ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ33ÖÜ
°ä²¼¹¦·ò 2018-08-20Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê08ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶79¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Digital Network Architecture Center CVE-2018-0427ºÅÁî×¢Èë·ì϶£»£»£»£»£»£»£»£»Microsoft Exchange CVE-2018-8302ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Microsoft Excel CVE-2018-8375Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Microsoft ChakraCore¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»WordPress CVE-2018-14028ËÁÒâÎļþÉÏ´«·ì϶¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖÕë¶Ô°ÍÎ÷ÒøÐеÄDNS½Ù³Ö¹¥»÷»î¶¯£»£»£»£»£»£»£»£»×êÑÐÈËÔ±³ÆGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶£»£»£»£»£»£»£»£»×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨£»£»£»£»£»£»£»£»Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬ÈýÌìÄÚËðʧ³¬¹ý1350ÍòÃÀÔª£»£»£»£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖÖØÒªÇÔÈ¡Office 365Í´´¦µÄPhishPoint¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
Cisco Digital Network Architecture Center CronJob scheduler API½Ó¿Ú´æÔÚºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ÌáÉýȨÏÞÒÔROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-dna-injection
2¡¢Microsoft Exchange CVE-2018-8302ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Microsoft Exchange Server´¦ÖÃÓʼþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8302
Microsoft Excel´¦ÖöñÒâxlsÎļþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8379
Microsoft ChakraCoreûÓÐÕýÈ·µÄ´¦ÖÃÄÚ´æÖеĶÔÏ󣬣¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8384
WordPressûÓмì²âͨ¹ýadminÇøÓòÉÏ´«µÄ²å¼þÊÇ·ñΪZIPÎļþ£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ÉÏ´«ËÁÒâPHPÎļþ²¢Ö´ÐС£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://core.trac.wordpress.org/ticket/44710
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
Radware×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÔÚÕë¶Ô°ÍÎ÷µÄDLink DSL·ÓÉÆ÷£¬£¬£¬£¬£¬£¬Í¨¹ýDNS½Ù³Ö¹¥»÷½«ÒøÐÐÓû§³Á¶¨ÏòÖÁ´¹µöÍøÕ¾²¢ÇÔÈ¡ÆäÒøÐÐÕË»§µÄµÇ¼ʹ´¦¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÅú¸ÄÁËÕâЩ·ÓÉÆ÷É豸ÖеÄDNSÉèÖ㬣¬£¬£¬£¬£¬½«ÆäÖ¸Ïò¶ñÒâµÄDNS·þÎñÆ÷£¨69.162.89.185ºÍ198.50.222.136£©£¬£¬£¬£¬£¬£¬ÕâЩÉ豸ÔÚ½Ó¼ûBanco de Brasil£¨www.bb.com.br£©ºÍItau Unibanco£¨www.itau.com.br£©Ê±½«±»³Á¶¨ÏòÖÁ¶ñÒâµÄipµØÖ·¡£¡£¡£¡£¡£¡£×êÑÐÈËԱǿµ÷³Æ£¬£¬£¬£¬£¬£¬ÕâÖÖ½Ù³Ö²»±ØÒªÈκεÄÓû§½»»¥¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://security.radware.com/ddos-threats-attacks/threat-advisories-attack-reports/dns-hijacking-brazil-banks/
2¡¢×êÑÐÈËÔ±³ÆGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶
UpGuard×êÑÐÍŶӷ¢ÏÖGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶£¬£¬£¬£¬£¬£¬Ð¹Â¶Éæ¼°µÄÎļþËÆºõÊÇGoDaddyÔÚAWSÔÆÉÏÔËÐеĻù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÎļþÔ̺¬Ô¼3.1Íò¸öϵͳµÄ¸ù»ùÅäÏàÐÅÏ¢£¬£¬£¬£¬£¬£¬ÈçÖ÷»úÃû¡¢²Ù×÷ϵͳ¡¢¹¤×÷¸ºÔØ¡¢AWSÇøÓò¡¢ÄÚ´æºÍCPU¹æ¸ñµÈ£¬£¬£¬£¬£¬£¬ÉõÖÁ»¹Ô̺¬AWSÔÚ·ÖÆçÇé¿öÏ´ÍÓëµÄÕÛ¿ÛÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÏÖʵÉÏ£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÖ±½Óй¶ÁËÒ»¸ö¹æÄ£¼«¶È´óµÄAWSÔÆ»ù´¡ÉèÊ©²¿Êð»·¾³¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75271/data-breach/godaddy-aws-data-leak.html
3¡¢×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨
ÔÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/
4¡¢Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬ÈýÌìÄÚËðʧ³¬¹ý1350ÍòÃÀÔª
ÉÏÖÜĩӡ¶ÈÒøÐÐCosmos BankÔâµ½ºÚ¿ÍµÄÈëÇÖ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈýÌìÄÚÇÔÈ¡Á˳¬¹ý9.4ÒÚ¬±È£¨Ô¼1350ÍòÃÀÔª£©µÄ×ʽ𡣡£¡£¡£¡£¡£¾Ý±¾µØÃ½Ì屨·£¬£¬£¬£¬£¬£¬Ç°Á½´Î͵ÇÔ²úÉúÔÚ8ÔÂ11ÈÕÐÇÆÚÁù£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý28¸ö¹ú¶ÈµÄ14849±ÊATMÂòÂôÇÔÈ¡ÁËÔ¼1140ÍòÃÀÔª¡£¡£¡£¡£¡£¡£ËæºóÔÚ8ÔÂ13ÈÕÐÇÆÚÒ»£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÙ´Îͨ¹ýSWIFTϵͳÇÔÈ¡ÁËÔ¼200ÍòÃÀÔª¡£¡£¡£¡£¡£¡£Ä¿Ç°µÄÖ¤¾ÝÅú×¢¹¥»÷À´×Ô¼ÓÄô󣬣¬£¬£¬£¬£¬¸ÃÒøÐаµÊ¾Õâ´Î¹¥»÷µÄ¼¼Êõϸ½ÚÈÔÔÚ½øÒ»´ëÊ©²éÖ®ÖС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-steal-135-million-across-three-days-from-indian-bank/
5¡¢×êÑÐÈËÔ±·¢ÏÖÖØÒªÇÔÈ¡Office 365Í´´¦µÄPhishPoint¹¥»÷»î¶¯
ÔÆ°²È«¹«Ë¾AvananµÄ×êÑÐÈËÔ±·¢ÏÖÖØÒªÓÃÓÚÇÔÈ¡Office 365Óû§Í´´¦µÄPhishPoint¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£PhishPointÊÇÒ»ÖÖеÄÀûÓÃSharePointµÄÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬ÆäÔÚ´ÓǰÁ½ÖÜÄÚԼĪӰÏìÁË10%µÄOffice 365Óû§¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ´¹µöÓʼþÖÐÔ̺¬Ò»¸öSharePointÎĵµµÄÁ´½Ó£¬£¬£¬£¬£¬£¬¶ø¸ÃSharePointÎĵµÉϵĽӼûÎĵµ°´Å¥ÏÖʵÉÏÊǽ«Óû§³Á¶¨ÏòÖÁ´¹µöÍøÒ³µÄ³¬Á´½Ó¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷Äܹ»ÈƹýOffice 365µÄ¸ß¼¶Íþв·À»¤£¨ATP£©»úÔì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/microsoft-office365-phishing.html


¾©¹«Íø°²±¸11010802024551ºÅ