΢Èí°ä²¼11Ô°²È«¸üУ¬£¬£¬£¬£¬½¨¸´74¸ö·ì϶£»£»£»£»£»£»£»£»Î¢Èí½«¼ÓÖÝÏû·ÑÕßÒþÖÔ·¨°¸À©´óÖÁÃÀ¹úËùÓÐЧ»§
°ä²¼¹¦·ò 2019-11-131¡¢Î¢Èí°ä²¼11Ô°²È«¸üУ¬£¬£¬£¬£¬½¨¸´74¸ö·ì϶
΢ÈíÔÚ11ÔµÄWindows°²È«¸üÐÂÖн¨¸´ÁË74¸ö·ì϶£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬IE¾ç±¾ÒýÇæÖеÄÒ»¸ö0day¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇCVE-2019-1429£¬£¬£¬£¬£¬ÓëIE¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½Óйأ¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬¸Ã·ì϶²»½öÓ°ÏìÁËIEä¯ÀÀÆ÷£¬£¬£¬£¬£¬»¹Ó°ÏìÁËOffice Suite¡£¡£¡£¡£¡£ÈôÊÇÓû§ÔÊÐíÏÔʾ¸»Îı¾£¨ÀýÈç»ùÓÚWebµÄiframe£©£¬£¬£¬£¬£¬Ôò¹¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâOfficeÎĵµÔÚÓû§µÄϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¸Ã·ì϶ÒÑÔÚÒ°±í±»¹¥»÷ÕßÀûÓᣡ£¡£¡£¡£¸ü¶à·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsofts-november-2019-patch-tuesday-arrives-with-a-patch-for-an-ie-zero-day/
2¡¢MagentoÍŶӶ½´ÙÓû§×°ÖýüÆÚRCE·ì϶²¹¶¡
Magento°²È«ÍŶӶ½´ÙÓû§¾¡¿ì×°ÖÃÆä×îа䲼µÄ°²È«¸üУ¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»£»£»¤ÆäÉ̵êÃâÊÜ×î½ü»ã±¨µÄRCE·ì϶£¨CVE-2019-8144£©µÄ¹¥»÷¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚÍøÕ¾ÉÏÖ²Èë¶ñÒâpayload²¢Ö´ÐУ¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁMagento 2.3.3°æ±¾»ò×°ÖÃMagento 2.3.2-p2²¹¶¡¡£¡£¡£¡£¡£ÓÉÓÚ»ùÓÚMagentoµÄÔÚÏßÉ̵êÒ»ÏòÊÇ·¸×ïÍÅ»ïMagecartµÄ¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬Òò¶øÎ´ÊµÊ±×°ÖøüеÄÍøÕ¾·çÏպܴ󡣡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/magento-urges-users-to-apply-security-update-for-rce-bug/
3¡¢Î¢Èí½«¼ÓÖÝÏû·ÑÕßÒþÖÔ·¨°¸À©´óÖÁÃÀ¹úËùÓÐЧ»§
΢ÈíÔÚ½«¼ÓÖÝÏû·ÑÕßÒþÖÔ·¨°¸À©´óµ½ÆäÔÚÃÀ¹úµÄËùÓÐЧ»§£¬£¬£¬£¬£¬ÕâÊÇÒ»Ïî³öºõÒâÁϵÄÐÐΪ£¬£¬£¬£¬£¬ÏÔʾ³ö¸Ã¹«Ë¾ÔÚ±£»£»£»£»£»£»£»£»¤Ïû·ÑÕßÊý¾ÝÒþÖÔ·½ÃæµÄ¿ÌÒâºÍÁ¦¶È¡£¡£¡£¡£¡£¼ÓÖÝÏû·ÑÕßÒþÖÔ·¨°¸£¨CCPA£©´òËãÓÚ2020Äê1ÔÂ1ÈÕÉúЧ£¬£¬£¬£¬£¬¸Ã·¨°¸Ö¼ÔÚ±£»£»£»£»£»£»£»£»¤Ïû·ÑÕßµÄÒþÖÔ£¬£¬£¬£¬£¬ÒªÇó¹«Ë¾ÔÚʹÓúʹ«²¼Óû§Êý¾Ý·½ÃæÌṩ¸ü¶àµÄͨÃ÷¶È²¢´ÍÓëÏû·ÑÕßÍ˳öÑ¡ÔñȨ¡£¡£¡£¡£¡£Î¢ÈíÊ×ϯÒþÖÔ¹ÙÖìÀò?²¼Àï¶û£¨Julie Brill£©¿ä½±Á˸ÃÏî˾·¨£¬£¬£¬£¬£¬²¢°µÊ¾¹ÌÈ»CCPAµÄϸ½ÚÒÔ¼°¹«Ë¾ÈôºÎ×ñÊØ¸Ã˾·¨µÄ·½Ê½ÈÔÔÚ»áÉÌÖУ¬£¬£¬£¬£¬µ«Î¢Èí½«ÔÚÕâЩÕþ²ßÉÏά³Ö×îУ¬£¬£¬£¬£¬²¢È·±£ÔÚËùÓÐЧ»§·½Ãæ¶¼×ñÊØÕâЩÕþ²ß¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/microsoft-to-apply-californias-privacy-law-to-all-u-s-users/150101/
4¡¢Ä«Î÷¸çʯÓ͹«Ë¾PemexÔâÀÕË÷Èí¼þRyuk¹¥»÷
Ä«Î÷¸ç¹úÓÐʯÓ͹«Ë¾PemexÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾ÒѾ³É¹¦×èÖ¹Á˹¥»÷³¢ÊÔ£¬£¬£¬£¬£¬¸Ã¹¥»÷½öÓ°ÏìÁ˲»µ½5%µÄϵͳ£¬£¬£¬£¬£¬Ô̺¬Ê¯Óͳö²úºÍÖü´æÔÚÄÚµÄÒµÎñ²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¾ÝÅí²©É籨·£¬£¬£¬£¬£¬ÓÉÓÚÒâ±íµÄ¹Ø¹ØÊÂÎñ£¬£¬£¬£¬£¬ÖÜÄ©PemexÒªÇóºÜ¶àÔ±¹¤²»Òª³¢ÊÔ½Ó¼û¹«Ë¾ÍøÂç»òITϵͳ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ä¿Ç°ÉÐδÅû¶¸ü¶à¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/mexicos-pemex-oil-provider-says-attempted-ransomware-hack-neutralized/
5¡¢°®¶ûÀ¼Á½¼Ò¹«Ë¾ÒòBECÚ²ÆËðʧ65ÍòÅ·Ôª
°®¶ûÀ¼ÖÐÓׯóҵлᣨISME£©Í¨Öª³ÆÁ½¼Ò¹«Ë¾Ôâµ½BECڲƣ¬£¬£¬£¬£¬ÆäÖÐÒ»¼Ò¹«Ë¾Ëðʧ20ÍòÅ·Ôª£¬£¬£¬£¬£¬ÁíÒ»¼ÒËðʧÁË45.3ÍòÅ·Ôª¡£¡£¡£¡£¡£¸ÃлáûÓÐй©¹«Ë¾µÄÃû³Æ£¬£¬£¬£¬£¬µ«ËüÃǶ¼½Ó¹Üµ½ÁËÚ²ÆÐԵĵç×ÓÓʼþ£¬£¬£¬£¬£¬ÒªÇó½«ÒѼͼµÄ¹©¸øÉÌÒøÐÐÕÊ»§ÐÅÏ¢¸ü¸ÄΪÓÉ·¸×ï·Ö×Ó½ÚÔìµÄÐÂÒøÐÐÕÊ»§¡£¡£¡£¡£¡£°²È«×¨¼ÒDavid Waldron°µÊ¾·¢Æ±³Á¶¨ÏòȦÌ׺ÍÉæ¼°µÄ½ð¶î¡°×î½üÒÑ´ó´óÔö³¤¡±¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÈëÇÖ¹©¸øÉ̵ĵç×ÓÓʼþϵͳ£¬£¬£¬£¬£¬Ê¹Æä¿´ÆðÀ´Ô½·¢ºÏ·¨ÓÐЧ¡£¡£¡£¡£¡£ÕâÖÔìÛÕ©ÐÐΪ¶ÔÖÐÓׯóÒµµÄÓ°Ïì¡°¿ÉÄÜÊÇ¿àÄÑÐԵġ±¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.irishtimes.com/news/ireland/irish-news/warning-as-irish-firms-lose-millions-in-sophisticated-invoice-scams-1.4079003
6¡¢Ó¢¹ú¹¤µ³³ÆÆäÊý×Ôì½Ì¨Ôâµ½´ó¹æÄ£ÍøÂç¹¥»÷
Ó¢¹ú¹¤µ³°µÊ¾ÆäÊý×Ôì½Ì¨Ôâµ½¡°¸´ÔÓ¡±ºÍ¡°´ó¹æÄ£¡±µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£Æ¾¾Ý¡¶Sky News¡·µÄ±¨Â·£¬£¬£¬£¬£¬¸Ãµ³½²»°È˳ƹ¥»÷δÄÜ·ÛËéÈκÎÊý¾Ý£¬£¬£¬£¬£¬ÓйØÏµÍ³ÒѾ¸´ÔÁËÕý³£ÔË×÷¡£¡£¡£¡£¡£¸Ãµ³ÒѾ½«´ËÊ»㱨¸øÓ¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ¡£¡£¡£¡£¡£¾Ý³Æ¸Ã¹¥»÷ÊÇDDoS¹¥»÷£¬£¬£¬£¬£¬Ã»Óм£Ïó¿ÉÄÜÅú×¢ÕâÖÖ¹¥»÷À´×Ժη½¡£¡£¡£¡£¡£Tripwire°²È«×¨¼ÒDean Ferrando°µÊ¾ÕþÖÎ×éÖ¯Ó¦¸ÃÔÚÑ¡¾ÙÕâ¸öÃô¸ÐµÄʱÆÚÓÈΪ°ÑÎÈÆäϵͳµÄ°²È«´ëÊ©ºÍ²¹¶¡·¨Ê½¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/uk-labour-party-cyberattack/


¾©¹«Íø°²±¸11010802024551ºÅ