¶íÂÞ˹Áª°î´¢±¸ÒøÐÐSberbankÔâµ½´ó¹æÄ£DDoS¹¥»÷
Ðû²¼Ê±¼ä 2022-05-23¾ÝýÌå5ÔÂ20ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Áª°î´¢±¸ÒøÐÐSberbankÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£¡£SberbankÊǶíÂÞ˹×î´óµÄ½ðÈÚ»ú¹¹£¬£¬£¬£¬£¬£¬Ò²ÊÇÅ·ÖÞµÚÈý´ó½ðÈÚ»ú¹¹£¬£¬£¬£¬£¬£¬×Ü×ʲúÁè¼Ý5700ÒÚÃÀÔª¡£¡£¹¥»÷±¬·¢ÔÚ5ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬SberbankÌåÏÖËûÃÇÒÑÀֳɵÖÓù¸ß´ï450 GB/ÃëµÄ¹¥»÷¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¶ñÒâÁ÷Á¿À´×ÔÒ»¸ö½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Æä°üÀ¨ÁËλÓÚÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾ºÍÖйų́ÍåµÄ27000̨±»Ñ¬È¾µÄ×°±¸£¬£¬£¬£¬£¬£¬ÆäÖÐÐí¶à¹¥»÷ʹÓÃÁËÔÚÏßÁ÷ýÌåºÍÓ°Ï·ÔºÍøÕ¾µÄÁ÷Á¿¡£¡£¸ÃÒøÐгƣ¬£¬£¬£¬£¬£¬×Ô2Ô·ݳåÍ»ÒÔÀ´£¬£¬£¬£¬£¬£¬ÕâÖÖ¹¥»÷´ÓδÏ÷Èõ¡£¡£
https://www.bleepingcomputer.com/news/security/russian-sberbank-says-it-s-facing-massive-waves-of-ddos-attacks/
2¡¢Ã½Ì幫˾ÈÕ¾¼¯ÍŵÄÐÂ¼ÓÆÂ·Ö²¿³ÆÆäÔâµ½ÀÕË÷¹¥»÷
¾Ý5ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÈÕ¾¼¯ÍÅÐÂ¼ÓÆÂ·Ö²¿³ÆÆäһ̨ЧÀÍÆ÷Ôâµ½ÁËÀÕË÷¹¥»÷¡£¡£ÈÕ¾£¨Nikkey£©ÊÇÈÕ±¾µÄýÌ幫˾£¬£¬£¬£¬£¬£¬×¨×¢ÓÚÉÌÒµºÍ½ðÈÚÐÐÒµ£¬£¬£¬£¬£¬£¬ËüÊÇÈ«Çò×î´óµÄ²Æ¾±¨Ö½¡£¡£¸Ã¹«Ë¾ÔÚ5ÔÂ13ÈÕÊ״μì²âµ½ÆäЧÀÍÆ÷Ôâµ½ÁËδ¾ÊÚȨµÄ»á¼û£¬£¬£¬£¬£¬£¬Ö®ºóÁ¬Ã¦Õö¿ªÁËÄÚ²¿ÊӲ죬£¬£¬£¬£¬£¬²¢¹Ø±ÕÁËÊÜÓ°ÏìµÄЧÀÍÆ÷¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄЧÀÍÆ÷¿ÉÄܰüÀ¨¿Í»§Êý¾Ý£¬£¬£¬£¬£¬£¬ËûÃÇÏÖÔÚÕýÔÚÈ·¶¨¹¥»÷µÄÐÔ×Ӻ͹æÄ££¬£¬£¬£¬£¬£¬×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬²¢Î´·¢Ã÷Êý¾Ýй¶µÄ¼£Ï󡣡£
https://securityaffairs.co/wordpress/131533/data-breach/nikkei-data-breach.html
3¡¢CiscoÐÞ¸´IOS XRÈí¼þÒѱ»Ê¹ÓõÄÎó²îCVE-2022-20821
5ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäIOS XRÈí¼þÖеÄÒ»¸öÒѱ»Ê¹ÓõÄÎó²î¡£¡£¸ÃÎó²î×·×ÙΪCVE-2022-20821£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ¿µ½¡¼ì²éRPMÔÚ¼¤»îʱĬÈÏ·¿ªTCP¶Ë¿Ú6379µ¼Öµģ¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÅþÁ¬µ½¿ª·Å¶Ë¿ÚÉϵÄRedisʵÀýÀ´Ê¹ÓôËÎó²î¡£¡£CiscoÔÚͨ¸æÖгƣ¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉʵÏÖRedisÄÚ´æÊý¾Ý¿âдÈ룬£¬£¬£¬£¬£¬½«í§ÒâÎļþдÈëÈÝÆ÷Îļþϵͳ£¬£¬£¬£¬£¬£¬²¢¼ìË÷ÓйØRedisÊý¾Ý¿âµÄÐÅÏ¢¡£¡£¸Ã¹«Ë¾ÌåÏÖÔÚ±¾ÔµÄÔçЩʱ¼ä·¢Ã÷ÓÐÈËÊÔͼʹÓÃËü£¬£¬£¬£¬£¬£¬Ç¿ÁÒ½¨Òé¿Í»§ÐÞ¸´´ËÎó²î¡£¡£
https://thehackernews.com/2022/05/cisco-issues-patches-for-new-ios-xr.html
4¡¢Ö¥¼Ó¸ç¹«Á¢Ñ§Ð£µÄ¹©Ó¦ÉÌÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬50ÍòѧÉúµÄÐÅϢй¶
