ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ23ÖÜ

°ä²¼¹¦·ò 2018-06-11

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê06ÔÂ04ÈÕÖÁ08ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAndroid NVIDIA TLK TrustZone±¾µØÈ¨ÏÞÌáÉý·ì϶£»£»£»£»£»£»Cisco Prime Collaboration ProvisioningÃÜÂë³ÁÖ÷ì϶£»£»£»£»£»£»Apple iOS WebKit CVE-2018-4204ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»£»£»£»£»£»ISC BIND CVE-2018-5737Ô¶³Ì»Ø¾ø·þÎñ·ì϶£»£»£»£»£»£»Adobe AcrobatºÍReader¿ªÊͺóÀûÓÃËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçVPNFilter¾íÍÁ³ÁÀ´£¬£¬ £¬£¬£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼£»£»£»£»£»£»Êýǧ¸ö¹«Ë¾ÒòGoogle GroupsÅäÖÃÃýÎó¶øÐ¹Â¼ûô¸ÐÊý¾Ý£»£»£»£»£»£»Ó¢¹úTSBÒøÐз¢Ë͸øÓû§µÄÓʼþÖÐй¶Óû§µÄÃô¸ÐÐÅÏ¢£»£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖ³¬¹ý11.5Íò¸öDrupalÍøÕ¾ÒÀÈ»Ò×ÊÜDrupalgeddon2¹¥»÷£»£»£»£»£»£»ÒÔÉ«ÁÐDNA¼ì²â¹«Ë¾MyHeritageÔâºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬³¬¹ý9200ÍòÓû§ÐÅϢй¶¡£¡£¡£¡£¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Android NVIDIA TLK TrustZone±¾µØÈ¨ÏÞÌáÉý·ì϶

        Android NVIDIA TLK TrustZone´æÔÚ°²È«·ì϶£¬£¬ £¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://source.android.com/security/bulletin/2018-06-01
2¡¢Cisco Prime Collaboration ProvisioningÃÜÂë³ÁÖ÷ì϶

        Cisco Prime Collaboration ProvisioningÃÜÂë³ÁÖÃÖ°ÄÜ´æÔÚ°²È«·ì϶£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬³ÁÖÃÖÎÀíÔ±ÃÜÂ룬£¬ £¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-password-reset
3¡¢Apple iOS WebKit CVE-2018-4204ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶

        Apple iOS WebKit´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬ £¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬ £¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://lists.apple.com/archives/security-announce/2018/Apr/msg00000.html
4¡¢ISC BIND CVE-2018-5737Ô¶³Ì»Ø¾ø·þÎñ·ì϶

        ISC BIND rbtdb.c´æÔÚ¶ÏÑÔʧ°Ü·ì϶£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬Ê¹ÏµÍ³±ÀÀ£¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://kb.isc.org/article/AA-01606/0/CVE-2018-5737%3A-BIND-9.12s-serve-stale-implementation-can-cause-an-assertion-failure-in-rbtdb.c-or-other-undesirable-behavior-even-if-serve-stale-is-not-enabled.
5¡¢Adobe AcrobatºÍReader¿ªÊͺóÀûÓÃËÁÒâ´úÂëÖ´Ðзì϶

        Adobe AcrobatºÍReader´¦ÖÃPDFÎļþ´æÔÚ¿ªÊͺóÀûÓ÷ì϶£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬ £¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬ £¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-09.html


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçVPNFilter¾íÍÁ³ÁÀ´£¬£¬ £¬£¬£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        À´×ÔJASKºÍGreyNoise IntelligenceµÄ°²È«×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçVPNFilterÕý¾íÍÁ³ÁÀ´¡£¡£¡£¡£¡£VPNFilterÔÚÉÏÖܱ»FBI·ÛË飬£¬ £¬£¬£¬µ«×êÑÐÈËÔ±·¢Ïָý©Ê¬ÍøÂçÕýÊÔͼϰȾеķÓÉÆ÷¡£¡£¡£¡£¡£ÕâÖÖϰȾ»î¶¯Ö»Õë¶ÔÎÚ¿ËÀ¼£¬£¬ £¬£¬£¬°²È«×êÑÐÈËÔ±ÒÔΪVPNFilter±³ºóµÄ×éÖ¯ÊǶíÂÞË¹ÍøÂç¼äµý×éÖ¯APT28¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/the-vpnfilter-botnet-is-attempting-a-comeback/

2¡¢Êýǧ¸ö¹«Ë¾ÒòGoogle GroupsÅäÖÃÃýÎó¶øÐ¹Â¼ûô¸ÐÊý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        Kenna SecurityµÄ°²È«×êÑÐÈËÔ±³ÆÊýÒÔǧ¼ÆµÄ¹«Ë¾ÒòGoogle GroupsµÄÃýÎóÅäÖõ¼ÖÂÃô¸ÐÊý¾Ýй¶£¬£¬ £¬£¬£¬ÔÚ9600¸ö·ÖÎö¶ÔÏóÖУ¬£¬ £¬£¬£¬ÓÐ31%µÄ¹«Ë¾µÄÃô¸Ðµç×ÓÓʼþÐÅϢй¶¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¶ÔÏóÔ̺¬²Æ¸»500Ç¿¹«Ë¾¡¢Ò½Ôº¡¢´óѧ¡¢±¨Ö½ºÍµçÊǪ́£¬£¬ £¬£¬£¬ÉõÖÁ»¹ÓÐÃÀ¹úµ±¾Ö»ú¹¹¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73176/security/google-groups-data-leak.html

3¡¢Ó¢¹úTSBÒøÐз¢Ë͸øÓû§µÄÓʼþÖÐй¶Óû§µÄÃô¸ÐÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        Ó¢¹úTSBÒøÐÐÔÚ·¢Ë͸øÓû§µÄÓʼþÖÐй¶ÁËÆäËûÓû§µÄÃô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬Õâ¿ÉÄÜÎ¥·´ÁËGDPR¡£¡£¡£¡£¡£ÕâЩÓʼþÕý±¾ÊÇΪÁËÚ¹ÊÍÆä×î½üµÄITÎÊÌ⣬£¬ £¬£¬£¬µ«ÓʼþÖÐÔ̺¬ÁËÆäËûÓû§µÄÓйغÅÂë¡¢ÐÕÃûºÍµØÖ·¡£¡£¡£¡£¡£TSB½²»°ÈËÈϿɸÃÃýÎóй¶ÁËÓû§µÄÒþÖÔ£¬£¬ £¬£¬£¬²¢³ÆÕýÓëµÚÈý·½¹©¸øÉ̺Ï×÷ÒÔÏàʶÎÊÌâ²úÉúµÄµ××ÓÔ­Òò¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/tsb-privacy-snafu-letters-sent/

4¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý11.5Íò¸öDrupalÍøÕ¾ÒÀÈ»Ò×ÊÜDrupalgeddon2¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        °²È«×êÑÐÔ±Troy MurschɨÃèÁËÔ¼50Íò¸öÔËÐÐÔÚDrupal 7ÉϵÄÍøÕ¾£¬£¬ £¬£¬£¬¹²·¢ÏÖ³¬¹ý11.5Íò¸öÍøÕ¾ÒÀÈ»Ò×ÊÜDrupalgeddon2¹¥»÷¡£¡£¡£¡£¡£ÆäÖбÈÀûʱ¾¯Ê𡢿ÆÂÞÀ­¶àÖÝ×ܼì²ì³¤°ì¹«ÊҺͷÆÑÇÌØ×Ó¹«Ë¾Magneti MarelliµÈÊý°Ù¸öÍøÕ¾ÒѾ­³ÉΪеĶñÒâÍÚ¿ó»î¶¯µÄÖ¸±ê¡£¡£¡£¡£¡£Drupalgeddon2£¨CVE-2018-7600£©ÊÇDrupal CMSÔÚ3ÔÂµ×ÆØ³öµÄ¸ßΣԶ³Ì´úÂëÖ´Ðзì϶£¬£¬ £¬£¬£¬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐжñÒâ´úÂëºÍÆëÈ«ÊÕÊÜÍøÕ¾¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/drupalgeddon2-exploit.html

5¡¢ÒÔÉ«ÁÐDNA¼ì²â¹«Ë¾MyHeritageÔâºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬³¬¹ý9200ÍòÓû§ÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ÒÔÉ«ÁÐDNA¼ì²â¹«Ë¾MyHeritage³Æ¸Ã¹«Ë¾ÓÚÈ¥ÄêÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬Ô¼9230ÍòÓû§µÄµç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂëй¶¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÓû§ÊÇ2017Äê10ÔÂ27ÈÕ֮ǰע²áMyHeritageÍøÕ¾µÄÓû§¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³öÓÉÓÚÓû§µÄÐÅÓþ¿¨¡¢×åÆ×ºÍ»ùÒòÊý¾ÝµÈÐÅÏ¢´æ´¢ÔÚµ¥¶ÀµÄϵͳÖУ¬£¬ £¬£¬£¬ÕâЩÊý¾ÝûÓÐй¶¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬Óû§µÄÃÜÂëʹÓüÓÑιþÏ£½øÐб£»£»£»£»£»£»¤£¬£¬ £¬£¬£¬Òò¶øÄÑÒÔ±»ÆÆ½â£¬£¬ £¬£¬£¬µ«¸Ã¹«Ë¾ÒÀÈ»½¨ÒéÓû§Åú¸ÄÃÜÂë¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹°µÊ¾½«ÎªÓû§Ôö³¤Ë«³É·ÖÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/myheritage-data-breach.html