ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ31ÖÜ

Ðû²¼Ê±¼ä 2018-08-07

Ò»¡¢±¾ÖÜÇ徲̬ÊÆ×ÛÊö


 2018Äê07ÔÂ30ÈÕÖÁ08ÔÂ05ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSamsung SmartThings Hub video-core HTTP·þÎñÆ÷»º³åÇøÒç³öÎó²î£»Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿éȨÏÞÌáÉýÎó²î£»Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î£»Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î£»SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î¡£

 

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÓ¢¹úµç×ÓÉÌÎñ·þÎñÉÌÊý¾Ý¿âй¶£¬Ô¼140ÍòÓû§ÊÜÓ°Ï죻Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶£»ICS-CERTÐû²¼ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÇ徲̬ÊƱ¨¸æ£»RedditÔâºÚ¿ÍÈëÇÖ£¬²¿·ÖÓû§µÄÊý¾Ýй¶£»KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅƱ»ÇÔ¡£

 

ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£

 

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢Samsung SmartThings Hub video-core HTTP·þÎñÆ÷»º³åÇøÒç³öÎó²î

 

 Samsung SmartThings Hub video-core HTTP·þÎñÆ÷´¦Öóͷ£¡®clips¡¯±í±£´æ»º³åÇøÒç³ö£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0583


2¡¢Intel Smart Sound TechnologyÇý¶¯³ÌÐòÄ£¿éȨÏÞÌáÉýÎó²î

 

Intel Smart Sound TechnologyÇý¶¯Ä£¿é±£´æÇå¾²Îó²î£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇó£¬ÒÔÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ´úÂë¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00163.html


3¡¢Foxit PDF Reader JavaScriptÒýÇæÊͷźóʹÓÃÎó²î

 

Foxit PDF Reader JavaScriptÒýÇæ±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬ÒÔÓ¦ÓóÌÐòȨÏÞÖ´ÐÐí§Òâ´úÂë¡£

 

 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588


4¡¢Apple iOS Wi-FiÄÚ´æÆÆËðÎó²î

 

Apple iOS Wi-Fi×é¼þ±£´æÄÚ´æÆÆËðÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÓ¦ÓóÌÐò£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉÈƹýɳºÐÌáÉýȨÏÞ¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://lists.apple.com/archives/security-announce/2018/Jul/msg00001.html


5¡¢SoftNAS Cloud OSÏÂÁî×¢ÈëÎó²î

 

SoftNAS Cloud OS webÖÎÀíÔ±¿ØÖÆ̨ÖеÄsnserv¾ç±¾Ã»ÓйýÂËÓû§ÊäÈ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨ÌØÊâµÄÇëÇó£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£

 

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.softnas.com/docs/softnas/v3/html/updating_to_the_latest_version.html

 

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ó¢¹úµç×ÓÉÌÎñ·þÎñÉÌÊý¾Ý¿âй¶£¬Ô¼140ÍòÓû§ÊÜÓ°Ïì

 

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

Ñо¿Ö°Ô±Taylor Ralston·¢Ã÷Ó¢¹úµç×ÓÉÌÎñ·þÎñÉÌFashion NexusµÄÒ»¸öÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬¶à¸ö´ò°çºÍÅäÊÎÍøÕ¾µÄÓû§ÐÅϢй¶£¬°üÀ¨Jaded London¡¢AX ParisºÍElle Belle AttireµÈÆ·ÅÆ¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Ô¼140ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢£¬°üÀ¨MD5¹þÏ£ÃÜÂë¡¢ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£Ã»Óм£ÏóÅú×¢Óû§µÄÒøÐп¨ÐÅÏ¢±£´æΣº¦¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/online-fashion-shoppers-exposed-ecommerce-breach/

 

2¡¢Boys Town¹ú¼ÒÑо¿Ò½ÔºÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶

 

