ºÚ¿ÍÔÚ°µÍøÐû²¼DriveSureµÄ320Íò¸öÓû§µÄÊý¾Ý£»£»£»£»£»£»£»¶à¸öÀÕË÷ÍÅ»ïÕë¶ÔESXiµÄÐéÄâ»úÖеÄÓ²Å̾ÙÐмÓÃÜ

Ðû²¼Ê±¼ä 2021-02-03

1.ºÚ¿ÍÔÚ°µÍøÐû²¼DriveSureµÄ320Íò¸öÓû§µÄÊý¾Ý

 

1.png

 

ºÚ¿ÍÔÚRaidforums°µÍøÂÛ̳ÉÏÐû²¼ÁË´ÓDriveSureÇÔÈ¡µÄ320Íò¸öÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£DriveSureÊÇÆû³µ¾­ÏúÉ̵ÄЧÀÍÌṩÉÌ£¬£¬£¬£¬£¬£¬Ö÷Òª´ÓÊÂÔ±¹¤ÅàѵÍýÏëºÍ¿Í»§Î¬»¤¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢IPµØµã¡¢Æû³µÖÆÔìÉ̺ÍÐͺš¢VINÂë¡¢Æû³µÐ§ÀͼͼºÍ¾­Ïú¼Í¼¡¢Ëð»µË÷ÅâºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÓÚ2020Äê12ÔÂ19ÈÕй¶ÁËÊý¾Ý£¬£¬£¬£¬£¬£¬¶øÑо¿Ö°Ô±ÓÚ1ÔÂ4ÈÕÖ®ºó²Å·¢Ã÷ÁË̻¶µÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£  


Ô­ÎÄÁ´½Ó£º

https://www.scmagazine.com/home/security-news/data-on-3-2-million-drivesure-users-exposed-on-hacking-forum/

 

2.»ªÊ¢¶ÙÖÝÉó¼ÆÊ¦°ì¹«ÊÒй¶160ÍòסÃñµÄСÎÒ˽¼ÒÐÅÏ¢

 

2.png

 

»ªÊ¢¶ÙÖÝÉó¼ÆÊ¦°ì¹«ÊÒ£¨SAO£©Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË160ÍòסÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£SAO³ÆºÚ¿ÍʹÓÃAccellionµÄÇå¾²Îļþ´«ÊäЧÀÍÖеÄÎó²îÌᳫ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2020Äê12ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬¶øÖ±µ½2021Äê1ÔÂ25ÈÕAccelion²ÅÏòSAOÈ·ÈÏÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ÓйØÃÀ¹ú¾ÍÒµÇå¾²²¿£¨ESD£©µÄʧҵÅâ³¥µÄÊý¾ÝÎļþй¶¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý°üÀ¨Ö°Ô±µÄÐÕÃû¡¢Éç»á°ü¹ÜºÅ»ò¼ÝʻִÕÕ¡¢ÒøÐÐÕʺźÍÒøÐÐõè¾¶±àºÅÒÔ¼°ÊÂÇéËùÔÚ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ò»Ð©»ªÊ¢¶ÙµØ·½Õþ¸®ºÍÆäËûÖÝ»ú¹¹µÄÎļþÒ²Êܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/data-breach-exposes-16-million-washington-unemployment-claims/

 

3.¶à¸öÀÕË÷ÍÅ»ïÕë¶ÔESXiµÄÐéÄâ»úÖеÄÓ²Å̾ÙÐмÓÃÜ

 

3.png

 

½üÆÚ£¬£¬£¬£¬£¬£¬¶à¸öÀÕË÷Èí¼þÍÅ»ïÕýÔÚʹÓÃVMWare ESXi²úÆ·ÖеÄÎó²î£¬£¬£¬£¬£¬£¬ÒÔ½ÓÊÜÆóÒµÇéÐÎÖеÄÐéÄâ»ú²¢¶ÔÆäÐéÄâÓ²Å̾ÙÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËESXiÖÐÓ°ÏìЧÀͶ¨Î»Ð­Ò飨SLP£©CVE-2019-5544ºÍCVE-2020-3992Îó²î£¬£¬£¬£¬£¬£¬ÆäÔÊÐí¶à¸öÐéÄâ»ú¹²ÏíͳһӲÅÌ´æ´¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÓÚÈ¥Äê10ÔÂÊ״η¢Ã÷£¬£¬£¬£¬£¬£¬ÓëRansomExxÍÅ»ïÓйØ£¬£¬£¬£¬£¬£¬×ÔÉϸöÔÂBabuk LockerÒ²ÌᳫÁËÀàËÆµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÍþвÇ鱨¹«Ë¾KELA³Æ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÈ¥Ä껹ÔÚ°µÍøÉϳöÊÛ¶ÔESXiʵÀýµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-gangs-are-abusing-vmware-esxi-exploits-to-encrypt-virtual-hard-disks/

 

4.Linux¶ñÒâÈí¼þKobalosÃé׼ȫÇòµÄ³¬µÈÅÌËã»ú

 

4.png


ESET·¢Ã÷Linux¶ñÒâÈí¼þKobalos£¬£¬£¬£¬£¬£¬ÕýÔÚÃé׼ȫÇòµÄ³¬µÈÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ÷ÒªÕë¶ÔѧÊõºÍÑо¿ÍøÂçÖеĸßÐÔÄÜÅÌËã»ú£¨HPC£©ºÍЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡SSHƾ֤¡£¡£¡£¡£¡£¡£¡£KobalosÓëÖÚ²î±ðµÄÊÇ£¬£¬£¬£¬£¬£¬Æä´úÂë¿âºÜС£¬£¬£¬£¬£¬£¬µ«×ã¹»ÖØ´ó£¬£¬£¬£¬£¬£¬×ãÒÔÓ°ÏìLinux¡¢BSDºÍSolaris²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬ÕâÖÖÅÓºéˮƽÔÚLinux¶ñÒâÈí¼þÖкÜÉÙ¼û¡£¡£¡£¡£¡£¡£¡£KobalosʵÖÊÉÏÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬£¬£¬Ò»µ©×°ÖÃÔÚ³¬µÈÅÌËã»úÉϾͻáÒþ²ØÔÚOpenSSHЧÀÍÆ÷¿ÉÖ´ÐÐÎļþÖУ¬£¬£¬£¬£¬£¬ÈôÊÇͨ¹ýÌØ¶¨µÄTCPÔ´¶Ë¿Ú¾ÙÐÐŲÓ㬣¬£¬£¬£¬£¬Ôò»á´¥·¢ºóÃÅ£¬£¬£¬£¬£¬£¬ÆäÄܹ»Í¨¹ýµ¥¸öÏÂÁÊÜѬȾµÄЧÀÍÆ÷ת»»ÎªC2¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/this-linux-malware-is-hijacking-supercomputers-across-the-globe/

 

5.Õþ¸®Íâ°üSercoѬȾBabuk£¬£¬£¬£¬£¬£¬»òÒÑй¶Áè¼Ý1TBÊý¾Ý

 

5.png

 

Ó¢¹úµÄ¿ç¹úÕþ¸®Íâ°üSercoѬȾÀÕË÷Èí¼þBabuk£¬£¬£¬£¬£¬£¬»òÒÑй¶Áè¼Ý1TBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£SercoÒÑÈ·ÈÏÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬³ÆÖ»Ó°ÏìÁËÆäÔÚÅ·ÖÞµÄÓªÒµ£¬£¬£¬£¬£¬£¬²¢Î´Í¸Â¶¹¥»÷µÄÓ°Ïì¹æÄ£ºÍÊê½ðÒªÇ󡣡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔòÉù³ÆÆäÔÚSercoµÄÍøÂçÖÐDZÔÚÁËԼĪÈýÖÜ£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÁè¼Ý1TBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬£¬£¬£¬¸Ã˵Ã÷ÌåÏÖÓйر±Ô¼ºÍ±ÈÀûʱ¾ü¶ÓµÈÏàÖúͬ°éµÄÎļþ¿ÉÄÜÒÑÔÚ¹¥»÷ÖÐй¶¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÏÖÔÚ»¹Î´Ðû²¼Èκα»µÁÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/global-government-outsourcer-serco/