ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ18ÖÜ
Ðû²¼Ê±¼ä 2019-05-05±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê4ÔÂ29ÈÕÖÁ5ÔÂ05ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Archiva CVE-2019-0214ÈÎÒâÎļþ䩶´£»Oracle WebLogic Server wls9_async_response·´ÐòÁл¯ÃüÁîÖ´ÐЩ¶´; Microsoft Visual Studio asmÄÚ´æ´úÂë´úÂëÖ´ÐЩ¶´£»Apple macOS Mojave APFS×é¼þÊͷźóʹÓÃÌØȨÌáÉý©¶´£»Foxit Reader AcroForm removeField CVE-2019-6768ÊͷźóʹÓôúÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇMalwarebytes LabsÐû²¼2019ÄêQ1ÍøÂç·¸×ï¼ÆıºÍ¼¼Êõ³ÂËߣ»Ð³ÂËß±íÃ÷2018Äê»ùÓÚÉ罻ýÌåµÄÆÛÕ©»î¶¯Ôö³¤43%£»¿¨°Í˹»ùÐû²¼2019ÄêQ1 APT¹¥»÷Ç÷ÊƳÂËߣ»ÃÀ¹úÕÐƸÍøÕ¾LaddersÒâÍâй¶½ü1300ÍòÇóÖ°ÕߵĸöÈË×ÊÁÏ£»Å·ÖÞÐ̾¯×éÖ¯µ·»Ù°µÍøÊг¡Wall Street MarketºÍSilkkitie¡£
ÖØÒªÄþ¾²Â©¶´Áбí
1. Apache Archiva CVE-2019-0214ÈÎÒâÎļþ䩶´
https://seclists.org/bugtraq/2019/Apr/48
2. Oracle WebLogic Server wls9_async_response·´ÐòÁл¯ÃüÁîÖ´ÐЩ¶´
Oracle Weblogic Server wls9_async_response´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://medium.com/@knownseczoomeye/knownsec-404-team-oracle-weblogic-deserialization-rce-vulnerability-0day-alert-90dd9a79ae93
3. Microsoft Visual Studio asmÄÚ´æ´úÂë´úÂëÖ´ÐЩ¶´
Microsoft Visual Studio __asm¿é±àÒë´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-448/
4. Apple macOS Mojave APFS×é¼þÊͷźóʹÓÃÌØȨÌáÉý©¶´
Apple macOS Mojave APFS×é¼þ´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÄÚºËÉÏÏÂÎÄÖ´ÐУ¬ÌáÉýȨÏÞ¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-422/
5. Foxit Reader AcroForm removeField CVE-2019-6768ÊͷźóʹÓôúÂëÖ´ÐЩ¶´
Foxit Reader´¦ÖÃAcroFormµÄremoveFieldÒªÁì´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-442/
ÖØÒªÄþ¾²Ê¼þ×ÛÊö

Malwarebytes LabsÐû²¼2019ÄêµÚÒ»¼¾¶ÈµÄÍøÂç·¸×ï¼ÆıÓë¼¼Êõ³ÂËߣ¬¸Ã³ÂËßÖ¸³öÆóÒµÔÚµÚÒ»¼¾¶ÈÔâÊܵÄÍþвÔö³¤ÁË235%£¬ÓÈÆäÊÇEmotetµÈľÂíºÍÀÕË÷Èí¼þÍþв¡£Õë¶Ô¸öÈËÏû·ÑÕߵĶñÒâÈí¼þÍþвϽµÁ˽ü40%¡£Òƶ¯É豸ºÍMacÉ豸ԽÀ´Ô½³ÉΪ¹ã¸æÈí¼þµÄÄ¿±ê£¬Mac¶ñÒâÈí¼þ´Ó2018ÄêQ4µ½2019ÄêQ1Ôö³¤ÁË60%£¬¹ã¸æÈí¼þÔòÔö³¤ÁË200%¡£ÔÚÈ«ÇòÍþв¼ì²âÂÊÖÐÃÀ¹ú×î¸ß£¬Îª47£¥£¬Ó¡¶ÈÄáÎ÷ÑÇΪ9£¥£¬°ÍÎ÷Ϊ8£¥¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/cybercrime/2019/04/labs-cybercrime-tactics-and-techniques-report-finds-businesses-hit-with-235-percent-more-threats-in-q1/
2¡¢Ð³ÂËß±íÃ÷2018Äê»ùÓÚÉ罻ýÌåµÄÆÛÕ©»î¶¯Ôö³¤43%
ƾ¾ÝRSA SecurityÐû²¼µÄ¡¶2019ÄêÍøÂç·¸×ïÏÖ×´°×ƤÊé¡·£¬ÍøÂç·¸×ï·Ö×ÓÔ½À´Ô½ÒÀÀµFacebook¡¢Instagram¡¢WhatsAppµÈÉ罻ýÌåºÍÁÄÌìƽ̨½øÐÐÏàͬ¡¢ÏúÊÛ±»µÁƾ¾ÝºÍÐÅÓÿ¨ÐÅÏ¢µÈ·¸×ïÐÐΪ¡£»ùÓÚÉ罻ýÌåµÄÆÛÕ©»î¶¯ÔÚ2018ÄêÔö³¤43%¡£´ËÍ⣬2015ÄêÖÁ2018ÄêÒƶ¯APPµÄÆÛÕ©ÐÐΪÔö³¤ÁË680%¡£2018ÄêRSAÔÚ¸÷´óÖ÷Á÷Ó¦Ó÷¨Ê½É̵êÖÐƽ¾ùÿÌì·¢ÏÖ82¸ö¶ñÒâAPP¡£
ÔÎÄÁ´½Ó£º
https://telecom.economictimes.indiatimes.com/news/social-media-fraud-increased-43-in-2018-report/69089489
3¡¢¿¨°Í˹»ùÐû²¼2019ÄêQ1 APT¹¥»÷Ç÷ÊƳÂËß
½üÄêÀ´£¬Õë¶ÔÄ¿±êµÄ¹©Ó¦Á´¹¥»÷ÒѾ֤Ã÷·Ç³£ÀÖ³É - ShadowPad£¬CCleanerºÍExPetr¾ÍÊǺܺõÄÀý×Ó¡£ÔÚÎÒÃǶÔ2019ÄêµÄÍþвԤ²âÖУ¬ÎÒÃǽ«´Ë±ê־Ϊ¿ÉÄÜÁ¬ÐøµÄ¹¥»÷ÏòÁ¿; ÎÒÃÇûÓÐÐëÒªµÈºÜ³¤Ê±¼ä²ÅÆø¿´µ½Õâ¸öÔ¤²â³ÉÕæ¡£1Ô·ݣ¬ÎÒÃÇ·¢ÏÖÁËÉæ¼°»ªË¶Live Update UtilityµÄÅÓ´ó¹©Ó¦Á´¹¥»÷£¬ÓÃÓÚÏò»ªË¶Ìõ¼Ç±¾µçÄÔºĮ́ʽ»úÌṩBIOS£¬UEFIºÍÈí¼þ¸üеĻúÖÆ¡£¡°ShadowHammer²Ù×÷¡±±³ºóµÄ¹¥»÷ÕßΪ¸ÃʵÓ÷¨Ê½Ìí¼ÓÁËÒ»¸öºóÃÅ£¬È»ºóͨ¹ý¹Ù·½ÇþµÀ½«Æä·Ö·¢¸øÓû§¡£¹¥»÷µÄÄ¿±êÊǾ«È·¶¨Î»ÓÉÆäÍøÂçÊÊÅäÆ÷MACµØÖ·±êʶµÄδ֪Óû§³Ø¡£·¢ÏÖ¹¥»÷ÕßÒѽ«Ò»ÏµÁÐMACµØÖ·Ó²±àÂëµ½ÌØÂåÒÁľÂí»¯Ñù±¾ÖУ¬´ú±íÁËÕâÒ»´ó¹æÄ£Ðж¯µÄÕæÕýÄ¿±ê¡£ÎÒÃÇÄܹ»´ÓÕâ´Î¹¥»÷Öз¢ÏÖµÄ200¶à¸öÑù±¾ÖÐÌáÈ¡600¶à¸öΨһµÄMACµØÖ·£¬¾¡¹Ü´æÔÚÕë¶Ô²îÒìMACµØÖ·µÄÆäËüÑù±¾¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/apt-trends-report-q1-2019/90643/
4¡¢ÃÀ¹úÕÐƸÍøÕ¾LaddersÒâÍâй¶½ü1300ÍòÇóÖ°ÕߵĸöÈË×ÊÁÏ
Äþ¾²Ñо¿ÈËÔ±Sanyam Jain·¢ÏÖÁËÒ»¸öδÊܱ£»¤µÄAWSÍйܵÄElasticsearchÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âÊôÓÚÕÐƸÍøÕ¾Ladders£¬ÓÉÓÚȱ·¦Éí·ÝÑéÖ¤£¬¸ÃÊý¾Ý¿â̻¶Á˽ü1300ÍòÇóÖ°ÕßµÄÊý¾Ý¡£°üÂÞÇóÖ°ÕߵĸöÈËÐÅÏ¢£¬ÈçÐÕÃû£¬µç×ÓÓʼþµØÖ·£¬µç»°ºÅÂëÒÔ¼°»ùÓÚIPµØÖ·µÄ´óÖµØÀíλÖá£Ëü»¹°üÂÞÆäËüÃô¸ÐÐÅÏ¢£¬Èç¾ÍÒµÀúÊ·£¬ÊÂÇéÃèÊö£¬ÊÂÇéÅâ³¥£¬ËûÃÇÕýÔÚÑ°ÕÒÊÂÇéµÄÐÐÒµ£¬ËûÃÇÊÇÃÀ¹ú¹«Ãñ»¹ÊÇÇ©Ö¤£¬ÈçH1-B £¬ºÍÆäËü¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/job-portal-ladders-exposed-profiles-of-13-million-job-seekers-thanks-to-an-unprotected-aws-elasticsearch-database-1b7d7474
5¡¢Å·ÖÞÐ̾¯×éÖ¯µ·»Ù°µÍøÊг¡Wall Street MarketºÍSilkkitie
Ö´·¨»ú¹¹³Æ£¬µÂ¹ú¾¯·½¹Ø±ÕWall Street Market£¬¾Ý³ÆÕâÊÇÊÀ½çÉϵڶþ´ó°µÍøÂçÊг¡£¬ÏÖÔÚÄêÔçЩʱºò£¬·ÒÀ¼¹Ø±ÕSilkkitie¡£¾Ý͸¶£¬µÂ¹ú¾¯·½´þ²¶ÁË3ÃûÏÓÒÉÈ˲¢¿ÛѺÁË55ÍòÅ·ÔªµÄÏÖ½ð£¬ÒÔ¼°ÁùλÊýµÄ¼ÓÃÜ»õ±Ò£¬³µÁ¾£¬¼ÆËã»ú£¬´æ´¢É豸ºÍÆäËûÖ¤¾Ý¡£ÃÀ¹úÕþ¸®´þ²¶ÁËÁ½Ãû¾Ý³ÆÔÚ¸ÃÍøÕ¾ÉÏÔËÓªµÄÖ÷Òª¶¾··¡£ÕâÁ½ÏîÊÓ²ìÏÔʾÁ˹ú¼Ê²ãÃæÖ´·¨ºÏ×÷µÄÖØÒªÐÔ£¬²¢Ö¤Ã÷°µÍøÉϵķǷ¨»î¶¯²¢²»Ïñ×ï·¸ËùÏëµÄÄÇÑùÄäÃû¡£Ä¿Ç°»¹²»Çå³þÖ´·¨»î¶¯ÊÇ·ñÓë¸ÃÍøÕ¾¹ÜÀíÔ±ÊÔͼÍ˳öթƻÓйء£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/europol-two-more-dark-web-1/