¶íÂÞ˹Áª¹ú´¢ÐîÒøÐÐSberbankÔâµ½´ó¹æÄ£DDoS¹¥»÷

°ä²¼¹¦·ò 2022-05-23
1¡¢¶íÂÞ˹Áª¹ú´¢ÐîÒøÐÐSberbankÔâµ½´ó¹æÄ£DDoS¹¥»÷


¾ÝýÌå5ÔÂ20ÈÕ±¨Â·£¬Áª¹ú´¢ÐîÒøÐÐSberbankÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£SberbankÊǶíÂÞ˹×î´óµÄ½ðÈÚ»ú¹¹£¬Ò²ÊÇÅ·ÖÞµÚÈý´ó½ðÈÚ»ú¹¹£¬×Ü×ʲú³¬¹ý5700ÒÚÃÀÔª¡£¹¥»÷²úÉúÔÚ5ÔÂ6ÈÕ£¬Sberbank°µÊ¾ËûÃÇÒѳɹ¦Õмܸߴï450 GB/ÃëµÄ¹¥»÷¡£¾ÝϤ£¬¶ñÒâÁ÷Á¿À´×ÔÒ»¸ö½©Ê¬ÍøÂ磬ÆäÔ̺¬ÁËλÓÚÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾ºÍÖйų́ÍåµÄ27000̨±»Ï°È¾µÄÉ豸£¬ÆäÖкܶ๥»÷ÀûÓÃÁËÔÚÏßÁ÷ýÌåºÍµçÓ°ÔºÍøÕ¾µÄÁ÷Á¿¡£¸ÃÒøÐгÆ£¬×Ô2Ô·Ýì¶ÜÒÔÀ´£¬ÕâÖÖ¹¥»÷´Óδ¼õÈõ¡£


https://www.bleepingcomputer.com/news/security/russian-sberbank-says-it-s-facing-massive-waves-of-ddos-attacks/


2¡¢Ã½Ì幫˾ÈÕ¾­¼¯ÍŵÄÐÂ¼ÓÆÂ·Ö²¿³ÆÆäÔâµ½ÀÕË÷¹¥»÷


¾Ý5ÔÂ21ÈÕ±¨Â·£¬ÈÕ¾­¼¯ÍÅÐÂ¼ÓÆÂ·Ö²¿³ÆÆäһ̨·þÎñÆ÷Ôâµ½ÁËÀÕË÷¹¥»÷¡£ÈÕ¾­£¨Nikkey£©ÊÇÈÕ±¾µÄýÌ幫˾£¬×¨Ò»ÓÚóÒ׺ͽðÈÚÐÐÒµ£¬ËüÊÇÈ«Çò×î´óµÄ²Æ¾­±¨Ö½¡£¸Ã¹«Ë¾ÔÚ5ÔÂ13ÈÕ³õ´Î¼ì²âµ½Æä·þÎñÆ÷Ôâµ½ÁËδ¾­ÊÚȨµÄ½Ó¼û£¬Ö®ºóµ±¼´·¢Õ¹ÁËÄÚ²¿µ÷²é£¬²¢¹Ø¹ØÁËÊÜÓ°ÏìµÄ·þÎñÆ÷¡£¸Ã¹«Ë¾°µÊ¾£¬ÊÜÓ°ÏìµÄ·þÎñÆ÷¿ÉÄÜÔ̺¬¿Í»§Êý¾Ý£¬ËûÃÇ´Ë¿ÌÔÚÈ·¶¨¹¥»÷µÄÐÔÖʺÍÁìÓò£¬½ØÖÁĿǰ£¬²¢Î´·¢ÏÖÊý¾Ýй¶µÄ¼£Ïó¡£


https://securityaffairs.co/wordpress/131533/data-breach/nikkei-data-breach.html


3¡¢Cisco½¨¸´IOS XRÈí¼þÒѱ»ÀûÓõķì϶CVE-2022-20821


5ÔÂ20ÈÕ£¬Cisco°ä²¼°²È«¸üУ¬½¨¸´ÆäIOS XRÈí¼þÖеÄÒ»¸öÒѱ»ÀûÓõķì϶¡£¸Ã·ì϶׷×ÙΪCVE-2022-20821£¬ÊÇÓÉÓÚ½¡È«²é³­RPMÔÚ¼¤»îʱĬÈÏ´ò¿ªTCP¶Ë¿Ú6379µ¼ÖµÄ£¬¹¥»÷ÕßÄܹ»Í¨¹ýÏνӵ½Ê¢ÅüÍ·¿ÚÉϵÄRedisÊ·ýÀ´ÀûÓô˷ì϶¡£CiscoÔÚ²¼¸æÖгÆ£¬³É¹¦ÀûÓø÷ì϶¿ÉʵÏÖRedisÄÚ´æÊý¾Ý¿âдÈ룬½«ËÁÒâÎļþдÈëÈÝÆ÷Îļþϵͳ£¬²¢¼ìË÷ÓйØRedisÊý¾Ý¿âµÄÐÅÏ¢¡£¸Ã¹«Ë¾°µÊ¾ÔÚ±¾ÔµÄÔçЩʱ³½·¢ÏÖÓÐÈËÊÔIJÀûÓÃËü£¬Ç¿ÁÒ½¨Òé¿Í»§½¨¸´´Ë·ì϶¡£


https://thehackernews.com/2022/05/cisco-issues-patches-for-new-ios-xr.html


4¡¢Ö¥¼Ó¸ç¹«Á¢Ñ§ÌõĹ©¸øÉÌÔâµ½¹¥»÷£¬50ÍòѧÉúµÄÐÅϢй¶


ýÌå5ÔÂ21Èճƣ¬Ö¥¼Ó¸ç495448¸öѧÉúºÍ56138¸öÔ±¹¤µÄÊý¾ÝÒѾ­Ð¹Â¶¡£Ð¹Â¶ÊÂÎñÔ´ÓÚÖ¥¼Ó¸ç¹«Á¢Ñ§Ìã¨CPS£©µÄ¹©¸øÉÌBattelle for KidsÔÚ12ÔÂÔâµ½ÁËÀÕË÷¹¥»÷£¬µ¼ÖÂÆäѧÌÃϵͳÖеĴ洢Êý¾Ýй¶¡£¸Ã¹«Ë¾Óë267¸öѧÌÃϵͳºÏ×÷£¬ÏîÄ¿Éæ¼°³¬¹ý280ÍòѧÉú¡£Õâ´Îй¶ÁË2015ÖÁ2019ѧÄêµÄÊý¾Ý£¬Ô̺¬Ñ§ÉúµÄÓ×ÎÒÐÅÏ¢ºÍ·ÖÊý£¬ÒÔ¼°Ô±¹¤µÄÓ×ÎÒÐÅÏ¢µÈ¡£Ö»¹ÜCPSÒªÇó¸Ã¹«Ë¾µ±¼´Í¨ÖªÊý¾Ýй¶Çé¿ö£¬µ«ÆäÔÚ³¬¹ý4¸öÔºó²ÅÅû¶ÁËÎ¥¹æÐÐΪ¡£


https://www.bleepingcomputer.com/news/security/ransomware-attack-exposes-data-of-500-000-chicago-students/


5¡¢AhnLab·¢ÏÖLazarusÕë¶Ôº«¹ú·Ö·¢ºóÃÅNukeSpedµÄ»î¶¯


5ÔÂ19ÈÕ£¬AhnLab°ä²¼»ã±¨Åû¶ÁËLazarusÍÅ»ïÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯¡£Õâ´Î»î¶¯ÖУ¬¹¥»÷ÕßÀûÓÃÁËVMware Horizon·þÎñÆ÷ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶Log4J£¨CVE-2021-44228£©À´×¢ÈëºóÃÅNukeSped¡£AhnLab·¢ÏָúóÃŵÄбäÌåÊÇÓÃC++±àдµÄ£¬²¢Ê¹ÓÃRC4¼ÓÃÜÓëC2µÄͨѶ£¨ÒÔǰʹÓÃXOR£©¡£¸Ã±äÌåÐÂÔöÁËÁ½¸öÄ£¿é£¬Ò»¸öÓÃÓÚת´¢USBÄÚÈÝ£¬ÁíÒ»¸ö½Ó¼ûÍøÂçÉãÏñÍ·É豸¡£´Ë±í£¬NukeSped»¹±»ÓÃÓÚ×°Ööî±íµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬ÍøÂçä¯ÀÀÆ÷ÖеÄÐÅÏ¢¡£


https://asec.ahnlab.com/en/34461/


6¡¢×êÑÐÍŶӷ¢ÏÖRust¹©¸øÁ´¹¥»÷»î¶¯CrateDepression


SentinelOneÔÚ5ÔÂ19ÈÕ°ä²¼»ã±¨³Æ£¬·¢ÏÖÁËÕë¶ÔRust¿ª·¢ÉçÇøµÄ¹©¸øÁ´¹¥»÷»î¶¯£¬²¢³ÆÖ®Îª¡°CrateDepression¡±¡£5ÔÂ10ÈÕ£¬Rust°ä²¼²¼¸æ°µÊ¾ÔÚRust´æ´¢¿âÖз¢ÏÖÁËÒ»¸ö¶ñÒâcrate¡° rustdecimal¡±£¬ËüÊÇ·ÂÕÕÁËÕæÕýµÄ°ü¡°rust_decimal¡±¡£×êÑз¢ÏÖ£¬¶ñÒâÒÀÀµÏî»á²é³­»·¾³±äÁ¿£¬ÕâÅú×¢Ëü¶ÔGitLab³ÖÐø¼¯³É(CI)¹Ü·ÓÐÌØÊâÐËÖ£¬±»Ï°È¾µÄCI¹Ü·ÌṩµÚ¶þ½×¶ÎµÄpayload¡£¶ñÒâcrateÓÚ3ÔÂ25ÈÕ³õ´ÎÍÆËÍ£¬´Ë¿ÌÒÑÔÚ´æ´¢¿âÖÐÓÀԶɾ³ý£¬ÏÂÔØÁ¿²»µ½500´Î¡£


https://www.sentinelone.com/labs/cratedepression-rust-supply-chain-attack-infects-cloud-ci-pipelines-with-go-malware/