ºÚ¿ÍÔÚ°µÍø³öÊÛ 4900 Íò·Ý´÷¶ûµÄ¿Í»§Êý¾Ý
Ðû²¼Ê±¼ä 2024-05-115ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬¿Æ¼¼¾ÞÍ·´÷¶û¹«Ë¾ÒÑÏòÆä¿Í»§×ª´ïÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶ӰÏìÁË´æ´¢¿Í»§ÐÅÏ¢¼°ÆäÔÚ´÷¶ûµÄ¹ºÖÃÀúÊ·¼Í¼µÄ´÷¶ûÃÅ»§ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°Ïì¿Í»§µÄÊýÄ¿£¬£¬£¬£¬£¬£¬µ«ÊÂÎñÖÐй¶µÄÊý¾Ý°üÀ¨£ºÈ«Ãû¡¢ÏÖʵµØµã¡¢´÷¶ûÓ²¼þºÍ¶©µ¥ÐÅÏ¢£¬£¬£¬£¬£¬£¬°üÀ¨Ð§ÀͱêÇ©¡¢ÉÌÆ·ÐÎò¡¢¶©¹ºÈÕÆÚºÍÏà¹Ø±£ÐÞÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÐèҪǿµ÷µÄÊÇ£¬£¬£¬£¬£¬£¬ËäÈ»´÷¶û±¨¸æµÄÊý¾Ýй¶ÊÂÎñÓë Menelik µÄ˵·¨Ö®¼äµÄÁªÏµÉÐδ»ñµÃ֤ʵ£¬£¬£¬£¬£¬£¬µ«ºÚ¿Í¼á³ÆÕâȷʵÊÇͳһÆðй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢ÌṩÁËÓйØÐ¹Â¶Êý¾ÝµÄ¸ü¶àÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬Menelik Éù³ÆÒÑ»ñÈ¡Áè¼Ý 4900 Íò´÷¶û¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´÷¶ûÒѽÓÄɶàÏî²½·¥À´Ó¦¶Ô´Ë´ÎÇå¾²ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ËûÃÇÒÑִ֪ͨ·¨²¿·Ö²¢Ô¼ÇëµÚÈýÒªÁìÒ½¹«Ë¾ÊÓ²ì¸ÃÊÂÎñ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜËûÃÇÌåÏÖ²»ÒÔΪÓÉÓÚÓÐÏÞµÄÐÅϢй¶¶ø±£´æÖØ´óΣº¦£¬£¬£¬£¬£¬£¬µ«°üÀ¨È«ÃûºÍÎïÀíµØµãµÄÊý¾ÝµÄÏúÊÛ¶Ô¿Í»§×é³ÉÁËÏ൱´óµÄÍþв¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/dell-data-breach-hacker-sells-customer-data/
2. ²¨Òô¹«Ë¾Ö¤ÊµÔøÔâLockbit¹¥»÷±»Ë÷Òª2ÒÚÃÀÔªÊê½ð
5ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬²¨Òô¹«Ë¾Ö¤Êµ£¬£¬£¬£¬£¬£¬²¨Òô¹«Ë¾¾Ü¾øÖ§¸¶ 2 ÒÚÃÀÔªÊê½ð£¬£¬£¬£¬£¬£¬ÒÔ»»È¡ºÚ¿ÍÇÔÈ¡µÄ 43GB Êý¾Ý¡£¡£¡£¡£¡£¡£¡£²¨Òô¹«Ë¾ÓÚ 2023 Äê 10 ÔÂÔâµ½ LockBit ÀÕË÷Èí¼þÍÅ»ïµÄºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÍþвҪй¶ÆäËù˵µÄ´ó×ÚÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£LockBit ×îÖÕÐû²¼Á˴˴κڿ͹¥»÷µÄÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨ IT ÖÎÀíÈí¼þ¡¢¼à¿ØÈÕÖ¾ºÍÉ󼯹¤¾ß¡£¡£¡£¡£¡£¡£¡£Æß¸öÔº󣬣¬£¬£¬£¬£¬Ë¾·¨²¿¶Ô Lockbit ²ß»®ÕßµÏÃ×ÌØÀÓÈÀïÒ®Î¬Ææ¡¤»ôÂÞÉá·ò (Dimitry Yuryevich Khoroshev) µÄδÃÜ·âÆðËßÊéÌáµ½£¬£¬£¬£¬£¬£¬Ò»¼Òδ͸¶ÐÕÃûµÄ¡°×ܲ¿Î»ÓÚ¸¥¼ªÄáÑÇÖݵĿç¹úº½¿ÕºÍ¹ú·À¹«Ë¾¡±ÊÇ Lockbit µÄ 2 ÒÚÃÀԪĿµÄ¡£¡£¡£¡£¡£¡£¡£²¨Òô¹«Ë¾ËæºóÏò CyberScoop ֤ʵ£¬£¬£¬£¬£¬£¬Õâ¾ÍÊÇÄǼÒδ͸¶ÐÕÃûµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£Khoroshev Ò²±»³ÆÎª LockBitSupp£¬£¬£¬£¬£¬£¬ÈÏÕæ½¨ÉèºÍÔËÓª LockBit ×éÖ¯£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÓµÓÐ 2,000 ¶àÃûÊܺ¦ÕßºÍ 5 ÒÚÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä£¬£¬£¬£¬£¬£¬Ö´·¨²¿·Ö²¿·ÖÈ¡µÞÁË Lockbit µÄÓªÒµ£¬£¬£¬£¬£¬£¬²¢ÓÚ±¾ÖÜÔçЩʱ¼äÊջظü¶àÓªÒµ¡£¡£¡£¡£¡£¡£¡£
https://news.hitb.org/content/boeing-confirms-lockbit-hackers-wanted-200-million-ransom-after-2023-hack
3. BIG-IP ×°±¸ÖеÄÒªº¦Îó²îʹ´óÐÍÍøÂçÈÝÒ×Êܵ½ÈëÇÖ
5ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±±¨¸æÁËÒ»ÖÖÆÕ±éʹÓõÄÍøÂç×°±¸ÖеÄÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îʹÌìÏÂÉÏһЩ×î´óµÄÍøÂçÈÝÒ×Êܵ½ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î±£´æÓÚ BIG-IP Next Central Manager ÖУ¬£¬£¬£¬£¬£¬¸ÃÖÎÀíÆ÷ÊÇ×îÐÂÒ»´ú BIG-IP ϵÁÐ×°±¸ÖеÄÒ»¸ö×é¼þ£¬£¬£¬£¬£¬£¬×éÖ¯ÓÃÀ´ÖÎÀíÊÕÖ§ÆäÍøÂçµÄÁ÷Á¿¡£¡£¡£¡£¡£¡£¡£ÏúÊ۸òúÆ·µÄ×ܲ¿Î»ÓÚÎ÷ÑÅͼµÄ F5ÌåÏÖ£¬£¬£¬£¬£¬£¬ ¡¶²Æ²ú¡·ÔÓÖ¾×·×ÙµÄ 50 Ç¿ÆóÒµÖÐÓÐ 48 ¼ÒʹÓÃÆä×°±¸¡£¡£¡£¡£¡£¡£¡£F5½« Next Central ManagerÐÎòΪ¡°¼òµ¥¼¯ÖпØÖƵ㡱£¬£¬£¬£¬£¬£¬ÓÃÓÚÖÎÀíÕû¸ö BIG-IP ×°±¸Èº¡£¡£¡£¡£¡£¡£¡£×÷ΪִÐиºÔØÆ½ºâ¡¢DDoS »º½âÒÔ¼°¶ÔÊÕÖ§´óÐÍÍøÂçµÄÊý¾Ý¾ÙÐмì²éºÍ¼ÓÃܵÄ×°±¸£¬£¬£¬£¬£¬£¬BIG-IP ×°±¸Î»ÓÚÆäÍâΧ£¬£¬£¬£¬£¬£¬³äµ±ÄÚ²¿Ä³Ð©×îÇå¾²Òªº¦×ÊÔ´µÄÖ÷Òª¹ÜµÀ¡£¡£¡£¡£¡£¡£¡£ÕâÐ©ÌØÕ÷ʹ BIG-IP ×°±¸³ÉΪºÚ¿Í¹¥»÷µÄÀíÏëÑ¡Ôñ¡£¡£¡£¡£¡£¡£¡£2021 ÄêºÍ2022Ä꣬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÑÏÖØÆ·¼¶Îª 9.8£¨Âú·Ö 10£©µÄÎó²îÆð¾¢ÆÆËð BIG-IP ×°±¸¡£¡£¡£¡£¡£¡£¡£
https://arstechnica.com/security/2024/05/critical-vulnerabilities-in-big-ip-appliances-leave-big-networks-open-to-intrusion/
4. ¿¨°Í˹»ùÐû²¼ 2023 ÄêÄê¶È½ðÈÚÍþв±¨¸æ
5ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù×îÐÂÐû²¼µÄ 2023 ÄêÄê¶È½ðÈÚÍþв±¨¸æÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬Óë 2022 ÄêÏà±È£¬£¬£¬£¬£¬£¬È«ÇòÒÆ¶¯ÒøÐжñÒâÈí¼þÔöÌíÁË 32%¡£¡£¡£¡£¡£¡£¡£±¨¸æÇ¿µ÷Õë¶Ô Android Óû§µÄ¹¥»÷¼¤Ôö£¬£¬£¬£¬£¬£¬ÆäÖа¢¸»º¹¡¢ÍÁ¿âÂü˹̹ºÍËþ¼ª¿Ë˹̹ÔâÓöÒøÐÐľÂíµÄ±ÈÀý×î¸ß¡£¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬ÍÁ¶úÆäÔÚÒÆ¶¯ÒøÐжñÒâÈí¼þ¹¥»÷·½Ãæ´¦ÓÚÁìÏÈְ룬£¬£¬£¬£¬£¬Ó°ÏìÁ˽ü 3% µÄÓû§¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü½ðÈÚ PC ¶ñÒâÈí¼þÊýĿϽµÁË 11%£¬£¬£¬£¬£¬£¬µ«À´×Ô Ramnit ºÍ Zbot µÈ¶ñÒâÈí¼þ¼Ò×åµÄÍþвÈÔÈ»±£´æ£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÏûºÄÕß¡£¡£¡£¡£¡£¡£¡£½ðÈÚÍøÂç´¹ÂÚÈÔÈ»ÊÇÒ»¸öÖØ´óÎÊÌ⣬£¬£¬£¬£¬£¬Õ¼Õë¶ÔÆóÒµÓû§µÄËùÓÐÍøÂç´¹ÂÚ¹¥»÷µÄËÄ·ÖÖ®Ò»ÒÔÉÏ£¬£¬£¬£¬£¬£¬ÒÔ¼°Õë¶Ô¼ÒÍ¥Óû§µÄ½üÈý·ÖÖ®Ò»¡£¡£¡£¡£¡£¡£¡£µç×ÓÊÐËÁÆ·ÅÆÊǽðÈÚÍøÂç´¹ÂÚʵÑéµÄ×î´óÓջ󣬣¬£¬£¬£¬£¬½ö PayPal ÍøÂç´¹ÂÚ¾ÍÕ¼ËùÓÐʵÑéµÄÒ»°ëÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£Óë¼ÓÃÜÇ®±ÒÏà¹ØµÄÍøÂç´¹ÂÚºÍÕ©ÆÕýÔÚÔöÌí¡£¡£¡£¡£¡£¡£¡£ 2023 Ä꣬£¬£¬£¬£¬£¬¿¨°Í˹»ù×èÖ¹ÁËÁè¼Ý 580 Íò´Î×·×ÙÒÔ¼ÓÃÜÇ®±ÒΪÖ÷ÌâµÄÍøÂç´¹ÂÚÁ´½ÓµÄʵÑ飬£¬£¬£¬£¬£¬±ÈÉÏÒ»ÄêÔöÌíÁË 16%¡£¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬¾ÍÍøÂç´¹ÂÚʵÑé¶øÑÔ£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·³ÉΪ±»Ä£Äâ×î¶àµÄÔÚÏßÊÐËÁ£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÆ»¹ûºÍ Netflix¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/mobile-banking-malware-surges-32/
5. MIRAIͨ¹ýʹÓÃIVANTI CONNECT SECUREÎó²î¾ÙÐÐÈö²¥
5ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬Juniper ÍþвʵÑéÊÒµÄÑо¿Ö°Ô±±¨¸æ³Æ£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýÔÚʹÓÃ×î½üÅû¶µÄ Ivanti Connect Secure (ICS) Îó²îCVE-2023-46805 ºÍ CVE-2024-21887À´É¾³ýMirai ½©Ê¬ÍøÂçµÄÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þ¹«Ë¾±¨¸æ³Æ £¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýÔÚʹÓà Connect Secure (ICS) ºÍ Policy Secure ÖеÄÁ½¸öÁãÈÕÎó²î£¨CVE-2023-46805¡¢CVE-2024-21887£©ÔÚÄ¿µÄÍø¹ØÉÏÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£CVE-2023-46805£¨CVSS ÆÀ·Ö 8.2£©ÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎÊÌ⣬£¬£¬£¬£¬£¬±£´æÓÚ Ivanti ICS 9.x¡¢22.x ºÍ Ivanti Policy Secure µÄ Web ×é¼þÖС£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔ´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬Í¨¹ýÈÆ¹ý¿ØÖƼì²éÀ´»á¼ûÊÜÏÞ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö±àºÅΪ CVE-2024-21887£¨CVSS ÆÀ·Ö 9.1£©£¬£¬£¬£¬£¬£¬ÊÇ Ivanti Connect Secure£¨9.x¡¢22.x£©ºÍ Ivanti Policy Secure Web ×é¼þÖеÄÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¾ÓÉÉí·ÝÑéÖ¤µÄÖÎÀíÔ±¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆÇëÇó²¢ÔÚ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁîÀ´Ê¹ÓøÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÁ´½ÓÕâÁ½¸öȱÏÝ£¬£¬£¬£¬£¬£¬ÏòδÐÞ²¹µÄϵͳ·¢ËÍÌØÖÆÇëÇó²¢Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/162936/cyber-crime/ivanti-connect-secure-flaws-mirai-botnet.html
6. ÃϼÓÀ¹ú IT ÌṩÉÌTappwareԼĪ50GÊý¾Ýй¶
5ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬Tappware ÊÇÒ»¼ÒÖøÃûµÄ IT ЧÀÍÌṩÉÌ£¬£¬£¬£¬£¬£¬ÆäԼĪ 50GB µÄÊý¾Ý¿âÔÚºÚ¿ÍÂÛ̳ÉÏÔ⵽й¶£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨ 230 ÍòÐÐÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨Ãô¸ÐµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈçÓë¸Ã¹«Ë¾Ïà¹ØµÄСÎÒ˽¼ÒµÄÐÕÃû¡¢µØµãºÍµç»°ºÅÂë¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÃϼÓÀ¹úÍøÂçÇå¾²Ç鱨 (BCSI)±¨¸æ£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾Ý½ÓÄÉ SQL ÃûÌ㬣¬£¬£¬£¬£¬ÈÕÆÚΪ 2024 Ä꣬£¬£¬£¬£¬£¬°üÀ¨ÆÕ±éµÄСÎÒ˽¼ÒÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬¶ÔÏà¹ØÐ¡ÎÒ˽¼Ò×é³ÉÁËÖØ´óµÄÒþ˽Σº¦¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÔÚÍøÂç·¸·¨·Ö×Ó³£ÓõÄÉúÒâ±»µÁÊý¾ÝµÄƽ̨ÉϾÙÐÐÀýÐÐ¼à¿Ø»î¶¯Ê±·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶ֱ½ÓÍþвµ½ÊýǧÈ˵ÄÒþ˽ºÍÇå¾²£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÉí·Ý͵ÇÔºÍڲơ£¡£¡£¡£¡£¡£¡£
https://gbhackers.com/bangladesh-it-provider-database/


¾©¹«Íø°²±¸11010802024551ºÅ