¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181217

°ä²¼¹¦·ò 2018-12-17
1¡¢ÃÀDoD³ÆÆäµ¯Â·µ¼µ¯·ÀÓùϵͳδͨ¹ýÍøÂ簲ȫÉó¼Æ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý»ã±¨£¬ÃÀ¹úµÄµ¯Â·µ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂ簲ȫÉ󼯡£¸Ã»ã±¨Ö¸³öBMDSÉèʩδÄÜÖ´ÐÐÓ¦Óеݲȫ½ÚÔì´ëÊ©£¬Ô̺¬¶à³É·ÖÉí·ÝÈÏÖ¤¡¢·ì϶ÆÀ¹À»ººÍ½â¡¢·þÎñÆ÷»ú¼Ü°²È«¡¢¿ÉÒÆ¶¯Ã½ÌåÉϵĻúÃÜÊý¾Ý±  £»¤ºÍ¼¼ÊõÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£´Ë±í£¬Ò»Ð©ÎïÀí°²È«´ëʩҲûÓе½Î»£¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»ÓÐ×°ÖÃÔÚ±ØÒª×°ÖõĵØÎ»¡£¼à²ì³¤°ì¹«ÊÒÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕǰ»ØÓ¦¸Ã·Ý»ã±¨¡£


Ô­ÎÄÁ´½Ó£º

https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF


2¡¢¿¨°Í˹»ùл㱨Åû¶µç¶¯Æû³µ³äµçÕ¾Öеݲȫ·çÏÕ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ƾ¾Ý¿¨°Í˹»ù³¢ÊÔÊÒµÄÒ»·Ý»ã±¨£¬ChargePoint¹«Ë¾Ôì×÷µÄ¼ÒÓõ綯Æû³µ³äµçÕ¾´æÔÚ¶à¸ö°²È«·ì϶£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßµ÷Õû³äµçµçÁ÷ÒÔ¼°ËæÊ±ÖÕ³¡Æû³µµÄ³äµç¹ý³Ì£¬´Ó¶øµ¼ÖÂDZÔÚµÄÎïÀí°Ü»µºÍ¾­¼ÃËðʧ¡£¸Ã¼ÒÓóäµçÕ¾Ö§³ÖWiFiºÍÀ¶ÑÀÎÞÏß¼¼Êõ£¬Óû§¿Éͨ¹ýiOS¼°Androidƽ̨µÄÒÆ¶¯appÔ¶³Ì½ÚÔì³äµç¹ý³Ì¡£×êÑÐÈËÔ±·¢ÏÖ¸ÃÉ豸µÄWeb·þÎñÆ÷´æÔÚÖ¤Ê鰲ȫÎÊÌâ¡¢»º³åÇøÒç³öµÈ·ì϶¡£Ä¿Ç°¸Ã¹«Ë¾Òѽ¨¸´ÁËÕâЩ·ì϶¡£


 Ô­ÎÄÁ´½Ó£º

https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/12/13084354/ChargePoint-Home-security-research_final.pdf


3¡¢Twitter°ä²¼Í¨Ã÷¶È»ã±¨£¬³ÆÆäÿÔÂÊÕµ½50ÍòÀ¬»øÓʼþ»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝTwitterµÄ2018ÄêÉϰëÄêͨÃ÷¶È»ã±¨£¬ÆäÿÔÂÊÕµ½µÄÀ¬»øÓʼþ»ã±¨ÊýÁ¿³ÖÐø½µÂ䣬´Ó1Ô·ݵľùÔÈÔ¼868349·Ý»ã±¨½µÂäµ½6Ô·ݵÄÔ¼504259·Ý¡£¸Ã»ã±¨»¹Ç¿µ÷Á˵±¾Ö¶ÔÓû§Êý¾ÝµÄÅû¶ҪÇó´ó·ùÉÏÉý¡£½ñÄê1ÔÂÖÁ6Ô£¬TwitterÊÕµ½È·µ±¾ÖÒªÇó±ÈÉϸö»ã±¨ÆÚÔö³¤ÁË10%£¬ÕâÊÇÈýÄêÀ´×î´óµÄÔö³¤¡£´Ë±í£¬1ÔÂÖÁ6Ô³¬¹ý205100¸öÕË»§Òò°ä²¼¿Ö²ÀÖ÷ÒåÄÚÈݶø±»É¾³ý£¬Óë2017ÄêϰëÄêµÄÊý×Ö£¨120Íò£©Ïà±È´ó·ù½µÂä¡£1ÔÂÖÁ6ÔÂÆÚ¼ä»¹Óг¬¹ý487300¸öÕË»§Òò¶ùͯÐÔ°þÏ÷ÎÊÌâ¶ø±»·â½û¡£


Ô­ÎÄÁ´½Ó£º

https://transparency.twitter.com/


4¡¢APT28ÀûÓÃZebrocyºóÃźÍCannonľÂí¹¥»÷¶à¸öµ±¾Ö»ú¹¹

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Palo Alto NetworksµÄUnit42ÍŶӰ䲼¹ØÓÚAPT28½üÆÚÕë¶Ôµ±¾Ö»ú¹¹µÄ¶ñÒâ»î¶¯µÄ·ÖÎö»ã±¨¡£2018Äê10ÔÂÖÐÑ®µ½2018Äê11ÔÂÖÐÑ®ÆÚ¼ä£¬APT28³ÖÐøÏ®»÷ÁËÊÀ½ç¸÷µØµÄ¶à¸öµ±¾Ö»ú¹¹£¬ÖØÒªÖ¸±êÊDZ±Ô¼¹ú¶È£¬µ«Ò²Ô̺¬¼¸¸öǰËÕÁª¹ú¶È¡£ÕâЩ¹¥»÷»î¶¯ÖØÒª²¿ÊðÁËZebrocy»òCannon±äÖÖ£¬Æä½»¸¶µÄ¶ñÒâÎĵµÊ¹ÓÃÁËͳһ¸ö×÷ÕßÃû³Æ£ºJoohn¡£×êÑÐÈËÔ±·ÖÎöÁËÍøÂçµ½µÄ9¸ö¶ñÒâÎĵµ£¬²¢³ÉÁ¢ÁËDear Joohn»î¶¯µÄ¹¦·òÏß¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/dear-joohn-sofacy-groups-global-campaign/


5¡¢Ð¶ñÒâÈí¼þCapitalInstall£¬ÖØÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


NetskopeÍþв×êÑг¢ÊÔÊÒ·¢ÏÖÒ»¸öеĶñÒâÈí¼þCapitalInstall¡£¸Ã¶ñÒâÈí¼þͨ¹ýMicrosoft Azure·Ö·¢£¬ÕâʹµÃÆäIPµØÖ·±»ºÜ¶à¹«Ë¾²ÎÓë°×Ãûµ¥¡£CapitalInstall¼Ù×°³ÉÊ¢ÐÐÈí¼þ£¨ÀýÈçAdobe CC 2019£©µÄÃâ·ÑÃÜÔ¿ºÍÐí¿ÉÖ¤£¬ÓÕÆ­Óû§½øÐÐÏÂÔØ£¬²¢°ó¸¿Á˸æ°×Èí¼þLinkury£¬½ø¶øÔÚÓû§µÄÍÆËã»ú¸ßµÍÔØ¸ü¶àDZÔÚÓк¦µÄ·¨Ê½¡£CapitalInstallÖØÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://www.netskope.com/blog/capitalinstall-hosted-and-served-via-iaas


6¡¢Î÷ÃÅ×Ó½¨¸´SINUMERIK½ÚÔìÆ÷ÖеĶà¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Î÷ÃÅ×Ó½¨¸´ÁËSINUMERIK½ÚÔìÆ÷ÖеÄ10¸ö°²È«·ì϶¡£ÆäÖзì϶£¨CVE-2018-11466£©ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòTCP¶Ë¿Ú102·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢DoS»òÖ´ÐÐËÁÒâ´úÂ룬¸Ã·ì϶µÄÀûÓò¢²»±ØÒªÈκÎÓû§½»»¥¡£´Ë±í£¬·ì϶£¨CVE-2018-11457ºÍCVE-2018-11458£©ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËͶñÒâTCPÊý¾Ý°üÀ´½øÐÐÌáȨ¡£½¨ÒéÓû§¾¡¿ì½øÐиüС£Î÷ÃÅ×Ó×î½ü°ä·¢½«Ïñ΢Èí¡¢AdobeºÍSAPÒ»ÑùÔÚÿ¸öÔµĵڶþ¸öÐÇÆÚ¶þ°ä²¼°²È«²¼¸æ¡£


 Ô­ÎÄÁ´½Ó£º

https://cert-portal.siemens.com/productcert/pdf/ssa-170881.pdf


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù