¶íÂÞ˹µçÐÅRostelecomÔâºÚ¿Í×éÖ¯¡°Silent Crow¡±¹¥»÷
°ä²¼¹¦·ò 2025-01-231. ¶íÂÞ˹µçÐÅRostelecomÔâºÚ¿Í×éÖ¯¡°Silent Crow¡±¹¥»÷
1ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬¶íÂÞ˹´óÐ͵çÐÅÌṩÉÌRostelecomÔÚµ÷²éһ·ÒÉËÆÍøÂç¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓÉ×Գơ°Silent Crow¡±µÄºÚ¿Í×éÖ¯Òý·¢£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Ðû³ÆÐ¹Â¶ÁËRostelecom³Ð°üÉ̵ÄÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬Êýǧ·Ý¿Í»§µç×ÓÓʼþºÍµç»°ºÅÂë¡£¡£¡£¡£¡£Rostelecom°µÊ¾ÔÚÉó²éÊý¾Ý¿âÒÔÈ·¶¨Ð¹Â¶Çé¿ö£¬£¬£¬£¬£¬£¬²¢½¨ÒéÓû§³ÁÖÃÃÜÂë²¢ÆôÓÃË«³É·ÖÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¶íÂÞ˹Êý×Ö·¢Õ¹²¿°µÊ¾Õâ´ÎйÃÜÊÂÎñδӰÏì¹ú¶È·þÎñÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬£¬ÇÒÓû§Ãô¸ÐÊý¾Ýδй¶¡£¡£¡£¡£¡£Silent Crow´ËÇ°ÔøÐû³Æ¶Ô¶íÂÞ˹µ±¾Ö»ú¹¹ºÍÆäËû³ÛÃû×éÖ¯½øÐкڿ͹¥»÷¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬£¬¶à¸ö¶íÂÞ˹ÆóÒµºÍ¹ú¶È»ú¹¹Ãæ¶ÔÍøÂ簲ȫÍþв£¬£¬£¬£¬£¬£¬±¾µØ»¥ÁªÍø¼à¹Ü»ú¹¹¼Í¼Á˶àÆðÊý¾Ý¿âй¶ÊÂÎñ¡£¡£¡£¡£¡£¶íÂÞ˹µçÐŹ«Ë¾×ܲðµÊ¾£¬£¬£¬£¬£¬£¬ËùÓжíÂÞ˹È˵ÄÓ×ÎÒÐÅÏ¢¶¼¿ÉÄÜÒÑÔÚÍøÉÏй¶¡£¡£¡£¡£¡£
https://therecord.media/rostelecom-russia-contractor-data-breach
2. BitbucketÔÆ·þÎñÑϳÁ̱»¾£¬£¬£¬£¬£¬£¬È«Çò¿Í»§Ôâ·ê´ó¹æÄ£ÔËÓªÖжÏ
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬BitbucketÊÇÒ»¿îÓÉAtlassianÌṩµÄ»ùÓÚWebµÄ°æ±¾½ÚÔì´æ´¢¿âÍйܷþÎñ£¬£¬£¬£¬£¬£¬½üÆÚÔâ·êÁË´ó¹æÄ£ÖжÏÊÂÎñ£¬£¬£¬£¬£¬£¬µ¼ÖÂÔÆ·þÎñ¡°ÑϳÁ̱»¾¡±¡£¡£¡£¡£¡£¸Ã·þÎñÔÚÓ×ÐÍÍŶӺʹóÐÍÆóÒµÖйãÊÜ»¶Ó£¬£¬£¬£¬£¬£¬³ö¸ñÊǶÔÓÚÄÇЩµ«Ô¸½«Ô´´úÂë½ÚÔìÓëÏîÄ¿ÖÎÀí¹¤¾ßÈçAtlassian JiraÏà½áºÏµÄÓû§¡£¡£¡£¡£¡£Æ¾¾ÝDownDetectorÉϵÄÓû§»ã±¨£¬£¬£¬£¬£¬£¬Õâ´ÎÖжÏÊÂÎñʼÓÚÁ½¸ö¶àÓ×ʱǰ£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÍøÕ¾¡¢·þÎñÆ÷ºÍÎļþ½Ó¼û¡£¡£¡£¡£¡£Bitbucket°µÊ¾£¬£¬£¬£¬£¬£¬Õâ´Î³Á´ó³ÖÐøÖжÏÓ°ÏìÁËÆäËùÓзþÎñ£¬£¬£¬£¬£¬£¬Ô̺¬ÍøÕ¾¡¢API¡¢Git²Ù×÷¡¢Éí·ÝÑéÖ¤¡¢Óû§ÖÎÀí¡¢Webhook¡¢Ô´ÏÂÔØ¡¢¹Ü·¡¢Git LFS¡¢µç×ÓÓʼþ´«µÝ¡¢²É°ìºÍÐíÄܹ»¼°×¢²áµÈ¡£¡£¡£¡£¡£ÔÚ¹Ù·½×´Ì¬Ò³ÃæÉϰ䲼µÄÊÂÎñ»ã±¨ÖУ¬£¬£¬£¬£¬£¬Bitbucket°µÊ¾ÔÚµ÷²éÓ°ÏìBitbucket WebºÍGit²Ù×÷µÄÎÊÌ⣬£¬£¬£¬£¬£¬²¢Ëæºó°ä·¢ÔÚµ÷²é¡°BitbucketÊý¾Ý¿â¹ÄºÍ²¢Ó°ÏìËùÓвÙ×÷¡±µÄÎÊÌâ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬BitbucketÈÔÔÚѰÕÒ½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬²¢°µÊ¾½«±ÉÈËÒ»¸öÓ×ʱÄÚÌṩ¸ü¶àϸ½Ú¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/technology/bitbucket-services-hard-down-due-to-major-worldwide-outage/
3. Cloudflare »º½âÁË´´¼Í¼µÄ 5.6 Tbps DDoS ¹¥»÷
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬Æù½ñΪֹ£¬£¬£¬£¬£¬£¬×î´óµÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷·åÖµ´ïµ½ÁËÿÃë5.6Tbps£¬£¬£¬£¬£¬£¬ÓÉ»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÌáÒ飬£¬£¬£¬£¬£¬Éæ¼°13,000̨ÊÜϰȾÉ豸£¬£¬£¬£¬£¬£¬Ö¸±êÊǶ«ÑǵÄÒ»¼Ò»¥ÁªÍø·þÎñÌṩÉÌ£¨ISP£©£¬£¬£¬£¬£¬£¬ÊÔͼʹÆä·þÎṉ̃»¾¡£¡£¡£¡£¡£Õâ´Î»ùÓÚUDPµÄ¹¥»÷²úÉúÔÚÈ¥Äê10ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬Ö»¹Ü³ÖÐøÁË80Ã룬£¬£¬£¬£¬£¬µ«Cloudflareƾ½èÆä×ÔÖ÷µÄ¼ì²â»ººÍ½âϵͳ³É¹¦Õмܣ¬£¬£¬£¬£¬£¬Î´¶ÔÖ¸±êÔì³ÉÓ°Ïì¡£¡£¡£¡£¡£2024Äê10Ô³õ£¬£¬£¬£¬£¬£¬Cloudflare»ã±¨ÁËÒ»´ÎÔçÆÚDDoS¹¥»÷£¬£¬£¬£¬£¬£¬·åÖµ´ïµ½3.8Tbps£¬£¬£¬£¬£¬£¬³ÖÐøÁË65Ã룬£¬£¬£¬£¬£¬´´ÏÂÁËмͼ¡£¡£¡£¡£¡£Êý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬³¬´óÈÝÁ¿DDoS¹¥»÷ÈÕ񾮵ÈÔ£¬£¬£¬£¬£¬£¬ÓÈÆäÔÚ2024ÄêµÚÈý¼¾¶ÈºóÏÔÖøÔö¶à£¬£¬£¬£¬£¬£¬µÚËÄʱ¶È¹¥»÷Ç¿¶È³¬¹ý1Tbps£¬£¬£¬£¬£¬£¬»·±ÈÔö³¤1,885%¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬Ã¿Ã볬¹ý1ÒÚ¸öÊý¾Ý°üµÄ¹¥»÷Ò²Ôö³¤ÁË175%¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬Ö»¹Ü³¬´óÈÝÁ¿HTTP DDoS¹¥»÷½öÕ¼¼Í¼×ÜÊýµÄ3%£¬£¬£¬£¬£¬£¬µ«¶ÌÔݵÄDDoS¹¥»÷È´Ô½À´Ô½ÆÕ±é£¬£¬£¬£¬£¬£¬Ô¼72%µÄHTTPºÍ91%µÄÍøÂç²ãDDoS¹¥»÷ÔÚ10·ÖÖÓÄÚʵÏÖ£¬£¬£¬£¬£¬£¬Õâ¶ÔÔÚÏß¡¢Ê¼ÖÕÔÚÏß¡¢×Ô¶¯»¯µÄDDoS·À»¤·þÎñÌá³öÁ˸ü¸ßÒªÇ󡣡£¡£¡£¡£CloudflareÖ¸³ö£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷ͨ³£²úÉúÔÚ¶¥·åʹÓÃʱ¶Î£¬£¬£¬£¬£¬£¬ÎªÊê½ðDDoS¹¥»÷ÌṩÁË»úÓö£¬£¬£¬£¬£¬£¬¸ÃÀàÐ͹¥»÷ÔÚµÚËÄʱ¶ÈºÍÊ¥µ®½Ú¼ÙÆÚ´ïµ½¶¥·å¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cloudflare-mitigated-a-record-breaking-56-tbps-ddos-attack/
4. ºÚ¿ÍÀûÓÃÁãÈÕ·ì϶²¿ÊðAIRASHI½©Ê¬ÍøÂç·¢ÆðDDoS¹¥»÷
1ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯ÕýÀûÓÃCambium Networks cnPilot·ÓÉÆ÷ÖеÄδÅû¶ÁãÈÕ·ì϶£¬£¬£¬£¬£¬£¬²¿ÊðAIRASHI½©Ê¬ÍøÂç±äÖÖ£¬£¬£¬£¬£¬£¬¸Ã±äÖÖÊÇAISURU£¨ÓÖ³ÆNAKOTNE£©µÄ½ø»¯°æ£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚ·¢ÆðÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷¡£¡£¡£¡£¡£×Ô2024Äê6ÔÂÆð£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷¾ÍÒÑÀûÓø÷ì϶ִÐУ¬£¬£¬£¬£¬£¬ÇÒΪԤ·À·ì϶±»ÀÄÓ㬣¬£¬£¬£¬£¬Óйؼ¼Êõϸ½ÚÔÝδ¹«¿ª¡£¡£¡£¡£¡£AIRASHI»¹ÀûÓÃÁ˶à¸öÒÑÖª·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÄÜÁ¦²»±äÔÚ1-3 TbpsÖ®¼ä¡£¡£¡£¡£¡£ÊÜϰȾÉè±¸ÖØÒªÎ»ÓÚ°ÍÎ÷¡¢¶íÂÞ˹¡¢Ô½ÄϺÍÓ¡¶ÈÄáÎ÷ÑÇ£¬£¬£¬£¬£¬£¬¶ø¹¥»÷Ö¸±êÔòÔ̺¬Öйú¡¢ÃÀ¹ú¡¢²¨À¼ºÍ¶íÂÞ˹¡£¡£¡£¡£¡£AIRASHIÖÁÉÙ´æÔÚÁ½ÖÖ°æ±¾£ºAIRASHI-DDoSºÍAIRASHI-Proxy£¬£¬£¬£¬£¬£¬ºóÕßÐÂÔöÁË´úÀíÖ°ÄÜ¡£¡£¡£¡£¡£×êÑÐÏÔʾ£¬£¬£¬£¬£¬£¬ºÚ¿Í³ÖÐøÀûÓÃÎïÁªÍøÉ豸·ì϶×齨½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬ÖúÍÆ´ó¹æÄ£DDoS¹¥»÷¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬»¹Åû¶ÁË¿çÆ½Ì¨ºóÃÅ·¨Ê½alphatronBot£¬£¬£¬£¬£¬£¬¸Ã·¨Ê½×Ô2023ËêÊׯð»îÔ¾£¬£¬£¬£¬£¬£¬Ö¸±êÔ̺¬Öйúµ±¾ÐİÆóÒµ£¬£¬£¬£¬£¬£¬ÀûÓñ»Ï°È¾µÄWindowsºÍLinuxϵͳ×齨½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬²¢Í¨¹ýºÏ·¨µÄ¿ªÔ´P2P̸ÌìÀûÓÃPeerChatͨѶ£¬£¬£¬£¬£¬£¬´ó·ùÌá¸ß½©Ê¬ÍøÂçµÄµÖ¿¹Á¦¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬»¹·ÖÎöÁËDarkCracks¿ò¼Ü£¬£¬£¬£¬£¬£¬¸Ã¿ò¼ÜÀûÓÃÊÜϰȾµÄÍøÕ¾³äÈÎÏÂÔØÆ÷ºÍC2·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÍøÂçÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬Î¬³Ö³Ö¾Ã½Ó¼û¡£¡£¡£¡£¡£
https://thehackernews.com/2025/01/hackers-exploit-zero-day-in-cnpilot.html
5. WordPress RealHomeÖ÷ÌâÓëEasy Real Estate²å¼þÆØ³ö¸ßΣ·ì϶
1ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬WordPressµÄRealHomeÖ÷ÌâºÍEasy Real Estate²å¼þ±»·¢ÏÖ´æÔÚÁ½¸öÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§»ñµÃÖÎÀíȨÏÞ¡£¡£¡£¡£¡£ÕâЩ·ì϶ÓÉPatchstackÓÚ2024Äê9Ô·¢ÏÖ£¬£¬£¬£¬£¬£¬µ«Ö»¹ÜÂŴγ¢ÊÔÁªÏµ¹©¸øÉÌInspiryThemes£¬£¬£¬£¬£¬£¬ÖÁ½ñÈÔδÊÕµ½»Ø¸´£¬£¬£¬£¬£¬£¬ÇÒ¹©¸øḚ́䲼µÄа汾Ҳδ½â¾öÕâЩ¹Ø¼üÎÊÌâ¡£¡£¡£¡£¡£RealHomeÖ÷ÌâµÄ·ì϶±àºÅΪCVE-2024-32444£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öδ¾Éí·ÝÑéÖ¤µÄȨÏÞÌáÉýÎÊÌ⣬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØÔìHTTPÒªÇóÈÆ¹ý°²È«²é³×¢²áΪÖÎÀíÔ±£¬£¬£¬£¬£¬£¬´Ó¶øÆëÈ«½ÚÔìÍøÕ¾¡£¡£¡£¡£¡£Easy Real Estate²å¼þµÄ·ì϶±àºÅΪCVE-2024-32555£¬£¬£¬£¬£¬£¬Ô´ÓÚÉç½»µÇ¼ְÄÜδÑéÖ¤µç×ÓÓʼþµØÖ·£¬£¬£¬£¬£¬£¬¹¥»÷Õß֪·ÖÎÀíÔ±ÓÊÏä¼´¿ÉÎÞÃÜÂëµÇ¼¡£¡£¡£¡£¡£ÓÉÓÚÕâÁ½¸ö·ì϶µÄCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬£¬ÇÒInspiryThemesÉÐδ°ä²¼²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬½¨ÒéÍøÕ¾ËùÓÐÕߺÍÖÎÀíÔ±Á¢¼´½ûÓÃÕâЩÖ÷ÌâºÍ²å¼þ£¬£¬£¬£¬£¬£¬²¢ÏÞ¶Å×û§×¢²áÒÔÔ¤·Àδ¾ÊÚȨµÄÕË»§´´½¨¡£¡£¡£¡£¡£¼øÓÚ·ì϶Òѹ«¿ª£¬£¬£¬£¬£¬£¬Ñ¸ËÙ·´Ó³ÒÔ¼õÇáÍþвÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/critical-zero-days-impact-premium-wordpress-real-estate-plugins/
6. Cloudflare CDN·ìÏ¶ÆØ¹â£º¿É·¢ËÍͼÏñ¶³öÓû§´óÌåµØÎ»
1ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±µ¤Äá¶û·¢ÏÖCloudflareÄÚÈݽ»¸¶ÍøÂ磨CDN£©´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬¿ÉÄÜͨ¹ýÔÚSignalºÍDiscordµÈƽ̨·¢ËÍͼÏñ¶³öÓû§´óÌåµØÎ»¡£¡£¡£¡£¡£Ö»¹ÜµØÀí¶¨Î»²»¹»¾«È·£¬£¬£¬£¬£¬£¬µ«×ãÒÔ´§¶ÈÓû§µØµãµØÀíÇøÓò²¢¼à¿Ø»î¶¯£¬£¬£¬£¬£¬£¬¶ÔÒþÖԸ߶ȹØ×¢ÕßÈç¼ÇÕß¡¢»î¶¯¼ÒµÈ×é³ÉÍþв£¬£¬£¬£¬£¬£¬¶ø¶Ô·¨Âɲ¿ÃÅÔò¿ÉÄÜÓÐÖúÓÚµ÷²é¡£¡£¡£¡£¡£¸Ã·ì϶ÀûÓÃCloudflare½«Ã½Ìå×ÊÔ´»º´æÔÚÓû§×ó½üÊý¾ÝÖÐÐĵĻúÔ죬£¬£¬£¬£¬£¬Í¨¹ýÏòÖ¸±ê·¢ËÍÔ̺¬¹ÖÒìͼÏñµÄÐÂÎÅ£¬£¬£¬£¬£¬£¬ÀûÓÃCloudflare WorkersÖеķì϶ǿÔìͨ¹ýÌØ¶¨Êý¾ÝÖÐÐÄ·¢³öÒªÇ󣬣¬£¬£¬£¬£¬Æ¾¾ÝCDN·µ»ØµÄÊý¾ÝÖÐÐÄ×ó½ü»ú³¡´úÂë»æÔìÓû§´óÌåµØÎ»¡£¡£¡£¡£¡£ÕâÊÇÒ»ÖÖÁãµã»÷¹¥»÷£¬£¬£¬£¬£¬£¬¸ú×Ù¾«¶ÈÔÚ50µ½300Ó¢ÀïÖ®¼ä£¬£¬£¬£¬£¬£¬È¡¾öÓÚµØÓòºÍ×ó½üÊý¾ÝÖÐÐÄÊýÁ¿¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÏòCloudflare¡¢SignalºÍDiscordÅû¶·ì϶£¬£¬£¬£¬£¬£¬CloudflareÒÑÏóÕ÷ΪÒѽâ¾ö²¢´ÍÓëÉͽ𣬣¬£¬£¬£¬£¬µ«µØÀí¶¨Î»¹¥»÷ÈÔ¿Éͨ¹ýÆäËû·½Ê½ÊµÏÖ¡£¡£¡£¡£¡£SignalºÍDiscordÒÔΪÎÊÌâÊÇCloudflareµÄÔðÈΣ¬£¬£¬£¬£¬£¬CloudflareÔò°µÊ¾½ûÓûº´æÊÇÓû§µÄÔðÈΡ£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cloudflare-cdn-flaw-leaks-user-location-data-even-through-secure-chat-apps/


¾©¹«Íø°²±¸11010802024551ºÅ