·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨»á¼û

Ðû²¼Ê±¼ä 2023-05-08

1¡¢·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨»á¼û


¾ÝýÌå5ÔÂ5ÈÕ±¨µÀ £¬·¨¹ú²ÎÒéÔºµÄÍøÕ¾ÒòÔâµ½ºÚ¿Í×éÖ¯NoNameµÄDDoS¹¥»÷¶ø¹Ø±Õ¡£·¨¹ú²ÎÒéÔº5ÈÕÐû²¼Ò»ÌõÍÆÎÄ³Æ £¬×Ôµ±ÈÕÔçÉÏÒÔÀ´ £¬²ÎÒéÔºµÄÍøÕ¾Ò»Ö±ÎÞ·¨»á¼û £¬ÆäÍŶÓÒÑÖÜÈ«·¢¶¯ÆðÀ´½â¾öÎÊÌâ¡£NoNameÔÚTelegramÉÏÐû²¼Á˶Է¨¹úµÄ¶à¸ö×éÖ¯Ìᳫ¹¥»÷ £¬°üÀ¨·¨¹ú²ÎÒéÔº¡¢·¨¹ú¹ú¼ÒÀ͹¤¾ÍÒµºÍÖ°ÒµÅàѵÑо¿Ëù¡¢·¨¹ú¹ú¼Ò¿Õ¼äÑо¿ÖÐÐĺͷ¨¹ú¹ú·À¹«Ë¾Ë®Ê¦¼¯ÍÅ¡£


https://www.securityweek.com/pro-russian-hackers-claim-downing-of-french-senate-website/


2¡¢Western Digital͸¶ÈýÔµÄÍøÂç¹¥»÷й¶²¿·ÖÓû§Êý¾Ý


ýÌå5ÔÂ7ÈÕ³Æ £¬Western DigitalÊÓ²ìÈ·ÈϹ¥»÷ÕßÔÚÈýÔ·ݵÄÍøÂç¹¥»÷ÖÐÇÔÈ¡Á˲¿·ÖСÎÒ˽¼ÒÐÅÏ¢¡£¸Ã¹«Ë¾ÌåÏÖ £¬3ÔÂ26ÈÕǰºó £¬Î´¾­ÊÚȨµÄµÚÈý·½»ñµÃÁËWestern DigitalÊý¾Ý¿âµÄ¸±±¾ £¬ÆäÖаüÀ¨ÔÚÏßÊÐËÁÓû§µÄÐÅÏ¢¡£Western DigitalÔÚÊÓ²ì´ËÊÂÎñµÄͬʱÒѽ«ÆäÊÐËÁÏÂÏß £¬ÏÖÔÚÊÐËÁ½öÏÔʾһÌõÐÂÎÅ¡°ÎÒÃǺܿì¾Í»á»ØÀ´£ºÎÒÃÇÏÖÔÚÎÞ·¨´¦Öóͷ£¶©µ¥¡£¡±¸Ã¹«Ë¾Ô¤¼Æ½«ÓÚ5ÔÂ15ÈÕ»Ö¸´¶ÔÊÐËÁµÄ»á¼û¡£TechCrunch±¨µÀ³Æ £¬Ä³²»×ÅÃûÍÅ»ïÈëÇÖÁËWestern Digital £¬²¢Éù³ÆÇÔÈ¡ÁË10 TBÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/western-digital-says-hackers-stole-customer-data-in-march-cyberattack/


3¡¢¼ÓÀû¸£ÄáÑÇijÊо¯·½ÔâÀÕË÷¹¥»÷ÒѸ¶110ÍòÃÀÔªÊê½ð


¾Ý5ÔÂ6ÈÕ±¨µÀ £¬¼ÓÀû¸£ÄáÑÇÖÝÊ¥±´ÄɵÏŵÊеÄÖΰ²²¿·ÖÔâµ½ÀÕË÷¹¥»÷ £¬²¢Ñ¡Ôñ¸¶110ÍòÃÀÔªÊê½ð¡£¹¥»÷±¬·¢ÔÚ4ÔÂ7ÈÕ £¬µ¼Ö¾¯Ô±¾Ö±»ÆÈ¹Ø±ÕÁ˲¿·Öϵͳ £¬Ó°ÏìÁ˵ç×ÓÓʼþ¡¢³µÔصçÄÔºÍһЩִ·¨Êý¾Ý¿âµÈ¡£ÏÖÔÚ £¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¾Ý¡¶Âåɼí¶Ê±±¨¡·±¨µÀ £¬¸ÃÊÐÒÑΪ´ËÀ๥»÷Ͷ±£ £¬Ëü½öÐ踶Êê½ð×ܶîµÄÒ»°ë£¨511852ÃÀÔª£© £¬ÆäÓಿ·ÖÓɰü¹Ü¹«Ë¾¼ç¸º¡£ÔÚÓëºÚ¿Í̸Åкó £¬°ü¹Ü¹«Ë¾ºÍ¸ÃÊÐÔÞ³ÉÖ§¸¶ÓöÈÒÔ»Ö¸´ÏµÍ³µÄËùÓй¦Ð§ºÍÇå¾²Êý¾Ý¡£


https://abc7.com/san-bernardino-cyberattack-ransom-paid-hackers/13215833/


4¡¢FortinetÐû²¼Çå¾²¸üÐÂÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄ9¸öÎó²î


5ÔÂ3ÈÕ £¬FortinetÐû²¼Çå¾²¸üР£¬ÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄ9¸öÎó²î¡£ÆäÖаüÀ¨Á½¸ö½ÏΪÑÏÖØÎó²î £¬FortiADCÖÐÍⲿ×ÊÔ´Ä £¿éÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2023-27999£© £¬¹¥»÷Õß¿Éͨ¹ýÌØÖÆµÄ²ÎÊýÀ´Ö´ÐÐδ¾­ÊÚȨµÄÏÂÁî¡£ÒÔ¼°FortiOSºÍFortiProxyµÄsslvpnd×é¼þÖеÄÔ½½çдÈëÎó²î£¨CVE-2023-22640£© £¬¿Éͨ¹ýÏò×°±¸·¢ËÍÌØÖÆµÄÇëÇóʹÓøÃÎó²î £¬À´Ö´ÐÐí§Òâ´úÂë¡£ÏÖÔÚÉв»ÇåÎúÕâЩÎó²îÊÇ·ñÒѱ»Ò°ÍâʹÓá£


https://securityaffairs.com/145825/security/fortinet-fortiadc-fortios-flaws.html


5¡¢AndroidÐÞ¸´ÄÚºËÖб»Ê¹ÓõÄÌáȨÎó²îCVE-2023-0266


5ÔÂ5ÈÕ±¨µÀ³Æ £¬±¾ÔÂÐû²¼µÄAndroidÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÑÏÖØµÄÎó²î£¨CVE-2023-0266£©¡£ÕâÊÇLinuxÄÚºËÉùÒô×ÓϵͳÖеÄÊͷźóʹÓÃÎó²î £¬¿ÉÄܻᵼÖÂȨÏÞÌáÉýÇÒÎÞÐèÓû§½»»¥¡£Æ¾Ö¤Google TAGÔÚ3Ô·ÝÐû²¼µÄ±¨¸æ £¬Õë¶ÔÈýÐÇAndroidÊÖ»úµÄÌØ¹¤Ô˶¯ÖÐ £¬¸ÃÎó²î±»×÷Ϊ¶à¸ö0-dayºÍn-day¹¥»÷Á´µÄÒ»²¿·Ö¡£±ðµÄ £¬±¾ÔµÄÇå¾²¸üл¹ÐÞ¸´ÁËÆäËü¼¸Ê®¸öÎó²î¡£


https://www.bleepingcomputer.com/news/security/new-android-updates-fix-kernel-bug-exploited-in-spyware-attacks/


6¡¢McAfeeÅû¶Amadey½üÆÚ¶à½×¶Î¹¥»÷ºÍ·Ö·¢µÄÔ˶¯


5ÔÂ5ÈÕ £¬McAfeeÅû¶ÁËAmadey×îеĶà½×¶Î¹¥»÷Ô˶¯ºÍ¶ñÒâÈí¼þ·Ö·¢Ô˶¯¡£Ñо¿Ö°Ô±·¢Ã÷½üÆÚWextract.exeÑù±¾ÓÐËùÔöÌí £¬Ëü±»ÓÃÓÚ¶àÖÖ¶ñÒâÈí¼þµÄ·Ö·¢ £¬°üÀ¨AmadeyºÍRedline Stealer¡£±¨¸æ»¹ÌṩÁËÓйضñÒâÈí¼þÈÆ¹ýÇå¾²Èí¼þ¼ì²â²¢Ö´ÐÐÆäpayloadµÄÊÖÒÕµÄÏêϸÐÅÏ¢¡£¶ñÒâÈí¼þÒ»µ©ÔÚϵͳÉÏÖ´ÐÐ £¬¾Í»áÓë¹¥»÷ÕßµÄC2·þÎñÆ÷½¨ÉèͨѶ £¬²¢´ÓÄ¿µÄµÄϵͳÖÐÇÔÈ¡Êý¾Ý £¬°üÀ¨µÇ¼ƾ֤¡¢²ÆÎñÊý¾ÝºÍСÎÒ˽¼ÒÐÅÏ¢µÈ¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/deconstructing-amadeys-latest-multi-stage-attack-and-malware-distribution/