CyberX9³ÆÓ¡¶È֤ȯ»ú¹¹CDSL 4390ÍòÓû§ÐÅϢй¶
Ðû²¼Ê±¼ä 2021-11-11MediaMarktÔâµ½Hive¹¥»÷²¢±»ÀÕË÷2.4ÒÚÃÀÔª
MediaMarktÔÚÖÜÈÕÍíÉÏÖÁÖÜÒ»ÔçÉÏÔâµ½À´×ÔHiveµÄÀÕË÷¹¥»÷£¬²¢±»ÒªÇóÖ§¸¶2.4ÒÚÃÀÔª¡£MediaMarktÊÇÅ·ÖÞ×î´óµÄµç×Ó²úÎïÁãÊÛÉÌ£¬ÔÚ13¸ö¹ú¼ÒÓµÓÐ1000¶à¼ÒÉ̵꣬×ÜÏúÊÛ¶îΪ208ÒÚÅ·Ôª¡£´Ë´Î¹¥»÷Ö÷ÒªÓ°ÏìÁËλÓڵ¹úºÍºÉÀ¼µÄÉ̵꣬ÊÂÇéÈËÔ±ÎÞ·¨½ÓÊÜÐÅÓÿ¨¸¶¿î»ò´òÓ¡Êվݣ¬µ«ÍøÉÏÉ̵êûÓÐÊÕµ½Ó°Ïì¡£¾ÝÄÚ²¿ÈËÔ±³ÆÓÐ3100̨·þÎñÆ÷Òѱ»¼ÓÃÜ£¬Ä¿Ç°ÉÐÎÞ·¨È·¶¨ÕâÖÖ˵·¨µÄ׼ȷÐÔ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mediamarkt-hit-by-hive-ransomware-initial-240-million-ransom/
΢ÈíÐû²¼11Ô¸üУ¬ÐÞ¸´6¸ö0dayÔÚÄÚµÄ55¸ö©¶´
΢ÈíÔÚ11ÔÂ9ÈÕÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´ÁË55¸ö©¶´¡£´Ë´ÎÐÞ¸´ÁË6¸ö0 day£¬°üÂÞExcelÖÐÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2021-42292£©¡¢Exchange ServerÖÐRCE£¨CVE-2021-42321£©£¬RDPÖÐÐÅϢй¶©¶´£¨CVE-2021-38631ºÍCVE-2021-41371£©£¬ÒÔ¼°3DÖмì²ìÆ÷RCE£¨CVE-2021-43208ºÍCVE-2021-43209£©¡£ÆäÖУ¬CVE-2021-42292ºÍCVE-2021-42321Òѱ»ÓÃÓÚ¶ñÒâ¹¥»÷»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2021-patch-tuesday-fixes-6-zero-days-55-flaws/
CyberX9³ÆÓ¡¶È֤ȯ»ú¹¹CDSL 4390ÍòÓû§ÐÅϢй¶
Äþ¾²ÍŶÓCyberX9ÔÚ11ÔÂ7ÈÕÅû¶ӡ¶È֤ȯÍйܻú¹¹CDSLµÄ4390ÍòÓû§ÐÅϢй¶¡£ÔçÔÚʮԳõ£¬Ñо¿ÈËÔ±·¢ÏÖCDSL´æÔÚÑÏÖØµÄ©¶´£¬¿Éй¶4390ÍòͶ×ÊÕߵĸöÈËÐÅÏ¢ºÍ²ÆÕþÊý¾Ý¡£10ÔÂ26ÈÕ£¬Â©¶´Òѱ»ÐÞ¸´¡£µ«ÊÇ£¬Ñо¿ÈËÔ±ÓÚ10ÔÂ29ÈÕ·¢ÏÖеIJ¹¶¡¿ÉÒÔÇáÒ׵ر»Èƹý£¬ÒÀÈ»¿ÉÒÔй¶4390ÍòÈ˵ÄÊý¾Ý¡£´Ë´Îй¶µÄÐÅÏ¢¿ÉÒÔ×·Ëݵ½2005Äê×óÓÒ×¢²áµÄÓû§£¬ÓÉÓÚ´ËÀàÊý¾ÝµÄÃô¸Ð¶È½Ï¸ß£¬Èç¹ûÂäÈë¹¥»÷ÕßÊÖÖжÔÓû§À´Ëµ¿ÉÄÜÊÇÖÂÃüµÄ¡£
ÔÎÄÁ´½Ó£º
https://www.cyberx9.com/cdsl-data-exposed-again-blog
ÂÞÂíÄáÑÇÕþ¸®´þ²¶REvilÍÅ»ïÔø¹¥»÷KaseyaµÄ³ÉÔ±
ÂÞÂíÄáÑÇÖ´·¨²¿ÃÅÔÚ11ÔÂ8ÈÕÐû²¼ÐÂΟ壬³ÆËûÃÇÔÚ11ÔÂ4ÈÕ´þ²¶ÁËÁ½ÃûÀÕË÷ÍÅ»ïREvilÁ¥Êô×éÖ¯µÄ³ÉÔ±¡£´Ë´ÎÐж¯ÃûΪGoldDust£¬ÔøÓÚ2ÔÂÔÚ¿ÆÍþÌØºÍº«¹ú´þ²¶ÁËÈý¸öREvilÍÅ»ïµÄ³ÉÔ±ºÍÁ½¸öÓëGandCrabÓйØÁªµÄÏÓÒÉÈË¡£´Ë´ÎÐж¯´þ²¶ÁËÒ»¸ö22ËêµÄÎÚ¿ËÀ¼ÄêÇáÈËYaroslav Vasinskyi£¬ËûÔÚ½ñÄê7Ô¹¥»÷ÁË·ðÂÞÀï´ïÖݵÄÈí¼þ¹«Ë¾Kaseya£¬Ó°ÏìÁ˶à´ï1500¸öÏÂÓι«Ë¾¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/suspected-revil-ransomware-affiliates.html
F5Ðû²¼¹ØÓÚÊý×Ö»¯×ªÐÍËùÃæÁÙΣÏյķÖÎö³ÂËß
11ÔÂ5ÈÕ£¬F5Ðû²¼Á˹ØÓÚÊý×Ö»¯×ªÐÍËùÃæÁÙΣÏյķÖÎö³ÂËß¡£×¨×¢ÓÚÊý×ÖתÐ͵Ä×éÖ¯ÐèÒª½«²îÒìµÄÓ¦Ó÷¨Ê½¡¢ÏµÍ³ºÍ·þÎñÆ´½Ó³ÉÎÞ·ìµÄÊý×ÖÌåÑ飬Ҳ¾ÍÊÇ˵×éÖ¯ÒѾ½ÓÊÜÁËAPI¡£Ñо¿ÈËÔ±Ô¤¼Æ£¬Èç½ñ¹«¹²ºÍ˽ÓÐAPIµÄ×ÜÁ¿½Ó½ü2ÒÚ£¬µ½2031ÄêÕâÒ»Êý×Ö¿ÉÄܻᵽ´ïÊýÊ®ÒÚ¡£¶øAPIµÄÀ©ÕŸøÔËÓªºÍÄþ¾²·½Ãæ´øÀ´ÁËÌôÕ½£¬ÀýÈçËæ×ÅAPIÊýÁ¿ºÍÓ¦ÓÃÅÓ´óÐÔµÄÔö¼Ó£¬×·×ÙAPIµÄλÖñäµÃÀ§ÄÑ£»ÒÔ¼°APIµÄƵ·±¸üлᵼÖ°汾ºÍÎĵµ·ºÆðÎÊÌâµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.f5.com/company/blog/digital-transformation-danger-ahead-api-sprawl
KasperskyÐû²¼2021ÄêQ3 DDoS¹¥»÷µÄ·ÖÎö³ÂËß
KasperskyÔÚ11ÔÂ8ÈÕÐû²¼ÁË2021ÄêQ3 DDoS¹¥»÷µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÓëÉÏÒ»¼¾¶ÈºÍÈ¥ÄêÏà±È£¬µÚÈý¼¾¶ÈµÄ¹¥»÷ÊýÁ¿ÏÔÖøÔö¼Ó¡£ÆäÖÐÃÀ¹úÔâµ½µÄDDoS¹¥»÷×î¶à£¨40.80%£©£¬Æä´ÎÊÇÖйúÏã¸Û£¨15.07%£©ºÍÖйú(7.74%)¡£µÚÈý¼¾¶Èµ¥ÈÕµÄDDoS¹¥»÷´ÎÊý´òÆÆÁË֮ǰµÄËùÓмǼ£º8ÔÂ18ÈÕÓÐ8825´Î¹¥»÷£¬8ÔÂ21ÈÕºÍ22Ò²ÓÐÁè¼Ý5000´Î¡£´ó¶àÊýDDoS¹¥»÷½ÓÄÉÁËSYN·ººéµÄÐÎʽ£¬¶ø´ó¶àÊý½©Ê¬ÍøÂçC&C·þÎñÆ÷λÓÚÃÀ¹ú£¨43.44%£©¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/ddos-attacks-in-q3-2021/104796/