¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181129

Ðû²¼Ê±¼ä 2018-11-29
1¡¢FBIÁªºÏGoogleµÈ¶à¼ÒÇå¾²³§É̴ݻٴó¹æÄ£¹ã¸æÚ²Æ­ÍÅ»ï3ve

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


FBIÁªºÏGoogle¡¢White OpsÒÔ¼°ProofpointµÈ¶à¼ÒÇå¾²³§ÉÌÅäºÏ´Ý»ÙÁËÒ»¸ö¹ã¸æÚ²Æ­ÍŻ¡£¡£¡£¡£¸ÃÔÚÏßڲƭ»î¶¯±»³ÆÎª3ve£¬£¬£¬ £¬£¬£¬£¬£¬×Ô2014ÄêÆðÒ»Ö±»îÔ¾£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÔÚÈ¥ÄêÀ©´óÁËÆä»î¶¯¹æÄ££¬£¬£¬ £¬£¬£¬£¬£¬Îª¹¥»÷Õß´øÀ´ÁËÁè¼Ý3000ÍòÃÀÔªµÄÊÕÈë¡£¡£¡£¡£¡£3veѬȾÁËÁè¼Ý170Íǫ̀ÅÌËã»ú£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃ80¶ą̀ЧÀÍÆ÷±¬·¢¶ñÒâÁ÷Á¿£¬£¬£¬ £¬£¬£¬£¬£¬²¢¹¹½¨ÁËÁè¼Ý1Íò¸ö´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£Ôڻá¯ÁëʱÆÚ£¬£¬£¬ £¬£¬£¬£¬£¬3veͬʱ²Ù¿ØÁËÁè¼Ý100Íò¸öIPµØµã£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÖðÈÕڲƭ¹ã¸æÍ¶·ÅÁ¿´ï30µ½120ÒڴΡ£¡£¡£¡£¡£±¾ÖܶþÃÀ¹ú˾·¨²¿ÆðËßÁËÓë¸Ã¹ã¸æÚ²Æ­»î¶¯ÓйصÄ8Ãû·¸·¨ÏÓÒÉÈË¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/3ve-ad-fraud-google.html


2¡¢Çå¾²³§ÉÌ·¢Ã÷É­º£Èû¶ûµÄHeadSetupÈí¼þÒ×ÊÜSSLÖÐÐÄÈ˹¥»÷

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Secorvo·¢Ã÷¶ú»ú³§ÉÌÉ­º£Èû¶ûµÄÅäÌ×Èí¼þHeadSetup±£´æÒ»¸öÇå¾²Îó²î£¨CVE-2018-17612£©£¬£¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂSSLÖÐÐÄÈ˹¥»÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃÈí¼þÔÚ×°ÖÃʱ»áÔÚÓû§ÅÌËã»úÉÏ×°ÖÃÒ»¸ö¸ùÖ¤ÊéºÍ¼ÓÃܵÄÖ¤Êé˽Կ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÕâÁ½¸öÎļþ¶ÔËùÓÐÓû§¶¼ÊÇÏàͬµÄ¡£¡£¡£¡£¡£¸ÃÈí¼þÔÚÐ¶ÔØÊ±Ò²²»»áɾ³ýÖ¤ÊéÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹µÃÓû§¼ÌÐøÒ×Êܹ¥»÷¡£¡£¡£¡£¡£¸ÃÖ¤Êé˽ԿËäÈ»±»¼ÓÃÜÁË£¬£¬£¬ £¬£¬£¬£¬£¬µ«Ê¹ÓõÄÊÇAES-128-CBCËã·¨¾ÙÐмÓÃÜ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÃÜÔ¿ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚ´úÂëÖУ¨WBCCListener.dll£©¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sennheiser-headset-software-could-allow-man-in-the-middle-ssl-attacks/


3¡¢Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ·ÇÓªÀûÒ½ÁÆ»ú¹¹Atrium HealthÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼265Íò»¼ÕßµÄÐÅϢй¶¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ9ÔÂ22ÈÕÖÁ9ÔÂ29ÈÕʱ´ú£¬£¬£¬ £¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢³öÉúÈÕÆÚ¡¢°ü¹ÜÐÅÏ¢¡¢Ð§ÀÍÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅºÍÕË»§Óà¶îµÈ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬£¬ÉÐÓпìÒª70Íò¸öÉç±£ºÅÂëй¶£¬£¬£¬ £¬£¬£¬£¬£¬µ«Ã»ÓвÆÎñÐÅϢй¶¡£¡£¡£¡£¡£¸Ã×éÖ¯Òѽ«Ïà¹ØÊÂÎñ֪ͨFBI£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/atrium-health-data-breach-exposed-2-65-million-patient-records/


4¡¢ElasticSearchЧÀÍÆ÷̻¶Áè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²³§ÉÌHackenµÄÑо¿Ö°Ô±Bob Diachenkoͨ¹ýShodan·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄElasticSearchЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÊý¾Ý¿â̻¶ÁËÁè¼Ý5700ÍòÃÀ¹ú¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¼Òͥסַ¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂëºÍIPµØµãµÈÐÅÏ¢¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÎÞ·¨È·ÈϸÃЧÀÍÆ÷µÄËùÓÐÕߣ¬£¬£¬ £¬£¬£¬£¬£¬µ«ËûÒÔΪ¼ÓÄôóÊý¾Ý¹«Ë¾Data£¦Leads»òÐíÓëÖ®ÓйØ¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃЧÀÍÆ÷Òѱ»¾ÙÐÐÇå¾²¼Ó¹Ì¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/elasticsearch-server-exposed-the-personal-data-of-over-57-million-us-citizens/


5¡¢¿¨°Í˹»ùÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùʵÑéÊÒÐû²¼2018Äê¶ñÒâÍÚ¿ó¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ£¬£¬£¬ £¬£¬£¬£¬£¬¶ñÒâÍÚ¿óÈí¼þͨ³£Í¨¹ý¹ã¸æÈí¼þ¡¢ÆÆ½âÓÎÏ·»òÆäËüµÁ°æÄÚÈݽøÈëÓû§ºÍÆóÒµµÄÅÌËã»ú£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒ½¨Éè¶ñÒâÍÚ¿óÈí¼þµÄÃż÷Ò²Ô½À´Ô½µÍ¡£¡£¡£¡£¡£2018ÄêÍ·¶ñÒâÍÚ¿ó¹¥»÷¿ìËÙÔöÌí£¬£¬£¬ £¬£¬£¬£¬£¬ËæºóÅãͬ׿ÓÃÜÇ®±Ò¼ÛÇ®µÄϽµ¶ñÒâÍÚ¿ó»î¶¯ÓÖÏÔÖøÏ½µ£¬£¬£¬ £¬£¬£¬£¬£¬µ«¸ÃÍþвÈÔÈ»½ûֹСêï¡£¡£¡£¡£¡£ËäȻһЩ¹ú¼Ò¶Ô¼ÓÃÜÇ®±Ò¾ÙÐÐÁ¢·¨¿ØÖÆ£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÕâЩ¹ú¼ÒµÄ¶ñÒâÍÚ¿ó»î¶¯²¢Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-2018-story-of-the-year-miners/89096/


6¡¢Î÷ÃÅ×ÓÅû¶SIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Î÷ÃÅ×ÓÕë¶ÔSIMATIC S7-1500²úÆ·ÖеĶà¸öÇå¾²Îó²îÐû²¼¾¯±¨¡£¡£¡£¡£¡£Æ¾Ö¤Î÷ÃÅ×ÓµÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁ˹̼þ°æ±¾ÎªV2.6.0µÄGNU/Linux×Óϵͳ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒ½«ÔÚÏÂÒ»¸ö¹Ì¼þ°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£Ïà¹ØÎó²îµÄÊýĿΪ21¸ö£¬£¬£¬ £¬£¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼Ö¾ܾøÐ§ÀÍ¡¢í§Òâ´úÂëÖ´ÐкÍÓû§Ã¶¾ÙµÈÎÊÌâ¡£¡£¡£¡£¡£Ôڹ̼þ¸üÐÂÐû²¼Ö®Ç°£¬£¬£¬ £¬£¬£¬£¬£¬Î÷ÃÅ×Ó½¨ÒéÓû§Ó¦ÓÃÎ÷ÃÅ×ÓÉî¶È·ÀÓù²½·¥²¢ÇÒ×èÖ¹ÔËÐв»¿ÉÐÅȪԴµÄ³ÌÐò¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-warns-linux-gnu-flaws-controller-platform



ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí