Ç×¶íºÚ¿Í×éÖ¯DDoS¹¥»÷µ¤ÂóÑ¡¾ÙÍøÕ¾
°ä²¼¹¦·ò 2025-11-201. Ç×¶íºÚ¿Í×éÖ¯DDoS¹¥»÷µ¤ÂóÑ¡¾ÙÍøÕ¾
11ÔÂ19ÈÕ£¬£¬´¦ËùÑ¡¾ÙǰϦ£¬£¬µ¤Âó¶à¸öÕþµ³¼°µ±¾ÖÍøÕ¾Ôâ·êÇ×¶íºÚ¿Í×éÖ¯NoName057(16)ÌáÒéµÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬£¬µ¼ÖÂÊØ¾Éµ³¡¢¡¢¡¢ºìÂÌÁªÃË¡¢¡¢¡¢ºÍÉÆµ³¡¢¡¢¡¢Éç»áÃñÖ÷µ³µÈÍøÕ¾¼°¡¶¸ç±¾¹þ¸ùÓʱ¨¡··þÎñÆ÷¶ÌÔÝ̱»¾£¬£¬µ«Ñ¡¾ÙͶƱδÊÜ×ÌÈÅ¡£¡£¸Ã×éÖ¯ÒÔDDoS¹¥»÷ÎÅÃû£¬£¬Ðû³ÆÕâ´ÎÐж¯Ö¼ÔÚÖÆ×÷»ìÂÒ£¬£¬µ«µ¤ÂóÉç»á±£ÏÕ¾ÖÓë¾üʵý±¨²¿ÃÅÖ¸³ö£¬£¬´ËÀ๥»÷ÔÚµ¤ÂóÒѳɡ°³£Ì¬¡±£¬£¬¶àÓɲ©È¡¹Ø×¢µÄ¼¯ÌåÖ´ÐУ¬£¬¶ø·Ç×·ÇóÕ½ÊõÀûÒæ¡£¡£Ñ¡¾Ù¹ÙԱǿµ÷£¬£¬Í¶Æ±ÆëÈ«ÓÉÈËΪʵÏÖ£¬£¬Ñ¡ÃñÖܶþÕý³£Ç°ÍùͶƱվ£¬£¬ÍøÂçÖжÏδӰÏìÁ˾֡£¡£µ¤Âóµ±¾Ö½üÆÚ¼à²âµ½¹«¹²¼°Ë½Óª²¿ÃÅÍøÕ¾¹¥»÷Ôö¶à£¬£¬ºÜ¶àÊÂÎñ±»Ç×¶í×éÖ¯ÈÏÁì¡£¡£ÀýÈç±¾Ô³õ£¬£¬µ±¾ÖÓë¹ú·À¹«Ë¾ÍøÕ¾ÔøÒòDDoS¹¥»÷¶ÌÔÝÏÂÏߣ¬£¬¹ÙÔ±´§Ä¦¹¥»÷ԴΪ¶íÂÞ˹¡£¡£NoName057(16)³ÉÁ¢ÓÚ2022Äê¶íÎÚì¶Üºó£¬£¬×¨Ò»ÓÚ·¢Æð¶ÌÆÚDDoS¹¥»÷£¬£¬Ö¸±êº¸Ç²¨À¼¡¢¡¢¡¢½Ý¿Ë¡¢¡¢¡¢Á¢ÌÕÍ𡢡¢¡¢Òâ´óÀûµÈÅ·ÖÞ¹ú¶È¡£¡£Ö»¹ÜÅ·ÃÀ·¨Âɲ¿ÃŽñÄê7Ô²é»ñ¸Ã×éÖ¯100Óą̀·þÎñÆ÷£¬£¬µÂ¹ú¶ÔÁùÃû¶íÂÞ˹¼®³ÉÔ±·¢³ö¿ÛÁôÁ£¬µ«¸Ã×éÖ¯ÈÔÖðÈÕͨ¹ýXºÍTelegramƵµÀ°ä·¢ÐÂÖ¸±ê¡£¡£
https://therecord.media/denmark-election-political-government-websites-ddos-incidents
2.FortinetÐÞ¸´ÁãÈÕ·ì϶£¬£¬ÍþвÐÐΪÕßÌáÒé¹¥»÷
11ÔÂ18ÈÕ£¬£¬È«ÇòÍøÂ簲ȫ³§ÉÌFortinet°ä²¼´¹Î£°²È«¸üУ¬£¬ÐÞ¸´ÆìÏÂFortiWeb WebÀûÓ÷À»ðǽÖÐÁ½¸ö±»»ý¼«ÀûÓõÄÁãÈÕ·ì϶¡ª¡ªCVE-2025-58034ºÍCVE-2025-64446¡£¡£ÆäÖУ¬£¬CVE-2025-58034ÓÉÇ÷Ïò¿Æ¼¼×êÑÐÍŶӻ㱨£¬£¬ÊôÓÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶£¬£¬¹¥»÷Õß¿Éͨ¹ý»ú¹ØHTTPÒªÇó»òCLIºÅÁîÔڵײãϵͳִÐÐËÁÒâ´úÂ룬£¬ÎÞÐèÓû§½»»¥ÇÒ¼¼ÊõÃż÷µÍ¡£¡£Fortinet֤ʵ£¬£¬¸Ã·ì϶Òѱ»ÍþвÐÐΪÕßÓÃÓÚÏÖʵ¹¥»÷£¬£¬Ç÷Ïò¿Æ¼¼¼à²âµ½Ô¼2000´Î¹¥»÷³¢ÊÔ¡£¡£ÁíÒ»·ì϶CVE-2025-64446ÔòÔÊÐí¹¥»÷Õßͨ¹ýHTTP POSTÒªÇóÔÚ¶³öÉ豸ÉÏ´´½¨ÖÎÀíÔ±ÕË»§£¬£¬´ËǰÒÑÒý·¢´ó¹æÄ£ÀûÓᣡ£ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«¸Ã·ì϶ÁÐÈë"ÒÑÖª±»ÀûÓ÷ì϶Ŀ¼"£¬£¬ÒªÇóÁª°î»ú¹¹ÓÚ11ÔÂ21ÈÕǰʵÏÖÐÞ¸´¡£¡£Õë¶Ô·ì϶ÐÞ¸´£¬£¬Fortinet½¨ÒéÖÎÀíÔ±½«FortiWebÉ豸Éý¼¶ÖÁ×îа汾£º8.0.2¡¢¡¢¡¢7.6.6¡¢¡¢¡¢7.4.11¡¢¡¢¡¢7.2.12»ò7.0.12¼°ÒÔÉÏ¡£¡£
https://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-fortiweb-zero-day-exploited-in-attacks/
3. ChromeÁãÈÕ·ì϶±»ÀûÓ㬣¬¹È¸è´¹Î£°ä²¼ÐÞ¸´
11ÔÂ18ÈÕ£¬£¬¹È¸è°ä²¼´¹Î£°²È«¸üУ¬£¬ÐÞ¸´Chromeä¯ÀÀÆ÷V8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶CVE-2025-13223¡£¡£¸Ã·ì϶Òѱ»Ö¤ÊµÔâÏÖʵÀûÓ㬣¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâ»ú¹ØµÄÍøÒ³´¥·¢·ì϶£¬£¬µ¼ÖÂä¯ÀÀÆ÷±ÀÀ£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¹È¸èÍþв·ÖÎöС×飨TAG£©Ö¸³ö£¬£¬´ËÀà·ì϶³£±»µ±¾ÖÖ§³ÖµÄ¼äµý×éÖ¯ÀûÓ㬣¬Õë¶Ô¼ÇÕß¡¢¡¢¡¢Òì¼ûÈËÊ¿µÈ¸ß·çÏÕȺÌåÖ´Ðо«×¼¹¥»÷¡£¡£Õâ´ÎÐÞ¸´¸²¸ÇWindows£¨142.0.7444.175/176£©¡¢¡¢¡¢Mac£¨142.0.7444.176£©¼°Linux£¨142.0.7444.175£©Æ½Ì¨¡£¡£Ö»¹ÜChromeͨ³£×Ô¶¯¸üУ¬£¬Óû§ÈÔ¿Éͨ¹ý¡°²Ëµ¥-Ô®ÊÖ-¹ØÓÚGoogle Chrome¡±ÊÖ¶¯²é³²¢×°Öò¹¶¡¡£¡£¹È¸è°µÊ¾£¬£¬ÔÚÎÞÊýÓû§ÊµÏÖ¸üÐÂǰ£¬£¬½«ÏÞ¶È·ì϶ϸ½Ú¹«¿ª£¬£¬Ô¤·ÀµÚÈý·½¿âÒÀÀµ¸Ã·ì϶µÄÑÜÉú·çÏÕ¡£¡£CVE-2025-13223Êǹȸè½ñÄêÐÞ¸´µÄµÚÆß¸ö±»ÀûÓõÄChromeÁãÈÕ·ì϶¡£¡£
https://www.bleepingcomputer.com/news/security/google-fixes-new-chrome-zero-day-flaw-exploited-in-attacks/
4. Everest GroupÀÕË÷ÍŻ﹥»÷°ÍÎ÷ʯÓ;ÞÍ·Petrobras
11ÔÂ18ÈÕ£¬£¬Óë¶íÂÞ˹¹ØÁªµÄÀÕË÷Èí¼þÍÅ»ïEverest Group½üÈÕÐû³Æ£¬£¬´Ó°ÍÎ÷¹ú¶ÈʯÓ͹«Ë¾PetrobrasÇÔÈ¡90GBÃô¸ÐµØÕð¿±Ì½Êý¾Ý£¬£¬Ô̺¬¿²²¨Ë¹ÅèµØÑλù²ãÈýά/ËÄάµØÕ𵼺½Êý¾Ý¡¢¡¢¡¢OBN½ÚµãµØÎ»¡¢¡¢¡¢DGPS¾«¶È¡¢¡¢¡¢É豸ԪÊý¾Ý¼°ÖÊÁ¿½ÚÖÆ»ã±¨µÈ£¬£¬²¢ÏÞ¶¨ÁùÌìÄÚ½»ÉæÊê½ð£¬£¬²»È»½«¹«¿ª»òÏúÊÛÊý¾Ý¡£¡£Petrobras×÷Ϊ°ÍÎ÷¹úÓпعɿç¹úÄÜÔ´ÆóÒµ£¬£¬2024ÄêÊÕÈ볬910ÒÚÃÀÔª£¬£¬Æä½üÆÚÔÚ¿²²¨Ë¹ÅèµØµÄÓÅÖÊʯÓÍ·¢ÏÖÓëй¶Êý¾Ý¸ß¶È¹ØÁª£¬£¬¿ÉÄÜÉæ¼°¿±Ì½¼¼Êõ»úÃÜ¡£¡£Cybernews·ÖÎöÖ¸³ö£¬£¬Ð¹Â¶Êý¾ÝËäδ¶³öʵʱ×÷ҵϵͳ£¬£¬µ«´¬²°×ø±ê¡¢¡¢¡¢É豸²ÎÊý¼°¿±Ì½³É¾ÍµÄÆØ¹â½«¼õÈõPetrobrasµÄ¾ºÕùÓÅÊÆ²¢ÇÖº¦ÃûÓþ¡£¡£
https://cybernews.com/security/brazil-petrobras-ransomware-attack/
5. CloudflareÈ«Çò·þÎñÖжÏÖÂÒÚÍòÓû§Åö±Ú
11ÔÂ18ÈÕ£¬£¬È«ÇòÔÆ·þÎñÌṩÉÌCloudflareÒò¼¼Êõ¹ÊÕÏÒý·¢´ó¹æÄ£»£»£»¥ÁªÍø½Ó¼ûÖжϣ¬£¬Ó°ÏìÁìÓò²¨¼°È«ÇòÊýÒÚÓû§¡£¡£ÊÂÎñʼÓÚ¸ñÁÖÍþÖα궨¹¦·ò11:48£¬£¬CloudflareÍøÂç³öÏÖ"ÄÚ²¿·þÎñ½µ¼¶"£¬£¬µ¼ÖÂÓû§ÎÞ·¨½Ó¼ûÒÀÀµÆä·þÎñµÄÍøÕ¾¼°ÀûÓ÷¨Ê½£¬£¬Ô̺¬X¡¢¡¢¡¢ChatGPT¡¢¡¢¡¢Spotify¡¢¡¢¡¢GrindrµÈÈÈµãÆ½Ì¨¡£¡£Cloudflare×÷ΪȫÇò19%»îÔ¾ÍøÕ¾¼°35%²Æ¸»500Ç¿ÆóÒµµÄµ×²ã·þÎñÉÌ£¬£¬ÆäÿÃë´¦ÖÃ8100Íò´ÎHTTPÒªÇóµÄÄÜÁ¦ÔÚ¹ÊÕÏÆÚ¼äÑÏÖØÅö±Ú£¬£¬Òý·¢Á¬Ëø·´Ó³¡£¡£½ØÖÁ14:30£¬£¬CloudflareËäÐû³ÆÖ´ÐÐÐÞ¸´·¨Ê½²¢½â¾öÖØÒªÎÊÌ⣬£¬µ«¼äЪÐÔÃýÎóÈÔ³ÖÐø´æÔÚ£¬£¬Â׶صØÓòWARP·þÎñÔø¶ÌÔݽûÓúó¸´Ô¡£¡£Õâ´ÎÖжϲ»½öÔì³ÉÓû§µÇ¼¡¢¡¢¡¢ÍøÕ¾½Ó¼û¼°½ÚÖÆÃæ°å²Ù×÷ÄÑÌ⣬£¬¸ü¶³öÁËÈ«ÇòÊý×Ö»ù´¡ÉèÊ©µÄ¸ß¶ÈÒÀÀµÐÔ¡£¡£¾¼ÃËðʧ·½Ã棬£¬¾ÝSupportMy.Website¹ÀË㣬£¬Ã¿Ð¡Ê±Í£»£»£»ú¿ÉÄܵ¼ÖÂÆóÒµËðʧ50ÒÚÖÁ150ÒÚÃÀÔª£¬£¬´Ó´óÐÍÒøÐе½Ð¡ÐÍÆóÒµ¾ùÊܲ¨¼°¡£¡£
https://cybernews.com/news/cloudflare-outage-internet-down/
6. ÃÀÓ¢°Ä½áºÏÖÆ²Ã¶íÂÞ˹·Àµ¯Ö÷»úÌṩÉÌ
11ÔÂ19ÈÕ£¬£¬ÃÀ¹ú¡¢¡¢¡¢Ó¢¹úºÍ°Ä´óÀûÑǽáºÏ°ä·¢¶ÔÖ§³ÖÀÕË÷Èí¼þÍŻPÆäËûÍøÂç·¸×ï»î¶¯µÄ¶íÂÞ˹·Àµ¯Ö÷»ú£¨BPH£©ÌṩÉÌÖ´ÐÐÖÆ²Ã£¬£¬Ö¼ÔÚ½ø¹¥ÍøÂç·¸×ïÉú̬Á´µÄ¹Ø¼ü»·½Ú¡£¡£Õâ´ÎÖÆ²Ã¾Û½¹ÓÚMedia Land¼°ÆäÈý¼Òæ¢Ãù«Ë¾£¨Media Land Technology¡¢¡¢¡¢Data Center Kirishi¡¢¡¢¡¢ML Cloud£©£¬£¬ÒÔ¼°ÈýÃû¸ß¹ÜAleksandr Volosovik¡¢¡¢¡¢Kirill ZatolokinºÍYulia Pankova¡£¡£ÕâЩʵÌåºÍСÎÒ±»Ö¸¿ØÎªLockBit¡¢¡¢¡¢BlackSuit¡¢¡¢¡¢PlayµÈÀÕË÷Èí¼þ×éÖ¯¼°Evil Corp¡¢¡¢¡¢Black BastaµÈÍøÂç·¸×OÍÅÌṩ·þÎñÆ÷×âÁÞ·þÎñ£¬£¬ÖúÆä·¢Õ¹ÍøÂç´¹µö¡¢¡¢¡¢¶ñÒâÈí¼þ´«²¼¡¢¡¢¡¢ºÅÁîÓë½ÚÖÆ²Ù×÷¡¢¡¢¡¢DDoS¹¥»÷¼°·¸·¨ÄÚÈÝÍйܵȻ¡£¡£Media LandµÄ»ù´¡ÉèÊ©ÉõÖÁ±»ÓÃÓÚ¹¥»÷ÃÀ¹ú¹Ø¼ü»ù´¡ÉèÊ©£¬£¬ÈçµçÐÅϵͳ¡£¡£ÃÀ¹ú²ÆÕþ²¿Íâ¹ú×ʲú½ÚÖÆ°ì¹«ÊÒ£¨OFAC£©½«ÉÏÊöʵÌåÁÐÈëÖÆ²ÃÃûµ¥£¬£¬¶³½áÆäÔÚÃÀ¹ú¾³ÄڵIJƸ»£¬£¬²¢ÖÒ¸æÓëÕâЩʵÌåÂòÂôµÄµÚÈý·½¿ÉÄÜÃæ¶Ô¶þ¼¶ÖƲᣡ£Ó¢¹úÍâ½»²¿Ç¿µ÷£¬£¬ÍøÂç·¸×ï·Ö×ÓÎÞ·¨ÌÓÍÑ×·Ô𣬣¬Ó¢ÃÀ°Ä½«½áºÏ¸æ·¢ÆäÒõÓôÍøÂç¡£¡£
https://www.bleepingcomputer.com/news/security/us-sanctions-russian-bulletproof-hosting-provider-media-land-over-ransomware-ties/


¾©¹«Íø°²±¸11010802024551ºÅ