Cloudflare°ä·¢ÆäÕмÜÁ˸ߴï2 TbpsµÄDDoS¹¥»÷
°ä²¼¹¦·ò 2021-11-17ÍøÐŰì°ä²¼¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·

¹ú¶ÈÍøÐŰìÓÚ11ÔÂ14ÈÕ°ä²¼ÁË¡¶ÍøÂçÊý¾Ý°²È«ÖÎÀíÌõÀý£¨Õ÷Ç󶨼û¸å£©¡·µÄ¹«¿ªÕ÷Ç󶨼û֪ͨ¡£½ØÖÁ½ñÄê6Ô£¬ÎÒ¹úÍøÃñ¹æÄ£´ï10.11ÒÚ£¬Óɴ˲úÉúµÄÍøÂçÊý¾ÝÁ¿¸üÊÇÌìÎÄÊý×Ö¡£¸ÃÌõÀý¹æ·¶ÍøÂçÊý¾Ý´¦Öû£¬±£»¤Ó×ÎÒ¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄºÏ·¨È¨Àû£¬ÊØ»¤¹ú¶È°²È«ºÍ¹«¹²ÀûÒæ¡£Öйú»¥ÁªÍøÐ»á·¨¹¤Î¯¸±ÃØÊ鳤ºú¸ÖÖ¸³ö£¬ÕâÊÇÐÂʱÆÚ¹æ·¶»¥ÁªÍøÆ½Ì¨ÆóÒµ£¬Ç¿»¯·´Â¢¶ÏºÍ±¾Ç®ÎÞÐòÀ©ÕŵÄÓ¦ÓÐÖ®Ò壬ҲÊÇÊØ»¤¹ú¶È°²È«¡¢±£»¤Éç»á¹«¹²ÀûÒæµÄ±ØÒª¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2021-11/14/c_1638501991577898.htm
VMware½¨¸´TanzuÖеÄDoS·ì϶CVE-2021-22101

VMwareÔÚ11ÔÂ11ÈÕ°ä²¼²¹¶¡£¬½¨¸´ÁËTanzu Application ServiceÖеķì϶CVE-2021-22101¡£¸Ã·ì϶´æÔÚÓÚCloud FoundryµÄÔÆ½ÚÔìÆ÷(CAPI)£¬CVSSv3ÆÀ·ÖΪ7.5¡£Ô¶³Ì¹¥»÷ÕßÀûÓô˷ì϶ʱ£¬Äܹ»Í¨¹ýʹÓÃREST HTTPÒªÇóÌìÉú´óÁ¿µÄSQL²éÎʵ¼ÖÂÊý¾Ý¿â(ccdb)²»³ÉÓã¬À´´¥·¢»Ø¾ø·þÎñ״̬¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/11/12/vmware-releases-security-update-tanzu-application-service-vms
CISAÅû¶¶à¸öDDS¹©¸øÉ̵ÄÉ豸ÖÐ13¸ö·ì϶µÄϸ½Ú

CISAÔÚ11ÔÂ11ÈÕ°ä²¼ÁËÒ»ÌõICSÕ÷ѯ£¬Åû¶ÁË6¸öÎÞÊý¾Ý·Ö·¢·þÎñ(DDS)¹©¸øÉ̵ÄÉ豸ÖдæÔÚµÄ13¸ö·ì϶µÄϸ½Ú¡£ÕâЩ·ìÏ¶Éæ¼°µ½Eclipse¡¢eProsimaºÍGurumNetworksµÈ¹«Ë¾£¬Éæ¼°µ½µÄÉ豸Ô̺¬CycloneDDS¡¢FastDDS¡¢GurumDDSºÍOpenDDSµÈ¡£ÆäÖнÏΪÑϳÁµÄ·ì϶ΪGurumDDSÖлùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2021-38439£©£¬OCI OpenDDSÖеÄDoS·ì϶£¨CVE-2021-38447£©ºÍ¿ÉÄܵ¼Ö»ؾø·þÎñǰÌáºÍÐÅϢй¶µÄ·ì϶£¨CVE-2021-38429£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ics/advisories/icsa-21-315-02
Cloudflare°ä·¢ÆäÕмÜÁ˸ߴï2 TbpsµÄDDoS¹¥»÷

ÃÀ¹úÍøÂ簲ȫ¹«Ë¾CloudflareÔÚ11ÔÂ15ÈÕ°ä·¢ÆäÕмÜÁËÆù½ñΪֹÓöµ½µÄ×î´ó¹¥»÷DDoS¹¥»÷£¬·åÖµÂÔµÍÓÚ2 Tbps¡£Õâ´Î¹¥»÷»î¶¯ÊǽáºÏÁËDNS·Å´ó¹¥»÷ºÍUDP·ººéµÄ¶àÏòÁ¿¹¥»÷£¬Õû¸ö¹ý³ÌÖ»³ÖÐøÁËÒ»·ÖÖÓ£¬À´×ÔÔ¼15000¸ö»úеÈË×é³ÉµÄ½©Ê¬ÍøÂçMirai±äÖÖ¡£Cloudflare»ã±¨³ÆµÚÈý¼¾¶ÈÍøÂç²ãDDoS¹¥»÷»î¶¯±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË44%£¬¸Ã¹«Ë¾ÔÚ8ÔÂÕмÜÁËÿÃë1720Íò´ÎÒªÇóµÄDDoS¹¥»÷£¬Î¢ÈíÔÚ10ÔÂ³ÆÆäÔÆ·þÎñAzureÕмÜÁË2.4 TbpsµÄDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html
Ivanti°ä²¼2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨

IvantiÓÚ11ÔÂ9ÈÕ°ä²¼ÁË2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬µÚÈý¼¾¶Å×ëÀÕË÷Èí¼þÓйصķì϶½ÏÖ®ÉÏÒ»¼¾¶ÈÔö³¤ÁË4.5%£¬×ÜÊý´ïµ½278¸ö£»ÀÕË÷Èí¼þ¼Ò×åÔö³¤ÁË3.4%£¬×ÜÊý´ïµ½151¸ö¡£»ã±¨»¹·¢ÏÖÀÕË÷ÔËÓªÍÅ»ïÈÔÔÚ»ý¼«ÀûÓÃÁãÈÕ·ì϶£»¹¥»÷ÖÐʹÓõļ¼ÊõÒ²±äµÃÔ½À´Ô½¸´ÔÓ£¬ÀýÈçdropper as-a-service£»ÓÐ3¸ö¿É×·Òäµ½2020Äê»ò¸üÔçµÄ·ì϶ÓëÕâÒ»¼¾¶ÈµÄÐÂÀÕË÷Èí¼þÓйء£
ÔÎÄÁ´½Ó£º
https://www.ivanti.com/lp/security/reports/2021-q3-ransomware-index-spotlight-report
Check Point°ä²¼2021Äê10ÔÂÈ«ÇòÍþвָÊý»ã±¨

Check PointÔÚ½üÆÚ°ä²¼ÁË2021Äê10ÔÂÈ«ÇòÍþвָÊý»ã±¨¡£»ã±¨Ö¸³ö£¬TrickbotÈÔλ¾Ó¶ñÒâÈí¼þ°ñµ¥Ö®Ê×£¬Ó°ÏìÁËÈ«Çò4%µÄ×éÖ¯£¬Æä´ÎÊÇXMRig£¨3%£©ºÍRemcos£¨2%£©£»½ÌÓýºÍ×êÑÐÐÐÒµÊÇÈ«ÇòÊܹ¥»÷×î¶àµÄÐÐÒµ£¬Æä´ÎÊÇͨѶÐÐÒµ£¬ÒÔ¼°µ±¾ÖºÍ¾üÊÂ×éÖ¯£»×î³£¼ûµÄ·ì϶ÊÇWeb·þÎñÆ÷URLĿ¼±éÀú·ì϶£¬Ô̺¬CVE-2010-4598ºÍCVE-2011-2474µÈ£»xHelper ÒÀÈ»ÊÇ×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þ£¬Æä´ÎÊÇAlienBotºÍXLoader¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/11/11/october-2021s-most-wanted-malware-trickbot-takes-top-spot-for-fifth-time/


¾©¹«Íø°²±¸11010802024551ºÅ