ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ24ÖÜ
°ä²¼¹¦·ò 2018-06-18
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê06ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows 'HTTP.sys'Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»Microsoft Excel CVE-2018-8248Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»Microsoft Windows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»Microsoft Windows CVE-2018-8213ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Cisco Network Services Orchestrator CVE-2018-0274ËÁÒâºÅÁîÖ´Ðзì϶¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÖÇÀûÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Êý°ÙÌ¨ÍÆËã»úµÄMBR±»·ÛË飻£»£»£»£»£»º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª£»£»£»£»£»£»Weight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅ»ù´¡ÉèÊ©µÄÍ´´¦Ð¹Â¶£»£»£»£»£»£»AÕ¾ÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½üǧÍòÓû§µÄÊý¾Ýй¶£»£»£»£»£»£»ÁãÊÛ¹«Ë¾Dixons CarphoneÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼590ÍòÓû§µÄÐÅÓþ¿¨ÐÅϢй¶¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Microsoft Windows 'HTTP.sys'Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Windows 'HTTP.sys'´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8231
2¡¢Microsoft Excel CVE-2018-8248Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Excel´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂëÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8248
3¡¢Microsoft Windows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶
Microsoft Windows DNSAPI.dll´¦ÖÃDNSÏìÓ¦´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8225
4¡¢Microsoft Windows CVE-2018-8213ËÁÒâ´úÂëÖ´Ðзì϶
Microsoft Windows´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÏµÍ³¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8213
5¡¢Cisco Network Services Orchestrator CVE-2018-0274ËÁÒâºÅÁîÖ´Ðзì϶
Cisco Network Services Orchestrator CLI½âÎöÆ÷´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-nso
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçVPNFilter¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼

5ÔÂ24ÈÕÖÇÀûÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼͨ¹ýÒøÐеÄSWIFTתÕËϵͳÇÔÈ¡×ʽ𣬣¬£¬£¬£¬£¬£¬£¬²¢Í¬Ê±Í¨¹ý´ÅÅ̲Á³ý¶ñÒâÈí¼þ·ÛËéÁËÊý°Ų̀µçÄÔÒÔ·ÖÉ¢Ô±¹¤È·°ÑÎÈÁ¦¡£¡£¡£¡£¡£¡£Æ¾¾Ý±¾µØÃ½ÌåµÄ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬¹ÌÈ»ÔÚÏßϵͳ¹¤×÷Õý³££¬£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÒøÐеĶà¸öÍøµã·þÎñ±ÀÀ£¡£¡£¡£¡£¡£¡£¹ÌȻûÓÐÃ÷È·Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÒøÐÐϰȾµÄ¶ñÒâÈí¼þºÜ¿ÉÄÜÊÇKillDiskµÄбäÌ壬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåÖØÒª²Á³ýÍÆËã»úµÄMBR£¬£¬£¬£¬£¬£¬£¬£¬Ç÷Ïò¿Æ¼¼°ä²¼Á˹ØÓڸñäÌåµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-crashed-a-bank-s-computers-while-attempting-a-swift-hack/
2¡¢º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª

ÉÏÖÜÈÕº«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÈëÇÖÕßÇÔÈ¡ÁËPundi X£¨NPXS£©¡¢NPER£¨NPER£©ºÍAston£¨ATX£©µÄ²¿ÃÅICO´ú±Ò£¬£¬£¬£¬£¬£¬£¬£¬ÂòÂôËùûÓÐÅû¶Óйر»µÁ×ʽðµÄ¾ßÌåÊý×Ö£¬£¬£¬£¬£¬£¬£¬£¬µ«ÓÐЧ»§¸ú×ÙÁËÈëÇÖÕßµÄÕË»§µØÖ·£¬£¬£¬£¬£¬£¬£¬£¬ÒÔΪÓйر»µÁ×ʽð¼ÛÖµÔÚ3000Íòµ½4000ÍòÃÀÔªÖ®¼ä£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼Ò»°ëΪNPXS´ú±Ò¡£¡£¡£¡£¡£¡£Coinrail³ÆÕýÓëÊÜÓ°ÏìµÄICO¹«Ë¾ºÏ×÷ÒÔ¶³½á±»µÁµÄ´ú±Ò¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/south-korean-cryptocurrency-exchange-coinrail-gets-hacked/
3¡¢Weight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅ»ù´¡ÉèÊ©µÄÍ´´¦Ð¹Â¶

