CybleÅû¶ÀûÓÃαÔìChatGPTÀûÓ÷ַ¢¶ñÒâÈí¼þµÄ»î¶¯

°ä²¼¹¦·ò 2023-02-24

1¡¢CybleÅû¶ÀûÓÃαÔìChatGPTÀûÓ÷ַ¢¶ñÒâÈí¼þµÄ»î¶¯


2ÔÂ22ÈÕ £¬Cyble³Æ»ùÓÚChatGPTµÄ´¹µö¹¥»÷µÄÍþвԽÀ´Ô½´ó¡£ChatGPT×Ô2022Äê11ÔÂÍÆ³öÒÔÀ´»ñµÃÁ˾޴óµÄ³É¹¦ £¬µ½2023Äê1ÔÂÓû§Òѳ¬¹ý1ÒÚ¡£Cyble¼ì²âµ½Á˶à¸ö´¹µöÍøÕ¾ £¬ËüÃÇÔÚͨ¹ýڲƭÐÔµÄOpenAIÉ罻ýÌåÒ³Ãæ½øÐÐÍÆ¹ã £¬À´´«²¼¸÷ÖÖÀàÐ͵ĶñÒâÈí¼þ¡£´Ë±í £¬Ò»Ð©´¹µöÍøÕ¾ÔÚ¼ÙÒâChatGPTÇÔÊØÐÅÓþ¿¨ÐÅÏ¢¡£×êÑÐÈËÔ±»¹¼ì²âµ½50¶à¸öʹÓÃChatGPTͼ±êµÄ¼ÙðºÍ¶ñÒâÀûÓà £¬ÈçÀ¬»ø·¨Ê½¡¢¸æ°×Èí¼þºÍ¼äµýÈí¼þµÈ¡£


https://blog.cyble.com/2023/02/22/the-growing-threat-of-chatgpt-based-phishing-attacks/


2¡¢ÐµÄS1deload Stealer½Ù³ÖYoutubeºÍFacebookÕÊ»§


BitdefenderÔÚ2ÔÂ22ÈÕÅû¶ÁËжñÒâÈí¼þS1deload StealerÕë¶ÔÈ«ÇòµÄ¹¥»÷»î¶¯¡£ÔÚ2022Äê7Ôµ½12Ô £¬Bitdefender¼ì²âµ½600¶à¸öÓû§Ï°È¾ÁËÕâÖÖ¶ñÒâÈí¼þ¡£S1deload StealerÒÀ¸½DLL²àÔØ¼¼ÊõÀ´ÔËÐÐÆä¶ñÒâ×é¼þ £¬Ê¹ÓÃÁËÒ»¸öºÏ·¨µÄ¡¢¾­¹ýÊý×ÖÊðÃûµÄ¿ÉÖ´ÐÐÎļþ¡£Ò»µ©³É¹¦Ï°È¾ £¬¸Ã¶ñÒâÈí¼þ¾Í»áÇÔÈ¡Óû§Æ¾Ö¤ £¬·ÂÕÕÈËÀàÐÐΪÀ´Ìá¸ßÊÓÆµºÍÆäËüÄÚÈݵIJμӶÈ £¬ÆÀ¹ÀÓ×ÎÒÕË»§µÄ¼ÛÖµ £¬ÍÚ¾òBEAM¼ÓÃÜÇ®±Ò £¬²¢½«¶ñÒâÁ´½Ó´«²¼¸øÓû§µÄ·ÛË¿¡£


https://www.bitdefender.com/blog/labs/s1deload-stealer-exploring-theeconomics-of-social-networkaccount-hijacking/


3¡¢OyeTalk»áй¶Óû§µÄ̸Ìì¼Í¼Òѱ»×°Öó¬¹ý500Íò´Î


¾ÝýÌå2ÔÂ22ÈÕ±¨Â· £¬AndroidÓïÒô̸ÌìÀûÓÃй¶ÁËÓû§µÄ̸Ìì¼Í¼¡£¸ÃÀûÓÃÔÚGoogle PlayÉϵÄÏÂÔØÁ¿³¬¹ý500Íò´Î £¬ÆäFirebaseÊ·ýй¶Á˳¬¹ý500MBµÄÊý¾Ý £¬Ô̺¬Î´¼ÓÃܵÄÓû§Ì¸Ìì¼Í¼¡¢Óû§ÃûºÍÊÖ»ú¹ú¼ÊÒÆ¶¯É豸¼ø±ðÂë(IMEI)ºÅÂëµÈ¡£×êÑÐÈËÔ±°µÊ¾ £¬ÈôÊÇûÓжÔй¶µÄÊý¾Ý½øÐб¸·Ý £¬¹¥»÷Õß¿ÉÄÜ»áɾ³ýÊý¾Ý¿âµ¼ÖÂÓû§µÄÓ×ÎÒÐÅÏ¢ÓÀÔ¼ûÔʧ¡£ÀûÓõĿª·¢ÈËÔ±ÔÚ»ñϤÊý¾Ýй¶ºóÈÔδÄÜÏÞ¶ÈÊý¾Ý¿âµÄ½Ó¼û £¬¹È¸è²»µÃ²»È¾Ö¸Éè·¨±£»¤¸ÃÊý¾Ý¿â¡£


https://www.hackread.com/android-voice-chat-app-data-leak/


4¡¢×êÑÐÈËÔ±¼ì²âµ½41¸ö¼Ù×°³ÉHTTP¿âµÄ¶ñÒâPyPI°ü


¾Ý2ÔÂ22ÈÕ±¨Â· £¬ReversingLabs×êÑÐÈËÔ±ÔÚPyPI´æ´¢¿âÖмì²âµ½41¸ö¼Ù×°³ÉHTTP¿âµÄ¶ñÒâ°ü¡£ÕâЩαÔìµÄHTTP¿âÖÐÔ̺¬Á½ÖÖ·ÖÆçÀàÐ͵ĶñÒâÄ £¿é£ºÏÂÔØ·¨Ê½ £¬ÓÃÓÚÏò±»¹¥»÷µÄϵͳÌṩµÚ¶þ½×¶ÎµÄ¶ñÒâÈí¼þ£»ÐÅÏ¢ÇÔÈ¡·¨Ê½ £¬Ô̺¬ÓÃÓÚÊý¾Ýй¶µÄ¶ñÒâÖ°ÄÜ¡£ÀýÈç £¬ÐÅÏ¢ÇÔÈ¡·¨Ê½httpxv2¿ÉÍøÂçÃÜÂëºÍÁîÅÆµÈÃô¸ÐÊý¾Ý²¢·¢Ë͸ø¹¥»÷Õß £¬ÏÂÔØ·¨Ê½httpsus½«¿ÉÒɵÄpayload°µ²ØÆðÀ´¡£


https://www.reversinglabs.com/blog/beware-impostor-http-libraries-lurk-on-pypi


5¡¢ÐºóÃÅWinorDLL64»ò±»LazarusÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢


¾ÝESET 2ÔÂ23ÈÕ±¨Â· £¬Lazarus Group¿ÉÄÜʹÓÃÁËÓëWslinkÓйصÄкóÃÅWinorDLL64¡£WinorDLL64ÊÇÒ»¸öÖ°ÄÜÆëÈ«µÄÖ²È뷨ʽ £¬Äܹ»Ð¹Â¶¡¢¸²¸ÇºÍɾ³ýÎļþ £¬Ö´ÐÐPowerShellºÅÁî £¬²¢»ñÈ¡´óÁ¿ÏµÍ³ÓйØÐÅÏ¢¡£×êÑÐÈËÔ±°µÊ¾ £¬ÓÉÓÚWinorDLL64ÔÚ¿ª·¢»·¾³¡¢ÐÐΪºÍ´úÂëÖÐÓë¶à¸öLazarusµÄÑù±¾ÓÐËù³Áµþ £¬ÕâÅú×¢Ëü¿ÉÄÜÊÇÕâ¸öAPT×éÖ¯µÄ±øÆ÷¿âÖеÄÒ»²¿ÃÅ¡£


https://www.welivesecurity.com/2023/02/23/winordll64-backdoor-vast-lazarus-arsenal/


6¡¢Synopsys°ä²¼2023Ä꿪Դ°²È«Î¢·çÏյķÖÎö»ã±¨


ýÌå2ÔÂ22ÈÕ³Æ £¬Synopsysµ÷²éÁË17¸öÐÐÒµÖÐÔ¼1700¸ö´úÂë¿âÖз¢Ïֵķì϶ºÍÐí¿Éì¶Ü £¬°ä²¼Á˹ØÓÚ2023Ä꿪Դ°²È«Î¢·çÏյķÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬84%µÄ´úÂë¿âÔ̺¬ÖÁÉÙÒ»¸öÒÑÖªµÄ¿ªÔ´·ì϶ £¬ÓëÈ¥ÄêÏà±ÈÔö³¤Á˽ü4%¡£¹ÌÈ»×ÜÌå·ì϶ÂÔÓÐÉÏÉý £¬µ«ÓµÓи߷çÏÕ·ì϶µÄ´úÂë¿âµÄÕ¼±ÈÁ¦Ö®È¥Äê½µÂäÁË2% £¬½µÖÁ48%¡£½ÌÓý¿Æ¼¼ÐÐҵѡȡ¿ªÔ´´úÂëµÄ±ÈÀýÔö³¤ÁË163% £¬Æä´ÎÊǺ½¿Õº½Ìì¡¢º½¿Õ¡¢Æû³µ¡¢ÔËÊäºÍÎïÊ¢ÐÐÒµ(97%)ÒÔ¼°Ôì×÷ÒµºÍ»úеÈ˼¼Êõ(74%)¡£


https://www.synopsys.com/software-integrity/resources/analyst-reports/open-source-security-risk-analysis.html