×êÑÐÍŶÓɨÃè·¢ÏÖ³¬¹ý360Íǫ̀¶³öµÄMySQL·þÎñÆ÷

°ä²¼¹¦·ò 2022-06-02

1¡¢×êÑÐÍŶÓɨÃè·¢ÏÖ³¬¹ý360Íǫ̀¶³öµÄMySQL·þÎñÆ÷


¾ÝýÌå5ÔÂ31ÈÕ±¨Â·£¬£¬£¬£¬£¬°²È«×êÑÐ×éÖ¯Shadowserver FoundationÔÚÉÏÖܽøÐеÄɨÃèÖУ¬£¬£¬£¬£¬·¢ÏÖ³¬¹ý360Íǫ̀¶³öµÄMySQL·þÎñÆ÷ʹÓÃĬÈ϶˿ÚTCP¶Ë¿Ú3306¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ·þÎñÆ÷ÔÚÍøÉϹ«¿ªÂ¶³ö²¢ÏìÓ¦²éÎÊ£¬£¬£¬£¬£¬¿ÉÄܳÉΪºÚ¿ÍºÍÀÕË÷¹¥»÷ÕßµÄÖ¸±ê¡£¡£¡£¡£¡£¡£ ¡£¡£ÆäÖУ¬£¬£¬£¬£¬ÓÐ230Íǫ̀ͨ¹ýIPv4ÏνÓ£¬£¬£¬£¬£¬130Íǫ̀É豸ͨ¹ýIPv6Ïνӡ£¡£¡£¡£¡£¡£ ¡£¡£×î¶àµÄ¹ú¶ÈÊÇÃÀ¹ú£¬£¬£¬£¬£¬Õ¼Óг¬¹ý120Íǫ̀¶³öµÄÉ豸£¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú¡¢ÐÂ¼ÓÆÂ¡¢ºÉÀ¼ºÍ²¨À¼µÈ¹ú¡£¡£¡£¡£¡£¡£ ¡£¡£²»Êʱ¾µØ±£»£»£»£»£»£»£»£»¤MySQLÊý¾Ý¿â·þÎñÆ÷¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢·ÛËéÐԵĹ¥»÷¡¢ÀÕË÷¹¥»÷ÒÔ¼°RATϰȾ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/


2¡¢ÍÁ¶úÆäº½¿Õ¹«Ë¾Pegasus AirlinesµÄ6.5 TBÊý¾Ýй¶


ýÌå5ÔÂ31Èճƣ¬£¬£¬£¬£¬ÍÁ¶úÆäº½¿Õ¹«Ë¾Pegasus AirlinesµÄAWS´æ´¢Í°ÅäÖÃÃýÎ󣬣¬£¬£¬£¬Ð¹Â¶ÁË6.5 TBÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±ÔÚ2ÔÂ28ÈÕ·¢ÏÖÁËÒ»¸öÊ¢¿ªµÄ´æ´¢Í°£¬£¬£¬£¬£¬ÆäÖÐÓÐÔ¼2300Íò·ÝÎĵµ£¬£¬£¬£¬£¬Éæ¼°³¬¹ý300Íò¸ö·ÉÐÐÊý¾ÝÎļþ£¨Èç·ÉÐÐͼ±í¡¢±£ÏÕÎļþºÍ»ú×éÂÖ°àÐÅÏ¢µÈ),³¬¹ý160Íò·Ý»ú×éÈËÔ±µÄPIIÐÅÏ¢£¬£¬£¬£¬£¬ÒÔ¼°Pegasusº½¿Õ¹«Ë¾¿ª·¢µÄµç×Ó·ÉÐаü(EFB)Èí¼þµÄÔ´´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬¸Ã´æ´¢¿âÒѱ»±£»£»£»£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.hackread.com/pegasus-airlines-leak-tb-data-aws-s3-bucket-mess-up/


3¡¢SideWinderÍÅ»ïÔÚ½üÁ½ÄêÖÐÒѽøÐÐ1000ÂŴι¥»÷»î¶¯


¾Ý5ÔÂ31ÈÕ±¨Â·£¬£¬£¬£¬£¬×Ô2020Äê4ÔÂÒÔÀ´£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïSideWinderÒÑÌáÒéÁ˳¬¹ý1000´Î¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£ ¡£¡£Kaspersky°µÊ¾£¬£¬£¬£¬£¬¸ÃÍÅ»ïµÄ²¿ÃÅÌØµãʹÆäÍÑÓ±¶ø³ö£¬£¬£¬£¬£¬Ô̺¬¹¥»÷µÄÊýÁ¿¡¢ÆµÂʺÍÓÆ¾ÃÐÔ£¬£¬£¬£¬£¬ÒÔ¼°ÔÚÆä»î¶¯ÖÐʹÓõĴóÁ¿¼ÓÃܺͻìºÏ¶ñÒâ×é¼þ¡£¡£¡£¡£¡£¡£ ¡£¡£ÔÚ´ÓǰµÄÁ½ÄêÖУ¬£¬£¬£¬£¬¹¥»÷ÕßÒ»ÏòÔËÓª×ÅÒ»¸öÓÉ400¶à¸öÓòºÍ×ÓÓò×é³ÉµÄ´óÐÍC2»ù´¡ÉèÊ©£¬£¬£¬£¬£¬À´ÍйܺͽÚÔì¶ñÒâpayload¡£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±³Æ¸ÃÍÅ»ïʹÓø÷ÀàϰȾý½éºÍÏȽøµÄ¼¼Êõ£¬£¬£¬£¬£¬ÓµÓнϸߵĸ´ÔÓÐÔ£¬£¬£¬£¬£¬½¨Òé×é֯ʹÓÃ×îа汾µÄMicrosoft Office»º½â´ËÀ๥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2022/05/sidewinder-hackers-launched-over-1000.html


4¡¢¶à¹ú·¨Âɲ¿ÃŽáºÏÐж¯³É¹¦µ·»ÙFluBotµÄ»ù´¡ÉèÊ©


Å·ÖÞÐ̾¯×éÖ¯ÔÚ6ÔÂ1ÈÕ°ä·¢£¬£¬£¬£¬£¬ÒѾ­³É¹¦µ·»ÙAndroid¶ñÒâÈí¼þFluBot¡£¡£¡£¡£¡£¡£ ¡£¡£Õâ´Î·¨ÂÉÐж¯Éæ¼°°Ä´óÀûÑÇ¡¢±ÈÀûʱ¡¢·ÒÀ¼¡¢ÐÙÑÀÀû¡¢°®¶ûÀ¼¡¢ÂÞÂíÄáÑÇ¡¢Î÷°àÑÀ¡¢Èðµä¡¢ÈðÊ¿¡¢ºÉÀ¼ºÍÃÀ¹ú¡£¡£¡£¡£¡£¡£ ¡£¡£ÔçÔÚ2021Äê3Ô£¬£¬£¬£¬£¬Î÷°àÑÀ¾¯·½Ôø¿ÛÁôÁË4ÃûÏÓÒÉÈË£¬£¬£¬£¬£¬ËûÃDZ»ÒÔΪÊÇFluBot»î¶¯µÄÖØÒª³ÉÔ±£¬£¬£¬£¬£¬µ«Õâ´ÎÖжÏÖ»ÊÇÁÙʱµÄ£¬£¬£¬£¬£¬¹¥»÷Õß²»¾ÃºóÆðÍ·Õë¶ÔÎ÷°àÑÀÖ®±íµÄ¹ú¶È¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâÒ»´Î£¬£¬£¬£¬£¬Å·ÖÞÐ̾¯×é֯ǿµ÷£¬£¬£¬£¬£¬FluBotµÄ»ù´¡ÉèÊ©ÒÑ´¦ÓÚ·¨Âɲ¿ÃŵĽÚÔì֮ϣ¬£¬£¬£¬£¬Òò¶ø²»³ÉÄÜÔÙËÀ»Ò¸´È¼¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/flubot-android-malware-operation-shutdown-by-law-enforcement/


5¡¢Check Point°ä²¼¹ØÓÚ½©Ê¬ÍøÂçXLoaderµÄ·ÖÎö»ã±¨


5ÔÂ31ÈÕ£¬£¬£¬£¬£¬Check Point°ä²¼¹ØÓÚа汾µÄ½©Ê¬ÍøÂçXLoaderµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£ ¡£¡£XLoaderÊÇÒ»¸öÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬×î³õ»ùÓÚFormbook£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔWindowsºÍmacOS£¬£¬£¬£¬£¬ËüÓÚ2021Äê1Ô³õ´Î±»¿í·ºµØÀûÓᣡ£¡£¡£¡£¡£ ¡£¡£×îа汾¶ÔC2³É¹¦µÄ½Ó¼ûÔ´ÓÚ¸ÅÂÊÂ۵ĴóÊý¶¨ÂÉ£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±±ØÐë¾­¹ýÈß³¤µÄÄ£ÄâÄÜÁ¦µÃÓ¿ÏÖʵµÄC2µØÖ·£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ²»³£¼ûµÄ×ö·¨£¬£¬£¬£¬£¬Ëü»áʹËùÓеÄ×Ô¶¯¾ç±¾±äµÃºÁÎÞÓô¦¡£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±·¢´Ë¿Ì2.6°æ±¾ÖУ¬£¬£¬£¬£¬XLoader´Ó64λµÄpayloadÖÐɾ³ýÁËÕâÒ»Ö°ÄÜ£¬£¬£¬£¬£¬Ã¿´Î³ÇÊÐÏνÓÕæÕýµÄC2Óò£»£»£»£»£»£»£»£»µ«ÔÚ32λϵͳÖУ¨Ò²¾ÍÊÇ×êÑÐÈËԱʹÓõÄɳºÐÖг£¼ûµÄϵͳ£©£¬£¬£¬£¬£¬±£ÁôÁËÕâ¸öеÄC2»ìºÏÖ°ÄÜ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/new-xloader-botnet-uses-probability-theory-to-hide-its-servers/


6¡¢Unit 42°ä²¼2021Äê11ÔÂÖÁ2022Äê1ÔÂÍøÂçÍþвµÄ·ÖÎö»ã±¨


Unit 42ÔÚ5ÔÂ31ÈÕ°ä²¼ÁË2021Äê11ÔÂÖÁ2022Äê1ÔÂÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£ ¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÔÚÕâÈý¸öÔÂÖÐ×ܹ²³öÏÖÁË6443¸öзì϶£¬£¬£¬£¬£¬ÆäÖÐ31.3%ÊDZ¾µØ·ì϶£¬£¬£¬£¬£¬¶øÔü×ÒµÄ68.7%ÊÇÔ¶³Ì·ì϶¡£¡£¡£¡£¡£¡£ ¡£¡£×î³£¼ûµÄ·ì϶ÀàÐÍÊÇ¿çÕ¾¾ç±¾·ì϶£¬£¬£¬£¬£¬Æä´ÎÊǻؾø·þÎñ·ì϶¡¢»º³åÇøÒç¶Âí½ÅºÍÌáȨ·ì϶¡£¡£¡£¡£¡£¡£ ¡£¡£×î³£¼ûµÄ¹¥»÷ÀàÐÍÊÇÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬Æä´ÎÊÇÐÅϢй¶ºÍ±éÀú¡£¡£¡£¡£¡£¡£ ¡£¡£×î¶àµÄ¹¥»÷À´×ÔÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬Ö®ºóÊǵ¹úºÍ¶íÂÞ˹£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÓпÉÄÜʹÓÃÁË´úÀíºÍVPNÀ´°µ²ØÏÖʵµØÎ»¡£¡£¡£¡£¡£¡£ ¡£¡£


https://unit42.paloaltonetworks.com/network-security-trends-cross-site-scripting/