÃé×¼°Í¶û¸ÉµØÇøµÄ½ðÈÚ²¿·Ö £¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËûÃǵÄÖ÷ÒªÄîÍ·ÊÇ»ñµÃ¿î×Ó¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÖÁÉÙ´Ó2016Äê1ÔÂ×îÏÈ £¬£¬£¬£¬£¬£¬£¬Ö±µ½½ñÌìÈÔÔÚÒ»Á¬¾ÙÐÐÖС£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÆÊÎöÁËËûÃÇËùʹÓõÄÕ½ÂÔ¡¢ÊÖÒÕºÍÁ÷³Ì£¨TTP£©¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2019/08/14/balkans-businesses-double-barreled-weapon/


6¡¢¹È¸èÆÀ¹À³ÆÈ«Íø1.5%µÄµÇ¼ƾ֤Òѱ»Ð¹Â¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤¹È¸èÐû²¼µÄÒ»ÏîÐÂÑо¿ £¬£¬£¬£¬£¬£¬£¬¹È¸èÔ¤¼ÆÈ«ÍøÔ¼1.5%µÄµÇ¼ƾ֤Ò×Ôâײ¿â¹¥»÷ £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇÒÑÔÚ֮ǰµÄÊý¾Ýй¶ÖÐ̻¶¡£¡£¡£¡£ÕâÏîÊý¾ÝÊÇÆ¾Ö¤¹È¸èµÄÃÜÂë¼ì²é²å¼þͳ¼ÆµÃÀ´¡£¡£¡£¡£¸Ã²å¼þ»áÔÚÓû§ÊäÈëµÇ¼ƾ֤ʱ £¬£¬£¬£¬£¬£¬£¬½«¹þÏ£Öµ·¢ËÍ»á¹È¸è¾ÙÐмì²é £¬£¬£¬£¬£¬£¬£¬ÈôÊǼì²âµ½Æ¥Åä £¬£¬£¬£¬£¬£¬£¬Ôò»áÖÒÑÔ²¢½¨ÒéÓû§¸ü¸ÄÃÜÂë¡£¡£¡£¡£Æ¾Ö¤¸Ã²å¼þÔÚ2ÔÂ5ÈÕÖÁ3ÔÂ4ÈÕʱ´úµÄͳ¼ÆÊý¾Ý £¬£¬£¬£¬£¬£¬£¬¹È¸è·¢Ã÷2100¶àÍò¸öµÇ¼ƾ֤ÖÐÓÐ1.5%µÄƾ֤Òѱ»Ð¹Â¶ £¬£¬£¬£¬£¬£¬£¬¶øÏÖʵй¶µÄÊý×Ö¿ÉÄܸü¸ß¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/google-estimates-15-percent-of-web-logins-exposed-in-data-breaches/