¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181129

°ä²¼¹¦·ò 2018-11-29
1¡¢FBI½áºÏGoogleµÈ¶à¼Ò°²È«³§ÉÌ·ÛËé´ó¹æÄ£¸æ°×ڲƭÍÅ»ï3ve

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


FBI½áºÏGoogle¡¢White OpsÒÔ¼°ProofpointµÈ¶à¼Ò°²È«³§É̹²Í¬·ÛËéÁËÒ»¸ö¸æ°×ڲƭÍÅ»ï ¡£¸ÃÔÚÏßڲƭ»î¶¯±»³ÆÎª3ve£¬×Ô2014ÄêÆðÒ»Ïò»îÔ¾£¬µ«ÔÚÈ¥ÄêÀ©´óÁËÆä»î¶¯¹æÄ££¬Îª¹¥»÷Õß´øÀ´Á˳¬¹ý3000ÍòÃÀÔªµÄÊÕÈë ¡£3veϰȾÁ˳¬¹ý170ÍòÌ¨ÍÆËã»ú£¬Ê¹ÓÃ80¶ą̀·þÎñÆ÷²úÉú¶ñÒâÁ÷Á¿£¬²¢¹¹½¨Á˳¬¹ý1Íò¸ö´¹µöÍøÕ¾ ¡£Ôڻ¶¥·åʱÆÚ£¬3veͬʱ²Ù¿ØÁ˳¬¹ý100Íò¸öIPµØÖ·£¬ÆäÖðÈÕڲƭ¸æ°×Ͷ·ÅÁ¿´ï30µ½120ÒÚ´Î ¡£±¾ÖܶþÃÀ¹ú˾·¨²¿¸æ×´ÁËÓë¸Ã¸æ°×ڲƭ»î¶¯ÓйصÄ8Ãû·¸×ïÏÓÒÉÈË ¡£

  

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/3ve-ad-fraud-google.html


2¡¢°²È«³§ÉÌ·¢ÏÖÉ­º£Èû¶ûµÄHeadSetupÈí¼þÒ×ÊÜSSLÖÐÑëÈ˹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Secorvo·¢ÏÖ¶ú»ú³§ÉÌÉ­º£Èû¶ûµÄÅäÌ×Èí¼þHeadSetup´æÔÚÒ»¸ö°²È«·ì϶£¨CVE-2018-17612£©£¬¿Éµ¼ÖÂSSLÖÐÑëÈ˹¥»÷ ¡£×êÑÐÈËÔ±·¢ÏÖ¸ÃÈí¼þÔÚ×°ÖÃʱ»áÔÚÓû§ÍÆËã»úÉÏ×°ÖÃÒ»¸ö¸ùÖ¤ÊéºÍ¼ÓÃܵÄÖ¤Êé˽Կ£¬²¢ÇÒÕâÁ½¸öÎļþ¶ÔËùÓÐЧ»§¶¼ÊÇÒ»ÑùµÄ ¡£¸ÃÈí¼þÔÚÐ¶ÔØÊ±Ò²²»»áɾ³ýÖ¤ÊéÎļþ£¬Ê¹µÃÓû§³ÖÐøÒ×Êܹ¥»÷ ¡£¸ÃÖ¤Êé˽Կ¹ÌÈ»±»¼ÓÃÜÁË£¬µ«Ê¹ÓõÄÊÇAES-128-CBCËã·¨½øÐмÓÃÜ£¬²¢ÇÒÃÜÔ¿ÒÔÃ÷ÎĵĴó¾Ö´æ´¢ÔÚ´úÂëÖУ¨WBCCListener.dll£© ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sennheiser-headset-software-could-allow-man-in-the-middle-ssl-attacks/


3¡¢Atrium HealthÔâºÚ¿Í¹¥»÷£¬Ô¼265Íò»¼ÕßÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ·ÇͶ»úÒ½ÁÆ»ú¹¹Atrium HealthÔâºÚ¿Í¹¥»÷£¬Ô¼265Íò»¼ÕßµÄÐÅϢй¶ ¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚ9ÔÂ22ÈÕÖÁ9ÔÂ29ÈÕÆÚ¼ä£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢¼Òͥסַ¡¢µ®ÉúÈÕÆÚ¡¢±£ÏÕÐÅÏ¢¡¢·þÎñÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅºÍÕË»§Óà¶îµÈ ¡£´Ë±í£¬»¹Óн«½ü70Íò¸öÉç±£ºÅÂëй¶£¬µ«Ã»ÓвÆÕþÐÅϢй¶ ¡£¸Ã×éÖ¯Òѽ«ÓйØÊÂÎñ֪ͨFBI£¬²¢ÏòÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓþ¼à¿Ø·þÎñ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/atrium-health-data-breach-exposed-2-65-million-patient-records/


