DopplePaymer°µÊ¾Òѳɹ¦ÈëÇÖDMI²¢ÇÔÈ¡NASAµÄÓйØÎļþ£»ÓÐÏß¹«Ë¾VoliaÔâDDoS¹¥»÷Ó°Ï쳬¹ý10ÍòÓû§

°ä²¼¹¦·ò 2020-06-04

1.DopplePaymer°µÊ¾Òѳɹ¦ÈëÇÖDMI²¢ÇÔÈ¡NASAµÄÓйØÎļþ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þÍÅ»ïDopplePaymer°ä·¢ËûÃdzɹ¦Ï°È¾ÁËNASAµÄIT³Ð°üÉÌDigital Management Inc.£¨DMI£©µÄÍøÂ硣ĿǰDMIµÄ½²»°È˲¢Ã»Óлظ´ZDNetµÄÖÃÆÀÒªÇó£¬Òò¶øÉв»Ã÷ÏÔDopplePaymer¶ÔDMIÍøÂçµÄÈëÇÖÓжàÉÒÔ¼°ËûÃÇÈëÇÖÁ˼¸¶à¸ö¿Í»§ÍøÂ硣ΨһÃ÷ÏÔµÄÊÇËûÃÇÒѾ­ÇÔÈ¡ÁËÓëNASAÓйصÄÎļþ£¬Õâ×¢Ã÷ËûÃÇÈëÇÖÁËDMIÓëNASAÓйصĻù´¡¼Ü¹¹¡£ÎªÁËÖ¤Ã÷ÈëÇֵijɹ¦£¬¸Ã×éÖ¯°ä²¼ÁË20¸öÎļþ£¬Ô̺¬HRÎĵµºÍÏîÄ¿´òËãµÄËùÓÐÄÚÈÝ¡£DopplePaymer»¹°ä²¼ÁËDMIÄÚ²¿ÍøÂçÖÐ2583̨·þÎñÆ÷ºÍ¹¤×÷Õ¾µÄÁбí£¬²¢°µÊ¾ÒÑ¶ÔÆä½øÐÐÁ˼ÓÃÜ£¬ÒÔÀÕË÷Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-gang-says-it-breached-one-of-nasas-it-contractors/


2.ÓÐÏßµçÊÓ¹«Ë¾VoliaÔâµ½DDoS¹¥»÷£¬Ó°ÏìÆä³¬¹ý10ÍòÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÐÏßµçÊÓ¹«Ë¾Volia°µÊ¾£¬×Ô5ÔÂ31ÈÕÒÔÀ´£¬Æä¹«Ë¾µÄ·þÎñÆ÷KharkovÒ»ÏòÔâ·êDDoS¹¥»÷¡£µ½6ÔÂ3ÈÕΪֹ£¬¸Ã¹«Ë¾Ôâµ½ÁËÂÅ´ÎÍøÂç¹¥»÷£¬Æð³õ¹¥»÷Ö»ÔÚÆäÓû§×ÓϵͳÉϽøÐУ¬ºóÀ´±ãתÏòÁ˵çÐÅ»ù´¡ÉèÊ©¡£µ¼ÖÂÆä³¬¹ý10ÍòÓû§ÔÚʹÓû¥ÁªÍø¡¢IPTV¡¢¶àÆÁƽ̨ºÍÊý×ÖµçÊÓʱÓöµ½ÁËÎÊÌâ¡£¾ÝVolia¹«Ë¾³Æ£¬ÔÚ5ÔÂ31ÈÕÓÐ12·ÖÖÓ¡¢6ÔÂ1ÈÕÓÐ45·ÖÖӸù«Ë¾µÄ·þÎñÊÇÎÞ·¨Ê¹ÓõÄ£¬²¢ÇÒÆäÍøÕ¾volia.comÒ²Ôâµ½Á˹¥»÷£¬Õâ´ÎDDoS¹¥»÷¹æÄ£Öش󣬹¥»÷ÀàÐÍΪUDPºéË®ºÍÐÅ·ÈÝÁ¿Òç³ö£¬Á÷Á¿³¬¹ý200 GB£¬À´×ÔÊÀ½ç¸÷µØ³ÉǧÉÏÍò¸ö·ÖÆçµÄIPµØÖ·£¬ÈçÃÀ¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ì¨Íå¡¢Ô½ÄϵÈ¡£Í¬Ê±£¬Volia°µÊ¾ËûÃDz»ÄÜÈ·¶¨½«À´¹¥»÷ÊÇ·ñ»áÔٴβúÉú¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/06/provider-volia-reported-to-cyber-police.html


3.Netwalker¹¥»÷¼ÓÀû¸£ÄáÑÇ´óѧ¾É½ðɽ·ÖУ£¬ÇÔȡδ¼ÓÃÜÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿Í×éÖ¯NetwalkerÐû³ÆÆäÒѳɹ¦¹¥»÷Á˼ÓÀû¸£ÄáÑÇ´óѧ¾É½ðɽ·ÖУ£¨UCSF£©£¬ÇÔÈ¡ÁËδ¼ÓÃܵÄÊý¾Ý£¬²¢¶ÔËûÃǵÄÍÆËã»ú½øÐÐÁ˼ÓÃÜ¡£Í¨¹ý¸Ã×éÖ¯°ä²¼µÄ½ØÍ¼À´¿´£¬±»µÁÊý¾ÝÔ̺¬Ñ§ÉúÀûÓ÷¨Ê½£¨´øÓÐÉç»á°²È«ºÅÂ룩£¬º¬ÓÐÔ±¹¤ÐÅÏ¢¡¢Ò½Ñ§×êÑкͲÆÕþÇé¿öµÄµç×Ó±í¸ñºÍÎļþ¼Ð¡£Ä¿Ç°¸ÃѧÌÃÉÐδ»Ø¸´ÓйØÕâ´Î¹¥»÷µÄÐÅÏ¢¡£ÔÚ´ÓǰµÄÒ»ÖÜÖУ¬ºÚ¿Í×éÖ¯NetwalkerÒ»Ö¹Øë¶ÔÃÀ¹ú´óѧ£¬²¢ÍþвҪ°ä²¼ÆäÊý¾ÝÒÔË÷ÒªÊê½ð£¬¸Ã×éÖ¯ÓÚ5ÔÂ28ÈÕ°ä·¢Æä¹¥»÷ÁËÃÜЪ¸ùÖÝÁ¢´óѧ£¬Ö®ºóÓÖÐû³ÆÏ®»÷ÁËÖ¥¼Ó¸ç¸çÂ×±ÈÑÇ´óѧ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/netwalker-ransomware-continues-assault-on-us-colleges-hits-ucsf/


4.˼¿Æ°ä²¼NX-OSÈí¼þµÄ°²È«¸üУ¬½¨¸´DoS·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿Æ°ä²¼NX-OSÈí¼þµÄ°²È«¸üУ¬½¨¸´ÆäÖпÉÄܵ¼ÖÂDoSµÄ·ì϶£¨CVE-2020-10136£©¡£¸Ã·ì϶´æÔÚÓÚCisco NX-OSÈí¼þµÄÍøÂç²Ö¿âÖУ¬ÊÇÓÉÓÚÉ豸ÃýÎ󵨲ð·âºÍ´¦ÖÃÁËÖ÷ÕŵØÊDZ¾µØµØÖ·µÄIP°üÖеÄIP¶ø´æÔڵ쬹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍÒ»¸ö¾«ÐÄÉè¼ÆµÄIP°üÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓúó¿ÉÄܵ¼Ö½«IP°üÖеÄIP·â×°²¢×ª·¢ÄÚ²¿IP°ü£¬´Ó¶øÔì³ÉIPÊý¾Ý°üÈÆ¹ýÉ豸ÉÏÅäÖõÄÊäÈë½Ó¼û½ÚÔìÁбí(acl)»òÍøÂçÖÐÆäËûµÄ°²È«Ììǵ¡£Òò¶ø£¬ÔÚijЩÇé¿öÏ£¬¸Ã·ì϶¿ÉÄܵ¼ÖÂÍøÂç²Ö¿â¹ý³Ì±ÀÀ£²¢ÂŴγÁÆô£¬´Ó¶øµ¼ÖÂÉ豸µÄ³ÁмÓÔØºÍDoS״̬¡£


