Choice Hotelsй¶70ÍòÌõ´î¿ÍÈëס¼Í¼£»£»£»£»£»£»¿¨°Í˹»ùɱÈí¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§
°ä²¼¹¦·ò 2019-08-16
°²È«×êÑÐÔ±Bob Diachenko·¢ÏÖÊôÓÚChoice HotelsµÄÒ»¸öMongoDBÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬70ÍòÌõ´î¿ÍÈëס¼Í¼¡£¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢Ô̺¬´î¿ÍµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¸üΪÔã¸âµÄÊÇ£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÀÕË÷µ¥¾Ý£¬£¬£¬£¬£¬¸Ãµ¥¾ÝÐû³ÆËùÓÐ70Íò±Ê¼Í¼Òѱ»ÇÔÈ¡²¢ÀÕË÷0.4¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼4000ÃÀÔª£©µÄÊê½ð¡£¡£¡£¡£¡£ÔÚÊý¾Ý¿â¶³öÁË4Ììºó£¬£¬£¬£¬£¬7ÔÂ2ÈÕChoice Hotels¹Ø¹ØÁ˶ÔÊý¾Ý¿âµÄ¹«¿ª½Ó¼û¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/700000-choice-hotels-records-leaked-in-data-breach/
2¡¢Adobe°ä²¼8Ô°²È«¸üУ¬£¬£¬£¬£¬½¨¸´119¸ö·ì϶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/adobe-releases-security-updates-for-reader-photoshop-and-more/
3¡¢Ç÷Ïò¿Æ¼¼½¨¸´ÆäÃÜÂëÖÎÀíÆ÷ÖеÄÌáȨ·ì϶
SafeBreach°²È«×êÑÐÔ±Peleg Hadar·¢ÏÖÇ÷Ïò¿Æ¼¼µÄÃÜÂëÖÎÀíÆ÷Èí¼þÖдæÔÚÒ»¸öÌáȨ·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-14684£©ÊÇÓÉÓÚÈí¼þÔÚ¼ÓÔØDLLʱ²»×ãÑéÖ¤»úÔìµ¼Öµģ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáȨÖÁSYSTEMȨÏÞ£¬£¬£¬£¬£¬ÔÚ¿ÉÐŹý³ÌÖмÓÔØ¶ñÒâDLL¡£¡£¡£¡£¡£ÕâͬÑùÓÐÀûÓÚ¹¥»÷ÕßÌӱܼì²â¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ç÷Ïò¿Æ¼¼»¹½ÓÊܵ½ÁíÒ»¸öÀàËÆµÄDLL½Ù³Ö·ì϶£¨CVE-2019-14687£©µÄ»ã±¨¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trend-micro-fixes-privilege-escalation-bug-in-password-manager/
4¡¢¿¨°Í˹»ùɱÈíÖеķì϶¿ÉÔÊÐí¿çÕ¾µã¸ú×ÙÓû§
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/kaspersky-antivirus-online-tracking.html
5¡¢Õë¶Ô°Í¶û¸ÉµÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬·Ö·¢BalkanDoorºÍBalkanRAT
ESET×êÑÐÈËÔ±·¢ÏÖÒ»¸öÕë¶Ô°Í¶û¸ÉµØÓòµÄй¥»÷»î¶¯£¬£¬£¬£¬£¬¹¥»÷ÕßÖØÒª·Ö·¢Ô¶¿ØºóÃÅBalkanDoorºÍľÂíBalkanRAT¡£¡£¡£¡£¡£ÕâЩ¶ñÒâpayloadÖØÒªÍ¨¹ý´¹µöÓʼþ½øÐзַ¢£¬£¬£¬£¬£¬ÓʼþµÄÖ÷ÌâÓë˰ÎñÓйأ¬£¬£¬£¬£¬ÆäÖÐÔ̺¬µö¶üPDFÒÔ¼°¶ñÒâÁ´½ÓµÈ¡£¡£¡£¡£¡£¹¥»÷ÕßÏÔÈ»ÖØÒª¶Ô×¼°Í¶û¸ÉµØÓòµÄ½ðÈÚ²¿ÃÅ£¬£¬£¬£¬£¬ÕâÒâζ×ÅËûÃǵÄÖØÒª¶¯»úÊÇ»ñµÃ½ðÇ®¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÖÁÉÙ´Ó2016Äê1ÔÂÆðÍ·£¬£¬£¬£¬£¬Ö±µ½½ñÌìÈÔÔÚ³ÖÐø½øÐÐÖÓ×£¡£¡£¡£¡£×êÑÐÈËÔ±Ôڻ㱨ÖзÖÎöÁËËûÃÇËùʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍÁ÷³Ì£¨TTP£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2019/08/14/balkans-businesses-double-barreled-weapon/
6¡¢¹È¸èÆÀ¹À³ÆÈ«Íø1.5%µÄµÇ¼ʹ´¦Òѱ»Ð¹Â¶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/google-estimates-15-percent-of-web-logins-exposed-in-data-breaches/


¾©¹«Íø°²±¸11010802024551ºÅ