¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180629

Ðû²¼Ê±¼ä 2018-06-29

 ¡¾Êý¾Ýй¶¡¿TicketmasterÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ £¬Ô¼5%µÄÓû§µÄÊý¾Ýй¶


ƱÎñ¹«Ë¾TicketmasterÐû²¼ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬ £¬¸ÃÊÂÎñ±¬·¢ÔÚ6ÔÂ23ÈÕÐÇÆÚÁù£¬£¬£¬£¬£¬ £¬ÆäËùÓпͻ§µÄÔ¼5%ÊÜÓ°Ïì¡£¡£¡£Ticketmaster³Æ£¬£¬£¬£¬£¬ £¬°²ÅÅÔÚÆä²¿·Ö¹ú¼ÊÍøÕ¾ÉϵÄʵʱ̸Ìì´°¿ÚС²¿¼þInbenta±»·¢Ã÷ÓÃÓÚÏòÓû§·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬¸Ã¶ñÒâÈí¼þ»áÇÔÈ¡Óû§µÄÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢µÇ¼ƾ֤¡¢ÒøÐп¨ÐÅÏ¢µÈÊý¾Ý¡£¡£¡£Ö»Óв¿·Ö¹ú¼ÊÓû§ÊÜÓ°Ï죬£¬£¬£¬£¬ £¬±±ÃÀµØÇøµÄÓû§²»ÊÜÓ°Ïì¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ticketmaster-announces-data-breach-affecting-5-percent-of-all-users/


¡¾Êý¾Ýй¶¡¿FacebookµÚÈý·½Ó¦Óõ¼ÖÂÔ¼1.2ÒÚÓû§µÄÊý¾ÝÃæÁÙй¶Σº¦


Ñо¿Ö°Ô±Inti De Ceukelaire·¢Ã÷µÚÈý·½ÖÇÁ¦¾ºÈüÓ¦ÓÃNametests.comʹԼ1.2ÒÚFacebookÓû§µÄÊý¾ÝÃæÁÙй¶Σº¦¡£¡£¡£Ö»ÒªFacebookÓû§ÔÚNameTestsÍøÕ¾ÉÏ×¢²á£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾½«¿ÉÒÔ»ñÈ¡Óû§µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£µ«Ñо¿Ö°Ô±·¢Ã÷NameTestsÍøÕ¾¹ýʧµØ½«Æä¡°Access-Control-Allow-Origin¡±Õ½ÂÔÉèÖóÉͨÅä·û*£¬£¬£¬£¬£¬ £¬ÕâÔÊÐíÈκÎÍøÕ¾»á¼ûÆä×ÊÔ´£¬£¬£¬£¬£¬ £¬°üÀ¨ÕâЩÓû§µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£NameTestsÒѾ­ÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/facebook-users-data-leak.html


¡¾ÆÊÎö±¨¸æ¡¿Ñо¿»ú¹¹Ðû²¼¹ØÓÚSSDP·´Éä·Å´ó¹¥»÷µÄÇ÷ÊÆµÄÆÊÎö±¨¸æ


Arbor Networks·¢Ã÷Ò»ÖÖÐÂÀàÐ͵ÄSSDP·´Éä·Å´ó¹¥»÷£¬£¬£¬£¬£¬ £¬ÕâÖÖ¹¥»÷ʹÓ÷DZê×¼µÄ¶Ë¿Ú¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ £¬½ÓÈ뻥ÁªÍøµÄÔ¼500Íò¸öSSDPЧÀÍÆ÷ÖеĴó´ó¶¼¶¼´ÓÔÝʱ¶Ë¿Ú¾ÙÐÐÏìÓ¦£¬£¬£¬£¬£¬ £¬¶øÊ¹ÓÃÔÝʱ¶Ë¿ÚµÄSSDP¹¥»÷¿ÉÒÔÈÆ¹ý¶Ë¿Ú¹ýÂË·À»¤²½·¥¡£¡£¡£ÕâÖÖ¹¥»÷ÐÐΪÓ뿪Դ¿âlibupnpÓйØ£¬£¬£¬£¬£¬ £¬¸Ã¿â±»ÓÃÓÚÖÖÖÖCPE×°±¸¡£¡£¡£ÕâÖÖ¹¥»÷»á±¬·¢¾ßÓÐÔÝʱԴ¶Ë¿ÚºÍÄ¿µÄ¶Ë¿ÚµÄUDPÊý¾Ý°ü£¬£¬£¬£¬£¬ £¬ÕâʹµÃ·À»¤Ô½·¢ÄÑÌâ¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://asert.arbornetworks.com/a-new-twist-in-ssdp-attacks/


¡¾¹¥»÷ÊÂÎñ¡¿ProtonMailÔâDDoS¹¥»÷£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒÉΪ¶íÂÞ˹ºÚ¿ÍÍÅ»ï


±¾ÖÜÈýProtonMailÔâµ½ÒÉËÆ¶íÂÞ˹ºÚ¿ÍÍÅ»ïµÄDDoS¹¥»÷£¬£¬£¬£¬£¬ £¬¹¥»÷Ò»Á¬Á˼¸¸öСʱ£¬£¬£¬£¬£¬ £¬×µÄÖÐֹʱ¼äΪ10·ÖÖÓ¡£¡£¡£ProtonMail³ÆÖ»¹ÜËüÌìÌì¶¼»áÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬ £¬µ«Õâ´Î¹¥»÷¸üΪÑÏÖØ£¬£¬£¬£¬£¬ £¬Æä·åÖµÁ÷Á¿´ï500Gbps£¬£¬£¬£¬£¬ £¬ÊÇÓмͼµÄ×î´óDDoS¹¥»÷Ö®Ò»¡£¡£¡£ProtonMailÌåÏÖËäÈ»Óû§µÄµç×ÓÓʼþ»áÑÓ³Ù£¬£¬£¬£¬£¬ £¬µ«²¢Î´µ¼ÖÂÓʼþɥʧ¡£¡£¡£ÆäЧÀÍÔÚÔ¼Èý¸öСʱºó»Ö¸´ÁËÕý³£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/significant-ddos-attack-protonmail-blamed-russia-linked-group


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆÕë¶ÔSpectreÎó²îµÄä¯ÀÀÆ÷²¹¶¡¿ÉÄܱ»Èƹý


ƾ֤±¾ÖܶþAleph SecurityÐû²¼µÄÑо¿£¬£¬£¬£¬£¬ £¬ÆäÑо¿Ö°Ô±¿ÉÈÆ¹ýSpectreÎó²îµÄä¯ÀÀÆ÷²¹¶¡£¬£¬£¬£¬£¬ £¬´ÓÄÚ´æÖмìË÷Óû§µÄÃô¸ÐÊý¾Ý¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖÆäPoCÔÚEdge¡¢ChromeºÍSafariµÈä¯ÀÀÆ÷É϶¼¿ÉÊÂÇ飬£¬£¬£¬£¬ £¬µ«¶ÔFirefoxÎÞЧ£¬£¬£¬£¬£¬ £¬ÓÉÓÚMozillaʹÓÃÁ˲î±ðµÄÐÞ²¹·½·¨¡£¡£¡£¸ÃPoCÄܹ»ÒÔºÜÊǵ͵ÄËÙÂÊй¶Êý¾Ý£¬£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±Ö÷Ҫ̽ÌÖÁËSpectreÎó²îµÄä¯ÀÀÆ÷²¹¶¡µÄÓÐÓÃÐÔ¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/some-spectre-in-browser-mitigations-can-be-defeated/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃNSAºÚ¿Í¹¤¾ßDoublePulsarÈëÇÖǶÈëʽWindowsϵͳ


Ñо¿Ö°Ô±Capt.Meelo¶ÔNSAºÚ¿Í¹¤¾ßDoublePulsar¾ÙÐÐÁËÒÆÖ²£¬£¬£¬£¬£¬ £¬Ê¹ÆäÔÚWindowsǶÈëʽϵͳÉÏÒ²¿ÉÊÂÇé¡£¡£¡£µ±DoublePulsarÔÚ2017Äê4ÔÂÐû²¼Ê±£¬£¬£¬£¬£¬ £¬Æä¿ÉÒÔ×÷ÓÃÓÚ³ýÁË×îеÄWindows 10Ö®ÍâµÄËùÓÐÖ÷ÒªWindows°æ±¾ÉÏ¡£¡£¡£2017ÄêDoublePulsarѬȾÁËÁè¼Ý40Íǫ̀µçÄÔ¡£¡£¡£Í¨¹ýÒÆÖ²Ö®ºó£¬£¬£¬£¬£¬ £¬DoublePulsarÏÖÔÚ¿ÉÒÔ×÷ÓÃÓÚIoT×°±¸¡¢PoS»ú»òATMµÈÔËÐÐWindows IoT Core OSµÄ×°±¸¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/nsa-exploit-doublepulsar-patched-to-work-on-windows-iot-systems/