ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ35ÖÜ
°ä²¼¹¦·ò 2018-09-03Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨±Ê¼Ç±¾±»µÁ£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö;AbbyyÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
Tencent Foxmail URI´¦ÖôæÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ»òÒ³ÃæÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/
OpenSSH auth-gss2.c´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÅжÏÓû§Ãû¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://seclists.org/oss-sec/2018/q3/180
Google Chrome Blob API´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Emerson Electric DeltaVÊ¢¿ªÍ¨Ñ¶¶Ë¿Ú´æÔÚÕ»Òç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01
Adobe Acrobat/Reader´¦ÖÃPDFÎļþ´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
ƾ¾Ý°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬¸Ã¹«Ë¾µÄһ̨Ô̺¬Óû§Êý¾ÝµÄδ¼ÓÃܵıʼDZ¾µçÄÔÔâÇÔ£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍeirÕ˺š£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»Ô̺¬ÈκÎÓû§µÄ²ÆÕþÊý¾Ý¡£Ä¿Ç°¸Ã¹«Ë¾ÒÑÏòÊý¾Ý±£»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±´«µÝÁËÕâ´ÎÊÂÎñ¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html
2¡¢AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö
ƾ¾ÝÃÀýBuzzFeedNewsµÄ±¨Â·£¬AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö¡£´Ë±í£¬ÊÖ»ú±£ÏÕ¹«Ë¾AsurionµÄ¹ÙÍøÒ²´æÔÚÒ»¸ö·ì϶£¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë¶³ö¡£ÕâÁ½¸ö·ì϶ÊÇÓɰ²È«×êÑÐÈËÔ±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ïֵġ£AppleÍøÕ¾Éϵķì϶¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³ÌÃýÎóÓйء£AppleºÍAsurionÒѾ½¨¸´ÁËÓйطì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple
3¡¢AbbyyÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶
8ÔÂ19ÈÕ°²È«×êÑÐÈËÔ±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢ÏÖÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDB·þÎñÆ÷ÎÞÐèµÇ¼¼´¿É¹«¿ª½Ó¼û¡£¸ÃÊý¾Ý¿â´óÓ×Ϊ142GB£¬Ô̺¬¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬ÈçºÏͬ¡¢±£ÃܺÍ̸¡¢ÄÚ²¿º¯¼þ¼°±¸Íü¼µÈ¡£ÆäÖÐÔ̺¬ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£AbbyyµÄ°²È«ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½Ììºó½¨¸´Á˸ÃÊý¾Ý¿âµÄÅäÖÃÃýÎóÎÊÌâ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/
4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û

ƾ¾Ý·͸ÉçµÄ±¨Â·£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕÆðÍ·Î÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÉ¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷£¨DDoS£©£¬ÆäÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û¡£¸ÃÒøÐеĽ²»°È˰µÊ¾£¬Õâ´Î¹¥»÷¶Ô¸ÃÒøÐеķþÎñ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѼû»ÓÐÔì³ÉÈκÎÓ°Ï죬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄ·çÏÕ¡£½ØÖÁÖܶþÏÂÎ磬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£
ÔÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B
5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/


¾©¹«Íø°²±¸11010802024551ºÅ