Vultur ÒøÐжñÒâÈí¼þ¼Ù×°³É McAfee Security ÀûÓ÷¨Ê½

°ä²¼¹¦·ò 2024-04-01
1. Vultur ÒøÐжñÒâÈí¼þ¼Ù×°³É McAfee Security ÀûÓ÷¨Ê½


3ÔÂ30ÈÕ£¬°²È«×êÑÐÈËÔ±·¢ÏÖÁË Android °æ Vultur ÒøÐÐľÂíµÄа汾£¬ÆäÖÐÔ̺¬¸üÏȽøµÄÔ¶³Ì½ÚÔìÖ°Äܺ͸ĽøµÄ¶ã±Ü»úÔì¡£×êÑÐÈËÔ±ÓÚ 2021 Äê 3 Ô³õ´Î¼Í¼Á˸öñÒâÈí¼þ£¬²¢ÔÚ 2022 Äêµ×·¢ÏָöñÒâÈí¼þͨ¹ýÖ²ÈëÀûÓ÷¨Ê½ÔÚ Google Play ÉÏ´«²¼¡£2023 Äêµ×£¬Òƶ¯°²È«Æ½Ì¨ Zimperium ½« Vultur ÁÐÈëÄê¶ÈÊ®´ó×î»îÔ¾ÒøÐÐľÂíÖ®ÁУ¬²¢Ö¸³öÆäÖÐ 9 ¸ö±äÖÖÕë¶Ô 15 ¸ö¹ú¶È/µØÓòµÄ 122 ¸öÒøÐÐÀûÓ÷¨Ê½¡£Ò»ÖÖеġ¢¸ü¾ß¶ã±ÜÐ﵀ Vultur °æ±¾Í¨¹ýÒ»ÖÖ»ìºÏ¹¥»÷´«²¼¸øÊܺ¦Õߣ¬ÕâÖÖ¹¥»÷ÒÀÀµÓÚ¶ÌÐÅ´¹µö£¨¶ÌÐÅÍøÂç´¹µö£©ºÍµç»°£¬ÓÕÆ­Ö¸±ê×°ÖÃÒ»¸ö°æ±¾µÄ Vultur¡£¼Ù×°³É McAfee Security ÀûÓ÷¨Ê½µÄ¶ñÒâÈí¼þ¡£Vultur ×îеÄϰȾÁ´Ê¼ÓÚÊܺ¦ÕßÊÕµ½Ò»Ìõ¶ÌÐÅ£¬ÌáÐÑδ¾­ÊÚȨµÄÂòÂô£¬²¢Åúʾ²¦´òÌṩµÄºÅÂë×·ÇóÁìµ¼¡£Ú¿Æ­Õß½ÓÌýµç»°£¬Ëµ·þÊܺ¦Õß´ò¿ªµÚ¶þÌõ¶ÌÐÅ·¢Ë͵ÄÁ´½Ó£¬¸ÃÁ´½ÓÖ¸ÏòÌṩ McAfee Security ÀûÓ÷¨Ê½Åú¸Ä°æ±¾µÄÍøÕ¾¡£


https://www.bleepingcomputer.com/news/security/vultur-banking-malware-for-android-poses-as-mcafee-security-app/


2. PyPI ÔÝÍ£ÐÂÓû§×¢²áÒÔ×èÖ¹¶ñÒâÈí¼þ»î¶¯


3ÔÂ28ÈÕ£¬PyPI ÊÇ Python ÏîÖ÷ÕÅË÷Òý£¬¿ÉÔ®ÊÖ¿ª·¢ÈËÔ±²éÕÒºÍ×°Öà Python °ü¡£¸Ã´æ´¢¿âÓµº±¼ûǧ¸ö¿ÉÓÃÈí¼þ°ü£¬¶ÔÓÚÍþвÐÐΪÕßÀ´ËµÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÖ¸±ê£¬ËûÃÇʱʱÉÏ´«Æ´Ð´ÃýÎó»òαÔìµÄÈí¼þ°üÀ´·çÏÕÈí¼þ¿ª·¢ÈËÔ±ºÍDZÔڵĹ©¸øÁ´¹¥»÷¡£´ËÀà»î¶¯ÆÈʹ PyPI ÖÎÀíÔ±½ñÌìÔçЩʱ³½°ä·¢ÔÝÍ£ËùÓÐÐÂÓû§×¢²á£¬ÒÔÏ÷¼õ¶ñÒâ»î¶¯¡£Checkmarx µÄÒ»·Ý»ã±¨ÏÔʾ£¬ÍþвÐÐΪÕß×òÌìÆðÍ·Ïò PyPI 365 ÉÏ´«ÓµÓзÂÕպϷ¨ÏîÄ¿Ãû³ÆµÄÈí¼þ°ü¡£ÕâЩÈí¼þ°üµÄ¡°setup.py¡±ÎļþÖÐÔ̺¬¶ñÒâ´úÂ룬¸Ã´úÂëÔÚ×°ÖÃʱִÐУ¬ÊÔͼ´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷¶î±íµÄÓÐЧ¸ºÔØ¡£ÎªÁËÌӱܼì²â£¬¶ñÒâ´úÂëʹÓà Fernet Ä£¿é½øÐмÓÃÜ£¬²¢ÔÚ±ØÒªÊ±¶¯Ì¬¹¹½¨Ô¶³Ì×ÊÔ´µÄ URL¡£×îÖÕµÄÓÐЧ¸ºÔØÊÇÒ»¸öÓµÓÐÓÆ¾ÃÐÔÖ°ÄܵÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬ÆäÖ¸±êÊÇ´æ´¢ÔÚÍøÂçä¯ÀÀÆ÷ÖеÄÊý¾Ý£¬ÀýÈçµÇ¼ÃÜÂë¡¢cookie ºÍ¼ÓÃÜÇ®±ÒµÈ¡£


https://www.bleepingcomputer.com/news/security/pypi-suspends-new-user-registration-to-block-malware-campaign/?&web_view=true


3. Ó¢¹úÈûÀ­·Æ¶ûµÂºËµçÕ¾ÒòÍøÂ簲ȫ¹ÊÕϱ»¸æ×´


3ÔÂ29ÈÕ£¬Ó¢¹ú¶ÀÁ¢ºË°²È«¼à¹Ü»ú¹¹°ä·¢£¬½«¸æ×´ÖÎÀíÈûÀ­·Æ¶ûµÂºËµçÕ¾µÄ¹«Ë¾£¬Ö¸¿ØÆä¡°ÔÚ 2019 ÄêÖÁ 2023 ËêÊ×µÄËÄÄêÆÚ¼äÉæÏÓÐÅÏ¢¼¼Êõ°²È«·¸×¡£Ä¿Ç°Éв»Ã÷ÏÔ¹úÓÐÈûÀ­·Æ¶ûµÂÓÐÏÞ¹«Ë¾µÄ¸ß¼¶ÖÎÀíÈËÔ±ÊÇ·ñ»áÎî¶ÔÖ¸¿Ø¡£Æ¾¾Ý2003 Äê¡¶ºË¹¤Òµ°²È«ÌõÀý¡·£¬±»¶¨×ïµÄÓ×ÎÒ¿ÉÃæ¶Ô×î¸ßÁ½ÄêµÄ½ûïÀ¡£ÕýÈçÓ¢¹úÊ×ϯºË¼à²ìԱȥÄêµÄÄê¶È»ã±¨ËùÅû¶µÄÄÇÑù£¬ÈûÀ­·Æ¶ûµÂ´ËǰÒòÆäÍøÂ簲ȫȱµã¶ø³ÉΪ¼à¹Ü»ú¹¹¼ÓÇ¿¹Ø×¢µÄ½¹µã¡£Óë´Ëͬʱ£¬ÔÚÓ¢¹úÔËÓªÊý×ùºËµçÕ¾µÄ·¨¹úµçÁ¦¹«Ë¾Ò²Êܵ½ÁËÀàËÆ´ëÊ©¡£ÕýÈçÓ¢¹úÃñÓúËÍøÂ簲ȫսÊõËùÊö£¬¹ú¶ÈÍøÂ簲ȫÖÐÐÄ (NCSC) ÍþвÆÀ¹ÀÖÒ¸æ³Æ£¬ÀÕË÷Èí¼þ¡°ÏÕЩע¶¨ÊÇ×îÓпÉÄܵķÛËéÐÔÍþв¡±¡£Ö»¹Ü¹¤ÒµÏµÍ³Éè¼ÆÓжà¸ö¹ÊÕϰ²È«×°ÖÃÀ´Ô¤·À·ÅÉäÐÔ±äÂÒ£¬µ«¶ÔºËµçվʹÓÃµÄ IT ϵͳµÄÀÕË÷Èí¼þ¹¥»÷¿ÉÄÜ»áÇÖÈÅÆäÔËÐС£ÈûÀ­·Æ¶ûµÂµÄºË·´Ó³¶ÑÓÚ 2003 Äê¹Ø¹Ø£¬µ«Õâ¸öÖØ´óµÄ×ÛºÏÌåÒÀÈ»ÊÇÅ·ÖÞ×î´óµÄºËµçÕ¾£¬ONR ½«ÆäÃèÊöΪ¡°ÊÀ½çÉÏ×ÔÓ¡¢×îΣÏյĺ˵çÕ¾Ö®Ò»¡±¡£


https://therecord.media/sellafield-site-prosecution-nuclear-facility-cybersecurity


