IBM WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-4279£©£»CloudflareºÍAmazon AWSÍøÂçÖÐÖ¹

Ðû²¼Ê±¼ä 2019-06-27
1¡¢IBM WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-4279£©

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
IBMÐÞ¸´WebSphere Application ServerÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-4279£©£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÈ«ÐĽṹµÄÐòÁл¯¹¤¾ß´¥·¢¸ÃÎó²î£¬×îÖÕµ¼ÖÂÔÚ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨WebSphere Application Server ND°æ±¾9.0ºÍ°æ±¾8.5¡¢WebSphere Virtual Enterprise V7.0¡£ÓÉÓÚ¿ËÈÕ¸ÃÎó²îµÄ¹¥»÷·½·¨ÒÑÔÚÒ°ÍâÈö²¥£¬½¨ÒéÓû§ÊµÊ±¾ÙÐзÀ»¤¡£

Ô­ÎÄÁ´½Ó£ºhttps://www-01.ibm.com/support/docview.wss?uid=ibm10883628

2¡¢AndroidÄ£ÄâÆ÷BlueStacksÐÞ¸´DNSÖØÐ°ó¶¨Îó²î

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
Çå¾²Ñо¿Ö°Ô±Nick Cano·¢Ã÷AndroidÄ£ÄâÆ÷BlueStacks±£´æDNSÖØÐ°ó¶¨Îó²î£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î»á¼ûÄ£ÄâÆ÷µÄIPC¹¦Ð§£¬½ø¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС¢ÐÅϢй¶ÒÔ¼°ÇÔÈ¡VM¼°ÆäÊý¾ÝµÄ±¸·Ý¡£BlueStacksÔÚ5ÔÂ27ÈÕÐû²¼µÄа汾4.90.0.1046ÖÐÐÞ¸´Á˸ÃÎó²î¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bluestacks-flaw-lets-attackers-remotely-control-android-emulator/

3¡¢EAÕË»§Ð®ÖÆÎó²î¿Éµ¼ÖÂ3ÒÚÍæ¼ÒÕË»§±»Ð®ÖÆ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
Check PointºÍCyberIntµÄÑо¿Ö°Ô±·¢Ã÷EA OriginÓÎϷƽ̨Öб£´æÒ»¸öÕË»§Ð®ÖÆÎó²î£¬¿ÉÔÊÐí¹¥»÷Õß½ÓÊܶà´ï3ÒÚÍæ¼ÒµÄÕË»§¡£ÎªÁËʹÓøÃÎó²î£¬¹¥»÷ÕßÖ»ÐèÒªÊܺ¦Õßµã»÷EAÓÎϷƽ̨µÄÕýµ±ÍƼöÁ´½Ó¡£¸ÃÎó²îµÄÔµ¹ÊÔ­ÓÉÊÇEAµÄÒ»¸ö×ÓÓòÃû±»Öض¨Ïòµ½Î¢ÈíAzureÔÆ·þÎñÉϵÄһ̨·ÅÆúÖ÷»ú£¬Ñо¿Ö°Ô±Äܹ»½«¡°ea-invite-reg.azurewebsites.net¡±ÓòÃû×¢²áΪ×Ô¼ºµÄWebÓ¦Ó÷þÎñ£¬ÓÉÓÚCNAME¼Í¼ÈÔ´¦ÓÚÔ˶¯×´Ì¬£¬Ñо¿Ö°Ô±Í¨¹ý¸ÃÓòÃûÎüÊÕµ½ÁËEAÓû§·¢³öµÄËùÓÐÇëÇó¡£ÍŽáEA oAuthµ¥µãµÇ¼£¨SSO£©ºÍTRUST»úÖÆÖеÄÎó²î£¬Ñо¿Ö°Ô±¿ÉÒÔÐ®ÖÆÍæ¼ÒµÄÕË»§¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ea-fixes-origin-game-platform-to-prevent-account-takeovers/

