˼¿ÆÐû²¼2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ£»£»£»£»ÃÀ¹úÒÉËÆÔ⵽ʷÉÏ×î´ó¹æÄ£DDoS¹¥»÷

Ðû²¼Ê±¼ä 2020-06-17

1.˼¿ÆÐû²¼2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


˼¿ÆÐû²¼ÁË2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷ £¬£¬£¬£¬£¬£¬£¬µç×ÓÓʼþÈÔÈ»ÊǶñÒⲡ¶¾×îÖ÷ÒªµÄÈö²¥Ç°ÑÔ £¬£¬£¬£¬£¬£¬£¬¶øÕë¶ÔÔ¶³Ì×ÀÃæÐ§ÀÍ£¨RDS£©ÒÔ¼°CitrixºÍPulse VPN×°±¸µÄ¹¥»÷ÓÐËùÔöÌí¡£¡£¡£¡£¡£ÕâÒ»¼¾¶ÈºÚ¿ÍµÄÖØµãÄ¿µÄΪҽÁƱ£½¡ºÍ¿Æ¼¼ÐÐÒµ £¬£¬£¬£¬£¬£¬£¬ÓëÉÏÒ»¼¾¶ÈµÄ½ðÈÚЧÀͺÍÕþ¸®²¿·ÖÓÐËù²î±ð¡£¡£¡£¡£¡£ÀÕË÷Èí¼þÊǴ˼¾¶È×îÖ÷ÒªµÄ¹¥»÷·½·¨ £¬£¬£¬£¬£¬£¬£¬¶øRyukÒѾ­Ò»Á¬Ëĸö¼¾¶ÈÔÚÓ¦¼±ÏìÓ¦ÖÐÕ¼ÓÐÁËÍþвÁìÓòµÄÖ÷µ¼Ö°Î»¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/06/CTIR-trends-q3-2020.html


2.AT&TµÈ30¼ÒÃÀ¹ú¹«Ë¾ÒÉËÆÔâµ½´ó¹æÄ£DDoS¹¥»÷


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


6ÔÂ15ÈÕÃÀ¹úÒÉËÆÔâµ½ÁËÆäÀúÊ·ÉÏ×î´óµÄDDoS¹¥»÷ £¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÃÀ¹ú¸÷µØµÄµçÐźÍÔÚÏßЧÀÍ £¬£¬£¬£¬£¬£¬£¬²¢µ¼Ö´ó¹æÄ£¶Ïµç¡£¡£¡£¡£¡£¾ÝÍøÕ¾Downdetectorͳ¼Æ £¬£¬£¬£¬£¬£¬£¬´Ë´ÎÊÜÓ°ÏìµÄ¹«Ë¾°üÀ¨T-Mobile¡¢Metro¡¢Verizon¡¢AT&T¡¢Sprint¡¢Consumer Cellular¡¢US Cellular¡¢Spectrum¡¢Comcast¡¢CenturyLink¡¢Cox¡¢Facebook¡¢Instagram¡¢SnapchatºÍTwitterµÈ¡£¡£¡£¡£¡£¾Ý±¨µÀ £¬£¬£¬£¬£¬£¬£¬Å¦Ô¼¡¢·ðÂÞÀï´ï¡¢µÂ¿ËÈøË¹ÖÝ¡¢ÇÇÖÎÑÇÖݺͼÓÀû¸£ÄáÑÇÖÝÒÔ¼°ÆäËûÖݶ¼±¬·¢Á˶ϵç¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬£¬Ã»ÓÐÒ»¼Ò¹«Ë¾Ú¹ÊÍÍøÂçÖÐÖ¹µÄÔµ¹ÊÔ­ÓÉ £¬£¬£¬£¬£¬£¬£¬ÊÖÒÕÖ°Ô±¾ùÍÆ²â´Ë´ÎÊÂÎñΪDDoS¹¥»÷µ¼Ö £¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁËͼƬ֤¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.geekdup.net/2020/06/16/largest-ddos-attack-in-united-states-history-might-have-happened-yesterday/



3.ºÚ¿Íð³ą̈Íå¼²¿ØÖÐÐÄ £¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Õþ¸®Ç鱨


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾

ÍøÂçÇå¾²¹«Ë¾ElevenPathsÌåÏÖ £¬£¬£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯ÕýÔÚð³ą̈Íå¼²¿ØÖÐÐĵÄÖÎÀíÖ°Ô± £¬£¬£¬£¬£¬£¬£¬Í¨¹ý·¢ËÍÈ«ÐıàдµÄ´¹ÂÚÓʼþÊÔͼÇÔÈ¡Õþ¸®Ç鱨¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯VendettaÔÚ5Ô³õ×îÏÈÏǫ̀ÍåijЩÓû§·¢Ë͵ç×ÓÓʼþ £¬£¬£¬£¬£¬£¬£¬²¢±Þ²ßËûÃǾÙÐÐеĹÚ×´²¡¶¾¼ì²â¡£¡£¡£¡£¡£¸Ã´¹ÂÚÓʼþÖи½´øÁËÒ»¸öÔ¶³ÌºÚ¿Í¹¤¾ß £¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÇÔÈ¡µÇ¼ƾ֤²¢Ð®ÖÆÍøÂçÉãÏñÍ·¡£¡£¡£¡£¡£Miguel ?ngel de Castro Sim¨®nÌåÏÖ £¬£¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í¹¤¾ßµÄÌØÕ÷Åú×¢ËûÃÇÕýÔÚËѼ¯Ç鱨 £¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÊÇÕþ¸®Ç鱨¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/vendetta-taiwan-coronavirus-telefonica/


4.Qbot¹¥»÷ÊýÊ®¼ÒÃÀ¹ú½ðÈÚ»ú¹¹²¢ÇÔÈ¡Æä¿Í»§Æ¾Ö¤


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


F5ʵÑéÊÒµÄÑо¿Ö°Ô±·¢Ã÷ºÚ¿ÍʹÓöñÒâÈí¼þQbot¶ÔÊýÊ®¼ÒÃÀ¹ú½ðÈÚ»ú¹¹Ìᳫ¹¥»÷ £¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÆä¿Í»§µÄƾ֤ºÍ½ðÈÚÊý¾Ý¡£¡£¡£¡£¡£ÊÜÓ°Ïì½ðÈÚ»ú¹¹°üÀ¨Ä¦¸ù´óͨ¡¢»¨ÆìÒøÐС¢ÃÀ¹úÒøÐС¢ Citizens¡¢Capital One¡¢ ¸»¹úÒøÐкÍFirstMeritÒøÐеÈ¡£¡£¡£¡£¡£Æ¾Ö¤¶ñÒâÈí¼þÆÊÎöʦDoron VoolfÆÊÎö £¬£¬£¬£¬£¬£¬£¬´Ë´ÎʹÓõÄQbotµÄ¹¥»÷»î¶¯×ܹ²Ãé×¼ÁË36¸öÃÀ¹úµÄ½ðÈÚ»ú¹¹ £¬£¬£¬£¬£¬£¬£¬ÁíÍâÉÐÓмÓÄôóºÍºÉÀ¼µÄÁ½¼ÒÒøÐС£¡£¡£¡£¡£Voolf˵ £¬£¬£¬£¬£¬£¬£¬Ïà±È֮ǰµÄ°æ±¾ £¬£¬£¬£¬£¬£¬£¬´Ë´ÎµÄQbotÐÂÔöÁËеķâ×°²ã £¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ¼ÓÃܲ¢Òþ²Ø´úÂëÀ´¶ã¹ýɨÃè³ÌÐò £¬£¬£¬£¬£¬£¬£¬Ëü»¹ÔöÌíÁË·´ÐéÄâ»úÊÖÒÕ £¬£¬£¬£¬£¬£¬£¬¿É×ÊÖúÆä¶ã¹ýɱ¶¾Èí¼þ¼ì²â¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-bank-customers-targeted-in-ongoing-qbot-campaign/


5.ÍâÂô¹«Ë¾FoodoraÊý¾Ýй¶ £¬£¬£¬£¬£¬£¬£¬Ó°Ïì14¸ö¹ú¼ÒµÄÓû§


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


ÔÚÏßʳÎïÅäËÍЧÀÍDelivery HeroÒÑÈ·ÈÏÆä¹«Ë¾Foodora±¬·¢ÁËÊý¾Ýй¶ £¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË14¸ö¹ú¼ÒµÄÓû§¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ¹²Ð¹Â¶ÁË72.7Íò¸ö¿Í»§µÄÕÊ»§ÏêϸÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨Ãû³Æ¡¢µØµã¡¢µç»°ºÅÂëºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£Ö»¹Ü´Ë´ÎÊÂÎñÖв¢Ã»ÓвÆÎñÊý¾Ý×ß© £¬£¬£¬£¬£¬£¬£¬µ«¿Í»§ÏÕЩ׼ȷµ½Ã׵ĵØÀíλÖÃÔâµ½ÁËй¶¡£¡£¡£¡£¡£Delivery HeroµÄ½²»°ÈË˵ £¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢¿ÉÒÔ×·Ëݵ½2016Äê £¬£¬£¬£¬£¬£¬£¬À´×Ô°Ä´óÀûÑÇ¡¢°ÂµØÀû¡¢¼ÓÄô󡢷¨¹ú¡¢µÂ¹ú¡¢Ïã¸Û¡¢Òâ´óÀû¡¢ÁÐÖ§¶ØÊ¿µÇ¡¢ºÉÀ¼¡¢Å²Íþ¡¢ÐÂ¼ÓÆÂ¡¢Î÷°àÑÀºÍ°¢À­²®ÁªºÏÇõ³¤¹úµÄFoodoraÓû§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/foodora-data-breach/


6.ARM CPUÐÂÎó²îΪSpectre±äÌå £¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö²àÐŵÀ¹¥»÷


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


GoogleµÄSafeSideС×é·¢Ã÷ARM CPU±£´æÐµÄͶÆõÖ´ÐÐÎó²î £¬£¬£¬£¬£¬£¬£¬ÎªSpectre±äÌå £¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö²àÐŵÀ¹¥»÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÙÔÚARM´¦Öóͷ£Æ÷µÄArmv8-A£¨Cortex-A£©CPUϵͳ½á¹¹Öз¢Ã÷ÁËÒ»¸öÃûΪֱÏßÍÆ²â£¨ Straight-Line Speculation £¬£¬£¬£¬£¬£¬£¬SLS£© µÄÐÂÎó²î £¬£¬£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2020-13844¡£¡£¡£¡£¡£SLS±»ÒÔΪÊÇSpectreÎó²îµÄ±äÌå £¬£¬£¬£¬£¬£¬£¬µ«¶þÕߵĹ¥»÷¹æÄ£ÂÔÓвî±ð £¬£¬£¬£¬£¬£¬£¬SLSÎó²î½öÓ°ÏìArm Armv-A´¦Öóͷ£Æ÷ £¬£¬£¬£¬£¬£¬£¬¶øSpectreÎó²îÓ°ÏìËùÓÐÖ÷ÒªÐ¾Æ¬ÖÆÔìÉ̵ÄCPU¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ £¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î»¹Ã»ÓÐÔÚҰʹÓᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.phoronix.com/scan.php?page=news_item&px=Arm-Straight-Line-Speculation