ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ43ÖÜ

°ä²¼¹¦·ò 2018-10-29

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê10ÔÂ22ÈÕÖÁ29ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox ¶à¸öÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»Eaton UPS 9PX 8000 SP CVE-2018-9279Óû§ÃÜÂëй¶·ì϶£»£»£»£»£»Citrix NetScaler SD-WAN OSºÅÁî×¢Èë·ì϶£»£»£»£»£»Moxa ThingsPro CVE-2018-18393ÃÜÂë¸ü¸Ä·ì϶£»£»£»£»£»Symantec Veritas NetBackup ApplianceÊäÈëÔ¶³Ì´úÂëÖ´Ðзì϶; GEOVAP Reliance 4 SCADA/HMIÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǹúÌ©º½¿Õ´î¿Í×ÊÁÏÒɱíй£¬£¬£¬£¬£¬£¬£¬£¬²¨¼°Ô¼940Íò³Ë¿Í£»£»£»£»£»Ò½ÁƱ£ÏÕ¹«Ë¾AnthemÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÅ⸶1600ÍòÃÀÔª£»£»£»£»£»ÃÀHealthCare.govÒ½ÁÆÏµÍ³ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼7.5ÍòÓû§µÄÐÅÏ¢±»ÇÔ£»£»£»£»£»FacebookÒò½£ÇÅ·ÖÎö³óÎű»Ó¢¹úICO·£¿£¿£¿£¿£¿î50ÍòÓ¢°÷£»£»£»£»£»CyberX°ä²¼È«ÇòICSºÍIIoT·çÏջ㱨£¨2019°æ£©¡£¡£ ¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£ ¡£¡£¡£




¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1. Mozilla Firefox ¶à¸öÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶


Mozilla Firefox´æÔÚÕûÊýÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£

https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/



2. Eaton UPS 9PX 8000 SP CVE-2018-9279Óû§ÃÜÂëй¶·ì϶


Eaton UPS 9PX 8000 SPÍøÒ³ÖÐÔ̺¬Ã÷ÎÄÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Óû§ÖÎÀíÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼ûÉ豸¡£¡£ ¡£¡£¡£

https://powerquality.eaton.com/support/software-drivers/downloads/connectivity-firmware.asp


3. Citrix NetScaler SD-WAN OSºÅÁî×¢Èë·ì϶


Citrix NetScaler SD-WAN´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâOSºÅÁî¡£¡£ ¡£¡£¡£

https://support.citrix.com/article/CTX236992


4. Moxa ThingsPro CVE-2018-18393ÃÜÂë¸ü¸Ä·ì϶


Moxa ThingsPro´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¸ü¸ÄÓû§ÃÜÂë¡£¡£ ¡£¡£¡£

https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/10/18/klcert-18-021-moxa-thingspro-iiot-gateway-and-device-management-software-solutions-password-management-issue/


5. Symantec Veritas NetBackup ApplianceÊäÈëÔ¶³Ì´úÂëÖ´Ðзì϶


Symantec Veritas NetBackup£¨NBU£©Appliance´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»rootÉí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¡£ ¡£¡£¡£

https://www.veritas.com/content/support/en_US/security/VTS18-003.html



Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢¹úÌ©º½¿Õ´î¿Í×ÊÁÏÒɱíй£¬£¬£¬£¬£¬£¬£¬£¬²¨¼°Ô¼940Íò³Ë¿Í

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹úÌ©º½¿Õ23ÈÕÍí°ä²¼²¼¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾¼°È«×Ê×Ó¹«Ë¾¸ÛÁúº½¿ÕÓÐÏÞ¹«Ë¾µÄ³Ë¿Í×ÊÁÏÔ⵽δÊÚȨ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬Ô¼940Íò³Ë¿Í×ÊÁϱ»ÇÔÈ¡£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬³Ë¿ÍµÄÐÕÃû¡¢ÉúÈÕ¡¢µç»°¡¢µØÖ·¡¢Éí·ÝÖ¤¼°»¤ÕպŵÈÃô¸ÐÐÅÏ¢¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬»¹ÓÐ403ÕÅÒÑÓâÆÚµÄÐÅÓþ¿¨ºÅÂëй¶¡£¡£ ¡£¡£¡£¹úÌ©º½¿Õ³ÆÊÜÓ°ÏìµÄÐÅϢϵͳÓ뺽°àÔË×÷ϵͳΪ¶ÀÁ¢µÄϵͳ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ²»»á¶Ôº½°à°²È«×é³ÉÈκÎÓ°Ïì¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/mcafee-labs/android-timpdoor-turns-mobile-devices-into-hidden-proxies/


2¡¢Ò½ÁƱ£ÏÕ¹«Ë¾AnthemÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÅ⸶1600ÍòÃÀÔª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ò½ÁƱ£ÏÕ¹«Ë¾AnthemÒÑÔÞ³ÉΪ2015ÄêµÄ³Á´óÊý¾Ýй¶ÊÂÎñÏòÃÀ¹úµ±¾ÖÖ§¸¶´´¼Í¼µÄ1600ÍòÃÀÔªºÍ½â½ð¡£¡£ ¡£¡£¡£2015ÄêÔ¼7900ÍòAnthemÓû§µÄÓ×ÎÒÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý´¹µöÓʼþ½Ó¼ûÁ˸Ã×éÖ¯²¿ÃÅÓû§µÄÐÕÃû¡¢Éç±£ºÅÂë¡¢Ò½ÁÆID¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·ºÍ¾ÍÒµÐÅÏ¢µÈ¡£¡£ ¡£¡£¡£AnthemÏÔȻδÄÜÒÀÕÕ½¡È«±£ÏÕÁ÷ͨÓëÔðÈη¨°¸£¨HIPAA£©µÄÒªÇóÍ×ÉÆ±£»£»£»£»£»¤Æä»ù´¡ÉèÊ©¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/anthem-in-record-16m-hipaa/


3¡¢ÃÀHealthCare.govÒ½ÁÆÏµÍ³ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼7.5ÍòÓû§µÄÐÅÏ¢±»ÇÔ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÉÏÖÜÎåÃÀ¹úÒ½ÁƱ£ÏÕºÍÒ½ÁƲ¹Öú·þÎñÖÐÐÄ£¨CMS£©°ä²¼ÐÂÎųÆ£¬£¬£¬£¬£¬£¬£¬£¬ÓëHealthCare.govÓйصÄÒ»¸öµ±¾ÖÍÆËã»úϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼7.5ÍòÃûÓû§µÄÃô¸ÐÓ×ÎÒÐÅÏ¢±»ÇÔ¡£¡£ ¡£¡£¡£CMS°µÊ¾ÔÚ10ÔÂ16ÈÕÈ·ÈÏÁËÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬²¢½ûÓÃÁËÓëÒì³£»£»£»£»£»î¶¯ÓйصÄÓû§ÕË»§¡£¡£ ¡£¡£¡£CMSºÍFBIÔÚ´òËã֪ͨËùÓÐÊÜÓ°ÏìµÄÓû§£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌṩÐÅÓþ±£»£»£»£»£»¤µÈ×ÊÔ´¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.apnews.com/212e1e36b10945968704bd7e86598a65


4¡¢FacebookÒò½£ÇÅ·ÖÎö³óÎű»Ó¢¹úICO·£¿£¿£¿£¿£¿î50ÍòÓ¢°÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒICO×îÖÕÒò½£ÇÅ·ÖÎö³óÎŶÔFacebook·£¿£¿£¿£¿£¿î50ÍòÓ¢°÷¡£¡£ ¡£¡£¡£Æ¾¾ÝICO¶Ô¸Ã³óÎŵĵ÷²é£¬£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙÓÐ100ÍòÓ¢¹ú¹«ÃñµÄÊý¾ÝÔâµ½²»Õýµ±µÄ´¦Ö㬣¬£¬£¬£¬£¬£¬£¬²¢ÇÒFacebookûÓпÉÄܲÉÈ¡ÏàÒ˵ļ¼Êõ¼¿Á©ºÍ´ëÊ©×èÖ¹ÕâÒ»Êý¾Ýй¶ÐÐΪ¡£¡£ ¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ»·£¿£¿£¿£¿£¿îÊý¶î¶ÔÓÚFacebook¶øÑԲ׺£Ò»ËÚ£¬£¬£¬£¬£¬£¬£¬£¬FacebookÈ¥ÄêµÄÈ«Çò×ÜÊÕÈë´ï315ÒÚÓ¢°÷¡£¡£ ¡£¡£¡£ÈôÊÇÆ¾¾Ý×îеÄGDPR¹æ¶¨£¬£¬£¬£¬£¬£¬£¬£¬Facebook¿ÉÄÜÃæ¶Ô×î¸ß12.6ÒÚÓ¢°÷µÄ·£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬£¬£¬£¬µ«ÐÒÔ˵ÄÊÇGDPRÔڸóóÎÅ·¢×÷Ö®ºó²ÅÆðÍ·ÉúЧ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/facebook-cambridge-analytica.html


5¡¢CyberX°ä²¼È«ÇòICSºÍIIoT·çÏջ㱨£¨2019°æ£©


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝCyberXµÄÈ«ÇòICSºÍIIoT·çÏջ㱨£¨2019°æ£©£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÔËÐйýÆÚµÄWindowsϵͳ£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ýÒ»°ëµÄ¹Ø¼ü»ù´¡ÉèʩϵͳÒ×ÊÜÕë¶ÔÐÔ¹¥»÷µÄÓ°Ïì¡£¡£ ¡£¡£¡£¸Ã»ã±¨ÊÇ»ùÓÚ¶ÔÁù´óÖ޵Ķà¸ö¹¤ÒµÐÐÒµ£¨ÈçÔì×÷Òµ¡¢»¯Ñ§Òµ¡¢¹«ÓÃÊÂÒµºÍÄÜÔ´ÒµµÈ£©µÄ³¬¹ý850¸öICS¼°SCADA³ö²úÍøÂç½øÐзÖÎöµÃÀ´¡£¡£ ¡£¡£¡£ÓÉÓÚʹÓùýÆÚµÄÍøÂçͨѶºÍ̸£¨ÈçSNMPºÍFTP£©£¬£¬£¬£¬£¬£¬£¬£¬69%µÄICSÍøÂçʹÓÃÃ÷ÎÄ´«ÊäÃÜÂë¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/53-percent-of-ics-networks-at-risk-because-of-legacy-windows-systems-523367.shtml


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù