ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ14ÖÜ
°ä²¼¹¦·ò 2018-04-09
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê04ÔÂ02ÈÕÖÁ06ÈÕ¹²ÊÕ¼°²È«·ì϶68¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»£»£»£»£»£»Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶£»£»£»£»£»£»Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ£»£»£»£»£»£»Panera BreadÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ï죻£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ£»£»£»£»£»£»·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶£»£»£»£»£»£»×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Apple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶
Apple MacOS "CoreTypes"×é¼þ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶ÈÖ´ÐÐδÊÚȨ²Ù×÷¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208692
2¡¢Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶
Apple Safari WEBKIT×é¼þ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208695
3¡¢Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶
Cisco IOS XE SoftwareµÄCLI½âÎöÆ÷ÔÚʵÏÖÉÏ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬±¾µØµØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ÒÔrootȨÏÞÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-cmdinj
4¡¢Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶
Schneider Electric Modicon PLC FTP·þÎñÆ÷δÏ޶ȺÅÁî²ÎÊý³¤¶È£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬½øÐлؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/
5¡¢D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶
D-Link DSL-3782 'set Diagnostics_Entry'´¦ÖÃÊäÈëÖµ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/SECFORCE/CVE-2018-8941
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ

Hudson's Bay CompanyÔÚÖÜÈÕÈ·Èϳƣ¬£¬£¬£¬£¬£¬£¬Æä±±ÃÀµØÓòµÄ×Ó¹«Ë¾Saks Fifth Avenue¡¢Saks Off 5THÒÔ¼°Lord£¦TaylorµÄ²¿ÃÅÓû§µÄÐÅÓþ¿¨ÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁË´Ó2017Äê5Ôµ½2018Äê3ÔÂÔÚ±±ÃÀÉÌµê½øÐйýÖ§¸¶µÄÔ¼500ÍòÕÅÐÅÓþ¿¨¡£¡£¡£¡£¡£¡£Ä¿Ç°ÐÅÓþ¿¨ÐÅÏ¢ÊÇΨһй¶µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Saks Fifth AvenueÔÚÉêÃ÷ÖаµÊ¾£¬£¬£¬£¬£¬£¬£¬Ã»Óм£ÏóÅú×¢Éç»á±£ÏÕºÅÂë»òÉç»á±£ÏÕºÅÂë¡¢¼ÝÕÕºÅÂë»òÃÜÂëÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£°²È«³§ÉÌGemini Advisory³Æ¸ÃÊÂÎñÓëºÚ¿ÍÍÅ»ïJokerStash£¨Ò²±»³ÆÎªFIN7£©Óйء£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/credit-card-data-swiped-from-5m-saks-lord-taylor-customers/130877/
2¡¢Panera BreadÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì

°²È«×êÑÐÔ±Brian Krebs»ã±¨³ÆÃæ°üÁ¬ËøµêPanera BreadµÄÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍòÓû§µÄ¼Í¼£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢ÉúÈÕºÍÐÅÓþ¿¨ºÅÂëµÄ×îºóËÄλÊý×Ö¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÖ±µ½ÖÜÒ»»¹Äܹ»ÔÚPanerabread.comÉÏÒÔ´¿Îı¾µÄ´ó¾Ö½Ó¼û¡£¡£¡£¡£¡£¡£°²È«×êÑÐÔ±Dylan Houlihan×î³õÓÚ2017Äê8ÔÂÏòPanera»ã±¨Á˸Ãй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾²¢Ã»ÓвÉÈ¡Ðж¯À´½â¾öÎÊÌâ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2018/04/panerabread-com-breach-could-have-impacted-millions/
3¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ

Flashpoint×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ1000¸öMagentoÖÎÀíÃæ°å±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý±©Á¦¹¥»÷»ñµÃ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓþ¿¨ºÅÂëºÍ×°ÖöñÒâÈí¼þ£¨Êý¾ÝÇÔÈ¡Èí¼þAZORultºÍ¶ñÒâ¿ó¹¤Rarog£©¡£¡£¡£¡£¡£¡£Flashpoint³Æ´óÎÞÊýÍøÕ¾ÊôÓÚ½ÌÓýºÍÒ½ÁƱ£½¡ÐÐÒµ£¬£¬£¬£¬£¬£¬£¬IPµØÖ·ÖØÒªÉ¢²¼ÔÚÃÀ¹úºÍÅ·ÖÞ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.flashpoint-intel.com/blog/compromised-magento-sites-delivering-malware/
4¡¢·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶

¾Ý±¾µØÃ½Ì屨·£¬£¬£¬£¬£¬£¬£¬·ÒÀ¼Ê·ÉϵÚÈý´óÊý¾Ýй¶ÊÂÎñµ¼Ö³¬¹ý13ÍòÃû·ÒÀ¼¹«ÃñµÄÍ´´¦Ð¹Â¶¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÈëÇÖÁËHelsingin Uusyrityskeskus¹«Ë¾µÄÍøÕ¾£¨http://liiketoimintasuunnitelma.com£©£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Á˳¬¹ý13ÍòÓû§µÄÃ÷ÎĵǼÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£ÕâЩÓû§ÃûºÍÃÜÂëÒÔ´¿Îı¾µÄ´ó¾Ö´æ´¢ÔÚ¸ÃÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬²¢Ã»ÓÐʹÓÃÈκιþÏ£¼ÓÃÜ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/04/helsingin-uusyrityskeskus-hack.html
5¡¢×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶

˼¿ÆTalos×êÑÐÍŶÓÔÚNatus NeuroWorksÈí¼þÖз¢ÏÖ¶à¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬NatusµÄÒ½ÁƲúÆ·Xltek EEGÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£·ì϶ÁìÓòÔ̺¬4¸öµ¼Ö´úÂëÖ´Ðеķì϶ºÍ1¸öµ¼Ö»ؾø·þÎñµÄ·ì϶¡£¡£¡£¡£¡£¡£NatusÔÚNeuroworks 8.5 GMA2Öн¨¸´ÁËÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬½¨ÒéʹÓÃÕâЩÉ豸µÄÒ½ÁÆ»ú¹¹¾¡¿ì½øÐиüС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttp://blog.talosintelligence.com/2018/04/vulnerability-spotlight-natus.html


¾©¹«Íø°²±¸11010802024551ºÅ