ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ14ÖÜ

°ä²¼¹¦·ò 2018-04-09

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ02ÈÕÖÁ06ÈÕ¹²ÊÕ¼°²È«·ì϶68¸ö£¬£¬£¬ £¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»£»£»£»£»£»Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶£»£»£»£»£»£»Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶¡£ ¡£¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬£¬£¬ £¬ £¬£¬£¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ£»£»£»£»£»£»Panera BreadÓû§Êý¾Ýй¶£¬£¬£¬ £¬ £¬£¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ï죻£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ£»£»£»£»£»£»·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬ £¬£¬£¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶£»£»£»£»£»£»×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶¡£ ¡£¡£¡£¡£¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬ £¬ £¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£ ¡£¡£¡£¡£¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Apple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶

        Apple MacOS "CoreTypes"×é¼þ´æÔÚ°²È«·ì϶£¬£¬£¬ £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬£¬ £¬ £¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬ £¬ £¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶ÈÖ´ÐÐδÊÚȨ²Ù×÷¡£ ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208692
2¡¢Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶

        Apple Safari WEBKIT×é¼þ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬ £¬ £¬£¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬£¬ £¬ £¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬ £¬ £¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208695
3¡¢Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶

        Cisco IOS XE SoftwareµÄCLI½âÎöÆ÷ÔÚʵÏÖÉÏ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬ £¬ £¬£¬£¬±¾µØµØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬ £¬£¬£¬ÒÔrootȨÏÞÖ´ÐкÅÁî¡£ ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-cmdinj
4¡¢Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶

        Schneider Electric Modicon PLC FTP·þÎñÆ÷δÏ޶ȺÅÁî²ÎÊý³¤¶È£¬£¬£¬ £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬ £¬£¬£¬½øÐлؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/
5¡¢D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶

        D-Link DSL-3782 'set Diagnostics_Entry'´¦ÖÃÊäÈëÖµ´æÔÚ°²È«·ì϶£¬£¬£¬ £¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬ £¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/SECFORCE/CVE-2018-8941


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬£¬£¬ £¬ £¬£¬£¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        Hudson's Bay CompanyÔÚÖÜÈÕÈ·ÈϳÆ£¬£¬£¬ £¬ £¬£¬£¬Æä±±ÃÀµØÓòµÄ×Ó¹«Ë¾Saks Fifth Avenue¡¢Saks Off 5THÒÔ¼°Lord£¦TaylorµÄ²¿ÃÅÓû§µÄÐÅÓþ¿¨ÐÅϢй¶£¬£¬£¬ £¬ £¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁË´Ó2017Äê5Ôµ½2018Äê3ÔÂÔÚ±±ÃÀÉÌµê½øÐйýÖ§¸¶µÄÔ¼500ÍòÕÅÐÅÓþ¿¨¡£ ¡£¡£¡£¡£¡£Ä¿Ç°ÐÅÓþ¿¨ÐÅÏ¢ÊÇΨһй¶µÄÊý¾Ý£¬£¬£¬ £¬ £¬£¬£¬Saks Fifth AvenueÔÚÉêÃ÷ÖаµÊ¾£¬£¬£¬ £¬ £¬£¬£¬Ã»Óм£ÏóÅú×¢Éç»á±£ÏÕºÅÂë»òÉç»á±£ÏÕºÅÂë¡¢¼ÝÕÕºÅÂë»òÃÜÂëÊܵ½Ó°Ïì¡£ ¡£¡£¡£¡£¡£°²È«³§ÉÌGemini Advisory³Æ¸ÃÊÂÎñÓëºÚ¿ÍÍÅ»ïJokerStash£¨Ò²±»³ÆÎªFIN7£©ÓйØ¡£ ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/credit-card-data-swiped-from-5m-saks-lord-taylor-customers/130877/

