ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ31ÖÜ

Ðû²¼Ê±¼ä 2018-08-07

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


 2018Äê07ÔÂ30ÈÕÖÁ08ÔÂ05ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´51¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇSamsung SmartThings Hub video-core HTTP·þÎñÆ÷»º³åÇøÒç³ö©¶´£»Intel Smart Sound TechnologyÇý¶¯·¨Ê½Ä£¿éȨÏÞÌáÉý©¶´£»Foxit PDF Reader JavaScriptÒýÇæÊͷźóÀûÓ鶴£»Apple iOS Wi-FiÄÚ´æÆÆ»µÂ©¶´£»SoftNAS Cloud OSÃüÁî×¢È멶´¡£

 

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÓ¢¹úµç×ÓÉÌÎñ·þÎñÉÌÊý¾Ý¿âй¶ £¬Ô¼140ÍòÓû§ÊÜÓ°Ï죻Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ £¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶£»ICS-CERTÐû²¼ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÄþ¾²Ì¬ÊƳÂËߣ»RedditÔâºÚ¿ÍÈëÇÖ £¬²¿ÃÅÓû§µÄÊý¾Ýй¶£»KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ £¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅƱ»ÇÔ¡£

 

ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£

 

¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí


1¡¢Samsung SmartThings Hub video-core HTTP·þÎñÆ÷»º³åÇøÒç³ö©¶´

 

 Samsung SmartThings Hub video-core HTTP·þÎñÆ÷´¦Öá®clips¡¯±í´æÔÚ»º³åÇøÒç³ö £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0583


2¡¢Intel Smart Sound TechnologyÇý¶¯·¨Ê½Ä£¿éȨÏÞÌáÉý©¶´

 

Intel Smart Sound TechnologyÇý¶¯Ä£¿é´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴¹¹½¨ÌØÊâµÄÇëÇó £¬ÒÔ¹ÜÀíԱȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00163.html


3¡¢Foxit PDF Reader JavaScriptÒýÇæÊͷźóÀûÓ鶴

 

Foxit PDF Reader JavaScriptÒýÇæ´æÔÚÊͷźóʹÓ鶴 £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬ÒÔÓ¦Ó÷¨Ê½È¨ÏÞÖ´ÐÐÈÎÒâ´úÂë¡£

 

 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588


4¡¢Apple iOS Wi-FiÄÚ´æÆÆ»µÂ©¶´

 

Apple iOS Wi-Fi×é¼þ´æÔÚÄÚ´æÆÆ»µÂ©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨ÌØÊâµÄÓ¦Ó÷¨Ê½ £¬ÓÕʹÓû§½âÎö £¬¿ÉÈƹýɳºÐÌáÉýȨÏÞ¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://lists.apple.com/archives/security-announce/2018/Jul/msg00001.html


5¡¢SoftNAS Cloud OSÃüÁî×¢È멶´

 

SoftNAS Cloud OS web¹ÜÀíÔ±¿ØÖÆ̨ÖеÄsnserv½Å±¾Ã»ÓйýÂËÓû§ÊäÈë £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨ÌØÊâµÄÇëÇó £¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.softnas.com/docs/softnas/v3/html/updating_to_the_latest_version.html

 

Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ó¢¹úµç×ÓÉÌÎñ·þÎñÉÌÊý¾Ý¿âй¶ £¬Ô¼140ÍòÓû§ÊÜÓ°Ïì

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ñо¿ÈËÔ±Taylor Ralston·¢ÏÖÓ¢¹úµç×ÓÉÌÎñ·þÎñÉÌFashion NexusµÄÒ»¸öÊý¾Ý¿â¿É¹ûÈ»·ÃÎÊ £¬¶à¸ö·þ×°ºÍÅäÊÎÍøÕ¾µÄÓû§ÐÅϢй¶ £¬°üÂÞJaded London¡¢AX ParisºÍElle Belle AttireµÈÆ·ÅÆ¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÔ¼140ÍòÓû§µÄ¸öÈËÐÅÏ¢ £¬°üÂÞMD5¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂëµÈ¡£Ã»Óм£Ïó±íÃ÷Óû§µÄÒøÐп¨ÐÅÏ¢´æÔÚ·çÏÕ¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/online-fashion-shoppers-exposed-ecommerce-breach/

 

