NB65³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦Öóͷ£Æ½Ì¨Qiwi 10.5TBÊý¾Ý

Ðû²¼Ê±¼ä 2022-05-10
1¡¢NB65³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦Öóͷ£Æ½Ì¨Qiwi 10.5 TBµÄÊý¾Ý 


¾ÝýÌå5ÔÂ9ÈÕ±¨µÀ£¬£¬£¬ £¬ £¬£¬AnonymousÁ¥Êô»ú¹¹NB65Éù³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦Öóͷ£Æ½Ì¨Qiwi 10.5 TBµÄÊý¾Ý¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨3000ÍòÌõÖ§¸¶¼Í¼£¬£¬£¬ £¬ £¬£¬ÆäÖÐÉæ¼°1250ÍòÕÅÐÅÓÿ¨¡£¡£¸ÃÍŻﻹÐû²¼ÁËÒ»·ÝÉùÃ÷£¬£¬£¬ £¬ £¬£¬ÌåÏִ˴ι¥»÷Ö¼ÔÚÈÅÂÒ¶íÂÞ˹½ðÈÚϵͳ¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß»¹Ê¹ÓÃÀÕË÷Èí¼þ¼ÓÃÜÁËÆ½Ì¨µÄϵͳ£¬£¬£¬ £¬ £¬£¬²¢ÍþвҪÔÚ3ÌìÏÞÆÚʺ󣬣¬£¬ £¬ £¬£¬ÌìÌìÐû²¼100ÍòÌõ¼Í¼¡£¡£5ÔÂ5ÈÕ£¬£¬£¬ £¬ £¬£¬NB65ÒѹûÕæÁË700ÍòÕÅÖ§¸¶¿¨Êý¾Ý£¬£¬£¬ £¬ £¬£¬×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£¡£Qiwi·ñ¶¨ÁËÔâµ½Á˹¥»÷£¬£¬£¬ £¬ £¬£¬»¹ÌåÏÖÆäÖ§¸¶Ð§ÀÍÔËÐÐÕý³££¬£¬£¬ £¬ £¬£¬¿Í»§Êý¾ÝÒ²ºÜÇå¾²¡£¡£


https://www.hackread.com/anonymous-nb65-hacki-russia-payment-processor-qiwi/


2¡¢Ó¢Î°´ïÒòδÅû¶¼ÓÃܻ¶ÔÓÎÏ·ÓªÒµµÄÓ°Ïì±»·£¿£¿£¿£¿î550ÍòÃÀÔª


¾Ý5ÔÂ6ÈÕ±¨µÀ£¬£¬£¬ £¬ £¬£¬Ó¢Î°´ï£¨NVIDIA£©±»ÃÀ¹ú֤ȯÉúÒâίԱ»á(SEC)·£¿£¿£¿£¿î550ÍòÃÀÔª¡£¡£´Ë´Î´¦·ÖµÄÀíÓÉΪδ³ä·ÖÅû¶¼ÓÃÜÇ®±Ò¶ÔÆäÓÎÏ·ÓªÒµµÄÓ°Ïì¡£¡£´Ó2017Äê×îÏÈ£¬£¬£¬ £¬ £¬£¬¿Í»§Ô½À´Ô½¶àµØÊ¹ÓÃNVIDIA GPUÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£SEC·¢Ã÷£¬£¬£¬ £¬ £¬£¬NVIDIAÔÚ2018²ÆÄêÒ»Á¬µÄ¼¸¸ö¼¾¶ÈÖУ¬£¬£¬ £¬ £¬£¬Î´ÄÜÅû¶¼ÓÃÜÍÚ¿óÊÇÆäÏúÊÛΪÓÎÏ·Éè¼ÆµÄGPU´øÀ´µÄʵÖÊÐÔÊÕÈëÔöÌíµÄÖ÷ÒªÒòËØ¡£¡£ÏÖÔÚ£¬£¬£¬ £¬ £¬£¬NVIDIAÔ޳ɲ¢Ö§¸¶ÁË550ÍòÃÀÔªµÄ·£¿£¿£¿£¿î¡£¡£


https://www.bleepingcomputer.com/news/technology/nvidia-fined-for-failure-to-disclose-cryptomining-sales-boost/


3¡¢Uptycs·¢Ã÷½üÆÚÕë¶ÔDocker API¶Ë¿Ú2375µÄ¶ñÒâ»î¶¯


UptycsÔÚ5ÔÂ5ÈÕÐû²¼±¨¸æ£¬£¬£¬ £¬ £¬£¬³ÆÆä·¢Ã÷½üÆÚÕë¶ÔDocker API¶Ë¿Ú2375µÄ¶ñÒâ»î¶¯¡£¡£ÕâЩ¹¥»÷Óë¼ÓÃÜ¿ó¹¤ÓйØ£¬£¬£¬ £¬ £¬£¬²¢ÔÚÄ¿µÄЧÀÍÆ÷ÉÏʹÓÃcmdlineÖеÄbase64±àÂëÏÂÁî¾ÙÐз´Ïòshell£¬£¬£¬ £¬ £¬£¬Ö¼ÔÚÈÆ¹ý·ÀÓù»úÖÆ¡£¡£Ñо¿Ö°Ô±×ܹ²·¢Ã÷ÁË3ÖÖÀàÐ͵Ĺ¥»÷£¬£¬£¬ £¬ £¬£¬»®·ÖΪ¿ó¹¤¹¥»÷¡¢·´Ïòshell¹¥»÷ºÍKinsing¶ñÒâÈí¼þ¹¥»÷¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ £¬ £¬£¬Ã»ÓнÓÄÉÊʵ±±£»£»£»£»¤²½·¥µÄDockerÒ×±»¹¥»÷ÕßʹÓᣡ£


https://www.uptycs.com/blog/vulnerable-docker-installations-are-a-playhouse-for-malware-attacks?hs_preview=roycVWho-72459548548


4¡¢OpenSeaµÄDiscordЧÀÍÆ÷±»ºÚ²¢±»ÓÃÀ´Ðû²¼Ðéαͨ¸æ


ýÌå5ÔÂ7Èճƣ¬£¬£¬ £¬ £¬£¬OpenSeaµÄDiscordЧÀÍÆ÷±»ºÚ²¢±»ÓÃÀ´Ðû²¼Ðéαͨ¸æ¡£¡£OpenSeaÊÇÒ»¸öNFTÉúÒâÊг¡£¬£¬£¬ £¬ £¬£¬ËüÔÚ5ÔÂ6ÈÕÐû²¼ÁËÒ»ÕŽØÍ¼£¬£¬£¬ £¬ £¬£¬ÊǹØÓÚÏàÖúͬ°é¹ØÏµµÄÐéαͨ¸æ£¬£¬£¬ £¬ £¬£¬ÆäÖл¹°üÀ¨Ö¸Ïò´¹ÂÚÍøÕ¾µÄÁ´½Ó¡£¡£OpenSea³Æ£¬£¬£¬ £¬ £¬£¬ÆäDiscordЧÀÍÆ÷ÓÚÉÏÖÜÎåÔçÉÏÔâµ½¹¥»÷£¬£¬£¬ £¬ £¬£¬ËûÃǽ¨ÒéÓû§²»Òª¹Ø×¢ÆµµÀÉÏÐû²¼µÄÈκÎÁ´½Ó¡£¡£¾ÝϤ£¬£¬£¬ £¬ £¬£¬¹¥»÷ÕßʹÓÃÁËWebhook»á¼ûЧÀÍÆ÷¿Ø¼þÀ´ÈëÇÖÆäÍøÂ磬£¬£¬ £¬ £¬£¬²¢¾ÙÐд¹ÂÚ¹¥»÷¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬ £¬ £¬£¬ÒÑÓÐ13¸öÇ®°ü±»µÁ¡£¡£


https://insidebitcoins.com/news/opensea-discord-server-hacked-increasing-the-risk-of-phishing-scams


5¡¢Î¢ÈíÐû²¼AzureÖÐRCEÎó²îCVE-2022-29972µÄ²¹¶¡


5ÔÂ9ÈÕ£¬£¬£¬ £¬ £¬£¬Î¢ÈíÐû²¼ÁËAzureÖеÄRCEÎó²î£¨CVE-2022-29972£©µÄ²¹¶¡¡£¡£¸ÃÎó²îÒ²±»³ÆÎªSynLapse£¬£¬£¬ £¬ £¬£¬Ó°ÏìÁËAzure SynapseºÍAzure Data Factory¹ÜµÀ£¬£¬£¬ £¬ £¬£¬ÒÑÓÚ4ÔÂ15ÈÕ»ñµÃ»º½â£¬£¬£¬ £¬ £¬£¬ÔÚ²¹¶¡Ðû²¼Ö®Ç°²¢Î´±»Ê¹Óᣡ£Orca Security³Æ£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»á¼ûºÍ¿ØÖÆÆäËû¿Í»§µÄSynapseÊÂÇéÇø£¬£¬£¬ £¬ £¬£¬ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý£¨°üÀ¨AzureµÄЧÀÍÃÜÔ¿¡¢APIÁîÅÆºÍÃÜÂëµÈ£©¡£¡£Î¢ÈíÔö²¹µÀ£¬£¬£¬ £¬ £¬£¬¸ÃÎó²î¿É±»ÓÃÓÚ¿çIR»ù´¡ÉèʩִÐÐÔ¶³ÌÏÂÁîÖ´ÐС£¡£


https://www.bleepingcomputer.com/news/security/microsoft-releases-fixes-for-azure-flaw-allowing-rce-attacks/


6¡¢Ñо¿ÍŶÓÐû²¼ÐÅÓÿ¨ÇÔÈ¡¶ñÒâÈí¼þCaramelµÄÆÊÎö±¨¸æ


5ÔÂ5ÈÕ£¬£¬£¬ £¬ £¬£¬Domain ToolsÐû²¼Á˹ØÓÚÐÅÓÿ¨ÇÔÈ¡¶ñÒâÈí¼þCaramelµÄÆÊÎö±¨¸æ¡£¡£CaramelÊÇÒ»ÖÖskimmer-as-a-service£¬£¬£¬ £¬ £¬£¬ÓɶíÂÞ˹ÍÅ»ïCaramelCorpÔËÓª¡£¡£¸ÃЧÀ͵ÄÖÕÉí¶©ÔÄÓöÈΪ2000ÃÀÔª£¬£¬£¬ £¬ £¬£¬½öÃæÏò½²¶íÓïµÄ¹ºÖÃÕß¡£¡£¹¦Ð§´óÖ°üÀ¨°²ÅÅ¡¢ÍøÂç¡¢ÖÎÀíºÍÈÆ¹ý¼ì²â£¬£¬£¬ £¬ £¬£¬¾Ý³ÆËü¿ÉÒÔÈÆ¹ýCloudflare¡¢AkamaiºÍIncapsulaµÈ¹«Ë¾µÄ±£»£»£»£»¤Ð§ÀÍ¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷Á˸ÃЧÀ͵ÄÖÎÀíÃæ°å±£´æ¼¸¸öÓëÉí·ÝÑéÖ¤Ïà¹ØµÄÊÖÒÕ¹ýʧ¡£¡£


https://www.domaintools.com/resources/blog/a-sticky-situation-part-1-the-pervasive-nature-of-credit-card-skimmers