ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ8ÖÜ
Ðû²¼Ê±¼ä 2019-02-25±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǺڿͰµÍø³öÊÛµÚÈýÅúÓû§Êý¾Ý£¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§£»Wendy'sͬÒâΪÊý¾Ýй¶Ê¼þÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð£»IxigoÔâºÚ¿ÍÈëÇÖ£¬Ô¼1800ÍòÓû§Êý¾Ýй¶£»WinRAR´úÂëÖ´ÐЩ¶´£¬Áè¼Ý5ÒÚÓû§Êܵ½Ó°Ï죻ӡ¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄ¸öÈËÐÅÏ¢¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
ÖØÒªÄþ¾²Â©¶´Áбí
DrupalÔÚͨ¹ý·Ç±í¸ñ£¨non-form resources£©ÀàÐÍÊäÈëʱδÄÜÕýÈ·¹ýÂËijЩ×ֶΣ¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.drupal.org/sa-core-2019-003
2. WinRAR ACEÎļþÈÎÒâ´úÂëÖ´ÐЩ¶´
WinRAR UNACEV2.dll¿â´¦ÖÃ.aceÎļþ´æÔÚĿ¼´©Ô½ÎÊÌ⣬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
http://win-rar.com/
3. Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉý©¶´
Intel Data Center Manager SDK°²×°·¨Ê½Óû§ÌáʾʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.html
4. Adobe Acrobat/Reader CVE-2019-7018ÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe Acrobat/Reader´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-07.html
5. Huawei Mate20 CVE-2019-5296»º³åÇøÒç³ö©¶´
Huawei Mate20´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹÉ豸Òì³£¡£
https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20190220-01-phone-cn
ÖØÒªÄþ¾²Ê¼þ×ÛÊö

GnosticplayersÔÚ°µÍøÊг¡ÉÏÐû²¼Á˵ÚÈýÅú´ýÊÛµÄÓû§ÕË»§Êý¾Ý£¬Éæ¼°µ½8¸öÍøÕ¾µÄ9276ÍòÓû§¡£Õâ8¸öÍøÕ¾°üÂÞ£ºLegendas.tv£¨386Íò£©¡¢Jobandtalent£¨1100Íò£©¡¢Onebip£¨260Íò£©¡¢StoryBird£¨400Íò£©¡¢StreetEasy£¨100Íò£©¡¢GfyCat£¨800Íò£©¡¢ClassPass£¨150Íò£©ºÍPizap£¨6080Íò£©¡£ÕâÅúÓû§Êý¾ÝµÄ×ܼ۸ñΪ2.6249¸ö±ÈÌرң¬¹²Ô¼9400ÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-puts-up-for-sale-third-round-of-hacked-databases-on-the-dark-web/
2¡¢Wendy'sͬÒâΪÊý¾Ýй¶Ê¼þÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/update-wendys-settles-financial-firms-lawsuit-over-data-breach-for-50-mln/
3¡¢IxigoÔâºÚ¿ÍÈëÇÖ£¬Ô¼1800ÍòÓû§Êý¾Ýй¶
ÔÎÄÁ´½Ó£º
https://timesofindia.indiatimes.com/business/india-business/emails-hashed-passwords-of-18m-ixigo-users-stolen/articleshow/68016866.cms
4¡¢WinRAR´úÂëÖ´ÐЩ¶´£¬Áè¼Ý5ÒÚÓû§Êܵ½Ó°Ïì
ÔÎÄÁ´½Ó£º
https://research.checkpoint.com/extracting-code-execution-from-winrar/
5¡¢Ó¡¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄ¸öÈËÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/indane-aadhaar-leak.html
ÉùÃ÷£º±¾×ÊѶÓɶ«Éƽ̨άËûÃüÄþ¾²Ð¡×é·ÒëºÍÕûÀí