¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180626

Ðû²¼Ê±¼ä 2018-06-26

¡¾ÍþвÇ鱨¡¿Ó¢¹ú˰Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÍøÂçÔ¼510ÍòÓû§µÄÓïÒô¼Í¼


Òþ˽±£»¤×éÖ¯Big Brother Watch·¢Ã÷Ó¢¹úµÄ˰Îñ»ú¹ØHMRCÉæÏÓÎ¥·¨ÍøÂçÔ¼510ÍòÓ¢¹ú¹«ÃñµÄÓïÒô¼Í¼¡£HMRCͨ¹ý2017Äê1ÔÂÍÆ³öµÄÒ»ÏîÓïÒôʶ±ð·þÎñÍøÂçÁËÕâЩ¼Í¼£¬¸Ã·þÎñÔÊÐíÓû§ÔÚºô½ÐHMRCʱͨ¹ýÓïÒô¾ÙÐÐÉí·ÝÑéÖ¤¡£µ«Big Brother Watch·¢Ã÷Óû§ÎÞ·¨Ñ¡Ôñ²»Ê¹Óø÷þÎñ£¬ËùÓв¦´òHMRCÈÈÏßµÄÓû§¶¼±»ÆÈÂ¼ÖÆÁËÓïÒô¼Í¼£¬²¢ÇÒÓû§ÎÞ·¨Ñ¡Ôñ´ÓHMRCµÄÊý¾Ý¿âÖÐɾ³ýÆäÓïÒô¼Í¼¡£¸Ã×éÖ¯ÒÔΪHMRC´Ë¾ÙÏÔ×ÅÎ¥·´ÁËGDPR£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒѶԴËÊÂÕö¿ªÕýʽµÄÊӲ졣

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/uk-tax-agency-recorded-the-voices-of-51-million-brits/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶ÔÒâ´óÀûµÄÒøÐÐľÂíUrsnifµÄбäÖÖ


CSE Cybsec ZLabÑо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶ÔÒâ´óÀû¹«Ë¾µÄÒøÐÐľÂíUrsnifµÄбäÖÖ¡£UrsnifÄܹ»ÇÔÈ¡Óû§µÄƾ֤£¬°üÀ¨Óû§µÄµç×ÓÓÊÏäÕË»§¡¢ÔÆ´æ´¢¡¢¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨ÒÔ¼°µç×ÓÉÌÎñÍøÕ¾µÈµÄƾ֤¡£´Ó6ÔÂ6ÈÕ×îÏÈ£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃбäÖֵĹ¥»÷Ô˶¯£¬²¢½«´Ë´Î¹¥»÷Ô˶¯Óë½©Ê¬ÍøÂçNecurs¾ÙÐйØÁª¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÅû¶ÁËÏêϸµÄÏà¹ØIoCºÍYara¹æÔò¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73865/malware/ursnif-banking-hits-italy.html


¡¾Îó²î²¹¶¡¡¿ÂÞ¿ËΤ¶û×Ô¶¯»¯ÐÞ¸´Æä²úÆ·ÖеĿɵ¼ÖÂDoSµÄÇå¾²Îó²î


ÂÞ¿ËΤ¶û×Ô¶¯»¯ÐÞ¸´Ò»¸ö¿Éµ¼ÖÂDoSµÄÇå¾²Îó²î£¬¸ÃÎó²î£¨CVE-2017-9312£©Ó°ÏìÁËAllen-Bradley CompactLogix 5370ºÍCompact GuardLogix 5370¿É±à³Ì×Ô¶¯»¯¿ØÖÆÆ÷£¬ÕâЩ²úÆ·±»ÆÕ±éÓÃÓÚÒªº¦»ù´¡ÉèÊ©¡¢¹©Ë®ÏµÍ³¡¢ÓéÀÖ¡¢Æû³µ¡¢Ê³ÎïºÍÒûÁϵÈÐÐÒµµÄ¿ØÖÆÁ÷³ÌÖС£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²î´¥·¢×°±¸µÄ²»¿É»Ö¸´¹ÊÕÏģʽ£¨MNRF£©£¬´Ó¶øµ¼ÖÂDoS¡£ÂÞ¿ËΤ¶ûÔڹ̼þ°æ±¾31.011ÖÐÐÞ¸´Á˸ÃÎó²î£¬½¨ÒéÓû§¾¡¿ì¸üС£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/rockwell-patches-flaw-affecting-safety-controllers-several-vendors


¡¾Îó²î²¹¶¡¡¿OracleÐÞ¸´×î½üÅû¶µÄSpectreºÍMeltdownÎó²îµÄбäÌå

ÉÏÖÜÎåOracleÐû²¼Æä×îÏÈÐû²¼²úÆ·µÄÈí¼þºÍ΢´úÂë¸üУ¬ÒÔÐÞ¸´×î½üÅû¶µÄSpectreºÍMeltdownÎó²îµÄбäÌå¡£ÕâЩбäÌå°üÀ¨Variant 4£¨CVE-2018-3639£©ÒÔ¼°Variant 3a£¨CVE-2018-3640£©µÈ¡£OracleÇå¾²Ö÷¹ÜEric Maurice³ÆOracleÒѾ­Õë¶ÔOracle LinuxºÍOracle VMÐéÄ⻯²úÆ·Ðû²¼Á˸üУ¬¸ü¶à¸üкͲ¹¶¡½«ÔÚËæºóÂ½ÐøÐû²¼¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/oracle-patches-new-spectre-meltdown-vulnerabilities


¡¾Îó²î²¹¶¡¡¿TapplockÖÇÄÜËøÐû²¼Çå¾²¸üУ¬ÐÞ¸´¶à¸öÇå¾²Îó²î


Çå¾²Ñо¿Ö°Ô±Andrew TierneºÍVangelis Stykas·¢Ã÷TapplockÖÇÄÜËøÖеĶà¸öÇå¾²Îó²î£¬°üÀ¨ÆäAPPʹÓÃHTTP¾ÙÐÐͨѶ¶øÃ»ÓоÙÐд«Êä¼ÓÃÜ£»Ã»ÓÐʹÓÃÉí·ÝÑé֤ЭÒ飻ÔڵǼTapplockÕË»§ºó¿Éͨ¹ýÆäËûÓû§µÄÕË»§ID»á¼ûÆäÃô¸ÐÊý¾Ý£¬ÈçÓû§Í¨¹ýÀ¶ÑÀ½âËøÊ±µÄµØµãºÍÓû§µÄµç×ÓÓʼþµÈ¡£TapplockÐû²¼ÁËÏà¹ØµÄÇå¾²¸üУ¬²¢½¨ÒéÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/unbreakable-smart-lock-tapplock-issues-critical-security-patch/132918/


¡¾Õþ²ß¹æÔò¡¿¹«°²²¿Ä⽫ÓÚ±¾ÖÜÐû²¼¡¶ÍøÂçÇ徲Ʒ¼¶±£»¤ÌõÀý¡·


Óɹ«°²²¿Ç£Í·£¬»áͬÖÐÑëÍøÐŰ졢¹ú¼Ò±£Ãܾ֡¢¹ú¼ÒÃÜÂëÖÎÀí¾ÖÍŽáÖÆ¶©µÄ¡¶ÍøÂçÇ徲Ʒ¼¶±£»¤ÌõÀý¡·£¨ÒÔϼò³Æ¡°ÌõÀý¡±£©Ä⽫ÓÚ±¾ÖÜÔÚÍøÉÏÐû²¼¡£¹«°²²¿ÍøÂçÇå¾²ÊØÎÀ¾Ö×ܹ¤¹ùÆôÈ«ÔÚ½²»°ÖÐÌåÏÖ£¬Òªº¦ÐÅÏ¢»ù´¡ÉèÊ©±£»¤ÊÇÍøÂçÇ徲Ʒ¼¶±£»¤ÖƶÈ2.0µÄÖØµã¡£ÏÖÔÚÖÐÑëÍøÐŰìºÍ¹«°²²¿Ë«Ç£Í·Öƶ©µÄ¡¶Òªº¦ÐÅÏ¢»ù´¡ÉèÊ©±£»¤ÌõÀý¡·Æð²ÝÊÂÇéÒѾ­Íê³É£¬ÕýÔÚ×ß˾·¨³ÌÐò¡£

Ô­ÎÄÁ´½Ó£ºhttp://m.sohu.com/news/a/237626584_161795