×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»£»£»£»£»£»£»£»Monday.com°ä·¢Êܵ½Codecov¹©¸øÁ´¹¥»÷µÄÓ°Ïì
°ä²¼¹¦·ò 2021-05-191.×êÑÐÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ

¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖеİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐÓ×£¡£¡£¡£¡£¡£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÓµÓÐx64Ä£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬Äܹ»ÓÕÆÊܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬£¬£¬£¬£¬»¹ÀûÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆÊܺ¦ÕßÏÂÔØÒÆ¶¯ÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄÖ÷Ìâ×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öºÅÁîµÄºóÃÅ£¬£¬£¬£¬£¬Ö»Óе±Æä¼ì²âµ½ÒѾÏνӵ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬£¬£¬£¬£¬ºóÃŲŻáÆô¶¯¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html
2.FBI·¢ÏÖ½üÆÚ¼ÙÒâÃÀ¹úTruistÒøÐеĴ¹µö¹¥»÷»î¶¯

FBI·¢ÏÖÐÂÒ»ÂÖµÄÓã²æÊ½µÄ´¹µö¹¥»÷»î¶¯£¬£¬£¬£¬£¬¼ÙÒâÃÀ¹úµÚÁù´óÒøÐпعɹ«Ë¾Truist Bank¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Ðû³Æ±ØÒªÊµÏÖÒ»±Ê6200ÍòÃÀÔª´û¿î£¬£¬£¬£¬£¬À´ÓÕʹÓû§ÏÂÔØÒ»¸ö¼ÙÒâÁ˺Ϸ¨µÄTruism Financial SecureBank AppµÄWindowsÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁËÌá¸ß¹¥»÷µÄ³É¹¦ÂÊ£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁËVirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÎ´¼ì²âµ½µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»áÔÚÓû§ÏÂÔØ´¹µöÓʼþÖеĶñÒâ¿ÉÖ´ÐÐÎļþºó£¬£¬£¬£¬£¬±»×°Öõ½secureportal(.)onlineÓò¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fbi-spots-spear-phishing-posing-as-truist-bank-bank-to-deliver-malware/
3.Monday.com°ä·¢Êܵ½Codecov¹©¸øÁ´¹¥»÷µÄÓ°Ïì

Monday.com×î½üÅû¶ÆäÔâµ½Codecov¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬Ó°ÏìÁ˶à¼Ò¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£Monday.comÊÇÒ»¸öÔÚÏß¹¤×÷Á÷ÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬¸Ãƽ̨µÄ¿Í»§Ô̺¬Uber¡¢BBC Studios¡¢Adobe¡¢Universal¡¢Hulu¡¢L'Oreal¡¢ÊʿڿÉÀֺͽáºÏÀû»ªµÈ³ÛÃû¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£Monday.com·¢´Ë¿ÌÕâ´Î¹¥»÷ÖкڿÍÇÔÈ¡ÁËÆäÔ´´úÂëµÄÖ»¶Á¸±±¾£¬£¬£¬£¬£¬²¢Î´¶ÔÆä½øÐд۸ġ£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬»¹Ð¹Â¶ÁËÍйÜÔÚ¸ÃÆ½Ì¨ÉϵĿͻ§±íµ¥ºÍÊÓͼ¡£¡£¡£¡£¡£¡£¡£¡£×÷Ϊ»º½â´ëÊ©£¬£¬£¬£¬£¬¸Ãƽ̨ÖÕ³¡Ê¹ÓÃCodecovµÄ·þÎñ²¢¸ü»»ÁËËùÓгö²úºÍ¿ª·¢»·¾³µÄÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/codecov-hackers-gained-access-to-mondaycom-source-code/
4.ÃÀ¹úUtility³ÆÆäϰȾClop£¬£¬£¬£¬£¬Ô±¹¤µÄÓ×ÎÒÐÅϢй¶

Utility Trailer Manufacturing³ÆÆäϰȾÁËÀÕË÷Èí¼þClop£¬£¬£¬£¬£¬²¿ÃÅϵÍÂäÙʱÖжϡ£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Î»ÓÚ¼ÓÀû¸£ÄáÑÇ£¬£¬£¬£¬£¬ÊÇÃÀ¹ú×î´óµÄÍϳµ³ö²úÉÌÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£ClopÍÅ»ïÓÚÉÏÖÜÔÚ°µÍø¹«¿ªÁ˴Ӹù«Ë¾ÇÔÈ¡µÄ5 GBÊý¾Ý£¬£¬£¬£¬£¬Ô̺¬¹¤×ʵ¥ºÍÈËÁ¦×ÊÔ´ÐÅÏ¢µÈÔ±¹¤µÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÉÐδ¹«¿ª¹¥»÷µÄÁìÓòÒÔ¼°Êý¾Ýй¶µÄˮƽ¡£¡£¡£¡£¡£¡£¡£¡£ClopÔø¹¥»÷Á˶à¼Ò´óÐ͹«Ë¾£¬£¬£¬£¬£¬Ô̺¬Ìú·ÔËÓªÉÌCSXºÍ¼ÓÄôóȼÁϹ«Ë¾ParklandµÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.freightwaves.com/news/trailer-maker-utility-targeted-in-ransomware-attack
5.ESET·¢ÏÖ¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö

ESET×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ2019Ä꣬£¬£¬£¬£¬Android¸ú×ÙÈí¼þµÄÊýÁ¿ÏÕЩÊÇ2018ÄêµÄÎå±¶£¬£¬£¬£¬£¬¶øµ½ÁË2020Ä꣬£¬£¬£¬£¬´ËÀà¶ñÒâÈí¼þÊýÁ¿±È2019ÄêÔö³¤ÁË48£¥¡£¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚ´ËÀàÀûÓõĹ©¸øÉÌÀ´Ëµ£¬£¬£¬£¬£¬ÎªÁËÔ¤·À±»ÏóÕ÷Ϊ¸ú×ÙÈí¼þ£¬£¬£¬£¬£¬Í¨³£½«ÆäÐû´«ÎªÎª¶ùͯ¡¢Ô±¹¤»òÅ®ÐÔÌṩ±£»£»£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎöÁËÀ´×Ô86¸ö·ÖÆç¹©¸øÉ̵ÄAndroid¸ú×ÙÀûÓ㬣¬£¬£¬£¬×ܹ²·¢ÏÖÁË158¸ö°²È«ÎÊÌ⣬£¬£¬£¬£¬ÀýÈçÓû§ÐÅÏ¢´«Êä²»°²È«(CWE-200)¡¢·þÎñÆ÷й¶¸ú×ÙÕßÐÅÏ¢(CWE-200)ºÍºÅÁî×¢Èë(cwe-926)µÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/stalkerware-adoption-rates-surge-over-2020-hundreds-of-vulnerabilities-found/
6.Netscout°ä²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨

Netscout°ä²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢ÆðÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬£¬£¬£¬£¬±È2020ÄêͬÆÚÔö³¤ÁË31£¥£¬£¬£¬£¬£¬×î´óΪ480 Gbps£¬£¬£¬£¬£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬£¬£¬£¬£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬£¬£¬£¬£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬£¬£¬£¬£¬ÔÚÏß·þÎñÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/asert/beat-goes


¾©¹«Íø°²±¸11010802024551ºÅ