Strava½¡ÉíÓ¦Óñ»ÆØ鶶à¹ú×Üͳ°²±£ÈËԱλÖÃÐÅÏ¢

Ðû²¼Ê±¼ä 2024-10-31

1. Strava½¡ÉíÓ¦Óñ»ÆØ鶶à¹ú×Üͳ°²±£ÈËԱλÖÃÐÅÏ¢


10ÔÂ29ÈÕ £¬StravaÊÇÒ»¿îÈ«Çò¹ãÊÜ»¶Ó­µÄ½¡ÉíÓ¦Ó÷¨Ê½ £¬ÓµÓÐ1.2ÒÚÓû§ £¬Äܹ»¼Ç¼Åܲ½¡¢ÆïÐеÈÔ˶¯¹ì¼£¡£È»¶ø £¬·¨¹úýÌ塶ÊÀ½ç±¨¡··¢ÏÖ £¬Strava´æÔÚй¶Ãô¸ÐλÖÃÐÅÏ¢µÄ·çÏÕ £¬°üÂÞÃÀ¹ú×Üͳ¼°Æ侺ѡÈ˵ÄÌùÉí°²±£ÈËԱλÖ᣾ݱ¨µÀ £¬ÖÁÉÙ26ÃûÃÀ¹úÌع¤ÔÚStravaÉÏÓµÓй«¹²ÕË»§ £¬ÇÒÔÚÌØÀÊÆÕÔâÓöıº¦Î´ËìʼþºóÈÔ»îÔ¾ÓÚ¸Ãƽ̨¡£´ËÍâ £¬·¨¹úºÍ¶íÂÞ˹µÄ×Üͳ°²±£ÈËÔ±Ò²±»·¢ÏÖʹÓøÃÓ¦Óà £¬Éæ¼°12Ãû·¨¹úGSPR³ÉÔ±ºÍ6Ãû¶íÂÞ˹FSO³ÉÔ±¡£ÕâЩÄþ¾²ÈËÔ±ÔÚStravaÉϵÄÐж¯¿ÉÄܵ¼ÖÂÄþ¾²Â©¶´ £¬ÒòΪËûÃǵÄÔ˶¯¹ì¼£¿ÉÄÜ̻¶Áìµ¼ÈËÏÂ齺ͻáÒéËùÔÚµÄÐÅÏ¢ £¬ÉõÖÁ¸öÈËÉú»îϸ½ÚÒ²¿ÉÄܱ»¶ñÒâÀûÓ᣾¡¹ÜÃÀ¹úÌØÇھֺͷ¨¹ú×Üͳ¹Ù·½»ú¹¹¶Ô´Ë½øÐÐÁË»ØÓ¦ £¬³ÆʹÓÃStrava²»»á¶Ô°²±£Ðж¯×é³ÉÍþв £¬µ«´ËÇ°StravaÐû²¼µÄÈ«Çò½¡ÉíÈÈÇøͼ¾ÍÔø̻¶ÃÀ¾üÔÚÖж«µØÓòµÄ»úÃܻλÖà £¬Òý·¢ÕùÒé¡£´ËÍâ £¬½¡ÉíÓ¦Ó÷¨Ê½Êý¾Ý»¹¿ÉÄܱ»¹¥»÷ÕßÓÃÓÚ×·×ÙDZÔÚÊܺ¦Õß £¬Ôö¼Ó¸ú×Ù¡¢ÇÀ½ÙµÈ·¸×ï·çÏÕ¡£Òò´Ë £¬Ê¹ÓôËÀàÓ¦ÓÃʱÐè½÷É÷ £¬ÖÆֹй¶Ãô¸ÐÐÅÏ¢¡£


https://cybernews.com/news/fitness-app-strava-location-biden-trump-harris/


2. Metaƽ̨Ôâ¶ñÒâ¹ã¸æ»î¶¯ÇÖÏ® £¬SYS01ÐÅÏ¢ÇÔÈ¡·¨Ê½È«ÇòËÁÅ°


10ÔÂ30ÈÕ £¬Ò»ÏîеĶñÒâ¹ã¸æ»î¶¯ÕýÔÚÀûÓà Meta ƽ̨Á÷´« SYS01 ÐÅÏ¢ÇÔÈ¡·¨Ê½ £¬¸Ã·¨Ê½×¨ÃÅÕë¶Ô 45 ËêÒÔÉϵÄÄÐÐÔÓû§ £¬Í¨¹ýαװ³ÉÁ÷ÐÐÈí¼þ¡¢ÓÎÏ·ºÍÔÚÏß·þÎñµÄÐé¼Ù¹ã¸æ½øÐй¥»÷¡£¸Ã»î¶¯×Ô 2024 Äê 9 ÔÂÊ״α»·¢ÏÖÒÔÀ´ £¬ÒÑÔÚÈ«Çò·¶Î§ÄÚÔì³É¹ã·ºÓ°Ïì £¬°üÂÞÅ·ÃË¡¢±±ÃÀ¡¢°Ä´óÀûÑǺÍÑÇÖ޵ȵØ¡£SYS01 ·¨Ê½»áÇÔÈ¡ Facebook ƾ֤ £¬ÌرðÊǹÜÀíÉÌÒµÒ³ÃæµÄÕË»§ £¬²¢ÀûÓÃÕâЩÕË»§½øÒ»²½Á÷´«¹¥»÷¡£¹¥»÷Õßͨ¹ý MediaFire Á´½ÓÌṩ¿´ËƺϷ¨µÄÈí¼þÏÂÔØ £¬ÕâЩÏÂÔØÄÚÈÝ°üÂÞ¶ñÒâµÄ Electron Ó¦Ó÷¨Ê½ £¬Ò»µ©Ö´ÐÐ £¬¾Í»áÖ²Èë²¢ÔËÐÐ SYS01 ·¨Ê½¡£¸Ã·¨Ê½½áºÏÁË·´É³ºÐ¼ì²éÒÔÌӱܼì²â £¬²¢»áÌáÈ¡°üÂÞºËÐĶñÒâÈí¼þ×é¼þµÄÊÜÃÜÂë± £»¤µÄ´æµµ¡£±»µÁÕË»§²»½öÓÃÓÚ½øÒ»²½¹¥»÷/Õ©Æ­ £¬»¹±»ÓÃÀ´ÖÆ×÷жñÒâ¹ã¸æ £¬ÈƹýÄþ¾²¹ýÂËÆ÷ £¬ÐγÉÒ»¸ö×ÔÎÒά³ÖµÄÑ­»·¡£Òò´Ë £¬Óû§ÔÚ Facebook ÉÏ £¬ÓÈÆäÊÇÔËÓªÉÌÒµÒ³ÃæµÄÓû§ £¬±ØÐ뾯Ìè´ËÀàÍþв¡£


https://hackread.com/fake-meta-ads-hijacking-facebook-sys01-infostealer/


3. ÃسInterbankÔâÊý¾Ýй¶ £¬ºÚ¿ÍÉù³ÆÇÔÈ¡300Íò¿Í»§ÐÅÏ¢


10ÔÂ30ÈÕ £¬Ãس֪Ãû½ðÈÚ»ú¹¹Interbank½üÆÚÔâÓöÊý¾Ýй¶Ê¼þ £¬Ò»ÃûÍþвÐÐΪÕßÈëÇÖÆäϵͳ²¢ÍµÈ¡ÁË¿Í»§Êý¾Ý £¬ËæºóÔÚÍøÉϽøÐÐй¶¡£¾¡¹ÜInterbankδ͸¶¾ßÌåÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿ £¬µ«Dark Web Informer·¢ÏÖ £¬Ò»ÃûʹÓá°kzoldyck¡±Óû§ÃûµÄºÚ¿ÍÕýÔÚ¶à¸öÂÛ̳³öÊ۾ݳƴӸÃÒøÐÐÇÔÈ¡µÄÊý¾Ý¡£¾ÝºÚ¿ÍÉù³Æ £¬ËûÃÇÄܹ»»ñÈ¡Interbank¿Í»§µÄÈ«Ãû¡¢ÕË»§ID¡¢³öÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ºÍIPµØÖ·µÈÃô¸ÐÐÅÏ¢ £¬ÒÔ¼°ÐÅÓÿ¨ÐÅÏ¢¡¢ÒøÐн»Ò×Êý¾ÝµÈ £¬×ÜÁ¿Áè¼Ý3.7TB¡£´ËÍâ £¬ºÚ¿Í»¹Éù³ÆÓµÓпͻ§µÄÃ÷È·Óû§ÃûºÍÃÜÂëÐÅÏ¢ £¬¿ÉÒÔ´ÓÃسIP¿é·ÃÎÊÒøÐÐÕË»§¡£ºÚ¿ÍÌåÏÖ £¬ËûÃÇÁ½ÖÜÇ°ÔøʵÑéÓëInterbank¹ÜÀí²ã̸Åе«Î´¹û £¬Òò´Ë¾ö¶¨¹ûȻй¶Êý¾Ý¡£InterbankÒÑÈ·ÈÏ·¢ÉúÊý¾Ýй¶ £¬²¢ÌåÏÖÒѲ¿ÊðÌرðÄþ¾²´ëÊ©± £»¤¿Í»§ÐÅÏ¢ºÍÔËÓª £¬Í¬Ê±±£Ö¤¿Í»§´æ¿îÄþ¾² £¬²¢Ö¸³ö´ó¶àÊýÒµÎñÇþµÀÒѻָ´ÔÚÏß¡£


https://www.bleepingcomputer.com/news/security/interbank-confirms-data-breach-following-failed-extortion-data-leak/


4. ³¯ÏʺڿÍ×éÖ¯AndarielÉæÏÓ¼ÓÈëPlayÀÕË÷Èí¼þÐж¯²¢ÌÓ±ÜÖƲÃ


10ÔÂ30ÈÕ £¬³¯Ïʹú¼ÒÖ§³ÖµÄºÚ¿Í×éÖ¯Andariel±»×·×ÙÓëPlayÀÕË÷Èí¼þÐж¯ÓйØÁª £¬¾ÝPalo Alto Networks¼°ÆäUnit 42Ñо¿ÈËÔ±µÄ³ÂËß³Æ £¬Andariel¿ÉÄÜÊÇPlayµÄÁ¥Êô»ú¹¹»ò³õʼ·ÃÎÊÊðÀí £¬Ð­ÖúÔÚÆäÈëÇÖµÄÍøÂçÉϲ¿Êð¶ñÒâÈí¼þ¡£AndarielÊÇÒ»¸öÊܳ¯ÏÊÕþ¸®Ö§³ÖµÄAPT×éÖ¯ £¬Ó볯ÏʾüÊÂÇ鱨»ú¹¹Õì²ì×ܾÖÓйØÁª £¬ÔøÒò¹¥»÷ÃÀ¹úÀûÒæ¶øÊܵ½ÃÀ¹úÖƲᣴËÇ° £¬AndarielÒ²ÔøÓëMauiÀÕË÷Èí¼þÐж¯ÓйØ¡£ÔÚ2024Äê9ÔµÄÒ»´ÎPlayÀÕË÷Èí¼þʼþÏìÓ¦ÖÐ £¬Unit 42·¢ÏÖAndarielÔÚÆä¿Í»§µÄÊÜѬȾÍøÂçÖл £¬²¢ÔÚ¼¸¸öÔºóPlayÀÕË÷Èí¼þ²ÅÔÚÍøÂçÉÏÖ´ÐС£Ñо¿ÈËÔ±ÈÏΪAndarielµÄ´æÔÚºÍPlayÔÚͬһÍøÂçÉϵIJ¿ÊðÓйØÁª £¬µ«²»È·¶¨AndarielÊÇ·ñ³äµ±ÁËPlayÁ¥Êô»ú¹¹»òÏò¹¥»÷Õß³öÊÛÁËÊÜѬȾÍøÂçµÄ·ÃÎÊȨÏÞ¡£Í¨¹ýÓëÀÕË÷Èí¼þÍÅ»ïºÏ×÷ £¬AndarielµÃÒÔÌӱܹú¼ÊÖƲà £¬ÕâÖÖ¼ÆıÀàËÆÓÚ֮ǰÊܵ½ÖƲõĶíÂÞ˹ºÚ¿Í×éÖ¯Evil CorpºÍÒÁÀÊÍþвÐÐΪÕß¡£


https://www.bleepingcomputer.com/news/security/north-korean-govt-hackers-linked-to-play-ransomware-attack/


5. Android°æFakeCall¶ñÒâÈí¼þ½Ù³ÖÒøÐе绰 £¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢


10ÔÂ30ÈÕ £¬Android°æFakeCall¶ñÒâÈí¼þµÄа汾ͨ¹ý½«×Ô¼ºÉèÖÃΪĬÈϺô½Ð´¦Ö÷¨Ê½ £¬Äܹ»½Ù³ÖÓû§²¦´òÒøÐе绰µÄºô½Ð £¬²¢½«ÆäÖض¨Ïòµ½¹¥»÷Õߵĵ绰ºÅÂë¡£¸Ã¶ñÒâÈí¼þÒÔÓïÒôÍøÂçµöÓãΪÖصã £¬Ö¼ÔÚÇÔÈ¡ÈËÃǵÄÃô¸ÐÐÅÏ¢ºÍÒøÐÐÕË»§×ʽð¡£³ýÁËÓïÒôÍøÂçµöÓã £¬Ëü»¹Äܲ¶×½ÊµÊ±ÒôƵºÍÊÓƵÁ÷¡£×îа汾µÄFakeCallÔö¼ÓÁ˶àÏî¸ïк͹¥»÷»úÖÆ £¬ÈçÀ¶ÑÀ¼àÌýÆ÷¡¢ÆÁĻ״̬¼àÊÓÆ÷ºÍ¸¨Öú¹¦Ð§·þÎñ £¬ÒÔ»ñµÃ¶ÔÓû§½çÃæµÄ¹ã·º¿ØÖÆ £¬²¢ÔÊÐí¹¥»÷ÕßÖ´ÐÐÖÖÖÖ²Ù×÷ £¬Èç»ñÈ¡É豸λÖá¢É¾³ýÓ¦Ó÷¨Ê½¡¢Â¼ÖÆÒôƵ»òÊÓƵÒÔ¼°±à¼­ÁªÏµÈË¡£´ËÍâ £¬¸Ã¶ñÒâÈí¼þ»¹ÔÚ»ý¼«¿ª·¢ÖÐ £¬Ôö¼ÓÁ˽«¶ñÒâÈí¼þÅäÖÃΪĬÈϺô½Ð´¦Ö÷¨Ê½¡¢ÊµÊ±²¥·ÅÉ豸ÆÁÄ»ÄÚÈݵÈй¦Ð§¡£ZimperiumÐû²¼ÁËÈëÇÖÖ¸±êÁбíÒÔ×ÊÖúÓû§±Ü¿ª¶ñÒâÓ¦Óà £¬µ«½¨ÒéÓû§´ÓGoogle Play°²×°Ó¦ÓÃÒÔÖÆÖ¹·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/android-malware-fakecall-now-reroutes-bank-calls-to-attackers/


6. EmeraldWhaleɨÃèGitÅäÖÃÎļþ £¬ÇÔÈ¡15,000¸öÔÆÕÊ»§Æ¾¾Ý


10ÔÂ30ÈÕ £¬ÃûΪ¡°EmeraldWhale¡±µÄ´ó¹æÄ£¶ñÒâ²Ù×÷ÀûÓÃ×Ô¶¯»¯¹¤¾ßɨÃè̻¶µÄGitÅäÖÃÎļþ £¬´ÓÊýǧ¸ö˽ÈË´æ´¢¿âÖÐÇÔÈ¡ÁËÁè¼Ý15,000¸öÔÆÕÊ»§Æ¾¾Ý¡£ÕâЩƾ¾Ý±»ÓÃÓÚÏÂÔØ´æ´¢ÔÚGitHub¡¢GitLabºÍBitBucketÉϵĴ洢¿â £¬²¢½øÒ»²½É¨ÃèÒÔ»ñÈ¡¸ü¶àƾ֤¡£±»µÁÊý¾Ý±»Ð¹Â¶ÖÁÆäËûÊܺ¦ÕßµÄAmazon S3´æ´¢Í°ÖÐ £¬²¢±»ÓÃÓÚÍøÂçµöÓã¡¢À¬»øÓʼþ»î¶¯»òÖ±½Ó³öÊÛ¸øÆäËûÍøÂç·¸×ï·Ö×Ó¡£EmeraldWhale±³ºóµÄÍþвÐÐΪÕßʹÓÿªÔ´¹¤¾ßɨÃèÔ¼5ÒÚ¸öIPµØÖ·ÉϵÄÍøÕ¾ £¬ÌرðÊǼì²éLaravelÓ¦Ó÷¨Ê½ÖеÄ/.git/configÎļþºÍ»·¾³Îļþ(.env)ÊÇ·ñ̻¶¡£ÕâЩÎļþÖпÉÄÜ°üÂÞAPIÃÜÔ¿¡¢ÔÆƾ֤µÈÃô¸ÐÐÅÏ¢¡£SysdigÊӲ쵽 £¬ºÚ¿ÍʹÓÃÉÌÆ·¹¤¾ß¼¯¼ò»¯ÕâÒ»Á÷³Ì £¬²¢ÔÚ̻¶µÄS3´æ´¢Í°Öз¢ÏÖÁË´óÁ¿»úÃÜÐÅÏ¢¡£Ñо¿ÈËÔ±Ö¸³ö £¬Õâ´Î»î¶¯ÒÀÀµÓÚÉÌÆ·¹¤¾ßºÍ×Ô¶¯»¯ £¬µ«ÈÔÈ»ÀÖ³ÉÇÔÈ¡ÁËÊýǧ¸ö¿ÉÄܵ¼ÖÂÔÖÄÑÐÔÊý¾Ýй¶µÄ»úÃÜ¡£Èí¼þ¿ª·¢ÈËԱӦʹÓÃרÓõÄÃØÃܹÜÀí¹¤¾ßÀ´½µµÍ·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/hackers-steal-15-000-cloud-credentials-from-exposed-git-config-files/