ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ29ÖÜ

°ä²¼¹¦·ò 2018-07-23

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê07ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼°²È«·ì϶44¸ö £¬£¬£¬£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇPivotal Spring FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁкÅÁî×¢Èë·ì϶£»£»£»£»£»ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶£»£»£»£»£»Dasan GPONºÅÁî×¢Èë·ì϶¡£ ¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÒøÐÐľÂíDorkbot¾íÍÁ³ÁÀ´ £¬£¬£¬£¬£¬ £¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%£»£»£»£»£»¶íÂÞ˹ÔÚÊÀ½ç±­ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷£»£»£»£»£»Telefonica¹ÙÍø·ì϶¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶£»£»£»£»£»ÃÀѪҺ¼ì²â³¢ÊÔÊÒLabCorpÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬ £¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ï죻£»£»£»£»¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬£¬ËðʧԼ100ÍòÃÀÔª¡£ ¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬ £¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£ ¡£¡£¡£¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1¡¢Pivotal Spring FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶

Spring FrameworkʹÓÃspring-messagingÄ£¿£¿£¿£¿£¿£¿éÀ´ÊµÏÖSTOMP´úÀíʱ´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÐÂÎÅ £¬£¬£¬£¬£¬ £¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.exploit-db.com/exploits/44796/


2¡¢Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁкÅÁî×¢Èë·ì϶

Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐWEB UI´æÔÚÊäÈëÑéÖ¤·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬£¬ £¬£¬£¬×¢ÈëËÁÒâSHELLºÅÁî²¢Ö´ÐÓ×£ ¡£¡£¡£¡£


 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180711-phone-webui-inject


3¡¢ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´Ðзì϶


 ManageEngine Exchange Reporter Plus Java servlet ¡®ADSHACluster¡¯ÔÚÖ´ÐÓ×®bcp.exe¡¯Îļþ´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâ¡®BCP_EXE¡¯²ÎÊýÒªÇó £¬£¬£¬£¬£¬ £¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.manageengine.com/products/exchange-reports/release-notes.html


4¡¢Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶

Adobe Flash Player´¦ÖÃSWFÎļþ´æÔÚÀàÐÍ»ìºÏ·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâÎļþÒªÇó £¬£¬£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§½âÎö £¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-24.html


5¡¢Dasan GPONºÅÁî×¢Èë·ì϶

Dasan GPON GponForm/diag_Form URI´æÔÚÉè¼Æ·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬ÔÊÐí¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ'dest_host¡¯²ÎÊýµÄdiag_action=pingÒªÇó £¬£¬£¬£¬£¬ £¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£ ¡£¡£¡£¡£

 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/

Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÒøÐÐľÂíDorkbot¾íÍÁ³ÁÀ´ £¬£¬£¬£¬£¬ £¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

 Æ¾¾ÝCheck PointµÄ×îÐÂÊý¾Ý £¬£¬£¬£¬£¬ £¬£¬£¬ÒøÐÐľÂíDorkbotÔÚ2018Äê¾íÍÁ³ÁÀ´ £¬£¬£¬£¬£¬ £¬£¬£¬³ÉΪһ¸öÑϳÁµÄÍþв¡£ ¡£¡£¡£¡£Dorkbot×îÔçÄܹ»×·Òäµ½2012Äê £¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖØÒªÓÃÓÚÇÔÈ¡Óû§µÄÒøÐеǼʹ´¦¡£ ¡£¡£¡£¡£ÔÚ2018ÄêÉϰëÄê £¬£¬£¬£¬£¬ £¬£¬£¬È«ÇòÒøÐжñÒâÈí¼þÊг¡Õ¼¾ÝǰÈýλµÄ±ðÀëÊÇRamnit£¨27£¥£©¡¢Dorkbot£¨25£¥£©ºÍZeus£¨13£¥£©¡£ ¡£¡£¡£¡£DorkbotÒѳÉΪ2018ÄêµÚ¶þ´óÁîÈËÍ·ÌÛµÄÒøÐжñÒâÈí¼þ¡£ ¡£¡£¡£¡£

 Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/threatlist-6-year-old-dorkbot-banking-malware-resurfaces-as-big-threat/133898/

2¡¢¶íÂÞ˹ÔÚÊÀ½ç±­ÆÚ¼äÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Ī˹¿ÆÊ±±¨±¨Â·³Æ £¬£¬£¬£¬£¬ £¬£¬£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂ簲ȫÊýÃÅ £¬£¬£¬£¬£¬ £¬£¬£¬¸Ã²¿ÃÅÔÚÊÀ½ç±­ÆÚ¼ä¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸×ï»î¶¯ £¬£¬£¬£¬£¬ £¬£¬£¬È·±£Á˽ÇÖðµÄ°²È«¡£ ¡£¡£¡£¡£FireEyeÄÏÅ·¼¼Êõ×ܼàDavid Grout°µÊ¾¹ÌÈ»ÕâÒ»Êý×ÖºÜ¸ß £¬£¬£¬£¬£¬ £¬£¬£¬µ«²¢²»³öºõÒâÁÏ¡£ ¡£¡£¡£¡£ÕâЩ¹¥»÷¿ÉÄÜÔ̺¬ÔÚ½ÇÖðǰ¼¸ÖÜ¾ÍÆðÍ·µÄÍøÂç´¹µö¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬£¬ÀýÈçÁ®¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÊÀ½ç±­Ö÷ÌâÓйصĴÙÏú»î¶¯£¨Èç¹ú¶È¶ÓÇòÒ£©µÈ¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/

3¡¢Telefonica¹ÙÍø·ì϶¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Î÷°àÑÀµçÐŹ«Ë¾TelefonicaµÄ¹Ì»°¡¢¿í´ø¼°¸¶·ÑµçÊÓÒµÎñMovistarµÄ¹ÙÍø´æÔÚ·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£ ¡£¡£¡£¡£Movistar¹ÙÍøÉÏÓÃÓڲ鿴·¢Æ±µÄÒ³ÃæµÄURLÖÐÔ̺¬ÁË·¢Æ±µÄID £¬£¬£¬£¬£¬ £¬£¬£¬ÈκÎÓû§¶¼Äܹ»Í¨¹ýÅú¸Ä´ËIDÀ´²é¿´ÆäËüÕË»§µÄÊý¾Ý¡£ ¡£¡£¡£¡£Æ¾¾ÝеÄGDPR»®¶¨ £¬£¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾¿ÉÄÜÃæ¶Ô1000Íò~2000ÍòÅ·Ôª»òÏ൱ÓÚÆäÄê½»Ò×¶î2%~4%µÄ·£¿£¿£¿£¿£¿£¿î¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/telefonica-spain-exposed-the-personal-details-of-millions-of-customers/

4¡¢ÃÀѪҺ¼ì²â³¢ÊÔÊÒLabCorpÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬ £¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

±¾ÖÜÒ»ÃÀ¹ú×î´óµÄѪҺ¼ì²â³¢ÊÔÊÒLabCorp°ä·¢ÆäÔÚÖÜÄ©ÆÚ¼äÔâµ½ºÚ¿ÍÈëÇÖ¡£ ¡£¡£¡£¡£LabCorp¹Ø¹ØÁ˲¿ÃÅϵͳÒÔ½ÚÔì¸ÃÈëÇֻ £¬£¬£¬£¬£¬ £¬£¬£¬Ä¿Ç°¸÷ϵͳְÄÜÔÚ¸´Ô­ÖÓ×£ ¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢²úÉúÁ˶ÔÊý¾ÝµÄδÊÚȨ½Ó¼û £¬£¬£¬£¬£¬ £¬£¬£¬µ«Ã»ÓÐÅû¶¸ü¶àÓйØÏ¸½Ú¡£ ¡£¡£¡£¡£Óйص±¾ÖÔÚ½øÐе÷²éÖ®ÖÓ×£ ¡£¡£¡£¡£LabCorpÔÚÈ«ÇòÕ¼Óнü6ÍòÃûÔ±¹¤ £¬£¬£¬£¬£¬ £¬£¬£¬ÆäÿÖܲâÊԵϼÕßÑù±¾³¬¹ý250Íò¸ö £¬£¬£¬£¬£¬ £¬£¬£¬Òò¶øÊý¾Ýй¶µÄDZÔÚºó¹û¿ÉÄÜÊǾ޴óµÄ £¬£¬£¬£¬£¬ £¬£¬£¬Êý°ÙÍòÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜÃæ¶Ô·çÏÕ¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-network-of-labcorp-us-biggest-blood-testing-laboratories/

5¡¢¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬£¬ËðʧԼ100ÍòÃÀÔª

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

 Æ¾¾Ý¶íÂÞ˹°²È«³§ÉÌGroup-IBµÄ»ã±¨ £¬£¬£¬£¬£¬ £¬£¬£¬ºÚ¿ÍÍÅ»ïMoneyTakerͨ¹ý·ÓÉÆ÷ÈëÇÖÁ˶íÂÞ˹PIRÒøÐеÄÍøÂç £¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÔÈ¡ÁËÔ¼100ÍòÃÀÔªµÄ×ʽ𡣠¡£¡£¡£¡£Group-IBÈ·ÈϹ¥»÷ʼÓÚ2018Äê5ÔÂÏÂÑ® £¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßµÄÈë¿ÚÊǹýÆÚµÄ·ÓÉÆ÷ £¬£¬£¬£¬£¬ £¬£¬£¬¸Ã·ÓÉÆ÷ÓÐËí· £¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÖ±½Ó½Ó¼ûÒøÐеı¾µØÍøÂç¡£ ¡£¡£¡£¡£¹¥»÷²úÉúÔÚ7ÔÂ3ÈÕ £¬£¬£¬£¬£¬ £¬£¬£¬PIRÒøÐеÄÔ±¹¤ÔÚÒ»ÌìºóµÄ7ÔÂ4ÈÕ·¢ÏÖÁË´ó±ÊδÊÚȨµÄÂòÂô £¬£¬£¬£¬£¬ £¬£¬£¬µ«ÎªÊ±ÒÑÍí¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-russian-bank-and-steal-1-million-due-to-outdated-router/