CloudFlare³ÆÒÑ×èÖ¹1500ÍòRPSµÄDDoSÁ÷Á¿

°ä²¼¹¦·ò 2022-04-29
1¡¢CloudFlare³ÆÒÑ×èÖ¹¸ß´ï1500ÍòRPSµÄDDoSÁ÷Á¿


¾Ý4ÔÂ27ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬CloudFlareÐû³ÆÒÑ×èÖ¹¸ß´ï1500ÍòRPSµÄDDoSÁ÷Á¿¡£¡£¡£¡£¡£ ¡£Õâ¼Ò¹«Ë¾°µÊ¾ÕâÊÇÓмͼÒÔÀ´×î´óµÄHTTPS DDoS¹¥»÷Ö®Ò»¡£¡£¡£¡£¡£ ¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷³ÖÐøÁ˲»µ½15Ã룬£¬£¬£¬£¬£¬ÓÉԼĪ6000¸ö½©Ê¬ÍøÂçÌáÒ飬£¬£¬£¬£¬£¬À´×ÔÈ«Çò112¸ö¹ú¶È¡£¡£¡£¡£¡£ ¡£Æ¾¾ÝCloudflareµÄÊý¾Ý£¬£¬£¬£¬£¬£¬½ü15%µÄ¹¥»÷Á÷Á¿À´×ÔÓ¡¶ÈÄáÎ÷ÑÇ£¬£¬£¬£¬£¬£¬Æä´ÎÊǶíÂÞ˹¡¢°ÍÎ÷¡¢Ó¡¶È¡¢¸çÂ×±ÈÑǺÍÃÀ¹ú¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÒªÀ´×ÔÊý¾ÝÖÐÐÄ£¬£¬£¬£¬£¬£¬Õâ¼ûÖ¤ÁËÁ÷Á¿´Ó×¡Õ¬ÍøÂç·þÎñÌṩÉÌ(ISP)µ½ÔÆÍÆËãISPµÄ³Á´óת±ä¡£¡£¡£¡£¡£ ¡£


https://thehackernews.com/2022/04/cloudflare-thwarts-record-ddos-attack.html


2¡¢ÐµÄÀÕË÷Èí¼þOnyx»áËæ»ú¸²¸Ç³¬¹ý2MBµÄ´óÎļþ


ýÌå4ÔÂ27ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬MalwareHunterTeam·¢ÏÖÁËÒ»¸öеÄÀÕË÷Èí¼þOnyx¡£¡£¡£¡£¡£ ¡£ÓëÆäËüÀÕË÷Èí¼þ·ÖÆçµÄÊÇ£¬£¬£¬£¬£¬£¬Onyx»á¶ÔÓ×ÓÚ2MB£¨±¨Â·ÖÐÒѽ«Ô­À´Ëù³ÆµÄ200MB¸üÕýΪ2MB£©µÄÎļþ½øÐмÓÃÜ£¬£¬£¬£¬£¬£¬È»¶ø¶ÔÓÚ´óÓÚ2MBµÄÎļþ£¬£¬£¬£¬£¬£¬»áÓÃËæ»úÊý¾Ý½øÐи²¸Ç¡£¡£¡£¡£¡£ ¡£ÓÉÓÚ¸²¸ÇµÄÊý¾ÝÊÇËæ»ú´´½¨µÄÇÒδ¼ÓÃÜ£¬£¬£¬£¬£¬£¬Òò¶øÎÞ·¨½âÃÜ´óÓÚ2MBµÄÎļþ¡£¡£¡£¡£¡£ ¡£¼´±ãÖ§¸¶Êê½ðÒ²Ö»Äܸ´Ô­½ÏÓ×µÄÎļþ£¬£¬£¬£¬£¬£¬×êÑÐÈËԱǿÁÒ½¨ÒéÓû§²»ÒªÖ§¸¶Êê½ð¡£¡£¡£¡£¡£ ¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þ»ùÓÚChaos£¬£¬£¬£¬£¬£¬ËüÃÇÓµÓÐÒ»ÑùµÄ·ÛËéÐÔ¼ÓÃÜ·¨Ê½¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/psa-onyx-ransomware-destroys-large-files-instead-of-encrypting-them/


3¡¢ÃÀ¹úSmile BrandsÔâµ½ÀÕË÷¹¥»÷й¶250ÍòÈ˵ÄÐÅÏ¢


¾ÝýÌå4ÔÂ27Èճƣ¬£¬£¬£¬£¬£¬ÃÀ¹ú×î´óµÄÑÀ¿Æ·þÎñ¹«Ë¾Smile BrandsÒÑй¶³¬¹ý250Íò»¼ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÔçÔÚ2021Äê6Ô¾ÍÅû¶ÁËһ·ÓÉÓÚÀÕË÷¹¥»÷µ¼ÖµÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬ÆäÓÚ2021Äê4ÔÂ24ÈÕÒâʶµ½²¿ÃÅϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË»¼ÕßÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢½¡È«±£ÏÕÐÅÏ¢ºÍÕï¶ÏÐÅÏ¢µÈ¡£¡£¡£¡£¡£ ¡£Æäʱ°µÊ¾ÓÐ1200¸ö»¼ÕßÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬Õâ¸öÊý×ÖºóÀ´±»Åú¸ÄΪ199683£¬£¬£¬£¬£¬£¬Ö±µ½½ñÄê4ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»ã±¨×ܹ²Ó°ÏìÁË2592494Ó×ÎÒ¡£¡£¡£¡£¡£ ¡£


https://www.infosecurity-magazine.com/news/smile-brands-breach-impacts-25m/   


4¡¢Dedalus BiologyÒòй¶49ÍòÈ˵ÄÐÅÏ¢±»·£¿£¿£¿£¿£¿£¿ £¿î150ÍòÅ·Ôª


¾ÝýÌå4ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Ò½ÁÆÈí¼þ¹©¸øÉÌDedalus BiologyÒòÎ¥·´GDPRµÄ3ÌõÌõ¿î£¬£¬£¬£¬£¬£¬±»·¨¹úÊý¾Ý±£» £»£»£»£»£» £»¤»ú¹¹(CNIL)·£¿£¿£¿£¿£¿£¿ £¿î150ÍòÅ·Ôª¡£¡£¡£¡£¡£ ¡£Dedalus BiologyΪ¸Ã¹úÊýǧ¸öҽѧ³¢ÊÔÊÒÌṩ·þÎñ£¬£¬£¬£¬£¬£¬Æäй¶ÁË28¸ö³¢ÊÔÊÒµÄ491939¸ö»¼ÕßµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢Ò½ÉúÐÕÃû¡¢²âÊÔÈÕÆÚ¡¢Ò½ÁÆÐÅÏ¢ºÍÒÅ´«ÐÅÏ¢µÈ¡£¡£¡£¡£¡£ ¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Î¥·´ÁËGDPRµÄµÚ29Ìõ¡¢µÚ32ÌõºÍµÚ28Ìõ£¬£¬£¬£¬£¬£¬CNIL¾ö¶¨°´¹«Ë¾ÄêÊÕÈëµÄ10%ÍÆË㣬£¬£¬£¬£¬£¬·£¿£¿£¿£¿£¿£¿ £¿î150ÍòÅ·Ôª£¨Ô¼ºÏ158ÍòÃÀÔª£©¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/medical-software-firm-fined-15m-for-leaking-data-of-490k-patients/  


5¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃRIG Exploit Kit·Ö·¢RedLineµÄ»î¶¯


BitdefenderÔÚ4ÔÂ27ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬³ÆÆä·¢ÏÖÁËÀûÓÃRIG Exploit Kit·Ö·¢ÇÔÈ¡¶ñÒâÈí¼þRedLineµÄ»î¶¯¡£¡£¡£¡£¡£ ¡£¹ËÃû˼Ò壬£¬£¬£¬£¬£¬RIG EKÔ̺¬Ò»×é·ì϶£¬£¬£¬£¬£¬£¬Í¨¹ýÔÚÖ¸±êÉÏÖ´ÐÐËùÐèµÄshellcodeÀ´×Ô¶¯½øÐÐÍøÂçÈëÇÖ¡£¡£¡£¡£¡£ ¡£Õâ´Î»î¶¯ÀûÓÃÁËInternet ExplorerÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-26411£©£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚ2021Äê3Ô·ݽ¨¸´¡£¡£¡£¡£¡£ ¡£×°Öóɹ¦ºó£¬£¬£¬£¬£¬£¬RedLine Stealer»á¶ÔÖ¸±êϵͳ½øÐÐÖ´ÐпúËÅ£¬£¬£¬£¬£¬£¬¶øºó½«Êý¾Ý·¢Ë͵½Ô¶³ÌºÅÁîºÍ½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£ ¡£


https://www.bitdefender.com/blog/labs/redline-stealer-resurfaces-in-fresh-rig-exploit-kit-campaign/


6¡¢ESET°ä²¼¹ØÓÚºÚ¿Í×éÖ¯TA410µÄTTPºÍ»î¶¯µÄ·ÖÎö»ã±¨


4ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬ESET°ä²¼Á˹ØÓÚºÚ¿Í×éÖ¯TA410µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¸Ã»ã±¨·ÖÎöÁËTA410×Ô2019ÄêÆðÍ·µÄ»î¶¯£¬£¬£¬£¬£¬£¬ËüÊÇÓëAPT10Óйصļäµý×éÖ¯£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹úµÄ¹«ÓÃÊÂÒµ²¿ÃÅ×éÖ¯£¬£¬£¬£¬£¬£¬ÒÔ¼°Öж«ºÍ·ÇÖÞµÄ±í½»×éÖ¯¡£¡£¡£¡£¡£ ¡£TA410ÊÇÒ»¸öɡ״×éÖ¯£¬£¬£¬£¬£¬£¬ÓÉ3¸öÍŶÓ×é³É£¬£¬£¬£¬£¬£¬±ðÀëºÅΪFlowingFrog¡¢LookingFrogºÍJollyFrog£¬£¬£¬£¬£¬£¬Ã¿¸öÍŶӶ¼ÓÐ×Ô¼ºµÄ¹¤¾ßºÍÖ¸±ê¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±»¹·¢ÏÖÁ˸ÃÍÅ»ïµÄ¶ñÒâÈí¼þFlowCloudµÄбäÌ壬£¬£¬£¬£¬£¬ÕâÊǸö¸´ÔÓµÄÄ£¿£¿£¿£¿£¿£¿ £¿é»¯C++ RAT¡£¡£¡£¡£¡£ ¡£


https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/