¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180817
Ðû²¼Ê±¼ä 2018-08-17¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÇÔÈ¡Office 365ƾ֤µÄPhishPoint¹¥»÷Ô˶¯
ÔÆÇå¾²¹«Ë¾AvananµÄÑо¿Ö°Ô±·¢Ã÷Ö÷ÒªÓÃÓÚÇÔÈ¡Office 365Óû§Æ¾Ö¤µÄPhishPoint¹¥»÷Ô˶¯¡£PhishPointÊÇÒ»ÖÖеÄʹÓÃSharePointµÄÍøÂç´¹ÂÚ¹¥»÷£¬ÆäÔÚÒÑÍùÁ½ÖÜÄÚԼĪӰÏìÁË10%µÄOffice 365Óû§¡£¹¥»÷ÕßÔÚ´¹ÂÚÓʼþÖаüÀ¨Ò»¸öSharePointÎĵµµÄÁ´½Ó£¬¶ø¸ÃSharePointÎĵµÉϵĻá¼ûÎĵµ°´Å¥ÏÖʵÉÏÊǽ«Óû§Öض¨ÏòÖÁ´¹ÂÚÍøÒ³µÄ³¬Á´½Ó¡£ÕâÖÖ¹¥»÷¿ÉÒÔÈÆ¹ýOffice 365µÄ¸ß¼¶Íþв·À»¤£¨ATP£©»úÖÆ¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/microsoft-office365-phishing.html
¡¾ÍþвÇ鱨¡¿Firefox²å¼þWeb SecurityÍøÂçÓû§µÄÊý¾Ý£¬Áè¼Ý22ÍòÓû§ÊÜÓ°Ïì
Ñо¿Ö°Ô±·¢Ã÷Ê¢ÐеÄFirefox²å¼þWeb SecurityÕýÔÚÉñÃØµØ¼ÍÈÎÃü»§µÄÀúÊ·ä¯ÀÀ¼Í¼£¬Õâ¿ÉÄÜÎ¥·´ÁËMozillaµÄ²å¼þ¿ª·¢Ö¸ÄÏ¡£¸Ã²å¼þÖ÷ÒªÓÃÓÚ×ÊÖúÓû§·À»¤¶ñÒâÈí¼þ¼°´¹ÂÚÍøÕ¾µÄÍþв£¬ÆäÏÂÔØ´ÎÊý´ï222746´Î¡£Ñо¿Ö°Ô±·¢Ã÷¹ØÓÚÓû§»á¼ûµÄÿһ¸öÍøÒ³£¬¸Ã²å¼þ¶¼½«Ïòhttp://136.243.163.73·¢ËÍÒ»¸öPOSTÇëÇ󣬯äÖмͼÁËÓû§»á¼ûµÄURLÒÔ¼°´ÓÄÄÒ»¸ö¾ÉURLÌø×ªµ½ÐÂURL¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/firefox-add-on-with-220-000-installs-caught-collecting-users-browsing-history/
¡¾¹¥»÷ÊÂÎñ¡¿InstagramÒÉÔâ¶íÂÞ˹ºÚ¿Í¹¥»÷£¬Êý°ÙÃûÓû§µÄÕË»§±»Ëø¶¨
InstagramÔâµ½ÁËÒÉËÆÀ´×Ô¶íÂÞ˹µÄºÚ¿Í¹¥»÷Ô˶¯µÄ¹¥»÷£¬ÒÑÍùÒ»ÖÜÄÚÊý°ÙÃûÓû§±»Ëø¶¨ÔÚËûÃǵÄÕË»§Ö®Í⡣ƾ֤Êܺ¦ÕßµÄ˵·¨£¬ËûÃǵÄÕË»§µÄÃû³Æ¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏͼƬ¡¢ÃÜÂë¡¢¹ØÁªµç×ÓÓʼþµØµãÉõÖÁ¹ØÁªµÄFacebookÕË»§¶¼±»¸ü¸Ä¡£ÏÖÔÚ»¹²»ÖªµÀ¹¥»÷Õß¼òÖ±Ç××Ô·Ý£¬µ«¹¥»÷ÕßʹÓÃÀ´×Ô¶íÂÞ˹µç×ÓÓʼþÌṩÉÌmail.ruµÄµç×ÓÓʼþµØµã£¬Õâ¿ÉÄÜÒâζÕßÊǶíÂÞ˹ºÚ¿ÍËùΪ£¬µ«Ò²ÓпÉÄÜÊǹ¥»÷ÕߵľÓÐÄÎ󵼡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/hack-instagram-accounts.html
