ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷£»CodecovʹÓÃÐÂuploaderÌæ»»½üÆÚ¹¥»÷ÖеÄBash½Å±¾
Ðû²¼Ê±¼ä 2021-06-151.ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâREvilÀÕË÷Èí¼þ¹¥»÷
ÃÀ¹úºËÎäÆ÷³Ð°üÉÌSol OriensÔâµ½ÁËREvilÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹«Ë¾³ÆÆäÖ÷ÒªÐÖú¹ú·À²¿¡¢ÄÜÔ´²¿¡¢º½¿Õº½Ìì³Ð°üÉ̺ͼ¼Êõ¹«Ë¾¿ªÕ¹ÅÓ´óµÄÏîÄ¿¡£REvilÍÅ»ïÕýÔÚÅÄÂô¹¥»÷ÆÚ¼äÇÔÈ¡µÄÊý¾Ý£¬ÆäÖаüÂÞÒµÎñÊý¾ÝºÍÔ±¹¤ÐÅÏ¢£¬ÀýÈçÔ±¹¤Éç»áÄþ¾²ºÅÂë¡¢ÕÐÆ¸¸ÅÀÀÎļþ¡¢ÈËΪµ¥ÎļþºÍÈËΪ³ÂËߵȡ£Sols OriensҲ֤ʵÁËÆäÔÚ2021Äê5ÔÂÔâµ½ÁËÍøÂç¹¥»÷£¬¿ÉÄÜÒѾй¶²¿ÃÅÊý¾Ý£¬Ä¿Ç°ÊÓ²ìÈÔÔÚ½øÐÐÖС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-us-nuclear-weapons-contractor/
2.CodecovʹÓÃÐÂuploaderÌæ»»½üÆÚ¹¥»÷ÖеÄBash½Å±¾
CodecovʹÓÃÁËÒ»¸öеÄuploaderÀ´Ìæ»»½üÆÚ¹¥»÷ÖеÄBash½Å±¾¡£¸Ãuploade½«×÷Ϊһ¸ö¾²Ì¬¶þ½øÖÆ¿ÉÖ´ÐÐÎļþÐû²¼£¬ÊÊÓÃÓÚWindows¡¢Linux¡¢Alpine LinuxºÍmacOS£¬Ä¿Ç°»¹´¦ÓÚ²âÊԽ׶Σ¬ÓëÏÖÓеÄBashʹÓÃÏàͬµÄ·½Ê½ÔÚ¿ª·¢ÖÜÆÚÖÐÍÆËÍÁýÕÖÊý¾ÝºÍ¸üС£´ËÂÖ¹¥»÷·¢ÉúÔÚ2021Äê1ÔÂ31ÈÕ×óÓÒ£¬²¢ÓÚ4ÔÂ15ÈÕ±»Åû¶¡£Ä¿Ç°£¬Êý°Ù¸ö×éÖ¯ÒѾíÈë¸Ãʼþ£¬°üÂÞRapid7¡¢Monday.comºÍMercariµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/codecov-debuts-new-uploader-dismisses-bash-script-as-source-of-supply-chain-attack-risk/
3.¹ú¼ÊÐ̾¯µÄPangea XIVÐж¯É¾³ýÁè¼Ý11Íò¸öµöÓãÁ´½Ó
¹ú¼ÊÐ̾¯×éÖ¯£¨The Interpol£©µÄPangea XIVÐж¯É¾³ýÁè¼Ý11Íò¸öµöÓãÁ´½Ó¡£´Ë´ÎÖ´·¨»î¶¯Ö÷ÒªÊÇÕë¶Ô¼ÙðºÍ·Ç·¨µÄÒ©Æ·ºÍÒ½ÁÆÉ豸µÄÔÚÏßÂô¼Ò¡£Ä¿Ç°£¬ÔÚ¹ú¼ÊÐ̾¯×éÖ¯µÄе÷Ï£¬92¸ö¹ú¼ÒµÄÖ´·¨»ú¹¹¡¢º£¹ØºÍÎÀÉú¼à¹Ü»ú¹¹É¾³ýÁË113020¸öÍøÂçÁ´½Ó£¬ÆäÖаüÂÞ±»¹Ø±Õ»òɾ³ýµÄÍøÕ¾ºÍÔÚÏßÊг¡¡£½öÔÚÓ¢¹ú£¬¾Í²é»ñÁ˼ÛÖµÁè¼Ý1300ÍòÃÀÔªµÄ300¶àÍò¼þ¼ÙÒ©ºÍÉ豸£¬»¹É¾³ýÁË3100¶à¸ö·Ç·¨ÏúÊۺ͹©Ó¦ÎÞÅÆÒ©Æ·µÄ¹ã¸æÁ´½Ó£¬²¢±ÕÁË43¸öÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/interpol-shuts-down-thousands-of-fake-online-pharmacies/
4.Rapid7Ñо¿ÈËÔ±Åû¶Akkadianƽ̨ÖеĶà¸öÄþ¾²Â©¶´
Rapid7Ñо¿ÈËÔ±Åû¶Akkadian Provisioning ManagerÖеĶà¸öÄþ¾²Â©¶´¡£¸Ãƽ̨ÊÇ˼¿ÆÍ³Ò»Í¨ÐÅ£¨UC£©»·¾³ÖеĵÚÈý·½¹©Ó¦¹¤¾ß£¬Í¨³£ÓÃÓÚ´óÐÍÆóÒµ£¬Í¨¹ý×Ô¶¯»¯À´×ÊÖúÆä¹ÜÀíËùÓÐUC¿Í»§¶ËºÍʵÀýµÄÅäÖá£ÕâЩ©¶´·Ö±ðΪʹÓÃÓ²±àÂëÆ¾¾Ý£¨CVE-2021-31579£©¡¢ÃüÁî×¢Èë©¶´£¨CVE-2021-31580ºÍCVE-2021-31581£©ÒÔ¼°Ãô¸ÐÐÅϢй¶£¨CVE-2021-31582£©¡£Rapid7³Æ£¬ÕâЩ©¶´¿ÉÓÃÀ´Ô¶³ÌÖ´ÐдúÂ룬ĿǰÈÔδÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/unpatched-bugs-provisioning-cisco-uc/166882/
5.APWGÐû²¼2021ÄêQ1ÍøÂçµöÓã»î¶¯Ì¬ÊƵķÖÎö³ÂËß
APWGÐû²¼ÁË2021ÄêQ1ÍøÂçµöÓã»î¶¯Ì¬ÊƵķÖÎö³ÂËß¡£³ÂËßÏÔʾ£¬ÍøÂçµöÓãÍøÕ¾ÊýÁ¿ÔÚ2021Äê1Ôµ½´ï·åÖµ£¬´´ÏÂÁË245771¸öµÄÀúʷиߣ¬È»ºóÔÚ±¾¼¾¶ÈµÄºóÆÚ¿ªÊ¼Ï½µ¡£ÉÌÒµµç×ÓÓʼþ(BEC)թƵijɱ¾Ô½À´Ô½¸ß£¬´Ó2020ÄêQ3µÄ48000ÃÀÔªÔö¼Óµ½ÁË2021ÄêQ1µÄ85000ÃÀÔª¡£Õë¶Ô½ðÈÚ»ú¹¹µÄÍøÂçµöÓãÊÇQ1Õ¼±È×î´óµÄÀàÐÍ£¬Õ¼ËùÓй¥»÷µÄ24.9%¡£´ËÍ⣬Õë¶ÔÉ罻ýÌåÐÐÒµµÄÍøÂçµöÓãÔÚËùÓй¥»÷ÖÐËùÕ¼±ÈÀý´Ó2020ÄêQ4µÄ11.8%¼¤ÔöÖÁ23.6%¡£
ÔÎÄÁ´½Ó£º
https://www.prnewswire.com/news-releases/apwg-q1-2021-report-detected-phishing-websites-maintain-historic-high-in-q1-2021-after-doubling-in-2020-301309187.html
6.Cisco TalosÐû²¼2021ÄêQ1ʼþÏìÓ¦Ç÷ÊÆµÄ·ÖÎö³ÂËß
Cisco TalosÐû²¼ÁË2021ÄêQ1ʼþÏìÓ¦Ç÷ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬Õë¶ÔMicrosoft Exchange ServerÖм¸¸öÁãÈÕ©¶´µÄ¹¥»÷ÊÇÉϸö¼¾¶È×î´óµÄÍþв£¬Ô¼Õ¼ËùÓÐÊÓ²ìʼþµÄ35%¡£´ËÍ⣬¸Ã³ÂËß»¹½éÉÜÁËÔÚÏÈǰ´ÓδÓöµ½µÄ¼¸¸öÀÕË÷Èí¼þϵÁУ¬°üÂÞMountLocker¡¢ZeppelinºÍAvaddon¡£Ñо¿ÈËÔ±ÍÆ²â£¬Q4 DridexѬȾÂʽ«´Ó3Ôµ׿ªÊ¼Ïà¶ÔÉÏÉý£¬Õâ¿ÉÄÜÓë½ñÄêÔçЩʱºòÈ«ÇòÖ´·¨²¿ÃÅÁªºÏµ·»ÙEmotetÓйء£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/06/quarterly-report-incident-response.html