ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷£»£»£»£»£»£»£»CodecovʹÓÃÐÂuploaderÌæ»»½üÆÚ¹¥»÷ÖеÄBash¾ç±¾

Ðû²¼Ê±¼ä 2021-06-15

1.ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷


1.jpg


ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâµ½ÁËREvilÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¸Ã¹«Ë¾³ÆÆäÖ÷ҪЭÖú¹ú·À²¿¡¢ÄÜÔ´²¿¡¢º½¿Õº½Ìì³Ð°üÉ̺ÍÊÖÒÕ¹«Ë¾¿ªÕ¹ÖØ´óµÄÏîÄ¿¡£¡£¡£REvilÍÅ»ïÕýÔÚÅÄÂô¹¥»÷ʱ´úÇÔÈ¡µÄÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨ÓªÒµÊý¾ÝºÍÔ±¹¤ÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬ÀýÈçÔ±¹¤Éç»áÇå¾²ºÅÂë¡¢ÕÐÆ¸¸ÅÀÀÎļþ¡¢ÈËΪµ¥ÎļþºÍÈËΪ±¨¸æµÈ¡£¡£¡£Sols OriensҲ֤ʵÁËÆäÔÚ2021Äê5ÔÂÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬£¬¿ÉÄÜÒѾ­Ð¹Â¶²¿·ÖÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬ÏÖÔÚÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-us-nuclear-weapons-contractor/


2.CodecovʹÓÃÐÂuploaderÌæ»»½üÆÚ¹¥»÷ÖеÄBash¾ç±¾


2.jpg


CodecovʹÓÃÁËÒ»¸öеÄuploaderÀ´Ìæ»»½üÆÚ¹¥»÷ÖеÄBash¾ç±¾¡£¡£¡£¸Ãuploade½«×÷Ϊһ¸ö¾²Ì¬¶þ½øÖÆ¿ÉÖ´ÐÐÎļþÐû²¼£¬£¬£¬ £¬£¬£¬£¬ÊÊÓÃÓÚWindows¡¢Linux¡¢Alpine LinuxºÍmacOS£¬£¬£¬ £¬£¬£¬£¬ÏÖÔÚ»¹´¦ÓÚ²âÊԽ׶Σ¬£¬£¬ £¬£¬£¬£¬ÓëÏÖÓеÄBashʹÓÃÏàͬµÄ·½·¨ÔÚ¿ª·¢ÖÜÆÚÖÐÍÆËÍÁýÕÖÊý¾ÝºÍ¸üС£¡£¡£´ËÂÖ¹¥»÷±¬·¢ÔÚ2021Äê1ÔÂ31ÈÕ×óÓÒ£¬£¬£¬ £¬£¬£¬£¬²¢ÓÚ4ÔÂ15ÈÕ±»Åû¶¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬£¬Êý°Ù¸ö×éÖ¯ÒѾíÈë¸ÃÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬°üÀ¨Rapid7¡¢Monday.comºÍMercariµÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/codecov-debuts-new-uploader-dismisses-bash-script-as-source-of-supply-chain-attack-risk/


3.¹ú¼ÊÐ̾¯µÄPangea XIVÐж¯É¾³ýÁè¼Ý11Íò¸ö´¹ÂÚÁ´½Ó


3.jpg


¹ú¼ÊÐ̾¯×éÖ¯£¨The Interpol£©µÄPangea XIVÐж¯É¾³ýÁè¼Ý11Íò¸ö´¹ÂÚÁ´½Ó¡£¡£¡£´Ë´ÎÖ´·¨»î¶¯Ö÷ÒªÊÇÕë¶Ôð³äºÍ²»·¨µÄÒ©Æ·ºÍÒ½ÁÆ×°±¸µÄÔÚÏßÂô¼Ò¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬£¬ÔÚ¹ú¼ÊÐ̾¯×éÖ¯µÄЭµ÷Ï£¬£¬£¬ £¬£¬£¬£¬92¸ö¹ú¼ÒµÄÖ´·¨»ú¹¹¡¢º£¹ØºÍÎÀÉúî¿Ïµ»ú¹¹É¾³ýÁË113020¸öÍøÂçÁ´½Ó£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨±»¹Ø±Õ»òɾ³ýµÄÍøÕ¾ºÍÔÚÏßÊг¡¡£¡£¡£½öÔÚÓ¢¹ú£¬£¬£¬ £¬£¬£¬£¬¾Í²é»ñÁ˼ÛÖµÁè¼Ý1300ÍòÃÀÔªµÄ300¶àÍò¼þ¼ÙÒ©ºÍ×°±¸£¬£¬£¬ £¬£¬£¬£¬»¹É¾³ýÁË3100¶à¸ö²»·¨ÏúÊۺ͹©Ó¦ÎÞÅÆÒ©Æ·µÄ¹ã¸æÁ´½Ó£¬£¬£¬ £¬£¬£¬£¬²¢±ÕÁË43¸öÍøÕ¾¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/interpol-shuts-down-thousands-of-fake-online-pharmacies/


4.Rapid7Ñо¿Ö°Ô±Åû¶Akkadianƽ̨ÖеĶà¸öÇå¾²Îó²î


4.jpg


Rapid7Ñо¿Ö°Ô±Åû¶Akkadian Provisioning ManagerÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¸Ãƽ̨ÊÇ˼¿ÆÍ³Ò»Í¨Ñ¶£¨UC£©ÇéÐÎÖеĵÚÈý·½¹©Ó¦¹¤¾ß£¬£¬£¬ £¬£¬£¬£¬Í¨³£ÓÃÓÚ´óÐÍÆóÒµ£¬£¬£¬ £¬£¬£¬£¬Í¨¹ý×Ô¶¯»¯À´×ÊÖúÆäÖÎÀíËùÓÐUC¿Í»§¶ËºÍʵÀýµÄÉèÖᣡ£¡£ÕâЩÎó²î»®·ÖΪʹÓÃÓ²±àÂëÆ¾Ö¤£¨CVE-2021-31579£©¡¢ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-31580ºÍCVE-2021-31581£©ÒÔ¼°Ãô¸ÐÐÅϢй¶£¨CVE-2021-31582£©¡£¡£¡£Rapid7³Æ£¬£¬£¬ £¬£¬£¬£¬ÕâЩÎó²î¿ÉÓÃÀ´Ô¶³ÌÖ´ÐдúÂ룬£¬£¬ £¬£¬£¬£¬ÏÖÔÚÈÔδÐÞ¸´¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/unpatched-bugs-provisioning-cisco-uc/166882/


5.APWGÐû²¼2021ÄêQ1ÍøÂç´¹ÂÚ»î¶¯Ì¬ÊÆµÄÆÊÎö±¨¸æ


5.jpg


APWGÐû²¼ÁË2021ÄêQ1ÍøÂç´¹ÂÚ»î¶¯Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬ £¬£¬£¬£¬ÍøÂç´¹ÂÚÍøÕ¾ÊýÄ¿ÔÚ2021Äê1Ôµִï·åÖµ£¬£¬£¬ £¬£¬£¬£¬´´ÏÂÁË245771¸öµÄÀúʷиߣ¬£¬£¬ £¬£¬£¬£¬È»ºóÔÚ±¾¼¾¶ÈµÄºóÆÚ×îÏÈϽµ¡£¡£¡£ÉÌÒµµç×ÓÓʼþ(BEC)Õ©Æ­µÄ±¾Ç®Ô½À´Ô½¸ß£¬£¬£¬ £¬£¬£¬£¬´Ó2020ÄêQ3µÄ48000ÃÀÔªÔöÌíµ½ÁË2021ÄêQ1µÄ85000ÃÀÔª¡£¡£¡£Õë¶Ô½ðÈÚ»ú¹¹µÄÍøÂç´¹ÂÚÊÇQ1Õ¼±È×î´óµÄÀàÐÍ£¬£¬£¬ £¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ24.9%¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬Õë¶ÔÉ罻ýÌåÐÐÒµµÄÍøÂç´¹ÂÚÔÚËùÓй¥»÷ÖÐËùÕ¼±ÈÀý´Ó2020ÄêQ4µÄ11.8%¼¤ÔöÖÁ23.6%¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.prnewswire.com/news-releases/apwg-q1-2021-report-detected-phishing-websites-maintain-historic-high-in-q1-2021-after-doubling-in-2020-301309187.html


6.Cisco TalosÐû²¼2021ÄêQ1ÊÂÎñÏìÓ¦Ç÷ÊÆµÄÆÊÎö±¨¸æ


6.jpg


Cisco TalosÐû²¼ÁË2021ÄêQ1ÊÂÎñÏìÓ¦Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬£¬£¬Õë¶ÔMicrosoft Exchange ServerÖм¸¸öÁãÈÕÎó²îµÄ¹¥»÷ÊÇÉϸö¼¾¶È×î´óµÄÍþв£¬£¬£¬ £¬£¬£¬£¬Ô¼Õ¼ËùÓÐÊÓ²ìÊÂÎñµÄ35%¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬¸Ã±¨¸æ»¹ÏÈÈÝÁËÔÚÏÈǰ´ÓδÓöµ½µÄ¼¸¸öÀÕË÷Èí¼þϵÁУ¬£¬£¬ £¬£¬£¬£¬°üÀ¨MountLocker¡¢ZeppelinºÍAvaddon¡£¡£¡£Ñо¿Ö°Ô±ÍƲ⣬£¬£¬ £¬£¬£¬£¬Q4 DridexѬȾÂʽ«´Ó3ÔÂβ×îÏÈÏà¶ÔÉÏÉý£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄÜÓë½ñÄêÔçЩʱ¼äÈ«ÇòÖ´·¨²¿·ÖÁªºÏµ·»ÙEmotetÓйØ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/06/quarterly-report-incident-response.html