µÂ¹úÁª°î½ðÈÚî¿Ïµ¾ÖµÄÍøÕ¾Ôâµ½DDoS¹¥»÷ÔÝʱÖÐÖ¹

Ðû²¼Ê±¼ä 2023-09-06

1¡¢µÂ¹úÁª°î½ðÈÚî¿Ïµ¾ÖµÄÍøÕ¾Ôâµ½DDoS¹¥»÷ÔÝʱÖÐÖ¹


¾ÝýÌå9ÔÂ5ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬µÂ¹úÁª°î½ðÈÚî¿Ïµ¾Ö(BaFin)µÄÍøÕ¾Ôâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬Ð§ÀÍÖÐÖ¹ÊýÌì¡£¡£¡£¡£ ¡£¡£¡£BaFinÊÇÁ¥ÊôÓڵ¹ú²ÆÎñ²¿µÄ½ðÈÚî¿Ïµ»ú¹¹£¬£¬£¬£¬£¬£¬ÈÏÕæî¿Ïµ2700¼ÒÒøÐС¢800¼Ò½ðÈÚºÍ700¼Ò°ü¹ÜЧÀÍÌṩÉÌ¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷×îÏÈÓÚ9ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬BaFin³ÆÒѽÓÄɳä·ÖµÄÇå¾²Ô¤·À²½·¥ºÍÓÐÓõķÀÓù²½·¥¡£¡£¡£¡£ ¡£¡£¡£BaFinµÄÍøÕ¾bafin.deÖÐÖ¹£¬£¬£¬£¬£¬£¬µ«¸Ã»ú¹¹³ÆÆäËüϵͳ¾ùδÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£¡£Éв»ÇåÎú´Ë´Î¹¥»÷µÄÄ»ºóºÚÊÖ£¬£¬£¬£¬£¬£¬µ«KillnetÔøÓÚ1Ô·ݽ«BaFinÍøÕ¾Ìí¼Óµ½ÆäÔÚTelegramÉÏÐû²¼µÄÄ¿µÄÁбíÖС£¡£¡£¡£ ¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÍøÕ¾ËƺõÒÑÍêÈ«»Ö¸´¡£¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/150359/hacking/ddos-attack-on-bafin.html


2¡¢LockBit¹¥»÷Zaun¹«Ë¾²¢¹ûÕæ´ó×ÚÓ¢¹ú¾üÊÂÏà¹ØÐÅÏ¢


¾Ý9ÔÂ4ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬LockBit¹ûÕæÁË´ó×ÚÓëÓ¢¹ú¾üʺÍÇ鱨վµãÏà¹ØµÄÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£Î§À¸ÏµÍ³ÖÆÔìÉÌZaun³Æ£¬£¬£¬£¬£¬£¬ÆäÓÚ8ÔÂ5ÈÕÖÁ6ÈÕÔâµ½ÁËLockBitµÄ¹¥»÷£¬£¬£¬£¬£¬£¬²¢Í¸Â¶¹¥»÷ÊÇͨ¹ýһ̨Windows 7 PC¾ÙÐеÄ£¬£¬£¬£¬£¬£¬¿ÉÄÜÒÑй¶10 GBµÄÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£LockBitÓÚ8ÔÂ13ÈÕ¹ûÕæÁ˴˴ι¥»÷£¬£¬£¬£¬£¬£¬²¢ÒªÇóZaunÔÚ8ÔÂ29ÈÕ½»Êê½ð¡£¡£¡£¡£ ¡£¡£¡£ZaunÒÔΪϵͳÉÏûÓд洢»òй¶ÈκÎÉñÃØÎļþ£¬£¬£¬£¬£¬£¬µ«Daily Mirror³Æ£¬£¬£¬£¬£¬£¬LockBit Ðû²¼µÄÊýǧҳÎļþ£¬£¬£¬£¬£¬£¬Éæ¼°ÁËÓ¢¹ú¿ËÀ³µÂˮʦ»ùµØ£¨HMNB Clyde£©ºËDZͧ»ùµØ¡¢²¨¶ÙÌÆ»¯Ñ§ÎäÆ÷ʵÑéÊÒºÍλÓÚ¿µÎÖ¶û²¼µÂµÄGCHQͨѶÖÐÐÄ¡£¡£¡£¡£ ¡£¡£¡£


https://www.infosecurity-magazine.com/news/sensitive-data-uk-army-potentially/


3¡¢Freecycle͸¶ӰÏìÁè¼Ý700ÍòÓû§µÄÊý¾Ýй¶ÊÂÎñ


ýÌå9ÔÂ4Èճƣ¬£¬£¬£¬£¬£¬ÔÚÏßÂÛ̳FreecycleÅû¶ÁËÓ°ÏìÁè¼Ý700ÍòÓû§µÄ´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£ ¡£¡£¡£5ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÒ»¸öÂÛ̳ÉϳöÊÛ±»µÁÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£FreecycleÔÚ8ÔÂ30ÈÕÒâʶµ½´Ë´Îй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÊÜÓ°ÏìµÄÓû§Á¬Ã¦Ìæ»»ÃÜÂë¡£¡£¡£¡£ ¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢°üÀ¨Óû§Ãû¡¢Óû§ID¡¢ÓʼþµØµãºÍMD5¹þÏ£ÃÜÂë¡£¡£¡£¡£ ¡£¡£¡£´Ó¹¥»÷ÕßÐû²¼µÄ½ØÍ¼À´¿´£¬£¬£¬£¬£¬£¬FreecycleÊ×´´È˼æÖ´Ðж­ÊÂµÄÆ¾Ö¤±»µÁ£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»ÍêÈ«»á¼û»áÔ±ÐÅÏ¢ºÍÂÛ̳Ìû×Ó¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/freecycle-confirms-massive-data-breach-impacting-7-million-users/


4¡¢»ªË¶Â·ÓÉÆ÷ÖеÄ3¸ö´úÂëÖ´ÐÐÎó²î¿ÉÄܵ¼ÖÂ×°±¸Ð®ÖÆ


9ÔÂ5ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬3¸öÓ°ÏìÁË»ªË¶RT-AX55¡¢RT-AX56U_V2ºÍRT-AC86U·ÓÉÆ÷µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂ×°±¸Ð®ÖÆ¡£¡£¡£¡£ ¡£¡£¡£ÕâЩÎó²î»®·ÖΪȱ·¦¶ÔiperfÏà¹ØAPIÄ£¿£¿£¿£¿£¿£¿éser_iperf3_svr.cgiÉϵÄÊäÈëÃûÌÃ×Ö·û´®×¼È·ÑéÖ¤µÄÎó²î£¨CVE-2023-39238£©¡¢Í¨ÓÃÉèÖú¯ÊýµÄAPIÖÐȱ·¦¶ÔÊäÈëÃûÌÃ×Ö·û´®×¼È·ÑéÖ¤µÄÎó²î£¨CVE-2023-39239£©ºÍȱ·¦¶ÔiperfÏà¹ØAPIÄ£¿£¿£¿£¿£¿£¿éser_iperf3_cli.cgiÉϵÄÊäÈëÃûÌÃ×Ö·û´®×¼È·ÑéÖ¤µÄÎó²î£¨CVE-2023-39240£©¡£¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÒѱ»ÐÞ¸´¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/asus-routers-vulnerable-to-critical-remote-code-execution-flaws/


5¡¢Ó¡¶È¼Ö¿²µÂ°îAYUSH²¿32Íò¶à»¼ÕßµÄÐÅÏ¢±»Ðû²¼ÔÚ°µÍø


ýÌå9ÔÂ4ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ºÚ¿ÍTanakaÔÚ°µÍøÐû²¼ÁËÒ»¸öÃûΪbitsphere[.]inµÄÊý¾Ý¿â¡£¡£¡£¡£ ¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ7.3MB£¬£¬£¬£¬£¬£¬°üÀ¨Áè¼Ý32ÍòÌõ»¼ÕßµÄPIIºÍÒ½ÁÆÕï¶ÏÐÅÏ¢£¬£¬£¬£¬£¬£¬500¸öµÇ¼ƾ֤ºÍÃ÷ÎÄÃÜÂ룬£¬£¬£¬£¬£¬ÒÔ¼°472ÌõÒ½ÉúPIIÐÅÏ¢µÈ¼Í¼¡£¡£¡£¡£ ¡£¡£¡£ÊӲ췢Ã÷£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÈ¡×Ôbitsphere.in¿ª·¢µÄayush.jharkhand.gov.inЧÀÍÆ÷¡£¡£¡£¡£ ¡£¡£¡£Ayush.jharkhand.gov.inÊÇÓ¡¶È¼Ö¿²µÂ°îµÄÕþ¸®²¿·ÖAYUSHµÄ¹Ù·½ÍøÕ¾¡£¡£¡£¡£ ¡£¡£¡£


https://www.cloudsek.com/threatintelligence/3-20-000-patient-records-from-ayush-jharkhand-gov-in-shared-on-dark-web-hacking-forums


6¡¢Ñо¿Ö°Ô±Åû¶ʹÓÃÁ½¸öMinIOÎó²îµÄ¹¥»÷»î¶¯µÄϸ½Ú


¾Ý9ÔÂ4ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Security JoesÑо¿Ö°Ô±¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓýüÆÚµÄÁ½¸öMinIOÎó²îÀ´¹¥»÷¹¤¾ß´æ´¢ÏµÍ³¡¢»á¼ûÐÅÏ¢²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£±»Ê¹ÓõÄÎó²î»®·ÖΪÐÅϢй¶Îó²î£¨CVE-2023-28432£©ºÍÌáȨÎó²î£¨CVE-2023-28434£©£¬£¬£¬£¬£¬£¬ÒÑÓÚ3ÔÂ3ÈÕÅû¶²¢ÐÞ¸´¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÊÔͼװÖÃMinIOµÄÐ޸İ汾Evil MinIO£¬£¬£¬£¬£¬£¬Æä¿ÉÔÚGitHubÉÏ»ñÈ¡¡£¡£¡£¡£ ¡£¡£¡£Evil MinIOÁ¬ÏµÊ¹ÓÃÁËÁ½¸öÎó²î£¬£¬£¬£¬£¬£¬ÓÃÐ޸ĺóµÄ´úÂëÌæ»»MinIOÈí¼þ£¬£¬£¬£¬£¬£¬Ìí¼ÓÁËÔ¶³Ì»á¼ûºóÃÅ¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß»¹»á¾ÙÐÐһЩÉ繤¹¥»÷£¬£¬£¬£¬£¬£¬ÒÔ˵·þÄ¿µÄ½«MinIO½µ¼¶µ½Êܵ½Îó²îÓ°ÏìµÄÔçÆÚ°æ±¾¡£¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/150308/breaking-news/minio-storage-system-exploit.html