¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180815

°ä²¼¹¦·ò 2018-08-15

·ÖÎö»ã±¨¡¿×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÀ¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨¡£±¾¼¾¶ÈÀ¬»øÓʼþ¾ùÔÈռȫÇòÓʼþ×ÜÁ¿µÄ49.66% £¬ÓëÉÏÒ»¼¾¶ÈÏà±È½µÂäÁË2.16¸ö°Ù·Öµã¡£·´´¹µöϵͳԮÊÖÓû§×èÖ¹Á˳¬¹ý1.07ÒڴζԴ¹µöÍøÕ¾µÄÏνÓ £¬±È2018ÄêµÚÒ»¼¾¶ÈÔö³¤ÁË1700Íò¡£±¾¼¾¶ÈµÄÀ¬»øÓʼþÖ÷ÌâÖØÒªÓëGDPR¡¢ÊÀ½ç±­ºÍ¼ÓÃÜÇ®±ÒÓйØ £¬·¸×ï·Ö×Ó»¹Í¨¹ýÉç½»ÍøÂç¡¢ÐÂÎÅÀûÓúÍÓªÏú¶ÌÐÅÀ´·Ö·¢´¹µöÍøÕ¾µÄÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/


¡¾·ì϶²¹¶¡¡¿Î¢ÈíµÄ8Ô°²È«¸üн¨¸´ÁË60¸ö°²È«·ì϶ £¬Ô̺¬2¸ö0day


΢Èí°ä²¼2018Äê8Եݲȫ¸üР£¬¹²½¨¸´60¸ö°²È«·ì϶ £¬Ô̺¬2¸ö0day¡£µÚÒ»¸ö0dayÊÇWindows ShellÖеĿɵ¼ÖÂËÁÒâ´úÂëÖ´Ðеķì϶£¨CVE-2018-8414£© £¬µÚ¶þ¸öÊǿɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄIE 0day£¨CVE-2018-8373£©¡£Õâ´Î°²È«¸üй²½¨¸´ÁË19¸ö¸ßΣ·ì϶ £¬ËùÓеÄÕâЩ¸ßΣ·ì϶¶¼¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-august-2018-patch-tuesday-fixes-60-security-flaws-including-two-zero-days/


¡¾·ì϶²¹¶¡¡¿ICS-CERTÖÒ¸æ³ÆNetComm¹¤ÒµÂ·ÓÉÆ÷´æÔÚÁ½¸ö¸ßΣ·ì϶


°²È«×êÑÐÔ±Aditya K. Sood·¢ÏÖ°Ä´óÀûÑǹ«Ë¾NetComm WirelessÔì×÷µÄ¹¤ÒµÂ·ÓÉÆ÷´æÔÚÁ½¸ö¸ßΣ·ì϶ £¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶À´ÊÕÊÜÉ豸¡£ÊÜÓ°ÏìµÄ²úÆ·ÐͺÅÊÇÔËÐй̼þ°æ±¾2.0.29.11¼°Ö®Ç°°æ±¾µÄNetComm 4G LTE Light M2M¹¤ÒµÂ·ÓÉÆ÷¡£ICS-CERTÕë¶ÔÔ̺¬ÕâÁ½¸ö·ì϶ÔÚÄÚµÄ4¸ö°²È«·ì϶£¨CVE-2018-14782µ½CVE-2018-14785£©·¢³öÖҸ档NetCommÒÑÔÚ2018Äê5ÔÂÖÐÑ®°ä²¼ÁËÓйع̼þ¸üС£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75332/hacking/netcomm-industrial-routers-flaws.html


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓô«ÕæºÍ̸·ìÏ¶ÉøÈëÆóÒµÄÚÍø


Check PointµÄ×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓô«ÕæºÍ̸ÖеÄÁ½¸ö·ì϶À´ÊÕÊÜ´òÓ¡»úºÍÉøÈëÆóÒµÄÚÍø¡£Ä¿Ç°È«ÇòÈÔÓг¬¹ý3ÒÚ¸ö´«ÕæºÅÂëºÍ4500Íǫ̀´«Õæ»úͶÈëʹÓà £¬´«Õæ±»¿í·ºÓÃÓÚóÒ××éÖ¯¡¢¼à¹Ü»ú¹¹¡¢Ë¾·¨»ú¹¹¡¢ÒøÐлú¹¹ºÍ·¿µØ²ú¹«Ë¾µÈ¡£¸Ã¹¥»÷²½Öè±»³ÆÎªFaxploit¹¥»÷ £¬Óë´«ÕæºÍ̸ÖеÄÁ½¸ö»º³åÇøÒç¶Âí½ÅÓйأ¨CVE-2018-5925ºÍCVE-2018-5924£©¡£Ô¶³Ì¹¥»÷ÕßÖ»Ðè·¢ËÍÌØÔìµÄͼÏñÎļþ¼´¿ÉÀûÓ÷ì϶ִÐÐËÁÒâ´úÂë¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/hack-printer-fax-machine.html


¡¾Íþвµý±¨¡¿°²È«×êÑÐÍŶӷ¢ÏÖ¶à¸öÖÇÄܹà¸Èϵͳ´æÔÚ°²È«·ì϶


À´×ÔÒÔÉ«Áб¾¹ÅÀï°²´óѧµÄ×êÑÐÍŶӷ¢ÏÖ¶à¸öÖÇÄܹà¸Èϵͳ´æÔÚ¿ÉÀûÓõķì϶ £¬¿ÉÓÃÓÚ¹¥»÷³ÇÊеũˮ·þÎñ¡£×êÑÐÈËÔ±·ÖÎöÁËRainMachine¡¢BlueSprayºÍGreenIQµÈÖ÷Á÷¹à¸Èϵͳ £¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ýIoT¶ñÒâÈí¼þ´´½¨ÖÇÄܹà¸ÈϵͳµÄ½©Ê¬ÍøÂç £¬²¢Í¨¹ýC&C·þÎñÆ÷½ÚÔìÕâЩϵͳ¡£×êÑÐÈËÔ±ÖÒ¸æ³Æ £¬ÕâÖÖ¹¥»÷¿ÉÄÜ»á¶Ô¹©Ë®¹«Ë¾²úÉú³Á´óÓ°Ïì £¬ÀýÈçÈÃÅçÍ·³ÖÐøÈ÷Ë®ÒÔÔڶ̹¦·òÄÚÇå¿ÕË®ÏäºÍË®¿â¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/smart-irrigation-systems-expose-water-utilities-attacks