Êý°ÙÆóÒµÔâCodecov¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¿°±ÈSolarWinds¹¥»÷£»£»£»£»QuantaѬȾREvil£¬£¬£¬£¬£¬£¬£¬£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶±»ÀÕË÷5ÍòÍò
Ðû²¼Ê±¼ä 2021-04-221.Êý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¿°±ÈSolarWinds¹¥»÷

·͸É籨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÓÐÊý°Ù¸öÆóÒµÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓë×î½üµÄSolarWinds¹¥»÷ÏàÌá²¢ÂÛ¡£¡£¡£¡£¡£¡£CodecovÓµÓÐ29000¶à¸ö¿Í»§£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨GoDaddy¡¢AtlassianºÍProcter£¦Gamble£¨P£¦G£©µÈÖøÃû¹«Ë¾¡£¡£¡£¡£¡£¡£³õ³ÌÐò²éÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í´Ó1ÔÂ31ÈÕ×îÏȰ´ÆÚ¶ÔBash Uploader¾ç±¾¾ÙÐи͝£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡´æ´¢ÔÚ´æ´¢ÔÚCIÇéÐÎÖеÄÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ö±µ½4ÔÂ1Èղű»·¢Ã÷¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬IBMµÈCodecovµÄ¶à¸ö¿Í»§¶¼ÌåÏÖËûÃǵĴúÂëÉÐδ±»¸Ä¶¯£¬£¬£¬£¬£¬£¬£¬£¬µ«¾Ü¾øÍ¸Â¶ÆäϵͳÊÇ·ñÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/
2.QuantaѬȾREvil£¬£¬£¬£¬£¬£¬£¬£¬AppleÉè¼ÆÀ¶Í¼Ð¹Â¶²¢±»ÀÕË÷5000Íò

Öйų́ÍåµÄQuantaѬȾREvil£¬£¬£¬£¬£¬£¬£¬£¬Apple¹«Ë¾°üÀ¨¼´½«Ðû²¼µÄ²úÆ·ÔÚÄڵĴó×ÚÉè¼ÆÀ¶Í¼Ð¹Â¶£¬£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷5000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£QuantaÊÇÈ«ÇòµÚ¶þ´óÌõ¼Ç±¾µçÄÔÔʼÉè¼ÆÖÆÔìÉÌ£¨ODM£©£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§°üÀ¨Apple¡¢Dell¡¢Hewlett-Packard¡¢Alienware¡¢Lenovo¡¢CiscoºÍMicrosoft¡£¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬£¬REvilÔÚÆäÍøÕ¾ÉϹûÕæÁËÊ®¼¸¸öMacBook×é¼þµÄʾÒâͼ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÆäÕýÔÚÓ뼸¸öÓÐÐËȤ¹ºÖÃÉñÃØÍ¼Ö½µÄµÚÈý·½¾ÙÐÐ̸ÅС£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬QuantaºÍApple¾ùδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/revil-ransomware-gang-hits-apple-supplier-quanta/
3.QlockerÔÚ½üÆÚ´ó¹æÄ£ÀÕË÷¹¥»÷ÖÐʹÓÃ7zip¼ÓÃÜQNAP×°±¸

ÀÕË÷Èí¼þQlocker×Ô2021Äê4ÔÂ19ÈÕ×îÏÈÕë¶ÔQNAP×°±¸Ìᳫ´ó¹æÄ£µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£ÔÚÕâÂÖ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃ7-zip½«QNAPÉè±¹ØÁ¬ÄÎļþÒÆÈëÓÐÃÜÂë±£»£»£»£»¤µÄµµ°¸¿â£¬£¬£¬£¬£¬£¬£¬£¬´ËʱQNAPµÄ×ÊÔ´¼àÊÓÖ»»áÏÔʾ´ó×ÚµÄ7zÀú³Ì¡£¡£¡£¡£¡£¡£Æ¾Ö¤QlockerµÄÊê½ð¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬ËùÓÐÊܺ¦Õß¾ù±»ÒªÇóÖ§¸¶0.01±ÈÌØ±Ò£¨Ô¼ºÏ557.74ÃÀÔª£©À´»ñÈ¡Æä½âÃÜÃÜÂë¡£¡£¡£¡£¡£¡£QNAP×î½üÐÞ¸´Á˶à¸öÑÏÖØµÄÎó²î£¬£¬£¬£¬£¬£¬£¬£¬²¢Ç¿ÁÒ½¨ÒéÓû§½«Æä²úÆ·Éý¼¶µ½×îа汾¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/
4.ESET·¢Ã÷ͨ¹ýαÔìSpotifyµÈÓ¦ÓÃÃé×¼ÄÏÃÀµØÇøµÄ¹¥»÷»î¶¯

Çå¾²¹«Ë¾ESET·¢Ã÷ͨ¹ýαÔìMicrosoft Store¡¢SpotifyºÍÔÚÏßÎĵµ×ª»»ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Ãé×¼ÄÏÃÀµØÇøµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷ʹÓöñÒâ¹ã¸æ½«Óû§ÒýÈëαÔìµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÓû§»á¼ûÍøÕ¾Ê±Éϰ¶Ò³Ã潫×Ô¶¯ÏÂÔØ°üÀ¨Ficker¶ñÒâÈí¼þµÄzipÎļþ¡£¡£¡£¡£¡£¡£FickerÊÇÒ»ÖÖÐÅÏ¢ÇÔȡľÂí£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ1Ô·Ý×îÏÈÔÚ°µÍøÉϾÙÐгö×⣬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚWebä¯ÀÀÆ÷¡¢×ÀÃæÐÂÎſͻ§¶Ë£¨Pidgin£¬£¬£¬£¬£¬£¬£¬£¬Steam£¬£¬£¬£¬£¬£¬£¬£¬Discord£©ºÍFTP¿Í»§¶ËÖÐÇÔȡƾ֤£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°ü¡¢ÎĵµÒÔ¼°ÕýÔڻµÄÓ¦ÓýØÍ¼¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-microsoft-store-spotify-sites-spread-info-stealing-malware/
5.SonicWallÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´3¸öÒѱ»ÔÚҰʹÓõÄ0day

SonicWallÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäÍйܺÍÍâµØµç×ÓÓʼþÇå¾²£¨ES£©²úÆ·ÖеÄ3¸öÒѱ»ÔÚҰʹÓõÄ0day¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î»®·ÖΪCVSSÆÀ·ÖΪ9.4µÄCVE-2021-20021£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÏòÔ¶³ÌÖ÷»ú·¢ËÍÌØÖÆµÄHTTPÇëÇóÀ´½¨ÉèÖÎÀíÕÊ»§¡¢í§ÒâÎļþÉÏ´«Îó²î£¨CVE-2021-20022£©ÒÔ¼°Ä¿Â¼±éÀúÎó²î£¨CVE-2021-20023£©¡£¡£¡£¡£¡£¡£FireEye³Æ¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×°ÖúóÃųÌÐò¡¢»á¼ûÎļþºÍµç×ÓÓʼþºÍºáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯±»×·×ÙΪUNC2682¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/04/3-zero-day-exploits-hit-sonicwall.html
6.GoogleÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´½ñÄêµÚ4¸öÒѱ»Ê¹ÓõÄ0day

GoogleÓÚ4ÔÂ20ÈÕÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´°üÀ¨Ò»¸ö0dayÔÚÄڵĶà¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0dayΪV8 ChromeäÖȾÒýÇæÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2021-21224£©£¬£¬£¬£¬£¬£¬£¬£¬ÊǽñÄê·¢Ã÷µÄµÚËĸöChrome 0day¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËV8×é¼þÖеĶѻº³åÇøÒç³öÎó²î£¨CVE-2021-21222£©ºÍÔ½½çÄÚ´æ»á¼ûÎó²î£¨CVE-2021-21225£©£¬£¬£¬£¬£¬£¬£¬£¬MojoÖеÄÕûÊýÒç³öÎó²î£¨CVE-2021-21223£©ºÍµ¼º½ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2021-21226£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/google-chrome-hit-another-mysterious-zero-day-attack


¾©¹«Íø°²±¸11010802024551ºÅ