ÑÇÂíÑ·AWSÔøÂ½Ðø3ÌìÔâµ½2.3 Tbps DDoS¹¥»÷£»Î÷ÃÅ×ÓµÄPLC´æÔÚÑϳÁ·ì϶£¬¿Éµ¼ÖÂDoS¹¥»÷
°ä²¼¹¦·ò 2020-06-161.ÑÇÂíÑ·AWSÔøÂ½Ðø3ÌìÔâµ½2.3 Tbps DDoS¹¥»÷
2020Äê2Ô£¬ÑÇÂíÑ·µÄÔÆ·þÎñAWSÂ½Ðø3ÌìÔâµ½Á˸ߴï2.3 TbpsµÄDDoS¹¥»÷¡£ÔÚÕâ´Î¹¥»÷ÖУ¬ºÚ¿ÍʹÓÃÁË»ùÓÚCLDAP·´ÉäµÄ¹¥»÷£¬Æ¾¾ÝµÚÒ»¼¾¶ÈAWS ShieldÍþÐ²Ì¬ÊÆ»ã±¨ £¬Õâ´Î¹¥»÷µÄ¹æÄ£±ÈAWS¾Àú¹ýµÄ×î´ó¹æÄ£¹¥»÷»¹Òª´ó44£¥¡£AWS»ã±¨°µÊ¾£¬Õâ´Î¹¥»÷Öкڿ͵͝»úÉв»Ã÷ÏÔ£¬»¹Ö¸³öÿ´ÎÔÚºÚ¿Í·¢ÏÖÐµĹ¥»÷ý½éºó£¬¹¥»÷ÊýÁ¿±ã»á¼¤Ôö£¬ÀýÈçÓÐÔ½À´Ô½¶àµÄDocker¡¢Hadoop¡¢RedisºÍSSH¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://androidrookies.com/amazons-aws-hit-with-a-record-breaking-2-3-tbps-ddos-attack/
2.Î÷ÃÅ×ÓµÄPLC´æÔÚÑϳÁ·ì϶£¬¿Éµ¼ÖÂDoS¹¥»÷
Î÷ÃÅ×ÓµÄLOGO!¿É±à³ÌÂß¼½ÚÔìÆ÷(PLCs)´æÔÚÑϳÁ·ì϶£¬¿É±»ÀûÓÃÅú¸ÄÉ豸ÅäÖûòÌáÒéDoS¹¥»÷¡£Î÷ÃÅ×Ó°µÊ¾£¬¸Ã·ì϶ӰÏìÁËÆäËùÓа汾µÄLOGO£¡8 BMÉ豸£¬ÒÔ¼°ÓÃÓÚ¼«¶ËǰÌáµÄSIPLUS°æ±¾¡£¸Ã·ì϶ÊÇÓÉÓÚ¶ÌȱÑéÖ¤¶ø´æÔڵģ¬Î´¾Éí·ÝÑéÖ¤µÄºÚ¿ÍÄܹ»½Ó¼ûTCPµÄ135¶Ë¿Ú£¬²¢¶ÁÈ¡ºÍÅú¸ÄÉ豸µÄÅäÖá£Ä¿Ç°ÉÐδ°ä²¼²¹¶¡·¨Ê½£¬µ«ÊÇÎ÷ÃÅ×Ó¹«Ë¾°µÊ¾Äܹ»Í¨¹ý×ÝÉî·ÀÓùÀ´½µµÍ¸Ã·ì϶±»ÀûÓõķçÏÕ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/critical-vulnerabilities-expose-siemens-logo-controllers-attacks
3.Claire'sÔâµ½MageCart¹¥»÷£¬Óû§Ö§¸¶ÐÅÏ¢±»µÁ
ÃÀ¹úÖ鱦ºÍÅäÊι«Ë¾Claire's¼°Æä×Ó¹«Ë¾IcingµÄÍøÕ¾ÔÚ4ÔÂÔâµ½¹¥»÷£¬Æä¿Í»§µÄÐÅÓþ¿¨ÐÅÏ¢±»µÁ¡£ÔÚ¹¥»÷Öкڿͽ«¶ñÒâJavaScript¾ç±¾×¢Èë¸Ã¹«Ë¾µÄÍøÕ¾£¬¶øºóÀûÓÃÕâЩ¾ç±¾ÇÔÈ¡¿Í»§Ìá½»µÄ¸¶¿îÐÅÏ¢¡£ÔÚClaireÓÉÓÚÒßÇ鹨¹ØÆäʵÌåµêµÄµÚ¶þÌ죬ºÚ¿Í±ã×¢²áÁËclaires-assets.comÓòÃû£¬Ö®ºó¸ÃÓòÒ»Ïò´¦ÓÚÐÝÃß״̬£¬Ö±µ½4ÔÂ25Èպڿͽ«¶ñÒâ¾ç±¾×¢Èë¸Ã¹«Ë¾ÍøÕ¾ºó£¬¸ÃÓòÆðÍ·ÓÃÀ´½Ó¹ÜÇÔÈ¡µ½µÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/accessories-giant-claires-hacked-to-steal-credit-card-info/
4.¶íÂÞ˹ºÚ¿Ím1xй¶1.4ÍòÄ«Î÷¸ç¹«ÃñµÄIDÐÅÏ¢
