¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180629

°ä²¼¹¦·ò 2018-06-29

 ¡¾Êý¾Ýй¶¡¿TicketmasterÔâºÚ¿ÍÈëÇÖ£¬Ô¼5%µÄÓû§µÄÊý¾Ýй¶


ƱÎñ¹«Ë¾Ticketmaster°ä·¢ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬¸ÃÊÂÎñ²úÉúÔÚ6ÔÂ23ÈÕÐÇÆÚÁù£¬ÆäÈ«Êý¿Í»§µÄÔ¼5%ÊÜÓ°Ïì¡£Ticketmaster³Æ£¬²¿ÊðÔÚÆä²¿ÃŹú¼ÊÍøÕ¾ÉϵÄʵʱ̸Ìì´°¿ÚÓײ¿¼þInbenta±»·¢ÏÖÓÃÓÚÏòÓû§·Ö·¢¶ñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þ»áÇÔÈ¡Óû§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µÇ¼ʹ´¦¡¢ÒøÐп¨ÐÅÏ¢µÈÊý¾Ý¡£Ö»Óв¿ÃŹú¼ÊÓû§ÊÜÓ°Ï죬±±ÃÀµØÓòµÄÓû§²»ÊÜÓ°Ïì¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ticketmaster-announces-data-breach-affecting-5-percent-of-all-users/


¡¾Êý¾Ýй¶¡¿FacebookµÚÈý·½ÀûÓõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæ¶Ôй¶·çÏÕ


×êÑÐÈËÔ±Inti De Ceukelaire·¢ÏÖµÚÈý·½ÖÇÁ¦½ÏÁ¿ÀûÓÃNametests.comʹԼ1.2ÒÚFacebookÓû§µÄÊý¾ÝÃæ¶Ôй¶·çÏÕ¡£Ö»ÓÐFacebookÓû§ÔÚNameTestsÍøÕ¾ÉÏ×¢²á£¬¸Ã¹«Ë¾½«Äܹ»»ñÈ¡Óû§µÄÓ×ÎÒÊý¾Ý¡£µ«×êÑÐÈËÔ±·¢ÏÖNameTestsÍøÕ¾ÃýÎ󵨽«Æä¡°Access-Control-Allow-Origin¡±Õ½ÊõÅäÖóÉͨÅä·û*£¬ÕâÔÊÐíÈκÎÍøÕ¾½Ó¼ûÆä×ÊÔ´£¬Ô̺¬ÕâЩÓû§µÄÓ×ÎÒÊý¾Ý¡£NameTestsÒѾ­½¨¸´Á˸ÃÎÊÌâ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/facebook-users-data-leak.html


¡¾·ÖÎö»ã±¨¡¿×êÑлú¹¹°ä²¼¹ØÓÚSSDP·´Éä·Å´ó¹¥»÷µÄÇ÷ÏòµÄ·ÖÎö»ã±¨


Arbor Networks·¢ÏÖÒ»ÖÖÐÂÀàÐ͵ÄSSDP·´Éä·Å´ó¹¥»÷£¬ÕâÖÖ¹¥»÷ÀûÓ÷dz߶ȵĶ˿Ú¡£»ã±¨Ö¸³ö£¬½ÓÈ뻥ÁªÍøµÄÔ¼500Íò¸öSSDP·þÎñÆ÷ÖеĴóÎÞÊý¶¼´Óһʱ¶Ë¿Ú½øÐÐÏìÓ¦£¬¶øÊ¹ÓÃһʱ¶Ë¿ÚµÄSSDP¹¥»÷Äܹ»Èƹý¶Ë¿Ú¹ýÂË·À»¤´ëÊ©¡£ÕâÖÖ¹¥»÷ÐÐΪÓ뿪Դ¿âlibupnpÓйØ£¬¸Ã¿â±»ÓÃÓÚ¸÷ÀàCPEÉ豸¡£ÕâÖÖ¹¥»÷»á²úÉúÓµÓÐһʱԴ¶Ë¿ÚºÍÖ¸±ê¶Ë¿ÚµÄUDPÊý¾Ý°ü£¬ÕâʹµÃ·À»¤Ô½·¢ÄÑÌâ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://asert.arbornetworks.com/a-new-twist-in-ssdp-attacks/


