˼¿ÆÐû²¼2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ£»£»£»ÃÀ¹úÒÉËÆÔ⵽ʷÉÏ×î´ó¹æÄ£DDoS¹¥»÷

Ðû²¼Ê±¼ä 2020-06-17

1.˼¿ÆÐû²¼2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆÐû²¼ÁË2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ¡£¡£¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬ £¬£¬£¬µç×ÓÓʼþÈÔÈ»ÊǶñÒⲡ¶¾×îÖ÷ÒªµÄÈö²¥Ç°ÑÔ£¬ £¬£¬£¬¶øÕë¶ÔÔ¶³Ì×ÀÃæÐ§ÀÍ£¨RDS£©ÒÔ¼°CitrixºÍPulse VPN×°±¸µÄ¹¥»÷ÓÐËùÔöÌí¡£¡£¡£¡£¡£¡£¡£ÕâÒ»¼¾¶ÈºÚ¿ÍµÄÖØµãÄ¿µÄΪҽÁƱ£½¡ºÍ¿Æ¼¼ÐÐÒµ£¬ £¬£¬£¬ÓëÉÏÒ»¼¾¶ÈµÄ½ðÈÚЧÀͺÍÕþ¸®²¿·ÖÓÐËù²î±ð¡£¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þÊǴ˼¾¶È×îÖ÷ÒªµÄ¹¥»÷·½·¨£¬ £¬£¬£¬¶øRyukÒѾ­Ò»Á¬Ëĸö¼¾¶ÈÔÚÓ¦¼±ÏìÓ¦ÖÐÕ¼ÓÐÁËÍþвÁìÓòµÄÖ÷µ¼Ö°Î»¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/06/CTIR-trends-q3-2020.html


2.AT&TµÈ30¼ÒÃÀ¹ú¹«Ë¾ÒÉËÆÔâµ½´ó¹æÄ£DDoS¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


6ÔÂ15ÈÕÃÀ¹úÒÉËÆÔâµ½ÁËÆäÀúÊ·ÉÏ×î´óµÄDDoS¹¥»÷£¬ £¬£¬£¬Ó°ÏìÁËÃÀ¹ú¸÷µØµÄµçÐźÍÔÚÏßЧÀÍ£¬ £¬£¬£¬²¢µ¼Ö´ó¹æÄ£¶Ïµç¡£¡£¡£¡£¡£¡£¡£¾ÝÍøÕ¾Downdetectorͳ¼Æ£¬ £¬£¬£¬´Ë´ÎÊÜÓ°ÏìµÄ¹«Ë¾°üÀ¨T-Mobile¡¢Metro¡¢Verizon¡¢AT&T¡¢Sprint¡¢Consumer Cellular¡¢US Cellular¡¢Spectrum¡¢Comcast¡¢CenturyLink¡¢Cox¡¢Facebook¡¢Instagram¡¢SnapchatºÍTwitterµÈ¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬ £¬£¬£¬Å¦Ô¼¡¢·ðÂÞÀï´ï¡¢µÂ¿ËÈøË¹ÖÝ¡¢ÇÇÖÎÑÇÖݺͼÓÀû¸£ÄáÑÇÖÝÒÔ¼°ÆäËûÖݶ¼±¬·¢Á˶ϵ硣¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬Ã»ÓÐÒ»¼Ò¹«Ë¾Ú¹ÊÍÍøÂçÖÐÖ¹µÄÔµ¹ÊÔ­ÓÉ£¬ £¬£¬£¬ÊÖÒÕÖ°Ô±¾ùÍÆ²â´Ë´ÎÊÂÎñΪDDoS¹¥»÷µ¼Ö£¬ £¬£¬£¬²¢Ðû²¼ÁËͼƬ֤¾Ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.geekdup.net/2020/06/16/largest-ddos-attack-in-united-states-history-might-have-happened-yesterday/



3.ºÚ¿Íð³ą̈Íå¼²¿ØÖÐÐÄ£¬ £¬£¬£¬Ö¼ÔÚÇÔÈ¡Õþ¸®Ç鱨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÍøÂçÇå¾²¹«Ë¾ElevenPathsÌåÏÖ£¬ £¬£¬£¬ºÚ¿Í×éÖ¯ÕýÔÚð³ą̈Íå¼²¿ØÖÐÐĵÄÖÎÀíÖ°Ô±£¬ £¬£¬£¬Í¨¹ý·¢ËÍÈ«ÐıàдµÄ´¹ÂÚÓʼþÊÔͼÇÔÈ¡Õþ¸®Ç鱨¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯VendettaÔÚ5Ô³õ×îÏÈÏǫ̀ÍåijЩÓû§·¢Ë͵ç×ÓÓʼþ£¬ £¬£¬£¬²¢±Þ²ßËûÃǾÙÐÐеĹÚ×´²¡¶¾¼ì²â¡£¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÓʼþÖи½´øÁËÒ»¸öÔ¶³ÌºÚ¿Í¹¤¾ß£¬ £¬£¬£¬¿ÉÒÔÇÔÈ¡µÇ¼ƾ֤²¢Ð®ÖÆÍøÂçÉãÏñÍ·¡£¡£¡£¡£¡£¡£¡£Miguel ?ngel de Castro Sim¨®nÌåÏÖ£¬ £¬£¬£¬¸ÃºÚ¿Í¹¤¾ßµÄÌØÕ÷Åú×¢ËûÃÇÕýÔÚËѼ¯Ç鱨£¬ £¬£¬£¬Ö÷ÒªÊÇÕþ¸®Ç鱨¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/vendetta-taiwan-coronavirus-telefonica/


4.Qbot¹¥»÷ÊýÊ®¼ÒÃÀ¹ú½ðÈÚ»ú¹¹²¢ÇÔÈ¡Æä¿Í»§Æ¾Ö¤


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


F5ʵÑéÊÒµÄÑо¿Ö°Ô±·¢Ã÷ºÚ¿ÍʹÓöñÒâÈí¼þQbot¶ÔÊýÊ®¼ÒÃÀ¹ú½ðÈÚ»ú¹¹Ìᳫ¹¥»÷£¬ £¬£¬£¬²¢ÇÔÈ¡ÁËÆä¿Í»§µÄƾ֤ºÍ½ðÈÚÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì½ðÈÚ»ú¹¹°üÀ¨Ä¦¸ù´óͨ¡¢»¨ÆìÒøÐС¢ÃÀ¹úÒøÐС¢ Citizens¡¢Capital One¡¢ ¸»¹úÒøÐкÍFirstMeritÒøÐеȡ£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¶ñÒâÈí¼þÆÊÎöʦDoron VoolfÆÊÎö£¬ £¬£¬£¬´Ë´ÎʹÓõÄQbotµÄ¹¥»÷»î¶¯×ܹ²Ãé×¼ÁË36¸öÃÀ¹úµÄ½ðÈÚ»ú¹¹£¬ £¬£¬£¬ÁíÍâÉÐÓмÓÄôóºÍºÉÀ¼µÄÁ½¼ÒÒøÐС£¡£¡£¡£¡£¡£¡£Voolf˵£¬ £¬£¬£¬Ïà±È֮ǰµÄ°æ±¾£¬ £¬£¬£¬´Ë´ÎµÄQbotÐÂÔöÁËеķâ×°²ã£¬ £¬£¬£¬¿ÉÒÔ¼ÓÃܲ¢Òþ²Ø´úÂëÀ´¶ã¹ýɨÃè³ÌÐò£¬ £¬£¬£¬Ëü»¹ÔöÌíÁË·´ÐéÄâ»úÊÖÒÕ£¬ £¬£¬£¬¿É×ÊÖúÆä¶ã¹ýɱ¶¾Èí¼þ¼ì²â¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-bank-customers-targeted-in-ongoing-qbot-campaign/


5.ÍâÂô¹«Ë¾FoodoraÊý¾Ýй¶£¬ £¬£¬£¬Ó°Ïì14¸ö¹ú¼ÒµÄÓû§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÔÚÏßʳÎïÅäËÍЧÀÍDelivery HeroÒÑÈ·ÈÏÆä¹«Ë¾Foodora±¬·¢ÁËÊý¾Ýй¶£¬ £¬£¬£¬Ó°ÏìÁË14¸ö¹ú¼ÒµÄÓû§¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ¹²Ð¹Â¶ÁË72.7Íò¸ö¿Í»§µÄÕÊ»§ÏêϸÐÅÏ¢£¬ £¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨Ãû³Æ¡¢µØµã¡¢µç»°ºÅÂëºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü´Ë´ÎÊÂÎñÖв¢Ã»ÓвÆÎñÊý¾Ý×ß©£¬ £¬£¬£¬µ«¿Í»§ÏÕЩ׼ȷµ½Ã׵ĵØÀíλÖÃÔâµ½ÁËй¶¡£¡£¡£¡£¡£¡£¡£Delivery HeroµÄ½²»°ÈË˵£¬ £¬£¬£¬Ð¹Â¶µÄÐÅÏ¢¿ÉÒÔ×·Ëݵ½2016Ä꣬ £¬£¬£¬À´×Ô°Ä´óÀûÑÇ¡¢°ÂµØÀû¡¢¼ÓÄô󡢷¨¹ú¡¢µÂ¹ú¡¢Ïã¸Û¡¢Òâ´óÀû¡¢ÁÐÖ§¶ØÊ¿µÇ¡¢ºÉÀ¼¡¢Å²Íþ¡¢ÐÂ¼ÓÆÂ¡¢Î÷°àÑÀºÍ°¢À­²®ÁªºÏÇõ³¤¹úµÄFoodoraÓû§¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/foodora-data-breach/


6.ARM CPUÐÂÎó²îΪSpectre±äÌ壬 £¬£¬£¬¿Éµ¼Ö²àÐŵÀ¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


GoogleµÄSafeSideС×é·¢Ã÷ARM CPU±£´æÐµÄͶÆõÖ´ÐÐÎó²î£¬ £¬£¬£¬ÎªSpectre±äÌ壬 £¬£¬£¬¿Éµ¼Ö²àÐŵÀ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÙÔÚARM´¦Öóͷ£Æ÷µÄArmv8-A£¨Cortex-A£©CPUϵͳ½á¹¹Öз¢Ã÷ÁËÒ»¸öÃûΪֱÏßÍÆ²â£¨ Straight-Line Speculation £¬ £¬£¬£¬SLS£© µÄÐÂÎó²î£¬ £¬£¬£¬±»×·×ÙΪCVE-2020-13844¡£¡£¡£¡£¡£¡£¡£SLS±»ÒÔΪÊÇSpectreÎó²îµÄ±äÌ壬 £¬£¬£¬µ«¶þÕߵĹ¥»÷¹æÄ£ÂÔÓвî±ð£¬ £¬£¬£¬SLSÎó²î½öÓ°ÏìArm Armv-A´¦Öóͷ£Æ÷£¬ £¬£¬£¬¶øSpectreÎó²îÓ°ÏìËùÓÐÖ÷ÒªÐ¾Æ¬ÖÆÔìÉ̵ÄCPU¡£¡£¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬ £¬£¬£¬¸ÃÎó²î»¹Ã»ÓÐÔÚҰʹÓᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.phoronix.com/scan.php?page=news_item&px=Arm-Straight-Line-Speculation