ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ28ÖÜ
°ä²¼¹¦·ò 2018-07-16Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê07ÔÂ09ÈÕÖÁ15ÈÕ¹²ÊÕ¼°²È«·ì϶63¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Edge Chakra¾ç±¾ÒýÇæÔ¶³ÌÄÚ´æ·ÛËé·ì϶£»£»£»£»£»Microsoft Skype for Business CVE-2018-8311Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»Adobe Acrobat/Reader CVE-2018-4888¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶£»£»£»£»£»TP-Link TL-WR841N CVE-2018-12577ºÅÁî×¢Èë·ì϶£»£»£»£»£»Desdev DedeCMSËÁÒâÎļþÉÏ´«·ì϶¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀ¹ú¿¨Ë¹µØÓòµÄÒ½ÁÆÖÐÐÄÔ⵽δ֪ÀÕË÷Èí¼þµÄ¹¥»÷£»£»£»£»£»VSDC¹ÙÍø1¸öÔÂÄÚÈý´ÎÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ÆäÈí¼þÏÂÔØÁ´½Ó±»½Ù³Ö£»£»£»£»£»Chrome²å¼þHola VPNÔ⺧£¬£¬£¬£¬£¬Ô²å¼þ±»Ö²Èë¶ñÒâ´úÂ룻£»£»£»£»TimehopÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬³¬¹ý2100ÍòÓû§µÄÊý¾Ýй¶£»£»£»£»£»Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Microsoft Edge Chakra¾ç±¾ÒýÇæÔ¶³ÌÄÚ´æ·ÛËé·ì϶
Microsoft EdgeChakra¾ç±¾ÒýÇæÃ»ÓÐÕýÈ·µÄ´¦ÖÃÄÚ´æÖеĶÔÏ󣬣¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8294
2¡¢Microsoft Skype for Business CVE-2018-8311Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Skype for Business 2016ûÓÐÕýÈ·µÄ¹ýÂËÌØÔìµÄÄÚÈÝ£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8311
3¡¢Adobe Acrobat/Reader CVE-2018-4888¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶
Adobe Acrobat/Reader XFAÒýÇæÊµÏÖ´æÔÚ¿ªÊͺóÀûÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-02.html
4¡¢TP-Link TL-WR841N CVE-2018-12577ºÅÁî×¢Èë·ì϶
TP-Link TL-WR841N Ping¼°TracerouteÖ°ÄÜ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://software-talk.org/blog/2018/06/tplink-wr841n-code-exec-cve-2018-12577/
5¡¢Desdev DedeCMSËÁÒâÎļþÉÏ´«·ì϶
DedeCMS dede/file_manage_control.phpÎļþ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄupfile1¡¯²ÎÊýÒªÇ󣬣¬£¬£¬£¬ÉÏ´«ËÁÒâÎļþ¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/SukaraLin/php_code_audit_project/blob/master/dedecms/dedecms%20v5.7%20sp2%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1.md
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÃÀ¹ú¿¨Ë¹µØÓòµÄÒ½ÁÆÖÐÐÄÔ⵽δ֪ÀÕË÷Èí¼þµÄ¹¥»÷
ÃÀ¹úÃÜËÕÀïÖÝ¿¨Ë¹µØÓòµÄÒ½ÁÆÖÐÐÄ³ÆÆäÔ⵽δ֪ÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬£¬£¬£¬ÆäÄÚ²¿Í¨Ñ¶ÏµÍ³ºÍµç×Ó½¡È«µµ°¸ÏµÍ³£¨EHR£©ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¸ÃÒ½ÁÆÖÐÐijÆÃ»ÓÐÖ¤¾ÝÅú×¢»¼ÕßµÄÊý¾Ý±»½Ó¼û¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹²»Ã÷ÏÔÆäÍÆËã»ú/·þÎñÆ÷ÈôºÎ±»Ï°È¾£¬£¬£¬£¬£¬µ«Óйط¨Âɲ¿ÃÅÒѾȾָ½øÐе÷²é¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cass-regional-medical-center-hit-with-unidentified-ransomware/
2¡¢VSDC¹ÙÍø1¸öÔÂÄÚÈý´ÎÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ÆäÈí¼þÏÂÔØÁ´½Ó±»½Ù³Ö
VSDCÊÇÒ»¼ÒÌṩÃâ·ÑÊÓÆµ±à×ëÈí¼þµÄ¹«Ë¾£¬£¬£¬£¬£¬Æä¹ÙÍøÔÚ1¸öÔÂÄÚÈý´ÎÔâµ½ºÚ¿ÍÈëÇÖ£¨6ÔÂ18ÈÕ¡¢7ÔÂ2ÈÕºÍ7ÔÂ6ÈÕ£©£¬£¬£¬£¬£¬¹¥»÷Õß½«ÆäVSDCÈí¼þµÄÏÂÔØÁ´½Ó´úÌæÎª¶ñÒâÁ´½Ó£¬£¬£¬£¬£¬±ðÀ뽫Óû§³Á¶¨ÏòÖÁÈý¸ö¶ñÒâÈí¼þ£¨Ò»¸öÓÃÓÚÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Ò»¸ö¼üÅ̼ͼÆ÷ºÍÒ»¸öÔ¶¿ØÄ¾ÂíRAT£©¡£¡£¡£¡£¡£¡£¡£VSDCÈ·ÈÏÁËÕâЩÊÂÎñ£¬£¬£¬£¬£¬²¢³ÆÆäÒѾ½¨¸´ÁËÍøÕ¾¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/popular-software-site-hacked-to-redirect-users-to-keylogger-infostealer-more/
3¡¢Chrome²å¼þHola VPNÔ⺧£¬£¬£¬£¬£¬Ô²å¼þ±»Ö²Èë¶ñÒâ´úÂë
Chrome²å¼þHola VPNµÄ¿ª·¢ÕßÕË»§ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Æä²å¼þ±»Ö²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬ÓÃÓÚ½«MyEtherWallet.comÍøÕ¾µÄÓû§³Á¶¨ÏòÖÁ´¹µöÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÔÚ7ÔÂ9ÈÕ£¬£¬£¬£¬£¬¹²³ÖÐøÁË5¸öÓ×ʱ£¬£¬£¬£¬£¬Ä¿Ç°¸Ã²å¼þÒѸ´ÔÖÁ¸É¾»µÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£Hola VPNÍŶÓûÓÐй©¹¥»÷ÕßÈôºÎ½øÈëÆäChrome¿ª·¢ÕßÕË»§¡£¡£¡£¡£¡£¡£¡£MEWÍŶÓÔÚ¶½´ÙʹÓô˲å¼þµÄÓû§½«Æä¼ÓÃÜÇ®±Ò×ªÒÆÖÁеÄÕË»§£¬£¬£¬£¬£¬ÒÔÈ·±£°²È«¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-breaches-hola-vpn-chrome-extension-to-go-after-cryptocurrency-wallet-site/
4¡¢TimehopÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬³¬¹ý2100ÍòÓû§µÄÊý¾Ýй¶
Gentoo Linux¿ª·¢ÍŶӰ䲼¹ØÓÚGitHubÕË»§ÔâºÚ¿ÍÈëÇÖÊÂÎñµÄµ÷²é»ã±¨¡£¡£¡£¡£¡£¡£¡£¸ÃÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂë²Â²â»ñµÃÆäGitHubÕË»§µÄÃÜÂë¼°ÖÎÀíȨÏÞ£¬£¬£¬£¬£¬µ÷²é·¢ÏÖµÄÎÊÌ⻹Ô̺¬Î´Ñ¡È¡Ë«³É·ÖÈÏÖ¤¡¢Î´±£ÁôGitHub Organization¾ßÌåÐÅÏ¢µÄ±¸·ÝÒÔ¼°systemd repoÖ±½Ó´æ´¢ÔÚGitHubÉÏ¡£¡£¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬GentooºÍGithub¶Ô¸ÃÊÂÎñµÄÏìÓ¦½Ïʵʱ£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Ö»³ÖÐøÁËÔ¼70·ÖÖÓ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/timehop-data-breach.html
5¡¢Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÊý¾Ýй¶
µÂ¹úÍйܷþÎñÌṩÉÌDomainFactoryÈ·ÈÏÔÚ1Ô·ݲúÉúÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÓ×ÎÒÊý¾Ýй¶£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Î´Åû¶¾ßÌåµÄÊý×Ö¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢¹«Ë¾Ãû¡¢ÕË»§ID¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢ÒøÐп¨Õ˺ŵÈÐÅÏ¢£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×Ó¿ÉÀûÓÃÕâЩÊý¾Ý½øÐÐÓÐÕë¶ÔÐÔµÄÉç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£¡£¡£DomainFactory½¨ÒéËùÓÐЧ»§Åú¸ÄÆäÃÜÂë¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/web-hosting-server-hack.html


¾©¹«Íø°²±¸11010802024551ºÅ