GitHubÆØÑϳÁRCE·ì϶ӰÏìÊý°ÙÍò´úÂë¿â

°ä²¼¹¦·ò 2026-04-30

1. GitHubÆØÑϳÁRCE·ì϶ӰÏìÊý°ÙÍò´úÂë¿â


4ÔÂ29ÈÕ £¬£¬£¬£¬£¬Ôư²È«¾ÞÍ·WizµÄ×êÑÐÈËÔ±ÔÚGitHubÉÏ·¢ÏÖÁËÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶ £¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÄܶ³öÊý°ÙÍò¸ö´úÂë¿â¡£¡£¡£¡£¡£·ì϶±àºÅΪCVE-2026-3854 £¬£¬£¬£¬£¬Ó°ÏìÁË´úÂëÍÐ¹ÜÆ½Ì¨ÄÚ²¿µÄGit»ù´¡¼Ü¹¹ £¬£¬£¬£¬£¬GitHub Enterprise ServerºÍGitHub.com¾ùÊܵ½²¨¼°¡£¡£¡£¡£¡£WizÚ¹ÊÍ³Æ £¬£¬£¬£¬£¬Í¨¹ýÀûÓÃGitHubÄÚ²¿ºÍ̸ÖеÄ×¢Èë·ì϶ £¬£¬£¬£¬£¬Èκξ­¹ýÉí·ÝÑéÖ¤µÄÓû§¾ù¿ÉʹÓó߶Ègit¿Í»§¶Ë £¬£¬£¬£¬£¬Í¨¹ýÒ»¸ögit pushºÅÁîÔÚGitHubµÄºó¶Ë·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£Õâ¼Ò°²È«¹«Ë¾ÀûÓÃÈËΪÖÇÄÜ·¢ÏÖ¸ÃÎÊÌâ £¬£¬£¬£¬£¬²¢°µÊ¾·ì϶ÀûÓü«¶ÈÈÝÒס£¡£¡£¡£¡£ÒÔGitHub Enterprise ServerΪÀý £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÆëÈ«½ÚÔì·þÎñÆ÷ £¬£¬£¬£¬£¬»ñµÃ¶ÔËùÓд洢¿âºÍÄÚ²¿»úÃÜÐÅÏ¢µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¸Ã·ì϶¶ÔGitHub.comµÄÓ°Ïì¸üΪ¿í·º £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔÚ¹²Ïí´æ´¢½ÚµãÉÏÖ´ÐÐÔ¶³Ì´úÂë £¬£¬£¬£¬£¬WizÈ·ÈÏÊý°ÙÍò¸öÊôÓÚÆäËûÓû§ºÍ×éÖ¯µÄ¹«¹²¼°Ë½ÓдúÂë¿âÔÚÊÜÓ°ÏìµÄ½ÚµãÉϾù¿É½Ó¼û¡£¡£¡£¡£¡£¹ÌÈ»Éí·ÝÑéÖ¤ÒªÇóËÆºõ½µµÍÁË·çÏÕ £¬£¬£¬£¬£¬µ«GitHubÚ¹ÊÍ³Æ £¬£¬£¬£¬£¬ÈκÎÕ¼ÓÐÏò´æ´¢¿âÍÆËÍȨÏÞµÄÓû§¾ù¿ÉÀûÓô˷ì϶ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£


https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/


2. CISA½«ConnectWiseÓëWindows Shell·ì϶ÄÉÈëKEVĿ¼


4ÔÂ29ÈÕ £¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö½üÈÕ½«Á½¸öÒѱ»¿í·ºÀûÓõݲȫ·ì϶ÄÉÈëÆäÒÑÖª¿ÉÀûÓ÷ì϶Ŀ¼ £¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ2026Äê5ÔÂ12ÈÕǰʵÏÖ½¨¸´¡£¡£¡£¡£¡£Ê׸ö·ì϶ÊÇConnectWise ScreenConnectÖеÄõè¾¶±éÀú·ì϶ £¬£¬£¬£¬£¬±àºÅCVE-2024-1708 £¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.4·Ö¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏì23.9.7¼°¸üÔç°æ±¾µÄScreenConnect £¬£¬£¬£¬£¬Ô´ÓÚÎļþõè¾¶Ï޶Ȳ»µ± £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄܽӼûÔ¤ÆÚÁìÓòÖ®±íµÄÎļþºÍĿ¼¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý´Û¸ÄÎļþõè¾¶ £¬£¬£¬£¬£¬¿É½Ó¼ûϵͳµÄÃô¸ÐÇøÓò £¬£¬£¬£¬£¬ÔÚijЩÇé¾°Ï¿ɵ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлòδ¾­ÊÚȨ½Ó¼û»úÃÜÊý¾ÝºÍ¹Ø¼ü×ÊÔ´¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ £¬£¬£¬£¬£¬¸Ã·ì϶³£ÓëÁíÒ»ÑϳÁÈÏÖ¤ÈÆ¹ý·ì϶CVE-2024-1709£¨CVSSÆÀ·Ö10.0£©¹²Í¬Ê¹Óᣡ£¡£¡£¡£µÚ¶þ¸ö·ì϶ÊÇWindows ShellºýŪ·ì϶ £¬£¬£¬£¬£¬±àºÅCVE-2026-32202 £¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ4.3·Ö¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ´ËǰÕë¶ÔCVE-2026-21510µÄ²»ÆëÈ«²¹¶¡¡£¡£¡£¡£¡£CVE-2026-21510Ô­ÊǶíÂÞ˹APT28ºÚ¿Í×éÖ¯×Ô2025Äê12ÔÂÆðÓÃÀ´¹¥»÷ÎÚ¿ËÀ¼ºÍÅ·Ã˹ú¶ÈµÄÁãÈÕ·ì϶ £¬£¬£¬£¬£¬ÓëMSHTML·ì϶CVE-2026-21513×é³ÉÀûÓÃÁ´¡£¡£¡£¡£¡£Î¢ÈíÓÚ4ÔÂ27ÈÕ¸üв¼¸æÈ·Èϸ÷ì϶Òѱ»»ý¼«ÀûÓà £¬£¬£¬£¬£¬½¨¸´ÁËÔçǰ°ä²¼µÄÃýÎóÀûÓÃÐÔÖ¸±ê¡£¡£¡£¡£¡£


https://securityaffairs.com/191442/security/u-s-cisa-adds-microsoft-windows-shell-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html


3. SAP¶à¸ö¹Ù·½npm°üÔ⹩¸øÁ´¹¥»÷


4ÔÂ29ÈÕ £¬£¬£¬£¬£¬TeamPCPÌáÒéÁËһ·¹©¸øÁ´¹¥»÷ £¬£¬£¬£¬£¬µ¼Ö¶à¸ö¹Ù·½SAP npm°üÔâµ½ÈëÇÖ £¬£¬£¬£¬£¬Ö÷ÕÅÊÇÇÔÈ¡¿ª·¢ÈËԱϵͳÖеÄÍ´´¦ºÍÉí·ÝÑéÖ¤ÁîÅÆ¡£¡£¡£¡£¡£°²È«×êÑÐÈËÔ±»ã±¨³Æ £¬£¬£¬£¬£¬Õâ´Î·ì϶ӰÏìÁËËĸöÈí¼þ°ü £¬£¬£¬£¬£¬Æä¶ñÒâ°æ±¾Ä¿Ç°ÒÑÔÚnpmÉϱ»ÆúÓãº@cap-js/sqlite v2.2.2¡¢@cap-js/postgres v2.2.2¡¢@cap-js/db-service v2.10.1ºÍmbt v1.2.48¡£¡£¡£¡£¡£ÕâЩÈí¼þ°üÖ§³ÖSAPµÄÔÆÀûÓ÷¨Ê½±à³ÌÄ£ÐͺÍÔÆMTA £¬£¬£¬£¬£¬Í¨³£ÓÃÓÚÆóÒµ¿ª·¢»·¾³¡£¡£¡£¡£¡£Æ¾¾ÝAikidoºÍSocketµÄ×îл㱨 £¬£¬£¬£¬£¬±»ÈëÇÖµÄÈí¼þ°üÒѱ»Åú¸Ä £¬£¬£¬£¬£¬Ô̺¬Ò»¸ö¶ñÒâµÄ¡°Ô¤×°Ö᱾籾 £¬£¬£¬£¬£¬¸Ã¾ç±¾ÔÚ×°ÖÃnpm°üʱ»á×Ô¶¯Ö´ÐÓ×£¡£¡£¡£¡£¸Ã¾ç±¾Æô¶¯Ò»¸öÃûΪsetup.mjsµÄ¼ÓÔØÆ÷ £¬£¬£¬£¬£¬´ÓGitHubÏÂÔØBun JavaScriptÔËÐÐʱ £¬£¬£¬£¬£¬²¢Ê¹ÓÃËüÀ´Ö´Ðо­¹ý¸ß¶È»ìºÏµÄexecution.jsÔØºÉ¡£¡£¡£¡£¡£¸ÃÔØºÉÊÇÒ»ÖÖÐÅÏ¢ÇÔÈ¡·¨Ê½ £¬£¬£¬£¬£¬ÓÃÓÚ´Ó¿ª·¢ÈËÔ±»úеºÍCI/CD»·¾³ÖÐÇÔÈ¡¸÷ÀàÍ´´¦ £¬£¬£¬£¬£¬Ô̺¬npmºÍGitHubÉí·ÝÑéÖ¤ÁîÅÆ¡¢SSHÃÜÔ¿¡¢¿ª·¢ÈËԱʹ´¦¡¢AWS/Azure/Google CloudµÄÔÆÆ¾Ö¤¡¢KubernetesÅäÖúÍÃÜÔ¿ £¬£¬£¬£¬£¬ÒÔ¼°CI/CDÁ÷Ë®ÏßÃÜÔ¿ºÍ»·¾³±äÁ¿¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/official-sap-npm-packages-compromised-to-steal-credentials/


4. Quick Page/Post Redirect²å¼þ²ØÎåÄêºóÃÅ


4ÔÂ29ÈÕ £¬£¬£¬£¬£¬ÎåÄêǰ £¬£¬£¬£¬£¬×°ÖÃÔÚ³¬¹ý70,000¸öWordPressÍøÕ¾ÉϵÄQuick Page/Post Redirect²å¼þ±»Ôö³¤ÁËÒ»¸öºóÃÅ £¬£¬£¬£¬£¬ÔÊÐíÏòÓû§ÍøÕ¾×¢ÈëËÁÒâ´úÂë¡£¡£¡£¡£¡£WordPressÖ÷»úÌṩÉÌAnchorµÄÊ×´´ÈËAustin Ginder·¢ÏÖÁ˸öñÒâÈí¼þ £¬£¬£¬£¬£¬´ËǰËûÍйܵķþÎñÆ÷ÉÏÓÐ12¸öÍøÕ¾Êܵ½Ï°È¾ £¬£¬£¬£¬£¬´¥·¢Á˰²È«¾¯±¨¡£¡£¡£¡£¡£Quick Page/Post RedirectÊÇÒ»¿îÓÃÓÚÔÚÎÄÕ¡¢Ò³ÃæºÍ×Ô½ç˵URLÖд´½¨³Á¶¨ÏòµÄ¸ù»ùʵÓòå¼þ £¬£¬£¬£¬£¬ÒÑÔÚWordPress.orgÉÏÌṩ¶àÄê¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬WordPress.orgÒÑÁÙʱ½«¸Ã²å¼þ´ÓĿ¼ÖÐÒÆ³ý £¬£¬£¬£¬£¬ÆÚ´ýÉó²é¡£¡£¡£¡£¡£Éв»Ã÷ÏÔÊDzå¼þ×÷Õß×ÔÐÐÖ²ÈëÁ˺óÃÅ £¬£¬£¬£¬£¬»¹ÊÇÆäÕË»§±»µÚÈý·½ÈëÇÖ¡£¡£¡£¡£¡£GinderÚ¹ÊÍ˵ £¬£¬£¬£¬£¬2020ÄêÖÁ2021Äê¼ä°ä²¼µÄ¹Ù·½²å¼þ°æ±¾5.2.1ºÍ5.2.2Ô̺¬Ò»¸öÖ¸ÏòµÚÈý·½ÓòÃûanadnet[.]comµÄ°µ²Ø×ÔÎÒ¸üлúÔì £¬£¬£¬£¬£¬¸Ã»úÔìÔÊÐí½«ËÁÒâ´úÂëÍÆË͵½WordPress.org½ÚÔìÁìÓòÖ®±í¡£¡£¡£¡£¡£2021Äê2Ô £¬£¬£¬£¬£¬¶ñÒâ×Ô¸üз¨Ê½´ÓWordPress.org²å¼þµÄºóÐø°æ±¾Öб»ÒƳý £¬£¬£¬£¬£¬´úÂëÉó²éÔ±»¹Ã»À´µÃ¼°×ÐϸÉó²éËü¡£¡£¡£¡£¡£¾ÝGinder³Æ £¬£¬£¬£¬£¬2021Äê3Ô £¬£¬£¬£¬£¬ÔËÐÐQuick Page/Post Redirect 5.2.1ºÍ5.2.2µÄÍøÕ¾ÍµÍµµØ´Ó¸Ã±í²¿·þÎñÆ÷½Ó¹Üµ½ÁËÒ»¸ö´Û»Ú¸ÄµÄ5.2.3°æ±¾ £¬£¬£¬£¬£¬¸Ã°æ±¾ÒýÈëÁËÒ»¸ö±»¶¯ºóÃÅ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/popular-wordpress-redirect-plugin-hid-dormant-backdoor-for-years/


5. ÇàÁúÃæ°åÆØÈÏÖ¤ÈÆ¹ý·ì϶ £¬£¬£¬£¬£¬¹¥»÷Õ߿ɲ¿Êð¼ÓÃÜ¿ó¹¤


4ÔÂ29ÈÕ £¬£¬£¬£¬£¬ºÚ¿ÍÔÚÀûÓÿªÔ´¹¤×÷µ÷¶È¹¤¾ßÇàÁúÃæ°åÖеÄÁ½¸öÈÏÖ¤ÈÆ¹ý·ì϶ £¬£¬£¬£¬£¬ÔÚ¿ª·¢Õß·þÎñÆ÷Éϲ¿Êð¼ÓÃܿ󹤡£¡£¡£¡£¡£Á½¸ö°²È«ÎÊÌâÓ°ÏìÇàÁúÃæ°å2.20.1¼°¸üÔç°æ±¾ £¬£¬£¬£¬£¬ÇÒÄܹ»´®ÁªÀûÓÃÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£CVE-2026-3965£ºÅäÖò»µ±µÄ³Áд¹æ¶¨½«/open/*ÒªÇóÓ³Éäµ½/api/* £¬£¬£¬£¬£¬ÎÞÒâÖÐͨ¹ýδ¾­Éí·ÝÑéÖ¤µÄõ辶¶³öÁËÊܱ£»£»£» £»£»£»£»¤µÄÖÎÀíÔ±¶Ëµã¡£¡£¡£¡£¡£CVE-2026-4047£ºÈÏÖ¤²é³­ÒÔ·Ö±æ´óÓ×д·½Ê½´¦ÖÃõè¾¶£¨/api/£© £¬£¬£¬£¬£¬¶øÂ·ÓÉÆ¥ÅäÔò²»·Ö´óÓ×д £¬£¬£¬£¬£¬ÕâÔÊÐí/aPi/...µÈÒªÇóÈÆ¹ýÈÏÖ¤²¢½Ó¼ûÊܱ£»£»£» £»£»£»£»¤µÄ¶Ëµã¡£¡£¡£¡£¡£Snyk»ã±¨³Æ £¬£¬£¬£¬£¬×Ô2ÔÂ7ÈÕÆð £¬£¬£¬£¬£¬¹¥»÷ÕßÒ»ÏòÔÚÕë¶Ô¹«¿ªÂ¶³öµÄÇàÁúÃæ°åÀûÓÃÕâÁ½¸ö·ì϶ÒÔ²¿Êð¼ÓÃܿ󹤡£¡£¡£¡£¡£¸Ã»î¶¯×î³õÓÉÇàÁúÓû§·¢ÏÖ £¬£¬£¬£¬£¬ËûÃǻ㱨³Æ´æÔÚÒ»¸öÃûΪ.fullgcµÄ¶ñÒâ°µ²Ø¹ý³Ì £¬£¬£¬£¬£¬Õ¼ÓÃÁË85%ÖÁ100%µÄCPU×ÊÔ´¡£¡£¡£¡£¡£¹¥»÷³ÖÐø½øÐÐ £¬£¬£¬£¬£¬ÔÚÔ̺¬NginxºÍSSL·´Ïò´úÀíºóµÄ¶àÖÖÅäÖû·¾³Öж¼È·ÈÏÁËϰȾ°¸Àý¡£¡£¡£¡£¡£¶øÇàÁúÊØ»¤ÕßÖ±µ½3ÔÂ1ÈղŶԴËÇé¿ö×÷³ö»ØÓ¦¡£¡£¡£¡£¡£½¨ÒéÈÔÔÚʹÓÃÒ×Êܹ¥»÷°æ±¾µÄÓû§Á¢¼´Éý¼¶µ½Òѽ¨¸´°æ±¾ £¬£¬£¬£¬£¬²¢²é³­·þÎñÆ÷ÖÐÊÇ·ñ´æÔÚ¿ÉÒɵÄ.fullgc¹ý³Ì¼°·ÇÊÚȨÅäÖõ÷»»¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/


