NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª

°ä²¼¹¦·ò 2021-09-23

NEW CooperativeÔâBlack Matter¹¥»÷±»ÀÕË÷590ÍòÃÀÔª


newcooperativeÔâ¹¥»÷.jpg


ÃÀ¹úÅ©·òºÏ×÷ÉçNEW CooperativeÔÚÉÏÖÜÄ©Ôâµ½Black MatterµÄÀÕË÷¹¥»÷¡£ÕâÊÇÒ»¼ÒËÇÁϺ͹ÈÎïºÏ×÷É磬Õâ´Î¹¥»÷»î¶¯½«µ¼ÖÂÁ¸Ê³¡¢ÖíÈâºÍ¼¦ÈâµÈʳƷ¹©¸øÖжÏ¡£¹¥»÷ÕßÒªÇó¸Ã¹«Ë¾Ö§¸¶590ÍòÃÀÔªÊê½ð£¬²¢°µÊ¾5ÈÕºóÊê½ð½ð¶î½«Ôö³¤µ½1180ÍòÃÀÔª¡£BlackMatterÐû³ÆÇÔÈ¡ÁË1000 GBµÄÊý¾Ý£¬Ô̺¬soilmap.comÏîÖ÷ÕÅÔ´´úÂë¡¢Ñз¢Á˾֡¢Ô±¹¤ÐÅÏ¢¡¢²ÆÕþÎļþÒÔ¼°KeePassÃÜÂëÖÎÀíÆ÷µÄµ¼³öÊý¾Ý¿âµÈ¡£


Ô­ÎÄÁ´½Ó£º


https://securityaffairs.co/wordpress/122410/cyber-crime/black-matter-new-cooperative.html



×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1.06ÒÚÌ©¹úÓο͵ÄÓ×ÎÒÐÅϢй¶


×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1.06ÒÚÌ©¹úÓο͵ÄÓ×ÎÒÐÅϢй¶.png


Comparitech×êÑÐÈËÔ±Bob DiachenkoÓÚ2021Äê8ÔÂ22ÈÕ·¢ÏÖÁËδÊܱ £»¤µÄElasticsearchÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ200GBÊý¾Ý£¬Ô̺¬Á˳¬¹ý1.06ÒÚÌ©¹úÓο͵ÄÓ×ÎÒÐÅÏ¢¡£Diachenko´§Ä¦£¬¸ÃÊÂÎñÉæ¼°µ½´ÓǰʮÄêÖÐǰÍùÌ©¹úÓÎÀÀµÄµÄËùÓбí¹úÈË¡£×êÑÐÈËԱĿǰÎÞ·¨È·¶¨ÕâЩÊý¾Ýй¶µÄ¹¦·ò£¬µ«ÊÇÔÚ֪̩ͨ¹úµ±¾ÖºóµÄ24Ó×ʱÄھͱ»± £»¤ÁËÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º


https://www.infosecurity-magazine.com/news/data-of-106-million-visitors-to/


»¥ÁªÍøÓïÒô¹«Ë¾VoIP.msÔâµ½REvilÍÅ»ïµÄDDoS¹¥»÷


»¥ÁªÍøÓïÒô¹«Ë¾VoIP.msÔâµ½REvilÍÅ»ïµÄDDoS¹¥»÷.png


»¥ÁªÍøÓïÒô¹«Ë¾VoIP.msÓÚ9ÔÂ16ÈÕÔâµ½REvilÍÅ»ïµÄDDoS¹¥»÷¡£¸Ã¹«Ë¾Óû§·´Ó³DDoS¹¥»÷ÖжÏÁ˵绰·þÎñ£¬Ê¹ËûÃÇÎÞ·¨½ÓÌý»ò²¦´òµç»°¡£¸Ã¹«Ë¾½¨Òé¿Í»§Åú¸ÄÆäHOSTSÎļþ£¬½«ÓòÃûÖ¸ÏòËûÃǵÄIPµØÖ·£¬ÒÔÈÆ¹ýDNS½âÎö£¬µ«Õâµ¼ÖÂÁ˹¥»÷ÕßÖ±½Ó¶Ô¸ÃIPµØÖ·ÌáÒéDDoS¹¥»÷¡£Ö®ºó£¬VoIP.ms½«×Ô¼ºµÄÍøÕ¾ºÍDNS·þÎñÆ÷×ªÒÆµ½ÁËCloudflareʹµÃÎÊÌâµÃµ½ÁË»º½â £¬µ«µç»°·þÎñÈÔ´æÔÚÖжϡ¢µôÏߺͻúÄÜÇ·°²µÈÎÊÌ⡣Ŀǰ£¬VoIP.msÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/voipms-phone-services-disrupted-by-ddos-extortion-attack/



ÃÀ¹ú¹²ºÍµ³Öݳ¤Ð­»á(RGA)³ÆÆäµç×ÓÓʼþϵͳÔâµ½ÈëÇÖ


ÃÀ¹ú¹²ºÍµ³Öݳ¤Ð­»á(RGA)³ÆÆäµç×ÓÓʼþϵͳÔâµ½ÈëÇÖ.png


ÃÀ¹ú¹²ºÍµ³Öݳ¤Ð­»á(RGA)ÔÚÉÏÖÜ·¢ËÍ֪ͨ£¬³ÆÆäµç×ÓÓʼþϵͳÔÚ2ÔÂÖÁ3ÔÂÔâµ½ÈëÇÖ¡£RGAÊÇÃÀ¹úµÄÒ»¸öÃâ˰×éÖ¯£¬ËüΪ¹²ºÍµ³ºòÑ¡ÈËÌṩ¾ºÑ¡ËùÐèµÄ×ÊÔ´£¬ÒÔÖ§³ÖËûÃǵ±Ñ¡Öݳ¤¡£RGAÔÚ6ÔÂ24ÈÕ·¢ÏÖÐÅϢй¶ÊÂÎñ£¬9ÔÂ1ÈÕʵÏÖµç×Óȡ֤£¬²¢ÓÚ9ÔÂ15ÈÕ·¢ËÍÓʼþ֪ͨÁËÊÜÓ°ÏìµÄÓ×ÎÒ¡£RGA³ÆÕâÊǽñÄê3Ô·ÝÕë¶ÔÈ«Çò×éÖ¯Microsoft ExchangeµÄ´ó¹æÄ£¹¥»÷»î¶¯µÄÒ»²¿ÃÅ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/republican-governors-association-email-server-breached-by-state-hackers/ 


Apache OpenOfficeÖдæÔÚRCE·ì϶CVE-2021-33035


Apache OpenOfficeÖдæÔÚRCE·ì϶CVE-2021-33035.png


×êÑÐÈËÔ±ÔÚ9ÔÂ19ÈÕÅû¶ÁËApache OpenOffice(AOO)ÖеÄRCE·ì϶CVE-2021-33035µÄϸ½Ú¡£ÕâÊÇÒ»¸öÎļþ¸²¸ÇµÄ»º³åÇøÒç¶Âí½Å£¬Ëüͨ¹ýDEP£¨µØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£©ºÍASLR£¨µØÖ·¿Õ¼ä²¼¾ÖËæ»ú»¯£©Èƹý·µ»ØÖ¸Õ룬×îÖÕÖ´ÐÐËÁÒâºÅÁ¹¥»÷ÕßÄܹ»Í¨¹ýÓÕÆ­Ö¸±ê´ò¿ªÌØÔìµÄ.dbfÎļþÀ´´¥·¢¸Ã·ì϶¡£Ä¿Ç°£¬½¨¸´¸Ã·ì϶µÄ²âÊ԰淨ʽÒѾ­°ä²¼¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122426/security/apache-openoffice-rce-cve-2021-33035.html



Netgear°ä²¼¸üУ¬½¨¸´¶à¿î·ÓÉÆ÷ÖеĴúÂëÖ´Ðзì϶


Netgear°ä²¼¸üУ¬½¨¸´¶à¿î·ÓÉÆ÷ÖеĴúÂëÖ´Ðзì϶.png


NetgearÓÚ9ÔÂ21ÈÕ°ä²¼°²È«¸üУ¬½¨¸´ÁËCircle¼Ò³¤½ÚÔì·þÎñÖеĴúÂëÖ´Ðзì϶CVE-2021-40847£¬¸Ã·þÎñÔÚÊ®¼¸¿îSOHO Netgear·ÓÉÆ÷ÉÏÒÔrootȨÏÞÔËÐС£¸Ã·ì϶´æÔÚÓÚcircled¸üÐÂÊØ»¤¹ý³ÌÖУ¬Äܹ»±»Ô¶³ÌÀûÓÃÀ´Ðá̽·ÓÉÆ÷²¢Ö´ÐÐÖÐÑëÈ˹¥»÷(MitM)¡£´Ë±í£¬Nichols»¹°ä²¼ÁËÒ»¸öDZÔڵĹ¥»÷Á´£¬ÑÝʾÁ˹¥»÷ÕßÈôºÎÔÚ·ÛËéÔ±¹¤µÄNetgear·ÓÉÆ÷ºóÓÃÀ´ÈëÇÔìóÒµµÄÍøÂç¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/netgear-fixes-dangerous-code-execution-bug-in-multiple-routers/