EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷,È«Çò·þÎñÖжÏ£»WappalyzerÔâºÚ¿ÍÈëÇÖ,1.6ÍòÓû§Êý¾Ý±»µÁ

°ä²¼¹¦·ò 2020-04-17

1.EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷ £¬È«Çò·þÎñÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷ £¬µ¼Ö¸ù«Ë¾µÄ·þÎñÆ÷ÔÚÈ«ÇòÁìÓòÄÚÍÑ»ú ¡£Õâ´Î¹¥»÷²úÉúÔÚ4ÔÂ14ÈÕÏÂÎç4:19 ¡£Æ¾¾ÝDown DetectorµÄʵʱµØÍ¼ £¬Õâ´Î¹¥»÷ÖØÒªÓ°ÏìÁËÅ·ÖÞµØÓòµÄ¿Í»§ £¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì ¡£4ÔÂ15ÈÕÁ賿1µã25·Ö £¬EA SportsÈϿɸù«Ë¾¡°¾­ÀúÁËһϵÁÐDDoS¹¥»÷¡± ¡£ÔÚ°ä²¼±¾ÎÄʱ £¬EA SportsµÄ¿Í»§ÈÔÔÚ±§Ô¹·þÎñå´»ú £¬ÕâÅú×¢¸Ã¹«Ë¾ÈÔÔÚÔâ·ê¹¥»÷ ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÁ賿4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷ £¬µ¼ÖÂÈ«Çò·þÎñÖжÏ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/


2.WappalyzerÔâºÚ¿ÍÈëÇÖ £¬1.6ÍòÓû§Êý¾Ý±»µÁ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



¿Æ¼¼¹«Ë¾WappalyzerÈ·ÈÏÔâµ½ºÚ¿ÍÈëÇÖ £¬Æä1.6ÍòÓû§ÐÅÏ¢±»µÁ ¡£Wappalyzer°µÊ¾Õâ´ÎºÚ¿ÍÈëÇÖ²úÉúÔÚ1ÔÂ20ÈÕ £¬ÆäʱÈëÇÖÕß½Ó¼ûÁËWappalyzerµÄÒ»¸öÒòÅäÖò»µ±Â¶³öÔÚ¹«ÍøÉϵÄÊý¾Ý¿â ¡£WappalyzerÊ×´´ÈËElbert Alias°µÊ¾¸ÃÊý¾ÝÖØÒªÔ̺¬¹«Ë¾µÄ¡°¼¼·¨Êõ¾Ý¡± £¬µ«Ò²Ô̺¬1.6Íò¿Í»§ÐÅÏ¢ £¬ÕâЩÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢Õ˵¥µØÖ·µÈ ¡£¹¥»÷ÕßÔÚ±¾ÖÜÏòWappalyzerµÄ¿Í»§·¢ËÍÁËÒ»·âµç×ÓÓʼþ £¬Ðû³ÆÒѾ­»ñµÃÁËWappalyzerµÄÆëÈ«Êý¾Ý¿â²¢ÒÔ2000ÃÀÔªµÄ¼ÛÖµÏúÊÛËü ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wappalyzer-discloses-security-breach-after-hacker-starts-emailing-users/


3.ºÚ¿ÍÀûÓÃNetWire RATбäÖÖ¶Ô×¼ÃÀ¹úÄÉ˰ÈË


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÀûÓÃNetWire RATµÄбäÖÖÀ´ÇÔÈ¡ÃÀ¹úÄÉ˰ÈËµÄÆ¾Ö¤ºÍ˰ÎñÐÅÏ¢ ¡£´Ë±äÖÖÖØÒªÊÇÀûÓÃÒÔirsΪÖ÷ÌâµÄÍøÂç´¹µöÕ½Êõ £¬Í¨¹ýʹÓÃ΢ÈíExcel 4.0ºêÀ´Ìӱܲ¡¶¾¼à²âºÍ·ÖÎö £¬²¢ÇҸĽøÁ˼üÅ̼ͼ·¨Ê½ºÍÍ´´¦ÍøÂçÖ°ÄÜ ¡£Excel 4.0ÊÇ΢ÈíÔçÆÚ£¨1992Ä꣩°ä²¼µÄ°æ±¾ £¬ÓÉÓÚ΢Èí´ÓδΪExcel 4.0ºêÌṩµ÷ÊÔÖ°ÄÜ £¬Òò¶ø°²È«×êÑÐÈËÔ±ÎÞ·¨·ÖÎöºÍµ÷ÊÔ¶ñÒâºê´úÂë ¡£ÓÉÓڸü¼ÊõÒѾ­ºÜ¹ÅÀÏ £¬Òò¶øÊ¹ÓÃExcel 4.0ºêÄܹ»Èƹý´óÎÞÊý·À²¡¶¾¼ì²â ¡£¹ÌÈ»Excel 4.0ºê֮ǰҲÔÚÆäËü¶ñÒâÈí¼þÖÐʹÓùý £¬µ«ÔÚNetWire¼Ò×åÖл¹Êdzõ´Î ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/taxpayers-targeted-with-improved-netwire-rat-variant/154830/


4.ÐÂIoT½©Ê¬ÍøÂçMozi £¬Ô¤¼ÆÒÑϰȾ1.5ÍòIoTÉ豸


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CenturyLinkµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öеÄIoT½©Ê¬ÍøÂçMozi £¬MoziÓÉÖÁÉÙÈý¸öÒÑÖªµÄ¶ñÒâÈí¼þ£¨Gafgyt¡¢MiraiºÍIoT Reaper£©µÄÔ´´úÂë×é³É £¬Ô¤¼ÆÒÑϰȾÁË1.5ÍòIoTÉ豸 ¡£¸Ã½©Ê¬ÍøÂç¿É±»ÓÃÓÚÌáÒéDDoS¹¥»÷µÈ ¡£µ«µ½Ä¿Ç°ÎªÖ¹ £¬»¹Ã»ÓÐÐÂÎÅ֤ʵ¸ÃÍøÂçÒѱ»ÓÃÓÚÈκι¥»÷ ¡£MoziÖØÒªÕë¶ÔµÄÊÇδ´ò²¹¶¡µÄ»òÊÇÓµÓÐÈõÃÜÂëµÄ¼ÒÓ÷ÓÉÆ÷ºÍDVR ¡£CenturyLink»¹°µÊ¾ £¬MoziµÄ¹ÖÒìÖ®´¦»¹Ô̺¬ÆäP2P½á¹¹µÄ¸öÐÔ £¬ÕâʹµÃËü¸üÄѱ»Æëȫɾ³ý ¡£Æù½ñΪֹ £¬CenturyLink¹Û²ìµ½70%µÄÊÜMoziϰȾµÄIoTÉ豸λÓÚÖйú £¬Æä´ÎÊÇÃÀ¹ú£¨10%£©ºÍÓ¡¶È£¨10%£© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/iot/new-malware-family-assembles-iot-botnet--/d/d-id/1337578


5.¹È¸èGmailÒ»ÖÜÄÚ×èÖ¹ÁË1800Íò·âÒÔCOVID-19ΪÖ÷ÌâµÄ´¹µöÓʼþ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸è°µÊ¾ £¬GmailÄÚÖõĶñÒâÈí¼þɨÃ跨ʽÔÚÉÏÖÜ×èÖ¹ÁËԼĪ1800Íò·âÒÔCOVID-19ΪÖ÷ÌâµÄ´¹µöÓʼþ ¡£ÕâЩ´¹µöÓʼþÔ̺¬¼ÙÒâÊÀ½çÎÀÉú×éÖ¯£¨WHO£©µÈȨÍþµ±¾Ö»ú¹¹Æ­È¡¾è¿î»ò·Ö·¢¶ñÒâÈí¼þ£»Õë¶ÔÔڼҰ칫µÄÔ±¹¤½øÐд¹µö£»¼Ù×°³Éµ±¾Ö»ú¹¹µÄ¾­¼Ã´Ì¼¤´òËãÓÕÆ­ÖÐÓ×ÐÍÆóÒµ£»¶Ô×¼¹úÄÚ¶©µ¥ÊÜÓ°ÏìµÄÆóÒµµÈ ¡£ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©ºÍÓ¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©Ò²ÓÚ±¾Ô³õ°ä²¼ÁËÓйØCOVID-19¹¥»÷µÄ½áºÏ¾¯±¨ ¡£½¨ÒéÓû§ºÍÖÎÀíÔ±²ÉÈ¡ÓйشëÊ©¼ÓÇ¿¶Ô´ËÀà´¹µö¹¥»÷µÄ·À»¤ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/gmail-blocked-18m-covid-19-themed-phishing-emails-in-a-week/


6.SAP°ä²¼4Ô°²È«¸üР£¬½¨¸´5¸ö¹Ø¼ü·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SAP±¾Öܰ䲼ÁË4Ô·ݵݲȫ²¹¶¡ £¬×ܹ²½¨¸´ÁË23¸ö·ì϶ £¬ÆäÖÐ5¸öΪ¹Ø¼ü·ì϶ ¡£ÆäÖÐ×îÑϳÁµÄÒ»¸öÊÇXMLÑé֤ȱʧ·ì϶ £¬¸Ã·ì϶±»¸ú×ÙΪCVE-2020-6238£¨CVSS 9.3£© £¬Ô¶³Ì¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓô˷ì϶ ¡£Æä´ÎSAP½¨¸´ÁËSAP NetWeaver ÖеÄĿ¼±éÀú·ì϶£¨CVE-2020-6225 £¬CVSS9.1£©¡¢SAP BusinessObjects Business Intelligence ƽ̨Öеķ´ÐòÁл¯·ì϶£¨CVE-2020-6219 £¬CVSS9.1£©¡¢OrientDB 3.0ÖеĴúÂë×¢Èë·ì϶£¨ CVE-2020-6230 £¬CVSS9.1£©¡¢SAP Diagnostics AgentÖеÄϵͳºÅÁî×¢Èë·ì϶£¨CVE-2019-0330 £¬CVSS9.1£© ¡£´Ë±í £¬SAP»¹½â¾öÁËBusiness Objects Business Intelligence Platform¡¢ERP & S/4 HANA¡¢NetWeaver¡¢Fiori Launchpad¡¢Business Client¡¢S/4 HANA¡¢ºÍSAP CommerceÖеĶà¸öÖеÍΣ·ì϶


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/saps-april-2020-security-updates-patch-five-critical-vulnerabilities