Êý°ÙÆóÒµÔâCodecov¹©Ó¦Á´¹¥»÷£¬¿°±ÈSolarWinds¹¥»÷ £»QuantaѬȾREvil£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶±»ÀÕË÷5ǧÍò

Ðû²¼Ê±¼ä 2021-04-22

1.Êý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬¿°±ÈSolarWinds¹¥»÷


1.jpg


·͸É籨µÀ³Æ£¬ÒÑÓÐÊý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬¿ÉÓë×î½üµÄSolarWinds¹¥»÷ÏàÌá²¢ÂÛ¡£CodecovÓµÓÐ29000¶à¸ö¿Í»§£¬ÆäÖаüÂÞGoDaddy¡¢AtlassianºÍProcter£¦Gamble£¨P£¦G£©µÈÖøÃû¹«Ë¾¡£³õ·¨Ê½²éÏÔʾ£¬ºÚ¿Í´Ó1ÔÂ31ÈÕ¿ªÊ¼¶¨ÆÚ¶ÔBash Uploader½Å±¾½øÐи͝£¬ÒÔÇÔÈ¡´æ´¢ÔÚ´æ´¢ÔÚCI»·¾³ÖеÄÓû§ÐÅÏ¢£¬Ö±µ½4ÔÂ1Èղű»·¢ÏÖ¡£Ä¿Ç°£¬IBMµÈCodecovµÄ¶à¸ö¿Í»§¶¼ÌåÏÖËûÃǵĴúÂëÉÐδ±»¸Ä¶¯£¬µ«¾Ü¾øÍ¸Â¶ÆäϵͳÊÇ·ñÔâµ½¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/


2.QuantaѬȾREvil£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶²¢±»ÀÕË÷5000Íò


2.jpg


Öйų́ÍåµÄQuantaѬȾREvil£¬Apple¹«Ë¾°üÂÞ¼´½«Ðû²¼µÄ²úÎïÔÚÄڵĴóÁ¿Éè¼ÆÀ¶Í¼Ð¹Â¶£¬±»ÀÕË÷5000ÍòÃÀÔª¡£QuantaÊÇÈ«ÇòµÚ¶þ´óÌõ¼Ç±¾µçÄÔԭʼÉè¼ÆÖÆÔìÉÌ£¨ODM£©£¬¿Í»§°üÂÞApple¡¢Dell¡¢Hewlett-Packard¡¢Alienware¡¢Lenovo¡¢CiscoºÍMicrosoft¡£µ½Ä¿Ç°ÎªÖ¹£¬REvilÔÚÆäÍøÕ¾ÉϹûÈ»ÁËÊ®¼¸¸öMacBook×é¼þµÄʾÒâͼ£¬²¢ÌåÏÖÆäÕýÔÚÓ뼸¸öÓÐÐËȤ¹ºÖûúÃÜͼֽµÄµÚÈý·½½øÐÐ̸ÅС£Ä¿Ç°£¬QuantaºÍApple¾ùδ¶Ô´Ëʼþ½øÐлØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/revil-ransomware-gang-hits-apple-supplier-quanta/


3.QlockerÔÚ½üÆÚ´ó¹æÄ£ÀÕË÷¹¥»÷ÖÐʹÓÃ7zip¼ÓÃÜQNAPÉ豸


3.jpg


ÀÕË÷Èí¼þQlocker×Ô2021Äê4ÔÂ19ÈÕ¿ªÊ¼Õë¶ÔQNAPÉ豸Ìᳫ´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£ÔÚÕâÂÖ¹¥»÷ÖУ¬ºÚ¿ÍʹÓÃ7-zip½«QNAPÉè±¹ØÁ¬ÄÎļþÒÆÈëÓÐÃÜÂë± £»¤µÄµµ°¸¿â£¬´ËʱQNAPµÄ×ÊÔ´¼àÊÓÖ»»áÏÔʾ´óÁ¿µÄ7z½ø³Ì¡£Æ¾¾ÝQlockerµÄÊê½ð¼Ç¼£¬ËùÓÐÊܺ¦Õß¾ù±»ÒªÇóÖ§¸¶0.01±ÈÌØ±Ò£¨Ô¼ºÏ557.74ÃÀÔª£©À´»ñÈ¡Æä½âÃÜÃÜÂë¡£QNAP×î½üÐÞ¸´Á˶à¸öÑÏÖØµÄ©¶´£¬²¢Ç¿ÁÒ½¨ÒéÓû§½«Æä²úÎïÉý¼¶µ½×îа汾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/


4.ESET·¢ÏÖͨ¹ýαÔìSpotifyµÈÓ¦ÓÃÃé×¼ÄÏÃÀµØÓòµÄ¹¥»÷»î¶¯


4.jpg


Äþ¾²¹«Ë¾ESET·¢ÏÖͨ¹ýαÔìMicrosoft Store¡¢SpotifyºÍÔÚÏßÎĵµ×ª»»ÍøÕ¾£¬Ãé×¼ÄÏÃÀµØÓòµÄ¹¥»÷»î¶¯¡£¹¥»÷ÀûÓöñÒâ¹ã¸æ½«Óû§ÒýÈëαÔìµÄÍøÕ¾£¬ÔÚÓû§·ÃÎÊÍøÕ¾Ê±µÇÂ½Ò³Ãæ½«×Ô¶¯ÏÂÔØ°üÂÞFicker¶ñÒâÈí¼þµÄzipÎļþ¡£FickerÊÇÒ»ÖÖÐÅÏ¢ÇÔȡľÂí£¬ÓÚ1Ô·ݿªÊ¼ÔÚ°µÍøÉϽøÐгö×⣬¿ÉÓÃÀ´ÔÚWebä¯ÀÀÆ÷¡¢×ÀÃæÏûÏ¢¿Í»§¶Ë£¨Pidgin£¬Steam£¬Discord£©ºÍFTP¿Í»§¶ËÖÐÇÔȡƾ¾Ý£¬»òÕßÇÔÈ¡¼ÓÃÜ»õ±ÒÇ®°ü¡¢ÎĵµÒÔ¼°ÕýÔڻµÄÓ¦ÓýØÍ¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-microsoft-store-spotify-sites-spread-info-stealing-malware/


5.SonicWallÄþ¾²¸üУ¬ÐÞ¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day


5.jpg


SonicWallÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÆäÍйܺ͵±µØµç×ÓÓʼþÄþ¾²£¨ES£©²úÎïÖеÄ3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day¡£´Ë´ÎÐÞ¸´µÄ©¶´·Ö±ðΪCVSSÆÀ·ÖΪ9.4µÄCVE-2021-20021£¬¿ÉÏòÔ¶³ÌÖ÷»ú·¢ËÍÌØÖÆµÄHTTPÇëÇóÀ´´´½¨¹ÜÀíÕÊ»§¡¢ÈÎÒâÎļþÉÏ´«Â©¶´£¨CVE-2021-20022£©ÒÔ¼°Ä¿Â¼±éÀú©¶´£¨CVE-2021-20023£©¡£FireEye³Æ¹¥»÷Õß¿ÉÀûÓÃÕâЩ©¶´°²×°ºóÃÅ·¨Ê½¡¢·ÃÎÊÎļþºÍµç×ÓÓʼþºÍºáÏòÒÆ¶¯£¬´Ë´Î¹¥»÷»î¶¯±»×·×ÙΪUNC2682¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/3-zero-day-exploits-hit-sonicwall.html


6.GoogleÐû²¼½ô¼±¸üУ¬ÐÞ¸´½ñÄêµÚ4¸öÒѱ»ÀûÓõÄ0day


6.jpg


GoogleÓÚ4ÔÂ20ÈÕÐû²¼½ô¼±Äþ¾²¸üУ¬ÐÞ¸´°üÂÞÒ»¸ö0dayÔÚÄڵĶà¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ0dayΪV8 ChromeäÖȾÒýÇæÖеÄÀàÐÍ»ìÏý©¶´£¨CVE-2021-21224£©£¬ÊǽñÄê·¢ÏֵĵÚËĸöChrome 0day¡£´ËÍ⣬´Ë´Î¸üл¹ÐÞ¸´ÁËV8×é¼þÖеĶѻº³åÇøÒç³ö©¶´£¨CVE-2021-21222£©ºÍÔ½½çÄÚ´æ·ÃÎÊ©¶´£¨CVE-2021-21225£©£¬MojoÖеÄÕûÊýÒç³ö©¶´£¨CVE-2021-21223£©ºÍµ¼º½ÖеÄÊͷźóʹÓé¶´£¨CVE-2021-21226£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-chrome-hit-another-mysterious-zero-day-attack