¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.05.03-2021.05.09£©
2021-05-10
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. DDoS¹¥»÷ʹ±ÈÀûʱÕþ¸®ÍøÕ¾ÀëÏß
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬±ÈÀûʱ¹«¹²²¿·Ö»¥ÁªÍø·þÎñÌṩÉÌBelnetÔâÊÜ´ó¹æÄ£ÂþÑÜʽ¾Ü¾ø·þÎñ(DDoS)¹¥»÷£¬ÖÂʹ¸Ã¹úÐí¶àÕþ¸®ÍøÕ¾¼°Ïà¹Ø·þÎṉ̃»¾¡£Æ¾Ö¤BelnetµÄ˵·¨£¬¹¥»÷ʼÓÚ5ÔÂ4ÈÕÉÏÎ磬ӰÏìÁËʹÓøù«Ë¾·þÎñµÄ½ü200¼Ò»ú¹¹ºÍ×éÖ¯£¬°üÀ¨¹«¹²²¿·Ö¡¢´óѧºÍÑо¿»ú¹¹¶¼²¿·Ö»òÍêÈ«ÎÞ·¨ÉÏÍø£¬Í¬Ê±ÍøÕ¾ÏÕЩÎÞ·¨»á¼û¡£DDoS¹¥»÷£¨°üÀ¨´ó×ÚÄ¿µÄ×°±¸±»½©Ê¬ÍøÂçÖеÄ×°±¸Á÷Á¿ÍÌü»¶øÊ¹Ä¿µÄ²»¿°Öظº£©Í¨³£ÊÇ´ÓÄ¿µÄÖÐÀÕË÷¿î×Ó»òÑÚÊÎÆäËû¹¥»÷µÄÊֶΡ£ÎÞÂÛ½ÓÄÉÄÄÖÖ·½·¨£¬DDoS¹¥»÷¶¼»áʹ×éÖ¯ËðʧÊý°ÙÍòÃÀÔªÒÔ¼°ÐÅÓÃÉϵÄËðʧ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSb
2. WordPress·´À¬»øÓʼþ²å¼þ¿ÉÄÜ»áÌ»Â¶ÍøÕ¾Óû§Êý¾Ý
¡¾¸ÅÊö¡¿
ÔÚWordPress²å¼þÖз¢Ã÷µÄÒ»¸öÃûΪ“À¬»øÓʼþ±£»¤CleanTalk·À»ðǽ”µÄsql×¢ÈëÎó²î£¬¿ÉÄܻὫÓû§µÄµç×ÓÓʼþ¡¢ÃÜÂë¡¢ÐÅÓÿ¨Êý¾ÝºÍÆäËûÃô¸ÐÐÅϢ̻¶¸øÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¡£100,000¶à¸öÕ¾µãÉÏÒÑ×°ÖÃCleanTalkÀ¬»øÓʼþ·À»¤£¬Ö÷ÒªÓÃÓÚɨ³ýÍøÕ¾ÂÛ̳ÉϵÄÀ¬»øÓʼþºÍÀ¬»øÌ¸ÂÛ¡£´ËÎó²î±àºÅCVE-2021-24295£¬CVSSΪ7.5¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSn
3. Dark ScammersÍÅ»ïð³äWTO¾ÙÐÐÚ²ÆÔ˶¯
¡¾¸ÅÊö¡¿
DarkPath ScammersÍŻィÉèÁËÒ»¸öÓÉ134¸öð³äÌìÏÂÎÀÉú×éÖ¯ÍøÕ¾×é³ÉµÄÂþÑÜÊ½ÍøÂ磬ÒÔð³äWHO£¬ÓÕÆÓû§»á¼ûÚ²ÆÐÔµÚÈý·½ÍøÕ¾£¬ÃãÀø»á¼ûÕ߻ظ²Ò»Ð©¼òÆÓµÄÎÊÌ⣬ÒÔÔÚÌìÏÂÎÀÉúÈÕÖ®¼ÊÓ®µÃ200Å·ÔªµÄ½±½ð¡£Ú²ÆÔ˶¯ÌìÌìÎüÒýÀ´×ÔÃÀ¹ú¡¢Ó¡¶È¡¢¶íÂÞ˹ºÍÆäËû¹ú¼ÒµÄÔ¼200,000Óû§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSe
4. N3TW0RMºÚ¿ÍÍÅ»ïÁ¬»·×÷°¸Õë¶ÔÒÔÉ«ÁÐ
¡¾¸ÅÊö¡¿
×î½ü£¬Ò»¸öÃûΪ“N3TW0RM”£¨networm£¬ÍøÂçÈ䳿£©µÄºÚ¿ÍÍÅ»ïÁ¬»·×÷°¸£¬Ê¹ÓÃÀÕË÷Èí¼þ¶ÔÒ»ÅúÒÔÉ«Áй«Ë¾·¢¶¯Á˹¥»÷£¬ÆäÖаüÀ¨H&M£¨ÒÔÉ«ÁУ©£¬ÎïÁ÷¹«Ë¾Veritas Logistics¡£N3TW0RM»®·Ö´ÓÕâÁ½¼Ò¹«Ë¾»ñÈ¡ÁË110GBºÍ9GBÊý¾Ý£¬°üÀ¨Ö÷¹Ë¡¢·¢Æ±¼°¹ÍÔ±ÐÅÏ¢£¬»¹°üÀ¨Ö§¸¶ÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSx
5. ¸ßͨ²úÆ·Îó²îÓ°ÏìÔ¼30%µÄÖÇÄÜÊÖ»ú
¡¾¸ÅÊö¡¿
CheckpointµÄÑо¿Ö°Ô±ÔÚ¸ßÍ¨ÒÆ¶¯Õ¾µ÷ÖÆ½âµ÷Æ÷Öз¢Ã÷ÁËÒ»¸ö»º³åÇøÒç³öÎó²î£¬×·×ÙΪCVE-2020-11292£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚÖÇÄÜÊÖ»úÉÏ´¥·¢ÄÚ´æË𻵺ÍÖ´ÐÐí§Òâ´úÂë¡£
ÒÆ¶¯»ùÕ¾µ÷ÖÆ½âµ÷Æ÷(MSM)ÊǸßͨ¹«Ë¾ÔÚ20ÊÀ¼Í90ÄêÔÂÔçÆÚÉè¼ÆµÄоƬ(SoC)ϵͳ£¬¶àÄêÀ´£¬Çå¾²Ñо¿Ö°Ô±¾³£Õë¶Ô¸Ã×é¼þѰÕÒÔ¶³Ì¹¥»÷ÒÆ¶¯×°±¸µÄÐÂÒªÁ죬ÀýÈçͨ¹ý·¢ËͶÌÐÅ»òÈ«ÐÄÖÆ×÷µÄÎÞÏßµç°ü¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSv
6. ShinyHuntersй¶ӡ¶È»éÀñÃÅ»§ÍøÕ¾WedMeGoodµÄÊý¾Ý¿â
¡¾¸ÅÊö¡¿
ÎÛÃûÕÑÖøµÄºÚ¿ÍShinyHuntersй¶ÁËÏñAnimal Jam¡¢Mashable¡¢UpstoxºÍWattPadµÈ¹«Ë¾µÄÊý¾Ý¿â£¬½üÆÚÓÖ±¬·¢Ò»Æð¸ßµ÷µÄÊý¾Ýй¶ÊÂÎñ¡£ShinyHuntersÒÑת´¢ÁËÊôÓÚWedMeGoodµÄÊý¾Ý¿â£¬WedMeGoodÊÇÓ¡¶ÈÆÄÊܽӴýµÄ»éÀñ²ß»®Æ½Ì¨£¬¸Ãƽ̨ÈÏÕæ»éÀñµÄ¸÷¸ö·½Ã棬´ÓѰÕÒÔ°µØµ½ÉãӰʦ£¬ÔÙµ½°²ÅÅ»éÖÆ´ò°ç¡£´Ë´Îй¶41.5GBµÄÃô¸ÐÊý¾Ý£¬ÆäÖаüÀ¨È«Ãû¡¢ÐԱ𡢶¼»á¡¢µç»°ºÅÂë¡¢µç×ÓÓÊÏ䵨µã¡¢ÃÜÂë¡¢Ô¤¶¨ÏßË÷¡¢ÉϴεǼÈÕÆÚ¡¢ÕË»§½¨ÉèÈÕÆÚ¡¢FacebookÕ˺źÍAirbnb¼ÙÆÚÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSw
7. EximÐÞ¸´ÁËÓʼþת´ïÊðÀíÖеÄ21¸öÎó²î
¡¾¸ÅÊö¡¿
EximÊÇ×î³£ÓõÄÐÂÎÅ´«ÊäÊðÀíÖ®Ò»£¬ËüÒÑÐû²¼ÁËÕë¶Ô21¸öÎó²îµÄ²¹¶¡³ÌÐò£¬ÆäÖаüÀ¨11¸öÍâµØÎó²îºÍ10¸öÔ¶³Ì´úÂëÎó²î£¬²¢ÇÒ»áÓ°Ïì´Ó2004Äê×îÏȵÄËùÓа汾µÄExim·þÎñÆ÷£¬ÕâЩ²¹¶¡³ÌÐò¿ÉÄÜʹ³ÉǧÉÏÍòµÄÓû§ÃæÁÙÔâÊܹ¥»÷µÄΣº¦¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSr
8. Áè¼Ý40¿îÓ¦ÓóÌÐò±»·¢Ã÷×ß©AWSÃÜÔ¿
¡¾¸ÅÊö¡¿
½üÆÚ·¢Ã÷40¶à¿îÓ¦ÓóÌÐò£¨ÀÛ¼ÆÏÂÔØÁ¿Áè¼Ý1ÒڴΣ©£¬ÕâЩӦÓóÌÐòÖÐǶÈëÁËÓ²±àÂëµÄAmazon Web Services£¨AWS£©×¨ÓÃÃÜÔ¿£¬´Ó¶øÆäÄÚ²¿ÍøÂçºÍÓû§Êý¾ÝÃæÁÙÍøÂç¹¥»÷µÄΣº¦¡£AWSÃÜÔ¿×ß©ÒÑÔÚһЩÖ÷ÒªÓ¦ÓóÌÐòÖз¢Ã÷£¬ÀýÈçAdobe Photoshop Fix£¬Adobe Comp£¬Hootsuite£¬IBMµÄWeather ChannelÒÔ¼°ÔÚÏß¹ºÎï·þÎñClub FactoryºÍWholee¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSz
9. Ghostwriter¹¥»÷Ô˶¯Õë¶Ô±±Ô¼ÓѰî
¡¾¸ÅÊö¡¿
GhostwriterÐéαÐÅÏ¢¹¥»÷ÕýÔÚ¾ÙÐÐÖУ¬Ä¿µÄÕë¶Ô²¨À¼¡¢Á¢ÌÕÍðºÍÀÍÑάÑǵĹ«Ãñ£¬Ö÷ҪĿµÄÊÇÆÆËð¶Ô±±Ô¼ÔÚ¶«Å·Ðж¯µÄÐÅÐÄ£¬²¢ÒýÆð°üÀ¨ÃÀ¹úºÍ¼ÓÄôóÔÚÄ򵀮äËû¹ú¼Ò°²ÅÅÊ¿±øµÄ×èµ²¡£´Ë´Î¹¥»÷Ô˶¯¹éÒòÓÚUNC1151×éÖ¯£¬¸Ã×éÖ¯ÊÇ´ÓÊÂÕþ¸®Ô˶¯µÄÍøÂçÌØ¹¤Ô˶¯£¬´ÓÊÂÆ¾Ö¤ÍøÂçºÍ¶ñÒâÈí¼þÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruS4
10. Êý°ÙÍòDell×°±¸Ò×ÊܸüÐÂÇý¶¯³ÌÐòȱÏݵĹ¥»÷
¡¾¸ÅÊö¡¿
DellÒÑÐÞ¸´Çý¶¯³ÌÐòÖеÄÎó²î£¬¸ÃÇý¶¯³ÌÐòÒÑÔÚÊý°ÙÍǫ̀Ìõ¼Ç±¾µçÄÔ¡¢Æ½°åµçÄÔºĮ́ʽ»úÖÐÌṩ¡£Îó²î±àºÅCVE-2021-21551£¬CVSSÆÀ·Ö8.8¡£DellÒѾÔÚBIOS¸üÐÂÊÊÓóÌÐòÖаü×°ÁËÒ×Êܹ¥»÷µÄÇý¶¯³ÌÐòdbutil_2_3.sys ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSf
11. ÃÀ¹ú×î´óȼÓ͹ܵÀÔËÓªÉÌÔâÍøÂç¹¥»÷
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2021Äê5ÔÂ9ÈÕ£¬ÃÀ¹úÐû²¼½øÈë¹ú¼Ò½ôÆÈ״̬£¬Ôµ¹ÊÔÓÉÊÇÍâµØ×î´óȼÓ͹ܵÀÔËÓªÉÌÔâÍøÂç¹¥»÷ÏÂÏß¡£ÃÀ¹ú×î´óµÄÖÆÆ·Ó͹ܵÀÔËÓªÉÌColonial PipelineÔÚÍâµØÊ±¼äÖÜÎ壨5ÔÂ7ÈÕ£©ÒòÊܵ½ÀÕË÷Èí¼þ¹¥»÷£¬±»ÆÈ¹Ø±ÕÆäÃÀ¹ú¶«²¿Ñغ£¸÷Öݹ©Ó͵ÄÒªº¦È¼ÓÍÍøÂç¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/ruSS

AG¹«Ë¾ÔÆ







