¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181217
Ðû²¼Ê±¼ä 2018-12-17
ƾ֤ÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý±¨¸æ£¬ÃÀ¹úµÄµ¯µÀµ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂçÇå¾²É󼯡£¸Ã±¨¸æÖ¸³öBMDSÉèʩδÄÜʵÑéÓ¦ÓеÄÇå¾²¿ØÖƲ½·¥£¬°üÀ¨¶àÒòËØÉí·ÝÈÏÖ¤¡¢Îó²îÆÀ¹À»ººÍ½â¡¢·þÎñÆ÷»ú¼ÜÇå¾²¡¢¿ÉÒÆ¶¯Ã½ÌåÉϵÄÉñÃØÊý¾Ý±£»¤ºÍÊÖÒÕÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£±ðµÄ£¬Ò»Ð©ÎïÀíÇå¾²²½·¥Ò²Ã»Óе½Î»£¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»ÓÐ×°ÖÃÔÚÐèҪװÖõÄλÖ᣼à²ì³¤°ì¹«ÊÒÕýÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕǰ»ØÓ¦¸Ã·Ý±¨¸æ¡£
ÔÎÄÁ´½Ó£º
https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF2¡¢¿¨°Í˹»ùб¨¸æÅû¶µç¶¯Æû³µ³äµçÕ¾ÖеÄÇ徲Σº¦
ƾ֤¿¨°Í˹»ùʵÑéÊÒµÄÒ»·Ý±¨¸æ£¬ChargePoint¹«Ë¾ÖÆÔìµÄ¼ÒÓõ綯Æû³µ³äµçÕ¾±£´æ¶à¸öÇå¾²Îó²î£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßµ÷½â³äµçµçÁ÷ÒÔ¼°ËæÊ±×èÖ¹Æû³µµÄ³äµçÀú³Ì£¬´Ó¶øµ¼ÖÂDZÔÚµÄÎïÀíË𻵺;¼ÃËðʧ¡£¸Ã¼ÒÓóäµçÕ¾Ö§³ÖWiFiºÍÀ¶ÑÀÎÞÏßÊÖÒÕ£¬Óû§¿Éͨ¹ýiOS¼°Androidƽ̨µÄÒÆ¶¯appÔ¶³Ì¿ØÖƳäµçÀú³Ì¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸µÄWeb·þÎñÆ÷±£´æÖ¤ÊéÇå¾²ÎÊÌâ¡¢»º³åÇøÒç³öµÈÎó²î¡£ÏÖÔڸù«Ë¾ÒÑÐÞ¸´ÁËÕâЩÎó²î¡£
ÔÎÄÁ´½Ó£º
https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/12/13084354/ChargePoint-Home-security-research_final.pdf3¡¢TwitterÐû²¼Í¸Ã÷¶È±¨¸æ£¬³ÆÆäÿÔÂÊÕµ½50ÍòÀ¬»øÓʼþ±¨¸æ
ƾ֤TwitterµÄ2018ÄêÉϰëÄê͸Ã÷¶È±¨¸æ£¬ÆäÿÔÂÊÕµ½µÄÀ¬»øÓʼþ±¨¸æÊýĿһÁ¬Ï½µ£¬´Ó1ÔÂ·ÝµÄÆ½¾ùÔ¼868349·Ý±¨¸æÏ½µµ½6Ô·ݵÄÔ¼504259·Ý¡£¸Ã±¨¸æ»¹Ç¿µ÷ÁËÕþ¸®¶ÔÓû§Êý¾ÝµÄÅû¶ÇëÇó´ó·ùÉÏÉý¡£½ñÄê1ÔÂÖÁ6Ô£¬TwitterÊÕµ½µÄÕþ¸®ÇëÇó±ÈÉϸö±¨¸æÆÚÔöÌíÁË10%£¬ÕâÊÇÈýÄêÀ´×î´óµÄÔöÌí¡£±ðµÄ£¬1ÔÂÖÁ6ÔÂÁè¼Ý205100¸öÕË»§ÒòÐû²¼¿Ö²ÀÖ÷ÒåÄÚÈݶø±»É¾³ý£¬Óë2017ÄêϰëÄêµÄÊý×Ö£¨120Íò£©Ïà±È´ó·ùϽµ¡£1ÔÂÖÁ6ÔÂʱ´úÉÐÓÐÁè¼Ý487300¸öÕË»§Òò¶ùͯÐÔ¾ÛÁ²ÎÊÌâ¶ø±»·â½û¡£
