¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181212
°ä²¼¹¦·ò 2018-12-12
ÃÀ¹ú¶àÒéÔºÄÜÔ´ºÍóÒ×ίԱ»á°ä²¼ÍøÂ簲ȫսÊõ»ã±¨£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÈ·Á¢Ô¤·À»ººÍ½âÍøÂ簲ȫÊÂÎñµÄÕ½Êõ¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨ÒÔΪµ±Ç°ÃÀ¹úµÄÍøÂ簲ȫÐж¯²¢Î´¸úÉÏ»¥ÁªÍøµÄ·¢Õ¹£¬£¬£¬£¬£¬£¬£¬´«Í³µÄÐÅÏ¢¼¼ÊõÕ½ÊõÔÚÓ¦¶Ô²»ÐÝÔö³¤µÄÍøÂ簲ȫÊÂÎñÖÐÊÕЧÉõ΢¡£¡£¡£¡£¡£¡£¡£»ã±¨ÊáÀí³öÁùµãÍøÂ簲ȫ¸ÅÏëÓëÁùÏîÍøÂ簲ȫÓÅÏÈÏ£¬£¬£¬£¬£¬£¬Ô̺¬³ÉÁ¢ÆÕ±é½ÓÊܵÄÐͬÅû¶·¨Ê½¡¢ÒýÈëÈí¼þÎïÁÏÇåµ¥£¨software bill of materials£¬£¬£¬£¬£¬£¬£¬¼ò³ÆSBOM£©¡¢Ö§³Ö¿ªÔ´Èí¼þ¡¢ÃÀÂúCVE·¨Ê½¡¢Ö´Ðм¼ÊõÐÔÃüÖÜÆÚÖ§³ÖÕ½ÊõÒÔ¼°Ç¿»¯¹«Ë½ºÏ×÷ģʽ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://energycommerce.house.gov/wp-content/uploads/2018/12/12.07.18-Cybersecurity-Strategy-Report.pdf2¡¢ÎªÌáÉý°²È«ÐÔ£¬£¬£¬£¬£¬£¬£¬Ó¢¹úNHS½«ÓÚ2020ÄêÈ«Ãæ½ûÓô«Õæ»ú
Ó¢¹ú¹ú¶ÈÎÀ×ÌÊÂÎñ¾Ö£¨NHS£©ÈÕǰ°ä·¢£¬£¬£¬£¬£¬£¬£¬½«´ÓÏÂÔÂÆð²»ÔٲɰìеĴ«Õæ»ú£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2020Äê3ÔÂ31ÈÕ½ûÓÃËùÓеĴ«Õæ»ú¡£¡£¡£¡£¡£¡£¡£´Ë¾ÙÊÇΪÁËÌáÉýNHSµÄ°²È«ÐÔ£¬£¬£¬£¬£¬£¬£¬Ó¢¹úÎÀÉú²¿³¤Matt Hancock°µÊ¾´«Õæ»úÀ©´óÁ˹¥»÷Ãæ£¬£¬£¬£¬£¬£¬£¬¶øµç×ÓÓʼþ±È´«Õæ»ú¸üΪ°²È«ºÍÓÐЧ¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÓ¢¹ú»Ê¼Ò±í¿ÆÑ§Ôº£¨RCS£©µÄ¹À¼Æ£¬£¬£¬£¬£¬£¬£¬½ØÖÁ2018Äê7ÔÂNHSÈÔÔÚʹÓó¬¹ý8000̨´«Õæ»ú¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/nhs-fax-ban-set-to-improve/3¡¢ÒòÎóµ¼Ïû·ÑÕߣ¬£¬£¬£¬£¬£¬£¬Òâ´óÀûICA¶ÔFacebook·£¿£¿£¿£¿£¿£¿î1000ÍòÅ·Ôª
Òâ´óÀû¾ºÕùÖÎÀí¾Ö£¨ICA£©ÒòFacebookÎ¥·´ÁËÏû·ÑÕß·¨°¸¶ø¶ÔÆä´¦ÒÔÁ½Ïî¹²¼Æ1000ÍòÅ·ÔªµÄ·£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£ICA³ÆFacebookÔÚÊèµ¼Ïû·ÑÕß×¢²áµÄ¹ý³ÌÖдæÔÚÎóµ¼ÐÐΪ£¬£¬£¬£¬£¬£¬£¬Ã»Óгä·Ö·î¸æÓû§ËûÃǵÄÊý¾Ý½«±»ÓÃÓÚóÒ×Ö÷ÕÅ£¬£¬£¬£¬£¬£¬£¬´Ë¾ÙÎ¥·´ÁËÏû·ÑÕß·¨°¸µÄµÚ21ºÍ22Ìõ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬FacebookÔÚûÓÐÃ÷ȷ֪ͨºÍÊÂÏÈ»ñµÃÓû§Ðí¿ÉµÄÇé¿öϽ«Êý¾ÝÌṩ¸øµÚÈý·½£¬£¬£¬£¬£¬£¬£¬Î¥·´ÁËÏû·ÑÕß·¨°¸µÄµÚ24ºÍ25Ìõ¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã·¨°¸µÚ27Ìõ£¬£¬£¬£¬£¬£¬£¬Facebook»¹±Ø±ØÒªÏòËùÓÐЧ»§°ä²¼¾À´íÉêÃ÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://en.agcm.it/en/media/press-releases/2018/12/Facebook-fined-10-million-Euros-by-the-ICA-for-unfair-commercial-practices-for-using-its-subscribers%E2%80%99-data-for-commercial-purposes4¡¢³¬¹ý30¸ö¹ú¶ÈµÄ4Íòµ±¾ÖÍøÕ¾Í´´¦±»ÇÔ£¬£¬£¬£¬£¬£¬£¬»òÒÑÔÚ°µÍøÏúÊÛ
Group-IB×êÑÐÈËÔ±·¢ÏÖ³¬¹ý30¸ö¹ú¶ÈµÄ4Íòµ±¾ÖÍøÕ¾Í´´¦±»ÇÔ£¬£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢ÊÇ·¸×ï·Ö×ÓÍøÂç¶øÀ´£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÒÑÔÚ°µÍøÂÛ̳ÉÏÏúÊÛ¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýÊܺ¦ÕßλÓÚÅ·ÖÞ£¬£¬£¬£¬£¬£¬£¬Ô̺¬Òâ´óÀû£¨52%£©¡¢É³Ìذ¢À²®£¨22%£©ÒÔ¼°ÆÏÌÑÑÀ£¨5%£©¡£¡£¡£¡£¡£¡£¡£Êܺ¦Õß»¹Ô̺¬·¨¹ú£¨gouv.fr£©¡¢ÐÙÑÀÀû£¨gov.hu£©¡¢ÈðÊ¿£¨admin.ch£©µÈ¹ú¶ÈÈ·µ±¾ÖÍøÕ¾ÒÔ¼°ÒÔÉ«Áйú·À¾ü£¨idf.il£©¡¢¸ñ³¼ªÑDzÆÕþ²¿£¨mof.ge£©¡¢Å²ÍþÒÆÃñ¾Ö£¨udi.no£©µÈÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Group-IBÒÑÏòÕâЩ¹ú¶ÈµÄCERT´«µÝÁËÓйطçÏÕ¡£¡£¡£¡£¡£¡£¡£µ±¾ÖÍøÕ¾µÄµÇ¼ʹ´¦ÔÚ°µÍøÊг¡Éϲ¢²»³£¼û£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇûÓÐÖ±½ÓµÄ²ÆÕþ¼ÛÖµ£¬£¬£¬£¬£¬£¬£¬µ«APT¹¥»÷Õß¿ÉÀûÓÃÕâЩʹ´¦ÉøÈëµ±¾ÖÍøÕ¾ºÍÇÔÈ¡»úÃÜÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-steal-over-40k-logins-for-gov-services-in-30-countries/5¡¢ÃÀ¹ú¿ÆµÂ½ÇÉçÇøÑ§ÔºÔâ´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼81ÍòÃÀÔª±»ÇÔ
ÃÀ¹ú¿ÆµÂ½ÇÉçÇøÑ§ÔºÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý´¹µö¹¥»÷¿ªÊÍÁËÖ¼ÔÚÇÔÈ¡ÒøÐÐÐÅÏ¢µÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬²¢´Ó¸ÃѧԺÇÔÈ¡ÁË80.7ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¸ÃѧԺ·¢ÏÖ²¢×èÖ¹Á˺óÐøµÄ¼¸´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢ÒÑÓëÒøÐкÏ×÷×·»ØÁË27.9ÍòÃÀÔªµÄ±»µÁ×ʽ𡣡£¡£¡£¡£¡£¡£Ä¿Ç°Ã»ÓиöñÒâÈí¼þÈôºÎÇÔÈ¡×ʽðµÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬µ«¸ÃѧԺ°µÊ¾ÉÐÎÞÖ¤¾ÝÅúעѧÉú¡¢Ô±¹¤µÄÓ×ÎÒÉí·ÝÐÅÏ¢ºÍ¼Í¼ÊÜÕâ´Î¹¥»÷Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÂíÈøÖîÈûÖÝÓëÁª¹ú¹ÙÔ¹Øý¶ÔÕâ´Î͵ÇÔÊÂÎñ·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/807-130-stolen-by-hackers-after-cape-cod-community-college-phishing-attack-524208.shtml6¡¢phpMyAdmin°ä²¼³ÁÒª¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´3¸ö°²È«·ì϶
phpMyAdmin°ä²¼ÁËа汾4.8.4£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁË3¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬Ô̺¬±¾µØÎļþÔ̺¬·ì϶£¨CVE-2018-19968£©£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß´Ó·þÎñÆ÷µÄ±¾µØÎļþÖлñÈ¡Ãô¸ÐÄÚÈÝ£»£»£»£»£»£»£»£»¿çÕ¾ÒªÇóαÔì·ì϶(CSRF)/XSRF£¨CVE-2018-19969£©£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷Õß½øÐÐÓꦵÄSQL²Ù×÷£»£»£»£»£»£»£»£»ÒÔ¼°XSS·ì϶£¨CVE-2018-19970£©¡£¡£¡£¡£¡£¡£¡£Ð°汾»¹Ô̺¬ÁËһЩbug½¨¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/phpmyadmin-security-update.htmlÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