2¡¢Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ £¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 Boys Town¹ú¼ÒÑо¿Ò½ÔºÐû²¼Í¨Öª³Æ¸Ã×éÖ¯ÓÚ2018Äê5ÔÂ23ÈÕÔâºÚ¿ÍÈëÇÖ £¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶¡£Õâ¿ÉÄÜÊÇÓйضùͯҽÁÆ·þÎñµÄ×î´ó¹æÄ£µÄÊý¾Ýй¶¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢Õï¶Ï»òÖÎÁÆÐÅÏ¢¡¢ÒøÐÐÕ˺š¢Óû§ÃûºÍÃÜÂëµÈÐÅÏ¢¡£¹¥»÷ÕßÈëÇÖÁ˸Ã×éÖ¯Ô±¹¤µÄµç×ÓÓʼþÕÊ»§ £¬²¢Í¨¹ýδÊÚȨ·ÃÎÊ»ñÈ¡ÁËÕâЩÐÅÏ¢¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/data-breach-healthcare.html

 

3¡¢ICS-CERTÐû²¼ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÄþ¾²Ì¬ÊƳÂËß

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

¹ú¼Ò¹¤Òµ»¥ÁªÍøÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©Ðû²¼ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÄþ¾²Ì¬ÊƳÂËß £¬³ÂËß´ÓµØÓòÂþÑÜ¡¢Æ·ÅÆÂþÑÜ¡¢ÍþвÂþÑܵȶà¸ö½Ç¶ÈÂÛÊö¹úÄÚÍøÂçÊÓƵ¼à¿ØϵͳµÄÄþ¾²Ì¬ÊÆÇé¿ö £¬²¢Õë¶Ô½üÄêÀ´·¢ÉúµÄÍøÂçÊÓƵ¼à¿ØϵͳÄþ¾²Ê¼þÆðÒòÌá³öÁËÏàÓ¦µÄ·çÏÕ·À·¶ºÍÄþ¾²Ó¦¶Ô·½°¸ £¬¸øÏà¹ØÕþ¸®²¿ÃÅ¡¢×éÖ¯ºÍÑо¿»ú¹¹Ìṩ²Î¿¼ºÍ½è¼ø¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/be9def54499644afb6ce4b119e5e7d42.html

 

4¡¢RedditÔâºÚ¿ÍÈëÇÖ £¬²¿ÃÅÓû§µÄÊý¾Ýй¶

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

RedditÐû²¼ÆäÔâºÚ¿ÍÈëÇÖ £¬²¿ÃÅÓû§µÄÊý¾Ýй¶¡£¹¥»÷ÕßÈƹýË«ÒòËØÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§ £¬²¢ÇÔÈ¡Á˲¿Ãŵç×ÓÓʼþµØÖ·¡¢ÈÕÖ¾¼Ç¼ÒÔ¼°°üÂÞ¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¸Ã¹¥»÷ʼþ·¢ÉúÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä £¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·Ý°üÂÞ2005ÄêÖÁ2007Äê5ÔÂÆÚ¼äµÄÓû§Êý¾Ý £¬ÈçÕË»§Æ¾¾Ý£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØÖ·ºÍ¹ûÈ»/˽ÈËÏûÏ¢¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍÐû²¼µÄÌû×Ó±»ÈÏΪÊÇÄþ¾²µÄ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/

 

5¡¢KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ £¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅƱ»ÇÔ

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ICOƽ̨KickICOÔâµ½ºÚ¿ÍÈëÇÖ £¬Áè¼Ý7000ÍòKICKÁîÅƱ»ÇÔ£¨¼ÛÖµÔ¼770ÍòÃÀÔª£©¡£Æ¾¾ÝKickICOÊ×ϯִÐйÙAnti DanilevskiµÄ˵·¨ £¬¸Ã¹¥»÷ʼþ·¢ÉúÔÚ7ÔÂ26ÈÕÐÇÆÚËĵÄUTCʱ¼ä09:04¡£¹¥»÷Õß»ñÈ¡ÁË¿ª·¢ÈËÔ±µÄ˽Կ £¬²¢ÐÞ¸ÄÖÇÄܺÏÔ¼µÄÐÐΪ £¬´Ý»ÙÁË40¸öµØÖ·ÖеÄKICKÁîÅÆÈ»ºóÔÚ40¸ö×Ô¼ºµÄÇ®°üÖд´½¨µÈÁ¿µÄÐÂÁîÅÆ¡£KickICO¿ª·¢ÈËԱĿǰÒÑÖØлñµÃÖÇÄܺÏÔ¼µÄ·ÃÎÊȨ¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/kickico-platform-loses-77-million-in-recent-hack/