GitHubÆØÑϳÁRCE·ì϶ӰÏìÊý°ÙÍò´úÂë¿â
°ä²¼¹¦·ò 2026-04-301. GitHubÆØÑϳÁRCE·ì϶ӰÏìÊý°ÙÍò´úÂë¿â
4ÔÂ29ÈÕ£¬£¬£¬£¬£¬Ôư²È«¾ÞÍ·WizµÄ×êÑÐÈËÔ±ÔÚGitHubÉÏ·¢ÏÖÁËÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÄܶ³öÊý°ÙÍò¸ö´úÂë¿â¡£¡£¡£¡£¡£·ì϶±àºÅΪCVE-2026-3854£¬£¬£¬£¬£¬Ó°ÏìÁË´úÂëÍÐ¹ÜÆ½Ì¨ÄÚ²¿µÄGit»ù´¡¼Ü¹¹£¬£¬£¬£¬£¬GitHub Enterprise ServerºÍGitHub.com¾ùÊܵ½²¨¼°¡£¡£¡£¡£¡£WizÚ¹Êͳƣ¬£¬£¬£¬£¬Í¨¹ýÀûÓÃGitHubÄÚ²¿ºÍ̸ÖеÄ×¢Èë·ì϶£¬£¬£¬£¬£¬Èκξ¹ýÉí·ÝÑéÖ¤µÄÓû§¾ù¿ÉʹÓó߶Ègit¿Í»§¶Ë£¬£¬£¬£¬£¬Í¨¹ýÒ»¸ögit pushºÅÁîÔÚGitHubµÄºó¶Ë·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£Õâ¼Ò°²È«¹«Ë¾ÀûÓÃÈËΪÖÇÄÜ·¢ÏÖ¸ÃÎÊÌ⣬£¬£¬£¬£¬²¢°µÊ¾·ì϶ÀûÓü«¶ÈÈÝÒס£¡£¡£¡£¡£ÒÔGitHub Enterprise ServerΪÀý£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÆëÈ«½ÚÔì·þÎñÆ÷£¬£¬£¬£¬£¬»ñµÃ¶ÔËùÓд洢¿âºÍÄÚ²¿»úÃÜÐÅÏ¢µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¸Ã·ì϶¶ÔGitHub.comµÄÓ°Ïì¸üΪ¿í·º£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔÚ¹²Ïí´æ´¢½ÚµãÉÏÖ´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬£¬WizÈ·ÈÏÊý°ÙÍò¸öÊôÓÚÆäËûÓû§ºÍ×éÖ¯µÄ¹«¹²¼°Ë½ÓдúÂë¿âÔÚÊÜÓ°ÏìµÄ½ÚµãÉϾù¿É½Ó¼û¡£¡£¡£¡£¡£¹ÌÈ»Éí·ÝÑéÖ¤ÒªÇóËÆºõ½µµÍÁË·çÏÕ£¬£¬£¬£¬£¬µ«GitHubÚ¹Êͳƣ¬£¬£¬£¬£¬ÈκÎÕ¼ÓÐÏò´æ´¢¿âÍÆËÍȨÏÞµÄÓû§¾ù¿ÉÀûÓô˷ì϶ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£
https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/
2. CISA½«ConnectWiseÓëWindows Shell·ì϶ÄÉÈëKEVĿ¼
4ÔÂ29ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö½üÈÕ½«Á½¸öÒѱ»¿í·ºÀûÓõݲȫ·ì϶ÄÉÈëÆäÒÑÖª¿ÉÀûÓ÷ì϶Ŀ¼£¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ2026Äê5ÔÂ12ÈÕǰʵÏÖ½¨¸´¡£¡£¡£¡£¡£Ê׸ö·ì϶ÊÇConnectWise ScreenConnectÖеÄõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬±àºÅCVE-2024-1708£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.4·Ö¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏì23.9.7¼°¸üÔç°æ±¾µÄScreenConnect£¬£¬£¬£¬£¬Ô´ÓÚÎļþõè¾¶Ï޶Ȳ»µ±£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄܽӼûÔ¤ÆÚÁìÓòÖ®±íµÄÎļþºÍĿ¼¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý´Û¸ÄÎļþõè¾¶£¬£¬£¬£¬£¬¿É½Ó¼ûϵͳµÄÃô¸ÐÇøÓò£¬£¬£¬£¬£¬ÔÚijЩÇé¾°Ï¿ɵ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлòδ¾ÊÚȨ½Ó¼û»úÃÜÊý¾ÝºÍ¹Ø¼ü×ÊÔ´¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬¸Ã·ì϶³£ÓëÁíÒ»ÑϳÁÈÏÖ¤ÈÆ¹ý·ì϶CVE-2024-1709£¨CVSSÆÀ·Ö10.0£©¹²Í¬Ê¹Óᣡ£¡£¡£¡£µÚ¶þ¸ö·ì϶ÊÇWindows ShellºýŪ·ì϶£¬£¬£¬£¬£¬±àºÅCVE-2026-32202£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ4.3·Ö¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ´ËǰÕë¶ÔCVE-2026-21510µÄ²»ÆëÈ«²¹¶¡¡£¡£¡£¡£¡£CVE-2026-21510ÔÊǶíÂÞ˹APT28ºÚ¿Í×éÖ¯×Ô2025Äê12ÔÂÆðÓÃÀ´¹¥»÷ÎÚ¿ËÀ¼ºÍÅ·Ã˹ú¶ÈµÄÁãÈÕ·ì϶£¬£¬£¬£¬£¬ÓëMSHTML·ì϶CVE-2026-21513×é³ÉÀûÓÃÁ´¡£¡£¡£¡£¡£Î¢ÈíÓÚ4ÔÂ27ÈÕ¸üв¼¸æÈ·Èϸ÷ì϶Òѱ»»ý¼«ÀûÓ㬣¬£¬£¬£¬½¨¸´ÁËÔçǰ°ä²¼µÄÃýÎóÀûÓÃÐÔÖ¸±ê¡£¡£¡£¡£¡£
https://securityaffairs.com/191442/security/u-s-cisa-adds-microsoft-windows-shell-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html
3. SAP¶à¸ö¹Ù·½npm°üÔ⹩¸øÁ´¹¥»÷
4ÔÂ29ÈÕ£¬£¬£¬£¬£¬TeamPCPÌáÒéÁËһ·¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬µ¼Ö¶à¸ö¹Ù·½SAP npm°üÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬Ö÷ÕÅÊÇÇÔÈ¡¿ª·¢ÈËԱϵͳÖеÄÍ´´¦ºÍÉí·ÝÑéÖ¤ÁîÅÆ¡£¡£¡£¡£¡£°²È«×êÑÐÈËÔ±»ã±¨³Æ£¬£¬£¬£¬£¬Õâ´Î·ì϶ӰÏìÁËËĸöÈí¼þ°ü£¬£¬£¬£¬£¬Æä¶ñÒâ°æ±¾Ä¿Ç°ÒÑÔÚnpmÉϱ»ÆúÓãº@cap-js/sqlite v2.2.2¡¢@cap-js/postgres v2.2.2¡¢@cap-js/db-service v2.10.1ºÍmbt v1.2.48¡£¡£¡£¡£¡£ÕâЩÈí¼þ°üÖ§³ÖSAPµÄÔÆÀûÓ÷¨Ê½±à³ÌÄ£ÐͺÍÔÆMTA£¬£¬£¬£¬£¬Í¨³£ÓÃÓÚÆóÒµ¿ª·¢»·¾³¡£¡£¡£¡£¡£Æ¾¾ÝAikidoºÍSocketµÄ×îл㱨£¬£¬£¬£¬£¬±»ÈëÇÖµÄÈí¼þ°üÒѱ»Åú¸Ä£¬£¬£¬£¬£¬Ô̺¬Ò»¸ö¶ñÒâµÄ¡°Ô¤×°Ö᱾籾£¬£¬£¬£¬£¬¸Ã¾ç±¾ÔÚ×°ÖÃnpm°üʱ»á×Ô¶¯Ö´ÐÓ×£¡£¡£¡£¡£¸Ã¾ç±¾Æô¶¯Ò»¸öÃûΪsetup.mjsµÄ¼ÓÔØÆ÷£¬£¬£¬£¬£¬´ÓGitHubÏÂÔØBun JavaScriptÔËÐÐʱ£¬£¬£¬£¬£¬²¢Ê¹ÓÃËüÀ´Ö´Ðо¹ý¸ß¶È»ìºÏµÄexecution.jsÔØºÉ¡£¡£¡£¡£¡£¸ÃÔØºÉÊÇÒ»ÖÖÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬ÓÃÓÚ´Ó¿ª·¢ÈËÔ±»úеºÍCI/CD»·¾³ÖÐÇÔÈ¡¸÷ÀàÍ´´¦£¬£¬£¬£¬£¬Ô̺¬npmºÍGitHubÉí·ÝÑéÖ¤ÁîÅÆ¡¢SSHÃÜÔ¿¡¢¿ª·¢ÈËԱʹ´¦¡¢AWS/Azure/Google CloudµÄÔÆÆ¾Ö¤¡¢KubernetesÅäÖúÍÃÜÔ¿£¬£¬£¬£¬£¬ÒÔ¼°CI/CDÁ÷Ë®ÏßÃÜÔ¿ºÍ»·¾³±äÁ¿¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/official-sap-npm-packages-compromised-to-steal-credentials/
4. Quick Page/Post Redirect²å¼þ²ØÎåÄêºóÃÅ
4ÔÂ29ÈÕ£¬£¬£¬£¬£¬ÎåÄêǰ£¬£¬£¬£¬£¬×°ÖÃÔÚ³¬¹ý70,000¸öWordPressÍøÕ¾ÉϵÄQuick Page/Post Redirect²å¼þ±»Ôö³¤ÁËÒ»¸öºóÃÅ£¬£¬£¬£¬£¬ÔÊÐíÏòÓû§ÍøÕ¾×¢ÈëËÁÒâ´úÂë¡£¡£¡£¡£¡£WordPressÖ÷»úÌṩÉÌAnchorµÄÊ×´´ÈËAustin Ginder·¢ÏÖÁ˸öñÒâÈí¼þ£¬£¬£¬£¬£¬´ËǰËûÍйܵķþÎñÆ÷ÉÏÓÐ12¸öÍøÕ¾Êܵ½Ï°È¾£¬£¬£¬£¬£¬´¥·¢Á˰²È«¾¯±¨¡£¡£¡£¡£¡£Quick Page/Post RedirectÊÇÒ»¿îÓÃÓÚÔÚÎÄÕ¡¢Ò³ÃæºÍ×Ô½ç˵URLÖд´½¨³Á¶¨ÏòµÄ¸ù»ùʵÓòå¼þ£¬£¬£¬£¬£¬ÒÑÔÚWordPress.orgÉÏÌṩ¶àÄê¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬WordPress.orgÒÑÁÙʱ½«¸Ã²å¼þ´ÓĿ¼ÖÐÒÆ³ý£¬£¬£¬£¬£¬ÆÚ´ýÉó²é¡£¡£¡£¡£¡£Éв»Ã÷ÏÔÊDzå¼þ×÷Õß×ÔÐÐÖ²ÈëÁ˺óÃÅ£¬£¬£¬£¬£¬»¹ÊÇÆäÕË»§±»µÚÈý·½ÈëÇÖ¡£¡£¡£¡£¡£GinderÚ¹ÊÍ˵£¬£¬£¬£¬£¬2020ÄêÖÁ2021Äê¼ä°ä²¼µÄ¹Ù·½²å¼þ°æ±¾5.2.1ºÍ5.2.2Ô̺¬Ò»¸öÖ¸ÏòµÚÈý·½ÓòÃûanadnet[.]comµÄ°µ²Ø×ÔÎÒ¸üлúÔ죬£¬£¬£¬£¬¸Ã»úÔìÔÊÐí½«ËÁÒâ´úÂëÍÆË͵½WordPress.org½ÚÔìÁìÓòÖ®±í¡£¡£¡£¡£¡£2021Äê2Ô£¬£¬£¬£¬£¬¶ñÒâ×Ô¸üз¨Ê½´ÓWordPress.org²å¼þµÄºóÐø°æ±¾Öб»ÒƳý£¬£¬£¬£¬£¬´úÂëÉó²éÔ±»¹Ã»À´µÃ¼°×ÐϸÉó²éËü¡£¡£¡£¡£¡£¾ÝGinder³Æ£¬£¬£¬£¬£¬2021Äê3Ô£¬£¬£¬£¬£¬ÔËÐÐQuick Page/Post Redirect 5.2.1ºÍ5.2.2µÄÍøÕ¾ÍµÍµµØ´Ó¸Ã±í²¿·þÎñÆ÷½Ó¹Üµ½ÁËÒ»¸ö´Û»Ú¸ÄµÄ5.2.3°æ±¾£¬£¬£¬£¬£¬¸Ã°æ±¾ÒýÈëÁËÒ»¸ö±»¶¯ºóÃÅ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/popular-wordpress-redirect-plugin-hid-dormant-backdoor-for-years/
5. ÇàÁúÃæ°åÆØÈÏÖ¤ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬¹¥»÷Õ߿ɲ¿Êð¼ÓÃÜ¿ó¹¤
4ÔÂ29ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÀûÓÿªÔ´¹¤×÷µ÷¶È¹¤¾ßÇàÁúÃæ°åÖеÄÁ½¸öÈÏÖ¤ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬ÔÚ¿ª·¢Õß·þÎñÆ÷Éϲ¿Êð¼ÓÃܿ󹤡£¡£¡£¡£¡£Á½¸ö°²È«ÎÊÌâÓ°ÏìÇàÁúÃæ°å2.20.1¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬ÇÒÄܹ»´®ÁªÀûÓÃÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£CVE-2026-3965£ºÅäÖò»µ±µÄ³Áд¹æ¶¨½«/open/*ÒªÇóÓ³Éäµ½/api/*£¬£¬£¬£¬£¬ÎÞÒâÖÐͨ¹ýδ¾Éí·ÝÑéÖ¤µÄõ辶¶³öÁËÊܱ£»£»£»£»£»£»£»¤µÄÖÎÀíÔ±¶Ëµã¡£¡£¡£¡£¡£CVE-2026-4047£ºÈÏÖ¤²é³ÒÔ·Ö±æ´óÓ×д·½Ê½´¦ÖÃõè¾¶£¨/api/£©£¬£¬£¬£¬£¬¶øÂ·ÓÉÆ¥ÅäÔò²»·Ö´óÓ×д£¬£¬£¬£¬£¬ÕâÔÊÐí/aPi/...µÈÒªÇóÈÆ¹ýÈÏÖ¤²¢½Ó¼ûÊܱ£»£»£»£»£»£»£»¤µÄ¶Ëµã¡£¡£¡£¡£¡£Snyk»ã±¨³Æ£¬£¬£¬£¬£¬×Ô2ÔÂ7ÈÕÆð£¬£¬£¬£¬£¬¹¥»÷ÕßÒ»ÏòÔÚÕë¶Ô¹«¿ªÂ¶³öµÄÇàÁúÃæ°åÀûÓÃÕâÁ½¸ö·ì϶ÒÔ²¿Êð¼ÓÃܿ󹤡£¡£¡£¡£¡£¸Ã»î¶¯×î³õÓÉÇàÁúÓû§·¢ÏÖ£¬£¬£¬£¬£¬ËûÃǻ㱨³Æ´æÔÚÒ»¸öÃûΪ.fullgcµÄ¶ñÒâ°µ²Ø¹ý³Ì£¬£¬£¬£¬£¬Õ¼ÓÃÁË85%ÖÁ100%µÄCPU×ÊÔ´¡£¡£¡£¡£¡£¹¥»÷³ÖÐø½øÐУ¬£¬£¬£¬£¬ÔÚÔ̺¬NginxºÍSSL·´Ïò´úÀíºóµÄ¶àÖÖÅäÖû·¾³Öж¼È·ÈÏÁËϰȾ°¸Àý¡£¡£¡£¡£¡£¶øÇàÁúÊØ»¤ÕßÖ±µ½3ÔÂ1ÈղŶԴËÇé¿ö×÷³ö»ØÓ¦¡£¡£¡£¡£¡£½¨ÒéÈÔÔÚʹÓÃÒ×Êܹ¥»÷°æ±¾µÄÓû§Á¢¼´Éý¼¶µ½Òѽ¨¸´°æ±¾£¬£¬£¬£¬£¬²¢²é³·þÎñÆ÷ÖÐÊÇ·ñ´æÔÚ¿ÉÒɵÄ.fullgc¹ý³Ì¼°·ÇÊÚȨÅäÖõ÷»»¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/
6. ¿ç¹ú¼ÓÃÜÇ®±ÒÚ¿ÆÍŻ︲Ã𣬣¬£¬£¬£¬È«ÇòËðʧ³¬5000ÍòÅ·Ôª
4ÔÂ29ÈÕ£¬£¬£¬£¬£¬°ÂµØÀûºÍ°¢¶û°ÍÄáÑǵ±¾Ö½üÈÕµ·»ÙÁËÒ»¸ö±»Ö¸¿ØÔËÓª´ó¹æÄ£¼ÓÃÜÇ®±ÒͶ×ÊڿƵķ¸×ïÍŻ£¬£¬£¬£¬¸ÃÍÅ»ï¸øÈ«ÇòÊܺ¦ÕßÔì³ÉµÄ¾¼ÃËðʧ¹À¼Æ³¬¹ý5000ÍòÅ·Ôª£¨Ô¼ºÏ5850ÍòÃÀÔª£©¡£¡£¡£¡£¡£Õâ´Î½áºÏÐж¯Ê¼ÓÚ2023Äê6Ô£¬£¬£¬£¬£¬²¢µÃµ½ÁËÅ·ÖÞÐ̾¯×éÖ¯ºÍÅ·ÖÞ˾·¨×éÖ¯µÄÖ§³Ö£¬£¬£¬£¬£¬×îÖÕÓÚ4ÔÂ17ÈÕ¿ÛÁôÁË10ÃûÏÓÒÉÈË£¬£¬£¬£¬£¬²¢¶ÔÈý¸öºô½ÐÖÐÐĺ;Ŵ¦¸öÈËסËù½øÐÐÁËËѲ顣¡£¡£¡£¡£Ðж¯ÖУ¬£¬£¬£¬£¬·¨ÂÉÈËÔ±½É»ñÁË891,735Å·ÔªÏÖ½ð¡¢443̨µçÄÔ¡¢238²¿ÊÖ»ú¡¢6̨±Ê¼Ç±¾µçÄÔÒÔ¼°¶àÖÖÊý¾Ý´æ´¢É豸ÒÔ¹©È¡Ö¤²é³¡£¡£¡£¡£¡£¸ÃÚ¿ÆÍÅ»ïѡȡÀàËÆºÏ·¨ÆóÒµµÄģʽÔËÓª£¬£¬£¬£¬£¬¹ÍÓ¶¶à´ï450ÃûÔ±¹¤£¬£¬£¬£¬£¬·ÖÊô¿Í»§»ñÈ¡¡¢¿Í»§Î¬Ïµ¡¢²ÆÕþ¡¢ITºÍÈËÁ¦×ÊÔ´µÈ²¿ÃÅ¡£¡£¡£¡£¡£Êܺ¦Õßͨ¹ýËÑË÷ÒýÇæºÍÉ罻ýÌåÉϵĸæ°×±»ÓÕÆÖÁÐéαµÄ¼ÓÃÜÇ®±ÒͶ×ÊÆ½Ì¨£¬£¬£¬£¬£¬Ëæºó±»·ÖÅ䏸ËùνµÄ¡°¿Í»§Î¬Ïµ×¨Ô±¡±£¬£¬£¬£¬£¬ÕâЩרԱÖÎÀíÊܺ¦ÕßµÄͶ×ÊÕË»§£¬£¬£¬£¬£¬³£Ê¹ÓÃÔ¶³Ì½Ó¼ûÈí¼þ½ÚÔìÊܺ¦ÕßÉ豸£¬£¬£¬£¬£¬²¢Í¨¹ýÉúÀíʩѹÓÕÆÊܺ¦Õß×·¼Ó´æ¿î¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Êܺ¦ÕßµÄ×ʽð´ÓÎ´ÕæÕý±»Í¶×Ê£¬£¬£¬£¬£¬¶øÊDZ»×ªÈëÒ»¸ö¹ú¼ÊÏ´Ç®´òË㣬£¬£¬£¬£¬×îÖÕÁ÷Èë·¸×ïÍøÂçµÄÕË»§¡£¡£¡£¡£¡£ÔÚ¶þ´ÎÚ¿ÆÖУ¬£¬£¬£¬£¬·¸×ï·Ö×ÓÔÙ´ÎÁªÏµÊܺ¦Õߣ¬£¬£¬£¬£¬Ðû³Æ¿ÉÔ®ÊÖ×·»ØËðʧ£¬£¬£¬£¬£¬µ«ÒªÇóÏÈÏò¼ÓÃÜÇ®±ÒÕË»§´æÈë500Å·Ôª×÷ΪÈ볡·Ñ£¬£¬£¬£¬£¬´Ó¶ø¶ÔÊܺ¦ÕßÖ´Ðжþ´Îڲơ£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/


¾©¹«Íø°²±¸11010802024551ºÅ