ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ33ÖÜ

°ä²¼¹¦·ò 2018-08-20

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


 2018Äê08ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶79¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Digital Network Architecture Center CVE-2018-0427ºÅÁî×¢Èë·ì϶£»Microsoft Exchange CVE-2018-8302ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»Microsoft Excel CVE-2018-8375Ô¶³Ì´úÂëÖ´Ðзì϶£»Microsoft ChakraCore¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶£»WordPress CVE-2018-14028ËÁÒâÎļþÉÏ´«·ì϶¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖÕë¶Ô°ÍÎ÷ÒøÐеÄDNS½Ù³Ö¹¥»÷»î¶¯£»×êÑÐÈËÔ±³ÆGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶£»×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨£»Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬ÈýÌìÄÚËðʧ³¬¹ý1350ÍòÃÀÔª£»×êÑÐÈËÔ±·¢ÏÖÖØÒªÇÔÈ¡Office 365Í´´¦µÄPhishPoint¹¥»÷»î¶¯¡£

 Æ¾¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£



¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1¡¢Cisco Digital Network Architecture Center CVE-2018-0427ºÅÁî×¢Èë·ì϶


Cisco Digital Network Architecture Center CronJob scheduler API½Ó¿Ú´æÔÚºÅÁî×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÌáÉýȨÏÞÒÔROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-dna-injection


2¡¢Microsoft Exchange CVE-2018-8302ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶



 Microsoft Exchange Server´¦ÖÃÓʼþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8302


3¡¢Microsoft Excel CVE-2018-8375Ô¶³Ì´úÂëÖ´Ðзì϶


Microsoft Excel´¦ÖöñÒâxlsÎļþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8379


4¡¢Microsoft ChakraCore¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶


Microsoft ChakraCoreûÓÐÕýÈ·µÄ´¦ÖÃÄÚ´æÖеĶÔÏó£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8384


5¡¢WordPress CVE-2018-14028ËÁÒâÎļþÉÏ´«·ì϶


WordPressûÓмì²âͨ¹ýadminÇøÓòÉÏ´«µÄ²å¼þÊÇ·ñΪZIPÎļþ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÉÏ´«ËÁÒâPHPÎļþ²¢Ö´ÐС£


Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://core.trac.wordpress.org/ticket/44710


 


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÍŶӷ¢ÏÖÕë¶Ô°ÍÎ÷ÒøÐеÄDNS½Ù³Ö¹¥»÷»î¶¯

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Radware×êÑÐÍŶӷ¢ÏÖ¹¥»÷ÕßÔÚÕë¶Ô°ÍÎ÷µÄDLink DSL·ÓÉÆ÷£¬Í¨¹ýDNS½Ù³Ö¹¥»÷½«ÒøÐÐÓû§³Á¶¨ÏòÖÁ´¹µöÍøÕ¾²¢ÇÔÈ¡ÆäÒøÐÐÕË»§µÄµÇ¼ʹ´¦¡£¹¥»÷ÕßÅú¸ÄÁËÕâЩ·ÓÉÆ÷É豸ÖеÄDNSÉèÖ㬽«ÆäÖ¸Ïò¶ñÒâµÄDNS·þÎñÆ÷£¨69.162.89.185ºÍ198.50.222.136£©£¬ÕâЩÉ豸ÔÚ½Ó¼ûBanco de Brasil£¨www.bb.com.br£©ºÍItau Unibanco£¨www.itau.com.br£©Ê±½«±»³Á¶¨ÏòÖÁ¶ñÒâµÄipµØÖ·¡£×êÑÐÈËԱǿµ÷³Æ£¬ÕâÖÖ½Ù³Ö²»±ØÒªÈκεÄÓû§½»»¥¡£


Ô­ÎÄÁ´½Ó£ºhttps://security.radware.com/ddos-threats-attacks/threat-advisories-attack-reports/dns-hijacking-brazil-banks/


2¡¢×êÑÐÈËÔ±³ÆGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


UpGuard×êÑÐÍŶӷ¢ÏÖGoDaddyÒòAWSÅäÖÃÃýÎóµ¼Ö²¿ÃÅÊý¾Ýй¶£¬Ð¹Â¶Éæ¼°µÄÎļþËÆºõÊÇGoDaddyÔÚAWSÔÆÉÏÔËÐеĻù´¡ÉèÊ©¡£Ð¹Â¶µÄÎļþÔ̺¬Ô¼3.1Íò¸öϵͳµÄ¸ù»ùÅäÏàÐÅÏ¢£¬ÈçÖ÷»úÃû¡¢²Ù×÷ϵͳ¡¢¹¤×÷¸ºÔØ¡¢AWSÇøÓò¡¢ÄÚ´æºÍCPU¹æ¸ñµÈ£¬ÉõÖÁ»¹Ô̺¬AWSÔÚ·ÖÆçÇé¿öÏ´ÍÓëµÄÕÛ¿ÛÐÅÏ¢µÈ¡£ÏÖʵÉÏ£¬ÕâЩÊý¾ÝÖ±½Óй¶ÁËÒ»¸ö¹æÄ£¼«¶È´óµÄAWSÔÆ»ù´¡ÉèÊ©²¿Êð»·¾³¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75271/data-breach/godaddy-aws-data-leak.html


3¡¢×êÑÐÍŶӰ䲼2018ÄêQ2À¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÀ¬»øÓʼþºÍ´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨¡£±¾¼¾¶ÈÀ¬»øÓʼþ¾ùÔÈռȫÇòÓʼþ×ÜÁ¿µÄ49.66%£¬ÓëÉÏÒ»¼¾¶ÈÏà±È½µÂäÁË2.16¸ö°Ù·Öµã¡£·´´¹µöϵͳԮÊÖÓû§×èÖ¹Á˳¬¹ý1.07ÒڴζԴ¹µöÍøÕ¾µÄÏνÓ£¬±È2018ÄêµÚÒ»¼¾¶ÈÔö³¤ÁË1700Íò¡£±¾¼¾¶ÈµÄÀ¬»øÓʼþÖ÷ÌâÖØÒªÓëGDPR¡¢ÊÀ½ç±­ºÍ¼ÓÃÜÇ®±ÒÓйØ£¬·¸×ï·Ö×Ó»¹Í¨¹ýÉç½»ÍøÂç¡¢ÐÂÎÅÀûÓúÍÓªÏú¶ÌÐÅÀ´·Ö·¢´¹µöÍøÕ¾µÄÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/


4¡¢Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬ÈýÌìÄÚËðʧ³¬¹ý1350ÍòÃÀÔª

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÉÏÖÜĩӡ¶ÈÒøÐÐCosmos BankÔâµ½ºÚ¿ÍµÄÈëÇÖ£¬¹¥»÷ÕßÔÚÈýÌìÄÚÇÔÈ¡Á˳¬¹ý9.4ÒÚ¬±È£¨Ô¼1350ÍòÃÀÔª£©µÄ×ʽ𡣾ݱ¾µØÃ½Ì屨·£¬Ç°Á½´Î͵ÇÔ²úÉúÔÚ8ÔÂ11ÈÕÐÇÆÚÁù£¬¹¥»÷Õßͨ¹ý28¸ö¹ú¶ÈµÄ14849±ÊATMÂòÂôÇÔÈ¡ÁËÔ¼1140ÍòÃÀÔª¡£ËæºóÔÚ8ÔÂ13ÈÕÐÇÆÚÒ»£¬¹¥»÷ÕßÔÙ´Îͨ¹ýSWIFTϵͳÇÔÈ¡ÁËÔ¼200ÍòÃÀÔª¡£Ä¿Ç°µÄÖ¤¾ÝÅú×¢¹¥»÷À´×Ô¼ÓÄô󣬸ÃÒøÐаµÊ¾Õâ´Î¹¥»÷µÄ¼¼Êõϸ½ÚÈÔÔÚ½øÒ»´ëÊ©²éÖ®ÖС£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-steal-135-million-across-three-days-from-indian-bank/


5¡¢×êÑÐÈËÔ±·¢ÏÖÖØÒªÇÔÈ¡Office 365Í´´¦µÄPhishPoint¹¥»÷»î¶¯

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÆ°²È«¹«Ë¾AvananµÄ×êÑÐÈËÔ±·¢ÏÖÖØÒªÓÃÓÚÇÔÈ¡Office 365Óû§Í´´¦µÄPhishPoint¹¥»÷»î¶¯¡£PhishPointÊÇÒ»ÖÖеÄÀûÓÃSharePointµÄÍøÂç´¹µö¹¥»÷£¬ÆäÔÚ´ÓǰÁ½ÖÜÄÚԼĪӰÏìÁË10%µÄOffice 365Óû§¡£¹¥»÷ÕßÔÚ´¹µöÓʼþÖÐÔ̺¬Ò»¸öSharePointÎĵµµÄÁ´½Ó£¬¶ø¸ÃSharePointÎĵµÉϵĽӼûÎĵµ°´Å¥ÏÖʵÉÏÊǽ«Óû§³Á¶¨ÏòÖÁ´¹µöÍøÒ³µÄ³¬Á´½Ó¡£ÕâÖÖ¹¥»÷Äܹ»ÈƹýOffice 365µÄ¸ß¼¶Íþв·À»¤£¨ATP£©»úÔì¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/microsoft-office365-phishing.html