Choice Hotelsй¶70ÍòÌõÓοÍÈëס¼Í¼£»£»£»£»£»¿¨°Í˹»ùɱÈí¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§
Ðû²¼Ê±¼ä 2019-08-16
Çå¾²Ñо¿Ô±Bob Diachenko·¢Ã÷ÊôÓÚChoice HotelsµÄÒ»¸öMongoDBÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬ÆäÖаüÀ¨70ÍòÌõÓοÍÈëס¼Í¼¡£¡£¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨Óο͵ÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£¸üΪÔã¸âµÄÊÇ£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÀÕË÷Ʊ¾Ý£¬£¬£¬¸ÃƱ¾ÝÉù³ÆËùÓÐ70ÍòÌõ¼Í¼Òѱ»ÇÔÈ¡²¢ÀÕË÷0.4¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼4000ÃÀÔª£©µÄÊê½ð¡£¡£¡£¡£¡£¡£ÔÚÊý¾Ý¿â̻¶ÁË4Ììºó£¬£¬£¬7ÔÂ2ÈÕChoice Hotels¹Ø±ÕÁ˶ÔÊý¾Ý¿âµÄ¹ûÕæ»á¼û¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/700000-choice-hotels-records-leaked-in-data-breach/
2¡¢AdobeÐû²¼8ÔÂÇå¾²¸üУ¬£¬£¬ÐÞ¸´119¸öÎó²î
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/adobe-releases-security-updates-for-reader-photoshop-and-more/
3¡¢Ç÷ÊÆ¿Æ¼¼ÐÞ¸´ÆäÃÜÂëÖÎÀíÆ÷ÖеÄÌáȨÎó²î
SafeBreachÇå¾²Ñо¿Ô±Peleg Hadar·¢Ã÷Ç÷ÊÆ¿Æ¼¼µÄÃÜÂëÖÎÀíÆ÷Èí¼þÖб£´æÒ»¸öÌáȨÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-14684£©ÊÇÓÉÓÚÈí¼þÔÚ¼ÓÔØDLLʱȱ·¦ÑéÖ¤»úÖÆµ¼Öµģ¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÖÁSYSTEMȨÏÞ£¬£¬£¬ÔÚ¿ÉÐÅÀú³ÌÖмÓÔØ¶ñÒâDLL¡£¡£¡£¡£¡£¡£ÕâͬÑùÓÐÀûÓÚ¹¥»÷ÕßÌӱܼì²â¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬Ç÷ÊÆ¿Æ¼¼»¹½ÓÊܵ½ÁíÒ»¸öÀàËÆµÄDLLÐ®ÖÆÎó²î£¨CVE-2019-14687£©µÄ±¨¸æ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trend-micro-fixes-privilege-escalation-bug-in-password-manager/
4¡¢¿¨°Í˹»ùɱÈíÖеÄÎó²î¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/kaspersky-antivirus-online-tracking.html
5¡¢Õë¶Ô°Í¶û¸ÉµÄ¹¥»÷»î¶¯£¬£¬£¬·Ö·¢BalkanDoorºÍBalkanRAT
ESETÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶Ô°Í¶û¸ÉµØÇøµÄй¥»÷»î¶¯£¬£¬£¬¹¥»÷ÕßÖ÷Òª·Ö·¢Ô¶¿ØºóÃÅBalkanDoorºÍľÂíBalkanRAT¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâpayloadÖ÷Ҫͨ¹ý´¹ÂÚÓʼþ¾ÙÐзַ¢£¬£¬£¬ÓʼþµÄÖ÷ÌâÓë˰ÎñÓйأ¬£¬£¬ÆäÖаüÀ¨ÓÕ¶üPDFÒÔ¼°¶ñÒâÁ´½ÓµÈ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÏÔÈ»Ö÷ÒªÃé×¼°Í¶û¸ÉµØÇøµÄ½ðÈÚ²¿·Ö£¬£¬£¬ÕâÒâζ×ÅËûÃǵÄÖ÷ÒªÄîÍ·ÊÇ»ñµÃ¿î×Ó¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÖÁÉÙ´Ó2016Äê1ÔÂ×îÏÈ£¬£¬£¬Ö±µ½½ñÌìÈÔÔÚÒ»Á¬¾ÙÐÐÖС£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÆÊÎöÁËËûÃÇËùʹÓõÄÕ½ÂÔ¡¢ÊÖÒÕºÍÁ÷³Ì£¨TTP£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2019/08/14/balkans-businesses-double-barreled-weapon/
6¡¢¹È¸èÆÀ¹À³ÆÈ«Íø1.5%µÄµÇ¼ƾ֤Òѱ»Ð¹Â¶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/google-estimates-15-percent-of-web-logins-exposed-in-data-breaches/


¾©¹«Íø°²±¸11010802024551ºÅ