UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps£»CiscoÅû¶macOSµÄSMBЭÒéÖеÄÐÅϢ鶩¶´

Ðû²¼Ê±¼ä 2021-05-20

1.UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps


1.jpg


UptycsÍþвÑо¿ÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÄ¿±ê½øÐÐÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢ÏÖ¡£Ñо¿ÈËÔ±Ö¸³ö£¬¹¥»÷Õßͨ¹ýWgetÀ´ÀûÓÃshell½Å±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª²îÒìµÄ»ùÓÚLinuxµÄϵͳ°²×°Simps payload¡£Æ¾¾ÝÒ»Ìõ°üÂÞGafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÏûÏ¢£¬Ñо¿ÈËÔ±ÍƶϸöñÒâÈí¼þÓëKeksecÍÅ»ïÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group


2.Tessian·¢ÏÖ½üÆÚαװ³ÉÍâÂô·þÎñµÄSMSÍøÂçµöÓã»î¶¯


2.jpg


TessianµÄÑо¿ÈËÔ±·¢ÏÖ½üÆÚαװ³ÉÍâÂô·þÎñµÄSMSÍøÂçµöÓã»î¶¯¡£Ôڴ˴ι¥»÷ÖУ¬ºÚ¿Íαװ³ÉÖªÃûÆ·ÅÆ£¨°üÂÞHelloFreshºÍGousto£©ÏòÄ¿±ê·¢ËͶÌÐÅ£¬ÀýÈç¡°ÄúµÄGoustoÏÖÔÚÒÑËʹ£¬À´ÓÕʹÓû§´ò¿ªµöÓã¶ÌÐÅÖеÄÁ´½Ó£¬²¢ÊäÈëÆä¸öÈËÐÅÏ¢¡£Ñо¿ÈËÔ±½¨ÒéÓû§½ÓÄÉһЩ¼òµ¥µÄÔ¤·À´ëÊ©£¬È羯Ìè²»ÊìϤµÄËÍ»õ֪ͨ£¬×Ðϸ¼ì²ì·¢¼þÈ˺ÅÂë²¢×îºÃ²»µã»÷SMSÏûÏ¢ÖеÄÁ´½Ó£¬À´Ô¤·À´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/scammers-meal-kit-services-customer-data/166282/


3.ÐÂÎ÷À¼DHBѬȾÀÕË÷Èí¼þ£¬¶à¼ÒÒ½ÔºµÄÊÖÊõ±»ÆÈÈ¡Ïû


3.jpg


ÐÂÎ÷À¼µÄ»³¿¨ÍеØÓòÎÀÉúίԱ»á£¨DHB£©ÓÚ±¾ÖܶþÔçÉÏÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬IT·þÎñÖжÏ£¬Áù¼ÒÁ¥ÊôÒ½ÔºÊܵ½Ó°Ïì¡£´Ë´Î¹¥»÷µ¼Ö»ú¹¹³ýµç×ÓÓʼþÒÔÍâµÄËùÓÐIT·þÎñ¶¼ÎÞ·¨Ê¹Óã¬Ò½ÔºÊÂÇéÈËÔ±±»ÆÈʹÓñʺÍÖ½°ì¹«£¬¶øÇÒÒòΪÁÙ´²·þÎñÖжϡ¢ÊÖÊõÍƳ١¢µç»°µôÏߣ¬Ò½ÔºÖ»ÄܽÓÊܽô¼±²¡ÈË¡£DHBÕý¶Ô´ËÊÂÕ¹¿ªÊӲ죬²¢ÒѾö¶¨²»Ö§¸¶Êê½ð£¬Ä¿Ç°Éв»Çå³þÌᳫ´Ë´Î¹¥»÷µÄºÚ¿ÍÍŻ


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/05/19/new_zealand_hospitals_taken_down/


4.CiscoÅû¶macOSµÄSMBЭÒéÖеÄÐÅϢ鶩¶´


4.jpg


Cisco TalosÅû¶ÁËApple macOSµÄSMBЭÒéÖеÄÐÅϢ鶩¶´¡£¸Ã©¶´ÊÇÒ»¸öÕûÊýÒç³ö©¶´£¨CVE-2021-1878£©£¬´æÔÚÓÚmacOS SMBЭÒé´¦ÖÃSMB3Êý¾Ý°üµÄ¹ý³ÌÖС£SMBÊÇWindowsÍøÂç»·¾³Öг£¼ûµÄÍøÂçÎļþ¼Ð¹²ÏíµÄ·þÎñ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿±êϵͳ·¢ËÍÌØÖÆÊý¾Ý°üÀ´ÀûÓôË©¶´¡£³ýÁËÄܹ»Ð¹Â¶Ãô¸ÐÐÅÏ¢Ö®Í⣬¹¥»÷Õß»¹¿ÉÒÔÀûÓø鶴À´Èƹý¼ÓÃܼì²é²¢µ¼Ö¾ܾø·þÎñ¡£ 


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/05/vuln-spotlight-smb-information-disclosure.html


5.NVIDIAÐû²¼½«ÔÚеÄÏÔ¿¨ÉϽµµÍËãÁ¦ÒÔÔ¤·ÀÍÚ¿ó»î¶¯


5.jpg


NVIDIAÐû²¼½«ÔÚеÄGeForce RTX 3080¡¢3070ºÍ3060 TiÏÔ¿¨ÉϽ«ËãÁ¦½µµÍÒ»°ë£¬ÒÔ½µµÍÆä¶Ô¿ó¹¤µÄÎüÒýÁ¦¡£¸Ã¹«Ë¾³Æ£¬´Ë¾ö¶¨ÊÇΪÁËÈ·±£ÓÎÏ·¿¨¿ÉÒÔ±»È«Çò¸ü¶àµÄÓÎÏ·Íæ¼ÒʹÓ㬶ø²»ÊǶÑÆöÔÚ¼ÓÃÜ»õ±Ò¿ó³¡ÖС£ÕâЩеIJúÎïµÄ°ü×°ºÐÉÏÓС°µÍËãÁ¦¡±»ò¡° LHR¡±±êʶ·û£¬Ô¤¼Æ½«ÓÚ±¾ÔÂÏÂÑ®¿ªÊ¼·¢»õ¡£´ËÍ⣬NVIDIA»¹ÍƳöÁËCMPרÓòɿóGPUϵÁУ¬¹æ¸ñΪ30HX£¨ËãÁ¦26 MH/Ã룩¡¢40HX£¨36 MH/Ã룩¡¢50HX£¨45 MH/Ã룩ºÍ90HX£¨86 MH/Ã룩¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/cryptocurrency/nvidia-cripples-cryptocurrency-mining-on-rtx-3080-and-3070-cards/


6.Elliptic³ÆDarkSideÔÚ½ü9¸öÔÂÒÑ»ñÀû9000ÍòÃÀÔª


6.jpg


Çø¿éÁ´·ÖÎö¹«Ë¾Elliptic³ÆDarkSideÔÚ½ü9¸öÔÂÒÑ»ñÀû9000ÍòÃÀÔª¡£ÕâЩÀûÈóµÄ10£¥À´×ÔÁ½¼Ò¹«Ë¾£ºÃÀ¹ú×î´óµÄʯÓ͹ܵÀϵͳColonial PipelineºÍµÂ¹úµÄ´óÐÍ»¯Ñ§Æ··ÖÏú¹«Ë¾Brenntag£¬×ܹ²ÎªÆä´øÀ´ÁËÔ¼1000ÍòÃÀÔª¡£¸Ã×éÖ¯µÄƽ¾ùÊê½ðΪ190ÍòÃÀÔª£¬ÕâʹÆä³ÉΪÀÕË÷Èí¼þÐÐÒµÖÐ×îÌ°À·µÄ¹«Ë¾Ö®Ò»¡£×÷ΪÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©ÔËÓªÉÌ£¬DarkSideÔÚÀûÈó·ÖÅä·½Ã棬»áƾ¾ÝÊê½ðµÄ¼¸¶àÊÕÈ¡10£¥ÖÁ25£¥µÄÓ¶½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/darkside-ransomware-made-90-million-in-just-nine-months/