¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180626

°ä²¼¹¦·ò 2018-06-26

¡¾Íþвµý±¨¡¿Ó¢¹ú˰Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÍøÂçÔ¼510ÍòÓû§µÄÓïÒô¼Í¼


ÒþÖÔ±£»¤×éÖ¯Big Brother Watch·¢ÏÖÓ¢¹úµÄ˰Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÍøÂçÔ¼510ÍòÓ¢¹ú¹«ÃñµÄÓïÒô¼Í¼¡£HMRCͨ¹ý2017Äê1ÔÂÍÆ³öµÄÒ»ÏîÓïÒô¼ø±ð·þÎñÍøÂçÁËÕâЩ¼Í¼£¬¸Ã·þÎñÔÊÐíÓû§ÔÚºô½ÐHMRCʱͨ¹ýÓïÒô½øÐÐÉí·ÝÑéÖ¤¡£µ«Big Brother Watch·¢ÏÖÓû§ÎÞ·¨Ñ¡Ôñ²»Ê¹Óø÷þÎñ£¬ËùÓв¦´òHMRCÈÈÏßµÄÓû§¶¼±»ÆÈ¼ÔìÁËÓïÒô¼Í¼£¬²¢ÇÒÓû§ÎÞ·¨Ñ¡Ôñ´ÓHMRCµÄÊý¾Ý¿âÖÐɾ³ýÆäÓïÒô¼Í¼¡£¸Ã×éÖ¯ÒÔΪHMRC´Ë¾ÙÏÔÖøÎ¥·´ÁËGDPR£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒѶԴËÊ·¢Õ¹ÕýʽµÄµ÷²é¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/uk-tax-agency-recorded-the-voices-of-51-million-brits/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔÒâ´óÀûµÄÒøÐÐľÂíUrsnifµÄбäÖÖ


CSE Cybsec ZLab×êÑÐÍŶӷ¢ÏÖÖØÒªÕë¶ÔÒâ´óÀû¹«Ë¾µÄÒøÐÐľÂíUrsnifµÄбäÖÖ¡£Ursnif¿ÉÄÜÇÔÈ¡Óû§µÄÍ´´¦£¬Ô̺¬Óû§µÄµç×ÓÓÊÏäÕË»§¡¢ÔÆ´æ´¢¡¢¼ÓÃÜÇ®±ÒÂòÂôƽ̨ÒÔ¼°µç×ÓÉÌÎñÍøÕ¾µÈµÄÍ´´¦¡£´Ó6ÔÂ6ÈÕÆðÍ·£¬×êÑÐÈËÔ±·¢ÏÖ¸ÃбäÖֵĹ¥»÷»î¶¯£¬²¢½«Õâ´Î¹¥»÷»î¶¯Óë½©Ê¬ÍøÂçNecurs½øÐйØÁª¡£×êÑÐÈËÔ±Ôڻ㱨ÖÐÅû¶Á˾ßÌåµÄÓйØIoCºÍYara¹æ¶¨¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73865/malware/ursnif-banking-hits-italy.html


¡¾·ì϶²¹¶¡¡¿ÂÞ¿ËΤ¶û×Ô¶¯»¯½¨¸´Æä²úÆ·ÖеĿɵ¼ÖÂDoSµÄ°²È«·ì϶


ÂÞ¿ËΤ¶û×Ô¶¯»¯½¨¸´Ò»¸ö¿Éµ¼ÖÂDoSµÄ°²È«·ì϶£¬¸Ã·ì϶£¨CVE-2017-9312£©Ó°ÏìÁËAllen-Bradley CompactLogix 5370ºÍCompact GuardLogix 5370¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷£¬ÕâЩ²úÆ·±»¿í·ºÓÃÓڹؼü»ù´¡ÉèÊ©¡¢¹©Ë®ÏµÍ³¡¢ÓéÀÖ¡¢Æû³µ¡¢Ê³Æ·ºÍÒûÁϵÈÐÐÒµµÄ½ÚÔìÁ÷³ÌÖС£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶´¥·¢É豸µÄ²»³É¸´Ô­¹ÊÕÏģʽ£¨MNRF£©£¬´Ó¶øµ¼ÖÂDoS¡£ÂÞ¿ËΤ¶ûÔڹ̼þ°æ±¾31.011Öн¨¸´Á˸÷ì϶£¬½¨ÒéÓû§¾¡¿ì¸üС£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/rockwell-patches-flaw-affecting-safety-controllers-several-vendors


