ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ7ÖÜ

Ðû²¼Ê±¼ä 2019-02-18

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe ColdFusion CVE-2019-7091í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Docker runc CVE-2019-5736í§ÒâÏÂÁîÖ´ÐÐÎó²î; Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉýÎó²î£»£»£»£»£»£»£»Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£ ¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£»£»£»£»£»£»£»VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý£»£»£»£»£»£»£»AZORultľÂíй¥»÷»î¶¯£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû£»£»£»£»£»£»£»VallettaÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª£»£»£»£»£»£»£»Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅϢй¶¡£¡£¡£¡£¡£ ¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£ ¡£¡£

Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe ColdFusion CVE-2019-7091í§Òâ´úÂëÖ´ÐÐÎó²î

Adobe ColdFusionÔÚ·´ÐòÁл¯²»¿ÉÐŵÄÊý¾Ý±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-10.html

2. Docker runc CVE-2019-5736í§ÒâÏÂÁîÖ´ÐÐÎó²î
Docker runcʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£¶ñÒâÈÝÆ÷ÐèÖª×ãÒÔÏÂÁ½¸öÌõ¼þÖ®Ò»: (1)ÓÉÒ»¸ö¹¥»÷Õß¿ØÖƵĶñÒâ¾µÏñ½¨Éè(2)¹¥»÷Õß¾ßÓÐijÒѱ£´æÈÝÆ÷µÄдȨÏÞ£¬£¬£¬ÇÒ¿Éͨ¹ýdocker exec½øÈë¡£¡£¡£¡£¡£ ¡£¡£
https://github.com/docker/docker-ce/releases/tag/v18.09.2

3. Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉýÎó²î
Microsoft Exchange Server×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬Ä£ÄâExchangeЧÀÍÆ÷µÄÆäËûÈκÎÓû§¡£¡£¡£¡£¡£ ¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0686

4. Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Windows´¦Öóͷ£SMBv2Êý¾Ý±¨Îı£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄSMBv2ÇëÇ󣬣¬£¬¿ÉÒÔÄÚºËÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0633

5. Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Office Access Connectivity Engine´¦Öóͷ£Äڴ湤¾ß±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0673

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°µÍøÊг¡Dream MarketÉÏÕýÔÚ³öÊÛ6.2ÒÚÕË»§ÐÅÏ¢£¬£¬£¬ÕâЩÐÅÏ¢µÁ×Ô16¸öÍøÕ¾£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£¨ÒÔ±ÈÌØ±ÒÖ§¸¶£©¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ±»µÁÊý¾ÝÉæ¼°µÄÍøÕ¾°üÀ¨Dubsmash£¨1.62ÒÚ£©¡¢MyFitnessPal£¨1.51ÒÚ£©¡¢MyHeritage£¨9200Íò£©¡¢ShareThis£¨4100Íò£©¡¢HauteLook£¨2800Íò£©¡¢Animoto£¨2500Íò£©¡¢EyeEm£¨2200Íò£©¡¢8fit£¨2000Íò£©¡¢Whitepages£¨1800Íò£©¡¢Fotolog£¨1600Íò£©¡¢500px£¨1500Íò£©¡¢Armor Games£¨1100Íò£©¡¢BookMate£¨800Íò£©¡¢CoffeeMeetsBagel£¨600Íò£©¡¢Artsy£¨100Íò£©ºÍDataCamp£¨70Íò£©¡£¡£¡£¡£¡£ ¡£¡£´ÓÑù±¾Êý¾ÝÀ´¿´£¬£¬£¬ÕâЩÊý¾ÝÖ÷Òª°üÀ¨ÕË»§³ÖÓÐÈ˵ÄÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂ룬£¬£¬µ«²»°üÀ¨ÒøÐп¨ÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/

2¡¢VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2ÔÂ11ÈÕ£¬£¬£¬µç×ÓÓʼþЧÀÍÉÌVFEmail.netÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬ËùÓÐÃÀ¹úЧÀÍÆ÷ÉϵÄÊý¾Ý±»É¾³ý£¬£¬£¬Õâµ¼ÖÂËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬¹¥»÷ÕßÃûÌû¯ÁËÿһ̨ЧÀÍÆ÷ÉϵÄÓ²ÅÌ£¬£¬£¬ËùÓеÄÐéÄâ»ú¡¢ÎļþЧÀÍÆ÷°üÀ¨±¸·ÝЧÀÍÆ÷¶¼ÒÑɥʧ¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿Í²¢Ã»ÓÐÒªÇóÊê½ð£¬£¬£¬VFEmail½«´ËÊÂÎñÐÎòΪ¹¥»÷ºÍÆÆËðÊÂÎñ¡£¡£¡£¡£¡£ ¡£¡£ÏÖÔڸù«Ë¾µÄÍøÕ¾ÒѾ­ÖØÐÂÉÏÏߣ¬£¬£¬µ«´Î¼¶ÓòÃûÈÔÎÞ·¨»á¼û¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-wipe-us-servers-of-email-provider-vfemail/

3¡¢AZORultľÂíй¥»÷»î¶¯£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cybaze-Yori ZLAB·¢Ã÷AZORultľÂíµÄй¥»÷»î¶¯£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû¡£¡£¡£¡£¡£ ¡£¡£¸ÃľÂíбäÌåͨ¹ýαװ³ÉDHL¿ìµÝ֪ͨµÄÓʼþ¾ÙÐÐÈö²¥£¬£¬£¬µ±Óû§·­¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó£¬£¬£¬¾Í»áÏÂÔØ²¢ÔËÐиÃľÂí¡£¡£¡£¡£¡£ ¡£¡£¸ÃľÂí¿ÉÒÔÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖÐÉúÑĵÄÕË»§ºÍƾ֤£¬£¬£¬²¢¿ÉÒÔ×°ÖÃÆäËüµÄpayload¡£¡£¡£¡£¡£ ¡£¡£ÆäC2ЧÀÍÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¡£¡£¡£¡£ ¡£¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931

4¡¢VallettaÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Âí¶úËûVallettaÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬¹¥»÷ÕßÊÔͼ½«1300ÍòŷԪתÈëÓ¢¹ú¡¢ÃÀ¹ú¡¢½Ý¿Ë¹²ºÍ¹úºÍÏã¸ÛÒøÐеÄÕË»§¡£¡£¡£¡£¡£ ¡£¡£ÕâЩÉúÒâÔÚ30·ÖÖÓÄÚ±»×èÖ¹£¬£¬£¬µ«¹¥»÷ÕßÊÇ·ñÒѾ­»ñµÃ×ʽðÉÐδ»ñµÃ֤ʵ¡£¡£¡£¡£¡£ ¡£¡£¸ÃÒøÐÐÒѾ­¹Ø±ÕÁËÆäϵͳ£¬£¬£¬²¢ÔÝʱ×èÖ¹ÁËËùÓÐÓªÒµ¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤Âí¶úËûʱ±¨µÄ±¨µÀ£¬£¬£¬ÕâÆð¹¥»÷ÊÂÎñ±¬·¢ÔÚ±¾ÖÜÈýÉÏÎç¡£¡£¡£¡£¡£ ¡£¡£¸ÃÒøÐÐÌåÏÖ£¬£¬£¬Ã»Óпͻ§ÕË»§¼°Æä×ʽðÊܵ½Ë𺦡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/02/14/bank-of-valletta-cyber-attack/

5¡¢Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅϢй¶

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÝ˹¶ÙÁ¬Ëø²ÍÌüTruluck¡¯s Seafood, Steak & Crab House±¬·¢Êý¾Ýй¶ÊÂÎñ£¬£¬£¬²¿·Ö¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£ ¡£¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËλÓÚAustin¡¢Houston¡¢Naples¡¢SouthlakeºÍChicagoµÄ8¼Ò²ÍÌü¡£¡£¡£¡£¡£ ¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2018Äê11ÔÂ21ÈÕÖÁ12ÔÂ8ÈÕʱ´ú£¬£¬£¬Æ¾Ö¤TruluckµÄ˵·¨£¬£¬£¬¹¥»÷ÕßÔÚÊÜÓ°Ïì²ÍÌüµÄPoSϵͳÖÐÖ²ÈëÁ˶ñÒâÈí¼þ£¬£¬£¬ÒÔÇÔÈ¡¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾»¹³ÆÐ¹Â¶µÄÐÅÏ¢Öв»°üÀ¨ÈκÎÐÕÃûºÍµØµãÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/trulucks-seafood-steak-crab-house-reports-data-breach-at-8-of-its-restaurants-b1fccc72

ÉùÃ÷£º±¾×ÊѶÓÉ¿­Ê±K66άËûÃüÇ徲С×é·­ÒëºÍÕûÀí