ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ21ÖÜ
Ðû²¼Ê±¼ä 2021-05-24> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î£»£»£»£»£»£»£»SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»£»£»Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»£»£»£»£»£»£»DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª£»£»£»£»£»£»£»Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»£»£»£»£»£»£»NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ£»£»£»£»£»£»£»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î
Microsoft Windows JETÊý¾Ý¿âÒýÇæ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-594/
2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î
Pulse Connect Secureä¯ÀÀSMB¹²Ïí±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
3.SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î
SolarWinds Orion Job Scheduler JobRouterService±£´æ²»×¼È·ÊÚȨÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-605/
4.Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î
Cisco DNA Space±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n
5.Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î
Ubiquiti Networks EdgeRouter HTTPSÏÂÔØ¹Ì¼þ±£´æÖ¤ÊéУÑéÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-601/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª

°®¶ûÀ¼µÄÒ½ÁÆÐ§ÀÍ»ú¹¹HSEÌåÏÖ£¬£¬£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¡£¡£¡£¸Ã»ú¹¹ÔÚ·¢Ã÷¹¥»÷ºó£¬£¬£¬ÒÑÓÚÉÏÖÜÎ幨±ÕÁËËùÓÐITϵͳ¡£¡£¡£¡£ContiÍÅ»ïÉù³ÆÒѾ½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬£¬£¬ÔÚ´Ëʱ´ú£¬£¬£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬£¬£¬°üÀ¨»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ÌõÔ¼¡¢²ÆÎñ±¨±íºÍÈËΪµ¥µÈ¡£¡£¡£¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎÅÐû²¼»áÉÏÌåÏÖ£¬£¬£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/
2¡¢DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª

DarkSideÊÇÒ»¸öÀÕË÷Èí¼þЧÀÍÆ÷ÍŻRaaS£©£¬£¬£¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¡£¡£¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕÐû²¼ÉùÃ÷³Æ£¬£¬£¬ÓÉÓÚÖ´·¨Ðж¯£¬£¬£¬ËûÃÇÏÖÔÚÒѾÎÞ·¨Í¨¹ýSSH»á¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶Ð§ÀÍÆ÷ºÍCDNЧÀÍÆ÷£¬£¬£¬ÒÔ¼°Ö÷»ú½çÃæ¡£¡£¡£¡£Òò´Ë½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬£¬£¬²¢ÔÊÐíÔÚ2021Äê5ÔÂ23ÈÕ֮ǰËÍ»¹ËùÓÐδ³¥Õ®Îñ¡£¡£¡£¡£¸ÃÉùÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬£¬£¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime
3¡¢Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ

¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷еİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£¡£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ£¬£¬£¬¾ßÓÐx64Ä£¿£¿£¿é£¬£¬£¬¿ÉÒÔÓÕÆÊܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬£¬£¬»¹Ê¹ÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆÊܺ¦ÕßÏÂÔØÒÆ¶¯Ó¦ÓóÌÐò¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄ½¹µã×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÏÂÁîµÄºóÃÅ£¬£¬£¬Ö»Óе±Æä¼ì²âµ½ÒѾÅþÁ¬µ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬£¬£¬ºóÃŲŻáÆô¶¯¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html
4¡¢NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ

NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬£¬£¬±È2020ÄêͬÆÚÔöÌíÁË31£¥£¬£¬£¬×î´óΪ480 Gbps£¬£¬£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬£¬£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£¡£¡£¡£ÆäÖУ¬£¬£¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬£¬£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬£¬£¬ÔÚÏßЧÀÍÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/asert/beat-goes
5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps

UptycsÍþвÑо¿ÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÄ¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬£¬£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢Ã÷¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬¹¥»÷Õßͨ¹ýWgetÀ´Ê¹ÓÃshell¾ç±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª²î±ðµÄ»ùÓÚLinuxµÄϵͳװÖÃSimps payload¡£¡£¡£¡£Æ¾Ö¤Ò»Ìõ°üÀ¨Gafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÐÂÎÅ£¬£¬£¬Ñо¿Ö°Ô±ÍƶϸöñÒâÈí¼þÓëKeksecÍÅ»ïÓйء£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group


¾©¹«Íø°²±¸11010802024551ºÅ