IBM WebSphereÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-4279£©£»CloudflareºÍAmazon AWSÍøÂçÖжÏ
°ä²¼¹¦·ò 2019-06-27
IBM½¨¸´WebSphere Application ServerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-4279£©£¬¹¥»÷Õß¿Éͨ¹ý·¢Ë;«ÐÄ»ú¹ØµÄÐòÁл¯¶ÔÏó´¥·¢¸Ã·ì϶£¬×îÖÕµ¼ÖÂÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬WebSphere Application Server ND°æ±¾9.0ºÍ°æ±¾8.5¡¢WebSphere Virtual Enterprise V7.0¡£ÓÉÓÚ½üÈո÷ì϶µÄ¹¥»÷·½Ê½ÒÑÔÚÒ°±í´«²¼£¬½¨ÒéÓû§ÊµÊ±½øÐзÀ»¤¡£
ÔÎÄÁ´½Ó£ºhttps://www-01.ibm.com/support/docview.wss?uid=ibm10883628
2¡¢Android·ÂÕÕÆ÷BlueStacks½¨¸´DNS³Áа󶨷ì϶
°²È«×êÑÐÈËÔ±Nick Cano·¢ÏÖAndroid·ÂÕÕÆ÷BlueStacks´æÔÚDNS³Áа󶨷ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼û·ÂÕÕÆ÷µÄIPCÖ°ÄÜ£¬½ø¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×¢ÐÅϢй¶ÒÔ¼°ÇÔÈ¡VM¼°ÆäÊý¾ÝµÄ±¸·Ý¡£BlueStacksÔÚ5ÔÂ27ÈÕ°ä²¼µÄа汾4.90.0.1046Öн¨¸´Á˸÷ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bluestacks-flaw-lets-attackers-remotely-control-android-emulator/
3¡¢EAÕË»§½Ù³Ö·ì϶¿Éµ¼ÖÂ3ÒÚÍæ¼ÒÕË»§±»½Ù³Ö
Check PointºÍCyberIntµÄ×êÑÐÈËÔ±·¢ÏÖEA OriginÓÎϷƽ̨ÖдæÔÚÒ»¸öÕË»§½Ù³Ö·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÊÕÊܶà´ï3ÒÚÍæ¼ÒµÄÕË»§¡£ÎªÁËÀûÓø÷ì϶£¬¹¥»÷ÕßÖ»±ØÒªÊܺ¦Õßµã»÷EAÓÎϷƽ̨µÄºÏ·¨ÍƼöÁ´½Ó¡£¸Ã·ì϶µÄÔÒòÊÇEAµÄÒ»¸ö×ÓÓòÃû±»³Á¶¨Ïòµ½Î¢ÈíAzureÔÆ·þÎñÉϵÄһ̨°Î³ýÖ÷»ú£¬×êÑÐÈËÔ±¿ÉÄܽ«¡°ea-invite-reg.azurewebsites.net¡±ÓòÃû×¢²áΪ×Ô¼ºµÄWebÀûÓ÷þÎñ£¬ÓÉÓÚCNAME¼Í¼ÈÔ´¦Óڻ״̬£¬×êÑÐÈËԱͨ¹ý¸ÃÓòÃû½Ó¹Üµ½ÁËEAÓû§·¢³öµÄËùÓÐÒªÇó¡£½áºÏEA oAuthµ¥µãµÇ¼£¨SSO£©ºÍTRUST»úÔìÖеķì϶£¬×êÑÐÈËÔ±Äܹ»½Ù³ÖÍæ¼ÒµÄÕË»§¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ea-fixes-origin-game-platform-to-prevent-account-takeovers/
