ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ15ÖÜ

°ä²¼¹¦·ò 2018-04-16

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ09ÈÕÖÁ13ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Graphics×é¼þȨÏÞÌáÉý·ì϶£»£» £»£»£»Microsoft Chakra¾ç±¾ÒýÇæCVE-2018-0980ÄÚ´æ·ÛËé·ì϶£»£» £»£»£»Microsoft Excel CVE-2018-1026Ô¶³Ì´úÂëÖ´Ðзì϶£»£» £»£»£»Microsoft WindowsǶÈëʽ×ÖÌåÔ¶³Ì´úÂëÖ´Ðзì϶£»£» £»£»£»Microsoft Windows 'HTTP.sys'»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ˼¿Æ·ì϶£¨CVE-2018-0171£©±»ºÚ¿ÍÀûÓ㬣¬£¬£¬£¬£¬È«Çò³¬¹ý20Íǫ̀·ÓÉÆ÷ÖÐÕУ»£» £»£»£»×êÑÐÈËÔ±·¢ÏÖÓÃÓÚ·Ö·¢¶ñÒâÈí¼þIcedIDºÍRovnixµÄ´¹µö¹¥»÷»î¶¯£»£» £»£»£»Sodexo FilmologyÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÐÅÓþ¿¨ÐÅϢй¶£»£» £»£»£»Ê¥Âí¶¡µºµÄ»ù´¡ÉèÊ©Ôâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬¹«¹²·þÎñ±»ÆÈÖжÏ£»£» £»£»£»×êÑÐÍŶӳƳ¬¹ý6.5Íò¸ö·ÓÉÆ÷Ϊ½©Ê¬ÍøÂçºÍAPTÌṩ¶ñÒâÁ÷Á¿¡£¡£¡£¡£¡£¡£¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Microsoft Windows Graphics×é¼þȨÏÞÌáÉý·ì϶

        Microsoft Graphics×é¼þ×ֶνâÎö´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1008
2¡¢Microsoft Chakra¾ç±¾ÒýÇæCVE-2018-0980ÄÚ´æ·ÛËé·ì϶

        Microsoft Edge´¦ÖÃWEBÒªÇó´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿Éʹ·¨Ê½±ÀÀ£»£» £»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0980
3¡¢Microsoft Excel CVE-2018-1026Ô¶³Ì´úÂëÖ´Ðзì϶

        Microsoft Excel´¦ÖÃÄÚ´æ¶ÔÏó·½Ê½ÖдæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1026
4¡¢Microsoft WindowsǶÈëʽ×ÖÌåÔ¶³Ì´úÂëÖ´Ðзì϶

        Microsoft Windows´¦ÖÃǶÈëʽ×ÖÌå´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1010
5¡¢Microsoft Windows 'HTTP.sys'»Ø¾ø·þÎñ·ì϶

        Microsoft Windows HTTP.sys´¦ÖÃHTTP 2.0ÒªÇó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0956


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Ë¼¿Æ·ì϶£¨CVE-2018-0171£©±»ºÚ¿ÍÀûÓ㬣¬£¬£¬£¬£¬È«Çò³¬¹ý20Íǫ̀·ÓÉÆ÷ÖÐÕÐ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ºÚ¿ÍÍÅ»ïJHTÀûÓÃ˼¿Æ·ì϶£¨CVE-2018-0171£©ÌáÒéÁËÕë¶Ô¶íÂÞ˹ºÍÒÁÀʵÄÍøÂç»ù´¡ÉèÊ©µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¾Ý·͸É籨·£¬£¬£¬£¬£¬£¬ÒÁÀÊͨѶºÍÐÅÏ¢¼¼Êõ²¿°µÊ¾È«Çò³¬¹ý20Íǫ̀·ÓÉÆ÷Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÒÁÀʵÄ3500̨·ÓÉÆ÷¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°ÊÜÓ°ÏìµÄÒÁÀÊ·ÓÉÆ÷ÖÐ95%ÒѸ´Ô­Õý³£·þÎñ¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/iranian-and-russian-networks-attacked-using-ciscos-cve-2018-0171-vulnerability/

2¡¢×êÑÐÈËÔ±·¢ÏÖÓÃÓÚ·Ö·¢¶ñÒâÈí¼þIcedIDºÍRovnixµÄ´¹µö¹¥»÷»î¶¯

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ÔÚ2018Äê2ÔÂÏÂÑ®¼°Õû¸ö3ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬Ë¼¿Æ×êÑÐÈËÔ±·¢ÏÖÒ»¸ö´¹µöÓʼþ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬µ±Óû§´ò¿ªÔ̺¬¶ñÒâºêµÄMicrosoft WordÎĵµ¸½¼þʱ£¬£¬£¬£¬£¬£¬½«»áÏÂÔØ¶ñÒâÈí¼þRovnix£¬£¬£¬£¬£¬£¬²¢ËæºóÏÂÔØÒøÐÐľÂíIcedID¡£¡£¡£¡£¡£¡£¡£Áí±í£¬£¬£¬£¬£¬£¬»¹ÓÐһЩÑù±¾»áÏÂÔØÒ»¸öBytecoinµÄ¶ñÒâÍÚ¿óÈí¼þ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖIcedIDʹÓõļò»¯´úÂë×¢Èë¼¼Êõ±äµÃÔ½·¢ÄÑÒÔ¼ì²â¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blogs.cisco.com/security/icedid-banking-trojan-teams-up-with-rovnix-for-distribution

3¡¢Sodexo FilmologyÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÐÅÓþ¿¨ÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        SodexoʳƷ·þÎñºÍÉèÊ©ÖÎÀí¹«Ë¾°µÊ¾ÆäµçÓ°¾íƽ̨FilmologyÔâµ½ÓÐÕë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÐÅÓþ¿¨ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬ÔÚ¶½´ÙÔÚ3ÔÂ19ÈÕÖÁ4ÔÂ3ÈÕÆÚ¼äʹÓÃÁËFilmologyÍøÕ¾µÄÓû§²é³­ÆäÒøÐп¨Õ˵¥¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñĿǰ»¹ÔÚ½øÒ»²½µÄµ÷²éÖ®ÖÓ×£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/71211/data-breach/sodexo-filmology-data-breach.html

4¡¢Ê¥Âí¶¡µºµÄ»ù´¡ÉèÊ©Ôâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬¹«¹²·þÎñ±»ÆÈÖжÏ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ¾Ý±¾µØÃ½ÌåÖðÈÕÏÈÇý±¨±¨Â·£¬£¬£¬£¬£¬£¬4ÔÂ2ÈÕλÓÚ¼ÓÀձȺ£µÄºÉÀ¼ÊôÊ¥Âí¶¡µºÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Õû¸öµ±¾ÖµÄ»ù´¡ÉèÊ©±»ÆÈ¹Ø¹Ø£¬£¬£¬£¬£¬£¬µ¼Ö¹«¹²·þÎñÖжϡ£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ³ýÁËÃñʵǼDz¿Ãűí£¬£¬£¬£¬£¬£¬ÆäÓ൱²¿ÃÅÃÅÒѾ­¸´Ô­ÁË·þÎñ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Ã»ÓйØÓÚÕâ´Î¹¥»÷ÊÂÎñµÄ¸ü¶àϸ½Ú¡£¡£¡£¡£¡£¡£¡£µ±¾Ö°µÊ¾ÕâÊÇÒ»ÄêÀ´²úÉúµÄµÚ3Æð¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/71236/hacking/sint-maarten-cyber-attack.html

5¡¢×êÑÐÍŶӳƳ¬¹ý6.5Íò¸ö·ÓÉÆ÷Ϊ½©Ê¬ÍøÂçºÍAPTÌṩ¶ñÒâÁ÷Á¿

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        Akamai°ä²¼»ã±¨³Æ¼ì²âµ½¹¥»÷ÕßÀûÓó¬¹ý6.5Íò¸ö·ÓÉÆ÷´´½¨µÄ´úÀíÍøÂçÖ´ÐжàÖÖ·¸·¨¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£½©Ê¬ÍøÂçÔËÓªÕߺÍÍøÂç¼äµý×éÖ¯ (APT) ±»Ö¸ÔÚÀÄÓ÷ÓÉÆ÷ʹÓõÄͨÓü´²å¼´Óà (UPnP) ºÍ̸À´´úÀí¶ñÒâÁ÷Á¿²¢¶ã±Üµ÷²éÈËÔ±²é¿´ÕæÊµµØÀíλÏàÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£²¢¼ì²âµ½³¬¹ý480Íò¸ö·ÓÉÆ÷Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-65-000-home-routers-are-proxying-bad-traffic-for-botnets-apts/