6. ¿ç¹ú¼ÓÃÜÇ®±ÒÚ¿Æ­ÍŻ︲Ã𠣬£¬£¬£¬£¬È«ÇòËðʧ³¬5000ÍòÅ·Ôª


4ÔÂ29ÈÕ £¬£¬£¬£¬£¬°ÂµØÀûºÍ°¢¶û°ÍÄáÑǵ±¾Ö½üÈÕµ·»ÙÁËÒ»¸ö±»Ö¸¿ØÔËÓª´ó¹æÄ£¼ÓÃÜÇ®±ÒͶ×ÊÚ¿Æ­µÄ·¸×ïÍÅ»ï £¬£¬£¬£¬£¬¸ÃÍÅ»ï¸øÈ«ÇòÊܺ¦ÕßÔì³ÉµÄ¾­¼ÃËðʧ¹À¼Æ³¬¹ý5000ÍòÅ·Ôª£¨Ô¼ºÏ5850ÍòÃÀÔª£©¡£¡£¡£¡£¡£Õâ´Î½áºÏÐж¯Ê¼ÓÚ2023Äê6Ô £¬£¬£¬£¬£¬²¢µÃµ½ÁËÅ·ÖÞÐ̾¯×éÖ¯ºÍÅ·ÖÞ˾·¨×éÖ¯µÄÖ§³Ö £¬£¬£¬£¬£¬×îÖÕÓÚ4ÔÂ17ÈÕ¿ÛÁôÁË10ÃûÏÓÒÉÈË £¬£¬£¬£¬£¬²¢¶ÔÈý¸öºô½ÐÖÐÐĺ;Ŵ¦¸öÈËסËù½øÐÐÁËËѲ顣¡£¡£¡£¡£Ðж¯ÖÐ £¬£¬£¬£¬£¬·¨ÂÉÈËÔ±½É»ñÁË891,735Å·ÔªÏÖ½ð¡¢443̨µçÄÔ¡¢238²¿ÊÖ»ú¡¢6̨±Ê¼Ç±¾µçÄÔÒÔ¼°¶àÖÖÊý¾Ý´æ´¢É豸ÒÔ¹©È¡Ö¤²é³­¡£¡£¡£¡£¡£¸ÃÚ¿Æ­ÍÅ»ïѡȡÀàËÆºÏ·¨ÆóÒµµÄģʽÔËÓª £¬£¬£¬£¬£¬¹ÍÓ¶¶à´ï450ÃûÔ±¹¤ £¬£¬£¬£¬£¬·ÖÊô¿Í»§»ñÈ¡¡¢¿Í»§Î¬Ïµ¡¢²ÆÕþ¡¢ITºÍÈËÁ¦×ÊÔ´µÈ²¿ÃÅ¡£¡£¡£¡£¡£Êܺ¦Õßͨ¹ýËÑË÷ÒýÇæºÍÉ罻ýÌåÉϵĸæ°×±»ÓÕÆ­ÖÁÐéαµÄ¼ÓÃÜÇ®±ÒͶ×ÊÆ½Ì¨ £¬£¬£¬£¬£¬Ëæºó±»·ÖÅ䏸ËùνµÄ¡°¿Í»§Î¬Ïµ×¨Ô±¡± £¬£¬£¬£¬£¬ÕâЩרԱÖÎÀíÊܺ¦ÕßµÄͶ×ÊÕË»§ £¬£¬£¬£¬£¬³£Ê¹ÓÃÔ¶³Ì½Ó¼ûÈí¼þ½ÚÔìÊܺ¦ÕßÉ豸 £¬£¬£¬£¬£¬²¢Í¨¹ýÉúÀíʩѹÓÕÆ­Êܺ¦Õß×·¼Ó´æ¿î¡£¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬Êܺ¦ÕßµÄ×ʽð´ÓÎ´ÕæÕý±»Í¶×Ê £¬£¬£¬£¬£¬¶øÊDZ»×ªÈëÒ»¸ö¹ú¼ÊÏ´Ç®´òËã £¬£¬£¬£¬£¬×îÖÕÁ÷Èë·¸×ïÍøÂçµÄÕË»§¡£¡£¡£¡£¡£ÔÚ¶þ´ÎÚ¿Æ­ÖÐ £¬£¬£¬£¬£¬·¸×ï·Ö×ÓÔÙ´ÎÁªÏµÊܺ¦Õß £¬£¬£¬£¬£¬Ðû³Æ¿ÉÔ®ÊÖ×·»ØËðʧ £¬£¬£¬£¬£¬µ«ÒªÇóÏÈÏò¼ÓÃÜÇ®±ÒÕË»§´æÈë500Å·Ôª×÷ΪÈ볡·Ñ £¬£¬£¬£¬£¬´Ó¶ø¶ÔÊܺ¦ÕßÖ´Ðжþ´Îڲƭ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/