ºÚ¿ÍÔÚ°µÍø°ä²¼DriveSureµÄ320Íò¸öÓû§µÄÊý¾Ý£»¶à¸öÀÕË÷ÍÅ»ïÕë¶ÔESXiµÄÐé¹¹»úÖеÄÓ²Å̽øÐмÓÃÜ
°ä²¼¹¦·ò 2021-02-031.ºÚ¿ÍÔÚ°µÍø°ä²¼DriveSureµÄ320Íò¸öÓû§µÄÊý¾Ý

ºÚ¿ÍÔÚRaidforums°µÍøÂÛ̳Éϰ䲼ÁË´ÓDriveSureÇÔÈ¡µÄ320Íò¸öÓû§µÄÊý¾Ý¡£DriveSureÊÇÆû³µ¾ÏúÉ̵ķþÎñÌṩÉÌ£¬ÖØÒª´ÓÊÂÔ±¹¤Åàѵ´òËãºÍ¿Í»§ÊØ»¤¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢Æû³µÔì×÷É̺ÍÐͺš¢VINÂë¡¢Æû³µ·þÎñ¼Í¼ºÍ¾Ïú¼Í¼¡¢°Ü»µË÷ÅâºÍ¹þÏ£ÃÜÂë¡£ºÚ¿ÍÓÚ2020Äê12ÔÂ19ÈÕй¶ÁËÊý¾Ý£¬¶ø×êÑÐÈËÔ±ÓÚ1ÔÂ4ÈÕÖ®ºó²Å·¢ÏÖÁ˶³öµÄÊý¾Ý¿â¡£
ÔÎÄÁ´½Ó£º
https://www.scmagazine.com/home/security-news/data-on-3-2-million-drivesure-users-exposed-on-hacking-forum/
2.»ªÊ¢¶ÙÖÝÉó¼ÆÊ¦°ì¹«ÊÒй¶160Íò¾ÓÃñµÄÓ×ÎÒÐÅÏ¢

»ªÊ¢¶ÙÖÝÉó¼ÆÊ¦°ì¹«ÊÒ£¨SAO£©Ôâµ½¹¥»÷£¬Ð¹Â¶ÁË160Íò¾ÓÃñµÄÓ×ÎÒÐÅÏ¢¡£SAO³ÆºÚ¿ÍÀûÓÃAccellionµÄ°²È«Îļþ´«Êä·þÎñÖеķì϶ÌáÒé¹¥»÷¡£¹¥»÷²úÉúÔÚ2020Äê12ÔÂÏÂÑ®£¬¶øÖ±µ½2021Äê1ÔÂ25ÈÕAccelion²ÅÏòSAOÈ·ÈÏÆäÔâµ½¹¥»÷£¬ÓйØÃÀ¹ú¾ÍÒµ°²È«Êý£¨ESD£©µÄʧҵÅâ³¥µÄÊý¾ÝÎļþй¶¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬ÈËÔ±µÄÐÕÃû¡¢Éç»á±£ÏպŻò¼ÝÊ»ÅÆÕÕ¡¢ÒøÐÐÕʺźÍÒøÐзÏß±àºÅÒÔ¼°¹¤×÷µØÖ·¡£´Ë±í£¬Ò»Ð©»ªÊ¢¶Ù´¦Ëùµ±¾ÖºÍÆäËûÖÝ»ú¹¹µÄÎļþÒ²Êܵ½ÁËÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/data-breach-exposes-16-million-washington-unemployment-claims/
3.¶à¸öÀÕË÷ÍÅ»ïÕë¶ÔESXiµÄÐé¹¹»úÖеÄÓ²Å̽øÐмÓÃÜ

½üÆÚ£¬¶à¸öÀÕË÷Èí¼þÍÅ»ïÔÚÀûÓÃVMWare ESXi²úÆ·Öеķì϶£¬ÒÔÊÕÊÜÆóÒµ»·¾³ÖеÄÐé¹¹»ú²¢¶ÔÆäÐé¹¹Ó²Å̽øÐмÓÃÜ¡£¹¥»÷ÕßʹÓÃÁËESXiÖÐÓ°Ïì·þÎñ¶¨Î»ºÍ̸£¨SLP£©CVE-2019-5544ºÍCVE-2020-3992·ì϶£¬ÆäÔʺܶà¸öÐé¹¹»ú¹²ÏíͳһӲÅÌ´æ´¢¡£¸Ã¹¥»÷ÓÚÈ¥Äê10Ô³õ´Î·¢ÏÖ£¬ÓëRansomExxÍÅ»ïÓйأ¬×ÔÉϸöÔÂBabuk LockerÒ²ÌáÒéÁËÀàËÆµÄ¹¥»÷¡£´Ë±í£¬Íþвµý±¨¹«Ë¾KELA³Æ£¬ºÚ¿ÍÈ¥Ä껹ÔÚ°µÍøÉÏÏúÊÛ¶ÔESXiÊ·ýµÄ½Ó¼ûȨÏÞ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-gangs-are-abusing-vmware-esxi-exploits-to-encrypt-virtual-hard-disks/
4.Linux¶ñÒâÈí¼þKobalos¶Ô׼ȫÇòµÄ³¬µÈÍÆËã»ú

ESET·¢ÏÖLinux¶ñÒâÈí¼þKobalos£¬ÔÚ¶Ô׼ȫÇòµÄ³¬µÈÍÆËã»ú¡£¸Ã¶ñÒâÈí¼þÖØÒªÕë¶ÔѧÊõºÍ×êÑÐÍøÂçÖеĸ߻úÄÜÍÆËã»ú£¨HPC£©ºÍ·þÎñÆ÷£¬Ö¼ÔÚÇÔÈ¡SSHÍ´´¦¡£KobalosÒìºõѰ³£µÄÊÇ£¬Æä´úÂë¿âºÜÓ×£¬µ«×ã¹»¸´ÔÓ£¬×ãÒÔÓ°ÏìLinux¡¢BSDºÍSolaris²Ù×÷ϵͳ£¬ÕâÖÖ¸´ÔÓˮƽÔÚLinux¶ñÒâÈí¼þÖкÜÉÙ¼û¡£KobalosÐÔÖÊÉÏÊÇÒ»¸öºóÃÅ£¬Ò»µ©×°ÖÃÔÚ³¬µÈÍÆËã»úÉϾͻᰵ²ØÔÚOpenSSH·þÎñÆ÷¿ÉÖ´ÐÐÎļþÖУ¬ÈôÊÇͨ¹ýÌØ¶¨µÄTCPÔ´¶Ë¿Ú½øÐÐŲÓã¬Ôò»á´¥·¢ºóÃÅ£¬Æä¿ÉÄÜͨ¹ýµ¥¸öºÅÁÊÜϰȾµÄ·þÎñÆ÷ת»»ÎªC2¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/this-linux-malware-is-hijacking-supercomputers-across-the-globe/
5.µ±¾Ö±í°üSercoϰȾBabuk£¬»òÒÑй¶³¬¹ý1TBÊý¾Ý

Ó¢¹úµÄ¿ç¹úµ±¾Ö±í°üSercoϰȾÀÕË÷Èí¼þBabuk£¬»òÒÑй¶³¬¹ý1TBÊý¾Ý¡£SercoÒÑÈ·ÈÏÆäÔâµ½¹¥»÷£¬³ÆÖ»Ó°ÏìÁËÆäÔÚÅ·ÖÞµÄÒµÎñ£¬²¢Î´Ð¹Â©¹¥»÷µÄÓ°ÏìÁìÓòºÍÊê½ðÒªÇó¡£¹¥»÷ÕßÔòÐû³ÆÆäÔÚSercoµÄÍøÂçÖÐÂñ·üÁËԼĪÈýÖÜ£¬²¢ÇÔÈ¡Á˳¬¹ý1TBµÄÊý¾Ý¡£¾Ý±¨Â·£¬¸Ã×¢Ã÷°µÊ¾Óйر±Ô¼ºÍ±ÈÀûʱ¾ü¶ÓµÈºÏ×÷ͬ°éµÄÎļþ¿ÉÄÜÒÑÔÚ¹¥»÷ÖÐй¶¡£µ«ÊÇ£¬ºÚ¿ÍĿǰ»¹Î´°ä²¼Èκα»µÁÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/global-government-outsourcer-serco/


¾©¹«Íø°²±¸11010802024551ºÅ