ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ14ÖÜ

°ä²¼¹¦·ò 2018-04-09

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ02ÈÕÖÁ06ÈÕ¹²ÊÕ¼°²È«·ì϶68¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶£»Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶£»Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶£»D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ£»Panera BreadÓû§Êý¾Ýй¶£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ï죻×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ£»·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶£»×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Apple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶

        Apple MacOS "CoreTypes"×é¼þ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉÈÆ¹ý°²È«ÏÞ¶ÈÖ´ÐÐδÊÚȨ²Ù×÷¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208692
2¡¢Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶

        Apple Safari WEBKIT×é¼þ´æÔÚÄÚ´æ·ÛËé·ì϶£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208695
3¡¢Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶

        Cisco IOS XE SoftwareµÄCLI½âÎöÆ÷ÔÚʵÏÖÉÏ´æÔÚÊäÈëÑéÖ¤·ì϶£¬±¾µØµØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔrootȨÏÞÖ´ÐкÅÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-cmdinj
4¡¢Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶

        Schneider Electric Modicon PLC FTP·þÎñÆ÷δÏ޶ȺÅÁî²ÎÊý³¤¶È£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬽øÐлؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/
5¡¢D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶

        D-Link DSL-3782 'set Diagnostics_Entry'´¦ÖÃÊäÈëÖµ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/SECFORCE/CVE-2018-8941


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Hudson's Bay CompanyÔÚÖÜÈÕÈ·ÈϳÆ£¬Æä±±ÃÀµØÓòµÄ×Ó¹«Ë¾Saks Fifth Avenue¡¢Saks Off 5THÒÔ¼°Lord£¦TaylorµÄ²¿ÃÅÓû§µÄÐÅÓþ¿¨ÐÅϢй¶£¬¸ÃÊÂÎñÓ°ÏìÁË´Ó2017Äê5Ôµ½2018Äê3ÔÂÔÚ±±ÃÀÉÌµê½øÐйýÖ§¸¶µÄÔ¼500ÍòÕÅÐÅÓþ¿¨¡£Ä¿Ç°ÐÅÓþ¿¨ÐÅÏ¢ÊÇΨһй¶µÄÊý¾Ý£¬Saks Fifth AvenueÔÚÉêÃ÷ÖаµÊ¾£¬Ã»Óм£ÏóÅú×¢Éç»á±£ÏÕºÅÂë»òÉç»á±£ÏÕºÅÂë¡¢¼ÝÕÕºÅÂë»òÃÜÂëÊܵ½Ó°Ïì¡£°²È«³§ÉÌGemini Advisory³Æ¸ÃÊÂÎñÓëºÚ¿ÍÍÅ»ïJokerStash£¨Ò²±»³ÆÎªFIN7£©ÓйØ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/credit-card-data-swiped-from-5m-saks-lord-taylor-customers/130877/

2¡¢Panera BreadÓû§Êý¾Ýй¶£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        °²È«×êÑÐÔ±Brian Krebs»ã±¨³ÆÃæ°üÁ¬ËøµêPanera BreadµÄÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍòÓû§µÄ¼Í¼£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢ÉúÈÕºÍÐÅÓþ¿¨ºÅÂëµÄ×îºóËÄλÊý×Ö¡£ÕâЩÊý¾ÝÖ±µ½ÖÜÒ»»¹Äܹ»ÔÚPanerabread.comÉÏÒÔ´¿Îı¾µÄ´ó¾Ö½Ó¼û¡£°²È«×êÑÐÔ±Dylan Houlihan×î³õÓÚ2017Äê8ÔÂÏòPanera»ã±¨Á˸Ãй¶ÊÂÎñ£¬µ«¸Ã¹«Ë¾²¢Ã»ÓвÉÈ¡Ðж¯À´½â¾öÎÊÌâ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2018/04/panerabread-com-breach-could-have-impacted-millions/

3¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Flashpoint×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ1000¸öMagentoÖÎÀíÃæ°å±»ºÚ¿ÍÈëÇÖ£¬¹¥»÷Õßͨ¹ý±©Á¦¹¥»÷»ñµÃ½Ó¼ûȨÏÞ£¬ÒÔÇÔÊØÐÅÓþ¿¨ºÅÂëºÍ×°ÖöñÒâÈí¼þ£¨Êý¾ÝÇÔÈ¡Èí¼þAZORultºÍ¶ñÒâ¿ó¹¤Rarog£©¡£Flashpoint³Æ´óÎÞÊýÍøÕ¾ÊôÓÚ½ÌÓýºÍÒ½ÁƱ£½¡ÐÐÒµ£¬IPµØÖ·ÖØÒªÉ¢²¼ÔÚÃÀ¹úºÍÅ·ÖÞ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.flashpoint-intel.com/blog/compromised-magento-sites-delivering-malware/

4¡¢·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¾Ý±¾µØÃ½Ì屨·£¬·ÒÀ¼Ê·ÉϵÚÈý´óÊý¾Ýй¶ÊÂÎñµ¼Ö³¬¹ý13ÍòÃû·ÒÀ¼¹«ÃñµÄÍ´´¦Ð¹Â¶¡£¹¥»÷ÕßÈëÇÖÁËHelsingin Uusyrityskeskus¹«Ë¾µÄÍøÕ¾£¨http://liiketoimintasuunnitelma.com£©£¬ÇÔÈ¡Á˳¬¹ý13ÍòÓû§µÄÃ÷ÎĵǼÃûºÍÃÜÂë¡£ÕâЩÓû§ÃûºÍÃÜÂëÒÔ´¿Îı¾µÄ´ó¾Ö´æ´¢ÔÚ¸ÃÍøÕ¾ÉÏ£¬²¢Ã»ÓÐʹÓÃÈκιþÏ£¼ÓÃÜ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/04/helsingin-uusyrityskeskus-hack.html

5¡¢×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ˼¿ÆTalos×êÑÐÍŶÓÔÚNatus NeuroWorksÈí¼þÖз¢ÏÖ¶à¸ö°²È«·ì϶£¬NatusµÄÒ½ÁƲúÆ·Xltek EEGÊܵ½Ó°Ïì¡£·ì϶ÁìÓòÔ̺¬4¸öµ¼Ö´úÂëÖ´Ðеķì϶ºÍ1¸öµ¼Ö»ؾø·þÎñµÄ·ì϶¡£NatusÔÚNeuroworks 8.5 GMA2Öн¨¸´ÁËÕâЩ·ì϶£¬½¨ÒéʹÓÃÕâЩÉ豸µÄÒ½ÁÆ»ú¹¹¾¡¿ì½øÐиüС£

        Ô­ÎÄÁ´½Ó£ºhttp://blog.talosintelligence.com/2018/04/vulnerability-spotlight-natus.html