¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181116

°ä²¼¹¦·ò 2018-11-16
1¡¢iPhone X¡¢Galaxy S9ºÍÓ×Ã×6¾ùÔÚ¶«¾©Pwn2Own 2018Éϱ»¹¥ÆÆ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚ11ÔÂ13ÈÕÖÁ14ÈյĶ«¾©Pwn2Own 2018ºÚ¿Í´óÈüÖУ¬£¬£¬£¬£¬°×ñºÚ¿ÍÔÙ´ÎÖ¤Ã÷¼´±ãÊÇÖ÷Á÷³§É̵Ä×îÐÂÖÇÄÜÊÖ»úÒ²Äܹ»±»¹¥ÆÆ¡£¡£¡£¡£¡£¡£Èý¿îÖ÷Á÷Æì½¢»ú-iPhone X¡¢ÈýÐÇGalaxy S9ºÍÓ×Ã×6¾ù±»³É¹¦ÈëÇÖ¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î´óÈüÉÏÀ´×Ô·ÖÆç¹ú¶È¡¢³§É̵ݲȫÍŶӹ²Åû¶ÁËÆ»¹û¡¢ÈýÐǺÍÓ×Ã×ÒÆ¶¯É豸ÖеÄ18¸öÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£ÓÉÁ½Ãû×êÑÐÈËÔ±-Richard ZhuºÍAmat Cama×é³ÉµÄÍŶÓFluoroacetate£¨·úÒÒËᣩ³ÉΪ×î´óÓ®¼Ò£¬£¬£¬£¬£¬ËûÃÇ»ñµÃÁË21.5ÍòÃÀÔªµÄ¼Î½±ºÍPwn´ó¼ÒµÄ³ÆºÅ¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/mobile-hacking-exploits.html


2¡¢ÐÂÔóÎ÷Öݴȱ¯»ú¹¹KARS4KIDSÒⱩ¶³ö2.1Íò¾èÔùÕßÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


11ÔÂ3ÈÕHacken×êÑÐÈËÔ±Bob Diachenko·¢ÏÖÊôÓÚÐÂÔóÎ÷Öݴȱ¯»ú¹¹KARS4KIDSµÄÒ»¸öMongoDBÊý¾Ý¿â¶³öÔÚÍøÉÏ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔ̺¬21612Ãû¾èÔùÕßµÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬Èçµç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃÜÂëµÄÃ÷ÎÄÊý¾Ý¡¢³¬µÈÖÎÀíԱʹ´¦µÈ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩʹ´¦µÇ¼KARS4KIDSÍøÕ¾£¬£¬£¬£¬£¬´Ó¶ø½øÒ»²½½Ó¼ûÊܺ¦ÕߵļÒͥסַºÍµç»°ºÅÂëµÈÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¸üΪÑϳÁµÄÊÇ£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÖÐÔ̺¬Ò»¸öÀÕË÷µ¥¾Ý£¬£¬£¬£¬£¬ÕâÅú×¢ÖÁÉÙÒÑÓÐÒ»¸öµÚÈý·½ÒѾ­·¢ÏÖÁËÕâ¸öÊý¾Ý¿â²¢¿ÉÄÜÇÔÈ¡ÁËÓйØÊý¾Ý¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/21k-donors-had-their-personal-info-leaked-following-kars4kids-data-breach-523795.shtml


3¡¢ÂíÀ´Î÷ÑÇýÌ幫˾Media PrimaÔâµ½ÀÕË÷Èí¼þ¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ÂíÀ´Î÷ÑÇýÌ幫˾Media PrimaÉÏÖÜËÄÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¹«Ë¾µÄµç×ÓÓʼþϵͳ±»ÆÈ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¾Ý±¾µØÃ½Ì屨·£¬£¬£¬£¬£¬¹¥»÷ÕßÒªÇó¸Ã¹«Ë¾Ö§¸¶1000¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼582ÍòÃÀÔª£©µÄÊê½ð£¬£¬£¬£¬£¬µ«Media Prima¾ö¶¨²»Ö§¸¶Õâ±ÊÊê½ð£¬£¬£¬£¬£¬¶øÊǽ«ËûÃǵĵç×ÓÓʼþϵͳǨáãµ½G SuiteÉÏ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÎ¨Ò»Êܵ½Ó°ÏìµÄÊǸù«Ë¾µÄµç×ÓÓʼþϵͳ£¬£¬£¬£¬£¬ÆäÖ÷ÌâÒµÎñÔËÓª²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/1-000-bitcoins-ransom-asked-from-media-prima-after-successful-ransomware-attack-523794.shtml


4¡¢×êÑлú¹¹°ä²¼¹ØÓÚºÚ¿ÍÍÅ»ïTEMP.PeriscopeµÄ·ÖÎö»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝRecorded FutureµÄÐÂ×êÑл㱨£¬£¬£¬£¬£¬ÍøÂç·¸×ïÍÅ»ïTEMP.PeriscopeÊÇÕë¶ÔÒ»¼ÒÓ¢¹ú¹¤³Ì¹«Ë¾µÄ´¹µö¹¥»÷±³ºóµÄ¹¥»÷Õß¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄÔ±¹¤ÔÚ2018Äê7Ô³õÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬Í³Ò»¸ö¹¥»÷»î¶¯ÒÉËÆ»¹Õë¶ÔÁËÒ»Ãû¼íÆÒÕ¯¼ÇÕß¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃscsnewstoday[.]comÓòÃû×÷ΪC2·þÎñÆ÷£¬£¬£¬£¬£¬²¢ÇÒͨ¹ýFoxmail·¢ËÍ´¹µöÓʼþ¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁ˶íÂÞ˹APT×éÖ¯DragonflyÔøÊ¹ÓùýµÄ¹ÖÒìµÄTTP¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.recordedfuture.com/chinese-threat-actor-tempperiscope/


5¡¢Î÷ÃÅ×Ó°ä²¼¶à¿î²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬½¨¸´8¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖܶþÎ÷ÃÅ×Ó°ä²¼ÁËһϵÁн¨¸´²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬½¨¸´Á˶à¿î²úÆ·ÖеÄ8¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£ÆäÖнÏÑϳÁµÄ·ì϶Ô̺¬SCALANCE·À»ðǽ²úÆ·ÖеÄXSS·ì϶£¨CVE-2018-16555£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ý·À»ðǽµÄ°²È«´ëÊ©£¬£¬£¬£¬£¬Ê¹¹¤ÒµÍøÂçµÄÔËÓªºÍ³ö²úÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Î÷ÃÅ×ÓS7-400 CPUÖеIJ»ÕýÈ·ÊäÈëÑéÖ¤·ì϶£¨CVE-2018-16556£©¿Éµ¼ÖÂÉ豸±ÀÀ£ºÍDoS¡£¡£¡£¡£¡£¡£ÆäËü·ì϶Çë²Î¿¼ICS-CERT°ä²¼µÄ°²È«Õ÷ѯ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/siemens-patches-firewall-flaw-that-put-operations-at-risk/139082/


6¡¢ÃÀ¹ú¹ú»áͨ¹ýз¨°¸£¬£¬£¬£¬£¬½«³ÉÁ¢ÐÂÍøÂ簲ȫ»ú¹¹CISA

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖÜÃÀ¹ú¹ú»áͨ¹ýÁËÒ»Ïîз¨°¸£¬£¬£¬£¬£¬½«ÔÚÃÀ¹úºÓɽ°²È«Êý£¨DHS£©³ÉÁ¢ÐÂÍøÂ簲ȫ»ú¹¹CISA£¨ÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£©£¬£¬£¬£¬£¬²¢ÓÉCISAÕÆ¹ÜÍøÂçºÍÎïÀí»ù´¡ÉèÊ©µÄ°²È«¡£¡£¡£¡£¡£¡£CISA½«ÓÉNPPD£¨¹ú¶È±£»£»£»£» £»£»¤Óë´òËã¾Ö£©³Á×é¶øÀ´¡£¡£¡£¡£¡£¡£NPPD¸±²¿³¤Christopher Krebs³Æ£¬£¬£¬£¬£¬¸Ã·¨°¸µÄͨ¹ý´ú±íÁ˹ú¶ÈÒâͼ¸ÄÉÆÍøÂ簲ȫ·½ÃæµÄÕæÕý½øÕ¹£¬£¬£¬£¬£¬Õ⽫ÓÐÖúÓڸò¿ÃŸüºÃµØ±£»£»£»£» £»£»¤¹ú¶ÈµÄ¹Ø¼ü»ù´¡ÉèÊ©ºÍÍøÂçÆ½Ì¨¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78063/laws-and-regulations/cybersecurity-and-infrastructure-security-agency.html


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù