ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ35ÖÜ
Ðû²¼Ê±¼ä 2018-09-03Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶;AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
Tencent Foxmail URI´¦Öóͷ£±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ»òÒ³ÃæÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/
OpenSSH auth-gss2.c±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÅжÏÓû§Ãû¡£¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttp://seclists.org/oss-sec/2018/q3/180
Google Chrome Blob API±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Emerson Electric DeltaV¿ª·ÅͨѶ¶Ë¿Ú±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01
Adobe Acrobat/Reader´¦Öóͷ£PDFÎļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html
Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
ƾ֤°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄһ̨°üÀ¨Óû§Êý¾ÝµÄδ¼ÓÃܵÄÌõ¼Ç±¾µçÄÔÔâÇÔ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍeirÕ˺𣡣¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»°üÀ¨ÈκÎÓû§µÄ²ÆÎñÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔڸù«Ë¾ÒÑÏòÊý¾Ý±£»£»£»£»£»£»£»£»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±×ª´ïÁË´Ë´ÎÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html
2¡¢AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶
ƾ֤ÃÀýBuzzFeedNewsµÄ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÊÖ»ú°ü¹Ü¹«Ë¾AsurionµÄ¹ÙÍøÒ²±£´æÒ»¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë̻¶¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²îÊÇÓÉÇå¾²Ñо¿Ö°Ô±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£¡£AppleÍøÕ¾ÉϵÄÎó²î¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³Ì¹ýʧÓйء£¡£¡£¡£¡£¡£¡£¡£AppleºÍAsurionÒѾÐÞ¸´ÁËÏà¹ØÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple
3¡¢AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶
8ÔÂ19ÈÕÇå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢Ã÷ÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDBЧÀÍÆ÷ÎÞÐèµÇ¼¼´¿É¹ûÕæ»á¼û¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ142GB£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÈçÌõÔ¼¡¢±£ÃÜÐÒé¡¢ÄÚ²¿Ðżþ¼°±¸Íü¼µÈ¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£AbbyyµÄÇå¾²ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½ÌìºóÐÞ¸´Á˸ÃÊý¾Ý¿âµÄÉèÖùýʧÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/
4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û

ƾ֤·͸ÉçµÄ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕ×îÏÈÎ÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷£¨DDoS£©£¬£¬£¬£¬£¬£¬£¬£¬ÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÒøÐеĽ²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷¶Ô¸ÃÒøÐеÄЧÀÍ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѶûÓÐÔì³ÉÈκÎÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄΣº¦¡£¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÖܶþÏÂÖ磬£¬£¬£¬£¬£¬£¬£¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B
5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/


¾©¹«Íø°²±¸11010802024551ºÅ