ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ7ÖÜ

Ðû²¼Ê±¼ä 2019-02-18

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe ColdFusion CVE-2019-7091í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Docker runc CVE-2019-5736í§ÒâÏÂÁîÖ´ÐÐÎó²î; Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉýÎó²î£»£»£»£»£»Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬£¬£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£»£»£»£»£»VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý£»£»£»£»£»AZORultľÂíй¥»÷»î¶¯£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû£»£»£»£»£»VallettaÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª£»£»£»£»£»Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅϢй¶¡£¡£¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£

Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe ColdFusion CVE-2019-7091í§Òâ´úÂëÖ´ÐÐÎó²î

Adobe ColdFusionÔÚ·´ÐòÁл¯²»¿ÉÐŵÄÊý¾Ý±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-10.html

2. Docker runc CVE-2019-5736í§ÒâÏÂÁîÖ´ÐÐÎó²î
Docker runcʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¶ñÒâÈÝÆ÷ÐèÖª×ãÒÔÏÂÁ½¸öÌõ¼þÖ®Ò»: (1)ÓÉÒ»¸ö¹¥»÷Õß¿ØÖƵĶñÒâ¾µÏñ½¨Éè(2)¹¥»÷Õß¾ßÓÐijÒѱ£´æÈÝÆ÷µÄдȨÏÞ£¬£¬£¬£¬£¬ÇÒ¿Éͨ¹ýdocker exec½øÈë¡£¡£¡£¡£¡£¡£
https://github.com/docker/docker-ce/releases/tag/v18.09.2

3. Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉýÎó²î
Microsoft Exchange Server×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬Ä£ÄâExchangeЧÀÍÆ÷µÄÆäËûÈκÎÓû§¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0686

4. Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Windows´¦Öóͷ£SMBv2Êý¾Ý±¨Îı£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄSMBv2ÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÄÚºËÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0633

5. Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Office Access Connectivity Engine´¦Öóͷ£Äڴ湤¾ß±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0673

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬£¬£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

°µÍøÊг¡Dream MarketÉÏÕýÔÚ³öÊÛ6.2ÒÚÕË»§ÐÅÏ¢£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢µÁ×Ô16¸öÍøÕ¾£¬£¬£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£¨ÒÔ±ÈÌØ±ÒÖ§¸¶£©¡£¡£¡£¡£¡£¡£ÕâЩ±»µÁÊý¾ÝÉæ¼°µÄÍøÕ¾°üÀ¨Dubsmash£¨1.62ÒÚ£©¡¢MyFitnessPal£¨1.51ÒÚ£©¡¢MyHeritage£¨9200Íò£©¡¢ShareThis£¨4100Íò£©¡¢HauteLook£¨2800Íò£©¡¢Animoto£¨2500Íò£©¡¢EyeEm£¨2200Íò£©¡¢8fit£¨2000Íò£©¡¢Whitepages£¨1800Íò£©¡¢Fotolog£¨1600Íò£©¡¢500px£¨1500Íò£©¡¢Armor Games£¨1100Íò£©¡¢BookMate£¨800Íò£©¡¢CoffeeMeetsBagel£¨600Íò£©¡¢Artsy£¨100Íò£©ºÍDataCamp£¨70Íò£©¡£¡£¡£¡£¡£¡£´ÓÑù±¾Êý¾ÝÀ´¿´£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÖ÷Òª°üÀ¨ÕË»§³ÖÓÐÈ˵ÄÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂ룬£¬£¬£¬£¬µ«²»°üÀ¨ÒøÐп¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/

2¡¢VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


2ÔÂ11ÈÕ£¬£¬£¬£¬£¬µç×ÓÓʼþЧÀÍÉÌVFEmail.netÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ËùÓÐÃÀ¹úЧÀÍÆ÷ÉϵÄÊý¾Ý±»É¾³ý£¬£¬£¬£¬£¬Õâµ¼ÖÂËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷ÕßÃûÌû¯ÁËÿһ̨ЧÀÍÆ÷ÉϵÄÓ²ÅÌ£¬£¬£¬£¬£¬ËùÓеÄÐéÄâ»ú¡¢ÎļþЧÀÍÆ÷°üÀ¨±¸·ÝЧÀÍÆ÷¶¼ÒÑɥʧ¡£¡£¡£¡£¡£¡£ºÚ¿Í²¢Ã»ÓÐÒªÇóÊê½ð£¬£¬£¬£¬£¬VFEmail½«´ËÊÂÎñÐÎòΪ¹¥»÷ºÍÆÆËðÊÂÎñ¡£¡£¡£¡£¡£¡£ÏÖÔڸù«Ë¾µÄÍøÕ¾ÒѾ­ÖØÐÂÉÏÏߣ¬£¬£¬£¬£¬µ«´Î¼¶ÓòÃûÈÔÎÞ·¨»á¼û¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-wipe-us-servers-of-email-provider-vfemail/

3¡¢AZORultľÂíй¥»÷»î¶¯£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Cybaze-Yori ZLAB·¢Ã÷AZORultľÂíµÄй¥»÷»î¶¯£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû¡£¡£¡£¡£¡£¡£¸ÃľÂíбäÌåͨ¹ýαװ³ÉDHL¿ìµÝ֪ͨµÄÓʼþ¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬µ±Óû§·­¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó£¬£¬£¬£¬£¬¾Í»áÏÂÔØ²¢ÔËÐиÃľÂí¡£¡£¡£¡£¡£¡£¸ÃľÂí¿ÉÒÔÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖÐÉúÑĵÄÕË»§ºÍƾ֤£¬£¬£¬£¬£¬²¢¿ÉÒÔ×°ÖÃÆäËüµÄpayload¡£¡£¡£¡£¡£¡£ÆäC2ЧÀÍÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¡£¡£¡£¡£¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931

4¡¢VallettaÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Âí¶úËûVallettaÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼ½«1300ÍòŷԪתÈëÓ¢¹ú¡¢ÃÀ¹ú¡¢½Ý¿Ë¹²ºÍ¹úºÍÏã¸ÛÒøÐеÄÕË»§¡£¡£¡£¡£¡£¡£ÕâЩÉúÒâÔÚ30·ÖÖÓÄÚ±»×èÖ¹£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÊÇ·ñÒѾ­»ñµÃ×ʽðÉÐδ»ñµÃ֤ʵ¡£¡£¡£¡£¡£¡£¸ÃÒøÐÐÒѾ­¹Ø±ÕÁËÆäϵͳ£¬£¬£¬£¬£¬²¢ÔÝʱ×èÖ¹ÁËËùÓÐÓªÒµ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Âí¶úËûʱ±¨µÄ±¨µÀ£¬£¬£¬£¬£¬ÕâÆð¹¥»÷ÊÂÎñ±¬·¢ÔÚ±¾ÖÜÈýÉÏÎç¡£¡£¡£¡£¡£¡£¸ÃÒøÐÐÌåÏÖ£¬£¬£¬£¬£¬Ã»Óпͻ§ÕË»§¼°Æä×ʽðÊܵ½Ë𺦡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/02/14/bank-of-valletta-cyber-attack/

5¡¢Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅϢй¶

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ÐÝ˹¶ÙÁ¬Ëø²ÍÌüTruluck¡¯s Seafood, Steak & Crab House±¬·¢Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËλÓÚAustin¡¢Houston¡¢Naples¡¢SouthlakeºÍChicagoµÄ8¼Ò²ÍÌü¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2018Äê11ÔÂ21ÈÕÖÁ12ÔÂ8ÈÕʱ´ú£¬£¬£¬£¬£¬Æ¾Ö¤TruluckµÄ˵·¨£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÊÜÓ°Ïì²ÍÌüµÄPoSϵͳÖÐÖ²ÈëÁ˶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÒÔÇÔÈ¡¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹³ÆÐ¹Â¶µÄÐÅÏ¢Öв»°üÀ¨ÈκÎÐÕÃûºÍµØµãÐÅÏ¢¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/trulucks-seafood-steak-crab-house-reports-data-breach-at-8-of-its-restaurants-b1fccc72

ÉùÃ÷£º±¾×ÊѶÓÉc7c7ÓéÀÖÆ½Ì¨Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí