Cloudflare³É¹¦À¹½Ø11.5 Tbps´´¼Í¼DDoS¹¥»÷

°ä²¼¹¦·ò 2025-09-04

1. Cloudflare³É¹¦À¹½Ø11.5 Tbps´´¼Í¼DDoS¹¥»÷


9ÔÂ2ÈÕ£¬Cloudflare½üÈÕ°ä·¢³É¹¦À¹½ØÁËÒ»³¡·åÖµ´ï11.5 TbpsµÄÊ·ÉÏ×î´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬Õâ´Î¹¥»÷ÒÔUDPºéË®¹¥»÷ΪÖ÷£¬ÖØÒªÔ´×ԹȸèÔÆÆ½Ì¨£¬²¢³ÉΪ³ÖÐøÊýÖܵĹ¥»÷º£³±ÖеÄ×îÈȳ±¡£¾ÝCloudflareÅû¶£¬Æä·ÀÓùϵͳÔÚ´ÓǰÊýÖÜÄÚÒÑ×Ô¶¯À¹½ØÊý°Ù´Î³¬´ó¹æÄ£DDoS¹¥»÷£¬ÆäÖÐ×îÐÂÆÆ¼Í¼µÄ¹¥»÷³ÖÐøÔ¼35Ã룬·åÖµÊý¾Ý°ü¿ìÂʸߴïÿÃë51ÒÚ¸ö£¬Ô¶³¬½ñÄê6Ô¸ù«Ë¾»ã±¨µÄ7.3 Tbps¹¥»÷£¬¹æÄ£Ôö³¤12%£¬ÉõÖÁ±ÈÍøÂ簲ȫ¼ÇÕß²¼À³¶÷¡¤¿ËÀײ¼Ë¹¼Í¼µÄ´Ëǰ×î¶¥·åÖµÓâÔ½1 Tbps¡£Õâ´Î11.5 TbpsµÄUDPºéË®¹¥»÷Õë¶Ôµ¥Ò»IPµØÖ·£¬¾ùÔÈÿÃë³å»÷21,925¸ö¶Ë¿Ú£¬·åֵʱ¶Ë¿ÚÉ¢²¼À©´óÖÁ34,517¸ö£¬¹¥»÷ÏòÁ¿ÒÔUDPºéˮΪÖ÷£¨Õ¼±È99.996%£©£¬¸¨ÒÔQOTD¡¢Echo¡¢NTP¡¢Mirai¡¢Portmap¼°RIPv1µÈ»ìºÏ¹¥»÷¼¿Á©¡£Ö»¹Ü¹¥»÷Á÷Á¿¾Þ´ó£¬CloudflareµÄ×Ô¶¯»¯·ÀÓùϵͳÈÔÓÐЧ¼ø±ð²¢¹ýÂËÁ˶ñÒâÁ÷Á¿£¬Î´¶Ô¿Í»§ÍøÂçÔì³ÉÄÚÈÝÓ°Ïì¡£


https://securityaffairs.com/181829/cyber-crime/cloudflare-blocked-a-record-11-5-tbps-ddos-attack.html


2. Ê¥´ï·ÆÏص±¾ÖÍøÕ¾Ô´´úÂëÔâÇÔÊÂÎñ±»Ö¤ÊµÎª¾ÉÊý¾Ýй¶


9ÔÂ2ÈÕ£¬Ò»ÔòÐû³ÆÇÔÈ¡ÃÀ¹úÐÂÄ«Î÷¸çÖÝÊ¥´ï·ÆÏص±¾ÖÍøÕ¾Ô´´úÂëµÄÌû×ÓÔÚºÚ¿ÍÂÛ̳Òý·¢¹Ø×¢£¬µ«¾­Cybernews×êÑÐÍŶÓÉî¿Ìµ÷²é£¬¸ÃÊÂÎñÏÖʵΪ¹¥»÷ÕßÀûÓùýÆÚÐÅÏ¢½øÐÐ"¸ÅÏëÑéÖ¤"µÄ³´×÷ÐÐΪ¡£Ê¥´ï·ÆÏØ×÷ΪÈ˶¡³¬15ÍòµÄÐÐÕþÇøÓò£¬Æä¹Ù·½ÍøÕ¾Êǵ±¾ÖÓëÃñ¶à½»»¥µÄ³ÁҪƽ̨£¬Õâ´ÎÊÂÎñËäδÔì³ÉÏÖʵ·çÏÕ£¬È´Â¶³öÁËÍøÂç¹¥»÷Õßͨ¹ý°ä²¼¾ÉÊý¾Ý²©È¡¹Ø×¢µÄÐÂÐÍÊÖ·¨¡£¹¥»÷ÕßÔÚÂÛ̳ÖÐÐû³ÆÒÑ»ñȡʥ´ï·ÆÏØÍøÕ¾µÄÔ´´úÂ룬²¢¸½ÉÏÁËÖÎÀíÔ±Óû§Ãû¡¢¹þÏ£ÃÜÂë¡¢Êý¾Ý¿âÄ£Ðͼ°PHP°æ±¾µÈÊý¾Ý¡£È»¶ø£¬CybernewsÍŶӷÖÎö·¢ÏÖ£¬¹¥»÷ÕßÌṩµÄÊý¾Ý¿âÄ£Ðͽö¸üÐÂÖÁ2017Ä꣬PHP°æ±¾¸üÊÇ2010Äê°ä²¼ÇÒÒÑÓÚ2011ÄêÖÕ³¡Ö§³ÖµÄ³Â¾É°æ±¾¡£¸ü¹Ø¼üµÄÊÇ£¬¶Ô±Èµ±Ç°ÍøÕ¾ÊµÊ±Á÷Á¿¼Ü¹¹£¬Æä¼¼ÊõÕ»Óëй¶Êý¾ÝÖеÄÅäÖôæÔÚÏÔÖø²î¾à£¬Ö¤Ã÷¹¥»÷ÕßÉÏ´«µÄÊµÎªÍøÕ¾2010Äê´ú¾É°æ±¾´úÂ룬¶ÔÏÖÓÐϵͳÎÞÄÚÈÝÐÔÍþв¡£


https://cybernews.com/security/santa-fe-county-hack-likely-outdated/


3. ¶íÂÞ˹APT28ÀûÓá°NotDoor¡±¶ñÒâÈí¼þ¹¥»÷Microsoft Outlook


9ÔÂ3ÈÕ£¬Î÷°àÑÀÍøÂ簲ȫ¹©¸øÉÌS2 GrupoµÄÍþвµý±¨³¢ÊÔÊÒLAB52ÓÚ2025Äê9ÔÂ3ÈÕ°ä²¼»ã±¨£¬Åû¶ÓɶíÂÞ˹֧³ÖµÄÍøÂçÍþв×éÖ¯APT28¿ª·¢µÄÐÂÐÍOutlookºóÃÅ¡°NotDoor¡±¡£¸Ã¶ñÒâÈí¼þ»ùÓÚVisual Basic for Applications£¨VBA£©¹¹½¨£¬Í¨¹ýOutlookÊÂÎñÇý¶¯´¥·¢Æ÷£¨ÈçÆô¶¯Ê±Application_MAPILogonCompleteºÍ½Ó¹ÜÐÂÓʼþʱApplication_NewMailEx£©¼¤»î£¬ÊµÏÖÊý¾ÝÇÔÈ¡¡¢ÎļþÉÏ´«¼°ËÁÒâºÅÁîÖ´ÐÐÖ°ÄÜ¡£NotDoorѡȡ´úÂë»ìºÏ¼¼Êõ£¬Ô̺¬Ëæ»ú»¯±äÁ¿ÃûºÍ×Ô½ç˵Base64±àÂ루¸½¼ÓÀ¬»ø×Ö·û·ÂÕÕ¼ÓÃÜ£©£¬²¢¼Ù×°³ÉºÏ·¨ºê¶ã±Ü¼ì²â¡£Æäͨ¹ýÊðÃûµÄ΢Èí¶þ½øÔìÎļþOneDrive.exe½øÐÐDLL²à¼ÓÔØ£¬¼ÓÔØ¶ñÒâSSPICLI.dll²¿ÊðºóÃÅ£¬Í¬Ê±Åú¸ÄOutlook×¢²á±íÉèÖýûÓð²È«ÖҸ桢ÆôÓú겢ÒÖÔì¶Ô»°¿òÌáÐÑ£¬È·Î¬Óƾû¯¾²Ä¬ÔËÐС£¸ÃºóÃÅͨ¹ý½«Êܺ¦ÕßÊý¾Ý±íйÖÁ¹¥»÷Õß½ÚÔìµÄÓÊÏ䣬²¢ÀûÓÃwebhook.site½øÐÐDNSºÍHTTP»Øµ÷ÑéÖ¤£¬³ÉÁ¢Òñ±ÎͨѶ¡£ÆäÄ £¿é»¯Éè¼ÆÖ§³Ö¶¯Ì¬¸üд¥·¢Æ÷ºÍºÅÁ¼ÓÇ¿¼ì²âÄѶÈ¡£


https://www.infosecurity-magazine.com/news/russia-apt28-notdoor-outlook/


4. È«Çò×î´ó·¸·¨ÌåÓýÖ±²¥Æ½Ì¨StreameastÔâ¶à¹ú½áºÏ½ø¹¥


9ÔÂ3ÈÕ£¬ÓÉ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©Óë°£¼°µ±¾Ö½áºÏ·¢Õ¹µÄרÏîÐж¯³É¹¦µ·»ÙÈ«Çò×î´ó·¸·¨ÌåÓýÖ±²¥Á÷ýÌåÍøÂçStreameast£¬²¢¿ÛÁôÁ½Ãû¹ØÁªÈËÔ±¡£¸Ãƽ̨×Ô2018ÄêÆðÔËÓª£¬ÒÀ¸½¸æ°×Ö§³ÖµÄÃâ·Ñģʽ£¬Ìṩ¸ßÇåµÁ²¥ÄÚÈÝ£¬¸²¸ÇÈ«Çò80¸öÓòÃû£¬Ô½ӼûÁ¿·åÖµ´ï1.36ÒڴΣ¬´ÓǰһÄê×ܽӼûÁ¿Í»ÆÆ16ÒڴΣ¬Óû§ÖØÒª¼¯ÖÐÓÚÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢·ÆÂɱö¼°µÂ¹ú¡£StreameastµÄÖ÷ÌâÇÖȨÐÐΪÔ̺¬Î´¾­ÊÚȨֱ²¥Å·ÖÞÎå´ó×ãÇòÁªÈü£¨Ó¢³¬¡¢Î÷¼×¡¢µÂ¼×µÈ£©¡¢¹ú¼Ê×ãÁªÊÀ½ç±­¡¢Å·ÖÞ±­µÈ¹ú¶È¶ÓÈüÊ£¬ÒÔ¼°NFL¡¢NBA¡¢F1µÈÃÀ¹úÖ÷Á÷ÌåÓýÈüÊ¡£Æä¼¼Êõ¼Ü¹¹Í¨¹ý¶àÓòÃûÌø×ª¶ã±Ü¹Ø±Õ£¬ÁùÌìǰ³õ´Î³öÏÖÔËÓªÖжϼ£Ïó£¬Óû§·´À¡ÍøÕ¾ÎÞ·¨½Ó¼û»òÁ÷ýÌå¼ÓÔØÒì³£¡£°£¼°¼ªÈøÊ¡Ð»ºÕÔúÒÁµÂÊо¯·½ÔÚÐж¯Öвé»ñ±Ê¼Ç±¾µçÄÔ¡¢ÖÇÄÜÊÖ»ú¡¢Ïֽ𼰶àÕÅÐÅÓþ¿¨¡£µ÷²éÏÔʾ£¬¸Ãƽ̨Óë°¢ÁªÇõÒ»¼Ò¿Õ¿Ç¹«Ë¾´æÔÚ¹ØÁª£¬ÉæÏÓ×Ô2010ÄêÆðͨ¹ý¸æ°×ÊÕÈëÏ´Ç®620ÍòÃÀÔª¼°20ÍòÃÀÔª¼ÓÃÜÇ®±Ò¡£Ä¿Ç°£¬Ô­ÊôÓÚStreameastµÄ80¸öÓòÃûÒÑ´ó²¿ÃųÁ¶¨ÏòÖÁACEµÄ¡°ºÏ·¨ÅÔ¹Û¡±ÍøÕ¾£¬µ«²¿ÃÅÓòÃûÈԿɽӼû£¬°µÊ¾¿ÉÄÜ´æÔÚδ²é·âÓòÃû»òÐÂÓòÃû×¢²á¡£


https://www.bleepingcomputer.com/news/security/streameast-the-largest-pirated-sports-platform-disrupted-by-police/


5. SaaS¾ÞÍ·WorkivaÔÚSalesforce¹¥»÷ºóÅû¶Êý¾Ýй¶


9ÔÂ3ÈÕ£¬Workiva×÷Ϊµ±ÏȵÄÔÆSaaS·þÎñÉÌ£¬×¨Ò»²ÆÕþ»ã±¨¡¢ºÏ¹æ¼°Éó¼ÆÊý¾ÝÖÎÀí£¬·þÎñ6305¼Ò¿Í»§£¬2024ÄêÔ¤¼ÆÓªÊÕ7.39ÒÚÃÀÔª¡£½üÈÕ£¬¸Ã¹«Ë¾´«µÝ¿Í»§³Æ£¬¹¥»÷Õßͨ¹ýµÚÈý·½CRMϵͳSalesforce·¸·¨»ñÈ¡²¿Ãſͻ§Êý¾Ý£¬Ô̺¬ÐÕÃû¡¢ÓÊÏä¡¢µç»°¼°Ö§³Ôì±Ö¤ÄÚÈÝ£¬µ«Workivaƽ̨Ö÷ÌâÊý¾ÝδÊܲ¨¼°¡£Õâ´ÎÊÂÎñÓëShinyHuntersÀÕË÷¼¯ÍŽüÆÚÕë¶ÔSalesforceÉú̬µÄ¹¥»÷¸ß¶È¹ØÁª¡£¸Ã¼¯ÍÅ×ÔËêÊׯðͨ¹ýÓïÒô´¹µö£¨vishing£©¼°OAuthÁîÅÆÀÄÓã¬ÉøÈë¶à¼ÒÆóÒµSalesforceÊ·ý£¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ£¬±¾´Î¹¥»÷õè¾¶Óë½üÆÚ¶àÆð´óÐÍ»ú¹¹Êý¾Ýй¶ģʽÀàËÆ¡£WorkivaÇ¿µ÷£¬ÆäCRM¹©¸øÉÌͨ¹ý¹ØÁªµÚÈý·½ÀûÓö³ö½Ó¼ûȨÏÞ£¬Í¹ÏÔ¹©¸øÁ´°²È«·çÏÕ¡£¹«Ë¾ÒÑÌáÐÑÊÜÓ°Ïì¿Í»§¾¯ÌèÓã²æÊ½´¹µö¹¥»÷£¬²¢³ÁÉê¹Ù·½¹µÍ¨Çþ·µÄΨһÐÔ£¬¾ø²»Í¨¹ý¶ÌÐÅ»òµç»°Ë÷Òª°²È«ÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/saas-giant-workiva-discloses-data-breach-after-salesforce-attack/


6. ºÚ¿ÍÀûÓÃеÄHexStrike-AI¹¤¾ß¼±¾çÀûÓÃn-day·ì϶


9ÔÂ3ÈÕ£¬ºÚ¿ÍÕý´ó¹æÄ£ÀûÓÃÃûΪHexStrike-AIµÄÐÂÐÍÈËΪÖÇÄܹ¥»÷¿ò¼Ü£¬¼Ó¿ìÐÂÅû¶n-day·ì϶µÄ±øÆ÷»¯¹ý³Ì¡£CheckPoint Research»ã±¨ÏÔʾ£¬¸Ã¿ò¼ÜÓë°µÍøÖÐÕë¶ÔCitrix·ì϶£¨ÈçCVE-2025-7775¡¢CVE-2025-7776£©µÄ¼±¾çÀûÓûÇ×êÇÓйØ¡£½ØÖÁ2025Äê9ÔÂ2ÈÕ£¬ÈÔÓнü8000¸ö¶ËµãÒ×ÊÜCVE-2025-7775¹¥»÷£¬½ÏǰһÖÜÏ÷¼õ2Íò¸ö£¬µ«·ì϶Åû¶Óë´ó¹æÄ£ÀûÓõŦ·ò´°¿ÚÒѼ±¾çËõ¶ÌÖÁÊýÓ×ʱ¡£HexStrike-AIÓÉÍøÂ簲ȫ×êÑÐÔ±Muhammad Osama¿ª·¢£¬Ô­ÎªºÏ·¨ºì¶Ó¹¤¾ß£¬Í¨¹ý¼¯³ÉAI´úÀí¿É×ÔÖ÷ÔËÐÐ150ÓàÖÖÍøÂ簲ȫ¹¤¾ß£¬ÊµÏÖÉøÈë²âÊÔÓë·ì϶·¢ÏÖµÄ×Ô¶¯»¯¡£Æä¿Í»§¶Ë¾ß±¸³ÁÊÔÂß¼­Ó븴ԭ´¦ÖÃÄÜÁ¦£¬¿É×Ô¶¯µ÷ÕûÅäÖÃÖ±ÖÁ²Ù×÷³É¹¦¡£¸Ã¹¤¾ß¿ªÔ´ºóѸ¿ì×ߺ죬GitHub»ñ1800ÐDZêÓ볬400´Îfork£¬È´Ò²Òý·¢ºÚ¿Í¹Ø×¢¡£¾ÝCheckPointÅû¶£¬ºÚ¿ÍÂÛ̳ÒѳöÏָù¤¾ßµÄ²¿Êð»áÉÌ£¬¹¥»÷ÕßÀûÓÃÆäÕë¶ÔCitrix NetScaler ADC¼°GatewayÁãÈÕ·ì϶£¬ÊµÏÖδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐУ¬²¢ÔÚÊÜϰȾÉ豸ֲÈëWebshell£¬Éõ´ó¹«¿ªÏúÊÛÊÜ¿ØÊ·ý¡£


https://www.bleepingcomputer.com/news/security/hackers-use-new-hexstrike-ai-tool-to-rapidly-exploit-n-day-flaws/