¼Ùð°ÍÁÖÕþ¸® Android Ó¦Ó÷¨Ê½ÇÔÈ¡Êý¾ÝÓÃÓÚÕ©Æ
Ðû²¼Ê±¼ä 2024-06-046ÔÂ2ÈÕ£¬Ðí¶àÕþ¸®»ú¹¹¶¼ÔÚÏßÌṩ·þÎñ£¬ÒÔ·½±ã¹«Ãñ¡£´ËÍ⣬Èç¹û¿ÉÒÔͨ¹ýÒƶ¯Ó¦Ó÷¨Ê½ÌṩÕâÏî·þÎñ£¬½«·Ç³£·½±ãºÍ±ã½Ý¡£µ«ÊÇ£¬µ±¶ñÒâÈí¼þαװ³ÉÕâЩ·þÎñʱ»á·¢Éúʲô£¿McAfee Òƶ¯Ñо¿ÍŶӷ¢ÏÖÁËÒ»¿îαװ³É°ÍÁÖÕþ¸®»ú¹¹·þÎñµÄ InfoStealer Android ¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þαװ³É°ÍÁֵĹٷ½Ó¦Ó÷¨Ê½£¬²¢Ðû´«Óû§¿ÉÒÔÔÚÊÖ»úÉϸüлòÉêÇë¼ÝʻִÕÕ¡¢Ç©Ö¤ºÍÉí·ÝÖ¤¡£±»¹ã¸æÆÛƵÄÓû§»áºÁ²»ÓÌÔ¥µØ»ñµÃÕâЩ·þÎñËùÐèµÄ¸öÈËÐÅÏ¢¡£ËüÃÇͨ¹ýÖÖÖÖ·½Ê½½Ó´¥Óû§£¬°üÂÞ Facebook ºÍ¶ÌÐÅ¡£²»ÊìϤÕâЩ¹¥»÷µÄÓû§ºÜÈÝÒ×·¸Ï·¢Ë͸öÈËÐÅÏ¢µÄ´íÎó¡£°ÍÁÖÓÐÒ»¸öÕþ¸®»ú¹¹£¬ÃûΪÀͶ¯Á¦Êг¡¼à¹Ü¾Ö (LMRA)¡£¸Ã»ú¹¹ÔÚÓÉÀ͹¤²¿³¤µ£ÈÎÖ÷ϯµÄ¶Ê»áÖ¸µ¼Ï£¬ÓµÓÐÍêÈ«µÄ²ÆÕþºÍÐÐÕþ¶ÀÁ¢ÐÔ¡£ËûÃÇÌṩÖÖÖÖÒƶ¯·þÎñ£¬´ó¶àÊýÓ¦Ó÷¨Ê½Ö»ÌṩһÏî·þÎñ¡£È»¶ø£¬Õâ¸ö¼ÙðӦÓ÷¨Ê½È´Ðû´«Ìṩ¶àÏî·þÎñ¡£³ýÁË×î³£¼ûµÄð³ä LMRA µÄ¼ÙðӦÓÃÍ⣬»¹ÓÐÖÖÖÖ¼ÙðӦÓ㬰üÂÞ°ÍÁֺͿÆÍþÌØÒøÐÐ (BBK)¡¢°ÍÁÖ½ðÈڿƼ¼¹«Ë¾ BenefitPay£¬ÉõÖÁ»¹ÓмÙ×°Óë±ÈÌرһò´û¿îÏà¹ØµÄÓ¦Óá£ÕâЩӦÓÃʹÓÃÓë LMRA ¼ÙðӦÓÃÏàͬµÄ¼¼ÊõÀ´ÇÔÈ¡¸öÈËÐÅÏ¢¡£
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/
2. SHINYHUNTERSÕýÔÚ³öÊÛ3000Íòɣ̹µÂÒøÐпͻ§µÄÊý¾Ý
6ÔÂ2ÈÕ£¬ÎÛÃûÕÑÖøµÄÍþвÐÐΪÕß ShinyHunters ÕýÔÚ³öÊ۾ݳƴÓɣ̹µÂÒøÐÐÇÔÈ¡µÄ´óÁ¿Êý¾Ý¡£ShinyHunters Éù³ÆÇÔÈ¡ÁË 3000 Íò¿Í»§¡¢Ô±¹¤ºÍÒøÐÐÕË»§Êý¾Ý¡£5 