ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ19ÖÜ
°ä²¼¹¦·ò 2018-05-14
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê05ÔÂ07ÈÕÖÁ13ÈÕÊÕ¼°²È«·ì϶58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Edge¾ç±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æ·ÛËé·ì϶£»Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´Ðзì϶£»Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶£»Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´Ðзì϶£»Lantech IDS CVE-2018-8865ËÁÒâ´úÂëÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÅ·ÖÞÖÐÑëÒøÐа䲼TIBER-EU¿ò¼Ü£¬Ö¼ÔÚÔ®ÊÖ²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦£»Android P½«¶ÔÀûÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞ¶È£»×êÑÐÈËÔ±·¢ÏÖpythonÄ£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬¿ÉÍøÂçÓû§SSHÍ´´¦£»ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ï죻×êÑÐÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÐÂÎſɱ»¸´Ô¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Microsoft Edge¾ç±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æ·ÛËé·ì϶
Microsoft Edge´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8128
2¡¢Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´Ðзì϶
Microsoft Exchange Server Outlook Web Access (OWA)´¦ÖÃWEBÒªÇó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬿ÉÌáÉýȨÏÞ¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8152
3¡¢Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶
Adobe Flash Player´¦ÖöñÒâÎļþ´æÔÚÀàÐÍ»ìºÏ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄSWFÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-16.html
4¡¢Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Office´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8158
5¡¢Lantech IDS CVE-2018-8865ËÁÒâ´úÂëÖ´Ðзì϶
Lantech IDS´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.lantechcom.tw/global/eng/IDS-2102A.html
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Å·ÖÞÖÐÑëÒøÐа䲼TIBER-EU¿ò¼Ü£¬Ö¼ÔÚÔ®ÊÖ²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦

Å·ÖÞÖÐÑëÒøÐУ¨ECB£©°ä²¼»ùÓÚÍþвµý±¨µÄTIBER-EU¿ò¼Ü£¬¸Ã¿ò¼ÜÊÇÊ׸öÁìÓòΪŷÖÞµÄÕë¶Ô½ðÈÚÊг¡µÄÊܿغͶ¨ÔìÍøÂç¹¥»÷µÄ²âÊÔ¿ò¼Ü¡£ÕâÒ»Ðж¯ÊǶԴÓǰ¼¸ÄêÄÚÕë¶Ô½ðÈÚÐÐÒµµÄ¶àÆðÍøÂç¹¥»÷µÄ»ØÓ¦¡£¸Ã¿ò¼ÜÔ̺¬Ò»¸ö·ÂÕÕÕæÕýºÚ¿ÍµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½µÄºì·½ÍŶӣ¬À´²Î¼Ó½ðÈÚÐÐÒµÖеĹ«Ë¾ÏµÍ³µÄ·ì϶ÆÀ¹ÀºÍÉøÈë²âÊÔ¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72176/hacking/european-central-bank-framework-cyber.html
2¡¢Android P½«¶ÔÀûÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞ¶È

ƾ¾ÝAndroid¿ªÔ´ÏîÄ¿£¨AOSP£©ÖеÄ×îдúÂë¸ü¸Ä£¬XDA¿ª·¢ÈËÔ±·¢´Ë¿ÌÏÂÒ»´úAndroidϵͳAndroid PÖУ¬ÈκÎÀûÓö¼½«²»Äܼì²âÉ豸ÉÏµÄÆäËüÀûÓÃÊÇ·ñÔÚÏνӻ¥ÁªÍø¡£XDA¿ª·¢ÈËÔ±Ö¸³ö£¬AndroidÒýÈëµÄÕâÒ»ÐÂ±ä¶¯ËÆºõºÜÓ×£¬µ«¶ÔÓû§ÒþÖÔµÄÓ°Ï콫ÊǾ޴óµÄ¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/android-p-network-activity.html
3¡¢×êÑÐÈËÔ±·¢ÏÖpythonÄ£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬¿ÉÍøÂçÓû§SSHÍ´´¦

PythonÄ£¿éSSH Decorator£¨ssh-decorate£©ÊÇÓÉÒÔÉ«Áпª·¢ÈËÔ±Uri Goren¿ª·¢µÄÒ»¸öÓÃÓÚ´¦ÖÃsshÏνӵĿ⡣×êÑÐÈËÔ±·¢ÏÖssh-decorateµÄ¶à¸ö°æ±¾ÖÐÔ̺¬ÍøÂçÓû§sshÍ´´¦µÄ´úÂ룬×îºóÒ»¸ö°²È«µÄ°æ±¾Îª0.27£¬Ö®ºóµÄ0.28µ½0.31¶¼Ô̺¬¶ñÒâ´úÂë¡£Goren³ÆºóÃÅÊDZ»ºÚ¿ÍÖ²ÈëµÄ£¬Ä¿Ç°GorenÒÑÔÚgithubºÍPyPIÉÑþ³ØýÁ˸ÿ⡣
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/
4¡¢ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ïì

¸ç±¾¹þ¸ùÊеijÇÊй«ÓÃ×ÔÐгµÏµÍ³BycyklenÔâºÚ¿ÍÈëÇÖ£¬Õû¸öÊý¾Ý¿â±»É¾³ý£¬µ¼ÖÂËùÓеÄÔ¼1860Á©¹«ÓÃ×ÔÐгµÎÞ·¨½âËø¡£¹¥»÷²úÉúÔÚ5ÔÂ4ÖçÒ¹Íí¡£Bycyklen³Æ½â¾ö¸ÃÎÊÌâ±ØÒª¶ÔËùÓеÄ×ÔÐгµ½øÐÐÊÖ¶¯¸üУ¬ÆäÔ±¹¤ÔÚÉÏÖÜÁùÒѸ´ÔÁË200Á¾×ÔÐгµ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-shuts-down-copenhagen-s-public-city-bikes-system/
5¡¢×êÑÐÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÐÂÎſɱ»¸´Ô

°²È«×êÑÐÈËÔ±Alec Muffett·¢ÏÖmacOSÖж˵½¶Ë¼ÓÃÜͨѶAPP SignalµÄÒÑɾ³ýÐÂÎſɱ»¸´Ô£¬ÕâʹµÃÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜй¶¡£ÆäÔÒòÊÇmacOS»áÔÚ֪ͨÖÐÐĵÄÊý¾Ý¿âÖб¸·ÝÐÂÎÅÄÚÈÝ£¨Í¨³£ÎªÆëÈ«ÐÂÎŵÄǰ1-1.5ÐУ©£¬ÓÃÓÚÏòÓû§ÏÔʾÐÂÎÅ֪ͨ¡£¼´±ãÔÚSignalÖÐɾ³ýÁ˸ÃÐÂÎÅ£¬ÕâЩ±»½ØÈ¡µÄÐÅÏ¢ÈÔÄܹ»Í¨¹ý¸ÃÊý¾Ý¿â½øÐнӼû¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/signal-secure-messaging.html


¾©¹«Íø°²±¸11010802024551ºÅ