ºÚ¿ÍÀûÓà Aiohttp ·ì϶ѰÕÒÒ×Êܹ¥»÷µÄÖ¸±ê
°ä²¼¹¦·ò 2024-03-183ÔÂ16ÈÕ£¬ÀÕË÷Èí¼þ¹¥»÷Õß¡°ShadowSyndicate¡¹ØýÔÚɨÃèÒ×ÊÜ CVE-2024-23334£¨aiohttp Python ¿âÖеÄĿ¼±éÀú·ì϶£©Ó°ÏìµÄ·þÎñÆ÷¡£Aiohttp ÊÇÒ»¸ö¹¹½¨ÔÚ Python Òì²½ I/O ¿ò¼Ü Asyncio Ö®ÉϵĿªÔ´¿â£¬ÓÃÓÚ´¦ÖôóÁ¿²¢·¢ HTTP ÒªÇ󣬶øÎÞÐ贫ͳµÄ»ùÓÚÏ̵߳ÄÍøÂç¡£2024 Äê 1 Ô 28 ÈÕ£¬aiohttp °ä²¼ÁË °æ±¾ 3.9.2£¬½â¾öÁË CVE-2024-23334£¬ÕâÊÇÒ»¸öÑϳÁµÄõè¾¶±éÀú·ì϶£¬Ó°Ïì 3.9.1 ¼°¸üÔç°æ±¾µÄËùÓÐ aiohttp °æ±¾£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß½Ó¼ûÒ×Êܹ¥»÷µÄ·þÎñÆ÷ÉϵÄÎļþ¡£¸ÃȱµãÊÇÓÉÓÚµ±¾²Ì¬Â·Óɵġ°follow_symlinks¡±ÉèÖÃΪ¡°True¡±Ê±ÑéÖ¤²»³ä·Ö£¬´Ó¶øÔÊÐíδ¾ÊÚȨ½Ó¼û·þÎñÆ÷¾²Ì¬¸ùĿ¼֮±íµÄÎļþ¡£ShadowSyndicate ÊÇÒ»¸ö»úÓöÖ÷Òå¡¢ ¾¼Ã¶¯»úµÄÍþвÐÐΪÕߣ¬×Ô 2022 Äê 7 ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬Óë Quantum¡¢Nokoyawa¡¢BlackCat/ALPHV¡¢Clop¡¢Royal¡¢Cactus ºÍ Play µÈÀÕË÷Èí¼þ¾úÖêÓÐ·ÖÆçˮƽµÄÐÅÀµ¡£Group-IB ÒÔΪÍþвÐÐΪÕßÊÇÓë¶à¸öÀÕË÷Èí¼þÔËÓª»ú¹¹ºÏ×÷µÄ´ÓÊô»ú¹¹¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-aiohttp-bug-to-find-vulnerable-networks/
2. ·¨¹ú TRAVAIL Êý¾Ýй¶ӰÏì 4300 ÍòÈË
3ÔÂ16ÈÕ£¬·¨¹úÍøÂç·¸×ïÔ¤·À´òËã½øÐеĵ÷²éÏÔʾ£¬ÍþвÐÐΪÕßÔÚ 2024 Äê 2 Ô 6 ÈÕÖÁ 3 Ô 5 ÈÕÆÚ¼äÇÔÈ¡ÁË 4300 ÍòÈ˵ÄÓ×ÎÒÐÅÏ¢¡£2023 Äê 8 Ô£¬·¨¹úµ±¾Ö¾ÍÒµ»ú¹¹ P?le emploiÔâ·êÊý¾Ýй¶£¬²¢Í¨ÖªÁËÊܰ²È«·ì϶ӰÏìµÄ 1000 ÍòÈË¡£Õâ´Î°²È«·ì϶¶³öÁËÊÜÓ°ÏìÓ×ÎÒµÄÐÕÊÏ¡¢Ãû×ÖºÍÉç»á°²È«ºÅÂë¡£µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÃÜÂëºÍ²ÆÕþÊý¾Ý²»»á±»Ð¹Â¶¡£¸Ã»ú¹¹½¨ÒéÇóÖ°Õß¶ÔÈκÎDZÔÚµÄڲƻά³Ö¾¯Ì裬¸Ã»ú¹¹»¹²¹³ä˵£¬¸Ã»ú¹¹ÌṩµÄÅâ³¥ºÍÖ§³ÖÒÔ¼°½Ó¼û polo-emploi.frµÄÓ×Îҿռ䲻´æÔÚÖ°ºÎ·çÏÕ¡£·¨¹úµ±¾Ö²¢Î´½«Õâ´Î¹¥»÷¹é×ïÓÚÒÑÖªµÄÀÕË÷Èí¼þÍŻ²»Í⣬Bleeping Computer ¹Û²ì µ½£¬°²È«¹«Ë¾Emsisoft ÔÚÆä MOVEitÒ³ÃæÉÏÁгöÁ˸÷¨¹úµ±¾Ö»ú¹¹ £¬ÕâÒâζ×ÅËüºÜ¿ÉÄÜÊÇClop ÀÕË÷Èí¼þÍÅ»ï µÄÊܺ¦Õß¡£
https://securityaffairs.com/160556/data-breach/france-travail-data-breach-34m-people.html
3. ºÚ¿ÍÐû³ÆÒѾ¹¥ÆÆ Viber²¢ÇÔÈ¡ÁË 740GB Êý¾Ý
3ÔÂ16ÈÕ£¬Handala Hack ÔÚ Telegram Ìû×ÓÖÐÐû³ÆËûÃÇÇÔÈ¡Á˳¬¹ý 740GB µÄÊý¾Ý£¬ÆäÖÐÔ̺¬ Viber µÄÔ´´úÂë¡£¸Ã×éÖ¯ÒªÇóΪ±»µÁÐÅÏ¢Ö§¸¶ 8 ±ÈÌØ±Ò£¨¼´ 583,000 ÃÀÔª£©µÄÊê½ð¡£Viber ÊÇÒ»¿îÐÂÎÅÀûÓ÷¨Ê½£¬ÓÚ 2010 ÄêÍÆ³ö£¬²¢ÓÚ 2014 Äê±»ÈÕ±¾¿ç¹ú¹«Ë¾ÀÖÌ칫˾ÒÔ 9 ÒÚÃÀÔªÊÕ¹º£¬¸ÃÀûÓ÷¨Ê½ÒѶԺڿ͵ÄÖ¸¿Ø×ö³öÁË»ØÓ¦¡£¸Ã¹«Ë¾·ñ¶¨ÓÐÈκÎÈëÇÔìäϵͳ»òÊý¾Ýй¶µÄÖ¤¾Ý£¬µ«È·ÈÏÒÑÆô¶¯µ÷²éÒÔºËʵÊÇ·ñ²úÉú°²È«·ì϶¡£ÈôÊǵõ½Ö¤Êµ£¬Õâ¿ÉÄÜÊǽü´úº¹ÇàÉÏ×î´óµÄÊý¾Ýй¶ÊÂÎñÖ®Ò»¡£×¨¼ÒÒÔΪ£¬ÕâÖÖй¶¿ÉÄÜÉæ¼°Ó×ÎÒÐÂÎÅ¡¢Í¨»°¼Í¼¡¢ÁªÏµ·½Ê½ºÍ²ÆÕþÐÅÏ¢£¬¿ÉÄÜ»á¶Ô Viber Óû§Ôì³É¸²ÃðÐÔ½ø¹¥¡£Handala Hack ÊÇÒ»¸öÓÐÕùÒéµÄ×éÖ¯£¬ÒÔÖ§³Ö°ÍÀÕ˹̹ÊÂÒµµÄÒÔÉ«ÁÐʵÌå¼°ÆäÃËÓÑΪָ±ê¶øÎÅÃû¡£×Ô 2023 Äê 12 Ô³ÉÁ¢ Telegram Ƶ·²¢Ëæºó²ÎÓëÎ¥¹æÂÛ̳ÒÔÀ´£¬ËüÒ»ÏòºÜ»îÔ¾¡£Óë´Ëͬʱ£¬Viber Óû§Ó¦ÉóÉ÷ÐÐʲ¢¸ü¸ÄÃÜÂ룬¾¯ÌèÍøÂç´¹µö³¢ÊÔ£¬²¢Í¨¹ý²é³ Viber µÄ¹Ù·½ÇþÂ·ËæÊ±ÏàʶÓйØÉæÏÓÊý¾Ýй¶µÄÈκθüС£
https://www.hackread.com/hackers-claim-740gb-of-data-viber-messaging-app/
4. ºÚ¿ÍÀûÓà GitHub ÉÏµÄÆÆ½âÈí¼þ´«²¼ RisePro
3ÔÂ16ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢Ïֺܶà GitHub ´æ´¢¿âÌá¹©ÆÆ½âÈí¼þ£¬ÕâЩÈí¼þÓÃÓÚ´«²¼ÃûΪ RisePro µÄÐÅÏ¢ÇÔÈ¡·¨Ê½¡£¾Ý G DATA ³Æ£¬¸Ã»î¶¯´úºÅΪgitgub £¬Ô̺¬Óë 11 ¸ö·ÖÆçÕË»§ÓÐ¹ØµÄ 17 ¸ö´æ´¢¿â¡£¶ûºó£¬Óйش洢¿âÒѱ»Î¢ÈíÆìÏÂ×Ó¹«Ë¾É¾³ý¡£Github ÉÏͨ³£Ê¹ÓÃÂÌÉ«ºÍºìɫԲȦÀ´ÏÔʾ×Ô¶¯¹¹½¨µÄ״̬¡£Gitgub Íþв²Î¼ÓÕßÔÚËûÃÇµÄ README.md ÖÐÔö³¤ÁËËĸöÂÌÉ« Unicode ԲȦ£¬¼Ù×°ÔÚµ±Ç°ÈÕÆÚÅÔ±ßÏÔʾ״̬£¬²¢ÌṩºÏ·¨ÐÔºÍнü¶ÈµÄ¸Ð´¥¡£RAR ´æµµÒªÇóÊܺ¦ÕßÌṩ´æ´¢¿â README.md ÎļþÖÐÌáµ½µÄÃÜÂ룬ÆäÖÐÔ̺¬Ò»¸ö×°Ö÷¨Ê½Îļþ£¬¸ÃÎļþ½âѹÏÂÒ»½×¶ÎµÄÓÐЧ¸ºÔØ£¬ÕâÊÇÒ»¸öÅòÕ͵½ 699 MB µÄ¿ÉÖ´ÐÐÎļþ£¬Ö¼ÔÚʹ·ÖÎö¹¤¾ß±ÀÀ££¬ÀýÈçIDA רҵ°æ¡£¸ÃÎļþµÄÏÖʵÄÚÈÝ£¨×ܼƽöΪ 3.43 MB£©³äÈμÓÔØ·¨Ê½£¬½« RisePro£¨°æ±¾ 1.6£©×¢Èë AppLaunch.exe »ò RegAsm.exe ÖС£RisePro ÔÚ 2022 Äêµ×ºöÈ»³ÉΪÈËÃǹØ×¢µÄ½¹µã£¬ÆäʱËüʹÓÃÃûΪ PrivateLoader µÄ°´×°Öø¶·Ñ (PPI) ¶ñÒâÈí¼þÏÂÔØ·þÎñ½øÐзַ¢¡£
https://thehackernews.com/2024/03/hackers-using-cracked-software-on.html
5. ºÚ¿Íͨ¹ý±øÆ÷»¯ PDF ÓÕÆÓû§×°ÖöñÒâÈí¼þ
3ÔÂ16ÈÕ£¬ÔÚÒ»³¡¸´ÔÓµÄÍøÂç¹¥»÷»î¶¯ÖУ¬¶ñÒâÐÐΪÕß¼ÙÒâ¸çÂ×±ÈÑǵ±¾Ö»ú¹¹£¬Õë¶ÔÀ¶¡ÃÀÖÞ¸÷µØµÄÓ×ÎÒ½øÐй¥»÷¡£¹¥»÷Õß·Ö·¢Ô̺¬ PDF ¸½¼þµÄµç×ÓÓʼþ£¬ÃýÎóµØÖ¸¿ØÊÕ¼þÈËÎ¥·´½»Í¨¹æ¶¨»òÆäËûÎ¥·¨ÐÐΪ¡£ÕâЩºýŪÐÔͨѶּÔÚвÆÈÊܺ¦ÕßÏÂÔØÔ̺¬ VBS ¾ç±¾µÄ´æµµ£¬´Ó¶øÆô¶¯¶à½×¶ÎϰȾ¹ý³Ì¡£Ö´Ðк󣬾¹ý»ìºÏµÄ VBS ¾ç±¾»á´¥·¢ PowerShell ¾ç±¾£¬Í¨¹ýÁ½²½ÒªÇó¹ý³Ì´ÓºÏ·¨ÔÚÏß´æ´¢·þÎñÖмìË÷×îÖյĶñÒâÈí¼þ¸ºÔØ¡£Æ¾¾Ý ANY.RUN Óë GBHackers ·ÖÏíµÄ°²È«»ã±¨£»×î³õ£¬¾ç±¾´Ó textbin.net µÈ×ÊÔ´»ñÈ¡ÓÐЧ¸ºÔصĵØÖ·¡£¶øºó£¬Ëü³ÖÐø´ÓÌṩµÄµØÖ·ÏÂÔØ²¢Ö´ÐÐÓÐЧ¸ºÔØ£¬¸ÃÓÐЧ¸ºÔØÄܹ»ÍйÜÔÚ¸÷ÀàÆ½Ì¨ÉÏ£¬Ô̺¬ cdn.discordapp(.)com¡¢pasteio(.)com¡¢hidrive.ionos.com ºÍ wtools.io¡£¹¥»÷ÕßµÄÖ´ÐÐÁ´×ñÑ´Ó PDF µ½ ZIP£¬¶øºóµ½ VBS ºÍ PowerShell£¬×îºóµ½¿ÉÖ´ÐÐÎļþ (EXE) µÄ°¤´Î¡£×îÖÕµÄÓÐЧ¸ºÔر»¼ø±ðΪ¼¸ÖÖÒÑÖªµÄÔ¶³Ì½Ó¼ûľÂí (RAT) Ö®Ò»£¬³ö¸ñÊÇAsyncRAT¡¢njRAT»òRemcos¡£ÕâЩ¶ñÒⷨʽÒòÆä¿ÉÄܶÔÊÜϰȾϵͳÌṩδ¾ÊÚȨµÄÔ¶³Ì½Ó¼û¶ø³ôÃûÔ¶Ñ¸øÊܺ¦ÕßµÄÒþÖÔºÍÊý¾Ý°²È«´øÀ´³Á´ó·çÏÕ¡£
https://gbhackers.com/hackers-trick-users-to-install-malware-via-weaponized-pdf/
6. TikTok±»Òâ´óÀû¼à¹Ü»ú¹¹·£¿î½ü1100ÍòÃÀÔª
3ÔÂ16ÈÕ£¬Æ¾¾Ý¸Ã¹ú¾ºÕùÖÎÀí¾Ö (AGCM) µÄÒ»·ÝÐÂΟ壬Òâ´óÀûµ±¾ÖÖÜËÄ¶Ô TikTok ´¦ÒÔ 1090 ÍòÃÀÔª·£¿î£¬ÔÒòÊÇÆäÖú³¤ÁË¿ÉÄÜÇÖº¦Óû§¡°ÉúÀíÈËÉí°²È«¡±µÄÊÓÆµ´«²¼¡£Õâ±Ê·£¿îÊǾ¹ýÒ»Äêµ÷²éµÄÁ˾֣¬Ò»ÌìǰÃÀ¹ú¶àÒéԺͶƱ¾ö¶¨ÓÐЧ²»ÈÝ¸ÃÆ½Ì¨£¬¹ú»áÒéÔ±ÒªÇó¸Ãƽ̨×Ö½ÚÌø¶¯³·×Ê£¬²»È»½«±»²»ÈÝÔÚÃÀ¹úÔËÓª¡£AGCM ³ö¸ñ¹Ø×¢¸Ãƽ̨ÈôºÎ¶Ôδ³ÉÄêÈ˺ÍÈõÊÆÈºÌå²úÉú¸ºÃæÓ°Ï죬°µÊ¾¶Ô¸Ãƽ̨Ëã·¨µÄµ÷²é²¿ÃÅÊÇΪÁË»ØÓ¦ÔÚ¸ÃÀûÓ÷¨Ê½ÉÏ·è´«µÄËùν¡°·¨¹ú°ÌºÛ¡±ÌôÕ½¡£¸ÃÌôÕ½ÒªÇóÀûÓ÷¨Ê½Óû§·ÖÏíÃæ²¿°ÌºÛµÄÊÓÆµ£¬µ¼ÖºܶàÈËÆ¤·ôÊÜÉË²Î¼ÓÆäÖС£´Ë±í£¬AGCM °µÊ¾£¬¸Ãƽ̨µÄÁìµ¼·½ÕëÊDz»¹»µÄ£¬²¢Ö¸³ö£¬ÕâЩÁìµ¼·½ÕëµÄÀûÓá°Ã»Óгä·Ö˼¿¼µ½ÇàÉÙÄêµÄ¾ßÌå´àÈõÐÔ£¬ÆäÌØµãÊÇÌØÊâµÄÈÏÖª»úÔ졣ŷÃËίԱ»áÉϸöÔ°䷢£¬ÒÑÆô¶¯µ÷²é£¬ÒÔÈ·¶¨ TiKTok ÊÇ·ñÒòδÄÜÑéÖ¤Óû§´ºÇï¡¢±£»¤Óû§ÒþÖÔºÍÔ¤·ÀÓû§³ÁÃÔ¸ÃÀûÓöøÎ¥·´ÁËÅ·ÖÞ´ó½µÄÊý×Ö·þÎñ·¨ (DSA)¡£¸Ãµ÷²éµÄ³Áµã»¹ÔÚÓÚ¸ÃÆ½Ì¨ÊÇ·ñͨ¹ý²»Í¨Ã÷µÄ¸æ°×ÐÐΪÒÔ¼°Î´Äܱ£»¤Î´³ÉÄêÈ˶øÎ¥·´ÁË DSA¡£
https://therecord.media/tiktok-italy-fine-regulator


¾©¹«Íø°²±¸11010802024551ºÅ