AvayaϵͳÖÎÀíÔ±ÒòÉæÏÓ·¸·¨ÌìÉú²¢ÏúÊÛVoIPÐí¿ÉÖ¤±»¸æ×´

°ä²¼¹¦·ò 2022-07-01

1¡¢AvayaϵͳÖÎÀíÔ±ÒòÉæÏÓ·¸·¨ÌìÉú²¢ÏúÊÛVoIPÐí¿ÉÖ¤±»¸æ×´


¾Ý6ÔÂ29ÈÕ±¨Â·£¬3ÃûÉæÏÓÏúÊÛ¼ÛÖµ³¬¹ý8800ÍòÃÀÔªµÄAvaya Holdings CorporationÈí¼þÐí¿ÉÖ¤µÄÏÓÒÉÈ˱»¸æ×´£¬Ãæ¶Ô14Ïîµç»ãڲƭºÍÏ´Ç®µÄ×ïÃû¡£Æ¾¾Ý²¼¸æ£¬Avaya¿Í»§·þÎñÔ±¹¤Raymond Bradly PearceÀÄÓÃÆäÖÎÀíԱȨÏÞÌìÉúADIÈí¼þÐí¿ÉÖ¤ÃÜÔ¿£¬¶øºóÏúÊÛ¸øAvayaÊÚȨ¾­ÏúÉÌJason M. Hines£¬¹«Ë¾²É°ìÕâЩÐí¿ÉÖ¤¿ÉÓÃÀ´½âËøAvaya IP Officeµç»°ÏµÍ³µÄÖ°ÄÜ¡£¾Ý³Æ£¬Pearce»¹½Ù³ÖÁËÆäËûAvayaÖÎÀíÔ±µÄÕË»§À´ÌìÉúÐí¿ÉÖ¤£¬ÒÔÔ¤·ÀÓÉÓÚÓëËûµÄÕË»§ÓйØÁªµÄÃÜÔ¿ÌìÉúÁ¿Òì³£¶øÒýÆðÒÉ»ó¡£


https://www.bleepingcomputer.com/news/security/avaya-sysadmin-indicted-for-illegally-generating-selling-voip-licenses/


2¡¢ÎÖ¶ûÂê·ñ¶¨ÆäÔâµ½ºÚ¿ÍÍÅ»ïYanluowangµÄÀÕË÷¹¥»÷


ýÌå6ÔÂ29ÈÕ±¨Â·³Æ£¬ÎÖ¶ûÂê·ñ¶¨ÆäÔâµ½ÁËYanluowangµÄÀÕË÷¹¥»÷¡£±¾ÖÜÒ»£¬ÀÕË÷ÍÅ»ïYanluowangÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼ÁËÒ»¸öÌõ¿î£¬Ðû³ÆËûÃǼÓÃÜÁËÎÖ¶ûÂê40000ÖÁ50000̨É豸¡£¹¥»÷Õßй©£¬¹¥»÷²úÉúÔÚÒ»¸ö¶àÔÂǰ£¬ËûÃǼÓÃÜÁËÖ¸±êµÄÉ豸µ«Ã»ÓÐÇÔÈ¡ÈκÎÊý¾Ý£¬ÀÕË÷5500ÍòÃÀÔªµ«´ÓδÊÕµ½ÎÖ¶ûÂêµÄ»ØÓ¦£¬²¢°ä²¼ÁË´ÓÎÖ¶ûÂêµÄWindowsÓòÖÐÌáÈ¡µÄÐÅÏ¢¡£ÎÖ¶ûÂê·ñ¶¨ÆäÔâµ½¹¥»÷£¬²¢°µÊ¾ÐÅÏ¢°²È«ÍŶÓÔÚ24/7È«Ììºò¼à¿ØËûÃǵÄϵͳ¡£


https://www.bleepingcomputer.com/news/security/walmart-denies-being-hit-by-yanluowang-ransomware-attack/


3¡¢Å²Íþ¶à¼ÒΪÃñ¶àÌṩ³ÁÒª·þÎñµÄ´óÐ͹«Ë¾Ôâµ½DDoS¹¥»÷  


¾ÝýÌå6ÔÂ29ÈÕ±¨Â·£¬Å²Íþ¹ú¶È°²È«¾Ö(NSM)³ÆÓë¶íÂÞ˹ÓÐ¹ØµÄºÚ¿Í¶ÔÆä¹Ø¼ü×éÖ¯½øÐÐÁËÂÅ´ÎDDoS¹¥»÷¡£¸Ã»ú¹¹µÄÖ÷¹ÜSofie Nystr?m°ä²¼ÉêÃ÷£¬ÔÚ´Óǰ24Ó×ʱÄÚ£¬Å²ÍþµÄÊý¸ö×éÖ¯ÒòÔâµ½¹¥»÷ÖжÏ£¬ÖØÒªÊÇһЩΪÃñ¶àÌṩ³ÁÒª·þÎñµÄ´óÐ͹«Ë¾¡£NSM²»Ô¸Ð¹Â©ÄÄЩ×éÖ¯Ôâµ½Á˹¥»÷£¬µ«Â·Í¸É簵ʾŲÍþÀ͹¤¼à²ì¾ÖÊÇÓ°ÏìµÄ×éÖ¯Ö®Ò»£¬ÔÚ±¾ÖÜÈý²úÉúÖжÏ¡£Ä¿Ç°£¬Å²ÍþÕÙ¿ªÁËÒ»´ÎÐÂÎŰ䲼»á£¬½éÉÜÁ˸þÖÊÇÈôºÎÓ¦¶ÔÕâÒ»ÎÊÌâµÄ¡£


https://therecord.media/norway-accuses-pro-russian-hackers-of-launching-wave-of-ddos-attacks/