¡¾·ì϶²¹¶¡¡¿Oracle½¨¸´×î½üÅû¶µÄSpectreºÍMeltdown·ì϶µÄбäÌå

ÉÏÖÜÎåOracle°ä·¢ÆäÆðÍ·°ä²¼²úÆ·µÄÈí¼þºÍ΢´úÂë¸üУ¬ÒÔ½¨¸´×î½üÅû¶µÄSpectreºÍMeltdown·ì϶µÄбäÌå¡£ÕâЩбäÌåÔ̺¬Variant 4£¨CVE-2018-3639£©ÒÔ¼°Variant 3a£¨CVE-2018-3640£©µÈ¡£Oracle°²È«Ö÷¹ÜEric Maurice³ÆOracleÒѾ­Õë¶ÔOracle LinuxºÍOracle VMÐé¹¹»¯²úÆ·°ä²¼Á˸üУ¬¸ü¶à¸üкͲ¹¶¡½«ÔÚËæºóÂ½Ðø°ä²¼¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/oracle-patches-new-spectre-meltdown-vulnerabilities


¡¾·ì϶²¹¶¡¡¿TapplockÖÇÄÜËø°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö°²È«·ì϶


°²È«×êÑÐÈËÔ±Andrew TierneºÍVangelis Stykas·¢ÏÖTapplockÖÇÄÜËøÖеĶà¸ö°²È«·ì϶£¬Ô̺¬ÆäAPPʹÓÃHTTP½øÐÐͨѶ¶øÃ»ÓнøÐд«Êä¼ÓÃÜ£»Ã»ÓÐʹÓÃÉí·ÝÑéÖ¤ºÍ̸£»ÔڵǼTapplockÕË»§ºó¿Éͨ¹ýÆäËûÓû§µÄÕË»§ID½Ó¼ûÆäÃô¸ÐÊý¾Ý£¬ÈçÓû§Í¨¹ýÀ¶ÑÀ½âËøÊ±µÄµØÖ·ºÍÓû§µÄµç×ÓÓʼþµÈ¡£Tapplock°ä²¼ÁËÓйصݲȫ¸üУ¬²¢½¨ÒéÓû§¾¡¿ì½øÐÐÉý¼¶¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/unbreakable-smart-lock-tapplock-issues-critical-security-patch/132918/


¡¾Õþ²ßÂÉÀý¡¿¹«°²²¿Ä⽫ÓÚ±¾Öܰ䲼¡¶ÍøÂ簲ȫµÈ¼¶±£»¤ÌõÀý¡·


Óɹ«°²²¿Ç£Í·£¬»áͬÖÐÑëÍøÐŰ졢¹ú¶È±£Ãܾ֡¢¹ú¶ÈÃÜÂëÖÎÀí¾Ö½áºÏÔì¶©µÄ¡¶ÍøÂ簲ȫµÈ¼¶±£»¤ÌõÀý¡·£¨ÒÔϼò³Æ¡°ÌõÀý¡±£©Ä⽫ÓÚ±¾ÖÜÔÚÍøÉϰ䲼¡£¹«°²²¿ÍøÂ簲ȫ±£ÎÀ¾Ö×ܹ¤¹ùÆôÈ«ÔÚ½²»°ÖаµÊ¾£¬¹Ø¼üÐÅÏ¢»ù´¡ÉèÊ©±£»¤ÊÇÍøÂ簲ȫµÈ¼¶±£»¤Ôì¶È2.0µÄ³Áµã¡£Ä¿Ç°ÖÐÑëÍøÐŰìºÍ¹«°²²¿Ë«Ç£Í·Ôì¶©µÄ¡¶¹Ø¼üÐÅÏ¢»ù´¡ÉèÊ©±£»¤ÌõÀý¡·²ÝÄ⹤×÷ÒѾ­ÊµÏÖ£¬ÔÚ×ß˾·¨·¨Ê½¡£

Ô­ÎÄÁ´½Ó£ºhttp://m.sohu.com/news/a/237626584_161795