¶íÂÞ˹µçÐÅRostelecomÔâºÚ¿Í×éÖ¯¡°Silent Crow¡±¹¥»÷

Ðû²¼Ê±¼ä 2025-01-23

1. ¶íÂÞ˹µçÐÅRostelecomÔâºÚ¿Í×éÖ¯¡°Silent Crow¡±¹¥»÷


1ÔÂ22ÈÕ£¬¶íÂÞ˹´óÐ͵çÐÅÌṩÉÌRostelecomÕýÔÚÊÓ²ìÒ»ÆðÒÉËÆÍøÂç¹¥»÷ÊÂÎñ£¬¸ÃÊÂÎñÓÉ×Գơ°Silent Crow¡±µÄºÚ¿Í×éÖ¯Òý·¢£¬¸Ã×éÖ¯Éù³Æй¶ÁËRostelecom³Ð°üÉ̵ÄÊý¾Ý£¬°üÀ¨Êýǧ·Ý¿Í»§µç×ÓÓʼþºÍµç»°ºÅÂë¡£RostelecomÌåÏÖÕýÔÚÉó²éÊý¾Ý¿âÒÔÈ·¶¨Ð¹Â¶ÇéÐΣ¬²¢½¨ÒéÓû§ÖØÖÃÃÜÂë²¢ÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤¡£¶íÂÞ˹Êý×ÖÉú³¤²¿ÌåÏÖ´Ë´ÎйÃÜÊÂÎñδӰÏì¹ú¼Ò·þÎñÃÅ»§ÍøÕ¾£¬ÇÒÓû§Ãô¸ÐÊý¾Ýδй¶¡£Silent Crow´ËÇ°ÔøÉù³Æ¶Ô¶íÂÞ˹Õþ¸®»ú¹¹ºÍÆäËû×ÅÃû×éÖ¯¾ÙÐкڿ͹¥»÷¡£½üÆÚ£¬¶à¸ö¶íÂÞ˹ÆóÒµºÍ¹ú¼Ò»ú¹¹ÃæÁÙÍøÂçÇå¾²Íþв£¬ÍâµØ»¥ÁªÍøî¿Ïµ»ú¹¹¼Í¼Á˶àÆðÊý¾Ý¿âй¶ÊÂÎñ¡£¶íÂÞ˹µçÐŹ«Ë¾×ܲÃÌåÏÖ£¬ËùÓжíÂÞ˹È˵ÄСÎÒ˽¼ÒÐÅÏ¢¶¼¿ÉÄÜÒÑÔÚÍøÉÏй¶¡£


https://therecord.media/rostelecom-russia-contractor-data-breach


2. BitbucketÔÆ·þÎñÑÏÖØ̱»¾£¬È«Çò¿Í»§ÔâÓö´ó¹æÄ£ÔËÓªÖÐÖ¹


1ÔÂ21ÈÕ£¬BitbucketÊÇÒ»¿îÓÉAtlassianÌṩµÄ»ùÓÚWebµÄ°æ±¾¿ØÖÆ´æ´¢¿âÍйܷþÎñ£¬½üÆÚÔâÓöÁË´ó¹æÄ£ÖÐÖ¹ÊÂÎñ£¬µ¼ÖÂÔÆ·þÎñ¡°ÑÏÖØ̱»¾¡±¡£¸Ã·þÎñÔÚСÐÍÍŶӺʹóÐÍÆóÒµÖйãÊܽӴý£¬ÌØÊâÊǹØÓÚÄÇЩϣÍû½«Ô´´úÂë¿ØÖÆÓëÏîÄ¿ÖÎÀí¹¤¾ßÈçAtlassian JiraÏàÍŽáµÄÓû§¡£Æ¾Ö¤DownDetectorÉϵÄÓû§±¨¸æ£¬´Ë´ÎÖÐÖ¹ÊÂÎñʼÓÚÁ½¸ö¶àСʱǰ£¬Ó°ÏìÁËÍøÕ¾¡¢·þÎñÆ÷ºÍÎļþ»á¼û¡£BitbucketÌåÏÖ£¬´Ë´ÎÖØ´óÒ»Á¬ÖÐÖ¹Ó°ÏìÁËÆäËùÓзþÎñ£¬°üÀ¨ÍøÕ¾¡¢API¡¢Git²Ù×÷¡¢Éí·ÝÑéÖ¤¡¢Óû§ÖÎÀí¡¢Webhook¡¢Ô´ÏÂÔØ¡¢¹ÜµÀ¡¢Git LFS¡¢µç×ÓÓʼþת´ï¡¢¹ºÖúÍÔÊÐíÒÔ¼°×¢²áµÈ¡£ÔÚ¹Ù·½×´Ì¬Ò³ÃæÉÏÐû²¼µÄÊÂÎñ±¨¸æÖУ¬BitbucketÌåÏÖÕýÔÚÊÓ²ìÓ°ÏìBitbucket WebºÍGit²Ù×÷µÄÎÊÌ⣬²¢ËæºóÐû²¼ÕýÔÚÊӲ조BitbucketÊý¾Ý¿â±¥ºÍ²¢Ó°ÏìËùÓвÙ×÷¡±µÄÎÊÌâ¡£ÏÖÔÚ£¬BitbucketÈÔÔÚÑ°ÕÒ½â¾ö¼Æ»®£¬²¢ÌåÏÖ½«ÔÚÏÂÒ»¸öСʱÄÚÌṩ¸ü¶àϸ½Ú¡£


