¶íÂÞ˹Áª°î´¢ÐîÒøÐÐSberbankÔâµ½´ó¹æÄ£DDoS¹¥»÷

Ðû²¼Ê±¼ä 2022-05-23
1¡¢¶íÂÞ˹Áª°î´¢ÐîÒøÐÐSberbankÔâµ½´ó¹æÄ£DDoS¹¥»÷


¾ÝýÌå5ÔÂ20ÈÕ±¨µÀ £¬Áª°î´¢ÐîÒøÐÐSberbankÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£SberbankÊǶíÂÞ˹×î´óµÄ½ðÈÚ»ú¹¹ £¬Ò²ÊÇÅ·ÖÞµÚÈý´ó½ðÈÚ»ú¹¹ £¬×Ü×ʲúÁè¼Ý5700ÒÚÃÀÔª¡£¹¥»÷·¢ÉúÔÚ5ÔÂ6ÈÕ £¬SberbankÌåÏÖËûÃÇÒÑÀֳɵÖÓù¸ß´ï450 GB/ÃëµÄ¹¥»÷¡£¾ÝϤ £¬¶ñÒâÁ÷Á¿À´×ÔÒ»¸ö½©Ê¬ÍøÂç £¬Æä°üÂÞÁËλÓÚÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾ºÍÖйų́ÍåµÄ27000̨±»Ñ¬È¾µÄÉ豸 £¬ÆäÖÐÐí¶à¹¥»÷ÀûÓÃÁËÔÚÏßÁ÷ýÌåºÍÓ°Ï·ÔºÍøÕ¾µÄÁ÷Á¿¡£¸ÃÒøÐгÆ £¬×Ô2Ô·ݳåÍ»ÒÔÀ´ £¬ÕâÖÖ¹¥»÷´Óδ¼õÈõ¡£


https://www.bleepingcomputer.com/news/security/russian-sberbank-says-it-s-facing-massive-waves-of-ddos-attacks/


2¡¢Ã½Ì幫˾ÈÕ¾­¼¯ÍŵÄмÓÆ·ֲ¿³ÆÆäÔâµ½ÀÕË÷¹¥»÷


¾Ý5ÔÂ21ÈÕ±¨µÀ £¬ÈÕ¾­¼¯ÍÅмÓÆ·ֲ¿³ÆÆäһ̨·þÎñÆ÷Ôâµ½ÁËÀÕË÷¹¥»÷¡£ÈÕ¾­£¨Nikkey£©ÊÇÈÕ±¾µÄýÌ幫˾ £¬×¨×¢ÓÚÉÌÒµºÍ½ðÈÚÐÐÒµ £¬ËüÊÇÈ«Çò×î´óµÄ²Æ¾­±¨Ö½¡£¸Ã¹«Ë¾ÔÚ5ÔÂ13ÈÕÊ״μì²âµ½Æä·þÎñÆ÷Ôâµ½ÁËδ¾­ÊÚȨµÄ·ÃÎÊ £¬Ö®ºóÁ¢¼´Õ¹¿ªÁËÄÚ²¿ÊÓ²ì £¬²¢¹Ø±ÕÁËÊÜÓ°ÏìµÄ·þÎñÆ÷¡£¸Ã¹«Ë¾ÌåÏÖ £¬ÊÜÓ°ÏìµÄ·þÎñÆ÷¿ÉÄÜ°üÂÞ¿Í»§Êý¾Ý £¬ËûÃÇÏÖÔÚÕýÔÚÈ·¶¨¹¥»÷µÄÐÔÖʺͷ¶Î§ £¬½ØÖÁÄ¿Ç° £¬²¢Î´·¢ÏÖÊý¾Ýй¶µÄ¼£Ïó¡£


https://securityaffairs.co/wordpress/131533/data-breach/nikkei-data-breach.html


3¡¢CiscoÐÞ¸´IOS XRÈí¼þÒѱ»ÀûÓõÄ©¶´CVE-2022-20821


5ÔÂ20ÈÕ £¬CiscoÐû²¼Äþ¾²¸üР£¬ÐÞ¸´ÆäIOS XRÈí¼þÖеÄÒ»¸öÒѱ»ÀûÓõÄ©¶´¡£¸Ã©¶´×·×ÙΪCVE-2022-20821 £¬ÊÇÓÉÓÚ½¡¿µ¼ì²éRPMÔÚ¼¤»îʱĬÈÏ´ò¿ªTCP¶Ë¿Ú6379µ¼ÖµÄ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýÁ¬½Óµ½¿ª·Å¶Ë¿ÚÉϵÄRedisʵÀýÀ´ÀûÓôË©¶´¡£CiscoÔÚͨ¸æÖгÆ £¬ÀÖ³ÉÀûÓø鶴¿ÉʵÏÖRedisÄÚ´æÊý¾Ý¿âдÈë £¬½«ÈÎÒâÎļþдÈëÈÝÆ÷Îļþϵͳ £¬²¢¼ìË÷ÓйØRedisÊý¾Ý¿âµÄÐÅÏ¢¡£¸Ã¹«Ë¾ÌåÏÖÔÚ±¾ÔµÄÔçЩʱºò·¢ÏÖÓÐÈËÊÔͼÀûÓÃËü £¬Ç¿ÁÒ½¨Òé¿Í»§ÐÞ¸´´Ë©¶´¡£


https://thehackernews.com/2022/05/cisco-issues-patches-for-new-ios-xr.html


4¡¢Ö¥¼Ó¸ç¹«Á¢Ñ§Ð£µÄ¹©Ó¦ÉÌÔâµ½¹¥»÷ £¬50ÍòѧÉúµÄÐÅϢй¶


ýÌå5ÔÂ21ÈÕ³Æ £¬Ö¥¼Ó¸ç495448¸öѧÉúºÍ56138¸öÔ±¹¤µÄÊý¾ÝÒѾ­Ð¹Â¶¡£Ð¹Â¶Ê¼þÔ´ÓÚÖ¥¼Ó¸ç¹«Á¢Ñ§Ð££¨CPS£©µÄ¹©Ó¦ÉÌBattelle for KidsÔÚ12ÔÂÔâµ½ÁËÀÕË÷¹¥»÷ £¬µ¼ÖÂÆäѧУϵͳÖеĴ洢Êý¾Ýй¶¡£¸Ã¹«Ë¾Óë267¸öѧУϵͳºÏ×÷ £¬ÏîÄ¿Éæ¼°Áè¼Ý280ÍòѧÉú¡£´Ë´Îй¶ÁË2015ÖÁ2019ѧÄêµÄÊý¾Ý £¬°üÂÞѧÉúµÄ¸öÈËÐÅÏ¢ºÍ·ÖÊý £¬ÒÔ¼°Ô±¹¤µÄ¸öÈËÐÅÏ¢µÈ¡£¾¡¹ÜCPSÒªÇó¸Ã¹«Ë¾Á¢¼´Í¨ÖªÊý¾Ýй¶Çé¿ö £¬µ«ÆäÔÚÁè¼Ý4¸öÔºó²ÅÅû¶ÁËÎ¥¹æÐÐΪ¡£


https://www.bleepingcomputer.com/news/security/ransomware-attack-exposes-data-of-500-000-chicago-students/


5¡¢AhnLab·¢ÏÖLazarusÕë¶Ôº«¹ú·Ö·¢ºóÃÅNukeSpedµÄ»î¶¯


5ÔÂ19ÈÕ £¬AhnLabÐû²¼³ÂËßÅû¶ÁËLazarusÍÅ»ïÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯¡£´Ë´Î»î¶¯ÖÐ £¬¹¥»÷ÕßÀûÓÃÁËVMware Horizon·þÎñÆ÷ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´Log4J£¨CVE-2021-44228£©À´×¢ÈëºóÃÅNukeSped¡£AhnLab·¢ÏָúóÃŵÄбäÌåÊÇÓÃC++±àдµÄ £¬²¢Ê¹ÓÃRC4¼ÓÃÜÓëC2µÄͨÐÅ£¨ÒÔǰʹÓÃXOR£©¡£¸Ã±äÌåÐÂÔöÁËÁ½¸öÄ £¿é £¬Ò»¸öÓÃÓÚת´¢USBÄÚÈÝ £¬ÁíÒ»¸ö·ÃÎÊÍøÂçÉãÏñÍ·É豸¡£´ËÍâ £¬NukeSped»¹±»ÓÃÓÚ°²×°ÌرðµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬ÊÕ¼¯ä¯ÀÀÆ÷ÖеÄÐÅÏ¢¡£


https://asec.ahnlab.com/en/34461/


6¡¢Ñо¿ÍŶӷ¢ÏÖRust¹©Ó¦Á´¹¥»÷»î¶¯CrateDepression


SentinelOneÔÚ5ÔÂ19ÈÕÐû²¼³ÂËß³Æ £¬·¢ÏÖÁËÕë¶ÔRust¿ª·¢ÉçÇøµÄ¹©Ó¦Á´¹¥»÷»î¶¯ £¬²¢³Æ֮Ϊ¡°CrateDepression¡±¡£5ÔÂ10ÈÕ £¬RustÐû²¼Í¨¸æÌåÏÖÔÚRust´æ´¢¿âÖз¢ÏÖÁËÒ»¸ö¶ñÒâcrate¡° rustdecimal¡± £¬ËüÊÇÄ£·ÂÁËÕæÕýµÄ°ü¡°rust_decimal¡±¡£Ñо¿·¢ÏÖ £¬¶ñÒâÒÀÀµÏî»á¼ì²é»·¾³±äÁ¿ £¬Õâ±íÃ÷Ëü¶ÔGitLabÁ¬Ðø¼¯³É(CI)¹ÜµÀÓÐÌØÊâÐËȤ £¬±»Ñ¬È¾µÄCI¹ÜµÀÌṩµÚ¶þ½×¶ÎµÄpayload¡£¶ñÒâcrateÓÚ3ÔÂ25ÈÕÊ×´ÎÍÆËÍ £¬ÏÖÔÚÒÑÔÚ´æ´¢¿âÖÐÓÀ¾Ãɾ³ý £¬ÏÂÔØÁ¿²»µ½500´Î¡£


https://www.sentinelone.com/labs/cratedepression-rust-supply-chain-attack-infects-cloud-ci-pipelines-with-go-malware/