Íþ¸Õ¿Æ¼¼³ÆÆäÔâµ½Ragnar Locker¹¥»÷£»£»£»£»£»£»£»Fastly CDNÖÐÖ¹£¬£¬£¬£¬Amazon¡¢RedditºÍGitHubµÈå´»ú

Ðû²¼Ê±¼ä 2021-06-10

1.KasperskyÅû¶PuzzleMakerÕë¶ÔÈ«ÇòµÄ¹¥»÷»î¶¯


1.jpg


KasperskyÅû¶ÐºڿÍÍÅ»ïPuzzleMakerÕë¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓÃÁ˹ȸèChromeÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21224£©£¬£¬£¬£¬Ö®ºóʹÓÃWindowsÄÚºËÖеÄÐÅϢй¶Îó²îºÍWindows NTFSÌáȨÎó²î£¨CVE-2021-31956£©ÌÓ×ßɳÏä²¢»ñµÃϵͳȨÏÞ¡£¡£¡£¡£¡£¡£Kaspersky³ÆPuzzleMakerµÄ¹¥»÷»î¶¯×îÔçÊÇÔÚ4ÔÂÖÐÑ®·¢Ã÷µÄ£¬£¬£¬£¬²¢ÌåÏÖÏÖÔÚÎó²î²¹¶¡ÒѾ­¿ÉÓ㬣¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üÐÂä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/chrome-windows-zero-day/40191/


2.Î÷°àÑÀÀͶ¯ºÍÉç»á¾­¼Ã²¿MITES³ÆÆäÔâµ½ÍøÂç¹¥»÷


2.jpg


Î÷°àÑÀÀͶ¯ºÍÉç»á¾­¼Ã²¿ (MITES)³ÆÆäÓÚÖÜÈýÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬ÕýÔÚÆð¾¢»Ö¸´ÊÜÓ°ÏìµÄЧÀÍ¡£¡£¡£¡£¡£¡£MITESµÄÄê¶ÈÔ¤Ëã¿¿½ü3900ÍòÅ·Ôª£¬£¬£¬£¬ÈÏÕæÐ­Ð­µ÷¼àÊÓÎ÷°àÑÀµÄ¾ÍÒµ¡¢Éç»á¾­¼ÃºÍÆóÒµÉç»áÔðÈÎÕþ²ß¡£¡£¡£¡£¡£¡£¸Ã²¿ÌåÏÖ£¬£¬£¬£¬´Ë´Î¹¥»÷µ¼ÖÂͨѶÊҺͶàýÌåÊҵIJ»¿ÉÓ㬣¬£¬£¬¿ÉÊÇÆä¹Ù·½µÄÍøÕ¾ÈÔÔÚÕý³£ÔËÐС£¡£¡£¡£¡£¡£ÕâÊǹ¤µ³ÔÚ½ñÄêÔâµ½µÄµÚ¶þ´ÎÍøÂç¹¥»÷£¬£¬£¬£¬ÔçÔÚ3Ô£¬£¬£¬£¬¹ú¼Ò¹«¹²¾ÍҵЧÀÍ¾Ö (SEPE)¾ÍÔâµ½ÁËRyukÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118768/hacking/spains-ministry-of-labor-cyberattack.html


3.Íþ¸Õ¿Æ¼¼Ôâµ½Ragnar Locker¹¥»÷£¬£¬£¬£¬Ð§ÀÍÔÝʱÖÐÖ¹


3.jpg


Öйų́ÍåµÄÍþ¸Õ¿Æ¼¼£¨ADATA£©Ôâµ½Ragnar Locker¹¥»÷£¬£¬£¬£¬Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£ADATAÖ÷ÒªÉú²ú¸ßÐÔÄÜDRAMÄÚ´æÄ£¿£¿£¿£¿£¿£¿£¿éºÍNANDÉÁ´æ¿¨µÈ²úÆ·£¬£¬£¬£¬ÔÚ2018Äê±»ÆÀΪµÚ¶þ´óDRAMÄÚ´æºÍ¹Ì̬ӲÅÌ (SSD) ÖÆÔìÉÌ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÉùÃ÷ÖÐ³ÆÆäÔÚ5ÔÂ23ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬Ö®ºóÁ¬Ã¦¹Ø±ÕÁËËùÓÐÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£Ragnar LockerÓÚÉÏÖÜÄ©³ÆÆäÔÚADATAµÄÍøÂçÖÐÇÔÈ¡ÁË1.5TBÊý¾Ý£¬£¬£¬£¬°üÀ¨×¨ÓÐÉÌÒµÐÅÏ¢¡¢ÉñÃØÎļþ¡¢Ô­Àíͼ¡¢²ÆÎñÊý¾Ý¡¢GitlabºÍSVNÔ´´úÂë¡¢Ö´·¨Îļþ¡¢Ô±¹¤ÐÅÏ¢¡¢±£ÃÜЭæÅºÍÊÂÇéÎļþ¼ÐµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/computer-memory-maker-adata-hit-by-ragnar-locker-ransomware/


4.Fastly CDNÖÐÖ¹£¬£¬£¬£¬Amazon¡¢RedditºÍGitHubµÈå´»ú


4.jpg


Fastly CDNÖÐÖ¹µ¼ÖÂÈ«Çò¹æÄ£ÄÚ¶à¼Ò¹«Ë¾µÄÍøÕ¾ÍêÈ«¹Ø±Õ»òÕßÎÞ·¨Õý³£¼ÓÔØ¡£¡£¡£¡£¡£¡£´Ë´ÎÊܵ½Ó°ÏìµÄ¹«Ë¾°üÀ¨Amazon¡¢Amazon Web Services (AWS)¡¢ÃÀ¹úÓÐÏßµçÊÓÐÂÎÅÍø¡¢Ó¢¹úÕþ¸®¡¢GitHub¡¢ShopifyºÍRedditµÈ¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÍøÕ¾¶¼»áÏÔʾ¡°ÅþÁ¬Ê§°Ü¡±¡¢¹ýʧ¡¢¡°IO ¹ýʧ¡±»òHTTP 503´úÂë¡£¡£¡£¡£¡£¡£¾­ÓÉ×îÖÕÊӲ죬£¬£¬£¬´Ë´ÎÖÐÖ¹ÊÇÓÉÓÚ¿Í»§ÉèÖøü¸Ä¶ø´¥·¢µÄÒ»¸öÈí¼þ¹ýʧµ¼ÖµÄ£¬£¬£¬£¬ÏÖÔÚÎÊÌâÒѾ­½â¾ö¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/stackoverflow-twitch-reddit-others-down-in-fastly-cdn-outage/


5.FBIºÍAFPαÔì¼ÓÃÜ̸ÌìÆ½Ì¨Anom×¥²¶800¶àÃûÏÓÒÉ·¸


5.jpg


ÔÚÆù½ñΪֹ¹æÄ£×î´ó¡¢×îÖØ´óµÄÖ´·¨Ðж¯Trojan Shield£¨ÓÖ³ÆIronside£©ÖУ¬£¬£¬£¬FBIºÍ°Ä´óÀûÑÇÁª°î¾¯Ô±Î±ÔìÁ˼ÓÃÜ̸ÌìÆ½Ì¨Anom²¢×¥²¶800¶àÃûÏÓÒÉ·¸¡£¡£¡£¡£¡£¡£ÔçÔÚÈýÄêǰִ·¨²¿·ÖαÔìÁ˸ö˵½¶Ë¼ÓÃÜ̸ÌìÆ½Ì¨£¬£¬£¬£¬×¨ÃųöÊÛ¸ø·¸·¨·Ö×Ó£¬£¬£¬£¬Ö¼ÔÚ¼àÌýËûÃǵÄÐÂÎźͶԻ°£¬£¬£¬£¬Îª100¶à¸ö¹ú¼ÒµÄ300¶à¸ö·¸·¨¼¯ÍÅÌṩÁè¼Ý1.2Íǫ̀¼ÓÃÜ×°±¸¡£¡£¡£¡£¡£¡£Ö´·¨²¿·ÖÔÚÉó²éÁË2700ÍòÌõÐÅÏ¢ºó¾Ð²¶800¶àÏÓ·¸£¬£¬£¬£¬½É»ñÁËÁè¼Ý4800ÍòÃÀÔª¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/800-arrest-fbi-anom-app-honeypot/


6.Ó¢ÌØ¶ûÐû²¼6Ô·ÝÇå¾²¸üУ¬£¬£¬£¬×ܼÆÐÞ¸´73¸öÇå¾²Îó²î


6.jpg


Ó¢ÌØ¶ûÐû²¼ÁË6Ô·ÝÇå¾²¸üУ¬£¬£¬£¬×ܼÆÐÞ¸´ÁË73¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇIntel VT-d²úÆ·ÖÐÍâµØÌáȨÎó²î£¨CVE-2021-24489£©ºÍCPU BIOS¹Ì¼þÖÐÓɲ»×¼È·µÄ³õʼ»¯¡¢¾ºÕùÌõ¼þ¡¢²»×¼È·µÄÊäÈëÑéÖ¤ºÍ¿ØÖÆÁ÷ÖÎÀíȱ·¦µ¼ÖµÄ4¸öÌáȨÎó²î£¨CVE-2020-12357¡¢CVE-2020-8670¡¢CVE-2020-8700ºÍCVE-2020-12359£©¡£¡£¡£¡£¡£¡£Ó¢Ìضû³Æ´Ë´ÎÐÞ¸´µÄÎó²îÖеÄ40¸ö(Ô¼55%)ÊÇͨ¹ýÆä¹«Ë¾ÄÚ²¿µÄ×Ô¶¯Çå¾²Ñо¿·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-fixes-73-vulnerabilities-in-june-2021-platform-update/