ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ24ÖÜ

Ðû²¼Ê±¼ä 2018-06-18

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
        2018Äê06ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö £¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows 'HTTP.sys'Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£» £»Microsoft Excel CVE-2018-8248Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£» £»Microsoft Windows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£» £»Microsoft Windows CVE-2018-8213í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£» £»Cisco Network Services Orchestrator CVE-2018-0274í§ÒâÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÖÇÀûÒøÐÐÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬Êý°Ų̀ÅÌËã»úµÄMBR±»ÆÆË𣻣»£»£»£» £»º«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùCoinrailÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª£»£»£»£»£» £»Weight Watchers¹«Ë¾µÄKubernetesЧÀÍÆ÷δÉèÖÃÃÜÂë £¬£¬£¬£¬£¬£¬²¿·Ö»ù´¡ÉèÊ©µÄƾ֤й¶£»£»£»£»£» £»AÕ¾ÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬½üÍòÍòÓû§µÄÊý¾Ýй¶£»£»£»£»£» £»ÁãÊÛ¹«Ë¾Dixons CarphoneÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬Ô¼590ÍòÓû§µÄÐÅÓÿ¨ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£

        ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£

 

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Microsoft Windows 'HTTP.sys'Ô¶³Ì´úÂëÖ´ÐÐÎó²î

        Microsoft Windows 'HTTP.sys'±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8231
2¡¢Microsoft Excel CVE-2018-8248Ô¶³Ì´úÂëÖ´ÐÐÎó²î

        Microsoft Excel´¦Öóͷ£Äڴ湤¾ß±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ £¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂëÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8248
3¡¢Microsoft Windows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î

        Microsoft Windows DNSAPI.dll´¦Öóͷ£DNSÏìÓ¦±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8225
4¡¢Microsoft Windows CVE-2018-8213í§Òâ´úÂëÖ´ÐÐÎó²î

        Microsoft Windows´¦Öóͷ£Äڴ湤¾ß±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8213
5¡¢Cisco Network Services Orchestrator CVE-2018-0274í§ÒâÏÂÁîÖ´ÐÐÎó²î

        Cisco Network Services Orchestrator CLIÆÊÎöÆ÷±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬ÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-nso

 

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ñо¿Ö°Ô±·¢Ã÷½©Ê¬ÍøÂçVPNFilter¾íÍÁÖØÀ´ £¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

        5ÔÂ24ÈÕÖÇÀûÒøÐÐÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼͨ¹ýÒøÐеÄSWIFTתÕËϵͳÇÔÈ¡×ʽ𠣬£¬£¬£¬£¬£¬²¢Í¬Ê±Í¨¹ý´ÅÅ̲Á³ý¶ñÒâÈí¼þÆÆËðÁËÊý°Ų̀µçÄÔÒÔÊèÉ¢Ô±¹¤µÄ×¢ÖØÁ¦¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÍâµØÃ½ÌåµÄ±¨µÀ £¬£¬£¬£¬£¬£¬ËäÈ»ÔÚÏßϵͳÊÂÇéÕý³£ £¬£¬£¬£¬£¬£¬µ«¸ÃÒøÐеĶà¸öÍøµãЧÀÍÍ߽⡣¡£¡£¡£¡£¡£¡£ËäȻûÓÐÃ÷È·Ö¸³ö £¬£¬£¬£¬£¬£¬µ«¸ÃÒøÐÐѬȾµÄ¶ñÒâÈí¼þºÜ¿ÉÄÜÊÇKillDiskµÄбäÌå £¬£¬£¬£¬£¬£¬¸Ã±äÌåÖ÷Òª²Á³ýÅÌËã»úµÄMBR £¬£¬£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼Ðû²¼Á˹ØÓڸñäÌåµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-crashed-a-bank-s-computers-while-attempting-a-swift-hack/

2¡¢º«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùCoinrailÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

        ÉÏÖÜÈÕº«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùCoinrailÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬ÈëÇÖÕßÇÔÈ¡ÁËPundi X£¨NPXS£©¡¢NPER£¨NPER£©ºÍAston£¨ATX£©µÄ²¿·ÖICO´ú±Ò £¬£¬£¬£¬£¬£¬ÉúÒâËùûÓÐÅû¶Ïà¹Ø±»µÁ×ʽðµÄÏêϸÊý×Ö £¬£¬£¬£¬£¬£¬µ«ÓÐÓû§¸ú×ÙÁËÈëÇÖÕßµÄÕË»§µØµã £¬£¬£¬£¬£¬£¬ÒÔΪÏà¹Ø±»µÁ×ʽð¼ÛÖµÔÚ3000Íòµ½4000ÍòÃÀÔªÖ®¼ä £¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼Ò»°ëΪNPXS´ú±Ò¡£¡£¡£¡£¡£¡£¡£Coinrail³ÆÕýÓëÊÜÓ°ÏìµÄICO¹«Ë¾ÏàÖúÒÔ¶³½á±»µÁµÄ´ú±Ò¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/south-korean-cryptocurrency-exchange-coinrail-gets-hacked/

3¡¢Weight Watchers¹«Ë¾µÄKubernetesЧÀÍÆ÷δÉèÖÃÃÜÂë £¬£¬£¬£¬£¬£¬²¿·Ö»ù´¡ÉèÊ©µÄƾ֤й¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

        µÂ¹úÇå¾²³§ÉÌKromtechµÄÑо¿Ö°Ô±·¢Ã÷Weight Watchers¹«Ë¾µÄKubernetesЧÀÍÆ÷δÉèÖÃÃÜÂë £¬£¬£¬£¬£¬£¬ÕâʹµÃÈκÎÈ˶¼¿ÉÒÔͨ¹ý¶Ë¿Ú10250»á¼û¸ÃЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ¸ÃЧÀÍÆ÷ÉÏ·¢Ã÷ÁËWeight Watchers¹«Ë¾µÄIT»ù´¡ÉèÊ©µÄÉèÖÃÐÅÏ¢ £¬£¬£¬£¬£¬£¬°üÀ¨ÖÎÀíԱƾ֤¡¢102¸öÓòµÄ»á¼ûÃÜÔ¿¡¢AWS»á¼ûÃÜÔ¿µÈ¡£¡£¡£¡£¡£¡£¡£Weight Watchers³ÆÕâ²»ÊÇÒ»¸öÉú²úÍøÂç¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/weight-watchers-it-infrastructure-exposed-via-no-password-kubernetes-server/

4¡¢AÕ¾ÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬½üÍòÍòÓû§µÄÊý¾Ýй¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

        ½ñÈÕÆÆÏþAcFunÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬½üÍòÍòÓû§µÄÊý¾Ýй¶ £¬£¬£¬£¬£¬£¬°üÀ¨Óû§ID¡¢êdzơ¢¼ÓÃÜ´æ´¢µÄÃÜÂëµÈ¡£¡£¡£¡£¡£¡£¡£ÔÚ2017Äê7ÔÂ7ÈÕ֮ǰµÇ¼¹ýAcFunµÄÓû§ÊÜÓ°Ïì £¬£¬£¬£¬£¬£¬µ«Ò²½¨ÒéÃÜÂë¹ýÓÚ¼òÆÓµÄÆäËüÓû§ÐÞ¸ÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£AcFun³ÆÒѾ­ÁªºÏÄÚ²¿ºÍÍⲿµÄÊÖÒÕר¼Ò¶ÔÎÊÌâ¾ÙÐÐÅÅ²é £¬£¬£¬£¬£¬£¬²¢Éý¼¶ÏµÍ³µÄÇ徲Ʒ¼¶¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttp://www.sohu.com/a/235455264_250147

5¡¢ÁãÊÛ¹«Ë¾Dixons CarphoneÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬Ô¼590ÍòÓû§µÄÐÅÓÿ¨ÐÅϢй¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

        ÁãÊÛ¹«Ë¾Dixons CarphoneÅû¶һ¸öÉæ¼°Ô¼590ÍòÕÅÐÅÓÿ¨ºÍ120ÍòÌõСÎÒ˽¼ÒÊý¾Ý¼Í¼µÄÇå¾²ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆºÚ¿Í»á¼ûÁË´æ´¢ÔÚÆäCurrys PC WorldºÍDixons TravelÊÐËÁµÄϵͳÖеÄÔ¼590ÍòÕÅÐÅÓÿ¨Êý¾Ý £¬£¬£¬£¬£¬£¬ÆäÖÐ580ÍòÕÅÐÅÓÿ¨¾ßÓÐоƬºÍPINÂë±£»£»£»£»£» £»¤ £¬£¬£¬£¬£¬£¬ÕâÒâζןڿͻñÈ¡µÄÊý¾Ý¼ÈûÓаüÀ¨PINÂë¡¢CVV £¬£¬£¬£¬£¬£¬Ò²Ã»ÓаüÀ¨ÈκοÉÒÔ¾ÙÐгֿ¨ÈËʶ±ðºÍ¹ºÖÃÐÐΪµÄÑéÖ¤Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÕýÔÚÁªÏµÊÜÓ°ÏìµÄÓû§ £¬£¬£¬£¬£¬£¬²¢ÏòËûÃǸøÓ轨Òé¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73479/data-breach/dixons-carphone-hacked.html