6K+ AI Ä£ÐÍ¿ÉÄÜÊܵ½ÑϳÁ RCE ·ì϶µÄÓ°Ïì
°ä²¼¹¦·ò 2024-05-215ÔÂ17ÈÕ£¬ÓÃÓÚ´ó˵»°Ä£ÐÍ (LLM) µÄÊ¢ÐÐ Python °üÖеÄÒ»¸öÑϳÁ·ì϶¿ÉÄÜ»áÓ°Ïì 6,000 ¶à¸öÄ£ÐÍ£¬²¢¿ÉÄܵ¼Ö¹©¸øÁ´¹¥»÷¡£¿ªÔ´llama-cpp-python°ü±»·¢ÏÖÈÝÒ×Êܵ½·þÎñÆ÷¶ËÄ£°å×¢ÈëµÄ¹¥»÷£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¸Ã·ì϶±»×·×ÙΪ CVE-2024-34359£¬Óɰ²È«×êÑÐÔ±ºÍ¿ª·¢ÈËÔ± Patrick Peng ·¢ÏÖ£¬ËûµÄÔÚÏßÕ˺ÅΪ Retro0reg¡£llama-cpp-python °üΪ¿í·ºÊ¢ÐÐµÄ llama.cpp ¿âÌṩ Python °ó¶¨£»llama.cpp ÊÇÒ»¸ö C++ ¿â£¬ÓÃÓÚÔÚÓ×ÎÒÍÆËã»úÉÏÔËÐÐ Meta µÄ LLaMA µÈ LLM ºÍ Mitral AI µÄÄ£ÐÍ¡£llama-cpp-python °ü½øÒ»²½Ê¹¿ª·¢ÈËÔ±¿ÉÄܽ«ÕâЩ¿ªÔ´Ä£Ðͼ¯³Éµ½ Python ÖС£CVE-2024-34359µÄ CVSS ¹Ø¼ü·ÖÊýΪ 9.7£¬ÓÉÓÚ Jinja2 Ä£°åÒýÇæµÄÖ´Ðв»µ±£¬´æÔÚ RCE ·çÏÕ¡£Peng ÔÚ²©¿ÍÎÄÕÂÖÐÚ¹ÊÍ˵£¬¸ÃȱµãÔÊÐí Jinja2 ½âÎö´æ´¢ÔÚÔªÊý¾ÝÖеÄ̸ÌìÄ£°å£¬¶øÎÞÐè½øÐÐËãÕÊ»òɳÏä´¦Ö㬴ӶøÎª¹¥»÷Õß×¢Èë¶ñÒâÄ£°å´´ÔìÁË»úÓö¡£
https://www.scmagazine.com/news/6k-plus-ai-models-may-be-affected-by-critical-rce-vulnerability
2. Grandoreiro ÒøÐÐľÂí´ø×ųÁ´ó¸üлعé
5ÔÂ20ÈÕ£¬¾Ý IBM ³Æ£¬Ò»ÖÖ¶à²úµÄÒøÐÐľÂíÔÚ¶à¸öлÖгÁгöÏÖ£¬Æä¼ÓÇ¿µÄÖ°ÄÜÖ¼ÔÚʹÆä³ÉΪ¸ü׳´óµÄÍþв¡£Õâ¼Ò¿Æ¼¼¾ÞÍ·µÄ X-Force ÍøÂ簲ȫÊýÃŰµÊ¾£¬×Ô 3 Ô·ÝÒÔÀ´£¬ËüÒ»ÏòÔÚ×·×ÙÊýÆð´ó¹æÄ£ÍøÂç´¹µö»î¶¯¡£ÆäÖÐÔ̺¬¼ÙÒâÄ«Î÷¸ç˰ÎñÖÎÀí¾Ö (SAT)¡¢Áª¹úµçÁ¦Î¯Ô±»á (CFE) ºÍÐÐÕþºÍ²ÆÕþ²¿³¤¡¢ÒÔ¼°°¢¸ù͢˰Îñ¾ÖºÍÄÏ·Ç˰Îñ¾Ö (SARS) µÄ¹¥»÷¡£IBM X-Force °µÊ¾£º¡°ÔÚÿ´Î»î¶¯ÖУ¬½Ó¹ÜÕß³ÇÊб»Åúʾµã»÷Á´½ÓÀ´²é¿´·¢Æ±»òÓöȡ¢ÕË»§¶ÔÕ˵¥¡¢¸¶¿îµÈ£¬¾ßÌåÈ¡¾öÓÚ±»¼ÙÒâµÄʵÌå¡£¡±¡°ÈôÊǵã»÷Á´½ÓµÄÓû§Î»ÓÚÌØ¶¨¹ú¶È/µØÓò£¨¾ßÌåÈ¡¾öÓڻ£¬Ä«Î÷¸ç¡¢ÖÇÀû¡¢Î÷°àÑÀ¡¢¸ç˹´ïÀè¼Ó¡¢ÃØÂ³»ò°¢¸ùÍ¢£©£¬ËûÃǽ«±»³Á¶¨Ïòµ½ PDF ͼ±êͼÏñºÍ ZIP ÎļþÊÇÔÚºó¶ÜÏÂÔØµÄ¡£ZIP ÎļþÔ̺¬Ò»¸öÓà PDF ͼ±ê¼Ù×°µÄ´óÐÍ¿ÉÖ´ÐÐÎļþ£¬·¢ÏÖÊÇÔÚµç×ÓÓʼþ·¢Ë͵ÄǰһÌì»òµ±Ìì´´½¨µÄ¡£¡±
https://www.infosecurity-magazine.com/news/grandoreiro-banking-trojan-major/?&web_view=true
3. Kinsing ºÚ¿Í×éÖ¯ÀûÓøü¶àȱµãÀ´À©´óÕë¶Ô½©Ê¬ÍøÂç
5ÔÂ17ÈÕ£¬ÃûΪKinsingµÄ¼ÓÃܽٳÖ×éÖ¯ÒѾչʾ³ö²»ÐÝ·¢Õ¹ºÍÊÊÓ¦µÄÄÜÁ¦£¬Í¨¹ýѸ¿ì½«ÐÂÅû¶µÄ·ì϶¼¯³Éµ½·ì϶ÀûÓÿâÖв¢À©´óÆä½©Ê¬ÍøÂ磬ÊÂʵ֤Ã÷¸Ã×éÖ¯ÊÇÒ»¸ö³ÖÐøµÄÍþв¡£¸Ãµ÷²éÁ˾ÖÀ´×ÔÔÆ°²È«¹«Ë¾ Aqua£¬¸Ã¹«Ë¾½«ÍþвÐÐΪÕßÃèÊöΪ×Ô 2019 ÄêÒÔÀ´»ý¼«²ß¶¯·¸·¨¼ÓÃÜÇ®±ÒÍÚ¿ó»î¶¯¡£Kinsing£¨±ðÃûH2Miner£©ÊǶñÒâÈí¼þ¼°Æä±³ºóµÄµÐÊÖµÄÃû×Ö£¬Ëü²»ÐÝÀûÓÃеķì϶À©´óÆä¹¤¾ß°ü£¬½«ÊÜϰȾµÄϵͳע²áµ½¼ÓÃÜÍÚ¾ò½©Ê¬ÍøÂçÖС£TrustedSec ÓÚ 2020 Äê 1 Ô³õ´Î¼Í¼ÁËËü¡£½üÄêÀ´£¬Éæ¼°»ùÓÚ Golang µÄ¶ñÒâÈí¼þµÄ»î¶¯ÀûÓÃÁËApache ActiveMQ¡¢Apache Log4j¡¢Apache NiFi¡¢Atlassian Confluence¡¢Citrix¡¢Liferay Portal¡¢Linux¡¢Openfire¡¢Oracle WebLogic ServerºÍSaltStackÖеĸ÷ÀàȱµãÀ´·ÛËéÒ×Êܹ¥»÷µÄϵͳ¡£
https://thehackernews.com/2024/05/kinsing-hacker-group-exploits-more.html?&web_view=true
4. 240 ÍòÈËÊܵ½ WebTPA Êý¾Ýй¶µÄÓ°Ïì
5ÔÂ20ÈÕ£¬WebTPA ¹ÍÖ÷·þÎñ¹«Ë¾Åû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁ˳¬¹ý 240 ÍòÈ˵ÄÓ×ÎÒÐÅÏ¢¡£WebTPA ×ܲ¿Î»Óڵ¿ËÈøË¹ÖÝÅ·ÎÄ£¬ÊÇ GuideWell Mutual Holding Corporation µÄÈ«×Ê×Ó¹«Ë¾£¬ÊÇÒ»¼ÒרÃÅ´Óʽ¡È«±£Ïպ͸£Àû´òËãµÄµÚÈý·½ÖÎÀí»ú¹¹ (TPA)¡£WebTPA ÔÚÆäÍøÕ¾ÉϵÄÒ»·Ý֪ͨÖаµÊ¾£¬¸ÃÍøÂçÊÂÎñÊÇÔÚÆäÍøÂçÉϼì²âµ½¿ÉÒɻµÄÖ¤¾ÝºóÓÚ 2023 Äê 12 Ô 28 ÈÕ·¢Ïֵġ£¶Ô´Ëʵĵ÷²éÏÔʾ£¬Ò»ÃûÍþвÐÐΪÕßÔÚ 2023 Äê 4 Ô 18 ÈÕÖÁ 23 ÈÕÆÚ¼ä´ÓÆäϵͳÖÐÇÔÈ¡ÁËÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢ÁªÏµÐÅÏ¢¡¢µ®ÉúÈÕÆÚ¡¢éæÃüÈÕÆÚ¡¢±£ÏÕÐÅÏ¢ºÍÉç»á°²È«ºÅÂ롣ƾ¾Ý TPA µÄ˵·¨£¬Â¶³öµÄÊý¾ÝÒòÈ˶øÒì¡£²ÆÕþÐÅÏ¢¡¢ÐÅÓþ¿¨ºÅÂëÒÔ¼°½¡È«ºÍÒ½ÁÆÐÅϢδÊܵ½¸ÃÊÂÎñµÄÓ°Ïì¡£
https://www.securityweek.com/2-4-million-impacted-by-webtpa-data-breach/
5. Singing River Ò½ÁÆÏµÍ³ÀÕË÷Èí¼þ¹¥»÷Ó°Ïì½ü 90 ÍòÈË
5ÔÂ20ÈÕ£¬Singing River Health System °µÊ¾£¬2023 Äê 8 ÔµÄÀÕË÷Èí¼þ¹¥»÷Ó°ÏìÁË 895,204 ÈË¡£Õâ¼Ò×ܲ¿Î»ÓÚÃÜÎ÷Î÷±ÈÖݵÄÒ½ÁƱ£½¡ÌṩÉÌÔÚÄ«Î÷¸çÍåÑØ°¶µØÓòÔËÓª×Ŷà¼ÒÒ½ÔººÍÒ½ÁÆÉèÊ©¡£Æ¾¾ÝÊý¾Ýй¶֪ͨ£¬Â¶³öµÄÐÅÏ¢Ô̺¬£ºÈ«Ãû¡¢µ®ÉúÈÕÆÚ¡¢ÎïÀíµØÖ·¡¢Éç»á°²È«ºÅÂë (SSN)ºÍÒÔ¼°Ò½Áƺͽ¡È«ÐÅÏ¢¡£Ö»¹Ü´æÔÚÊý¾Ý±»µÁµÄÇé¿ö£¬µ«Ä¿Ç°Ã»ÓÐÖ¤¾ÝÅú×¢Éí·Ý±»µÁ»òڲơ£¸Ã×é֯ͨ¹ý IDX ÏòÊÜÓ°ÏìµÄÈËÌṩ 24 ¸öÔµÄÐÅÓþ¼à¿ØºÍÉí·Ý¸´Ô·þÎñ¡£Bleeping ComputerÚ¹ÊÍ˵£¬¾Ý±¨Â·£¬ËûÃÇй¶ÁËԼĪ 80% µÄ±»µÁÊý¾Ý£¬ÆäÖÐÔ̺¬ 420,766 ¸öÎļþ£¨754 GB£©µÄĿ¼¡£
https://heimdalsecurity.com/blog/singing-river-health-system-ransomware-attack-affects-nearly-900000/
6. ÍøÂç·¸×ï·Ö×ÓÀûÓÃGitHubºÍFileZilla´«²¼¶ñÒâÈí¼þ
5ÔÂ20ÈÕ£¬¾Ý¹Û²ì£¬Ò»³¡¡°¶à·½ÃæµÄ»î¶¯¡±ÀÄÓà GitHub ºÍ FileZilla µÈºÏ·¨·þÎñ£¬Í¨¹ý¼ÙÒâ¿ÉÐÅÈí¼þ£¨Èç1Password¡¢Bartender 5 ºÍ Pixelmator Pro¡£Recorded Future µÄ Insikt GroupÔÚÒ»·Ý»ã±¨ÖаµÊ¾£º¡°¶àÖÖ¶ñÒâÈí¼þ±äÌåµÄ´æÔÚ½²ÁËÈ»¿í·ºµÄ¿çƽָ̨±êÕ½Êõ£¬¶ø³ÁµþµÄ C2 »ù´¡ÉèÊ©Ôò½²ÁËÈ»¼¯ÖÐʽºÅÁîÉèÖã¬Õâ¿ÉÄÜ»áÌá¸ß¹¥»÷µÄЧÄÜ¡£¡¹Øâ¼ÒÃûΪ GitCaught µÄÍøÂ簲ȫ¹«Ë¾ÔÚ×·×ÙÕâÒ»»î¶¯£¬¸Ã¹«Ë¾°µÊ¾£¬¸Ã»î¶¯²»½ö͹ÏÔÁËÀÄÓÃÕæÊµ»¥ÁªÍø·þÎñÀ´²ß¶¯ÍøÂç¹¥»÷£¬²¢ÇÒ»¹ÒÀÀµÓÚÕë¶Ô Android¡¢macOS ºÍ Windows µÄ¶àÖÖ¶ñÒâÈí¼þ±äÌåÀ´Ìá¸ß³É¹¦ÂÊ¡£¿ìÂÊ¡£¹¥»÷Á´±ØÒªÊ¹Óà GitHub ÉϵÄÐéαÅäÖÃÎļþºÍ´æ´¢¿â£¬ÍйܳÛÃûÈí¼þµÄ¼Ùð°æ±¾£¬Ö÷ÕÅÊÇ´ÓÊÜϰȾÉ豸»ñÈ¡Ãô¸ÐÊý¾Ý¡£¶øºó£¬ÕâЩ¶ñÒâÎļþµÄÁ´½Ó»áǶÈëµ½¼¸¸öÓòÖУ¬ÕâЩÓòͨ³£Í¨¹ý¶ñÒâ¸æ°×ºÍ SEO Öж¾»î¶¯½øÐзַ¢¡£
https://thehackernews.com/2024/05/cyber-criminals-exploit-github-and.html


¾©¹«Íø°²±¸11010802024551ºÅ