ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ21ÖÜ
°ä²¼¹¦·ò 2021-05-24> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼°²È«·ì϶51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç¶Âí½Å£»SolarWinds Orion Job Scheduler JobRouterService²»ÕýÈ·ÊÚȨ´úÂëÖ´Ðзì϶£»Cisco DNA Space CVE-2021-1559 OSºÅÁîÖ´Ðзì϶£»Ubiquiti Networks EdgeRouter²»ÕýÈ·Ö¤ÊéУÑéËÁÒâ´úÂëÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEϰȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢°ä·¢½«ÖÕÖ¹ÔËÓª£»×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»Netscout°ä²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨£»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Microsoft Windows JETÊý¾Ý¿âÒýÇæ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-594/
2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç¶Âí½Å
Pulse Connect Secureä¯ÀÀSMB¹²Ïí´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
3.SolarWinds Orion Job Scheduler JobRouterService²»ÕýÈ·ÊÚȨ´úÂëÖ´Ðзì϶
SolarWinds Orion Job Scheduler JobRouterService´æÔÚ²»ÕýÈ·ÊÚȨ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-605/
4.Cisco DNA Space CVE-2021-1559 OSºÅÁîÖ´Ðзì϶
Cisco DNA Space´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ROOT¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n
5.Ubiquiti Networks EdgeRouter²»ÕýÈ·Ö¤ÊéУÑéËÁÒâ´úÂëÖ´Ðзì϶
Ubiquiti Networks EdgeRouter HTTPSÏÂÔØ¹Ì¼þ´æÔÚÖ¤ÊéУÑé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ROOT¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-601/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEϰȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª

°®¶ûÀ¼µÄÒ½ÁÆ·þÎñ»ú¹¹HSE°µÊ¾£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¸Ã»ú¹¹ÔÚ·¢ÏÖ¹¥»÷ºó£¬ÒÑÓÚÉÏÖÜÎ幨¹ØÁËËùÓÐITϵͳ¡£ContiÍÅ»ïÐû³ÆÒѾ½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬ÔÚ´ËÆÚ¼ä£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬Ô̺¬»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ºÏͬ¡¢²ÆÕþ±¨±íºÍ¹¤×ʵ¥µÈ¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎŰ䲼»áÉϰµÊ¾£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/
2¡¢DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢°ä·¢½«ÖÕÖ¹ÔËÓª

DarkSideÊÇÒ»¸öÀÕË÷Èí¼þ·þÎñÆ÷ÍŻRaaS£©£¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕ°ä²¼ÉêÃ÷³Æ£¬ÓÉÓÚ·¨ÂÉÐж¯£¬ËûÃÇĿǰÒѾÎÞ·¨Í¨¹ýSSH½Ó¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶·þÎñÆ÷ºÍCDN·þÎñÆ÷£¬ÒÔ¼°Ö÷»ú½çÃæ¡£Òò¶ø½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬²¢³ÐŵÔÚ2021Äê5ÔÂ23ÈÕ֮ǰ³¥»¹ËùÓÐδ³¥Õ®Îñ¡£¸ÃÉêÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime
3¡¢×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ

¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖеİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£BizarroÊÇWindows¶ñÒâÈí¼þ£¬ÓµÓÐx64Ä£¿é£¬Äܹ»ÓÕÆÊܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬»¹ÀûÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆÊܺ¦ÕßÏÂÔØÒÆ¶¯ÀûÓ÷¨Ê½¡£¸Ã¶ñÒâÈí¼þµÄµÄÖ÷Ìâ×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öºÅÁîµÄºóÃÅ£¬Ö»Óе±Æä¼ì²âµ½ÒѾÏνӵ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬ºóÃŲŻáÆô¶¯¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html
4¡¢Netscout°ä²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨

Netscout°ä²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢ÆðÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬±È2020ÄêͬÆÚÔö³¤ÁË31£¥£¬×î´óΪ480 Gbps£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£ÆäÖУ¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬ÔÚÏß·þÎñÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/asert/beat-goes
5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps

UptycsÍþв×êÑÐÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÖ¸±ê½øÐÐÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢ÏÖ¡£×êÑÐÈËÔ±Ö¸³ö£¬¹¥»÷Õßͨ¹ýWgetÀ´ÀûÓÃshell¾ç±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª·ÖÆçµÄ»ùÓÚLinuxµÄϵͳװÖÃSimps payload¡£Æ¾¾ÝÒ»ÌõÔ̺¬Gafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÐÂÎÅ£¬×êÑÐÈËÔ±´§¶È¸Ã¶ñÒâÈí¼þÓëKeksecÍÅ»ïÓйء£
ÔÎÄÁ´½Ó£º
https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group


¾©¹«Íø°²±¸11010802024551ºÅ