ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ32ÖÜ
°ä²¼¹¦·ò 2018-08-13Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ¢À˹¼ÓijÕòÈ·µ±¾ÖÍøÂçÒòϰȾÀÕË÷Èí¼þBitPaymer¶ø±»ÆÈ¹Ø¹Ø£»Ä«Î÷¸çÒ»Ò½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬Ô¼200Íò»¼ÕßµÄÐÅϢй¶£»TCMÒøÐÐÒòÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÓû§µÄÃô¸ÐÊý¾Ýй¶£»SnapchatÔ´ÂëÔÚGitHubÉÏÆØ¹â£¬¹«Ë¾»úÃÜ¿ÉÄܱíй£»ÃÀÖ°Òµ¸ß¶û·òлáPGAÒÉÔâÀÕË÷Èí¼þBitPaymer¹¥»÷¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
Siemens SIMATIC STEP 7ºÍWinCC TIA PortalĬÈÏ×°ÖÃÖеÄÎļþȨÏÞ·ÖÅä²»µ±£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬Ö´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://cert-portal.siemens.com/productcert/pdf/ssa-979106.pdf
2¡¢HP Ink PrintersÔ¶³Ì´úÂëÖ´Ðзì϶
HP Ink¶à¸ö´òÓ¡»ú´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.hp.com/us-en/document/c06097712
3¡¢Linux kernel 'tcp_input.c'Ô¶³Ì»Ø¾ø·þÎñ·ì϶
Linux kernel tcp_collapse_ofo_queue()¼°tcp_prune_ofo_queue() ŲÓôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬽øÐлؾø·þÎñ¹¥»÷¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.synology.com/support/security/Synology_SA_18_41
SonicWall Global Management SystemûÓÐÑéÖ¤Óû§Ìá½»µÄÓÃÓÚXML-RPCŲÓõIJÎÊý£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007
HPE Intelligent Management Center£¨iMC£©PLAT´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Ö´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03864en_us
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
7ÔÂ24ÈÕ°¢À˹¼Ó³ÇÕòMat-SuÈ·µ±¾ÖÍøÂçϰȾÀÕË÷Èí¼þBitPaymer£¬µ¼ÖÂÆäÍøÂçÏÝÈë̱»¾¡£BitPaymerËÆºõÔçÔÚ5ÔÂ3ÈÕ¾ÍÒѾ½øÈëÁËMat-SuµÄÍøÂ磬µ«´¦ÓÚÐÝÃß»òδ±»·¢½ü¿ö̬¡£¸ÃÀÕË÷Èí¼þÔÚ7ÔÂ24ÈÕ·¢×÷£¬Ó°ÏìÁË500̨×ÀÃæ¹¤×÷Õ¾ºÍ120̨·þÎñÆ÷¡£Mat-Su¹«¹²ÊÂÎñ×ܼàPatty Sullivan³Æ¸ÃÕòµÄ»ù´¡ÉèÊ©ÔÚÎȲ½³Á½¨£¬Ô̺¬µç×ÓÓʼþ·þÎñ¡¢µç»°ºÍ»¥ÁªÍøµÈ·þÎñÒ²½«¸´Ô¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bitpaymer-ransomware-infection-forces-alaskan-town-to-use-typewriters-for-a-week/
2¡¢Ä«Î÷¸çÒ»Ò½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬Ô¼200Íò»¼ÕßµÄÐÅϢй¶
°²È«×êÑÐÔ±Bob Diachenkoͨ¹ýShodan·¢ÏÖÒ»¸öÄ«Î÷¸çÒ½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬¸ÃMongoDBÊý¾Ý¿âÔ̺¬Ô¼200Íò»¼ÕßµÄÒ½ÁÆÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢±£ÏÕÐÅÏ¢¡¢²Ð¼²Çé¿öºÍ¼ÒͥסַµÈÐÅÏ¢¡£Diachenko·¢ÏÖ¸ÃÊý¾Ý¿âµÄÖÎÀíÔ±µç×ÓÓʼþÓòÃûΪhovahealth.comºÍefimed.care£¬ÔÚ֪ͨHova Health¹«Ë¾ºó£¬¸ÃÊý¾Ý¿âÔÚÈý¸öÓ×ʱÄڵõ½±£»¤¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/health-care-data-of-2-million-people-in-mexico-exposed-online/
3¡¢TCMÒøÐÐÒòÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÓû§µÄÃô¸ÐÊý¾Ýй¶
TCMÒøÐÐÊÇICBA BancardµÄ×Ó¹«Ë¾£¬ËüÊÇÃÀ¹ú750¶à¼ÒÓ×ÐͺÍÉçÇøÒøÐеÄÐÅÓþ¿¨¿¯ÐÐÉÌ¡£¸ÃÒøÐа䷢ÆäÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÐÅÓþ¿¨ÉêÇëÈ˵ÄÐÅÏ¢ÔÚ2017Äê3Ô³õÖÁ2018Äê7ÔÂÖÐѮ֮¼äµÄ16¸öÔÂÄÚºÏß¶³ö¡£¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬ÉêÇëÈ˵ÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚºÍÉç±£ºÅÂëµÈ¡£ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿Îª²»µ½1ÍòÈË¡£TCM³ÆÆäÔÚ2018Äê7ÔÂ16ÈÕ·¢ÏÖÁ˸ÃÎÊÌ⣬²¢ÔÚµÚ¶þÌì½øÐÐÁ˽¨¸´¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75078/data-breach/tcm-bank-data-leak.html
4¡¢SnapchatÔ´ÂëÔÚGitHubÉÏÆØ¹â£¬¹«Ë¾»úÃÜ¿ÉÄܱíй
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/snapchat-hack-source-code.html
5¡¢ÃÀÖ°Òµ¸ß¶û·òлáPGAÒÉÔâÀÕË÷Èí¼þBitPaymer¹¥»÷
ƾ¾ÝGolfWeekµÄ±¨Â·£¬±¾ÖܶþÃÀ¹úÖ°Òµ¸ß¶û·òлᣨPGA£©ÒÉÔâÀÕË÷Èí¼þBitPaymerµÄ¹¥»÷¡£ÓëÀÕË÷Èí¼þSamSamÒ»Ñù£¬BitPaymerÆ«²îÓÚͨ¹ýRDP·þÎñÈëÇÖÖ¸±ê×éÖ¯µÄÍøÂ磬²¢ºáÏò´«²¼ÖÁÃ¿Ò»Ì¨ÍÆËã»ú¡£¸Ã±äÖÖÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lockedÀ©´óÃû£¬²¢ÀÕË÷½Ï¸ßµÄÊê½ð¡£ÔÚ´ÓǰµÄ¼¸ÖÜÄÚBitpaymerÒѾ³öÏÖÁËÊý´ÎÕë¶ÔÆóÒµ¡¢µ±¾Ö»ú¹¹ºÍÒ½ÔºµÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/the-pga-possibly-infected-with-the-bitpaymer-ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