2019ÉϰëÄêÍþвµý±¨»ã±¨£»2019ÄêQ2 DDoS¹¥»÷Ç÷Ïò»ã±¨£»¹í»ê·ì϶бäÖÖSWAPGS £¬¹©¸øÉÌÒѰ䲼½¨¸´²¹¶¡

°ä²¼¹¦·ò 2019-08-07
1¡¢¹í»ê·ì϶бäÖÖSWAPGS £¬¹©¸øÉÌÒѰ䲼½¨¸´²¹¶¡


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Bitdefender×êÑÐÈËÔ±·¢ÏÖCPU¹í»ê·ì϶µÄбäÖÖ-SWAPGS·ì϶ £¬¸Ã·ì϶¿ÉÔÊÐí¶ñÒⷨʽ½Ó¼ûºÍ¶ÁȡϵͳÄÚºËÄÚ´æÖеÄÊý¾Ý¡£SWAPGS·ì϶ÊÇÒ»ÖÖ´§Ä¦ÐÔÖ´ÐеIJâÐÅ··ì϶ £¬¹¥»÷ÕßÄܹ»ÀûÓÃ64λCPUÖеÄSWAPGSÖ¸ÁîÍ»ÆÆÄÚ´æ¸ôÀë £¬ÔÊÐíÎÞÌØÈ¨µÄ¹¥»÷Õß½Ó¼ûÌØÈ¨Äں˵ÄÄڴ档΢Èí¡¢ºìñÒÔ¼°Ó¢ÌضûºÍ¹È¸èµÈ¹©¸øÉÌÒѾ­°ä²¼ÁËÓйؽ¨¸´²¹¶¡ºÍÕ÷ѯ £¬AMDÔò³ÆËûÃǵIJúÆ·²»ÊÜÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/swapgs-vulnerability-in-modern-cpus-fixed-in-windows-linux-chromeos/


2¡¢NetScout°ä²¼2019ÉϰëÄêÍþвµý±¨»ã±¨ £¬DDoS¹¥»÷Ôö³¤39%


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


NetScout°ä²¼2019ÄêÉϰëÄêÍþвµý±¨»ã±¨ £¬¸Ã»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£º½©Ê¬ÍøÂçµÄËùÓÐÕßÔ½À´Ô½´ÏÃ÷ £¬¹¥»÷ÕßÔ½À´Ô½¶àµØÀûÓÃÖÇÄܼҾӴ«¸ÐÆ÷¡¢ÖÇÄÜÊÖ»ú¡¢Â·ÓÉÆ÷ÉõÖÁAppleÈí¼þµÄÖ°ÄÜÀ´¹¹½¨ºÍ±øÆ÷»¯ÐµĹ¥»÷ÏòÁ¿£»·¸×ïÕßרһÓÚÖеȹæÄ£µÄDDoS¹¥»÷ £¬Óë2018ÄêÉϰëÄêÏà±È £¬2019ÄêÉϰëÄêDDoS¹¥»÷µÄƵÂÊÔö³¤ÁË39% £¬Á÷Á¿ÔÚ100GbpsºÍ400GbpsÖ®¼äµÄ¹¥»÷ÊýÁ¿¸üÊÇÔö³¤Á˾ªÈ˵Ä776%£»·À»ðǽÊܵ½Á˳å»÷ £¬PoC¶ñÒâÈí¼þÔÚÕë¶Ô·À»ðǽºóÃæµÄIoTÉ豸£»µØÔµÕþÖÎÔ½À´Ô½¶àµØÊ¹ÓÃÍøÂçÕ½¹¥»÷¶Ô·½¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.netscout.com/press-releases/netscout-1h2019-threat-intelligence-report


3¡¢¿¨°Í˹»ù°ä²¼2019ÄêµÚ¶þ¼¾¶ÈDDoS¹¥»÷Ç÷Ïò»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾Ý¿¨°Í˹»ùµÄ2019ÄêQ2 DDoS¹¥»÷»ã±¨ £¬±¾¼¾¶ÈµÄDDoS¹¥»÷ÊýÁ¿±ÈÉÏÒ»¼¾¶ÈÉٵöà¡£ÕâÖÖ³Á¾²¿ÉÄÜÊÇÓÉÓÚÏļ¾ÍøÂç·¸×ï»î¶¯µÄ´«Í³ÐÔÏ÷¼õËùÖ £¬Óë2018ÄêQ2Ïà±È £¬¹¥»÷×ÜÊýÏÖʵÉÏÔö³¤ÁË18¸ö°Ù·Öµã £¬ÕâÒâζ×Å×Ô2019ËêÊ×ÒÔÀ´¹Û²ìµ½µÄDDoSÔö³¤Ç÷ÏòÒÀÈ»´æÔÚ¡£±¾¼¾¶ÈÖйú»¹ÊÇDDoS¹¥»÷ÊýÁ¿×î¶àµÄµØÓò£¨63.80£¥£© £¬Æä´ÎÊÇÃÀ¹ú£¨17.57£¥£©¡£±¾¼¾¶È³ÖÐø¹¦·ò×µÄ¹¥»÷´ï509¸öÓ×ʱ £¬´´ÏÂÁËеĺ¹Çà¼Í¼¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/ddos-report-q2-2019/91934/


4¡¢E3¹ÙÍøÒâ±íй¶2000¶àÃû²ÎÕ¹¼ÇÕßµÄÒþÖÔÐÅÏ¢

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


YouTube²©Ö÷Sophia Narwitz·¢ÏÖE3µÄ¹ÙÍøÉÏй¶ÁËÒ»·ÝÔ̺¬2000¶àÃû¼ÇÕßÐÅÏ¢µÄµç×Ó±í¸ñ £¬±í¸ñÖÐй¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç»°ºÅÂëºÍסַµÈ¡£ÊÜÓ°ÏìµÄ¼ÇÕßÀ´×Ô¸÷´óÐÂÎÅýÌå £¬Ô̺¬Vice¡¢ÓÎÏ·ÍøÕ¾Polygon¡¢IMDb¡¢iHeartMediaÒÔ¼°YouTubeºÍTwitch¡£¸Ã±í¸ñ¿ÉÔÚE3¹ÙÍøÉϹ«¿ªÏÂÔØ £¬ÔÚNarwitz֪ͨE3×éÖ¯ÕßESAÖ®ºó £¬¸Ã±í¸ñµÄÏÂÔØÁ´½ÓÒѲ»³ÉÓá£E3 2019ÓÚ½ñÄê6ÔÂ11ÈÕÖÁ6ÔÂ13ÈÕÔÚÂåÉ¼í¶½øÐÐ £¬¹²ÎüÒýÁË1.5ÍòÈ˲ÎÕ¹¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/e3-website-leaks-private-addresses-for-thousands-of-journalists/146965/


5¡¢ÐÂÍøÂç¼äµý×éÖ¯Machete £¬ÖØÒªÕë¶ÔίÄÚÈðÀ­

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ESET×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÍøÂç¼äµý×éÖ¯Machete £¬¸Ã×éÖ¯ÖØÒª¶Ô׼ίÄÚÈðÀ­¾ü·½ £¬ÊÔͼÇÔÈ¡Æä»úÃÜÎļþ¡£¸Ã×éÖ¯×Ô2010ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬²¢¶¨ÆÚÉý¼¶Æä±øÆ÷¿âÒÔ¼°»ù´¡ÉèÊ©ÖеĶñÒâÈí¼þ¡£ÔÚ2019Äê3ÔÂÖÁ5ÔÂÆÚ¼ä £¬ESET¹Û²ìµ½ÖÁÉÙ50´ÎϰȾÊÂÎñ¡£´óÎÞÊýϰȾÊÂÎñ£¨75£¥£©²úÉúÔÚίÄÚÈðÀ­ £¬Æä´ÎÊǸçÂ×±ÈÑÇ£¨16£¥£©¡£ESET×êÑÐÈËԱûÓн«MacheteÓëÈκÎÌØ¶¨µ±¾Ö½øÐйØÁª¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/89437/apt/machete-targets-venezuela.html


6¡¢×êÑÐÈËÔ±°ä²¼ÀÕË÷Èí¼þECh0raixµÄ½âÃܹ¤¾ß


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÔ±BloodDolly°ä²¼ÀÕË÷Èí¼þeCh0raixµÄ½âÃÜÆ÷ £¬¸ÃÀÕË÷Èí¼þ±ðÃûQNAPCrypt £¬×Ô2018Äê6ÔÂÒÔÀ´Ò»Ö¹Øë¶ÔQNAP NASÉ豸¡£Ò»µ©Í¨¹ý±©Á¦ÆÆ½âºÍ·ì϶ÀûÓûñµÃQNAPÉ豸µÄ½Ó¼ûȨÏÞ £¬¸ÃÀÕË÷Èí¼þ½«¼ÓÃÜÉ豸ÉϵÄÎļþ²¢¸½¼Ó.encryptedÀ©´óÃû¡£±ØÒª°ÑÎȵÄÊǵ±Ç°°æ±¾µÄ½âÃÜÆ÷Ö»ÄܽâÃÜ7ÔÂ17ÈÕ֮ǰ±»¼ÓÃܵÄÎļþ £¬×êÑÐÈËÔ¹ØýÖÂÁ¦ÓÚ¿ª·¢ºÏÓÃÓÚ×îбäÌåµÄ½âÃÜÆ÷¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/ransomware/decryptor/ech0raix-ransomware-decryptor-restores-qnap-files-for-free/