ÔÎÄÁ´½Ó£º
https://transparency.twitter.com/4¡¢APT28ʹÓÃZebrocyºóÃźÍCannonľÂí¹¥»÷¶à¸öÕþ¸®»ú¹¹
Palo Alto NetworksµÄUnit42ÍŶÓÐû²¼¹ØÓÚAPT28½üÆÚÕë¶ÔÕþ¸®»ú¹¹µÄ¶ñÒâÔ˶¯µÄÆÊÎö±¨¸æ¡£2018Äê10ÔÂÖÐÑ®µ½2018Äê11ÔÂÖÐѮʱ´ú£¬APT28Ò»Á¬Ï®»÷ÁËÌìϸ÷µØµÄ¶à¸öÕþ¸®»ú¹¹£¬Ö÷ҪĿµÄÊDZ±Ô¼¹ú¼Ò£¬µ«Ò²°üÀ¨¼¸¸öǰËÕÁª¹ú¼Ò¡£ÕâЩ¹¥»÷Ô˶¯Ö÷Òª°²ÅÅÁËZebrocy»òCannon±äÖÖ£¬Æä½»¸¶µÄ¶ñÒâÎĵµÊ¹ÓÃÁËͳһ¸ö×÷ÕßÃû³Æ£ºJoohn¡£Ñо¿Ö°Ô±ÆÊÎöÁËÍøÂçµ½µÄ9¸ö¶ñÒâÎĵµ£¬²¢½¨ÉèÁËDear JoohnÔ˶¯µÄʱ¼äÏß¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/dear-joohn-sofacy-groups-global-campaign/5¡¢Ð¶ñÒâÈí¼þCapitalInstall£¬Ö÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ
NetskopeÍþвÑо¿ÊµÑéÊÒ·¢Ã÷Ò»¸öеĶñÒâÈí¼þCapitalInstall¡£¸Ã¶ñÒâÈí¼þͨ¹ýMicrosoft Azure·Ö·¢£¬ÕâʹµÃÆäIPµØµã±»Ðí¶à¹«Ë¾¼ÓÈë°×Ãûµ¥¡£CapitalInstallαװ³ÉÊ¢ÐÐÈí¼þ£¨ÀýÈçAdobe CC 2019£©µÄÃâ·ÑÃÜÔ¿ºÍÔÊÐíÖ¤£¬ÓÕÆÓû§¾ÙÐÐÏÂÔØ£¬²¢À¦°óÁË¹ã¸æÈí¼þLinkury£¬½ø¶øÔÚÓû§µÄÅÌËã»úÉÏÏÂÔØ¸ü¶àDZÔÚÓк¦µÄ³ÌÐò¡£CapitalInstallÖ÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ¡£
ÔÎÄÁ´½Ó£º
https://www.netskope.com/blog/capitalinstall-hosted-and-served-via-iaas6¡¢Î÷ÃÅ×ÓÐÞ¸´SINUMERIK¿ØÖÆÆ÷ÖеĶà¸öÇå¾²Îó²î
Î÷ÃÅ×ÓÐÞ¸´ÁËSINUMERIK¿ØÖÆÆ÷ÖеÄ10¸öÇå¾²Îó²î¡£ÆäÖÐÎó²î£¨CVE-2018-11466£©ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòTCP¶Ë¿Ú102·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢DoS»òÖ´ÐÐí§Òâ´úÂ룬¸ÃÎó²îµÄʹÓò¢²»ÐèÒªÈκÎÓû§½»»¥¡£±ðµÄ£¬Îó²î£¨CVE-2018-11457ºÍCVE-2018-11458£©ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËͶñÒâTCPÊý¾Ý°üÀ´¾ÙÐÐÌáȨ¡£½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£Î÷ÃÅ×Ó×î½üÐû²¼½«Ïñ΢Èí¡¢AdobeºÍSAPÒ»ÑùÔÚÿ¸öÔµĵڶþ¸öÐÇÆÚ¶þÐû²¼Ç徲ͨ¸æ¡£
ÔÎÄÁ´½Ó£º
https://cert-portal.siemens.com/productcert/pdf/ssa-170881.pdfÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