Òò»ù´¡¼Ü¹¹ÅäÖÃÃýÎó΢ÈíºÍAdobeµÈÔ­Âëй¶£»£»£»£»£»£»£»£»FBIÖÒ¸æCoAP¡¢WS-DD¡¢ARMSºÍJenkins³ÉDDoS¹¥»÷ÐÂý½é

°ä²¼¹¦·ò 2020-07-28

1.Òò»ù´¡¼Ü¹¹ÅäÖÃÃýÎ󣬣¬£¬£¬£¬ £¬Î¢ÈíºÍAdobeµÈ¹«Ë¾Ô­´úÂëй¶



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÓÉÓÚ»ù´¡¼Ü¹¹ÅäÖÃÃýÎ󣬣¬£¬£¬£¬ £¬ÊýÊ®¼Ò¹«Ë¾µÄÔ´´úÂëй¶£¬£¬£¬£¬£¬ £¬Ð¹Â¶¹«Ë¾Ô̺¬Î¢Èí¡¢Adobe¡¢åÚÏë¡¢AMD¡¢¸ßͨ¡¢Ä¦ÍÐÂÞÀ­¡¢º£Ë¼£¨»ªÎªÕ¼ÓУ©¡¢Áª·¢¿Æ¼¼¡¢GE¼Òµç¡¢ÈÎÌìÌá¢Roblox¡¢µÏÊ¿Äá¡¢½­É­×ԿصȳÛÃû¹«Ë¾¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâЩй¶Êý¾ÝÊÇÓÉ¿ª·¢ÈËÔ±Tillie KottmannÍøÂçµÄ£¬£¬£¬£¬£¬ £¬Æä°µÊ¾ÔÚGitLabµÄ¹«¹²´æ´¢¿âÖÐÄܹ»ÕÒµ½´óÁ¿´ËÀàÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿£¿£¿ª·¢ÈËÔ±°µÊ¾£¬£¬£¬£¬£¬ £¬»¹Óиü¶à¹«Ë¾Ê¹ÓÃÅäÖÃÃýÎóµÄdevopsµ¼ÖÂÆäÔ´´úÂë¶³ö£¬£¬£¬£¬£¬ £¬´Ë±í£¬£¬£¬£¬£¬ £¬ËûÃÇÒ²·¢ÏÖÁËÊýǧ¼Ò¹«Ë¾Î´ÄÜÕýÈ·ÔËÐÐSonarQube£¬£¬£¬£¬£¬ £¬´Ó¶øÂ¶³öÁË»úÃÜ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/source-code-from-dozens-of-companies-leaked-online/


2.ºÚ¿ÍÔÚ°µÍøÏúÊÛ27.8ÍòInstacart¿Í»§ÐÅÏ¢£¬£¬£¬£¬£¬ £¬ÆðԴδ֪


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍÔÚ°µÍøÏúÊÛԼĪ278531¸öInstacart¿Í»§ÐÅÏ¢£¬£¬£¬£¬£¬ £¬Êý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÐÅÓþ¿¨ºÅµÄºóËÄλÊý×ֺͶ©µ¥º¹Çà¼Í¼µÈÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£Instacart·ñ¶¨Æä²úÉúÁËÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬ £¬²¢°µÊ¾¹¥»÷Õß¿ÉÄÜ»áÀûÓÃÍøÂç´¹µö»òƾ֤Ìî³ä¼¼ÊõÀ´¹¥»÷Ó×ÎÒ£¬£¬£¬£¬£¬ £¬ÒÔÇÔÊØÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£µ«ÊDz鿴Êý¾ÝµÄ°²È«×êÑÐÈËÔ±Ôò°µÊ¾£¬£¬£¬£¬£¬ £¬ÕâЩÊý¾ÝËÆºõÊÇÕæÊµµÄ£¬£¬£¬£¬£¬ £¬²¢ÇÒBuzzFeedÒѾ­Óëй¶Êý¾ÝµÄÁ½Ãû¿Í»§ÑéÖ¤¾ßÌåÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬ÕâЩÕË»§ÐÅÏ¢ÒÔÿÃû¿Í»§2ÃÀÔªµÄ¼ÛÖµÏúÊÛ¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://9to5mac.com/2020/07/23/instacart-customer-records/


3.ºÚ¿ÍÔÚ°µÍø¹«¿ª¶íÂÞ˹AvitoºÍYula¹«Ë¾µÄ60ÍòÓû§Êý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÁù¸öCSVÌåʽµÄÎļþ£¬£¬£¬£¬£¬ £¬Ã¿¸öÎļþÔ̺¬Ô¼Äª10ÍòÓû§µÄÊý¾Ý£¬£¬£¬£¬£¬ £¬ÆäÖÐÈý¸öÊý¾Ý¿âÔ̺¬AvitoÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬Áí±íÈý¸öÔ̺¬YulaÓû§µÄÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâЩй¶Êý¾ÝÓйØÓû§µÄ¾ÓסµØÓò¡¢µç»°ºÅÂë¡¢µØÖ·¡¢²úÆ·Àà±ðºÍÊ±ÇøµÄÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£Yula°µÊ¾£¬£¬£¬£¬£¬ £¬Ð¹Â¶µÄÎļþ²»Ô̺¬Óû§µÄÓ×ÎÒÊý¾Ý£¬£¬£¬£¬£¬ £¬ÊÇÈκÎÈ˶¼Äܹ»Ö±½Ó´ÓÍøÕ¾»òͨ¹ý½âÎö¸æ°×»ñµÃµÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬AvitoÔòÒÔΪÊý¾Ý¿âÖÐÔ̺¬µÄÓû§Êý¾ÝÊǹ«¿ªµÄ¡£ ¡£¡£¡£¡£¡£¡£¡£AecurionÖ¸³ö£¬£¬£¬£¬£¬ £¬ÕâЩÊý¾ÝÉõÖÁ¿ÉÄÜÊÇÊÖ¹¤ÍøÂçµÄ£¬£¬£¬£¬£¬ £¬²¢ÇÒÄܹ»±»ºÚ¿ÍÀûÓýøÐÐÉç»á¹¤³Ì¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/07/databases-of-users-of-russian-ad.html


4.CISAºÍNCSC½áºÏÖҸ棬£¬£¬£¬£¬ £¬6.2ÍòQNAP NASÉ豸ÒÑϰȾQSnatch


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úCISAºÍÓ¢¹úNCSC½áºÏ·¢³öµÄ°²È«¾¯±¨£¬£¬£¬£¬£¬ £¬°µÊ¾ÒÑÓÐ62000̨QNAPÍøÂçÏνӴ洢£¨NAS£©É豸ϰȾ¶ñÒâÈí¼þQSnatch¡£ ¡£¡£¡£¡£¡£¡£¡£QSnatchÓÚ2019Äêµ×³õ´Î·¢ÏÖ£¬£¬£¬£¬£¬ £¬»ã±¨µÄϰȾÊýÁ¿´Ó2019Äê10ÔµÄ7000̨É豸Ôö³¤µ½2020Äê6ÔÂÖеÄ62000̨£¬£¬£¬£¬£¬ £¬ÆäÖÐ7600̨λÓÚÃÀ¹ú£¬£¬£¬£¬£¬ £¬3900̨λÓÚÓ¢¹ú¡£ ¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖгöÏÖÁ˶ñÒâÈí¼þQSnatchµÄбäÌ壬£¬£¬£¬£¬ £¬ËüÓµÓÐCGIÃÜÂë¼Í¼ְÄÜ¡¢Æ¾Ö¤ÇÔȡְÄÜ¡¢SSHºóÃÅ¡¢ÉøÈëÖ°ÄÜÒÔ¼°ÓÃÓÚÔ¶³Ì½Ó¼ûµÄWebshellÖ°ÄÜ¡£ ¡£¡£¡£¡£¡£¡£¡£CISAºÍNCSC½áºÏ¶½´Ù¹«Ë¾£¬£¬£¬£¬£¬ £¬¾¡¿ì½¨¸´QNAP NASÉ豸¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisa-says-62000-qnap-nas-devices-have-been-infected-with-the-qsnatch-malware/#ftag=RSSbaffb68


5.FBIÖÒ¸æCoAP¡¢WS-DD¡¢ARMSºÍJenkins³ÉΪDDoS¹¥»÷ÐÂý½é


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


FBI·¢³ö¾¯±¨£¬£¬£¬£¬£¬ £¬·¢ÏÖCoAP£¨ÊÜÔ¼ÊøµÄÀûÓúÍ̸£©¡¢WS-DD£¨Web·þÎñ¶¯Ì¬·¢ÏÖ£©¡¢ARMS£¨AppleÔ¶³ÌÖÎÀí·þÎñ£©ºÍ»ùÓÚWebµÄ×Ô¶¯»¯Èí¼þJenkinsÒѱ»ÀÄÓÃÓÚÌáÒé´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£2018Äê12Ô£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÆðÍ·ÀÄÓÃCoAP½øÐÐDDoS·´ÉäºÍ·Å´ó¹¥»÷£¬£¬£¬£¬£¬ £¬·Å´ó±¶ÊýΪ34£»£»£»£»£»£»£»£»2019Äê5ÔºÍ8Ô£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÀûÓÃWS-DDºÍ̸ÌáÒéÁË130¶àÖÖDDoS¹¥»÷£¬£¬£¬£¬£¬ £¬ÆäÖÐÁ½´Î¹¥»÷±ðÀë´ïµ½ÁËÿÃë350GbpsÒÔÉϹæÄ££»£»£»£»£»£»£»£»2019Äê10Ô£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÀûÓÃARMS½øÐÐDDoS·Å´ó¹¥»÷£»£»£»£»£»£»£»£»2020Äê2Ô£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖJenkins¿ÉÓÃÀ´½øÐÐDDoS·Å´ó¹¥»÷µÄÈí¼þ¿ª·¢£¬£¬£¬£¬£¬ £¬¿É·Å´ó100±¶DDoS¹¥»÷Á÷Á¿¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-warns-of-new-ddos-attack-vectors-coap-ws-dd-arms-and-jenkins/#ftag=RSSbaffb68


6.×êÑÐÍŶӷ¢ÏÖºÚ¿ÍÀûÓÃÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þValak


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


´Ó2020Äê4Ôµ½6Ô£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖºÚ¿Í×éÖ¯Shathak£¨»òTA551£©ÀûÓÃÀ¬»øÓʼþ»î¶¯´óÁ¿·Ö·¢¶ñÒâÈí¼þValak¡£ ¡£¡£¡£¡£¡£¡£¡£ValakÊÇÐÅÏ¢ÇÔÈ¡Æ÷ºÍ¶ñÒâÈí¼þ¼ÓÔØÆ÷£¬£¬£¬£¬£¬ £¬ÓÚÔÚ2019Äêµ×³õ´Î±»·¢ÏÖ¡£ ¡£¡£¡£¡£¡£¡£¡£ÆäÒÀÀµÓÚ¹¤×÷´òËãºÍWindows×¢²á±í¸üÐÂÔÚWindowsÖ÷»úÉÏÂñ·ü£¬£¬£¬£¬£¬ £¬Ê¹ÓôúÌæÊý¾ÝÁ÷(ADS)ÔÚÊÜϰȾµÄÖ÷»úÉÏÔËÐкóÐø¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬Ê¹Óõĸü¶àµÄ»ìºÏ´úÂëÒÔÔ¤·À±»·¢ÏÖ¡£ ¡£¡£¡£¡£¡£¡£¡£×î½ü¼¸¸öÔ£¬£¬£¬£¬£¬ £¬Valakͨ¹ý¶ñÒâÀ¬»øÓʼþ·Ö·¢£¬£¬£¬£¬£¬ £¬Í¨¹ýÒÔ.cab½áβµÄhttp»òhttpsÁ´½Ó×°Öᣠ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/valak-evolution/