¡¾¹¥»÷ÊÂÎñ¡¿ProtonMailÔâDDoS¹¥»÷£¬¹¥»÷ÕßÒÉΪ¶íÂÞ˹ºÚ¿ÍÍÅ»ï


±¾ÖÜÈýProtonMailÔâµ½ÒÉËÆ¶íÂÞ˹ºÚ¿ÍÍÅ»ïµÄDDoS¹¥»÷£¬¹¥»÷³ÖÐøÁ˼¸¸öÓ×ʱ£¬×µÄ¼ä¶Ï¹¦·òΪ10·ÖÖÓ¡£ProtonMail³ÆÖ»¹ÜËüÿÌì³ÇÊÐÔâµ½DDoS¹¥»÷£¬µ«Õâ´Î¹¥»÷¸üΪÑϳÁ£¬Æä·åÖµÁ÷Á¿´ï500Gbps£¬ÊÇÓмͼµÄ×î´óDDoS¹¥»÷Ö®Ò»¡£ProtonMail°µÊ¾¹ÌÈ»Óû§µÄµç×ÓÓʼþ»áÑÓ³¤£¬µ«²¢Î´µ¼ÖÂÓʼþÃÔʧ¡£Æä·þÎñÔÚÔ¼Èý¸öÓ×ʱºó¸´Ô­ÁËÕý³£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/significant-ddos-attack-protonmail-blamed-russia-linked-group


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±³ÆÕë¶ÔSpectre·ì϶µÄä¯ÀÀÆ÷²¹¶¡¿ÉÄܱ»Èƹý


ƾ¾Ý±¾ÖܶþAleph Security°ä²¼µÄ×êÑУ¬Æä×êÑÐÈËÔ±¿ÉÈÆ¹ýSpectre·ì϶µÄä¯ÀÀÆ÷²¹¶¡£¬´ÓÄÚ´æÖмìË÷Óû§µÄÃô¸ÐÊý¾Ý¡£×êÑÐÈËÔ±°µÊ¾ÆäPoCÔÚEdge¡¢ChromeºÍSafariµÈä¯ÀÀÆ÷É϶¼¿É¹¤×÷£¬µ«¶ÔFirefoxÎÞЧ£¬ÓÉÓÚMozillaʹÓÃÁË·ÖÆçµÄ½¨²¹·½Ê½¡£¸ÃPoC¿ÉÄÜÒÔ¼«¶ÈµÍµÄ¿ìÂÊй¶Êý¾Ý£¬×êÑÐÈËÔ±ÖØÒªÌ½ÇóÁËSpectre·ì϶µÄä¯ÀÀÆ÷²¹¶¡µÄÓÐЧÐÔ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/some-spectre-in-browser-mitigations-can-be-defeated/


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃNSAºÚ¿Í¹¤¾ßDoublePulsarÈëÇÖǶÈëʽWindowsϵͳ


×êÑÐÈËÔ±Capt.Meelo¶ÔNSAºÚ¿Í¹¤¾ßDoublePulsar½øÐÐÁËÒÆÖ²£¬Ê¹ÆäÔÚWindowsǶÈëʽϵͳÉÏÒ²¿É¹¤×÷¡£µ±DoublePulsarÔÚ2017Äê4Ô°䲼ʱ£¬ÆäÄܹ»×÷ÓÃÓÚ³ýÁË×îеÄWindows 10Ö®±íµÄËùÓÐÖØÒªWindows°æ±¾ÉÏ¡£2017ÄêDoublePulsarϰȾÁ˳¬¹ý40Íǫ̀µçÄÔ¡£Í¨¹ýÒÆÖ²Ö®ºó£¬DoublePulsar´Ë¿ÌÄܹ»×÷ÓÃÓÚIoTÉ豸¡¢PoS»ú»òATMµÈÔËÐÐWindows IoT Core OSµÄÉ豸¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/nsa-exploit-doublepulsar-patched-to-work-on-windows-iot-systems/