ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ32ÖÜ

°ä²¼¹¦·ò 2018-08-13

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê08ÔÂ06ÈÕÖÁ12ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬£¬ £¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇSiemens SIMATIC STEP 7ºÍWinCC´úÂëÖ´Ðзì϶£»£» £»£»£»£»£»HP Ink PrintersÔ¶³Ì´úÂëÖ´Ðзì϶£»£» £»£»£»£»£»Linux kernel 'tcp_input.c'Ô¶³Ì»Ø¾ø·þÎñ·ì϶£»£» £»£»£»£»£»SonicWall Global Management System XML-RPCŲÓÃËÁÒâ´úÂëÖ´Ðзì϶£»£» £»£»£»£»£»HPE Intelligent Management Center PLAT´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ¢À­Ë¹¼ÓijÕòÈ·µ±¾ÖÍøÂçÒòϰȾÀÕË÷Èí¼þBitPaymer¶ø±»ÆÈ¹Ø¹Ø£»£» £»£»£»£»£»Ä«Î÷¸çÒ»Ò½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬ £¬£¬£¬ £¬£¬Ô¼200Íò»¼ÕßµÄÐÅϢй¶£»£» £»£»£»£»£»TCMÒøÐÐÒòÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÓû§µÄÃô¸ÐÊý¾Ýй¶£»£» £»£»£»£»£»SnapchatÔ´ÂëÔÚGitHubÉÏÆØ¹â£¬£¬ £¬£¬£¬ £¬£¬¹«Ë¾»úÃÜ¿ÉÄܱíй£»£» £»£»£»£»£»ÃÀÖ°Òµ¸ß¶û·òЭ»áPGAÒÉÔâÀÕË÷Èí¼þBitPaymer¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬ £¬£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1¡¢Siemens SIMATIC STEP 7ºÍWinCC´úÂëÖ´Ðзì϶

Siemens SIMATIC STEP 7ºÍWinCC TIA PortalĬÈÏ×°ÖÃÖеÄÎļþȨÏÞ·ÖÅä²»µ±£¬£¬ £¬£¬£¬ £¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬ £¬£¬£¬ £¬£¬Ö´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://cert-portal.siemens.com/productcert/pdf/ssa-979106.pdf


2¡¢HP Ink PrintersÔ¶³Ì´úÂëÖ´Ðзì϶

HP Ink¶à¸ö´òÓ¡»ú´æÔÚ°²È«·ì϶£¬£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬ £¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.hp.com/us-en/document/c06097712


3¡¢Linux kernel 'tcp_input.c'Ô¶³Ì»Ø¾ø·þÎñ·ì϶

Linux kernel tcp_collapse_ofo_queue()¼°tcp_prune_ofo_queue() ŲÓôæÔÚ°²È«·ì϶£¬£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬ £¬£¬½øÐлؾø·þÎñ¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.synology.com/support/security/Synology_SA_18_41


4¡¢SonicWall Global Management System XML-RPCŲÓÃËÁÒâ´úÂëÖ´Ðзì϶

SonicWall Global Management SystemûÓÐÑéÖ¤Óû§Ìá½»µÄÓÃÓÚXML-RPCŲÓõIJÎÊý£¬£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬ £¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0007


5¡¢HPE Intelligent Management Center PLAT´úÂëÖ´Ðзì϶

HPE Intelligent Management Center£¨iMC£©PLAT´æÔÚ°²È«·ì϶£¬£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬ £¬£¬Ö´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03864en_us


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°¢À­Ë¹¼ÓijÕòÈ·µ±¾ÖÍøÂçÒòϰȾÀÕË÷Èí¼þBitPaymer¶ø±»ÆÈ¹Ø¹Ø

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

7ÔÂ24ÈÕ°¢À­Ë¹¼Ó³ÇÕòMat-SuÈ·µ±¾ÖÍøÂçϰȾÀÕË÷Èí¼þBitPaymer£¬£¬ £¬£¬£¬ £¬£¬µ¼ÖÂÆäÍøÂçÏÝÈë̱»¾ ¡£¡£¡£¡£¡£¡£¡£BitPaymerËÆºõÔçÔÚ5ÔÂ3ÈÕ¾ÍÒѾ­½øÈëÁËMat-SuµÄÍøÂ磬£¬ £¬£¬£¬ £¬£¬µ«´¦ÓÚÐÝÃß»òδ±»·¢½ü¿ö̬ ¡£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þÔÚ7ÔÂ24ÈÕ·¢×÷£¬£¬ £¬£¬£¬ £¬£¬Ó°ÏìÁË500̨×ÀÃæ¹¤×÷Õ¾ºÍ120̨·þÎñÆ÷ ¡£¡£¡£¡£¡£¡£¡£Mat-Su¹«¹²ÊÂÎñ×ܼàPatty Sullivan³Æ¸ÃÕòµÄ»ù´¡ÉèÊ©ÔÚÎȲ½³Á½¨£¬£¬ £¬£¬£¬ £¬£¬Ô̺¬µç×ÓÓʼþ·þÎñ¡¢µç»°ºÍ»¥ÁªÍøµÈ·þÎñÒ²½«¸´Ô­ ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bitpaymer-ransomware-infection-forces-alaskan-town-to-use-typewriters-for-a-week/

2¡¢Ä«Î÷¸çÒ»Ò½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬ £¬£¬£¬ £¬£¬Ô¼200Íò»¼ÕßµÄÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÔ±Bob Diachenkoͨ¹ýShodan·¢ÏÖÒ»¸öÄ«Î÷¸çÒ½ÁÆÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬ £¬£¬£¬ £¬£¬¸ÃMongoDBÊý¾Ý¿âÔ̺¬Ô¼200Íò»¼ÕßµÄÒ½ÁÆÐÅÏ¢£¬£¬ £¬£¬£¬ £¬£¬Ô̺¬ÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢±£ÏÕÐÅÏ¢¡¢²Ð¼²Çé¿öºÍ¼ÒͥסַµÈÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£Diachenko·¢ÏÖ¸ÃÊý¾Ý¿âµÄÖÎÀíÔ±µç×ÓÓʼþÓòÃûΪhovahealth.comºÍefimed.care£¬£¬ £¬£¬£¬ £¬£¬ÔÚ֪ͨHova Health¹«Ë¾ºó£¬£¬ £¬£¬£¬ £¬£¬¸ÃÊý¾Ý¿âÔÚÈý¸öÓ×ʱÄڵõ½±£»£» £»£»£»£»£»¤ ¡£¡£¡£¡£¡£¡£¡£

 Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/health-care-data-of-2-million-people-in-mexico-exposed-online/

3¡¢TCMÒøÐÐÒòÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÓû§µÄÃô¸ÐÊý¾Ýй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


TCMÒøÐÐÊÇICBA BancardµÄ×Ó¹«Ë¾£¬£¬ £¬£¬£¬ £¬£¬ËüÊÇÃÀ¹ú750¶à¼ÒÓ×ÐͺÍÉçÇøÒøÐеÄÐÅÓþ¿¨¿¯ÐÐÉÌ ¡£¡£¡£¡£¡£¡£¡£¸ÃÒøÐа䷢ÆäÍøÕ¾ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÐÅÓþ¿¨ÉêÇëÈ˵ÄÐÅÏ¢ÔÚ2017Äê3Ô³õÖÁ2018Äê7ÔÂÖÐѮ֮¼äµÄ16¸öÔÂÄÚº­Ïß¶³ö ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬ÉêÇëÈ˵ÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚºÍÉç±£ºÅÂëµÈ ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿Îª²»µ½1ÍòÈË ¡£¡£¡£¡£¡£¡£¡£TCM³ÆÆäÔÚ2018Äê7ÔÂ16ÈÕ·¢ÏÖÁ˸ÃÎÊÌ⣬£¬ £¬£¬£¬ £¬£¬²¢ÔÚµÚ¶þÌì½øÐÐÁ˽¨¸´ ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75078/data-breach/tcm-bank-data-leak.html

4¡¢SnapchatÔ´ÂëÔÚGitHubÉÏÆØ¹â£¬£¬ £¬£¬£¬ £¬£¬¹«Ë¾»úÃÜ¿ÉÄܱíй


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ê¢ÐеÄÉ罻ýÌåÀûÓÃSnapchatµÄÔ´´úÂë±»Ò»ÃûºÚ¿Í°ä²¼ÔÚGitHubÉÏ ¡£¡£¡£¡£¡£¡£¡£¸ÃGitHubÕË»§ÎªKhaled Alshehri£¬£¬ £¬£¬£¬ £¬£¬ÊÇÒ»Ãû°Í»ù˹̹Óû§£¬£¬ £¬£¬£¬ £¬£¬ÆäÔÚSource-Snapchat´æ´¢¿âÖа䲼ÁËÌý˵ÊÇSnapchatµÄiOSÀûÓõĴúÂë ¡£¡£¡£¡£¡£¡£¡£µ×²ã´úÂë¿ÉÄÜ»áй¶¹«Ë¾µÄ»úÃÜÐÅÏ¢£¬£¬ £¬£¬£¬ £¬£¬ÀýÈçappµÄÕûÌåÉè¼Æ¡¢¹¤×÷·½Ê½ÒÔ¼°¹æ»®µÄ½«À´Ö°ÄÜµÈ ¡£¡£¡£¡£¡£¡£¡£SnapchatµÄĸ¹«Ë¾Snap Inc.ƾ¾ÝDMCA·¨ÒªÇóɾ³ýÁ˸ô洢¿â ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/snapchat-hack-source-code.html

5¡¢ÃÀÖ°Òµ¸ß¶û·òЭ»áPGAÒÉÔâÀÕË÷Èí¼þBitPaymer¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ƾ¾ÝGolfWeekµÄ±¨Â·£¬£¬ £¬£¬£¬ £¬£¬±¾ÖܶþÃÀ¹úÖ°Òµ¸ß¶û·òЭ»á£¨PGA£©ÒÉÔâÀÕË÷Èí¼þBitPaymerµÄ¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£ÓëÀÕË÷Èí¼þSamSamÒ»Ñù£¬£¬ £¬£¬£¬ £¬£¬BitPaymerÆ«²îÓÚͨ¹ýRDP·þÎñÈëÇÖÖ¸±ê×éÖ¯µÄÍøÂ磬£¬ £¬£¬£¬ £¬£¬²¢ºáÏò´«²¼ÖÁÃ¿Ò»Ì¨ÍÆËã»ú ¡£¡£¡£¡£¡£¡£¡£¸Ã±äÖÖÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lockedÀ©´óÃû£¬£¬ £¬£¬£¬ £¬£¬²¢ÀÕË÷½Ï¸ßµÄÊê½ð ¡£¡£¡£¡£¡£¡£¡£ÔÚ´ÓǰµÄ¼¸ÖÜÄÚBitpaymerÒѾ­³öÏÖÁËÊý´ÎÕë¶ÔÆóÒµ¡¢µ±¾Ö»ú¹¹ºÍÒ½ÔºµÄ¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/the-pga-possibly-infected-with-the-bitpaymer-ransomware/