Ó¢¹úHarrisͬÃËϰȾÀÕË÷Èí¼þ£¬50¶àËùѧÌÃÊÜÓ°Ï죻LinuxÖеÄ2¸ö·ì϶¿ÉÈÆ¹ýSpectre¹¥»÷µÄ»º½â´ëÊ©
°ä²¼¹¦·ò 2021-03-311.Ó¢¹úHarrisͬÃËϰȾÀÕË÷Èí¼þ£¬50¶àËùѧÌÃÊÜÓ°Ïì

3ÔÂ27ÈÕ£¨ÐÇÆÚÁù£©£¬Î»ÓÚÂ׶صĽÌÓý´È±¯»ú¹¹¹þÀï˹½áºÏ»á£¨Harris Federation£©µÄITϵͳºÍµç×ÓÓʼþ·þÎñÆ÷Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ó°ÏìÁË50¸öÖÐÓ×ѧµÄ37000ÃûѧÉú¡£ÔÚ¼ì²âµ½¹¥»÷Ö®ºó£¬¸Ã×éÖ¯ÂíÉϹعØÁ˵ç×ÓÓʼþºÍ¹Ì¶¨µç»°ÏµÍ³²¢½«ËùÓÐÀ´µç³Á¶¨ÏòµÃÊÖ»ú£¬Í¬Ê±»¹½ûÓÃÁËѧÉúµÄÉ豸ÒÔÔ¤·ÀÀÕË÷Èí¼þ´«²¼¡£¸Ã×éÖ¯°µÊ¾ÕâÊÇÒ»´Î¸ß¶È¸´ÔӵĹ¥»÷»î¶¯£¬ÆäĿǰÔÚÓëµ±¾Ö×éÖ¯ºÏ×÷¶Ô´ËÊ·¢Õ¹µ÷²é¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/harris-federation-hit-by-ransomware-attack-affecting-50-schools/
2.ÐÂ¼ÓÆÂVhiveϰȾALTDOS£¬30¶àÍò¸ö¿Í»§µÄ¼Í¼й¶

ÐÂ¼ÓÆÂ¼Ò¾ßÁ¬ËøµêVhiveÔÚ3ÔÂ23ÈÕ°ä·¢ÆäÔâµ½ALTDOSÀÕË÷Èí¼þ¹¥»÷£¬30¶àÍò¸ö¿Í»§µÄ¼Í¼ÒÑй¶¡£¸Ã¹«Ë¾³ÆÆä¹ÙÍøvhive.com.sgÔÚ3ÔÂ21ÈÕÔâµ½³õ´Î¹¥»÷£¬ÆäÍøÂç·þÎñÆ÷ÔÚ3ÔÂ22ÈÕ±»¹¥ÆÆ¡£VhiveÔÚ3ÔÂ23ÈÕʹÓñ¸·Ý¸´ÔÆäÍøÕ¾ºÍÎļþ£¬µ«Î´Äܽâ¾öÖØÒª·ì϶¡£ÕâʹµÃ¹¥»÷ÔÚ3ÔÂ25ÈÕ³ÖÐø£¬ALTDOSÇÔÈ¡ÁËÆäÔ´´úÂëºÍÎļþ£¬²¢¼ÓÃÜÁË·þÎñÆ÷ÉϵÄËùÓÐÎļþ¡£Ä¿Ç°£¬Vhive»Ø¾øÁËÊê½ðÒªÇó¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/sg-vhive-alerts-consumers-to-cyberattack/
3.Õë¶ÔÓ¡¶ÈµÄAPT×éÖ¯RedEchoÒÑ¹Ø¹ØÆäʹÓõĻù´¡ÉèÊ©

APT×éÖ¯RedEchoÔÚ2Ôµױ»×êÑÐÈËÔ±Åû¶ºó£¬ÒÑ¹Ø¹ØÆäʹÓõĻù´¡ÉèÊ©¡£Recorded FutureµÄ°²È«ÈËÔ±ÓÚ2Ô·¢ÏÖÁ˸ÃAPT×éÖ¯£¬³Æ¸ÃÍÅ»ï×Ô2020ËêÊ×¹¥»÷ÁËÓ¡¶ÈµÄÖÁÉÙ10¸öµçÁ¦²¿ÃÅ£¬»¹½«Ö¸±ê¶Ô×¼Á˸ßѹÊäµç±äµçÕ¾ºÍȼú»ðÁ¦·¢µç³§¡£Ôڸ÷¢ÏÖ°ä²¼¼¸Öܺó£¬RedEchoÒѾ¹Ø¹ØÁ˲¿ÃÅÓÃÓÚ½ÚÔì×°ÖÃÔÚÖ¸±êÍøÂçÖеÄShadowPadºóÃŵĻù´¡ÉèÊ©¡£×êÑÐÈËÔ±´§Ä¦£¬¸ÃAPT×éÖ¯ÔÚ±»·¢ÏÖºó¿ÉÄܽ«ÆäC2×ªÒÆµ½ÁËÆäËû´¦Ëù¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116094/apt/redecho-apt-c2-shutdown.html
4.ClopÍŻ﹫¿ªÃÀ¹úMarylandºÍCalifornia´óѧµÄÐÅÏ¢

3ÔÂ29ÈÕ£¬ClopÍÅ»ïÆðÍ·°ä²¼´ÓÃÀ¹ú½ÌÓý»ú¹¹ÇÔÈ¡µÄÊý¾ÝµÄ½ØÍ¼£¬ÆäÖÐÔ̺¬ÃÀ¹úÂíÀïÀ¼´óѧ£¨University of Maryland£©ºÍ¼ÓÀû¸£ÄáÑÇ´óѧ£¨University of California£©µÄ²ÆÕþÎļþºÍÓ×ÎÒÐÅÏ¢¡£Æ¾¾Ý½ØÍ¼£¬Õâ´Îй¶µÄÊý¾ÝÔ̺¬Áª¹ú˰ÊÕÎļþ¡¢¸à»ð¼õÃâÒªÇó¡¢»¤ÀíίԱ»áÉêÇëºÍ˰ÊÕÌáÒªÎļþµÈ²ÆÕþÐÅÏ¢£¬ÒÔ¼°ÕÕÆ¬¡¢ÐÕÃû¡¢¼Òͥסַ¡¢Éç»á°²È«ºÅÂë¡¢ÒÆÃñÉí·Ý¡¢µ®ÉúÈÕÆÚºÍ»¤ÕÕµÈÓ×ÎÒÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-group-targets-universities-of-maryland-california-in-new-data-leaks/
5.Ovarro TBox RTUÖдæÔÚÔ̺¬RCEÔÚÄڵĶà¸ö·ì϶

°²È«¹«Ë¾ClarotyµÄ°²È«×êÑÐÔ±Uri Katz·¢ÏÖOvarroµÄTBoxÔ¶³ÌÖն˵¥Ôª£¨RTU£©´æÔÚ5¸ö·ì϶¡£TBoxÊÇÓÃÓÚ½ÚÔì¼à¿ØºÍÊý¾Ý²É¼¯£¨SCADA£©ÀûÓõÄ×Ô¶¯»¯½â¾ö¹æ»®£¬Éæ¼°µçÁ¦¡¢Ê¯ÓͺÍÌìÈ»Æø¡¢ÔËÊäºÍ¼Ó¹¤µÈÐÐÒµ¡£ÕâЩ·ì϶±ðÀëΪ´úÂëÖ´Ðзì϶CVE-2021-22646¡¢¿Éµ¼ÖÂTBox±ÀÀ£µÄCVE-2021-22642¡¢¿É½âÃܵǼÃÜÂëµÄCVE-2021-22640¡¢¿É¸ü¸Ä»òɾ³ýÅäÖÃÎļþµÄCVE-2021-22648ºÍ¿ÉÇÔȡӲ±àÂëµÄ¼ÓÃÜÃÜÔ¿µÄCVE-2021-22644¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/03/flaws-in-ovarro-tbox-rtus-could-open.html
6.LinuxÖеÄ2¸ö·ì϶¿ÉÈÆ¹ýSpectre¹¥»÷µÄ»º½â´ëÊ©

SymantecµÄ×êÑÐÈËÔ±·¢ÏÖÁËLinuxÖеÄ2¸öзì϶£¬¿É±»ÓÃÀ´ÈƹýSpectre¹¥»÷µÄ»º½â´ëÊ©¡£SpectreÊÇ2018Äê1Ô·¢ÏÖµÄоƬ·ì϶£¬ÏÕЩӰÏìÁËËùÓд¦ÖÃÆ÷£¬Ö»ÄÜͨ¹ý²Ù×÷ϵͳ²¹¶¡À´½øÐлº½â¡£ÕâÁ½¸öзì϶¶¼ÓëLinuxÄÚ²é¶ÔÀ©´óµÄBerkeleyÊý¾Ý°ü¹ýÂËÆ÷£¨BPF£©µÄÖ§³ÖÓйأ¬ÆäÖÐ×îÑϳÁµÄ·ì϶£¨CVE-2020-27170£©Äܹ»ÓÃÀ´¶ÁÈ¡ÄÚºËÄÚ´æÖÐÈκεØÎ»µÄÄÚÈÝ£¬µÚ¶þ¸ö·ì϶£¨CVE-2020-27171£©¿É¶ÁÈ¡4 GBÁìÓòµÄÄÚºËÄÚ´æÖеÄÄÚÈÝ¡£
ÔÎÄÁ´½Ó£º
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spectre-bypass-linux-vulnerabilities


¾©¹«Íø°²±¸11010802024551ºÅ