¸ßͨоƬQualPwnÎó²î£»£»£»£»GoogleºÍNASAÒòJiraЧÀÍÆ÷ÉèÖùýʧµ¼ÖÂÃô¸ÐÊý¾Ýй¶

Ðû²¼Ê±¼ä 2019-08-06
1¡¢Ñо¿ÍŶÓÐû²¼Sextortionڲƭ»î¶¯±¨¸æ£¬£¬£¬£¬£¬£¬Áè¼Ý2ÒÚÓʼþÕË»§³ÉΪĿµÄ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Cofense LabsÔÚ6Ô·ݷ¢Ã÷Ò»¸öÖ÷Òª·Ö·¢sextortionڲƭÓʼþµÄ½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂçûÓÐÊÔͼ´ÓÊÜѬȾµÄÅÌËã»úÖÐÇÔȡеÄÊý¾Ý¼¯£¬£¬£¬£¬£¬£¬¶øÊÇÖØ¸´Ê¹ÓÃ֮ǰй¶µÄÊý¾Ý¼¯¡£¡£¡£ ¡£ÕâЩÊý¾Ý¼¯×îÔç¿É×·ËÝÖÁ10Äêǰ£¬£¬£¬£¬£¬£¬Æ¾Ö¤Ñо¿Ö°Ô±Ðû²¼µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬¹²ÓÐÁè¼Ý2ÒÚ¸öµç×ÓÓʼþÕË»§³ÉΪ¸Ã½©Ê¬ÍøÂçµÄ¹¥»÷Ä¿µÄ¡£¡£¡£ ¡£Cofense»¹ÆÀ¹À³Æ½ñÄêsextortion»î¶¯µÄ±ÈÌØ±ÒÇ®°üÒѾ­ÎüÊÕµ½ÁËÁè¼Ý150ÍòÃÀÔªµÄ¸¶¿î¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://cofense.com/cofense-labs-publishes-database-200-million-compromised-accounts-targeted-sextortion-email-campaigns/


2¡¢CafePressÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬Áè¼Ý2300ÍòÓû§µÄÐÅϢй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Êý¾ÝÐ¹Â¶Í¨ÖªÍøÕ¾HIBP³ÆCafePressÓÚ2019Äê2ÔÂÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Áè¼Ý2300ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£ ¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨µç×ÓÓʼþµØµã¡¢ÐÕÃû¡¢ÃÜÂë¡¢µç»°ºÅÂëÒÔ¼°×¡Ö·¡£¡£¡£ ¡£Æ¾Ö¤Çå¾²Ñо¿Ô±Jim ScottµÄ±íÊö£¬£¬£¬£¬£¬£¬½üÒ»°ëµÄÓû§ÃÜÂëÊÇͨ¹ýbase64 SHA1±àÂëµÄ£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸ö½ÏÈõµÄ¼ÓÃÜËã·¨£¬£¬£¬£¬£¬£¬ÁíÒ»°ëÓû§ÔòÊÇͨ¹ýFacebookºÍÑÇÂíÑ·Æ·¼¶Èý·½ÁîÅÆ¾ÙÐеǼ¡£¡£¡£ ¡£BleepingComputer·¢Ã÷Ô¼49.3Íò¸öCafePressÕË»§Êý¾ÝÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúËüÃÇÊÇ·ñÓëͳһÊÂÎñÓйØ¡£¡£¡£ ¡£×èÖ¹ÏÖÔÚCafePressÉÐδÐû²¼ÈκÎÉùÃ÷»ò֪ͨ£¬£¬£¬£¬£¬£¬µ«Óû§ÔڵǼʱ±»Ç¿ÖÆÒªÇóÖØÖÃÃÜÂë¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.forbes.com/sites/daveywinder/2019/08/05/cafepress-hacked-23m-accounts-compromised-is-yours-one-of-them/#1c5b34a7407e


3¡¢PresbyterianÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬½ü18.3Íò»¼ÕßÐÅϢй¶

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


PresbyterianÒ½ÁÆÐ§ÀÍÖÐÐÄÔÚÆä²¿·ÖÔ±¹¤Êܵ½´¹ÂÚ¹¥»÷ºóÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬Æ¾Ö¤¸ÃÒ½ÁÆÖÐÐÄÐû²¼µÄͨ¸æ£¬£¬£¬£¬£¬£¬¹²Óнü18.3Íò»¼ÕßµÄÐÅϢй¶£¬£¬£¬£¬£¬£¬°üÀ¨ËûÃǵÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂëÒÔ¼°ÁÙ´²ÐÅÏ¢µÈ¡£¡£¡£ ¡£¸ÃÊÂÎñ±¬·¢ÔÚ5ÔÂ9ÈÕ×óÓÒ£¬£¬£¬£¬£¬£¬PresbyterianÓÚ6ÔÂ6ÈÕ¼ì²âµ½ÁËÕâÒ»ÊÂÎñ¡£¡£¡£ ¡£¸ÃÒ½ÁÆÖÐÐÄËæ¼´Í¨ÖªÁËÁª°îÖ´·¨²¿·Ö²¢Õö¿ª½øÒ»²½µÄÊӲ졣¡£¡£ ¡£ÎªÁ˱ÜÃâ´ËÀàÊÂÎñÔٴα¬·¢£¬£¬£¬£¬£¬£¬Presbyterian½ÓÄÉÁׯü¶àÇå¾²²½·¥±£»£»£»£»¤ÆäÓʼþϵͳ£¬£¬£¬£¬£¬£¬²¢¶ÔÔ±¹¤¾ÙÐÐÇ¿ÖÆÐÔÇå¾²Åàѵ¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.phs.org/Pages/data-security.aspx


4¡¢Aegon Life¹ÙÍø±£´æÎó²î£¬£¬£¬£¬£¬£¬µ¼ÖÂ1ÍòÃû¿Í»§µÄÒþ˽й¶

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ó¡¶È°ü¹Ü¹«Ë¾Aegon Life¹ÙÍø±£´æÎó²î£¬£¬£¬£¬£¬£¬µ¼ÖÂ×î¶à1ÍòÃû¿Í»§µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÄÜй¶¡£¡£¡£ ¡£ÕâЩÊý¾Ý°üÀ¨ÐÕÃû¡¢ÄêËê¡¢ÐÔ±ð¡¢ÊÖ»úºÅÂëÒÔ¼°ÄêÊÕÈë¡¢¿µ½¡Õ½ÂÔµÈÐÅÏ¢¡£¡£¡£ ¡£¸ÃÎó²îÊ®·Ö¼òÆÓ£¬£¬£¬£¬£¬£¬µ±Óû§µÇ¼Aegon Life¹ÙÍøÊ±£¬£¬£¬£¬£¬£¬ÆäÌîÈëµÄСÎÒ˽¼ÒÉí·ÝÐÅÏ¢²¢Ã»ÓлñµÃ³ä·Ö±£»£»£»£»¤£¬£¬£¬£¬£¬£¬ÀýÈçÓû§ÔÚÁªÏµ±í¸ñ¡¢ÖÖÖÖ°ü¹Ü¼Æ»®ÅÌË㹤¾ßÖÐÌîÈëµÄÐÅÏ¢¡£¡£¡£ ¡£ÔÚ7ÔÂÖÐÑ®½Óµ½Îó²î±¨¸æºó£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѾ­ÐÞ¸´ÁËÎó²î¡£¡£¡£ ¡£ÏÖÔÚÉв»ÇåÎúÊÇ·ñÓÐÈκοͻ§Êý¾ÝÔâµ½ÀÄÓᣡ£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thewire.in/tech/aegon-life-insurance-data-leak


5¡¢GoogleºÍNASAÒòJiraЧÀÍÆ÷ÉèÖùýʧµ¼ÖÂÃô¸ÐÊý¾Ýй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


JiraÊÇÒ»¸öÊ¢ÐеÄÏîÄ¿ÖÎÃ÷È·¾ö¼Æ»®£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ô±Avinash Jain·¢Ã÷µ±ÔÚJira CloudÖн¨ÉèеÄfilterºÍdashboardʱ£¬£¬£¬£¬£¬£¬ÆäĬÈϿɼûÐÔÊÇ¡°ËùÓС±£¬£¬£¬£¬£¬£¬ÕâºÜÈÝÒ×±»Ã÷ȷΪ¡°ÆóÒµÄÚ²¿ËùÓÐÈË¡±µ«ÏÖʵÉÏËüÖ¸µÄÊÇ¡°»¥ÁªÍøÉϵÄËùÓÐÈË¡±¡£¡£¡£ ¡£ÕâÖÖÉèÖùýʧʹµÃÐí¶à×éÖ¯µÄÃô¸ÐÏîÄ¿ÐÅÏ¢ÆØ¹â£¬£¬£¬£¬£¬£¬°üÀ¨Google¡¢Yahoo¡¢NASA¡¢Lenovo¡¢1Password¡¢ZendeskÒÔ¼°Õþ¸®»ú¹¹µÈ¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/misconfigured-jira-servers-leak-info-on-users-and-projects/


6¡¢¸ßͨоƬ±£´æQualPwnÎó²î£¬£¬£¬£¬£¬£¬²¨¼°æçÁú855µÈ¶à¿îSoC

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¸ßͨ¶à¿îSoCÊܵ½Á½¸öÎó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬ÕâÁ½¸öÎó²î±»³ÆÎªQualPwn£¬£¬£¬£¬£¬£¬»®·ÖÊÇÓ°Ïì¸ßͨWLAN×é¼þ¼°AndroidÄں˵Ļº³åÇøÒç³öÎó²î£¨CVE-2019-10538£©ÒÔ¼°¸ßͨWLAN¼°Modem¹Ì¼þÖеĻº³åÇøÒç³öÎó²î£¨CVE-2019-10540£©¡£¡£¡£ ¡£Æ¾Ö¤¸ßͨÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ºóÕßÓ°ÏìµÄ²úÆ·°üÀ¨SD 820¡¢SD 835¡¢SD 845¡¢SD 850¡¢SD 855µÈ20¶à¿îоƬ¡£¡£¡£ ¡£¸ßͨºÍAndroidÍŶÓÒѾ­Ðû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/qualpwn-vulnerabilities-in-qualcomm-chips-let-hackers-compromise-android-devices/