4. Õë¶ÔÓ¡¶È¹ú·ÀºÍÄÜÔ´²¿ÃŵĴ¹µö¹¥»÷


3ÔÂ29ÈÕ£¬EclecticIQ ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÏîÃûΪ¡°Operation FlightNight¡±µÄÍøÂç¼äµý»î¶¯£¬Ö¸±êÊÇÓ¡¶ÈµÐÔÖʵÌåºÍÄÜÔ´¹«Ë¾¡£¹¥»÷Õß¿ÉÄÜÊÇÓɹú¶ÈÔÞÖúµÄ£¬ËûÃÇÀûÓÿªÔ´ÐÅÏ¢ÇÔÈ¡·¨Ê½ HackBrowserData µÄÅú¸Ä°æÕý±¾ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£EclecticIQ ·¢ÏÖ¹¥»÷ÕßʹÓÃÊ¢ÐеÄͨѶƽ̨ Slack ͨ·×÷ÎªÉøÈëµã¡£¹¥»÷Õ߳ɹ¦ÉøÈëµ½¶à¸öÕÆ¹ÜͨѶ¡¢IT ºÍ¹ú·ÀÈ·µ±¾Ö»ú¹¹¡£´Ë±í£¬Ë½ÓªÄÜÔ´¹«Ë¾Ò²Êܵ½ÇÖº¦£¬ÓйزÆÕþÎļþ¡¢Ô±¹¤ÐÅÏ¢¡¢ÉõÖÁʯÓͺÍÌìÈ»Æø×ê̽»î¶¯µÄ¾ßÌåÐÅÏ¢±»µÁ¡£¸ß´ï 8.81 GB µÄÊý¾Ý±»Ð¹Â¶£¬¿ÉÄÜÓÐÖúÓÚ½«À´µÄÈëÇÖ¡£¹¥»÷ÕßʹÓÃÁËÒ»ÖÖ¼¼ÇÉÀ´ÈÃÊܺ¦Õß×°ÖöñÒâÈí¼þ¡£ËûÃÇ·¢ËͼÙ×°³ÉÓ¡¶È¿Õ¾üÔ¼ÇëµÄµç×ÓÓʼþ¡£ÕâЩµç×ÓÓʼþÔ̺¬Ò»¸ö ISO Îļþ£¬¸ÃÎļþËÆºõÊÇÎÞº¦µÄ´æµµ¡£µ±Êܺ¦Õß´ò¿ªISOÎļþʱ£¬ËüÏÖʵÉÏÆô¶¯ÁËÒ»¸ö¼Ù×°³ÉPDFÎĵµµÄ¿ì½Ý·½Ê½Îļþ£¨LNK£© ¡£µ¥»÷ LNK Îļþ»áÔÚ²»Öª²»¾õÖ줻î¶ñÒâÈí¼þ¡£¶øºó£¬¶ñÒâÈí¼þ»áÇÔÈ¡»úÃÜÎĵµ¡¢¸öÈ˵ç×ÓÓʼþ»ººÍ´æµÄÍøÂçä¯ÀÀÆ÷Êý¾Ý¡£ 


