Òâ´óÀûCSIRT³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½DDoS¹¥»÷
Ðû²¼Ê±¼ä 2022-05-165ÔÂ13ÈÕ£¬Òâ´óÀû¼ÆËã»úÄþ¾²Ê¼þÏìӦС×é(CSIRT)³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾ÔÚ×î½ü¼¸ÌìÔâµ½DDoS¹¥»÷¡£CSIRT½âÊÍ˵£¬´Ó5ÔÂ11ÈÕ¿ªÊ¼£¬¹¥»÷Õß¶ÔÆäÕþ¸®¡¢²¿Î¯¡¢Òé»áÉõÖÁ¾ü¶ÓµÄÍøÕ¾½øÐÐÁËËùνµÄ¡°Slow HTTP¡±DDoS¹¥»÷¡£ÕâÖÖÀàÐ͵Ĺ¥»÷ÔÚʹÓÃPOSTÇëÇóµÄÇé¿öϸüÓÐЧ£¬ÒòΪËüÃÇ»¹ÓÃÓÚÏòWeb·þÎñÆ÷·¢ËÍ´óÁ¿Êý¾Ý¡£´ËÍ⣬¸Ã»ú¹¹»¹ÌṩÁË»º½â´ËÀ๥»÷µÄÒªÁì¡£ºÚ¿ÍÍÅ»ïKillnetÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬ËûÃÇ»¹¶ÔÂÞÂíÄáÑÇÃÅ»§ÍøÕ¾ºÍÃÀ¹ú²¼ÀµÂÀû»ú³¡½øÐÐÁËÀàËÆ¹¥»÷µÄ¡£
https://securityaffairs.co/wordpress/131256/hacktivism/pro-russian-hacktivists-target-italy.html
2¡¢2¸öÅäÖôíÎóµÄES·þÎñÆ÷й¶Լ3.59ÒÚÌõ¼Ç¼
ýÌå5ÔÂ12Èճƣ¬2¸öÅäÖôíÎóµÄElasticSearch·þÎñÆ÷йÁ˶Լ359019902Ìõ¼Ç¼¡£¾ÝÑо¿ÈËÔ±³Æ£¬ÕâÁ½Ð©ES·þÎñÆ÷¾ùÊôÓÚÒ»¸ö×éÖ¯£¬°üÂÞÔ¼579.4 GBµÄÊý¾Ý£¬Éæ¼°ÍÆ¼öÈËÒ³Ãæ¡¢Ê±¼ä´ÁIP¡¢µØÀíλÖÃÊý¾Ý¡¢·ÃÎʵÄÍøÒ³¡¢ºÍÓû§ÊðÀíÊý¾ÝµÈ¡£ÆäÖеÚһ̨·þÎñÆ÷°üÂÞ2021Äê9ÔÂ2ÈÕÖÁ10ÔÂ1ÈÕÆÚ¼äÊÕ¼¯µÄ242728328Ìõ¼Ç¼£¬Áíһ̨°üÂÞ2021Äê12ÔÂ1ÈÕÖÁ12ÔÂ27ÈÕÊÕ¼¯µÄ116291574Ìõ¼Ç¼¡£¾ÝÔ¤¼Æ£¬Ô¼ÓÐ1500ÍòÓû§ÊÜ´ËʼþµÄÓ°Ïì¡£
https://www.hackread.com/misconfigured-elasticsearch-servers-user-website-activity/
3¡¢´óÁ¿¶íÂÞ˹AndroidÓû§·´Ó³ÎÞ·¨°²×°Chrome¸üÐÂ
¾ÝýÌå5ÔÂ13ÈÕ±¨µÀ£¬¶íÂÞ˹ԽÀ´Ô½¶àµÄAndroid ChromeÓû§·´Ó³ÔÚ°²×°¸üÐÂʱ³ÂËß´íÎ󡣯¾¾ÝÓû§ÆÀÂÛ£¬ÎÊÌâʼÓÚ2022Äê5ÔÂ9ÈÕ£¬ËûÃÇÔÚÊÔͼ°²×°Chrome°æ±¾101ʱÊÕµ½ÁËÒ»Ìõ´íÎóÏûÏ¢¡°ÎÞ·¨°²×°Google Chrome¡±¡£´ËÍ⣬´íÎóÏûÏ¢²¢Î´ËµÃ÷¸üÐÂʧ°ÜµÄÔÒò£¬GoogleµÄÖ§³ÖÊðÀí½¨ÒéÓû§ÔÚÖ§³ÖÉçÇøÌÖÂÛÖвéÕÒ½â¾ö·½°¸¡£Í¶ËßµÄÊýÁ¿Ã¿Ìì¶¼ÔÚÔö¼Ó£¬µ«µ½Ä¿Ç°ÎªÖ¹£¬ÎÊÌâµÄÔÒòÈÔȻδ֪£¬Ò²Î´½â¾ö¡£
https://www.bleepingcomputer.com/news/security/google-chrome-updates-failing-on-android-devices-in-russia/
4¡¢Windows 5Ô·ݵĸüпÉÄܻᵼÖÂADÉí·ÝÑé֤ʧ°Ü
¾Ý5ÔÂ12ÈÕ±¨µÀ£¬Î¢ÈíÕýÔÚÊÓ²ì2022Äê5ÔµÄÖܶþ²¹¶¡µ¼ÖµÄWindows·þÎñÉí·ÝÑé֤ʧ°ÜµÄÎÊÌâ¡£Óû§³ÆËûÃÇÔÚ°²×°¸üкóÊÕµ½ÁË´íÎóÏûÏ¢¡°ÓÉÓÚÓû§Æ¾¾Ý²»Æ¥Å䣬Éí·ÝÑé֤ʧ°Ü¡£ÌṩµÄÓû§ÃûδӳÉäµ½ÏÖÓÐÕÊ»§»òÃÜÂë²»ÕýÈ·¡£¡±Î¢ÈíÌåÏÖ£¬Ö»ÓÐÔÚÓÃ×÷Óò¿ØÖÆÆ÷µÄ·þÎñÆ÷Éϰ²×°¸üкó²Å»á´¥·¢ÎÊÌ⣬´ËÉí·ÝÑéÖ¤ÎÊÌâÊÇÓÉÐÞ¸´ÁËWindows KerberosºÍActive DirectoryÓò·þÎñÖеÄÁ½¸öÌáȨ©¶´£¨CVE-2022-26931ºÍCVE-2022-26923£©ÒýÆðµÄ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-windows-updates-cause-ad-authentication-failures/
5¡¢Î¢Èí·¢ÏÖSysrv-KÀûÓöà¸öЩ¶´°²×°¶ñÒâ¿ó¹¤µÄ»î¶¯
ýÌå5ÔÂ13Èճƣ¬Î¢Èí·¢ÏÖ½©Ê¬ÍøÂç±äÌåSysrv-KÕýÔÚÀûÓÃеĩ¶´£¬ÔÚWindowsºÍLinux·þÎñÆ÷Éϰ²×°¼ÓÃܶñÒâÈí¼þ¡£´Ë´ÎÀûÓõÄ©¶´¾ùÒѱ»ÐÞ¸´£¬ÆäÖаüÂÞWordPress²å¼þÖеÄCVE-2022-22947µÈ½Ïеĩ¶´£¬ÒÔ¼°Spring Cloud Gateway¿âÖеĴúÂë×¢Èë©¶´£¨CVE-2022-22947£©¡£´ËÍ⣬Sysrv-K±äÌ廹Ôö¼ÓÁËй¦Ð§£¬ÀýÈçɨÃèWordPressÅäÖÃÎļþ¼°Æä±¸·ÝÒÔÇÔÈ¡Êý¾Ý¿âƾ¾Ý£¬ÓÃÓÚ½Ó¹ÜÍøÂç·þÎñÆ÷¡£
https://www.bleepingcomputer.com/news/security/microsoft-sysrv-botnet-targets-windows-linux-servers-with-new-exploits/
6¡¢SecureworksÅû¶COBALT MIRAGEÕë¶Ô¶à¹úµÄ¹¥»÷»î¶¯
5ÔÂ12ÈÕ£¬SecureworksÐû²¼³ÂËßÅû¶ÁËCOBALT MIRAGEÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£¸ÃÍÅ»ï´Ó2020Äê6Ô¿ªÊ¼»îÔ¾£¬ÓëÒÁÀÊCOBALT ILLUSION£¨ÓÖ³ÆAPT35£©ÓйØÁª£¬Ö÷ÒªÕë¶ÔÒÔÉ«ÁС¢ÃÀ¹ú¡¢Å·Ö޺ͰĴóÀûÑÇ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¹¥»÷ÕßʹÓÃÁËÁ½ÖÖ²îÒìµÄÈëÇÖ·½Ê½£¬ÆäÖÐÒ»ÖÖÀûÓÃBitLockerºÍDiskCryptor½øÐÐÀÕË÷¹¥»÷£¬ÒÔ»ñÈ¡¾¼ÃÀûÒæ£»ÁíÒ»ÖÖ¸ü¾ßÕë¶ÔÐÔ£¬Ö÷ҪĿµÄÊÇ»ñÈ¡·ÃÎÊȨÏÞºÍÊÕ¼¯Ç鱨£¬µ«ÓÐʱҲ»áʹÓÃÀÕË÷Èí¼þ¡£
https://www.secureworks.com/blog/cobalt-mirage-conducts-ransomware-operations-in-us