·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨»á¼û

Ðû²¼Ê±¼ä 2023-05-08

1¡¢·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨»á¼û


¾ÝýÌå5ÔÂ5ÈÕ±¨µÀ£¬£¬£¬·¨¹ú²ÎÒéÔºµÄÍøÕ¾ÒòÔâµ½ºÚ¿Í×éÖ¯NoNameµÄDDoS¹¥»÷¶ø¹Ø±Õ¡£¡£¡£¡£¡£·¨¹ú²ÎÒéÔº5ÈÕÐû²¼Ò»ÌõÍÆÎijÆ£¬£¬£¬×Ôµ±ÈÕÔçÉÏÒÔÀ´£¬£¬£¬²ÎÒéÔºµÄÍøÕ¾Ò»Ö±ÎÞ·¨»á¼û£¬£¬£¬ÆäÍŶÓÒÑÖÜÈ«·¢¶¯ÆðÀ´½â¾öÎÊÌâ¡£¡£¡£¡£¡£NoNameÔÚTelegramÉÏÐû²¼Á˶Է¨¹úµÄ¶à¸ö×éÖ¯Ìᳫ¹¥»÷£¬£¬£¬°üÀ¨·¨¹ú²ÎÒéÔº¡¢·¨¹ú¹ú¼ÒÀ͹¤¾ÍÒµºÍÖ°ÒµÅàѵÑо¿Ëù¡¢·¨¹ú¹ú¼Ò¿Õ¼äÑо¿ÖÐÐĺͷ¨¹ú¹ú·À¹«Ë¾Ë®Ê¦¼¯ÍÅ¡£¡£¡£¡£¡£


https://www.securityweek.com/pro-russian-hackers-claim-downing-of-french-senate-website/


2¡¢Western Digital͸¶ÈýÔµÄÍøÂç¹¥»÷й¶²¿·ÖÓû§Êý¾Ý


ýÌå5ÔÂ7Èճƣ¬£¬£¬Western DigitalÊÓ²ìÈ·ÈϹ¥»÷ÕßÔÚÈýÔ·ݵÄÍøÂç¹¥»÷ÖÐÇÔÈ¡Á˲¿·ÖСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬3ÔÂ26ÈÕǰºó£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½»ñµÃÁËWestern DigitalÊý¾Ý¿âµÄ¸±±¾£¬£¬£¬ÆäÖаüÀ¨ÔÚÏßÊÐËÁÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£Western DigitalÔÚÊÓ²ì´ËÊÂÎñµÄͬʱÒѽ«ÆäÊÐËÁÏÂÏߣ¬£¬£¬ÏÖÔÚÊÐËÁ½öÏÔʾһÌõÐÂÎÅ¡°ÎÒÃǺܿì¾Í»á»ØÀ´£ºÎÒÃÇÏÖÔÚÎÞ·¨´¦Öóͷ£¶©µ¥¡£¡£¡£¡£¡£¡±¸Ã¹«Ë¾Ô¤¼Æ½«ÓÚ5ÔÂ15ÈÕ»Ö¸´¶ÔÊÐËÁµÄ»á¼û¡£¡£¡£¡£¡£TechCrunch±¨µÀ³Æ £¬£¬£¬Ä³²»×ÅÃûÍÅ»ïÈëÇÖÁËWestern Digital£¬£¬£¬²¢Éù³ÆÇÔÈ¡ÁË10 TBÊý¾Ý¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/western-digital-says-hackers-stole-customer-data-in-march-cyberattack/


3¡¢¼ÓÀû¸£ÄáÑÇijÊо¯·½ÔâÀÕË÷¹¥»÷ÒѸ¶110ÍòÃÀÔªÊê½ð


¾Ý5ÔÂ6ÈÕ±¨µÀ£¬£¬£¬¼ÓÀû¸£ÄáÑÇÖÝÊ¥±´ÄɵÏŵÊеÄÖΰ²²¿·ÖÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬²¢Ñ¡Ôñ¸¶110ÍòÃÀÔªÊê½ð¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ4ÔÂ7ÈÕ£¬£¬£¬µ¼Ö¾¯Ô±¾Ö±»ÆÈ¹Ø±ÕÁ˲¿·Öϵͳ£¬£¬£¬Ó°ÏìÁ˵ç×ÓÓʼþ¡¢³µÔصçÄÔºÍһЩִ·¨Êý¾Ý¿âµÈ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£¾Ý¡¶Âåɼí¶Ê±±¨¡·±¨µÀ£¬£¬£¬¸ÃÊÐÒÑΪ´ËÀ๥»÷Ͷ±££¬£¬£¬Ëü½öÐ踶Êê½ð×ܶîµÄÒ»°ë£¨511852ÃÀÔª£©£¬£¬£¬ÆäÓಿ·ÖÓɰü¹Ü¹«Ë¾¼ç¸º¡£¡£¡£¡£¡£ÔÚÓëºÚ¿Í̸Åк󣬣¬£¬°ü¹Ü¹«Ë¾ºÍ¸ÃÊÐÔÞ³ÉÖ§¸¶ÓöÈÒÔ»Ö¸´ÏµÍ³µÄËùÓй¦Ð§ºÍÇå¾²Êý¾Ý¡£¡£¡£¡£¡£


https://abc7.com/san-bernardino-cyberattack-ransom-paid-hackers/13215833/


4¡¢FortinetÐû²¼Çå¾²¸üÐÂÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄ9¸öÎó²î


