¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180831

°ä²¼¹¦·ò 2018-08-31

¡¾Êý¾Ýй¶¡¿¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


8ÔÂ22ÈÕÖÁ24ÈÕÆÚ¼ä£¬¼ÓÄô󺽿չ«Ë¾·¢ÏÖÒì³£µÄµÇ¼»î¶¯£¬ÎªÁ˱£»¤Óû§µÄÊý¾Ý£¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£29ÈÕ£¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬³ÆÆäÓ×ÎÒ×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ½Ó¼û¡£ÕâЩ×ÊÁÏÖÁÉÙÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂ룬Ҳ¿ÉÄÜÔ̺¬ÐԱ𡢵®ÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉêÃ÷Öиù«Ë¾°µÊ¾Óû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/


¡¾·ÖÎö»ã±¨¡¿¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚ½©Ê¬ÍøÂçÏÂÔØÎļþµÄͳ¼Æ·ÖÎö


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼ÁË2017ÄêϰëÄêºÍ2018ÄêÉϰëÄêµÄ½©Ê¬ÍøÂç»î¶¯µÄ·ÖÎöÁ˾Ö£¬ÖØÒª·¢ÏÖÔ̺¬£ºËæ×ÅÍøÂç·¸×ï·Ö×ÓÆðÍ·½«½©Ê¬ÍøÂçÊÓΪ¶ñÒâÍÚ¿óµÄ¹¤¾ß£¬¶ñÒâ¿ó¹¤ÔÚ½©Ê¬ÍøÂçÏÂÔØÎļþÖеıÈÀýÔÚÔö³¤£»ºóÃųÖÐøÕ¼¾Ý½©Ê¬ÍøÂçÏÂÔØÎļþµÄ´ó²¿ÃÅ£»dropperµÄÊýÁ¿Ò²ÔÚÔö³¤£»2018ÄêÒøÐÐľÂíµÄ±ÈÀýÓÐËù½µÂ䣻½©Ê¬ÍøÂçÔ½À´Ô½¶àµØÆ¾¾Ý¿Í»§µÄÐèÒª½øÐÐ×âÁÞ£¬ºÃ¶àÇé¿öÏÂÄÑÒÔÈ·¶¨½©Ê¬ÍøÂçµÄרְ¹¤×÷¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/what-are-botnets-downloading/87658/


¡¾Íþвµý±¨¡¿Ç÷Ïò¿Æ¼¼·¢ÏÖÓëBahamut¡¢ConfuciusºÍPatchworkÓйصÄAPT×éÖ¯Urpage


Ç÷Ïò¿Æ¼¼Í¨¹ý¶ÈÎöÐµĹ¥»÷×éÖ¯UrpageÓëAPT×éÖ¯Confucius¡¢PatchworkÒÔ¼°BahamutµÄÀàËÆÖ®´¦£¬Éî¿Ì̽ÇóÁËÍøÂç¹¥»÷Ö®¼ä¿ÉÄÜ´æÔÚµÄÁªÏµ¡£UrpageÖØÒªÕë¶ÔÎÚ¶û¶¼ÓïºÍ°¢À­²®ÓïµÄÎÄ×Ö´¦ÖÃÆ÷InPage£¬ÆäʹÓÃÁËÓëConfuciusºÍPatchworkÒ»ÑùµÄDelphiºóÃÅ×é¼þ£¬²¢Ê¹ÓÃÁËÓëBahamutÀàËÆµÄ¶ñÒâÈí¼þ¡£ºÜ¶àÀàËÆÖ®´¦ºÍÁªÏµÅú×¢£¬Õâ¿ÉÄÜÊÇÒ»¸öµ¥Ò»µÄÊÕ·ÑÍŶӽ«Æä¹¤¾ßºÍ·þÎñÏúÊÛ¸øÓµÓÐ·ÖÆçÖ÷ÕźÍÖ¸±êµÄÆäËü×éÖ¯¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/the-urpage-connection-to-bahamut-confucius-and-patchwork/


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖ7339¸öMagentoÔÚÏßÉ̵êϰȾ¶ñÒâÈí¼þMagentoCore


ºÉÀ¼°²È«×êÑÐÈËÔ±Willem de Groot·¢ÏÖ¶ñÒâÈí¼þMagentoCoreÔÚ´ÓǰÁù¸öÔÂÄÚϰȾÁË7339¸öMagentoÔÚÏßÉ̵ê¡£MagentoCoreÊÇÒ»¸öskimmer¾ç±¾£¬Í¨³£¹ÒÔØÔÚÉ̵êµÄ¸¶¿îÒ³Ãæ²¢ÇÔÈ¡Óû§µÄÖ§¸¶¿¨ÐÅÏ¢¡£¸Ã¾ç±¾´Ómagentocore.netÓòÃû¼ÓÔØ£¬¾ùÔÈÿÌìϰȾ50µ½60¼ÒÔÚÏßÉ̵ê¡£Groot»¹³ÆÄ¿Ç°ËùÓеÄMagentoÉ̵êÖÐÓÐ4.2£¥Ï°È¾ÁËÒ»ÖÖ»ò¶àÖÖ¶ñÒâ¾ç±¾¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/magentocore-malware-found-on-7-339-magento-stores/


¡¾·ì϶²¹¶¡¡¿4ÄêǰÅû¶µÄ·ì϶Misfortune CookieÈÔÔÚÓ°Ï첿ÃÅÒ½ÁÆÉ豸


CyberMDX×êÑÐÈËÔ±·¢ÏÖ¸ßͨ×Ó¹«Ë¾CapsuleµÄDatacatptorÖÕ¶Ë·þÎñÆ÷£¨DTS£©²úÆ·ÒÀÈ»Ò×ÊÜMisfortune Cookie·ì϶µÄÓ°Ïì¡£DTS×÷ΪҽÁÆÉè±¸Íø¹Ø£¬ÓÃÓÚ½«¼à»¤ÒÇ¡¢ºôÎüÆ÷¡¢Âé×íϵͳºÍÊäÒº±ÃµÈÉ豸Ïνӵ½Ò½ÔºµÄÍøÂç¡£¸Ã·ì϶ÓÚ2014ÄêÓÉCheck PointÅû¶£¬´æÔÚÓÚAllegroSoftµÄRomPager×é¼þÖУ¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ICS-CERTÕë¶Ô¸Ã·ì϶£¨CVE-2014-9222£©°ä²¼ÁËÖҸ棬¸Ã·ì϶µÄCVSSµÃ·ÖΪ9.8¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/4-year-old-misfortune-cookie-rears-its-head-in-medical-gateway-device/


¡¾·ì϶²¹¶¡¡¿Ê©ÄÍµÂµçÆø°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·Öеݲȫ·ì϶


Ê©ÄÍµÂµçÆø½¨¸´ÆäµçÔ´ÖÎÀíϵͳPowerLogic PM5560¼°¿É±à³ÌÂß¼­½ÚÔìÆ÷Modicon M221ÖеĶà¸ö°²È«·ì϶¡£¹Ì¼þ°æ±¾2.5.4֮ǰµÄPowerLogic PM5560´æÔÚ¿çÕ¾¾ç±¾·ì϶£¨CVE-2018-7795£©£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¹Ì¼þ°æ±¾V1.6.2.0֮ǰµÄModicon M221´æÔÚ¶à¸ö·ì϶£¬Ô̺¬¿ÉÔÊÐíδ¾­ÊÚȨµÄÓû§³Á·ÅÈÏÖ¤ÐòÁеķì϶£¨CVE-2018-7790£©¡¢¿ÉÔÊÐíδ¾­ÊÚȨµÄÓû§¸²¸ÇÔ­ÃÜÂëµÄ·ì϶£¨CVE-2018-7791£©ÒÔ¼°¿ÉÔÊÐíδ¾­ÊÚȨµÄÓû§Ê¹Óòʺç±íÆÆ½âÃÜÂëµÄ·ì϶£¨CVE-2018-7792£©¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/high-severity-flaws-patched-in-schneider-electric-products/137034/