¶íÂÞ˹µçÐÅRostelecomÔâºÚ¿Í×éÖ¯¡°Silent Crow¡±¹¥»÷
Ðû²¼Ê±¼ä 2025-01-231. ¶íÂÞ˹µçÐÅRostelecomÔâºÚ¿Í×éÖ¯¡°Silent Crow¡±¹¥»÷
1ÔÂ22ÈÕ£¬¶íÂÞ˹´óÐ͵çÐÅÌṩÉÌRostelecomÕýÔÚÊÓ²ìÒ»ÆðÒÉËÆÍøÂç¹¥»÷ʼþ£¬¸ÃʼþÓÉ×Գơ°Silent Crow¡±µÄºÚ¿Í×éÖ¯Òý·¢£¬¸Ã×éÖ¯Éù³Æй¶ÁËRostelecom³Ð°üÉ̵ÄÊý¾Ý£¬°üÂÞÊýǧ·Ý¿Í»§µç×ÓÓʼþºÍµç»°ºÅÂë¡£RostelecomÌåÏÖÕýÔÚÉó²éÊý¾Ý¿âÒÔÈ·¶¨Ð¹Â¶Çé¿ö£¬²¢½¨ÒéÓû§ÖØÖÃÃÜÂë²¢ÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤¡£¶íÂÞ˹Êý×ÖÉú³¤²¿ÌåÏÖ´Ë´ÎйÃÜʼþδӰÏì¹ú¼Ò·þÎñÃÅ»§ÍøÕ¾£¬ÇÒÓû§Ãô¸ÐÊý¾Ýδй¶¡£Silent Crow´ËÇ°ÔøÉù³Æ¶Ô¶íÂÞ˹Õþ¸®»ú¹¹ºÍÆäËûÖªÃû×éÖ¯½øÐкڿ͹¥»÷¡£½üÆÚ£¬¶à¸ö¶íÂÞ˹ÆóÒµºÍ¹ú¼Ò»ú¹¹ÃæÁÙÍøÂçÄþ¾²Íþв£¬µ±µØ»¥ÁªÍø¼à¹Ü»ú¹¹¼Ç¼Á˶àÆðÊý¾Ý¿âй¶Ê¼þ¡£¶íÂÞ˹µçÐŹ«Ë¾×ܲÃÌåÏÖ£¬ËùÓжíÂÞ˹È˵ĸöÈËÐÅÏ¢¶¼¿ÉÄÜÒÑÔÚÍøÉÏй¶¡£
https://therecord.media/rostelecom-russia-contractor-data-breach
2. BitbucketÔÆ·þÎñÑÏÖØ̱»¾£¬È«Çò¿Í»§ÔâÓö´ó¹æÄ£ÔËÓªÖжÏ
1ÔÂ21ÈÕ£¬BitbucketÊÇÒ»¿îÓÉAtlassianÌṩµÄ»ùÓÚWebµÄ°æ±¾¿ØÖÆ´æ´¢¿âÍйܷþÎñ£¬½üÆÚÔâÓöÁË´ó¹æÄ£ÖжÏʼþ£¬µ¼ÖÂÔÆ·þÎñ¡°ÑÏÖØ̱»¾¡±¡£¸Ã·þÎñÔÚСÐÍÍŶӺʹóÐÍÆóÒµÖйãÊÜ»¶Ó£¬ÌرðÊǶÔÓÚÄÇЩϣÍû½«Ô´´úÂë¿ØÖÆÓëÏîÄ¿¹ÜÀí¹¤¾ßÈçAtlassian JiraÏà½áºÏµÄÓû§¡£Æ¾¾ÝDownDetectorÉϵÄÓû§³ÂËߣ¬´Ë´ÎÖжÏʼþʼÓÚÁ½¸ö¶àСʱǰ£¬Ó°ÏìÁËÍøÕ¾¡¢·þÎñÆ÷ºÍÎļþ·ÃÎÊ¡£BitbucketÌåÏÖ£¬´Ë´ÎÖØ´óÁ¬ÐøÖжÏÓ°ÏìÁËÆäËùÓзþÎñ£¬°üÂÞÍøÕ¾¡¢API¡¢Git²Ù×÷¡¢Éí·ÝÑéÖ¤¡¢Óû§¹ÜÀí¡¢Webhook¡¢Ô´ÏÂÔØ¡¢¹ÜµÀ¡¢Git LFS¡¢µç×ÓÓʼþͨ±¨¡¢¹ºÖúÍÐí¿ÉÒÔ¼°×¢²áµÈ¡£ÔÚ¹Ù·½×´Ì¬Ò³ÃæÉÏÐû²¼µÄʼþ³ÂËßÖУ¬BitbucketÌåÏÖÕýÔÚÊÓ²ìÓ°ÏìBitbucket WebºÍGit²Ù×÷µÄÎÊÌ⣬²¢ËæºóÐû²¼ÕýÔÚÊӲ조BitbucketÊý¾Ý¿â±¥ºÍ²¢Ó°ÏìËùÓвÙ×÷¡±µÄÎÊÌ⡣Ŀǰ£¬BitbucketÈÔÔÚÑ°ÕÒ½â¾ö·½°¸£¬²¢ÌåÏÖ½«ÔÚÏÂÒ»¸öСʱÄÚÌṩ¸ü¶àϸ½Ú¡£
https://www.bleepingcomputer.com/news/technology/bitbucket-services-hard-down-due-to-major-worldwide-outage/
3. Cloudflare »º½âÁË´´¼Í¼µÄ 5.6 Tbps DDoS ¹¥»÷
1ÔÂ21ÈÕ£¬Æù½ñΪֹ£¬×î´óµÄÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷·åÖµµ½´ïÁËÿÃë5.6Tbps£¬ÓÉ»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÌᳫ£¬Éæ¼°13,000̨ÊÜѬȾÉ豸£¬Ä¿±êÊǶ«ÑǵÄÒ»¼Ò»¥ÁªÍø·þÎñÌṩÉÌ£¨ISP£©£¬ÊÔͼʹÆä·þÎṉ̃»¾¡£´Ë´Î»ùÓÚUDPµÄ¹¥»÷·¢ÉúÔÚÈ¥Äê10ÔÂ29ÈÕ£¬¾¡¹ÜÁ¬ÐøÁË80Ã룬µ«Cloudflareƾ½èÆä×ÔÖ÷µÄ¼ì²âºÍ»º½âϵͳÀֳɵÖÓù£¬Î´¶ÔÄ¿±êÔì³ÉÓ°Ïì¡£2024Äê10Ô³õ£¬Cloudflare³ÂËßÁËÒ»´ÎÔçÆÚDDoS¹¥»÷£¬·åÖµµ½´ï3.8Tbps£¬Á¬ÐøÁË65Ã룬´´ÏÂÁËмͼ¡£Êý¾ÝÏÔʾ£¬³¬´óÈÝÁ¿DDoS¹¥»÷ÈÕÒæƵ·±£¬ÓÈÆäÔÚ2024ÄêµÚÈý¼¾¶ÈºóÏÔÖøÔö¶à£¬µÚËļ¾¶È¹¥»÷Ç¿¶ÈÁè¼Ý1Tbps£¬»·±ÈÔö³¤1,885%¡£Í¬Ê±£¬Ã¿ÃëÁè¼Ý1ÒÚ¸öÊý¾Ý°üµÄ¹¥»÷Ò²Ôö¼ÓÁË175%¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¾¡¹Ü³¬´óÈÝÁ¿HTTP DDoS¹¥»÷½öÕ¼¼Ç¼×ÜÊýµÄ3%£¬µ«¶ÌÔݵÄDDoS¹¥»÷È´Ô½À´Ô½Æձ飬Լ72%µÄHTTPºÍ91%µÄÍøÂç²ãDDoS¹¥»÷ÔÚ10·ÖÖÓÄÚ½áÊø£¬Õâ¶ÔÔÚÏß¡¢Ê¼ÖÕÔÚÏß¡¢×Ô¶¯»¯µÄDDoS·À»¤·þÎñÌá³öÁ˸ü¸ßÒªÇó¡£CloudflareÖ¸³ö£¬ÕâЩ¹¥»÷ͨ³£·¢ÉúÔÚá¯ÁëʹÓÃʱ¶Î£¬ÎªÊê½ðDDoS¹¥»÷ÌṩÁË»ú»á£¬¸ÃÀàÐ͹¥»÷ÔÚµÚËļ¾¶ÈºÍÊ¥µ®½Ú¼ÙÆÚµ½´ïáÛ·å¡£
https://www.bleepingcomputer.com/news/security/cloudflare-mitigated-a-record-breaking-56-tbps-ddos-attack/
4. ºÚ¿ÍÀûÓÃÁãÈÕ©¶´²¿ÊðAIRASHI½©Ê¬ÍøÂç·¢¶¯DDoS¹¥»÷
1ÔÂ22ÈÕ£¬ºÚ¿Í×éÖ¯ÕýÀûÓÃCambium Networks cnPilot·ÓÉÆ÷ÖеÄδÅû¶ÁãÈÕ©¶´£¬²¿ÊðAIRASHI½©Ê¬ÍøÂç±äÖÖ£¬¸Ã±äÖÖÊÇAISURU£¨ÓÖ³ÆNAKOTNE£©µÄ½ø»¯°æ£¬Ö÷ÒªÓÃÓÚ·¢¶¯ÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷¡£×Ô2024Äê6ÔÂÆð£¬ÕâЩ¹¥»÷¾ÍÒÑÀûÓø鶴ʵʩ£¬ÇÒΪ·Àֹ©¶´±»ÀÄÓã¬Ïà¹Ø¼¼Êõϸ½ÚÔÝδ¹ûÈ»¡£AIRASHI»¹ÀûÓÃÁ˶à¸öÒÑ֪©¶´£¬¹¥»÷ÄÜÁ¦Îȶ¨ÔÚ1-3 TbpsÖ®¼ä¡£ÊÜѬȾÉ豸Ö÷ҪλÓÚ°ÍÎ÷¡¢¶íÂÞ˹¡¢Ô½ÄϺÍÓ¡¶ÈÄáÎ÷ÑÇ£¬¶ø¹¥»÷Ä¿±êÔò°üÂÞÖйú¡¢ÃÀ¹ú¡¢²¨À¼ºÍ¶íÂÞ˹¡£AIRASHIÖÁÉÙ´æÔÚÁ½ÖÖ°æ±¾£ºAIRASHI-DDoSºÍAIRASHI-Proxy£¬ºóÕßÐÂÔöÁËÊðÀí¹¦Ð§¡£Ñо¿ÏÔʾ£¬ºÚ¿ÍÁ¬ÐøÀûÓÃÎïÁªÍøÉ豸©¶´×齨½©Ê¬ÍøÂ磬ÖúÍÆ´ó¹æÄ£DDoS¹¥»÷¡£´ËÍ⣬»¹Åû¶ÁË¿çƽ̨ºóÃÅ·¨Ê½alphatronBot£¬¸Ã·¨Ê½×Ô2023Äê³õÆð»îÔ¾£¬Ä¿±ê°üÂÞÖйúÕþ¸®¼°ÆóÒµ£¬ÀûÓñ»Ñ¬È¾µÄWindowsºÍLinuxϵͳ×齨½©Ê¬ÍøÂ磬²¢Í¨¹ýºÏ·¨µÄ¿ªÔ´P2PÁÄÌìÓ¦ÓÃPeerChatͨÐÅ£¬´ó·ùÌá¸ß½©Ê¬ÍøÂçµÄ·´¿¹Á¦¡£Í¬Ê±£¬»¹·ÖÎöÁËDarkCracks¿ò¼Ü£¬¸Ã¿ò¼ÜÀûÓÃÊÜѬȾµÄÍøÕ¾³äµ±ÏÂÔØÆ÷ºÍC2·þÎñÆ÷£¬ÊÕ¼¯Ãô¸ÐÐÅÏ¢£¬Î¬³Öºã¾Ã·ÃÎÊ¡£
https://thehackernews.com/2025/01/hackers-exploit-zero-day-in-cnpilot.html
5. WordPress RealHomeÖ÷ÌâÓëEasy Real Estate²å¼þÆسö¸ßΣ©¶´
1ÔÂ22ÈÕ£¬WordPressµÄRealHomeÖ÷ÌâºÍEasy Real Estate²å¼þ±»·¢ÏÖ´æÔÚÁ½¸öÑÏÖØ©¶´£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§»ñµÃ¹ÜÀíȨÏÞ¡£ÕâЩ©¶´ÓÉPatchstackÓÚ2024Äê9Ô·¢ÏÖ£¬µ«¾¡¹Ü¶à´ÎʵÑéÁªÏµ¹©Ó¦ÉÌInspiryThemes£¬ÖÁ½ñÈÔδÊÕµ½»Ø¸´£¬ÇÒ¹©Ó¦ÉÌÐû²¼µÄа汾Ҳδ½â¾öÕâЩҪº¦ÎÊÌâ¡£RealHomeÖ÷ÌâµÄ©¶´±àºÅΪCVE-2024-32444£¬ÊÇÒ»¸öδ¾Éí·ÝÑéÖ¤µÄȨÏÞÌáÉýÎÊÌ⣬¹¥»÷Õß¿Éͨ¹ýÌØÖÆHTTPÇëÇóÈƹýÄþ¾²¼ì²é×¢²áΪ¹ÜÀíÔ±£¬´Ó¶øÍêÈ«¿ØÖÆÍøÕ¾¡£Easy Real Estate²å¼þµÄ©¶´±àºÅΪCVE-2024-32555£¬Ô´ÓÚÉç½»µÇ¼¹¦Ð§Î´ÑéÖ¤µç×ÓÓʼþµØÖ·£¬¹¥»÷ÕßÖªµÀ¹ÜÀíÔ±ÓÊÏä¼´¿ÉÎÞÃÜÂëµÇ¼¡£ÓÉÓÚÕâÁ½¸ö©¶´µÄCVSSÆÀ·Ö¾ùΪ9.8£¬ÇÒInspiryThemesÉÐδÐû²¼²¹¶¡£¬½¨ÒéÍøÕ¾ËùÓÐÕߺ͹ÜÀíÔ±Á¢¼´½ûÓÃÕâЩÖ÷ÌâºÍ²å¼þ£¬²¢ÏÞÖÆÓû§×¢²áÒÔ·Àֹδ¾ÊÚȨµÄÕË»§´´½¨¡£¼øÓÚ©¶´ÒѹûÈ»£¬Ñ¸ËÙ·´Ó³ÒÔ¼õÇáÍþвÖÁ¹ØÖØÒª¡£
https://www.bleepingcomputer.com/news/security/critical-zero-days-impact-premium-wordpress-real-estate-plugins/
6. Cloudflare CDN©¶´Æع⣺¿É·¢ËÍͼÏñ̻¶Óû§´óÖÂλÖÃ
1ÔÂ22ÈÕ£¬Äþ¾²Ñо¿ÈËÔ±µ¤Äá¶û·¢ÏÖCloudflareÄÚÈݽ»¸¶ÍøÂ磨CDN£©´æÔÚ©¶´£¬¿ÉÄÜͨ¹ýÔÚSignalºÍDiscordµÈƽ̨·¢ËÍͼÏñ̻¶Óû§´óÖÂλÖ᣾¡¹ÜµØÀí¶¨Î»²»¹»¾«È·£¬µ«×ãÒÔÍƶÏÓû§ËùÔÚµØÀíÇøÓò²¢¼à¿Ø»î¶¯£¬¶ÔÒþ˽¸ß¶È¹Ø×¢ÕßÈç¼ÇÕß¡¢»î¶¯¼ÒµÈ×é³ÉÍþв£¬¶ø¶ÔÖ´·¨²¿ÃÅÔò¿ÉÄÜÓÐÖúÓÚÊӲ졣¸Ã©¶´ÀûÓÃCloudflare½«Ã½Ìå×ÊÔ´»º´æÔÚÓû§ËÄÖÜÊý¾ÝÖÐÐĵĻúÖÆ£¬Í¨¹ýÏòÄ¿±ê·¢ËÍ°üÂÞÆæÌØͼÏñµÄÏûÏ¢£¬ÀûÓÃCloudflare WorkersÖеÄ©¶´Ç¿ÖÆͨ¹ýÌض¨Êý¾ÝÖÐÐÄ·¢³öÇëÇó£¬Æ¾¾ÝCDN·µ»ØµÄÊý¾ÝÖÐÐÄËÄÖÜ»ú³¡´úÂë»æÖÆÓû§´óÖÂλÖá£ÕâÊÇÒ»ÖÖÁãµã»÷¹¥»÷£¬¸ú×Ù¾«¶ÈÔÚ50µ½300Ó¢ÀïÖ®¼ä£¬È¡¾öÓÚµØÓòºÍËÄÖÜÊý¾ÝÖÐÐÄÊýÁ¿¡£Ñо¿ÈËÔ±ÏòCloudflare¡¢SignalºÍDiscordÅû¶©¶´£¬CloudflareÒѱê־ΪÒѽâ¾ö²¢¸øÓèÉͽ𣬵«µØÀí¶¨Î»¹¥»÷ÈÔ¿Éͨ¹ýÆäËû·½Ê½ÊµÏÖ¡£SignalºÍDiscordÈÏΪÎÊÌâÊÇCloudflareµÄÔðÈΣ¬CloudflareÔòÌåÏÖ½ûÓûº´æÊÇÓû§µÄÔðÈΡ£
https://www.bleepingcomputer.com/news/security/cloudflare-cdn-flaw-leaks-user-location-data-even-through-secure-chat-apps/