Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐУ»£»£»£»£»£»£»£»Monday.comÐû²¼Êܵ½Codecov¹©Ó¦Á´¹¥»÷µÄÓ°Ïì

Ðû²¼Ê±¼ä 2021-05-19

1.Ñо¿Ö°Ô±Åû¶ÐÂľÂíBizarroÕë¶ÔÅ·Ö޵ȶà¼ÒÒøÐÐ


1.jpg


¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷еİÍÎ÷ÒøÐÐľÂíBizarroÕë¶ÔÅ·ÖÞºÍÄÏÃÀµÄ70¶à¼ÒÒøÐС£¡£¡£¡£¡£BizarroÊÇWindows¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬£¬¾ßÓÐx64Ä £¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔÓÕÆ­Êܺ¦ÕßÔÚαÔìµÄµ¯³ö´°¿ÚÖÐÊäÈë2FAÉí·ÝÑéÖ¤´úÂ룬£¬£¬£¬£¬ £¬£¬»¹Ê¹ÓÃÉç»á¹¤³Ì¹¥»÷ÓÕÆ­Êܺ¦ÕßÏÂÔØÒÆ¶¯Ó¦ÓóÌÐò¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄµÄ½¹µã×é¼þÊÇÒ»¸öÖ§³Ö100¶à¸öÏÂÁîµÄºóÃÅ£¬£¬£¬£¬£¬ £¬£¬Ö»Óе±Æä¼ì²âµ½ÒѾ­ÅþÁ¬µ½Ò»¸öÓ²±àÂëµÄÍøÉÏÒøÐÐϵͳʱ£¬£¬£¬£¬£¬ £¬£¬ºóÃŲŻáÆô¶¯¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118032/cyber-crime/bizarro-banking-trojan.html


2.FBI·¢Ã÷½üÆÚð³äÃÀ¹úTruistÒøÐеĴ¹ÂÚ¹¥»÷»î¶¯


2.jpg


FBI·¢Ã÷ÐÂÒ»ÂÖµÄÓã²æÊ½µÄ´¹ÂÚ¹¥»÷»î¶¯£¬£¬£¬£¬£¬ £¬£¬Ã°³äÃÀ¹úµÚÁù´óÒøÐпعɹ«Ë¾Truist Bank¡£¡£¡£¡£¡£´Ë´Î»î¶¯Éù³ÆÐèÒªÍê³ÉÒ»±Ê6200ÍòÃÀÔª´û¿î£¬£¬£¬£¬£¬ £¬£¬À´ÓÕʹÓû§ÏÂÔØÒ»¸öð³äÁËÕýµ±µÄTruism Financial SecureBank AppµÄWindowsÓ¦ÓóÌÐò¡£¡£¡£¡£¡£ÎªÁËÌá¸ß¹¥»÷µÄÀÖ³ÉÂÊ£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁËVirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÎ´¼ì²âµ½µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»áÔÚÓû§ÏÂÔØ´¹ÂÚÓʼþÖеĶñÒâ¿ÉÖ´ÐÐÎļþºó£¬£¬£¬£¬£¬ £¬£¬±»×°Öõ½secureportal(.)onlineÓò¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-spots-spear-phishing-posing-as-truist-bank-bank-to-deliver-malware/


3.Monday.comÐû²¼Êܵ½Codecov¹©Ó¦Á´¹¥»÷µÄÓ°Ïì


3.jpg


Monday.com×î½üÅû¶ÆäÔâµ½Codecov¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÁ˶à¼Ò¹«Ë¾¡£¡£¡£¡£¡£Monday.comÊÇÒ»¸öÔÚÏßÊÂÇéÁ÷ÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬ £¬£¬¸Ãƽ̨µÄ¿Í»§°üÀ¨Uber¡¢BBC Studios¡¢Adobe¡¢Universal¡¢Hulu¡¢L'Oreal¡¢ÊʿڿÉÀÖºÍÁªºÏÀû»ªµÈ×ÅÃû¹«Ë¾¡£¡£¡£¡£¡£Monday.com·¢Ã÷Ôڴ˴ι¥»÷ÖкڿÍÇÔÈ¡ÁËÆäÔ´´úÂëµÄÖ»¶Á¸±±¾£¬£¬£¬£¬£¬ £¬£¬²¢Î´¶ÔÆä¾ÙÐи͝¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬»¹Ð¹Â¶ÁËÍйÜÔÚ¸ÃÆ½Ì¨ÉϵĿͻ§±íµ¥ºÍÊÓͼ¡£¡£¡£¡£¡£×÷Ϊ»º½â²½·¥£¬£¬£¬£¬£¬ £¬£¬¸Ãƽ̨×èֹʹÓÃCodecovµÄЧÀͲ¢Ìæ»»ÁËËùÓÐÉú²úºÍ¿ª·¢ÇéÐεÄÃÜÔ¿¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/codecov-hackers-gained-access-to-mondaycom-source-code/


