ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ21ÖÜ
°ä²¼¹¦·ò 2021-05-24> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼°²È«·ì϶51¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»£»£»£»£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç¶Âí½Å£»£»£»£»£»SolarWinds Orion Job Scheduler JobRouterService²»ÕýÈ·ÊÚȨ´úÂëÖ´Ðзì϶£»£»£»£»£»Cisco DNA Space CVE-2021-1559 OSºÅÁîÖ´Ðзì϶£»£»£»£»£»Ubiquiti Networks EdgeRouter²»ÕýÈ·Ö¤ÊéУÑéËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEϰȾConti£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»£»£»£»£»DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢°ä·¢½«ÖÕÖ¹ÔËÓª£»£»£»£»£»×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»£»£»£»£»Netscout°ä²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨£»£»£»£»£»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Microsoft Windows JETÊý¾Ý¿âÒýÇæ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-594/
2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç¶Âí½Å
Pulse Connect Secureä¯ÀÀSMB¹²Ïí´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
3.SolarWinds Orion Job Scheduler JobRouterService²»ÕýÈ·ÊÚȨ´úÂëÖ´Ðзì϶
SolarWinds Orion Job Scheduler JobRouterService´æÔÚ²»ÕýÈ·ÊÚȨ·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-605/
4.Cisco DNA Space CVE-2021-1559 OSºÅÁîÖ´Ðзì϶
Cisco DNA Space´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ROOT¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n
5.Ubiquiti Networks EdgeRouter²»ÕýÈ·Ö¤ÊéУÑéËÁÒâ´úÂëÖ´Ðзì϶
Ubiquiti Networks EdgeRouter HTTPSÏÂÔØ¹Ì¼þ´æÔÚÖ¤ÊéУÑé·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ROOT¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-601/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEϰȾConti£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª

°®¶ûÀ¼µÄÒ½ÁÆ·þÎñ»ú¹¹HSE°µÊ¾£¬£¬£¬£¬£¬£¬£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔÚ·¢ÏÖ¹¥»÷ºó£¬£¬£¬£¬£¬£¬£¬ÒÑÓÚÉÏÖÜÎ幨¹ØÁËËùÓÐITϵͳ¡£¡£¡£¡£¡£¡£¡£¡£ContiÍÅ»ïÐû³ÆÒѾ½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬£¬£¬£¬£¬£¬£¬ÔÚ´ËÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬Ô̺¬»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ºÏͬ¡¢²ÆÕþ±¨±íºÍ¹¤×ʵ¥µÈ¡£¡£¡£¡£¡£¡£¡£¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎŰ䲼»áÉϰµÊ¾£¬£¬£¬£¬£¬£¬£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/
2¡¢DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢°ä·¢½«ÖÕÖ¹ÔËÓª

DarkSideÊÇÒ»¸öÀÕË÷Èí¼þ·þÎñÆ÷ÍŻRaaS£©£¬£¬£¬£¬£¬£¬£¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕ°ä²¼ÉêÃ÷³Æ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ·¨ÂÉÐж¯£¬£¬£¬£¬£¬£¬£¬ËûÃÇĿǰÒѾÎÞ·¨Í¨¹ýSSH½Ó¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶·þÎñÆ÷ºÍCDN·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ö÷»ú½çÃæ¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬£¬£¬£¬£¬£¬£¬²¢³ÐŵÔÚ2021Äê5ÔÂ23ÈÕ֮ǰ³¥»¹ËùÓÐδ³¥Õ®Îñ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÉêÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬£¬£¬£¬£¬£¬£¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime
3¡¢×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ

¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖеİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£¡£¡£¡£¡£¡£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÓµÓÐx64Ä£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬Äܹ»ÓÕÆÊܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬£¬£¬£¬£¬£¬£¬»¹ÀûÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆÊܺ¦ÕßÏÂÔØÒÆ¶¯ÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄÖ÷Ìâ×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öºÅÁîµÄºóÃÅ£¬£¬£¬£¬£¬£¬£¬Ö»Óе±Æä¼ì²âµ½ÒѾÏνӵ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬£¬£¬£¬£¬£¬£¬ºóÃŲŻáÆô¶¯¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html
4¡¢Netscout°ä²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨

Netscout°ä²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢ÆðÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬±È2020ÄêͬÆÚÔö³¤ÁË31£¥£¬£¬£¬£¬£¬£¬£¬×î´óΪ480 Gbps£¬£¬£¬£¬£¬£¬£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬£¬£¬£¬£¬£¬£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÔÚÏß·þÎñÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/asert/beat-goes
5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps

UptycsÍþв×êÑÐÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£¡£¡£¡£¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÖ¸±ê½øÐÐÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýWgetÀ´ÀûÓÃshell¾ç±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª·ÖÆçµÄ»ùÓÚLinuxµÄϵͳװÖÃSimps payload¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÒ»ÌõÔ̺¬Gafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±´§¶È¸Ã¶ñÒâÈí¼þÓëKeksecÍÅ»ïÓйء£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group


¾©¹«Íø°²±¸11010802024551ºÅ