NB65³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦ÖÃƽ̨Qiwi 10.5TBÊý¾Ý

Ðû²¼Ê±¼ä 2022-05-10
1¡¢NB65³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦ÖÃƽ̨Qiwi 10.5 TBµÄÊý¾Ý 


¾ÝýÌå5ÔÂ9ÈÕ±¨µÀ£¬AnonymousÁ¥Êô»ú¹¹NB65Éù³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦ÖÃƽ̨Qiwi 10.5 TBµÄÊý¾Ý¡£´Ë´Î鶵ÄÐÅÏ¢°üÂÞ3000ÍòÌõÖ§¸¶¼Ç¼£¬ÆäÖÐÉæ¼°1250ÍòÕÅÐÅÓÿ¨¡£¸ÃÍŻﻹÐû²¼ÁËÒ»·ÝÉùÃ÷£¬ÌåÏִ˴ι¥»÷Ö¼ÔÚÈÅÂÒ¶íÂÞ˹½ðÈÚÌåϵ¡£´ËÍ⣬¹¥»÷Õß»¹Ê¹ÓÃÀÕË÷Èí¼þ¼ÓÃÜÁËƽ̨µÄϵͳ£¬²¢ÍþвҪÔÚ3ÌìÆÚÏÞ¹ýºó£¬Ã¿ÌìÐû²¼100ÍòÌõ¼Ç¼¡£5ÔÂ5ÈÕ£¬NB65ÒѹûÈ»ÁË700ÍòÕÅÖ§¸¶¿¨Êý¾Ý£¬×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£Qiwi·ñÈÏÁËÔâµ½Á˹¥»÷£¬»¹ÌåÏÖÆäÖ§¸¶·þÎñÔËÐÐÕý³££¬¿Í»§Êý¾ÝÒ²ºÜÄþ¾²¡£


https://www.hackread.com/anonymous-nb65-hacki-russia-payment-processor-qiwi/


2¡¢Ó¢Î°´ïÒòδÅû¶¼ÓÃܻ¶ÔÓÎÏ·ÒµÎñµÄÓ°Ïì±»·£¿î550ÍòÃÀÔª


¾Ý5ÔÂ6ÈÕ±¨µÀ£¬Ó¢Î°´ï£¨NVIDIA£©±»ÃÀ¹ú֤ȯ½»Ò×ίԱ»á(SEC)·£¿î550ÍòÃÀÔª¡£´Ë´Î´¦·£µÄÀíÓÉΪδ³äʵÅû¶¼ÓÃÜ»õ±Ò¶ÔÆäÓÎÏ·ÒµÎñµÄÓ°Ïì¡£´Ó2017Ä꿪ʼ£¬¿Í»§Ô½À´Ô½¶àµØʹÓÃNVIDIA GPUÍÚ¾ò¼ÓÃÜ»õ±Ò¡£SEC·¢ÏÖ£¬NVIDIAÔÚ2018²ÆÄêÁ¬ÐøµÄ¼¸¸ö¼¾¶ÈÖУ¬Î´ÄÜÅû¶¼ÓÃÜÍÚ¿óÊÇÆäÏúÊÛΪÓÎÏ·Éè¼ÆµÄGPU´øÀ´µÄʵÖÊÐÔÊÕÈëÔö³¤µÄÖØÒªÒòËØ¡£Ä¿Ç°£¬NVIDIAͬÒâ²¢Ö§¸¶ÁË550ÍòÃÀÔªµÄ·£¿î¡£


https://www.bleepingcomputer.com/news/technology/nvidia-fined-for-failure-to-disclose-cryptomining-sales-boost/


3¡¢Uptycs·¢ÏÖ½üÆÚÕë¶ÔDocker API¶Ë¿Ú2375µÄ¶ñÒâ»î¶¯


UptycsÔÚ5ÔÂ5ÈÕÐû²¼³ÂËߣ¬³ÆÆä·¢ÏÖ½üÆÚÕë¶ÔDocker API¶Ë¿Ú2375µÄ¶ñÒâ»î¶¯¡£ÕâЩ¹¥»÷Óë¼ÓÃÜ¿ó¹¤ÓйØ£¬²¢ÔÚÄ¿±ê·þÎñÆ÷ÉÏʹÓÃcmdlineÖеÄbase64±àÂëÃüÁî½øÐз´Ïòshell£¬Ö¼ÔÚÈƹý·ÀÓù»úÖÆ¡£Ñо¿ÈËÔ±×ܹ²·¢ÏÖÁË3ÖÖÀàÐ͵Ĺ¥»÷£¬·Ö±ðΪ¿ó¹¤¹¥»÷¡¢·´Ïòshell¹¥»÷ºÍKinsing¶ñÒâÈí¼þ¹¥»÷¡£³ÂËßÖ¸³ö£¬Ã»ÓнÓÄÉÊʵ±±£»¤´ëÊ©µÄDockerÒ×±»¹¥»÷ÕßÀûÓá£


https://www.uptycs.com/blog/vulnerable-docker-installations-are-a-playhouse-for-malware-attacks?hs_preview=roycVWho-72459548548


4¡¢OpenSeaµÄDiscord·þÎñÆ÷±»ºÚ²¢±»ÓÃÀ´Ðû²¼Ðé¼Ùͨ¸æ


ýÌå5ÔÂ7Èճƣ¬OpenSeaµÄDiscord·þÎñÆ÷±»ºÚ²¢±»ÓÃÀ´Ðû²¼Ðé¼Ùͨ¸æ¡£OpenSeaÊÇÒ»¸öNFTÂòÂôÊг¡£¬ËüÔÚ5ÔÂ6ÈÕÐû²¼ÁËÒ»ÕŽØͼ£¬ÊǹØÓÚºÏ×÷»ï°é¹ØϵµÄÐé¼Ùͨ¸æ£¬ÆäÖл¹°üÂÞÖ¸ÏòµöÓãÍøÕ¾µÄÁ´½Ó¡£OpenSea³Æ£¬ÆäDiscord·þÎñÆ÷ÓÚÉÏÖÜÎåÔçÉÏÔâµ½¹¥»÷£¬ËûÃǽ¨ÒéÓû§²»Òª¹ØעƵµÀÉÏÐû²¼µÄÈκÎÁ´½Ó¡£¾ÝϤ£¬¹¥»÷ÕßÀûÓÃÁËWebhook·ÃÎÊ·þÎñÆ÷¿Ø¼þÀ´ÈëÇÖÆäÍøÂ磬²¢½øÐеöÓã¹¥»÷¡£µ½Ä¿Ç°ÎªÖ¹£¬ÒÑÓÐ13¸öÇ®°ü±»µÁ¡£


https://insidebitcoins.com/news/opensea-discord-server-hacked-increasing-the-risk-of-phishing-scams


5¡¢Î¢ÈíÐû²¼AzureÖÐRCE©¶´CVE-2022-29972µÄ²¹¶¡


5ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁËAzureÖеÄRCE©¶´£¨CVE-2022-29972£©µÄ²¹¶¡¡£¸Ã©¶´Ò²±»³ÆΪSynLapse£¬Ó°ÏìÁËAzure SynapseºÍAzure Data Factory¹ÜµÀ£¬ÒÑÓÚ4ÔÂ15Èյõ½»º½â£¬ÔÚ²¹¶¡Ðû²¼Ö®Ç°²¢Î´±»ÀûÓá£Orca Security³Æ£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´·ÃÎʺͿØÖÆÆäËû¿Í»§µÄSynapseÊÂÇéÇø£¬ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý£¨°üÂÞAzureµÄ·þÎñÃÜÔ¿¡¢APIÁîÅƺÍÃÜÂëµÈ£©¡£Î¢ÈíÔö²¹µÀ£¬¸Ã©¶´¿É±»ÓÃÓÚ¿çIR»ù´¡ÉèÊ©Ö´ÐÐÔ¶³ÌÃüÁîÖ´ÐС£


https://www.bleepingcomputer.com/news/security/microsoft-releases-fixes-for-azure-flaw-allowing-rce-attacks/


6¡¢Ñо¿ÍŶÓÐû²¼ÐÅÓÿ¨ÇÔÈ¡¶ñÒâÈí¼þCaramelµÄ·ÖÎö³ÂËß


5ÔÂ5ÈÕ£¬Domain ToolsÐû²¼Á˹ØÓÚÐÅÓÿ¨ÇÔÈ¡¶ñÒâÈí¼þCaramelµÄ·ÖÎö³ÂËß¡£CaramelÊÇÒ»ÖÖskimmer-as-a-service£¬ÓɶíÂÞ˹ÍÅ»ïCaramelCorpÔËÓª¡£¸Ã·þÎñµÄÖÕÉí¶©ÔÄÓöÈΪ2000ÃÀÔª£¬½öÃæÏò½²¶íÓïµÄ¹ºÖÃÕß¡£¹¦Ð§´óÖ°üÂÞ²¿Êð¡¢ÊÕ¼¯¡¢¹ÜÀíºÍÈƹý¼ì²â£¬¾Ý³ÆËü¿ÉÒÔÈƹýCloudflare¡¢AkamaiºÍIncapsulaµÈ¹«Ë¾µÄ±£»¤·þÎñ¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁ˸÷þÎñµÄ¹ÜÀíÃæ°å´æÔÚ¼¸¸öÓëÉí·ÝÑéÖ¤Ïà¹ØµÄ¼¼Êõ´íÎó¡£


https://www.domaintools.com/resources/blog/a-sticky-situation-part-1-the-pervasive-nature-of-credit-card-skimmers