ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ14ÖÜ

°ä²¼¹¦·ò 2018-04-09

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ02ÈÕÖÁ06ÈÕ¹²ÊÕ¼°²È«·ì϶68¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶£»Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶£»Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶£»D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶ £¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ£»Panera BreadÓû§Êý¾Ýй¶ £¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ï죻×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ£»·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ £¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶£»×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Apple macOS°²È«ÏÞ¶ÈÈÆ¹ý·ì϶

        Apple MacOS "CoreTypes"×é¼þ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ £¬ÓÕʹÓû§½âÎö £¬¿ÉÈÆ¹ý°²È«ÏÞ¶ÈÖ´ÐÐδÊÚȨ²Ù×÷¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208692
2¡¢Apple Safari WEBKIT CVE-2018-4101ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶

        Apple Safari WEBKIT×é¼þ´æÔÚÄÚ´æ·ÛËé·ì϶ £¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.apple.com/en-ie/HT208695
3¡¢Cisco IOS XE Software¶à¸öºÅÁî×¢Èë·ì϶

        Cisco IOS XE SoftwareµÄCLI½âÎöÆ÷ÔÚʵÏÖÉÏ´æÔÚÊäÈëÑéÖ¤·ì϶ £¬±¾µØµØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬ÒÔrootȨÏÞÖ´ÐкÅÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-cmdinj
4¡¢Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´Ðзì϶

        Schneider Electric Modicon PLC FTP·þÎñÆ÷δÏ޶ȺÅÁî²ÎÊý³¤¶È £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬½øÐлؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/
5¡¢D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´Ðзì϶

        D-Link DSL-3782 'set Diagnostics_Entry'´¦ÖÃÊäÈëÖµ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/SECFORCE/CVE-2018-8941


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶ £¬Ô¼500ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢±»µÁ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        Hudson's Bay CompanyÔÚÖÜÈÕÈ·ÈϳÆ £¬Æä±±ÃÀµØÓòµÄ×Ó¹«Ë¾Saks Fifth Avenue¡¢Saks Off 5THÒÔ¼°Lord£¦TaylorµÄ²¿ÃÅÓû§µÄÐÅÓþ¿¨ÐÅϢй¶ £¬¸ÃÊÂÎñÓ°ÏìÁË´Ó2017Äê5Ôµ½2018Äê3ÔÂÔÚ±±ÃÀÉÌµê½øÐйýÖ§¸¶µÄÔ¼500ÍòÕÅÐÅÓþ¿¨¡£Ä¿Ç°ÐÅÓþ¿¨ÐÅÏ¢ÊÇΨһй¶µÄÊý¾Ý £¬Saks Fifth AvenueÔÚÉêÃ÷ÖаµÊ¾ £¬Ã»Óм£ÏóÅú×¢Éç»á±£ÏÕºÅÂë»òÉç»á±£ÏÕºÅÂë¡¢¼ÝÕÕºÅÂë»òÃÜÂëÊܵ½Ó°Ïì¡£°²È«³§ÉÌGemini Advisory³Æ¸ÃÊÂÎñÓëºÚ¿ÍÍÅ»ïJokerStash£¨Ò²±»³ÆÎªFIN7£©ÓйØ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/credit-card-data-swiped-from-5m-saks-lord-taylor-customers/130877/

2¡¢Panera BreadÓû§Êý¾Ýй¶ £¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        °²È«×êÑÐÔ±Brian Krebs»ã±¨³ÆÃæ°üÁ¬ËøµêPanera BreadµÄÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍòÓû§µÄ¼Í¼ £¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢ÉúÈÕºÍÐÅÓþ¿¨ºÅÂëµÄ×îºóËÄλÊý×Ö¡£ÕâЩÊý¾ÝÖ±µ½ÖÜÒ»»¹Äܹ»ÔÚPanerabread.comÉÏÒÔ´¿Îı¾µÄ´ó¾Ö½Ó¼û¡£°²È«×êÑÐÔ±Dylan Houlihan×î³õÓÚ2017Äê8ÔÂÏòPanera»ã±¨Á˸Ãй¶ÊÂÎñ £¬µ«¸Ã¹«Ë¾²¢Ã»ÓвÉÈ¡Ðж¯À´½â¾öÎÊÌâ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2018/04/panerabread-com-breach-could-have-impacted-millions/

3¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        Flashpoint×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ1000¸öMagentoÖÎÀíÃæ°å±»ºÚ¿ÍÈëÇÖ £¬¹¥»÷Õßͨ¹ý±©Á¦¹¥»÷»ñµÃ½Ó¼ûȨÏÞ £¬ÒÔÇÔÊØÐÅÓþ¿¨ºÅÂëºÍ×°ÖöñÒâÈí¼þ£¨Êý¾ÝÇÔÈ¡Èí¼þAZORultºÍ¶ñÒâ¿ó¹¤Rarog£©¡£Flashpoint³Æ´óÎÞÊýÍøÕ¾ÊôÓÚ½ÌÓýºÍÒ½ÁƱ£½¡ÐÐÒµ £¬IPµØÖ·ÖØÒªÉ¢²¼ÔÚÃÀ¹úºÍÅ·ÖÞ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.flashpoint-intel.com/blog/compromised-magento-sites-delivering-malware/

4¡¢·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ £¬Ô¼13ÍòÓû§µÄÍ´´¦Ð¹Â¶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        ¾Ý±¾µØÃ½Ì屨· £¬·ÒÀ¼Ê·ÉϵÚÈý´óÊý¾Ýй¶ÊÂÎñµ¼Ö³¬¹ý13ÍòÃû·ÒÀ¼¹«ÃñµÄÍ´´¦Ð¹Â¶¡£¹¥»÷ÕßÈëÇÖÁËHelsingin Uusyrityskeskus¹«Ë¾µÄÍøÕ¾£¨http://liiketoimintasuunnitelma.com£© £¬ÇÔÈ¡Á˳¬¹ý13ÍòÓû§µÄÃ÷ÎĵǼÃûºÍÃÜÂë¡£ÕâЩÓû§ÃûºÍÃÜÂëÒÔ´¿Îı¾µÄ´ó¾Ö´æ´¢ÔÚ¸ÃÍøÕ¾ÉÏ £¬²¢Ã»ÓÐʹÓÃÈκιþÏ£¼ÓÃÜ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/04/helsingin-uusyrityskeskus-hack.html

5¡¢×êÑÐÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑϳÁ°²È«·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

        ˼¿ÆTalos×êÑÐÍŶÓÔÚNatus NeuroWorksÈí¼þÖз¢ÏÖ¶à¸ö°²È«·ì϶ £¬NatusµÄÒ½ÁƲúÆ·Xltek EEGÊܵ½Ó°Ïì¡£·ì϶ÁìÓòÔ̺¬4¸öµ¼Ö´úÂëÖ´Ðеķì϶ºÍ1¸öµ¼Ö»ؾø·þÎñµÄ·ì϶¡£NatusÔÚNeuroworks 8.5 GMA2Öн¨¸´ÁËÕâЩ·ì϶ £¬½¨ÒéʹÓÃÕâЩÉ豸µÄÒ½ÁÆ»ú¹¹¾¡¿ì½øÐиüС£

        Ô­ÎÄÁ´½Ó£ºhttp://blog.talosintelligence.com/2018/04/vulnerability-spotlight-natus.html