ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ39ÖÜ
Ðû²¼Ê±¼ä 2018-10-03Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇFacebookÔâ0day©¶´¹¥»÷£¬Ô¼5000ÍòÓû§µÄ·ÃÎÊÁîÅƱ»ÇÔ£»Äþ¾²Ñо¿ÍŶÓÐû²¼¹ØÓÚUSBÍþвÏÖ×´µÄ·ÖÎö³ÂËߣ»¿¨°Í˹»ùÐû²¼¹ØÓÚICSϵͳÖеÄRAT·çÏյķÖÎö³ÂËߣ»Ê±×°ÁãÊÛÉÌSHEINÔâºÚ¿ÍÈëÇÖ£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶£»ÔƼÆË㹫˾ZohoµÄÓòÃû±»½ûÓýüÁ½Ð¡Ê±£¬Ô¼3000ÍòÓû§ÊÜÓ°Ïì¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1. Foxit Reader for Windows¶à¸ö¹¤¾ßÊͷźóʹÓ鶴
Foxit Reader for Windows Calculateʼþ´¦ÖôæÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
2. Wecon LeviStudioU CVE-2018-10610»º³åÇøÒç³ö©¶´
Wecon LeviStudioU TIFFͼÏñµÄ½âÎö´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
3. Cisco Video Surveillance Manager ApplianceĬÈÏÃÜÂ멶´
Cisco Video Surveillance Manager Appliance ROOTÕË»§Ê¹ÓÃÓ²±àÂëƾ֤£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐÈÎÒâÃüÁî¡£
4. ISC BIND CVE-2018-5741Äþ¾²ÏÞÖÆÈƹý©¶´
ISC BINDʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÈƹýÄþ¾²ÏÞÖÆ£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£
5. DedeCMS XML×¢ÈëÈÎÒâ´úÂ멶´
DedeCMS´¦ÖÃ<file type='file' name='../×Ö·û´®´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Ö´ÐÐÈÎÒâ´úÂë¡£
Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö

9ÔÂ28ÈÕFacebookÈ·ÈÏÆäÔâµ½ºÚ¿Í¹¥»÷£¬¹¥»÷ÕßÀûÓÃ0day©¶´ÇÔÈ¡ÁËÁè¼Ý5000ÍòÓû§µÄ·ÃÎÊÁîÅÆ¡£¸Ã©¶´´æÔÚÓÚFacebookµÄView As¹¦Ð§ÖУ¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Óû§µÄ·ÃÎÊÁîÅƲ¢·ÃÎÊÓû§µÄ˽ÈËÐÅÏ¢£¬¶øÎÞÐèÕË»§ÃÜÂë»òË«ÒòËØÑéÖ¤Âë¡£FacebookÒѽÓÄÉ´ëÊ©×ÊÖú½ü9000ÍòÓû§ÖØÖÃÁË·ÃÎÊÁîÅÆ£¬²¢½ûÓÃÁËView As¹¦Ð§¡£ÓÉÓÚÊÓ²ìÈÔ´¦ÓÚÔçÆڽ׶Σ¬FacebookÉÐδȷ¶¨ÊÇ·ñÓÐÈκÎÕË»§±»ÀÄÓûòÐÅÏ¢±»·ÃÎÊ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/09/facebook-account-hack.html
2¡¢Äþ¾²Ñо¿ÍŶÓÐû²¼¹ØÓÚUSBÍþвÏÖ×´µÄ·ÖÎö³ÂËß
ÔÎÄÁ´½Ó£º
https://securelist.com/usb-threats-from-malware-to-miners/87989/
3¡¢¿¨°Í˹»ùÐû²¼¹ØÓÚICSϵͳÖеÄRAT·çÏյķÖÎö³ÂËß
¿¨°Í˹»ùʵÑéÊÒÐû²¼¹ØÓÚICSÖеÄRAT·çÏյķÖÎö³ÂËß¡£Ô¶³Ì¹ÜÀí¹¤¾ß£¨RAT£©±»¹ã·ºÓÃÓÚ¹¤ÒµÍøÂçÖ®ÖУ¬ÓÃÓÚ½øÐÐICS¼à²â¡¢¿ØÖƺÍά»¤¡£Ô¶³Ì²Ù×÷ICSµÄÄÜÁ¦¿ÉÒÔ´ó´ó½µµÍά»¤³É±¾£¬µ«²»ÊÜ¿ØÖƵÄÔ¶³Ì·ÃÎÊ¡¢ÎÞ·¨100%µØÌṩԶ³Ì¿Í»§¶ËµÄºÏ·¨ÐÔÑéÖ¤ÒÔ¼°RAT´úÂëºÍÅäÖÃÖеÄ©¶´¶¼´ó´óÔö¼ÓÁ˹¥»÷Ãæ¡£Óë´Ëͬʱ£¬¹¥»÷ÕßÔ½À´Ô½¶àµØʹÓÃRATºÍÆäËüºÏ·¨¹¤¾ßÀ´ÑÚ¸ÇÆä¶ñÒâ»î¶¯£¬Ê¹µÃ¶Ô¶ñÒâ»î¶¯½øÐйéÒòÔ½·¢À§ÄÑ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/threats-posed-by-using-rats-in-ics/88011/
4¡¢Ê±×°ÁãÊÛÉÌSHEINÔâºÚ¿ÍÈëÇÖ£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶
ʱװÁãÊÛÉÌSHEINÉÏÖÜÎåÐû²¼ÆäÔâµ½ºÚ¿Í¹¥»÷£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶¡£¹¥»÷ʼþ·¢ÉúÔÚÏÄÌ죬¼´6ÔµÄij¸öʱºò£¬¹¥»÷Õß·ÃÎÊÁËÓû§µÄµç×ÓÓʼþµØÖ·ºÍ¼ÓÃܵÄÃÜÂë¡£¸Ã¹«Ë¾ÓÚ8ÔÂ22ÈÕ·¢ÏÖÁËÕâһʼþ£¬²¢ÕýÔÚÁªÏµÊÜÓ°ÏìµÄÓû§ÐÞ¸ÄÆäÃÜÂ롣鶵ÄÊý¾ÝÖв»°üÂÞÈκÎÐÅÓÿ¨ÐÅÏ¢¡£¸Ã¹«Ë¾ÕýÔÚ½øÐнøÒ»²½µÄÊӲ졣
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/shein-fashion-retailer-announces-breach-affecting-6-42-million-users/
5¡¢ÔƼÆË㹫˾ZohoµÄÓòÃû±»½ûÓýüÁ½Ð¡Ê±£¬Ô¼3000ÍòÓû§ÊÜÓ°Ïì
Ó¡¶ÈÖªÃûÔƼÆËã¿Æ¼¼¹«Ë¾ZohoµÄÓòÃû£¨zoho.com£©±»ÆäÓòÃû×¢²áÉÌTierraNet½ûÓýüÁ½¸öСʱ£¬ÔÚ´ËÆÚ¼äÓû§±»Öض¨ÏòÖÁÒ»¸ö¿Õ°×Ò³Ã棬Լ3000ÍòÓû§Êܵ½Ó°Ï졣ƾ¾ÝTierraNetµÄ˵·¨£¬Æä¶à´ÎÊÕµ½¹ØÓÚÀûÓÃZohoÓʼþ·þÎñ·¢Ë͵öÓãÓʼþµÄͶËߣ¬µ«ÔÚÊý´ÎÓëZohoÏàͬºó¸ÃÎÊÌâûÓеõ½½â¾ö£¬×îÖÕÒ»Ì××Ô¶¯»¯ÏµÍ³µ¼ÖÂÁË´ËʼþµÄ·¢Éú¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/domain-registrar-oversteps-taking-down-zoho-domain-impacts-over-30mil-users/
ÉùÃ÷£º±¾×ÊѶÓɶ«Éƽ̨άËûÃüÄþ¾²Ð¡×é·ÒëºÍÕûÀí