ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ29ÖÜ
°ä²¼¹¦·ò 2018-07-23Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê07ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼°²È«·ì϶44¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇPivotal Spring FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶£»Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁкÅÁî×¢Èë·ì϶£»ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´Ðзì϶£»Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶£»Dasan GPONºÅÁî×¢Èë·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÒøÐÐľÂíDorkbot¾íÍÁ³ÁÀ´£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%£»¶íÂÞ˹ÔÚÊÀ½ç±ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷£»Telefonica¹ÙÍø·ì϶¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶£»ÃÀѪҺ¼ì²â³¢ÊÔÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ï죻¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬ËðʧԼ100ÍòÃÀÔª¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Pivotal Spring FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶
Spring FrameworkʹÓÃspring-messagingÄ£¿éÀ´ÊµÏÖSTOMP´úÀíʱ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÐÂÎÅ£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.exploit-db.com/exploits/44796/
2¡¢Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁкÅÁî×¢Èë·ì϶
Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐWEB UI´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬×¢ÈëËÁÒâSHELLºÅÁî²¢Ö´ÐС£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180711-phone-webui-inject
3¡¢ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´Ðзì϶
ManageEngine Exchange Reporter Plus Java servlet ¡®ADSHACluster¡¯ÔÚÖ´ÐÓ×®bcp.exe¡¯Îļþ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâ¡®BCP_EXE¡¯²ÎÊýÒªÇó£¬Ö´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.manageengine.com/products/exchange-reports/release-notes.html
4¡¢Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶
Adobe Flash Player´¦ÖÃSWFÎļþ´æÔÚÀàÐÍ»ìºÏ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-24.html
5¡¢Dasan GPONºÅÁî×¢Èë·ì϶
Dasan GPON GponForm/diag_Form URI´æÔÚÉè¼Æ·ì϶£¬ÔÊÐí¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ'dest_host¡¯²ÎÊýµÄdiag_action=pingÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÒøÐÐľÂíDorkbot¾íÍÁ³ÁÀ´£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%
ƾ¾ÝCheck PointµÄ×îÐÂÊý¾Ý£¬ÒøÐÐľÂíDorkbotÔÚ2018Äê¾íÍÁ³ÁÀ´£¬³ÉΪһ¸öÑϳÁµÄÍþв¡£Dorkbot×îÔçÄܹ»×·Òäµ½2012Ä꣬ÆäÖØÒªÓÃÓÚÇÔÈ¡Óû§µÄÒøÐеǼʹ´¦¡£ÔÚ2018ÄêÉϰëÄ꣬ȫÇòÒøÐжñÒâÈí¼þÊг¡Õ¼¾ÝǰÈýλµÄ±ðÀëÊÇRamnit£¨27£¥£©¡¢Dorkbot£¨25£¥£©ºÍZeus£¨13£¥£©¡£DorkbotÒѳÉΪ2018ÄêµÚ¶þ´óÁîÈËÍ·ÌÛµÄÒøÐжñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/threatlist-6-year-old-dorkbot-banking-malware-resurfaces-as-big-threat/133898/
2¡¢¶íÂÞ˹ÔÚÊÀ½ç±ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷
Ī˹¿ÆÊ±±¨±¨Â·³Æ£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂ簲ȫÊýÃÅ£¬¸Ã²¿ÃÅÔÚÊÀ½ç±ÆÚ¼ä¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸×ï»î¶¯£¬È·±£Á˽ÇÖðµÄ°²È«¡£FireEyeÄÏÅ·¼¼Êõ×ܼàDavid Grout°µÊ¾¹ÌÈ»ÕâÒ»Êý×ֺܸߣ¬µ«²¢²»³öºõÒâÁÏ¡£ÕâЩ¹¥»÷¿ÉÄÜÔ̺¬ÔÚ½ÇÖðǰ¼¸ÖÜ¾ÍÆðÍ·µÄÍøÂç´¹µö¹¥»÷£¬ÀýÈçÁ®¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÊÀ½ç±Ö÷ÌâÓйصĴÙÏú»î¶¯£¨Èç¹ú¶È¶ÓÇòÒ£©µÈ¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/
3¡¢Telefonica¹ÙÍø·ì϶¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶
Î÷°àÑÀµçÐŹ«Ë¾TelefonicaµÄ¹Ì»°¡¢¿í´ø¼°¸¶·ÑµçÊÓÒµÎñMovistarµÄ¹ÙÍø´æÔÚ·ì϶£¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£Movistar¹ÙÍøÉÏÓÃÓڲ鿴·¢Æ±µÄÒ³ÃæµÄURLÖÐÔ̺¬ÁË·¢Æ±µÄID£¬ÈκÎÓû§¶¼Äܹ»Í¨¹ýÅú¸Ä´ËIDÀ´²é¿´ÆäËüÕË»§µÄÊý¾Ý¡£Æ¾¾ÝеÄGDPR»®¶¨£¬¸Ã¹«Ë¾¿ÉÄÜÃæ¶Ô1000Íò~2000ÍòÅ·Ôª»òÏ൱ÓÚÆäÄê½»Ò×¶î2%~4%µÄ·£¿î¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/telefonica-spain-exposed-the-personal-details-of-millions-of-customers/
4¡¢ÃÀѪҺ¼ì²â³¢ÊÔÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ïì
±¾ÖÜÒ»ÃÀ¹ú×î´óµÄѪҺ¼ì²â³¢ÊÔÊÒLabCorp°ä·¢ÆäÔÚÖÜÄ©ÆÚ¼äÔâµ½ºÚ¿ÍÈëÇÖ¡£LabCorp¹Ø¹ØÁ˲¿ÃÅϵͳÒÔ½ÚÔì¸ÃÈëÇֻ£¬Ä¿Ç°¸÷ϵͳְÄÜÔÚ¸´ÔÖС£¸Ã¹«Ë¾°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢²úÉúÁ˶ÔÊý¾ÝµÄδÊÚȨ½Ó¼û£¬µ«Ã»ÓÐÅû¶¸ü¶àÓйØÏ¸½Ú¡£Óйص±¾ÖÔÚ½øÐе÷²éÖ®ÖС£LabCorpÔÚÈ«ÇòÕ¼Óнü6ÍòÃûÔ±¹¤£¬ÆäÿÖܲâÊԵϼÕßÑù±¾³¬¹ý250Íò¸ö£¬Òò¶øÊý¾Ýй¶µÄDZÔÚºó¹û¿ÉÄÜÊǾ޴óµÄ£¬Êý°ÙÍòÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜÃæ¶Ô·çÏÕ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-network-of-labcorp-us-biggest-blood-testing-laboratories/
5¡¢¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬ËðʧԼ100ÍòÃÀÔª
ƾ¾Ý¶íÂÞ˹°²È«³§ÉÌGroup-IBµÄ»ã±¨£¬ºÚ¿ÍÍÅ»ïMoneyTakerͨ¹ý·ÓÉÆ÷ÈëÇÖÁ˶íÂÞ˹PIRÒøÐеÄÍøÂ磬²¢ÇÔÈ¡ÁËÔ¼100ÍòÃÀÔªµÄ×ʽð¡£Group-IBÈ·ÈϹ¥»÷ʼÓÚ2018Äê5ÔÂÏÂÑ®£¬¹¥»÷ÕßµÄÈë¿ÚÊǹýÆÚµÄ·ÓÉÆ÷£¬¸Ã·ÓÉÆ÷ÓÐËí·£¬¿ÉÔÊÐí¹¥»÷ÕßÖ±½Ó½Ó¼ûÒøÐеı¾µØÍøÂç¡£¹¥»÷²úÉúÔÚ7ÔÂ3ÈÕ£¬PIRÒøÐеÄÔ±¹¤ÔÚÒ»ÌìºóµÄ7ÔÂ4ÈÕ·¢ÏÖÁË´ó±ÊδÊÚȨµÄÂòÂô£¬µ«ÎªÊ±ÒÑÍí¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-russian-bank-and-steal-1-million-due-to-outdated-router/


¾©¹«Íø°²±¸11010802024551ºÅ