¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190222

°ä²¼¹¦·ò 2019-02-22
1¡¢DrupalÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìDrupal°æ±¾7ºÍ8

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

DrupalÍŶӽ¨¸´¸ßΣԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-6340£© ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËDrupal 7¡¢8µÄÖ÷Ìâ×é¼þ£¬£¬ £¬£¬£¬£¬£¬£¬¹ÌÈ»¸ÃÍŶӲ¢Î´Åû¶Èκμ¼Êõϸ½Ú£¬£¬ £¬£¬£¬£¬£¬£¬µ«Ìáµ½¸Ã·ì϶ÓëijЩ×Ö¶ÎδÕýÈ·´¦ÖÃÊý¾ÝÀàÐÍÓÐ¹Ø ¡£¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»¹Ó¦¸Ã°ÑÎÈÖ»ÓÐÆôÓÃÁËRESTful Web·þÎñÄ£¿ £¿ £¿£¿£¿éÇÒÔÊÐí½Ó¹ÜPATCHºÍPOSTÒªÇóµÄÍøÕ¾²Å»áÊܵ½Ó°Ïì ¡£¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§½«ÍøÕ¾¾¡¿ìÉý¼¶ÖÁDrupal 8.6.10»ò8.5.11 ¡£¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/hacking-drupal-vulnerability.html

2¡¢AdobeÕë¶ÔAdobe ReaderÐÅϢй¶·ì϶°ä²¼µÚ¶þ¸ö½¨¸´²¹¶¡

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

±¾ÖÜËÄAdobeÕë¶ÔAdobe ReaderÖеĿɵ¼ÖÂÐÅϢй¶µÄ¸ßΣ·ì϶£¨CVE 2019-7089£©°ä²¼Á˵ڶþ¸ö½¨¸´²¹¶¡ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉCure53µÄ×êÑÐÈËÔ±AlexInf¨¹hr·¢Ïֵ쬣¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÁ˰汾19.010.20069֮ǰµÄËùÓÐReader DC°æ±¾ ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚAdobeÓÚ2ÔÂ12ÈÕ°ä²¼µÚÒ»¸ö½¨¸´²¹¶¡Ö®ºó£¬£¬ £¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁ˿ɵ¼ÖÂÒ»ÑùÎÊÌâµÄÅÔ·¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£¡£Õâ¸öеÄÅÔ·¹¥»÷±»·ÖÅ䏸CVE±àºÅCVE-2019-7815£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓöñÒâPDFÎĵµ´¥·¢¸Ã·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÒÔSMBÒªÇóµÄ´ó¾Ö½«Êܺ¦ÕßµÄNTLM¹þÏ£·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷ ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-patches-critical-information-disclosure-flaw-in-reader-again/

3¡¢UW MedicineÒâ±íй¶Լ97.4Íò»¼ÕßµÄPHIÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

»ªÊ¢¶Ù´óѧҽѧԺ£¨UW Medicine£©µÄÒ»¸öÊý¾Ý¿â´æÔÚÅäÖÃÃýÎ󣬣¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼97.4Íò»¼ÕßµÄPHIÐÅÏ¢ÔÚÍøÂçÉϿɹ«¿ª½Ó¼û ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ2018Äê12ÔÂ4ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬UW  MedicineÓÚ12ÔÂ26ÈÕ·¢ÏÖÁËÕâÒ»ÊÂÎñ£¬£¬ £¬£¬£¬£¬£¬£¬²¢Ïò¼à¹Ü»ú¹¹½øÐÐÁ˻㱨 ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢Ô̺¬»¼ÕßµÄÐÕÃû¡¢Ò½ÁƼͼ±àºÅÒÔ¼°Ò»¶ÎÃèÊöÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬£¬µ«²»Ô̺¬ÈκÎÒ½ÁƼͼ¡¢²ÆÕþÐÅÏ¢ºÍÉç»á°²È«ºÅÂë ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/uw-medicine-notifying-974000-patients-whose-information-was-exposed-online-in-december/

4¡¢GNCTDÊý¾Ý¿âÒâ±íй¶½ü50ÍòÓ¡¶È¹«ÃñµÄÓ×ÎÒÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

×êÑÐÈËÔ±Bob Diachenko·¢ÏÖÒ»¸ö²»°²È«µÄ·þÎñÆ÷й¶Á˽ü50ÍòÓ¡¶È¹«ÃñµÄ¾ßÌåÓ×ÎÒÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊÇÒ»¸öÃûΪGNCTDµÄMongoDBÊ·ý£¬£¬ £¬£¬£¬£¬£¬£¬´óÓ×Ϊ4.1GB£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬458388ÃûÓ¡¶ÈеÂÀ﹫ÃñµÄÓ×ÎÒÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬ËûÃǵÄAadhaarºÅÂëºÍÑ¡ÃñIDµÈ ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âµÄÖÎÀíÔ±µç×ÓÓʼþµØÖ·Ô̺¬transerve.comÓòÃû ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿âÔÚÍøÉ϶³öµÄ¹¦·ò³¤¶ÌÒÔ¼°ÊÇ·ñÔâµ½ÆäËûÈ˵ĽӼû£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚDiachenko֪ͨӡ¶ÈCERTºó£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒѽøÐÐÍÑ»ú±£»£»£»£»£»£»¤ ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/mongodb-delhi-database-leaked.html

5¡¢·áÌï°Ä´óÀûÑÇ×Ó¹«Ë¾È·ÈÏÔâÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬ÔÝÎÞϸ½ÚÅû¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

2ÔÂ21ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬·áÌï°Ä´óÀûÑÇ×Ó¹«Ë¾Ö¤ÊµÔâµ½ÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏûÓÐÔ±¹¤»ò¿Í»§µÄÓ×ÎÒÊý¾ÝÊܵ½ÇÖº¦ ¡£¡£¡£¡£¡£¡£¡£¡£µ±Ç°¹¥»÷µÄÆðÔ´ÒÀȻδ֪£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÇҸù«Ë¾²¢Î´Åû¶ÈκÎÓйØÏ¸½Ú ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÓë¹ú¼ÊÍøÂ簲ȫר¼ÒÇ×êǺÏ×÷£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔʹÆäϵͳ³Áи´Ô­ÔË×÷ ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/toyota-australia-hit-by-cyberattack-no-customer-data-compromised-814cb777

6¡¢Ð´¹µö¹¥»÷»î¶¯Separ£¬£¬ £¬£¬£¬£¬£¬£¬ÒÑϰȾ½ü200¼Ò¹«Ë¾

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Ò»¸öеĴ¹µö¹¥»÷»î¶¯ÔÚÀûÓöñÒâPDFÎĵµÏòÖ¸±ê´«²¼¶ñÒâÈí¼þSepar£¬£¬ £¬£¬£¬£¬£¬£¬²¢×îÖÕÇÔÈ¡ËûÃÇä¯ÀÀÆ÷ºÍµç×ÓÓʼþµÄÍ´´¦ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÆðÍ·ÓÚ1Ôµ×£¬£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¶«ÄÏÑÇ¡¢Öж«ºÍ±±ÃÀ£¬£¬ £¬£¬£¬£¬£¬£¬ÒÑÓÐÔ¼200¼Ò¹«Ë¾ºÍ1000¶àÃûÓ×ÎÒÊܵ½Ó°Ïì ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓúϷ¨µÄ¿ÉÖ´ÐÐÎļþºÍ¶ÌµÄ¾ç±¾£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷»úÔìµ¥Ò»¶øÓÖÓÐЧ ¡£¡£¡£¡£¡£¡£¡£¡£Deep Instinct×êÑÐÈËÔ±°µÊ¾ÕâÒ»´¹µö»î¶¯ÈÔÔÚ»ý¼«½øÐÐÖÐ ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/separ-malware-credentials-phishing/142009/

ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù