GitHubÆØÑÏÖØRCE·ì϶ӰÏìÊý°ÙÍò´úÂë¿â
°ä²¼¹¦·ò 2026-04-301. GitHubÆØÑÏÖØRCE·ì϶ӰÏìÊý°ÙÍò´úÂë¿â
4ÔÂ29ÈÕ£¬Ôư²È«¾ÞÍ·WizµÄ×êÑÐÈËÔ±ÔÚGitHubÉÏ·¢ÏÖÁËÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶¿ÉÄܶ³öÊý°ÙÍò¸ö´úÂë¿â¡£¡£¡£·ì϶±àºÅΪCVE-2026-3854£¬Ó°ÏìÁË´úÂëÍÐ¹ÜÆ½Ì¨ÄÚ²¿µÄGit»ù´¡¼Ü¹¹£¬GitHub Enterprise ServerºÍGitHub.com¾ùÊܵ½²¨¼°¡£¡£¡£WizÚ¹Êͳƣ¬Í¨¹ýÀûÓÃGitHubÄÚ²¿ºÍ̸ÖеÄ×¢Èë·ì϶£¬Èκξ¹ýÉí·ÝÑéÖ¤µÄÓû§¾ù¿ÉʹÓó߶Ègit¿Í»§¶Ë£¬Í¨¹ýÒ»¸ögit pushºÅÁîÔÚGitHubµÄºó¶Ë·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£Õâ¼Ò°²È«¹«Ë¾ÀûÓÃÈËΪÖÇÄÜ·¢ÏÖ¸ÃÎÊÌ⣬²¢°µÊ¾·ì϶ÀûÓü«¶ÈÈÝÒס£¡£¡£ÒÔGitHub Enterprise ServerΪÀý£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÆëÈ«½ÚÀñ·þÎñÆ÷£¬»ñµÃ¶ÔËùÓд洢¿âºÍÄÚ²¿»úÃÜÐÅÏ¢µÄ½Ó¼ûȨÏÞ¡£¡£¡£¸Ã·ì϶¶ÔGitHub.comµÄÓ°Ïì¸üΪ¿í·º£¬¹¥»÷Õß¿ÉÔÚ¹²Ïí´æ´¢½ÚµãÉÏÖ´ÐÐÔ¶³Ì´úÂ룬WizÈ·ÈÏÊý°ÙÍò¸öÊôÓÚÆäËûÓû§ºÍ×éÖ¯µÄ¹«¹²¼°Ë½ÓдúÂë¿âÔÚÊÜÓ°ÏìµÄ½ÚµãÉϾù¿É½Ó¼û¡£¡£¡£¹ÌÈ»Éí·ÝÑéÖ¤ÒªÇóËÆºõ½µµÍÁË·çÏÕ£¬µ«GitHubÚ¹Êͳƣ¬ÈκÎÕ¼ÓÐÏò´æ´¢¿âÍÆËÍȨÏÞµÄÓû§¾ù¿ÉÀûÓô˷ì϶ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£
https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/
2. CISA½«ConnectWiseÓëWindows Shell·ì϶ÄÉÈëKEVĿ¼
4ÔÂ29ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö½üÈÕ½«Á½¸öÒѱ»¿í·ºÀûÓõݲȫ·ì϶ÄÉÈëÆäÒÑÖª¿ÉÀûÓ÷ì϶Ŀ¼£¬ÒªÇóÁª°î»ú¹¹ÔÚ2026Äê5ÔÂ12ÈÕǰʵÏÖÐÞ¸´¡£¡£¡£Ê׸ö·ì϶ÊÇConnectWise ScreenConnectÖеÄõè¾¶±éÀú·ì϶£¬±àºÅCVE-2024-1708£¬CVSSÆÀ·ÖΪ8.4·Ö¡£¡£¡£¸Ã·ì϶ӰÏì23.9.7¼°¸üÔç°æ±¾µÄScreenConnect£¬Ô´ÓÚÎļþõè¾¶Ï޶Ȳ»µ±£¬¹¥»÷Õß¿ÉÄܽӼûÔ¤ÆÚÁìÓòÖ®ÍâµÄÎļþºÍĿ¼¡£¡£¡£¹¥»÷Õßͨ¹ý´Û¸ÄÎļþõè¾¶£¬¿É½Ó¼ûϵͳµÄÃô¸ÐÇøÓò£¬ÔÚijЩÇé¾°Ï¿ɵ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлòδ¾ÊÚȨ½Ó¼û»úÃÜÊý¾ÝºÍ¹Ø¼ü×ÊÔ´¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸Ã·ì϶³£ÓëÁíÒ»ÑÏÖØÈÏÖ¤ÈÆ¹ý·ì϶CVE-2024-1709£¨CVSSÆÀ·Ö10.0£©¹²Í¬Ê¹Óᣡ£¡£µÚ¶þ¸ö·ì϶ÊÇWindows ShellºýŪ·ì϶£¬±àºÅCVE-2026-32202£¬CVSSÆÀ·ÖΪ4.3·Ö¡£¡£¡£¸Ã·ì϶ԴÓÚ´ËǰÕë¶ÔCVE-2026-21510µÄ²»ÆëÈ«²¹¶¡¡£¡£¡£CVE-2026-21510ÔÊǶíÂÞ˹APT28ºÚ¿Í×éÖ¯×Ô2025Äê12ÔÂÆðÓÃÀ´¹¥»÷ÎÚ¿ËÀ¼ºÍÅ·Ã˹ú¶ÈµÄÁãÈÕ·ì϶£¬ÓëMSHTML·ì϶CVE-2026-21513×é³ÉÀûÓÃÁ´¡£¡£¡£Î¢ÈíÓÚ4ÔÂ27ÈÕ¸üв¼¸æÈ·Èϸ÷ì϶Òѱ»»ý¼«ÀûÓã¬ÐÞ¸´ÁËÔçǰ°ä²¼µÄÃýÎóÀûÓÃÐÔÖ¸±ê¡£¡£¡£
https://securityaffairs.com/191442/security/u-s-cisa-adds-microsoft-windows-shell-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html
3. SAP¶à¸ö¹Ù·½npm°üÔ⹩¸øÁ´¹¥»÷
4ÔÂ29ÈÕ£¬TeamPCPÌáÒéÁËһ·¹©¸øÁ´¹¥»÷£¬µ¼Ö¶à¸ö¹Ù·½SAP npm°üÔâµ½ÈëÇÖ£¬Ö÷ÕÅÊÇÇÔÈ¡¿ª·¢ÈËԱϵͳÖеÄÍ´´¦ºÍÉí·ÝÑéÖ¤ÁîÅÆ¡£¡£¡£°²È«×êÑÐÈËÔ±»ã±¨³Æ£¬Õâ´Î·ì϶ӰÏìÁËËĸöÈí¼þ°ü£¬Æä¶ñÒâ°æ±¾Ä¿Ç°ÒÑÔÚnpmÉϱ»ÆúÓ㺣º@cap-js/sqlite v2.2.2¡¢@cap-js/postgres v2.2.2¡¢@cap-js/db-service v2.10.1ºÍmbt