¼ÓÄôóÓÊÕþÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬Ð¹Â¶95Íò¿Í»§µÄÐÅÏ¢£»TeamTNTÍŻ﹥»÷¶à¸öKubernetes¼¯ÈºÖеĽü5Íò¸öIP

Ðû²¼Ê±¼ä 2021-05-28

1.¼ÓÄôóÓÊÕþÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬Ð¹Â¶95Íò¿Í»§µÄÐÅÏ¢


1.jpg


¼ÓÄôóÓÊÕþ֪ͨ¿Í»§ £¬ÓÉÓÚµÚÈý·½¹©Ó¦ÉÌCommport CommunicationsѬȾÀÕË÷Èí¼þ £¬ÆäÐÅÏ¢ÒѾ­Ð¹Â¶¡£¼ÓÄôóÓÊÕþÊǼÓÄôóÖ÷ÒªµÄÓÊÕþÔËÓªÉÌ £¬·þÎñÓÚ1650Íò¼ÓÄôó¾ÓÃñºÍÉÌÒµµØÖ·¡£´Ë´Îʼþ¹²Ó°ÏìÁ˸ù«Ë¾µÄ44¸ö´óÐÍÉÌÒµ¿Í»§ºÍ950000¸öÊÕ¼þÈË £¬Ð¹Â¶ÁË·¢¼þÈ˺ÍÊÕ¼þÈ˵ÄÁªÏµÐÅÏ¢¡¢ÐÕÃûºÍÓʼĵØÖ·µÈÐÅÏ¢¡£ÔçÔÚ2020Äê12Ô £¬Lorenz¾Í³ÆÆä¹¥»÷ÁËCommport Communications £¬²¢ÇÔÈ¡ÁË35.3 GBµÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/canada-post-hit-by-data-breach-after-supplier-ransomware-attack/


2.TeamTNTÍŻ﹥»÷¶à¸öKubernetes¼¯ÈºÖеĽü5Íò¸öIP


2.jpg


Ç÷ÊÆ¿Æ¼¼µÄÑо¿ÈËÔ±·¢ÏÖTeamTNTÍŻ﹥»÷¶à¸öKubernetes¼¯ÈºÖеĽü5Íò¸öIP¡£KubernetesÊÇÒ»¸ö¿ªÔ´µÄÈÝÆ÷±àÅÅϵͳ £¬ÓÃÓÚ×Ô¶¯»¯¼ÆËã»úÓ¦Ó÷¨Ê½µÄ²¿Êð¡¢À©Õ¹ºÍ¹ÜÀí¡£¹¥»÷·¢ÉúÔÚ3ÔÂÖÁ5Ô £¬´ó¶àÊý±»¹¥»÷µÄ½ÚµãÀ´×ÔÖйúºÍÃÀ¹ú¡£TeamTNT½©Ê¬ÍøÂç×Ô2020Äê4Ô¿ªÊ¼»îÔ¾ £¬Ö÷ÒªÕë¶ÔDocker £¬µ«ÊÇ×Ô8ÔÂÒÔÀ´¿ªÊ¼Õë¶ÔÅäÖôíÎóµÄKubernetes¼¯Èº¡£¹¥»÷ÕßʹÓÃÁËÔÚVirusTotalÖмì²âÂʺܵ͵Ľű¾kube.lateral.sh £¬ÒÔ¼°Á½¸ö¿ªÔ´¹¤¾ßmasscanºÍZgrab¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118306/digital-id/kubernetes-clusters-teamtnt.html


3.·¨¹ú¾¯·½ÀúʱÊýÔÂÀֳɲé·â°µÍøLe MondeParall¨¨le


3.jpg


·¨¹ú¹ú¼ÒÇ鱨ºÍº£¹ØÊÓ²ì¾Ö£¨DNRED£©ÀúʱÊýÔ £¬ÖÕÓÚÀֳɲé·â°µÍøLe MondeParall¨¨le¡£ÕâÊǼÌ2018ÄêµÄBlack HandºÍ2019ÄêµÄFrench Deep Web MarketÖ®ºó £¬µ±µØ¾¯·½²é·âµÄµÚÈý¸ö´óÐÍ·¨ÓïÆ½Ì¨¡£¸Ãƽ̨×Ô2020Äê³õ¿ªÊ¼»îÔ¾ £¬ÌṩÖÖÖÖ²úÎïºÍ·þÎñ £¬°üÂÞ±»µÁµÄÒøÐп¨Êý¾Ý¡¢¶¾Æ·¡¢Î±ÔìÎļþºÍÎäÆ÷µÈ¡£Æ¾¾Ý·¨¹ú¾­¼Ã²¿(Ministry of the Economy)ÉùÃ÷ £¬¾¯·½´þ²¶ÁËÁ½Ãû¹ÜÀíÔ± £¬²¢²é»ñÁËÖÖÖÖ¼ÆËã»úÉ豸¡¢Ðé¼ÙÎļþ¡¢ÒøÐп¨ÒÔ¼°ÊýǧŷԪµÄ¼ÓÃÜ»õ±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118295/deep-web/le-monde-parallele-dark-web.html


