Cloudflare³ÆÆä¿Í»§½üÆÚÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷

°ä²¼¹¦·ò 2022-06-16

1¡¢Cloudflare³ÆÆä¿Í»§½üÆÚÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷»î¶¯


CloudflareÔÚ6ÔÂ14ÈÕй©£¬ £¬£¬£¬ £¬ £¬£¬£¬Æä¿Í»§Ôâµ½ÁË´ó¹æÄ£µÄDDoS¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬ £¬£¬£¬ £¬ £¬£¬£¬ËüÒѲÉÈ¡Ðж¯ÕмÜÁËÿÃë2600Íò´ÎÒªÇó(RPS)µÄDDoS¹¥»÷£¬ £¬£¬£¬ £¬ £¬£¬£¬ÕâÊÇÆù½ñΪֹ¼ì²âµ½µÄ×î´óµÄHTTPS DDoS¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷À´×ÔÓÉ5067̨É豸×é³ÉµÄ½©Ê¬ÍøÂ磬 £¬£¬£¬ £¬ £¬£¬£¬Ã¿¸ö½ÚµãÔÚ·åֵʱ²úÉúÔ¼5200 RPS¡£¡£¡£ ¡£¡£¡£¡£¡£¾ÝϤ£¬ £¬£¬£¬ £¬ £¬£¬£¬¸Ã½©Ê¬ÍøÂçÔÚ²»µ½30ÃëµÄ¹¦·òÄÚ´ÓÓ¡¶ÈÄáÎ÷ÑÇ¡¢ÃÀ¹ú¡¢°ÍÎ÷¡¢¶íÂÞ˹ºÍÓ¡¶ÈµÈ121¸ö¹ú¶ÈµÄ1500¶à¸öÍøÂçÖд´½¨Á˳¬¹ý2.12ÒÚ¸öHTTPSÒªÇó£¬ £¬£¬£¬ £¬ £¬£¬£¬Ô¼3%µÄ¹¥»÷À´×ÔTor½Úµã¡£¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/06/cloudflare-saw-record-breaking-ddos.html 


2¡¢¹ú¼ÊÐ̾¯First Light 2022·¨ÂÉÐж¯¿ÛÁôÔ¼2000¸öÏÓÒÉÈË


ýÌå6ÔÂ15ÈÕ±¨Â·£¬ £¬£¬£¬ £¬ £¬£¬£¬¹ú¼ÊÐ̾¯×éÖ¯ÔÚ76¸ö¹ú¶ÈºÍµØÓòµÄ¾¯·½Ð­ÖúÏÂÌáÒéÁË´úºÅΪFirst Light 2022µÄ¹ú¼Ê·¨ÂÉÐж¯¡£¡£¡£ ¡£¡£¡£¡£¡£ÔÚ2022Äê3ÔÂÖÁ5ÔÂÆÚ¼ä£¬ £¬£¬£¬ £¬ £¬£¬£¬·¨ÂÉÈËԱͻϮÁËÈ«ÇòµÄ1770¸öµØÖ·£¬ £¬£¬£¬ £¬ £¬£¬£¬µ÷²éÁËÔ¼3000ÃûÏÓÒÉÈË£¬ £¬£¬£¬ £¬ £¬£¬£¬¿ÛÁôÁËÔ¼2000Ãû²Î¼ÓÉç»á¹¤³Ì¹¥»÷µÄÏÓÒÉÈË£¬ £¬£¬£¬ £¬ £¬£¬£¬¶³½áÁË4000¸öÒøÐÐÕË»§²¢²é·âÁ˼ÛÖµÔ¼5000ÍòÃÀÔªµÄ·¸·¨×ʽ𡣡£¡£ ¡£¡£¡£¡£¡£Õâ´ÎÐж¯³Áµã½ø¹¥Éæ¼°µç»°Ú¿Æ­¡¢ÀËÂþÚ¿Æ­¡¢BEC¹¥»÷ºÍ¹ØÓÚÏ´Ç®µÄÉç»á¹¤³Ì¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/interpol-seizes-50-million-arrests-2000-social-engineers/


3¡¢×êÑÐÍŶӷ¢ÏÖÕë¶ÔIntelºÍAMD CPUµÄ²àÐÅ·¹¥»÷Hertzbleed


¾Ý6ÔÂ14ÈÕ±¨Â·£¬ £¬£¬£¬ £¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖ³ÆÎªHertzbleedµÄвàÐÅ·¹¥»÷£¬ £¬£¬£¬ £¬ £¬£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßÓÃÀ´Í¨¹ý¹Û²ì¶¯Ì¬µçѹºÍƵÂÊËõ·Å(DVFS)ÆôÓõÄCPUƵÂʱ䶯ÇÔÈ¡¼ÓÃÜÃÜÔ¿¡£¡£¡£ ¡£¡£¡£¡£¡£DVFSÊÇÏÖ´úCPUʹÓõÄÒ»ÖÖµçÔ´ÖÎÀí½ÚÁ÷Ö°ÄÜ£¬ £¬£¬£¬ £¬ £¬£¬£¬¿ÉÈ·±£ÏµÍ³Ôڸ߸ºÔØÆÚ¼ä²»»á³¬¹ýÈȺ͹¦ÂÊÏÞ¶È£¬ £¬£¬£¬ £¬ £¬£¬£¬²¢ÔÚµÍCPU¸ºÔØÆÚ¼ä½µµÍÕûÌ幦ºÄ¡£¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÊÇ¿ÉÐеģ¬ £¬£¬£¬ £¬ £¬£¬£¬ÓÉÓÚÔÚIntel(CVE-2022-24436)ºÍAMD(CVE-2022-23823)x86´¦ÖÃÆ÷ÉÏ£¬ £¬£¬£¬ £¬ £¬£¬£¬¶¯Ì¬ÆµÂÊËõ·ÅÈ¡¾öÓÚ¹¦ºÄºÍÔÚ´¦ÖõÄÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¡£IntelºÍAMDй©£¬ £¬£¬£¬ £¬ £¬£¬£¬²»³ïËã°ä²¼²¹¶¡£¡£¡£ ¡£¡£¡£¡£¡£¬ £¬£¬£¬ £¬ £¬£¬£¬µ«°ä²¼ÁËÈôºÎ»º½â´ËÀ๥»÷µÄÖ¸ÄÏ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-hertzbleed-side-channel-attack-affects-intel-amd-cpus/


4¡¢Zimbra½¨¸´¿ÉÇÔÈ¡Óû§µÇ¼ʹ´¦µÄ·ì϶CVE-2022-27924


ýÌå6ÔÂ14Èճƣ¬ £¬£¬£¬ £¬ £¬£¬£¬µç×ÓÓʼþÌ×¼þZimbraÖдæÔÚÒ»¸öÑϳÁµÄ·ì϶£¨CVE-2022-27924£©£¬ £¬£¬£¬ £¬ £¬£¬£¬Ó°ÏìÁË¿ªÔ´ºÍóÒ×°æ±¾8.8.xºÍ9.x¡£¡£¡£ ¡£¡£¡£¡£¡£SonarSource½«¸Ã·ì϶×ܽáΪδ¾­Éí·ÝÑéÖ¤ÒªÇóµÄMemcachedÖж¾£¬ £¬£¬£¬ £¬ £¬£¬£¬Í¨¹ý½«CRLF×¢Èëµ½Memcached²éÕÒµÄÓû§ÃûÖÐÄܹ»ÀûÓô˷ì϶¡£¡£¡£ ¡£¡£¡£¡£¡£³É¹¦ÀûÓÃºó£¬ £¬£¬£¬ £¬ £¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚ²»ÓëÓû§½øÐÐÈκν»»¥µÄÇé¿öÏÂÇÔÈ¡Ã÷ÎĵÄÃÜÂë¡£¡£¡£ ¡£¡£¡£¡£¡£SonarSourceÓÚ½ñÄê3ÔÂ11ÈÕÅû¶·ì϶£»£»£»£»£»£»ZimbraÔÚ3ÔÂ31ÈÕ°ä²¼Á˵ÚÒ»¸ö²¹¶¡£¡£¡£ ¡£¡£¡£¡£¡£¬ £¬£¬£¬ £¬ £¬£¬£¬µ«²»ÄÜÆëÈ«½â¾öÎÊÌ⣻£»£»£»£»£»Ö®ºó£¬ £¬£¬£¬ £¬ £¬£¬£¬¹©¸øÉÌÓÖÔÚ5ÔÂ10ÈÕ°ä²¼²¹¶¡£¡£¡£ ¡£¡£¡£¡£¡£¬ £¬£¬£¬ £¬ £¬£¬£¬ÆëÈ«½¨¸´ÁË·ì϶¡£¡£¡£ ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/06/new-zimbra-email-vulnerability-could.html


5¡¢ÄÏ·ÇÁ¬Ëø³¬ÊÐShopriteÔâµ½RansomHouseµÄÀÕË÷¹¥»÷

      

¾ÝýÌå6ÔÂ14ÈÕ±¨Â·£¬ £¬£¬£¬ £¬ £¬£¬£¬Shoprite Group³ÆÆäÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¡£Õⳤ¶ÌÖÞ×î´óµÄÁ¬Ëø³¬ÊУ¬ £¬£¬£¬ £¬ £¬£¬£¬ÊÕÈë58ÒÚÃÀÔª£¬ £¬£¬£¬ £¬ £¬£¬£¬ÔÚ·ÇÖÞµÄ12¸ö¹ú¶È¾­Óª×Žü3000¼ÒÃŵ꣬ £¬£¬£¬ £¬ £¬£¬£¬Õ¼ÓÐ149000¸öÔ±¹¤¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬ £¬£¬£¬ £¬ £¬£¬£¬Õâ´ÎÊÂÎñ¿ÉÄÜй¶ÁËÆäλÓÚ˹ÍþÊ¿À¼¡¢ÄÉÃ×±ÈÑǺÍÔÞ±ÈÑǵĿͻ§µÄÓ×ÎÒÐÅÏ¢£¬ £¬£¬£¬ £¬ £¬£¬£¬Éæ¼°ÐÕÃûºÍÉí·ÝÖ¤ºÅÂëµÈ¡£¡£¡£ ¡£¡£¡£¡£¡£6ÔÂ14ÈÕ£¬ £¬£¬£¬ £¬ £¬£¬£¬RansomHouseÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬ £¬£¬£¬ £¬ £¬£¬£¬²¢¹«¿ªÁËÒ»·ÝÐû³Æ´ÓShopriteÇÔÈ¡µÄ600GBÊý¾ÝµÄÑù±¾¡£¡£¡£ ¡£¡£¡£¡£¡£


https://therecord.media/large-supermarket-chain-in-southern-africa-hit-with-ransomware/


6¡¢Check Point·¢ÏÖÕë¶ÔÒÔÉ«ÁкÍÃÀ¹úµÄÓã²æÊ½´¹µö¹¥»÷

      

6ÔÂ14ÈÕ£¬ £¬£¬£¬ £¬ £¬£¬£¬Check Point°ä²¼ÁËÒÁÀÊPhosphorusÕë¶ÔÒÔÉ«ÁкÍÃÀ¹úµÄÓã²æÊ½´¹µö¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î»î¶¯Äܹ»×·Òäµ½2021Äê12Ô£¬ £¬£¬£¬ £¬ £¬£¬£¬¹¥»÷Õß½Ù³ÖÁËÒÔÉ«Áи߼¶¹ÙÔ±µÄµç×ÓÓʼþ£¬ £¬£¬£¬ £¬ £¬£¬£¬¶øºóÓÃËüÀ´¹¥»÷ÆäËûÖ¸±ê¡£¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î»î¶¯µÄÖ¸±êÔ̺¬£¬ £¬£¬£¬ £¬ £¬£¬£¬ÒÔÉ«ÁÐǰ±í½»²¿³¤Tzipi Livni¡¢ÃÀ¹úǰפÒÔÉ«ÁдóʹºÍÒÔÉ«Áйú·À¾üǰÉÙ½«µÈÈË¡£¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪ¸Ã»î¶¯µÄ×îÖÕÖ÷ÕÅÊÇÇÔȡָ±êµÄÓ×ÎÒÐÅÏ¢¡¢»¤ÕÕɨÃè¼þºÍ½Ó¼ûµç×ÓÓʼþ£¬ £¬£¬£¬ £¬ £¬£¬£¬²¢½«Æä¹éÒòÓÚÒÁÀʵÄAPTÍÅ»ïPhosphorus¡£¡£¡£ ¡£¡£¡£¡£¡£


https://blog.checkpoint.com/2022/06/14/iranian-spear-phishing-operation-targets-former-israeli-foreign-minister-former-us-ambassador-to-israel-former-israeli-army-general-and-three-other-high-profile-executives/