ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ21ÖÜ

°ä²¼¹¦·ò 2018-05-28

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ21ÈÕÖÁ27ÈÕ¹²ÊÕ¼°²È«·ì϶47¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGNU glibc±¾µØ»º³åÇøÒç¶Âí½Å£»Foxit Reader U3DͼÐζà¸öËÁÒâ´úÂëÖ´Ðзì϶£»Trend Micro Email Encryption GatewayºÅÁî×¢Èë·ì϶£»Intel¶à¸öCPUÓ²¼þCVE-2018-3640ÐÅϢй¶·ì϶£»D-Link DIR-550AºÍDIR-604MÔ¶³Ì´úÂëÖ´Ðзì϶¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖÀûÓÃGoogle PlayºÍFackbookµÄAPT¹¥»÷»î¶¯RedDawn£»×êÑÐÍŶӷ¢ÏÖ·¸×ïÍÅ»ïChryseneÕë¶ÔÖж«ºÍÓ¢¹úICSÍøÂçµÄ¹¥»÷»î¶¯£»×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçBrain FoodÔÚÒ»ÖÜÄÚϰȾԼ2400¸öÍøÕ¾£»°²È«×êÑÐÈËÔ±·¢ÏÖD-Link DIR-620·ÓÉÆ÷ÖдæÔÚºóÃÅÕË»§£»×êÑÐÍŶӷ¢ÏÖÕë¶Ô°Í»ù˹̹µÄAPT×éÖ¯ConfuciusÓëPatchwork´æÔÚ¹ØÁª¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢GNU glibc±¾µØ»º³åÇøÒç¶Âí½Å

        GNU C Library mempcpyº¯ÊýÔÚAVX-512-optimizedʵÏÖÖдæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://sourceware.org/bugzilla/show_bug.cgi?id=23196
2¡¢Foxit Reader U3DͼÐζà¸öËÁÒâ´úÂëÖ´Ðзì϶

        Foxit Reader´¦ÖÃPDFÖеÄU3DͼÐδæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://srcincite.io/advisories/src-2018-0016/
3¡¢Trend Micro Email Encryption GatewayºÅÁî×¢Èë·ì϶

        Trend Micro Encryption for Email LauncherServer´æÔÚºÅÁî×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-416/
4¡¢Intel¶à¸öCPUÓ²¼þCVE-2018-3640ÐÅϢй¶·ì϶

        Intel CPUÈôÀûÓô§Ä¦Ö´ÐÐÇÒÖ´Ðд§Ä¦¶Áȡϵͳ¼Ä·ÅÆ÷µÄÇé¿öÏ´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶ͨ¹ý²àÐÅ··ÖÎö»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.kb.cert.org/vuls/id/180049
5¡¢D-Link DIR-550AºÍDIR-604MÔ¶³Ì´úÂëÖ´Ðзì϶

        D-Link DIR-550AºÍDIR-604M´¦ÖÃαÔìHTTPÒªÇó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐвÙ×÷ϵͳºÅÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://fortiguard.com/zeroday/FG-VD-18-060


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃGoogle PlayºÍFackbookµÄAPT¹¥»÷»î¶¯RedDawn

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ×êÑÐÈËÔ±·¢ÏÖÕë¶Ô³¯ÏÊÅÑÌÓÕßµÄÒ»ÏÔӵļäµý»î¶¯¡£¸ÃAPT×éÖ¯±»³ÆÎªSun Team£¬ÖØÒªÊ¹ÓÃGoogle PlayºÍFacebook×÷Ϊ¹¥»÷ý½é£¬ËüÏÔʾÁËÒÆ¶¯Íþв¾ÖÊÆ·¢Õ¹µÄ¿ì¶Å×жà¿ì£¬ÓÉÓÚ¸ÃAPT½«Õ½Êõ×ªÒÆµ½×¨Ò»Óڴ˲¿ÃÅ¡£¾Ý¹Û²ìËüµÄ×êÑÐÈËÔ±³Æ£¬ËüÔÚGoogle PlayÖа䲼ÁËÈý¸ö¡°Î´°ä²¼¡±µÄ²âÊÔ°æÀûÓ÷¨Ê½£¬ÆäÖ¸±êÊǽ²º«ÓïµÄÓû§¡£ËûÃǼÙ×°³ÉFood Ingredients Info¡¢ast AppLockºÍAppLockFree¡£Food Ingredients InfoºÍFast AppLockÓÃÓÚ͵͵ÇÔÈ¡Ãô¸ÐÊý¾Ý£¬ÈçÁªÏµÈË¡¢ÐÅÏ¢¡¢Í¨»°¹àÒôºÍÕÕÆ¬£¬²¢ÇÒ»¹¿ÉÄÜ´ÓC2·þÎñÆ÷½Ó¹ÜºÅÁîºÍÆäËû¿ÉÖ´ÐÐÎļþ£¨.dex£©£¬AppLockFreeËÆºõÊÇ¿úËŹ¤×÷µÄÒ»²¿ÃÅ£¬Îª½«À´µÄÒ»ÂÖ¹¥»÷µì¶¨»ù´¡¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/reddawn-espionage-campaign-shows-mobile-apts-on-the-rise/132081/

2¡¢×êÑÐÍŶӷ¢ÏÖ·¸×ïÍÅ»ïChryseneÕë¶ÔÖж«ºÍÓ¢¹úICSÍøÂçµÄ¹¥»÷»î¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ×êÑÐÍŶӷ¢ÏÖ·¸×ïÍÅ»ïChryseneÒ»ÏòÒÔÀ´¶¼Õë¶ÔÖж«ºÍÓ¢¹ú×éÖ¯µÄ¹¤ÒµÍøÂç¡£¹¤ÒµÍøÂ簲ȫ¹«Ë¾Dragos³ÆÆäΪ¡°Chrysene¡±£¬¸ÃÍÅ»ïÓëOilRigºÍGreenbugÓйØ£¬ÖØÒª¼¯ÖÐÔÚ°¢À­²®º£Í嵨Óò£¬²¢ÇҲμÓÁËShamoonºÍShamoon 2¹¥»÷¡£Æ¾¾ÝDragosµÄ˵·¨£¬Chrysene´Ó֮ǰµÄOilRigºÍGreenbugµÄ¼äµý»î¶¯ÑÝ±ä¶øÀ´£¬ËûÃǵŤ¾ß¡¢¼¼ÊõºÍ·¨Ê½³Áµþ£¬µ«ÓëÕâЩÆäËû¼¯ÌåÏà±È£¬ChryseneÔÚ¼¼ÊõÄÜÁ¦·½ÃæÓÐ×ÅÏÔ×ŵĽøÈ¡¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/chrysene-group-targets-ics-networks-middle-east-uk

3¡¢×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçBrain FoodÔÚÒ»ÖÜÄÚϰȾԼ2400¸öÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ½©Ê¬ÍøÂçBrain Foodͨ¹ý¶ñÒâPHP¾ç±¾Ï°È¾ºÏ·¨ÍøÕ¾£¬²¢°ä²¼¼Ùð¼õ·ÊÒ©ºÍ²¹ÄÔÒ©µÄ¸æ°×¡£Proofpoint×êÑÐÈËÔ±³Æ¸Ã½©Ê¬ÍøÂçÒѾ­Ï°È¾ÁËÔ¼5000¸öÍøÕ¾£¬ÓòÃûÍйܷþÎñÉÌGoDaddyÊܵ½µÄÓ°Ïì×î´ó£¬Ô¼Õ¼5000¸öÍøÕ¾µÄ40%£¬Æä´ÎÒÀÐòÊÇDreamHost¡¢UnitedLayerºÍCyrusOne¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/malicious-php-script-infects-2400-websites-in-the-past-week/132161/

4¡¢°²È«×êÑÐÈËÔ±·¢ÏÖD-Link DIR-620·ÓÉÆ÷ÖдæÔÚºóÃÅÕË»§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¿¨°Í˹»ù³¢ÊÔÊҵݲȫ×êÑÐÈËÔ±·¢ÏÖD-Link DIR-620·ÓÉÆ÷¹Ì¼þÖдæÔÚÒ»¸öºóÃÅÕË»§£¨CVE-2018-6213£©£¬¿Éµ¼Ö¹¥»÷Õßͨ¹ý»¥ÁªÍøÊÕÊܸÃÉ豸¡£³öÓÚ°²È«Ë¼¿¼×êÑÐÈËԱûÓÐÅû¶¸ÃºóÃÅÕË»§µÄÓû§ÃûºÍÃÜÂ룬×êÑÐÈËÔ±°µÊ¾É豸ËùÓÐÕßÎÞ·¨½ûÓøúóÃÅÕË»§¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/backdoor-account-found-in-d-link-dir-620-routers/

5¡¢×êÑÐÍŶӷ¢ÏÖÕë¶Ô°Í»ù˹̹µÄAPT×éÖ¯ConfuciusÓëPatchwork´æÔÚ¹ØÁª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Ç÷Ïò¿Æ¼¼×êÑÐÍŶӷ¢ÏÖAPT×éÖ¯ConfuciusÕë¶Ô°Í»ù˹̹µÄй¥»÷»î¶¯£¬¸Ã»î¶¯Í¨¹ý2¸öеÄÍøÕ¾ºÍÓÐЧºÉÔØ¹¥»÷Ö¸±ê£¬Ô̺¬Android¶ñÒâÀûÓÃFuddi DuniyaÒÔ¼°Ò»¸ö¶ñÒâ̸ÌìÀûÓá£×êÑÐÈËÔ±·¢ÏÖConfuciusºÍPatchworkʹÓõĶñÒâÈí¼þÖÐÔ̺¬¸ü¶àµÄ¹²Ïí´úÂë¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/confucius-update-new-tools-and-techniques-further-connections-with-patchwork/