CISAºÍºÏ×÷ͬ°é°ä²¼ÓйØBlack BastaµÄÕ÷ѯ

°ä²¼¹¦·ò 2024-05-13
1. CISAºÍºÏ×÷ͬ°é°ä²¼ÓйØBlack BastaµÄÕ÷ѯ


5ÔÂ11ÈÕ£¬CISA ÓëÁª¹úµ÷²é¾Ö (FBI)¡¢ÎÀÉúÓ빫¼Ò·þÎñ²¿ (HHS) ÒÔ¼°¶àÖÝÐÅÏ¢¹²ÏíºÍ·ÖÎöÖÐÐÄ (MS-ISAC) ºÏ×÷°ä²¼Á˽áºÏÍøÂ簲ȫÕ÷ѯ (CSA) # StopRansomware£ºBlack BastaÎªÍøÂ簲ȫ·ÀÓùÕßÌṩսÊõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP) ÒÔ¼°ÒÑÖª Black Basta ÀÕË÷Èí¼þ´ÓÊô»ú¹¹Ê¹ÓõķçÏÕÖ¸±ê (IOC)£¬²¢Í¨¹ý FBI µ÷²éºÍµÚÈý·½»ã±¨½øÐмø±ð¡£Black Basta ÊÇÒ»ÖÖÀÕË÷Èí¼þ¼´·þÎñ (RaaS) ±äÌ壬ÓÚ 2022 Äê 4 Ô³õ´Î·¢ÏÖ¡£Black Basta ´ÓÊô¹«Ë¾ÒÑÕë¶Ô±±ÃÀ¡¢Å·Ö޺ͰĴóÀûÑÇµÄ 500 ¶à¸ö˽ӪÐÐÒµºÍ¹Ø¼ü»ù´¡ÉèʩʵÌ壬Ô̺¬Ò½ÁƱ£½¡×éÖ¯¡£CISA ºÍºÏ×÷ͬ°é¼¤Àø×éÖ¯Éó²é²¢Ö´ÐнáºÏ CSA ÖÐÌṩµÄ»º½â´ëÊ©£¬ÒÔÏ÷¼õ Black Basta ºÍÆäËûÀÕË÷Èí¼þÊÂÎñµÄ¿ÉÄÜÐÔºÍÓ°Ïì¡£


https://www.cisa.gov/news-events/alerts/2024/05/10/cisa-and-partners-release-advisory-black-basta-ransomware


2. Chrome´¹Î£¸üУ¬½¨¸´ÑϳÁ·ì϶CVE-2024-4671


5ÔÂ11ÈÕ£¬¹È¸è°ä²¼ÁË Chrome ä¯ÀÀÆ÷µÄ´¹Î£¸üУ¬½¨¸´ÁËÒ»¸öÑϳÁµÄÁãÈÕ·ì϶CVE-2024-4671¡£¡°¿ªÊͺóʹÓá±·ì϶ӰÏì Chrome µÄÊÓ¾õ×é¼þ£¬¸Ã×é¼þÕÆ¹ÜäÖȾºÍÏÔʾÄÚÈÝ¡£CVE-2024-4671 ÊÇÓÉһλÄäÃû×êÑÐÈËÔ±¼ø±ð²¢Ïò Google »ã±¨µÄ¡£¸Ã¹«Ë¾Ð¹Â©£¬¸Ã·ì϶¿ÉÄÜÔÚ±»»ý¼«ÀûÓᣴ˷ì϶ÀûÓÃÁË·¨Ê½ÔÚ¿ªÊÍÄÚ´æÖ¸Õëºó³ÖÐøÊ¹ÓøÃÄÚ´æÖ¸ÕëµÄȱµã£¬¿ÉÄܻᵼÖÂδ¾­ÊÚȨµÄÊý¾Ý²Ù×÷»ò±ÀÀ£¡£ÓÉÓÚ¸üв¿ÊðÔÚ¸÷ÀàÆ½Ì¨£¨Ô̺¬ Mac¡¢Windows ºÍ Linux£©ÉÏ£¬Òò¶øÓû§Ó¦È·±£ËûÃÇÔËÐеÄÊÇ×îа汾µÄ Chrome¡£Äܹ»Í¨¹ýµ¼º½ÖÁ¡°ÉèÖá±>¡°¹ØÓÚ Chrome¡±À´²é³­¡£ÕâÖÖ×Ô¶¯´ëÊ©¿ÉÈ·Èϲ¹¶¡ÒÑÀûÓ㬴Ӷø±£»¤ÄúµÄϵͳÃâÊÜDZÔڵĹ¥»÷¡£ÈôÊÇÄú·¢ÏÖÄúµÄä¯ÀÀÆ÷²»ÊÇ×îа汾£¬½¨ÒéÄúµ±¼´¸üС£


https://blog.qualys.com/vulnerabilities-threat-research/2024/05/10/get-weekends-back-put-chrome-cves-like-cve-2024-4671-on-auto-patching


3. IntelBroker Ðû³ÆÒѳɹ¦ÇÖÈëÅ·ÃË·¨ÂɺÏ×÷»ú¹¹


5ÔÂ10ÈÕ£¬ºÚ¿ÍÔÚBreachForumsÉϰ䷢ÁËÕâÒ»ÐÂÎÅ£¬³ÆÕâ´Îй¶ÊÂÎñ²úÉúÔÚ±¾ÔÂÔçЩʱ³½£¬Éæ¼°¸ß¶ÈÃô¸ÐºÍ»úÃÜÐÅÏ¢¡£²¢ÇÒIntelBrokerй©Êý¾ÝÒѱ»ÏúÊÛ¸øÄäÃûÂò¼Ò¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Í¬ÃËÔ±¹¤µÄÓ×ÎÒÐÅÏ¢¡¢½ö¹©¹Ù·½Ê¹Óà (FOUO) Ô´´úÂë¡¢×÷Õ½ÎļþºÍÊÜÓ°ÏìµÄ¾ßÌå»ú¹¹ÁбíµÈ¡£ÈôÊÇÊôʵ£¬´ËÀà¹Ø¼üÊý¾ÝµÄ¶³ö¿ÉÄÜ»á¶ÔÕâЩ»ú¹¹µÄ³ÖÐøÔËÓªºÍÓ×ÎÒ°²È«×é³ÉÑϳÁ·çÏÕ¡£¾Ý³ÆµÄÎ¥¹æÐÐΪ»¹¿ÉÄÜ·ÛËéÅ·ÖÞÐ̾¯×éÖ¯Ðж¯µÄÆëÈ«ÐԺͰ²È«ÐÔ¡£Å·ÖÞÐ̾¯×éÖ¯ÉÐδ°ä²¼ÕýʽÉêÃ÷£¬¾ßÌå×¢Ã÷ÊÇ·ñ²úÉúÁËÎ¥¹æÐÐΪ¡¢Î¥¹æË®Æ½ÒÔ¼°Îª¼õÇáÆäÓ°Ïì¶ø²ÉÈ¡µÄ´ëÊ©¡£


https://www.hackread.com/europol-hacked-intelbroker-claims-data-breach/


4. LLM ½Ù³Ö¹¥»÷ÈÃºÚ¿Í½Ù³Ö AI Ä£ÐÍÒÔ»ñÈ¡ÀûÈó


5ÔÂ10ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪ¡°LLMjacking¡±µÄÐÂÐÍÍøÂç¹¥»÷´òË㣬ÀûÓñ»µÁµÄÔÆÆ¾Ö¤À´½Ù³Ö׳´óµÄÈËΪÖÇÄÜÄ£ÐÍ¡£ÍøÂç·¸×ï·Ö×ÓʹÓñ»µÁµÄÔÆÍ´´¦£¨ºÜ¿ÉÄÜÊÇ´ÓÊÜËðµÄÔÆÕÊ»§»ñµÃµÄ£©À´¶Ô×¼ÔËÐйýÆÚÈí¼þµÄϵͳ£¬ÒÔÉøÈëÔËÐÐ LLM µÄϵͳ£¬ÒÔ½âËøÆäÄÜÁ¦µÄ±¦¿â¡£×êÑÐÈËÔ±°µÊ¾£¬ÔÚËûÃǵÄ×êÑа䲼֮ǰ£¬¹¥»÷ÕßÒѾ­½Ó¼ûÁËÊ®ÖÖ·ÖÆçÈËΪÖÇÄÜ·þÎñµÄ LLM Ä£ÐÍ£¬Ô̺¬ Anthropic¡¢AWS Bedrock¡¢Google Cloud Vertex AI¡¢Mistral ºÍ OpenAI¡£×êÑÐÈËÔ±·¢ÏÖ£¬¹¥»÷ÕßÔÚ´Û¸ÄÊÜϰȾϵͳÖеÄÈÕÖ¾ÉèÖã¬ÕâÅú×¢ËûÃÇÔÚʹÓñ»µÁµÄ LLM ½Ó¼ûȨÏÞʱÓÐÒâÊÔͼÌӱܼì²â£¬Õâ͹ÏÔÁËÍøÂç·¸×ï·Ö×ÓµÄÈÕÒæµó»¬¡£


https://www.hackread.com/llmjacking-attack-hackers-hijack-ai-models/


5. ¶íº¥¶íÖÝ²ÊÆ±Ôâµ½DragonForce¹¥»÷Ó°Ï쳬¹ý50ÍòÈË


5ÔÂ10ÈÕ£¬¶íº¥¶íÖÝ²ÊÆ±±¾ÖܰµÊ¾£¬ÀÕË÷Èí¼þ×é֯ȥÄêÌáÒéµÄ¶íº¥¶íÖÝ²ÊÆ±ÍøÂç¹¥»÷ÒÑÓ°ÏìÁ˳¬¹ý 50 ÍòÈË¡£¸ÃÊÂÎñÓÚ 2023 Äê 12 ÔÂÏÂÑ®ÆØ¹â£¬Æäʱ¶íº¥¶íÖÝ²ÊÆ±¹«Ë¾°ä·¢¹Ø¹ØÒ»Ð©ÏµÍ³ÒÔ¶ôÔìÎ¥¹æÐÐΪ¡£Ô¼ÄªÔÚͳһ¹¦·ò£¬Ò»¸öÃûΪ DragonForce µÄ¿´ËÆÐµÄÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£  ¶ûºó£¬ºÚ¿ÍÌṩÁË¾Ý³Æ´Ó¶íº¥¶íÖÝ²ÊÆ±¹«Ë¾ÇÔÈ¡µÄ³¬¹ý 90 GB µÄÎļþ£¨ÒÔ .bak ±¸·ÝÌåʽ£©¡£ËûÃÇÐû³ÆÒÑ»ñµÃ³¬¹ý 150 ÍòÌõÔ±¹¤ºÍÍæ¼ÒÐÅÏ¢¼Í¼£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·¡¢½±½ð¡¢µ®ÉúÈÕÆÚºÍÉç»á°²È«ºÅÂë¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸ÃÀÕË÷Èí¼þ×éÖ¯×î³õÐû³ÆÇÔÈ¡ÁË 300 Íò±Ê¼Í¼¡£¶íº¥¶íÖÝ²ÊÆ±Í¨ÖªÃåÒòÖÝ×ܼì²ì³¤£¬Ô¼ÄªÓÐ 538,000 ÈËÊܵ½Ó°Ïì¡£·¢Ë͸ø×ܼì²ì³¤µÄ»ã±¨ºÍ·¢Ë͸øÊÜÓ°ÏìÓ×ÎÒµÄÐź¯Ö¤Êµ£¬È«ÃûºÍÉç»á°²È«ºÅÂëÒѱ»Ð¹Â¶¡£


https://www.securityweek.com/500000-impacted-by-ohio-lottery-ransomware-attack/


6. HijackLoaderͨ¹ý±øÆ÷»¯PNGͼƬ¹¥»÷Windows


5ÔÂ10ÈÕ£¬ÔÚ×î½üµÄÍøÂç°²È«Í»ÆÆÖУ¬×êÑÐÈËÔ±°ä²¼ÁË HijackLoader ¶ñÒâÈí¼þµÄ³Á´ó¸üУ¬ÕâÊÇÒ»ÖÖ¸´ÔÓµÄÄ£¿é»¯¼ÓÔØ·¨Ê½£¬Òò´«µÝ¸÷Àà¶ñÒâ¸ºÔØ¶ø³ôÃûÔ¶Ñï¡£¸Ã¶ñÒâÈí¼þÒѸüÐÂΪ¿É²¿Êð Amadey¡¢Lumma Stealer¡¢Racoon Stealer v2 ºÍRemcos RATµÈÍþв£¬Õ¹Ê¾ÁËÆä²Ù×÷µÄ¾ªÈ˶àÖ°ÄÜÐÔ¡£HijackLoader ÒѾ­·¢Õ¹³ÉΪһÖÖм¼Êõ£¬É漰ʹÓÃPNG ͼÏñÀ´½âÃܲ¢Æô¶¯ºóÐø½×¶ÎµÄ¼ÓÔØ¡£´Ë²½ÖèÊǸü¿í·ºÕ½ÊõµÄÒ»²¿ÃÅ£¬ÆäÖÐÔ̺¬¶¯Ì¬ API ½âÎö¡¢ÏêϸµÄ×èÖ¹Áбí¹ý³Ì²é³­ÒÔ¼°ÌÓ±ÜÓû§Ä£Ê½¹Ò¹³£¬Í¹ÏÔÁ˶ñÒâÈí¼þÔÚÌӱܼì²â·½ÃæµÄÈÕÒæ¸´ÔÓÐÔ¡£ÕâЩ¸üл¹ÒýÈëÁËÖ¼ÔÚ¼ÓÇ¿¶ñÒâÈí¼þÖ°ÄܵÄÐÂÄ£¿é¡£ÆäÖÐÔ̺¬´´½¨¹ý³Ì¡¢ÈƹýÓû§ÕÊ»§½ÚÔì (UAC)¡¢Ïò Windows Defender Ôö³¤ÅųýÏîÒÔ¼°Ð´ÈëÎļþµÄÖ°ÄÜ£¬´Ó¶øÀ©´óÁ˶ñÒâÈí¼þ·çÏպͽÚÔìÊÜϰȾϵͳµÄÄÜÁ¦¡£


https://gbhackers.com/hijackloader-malware/