ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ19ÖÜ

°ä²¼¹¦·ò 2018-05-14

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ07ÈÕÖÁ13ÈÕÊÕ¼°²È«·ì϶58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Edge¾ç±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æ·ÛËé·ì϶ £»Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´Ðзì϶ £»Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶ £»Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´Ðзì϶ £»Lantech IDS CVE-2018-8865ËÁÒâ´úÂëÖ´Ðзì϶ ¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÅ·ÖÞÖÐÑëÒøÐа䲼TIBER-EU¿ò¼Ü£¬Ö¼ÔÚÔ®ÊÖ²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦ £»Android P½«¶ÔÀûÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞ¶È £»×êÑÐÈËÔ±·¢ÏÖpythonÄ£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬¿ÉÍøÂçÓû§SSHÍ´´¦ £»ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ïì £»×êÑÐÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÐÂÎſɱ»¸´Ô­ ¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Microsoft Edge¾ç±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æ·ÛËé·ì϶

        Microsoft Edge´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8128
2¡¢Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´Ðзì϶

        Microsoft Exchange Server Outlook Web Access (OWA)´¦ÖÃWEBÒªÇó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬿ÉÌáÉýȨÏÞ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8152
3¡¢Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶

        Adobe Flash Player´¦ÖöñÒâÎļþ´æÔÚÀàÐÍ»ìºÏ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄSWFÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-16.html
4¡¢Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´Ðзì϶

        Microsoft Office´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8158
5¡¢Lantech IDS CVE-2018-8865ËÁÒâ´úÂëÖ´Ðзì϶

        Lantech IDS´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.lantechcom.tw/global/eng/IDS-2102A.html


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Å·ÖÞÖÐÑëÒøÐа䲼TIBER-EU¿ò¼Ü£¬Ö¼ÔÚÔ®ÊÖ²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Å·ÖÞÖÐÑëÒøÐУ¨ECB£©°ä²¼»ùÓÚÍþвµý±¨µÄTIBER-EU¿ò¼Ü£¬¸Ã¿ò¼ÜÊÇÊ׸öÁìÓòΪŷÖÞµÄÕë¶Ô½ðÈÚÊг¡µÄÊܿغͶ¨ÔìÍøÂç¹¥»÷µÄ²âÊÔ¿ò¼Ü ¡£ÕâÒ»Ðж¯ÊǶԴÓǰ¼¸ÄêÄÚÕë¶Ô½ðÈÚÐÐÒµµÄ¶àÆðÍøÂç¹¥»÷µÄ»ØÓ¦ ¡£¸Ã¿ò¼ÜÔ̺¬Ò»¸ö·ÂÕÕÕæÕýºÚ¿ÍµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½µÄºì·½ÍŶÓ£¬À´²Î¼Ó½ðÈÚÐÐÒµÖеĹ«Ë¾ÏµÍ³µÄ·ì϶ÆÀ¹ÀºÍÉøÈë²âÊÔ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72176/hacking/european-central-bank-framework-cyber.html

2¡¢Android P½«¶ÔÀûÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞ¶È

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ƾ¾ÝAndroid¿ªÔ´ÏîÄ¿£¨AOSP£©ÖеÄ×îдúÂë¸ü¸Ä£¬XDA¿ª·¢ÈËÔ±·¢´Ë¿ÌÏÂÒ»´úAndroidϵͳAndroid PÖУ¬ÈκÎÀûÓö¼½«²»Äܼì²âÉ豸ÉÏµÄÆäËüÀûÓÃÊÇ·ñÔÚÏνӻ¥ÁªÍø ¡£XDA¿ª·¢ÈËÔ±Ö¸³ö£¬AndroidÒýÈëµÄÕâÒ»ÐÂ±ä¶¯ËÆºõºÜÓ×£¬µ«¶ÔÓû§ÒþÖÔµÄÓ°Ï콫ÊǾ޴óµÄ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/android-p-network-activity.html

3¡¢×êÑÐÈËÔ±·¢ÏÖpythonÄ£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬¿ÉÍøÂçÓû§SSHÍ´´¦

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        PythonÄ£¿éSSH Decorator£¨ssh-decorate£©ÊÇÓÉÒÔÉ«Áпª·¢ÈËÔ±Uri Goren¿ª·¢µÄÒ»¸öÓÃÓÚ´¦ÖÃsshÏνӵĿâ ¡£×êÑÐÈËÔ±·¢ÏÖssh-decorateµÄ¶à¸ö°æ±¾ÖÐÔ̺¬ÍøÂçÓû§sshÍ´´¦µÄ´úÂ룬×îºóÒ»¸ö°²È«µÄ°æ±¾Îª0.27£¬Ö®ºóµÄ0.28µ½0.31¶¼Ô̺¬¶ñÒâ´úÂë ¡£Goren³ÆºóÃÅÊDZ»ºÚ¿ÍÖ²ÈëµÄ£¬Ä¿Ç°GorenÒÑÔÚgithubºÍPyPIÉÑþ³ØýÁ˸ÿâ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/

4¡¢ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¸ç±¾¹þ¸ùÊеijÇÊй«ÓÃ×ÔÐгµÏµÍ³BycyklenÔâºÚ¿ÍÈëÇÖ£¬Õû¸öÊý¾Ý¿â±»É¾³ý£¬µ¼ÖÂËùÓеÄÔ¼1860Á©¹«ÓÃ×ÔÐгµÎÞ·¨½âËø ¡£¹¥»÷²úÉúÔÚ5ÔÂ4ÖçÒ¹Íí ¡£Bycyklen³Æ½â¾ö¸ÃÎÊÌâ±ØÒª¶ÔËùÓеÄ×ÔÐгµ½øÐÐÊÖ¶¯¸üУ¬ÆäÔ±¹¤ÔÚÉÏÖÜÁùÒѸ´Ô­ÁË200Á¾×ÔÐгµ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-shuts-down-copenhagen-s-public-city-bikes-system/

5¡¢×êÑÐÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÐÂÎſɱ»¸´Ô­

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        °²È«×êÑÐÈËÔ±Alec Muffett·¢ÏÖmacOSÖж˵½¶Ë¼ÓÃÜͨѶAPP SignalµÄÒÑɾ³ýÐÂÎſɱ»¸´Ô­£¬ÕâʹµÃÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜй¶ ¡£ÆäÔ­ÒòÊÇmacOS»áÔÚ֪ͨÖÐÐĵÄÊý¾Ý¿âÖб¸·ÝÐÂÎÅÄÚÈÝ£¨Í¨³£ÎªÆëÈ«ÐÂÎŵÄǰ1-1.5ÐУ©£¬ÓÃÓÚÏòÓû§ÏÔʾÐÂÎÅ֪ͨ ¡£¼´±ãÔÚSignalÖÐɾ³ýÁ˸ÃÐÂÎÅ£¬ÕâЩ±»½ØÈ¡µÄÐÅÏ¢ÈÔÄܹ»Í¨¹ý¸ÃÊý¾Ý¿â½øÐнӼû ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/signal-secure-messaging.html