4.ÃÀ¹úUtility³ÆÆäѬȾClop£¬£¬£¬£¬£¬ £¬£¬Ô±¹¤µÄСÎÒ˽¼ÒÐÅϢй¶


4.jpg


Utility Trailer Manufacturing³ÆÆäѬȾÁËÀÕË÷Èí¼þClop£¬£¬£¬£¬£¬ £¬£¬²¿·ÖϵͳÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¸Ã¹«Ë¾Î»ÓÚ¼ÓÀû¸£ÄáÑÇ£¬£¬£¬£¬£¬ £¬£¬ÊÇÃÀ¹ú×î´óµÄÍϳµÉú²úÉÌÖ®Ò»¡£¡£¡£¡£¡£ClopÍÅ»ïÓÚÉÏÖÜÔÚ°µÍø¹ûÕæÁ˴Ӹù«Ë¾ÇÔÈ¡µÄ5 GBÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬°üÀ¨ÈËΪµ¥ºÍÈËÁ¦×ÊÔ´ÐÅÏ¢µÈÔ±¹¤µÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾ÉÐδ¹ûÕæ¹¥»÷µÄ¹æÄ£ÒÔ¼°Êý¾Ýй¶µÄˮƽ¡£¡£¡£¡£¡£ClopÔø¹¥»÷Á˶à¼Ò´óÐ͹«Ë¾£¬£¬£¬£¬£¬ £¬£¬°üÀ¨Ìú·ÔËÓªÉÌCSXºÍ¼ÓÄôóȼÁϹ«Ë¾ParklandµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.freightwaves.com/news/trailer-maker-utility-targeted-in-ransomware-attack


5.ESET·¢Ã÷¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö


5.jpg


ESETÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬ £¬£¬¼ì²â³öµÄAndroid¸ú×ÙÈí¼þÔÚ2020Ä꼤Ôö¡£¡£¡£¡£¡£ÔÚ2019Ä꣬£¬£¬£¬£¬ £¬£¬Android¸ú×ÙÈí¼þµÄÊýÄ¿ÏÕЩÊÇ2018ÄêµÄÎå±¶£¬£¬£¬£¬£¬ £¬£¬¶øµ½ÁË2020Ä꣬£¬£¬£¬£¬ £¬£¬´ËÀà¶ñÒâÈí¼þÊýÄ¿±È2019ÄêÔöÌíÁË48£¥¡£¡£¡£¡£¡£¹ØÓÚ´ËÀàÓ¦ÓõũӦÉÌÀ´Ëµ£¬£¬£¬£¬£¬ £¬£¬ÎªÁË×èÖ¹±»±ê¼ÇΪ¸ú×ÙÈí¼þ£¬£¬£¬£¬£¬ £¬£¬Í¨³£½«ÆäÐû´«ÎªÎª¶ùͯ¡¢Ô±¹¤»òÅ®ÐÔÌṩ±£»£»£»£»£»£»£»£»¤¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöÁËÀ´×Ô86¸ö²î±ð¹©Ó¦É̵ÄAndroid¸ú×ÙÓ¦Ó㬣¬£¬£¬£¬ £¬£¬×ܹ²·¢Ã÷ÁË158¸öÇå¾²ÎÊÌ⣬£¬£¬£¬£¬ £¬£¬ÀýÈçÓû§ÐÅÏ¢´«Êä²»Çå¾²(CWE-200)¡¢Ð§ÀÍÆ÷й¶¸ú×ÙÕßÐÅÏ¢(CWE-200)ºÍÏÂÁî×¢Èë(cwe-926)µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/stalkerware-adoption-rates-surge-over-2020-hundreds-of-vulnerabilities-found/


6.NetscoutÐû²¼ÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ


6.jpg


NetscoutÐû²¼ÁËÓйØ2021ÄêQ1 DDoS¹¥»÷µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÔÚ2021ÄêµÚÒ»¼¾¶È·¢¶¯ÁËԼĪ290Íò´ÎDDoS¹¥»÷£¬£¬£¬£¬£¬ £¬£¬±È2020ÄêͬÆÚÔöÌíÁË31£¥£¬£¬£¬£¬£¬ £¬£¬×î´óΪ480 Gbps£¬£¬£¬£¬£¬ £¬£¬×î´óÍÌÍÂÁ¿Îª675 Mpps£¬£¬£¬£¬£¬ £¬£¬×î¸ß¹¥»÷ÀàÐÍÊÇUDP¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬ £¬£¬ÎÀÉú±£½¡ÐÐÒµÔâµ½ÁË8400´Î¹¥»÷£¬£¬£¬£¬£¬ £¬£¬½ÌÓýÐÐÒµÔâµ½ÁË45000´Î¹¥»÷£¬£¬£¬£¬£¬ £¬£¬ÔÚÏßЧÀÍÐÐÒµÔâµ½ÁË59000´Î¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/asert/beat-goes