5ÔÂ3ÈÕ£¬£¬£¬FortinetÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄ9¸öÎó²î¡£¡£¡£¡£¡£ÆäÖаüÀ¨Á½¸ö½ÏΪÑÏÖØÎó²î£¬£¬£¬FortiADCÖÐÍⲿ×ÊÔ´Ä£¿£¿£¿£¿éÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2023-27999£©£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØÖÆµÄ²ÎÊýÀ´Ö´ÐÐδ¾­ÊÚȨµÄÏÂÁî¡£¡£¡£¡£¡£ÒÔ¼°FortiOSºÍFortiProxyµÄsslvpnd×é¼þÖеÄÔ½½çдÈëÎó²î£¨CVE-2023-22640£©£¬£¬£¬¿Éͨ¹ýÏò×°±¸·¢ËÍÌØÖÆµÄÇëÇóʹÓøÃÎó²î£¬£¬£¬À´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÕâЩÎó²îÊÇ·ñÒѱ»Ò°ÍâʹÓᣡ£¡£¡£¡£


https://securityaffairs.com/145825/security/fortinet-fortiadc-fortios-flaws.html


5¡¢AndroidÐÞ¸´ÄÚºËÖб»Ê¹ÓõÄÌáȨÎó²îCVE-2023-0266


5ÔÂ5ÈÕ±¨µÀ³Æ£¬£¬£¬±¾ÔÂÐû²¼µÄAndroidÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÑÏÖØµÄÎó²î£¨CVE-2023-0266£©¡£¡£¡£¡£¡£ÕâÊÇLinuxÄÚºËÉùÒô×ÓϵͳÖеÄÊͷźóʹÓÃÎó²î£¬£¬£¬¿ÉÄܻᵼÖÂȨÏÞÌáÉýÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£Æ¾Ö¤Google TAGÔÚ3Ô·ÝÐû²¼µÄ±¨¸æ£¬£¬£¬Õë¶ÔÈýÐÇAndroidÊÖ»úµÄÌØ¹¤»î¶¯ÖУ¬£¬£¬¸ÃÎó²î±»×÷Ϊ¶à¸ö0-dayºÍn-day¹¥»÷Á´µÄÒ»²¿·Ö¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬±¾ÔµÄÇå¾²¸üл¹ÐÞ¸´ÁËÆäËü¼¸Ê®¸öÎó²î¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-android-updates-fix-kernel-bug-exploited-in-spyware-attacks/


6¡¢McAfeeÅû¶Amadey½üÆÚ¶à½×¶Î¹¥»÷ºÍ·Ö·¢µÄ»î¶¯


5ÔÂ5ÈÕ£¬£¬£¬McAfeeÅû¶ÁËAmadey×îеĶà½×¶Î¹¥»÷»î¶¯ºÍ¶ñÒâÈí¼þ·Ö·¢»î¶¯¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷½üÆÚWextract.exeÑù±¾ÓÐËùÔöÌí£¬£¬£¬Ëü±»ÓÃÓÚ¶àÖÖ¶ñÒâÈí¼þµÄ·Ö·¢£¬£¬£¬°üÀ¨AmadeyºÍRedline Stealer¡£¡£¡£¡£¡£±¨¸æ»¹ÌṩÁËÓйضñÒâÈí¼þÈÆ¹ýÇå¾²Èí¼þ¼ì²â²¢Ö´ÐÐÆäpayloadµÄÊÖÒÕµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¶ñÒâÈí¼þÒ»µ©ÔÚϵͳÉÏÖ´ÐУ¬£¬£¬¾Í»áÓë¹¥»÷ÕßµÄC2ЧÀÍÆ÷½¨ÉèͨѶ£¬£¬£¬²¢´ÓÄ¿µÄµÄϵͳÖÐÇÔÈ¡Êý¾Ý£¬£¬£¬°üÀ¨µÇ¼ƾ֤¡¢²ÆÎñÊý¾ÝºÍСÎÒ˽¼ÒÐÅÏ¢µÈ¡£¡£¡£¡£¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/deconstructing-amadeys-latest-multi-stage-attack-and-malware-distribution/