ÆÊÎö±¨¸æ¡¿Ñо¿ÍŶÓÐû²¼2018ÄêQ2À¬»øÓʼþºÍ´¹ÂÚ¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÀ¬»øÓʼþºÍ´¹ÂÚ¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¾¼¾¶ÈÀ¬»øÓʼþƽ¾ùռȫÇòÓʼþ×ÜÁ¿µÄ49.66%£¬£¬£¬£¬ÓëÉÏÒ»¼¾¶ÈÏà±ÈϽµÁË2.16¸ö°Ù·Öµã¡£¡£¡£¡£¡£·´´¹ÂÚϵͳ×ÊÖúÓû§×èÖ¹ÁËÁè¼Ý1.07ÒڴζԴ¹ÂÚÍøÕ¾µÄÅþÁ¬£¬£¬£¬£¬±È2018ÄêµÚÒ»¼¾¶ÈÔöÌíÁË1700Íò¡£¡£¡£¡£¡£±¾¼¾¶ÈµÄÀ¬»øÓʼþÖ÷ÌâÖ÷ÒªÓëGDPR¡¢ÌìϱºÍ¼ÓÃÜÇ®±ÒÓйأ¬£¬£¬£¬·¸·¨·Ö×Ó»¹Í¨¹ýÉç½»ÍøÂç¡¢ÐÂÎÅÓ¦ÓúÍÓªÏú¶ÌÐÅÀ´·Ö·¢´¹ÂÚÍøÕ¾µÄÁ´½Ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/spam-and-phishing-in-q2-2018/87368/
¡¾Îó²î²¹¶¡¡¿Î¢ÈíµÄ8ÔÂÇå¾²¸üÐÂÐÞ¸´ÁË60¸öÇå¾²Îó²î£¬£¬£¬£¬°üÀ¨2¸ö0day
΢ÈíÐû²¼2018Äê8ÔµÄÇå¾²¸üУ¬£¬£¬£¬¹²ÐÞ¸´60¸öÇå¾²Îó²î£¬£¬£¬£¬°üÀ¨2¸ö0day¡£¡£¡£¡£¡£µÚÒ»¸ö0dayÊÇWindows ShellÖеĿɵ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÎó²î£¨CVE-2018-8414£©£¬£¬£¬£¬µÚ¶þ¸öÊǿɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄIE 0day£¨CVE-2018-8373£©¡£¡£¡£¡£¡£´Ë´ÎÇå¾²¸üй²ÐÞ¸´ÁË19¸ö¸ßΣÎó²î£¬£¬£¬£¬ËùÓеÄÕâЩ¸ßΣÎó²î¶¼¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-august-2018-patch-tuesday-fixes-60-security-flaws-including-two-zero-days/
¡¾Îó²î²¹¶¡¡¿ICS-CERTÖÒÑÔ³ÆNetComm¹¤ÒµÂ·ÓÉÆ÷±£´æÁ½¸ö¸ßΣÎó²î
Çå¾²Ñо¿Ô±Aditya K. Sood·¢Ã÷°Ä´óÀûÑǹ«Ë¾NetComm WirelessÖÆÔìµÄ¹¤ÒµÂ·ÓÉÆ÷±£´æÁ½¸ö¸ßΣÎó²î£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÀ´½ÓÊÜ×°±¸¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·ÐͺÅÊÇÔËÐй̼þ°æ±¾2.0.29.11¼°Ö®Ç°°æ±¾µÄNetComm 4G LTE Light M2M¹¤ÒµÂ·ÓÉÆ÷¡£¡£¡£¡£¡£ICS-CERTÕë¶Ô°üÀ¨ÕâÁ½¸öÎó²îÔÚÄÚµÄ4¸öÇå¾²Îó²î£¨CVE-2018-14782µ½CVE-2018-14785£©·¢³öÖÒÑÔ¡£¡£¡£¡£¡£NetCommÒÑÔÚ2018Äê5ÔÂÖÐÑ®Ðû²¼ÁËÏà¹Ø¹Ì¼þ¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75332/hacking/netcomm-industrial-routers-flaws.html
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓô«ÕæÐÒéÎó²îÉøÍ¸ÆóÒµÄÚÍø
Check PointµÄÑо¿Ö°Ô±ÑÝʾÔõÑùʹÓô«ÕæÐÒéÖеÄÁ½¸öÎó²îÀ´½ÓÊÜ´òÓ¡»úºÍÉøÍ¸ÆóÒµÄÚÍø¡£¡£¡£¡£¡£ÏÖÔÚÈ«ÇòÈÔÓÐÁè¼Ý3ÒÚ¸ö´«ÕæºÅÂëºÍ4500Íǫ̀´«Õæ»úͶÈëʹÓ㬣¬£¬£¬´«Õæ±»ÆÕ±éÓÃÓÚÉÌÒµ×éÖ¯¡¢î¿Ïµ»ú¹¹¡¢Ö´·¨»ú¹¹¡¢ÒøÐлú¹¹ºÍ·¿µØ²ú¹«Ë¾µÈ¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒªÁì±»³ÆÎªFaxploit¹¥»÷£¬£¬£¬£¬Óë´«ÕæÐÒéÖеÄÁ½¸ö»º³åÇøÒç³öÎó²îÓйأ¨CVE-2018-5925ºÍCVE-2018-5924£©¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÖ»Ðè·¢ËÍÌØÖÆµÄͼÏñÎļþ¼´¿ÉʹÓÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/hack-printer-fax-machine.html
¡¾ÍþвÇ鱨¡¿Çå¾²Ñо¿ÍŶӷ¢Ã÷¶à¸öÖÇÄܽ½¹àϵͳ±£´æÇå¾²Îó²î
À´×ÔÒÔÉ«Áб¾¹ÅÀï°²´óѧµÄÑо¿ÍŶӷ¢Ã÷¶à¸öÖÇÄܽ½¹àϵͳ±£´æ¿ÉʹÓõÄÎó²î£¬£¬£¬£¬¿ÉÓÃÓÚ¹¥»÷¶¼»áµÄ¹©Ë®Ð§ÀÍ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöÁËRainMachine¡¢BlueSprayºÍGreenIQµÈÖ÷Á÷½½¹àϵͳ£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ýIoT¶ñÒâÈí¼þ½¨ÉèÖÇÄܽ½¹àϵͳµÄ½©Ê¬ÍøÂ磬£¬£¬£¬²¢Í¨¹ýC&CЧÀÍÆ÷¿ØÖÆÕâЩϵͳ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÖÒÑԳƣ¬£¬£¬£¬ÕâÖÖ¹¥»÷¿ÉÄÜ»á¶Ô¹©Ë®¹«Ë¾±¬·¢ÖØ´óÓ°Ï죬£¬£¬£¬ÀýÈçÈÃÅçÍ·Ò»Á¬È÷Ë®ÒÔÔÚ¶Ìʱ¼äÄÚÇå¿ÕË®ÏäºÍË®¿â¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/smart-irrigation-systems-expose-water-utilities-attacks