¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181217

Ðû²¼Ê±¼ä 2018-12-17
1¡¢ÃÀDoD³ÆÆäµ¯µÀµ¼µ¯·ÀÓùϵͳδͨ¹ýÍøÂçÇå¾²Éó¼Æ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤ÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬ÃÀ¹úµÄµ¯µÀµ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂçÇå¾²É󼯡£¡£¡£¡£¸Ã±¨¸æÖ¸³öBMDSÉèʩδÄÜʵÑéÓ¦ÓеÄÇå¾²¿ØÖƲ½·¥£¬£¬£¬£¬°üÀ¨¶àÒòËØÉí·ÝÈÏÖ¤¡¢Îó²îÆÀ¹À»ººÍ½â¡¢Ð§ÀÍÆ÷»ú¼ÜÇå¾²¡¢¿ÉÒÆ¶¯Ã½ÌåÉϵÄÉñÃØÊý¾Ý±£»£» £»£»£»¤ºÍÊÖÒÕÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Ò»Ð©ÎïÀíÇå¾²²½·¥Ò²Ã»Óе½Î»£¬£¬£¬£¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»ÓÐ×°ÖÃÔÚÐèҪװÖõÄλÖᣡ£¡£¡£¼à²ì³¤°ì¹«ÊÒÕýÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕǰ»ØÓ¦¸Ã·Ý±¨¸æ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF


2¡¢¿¨°Í˹»ùб¨¸æÅû¶µç¶¯Æû³µ³äµçÕ¾ÖеÄÇ徲Σº¦

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



ƾ֤¿¨°Í˹»ùʵÑéÊÒµÄÒ»·Ý±¨¸æ£¬£¬£¬£¬ChargePoint¹«Ë¾ÖÆÔìµÄ¼ÒÓõ綯Æû³µ³äµçÕ¾±£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßµ÷½â³äµçµçÁ÷ÒÔ¼°ËæÊ±×èÖ¹Æû³µµÄ³äµçÀú³Ì£¬£¬£¬£¬´Ó¶øµ¼ÖÂDZÔÚµÄÎïÀíË𻵺;­¼ÃËðʧ¡£¡£¡£¡£¸Ã¼ÒÓóäµçÕ¾Ö§³ÖWiFiºÍÀ¶ÑÀÎÞÏßÊÖÒÕ£¬£¬£¬£¬Óû§¿Éͨ¹ýiOS¼°Androidƽ̨µÄÒÆ¶¯appÔ¶³Ì¿ØÖƳäµçÀú³Ì¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸µÄWebЧÀÍÆ÷±£´æÖ¤ÊéÇå¾²ÎÊÌâ¡¢»º³åÇøÒç³öµÈÎó²î¡£¡£¡£¡£ÏÖÔڸù«Ë¾ÒÑÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/12/13084354/ChargePoint-Home-security-research_final.pdf


3¡¢TwitterÐû²¼Í¸Ã÷¶È±¨¸æ£¬£¬£¬£¬³ÆÆäÿÔÂÊÕµ½50ÍòÀ¬»øÓʼþ±¨¸æ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤TwitterµÄ2018ÄêÉϰëÄê͸Ã÷¶È±¨¸æ£¬£¬£¬£¬ÆäÿÔÂÊÕµ½µÄÀ¬»øÓʼþ±¨¸æÊýĿһÁ¬Ï½µ£¬£¬£¬£¬´Ó1ÔÂ·ÝµÄÆ½¾ùÔ¼868349·Ý±¨¸æÏ½µµ½6Ô·ݵÄÔ¼504259·Ý¡£¡£¡£¡£¸Ã±¨¸æ»¹Ç¿µ÷ÁËÕþ¸®¶ÔÓû§Êý¾ÝµÄÅû¶ÇëÇó´ó·ùÉÏÉý¡£¡£¡£¡£½ñÄê1ÔÂÖÁ6Ô£¬£¬£¬£¬TwitterÊÕµ½µÄÕþ¸®ÇëÇó±ÈÉϸö±¨¸æÆÚÔöÌíÁË10%£¬£¬£¬£¬ÕâÊÇÈýÄêÀ´×î´óµÄÔöÌí¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬1ÔÂÖÁ6ÔÂÁè¼Ý205100¸öÕË»§ÒòÐû²¼¿Ö²ÀÖ÷ÒåÄÚÈݶø±»É¾³ý£¬£¬£¬£¬Óë2017ÄêϰëÄêµÄÊý×Ö£¨120Íò£©Ïà±È´ó·ùϽµ¡£¡£¡£¡£1ÔÂÖÁ6ÔÂʱ´úÉÐÓÐÁè¼Ý487300¸öÕË»§Òò¶ùͯÐÔ¾ÛÁ²ÎÊÌâ¶ø±»·â½û¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://transparency.twitter.com/


4¡¢APT28ʹÓÃZebrocyºóÃźÍCannonľÂí¹¥»÷¶à¸öÕþ¸®»ú¹¹

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Palo Alto NetworksµÄUnit42ÍŶÓÐû²¼¹ØÓÚAPT28½üÆÚÕë¶ÔÕþ¸®»ú¹¹µÄ¶ñÒâ»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£2018Äê10ÔÂÖÐÑ®µ½2018Äê11ÔÂÖÐѮʱ´ú£¬£¬£¬£¬APT28Ò»Á¬Ï®»÷ÁËÌìϸ÷µØµÄ¶à¸öÕþ¸®»ú¹¹£¬£¬£¬£¬Ö÷ҪĿµÄÊDZ±Ô¼¹ú¼Ò£¬£¬£¬£¬µ«Ò²°üÀ¨¼¸¸öǰËÕÁª¹ú¼Ò¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯Ö÷Òª°²ÅÅÁËZebrocy»òCannon±äÖÖ£¬£¬£¬£¬Æä½»¸¶µÄ¶ñÒâÎĵµÊ¹ÓÃÁËͳһ¸ö×÷ÕßÃû³Æ£ºJoohn¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöÁËÍøÂçµ½µÄ9¸ö¶ñÒâÎĵµ£¬£¬£¬£¬²¢½¨ÉèÁËDear Joohn»î¶¯µÄʱ¼äÏß¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/dear-joohn-sofacy-groups-global-campaign/


5¡¢Ð¶ñÒâÈí¼þCapitalInstall£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


NetskopeÍþвÑо¿ÊµÑéÊÒ·¢Ã÷Ò»¸öеĶñÒâÈí¼þCapitalInstall¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýMicrosoft Azure·Ö·¢£¬£¬£¬£¬ÕâʹµÃÆäIPµØµã±»Ðí¶à¹«Ë¾¼ÓÈë°×Ãûµ¥¡£¡£¡£¡£CapitalInstallαװ³ÉÊ¢ÐÐÈí¼þ£¨ÀýÈçAdobe CC 2019£©µÄÃâ·ÑÃÜÔ¿ºÍÔÊÐíÖ¤£¬£¬£¬£¬ÓÕÆ­Óû§¾ÙÐÐÏÂÔØ£¬£¬£¬£¬²¢À¦°óÁË¹ã¸æÈí¼þLinkury£¬£¬£¬£¬½ø¶øÔÚÓû§µÄÅÌËã»úÉÏÏÂÔØ¸ü¶àDZÔÚÓк¦µÄ³ÌÐò¡£¡£¡£¡£CapitalInstallÖ÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.netskope.com/blog/capitalinstall-hosted-and-served-via-iaas


6¡¢Î÷ÃÅ×ÓÐÞ¸´SINUMERIK¿ØÖÆÆ÷ÖеĶà¸öÇå¾²Îó²î

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Î÷ÃÅ×ÓÐÞ¸´ÁËSINUMERIK¿ØÖÆÆ÷ÖеÄ10¸öÇå¾²Îó²î¡£¡£¡£¡£ÆäÖÐÎó²î£¨CVE-2018-11466£©ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòTCP¶Ë¿Ú102·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢DoS»òÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬¸ÃÎó²îµÄʹÓò¢²»ÐèÒªÈκÎÓû§½»»¥¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Îó²î£¨CVE-2018-11457ºÍCVE-2018-11458£©ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËͶñÒâTCPÊý¾Ý°üÀ´¾ÙÐÐÌáȨ¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£Î÷ÃÅ×Ó×î½üÐû²¼½«Ïñ΢Èí¡¢AdobeºÍSAPÒ»ÑùÔÚÿ¸öÔµĵڶþ¸öÐÇÆÚ¶þÐû²¼Ç徲ͨ¸æ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://cert-portal.siemens.com/productcert/pdf/ssa-170881.pdf


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí