IBM WebSphereÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-4279£©£»CloudflareºÍAmazon AWSÍøÂçÖжÏ

°ä²¼¹¦·ò 2019-06-27
1¡¢IBM WebSphereÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-4279£©

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
IBM½¨¸´WebSphere Application ServerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-4279£©£¬¹¥»÷Õß¿Éͨ¹ý·¢Ë;«ÐÄ»ú¹ØµÄÐòÁл¯¶ÔÏó´¥·¢¸Ã·ì϶£¬×îÖÕµ¼ÖÂÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬WebSphere Application Server ND°æ±¾9.0ºÍ°æ±¾8.5¡¢WebSphere Virtual Enterprise V7.0¡£ÓÉÓÚ½üÈո÷ì϶µÄ¹¥»÷·½Ê½ÒÑÔÚÒ°±í´«²¼£¬½¨ÒéÓû§ÊµÊ±½øÐзÀ»¤¡£

Ô­ÎÄÁ´½Ó£ºhttps://www-01.ibm.com/support/docview.wss?uid=ibm10883628

2¡¢Android·ÂÕÕÆ÷BlueStacks½¨¸´DNS³Áа󶨷ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«×êÑÐÈËÔ±Nick Cano·¢ÏÖAndroid·ÂÕÕÆ÷BlueStacks´æÔÚDNS³Áа󶨷ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼û·ÂÕÕÆ÷µÄIPCÖ°ÄÜ£¬½ø¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×¢ÐÅϢй¶ÒÔ¼°ÇÔÈ¡VM¼°ÆäÊý¾ÝµÄ±¸·Ý¡£BlueStacksÔÚ5ÔÂ27ÈÕ°ä²¼µÄа汾4.90.0.1046Öн¨¸´Á˸÷ì϶¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bluestacks-flaw-lets-attackers-remotely-control-android-emulator/

3¡¢EAÕË»§½Ù³Ö·ì϶¿Éµ¼ÖÂ3ÒÚÍæ¼ÒÕË»§±»½Ù³Ö

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Check PointºÍCyberIntµÄ×êÑÐÈËÔ±·¢ÏÖEA OriginÓÎϷƽ̨ÖдæÔÚÒ»¸öÕË»§½Ù³Ö·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÊÕÊܶà´ï3ÒÚÍæ¼ÒµÄÕË»§¡£ÎªÁËÀûÓø÷ì϶£¬¹¥»÷ÕßÖ»±ØÒªÊܺ¦Õßµã»÷EAÓÎϷƽ̨µÄºÏ·¨ÍƼöÁ´½Ó¡£¸Ã·ì϶µÄÔ­ÒòÊÇEAµÄÒ»¸ö×ÓÓòÃû±»³Á¶¨Ïòµ½Î¢ÈíAzureÔÆ·þÎñÉϵÄһ̨°Î³ýÖ÷»ú£¬×êÑÐÈËÔ±¿ÉÄܽ«¡°ea-invite-reg.azurewebsites.net¡±ÓòÃû×¢²áΪ×Ô¼ºµÄWebÀûÓ÷þÎñ£¬ÓÉÓÚCNAME¼Í¼ÈÔ´¦Óڻ״̬£¬×êÑÐÈËԱͨ¹ý¸ÃÓòÃû½Ó¹Üµ½ÁËEAÓû§·¢³öµÄËùÓÐÒªÇó¡£½áºÏEA oAuthµ¥µãµÇ¼£¨SSO£©ºÍTRUST»úÔìÖеķì϶£¬×êÑÐÈËÔ±Äܹ»½Ù³ÖÍæ¼ÒµÄÕË»§¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ea-fixes-origin-game-platform-to-prevent-account-takeovers/

4¡¢·ðÂÞÀï´ïÖÝLake CityÏòºÚ¿ÍÖ§¸¶50ÍòÃÀÔªÊê½ð

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
±¾ÖÜÒ»·ðÂÞÀï´ïÖݱ±²¿µÄLake CityÔÞ³ÉÏòºÚ¿ÍÖ§¸¶42±ÈÌØ±Ò£¨Ï൱ÓÚ573300ÃÀÔª£©µÄÊê½ð£¬ÒÔ½âËø³ÇÊеĵ绰ºÍµç×ÓÓʼþϵͳ¡£Lake CityÓÚ6ÔÂ10ÈÕϰȾÀÕË÷²¡¶¾Triple Threat£¬ÆäÍÆËã»úϵͳÒÑÒò¶øÌ±»¾ÁËÁ½ÖÜ¡£¸ÃÊеĹÙԱͶƱ¾ö¶¨ÏòºÚ¿ÍÖ§¸¶Êê½ðÒÔ¸´Ô­³ÁÒªµµ°¸£¬´ó²¿ÃÅÊê½ð½«Óɱ£ÏÕÖ§¸¶£¬µ«½ü1ÍòÃÀÔªÐèÓɲÆÕþ½øÐÐÖ§³ö¡£ÕâÊÇÒ»ÖÜÄÚ·ðÂÞÀï´ïÖݵڶþÆð³ÇÊÐÖ§¸¶Êê½ðµÄÊÂÎñ£¬¼¸ÌìǰRiviera Beach CityÒ²ÏòºÚ¿ÍÖ§¸¶ÁË60ÍòÃÀÔªµÄÊê½ð¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/87621/hacking/lake-city-500k-ransom.html

5¡¢Troldesh¹¥»÷»î¶¯ÔÙ´Îì­Éý£¬Õë¶Ô¶íÂÞ˹¡¢Ä«Î÷¸çºÍÃÀ¹ú

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Avast×êÑÐÔ±Jakub K?oustek·¢ÏÖÀÕË÷Èí¼þTroldeshµÄ¹¥»÷»î¶¯×Ô6ÔÂ24ÈÕÒÔÀ´ÔÙ´Îì­Éý£¬´ïµ½ÁË1Ô·ÝÖ®ºóµÄÓÖÒ»¸ö¶¥·å¡£ÐµĹ¥»÷»î¶¯ÖØÒªÕë¶Ô¶íÂÞ˹¡¢Ä«Î÷¸çºÍÃÀ¹ú£¬AvastÒѾ­×èÖ¹Á˸ÃÀÕË÷Èí¼þµÄ10ÍòÂŴι¥»÷¡£TroldeshÔÚ2018Ä궬¼¾ÖØÒªÍ¨¹ý´¹µöÓʼþ½øÐд«²¼£¬´Ë¿ÌËüÖØÒªÍ¨¹ýÉç½»ÍøÂçµÈÐÂÎÅÆ½Ì¨ÉϵĶñÒâÁ´½Ó½øÐд«²¼¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.avast.com/ransomware-strain-troldesh-spikes

6¡¢BGP·ÓÉй©µ¼ÖÂCloudflareºÍAmazon AWSÍøÂçÖжÏ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
6ÔÂ24ÈÕÓÉÓÚVerizonÃýÎóµØ×ª·¢ÁËBGP·Óɹ㲥£¬µ¼ÖÂÍøÂçÁ÷Á¿±»ÃýÎ󵨵¼ÏòVerizon£¬Ê¹µÃCloudflare¡¢Amazon AWSºÍFacebookµÈ¹«Ë¾µÄ·þÎñÎÞ·¨½Ó¼û¡£ÊÂÎñµÄÆðÒòÊDZöϦ·¨ÄáÑÇÖݵÄÒ»¼ÒÓ×ÐÍISP AS33154-DQE CommunicationsʹÓÃNoctionµÄBGPÓÅ»¯Æ÷ÓÅ»¯ÆäÄÚ²¿ÍøÂçµÄ·ÓÉ£¬µ«ÓÉÓÚÃýÎóÅäÖÃÕâЩ·ÓÉÐÅÏ¢±»ÃýÎ󵨷¢¸øÁËVerizon£¬×îÖÕµ¼Ö´óÁìÓòµÄÍøÂçÖжÏ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/technology/bgp-route-leak-causes-cloudflare-and-amazon-aws-problems/