¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180823
°ä²¼¹¦·ò 2018-08-23¡¾·ì϶²¹¶¡¡¿Struts2¹ÙÍøÅû¶×îÐÂRCE·ì϶S2-057£¨CVE-2018-11776£©
2018Äê8ÔÂ22ÈÕ£¬Apache Struts°ä²¼×îа²È«²¼¸æ£¬Åû¶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðеݲȫ·ì϶£¨S2-057/CVE-2018-11776£©¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬Apache Struts 2.3 - Struts 2.3.34ÒÔ¼°Apache Struts 2.5 - Struts 2.5.16£¬½¨ÒéÓû§Éý¼¶ÖÁ×îа汾Apache Struts 2.3.35»òStruts 2.5.17¡£
ÔÎÄÁ´½Ó£ºhttps://cwiki.apache.org/confluence/display/WW/S2-057
¡¾·ì϶²¹¶¡¡¿Adobe°ä²¼´¹Î£°²È«¸üУ¬½¨¸´PSÖеÄÁ½¸öRCE·ì϶
Adobe°ä²¼´¹Î£°²È«¸üУ¬½¨¸´WindowsºÍmacOSƽ̨ÉϵÄAdobe Photoshop CCÖеÄÁ½¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеĸßΣ·ì϶¡£ÕâÁ½¸ö·ì϶£¨CVE-2018-12810ºÍCVE-2018-12811£©Ó°ÏìÁË19.1.5¼°¸üÔçµÄ19.x°æ±¾ÒÔ¼°18.1.5¼°¸üÔçµÄ18.x°æ±¾¡£½¨ÒéÓû§¸üÐÂÖÁ°æ±¾19.1.6ºÍ18.1.6¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/adobe-photoshop-update.html
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖGhostscript´æÔÚ¶à¸ö-dSAFERɳÏäÈÆ¹ý·ì϶
Google Project Zero°²È«×êÑÐÈËÔ±Tavis OrmandyÅû¶ÁËGhostscriptÖеĶà¸ö-dSAFERɳÏäÈÆ¹ý·ì϶¡£GhostscriptÊÇAdobe PostScriptºÍPDFµÄÚ¹ÊÍ˵»°£¬¿í·ºÀûÓÃÔÚImageMagick¡¢Evince¡¢GIMP¡¢PDFÔĶÁÆ÷µÈÈí¼þÖС£¹¥»÷Õß¿Éͨ¹ý¶ñÒâµÄPostScript¡¢PDF¡¢EPS»òXPSÎļþ´¥·¢·ì϶¡£Ä¿Ç°ÕâЩ·ì϶»¹Ã»Óб»·ÖÅäCVE±àºÅ£¬Ò²Ã»Óйٷ½½¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/ghostscript-postscript-vulnerability.html
¡¾Õþ²ßÂÉÀý¡¿Å·ÖÞµçÐų߶ÈлáETSI°ä²¼°²È«½Ó¼û½ÚÔìµÄ¼ÓÃܳ߶È
Å·ÖÞµçÐų߶ÈлáETSI°ä²¼Á½¸ö»ùÓÚÊôÐÔ¼ÓÃÜ£¨ABE£©µÄ¹æ·¶£¬ÃèÊöÁËÈôºÎͨ¹ýϸÁ£¶ÈµÄ½Ó¼û½ÚÔìÀ´±£»¤Ó×ÎÒÊý¾ÝµÄ°²È«¡£ÕâÁ½¸ö¹æ·¶ÊÇETSI TS 103 458ºÍETSI TS 103 532£¬±ðÀëÃèÊöÁËABEµÄ¸ß¹æ¸ñÒªÇóºÍʹÓÃABE½Ó¼û½ÚÔìʱµÄÐÅÀµÄ£ÐÍ¡¢Ö°ÄÜÒÔ¼°ºÍ̸¡£ÕâÁ½¸ö¹æ·¶¶¼×ñÑ2018Äê5ÔÂÆðÖ´ÐеÄGDPR¡£
ÔÎÄÁ´½Ó£ºhttps://www.etsi.org/news-events/news/1328-2018-08-press-etsi-releases-cryptographic-standards-for-secure-access-control
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÐÂÀÕË÷Èí¼þRyukÓëHermes´æÔÚ¹ØÁª
Check Point×êÑÐÍŶӷ¢ÏÖÒѾϮ»÷ÁËÈ«Çò¶à¸ö×éÖ¯µÄÐÂÀÕË÷Èí¼þRyuk£¬¹¥»÷ÕßÒѾ»ñµÃÁ˳¬¹ý64ÍòÃÀÔªµÄÊê½ð¡£×êÑÐÈËÔ±»¹²»ÄÜÈ·¶¨RyukµÄ´«²¼·½Ê½£¬Ryuk±ØÒªÖÎÀíԱȨÏÞÀ´Ö´ÐУ¬µ«Æä×ÔÉíûÓлñµÃÖÎÀíԱȨÏÞµÄÖ°ÄÜ£¬Ò²Ã»Óз¢ÏÖÓÃÓÚʵÏÖÕâÒ»Ö÷ÕŵÄÓʼþ¡¢ÎĵµºÍ¾ç±¾µÈ¡£Òò¶øRyukºÜÓпÉÄÜÊÇÊÖ¶¯ÈëÇÖµÄÁ˾֡£×êÑÐÈËÔ±·¢ÏÖRyukºÍÀÕË÷Èí¼þHermes¹²ÏíÁË´óÁ¿µÄ´úÂ룬ÕâÒâζ×ÅÆä±³ºóµÄ¹¥»÷Õß´æÔÚ¹ØÁª¡£Hermes´Ë¿ÌÒÀÈ»»îÔ¾£¬Hermes 2.1ͨ¹ý´ó¹æÄ£À¬»øÓʼþ½øÐзַ¢£¬¶øRyukÖØÒªÓÃÓÚÓÐÕë¶ÔÐԵĹ¥»÷¡£
ÔÎÄÁ´½Ó£ºhttps://research.checkpoint.com/ryuk-ransomware-targeted-campaign-break/
¡¾Êý¾Ýй¶¡¿±£Ä··þÎñSitterÒòMongoDBÅäÖÃÃýÎóµ¼Ö³¬¹ý9.3ÍòÓû§µÄÐÅϢй¶
8ÔÂ14ÈÕ°²È«×êÑÐÈËÔ±Bob Diachenko·¢ÏÖ±£Ä··þÎñSitterµÄÒ»¸öMongoDB¿Éͨ¹ý»¥ÁªÍø¹«¿ª½Ó¼û£¨ÎÞÐèµÇ¼ʹ´¦£©£¬³¬¹ý9.3ÍòÃûÓû§µÄÃô¸ÐÊý¾Ýй¶¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÕË»§µÄÃÜÂë¹þÏ£¡¢Ã¿¸ö¼ÒÍ¥µÄº¢×ÓÊý¡¢¼ÒÍ¥µØÖ·¡¢µç»°ºÅÂë¡¢ÁªÏµÈËÁÐ±í¡¢Ö§¸¶¿¨ºÅÒÔ¼°appÄÚµÄ̸ÌìÐÅÏ¢µÈ¡£Êý¾Ý×ÜÁ¿³¬¹ý2GB¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mongodb-server-exposes-babysitting-apps-database/


¾©¹«Íø°²±¸11010802024551ºÅ