¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181217

Ðû²¼Ê±¼ä 2018-12-17
1¡¢ÃÀDoD³ÆÆäµ¯µÀµ¼µ¯·ÀÓùϵͳδͨ¹ýÍøÂçÇå¾²Éó¼Æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ƾ֤ÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý±¨¸æ £¬ÃÀ¹úµÄµ¯µÀµ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂçÇå¾²É󼯡£¸Ã±¨¸æÖ¸³öBMDSÉèʩδÄÜʵÑéÓ¦ÓеÄÇå¾²¿ØÖƲ½·¥ £¬°üÀ¨¶àÒòËØÉí·ÝÈÏÖ¤¡¢Îó²îÆÀ¹À»ººÍ½â¡¢·þÎñÆ÷»ú¼ÜÇå¾²¡¢¿ÉÒÆ¶¯Ã½ÌåÉϵÄÉñÃØÊý¾Ý±£»¤ºÍÊÖÒÕÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£±ðµÄ £¬Ò»Ð©ÎïÀíÇå¾²²½·¥Ò²Ã»Óе½Î» £¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»ÓÐ×°ÖÃÔÚÐèҪװÖõÄλÖ᣼à²ì³¤°ì¹«ÊÒÕýÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕǰ»ØÓ¦¸Ã·Ý±¨¸æ¡£


Ô­ÎÄÁ´½Ó£º

https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF


2¡¢¿¨°Í˹»ùб¨¸æÅû¶µç¶¯Æû³µ³äµçÕ¾ÖеÄÇ徲Σº¦

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



ƾ֤¿¨°Í˹»ùʵÑéÊÒµÄÒ»·Ý±¨¸æ £¬ChargePoint¹«Ë¾ÖÆÔìµÄ¼ÒÓõ綯Æû³µ³äµçÕ¾±£´æ¶à¸öÇå¾²Îó²î £¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßµ÷½â³äµçµçÁ÷ÒÔ¼°ËæÊ±×èÖ¹Æû³µµÄ³äµçÀú³Ì £¬´Ó¶øµ¼ÖÂDZÔÚµÄÎïÀíË𻵺;­¼ÃËðʧ¡£¸Ã¼ÒÓóäµçÕ¾Ö§³ÖWiFiºÍÀ¶ÑÀÎÞÏßÊÖÒÕ £¬Óû§¿Éͨ¹ýiOS¼°Androidƽ̨µÄÒÆ¶¯appÔ¶³Ì¿ØÖƳäµçÀú³Ì¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸µÄWeb·þÎñÆ÷±£´æÖ¤ÊéÇå¾²ÎÊÌâ¡¢»º³åÇøÒç³öµÈÎó²î¡£ÏÖÔڸù«Ë¾ÒÑÐÞ¸´ÁËÕâЩÎó²î¡£


 Ô­ÎÄÁ´½Ó£º

https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/12/13084354/ChargePoint-Home-security-research_final.pdf


3¡¢TwitterÐû²¼Í¸Ã÷¶È±¨¸æ £¬³ÆÆäÿÔÂÊÕµ½50ÍòÀ¬»øÓʼþ±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ƾ֤TwitterµÄ2018ÄêÉϰëÄê͸Ã÷¶È±¨¸æ £¬ÆäÿÔÂÊÕµ½µÄÀ¬»øÓʼþ±¨¸æÊýĿһÁ¬Ï½µ £¬´Ó1ÔÂ·ÝµÄÆ½¾ùÔ¼868349·Ý±¨¸æÏ½µµ½6Ô·ݵÄÔ¼504259·Ý¡£¸Ã±¨¸æ»¹Ç¿µ÷ÁËÕþ¸®¶ÔÓû§Êý¾ÝµÄÅû¶ÇëÇó´ó·ùÉÏÉý¡£½ñÄê1ÔÂÖÁ6Ô £¬TwitterÊÕµ½µÄÕþ¸®ÇëÇó±ÈÉϸö±¨¸æÆÚÔöÌíÁË10% £¬ÕâÊÇÈýÄêÀ´×î´óµÄÔöÌí¡£±ðµÄ £¬1ÔÂÖÁ6ÔÂÁè¼Ý205100¸öÕË»§ÒòÐû²¼¿Ö²ÀÖ÷ÒåÄÚÈݶø±»É¾³ý £¬Óë2017ÄêϰëÄêµÄÊý×Ö£¨120Íò£©Ïà±È´ó·ùϽµ¡£1ÔÂÖÁ6ÔÂʱ´úÉÐÓÐÁè¼Ý487300¸öÕË»§Òò¶ùͯÐÔ¾ÛÁ²ÎÊÌâ¶ø±»·â½û¡£


Ô­ÎÄÁ´½Ó£º

https://transparency.twitter.com/


4¡¢APT28ʹÓÃZebrocyºóÃźÍCannonľÂí¹¥»÷¶à¸öÕþ¸®»ú¹¹

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Palo Alto NetworksµÄUnit42ÍŶÓÐû²¼¹ØÓÚAPT28½üÆÚÕë¶ÔÕþ¸®»ú¹¹µÄ¶ñÒâÔ˶¯µÄÆÊÎö±¨¸æ¡£2018Äê10ÔÂÖÐÑ®µ½2018Äê11ÔÂÖÐѮʱ´ú £¬APT28Ò»Á¬Ï®»÷ÁËÌìϸ÷µØµÄ¶à¸öÕþ¸®»ú¹¹ £¬Ö÷ҪĿµÄÊDZ±Ô¼¹ú¼Ò £¬µ«Ò²°üÀ¨¼¸¸öǰËÕÁª¹ú¼Ò¡£ÕâЩ¹¥»÷Ô˶¯Ö÷Òª°²ÅÅÁËZebrocy»òCannon±äÖÖ £¬Æä½»¸¶µÄ¶ñÒâÎĵµÊ¹ÓÃÁËͳһ¸ö×÷ÕßÃû³Æ£ºJoohn¡£Ñо¿Ö°Ô±ÆÊÎöÁËÍøÂçµ½µÄ9¸ö¶ñÒâÎĵµ £¬²¢½¨ÉèÁËDear JoohnÔ˶¯µÄʱ¼äÏß¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/dear-joohn-sofacy-groups-global-campaign/


5¡¢Ð¶ñÒâÈí¼þCapitalInstall £¬Ö÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


NetskopeÍþвÑо¿ÊµÑéÊÒ·¢Ã÷Ò»¸öеĶñÒâÈí¼þCapitalInstall¡£¸Ã¶ñÒâÈí¼þͨ¹ýMicrosoft Azure·Ö·¢ £¬ÕâʹµÃÆäIPµØµã±»Ðí¶à¹«Ë¾¼ÓÈë°×Ãûµ¥¡£CapitalInstallαװ³ÉÊ¢ÐÐÈí¼þ£¨ÀýÈçAdobe CC 2019£©µÄÃâ·ÑÃÜÔ¿ºÍÔÊÐíÖ¤ £¬ÓÕÆ­Óû§¾ÙÐÐÏÂÔØ £¬²¢À¦°óÁË¹ã¸æÈí¼þLinkury £¬½ø¶øÔÚÓû§µÄÅÌËã»úÉÏÏÂÔØ¸ü¶àDZÔÚÓк¦µÄ³ÌÐò¡£CapitalInstallÖ÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://www.netskope.com/blog/capitalinstall-hosted-and-served-via-iaas


6¡¢Î÷ÃÅ×ÓÐÞ¸´SINUMERIK¿ØÖÆÆ÷ÖеĶà¸öÇå¾²Îó²î

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Î÷ÃÅ×ÓÐÞ¸´ÁËSINUMERIK¿ØÖÆÆ÷ÖеÄ10¸öÇå¾²Îó²î¡£ÆäÖÐÎó²î£¨CVE-2018-11466£©ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòTCP¶Ë¿Ú102·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢DoS»òÖ´ÐÐí§Òâ´úÂë £¬¸ÃÎó²îµÄʹÓò¢²»ÐèÒªÈκÎÓû§½»»¥¡£±ðµÄ £¬Îó²î£¨CVE-2018-11457ºÍCVE-2018-11458£©ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËͶñÒâTCPÊý¾Ý°üÀ´¾ÙÐÐÌáȨ¡£½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£Î÷ÃÅ×Ó×î½üÐû²¼½«Ïñ΢Èí¡¢AdobeºÍSAPÒ»ÑùÔÚÿ¸öÔµĵڶþ¸öÐÇÆÚ¶þÐû²¼Ç徲ͨ¸æ¡£


 Ô­ÎÄÁ´½Ó£º

https://cert-portal.siemens.com/productcert/pdf/ssa-170881.pdf


ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí