ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ14ÖÜ

Ðû²¼Ê±¼ä 2018-04-09

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ02ÈÕÖÁ06ÈÕ¹²ÊÕ¼Çå¾²Îó²î68¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOSÇå¾²ÏÞÖÆÈÆ¹ýÎó²î£»£»£» £»£»Apple Safari WEBKIT CVE-2018-4101ÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î£»£»£» £»£»Cisco IOS XE Software¶à¸öÏÂÁî×¢ÈëÎó²î£»£»£» £»£»Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£» £»£»D-Link DSL-3782×°±¸'set Diagnostics_Entry'´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£ ¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬Ô¼500ÍòÕÅÐÅÓÿ¨ÐÅÏ¢±»µÁ£»£»£» £»£»Panera BreadÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ï죻£»£» £»£»Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ£»£»£» £»£»·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼13ÍòÓû§µÄƾ֤й¶£»£»£» £»£»Ñо¿ÍŶÓÅû¶NatusÒ½ÁÆ×°±¸ÖеĶà¸öÑÏÖØÇå¾²Îó²î¡£¡£¡£¡£ ¡£¡£¡£¡£

        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£ ¡£¡£¡£¡£


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Apple macOSÇå¾²ÏÞÖÆÈÆ¹ýÎó²î

        Apple MacOS "CoreTypes"×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆÖ´ÐÐδÊÚȨ²Ù×÷¡£¡£¡£¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://support.apple.com/en-ie/HT208692
2¡¢Apple Safari WEBKIT CVE-2018-4101ÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î

        Apple Safari WEBKIT×é¼þ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£» £»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://support.apple.com/en-ie/HT208695
3¡¢Cisco IOS XE Software¶à¸öÏÂÁî×¢ÈëÎó²î

        Cisco IOS XE SoftwareµÄCLIÆÊÎöÆ÷ÔÚʵÏÖÉϱ£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÍâµØµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔrootȨÏÞÖ´ÐÐÏÂÁî¡£¡£¡£¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-cmdinj
4¡¢Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´ÐÐÎó²î

        Schneider Electric Modicon PLC FTPЧÀÍÆ÷δÏÞÖÆÏÂÁî²ÎÊý³¤¶È£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¾ÙÐоܾøÐ§À͹¥»÷»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/
5¡¢D-Link DSL-3782×°±¸'set Diagnostics_Entry'´úÂëÖ´ÐÐÎó²î

        D-Link DSL-3782 'set Diagnostics_Entry'´¦Öóͷ£ÊäÈëÖµ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://github.com/SECFORCE/CVE-2018-8941


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬Ô¼500ÍòÕÅÐÅÓÿ¨ÐÅÏ¢±»µÁ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        Hudson's Bay CompanyÔÚÖÜÈÕÈ·ÈϳÆ£¬£¬£¬£¬£¬£¬£¬£¬Æä±±ÃÀµØÇøµÄ×Ó¹«Ë¾Saks Fifth Avenue¡¢Saks Off 5THÒÔ¼°Lord£¦TaylorµÄ²¿·ÖÓû§µÄÐÅÓÿ¨ÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁË´Ó2017Äê5Ôµ½2018Äê3ÔÂÔÚ±±ÃÀÊÐËÁ¾ÙÐйýÖ§¸¶µÄÔ¼500ÍòÕÅÐÅÓÿ¨¡£¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚÐÅÓÿ¨ÐÅÏ¢ÊÇΨһй¶µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Saks Fifth AvenueÔÚÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ã»Óм£ÏóÅú×¢Éç»á°ü¹ÜºÅÂë»òÉç»á°ü¹ÜºÅÂë¡¢¼ÝÕÕºÅÂë»òÃÜÂëÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£¡£¡£Çå¾²³§ÉÌGemini Advisory³Æ¸ÃÊÂÎñÓëºÚ¿ÍÍÅ»ïJokerStash£¨Ò²±»³ÆÎªFIN7£©Óйء£¡£¡£¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/credit-card-data-swiped-from-5m-saks-lord-taylor-customers/130877/

2¡¢Panera BreadÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        Çå¾²Ñо¿Ô±Brian Krebs±¨¸æ³ÆÃæ°üÁ¬ËøµêPanera BreadµÄÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍòÓû§µÄ¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¼ÒÍ¥µØµã¡¢ÉúÈÕºÍÐÅÓÿ¨ºÅÂëµÄ×îºóËÄλÊý×Ö¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÊý¾ÝÖ±µ½ÖÜÒ»»¹¿ÉÒÔÔÚPanerabread.comÉÏÒÔ´¿Îı¾µÄÐÎʽ»á¼û¡£¡£¡£¡£ ¡£¡£¡£¡£Çå¾²Ñо¿Ô±Dylan Houlihan×î³õÓÚ2017Äê8ÔÂÏòPanera±¨¸æÁ˸Ãй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾²¢Ã»ÓнÓÄÉÐж¯À´½â¾öÎÊÌâ¡£¡£¡£¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2018/04/panerabread-com-breach-could-have-impacted-millions/

3¡¢Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        FlashpointÑо¿Ö°Ô±·¢Ã÷ÖÁÉÙ1000¸öMagentoÖÎÀíÃæ°å±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý±©Á¦¹¥»÷»ñµÃ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÓÿ¨ºÅÂëºÍ×°ÖöñÒâÈí¼þ£¨Êý¾ÝÇÔÈ¡Èí¼þAZORultºÍ¶ñÒâ¿ó¹¤Rarog£©¡£¡£¡£¡£ ¡£¡£¡£¡£Flashpoint³Æ´ó´ó¶¼ÍøÕ¾ÊôÓÚ½ÌÓýºÍÒ½ÁƱ£½¡ÐÐÒµ£¬£¬£¬£¬£¬£¬£¬£¬IPµØµãÖ÷ÒªÂþÑÜÔÚÃÀ¹úºÍÅ·ÖÞ¡£¡£¡£¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.flashpoint-intel.com/blog/compromised-magento-sites-delivering-malware/

4¡¢·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼13ÍòÓû§µÄƾ֤й¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        ¾ÝÍâµØÃ½Ì屨µÀ£¬£¬£¬£¬£¬£¬£¬£¬·ÒÀ¼Ê·ÉϵÚÈý´óÊý¾Ýй¶ÊÂÎñµ¼ÖÂÁè¼Ý13ÍòÃû·ÒÀ¼¹«ÃñµÄƾ֤й¶¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÈëÇÖÁËHelsingin Uusyrityskeskus¹«Ë¾µÄÍøÕ¾£¨http://liiketoimintasuunnitelma.com£©£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÁËÁè¼Ý13ÍòÓû§µÄÃ÷ÎĵǼÃûºÍÃÜÂë¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÓû§ÃûºÍÃÜÂëÒÔ´¿Îı¾µÄÐÎʽ´æ´¢ÔÚ¸ÃÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ã»ÓÐʹÓÃÈκιþÏ£¼ÓÃÜ¡£¡£¡£¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/04/helsingin-uusyrityskeskus-hack.html

5¡¢Ñо¿ÍŶÓÅû¶NatusÒ½ÁÆ×°±¸ÖеĶà¸öÑÏÖØÇå¾²Îó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        ˼¿ÆTalosÑо¿ÍŶÓÔÚNatus NeuroWorksÈí¼þÖз¢Ã÷¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬NatusµÄÒ½ÁƲúÆ·Xltek EEGÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£¡£¡£Îó²î¹æÄ£°üÀ¨4¸öµ¼Ö´úÂëÖ´ÐеÄÎó²îºÍ1¸öµ¼Ö¾ܾøÐ§À͵ÄÎó²î¡£¡£¡£¡£ ¡£¡£¡£¡£NatusÔÚNeuroworks 8.5 GMA2ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéʹÓÃÕâЩװ±¸µÄÒ½ÁÆ»ú¹¹¾¡¿ì¾ÙÐиüС£¡£¡£¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttp://blog.talosintelligence.com/2018/04/vulnerability-spotlight-natus.html