4¡¢·ðÂÞÀï´ïÖÝLake CityÏòºÚ¿ÍÖ§¸¶50ÍòÃÀÔªÊê½ð

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
±¾ÖÜÒ»·ðÂÞÀï´ïÖݱ±²¿µÄLake CityÔÞ³ÉÏòºÚ¿ÍÖ§¸¶42±ÈÌØ±Ò£¨Ï൱ÓÚ573300ÃÀÔª£©µÄÊê½ð£¬ÒÔ½âËø¶¼»áµÄµç»°ºÍµç×ÓÓʼþϵͳ¡£Lake CityÓÚ6ÔÂ10ÈÕѬȾÀÕË÷²¡¶¾Triple Threat£¬ÆäÅÌËã»úϵͳÒÑÒò´Ë̱»¾ÁËÁ½ÖÜ¡£¸ÃÊеĹÙԱͶƱ¾öÒéÏòºÚ¿ÍÖ§¸¶Êê½ðÒÔ»Ö¸´Ö÷Òªµµ°¸£¬´ó²¿·ÖÊê½ð½«Óɰü¹ÜÖ§¸¶£¬µ«½ü1ÍòÃÀÔªÐèÓɲÆÎñ¾ÙÐÐÖ§³ö¡£ÕâÊÇÒ»ÖÜÄÚ·ðÂÞÀï´ïÖݵڶþÆð¶¼»áÖ§¸¶Êê½ðµÄÊÂÎñ£¬¼¸ÌìǰRiviera Beach CityÒ²ÏòºÚ¿ÍÖ§¸¶ÁË60ÍòÃÀÔªµÄÊê½ð¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/87621/hacking/lake-city-500k-ransom.html

5¡¢Troldesh¹¥»÷Ô˶¯ÔÙ´Îì­Éý£¬Õë¶Ô¶íÂÞ˹¡¢Ä«Î÷¸çºÍÃÀ¹ú

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
AvastÑо¿Ô±Jakub K?oustek·¢Ã÷ÀÕË÷Èí¼þTroldeshµÄ¹¥»÷Ô˶¯×Ô6ÔÂ24ÈÕÒÔÀ´ÔÙ´Îì­Éý£¬µÖ´ïÁË1Ô·ÝÖ®ºóµÄÓÖÒ»¸öá¯Áë¡£ÐµĹ¥»÷Ô˶¯Ö÷ÒªÕë¶Ô¶íÂÞ˹¡¢Ä«Î÷¸çºÍÃÀ¹ú£¬AvastÒѾ­×èÖ¹Á˸ÃÀÕË÷Èí¼þµÄ10Íò¶à´Î¹¥»÷¡£TroldeshÔÚ2018Ä궬¼¾Ö÷Ҫͨ¹ý´¹ÂÚÓʼþ¾ÙÐÐÈö²¥£¬ÏÖÔÚËüÖ÷Ҫͨ¹ýÉç½»ÍøÂçµÈÐÂÎÅÆ½Ì¨ÉϵĶñÒâÁ´½Ó¾ÙÐÐÈö²¥¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.avast.com/ransomware-strain-troldesh-spikes

6¡¢BGP·ÓÉ×ß©µ¼ÖÂCloudflareºÍAmazon AWSÍøÂçÖÐÖ¹

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
6ÔÂ24ÈÕÓÉÓÚVerizon¹ýʧµØ×ª·¢ÁËBGP·Óɹ㲥£¬µ¼ÖÂÍøÂçÁ÷Á¿±»¹ýʧµØµ¼ÏòVerizon£¬Ê¹µÃCloudflare¡¢Amazon AWSºÍFacebookµÈ¹«Ë¾µÄ·þÎñÎÞ·¨»á¼û¡£ÊÂÎñµÄÒòÓÉÊDZöϦ·¨ÄáÑÇÖݵÄÒ»¼ÒСÐÍISP AS33154-DQE CommunicationsʹÓÃNoctionµÄBGPÓÅ»¯Æ÷ÓÅ»¯ÆäÄÚ²¿ÍøÂçµÄ·ÓÉ£¬µ«ÓÉÓÚ¹ýʧÉèÖÃÕâЩ·ÓÉÐÅÏ¢±»¹ýʧµØ·¢¸øÁËVerizon£¬×îÖÕµ¼Ö´ó¹æÄ£µÄÍøÂçÖÐÖ¹¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/technology/bgp-route-leak-causes-cloudflare-and-amazon-aws-problems/