¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190222

Ðû²¼Ê±¼ä 2019-02-22
1¡¢DrupalÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬Ó°ÏìDrupal°æ±¾7ºÍ8

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

DrupalÍŶÓÐÞ¸´¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-6340£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËDrupal 7¡¢8µÄ½¹µã×é¼þ£¬£¬£¬£¬£¬ËäÈ»¸ÃÍŶӲ¢Î´Åû¶ÈκÎÊÖÒÕϸ½Ú£¬£¬£¬£¬£¬µ«Ìáµ½¸ÃÎó²îÓëijЩ×Ö¶Îδ׼ȷ´¦Öóͷ£Êý¾ÝÀàÐÍÓйء£¡£¡£¡£¡£¡ £»£»£»£»£»¹Ó¦¸Ã×¢ÖØÖ»ÓÐÆôÓÃÁËRESTful WebЧÀÍÄ£¿£¿£¿£¿£¿éÇÒÔÊÐíÎüÊÕPATCHºÍPOSTÇëÇóµÄÍøÕ¾²Å»áÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£½¨ÒéÓû§½«ÍøÕ¾¾¡¿ìÉý¼¶ÖÁDrupal 8.6.10»ò8.5.11¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/hacking-drupal-vulnerability.html

2¡¢AdobeÕë¶ÔAdobe ReaderÐÅϢй¶Îó²îÐû²¼µÚ¶þ¸öÐÞ¸´²¹¶¡

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

±¾ÖÜËÄAdobeÕë¶ÔAdobe ReaderÖеĿɵ¼ÖÂÐÅϢй¶µÄ¸ßΣÎó²î£¨CVE 2019-7089£©Ðû²¼Á˵ڶþ¸öÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉCure53µÄÑо¿Ö°Ô±AlexInf¨¹hr·¢Ã÷µÄ£¬£¬£¬£¬£¬Ó°ÏìÁ˰汾19.010.20069֮ǰµÄËùÓÐReader DC°æ±¾¡£¡£¡£¡£¡£¡£ÔÚAdobeÓÚ2ÔÂ12ÈÕÐû²¼µÚÒ»¸öÐÞ¸´²¹¶¡Ö®ºó£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Á˿ɵ¼ÖÂÏàͬÎÊÌâµÄÅÔ·¹¥»÷¡£¡£¡£¡£¡£¡£Õâ¸öеÄÅÔ·¹¥»÷±»·ÖÅɸøCVE±àºÅCVE-2019-7815£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâPDFÎĵµ´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬²¢ÒÔSMBÇëÇóµÄÐÎʽ½«Êܺ¦ÕßµÄNTLM¹þÏ£·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-patches-critical-information-disclosure-flaw-in-reader-again/

3¡¢UW MedicineÒâÍâй¶Լ97.4Íò»¼ÕßµÄPHIÐÅÏ¢

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

»ªÊ¢¶Ù´óѧҽѧԺ£¨UW Medicine£©µÄÒ»¸öÊý¾Ý¿â±£´æÉèÖùýʧ£¬£¬£¬£¬£¬µ¼ÖÂÔ¼97.4Íò»¼ÕßµÄPHIÐÅÏ¢ÔÚÍøÂçÉϿɹûÕæ»á¼û¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ2018Äê12ÔÂ4ÈÕ£¬£¬£¬£¬£¬UW  MedicineÓÚ12ÔÂ26ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬²¢Ïòî¿Ïµ»ú¹¹¾ÙÐÐÁ˱¨¸æ¡£¡£¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢Ò½ÁƼͼ±àºÅÒÔ¼°Ò»¶ÎÐÎòÐÅÏ¢£¬£¬£¬£¬£¬µ«²»°üÀ¨ÈκÎÒ½ÁƼͼ¡¢²ÆÎñÐÅÏ¢ºÍÉç»áÇå¾²ºÅÂë¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/uw-medicine-notifying-974000-patients-whose-information-was-exposed-online-in-december/

4¡¢GNCTDÊý¾Ý¿âÒâÍâй¶½ü50ÍòÓ¡¶È¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

Ñо¿Ö°Ô±Bob Diachenko·¢Ã÷Ò»¸ö²»Çå¾²µÄЧÀÍÆ÷й¶Á˽ü50ÍòÓ¡¶È¹«ÃñµÄÏêϸСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊÇÒ»¸öÃûΪGNCTDµÄMongoDBʵÀý£¬£¬£¬£¬£¬¾ÞϸΪ4.1GB£¬£¬£¬£¬£¬ÆäÖаüÀ¨458388ÃûÓ¡¶ÈеÂÀ﹫ÃñµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨ËûÃǵÄAadhaarºÅÂëºÍÑ¡ÃñIDµÈ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âµÄÖÎÀíÔ±µç×ÓÓʼþµØµã°üÀ¨transerve.comÓòÃû¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸ÃÊý¾Ý¿âÔÚÍøÉÏ̻¶µÄʱ¼äÊÇ·ÇÒÔ¼°ÊÇ·ñÔâµ½ÆäËûÈ˵Ļá¼û£¬£¬£¬£¬£¬ÔÚDiachenko֪ͨӡ¶ÈCERTºó£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒѾÙÐÐÍÑ»ú± £»£»£»£»£»¤¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/mongodb-delhi-database-leaked.html

5¡¢·áÌï°Ä´óÀûÑÇ×Ó¹«Ë¾È·ÈÏÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÔÝÎÞϸ½ÚÅû¶

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

2ÔÂ21ÈÕ£¬£¬£¬£¬£¬·áÌï°Ä´óÀûÑÇ×Ó¹«Ë¾Ö¤ÊµÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏûÓÐÔ±¹¤»ò¿Í»§µÄСÎÒ˽¼ÒÊý¾ÝÊܵ½Ë𺦡£¡£¡£¡£¡£¡£Ä¿½ñ¹¥»÷µÄȪԴÈÔȻδ֪£¬£¬£¬£¬£¬²¢ÇҸù«Ë¾²¢Î´Åû¶ÈκÎÏà¹ØÏ¸½Ú¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÕýÔÚÓë¹ú¼ÊÍøÂçÇ徲ר¼ÒÇ×½üÏàÖú£¬£¬£¬£¬£¬ÒÔʹÆäÏµÍ³ÖØÐ»ָ´ÔË×÷¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/toyota-australia-hit-by-cyberattack-no-customer-data-compromised-814cb777

6¡¢Ð´¹ÂÚ¹¥»÷»î¶¯Separ£¬£¬£¬£¬£¬ÒÑѬȾ½ü200¼Ò¹«Ë¾

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

Ò»¸öеĴ¹ÂÚ¹¥»÷»î¶¯ÕýÔÚʹÓöñÒâPDFÎĵµÏòÄ¿µÄÈö²¥¶ñÒâÈí¼þSepar£¬£¬£¬£¬£¬²¢×îÖÕÇÔÈ¡ËûÃÇä¯ÀÀÆ÷ºÍµç×ÓÓʼþµÄƾ֤¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯×îÏÈÓÚ1ÔÂ⣬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑÇ¡¢Öж«ºÍ±±ÃÀ£¬£¬£¬£¬£¬ÒÑÓÐÔ¼200¼Ò¹«Ë¾ºÍ1000¶àÃûСÎÒ˽¼ÒÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÕýµ±µÄ¿ÉÖ´ÐÐÎļþºÍ¶ÌµÄ¾ç±¾£¬£¬£¬£¬£¬¹¥»÷»úÖÆ¼òÆÓ¶øÓÖÓÐÓᣡ£¡£¡£¡£¡£Deep InstinctÑо¿Ö°Ô±ÌåÏÖÕâÒ»´¹ÂڻÈÔÔÚÆð¾¢¾ÙÐÐÖС£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/separ-malware-credentials-phishing/142009/

ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí