Êý°ÙÆóÒµÔâCodecov¹©Ó¦Á´¹¥»÷£¬£¬£¬¿°±ÈSolarWinds¹¥»÷£»£»£»£»QuantaѬȾREvil£¬£¬£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶±»ÀÕË÷5ÍòÍò
Ðû²¼Ê±¼ä 2021-04-221.Êý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬£¬£¬¿°±ÈSolarWinds¹¥»÷

·͸É籨µÀ³Æ£¬£¬£¬ÒÑÓÐÊý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬£¬£¬¿ÉÓë×î½üµÄSolarWinds¹¥»÷ÏàÌá²¢ÂÛ¡£¡£¡£¡£¡£¡£CodecovÓµÓÐ29000¶à¸ö¿Í»§£¬£¬£¬ÆäÖаüÀ¨GoDaddy¡¢AtlassianºÍProcter£¦Gamble£¨P£¦G£©µÈÖøÃû¹«Ë¾¡£¡£¡£¡£¡£¡£³õ³ÌÐò²éÏÔʾ£¬£¬£¬ºÚ¿Í´Ó1ÔÂ31ÈÕ×îÏȰ´ÆÚ¶ÔBash Uploader¾ç±¾¾ÙÐи͝£¬£¬£¬ÒÔÇÔÈ¡´æ´¢ÔÚ´æ´¢ÔÚCIÇéÐÎÖеÄÓû§ÐÅÏ¢£¬£¬£¬Ö±µ½4ÔÂ1Èղű»·¢Ã÷¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬IBMµÈCodecovµÄ¶à¸ö¿Í»§¶¼ÌåÏÖËûÃǵĴúÂëÉÐδ±»¸Ä¶¯£¬£¬£¬µ«¾Ü¾øÍ¸Â¶ÆäϵͳÊÇ·ñÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/
2.QuantaѬȾREvil£¬£¬£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶²¢±»ÀÕË÷5000Íò

Öйų́ÍåµÄQuantaѬȾREvil£¬£¬£¬Apple¹«Ë¾°üÀ¨¼´½«Ðû²¼µÄ²úÆ·ÔÚÄڵĴó×ÚÉè¼ÆÀ¶Í¼Ð¹Â¶£¬£¬£¬±»ÀÕË÷5000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£QuantaÊÇÈ«ÇòµÚ¶þ´óÌõ¼Ç±¾µçÄÔÔʼÉè¼ÆÖÆÔìÉÌ£¨ODM£©£¬£¬£¬¿Í»§°üÀ¨Apple¡¢Dell¡¢Hewlett-Packard¡¢Alienware¡¢Lenovo¡¢CiscoºÍMicrosoft¡£¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬REvilÔÚÆäÍøÕ¾ÉϹûÕæÁËÊ®¼¸¸öMacBook×é¼þµÄʾÒâͼ£¬£¬£¬²¢ÌåÏÖÆäÕýÔÚÓ뼸¸öÓÐÐËȤ¹ºÖÃÉñÃØÍ¼Ö½µÄµÚÈý·½¾ÙÐÐ̸ÅС£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬QuantaºÍApple¾ùδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/revil-ransomware-gang-hits-apple-supplier-quanta/
3.QlockerÔÚ½üÆÚ´ó¹æÄ£ÀÕË÷¹¥»÷ÖÐʹÓÃ7zip¼ÓÃÜQNAP×°±¸

ÀÕË÷Èí¼þQlocker×Ô2021Äê4ÔÂ19ÈÕ×îÏÈÕë¶ÔQNAP×°±¸Ìᳫ´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£ÔÚÕâÂÖ¹¥»÷ÖУ¬£¬£¬ºÚ¿ÍʹÓÃ7-zip½«QNAPÉè±¹ØÁ¬ÄÎļþÒÆÈëÓÐÃÜÂë±£»£»£»£»¤µÄµµ°¸¿â£¬£¬£¬´ËʱQNAPµÄ×ÊÔ´¼àÊÓÖ»»áÏÔʾ´ó×ÚµÄ7zÀú³Ì¡£¡£¡£¡£¡£¡£Æ¾Ö¤QlockerµÄÊê½ð¼Í¼£¬£¬£¬ËùÓÐÊܺ¦Õß¾ù±»ÒªÇóÖ§¸¶0.01±ÈÌØ±Ò£¨Ô¼ºÏ557.74ÃÀÔª£©À´»ñÈ¡Æä½âÃÜÃÜÂë¡£¡£¡£¡£¡£¡£QNAP×î½üÐÞ¸´Á˶à¸öÑÏÖØµÄÎó²î£¬£¬£¬²¢Ç¿ÁÒ½¨ÒéÓû§½«Æä²úÆ·Éý¼¶µ½×îа汾¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/
4.ESET·¢Ã÷ͨ¹ýαÔìSpotifyµÈÓ¦ÓÃÃé×¼ÄÏÃÀµØÇøµÄ¹¥»÷»î¶¯

Çå¾²¹«Ë¾ESET·¢Ã÷ͨ¹ýαÔìMicrosoft Store¡¢SpotifyºÍÔÚÏßÎĵµ×ª»»ÍøÕ¾£¬£¬£¬Ãé×¼ÄÏÃÀµØÇøµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷ʹÓöñÒâ¹ã¸æ½«Óû§ÒýÈëαÔìµÄÍøÕ¾£¬£¬£¬ÔÚÓû§»á¼ûÍøÕ¾Ê±Éϰ¶Ò³Ã潫×Ô¶¯ÏÂÔØ°üÀ¨Ficker¶ñÒâÈí¼þµÄzipÎļþ¡£¡£¡£¡£¡£¡£FickerÊÇÒ»ÖÖÐÅÏ¢ÇÔȡľÂí£¬£¬£¬ÓÚ1Ô·Ý×îÏÈÔÚ°µÍøÉϾÙÐгö×⣬£¬£¬¿ÉÓÃÀ´ÔÚWebä¯ÀÀÆ÷¡¢×ÀÃæÐÂÎſͻ§¶Ë£¨Pidgin£¬£¬£¬Steam£¬£¬£¬Discord£©ºÍFTP¿Í»§¶ËÖÐÇÔȡƾ֤£¬£¬£¬»òÕßÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°ü¡¢ÎĵµÒÔ¼°ÕýÔڻµÄÓ¦ÓýØÍ¼¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-microsoft-store-spotify-sites-spread-info-stealing-malware/
5.SonicWallÇå¾²¸üУ¬£¬£¬ÐÞ¸´3¸öÒѱ»ÔÚҰʹÓõÄ0day

SonicWallÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´ÆäÍйܺÍÍâµØµç×ÓÓʼþÇå¾²£¨ES£©²úÆ·ÖеÄ3¸öÒѱ»ÔÚҰʹÓõÄ0day¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î»®·ÖΪCVSSÆÀ·ÖΪ9.4µÄCVE-2021-20021£¬£¬£¬¿ÉÏòÔ¶³ÌÖ÷»ú·¢ËÍÌØÖÆµÄHTTPÇëÇóÀ´½¨ÉèÖÎÀíÕÊ»§¡¢í§ÒâÎļþÉÏ´«Îó²î£¨CVE-2021-20022£©ÒÔ¼°Ä¿Â¼±éÀúÎó²î£¨CVE-2021-20023£©¡£¡£¡£¡£¡£¡£FireEye³Æ¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×°ÖúóÃųÌÐò¡¢»á¼ûÎļþºÍµç×ÓÓʼþºÍºáÏòÒÆ¶¯£¬£¬£¬´Ë´Î¹¥»÷»î¶¯±»×·×ÙΪUNC2682¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/04/3-zero-day-exploits-hit-sonicwall.html
6.GoogleÐû²¼½ôÆÈ¸üУ¬£¬£¬ÐÞ¸´½ñÄêµÚ4¸öÒѱ»Ê¹ÓõÄ0day

GoogleÓÚ4ÔÂ20ÈÕÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬ÐÞ¸´°üÀ¨Ò»¸ö0dayÔÚÄڵĶà¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0dayΪV8 ChromeäÖȾÒýÇæÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-21224£©£¬£¬£¬ÊǽñÄê·¢Ã÷µÄµÚËĸöChrome 0day¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËV8×é¼þÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21222£©ºÍÔ½½çÄÚ´æ»á¼ûÎó²î£¨CVE-2021-21225£©£¬£¬£¬MojoÖеÄÕûÊýÒç³öÎó²î£¨CVE-2021-21223£©ºÍµ¼º½ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-21226£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/google-chrome-hit-another-mysterious-zero-day-attack


¾©¹«Íø°²±¸11010802024551ºÅ