ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ1ÖÜ
Ðû²¼Ê±¼ä 2019-01-07±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ°ÄÖÞÊý×Ö½¡¿µÊðÐû²¼2017-2018Äê¶È³ÂËߣ¬Åû¶42ÆðÊý¾Ýй¶Ê¼þ£»ÃÀ¹úÎÀÉú²¿Ðû²¼Ò½ÁÆÐÐÒµÍøÂçÄþ¾²Êµ¼ù³ÂËߣ»Ô½ÄÏÕþ¸®Í¨¹ýÐÂÍøÂçÄþ¾²·¨£¬ÔÊÐíÕþ¸®·ÃÎÊÓû§Êý¾Ý£»ÃÜÂë¹ÜÀíÆ÷BlurÓû§Êý¾Ýй¶£¬240ÍòÈËÊܵ½Ó°Ï죻°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸¸æ¿¢ºÍ½â£¬Å⸶38.2ÍòÃÀÔª¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
ÖØÒªÄþ¾²Â©¶´Áбí
1. Adobe Acrobat/Reader CVE-2018-16011ÊͷźóÀûÓôúÂëÖ´ÐЩ¶´
Adobe Acrobat/Reader´¦ÖÃPDFÎļþ´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£https://www.auscert.org.au/bulletins/73738
2. D-Link DIR-818LW/DIR-860L soap.cgi OSÃüÁîÖ´ÐЩ¶´
D-Link DIR-818LW/DIR-860L soap.cgi´¦ÖÃService²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£https://github.com/pr0v3rbs/CVE/tree/master/CVE-2018-20114
3. Apache NetBeans Proxy Auto-Configuration (PAC) interpretationÔ¶³ÌÃüÁîÖ´ÐЩ¶´
Apache NetBeans Proxy Auto-Configuration (PAC) interpretationʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://lists.apache.org/thread.html/d1c37966a316a326ab4ff4d4bc056322e8adcbe984e8145c0ecda7fa@%3Cdev.netbeans.apache.org%3E
4. Guardzilla GZ621W CVE-2018-18601»º³åÇøÒç³ö©¶´
Guardzilla GZ621W ¡®TK_set_deviceModel_req_handle¡¯º¯Êý´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐдúÂë¡£
https://labs.bitdefender.com/2018/12/iot-report-major-flaws-in-guardzilla-cameras-allow-remote-hijack-of-the-security-device/
5. Dell EMC RSA Archer·ÃÎÊ¿ØÖÆ´íÎ󩶴
Dell EMC RSA Archer´æÔÚ·ÃÎÊ¿ØÖÆ´íÎ󩶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆ£¬¶ÁÈ¡ÊÜÏÞÐÅÏ¢¡£
https://seclists.org/fulldisclosure/2019/Jan/3
ÖØÒªÄþ¾²Ê¼þ×ÛÊö

°Ä´óÀûÑÇÊý×Ö½¡¿µÊð£¨ADHA£©ÔÚÆä2017-2018Äê¶È³ÂËßÖÐÌåÏÖ£¬My Health RecordϵͳÖеÄÒ½ÁƼǼÔÚ2017Äê7ÔÂ1ÈÕÖÁ2018Äê6ÔÂ30ÈÕÆڼ乲·¢Éú42ÆðÊý¾Ýй¶Ê¼þ¡£ÆäÖдó¶àÊýй¶Ê¼þÓëÒ½ÁƱ£ÏÕÆÛÕ©Óйأ¬My Health Record²¢Î´Ôâµ½Ëðº¦ÆäÍêÕûÐÔºÍÄþ¾²ÐԵĶñÒâ¹¥»÷¡£½ØÖÁ2018Äê7ÔÂ27ÈÕ£¬ÒÑÓÐÔ¼ËÄ·ÖÖ®Ò»µÄ°Ä´óÀûÑÇÈËÔÚMy Health RecordϵͳÖн¨Á¢ÁËÒ½ÁƼǼ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/my-health-record-had-42-data-breaches-in-2017-18-but-no-malicious-attacks-adha/

ÃÀ¹úÎÀÉú²¿£¨HHS£©Ðû²¼Ò»·ÝÕë¶ÔÒ½ÁÆÐÐÒµµÄÍøÂçÄþ¾²Ö¸ÄÏ£¬¸Ã³öÊéÎïµÄÃû³ÆΪ¡¶Ò½ÁÆÐÐÒµÍøÂçÄþ¾²Êµ¼ù£º¹ÜÀíÍþв¼°±£»¤»¼Õß¡·¡£Õâ·Ý³ÂËßÊÇHHS¼°Ò½ÁÆר¼Ò»¨·ÑÁ½Äêʱ¼äµÄÊÂÇé½á¹û£¬ÊÇÓÉ2015ÄêµÄÍøÂçÄþ¾²·¨°¸ÊÚȨµÄ¡£¸ÃÖ¸ÄÏ̽ÌÖÁËÒ½ÁÆÐÐÒµÃæÁÙµÄÎå´óÏà¹ØÍþв£¬²¢½¨Òé½ÓÄÉ10ÖÖÍøÂçÄþ¾²´ëÊ©À´»º½âÕâЩÍþв¡£¸ÃÖ¸ÄÏ»¹Ç¿µ÷ÁË¿ìËÙÓ¦¶ÔÕâЩÍþвµÄÖØÒªÐÔ¡£
ÔÎÄÁ´½Ó£º
https://www.nextgov.com/cybersecurity/2019/01/hhs-releases-voluntary-cybersecurity-practices-health-industry/153835/
3¡¢Ô½ÄÏÕþ¸®Í¨¹ýÐÂÍøÂçÄþ¾²·¨£¬ÔÊÐíÕþ¸®·ÃÎÊÓû§Êý¾Ý
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/vietnams-new-cyber-law-threatens/
4¡¢ÃÜÂë¹ÜÀíÆ÷BlurÓû§Êý¾Ýй¶£¬240ÍòÈËÊܵ½Ó°Ïì

±¾ÖÜÒ»Abine¹«Ë¾ÌåÏÖÆäÃÜÂë¹ÜÀíÆ÷²úÎïBlurµÄÓû§Êý¾ÝÔÚ·þÎñÆ÷ÉÏ̻¶£¬ÕâЩÊý¾Ý°üÂÞ2018Äê1ÔÂ6ÈÕ֮ǰע²áµÄBlurÓû§µÄÐÅÏ¢£¬Èçµç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂëÌáʾÓï¡¢×îºóµÇ¼IPºÍ¼ÓÑÎÃÜÂë¹þÏ£¡£¸Ã¹«Ë¾Ç¿µ÷³ÆÓû§µÄÃÜÂë¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍµç»°ºÅÂëûÓÐй¶¡£ÕâһʼþÓ°ÏìÁËÔ¼240ÍòBlurÓû§¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/
5¡¢°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸¸æ¿¢ºÍ½â£¬Å⸶38.2ÍòÃÀÔª

°ÍÎ÷ÒøÐÐInter¾Í2018ÄêÔçЩʱºòµÄ½üÁ½ÍòÓû§Êý¾Ýй¶°¸¼þ¸æ¿¢ºÍ½â£¬Æ¾¾Ý°ÍÎ÷¼ì²ì¹Ù°ì¹«ÊÒ£¨PPO£©Ðû²¼µÄÏûÏ¢£¬¸ÃÒøÐн«Ö§¸¶150ÍòÀ×ÑǶû£¨Ô¼ºÏ38.2ÍòÃÀÔª£©µÄÅâ³¥½ð¡£Æ¾¾Ý¸ÃʼþÊÓ²ìίԱ»á¼ì²ì¹ÙFrederick MeinbergµÄÏûÏ¢£¬InterÔøÊÔͼÑÚ¸ÇÕâÒ»Êý¾Ýй¶Ê¼þ£¬Õâ¸ø¿Í»§¡¢¹É¶«ºÍͶ×ÊÕß´øÀ´Á˸ü´óµÄ·çÏÕ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/brazilian-bank-inter-pays-fine-over-customer-data-leak/
ÉùÃ÷£º±¾×ÊѶÓɶ«Éƽ̨άËûÃüÄþ¾²Ð¡×é·ÒëºÍÕûÀí