·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨»á¼û

Ðû²¼Ê±¼ä 2023-05-08

1¡¢·¨¹ú²ÎÒéÔºÍøÕ¾Ôâµ½NoNameµÄDDoS¹¥»÷ÔÝʱÎÞ·¨»á¼û


¾ÝýÌå5ÔÂ5ÈÕ±¨µÀ £¬£¬£¬£¬£¬·¨¹ú²ÎÒéÔºµÄÍøÕ¾ÒòÔâµ½ºÚ¿Í×éÖ¯NoNameµÄDDoS¹¥»÷¶ø¹Ø±Õ¡£¡£¡£¡£·¨¹ú²ÎÒéÔº5ÈÕÐû²¼Ò»ÌõÍÆÎÄ³Æ £¬£¬£¬£¬£¬×Ôµ±ÈÕÔçÉÏÒÔÀ´ £¬£¬£¬£¬£¬²ÎÒéÔºµÄÍøÕ¾Ò»Ö±ÎÞ·¨»á¼û £¬£¬£¬£¬£¬ÆäÍŶÓÒÑÖÜÈ«·¢¶¯ÆðÀ´½â¾öÎÊÌâ¡£¡£¡£¡£NoNameÔÚTelegramÉÏÐû²¼Á˶Է¨¹úµÄ¶à¸ö×éÖ¯Ìᳫ¹¥»÷ £¬£¬£¬£¬£¬°üÀ¨·¨¹ú²ÎÒéÔº¡¢·¨¹ú¹ú¼ÒÀ͹¤¾ÍÒµºÍÖ°ÒµÅàѵÑо¿Ëù¡¢·¨¹ú¹ú¼Ò¿Õ¼äÑо¿ÖÐÐĺͷ¨¹ú¹ú·À¹«Ë¾Ë®Ê¦¼¯ÍÅ¡£¡£¡£¡£


https://www.securityweek.com/pro-russian-hackers-claim-downing-of-french-senate-website/


2¡¢Western Digital͸¶ÈýÔµÄÍøÂç¹¥»÷й¶²¿·ÖÓû§Êý¾Ý


ýÌå5ÔÂ7ÈÕ³Æ £¬£¬£¬£¬£¬Western DigitalÊÓ²ìÈ·ÈϹ¥»÷ÕßÔÚÈýÔ·ݵÄÍøÂç¹¥»÷ÖÐÇÔÈ¡Á˲¿·ÖСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ £¬£¬£¬£¬£¬3ÔÂ26ÈÕǰºó £¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½»ñµÃÁËWestern DigitalÊý¾Ý¿âµÄ¸±±¾ £¬£¬£¬£¬£¬ÆäÖаüÀ¨ÔÚÏßÊÐËÁÓû§µÄÐÅÏ¢¡£¡£¡£¡£Western DigitalÔÚÊÓ²ì´ËÊÂÎñµÄͬʱÒѽ«ÆäÊÐËÁÏÂÏß £¬£¬£¬£¬£¬ÏÖÔÚÊÐËÁ½öÏÔʾһÌõÐÂÎÅ¡°ÎÒÃǺܿì¾Í»á»ØÀ´£ºÎÒÃÇÏÖÔÚÎÞ·¨´¦Öóͷ£¶©µ¥¡£¡£¡£¡£¡±¸Ã¹«Ë¾Ô¤¼Æ½«ÓÚ5ÔÂ15ÈÕ»Ö¸´¶ÔÊÐËÁµÄ»á¼û¡£¡£¡£¡£TechCrunch±¨µÀ³Æ £¬£¬£¬£¬£¬Ä³²»×ÅÃûÍÅ»ïÈëÇÖÁËWestern Digital £¬£¬£¬£¬£¬²¢Éù³ÆÇÔÈ¡ÁË10 TBÊý¾Ý¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/western-digital-says-hackers-stole-customer-data-in-march-cyberattack/


3¡¢¼ÓÀû¸£ÄáÑÇijÊо¯·½ÔâÀÕË÷¹¥»÷ÒѸ¶110ÍòÃÀÔªÊê½ð


¾Ý5ÔÂ6ÈÕ±¨µÀ £¬£¬£¬£¬£¬¼ÓÀû¸£ÄáÑÇÖÝÊ¥±´ÄɵÏŵÊеÄÖΰ²²¿·ÖÔâµ½ÀÕË÷¹¥»÷ £¬£¬£¬£¬£¬²¢Ñ¡Ôñ¸¶110ÍòÃÀÔªÊê½ð¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ4ÔÂ7ÈÕ £¬£¬£¬£¬£¬µ¼Ö¾¯Ô±¾Ö±»ÆÈ¹Ø±ÕÁ˲¿·Öϵͳ £¬£¬£¬£¬£¬Ó°ÏìÁ˵ç×ÓÓʼþ¡¢³µÔصçÄÔºÍһЩִ·¨Êý¾Ý¿âµÈ¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¾Ý¡¶Âåɼí¶Ê±±¨¡·±¨µÀ £¬£¬£¬£¬£¬¸ÃÊÐÒÑΪ´ËÀ๥»÷Ͷ±£ £¬£¬£¬£¬£¬Ëü½öÐ踶Êê½ð×ܶîµÄÒ»°ë£¨511852ÃÀÔª£© £¬£¬£¬£¬£¬ÆäÓಿ·ÖÓɰü¹Ü¹«Ë¾¼ç¸º¡£¡£¡£¡£ÔÚÓëºÚ¿Í̸ÅÐºó £¬£¬£¬£¬£¬°ü¹Ü¹«Ë¾ºÍ¸ÃÊÐÔÞ³ÉÖ§¸¶ÓöÈÒÔ»Ö¸´ÏµÍ³µÄËùÓй¦Ð§ºÍÇå¾²Êý¾Ý¡£¡£¡£¡£


https://abc7.com/san-bernardino-cyberattack-ransom-paid-hackers/13215833/


4¡¢FortinetÐû²¼Çå¾²¸üÐÂÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄ9¸öÎó²î


5ÔÂ3ÈÕ £¬£¬£¬£¬£¬FortinetÐû²¼Çå¾²¸üР£¬£¬£¬£¬£¬ÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄ9¸öÎó²î¡£¡£¡£¡£ÆäÖаüÀ¨Á½¸ö½ÏΪÑÏÖØÎó²î £¬£¬£¬£¬£¬FortiADCÖÐÍⲿ×ÊÔ´Ä£¿£¿£¿£¿£¿£¿£¿éÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2023-27999£© £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØÖÆµÄ²ÎÊýÀ´Ö´ÐÐδ¾­ÊÚȨµÄÏÂÁî¡£¡£¡£¡£ÒÔ¼°FortiOSºÍFortiProxyµÄsslvpnd×é¼þÖеÄÔ½½çдÈëÎó²î£¨CVE-2023-22640£© £¬£¬£¬£¬£¬¿Éͨ¹ýÏò×°±¸·¢ËÍÌØÖÆµÄÇëÇóʹÓøÃÎó²î £¬£¬£¬£¬£¬À´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÕâЩÎó²îÊÇ·ñÒѱ»Ò°ÍâʹÓᣡ£¡£¡£


https://securityaffairs.com/145825/security/fortinet-fortiadc-fortios-flaws.html


5¡¢AndroidÐÞ¸´ÄÚºËÖб»Ê¹ÓõÄÌáȨÎó²îCVE-2023-0266


5ÔÂ5ÈÕ±¨µÀ³Æ £¬£¬£¬£¬£¬±¾ÔÂÐû²¼µÄAndroidÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÑÏÖØµÄÎó²î£¨CVE-2023-0266£©¡£¡£¡£¡£ÕâÊÇLinuxÄÚºËÉùÒô×ÓϵͳÖеÄÊͷźóʹÓÃÎó²î £¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂȨÏÞÌáÉýÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£Æ¾Ö¤Google TAGÔÚ3Ô·ÝÐû²¼µÄ±¨¸æ £¬£¬£¬£¬£¬Õë¶ÔÈýÐÇAndroidÊÖ»úµÄÌØ¹¤»î¶¯ÖÐ £¬£¬£¬£¬£¬¸ÃÎó²î±»×÷Ϊ¶à¸ö0-dayºÍn-day¹¥»÷Á´µÄÒ»²¿·Ö¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬±¾ÔµÄÇå¾²¸üл¹ÐÞ¸´ÁËÆäËü¼¸Ê®¸öÎó²î¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-android-updates-fix-kernel-bug-exploited-in-spyware-attacks/


6¡¢McAfeeÅû¶Amadey½üÆÚ¶à½×¶Î¹¥»÷ºÍ·Ö·¢µÄ»î¶¯


5ÔÂ5ÈÕ £¬£¬£¬£¬£¬McAfeeÅû¶ÁËAmadey×îеĶà½×¶Î¹¥»÷»î¶¯ºÍ¶ñÒâÈí¼þ·Ö·¢»î¶¯¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷½üÆÚWextract.exeÑù±¾ÓÐËùÔöÌí £¬£¬£¬£¬£¬Ëü±»ÓÃÓÚ¶àÖÖ¶ñÒâÈí¼þµÄ·Ö·¢ £¬£¬£¬£¬£¬°üÀ¨AmadeyºÍRedline Stealer¡£¡£¡£¡£±¨¸æ»¹ÌṩÁËÓйضñÒâÈí¼þÈÆ¹ýÇå¾²Èí¼þ¼ì²â²¢Ö´ÐÐÆäpayloadµÄÊÖÒÕµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¶ñÒâÈí¼þÒ»µ©ÔÚϵͳÉÏÖ´ÐÐ £¬£¬£¬£¬£¬¾Í»áÓë¹¥»÷ÕßµÄC2ЧÀÍÆ÷½¨ÉèͨѶ £¬£¬£¬£¬£¬²¢´ÓÄ¿µÄµÄϵͳÖÐÇÔÈ¡Êý¾Ý £¬£¬£¬£¬£¬°üÀ¨µÇ¼ƾ֤¡¢²ÆÎñÊý¾ÝºÍСÎÒ˽¼ÒÐÅÏ¢µÈ¡£¡£¡£¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/deconstructing-amadeys-latest-multi-stage-attack-and-malware-distribution/