ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ31ÖÜ

Ðû²¼Ê±¼ä 2018-08-07

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


 2018Äê07ÔÂ30ÈÕÖÁ08ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇSamsung SmartThings Hub video-core HTTPЧÀÍÆ÷»º³åÇøÒç³öÎó²î£»£»£»£»£»£»Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿ £¿£¿ £¿£¿£¿éȨÏÞÌáÉýÎó²î£»£»£»£»£»£»Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î£»£»£»£»£»£»Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î£»£»£»£»£»£»SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£

 

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÓ¢¹úµç×ÓÉÌÎñЧÀÍÉÌÊý¾Ý¿âй¶£¬£¬£¬ £¬£¬Ô¼140ÍòÓû§ÊÜÓ°Ï죻£»£»£»£»£»Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶£»£»£»£»£»£»ICS-CERTÐû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ£»£»£»£»£»£»RedditÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶£»£»£»£»£»£»KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ¡£¡£¡£¡£

 

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£

 

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢Samsung SmartThings Hub video-core HTTPЧÀÍÆ÷»º³åÇøÒç³öÎó²î

 

 Samsung SmartThings Hub video-core HTTPЧÀÍÆ÷´¦Öóͷ£¡®clips¡¯±í±£´æ»º³åÇøÒç³ö£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0583


2¡¢Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿ £¿£¿ £¿£¿£¿éȨÏÞÌáÉýÎó²î

 

Intel Smart Sound TechnologyÇý¶¯Ä£¿ £¿£¿ £¿£¿£¿é±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬ÒÔÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00163.html


3¡¢Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î

 

Foxit PDF Reader JavaScriptÒýÇæ±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÎļþÇëÇ󣬣¬£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬ £¬£¬ÒÔÓ¦ÓóÌÐòȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

 

 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588


4¡¢Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î

 

Apple iOS Wi-Fi×é¼þ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÓ¦ÓóÌÐò£¬£¬£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬ £¬£¬¿ÉÈÆ¹ýɳºÐÌáÉýȨÏÞ¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://lists.apple.com/archives/security-announce/2018/Jul/msg00001.html


5¡¢SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î

 

SoftNAS Cloud OS webÖÎÀíÔ±¿ØÖÆÌ¨ÖеÄsnserv¾ç±¾Ã»ÓйýÂËÓû§ÊäÈ룬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.softnas.com/docs/softnas/v3/html/updating_to_the_latest_version.html

 

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ó¢¹úµç×ÓÉÌÎñЧÀÍÉÌÊý¾Ý¿âй¶£¬£¬£¬ £¬£¬Ô¼140ÍòÓû§ÊÜÓ°Ïì

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ñо¿Ö°Ô±Taylor Ralston·¢Ã÷Ó¢¹úµç×ÓÉÌÎñЧÀÍÉÌFashion NexusµÄÒ»¸öÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬ £¬£¬¶à¸ö´ò°çºÍÅäÊÎÍøÕ¾µÄÓû§ÐÅϢй¶£¬£¬£¬ £¬£¬°üÀ¨Jaded London¡¢AX ParisºÍElle Belle AttireµÈÆ·ÅÆ¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Ô¼140ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬ £¬£¬°üÀ¨MD5¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£Ã»Óм£ÏóÅú×¢Óû§µÄÒøÐп¨ÐÅÏ¢±£´æÎ£º¦¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/online-fashion-shoppers-exposed-ecommerce-breach/

 

2¡¢Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


 Boys Town¹ú¼ÒÑо¿Ò½ÔºÐû²¼Í¨Öª³Æ¸Ã×éÖ¯ÓÚ2018Äê5ÔÂ23ÈÕÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶¡£¡£¡£¡£Õâ¿ÉÄÜÊÇÓйضùͯҽÁÆÐ§À͵Ä×î´ó¹æÄ£µÄÊý¾Ýй¶¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢Õï¶Ï»òÖÎÁÆÐÅÏ¢¡¢ÒøÐÐÕ˺š¢Óû§ÃûºÍÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£¹¥»÷ÕßÈëÇÖÁ˸Ã×éÖ¯Ô±¹¤µÄµç×ÓÓʼþÕÊ»§£¬£¬£¬ £¬£¬²¢Í¨¹ýδÊÚȨ»á¼û»ñÈ¡ÁËÕâЩÐÅÏ¢¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/data-breach-healthcare.html

 

3¡¢ICS-CERTÐû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

 

¹ú¼Ò¹¤Òµ»¥ÁªÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©Ðû²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ£¬£¬£¬ £¬£¬±¨¸æ´ÓµØÇøÂþÑÜ¡¢Æ·ÅÆÂþÑÜ¡¢ÍþвÂþÑܵȶà¸ö½Ç¶ÈÐðÊöº£ÄÚÍøÂçÊÓÆµ¼à¿ØÏµÍ³µÄÇå¾²Ì¬ÊÆÇéÐΣ¬£¬£¬ £¬£¬²¢Õë¶Ô½üÄêÀ´±¬·¢µÄÍøÂçÊÓÆµ¼à¿ØÏµÍ³Çå¾²ÊÂÎñÒòÓÉÌá³öÁËÏìÓ¦µÄΣº¦Ìá·ÀºÍÇå¾²Ó¦¶Ô¼Æ»®£¬£¬£¬ £¬£¬¸øÏà¹ØÕþ¸®²¿·Ö¡¢×éÖ¯ºÍÑо¿»ú¹¹Ìṩ²Î¿¼ºÍ½è¼ø¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/be9def54499644afb6ce4b119e5e7d42.html

 

4¡¢RedditÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

 

RedditÐû²¼ÆäÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶¡£¡£¡£¡£¹¥»÷ÕßÈÆ¹ýË«ÒòËØÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§£¬£¬£¬ £¬£¬²¢ÇÔÈ¡Á˲¿·Öµç×ÓÓʼþµØµã¡¢ÈÕÖ¾¼Í¼ÒÔ¼°°üÀ¨¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä£¬£¬£¬ £¬£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·Ý°üÀ¨2005ÄêÖÁ2007Äê5ÔÂʱ´úµÄÓû§Êý¾Ý£¬£¬£¬ £¬£¬ÈçÕË»§Æ¾Ö¤£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØµãºÍ¹ûÕæ/˽ÈËÐÂÎÅ¡£¡£¡£¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍÐû²¼µÄÌû×Ó±»ÒÔΪÊÇÇå¾²µÄ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/

 

5¡¢KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ICOƽ̨KickICOÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Áè¼Ý7000ÍòKICKÁîÅÆ±»ÇÔ£¨¼ÛÖµÔ¼770ÍòÃÀÔª£©¡£¡£¡£¡£Æ¾Ö¤KickICOÊ×ϯִÐйÙAnti DanilevskiµÄ˵·¨£¬£¬£¬ £¬£¬¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ7ÔÂ26ÈÕÐÇÆÚËĵÄUTCʱ¼ä09:04¡£¡£¡£¡£¹¥»÷Õß»ñÈ¡ÁË¿ª·¢Ö°Ô±µÄ˽Կ£¬£¬£¬ £¬£¬²¢ÐÞ¸ÄÖÇÄܺÏÔ¼µÄÐÐΪ£¬£¬£¬ £¬£¬´Ý»ÙÁË40¸öµØµãÖеÄKICKÁîÅÆÈ»ºóÔÚ40¸ö×Ô¼ºµÄÇ®°üÖн¨ÉèµÈÁ¿µÄÐÂÁîÅÆ¡£¡£¡£¡£KickICO¿ª·¢Ö°Ô±ÏÖÔÚÒÑÖØÐ»ñµÃÖÇÄܺÏÔ¼µÄ»á¼ûȨ¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/kickico-platform-loses-77-million-in-recent-hack/