¡¾Îó²î²¹¶¡¡¿SAPÐû²¼2018Äê8ÔÂÇå¾²¸üУ¬¹²ÐÞ¸´27¸öÎó²î
±¾ÖܶþSAPÐû²¼2018Äê8ÔµÄÇå¾²¸üУ¬ÆäÖаüÀ¨27¸öÎó²î²¹¶¡£¬µ«²¢²»°üÀ¨ÈκθßΣÎó²î¡£½ÏÑÏÖØµÄÎó²î°üÀ¨BusinessObjectsÖеÄSQL×¢ÈëÎó²î£¨CVE-2018-2447£©¡¢Business Intelligenceƽ̨ÖеĿɵ¼ÖÂí§ÒâÏÂÁîÖ´ÐеÄÎó²î£¨CVE-2015-5237£©ÒÔ¼°SAP SRM MDM Catalog ÖеÄȱÉÙÊÚȨ¼ì²éÎó²î£¨CVE-2018-2449£©¡£¹¥»÷Õß¿ÉʹÓÃÎó²î£¨CVE-2018-2449£©ÔÚûÓÐÊÚȨµÄÇéÐÎÏ»á¼û·þÎñ£¬Õâ¿ÉÄܵ¼ÖÂÐÅϢй¶»òÌáȨ¹¥»÷µÈ¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/sap-releases-august-2018-security-updates
¡¾Îó²î²¹¶¡¡¿LinuxÄں˿ª·¢ÍŶÓÐû²¼Çå¾²¸üУ¬ÐÞ¸´Á½¸öÒ×±»DDoS¹¥»÷ʹÓõÄÎó²î
ÕâÁ½¸öÎó²îÊÇSegmentSmack£¨CVE-2018-5390£©ºÍFragmentSmack£¨CVE-2018-5391£©£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâµÄTCPºÍIPÊý¾ÝÁ÷»®·ÖʹÓÃÕâÁ½¸öÎó²î£¬´¥·¢×ÊÔ´ºÄ¾¡£¨ÔöÌíCPUºÍRAMµÄʹÓ㩹¥»÷¡£ÕâÁ½¸öÎó²î¿ÉÒÔ±»Ô¶³ÌʹÓã¬ÕâÒâζ×ÅËüÃǺÜÊÇÊÊÊÊÓÃÓÚDoS»òDDoS¹¥»÷¡£Debian¡¢Red Hat¡¢UbuntuµÈÖ÷ÒªµÄLinux¿¯ÐаæÒÔ¼°Androidϵͳ¶¼ÒѾÐû²¼ÁËÏà¹Ø¸üС£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/linux/two-ddos-friendly-bugs-fixed-in-linux-kernel/
¡¾ÆÊÎö±¨¸æ¡¿Ñо¿ÍŶÓÐû²¼2017ÄêÆóÒµÐÅϢϵͳµÄÇå¾²ÆÀ¹À±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼ÁË2017ÄêÆóÒµÐÅϢϵͳµÄÇå¾²ÆÀ¹À±¨¸æ¡£2017Ä꣬¿¨°Í˹»ùʵÑéÊÒΪȫÇò¶à¸öÐÐÒµµÄ¹«Ë¾ÌṩÁËÊýÊ®¸öÍøÂçÇå¾²ÆÀ¹ÀÏîÄ¿£¬°üÀ¨Õþ¸®»ú¹¹¡¢½ðÈÚ»ú¹¹¡¢µçÐŹ«Ë¾¡¢IT¹«Ë¾¡¢ÖÆÔ칫˾ÒÔ¼°ÄÜÔ´¹«Ë¾µÈ¡£Õë¶ÔÿһÖÖÌṩµÄ·þÎñÀàÐÍ£¨Íâ²¿ÉøÍ¸²âÊÔ¡¢ÄÚ²¿ÉøÍ¸²âÊÔºÍwebÓ¦ÓÃÇå¾²ÆÀ¹À£©£¬ÌṩÁËÎó²î¼ì²âЧ¹ûºÍͳ¼ÆÊý¾Ý¡£ÔÚËùÓÐµÄÆÊÎö¹¤¾ßÖУ¬43%µÄÆóÒµÕë¶ÔÍⲿ¹¥»÷Õߵı£»¤ÆÀ¼¶ÎªµÍ»òºÜÊǵͣ¬93%µÄÆóÒµÕë¶ÔÄÚ²¿¹¥»÷Õߵı£»¤ÆÀ¼¶ÎªµÍ»òºÜÊǵ͡£
ÔÎÄÁ´½Ó£ºhttps://media.kasperskycontenthub.com/wpcontent/uploads/sites/43/2018/08/16093216/Security_assessment_of_corporate_information_systems_2017_ENG_web.pdf


¾©¹«Íø°²±¸11010802024551ºÅ