ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ21ÖÜ

Ðû²¼Ê±¼ä 2021-05-24

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»£»£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î£»£»£»SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î£»£»£»Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î£»£»£»Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬£¬ £¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»£»£»DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª£»£»£»Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»£»£»NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ£»£»£»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î


Microsoft Windows JETÊý¾Ý¿âÒýÇæ±£´æÄÚ´æÆÆËðÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-594/


2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î


Pulse Connect Secureä¯ÀÀSMB¹²Ïí±£´æ»º³åÇøÒç³öÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800


3.SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î


SolarWinds Orion Job Scheduler JobRouterService±£´æ²»×¼È·ÊÚȨÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-605/


4.Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î


Cisco DNA Space±£´æÊäÈëÑéÖ¤Îó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n


5.Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î


Ubiquiti Networks EdgeRouter HTTPSÏÂÔØ¹Ì¼þ±£´æÖ¤ÊéУÑéÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-601/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬£¬ £¬±»ÀÕË÷½ü2000ÍòÃÀÔª


1.jpg


°®¶ûÀ¼µÄÒ½ÁÆÐ§ÀÍ»ú¹¹HSEÌåÏÖ£¬£¬ £¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¡£¡£¡£¸Ã»ú¹¹ÔÚ·¢Ã÷¹¥»÷ºó£¬£¬ £¬ÒÑÓÚÉÏÖÜÎ幨±ÕÁËËùÓÐITϵͳ¡£¡£¡£¡£ContiÍÅ»ïÉù³ÆÒѾ­½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬£¬ £¬ÔÚ´Ëʱ´ú£¬£¬ £¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬£¬ £¬°üÀ¨»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ÌõÔ¼¡¢²ÆÎñ±¨±íºÍÈËΪµ¥µÈ¡£¡£¡£¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎÅÐû²¼»áÉÏÌåÏÖ£¬£¬ £¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/


2¡¢DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª


2.jpg


DarkSideÊÇÒ»¸öÀÕË÷Èí¼þЧÀÍÆ÷ÍŻRaaS£©£¬£¬ £¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¡£¡£¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕÐû²¼ÉùÃ÷³Æ£¬£¬ £¬ÓÉÓÚÖ´·¨Ðж¯£¬£¬ £¬ËûÃÇÏÖÔÚÒѾ­ÎÞ·¨Í¨¹ýSSH»á¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶Ð§ÀÍÆ÷ºÍCDNЧÀÍÆ÷£¬£¬ £¬ÒÔ¼°Ö÷»ú½çÃæ¡£¡£¡£¡£Òò´Ë½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬£¬ £¬²¢ÔÊÐíÔÚ2021Äê5ÔÂ23ÈÕ֮ǰËÍ»¹ËùÓÐδ³¥Õ®Îñ¡£¡£¡£¡£¸ÃÉùÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬£¬ £¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime


3¡¢Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ


3.jpg


¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷еİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£¡£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ£¬£¬ £¬¾ßÓÐx64Ä£¿£¿ £¿£¿£¿£¿£¿é£¬£¬ £¬¿ÉÒÔÓÕÆ­Êܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬£¬ £¬»¹Ê¹ÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆ­Êܺ¦ÕßÏÂÔØÒÆ¶¯Ó¦ÓóÌÐò¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄ½¹µã×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÏÂÁîµÄºóÃÅ£¬£¬ £¬Ö»Óе±Æä¼ì²âµ½ÒѾ­ÅþÁ¬µ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬£¬ £¬ºóÃŲŻáÆô¶¯¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html


4¡¢NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ


4.jpg


NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬£¬ £¬±È2020ÄêͬÆÚÔöÌíÁË31£¥£¬£¬ £¬×î´óΪ480 Gbps£¬£¬ £¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬£¬ £¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£¡£¡£¡£ÆäÖУ¬£¬ £¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬£¬ £¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬£¬ £¬ÔÚÏßЧÀÍÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/asert/beat-goes


5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps


5.jpg


UptycsÍþвÑо¿ÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÄ¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬£¬ £¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢Ã÷¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬ £¬¹¥»÷Õßͨ¹ýWgetÀ´Ê¹ÓÃshell¾ç±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª²î±ðµÄ»ùÓÚLinuxµÄϵͳװÖÃSimps payload¡£¡£¡£¡£Æ¾Ö¤Ò»Ìõ°üÀ¨Gafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÐÂÎÅ£¬£¬ £¬Ñо¿Ö°Ô±ÍƶϸöñÒâÈí¼þÓëKeksecÍÅ»ïÓйء£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group