PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬´úÂë¿âÒѱ»¸Ä¶¯£»ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳öºóÓû½«Êê½ðÍË»¹¸øÊܺ¦Õß

Ðû²¼Ê±¼ä 2021-03-30

1.PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬´úÂë¿âÒѱ»¸Ä¶¯


1.jpg


ÉÏÖÜÈÕ£¬Î¬»¤ÈËÔ±Rasmus Lerdorf·¢Ïֺڿ͹¥»÷ÁË·þÎñÆ÷git.php.net£¬²¢Ôڸ÷þÎñÆ÷µÄ×ÔÍйÜphp-src´æ´¢¿âÖÐÉÏ´«ÁË2¸öδ¾­ÊÚȨµÄ¸üаü£¬ÆäÖеÄÔ´´úÂë±»²åÈëÁËÃØÃܺóÃÅ´úÂë ¡£´ËÍ⣬ÕâЩ¶ñÒâ´úÂëÊÇÒÔPHP´´½¨ÕßRasmus LerdorfµÄÃûÒåÌá½»µÄ ¡£Ñо¿ÈËÔ±ÍÆ²â´Ë´ÎÊÇÃûΪÒÀÀµ»ìÏý£¨dependency confusion£©µÄÐÂÐ͹©Ó¦Á´¹¥»÷·½Ê½£¬ËüÀûÓÃÁËÒ»¸ö¿ÉÄܰüÂÞÀ´×Ô˽Óк͹«¹²À´Ô´µÄ»ìºÏÒÀÀµ¿âµÄÈí¼þ ¡£×÷ΪԤ·À´ëÊ©£¬PHPά»¤ÈËÔ±ÒѾö¶¨½«¹Ù·½PHPÔ´´úÂë´æ´¢¿âÇ¨ÒÆµ½GitHub ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/


2.°ÄÓéÀÖ¹«Ë¾NineÔâµ½¹¥»÷£¬µçÊÓÖ±²¥½ÚÄ¿ÔÝʱÖжÏ


2.jpg


°Ä´óÀûÑǵÄÓéÀÖ¹«Ë¾NineÓÚÉÏÖÜÈÕÔâµ½¹¥»÷£¬µ¼ÖÂÆäÉÏÎç7:00ÖÁÏÂÎç1:00´ÓϤÄá²¥³öµÄÐÂÎŽÚÄ¿ÔÝʱÖжÏ£¬¶øÏÂÎç5:00´ÓÄ«¶û±¾×ª²¥µÄÐÂÎŽÚĿҲûÓÐÕý³£²¥³ö ¡£¸Ã¹«Ë¾³ÆÆäÔâµ½ÁË´ó¹æÄ£µÄÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäÍøÂç̱»¾£¬µ«µç×ÓÓʼþϵͳ²¢Î´Êܵ½Ó°Ïì ¡£¾ÝϤ£¬Nine´Ë´ÎÔâµ½µÄ¹¥»÷ÊÇÒ»´ÎÅê»÷ÐÐΪ£¬ÒòΪºÚ¿Í²¢Î´Ìá³öÊê½ðÒªÇó£¬Õâ¶ÔÓÚÀÕË÷Èí¼þ¹¥»÷À´ËµÊǷdz£º±¼ûµÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116053/breaking-news/channel-nine-cyber-attack.html


3.ºÚ¿Í³öÊÛÓ¡¶ÈÖ§¸¶Æ½Ì¨MobiKwik 1ÒÚÓû§µÄ8TBÊý¾Ý


3.jpg


ºÚ¿ÍÔÚ°µÍø³öÊÛÓ¡¶ÈÖ§¸¶Æ½Ì¨MobiKwik 1ÒÚÓû§µÄ8TBÊý¾Ý ¡£MobiKwikÊÇÓ¡¶È×î´óµÄÖ§¸¶ÍøÂçÖ®Ò»£¬ÓµÓÐ1.2ÒÚÓû§¡¢300ÍòÉ̼ҺÍ300¶à¸öÕʵ¥£¬ÒѾ­ÎªÆäÊý×ÖÐÅÓÿ¨Ô¤ÏÈÅú×¼ÁË2000ÍòÓà ¡£Äþ¾²ÈËÔ±ÔÚ2ÔÂÊ×´ÎÓë¸Ã¹«Ë¾ÁªÏµÓйØÊý¾Ýй¶µÄÎÊÌ⣬²¢ÓÚ3ÔÂ4ÈÕÊÕµ½ÁËMobiKwik·ñÈϸÃʼþµÄÏûÏ¢ ¡£ºÚ¿Í´Ë´ÎÒÔ1.5 BTCµÄ¼Û¸ñ³öÊÛ°üÂÞÁË36099759¸öÎļþµÄ8.2 TBÊý¾Ý£¬°üÂÞÔ¼350ÍòÈ˵ÄKYCÏêϸÐÅÏ¢ºÍÒÔ¼°99224559¸öÓû§µÄµç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢¹þÏ£ÃÜÂë¡¢µØÖ·¡¢ÒøÐÐÕÊ»§ºÍÐÅÓÿ¨ÏêϸÐÅÏ¢µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/in-threat-actor-offers-to-sell-8-tb-of-mobikwiks-personal-and-financial-data-on-almost-100m-consumers/


4.CompuComÔ¤¼Æ±¾ÔµÄDarkSide¹¥»÷Ôì³É2000ÍòÃÀÔªËðʧ


4.jpg


ÃÀ¹úITÍйܷþÎñÌṩÉÌ£¨MSP£©CompuComÔ¤¼Æ£¬±¾ÔµÄDarkSideÀÕË÷Èí¼þ¹¥»÷¸øÆäÔì³ÉµÄËðʧ½«Áè¼Ý2000ÍòÃÀÔª ¡£¸Ã¹«Ë¾Îª»¨ÆìÒøÐС¢¼ÒµÃ±¦¡¢¸»¹úÒøÐС¢Target¡¢ÐÅÍÐÒøÐкÍLowe'sµÈÖªÃû¹«Ë¾ÌṩӲ¼þºÍÈí¼þάÐÞ¡¢Ô¶³ÌÖ§³ÖÒÔ¼°ÆäËû¼¼Êõ·þÎñ ¡£¸Ã¹«Ë¾Ô¤¼Æ£¬ÓÉÓÚ·þÎñÖжÏÔì³ÉµÄÊÕÈëËðʧÔÚ500Íòµ½800ÍòÃÀÔªÖ®¼ä ¡£´ËÍ⣬»Ö¸´ÊÜÓ°ÏìϵͳºÍ·þÎñËùÉæ¼°µÄÓöȽ«¸ß´ï2000ÍòÃÀÔª£¬ÆäÖÐÔ¼1000ÍòÃÀÔª½«ÔÚ2021ÄêµÚÒ»¼¾¶ÈÖ§¸¶ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/compucom-msp-expects-over-20m-in-losses-after-ransomware-attack/


5.IntelÒò¸ú×ÙÆä¹ÙÍøÉϵÄÓû§ÐÐΪ±»Ö¸¿ØÇÔÈ¡Òþ˽


5.jpg


IntelÒòÀûÓõÚÈý·½½Å±¾¸ú×ÙÆä¹ÙÍøÉϵÄÊó±êÒÆ¶¯ÒÔ¼°¼üÅÌÊäÈ룬±»Ö¸¿ØÇÔÈ¡Òþ˽ ¡£Ô­¸æHolly Londers³Æ£¬ÔÚÈ¥ÄêËýԼĪ·ÃÎÊÁËIntelÍøÕ¾12´Î£¬¶ø¸ÃÍøÕ¾ÀûÓøú×Ù¡¢¼Ç¼ºÍ»á»°ÖØ·ÅÈí¼þÀ¹½ØÁËÆäÊó±êµÄµã»÷ºÍÒÆ¶¯£¬ÒÔ¼°ÊäÈëµÄÐÅÏ¢¡¢·ÃÎʺͼì²ìµÄÒ³ÃæµÈÄÚÈÝ ¡£The MarkupÒ²¾¯¸æ³Æ£¬IntelÍøÕ¾´æÔÚÒ»¸öClicktale½Å±¾£¬Ëü¿ÉÒԼǼ»á»°À´¸ú×ÙÓû§µÄÍøÂç»î¶¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/03/30/intel_wiretapping_data/


6.ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳öºóÓû½«Êê½ðÍË»¹¸øÊܺ¦Õß


6.jpg


ÀÕË÷ÍÅ»ïZiggyÔÚ2Ô³õÐû²¼Í˳öºó£¬Óû½«Êê½ðÍË»¹¸øÊܺ¦Õß ¡£2ÔÂ7ÈÕ£¬ZiggyÍ£Ö¹ÁËÆä»î¶¯²¢¹ûÈ»Á˰üÂÞ922¸ö½âÃÜÃÜÔ¿µÄSQLÎļþ£¬3ÔÂ19ÈÕÌåÏÖÏ£Íû¿ÉÒÔ½«Êê½ðÍË»¹¸øÊܺ¦Õߣ¬²¢ÓÚÔÂ28ÈÕ³ÆÒѾ­×¼±¸ºÃÍË»¹Êê½ð ¡£Êܺ¦Õß¿Éͨ¹ýÓʼþµØÖ·ziggyransomware@secmail.proÓë¹ÜÀíÔ±ÁªÏµ£¬²¢ÌṩÓñÈÌØ±Ò¸¶¿îµÄÖ¤Ã÷ºÍ¼ÆËã»úID£¬Êê½ð½«ÔÚÁ½ÖÜÄÚÍË»¹µ½Êܺ¦ÕߵıÈÌØ±ÒÇ®°üÖÐ ¡£Ziggy³ÆÆäÉú»îÔÚÒ»¸öµÚÈýÊÀ½ç¹ú¼Ò£¬ÀÕË÷»î¶¯ÊdzöÓÚ¾­¼ÃÄ¿µÄ£¬²¢Í¸Â¶´Ë´ÎÐÐΪÊǵ£ÓÇÖ´·¨ÈËÔ±»á½ÓÄÉÐж¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-admin-is-refunding-victims-their-ransom-payments/