¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181128

Ðû²¼Ê±¼ä 2018-11-28
1¡¢NodeJSÈÈÃÅÄ£¿£¿£¿£¿éEvent-Stream±»Ö²Èë¶ñÒâ´úÂë

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ò»¸öÆÕ±éʹÓõÄNodeJSÄ£¿£¿£¿£¿éEvent-Stream±»·¢Ã÷ѬȾÁ˶ñÒâ´úÂë £¬£¬¿ÉÇÔÈ¡±ÈÌØ±ÒÇ®°üÖеÄ×ʽ𡣡£¡£¡£Event-StreamÊÇÒ»¸öµÚÈý·½¿â £¬£¬ÓÃÓÚ´¦Öóͷ£Node.jsÁ÷Êý¾Ý £¬£¬ÆäÒ»ÖܵÄÏÂÔØÁ¿¾Í¿¿½ü200Íò´Î¡£¡£¡£¡£¸Ã¶ñÒâ´úÂë±£´æÓÚEvent-Stream°æ±¾3.3.6ÖÐ £¬£¬ÏÖÔڸð汾Òѱ»É¾³ý £¬£¬Óû§¿É¸üÐÂÖÁ×îа汾4.0.1¡£¡£¡£¡£ÊÂÎñµÄÒòÓÉÊÇEvent-StreamµÄÔ­×÷ÕßDominic Tarr½«ÏîÄ¿µÄ¿ª·¢ºÍά»¤½»¸øÁËÁíÒ»Ãû×÷Õßright9ctrl £¬£¬µ«right9ctrlËæºóÐû²¼Á˰üÀ¨¶ñÒâ´úÂëµÄ°æ±¾¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/nodejs-event-stream-module.html


2¡¢Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþ»î¶¯sLoad

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


CERT-Yoroi·¢Ã÷Ò»¸öÕë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþ»î¶¯ £¬£¬¸Ã»î¶¯Ö÷Òª·Ö·¢sLoadµÄбäÖÖ¡£¡£¡£¡£sLoadµÄ¹¦Ð§Ç¿Ê¢ £¬£¬Ëü¿ÉÒÔ½ØÈ¡ÆÁÄ»¡¢¶ÁÈ¡Àú³ÌÁÐ±í¡¢»ñÈ¡DNS»º´æ¡¢ÇÔÈ¡outlookÓʼþÄÚÈݵÈ¡£¡£¡£¡£¸Ã»î¶¯ÖÐsLoadͨ¹ýÀ¬»øÓʼþÖеÄzip¸½¼þ¾ÙÐзַ¢¡£¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎú¸Ã»î¶¯ÊÇÒ»¸öÐµķ¸·¨ÍÅ»ïËùΪÕÕ¾ÉÒÑÖªµÄ·¸·¨ÍÅ»ï¸Ä±äÁËËüÃǵÄTTP¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78468/malware/sload-malspam-hit-italy.html


3¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶ÔÖж«µØÇøµÄ¶ñÒâ»î¶¯DNSpionage

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


˼¿ÆTalos·¢Ã÷Õë¶ÔÀè°ÍÄۺͰ¢ÁªÇõÕþ¸®ÍøÕ¾ÒÔ¼°Ò»¼ÒÀè°ÍÄÛº½¿Õ¹«Ë¾µÄжñÒâ»î¶¯¡£¡£¡£¡£Æ¾Ö¤Talos¶ÔÆä»ù´¡ÉèÊ©ºÍTTPµÄÊÓ²ìЧ¹û £¬£¬¸Ã¶ñÒâ»î¶¯ÎÞ·¨ÓëÈκÎÒÑÖªµÄ¹¥»÷Õß¾ÙÐйØÁª¡£¡£¡£¡£ÏÖÔÚ»¹²»¿ÉÈ·¶¨¹¥»÷ÕßµÄÄ¿µÄ £¬£¬Ò²²»ÇåÎú¹¥»÷ÕßÓÃÓÚ·Ö·¢¶ñÒâÎĵµµÄÒªÁì £¬£¬µ«×îÓпÉÄܵÄÊÇͨ¹ýÓã²æÊ½´¹Âڻ»òÉ罻ýÌåÆ½Ì¨¾ÙÐзַ¢¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÅû¶Á˸ü¶àµÄÊÖÒÕϸ½ÚºÍ¹¥»÷ʱ¼äÖá¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html


4¡¢ÃÀ¹úiOSÓû§Ôâ´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯¹¥»÷

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Çå¾²³§ÉÌConfiant·¢Ã÷Ò»¸öÕë¶ÔÃÀ¹úiOSÓû§µÄ´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯¡£¡£¡£¡£11ÔÂ12ÈոöñÒâ»î¶¯²þâ±ì­Éý £¬£¬·¸·¨·Ö×ÓÔÚ48СʱÄÚÐ®ÖÆÁËÁè¼Ý3ÒÚ¸öä¯ÀÀÆ÷»á»°¡£¡£¡£¡£¸Ã¶ñÒâ»î¶¯Í¨¹ýÕýµ±ÍøÕ¾ÉϵĶñÒâ¹ã¸æ½«Óû§Öض¨ÏòÖÁһϵÁеÄÔÝÊ±ÍøÕ¾ £¬£¬²¢ÏòÓû§ÍÆËͳÉÈËÍøÕ¾»òÀñÎ│Ö÷ÌâµÄÕ©Æ­»î¶¯¡£¡£¡£¡£Ñо¿Ö°Ô±½«¸Ã¶ñÒâ»î¶¯¹ØÁªÖÁ·¸·¨ÍÅ»ïScamClub¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/us-ios-users-targeted-by-massive-malvertising-campaign/


5¡¢¶íº¥¶íÖÝÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷ £¬£¬¼±ÕïЧÀͱ»ÆÈÖÐÖ¹

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¾ÝThe Times Leader±¨µÀ £¬£¬11ÔÂ23ÈÕÐÇÆÚÎåÍíÉ϶«¶íº¥¶íµØÇøÒ½ÔººÍ¶íº¥¶í¹ÈÒ½ÁÆÖÐÐĵÄÅÌËã»úϵͳÔâÀÕË÷Èí¼þ¹¥»÷ £¬£¬ÖÂʹҽԺµÄ¼±ÕïЧÀͱ»ÆÈÖÐÖ¹¡£¡£¡£¡£¸ÃµØÇøµÄ¼±Õï²½¶ÓÒѽ«²¡ÈË×ªÒÆÖÁÆäËüµØÇøµÄÒ½Ôº¡£¡£¡£¡£ºÃÐÂÎÅÊÇ £¬£¬Ã»Óл¼ÕßµÄÊý¾ÝÔڴ˴ι¥»÷ÊÂÎñÖÐй¶¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78441/breaking-news/ohio-hospital-system-ransomware.html


6¡¢UberÒò2016ÄêÊý¾Ýй¶±»ºÉÀ¼ºÍÓ¢¹ú·£¿£¿£¿£¿î120ÍòÃÀÔª

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ó¢¹úµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒÔ¼°ºÉÀ¼µÄÊý¾Ý±£»£»£»£»£»¤»ú¹¹Autoriteit Persoonsgegevens»®·ÖÒò2016Äê10ÔµÄÊý¾Ýй¶ÊÂÎñ¶ÔUber´¦ÒÔ38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿£¿£¿£¿î¡£¡£¡£¡£ICOÌåÏÖ¸ÃÊÂÎñÓ°ÏìÁËÓ¢¹úµÄ270ÍòUberÓû§ÒÔ¼°8.2Íò˾»ú¡£¡£¡£¡£ºÉÀ¼DPA³ÆÓÐ17.4ÍòºÉÀ¼¹«ÃñÊܵ½Ó°Ïì¡£¡£¡£¡£·£¿£¿£¿£¿îµÄÖ÷ÒªÔµ¹ÊÔ­ÓÉÊÇUberÑÓ³ÙÁ˽üÒ»Äê²Å±¨¸æ´Ë´Îй¶ÊÂÎñ £¬£¬ÕâÑÏÖØÎ¥·´ÁËÏà¹ØÖ´·¨ÌõÀý £¬£¬²¢ÇÒʹÊÜÓ°ÏìµÄÓû§ºÍ˾»úÃæÁÙ¸ü¸ßµÄڲƭΣº¦¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uber-fined-for-covering-up-2016-data-breach/



ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí