·ÖÎö»ã±¨¡¿×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÀ¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨¡£±¾¼¾¶ÈÀ¬»øÓʼþ¾ùÔÈռȫÇòÓʼþ×ÜÁ¿µÄ49.66%£¬ÓëÉÏÒ»¼¾¶ÈÏà±È½µÂäÁË2.16¸ö°Ù·Öµã¡£·´´¹µöϵͳԮÊÖÓû§×èÖ¹Á˳¬¹ý1.07ÒڴζԴ¹µöÍøÕ¾µÄÏνӣ¬±È2018ÄêµÚÒ»¼¾¶ÈÔö³¤ÁË1700Íò¡£±¾¼¾¶ÈµÄÀ¬»øÓʼþÖ÷ÌâÖØÒªÓëGDPR¡¢ÊÀ½ç±ºÍ¼ÓÃÜÇ®±ÒÓйأ¬·¸×ï·Ö×Ó»¹Í¨¹ýÉç½»ÍøÂç¡¢ÐÂÎÅÀûÓúÍÓªÏú¶ÌÐÅÀ´·Ö·¢´¹µöÍøÕ¾µÄÁ´½Ó¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/
¡¾·ì϶²¹¶¡¡¿Î¢ÈíµÄ8Ô°²È«¸üн¨¸´ÁË60¸ö°²È«·ì϶£¬Ô̺¬2¸ö0day
΢Èí°ä²¼2018Äê8Եݲȫ¸üУ¬¹²½¨¸´60¸ö°²È«·ì϶£¬Ô̺¬2¸ö0day¡£µÚÒ»¸ö0dayÊÇWindows ShellÖеĿɵ¼ÖÂËÁÒâ´úÂëÖ´Ðеķì϶£¨CVE-2018-8414£©£¬µÚ¶þ¸öÊǿɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄIE 0day£¨CVE-2018-8373£©¡£Õâ´Î°²È«¸üй²½¨¸´ÁË19¸ö¸ßΣ·ì϶£¬ËùÓеÄÕâЩ¸ßΣ·ì϶¶¼¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-august-2018-patch-tuesday-fixes-60-security-flaws-including-two-zero-days/
¡¾·ì϶²¹¶¡¡¿ICS-CERTÖÒ¸æ³ÆNetComm¹¤ÒµÂ·ÓÉÆ÷´æÔÚÁ½¸ö¸ßΣ·ì϶
°²È«×êÑÐÔ±Aditya K. Sood·¢ÏÖ°Ä´óÀûÑǹ«Ë¾NetComm WirelessÔì×÷µÄ¹¤ÒµÂ·ÓÉÆ÷´æÔÚÁ½¸ö¸ßΣ·ì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶À´ÊÕÊÜÉ豸¡£ÊÜÓ°ÏìµÄ²úÆ·ÐͺÅÊÇÔËÐй̼þ°æ±¾2.0.29.11¼°Ö®Ç°°æ±¾µÄNetComm 4G LTE Light M2M¹¤ÒµÂ·ÓÉÆ÷¡£ICS-CERTÕë¶ÔÔ̺¬ÕâÁ½¸ö·ì϶ÔÚÄÚµÄ4¸ö°²È«·ì϶£¨CVE-2018-14782µ½CVE-2018-14785£©·¢³öÖҸ档NetCommÒÑÔÚ2018Äê5ÔÂÖÐÑ®°ä²¼ÁËÓйع̼þ¸üС£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75332/hacking/netcomm-industrial-routers-flaws.html
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓô«ÕæºÍ̸·ìÏ¶ÉøÈëÆóÒµÄÚÍø
Check PointµÄ×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓô«ÕæºÍ̸ÖеÄÁ½¸ö·ì϶À´ÊÕÊÜ´òÓ¡»úºÍÉøÈëÆóÒµÄÚÍø¡£Ä¿Ç°È«ÇòÈÔÓг¬¹ý3ÒÚ¸ö´«ÕæºÅÂëºÍ4500Íǫ̀´«Õæ»úͶÈëʹÓ㬴«Õæ±»¿í·ºÓÃÓÚóÒ××éÖ¯¡¢¼à¹Ü»ú¹¹¡¢Ë¾·¨»ú¹¹¡¢ÒøÐлú¹¹ºÍ·¿µØ²ú¹«Ë¾µÈ¡£¸Ã¹¥»÷²½Öè±»³ÆÎªFaxploit¹¥»÷£¬Óë´«ÕæºÍ̸ÖеÄÁ½¸ö»º³åÇøÒç¶Âí½ÅÓйأ¨CVE-2018-5925ºÍCVE-2018-5924£©¡£Ô¶³Ì¹¥»÷ÕßÖ»Ðè·¢ËÍÌØÔìµÄͼÏñÎļþ¼´¿ÉÀûÓ÷ì϶ִÐÐËÁÒâ´úÂë¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/hack-printer-fax-machine.html
¡¾Íþвµý±¨¡¿°²È«×êÑÐÍŶӷ¢ÏÖ¶à¸öÖÇÄܹà¸Èϵͳ´æÔÚ°²È«·ì϶
À´×ÔÒÔÉ«Áб¾¹ÅÀï°²´óѧµÄ×êÑÐÍŶӷ¢ÏÖ¶à¸öÖÇÄܹà¸Èϵͳ´æÔÚ¿ÉÀûÓõķì϶£¬¿ÉÓÃÓÚ¹¥»÷³ÇÊеũˮ·þÎñ¡£×êÑÐÈËÔ±·ÖÎöÁËRainMachine¡¢BlueSprayºÍGreenIQµÈÖ÷Á÷¹à¸Èϵͳ£¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ýIoT¶ñÒâÈí¼þ´´½¨ÖÇÄܹà¸ÈϵͳµÄ½©Ê¬ÍøÂ磬²¢Í¨¹ýC&C·þÎñÆ÷½ÚÔìÕâЩϵͳ¡£×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬ÕâÖÖ¹¥»÷¿ÉÄÜ»á¶Ô¹©Ë®¹«Ë¾²úÉú³Á´óÓ°Ï죬ÀýÈçÈÃÅçÍ·³ÖÐøÈ÷Ë®ÒÔÔڶ̹¦·òÄÚÇå¿ÕË®ÏäºÍË®¿â¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/smart-irrigation-systems-expose-water-utilities-attacks