ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ21ÖÜ
Ðû²¼Ê±¼ä 2021-05-24> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê05ÔÂ17ÈÕÖÁ05ÔÂ23ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î£»£»£»£»£»£»SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»£»Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»£»£»£»£»£»DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª£»£»£»£»£»£»Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»£»£»£»£»£»NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ£»£»£»£»£»£»UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Microsoft Windows JETÊý¾Ý¿âÒýÇæÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î
Microsoft Windows JETÊý¾Ý¿âÒýÇæ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-594/
2.Pulse Connect Secure CVE-2021-22908»º³åÇøÒç³öÎó²î
Pulse Connect Secureä¯ÀÀSMB¹²Ïí±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800
3.SolarWinds Orion Job Scheduler JobRouterService²»×¼È·ÊÚȨ´úÂëÖ´ÐÐÎó²î
SolarWinds Orion Job Scheduler JobRouterService±£´æ²»×¼È·ÊÚȨÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-605/
4.Cisco DNA Space CVE-2021-1559 OSÏÂÁîÖ´ÐÐÎó²î
Cisco DNA Space±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnasp-conn-cmdinj-HOj4YV5n
5.Ubiquiti Networks EdgeRouter²»×¼È·Ö¤ÊéУÑéí§Òâ´úÂëÖ´ÐÐÎó²î
Ubiquiti Networks EdgeRouter HTTPSÏÂÔØ¹Ì¼þ±£´æÖ¤ÊéУÑéÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-601/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti£¬£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª
°®¶ûÀ¼µÄÒ½ÁÆÐ§ÀÍ»ú¹¹HSEÌåÏÖ£¬£¬£¬£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔÚ·¢Ã÷¹¥»÷ºó£¬£¬£¬£¬ÒÑÓÚÉÏÖÜÎ幨±ÕÁËËùÓÐITϵͳ¡£¡£¡£¡£¡£ContiÍÅ»ïÉù³ÆÒѾ½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬£¬£¬£¬ÔÚ´Ëʱ´ú£¬£¬£¬£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬£¬£¬£¬°üÀ¨»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ÌõÔ¼¡¢²ÆÎñ±¨±íºÍÈËΪµ¥µÈ¡£¡£¡£¡£¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎÅÐû²¼»áÉÏÌåÏÖ£¬£¬£¬£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/
2¡¢DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª
DarkSideÊÇÒ»¸öÀÕË÷Èí¼þЧÀÍÆ÷ÍŻRaaS£©£¬£¬£¬£¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¡£¡£¡£¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕÐû²¼ÉùÃ÷³Æ£¬£¬£¬£¬ÓÉÓÚÖ´·¨Ðж¯£¬£¬£¬£¬ËûÃÇÏÖÔÚÒѾÎÞ·¨Í¨¹ýSSH»á¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶Ð§ÀÍÆ÷ºÍCDNЧÀÍÆ÷£¬£¬£¬£¬ÒÔ¼°Ö÷»ú½çÃæ¡£¡£¡£¡£¡£Òò´Ë½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬£¬£¬£¬²¢ÔÊÐíÔÚ2021Äê5ÔÂ23ÈÕ֮ǰËÍ»¹ËùÓÐδ³¥Õ®Îñ¡£¡£¡£¡£¡£¸ÃÉùÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬£¬£¬£¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime
3¡¢Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ
¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷еİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£¡£¡£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ£¬£¬£¬£¬¾ßÓÐx64Ä£¿£¿£¿£¿£¿é£¬£¬£¬£¬¿ÉÒÔÓÕÆÊܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬£¬£¬£¬»¹Ê¹ÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆÊܺ¦ÕßÏÂÔØÒÆ¶¯Ó¦ÓóÌÐò¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄ½¹µã×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÏÂÁîµÄºóÃÅ£¬£¬£¬£¬Ö»Óе±Æä¼ì²âµ½ÒѾÅþÁ¬µ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬£¬£¬£¬ºóÃŲŻáÆô¶¯¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html
4¡¢NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ
NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬£¬£¬£¬±È2020ÄêͬÆÚÔöÌíÁË31£¥£¬£¬£¬£¬×î´óΪ480 Gbps£¬£¬£¬£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬£¬£¬£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬£¬£¬£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬£¬£¬£¬ÔÚÏßЧÀÍÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/asert/beat-goes
5¡¢UptycsÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps
UptycsÍþвÑо¿ÍŶÓÅû¶ÓëKeksecÍÅ»ïÓйصÄн©Ê¬ÍøÂçSimps¡£¡£¡£¡£¡£ËüʹÓÃÎïÁªÍø£¨IoT£©½Úµã¶ÔÓÎÏ·ºÍÆäËûÄ¿µÄ¾ÙÐÐÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬£¬£¬£¬ÓÚ2021Äê5ÔµĵÚÒ»Öܱ»·¢Ã÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬£¬¹¥»÷Õßͨ¹ýWgetÀ´Ê¹ÓÃshell¾ç±¾ºÍGafgyt£¨Keksec×îÇàíùµÄ¹¤¾ßÖ®Ò»£©Îª²î±ðµÄ»ùÓÚLinuxµÄϵͳװÖÃSimps payload¡£¡£¡£¡£¡£Æ¾Ö¤Ò»Ìõ°üÀ¨Gafgyt¶ñÒâÈí¼þÑù±¾µÄDiscordÐÂÎÅ£¬£¬£¬£¬Ñо¿Ö°Ô±ÍƶϸöñÒâÈí¼þÓëKeksecÍÅ»ïÓйء£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.uptycs.com/blog/discovery-of-simps-botnet-leads-ties-to-keksec-group