CybleÅû¶ÀûÓÃαÔìChatGPTÓ¦Ó÷ַ¢¶ñÒâÈí¼þµÄ»î¶¯

Ðû²¼Ê±¼ä 2023-02-24

1¡¢CybleÅû¶ÀûÓÃαÔìChatGPTÓ¦Ó÷ַ¢¶ñÒâÈí¼þµÄ»î¶¯


2ÔÂ22ÈÕ£¬Cyble³Æ»ùÓÚChatGPTµÄµöÓã¹¥»÷µÄÍþвԽÀ´Ô½´ó¡£ChatGPT×Ô2022Äê11ÔÂÍƳöÒÔÀ´»ñµÃÁ˾޴óµÄÀֳɣ¬µ½2023Äê1ÔÂÓû§ÒÑÁè¼Ý1ÒÚ¡£Cyble¼ì²âµ½Á˶à¸öµöÓãÍøÕ¾£¬ËüÃÇÕýÔÚͨ¹ýÆÛÕ©ÐÔµÄOpenAIÉ罻ýÌåÒ³Ãæ½øÐÐÍƹ㣬À´Á÷´«ÖÖÖÖÀàÐ͵ĶñÒâÈí¼þ¡£´ËÍ⣬һЩµöÓãÍøÕ¾ÕýÔÚð³äChatGPTÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢¡£Ñо¿ÈËÔ±»¹¼ì²âµ½50¶à¸öʹÓÃChatGPTͼ±êµÄ¼ÙðºÍ¶ñÒâÓ¦Óã¬ÈçÀ¬»ø·¨Ê½¡¢¹ã¸æÈí¼þºÍ¼äµýÈí¼þµÈ¡£


https://blog.cyble.com/2023/02/22/the-growing-threat-of-chatgpt-based-phishing-attacks/


2¡¢ÐµÄS1deload Stealer½Ù³ÖYoutubeºÍFacebookÕÊ»§


BitdefenderÔÚ2ÔÂ22ÈÕÅû¶ÁËжñÒâÈí¼þS1deload StealerÕë¶ÔÈ«ÇòµÄ¹¥»÷»î¶¯¡£ÔÚ2022Äê7Ôµ½12Ô£¬Bitdefender¼ì²âµ½600¶à¸öÓû§Ñ¬È¾ÁËÕâÖÖ¶ñÒâÈí¼þ¡£S1deload StealerÒÀ¿¿DLL²àÔؼ¼ÊõÀ´ÔËÐÐÆä¶ñÒâ×é¼þ£¬Ê¹ÓÃÁËÒ»¸öºÏ·¨µÄ¡¢¾­¹ýÊý×ÖÇ©ÃûµÄ¿ÉÖ´ÐÐÎļþ¡£Ò»µ©ÀÖ³ÉѬȾ£¬¸Ã¶ñÒâÈí¼þ¾Í»áÇÔÈ¡Óû§Æ¾Ö¤£¬Ä£·ÂÈËÀàÐÐΪÀ´Ìá¸ßÊÓƵºÍÆäËüÄÚÈݵļÓÈë¶È£¬ÆÀ¹À¸öÈËÕË»§µÄ¼ÛÖµ£¬ÍÚ¾òBEAM¼ÓÃÜ»õ±Ò£¬²¢½«¶ñÒâÁ´½ÓÁ÷´«¸øÓû§µÄ·ÛË¿¡£


https://www.bitdefender.com/blog/labs/s1deload-stealer-exploring-theeconomics-of-social-networkaccount-hijacking/


3¡¢OyeTalk»áй¶Óû§µÄÁÄÌì¼Ç¼Òѱ»°²×°Áè¼Ý500Íò´Î


¾ÝýÌå2ÔÂ22ÈÕ±¨µÀ£¬AndroidÓïÒôÁÄÌìÓ¦ÓÃй¶ÁËÓû§µÄÁÄÌì¼Ç¼¡£¸ÃÓ¦ÓÃÔÚGoogle PlayÉϵÄÏÂÔØÁ¿Áè¼Ý500Íò´Î£¬ÆäFirebaseʵÀýй¶ÁËÁè¼Ý500MBµÄÊý¾Ý£¬°üÂÞδ¼ÓÃܵÄÓû§ÁÄÌì¼Ç¼¡¢Óû§ÃûºÍÊÖ»ú¹ú¼ÊÒƶ¯É豸ʶ±ðÂë(IMEI)ºÅÂëµÈ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬Èç¹ûûÓжÔ鶵ÄÊý¾Ý½øÐб¸·Ý£¬¹¥»÷Õß¿ÉÄÜ»áɾ³ýÊý¾Ý¿âµ¼ÖÂÓû§µÄ¸öÈËÐÅÏ¢ÓÀ¾Ã¶ªÊ§¡£Ó¦ÓõĿª·¢ÈËÔ±ÔÚ»ñϤÊý¾Ýй¶ºóÈÔδÄÜÏÞÖÆÊý¾Ý¿âµÄ·ÃÎÊ£¬¹È¸è²»µÃ²»½éÈëÉè·¨±£»¤¸ÃÊý¾Ý¿â¡£


https://www.hackread.com/android-voice-chat-app-data-leak/


4¡¢Ñо¿ÈËÔ±¼ì²âµ½41¸öαװ³ÉHTTP¿âµÄ¶ñÒâPyPI°ü


¾Ý2ÔÂ22ÈÕ±¨µÀ£¬ReversingLabsÑо¿ÈËÔ±ÔÚPyPI´æ´¢¿âÖмì²âµ½41¸öαװ³ÉHTTP¿âµÄ¶ñÒâ°ü¡£ÕâЩαÔìµÄHTTP¿âÖаüÂÞÁ½ÖÖ²îÒìÀàÐ͵ĶñÒâÄ £¿é£ºÏÂÔØ·¨Ê½£¬ÓÃÓÚÏò±»¹¥»÷µÄϵͳÌṩµÚ¶þ½×¶ÎµÄ¶ñÒâÈí¼þ£»ÐÅÏ¢ÇÔÈ¡·¨Ê½£¬°üÂÞÓÃÓÚÊý¾Ýй¶µÄ¶ñÒ⹦Ч¡£ÀýÈ磬ÐÅÏ¢ÇÔÈ¡·¨Ê½httpxv2¿ÉÊÕ¼¯ÃÜÂëºÍÁîÅƵÈÃô¸ÐÊý¾Ý²¢·¢Ë͸ø¹¥»÷Õߣ¬ÏÂÔØ·¨Ê½httpsus½«¿ÉÒɵÄpayloadÒþ²ØÆðÀ´¡£


https://www.reversinglabs.com/blog/beware-impostor-http-libraries-lurk-on-pypi


5¡¢ÐºóÃÅWinorDLL64»ò±»LazarusÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢


¾ÝESET 2ÔÂ23ÈÕ±¨µÀ£¬Lazarus Group¿ÉÄÜʹÓÃÁËÓëWslinkÏà¹ØµÄкóÃÅWinorDLL64¡£WinorDLL64ÊÇÒ»¸ö¹¦Ð§ÆëÈ«µÄÖ²È뷨ʽ£¬¿ÉÒÔй¶¡¢ÁýÕÖºÍɾ³ýÎļþ£¬Ö´ÐÐPowerShellÃüÁ²¢»ñÈ¡´óÁ¿ÏµÍ³Ïà¹ØÐÅÏ¢¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ÒòΪWinorDLL64ÔÚ¿ª·¢»·¾³¡¢ÐÐΪºÍ´úÂëÖÐÓë¶à¸öLazarusµÄÑù±¾ÓÐËùÖصþ£¬Õâ±íÃ÷Ëü¿ÉÄÜÊÇÕâ¸öAPT×éÖ¯µÄÎäÆ÷¿âÖеÄÒ»²¿ÃÅ¡£


https://www.welivesecurity.com/2023/02/23/winordll64-backdoor-vast-lazarus-arsenal/


6¡¢SynopsysÐû²¼2023Ä꿪ԴÄþ¾²ºÍ·çÏյķÖÎö³ÂËß


ýÌå2ÔÂ22Èճƣ¬SynopsysÊÓ²ìÁË17¸öÐÐÒµÖÐÔ¼1700¸ö´úÂë¿âÖз¢Ïֵĩ¶´ºÍÐí¿É³åÍ»£¬Ðû²¼Á˹ØÓÚ2023Ä꿪ԴÄþ¾²ºÍ·çÏյķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬84%µÄ´úÂë¿â°üÂÞÖÁÉÙÒ»¸öÒÑÖªµÄ¿ªÔ´Â©¶´£¬ÓëÈ¥ÄêÏà±ÈÔö³¤Á˽ü4%¡£ËäÈ»×ÜÌ婶´ÂÔÓÐÉÏÉý£¬µ«¾ßÓи߷çÏÕ©¶´µÄ´úÂë¿âµÄÕ¼±ÈÁ¦Ö®È¥ÄêϽµÁË2%£¬½µÖÁ48%¡£½ÌÓý¿Æ¼¼ÐÐÒµ½ÓÄÉ¿ªÔ´´úÂëµÄ±ÈÀýÔö³¤ÁË163%£¬Æä´ÎÊǺ½¿Õº½Ìì¡¢º½¿Õ¡¢Æû³µ¡¢ÔËÊäºÍÎïÁ÷ÐÐÒµ(97%)ÒÔ¼°ÖÆÔìÒµºÍ»úÆ÷È˼¼Êõ(74%)¡£


https://www.synopsys.com/software-integrity/resources/analyst-reports/open-source-security-risk-analysis.html