Telegram ½¨¸´ÓÃÓÚÆô¶¯ Python ¾ç±¾µÄ Windows ÀûÓ÷¨Ê½ÁãÈÕ·ì϶
°ä²¼¹¦·ò 2024-04-154ÔÂ12ÈÕ£¬Telegram ½¨¸´ÁËÆä Windows ×ÀÃæÀûÓ÷¨Ê½ÖеÄÒ»¸öÁãÈÕ·ì϶£¬¸Ã·ì϶¿ÉÓÃÓÚÈÆ¹ý°²È«ÖҸ沢×Ô¶¯Æô¶¯ Python ¾ç±¾¡£´Óǰ¼¸Ì죬 ÓÐ¹Ø Windows °æ Telegram ÖÐÉæÏÓÔ¶³Ì´úÂëÖ´Ðзì϶µÄÒ¥ÑÔÔÚ X ºÍºÚ¿ÍÂÛ̳ÉÏÁ÷´«¡£¹ÌÈ»ÆäÖÐһЩÌû×ÓÐû³ÆÕâÊÇÒ»¸öÁãµã»÷ȱµã£¬µ«ÑÝʾËùνµÄ°²È«ÖÒ¸æÈƹýºÍ RCE ·ì϶µÄÊÓÆµÃ÷ÏÔµØÏÔʾÓÐÈ˵ã»÷¹²ÏíýÌåÀ´Æô¶¯ Windows ÍÆËãÆ÷¡£Telegram Desktop ¿Í»§¶Ë»á¸ú×Ù Óë·çÏÕÎļþ£¨ÀýÈç¿ÉÖ´ÐÐÎļþ£©ÓÐ¹ØµÄ ÎļþÀ©´óÃûÁÐ±í¡£µ±ÓÐÈËÔÚ Telegram Öз¢ËÍÆäÖÐÒ»ÖÖÎļþÀàÐÍ£¬²¢ÇÒÓû§µ¥»÷¸ÃÎļþʱ£¬Telegram Ê×ÏÈ»áÏÔʾÒÔϰ²È«ÖҸ棬¶ø²»ÊÇÔÚ Windows ÖеĹØÁª·¨Ê½ÖÐ×Ô¶¯Æô¶¯¡£ÈôÊǹ¥»÷Õß¿ÉÄÜÓÕÆÖ¸±ê´ò¿ªÎļþ£¬Õ⽫ÓÐЧµØÔÊÐí¹¥»÷ÕßÈÆ¹ý°²È«ÖҸ沢ÔÚÖ¸±êµÄ Windows É豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£
https://www.bleepingcomputer.com/news/security/telegram-fixes-windows-app-zero-day-used-to-launch-python-scripts/
2. ·¨¹ú¶à¸öÊе±¾ÖµÄ¹²Ïí·þÎñÆ÷Ôâµ½´ó¹æÄ£ÍøÂç¹¥»÷
4ÔÂ12ÈÕ£¬Ê¥ÄÉÔó¶ûÊгƣ¬¹¥»÷ÈÔÔÚ³ÖÐø¡£¡°ÕâÁ½¸öÉçÇøµÄ·þÎñÎÞ·¨Õý³£ÔËÐУ¬¡±¸ÃÊÐÔÚÒ»·Ý¾¯±¨ÖÐ֪ͨ¾ÓÃñ£¬Ö¸µÄÊÇÊ¥ÄÉÔó¶ûÊкÍÊ¥ÄÉÔó¶û³ÇÇø¡£ÆäËûÊÜÓ°ÏìµÄ³ÇÊÐÔ̺¬ÃÉͼÍß²¼ÁÐËþÄá¡¢¶«ÈÕ¡¢ÀɳÅåÀÕµÂÂêÀ³ºÍ²¨¶ûÄáʲ£¬ÒÔ¼°Ë÷Äɵ·òºÍÊ¥ÄÉÔó¶ûµØÓò¿É³ÖÐø·¢Õ¹»ú¹¹¡£Í¨Öª³Æ£¬¡°Ïֽ׶Σ¬ÍøÂç¹¥»÷µÄ·¢Ô´ºÍ³ÖÐø¹¦·òÉв»Ã÷ÏÔ¡±¡£Í¨Öª³Æ£¬Ëæ×Å·þÎñ¸´Ô£¬Ê¥ÄÉÔó¶ûÊкÍÊ¥ÄÉÔó¶ûÊн«ÔÚÉ罻ýÌåºÍµ±¾ÖÍøÕ¾Éϰ䲼¸üÐÂÐÅÏ¢¡£¹ÌȻûÓÐй©ÊÂÎñµÄÐÔÖÊ£¬µ«Õâ´ÎÖжÏÊÇÔÚ 3 Ô 11 ÈÕÖÁ 12 ÈÕ²úÉúµÄ´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ¹¥»÷Ö®ºó²úÉúµÄ£¬¸Ã¹¥»÷ʹ¶à¸ö·¨¹úµ±¾ÖÍøÕ¾³äÒç×ÅÐéαÁ÷Á¿£¬µ«²¢Î´Öжϵ±¾Ö·þÎñ¡£DDoS ÊÂÎñ²úÉú¼¸Ììºó£¬ÕƹܵǼǺÍÔöԮʧҵÈËԱȷµ±²¿ÃÅÃÅ France Travail Åû¶ÁËһ·¾Þ´óµÄÊý¾Ýй¶ÊÂÎñ£¬¸ÃÊÂÎñй¶Á˳¬¹ý 4300 Íò¹«Ãñ 20 ÄêǰµÄ¸öÈËÐÅÏ¢¡£¸Ã²¿ÃŰµÊ¾£¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢·¨¹úÀ͹¤±êʶ·û¡¢µç×ÓÓʼþµØÖ·¡¢ÓÊÕþµØÖ·ºÍµç»°ºÅÂë¶¼±»Ð¹Â¶¡£
https://www.theregister.com/2024/04/12/french_municipalities_cyberattack/
3. CISA ¶½´ÙÔÚ Sisense й¶ºóµ±¼´³ÁÖÃÆ¾Ö¤
4ÔÂ12ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) Åû¶ÁËÓ°ÏìÒµÎñ·ÖÎöÌṩÉÌ Sisense µÄ·ì϶£¬²¢¶½´ÙÆä¿Í»§±£ÁôÆäÍ´´¦¡£2024 Äê 4 Ô 11 ÈÕ£¬CISA °ä²¼ÁËÓÐ¹Ø Sisense ¿Í»§Êý¾Ý¿ÉÄÜÔ⵽й¶µÄ²¼¸æ¡£¸Ã»ú¹¹¡°Ä¿Ç°ÔÚÓë˽ӪÐÐÒµºÏ×÷ͬ°éºÏ×÷£¬ÒÔÓ¦¶Ô¶ÀÁ¢°²È«×êÑÐÈËÔ±×î½ü·¢ÏÖµÄÓ°Ïì Sisense£¨Ò»¼ÒÌṩÊý¾Ý·ÖÎö·þÎñµÄ¹«Ë¾£©µÄ·ì϶¡£¡±½ØÖÁ׫д±¾ÎÄʱ£¬Sisense ÉÐδ¹«¿ªÈ·ÈÏ»ò½â¾öÕâһΥ¹æÎÊÌ⡣Ȼ¶ø£¬ÍøÂ簲ȫ¼ÇÕß Brian Krebs ÔÚËûµÄÍøÕ¾ÉϰµÊ¾£¬¸Ã¹«Ë¾ÏòÆä¿Í»§·¢ËÍÁËÒ»·âµç×ÓÓʼþ£¬È·ÈÏÆäÒÑÒâʶµ½¡°Sisense ¹«Ë¾µÄijЩÐÅÏ¢¿ÉÄÜÒÑÔÚÎÒÃDZ»·î¸æµÄÊÜÏÞ½Ó¼û·þÎñÆ÷ÉÏÌṩ¡£¡±¸Ãµç×ÓÓʼþµÄ×÷Õß¡¢Sisense µÄ CISO Sangram Dash ²¹³ä·£º¡°ÎÒÃÇÔÚµ±Õæ¶Ô´ý´ËÊ£¬²¢µ±¼´·¢Õ¹µ÷²é¡£¡±´ïʲ³ÖÐøËµÂ·£º¡°ÎÒÃÇÀñƸÁËÐÐÒµµ±ÏȵÄר¼ÒÀ´ÐÖúÎÒÃǽøÐе÷²é¡£¸ÃÊÂÎñ²¢Î´µ¼ÖÂGA»Æ½ð¼×ÒµÎñÔËÓªÖжϡ£Sisense ¿Í»§À´×Ô¸÷¸ö´¹Ö±ÐÐÒµ£¬Ô̺¬ÒøÐкͽðÈÚ¡¢µçÐÅ¡¢½ÌÓýºÍÒ½ÁƱ£½¡¡£
https://www.infosecurity-magazine.com/news/cisa-urges-reset-sisense-breach/
4. Æ×Ó°Ñ³Ö GITHUB µÄËÑË÷Á˾ÖÀ´´«²¼¶ñÒâÈí¼þ
https://securityaffairs.com/161792/cyber-crime/githubs-search-results-distribute-malware.html
5. ¼ÓÄôóÁãÊÛÁ¬Ëø¾ÞÍ· GIANT TIGER й¶280ÍòÌõÊý¾Ý
4ÔÂ14ÈÕ£¬Ò»ÃûÍøÃûΪ ShopifyGUY µÄÍþвÐÐΪÕßÐû³Æ¶Ô¹¥»÷¼ÓÄôóÁãÊÛÁ¬Ëøµê Giant Tiger ÕÆ¹Ü£¬²¢ÔÚºÚ¿ÍÂÛ̳ÉÏй¶ÁË 280 Íò±Ê¼Í¼¡£Giant Tiger ÊÇÒ»¼Ò¼ÓÄôóÕÛ¿ÛÁ¬Ëøµê£¬ÔÚ¼ÓÄôó¸÷µØ¾Óª 260 ¶à¼ÒÉ̵ꡣ°ä²¼¸ÃÌû×ÓµÄÍþвÐÐΪÕßÐû³ÆÒÑÉÏ´« 2024 Äê 3 Ô±»µÁµÄ¹«Ë¾µÄÆëÈ«Êý¾Ý¿â¡£¸ÃÌû×Ó±³ºóµÄÍþвÐÐΪÕßÐû³ÆÒÑÉÏ´« 2024 Äê 3 Ô±»µÁµÄ Giant Tiger ¿Í»§¼Í¼µÄ¡°ÆëÈ«¡±Êý¾Ý¿â¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬µç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØÖ·ºÍÍøÕ¾»î¶¯¡£²ÆÕþÊý¾Ý²¢Î´Êܵ½ËùνÊÂÎñµÄÓ°Ïì¡£¼ÓÄôóÁãÊÛÁ¬ËøµêµÄ¿Í»§Äܹ»Í¨¹ý²éÎÊÊý¾Ýй¶¼à¿Ø·þÎñ HaveIBeenPwned À´²é³Ð¹Â¶µÄµµ°¸ÖÐÊÇ·ñ´æÔÚÆäÊý¾Ý¡£
https://securityaffairs.com/161811/cyber-crime/giant-tiger-data-breach.html
6. RokuÔ⵽ײ¿â¹¥»÷³¬¹ý57Íò¸öÕ˺ÅÐÅϢй¶
4ÔÂ12ÈÕ£¬Roku °ä·¢£¬576,000 ¸öÕÊ»§ÔÚеÄײ¿â¹¥»÷ÖÐÔâµ½ºÚ¿Í¹¥»÷£¬ÍþвÐÐΪÕßʹÓôӵÚÈý·½Æ½Ì¨ÇÔÈ¡µÄÍ´´¦¡£½ñÄêÔçЩʱ³½£¬Roku ¼ì²âµ½Òì³£ÕÊ»§»î¶¯£¬²¢·¢ÏÖδ¾ÊÚȨµÄ¹¥»÷ÕßʹÓÃͨ¹ý¡°Í´´¦Ìî³ä¡±´Ó·ÖÆçÆðÔ´»ñÈ¡µÄµÇ¼ʹ´¦½Ó¼ûÁËԼĪ 15,000 ¸öÓû§ÕÊ»§¡£¸Ã¹«Ë¾ÊµÏÖ¶ÔÊ׸ö°²È«·ì϶µÄµ÷²éºó£¬ÓÚÈýÔ³õ֪ͨÁËÊÜÓ°ÏìµÄ¿Í»§¡£¸Ã¹«Ë¾³ÖÐø¼à¿ØÕË»§»î¶¯£¬²¢·¢ÏÖÁ˵ڶþÆðÓ°ÏìԼĪ 576,000 ¸öÕË»§µÄÊÂÎñ¡£Ã»Óм£ÏóÅú×¢ Roku ÊÇÕâЩ¹¥»÷ÖÐʹÓõÄÕÊ»§Í´´¦µÄÆðÔ´£¬Ò²Ã»Óм£ÏóÅú×¢ Roku µÄϵͳÔÚÕâÁ½ÆðÊÂÎñÖÐÊܵ½ÁËÇÖº¦¡£Ïà·´£¬ÕâЩ¹¥»÷ÖÐʹÓõĵǼʹ´¦ºÜ¿ÉÄÜÊÇ´ÓÆäËûÆðÔ´»ñÈ¡µÄ£¬ÀýÈçÁíÒ»¸öÔÚÏßÕÊ»§£¬ÊÜÓ°ÏìµÄÓû§¿ÉÄÜʹÓÃÁËÒ»ÑùµÄÍ´´¦¡£¡±ÔĶÁ¸Ã¹«Ë¾°ä²¼µÄÐÂΟ塣¡°ÔÚ²»µ½ 400 Æð°¸ÀýÖУ¬¶ñÒâÐÐΪÕߵǼ²¢Ê¹ÓÃÕâЩÕÊ»§Öд洢µÄ¸¶¿î·½Ê½Î´¾ÊÚȨ²É°ìÁ÷ýÌå·þÎñ¶©ÔÄºÍ Roku Ó²¼þ²úÆ·£¬µ«ËûÃÇÎÞ·¨½Ó¼ûÈκÎÃô¸ÐÐÅÏ¢£¬Ô̺¬ÆëÈ«µÄÐÅÓþ¿¨ºÅ»òÆäËûÐÅÏ¢¡£ÆëÈ«µÄ¸¶¿îÐÅÏ¢¡£
https://securityaffairs.com/161765/data-breach/roku-second-data-breach.html


¾©¹«Íø°²±¸11010802024551ºÅ