Íþ¸Õ¿Æ¼¼³ÆÆäÔâµ½Ragnar Locker¹¥»÷£»Fastly CDNÖжÏ£¬Amazon¡¢RedditºÍGitHubµÈå´»ú

°ä²¼¹¦·ò 2021-06-10

1.KasperskyÅû¶PuzzleMakerÕë¶ÔÈ«ÇòµÄ¹¥»÷»î¶¯


1.jpg


KasperskyÅû¶ÐºڿÍÍÅ»ïPuzzleMakerÕë¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÊ×ÏÈÀûÓÃÁ˹ȸèChromeÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21224£©£¬Ö®ºóÀûÓÃWindowsÄÚºËÖеÄÐÅϢй¶·ì϶ºÍWindows NTFSÌáȨ·ì϶£¨CVE-2021-31956£©ÌÓÍÑɳÏä²¢»ñµÃϵͳȨÏÞ¡£Kaspersky³ÆPuzzleMakerµÄ¹¥»÷»î¶¯×îÔçÊÇÔÚ4ÔÂÖÐÑ®·¢Ïֵ쬲¢°µÊ¾Ä¿Ç°·ì϶²¹¶¡ÒѾ­¿ÉÓ㬽¨ÒéÓû§¾¡¿ì¸üÐÂä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/chrome-windows-zero-day/40191/


2.Î÷°àÑÀÀͶ¯ºÍÉç»á¾­¼Ã²¿MITES³ÆÆäÔâµ½ÍøÂç¹¥»÷


2.jpg


Î÷°àÑÀÀͶ¯ºÍÉç»á¾­¼Ã²¿ (MITES)³ÆÆäÓÚÖÜÈýÔâµ½ÍøÂç¹¥»÷£¬ÔÚÖÂÁ¦¸´Ô­ÊÜÓ°ÏìµÄ·þÎñ¡£MITESµÄÄê¶ÈÔ¤Ëã¿¿½ü3900ÍòÅ·Ôª£¬ÕƹÜЭºÍг¼à¶½Î÷°àÑÀµÄ¾ÍÒµ¡¢Éç»á¾­¼ÃºÍÆóÒµÉç»áÔðÈÎÕþ²ß¡£¸Ã²¿°µÊ¾£¬Õâ´Î¹¥»÷µ¼ÖÂͨѶÊҺͶàýÌåÊҵIJ»³ÉÓ㬵«ÊÇÆä¹Ù·½µÄÍøÕ¾ÈÔÔÚÕý³£ÔËÐС£ÕâÊǹ¤µ³ÔÚ½ñÄêÔâµ½µÄµÚ¶þ´ÎÍøÂç¹¥»÷£¬ÔçÔÚ3Ô£¬¹ú¶È¹«¹²¾ÍÒµ·þÎñ¾Ö (SEPE)¾ÍÔâµ½ÁËRyukÀÕË÷Èí¼þ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118768/hacking/spains-ministry-of-labor-cyberattack.html


3.Íþ¸Õ¿Æ¼¼Ôâµ½Ragnar Locker¹¥»÷£¬·þÎñÁÙʱÖжÏ


3.jpg


Öйų́ÍåµÄÍþ¸Õ¿Æ¼¼£¨ADATA£©Ôâµ½Ragnar Locker¹¥»÷£¬·þÎñÁÙʱÖжÏ¡£ADATAÖØÒª³ö²ú¸ß»úÄÜDRAMÄÚ´æÄ£¿éºÍNANDÉÁ´æ¿¨µÈ²úÆ·£¬ÔÚ2018Äê±»ÆÀΪµÚ¶þ´óDRAMÄÚ´æºÍ¹Ì̬ӲÅÌ (SSD) Ôì×÷ÉÌ¡£¸Ã¹«Ë¾ÔÚÉêÃ÷ÖÐ³ÆÆäÔÚ5ÔÂ23ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ö®ºóÂíÉϹعØÁËËùÓÐÊÜÓ°ÏìµÄϵͳ¡£Ragnar LockerÓÚÉÏÖÜÄ©³ÆÆäÔÚADATAµÄÍøÂçÖÐÇÔÈ¡ÁË1.5TBÊý¾Ý£¬Ô̺¬×¨ÓÐóÒ×ÐÅÏ¢¡¢»úÃÜÎļþ¡¢µÀÀíͼ¡¢²ÆÕþÊý¾Ý¡¢GitlabºÍSVNÔ´´úÂ롢˾·¨Îļþ¡¢Ô±¹¤ÐÅÏ¢¡¢±£ÃܺÍ̸ºÍ¹¤×÷Îļþ¼ÐµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/computer-memory-maker-adata-hit-by-ragnar-locker-ransomware/


4.Fastly CDNÖжÏ£¬Amazon¡¢RedditºÍGitHubµÈå´»ú


4.jpg


Fastly CDNÖжϵ¼ÖÂÈ«ÇòÁìÓòÄÚ¶à¼Ò¹«Ë¾µÄÍøÕ¾ÆëÈ«¹Ø¹Ø»òÕßÎÞ·¨Õý³£¼ÓÔØ¡£Õâ´ÎÊܵ½Ó°ÏìµÄ¹«Ë¾Ô̺¬Amazon¡¢Amazon Web Services (AWS)¡¢ÃÀ¹úÓÐÏßµçÊÓÐÂÎÅÍø¡¢Ó¢¹úµ±¾Ö¡¢GitHub¡¢ShopifyºÍRedditµÈ¡£ÊÜÓ°ÏìÍøÕ¾³ÇÊÐÏÔʾ¡°ÏνÓʧ°Ü¡±¡¢ÃýÎ󡢡°IO ÃýÎó¡±»òHTTP 503´úÂë¡£¾­¹ý×îÖÕµ÷²é£¬Õâ´ÎÖжÏÊÇÓÉÓÚ¿Í»§ÅäÖøü¸Ä¶ø´¥·¢µÄÒ»¸öÈí¼þÃýÎóµ¼ÖµÄ£¬Ä¿Ç°ÎÊÌâÒѾ­½â¾ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/stackoverflow-twitch-reddit-others-down-in-fastly-cdn-outage/


5.FBIºÍAFPαÔì¼ÓÃÜ̸ÌìÆ½Ì¨Anom×¥²¶800¶àÃûÏÓÒÉ·¸


5.jpg


ÔÚÆù½ñΪֹ¹æÄ£×î´ó¡¢×Ôӵķ¨ÂÉÐж¯Trojan Shield£¨ÓÖ³ÆIronside£©ÖУ¬FBIºÍ°Ä´óÀûÑÇÁª¹ú¾¯Ô±Î±ÔìÁ˼ÓÃÜ̸ÌìÆ½Ì¨Anom²¢×¥²¶800¶àÃûÏÓÒÉ·¸¡£ÔçÔÚÈýÄêǰ·¨Âɲ¿ÃÅαÔìÁ˸ö˵½¶Ë¼ÓÃÜ̸ÌìÆ½Ì¨£¬×¨ÃÅÏúÊÛ¸ø·¸×ï·Ö×Ó£¬Ö¼ÔÚ¼àÌýËûÃǵÄÐÂÎźͶԻ°£¬Îª100¶à¸ö¹ú¶ÈµÄ300¶à¸ö·¸×OÍÅÌṩ³¬¹ý1.2Íǫ̀¼ÓÃÜÉ豸¡£·¨Âɲ¿ÃÅÔÚÉó²éÁË2700ÍòÌõÐÅÏ¢ºó¿ÛÁô800¶àÏÓ·¸£¬½É»ñÁ˳¬¹ý4800ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/800-arrest-fbi-anom-app-honeypot/


6.Ó¢ÌØ¶û°ä²¼6Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´73¸ö°²È«·ì϶


6.jpg


Ó¢ÌØ¶û°ä²¼ÁË6Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´ÁË73¸ö°²È«·ì϶¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇIntel VT-d²úÆ·Öб¾µØÌáȨ·ì϶£¨CVE-2021-24489£©ºÍCPU BIOS¹Ì¼þÖÐÓɲ»ÕýÈ·µÄ³õʼ»¯¡¢¾ºÕùǰÌá¡¢²»ÕýÈ·µÄÊäÈëÑéÖ¤ºÍ½ÚÔìÁ÷ÖÎÀí²»¼°µ¼ÖµÄ4¸öÌáȨ·ì϶£¨CVE-2020-12357¡¢CVE-2020-8670¡¢CVE-2020-8700ºÍCVE-2020-12359£©¡£Ó¢Ìضû³ÆÕâ´Î½¨¸´µÄ·ì϶ÖеÄ40¸ö(Ô¼55%)ÊÇͨ¹ýÆä¹«Ë¾ÄÚ²¿µÄ×Ô¶¯°²È«×êÑз¢Ïֵġ£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-fixes-73-vulnerabilities-in-june-2021-platform-update/