ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ17ÖÜ

Ðû²¼Ê±¼ä 2018-05-02

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´43¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Text AnnotationsÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´ £»DrupalÔ¶³Ì´úÂëÖ´ÐЩ¶´ £»Apache Tika±êÌâÃüÁî×¢È멶´ £»Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç³ö©¶´ £»D-Link DIR-615 / TracerouteÈÎÒâ´úÂëÖ´ÐЩ¶´¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀSunTrustÒøÐÐÇ°¹ÍÔ±ÇÔÈ¡Ô¼150Íò¿Í»§µÄ¸öÈËÐÅÏ¢ £»Ñо¿ÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstik¿ªÊ¼´ó¹æÄ£ÀûÓ鶴Drupalgeddon 2 £»ºÚ¿ÍÀûÓÃDrupalgeddon2©¶´¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø £»Ñо¿ÍŶӷ¢ÏÖÖ¼ÔÚÇÔÈ¡È«Çò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret £»Î¢ÈíÐû²¼¸ü¶à¹ØÓÚIntel CPU Spectre©¶´µÄ΢´úÂë¸üС£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Foxit Reader Text AnnotationsÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´

        Foxit Reader Text Annotations´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.foxitsoftware.com/support/security-bulletins.php
2¡¢DrupalÔ¶³Ì´úÂëÖ´ÐЩ¶´

        Drupal¶à¸ö×Óϵͳ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.drupal.org/sa-core-2018-002
3¡¢Apache Tika±êÌâÃüÁî×¢È멶´

        Apache Tika´¦ÖýṹµÄ±êÌâ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÔÚtika-serverÉÏÖ´ÐÐÈÎÒâÃüÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca@%3Cdev.tika.apache.org%3E
4¡¢Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç³ö©¶´

        Advantech WebAccess HMI Designer´¦ÖÃPM3Îļþ´æÔڶѻº³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://webaccess.advantech.com/product.php
5¡¢D-Link DIR-615 / TracerouteÈÎÒâ´úÂëÖ´ÐЩ¶´

        D-Link DIR-615 / Traceroute´æÔÚÊäÈëÑéÖ¤Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄHOST×Ö¶ÎÊý¾Ý£¬Ö´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://github.com/imsebao/404team/blob/master/dlink/dlink_dir615_rce.md


Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢ÃÀSunTrustÒøÐÐÇ°¹ÍÔ±ÇÔÈ¡Ô¼150Íò¿Í»§µÄ¸öÈËÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÃÀ¹úSunTrustÒøÐеÄCEO William RogersÔÚýÌåÐû²¼»áÉÏÌåÏÖ£¬¸ÃÒøÐз¢ÏÖÒ»ÃûÇ°¹ÍÔ±ÇÔÈ¡ÁËÔ¼150Íò¿Í»§µÄ¸öÈËÐÅÏ¢²¢½«ÕâЩÐÅÏ¢¹²Ïí¸øµÚÈý·½·¸×ïÍŻ鶵ÄÐÅÏ¢°üÂÞ¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÕË»§Óà¶î¡£SunTrust³Æ¿Í»§µÄÃÜÂë¡¢Éç±£ºÅÂë¡¢Õ˺š¢ID»ò¼ÝÕÕºÅÂ벢δй¶¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/suntrust-bank-says-former-employee-stole-details-on-15-million-customers/

2¡¢Ñо¿ÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstik¿ªÊ¼´ó¹æÄ£ÀûÓ鶴Drupalgeddon 2

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Äþ¾²Ñо¿ÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÒѾ­×ªÒƵ½ÀûÓÃDrupalgeddon 2©¶´£¨CVE-2018-7600£©Ìᳫ´ó¹æÄ£¹¥»÷¡£Ñ¬È¾Ä¿±êÖ÷»úºó£¬¹¥»÷Õß½«Ê¹Óö¨ÖƵĶñÒâÈí¼þTsunamiÌᳫDDoS¹¥»÷¡¢°²×°ÃÅÂÞ±ÒÍÚ¿óÈí¼þXMRig»òDash±ÒÍÚ¿óÈí¼þCGMiner¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/big-iot-botnet-starts-large-scale-exploitation-of-drupalgeddon-2-vulnerability/

3¡¢ºÚ¿ÍÀûÓÃDrupalgeddon2©¶´¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÎÚ¿ËÀ¼ÍøÂ羯²ìÅ®·¢ÑÔÈËYulia Kvitko³ÆÕâһʼþÊÇ¡°ÁæØꡱµÄ£¬Ä¿Ç°µ¼Ö¸ò¿ÃÅÍøÕ¾Òѱ»Ëø¶¨¡£¹¥»÷ÕßËƺõÀûÓÃDrupalgeddon2£¬ÕâÊÇÒ»¸öÓ°Ïì´ó¶àÊýDrupalÍøÕ¾µÄµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£

        Ô­aÁ´½Ó£ºhttps://threatpost.com/ransomware-attack-hits-ukrainian-energy-ministry-exploiting-drupalgeddon2/131373/

4¡¢Ñо¿ÍŶӷ¢ÏÖÖ¼ÔÚÇÔÈ¡È«Çò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        McAfeeÑо¿ÍŶÓÐû²¼¹ØÓÚ¶ñÒâ»î¶¯Operation GhostSecretµÄ·ÖÎö³ÂËß¡£GhostSecretÖ¼ÔÚÇÔÈ¡È«Çò¶à¸öÐÐÒµµÄÊý¾Ý£¬°üÂÞÒªº¦»ù´¡ÉèÊ©¡¢ÓéÀÖ¡¢½ðÈÚ¡¢Ò½ÁƱ£½¡ÒÔ¼°µçÐÅ¡£GhostSecretʹÓõÄÖ²ÈëÎï¡¢¹¤¾ßºÍ¶ñÒâÈí¼þ±äÖÖÓë¹ú¼Ò×ÊÖúµÄ·¸×ïÍÅ»ïHidden Cobra´æÔÚ¹ØÁª¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide

5¡¢Î¢ÈíÐû²¼¸ü¶à¹ØÓÚIntel CPU Spectre©¶´µÄ΢´úÂë¸üÐÂ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ΢ÈíÐû²¼¸ü¶à¹ØÓÚSpectre©¶´µÄCPU΢´úÂë¸üУ¬½«¸Ã©¶´µÄÐÞ¸´½øÒ»²½À©Õ¹µ½Intel CPUµÄBroadwellºÍHaswellƽ̨¡£´Ë´Î¸üаüÂÞKB4091666ºÍKB4078407Á½¸ö²¹¶¡°ü£¬¾ù¿É´ÓMicrosoft Update CatalogÃÅ»§ÍøÕ¾ÊÖ¶¯ÏÂÔØ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/microsoft-issues-more-spectre-updates-for-intel-cpus/131468/