¹¤ÐŲ¿°ä²¼¡¶ÍøÂ簲ȫ·ì϶ÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·£»WebLogic£¨CVE-2019-2729£©·ì϶²¹¶¡
°ä²¼¹¦·ò 2019-06-20
ÔÎÄÁ´½Ó£º
http://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c7005976/content.html2.Oracle°ä²¼WebLogic£¨CVE-2019-2729£©·ì϶µÄ½¨¸´²¹¶¡
Oracle°ä²¼WebLogic ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-2729£©µÄ´¹Î£½¨¸´²¹¶¡¡£¸Ã·ì϶ÊÇCVE-2019-2725µÄ²¹¶¡Èƹý£¬ÆäCVSSÆÀ·ÖΪ9.8·Ö£¬ÊÜÓ°ÏìµÄWebLogic Server°æ±¾Îª10.3.6.0.0¡¢12.1.3.0.0ºÍ12.2.1.3.0¡£ÈôÊÇÎÞ·¨ÂíÉÏ×°Öý¨¸´²¹¶¡£¬×êÑÐÈËÔ±½¨Òé²ÉÈ¡ÒÔÏ»º½â´ëÊ©£ºÉ¾³ý¡°wls9_async_response.war¡±ºÍ¡°wls-wsat.war¡±¶øºó³ÁÐÂÆô¶¯WebLogic·þÎñ£»¶Ôõè¾¶¡°/_async/*¡±ºÍ¡°/wls-wsat/*¡±µÄURL½Ó¼ûÖ´ÐнӼûÕ½Êõ½ÚÔì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/oracle-fixes-critical-bug-in-weblogic-server-web-services/3.¶íÀÕ¸ÔÖÝDHSÅû¶2019Äê1ÔµÄÊý¾Ýй¶ÊÂÎñ£¬¹²²¨¼°64.5ÍòÈË
¶íÀÕ¸ÔÖÝDHSÏÂÊôµÄÈËÀà·þÎñ²¿Åû¶2019Äê1Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñ£¬¸Ã²¿ÃÅÈ·ÈϹ²ÓÐ64.5ÍòÈËÊܵ½Ó°Ï죬¶ø²»ÊÇ֮ǰ3Ô·ÝÅû¶µÄ35ÍòÈË¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢Ó×ÎÒ½¡È«ÐÅÏ¢µÈÃô¸ÐÊý¾Ý£¬¶à´ï200Íò·âµç×ÓÓʼþ¿ÉÄÜй¶¡£µ÷²éÈ·ÈÏÓÐ9ÃûÔ±¹¤´ò¿ªÁË´¹µöÓʼþ²¢½Ó¼ûÁËÆäÖеÄÁ´½Ó£¬µ¼ÖÂÓÊÏäÕË»§Ð¹Â¶¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/oregon-dhs-notifies-645000-people-of-data-breach-that-occurred-in-january-2019-030ed97c4.2018ÄêÐÂ¼ÓÆÂÆóÒµÒòBECڿƹ¥»÷¹²Ëðʧ5800ÍòÐÂÔª
ÔÎÄÁ´½Ó£º
https://www.businessinsider.sg/businesses-in-singapore-lost-nearly-s58-million-to-cyber-attacks-last-year-csa-report/5.ÀÕË÷Èí¼þRyukбäÖÖ£¬ÄÚÖÃIPµØÖ·ºÍÍÆËã»úÃû³ÆµÄºÚÃûµ¥
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-adds-ip-and-computer-name-blacklisting/6.ÐÂÄ£¿é»¯¶ñÒâÈí¼þPlurox£¬ÖØÒª·Ö·¢ÍÚ¿óľÂí
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/modular-plurox-malware-is-a-wormable-backdoor-cryptominer/


¾©¹«Íø°²±¸11010802024551ºÅ