¹¤ÐŲ¿°ä²¼¡¶ÍøÂ簲ȫ·ì϶ÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·£»WebLogic£¨CVE-2019-2729£©·ì϶²¹¶¡

°ä²¼¹¦·ò 2019-06-20
1.¹¤ÐŲ¿°ä²¼¡¶ÍøÂ簲ȫ·ì϶ÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ϊ¹á³¹Âäʵ¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂ簲ȫ·¨¡·£¬¼ÓÇ¿ÍøÂ簲ȫ·ì϶ÖÎÀí£¬¹¤ÒµºÍÐÅÏ¢»¯²¿»áͬÓйز¿ÃŲÝÄâÁË¡¶ÍøÂ簲ȫ·ì϶ÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·£¬ÄâÒԹ淶ÐÔÎļþ´ó¾ÖÓ¡·¢£¬ÏÖÃæÏòÉç»á¹«¿ªÕ÷Ç󶨼û¡£¸Ã»®¶¨Ô̺¬12ÌõÄÚÈÝ£¬ºÏÓÃÓÚ¹úÄÚËùÓÐÆóÒµ¡¢×éÖ¯ºÍÓ×ÎÒ£¬ÖØÒªÄÚÈÝÔ̺¬ÏÞÔì·ì϶µÄ½¨¸´¹¦·ò¡¢²»ÈÝ˽ϰ䲼ºÍÀûÓ÷ì϶¡¢²»µÃ˽ϰ䲼·ì϶ÑéÖ¤¹¤¾ß¡¢»®¶¨¼à¹Ü²¿ÃŵÄÔðÈεÈ¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c7005976/content.html

2.Oracle°ä²¼WebLogic£¨CVE-2019-2729£©·ì϶µÄ½¨¸´²¹¶¡


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Oracle°ä²¼WebLogic ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-2729£©µÄ´¹Î£½¨¸´²¹¶¡¡£¸Ã·ì϶ÊÇCVE-2019-2725µÄ²¹¶¡Èƹý£¬ÆäCVSSÆÀ·ÖΪ9.8·Ö£¬ÊÜÓ°ÏìµÄWebLogic Server°æ±¾Îª10.3.6.0.0¡¢12.1.3.0.0ºÍ12.2.1.3.0¡£ÈôÊÇÎÞ·¨ÂíÉÏ×°Öý¨¸´²¹¶¡£¬×êÑÐÈËÔ±½¨Òé²ÉÈ¡ÒÔÏ»º½â´ëÊ©£ºÉ¾³ý¡°wls9_async_response.war¡±ºÍ¡°wls-wsat.war¡±¶øºó³ÁÐÂÆô¶¯WebLogic·þÎñ£»¶Ôõè¾¶¡°/_async/*¡±ºÍ¡°/wls-wsat/*¡±µÄURL½Ó¼ûÖ´ÐнӼûÕ½Êõ½ÚÔì¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/oracle-fixes-critical-bug-in-weblogic-server-web-services/

3.¶íÀÕ¸ÔÖÝDHSÅû¶2019Äê1ÔµÄÊý¾Ýй¶ÊÂÎñ£¬¹²²¨¼°64.5ÍòÈË

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¶íÀÕ¸ÔÖÝDHSÏÂÊôµÄÈËÀà·þÎñ²¿Åû¶2019Äê1Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñ£¬¸Ã²¿ÃÅÈ·ÈϹ²ÓÐ64.5ÍòÈËÊܵ½Ó°Ï죬¶ø²»ÊÇ֮ǰ3Ô·ÝÅû¶µÄ35ÍòÈË¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢Ó×ÎÒ½¡È«ÐÅÏ¢µÈÃô¸ÐÊý¾Ý£¬¶à´ï200Íò·âµç×ÓÓʼþ¿ÉÄÜй¶¡£µ÷²éÈ·ÈÏÓÐ9ÃûÔ±¹¤´ò¿ªÁË´¹µöÓʼþ²¢½Ó¼ûÁËÆäÖеÄÁ´½Ó£¬µ¼ÖÂÓÊÏäÕË»§Ð¹Â¶¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/oregon-dhs-notifies-645000-people-of-data-breach-that-occurred-in-january-2019-030ed97c

