Ó¢¹úHarrisÁªÃËѬȾÀÕË÷Èí¼þ£¬50¶àËùѧУÊÜÓ°Ï죻LinuxÖеÄ2¸ö©¶´¿ÉÈÆ¹ýSpectre¹¥»÷µÄ»º½â´ëÊ©

Ðû²¼Ê±¼ä 2021-03-31

1.Ó¢¹úHarrisÁªÃËѬȾÀÕË÷Èí¼þ£¬50¶àËùѧУÊÜÓ°Ïì


1.jpg


3ÔÂ27ÈÕ£¨ÐÇÆÚÁù£©£¬Î»ÓÚÂ׶صĽÌÓý´ÈÉÆ»ú¹¹¹þÀï˹ÁªºÏ»á£¨Harris Federation£©µÄITϵͳºÍµç×ÓÓʼþ·þÎñÆ÷Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ó°ÏìÁË50ÆäÖÐСѧµÄ37000ÃûѧÉú¡£ÔÚ¼ì²âµ½¹¥»÷Ö®ºó£¬¸Ã×éÖ¯Á¢¿Ì¹Ø±ÕÁ˵ç×ÓÓʼþºÍÀι̵绰ϵͳ²¢½«ËùÓÐÀ´µçÖØ¶¨ÏòµÃÊÖ»ú£¬Í¬Ê±»¹½ûÓÃÁËѧÉúµÄÉ豸ÒÔ·ÀÖ¹ÀÕË÷Èí¼þÁ÷´«¡£¸Ã×éÖ¯ÌåÏÖÕâÊÇÒ»´Î¸ß¶ÈÅÓ´óµÄ¹¥»÷»î¶¯£¬ÆäĿǰÕýÔÚÓëÕþ¸®×éÖ¯ºÏ×÷¶Ô´ËÊÂÕ¹¿ªÊӲ졣


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/harris-federation-hit-by-ransomware-attack-affecting-50-schools/


2.ÐÂ¼ÓÆÂVhiveѬȾALTDOS£¬30¶àÍò¸ö¿Í»§µÄ¼Ç¼й¶


2.jpg


ÐÂ¼ÓÆÂ¼Ò¾ßÁ¬ËøµêVhiveÔÚ3ÔÂ23ÈÕÐû²¼ÆäÔâµ½ALTDOSÀÕË÷Èí¼þ¹¥»÷£¬30¶àÍò¸ö¿Í»§µÄ¼Ç¼ÒÑй¶¡£¸Ã¹«Ë¾³ÆÆä¹ÙÍøvhive.com.sgÔÚ3ÔÂ21ÈÕÔâµ½Ê״ι¥»÷£¬ÆäÍøÂç·þÎñÆ÷ÔÚ3ÔÂ22ÈÕ±»¹¥ÆÆ¡£VhiveÔÚ3ÔÂ23ÈÕʹÓñ¸·Ý»Ö¸´ÆäÍøÕ¾ºÍÎļþ£¬µ«Î´Äܽâ¾öÖ÷Ҫ©¶´¡£ÕâʹµÃ¹¥»÷ÔÚ3ÔÂ25ÈÕ¼ÌÐø£¬ALTDOSÇÔÈ¡ÁËÆäÔ´´úÂëºÍÎļþ£¬²¢¼ÓÃÜÁË·þÎñÆ÷ÉϵÄËùÓÐÎļþ¡£Ä¿Ç°£¬Vhive¾Ü¾øÁËÊê½ðÒªÇó¡£    


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/sg-vhive-alerts-consumers-to-cyberattack/    


3.Õë¶ÔÓ¡¶ÈµÄAPT×éÖ¯RedEchoÒÑ¹Ø±ÕÆäʹÓõĻù´¡ÉèÊ©


3.jpg


APT×éÖ¯RedEchoÔÚ2Ôµױ»Ñо¿ÈËÔ±Åû¶ºó£¬ÒÑ¹Ø±ÕÆäʹÓõĻù´¡ÉèÊ©¡£Recorded FutureµÄÄþ¾²ÈËÔ±ÓÚ2Ô·¢ÏÖÁ˸ÃAPT×éÖ¯£¬³Æ¸ÃÍÅ»ï×Ô2020Äê³õ¹¥»÷ÁËÓ¡¶ÈµÄÖÁÉÙ10¸öµçÁ¦²¿ÃÅ£¬»¹½«Ä¿±êÃé×¼Á˸ßѹÊäµç±äµçÕ¾ºÍȼú»ðÁ¦·¢µç³§¡£Ôڸ÷¢ÏÖÐû²¼¼¸Öܺó£¬RedEchoÒѾ­¹Ø±ÕÁ˲¿ÃÅÓÃÓÚ¿ØÖư²×°ÔÚÄ¿±êÍøÂçÖеÄShadowPadºóÃŵĻù´¡ÉèÊ©¡£Ñо¿ÈËÔ±ÍÆ²â£¬¸ÃAPT×éÖ¯ÔÚ±»·¢ÏÖºó¿ÉÄܽ«ÆäC2×ªÒÆµ½ÁËÆäËûµØ·½¡£    


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116094/apt/redecho-apt-c2-shutdown.html


4.ClopÍÅ»ï¹ûÈ»ÃÀ¹úMarylandºÍCalifornia´óѧµÄÐÅÏ¢


4.jpg


3ÔÂ29ÈÕ£¬ClopÍŻ↑ʼÐû²¼´ÓÃÀ¹ú½ÌÓý»ú¹¹ÇÔÈ¡µÄÊý¾ÝµÄ½ØÍ¼£¬ÆäÖаüÂÞÃÀ¹úÂíÀïÀ¼´óѧ£¨University of Maryland£©ºÍ¼ÓÀû¸£ÄáÑÇ´óѧ£¨University of California£©µÄ²ÆÕþÎļþºÍ¸öÈËÐÅÏ¢¡£Æ¾¾Ý½ØÍ¼£¬´Ë´Îй¶µÄÊý¾Ý°üÂÞÁª°î˰ÊÕÎļþ¡¢Ñ§·Ñ¼õÃâÇëÇó¡¢»¤ÀíίԱ»áÉêÇëºÍ˰ÊÕÕªÒªÎļþµÈ²ÆÕþÐÅÏ¢£¬ÒÔ¼°ÕÕÆ¬¡¢ÐÕÃû¡¢¼Òͥסַ¡¢Éç»áÄþ¾²ºÅÂë¡¢ÒÆÃñÉí·Ý¡¢³öÉúÈÕÆÚºÍ»¤ÕյȸöÈËÐÅÏ¢¡£     


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-group-targets-universities-of-maryland-california-in-new-data-leaks/


5.Ovarro TBox RTUÖдæÔÚ°üÂÞRCEÔÚÄڵĶà¸ö©¶´


5.jpg


Äþ¾²¹«Ë¾ClarotyµÄÄþ¾²Ñо¿Ô±Uri Katz·¢ÏÖOvarroµÄTBoxÔ¶³ÌÖն˵¥Ôª£¨RTU£©´æÔÚ5¸ö©¶´¡£TBoxÊÇÓÃÓÚ¿ØÖÆ¼à¿ØºÍÊý¾ÝÊÕÂÞ£¨SCADA£©Ó¦ÓõÄ×Ô¶¯»¯½â¾ö·½°¸£¬Éæ¼°µçÁ¦¡¢Ê¯ÓͺÍÌìÈ»Æø¡¢ÔËÊäºÍ¼Ó¹¤µÈÐÐÒµ¡£ÕâЩ©¶´·Ö±ðΪ´úÂëÖ´ÐЩ¶´CVE-2021-22646¡¢¿Éµ¼ÖÂTBoxÍß½âµÄCVE-2021-22642¡¢¿É½âÃܵǼÃÜÂëµÄCVE-2021-22640¡¢¿É¸ü¸Ä»òɾ³ýÅäÖÃÎļþµÄCVE-2021-22648ºÍ¿ÉÇÔȡӲ±àÂëµÄ¼ÓÃÜÃÜÔ¿µÄCVE-2021-22644¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/03/flaws-in-ovarro-tbox-rtus-could-open.html


6.LinuxÖеÄ2¸ö©¶´¿ÉÈÆ¹ýSpectre¹¥»÷µÄ»º½â´ëÊ©


6.jpg


SymantecµÄÑо¿ÈËÔ±·¢ÏÖÁËLinuxÖеÄ2¸öЩ¶´£¬¿É±»ÓÃÀ´ÈƹýSpectre¹¥»÷µÄ»º½â´ëÊ©¡£SpectreÊÇ2018Äê1Ô·¢ÏÖµÄоƬ©¶´£¬¼¸ºõÓ°ÏìÁËËùÓд¦ÖÃÆ÷£¬Ö»ÄÜͨ¹ý²Ù×÷ϵͳ²¹¶¡À´½øÐлº½â¡£ÕâÁ½¸öЩ¶´¶¼ÓëLinuxÄں˶ÔÀ©Õ¹µÄBerkeleyÊý¾Ý°ü¹ýÂËÆ÷£¨BPF£©µÄÖ§³ÖÓйØ£¬ÆäÖÐ×îÑÏÖØµÄ©¶´£¨CVE-2020-27170£©¿ÉÒÔÓÃÀ´¶ÁÈ¡ÄÚºËÄÚ´æÖÐÈκÎλÖõÄÄÚÈÝ£¬µÚ¶þ¸ö©¶´£¨CVE-2020-27171£©¿É¶ÁÈ¡4 GB·¶Î§µÄÄÚºËÄÚ´æÖеÄÄÚÈÝ¡£


Ô­ÎÄÁ´½Ó£º

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spectre-bypass-linux-vulnerabilities