Lucy Security×êÑÐÈËÔ±×î½ü·¢ÏÖ£¬ÃûΪm1xµÄ¶íÂÞ˹ºÚ¿ÍÈëÇÖÁËÄ«Î÷¸çµ±¾ÖµÄÒ»¸öÃÅ»§ÍøÕ¾£¬²¢ÇÒÓÉÓÚÓ¦¸Ã¾Ö¾Ü¸¶Êê½ð£¬ºÚ¿ÍÓÚÈýÌìºóй¶ÁËÔ¼1.4ÍòÃûÄ«Î÷¸ç¹«ÃñµÄÉí·ÝÖ¤ºÅÂë¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬¹«ÃñµÄµÄÉí·ÝÖ¤ºÅÂë¡¢¼ÒͥסַºÍµç»°ºÅÂ룬»¹ÓÐһЩ¾¯·½¼Í¼¡£Ä¿Ç°Äܹ»È·¶¨ºÚ¿Ím1xÊÇÀ´×Ô¶íÂÞ˹µÄ£¬µ«Éв»ÖªÂ·Õâ´Î¹¥»÷ÊÇ·ñºÍ¸Ã¹úµ±¾ÖÓйء£
ÔÎÄÁ´½Ó£º
https://www.scmagazine.com/home/security-news/apts-cyberespionage/russian-hacker-releases-at-least-14000-mexican-taxpayer-ids/?web_view=true
5.¶ñÒâÈí¼þTroyStealerÕë¶ÔÆÏÌÑÑÀÓû§²¢ÇÔÊØÐÅÏ¢
Abuse.ch·¢ÏÖеÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þTroyStealer£¬ÖØÒªÕë¶ÔÆÏÌÑÑÀÓû§¡£¸Ã¶ñÒâÈí¼þÓÃÓÚÍøÂçµÇ¼ƾ֤£¬ÀýÈç´æ´¢ÔÚÍøÂçä¯ÀÀÆ÷ÖеÄÓû§ÃûºÍÃÜÂ룬¶øºóͨ¹ýµç×ÓÓʼþ½«Æä·¢Ëͻغڿ͡£¸Ã¶ñÒâÈí¼þ»á¼ì²âËüµÄÔËÐл·¾³£¬ÈôÊÇÊÇÔÚVMÖÐÔËÐÐÔò»áµ±¼´ÖÕ³¡ÔËÐС£²¢ÇÒTroyStealer»áͨ¹ýÍø¿ì²âÊÔÍøÕ¾ÑéÖ¤µ±Ç°ÊÇ·ñ´æÔÚÓÐЧµÄInternetÏνӣ¬ÈôÊÇÓУ¬Ëü½«Óë¾¹ýÉí·ÝÑéÖ¤µÄµç×ÓÓʼþ·þÎñÆ÷³ÉÁ¢SMTPͨѶ£¬²¢Í¨¹ýµç×ÓÓʼþ·¢ËÍÊܺ¦ÕߵľßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://seguranca-informatica.pt/troystealer-a-new-info-stealer-targeting-portuguese-internet-users/#.Xucw2KgzZPY
6.NBWNaWas·¢ÏÖDDoS¹¥»÷¸´ÔÓÐԺ͹æÄ£¾ù´ó·ùÔö³¤
NBWNaWas°ä²¼»ã±¨£¬Ïà±È2018Ä꣬2019ÄêDDoS¹¥»÷µÄÊýÁ¿ÓÐËù½µÂ䣬µ«ÊÇÆä¹¥»÷µÄ¸´ÔÓÐԺ͹æÄ£¾ù´ó·ùÔö³¤¡£NBIP¶ÊÂ×ܾÀíOctavia de Weerdt°µÊ¾£¬2019ÄêDDoS¹¥»÷ÂÔÉÙ£¨2019Äê919´ÎºÍ2018Äê938´Î£©£¬µ«²Î¼ÓÕßÈËÊýÈ´Ôö³¤ÁË10£¥¡£ÔÚ2018Ä꣬×î´ó¹¥»÷ÊÇ68 Gbps£¬×ÔӵĹ¥»÷ʹÓÃÁË12ÖÖý½é£¬¶øÔÚ2019Äê¹Û²ìµ½µÄ×î´ó¹¥»÷ÊÇ124 Gbps£¬×ÔÓµÄÒ»´Î¹¥»÷ÖкڿÍ×ܹ²Ê¹ÓÃÁË30ÖÖý½é¡£NBWNaWas°µÊ¾£¬DDoS¹¥»÷µÄ¸´ÔÓÐԺ͹æÄ£ÓëÈÕ¾ãÔö³ÉΪһ¸öÇ÷Ïò£¬ÀýÈ磬ÔÚ2020ÄêµÚÒ»¼¾¶È¾ÍÓÐ140 GbpsµÄDDoS¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/06/15/2019-ddos-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