µÂ¹ú°²È«³§ÉÌKromtechµÄ×êÑÐÈËÔ±·¢ÏÖWeight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃÈκÎÈ˶¼Äܹ»Í¨¹ý¶Ë¿Ú10250½Ó¼û¸Ã·þÎñÆ÷¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ôڸ÷þÎñÆ÷ÉÏ·¢ÏÖÁËWeight Watchers¹«Ë¾µÄIT»ù´¡ÉèÊ©µÄÅäÏàÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÖÎÀíԱʹ´¦¡¢102¸öÓòµÄ½Ó¼ûÃÜÔ¿¡¢AWS½Ó¼ûÃÜÔ¿µÈ¡£¡£¡£¡£¡£¡£Weight Watchers³ÆÕâ²»ÊÇÒ»¸ö³ö²úÍøÂç¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/weight-watchers-it-infrastructure-exposed-via-no-password-kubernetes-server/
4¡¢AÕ¾ÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½üǧÍòÓû§µÄÊý¾Ýй¶

½ñÈÕÁ賿AcFun°ä²¼²¼¸æ³ÆÆäÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½üǧÍòÓû§µÄÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Óû§ID¡¢êdzơ¢¼ÓÃÜ´æ´¢µÄÃÜÂëµÈ¡£¡£¡£¡£¡£¡£ÔÚ2017Äê7ÔÂ7ÈÕ֮ǰµÇ¼¹ýAcFunµÄÓû§ÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬µ«Ò²½¨ÒéÃÜÂë¹ýÓÚµ¥Ò»µÄÆäËüÓû§Åú¸ÄÃÜÂë¡£¡£¡£¡£¡£¡£AcFun³ÆÒѾ½áºÏÄÚ²¿ºÍ±í²¿µÄ¼¼Êõר¼Ò¶ÔÎÊÌâ½øÐÐÅŲ飬£¬£¬£¬£¬£¬£¬£¬²¢Éý¼¶ÏµÍ³µÄ°²È«µÈ¼¶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttp://www.sohu.com/a/235455264_250147
5¡¢ÁãÊÛ¹«Ë¾Dixons CarphoneÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼590ÍòÓû§µÄÐÅÓþ¿¨ÐÅϢй¶

ÁãÊÛ¹«Ë¾Dixons CarphoneÅû¶һ¸öÉæ¼°Ô¼590ÍòÕÅÐÅÓþ¿¨ºÍ120ÍòÌõÓ×ÎÒÊý¾Ý¼Í¼µÄ°²È«ÊÂÎñ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆºÚ¿Í½Ó¼ûÁË´æ´¢ÔÚÆäCurrys PC WorldºÍDixons TravelÉ̵êµÄϵͳÖеÄÔ¼590ÍòÕÅÐÅÓþ¿¨Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ580ÍòÕÅÐÅÓþ¿¨ÓµÓÐоƬºÍPINÂë±£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζןڿͻñÈ¡µÄÊý¾Ý¼ÈûÓÐÔ̺¬PINÂë¡¢CVV£¬£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÔ̺¬ÈκÎÄܹ»½øÐгֿ¨È˼ø±ðºÍ²É°ìÐÐΪµÄÑéÖ¤Êý¾Ý¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÁªÏµÊÜÓ°ÏìµÄÓû§£¬£¬£¬£¬£¬£¬£¬£¬²¢ÏòËûÃÇ´ÍÓ뽨Òé¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73479/data-breach/dixons-carphone-hacked.html


¾©¹«Íø°²±¸11010802024551ºÅ