¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190115

°ä²¼¹¦·ò 2019-01-16
1¡¢Ó¢¹úBSIA°ä²¼»¥Áª°²Õûϵͳ×î¼Ñʵ¼ÊÖ¸ÄÏ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú°²·ÀÐÐҵЭ»á£¨BSIA£©°ä²¼»¥Áª°²Õûϵͳ×î¼Ñʵ¼ÊÖ¸ÄÏ¡£¸ÃÖ¸ÄÏÖ¼ÔÚ×î´óÏ޶ȵØÏ÷¼õµç×Ó°²ÕûϵͳÖеÄÍøÂçÏνÓÉ豸¡¢Èí¼þºÍϵͳµÄÊý×ÔìÆ»µ·çÏÕ¡£¸ÃÖ¸ÄÏÒÔÐÐÒµµÄ×î¼Ñ¹ú¼Êʵ¼ÊΪ»ù´¡£¬²¢²Î¿¼¹«ÈϵĹú¼ÊÖ¸ÄϺͳ߶È£¬Äܹ»Ô®ÊÖ»¥Áª°²Õûϵͳ¹©¸øÁ´ÖеÄÉè¼ÆÕß¡¢Ôì×÷ÉÌ¡¢×°ÖÃÈËÔ±¡¢ÊØ»¤ÈËÔ±¡¢·þÎñÌṩÉ̺ÍÓû§ÌáÉý°²È«ÏνӵÄÐÅÄî¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/bsia-guidelines-digital-sabotage/


2¡¢ETC51%¹¥»÷Õß½«¼ÛÖµ10ÍòÃÀÔªµÄETC·µ»¹¸øGate.io

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ƾ¾ÝGate.ioµÄ˵·¨£¬2019Äê1ÔÂ10ÈÕETCÍøÂç51%¹¥»÷ÕßÍË»ØÁ˼ÛÖµ10ÍòÃÀÔªµÄETC¡£¸ú×Ù·¢ÏÖ»¹Óиü¶à×ʽ𷵻ص½ÆäËüƽ̨¡£Gate.ioÊÔͼÓë¹¥»÷Õß»ñµÃÁªÏµ£¬µ«ÉÐδÊÕµ½»Ø¸´¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷Õß·¢ÆðÕë¶ÔETCµÄ51%¹¥»÷µÄ¾ßÌåÔ­Òò£¬ÈôÊDz»ÊÇΪÁË»ñÀû£¬ÄÇôÆäÖ÷ÕÅÓпÉÄÜÊÇΪÁËÒýÆðÐÐÒµ¶ÔÓÚÇø¿éÁ´¹²Ê¶Ëã·¨ºÍËãÁ¦±£»¤µÄÆ÷³Á¡£µ«¹¥»÷ÕßÈÔ±£ÁôÓмÛÖµÔ¼100ÍòÃÀÔªµÄ±»µÁ×ʽð¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/51-percent-ethereum-hacker-returns-100000-in-stolen-cryptocurrency/


3¡¢Mozilla½«´ÓFirefox 69ÆðÍ·½ûÓÃAdobe Flash

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝMozilla×îеIJå¼þ·Ïßͼ£¬¸Ã¹«Ë¾´òËãÔÚFirefox 69ÖнûÓÃAdobe Flash²å¼þ¡£¸Ã°æ±¾Ô¤¼Æ½«ÓÚ2019Äê9ÔÂ3ÈÕ°ä²¼£¬ÕâÒâζ×Å´ÓÕâÒ»ÌìÆðÍ·£¬FlashÔÚFirefoxÉϵĺ¹Çཫ¸ù»ùÍê½á¡£½ûÓÃFlashÊÇΪÁ˹²Í¬Adobe½«ÔÚ2020Äêµ×ÖÕ³¡Ö§³ÖFlash²å¼þµÄÕþ²ß¡£ÔÚFirefox 69֮ǰ£¬Óû§Ò²Äܹ»Í¨¹ýÊÖ¶¯²Ù×÷½ûÓÃFlash²å¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/mozilla-to-disable-flash-plugin-by-default-in-firefox-69/


4¡¢Neiman MarcusÊý¾Ýй¶ÊÂÎñ´ï³É150ÍòÃÀÔªºÍ½âºÍ̸

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÝ³ÞÆ·Á¬Ëø°Ù»õÉ̵êNeiman MarcusÒѾ­Ô޳ɾÍ2014ÄêµÄÊý¾Ýй¶ÊÂÎñ´ï³É150ÍòÃÀÔªµÄºÍ½âºÍ̸¡£¸Ãй¶ÊÂÎñ²úÉúÔÚ2014Äê7ÔÂ16ÈÕÖÁ10ÔÂ30ÈÕÆÚ¼ä£¬Ô¼ÓÐ37ÍòÓû§µÄÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ£¬ÆäÖÐÖÁÉÙÓÐ9200ÕÅÐÅÓþ¿¨ÒÑÔ⵽ڲƭʹÓá£Æ¾¾ÝµÂ¿ËÈøË¹Öݼì²ì³¤°ì¹«ÊÒµÄÉêÃ÷£¬Neiman MarcusÒÑÓë43¸öÖÝ´ï³ÉºÍ½â£¬Ô̺¬µÂ¿ËÈøË¹ÖÝ¡¢°¢À­Ë¹¼ÓÖÝ¡¢¿ÆÂÞÀ­¶àÖÝ¡¢Å¦Ô¼ÖݺͻªÊ¢¶ÙÖݵÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/neiman-marcus-agrees-to-1-5-million-data-breach-settlement/


5¡¢DX.ExchangeÂòÂôÍøÕ¾·ì϶µ¼ÖÂÓû§Êý¾Ýй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÐÂÎÅÍøÕ¾Ars TechnicaµÄ±¨Â·£¬Ò»ÃûÂòÂôÔ±·¢ÏÖDX.ExchangeÂòÂôÍøÕ¾ÉÏ´æÔÚ°²È«·ì϶£¬¿Éµ¼ÖÂÓû§µÄÃô¸ÐÊý¾Ýй¶¡£¸ÃÂòÂôÔ±·¢ÏÖDX.ExchangeÍøÕ¾µÄHTTPÏìÓ¦ÖÐÔ̺¬ÆäËüÓû§µÄÉí·ÝÑéÖ¤ÁîÅÆºÍÃÜÂë³ÁÖÃÁ´½Ó£¬¸ÃÂòÂôÔ±»¹¿Éͨ¹ýÆôÓÃAPI½Ó¼ûÀ´´ò¿ªÓÀÔ¶ºóÃŽøÈëÊÜÓ°ÏìµÄÓû§ÕË»§¡£ÈôÊÇÄܹ»½øÈëÓµÓÐÖÎÀíȨÏÞµÄÕË»§£¬¹¥»÷Õß½«¿ÉÄÜÏÂÔØÕû¸öÊý¾Ý¿â¡¢×¢Èë¶ñÒâÈí¼þÉõÖÁ´ÓÓû§ÕË»§ÖÐ×ªÒÆ×ʽð¡£DX.ExchangeÒѾ­½¨¸´Á˸÷ì϶¡£


 Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2019/01/11/trading-site-dx-exchange-spills-gobs-of-user-data/


6¡¢Ê©Ä͵½¨¸´EVlink³äµç×®ÖеÄÈý¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



×êÑÐÈËÔ±·¢ÏÖÊ©Ä͵ÂEVlink³äµç×®ÖдæÔÚÈý¸ö°²È«·ì϶£¨CVE-2018-7800¡¢CVE-2018-7801ºÍCVE-2018-7802£©£¬ÕâЩ·ì϶ӰÏìÁËEVLink Parking v3.2.0-12_v1¼°¸üÔçµÄ°æ±¾¡£Ê©Ä͵ÂEVlink³äµç×®±»¿í·ºÓÃÓھƵꡢ³¬ÊкÍÊÐÕþ¾ÖµÄÍ£³µ³¡ÖУ¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶»ñµÃ³äµç×®µÄ½Ó¼ûȨÏÞ£¬´Ó¶øÓ°Ïì³µÁ¾µÄ³äµç¹ý³Ì¡£½¨ÒéÓû§¾¡Á¿Ï÷¼õÕâЩÉ豸ÔÚ»¥ÁªÍøÉϵͳöÇé¿ö¡£


 Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/three-flaws-in-schneider-electric/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù