AvayaϵͳÖÎÀíÔ±ÒòÉæÏÓ·¸·¨ÌìÉú²¢ÏúÊÛVoIPÐí¿ÉÖ¤±»¸æ×´

°ä²¼¹¦·ò 2022-07-01

1¡¢AvayaϵͳÖÎÀíÔ±ÒòÉæÏÓ·¸·¨ÌìÉú²¢ÏúÊÛVoIPÐí¿ÉÖ¤±»¸æ×´


¾Ý6ÔÂ29ÈÕ±¨Â· £¬3ÃûÉæÏÓÏúÊÛ¼ÛÖµ³¬¹ý8800ÍòÃÀÔªµÄAvaya Holdings CorporationÈí¼þÐí¿ÉÖ¤µÄÏÓÒÉÈ˱»¸æ×´ £¬Ãæ¶Ô14Ïîµç»ãڲƭºÍÏ´Ç®µÄ×ïÃû¡£Æ¾¾Ý²¼¸æ £¬Avaya¿Í»§·þÎñÔ±¹¤Raymond Bradly PearceÀÄÓÃÆäÖÎÀíԱȨÏÞÌìÉúADIÈí¼þÐí¿ÉÖ¤ÃÜÔ¿ £¬¶øºóÏúÊÛ¸øAvayaÊÚȨ¾­ÏúÉÌJason M. Hines £¬¹«Ë¾²É°ìÕâЩÐí¿ÉÖ¤¿ÉÓÃÀ´½âËøAvaya IP Officeµç»°ÏµÍ³µÄÖ°ÄÜ¡£¾Ý³Æ £¬Pearce»¹½Ù³ÖÁËÆäËûAvayaÖÎÀíÔ±µÄÕË»§À´ÌìÉúÐí¿ÉÖ¤ £¬ÒÔÔ¤·ÀÓÉÓÚÓëËûµÄÕË»§ÓйØÁªµÄÃÜÔ¿ÌìÉúÁ¿Òì³£¶øÒýÆðÒÉ»ó¡£


https://www.bleepingcomputer.com/news/security/avaya-sysadmin-indicted-for-illegally-generating-selling-voip-licenses/


2¡¢ÎÖ¶ûÂê·ñ¶¨ÆäÔâµ½ºÚ¿ÍÍÅ»ïYanluowangµÄÀÕË÷¹¥»÷


ýÌå6ÔÂ29ÈÕ±¨Â·³Æ £¬ÎÖ¶ûÂê·ñ¶¨ÆäÔâµ½ÁËYanluowangµÄÀÕË÷¹¥»÷¡£±¾ÖÜÒ» £¬ÀÕË÷ÍÅ»ïYanluowangÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼ÁËÒ»¸öÌõ¿î £¬Ðû³ÆËûÃǼÓÃÜÁËÎÖ¶ûÂê40000ÖÁ50000̨É豸¡£¹¥»÷Õßй© £¬¹¥»÷²úÉúÔÚÒ»¸ö¶àÔÂǰ £¬ËûÃǼÓÃÜÁËÖ¸±êµÄÉ豸µ«Ã»ÓÐÇÔÈ¡ÈκÎÊý¾Ý £¬ÀÕË÷5500ÍòÃÀÔªµ«´ÓδÊÕµ½ÎÖ¶ûÂêµÄ»ØÓ¦ £¬²¢°ä²¼ÁË´ÓÎÖ¶ûÂêµÄWindowsÓòÖÐÌáÈ¡µÄÐÅÏ¢¡£ÎÖ¶ûÂê·ñ¶¨ÆäÔâµ½¹¥»÷ £¬²¢°µÊ¾ÐÅÏ¢°²È«ÍŶÓÔÚ24/7È«Ììºò¼à¿ØËûÃǵÄϵͳ¡£


https://www.bleepingcomputer.com/news/security/walmart-denies-being-hit-by-yanluowang-ransomware-attack/


3¡¢Å²Íþ¶à¼ÒΪÃñ¶àÌṩ³ÁÒª·þÎñµÄ´óÐ͹«Ë¾Ôâµ½DDoS¹¥»÷  


¾ÝýÌå6ÔÂ29ÈÕ±¨Â· £¬Å²Íþ¹ú¶È°²È«¾Ö(NSM)³ÆÓë¶íÂÞ˹ÓÐ¹ØµÄºÚ¿Í¶ÔÆä¹Ø¼ü×éÖ¯½øÐÐÁËÂÅ´ÎDDoS¹¥»÷¡£¸Ã»ú¹¹µÄÖ÷¹ÜSofie Nystr?m°ä²¼ÉêÃ÷ £¬ÔÚ´Óǰ24Ó×ʱÄÚ £¬Å²ÍþµÄÊý¸ö×éÖ¯ÒòÔâµ½¹¥»÷ÖжÏ £¬ÖØÒªÊÇһЩΪÃñ¶àÌṩ³ÁÒª·þÎñµÄ´óÐ͹«Ë¾¡£NSM²»Ô¸Ð¹Â©ÄÄЩ×éÖ¯Ôâµ½Á˹¥»÷ £¬µ«Â·Í¸É簵ʾŲÍþÀ͹¤¼à²ì¾ÖÊÇÓ°ÏìµÄ×éÖ¯Ö®Ò» £¬ÔÚ±¾ÖÜÈý²úÉúÖжÏ¡£Ä¿Ç° £¬Å²ÍþÕÙ¿ªÁËÒ»´ÎÐÂÎŰ䲼»á £¬½éÉÜÁ˸þÖÊÇÈôºÎÓ¦¶ÔÕâÒ»ÎÊÌâµÄ¡£


https://therecord.media/norway-accuses-pro-russian-hackers-of-launching-wave-of-ddos-attacks/


4¡¢Intezer·¢ÏÖ¿ÉÇÔÈ¡YouTubeÕË»§µÄ¶ñÒâÈí¼þYTStealer


6ÔÂ29ÈÕ £¬IntezerÅû¶ÁËÖ¼ÔÚÇÔÈ¡YouTube´´×÷ÕßµÄÕË»§µÄжñÒâÈí¼þYTStealer¡£ÓëÆäËüÇÔÈ¡·¨Ê½µÄ·ÖÆçÖ®´¦ÔÚÓÚ £¬YTStealerÖ»Õë¶ÔÒ»Ïî·þÎñÇÔȡʹ´¦¡£·Ö·¢YTStealerÑù±¾µÄÎļþ²»Ö»×°ÖÃYTStealer £¬»¹×°ÖÃÁËÆäËüÇÔÈ¡·¨Ê½ £¬Ô̺¬ÇÔÈ¡·¨Ê½RedLineºÍVidar¡£¸Ã¶ñÒâÈí¼þÔÚÖ´ÐÐ֮ǰ»¹»á½øÐÐһЩ·´É³ºÐµÄ²é³­ £¬Ê¹ÓÃÁËGitHubÉϵĿªÔ´¹¤¾ßChacal¡£µ±È·¶¨Ö¸±êºó £¬Ëü»á×Ðϸ²é³­ä¯ÀÀÆ÷SQLÊý¾Ý¿âÎļþÒÔ¶¨Î»YouTubeÉí·ÝÑéÖ¤ÁîÅÆ¡£


https://www.intezer.com/blog/research/ytstealer-malware-youtube-cookies/


5¡¢Amazon½¨¸´PhotosÀûÓÃÖпÉй¶Óû§½Ó¼ûÁîÅÆµÄ·ì϶


ýÌå6ÔÂ29ÈÕ³Æ £¬Amazon½¨¸´ÁËÆäPhotosÀûÓÃÖÐÒ»¸öÑϳÁµÄ·ì϶ £¬¸ÃÀûÓÃÔÚGoogle PlayµÄÏÂÔØÁ¿Òѳ¬¹ý5000Íò´Î¡£Checkmarx·¢Ïָ÷ì϶ԴÓÚÀûÓ÷¨Ê½×é¼þÅäÖÃÃýÎó £¬µ¼ÖÂÆäÇåµ¥ÎļþÎÞÐèÉí·ÝÑéÖ¤¼´¿É´Ó±í²¿½Ó¼û¡£ÀûÓô˷ì϶¿ÉÄÜ»áʹװÖÃÔÚͳһÉ豸ÉϵĶñÒâÀûÓûñÈ¡ÓÃÓÚAmazon APIÉí·ÝÑéÖ¤µÄAmazon½Ó¼ûÁîÅÆ¡£×êÑÐÈËÔ±³Æ £¬ÀÕË÷Èí¼þºÜÈÝÒ׳ÉΪDZÔڵĹ¥»÷ý½é £¬¹¥»÷ÕßÖ»±ØÒª¶ÁÈ¡¡¢¼ÓÃܺͳÁдָ±êµÄÎļþ £¬Í¬Ê±²Á³ýËûÃǵĺ¹Çà¼Í¼¡£´Ë±í £¬ÆäËüAmazon APIsÒ²¿ÉÄÜʹÓÃÒ»ÑùµÄÁîÅÆ £¬ÈçPrime Video¡¢AlexaºÍKindleµÈ £¬Òò¶ø £¬·çÏÕ¿ÉÄÜÊÇÉîÔ¶µÄ¡£


https://www.bleepingcomputer.com/news/security/amazon-fixes-high-severity-vulnerability-in-android-photos-app/


6¡¢º«¹úKISA°ä²¼ºÏÓÃÓÚv1µ½v4°æ±¾µÄHive½âÃܹ¤¾ß


6ÔÂ30ÈÕ±¨Â· £¬º«¹úÍøÂ簲ȫ»ú¹¹KISA°ä²¼ÁËÀÕË÷Èí¼þHiveµÄÃâ·Ñ½âÃÜÆ÷ £¬ºÏÓÃÓÚv1µ½v4°æ±¾¡£Hive×Ô2021Äê6ÔÂÒÔÀ´Ò»Ïò»îÔ¾ £¬Æ¾¾ÝChainalysisµÄÊý¾Ý £¬ËüÊÇ2021ÄêÊÕÈëTop 10µÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»¡£½ñÄê2Ô £¬Kookmin´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÁËHiveʹÓõļÓÃÜËã·¨ÖдæÔÚÒ»¸ö·ì϶ £¬¿ÉÓÃÀ´ÔÚ²»ÖªÂ·¼ÓÃÜÎļþµÄ˽ԿµÄÇé¿öϽâÃÜÊý¾Ý¡£


https://securityaffairs.co/wordpress/132770/malware/hive-ransomware-decryptor.html