4¡¢ElasticSearch·þÎñÆ÷¶³ö³¬¹ý5700ÍòÃÀ¹ú¹«ÃñµÄÓ×ÎÒÊý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«³§ÉÌHackenµÄ×êÑÐÈËÔ±Bob Diachenkoͨ¹ýShodan·¢ÏÖÁËÒ»¸ö¿É¹«¿ª½Ó¼ûµÄElasticSearch·þÎñÆ÷£¬ÆäÊý¾Ý¿â¶³öÁ˳¬¹ý5700ÍòÃÀ¹ú¹«ÃñµÄÓ×ÎÒÊý¾Ý ¡£ÕâЩÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼Òͥסַ¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂëºÍIPµØÖ·µÈÐÅÏ¢ ¡£×êÑÐÈËÔ±ÎÞ·¨È·Èϸ÷þÎñÆ÷µÄËùÓÐÕߣ¬µ«ËûÒÔΪ¼ÓÄôóÊý¾Ý¹«Ë¾Data£¦Leads»òÐíÓëÖ®ÓÐ¹Ø ¡£Ä¿Ç°¸Ã·þÎñÆ÷Òѱ»½øÐа²È«¼Ó¹Ì ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/elasticsearch-server-exposed-the-personal-data-of-over-57-million-us-citizens/


5¡¢¿¨°Í˹»ù°ä²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨£¬¶ñÒâÍÚ¿óÈí¼þͨ³£Í¨¹ý¸æ°×Èí¼þ¡¢ÆÆ½âÓÎÏ·»òÆäËüµÁ°æÄÚÈݽøÈëÓû§ºÍÆóÒµµÄÍÆËã»ú£¬²¢ÇÒ´´½¨¶ñÒâÍÚ¿óÈí¼þµÄÃż÷Ò²Ô½À´Ô½µÍ ¡£2018Ëê×ï¿ýÒâÍÚ¿ó¹¥»÷¼±¾çÔö³¤£¬ËæºóÅã°é׿ÓÃÜÇ®±Ò¼ÛÖµµÄ½µÂä¶ñÒâÍÚ¿ó»î¶¯ÓÖÏÔÖø½µÂ䣬µ«¸ÃÍþвÒÀÈ»²»ÈÝÓ×êï ¡£¹ÌȻһЩ¹ú¶È¶Ô¼ÓÃÜÇ®±Ò½øÐÐÁ¢·¨½ÚÔ죬µ«ÕâЩ¹ú¶ÈµÄ¶ñÒâÍÚ¿ó»î¶¯²¢Ã»ÓÐÊܵ½Ó°Ïì ¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-2018-story-of-the-year-miners/89096/


6¡¢Î÷ÃÅ×ÓÅû¶SIMATIC S7-1500²úÆ·ÖеĶà¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Î÷ÃÅ×ÓÕë¶ÔSIMATIC S7-1500²úÆ·ÖеĶà¸ö°²È«·ì϶°ä²¼¾¯±¨ ¡£Æ¾¾ÝÎ÷ÃÅ×ÓµÄ˵·¨£¬ÕâЩ·ì϶ӰÏìÁ˹̼þ°æ±¾ÎªV2.6.0µÄGNU/Linux×Óϵͳ£¬²¢ÇÒ½«±ÉÈËÒ»¸ö¹Ì¼þ°æ±¾Öн¨¸´ ¡£Óйطì϶µÄÊýÁ¿Îª21¸ö£¬ÕâЩ·ì϶¿Éµ¼Ö»ؾø·þÎñ¡¢ËÁÒâ´úÂëÖ´ÐкÍÓû§Ã¶¾ÙµÈÎÊÌâ ¡£Ôڹ̼þ¸üа䲼֮ǰ£¬Î÷ÃÅ×Ó½¨ÒéÓû§ÀûÓÃÎ÷ÃÅ×ÓÉî¶È·ÀÓù´ëÊ©²¢ÇÒÔ¤·ÀÔËÐв»³ÉÐÅÆðÔ´µÄ·¨Ê½ ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-warns-linux-gnu-flaws-controller-platform



ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù