¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181212
°ä²¼¹¦·ò 2018-12-12
ÃÀ¹ú¶àÒéÔºÄÜÔ´ºÍóÒ×ίԱ»á°ä²¼ÍøÂ簲ȫսÊõ»ã±¨£¬Ö¼ÔÚÈ·Á¢Ô¤·À»ººÍ½âÍøÂ簲ȫÊÂÎñµÄÕ½Êõ¡£¸Ã»ã±¨ÒÔΪµ±Ç°ÃÀ¹úµÄÍøÂ簲ȫÐж¯²¢Î´¸úÉÏ»¥ÁªÍøµÄ·¢Õ¹£¬´«Í³µÄÐÅÏ¢¼¼ÊõÕ½ÊõÔÚÓ¦¶Ô²»ÐÝÔö³¤µÄÍøÂ簲ȫÊÂÎñÖÐÊÕЧÉõ΢¡£»ã±¨ÊáÀí³öÁùµãÍøÂ簲ȫ¸ÅÏëÓëÁùÏîÍøÂ簲ȫÓÅÏÈÏÔ̺¬³ÉÁ¢ÆÕ±é½ÓÊܵÄÐͬÅû¶·¨Ê½¡¢ÒýÈëÈí¼þÎïÁÏÇåµ¥£¨software bill of materials£¬¼ò³ÆSBOM£©¡¢Ö§³Ö¿ªÔ´Èí¼þ¡¢ÃÀÂúCVE·¨Ê½¡¢Ö´Ðм¼ÊõÐÔÃüÖÜÆÚÖ§³ÖÕ½ÊõÒÔ¼°Ç¿»¯¹«Ë½ºÏ×÷ģʽ¡£
ÔÎÄÁ´½Ó£º
https://energycommerce.house.gov/wp-content/uploads/2018/12/12.07.18-Cybersecurity-Strategy-Report.pdf2¡¢ÎªÌáÉý°²È«ÐÔ£¬Ó¢¹úNHS½«ÓÚ2020ÄêÈ«Ãæ½ûÓô«Õæ»ú
Ó¢¹ú¹ú¶ÈÎÀ×ÌÊÂÎñ¾Ö£¨NHS£©ÈÕǰ°ä·¢£¬½«´ÓÏÂÔÂÆð²»ÔٲɰìеĴ«Õæ»ú£¬²¢ÓÚ2020Äê3ÔÂ31ÈÕ½ûÓÃËùÓеĴ«Õæ»ú¡£´Ë¾ÙÊÇΪÁËÌáÉýNHSµÄ°²È«ÐÔ£¬Ó¢¹úÎÀÉú²¿³¤Matt Hancock°µÊ¾´«Õæ»úÀ©´óÁ˹¥»÷Ãæ£¬¶øµç×ÓÓʼþ±È´«Õæ»ú¸üΪ°²È«ºÍÓÐЧ¡£Æ¾¾ÝÓ¢¹ú»Ê¼Ò±í¿ÆÑ§Ôº£¨RCS£©µÄ¹À¼Æ£¬½ØÖÁ2018Äê7ÔÂNHSÈÔÔÚʹÓó¬¹ý8000̨´«Õæ»ú¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/nhs-fax-ban-set-to-improve/3¡¢ÒòÎóµ¼Ïû·ÑÕߣ¬Òâ´óÀûICA¶ÔFacebook·£¿î1000ÍòÅ·Ôª
Òâ´óÀû¾ºÕùÖÎÀí¾Ö£¨ICA£©ÒòFacebookÎ¥·´ÁËÏû·ÑÕß·¨°¸¶ø¶ÔÆä´¦ÒÔÁ½Ïî¹²¼Æ1000ÍòÅ·ÔªµÄ·£¿î¡£ICA³ÆFacebookÔÚÊèµ¼Ïû·ÑÕß×¢²áµÄ¹ý³ÌÖдæÔÚÎóµ¼ÐÐΪ£¬Ã»Óгä·Ö·î¸æÓû§ËûÃǵÄÊý¾Ý½«±»ÓÃÓÚóÒ×Ö÷ÕÅ£¬´Ë¾ÙÎ¥·´ÁËÏû·ÑÕß·¨°¸µÄµÚ21ºÍ22Ìõ¡£´Ë±í£¬FacebookÔÚûÓÐÃ÷ȷ֪ͨºÍÊÂÏÈ»ñµÃÓû§Ðí¿ÉµÄÇé¿öϽ«Êý¾ÝÌṩ¸øµÚÈý·½£¬Î¥·´ÁËÏû·ÑÕß·¨°¸µÄµÚ24ºÍ25Ìõ¡£Æ¾¾Ý¸Ã·¨°¸µÚ27Ìõ£¬Facebook»¹±Ø±ØÒªÏòËùÓÐЧ»§°ä²¼¾À´íÉêÃ÷¡£
ÔÎÄÁ´½Ó£º
http://en.agcm.it/en/media/press-releases/2018/12/Facebook-fined-10-million-Euros-by-the-ICA-for-unfair-commercial-practices-for-using-its-subscribers%E2%80%99-data-for-commercial-purposes4¡¢³¬¹ý30¸ö¹ú¶ÈµÄ4Íòµ±¾ÖÍøÕ¾Í´´¦±»ÇÔ£¬»òÒÑÔÚ°µÍøÏúÊÛ
Group-IB×êÑÐÈËÔ±·¢ÏÖ³¬¹ý30¸ö¹ú¶ÈµÄ4Íòµ±¾ÖÍøÕ¾Í´´¦±»ÇÔ£¬ÕâЩÐÅÏ¢ÊÇ·¸×ï·Ö×ÓÍøÂç¶øÀ´£¬²¢ÇÒ¿ÉÄÜÒÑÔÚ°µÍøÂÛ̳ÉÏÏúÊÛ¡£´óÎÞÊýÊܺ¦ÕßλÓÚÅ·ÖÞ£¬Ô̺¬Òâ´óÀû£¨52%£©¡¢É³Ìذ¢À²®£¨22%£©ÒÔ¼°ÆÏÌÑÑÀ£¨5%£©¡£Êܺ¦Õß»¹Ô̺¬·¨¹ú£¨gouv.fr£©¡¢ÐÙÑÀÀû£¨gov.hu£©¡¢ÈðÊ¿£¨admin.ch£©µÈ¹ú¶ÈÈ·µ±¾ÖÍøÕ¾ÒÔ¼°ÒÔÉ«Áйú·À¾ü£¨idf.il£©¡¢¸ñ³¼ªÑDzÆÕþ²¿£¨mof.ge£©¡¢Å²ÍþÒÆÃñ¾Ö£¨udi.no£©µÈÍøÕ¾¡£Group-IBÒÑÏòÕâЩ¹ú¶ÈµÄCERT´«µÝÁËÓйطçÏÕ¡£µ±¾ÖÍøÕ¾µÄµÇ¼ʹ´¦ÔÚ°µÍøÊг¡Éϲ¢²»³£¼û£¬ÓÉÓÚËüÃÇûÓÐÖ±½ÓµÄ²ÆÕþ¼ÛÖµ£¬µ«APT¹¥»÷Õß¿ÉÀûÓÃÕâЩʹ´¦ÉøÈëµ±¾ÖÍøÕ¾ºÍÇÔÈ¡»úÃÜÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-steal-over-40k-logins-for-gov-services-in-30-countries/5¡¢ÃÀ¹ú¿ÆµÂ½ÇÉçÇøÑ§ÔºÔâ´¹µö¹¥»÷£¬Ô¼81ÍòÃÀÔª±»ÇÔ
ÃÀ¹ú¿ÆµÂ½ÇÉçÇøÑ§ÔºÔâµ½ÍøÂç¹¥»÷£¬¹¥»÷Õßͨ¹ý´¹µö¹¥»÷¿ªÊÍÁËÖ¼ÔÚÇÔÈ¡ÒøÐÐÐÅÏ¢µÄ¶ñÒâÈí¼þ£¬²¢´Ó¸ÃѧԺÇÔÈ¡ÁË80.7ÍòÃÀÔª¡£¸ÃѧԺ·¢ÏÖ²¢×èÖ¹Á˺óÐøµÄ¼¸´Î¹¥»÷£¬²¢ÒÑÓëÒøÐкÏ×÷×·»ØÁË27.9ÍòÃÀÔªµÄ±»µÁ×ʽð¡£Ä¿Ç°Ã»ÓиöñÒâÈí¼þÈôºÎÇÔÈ¡×ʽðµÄ¾ßÌåÐÅÏ¢£¬µ«¸ÃѧԺ°µÊ¾ÉÐÎÞÖ¤¾ÝÅúעѧÉú¡¢Ô±¹¤µÄÓ×ÎÒÉí·ÝÐÅÏ¢ºÍ¼Í¼ÊÜÕâ´Î¹¥»÷Ó°Ïì¡£ÂíÈøÖîÈûÖÝÓëÁª¹ú¹ÙÔ¹Øý¶ÔÕâ´Î͵ÇÔÊÂÎñ·¢Õ¹µ÷²é¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/807-130-stolen-by-hackers-after-cape-cod-community-college-phishing-attack-524208.shtml6¡¢phpMyAdmin°ä²¼³ÁÒª¸üУ¬½¨¸´3¸ö°²È«·ì϶
phpMyAdmin°ä²¼ÁËа汾4.8.4£¬½¨¸´ÁË3¸ö°²È«·ì϶£¬Ô̺¬±¾µØÎļþÔ̺¬·ì϶£¨CVE-2018-19968£©£¬¸Ã·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß´Ó·þÎñÆ÷µÄ±¾µØÎļþÖлñÈ¡Ãô¸ÐÄÚÈÝ£»¿çÕ¾ÒªÇóαÔì·ì϶(CSRF)/XSRF£¨CVE-2018-19969£©£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷Õß½øÐÐÓꦵÄSQL²Ù×÷£»ÒÔ¼°XSS·ì϶£¨CVE-2018-19970£©¡£Ð°汾»¹Ô̺¬ÁËһЩbug½¨¸´£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/phpmyadmin-security-update.htmlÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