https://www.bleepingcomputer.com/news/technology/bitbucket-services-hard-down-due-to-major-worldwide-outage/


3. Cloudflare »º½âÁË´´¼Í¼µÄ 5.6 Tbps DDoS ¹¥»÷


1ÔÂ21ÈÕ£¬Æù½ñΪֹ£¬×î´óµÄÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷·åÖµµÖ´ïÁËÿÃë5.6Tbps£¬ÓÉ»ùÓÚMiraiµÄ½©Ê¬ÍøÂçÌᳫ£¬Éæ¼°13,000̨ÊÜѬȾװ±¸£¬Ä¿µÄÊǶ«ÑǵÄÒ»¼Ò»¥ÁªÍø·þÎñÌṩÉÌ£¨ISP£©£¬ÊÔͼʹÆä·þÎṉ̃»¾¡£´Ë´Î»ùÓÚUDPµÄ¹¥»÷±¬·¢ÔÚÈ¥Äê10ÔÂ29ÈÕ£¬Ö»¹ÜÒ»Á¬ÁË80Ã룬µ«CloudflareÒÀ¸½Æä×ÔÖ÷µÄ¼ì²â»ººÍ½âϵͳÀֳɵÖÓù£¬Î´¶ÔÄ¿µÄÔì³ÉÓ°Ïì¡£2024Äê10Ô³õ£¬Cloudflare±¨¸æÁËÒ»´ÎÔçÆÚDDoS¹¥»÷£¬·åÖµµÖ´ï3.8Tbps£¬Ò»Á¬ÁË65Ã룬´´ÏÂÁËмͼ¡£Êý¾ÝÏÔʾ£¬³¬´óÈÝÁ¿DDoS¹¥»÷ÈÕÒæƵÈÔ£¬ÓÈÆäÔÚ2024ÄêµÚÈý¼¾¶ÈºóÏÔÖøÔö¶à£¬µÚËÄÐò¶È¹¥»÷Ç¿¶ÈÁè¼Ý1Tbps£¬»·±ÈÔöÌí1,885%¡£Í¬Ê±£¬Ã¿ÃëÁè¼Ý1ÒÚ¸öÊý¾Ý°üµÄ¹¥»÷Ò²ÔöÌíÁË175%¡£ÖµµÃ×¢ÖصÄÊÇ£¬Ö»¹Ü³¬´óÈÝÁ¿HTTP DDoS¹¥»÷½öÕ¼¼Í¼×ÜÊýµÄ3%£¬µ«¶ÌÔݵÄDDoS¹¥»÷È´Ô½À´Ô½Æձ飬Լ72%µÄHTTPºÍ91%µÄÍøÂç²ãDDoS¹¥»÷ÔÚ10·ÖÖÓÄÚ¿¢Ê£¬Õâ¶ÔÔÚÏß¡¢Ê¼ÖÕÔÚÏß¡¢×Ô¶¯»¯µÄDDoS·À»¤·þÎñÌá³öÁ˸ü¸ßÒªÇó¡£CloudflareÖ¸³ö£¬ÕâЩ¹¥»÷ͨ³£±¬·¢ÔÚá¯ÁëʹÓÃʱ¶Î£¬ÎªÊê½ðDDoS¹¥»÷ÌṩÁËʱ»ú£¬¸ÃÀàÐ͹¥»÷ÔÚµÚËÄÐò¶ÈºÍÊ¥µ®½Ú¼ÙÆÚµÖ´ïáÛ·å¡£


https://www.bleepingcomputer.com/news/security/cloudflare-mitigated-a-record-breaking-56-tbps-ddos-attack/


