¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181128

Ðû²¼Ê±¼ä 2018-11-28
1¡¢NodeJSÈÈÃÅÄ£¿£¿£¿£¿£¿éEvent-Stream±»Ö²Èë¶ñÒâ´úÂë

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ò»¸öÆÕ±éʹÓõÄNodeJSÄ£¿£¿£¿£¿£¿éEvent-Stream±»·¢Ã÷ѬȾÁ˶ñÒâ´úÂë £¬£¬£¬£¬£¬¿ÉÇÔÈ¡±ÈÌØ±ÒÇ®°üÖеÄ×ʽ𡣡£¡£ ¡£¡£¡£Event-StreamÊÇÒ»¸öµÚÈý·½¿â £¬£¬£¬£¬£¬ÓÃÓÚ´¦Öóͷ£Node.jsÁ÷Êý¾Ý £¬£¬£¬£¬£¬ÆäÒ»ÖܵÄÏÂÔØÁ¿¾Í¿¿½ü200Íò´Î¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâ´úÂë±£´æÓÚEvent-Stream°æ±¾3.3.6ÖÐ £¬£¬£¬£¬£¬ÏÖÔڸð汾Òѱ»É¾³ý £¬£¬£¬£¬£¬Óû§¿É¸üÐÂÖÁ×îа汾4.0.1¡£¡£¡£ ¡£¡£¡£ÊÂÎñµÄÒòÓÉÊÇEvent-StreamµÄÔ­×÷ÕßDominic Tarr½«ÏîÄ¿µÄ¿ª·¢ºÍά»¤½»¸øÁËÁíÒ»Ãû×÷Õßright9ctrl £¬£¬£¬£¬£¬µ«right9ctrlËæºóÐû²¼Á˰üÀ¨¶ñÒâ´úÂëµÄ°æ±¾¡£¡£¡£ ¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/nodejs-event-stream-module.html


2¡¢Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþ»î¶¯sLoad

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


CERT-Yoroi·¢Ã÷Ò»¸öÕë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþ»î¶¯ £¬£¬£¬£¬£¬¸Ã»î¶¯Ö÷Òª·Ö·¢sLoadµÄбäÖÖ¡£¡£¡£ ¡£¡£¡£sLoadµÄ¹¦Ð§Ç¿Ê¢ £¬£¬£¬£¬£¬Ëü¿ÉÒÔ½ØÈ¡ÆÁÄ»¡¢¶ÁÈ¡Àú³ÌÁÐ±í¡¢»ñÈ¡DNS»º´æ¡¢ÇÔÈ¡outlookÓʼþÄÚÈݵÈ¡£¡£¡£ ¡£¡£¡£¸Ã»î¶¯ÖÐsLoadͨ¹ýÀ¬»øÓʼþÖеÄzip¸½¼þ¾ÙÐзַ¢¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎú¸Ã»î¶¯ÊÇÒ»¸öÐµķ¸·¨ÍÅ»ïËùΪÕÕ¾ÉÒÑÖªµÄ·¸·¨ÍÅ»ï¸Ä±äÁËËüÃǵÄTTP¡£¡£¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78468/malware/sload-malspam-hit-italy.html


3¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶ÔÖж«µØÇøµÄ¶ñÒâ»î¶¯DNSpionage

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


˼¿ÆTalos·¢Ã÷Õë¶ÔÀè°ÍÄۺͰ¢ÁªÇõÕþ¸®ÍøÕ¾ÒÔ¼°Ò»¼ÒÀè°ÍÄÛº½¿Õ¹«Ë¾µÄжñÒâ»î¶¯¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤Talos¶ÔÆä»ù´¡ÉèÊ©ºÍTTPµÄÊÓ²ìЧ¹û £¬£¬£¬£¬£¬¸Ã¶ñÒâ»î¶¯ÎÞ·¨ÓëÈκÎÒÑÖªµÄ¹¥»÷Õß¾ÙÐйØÁª¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ»¹²»¿ÉÈ·¶¨¹¥»÷ÕßµÄÄ¿µÄ £¬£¬£¬£¬£¬Ò²²»ÇåÎú¹¥»÷ÕßÓÃÓÚ·Ö·¢¶ñÒâÎĵµµÄÒªÁì £¬£¬£¬£¬£¬µ«×îÓпÉÄܵÄÊÇͨ¹ýÓã²æÊ½´¹Âڻ»òÉ罻ýÌåÆ½Ì¨¾ÙÐзַ¢¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÅû¶Á˸ü¶àµÄÊÖÒÕϸ½ÚºÍ¹¥»÷ʱ¼äÖá¡£¡£¡£ ¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html


4¡¢ÃÀ¹úiOSÓû§Ôâ´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯¹¥»÷

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Çå¾²³§ÉÌConfiant·¢Ã÷Ò»¸öÕë¶ÔÃÀ¹úiOSÓû§µÄ´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯¡£¡£¡£ ¡£¡£¡£11ÔÂ12ÈոöñÒâ»î¶¯²þâ±ì­Éý £¬£¬£¬£¬£¬·¸·¨·Ö×ÓÔÚ48СʱÄÚÐ®ÖÆÁËÁè¼Ý3ÒÚ¸öä¯ÀÀÆ÷»á»°¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâ»î¶¯Í¨¹ýÕýµ±ÍøÕ¾ÉϵĶñÒâ¹ã¸æ½«Óû§Öض¨ÏòÖÁһϵÁеÄÔÝÊ±ÍøÕ¾ £¬£¬£¬£¬£¬²¢ÏòÓû§ÍÆËͳÉÈËÍøÕ¾»òÀñÎ│Ö÷ÌâµÄÕ©Æ­»î¶¯¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±½«¸Ã¶ñÒâ»î¶¯¹ØÁªÖÁ·¸·¨ÍÅ»ïScamClub¡£¡£¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/us-ios-users-targeted-by-massive-malvertising-campaign/


5¡¢¶íº¥¶íÖÝÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬£¬¼±ÕïЧÀͱ»ÆÈÖÐÖ¹

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¾ÝThe Times Leader±¨µÀ £¬£¬£¬£¬£¬11ÔÂ23ÈÕÐÇÆÚÎåÍíÉ϶«¶íº¥¶íµØÇøÒ½ÔººÍ¶íº¥¶í¹ÈÒ½ÁÆÖÐÐĵÄÅÌËã»úϵͳÔâÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬£¬ÖÂʹҽԺµÄ¼±ÕïЧÀͱ»ÆÈÖÐÖ¹¡£¡£¡£ ¡£¡£¡£¸ÃµØÇøµÄ¼±Õï²½¶ÓÒѽ«²¡ÈË×ªÒÆÖÁÆäËüµØÇøµÄÒ½Ôº¡£¡£¡£ ¡£¡£¡£ºÃÐÂÎÅÊÇ £¬£¬£¬£¬£¬Ã»Óл¼ÕßµÄÊý¾ÝÔڴ˴ι¥»÷ÊÂÎñÖÐй¶¡£¡£¡£ ¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78441/breaking-news/ohio-hospital-system-ransomware.html


6¡¢UberÒò2016ÄêÊý¾Ýй¶±»ºÉÀ¼ºÍÓ¢¹ú·£¿£¿£¿£¿£¿î120ÍòÃÀÔª

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ó¢¹úµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒÔ¼°ºÉÀ¼µÄÊý¾Ý±£»£»£»£»£»¤»ú¹¹Autoriteit Persoonsgegevens»®·ÖÒò2016Äê10ÔµÄÊý¾Ýй¶ÊÂÎñ¶ÔUber´¦ÒÔ38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿£¿£¿£¿£¿î¡£¡£¡£ ¡£¡£¡£ICOÌåÏÖ¸ÃÊÂÎñÓ°ÏìÁËÓ¢¹úµÄ270ÍòUberÓû§ÒÔ¼°8.2Íò˾»ú¡£¡£¡£ ¡£¡£¡£ºÉÀ¼DPA³ÆÓÐ17.4ÍòºÉÀ¼¹«ÃñÊܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£·£¿£¿£¿£¿£¿îµÄÖ÷ÒªÔµ¹ÊÔ­ÓÉÊÇUberÑÓ³ÙÁ˽üÒ»Äê²Å±¨¸æ´Ë´Îй¶ÊÂÎñ £¬£¬£¬£¬£¬ÕâÑÏÖØÎ¥·´ÁËÏà¹ØÖ´·¨ÌõÀý £¬£¬£¬£¬£¬²¢ÇÒʹÊÜÓ°ÏìµÄÓû§ºÍ˾»úÃæÁÙ¸ü¸ßµÄڲƭΣº¦¡£¡£¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uber-fined-for-covering-up-2016-data-breach/



ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí