ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ19ÖÜ

°ä²¼¹¦·ò 2018-05-14

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ07ÈÕÖÁ13ÈÕÊÕ¼°²È«·ì϶58¸ö£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Edge¾ç±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æ·ÛËé·ì϶£»£»£» £»£»Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£» £»£»Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£» £»£»Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£» £»£»Lantech IDS CVE-2018-8865ËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÅ·ÖÞÖÐÑëÒøÐа䲼TIBER-EU¿ò¼Ü£¬£¬ £¬£¬£¬£¬Ö¼ÔÚÔ®ÊÖ²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦£»£»£» £»£»Android P½«¶ÔÀûÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞ¶È£»£»£» £»£»×êÑÐÈËÔ±·¢ÏÖpythonÄ £¿£¿£¿ £¿£¿£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬£¬ £¬£¬£¬£¬¿ÉÍøÂçÓû§SSHÍ´´¦£»£»£» £»£»ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬£¬ £¬£¬£¬£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ï죻£»£» £»£»×êÑÐÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÐÂÎſɱ»¸´Ô­¡£¡£¡£¡£¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Microsoft Edge¾ç±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æ·ÛËé·ì϶

        Microsoft Edge´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄWEBÒ³£¬£¬ £¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8128
2¡¢Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´Ðзì϶

        Microsoft Exchange Server Outlook Web Access (OWA)´¦ÖÃWEBÒªÇó´æÔÚ°²È«·ì϶£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8152
3¡¢Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶

        Adobe Flash Player´¦ÖöñÒâÎļþ´æÔÚÀàÐÍ»ìºÏ·ì϶£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄSWFÎļþ£¬£¬ £¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-16.html
4¡¢Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´Ðзì϶

        Microsoft Office´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨ÌØÊâµÄÎļþ£¬£¬ £¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8158
5¡¢Lantech IDS CVE-2018-8865ËÁÒâ´úÂëÖ´Ðзì϶

        Lantech IDS´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.lantechcom.tw/global/eng/IDS-2102A.html


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Å·ÖÞÖÐÑëÒøÐа䲼TIBER-EU¿ò¼Ü£¬£¬ £¬£¬£¬£¬Ö¼ÔÚÔ®ÊÖ²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        Å·ÖÞÖÐÑëÒøÐУ¨ECB£©°ä²¼»ùÓÚÍþвµý±¨µÄTIBER-EU¿ò¼Ü£¬£¬ £¬£¬£¬£¬¸Ã¿ò¼ÜÊÇÊ׸öÁìÓòΪŷÖÞµÄÕë¶Ô½ðÈÚÊг¡µÄÊܿغͶ¨ÔìÍøÂç¹¥»÷µÄ²âÊÔ¿ò¼Ü¡£¡£¡£¡£¡£ÕâÒ»Ðж¯ÊǶԴÓǰ¼¸ÄêÄÚÕë¶Ô½ðÈÚÐÐÒµµÄ¶àÆðÍøÂç¹¥»÷µÄ»ØÓ¦¡£¡£¡£¡£¡£¸Ã¿ò¼ÜÔ̺¬Ò»¸öÄ£ÄâÕæÕýºÚ¿ÍµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½µÄºì·½ÍŶÓ£¬£¬ £¬£¬£¬£¬À´²Î¼Ó½ðÈÚÐÐÒµÖеĹ«Ë¾ÏµÍ³µÄ·ì϶ÆÀ¹ÀºÍÉøÈë²âÊÔ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72176/hacking/european-central-bank-framework-cyber.html

2¡¢Android P½«¶ÔÀûÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞ¶È

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ƾ¾ÝAndroid¿ªÔ´ÏîÄ¿£¨AOSP£©ÖеÄ×îдúÂë¸ü¸Ä£¬£¬ £¬£¬£¬£¬XDA¿ª·¢ÈËÔ±·¢´Ë¿ÌÏÂÒ»´úAndroidϵͳAndroid PÖУ¬£¬ £¬£¬£¬£¬ÈκÎÀûÓö¼½«²»Äܼì²âÉ豸ÉÏµÄÆäËüÀûÓÃÊÇ·ñÔÚÏνӻ¥ÁªÍø¡£¡£¡£¡£¡£XDA¿ª·¢ÈËÔ±Ö¸³ö£¬£¬ £¬£¬£¬£¬AndroidÒýÈëµÄÕâÒ»ÐÂ±ä¶¯ËÆºõºÜÓ×£¬£¬ £¬£¬£¬£¬µ«¶ÔÓû§ÒþÖÔµÄÓ°Ï콫ÊǾ޴óµÄ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/android-p-network-activity.html

3¡¢×êÑÐÈËÔ±·¢ÏÖpythonÄ £¿£¿£¿ £¿£¿£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬£¬ £¬£¬£¬£¬¿ÉÍøÂçÓû§SSHÍ´´¦

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        PythonÄ £¿£¿£¿ £¿£¿£¿éSSH Decorator£¨ssh-decorate£©ÊÇÓÉÒÔÉ«Áпª·¢ÈËÔ±Uri Goren¿ª·¢µÄÒ»¸öÓÃÓÚ´¦ÖÃsshÏνӵĿ⡣¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖssh-decorateµÄ¶à¸ö°æ±¾ÖÐÔ̺¬ÍøÂçÓû§sshÍ´´¦µÄ´úÂ룬£¬ £¬£¬£¬£¬×îºóÒ»¸ö°²È«µÄ°æ±¾Îª0.27£¬£¬ £¬£¬£¬£¬Ö®ºóµÄ0.28µ½0.31¶¼Ô̺¬¶ñÒâ´úÂë¡£¡£¡£¡£¡£Goren³ÆºóÃÅÊDZ»ºÚ¿ÍÖ²ÈëµÄ£¬£¬ £¬£¬£¬£¬Ä¿Ç°GorenÒÑÔÚgithubºÍPyPIÉÑþ³ØýÁ˸ÿ⡣¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/

4¡¢ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬£¬ £¬£¬£¬£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ïì

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ¸ç±¾¹þ¸ùÊеijÇÊй«ÓÃ×ÔÐгµÏµÍ³BycyklenÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬Õû¸öÊý¾Ý¿â±»É¾³ý£¬£¬ £¬£¬£¬£¬µ¼ÖÂËùÓеÄÔ¼1860Á©¹«ÓÃ×ÔÐгµÎÞ·¨½âËø¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ5ÔÂ4ÖçÒ¹Íí¡£¡£¡£¡£¡£Bycyklen³Æ½â¾ö¸ÃÎÊÌâ±ØÒª¶ÔËùÓеÄ×ÔÐгµ½øÐÐÊÖ¶¯¸üУ¬£¬ £¬£¬£¬£¬ÆäÔ±¹¤ÔÚÉÏÖÜÁùÒѸ´Ô­ÁË200Á¾×ÔÐгµ¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-shuts-down-copenhagen-s-public-city-bikes-system/

5¡¢×êÑÐÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÐÂÎſɱ»¸´Ô­

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        °²È«×êÑÐÈËÔ±Alec Muffett·¢ÏÖmacOSÖж˵½¶Ë¼ÓÃÜͨѶAPP SignalµÄÒÑɾ³ýÐÂÎſɱ»¸´Ô­£¬£¬ £¬£¬£¬£¬ÕâʹµÃÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£ÆäÔ­ÒòÊÇmacOS»áÔÚ֪ͨÖÐÐĵÄÊý¾Ý¿âÖб¸·ÝÐÂÎÅÄÚÈÝ£¨Í¨³£ÎªÆëÈ«ÐÂÎŵÄǰ1-1.5ÐУ©£¬£¬ £¬£¬£¬£¬ÓÃÓÚÏòÓû§ÏÔʾÐÂÎÅ֪ͨ¡£¡£¡£¡£¡£¼´±ãÔÚSignalÖÐɾ³ýÁ˸ÃÐÂÎÅ£¬£¬ £¬£¬£¬£¬ÕâЩ±»½ØÈ¡µÄÐÅÏ¢ÈÔÄܹ»Í¨¹ý¸ÃÊý¾Ý¿â½øÐнӼû¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/signal-secure-messaging.html