¹¤ÐŲ¿Ðû²¼¡¶ÍøÂçÇå¾²Îó²îÖÎÀí»®¶¨£¨Õ÷ÇóÒâ¼û¸å£©¡·£»£»£»£»£»WebLogic£¨CVE-2019-2729£©Îó²î²¹¶¡
Ðû²¼Ê±¼ä 2019-06-20
ÔÎÄÁ´½Ó£º
http://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c7005976/content.html2.OracleÐû²¼WebLogic£¨CVE-2019-2729£©Îó²îµÄÐÞ¸´²¹¶¡
OracleÐû²¼WebLogic ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-2729£©µÄ½ôÆÈÐÞ¸´²¹¶¡¡£¡£¡£¡£¸ÃÎó²îÊÇCVE-2019-2725µÄ²¹¶¡Èƹý£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄWebLogic Server°æ±¾Îª10.3.6.0.0¡¢12.1.3.0.0ºÍ12.2.1.3.0¡£¡£¡£¡£ÈôÊÇÎÞ·¨Á¬Ã¦×°ÖÃÐÞ¸´²¹¶¡£¡£¡£¡£¬£¬£¬£¬£¬Ñо¿Ö°Ô±½¨Òé½ÓÄÉÒÔÏ»º½â²½·¥£ºÉ¾³ý¡°wls9_async_response.war¡±ºÍ¡°wls-wsat.war¡±È»ºóÖØÐÂÆô¶¯WebLogicЧÀÍ£»£»£»£»£»¶Ô·¾¶¡°/_async/*¡±ºÍ¡°/wls-wsat/*¡±µÄURL»á¼ûʵÑé»á¼ûÕ½ÂÔ¿ØÖÆ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/oracle-fixes-critical-bug-in-weblogic-server-web-services/3.¶íÀÕ¸ÔÖÝDHSÅû¶2019Äê1ÔµÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬¹²²¨¼°64.5ÍòÈË

¶íÀÕ¸ÔÖÝDHSÏÂÊôµÄÈËÀàЧÀͲ¿Åû¶2019Äê1Ô±¬·¢µÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬¸Ã²¿·ÖÈ·ÈϹ²ÓÐ64.5ÍòÈËÊܵ½Ó°Ï죬£¬£¬£¬£¬¶ø²»ÊÇ֮ǰ3Ô·ÝÅû¶µÄ35ÍòÈË¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂ롢СÎÒ˽¼Ò¿µ½¡ÐÅÏ¢µÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬¶à´ï200Íò·âµç×ÓÓʼþ¿ÉÄÜй¶¡£¡£¡£¡£ÊÓ²ìÈ·ÈÏÓÐ9ÃûÔ±¹¤·¿ªÁË´¹ÂÚÓʼþ²¢»á¼ûÁËÆäÖеÄÁ´½Ó£¬£¬£¬£¬£¬µ¼ÖÂÓÊÏäÕË»§Ð¹Â¶¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/oregon-dhs-notifies-645000-people-of-data-breach-that-occurred-in-january-2019-030ed97c4.2018ÄêÐÂ¼ÓÆÂÆóÒµÒòBECթƹ¥»÷¹²Ëðʧ5800ÍòÐÂÔª
ÔÎÄÁ´½Ó£º
https://www.businessinsider.sg/businesses-in-singapore-lost-nearly-s58-million-to-cyber-attacks-last-year-csa-report/5.ÀÕË÷Èí¼þRyukбäÖÖ£¬£¬£¬£¬£¬ÄÚÖÃIPµØµãºÍÅÌËã»úÃû³ÆµÄºÚÃûµ¥
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-adds-ip-and-computer-name-blacklisting/6.ÐÂÄ£¿£¿£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þPlurox£¬£¬£¬£¬£¬Ö÷Òª·Ö·¢ÍÚ¿óľÂí
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/modular-plurox-malware-is-a-wormable-backdoor-cryptominer/