Áè¼Ý3600ÍòPoshmarkÕÊ»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£»£»£»£»£» £»µÂ¹úOLBÒøÐб»ºÚ¿ÍÇÔÈ¡Áè¼Ý150ÍòÅ·Ôª×ʽð

Ðû²¼Ê±¼ä 2019-09-04

1.Áè¼Ý3600ÍòPoshmarkÕÊ»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨




ÃÀ¹ú´ò°çÉúÒâÊг¡PoshmarkÓÚ2018Äê5ÔÂÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬ £¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾ÔÚ2019Äê8Ô·ݲÅÏò¹«ÖÚÅû¶¡£¡£¡£¡£ÏÖÔÚÕâЩй¶µÄ¿Í»§ÏêϸÐÅÏ¢ÔÚÍøÉÏÒÔÃ÷ÎĵÄÐÎʽÈö²¥£¬£¬ £¬£¬£¬£¬£¬Have I Been PwnedÍøÕ¾ÒѾ­ÊÕ¼ÁËÁè¼Ý3600ÍòÌõPoshmarkµÇ¼ÐÅÏ¢¡£¡£¡£¡£ÌṩÊý¾ÝµÄÈËÊÇJim Scott£¬£¬ £¬£¬£¬£¬£¬ËûÌåÏÖÕâЩÊý¾ÝÔÚ°µÍøÉϵijöÊÛ¼ÛǮΪ750ÃÀÔª¡£¡£¡£¡£Êý¾Ý°üÀ¨µç×ÓÓʼþµØµã¡¢ÐÕÃû¡¢Óû§Ãû¡¢ÐÔ±ð¡¢Î»ÖúÍbcrypt¹þÏ£ÃÜÂë¡£¡£¡£¡£Scott»¹ÌåÏÖÓÐÒ»Ì×ΪÊý100ÍòµÄÒÑÆÆ½âPoshmarkÕË»§ÃÜÂëÔÚÍøÉÏÈö²¥¡£¡£¡£¡£ÓÉÓÚÃÜÂëÒѱ»½âÃÜ£¬£¬ £¬£¬£¬£¬£¬Òò´Ë¼ÛÇ®¿ÉÄܸü¸ß¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/90712/data-breach/poshmark-cracked-passwords.html



2.¼ÓÄôóYves Rocher¹«Ë¾ÒâÍâй¶250Íò¿Í»§ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



vpnMentorÑо¿Ö°Ô±·¢Ã÷ÊôÓÚAliznet¹«Ë¾µÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬ £¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨¼ÓÄôó»¯×±Æ·¾ÞÍ·Yves RocherµÄ250Íò¿Í»§Êý¾Ý¡£¡£¡£¡£Aliznet¹«Ë¾´ÓÊÂÊý×Ö»¯×ªÐÍЧÀÍ£¬£¬ £¬£¬£¬£¬£¬Yves RocherÊÇÆäÒ»¸ö¿Í»§¡£¡£¡£¡£¸Ã˽ÓÐÊý¾Ý¿â°üÀ¨Yves Rocher¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚºÍÓÊÕþ±àÂëµÈÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬»¹°üÀ¨600¶àÍò¸ö¶©µ¥£¬£¬ £¬£¬£¬£¬£¬°üÀ¨ÉúÒâ½ð¶î¡¢Ê¹ÓõÄÇ®±Ò¡¢½»»õÈÕÆÚºÍÊÐËÁλÖõÈÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬ÕâЩ¶©µ¥ÐÅÏ¢¿Éͨ¹ý¿Í»§IDÓë¿Í»§Ïà¹ØÁª¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬£¬vpnMentor»¹·¢Ã÷ÁËYves RocherµÄÄÚ²¿Êý¾Ý£¬£¬ £¬£¬£¬£¬£¬°üÀ¨ÊÐËÁÁ÷Á¿¡¢ÓªÒµ¶îºÍ¶©µ¥Á¿Í³¼Æ¡¢Áè¼Ý4ÍòÖÖ²úÆ·µÄÐÎòºÍÒòËØÒÔ¼°²úÆ·¼ÛÇ®ºÍ±¨¼Û´úÂë¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/data-leak-affects-25m-customers/



3.Ó¢¹ú¼Ò¼Ù¹«Ë¾½«20Íò¿Í»§×ÊÁÏÔÚÍøÉÏ̻¶³¤´ï3Äê




¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝÍâý±¨µÀ£¬£¬ £¬£¬£¬£¬£¬Ò»¼ÒÓ¢¹ú¼Ò¼Ù¹«Ë¾Teletext Holidays½«Áè¼Ý20Íò¿Í»§µÄСÎÒ˽¼Ò×ÊÁÏ´æ´¢ÔÚÒôƵÎļþÖв¢ÔÚÍøÉÏ̻¶Á˳¤´ï3ÄêµÄʱ¼ä¡£¡£¡£¡£VerdictÔÚÒ»¸ö¿É¹ûÕæ»á¼ûµÄAmazon Web ServicesЧÀÍÆ÷ÉÏ·¢Ã÷ÁËÕâЩ21.2Íò¸öÒôƵÎļþ£¬£¬ £¬£¬£¬£¬£¬ÎļþµÄÈÕÆÚÔÚ2016Äê4ÔÂ10ÈÕÖÁ8ÔÂ10ÈÕÖ®¼ä£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÇåÎúµØÌýµ½¿Í»§µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþºÍ¼Òͥסַ¡¢º½°àʱ¼äµÈÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬µ«Ö»°üÀ¨²¿·ÖÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¸Ã¶È¼Ù¹«Ë¾ÔÚ½Óµ½Í¨Öªºóɾ³ýÁËËùÓÐ53.2Íò¸öÎļþ£¨°üÀ¨ÄÇЩÒôƵÎļþ£©£¬£¬ £¬£¬£¬£¬£¬²¢ÌåÏÖÕýÔÚÏòICO±¨¸æ´ËÊ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/uk-holidaymakers-data-exposed-for/



4.XKCDÂÛ̳й¶56.2ÍòÓû§µÄµÇ¼ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



XKCDÂÛ̳Óû§Êý¾Ýй¶£¬£¬ £¬£¬£¬£¬£¬²¨¼°56.2ÍòÓû§£¬£¬ £¬£¬£¬£¬£¬¸ÃÂÛ̳ÔÚÊÂÎñ±¬·¢ºóÒÑ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£Êý¾Ýй¶±¬·¢ÔÚ7ÔÂ1ÈÕ£¬£¬ £¬£¬£¬£¬£¬°üÀ¨Óû§Ãû¡¢µç×ÓÓʼþºÍIPµØµã¡¢¼ÓÑιþÏ£ÃÜÂëµÈÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬ÕâЩÊý¾ÝÓÚ9ÔÂ1ÈÕ±»Ìí¼Óµ½Have I Been PwnedÊý¾Ý¿âÖС£¡£¡£¡£HIBP³Æ58%µÄÊý¾ÝÒѾ­ÔÚHIBPµÄ´æµµÖУ¬£¬ £¬£¬£¬£¬£¬ÕâÅú×¢ËüÃÇÀ´×ÔÓÚÒÔǰµÄÊý¾Ýй¶¡£¡£¡£¡£ÓÉÓÚй¶µÄÓû§Æ¾Ö¤¿ÉÄܱ»ÓÃÓÚײ¿â£¬£¬ £¬£¬£¬£¬£¬½¨ÒéXKCDÂÛ̳Óû§¾¡¿ìÐÞ¸ÄʹÓÃÏàͬÃÜÂëµÄÈÎºÎÆäËüÕË»§µÇ¼ƾ֤¡£¡£¡£¡£



Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/xkcd-forum-breach-exposes-emails-passwords-of-562-000-users/



5.µÂ¹úOLBÒøÐб»ºÚ¿ÍÇÔÈ¡Áè¼Ý150ÍòÅ·Ôª×ʽð


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



°ÍÎ÷·¸·¨ÍÅ»ïͨ¹ý¿Ë¡µÂ¹úOLBÒøÐп¯ÐеÄÍòÊ´│½è¼Ç¿¨£¬£¬ £¬£¬£¬£¬£¬´ÓÔ¼2000Ãû¿Í»§ÖÐÇÔÈ¡ÁË150¶àÍòÅ·Ôª£¨Ô¼165ÍòÃÀÔª£©¡£¡£¡£¡£Õâһ͵ÇÔÊÂÎñ±¬·¢ÔÚÉÏÖÜ£¬£¬ £¬£¬£¬£¬£¬Æ¾Ö¤OLBÒøÐÐÔÚ8ÔÂ27ÈÕÐÇÆÚÎåÐû²¼µÄÉùÃ÷£¬£¬ £¬£¬£¬£¬£¬¸ÃÒøÐÐÒѾ­ÏòËùÓÐÊÜÓ°ÏìµÄ¿Í»§ÍË»¹ÁË×ʽ𡣡£¡£¡£¸ÃÒøÐл¹ÔÚÊÂÎñ±¬·¢ºó½ûÓÃÁËËùÓеÄÍòÊ´ï½è¼Ç¿¨£¬£¬ £¬£¬£¬£¬£¬²¢¿¯ÐÐÌæ»»¿¨¡£¡£¡£¡£Ö»¹ÜԭʼµÄ¿¨Æ¬Êܵ½EMV£¨Ð¾Æ¬ºÍPIN£©ÊÖÒյı£»£»£»£»£» £»¤£¬£¬ £¬£¬£¬£¬£¬·¸·¨·Ö×ÓÈÔͨ¹ý¿Ë¡¿¨ÊµÑéÁË͵ÇÔ£¬£¬ £¬£¬£¬£¬£¬OLBÌåÏÖÕâÊÇÓÐ×éÖ¯µÄ·¸·¨£¬£¬ £¬£¬£¬£¬£¬²¢³ÆÆäûÓÐÔâÓöºÚ¿ÍÈëÇÖ/Êý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£



Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/german-bank-loses-eur1-5-million-in-mysterious-cashout-of-emv-cards/



6.SupermicroЧÀÍÆ÷BMCÎó²î¿ÉÖÂ×°±¸±»Ô¶³Ì½ÓÊÜ



¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


EclypsiumÑо¿Ö°Ô±·¢Ã÷SupermicroЧÀÍÆ÷»ù°åÖÎÀí¿ØÖÆÆ÷£¨BMC£©Öб£´æ¶à¸öÎó²î£¬£¬ £¬£¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßʹÓÃÀ´½ÓÊÜ×°±¸ºÍ»á¼û¹«Ë¾ÍøÂ磬£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÐͺŰüÀ¨X9¡¢X10ºÍX11¡£¡£¡£¡£ÕâЩÎó²îÓëBMCµÄÐéÄâýÌåЧÀÍÓйØ£¬£¬ £¬£¬£¬£¬£¬¸ÃЧÀͼàÌýTCP¶Ë¿Ú623£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚ½«Ô¶³ÌÅþÁ¬µÄ´ÅÅ̾µÏñ×÷ΪÐéÄâµÄuÅÌ»òÈíÅÌ´¦Öóͷ£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ËÄÖÖ²î±ðµÄÎó²î£¬£¬ £¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃÃ÷ÎÄÉí·ÝÑéÖ¤¡¢Î´¼ÓÃܵÄÍøÂçÁ÷Á¿¡¢Èõ¼ÓÃÜÒÔ¼°X10/X11ƽ̨ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÖÁÉÙ47000¸öBMCϵͳ̻¶ÔÚ»¥ÁªÍøÉÏ£¬£¬ £¬£¬£¬£¬£¬ÆäÖдó´ó¶¼Î»ÓÚÃÀ¹ú¡£¡£¡£¡£ÕâЩÎó²îÒÑÓÚ6Ô·ÝÏòSupermicro±¨¸æ£¬£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѾ­Ðû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/09/03/vulnerabilities-supermicro-servers/