AWS CodeBuildÉèÖÃÎó²îÒý·¢¹©Ó¦Á´Ç徲Σ»£»£»£»£»£»ú

Ðû²¼Ê±¼ä 2026-01-20

1. AWS CodeBuildÉèÖÃÎó²îÒý·¢¹©Ó¦Á´Ç徲Σ»£»£»£»£»£»ú


1ÔÂ15ÈÕ£¬£¬£¬£¬£¬Wiz Research·¢Ã÷²¢ÃüÃû¡°CodeBreach¡±Îó²î£¬£¬£¬£¬£¬Õ¹ÏÖAWS CodeBuildÒòÕýÔò±í´ïʽÉèÖùýʧµ¼ÖÂÑÏÖØÇ徲Σº¦¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚCodeBuild´¦Öóͷ£À­È¡ÇëÇó´¥·¢Æ÷µÄÇå¾²¹ýÂËÆ÷±£´æÏ¸Ð¡È±ÏÝ£¬£¬£¬£¬£¬½öȱÉÙÁ½¸ö×Ö·û£¬£¬£¬£¬£¬µ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý°üÀ¨ÒÑÅú×¼ID×Ó×Ö·û´®µÄGitHubÓû§IDÈÆ¹ýÏÞÖÆ£¬£¬£¬£¬£¬´¥·¢ÌØÈ¨¹¹½¨Ê¹Ãü¡£¡£¡£¡£¡£¡£¹¥»÷Õß½è´Ë»á¼û¹¹½¨ÄÚ´æÖеÄGitHubƾ֤£¬£¬£¬£¬£¬×îÖÕÍêÈ«¿ØÖƽ¹µãAWS GitHub´úÂë¿â£¬£¬£¬£¬£¬°üÀ¨Ö§³ÖAWS¿ØÖÆÌ¨µÄJavaScript SDK¡£¡£¡£¡£¡£¡£Îó²îÓ°Ïì¹æÄ£ÆÕ±é£¬£¬£¬£¬£¬×îÃô¸ÐÄ¿µÄΪAWS SDK for JavaScript¡£¡£¡£¡£¡£¡£¸Ã¿âÆÕ±éÓÃÓÚ¿Í»§Ó¦Óü°AWS¿ØÖÆÌ¨×Ô¼º£¬£¬£¬£¬£¬¾ÝÔ¤¼Æ66%µÄÔÆÇéÐΰüÀ¨´ËSDK£¬£¬£¬£¬£¬ÏÔÖø·Å´ó¹©Ó¦Á´¹¥»÷µÄDZÔÚÓ°Ïì¡£¡£¡£¡£¡£¡£WizÑо¿Ö°Ô±Í¨¹ý×Ô¶¯»¯½¨ÉèGitHubÓ¦Ó㬣¬£¬£¬£¬Ê¹ÓÃGitHubÓû§ID·ÖÅɼÍÂÉ£¬£¬£¬£¬£¬ÀÖ³ÉÕ¹Íû²¢»ñÈ¡¿ÉÈÆ¹ý¹ýÂËÆ÷µÄID£¬£¬£¬£¬£¬ÑÝʾÁ˶Ôaws/aws-sdk-js-v3´úÂë¿âµÄ½ÓÊÜ£¬£¬£¬£¬£¬ÇÔÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÖÁÉÙÈý¸öÆäËûAWS´úÂë¿â±£´æÏàͬÈõµã£¬£¬£¬£¬£¬ÆäÖÐÒ»Àý¹ØÁªAWSÔ±¹¤Ð¡ÎÒ˽¼ÒÕË»§¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/codebuild-flaw-aws-console-risk/


2. Ó¢ÖÒÑÔÇ×¶íºÚ¿ÍDDoS¹¥»÷ÍþвҪº¦ÉèÊ©Çå¾²


1ÔÂ19ÈÕ£¬£¬£¬£¬£¬Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©¿ËÈÕÐû²¼½ôÆÈ¾¯±¨£¬£¬£¬£¬£¬Ö¸³öÓë¶íÂÞ˹¹ØÁªµÄºÚ¿Í×éÖ¯ÕýÒ»Á¬¶ÔÓ¢¹úÒªº¦»ù´¡ÉèÊ©¼°µØ·½Õþ¸®»ú¹¹·¢¶¯ÆÆËðÐÔÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷¡£¡£¡£¡£¡£¡£´ËÀ๥»÷ͨ¹ýÏòÄ¿µÄЧÀÍÆ÷·¢Ëͺ£Á¿ÐéαÇëÇóµ¼ÖÂЧÀÍ̱»¾£¬£¬£¬£¬£¬ËäÊÖÒÕÃż÷½ÏµÍ£¬£¬£¬£¬£¬µ«ÀÖ³ÉʵÑéÈÔ¿ÉÄÜÔì³ÉÄ¿µÄ»ú¹¹¸ß°ºµÄʱ¼ä¡¢×ʽð¼°ÔËÓªµ¯ÐÔËðʧ¡£¡£¡£¡£¡£¡£NCSCÌØÊâµãÃûÇ×¶íºÚ¿ÍÐж¯Ö÷Òå×éÖ¯NoName057(16)£¬£¬£¬£¬£¬¸Ã×éÖ¯×Ô2022Äê3ÔÂÆð»îÔ¾£¬£¬£¬£¬£¬ÔËÓªÃûΪDDoSiaµÄÖÚ°üƽ̨£¬£¬£¬£¬£¬Í¨¹ýÕÐļ×ÔÔ¸ÕßТ˳ÅÌËã×ÊÔ´Ö´Ðй¥»÷£¬£¬£¬£¬£¬¼ÓÈëÕ߿ɻñ¿î×Ó½±Àø»òÉçÇøÈϿɡ£¡£¡£¡£¡£¡£2025Äê7Ô£¬£¬£¬£¬£¬¹ú¼ÊÖ´·¨Ðж¯¡°ÒÁË¹ÌØÎ鯷Ðж¯¡±Ëä¾Ð²¶Á½Ãû³ÉÔ±¡¢Ç©·¢°Ë·Ý¾Ð²¶Áî²¢¹Ø±Õ100̨ЧÀÍÆ÷£¬£¬£¬£¬£¬µ«ÒòÖ÷ÒªÔËÓªÕß¾ÝÐÅÒþ²Ø¶íÂÞ˹¾³ÄÚδ±»¾Ð²¶£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÑÖØ·µ·¸·¨»î¶¯¡£¡£¡£¡£¡£¡£NCSCÇ¿µ÷£¬£¬£¬£¬£¬NoName057(16)µÄÄîÍ··Ç¾­¼ÃÀûÒæ£¬£¬£¬£¬£¬¶øÊÇÒâʶÐÎ̬Çý¶¯£¬£¬£¬£¬£¬ÆäÍþвÕýÑݱäΪӰÏìÔËÓªÊÖÒÕ£¨OT£©ÇéÐεÄÐÂÐÎ̬¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÒÔ±±Ô¼³ÉÔ±¹ú¼°Å·ÖÞÆäËû¹ú¼ÒÖÐ×èµ²¡°¶íÂÞ˹µØÔµÕþÖÎÒ°ÐÄ¡±µÄ¹«¹²¼°Ë½Óª²¿·Ö×é֯ΪĿµÄ£¬£¬£¬£¬£¬×é³ÉÒ»Á¬Çå¾²ÌôÕ½¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/uk-govt-warns-about-ongoing-russian-hacktivist-group-attacks/


3. ¶ñÒâ¹ã¸æÀ©Õ¹NexShieldÖÂä¯ÀÀÆ÷ÕæÊµÍß½â


1ÔÂ19ÈÕ£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ò»ÆðʹÓÃÐéαChromeºÍEdgeÀ©Õ¹NexShieldʵÑéµÄ¶ñÒâ¹ã¸æ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¸ÃÀ©Õ¹Î±×°³ÉÓÉ×ÅÃû¹ã¸æ×èµ²Æ÷uBlock Origin¿ª·¢ÕßRaymond Hill½¨ÉèµÄ"¸ßÐÔÄÜÇáÁ¿¼¶¹ã¸æ×èµ²Æ÷"£¬£¬£¬£¬£¬ÏÖʵͨ¹ýÎÞÏÞÑ­»·½¨Éè"chrome.runtime"¶Ë¿ÚÅþÁ¬ºÄ¾¡ÄÚ´æ×ÊÔ´£¬£¬£¬£¬£¬µ¼ÖÂä¯ÀÀÆ÷±êǩҳ¿¨ËÀ¡¢CPUºÍÄÚ´æÊ¹ÓÃÂÊì­Éý£¬£¬£¬£¬£¬×îÖÕÒý·¢ÕæÊµÍ߽⡣¡£¡£¡£¡£¡£¹¥»÷Õß½«´Ë³ÆÎª"CrashFix"¹¥»÷£¬£¬£¬£¬£¬ÊôÓÚClickFix¹¥»÷±äÖÖ¡£¡£¡£¡£¡£¡£¹¥»÷Á÷³ÌÏÔʾ£¬£¬£¬£¬£¬ä¯ÀÀÆ÷Íß½âÖØÆôºó£¬£¬£¬£¬£¬À©Õ¹»áµ¯³öÐéαÖÒÑÔÓÕµ¼Óû§Ö´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£¡£Í¨¹ý¸´ÖÆÏÂÁîµ½¼ôÌù°å²¢Ö¸µ¼Óû§Õ³ÌùÖ´ÐУ¬£¬£¬£¬£¬¹¥»÷Á´×îÖÕ´¥·¢»ìÏýµÄPowerShell¾ç±¾ÏÂÔØÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬ÓÐÓÃÔØºÉÔÚ×°Öúó60·ÖÖӲŻáÖ´ÐУ¬£¬£¬£¬£¬ÒԴ˹æ±Ü¼ì²â¡£¡£¡£¡£¡£¡£Õë¶ÔÆóÒµÇéÐΣ¬£¬£¬£¬£¬¹¥»÷Õß°²ÅÅÁË»ùÓÚPythonµÄÐÂÐÍÔ¶³Ì»á¼û¹¤¾ßModeloRAT£¬£¬£¬£¬£¬¿ÉÖ´ÐÐϵͳÕì̽¡¢×¢²á±íÐ޸ġ¢ÓÐÓÃÔØºÉ×¢Èë¼°×ÔÎÒ¸üеȲÙ×÷¡£¡£¡£¡£¡£¡£¹ØÓÚ·ÇÆóÒµÖ÷»ú£¬£¬£¬£¬£¬¿ØÖÆÐ§ÀÍÆ÷½ö·µ»Ø"²âÊÔÓÐÓÃÔØºÉ!!!!"ÐÂÎÅ£¬£¬£¬£¬£¬ÏÔʾ²î±ðÓÅÏȼ¶´¦Öóͷ£Õ½ÂÔ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-ad-blocker-extension-crashes-the-browser-for-clickfix-attacks/


4. ²Æ²ú°ÙÇ¿½ðÈÚÆóÒµÔâPDFSider¶ñÒâÈí¼þ¹¥»÷


1ÔÂ19ÈÕ£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾ResecurityÔÚÕë¶Ôij²Æ²ú100Ç¿½ðÈÚÆóÒµµÄÀÕË÷Èí¼þÊÂÎñÏìÓ¦ÖУ¬£¬£¬£¬£¬·¢Ã÷Ò»ÖÖÃûΪPDFSiderµÄÐÂÐͶñÒâÈí¼þÕý±»ÓÃÓÚͶ·Å¶ñÒâÔØºÉ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÉç»á¹¤³ÌÊÖ¶ÎʵÑé¹¥»÷£¬£¬£¬£¬£¬¹¥»÷Õßð³äÊÖÒÕÖ§³ÖÖ°Ô±ÓÕÆ­Ô±¹¤×°ÖÃ΢Èí¿ìËÙÖúÊÖ¹¤¾ß£¬£¬£¬£¬£¬²¢Ê¹ÓÃÓã²æÊ½ÍøÂç´¹ÂÚÓʼþÈö²¥¡£¡£¡£¡£¡£¡£Óʼþ¸½¼þ°üÀ¨Õýµ±PDF24 Creator¹¤¾ßÓë¶ñÒâDLLÎļþ£¬£¬£¬£¬£¬Í¨¹ýDLL²à¼ÓÔØÊÖÒÕ£¬£¬£¬£¬£¬ÔÚÕýµ±¿ÉÖ´ÐÐÎļþÔËÐÐʱ¼ÓÔØ¶ñÒâ´úÂ룬£¬£¬£¬£¬´Ó¶øÈƹýEDRϵͳ¼ì²â¡£¡£¡£¡£¡£¡£PDFSider±»ÐÎòΪ¾ßÓи߼¶Ò»Á¬ÐÔÍþв£¨APT£©ÌØÕ÷µÄÒþ²ØºóÃÅ£¬£¬£¬£¬£¬Éè¼ÆÓÃÓÚºã¾ÃÉñÃØ»á¼ûÄ¿µÄϵͳ¡£¡£¡£¡£¡£¡£ÆäÊÖÒÕʵÏÖ°üÀ¨£ºÊ¹ÓÃPDF24Èí¼þÎó²î¼ÓÔØ¶ñÒâÈí¼þ£»£»£»£»£»£»ÄÚ´æÖÐÉÙÉٵĴÅÅ̺ۼ££»£»£»£»£»£»Í¨¹ýÄäÃû¹ÜµÀÒÔCMDÆô¶¯ÏÂÁ£»£»£»£»£»Ê¹ÓÃBotan 3.0.0¼ÓÃÜ¿âÓëAES-256-GCM¼ÓÃÜC2ͨѶ£¬£¬£¬£¬£¬²¢ÔÚÄÚ´æÖнâÃÜÊý¾ÝÒÔïÔÌ­Ó°Ï죻£»£»£»£»£»½ÓÄɹØÁªÊý¾ÝÈÏÖ¤¼ÓÃÜ£¨AEAD£©Ä£Ê½°ü¹ÜͨѶÍêÕûÐÔ£»£»£»£»£»£»Í¨¹ýDNS£¨¶Ë¿Ú53£©Ð¹Â¶ÏµÍ³ÐÅÏ¢ÖÁ¹¥»÷ÕßVPSЧÀÍÆ÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¾ß±¸·´ÆÊÎö»úÖÆ£¬£¬£¬£¬£¬ÈçRAM¾Þϸ¼ì²éºÍµ÷ÊÔÆ÷¼ì²â£¬£¬£¬£¬£¬¿ÉÔÚɳÏäÇéÐÎÖÐ×Ô¶¯Í˳ö¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-pdfsider-windows-malware-deployed-on-fortune-100-firms-network/


5. Ó¢Âõ¹ú¼ÊÔâÀÕË÷¹¥»÷ÖÂ4.2ÍòÈËÊý¾Ýй¶


1ÔÂ19ÈÕ£¬£¬£¬£¬£¬È«Çò×î´óB2BÊÖÒÕ·ÖÏúÉÌÓ¢Âõ¹ú¼Ê£¨Ingram Micro£©ÓÚ2025Äê7ÔÂ2ÈÕÖÁ3ÈÕʱ´úÔâÊÜÑÏÖØÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÁè¼Ý4.2ÍòÈ˵ÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Åû¶£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡Á˰üÀ¨ÐÕÃû¡¢ÁªÏµ·½·¨¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂë¼°ÊÂÇéÆÀ¹ÀµÈСÎÒ˽¼ÒÐÅÏ¢µÄÎļþ£¬£¬£¬£¬£¬²¢°²ÅÅÀÕË÷Èí¼þ¼ÓÃÜϵͳ¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñµ¼ÖÂÆäÄÚ²¿ÏµÍ³ºÍÍøÕ¾Ì±»¾£¬£¬£¬£¬£¬Ô±¹¤±»ÆÈÔ¶³Ì°ì¹«£¬£¬£¬£¬£¬ÓªÒµÔËÓªÔâÊÜÖØ´ó¹¥»÷¡£¡£¡£¡£¡£¡£SafePayÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÊÂÎñÈÏÕæ£¬£¬£¬£¬£¬²¢½«Ó¢Âõ¹ú¼ÊÁÐÈëÆä°µÍøÐ¹Â¶ÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬Éù³ÆÇÔÈ¡ÁË3.5TBÎļþ¡£¡£¡£¡£¡£¡£Ó¢Âõ¹ú¼ÊÔÚÊý¾Ýй¶֪ͨÐÅÖÐÇ¿µ÷£¬£¬£¬£¬£¬¹«Ë¾Ñ¸ËÙÆô¶¯ÊÓ²ìÒÔÈ·¶¨ÊÂÎñÐÔ×Ӻ͹æÄ££¬£¬£¬£¬£¬µ«ÉÐ佫ÊÂÎñÓëÌØ¶¨Íþв×éÖ¯Ö±½Ó¹ØÁª¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬¹¥»÷ʱ¼äÏßÓëSafePayµÄ×÷°¸Ä£Ê½¸ß¶ÈÎǺϣ¬£¬£¬£¬£¬ÇÒ¸Ã×éÖ¯ÔÚ2025ÄêÒÑÖð½¥³ÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯Ö®Ò»£¬£¬£¬£¬£¬Ìî²¹ÁËLockBitºÍBlackCat£¨ALPHV£©Í˳¡ºóµÄÊг¡¿Õȱ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ingram-micro-says-ransomware-attack-affected-42-000-people/


6. ÌïÄÉÎ÷ÄÐ×ÓÈëÇÖÁª°îϵͳй¶Ãô¸ÐÐÅÏ¢


1ÔÂ19ÈÕ£¬£¬£¬£¬£¬2023Äê8ÔÂÖÁ10ÔÂʱ´ú£¬£¬£¬£¬£¬ÌïÄÉÎ÷ÖÝ24ËêÄÐ×ÓÄá¹ÅÀ­Ë¹¡¤Ä¦¶ûͨ¹ýÇÔÈ¡µÄƾ֤£¬£¬£¬£¬£¬¶à´Î²»·¨»á¼ûÃÀ¹ú×î¸ß·¨Ôºµç×ӹ鵵ϵͳ¡¢AmeriCorpsÕË»§¼°ÍËÎéÎäÊ¿ÊÂÎñ²¿ÔÚÏß¿µ½¡¼Í¼ϵͳ¡£¡£¡£¡£¡£¡£¾ÝÁª°îÉó²é¹ÙÅû¶£¬£¬£¬£¬£¬Ä¦¶ûÔÚ×î¸ß·¨ÔºÏµÍ³ÖÐʹÓñ»µÁƾ֤ÖÁÉÙ25´ÎµÇ¼£¬£¬£¬£¬£¬ÓÐʱµ¥ÈÕ¶à´Î»á¼û£¬£¬£¬£¬£¬²¢½ØÈ¡°üÀ¨Êܺ¦ÕßÐÕÃû¡¢ÕË»§ÏêÇéµÈÐÅÏ¢µÄ½çÃæ½ØÍ¼£¬£¬£¬£¬£¬Ðû²¼ÖÁÆäInstagramÕ˺Å@ihackedthegovernment¾ÙÐÐìÅÒ«¡£¡£¡£¡£¡£¡£ÔÚAmeriCorpsÕË»§ÈëÇÖÊÂÎñÖУ¬£¬£¬£¬£¬Ä¦¶ûÆß´Î»á¼ûµÚ¶þÃûÊܺ¦ÕßµÄÕË»§£¬£¬£¬£¬£¬´ÓЧÀÍÆ÷»ñÈ¡°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓÊÏä¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢¹«ÃñÉí·Ý¡¢ÍËÎéÎäÊ¿Éí·Ý¡¢·þÒÛÀúÊ·¼°Éç»á°ü¹ÜºÅÂëºóËÄλµÈСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬²¢ÔÚÉ罻ýÌåÉϹûÕæÐ¹Â¶¡£¡£¡£¡£¡£¡£Õë¶ÔÍËÎéÎäÊ¿ÊÂÎñ²¿£¬£¬£¬£¬£¬ËûÎå´ÎʹÓôÓÒ»Ãûˮʦ½ս¶ÓÍËÎéÎäÊ¿´¦ÇÔÈ¡µÄƾ֤£¬£¬£¬£¬£¬µÇ¼My HealtheVetСÎÒ˽¼Ò¿µ½¡¼Í¼ÃÅ»§£¬£¬£¬£¬£¬»ñÈ¡¸ÃÍËÎéÎäÊ¿µÄ˽ÈË¿µ½¡ÐÅÏ¢£¬£¬£¬£¬£¬Èç´¦·½Ò©Îï¼Í¼¼°ÆäËûÃô¸ÐÒ½ÁÆÊý¾Ý£¬£¬£¬£¬£¬ËæºóͬÑùÔÚInstagramÉÏÐû²¼Ïà¹Ø½ØÍ¼²¢Ðû³Æ¡°ÈëÇÖÀֳɡ±¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬Ä¦¶ûÒÑÈϿɷ¸·¨ÊÂʵ£¬£¬£¬£¬£¬°¸¼þ½øÈëÁ¿Ð̽׶Ρ£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hacker-admits-to-leaking-stolen-supreme-court-data-on-instagram/