¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181212

Ðû²¼Ê±¼ä 2018-12-12
1¡¢ÃÀ¹úÖÚÒéÔºÐû²¼ÍøÂçÇå¾²Õ½ÂÔ±¨¸æ£¬£¬£¬£¬£¬£¬Ìá³öÁùÏîÖ¸µ¼Ô­Ôò

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹úÖÚÒéÔºÄÜÔ´ºÍÉÌҵίԱ»áÐû²¼ÍøÂçÇå¾²Õ½ÂÔ±¨¸æ£¬£¬£¬£¬£¬£¬Ö¼ÔÚÈ·Á¢Ô¤·À»ººÍ½âÍøÂçÇå¾²ÊÂÎñµÄÕ½ÂÔ ¡£¡£¸Ã±¨¸æÒÔΪĿ½ñÃÀ¹úµÄÍøÂçÇå¾²Ðж¯²¢Î´¸úÉÏ»¥ÁªÍøµÄÉú³¤£¬£¬£¬£¬£¬£¬¹Å°åµÄÐÅÏ¢ÊÖÒÕÕ½ÂÔÔÚÓ¦¶ÔÒ»Ö±ÔöÌíµÄÍøÂçÇå¾²ÊÂÎñÖÐÊÕЧÉõ΢ ¡£¡£±¨¸æÊáÀí³öÁùµãÍøÂçÇå¾²¿´·¨ÓëÁùÏîÍøÂçÇå¾²ÓÅÏÈÏ£¬£¬£¬£¬£¬°üÀ¨½¨ÉèÆÕ±é½ÓÊܵÄЭͬÅû¶³ÌÐò¡¢ÒýÈëÈí¼þÎïÁÏÇåµ¥£¨software bill of materials£¬£¬£¬£¬£¬£¬¼ò³ÆSBOM£©¡¢Ö§³Ö¿ªÔ´Èí¼þ¡¢ÍêÉÆCVE³ÌÐò¡¢ÊµÑéÊÖÒÕÉúÃüÖÜÆÚÖ§³ÖÕ½ÂÔÒÔ¼°Ç¿»¯¹«Ë½ÏàÖúģʽ ¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://energycommerce.house.gov/wp-content/uploads/2018/12/12.07.18-Cybersecurity-Strategy-Report.pdf


2¡¢ÎªÌáÉýÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬Ó¢¹úNHS½«ÓÚ2020ÄêÖÜÈ«½ûÓô«Õæ»ú

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



Ó¢¹ú¹ú¼ÒÎÀÉúÊÂÎñ¾Ö£¨NHS£©ÈÕǰÐû²¼£¬£¬£¬£¬£¬£¬½«´ÓÏÂÔÂÆð²»ÔÙ¹ºÖÃеĴ«Õæ»ú£¬£¬£¬£¬£¬£¬²¢ÓÚ2020Äê3ÔÂ31ÈÕ½ûÓÃËùÓеĴ«Õæ»ú ¡£¡£´Ë¾ÙÊÇΪÁËÌáÉýNHSµÄÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬Ó¢¹úÎÀÉú²¿³¤Matt HancockÌåÏÖ´«Õæ»úÀ©´óÁ˹¥»÷Ãæ£¬£¬£¬£¬£¬£¬¶øµç×ÓÓʼþ±È´«Õæ»ú¸üΪÇå¾²ºÍÓÐÓà ¡£¡£Æ¾Ö¤Ó¢¹ú»Ê¼ÒÍâ¿ÆÑ§Ôº£¨RCS£©µÄÔ¤¼Æ£¬£¬£¬£¬£¬£¬×èÖ¹2018Äê7ÔÂNHSÈÔÔÚʹÓÃÁè¼Ý8000̨´«Õæ»ú ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/nhs-fax-ban-set-to-improve/


3¡¢ÒòÎóµ¼ÏûºÄÕߣ¬£¬£¬£¬£¬£¬Òâ´óÀûICA¶ÔFacebook·£¿£¿£¿£¿£¿£¿î1000ÍòÅ·Ôª

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Òâ´óÀû¾ºÕùÖÎÀí¾Ö£¨ICA£©ÒòFacebookÎ¥·´ÁËÏûºÄÕß·¨°¸¶ø¶ÔÆä´¦ÒÔÁ½Ïî¹²¼Æ1000ÍòÅ·ÔªµÄ·£¿£¿£¿£¿£¿£¿î ¡£¡£ICA³ÆFacebookÔÚÖ¸µ¼ÏûºÄÕß×¢²áµÄÀú³ÌÖб£´æÎóµ¼ÐÐΪ£¬£¬£¬£¬£¬£¬Ã»Óгä·Ö¼û¸æÓû§ËûÃǵÄÊý¾Ý½«±»ÓÃÓÚÉÌҵĿµÄ£¬£¬£¬£¬£¬£¬´Ë¾ÙÎ¥·´ÁËÏûºÄÕß·¨°¸µÄµÚ21ºÍ22Ìõ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬FacebookÔÚûÓÐÃ÷ȷ֪ͨºÍÊÂÏÈ»ñµÃÓû§ÔÊÐíµÄÇéÐÎϽ«Êý¾ÝÌṩӦµÚÈý·½£¬£¬£¬£¬£¬£¬Î¥·´ÁËÏûºÄÕß·¨°¸µÄµÚ24ºÍ25Ìõ ¡£¡£Æ¾Ö¤¸Ã·¨°¸µÚ27Ìõ£¬£¬£¬£¬£¬£¬Facebook»¹±ØÐèÒªÏòËùÓÐÓû§Ðû²¼¾À´íÉùÃ÷ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

http://en.agcm.it/en/media/press-releases/2018/12/Facebook-fined-10-million-Euros-by-the-ICA-for-unfair-commercial-practices-for-using-its-subscribers%E2%80%99-data-for-commercial-purposes


4¡¢Áè¼Ý30¸ö¹ú¼ÒµÄ4ÍòÕþ¸®ÍøÕ¾Æ¾Ö¤±»ÇÔ£¬£¬£¬£¬£¬£¬»òÒÑÔÚ°µÍø³öÊÛ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Group-IBÑо¿Ö°Ô±·¢Ã÷Áè¼Ý30¸ö¹ú¼ÒµÄ4ÍòÕþ¸®ÍøÕ¾Æ¾Ö¤±»ÇÔ£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢ÊÇ·¸·¨·Ö×ÓÍøÂç¶øÀ´£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÒÑÔÚ°µÍøÂÛ̳ÉϳöÊÛ ¡£¡£´ó´ó¶¼Êܺ¦ÕßλÓÚÅ·ÖÞ£¬£¬£¬£¬£¬£¬°üÀ¨Òâ´óÀû£¨52%£©¡¢É³Ìذ¢À­²®£¨22%£©ÒÔ¼°ÆÏÌÑÑÀ£¨5%£© ¡£¡£Êܺ¦Õß»¹°üÀ¨·¨¹ú£¨gouv.fr£©¡¢ÐÙÑÀÀû£¨gov.hu£©¡¢ÈðÊ¿£¨admin.ch£©µÈ¹ú¼ÒµÄÕþ¸®ÍøÕ¾ÒÔ¼°ÒÔÉ«Áйú·À¾ü£¨idf.il£©¡¢¸ñ³¼ªÑDzÆÎñ²¿£¨mof.ge£©¡¢Å²ÍþÒÆÃñ¾Ö£¨udi.no£©µÈÍøÕ¾ ¡£¡£Group-IBÒÑÏòÕâЩ¹ú¼ÒµÄCERTת´ïÁËÏà¹ØÎ£º¦ ¡£¡£Õþ¸®ÍøÕ¾µÄµÇ¼ƾ֤ÔÚ°µÍøÊг¡Éϲ¢²»³£¼û£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇûÓÐÖ±½ÓµÄ²ÆÎñ¼ÛÖµ£¬£¬£¬£¬£¬£¬µ«APT¹¥»÷Õß¿ÉʹÓÃÕâÐ©Æ¾Ö¤ÉøÍ¸Õþ¸®ÍøÕ¾ºÍÇÔÈ¡ÉñÃØÐÅÏ¢ ¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-steal-over-40k-logins-for-gov-services-in-30-countries/


5¡¢ÃÀ¹ú¿ÆµÂ½ÇÉçÇøÑ§ÔºÔâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬Ô¼81ÍòÃÀÔª±»ÇÔ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹ú¿ÆµÂ½ÇÉçÇøÑ§ÔºÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý´¹ÂÚ¹¥»÷ÊÍ·ÅÁËÖ¼ÔÚÇÔÈ¡ÒøÐÐÐÅÏ¢µÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬²¢´Ó¸ÃѧԺÇÔÈ¡ÁË80.7ÍòÃÀÔª ¡£¡£¸ÃѧԺ·¢Ã÷²¢×èÖ¹Á˺óÐøµÄÒ»ÔÙ¹¥»÷£¬£¬£¬£¬£¬£¬²¢ÒÑÓëÒøÐÐÏàÖú×·»ØÁË27.9ÍòÃÀÔªµÄ±»µÁ×ʽ𠡣¡£ÏÖÔÚûÓиöñÒâÈí¼þÔõÑùÇÔÈ¡×ʽðµÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬µ«¸ÃѧԺÌåÏÖÉÐÎÞÖ¤¾ÝÅúעѧÉú¡¢Ô±¹¤µÄСÎÒ˽¼ÒÉí·ÝÐÅÏ¢ºÍ¼Í¼Êܴ˴ι¥»÷Ó°Ïì ¡£¡£ÂíÈøÖîÈûÖÝÓëÁª°î¹ÙÔ±Õý¶Ô´Ë´Î͵ÇÔÊÂÎñÕö¿ªÊÓ²ì ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/807-130-stolen-by-hackers-after-cape-cod-community-college-phishing-attack-524208.shtml


6¡¢phpMyAdminÐû²¼Ö÷Òª¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´3¸öÇå¾²Îó²î

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


phpMyAdminÐû²¼ÁËа汾4.8.4£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁË3¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬°üÀ¨ÍâµØÎļþ°üÀ¨Îó²î£¨CVE-2018-19968£©£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß´ÓЧÀÍÆ÷µÄÍâµØÎļþÖлñÈ¡Ãô¸ÐÄÚÈÝ£»£»£»£»¿çÕ¾ÇëÇóαÔìÎó²î(CSRF)/XSRF£¨CVE-2018-19969£©£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷Õß¾ÙÐÐÓꦵÄSQL²Ù×÷£»£»£»£»ÒÔ¼°XSSÎó²î£¨CVE-2018-19970£© ¡£¡£Ð°汾»¹°üÀ¨ÁËһЩbugÐÞ¸´£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüР¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/12/phpmyadmin-security-update.html


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí