CyberX9³ÆÓ¡¶È֤ȯ»ú¹¹CDSL 4390ÍòÓû§ÐÅϢй¶

°ä²¼¹¦·ò 2021-11-11

MediaMarktÔâµ½Hive¹¥»÷²¢±»ÀÕË÷2.4ÒÚÃÀÔª


MediaMarktÔâµ½Hive¹¥»÷²¢±»ÀÕË÷2.4ÒÚÃÀÔª.png


MediaMarktÔÚÖÜÈÕÍíÉÏÖÁÖÜÒ»ÔçÉÏÔâµ½À´×ÔHiveµÄÀÕË÷¹¥»÷£¬²¢±»ÒªÇóÖ§¸¶2.4ÒÚÃÀÔª¡£MediaMarktÊÇÅ·ÖÞ×î´óµÄµç×Ó²úÆ·ÁãÊÛÉÌ£¬ÔÚ13¸ö¹ú¶ÈÕ¼ÓÐ1000¶à¼ÒÉ̵꣬×ÜÏúÊÛ¶îΪ208ÒÚÅ·Ôª¡£Õâ´Î¹¥»÷ÖØÒªÓ°ÏìÁËλÓڵ¹úºÍºÉÀ¼µÄÉ̵꣬¹¤×÷ÈËÔ±ÎÞ·¨½ÓÊÜÐÅÓþ¿¨¸¶¿î»ò´òÓ¡ÊÕÌõ£¬µ«ÍøÉÏÉ̵êûÓÐÊÕµ½Ó°Ïì¡£¾ÝÄÚ²¿ÈËÔ±³ÆÓÐ3100̨·þÎñÆ÷Òѱ»¼ÓÃÜ£¬Ä¿Ç°ÉÐÎÞ·¨È·¶¨ÕâÖÖ˵·¨µÄÕýÈ·ÐÔ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mediamarkt-hit-by-hive-ransomware-initial-240-million-ransom/



΢Èí°ä²¼11Ô¸üУ¬½¨¸´6¸ö0dayÔÚÄÚµÄ55¸ö·ì϶


΢Èí°ä²¼11Ô¸üУ¬½¨¸´6¸ö0dayÔÚÄÚµÄ55¸ö·ì϶.png


΢ÈíÔÚ11ÔÂ9ÈÕ°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬×ܼƽ¨¸´ÁË55¸ö·ì϶¡£Õâ´Î½¨¸´ÁË6¸ö0 day£¬Ô̺¬ExcelÖа²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2021-42292£©¡¢Exchange ServerÖÐRCE£¨CVE-2021-42321£©£¬RDPÖÐÐÅϢй¶·ì϶£¨CVE-2021-38631ºÍCVE-2021-41371£©£¬ÒÔ¼°3DÖв鿴Æ÷RCE£¨CVE-2021-43208ºÍCVE-2021-43209£©¡£ÆäÖУ¬CVE-2021-42292ºÍCVE-2021-42321Òѱ»ÓÃÓÚ¶ñÒâ¹¥»÷»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2021-patch-tuesday-fixes-6-zero-days-55-flaws/



CyberX9³ÆÓ¡¶È֤ȯ»ú¹¹CDSL 4390ÍòÓû§ÐÅϢй¶


CyberX9³ÆÓ¡¶È֤ȯ»ú¹¹CDSL 4390ÍòÓû§ÐÅϢй¶.png


°²È«ÍŶÓCyberX9ÔÚ11ÔÂ7ÈÕÅû¶ӡ¶È֤ȯÍйܻú¹¹CDSLµÄ4390ÍòÓû§ÐÅϢй¶¡£ÔçÔÚʮԳõ£¬×êÑÐÈËÔ±·¢ÏÖCDSL´æÔÚÑϳÁµÄ·ì϶£¬¿Éй¶4390ÍòͶ×ÊÕßµÄÓ×ÎÒÐÅÏ¢ºÍ²ÆÕþÊý¾Ý¡£10ÔÂ26ÈÕ£¬·ì϶Òѱ»½¨¸´¡£µ«ÊÇ£¬×êÑÐÈËÔ±ÓÚ10ÔÂ29ÈÕ·¢ÏÖеIJ¹¶¡Äܹ»µÈÏеر»Èƹý£¬ÒÀÈ»Äܹ»Ð¹Â¶4390ÍòÈ˵ÄÊý¾Ý¡£Õâ´Îй¶µÄÐÅÏ¢Äܹ»×·Òäµ½2005Äê×óÓÒ×¢²áµÄÓû§£¬ÓÉÓÚ´ËÀàÊý¾ÝµÄÃô¸Ð¶È½Ï¸ß£¬ÈôÊÇÂäÈë¹¥»÷ÕßÊÖÖжÔÓû§À´Ëµ¿ÉÄÜÊÇÖÂÃüµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberx9.com/cdsl-data-exposed-again-blog



ÂÞÂíÄáÑǵ±¾Ö¿ÛÁôREvilÍÅ»ïÔø¹¥»÷KaseyaµÄ³ÉÔ±


ÂÞÂíÄáÑǵ±¾Ö¿ÛÁôREvilÍÅ»ïÔø¹¥»÷KaseyaµÄ³ÉÔ±.png


ÂÞÂíÄáÑÇ·¨Âɲ¿ÃÅÔÚ11ÔÂ8ÈÕ°ä²¼ÐÂΟ壬³ÆËûÃÇÔÚ11ÔÂ4ÈÕ¿ÛÁôÁËÁ½ÃûÀÕË÷ÍÅ»ïREvil´ÓÊô×éÖ¯µÄ³ÉÔ±¡£Õâ´ÎÐж¯ÃûΪGoldDust£¬ÔøÓÚ2ÔÂÔÚ¿ÆÍþÌØºÍº«¹ú¿ÛÁôÁËÈý¸öREvilÍÅ»ïµÄ³ÉÔ±ºÍÁ½¸öÓëGandCrabÓйØÁªµÄÏÓÒÉÈË¡£Õâ´ÎÐж¯¿ÛÁôÁËÒ»¸ö22ËêµÄÎÚ¿ËÀ¼ÄêÇáÈËYaroslav Vasinskyi£¬ËûÔÚ½ñÄê7Ô¹¥»÷ÁË·ðÂÞÀï´ïÖݵÄÈí¼þ¹«Ë¾Kaseya£¬Ó°ÏìÁ˶à´ï1500¸öÏÂÓι«Ë¾¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/suspected-revil-ransomware-affiliates.html



F5°ä²¼¹ØÓÚÊý×Ö»¯×ªÐÍËùÃæ¶ÔΣÏյķÖÎö»ã±¨


F5°ä²¼¹ØÓÚÊý×Ö»¯×ªÐÍËùÃæ¶ÔΣÏյķÖÎö»ã±¨.png


11ÔÂ5ÈÕ£¬F5°ä²¼Á˹ØÓÚÊý×Ö»¯×ªÐÍËùÃæ¶ÔΣÏյķÖÎö»ã±¨¡£×¨Ò»ÓÚÊý×ÖתÐ͵Ä×éÖ¯±ØÒª½«·ÖÆçµÄÀûÓ÷¨Ê½¡¢ÏµÍ³ºÍ·þÎñÆ´½Ó³ÉÎÞ·ìµÄÊý×ÖÂÄÀú£¬Ò²¾ÍÊÇ˵×éÖ¯ÒѾ­½ÓÊÜÁËAPI¡£×êÑÐÈËÔ±¹À¼Æ£¬Èç½ñ¹«¹²ºÍ˽ÓÐAPIµÄ×ÜÁ¿¿¿½ü2ÒÚ£¬µ½2031ÄêÕâÒ»Êý×Ö¿ÉÄÜ»á´ïµ½ÊýÊ®ÒÚ¡£¶øAPIµÄÀ©ÕŸøÔËÓªºÍ°²È«·½Ãæ´øÀ´ÁËÌôÕ½£¬ÀýÈçËæ×ÅAPIÊýÁ¿ºÍÀûÓø´ÔÓÐÔµÄÔö³¤£¬×·×ÙAPIµÄµØÎ»±äµÃÄÑÌâ £»ÒÔ¼°APIµÄƵÈÔ¸üлᵼÖ°汾ºÍÎĵµ³öÏÖÎÊÌâµÈ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.f5.com/company/blog/digital-transformation-danger-ahead-api-sprawl



Kaspersky°ä²¼2021ÄêQ3 DDoS¹¥»÷µÄ·ÖÎö»ã±¨


Kaspersky°ä²¼2021ÄêQ3 DDoS¹¥»÷µÄ·ÖÎö»ã±¨.png


KasperskyÔÚ11ÔÂ8ÈÕ°ä²¼ÁË2021ÄêQ3 DDoS¹¥»÷µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÓëÉÏÒ»¼¾¶ÈºÍÈ¥ÄêÏà±È£¬µÚÈý¼¾¶ÈµÄ¹¥»÷ÊýÁ¿ÏÔÖøÔö³¤¡£ÆäÖÐÃÀ¹úÔâµ½µÄDDoS¹¥»÷×î¶à£¨40.80%£©£¬Æä´ÎÊÇÖйúÏã¸Û£¨15.07%£©ºÍÖйú(7.74%)¡£µÚÈý¼¾¶Èµ¥ÈÕµÄDDoS¹¥»÷´ÎÊýÍ»ÆÆÁË֮ǰµÄËùÓмͼ£º8ÔÂ18ÈÕÓÐ8825´Î¹¥»÷£¬8ÔÂ21ÈÕºÍ22Ò²Óг¬¹ý5000´Î¡£´óÎÞÊýDDoS¹¥»÷²ÉÈ¡ÁËSYN·ººéµÄ´ó¾Ö£¬¶ø´óÎÞÊý½©Ê¬ÍøÂçC&C·þÎñÆ÷λÓÚÃÀ¹ú£¨43.44%£©¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/ddos-attacks-in-q3-2021/104796/