ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ34ÖÜ
Ðû²¼Ê±¼ä 2018-08-27Ò»¡¢±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷Ô˶¯£»Ñо¿Åú×¢GDPRʵÑéºóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýĿϽµÁË22%£»ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶£»±£Ä··þÎñSitterÒòMongoDBÉèÖùýʧµ¼ÖÂÁè¼Ý9.3ÍòÓû§µÄÐÅϢй¶£»Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
Apache Struts½ç˵XMLÉèÖÃnamespaceֵΪͨÅä·û(¡°/*¡±)£¬»òÔÚÉϲãactionÖÐnamespaceֵȱʡʱ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://cwiki.apache.org/confluence/display/WW/S2-057
2¡¢Adobe Photoshop CC CVE-2018-12811ÄÚ´æÆÆËðÎó²î
Adobe Photoshop CC´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/photoshop/apsb18-28.html
Philips IntelliSpace CardiovascularûÓоÙÐÐ׼ȷµÄȨÏÞÖÎÀí£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÌáÉýȨÏÞ¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01
4¡¢SambaĿ¼ÁÐ±í³¤Îļþ¼ì²é´úÂëÖ´ÐÐÎó²î
samba¿Í»§¶ËûÓгä·ÖµÄ¼ì²âĿ¼ÁбíÖйý³¤µÄÎļþÃû£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ¶ñÒâSAMBA·þÎñÆ÷ÇëÇó£¬Ö´ÐÐí§Òâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.samba.org/samba/security/CVE-2018-10858.html
Emerson Electric DeltaV±£´æ»ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Ö´ÐÐí§Òâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01
Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷Ô˶¯

Ç÷ÊƿƼ¼µÄÇå¾²Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚʹÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕÎó²î£¨CVE-2018-8373£©Ìᳫ¹¥»÷Ô˶¯£¬¸ÃÎó²îÊÇÒ»¸öuse-after-freeÎó²î£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÅÌËã»úÉÏÔËÐÐshellcode¡£ÔÚ×îа汾µÄWindowsÖУ¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÉèÖÃÖнûÓÃÁËVBScript£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£Î¢ÈíÒÑÔÚ8ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË´ËÎó²î¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/
2¡¢Ñо¿Åú×¢GDPRʵÑéºóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýĿϽµÁË22%

ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/technology/number-of-third-party-cookies-on-eu-news-sites-dropped-by-22-percent-post-gdpr/
3¡¢ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶

ÃÀ¹úAugustaÒ½ÁÆÖÐÐÄ7ÔÂ31ÈÕµÄÊÓ²ìЧ¹ûÏÔʾ£¬2017Äê9ÔÂÕë¶ÔÆäÒ½ÁÆÊÂÇéÖ°Ô±µÄÍøÂç´¹ÂÚ¹¥»÷µ¼ÖÂÔ¼41.7Íò»¼ÕßµÄÊý¾Ý±»ÇÔ¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨µØµã¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅ¡¢ÖÎÁƺÍÊÖÊõÐÅÏ¢¡¢Õï¶ÏЧ¹û¡¢Ò©ÎïÒÔ¼°°ü¹ÜÐÅÏ¢µÈ£¬ÉõÖÁ°üÀ¨²¿·Ö»¼ÕßµÄÉç±£ºÅÂëºÍ¼ÝÕÕºÅÂë¡£ÕâЩÐÅÏ¢¿ÉÄܻᱻºóÐøµÄÍøÂç´¹ÂÚ¹¥»÷¡¢Éí·ÝÚ²ÆÔ˶¯ÉõÖÁÀÕË÷Ô˶¯ËùʹÓá£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/augusta-health-center-reveals/
4¡¢±£Ä··þÎñSitterÒòMongoDBÉèÖùýʧµ¼ÖÂÁè¼Ý9.3ÍòÓû§µÄÐÅϢй¶
8ÔÂ14ÈÕÇå¾²Ñо¿Ö°Ô±Bob Diachenko·¢Ã÷±£Ä··þÎñSitterµÄÒ»¸öMongoDB¿Éͨ¹ý»¥ÁªÍø¹ûÕæ»á¼û£¨ÎÞÐèµÇ¼ƾ֤£©£¬Áè¼Ý9.3ÍòÃûÓû§µÄÃô¸ÐÊý¾Ýй¶¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÕË»§µÄÃÜÂë¹þÏ£¡¢Ã¿¸ö¼ÒÍ¥µÄº¢×ÓÊý¡¢¼ÒÍ¥µØµã¡¢µç»°ºÅÂë¡¢ÁªÏµÈËÁÐ±í¡¢Ö§¸¶¿¨ºÅÒÔ¼°appÄÚµÄ̸ÌìÐÅÏ¢µÈ¡£Êý¾Ý×ÜÁ¿Áè¼Ý2GB¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mongodb-server-exposes-babysitting-apps-database/
5¡¢Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶

Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª°îÕþ¸®µÄÖÒÑÔ£¬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£ÏÖÔÚÔÚ°µÍøÉÏÏúÊÛµÄÏà¹ØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£ÊÓ²ìÅú×¢£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕʱ´úÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ£¬ÕâÒâζ×ÅÄ¿½ñµÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼Óзֵ꣬¸Ã¹«Ë¾ÕýÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»¤·þÎñ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/