2¡¢Panera BreadÓû§Êý¾Ýй¶£¬£¬£¬ £¬ £¬£¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        °²È«×êÑÐÔ±Brian Krebs»ã±¨³ÆÃæ°üÁ¬ËøµêPanera BreadµÄÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍòÓû§µÄ¼Í¼£¬£¬£¬ £¬ £¬£¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢ÉúÈÕºÍÐÅÓþ¿¨ºÅÂëµÄ×îºóËÄλÊý×Ö¡£ ¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÖ±µ½ÖÜÒ»»¹Äܹ»ÔÚPanerabread.comÉÏÒÔ´¿Îı¾µÄ´ó¾Ö½Ó¼û¡£ ¡£¡£¡£¡£¡£°²È«×êÑÐÔ±Dylan Houlihan×î³õÓÚ2017Äê8ÔÂÏòPanera»ã±¨Á˸Ãй¶ÊÂÎñ£¬£¬£¬ £¬ £¬£¬£¬µ«¸Ã¹«Ë¾²¢Ã»ÓвÉÈ¡Ðж¯À´½â¾öÎÊÌâ¡£ ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2018/04/panerabread-com-breach-could-have-impacted-millions/

3¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        Flashpoint×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ1000¸öMagentoÖÎÀíÃæ°å±»ºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬ £¬£¬£¬¹¥»÷Õßͨ¹ý±©Á¦¹¥»÷»ñµÃ½Ó¼ûȨÏÞ£¬£¬£¬ £¬ £¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨ºÅÂëºÍ×°ÖöñÒâÈí¼þ£¨Êý¾ÝÇÔÈ¡Èí¼þAZORultºÍ¶ñÒâ¿ó¹¤Rarog£©¡£ ¡£¡£¡£¡£¡£Flashpoint³Æ´óÎÞÊýÍøÕ¾ÊôÓÚ½ÌÓýºÍÒ½ÁƱ£½¡ÐÐÒµ£¬£¬£¬ £¬ £¬£¬£¬IPµØÖ·ÖØÒªÉ¢²¼ÔÚÃÀ¹úºÍÅ·ÖÞ¡£ ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.flashpoint-intel.com/blog/compromised-magento-sites-delivering-malware/

4¡¢·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬ £¬£¬£¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ¾Ý±¾µØÃ½Ì屨·£¬£¬£¬ £¬ £¬£¬£¬·ÒÀ¼Ê·ÉϵÚÈý´óÊý¾Ýй¶ÊÂÎñµ¼Ö³¬¹ý13ÍòÃû·ÒÀ¼¹«ÃñµÄÍ´´¦Ð¹Â¶¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßÈëÇÖÁËHelsingin Uusyrityskeskus¹«Ë¾µÄÍøÕ¾£¨http://liiketoimintasuunnitelma.com£©£¬£¬£¬ £¬ £¬£¬£¬ÇÔÈ¡Á˳¬¹ý13ÍòÓû§µÄÃ÷ÎĵǼÃûºÍÃÜÂë¡£ ¡£¡£¡£¡£¡£ÕâЩÓû§ÃûºÍÃÜÂëÒÔ´¿Îı¾µÄ´ó¾Ö´æ´¢ÔÚ¸ÃÍøÕ¾ÉÏ£¬£¬£¬ £¬ £¬£¬£¬²¢Ã»ÓÐʹÓÃÈκιþÏ£¼ÓÃÜ¡£ ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/04/helsingin-uusyrityskeskus-hack.html

5¡¢×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ˼¿ÆTalos×êÑÐÍŶÓÔÚNatus NeuroWorksÈí¼þÖз¢ÏÖ¶à¸ö°²È«·ì϶£¬£¬£¬ £¬ £¬£¬£¬NatusµÄÒ½ÁƲúÆ·Xltek EEGÊܵ½Ó°Ïì¡£ ¡£¡£¡£¡£¡£·ì϶ÁìÓòÔ̺¬4¸öµ¼Ö´úÂëÖ´Ðеķì϶ºÍ1¸öµ¼Ö»ؾø·þÎñµÄ·ì϶¡£ ¡£¡£¡£¡£¡£NatusÔÚNeuroworks 8.5 GMA2Öн¨¸´ÁËÕâЩ·ì϶£¬£¬£¬ £¬ £¬£¬£¬½¨ÒéʹÓÃÕâЩÉ豸µÄÒ½ÁÆ»ú¹¹¾¡¿ì½øÐиüС£ ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttp://blog.talosintelligence.com/2018/04/vulnerability-spotlight-natus.html