MikroTik¹«¿ªDDoS½©Ê¬ÍøÂ磺Unit 42°ä²¼ÒÔÓÎÀÀÖ÷ÌâµÄ´¹µö»î¶¯
°ä²¼¹¦·ò 2021-09-18Anonymous³ÆÒÑÇÔÈ¡ÍйÜÔËÓªÉÌEpik½üÊ®ÄêµÄÊý¾Ý

AnonymousÔÚ9ÔÂ15ÈÕÐû³ÆÒÑÇÔÈ¡ÍйÜÔËÓªÉÌEpik½üÊ®ÄêµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚDDoSecretsÉϹ«¿ª¡£¡£¡£¡£¡£¡£¡£¡£EpikµÄ¿Í»§Ô̺¬Parler¡¢Gab¡¢The DonaldºÍprolifewhistleblower.comµÈ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÊÇEPIKFAILÐж¯µÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬×ܼÆÇÔÈ¡ÁËÔ¼180GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÕË»§Æ¾Ö¤¡¢WHOISº¹Çà¡¢DNS¸ü¸Ä¡¢Git´æ´¢¿âºÍÖ÷ÌâϵͳµÄ/home/ºÍ/root/Ŀ¼µÈ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÔøÔÚÉÏÖÜÈëÇÖÁËGOP£¨µÂ¿ËÈøË¹¹²ºÍµ³£©µÄ¹Ù·½ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/anonymous-steals-far-right-web-host-epik-data/
ÃÀ¹úDesert WellsÒ½ÔºEHRϵͳÔâµ½¹¥»÷ÇÒÊý¾ÝÃÔʧ

ÃÀ¹úÑÇÀûÉ£ÄÇÖݵÄÒ½ÔºDesert Wells Family Medicine³ÆÆäµç×Ó½¡È«¼Í¼(EHR)ϵͳÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ5ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¼´±ã¸ÃÒ½ÔºÔÚ¹¥»÷²úÉúǰ±¸·ÝÁËEHRÖеÄËùº±¼û¾Ý£¬£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷Õß¶ÔÁ½¸öϵͳÖеÄÊý¾Ý¾ù½øÐÐÁ˼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃϵͳÖеÄËùÓÐEHRÐÅÏ¢¶¼ÒÑÓÀÔ¼ûÔʧ¡£¡£¡£¡£¡£¡£¡£¡£Desert Wells°µÊ¾ÒѾ¡ÆäËùÄܸ´ÔÊý¾Ýµ«Ã»ÓÐÈκÎ×÷Ó㬣¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚ¹¹½¨È«ÐµÄEHRϵͳ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÆäÒÑ֪ͨ35000¸ö»¼ÕßËûÃǵĽ¡È«ÐÅÏ¢¿ÉÄÜÒѾй¶¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/arizona-medical-practice-loses-ehr/
MikroTik¹«¿ªDDoS½©Ê¬ÍøÂçM¨¥ris»î¶¯µÄ¾ßÌåÐÅÏ¢

ÀÍÑάÑÇÍøÂçÉ豸Ôì×÷ÉÌMikroTikÔÚ9ÔÂ15ÈÕ¹«¿ªÁËM¨¥ris¹¥»÷»î¶¯µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£MicroTik½²»°È˳ƣ¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ʹÓõÄ·ÓÉÆ÷Óë2018Äê±»ÈëÇֵķÓÉÆ÷Ò»Ñù£¬£¬£¬£¬£¬£¬£¬£¬ÆäʱMikroTik RouterOSÖдæÔÚÒ»¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã·ì϶ºÜ¿ì¾Í±»½¨¸´ÁË¡£¡£¡£¡£¡£¡£¡£¡£²»Íâ½ö½¨¸´·ì϶²¢²»Äܱ£»£»£»£»£»£»£»£»¤Â·ÓÉÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹¥»÷ÕßÔÚ2018Äê¾Í»ñµÃÁËÓû§µÄÍ´´¦¡£¡£¡£¡£¡£¡£¡£¡£MicroTik½¨ÒéÓû§¶¨ÆÚÉý¼¶É豸£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ê¹ÓÃÇ¿ÃÜÂë²¢¶¨ÆÚ¸ü»»µÈ´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mikrotik-shares-info-on-securing-routers-hit-by-massive-m-ris-botnet/
°²È«¹«Ë¾Bitdefender°ä²¼ÀÕË÷Èí¼þREvilÖ÷½âÃÜÆ÷

°²È«¹«Ë¾Bitdefender°ä²¼ÁËÕë¶ÔÀÕË÷Èí¼þREvilÖ÷½âÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Bitdefender³Æ¸Ã½âÃÜÆ÷ÊÇÓÉÆäºÍij·¨Âɲ¿ÃźÏ×÷¿ª·¢µÄ£¬£¬£¬£¬£¬£¬£¬£¬ºÏÓÃÓÚ7ÔÂ13ÈÕ֮ǰÔâµ½REvil¹¥»÷µÄËùÓÐÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£BleepingComputer×êÑÐÈËÔ±ÀûÓýñÄêÔçЩʱ³½µÄREvilÑù±¾¶ÔÆä½øÐÐÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬È·¶¨Ã»ÓÐÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£7Ô·Ýʱ£¬£¬£¬£¬£¬£¬£¬£¬KaseyaÒ²Ôø»ñµÃÁËREvil½âÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹¤¾ßÖ»ºÏÓÃÓÚÕë¶ÔKaseyaµÄ¹¥»÷»î¶¯µÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/free-revil-ransomware-master-decrypter-released-for-past-victims/
΢ÈíÅû¶½üÆÚÀûÓÃMSHTML·ì϶µÄ´¹µö¹¥»÷»î¶¯

΢ÈíÔÚ9ÔÂ15Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÆäÍþвµý±¨ÖÐÐÄÔÚ8Ô·ݷ¢ÏÖÁËÉÙÁ¿Í¨¹ýÌØÔìMicrosoftOfficeÎĵ·ûÓÃMSHTMLÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40444£©µÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÀûÓÃÁ˽»¸¶»úÔ죬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÍйÜÔÚÎļþ¹²ÏíÕ¾µãÉϵĺÏͬºÍ˾·¨ºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹָ±êÏÂÔØCabinet¹éµµÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔ̺¬Ò»¸öÀ©´óÃûΪINFµÄDLL£¬£¬£¬£¬£¬£¬£¬£¬¸ÃDLL½«¼ìË÷²¢ÏÂÔØÔ¶³ÌÍйܵÄshellcode¡£¡£¡£¡£¡£¡£¡£¡£Î¢Èí½«Õâ´Î»î¶¯¹éÒòÓÚºÚ¿Í×éÖ¯DEV-0413ºÍDEV-0365¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/09/windows-mshtml-0-day-exploited-to.html
Unit 42°ä²¼ÒÔÓÎÀÀΪÖ÷ÌâµÄ´¹µö»î¶¯µÄ·ÖÎö»ã±¨

Unit 42ÓÚ9ÔÂ15ÈÕ°ä²¼ÁËÒÔÓÎÀÀΪÖ÷ÌâµÄ´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎöÁË2019Äê10ÔÂÖÁ2021Äê8Ô´´½¨µÄÒÔÓÎÀÀΪÖ÷ÌâµÄ´¹µöURL£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÊýÁ¿³ÊÖð²½ÉÏÉýµÄÇ÷Ïò£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ2021Äê6Ô³öÏÖÏÔÖøÔö³¤¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÌṩÁËDridexÔÚ2021ÄêʹÓõĴøÓÓ×°º½¿Õ¹«Ë¾¡±ºÍ¡°¼ÙÆÚ¡±¹Ø¼ü´ÊµÄ´¹µö»î¶¯µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬·ÖÎö·¢ÏÖ¹¥»÷Õßͨ³£ÀûÓÃGoogle FirebaseÓòÀ´ºýŪָ±ê²¢Èƹý°²È«¹ýÂËÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/travel-themed-phishing/


¾©¹«Íø°²±¸11010802024551ºÅ