ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ24ÖÜ
°ä²¼¹¦·ò 2018-06-18
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê06ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows 'HTTP.sys'Ô¶³Ì´úÂëÖ´Ðзì϶£»Microsoft Excel CVE-2018-8248Ô¶³Ì´úÂëÖ´Ðзì϶£»Microsoft Windows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£»Microsoft Windows CVE-2018-8213ËÁÒâ´úÂëÖ´Ðзì϶£»Cisco Network Services Orchestrator CVE-2018-0274ËÁÒâºÅÁîÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÖÇÀûÒøÐÐÔâºÚ¿Í¹¥»÷£¬Êý°ÙÌ¨ÍÆËã»úµÄMBR±»·ÛË飻º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿ÍÈëÇÖ£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª£»Weight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬²¿ÃÅ»ù´¡ÉèÊ©µÄÍ´´¦Ð¹Â¶£»AÕ¾ÔâºÚ¿Í¹¥»÷£¬½üǧÍòÓû§µÄÊý¾Ýй¶£»ÁãÊÛ¹«Ë¾Dixons CarphoneÔâºÚ¿ÍÈëÇÖ£¬Ô¼590ÍòÓû§µÄÐÅÓþ¿¨ÐÅϢй¶¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Microsoft Windows 'HTTP.sys'Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Windows 'HTTP.sys'´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8231
2¡¢Microsoft Excel CVE-2018-8248Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Excel´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐËÁÒâ´úÂëÌáÉýȨÏÞ¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8248
3¡¢Microsoft Windows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶
Microsoft Windows DNSAPI.dll´¦ÖÃDNSÏìÓ¦´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8225
4¡¢Microsoft Windows CVE-2018-8213ËÁÒâ´úÂëÖ´Ðзì϶
Microsoft Windows´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÏµÍ³¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8213
5¡¢Cisco Network Services Orchestrator CVE-2018-0274ËÁÒâºÅÁîÖ´Ðзì϶
Cisco Network Services Orchestrator CLI½âÎöÆ÷´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-nso
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçVPNFilter¾íÍÁ³ÁÀ´£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼

5ÔÂ24ÈÕÖÇÀûÒøÐÐÔâºÚ¿Í¹¥»÷£¬¹¥»÷ÕßÊÔͼͨ¹ýÒøÐеÄSWIFTתÕËϵͳÇÔÈ¡×ʽ𣬲¢Í¬Ê±Í¨¹ý´ÅÅ̲Á³ý¶ñÒâÈí¼þ·ÛËéÁËÊý°Ų̀µçÄÔÒÔ·ÖÉ¢Ô±¹¤È·°ÑÎÈÁ¦¡£Æ¾¾Ý±¾µØÃ½ÌåµÄ±¨Â·£¬¹ÌÈ»ÔÚÏßϵͳ¹¤×÷Õý³££¬µ«¸ÃÒøÐеĶà¸öÍøµã·þÎñ±ÀÀ£¡£¹ÌȻûÓÐÃ÷È·Ö¸³ö£¬µ«¸ÃÒøÐÐϰȾµÄ¶ñÒâÈí¼þºÜ¿ÉÄÜÊÇKillDiskµÄбäÌ壬¸Ã±äÌåÖØÒª²Á³ýÍÆËã»úµÄMBR£¬Ç÷Ïò¿Æ¼¼°ä²¼Á˹ØÓڸñäÌåµÄ·ÖÎö»ã±¨¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-crashed-a-bank-s-computers-while-attempting-a-swift-hack/
2¡¢º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿ÍÈëÇÖ£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª

ÉÏÖÜÈÕº«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿Í¹¥»÷£¬ÈëÇÖÕßÇÔÈ¡ÁËPundi X£¨NPXS£©¡¢NPER£¨NPER£©ºÍAston£¨ATX£©µÄ²¿ÃÅICO´ú±Ò£¬ÂòÂôËùûÓÐÅû¶Óйر»µÁ×ʽðµÄ¾ßÌåÊý×Ö£¬µ«ÓÐЧ»§¸ú×ÙÁËÈëÇÖÕßµÄÕË»§µØÖ·£¬ÒÔΪÓйر»µÁ×ʽð¼ÛÖµÔÚ3000Íòµ½4000ÍòÃÀÔªÖ®¼ä£¬ÆäÖÐÔ¼Ò»°ëΪNPXS´ú±Ò¡£Coinrail³ÆÕýÓëÊÜÓ°ÏìµÄICO¹«Ë¾ºÏ×÷ÒÔ¶³½á±»µÁµÄ´ú±Ò¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/south-korean-cryptocurrency-exchange-coinrail-gets-hacked/
3¡¢Weight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬²¿ÃÅ»ù´¡ÉèÊ©µÄÍ´´¦Ð¹Â¶

µÂ¹ú°²È«³§ÉÌKromtechµÄ×êÑÐÈËÔ±·¢ÏÖWeight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬ÕâʹµÃÈκÎÈ˶¼Äܹ»Í¨¹ý¶Ë¿Ú10250½Ó¼û¸Ã·þÎñÆ÷¡£×êÑÐÈËÔ±Ôڸ÷þÎñÆ÷ÉÏ·¢ÏÖÁËWeight Watchers¹«Ë¾µÄIT»ù´¡ÉèÊ©µÄÅäÏàÐÅÏ¢£¬Ô̺¬ÖÎÀíԱʹ´¦¡¢102¸öÓòµÄ½Ó¼ûÃÜÔ¿¡¢AWS½Ó¼ûÃÜÔ¿µÈ¡£Weight Watchers³ÆÕâ²»ÊÇÒ»¸ö³ö²úÍøÂç¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/weight-watchers-it-infrastructure-exposed-via-no-password-kubernetes-server/
4¡¢AÕ¾ÔâºÚ¿Í¹¥»÷£¬½üǧÍòÓû§µÄÊý¾Ýй¶

½ñÈÕÁ賿AcFun°ä²¼²¼¸æ³ÆÆäÔâºÚ¿Í¹¥»÷£¬½üǧÍòÓû§µÄÊý¾Ýй¶£¬Ô̺¬Óû§ID¡¢êdzơ¢¼ÓÃÜ´æ´¢µÄÃÜÂëµÈ¡£ÔÚ2017Äê7ÔÂ7ÈÕ֮ǰµÇ¼¹ýAcFunµÄÓû§ÊÜÓ°Ï죬µ«Ò²½¨ÒéÃÜÂë¹ýÓÚµ¥Ò»µÄÆäËüÓû§Åú¸ÄÃÜÂë¡£AcFun³ÆÒѾ½áºÏÄÚ²¿ºÍ±í²¿µÄ¼¼Êõר¼Ò¶ÔÎÊÌâ½øÐÐÅŲ飬²¢Éý¼¶ÏµÍ³µÄ°²È«µÈ¼¶¡£
ÔÎÄÁ´½Ó£ºhttp://www.sohu.com/a/235455264_250147
5¡¢ÁãÊÛ¹«Ë¾Dixons CarphoneÔâºÚ¿ÍÈëÇÖ£¬Ô¼590ÍòÓû§µÄÐÅÓþ¿¨ÐÅϢй¶

ÁãÊÛ¹«Ë¾Dixons CarphoneÅû¶һ¸öÉæ¼°Ô¼590ÍòÕÅÐÅÓþ¿¨ºÍ120ÍòÌõÓ×ÎÒÊý¾Ý¼Í¼µÄ°²È«ÊÂÎñ¡£¸Ã¹«Ë¾³ÆºÚ¿Í½Ó¼ûÁË´æ´¢ÔÚÆäCurrys PC WorldºÍDixons TravelÉ̵êµÄϵͳÖеÄÔ¼590ÍòÕÅÐÅÓþ¿¨Êý¾Ý£¬ÆäÖÐ580ÍòÕÅÐÅÓþ¿¨ÓµÓÐоƬºÍPINÂë±£»¤£¬ÕâÒâζןڿͻñÈ¡µÄÊý¾Ý¼ÈûÓÐÔ̺¬PINÂë¡¢CVV£¬Ò²Ã»ÓÐÔ̺¬ÈκÎÄܹ»½øÐгֿ¨È˼ø±ðºÍ²É°ìÐÐΪµÄÑéÖ¤Êý¾Ý¡£¸Ã¹«Ë¾ÔÚÁªÏµÊÜÓ°ÏìµÄÓû§£¬²¢ÏòËûÃÇ´ÍÓ뽨Òé¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73479/data-breach/dixons-carphone-hacked.html


¾©¹«Íø°²±¸11010802024551ºÅ