ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ14ÖÜ

Ðû²¼Ê±¼ä 2018-04-09

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ02ÈÕÖÁ06ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´68¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOSÄþ¾²ÏÞÖÆÈÆ¹ý©¶´ £»Apple Safari WEBKIT CVE-2018-4101ÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´ £»Cisco IOS XE Software¶à¸öÃüÁî×¢Èë©¶´ £»Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´ÐЩ¶´ £»D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´ÐЩ¶´¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬Ô¼500ÍòÕÅÐÅÓÿ¨ÐÅÏ¢±»µÁ £»Panera BreadÓû§Êý¾Ýй¶£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì £»Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ £»·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼13ÍòÓû§µÄƾ¾Ýй¶ £»Ñо¿ÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑÏÖØÄþ¾²Â©¶´¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Apple macOSÄþ¾²ÏÞÖÆÈÆ¹ý©¶´

        Apple MacOS "CoreTypes"×é¼þ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉÈÆ¹ýÄþ¾²ÏÞÖÆÖ´ÐÐδÊÚȨ²Ù×÷¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://support.apple.com/en-ie/HT208692
2¡¢Apple Safari WEBKIT CVE-2018-4101ÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´

        Apple Safari WEBKIT×é¼þ´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://support.apple.com/en-ie/HT208695
3¡¢Cisco IOS XE Software¶à¸öÃüÁî×¢Èë©¶´

        Cisco IOS XE SoftwareµÄCLI½âÎöÆ÷ÔÚʵÏÖÉÏ´æÔÚÊäÈëÑé֤©¶´£¬µ±µØµØ¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔrootȨÏÞÖ´ÐÐÃüÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-cmdinj
4¡¢Schneider Electric Modicon Quantum CVE-2018-7240Ô¶³Ì´úÂëÖ´ÐЩ¶´

        Schneider Electric Modicon PLC FTP·þÎñÆ÷δÏÞÖÆÃüÁî²ÎÊý³¤¶È£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬽øÐоܾø·þÎñ¹¥»÷»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/
5¡¢D-Link DSL-3782É豸'set Diagnostics_Entry'´úÂëÖ´ÐЩ¶´

        D-Link DSL-3782 'set Diagnostics_Entry'´¦ÖÃÊäÈëÖµ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://github.com/SECFORCE/CVE-2018-8941


Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢ÉÝ³ÞÆ·ÏúÊÛ¹«Ë¾SaksºÍLord£¦TaylorÓû§Êý¾Ýй¶£¬Ô¼500ÍòÕÅÐÅÓÿ¨ÐÅÏ¢±»µÁ

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        Hudson's Bay CompanyÔÚÖÜÈÕÈ·ÈϳÆ£¬Æä±±ÃÀµØÓòµÄ×Ó¹«Ë¾Saks Fifth Avenue¡¢Saks Off 5THÒÔ¼°Lord£¦TaylorµÄ²¿ÃÅÓû§µÄÐÅÓÿ¨ÐÅϢй¶£¬¸ÃʼþÓ°ÏìÁË´Ó2017Äê5Ôµ½2018Äê3ÔÂÔÚ±±ÃÀÉÌµê½øÐйýÖ§¸¶µÄÔ¼500ÍòÕÅÐÅÓÿ¨¡£Ä¿Ç°ÐÅÓÿ¨ÐÅÏ¢ÊÇΨһй¶µÄÊý¾Ý£¬Saks Fifth AvenueÔÚÉùÃ÷ÖÐÌåÏÖ£¬Ã»Óм£Ïó±íÃ÷Éç»á±£ÕϺÅÂë»òÉç»á±£ÏÕºÅÂë¡¢¼ÝÕÕºÅÂë»òÃÜÂëÊܵ½Ó°Ïì¡£Äþ¾²³§ÉÌGemini Advisory³Æ¸ÃʼþÓëºÚ¿ÍÍÅ»ïJokerStash£¨Ò²±»³ÆÎªFIN7£©ÓйØ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/credit-card-data-swiped-from-5m-saks-lord-taylor-customers/130877/

2¡¢Panera BreadÓû§Êý¾Ýй¶£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        Äþ¾²Ñо¿Ô±Brian Krebs³ÂËß³ÆÃæ°üÁ¬ËøµêPanera BreadµÄÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍòÓû§µÄ¼Ç¼£¬°üÂÞÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢ÉúÈÕºÍÐÅÓÿ¨ºÅÂëµÄ×îºóËÄλÊý×Ö¡£ÕâЩÊý¾ÝÖ±µ½ÖÜÒ»»¹¿ÉÒÔÔÚPanerabread.comÉÏÒÔ´¿Îı¾µÄÐÎʽ·ÃÎÊ¡£Äþ¾²Ñо¿Ô±Dylan Houlihan×î³õÓÚ2017Äê8ÔÂÏòPanera³ÂËßÁ˸Ãй¶Ê¼þ£¬µ«¸Ã¹«Ë¾²¢Ã»ÓнÓÄÉÐж¯À´½â¾öÎÊÌâ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/cybercrime/2018/04/panerabread-com-breach-could-have-impacted-millions/

3¡¢Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý1000¸öMagentoÍøÕ¾Ôâµ½ºÚ¿ÍÈëÇÖ

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        FlashpointÑо¿ÈËÔ±·¢ÏÖÖÁÉÙ1000¸öMagento¹ÜÀíÃæ°å±»ºÚ¿ÍÈëÇÖ£¬¹¥»÷Õßͨ¹ý±©Á¦¹¥»÷»ñµÃ·ÃÎÊȨÏÞ£¬ÒÔÇÔÈ¡ÐÅÓÿ¨ºÅÂëºÍ°²×°¶ñÒâÈí¼þ£¨Êý¾ÝÇÔÈ¡Èí¼þAZORultºÍ¶ñÒâ¿ó¹¤Rarog£©¡£Flashpoint³Æ´ó¶àÊýÍøÕ¾ÊôÓÚ½ÌÓýºÍÒ½ÁƱ£½¡ÐÐÒµ£¬IPµØÖ·Ö÷ÒªÂþÑÜÔÚÃÀ¹úºÍÅ·ÖÞ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.flashpoint-intel.com/blog/compromised-magento-sites-delivering-malware/

4¡¢·ÒÀ¼Helsingin Uusyrityskeskus¹«Ë¾ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼13ÍòÓû§µÄƾ¾Ýй¶

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        ¾Ýµ±µØÃ½Ì屨µÀ£¬·ÒÀ¼Ê·ÉϵÚÈý´óÊý¾Ýй¶Ê¼þµ¼ÖÂÁè¼Ý13ÍòÃû·ÒÀ¼¹«ÃñµÄƾ¾Ýй¶¡£¹¥»÷ÕßÈëÇÖÁËHelsingin Uusyrityskeskus¹«Ë¾µÄÍøÕ¾£¨http://liiketoimintasuunnitelma.com£©£¬ÇÔÈ¡ÁËÁè¼Ý13ÍòÓû§µÄÃ÷ÎĵǼÃûºÍÃÜÂë¡£ÕâЩÓû§ÃûºÍÃÜÂëÒÔ´¿Îı¾µÄÐÎʽ´æ´¢ÔÚ¸ÃÍøÕ¾ÉÏ£¬²¢Ã»ÓÐʹÓÃÈκιþÏ£¼ÓÃÜ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/04/helsingin-uusyrityskeskus-hack.html

5¡¢Ñо¿ÍŶÓÅû¶NatusÒ½ÁÆÉ豸ÖеĶà¸öÑÏÖØÄþ¾²Â©¶´

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        ˼¿ÆTalosÑо¿ÍŶÓÔÚNatus NeuroWorksÈí¼þÖз¢ÏÖ¶à¸öÄþ¾²Â©¶´£¬NatusµÄÒ½ÁƲúÎïXltek EEGÊܵ½Ó°Ï졣©¶´·¶Î§°üÂÞ4¸öµ¼Ö´úÂëÖ´ÐеÄ©¶´ºÍ1¸öµ¼Ö¾ܾø·þÎñµÄ©¶´¡£NatusÔÚNeuroworks 8.5 GMA2ÖÐÐÞ¸´ÁËÕâЩ©¶´£¬½¨ÒéʹÓÃÕâЩÉ豸µÄÒ½ÁÆ»ú¹¹¾¡¿ì½øÐиüС£

        Ô­ÎÄÁ´½Ó£ºhttp://blog.talosintelligence.com/2018/04/vulnerability-spotlight-natus.html