ÃÀ¹úË®Îñ¹«Ë¾ÔâÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬²¿·Öϵͳ¹Ø±Õ²¢Æô¶¯ÊÓ²ì

Ðû²¼Ê±¼ä 2024-10-08

1. ÃÀ¹úË®Îñ¹«Ë¾ÔâÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬²¿·Öϵͳ¹Ø±Õ²¢Æô¶¯ÊÓ²ì


10ÔÂ7ÈÕ£¬ £¬£¬£¬£¬£¬ÃÀ¹úË®Îñ¹«Ë¾£¬ £¬£¬£¬£¬£¬×÷Ϊ¸Ã¹ú×î´óµÄÉÏÊÐË®ÎñºÍÎÛË®´¦Öóͷ£¹«ÓÃÊÂÒµ¹«Ë¾£¬ £¬£¬£¬£¬£¬½üÆÚÔâÊÜÁËÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬µ¼Ö²¿·Öϵͳ±»ÆÈ¹Ø±Õ¡£¡£¡£¡£¡£¹«Ë¾ÒÑÔ¼ÇëµÚÈý·½ÍøÂçÇ徲ר¼Ò½éÈ룬 £¬£¬£¬£¬£¬²¢ÏòÖ´·¨²¿·Ö±¨¸æ´ËÊÂÎñ£¬ £¬£¬£¬£¬£¬Ð­µ÷ÁªºÏÊӲ졣¡£¡£¡£¡£ÎªÓ¦¶Ô¹¥»÷£¬ £¬£¬£¬£¬£¬¹«Ë¾½ÓÄÉÁ˶Ͽª»òÍ£ÓÃijЩϵͳµÄ²½·¥£¬ £¬£¬£¬£¬£¬²¢¹Ø±ÕÁËÔÚÏ߿ͻ§ÃÅ»§Ð§ÀÍMyWater£¬ £¬£¬£¬£¬£¬ÔÝÍ£Á˼ƷÑЧÀÍ¡£¡£¡£¡£¡£¹«Ë¾½²»°ÈËÌåÏÖ£¬ £¬£¬£¬£¬£¬Ê±´ú²»»áÏò¿Í»§ÊÕÈ¡ÖÍÄɽ𣬠£¬£¬£¬£¬£¬²¢Ç¿µ÷¹©Ë®»ò·ÏË®ÉèÊ©¼°ÔËӪδÊÜ´Ë´ÎÊÂÎñÓ°Ïì¡£¡£¡£¡£¡£ÃÀ¹úË®Îñ¹«Ë¾ÓµÓÐ6,500¶àÃûÔ±¹¤£¬ £¬£¬£¬£¬£¬Îª14¸öÖݺÍ18¸ö¾üÊ»ùµØµÄÁè¼Ý1,400ÍòÈËÌṩЧÀÍ¡£¡£¡£¡£¡£´Ëǰ£¬ £¬£¬£¬£¬£¬ÀàËÆÊÂÎñÒ²Ôø±¬·¢£¬ £¬£¬£¬£¬£¬Èç¿°ÈøË¹Öݰ¢¿ÏÉ«³ÇµÄË®´¦Öóͷ£³§ÔÚÖÜÄ©ÔâÊÜÍøÂç¹¥»÷ºóתΪÊÖ¶¯²Ù×÷¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬Ë®ÐÅÏ¢¹²ÏíÓëÆÊÎöÖÐÐÄÔøÐû²¼ÖÒÑԳƶíÂÞ˹Õë¶ÔË®Îñ²¿·ÖÌá³«ÍøÂç¹¥»÷¡£¡£¡£¡£¡£ÃÀ¹úÇéÐα£»£»£»¤ÊðÒ²Ðû²¼ÁËÖ¸µ¼Òâ¼û£¬ £¬£¬£¬£¬£¬×ÊÖúÆÀ¹ÀÍøÂçÇ徲ʵ¼ù²¢È·¶¨ïÔÌ­¹¥»÷Σº¦µÄ²½·¥¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/american-water-shuts-down-online-services-after-cyberattack/


2. Cloudflare×èÖ¹ÁËÊ·ÉÏ×î´óÁ÷Á¿DDoS¹¥»÷£¬ £¬£¬£¬£¬£¬·åÖµµÖ´ï3.8Tbps


10ÔÂ3ÈÕ£¬ £¬£¬£¬£¬£¬½ðÈÚЧÀÍ¡¢»¥ÁªÍøºÍµçÐÅÐÐÒµÔâÊÜÁËÒ»³¡Ø¨¹ÅδÓеÄÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬ £¬£¬£¬£¬£¬·åÖµÁ÷Á¿¸ß´ïÿÃë3.8½ðÈÚЧÀÍ¡¢»¥ÁªÍøºÍµçÐÅÐÐÒµÔâÊÜÁËÒ»³¡Ø¨¹ÅδÓеÄÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬ £¬£¬£¬£¬£¬·åÖµÁ÷Á¿¸ß´ïÿÃë3.8Tbps£¬ £¬£¬£¬£¬£¬´´ÏÂÁ˹ûÕæ¼Í¼µÄ×î´óÖµ¡£¡£¡£¡£¡£Õⳡ¹¥»÷Ò»Á¬ÁËÒ»¸öÔ£¬ £¬£¬£¬£¬£¬°üÀ¨ÁËÁè¼Ý100´ÎµÄ³¬´óÁ÷Á¿DDoS¹¥»÷£¬ £¬£¬£¬£¬£¬Í¨¹ýÀ¬»øÊý¾ÝÑÍÃ»ÍøÂç»ù´¡ÉèÊ©¡£¡£¡£¡£¡£ÔÚÈÝÁ¿÷缯ÐÍDDoS¹¥»÷ÖУ¬ £¬£¬£¬£¬£¬´ó×ÚÊý¾Ýµ¼Ö´ø¿íÏûºÄ´ù¾¡£¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬Ó¦ÓóÌÐòºÍ×°±¸×ÊÔ´¿Ý½ß£¬ £¬£¬£¬£¬£¬Õýµ±Óû§ÎÞ·¨»á¼û¡£¡£¡£¡£¡£ÊÜѬȾµÄ×°±¸°üÀ¨Asus·ÓÉÆ÷¡¢MikroTik×°±¸¡¢DVRºÍÍøÂçЧÀÍÆ÷£¬ £¬£¬£¬£¬£¬Çұ鲼ȫÇò£¬ £¬£¬£¬£¬£¬¶íÂÞ˹¡¢Ô½ÄÏ¡¢ÃÀ¹ú¡¢°ÍÎ÷ºÍÎ÷°àÑÀÓÈΪ¼¯ÖС£¡£¡£¡£¡£CloudflareÀֳɻº½âÁËËùÓй¥»÷£¬ £¬£¬£¬£¬£¬²¢Ö¸³ö·åÖµ¹¥»÷Ò»Á¬ÁË65Ãë¡£¡£¡£¡£¡£¶ñÒâ×°±¸Ö÷ҪʹÓÃUDPЭÒ飬 £¬£¬£¬£¬£¬¸ÃЭÒéÊý¾Ý´«ÊäËÙÂʿ죬 £¬£¬£¬£¬£¬µ«ÎÞÐ轨ÉèÕýʽÅþÁ¬¡£¡£¡£¡£¡£´Ëǰ£¬ £¬£¬£¬£¬£¬Î¢ÈíÔø¼á³Ö·ÀÓù×î´óDDoS¹¥»÷µÄ¼Í¼£¬ £¬£¬£¬£¬£¬Á÷Á¿Îª3.47Tbps¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cloudflare-blocks-largest-recorded-ddos-attack-peaking-at-38tbps/


3. CosmicSting¹¥»÷ÍþвAdobe CommerceºÍMagentoÊÐËÁÇå¾²


10ÔÂ3ÈÕ£¬ £¬£¬£¬£¬£¬Adobe CommerceºÍMagentoÔÚÏßÊÐËÁÕýÃæÁÙÃûΪ¡°CosmicSting¡±µÄÑÏÖØ¹¥»÷£¬ £¬£¬£¬£¬£¬¸Ã¹¥»÷ÒÑÈëÇÖÔ¼5%µÄÊÐËÁ¡£¡£¡£¡£¡£CosmicStingÎó²î£¨CVE-2024-34102£©ÊÇÒ»¸ö¸ßÑÏÖØÐÔµÄÐÅϢй¶Îó²î£¬ £¬£¬£¬£¬£¬µ±ÓëglibcµÄiconvº¯ÊýÖеÄÁíÒ»Çå¾²ÎÊÌ⣨CVE-2024-2961£©½áÊÊʱ£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔÚÄ¿µÄЧÀÍÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Adobe CommerceµÄ¶à¸ö°æ±¾¡¢Magento¿ªÔ´µÄ¶à¸ö°æ±¾ÒÔ¼°Adobe Commerce Webhooks²å¼þµÄijЩ°æ±¾¡£¡£¡£¡£¡£×Ô2024Äê6ÔÂÒÔÀ´£¬ £¬£¬£¬£¬£¬ÍøÕ¾Çå¾²¹«Ë¾SansecÒÑ×·×Ùµ½4,275¼ÒÊÐËÁÔÚCosmicSting¹¥»÷ÖÐÔâµ½ÈëÇÖ£¬ £¬£¬£¬£¬£¬×ÅÃûÊܺ¦Õß°üÀ¨»Ý¶øÆÖ¡¢À×Åó¡¢¹ú¼ÒµØÀí¡¢Èü¸ñÍþºÍ˼¿ÆµÈ¡£¡£¡£¡£¡£SansecÖÒÑԳƣ¬ £¬£¬£¬£¬£¬ÓÉÓÚÐÞ²¹ËÙÂÊÓëÇéÐÎÑÏÖØÐÔ²»Æ¥Å䣬 £¬£¬£¬£¬£¬ÏÖÔÚ¶à¸öÍþвÐÐΪÕßÕýÔÚʹÓÃCosmicStingÎó²îÈëÇÖδ´ò²¹¶¡µÄÍøÕ¾¡£¡£¡£¡£¡£ÕâЩÍþв×éÖ¯ÃûΪ¡°Bobry¡±¡¢¡°Polyovki¡±µÈ£¬ £¬£¬£¬£¬£¬ËûÃdzöÓÚ¾­¼ÃÄîÍ·£¬ £¬£¬£¬£¬£¬ÈëÇÖÍøÕ¾ÒÔÇÔÊØÐÅÓÿ¨ºÍ¿Í»§ÐÅÏ¢¡£¡£¡£¡£¡£¶ñÒâ¾ç±¾»á´Óαװ³É×ÅÃûJavaScript¿â»òÆÊÎö°üµÄÓòÃû×¢ÈëÊÜѬȾµÄÍøÕ¾¡£¡£¡£¡£¡£Òò´Ë£¬ £¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéÍøÕ¾ÖÎÀíÔ±¾¡¿ìÉý¼¶µ½Çå¾²µÄÈí¼þ°æ±¾¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/over-4-000-adobe-commerce-magento-shops-hacked-in-cosmicsting-attacks/


4. ZimbraÓʼþЧÀÍÆ÷ÑÏÖØÎó²îCVE-2024-45519Òý·¢Çå¾²¾¯±¨


10ÔÂ4ÈÕ£¬ £¬£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©Òѽ«Zimbraµç×ÓÓʼþЧÀÍÆ÷ÖеÄÑÏÖØÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2024-45519Ìí¼Óµ½ÆäÒÑ֪ʹÓÃÎó²îĿ¼ÖУ¬ £¬£¬£¬£¬£¬¸ÃÎó²îÕë¶ÔZimbraµÄpostjournalЧÀÍ£¬ £¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆµç×ÓÓʼþʹÓÃϵͳ£¬ £¬£¬£¬£¬£¬Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£´ËÎó²îÒÑÒýÆðÕþ¸®ºÍÒªº¦»ù´¡ÉèÊ©²¿·ÖµÄСÐÄ£¬ £¬£¬£¬£¬£¬ÓÉÓÚ¹¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃËü£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³ÈëÇÖ»òδ¾­ÊÚȨµÄ»á¼ûµÈÑÏÖØÐ§¹û¡£¡£¡£¡£¡£ZimbraÒÑÐû²¼²¹¶¡ÐÞ¸´´ËÎó²î£¬ £¬£¬£¬£¬£¬½¨ÒéϵͳÖÎÀíÔ±Á¬Ã¦Ó¦Óᣡ£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬ProjectDiscoveryµÄÑо¿Ö°Ô±Ìá³öÁËÁ½ÖÖ»º½â²½·¥£ºÈôÊÇPostjournalЧÀͲ»Ö÷Òª£¬ £¬£¬£¬£¬£¬Çë½ûÓÃËü£»£»£»²¢È·±£¡°mynetworks¡±ÉèÖÃ׼ȷÉèÖÃÒÔ×èֹδ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¼øÓÚZimbraÔÚÈ«ÇòµÄÆÕ±éʹÓ㬠£¬£¬£¬£¬£¬ºöÊÓÕâЩ·ÀÓù²½·¥¿ÉÄÜ»áʹϵͳ̻¶ÓÚ×Ô¶¯¹¥»÷µÄΣº¦ÖС£¡£¡£¡£¡£CISAÒÑ·¢³öÇ¿ÁÒÖÒÑÔ£¬ £¬£¬£¬£¬£¬²¢É趨ÁËÁª°î»º½â²½·¥µÄ×îºóÏÞÆÚΪ2024Äê10ÔÂ24ÈÕ£¬ £¬£¬£¬£¬£¬ÎªÁª°î»ú¹¹ºÍÒªº¦»ù´¡ÉèÊ©×éÖ¯ÌṩÁ˽ôÆÈµÄʱ¼äÀ´Ó¦Óò¹¶¡»ò×èֹʹÓÃZimbraµÄÈÕ־ЧÀÍ¡£¡£¡£¡£¡£


https://securityonline.info/zimbra-email-servers-under-attack-cisa-flags-cve-2024-45519-as-actively-exploited/


5. perfctl¶ñÒâÈí¼þ£ºÕë¶ÔLinuxЧÀÍÆ÷µÄÒþ²Ø³¤ÆÚ¹¥»÷Óë×ÊÔ´Ð®ÖÆ


10ÔÂ4ÈÕ£¬ £¬£¬£¬£¬£¬Aqua Nautilus µÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪ perfctl µÄ Linux ¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬ËüÒÑÕë¶ÔÉèÖùýʧµÄ Linux ЧÀÍÆ÷¾ÙÐÐÁ˳¤´ï 3-4 ÄêµÄ¹¥»÷¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þʹÓà rootkit Òþ²ØÆä±£´æ£¬ £¬£¬£¬£¬£¬Í¨¹ý TOR ¾ÙÐÐͨѶ£¬ £¬£¬£¬£¬£¬²¢ÔÚЧÀÍÆ÷¿ÕÏÐʱִÐмÓÃÜÇ®±Ò¿ó¹¤ºÍÊðÀíÐ®ÖÆÈí¼þ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÎó²î»ò¹ýʧÉèÖ㬠£¬£¬£¬£¬£¬´Ó¿ØÖÆµÄ HTTP ЧÀÍÆ÷ÏÂÔØ¶à²ã½á¹¹µÄÓÐÓÃÔØºÉ£¬ £¬£¬£¬£¬£¬Í¨¹ýÖØÃüÃûºÍɾ³ýԭʼ¶þ½øÖÆÎļþÀ´ÑÚÊÎ×Ù¼£¡£¡£¡£¡£¡£Ëü»¹»áͶ·ÅÒ»¸ö rootkit ºÍ¾­ÓÉÐÞ¸ÄµÄ Linux ÊÊÓóÌÐò£¬ £¬£¬£¬£¬£¬Ê¹Óø߼¶ÌÓ±ÜÊÖÒÕÈç¼ì²âÐÂÓû§Ê±×èÖ¹»î¶¯£¬ £¬£¬£¬£¬£¬²¢ÖÕÖ¹¾ºÕù¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÎªÁ˼á³Ö³¤ÆÚÐÔ£¬ £¬£¬£¬£¬£¬¶ñÒâÈí¼þ»áÐÞ¸ÄÓû§µÇ¼¾ç±¾£¬ £¬£¬£¬£¬£¬ÔÚÓû§µÇ¼ʱִÐУ¬ £¬£¬£¬£¬£¬²¢ÔÚºǫ́ÔËÐÐÒÔÈ·±£ÆäÒ»Á¬ÔËÐС£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄÖ÷ÒªÓ°ÏìÊÇ×ÊÔ´Ð®ÖÆ£¬ £¬£¬£¬£¬£¬Í¨¹ýÖ´ÐÐÃÅÂÞ±ÒÍÚ¿ó³ÌÐòÀ´ºÄ¾¡Ð§ÀÍÆ÷ CPU ×ÊÔ´¡£¡£¡£¡£¡£Òª¼ì²â perfctl ¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬ÐèÒªÉó²é CPU ʹÓÃÂÊÊÇ·ñ·ºÆðÒì³£·åÖµ»òϵͳÊÇ·ñ±äÂý¡£¡£¡£¡£¡£


https://securityaffairs.com/169351/malware/perfctl-malware-targets-misconfigured-linux-servers.html


6. UMC Health SystemÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬»¼Õß×ªÒÆÓëЧÀÍÊÜ×è


10ÔÂ1ÈÕ£¬ £¬£¬£¬£¬£¬µÂ¿ËÈøË¹ÖÝÒ½ÁƱ£½¡ÌṩÉÌUMC Health System½üÆÚÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬µ¼ÖÂÆäITϵͳ·ºÆðÒì³£»£»£»î¶¯¡£¡£¡£¡£¡£Îª×èÖ¹ÊÂÎñ£¬ £¬£¬£¬£¬£¬UMCÁ¬Ã¦¶Ï¿ªÏµÍ³²¢Õö¿ªÊӲ죬 £¬£¬£¬£¬£¬È·ÈÏ´Ë´ÎÒì³£»£»£»î¶¯ÓëÀÕË÷Èí¼þÊÂÎñÓйØ¡£¡£¡£¡£¡£Ö»¹ÜÉÐδÓдóÐÍÀÕË÷Èí¼þ×éÖ¯¶Ô¹¥»÷ÈÏÕæ£¬ £¬£¬£¬£¬£¬µ«¹¥»÷ÒÑÆÈʹUMC½«²¿·Ö»¼Õß×ªÒÆµ½ÆäËûËùÔÚ£¬ £¬£¬£¬£¬£¬²¢µ¼ÖÂһЩ¿ÆÊҹرջòÖ»ÄÜÌṩÑÓ³ÙЧÀÍ£¬ £¬£¬£¬£¬£¬ÆäÖзÅÉä¿ÆÊÜÓ°ÏìÓÈΪÑÏÖØ¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬ÓÉÓÚITϵͳ¹ÊÕÏ£¬ £¬£¬£¬£¬£¬UMCÕïËùÎÞ·¨ÌṩҽÁÆ´¦·½Çåµ¥£¬ £¬£¬£¬£¬£¬½¨Ò黼ÕßËæÉíЯ´ø£¬ £¬£¬£¬£¬£¬Ò½ÁƼͼËä¿ÉÔÚ»¼ÕßÃÅ»§ÍøÕ¾ÉÏÕÒµ½£¬ £¬£¬£¬£¬£¬µ«ÎÞ·¨´òÓ¡¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬Í¨¹ýµç»°»òÔÚÏßÃÅ»§½¨ÉèÏàͬҲÎÞ·¨°ü¹Ü£¬ £¬£¬£¬£¬£¬½¨ÒéÐèÒªÁ¬Ã¦×ÊÖúµÄÈËǰÍùÕïËù¡£¡£¡£¡£¡£´Ë´Î¹¥»÷¿ÉÄÜÉæ¼°Êý¾Ý͵ÇÔ£¬ £¬£¬£¬£¬£¬ÊýÊ®ÍòÈ˵ÄÃô¸ÐÒ½ÁÆÐÅÏ¢¿ÉÄÜÊܵ½Ó°Ï죬 £¬£¬£¬£¬£¬UMCÕýÔڶԴ˾ÙÐÐÊӲ죬 £¬£¬£¬£¬£¬²¢ÌåÏÖ½«ÔÚÓиü¶àÐÅϢʱÌṩ¸üС£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ransomware-attack-forces-umc-health-system-to-divert-some-patients/