v1.2.48¡£¡£¡£ÕâЩÈí¼þ°üÖ§³ÖSAPµÄÔÆÀûÓ÷¨Ê½±à³ÌÄ£ÐͺÍÔÆMTA£¬Í¨³£ÓÃÓÚÆóÒµ¿ª·¢»·¾³¡£¡£¡£Æ¾¾ÝAikidoºÍSocketµÄ×îл㱨£¬±»ÈëÇÖµÄÈí¼þ°üÒѱ»Åú¸Ä£¬Ô̺¬Ò»¸ö¶ñÒâµÄ¡°Ô¤×°Ö᱾籾£¬¸Ã¾ç±¾ÔÚ×°ÖÃnpm°üʱ»á×Ô¶¯Ö´ÐС£¡£¡£¸Ã¾ç±¾Æô¶¯Ò»¸öÃûΪsetup.mjsµÄ¼ÓÔØÆ÷£¬´ÓGitHubÏÂÔØBun JavaScriptÔËÐÐʱ£¬²¢Ê¹ÓÃËüÀ´Ö´Ðо¹ý¸ß¶È»ìºÏµÄexecution.jsÔØºÉ¡£¡£¡£¸ÃÔØºÉÊÇÒ»ÖÖÐÅÏ¢ÇÔÈ¡·¨Ê½£¬ÓÃÓÚ´Ó¿ª·¢ÈËÔ±»úеºÍCI/CD»·¾³ÖÐÇÔÈ¡¸÷ÀàÍ´´¦£¬Ô̺¬npmºÍGitHubÉí·ÝÑéÖ¤ÁîÅÆ¡¢SSHÃÜÔ¿¡¢¿ª·¢ÈËԱʹ´¦¡¢AWS/Azure/Google CloudµÄÔÆÆ¾Ö¤¡¢KubernetesÅäÖúÍÃÜÔ¿£¬ÒÔ¼°CI/CDÁ÷Ë®ÏßÃÜÔ¿ºÍ»·¾³±äÁ¿¡£¡£¡£
https://www.bleepingcomputer.com/news/security/official-sap-npm-packages-compromised-to-steal-credentials/
4. Quick Page/Post Redirect²å¼þ²ØÎåÄêºóÃÅ
4ÔÂ29ÈÕ£¬ÎåÄêǰ£¬×°ÖÃÔÚ³¬¹ý70,000¸öWordPressÍøÕ¾ÉϵÄQuick Page/Post Redirect²å¼þ±»Ôö³¤ÁËÒ»¸öºóÃÅ£¬ÔÊÐíÏòÓû§ÍøÕ¾×¢ÈëËÁÒâ´úÂë¡£¡£¡£WordPressÖ÷»úÌṩÉÌAnchorµÄÊ×´´ÈËAustin Ginder·¢ÏÖÁ˸öñÒâÈí¼þ£¬´ËǰËûÍйܵķþÎñÆ÷ÉÏÓÐ12¸öÍøÕ¾Êܵ½Ï°È¾£¬´¥·¢Á˰²È«¾¯±¨¡£¡£¡£Quick Page/Post RedirectÊÇÒ»¿îÓÃÓÚÔÚÎÄÕ¡¢Ò³ÃæºÍ×Ô½ç˵URLÖд´½¨Öض¨ÏòµÄ¸ù»ùʵÓòå¼þ£¬ÒÑÔÚWordPress.orgÉÏÌṩ¶àÄê¡£¡£¡£Ä¿Ç°£¬WordPress.orgÒÑÁÙʱ½«¸Ã²å¼þ´ÓĿ¼ÖÐÒÆ³ý£¬ÆÚ´ýÉó²é¡£¡£¡£Éв»Ã÷ÏÔÊDzå¼þ×÷Õß×ÔÐÐÖ²ÈëÁ˺óÃÅ£¬»¹ÊÇÆäÕË»§±»µÚÈý·½ÈëÇÖ¡£¡£¡£GinderÚ¹ÊÍ˵£¬2020ÄêÖÁ2021Äê¼ä°ä²¼µÄ¹Ù·½²å¼þ°æ±¾5.2.1ºÍ5.2.2Ô̺¬Ò»¸öÖ¸ÏòµÚÈý·½ÓòÃûanadnet[.]comµÄ°µ²Ø×ÔÎÒ¸üлúÖÆ£¬¸Ã»úÖÆÔÊÐí½«ËÁÒâ´úÂëÍÆË͵½WordPress.org½ÚÖÆÁìÓòÖ®Íâ¡£¡£¡£2021Äê2Ô£¬¶ñÒâ×Ô¸üз¨Ê½´ÓWordPress.org²å¼þµÄºóÐø°æ±¾Öб»ÒƳý£¬´úÂëÉó²éÔ±»¹Ã»À´µÃ¼°×ÐϸÉó²éËü¡£¡£¡£¾ÝGinder³Æ£¬2021Äê3Ô£¬ÔËÐÐQuick Page/Post Redirect 5.2.1ºÍ5.2.2µÄÍøÕ¾ÍµÍµµØ´Ó¸ÃÍⲿ·þÎñÆ÷½Ó¹Üµ½ÁËÒ»¸ö´Û»Ú¸ÄµÄ5.2.3°æ±¾£¬¸Ã°æ±¾ÒýÈëÁËÒ»¸ö±»¶¯ºóÃÅ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/popular-wordpress-redirect-plugin-hid-dormant-backdoor-for-years/
5. ÇàÁúÃæ°åÆØÈÏÖ¤ÈÆ¹ý·ì϶£¬¹¥»÷Õ߿ɲ¿Êð¼ÓÃÜ¿ó¹¤
4ÔÂ29ÈÕ£¬ºÚ¿ÍÕýÔÚÀûÓÿªÔ´¹¤×÷µ÷¶È¹¤¾ßÇàÁúÃæ°åÖеÄÁ½¸öÈÏÖ¤ÈÆ¹ý·ì϶£¬ÔÚ¿ª·¢Õß·þÎñÆ÷Éϲ¿Êð¼ÓÃܿ󹤡£¡£¡£Á½¸ö°²È«ÎÊÌâÓ°ÏìÇàÁúÃæ°å2.20.1¼°¸üÔç°æ±¾£¬ÇÒÄܹ»´®ÁªÀûÓÃÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£CVE-2026-3965£º£ºÅäÖò»µ±µÄÖØÐ´¹æ¶¨½«/open/*ÒªÇóÓ³Éäµ½/api/*£¬ÎÞÒâÖÐͨ¹ýδ¾Éí·ÝÑéÖ¤µÄõ辶¶³öÁËÊܱ£»£»£»¤µÄÖÎÀíÔ±¶Ëµã¡£¡£¡£CVE-2026-4047£º£ºÈÏÖ¤²é³ÒÔ·Ö±æ¾Þϸд·½Ê½´¦ÖÃõè¾¶£¨/api/£©£¬¶øÂ·ÓÉÆ¥ÅäÔò²»·Ö¾Þϸд£¬ÕâÔÊÐí/aPi/...µÈÒªÇóÈÆ¹ýÈÏÖ¤²¢½Ó¼ûÊܱ£»£»£»¤µÄ¶Ëµã¡£¡£¡£Snyk»ã±¨³Æ£¬×Ô2ÔÂ7ÈÕÆð£¬¹¥»÷ÕßÒ»ÏòÔÚÕë¶Ô¹«¿ªÂ¶³öµÄÇàÁúÃæ°åÀûÓÃÕâÁ½¸ö·ì϶ÒÔ²¿Êð¼ÓÃܿ󹤡£¡£¡£¸Ã»î¶¯×î³õÓÉÇàÁúÓû§·¢ÏÖ£¬ËûÃǻ㱨³Æ´æÔÚÒ»¸öÃûΪ.fullgcµÄ¶ñÒâ°µ²Ø¹ý³Ì£¬Õ¼ÓÃÁË85%ÖÁ100%µÄCPU×ÊÔ´¡£¡£¡£¹¥»÷³ÖÐø½øÐУ¬ÔÚÔ̺¬NginxºÍSSL·´Ïò´úÀíºóµÄ¶àÖÖÅäÖû·¾³Öж¼È·ÈÏÁËϰȾ°¸Àý¡£¡£¡£¶øÇàÁúÊØ»¤ÕßÖ±µ½3ÔÂ1ÈղŶԴËÇé¿ö×÷³ö»ØÓ¦¡£¡£¡£½¨ÒéÈÔÔÚʹÓÃÒ×Êܹ¥»÷°æ±¾µÄÓû§Á¢¼´Éý¼¶µ½ÒÑÐÞ¸´°æ±¾£¬²¢²é³·þÎñÆ÷ÖÐÊÇ·ñ´æÔÚ¿ÉÒɵÄ.fullgc¹ý³Ì¼°·ÇÊÚȨÅäÖõ÷»»¡£¡£¡£
https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/
6. ¿ç¹ú¼ÓÃÜÇ®±ÒÚ¿ÆÍŻ︲Ãð£¬È«ÇòËðʧ³¬5000ÍòÅ·Ôª
4ÔÂ29ÈÕ£¬°ÂµØÀûºÍ°¢¶û°ÍÄáÑǵ±¾Ö½üÈÕµ·»ÙÁËÒ»¸ö±»Ö¸¿ØÔËÓª´ó¹æÄ£¼ÓÃÜÇ®±ÒͶ×ÊڿƵķ¸×ïÍŻ¸ÃÍÅ»ï¸øÈ«ÇòÊܺ¦ÕßÔì³ÉµÄ¾¼ÃËðʧ¹À¼Æ³¬¹ý5000ÍòÅ·Ôª£¨Ô¼ºÏ5850ÍòÃÀÔª£©¡£¡£¡£Õâ´Î½áºÏÐж¯Ê¼ÓÚ2023Äê6Ô£¬²¢µÃµ½ÁËÅ·ÖÞÐ̾¯×éÖ¯ºÍÅ·ÖÞ˾·¨×éÖ¯µÄÖ§³Ö£¬×îÖÕÓÚ4ÔÂ17ÈÕ¿ÛÁôÁË10ÃûÏÓÒÉÈË£¬²¢¶ÔÈý¸öºô½ÐÖÐÐĺ;Ŵ¦¸öÈËסËù½øÐÐÁËËѲ顣¡£¡£Ðж¯ÖУ¬·¨ÂÉÈËÔ±½É»ñÁË891,735Å·ÔªÏÖ½ð¡¢443̨µçÄÔ¡¢238²¿ÊÖ»ú¡¢6̨±Ê¼Ç±¾µçÄÔÒÔ¼°¶àÖÖÊý¾Ý´æ´¢É豸ÒÔ¹©È¡Ö¤²é³¡£¡£¡£¸ÃÚ¿ÆÍÅ»ïѡȡÀàËÆºÏ·¨ÆóÒµµÄģʽÔËÓª£¬¹ÍÓ¶¶à´ï450ÃûÔ±¹¤£¬·ÖÊô¿Í»§»ñÈ¡¡¢¿Í»§Î¬Ïµ¡¢²ÆÕþ¡¢ITºÍÈËÁ¦×ÊÔ´µÈ²¿ÃÅ¡£¡£¡£Êܺ¦Õßͨ¹ýËÑË÷ÒýÇæºÍÉ罻ýÌåÉϵĸæ°×±»ÓÕÆÖÁÐéαµÄ¼ÓÃÜÇ®±ÒͶ×ÊÆ½Ì¨£¬Ëæºó±»·ÖÅ䏸ËùνµÄ¡°¿Í»§Î¬Ïµ×¨Ô±¡±£¬ÕâЩרԱÖÎÀíÊܺ¦ÕßµÄͶ×ÊÕË»§£¬³£Ê¹ÓÃÔ¶³Ì½Ó¼ûÈí¼þ½ÚÖÆÊܺ¦ÕßÉ豸£¬²¢Í¨¹ýÉúÀíʩѹÓÕÆÊܺ¦Õß×·¼Ó´æ¿î¡£¡£¡£È»¶ø£¬Êܺ¦ÕßµÄ×ʽð´ÓÎ´ÕæÕý±»Í¶×Ê£¬¶øÊDZ»×ªÈëÒ»¸ö¹ú¼ÊÏ´Ç®´òË㣬×îÖÕÁ÷Èë·¸×ïÍøÂçµÄÕË»§¡£¡£¡£ÔÚ¶þ´ÎÚ¿ÆÖУ¬·¸×ï·Ö×ÓÔÙ´ÎÁªÏµÊܺ¦Õߣ¬Ðû³Æ¿ÉÔ®ÊÖ×·»ØËðʧ£¬µ«ÒªÇóÏÈÏò¼ÓÃÜÇ®±ÒÕË»§´æÈë500Å·Ôª×÷ΪÈ볡·Ñ£¬´Ó¶ø¶ÔÊܺ¦ÕßÖ´Ðжþ´Îڲơ£¡£¡£
https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/


¾©¹«Íø°²±¸11010802024551ºÅ