ÔÂÖÐÑ®£¬Î÷°àÑÀ½ðÈÚ»ú¹¹É£Ì¹µÂÒøÐÐÅû¶ÁËÒ»ÆðÉæ¼°µÚÈý·½ÌṩÉ̵ÄÊý¾Ýй¶Ê¼þ£¬Ó°ÏìÁËÖÇÀû¡¢Î÷°àÑÀºÍÎÚÀ¹çµÄ¿Í»§¡£¸ÃÒøÐз¢ÏÖµÚÈý·½ÌṩÉÌÍйܵÄÆäÖÐÒ»¸öÊý¾Ý¿âÔ⵽δ¾ÊÚȨµÄ·ÃÎÊ¡£¸Ã¹«Ë¾Ðû²¼Á¢¼´½ÓÄÉ´ëÊ©¿ØÖÆʼþ¡£¸Ã¹«Ë¾×èÖ¹Á˶ÔÊý¾Ý¿âµÄÈëÇÖ·ÃÎÊ£¬²¢½¨Á¢ÁËÌرðµÄÆÛÕ©Ô¤·À¿ØÖÆ´ëÊ©À´±£»¤ÊÜÓ°ÏìµÄ¿Í»§¡£±»µÁÊý¾Ý¿â°üÂÞËùÓÐÏÖÈκͲ¿ÃÅÇ°ÈÎÔ±¹¤µÄÐÅÏ¢¡£¸ÃÒøÐÐÖ¸³ö£¬¸ÃÊý¾Ý¿â²»´æ´¢½»Ò×Êý¾Ý¡¢ÍøÉÏÒøÐÐÏêϸÐÅÏ¢¡¢ÃÜÂë»òÆäËûÔÊÐíijÈ˽øÐн»Ò×µÄÊý¾Ý¡£¸Ã½ðÈÚ»ú¹¹ÉÐδÌṩ´Ë´ÎʼþµÄ¼¼Êõϸ½Ú»ò鶵ÄÊý¾ÝÖÖÀࡣĿǰÉв»Çå³þÓм¸¶àÈËÊܵ½Ó°Ïì¡£ShinyHunters Éù³Æ Ticketmaster Ôâµ½ºÚ¿Í¹¥»÷£¬²¢ÒÔ 50 ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛ 1.3 TB µÄÊý¾Ý£¬ÆäÖаüÂÞ 5.6 ÒÚ¿Í»§µÄÍêÕûÏêϸÐÅÏ¢¡£±»µÁÊý¾Ý°üÂÞÐÕÃû¡¢µç×ÓÓʼþ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÃÅƱÏúÊۺͶ©µ¥ÏêϸÐÅÏ¢¡£
https://securityaffairs.com/163956/data-breach/shinyhunters-claims-santander-breach.html
3. CISA ¾¯¸æ³Æ Linux ÌØȨÌáÉý©¶´¿ÉÄܱ»»ý¼«ÀûÓÃ
6ÔÂ2ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö (CISA) ÔÚÆäÒÑÖªÀûÓ鶴 (KEV) Ŀ¼ÖÐÌí¼ÓÁËÁ½¸ö©¶´£¬ÆäÖаüÂÞ Linux ÄÚºËȨÏÞÌáÉý©¶´¡£¸Ã¸ßÑÏÖØÐÔ©¶´ ( CVE-2024-1086)ÓÚ 2024 Äê 1 Ô 31 ÈÕÊ×´ÎÅû¶£¬ÊÇ netfilter£ºnf_tables ×é¼þÖеÄÊͷźóʹÓÃÎÊÌ⣬µ«×îÔçÊÇÔÚ 2014 Äê 2 ÔµÄÒ»´ÎÌá½»ÖÐÒýÈëµÄ¡£Netfilter ÊÇ Linux ÄÚºËÌṩµÄÒ»¸ö¿ò¼Ü£¬ÔÊÐíÖÖÖÖÓëÍøÂçÏà¹ØµÄ²Ù×÷£¬ÀýÈçÊý¾Ý°ü¹ýÂË¡¢ÍøÂçµØַת»» (NAT) ºÍÊý¾Ý°üÐ޸ġ£¸Ã©¶´ÊÇÓÉÓÚ 'nft_verdict_init()' º¯ÊýÔÊÐí½«ÕýÖµÓÃ×÷¹³×ÓÅоöÖеÄɾ³ý´íÎ󣬴Ӷøµ¼Ö 'nf_hook_slow()' º¯ÊýÔÚ NF_DROP ·¢³öÀàËÆÓÚ NF_ACCEPT µÄɾ³ý´íÎóʱִÐÐË«ÖØÊÍ·Å¡£ÀûÓà CVE-2024-1086 ¿ÉÈþßÓе±µØ·ÃÎÊȨÏ޵Ĺ¥»÷ÕßÔÚÄ¿±êϵͳÉÏʵÏÖȨÏÞÌáÉý£¬²¢¿ÉÄÜ»ñµÃ root ¼¶·ÃÎÊȨÏÞ¡£
https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-linux-privilege-elevation-flaw/
4. Ðé¼Ùä¯ÀÀÆ÷¸üлáÁ÷´«BitRATºÍLumma Stealer¶ñÒâÈí¼þ
6ÔÂ3ÈÕ£¬Ðé¼ÙµÄÍøÂçä¯ÀÀÆ÷¸üб»ÓÃÓÚÁ÷´«Ô¶³Ì·ÃÎÊľÂí (RAT) ºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬ÀýÈçBitRATºÍLumma Stealer£¨ÓÖÃû LummaC2£©¡£µ±Ç±ÔÚÄ¿±ê·ÃÎÊÒ»¸ö´øÓÐÏÝÚåµÄÍøվʱ£¬¹¥»÷Á´¾Í¿ªÊ¼ÁË£¬¸ÃÍøÕ¾°üÂÞÖ¼ÔÚ½«Óû§Öض¨Ïòµ½Ðé¼Ùä¯ÀÀÆ÷¸üÐÂÒ³Ã棨¡°chatgpt-app[.]cloud¡±£©µÄ JavaScript ´úÂë¡£Öض¨ÏòµÄÍøҳǶÈëÁËÖ¸Ïò ZIP ´æµµÎļþ£¨¡°Update.zip¡±£©µÄÏÂÔØÁ´½Ó£¬¸ÃÎļþÍйÜÔÚ Discord Éϲ¢×Ô¶¯ÏÂÔص½Êܺ¦ÕßµÄÉ豸¡£ÖµµÃÖ¸³öµÄÊÇ£¬ÍþвÐÐΪÕß¾³£Ê¹Óà Discord ×÷Ϊ¹¥»÷ý½é£¬ Bitdefender×î½üµÄ·ÖÎö·¢ÏÖ£¬ÔÚ¹ýÈ¥Áù¸öÔÂÖУ¬ÓÐÁè¼Ý 50,000 ¸öΣÏÕÁ´½ÓÁ÷´«¶ñÒâÈí¼þ¡¢ÍøÂçµöÓã»î¶¯ºÍÀ¬»øÓʼþ¡£ZIP ´æµµÎļþÖдæÔÚÁíÒ»¸ö JavaScript Îļþ£¨¡°Update.js¡±£©£¬Ëü»á´¥·¢ PowerShell ½Å±¾µÄÖ´ÐУ¬¸Ã½Å±¾ÂôÁ¦´ÓÔ¶³Ì·þÎñÆ÷ÒÔ PNG ͼÏñÎļþµÄÐÎʽ¼ìË÷ÆäËûÓÐЧ¸ºÔØ£¬°üÂÞ BitRAT ºÍ Lumma Stealer¡£
https://thehackernews.com/2024/06/beware-fake-browser-updates-deliver.html
5. ¾¯·½µ·»ÙµÁ°æµçÊÓÁ÷ýÌåÍøÂçÒѾ»ñÀû570ÍòÃÀÔª
6ÔÂ3ÈÕ£¬Î÷°àÑÀ¾¯·½µ·»ÙÁËÒ»¸ö·Ç·¨Ã½ÌåÄÚÈÝÁ÷´«ÍøÂ磬¸ÃÍøÂç×Ô 2015 Ä꿪ʼÔËÓªÒÔÀ´ÒÑ»ñÀûÁè¼Ý 570 ÍòÃÀÔª¡£¸ÃÊÓ²ìÓÚ 2022 Äê 11 Ô¿ªÊ¼£¬Æäʱ´´ÒâÓëÓéÀÖÁªÃË (ACE) Ìá½»ÁËÒ»·ÝͶËߣ¬¾Ù±¨Á½¸öÍøÒ³ÇÖ·¸ÁË֪ʶ²úȨ¡£ÕâЩÍøÕ¾ÍйÜ×Å·Ç·¨ IPTV ·þÎñ¡°TVMucho¡±£¨Ò²³ÆΪ¡°Teeveeing¡±£©£¬¾Ý ACE ³Æ£¬¸Ã·þÎñÔÚ 2023 ÄêµÄ·ÃÎÊÁ¿Áè¼Ý 400 Íò´Î¡£¾¯·½ÊÓ²ìºó·¢ÏÖ£¬ÕâЩÍøÕ¾µÄËùÓÐÕß±³ºóÓÐÒ»¸ö´ó¹æÄ£µÄ IPTV Ðж¯£¬ÎªÔ¼Äª 14,000 ÃûÓû§Ìṩ 130 ¸ö¹ú¼ÊµçÊÓƵµÀºÍÊýǧ²¿Ó°Ï·ºÍµçÊÓ¾çµÄ·Ç·¨·ÃÎÊȨÏÞ¡£¸Ã·þÎñµÄÓû§Æ¾¾ÝÆ䶩ÔÄÆ·¼¶Ö§¸¶Ã¿Ô 11 ÖÁ 20.5 ÃÀÔª»òÿÄê 97 ÖÁ 182.5 ÃÀÔª£¬ÕâʹµÃ IPTV ƽ̨ÔËÓªÉÌ×ܹ²»ñÀû 570 ÍòÃÀÔª¡£
https://www.bleepingcomputer.com/news/legal/police-dismantle-pirated-tv-streaming-network-that-made-57-million/
6. Hugging Face ³ÆºÚ¿Í´Ó Spaces ÇÔÈ¡Éí·ÝÑéÖ¤ÁîÅÆ
6ÔÂ2ÈÕ£¬È˹¤ÖÇÄÜƽ̨ Hugging Face ÌåÏÖÆä Spaces ƽ̨Ôâµ½ÈëÇÖ£¬ºÚ¿ÍµÃÒÔ»ñÈ¡Æä³ÉÔ±µÄÉí·ÝÑéÖ¤»úÃÜ¡£Hugging Face Spaces ÊÇÒ»¸öÓÉÉçÇøÓû§´´½¨ºÍÌá½»µÄ AI Ó¦Ó÷¨Ê½¿â£¬ÔÊÐíÆäËû³ÉÔ±ÑÝʾËüÃÇ¡£Hugging Face ÌåÏÖ£¬ËûÃÇÒѾȡÏûÁË鶻úÃÜÖеÄÉí·ÝÑéÖ¤ÁîÅÆ£¬²¢Í¨¹ýµç×ÓÓʼþ֪ͨÁËÊÜÓ°ÏìµÄÓû§¡£µ«ÊÇ£¬ËûÃǽ¨ÒéËùÓÐ Hugging Face Spaces Óû§Ë¢ÐÂËûÃǵÄÁîÅƲ¢Çл»µ½ ϸÁ£¶È·ÃÎÊÁîÅÆ£¬ÕâʹµÃ×éÖ¯¿ÉÒÔ¸üÑϸñµØ¿ØÖÆËÓÐȨ·ÃÎÊËûÃÇµÄ AI Ä£ÐÍ¡£¸Ã¹«Ë¾ÕýÔÚÓëÍⲿÍøÂçÄþ¾²×¨¼ÒºÏ×÷ÊÓ²ì´Ë´ÎÎ¥¹æÐÐΪ£¬²¢ÏòÖ´·¨ºÍÊý¾Ý±£»¤»ú¹¹³ÂË߸Ãʼþ¡£
https://www.bleepingcomputer.com/news/security/ai-platform-hugging-face-says-hackers-stole-auth-tokens-from-spaces/