¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181217
Ðû²¼Ê±¼ä 2018-12-17
ƾ֤ÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬ÃÀ¹úµÄµ¯µÀµ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂçÇå¾²É󼯡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³öBMDSÉèʩδÄÜʵÑéÓ¦ÓеÄÇå¾²¿ØÖƲ½·¥£¬£¬£¬£¬£¬°üÀ¨¶àÒòËØÉí·ÝÈÏÖ¤¡¢Îó²îÆÀ¹À»ººÍ½â¡¢Ð§ÀÍÆ÷»ú¼ÜÇå¾²¡¢¿ÉÒÆ¶¯Ã½ÌåÉϵÄÉñÃØÊý¾Ý±£»£»£»£»£»£»¤ºÍÊÖÒÕÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ò»Ð©ÎïÀíÇå¾²²½·¥Ò²Ã»Óе½Î»£¬£¬£¬£¬£¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»ÓÐ×°ÖÃÔÚÐèҪװÖõÄλÖᣡ£¡£¡£¡£¡£¡£¼à²ì³¤°ì¹«ÊÒÕýÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕǰ»ØÓ¦¸Ã·Ý±¨¸æ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF2¡¢¿¨°Í˹»ùб¨¸æÅû¶µç¶¯Æû³µ³äµçÕ¾ÖеÄÇ徲Σº¦

ƾ֤¿¨°Í˹»ùʵÑéÊÒµÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬ChargePoint¹«Ë¾ÖÆÔìµÄ¼ÒÓõ綯Æû³µ³äµçÕ¾±£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßµ÷½â³äµçµçÁ÷ÒÔ¼°ËæÊ±×èÖ¹Æû³µµÄ³äµçÀú³Ì£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂDZÔÚµÄÎïÀíË𻵺;¼ÃËðʧ¡£¡£¡£¡£¡£¡£¡£¸Ã¼ÒÓóäµçÕ¾Ö§³ÖWiFiºÍÀ¶ÑÀÎÞÏßÊÖÒÕ£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýiOS¼°Androidƽ̨µÄÒÆ¶¯appÔ¶³Ì¿ØÖƳäµçÀú³Ì¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸µÄWebЧÀÍÆ÷±£´æÖ¤ÊéÇå¾²ÎÊÌâ¡¢»º³åÇøÒç³öµÈÎó²î¡£¡£¡£¡£¡£¡£¡£ÏÖÔڸù«Ë¾ÒÑÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/12/13084354/ChargePoint-Home-security-research_final.pdf3¡¢TwitterÐû²¼Í¸Ã÷¶È±¨¸æ£¬£¬£¬£¬£¬³ÆÆäÿÔÂÊÕµ½50ÍòÀ¬»øÓʼþ±¨¸æ

ƾ֤TwitterµÄ2018ÄêÉϰëÄê͸Ã÷¶È±¨¸æ£¬£¬£¬£¬£¬ÆäÿÔÂÊÕµ½µÄÀ¬»øÓʼþ±¨¸æÊýĿһÁ¬Ï½µ£¬£¬£¬£¬£¬´Ó1ÔÂ·ÝµÄÆ½¾ùÔ¼868349·Ý±¨¸æÏ½µµ½6Ô·ݵÄÔ¼504259·Ý¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹Ç¿µ÷ÁËÕþ¸®¶ÔÓû§Êý¾ÝµÄÅû¶ÇëÇó´ó·ùÉÏÉý¡£¡£¡£¡£¡£¡£¡£½ñÄê1ÔÂÖÁ6Ô£¬£¬£¬£¬£¬TwitterÊÕµ½µÄÕþ¸®ÇëÇó±ÈÉϸö±¨¸æÆÚÔöÌíÁË10%£¬£¬£¬£¬£¬ÕâÊÇÈýÄêÀ´×î´óµÄÔöÌí¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬1ÔÂÖÁ6ÔÂÁè¼Ý205100¸öÕË»§ÒòÐû²¼¿Ö²ÀÖ÷ÒåÄÚÈݶø±»É¾³ý£¬£¬£¬£¬£¬Óë2017ÄêϰëÄêµÄÊý×Ö£¨120Íò£©Ïà±È´ó·ùϽµ¡£¡£¡£¡£¡£¡£¡£1ÔÂÖÁ6ÔÂʱ´úÉÐÓÐÁè¼Ý487300¸öÕË»§Òò¶ùͯÐÔ¾ÛÁ²ÎÊÌâ¶ø±»·â½û¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://transparency.twitter.com/4¡¢APT28ʹÓÃZebrocyºóÃźÍCannonľÂí¹¥»÷¶à¸öÕþ¸®»ú¹¹

Palo Alto NetworksµÄUnit42ÍŶÓÐû²¼¹ØÓÚAPT28½üÆÚÕë¶ÔÕþ¸®»ú¹¹µÄ¶ñÒâ»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£2018Äê10ÔÂÖÐÑ®µ½2018Äê11ÔÂÖÐѮʱ´ú£¬£¬£¬£¬£¬APT28Ò»Á¬Ï®»÷ÁËÌìϸ÷µØµÄ¶à¸öÕþ¸®»ú¹¹£¬£¬£¬£¬£¬Ö÷ҪĿµÄÊDZ±Ô¼¹ú¼Ò£¬£¬£¬£¬£¬µ«Ò²°üÀ¨¼¸¸öǰËÕÁª¹ú¼Ò¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯Ö÷Òª°²ÅÅÁËZebrocy»òCannon±äÖÖ£¬£¬£¬£¬£¬Æä½»¸¶µÄ¶ñÒâÎĵµÊ¹ÓÃÁËͳһ¸ö×÷ÕßÃû³Æ£ºJoohn¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöÁËÍøÂçµ½µÄ9¸ö¶ñÒâÎĵµ£¬£¬£¬£¬£¬²¢½¨ÉèÁËDear Joohn»î¶¯µÄʱ¼äÏß¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/dear-joohn-sofacy-groups-global-campaign/5¡¢Ð¶ñÒâÈí¼þCapitalInstall£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ

NetskopeÍþвÑо¿ÊµÑéÊÒ·¢Ã÷Ò»¸öеĶñÒâÈí¼þCapitalInstall¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýMicrosoft Azure·Ö·¢£¬£¬£¬£¬£¬ÕâʹµÃÆäIPµØµã±»Ðí¶à¹«Ë¾¼ÓÈë°×Ãûµ¥¡£¡£¡£¡£¡£¡£¡£CapitalInstallαװ³ÉÊ¢ÐÐÈí¼þ£¨ÀýÈçAdobe CC 2019£©µÄÃâ·ÑÃÜÔ¿ºÍÔÊÐíÖ¤£¬£¬£¬£¬£¬ÓÕÆÓû§¾ÙÐÐÏÂÔØ£¬£¬£¬£¬£¬²¢À¦°óÁË¹ã¸æÈí¼þLinkury£¬£¬£¬£¬£¬½ø¶øÔÚÓû§µÄÅÌËã»úÉÏÏÂÔØ¸ü¶àDZÔÚÓк¦µÄ³ÌÐò¡£¡£¡£¡£¡£¡£¡£CapitalInstallÖ÷ÒªÕë¶ÔÒ½ÁƺÍÁãÊÛÒµ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.netskope.com/blog/capitalinstall-hosted-and-served-via-iaas6¡¢Î÷ÃÅ×ÓÐÞ¸´SINUMERIK¿ØÖÆÆ÷ÖеĶà¸öÇå¾²Îó²î

Î÷ÃÅ×ÓÐÞ¸´ÁËSINUMERIK¿ØÖÆÆ÷ÖеÄ10¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÎó²î£¨CVE-2018-11466£©ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÏòTCP¶Ë¿Ú102·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢DoS»òÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬¸ÃÎó²îµÄʹÓò¢²»ÐèÒªÈκÎÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Îó²î£¨CVE-2018-11457ºÍCVE-2018-11458£©ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËͶñÒâTCPÊý¾Ý°üÀ´¾ÙÐÐÌáȨ¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£¡£¡£Î÷ÃÅ×Ó×î½üÐû²¼½«Ïñ΢Èí¡¢AdobeºÍSAPÒ»ÑùÔÚÿ¸öÔµĵڶþ¸öÐÇÆÚ¶þÐû²¼Ç徲ͨ¸æ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cert-portal.siemens.com/productcert/pdf/ssa-170881.pdfÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí