ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ5ÖÜ
Ðû²¼Ê±¼ä 2019-03-04±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÊý¾Ý¹ÜÀí¹«Ë¾RubrikÒâÍâй¶´óÁ¿¿Í»§Êý¾Ý£»FaceTimeÆØÖØ´óÇÔÌý©¶´£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´£»Å·ÖÞÍøÂçÐÅÏ¢Äþ¾²¾ÖENISAÐû²¼2018ÄêÍøÂçÍþв¾°¹Û³ÂËߣ»Ó¡¶È¹ú¼ÒÒøÐÐSBIÒâÍâй¶Êý°ÙÍò¿Í»§ÐÅÏ¢£»ºÉÀ¼DPAÐû²¼2018ÄêÊý¾Ýй¶ͳ¼Æ³ÂËß¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
ÖØÒªÄþ¾²Â©¶´Áбí
Apache Hadoop´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÈƹýÄþ¾²ÏÞÖÆ£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£
https://hadoop.apache.org/cve_list.html#cve-2018-8009-http-cve-mitre-org-cgi-bin-cvename-cgi-name-cve-2018-8009-zip-slip-impact-on-apache-hadoop
2. D-Link DIR-823G HNAP1ÇëÇóÃüÁî×¢È멶´
D-Link DIR-823G´æÔÚ´úÂë×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄHNAP1ÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐOSÃüÁî¡£
https://github.com/leonW7/D-Link/blob/master/Vul_1.md
3. ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç³ö©¶´
ACD Systems Canvas Draw CALS RasterÎļþ½âÎö¹¦Ð§´æÔÚÔ½½çдÈ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0642
4. ARM Trusted Firmware-AÐÅϢ鶩¶´
ARM Trusted Firmware-A´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://github.com/ARM-software/arm-trusted-firmware/wiki/Trusted-Firmware-A-Security-Advisory-TFV-8
5. Google Chrome PDFium CVE-2019-5772ÊͷźóÀûÓôúÂëÖ´ÐЩ¶´
Google Chrome PDFium´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
ÖØÒªÄþ¾²Ê¼þ×ÛÊö

Äþ¾²Ñо¿Ô±Oliver Hough·¢ÏÖÊôÓÚÊý¾Ý¹ÜÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearch·þÎñÆ÷δÊÜÃÜÂë±£»¤£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬°üÂÞÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍÊÂÇé°¸Àý¡£Æ¾¾Ýʱ¼ä´Á£¬ÕâЩÊý¾Ý¿É×·ËÝÖÁ2018Äê10Ô¡£¾¹ýÊӲ죬Rubrik³ÆÕâһʼþÊÇÓÉÈËΪ´íÎóµ¼Öµġ£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/29/rubrik-data-leak/
2¡¢FaceTimeÆØÖØ´óÇÔÌý©¶´£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html
3¡¢Å·ÖÞÍøÂçÐÅÏ¢Äþ¾²¾ÖENISAÐû²¼2018ÄêÍøÂçÍþв¾°¹Û³ÂËß
ÔÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/enisa-threat-landscape-report-2018/
4¡¢Ó¡¶È¹ú¼ÒÒøÐÐSBIÒâÍâй¶Êý°ÙÍò¿Í»§ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/80555/data-breach/state-bank-of-india-leak.html
5¡¢ºÉÀ¼DPAÐû²¼2018ÄêÊý¾Ýй¶ͳ¼Æ³ÂËß
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/dutch-dpa-publishes-2018-report-on-data-breach-statistics/
ÉùÃ÷£º±¾×ÊѶÓɶ«Éƽ̨άËûÃüÄþ¾²Ð¡×é·ÒëºÍÕûÀí