˼¿ÆÐû²¼2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ£»£»£»£»£»£»£»£»ÃÀ¹úÒÉËÆÔ⵽ʷÉÏ×î´ó¹æÄ£DDoS¹¥»÷

Ðû²¼Ê±¼ä 2020-06-17

1.˼¿ÆÐû²¼2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆÐû²¼ÁË2020ÄêÏÄÈÕµÄÓ¦¼±ÏìÓ¦Ç÷ÊÆ±¨¸æ¡£¡£¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷ £¬£¬£¬£¬£¬£¬µç×ÓÓʼþÈÔÈ»ÊǶñÒⲡ¶¾×îÖ÷ÒªµÄÈö²¥Ç°ÑÔ £¬£¬£¬£¬£¬£¬¶øÕë¶ÔÔ¶³Ì×ÀÃæÐ§ÀÍ£¨RDS£©ÒÔ¼°CitrixºÍPulse VPN×°±¸µÄ¹¥»÷ÓÐËùÔöÌí¡£¡£¡£¡£¡£¡£¡£ÕâÒ»¼¾¶ÈºÚ¿ÍµÄÖØµãÄ¿µÄΪҽÁƱ£½¡ºÍ¿Æ¼¼ÐÐÒµ £¬£¬£¬£¬£¬£¬ÓëÉÏÒ»¼¾¶ÈµÄ½ðÈÚЧÀͺÍÕþ¸®²¿·ÖÓÐËù²î±ð¡£¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þÊǴ˼¾¶È×îÖ÷ÒªµÄ¹¥»÷·½·¨ £¬£¬£¬£¬£¬£¬¶øRyukÒѾ­Ò»Á¬Ëĸö¼¾¶ÈÔÚÓ¦¼±ÏìÓ¦ÖÐÕ¼ÓÐÁËÍþвÁìÓòµÄÖ÷µ¼Ö°Î»¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/06/CTIR-trends-q3-2020.html


2.AT&TµÈ30¼ÒÃÀ¹ú¹«Ë¾ÒÉËÆÔâµ½´ó¹æÄ£DDoS¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


6ÔÂ15ÈÕÃÀ¹úÒÉËÆÔâµ½ÁËÆäÀúÊ·ÉÏ×î´óµÄDDoS¹¥»÷ £¬£¬£¬£¬£¬£¬Ó°ÏìÁËÃÀ¹ú¸÷µØµÄµçÐźÍÔÚÏßЧÀÍ £¬£¬£¬£¬£¬£¬²¢µ¼Ö´ó¹æÄ£¶Ïµç¡£¡£¡£¡£¡£¡£¡£¾ÝÍøÕ¾Downdetectorͳ¼Æ £¬£¬£¬£¬£¬£¬´Ë´ÎÊÜÓ°ÏìµÄ¹«Ë¾°üÀ¨T-Mobile¡¢Metro¡¢Verizon¡¢AT&T¡¢Sprint¡¢Consumer Cellular¡¢US Cellular¡¢Spectrum¡¢Comcast¡¢CenturyLink¡¢Cox¡¢Facebook¡¢Instagram¡¢SnapchatºÍTwitterµÈ¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ £¬£¬£¬£¬£¬£¬Å¦Ô¼¡¢·ðÂÞÀï´ï¡¢µÂ¿ËÈøË¹ÖÝ¡¢ÇÇÖÎÑÇÖݺͼÓÀû¸£ÄáÑÇÖÝÒÔ¼°ÆäËûÖݶ¼±¬·¢Á˶ϵç¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬Ã»ÓÐÒ»¼Ò¹«Ë¾Ú¹ÊÍÍøÂçÖÐÖ¹µÄÔµ¹ÊÔ­ÓÉ £¬£¬£¬£¬£¬£¬ÊÖÒÕÖ°Ô±¾ùÍÆ²â´Ë´ÎÊÂÎñΪDDoS¹¥»÷µ¼Ö £¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁËͼƬ֤¾Ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.geekdup.net/2020/06/16/largest-ddos-attack-in-united-states-history-might-have-happened-yesterday/



3.ºÚ¿Íð³ą̈Íå¼²¿ØÖÐÐÄ £¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Õþ¸®Ç鱨


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÍøÂçÇå¾²¹«Ë¾ElevenPathsÌåÏÖ £¬£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯ÕýÔÚð³ą̈Íå¼²¿ØÖÐÐĵÄÖÎÀíÖ°Ô± £¬£¬£¬£¬£¬£¬Í¨¹ý·¢ËÍÈ«ÐıàдµÄ´¹ÂÚÓʼþÊÔͼÇÔÈ¡Õþ¸®Ç鱨¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯VendettaÔÚ5Ô³õ×îÏÈÏǫ̀ÍåijЩÓû§·¢Ë͵ç×ÓÓʼþ £¬£¬£¬£¬£¬£¬²¢±Þ²ßËûÃǾÙÐÐеĹÚ×´²¡¶¾¼ì²â¡£¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÓʼþÖи½´øÁËÒ»¸öÔ¶³ÌºÚ¿Í¹¤¾ß £¬£¬£¬£¬£¬£¬¿ÉÒÔÇÔÈ¡µÇ¼ƾ֤²¢Ð®ÖÆÍøÂçÉãÏñÍ·¡£¡£¡£¡£¡£¡£¡£Miguel ?ngel de Castro Sim¨®nÌåÏÖ £¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í¹¤¾ßµÄÌØÕ÷Åú×¢ËûÃÇÕýÔÚËѼ¯Ç鱨 £¬£¬£¬£¬£¬£¬Ö÷ÒªÊÇÕþ¸®Ç鱨¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/vendetta-taiwan-coronavirus-telefonica/


4.Qbot¹¥»÷ÊýÊ®¼ÒÃÀ¹ú½ðÈÚ»ú¹¹²¢ÇÔÈ¡Æä¿Í»§Æ¾Ö¤


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


F5ʵÑéÊÒµÄÑо¿Ö°Ô±·¢Ã÷ºÚ¿ÍʹÓöñÒâÈí¼þQbot¶ÔÊýÊ®¼ÒÃÀ¹ú½ðÈÚ»ú¹¹Ìᳫ¹¥»÷ £¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÆä¿Í»§µÄƾ֤ºÍ½ðÈÚÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì½ðÈÚ»ú¹¹°üÀ¨Ä¦¸ù´óͨ¡¢»¨ÆìÒøÐС¢ÃÀ¹úÒøÐС¢ Citizens¡¢Capital One¡¢ ¸»¹úÒøÐкÍFirstMeritÒøÐеÈ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¶ñÒâÈí¼þÆÊÎöʦDoron VoolfÆÊÎö £¬£¬£¬£¬£¬£¬´Ë´ÎʹÓõÄQbotµÄ¹¥»÷»î¶¯×ܹ²Ãé×¼ÁË36¸öÃÀ¹úµÄ½ðÈÚ»ú¹¹ £¬£¬£¬£¬£¬£¬ÁíÍâÉÐÓмÓÄôóºÍºÉÀ¼µÄÁ½¼ÒÒøÐС£¡£¡£¡£¡£¡£¡£Voolf˵ £¬£¬£¬£¬£¬£¬Ïà±È֮ǰµÄ°æ±¾ £¬£¬£¬£¬£¬£¬´Ë´ÎµÄQbotÐÂÔöÁËеķâ×°²ã £¬£¬£¬£¬£¬£¬¿ÉÒÔ¼ÓÃܲ¢Òþ²Ø´úÂëÀ´¶ã¹ýɨÃè³ÌÐò £¬£¬£¬£¬£¬£¬Ëü»¹ÔöÌíÁË·´ÐéÄâ»úÊÖÒÕ £¬£¬£¬£¬£¬£¬¿É×ÊÖúÆä¶ã¹ýɱ¶¾Èí¼þ¼ì²â¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-bank-customers-targeted-in-ongoing-qbot-campaign/


5.ÍâÂô¹«Ë¾FoodoraÊý¾Ýй¶ £¬£¬£¬£¬£¬£¬Ó°Ïì14¸ö¹ú¼ÒµÄÓû§


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÔÚÏßʳÎïÅäËÍЧÀÍDelivery HeroÒÑÈ·ÈÏÆä¹«Ë¾Foodora±¬·¢ÁËÊý¾Ýй¶ £¬£¬£¬£¬£¬£¬Ó°ÏìÁË14¸ö¹ú¼ÒµÄÓû§¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ¹²Ð¹Â¶ÁË72.7Íò¸ö¿Í»§µÄÕÊ»§ÏêϸÐÅÏ¢ £¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨Ãû³Æ¡¢µØµã¡¢µç»°ºÅÂëºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü´Ë´ÎÊÂÎñÖв¢Ã»ÓвÆÎñÊý¾Ý×ß© £¬£¬£¬£¬£¬£¬µ«¿Í»§ÏÕЩ׼ȷµ½Ã׵ĵØÀíλÖÃÔâµ½ÁËй¶¡£¡£¡£¡£¡£¡£¡£Delivery HeroµÄ½²»°ÈË˵ £¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢¿ÉÒÔ×·Ëݵ½2016Äê £¬£¬£¬£¬£¬£¬À´×Ô°Ä´óÀûÑÇ¡¢°ÂµØÀû¡¢¼ÓÄô󡢷¨¹ú¡¢µÂ¹ú¡¢Ïã¸Û¡¢Òâ´óÀû¡¢ÁÐÖ§¶ØÊ¿µÇ¡¢ºÉÀ¼¡¢Å²Íþ¡¢ÐÂ¼ÓÆÂ¡¢Î÷°àÑÀºÍ°¢À­²®ÁªºÏÇõ³¤¹úµÄFoodoraÓû§¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/foodora-data-breach/


6.ARM CPUÐÂÎó²îΪSpectre±äÌå £¬£¬£¬£¬£¬£¬¿Éµ¼Ö²àÐŵÀ¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


GoogleµÄSafeSideС×é·¢Ã÷ARM CPU±£´æÐµÄͶÆõÖ´ÐÐÎó²î £¬£¬£¬£¬£¬£¬ÎªSpectre±äÌå £¬£¬£¬£¬£¬£¬¿Éµ¼Ö²àÐŵÀ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÙÔÚARM´¦Öóͷ£Æ÷µÄArmv8-A£¨Cortex-A£©CPUϵͳ½á¹¹Öз¢Ã÷ÁËÒ»¸öÃûΪֱÏßÍÆ²â£¨ Straight-Line Speculation £¬£¬£¬£¬£¬£¬SLS£© µÄÐÂÎó²î £¬£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2020-13844¡£¡£¡£¡£¡£¡£¡£SLS±»ÒÔΪÊÇSpectreÎó²îµÄ±äÌå £¬£¬£¬£¬£¬£¬µ«¶þÕߵĹ¥»÷¹æÄ£ÂÔÓвî±ð £¬£¬£¬£¬£¬£¬SLSÎó²î½öÓ°ÏìArm Armv-A´¦Öóͷ£Æ÷ £¬£¬£¬£¬£¬£¬¶øSpectreÎó²îÓ°ÏìËùÓÐÖ÷ÒªÐ¾Æ¬ÖÆÔìÉ̵ÄCPU¡£¡£¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ £¬£¬£¬£¬£¬£¬¸ÃÎó²î»¹Ã»ÓÐÔÚҰʹÓᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.phoronix.com/scan.php?page=news_item&px=Arm-Straight-Line-Speculation