https://gbhackers.com/weaponized-air-force-invitation-pdf-indian-defense-energy/


5. Linux ·ì϶¿ÉÄܵ¼ÖÂÓû§ÃÜÂëй¶ºÍ¼ôÌù°å½Ù³Ö


3ÔÂ28ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖLinux ²Ù×÷ϵͳÖеÄutil-linuxÈí¼þ°üµÄwallºÅÁîÖдæÔÚ·ì϶£¬¿ÉÄܵ¼Ö·ÇÌØÈ¨¹¥»÷ÕßÇÔÈ¡ÃÜÂë»ò¸ü¸ÄÊܺ¦ÕߵļôÌù°å¡£¸Ã°²È«ÎÊÌâ±»×·×ÙΪCVE-2024-28085£¬±»³ÆÎª WallEscape£¬²¢ÇÒÔÚ´Óǰ 11 ÄêÖÐÒ»Ïò´æÔÚÓÚ¸ÃÈí¼þ°üµÄÿ¸ö°æ±¾ÖУ¬Ö±µ½×î½ü°ä²¼µÄ2.40¡£Ö»¹Ü¸Ã·ì϶Êǹ¥»÷ÕßÈôºÎºýŪÓû§ÌṩÖÎÀíÔ±ÃÜÂëµÄÒ»¸öÓÐȤʾÀý£¬µ«ÀûÓø÷ì϶¿ÉÄܽöÏÞÓÚijЩÇé¿ö¡£¹¥»÷Õß±ØÒª½Ó¼ûÒѾ­Óжà¸öÓû§Í¨¹ýÖÕ¶ËͬʱÏÎ½ÓµÄ Linux ·þÎñÆ÷¡£WallEscape Ó°Ïì¡°wall¡±ºÅÁ¸ÃºÅÁîͨ³£ÔÚ Linux ϵͳÖÐÓÃÓÚÏòµÇ¼µ½Í³Ò»ÏµÍ³£¨ÀýÈç·þÎñÆ÷£©µÄËùÓÐЧ»§µÄÖն˹㲥ÐÂÎÅ¡£ÓÉÓÚÔÚͨ¹ýºÅÁîÐвÎÊý´¦ÖÃÊäÈëʱδÕýÈ·¹ýÂËתÒåÐòÁУ¬Òò¶ø·ÇÌØÈ¨Óû§Äܹ»Ê¹ÓÃתÒå½ÚÔì×Ö·ûÀûÓø÷ì϶ÔÚÆäËûÓû§µÄÖÕ¶ËÉÏ´´½¨ÐéαµÄ SUDO ÌáÐÑ·û£¬²¢ÓÕÆ­ËûÃÇÊäÈëÖÎÀíÔ±ÃÜÂë¡£×êÑÐÈËÔ±Ö¸³ö£¬ÕâÁ½ÖÖÇé¿öÔÚ Ubuntu 22.04 LTS (Jammy Jellyfish) ºÍ Debian 12.5 (Bookworm) É϶¼´æÔÚ£¬µ«ÔÚ CentOS Éϲ»´æÔÚ¡£


https://www.bleepingcomputer.com/news/security/decade-old-linux-wall-bug-helps-make-fake-sudo-prompts-steal-passwords/?&web_view=true


6. ÂíÈøÖîÈûÖݽ¡È«±£ÏÕ¹«Ë¾Êý¾Ýй¶ӰÏì 280 ÍòÈË


3ÔÂ29ÈÕ£¬ÂíÈøÖîÈûÖݵڶþ´ó½¡È«±£ÏÕ¹«Ë¾ Point32Health й©£¬³¬¹ý 280 ÍòÈ˵ÄÓ×ÎÒÐÅÏ¢ÔÚ2023 Äê 4 ÔµÄÀÕË÷Èí¼þ¹¥»÷Öб»µÁ¡£Õâ´Î¹¥»÷Ó°ÏìÁËÓë Point32Health µÄ¹þ·ð Pilgrim Ò½ÁƱ£½¡Æ·ÅÆÓйصÄϵͳ£¬Ô̺¬Îª¹þ·ð Pilgrim Ò½ÁƱ£½¡Ã³Ò×ºÍ Medicare Advantage Stride ´òËãÌṩ·þÎñµÄϵͳ£¬ÒÔ¼°¡°ÓÃÓÚΪ»áÔ±¡¢ÕË»§¡¢¾­¼ÍÈ˺ÍÌṩÉÌÌṩ·þÎñ¡±µÄϵͳ¡£µ÷²é·¢ÏÖ£¬Óм£ÏóÅú×¢Êý¾ÝÔÚ 2023 Äê 3 Ô 28 ÈÕÖÁ 2023 Äê 4 Ô 17 ÈÕÆÚ¼ä´Ó¹þ·ð Pilgrim ϵͳÖб»¸´ÔìºÍ»ñÈ¡¡£±»µÁÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢½¡È«±£ÏÕÕË»§ÐÅÏ¢¡¢²ÆÕþÕË»§ÐÅÏ¢¡¢²¡Ê·¡¢Õï¶ÏºÍÒ½ÖÎÐÅÏ¢µÈ¡£


https://www.securityweek.com/massachusetts-health-insurer-data-breach-impacts-2-8-million/