ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ17ÖÜ

°ä²¼¹¦·ò 2018-05-02

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼°²È«·ì϶43¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Text Annotations¿ªÊͺóʹÓÃÔ¶³Ì´úÂëÖ´Ðзì϶£»DrupalÔ¶³Ì´úÂëÖ´Ðзì϶£»Apache Tika±êÌâºÅÁî×¢Èë·ì϶£»Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç¶Âí½Å£»D-Link DIR-615 / TracerouteËÁÒâ´úÂëÖ´Ðзì϶ ¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀSunTrustÒøÐÐǰ¹ÍÔ±ÇÔȡԼ150Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢£»×êÑÐÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÆðÍ·´ó¹æÄ£ÀûÓ÷ì϶Drupalgeddon 2£»ºÚ¿ÍÀûÓÃDrupalgeddon2·ì϶¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø£»×êÑÐÍŶӷ¢ÏÖÖ¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret£»Î¢Èí°ä²¼¸ü¶à¹ØÓÚIntel CPU Spectre·ì϶µÄ΢´úÂë¸üР¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Foxit Reader Text Annotations¿ªÊͺóʹÓÃÔ¶³Ì´úÂëÖ´Ðзì϶

        Foxit Reader Text Annotations´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.foxitsoftware.com/support/security-bulletins.php
2¡¢DrupalÔ¶³Ì´úÂëÖ´Ðзì϶

        Drupal¶à¸ö×Óϵͳ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.drupal.org/sa-core-2018-002
3¡¢Apache Tika±êÌâºÅÁî×¢Èë·ì϶

        Apache Tika´¦Öûú¹ØµÄ±êÌâ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÔÚtika-serverÉÏÖ´ÐÐËÁÒâºÅÁî ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca@%3Cdev.tika.apache.org%3E
4¡¢Advantech WebAccess HMI Designer¶Ñ»º³åÇøÒç¶Âí½Å

        Advantech WebAccess HMI Designer´¦ÖÃPM3Îļþ´æÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://webaccess.advantech.com/product.php
5¡¢D-Link DIR-615 / TracerouteËÁÒâ´úÂëÖ´Ðзì϶

        D-Link DIR-615 / Traceroute´æÔÚÊäÈëÑéÖ¤°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄHOST×Ö¶ÎÊý¾Ý£¬Ö´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/imsebao/404team/blob/master/dlink/dlink_dir615_rce.md


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÃÀSunTrustÒøÐÐǰ¹ÍÔ±ÇÔȡԼ150Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        ÃÀ¹úSunTrustÒøÐеÄCEO William RogersÔÚýÌå°ä²¼»áÉϰµÊ¾£¬¸ÃÒøÐз¢ÏÖÒ»Ãûǰ¹ÍÔ±ÇÔÈ¡ÁËÔ¼150Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢²¢½«ÕâЩÐÅÏ¢¹²Ïí¸øµÚÈý·½·¸×ïÍÅ»ï ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÕË»§Óà¶î ¡£SunTrust³Æ¿Í»§µÄÃÜÂë¡¢Éç±£ºÅÂë¡¢Õ˺š¢ID»ò¼ÝÕÕºÅÂ벢δй¶ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/suntrust-bank-says-former-employee-stole-details-on-15-million-customers/

2¡¢×êÑÐÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÆðÍ·´ó¹æÄ£ÀûÓ÷ì϶Drupalgeddon 2

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        °²È«×êÑÐÍŶӷ¢ÏÖIoT½©Ê¬ÍøÂçMuhstikÒѾ­×ªÒƵ½ÀûÓÃDrupalgeddon 2·ì϶£¨CVE-2018-7600£©ÌáÒé´ó¹æÄ£¹¥»÷ ¡£Ï°È¾Ö¸±êÖ÷»úºó£¬¹¥»÷Õß½«Ê¹Óö¨ÔìµÄ¶ñÒâÈí¼þTsunamiÌáÒéDDoS¹¥»÷¡¢×°ÖÃÃÅÂÞ±ÒÍÚ¿óÈí¼þXMRig»òDash±ÒÍÚ¿óÈí¼þCGMiner ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/big-iot-botnet-starts-large-scale-exploitation-of-drupalgeddon-2-vulnerability/

3¡¢ºÚ¿ÍÀûÓÃDrupalgeddon2·ì϶¹¥»÷ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍø

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        ÎÚ¿ËÀ¼ÄÜÔ´²¿¹ÙÍøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÎÚ¿ËÀ¼ÍøÂ羯ԱŮ½²»°ÈËYulia Kvitko³ÆÕâÒ»ÊÂÎñÊÇ¡°¹ÂÁ¢¡±µÄ£¬Ä¿Ç°µ¼Ö¸ò¿ÃÅÍøÕ¾Òѱ»Ëø¶¨ ¡£¹¥»÷ÕßËÆºõÀûÓÃDrupalgeddon2£¬ÕâÊÇÒ»¸öÓ°Ïì´óÎÞÊýDrupalÍøÕ¾µÄµÄÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£

        Ô­aÁ´½Ó£ºhttps://threatpost.com/ransomware-attack-hits-ukrainian-energy-ministry-exploiting-drupalgeddon2/131373/

4¡¢×êÑÐÍŶӷ¢ÏÖÖ¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµÊý¾ÝµÄ¶ñÒâ»î¶¯Operation GhostSecret

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        McAfee×êÑÐÍŶӰ䲼¹ØÓÚ¶ñÒâ»î¶¯Operation GhostSecretµÄ·ÖÎö»ã±¨ ¡£GhostSecretÖ¼ÔÚÇÔȡȫÇò¶à¸öÐÐÒµµÄÊý¾Ý£¬Ô̺¬¹Ø¼ü»ù´¡ÉèÊ©¡¢ÓéÀÖ¡¢½ðÈÚ¡¢Ò½ÁƱ£½¡ÒÔ¼°µçÐÅ ¡£GhostSecretʹÓõÄÖ²ÈëÎï¡¢¹¤¾ßºÍ¶ñÒâÈí¼þ±äÖÖÓë¹ú¶ÈÔÞÖúµÄ·¸×ïÍÅ»ïHidden Cobra´æÔÚ¹ØÁª ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide

5¡¢Î¢Èí°ä²¼¸ü¶à¹ØÓÚIntel CPU Spectre·ì϶µÄ΢´úÂë¸üÐÂ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        ΢Èí°ä²¼¸ü¶à¹ØÓÚSpectre·ì϶µÄCPU΢´úÂë¸üУ¬½«¸Ã·ì϶µÄ½¨¸´½øÒ»²½À©´óµ½Intel CPUµÄBroadwellºÍHaswellƽ̨ ¡£Õâ´Î¸üÐÂÔ̺¬KB4091666ºÍKB4078407Á½¸ö²¹¶¡°ü£¬¾ù¿É´ÓMicrosoft Update CatalogÃÅ»§ÍøÕ¾ÊÖ¶¯ÏÂÔØ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/microsoft-issues-more-spectre-updates-for-intel-cpus/131468/