·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨·ÃÎÊ

Ðû²¼Ê±¼ä 2023-05-08

1¡¢·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨·ÃÎÊ


¾ÝýÌå5ÔÂ5ÈÕ±¨µÀ £¬·¨¹ú²ÎÒéÔºµÄÍøÕ¾ÒòÔâµ½ºÚ¿Í×éÖ¯NoNameµÄDDoS¹¥»÷¶ø¹Ø±Õ ¡£·¨¹ú²ÎÒéÔº5ÈÕÐû²¼Ò»ÌõÍÆÎÄ³Æ £¬×Ôµ±ÈÕÔçÉÏÒÔÀ´ £¬²ÎÒéÔºµÄÍøÕ¾Ò»Ö±ÎÞ·¨·ÃÎÊ £¬ÆäÍŶÓÒÑÈ«Ãæ·¢¶¯ÆðÀ´½â¾öÎÊÌâ ¡£NoNameÔÚTelegramÉÏÐû²¼Á˶Է¨¹úµÄ¶à¸ö×éÖ¯Ìᳫ¹¥»÷ £¬°üÂÞ·¨¹ú²ÎÒéÔº¡¢·¨¹ú¹ú¼ÒÀ͹¤¾ÍÒµºÍÖ°ÒµÅàѵÑо¿Ëù¡¢·¨¹ú¹ú¼Ò¿Õ¼äÑо¿ÖÐÐĺͷ¨¹ú¹ú·À¹«Ë¾º£¾ü¼¯ÍÅ ¡£


https://www.securityweek.com/pro-russian-hackers-claim-downing-of-french-senate-website/


2¡¢Western Digital͸¶ÈýÔµÄÍøÂç¹¥»÷й¶²¿ÃÅÓû§Êý¾Ý


ýÌå5ÔÂ7ÈÕ³Æ £¬Western DigitalÊÓ²ìÈ·ÈϹ¥»÷ÕßÔÚÈýÔ·ݵÄÍøÂç¹¥»÷ÖÐÇÔÈ¡Á˲¿ÃŸöÈËÐÅÏ¢ ¡£¸Ã¹«Ë¾ÌåÏÖ £¬3ÔÂ26ÈÕÇ°ºó £¬Î´¾­ÊÚȨµÄµÚÈý·½»ñµÃÁËWestern DigitalÊý¾Ý¿âµÄ¸±±¾ £¬ÆäÖаüÂÞÔÚÏßÉ̵êÓû§µÄÐÅÏ¢ ¡£Western DigitalÔÚÊÓ²ì´ËʼþµÄͬʱÒѽ«ÆäÉ̵êÏÂÏß £¬Ä¿Ç°É̵ê½öÏÔʾһÌõÏûÏ¢¡°ÎÒÃǺܿì¾Í»á»ØÀ´£ºÎÒÃÇÄ¿Ç°ÎÞ·¨´¦Öö©µ¥ ¡£¡±¸Ã¹«Ë¾Ô¤¼Æ½«ÓÚ5ÔÂ15ÈÕ»Ö¸´¶ÔÉ̵êµÄ·ÃÎÊ ¡£TechCrunch±¨µÀ³Æ £¬Ä³²»ÖªÃûÍÅ»ïÈëÇÖÁËWestern Digital £¬²¢Éù³ÆÇÔÈ¡ÁË10 TBÊý¾Ý ¡£


https://www.bleepingcomputer.com/news/security/western-digital-says-hackers-stole-customer-data-in-march-cyberattack/


3¡¢¼ÓÀû¸£ÄáÑÇijÊо¯·½ÔâÀÕË÷¹¥»÷ÒѸ¶110ÍòÃÀÔªÊê½ð


¾Ý5ÔÂ6ÈÕ±¨µÀ £¬¼ÓÀû¸£ÄáÑÇÖÝÊ¥±´ÄɵÏŵÊеÄÖΰ²²¿ÃÅÔâµ½ÀÕË÷¹¥»÷ £¬²¢Ñ¡Ôñ¸¶110ÍòÃÀÔªÊê½ð ¡£¹¥»÷·¢ÉúÔÚ4ÔÂ7ÈÕ £¬µ¼Ö¾¯²ì¾Ö±»ÆȹرÕÁ˲¿ÃÅϵͳ £¬Ó°ÏìÁ˵ç×ÓÓʼþ¡¢³µÔصçÄÔºÍһЩִ·¨Êý¾Ý¿âµÈ ¡£Ä¿Ç° £¬ÊÓ²ìÈÔÔÚ½øÐÐÖÐ ¡£¾Ý¡¶Âåɼí¶Ê±±¨¡·±¨µÀ £¬¸ÃÊÐÒÑΪ´ËÀ๥»÷Ͷ±£ £¬Ëü½öÐ踶Êê½ð×ܶîµÄÒ»°ë£¨511852ÃÀÔª£© £¬ÆäÓಿÃÅÓɱ£ÏÕ¹«Ë¾¸ºµ£ ¡£ÔÚÓëºÚ¿Í̸Åкó £¬±£ÏÕ¹«Ë¾ºÍ¸ÃÊÐͬÒâÖ§¸¶ÓöÈÒÔ»Ö¸´ÏµÍ³µÄÈ«²¿¹¦Ð§ºÍÄþ¾²Êý¾Ý ¡£


https://abc7.com/san-bernardino-cyberattack-ransom-paid-hackers/13215833/


4¡¢FortinetÐû²¼Äþ¾²¸üÐÂÐÞ¸´Æä¶à¸ö²úÎïÖеÄ9¸ö©¶´


5ÔÂ3ÈÕ £¬FortinetÐû²¼Äþ¾²¸üР£¬ÐÞ¸´Æä¶à¸ö²úÎïÖеÄ9¸ö©¶´ ¡£ÆäÖаüÂÞÁ½¸ö½ÏΪÑÏÖØ©¶´ £¬FortiADCÖÐÍⲿ×ÊÔ´Ä£¿éÖеÄÃüÁî×¢È멶´£¨CVE-2023-27999£© £¬¹¥»÷Õß¿Éͨ¹ýÌØÖƵIJÎÊýÀ´Ö´ÐÐδ¾­ÊÚȨµÄÃüÁî ¡£ÒÔ¼°FortiOSºÍFortiProxyµÄsslvpnd×é¼þÖеÄÔ½½çдÈ멶´£¨CVE-2023-22640£© £¬¿Éͨ¹ýÏòÉ豸·¢ËÍÌØÖƵÄÇëÇóÀûÓø鶴 £¬À´Ö´ÐÐÈÎÒâ´úÂë ¡£Ä¿Ç°Éв»Çå³þÕâЩ©¶´ÊÇ·ñÒѱ»Ò°ÍâÀûÓà ¡£


https://securityaffairs.com/145825/security/fortinet-fortiadc-fortios-flaws.html


5¡¢AndroidÐÞ¸´ÄÚºËÖб»ÀûÓõÄÌáȨ©¶´CVE-2023-0266


5ÔÂ5ÈÕ±¨µÀ³Æ £¬±¾ÔÂÐû²¼µÄAndroidÄþ¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÑÏÖصÄ©¶´£¨CVE-2023-0266£© ¡£ÕâÊÇLinuxÄÚºËÉùÒô×ÓϵͳÖеÄÊͷźóʹÓ鶴 £¬¿ÉÄܻᵼÖÂȨÏÞÌáÉýÇÒÎÞÐèÓû§½»»¥ ¡£Æ¾¾ÝGoogle TAGÔÚ3Ô·ÝÐû²¼µÄ³ÂËß £¬Õë¶ÔÈýÐÇAndroidÊÖ»úµÄ¼äµý»î¶¯ÖÐ £¬¸Ã©¶´±»×÷Ϊ¶à¸ö0-dayºÍn-day¹¥»÷Á´µÄÒ»²¿ÃÅ ¡£´ËÍâ £¬±¾ÔµÄÄþ¾²¸üл¹ÐÞ¸´ÁËÆäËü¼¸Ê®¸ö©¶´ ¡£


https://www.bleepingcomputer.com/news/security/new-android-updates-fix-kernel-bug-exploited-in-spyware-attacks/


6¡¢McAfeeÅû¶Amadey½üÆÚ¶à½×¶Î¹¥»÷ºÍ·Ö·¢µÄ»î¶¯


5ÔÂ5ÈÕ £¬McAfeeÅû¶ÁËAmadey×îеĶà½×¶Î¹¥»÷»î¶¯ºÍ¶ñÒâÈí¼þ·Ö·¢»î¶¯ ¡£Ñо¿ÈËÔ±·¢ÏÖ½üÆÚWextract.exeÑù±¾ÓÐËùÔö¼Ó £¬Ëü±»ÓÃÓÚ¶àÖÖ¶ñÒâÈí¼þµÄ·Ö·¢ £¬°üÂÞAmadeyºÍRedline Stealer ¡£³ÂËß»¹ÌṩÁËÓйضñÒâÈí¼þÈƹýÄþ¾²Èí¼þ¼ì²â²¢Ö´ÐÐÆäpayloadµÄ¼¼ÊõµÄÏêϸÐÅÏ¢ ¡£¶ñÒâÈí¼þÒ»µ©ÔÚϵͳÉÏÖ´ÐÐ £¬¾Í»áÓë¹¥»÷ÕßµÄC2·þÎñÆ÷½¨Á¢Í¨ÐÅ £¬²¢´ÓÄ¿±êµÄϵͳÖÐÇÔÈ¡Êý¾Ý £¬°üÂ޵Ǽƾ¾Ý¡¢²ÆÕþÊý¾ÝºÍ¸öÈËÐÅÏ¢µÈ ¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/deconstructing-amadeys-latest-multi-stage-attack-and-malware-distribution/