4¡¢Intezer·¢ÏÖ¿ÉÇÔÈ¡YouTubeÕË»§µÄ¶ñÒâÈí¼þYTStealer


6ÔÂ29ÈÕ£¬IntezerÅû¶ÁËÖ¼ÔÚÇÔÈ¡YouTube´´×÷ÕßµÄÕË»§µÄжñÒâÈí¼þYTStealer¡£ÓëÆäËüÇÔÈ¡·¨Ê½µÄ·ÖÆçÖ®´¦ÔÚÓÚ£¬YTStealerÖ»Õë¶ÔÒ»Ïî·þÎñÇÔȡʹ´¦¡£·Ö·¢YTStealerÑù±¾µÄÎļþ²»Ö»×°ÖÃYTStealer£¬»¹×°ÖÃÁËÆäËüÇÔÈ¡·¨Ê½£¬Ô̺¬ÇÔÈ¡·¨Ê½RedLineºÍVidar¡£¸Ã¶ñÒâÈí¼þÔÚÖ´ÐÐ֮ǰ»¹»á½øÐÐһЩ·´É³ºÐµÄ²é³­£¬Ê¹ÓÃÁËGitHubÉϵĿªÔ´¹¤¾ßChacal¡£µ±È·¶¨Ö¸±êºó£¬Ëü»á×Ðϸ²é³­ä¯ÀÀÆ÷SQLÊý¾Ý¿âÎļþÒÔ¶¨Î»YouTubeÉí·ÝÑéÖ¤ÁîÅÆ¡£


https://www.intezer.com/blog/research/ytstealer-malware-youtube-cookies/


5¡¢Amazon½¨¸´PhotosÀûÓÃÖпÉй¶Óû§½Ó¼ûÁîÅÆµÄ·ì϶


ýÌå6ÔÂ29Èճƣ¬Amazon½¨¸´ÁËÆäPhotosÀûÓÃÖÐÒ»¸öÑϳÁµÄ·ì϶£¬¸ÃÀûÓÃÔÚGoogle PlayµÄÏÂÔØÁ¿Òѳ¬¹ý5000Íò´Î¡£Checkmarx·¢Ïָ÷ì϶ԴÓÚÀûÓ÷¨Ê½×é¼þÅäÖÃÃýÎ󣬵¼ÖÂÆäÇåµ¥ÎļþÎÞÐèÉí·ÝÑéÖ¤¼´¿É´Ó±í²¿½Ó¼û¡£ÀûÓô˷ì϶¿ÉÄÜ»áʹװÖÃÔÚͳһÉ豸ÉϵĶñÒâÀûÓûñÈ¡ÓÃÓÚAmazon APIÉí·ÝÑéÖ¤µÄAmazon½Ó¼ûÁîÅÆ¡£×êÑÐÈËÔ±³Æ£¬ÀÕË÷Èí¼þºÜÈÝÒ׳ÉΪDZÔڵĹ¥»÷ý½é£¬¹¥»÷ÕßÖ»±ØÒª¶ÁÈ¡¡¢¼ÓÃܺͳÁдָ±êµÄÎļþ£¬Í¬Ê±²Á³ýËûÃǵĺ¹Çà¼Í¼¡£´Ë±í£¬ÆäËüAmazon APIsÒ²¿ÉÄÜʹÓÃÒ»ÑùµÄÁîÅÆ£¬ÈçPrime Video¡¢AlexaºÍKindleµÈ£¬Òò¶ø£¬·çÏÕ¿ÉÄÜÊÇÉîÔ¶µÄ¡£


https://www.bleepingcomputer.com/news/security/amazon-fixes-high-severity-vulnerability-in-android-photos-app/


6¡¢º«¹úKISA°ä²¼ºÏÓÃÓÚv1µ½v4°æ±¾µÄHive½âÃܹ¤¾ß


6ÔÂ30ÈÕ±¨Â·£¬º«¹úÍøÂ簲ȫ»ú¹¹KISA°ä²¼ÁËÀÕË÷Èí¼þHiveµÄÃâ·Ñ½âÃÜÆ÷£¬ºÏÓÃÓÚv1µ½v4°æ±¾¡£Hive×Ô2021Äê6ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬Æ¾¾ÝChainalysisµÄÊý¾Ý£¬ËüÊÇ2021ÄêÊÕÈëTop 10µÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»¡£½ñÄê2Ô£¬Kookmin´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÁËHiveʹÓõļÓÃÜËã·¨ÖдæÔÚÒ»¸ö·ì϶£¬¿ÉÓÃÀ´ÔÚ²»ÖªÂ·¼ÓÃÜÎļþµÄ˽ԿµÄÇé¿öϽâÃÜÊý¾Ý¡£


https://securityaffairs.co/wordpress/132770/malware/hive-ransomware-decryptor.html