ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ16ÖÜ
Ðû²¼Ê±¼ä 2019-04-22±¾ÖÜÇ徲̬ÊÆ×ÛÊö
¹²ÊÕ¼Çå¾²Îó²î46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAtlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀúÎó²î£»Sangfor Sundray WLAN ControllerȨÏÞÌáÉýÎó²î; GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉýÎó²î£»Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç³öÎó²î£»Cloud Foundry Cloud Controller APIÑéÖ¤Îó²î¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
Ö÷ÒªÇå¾²Îó²îÁбí
Atlassian Confluence ServerºÍAtlassian Data Center downloadallattachments×ÊÔ´±£´æ·¾¶±éÀúÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÉó²éϵͳÎļþÄÚÈÝ¡£
https://jira.atlassian.com/browse/CONFSERVER-58102
2. Sangfor Sundray WLAN ControllerȨÏÞÌáÉýÎó²î
Sundray WLAN Controller nginx_webconsole.php±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɶÁÈ¡adminÃÜÂ룬»ñȡȨÏÞ¡£
https://nvd.nist.gov/vuln/detail/CVE-2019-9161
3. GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉýÎó²î
GitLab impersonate user¹¦Ð§±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÌáÉýÓû§È¨ÏÞ¡£
https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/
4. Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç³öÎó²î
Delta Electronics Delta Industrial Automation CNCSoft±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§Òâ´úÂë»ò¾ÙÐоܾø·þÎñ¹¥»÷¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01
Cloud Foundry Cloud Controller APIÑé֤ʵÏÖ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£
https://www.cloudfoundry.org/blog/cve-2019-3798
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

΢Èí֤ʵ1ÔÂ1ÈÕÖÁ3ÔÂ29ÈÕʱ´ú¹¥»÷ÕßÈëÇÖÁËÒ»¸ö¿Í»§Ö§³ÖÊðÀíÕË»§£¬²¢Ê¹ÓøÃÕË»§»á¼ûÁË¿Í»§Ö§³ÖÃÅ»§ÍøÕ¾¼°²¿·ÖOutLookÓû§µÄÏà¹ØÐÅÏ¢¡£ÕâЩÐÅÏ¢°üÀ¨µç×ÓÓʼþµØµã¡¢Îļþ¼ÐÃû³Æ¡¢ÓʼþÖ÷Ìâ¼°ÁªÏµÈ˵ç×ÓÓʼþµØµã£¬µ«²»°üÀ¨Óʼþ¼°¸½¼þµÄÄÚÈÝ¡£ÏÖÔÚÉв»ÇåÎú¹¥»÷µÄÏêϸϸ½Ú£¬µ«Î¢ÈíÌåÏÖÒѾ½ûÓÃÁ˸ÃÊðÀíÕË»§µÄƾ֤£¬²¢Í¨ÖªËùÓÐÊÜÓ°ÏìµÄÓû§¡£Î¢ÈíҲûÓÐ͸¶ÊÜÓ°ÏìµÄÓû§×ÜÊý¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/microsoft-outlook-email-hack.html
2¡¢Gnosticplayers³öÊÛµÚÎåÅúÓû§Êý¾Ý£¬°üÀ¨6500¶àÍò¸öÕ˺Å
ÔÎÄÁ´½Ó£º
https://cyware.com/news/gnosticplayers-hacker-returns-with-fifth-dataset-containing-over-65-million-user-accounts-for-sale-95450e99
3¡¢³¬´ó¹æÄ£¶ñÒâ¹ã¸æÔ˶¯£¬Ð®ÖÆ5ÒÚiOSÓû§»á»°
Çå¾²³§ÉÌConfiant·¢Ã÷·¸·¨ÍÅ»ïeGobblerÌᳫÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¹ã¸æÔ˶¯£¬ÒÑЮÖÆ5ÒÚiOSÓû§µÄ»á»°¡£¸Ã¹¥»÷Ô˶¯´Ó4ÔÂ6ÈÕ×îÏÈ£¬Ò»Á¬ÁË6ÌìµÄʱ¼ä£¬¹¥»÷ÕßʹÓÃÁË8¸ö²î±ðµÄ¶ñÒâ¹ã¸æϵÁкÍ30¶à¸öÐéα¹ã¸æ£¬Ã¿¸öÐéα¹ã¸æϵÁеÄÉúÃüÖÜÆÚΪ24-48Сʱ֮¼ä¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§£¬²¢ÔÚ¹¥»÷ÖÐʹÓÃÁËChromeä¯ÀÀÆ÷ÖеÄÎó²îÒÔÈƹýɳºÐ¼ì²â¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĴ¹ÂÚÍøÕ¾£¬¾ÓɶÌÔݵÄÍ£ÁôÖ®ºó£¬ÓÖתÏò.siteÓòÃûµÄ´¹ÂÚÍøÕ¾¡£×Ô4ÔÂ14ÈÕÒÔÀ´£¬ÕâЩ´¹ÂÚÍøÕ¾Ò»Ö±´¦ÓÚ»îԾ״̬¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/
4¡¢JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄСÎÒ˽¼ÒÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/justdial-hacked-data-breach.html
5¡¢FacebookÐÂÊý¾Ý³óÎÅ£¬Î´¾Óû§ÔÊÐíÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË
ÔÚÖÜÈýÐû²¼µÄÒ»·ÝÉùÃ÷ÖУ¬FacebookÌåÏÖ×Ô2016Äê5ÔÂÒÔÀ´¸Ã¹«Ë¾¡°ÎÞÒâ¼ä¡±ÔÚδ¾Óû§ÔÊÐíµÄÇéÐÎÏÂÏò·þÎñÆ÷ÉÏ´«Á˶à´ï150ÍòÓû§µÄµç×ÓÓʼþÁªÏµÈË¡£ÕâÊÇFacebook½üÆÚÃæÁÙµÄһϵÁÐÒþ˽Ïà¹ØÎÊÌâºÍÕùÒéÖеÄ×îÐÂÊÂÎñ¡£FacebookÌåÏÖÒÑÔÚÒ»¸öÔÂÇ°×èÖ¹ÁË¿ÉÒɵĵç×ÓÓʼþÑéÖ¤Àú³Ì£¬²¢ÏòÓû§°ü¹Üδ·ÖÏíÕâЩÁªÏµÈËÐÅÏ¢¼°ÒѾ×îÏÈɾ³ýÕâЩÁªÏµÈË¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/facebook-email-database.html