Cisco³ÆÆä²¿ÃŲúÆ·ÒòSnortÖеķì϶Ò×ÊÜDoS¹¥»÷£»Spirit AirlinesϰȾNefilim£¬Ð¹Â¶³¬¹ý40GBÊý¾Ý
°ä²¼¹¦·ò 2021-03-081.Cisco³ÆÆä²¿ÃŲúÆ·ÒòSnortÖеķì϶Ò×ÊÜDoS¹¥»÷

Cisco³ÆÆä²¿ÃŲúÆ·ÒòSnort¼ì²âÒýÇæÖеķì϶Ò×ÊÜDoS¹¥»÷¡£¸Ã·ì϶λÓÚSnort¼ì²âÒýÇæµÄÒÔÌ«ÍøÖ¡½âÂëÆ÷ÖУ¬±»×·×ÙΪCVE-2021-1285£¬CVSSÆÀ·ÖΪ7.4¡£¸Ã·ì϶ÊǶÔÒÔÌ«ÍøÖ¡µÄÃýÎóÇé¿ö´¦Öò»ÕýÈ·ËùÖ£¬Î´¾ÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÏòÖ¸±êÉ豸·¢ËͶñÒâÒÔÌ«ÍøÖ¡À´ÀûÓô˷ì϶¡£³É¹¦ÀûÓø÷ì϶Äܹ»ºÄ¾¡Ö¸±êÉ豸ÉϵĴÅÅ̿ռ䣬µ¼ÖÂÖÎÀíÔ±ÎÞ·¨µÇ¼µ½¸ÃÉ豸»ò¸ÃÉ豸ÎÞ·¨ÕýÈ·Æô¶¯¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115341/security/cisco-products-dos-snort-issue.html
2.Spirit AirlinesϰȾNefilim£¬Ð¹Â¶³¬¹ý40GBÊý¾Ý

Spirit AirlinesϰȾNefilim£¬Ð¹Â¶³¬¹ý40GBÊý¾ÝºÍ³¬¹ý33000¸öÎļþ¡£ÔçÔÚ2017Ä꣬Spirit Airlines³õ´Î²úÉúÊý¾Ýй¶£¬ºÚ¿Í´Ó¸Ãº½¿Õ¹«Ë¾µÄITϵͳÇÔÈ¡Á˳¬¹ý1170Íò¸öÕÊ»§ÐÅÏ¢¡£Ê±¸ôËÄÄê¸Ã¹«Ë¾ÔٴβúÉúÁ˸üÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬Ð¹Â¶ÁËÓû§²É°ì»úƱµÄÂòÂôµÄÃô¸ÐÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÂòÂôºÅ¡¢¹ºÆ±µÄ¹¦·òºÍÈÕÆÚ¡¢¼ÛÖµ¡¢Ë°½ðÒÔ¼°ÐÅÓþ¿¨ÐÅÏ¢µÈ¡£Ä¿Ç°£¬¸Ã¹«Ë¾²¢Î´°ä²¼ÓйØÕâ´ÎÊÂÎñµÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.suspectfile.com/florida-compagnia-aerea-spirit-airlines-nuovamente-colpita-da-un-data-breach/
3.×êÑÐÈËÔ±·¢ÏÖREvilµÄ¹¥»÷»î¶¯£¬Ê¹ÓÃVOIPºÍDDoS¹¥»÷

ÃûΪ3xp0rtµÄ×êÑÐÈËÔ±·¢ÏÖREvilµÄ¹¥»÷»î¶¯£¬ÆðͷʹÓÃVOIPºÍDDoS¹¥»÷¡£REvilÊÇÒ»ÖÖÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©£¬ÆäÐÂÕ½ÊõÖÐÔ̺¬Ê¹ÓÃÓïÒô¼ÓÃÜVOIPµç»°£¬ÏòýÌåºÍÊܺ¦ÕßÌṩÓйع¥»÷µÄÐÅÏ¢¡£´Ë±í£¬¸ÃÍŻﻹÌṩÁ˸¶·ÑµÄ¹¥»÷·þÎñ£¬Äܹ»¶ÔÖ¸±ê¹«Ë¾½øÐÐLayer 3ºÍLayer 7µÄDDoS¹¥»÷¡£ÆäÖÐLayer 3µÄ¹¥»÷ͨ³£ÓÃÓÚ¶Ï¿ª¹«Ë¾µÄInternetÏνӣ¬Layer 7µÄ¹¥»÷ÓÃÀ´¹Ø¹ØÖ¸±ê¹«Ë¾¿É¹«¿ª½Ó¼ûµÄÀûÓ÷¨Ê½£¬ÀýÈçWeb·þÎñÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-gang-plans-to-call-victims-business-partners-about-attacks/
4.Õë¶ÔCPUµÄÐÂÐͲàÐÅ·¹¥»÷¿Éй¶¼ÓÃÜÃÜÔ¿µÈÐÅÏ¢

ÒÁÀûŵÒÁ´óѧµÄ×êÑÐÍŶӷ¢ÏÖÕë¶ÔCPUÄÚ²¿¼Ü¹¹µÄÐÂÐͲàÐÅ·¹¥»÷¡£´ÓǰµÄ²àÐÅ·¹¥»÷ÖØÒª¹Ø×¢µÄÊÇCPUζȡ¢µçÉÈÔëÒô¡¢´«ÊäÃýÎó£¬ÒÔ¼°CPUµÄÄÚ²¿»º´æÏµÍ³½á¹¹£¬¶øÕâ´Î¹¥»÷×êÑÐÁËÉÐδʹÓõĶàºËCPUµÄÒ»²¿ÃÅ£¬¼´»·Ðλ¥Á¬£¨ring interconnect£©£¬Ò²³ÆÎª»·ÐÎ×ÜÏß¡£×êÑÐÈËÔ±³Æ£¬ÓÉÓÚ´ËÀ๥»÷²»ÒÀÀµÓÚ¹²ÏíÄÚ´æ¡¢»º´æ¼¯¡¢Ö÷Ìâ×ÊÔ´»òÈκÎÌØ¶¨µÄ·ÇÖ÷Ìâ½á¹¹£¬Òò¶øÀûÓÃÏÖÓеIJàÐÅ··ÀÓù·½Ê½ºÜÄѽøÐлº½â¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/new-side-channel-attack-targets-the-cpu-ring-bus-for-the-first-time/
5.Zimperium°ä²¼ÓйØÒƶ¯ÀûÓÃÊý¾Ýй¶µÄ·ÖÎö»ã±¨

Zimperium°ä²¼ÁËÓйØÒƶ¯ÀûÓÃÊý¾Ýй¶µÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨·ÖÎöÁËÖØÒªÒÆ¶¯²Ù×÷ϵͳ£¨iOSºÍAndroid£©µÄÀûÓã¬Õë¶ÔËĸöÔÆ´æ´¢·þÎñ£ºÑÇÂíÑ·AWS¡¢Î¢ÈíAzure¡¢¹È¸èStorageºÍFirebase¡£×êÑз¢ÏÖ£¬ÓÐ14£¥µÄʹÓÃÔÆ´æ´¢µÄÒÆ¶¯ÀûÓ÷¨Ê½´æÔÚÅäÖÃÎÊÌ⣬¿Éй¶PII£¨Ò½ÁÆÀûÓúÍÉ罻ýÌåÀûÓõȣ©¡¢µ¼ÖÂڲƻ£¨²Æ¸»500Ç¿ÊÖ»úÇ®°üºÍ½»Í¨ÀûÓõȣ©¡¢Â¶³öIPºÍÄÚ²¿ÏµÍ³ÅäÖã¨ÐÂÎÅ·þÎñºÍ»ú³¡·þÎñµÈ£©¡£ÆäÖУ¬ÊÜÓ°ÏìµÄÐÐÒµÖØÒªÊÇóÒס¢¹ºÎï¡¢Éç½»¡¢Í¨Ñ¶ºÍ¹¤¾ßÐÐÒµ¡£
ÔÎÄÁ´½Ó£º
https://blog.zimperium.com/unsecured-cloud-configurations-exposing-information-in-thousands-of-mobile-apps/
6.Ó¢ÌØ¶û°ä²¼2020Äê²úÆ·°²È«ÐԵķÖÎö»ã±¨

Ó¢ÌØ¶û°ä²¼ÁË2020Äê²úÆ·°²È«ÐԵķÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÔÚ2020ÄêÅû¶µÄ231¸ö·ì϶ÖУ¬ÓÐ109¸ö(47%)ÊÇÓÉÓ¢ÌØ¶ûÔ±¹¤Í¨¹ý°²È«×êÑз¢Ïֵ쬶ø²Î¼Ó·ì϶Éͽð´òËãµÄ±í²¿×êÑÐÈËÔ±»ã±¨ÁË105¸ö·ì϶£¨45£¥£©¡£´Ë±í£¬ÓÉ±í²¿·¢ÏֵĴó²¿ÃÅ·ì϶¶¼´æÔÚÓÚÔÚÈí¼þÖУ¬ÖØÒªÔÚÓÃÓÚͼÐΡ¢ÍøÂçºÍÀ¶ÑÀ×é¼þµÄÈí¼þʵÓ÷¨Ê½ºÍÈí¼þÇý¶¯·¨Ê½ÖС£ÆäÖУ¬Çý¶¯·¨Ê½ºÍÆäËûÈí¼þ×é¼þÖеķì϶×î¶à£¬Îª93¸ö£»Æä´ÎΪ¹Ì¼þ£¬´æÔÚ66¸ö·ì϶£»¶øÓÐ58¸ö·ì϶ӰÏìµ½¹Ì¼þºÍÈí¼þµÄ×éºÏ¡£
ÔÎÄÁ´½Ó£º
https://blogs.intel.com/technology/2021/03/ipas-intel-2020-product-security-report/#gs.vg4enn


¾©¹«Íø°²±¸11010802024551ºÅ