ÃÀ¹úºË±øÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷£»£»£»£»£»CodecovʹÓÃÐÂuploader´úÌæ½üÆÚ¹¥»÷ÖеÄBash¾ç±¾

°ä²¼¹¦·ò 2021-06-15

1.ÃÀ¹úºË±øÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷


1.jpg


ÃÀ¹úºË±øÆ÷³Ð°üÉÌSol OriensÔâµ½ÁËREvilÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÆäÖØÒªÐ­Öú¹ú·À²¿¡¢ÄÜÔ´²¿¡¢º½¿Õº½Ìì³Ð°üÉ̺ͼ¼Êõ¹«Ë¾·¢Õ¹¸´ÔÓµÄÏîÄ¿¡£¡£¡£¡£¡£REvilÍÅ»ïÔÚÅÄÂô¹¥»÷ÆÚ¼äÇÔÈ¡µÄÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÒµÎñÊý¾ÝºÍÔ±¹¤ÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÔ±¹¤Éç»á°²È«ºÅÂë¡¢ÕÐÆ¸¸ÅÀÀÎļþ¡¢¹¤×ʵ¥ÎļþºÍ¹¤×ʻ㱨µÈ¡£¡£¡£¡£¡£Sols OriensҲ֤ʵÁËÆäÔÚ2021Äê5ÔÂÔâµ½ÁËÍøÂç¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÒѾ­Ð¹Â¶²¿ÃÅÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖÓ×£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-us-nuclear-weapons-contractor/


2.CodecovʹÓÃÐÂuploader´úÌæ½üÆÚ¹¥»÷ÖеÄBash¾ç±¾


2.jpg


CodecovʹÓÃÁËÒ»¸öеÄuploaderÀ´´úÌæ½üÆÚ¹¥»÷ÖеÄBash¾ç±¾¡£¡£¡£¡£¡£¸Ãuploade½«×÷Ϊһ¸ö¾²Ì¬¶þ½øÔì¿ÉÖ´ÐÐÎļþ°ä²¼ £¬£¬£¬£¬£¬£¬£¬£¬ºÏÓÃÓÚWindows¡¢Linux¡¢Alpine LinuxºÍmacOS £¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°»¹´¦ÓÚ²âÊÔ½×¶Î £¬£¬£¬£¬£¬£¬£¬£¬ÓëÏÖÓеÄBashʹÓÃÒ»ÑùµÄ·½Ê½ÔÚ¿ª·¢ÖÜÆÚÖÐÍÆË͸²¸ÇÊý¾ÝºÍ¸üС£¡£¡£¡£¡£´ËÂÖ¹¥»÷²úÉúÔÚ2021Äê1ÔÂ31ÈÕ×óÓÒ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ4ÔÂ15ÈÕ±»Åû¶¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬£¬Êý°Ù¸ö×éÖ¯ÒѾíÈë¸ÃÊÂÎñ £¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Rapid7¡¢Monday.comºÍMercariµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/codecov-debuts-new-uploader-dismisses-bash-script-as-source-of-supply-chain-attack-risk/


3.¹ú¼ÊÐ̾¯µÄPangea XIVÐж¯É¾³ý³¬¹ý11Íò¸ö´¹µöÁ´½Ó


3.jpg


¹ú¼ÊÐ̾¯×éÖ¯£¨The Interpol£©µÄPangea XIVÐж¯É¾³ý³¬¹ý11Íò¸ö´¹µöÁ´½Ó¡£¡£¡£¡£¡£Õâ´Î·¨ÂÉ»î¶¯ÖØÒªÊÇÕë¶Ô¼ÙðºÍ·¸·¨µÄÒ©Æ·ºÍÒ½ÁÆÉ豸µÄÔÚÏßÂô¼Ò¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¹ú¼ÊÐ̾¯×éÖ¯µÄЭµ÷Ï £¬£¬£¬£¬£¬£¬£¬£¬92¸ö¹ú¶ÈµÄ·¨ÂÉ»ú¹¹¡¢º£¹ØºÍÎÀÉú¼à¹Ü»ú¹¹É¾³ýÁË113020¸öÍøÂçÁ´½Ó £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬±»¹Ø¹Ø»òɾ³ýµÄÍøÕ¾ºÍÔÚÏßÊг¡¡£¡£¡£¡£¡£½öÔÚÓ¢¹ú £¬£¬£¬£¬£¬£¬£¬£¬¾Í²é»ñÁ˼ÛÖµ³¬¹ý1300ÍòÃÀÔªµÄ300¶àÍò¼þ¼ÙÒ©ºÍÉ豸 £¬£¬£¬£¬£¬£¬£¬£¬»¹É¾³ýÁË3100¶à¸ö·¸·¨ÏúÊۺ͹©¸øÎÞÅÆÒ©Æ·µÄ¸æ°×Á´½Ó £¬£¬£¬£¬£¬£¬£¬£¬²¢¹ØÁË43¸öÍøÕ¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/interpol-shuts-down-thousands-of-fake-online-pharmacies/


4.Rapid7×êÑÐÈËÔ±Åû¶Akkadianƽ̨ÖеĶà¸ö°²È«·ì϶


4.jpg


Rapid7×êÑÐÈËÔ±Åû¶Akkadian Provisioning ManagerÖеĶà¸ö°²È«·ì϶¡£¡£¡£¡£¡£¸Ãƽ̨ÊÇ˼¿ÆÍ³Ò»Í¨Ñ¶£¨UC£©»·¾³ÖеĵÚÈý·½¹©¸ø¹¤¾ß £¬£¬£¬£¬£¬£¬£¬£¬Í¨³£ÓÃÓÚ´óÐÍÆóÒµ £¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý×Ô¶¯»¯À´Ô®ÊÔìäÖÎÀíËùÓÐUC¿Í»§¶ËºÍÊ·ýµÄÅäÖᣡ£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪʹÓÃÓ²±àÂëÍ´´¦£¨CVE-2021-31579£©¡¢ºÅÁî×¢Èë·ì϶£¨CVE-2021-31580ºÍCVE-2021-31581£©ÒÔ¼°Ãô¸ÐÐÅϢй¶£¨CVE-2021-31582£©¡£¡£¡£¡£¡£Rapid7³Æ £¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÓÃÀ´Ô¶³ÌÖ´ÐдúÂë £¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÈÔ佨¸´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/unpatched-bugs-provisioning-cisco-uc/166882/


5.APWG°ä²¼2021ÄêQ1ÍøÂç´¹µö»î¶¯Ì¬ÊƵķÖÎö»ã±¨


5.jpg


APWG°ä²¼ÁË2021ÄêQ1ÍøÂç´¹µö»î¶¯Ì¬ÊƵķÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨ÏÔʾ £¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç´¹µöÍøÕ¾ÊýÁ¿ÔÚ2021Äê1Ô´ﵽ·åÖµ £¬£¬£¬£¬£¬£¬£¬£¬´´ÏÂÁË245771¸öµÄº¹ÇàÐÂ¸ß £¬£¬£¬£¬£¬£¬£¬£¬¶øºóÔÚ±¾¼¾¶ÈµÄºóÆÚÆðÍ·½µÂä¡£¡£¡£¡£¡£Ã³Ò×µç×ÓÓʼþ(BEC)Ú¿Æ­µÄ³É±¾Ô½À´Ô½¸ß £¬£¬£¬£¬£¬£¬£¬£¬´Ó2020ÄêQ3µÄ48000ÃÀÔªÔö³¤µ½ÁË2021ÄêQ1µÄ85000ÃÀÔª¡£¡£¡£¡£¡£Õë¶Ô½ðÈÚ»ú¹¹µÄÍøÂç´¹µöÊÇQ1Õ¼±È×î´óµÄÀàÐÍ £¬£¬£¬£¬£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ24.9%¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÉ罻ýÌåÐÐÒµµÄÍøÂç´¹µöÔÚËùÓй¥»÷ÖÐËùÕ¼±ÈÀý´Ó2020ÄêQ4µÄ11.8%¼¤ÔöÖÁ23.6%¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.prnewswire.com/news-releases/apwg-q1-2021-report-detected-phishing-websites-maintain-historic-high-in-q1-2021-after-doubling-in-2020-301309187.html


6.Cisco Talos°ä²¼2021ÄêQ1ÊÂÎñÏìÓ¦Ç÷ÏòµÄ·ÖÎö»ã±¨


6.jpg


Cisco Talos°ä²¼ÁË2021ÄêQ1ÊÂÎñÏìÓ¦Ç÷ÏòµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö £¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔMicrosoft Exchange ServerÖм¸¸öÁãÈÕ·ì϶µÄ¹¥»÷ÊÇÉϸö¼¾¶È×î´óµÄÍþв £¬£¬£¬£¬£¬£¬£¬£¬Ô¼Õ¼ËùÓе÷²éÊÂÎñµÄ35%¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬£¬£¬¸Ã»ã±¨»¹½éÉÜÁËÔÚÏÈǰ´ÓδÓöµ½µÄ¼¸¸öÀÕË÷Èí¼þϵÁÐ £¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬MountLocker¡¢ZeppelinºÍAvaddon¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§Ä¦ £¬£¬£¬£¬£¬£¬£¬£¬Q4 DridexϰȾÂʽ«´Ó3ÔÂµ×ÆðÍ·Ïà¶ÔÉÏÉý £¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÓë½ñÄêÔçЩʱ³½È«Çò·¨Âɲ¿ÃŽáºÏµ·»ÙEmotetÓйء£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/06/quarterly-report-incident-response.html