ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ29ÖÜ
°ä²¼¹¦·ò 2018-07-23Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê07ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼°²È«·ì϶44¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇPivotal Spring FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁкÅÁî×¢Èë·ì϶£»£»£»£»£»ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶£»£»£»£»£»Dasan GPONºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÒøÐÐľÂíDorkbot¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%£»£»£»£»£»¶íÂÞ˹ÔÚÊÀ½ç±ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷£»£»£»£»£»Telefonica¹ÙÍø·ì϶¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶£»£»£»£»£»ÃÀѪҺ¼ì²â³¢ÊÔÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ï죻£»£»£»£»¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ËðʧԼ100ÍòÃÀÔª¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Pivotal Spring FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶
Spring FrameworkʹÓÃspring-messagingÄ£¿£¿£¿£¿£¿£¿éÀ´ÊµÏÖSTOMP´úÀíʱ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.exploit-db.com/exploits/44796/
2¡¢Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁкÅÁî×¢Èë·ì϶
Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐWEB UI´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬×¢ÈëËÁÒâSHELLºÅÁî²¢Ö´ÐÓ×£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180711-phone-webui-inject
3¡¢ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´Ðзì϶
ManageEngine Exchange Reporter Plus Java servlet ¡®ADSHACluster¡¯ÔÚÖ´ÐÓ×®bcp.exe¡¯Îļþ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâ¡®BCP_EXE¡¯²ÎÊýÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.manageengine.com/products/exchange-reports/release-notes.html
4¡¢Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶
Adobe Flash Player´¦ÖÃSWFÎļþ´æÔÚÀàÐÍ»ìºÏ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-24.html
5¡¢Dasan GPONºÅÁî×¢Èë·ì϶
Dasan GPON GponForm/diag_Form URI´æÔÚÉè¼Æ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ'dest_host¡¯²ÎÊýµÄdiag_action=pingÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÒøÐÐľÂíDorkbot¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%
ƾ¾ÝCheck PointµÄ×îÐÂÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÒøÐÐľÂíDorkbotÔÚ2018Äê¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬£¬£¬³ÉΪһ¸öÑϳÁµÄÍþв¡£¡£¡£¡£¡£Dorkbot×îÔçÄܹ»×·Òäµ½2012Ä꣬£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÓÃÓÚÇÔÈ¡Óû§µÄÒøÐеǼʹ´¦¡£¡£¡£¡£¡£ÔÚ2018ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬£¬£¬È«ÇòÒøÐжñÒâÈí¼þÊг¡Õ¼¾ÝǰÈýλµÄ±ðÀëÊÇRamnit£¨27£¥£©¡¢Dorkbot£¨25£¥£©ºÍZeus£¨13£¥£©¡£¡£¡£¡£¡£DorkbotÒѳÉΪ2018ÄêµÚ¶þ´óÁîÈËÍ·ÌÛµÄÒøÐжñÒâÈí¼þ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/threatlist-6-year-old-dorkbot-banking-malware-resurfaces-as-big-threat/133898/
