Êý°ÙÆóÒµÔâCodecov¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬¿°±ÈSolarWinds¹¥»÷£»£»£»£»£»£»£»£»QuantaϰȾREvil£¬£¬£¬£¬£¬£¬£¬ £¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶±»ÀÕË÷5ǧÍò

°ä²¼¹¦·ò 2021-04-22

1.Êý°Ù¸öÆóÒµÔâµ½Codecov¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬¿°±ÈSolarWinds¹¥»÷


1.jpg


·͸É籨·³Æ£¬£¬£¬£¬£¬£¬£¬ £¬ÒѺ±¼û°Ù¸öÆóÒµÔâµ½Codecov¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬¿ÉÓë×î½üµÄSolarWinds¹¥»÷µÈÁ¿Æë¹Û¡£¡£¡£¡£¡£CodecovÕ¼ÓÐ29000¶à¸ö¿Í»§£¬£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬GoDaddy¡¢AtlassianºÍProcter£¦Gamble£¨P£¦G£©µÈ³ÛÃû¹«Ë¾¡£¡£¡£¡£¡£³õ´ëÊ©²éÏÔʾ£¬£¬£¬£¬£¬£¬£¬ £¬ºÚ¿Í´Ó1ÔÂ31ÈÕÆðÍ·¶¨ÆÚ¶ÔBash Uploader¾ç±¾½øÐд۸쬣¬£¬£¬£¬£¬£¬ £¬ÒÔÇÔÈ¡´æ´¢ÔÚ´æ´¢ÔÚCI»·¾³ÖеÄÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ £¬Ö±µ½4ÔÂ1Èղű»·¢ÏÖ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬ £¬IBMµÈCodecovµÄ¶à¸ö¿Í»§¶¼°µÊ¾ËûÃǵĴúÂëÉÐδ±»´Û¸Ä£¬£¬£¬£¬£¬£¬£¬ £¬µ«»Ø¾øÐ¹Â©ÆäϵͳÊÇ·ñÔâµ½¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/


2.QuantaϰȾREvil£¬£¬£¬£¬£¬£¬£¬ £¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶²¢±»ÀÕË÷5000Íò


2.jpg


Öйų́ÍåµÄQuantaϰȾREvil£¬£¬£¬£¬£¬£¬£¬ £¬Apple¹«Ë¾Ô̺¬¼´½«°ä²¼µÄ²úÆ·ÔÚÄڵĴóÁ¿Éè¼ÆÀ¶Í¼Ð¹Â¶£¬£¬£¬£¬£¬£¬£¬ £¬±»ÀÕË÷5000ÍòÃÀÔª¡£¡£¡£¡£¡£QuantaÊÇÈ«ÇòµÚ¶þ´ó±Ê¼Ç±¾µçÄÔԭʼÉè¼ÆÔì×÷ÉÌ£¨ODM£©£¬£¬£¬£¬£¬£¬£¬ £¬¿Í»§Ô̺¬Apple¡¢Dell¡¢Hewlett-Packard¡¢Alienware¡¢Lenovo¡¢CiscoºÍMicrosoft¡£¡£¡£¡£¡£µ½Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬£¬£¬£¬ £¬REvilÔÚÆäÍøÕ¾ÉϹ«¿ªÁËÊ®¼¸¸öMacBook×é¼þµÄʾÒâͼ£¬£¬£¬£¬£¬£¬£¬ £¬²¢°µÊ¾ÆäÔÚÓ뼸¸öÓÐÐËÖ²ɰì»úÃÜͼֽµÄµÚÈý·½½øÐн»Éæ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬ £¬QuantaºÍApple¾ùδ¶Ô´ËÊÂÎñ½øÐлØÓ¦¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/revil-ransomware-gang-hits-apple-supplier-quanta/


3.QlockerÔÚ½üÆÚ´ó¹æÄ£ÀÕË÷¹¥»÷ÖÐʹÓÃ7zip¼ÓÃÜQNAPÉ豸


3.jpg


ÀÕË÷Èí¼þQlocker×Ô2021Äê4ÔÂ19ÈÕÆðÍ·Õë¶ÔQNAPÉ豸ÌáÒé´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ÔÚÕâÂÖ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬ £¬ºÚ¿ÍʹÓÃ7-zip½«QNAPÉ豸ÉϵÄÎļþÒÆÈëÓÐÃÜÂë±£»£»£»£»£»£»£»£»¤µÄµµ°¸¿â£¬£¬£¬£¬£¬£¬£¬ £¬´ËʱQNAPµÄ×ÊÔ´¼à¶½Ö»»áÏÔʾ´óÁ¿µÄ7z¹ý³Ì¡£¡£¡£¡£¡£Æ¾¾ÝQlockerµÄÊê½ð¼Í¼£¬£¬£¬£¬£¬£¬£¬ £¬ËùÓÐÊܺ¦Õß¾ù±»ÒªÇóÖ§¸¶0.01±ÈÌØ±Ò£¨Ô¼ºÏ557.74ÃÀÔª£©À´»ñÈ¡Æä½âÃÜÃÜÂë¡£¡£¡£¡£¡£QNAP×î½ü½¨¸´Á˶à¸öÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬£¬£¬ £¬²¢Ç¿ÁÒ½¨ÒéÓû§½«Æä²úÆ·Éý¼¶µ½×îа汾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/


4.ESET·¢ÏÖͨ¹ýαÔìSpotifyµÅצÓöÔ×¼ÄÏÃÀµØÓòµÄ¹¥»÷»î¶¯


4.jpg


°²È«¹«Ë¾ESET·¢ÏÖͨ¹ýαÔìMicrosoft Store¡¢SpotifyºÍÔÚÏßÎĵµ×ª»»ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ £¬¶Ô×¼ÄÏÃÀµØÓòµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÀûÓöñÒâ¸æ°×½«Óû§ÒýÈëαÔìµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ £¬ÔÚÓû§½Ó¼ûÍøÕ¾Ê±µÇÂ½Ò³Ãæ½«×Ô¶¯ÏÂÔØÔ̺¬Ficker¶ñÒâÈí¼þµÄzipÎļþ¡£¡£¡£¡£¡£FickerÊÇÒ»ÖÖÐÅÏ¢ÇÔȡľÂí£¬£¬£¬£¬£¬£¬£¬ £¬ÓÚ1ÔÂ·ÝÆðÍ·ÔÚ°µÍøÉϽøÐгö×⣬£¬£¬£¬£¬£¬£¬ £¬¿ÉÓÃÀ´ÔÚWebä¯ÀÀÆ÷¡¢×ÀÃæÐÂÎſͻ§¶Ë£¨Pidgin£¬£¬£¬£¬£¬£¬£¬ £¬Steam£¬£¬£¬£¬£¬£¬£¬ £¬Discord£©ºÍFTP¿Í»§¶ËÖÐÇÔȡʹ´¦£¬£¬£¬£¬£¬£¬£¬ £¬»òÕßÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°ü¡¢ÎĵµÒÔ¼°ÔڻµÄÀûÓýØÍ¼¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-microsoft-store-spotify-sites-spread-info-stealing-malware/


5.SonicWall°²È«¸üУ¬£¬£¬£¬£¬£¬£¬ £¬½¨¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day


5.jpg


SonicWall°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬ £¬½¨¸´ÆäÍйܺͱ¾µØµç×ÓÓʼþ°²È«£¨ES£©²úÆ·ÖеÄ3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶±ðÀëΪCVSSÆÀ·ÖΪ9.4µÄCVE-2021-20021£¬£¬£¬£¬£¬£¬£¬ £¬¿ÉÏòÔ¶³ÌÖ÷»ú·¢ËÍÌØÔìµÄHTTPÒªÇóÀ´´´½¨ÖÎÀíÕÊ»§¡¢ËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2021-20022£©ÒÔ¼°Ä¿Â¼±éÀú·ì϶£¨CVE-2021-20023£©¡£¡£¡£¡£¡£FireEye³Æ¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶װÖúóÃÅ·¨Ê½¡¢½Ó¼ûÎļþºÍµç×ÓÓʼþºÍºáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬£¬ £¬Õâ´Î¹¥»÷»î¶¯±»×·×ÙΪUNC2682¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/3-zero-day-exploits-hit-sonicwall.html


6.Google°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬£¬£¬ £¬½¨¸´½ñÄêµÚ4¸öÒѱ»ÀûÓõÄ0day


6.jpg


GoogleÓÚ4ÔÂ20ÈÕ°ä²¼´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬£¬ £¬½¨¸´Ô̺¬Ò»¸ö0dayÔÚÄڵĶà¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ0dayΪV8 ChromeäÖȾÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2021-21224£©£¬£¬£¬£¬£¬£¬£¬ £¬ÊǽñÄê·¢ÏֵĵÚËĸöChrome 0day¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ £¬Õâ´Î¸üл¹½¨¸´ÁËV8×é¼þÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2021-21222£©ºÍÔ½½çÄÚ´æ½Ó¼û·ì϶£¨CVE-2021-21225£©£¬£¬£¬£¬£¬£¬£¬ £¬MojoÖеÄÕûÊýÒç¶Âí½Å£¨CVE-2021-21223£©ºÍµ¼º½ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-21226£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-chrome-hit-another-mysterious-zero-day-attack