Click StudiosÔ⹩ӦÁ´¹¥»÷£¬²úÎï¸üзþÎñÆ÷±»½Ù³Ö£»HashiCorpÔâCodecov¹©Ó¦Á´¹¥»÷£¬GPGÇ©ÃûÃÜԿй¶

Ðû²¼Ê±¼ä 2021-04-25

1.Click StudiosÔ⹩ӦÁ´¹¥»÷£¬²úÎï¸üзþÎñÆ÷±»½Ù³Ö


1.jpg


Click Studios֪ͨ¿Í»§ÆäÔâµ½Á˹©Ó¦Á´¹¥»÷£¬ÆäPasswordstateµÄ¸üзþÎñÆ÷±»½Ù³Ö ¡£PasswordstateÊÇÒ»ÖÖµ±µØÃÜÂë¹ÜÀí½â¾ö·½°¸£¬Òѱ»È«Çò29000¼Ò¹«Ë¾µÄ370000¶àÃûÄþ¾²ºÍITÈËԱʹÓã¬Éæ¼°Õþ¸®¡¢¹ú·À¡¢½ðÈÚ¡¢º½¿Õº½Ìì¡¢Ò½ÁƱ£½¡¡¢Ö´·¨ºÍýÌåµÈÐÐÒµ ¡£¸Ã¹«Ë¾³Æ£¬ºÚ¿ÍÔÚPasswordstateµÄԭʼ´úÂëÖÐÔö¼ÓÁËÒ»¶ÎÖ¼ÔÚ´ÓC2ÖÐÏÂÔØpayloadµÄ'Loader'´úÂ룬Òò´ËÆä¿Í»§¿ÉÄÜÔÚ4ÔÂ20ÈÕÖÁ4ÔÂ22ÈÕÖ®¼äÏÂÔØÁËÒѱ»¸Ä¶¯µÄÉý¼¶·¨Ê½ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/passwordstate-password-manager-hacked-in-supply-chain-attack/


2.HashiCorpÔâCodecov¹©Ó¦Á´¹¥»÷£¬GPGÇ©ÃûÃÜԿй¶


2.jpg


¿ªÔ´Èí¼þ¹¤¾ßºÍ»ù´¡ÉèÊ©ÌṩÉÌHashiCorpÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬GPGÇ©ÃûÃÜԿй¶ ¡£¾ÝÊӲ죬´Ë´Î¹©Ó¦Á´¹¥»÷×î³õΣº¦·¢ÉúÔÚ1ÔÂ31ÈÕ£¬²¢Á¬ÐøÁËԼĪÁ½¸öÔ£¬HashiCorpÓÃÓÚÇ©ÃûÀ´ÑéÖ¤HashiCorpµÄ²úÎïµÄGPG˽Կ±ãÊÇÔÚÕâ¶Îʱ¼äй¶µÄ ¡£¸Ã¹«Ë¾³Æ£¬Ä¿Ç°ÉÐδÓÐÖ¤¾Ý±íÃ÷ÓÐÈËʹÓÃÁ˸ÃÃÜÔ¿£¬µ«ÔÚÄþ¾²Æð¼ûÈÔ¶ÔÆä½øÐÐÁ˸ü»»£¬ÏÖÒÑÐû²¼ÐµÄGPGÃÜÔ¿¶Ô£ºC874 011F 0AB4 0511 0D02 1055 3436 5D94 72D7 468F ¡£µ«ÊÇ£¬ÆäTerraform²úÎïÉÐδ´ò²¹¶¡À´Ê¹ÓÃеÄGPGÃÜÔ¿ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hashicorp-is-the-latest-victim-of-codecov-supply-chain-attack/


3.°¢¸ùÍ¢µÄ¹È¸èËÑË÷ÒýÇæÒòÓòÃû±»ÒâÍâ³öÊÛ¶øÌ±»¾ÊýСʱ


3.jpg


ÉÏÖÜÈý£¬°¢¸ùÍ¢µÄ¹È¸èËÑË÷ÒýÇæÌ±»¾Á˽üÈý¸öСʱ ¡£Æ¾¾ÝMercoPressµÄ×ÊÁÏÏÔʾ£¬´Ë´ÎÖжϵÄÔ­ÒòÊÇÒ»¸öÃûΪNicolas DavidKuro?aµÄ°¢¸ùÍ¢¹«ÃñÒÔ540°¢¸ùÍ¢±ÈË÷£¨Ô¼ºÏ5.81ÃÀÔª£©µÄ¼Û¸ñ¹ºÖÃÁËgoogle.com.arÓòÃûµÄËùÓÐȨ ¡£Kuro?aÔÚµ±ÈÕÍíÉÏ10:45×óÓÒÐû²¼ÍÆÎÄÌåÏÖ£¬ËûÊǺϷ¨µÄ¹ºÖÃÁ˸ÃÓòÃû ¡£Õâ¸öÓòÃûÖ®ËùÒÔ¿ÉÒÔʹÓã¬ÊÇÒòΪ¹È¸è°¢¸ùÍ¢¹«Ë¾Ã»ÓÐÔÚµ½ÆÚºóÐøÆÚ£¬Ê¹µÃÓû§¿ÉÒԺϷ¨ÇÀ×¢ ¡£µ«ÊǸÃÓòµÄ¹ýÆÚÈÕÆÚÊÇ7Ô£¬Ä¿Ç°ÉÐδ¹ýÆÚ£¬Òò´Ë¸Ã¹«ÃñÈçºÎºÏ·¨µÄ¹ºÖÃËü³ÉΪÁËÒ»¸öÃÕ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/google-argentina-domain-bought/


4.ÐÂLinux½©Ê¬ÍøÂçʹÓÃIaCºÍDevOpsµÈ¹¤¾ßÍÚ¾òÃÅÂÞ±Ò


4.jpg


Ç÷ÊÆ¿Æ¼¼µÄÑо¿ÈËÔ±·¢ÏÖÁËÒ»¸öеÄLinux½©Ê¬ÍøÂ磬ʹÓÃÁË»ù´¡¼Ü¹¹´úÂ루IaC£©¹¤¾ß¡¢TorÊðÀíºÍºÏ·¨µÄDevOps¹¤¾ßÀ´ÍÚ¾òXMRig Monero ¡£¸ÃLinux½©Ê¬ÍøÂç´ÓTorÍøÂçÏÂÔØËüËùÐèµÄËùÓÐÎļþ£¬°üÂÞss¡¢psºÍcurlµÈºÏ·¨µÄ¶þ½øÖÆÎļþ£¬»¹Ê¹ÓÃÁËShell½Å±¾ºÍUnixϵͳÉè¼ÆÖ´ÐÐHTTPÇëÇó£¬ÒÔ»ñÈ¡ÓйØÊÜѬȾϵͳµÄ¸ü¶àÐÅÏ¢ ¡£´ËÍ⣬Ñо¿ÈËÔ±³ÆÕâÊǵÚÒ»¸öÀûÓÃÁË»ù´¡¼Ü¹¹´úÂ루IaC£©¹¤¾ß£¬ÖîÈçAnsible¡¢ChefºÍSalt Stack½øÐÐÁ÷´«µÄ½©Ê¬ÍøÂç ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117155/malware/linux-botnet-emerging-techniques.html


5.еöÓã»î¶¯Î±×°³ÉÁÔÍ·¹«Ë¾Michael Page·Ö·¢Ursnif


5.jpg


ÐÂÒ»ÂÖµöÓã»î¶¯Î±×°³ÉÖ°Òµ½éÉÜËùMichael Page·Ö·¢Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þUrsnif ¡£Michael PageµÄÒµÎñ±é¼°ÃÀÖÞ¡¢Ó¢¹ú¡¢Å·Ö޴󽡢ÑÇÌ«µØÓòºÍ·ÇÖÞ£¬ÊÇÓ¢¹úµÄPageGroupµÄ×Ó¹«Ë¾ ¡£PageGroup³Æ£¬ÆäITϵͳ²¢Î´Ôâµ½¹¥»÷£¬ÕâЩµöÓãÓʼþÊÇÀûÓùûÈ»ÐÅÏ¢Éú³ÉµÄÈ»ºóËæ»ú·¢Ë͸øÄ¿±êµÄ ¡£ÕâЩÓʼþÀûÓÃǶÈëʽÁ´½Ó½«Êܺ¦ÕßÖØ¶¨Ïòµ½¾ßÓÐGeoIPºÍ·´»úÆ÷È˼ì²é¹¦Ð§µÄµöÓãÒ³Ãæ£¬È»ºó£¬ÒªÇóÆäÏÂÔØÆôÓÃÁ˺êµÄXSLMÎļþ²¢¾ßÓÐDocuSign±êÖ¾µÄÎĵµ£¬×îºóÏÂÔØUrsnif ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phishing-impersonates-global-recruitment-firm-to-push-malware/


6.Ñо¿ÈËÔ±Åû¶Homebrew Cask´æ´¢¿âÖеĴúÂëÖ´ÐЩ¶´


6.jpg


ÈÕ±¾Äþ¾²Ñо¿ÈËÔ±RyotaKÓÚ4ÔÂ18ÈÕÅû¶Homebrew Cask´æ´¢¿âÖдæÔÚ´úÂëÖ´ÐЩ¶´ ¡£HomebrewÊÇÒ»¸ö¿ªÔ´Èí¼þ±£Ö¤ÀíÆ÷½â¾ö·½°¸£¬¿ÉÔÚAppleµÄmacOS²Ù×÷ϵͳºÍLinuxÉϰ²×°Èí¼þ ¡£¸Ã©¶´ÊÇÓÉÓÚreview- cask -pr GitHub ActionµÄgit_diffÖÐÓÃÓÚ½âÎöpullÇëÇóµÄdiffÒÀÀµÏî´æÔÚȱÏÝ£¬Òò´Ë½âÎöÆ÷¿ÉÄܻᱻÆÛÆ­¶øÅú×¼¶ñÒâµÄpullÇëÇ󣬿ɱ»ÓÃÀ´½«ÈÎÒâ´úÂë×¢Èëµ½ÈÝÆ÷ÖÐ ¡£Ä¿Ç°£¬¸Ã©¶´ÒÑÓÚ4ÔÂ19ÈÕ±»ÐÞ¸´ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/04/critical-rce-bug-found-in-homebrew.html