ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ17ÖÜ

Ðû²¼Ê±¼ä 2018-05-02

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î43¸ö£¬£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Text AnnotationsÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»DrupalÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Apache TikaÎÊÌâÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£»Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç³öÎó²î£»£»£»£»£»£»D-Link DIR-615 / Tracerouteí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÃÀSunTrustÒøÐÐǰ¹ÍÔ±ÇÔȡԼ150Íò¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£»£»£»£»£»£»Ñо¿ÍŶӷ¢Ã÷IoT½©Ê¬ÍøÂçMuhstik×îÏÈ´ó¹æÄ£Ê¹ÓÃÎó²îDrupalgeddon 2£»£»£»£»£»£»ºÚ¿ÍʹÓÃDrupalgeddon2Îó²î¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø£»£»£»£»£»£»Ñо¿ÍŶӷ¢Ã÷Ö¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret£»£»£»£»£»£»Î¢ÈíÐû²¼¸ü¶à¹ØÓÚIntel CPU SpectreÎó²îµÄ΢´úÂë¸üС£¡£¡£¡£¡£

        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Foxit Reader Text AnnotationsÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î

        Foxit Reader Text Annotations±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬ £¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.foxitsoftware.com/support/security-bulletins.php
2¡¢DrupalÔ¶³Ì´úÂëÖ´ÐÐÎó²î

        Drupal¶à¸ö×Óϵͳ±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.drupal.org/sa-core-2018-002
3¡¢Apache TikaÎÊÌâÏÂÁî×¢ÈëÎó²î

        Apache Tika´¦Öóͷ£½á¹¹µÄÎÊÌâ±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬£¬¿ÉÔÚtika-serverÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca@%3Cdev.tika.apache.org%3E
4¡¢Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç³öÎó²î

        Advantech WebAccess HMI Designer´¦Öóͷ£PM3Îļþ±£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬ £¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttp://webaccess.advantech.com/product.php
5¡¢D-Link DIR-615 / Tracerouteí§Òâ´úÂëÖ´ÐÐÎó²î

        D-Link DIR-615 / Traceroute±£´æÊäÈëÑéÖ¤Çå¾²Îó²î£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄHOST×Ö¶ÎÊý¾Ý£¬£¬£¬ £¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://github.com/imsebao/404team/blob/master/dlink/dlink_dir615_rce.md


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÃÀSunTrustÒøÐÐǰ¹ÍÔ±ÇÔȡԼ150Íò¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾

        ÃÀ¹úSunTrustÒøÐеÄCEO William RogersÔÚýÌåÐû²¼»áÉÏÌåÏÖ£¬£¬£¬ £¬£¬£¬¸ÃÒøÐз¢Ã÷Ò»Ãûǰ¹ÍÔ±ÇÔÈ¡ÁËÔ¼150Íò¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢²¢½«ÕâЩÐÅÏ¢¹²Ïí¸øµÚÈý·½·¸·¨ÍŻ¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëºÍÕË»§Óà¶î¡£¡£¡£¡£¡£SunTrust³Æ¿Í»§µÄÃÜÂë¡¢Éç±£ºÅÂë¡¢Õ˺š¢ID»ò¼ÝÕÕºÅÂ벢δй¶¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/suntrust-bank-says-former-employee-stole-details-on-15-million-customers/

2¡¢Ñо¿ÍŶӷ¢Ã÷IoT½©Ê¬ÍøÂçMuhstik×îÏÈ´ó¹æÄ£Ê¹ÓÃÎó²îDrupalgeddon 2

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾

        Çå¾²Ñо¿ÍŶӷ¢Ã÷IoT½©Ê¬ÍøÂçMuhstikÒѾ­×ªÒƵ½Ê¹ÓÃDrupalgeddon 2Îó²î£¨CVE-2018-7600£©Ìᳫ´ó¹æÄ£¹¥»÷¡£¡£¡£¡£¡£Ñ¬È¾Ä¿µÄÖ÷»úºó£¬£¬£¬ £¬£¬£¬¹¥»÷Õß½«Ê¹Óö¨ÖƵĶñÒâÈí¼þTsunamiÌᳫDDoS¹¥»÷¡¢×°ÖÃÃÅÂÞ±ÒÍÚ¿óÈí¼þXMRig»òDash±ÒÍÚ¿óÈí¼þCGMiner¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/big-iot-botnet-starts-large-scale-exploitation-of-drupalgeddon-2-vulnerability/

3¡¢ºÚ¿ÍʹÓÃDrupalgeddon2Îó²î¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾

        ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬ÎÚ¿ËÀ¼ÍøÂ羯ԱŮ½²»°ÈËYulia Kvitko³ÆÕâÒ»ÊÂÎñÊÇ¡°ÁæØê¡±µÄ£¬£¬£¬ £¬£¬£¬ÏÖÔÚµ¼Ö¸ò¿·ÖÍøÕ¾Òѱ»Ëø¶¨¡£¡£¡£¡£¡£¹¥»÷ÕßËÆºõʹÓÃDrupalgeddon2£¬£¬£¬ £¬£¬£¬ÕâÊÇÒ»¸öÓ°Ïì´ó´ó¶¼DrupalÍøÕ¾µÄµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£

        Ô­aÁ´½Ó£ºhttps://threatpost.com/ransomware-attack-hits-ukrainian-energy-ministry-exploiting-drupalgeddon2/131373/

4¡¢Ñо¿ÍŶӷ¢Ã÷Ö¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾

        McAfeeÑо¿ÍŶÓÐû²¼¹ØÓÚ¶ñÒâ»î¶¯Operation GhostSecretµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£GhostSecretÖ¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬°üÀ¨Òªº¦»ù´¡ÉèÊ©¡¢ÓéÀÖ¡¢½ðÈÚ¡¢Ò½ÁƱ£½¡ÒÔ¼°µçÐÅ¡£¡£¡£¡£¡£GhostSecretʹÓõÄÖ²ÈëÎï¡¢¹¤¾ßºÍ¶ñÒâÈí¼þ±äÖÖÓë¹ú¼Ò×ÊÖúµÄ·¸·¨ÍÅ»ïHidden Cobra±£´æ¹ØÁª¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide

5¡¢Î¢ÈíÐû²¼¸ü¶à¹ØÓÚIntel CPU SpectreÎó²îµÄ΢´úÂë¸üÐÂ

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾

        ΢ÈíÐû²¼¸ü¶à¹ØÓÚSpectreÎó²îµÄCPU΢´úÂë¸üУ¬£¬£¬ £¬£¬£¬½«¸ÃÎó²îµÄÐÞ¸´½øÒ»²½À©Õ¹µ½Intel CPUµÄBroadwellºÍHaswellƽ̨¡£¡£¡£¡£¡£´Ë´Î¸üаüÀ¨KB4091666ºÍKB4078407Á½¸ö²¹¶¡°ü£¬£¬£¬ £¬£¬£¬¾ù¿É´ÓMicrosoft Update CatalogÃÅ»§ÍøÕ¾ÊÖ¶¯ÏÂÔØ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/microsoft-issues-more-spectre-updates-for-intel-cpus/131468/