ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ21ÖÜ
Ðû²¼Ê±¼ä 2021-05-24> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³ö©¶´£»SolarWinds Orion Job Scheduler JobRouterService²»ÕýÈ·ÊÚȨ´úÂëÖ´ÐЩ¶´£»Cisco DNA Space CVE-2021-1559 OSÃüÁîÖ´ÐЩ¶´£»Ubiquiti Networks EdgeRouter²»ÕýÈ·Ö¤ÊéУÑéÈÎÒâ´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª£»Ñо¿ÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö³ÂËߣ»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´
Microsoft Windows JETÊý¾Ý¿âÒýÇæ´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-594/
2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³ö©¶´
Pulse Connect Secureä¯ÀÀSMB¹²Ïí´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
3.SolarWinds Orion Job Scheduler JobRouterService²»ÕýÈ·ÊÚȨ´úÂëÖ´ÐЩ¶´
SolarWinds Orion Job Scheduler JobRouterService´æÔÚ²»ÕýÈ·ÊÚȨ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-605/
4.Cisco DNA Space CVE-2021-1559 OSÃüÁîÖ´ÐЩ¶´
Cisco DNA Space´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n
5.Ubiquiti Networks EdgeRouter²»ÕýÈ·Ö¤ÊéУÑéÈÎÒâ´úÂëÖ´ÐЩ¶´
Ubiquiti Networks EdgeRouter HTTPSÏÂÔع̼þ´æÔÚÖ¤ÊéУÑ驶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-601/
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª
°®¶ûÀ¼µÄÒ½ÁÆ·þÎñ»ú¹¹HSEÌåÏÖ£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¸Ã»ú¹¹ÔÚ·¢ÏÖ¹¥»÷ºó£¬ÒÑÓÚÉÏÖÜÎå¹Ø±ÕÁËËùÓÐITϵͳ¡£ContiÍÅ»ïÉù³ÆÒѾ½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬ÔÚ´ËÆڼ䣬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬°üÂÞ»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ºÏͬ¡¢²ÆÕþ±¨±íºÍÈËΪµ¥µÈ¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎÅÐû²¼»áÉÏÌåÏÖ£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/
2¡¢DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª
DarkSideÊÇÒ»¸öÀÕË÷Èí¼þ·þÎñÆ÷ÍŻRaaS£©£¬Ò»ÖÜÇ°¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕÐû²¼ÉùÃ÷³Æ£¬ÓÉÓÚÖ´·¨Ðж¯£¬ËûÃÇÄ¿Ç°ÒѾÎÞ·¨Í¨¹ýSSH·ÃÎÊÆ乫¹²Êý¾Ýй¶ÍøÕ¾¡¢Ö§¸¶·þÎñÆ÷ºÍCDN·þÎñÆ÷£¬ÒÔ¼°Ö÷»ú½çÃæ¡£Òò´Ë½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬²¢ÔÊÐíÔÚ2021Äê5ÔÂ23ÈÕ֮ǰ¹é»¹ËùÓÐδ³¥Õ®Îñ¡£¸ÃÉùÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬Æ佫ÖÕÖ¹ÀÕË÷»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime
3¡¢Ñо¿ÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ
¿¨°Í˹»ùÑо¿ÈËÔ±·¢ÏÖеİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£BizarroÊÇWindows¶ñÒâÈí¼þ£¬¾ßÓÐx64Ä£¿é£¬¿ÉÒÔÓÕÆÊܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬»¹ÀûÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆÊܺ¦ÕßÏÂÔØÒƶ¯Ó¦Ó÷¨Ê½¡£¸Ã¶ñÒâÈí¼þµÄµÄºËÐÄ×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÃüÁîµÄºóÃÅ£¬Ö»Óе±Æä¼ì²âµ½ÒѾÁ¬½Óµ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬ºóÃŲŻáÆô¶¯¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html
4¡¢NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö³ÂËß
NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬±È2020ÄêͬÆÚÔö¼ÓÁË31£¥£¬×î´óΪ480 Gbps£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£ÆäÖУ¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬ÔÚÏß·þÎñÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/asert/beat-goes
5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps
UptycsÍþвÑо¿ÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÄ¿±ê½øÐÐÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢ÏÖ¡£Ñо¿ÈËÔ±Ö¸³ö£¬¹¥»÷Õßͨ¹ýWgetÀ´ÀûÓÃshell½Å±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª²îÒìµÄ»ùÓÚLinuxµÄϵͳ°²×°Simps payload¡£Æ¾¾ÝÒ»Ìõ°üÂÞGafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÏûÏ¢£¬Ñо¿ÈËÔ±ÍƶϸöñÒâÈí¼þÓëKeksecÍÅ»ïÓйء£
ÔÎÄÁ´½Ó£º
https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group