ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ31ÖÜ
°ä²¼¹¦·ò 2018-08-07Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê07ÔÂ30ÈÕÖÁ08ÔÂ05ÈÕ¹²ÊÕ¼°²È«·ì϶51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSamsung SmartThings Hub video-core HTTP·þÎñÆ÷»º³åÇøÒç¶Âí½Å£»Intel Smart Sound TechnologyÇý¶¯·¨Ê½Ä£¿éȨÏÞÌáÉý·ì϶£»Foxit PDF Reader JavaScriptÒýÇæ¿ªÊͺóÀûÓ÷ì϶£»Apple iOS Wi-FiÄÚ´æ·ÛËé·ì϶£»SoftNAS Cloud OSºÅÁî×¢Èë·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÓ¢¹úµç×ÓÉÌÎñ·þÎñÉÌÊý¾Ý¿âй¶£¬Ô¼140ÍòÓû§ÊÜÓ°Ï죻Boys Town¹ú¶È×êÑÐÒ½ÔºÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶£»ICS-CERT°ä²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂç°²È«Ì¬ÊÆ»ã±¨£»RedditÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶£»KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Samsung SmartThings Hub video-core HTTP·þÎñÆ÷»º³åÇøÒç¶Âí½Å
Samsung SmartThings Hub video-core HTTP·þÎñÆ÷´¦Öá®clips¡¯±í´æÔÚ»º³åÇøÒç³ö£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0583
2¡¢Intel Smart Sound TechnologyÇý¶¯·¨Ê½Ä£¿éȨÏÞÌáÉý·ì϶
Intel Smart Sound TechnologyÇý¶¯Ä£¿é´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄÒªÇó£¬ÒÔÖÎÀíԱȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00163.html
3¡¢Foxit PDF Reader JavaScriptÒýÇæ¿ªÊͺóÀûÓ÷ì϶
Foxit PDF Reader JavaScriptÒýÇæ´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬ÒÔÀûÓ÷¨Ê½È¨ÏÞÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588
4¡¢Apple iOS Wi-FiÄÚ´æ·ÛËé·ì϶
Apple iOS Wi-Fi×é¼þ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄÀûÓ÷¨Ê½£¬ÓÕʹÓû§½âÎö£¬¿ÉÈÆ¹ýɳºÐÌáÉýȨÏÞ¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://lists.apple.com/archives/security-announce/2018/Jul/msg00001.html
5¡¢SoftNAS Cloud OSºÅÁî×¢Èë·ì϶
SoftNAS Cloud OS webÖÎÀíÔ±½ÚÔį̀ÖеÄsnserv¾ç±¾Ã»ÓйýÂËÓû§ÊäÈ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.softnas.com/docs/softnas/v3/html/updating_to_the_latest_version.html
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Ó¢¹úµç×ÓÉÌÎñ·þÎñÉÌÊý¾Ý¿âй¶£¬Ô¼140ÍòÓû§ÊÜÓ°Ïì
×êÑÐÈËÔ±Taylor Ralston·¢ÏÖÓ¢¹úµç×ÓÉÌÎñ·þÎñÉÌFashion NexusµÄÒ»¸öÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬¶à¸ö·þ×°ºÍÅäÊÎÍøÕ¾µÄÓû§ÐÅϢй¶£¬Ô̺¬Jaded London¡¢AX ParisºÍElle Belle AttireµÈÆ·ÅÆ¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Ô¼140ÍòÓû§µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬MD5¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂëµÈ¡£Ã»Óм£ÏóÅú×¢Óû§µÄÒøÐп¨ÐÅÏ¢´æÔÚ·çÏÕ¡£
ÔÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/online-fashion-shoppers-exposed-ecommerce-breach/
2¡¢Boys Town¹ú¶È×êÑÐÒ½ÔºÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶
Boys Town¹ú¶È×êÑÐÒ½Ôº°ä²¼Í¨Öª³Æ¸Ã×éÖ¯ÓÚ2018Äê5ÔÂ23ÈÕÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶¡£Õâ¿ÉÄÜÊÇÓйضùͯҽÁÆ·þÎñµÄ×î´ó¹æÄ£µÄÊý¾Ýй¶¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢Õï¶Ï»òÒ½ÖÎÐÅÏ¢¡¢ÒøÐÐÕ˺š¢Óû§ÃûºÍÃÜÂëµÈÐÅÏ¢¡£¹¥»÷ÕßÈëÇÖÁ˸Ã×éÖ¯Ô±¹¤µÄµç×ÓÓʼþÕÊ»§£¬²¢Í¨¹ýδÊÚȨ½Ó¼û»ñÈ¡ÁËÕâЩÐÅÏ¢¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/data-breach-healthcare.html
3¡¢ICS-CERT°ä²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂç°²È«Ì¬ÊÆ»ã±¨
¹ú¶È¹¤Òµ»¥ÁªÍø°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©°ä²¼ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂç°²È«Ì¬ÊÆ»ã±¨£¬»ã±¨´ÓµØÓòÉ¢²¼¡¢Æ·ÅÆÉ¢²¼¡¢Íþвɢ²¼µÈ¶à¸ö½Ç¶ÈÂÛÊö¹úÄÚÍøÂçÊÓÆµ¼à¿ØÏµÍ³µÄ°²È«Ì¬ÊÆÇé¿ö£¬²¢Õë¶Ô½üÄêÀ´²úÉúµÄÍøÂçÊÓÆµ¼à¿ØÏµÍ³°²È«ÊÂÎñÆðÒòÌá³öÁËÏàÓ¦µÄ·çÏÕ·À±¸ºÍ°²È«Ó¦¶Ô¹æ»®£¬¸øÓйص±²¿ÃÅÃÅ¡¢×éÖ¯ºÍ×êÑлú¹¹Ìṩ²Î¿¼ºÍ½è¼ø¡£
ÔÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/be9def54499644afb6ce4b119e5e7d42.html
4¡¢RedditÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶
Reddit°ä·¢ÆäÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶¡£¹¥»÷ÕßÈÆ¹ýË«³É·ÖÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§£¬²¢ÇÔÈ¡Á˲¿Ãŵç×ÓÓʼþµØÖ·¡¢ÈÕÖ¾¼Í¼ÒÔ¼°Ô̺¬¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·ÝÔ̺¬2005ÄêÖÁ2007Äê5ÔÂÆÚ¼äµÄÓû§Êý¾Ý£¬ÈçÕË»§Í´´¦£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØÖ·ºÍ¹«¿ª/¸öÈËÐÂÎÅ¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍ°ä²¼µÄÌû×Ó±»ÒÔΪÊǰ²È«µÄ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/
5¡¢KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅÆ±»ÇÔ
ICOƽ̨KickICOÔâµ½ºÚ¿ÍÈëÇÖ£¬³¬¹ý7000ÍòKICKÁîÅÆ±»ÇÔ£¨¼ÛÖµÔ¼770ÍòÃÀÔª£©¡£Æ¾¾ÝKickICOÊ×ϯִÐйÙAnti DanilevskiµÄ˵·¨£¬¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚ7ÔÂ26ÈÕÐÇÆÚËĵÄUTC¹¦·ò09:04¡£¹¥»÷Õß»ñÈ¡ÁË¿ª·¢ÈËÔ±µÄ˽Կ£¬²¢Åú¸ÄÖÇÄܺÏÔ¼µÄÐÐΪ£¬·ÛËéÁË40¸öµØÖ·ÖеÄKICKÁîÅÆ¶øºóÔÚ40¸ö×Ô¼ºµÄÇ®°üÖд´½¨µÈÁ¿µÄÐÂÁîÅÆ¡£KickICO¿ª·¢ÈËԱĿǰÒѳÁлñµÃÖÇÄܺÏÔ¼µÄ½Ó¼ûȨ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/kickico-platform-loses-77-million-in-recent-hack/


¾©¹«Íø°²±¸11010802024551ºÅ