ºÚ¿ÍÔÚ°µÍøÏúÊÛ 4900 Íò·Ý´÷¶ûµÄ¿Í»§Êý¾Ý

°ä²¼¹¦·ò 2024-05-11
1. ºÚ¿ÍÔÚ°µÍøÏúÊÛ 4900 Íò·Ý´÷¶ûµÄ¿Í»§Êý¾Ý


5ÔÂ10ÈÕ£¬¿Æ¼¼¾ÞÍ·´÷¶û¹«Ë¾ÒÑÏòÆä¿Í»§´«µÝÊý¾Ýй¶ÊÂÎñ¡£Õâ´Îй¶ӰÏìÁË´æ´¢¿Í»§ÐÅÏ¢¼°ÆäÔÚ´÷¶ûµÄ²É°ìº¹Çà¼Í¼µÄ´÷¶ûÃÅ»§ÍøÕ¾¡£Ö»¹Ü¸Ã¹«Ë¾Ã»ÓÐй©ÊÜÓ°Ïì¿Í»§µÄÊýÁ¿£¬µ«ÊÂÎñÖÐй¶µÄÊý¾ÝÔ̺¬£ºÈ«Ãû¡¢ÏÖʵµØÖ·¡¢´÷¶ûÓ²¼þºÍ¶©µ¥ÐÅÏ¢£¬Ô̺¬·þÎñ±êÇ©¡¢ÉÌÆ·ÃèÊö¡¢¶©¹ºÈÕÆÚºÍÓйر£½¨ÐÅÏ¢¡£±ØÒªÇ¿µ÷µÄÊÇ£¬¹ÌÈ»´÷¶û»ã±¨µÄÊý¾Ýй¶ÊÂÎñÓë Menelik µÄ˵·¨Ö®¼äµÄÁªÏµÉÐδµÃµ½Ö¤Êµ£¬µ«ºÚ¿Í¼á³ÆÕâµÄÈ·ÊÇͳһ·й¶ÊÂÎñ£¬²¢ÌṩÁËÓйØÐ¹Â¶Êý¾ÝµÄ¸ü¶à¾ßÌåÐÅÏ¢¡£¾ßÌåÀ´Ëµ£¬Menelik Ðû³ÆÒÑ»ñÈ¡³¬¹ý 4900 Íò´÷¶û¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£´÷¶ûÒѲÉÈ¡¶àÏî´ëÊ©À´Ó¦¶ÔÕâ´Î°²È«ÊÂÎñ¡£ËûÃÇÒÑ֪ͨ·¨Âɲ¿ÃŲ¢ÀñƸµÚÈý²½ÖèÒ½¹«Ë¾µ÷²é¸ÃÊÂÎñ¡£Ö»¹ÜËûÃǰµÊ¾²»ÒÔΪÓÉÓÚÓÐÏÞµÄÐÅϢй¶¶ø´æÔÚ³Á´ó·çÏÕ£¬µ«Ô̺¬È«ÃûºÍÎïÀíµØÖ·µÄÊý¾ÝµÄÏúÊÛ¶Ô¿Í»§×é³ÉÁËÏ൱´óµÄÍþв¡£


https://www.hackread.com/dell-data-breach-hacker-sells-customer-data/


2. ²¨Òô¹«Ë¾Ö¤ÊµÔøÔâLockbit¹¥»÷±»Ë÷Òª2ÒÚÃÀÔªÊê½ð


5ÔÂ10ÈÕ£¬²¨Òô¹«Ë¾Ö¤Êµ£¬²¨Òô¹«Ë¾»Ø¾øÖ§¸¶ 2 ÒÚÃÀÔªÊê½ð£¬ÒÔ»»È¡ºÚ¿ÍÇÔÈ¡µÄ 43GB Êý¾Ý¡£²¨Òô¹«Ë¾ÓÚ 2023 Äê 10 ÔÂÔâµ½ LockBit ÀÕË÷Èí¼þÍÅ»ïµÄºÚ¿Í¹¥»÷£¬¸ÃÍÅ»ïÍþвҪй¶ÆäËù˵µÄ´óÁ¿Ãô¸ÐÊý¾Ý¡£LockBit ×îÖÕ°ä²¼ÁËÕâ´ÎºÚ¿Í¹¥»÷µÄÊý¾Ý£¬Ô̺¬ IT ÖÎÀíÈí¼þ¡¢¼à¿ØÈÕÖ¾ºÍÉ󼯹¤¾ß¡£Æß¸öÔºó£¬Ë¾·¨²¿¶Ô Lockbit ²ß¶¯ÕßµÏÃ×ÌØÀÓÈÀïÒ®Î¬Ææ¡¤»ôÂÞÉá·ò (Dimitry Yuryevich Khoroshev) µÄδÃÜ·â¸æ×´ÊéÌáµ½£¬Ò»¼Òδй©ÐÕÃûµÄ¡°×ܲ¿Î»ÓÚ¸¥¼ªÄáÑÇÖݵĿç¹úº½¿ÕºÍ¹ú·À¹«Ë¾¡±ÊÇ Lockbit µÄ 2 ÒÚÃÀÔªÖ¸±ê¡£²¨Òô¹«Ë¾ËæºóÏò CyberScoop ֤ʵ£¬Õâ¾ÍÊÇÄǼÒδй©ÐÕÃûµÄ¹«Ë¾¡£Khoroshev Ò²±»³ÆÎª LockBitSupp£¬Õƹܴ´½¨ºÍÔËÓª LockBit ×éÖ¯£¬¸Ã×éÖ¯Õ¼ÓÐ 2,000 ¶àÃûÊܺ¦ÕßºÍ 5 ÒÚÃÀÔªµÄÊê½ð¡£½ñÄêÔçЩʱ³½£¬·¨Âɲ¿ÃŲ¿ÃÅÈ¡µÞÁË Lockbit µÄÒµÎñ£¬²¢ÓÚ±¾ÖÜÔçЩʱ³½Êջظü¶àÒµÎñ¡£


https://news.hitb.org/content/boeing-confirms-lockbit-hackers-wanted-200-million-ransom-after-2023-hack


3. BIG-IP É豸ÖеĹؼü·ì϶ʹ´óÐÍÍøÂçÈÝÒ×Êܵ½ÈëÇÖ


5ÔÂ9ÈÕ£¬×êÑÐÈËÔ±»ã±¨ÁËÒ»ÖÖ¿í·ºÊ¹ÓõÄÍøÂçÉ豸ÖеÄÑϳÁ·ì϶£¬¸Ã·ì϶ʹÊÀ½çÉÏһЩ×î´óµÄÍøÂçÈÝÒ×Êܵ½ÈëÇÖ¡£ÕâЩ·ì϶´æÔÚÓÚ BIG-IP Next Central Manager ÖУ¬¸ÃÖÎÀíÆ÷ÊÇ×îÐÂÒ»´ú BIG-IP ϵÁÐÉ豸ÖеÄÒ»¸ö×é¼þ£¬×éÖ¯ÓÃÀ´ÖÎÀí½ø³öÆäÍøÂçµÄÁ÷Á¿¡£ÏúÊ۸òúÆ·µÄ×ܲ¿Î»ÓÚÎ÷ÑÅͼµÄ F5°µÊ¾£¬ ¡¶²Æ¸»¡·ÔÓÖ¾×·×ÙµÄ 50 Ç¿ÆóÒµÖÐÓÐ 48 ¼ÒʹÓÃÆäÉ豸¡£F5½« Next Central ManagerÃèÊöΪ¡°µ¥Ò»¼¯ÖнÚÔìµã¡±£¬ÓÃÓÚÖÎÀíÕû¸ö BIG-IP É豸Ⱥ¡£×÷ΪִÐиºÔØÆ½ºâ¡¢DDoS »º½âÒÔ¼°¶Ô½ø³ö´óÐÍÍøÂçµÄÊý¾Ý½øÐв鳭ºÍ¼ÓÃܵÄÉ豸£¬BIG-IP É豸λÓÚÆä±íΧ£¬³äÈÎÄÚ²¿Ä³Ð©×ȫ¹Ø¼ü×ÊÔ´µÄÖØÒª¹Ü·¡£ÕâЩ¸öÐÔʹ BIG-IP É豸³ÉΪºÚ¿Í¹¥»÷µÄÃÎÏëÑ¡Ôñ¡£2021 ÄêºÍ2022Ä꣬ºÚ¿ÍÀûÓÃÑϳÁµÈ¼¶Îª 9.8£¨Âú·Ö 10£©µÄ·ì϶»ý¼«·ÛËé BIG-IP É豸¡£


https://arstechnica.com/security/2024/05/critical-vulnerabilities-in-big-ip-appliances-leave-big-networks-open-to-intrusion/


4. ¿¨°Í˹»ù°ä²¼ 2023 ÄêÄê¶È½ðÈÚÍþв»ã±¨


5ÔÂ10ÈÕ£¬¿¨°Í˹»ù×îа䲼µÄ 2023 ÄêÄê¶È½ðÈÚÍþв»ã±¨Êý¾ÝÏÔʾ£¬Óë 2022 ÄêÏà±È£¬È«ÇòÒÆ¶¯ÒøÐжñÒâÈí¼þÔö³¤ÁË 32%¡£»ã±¨Ç¿µ÷Õë¶Ô Android Óû§µÄ¹¥»÷¼¤Ôö£¬ÆäÖа¢¸»º¹¡¢ÍÁ¿âÂü˹̹ºÍËþ¼ª¿Ë˹̹Ôâ·êÒøÐÐľÂíµÄ±ÈÀý×î¸ß¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÍÁ¶úÆäÔÚÒÆ¶¯ÒøÐжñÒâÈí¼þ¹¥»÷·½Ãæ´¦ÓÚµ±ÏÈְλ£¬Ó°ÏìÁ˽ü 3% µÄÓû§¡£Ö»¹Ü½ðÈÚ PC ¶ñÒâÈí¼þÊýÁ¿½µÂäÁË 11%£¬µ«À´×Ô Ramnit ºÍ Zbot µÈ¶ñÒâÈí¼þ¼Ò×åµÄÍþвÒÀÈ»´æÔÚ£¬ÖØÒªÕë¶ÔÏû·ÑÕß¡£½ðÈÚÍøÂç´¹µöÒÀÈ»ÊÇÒ»¸ö³Á´óÎÊÌ⣬ռÕë¶ÔÆóÒµÓû§µÄËùÓÐÍøÂç´¹µö¹¥»÷µÄËÄ·ÖÖ®Ò»ÒÔÉÏ£¬ÒÔ¼°Õë¶Ô¼ÒÍ¥Óû§µÄ½üÈý·ÖÖ®Ò»¡£µç×ÓÉÌµêÆ·ÅÆÊǽðÈÚÍøÂç´¹µö³¢ÊÔµÄ×î´óÒýÓÕ£¬½ö PayPal ÍøÂç´¹µö¾ÍÕ¼ËùÓг¢ÊÔµÄÒ»°ëÒÔÉÏ¡£Óë¼ÓÃÜÇ®±ÒÓйصÄÍøÂç´¹µöºÍÚ¿Æ­ÔÚÔö³¤¡£ 2023 Ä꣬¿¨°Í˹»ù×èÖ¹Á˳¬¹ý 580 Íò´Î×·×ÙÒÔ¼ÓÃÜÇ®±ÒΪÖ÷ÌâµÄÍøÂç´¹µöÁ´½ÓµÄ³¢ÊÔ£¬±ÈÉÏÒ»ÄêÔö³¤ÁË 16%¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¾ÍÍøÂç´¹µö³¢ÊÔ¶øÑÔ£¬ÑÇÂíÑ·³ÉΪ±»·ÂÕÕ×î¶àµÄÔÚÏßÉ̵꣬Æä´ÎÊÇÆ»¹ûºÍ Netflix¡£


https://www.infosecurity-magazine.com/news/mobile-banking-malware-surges-32/


5. MIRAIͨ¹ýÀûÓÃIVANTI CONNECT SECURE·ì϶½øÐд«²¼


5ÔÂ9ÈÕ£¬Juniper Íþв³¢ÊÔÊÒµÄ×êÑÐÈËÔ±»ã±¨³Æ£¬ÍþвÐÐΪÕßÔÚÀûÓÃ×î½üÅû¶µÄ Ivanti Connect Secure (ICS) ·ì϶CVE-2023-46805 ºÍ CVE-2024-21887À´É¾³ýMirai ½©Ê¬ÍøÂçµÄÓÐЧ¸ºÔØ¡£¸ÃÈí¼þ¹«Ë¾»ã±¨³Æ £¬ÍþвÐÐΪÕßÔÚÀûÓà Connect Secure (ICS) ºÍ Policy Secure ÖеÄÁ½¸öÁãÈÕ·ì϶£¨CVE-2023-46805¡¢CVE-2024-21887£©ÔÚÖ¸±êÍø¹ØÉÏÔ¶³ÌÖ´ÐÐËÁÒâºÅÁî¡£CVE-2023-46805£¨CVSS ÆÀ·Ö 8.2£©ÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎÊÌ⣬´æÔÚÓÚ Ivanti ICS 9.x¡¢22.x ºÍ Ivanti Policy Secure µÄ Web ×é¼þÖС£Ô¶³Ì¹¥»÷ÕßÄܹ»´¥·¢¸Ã·ì϶£¬Í¨¹ýÈÆ¹ý½ÚÔì²é³­À´½Ó¼ûÊÜÏÞ×ÊÔ´¡£µÚ¶þ¸ö±àºÅΪ CVE-2024-21887£¨CVSS ÆÀ·Ö 9.1£©£¬ÊÇ Ivanti Connect Secure£¨9.x¡¢22.x£©ºÍ Ivanti Policy Secure Web ×é¼þÖеĺÅÁî×¢Èë·ì϶¡£¾­¹ýÉí·ÝÑéÖ¤µÄÖÎÀíÔ±Äܹ»Í¨¹ý·¢ËÍÌØÔìÒªÇó²¢ÔÚÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁîÀ´ÀûÓøÃÎÊÌâ¡£¹¥»÷ÕßÄܹ»Á´½ÓÕâÁ½¸öȱµã£¬Ïò佨²¹µÄϵͳ·¢ËÍÌØÔìÒªÇó²¢Ö´ÐÐËÁÒâºÅÁî¡£ 


https://securityaffairs.com/162936/cyber-crime/ivanti-connect-secure-flaws-mirai-botnet.html


6. ÃϼÓÀ­¹ú IT ÌṩÉÌTappwareԼĪ50GÊý¾Ýй¶


5ÔÂ9ÈÕ£¬Tappware ÊÇÒ»¼Ò³ÛÃûµÄ IT ·þÎñÌṩÉÌ£¬ÆäԼĪ 50GB µÄÊý¾Ý¿âÔÚºÚ¿ÍÂÛ̳ÉÏÔ⵽й¶£¬¸ÃÊý¾Ý¿âÔ̺¬ 230 ÍòÐÐÊý¾Ý£¬Ô̺¬Ãô¸ÐµÄÓ×ÎÒÐÅÏ¢£¬ÀýÈçÓë¸Ã¹«Ë¾ÓйصÄÓ×ÎÒµÄÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂ롣ƾ¾ÝÃϼÓÀ­¹úÍøÂ簲ȫµý±¨ (BCSI)»ã±¨£¬Ð¹Â¶µÄÊý¾Ýѡȡ SQL Ìåʽ£¬ÈÕÆÚΪ 2024 Ä꣬Ô̺¬¿í·ºµÄÓ×ÎÒ¾ßÌåÐÅÏ¢£¬¶ÔÓйØÓ×ÎÒ×é³ÉÁ˾޴óµÄÒþÖÔ·çÏÕ¡£¸Ã·ì϶ÊÇÔÚÍøÂç·¸×ï·Ö×Ó³£ÓõÄÂòÂô±»µÁÊý¾ÝµÄƽ̨ÉϽøÐÐÀýÐÐ¼à¿Ø»î¶¯Ê±·¢Ïֵġ£Õâ´Îй¶ֱ½ÓÍþвµ½ÊýǧÈ˵ÄÒþÖԺͰ²È«£¬¿ÉÄܵ¼ÖÂÉí·Ý͵ÇÔºÍڲƭ¡£


https://gbhackers.com/bangladesh-it-provider-database/