ÆÊÎö±¨¸æ¡¿Ñо¿ÍŶÓÐû²¼2018ÄêQ2À¬»øÓʼþºÍ´¹ÂÚ¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÀ¬»øÓʼþºÍ´¹ÂÚ¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£±¾¼¾¶ÈÀ¬»øÓʼþƽ¾ùռȫÇòÓʼþ×ÜÁ¿µÄ49.66%£¬ÓëÉÏÒ»¼¾¶ÈÏà±ÈϽµÁË2.16¸ö°Ù·Öµã¡£·´´¹ÂÚϵͳ×ÊÖúÓû§×èÖ¹ÁËÁè¼Ý1.07ÒڴζԴ¹ÂÚÍøÕ¾µÄÅþÁ¬£¬±È2018ÄêµÚÒ»¼¾¶ÈÔöÌíÁË1700Íò¡£±¾¼¾¶ÈµÄÀ¬»øÓʼþÖ÷ÌâÖ÷ÒªÓëGDPR¡¢ÌìϱºÍ¼ÓÃÜÇ®±ÒÓйأ¬·¸·¨·Ö×Ó»¹Í¨¹ýÉç½»ÍøÂç¡¢ÐÂÎÅÓ¦ÓúÍÓªÏú¶ÌÐÅÀ´·Ö·¢´¹ÂÚÍøÕ¾µÄÁ´½Ó¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/
¡¾Îó²î²¹¶¡¡¿Î¢ÈíµÄ8ÔÂÇå¾²¸üÐÂÐÞ¸´ÁË60¸öÇå¾²Îó²î£¬°üÀ¨2¸ö0day
΢ÈíÐû²¼2018Äê8ÔµÄÇå¾²¸üУ¬¹²ÐÞ¸´60¸öÇå¾²Îó²î£¬°üÀ¨2¸ö0day¡£µÚÒ»¸ö0dayÊÇWindows ShellÖеĿɵ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÎó²î£¨CVE-2018-8414£©£¬µÚ¶þ¸öÊǿɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄIE 0day£¨CVE-2018-8373£©¡£´Ë´ÎÇå¾²¸üй²ÐÞ¸´ÁË19¸ö¸ßΣÎó²î£¬ËùÓеÄÕâЩ¸ßΣÎó²î¶¼¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-august-2018-patch-tuesday-fixes-60-security-flaws-including-two-zero-days/
¡¾Îó²î²¹¶¡¡¿ICS-CERTÖÒÑÔ³ÆNetComm¹¤ÒµÂ·ÓÉÆ÷±£´æÁ½¸ö¸ßΣÎó²î
Çå¾²Ñо¿Ô±Aditya K. Sood·¢Ã÷°Ä´óÀûÑǹ«Ë¾NetComm WirelessÖÆÔìµÄ¹¤ÒµÂ·ÓÉÆ÷±£´æÁ½¸ö¸ßΣÎó²î£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÀ´½ÓÊÜ×°±¸¡£ÊÜÓ°ÏìµÄ²úÆ·ÐͺÅÊÇÔËÐй̼þ°æ±¾2.0.29.11¼°Ö®Ç°°æ±¾µÄNetComm 4G LTE Light M2M¹¤ÒµÂ·ÓÉÆ÷¡£ICS-CERTÕë¶Ô°üÀ¨ÕâÁ½¸öÎó²îÔÚÄÚµÄ4¸öÇå¾²Îó²î£¨CVE-2018-14782µ½CVE-2018-14785£©·¢³öÖÒÑÔ¡£NetCommÒÑÔÚ2018Äê5ÔÂÖÐÑ®Ðû²¼ÁËÏà¹Ø¹Ì¼þ¸üС£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75332/hacking/netcomm-industrial-routers-flaws.html
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓô«ÕæÐÒéÎó²îÉøÍ¸ÆóÒµÄÚÍø
Check PointµÄÑо¿Ö°Ô±ÑÝʾÔõÑùʹÓô«ÕæÐÒéÖеÄÁ½¸öÎó²îÀ´½ÓÊÜ´òÓ¡»úºÍÉøÍ¸ÆóÒµÄÚÍø¡£ÏÖÔÚÈ«ÇòÈÔÓÐÁè¼Ý3ÒÚ¸ö´«ÕæºÅÂëºÍ4500Íǫ̀´«Õæ»úͶÈëʹÓ㬴«Õæ±»ÆÕ±éÓÃÓÚÉÌÒµ×éÖ¯¡¢î¿Ïµ»ú¹¹¡¢Ö´·¨»ú¹¹¡¢ÒøÐлú¹¹ºÍ·¿µØ²ú¹«Ë¾µÈ¡£¸Ã¹¥»÷ÒªÁì±»³ÆÎªFaxploit¹¥»÷£¬Óë´«ÕæÐÒéÖеÄÁ½¸ö»º³åÇøÒç³öÎó²îÓйأ¨CVE-2018-5925ºÍCVE-2018-5924£©¡£Ô¶³Ì¹¥»÷ÕßÖ»Ðè·¢ËÍÌØÖÆµÄͼÏñÎļþ¼´¿ÉʹÓÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/hack-printer-fax-machine.html
¡¾ÍþвÇ鱨¡¿Çå¾²Ñо¿ÍŶӷ¢Ã÷¶à¸öÖÇÄܽ½¹àϵͳ±£´æÇå¾²Îó²î
À´×ÔÒÔÉ«Áб¾¹ÅÀï°²´óѧµÄÑо¿ÍŶӷ¢Ã÷¶à¸öÖÇÄܽ½¹àϵͳ±£´æ¿ÉʹÓõÄÎó²î£¬¿ÉÓÃÓÚ¹¥»÷¶¼»áµÄ¹©Ë®·þÎñ¡£Ñо¿Ö°Ô±ÆÊÎöÁËRainMachine¡¢BlueSprayºÍGreenIQµÈÖ÷Á÷½½¹àϵͳ£¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ýIoT¶ñÒâÈí¼þ½¨ÉèÖÇÄܽ½¹àϵͳµÄ½©Ê¬ÍøÂ磬²¢Í¨¹ýC&C·þÎñÆ÷¿ØÖÆÕâЩϵͳ¡£Ñо¿Ö°Ô±ÖÒÑԳƣ¬ÕâÖÖ¹¥»÷¿ÉÄÜ»á¶Ô¹©Ë®¹«Ë¾±¬·¢ÖØ´óÓ°Ï죬ÀýÈçÈÃÅçÍ·Ò»Á¬È÷Ë®ÒÔÔÚ¶Ìʱ¼äÄÚÇå¿ÕË®ÏäºÍË®¿â¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/smart-irrigation-systems-expose-water-utilities-attacks