¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190222
Ðû²¼Ê±¼ä 2019-02-22
DrupalÍŶÓÐÞ¸´¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-6340£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËDrupal 7¡¢8µÄ½¹µã×é¼þ£¬£¬£¬£¬£¬ËäÈ»¸ÃÍŶӲ¢Î´Åû¶ÈκÎÊÖÒÕϸ½Ú£¬£¬£¬£¬£¬µ«Ìáµ½¸ÃÎó²îÓëijЩ×Ö¶Îδ׼ȷ´¦Öóͷ£Êý¾ÝÀàÐÍÓйء£¡£¡£¡£¡£¡£»£»£»£»£»¹Ó¦¸Ã×¢ÖØÖ»ÓÐÆôÓÃÁËRESTful WebЧÀÍÄ£¿£¿£¿£¿£¿éÇÒÔÊÐíÎüÊÕPATCHºÍPOSTÇëÇóµÄÍøÕ¾²Å»áÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£½¨ÒéÓû§½«ÍøÕ¾¾¡¿ìÉý¼¶ÖÁDrupal 8.6.10»ò8.5.11¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/hacking-drupal-vulnerability.html2¡¢AdobeÕë¶ÔAdobe ReaderÐÅϢй¶Îó²îÐû²¼µÚ¶þ¸öÐÞ¸´²¹¶¡
±¾ÖÜËÄAdobeÕë¶ÔAdobe ReaderÖеĿɵ¼ÖÂÐÅϢй¶µÄ¸ßΣÎó²î£¨CVE 2019-7089£©Ðû²¼Á˵ڶþ¸öÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉCure53µÄÑо¿Ö°Ô±AlexInf¨¹hr·¢Ã÷µÄ£¬£¬£¬£¬£¬Ó°ÏìÁ˰汾19.010.20069֮ǰµÄËùÓÐReader DC°æ±¾¡£¡£¡£¡£¡£¡£ÔÚAdobeÓÚ2ÔÂ12ÈÕÐû²¼µÚÒ»¸öÐÞ¸´²¹¶¡Ö®ºó£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Á˿ɵ¼ÖÂÏàͬÎÊÌâµÄÅÔ·¹¥»÷¡£¡£¡£¡£¡£¡£Õâ¸öеÄÅÔ·¹¥»÷±»·ÖÅɸøCVE±àºÅCVE-2019-7815£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâPDFÎĵµ´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬²¢ÒÔSMBÇëÇóµÄÐÎʽ½«Êܺ¦ÕßµÄNTLM¹þÏ£·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-patches-critical-information-disclosure-flaw-in-reader-again/3¡¢UW MedicineÒâÍâй¶Լ97.4Íò»¼ÕßµÄPHIÐÅÏ¢

»ªÊ¢¶Ù´óѧҽѧԺ£¨UW Medicine£©µÄÒ»¸öÊý¾Ý¿â±£´æÉèÖùýʧ£¬£¬£¬£¬£¬µ¼ÖÂÔ¼97.4Íò»¼ÕßµÄPHIÐÅÏ¢ÔÚÍøÂçÉϿɹûÕæ»á¼û¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ2018Äê12ÔÂ4ÈÕ£¬£¬£¬£¬£¬UW MedicineÓÚ12ÔÂ26ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬²¢Ïòî¿Ïµ»ú¹¹¾ÙÐÐÁ˱¨¸æ¡£¡£¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢Ò½ÁƼͼ±àºÅÒÔ¼°Ò»¶ÎÐÎòÐÅÏ¢£¬£¬£¬£¬£¬µ«²»°üÀ¨ÈκÎÒ½ÁƼͼ¡¢²ÆÎñÐÅÏ¢ºÍÉç»áÇå¾²ºÅÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/uw-medicine-notifying-974000-patients-whose-information-was-exposed-online-in-december/4¡¢GNCTDÊý¾Ý¿âÒâÍâй¶½ü50ÍòÓ¡¶È¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢

Ñо¿Ö°Ô±Bob Diachenko·¢Ã÷Ò»¸ö²»Çå¾²µÄЧÀÍÆ÷й¶Á˽ü50ÍòÓ¡¶È¹«ÃñµÄÏêϸСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊÇÒ»¸öÃûΪGNCTDµÄMongoDBʵÀý£¬£¬£¬£¬£¬¾ÞϸΪ4.1GB£¬£¬£¬£¬£¬ÆäÖаüÀ¨458388ÃûÓ¡¶ÈеÂÀ﹫ÃñµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨ËûÃǵÄAadhaarºÅÂëºÍÑ¡ÃñIDµÈ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âµÄÖÎÀíÔ±µç×ÓÓʼþµØµã°üÀ¨transerve.comÓòÃû¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸ÃÊý¾Ý¿âÔÚÍøÉÏ̻¶µÄʱ¼äÊÇ·ÇÒÔ¼°ÊÇ·ñÔâµ½ÆäËûÈ˵Ļá¼û£¬£¬£¬£¬£¬ÔÚDiachenko֪ͨӡ¶ÈCERTºó£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒѾÙÐÐÍÑ»ú±£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/mongodb-delhi-database-leaked.html5¡¢·áÌï°Ä´óÀûÑÇ×Ó¹«Ë¾È·ÈÏÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÔÝÎÞϸ½ÚÅû¶
2ÔÂ21ÈÕ£¬£¬£¬£¬£¬·áÌï°Ä´óÀûÑÇ×Ó¹«Ë¾Ö¤ÊµÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏûÓÐÔ±¹¤»ò¿Í»§µÄСÎÒ˽¼ÒÊý¾ÝÊܵ½Ë𺦡£¡£¡£¡£¡£¡£Ä¿½ñ¹¥»÷µÄȪԴÈÔȻδ֪£¬£¬£¬£¬£¬²¢ÇҸù«Ë¾²¢Î´Åû¶ÈκÎÏà¹ØÏ¸½Ú¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÕýÔÚÓë¹ú¼ÊÍøÂçÇ徲ר¼ÒÇ×½üÏàÖú£¬£¬£¬£¬£¬ÒÔʹÆäÏµÍ³ÖØÐ»ָ´ÔË×÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/toyota-australia-hit-by-cyberattack-no-customer-data-compromised-814cb7776¡¢Ð´¹ÂÚ¹¥»÷»î¶¯Separ£¬£¬£¬£¬£¬ÒÑѬȾ½ü200¼Ò¹«Ë¾
Ò»¸öеĴ¹ÂÚ¹¥»÷»î¶¯ÕýÔÚʹÓöñÒâPDFÎĵµÏòÄ¿µÄÈö²¥¶ñÒâÈí¼þSepar£¬£¬£¬£¬£¬²¢×îÖÕÇÔÈ¡ËûÃÇä¯ÀÀÆ÷ºÍµç×ÓÓʼþµÄƾ֤¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯×îÏÈÓÚ1ÔÂ⣬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑÇ¡¢Öж«ºÍ±±ÃÀ£¬£¬£¬£¬£¬ÒÑÓÐÔ¼200¼Ò¹«Ë¾ºÍ1000¶àÃûСÎÒ˽¼ÒÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÕýµ±µÄ¿ÉÖ´ÐÐÎļþºÍ¶ÌµÄ¾ç±¾£¬£¬£¬£¬£¬¹¥»÷»úÖÆ¼òÆÓ¶øÓÖÓÐÓᣡ£¡£¡£¡£¡£Deep InstinctÑо¿Ö°Ô±ÌåÏÖÕâÒ»´¹ÂڻÈÔÔÚÆð¾¢¾ÙÐÐÖС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/separ-malware-credentials-phishing/142009/ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