CloudflareÔٴα¬·¢¹ÊÕÏ£¬£¬£¬£¬ £¬´ó×ÚÍøÕ¾å´»ú£»£»£»£»ÖÇÄܼҾӳ§ÉÌOrviboÒâÍâй¶Áè¼Ý20ÒÚÌõÓû§¼Í¼

Ðû²¼Ê±¼ä 2019-07-03
1¡¢CloudflareÔٴα¬·¢¹ÊÕÏ£¬£¬£¬£¬ £¬´ó×ÚÍøÕ¾å´»ú

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
CDN¼ÓËÙЧÀÍÉÌCloudflareÔÚ±±¾©Ê±¼ä7ÔÂ2ÈÕÍí¼ä·ºÆð´óÃæ»ýå´»ú£¬£¬£¬£¬ £¬Óû§»á¼ûʹÓÃÁËCloudflareµÄÍøÕ¾·ºÆð502¹ýʧ¡£¡£¡£¡£¡£¡£¡£´Ë´Îå´»úÔµ¹ÊÔ­ÓÉÊÇCloudflareÔÚеÄWebÓ¦Óòã·À»ðǽ(WAF£©Öа²ÅÅÁËÒ»¸öÉèÖùýʧµÄ¹æÔò£¬£¬£¬£¬ £¬ÇÒÕâЩ¹æÔòÒ»´ÎÐÔÔÚËùÓнڵãÉϰ²ÅÅ£¬£¬£¬£¬ £¬´Ó¶øµ¼ÖÂÁËÈ«Çò´óÃæ»ýå´»ú¡£¡£¡£¡£¡£¡£¡£¸Ã¹ýʧµÄ¹æÔò°üÀ¨Ò»¸öÕýÔò±í´ïʽ£¬£¬£¬£¬ £¬µ¼ÖÂCloudflareЧÀÍÆ÷ÉϵÄCPUÕ¼ÓÃì­ÉýÖÁ100%¡£¡£¡£¡£¡£¡£¡£ËæºóCloudflare»Ø¹öÁ˹ýʧµÄ¹æÔò£¬£¬£¬£¬ £¬ÏÖÔÚÏà¹ØÐ§ÀÍÒѻָ´Õý³£¡£¡£¡£¡£¡£¡£¡£ÕâÒѾ­ÊÇCloundflare±¾Ôµڶþ´Î·ºÆðå´»úÊÂÎñ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.cloudflare.com/cloudflare-outage/

2¡¢ÖÇÄܼҾӳ§ÉÌOrviboÒâÍâй¶Áè¼Ý20ÒÚÌõÓû§¼Í¼

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
vpnMentorÑо¿Ö°Ô±·¢Ã÷ÖÇÄܼҾӳ§ÉÌOrviboµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬ £¬ÆäÖÐй¶ÁËÁè¼Ý20ÒÚÌõÓû§¼Í¼¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Óû§ÈÕÖ¾£¬£¬£¬£¬ £¬ÐÅÏ¢±»Ð¹Â¶µÄÓû§À´×ÔÖйú¡¢ÈÕ±¾¡¢Ì©¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢Ä«Î÷¸ç¡¢·¨¹ú¡¢°Ä´óÀûÑǺͰÍÎ÷¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨µç×ÓÓʼþµØµã¡¢ÃÜÂë¡¢ÕÊ»§ÖØÖôúÂ롢׼ȷµÄµØÀíλÖá¢IPµØµã¡¢Óû§ÃûºÍÓû§ID¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÃÜÂëΪδ¼ÓÑεÄMD5¹þÏ£ÃûÌᣡ£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬ £¬Êý¾Ý¿âÖл¹°üÀ¨¼ÒÍ¥ID¡¢¼ÒÍ¥Ãû³Æ¡¢¹ØÁªÖÇÄÜ×°±¸ÐÅÏ¢ºÍÍýÏëʹÃüµÈ¡£¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢¿ÉÄܱ»ÓÃÀ´ÓÀÊÀËø¶¨Óû§µÄÕË»§¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-of-smart-home-vendor-exposes-billions-of-records-23f3a56b

3¡¢×ôÖÎÑÇÖÝÒ»¼Ò·¨Ôº»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬Ð§ÀÍÆ÷ÒÑå´»ú

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
×ôÖÎÑÇÖÝÒ»¼Ò·¨Ôº»ú×é³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬£¬ £¬·¨ÔºÐÐÕþ°ì¹«ÊÒ£¨AOC£©µÄЧÀÍÆ÷ÓÉÓÚÔ⵽δ֪µÄÀÕË÷Èí¼þ¹¥»÷¶øå´»ú¡£¡£¡£¡£¡£¡£¡£¸Ã·¨Ôº»ú¹¹Îª×ôÖÎÑÇÖݵÄÕþ¸®¡¢ÒÅÖöÈÏÖ¤¡¢µØÒªÁìÔººÍÊз¨ÔºÌṩ֧³Ö¡£¡£¡£¡£¡£¡£¡£AOC½²»°ÈËBruce Shaw¸æËßýÌ壬£¬£¬£¬ £¬ÊÖÒÕÖ°Ô±ÔÚ·¢Ã÷¹¥»÷ºó¸ôÀëÁ˸ûú¹¹µÄЧÀÍÆ÷£¬£¬£¬£¬ £¬²¢ÇжÏÁËÓëÍâ½çÍøÂçµÄÁªÏµ£¬£¬£¬£¬ £¬µ«²»È·¶¨Óм¸¶àÅÌËã»úϵͳ»òЧÀÍÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÉÐδ·¢Ã÷¹¥»÷µÄÏà¹ØÊÖÒÕϸ½Ú£¬£¬£¬£¬ £¬ÀýÈçÀÕË÷Èí¼þµÄÀàÐͺ͹¥»÷ÖÐʹÓõÄѬȾҪÁì¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/georgias-court-agency-becomes-latest-victim-of-ransomware-attack-21cb56e6

4¡¢OceanLotusй¥»÷»î¶¯£¬£¬£¬£¬ £¬·Ö·¢RatsnifľÂí±äÖÖ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
CylanceÑо¿ÍŶӷ¢Ã÷Ô½ÄÏAPT×éÖ¯OceanLotus·Ö·¢RatsnifбäÖֵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¹²¼ì²âµ½Ëĸö²î±ðµÄRatsnifľÂíÑù±¾£¬£¬£¬£¬ £¬ÆäÖÐÈý¸öÊÇÔÚ2016Ä꿪·¢µÄ£¬£¬£¬£¬ £¬µÚËĸöÔòÊÇÔÚ2018ÄêϰëÄ꽨ÉèµÄ¡£¡£¡£¡£¡£¡£¡£µÚËĸöÑù±¾µÄ¹¦Ð§°üÀ¨Êý¾Ý°üÐá̽¡¢ARPÓÕÆ­¡¢DNSÓÕÆ­¡¢HTTPÖØ¶¨Ïò¡¢MacÓÕÆ­ÒÔ¼°Ô¶³Ìshell¡£¡£¡£¡£¡£¡£¡£ÆäÊý¾Ý°üÐá̽¹¦Ð§×ÅÖØÓÚͨ¹ýЭÒéÆÊÎöÌáÈ¡µÇ¼ƾ֤ºÍÆäËûÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/new-ratsnif-trojan-variant-emerges-in-new-wave-of-attacks-by-oceanlotus-apt-group-14daab88

5¡¢¹È¸èÐû²¼7ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ¸´30¶à¸öÎó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
¹È¸èµÄ7ÔÂAndroidÇå¾²¸üаüÀ¨2019-07-01ºÍ2019-07-05Á½¸ö²¹¶¡°ü£¬£¬£¬£¬ £¬¹²ÐÞ¸´30¶à¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇýÌå¿ò¼ÜÖеÄÎó²î£¬£¬£¬£¬ £¬¸ÃÎó²î£¨CVE-2019-2106¡¢CVE-2019-2107¡¢CVE-2019-2109£©¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÖÆÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÑÏÖØÎó²î£¨CVE-2019-2111£©±£´æÓÚϵͳ×é¼þÖУ¬£¬£¬£¬ £¬¸ÃÎó²îͬÑù¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£ÆäËüÎó²î»¹°üÀ¨ÏµÍ³×é¼þÖеÄËĸöÐÅϢй¶Îó²î£¨CVE-2019-2116~CVE-2019-2119£©ºÍÁ½¸öÌáȨÎó²î£¨CVE-2019-2112¡¢CVE-2019-2113£©µÈ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://news.softpedia.com/news/google-releases-july-2019-s-android-security-patch-to-fix-over-30-security-flaws-526582.shtml

6¡¢SICKÐÞ¸´MSC800Ä£¿£¿£¿£¿£¿£¿é»¯¿ØÖÆÆ÷ÖеÄÓ²±àÂëÆ¾Ö¤Îó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Ñо¿Ö°Ô±·¢Ã÷µÂ¹ú´«¸ÐÆ÷ÖÆÔìÉÌSICKµÄMSC800Ä£¿£¿£¿£¿£¿£¿é»¯ÏµÍ³¿ØÖÆÆ÷±£´æÓ²±àÂëÆ¾Ö¤Îó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-10979£©¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÖØÐÂÉèÖÿØÖÆÆ÷µÄÉèÖûòÆÆËðÆä¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¾ÝÃÀ¹úÁìÍÁÇå¾²²¿£¨DHS£©³Æ£¬£¬£¬£¬ £¬ÊÜÓ°ÏìµÄ¿ØÖÆÆ÷ÔÚÈ«Çò¹æÄ£ÄÚʹÓ㬣¬£¬£¬ £¬ÌØÊâÊÇÔÚÒªº¦ÖÆÔìÁìÓò¡£¡£¡£¡£¡£¡£¡£ÔÚ×î½üÐû²¼µÄÒ»·ÝÇ徲ת´ïÖУ¬£¬£¬£¬ £¬SICKÌåÏÖ²¢Î´·¢Ã÷ÈκÎʹÓôËÎó²îµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ¹Ì¼þ°æ±¾4.0¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/hardcoded-credentials-expose-sick-controllers-remote-attacks