ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ26ÖÜ

Ðû²¼Ê±¼ä 2018-07-02

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


        2018Äê06ÔÂ25ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î55¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSchneider Electric U.motion BuilderÕ»»º³åÇøÒç³öÎó²î £»£»£»£»£»Delta Industrial Automation COMMGR AHSIM_5x0 SimulatorÕ»»º³åÇøÒç³öÎó²î £»£»£»£»£»Adobe Reader DCÔ½½ç¶Áí§Òâ´úÂëÖ´ÐÐÎó²î £»£»£»£»£»Microsoft OneDrive DLL´¦Öóͷ£í§Òâ´úÂëÖ´ÐÐÎó²î £»£»£»£»£»Apache HBaseÇå¾²ÏÞÖÆÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£¡£

 

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿Ö°Ô±ÖÒÑÔ³ÆÊ¹ÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflix´¹ÂڻһֱÔöÌí £»£»£»£»£»Ó¢¹ú˰Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÍøÂçÔ¼510ÍòÓû§µÄÓïÒô¼Í¼ £»£»£»£»£»Wi-FiͬÃËÕýʽÐû²¼ÐÂÒ»´úÇå¾²±ê×¼WPA3£¬£¬£¬£¬£¬£¬£¬¿É½øÒ»²½Ìá¸ßÍøÂçÇå¾²ÐÔ £»£»£»£»£»FastBookingÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Êý°Ù¼ÒÂùݵÄÓû§Êý¾Ýй¶ £»£»£»£»£»FacebookµÚÈý·½Ó¦Óõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæÁÙй¶Σº¦¡£¡£¡£¡£¡£¡£¡£¡£

 

        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£

 

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢Schneider Electric U.motion BuilderÕ»»º³åÇøÒç³öÎó²î

 

        Schneider Electric U.motion Builder±£´æÕ»µÄ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.schneiderelectric.com/en/download/document/Umotion_Server_update/


2¡¢Delta Industrial Automation COMMGR AHSIM_5x0 SimulatorÕ»»º³åÇøÒç³öÎó²î

 

        Delta Industrial Automation COMMGR AHSIM_5x0 Simulator´¦Öóͷ£TCP±¨Îı£´æÕ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÒÔCOMMGRÀú³ÌÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

       

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttp://www.deltaww.com/Products/PluginWebUserControl/downloadCenterCounter.aspx?DID=2093&DocPath=1&hl=en-US

3¡¢Adobe Reader DCÔ½½ç¶Áí§Òâ´úÂëÖ´ÐÐÎó²î

 

        Adobe Reader DC±£´æÔ½½ç¶ÁÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄPDFÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

      

  Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-02.html
4¡¢Microsoft OneDrive DLL´¦Öóͷ£í§Òâ´úÂëÖ´ÐÐÎó²î

 

        Microsoft OneDrive´¦Öóͷ£ËÑË÷·¾¶±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄDLL£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://blogs.technet.microsoft.com/srd/2018/04/04/triaging-a-dll-planting-vulnerability/


5¡¢Apache HBaseÇå¾²ÏÞÖÆÈÆ¹ýÎó²î

        Apache HBase±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÈƹýÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://lists.apache.org/thread.html/a919e38f587c714c386a01d40fc8f45bd4219a65aaf2dc0bb4eccc96@%3Cdev.hbase.apache.org%3E

 

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ñо¿Ö°Ô±ÖÒÑÔ³ÆÊ¹ÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflix´¹ÂڻһֱÔöÌí

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


       

 

 SANSÊÖÒÕÑо¿ÔºÔº³¤Johannes Ullrich³ÆÊ¹ÓÃTLSÈÏÖ¤ÍøÕ¾µÄNetflix´¹ÂڻһֱÔöÌí¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÈëÇÖWordPress»òDrupalµÈCMS¹¹½¨µÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬È»ºó½¨ÉèNetflix´¹ÂÚÍøÕ¾²¢»ñÈ¡ÓëNetflixÃû³ÆÏà¹ØµÄTLSÖ¤Ê飬£¬£¬£¬£¬£¬£¬Èçnetflix.domain.com»ònetflix.login.domain.com£¬£¬£¬£¬£¬£¬£¬ÕâʹÆä¿´ÆðÀ´Ô½·¢¿ÉÐÅ¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»NetflixÕË»§¼ÛÖµ²¢²»¸ß£¬£¬£¬£¬£¬£¬£¬µ«ÕâÖÖ¹¥»÷Ò×ÓÚʵÏÖ×Ô¶¯»¯ÇÒÄÑÒÔÈÃÊܺ¦Õß·¢Ã÷¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/new-phishing-scam-reels-in-netflix-users-to-tls-certified-sites/132976/

 

2¡¢Ó¢¹ú˰Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÍøÂçÔ¼510ÍòÓû§µÄÓïÒô¼Í¼

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



Òþ˽± £»£»£»£»£»¤×éÖ¯Big Brother Watch·¢Ã÷Ó¢¹úµÄ˰Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÍøÂçÔ¼510ÍòÓ¢¹ú¹«ÃñµÄÓïÒô¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£HMRCͨ¹ý2017Äê1ÔÂÍÆ³öµÄÒ»ÏîÓïÒôʶ±ðЧÀÍÍøÂçÁËÕâЩ¼Í¼£¬£¬£¬£¬£¬£¬£¬¸ÃЧÀÍÔÊÐíÓû§ÔÚºô½ÐHMRCʱͨ¹ýÓïÒô¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£µ«Big Brother Watch·¢Ã÷Óû§ÎÞ·¨Ñ¡Ôñ²»Ê¹ÓøÃЧÀÍ£¬£¬£¬£¬£¬£¬£¬ËùÓв¦´òHMRCÈÈÏßµÄÓû§¶¼±»ÆÈÂ¼ÖÆÁËÓïÒô¼Í¼£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓû§ÎÞ·¨Ñ¡Ôñ´ÓHMRCµÄÊý¾Ý¿âÖÐɾ³ýÆäÓïÒô¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÒÔΪHMRC´Ë¾ÙÏÔ×ÅÎ¥·´ÁËGDPR£¬£¬£¬£¬£¬£¬£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒѶԴËÊÂÕö¿ªÕýʽµÄÊӲ졣¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/uk-tax-agency-recorded-the-voices-of-51-million-brits/

 

3¡¢Wi-FiͬÃËÕýʽÐû²¼ÐÂÒ»´úÇå¾²±ê×¼WPA3£¬£¬£¬£¬£¬£¬£¬¿É½øÒ»²½Ìá¸ßÍøÂçÇå¾²ÐÔ

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾
       

±¾ÖÜÒ»Wi-FiͬÃËÕýʽÐû²¼ÐÂÒ»´úÇå¾²±ê×¼WPA3£¬£¬£¬£¬£¬£¬£¬WPA3ÊÇÓÃÓÚWi-FiÅþÁ¬µÄÓû§Éí·ÝÑéÖ¤ÊÖÒÕµÄ×îа汾¡£¡£¡£¡£¡£¡£¡£¡£WPA3ÓÐÁ½ÖÖÇ徲ģʽ£¬£¬£¬£¬£¬£¬£¬WPA3-PersonalºÍWPA3-Enterprise£¬£¬£¬£¬£¬£¬£¬ÕâÁ½ÖÖÇ徲ģʽµÄÖ÷񻂿±ðÔÚÓÚÉí·ÝÑéÖ¤½×¶Î¡£¡£¡£¡£¡£¡£¡£¡£¹ØÓÚÆóÒµ¡¢Õþ¸®ºÍ½ðÈÚÍøÂçÖÐʹÓõÄ×°±¸£¬£¬£¬£¬£¬£¬£¬½¨ÒéʹÓÃWPA3-EnterpriseÇ徲ģʽ£¬£¬£¬£¬£¬£¬£¬WPA3-PersonalÔòÊÇÃæÏòͨË×СÎÒ˽¼ÒÓû§¡£¡£¡£¡£¡£¡£¡£¡£Wi-FiͬÃËÌåÏÖWPA3µÄSAEËã·¨Äܹ»µÖÓù±©Á¦¹¥»÷£¬£¬£¬£¬£¬£¬£¬WPA3½«ÔÚ¶à´Îʧ°ÜʵÑéºó×èÖ¹ÈÏÖ¤ÇëÇ󡣡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-wpa3-wi-fi-standard-released/

 

4¡¢FastBookingÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Êý°Ù¼ÒÂùݵÄÓû§Êý¾Ýй¶

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



       

°ÍÀèÂùÝÔ¤¶©¹«Ë¾FastBookingÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Êý°Ù¼ÒÂùݵÄÓû§Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£FastBooking³Æ¹¥»÷ÕßÔÚ6ÔÂ14ÈÕʹÓÃÆäЧÀÍÆ÷ÉÏÒ»¸öÈí¼þµÄÎó²î×°ÖÃÁ˶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÂùÝÓû§µÄÐÕÃû¡¢¹ú¼®¡¢µØµã¡¢µç×ÓÓʼþµØµãºÍÂùÝÔ¤¶¨Ïà¹ØÐÅÏ¢£¨ÂùÝÃû³Æ¡¢ÈëסºÍÍË·¿£©µÈÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡µÄÊý¾Ý»¹°üÀ¨²¿·ÖÓû§µÄÒøÐп¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬È翨ºÅ¡¢ÓâÆÚÈÕÆÚµÈ¡£¡£¡£¡£¡£¡£¡£¡£FastBooking³Æ¸ÃÊÂÎñÓ°ÏìÁËÈÕ±¾µÄ380¼ÒÂùÝ£¬£¬£¬£¬£¬£¬£¬Bleeping ComputerÒÔΪÕâÒ»Êý×ÖÔÚÈ«Çò¹æÄ£ÄÚ¿ÉÄÜÁè¼ÝÁË1000¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hundreds-of-hotels-affected-by-data-breach-at-hotel-booking-software-provider/

 

5¡¢FacebookµÚÈý·½Ó¦Óõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæÁÙй¶Σº¦

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



 Ñо¿Ö°Ô±Inti De Ceukelaire·¢Ã÷µÚÈý·½ÖÇÁ¦¾ºÈüÓ¦ÓÃNametests.comʹԼ1.2ÒÚFacebookÓû§µÄÊý¾ÝÃæÁÙй¶Σº¦¡£¡£¡£¡£¡£¡£¡£¡£Ö»ÒªFacebookÓû§ÔÚNameTestsÍøÕ¾ÉÏ×¢²á£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½«¿ÉÒÔ»ñÈ¡Óû§µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£µ«Ñо¿Ö°Ô±·¢Ã÷NameTestsÍøÕ¾¹ýʧµØ½«Æä¡°Access-Control-Allow-Origin¡±Õ½ÂÔÉèÖóÉͨÅä·û*£¬£¬£¬£¬£¬£¬£¬ÕâÔÊÐíÈκÎÍøÕ¾»á¼ûÆä×ÊÔ´£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÕâЩÓû§µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£NameTestsÒѾ­ÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/facebook-users-data-leak.html

 

©ADLab ÍòÀû¹ú¼Ê¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ 2016