×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»£»£»£»£»£» £»£»Monday.com°ä·¢Êܵ½Codecov¹©¸øÁ´¹¥»÷µÄÓ°Ïì

°ä²¼¹¦·ò 2021-05-19

1.×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ


1.jpg


¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖеİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐÓ×£ ¡£¡£¡£¡£¡£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬ÓµÓÐx64Ä£¿£¿ £¿£¿£¿é£¬ £¬£¬£¬£¬Äܹ»ÓÕÆ­Êܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬 £¬£¬£¬£¬»¹ÀûÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆ­Êܺ¦ÕßÏÂÔØÒÆ¶¯ÀûÓ÷¨Ê½¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄÖ÷Ìâ×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öºÅÁîµÄºóÃÅ£¬ £¬£¬£¬£¬Ö»Óе±Æä¼ì²âµ½ÒѾ­Ïνӵ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬ £¬£¬£¬£¬ºóÃŲŻáÆô¶¯¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html


2.FBI·¢ÏÖ½üÆÚ¼ÙÒâÃÀ¹úTruistÒøÐеĴ¹µö¹¥»÷»î¶¯


2.jpg


FBI·¢ÏÖÐÂÒ»ÂÖµÄÓã²æÊ½µÄ´¹µö¹¥»÷»î¶¯£¬ £¬£¬£¬£¬¼ÙÒâÃÀ¹úµÚÁù´óÒøÐпعɹ«Ë¾Truist Bank¡£ ¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Ðû³Æ±ØÒªÊµÏÖÒ»±Ê6200ÍòÃÀÔª´û¿î£¬ £¬£¬£¬£¬À´ÓÕʹÓû§ÏÂÔØÒ»¸ö¼ÙÒâÁ˺Ϸ¨µÄTruism Financial SecureBank AppµÄWindowsÀûÓ÷¨Ê½¡£ ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÌá¸ß¹¥»÷µÄ³É¹¦ÂÊ£¬ £¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁËVirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÎ´¼ì²âµ½µÄ¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»áÔÚÓû§ÏÂÔØ´¹µöÓʼþÖеĶñÒâ¿ÉÖ´ÐÐÎļþºó£¬ £¬£¬£¬£¬±»×°Öõ½secureportal(.)onlineÓò¡£ ¡£¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-spots-spear-phishing-posing-as-truist-bank-bank-to-deliver-malware/


3.Monday.com°ä·¢Êܵ½Codecov¹©¸øÁ´¹¥»÷µÄÓ°Ïì


3.jpg


Monday.com×î½üÅû¶ÆäÔâµ½Codecov¹©¸øÁ´¹¥»÷£¬ £¬£¬£¬£¬Ó°ÏìÁ˶à¼Ò¹«Ë¾¡£ ¡£¡£¡£¡£¡£¡£¡£Monday.comÊÇÒ»¸öÔÚÏß¹¤×÷Á÷ÖÎÀíÆ½Ì¨£¬ £¬£¬£¬£¬¸Ãƽ̨µÄ¿Í»§Ô̺¬Uber¡¢BBC Studios¡¢Adobe¡¢Universal¡¢Hulu¡¢L'Oreal¡¢ÊʿڿÉÀֺͽáºÏÀû»ªµÈ³ÛÃû¹«Ë¾¡£ ¡£¡£¡£¡£¡£¡£¡£Monday.com·¢´Ë¿ÌÕâ´Î¹¥»÷ÖкڿÍÇÔÈ¡ÁËÆäÔ´´úÂëµÄÖ»¶Á¸±±¾£¬ £¬£¬£¬£¬²¢Î´¶ÔÆä½øÐд۸ġ£ ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬»¹Ð¹Â¶ÁËÍйÜÔÚ¸ÃÆ½Ì¨ÉϵĿͻ§±íµ¥ºÍÊÓͼ¡£ ¡£¡£¡£¡£¡£¡£¡£×÷Ϊ»º½â´ëÊ©£¬ £¬£¬£¬£¬¸Ãƽ̨ÖÕ³¡Ê¹ÓÃCodecovµÄ·þÎñ²¢¸ü»»ÁËËùÓгö²úºÍ¿ª·¢»·¾³µÄÃÜÔ¿¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/codecov-hackers-gained-access-to-mondaycom-source-code/


4.ÃÀ¹úUtility³ÆÆäϰȾClop£¬ £¬£¬£¬£¬Ô±¹¤µÄÓ×ÎÒÐÅϢй¶


4.jpg


Utility Trailer Manufacturing³ÆÆäϰȾÁËÀÕË÷Èí¼þClop£¬ £¬£¬£¬£¬²¿ÃÅϵÍÂäÙʱÖжϡ£ ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Î»ÓÚ¼ÓÀû¸£ÄáÑÇ£¬ £¬£¬£¬£¬ÊÇÃÀ¹ú×î´óµÄÍϳµ³ö²úÉÌÖ®Ò»¡£ ¡£¡£¡£¡£¡£¡£¡£ClopÍÅ»ïÓÚÉÏÖÜÔÚ°µÍø¹«¿ªÁ˴Ӹù«Ë¾ÇÔÈ¡µÄ5 GBÊý¾Ý£¬ £¬£¬£¬£¬Ô̺¬¹¤×ʵ¥ºÍÈËÁ¦×ÊÔ´ÐÅÏ¢µÈÔ±¹¤µÄÃô¸ÐÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬¸Ã¹«Ë¾ÉÐδ¹«¿ª¹¥»÷µÄÁìÓòÒÔ¼°Êý¾Ýй¶µÄˮƽ¡£ ¡£¡£¡£¡£¡£¡£¡£ClopÔø¹¥»÷Á˶à¼Ò´óÐ͹«Ë¾£¬ £¬£¬£¬£¬Ô̺¬Ìú·ÔËÓªÉÌCSXºÍ¼ÓÄôóȼÁϹ«Ë¾ParklandµÈ¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.freightwaves.com/news/trailer-maker-utility-targeted-in-ransomware-attack


5.ESET·¢ÏÖ¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö


5.jpg


ESET×êÑÐÈËÔ±·¢ÏÖ£¬ £¬£¬£¬£¬¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö¡£ ¡£¡£¡£¡£¡£¡£¡£ÔÚ2019Ä꣬ £¬£¬£¬£¬Android¸ú×ÙÈí¼þµÄÊýÁ¿ÏÕЩÊÇ2018ÄêµÄÎå±¶£¬ £¬£¬£¬£¬¶øµ½ÁË2020Ä꣬ £¬£¬£¬£¬´ËÀà¶ñÒâÈí¼þÊýÁ¿±È2019ÄêÔö³¤ÁË48£¥¡£ ¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚ´ËÀàÀûÓõĹ©¸øÉÌÀ´Ëµ£¬ £¬£¬£¬£¬ÎªÁËÔ¤·À±»ÏóÕ÷Ϊ¸ú×ÙÈí¼þ£¬ £¬£¬£¬£¬Í¨³£½«ÆäÐû´«ÎªÎª¶ùͯ¡¢Ô±¹¤»òÅ®ÐÔÌṩ±£»£»£»£»£»£» £»£»¤¡£ ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎöÁËÀ´×Ô86¸ö·ÖÆç¹©¸øÉ̵ÄAndroid¸ú×ÙÀûÓ㬠£¬£¬£¬£¬×ܹ²·¢ÏÖÁË158¸ö°²È«ÎÊÌ⣬ £¬£¬£¬£¬ÀýÈçÓû§ÐÅÏ¢´«Êä²»°²È«(CWE-200)¡¢·þÎñÆ÷й¶¸ú×ÙÕßÐÅÏ¢(CWE-200)ºÍºÅÁî×¢Èë(cwe-926)µÈ¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/stalkerware-adoption-rates-surge-over-2020-hundreds-of-vulnerabilities-found/


6.Netscout°ä²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨


6.jpg


Netscout°ä²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢ÆðÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬ £¬£¬£¬£¬±È2020ÄêͬÆÚÔö³¤ÁË31£¥£¬ £¬£¬£¬£¬×î´óΪ480 Gbps£¬ £¬£¬£¬£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬ £¬£¬£¬£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£ ¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬ £¬£¬£¬£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬ £¬£¬£¬£¬ÔÚÏß·þÎñÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/asert/beat-goes