¹¤ÐŲ¿Ðû²¼¡¶ÍøÂçÇå¾²Îó²îÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·£»£»£»WebLogic£¨CVE-2019-2729£©Îó²î²¹¶¡

Ðû²¼Ê±¼ä 2019-06-20
1.¹¤ÐŲ¿Ðû²¼¡¶ÍøÂçÇå¾²Îó²îÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ϊ¹á³¹Âäʵ¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂçÇå¾²·¨¡· £¬£¬£¬£¬£¬£¬£¬ÔöÇ¿ÍøÂçÇå¾²Îó²îÖÎÀí £¬£¬£¬£¬£¬£¬£¬¹¤ÒµºÍÐÅÏ¢»¯²¿»áͬÓйز¿·ÖÆð²ÝÁË¡¶ÍøÂçÇå¾²Îó²îÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡· £¬£¬£¬£¬£¬£¬£¬ÄâÒԹ淶ÐÔÎļþÐÎʽӡ·¢ £¬£¬£¬£¬£¬£¬£¬ÏÖÃæÏòÉç»á¹ûÕæÕ÷ÇóÒâ¼û¡£¡£¡£¡£¡£¡£¸Ã»®¶¨°üÀ¨12ÌõÄÚÈÝ £¬£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚº£ÄÚËùÓÐÆóÒµ¡¢×éÖ¯ºÍСÎÒ˽¼Ò £¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÄÚÈݰüÀ¨ÏÞÖÆÎó²îµÄÐÞ¸´Ê±¼ä¡¢Õ¥È¡Ë½×ÔÐû²¼ºÍʹÓÃÎó²î¡¢²»µÃ˽×ÔÐû²¼Îó²îÑéÖ¤¹¤¾ß¡¢»®¶¨î¿Ïµ²¿·ÖµÄÔðÈεȡ£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c7005976/content.html

2.OracleÐû²¼WebLogic£¨CVE-2019-2729£©Îó²îµÄÐÞ¸´²¹¶¡


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


OracleÐû²¼WebLogic ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-2729£©µÄ½ôÆÈÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇCVE-2019-2725µÄ²¹¶¡Èƹý £¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8·Ö £¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄWebLogic Server°æ±¾Îª10.3.6.0.0¡¢12.1.3.0.0ºÍ12.2.1.3.0¡£¡£¡£¡£¡£¡£ÈôÊÇÎÞ·¨Á¬Ã¦×°ÖÃÐÞ¸´²¹¶¡ £¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±½¨Òé½ÓÄÉÒÔÏ»º½â²½·¥£ºÉ¾³ý¡°wls9_async_response.war¡±ºÍ¡°wls-wsat.war¡±È»ºóÖØÐÂÆô¶¯WebLogicЧÀÍ£»£»£»¶Ô·¾¶¡°/_async/*¡±ºÍ¡°/wls-wsat/*¡±µÄURL»á¼ûʵÑé»á¼ûÕ½ÂÔ¿ØÖÆ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/oracle-fixes-critical-bug-in-weblogic-server-web-services/

3.¶íÀÕ¸ÔÖÝDHSÅû¶2019Äê1ÔµÄÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬£¬£¬¹²²¨¼°64.5ÍòÈË

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

¶íÀÕ¸ÔÖÝDHSÏÂÊôµÄÈËÀàЧÀͲ¿Åû¶2019Äê1Ô±¬·¢µÄÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬£¬£¬¸Ã²¿·ÖÈ·ÈϹ²ÓÐ64.5ÍòÈËÊܵ½Ó°Ïì £¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇ֮ǰ3Ô·ÝÅû¶µÄ35ÍòÈË¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂ롢СÎÒ˽¼Ò¿µ½¡ÐÅÏ¢µÈÃô¸ÐÊý¾Ý £¬£¬£¬£¬£¬£¬£¬¶à´ï200Íò·âµç×ÓÓʼþ¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£ÊÓ²ìÈ·ÈÏÓÐ9ÃûÔ±¹¤·­¿ªÁË´¹ÂÚÓʼþ²¢»á¼ûÁËÆäÖеÄÁ´½Ó £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÓÊÏäÕË»§Ð¹Â¶¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/oregon-dhs-notifies-645000-people-of-data-breach-that-occurred-in-january-2019-030ed97c

4.2018ÄêÐÂ¼ÓÆÂÆóÒµÒòBECÕ©Æ­¹¥»÷¹²Ëðʧ5800ÍòÐÂÔª

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤ÐÂ¼ÓÆÂÍøÂçÇå¾²¾Ö£¨CSA£©µÄб¨¸æ £¬£¬£¬£¬£¬£¬£¬2018ÄêÐÂ¼ÓÆÂµÄÆóÒµÒòBECÕ©Æ­¹¥»÷Ëðʧ½ü5800ÍòÐÂÔª£¨4200ÍòÃÀÔª£© £¬£¬£¬£¬£¬£¬£¬Ïà±ÈǰһÄêÔö·ùԼΪ31%¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã±¨¸æÖеÄÊý¾Ý £¬£¬£¬£¬£¬£¬£¬2018Äê¹²±¬·¢378ÆðBECÕ©Æ­ £¬£¬£¬£¬£¬£¬£¬±È2017ÄêµÄ332ÆðÉÏÉý¡£¡£¡£¡£¡£¡£¶ø2018ÄêÐÂ¼ÓÆÂ¹²±¨¸æÁË6179ÆðÍøÂç·¸·¨°¸¼þ £¬£¬£¬£¬£¬£¬£¬±È2017ÄêµÄ5351ÆðÒª¶à¡£¡£¡£¡£¡£¡£±¨¸æ»¹ÏÔʾ £¬£¬£¬£¬£¬£¬£¬½ü70£¥µÄµç×ÓÉÌÎñȦÌ×±¬·¢ÔÚÍøÉÏÊг¡CarousellÉÏ £¬£¬£¬£¬£¬£¬£¬Éæ¼°µç×Ó²úÆ·¡¢»î¶¯»ò¾°µãÃÅÆ±¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.businessinsider.sg/businesses-in-singapore-lost-nearly-s58-million-to-cyber-attacks-last-year-csa-report/

5.ÀÕË÷Èí¼þRyukбäÖÖ £¬£¬£¬£¬£¬£¬£¬ÄÚÖÃIPµØµãºÍÅÌËã»úÃû³ÆµÄºÚÃûµ¥

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿ÍŶÓMalwareHunterTeam·¢Ã÷ÀÕË÷Èí¼þRyukµÄÒ»¸öбäÖÖ £¬£¬£¬£¬£¬£¬£¬¸Ã±äÖÖʹÓÃÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû £¬£¬£¬£¬£¬£¬£¬²¢ÇÒÌí¼ÓÁËIPµØµãºÍÅÌËã»úÃû³ÆµÄºÚÃûµ¥ £¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£Æ¥ÅäµÄÅÌËã»ú²»»á±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Vitali Kremez¶Ô¸ÃÑùÌìÖ°Îöºó·¢Ã÷ £¬£¬£¬£¬£¬£¬£¬¸ÃÑù±¾½«¼ì²éarp -aµÄÊä³ö £¬£¬£¬£¬£¬£¬£¬²¢ÓëÄÚÖõÄIPµØµã×Ö·û´®¾ÙÐÐÆ¥Å䣻£»£»¸ÃÑù±¾»¹»á¼ì²éÅÌËã»úÃû³Æ £¬£¬£¬£¬£¬£¬£¬KremezÒÔΪÕâ¿ÉÄÜÊÇΪÁË×èÖ¹¼ÓÃܶíÂÞ˹µÄÅÌËã»ú¡£¡£¡£¡£¡£¡£Ò»µ©Íê³É¼ÓÃÜ £¬£¬£¬£¬£¬£¬£¬¸ÃÑù±¾½«ÔÚ¼ÓÃܵÄÎļþºóÌí¼Ó.RYKÀ©Õ¹Ãû¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-adds-ip-and-computer-name-blacklisting/

6.ÐÂÄ£¿£¿£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þPlurox £¬£¬£¬£¬£¬£¬£¬Ö÷Òª·Ö·¢ÍÚ¿óľÂí

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷еÄÄ£¿£¿£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þPlurox £¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÄܹ»Ê¹ÓÃSMBºÍUPnP²å¼þÍÚ¿ó²¢¾ÙÐÐÍâµØÈö²¥¡£¡£¡£¡£¡£¡£Plurox·ºÆðÓÚ2ÔÂ·Ý £¬£¬£¬£¬£¬£¬£¬ËƺõÈÔ´¦ÓÚ²âÊÔ½×¶Î £¬£¬£¬£¬£¬£¬£¬ÆäC£¦CµØµã±»Ó²±àÂë½øÄ¾ÂíÖС£¡£¡£¡£¡£¡£PluroxÖ§³Öͨ¹ýC£¦CЧÀÍÆ÷·¢ËÍµÄÆß¸öÏÂÁî £¬£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃWinAPI CreateProcessÏÂÔØºÍÔËÐÐÎļþ¡¢¸üкͿØÖÆbotÒÔ¼°ÏÂÔØ¡¢¿ØÖƺÍÖÎÀí²å¼þ¡£¡£¡£¡£¡£¡£Plurox¿Éͨ¹ýÍâµØÍøÂç¾ÙÐкáÏòÒÆ¶¯ £¬£¬£¬£¬£¬£¬£¬ÕâÖÖÀàËÆÓÚÈ䳿µÄÐÐΪʹÆäÔ½·¢Î£ÏÕ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/modular-plurox-malware-is-a-wormable-backdoor-cryptominer/