EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷,È«ÇòЧÀÍÖÐÖ¹£»£»£»£»£»WappalyzerÔâºÚ¿ÍÈëÇÖ,1.6ÍòÓû§Êý¾Ý±»µÁ

Ðû²¼Ê±¼ä 2020-04-17

1.EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬£¬ £¬£¬£¬£¬£¬È«ÇòЧÀÍÖÐÖ¹


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷£¬£¬ £¬£¬£¬£¬£¬µ¼Ö¸ù«Ë¾µÄЧÀÍÆ÷ÔÚÈ«Çò¹æÄ£ÄÚÍÑ»ú¡£¡£¡£¡£¡£ ¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚ4ÔÂ14ÈÕÏÂÖç4:19¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤Down DetectorµÄʵʱµØÍ¼£¬£¬ £¬£¬£¬£¬£¬´Ë´Î¹¥»÷Ö÷ÒªÓ°ÏìÁËÅ·ÖÞµØÇøµÄ¿Í»§£¬£¬ £¬£¬£¬£¬£¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì¡£¡£¡£¡£¡£ ¡£¡£4ÔÂ15ÈÕÆÆÏþ1µã25·Ö£¬£¬ £¬£¬£¬£¬£¬EA SportsÈϿɸù«Ë¾¡°ÂÄÀúÁËһϵÁÐDDoS¹¥»÷¡±¡£¡£¡£¡£¡£ ¡£¡£ÔÚÐû²¼±¾ÎÄʱ£¬£¬ £¬£¬£¬£¬£¬EA SportsµÄ¿Í»§ÈÔÔÚËß¿àЧÀÍå´»ú£¬£¬ £¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¹«Ë¾ÈÔÔÚÔâÊܹ¥»÷¡£¡£¡£¡£¡£ ¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬ £¬£¬£¬£¬£¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÆÆÏþ4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂÈ«ÇòЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/


2.WappalyzerÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬1.6ÍòÓû§Êý¾Ý±»µÁ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



¿Æ¼¼¹«Ë¾WappalyzerÈ·ÈÏÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬Æä1.6ÍòÓû§ÐÅÏ¢±»µÁ¡£¡£¡£¡£¡£ ¡£¡£WappalyzerÌåÏִ˴κڿÍÈëÇÖ±¬·¢ÔÚ1ÔÂ20ÈÕ£¬£¬ £¬£¬£¬£¬£¬ÆäʱÈëÇÖÕß»á¼ûÁËWappalyzerµÄÒ»¸öÒòÉèÖò»µ±Ì»Â¶ÔÚ¹«ÍøÉϵÄÊý¾Ý¿â¡£¡£¡£¡£¡£ ¡£¡£WappalyzerÊ×´´ÈËElbert AliasÌåÏÖ¸ÃÊý¾ÝÖ÷Òª°üÀ¨¹«Ë¾µÄ¡°ÊÖÒÕÊý¾Ý¡±£¬£¬ £¬£¬£¬£¬£¬µ«Ò²°üÀ¨1.6Íò¿Í»§ÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨µç×ÓÓʼþµØµã¡¢Õ˵¥µØµãµÈ¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÔÚ±¾ÖÜÏòWappalyzerµÄ¿Í»§·¢ËÍÁËÒ»·âµç×ÓÓʼþ£¬£¬ £¬£¬£¬£¬£¬Ðû³ÆÒѾ­»ñµÃÁËWappalyzerµÄÍêÕûÊý¾Ý¿â²¢ÒÔ2000ÃÀÔªµÄ¼ÛÇ®³öÊÛËü¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wappalyzer-discloses-security-breach-after-hacker-starts-emailing-users/


3.ºÚ¿ÍʹÓÃNetWire RATбäÖÖÃé×¼ÃÀ¹úÄÉ˰ÈË


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ºÚ¿ÍʹÓÃNetWire RATµÄбäÖÖÀ´ÇÔÈ¡ÃÀ¹úÄÉ˰ÈËµÄÆ¾Ö¤ºÍ˰ÎñÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£´Ë±äÖÖÖ÷ÒªÊÇʹÓÃÒÔirsΪÖ÷ÌâµÄÍøÂç´¹ÂÚÕ½ÂÔ£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýʹÓÃ΢ÈíExcel 4.0ºêÀ´Ìӱܲ¡¶¾¼à²âºÍÆÊÎö£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒË¢ÐÂÁ˼üÅ̼ͼ³ÌÐòºÍÆ¾Ö¤ÍøÂ繦Ч¡£¡£¡£¡£¡£ ¡£¡£Excel 4.0ÊÇ΢ÈíÔçÆÚ£¨1992Ä꣩Ðû²¼µÄ°æ±¾£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚ΢Èí´ÓδΪExcel 4.0ºêÌṩµ÷ÊÔ¹¦Ð§£¬£¬ £¬£¬£¬£¬£¬Òò´ËÇå¾²Ñо¿Ö°Ô±ÎÞ·¨ÆÊÎöºÍµ÷ÊÔ¶ñÒâºê´úÂë¡£¡£¡£¡£¡£ ¡£¡£ÓÉÓÚ¸ÃÊÖÒÕÒѾ­ºÜ¹ÅÀÏ£¬£¬ £¬£¬£¬£¬£¬Òò´ËʹÓÃExcel 4.0ºê¿ÉÒÔÈÆ¹ý´ó´ó¶¼·À²¡¶¾¼ì²â¡£¡£¡£¡£¡£ ¡£¡£ËäÈ»Excel 4.0ºê֮ǰҲÔÚÆäËü¶ñÒâÈí¼þÖÐʹÓùý£¬£¬ £¬£¬£¬£¬£¬µ«ÔÚNetWire¼Ò×åÖÐÕÕ¾ÉÊ״Ρ£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/taxpayers-targeted-with-improved-netwire-rat-variant/154830/


4.ÐÂIoT½©Ê¬ÍøÂçMozi£¬£¬ £¬£¬£¬£¬£¬Ô¤¼ÆÒÑѬȾ1.5ÍòIoT×°±¸


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


CenturyLinkµÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öеÄIoT½©Ê¬ÍøÂçMozi£¬£¬ £¬£¬£¬£¬£¬MoziÓÉÖÁÉÙÈý¸öÒÑÖªµÄ¶ñÒâÈí¼þ£¨Gafgyt¡¢MiraiºÍIoT Reaper£©µÄÔ´´úÂë×é³É£¬£¬ £¬£¬£¬£¬£¬Ô¤¼ÆÒÑѬȾÁË1.5ÍòIoT×°±¸¡£¡£¡£¡£¡£ ¡£¡£¸Ã½©Ê¬ÍøÂç¿É±»ÓÃÓÚÌᳫDDoS¹¥»÷µÈ¡£¡£¡£¡£¡£ ¡£¡£µ«µ½ÏÖÔÚΪֹ£¬£¬ £¬£¬£¬£¬£¬»¹Ã»ÓÐÐÂÎÅ֤ʵ¸ÃÍøÂçÒѱ»ÓÃÓÚÈκι¥»÷¡£¡£¡£¡£¡£ ¡£¡£MoziÖ÷ÒªÕë¶ÔµÄÊÇδ´ò²¹¶¡µÄ»òÊǾßÓÐÈõÃÜÂëµÄ¼ÒÓ÷ÓÉÆ÷ºÍDVR¡£¡£¡£¡£¡£ ¡£¡£CenturyLink»¹ÌåÏÖ£¬£¬ £¬£¬£¬£¬£¬MoziµÄÆæÒìÖ®´¦»¹°üÀ¨ÆäP2P½á¹¹µÄÌØÕ÷£¬£¬ £¬£¬£¬£¬£¬ÕâʹµÃËü¸üÄѱ»Íêȫɾ³ý¡£¡£¡£¡£¡£ ¡£¡£Æù½ñΪֹ£¬£¬ £¬£¬£¬£¬£¬CenturyLinkÊӲ쵽70%µÄÊÜMoziѬȾµÄIoT×°±¸Î»ÓÚÖйú£¬£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇÃÀ¹ú£¨10%£©ºÍÓ¡¶È£¨10%£©¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/iot/new-malware-family-assembles-iot-botnet--/d/d-id/1337578


5.¹È¸èGmailÒ»ÖÜÄÚ×èÖ¹ÁË1800Íò·âÒÔCOVID-19ΪÖ÷ÌâµÄ´¹ÂÚÓʼþ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¹È¸èÌåÏÖ£¬£¬ £¬£¬£¬£¬£¬GmailÄÚÖõĶñÒâÈí¼þɨÃè³ÌÐòÔÚÉÏÖÜ×èÖ¹ÁËԼĪ1800Íò·âÒÔCOVID-19ΪÖ÷ÌâµÄ´¹ÂÚÓʼþ¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ´¹ÂÚÓʼþ°üÀ¨Ã°³äÌìÏÂÎÀÉú×éÖ¯£¨WHO£©µÈȨÍþÕþ¸®»ú¹¹Æ­È¡¾èÇ®»ò·Ö·¢¶ñÒâÈí¼þ£»£»£»£»£»Õë¶ÔÔڼҰ칫µÄÔ±¹¤¾ÙÐд¹ÂÚ£»£»£»£»£»Î±×°³ÉÕþ¸®»ú¹¹µÄ¾­¼Ã´Ì¼¤ÍýÏëÓÕÆ­ÖÐСÐÍÆóÒµ£»£»£»£»£»Ãé×¼º£ÄÚ¶©µ¥ÊÜÓ°ÏìµÄÆóÒµµÈ¡£¡£¡£¡£¡£ ¡£¡£ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ºÍÓ¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ò²ÓÚ±¾Ô³õÐû²¼ÁËÓйØCOVID-19¹¥»÷µÄÁªºÏ¾¯±¨¡£¡£¡£¡£¡£ ¡£¡£½¨ÒéÓû§ºÍÖÎÀíÔ±½ÓÄÉÏà¹Ø²½·¥ÔöÇ¿¶Ô´ËÀà´¹ÂÚ¹¥»÷µÄ·À»¤¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/gmail-blocked-18m-covid-19-themed-phishing-emails-in-a-week/


6.SAPÐû²¼4ÔÂÇå¾²¸üУ¬£¬ £¬£¬£¬£¬£¬ÐÞ¸´5¸öÒªº¦Îó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


SAP±¾ÖÜÐû²¼ÁË4Ô·ݵÄÇå¾²²¹¶¡£¡£¡£¡£¡£ ¡£¡£¬£¬ £¬£¬£¬£¬£¬×ܹ²ÐÞ¸´ÁË23¸öÎó²î£¬£¬ £¬£¬£¬£¬£¬ÆäÖÐ5¸öΪҪº¦Îó²î¡£¡£¡£¡£¡£ ¡£¡£ÆäÖÐ×îÑÏÖØµÄÒ»¸öÊÇXMLÑé֤ȱʧÎó²î£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²î±»¸ú×ÙΪCVE-2020-6238£¨CVSS 9.3£©£¬£¬ £¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓôËÎó²î¡£¡£¡£¡£¡£ ¡£¡£Æä´ÎSAPÐÞ¸´ÁËSAP NetWeaver ÖеÄĿ¼±éÀúÎó²î£¨CVE-2020-6225£¬£¬ £¬£¬£¬£¬£¬CVSS9.1£©¡¢SAP BusinessObjects Business Intelligence ƽ̨Öеķ´ÐòÁл¯Îó²î£¨CVE-2020-6219£¬£¬ £¬£¬£¬£¬£¬CVSS9.1£©¡¢OrientDB 3.0ÖеĴúÂë×¢ÈëÎó²î£¨ CVE-2020-6230£¬£¬ £¬£¬£¬£¬£¬CVSS9.1£©¡¢SAP Diagnostics AgentÖеÄϵͳÏÂÁî×¢ÈëÎó²î£¨CVE-2019-0330£¬£¬ £¬£¬£¬£¬£¬CVSS9.1£©¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬£¬SAP»¹½â¾öÁËBusiness Objects Business Intelligence Platform¡¢ERP & S/4 HANA¡¢NetWeaver¡¢Fiori Launchpad¡¢Business Client¡¢S/4 HANA¡¢ºÍSAP CommerceÖеĶàÆäÖеÍΣÎó²î


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/saps-april-2020-security-updates-patch-five-critical-vulnerabilities