4¡¢·ðÂÞÀï´ïÖÝLake CityÏòºÚ¿ÍÖ§¸¶50ÍòÃÀÔªÊê½ð
±¾ÖÜÒ»·ðÂÞÀï´ïÖݱ±²¿µÄLake CityÔÞ³ÉÏòºÚ¿ÍÖ§¸¶42±ÈÌØ±Ò£¨Ï൱ÓÚ573300ÃÀÔª£©µÄÊê½ð£¬ÒÔ½âËø³ÇÊеĵ绰ºÍµç×ÓÓʼþϵͳ¡£Lake CityÓÚ6ÔÂ10ÈÕϰȾÀÕË÷²¡¶¾Triple Threat£¬ÆäÍÆËã»úϵͳÒÑÒò¶øÌ±»¾ÁËÁ½ÖÜ¡£¸ÃÊеĹÙԱͶƱ¾ö¶¨ÏòºÚ¿ÍÖ§¸¶Êê½ðÒÔ¸´Ô³ÁÒªµµ°¸£¬´ó²¿ÃÅÊê½ð½«Óɱ£ÏÕÖ§¸¶£¬µ«½ü1ÍòÃÀÔªÐèÓɲÆÕþ½øÐÐÖ§³ö¡£ÕâÊÇÒ»ÖÜÄÚ·ðÂÞÀï´ïÖݵڶþÆð³ÇÊÐÖ§¸¶Êê½ðµÄÊÂÎñ£¬¼¸ÌìǰRiviera Beach CityÒ²ÏòºÚ¿ÍÖ§¸¶ÁË60ÍòÃÀÔªµÄÊê½ð¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/87621/hacking/lake-city-500k-ransom.html
5¡¢Troldesh¹¥»÷»î¶¯ÔÙ´ÎìÉý£¬Õë¶Ô¶íÂÞ˹¡¢Ä«Î÷¸çºÍÃÀ¹ú
Avast×êÑÐÔ±Jakub K?oustek·¢ÏÖÀÕË÷Èí¼þTroldeshµÄ¹¥»÷»î¶¯×Ô6ÔÂ24ÈÕÒÔÀ´ÔÙ´ÎìÉý£¬´ïµ½ÁË1Ô·ÝÖ®ºóµÄÓÖÒ»¸ö¶¥·å¡£ÐµĹ¥»÷»î¶¯ÖØÒªÕë¶Ô¶íÂÞ˹¡¢Ä«Î÷¸çºÍÃÀ¹ú£¬AvastÒѾ×èÖ¹Á˸ÃÀÕË÷Èí¼þµÄ10ÍòÂŴι¥»÷¡£TroldeshÔÚ2018Ä궬¼¾ÖØÒªÍ¨¹ý´¹µöÓʼþ½øÐд«²¼£¬´Ë¿ÌËüÖØÒªÍ¨¹ýÉç½»ÍøÂçµÈÐÂÎÅÆ½Ì¨ÉϵĶñÒâÁ´½Ó½øÐд«²¼¡£
ÔÎÄÁ´½Ó£ºhttps://blog.avast.com/ransomware-strain-troldesh-spikes
6¡¢BGP·ÓÉй©µ¼ÖÂCloudflareºÍAmazon AWSÍøÂçÖжÏ
6ÔÂ24ÈÕÓÉÓÚVerizonÃýÎóµØ×ª·¢ÁËBGP·Óɹ㲥£¬µ¼ÖÂÍøÂçÁ÷Á¿±»ÃýÎ󵨵¼ÏòVerizon£¬Ê¹µÃCloudflare¡¢Amazon AWSºÍFacebookµÈ¹«Ë¾µÄ·þÎñÎÞ·¨½Ó¼û¡£ÊÂÎñµÄÆðÒòÊDZöϦ·¨ÄáÑÇÖݵÄÒ»¼ÒÓ×ÐÍISP AS33154-DQE CommunicationsʹÓÃNoctionµÄBGPÓÅ»¯Æ÷ÓÅ»¯ÆäÄÚ²¿ÍøÂçµÄ·ÓÉ£¬µ«ÓÉÓÚÃýÎóÅäÖÃÕâЩ·ÓÉÐÅÏ¢±»ÃýÎ󵨷¢¸øÁËVerizon£¬×îÖÕµ¼Ö´óÁìÓòµÄÍøÂçÖжϡ£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/technology/bgp-route-leak-causes-cloudflare-and-amazon-aws-problems/


¾©¹«Íø°²±¸11010802024551ºÅ