4.2018ÄêÐÂ¼ÓÆÂÆóÒµÒòBECÚ¿Æ­¹¥»÷¹²Ëðʧ5800ÍòÐÂÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÐÂ¼ÓÆÂÍøÂ簲ȫ¾Ö£¨CSA£©µÄл㱨£¬2018ÄêÐÂ¼ÓÆÂµÄÆóÒµÒòBECÚ¿Æ­¹¥»÷Ëðʧ½ü5800ÍòÐÂÔª£¨4200ÍòÃÀÔª£©£¬Ïà±ÈǰһÄêÔö·ùԼΪ31%¡£Æ¾¾Ý¸Ã»ã±¨ÖеÄÊý¾Ý£¬2018Äê¹²²úÉú378ÆðBECÚ¿Æ­£¬±È2017ÄêµÄ332ÆðÉÏÉý¡£¶ø2018ÄêÐÂ¼ÓÆÂ¹²»ã±¨ÁË6179ÆðÍøÂç·¸×ï°¸¼þ£¬±È2017ÄêµÄ5351ÆðÒª¶à¡£»ã±¨»¹ÏÔʾ£¬½ü70£¥µÄµç×ÓÉÌÎñȦÌײúÉúÔÚÍøÉÏÊг¡CarousellÉÏ£¬Éæ¼°µç×Ó²úÆ·¡¢»î¶¯»ò¾°µãÃÅÆ±¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.businessinsider.sg/businesses-in-singapore-lost-nearly-s58-million-to-cyber-attacks-last-year-csa-report/

5.ÀÕË÷Èí¼þRyukбäÖÖ£¬ÄÚÖÃIPµØÖ·ºÍÍÆËã»úÃû³ÆµÄºÚÃûµ¥

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÍŶÓMalwareHunterTeam·¢ÏÖÀÕË÷Èí¼þRyukµÄÒ»¸öбäÖÖ£¬¸Ã±äÖÖʹÓÃÊý×ÖÖ¤Êé½øÐÐÊðÃû£¬²¢ÇÒÔö³¤ÁËIPµØÖ·ºÍÍÆËã»úÃû³ÆµÄºÚÃûµ¥£¬ÒÔÈ·±£Æ¥ÅäµÄÍÆËã»ú²»»á±»¼ÓÃÜ¡£×êÑÐÈËÔ±Vitali Kremez¶Ô¸ÃÑù±¾·ÖÎöºó·¢ÏÖ£¬¸ÃÑù±¾½«²é³­arp -aµÄÊä³ö£¬²¢ÓëÄÚÖõÄIPµØÖ·×Ö·û´®½øÐÐÆ¥Å䣻¸ÃÑù±¾»¹»á²é³­ÍÆËã»úÃû³Æ£¬KremezÒÔΪÕâ¿ÉÄÜÊÇΪÁËÔ¤·À¼ÓÃܶíÂÞ˹µÄÍÆËã»ú¡£Ò»µ©ÊµÏÖ¼ÓÃÜ£¬¸ÃÑù±¾½«ÔÚ¼ÓÃܵÄÎļþºóÔö³¤.RYKÀ©´óÃû¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-adds-ip-and-computer-name-blacklisting/

6.ÐÂÄ £¿é»¯¶ñÒâÈí¼þPlurox£¬ÖØÒª·Ö·¢ÍÚ¿óľÂí

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖеÄÄ £¿é»¯¶ñÒâÈí¼þPlurox£¬¸Ã¶ñÒâÈí¼þ¿ÉÄÜÀûÓÃSMBºÍUPnP²å¼þÍÚ¿ó²¢½øÐб¾µØ´«²¼¡£Plurox³öÏÖÓÚ2Ô·Ý£¬ËƺõÈÔ´¦ÓÚ²âÊԽ׶Σ¬ÆäC£¦CµØÖ·±»Ó²±àÂë½øÄ¾ÂíÖС£PluroxÖ§³Öͨ¹ýC£¦C·þÎñÆ÷·¢ËÍµÄÆß¸öºÅÁÔ̺¬Ê¹ÓÃWinAPI CreateProcessÏÂÔØºÍÔËÐÐÎļþ¡¢¸üкͽÚÔìbotÒÔ¼°ÏÂÔØ¡¢½ÚÔìºÍÖÎÀí²å¼þ¡£Plurox¿Éͨ¹ý±¾µØÍøÂç½øÐкáÏòÒÆ¶¯£¬ÕâÖÖÀàËÆÓÚÈ䳿µÄÐÐΪʹÆäÔ½·¢Î£ÏÕ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/modular-plurox-malware-is-a-wormable-backdoor-cryptominer/