ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ23ÖÜ

Ðû²¼Ê±¼ä 2018-06-11

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
        2018Äê06ÔÂ04ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö £¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAndroid NVIDIA TLK TrustZoneÍâµØÈ¨ÏÞÌáÉýÎó²î£»£»£»£» £»Cisco Prime Collaboration ProvisioningÃÜÂëÖØÖÃÎó²î£»£»£»£» £»Apple iOS WebKit CVE-2018-4204ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»£»£»£» £»ISC BIND CVE-2018-5737Ô¶³Ì¾Ü¾øÐ§ÀÍÎó²î£»£»£»£» £»Adobe AcrobatºÍReaderÊͷźóʹÓÃí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿Ö°Ô±·¢Ã÷½©Ê¬ÍøÂçVPNFilter¾íÍÁÖØÀ´ £¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼£»£»£»£» £»Êýǧ¸ö¹«Ë¾ÒòGoogle GroupsÉèÖùýʧ¶øÐ¹Â¶Ãô¸ÐÊý¾Ý£»£»£»£» £»Ó¢¹úTSBÒøÐз¢Ë͸øÓû§µÄÓʼþÖÐй¶Óû§µÄÃô¸ÐÐÅÏ¢£»£»£»£» £»Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý11.5Íò¸öDrupalÍøÕ¾ÈÔÈ»Ò×ÊÜDrupalgeddon2¹¥»÷£»£»£»£» £»ÒÔÉ«ÁÐDNA¼ì²â¹«Ë¾MyHeritageÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý9200ÍòÓû§ÐÅϢй¶¡£¡£¡£

        ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Android NVIDIA TLK TrustZoneÍâµØÈ¨ÏÞÌáÉýÎó²î

        Android NVIDIA TLK TrustZone±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://source.android.com/security/bulletin/2018-06-01
2¡¢Cisco Prime Collaboration ProvisioningÃÜÂëÖØÖÃÎó²î

        Cisco Prime Collaboration ProvisioningÃÜÂëÖØÖù¦Ð§±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬ÖØÖÃÖÎÀíÔ±ÃÜÂë £¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-password-reset
3¡¢Apple iOS WebKit CVE-2018-4204ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î

        Apple iOS WebKit±£´æÄÚ´æÆÆËðÎó²î £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ £¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£» £»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://lists.apple.com/archives/security-announce/2018/Apr/msg00000.html
4¡¢ISC BIND CVE-2018-5737Ô¶³Ì¾Ü¾øÐ§ÀÍÎó²î

        ISC BIND rbtdb.c±£´æ¶ÏÑÔʧ°ÜÎó²î £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÏµÍ³Í߽⡣¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://kb.isc.org/article/AA-01606/0/CVE-2018-5737%3A-BIND-9.12s-serve-stale-implementation-can-cause-an-assertion-failure-in-rbtdb.c-or-other-undesirable-behavior-even-if-serve-stale-is-not-enabled.
5¡¢Adobe AcrobatºÍReaderÊͷźóʹÓÃí§Òâ´úÂëÖ´ÐÐÎó²î

        Adobe AcrobatºÍReader´¦Öóͷ£PDFÎļþ±£´æÊͷźóʹÓÃÎó²î £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ £¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-09.html


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ñо¿Ö°Ô±·¢Ã÷½©Ê¬ÍøÂçVPNFilter¾íÍÁÖØÀ´ £¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        À´×ÔJASKºÍGreyNoise IntelligenceµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷½©Ê¬ÍøÂçVPNFilterÕý¾íÍÁÖØÀ´¡£¡£¡£VPNFilterÔÚÉÏÖܱ»FBI´Ý»Ù £¬£¬£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷¸Ã½©Ê¬ÍøÂçÕýÊÔͼѬȾеķÓÉÆ÷¡£¡£¡£ÕâÖÖѬȾ»î¶¯Ö»Õë¶ÔÎÚ¿ËÀ¼ £¬£¬£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÒÔΪVPNFilter±³ºóµÄ×éÖ¯ÊǶíÂÞË¹ÍøÂçÌØ¹¤×éÖ¯APT28¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/the-vpnfilter-botnet-is-attempting-a-comeback/

