¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.3.29-4.4£©
2021-04-07
Ò»¡¢ Íþвͨ¸æ
GitLab¶à¸ö¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2021-04-02 15:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê4ÔÂ1ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½GitLab¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ÐÞ¸´Á˱£´æÓÚÉçÇø°æ(CE)ºÍÆóÒµ°æ(EE)ÖеĶà¸ö¸ßΣÎó²î¡£Project ImportÎļþ¶ÁÈ¡Îó²î£º´Ó13.9×îÏȵÄGitLab°æ±¾£¬¹¥»÷Õß¿ÉÒÔͨ¹ýµ¼ÈëÌØ¶¨µÄÎļþ¶ÁÈ¡·þÎñÆ÷ÉϵÄí§ÒâÎļþ¡£Wiki pageÎļþ¶ÁÈ¡Îó²î£º¹¥»÷Õßͨ¹ýÌØÖÆµÄ Wiki Ò³ÃæÔÚ·þÎñÆ÷É϶ÁÈ¡í§ÒâÎļþ¡£Îļþ¶ÁÈ¡Îó²î£º´Ó12.6×îÏȵÄGitLab°æ±¾£¬¹¥»÷Õß¿ÉÒÔÓÃÄäÃûÓû§µÄÉí·Ýͨ¹ý¹«¹²ÏîÄ¿fork»á¼ûÄÚ²¿´æ´¢¿âµÄÊý¾Ý¡£Îļþɾ³ýÎó²î£º´Ó13.8×îÏȵÄGitLab°æ±¾£¬¾ÓÉÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔɾ³ý¹«¹²ÏîÄ¿µÄͼÏñ¡£¿çÕ¾¾ç±¾¹¥»÷Îó²î£º´Ó13.4×îÏȵÄGitLab°æ±¾£¬¹¥»÷Õßͨ¹ýÖÆ×÷ÌØ¶¨µÄ·ÖÖ§Ãû³ÆÔںϲ¢ÇëÇóÖд¥·¢¿çÕ¾¾ç±¾¹¥»÷¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. 2020ÄêÈ«ÇòÊý¾Ýй¶Áè¼ÝÈ¥15Äê×ܺÍ
¡¾¸ÅÊö¡¿
CanalysµÄ×îб¨¸æ³Æ£¬2020ÄêÊý¾Ýй¶Σ»úÉý¼¶£¬Ôڶ̶Ì12¸öÔÂÖÐй¶µÄ¼Í¼±ÈÒÑÍù15ÄêµÄ×ܺͻ¹¶à¡£Í¬Ê±ÀÕË÷Èí¼þ¹¥»÷¼¤Ôö£¬Óë2019ÄêÏà±ÈÔöÌí60%¡£ÕâÖÖØ¨¹ÅδÓеĹ¥»÷Èȳ±¿É²¿·Ö¹éÒòÓÚйÚÒßÇéÓ°Ïì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://canalys.com/newsroom/cybersecurity-investment-2020
2. ºÚ¿ÍÉù³ÆÇÔÈ¡ÁË8.2TBµÄMobiKwikÊý¾Ý
¡¾¸ÅÊö¡¿
Ó¡¶ÈÖ§¸¶Ó¦ÓóÌÐò¹«Ë¾MobiKwikÒòÕÚÑÚй¶Á˽ü8.2TBÊý¾Ý¶øÊܵ½Æ·ÆÀ£¬ÆäÖаüÀ¨Ãô¸Ð¼Í¼£¬ÀýÈçKYCÏêϸÐÅÏ¢¡¢µç»°ºÅÂë¡¢µØµã¡¢Adhaar¿¨ºÍÆäËûÃô¸ÐÊý¾Ý¡£ÕâЩÊý¾ÝÒѱ»·ÅÔÚ°µÍøÉÏÒÔ1.5±ÈÌØ±ÒµÄ¼ÛÇ®³öÊÛ£¬Ô¼86000ÃÀÔª¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/hacker-steal-mobikwik-data-leaks-online/
3. WordPressËÑË÷²å¼þÖÐXSSÎó²îÓ°Ïì6Íò¶à¸öÕ¾µã
¡¾¸ÅÊö¡¿
2021Äê3ÔÂ28ÈÕ£¬Çå¾²Ñо¿Ö°Ô±Åû¶ÁËIvory SearchÖеÄÒ»¸öÎó²î£¬Ivory SearchÊÇÒ»¸ö×°ÖÃÔÚ60,000¶à¸öÕ¾µãÉϵÄWordPressËÑË÷²å¼þ¡£¹¥»÷Õß¿ÉÒÔʹÓôËÇå¾²Îó²îÔÚÊܺ¦ÕßµÄÍøÕ¾ÉÏÖ´ÐжñÒâ²Ù×÷£¬¸ÃÎó²îÊÇXSSÎó²î£¬Ó°ÏìIvory Search²å¼þ°æ±¾4.6.0¼°¸üµÍ°æ±¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/116140/hacking/reflected-xss-ivory-search-wp-plugin.html
4. ¡¶Öǻ۶¼»á°×ƤÊ飨2021Ä꣩¡·Ðû²¼
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Óɹú¼Ò¹¤ÒµÐÅÏ¢Çå¾²Éú³¤Ñо¿ÖÐÐÄ¡¢åÚÏ뼯ÍÅ¡¢Öйú¹¤Òµ»¥ÁªÍøÉú³¤Í¬ÃË¡¢¹¤Òµ´óÊý¾ÝÆÊÎöÓ뼯³ÉÓ¦ÓÃʵÑéÊÒÅäºÏÌåÀýµÄ¡¶ÒÀÍÐÖǻ۷þÎñ£¬¹²Á¢ÒìÐÍÖǻ۶¼»á——Öǻ۶¼»á°×ƤÊ飨2021Ä꣩¡·£¨ÒÔϼò³Æ“°×ƤÊ锣©ÕýʽÐû²¼¡£¸Ã°×ƤÊé½ÓÄɰ¸ÀýÆÊÎö¡¢ÊµÖ¤ÆÊÎö¡¢µ÷ÑÐÆÊÎöµÈÑо¿ÒªÁ죬ÉîÈëÆÊÎöÎÒ¹úÖǻ۶¼»áÉú³¤Àú³ÌÓëÄÚÔÚ¼ÍÂÉ£¬Õë¶ÔÖǻ۶¼»áÄ¿½ñµÄÉú³¤ÇéÐΣ¬Ìá³öһϵÁÐÖǻ۶¼»á½¨ÉèµÄÐÂÀíÄмܹ¹¡¢Ð½¨Ò飬ּÔÚΪ½¨ÉèÓ¦ÓÃÊÖÒÕÏȽø¡¢Éç»áÐ§ÒæÓÅÒì¡¢Éú̬ÇéÐÎÓѺõÄÐÂÐÍÖǻ۶¼»áÌṩ²Î¿¼¡£
¡¾²Î¿¼Á´½Ó¡¿
https://mp.weixin.qq.com/s/BcRKpzbYGzd5JH-TPu6FxA?scene=25#wechat_redirect
5. Cl0pÀÕË÷Èí¼þ¼¯ÍÅй¶ÁËÃÀ¹úÁùËù´óѧµÄѧÉúÐÅÏ¢
¡¾¸ÅÊö¡¿
Cl0pÀÕË÷Èí¼þ×é֯й¶ÃÀ¹úÁùËù¶¥¼â´óѧµÄѧÉúÏêϸÐÅÏ¢£¬ÆäÖаüÀ¨ÔÚУѧÉúµÄÕÕÆ¬¡¢³öÉúÄêÔ¡¢¼Òͥסַ¡¢»¤ÕÕºÅÂë¡¢ÒÆÃñÉí·Ý¡¢Ð¡ÎÒ˽¼ÒÐÕÃûºÍÉç»áÇå¾²ºÅÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://seguranca-informatica.pt/cl0p-ransomware-group-compromised-and-leaked-data-from-6-us-universities-including-students-details/
6. ÖÆÔìÒµ³ÉΪºÚ¿ÍÍ·ºÅÄ¿µÄ
¡¾¸ÅÊö¡¿
ÍøÂçÇå¾²¹«Ë¾Ç÷ÊÆ¿Æ¼¼×îÐÂÐû²¼µÄ±¨¸æ³Æ£¬ÖÆÔìÒµÆóÒµÒѾ³ÉÎªÍøÂç·¸·¨·Ö×Ó¡¢ÀÕË÷Èí¼þºÍ¹ú¼ÒºÚ¿ÍµÄÖ÷ҪĿµÄ£¬ 61£¥µÄÆóÒµ¹¤³§±¬·¢¹ýÍøÂçÇå¾²ÊÂÎñ£¬ÆäÖÐËÄ·ÖÖ®Èýµ¼ÖÂÉú²úÏßÏÂÍ£°Ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://resources.trendmicro.com/Industrial-Cybersecurity-WP.html
7. 2020ÄêÎÞÎļþ¶ñÒâÈí¼þÊýÄ¿ìÉý900%
¡¾¸ÅÊö¡¿
ƾ֤Watchguard TechnologiesµÄ×îÐÂÊý¾Ý£¬ÓÉÓÚ¹¥»÷ÕßÒ»Ö±Ìá¸ßÒþ²ØÐÔÈÆ¹ý¹Å°åÇå¾²¿ØÖÆ£¬2020Ä꣬ÎÞÎļþ¶ñÒâÈí¼þµÄ¼ìÕÉÁ¿Í¬±ÈÔöÌíÁ˽ü900£¥¡£ÓÉÓÚ¹¥»÷ÕßÊÔͼͨ¹ýÔÚ²»×°ÖöñÒâ´úÂëµÄÇéÐÎϾÙÐй¥»÷£¬´Ó¶øÊÔͼÌÓ±ÜÐí¶à¶Ëµã±£»¤²úÆ·µÄ¼àÊÓ£¬Òò´ËÎÞÎļþ¶ñÒâÈí¼þ±ÈÂÊÔÚÒÑÍùÒ»ÄêÖÐѸÃÍÔöÌí¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.watchguard.com/wgrd-resource-center/security-report-q4-2020
8. Õë¶ÔÊÓÆµÓÎÏ·Íæ¼ÒºÍPC¸Ä×°ÕߵĹ¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
½üÆÚ¹¥»÷ÕßʹÓÃÓÎÏ·ÖкóÃÅרÃÅÕë¶ÔÓÎÏ·Íæ¼ÒºÍPC¸Ä×°Õߣ¬ÕâЩÓÎÏ·µ÷½âÒþ²ØÁËÄܹ»Í¨¹ý»ñÈ¡Âó¿Ë·çºÍÍøÂçÉãÏñÍ·»á¼ûȨ¶ø´ÓÆäϵͳÖÐÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þXtremeRAT£¬¸Ã¶ñÒâÈí¼þÊÇÒ»ÖÖÉÌÒµ¿ÉÓõÄÔ¶³Ì»á¼ûľÂí¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/gamers-malware-attack-games-cheat-codes/
9. Boggi Milano´ò°ç¹«Ë¾ÔâÊÜRagnarokÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
Boggi Milano´ò°ç¹«Ë¾ÔâÊÜRagnarokÀÕË÷Èí¼þ¹¥»÷£¬´Ë´Î¹¥»÷Ô˶¯ÇÔÈ¡ÁË40 GBµÄÃô¸ÐÊý¾Ý£¬ÆäÖаüÀ¨ÈËΪµ¥Îļþ¡¢¸¶¿îPDF¡¢Æ¾Ö¤¡¢Ë°ÎñÎļþµÈ¡£Boggi MilanoµÄ×ܲ¿Î»ÓÚÒâ´óÀû£¬¾Ý¸Ã¹«Ë¾³Æ£¬ÔÚÈ«Çò38¸öÒÔÉϵĹú¼Ò/µØÇøÓµÓÐ190¼ÒÊÐËÁ£¬ÎªÄÐÊ¿Ìṩ¸ß¶ËʱÉÐ×°°ç¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/ragnarok-ransomware-boggi-milano-menswear/165161/
10. HadesÀÕË÷Èí¼þÃé×¼Èý¼ÒÃÀ¹ú¹«Ë¾µÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
½üÆÚδ֪µÄÍþв×éÖ¯ÕýÔÚ°²ÅÅHadesÀÕË÷Èí¼þÕë¶ÔÃÀ¹úÔËÊä¡¢ÏûºÄÆ·ºÍÖÆÔìÒµµÄÈý¼Ò¹«Ë¾¾ÙÐÐÍøÂç¹¥»÷Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/hades-ransomware-targets-3-us-companies-a-16268

AG¹«Ë¾ÔÆ