2¡¢¶íÂÞ˹ÔÚÊÀ½ç±ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷
Ī˹¿ÆÊ±±¨±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂ簲ȫÊýÃÅ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã²¿ÃÅÔÚÊÀ½ç±ÆÚ¼ä¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸×ï»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬È·±£Á˽ÇÖðµÄ°²È«¡£¡£¡£¡£¡£FireEyeÄÏÅ·¼¼Êõ×ܼàDavid Grout°µÊ¾¹ÌÈ»ÕâÒ»Êý×ֺܸߣ¬£¬£¬£¬£¬£¬£¬£¬µ«²¢²»³öºõÒâÁÏ¡£¡£¡£¡£¡£ÕâЩ¹¥»÷¿ÉÄÜÔ̺¬ÔÚ½ÇÖðǰ¼¸ÖÜ¾ÍÆðÍ·µÄÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÁ®¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÊÀ½ç±Ö÷ÌâÓйصĴÙÏú»î¶¯£¨Èç¹ú¶È¶ÓÇòÒ£©µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/
3¡¢Telefonica¹ÙÍø·ì϶¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶
Î÷°àÑÀµçÐŹ«Ë¾TelefonicaµÄ¹Ì»°¡¢¿í´ø¼°¸¶·ÑµçÊÓÒµÎñMovistarµÄ¹ÙÍø´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£¡£¡£¡£¡£Movistar¹ÙÍøÉÏÓÃÓڲ鿴·¢Æ±µÄÒ³ÃæµÄURLÖÐÔ̺¬ÁË·¢Æ±µÄID£¬£¬£¬£¬£¬£¬£¬£¬ÈκÎÓû§¶¼Äܹ»Í¨¹ýÅú¸Ä´ËIDÀ´²é¿´ÆäËüÕË»§µÄÊý¾Ý¡£¡£¡£¡£¡£Æ¾¾ÝеÄGDPR»®¶¨£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾¿ÉÄÜÃæ¶Ô1000Íò~2000ÍòÅ·Ôª»òÏ൱ÓÚÆäÄê½»Ò×¶î2%~4%µÄ·£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/telefonica-spain-exposed-the-personal-details-of-millions-of-customers/
4¡¢ÃÀѪҺ¼ì²â³¢ÊÔÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ïì
±¾ÖÜÒ»ÃÀ¹ú×î´óµÄѪҺ¼ì²â³¢ÊÔÊÒLabCorp°ä·¢ÆäÔÚÖÜÄ©ÆÚ¼äÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£LabCorp¹Ø¹ØÁ˲¿ÃÅϵͳÒÔ½ÚÔì¸ÃÈëÇֻ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°¸÷ϵͳְÄÜÔÚ¸´ÔÖÓ×£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢²úÉúÁ˶ÔÊý¾ÝµÄδÊÚȨ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐÅû¶¸ü¶àÓйØÏ¸½Ú¡£¡£¡£¡£¡£Óйص±¾ÖÔÚ½øÐе÷²éÖ®ÖÓ×£¡£¡£¡£¡£LabCorpÔÚÈ«ÇòÕ¼Óнü6ÍòÃûÔ±¹¤£¬£¬£¬£¬£¬£¬£¬£¬ÆäÿÖܲâÊԵϼÕßÑù±¾³¬¹ý250Íò¸ö£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÊý¾Ýй¶µÄDZÔÚºó¹û¿ÉÄÜÊǾ޴óµÄ£¬£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍòÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-network-of-labcorp-us-biggest-blood-testing-laboratories/
5¡¢¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ËðʧԼ100ÍòÃÀÔª
ƾ¾Ý¶íÂÞ˹°²È«³§ÉÌGroup-IBµÄ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïMoneyTakerͨ¹ý·ÓÉÆ÷ÈëÇÖÁ˶íÂÞ˹PIRÒøÐеÄÍøÂ磬£¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÔ¼100ÍòÃÀÔªµÄ×ʽ𡣡£¡£¡£¡£Group-IBÈ·ÈϹ¥»÷ʼÓÚ2018Äê5ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÈë¿ÚÊǹýÆÚµÄ·ÓÉÆ÷£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ÓÉÆ÷ÓÐËí·£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÖ±½Ó½Ó¼ûÒøÐеı¾µØÍøÂç¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ7ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬PIRÒøÐеÄÔ±¹¤ÔÚÒ»ÌìºóµÄ7ÔÂ4ÈÕ·¢ÏÖÁË´ó±ÊδÊÚȨµÄÂòÂô£¬£¬£¬£¬£¬£¬£¬£¬µ«ÎªÊ±ÒÑÍí¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-russian-bank-and-steal-1-million-due-to-outdated-router/


¾©¹«Íø°²±¸11010802024551ºÅ