Ô­ÎÄÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-ipip-dos-kCT9X4


5.½ø½¨Æ½Ì¨8BeltsÒòÅäÖÃÃýÎó£¬Ð¹Â¶È«Çò1Íò¶àÓû§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VpnMentorµÄÍøÂ簲ȫ×êÑÐÓ××é·¢ÏÖ£¬Î÷°àÑÀÔÚÏß½ø½¨Æ½Ì¨8BeltsÓÉÓÚAmazon Web Services£¨AWS£©S3´æ´¢Í°ÅäÖÃÃýÎ󣬵¼ÖÂÊý¾Ýй¶¡£¾Ý¹À¼Æ£¬Õâ´ÎÊÂÎñй¶ÁËÊýÍòÃûµç×Ó½ø½¨Óû§µÄ¸öÈ˾ßÌåÐÅÏ¢£¬Ô̺¬¹ú¶ÈÉí·ÝÖ¤ºÅÂ롢ȫÃû¡¢µç×ÓÓʼþIDºÍÁªÏµÐÅÏ¢£¬¿ÉÄܻᵼÖÂÍøÂçڲƭºÍÉí·Ý͵ÇÔµÈÎÊÌâ¡£ÓÉÓÚÊý¾Ý´æ´¢ÔÚ²»°²È«µÄÔÆÊý¾Ý¿âÖУ¬Òò¶øÈκÎÕ¼ÓÐÆäIPµØÖ·µÄÈ˶¼Äܹ»½Ó¼û¸ÃÊý¾Ý£¬×êÑÐÈËÔ±ÓÚ4ÔÂ16ÈÕ·¢ÏÖ´ËÊý¾Ý¿â£¬²¢ÔÚ4ÔÂ20ÈÕºÍ4ÔÂ22ÈÕ³¢ÊÔÁªÏµ¸Ã¹«Ë¾µ«²¢Î´µÃµ½»Ø¸´£¬4ÔÂ28ÈÕ¸ÃÊý¾Ý¿âÍÑ»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/8belts-exposes-data-of-100000-e-learners/


6.ºÚ¿ÍÀûÓÃGithub»úеÈË¿ÉÔÚ100ÃëÄÚÇÔÈ¡1200ÃÀÔª¼ÓÃÜÇ®±Ò


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ǰ¼¸Ì죬ºÚ¿ÍÀûÓÃGithub»úеÈËÔڶ̶̵Ä100ÃëÄÚÇÔÈ¡ÁËRedditÓû§Ty Cooper¼ÛÖµ1200ÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¾Ý¸ÃÓû§½éÉÜ£¬Ëû½«ÆäMetaMaskÇ®°üÖÐ12¸ö×Ö·ûµÄÃÜÂëÕһضÌÓïÃýÎóµÄ¶³öÔÚÒ»¸ö¹«¹²Github´æ´¢¿âÖУ¬Óë´Ëͬʱ£¬ºÚ¿ÍÔÚʹÓûúеÈËɨÃèGithub£¬ÎÞÒâÖз¢ÏÖÁËÕâ¸öÈÝÒ×¼ÇסµÄ¶ÌÓÒò¶øÓÃÕâ¸ö¶ÌÓï½øÈëÁËËûµÄÇ®°ü²¢Íµ×ßÁ˼ÓÃÜÇ®±Ò¡£ÔÚ´ÓǰһÄêÖвúÉúÁËÎÞÊýµÁÈ¡¼ÓÃÜÇ®±Ò°¸Àý£¬×êÑÐÈËÔ±½¨ÒéÓû§¾¡Á¿±£ÕÏÖú¼Ç·ûºÍ˽ԿµÄËùÓи±±¾Ê¼ÖÕά³ÖÍÑ»ú״̬£¬²¢½«´ó²¿ÃÅ×Ê½ð´æ´¢ÔÚTrezor / LedgerÖ®ÀàµÄÇ®°üÖС£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hackers-use-github-bot-steal-eth-in-seconds/