ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ33ÖÜ
Ðû²¼Ê±¼ä 2018-08-20Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2018Äê08ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î79¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Digital Network Architecture Center CVE-2018-0427ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»Microsoft Exchange CVE-2018-8302ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Microsoft Excel CVE-2018-8375Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Microsoft ChakraCore¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»WordPress CVE-2018-14028í§ÒâÎļþÉÏ´«Îó²î¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÎ÷ÒøÐеÄDNSÐ®ÖÆ¹¥»÷»î¶¯£»£»£»£»£»Ñо¿Ö°Ô±³ÆGoDaddyÒòAWSÉèÖùýʧµ¼Ö²¿·ÖÊý¾Ýй¶£»£»£»£»£»Ñо¿ÍŶÓÐû²¼2018ÄêQ2À¬»øÓʼþºÍ´¹ÂÚ¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ£»£»£»£»£»Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬ÈýÌìÄÚËðʧÁè¼Ý1350ÍòÃÀÔª£»£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÇÔÈ¡Office 365ƾ֤µÄPhishPoint¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£
¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
Cisco Digital Network Architecture Center CronJob scheduler API½Ó¿Ú±£´æÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-dna-injection
2¡¢Microsoft Exchange CVE-2018-8302ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î
Microsoft Exchange Server´¦Öóͷ£Óʼþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8302
Microsoft Excel´¦Öóͷ£¶ñÒâxlsÎļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8379
Microsoft ChakraCoreûÓÐ׼ȷµÄ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8384
WordPressûÓмì²âͨ¹ýadminÇøÓòÉÏ´«µÄ²å¼þÊÇ·ñΪZIPÎļþ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÉÏ´«í§ÒâPHPÎļþ²¢Ö´ÐС£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://core.trac.wordpress.org/ticket/44710
Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
RadwareÑо¿ÍŶӷ¢Ã÷¹¥»÷ÕßÕýÔÚÕë¶Ô°ÍÎ÷µÄDLink DSL·ÓÉÆ÷£¬£¬£¬£¬£¬£¬£¬Í¨¹ýDNSÐ®ÖÆ¹¥»÷½«ÒøÐÐÓû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾²¢ÇÔÈ¡ÆäÒøÐÐÕË»§µÄµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÐÞ¸ÄÁËÕâЩ·ÓÉÆ÷×°±¸ÖеÄDNSÉèÖ㬣¬£¬£¬£¬£¬£¬½«ÆäÖ¸Ïò¶ñÒâµÄDNSЧÀÍÆ÷£¨69.162.89.185ºÍ198.50.222.136£©£¬£¬£¬£¬£¬£¬£¬ÕâЩװ±¸ÔÚ»á¼ûBanco de Brasil£¨www.bb.com.br£©ºÍItau Unibanco£¨www.itau.com.br£©Ê±½«±»Öض¨ÏòÖÁ¶ñÒâµÄipµØµã¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ç¿µ÷³Æ£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÐ®ÖÆ²»ÐèÒªÈκεÄÓû§½»»¥¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://security.radware.com/ddos-threats-attacks/threat-advisories-attack-reports/dns-hijacking-brazil-banks/
2¡¢Ñо¿Ö°Ô±³ÆGoDaddyÒòAWSÉèÖùýʧµ¼Ö²¿·ÖÊý¾Ýй¶
UpGuardÑо¿ÍŶӷ¢Ã÷GoDaddyÒòAWSÉèÖùýʧµ¼Ö²¿·ÖÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶Éæ¼°µÄÎļþËÆºõÊÇGoDaddyÔÚAWSÔÆÉÏÔËÐеĻù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÎļþ°üÀ¨Ô¼3.1Íò¸öϵͳµÄ»ù±¾ÉèÖÃÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÈçÖ÷»úÃû¡¢²Ù×÷ϵͳ¡¢ÊÂÇé¸ºÔØ¡¢AWSÇøÓò¡¢ÄÚ´æºÍCPU¹æ¸ñµÈ£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ»¹°üÀ¨AWSÔÚ²î±ðÇéÐÎϸøÓèµÄÕÛ¿ÛÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÏÖʵÉÏ£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÖ±½Óй¶ÁËÒ»¸ö¹æÄ£ºÜÊÇ´óµÄAWSÔÆ»ù´¡ÉèÊ©°²ÅÅÇéÐΡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75271/data-breach/godaddy-aws-data-leak.html
3¡¢Ñо¿ÍŶÓÐû²¼2018ÄêQ2À¬»øÓʼþºÍ´¹ÂÚ¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ
ÔÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/
4¡¢Ó¡¶ÈÒøÐÐCosmos BankÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬ÈýÌìÄÚËðʧÁè¼Ý1350ÍòÃÀÔª
ÉÏÖÜĩӡ¶ÈÒøÐÐCosmos BankÔâµ½ºÚ¿ÍµÄÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈýÌìÄÚÇÔÈ¡ÁËÁè¼Ý9.4ÒÚ¬±È£¨Ô¼1350ÍòÃÀÔª£©µÄ×ʽ𡣡£¡£¡£¡£¡£¾ÝÍâµØÃ½Ì屨µÀ£¬£¬£¬£¬£¬£¬£¬Ç°Á½´Î͵ÇÔ±¬·¢ÔÚ8ÔÂ11ÈÕÐÇÆÚÁù£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý28¸ö¹ú¼ÒµÄ14849±ÊATMÉúÒâÇÔÈ¡ÁËÔ¼1140ÍòÃÀÔª¡£¡£¡£¡£¡£¡£ËæºóÔÚ8ÔÂ13ÈÕÐÇÆÚÒ»£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÙ´Îͨ¹ýSWIFTϵͳÇÔÈ¡ÁËÔ¼200ÍòÃÀÔª¡£¡£¡£¡£¡£¡£ÏÖÔÚµÄÖ¤¾ÝÅú×¢¹¥»÷À´×Ô¼ÓÄô󣬣¬£¬£¬£¬£¬£¬¸ÃÒøÐÐÌåÏִ˴ι¥»÷µÄÊÖÒÕϸ½ÚÈÔÔÚ½øÒ»³ÌÐò²éÖ®ÖС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-steal-135-million-across-three-days-from-indian-bank/
5¡¢Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÇÔÈ¡Office 365ƾ֤µÄPhishPoint¹¥»÷»î¶¯
ÔÆÇå¾²¹«Ë¾AvananµÄÑо¿Ö°Ô±·¢Ã÷Ö÷ÒªÓÃÓÚÇÔÈ¡Office 365Óû§Æ¾Ö¤µÄPhishPoint¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£PhishPointÊÇÒ»ÖÖеÄʹÓÃSharePointµÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÔÚÒÑÍùÁ½ÖÜÄÚԼĪӰÏìÁË10%µÄOffice 365Óû§¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ´¹ÂÚÓʼþÖаüÀ¨Ò»¸öSharePointÎĵµµÄÁ´½Ó£¬£¬£¬£¬£¬£¬£¬¶ø¸ÃSharePointÎĵµÉϵĻá¼ûÎĵµ°´Å¥ÏÖʵÉÏÊǽ«Óû§Öض¨ÏòÖÁ´¹ÂÚÍøÒ³µÄ³¬Á´½Ó¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷¿ÉÒÔÈÆ¹ýOffice 365µÄ¸ß¼¶Íþв·À»¤£¨ATP£©»úÖÆ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/microsoft-office365-phishing.html


¾©¹«Íø°²±¸11010802024551ºÅ