Êý°ÙÆóÒµÔâCodecov¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬¿°±ÈSolarWinds¹¥»÷£»£»£»QuantaѬȾREvil£¬£¬£¬£¬£¬£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶±»ÀÕË÷5ÍòÍò

Ðû²¼Ê±¼ä 2021-04-22

1.Êý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬¿°±ÈSolarWinds¹¥»÷


1.jpg


·͸É籨µÀ³Æ£¬£¬£¬£¬£¬£¬ÒÑÓÐÊý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬¿ÉÓë×î½üµÄSolarWinds¹¥»÷ÏàÌá²¢ÂÛ¡£¡£¡£¡£¡£¡£ ¡£CodecovÓµÓÐ29000¶à¸ö¿Í»§£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨GoDaddy¡¢AtlassianºÍProcter£¦Gamble£¨P£¦G£©µÈÖøÃû¹«Ë¾¡£¡£¡£¡£¡£¡£ ¡£³õ³ÌÐò²éÏÔʾ£¬£¬£¬£¬£¬£¬ºÚ¿Í´Ó1ÔÂ31ÈÕ×îÏȰ´ÆÚ¶ÔBash Uploader¾ç±¾¾ÙÐи͝£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡´æ´¢ÔÚ´æ´¢ÔÚCIÇéÐÎÖеÄÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬Ö±µ½4ÔÂ1Èղű»·¢Ã÷¡£¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬IBMµÈCodecovµÄ¶à¸ö¿Í»§¶¼ÌåÏÖËûÃǵĴúÂëÉÐδ±»¸Ä¶¯£¬£¬£¬£¬£¬£¬µ«¾Ü¾øÍ¸Â¶ÆäϵͳÊÇ·ñÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/


2.QuantaѬȾREvil£¬£¬£¬£¬£¬£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶²¢±»ÀÕË÷5000Íò


2.jpg


Öйų́ÍåµÄQuantaѬȾREvil£¬£¬£¬£¬£¬£¬Apple¹«Ë¾°üÀ¨¼´½«Ðû²¼µÄ²úÆ·ÔÚÄڵĴó×ÚÉè¼ÆÀ¶Í¼Ð¹Â¶£¬£¬£¬£¬£¬£¬±»ÀÕË÷5000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£ ¡£QuantaÊÇÈ«ÇòµÚ¶þ´óÌõ¼Ç±¾µçÄÔԭʼÉè¼ÆÖÆÔìÉÌ£¨ODM£©£¬£¬£¬£¬£¬£¬¿Í»§°üÀ¨Apple¡¢Dell¡¢Hewlett-Packard¡¢Alienware¡¢Lenovo¡¢CiscoºÍMicrosoft¡£¡£¡£¡£¡£¡£ ¡£µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬REvilÔÚÆäÍøÕ¾ÉϹûÕæÁËÊ®¼¸¸öMacBook×é¼þµÄʾÒâͼ£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÆäÕýÔÚÓ뼸¸öÓÐÐËȤ¹ºÖÃÉñÃØÍ¼Ö½µÄµÚÈý·½¾ÙÐÐ̸ÅС£¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬QuantaºÍApple¾ùδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/revil-ransomware-gang-hits-apple-supplier-quanta/


3.QlockerÔÚ½üÆÚ´ó¹æÄ£ÀÕË÷¹¥»÷ÖÐʹÓÃ7zip¼ÓÃÜQNAP×°±¸


3.jpg


ÀÕË÷Èí¼þQlocker×Ô2021Äê4ÔÂ19ÈÕ×îÏÈÕë¶ÔQNAP×°±¸Ìᳫ´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£ ¡£ÔÚÕâÂÖ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃ7-zip½«QNAPÉè±¹ØÁ¬ÄÎļþÒÆÈëÓÐÃÜÂë±£»£»£»¤µÄµµ°¸¿â£¬£¬£¬£¬£¬£¬´ËʱQNAPµÄ×ÊÔ´¼àÊÓÖ»»áÏÔʾ´ó×ÚµÄ7zÀú³Ì¡£¡£¡£¡£¡£¡£ ¡£Æ¾Ö¤QlockerµÄÊê½ð¼Í¼£¬£¬£¬£¬£¬£¬ËùÓÐÊܺ¦Õß¾ù±»ÒªÇóÖ§¸¶0.01±ÈÌØ±Ò£¨Ô¼ºÏ557.74ÃÀÔª£©À´»ñÈ¡Æä½âÃÜÃÜÂë¡£¡£¡£¡£¡£¡£ ¡£QNAP×î½üÐÞ¸´Á˶à¸öÑÏÖØµÄÎó²î£¬£¬£¬£¬£¬£¬²¢Ç¿ÁÒ½¨ÒéÓû§½«Æä²úÆ·Éý¼¶µ½×îа汾¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/


4.ESET·¢Ã÷ͨ¹ýαÔìSpotifyµÈÓ¦ÓÃÃé×¼ÄÏÃÀµØÇøµÄ¹¥»÷»î¶¯


4.jpg


Çå¾²¹«Ë¾ESET·¢Ã÷ͨ¹ýαÔìMicrosoft Store¡¢SpotifyºÍÔÚÏßÎĵµ×ª»»ÍøÕ¾£¬£¬£¬£¬£¬£¬Ãé×¼ÄÏÃÀµØÇøµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£ ¡£¹¥»÷ʹÓöñÒâ¹ã¸æ½«Óû§ÒýÈëαÔìµÄÍøÕ¾£¬£¬£¬£¬£¬£¬ÔÚÓû§»á¼ûÍøÕ¾Ê±Éϰ¶Ò³Ã潫×Ô¶¯ÏÂÔØ°üÀ¨Ficker¶ñÒâÈí¼þµÄzipÎļþ¡£¡£¡£¡£¡£¡£ ¡£FickerÊÇÒ»ÖÖÐÅÏ¢ÇÔȡľÂí£¬£¬£¬£¬£¬£¬ÓÚ1Ô·Ý×îÏÈÔÚ°µÍøÉϾÙÐгö×⣬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚWebä¯ÀÀÆ÷¡¢×ÀÃæÐÂÎſͻ§¶Ë£¨Pidgin£¬£¬£¬£¬£¬£¬Steam£¬£¬£¬£¬£¬£¬Discord£©ºÍFTP¿Í»§¶ËÖÐÇÔȡƾ֤£¬£¬£¬£¬£¬£¬»òÕßÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°ü¡¢ÎĵµÒÔ¼°ÕýÔڻµÄÓ¦ÓýØÍ¼¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-microsoft-store-spotify-sites-spread-info-stealing-malware/


5.SonicWallÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´3¸öÒѱ»ÔÚҰʹÓõÄ0day


5.jpg


SonicWallÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäÍйܺÍÍâµØµç×ÓÓʼþÇå¾²£¨ES£©²úÆ·ÖеÄ3¸öÒѱ»ÔÚҰʹÓõÄ0day¡£¡£¡£¡£¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄÎó²î»®·ÖΪCVSSÆÀ·ÖΪ9.4µÄCVE-2021-20021£¬£¬£¬£¬£¬£¬¿ÉÏòÔ¶³ÌÖ÷»ú·¢ËÍÌØÖÆµÄHTTPÇëÇóÀ´½¨ÉèÖÎÀíÕÊ»§¡¢í§ÒâÎļþÉÏ´«Îó²î£¨CVE-2021-20022£©ÒÔ¼°Ä¿Â¼±éÀúÎó²î£¨CVE-2021-20023£©¡£¡£¡£¡£¡£¡£ ¡£FireEye³Æ¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×°ÖúóÃųÌÐò¡¢»á¼ûÎļþºÍµç×ÓÓʼþºÍºáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯±»×·×ÙΪUNC2682¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/3-zero-day-exploits-hit-sonicwall.html


6.GoogleÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´½ñÄêµÚ4¸öÒѱ»Ê¹ÓõÄ0day


6.jpg


GoogleÓÚ4ÔÂ20ÈÕÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´°üÀ¨Ò»¸ö0dayÔÚÄڵĶà¸öÎó²î¡£¡£¡£¡£¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄ0dayΪV8 ChromeäÖȾÒýÇæÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-21224£©£¬£¬£¬£¬£¬£¬ÊǽñÄê·¢Ã÷µÄµÚËĸöChrome 0day¡£¡£¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËV8×é¼þÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21222£©ºÍÔ½½çÄÚ´æ»á¼ûÎó²î£¨CVE-2021-21225£©£¬£¬£¬£¬£¬£¬MojoÖеÄÕûÊýÒç³öÎó²î£¨CVE-2021-21223£©ºÍµ¼º½ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-21226£©¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-chrome-hit-another-mysterious-zero-day-attack