Ñо¿ÍŶÓɨÃè·¢Ã÷Áè¼Ý360Íǫ̻̀¶µÄMySQLЧÀÍÆ÷
Ðû²¼Ê±¼ä 2022-06-021¡¢Ñо¿ÍŶÓɨÃè·¢Ã÷Áè¼Ý360Íǫ̻̀¶µÄMySQLЧÀÍÆ÷
¾ÝýÌå5ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿×éÖ¯Shadowserver FoundationÔÚÉÏÖܾÙÐеÄɨÃèÖУ¬£¬£¬£¬£¬£¬£¬·¢Ã÷Áè¼Ý360Íǫ̻̀¶µÄMySQLЧÀÍÆ÷ʹÓÃĬÈ϶˿ÚTCP¶Ë¿Ú3306¡£¡£¡£¡£¡£ÕâЩЧÀÍÆ÷ÔÚÍøÉϹûÕæÌ»Â¶²¢ÏìÓ¦ÅÌÎÊ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܳÉΪºÚ¿ÍºÍÀÕË÷¹¥»÷ÕßµÄÄ¿µÄ¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬ÓÐ230Íǫ̀ͨ¹ýIPv4ÅþÁ¬£¬£¬£¬£¬£¬£¬£¬130Íǫ̀װ±¸Í¨¹ýIPv6ÅþÁ¬¡£¡£¡£¡£¡£×î¶àµÄ¹ú¼ÒÊÇÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁè¼Ý120Íǫ̻̀¶µÄ×°±¸£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú¡¢ÐÂ¼ÓÆÂ¡¢ºÉÀ¼ºÍ²¨À¼µÈ¹ú¡£¡£¡£¡£¡£²»ÊÊÍâµØ±£»£»£»£»£»£»¤MySQLÊý¾Ý¿âЧÀÍÆ÷¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÆÆËðÐԵĹ¥»÷¡¢ÀÕË÷¹¥»÷ÒÔ¼°RATѬȾ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/
2¡¢ÍÁ¶úÆäº½¿Õ¹«Ë¾Pegasus AirlinesµÄ6.5 TBÊý¾Ýй¶
ýÌå5ÔÂ31Èճƣ¬£¬£¬£¬£¬£¬£¬ÍÁ¶úÆäº½¿Õ¹«Ë¾Pegasus AirlinesµÄAWS´æ´¢Í°ÉèÖùýʧ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË6.5 TBÊý¾Ý¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ2ÔÂ28ÈÕ·¢Ã÷ÁËÒ»¸ö¿ª·ÅµÄ´æ´¢Í°£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐÔ¼2300Íò·ÝÎĵµ£¬£¬£¬£¬£¬£¬£¬Éæ¼°Áè¼Ý300Íò¸öº½ÐÐÊý¾ÝÎļþ£¨È纽ÐÐͼ±í¡¢°ü¹ÜÎļþºÍ»ú×éÂÖ°àÐÅÏ¢µÈ),Áè¼Ý160Íò·Ý»ú×éÖ°Ô±µÄPIIÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Pegasusº½¿Õ¹«Ë¾¿ª·¢µÄµç×Óº½Ðаü(EFB)Èí¼þµÄÔ´´úÂë¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¸Ã´æ´¢¿âÒѱ»±£»£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£
https://www.hackread.com/pegasus-airlines-leak-tb-data-aws-s3-bucket-mess-up/
3¡¢SideWinderÍÅ»ïÔÚ½üÁ½ÄêÖÐÒѾÙÐÐ1000¶à´Î¹¥»÷»î¶¯
¾Ý5ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬×Ô2020Äê4ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïSideWinderÒÑÌᳫÁËÁè¼Ý1000´Î¹¥»÷»î¶¯¡£¡£¡£¡£¡£KasperskyÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïµÄ²¿·ÖÌØÕ÷ʹÆäÍÑÓ±¶ø³ö£¬£¬£¬£¬£¬£¬£¬°üÀ¨¹¥»÷µÄÊýÄ¿¡¢ÆµÂʺͳ¤ÆÚÐÔ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÔÚÆä»î¶¯ÖÐʹÓõĴó×Ú¼ÓÃܺͻìÏý¶ñÒâ×é¼þ¡£¡£¡£¡£¡£ÔÚÒÑÍùµÄÁ½ÄêÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ»Ö±ÔËÓª×ÅÒ»¸öÓÉ400¶à¸öÓòºÍ×ÓÓò×é³ÉµÄ´óÐÍC2»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬À´ÍйܺͿØÖƶñÒâpayload¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¸ÃÍÅ»ïʹÓÃÖÖÖÖѬȾǰÑÔºÍÏȽøµÄÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬¾ßÓнϸߵÄÖØ´óÐÔ£¬£¬£¬£¬£¬£¬£¬½¨Òé×é֯ʹÓÃ×îа汾µÄMicrosoft Office»º½â´ËÀ๥»÷¡£¡£¡£¡£¡£
https://thehackernews.com/2022/05/sidewinder-hackers-launched-over-1000.html
4¡¢¶à¹úÖ´·¨²¿·ÖÁªºÏÐж¯Àֳɵ·»ÙFluBotµÄ»ù´¡ÉèÊ©
Å·ÖÞÐ̾¯×éÖ¯ÔÚ6ÔÂ1ÈÕÐû²¼£¬£¬£¬£¬£¬£¬£¬ÒѾÀֳɵ·»ÙAndroid¶ñÒâÈí¼þFluBot¡£¡£¡£¡£¡£´Ë´ÎÖ´·¨Ðж¯Éæ¼°°Ä´óÀûÑÇ¡¢±ÈÀûʱ¡¢·ÒÀ¼¡¢ÐÙÑÀÀû¡¢°®¶ûÀ¼¡¢ÂÞÂíÄáÑÇ¡¢Î÷°àÑÀ¡¢Èðµä¡¢ÈðÊ¿¡¢ºÉÀ¼ºÍÃÀ¹ú¡£¡£¡£¡£¡£ÔçÔÚ2021Äê3Ô£¬£¬£¬£¬£¬£¬£¬Î÷°àÑÀ¾¯·½Ôø¾Ð²¶ÁË4ÃûÏÓÒÉÈË£¬£¬£¬£¬£¬£¬£¬ËûÃDZ»ÒÔΪÊÇFluBot»î¶¯µÄÖ÷Òª³ÉÔ±£¬£¬£¬£¬£¬£¬£¬µ«´Ë´ÎÖÐÖ¹Ö»ÊÇÔÝʱµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß²»¾Ãºó×îÏÈÕë¶ÔÎ÷°àÑÀÖ®ÍâµÄ¹ú¼Ò¡£¡£¡£¡£¡£ÕâÒ»´Î£¬£¬£¬£¬£¬£¬£¬Å·ÖÞÐ̾¯×é֯ǿµ÷£¬£¬£¬£¬£¬£¬£¬FluBotµÄ»ù´¡ÉèÊ©ÒÑ´¦ÓÚÖ´·¨²¿·ÖµÄ¿ØÖÆÖ®Ï£¬£¬£¬£¬£¬£¬£¬Òò´Ë²»¿ÉÄÜÔÙËÀ»Ò¸´È¼¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/flubot-android-malware-operation-shutdown-by-law-enforcement/
5¡¢Check PointÐû²¼¹ØÓÚ½©Ê¬ÍøÂçXLoaderµÄÆÊÎö±¨¸æ
5ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬Check PointÐû²¼¹ØÓÚа汾µÄ½©Ê¬ÍøÂçXLoaderµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£XLoaderÊÇÒ»¸öÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬£¬£¬×î³õ»ùÓÚFormbook£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔWindowsºÍmacOS£¬£¬£¬£¬£¬£¬£¬ËüÓÚ2021Äê1ÔÂÊ״α»ÆÕ±éµØÊ¹Óᣡ£¡£¡£¡£×îа汾¶ÔC2ÀֳɵĻá¼ûÔ´ÓÚ¸ÅÂÊÂ۵ĴóÊý¶¨ÂÉ£¬£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±±ØÐè¾ÓÉÈß³¤µÄÄ£Äâ²Å»ªµÃ³ÊÏÖʵµÄC2µØµã£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ²»³£¼ûµÄ×ö·¨£¬£¬£¬£¬£¬£¬£¬Ëü»áʹËùÓеÄ×Ô¶¯¾ç±¾±äµÃºÁÎÞÓô¦¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÔÚ2.6°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬XLoader´Ó64λµÄpayloadÖÐɾ³ýÁËÕâÒ»¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ã¿´Î¶¼»áÅþÁ¬ÕæÕýµÄC2Óò£»£»£»£»£»£»µ«ÔÚ32λϵͳÖУ¨Ò²¾ÍÊÇÑо¿Ö°Ô±Ê¹ÓõÄɳºÐÖг£¼ûµÄϵͳ£©£¬£¬£¬£¬£¬£¬£¬±£´æÁËÕâ¸öеÄC2»ìÏý¹¦Ð§¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-xloader-botnet-uses-probability-theory-to-hide-its-servers/
6¡¢Unit 42Ðû²¼2021Äê11ÔÂÖÁ2022Äê1ÔÂÍøÂçÍþвµÄÆÊÎö±¨¸æ
Unit 42ÔÚ5ÔÂ31ÈÕÐû²¼ÁË2021Äê11ÔÂÖÁ2022Äê1ÔÂÍøÂçÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÔÚÕâÈý¸öÔÂÖÐ×ܹ²·ºÆðÁË6443¸öÐÂÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ31.3%ÊÇÍâµØÎó²î£¬£¬£¬£¬£¬£¬£¬¶øÊ£ÓàµÄ68.7%ÊÇÔ¶³ÌÎó²î¡£¡£¡£¡£¡£×î³£¼ûµÄÎó²îÀàÐÍÊÇ¿çÕ¾¾ç±¾Îó²î£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǾܾøÐ§ÀÍÎó²î¡¢»º³åÇøÒç³öÎó²îºÍÌáȨÎó²î¡£¡£¡£¡£¡£×î³£¼ûµÄ¹¥»÷ÀàÐÍÊÇÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÐÅϢй¶ºÍ±éÀú¡£¡£¡£¡£¡£×î¶àµÄ¹¥»÷À´×ÔÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬Ö®ºóÊǵ¹úºÍ¶íÂÞ˹£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÓпÉÄÜʹÓÃÁËÊðÀíºÍVPNÀ´Òþ²ØÏÖʵλÖᣡ£¡£¡£¡£
https://unit42.paloaltonetworks.com/network-security-trends-cross-site-scripting/


¾©¹«Íø°²±¸11010802024551ºÅ