2¡¢Êýǧ¸ö¹«Ë¾ÒòGoogle GroupsÉèÖùýʧ¶øÐ¹Â¶Ãô¸ÐÊý¾Ý

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        Kenna SecurityµÄÇå¾²Ñо¿Ö°Ô±³ÆÊýÒÔǧ¼ÆµÄ¹«Ë¾ÒòGoogle GroupsµÄ¹ýʧÉèÖõ¼ÖÂÃô¸ÐÊý¾Ýй¶ £¬£¬£¬£¬£¬£¬£¬£¬ÔÚ9600¸öÆÊÎö¹¤¾ßÖÐ £¬£¬£¬£¬£¬£¬£¬£¬ÓÐ31%µÄ¹«Ë¾µÄÃô¸Ðµç×ÓÓʼþÐÅϢй¶¡£¡£¡£ÊÜÓ°ÏìµÄ¹¤¾ß°üÀ¨²Æ²ú500Ç¿¹«Ë¾¡¢Ò½Ôº¡¢´óѧ¡¢±¨Ö½ºÍµçÊǪ́ £¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÉÐÓÐÃÀ¹úÕþ¸®»ú¹¹¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73176/security/google-groups-data-leak.html

3¡¢Ó¢¹úTSBÒøÐз¢Ë͸øÓû§µÄÓʼþÖÐй¶Óû§µÄÃô¸ÐÐÅÏ¢

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        Ó¢¹úTSBÒøÐÐÔÚ·¢Ë͸øÓû§µÄÓʼþÖÐй¶ÁËÆäËûÓû§µÄÃô¸ÐÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÎ¥·´ÁËGDPR¡£¡£¡£ÕâЩÓʼþÔ­±¾ÊÇΪÏàʶÊÍÆä×î½üµÄITÎÊÌâ £¬£¬£¬£¬£¬£¬£¬£¬µ«ÓʼþÖаüÀ¨ÁËÆäËûÓû§µÄÏà¹ØºÅÂë¡¢ÐÕÃûºÍµØµã¡£¡£¡£TSB½²»°ÈËÈϿɸùýʧй¶ÁËÓû§µÄÒþ˽ £¬£¬£¬£¬£¬£¬£¬£¬²¢³ÆÕýÓëµÚÈý·½¹©Ó¦ÉÌÏàÖúÒÔÏàʶÎÊÌⱬ·¢µÄ»ù´¡Ôµ¹ÊÔ­ÓÉ¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/tsb-privacy-snafu-letters-sent/

4¡¢Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý11.5Íò¸öDrupalÍøÕ¾ÈÔÈ»Ò×ÊÜDrupalgeddon2¹¥»÷

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        Çå¾²Ñо¿Ô±Troy MurschɨÃèÁËÔ¼50Íò¸öÔËÐÐÔÚDrupal 7ÉϵÄÍøÕ¾ £¬£¬£¬£¬£¬£¬£¬£¬¹²·¢Ã÷Áè¼Ý11.5Íò¸öÍøÕ¾ÈÔÈ»Ò×ÊÜDrupalgeddon2¹¥»÷¡£¡£¡£ÆäÖбÈÀûʱ¾¯Ê𡢿ÆÂÞÀ­¶àÖÝ×ÜÉó²é³¤°ì¹«ÊҺͷÆÑÇÌØ×Ó¹«Ë¾Magneti MarelliµÈÊý°Ù¸öÍøÕ¾ÒѾ­³ÉΪеĶñÒâÍÚ¿ó»î¶¯µÄÄ¿µÄ¡£¡£¡£Drupalgeddon2£¨CVE-2018-7600£©ÊÇDrupal CMSÔÚ3ÔÂÎ²ÆØ³öµÄ¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î £¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐжñÒâ´úÂëºÍÍêÈ«½ÓÊÜÍøÕ¾¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/drupalgeddon2-exploit.html

5¡¢ÒÔÉ«ÁÐDNA¼ì²â¹«Ë¾MyHeritageÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý9200ÍòÓû§ÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

        ÒÔÉ«ÁÐDNA¼ì²â¹«Ë¾MyHeritage³Æ¸Ã¹«Ë¾ÓÚÈ¥ÄêÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬£¬£¬Ô¼9230ÍòÓû§µÄµç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂëй¶¡£¡£¡£ÊÜÓ°ÏìµÄÓû§ÊÇ2017Äê10ÔÂ27ÈÕ֮ǰע²áMyHeritageÍøÕ¾µÄÓû§¡£¡£¡£¸Ã¹«Ë¾Ö¸³öÓÉÓÚÓû§µÄÐÅÓÿ¨¡¢×åÆ×ºÍ»ùÒòÊý¾ÝµÈÐÅÏ¢´æ´¢ÔÚµ¥¶ÀµÄϵͳÖÐ £¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝûÓÐй¶¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬£¬£¬Óû§µÄÃÜÂëʹÓüÓÑιþÏ£¾ÙÐб£»£»£»£» £»¤ £¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÄÑÒÔ±»ÆÆ½â £¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾ÈÔÈ»½¨ÒéÓû§ÐÞ¸ÄÃÜÂë¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖ½«ÎªÓû§ÔöÌíË«ÒòËØÉí·ÝÑéÖ¤¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/myheritage-data-breach.html