ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ7ÖÜ

Ðû²¼Ê±¼ä 2019-02-18

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe ColdFusion CVE-2019-7091ÈÎÒâ´úÂëÖ´ÐЩ¶´£»Docker runc CVE-2019-5736ÈÎÒâÃüÁîÖ´ÐЩ¶´; Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉý©¶´£»Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´ÐЩ¶´¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£»VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý£»AZORultľÂíй¥»÷»î¶¯£¬Ö÷ÒªÕë¶ÔÒâ´óÀû£»VallettaÒøÐÐÔâºÚ¿Í¹¥»÷£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª£»Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅ¿Í»§µÄÖ§¸¶ÐÅϢй¶¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£

ÖØÒªÄþ¾²Â©¶´Áбí


1. Adobe ColdFusion CVE-2019-7091ÈÎÒâ´úÂëÖ´ÐЩ¶´

Adobe ColdFusionÔÚ·´ÐòÁл¯²»ÐÐÐŵÄÊý¾Ý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-10.html

2. Docker runc CVE-2019-5736ÈÎÒâÃüÁîÖ´ÐЩ¶´
Docker runcʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔrootÉí·ÝÖ´ÐÐÈÎÒâ´úÂë¡£¶ñÒâÈÝÆ÷ÐèÂú×ãÒÔÏÂÁ½¸öÌõ¼þÖ®Ò»: (1)ÓÉÒ»¸ö¹¥»÷Õß¿ØÖƵĶñÒâ¾µÏñ´´½¨(2)¹¥»÷Õß¾ßÓÐijÒÑ´æÔÚÈÝÆ÷µÄдȨÏÞ£¬ÇÒ¿Éͨ¹ýdocker exec½øÈë¡£
https://github.com/docker/docker-ce/releases/tag/v18.09.2

3. Microsoft Exchange Server CVE-2019-0686Ô¶³ÌȨÏÞÌáÉý©¶´
Microsoft Exchange Server×é¼þ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Ä£ÄâExchange·þÎñÆ÷µÄÆäËûÈκÎÓû§¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0686

4. Microsoft Windows SMB Server SMBv2 CVE-2019-0633Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Windows´¦ÖÃSMBv2Êý¾Ý±¨ÎÄ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄSMBv2ÇëÇ󣬿ÉÒÔÄÚºËÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0633

5. Microsoft Office Access Connectivity Engine CVE-2019-0673Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Office Access Connectivity Engine´¦ÖÃÄڴ湤¾ß´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0673

 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°µÍøÊг¡Dream MarketÉÏÕýÔÚ³öÊÛ6.2ÒÚÕË»§ÐÅÏ¢£¬ÕâЩÐÅÏ¢µÁ×Ô16¸öÍøÕ¾£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£¨ÒÔ±ÈÌرÒÖ§¸¶£©¡£ÕâЩ±»µÁÊý¾ÝÉæ¼°µÄÍøÕ¾°üÂÞDubsmash£¨1.62ÒÚ£©¡¢MyFitnessPal£¨1.51ÒÚ£©¡¢MyHeritage£¨9200Íò£©¡¢ShareThis£¨4100Íò£©¡¢HauteLook£¨2800Íò£©¡¢Animoto£¨2500Íò£©¡¢EyeEm£¨2200Íò£©¡¢8fit£¨2000Íò£©¡¢Whitepages£¨1800Íò£©¡¢Fotolog£¨1600Íò£©¡¢500px£¨1500Íò£©¡¢Armor Games£¨1100Íò£©¡¢BookMate£¨800Íò£©¡¢CoffeeMeetsBagel£¨600Íò£©¡¢Artsy£¨100Íò£©ºÍDataCamp£¨70Íò£©¡£´ÓÑù±¾Êý¾ÝÀ´¿´£¬ÕâЩÊý¾ÝÖ÷Òª°üÂÞÕË»§³ÖÓÐÈ˵ÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂ룬µ«²»°üÂÞÒøÐп¨ÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/

2¡¢VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2ÔÂ11ÈÕ£¬µç×ÓÓʼþ·þÎñÉÌVFEmail.netÔâµ½ºÚ¿Í¹¥»÷£¬ËùÓÐÃÀ¹ú·þÎñÆ÷ÉϵÄÊý¾Ý±»É¾³ý£¬Õâµ¼ÖÂËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾¡£¸Ã¹«Ë¾ÌåÏÖ£¬¹¥»÷Õ߸ñʽ»¯ÁËÿһ̨·þÎñÆ÷ÉϵÄÓ²ÅÌ£¬ËùÓеÄÐéÄâ»ú¡¢Îļþ·þÎñÆ÷°üÂÞ±¸·Ý·þÎñÆ÷¶¼ÒѶªÊ§¡£ºÚ¿Í²¢Ã»ÓÐÒªÇóÊê½ð£¬VFEmail½«´ËʼþÃèÊöΪ¹¥»÷ºÍÆÆ»µÊ¼þ¡£Ä¿Ç°¸Ã¹«Ë¾µÄÍøÕ¾ÒѾ­ÖØÐÂÉÏÏߣ¬µ«´Î¼¶ÓòÃûÈÔÎÞ·¨·ÃÎÊ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-wipe-us-servers-of-email-provider-vfemail/

3¡¢AZORultľÂíй¥»÷»î¶¯£¬Ö÷ÒªÕë¶ÔÒâ´óÀû

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cybaze-Yori ZLAB·¢ÏÖAZORultľÂíµÄй¥»÷»î¶¯£¬Ö÷ÒªÕë¶ÔÒâ´óÀû¡£¸ÃľÂíбäÌåͨ¹ýαװ³ÉDHL¿ìµÝ֪ͨµÄÓʼþ½øÐÐÁ÷´«£¬µ±Óû§´ò¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó£¬¾Í»áÏÂÔز¢ÔËÐиÃľÂí¡£¸ÃľÂí¿ÉÒÔÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖÐÉú´æµÄÕË»§ºÍƾ¾Ý£¬²¢¿ÉÒÔ°²×°ÆäËüµÄpayload¡£ÆäC2·þÎñÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931

4¡¢VallettaÒøÐÐÔâºÚ¿Í¹¥»÷£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Âí¶úËûVallettaÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬¹¥»÷ÕßÊÔͼ½«1300ÍòŷԪתÈëÓ¢¹ú¡¢ÃÀ¹ú¡¢½Ý¿Ë¹²ºÍ¹úºÍÏã¸ÛÒøÐеÄÕË»§¡£ÕâЩ½»Ò×ÔÚ30·ÖÖÓÄÚ±»×èÖ¹£¬µ«¹¥»÷ÕßÊÇ·ñÒѾ­»ñµÃ×ʽðÉÐδµÃµ½Ö¤Êµ¡£¸ÃÒøÐÐÒѾ­¹Ø±ÕÁËÆäϵͳ£¬²¢ÔÝʱֹͣÁËËùÓÐÒµÎñ¡£Æ¾¾ÝÂí¶úËûʱ±¨µÄ±¨µÀ£¬ÕâÆð¹¥»÷ʼþ·¢ÉúÔÚ±¾ÖÜÈýÉÏÎç¡£¸ÃÒøÐÐÌåÏÖ£¬Ã»Óпͻ§ÕË»§¼°Æä×ʽðÊܵ½Ë𺦡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/02/14/bank-of-valletta-cyber-attack/

5¡¢Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅ¿Í»§µÄÖ§¸¶ÐÅϢй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÝ˹¶ÙÁ¬Ëø²ÍÌüTruluck¡¯s Seafood, Steak & Crab House·¢ÉúÊý¾Ýй¶Ê¼þ£¬²¿ÃÅ¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢±»ÇÔ¡£ÕâһʼþÓ°ÏìÁËλÓÚAustin¡¢Houston¡¢Naples¡¢SouthlakeºÍChicagoµÄ8¼Ò²ÍÌü¡£¸Ãʼþ·¢ÉúÔÚ2018Äê11ÔÂ21ÈÕÖÁ12ÔÂ8ÈÕÆڼ䣬ƾ¾ÝTruluckµÄ˵·¨£¬¹¥»÷ÕßÔÚÊÜÓ°Ïì²ÍÌüµÄPoSϵͳÖÐÖ²ÈëÁ˶ñÒâÈí¼þ£¬ÒÔÇÔÈ¡¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢¡£¸Ã¹«Ë¾»¹³Æ鶵ÄÐÅÏ¢Öв»°üÂÞÈκÎÐÕÃûºÍµØÖ·ÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/trulucks-seafood-steak-crab-house-reports-data-breach-at-8-of-its-restaurants-b1fccc72

ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí