ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ17ÖÜ
Ðû²¼Ê±¼ä 2018-05-02
Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2018Äê04ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´43¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Text AnnotationsÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£»DrupalÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Apache Tika±êÌâÃüÁî×¢È멶´£»Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç³ö©¶´£»D-Link DIR-615 / TracerouteÈÎÒâ´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀSunTrustÒøÐÐÇ°¹ÍÔ±ÇÔÈ¡Ô¼150Íò¿Í»§µÄ¸öÈËÐÅÏ¢£»Ñо¿ÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstik¿ªÊ¼´ó¹æÄ£ÀûÓ鶴Drupalgeddon 2£»ºÚ¿ÍÀûÓÃDrupalgeddon2©¶´¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø£»Ñо¿ÍŶӷ¢ÏÖÖ¼ÔÚÇÔÈ¡È«Çò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret£»Î¢ÈíÐû²¼¸ü¶à¹ØÓÚIntel CPU Spectre©¶´µÄ΢´úÂë¸üС£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Foxit Reader Text AnnotationsÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´
Foxit Reader Text Annotations´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.foxitsoftware.com/support/security-bulletins.php
2¡¢DrupalÔ¶³Ì´úÂëÖ´ÐЩ¶´
Drupal¶à¸ö×Óϵͳ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.drupal.org/sa-core-2018-002
3¡¢Apache Tika±êÌâÃüÁî×¢È멶´
Apache Tika´¦ÖýṹµÄ±êÌâ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÔÚtika-serverÉÏÖ´ÐÐÈÎÒâÃüÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca@%3Cdev.tika.apache.org%3E
4¡¢Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç³ö©¶´
Advantech WebAccess HMI Designer´¦ÖÃPM3Îļþ´æÔڶѻº³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://webaccess.advantech.com/product.php
5¡¢D-Link DIR-615 / TracerouteÈÎÒâ´úÂëÖ´ÐЩ¶´
D-Link DIR-615 / Traceroute´æÔÚÊäÈëÑéÖ¤Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄHOST×Ö¶ÎÊý¾Ý£¬Ö´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://github.com/imsebao/404team/blob/master/dlink/dlink_dir615_rce.md
Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢ÃÀSunTrustÒøÐÐÇ°¹ÍÔ±ÇÔÈ¡Ô¼150Íò¿Í»§µÄ¸öÈËÐÅÏ¢

ÃÀ¹úSunTrustÒøÐеÄCEO William RogersÔÚýÌåÐû²¼»áÉÏÌåÏÖ£¬¸ÃÒøÐз¢ÏÖÒ»ÃûÇ°¹ÍÔ±ÇÔÈ¡ÁËÔ¼150Íò¿Í»§µÄ¸öÈËÐÅÏ¢²¢½«ÕâЩÐÅÏ¢¹²Ïí¸øµÚÈý·½·¸×ïÍŻ鶵ÄÐÅÏ¢°üÂÞ¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÕË»§Óà¶î¡£SunTrust³Æ¿Í»§µÄÃÜÂë¡¢Éç±£ºÅÂë¡¢Õ˺š¢ID»ò¼ÝÕÕºÅÂ벢δй¶¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/suntrust-bank-says-former-employee-stole-details-on-15-million-customers/
2¡¢Ñо¿ÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstik¿ªÊ¼´ó¹æÄ£ÀûÓ鶴Drupalgeddon 2

Äþ¾²Ñо¿ÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÒѾתÒƵ½ÀûÓÃDrupalgeddon 2©¶´£¨CVE-2018-7600£©Ìᳫ´ó¹æÄ£¹¥»÷¡£Ñ¬È¾Ä¿±êÖ÷»úºó£¬¹¥»÷Õß½«Ê¹Óö¨ÖƵĶñÒâÈí¼þTsunamiÌᳫDDoS¹¥»÷¡¢°²×°ÃÅÂÞ±ÒÍÚ¿óÈí¼þXMRig»òDash±ÒÍÚ¿óÈí¼þCGMiner¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/big-iot-botnet-starts-large-scale-exploitation-of-drupalgeddon-2-vulnerability/
3¡¢ºÚ¿ÍÀûÓÃDrupalgeddon2©¶´¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø

ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÎÚ¿ËÀ¼ÍøÂ羯²ìÅ®·¢ÑÔÈËYulia Kvitko³ÆÕâһʼþÊÇ¡°ÁæØꡱµÄ£¬Ä¿Ç°µ¼Ö¸ò¿ÃÅÍøÕ¾Òѱ»Ëø¶¨¡£¹¥»÷ÕßËƺõÀûÓÃDrupalgeddon2£¬ÕâÊÇÒ»¸öÓ°Ïì´ó¶àÊýDrupalÍøÕ¾µÄµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£
ÔaÁ´½Ó£ºhttps://threatpost.com/ransomware-attack-hits-ukrainian-energy-ministry-exploiting-drupalgeddon2/131373/
4¡¢Ñо¿ÍŶӷ¢ÏÖÖ¼ÔÚÇÔÈ¡È«Çò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret

McAfeeÑо¿ÍŶÓÐû²¼¹ØÓÚ¶ñÒâ»î¶¯Operation GhostSecretµÄ·ÖÎö³ÂËß¡£GhostSecretÖ¼ÔÚÇÔÈ¡È«Çò¶à¸öÐÐÒµµÄÊý¾Ý£¬°üÂÞÒªº¦»ù´¡ÉèÊ©¡¢ÓéÀÖ¡¢½ðÈÚ¡¢Ò½ÁƱ£½¡ÒÔ¼°µçÐÅ¡£GhostSecretʹÓõÄÖ²ÈëÎï¡¢¹¤¾ßºÍ¶ñÒâÈí¼þ±äÖÖÓë¹ú¼Ò×ÊÖúµÄ·¸×ïÍÅ»ïHidden Cobra´æÔÚ¹ØÁª¡£
ÔÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide
5¡¢Î¢ÈíÐû²¼¸ü¶à¹ØÓÚIntel CPU Spectre©¶´µÄ΢´úÂë¸üÐÂ

΢ÈíÐû²¼¸ü¶à¹ØÓÚSpectre©¶´µÄCPU΢´úÂë¸üУ¬½«¸Ã©¶´µÄÐÞ¸´½øÒ»²½À©Õ¹µ½Intel CPUµÄBroadwellºÍHaswellƽ̨¡£´Ë´Î¸üаüÂÞKB4091666ºÍKB4078407Á½¸ö²¹¶¡°ü£¬¾ù¿É´ÓMicrosoft Update CatalogÃÅ»§ÍøÕ¾ÊÖ¶¯ÏÂÔØ¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/microsoft-issues-more-spectre-updates-for-intel-cpus/131468/