ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ19ÖÜ

Ðû²¼Ê±¼ä 2018-05-14

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ07ÈÕÖÁ13ÈÕÊÕ¼Äþ¾²Â©¶´58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Edge½Å±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æÆÆ»µÂ©¶´£»Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Adobe Flash PlayerÀàÐÍ»ìÏýÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Lantech IDS CVE-2018-8865ÈÎÒâ´úÂëÖ´ÐЩ¶´¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÅ·ÖÞÖÐÑëÒøÐÐÐû²¼TIBER-EU¿ò¼Ü£¬Ö¼ÔÚ×ÊÖú²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦£»Android P½«¶ÔÓ¦ÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞÖÆ£»Ñо¿ÈËÔ±·¢ÏÖpythonÄ£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬¿ÉÊÕ¼¯Óû§SSHƾ¾Ý£»ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ï죻Ñо¿ÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÏûÏ¢¿É±»»Ö¸´¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Microsoft Edge½Å±¾ÒýÇæCVE-2018-8128Ô¶³ÌÄÚ´æÆÆ»µÂ©¶´

        Microsoft Edge´¦ÖÃÄڴ湤¾ß´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8128
2¡¢Microsoft Exchange Server Outlook Web AccessÔ¶³Ì´úÂëÖ´ÐЩ¶´

        Microsoft Exchange Server Outlook Web Access (OWA)´¦ÖÃWEBÇëÇó´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8152
3¡¢Adobe Flash PlayerÀàÐÍ»ìÏýÔ¶³Ì´úÂëÖ´ÐЩ¶´

        Adobe Flash Player´¦ÖöñÒâÎļþ´æÔÚÀàÐÍ»ìÏý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´ÌØÊâµÄSWFÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-16.html
4¡¢Microsoft Office CVE-2018-8158Ô¶³Ì´úÂëÖ´ÐЩ¶´

        Microsoft Office´¦ÖÃÄڴ湤¾ß´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´¹¹½¨ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8158
5¡¢Lantech IDS CVE-2018-8865ÈÎÒâ´úÂëÖ´ÐЩ¶´

        Lantech IDS´æÔÚÕ»»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.lantechcom.tw/global/eng/IDS-2102A.html


Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Å·ÖÞÖÐÑëÒøÐÐÐû²¼TIBER-EU¿ò¼Ü£¬Ö¼ÔÚ×ÊÖú²âÊÔ½ðÈÚÐÐÒµµÄÍøÂç·ÀÓùÄÜÁ¦

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        Å·ÖÞÖÐÑëÒøÐУ¨ECB£©Ðû²¼»ùÓÚÍþвÇ鱨µÄTIBER-EU¿ò¼Ü£¬¸Ã¿ò¼ÜÊÇÊ׸ö·¶Î§ÎªÅ·ÖÞµÄÕë¶Ô½ðÈÚÊг¡µÄÊܿغͶ¨ÖÆÍøÂç¹¥»÷µÄ²âÊÔ¿ò¼Ü¡£ÕâÒ»¾Ù´ëÊǶԹýÈ¥¼¸ÄêÄÚÕë¶Ô½ðÈÚÐÐÒµµÄ¶àÆðÍøÂç¹¥»÷µÄ»ØÓ¦¡£¸Ã¿ò¼Ü°üÂÞÒ»¸öÄ£ÄâÕæÕýºÚ¿ÍµÄ¼ÆÄ±¡¢¼¼ÊõºÍ·¨Ê½µÄºì·½ÍŶÓ£¬À´¼ÓÈë½ðÈÚÐÐÒµÖеĹ«Ë¾ÏµÍ³µÄ©¶´ÆÀ¹ÀºÍÉøÍ¸²âÊÔ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72176/hacking/european-central-bank-framework-cyber.html

2¡¢Android P½«¶ÔÓ¦ÓÃ¼à¿ØÉè±¸ÍøÂç»î¶¯µÄÐÐΪ½øÐÐÏÞÖÆ

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        ƾ¾ÝAndroid¿ªÔ´ÏîÄ¿£¨AOSP£©ÖеÄ×îдúÂë¸ü¸Ä£¬XDA¿ª·¢ÈËÔ±·¢ÏÖÔÚÏÂÒ»´úAndroidϵͳAndroid PÖУ¬ÈκÎÓ¦Óö¼½«²»Äܼì²âÉè±¹ØÁ¬ÄÆäËüÓ¦ÓÃÊÇ·ñÔÚÁ¬½Ó»¥ÁªÍø¡£XDA¿ª·¢ÈËÔ±Ö¸³ö£¬AndroidÒýÈëµÄÕâÒ»ÐÂ±ä»¯ËÆºõºÜС£¬µ«¶ÔÓû§Òþ˽µÄÓ°Ï콫ÊǾ޴óµÄ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/android-p-network-activity.html

3¡¢Ñо¿ÈËÔ±·¢ÏÖpythonÄ£¿éssh-decorate±»Ö²ÈëºóÃÅ£¬¿ÉÊÕ¼¯Óû§SSHƾ¾Ý

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        PythonÄ£¿éSSH Decorator£¨ssh-decorate£©ÊÇÓÉÒÔÉ«Áпª·¢ÈËÔ±Uri Goren¿ª·¢µÄÒ»¸öÓÃÓÚ´¦ÖÃsshÁ¬½ÓµÄ¿â¡£Ñо¿ÈËÔ±·¢ÏÖssh-decorateµÄ¶à¸ö°æ±¾ÖаüÂÞÊÕ¼¯Óû§sshƾ¾ÝµÄ´úÂ룬×îºóÒ»¸öÄþ¾²µÄ°æ±¾Îª0.27£¬Ö®ºóµÄ0.28µ½0.31¶¼°üÂÞ¶ñÒâ´úÂë¡£Goren³ÆºóÃÅÊDZ»ºÚ¿ÍÖ²ÈëµÄ£¬Ä¿Ç°GorenÒÑÔÚgithubºÍPyPIÉÏɾ³ýÁ˸ÿâ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/

4¡¢ºÚ¿ÍÏ®»÷¸ç±¾¹þ¸ùÊеĹ«¹²×ÔÐгµÏµÍ³£¬Ô¼1860Á¾×ÔÐгµÊܵ½Ó°Ïì

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        ¸ç±¾¹þ¸ùÊеͼÊй«ÓÃ×ÔÐгµÏµÍ³BycyklenÔâºÚ¿ÍÈëÇÖ£¬Õû¸öÊý¾Ý¿â±»É¾³ý£¬µ¼ÖÂËùÓеÄÔ¼1860Á©¹«ÓÃ×ÔÐгµÎÞ·¨½âËø¡£¹¥»÷·¢ÉúÔÚ5ÔÂ4ÈÕÒ¹Íí¡£Bycyklen³Æ½â¾ö¸ÃÎÊÌâÐèÒª¶ÔËùÓеÄ×ÔÐгµ½øÐÐÊÖ¶¯¸üУ¬ÆäÔ±¹¤ÔÚÉÏÖÜÁùÒѻָ´ÁË200Á¾×ÔÐгµ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-shuts-down-copenhagen-s-public-city-bikes-system/

5¡¢Ñо¿ÈËÔ±·¢ÏÖmacOSÖеļÓÃÜͨѶAPP SignalµÄÒÑɾÏûÏ¢¿É±»»Ö¸´

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        Äþ¾²Ñо¿ÈËÔ±Alec Muffett·¢ÏÖmacOSÖж˵½¶Ë¼ÓÃÜͨѶAPP SignalµÄÒÑɾ³ýÏûÏ¢¿É±»»Ö¸´£¬ÕâʹµÃÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜй¶¡£ÆäÔ­ÒòÊÇmacOS»áÔÚ֪ͨÖÐÐĵÄÊý¾Ý¿âÖб¸·ÝÏûÏ¢ÄÚÈÝ£¨Í¨³£ÎªÍêÕûÏûÏ¢µÄǰ1-1.5ÐУ©£¬ÓÃÓÚÏòÓû§ÏÔʾÏûϢ֪ͨ¡£¼´Ê¹ÔÚSignalÖÐɾ³ýÁ˸ÃÏûÏ¢£¬ÕâЩ±»½ØÈ¡µÄÐÅÏ¢ÈÔ¿ÉÒÔͨ¹ý¸ÃÊý¾Ý¿â½øÐзÃÎÊ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/05/signal-secure-messaging.html