ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ16ÖÜ
°ä²¼¹¦·ò 2019-04-22±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
¹²ÊÕ¼°²È«·ì϶46¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAtlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀú·ì϶£»£»£»£»£»£»£»£»Sangfor Sundray WLAN ControllerȨÏÞÌáÉý·ì϶; GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉý·ì϶£»£»£»£»£»£»£»£»Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»Cloud Foundry Cloud Controller APIÑéÖ¤·ì϶¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
Atlassian Confluence ServerºÍAtlassian Data Center downloadallattachments×ÊÔ´´æÔÚõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎIJ鿴ϵͳÎļþÄÚÈÝ¡£¡£¡£¡£¡£
https://jira.atlassian.com/browse/CONFSERVER-58102
2. Sangfor Sundray WLAN ControllerȨÏÞÌáÉý·ì϶
Sundray WLAN Controller nginx_webconsole.php´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É¶ÁÈ¡adminÃÜÂ룬£¬£¬£¬£¬»ñȡȨÏÞ¡£¡£¡£¡£¡£
https://nvd.nist.gov/vuln/detail/CVE-2019-9161
3. GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉý·ì϶
GitLab impersonate userÖ°ÄÜ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÌáÉýÓû§È¨ÏÞ¡£¡£¡£¡£¡£
https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/
4. Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç¶Âí½Å
Delta Electronics Delta Industrial Automation CNCSoft´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë»ò½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01
Cloud Foundry Cloud Controller APIÑé֤ʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£¡£
https://www.cloudfoundry.org/blog/cve-2019-3798
³ÁÒª°²È«ÊÂÎñ×ÛÊö
΢Èí֤ʵ1ÔÂ1ÈÕÖÁ3ÔÂ29ÈÕÆÚ¼ä¹¥»÷ÕßÈëÇÖÁËÒ»¸ö¿Í»§Ö§³Ö´úÀíÕË»§£¬£¬£¬£¬£¬²¢ÀûÓøÃÕË»§½Ó¼ûÁ˿ͻ§Ö§³ÖÃÅ»§ÍøÕ¾¼°²¿ÃÅOutLookÓû§µÄÓйØÐÅÏ¢¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢Îļþ¼ÐÃû³Æ¡¢ÓʼþÖ÷Ìâ¼°ÁªÏµÈ˵ç×ÓÓʼþµØÖ·£¬£¬£¬£¬£¬µ«²»Ô̺¬Óʼþ¼°¸½¼þµÄÄÚÈÝ¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷µÄ¾ßÌåϸ½Ú£¬£¬£¬£¬£¬µ«Î¢Èí°µÊ¾ÒѾ½ûÓÃÁ˸ôúÀíÕË»§µÄÍ´´¦£¬£¬£¬£¬£¬²¢Í¨ÖªËùÓÐÊÜÓ°ÏìµÄÓû§¡£¡£¡£¡£¡£Î¢ÈíҲûÓÐй©ÊÜÓ°ÏìµÄÓû§×ÜÊý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/microsoft-outlook-email-hack.html
2¡¢GnosticplayersÏúÊÛµÚÎåÅúÓû§Êý¾Ý£¬£¬£¬£¬£¬Ô̺¬6500¶àÍò¸öÕ˺Å
ÔÎÄÁ´½Ó£º
https://cyware.com/news/gnosticplayers-hacker-returns-with-fifth-dataset-containing-over-65-million-user-accounts-for-sale-95450e99
3¡¢³¬´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬£¬£¬£¬£¬½Ù³Ö5ÒÚiOSÓû§»á»°
°²È«³§ÉÌConfiant·¢ÏÖ·¸×ïÍÅ»ïeGobblerÌáÒéÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬£¬£¬£¬£¬ÒѽٳÖ5ÒÚiOSÓû§µÄ»á»°¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯´Ó4ÔÂ6ÈÕÆðÍ·£¬£¬£¬£¬£¬³ÖÐøÁË6ÌìµÄ¹¦·ò£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁË8¸ö·ÖÆçµÄ¶ñÒâ¸æ°×ϵÁкÍ30¶à¸öÐéα¸æ°×£¬£¬£¬£¬£¬Ã¿¸öÐéα¸æ°×ϵÁеÄÐÔÃüÖÜÆÚΪ24-48Ó×ʱ֮¼ä¡£¡£¡£¡£¡£¹¥»÷ÕßÖØÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§£¬£¬£¬£¬£¬²¢ÔÚ¹¥»÷ÖÐÀûÓÃÁËChromeä¯ÀÀÆ÷Öеķì϶ÒÔÈÆ¹ýɳºÐ¼ì²â¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĴ¹µöÍøÕ¾£¬£¬£¬£¬£¬¾¹ý¶ÌÔݵĸédz֮ºó£¬£¬£¬£¬£¬ÓÖתÏò.siteÓòÃûµÄ´¹µöÍøÕ¾¡£¡£¡£¡£¡£×Ô4ÔÂ14ÈÕÒÔÀ´£¬£¬£¬£¬£¬ÕâЩ´¹µöÍøÕ¾Ò»Ïò´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/
4¡¢JustDial APIй¶³¬¹ý1ÒÚÓ¡¶Å×û§µÄÓ×ÎÒÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/justdial-hacked-data-breach.html
5¡¢FacebookÐÂÊý¾Ý³óÎÅ£¬£¬£¬£¬£¬Î´¾Óû§Ðí¿ÉÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË
ÔÚÖÜÈý°ä²¼µÄÒ»·ÝÉêÃ÷ÖУ¬£¬£¬£¬£¬Facebook°µÊ¾×Ô2016Äê5ÔÂÒÔÀ´¸Ã¹«Ë¾¡°ÎÞÒâ¼ä¡±ÔÚδ¾Óû§Ðí¿ÉµÄÇé¿öÏÂÏò·þÎñÆ÷ÉÏ´«Á˶à´ï150ÍòÓû§µÄµç×ÓÓʼþÁªÏµÈË¡£¡£¡£¡£¡£ÕâÊÇFacebook½üÆÚÃæ¶ÔµÄһϵÁÐÒþÖÔÓйØÎÊÌâºÍÕùÒéÖеÄ×îÐÂÊÂÎñ¡£¡£¡£¡£¡£Facebook°µÊ¾ÒÑÔÚÒ»¸öÔÂǰÖÕ³¡ÁË¿ÉÒɵĵç×ÓÓʼþÑéÖ¤¹ý³Ì£¬£¬£¬£¬£¬²¢ÏòÓû§±£ÕÏδ·ÖÏíÕâЩÁªÏµÈËÐÅÏ¢¼°ÒѾÆðͷɾ³ýÕâЩÁªÏµÈË¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/facebook-email-database.html


¾©¹«Íø°²±¸11010802024551ºÅ