ÎÒ¹ú°ä²¼¡¶Ó×ÎÒÐÅÏ¢±£»¤·¨£¨²Ý°¸¶þ´ÎÉóÒé¸å£©¡·£»×êÑÐÍŶÓÅû¶¿ÉÓÃÓÚDDoS¹¥»÷µÄÐÂDNS·ì϶TsuNAME

°ä²¼¹¦·ò 2021-05-08

1.ÎÒ¹ú°ä²¼¡¶Ó×ÎÒÐÅÏ¢±£»¤·¨£¨²Ý°¸¶þ´ÎÉóÒé¸å£©¡·


1.jpg


2021Äê4ÔÂ29ÈÕ£¬ÎÒ¹ú°ä²¼Á˵ڶþ°æµÄ¡¶Ó×ÎÒÐÅÏ¢±£»¤·¨¡·²Ý°¸£¬²¢½«ÔÚ2021Äê5ÔÂ28ÈÕ֮ǰ¹«¿ªÕ÷ѯ¹«¼Ò¶¨¼û¡£µÚÊ®Èý½ìÈ«¹úÈË´ó³£Î¯»áµÚ¶þÊ®°Ë´Î»áÒé¶Ô½øÐÐÁ˳õ´ÎÉóÒ飬»áºó½«Ó¡·¢¸÷Ê¡£¨Çø¡¢ÊУ©¡¢ÖÐÑëÓйز¿ÃźͲ¿ÃÅ»ù²ãÁ¢·¨ÁªÏµµã¡¢ÈË´ó´ú±í¡¢ÆóÒµ¡¢×êÑлú¹¹µÈÕ÷Ç󶨼û¡£¸Ã²Ý°¸µÄ¿ò¼ÜÓë³õ°æ´óÌåÒ»Ñù£¬µÚ13ÌõÔö³¤ÁË´¦ÖÃÓ×ÎÒÐÅÏ¢µÄ˾·¨Æ¾¾Ý£¬µÚ15ÌõΪ´¦ÖÃδ³ÉÄêÈ˵ÄÓ×ÎÒÐÅÏ¢ÌṩÁ˸ü¸ßµÄ³ß¶È¡£


Ô­ÎÄÁ´½Ó£º

https://www.chainnews.com/articles/762892395785.htm


2.×êÑÐÍŶÓÅû¶¿ÉÓÃÓÚDDoS¹¥»÷µÄÐÂDNS·ì϶TsuNAME


2.jpg


×êÑÐÍŶÓÅû¶ÐµÄDNS·ì϶TsuNAME£¬¿ÉÕë¶ÔDNS·þÎñÆ÷ÌáÒé´ó¹æÄ£µÄ»ùÓÚ·´ÉäµÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷¡£¹¥»÷Õßͨ¹ý´æÔڸ÷ì϶µÄ½âÎöÆ÷ÏòÓµÓÐÑ­»·ÒÀÀµ¼Í¼µÄȨÍþ·þÎñÆ÷·¢ËͲ»¼ä¶Ï²éÎÊ£¬¶øµ¼ÖÂÆä̱»¾¡£´Ë±í£¬¸Ã·ì϶»¹Ó°ÏìÁËÅ·Ã˵ÄccTLD£¬ÓÉÓÚÆä½öÓÐÁ½¸öÓòµÄÑ­»·ÒÀÀµÅäÖÃÃýÎó£¬Òò¶ø´«ÈëµÄDNSÁ÷Á¿±»·Å´óÁË10±¶¡£Óû§Í¨¹ý¸ü¸Ä½âÎöÆ÷µÄÅäÖã¬Ñ¡Ôñ¡°Í¨¹ýÔ̺¬Ñ­»·¼ì²â´úÂ뻺ºÍ´æÑ­»·Óйؼͼ¡±£¬À´»º½â´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/new-tsuname-bug-can-be-used-to-ddos-key-dns-servers/


3.Å·ÖÞijÉúÎï×êÑÐËùÒòÆäѧÉúʹÓõÁ°æÈí¼þ¶øÏ°È¾Ryuk


3.jpg


Sophos·¢ÏÖÅ·ÖÞijÉúÎï·Ö×Ó×êÑÐËùÒòÆäѧÉúʹÓÃÃâ·ÑµÄµÁ°æÈí¼þ¶øÏ°È¾Ryuk¡£¸ÃѧÉúÔÚwarezÍøÕ¾ÏÂÔØÁËijÊý¾Ý¿ÉÊÓ»¯Èí¼þµÄÆÆ½â°æ£¬¶øÏ°È¾ÁËÐÅÏ¢ÇÔȡľÂí¡£¸ÃľÂíÇÔÈ¡ÁËWindows¼ôÌù°åµÄº¹Çà¼Í¼ºÍµÇ¼¸Ã×êÑÐËùµÄÃÜÂ룬²¢ÀûÓÃÆäÈëÇÖÁË×êÑÐËùµÄÍøÂç¡£Ôâµ½¹¥»÷ºó£¬¸Ã×êÑÐËùÐè³Á½¨·þÎñÆ÷²¢´Ó±¸·ÝÖи´Ô­Êý¾Ý£¬Òò¶øµ¼ÖÂÁËΪÆÚÒ»ÖܵÄÍøÂçÖжÏ£¬²¢ÃÔʧÁËÒ»ÖܵÄ×êÑÐÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ryuk-ransomware-finds-foothold-in-bio-research-institute-through-a-student-who-wouldnt-pay-for-software/


4.KasperskyÔÚÒ°·¢ÏÖÕë¶ÔWindowsµÄкóÃÅMoriya


4.jpg


KasperskyµÄ×êÑÐÈËÔ±ÔÚÒ°·¢ÏÖÕë¶ÔWindowsϵͳµÄкóÃÅMoriya¡£¸ÃºóÃÅ¿ÉÍøÂç²¢·ÖÎöÀ´×ÔWindowsÄں˵ØÖ·¿Õ¼äµÄÍøÂçÁ÷Á¿£¬ÕâÊDzÙ×÷ϵͳÄں˵صãµÄÄÚ´æÇøÓò£¬Í¨³£Ö»ÓÐÌØÈ¨ºÍ¿ÉÐÅ´úÂëÄÜÁ¦ÔËÐС£Æ¾¾Ý¿¨°Í˹»ùµÄÒ£²â¼¼Êõ£¬¸Ã¶ñÒâÈí¼þÒѱ»×°ÖÃÔÚ½ü10¸ö×éÖ¯µÄÍøÂçÉÏ¡£´Ë±í£¬¹¥»÷Õß»¹ÔÚ¹¥»÷ºóÆÚ×°ÖÃÁËÆäËû¹¤¾ß£¬Ô̺¬China Chopper¡¢BOUNCER¡¢TermiteºÍEarthµÈ£¬ÒÔÔÚÖ¸±êÍøÂçÉÏɨÃè²¢·¢ÏÖеÄÖ¸±ê£¬²¢ºáÏòÒÆ¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-moriya-rootkit-used-in-the-wild-to-backdoor-windows-systems/


5.ShinyHuntersÔÚ°µÍø¹«¿ªÓ¡¶ÈWedMeGoodµÄ41.5 GBÊý¾Ý


5.jpg


ShinyHuntersÔÚ°µÍø¹«¿ªÓ¡¶È»éÀñ²ß¶¯Æ½Ì¨WedMeGoodµÄ41.5 GBÊý¾Ý¡£Õâ´Îй©µÄÊý¾ÝÔ̺¬³ÇÊÓ×¢ÐÔ±ð¡¢ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ· ¡¢¹þÏ£ÃÜÂë¡¢Ô¤Ô¼ÏßË÷¡¢ÉϴεǼÈÕÆÚ¡¢ÕÊ»§´´½¨ÈÕÆÚ¡¢FacebookµÄIDºÅºÍAirbnbÖеÄÐÅÏ¢µÈ¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÉÐδ֤ʵÆä²úÉúÁËÊý¾Ýй¶ÊÂÎñ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬WedMeGoodÔÚ2020Äê10ÔÂÔø²úÉúÁËÒ»´ÎÊý¾Ýй¶ÊÂÎñ£¬ºÚ¿Í¹«¿ªÁ˼¸¼ÒÊܵ½¹¥»÷µÄÍøÕ¾µÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/shinyhunters-leak-india-wedmegood-database/


6.Foxit°²È«¸üУ¬½¨¸´ÆäPDF ReaderÖеĶà¸ö°²È«·ì϶


6.jpg


Foxit£¨¸£ê¿£©°ä²¼°²È«¸üУ¬ÒÔ½¨¸´PDF ReaderÖеĶà¸ö°²È«·ì϶£¬FoxitÐû³ÆÕ¼ÓÐÀ´×Ô200¸ö¹ú¶ÈºÍµØÓòµÄ6.5ÒÚÓû§£¬ÆäÈí¼þĿǰÒѱ»100000¶à¸ö¿Í»§Ê¹Óá£ÆäÖÐÒ»¸ö·ì϶׷×ÙΪCVE-2021-21822£¬ÊÇÓÉÓÚV8 JavaScriptÒýÇæÖеĿªÊͺóʹÓ÷ì϶µ¼ÖµÄ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚWindowsÍÆËã»úÉÏÔËÐжñÒâ´úÂ룬²¢ÓпÉÄÜÊÕÊܽÚÔìȨ¡£Õâ´Î¸üл¹½¨¸´Á˻ؾø·þÎñ¡¢Ô¶³ÌÖ´ÐдúÂë¡¢ÐÅϢй¶·ì϶¡¢SQL×¢Èë·ì϶¡¢DLL½Ù³Ö·ì϶µÈÆäËü·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/foxit-reader-bug-lets-attackers-run-malicious-code-via-pdfs/