CloudflareÔٴη¢×÷¹ÊÕÏ£¬£¬£¬£¬£¬´óÁ¿ÍøÕ¾å´»ú£»£»£»£»£»ÖÇÄܼҾӳ§ÉÌOrviboÒâ±íй¶³¬¹ý20ÒÚÌõÓû§¼Í¼

°ä²¼¹¦·ò 2019-07-03
1¡¢CloudflareÔٴη¢×÷¹ÊÕÏ£¬£¬£¬£¬£¬´óÁ¿ÍøÕ¾å´»ú

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
CDN¼Ó¿ì·þÎñÉÌCloudflareÔÚ±±¾©¹¦·ò7ÔÂ2ÈÕÍí¼ä³öÏÖ´óÃæ»ýå´»ú£¬£¬£¬£¬£¬Óû§½Ó¼ûʹÓÃÁËCloudflareµÄÍøÕ¾³öÏÖ502ÃýÎ󡣡£¡£¡£¡£¡£Õâ´Îå´»úÔ­ÒòÊÇCloudflareÔÚеÄWebÀûÓòã·À»ðǽ(WAF£©Öв¿ÊðÁËÒ»¸öÅäÖÃÃýÎóµÄ¹æ¶¨£¬£¬£¬£¬£¬ÇÒÕâЩ¹æ¶¨Ò»´ÎÐÔÔÚËùÓнڵãÉϲ¿Ê𣬣¬£¬£¬£¬´Ó¶øµ¼ÖÂÁËÈ«Çò´óÃæ»ýå´»ú¡£¡£¡£¡£¡£¡£¸ÃÃýÎóµÄ¹æ¶¨Ô̺¬Ò»¸öÕýÔò±í°×ʽ£¬£¬£¬£¬£¬µ¼ÖÂCloudflare·þÎñÆ÷ÉϵÄCPUÕ¼ÓÃì­ÉýÖÁ100%¡£¡£¡£¡£¡£¡£ËæºóCloudflare»Ø¹öÁËÃýÎóµÄ¹æ¶¨£¬£¬£¬£¬£¬Ä¿Ç°ÓйطþÎñÒѸ´Ô­Õý³£¡£¡£¡£¡£¡£¡£ÕâÒѾ­ÊÇCloundflare±¾Ôµڶþ´Î³öÏÖå´»úÊÂÎñ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.cloudflare.com/cloudflare-outage/

2¡¢ÖÇÄܼҾӳ§ÉÌOrviboÒâ±íй¶³¬¹ý20ÒÚÌõÓû§¼Í¼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
vpnMentor×êÑÐÈËÔ±·¢ÏÖÖÇÄܼҾӳ§ÉÌOrviboµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬ÆäÖÐй¶Á˳¬¹ý20ÒÚÌõÓû§¼Í¼¡£¡£¡£¡£¡£¡£Æ¾¾ÝÓû§ÈÕÖ¾£¬£¬£¬£¬£¬ÐÅÏ¢±»Ð¹Â¶µÄÓû§À´×ÔÖйú¡¢ÈÕ±¾¡¢Ì©¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢Ä«Î÷¸ç¡¢·¨¹ú¡¢°Ä´óÀûÑǺͰÍÎ÷¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÃÜÂë¡¢ÕÊ»§³ÁÖôúÂë¡¢¾«È·µÄµØÀíµØÎ»¡¢IPµØÖ·¡¢Óû§ÃûºÍÓû§ID¡£¡£¡£¡£¡£¡£ÆäÖÐÃÜÂëΪδ¼ÓÑεÄMD5¹þÏ£Ìåʽ¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬Êý¾Ý¿âÖл¹Ô̺¬¼ÒÍ¥ID¡¢¼ÒÍ¥Ãû³Æ¡¢¹ØÁªÖÇÄÜÉ豸ÐÅÏ¢ºÍ´òË㹤×÷µÈ¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢¿ÉÄܱ»ÓÃÀ´ÓÀÔ¶Ëø¶¨Óû§µÄÕË»§¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-of-smart-home-vendor-exposes-billions-of-records-23f3a56b

3¡¢×ôÖÎÑÇÖÝÒ»¼Ò·¨Ôº»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬·þÎñÆ÷ÒÑå´»ú

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
×ôÖÎÑÇÖÝÒ»¼Ò·¨Ôº»ú×é³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£¾Ý±¨Â·£¬£¬£¬£¬£¬·¨ÔºÐÐÕþ°ì¹«ÊÒ£¨AOC£©µÄ·þÎñÆ÷ÓÉÓÚÔ⵽δ֪µÄÀÕË÷Èí¼þ¹¥»÷¶øå´»ú¡£¡£¡£¡£¡£¡£¸Ã·¨Ôº»ú¹¹Îª×ôÖÎÑÇÖÝÈ·µ±¾Ö¡¢ÒÅÖöÈÏÖ¤¡¢´¦Ëù·¨ÔººÍÊз¨ÔºÌṩ֧³Ö¡£¡£¡£¡£¡£¡£AOC½²»°ÈËBruce Shaw֪ͨýÌ壬£¬£¬£¬£¬¼¼ÊõÈËÔ±ÔÚ·¢ÏÖ¹¥»÷ºó¸ôÀëÁ˸ûú¹¹µÄ·þÎñÆ÷£¬£¬£¬£¬£¬²¢¶Â½ØÁËÓë±í½çÍøÂçµÄÁªÏµ£¬£¬£¬£¬£¬µ«²»È·¶¨Óм¸¶àÍÆËã»úϵͳ»ò·þÎñÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÉÐδ·¢ÏÖ¹¥»÷µÄÓйؼ¼Êõϸ½Ú£¬£¬£¬£¬£¬ÀýÈçÀÕË÷Èí¼þµÄÀàÐͺ͹¥»÷ÖÐʹÓõÄϰȾ²½Öè¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/georgias-court-agency-becomes-latest-victim-of-ransomware-attack-21cb56e6

4¡¢OceanLotusй¥»÷»î¶¯£¬£¬£¬£¬£¬·Ö·¢RatsnifľÂí±äÖÖ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
Cylance×êÑÐÍŶӷ¢ÏÖÔ½ÄÏAPT×éÖ¯OceanLotus·Ö·¢RatsnifбäÖֵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±¹²¼ì²âµ½Ëĸö·ÖÆçµÄRatsnifľÂíÑù±¾£¬£¬£¬£¬£¬ÆäÖÐÈý¸öÊÇÔÚ2016Ä꿪·¢µÄ£¬£¬£¬£¬£¬µÚËĸöÔòÊÇÔÚ2018ÄêϰëÄê´´½¨µÄ¡£¡£¡£¡£¡£¡£µÚËĸöÑù±¾µÄÖ°ÄÜÔ̺¬Êý¾Ý°üÐá̽¡¢ARPºýŪ¡¢DNSºýŪ¡¢HTTP³Á¶¨Ïò¡¢MacºýŪÒÔ¼°Ô¶³Ìshell¡£¡£¡£¡£¡£¡£ÆäÊý¾Ý°üÐáְ̽Äܲà³ÁÓÚͨ¹ýºÍ̸½âÎöÌáÈ¡µÇ¼ʹ´¦ºÍÆäËûÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/new-ratsnif-trojan-variant-emerges-in-new-wave-of-attacks-by-oceanlotus-apt-group-14daab88

5¡¢¹È¸è°ä²¼7ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬½¨¸´30¶à¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
¹È¸èµÄ7ÔÂAndroid°²È«¸üÐÂÔ̺¬2019-07-01ºÍ2019-07-05Á½¸ö²¹¶¡°ü£¬£¬£¬£¬£¬¹²½¨¸´30¶à¸ö·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇýÌå¿ò¼ÜÖеķì϶£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2019-2106¡¢CVE-2019-2107¡¢CVE-2019-2109£©¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÔìÎļþÔÚÌØÈ¨¹ý³ÌµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÑϳÁ·ì϶£¨CVE-2019-2111£©´æÔÚÓÚϵͳ×é¼þÖУ¬£¬£¬£¬£¬¸Ã·ì϶ͬÑù¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£ÆäËü·ì϶»¹Ô̺¬ÏµÍ³×é¼þÖеÄËĸöÐÅϢй¶·ì϶£¨CVE-2019-2116~CVE-2019-2119£©ºÍÁ½¸öÌáȨ·ì϶£¨CVE-2019-2112¡¢CVE-2019-2113£©µÈ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://news.softpedia.com/news/google-releases-july-2019-s-android-security-patch-to-fix-over-30-security-flaws-526582.shtml

6¡¢SICK½¨¸´MSC800Ä £¿£¿£¿£¿£¿£¿é»¯½ÚÔìÆ÷ÖеÄÓ²±àÂëÍ´´¦·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
×êÑÐÈËÔ±·¢Ïֵ¹ú´«¸ÐÆ÷Ôì×÷ÉÌSICKµÄMSC800Ä £¿£¿£¿£¿£¿£¿é»¯ÏµÍ³½ÚÔìÆ÷´æÔÚÓ²±àÂëÍ´´¦·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-10979£©¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß³ÁÐÂÅäÖýÚÔìÆ÷µÄÉèÖûò·ÛËéÆäÖ°ÄÜ¡£¡£¡£¡£¡£¡£¾ÝÃÀ¹úºÓɽ°²È«Êý£¨DHS£©³Æ£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ½ÚÔìÆ÷ÔÚÈ«ÇòÁìÓòÄÚʹÓ㬣¬£¬£¬£¬³ö¸ñÊÇÔڹؼüÔì×÷ÁìÓò¡£¡£¡£¡£¡£¡£ÔÚ×î½ü°ä²¼µÄÒ»·Ý°²È«´«µÝÖУ¬£¬£¬£¬£¬SICK°µÊ¾²¢Î´·¢ÏÖÈκÎÀûÓô˷ì϶µÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ¹Ì¼þ°æ±¾4.0¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/hardcoded-credentials-expose-sick-controllers-remote-attacks