¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180831

°ä²¼¹¦·ò 2018-08-31

¡¾Êý¾Ýй¶¡¿¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬ £¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


8ÔÂ22ÈÕÖÁ24ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬ £¬¼ÓÄô󺽿չ«Ë¾·¢ÏÖÒì³£µÄµÇ¼»î¶¯£¬£¬£¬£¬£¬£¬£¬ £¬ÎªÁ˱£»£»£»£»£»£»£»¤Óû§µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£¡£¡£¡£¡£¡£¡£29ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬£¬£¬£¬£¬£¬£¬ £¬³ÆÆäÓ×ÎÒ×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£ÕâЩ×ÊÁÏÖÁÉÙÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂ룬£¬£¬£¬£¬£¬£¬ £¬Ò²¿ÉÄÜÔ̺¬ÐԱ𡢵®ÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉêÃ÷Öиù«Ë¾°µÊ¾Óû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/


¡¾·ÖÎö»ã±¨¡¿¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚ½©Ê¬ÍøÂçÏÂÔØÎļþµÄͳ¼Æ·ÖÎö


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼ÁË2017ÄêϰëÄêºÍ2018ÄêÉϰëÄêµÄ½©Ê¬ÍøÂç»î¶¯µÄ·ÖÎöÁ˾Ö£¬£¬£¬£¬£¬£¬£¬ £¬ÖØÒª·¢ÏÖÔ̺¬£ºËæ×ÅÍøÂç·¸×ï·Ö×ÓÆðÍ·½«½©Ê¬ÍøÂçÊÓΪ¶ñÒâÍÚ¿óµÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ £¬¶ñÒâ¿ó¹¤ÔÚ½©Ê¬ÍøÂçÏÂÔØÎļþÖеıÈÀýÔÚÔö³¤£»£»£»£»£»£»£»ºóÃųÖÐøÕ¼¾Ý½©Ê¬ÍøÂçÏÂÔØÎļþµÄ´ó²¿ÃÅ£»£»£»£»£»£»£»dropperµÄÊýÁ¿Ò²ÔÚÔö³¤£»£»£»£»£»£»£»2018ÄêÒøÐÐľÂíµÄ±ÈÀýÓÐËù½µÂ䣻£»£»£»£»£»£»½©Ê¬ÍøÂçÔ½À´Ô½¶àµØÆ¾¾Ý¿Í»§µÄÐèÒª½øÐÐ×âÁÞ£¬£¬£¬£¬£¬£¬£¬ £¬ºÃ¶àÇé¿öÏÂÄÑÒÔÈ·¶¨½©Ê¬ÍøÂçµÄרְ¹¤×÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/what-are-botnets-downloading/87658/


¡¾Íþвµý±¨¡¿Ç÷Ïò¿Æ¼¼·¢ÏÖÓëBahamut¡¢ConfuciusºÍPatchworkÓйصÄAPT×éÖ¯Urpage


Ç÷Ïò¿Æ¼¼Í¨¹ý¶ÈÎöÐµĹ¥»÷×éÖ¯UrpageÓëAPT×éÖ¯Confucius¡¢PatchworkÒÔ¼°BahamutµÄÀàËÆÖ®´¦£¬£¬£¬£¬£¬£¬£¬ £¬Éî¿Ì̽ÇóÁËÍøÂç¹¥»÷Ö®¼ä¿ÉÄÜ´æÔÚµÄÁªÏµ¡£¡£¡£¡£¡£¡£¡£UrpageÖØÒªÕë¶ÔÎÚ¶û¶¼ÓïºÍ°¢À­²®ÓïµÄÎÄ×Ö´¦ÖÃÆ÷InPage£¬£¬£¬£¬£¬£¬£¬ £¬ÆäʹÓÃÁËÓëConfuciusºÍPatchworkÒ»ÑùµÄDelphiºóÃÅ×é¼þ£¬£¬£¬£¬£¬£¬£¬ £¬²¢Ê¹ÓÃÁËÓëBahamutÀàËÆµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ºÜ¶àÀàËÆÖ®´¦ºÍÁªÏµÅú×¢£¬£¬£¬£¬£¬£¬£¬ £¬Õâ¿ÉÄÜÊÇÒ»¸öµ¥Ò»µÄÊÕ·ÑÍŶӽ«Æä¹¤¾ßºÍ·þÎñÏúÊÛ¸øÓµÓÐ·ÖÆçÖ÷ÕźÍÖ¸±êµÄÆäËü×éÖ¯¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/the-urpage-connection-to-bahamut-confucius-and-patchwork/


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖ7339¸öMagentoÔÚÏßÉ̵êϰȾ¶ñÒâÈí¼þMagentoCore


ºÉÀ¼°²È«×êÑÐÈËÔ±Willem de Groot·¢ÏÖ¶ñÒâÈí¼þMagentoCoreÔÚ´ÓǰÁù¸öÔÂÄÚϰȾÁË7339¸öMagentoÔÚÏßÉ̵ꡣ¡£¡£¡£¡£¡£¡£MagentoCoreÊÇÒ»¸öskimmer¾ç±¾£¬£¬£¬£¬£¬£¬£¬ £¬Í¨³£¹ÒÔØÔÚÉ̵êµÄ¸¶¿îÒ³Ãæ²¢ÇÔÈ¡Óû§µÄÖ§¸¶¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã¾ç±¾´Ómagentocore.netÓòÃû¼ÓÔØ£¬£¬£¬£¬£¬£¬£¬ £¬¾ùÔÈÿÌìϰȾ50µ½60¼ÒÔÚÏßÉ̵ꡣ¡£¡£¡£¡£¡£¡£Groot»¹³ÆÄ¿Ç°ËùÓеÄMagentoÉ̵êÖÐÓÐ4.2£¥Ï°È¾ÁËÒ»ÖÖ»ò¶àÖÖ¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/magentocore-malware-found-on-7-339-magento-stores/


¡¾·ì϶²¹¶¡¡¿4ÄêǰÅû¶µÄ·ì϶Misfortune CookieÈÔÔÚÓ°Ï첿ÃÅÒ½ÁÆÉ豸


CyberMDX×êÑÐÈËÔ±·¢ÏÖ¸ßͨ×Ó¹«Ë¾CapsuleµÄDatacatptorÖÕ¶Ë·þÎñÆ÷£¨DTS£©²úÆ·ÒÀÈ»Ò×ÊÜMisfortune Cookie·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£DTS×÷ΪҽÁÆÉè±¸Íø¹Ø£¬£¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚ½«¼à»¤ÒÇ¡¢ºôÎüÆ÷¡¢Âé×íϵͳºÍÊäÒº±ÃµÈÉ豸Ïνӵ½Ò½ÔºµÄÍøÂç¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓÚ2014ÄêÓÉCheck PointÅû¶£¬£¬£¬£¬£¬£¬£¬ £¬´æÔÚÓÚAllegroSoftµÄRomPager×é¼þÖУ¬£¬£¬£¬£¬£¬£¬ £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£ICS-CERTÕë¶Ô¸Ã·ì϶£¨CVE-2014-9222£©°ä²¼ÁËÖҸ棬£¬£¬£¬£¬£¬£¬ £¬¸Ã·ì϶µÄCVSSµÃ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/4-year-old-misfortune-cookie-rears-its-head-in-medical-gateway-device/


¡¾·ì϶²¹¶¡¡¿Ê©ÄÍµÂµçÆø°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬ £¬½¨¸´¶à¿î²úÆ·Öеݲȫ·ì϶


Ê©ÄÍµÂµçÆø½¨¸´ÆäµçÔ´ÖÎÀíϵͳPowerLogic PM5560¼°¿É±à³ÌÂß¼­½ÚÔìÆ÷Modicon M221ÖеĶà¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¹Ì¼þ°æ±¾2.5.4֮ǰµÄPowerLogic PM5560´æÔÚ¿çÕ¾¾ç±¾·ì϶£¨CVE-2018-7795£©£¬£¬£¬£¬£¬£¬£¬ £¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¹Ì¼þ°æ±¾V1.6.2.0֮ǰµÄModicon M221´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ £¬Ô̺¬¿ÉÔÊÐíδ¾­ÊÚȨµÄÓû§³Á·ÅÈÏÖ¤ÐòÁеķì϶£¨CVE-2018-7790£©¡¢¿ÉÔÊÐíδ¾­ÊÚȨµÄÓû§¸²¸ÇÔ­ÃÜÂëµÄ·ì϶£¨CVE-2018-7791£©ÒÔ¼°¿ÉÔÊÐíδ¾­ÊÚȨµÄÓû§Ê¹Óòʺç±íÆÆ½âÃÜÂëµÄ·ì϶£¨CVE-2018-7792£©¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/high-severity-flaws-patched-in-schneider-electric-products/137034/