ýÌå5ÔÂ21Èճƣ¬£¬£¬£¬£¬£¬Ö¥¼Ó¸ç495448¸öѧÉúºÍ56138¸öÔ±¹¤µÄÊý¾ÝÒѾй¶¡£¡£Ð¹Â¶ÊÂÎñÔ´ÓÚÖ¥¼Ó¸ç¹«Á¢Ñ§Ð££¨CPS£©µÄ¹©Ó¦ÉÌBattelle for KidsÔÚ12ÔÂÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäѧУϵͳÖеĴ洢Êý¾Ýй¶¡£¡£¸Ã¹«Ë¾Óë267¸öѧУϵͳÏàÖú£¬£¬£¬£¬£¬£¬ÏîÄ¿Éæ¼°Áè¼Ý280ÍòѧÉú¡£¡£´Ë´Îй¶ÁË2015ÖÁ2019ѧÄêµÄÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨Ñ§ÉúµÄСÎÒ˽¼ÒÐÅÏ¢ºÍ·ÖÊý£¬£¬£¬£¬£¬£¬ÒÔ¼°Ô±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢µÈ¡£¡£Ö»¹ÜCPSÒªÇó¸Ã¹«Ë¾Á¬Ã¦Í¨ÖªÊý¾Ýй¶ÇéÐΣ¬£¬£¬£¬£¬£¬µ«ÆäÔÚÁè¼Ý4¸öÔºó²ÅÅû¶ÁËÎ¥¹æÐÐΪ¡£¡£
https://www.bleepingcomputer.com/news/security/ransomware-attack-exposes-data-of-500-000-chicago-students/
5¡¢AhnLab·¢Ã÷LazarusÕë¶Ôº«¹ú·Ö·¢ºóÃÅNukeSpedµÄ»î¶¯
5ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬AhnLabÐû²¼±¨¸æÅû¶ÁËLazarusÍÅ»ïÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯¡£¡£´Ë´Î»î¶¯ÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËVMware HorizonЧÀÍÆ÷ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îLog4J£¨CVE-2021-44228£©À´×¢ÈëºóÃÅNukeSped¡£¡£AhnLab·¢Ã÷¸ÃºóÃŵÄбäÌåÊÇÓÃC++±àдµÄ£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃRC4¼ÓÃÜÓëC2µÄͨѶ£¨ÒÔǰʹÓÃXOR£©¡£¡£¸Ã±äÌåÐÂÔöÁËÁ½¸öÄ£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬Ò»¸öÓÃÓÚת´¢USBÄÚÈÝ£¬£¬£¬£¬£¬£¬ÁíÒ»¸ö»á¼ûÍøÂçÉãÏñÍ·×°±¸¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬NukeSped»¹±»ÓÃÓÚ×°ÖÃÌØÁíÍâÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÍøÂçä¯ÀÀÆ÷ÖеÄÐÅÏ¢¡£¡£
https://asec.ahnlab.com/en/34461/
6¡¢Ñо¿ÍŶӷ¢Ã÷Rust¹©Ó¦Á´¹¥»÷»î¶¯CrateDepression
SentinelOneÔÚ5ÔÂ19ÈÕÐû²¼±¨¸æ³Æ£¬£¬£¬£¬£¬£¬·¢Ã÷ÁËÕë¶ÔRust¿ª·¢ÉçÇøµÄ¹©Ó¦Á´¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬²¢³ÆÖ®Îª¡°CrateDepression¡±¡£¡£5ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬RustÐû²¼Í¨¸æÌåÏÖÔÚRust´æ´¢¿âÖз¢Ã÷ÁËÒ»¸ö¶ñÒâcrate¡° rustdecimal¡±£¬£¬£¬£¬£¬£¬ËüÊÇÄ£ÄâÁËÕæÕýµÄ°ü¡°rust_decimal¡±¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬£¬£¬¶ñÒâÒÀÀµÏî»á¼ì²éÇéÐαäÁ¿£¬£¬£¬£¬£¬£¬ÕâÅú×¢Ëü¶ÔGitLabÒ»Á¬¼¯³É(CI)¹ÜµÀÓÐÌØÊâÐËȤ£¬£¬£¬£¬£¬£¬±»Ñ¬È¾µÄCI¹ÜµÀÌṩµÚ¶þ½×¶ÎµÄpayload¡£¡£¶ñÒâcrateÓÚ3ÔÂ25ÈÕÊ×´ÎÍÆËÍ£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑÔÚ´æ´¢¿âÖÐÓÀÊÀɾ³ý£¬£¬£¬£¬£¬£¬ÏÂÔØÁ¿²»µ½500´Î¡£¡£
https://www.sentinelone.com/labs/cratedepression-rust-supply-chain-attack-infects-cloud-ci-pipelines-with-go-malware/


¾©¹«Íø°²±¸11010802024551ºÅ