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


 Boys Town¹ú¼ÒÑо¿Ò½ÔºÐû²¼Í¨Öª³Æ¸Ã×éÖ¯ÓÚ2018Äê5ÔÂ23ÈÕÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý10ÍòÃû»¼ÕߺÍÔ±¹¤µÄÐÅϢй¶¡£Õâ¿ÉÄÜÊÇÓйضùͯҽÁÆ·þÎñµÄ×î´ó¹æÄ£µÄÊý¾Ýй¶¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢Õï¶Ï»òÖÎÁÆÐÅÏ¢¡¢ÒøÐÐÕ˺š¢Óû§ÃûºÍÃÜÂëµÈÐÅÏ¢¡£¹¥»÷ÕßÈëÇÖÁ˸Ã×éÖ¯Ô±¹¤µÄµç×ÓÓʼþÕÊ»§£¬²¢Í¨¹ýδÊÚȨ»á¼û»ñÈ¡ÁËÕâЩÐÅÏ¢¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/data-breach-healthcare.html

 

3¡¢ICS-CERTÐû²¼ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÇ徲̬ÊƱ¨¸æ

 

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

 

¹ú¼Ò¹¤Òµ»¥ÁªÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©Ðû²¼ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÇ徲̬ÊƱ¨¸æ£¬±¨¸æ´ÓµØÇøÂþÑÜ¡¢Æ·ÅÆÂþÑÜ¡¢ÍþвÂþÑܵȶà¸ö½Ç¶ÈÐðÊöº£ÄÚÍøÂçÊÓƵ¼à¿ØϵͳµÄÇ徲̬ÊÆÇéÐΣ¬²¢Õë¶Ô½üÄêÀ´±¬·¢µÄÍøÂçÊÓƵ¼à¿ØϵͳÇå¾²ÊÂÎñÒòÓÉÌá³öÁËÏìÓ¦µÄΣº¦Ìá·ÀºÍÇå¾²Ó¦¶Ô¼Æ»®£¬¸øÏà¹ØÕþ¸®²¿·Ö¡¢×éÖ¯ºÍÑо¿»ú¹¹Ìṩ²Î¿¼ºÍ½è¼ø¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/be9def54499644afb6ce4b119e5e7d42.html

 

4¡¢RedditÔâºÚ¿ÍÈëÇÖ£¬²¿·ÖÓû§µÄÊý¾Ýй¶

 

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

 

RedditÐû²¼ÆäÔâºÚ¿ÍÈëÇÖ£¬²¿·ÖÓû§µÄÊý¾Ýй¶¡£¹¥»÷ÕßÈƹýË«ÒòËØÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§£¬²¢ÇÔÈ¡Á˲¿·Öµç×ÓÓʼþµØµã¡¢ÈÕÖ¾¼Í¼ÒÔ¼°°üÀ¨¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·Ý°üÀ¨2005ÄêÖÁ2007Äê5ÔÂʱ´úµÄÓû§Êý¾Ý£¬ÈçÕË»§Æ¾Ö¤£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØµãºÍ¹ûÕæ/˽ÈËÐÂÎÅ¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍÐû²¼µÄÌû×Ó±»ÒÔΪÊÇÇå¾²µÄ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/

 

5¡¢KickICOƽ̨ÔâºÚ¿ÍÈëÇÖ£¬¼ÛÖµÔ¼770ÍòÃÀÔªµÄÁîÅƱ»ÇÔ

 

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ICOƽ̨KickICOÔâµ½ºÚ¿ÍÈëÇÖ£¬Áè¼Ý7000ÍòKICKÁîÅƱ»ÇÔ£¨¼ÛÖµÔ¼770ÍòÃÀÔª£©¡£Æ¾Ö¤KickICOÊ×ϯִÐйÙAnti DanilevskiµÄ˵·¨£¬¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ7ÔÂ26ÈÕÐÇÆÚËĵÄUTCʱ¼ä09:04¡£¹¥»÷Õß»ñÈ¡ÁË¿ª·¢Ö°Ô±µÄ˽Կ£¬²¢ÐÞ¸ÄÖÇÄܺÏÔ¼µÄÐÐΪ£¬´Ý»ÙÁË40¸öµØµãÖеÄKICKÁîÅÆÈ»ºóÔÚ40¸ö×Ô¼ºµÄÇ®°üÖн¨ÉèµÈÁ¿µÄÐÂÁîÅÆ¡£KickICO¿ª·¢Ö°Ô±ÏÖÔÚÒÑÖØлñµÃÖÇÄܺÏÔ¼µÄ»á¼ûȨ¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/kickico-platform-loses-77-million-in-recent-hack/