ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ33ÖÜ

°ä²¼¹¦·ò 2018-08-20

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


 2018Äê08ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶79¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Digital Network Architecture Center CVE-2018-0427ºÅÁî×¢Èë·ì϶£»Microsoft Exchange CVE-2018-8302ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»Microsoft Excel CVE-2018-8375Ô¶³Ì´úÂëÖ´Ðзì϶£»Microsoft ChakraCore¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶£»WordPress CVE-2018-14028ËÁÒâÎļþÉÏ´«·ì϶ ¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖÕë¶Ô°ÍÎ÷ÒøÐеÄDNS½Ù³Ö¹¥»÷»î¶¯£»×êÑÐÈËÔ±³ÆGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶£»×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨£»Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬ÈýÌìÄÚËðʧ³¬¹ý1350ÍòÃÀÔª£»×êÑÐÈËÔ±·¢ÏÖÖØÒªÇÔÈ¡Office 365Í´´¦µÄPhishPoint¹¥»÷»î¶¯ ¡£

 Æ¾¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£



¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1¡¢Cisco Digital Network Architecture Center CVE-2018-0427ºÅÁî×¢Èë·ì϶


Cisco Digital Network Architecture Center CronJob scheduler API½Ó¿Ú´æÔÚºÅÁî×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÌáÉýȨÏÞÒÔROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë ¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-dna-injection


2¡¢Microsoft Exchange CVE-2018-8302ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶



 Microsoft Exchange Server´¦ÖÃÓʼþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë ¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8302


3¡¢Microsoft Excel CVE-2018-8375Ô¶³Ì´úÂëÖ´Ðзì϶


Microsoft Excel´¦ÖöñÒâxlsÎļþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8379


4¡¢Microsoft ChakraCore¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶


Microsoft ChakraCoreûÓÐÕýÈ·µÄ´¦ÖÃÄÚ´æÖеĶÔÏó£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8384


5¡¢WordPress CVE-2018-14028ËÁÒâÎļþÉÏ´«·ì϶


WordPressûÓмì²âͨ¹ýadminÇøÓòÉÏ´«µÄ²å¼þÊÇ·ñΪZIPÎļþ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÉÏ´«ËÁÒâPHPÎļþ²¢Ö´ÐÐ ¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://core.trac.wordpress.org/ticket/44710


 


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÍŶӷ¢ÏÖÕë¶Ô°ÍÎ÷ÒøÐеÄDNS½Ù³Ö¹¥»÷»î¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Radware×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÔÚÕë¶Ô°ÍÎ÷µÄDLink DSL·ÓÉÆ÷£¬Í¨¹ýDNS½Ù³Ö¹¥»÷½«ÒøÐÐÓû§³Á¶¨ÏòÖÁ´¹µöÍøÕ¾²¢ÇÔÈ¡ÆäÒøÐÐÕË»§µÄµÇ¼ʹ´¦ ¡£¹¥»÷ÕßÅú¸ÄÁËÕâЩ·ÓÉÆ÷É豸ÖеÄDNSÉèÖ㬽«ÆäÖ¸Ïò¶ñÒâµÄDNS·þÎñÆ÷£¨69.162.89.185ºÍ198.50.222.136£©£¬ÕâЩÉ豸ÔÚ½Ó¼ûBanco de Brasil£¨www.bb.com.br£©ºÍItau Unibanco£¨www.itau.com.br£©Ê±½«±»³Á¶¨ÏòÖÁ¶ñÒâµÄipµØÖ· ¡£×êÑÐÈËԱǿµ÷³Æ£¬ÕâÖÖ½Ù³Ö²»±ØÒªÈκεÄÓû§½»»¥ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://security.radware.com/ddos-threats-attacks/threat-advisories-attack-reports/dns-hijacking-brazil-banks/


2¡¢×êÑÐÈËÔ±³ÆGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


UpGuard×êÑÐÍŶӷ¢ÏÖGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶£¬Ð¹Â¶Éæ¼°µÄÎļþËÆºõÊÇGoDaddyÔÚAWSÔÆÉÏÔËÐеĻù´¡ÉèÊ© ¡£Ð¹Â¶µÄÎļþÔ̺¬Ô¼3.1Íò¸öϵͳµÄ¸ù»ùÅäÏàÐÅÏ¢£¬ÈçÖ÷»úÃû¡¢²Ù×÷ϵͳ¡¢¹¤×÷¸ºÔØ¡¢AWSÇøÓò¡¢ÄÚ´æºÍCPU¹æ¸ñµÈ£¬ÉõÖÁ»¹Ô̺¬AWSÔÚ·ÖÆçÇé¿öÏ´ÍÓëµÄÕÛ¿ÛÐÅÏ¢µÈ ¡£ÏÖʵÉÏ£¬ÕâЩÊý¾ÝÖ±½Óй¶ÁËÒ»¸ö¹æÄ£¼«¶È´óµÄAWSÔÆ»ù´¡ÉèÊ©²¿Êð»·¾³ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75271/data-breach/godaddy-aws-data-leak.html


3¡¢×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÀ¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨ ¡£±¾¼¾¶ÈÀ¬»øÓʼþ¾ùÔÈռȫÇòÓʼþ×ÜÁ¿µÄ49.66%£¬ÓëÉÏÒ»¼¾¶ÈÏà±È½µÂäÁË2.16¸ö°Ù·Öµã ¡£·´´¹µöϵͳԮÊÖÓû§×èÖ¹Á˳¬¹ý1.07ÒڴζԴ¹µöÍøÕ¾µÄÏνÓ£¬±È2018ÄêµÚÒ»¼¾¶ÈÔö³¤ÁË1700Íò ¡£±¾¼¾¶ÈµÄÀ¬»øÓʼþÖ÷ÌâÖØÒªÓëGDPR¡¢ÊÀ½ç±­ºÍ¼ÓÃÜÇ®±ÒÓйØ£¬·¸×ï·Ö×Ó»¹Í¨¹ýÉç½»ÍøÂç¡¢ÐÂÎÅÀûÓúÍÓªÏú¶ÌÐÅÀ´·Ö·¢´¹µöÍøÕ¾µÄÁ´½Ó ¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/


4¡¢Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬ÈýÌìÄÚËðʧ³¬¹ý1350ÍòÃÀÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÏÖÜĩӡ¶ÈÒøÐÐCosmos BankÔâµ½ºÚ¿ÍµÄÈëÇÖ£¬¹¥»÷ÕßÔÚÈýÌìÄÚÇÔÈ¡Á˳¬¹ý9.4ÒÚ¬±È£¨Ô¼1350ÍòÃÀÔª£©µÄ×ʽð ¡£¾Ý±¾µØÃ½Ì屨·£¬Ç°Á½´Î͵ÇÔ²úÉúÔÚ8ÔÂ11ÈÕÐÇÆÚÁù£¬¹¥»÷Õßͨ¹ý28¸ö¹ú¶ÈµÄ14849±ÊATMÂòÂôÇÔÈ¡ÁËÔ¼1140ÍòÃÀÔª ¡£ËæºóÔÚ8ÔÂ13ÈÕÐÇÆÚÒ»£¬¹¥»÷ÕßÔÙ´Îͨ¹ýSWIFTϵͳÇÔÈ¡ÁËÔ¼200ÍòÃÀÔª ¡£Ä¿Ç°µÄÖ¤¾ÝÅú×¢¹¥»÷À´×Ô¼ÓÄô󣬸ÃÒøÐаµÊ¾Õâ´Î¹¥»÷µÄ¼¼Êõϸ½ÚÈÔÔÚ½øÒ»´ëÊ©²éÖ®ÖÐ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-steal-135-million-across-three-days-from-indian-bank/


5¡¢×êÑÐÈËÔ±·¢ÏÖÖØÒªÇÔÈ¡Office 365Í´´¦µÄPhishPoint¹¥»÷»î¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÆ°²È«¹«Ë¾AvananµÄ×êÑÐÈËÔ±·¢ÏÖÖØÒªÓÃÓÚÇÔÈ¡Office 365Óû§Í´´¦µÄPhishPoint¹¥»÷»î¶¯ ¡£PhishPointÊÇÒ»ÖÖеÄÀûÓÃSharePointµÄÍøÂç´¹µö¹¥»÷£¬ÆäÔÚ´ÓǰÁ½ÖÜÄÚԼĪӰÏìÁË10%µÄOffice 365Óû§ ¡£¹¥»÷ÕßÔÚ´¹µöÓʼþÖÐÔ̺¬Ò»¸öSharePointÎĵµµÄÁ´½Ó£¬¶ø¸ÃSharePointÎĵµÉϵĽӼûÎĵµ°´Å¥ÏÖʵÉÏÊǽ«Óû§³Á¶¨ÏòÖÁ´¹µöÍøÒ³µÄ³¬Á´½Ó ¡£ÕâÖÖ¹¥»÷Äܹ»ÈƹýOffice 365µÄ¸ß¼¶Íþв·À»¤£¨ATP£©»úÔì ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/microsoft-office365-phishing.html