ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ29ÖÜ
Ðû²¼Ê±¼ä 2018-07-23Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2018Äê07ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼Çå¾²Îó²î44¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇPivotal Spring FrameworkÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐÏÂÁî×¢ÈëÎó²î£»£»£»£»£»ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Dasan GPONÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÒøÐÐľÂíDorkbot¾íÍÁÖØÀ´£¬£¬£¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%£»£»£»£»£»¶íÂÞ˹ÔÚÌìϱʱ´úÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷£»£»£»£»£»Telefonica¹ÙÍøÎó²î¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶£»£»£»£»£»ÃÀѪҺ¼ì²âʵÑéÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ï죻£»£»£»£»¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ËðʧԼ100ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Pivotal Spring FrameworkÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Spring FrameworkʹÓÃspring-messagingÄ£¿£¿£¿£¿£¿£¿éÀ´ÊµÏÖSTOMPÊðÀíʱ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÐÂÎÅ£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.exploit-db.com/exploits/44796/
2¡¢Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐÏÂÁî×¢ÈëÎó²î
Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐWEB UI±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬×¢Èëí§ÒâSHELLÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180711-phone-webui-inject
3¡¢ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î
ManageEngine Exchange Reporter Plus Java servlet ¡®ADSHACluster¡¯ÔÚÖ´ÐС®bcp.exe¡¯Îļþ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâ¡®BCP_EXE¡¯²ÎÊýÇëÇ󣬣¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.manageengine.com/products/exchange-reports/release-notes.html
4¡¢Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î
Adobe Flash Player´¦Öóͷ£SWFÎļþ±£´æÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-24.html
5¡¢Dasan GPONÏÂÁî×¢ÈëÎó²î
Dasan GPON GponForm/diag_Form URI±£´æÉè¼ÆÎó²î£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ'dest_host¡¯²ÎÊýµÄdiag_action=pingÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/
Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÒøÐÐľÂíDorkbot¾íÍÁÖØÀ´£¬£¬£¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%
ƾ֤Check PointµÄ×îÐÂÊý¾Ý£¬£¬£¬£¬£¬ÒøÐÐľÂíDorkbotÔÚ2018Äê¾íÍÁÖØÀ´£¬£¬£¬£¬£¬³ÉΪһ¸öÑÏÖØµÄÍþв¡£¡£¡£¡£¡£¡£¡£Dorkbot×îÔç¿ÉÒÔ×·Ëݵ½2012Ä꣬£¬£¬£¬£¬ÆäÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÒøÐеǼƾ֤¡£¡£¡£¡£¡£¡£¡£ÔÚ2018ÄêÉϰëÄ꣬£¬£¬£¬£¬È«ÇòÒøÐжñÒâÈí¼þÊг¡Õ¼ÓÐǰÈýλµÄ»®·ÖÊÇRamnit£¨27£¥£©¡¢Dorkbot£¨25£¥£©ºÍZeus£¨13£¥£©¡£¡£¡£¡£¡£¡£¡£DorkbotÒѳÉΪ2018ÄêµÚ¶þ´óÁîÈËÍ·ÌÛµÄÒøÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/threatlist-6-year-old-dorkbot-banking-malware-resurfaces-as-big-threat/133898/
2¡¢¶íÂÞ˹ÔÚÌìϱʱ´úÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷
Ī˹¿ÆÊ±±¨±¨µÀ³Æ£¬£¬£¬£¬£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂçÇå¾²²¿·Ö£¬£¬£¬£¬£¬¸Ã²¿·ÖÔÚÌìϱʱ´ú¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸·¨»î¶¯£¬£¬£¬£¬£¬È·±£Á˽ÇÖðµÄÇå¾²¡£¡£¡£¡£¡£¡£¡£FireEyeÄÏÅ·ÊÖÒÕ×ܼàDavid GroutÌåÏÖËäÈ»ÕâÒ»Êý×ֺܸߣ¬£¬£¬£¬£¬µ«²¢²»³öÈËÒâÁÏ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷¿ÉÄܰüÀ¨ÔÚ½ÇÖðǰ¼¸ÖܾÍ×îÏȵÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬ÀýÈçµÍ¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÌìϱÖ÷ÌâÏà¹ØµÄ´ÙÏú»î¶¯£¨Èç¹ú¼Ò¶ÓÇòÒ£©µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/
3¡¢Telefonica¹ÙÍøÎó²î¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶
Î÷°àÑÀµçÐŹ«Ë¾TelefonicaµÄ¹Ì»°¡¢¿í´ø¼°¸¶·ÑµçÊÓÓªÒµMovistarµÄ¹ÙÍø±£´æÎó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£Movistar¹ÙÍøÉÏÓÃÓÚÉó²é·¢Æ±µÄÒ³ÃæµÄURLÖаüÀ¨ÁË·¢Æ±µÄID£¬£¬£¬£¬£¬ÈκÎÓû§¶¼¿ÉÒÔͨ¹ýÐ޸ĴËIDÀ´Éó²éÆäËüÕË»§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÐµÄGDPR»®¶¨£¬£¬£¬£¬£¬¸Ã¹«Ë¾¿ÉÄÜÃæÁÙ1000Íò~2000ÍòÅ·Ôª»òÏ൱ÓÚÆäÄêÓªÒµ¶î2%~4%µÄ·£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/telefonica-spain-exposed-the-personal-details-of-millions-of-customers/
4¡¢ÃÀѪҺ¼ì²âʵÑéÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ïì
±¾ÖÜÒ»ÃÀ¹ú×î´óµÄѪҺ¼ì²âʵÑéÊÒLabCorpÐû²¼ÆäÔÚÖÜĩʱ´úÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£¡£¡£LabCorp¹Ø±ÕÁ˲¿·ÖϵͳÒÔ¿ØÖƸÃÈëÇֻ£¬£¬£¬£¬£¬ÏÖÔÚ¸÷ϵͳ¹¦Ð§ÕýÔÚ»Ö¸´ÖС£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖûÓÐÖ¤¾ÝÅú×¢±¬·¢Á˶ÔÊý¾ÝµÄδÊÚȨ»á¼û£¬£¬£¬£¬£¬µ«Ã»ÓÐÅû¶¸ü¶àÏà¹ØÏ¸½Ú¡£¡£¡£¡£¡£¡£¡£ÓйØÕþ¸®ÕýÔÚ¾ÙÐÐÊÓ²ìÖ®ÖС£¡£¡£¡£¡£¡£¡£LabCorpÔÚÈ«ÇòÓµÓнü6ÍòÃûÔ±¹¤£¬£¬£¬£¬£¬ÆäÿÖܲâÊԵϼÕßÑù±¾Áè¼Ý250Íò¸ö£¬£¬£¬£¬£¬Òò´ËÊý¾Ýй¶µÄDZÔÚЧ¹û¿ÉÄÜÊÇÖØ´óµÄ£¬£¬£¬£¬£¬Êý°ÙÍòÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-network-of-labcorp-us-biggest-blood-testing-laboratories/
5¡¢¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ËðʧԼ100ÍòÃÀÔª
ƾ֤¶íÂÞ˹Çå¾²³§ÉÌGroup-IBµÄ±¨¸æ£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïMoneyTakerͨ¹ý·ÓÉÆ÷ÈëÇÖÁ˶íÂÞ˹PIRÒøÐеÄÍøÂ磬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÔ¼100ÍòÃÀÔªµÄ×ʽ𡣡£¡£¡£¡£¡£¡£Group-IBÈ·ÈϹ¥»÷ʼÓÚ2018Äê5ÔÂÏÂÑ®£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÈë¿ÚÊǹýʱµÄ·ÓÉÆ÷£¬£¬£¬£¬£¬¸Ã·ÓÉÆ÷ÓÐËíµÀ£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÖ±½Ó»á¼ûÒøÐеÄÍâµØÍøÂç¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ7ÔÂ3ÈÕ£¬£¬£¬£¬£¬PIRÒøÐеÄÔ±¹¤ÔÚÒ»ÌìºóµÄ7ÔÂ4ÈÕ·¢Ã÷ÁË´ó±ÊδÊÚȨµÄÉúÒ⣬£¬£¬£¬£¬µ«ÎªÊ±ÒÑÍí¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-russian-bank-and-steal-1-million-due-to-outdated-router/


¾©¹«Íø°²±¸11010802024551ºÅ