¹¤ÐŲ¿°ä²¼¡¶ÍøÂ簲ȫ·ì϶ÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·£»£»£»£»£»WebLogic£¨CVE-2019-2729£©·ì϶²¹¶¡

°ä²¼¹¦·ò 2019-06-20
1.¹¤ÐŲ¿°ä²¼¡¶ÍøÂ簲ȫ·ì϶ÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ϊ¹á³¹Âäʵ¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂ簲ȫ·¨¡·£¬ £¬£¬£¬£¬¼ÓÇ¿ÍøÂ簲ȫ·ì϶ÖÎÀí£¬ £¬£¬£¬£¬¹¤ÒµºÍÐÅÏ¢»¯²¿»áͬÓйز¿ÃŲÝÄâÁË¡¶ÍøÂ簲ȫ·ì϶ÖÎÀí»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·£¬ £¬£¬£¬£¬ÄâÒԹ淶ÐÔÎļþ´ó¾ÖÓ¡·¢£¬ £¬£¬£¬£¬ÏÖÃæÏòÉç»á¹«¿ªÕ÷Ç󶨼û¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»®¶¨Ô̺¬12ÌõÄÚÈÝ£¬ £¬£¬£¬£¬ºÏÓÃÓÚ¹úÄÚËùÓÐÆóÒµ¡¢×éÖ¯ºÍÓ×ÎÒ£¬ £¬£¬£¬£¬ÖØÒªÄÚÈÝÔ̺¬ÏÞÔì·ì϶µÄ½¨¸´¹¦·ò¡¢²»ÈÝ˽ϰ䲼ºÍÀûÓ÷ì϶¡¢²»µÃ˽ϰ䲼·ì϶ÑéÖ¤¹¤¾ß¡¢»®¶¨¼à¹Ü²¿ÃŵÄÔðÈεÈ¡£¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c7005976/content.html

2.Oracle°ä²¼WebLogic£¨CVE-2019-2729£©·ì϶µÄ½¨¸´²¹¶¡


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Oracle°ä²¼WebLogic ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-2729£©µÄ´¹Î£½¨¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇCVE-2019-2725µÄ²¹¶¡Èƹý£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8·Ö£¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄWebLogic Server°æ±¾Îª10.3.6.0.0¡¢12.1.3.0.0ºÍ12.2.1.3.0¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÎÞ·¨Á¢¿Ì×°Öý¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬ £¬£¬£¬£¬×êÑÐÈËÔ±½¨Òé²ÉÈ¡ÒÔÏ»º½â´ëÊ©£ºÉ¾³ý¡°wls9_async_response.war¡±ºÍ¡°wls-wsat.war¡±¶øºó³ÁÐÂÆô¶¯WebLogic·þÎñ£»£»£»£»£»¶Ôõè¾¶¡°/_async/*¡±ºÍ¡°/wls-wsat/*¡±µÄURL½Ó¼ûÖ´ÐнӼûÕ½Êõ½ÚÔì¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/oracle-fixes-critical-bug-in-weblogic-server-web-services/

3.¶íÀÕ¸ÔÖÝDHSÅû¶2019Äê1ÔµÄÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬¹²²¨¼°64.5ÍòÈË

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

¶íÀÕ¸ÔÖÝDHSÏÂÊôµÄÈËÀà·þÎñ²¿Åû¶2019Äê1Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬¸Ã²¿ÃÅÈ·ÈϹ²ÓÐ64.5ÍòÈËÊܵ½Ó°Ï죬 £¬£¬£¬£¬¶ø²»ÊÇ֮ǰ3Ô·ÝÅû¶µÄ35ÍòÈË¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢Ó×ÎÒ½¡È«ÐÅÏ¢µÈÃô¸ÐÊý¾Ý£¬ £¬£¬£¬£¬¶à´ï200Íò·âµç×ÓÓʼþ¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¡£¡£µ÷²éÈ·ÈÏÓÐ9ÃûÔ±¹¤´ò¿ªÁË´¹µöÓʼþ²¢½Ó¼ûÁËÆäÖеÄÁ´½Ó£¬ £¬£¬£¬£¬µ¼ÖÂÓÊÏäÕË»§Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/oregon-dhs-notifies-645000-people-of-data-breach-that-occurred-in-january-2019-030ed97c

4.2018ÄêÐÂ¼ÓÆÂÆóÒµÒòBECÚ¿Æ­¹¥»÷¹²Ëðʧ5800ÍòÐÂÔª

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝÐÂ¼ÓÆÂÍøÂ簲ȫ¾Ö£¨CSA£©µÄл㱨£¬ £¬£¬£¬£¬2018ÄêÐÂ¼ÓÆÂµÄÆóÒµÒòBECÚ¿Æ­¹¥»÷Ëðʧ½ü5800ÍòÐÂÔª£¨4200ÍòÃÀÔª£©£¬ £¬£¬£¬£¬Ïà±ÈǰһÄêÔö·ùԼΪ31%¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã»ã±¨ÖеÄÊý¾Ý£¬ £¬£¬£¬£¬2018Äê¹²²úÉú378ÆðBECÚ¿Æ­£¬ £¬£¬£¬£¬±È2017ÄêµÄ332ÆðÉÏÉý¡£¡£¡£¡£¡£¡£¡£¡£¶ø2018ÄêÐÂ¼ÓÆÂ¹²»ã±¨ÁË6179ÆðÍøÂç·¸×ï°¸¼þ£¬ £¬£¬£¬£¬±È2017ÄêµÄ5351ÆðÒª¶à¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨»¹ÏÔʾ£¬ £¬£¬£¬£¬½ü70£¥µÄµç×ÓÉÌÎñȦÌײúÉúÔÚÍøÉÏÊг¡CarousellÉÏ£¬ £¬£¬£¬£¬Éæ¼°µç×Ó²úÆ·¡¢»î¶¯»ò¾°µãÃÅÆ±¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.businessinsider.sg/businesses-in-singapore-lost-nearly-s58-million-to-cyber-attacks-last-year-csa-report/

5.ÀÕË÷Èí¼þRyukбäÖÖ£¬ £¬£¬£¬£¬ÄÚÖÃIPµØÖ·ºÍÍÆËã»úÃû³ÆµÄºÚÃûµ¥

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÍŶÓMalwareHunterTeam·¢ÏÖÀÕË÷Èí¼þRyukµÄÒ»¸öбäÖÖ£¬ £¬£¬£¬£¬¸Ã±äÖÖʹÓÃÊý×ÖÖ¤Êé½øÐÐÊðÃû£¬ £¬£¬£¬£¬²¢ÇÒÔö³¤ÁËIPµØÖ·ºÍÍÆËã»úÃû³ÆµÄºÚÃûµ¥£¬ £¬£¬£¬£¬ÒÔÈ·±£Æ¥ÅäµÄÍÆËã»ú²»»á±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Vitali Kremez¶Ô¸ÃÑù±¾·ÖÎöºó·¢ÏÖ£¬ £¬£¬£¬£¬¸ÃÑù±¾½«²é³­arp -aµÄÊä³ö£¬ £¬£¬£¬£¬²¢ÓëÄÚÖõÄIPµØÖ·×Ö·û´®½øÐÐÆ¥Å䣻£»£»£»£»¸ÃÑù±¾»¹»á²é³­ÍÆËã»úÃû³Æ£¬ £¬£¬£¬£¬KremezÒÔΪÕâ¿ÉÄÜÊÇΪÁËÔ¤·À¼ÓÃܶíÂÞ˹µÄÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©ÊµÏÖ¼ÓÃÜ£¬ £¬£¬£¬£¬¸ÃÑù±¾½«ÔÚ¼ÓÃܵÄÎļþºóÔö³¤.RYKÀ©´óÃû¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-adds-ip-and-computer-name-blacklisting/

6.ÐÂÄ£¿£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þPlurox£¬ £¬£¬£¬£¬ÖØÒª·Ö·¢ÍÚ¿óľÂí

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖеÄÄ£¿£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þPlurox£¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÄÜÀûÓÃSMBºÍUPnP²å¼þÍÚ¿ó²¢½øÐб¾µØ´«²¼¡£¡£¡£¡£¡£¡£¡£¡£Plurox³öÏÖÓÚ2Ô·ݣ¬ £¬£¬£¬£¬ËƺõÈÔ´¦ÓÚ²âÊԽ׶Σ¬ £¬£¬£¬£¬ÆäC£¦CµØÖ·±»Ó²±àÂë½øÄ¾ÂíÖС£¡£¡£¡£¡£¡£¡£¡£PluroxÖ§³Öͨ¹ýC£¦C·þÎñÆ÷·¢ËÍµÄÆß¸öºÅÁ £¬£¬£¬£¬Ô̺¬Ê¹ÓÃWinAPI CreateProcessÏÂÔØºÍÔËÐÐÎļþ¡¢¸üкͽÚÔìbotÒÔ¼°ÏÂÔØ¡¢½ÚÔìºÍÖÎÀí²å¼þ¡£¡£¡£¡£¡£¡£¡£¡£Plurox¿Éͨ¹ý±¾µØÍøÂç½øÐкáÏòÒÆ¶¯£¬ £¬£¬£¬£¬ÕâÖÖÀàËÆÓÚÈ䳿µÄÐÐΪʹÆäÔ½·¢Î£ÏÕ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/modular-plurox-malware-is-a-wormable-backdoor-cryptominer/