PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬´úÂë¿âÒѱ»¸Ä¶¯£»£» £»£»£»£»£»£»ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳öºóÓû½«Êê½ðÍË»¹¸øÊܺ¦Õß

Ðû²¼Ê±¼ä 2021-03-30

1.PHP¹Ù·½Git´æ´¢¿âÔâµ½¹©Ó¦Á´¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬´úÂë¿âÒѱ»¸Ä¶¯


1.jpg


ÉÏÖÜÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬Î¬»¤Ö°Ô±Rasmus Lerdorf·¢Ã÷ºÚ¿Í¹¥»÷ÁËЧÀÍÆ÷git.php.net£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¸ÃЧÀÍÆ÷µÄ×ÔÍйÜphp-src´æ´¢¿âÖÐÉÏ´«ÁË2¸öδ¾­ÊÚȨµÄ¸üаü£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖеÄÔ´´úÂë±»²åÈëÁËÉñÃØºóÃÅ´úÂë ¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâ´úÂëÊÇÒÔPHP½¨ÉèÕßRasmus LerdorfµÄÃûÒåÌá½»µÄ ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÍƲâ´Ë´ÎÊÇÃûΪÒÀÀµ»ìÏý£¨dependency confusion£©µÄÐÂÐ͹©Ó¦Á´¹¥»÷·½·¨£¬ £¬£¬£¬£¬£¬£¬£¬ËüʹÓÃÁËÒ»¸ö¿ÉÄܰüÀ¨À´×Ô˽Óк͹«¹²ÈªÔ´µÄ»ìÏýÒÀÀµ¿âµÄÈí¼þ ¡£¡£¡£¡£¡£¡£×÷ΪԤ·À²½·¥£¬ £¬£¬£¬£¬£¬£¬£¬PHPά»¤Ö°Ô±ÒѾöÒ齫¹Ù·½PHPÔ´´úÂë´æ´¢¿âǨáãµ½GitHub ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/


2.°ÄÓéÀÖ¹«Ë¾NineÔâµ½¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬µçÊÓÖ±²¥½ÚÄ¿ÔÝʱÖÐÖ¹


2.jpg


°Ä´óÀûÑǵÄÓéÀÖ¹«Ë¾NineÓÚÉÏÖÜÈÕÔâµ½¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÉÏÎç7:00ÖÁÏÂÖç1:00´ÓϤÄá²¥³öµÄÐÂÎŽÚÄ¿ÔÝʱÖÐÖ¹£¬ £¬£¬£¬£¬£¬£¬£¬¶øÏÂÖç5:00´ÓÄ«¶û±¾×ª²¥µÄÐÂÎŽÚĿҲûÓÐÕý³£²¥³ö ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÆäÔâµ½ÁË´ó¹æÄ£µÄÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÍøÂç̱»¾£¬ £¬£¬£¬£¬£¬£¬£¬µ«µç×ÓÓʼþϵͳ²¢Î´Êܵ½Ó°Ïì ¡£¡£¡£¡£¡£¡£¾ÝϤ£¬ £¬£¬£¬£¬£¬£¬£¬Nine´Ë´ÎÔâµ½µÄ¹¥»÷ÊÇÒ»´ÎÅê»÷ÐÐΪ£¬ £¬£¬£¬£¬£¬£¬£¬ÓÉÓںڿͲ¢Î´Ìá³öÊê½ðÒªÇó£¬ £¬£¬£¬£¬£¬£¬£¬Õâ¹ØÓÚÀÕË÷Èí¼þ¹¥»÷À´ËµÊǺÜÊÇÓÐÊýµÄ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116053/breaking-news/channel-nine-cyber-attack.html


3.ºÚ¿Í³öÊÛÓ¡¶ÈÖ§¸¶Æ½Ì¨MobiKwik 1ÒÚÓû§µÄ8TBÊý¾Ý


3.jpg


ºÚ¿ÍÔÚ°µÍø³öÊÛÓ¡¶ÈÖ§¸¶Æ½Ì¨MobiKwik 1ÒÚÓû§µÄ8TBÊý¾Ý ¡£¡£¡£¡£¡£¡£MobiKwikÊÇÓ¡¶È×î´óµÄÖ§¸¶ÍøÂçÖ®Ò»£¬ £¬£¬£¬£¬£¬£¬£¬ÓµÓÐ1.2ÒÚÓû§¡¢300ÍòÉ̼ҺÍ300¶à¸öÕʵ¥£¬ £¬£¬£¬£¬£¬£¬£¬ÒѾ­ÎªÆäÊý×ÖÐÅÓÿ¨Ô¤ÏÈÅú×¼ÁË2000ÍòÓà ¡£¡£¡£¡£¡£¡£Çå¾²Ö°Ô±ÔÚ2ÔÂÊ×´ÎÓë¸Ã¹«Ë¾ÁªÏµÓйØÊý¾Ýй¶µÄÎÊÌ⣬ £¬£¬£¬£¬£¬£¬£¬²¢ÓÚ3ÔÂ4ÈÕÊÕµ½ÁËMobiKwik·ñ¶¨¸ÃÊÂÎñµÄÐÂÎÅ ¡£¡£¡£¡£¡£¡£ºÚ¿Í´Ë´ÎÒÔ1.5 BTCµÄ¼ÛÇ®³öÊÛ°üÀ¨ÁË36099759¸öÎļþµÄ8.2 TBÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬£¬°üÀ¨Ô¼350ÍòÈ˵ÄKYCÏêϸÐÅÏ¢ºÍÒÔ¼°99224559¸öÓû§µÄµç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢¹þÏ£ÃÜÂë¡¢µØµã¡¢ÒøÐÐÕÊ»§ºÍÐÅÓÿ¨ÏêϸÐÅÏ¢µÈ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/in-threat-actor-offers-to-sell-8-tb-of-mobikwiks-personal-and-financial-data-on-almost-100m-consumers/


4.CompuComÔ¤¼Æ±¾ÔµÄDarkSide¹¥»÷Ôì³É2000ÍòÃÀÔªËðʧ


4.jpg


ÃÀ¹úITÍйÜЧÀÍÌṩÉÌ£¨MSP£©CompuComÔ¤¼Æ£¬ £¬£¬£¬£¬£¬£¬£¬±¾ÔµÄDarkSideÀÕË÷Èí¼þ¹¥»÷¸øÆäÔì³ÉµÄËðʧ½«Áè¼Ý2000ÍòÃÀÔª ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Îª»¨ÆìÒøÐС¢¼ÒµÃ±¦¡¢¸»¹úÒøÐС¢Target¡¢ÐÅÍÐÒøÐкÍLowe'sµÈ×ÅÃû¹«Ë¾ÌṩӲ¼þºÍÈí¼þάÐÞ¡¢Ô¶³ÌÖ§³ÖÒÔ¼°ÆäËûÊÖÒÕЧÀÍ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ô¤¼Æ£¬ £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚЧÀÍÖÐÖ¹Ôì³ÉµÄÊÕÈëËðʧÔÚ500Íòµ½800ÍòÃÀÔªÖ®¼ä ¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬£¬»Ö¸´ÊÜÓ°ÏìϵͳºÍЧÀÍËùÉæ¼°µÄÓöȽ«¸ß´ï2000ÍòÃÀÔª£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼1000ÍòÃÀÔª½«ÔÚ2021ÄêµÚÒ»¼¾¶ÈÖ§¸¶ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/compucom-msp-expects-over-20m-in-losses-after-ransomware-attack/


5.IntelÒò¸ú×ÙÆä¹ÙÍøÉϵÄÓû§ÐÐΪ±»Ö¸¿ØÇÔÈ¡Òþ˽


5.jpg


IntelÒòʹÓõÚÈý·½¾ç±¾¸ú×ÙÆä¹ÙÍøÉϵÄÊó±êÒÆ¶¯ÒÔ¼°¼üÅÌÊäÈ룬 £¬£¬£¬£¬£¬£¬£¬±»Ö¸¿ØÇÔÈ¡Òþ˽ ¡£¡£¡£¡£¡£¡£Ô­¸æHolly Londers³Æ£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚÈ¥ÄêËýԼĪ»á¼ûÁËIntelÍøÕ¾12´Î£¬ £¬£¬£¬£¬£¬£¬£¬¶ø¸ÃÍøÕ¾Ê¹Óøú×Ù¡¢¼Í¼ºÍ»á»°ÖØ·ÅÈí¼þ×èµ²ÁËÆäÊó±êµÄµã»÷ºÍÒÆ¶¯£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÊäÈëµÄÐÅÏ¢¡¢»á¼ûºÍÉó²éµÄÒ³ÃæµÈÄÚÈÝ ¡£¡£¡£¡£¡£¡£The MarkupÒ²ÖÒÑԳƣ¬ £¬£¬£¬£¬£¬£¬£¬IntelÍøÕ¾±£´æÒ»¸öClicktale¾ç±¾£¬ £¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒԼͼ»á»°À´¸ú×ÙÓû§µÄÍøÂç»î¶¯ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/03/30/intel_wiretapping_data/


6.ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳öºóÓû½«Êê½ðÍË»¹¸øÊܺ¦Õß


6.jpg


ÀÕË÷ÍÅ»ïZiggyÔÚ2Ô³õÐû²¼Í˳öºó£¬ £¬£¬£¬£¬£¬£¬£¬Óû½«Êê½ðÍË»¹¸øÊܺ¦Õß ¡£¡£¡£¡£¡£¡£2ÔÂ7ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬Ziggy×èÖ¹ÁËÆä»î¶¯²¢¹ûÕæÁ˰üÀ¨922¸ö½âÃÜÃÜÔ¿µÄSQLÎļþ£¬ £¬£¬£¬£¬£¬£¬£¬3ÔÂ19ÈÕÌåÏÖÏ£Íû¿ÉÒÔ½«Êê½ðÍË»¹¸øÊܺ¦Õߣ¬ £¬£¬£¬£¬£¬£¬£¬²¢ÓÚÔÂ28ÈÕ³ÆÒѾ­×¼±¸ºÃÍË»¹Êê½ð ¡£¡£¡£¡£¡£¡£Êܺ¦Õß¿Éͨ¹ýÓʼþµØµãziggyransomware@secmail.proÓëÖÎÀíÔ±ÁªÏµ£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÌṩÓñÈÌØ±Ò¸¶¿îµÄ֤ʵºÍÅÌËã»úID£¬ £¬£¬£¬£¬£¬£¬£¬Êê½ð½«ÔÚÁ½ÖÜÄÚÍË»¹µ½Êܺ¦ÕߵıÈÌØ±ÒÇ®°üÖÐ ¡£¡£¡£¡£¡£¡£Ziggy³ÆÆäÉúÑÄÔÚÒ»¸öµÚÈýÌìϹú¼Ò£¬ £¬£¬£¬£¬£¬£¬£¬ÀÕË÷»î¶¯ÊdzöÓÚ¾­¼ÃÄ¿µÄ£¬ £¬£¬£¬£¬£¬£¬£¬²¢Í¸Â¶´Ë´ÎÐÐΪÊǵ£ÐÄÖ´·¨Ö°Ô±»á½ÓÄÉÐж¯ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-admin-is-refunding-victims-their-ransom-payments/