Íþ¸Õ¿Æ¼¼³ÆÆäÔâµ½Ragnar Locker¹¥»÷£»Fastly CDNÖжÏ £¬Amazon¡¢RedditºÍGitHubµÈå´»ú

Ðû²¼Ê±¼ä 2021-06-10

1.KasperskyÅû¶PuzzleMakerÕë¶ÔÈ«ÇòµÄ¹¥»÷»î¶¯


1.jpg


KasperskyÅû¶ÐºڿÍÍÅ»ïPuzzleMakerÕë¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÊ×ÏÈÀûÓÃÁ˹ȸèChromeÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-21224£© £¬Ö®ºóÀûÓÃWindowsÄÚºËÖеÄÐÅϢ鶩¶´ºÍWindows NTFSÌáȨ©¶´£¨CVE-2021-31956£©ÌÓÍÑɳÏä²¢»ñµÃϵͳȨÏÞ¡£Kaspersky³ÆPuzzleMakerµÄ¹¥»÷»î¶¯×îÔçÊÇÔÚ4ÔÂÖÐÑ®·¢ÏÖµÄ £¬²¢ÌåÏÖĿǰ©¶´²¹¶¡ÒѾ­¿ÉÓà £¬½¨ÒéÓû§¾¡¿ì¸üÐÂä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/chrome-windows-zero-day/40191/


2.Î÷°àÑÀÀͶ¯ºÍÉç»á¾­¼Ã²¿MITES³ÆÆäÔâµ½ÍøÂç¹¥»÷


2.jpg


Î÷°àÑÀÀͶ¯ºÍÉç»á¾­¼Ã²¿ (MITES)³ÆÆäÓÚÖÜÈýÔâµ½ÍøÂç¹¥»÷ £¬ÕýÔÚŬÁ¦»Ö¸´ÊÜÓ°ÏìµÄ·þÎñ¡£MITESµÄÄê¶ÈÔ¤Ëã½Ó½ü3900ÍòÅ·Ôª £¬ÂôÁ¦Ð­µ÷ºÍ¼à¶½Î÷°àÑÀµÄ¾ÍÒµ¡¢Éç»á¾­¼ÃºÍÆóÒµÉç»áÔðÈÎÕþ²ß¡£¸Ã²¿ÌåÏÖ £¬´Ë´Î¹¥»÷µ¼ÖÂͨѶÊҺͶàýÌåÊҵIJ»ÐÐÓà £¬µ«ÊÇÆä¹Ù·½µÄÍøÕ¾ÈÔÔÚÕý³£ÔËÐС£ÕâÊǹ¤µ³ÔÚ½ñÄêÔâµ½µÄµÚ¶þ´ÎÍøÂç¹¥»÷ £¬ÔçÔÚ3Ô £¬¹ú¼Ò¹«¹²¾ÍÒµ·þÎñ¾Ö (SEPE)¾ÍÔâµ½ÁËRyukÀÕË÷Èí¼þ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118768/hacking/spains-ministry-of-labor-cyberattack.html


3.Íþ¸Õ¿Æ¼¼Ôâµ½Ragnar Locker¹¥»÷ £¬·þÎñÔÝʱÖжÏ


3.jpg


Öйų́ÍåµÄÍþ¸Õ¿Æ¼¼£¨ADATA£©Ôâµ½Ragnar Locker¹¥»÷ £¬·þÎñÔÝʱÖжÏ¡£ADATAÖ÷ÒªÉú²ú¸ßÐÔÄÜDRAMÄÚ´æÄ  £¿éºÍNANDÉÁ´æ¿¨µÈ²úÎï £¬ÔÚ2018Äê±»ÆÀΪµÚ¶þ´óDRAMÄÚ´æºÍ¹Ì̬ӲÅÌ (SSD) ÖÆÔìÉÌ¡£¸Ã¹«Ë¾ÔÚÉùÃ÷ÖгÆÆäÔÚ5ÔÂ23ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬Ö®ºóÁ¢¿Ì¹Ø±ÕÁËËùÓÐÊÜÓ°ÏìµÄϵͳ¡£Ragnar LockerÓÚÉÏÖÜÄ©³ÆÆäÔÚADATAµÄÍøÂçÖÐÇÔÈ¡ÁË1.5TBÊý¾Ý £¬°üÂÞרÓÐÉÌÒµÐÅÏ¢¡¢»úÃÜÎļþ¡¢Ô­Àíͼ¡¢²ÆÕþÊý¾Ý¡¢GitlabºÍSVNÔ´´úÂë¡¢Ö´·¨Îļþ¡¢Ô±¹¤ÐÅÏ¢¡¢±£ÃÜЭÒéºÍÊÂÇéÎļþ¼ÐµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/computer-memory-maker-adata-hit-by-ragnar-locker-ransomware/


4.Fastly CDNÖжÏ £¬Amazon¡¢RedditºÍGitHubµÈå´»ú


4.jpg


Fastly CDNÖжϵ¼ÖÂÈ«Çò·¶Î§ÄÚ¶à¼Ò¹«Ë¾µÄÍøÕ¾ÍêÈ«¹Ø±Õ»òÕßÎÞ·¨Õý³£¼ÓÔØ¡£´Ë´ÎÊܵ½Ó°ÏìµÄ¹«Ë¾°üÂÞAmazon¡¢Amazon Web Services (AWS)¡¢ÃÀ¹úÓÐÏßµçÊÓÐÂÎÅÍø¡¢Ó¢¹úÕþ¸®¡¢GitHub¡¢ShopifyºÍRedditµÈ¡£ÊÜÓ°ÏìÍøÕ¾¶¼ÊÐÏÔʾ¡°Á¬½Óʧ°Ü¡±¡¢´íÎ󡢡°IO ´íÎó¡±»òHTTP 503´úÂë¡£¾­¹ý×îÖÕÊÓ²ì £¬´Ë´ÎÖжÏÊÇÓÉÓÚ¿Í»§ÅäÖøü¸Ä¶ø´¥·¢µÄÒ»¸öÈí¼þ´íÎóµ¼ÖµÄ £¬Ä¿Ç°ÎÊÌâÒѾ­½â¾ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/stackoverflow-twitch-reddit-others-down-in-fastly-cdn-outage/


5.FBIºÍAFPαÔì¼ÓÃÜÁÄÌìƽ̨Anom×¥²¶800¶àÃûÏÓÒÉ·¸


5.jpg


ÔÚÆù½ñΪֹ¹æÄ£×î´ó¡¢×îÅÓ´óµÄÖ´·¨Ðж¯Trojan Shield£¨ÓÖ³ÆIronside£©ÖÐ £¬FBIºÍ°Ä´óÀûÑÇÁª°î¾¯²ìαÔìÁ˼ÓÃÜÁÄÌìƽ̨Anom²¢×¥²¶800¶àÃûÏÓÒÉ·¸¡£ÔçÔÚÈýÄêÇ°Ö´·¨²¿ÃÅαÔìÁ˸ö˵½¶Ë¼ÓÃÜÁÄÌìƽ̨ £¬×¨ÃųöÊÛ¸ø·¸×ï·Ö×Ó £¬Ö¼ÔÚ¼àÌýËûÃǵÄÏûÏ¢ºÍ¶Ô»° £¬Îª100¶à¸ö¹ú¼ÒµÄ300¶à¸ö·¸×OÍÅÌṩÁè¼Ý1.2Íǫ̀¼ÓÃÜÉ豸¡£Ö´·¨²¿ÃÅÔÚÉó²éÁË2700ÍòÌõÐÅÏ¢ºó´þ²¶800¶àÏÓ·¸ £¬½É»ñÁËÁè¼Ý4800ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/800-arrest-fbi-anom-app-honeypot/


6.Ó¢ÌضûÐû²¼6Ô·ÝÄþ¾²¸üР£¬×ܼÆÐÞ¸´73¸öÄþ¾²Â©¶´


6.jpg


Ó¢ÌضûÐû²¼ÁË6Ô·ÝÄþ¾²¸üР£¬×ܼÆÐÞ¸´ÁË73¸öÄþ¾²Â©¶´¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖصÄ©¶´ÊÇIntel VT-d²úÎïÖе±µØÌáȨ©¶´£¨CVE-2021-24489£©ºÍCPU BIOS¹Ì¼þÖÐÓɲ»ÕýÈ·µÄ³õʼ»¯¡¢¾ºÕùÌõ¼þ¡¢²»ÕýÈ·µÄÊäÈëÑéÖ¤ºÍ¿ØÖÆÁ÷¹ÜÀí²»×ãµ¼ÖµÄ4¸öÌáȨ©¶´£¨CVE-2020-12357¡¢CVE-2020-8670¡¢CVE-2020-8700ºÍCVE-2020-12359£©¡£Ó¢Ìضû³Æ´Ë´ÎÐÞ¸´µÄ©¶´ÖеÄ40¸ö(Ô¼55%)ÊÇͨ¹ýÆ乫˾ÄÚ²¿µÄÖ÷¶¯Äþ¾²Ñо¿·¢Ïֵġ£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-fixes-73-vulnerabilities-in-june-2021-platform-update/