AWS CodeBuildÉèÖÃÎó²îÒý·¢¹©Ó¦Á´Ç徲Σ»£»ú
Ðû²¼Ê±¼ä 2026-01-201. AWS CodeBuildÉèÖÃÎó²îÒý·¢¹©Ó¦Á´Ç徲Σ»£»ú
1ÔÂ15ÈÕ£¬£¬£¬Wiz Research·¢Ã÷²¢ÃüÃû¡°CodeBreach¡±Îó²î£¬£¬£¬Õ¹ÏÖAWS CodeBuildÒòÕýÔò±í´ïʽÉèÖùýʧµ¼ÖÂÑÏÖØÇ徲Σº¦¡£¡£¸ÃÎó²îÔ´ÓÚCodeBuild´¦Öóͷ£ÀÈ¡ÇëÇó´¥·¢Æ÷µÄÇå¾²¹ýÂËÆ÷±£´æÏ¸Ð¡È±ÏÝ£¬£¬£¬½öȱÉÙÁ½¸ö×Ö·û£¬£¬£¬µ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý°üÀ¨ÒÑÅú×¼ID×Ó×Ö·û´®µÄGitHubÓû§IDÈÆ¹ýÏÞÖÆ£¬£¬£¬´¥·¢ÌØÈ¨¹¹½¨Ê¹Ãü¡£¡£¹¥»÷Õß½è´Ë»á¼û¹¹½¨ÄÚ´æÖеÄGitHubƾ֤£¬£¬£¬×îÖÕÍêÈ«¿ØÖƽ¹µãAWS GitHub´úÂë¿â£¬£¬£¬°üÀ¨Ö§³ÖAWS¿ØÖÆÌ¨µÄJavaScript SDK¡£¡£Îó²îÓ°Ïì¹æÄ£ÆÕ±é£¬£¬£¬×îÃô¸ÐÄ¿µÄΪAWS SDK for JavaScript¡£¡£¸Ã¿âÆÕ±éÓÃÓÚ¿Í»§Ó¦Óü°AWS¿ØÖÆÌ¨×Ô¼º£¬£¬£¬¾ÝÔ¤¼Æ66%µÄÔÆÇéÐΰüÀ¨´ËSDK£¬£¬£¬ÏÔÖø·Å´ó¹©Ó¦Á´¹¥»÷µÄDZÔÚÓ°Ïì¡£¡£WizÑо¿Ö°Ô±Í¨¹ý×Ô¶¯»¯½¨ÉèGitHubÓ¦Ó㬣¬£¬Ê¹ÓÃGitHubÓû§ID·ÖÅɼÍÂÉ£¬£¬£¬ÀÖ³ÉÕ¹Íû²¢»ñÈ¡¿ÉÈÆ¹ý¹ýÂËÆ÷µÄID£¬£¬£¬ÑÝʾÁ˶Ôaws/aws-sdk-js-v3´úÂë¿âµÄ½ÓÊÜ£¬£¬£¬ÇÔÈ¡ÖÎÀíԱȨÏÞ¡£¡£±ðµÄ£¬£¬£¬ÖÁÉÙÈý¸öÆäËûAWS´úÂë¿â±£´æÏàͬÈõµã£¬£¬£¬ÆäÖÐÒ»Àý¹ØÁªAWSÔ±¹¤Ð¡ÎÒ˽¼ÒÕË»§¡£¡£
https://www.infosecurity-magazine.com/news/codebuild-flaw-aws-console-risk/
2. Ó¢ÖÒÑÔÇ×¶íºÚ¿ÍDDoS¹¥»÷ÍþвҪº¦ÉèÊ©Çå¾²
1ÔÂ19ÈÕ£¬£¬£¬Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©¿ËÈÕÐû²¼½ôÆÈ¾¯±¨£¬£¬£¬Ö¸³öÓë¶íÂÞ˹¹ØÁªµÄºÚ¿Í×éÖ¯ÕýÒ»Á¬¶ÔÓ¢¹úÒªº¦»ù´¡ÉèÊ©¼°µØ·½Õþ¸®»ú¹¹·¢¶¯ÆÆËðÐÔÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷¡£¡£´ËÀ๥»÷ͨ¹ýÏòÄ¿µÄЧÀÍÆ÷·¢Ëͺ£Á¿ÐéαÇëÇóµ¼ÖÂЧÀÍ̱»¾£¬£¬£¬ËäÊÖÒÕÃż÷½ÏµÍ£¬£¬£¬µ«ÀÖ³ÉʵÑéÈÔ¿ÉÄÜÔì³ÉÄ¿µÄ»ú¹¹¸ß°ºµÄʱ¼ä¡¢×ʽð¼°ÔËÓªµ¯ÐÔËðʧ¡£¡£NCSCÌØÊâµãÃûÇ×¶íºÚ¿ÍÐж¯Ö÷Òå×éÖ¯NoName057(16)£¬£¬£¬¸Ã×éÖ¯×Ô2022Äê3ÔÂÆð»îÔ¾£¬£¬£¬ÔËÓªÃûΪDDoSiaµÄÖÚ°üƽ̨£¬£¬£¬Í¨¹ýÕÐļ×ÔÔ¸ÕßТ˳ÅÌËã×ÊÔ´Ö´Ðй¥»÷£¬£¬£¬¼ÓÈëÕ߿ɻñ¿î×Ó½±Àø»òÉçÇøÈϿɡ£¡£2025Äê7Ô£¬£¬£¬¹ú¼ÊÖ´·¨Ðж¯¡°ÒÁË¹ÌØÎ鯷Ðж¯¡±Ëä¾Ð²¶Á½Ãû³ÉÔ±¡¢Ç©·¢°Ë·Ý¾Ð²¶Áî²¢¹Ø±Õ100̨ЧÀÍÆ÷£¬£¬£¬µ«ÒòÖ÷ÒªÔËÓªÕß¾ÝÐÅÒþ²Ø¶íÂÞ˹¾³ÄÚδ±»¾Ð²¶£¬£¬£¬¸Ã×éÖ¯ÒÑÖØ·µ·¸·¨»î¶¯¡£¡£NCSCÇ¿µ÷£¬£¬£¬NoName057(16)µÄÄîÍ··Ç¾¼ÃÀûÒæ£¬£¬£¬¶øÊÇÒâʶÐÎ̬Çý¶¯£¬£¬£¬ÆäÍþвÕýÑݱäΪӰÏìÔËÓªÊÖÒÕ£¨OT£©ÇéÐεÄÐÂÐÎ̬¡£¡£¸Ã×éÖ¯ÒÔ±±Ô¼³ÉÔ±¹ú¼°Å·ÖÞÆäËû¹ú¼ÒÖÐ×èµ²¡°¶íÂÞ˹µØÔµÕþÖÎÒ°ÐÄ¡±µÄ¹«¹²¼°Ë½Óª²¿·Ö×é֯ΪĿµÄ£¬£¬£¬×é³ÉÒ»Á¬Çå¾²ÌôÕ½¡£¡£
https://www.bleepingcomputer.com/news/security/uk-govt-warns-about-ongoing-russian-hacktivist-group-attacks/
3. ¶ñÒâ¹ã¸æÀ©Õ¹NexShieldÖÂä¯ÀÀÆ÷ÕæÊµÍß½â
1ÔÂ19ÈÕ£¬£¬£¬¿ËÈÕ£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ò»ÆðʹÓÃÐéαChromeºÍEdgeÀ©Õ¹NexShieldʵÑéµÄ¶ñÒâ¹ã¸æ¹¥»÷»î¶¯¡£¡£¸ÃÀ©Õ¹Î±×°³ÉÓÉ×ÅÃû¹ã¸æ×èµ²Æ÷uBlock Origin¿ª·¢ÕßRaymond Hill½¨ÉèµÄ"¸ßÐÔÄÜÇáÁ¿¼¶¹ã¸æ×èµ²Æ÷"£¬£¬£¬ÏÖʵͨ¹ýÎÞÏÞÑ»·½¨Éè"chrome.runtime"¶Ë¿ÚÅþÁ¬ºÄ¾¡ÄÚ´æ×ÊÔ´£¬£¬£¬µ¼ÖÂä¯ÀÀÆ÷±êǩҳ¿¨ËÀ¡¢CPUºÍÄÚ´æÊ¹ÓÃÂÊìÉý£¬£¬£¬×îÖÕÒý·¢ÕæÊµÍ߽⡣¡£¹¥»÷Õß½«´Ë³ÆÎª"CrashFix"¹¥»÷£¬£¬£¬ÊôÓÚClickFix¹¥»÷±äÖÖ¡£¡£¹¥»÷Á÷³ÌÏÔʾ£¬£¬£¬ä¯ÀÀÆ÷Íß½âÖØÆôºó£¬£¬£¬À©Õ¹»áµ¯³öÐéαÖÒÑÔÓÕµ¼Óû§Ö´ÐжñÒâÏÂÁî¡£¡£Í¨¹ý¸´ÖÆÏÂÁîµ½¼ôÌù°å²¢Ö¸µ¼Óû§Õ³ÌùÖ´ÐУ¬£¬£¬¹¥»÷Á´×îÖÕ´¥·¢»ìÏýµÄPowerShell¾ç±¾ÏÂÔØÖ´ÐжñÒâ´úÂë¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬ÓÐÓÃÔØºÉÔÚ×°Öúó60·ÖÖӲŻáÖ´ÐУ¬£¬£¬ÒԴ˹æ±Ü¼ì²â¡£¡£Õë¶ÔÆóÒµÇéÐΣ¬£¬£¬¹¥»÷Õß°²ÅÅÁË»ùÓÚPythonµÄÐÂÐÍÔ¶³Ì»á¼û¹¤¾ßModeloRAT£¬£¬£¬¿ÉÖ´ÐÐϵͳÕì̽¡¢×¢²á±íÐ޸ġ¢ÓÐÓÃÔØºÉ×¢Èë¼°×ÔÎÒ¸üеȲÙ×÷¡£¡£¹ØÓÚ·ÇÆóÒµÖ÷»ú£¬£¬£¬¿ØÖÆÐ§ÀÍÆ÷½ö·µ»Ø"²âÊÔÓÐÓÃÔØºÉ!!!!"ÐÂÎÅ£¬£¬£¬ÏÔʾ²î±ðÓÅÏȼ¶´¦Öóͷ£Õ½ÂÔ¡£¡£
https://www.bleepingcomputer.com/news/security/fake-ad-blocker-extension-crashes-the-browser-for-clickfix-attacks/
4. ²Æ²ú°ÙÇ¿½ðÈÚÆóÒµÔâPDFSider¶ñÒâÈí¼þ¹¥»÷
1ÔÂ19ÈÕ£¬£¬£¬¿ËÈÕ£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾ResecurityÔÚÕë¶Ôij²Æ²ú100Ç¿½ðÈÚÆóÒµµÄÀÕË÷Èí¼þÊÂÎñÏìÓ¦ÖУ¬£¬£¬·¢Ã÷Ò»ÖÖÃûΪPDFSiderµÄÐÂÐͶñÒâÈí¼þÕý±»ÓÃÓÚͶ·Å¶ñÒâÔØºÉ¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÉç»á¹¤³ÌÊÖ¶ÎʵÑé¹¥»÷£¬£¬£¬¹¥»÷Õßð³äÊÖÒÕÖ§³ÖÖ°Ô±ÓÕÆÔ±¹¤×°ÖÃ΢Èí¿ìËÙÖúÊÖ¹¤¾ß£¬£¬£¬²¢Ê¹ÓÃÓã²æÊ½ÍøÂç´¹ÂÚÓʼþÈö²¥¡£¡£Óʼþ¸½¼þ°üÀ¨Õýµ±PDF24 Creator¹¤¾ßÓë¶ñÒâDLLÎļþ£¬£¬£¬Í¨¹ýDLL²à¼ÓÔØÊÖÒÕ£¬£¬£¬ÔÚÕýµ±¿ÉÖ´ÐÐÎļþÔËÐÐʱ¼ÓÔØ¶ñÒâ´úÂ룬£¬£¬´Ó¶øÈƹýEDRϵͳ¼ì²â¡£¡£PDFSider±»ÐÎòΪ¾ßÓи߼¶Ò»Á¬ÐÔÍþв£¨APT£©ÌØÕ÷µÄÒþ²ØºóÃÅ£¬£¬£¬Éè¼ÆÓÃÓÚºã¾ÃÉñÃØ»á¼ûÄ¿µÄϵͳ¡£¡£ÆäÊÖÒÕʵÏÖ°üÀ¨£ºÊ¹ÓÃPDF24Èí¼þÎó²î¼ÓÔØ¶ñÒâÈí¼þ£»£»ÄÚ´æÖÐÉÙÉٵĴÅÅ̺ۼ££»£»Í¨¹ýÄäÃû¹ÜµÀÒÔCMDÆô¶¯ÏÂÁ£»Ê¹ÓÃBotan 3.0.0¼ÓÃÜ¿âÓëAES-256-GCM¼ÓÃÜC2ͨѶ£¬£¬£¬²¢ÔÚÄÚ´æÖнâÃÜÊý¾ÝÒÔïÔÌÓ°Ï죻£»½ÓÄɹØÁªÊý¾ÝÈÏÖ¤¼ÓÃÜ£¨AEAD£©Ä£Ê½°ü¹ÜͨѶÍêÕûÐÔ£»£»Í¨¹ýDNS£¨¶Ë¿Ú53£©Ð¹Â¶ÏµÍ³ÐÅÏ¢ÖÁ¹¥»÷ÕßVPSЧÀÍÆ÷¡£¡£±ðµÄ£¬£¬£¬¸Ã¶ñÒâÈí¼þ¾ß±¸·´ÆÊÎö»úÖÆ£¬£¬£¬ÈçRAM¾Þϸ¼ì²éºÍµ÷ÊÔÆ÷¼ì²â£¬£¬£¬¿ÉÔÚɳÏäÇéÐÎÖÐ×Ô¶¯Í˳ö¡£¡£
https://www.bleepingcomputer.com/news/security/new-pdfsider-windows-malware-deployed-on-fortune-100-firms-network/
5. Ó¢Âõ¹ú¼ÊÔâÀÕË÷¹¥»÷ÖÂ4.2ÍòÈËÊý¾Ýй¶
1ÔÂ19ÈÕ£¬£¬£¬È«Çò×î´óB2BÊÖÒÕ·ÖÏúÉÌÓ¢Âõ¹ú¼Ê£¨Ingram Micro£©ÓÚ2025Äê7ÔÂ2ÈÕÖÁ3ÈÕʱ´úÔâÊÜÑÏÖØÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬µ¼ÖÂÁè¼Ý4.2ÍòÈ˵ÄÃô¸ÐÊý¾Ýй¶¡£¡£¸Ã¹«Ë¾Åû¶£¬£¬£¬¹¥»÷ÕßÇÔÈ¡Á˰üÀ¨ÐÕÃû¡¢ÁªÏµ·½·¨¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂë¼°ÊÂÇéÆÀ¹ÀµÈСÎÒ˽¼ÒÐÅÏ¢µÄÎļþ£¬£¬£¬²¢°²ÅÅÀÕË÷Èí¼þ¼ÓÃÜϵͳ¡£¡£´Ë´ÎÊÂÎñµ¼ÖÂÆäÄÚ²¿ÏµÍ³ºÍÍøÕ¾Ì±»¾£¬£¬£¬Ô±¹¤±»ÆÈÔ¶³Ì°ì¹«£¬£¬£¬ÓªÒµÔËÓªÔâÊÜÖØ´ó¹¥»÷¡£¡£SafePayÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÊÂÎñÈÏÕæ£¬£¬£¬²¢½«Ó¢Âõ¹ú¼ÊÁÐÈëÆä°µÍøÐ¹Â¶ÃÅ»§ÍøÕ¾£¬£¬£¬Éù³ÆÇÔÈ¡ÁË3.5TBÎļþ¡£¡£Ó¢Âõ¹ú¼ÊÔÚÊý¾Ýй¶֪ͨÐÅÖÐÇ¿µ÷£¬£¬£¬¹«Ë¾Ñ¸ËÙÆô¶¯ÊÓ²ìÒÔÈ·¶¨ÊÂÎñÐÔ×Ӻ͹æÄ££¬£¬£¬µ«ÉÐ佫ÊÂÎñÓëÌØ¶¨Íþв×éÖ¯Ö±½Ó¹ØÁª¡£¡£È»¶ø£¬£¬£¬¹¥»÷ʱ¼äÏßÓëSafePayµÄ×÷°¸Ä£Ê½¸ß¶ÈÎǺϣ¬£¬£¬ÇÒ¸Ã×éÖ¯ÔÚ2025ÄêÒÑÖð½¥³ÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯Ö®Ò»£¬£¬£¬Ìî²¹ÁËLockBitºÍBlackCat£¨ALPHV£©Í˳¡ºóµÄÊг¡¿Õȱ¡£¡£
https://www.bleepingcomputer.com/news/security/ingram-micro-says-ransomware-attack-affected-42-000-people/
6. ÌïÄÉÎ÷ÄÐ×ÓÈëÇÖÁª°îϵͳй¶Ãô¸ÐÐÅÏ¢
1ÔÂ19ÈÕ£¬£¬£¬2023Äê8ÔÂÖÁ10ÔÂʱ´ú£¬£¬£¬ÌïÄÉÎ÷ÖÝ24ËêÄÐ×ÓÄá¹ÅÀ˹¡¤Ä¦¶ûͨ¹ýÇÔÈ¡µÄƾ֤£¬£¬£¬¶à´Î²»·¨»á¼ûÃÀ¹ú×î¸ß·¨Ôºµç×ӹ鵵ϵͳ¡¢AmeriCorpsÕË»§¼°ÍËÎéÎäÊ¿ÊÂÎñ²¿ÔÚÏß¿µ½¡¼Í¼ϵͳ¡£¡£¾ÝÁª°îÉó²é¹ÙÅû¶£¬£¬£¬Ä¦¶ûÔÚ×î¸ß·¨ÔºÏµÍ³ÖÐʹÓñ»µÁƾ֤ÖÁÉÙ25´ÎµÇ¼£¬£¬£¬ÓÐʱµ¥ÈÕ¶à´Î»á¼û£¬£¬£¬²¢½ØÈ¡°üÀ¨Êܺ¦ÕßÐÕÃû¡¢ÕË»§ÏêÇéµÈÐÅÏ¢µÄ½çÃæ½ØÍ¼£¬£¬£¬Ðû²¼ÖÁÆäInstagramÕ˺Å@ihackedthegovernment¾ÙÐÐìÅÒ«¡£¡£ÔÚAmeriCorpsÕË»§ÈëÇÖÊÂÎñÖУ¬£¬£¬Ä¦¶ûÆß´Î»á¼ûµÚ¶þÃûÊܺ¦ÕßµÄÕË»§£¬£¬£¬´ÓЧÀÍÆ÷»ñÈ¡°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓÊÏä¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢¹«ÃñÉí·Ý¡¢ÍËÎéÎäÊ¿Éí·Ý¡¢·þÒÛÀúÊ·¼°Éç»á°ü¹ÜºÅÂëºóËÄλµÈСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬²¢ÔÚÉ罻ýÌåÉϹûÕæÐ¹Â¶¡£¡£Õë¶ÔÍËÎéÎäÊ¿ÊÂÎñ²¿£¬£¬£¬ËûÎå´ÎʹÓôÓÒ»Ãûˮʦ½ս¶ÓÍËÎéÎäÊ¿´¦ÇÔÈ¡µÄƾ֤£¬£¬£¬µÇ¼My HealtheVetСÎÒ˽¼Ò¿µ½¡¼Í¼ÃÅ»§£¬£¬£¬»ñÈ¡¸ÃÍËÎéÎäÊ¿µÄ˽ÈË¿µ½¡ÐÅÏ¢£¬£¬£¬Èç´¦·½Ò©Îï¼Í¼¼°ÆäËûÃô¸ÐÒ½ÁÆÊý¾Ý£¬£¬£¬ËæºóͬÑùÔÚInstagramÉÏÐû²¼Ïà¹Ø½ØÍ¼²¢Ðû³Æ¡°ÈëÇÖÀֳɡ±¡£¡£ÏÖÔÚ£¬£¬£¬Ä¦¶ûÒÑÈϿɷ¸·¨ÊÂʵ£¬£¬£¬°¸¼þ½øÈëÁ¿Ð̽׶Ρ£¡£
https://www.bleepingcomputer.com/news/security/hacker-admits-to-leaking-stolen-supreme-court-data-on-instagram/


¾©¹«Íø°²±¸11010802024551ºÅ