ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ50ÖÜ
°ä²¼¹¦·ò 2018-12-17
2018Äê12ÔÂ10ÈÕ16ÈÕ¹²ÊÕ¼°²È«·ì϶82¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇThinkPHP 5.xÔ¶³ÌºÅÁîÖ´Ðзì϶£»£»£»£»£»Adobe Acrobat/Reader¶à¸öÕûÊýÒç¶Âí½Å£»£»£»£»£»Microsoft Outlook CVE-2018-8587Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»Microsoft Windows DNS¶ÑÒç¶Âí½Å£»£»£»£»£»Apache Commons FileUpload DiskFileItemÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ®Á¢ÐÅÈí¼þÖ¤Êé¹ýÆÚ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ11¸ö¹ú¶ÈÍ¨Ñ¶ÍøÂç̱»¾£»£»£»£»£»ÐÂAPI·ì϶µ¼ÖÂ5250ÍòÓû§ÒþÖÔ¶³ö£¬£¬£¬£¬£¬£¬£¬£¬Google+½«±»Ìáǰ¹Ø¹Ø£»£»£»£»£»ÃÀ¹ú¶àÒéÔº°ä²¼ÍøÂ簲ȫսÊõ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Ìá³öÁùÏîÁìµ¼×¼Ôò£»£»£»£»£»ÉñǹÊÖÐж¯£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃRising Sun¶Ô׼ȫÇò¹ú·À¼°¹Ø¼ü»ù´¡ÉèÊ©£»£»£»£»£»Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SaipemÔâµ½ºÚ¿ÍÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£
1. ThinkPHP 5.xÔ¶³ÌºÅÁîÖ´Ðзì϶
ThinkPHP¶Ô½ÚÔìÆ÷Ãû´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔWEBȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£
https://blog.thinkphp.cn/8690752. Adobe Acrobat/Reader¶à¸öÕûÊýÒç¶Âí½Å
Adobe Acrobat/Reader´æÔÚÕûÊýÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb18-41.html3. Microsoft Outlook CVE-2018-8587Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Outlook²»ÕýÈ·´¦ÖÃÄÚ´æ¶ÔÏó·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-85874. Microsoft Windows DNS¶ÑÒç¶Âí½Å
Microsoft DNS Server´æÔÚ»ùÓڶѵÄÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-86265. Apache Commons FileUpload DiskFileItemÔ¶³Ì´úÂëÖ´Ðзì϶
Apache Commons FileUploadʵÏÖ´æÔÚJava Object·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
http://www.zerodayinitiative.com/advisories/ZDI-16-570/
1¡¢°®Á¢ÐÅÈí¼þÖ¤Êé¹ýÆÚ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ11¸ö¹ú¶ÈÍ¨Ñ¶ÍøÂç̱»¾
12ÔÂ6ÈÕÈðµäͨѶ¾ÞÍ·°®Á¢ÐŵÄÉ豸³öÏÖÈí¼þ¹ÊÕÏ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊýÒÔ°ÙÍò¼ÆµÄÊÖ»úÓû§ÍøÂçͨѶ̱»¾£¬£¬£¬£¬£¬£¬£¬£¬¶à¸öʹÓð®Á¢ÐÅÉ豸µÄ¹ú¶ÈÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ó¢¹úÒÆ¶¯ÔËÓªÉÌO2µÄÓû§¡¢ÈÕ±¾ÈíÒøµÄÓû§µÈ¡£¡£¡£¡£¡£¡£¡£°®Á¢ÐÅÔÚÐÂΟåÖгÆÉ豸¹ÊÕÏÊÇÓÉÌØ¶¨°æ±¾µÄSGSN¨CMMEÈí¼þµ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬¾ßÌåÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬Æäµ××ÓÔÒòÊÇ×°ÖÃÔÚ¿Í»§É豸ÉϵÄÈí¼þÖ¤Êé¹ýÆÚ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ericsson.com/en/press-releases/2018/12/update-on-software-issue-impacting-certain-customers
2¡¢ÐÂAPI·ì϶µ¼ÖÂ5250ÍòÓû§ÒþÖÔ¶³ö£¬£¬£¬£¬£¬£¬£¬£¬Google+½«±»Ìáǰ¹Ø¹Ø
GoogleÈ·ÈÏGoogle+ÔÙÔⰲȫÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öAPI·ì϶µ¼ÖµÚÈý·½ÀûÓúͿª·¢Õß¿ÉÔÚδ¾Ðí¿ÉµÄÇé¿öϽӼû5250ÍòÓû§µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Ö°ÒµºÍ´ºÇïµÈ¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝGoogleµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÔÚ11ÔÂͨ¹ýÈí¼þ¸üÐÂÒýÈëµÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÒ»ÖÜÄÚ±»·¢Ïֺͽâ¾ö£¬£¬£¬£¬£¬£¬£¬£¬Ã»ÓÐÖ¤¾ÝÅú×¢¸Ã·ì϶±»µÚÈý·½ÀûÓᣡ£¡£¡£¡£¡£¡£Google½«ÔÚ2019Äê4Ô¹عØGoogle+·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬±ÈÔ¶¨µÄ2019Äê8ÔÂÌáǰÁË4¸öÔ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/google-plus-hacking.html
