ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ17ÖÜ

°ä²¼¹¦·ò 2018-05-02

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼°²È«·ì϶43¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Text Annotations¿ªÊͺóʹÓÃÔ¶³Ì´úÂëÖ´Ðзì϶ £»DrupalÔ¶³Ì´úÂëÖ´Ðзì϶ £»Apache Tika±êÌâºÅÁî×¢Èë·ì϶ £»Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç¶Âí½Å £»D-Link DIR-615 / TracerouteËÁÒâ´úÂëÖ´Ðзì϶¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀSunTrustÒøÐÐǰ¹ÍÔ±ÇÔȡԼ150Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢ £»×êÑÐÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÆðÍ·´ó¹æÄ£ÀûÓ÷ì϶Drupalgeddon 2 £»ºÚ¿ÍÀûÓÃDrupalgeddon2·ì϶¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø £»×êÑÐÍŶӷ¢ÏÖÖ¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret £»Î¢Èí°ä²¼¸ü¶à¹ØÓÚIntel CPU Spectre·ì϶µÄ΢´úÂë¸üС£

        ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Foxit Reader Text Annotations¿ªÊͺóʹÓÃÔ¶³Ì´úÂëÖ´Ðзì϶

        Foxit Reader Text Annotations´æÔÚ¿ªÊͺóʹÓ÷ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.foxitsoftware.com/support/security-bulletins.php
2¡¢DrupalÔ¶³Ì´úÂëÖ´Ðзì϶

        Drupal¶à¸ö×Óϵͳ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.drupal.org/sa-core-2018-002
3¡¢Apache Tika±êÌâºÅÁî×¢Èë·ì϶

        Apache Tika´¦Öûú¹ØµÄ±êÌâ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÔÚtika-serverÉÏÖ´ÐÐËÁÒâºÅÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca@%3Cdev.tika.apache.org%3E
4¡¢Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç¶Âí½Å

        Advantech WebAccess HMI Designer´¦ÖÃPM3Îļþ´æÔÚ¶Ñ»º³åÇøÒç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://webaccess.advantech.com/product.php
5¡¢D-Link DIR-615 / TracerouteËÁÒâ´úÂëÖ´Ðзì϶

        D-Link DIR-615 / Traceroute´æÔÚÊäÈëÑéÖ¤°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄHOST×Ö¶ÎÊý¾Ý £¬Ö´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/imsebao/404team/blob/master/dlink/dlink_dir615_rce.md


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÃÀSunTrustÒøÐÐǰ¹ÍÔ±ÇÔȡԼ150Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÃÀ¹úSunTrustÒøÐеÄCEO William RogersÔÚýÌå°ä²¼»áÉϰµÊ¾ £¬¸ÃÒøÐз¢ÏÖÒ»Ãûǰ¹ÍÔ±ÇÔÈ¡ÁËÔ¼150Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢²¢½«ÕâЩÐÅÏ¢¹²Ïí¸øµÚÈý·½·¸×ïÍŻй¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÕË»§Óà¶î¡£SunTrust³Æ¿Í»§µÄÃÜÂë¡¢Éç±£ºÅÂë¡¢Õ˺š¢ID»ò¼ÝÕÕºÅÂ벢δй¶¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/suntrust-bank-says-former-employee-stole-details-on-15-million-customers/

2¡¢×êÑÐÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÆðÍ·´ó¹æÄ£ÀûÓ÷ì϶Drupalgeddon 2

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        °²È«×êÑÐÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÒѾ­×ªÒƵ½ÀûÓÃDrupalgeddon 2·ì϶£¨CVE-2018-7600£©ÌáÒé´ó¹æÄ£¹¥»÷¡£Ï°È¾Ö¸±êÖ÷»úºó £¬¹¥»÷Õß½«Ê¹Óö¨ÔìµÄ¶ñÒâÈí¼þTsunamiÌáÒéDDoS¹¥»÷¡¢×°ÖÃÃÅÂÞ±ÒÍÚ¿óÈí¼þXMRig»òDash±ÒÍÚ¿óÈí¼þCGMiner¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/big-iot-botnet-starts-large-scale-exploitation-of-drupalgeddon-2-vulnerability/

3¡¢ºÚ¿ÍÀûÓÃDrupalgeddon2·ì϶¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍøÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬ÎÚ¿ËÀ¼ÍøÂ羯ԱŮ½²»°ÈËYulia Kvitko³ÆÕâÒ»ÊÂÎñÊÇ¡°¹ÂÁ¢¡±µÄ £¬Ä¿Ç°µ¼Ö¸ò¿ÃÅÍøÕ¾Òѱ»Ëø¶¨¡£¹¥»÷ÕßËÆºõÀûÓÃDrupalgeddon2 £¬ÕâÊÇÒ»¸öÓ°Ïì´óÎÞÊýDrupalÍøÕ¾µÄµÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£

        Ô­aÁ´½Ó£ºhttps://threatpost.com/ransomware-attack-hits-ukrainian-energy-ministry-exploiting-drupalgeddon2/131373/

4¡¢×êÑÐÍŶӷ¢ÏÖÖ¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        McAfee×êÑÐÍŶӰ䲼¹ØÓÚ¶ñÒâ»î¶¯Operation GhostSecretµÄ·ÖÎö»ã±¨¡£GhostSecretÖ¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµµÄÊý¾Ý £¬Ô̺¬¹Ø¼ü»ù´¡ÉèÊ©¡¢ÓéÀÖ¡¢½ðÈÚ¡¢Ò½ÁƱ£½¡ÒÔ¼°µçÐÅ¡£GhostSecretʹÓõÄÖ²ÈëÎï¡¢¹¤¾ßºÍ¶ñÒâÈí¼þ±äÖÖÓë¹ú¶ÈÔÞÖúµÄ·¸×ïÍÅ»ïHidden Cobra´æÔÚ¹ØÁª¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide

5¡¢Î¢Èí°ä²¼¸ü¶à¹ØÓÚIntel CPU Spectre·ì϶µÄ΢´úÂë¸üÐÂ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ΢Èí°ä²¼¸ü¶à¹ØÓÚSpectre·ì϶µÄCPU΢´úÂë¸üР£¬½«¸Ã·ì϶µÄ½¨¸´½øÒ»²½À©´óµ½Intel CPUµÄBroadwellºÍHaswellƽ̨¡£Õâ´Î¸üÐÂÔ̺¬KB4091666ºÍKB4078407Á½¸ö²¹¶¡°ü £¬¾ù¿É´ÓMicrosoft Update CatalogÃÅ»§ÍøÕ¾ÊÖ¶¯ÏÂÔØ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/microsoft-issues-more-spectre-updates-for-intel-cpus/131468/