4.ºÚ¿ÍÔÚ°µÍø³öÊÛ½ü1300Íò¸öDailyQuizÓû§µÄÐÅÏ¢


4.jpg


The Record³Æ £¬ºÚ¿ÍÇÔÈ¡ÁË1300Íò¸öDailyQuizÓû§µÄÏêϸÐÅÏ¢¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞ830Íò¸öÕË»§µÄÃ÷ÎÄÃÜÂë¡¢µç×ÓÓʼþºÍIPµØÖ· £¬²¢ÒÔԼĪ2000ÃÀÔª¼ÓÃÜ»õ±ÒµÄ¼Û¸ñ³öÊÛ¡£µ«ÏÖÔÚÕâЩÐÅÏ¢ÔÚÄþ¾²Ñо¿ÈËÔ±ÊÖÖÐ £¬¿ÉÒÔ¹ûÈ»·ÃÎÊ¡£DailyQuizµÄÓû§¿ÉÒÔͨ¹ý·ÃÎÊHave I been PwnedÍøÕ¾ £¬À´²éѯ×Ô¼ºµÄÐÅÏ¢ÊÇ·ñÒѾ­±»Ð¹Â¶¡£Ä¿Ç° £¬DailyQuiz¾Ü¾ø¶Ô´ËʽøÆÀÂÛ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/plaintext-passwords-of-83-million-users.html


5.GoogleÅû¶Rowhammer¹¥»÷µÄбäÖÖHalf-Double


5.jpg


GoogleµÄÑо¿ÈËÔ±Åû¶ÁËRowhammer¹¥»÷µÄбäÖÖHalf-Double¡£´ËÀ๥»÷·¢ÏÖÓÚ2014Äê,ͨ¹ýÖØ¸´·ÃÎÊ´æ´¢ÐпÉÄÜ»áÒýÆð×ãÒÔÈÅÂÒ´æ´¢ÔÚÏàÁÚÐÐÖеĵç×Ó×ÌÈÅ £¬´Ó¶øÔÊÐí²»ÊÜÐÅÈεĴúÂëÈÆ¹ýɳÏä²¢½Ó¹Ü¿ØÖÆÏµÍ³¡£Îª´Ë £¬¹©Ó¦ÉÌÀûÓÃÄ¿±êÐÐˢУ¨Target Row Refresh £¬TRR£©À´»º½â´ËÀ๥»÷¡£Ñо¿ÈËÔ±ÌåÏÖ £¬ÐµÄHalf-Double¹¥»÷ÀûÓÃÁ˵ײã¹è»ù°åµÄ¹ÌÓÐÌØÐÔ £¬¿ÉÒÔÈÆ¹ýµ±Ç°ËùÓзÀÓù´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/05/google-researchers-discover-new-variant.html


6.°¢À­Ë¹¼ÓÎÀÉú²¿³ÆÆäÔâµ½¹¥»÷ £¬¹ÙÍøÔÝʱÎÞ·¨·ÃÎÊ


6.jpg


ÃÀ¹ú°¢À­Ë¹¼ÓÎÀÉúºÍÉç»á·þÎñ²¿£¨DHSS£©³ÆÆäÔâµ½¶ñÒâÈí¼þ¹¥»÷ £¬¹ÙÍøÔÝʱÎÞ·¨·ÃÎÊ¡£´Ë´Î¹¥»÷²»½öÖжÏÁËDHSSÍøÕ¾ £¬»¹Ó°ÏìÁËÐí¶àÆäËû·þÎñ £¬°üÂÞ°¢À­Ë¹¼ÓÖÝÉúÃü¼Ç¼ϵͳ¡¢DHSSÁ÷Ðв¡Ñ§¹«±¨ºÍѧУÏò¹«¹²ÎÀÉú³ÂËßÒßÃçÊý¾ÝµÄϵͳSAGEµÈ¡£¸ÃÖݵĹÙÔ±²¢Î´Í¸Â¶Óйع¥»÷µÄ¼¼Êõϸ½Ú £¬Ò²²»Çå³þÊÇ·ñΪÀÕË÷Èí¼þ¹¥»÷ £¬µ«Æä͸¶DHSSÍøÕ¾ÊÇÔÚ2021Äê5ÔÂ17ÈÕÍíÉÏÖжϵÄ £¬½ØÖÁÏÖÔÚ¸ÃÍøÕ¾ÈÔ´¦ÓÚÍÑ»ú״̬¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/05/26/alaska-health-department-site-went-offline-after-malware-attack/