¼ÓÄôóÓÊÕþÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Ð¹Â¶95Íò¿Í»§µÄÐÅÏ¢£» £»£»£»£»£»£»TeamTNTÍŻ﹥»÷¶à¸öKubernetes¼¯ÈºÖеĽü5Íò¸öIP

Ðû²¼Ê±¼ä 2021-05-28

1.¼ÓÄôóÓÊÕþÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Ð¹Â¶95Íò¿Í»§µÄÐÅÏ¢


1.jpg


¼ÓÄôóÓÊÕþ֪ͨ¿Í»§£¬£¬£¬ÓÉÓÚµÚÈý·½¹©Ó¦ÉÌCommport CommunicationsѬȾÀÕË÷Èí¼þ£¬£¬£¬ÆäÐÅÏ¢ÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£¼ÓÄôóÓÊÕþÊǼÓÄôóÖ÷ÒªµÄÓÊÕþÔËÓªÉÌ£¬£¬£¬Ð§ÀÍÓÚ1650Íò¼ÓÄôóסÃñºÍÉÌÒµµØµã¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ¹²Ó°ÏìÁ˸ù«Ë¾µÄ44¸ö´óÐÍÉÌÒµ¿Í»§ºÍ950000¸öÊÕ¼þÈË£¬£¬£¬Ð¹Â¶ÁË·¢¼þÈ˺ÍÊÕ¼þÈ˵ÄÁªÏµÐÅÏ¢¡¢ÐÕÃûºÍÓʼĵصãµÈÐÅÏ¢¡£¡£¡£¡£¡£ÔçÔÚ2020Äê12Ô£¬£¬£¬Lorenz¾Í³ÆÆä¹¥»÷ÁËCommport Communications£¬£¬£¬²¢ÇÔÈ¡ÁË35.3 GBµÄÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/canada-post-hit-by-data-breach-after-supplier-ransomware-attack/


2.TeamTNTÍŻ﹥»÷¶à¸öKubernetes¼¯ÈºÖеĽü5Íò¸öIP


2.jpg


Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±·¢Ã÷TeamTNTÍŻ﹥»÷¶à¸öKubernetes¼¯ÈºÖеĽü5Íò¸öIP¡£¡£¡£¡£¡£KubernetesÊÇÒ»¸ö¿ªÔ´µÄÈÝÆ÷±àÅÅϵͳ£¬£¬£¬ÓÃÓÚ×Ô¶¯»¯ÅÌËã»úÓ¦ÓóÌÐòµÄ°²ÅÅ¡¢À©Õ¹ºÍÖÎÀí¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ3ÔÂÖÁ5Ô£¬£¬£¬´ó´ó¶¼±»¹¥»÷µÄ½ÚµãÀ´×ÔÖйúºÍÃÀ¹ú¡£¡£¡£¡£¡£TeamTNT½©Ê¬ÍøÂç×Ô2020Äê4ÔÂ×îÏÈ»îÔ¾£¬£¬£¬Ö÷ÒªÕë¶ÔDocker£¬£¬£¬¿ÉÊÇ×Ô8ÔÂÒÔÀ´×îÏÈÕë¶ÔÉèÖùýʧµÄKubernetes¼¯Èº¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÔÚVirusTotalÖмì²âÂʺܵ͵ľ籾kube.lateral.sh£¬£¬£¬ÒÔ¼°Á½¸ö¿ªÔ´¹¤¾ßmasscanºÍZgrab¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118306/digital-id/kubernetes-clusters-teamtnt.html


3.·¨¹ú¾¯·½ÀúʱÊýÔÂÀֳɲé·â°µÍøLe MondeParall¨¨le


3.jpg


·¨¹ú¹ú¼ÒÇ鱨ºÍº£¹ØÊÓ²ì¾Ö£¨DNRED£©ÀúʱÊýÔ£¬£¬£¬ÖÕÓÚÀֳɲé·â°µÍøLe MondeParall¨¨le¡£¡£¡£¡£¡£ÕâÊǼÌ2018ÄêµÄBlack HandºÍ2019ÄêµÄFrench Deep Web MarketÖ®ºó£¬£¬£¬ÍâµØ¾¯·½²é·âµÄµÚÈý¸ö´óÐÍ·¨ÓïÆ½Ì¨¡£¡£¡£¡£¡£¸Ãƽ̨×Ô2020ÄêÍ·×îÏÈ»îÔ¾£¬£¬£¬ÌṩÖݪֲúÆ·ºÍЧÀÍ£¬£¬£¬°üÀ¨±»µÁµÄÒøÐп¨Êý¾Ý¡¢¶¾Æ·¡¢Î±ÔìÎļþºÍÎäÆ÷µÈ¡£¡£¡£¡£¡£Æ¾Ö¤·¨¹ú¾­¼Ã²¿(Ministry of the Economy)ÉùÃ÷£¬£¬£¬¾¯·½¾Ð²¶ÁËÁ½ÃûÖÎÀíÔ±£¬£¬£¬²¢²é»ñÁËÖÖÖÖÅÌËã»ú×°±¸¡¢ÐéαÎļþ¡¢ÒøÐп¨ÒÔ¼°ÊýǧŷԪµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118295/deep-web/le-monde-parallele-dark-web.html


4.ºÚ¿ÍÔÚ°µÍø³öÊÛ½ü1300Íò¸öDailyQuizÓû§µÄÐÅÏ¢


4.jpg


The Record³Æ£¬£¬£¬ºÚ¿ÍÇÔÈ¡ÁË1300Íò¸öDailyQuizÓû§µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨830Íò¸öÕË»§µÄÃ÷ÎÄÃÜÂë¡¢µç×ÓÓʼþºÍIPµØµã£¬£¬£¬²¢ÒÔԼĪ2000ÃÀÔª¼ÓÃÜÇ®±ÒµÄ¼ÛÇ®³öÊÛ¡£¡£¡£¡£¡£µ«ÏÖÔÚÕâЩÐÅÏ¢ÔÚÇå¾²Ñо¿Ö°Ô±ÊÖÖУ¬£¬£¬¿ÉÒÔ¹ûÕæ»á¼û¡£¡£¡£¡£¡£DailyQuizµÄÓû§¿ÉÒÔͨ¹ý»á¼ûHave I been PwnedÍøÕ¾£¬£¬£¬À´ÅÌÎÊ×Ô¼ºµÄÐÅÏ¢ÊÇ·ñÒѾ­±»Ð¹Â¶¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬DailyQuiz¾Ü¾ø¶Ô´ËʽøÌ¸ÂÛ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/plaintext-passwords-of-83-million-users.html


5.GoogleÅû¶Rowhammer¹¥»÷µÄбäÖÖHalf-Double


5.jpg


GoogleµÄÑо¿Ö°Ô±Åû¶ÁËRowhammer¹¥»÷µÄбäÖÖHalf-Double¡£¡£¡£¡£¡£´ËÀ๥»÷·¢Ã÷ÓÚ2014Äê,ͨ¹ýÖØ¸´»á¼û´æ´¢ÐпÉÄÜ»áÒýÆð×ãÒÔÈÅÂÒ´æ´¢ÔÚÏàÁÚÐÐÖеĵç×Ó×ÌÈÅ£¬£¬£¬´Ó¶øÔÊÐí²»ÊÜÐÅÈεĴúÂëÈÆ¹ýɳÏä²¢½ÓÊÜ¿ØÖÆÏµÍ³¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬¹©Ó¦ÉÌʹÓÃÄ¿µÄÐÐˢУ¨Target Row Refresh£¬£¬£¬TRR£©À´»º½â´ËÀ๥»÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬ÐµÄHalf-Double¹¥»÷ʹÓÃÁ˵ײã¹è»ù°åµÄ¹ÌÓÐÌØÕ÷£¬£¬£¬¿ÉÒÔÈÆ¹ýÄ¿½ñËùÓзÀÓù²½·¥¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/05/google-researchers-discover-new-variant.html


6.°¢À­Ë¹¼ÓÎÀÉú²¿³ÆÆäÔâµ½¹¥»÷£¬£¬£¬¹ÙÍøÔÝʱÎÞ·¨»á¼û


6.jpg


ÃÀ¹ú°¢À­Ë¹¼ÓÎÀÉúºÍÉç»áЧÀͲ¿£¨DHSS£©³ÆÆäÔâµ½¶ñÒâÈí¼þ¹¥»÷£¬£¬£¬¹ÙÍøÔÝʱÎÞ·¨»á¼û¡£¡£¡£¡£¡£´Ë´Î¹¥»÷²»µ«ÖÐÖ¹ÁËDHSSÍøÕ¾£¬£¬£¬»¹Ó°ÏìÁËÐí¶àÆäËûЧÀÍ£¬£¬£¬°üÀ¨°¢À­Ë¹¼ÓÖÝÉúÃü¼Í¼ϵͳ¡¢DHSSÊ¢Ðв¡Ñ§¹«±¨ºÍѧУÏò¹«¹²ÎÀÉú±¨¸æÒßÃçÊý¾ÝµÄϵͳSAGEµÈ¡£¡£¡£¡£¡£¸ÃÖݵĹÙÔ±²¢Î´Í¸Â¶Óйع¥»÷µÄÊÖÒÕϸ½Ú£¬£¬£¬Ò²²»ÇåÎúÊÇ·ñΪÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬µ«Æä͸¶DHSSÍøÕ¾ÊÇÔÚ2021Äê5ÔÂ17ÈÕÍíÉÏÖÐÖ¹µÄ£¬£¬£¬×èÖ¹ÏÖÔÚ¸ÃÍøÕ¾ÈÔ´¦ÓÚÍÑ»ú״̬¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/05/26/alaska-health-department-site-went-offline-after-malware-attack/