Ó¢¹úHarrisͬÃËѬȾÀÕË÷Èí¼þ£¬£¬ £¬£¬£¬£¬50¶àËùѧУÊÜÓ°Ï죻£»£»£»£»£»£»£»LinuxÖеÄ2¸öÎó²î¿ÉÈÆ¹ýSpectre¹¥»÷µÄ»º½â²½·¥

Ðû²¼Ê±¼ä 2021-03-31

1.Ó¢¹úHarrisͬÃËѬȾÀÕË÷Èí¼þ£¬£¬ £¬£¬£¬£¬50¶àËùѧУÊÜÓ°Ïì


1.jpg


3ÔÂ27ÈÕ£¨ÐÇÆÚÁù£©£¬£¬ £¬£¬£¬£¬Î»ÓÚÂ׶صĽÌÓý´ÈÉÆ»ú¹¹¹þÀï˹ÁªºÏ»á£¨Harris Federation£©µÄITϵͳºÍµç×ÓÓʼþЧÀÍÆ÷Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬Ó°ÏìÁË50ÆäÖÐСѧµÄ37000ÃûѧÉú¡£¡£¡£¡£¡£ ¡£¡£¡£ÔÚ¼ì²âµ½¹¥»÷Ö®ºó£¬£¬ £¬£¬£¬£¬¸Ã×éÖ¯Á¬Ã¦¹Ø±ÕÁ˵ç×ÓÓʼþºÍÀο¿µç»°ÏµÍ³²¢½«ËùÓÐÀ´µçÖØ¶¨Ïòµ½ÊÖ»ú£¬£¬ £¬£¬£¬£¬Í¬Ê±»¹½ûÓÃÁËѧÉúµÄ×°±¸ÒÔ±ÜÃâÀÕË÷Èí¼þÈö²¥¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã×éÖ¯ÌåÏÖÕâÊÇÒ»´Î¸ß¶ÈÖØ´óµÄ¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬ÆäÏÖÔÚÕýÔÚÓëÕþ¸®×éÖ¯ÏàÖú¶Ô´ËÊÂÕö¿ªÊӲ졣¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/harris-federation-hit-by-ransomware-attack-affecting-50-schools/


2.ÐÂ¼ÓÆÂVhiveѬȾALTDOS£¬£¬ £¬£¬£¬£¬30¶àÍò¸ö¿Í»§µÄ¼Í¼й¶


2.jpg


ÐÂ¼ÓÆÂ¼Ò¾ßÁ¬ËøµêVhiveÔÚ3ÔÂ23ÈÕÐû²¼ÆäÔâµ½ALTDOSÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬30¶àÍò¸ö¿Í»§µÄ¼Í¼ÒÑй¶¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾³ÆÆä¹ÙÍøvhive.com.sgÔÚ3ÔÂ21ÈÕÔâµ½Ê״ι¥»÷£¬£¬ £¬£¬£¬£¬ÆäÍøÂçЧÀÍÆ÷ÔÚ3ÔÂ22ÈÕ±»¹¥ÆÆ¡£¡£¡£¡£¡£ ¡£¡£¡£VhiveÔÚ3ÔÂ23ÈÕʹÓñ¸·Ý»Ö¸´ÆäÍøÕ¾ºÍÎļþ£¬£¬ £¬£¬£¬£¬µ«Î´Äܽâ¾öÖ÷ÒªÎó²î¡£¡£¡£¡£¡£ ¡£¡£¡£ÕâʹµÃ¹¥»÷ÔÚ3ÔÂ25ÈÕ¼ÌÐø£¬£¬ £¬£¬£¬£¬ALTDOSÇÔÈ¡ÁËÆäÔ´´úÂëºÍÎļþ£¬£¬ £¬£¬£¬£¬²¢¼ÓÃÜÁËЧÀÍÆ÷ÉϵÄËùÓÐÎļþ¡£¡£¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬£¬Vhive¾Ü¾øÁËÊê½ðÒªÇ󡣡£¡£¡£¡£ ¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/sg-vhive-alerts-consumers-to-cyberattack/    


3.Õë¶ÔÓ¡¶ÈµÄAPT×éÖ¯RedEchoÒÑ¹Ø±ÕÆäʹÓõĻù´¡ÉèÊ©


3.jpg


APT×éÖ¯RedEchoÔÚ2ÔÂβ±»Ñо¿Ö°Ô±Åû¶ºó£¬£¬ £¬£¬£¬£¬ÒÑ¹Ø±ÕÆäʹÓõĻù´¡ÉèÊ©¡£¡£¡£¡£¡£ ¡£¡£¡£Recorded FutureµÄÇå¾²Ö°Ô±ÓÚ2Ô·¢Ã÷Á˸ÃAPT×éÖ¯£¬£¬ £¬£¬£¬£¬³Æ¸ÃÍÅ»ï×Ô2020ÄêÍ·¹¥»÷ÁËÓ¡¶ÈµÄÖÁÉÙ10¸öµçÁ¦²¿·Ö£¬£¬ £¬£¬£¬£¬»¹½«Ä¿µÄÃé×¼Á˸ßѹÊäµç±äµçÕ¾ºÍȼú»ðÁ¦·¢µç³§¡£¡£¡£¡£¡£ ¡£¡£¡£Ôڸ÷¢Ã÷Ðû²¼¼¸Öܺ󣬣¬ £¬£¬£¬£¬RedEchoÒѾ­¹Ø±ÕÁ˲¿·ÖÓÃÓÚ¿ØÖÆ×°ÖÃÔÚÄ¿µÄÍøÂçÖеÄShadowPadºóÃŵĻù´¡ÉèÊ©¡£¡£¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÍƲ⣬£¬ £¬£¬£¬£¬¸ÃAPT×éÖ¯ÔÚ±»·¢Ã÷ºó¿ÉÄܽ«ÆäC2×ªÒÆµ½ÁËÆäËûµØ·½¡£¡£¡£¡£¡£ ¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116094/apt/redecho-apt-c2-shutdown.html


4.ClopÍÅ»ï¹ûÕæÃÀ¹úMarylandºÍCalifornia´óѧµÄÐÅÏ¢


4.jpg


3ÔÂ29ÈÕ£¬£¬ £¬£¬£¬£¬ClopÍÅ»ï×îÏÈÐû²¼´ÓÃÀ¹ú½ÌÓý»ú¹¹ÇÔÈ¡µÄÊý¾ÝµÄ½ØÍ¼£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨ÃÀ¹úÂíÀïÀ¼´óѧ£¨University of Maryland£©ºÍ¼ÓÀû¸£ÄáÑÇ´óѧ£¨University of California£©µÄ²ÆÎñÎļþºÍСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤½ØÍ¼£¬£¬ £¬£¬£¬£¬´Ë´Îй¶µÄÊý¾Ý°üÀ¨Áª°î˰ÊÕÎļþ¡¢Ñ§·Ñ¼õÃâÇëÇó¡¢Õչ˻¤Ê¿Î¯Ô±»áÉêÇëºÍ˰ÊÕÕªÒªÎļþµÈ²ÆÎñÐÅÏ¢£¬£¬ £¬£¬£¬£¬ÒÔ¼°ÕÕÆ¬¡¢ÐÕÃû¡¢¼Òͥסַ¡¢Éç»áÇå¾²ºÅÂë¡¢ÒÆÃñÉí·Ý¡¢³öÉúÈÕÆÚºÍ»¤ÕÕµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¡£     


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-group-targets-universities-of-maryland-california-in-new-data-leaks/


5.Ovarro TBox RTUÖб£´æ°üÀ¨RCEÔÚÄڵĶà¸öÎó²î


5.jpg


Çå¾²¹«Ë¾ClarotyµÄÇå¾²Ñо¿Ô±Uri Katz·¢Ã÷OvarroµÄTBoxÔ¶³ÌÖն˵¥Î»£¨RTU£©±£´æ5¸öÎó²î¡£¡£¡£¡£¡£ ¡£¡£¡£TBoxÊÇÓÃÓÚ¿ØÖÆ¼à¿ØºÍÊý¾ÝÊÕÂÞ£¨SCADA£©Ó¦ÓõÄ×Ô¶¯»¯½â¾ö¼Æ»®£¬£¬ £¬£¬£¬£¬Éæ¼°µçÁ¦¡¢Ê¯ÓͺÍ×ÔÈ»Æø¡¢ÔËÊäºÍ¼Ó¹¤µÈÐÐÒµ¡£¡£¡£¡£¡£ ¡£¡£¡£ÕâЩÎó²î»®·ÖΪ´úÂëÖ´ÐÐÎó²îCVE-2021-22646¡¢¿Éµ¼ÖÂTBoxÍß½âµÄCVE-2021-22642¡¢¿É½âÃܵǼÃÜÂëµÄCVE-2021-22640¡¢¿É¸ü¸Ä»òɾ³ýÉèÖÃÎļþµÄCVE-2021-22648ºÍ¿ÉÇÔȡӲ±àÂëµÄ¼ÓÃÜÃÜÔ¿µÄCVE-2021-22644¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/flaws-in-ovarro-tbox-rtus-could-open.html


6.LinuxÖеÄ2¸öÎó²î¿ÉÈÆ¹ýSpectre¹¥»÷µÄ»º½â²½·¥


6.jpg


SymantecµÄÑо¿Ö°Ô±·¢Ã÷ÁËLinuxÖеÄ2¸öÐÂÎó²î£¬£¬ £¬£¬£¬£¬¿É±»ÓÃÀ´ÈƹýSpectre¹¥»÷µÄ»º½â²½·¥¡£¡£¡£¡£¡£ ¡£¡£¡£SpectreÊÇ2018Äê1Ô·¢Ã÷µÄоƬÎó²î£¬£¬ £¬£¬£¬£¬ÏÕЩӰÏìÁËËùÓд¦Öóͷ£Æ÷£¬£¬ £¬£¬£¬£¬Ö»ÄÜͨ¹ý²Ù×÷ϵͳ²¹¶¡À´¾ÙÐлº½â¡£¡£¡£¡£¡£ ¡£¡£¡£ÕâÁ½¸öÐÂÎó²î¶¼ÓëLinuxÄں˶ÔÀ©Õ¹µÄBerkeleyÊý¾Ý°ü¹ýÂËÆ÷£¨BPF£©µÄÖ§³ÖÓйØ£¬£¬ £¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÎó²î£¨CVE-2020-27170£©¿ÉÒÔÓÃÀ´¶ÁÈ¡ÄÚºËÄÚ´æÖÐÈκÎλÖõÄÄÚÈÝ£¬£¬ £¬£¬£¬£¬µÚ¶þ¸öÎó²î£¨CVE-2020-27171£©¿É¶ÁÈ¡4 GB¹æÄ£µÄÄÚºËÄÚ´æÖеÄÄÚÈÝ¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spectre-bypass-linux-vulnerabilities