4. ºÚ¿ÍʹÓÃÁãÈÕÎó²î°²ÅÅAIRASHI½©Ê¬ÍøÂç·¢¶¯DDoS¹¥»÷


1ÔÂ22ÈÕ£¬ºÚ¿Í×éÖ¯ÕýʹÓÃCambium Networks cnPilot·ÓÉÆ÷ÖеÄδÅû¶ÁãÈÕÎó²î£¬°²ÅÅAIRASHI½©Ê¬ÍøÂç±äÖÖ£¬¸Ã±äÖÖÊÇAISURU£¨ÓÖ³ÆNAKOTNE£©µÄ½ø»¯°æ£¬Ö÷ÒªÓÃÓÚ·¢¶¯ÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷¡£×Ô2024Äê6ÔÂÆð£¬ÕâЩ¹¥»÷¾ÍÒÑʹÓøÃÎó²îʵÑ飬ÇÒΪ±ÜÃâÎó²î±»ÀÄÓã¬Ïà¹ØÊÖÒÕϸ½ÚÔÝδ¹ûÕæ¡£AIRASHI»¹Ê¹ÓÃÁ˶à¸öÒÑÖªÎó²î£¬¹¥»÷ÄÜÁ¦ÎȹÌÔÚ1-3 TbpsÖ®¼ä¡£ÊÜѬȾװ±¸Ö÷ҪλÓÚ°ÍÎ÷¡¢¶íÂÞ˹¡¢Ô½ÄϺÍÓ¡¶ÈÄáÎ÷ÑÇ£¬¶ø¹¥»÷Ä¿µÄÔò°üÀ¨Öйú¡¢ÃÀ¹ú¡¢²¨À¼ºÍ¶íÂÞ˹¡£AIRASHIÖÁÉÙ±£´æÁ½ÖÖ°æ±¾£ºAIRASHI-DDoSºÍAIRASHI-Proxy£¬ºóÕßÐÂÔöÁËÊðÀí¹¦Ð§¡£Ñо¿ÏÔʾ£¬ºÚ¿ÍÒ»Á¬Ê¹ÓÃÎïÁªÍø×°±¸Îó²î×齨½©Ê¬ÍøÂ磬ÖúÍÆ´ó¹æÄ£DDoS¹¥»÷¡£±ðµÄ£¬»¹Åû¶ÁË¿çƽ̨ºóÃųÌÐòalphatronBot£¬¸Ã³ÌÐò×Ô2023ÄêÍ·Æð»îÔ¾£¬Ä¿µÄ°üÀ¨ÖйúÕþ¸®¼°ÆóÒµ£¬Ê¹Óñ»Ñ¬È¾µÄWindowsºÍLinuxϵͳ×齨½©Ê¬ÍøÂ磬²¢Í¨¹ýÕýµ±µÄ¿ªÔ´P2P̸ÌìÓ¦ÓÃPeerChatͨѶ£¬´ó·ùÌá¸ß½©Ê¬ÍøÂçµÄ¶Ô¿¹Á¦¡£Í¬Ê±£¬»¹ÆÊÎöÁËDarkCracks¿ò¼Ü£¬¸Ã¿ò¼ÜʹÓÃÊÜѬȾµÄÍøÕ¾³äµ±ÏÂÔØÆ÷ºÍC2·þÎñÆ÷£¬ÍøÂçÃô¸ÐÐÅÏ¢£¬Î¬³Öºã¾Ã»á¼û¡£


https://thehackernews.com/2025/01/hackers-exploit-zero-day-in-cnpilot.html


5. WordPress RealHomeÖ÷ÌâÓëEasy Real Estate²å¼þÆسö¸ßΣÎó²î


1ÔÂ22ÈÕ£¬WordPressµÄRealHomeÖ÷ÌâºÍEasy Real Estate²å¼þ±»·¢Ã÷±£´æÁ½¸öÑÏÖØÎó²î£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§»ñµÃÖÎÀíȨÏÞ¡£ÕâЩÎó²îÓÉPatchstackÓÚ2024Äê9Ô·¢Ã÷£¬µ«Ö»¹Ü¶à´ÎʵÑéÁªÏµ¹©Ó¦ÉÌInspiryThemes£¬ÖÁ½ñÈÔδÊÕµ½»Ø¸´£¬ÇÒ¹©Ó¦ÉÌÐû²¼µÄа汾Ҳδ½â¾öÕâЩҪº¦ÎÊÌâ¡£RealHomeÖ÷ÌâµÄÎó²î±àºÅΪCVE-2024-32444£¬ÊÇÒ»¸öδ¾­Éí·ÝÑéÖ¤µÄȨÏÞÌáÉýÎÊÌ⣬¹¥»÷Õß¿Éͨ¹ýÌØÖÆHTTPÇëÇóÈƹýÇå¾²¼ì²é×¢²áΪÖÎÀíÔ±£¬´Ó¶øÍêÈ«¿ØÖÆÍøÕ¾¡£Easy Real Estate²å¼þµÄÎó²î±àºÅΪCVE-2024-32555£¬Ô´ÓÚÉç½»µÇ¼¹¦Ð§Î´ÑéÖ¤µç×ÓÓʼþµØµã£¬¹¥»÷ÕßÖªµÀÖÎÀíÔ±ÓÊÏä¼´¿ÉÎÞÃÜÂëµÇ¼¡£ÓÉÓÚÕâÁ½¸öÎó²îµÄCVSSÆÀ·Ö¾ùΪ9.8£¬ÇÒInspiryThemesÉÐδÐû²¼²¹¶¡£¬½¨ÒéÍøÕ¾ËùÓÐÕߺÍÖÎÀíÔ±Á¬Ã¦½ûÓÃÕâЩÖ÷ÌâºÍ²å¼þ£¬²¢ÏÞÖÆÓû§×¢²áÒÔ±ÜÃâδ¾­ÊÚȨµÄÕË»§½¨Éè¡£¼øÓÚÎó²îÒѹûÕ棬ѸËÙ·´Ó¦ÒÔ¼õÇáÍþвÖÁ¹ØÖ÷Òª¡£


https://www.bleepingcomputer.com/news/security/critical-zero-days-impact-premium-wordpress-real-estate-plugins/


6. Cloudflare CDNÎó²îÆع⣺¿É·¢ËÍͼÏñ̻¶Óû§´óÖÂλÖÃ


1ÔÂ22ÈÕ£¬Çå¾²Ñо¿Ö°Ô±µ¤Äá¶û·¢Ã÷CloudflareÄÚÈݽ»¸¶ÍøÂ磨CDN£©±£´æÎó²î£¬¿ÉÄÜͨ¹ýÔÚSignalºÍDiscordµÈƽ̨·¢ËÍͼÏñ̻¶Óû§´óÖÂλÖá£Ö»¹ÜµØÀí¶¨Î»²»·ó׼ȷ£¬µ«×ãÒÔÍƶÏÓû§ËùÔÚµØÀíÇøÓò²¢¼à¿ØÔ˶¯£¬¶ÔÒþ˽¸ß¶È¹Ø×¢ÕßÈç¼ÇÕß¡¢Ô˶¯¼ÒµÈ×é³ÉÍþв£¬¶ø¶ÔÖ´·¨²¿·ÖÔò¿ÉÄÜÓÐÖúÓÚÊӲ졣¸ÃÎó²îʹÓÃCloudflare½«Ã½Ìå×ÊÔ´»º±£´æÓû§ÖÜΧÊý¾ÝÖÐÐĵĻúÖÆ£¬Í¨¹ýÏòÄ¿µÄ·¢ËÍ°üÀ¨ÆæÒìͼÏñµÄÐÂÎÅ£¬Ê¹ÓÃCloudflare WorkersÖеÄÎó²îÇ¿ÖÆͨ¹ýÌض¨Ãü¾ÝÖÐÐÄ·¢³öÇëÇó£¬Æ¾Ö¤CDN·µ»ØµÄÊý¾ÝÖÐÐÄÖÜΧ»ú³¡´úÂë»æÖÆÓû§´óÖÂλÖá£ÕâÊÇÒ»ÖÖÁãµã»÷¹¥»÷£¬¸ú×Ù¾«¶ÈÔÚ50µ½300Ó¢ÀïÖ®¼ä£¬È¡¾öÓÚµØÇøºÍÖÜΧÊý¾ÝÖÐÐÄÊýÄ¿¡£Ñо¿Ö°Ô±ÏòCloudflare¡¢SignalºÍDiscordÅû¶Îó²î£¬CloudflareÒѱê¼ÇΪÒѽâ¾ö²¢¸øÓèÉͽ𣬵«µØÀí¶¨Î»¹¥»÷ÈÔ¿Éͨ¹ýÆäËû·½·¨ÊµÏÖ¡£SignalºÍDiscordÒÔΪÎÊÌâÊÇCloudflareµÄÔðÈΣ¬CloudflareÔòÌåÏÖ½ûÓûº´æÊÇÓû§µÄÔðÈΡ£


https://www.bleepingcomputer.com/news/security/cloudflare-cdn-flaw-leaks-user-location-data-even-through-secure-chat-apps/