Ñо¿ÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»Monday.comÐû²¼Êܵ½Codecov¹©Ó¦Á´¹¥»÷µÄÓ°Ïì

Ðû²¼Ê±¼ä 2021-05-19

1.Ñо¿ÈËÔ±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ


1.jpg


¿¨°Í˹»ùÑо¿ÈËÔ±·¢ÏÖеİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£BizarroÊÇWindows¶ñÒâÈí¼þ£¬¾ßÓÐx64Ä£¿é£¬¿ÉÒÔÓÕÆ­Êܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬»¹ÀûÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆ­Êܺ¦ÕßÏÂÔØÒÆ¶¯Ó¦Ó÷¨Ê½¡£¸Ã¶ñÒâÈí¼þµÄµÄºËÐÄ×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÃüÁîµÄºóÃÅ£¬Ö»Óе±Æä¼ì²âµ½ÒѾ­Á¬½Óµ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬ºóÃŲŻáÆô¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html


2.FBI·¢ÏÖ½üÆÚð³äÃÀ¹úTruistÒøÐеĵöÓã¹¥»÷»î¶¯


2.jpg


FBI·¢ÏÖÐÂÒ»ÂÖµÄÓã²æÊ½µÄµöÓã¹¥»÷»î¶¯£¬Ã°³äÃÀ¹úµÚÁù´óÒøÐпعɹ«Ë¾Truist Bank¡£´Ë´Î»î¶¯Éù³ÆÐèÒªÍê³ÉÒ»±Ê6200ÍòÃÀÔª´û¿î£¬À´ÓÕʹÓû§ÏÂÔØÒ»¸öð³äÁ˺Ϸ¨µÄTruism Financial SecureBank AppµÄWindowsÓ¦Ó÷¨Ê½¡£ÎªÁËÌá¸ß¹¥»÷µÄÀÖ³ÉÂÊ£¬¹¥»÷Õß»¹Ê¹ÓÃÁËVirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÎ´¼ì²âµ½µÄ¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þ»áÔÚÓû§ÏÂÔØµöÓãÓʼþÖеĶñÒâ¿ÉÖ´ÐÐÎļþºó£¬±»°²×°µ½secureportal(.)onlineÓò¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-spots-spear-phishing-posing-as-truist-bank-bank-to-deliver-malware/


3.Monday.comÐû²¼Êܵ½Codecov¹©Ó¦Á´¹¥»÷µÄÓ°Ïì


3.jpg


Monday.com×î½üÅû¶ÆäÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬Ó°ÏìÁ˶à¼Ò¹«Ë¾¡£Monday.comÊÇÒ»¸öÔÚÏßÊÂÇéÁ÷¹ÜÀíÆ½Ì¨£¬¸Ãƽ̨µÄ¿Í»§°üÂÞUber¡¢BBC Studios¡¢Adobe¡¢Universal¡¢Hulu¡¢L'Oreal¡¢¿É¿Ú¿ÉÀÖºÍÁªºÏÀû»ªµÈÖªÃû¹«Ë¾¡£Monday.com·¢ÏÖÔڴ˴ι¥»÷ÖкڿÍÇÔÈ¡ÁËÆäÔ´´úÂëµÄÖ»¶Á¸±±¾£¬²¢Î´¶ÔÆä½øÐи͝¡£´ËÍ⣬»¹Ð¹Â¶ÁËÍйÜÔÚ¸ÃÆ½Ì¨ÉϵĿͻ§±íµ¥ºÍÊÓͼ¡£×÷Ϊ»º½â´ëÊ©£¬¸Ãƽֹ̨ͣʹÓÃCodecovµÄ·þÎñ²¢¸ü»»ÁËËùÓÐÉú²úºÍ¿ª·¢»·¾³µÄÃÜÔ¿¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/codecov-hackers-gained-access-to-mondaycom-source-code/


4.ÃÀ¹úUtility³ÆÆäѬȾClop£¬Ô±¹¤µÄ¸öÈËÐÅϢй¶


4.jpg


Utility Trailer Manufacturing³ÆÆäѬȾÁËÀÕË÷Èí¼þClop£¬²¿ÃÅϵͳÔÝʱÖжÏ¡£¸Ã¹«Ë¾Î»ÓÚ¼ÓÀû¸£ÄáÑÇ£¬ÊÇÃÀ¹ú×î´óµÄÍϳµÉú²úÉÌÖ®Ò»¡£ClopÍÅ»ïÓÚÉÏÖÜÔÚ°µÍø¹ûÈ»Á˴Ӹù«Ë¾ÇÔÈ¡µÄ5 GBÊý¾Ý£¬°üÂÞÈËΪµ¥ºÍÈËÁ¦×ÊÔ´ÐÅÏ¢µÈÔ±¹¤µÄÃô¸ÐÊý¾Ý¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÉÐδ¹ûÈ»¹¥»÷µÄ·¶Î§ÒÔ¼°Êý¾Ýй¶µÄˮƽ¡£ClopÔø¹¥»÷Á˶à¼Ò´óÐ͹«Ë¾£¬°üÂÞÌú·ÔËÓªÉÌCSXºÍ¼ÓÄôóȼÁϹ«Ë¾ParklandµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.freightwaves.com/news/trailer-maker-utility-targeted-in-ransomware-attack


5.ESET·¢ÏÖ¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö


5.jpg


ESETÑо¿ÈËÔ±·¢ÏÖ£¬¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö¡£ÔÚ2019Ä꣬Android¸ú×ÙÈí¼þµÄÊýÁ¿¼¸ºõÊÇ2018ÄêµÄÎå±¶£¬¶øµ½ÁË2020Ä꣬´ËÀà¶ñÒâÈí¼þÊýÁ¿±È2019ÄêÔö¼ÓÁË48£¥¡£¶ÔÓÚ´ËÀàÓ¦ÓõũӦÉÌÀ´Ëµ£¬ÎªÁËÖÆÖ¹±»±ê־Ϊ¸ú×ÙÈí¼þ£¬Í¨³£½«ÆäÐû´«ÎªÎª¶ùͯ¡¢Ô±¹¤»òÅ®ÐÔÌṩ±£»¤¡£Ñо¿ÈËÔ±·ÖÎöÁËÀ´×Ô86¸ö²îÒ칩ӦÉ̵ÄAndroid¸ú×ÙÓ¦Óã¬×ܹ²·¢ÏÖÁË158¸öÄþ¾²ÎÊÌ⣬ÀýÈçÓû§ÐÅÏ¢´«Êä²»Äþ¾²(CWE-200)¡¢·þÎñÆ÷й¶¸ú×ÙÕßÐÅÏ¢(CWE-200)ºÍÃüÁî×¢Èë(cwe-926)µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/stalkerware-adoption-rates-surge-over-2020-hundreds-of-vulnerabilities-found/


6.NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö³ÂËß


6.jpg


NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬±È2020ÄêͬÆÚÔö¼ÓÁË31£¥£¬×î´óΪ480 Gbps£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£ÆäÖУ¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬ÔÚÏß·þÎñÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/asert/beat-goes