3¡¢ÃÀ¹ú¶àÒéÔº°ä²¼ÍøÂ簲ȫսÊõ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Ìá³öÁùÏîÁìµ¼×¼Ôò
ÃÀ¹ú¶àÒéÔºÄÜÔ´ºÍóÒ×ίԱ»á°ä²¼ÍøÂ簲ȫսÊõ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÈ·Á¢Ô¤·À»ººÍ½âÍøÂ簲ȫÊÂÎñµÄÕ½Êõ¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨ÒÔΪµ±Ç°ÃÀ¹úµÄÍøÂ簲ȫÐж¯²¢Î´¸úÉÏ»¥ÁªÍøµÄ·¢Õ¹£¬£¬£¬£¬£¬£¬£¬£¬´«Í³µÄÐÅÏ¢¼¼ÊõÕ½ÊõÔÚÓ¦¶Ô²»ÐÝÔö³¤µÄÍøÂ簲ȫÊÂÎñÖÐÊÕЧÉõ΢¡£¡£¡£¡£¡£¡£¡£»ã±¨ÊáÀí³öÁùµãÍøÂ簲ȫ¸ÅÏëÓëÁùÏîÍøÂ簲ȫÓÅÏÈÏ£¬£¬£¬£¬£¬£¬£¬Ô̺¬³ÉÁ¢ÆÕ±é½ÓÊܵÄÐͬÅû¶·¨Ê½¡¢ÒýÈëÈí¼þÎïÁÏÇåµ¥£¨software bill of materials£¬£¬£¬£¬£¬£¬£¬£¬¼ò³ÆSBOM£©¡¢Ö§³Ö¿ªÔ´Èí¼þ¡¢ÃÀÂúCVE·¨Ê½¡¢Ö´Ðм¼ÊõÐÔÃüÖÜÆÚÖ§³ÖÕ½ÊõÒÔ¼°Ç¿»¯¹«Ë½ºÏ×÷ģʽ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://energycommerce.house.gov/wp-content/uploads/2018/12/12.07.18-Cybersecurity-Strategy-Report.pdf
4¡¢ÉñǹÊÖÐж¯£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃRising Sun¶Ô׼ȫÇò¹ú·À¼°¹Ø¼ü»ù´¡ÉèÊ©
McAfee×êÑÐÈËÔ±·¢ÏÖжñÒâ»î¶¯¡°ÉñǹÊÖÐж¯¡±£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Õë¶ÔÈ«ÇòµÄ¹ú·ÀºÍ¹Ø¼ü»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ºËÄÜ¡¢¹ú·À¡¢ÄÜÔ´ºÍ½ðÈÚÆóÒµ¡£¡£¡£¡£¡£¡£¡£×Ô2018Äê10ÔÂ25ÈÕÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬Ôڶ̶ÌÁ½¸öÔÂÄÚÉñǹÊÖÐж¯ÒÑÓ°ÏìÁËÈ«Çò87¸öÆóÒµ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼Ù×°³ÉÕÐÆ¸»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýDropbox·Ö·¢Ô̺¬¶ñÒâºêµÄWordÎĵµ£¬£¬£¬£¬£¬£¬£¬£¬²¢×îÖÕ½»¸¶Rising SunºóÃÅ¡£¡£¡£¡£¡£¡£¡£¸ÃºóÃÅÓëAPT×éÖ¯LazarusÔÚ2015ÄêʹÓõĶñÒâÈí¼þDuuzerÓµÓÐÒ»ÑùµÄ´úÂë¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜºÜ¶àÏßË÷¶¼Ö¸ÏòÁËLazarus£¬£¬£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±ÒÔΪÕâЩ¹ýÓÚÏÔÖøµÄÖ¤¾Ý¿ÉÄÜÖ»Êǹ¥»÷ÕßÓÐÒâÉèÖõÄfalse flag¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/operation-sharpshooter-targets-global-defense-critical-infrastructure/
5¡¢Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SaipemÔâµ½ºÚ¿ÍÍøÂç¹¥»÷
±¾ÖÜÒ»Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SaipemÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£Saipem¹«Ë¾µÄ¿Í»§±é²¼ÔÚ60¶à¸ö¹ú¶ÈÄÚ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÆðÔ´ÓÚÓ¡¶È£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÓ°ÏìÁ˸ù«Ë¾ÔÚÖж«µØÓòµÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬É³Ìذ¢À²®¡¢°¢ÁªÇõºÍ¿ÆÍþÌØ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚÒâ´óÀû¡¢·¨¹úºÍÓ¢¹úµÄÖØÒªÔËÓªÖÐÐÄûÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£Saipem¶Ô·͸É簵ʾ¹¥»÷ÆðÔ´ÓÚÓ¡¶È½ðÄΣ¬£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßµÄÉí·Ý²»Ã÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚϵͳ¶¼Óб¸·Ý£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÃ»º±¼û¾ÝÊܵ½Ëðʧ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78859/hacking/saipem-cyber-attack.html
ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