ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ7ÖÜ

°ä²¼¹¦·ò 2019-02-18

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö £¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe ColdFusion CVE-2019-7091ËÁÒâ´úÂëÖ´Ðзì϶£» £»£»£»£»£»Docker runc CVE-2019-5736ËÁÒâºÅÁîÖ´Ðзì϶; Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉý·ì϶£» £»£»£»£»£»Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´Ðзì϶£» £»£»£»£»£»Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£ ¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍøÏúÊÛ £¬£¬£¬£¬£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£» £»£»£»£»£»VFEmail.netÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý£» £»£»£»£»£»AZORultľÂíй¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒâ´óÀû£» £»£»£»£»£»VallettaÒøÐÐÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª£» £»£»£»£»£»Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬£¬²¿Ãſͻ§µÄÖ§¸¶ÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£ ¡£¡£¡£¡£

³ÁÒª°²È«·ì϶Áбí


1. Adobe ColdFusion CVE-2019-7091ËÁÒâ´úÂëÖ´Ðзì϶

Adobe ColdFusionÔÚ·´ÐòÁл¯²»³ÉÐŵÄÊý¾Ý´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-10.html

2. Docker runc CVE-2019-5736ËÁÒâºÅÁîÖ´Ðзì϶
Docker runcʵÏÖ´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬£¬£¬£¬ÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£¶ñÒâÈÝÆ÷ÐèÂú×ãÒÔÏÂÁ½¸öǰÌáÖ®Ò»: (1)ÓÉÒ»¸ö¹¥»÷Õß½ÚÔìµÄ¶ñÒâ¾µÏñ´´½¨(2)¹¥»÷ÕßÓµÓÐijÒÑ´æÔÚÈÝÆ÷µÄдȨÏÞ £¬£¬£¬£¬£¬£¬£¬ÇÒ¿Éͨ¹ýdocker exec½øÈë¡£¡£¡£¡£ ¡£¡£¡£¡£
https://github.com/docker/docker-ce/releases/tag/v18.09.2

3. Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉý·ì϶
Microsoft Exchange Server×é¼þ´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬£¬£¬£¬Ä£ÄâExchange·þÎñÆ÷µÄÆäËûÈκÎÓû§¡£¡£¡£¡£ ¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0686

4. Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Windows´¦ÖÃSMBv2Êý¾Ý±¨ÎÄ´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄSMBv2ÒªÇó £¬£¬£¬£¬£¬£¬£¬Äܹ»Äں˸ߵÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0633

5. Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Office Access Connectivity Engine´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ £¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö £¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£» £»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0673

 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍøÏúÊÛ £¬£¬£¬£¬£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

°µÍøÊг¡Dream MarketÉÏÔÚÏúÊÛ6.2ÒÚÕË»§ÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢µÁ×Ô16¸öÍøÕ¾ £¬£¬£¬£¬£¬£¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£¨ÒÔ±ÈÌØ±ÒÖ§¸¶£©¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ±»µÁÊý¾ÝÉæ¼°µÄÍøÕ¾Ô̺¬Dubsmash£¨1.62ÒÚ£©¡¢MyFitnessPal£¨1.51ÒÚ£©¡¢MyHeritage£¨9200Íò£©¡¢ShareThis£¨4100Íò£©¡¢HauteLook£¨2800Íò£©¡¢Animoto£¨2500Íò£©¡¢EyeEm£¨2200Íò£©¡¢8fit£¨2000Íò£©¡¢Whitepages£¨1800Íò£©¡¢Fotolog£¨1600Íò£©¡¢500px£¨1500Íò£©¡¢Armor Games£¨1100Íò£©¡¢BookMate£¨800Íò£©¡¢CoffeeMeetsBagel£¨600Íò£©¡¢Artsy£¨100Íò£©ºÍDataCamp£¨70Íò£©¡£¡£¡£¡£ ¡£¡£¡£¡£´ÓÑù±¾Êý¾ÝÀ´¿´ £¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÖØÒªÔ̺¬ÕË»§³ÖÓÐÈ˵ÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂë £¬£¬£¬£¬£¬£¬£¬µ«²»Ô̺¬ÒøÐп¨ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/

2¡¢VFEmail.netÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2ÔÂ11ÈÕ £¬£¬£¬£¬£¬£¬£¬µç×ÓÓʼþ·þÎñÉÌVFEmail.netÔâµ½ºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬£¬ËùÓÐÃÀ¹ú·þÎñÆ÷ÉϵÄÊý¾Ý±»É¾³ý £¬£¬£¬£¬£¬£¬£¬Õâµ¼ÖÂËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÌåʽ»¯ÁËÿһ̨·þÎñÆ÷ÉϵÄÓ²ÅÌ £¬£¬£¬£¬£¬£¬£¬ËùÓеÄÐé¹¹»ú¡¢Îļþ·þÎñÆ÷Ô̺¬±¸·Ý·þÎñÆ÷¶¼ÒÑÃÔʧ¡£¡£¡£¡£ ¡£¡£¡£¡£ºÚ¿Í²¢Ã»ÓÐÒªÇóÊê½ð £¬£¬£¬£¬£¬£¬£¬VFEmail½«´ËÊÂÎñÃèÊöΪ¹¥»÷ºÍ·ÛËéÊÂÎñ¡£¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°¸Ã¹«Ë¾µÄÍøÕ¾ÒѾ­³ÁÐÂÉÏÏß £¬£¬£¬£¬£¬£¬£¬µ«´Î¼¶ÓòÃûÈÔÎÞ·¨½Ó¼û¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-wipe-us-servers-of-email-provider-vfemail/

3¡¢AZORultľÂíй¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒâ´óÀû

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Cybaze-Yori ZLAB·¢ÏÖAZORultľÂíµÄй¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒâ´óÀû¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃľÂíбäÌåͨ¹ý¼Ù×°³ÉDHL¿ìµÝ֪ͨµÄÓʼþ½øÐд«²¼ £¬£¬£¬£¬£¬£¬£¬µ±Óû§´ò¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó £¬£¬£¬£¬£¬£¬£¬¾Í»áÏÂÔØ²¢ÔËÐиÃľÂí¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃľÂíÄܹ»ÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖб£ÁôµÄÕË»§ºÍÍ´´¦ £¬£¬£¬£¬£¬£¬£¬²¢Äܹ»×°ÖÃÆäËüµÄpayload¡£¡£¡£¡£ ¡£¡£¡£¡£ÆäC2·þÎñÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931

4¡¢VallettaÒøÐÐÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Âí¶úËûVallettaÒøÐÐÔâµ½ºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼ½«1300ÍòŷԪתÈëÓ¢¹ú¡¢ÃÀ¹ú¡¢½Ý¿Ë¹²ºÍ¹úºÍÏã¸ÛÒøÐеÄÕË»§¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÂòÂôÔÚ30·ÖÖÓÄÚ±»×èÖ¹ £¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÊÇ·ñÒѾ­»ñµÃ×ʽðÉÐδµÃµ½Ö¤Êµ¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÒøÐÐÒѾ­¹Ø¹ØÁËÆäϵͳ £¬£¬£¬£¬£¬£¬£¬²¢ÁÙʱÖÕ³¡ÁËËùÓÐÒµÎñ¡£¡£¡£¡£ ¡£¡£¡£¡£Æ¾¾ÝÂí¶úËûʱ±¨µÄ±¨Â· £¬£¬£¬£¬£¬£¬£¬ÕâÆð¹¥»÷ÊÂÎñ²úÉúÔÚ±¾ÖÜÈýÉÏÎç¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÒøÐаµÊ¾ £¬£¬£¬£¬£¬£¬£¬Ã»Óпͻ§ÕË»§¼°Æä×ʽðÊܵ½ÇÖº¦¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/02/14/bank-of-valletta-cyber-attack/

5¡¢Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬£¬²¿Ãſͻ§µÄÖ§¸¶ÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÐÝ˹¶ÙÁ¬Ëø²ÍÌüTruluck¡¯s Seafood, Steak & Crab House²úÉúÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬£¬£¬²¿Ãſͻ§µÄÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËλÓÚAustin¡¢Houston¡¢Naples¡¢SouthlakeºÍChicagoµÄ8¼Ò²ÍÌü¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÔÚ2018Äê11ÔÂ21ÈÕÖÁ12ÔÂ8ÈÕÆÚ¼ä £¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝTruluckµÄ˵·¨ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÊÜÓ°Ïì²ÍÌüµÄPoSϵͳÖÐÖ²ÈëÁ˶ñÒâÈí¼þ £¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡¿Í»§µÄÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾»¹³ÆÐ¹Â¶µÄÐÅÏ¢Öв»Ô̺¬ÈκÎÐÕÃûºÍµØÖ·ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/trulucks-seafood-steak-crab-house-reports-data-breach-at-8-of-its-restaurants-b1fccc72

ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù