ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ1ÖÜ

°ä²¼¹¦·ò 2019-01-07

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ31ÈÕÖÁ2019Äê1ÔÂ6ÈÕ¹²ÊÕ¼°²È«·ì϶37¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Acrobat/Reader CVE-2018-16011¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶£»£»£»£»£»£» £»D-Link DIR-818LW/DIR-860L soap.cgi OSºÅÁîÖ´Ðзì϶£»£»£»£»£»£» £»Apache NetBeans Proxy Auto-Configuration (PAC) interpretationÔ¶³ÌºÅÁîÖ´Ðзì϶£»£»£»£»£»£» £»Guardzilla GZ621W CVE-2018-18601»º³åÇøÒç¶Âí½Å£»£»£»£»£»£» £»Dell EMC RSA Archer½Ó¼û½ÚÔìÃýÎó·ì϶¡£¡£¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰÄÖÞÊý×Ö½¡È«Êð°ä²¼2017-2018Äê¶È»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Åû¶42ÆðÊý¾Ýй¶ÊÂÎñ£»£»£»£»£»£» £»ÃÀ¹úÎÀÉú²¿°ä²¼Ò½ÁÆÐÐÒµÍøÂ簲ȫʵ¼Ê»ã±¨£»£»£»£»£»£» £»Ô½Äϵ±¾Öͨ¹ýÐÂÍøÂ簲ȫ·¨£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíµ±¾Ö½Ó¼ûÓû§Êý¾Ý£»£»£»£»£»£» £»ÃÜÂëÖÎÀíÆ÷BlurÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬240ÍòÈËÊܵ½Ó°Ï죻£»£»£»£»£» £»°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸´ï³ÉºÍ½â£¬£¬£¬£¬£¬£¬£¬£¬Å⸶38.2ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1. Adobe Acrobat/Reader CVE-2018-16011¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶

Adobe Acrobat/Reader´¦ÖÃPDFÎļþ´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.auscert.org.au/bulletins/73738

2. D-Link DIR-818LW/DIR-860L soap.cgi OSºÅÁîÖ´Ðзì϶

D-Link DIR-818LW/DIR-860L soap.cgi´¦ÖÃService²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£¡£¡£
https://github.com/pr0v3rbs/CVE/tree/master/CVE-2018-20114

3. Apache NetBeans Proxy Auto-Configuration (PAC) interpretationÔ¶³ÌºÅÁîÖ´Ðзì϶
Apache NetBeans Proxy Auto-Configuration (PAC) interpretationʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/d1c37966a316a326ab4ff4d4bc056322e8adcbe984e8145c0ecda7fa@%3Cdev.netbeans.apache.org%3E

4. Guardzilla GZ621W CVE-2018-18601»º³åÇøÒç¶Âí½Å
Guardzilla GZ621W ¡®TK_set_deviceModel_req_handle¡¯º¯Êý´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£» £»òÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
https://labs.bitdefender.com/2018/12/iot-report-major-flaws-in-guardzilla-cameras-allow-remote-hijack-of-the-security-device/

5. Dell EMC RSA Archer½Ó¼û½ÚÔìÃýÎó·ì϶
Dell EMC RSA Archer´æÔÚ½Ó¼û½ÚÔìÃýÎó·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬£¬£¬¶ÁÈ¡ÊÜÏÞÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://seclists.org/fulldisclosure/2019/Jan/3


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°ÄÖÞÊý×Ö½¡È«Êð°ä²¼2017-2018Äê¶È»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Åû¶42ÆðÊý¾Ýй¶ÊÂÎñ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

°Ä´óÀûÑÇÊý×Ö½¡È«Êð£¨ADHA£©ÔÚÆä2017-2018Äê¶È»ã±¨ÖаµÊ¾£¬£¬£¬£¬£¬£¬£¬£¬My Health RecordϵͳÖеÄÒ½ÁƼͼÔÚ2017Äê7ÔÂ1ÈÕÖÁ2018Äê6ÔÂ30ÈÕÆÚ¼ä¹²²úÉú42ÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÆäÖдóÎÞÊýй¶ÊÂÎñÓëÒ½ÁƱ£ÏÕڲƭÓйأ¬£¬£¬£¬£¬£¬£¬£¬My Health Record²¢Î´Ôâµ½ÇÖº¦ÆäÆëÈ«ÐԺͰ²È«ÐԵĶñÒâ¹¥»÷¡£¡£¡£¡£¡£¡£¡£½ØÖÁ2018Äê7ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÓÐÔ¼ËÄ·ÖÖ®Ò»µÄ°Ä´óÀûÑÇÈËÔÚMy Health RecordϵͳÖгÉÁ¢ÁËÒ½ÁƼͼ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/my-health-record-had-42-data-breaches-in-2017-18-but-no-malicious-attacks-adha/



2¡¢ÃÀ¹úÎÀÉú²¿°ä²¼Ò½ÁÆÐÐÒµÍøÂ簲ȫʵ¼Ê»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úÎÀÉú²¿£¨HHS£©°ä²¼Ò»·ÝÕë¶ÔÒ½ÁÆÐÐÒµµÄÍøÂ簲ȫָÄÏ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã³ö°æÎïµÄÃû³ÆÎª¡¶Ò½ÁÆÐÐÒµÍøÂ簲ȫʵ¼Ê£ºÖÎÀíÍþв¼°±£»£»£»£»£»£» £»¤»¼Õß¡·¡£¡£¡£¡£¡£¡£¡£Õâ·Ý»ã±¨ÊÇHHS¼°Ò½ÁÆ×¨¼ÒÆÆ·ÑÁ½Ä깦·òµÄ¹¤×÷³É¾Í£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉ2015ÄêµÄÍøÂ簲ȫ·¨°¸ÊÚȨµÄ¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏ̽ÇóÁËÒ½ÁÆÐÐÒµÃæ¶ÔµÄÎå´óÓйØÍþв£¬£¬£¬£¬£¬£¬£¬£¬²¢½¨Òéѡȡ10ÖÖÍøÂ簲ȫ´ëÊ©À´»º½âÕâЩÍþв¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏ»¹Ç¿µ÷Á˼±¾çÓ¦¶ÔÕâЩÍþвµÄ³ÁÒªÐÔ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.nextgov.com/cybersecurity/2019/01/hhs-releases-voluntary-cybersecurity-practices-health-industry/153835/


3¡¢Ô½Äϵ±¾Öͨ¹ýÐÂÍøÂ簲ȫ·¨£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíµ±¾Ö½Ó¼ûÓû§Êý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾Ý·¨ÐÂÉç1ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Ô½ÄÏ´Óµ±ÌìÆðÍ·Ö´Ðм«ÎªÑϸñµÄÍøÂ簲ȫ·¨¡£¡£¡£¡£¡£¡£¡£¸ÃÂÉÀý¶¨£¬£¬£¬£¬£¬£¬£¬£¬»¥ÁªÍø¹«Ë¾±ØÐëɾ³ý±»µ±¾ÖÈ϶¨Îª¡°Óж¾¡±µÄÍøÉÏÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬£¬Ô½ÄÏÍøÃñÒ²²»µÃÔÚ»¥ÁªÍøÉÏÉ¢²¼·´µ±¾ÖÐÅÏ¢»òÇú½âº¹Çà¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Facebook¡¢GoogleµÈ¹ú¼Ê¿Æ¼¼¹«Ë¾ÒªÔÚÔ½ÄÏ·¢Õ¹ÒµÎñ±ØÐëÔÚÔ½ÄϹúÄÚÉèÁ¢´¦Ê´¦£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÔ½Äϵ±¾ÖÒªÇóʱ±ØÐ뽫Óû§Êý¾ÝÌá½»¸øµ±¾Ö¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/vietnams-new-cyber-law-threatens/


4¡¢ÃÜÂëÖÎÀíÆ÷BlurÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬240ÍòÈËÊܵ½Ó°Ïì

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖÜÒ»Abine¹«Ë¾°µÊ¾ÆäÃÜÂëÖÎÀíÆ÷²úÆ·BlurµÄÓû§Êý¾ÝÔÚ·þÎñÆ÷É϶³ö£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÔ̺¬2018Äê1ÔÂ6ÈÕ֮ǰע²áµÄBlurÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Èçµç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂëÌáÐÑÓï¡¢×îºóµÇ¼IPºÍ¼ÓÑÎÃÜÂë¹þÏ£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ç¿µ÷³ÆÓû§µÄÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢ºÍµç»°ºÅÂëûÓÐй¶¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËÔ¼240ÍòBlurÓû§¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/


5¡¢°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸´ï³ÉºÍ½â£¬£¬£¬£¬£¬£¬£¬£¬Å⸶38.2ÍòÃÀÔª

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°ÍÎ÷ÒøÐÐInter¾Í2018ÄêÔçЩʱ³½µÄ½üÁ½ÍòÓû§Êý¾Ýй¶°¸¼þ´ï³ÉºÍ½â£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾Ý°ÍÎ÷¼ì²ì¹Ù°ì¹«ÊÒ£¨PPO£©°ä²¼µÄÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÒøÐн«Ö§¸¶150ÍòÀ×ÑǶû£¨Ô¼ºÏ38.2ÍòÃÀÔª£©µÄÅâ³¥½ð¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸ÃÊÂÎñµ÷²éίԱ»á¼ì²ì¹ÙFrederick MeinbergµÄÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬InterÔøÊÔͼ¸²¸ÇÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Õâ¸ø¿Í»§¡¢¹É¶«ºÍͶ×ÊÕß´øÀ´Á˸ü´óµÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/brazilian-bank-inter-pays-fine-over-customer-data-leak/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù