¼Ùð°ÍÁÖµ±¾Ö Android ÀûÓ÷¨Ê½ÇÔÈ¡Êý¾ÝÓÃÓÚÚ¿Æ
°ä²¼¹¦·ò 2024-06-046ÔÂ2ÈÕ£¬ºÜ¶àµ±¾Ö»ú¹¹¶¼ÔÚÏßÌṩ·þÎñ£¬ÒÔ·½±ã¹«Ãñ¡£´Ë±í£¬ÈôÊÇÄܹ»Í¨¹ýÒÆ¶¯ÀûÓ÷¨Ê½ÌṩÕâÏî·þÎñ£¬½«¼«¶È·½±ãºÍ±ã½Ý¡£µ«ÊÇ£¬µ±¶ñÒâÈí¼þ¼Ù×°³ÉÕâЩ·þÎñʱ»á²úÉúʲô£¿McAfee ÒÆ¶¯×êÑÐÍŶӷ¢ÏÖÁËÒ»¿î¼Ù×°³É°ÍÁÖµ±¾Ö»ú¹¹·þÎñµÄ InfoStealer Android ¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þ¼Ù×°³É°ÍÁֵĹٷ½ÀûÓ÷¨Ê½£¬²¢Ðû´«Óû§Äܹ»ÔÚÊÖ»úÉϸüлòÉêÇë¼ÝÊ»ÅÆÕÕ¡¢Ç©Ö¤ºÍÉí·ÝÖ¤¡£±»¸æ°×ºýŪµÄÓû§»á¾ø²»ÓÌÔ¥µØ»ñµÃÕâЩ·þÎñËùÐèµÄÓ×ÎÒÐÅÏ¢¡£ËüÃÇͨ¹ý¸÷À෽ʽ½Ó´¥Óû§£¬Ô̺¬ Facebook ºÍ¶ÌÐÅ¡£²»ÊìϤÕâЩ¹¥»÷µÄÓû§ºÜÈÝÒ×·¸Ï·¢ËÍÓ×ÎÒÐÅÏ¢µÄÃýÎó¡£°ÍÁÖÓÐÒ»¸öµ±¾Ö»ú¹¹£¬ÃûΪÀͶ¯Á¦Êг¡¼à¹Ü¾Ö (LMRA)¡£¸Ã»ú¹¹ÔÚÓÉÀ͹¤²¿³¤µ£ÈÎÖ÷ϯµÄ¶Ê»áÁ쵼ϣ¬Õ¼ÓÐÆëÈ«µÄ²ÆÕþºÍÐÐÕþ¶ÀÁ¢ÐÔ¡£ËûÃÇÌṩ¸÷ÀàÒÆ¶¯·þÎñ£¬´óÎÞÊýÀûÓ÷¨Ê½Ö»ÌṩһÏî·þÎñ¡£È»¶ø£¬Õâ¸ö¼ÙðÀûÓ÷¨Ê½È´Ðû´«Ìṩ¶àÏî·þÎñ¡£³ýÁË×î³£¼ûµÄ¼ÙÒâ LMRA µÄ¼ÙðÀûÓÃ±í£¬»¹Óи÷Àà¼ÙðÀûÓã¬Ô̺¬°ÍÁֺͿÆÍþÌØÒøÐÐ (BBK)¡¢°ÍÁÖ½ðÈڿƼ¼¹«Ë¾ BenefitPay£¬ÉõÖÁ»¹ÓмÙ×°Óë±ÈÌØ±Ò»ò´û¿îÓйصÄÀûÓá£ÕâЩÀûÓÃʹÓÃÓë LMRA ¼ÙðÀûÓÃÒ»ÑùµÄ¼¼ÊõÀ´ÇÔÈ¡Ó×ÎÒÐÅÏ¢¡£
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/
2. SHINYHUNTERSÔÚÏúÊÛ3000Íòɣ̹µÂÒøÐпͻ§µÄÊý¾Ý
6ÔÂ2ÈÕ£¬³ôÃûÔ¶ÑïµÄÍþвÐÐΪÕß ShinyHunters ÔÚÏúÊ۾ݳƴÓɣ̹µÂÒøÐÐÇÔÈ¡µÄ´óÁ¿Êý¾Ý¡£ShinyHunters Ðû³ÆÇÔÈ¡ÁË 3000 Íò¿Í»§¡¢Ô±¹¤ºÍÒøÐÐÕË»§Êý¾Ý¡£5 ÔÂÖÐÑ®£¬Î÷°àÑÀ½ðÈÚ»ú¹¹É£Ì¹µÂÒøÐÐÅû¶ÁËÒ»Â·Éæ¼°µÚÈý·½ÌṩÉ̵ÄÊý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁËÖÇÀû¡¢Î÷°àÑÀºÍÎÚÀ¹çµÄ¿Í»§¡£¸ÃÒøÐз¢ÏÖµÚÈý·½ÌṩÉÌÍÐ¹ÜµÄÆäÖÐÒ»¸öÊý¾Ý¿âÔ⵽δ¾ÊÚȨµÄ½Ó¼û¡£¸Ã¹«Ë¾°ä·¢µ±¼´²ÉÈ¡´ëÊ©½ÚÔìÊÂÎñ¡£¸Ã¹«Ë¾×èÖ¹Á˶ÔÊý¾Ý¿âµÄÈëÇÖ½Ó¼û£¬²¢³ÉÁ¢Á˶î±íµÄÚ²ÆÔ¤·À½ÚÔì´ëÊ©À´±£»¤ÊÜÓ°ÏìµÄ¿Í»§¡£±»µÁÊý¾Ý¿âÔ̺¬ËùÓÐÏÖÈκͲ¿ÃÅǰÈÎÔ±¹¤µÄÐÅÏ¢¡£¸ÃÒøÐÐÖ¸³ö£¬¸ÃÊý¾Ý¿â²»´æ´¢ÂòÂôÊý¾Ý¡¢ÍøÉÏÒøÐоßÌåÐÅÏ¢¡¢ÃÜÂë»òÆäËûÔÊÐíijÈ˽øÐÐÂòÂôµÄÊý¾Ý¡£¸Ã½ðÈÚ»ú¹¹ÉÐδÌṩÕâ´ÎÊÂÎñµÄ¼¼Êõϸ½Ú»òй¶µÄÊý¾ÝÖÖÀࡣĿǰÉв»Ã÷ÏÔÓм¸¶àÈËÊܵ½Ó°Ïì¡£ShinyHunters Ðû³Æ Ticketmaster Ôâµ½ºÚ¿Í¹¥»÷£¬²¢ÒÔ 50 ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛ 1.3 TB µÄÊý¾Ý£¬ÆäÖÐÔ̺¬ 5.6 ÒÚ¿Í»§µÄÆëÈ«¾ßÌåÐÅÏ¢¡£±»µÁÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÃÅÆ±ÏúÊۺͶ©µ¥¾ßÌåÐÅÏ¢¡£
https://securityaffairs.com/163956/data-breach/shinyhunters-claims-santander-breach.html
3. CISA ÖÒ¸æ³Æ Linux ÌØÈ¨ÌáÉý·ì϶¿ÉÄܱ»»ý¼«ÀûÓÃ
6ÔÂ2ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) ÔÚÆäÒÑÖªÀûÓ÷ì϶ (KEV) Ŀ¼ÖÐÔö³¤ÁËÁ½¸ö·ì϶£¬ÆäÖÐÔ̺¬ Linux ÄÚºËȨÏÞÌáÉý·ì϶¡£¸Ã¸ßÑϳÁÐÔ·ì϶ ( CVE-2024-1086)ÓÚ 2024 Äê 1 Ô 31 ÈÕ³õ´ÎÅû¶£¬ÊÇ netfilter£ºnf_tables ×é¼þÖеĿªÊͺóʹÓÃÎÊÌ⣬µ«×îÔçÊÇÔÚ 2014 Äê 2 ÔµÄÒ»´ÎÌá½»ÖÐÒýÈëµÄ¡£Netfilter ÊÇ Linux ÄÚºËÌṩµÄÒ»¸ö¿ò¼Ü£¬ÔÊÐí¸÷ÀàÓëÍøÂçÓйصIJÙ×÷£¬ÀýÈçÊý¾Ý°ü¹ýÂË¡¢ÍøÂçµØÖ·×ª»» (NAT) ºÍÊý¾Ý°üÅú¸Ä¡£¸Ã·ì϶ÊÇÓÉÓÚ 'nft_verdict_init()' º¯ÊýÔÊÐí½«ÕýÖµÓÃ×÷¹³×ÓÅоöÖеÄɾ³ýÃýÎ󣬴Ӷøµ¼Ö 'nf_hook_slow()' º¯ÊýÔÚ NF_DROP ·¢³öÀàËÆÓÚ NF_ACCEPT µÄɾ³ýÃýÎóʱִÐÐË«³Á¿ªÊÍ¡£ÀûÓà CVE-2024-1086 ¿ÉÈÃÓµÓб¾µØ½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÔÚÖ¸±êϵͳÉÏʵÏÖȨÏÞÌáÉý£¬²¢¿ÉÄÜ»ñµÃ root ¼¶½Ó¼ûȨÏÞ¡£
https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-linux-privilege-elevation-flaw/
4. Ðéαä¯ÀÀÆ÷¸üлᴫ²¼BitRATºÍLumma Stealer¶ñÒâÈí¼þ
6ÔÂ3ÈÕ£¬ÐéαµÄÍøÂçä¯ÀÀÆ÷¸üб»ÓÃÓÚ´«²¼Ô¶³Ì½Ó¼ûľÂí (RAT) ºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬ÀýÈçBitRATºÍLumma Stealer£¨±ðÃû LummaC2£©¡£µ±Ç±ÔÚÖ¸±ê½Ó¼ûÒ»¸ö´øÓÐÏÝÚåµÄÍøÕ¾Ê±£¬¹¥»÷Á´¾ÍÆðÍ·ÁË£¬¸ÃÍøÕ¾Ô̺¬Ö¼ÔÚ½«Óû§³Á¶¨Ïòµ½Ðéαä¯ÀÀÆ÷¸üÐÂÒ³Ãæ£¨¡°chatgpt-app[.]cloud¡±£©µÄ JavaScript ´úÂë¡£³Á¶¨ÏòµÄÍøÒ³Ç¶ÈëÁËÖ¸Ïò ZIP ´æµµÎļþ£¨¡°Update.zip¡±£©µÄÏÂÔØÁ´½Ó£¬¸ÃÎļþÍйÜÔÚ Discord Éϲ¢×Ô¶¯ÏÂÔØµ½Êܺ¦ÕßµÄÉ豸¡£ÖµµÃÖ¸³öµÄÊÇ£¬ÍþвÐÐΪÕßʱʱʹÓà Discord ×÷Ϊ¹¥»÷ý½é£¬ Bitdefender×î½üµÄ·ÖÎö·¢ÏÖ£¬ÔÚ´ÓǰÁù¸öÔÂÖУ¬Óг¬¹ý 50,000 ¸öΣÏÕÁ´½Ó´«²¼¶ñÒâÈí¼þ¡¢ÍøÂç´¹µö»î¶¯ºÍÀ¬»øÓʼþ¡£ZIP ´æµµÎļþÖдæÔÚÁíÒ»¸ö JavaScript Îļþ£¨¡°Update.js¡±£©£¬Ëü»á´¥·¢ PowerShell ¾ç±¾µÄÖ´ÐУ¬¸Ã¾ç±¾ÕƹܴÓÔ¶³Ì·þÎñÆ÷ÒÔ PNG ͼÏñÎļþµÄ´ó¾Ö¼ìË÷ÆäËûÓÐЧ¸ºÔØ£¬Ô̺¬ BitRAT ºÍ Lumma Stealer¡£
https://thehackernews.com/2024/06/beware-fake-browser-updates-deliver.html
5. ¾¯·½µ·»ÙµÁ°æµçÊÓÁ÷ýÌåÍøÂçÒѾ»ñÀû570ÍòÃÀÔª
6ÔÂ3ÈÕ£¬Î÷°àÑÀ¾¯·½µ·»ÙÁËÒ»¸ö·¸·¨Ã½ÌåÄÚÈÝ´«²¼ÍøÂ磬¸ÃÍøÂç×Ô 2015 ÄêÆðÍ·ÔËÓªÒÔÀ´ÒÑ»ñÀû³¬¹ý 570 ÍòÃÀÔª¡£¸Ãµ÷²éÓÚ 2022 Äê 11 ÔÂÆðÍ·£¬Æäʱ´´ÒâÓëÓéÀÖͬÃË (ACE) Ìá½»ÁËÒ»·ÝͶËߣ¬¾Ù±¨Á½¸öÍøÒ³¼Óº¦ÁË֪ʶ²úȨ¡£ÕâÐ©ÍøÕ¾ÍйÜ×Å·¸·¨ IPTV ·þÎñ¡°TVMucho¡±£¨Ò²³ÆÎª¡°Teeveeing¡±£©£¬¾Ý ACE ³Æ£¬¸Ã·þÎñÔÚ 2023 ÄêµÄ½Ó¼ûÁ¿³¬¹ý 400 Íò´Î¡£¾¯·½µ÷²éºó·¢ÏÖ£¬ÕâÐ©ÍøÕ¾µÄËùÓÐÕß±³ºóÓÐÒ»¸ö´ó¹æÄ£µÄ IPTV Ðж¯£¬ÎªÔ¼Äª 14,000 ÃûÓû§Ìṩ 130 ¸ö¹ú¼ÊµçÊÓÆµÂ·ºÍÊýǧ²¿µçÓ°ºÍµçÊÓ¾çµÄ·¸·¨½Ó¼ûȨÏÞ¡£¸Ã·þÎñµÄÓû§Æ¾¾ÝÆä¶©Ôĵȼ¶Ö§¸¼û¿Ô 11 ÖÁ 20.5 ÃÀÔª»òÿÄê 97 ÖÁ 182.5 ÃÀÔª£¬ÕâʹµÃ IPTV ƽ̨ÔËÓªÉÌ×ܹ²»ñÀû 570 ÍòÃÀÔª¡£
https://www.bleepingcomputer.com/news/legal/police-dismantle-pirated-tv-streaming-network-that-made-57-million/
6. Hugging Face ³ÆºÚ¿Í´Ó Spaces ÇÔÈ¡Éí·ÝÑéÖ¤ÁîÅÆ
6ÔÂ2ÈÕ£¬ÈËΪÖÇÄÜÆ½Ì¨ Hugging Face °µÊ¾Æä Spaces ƽ̨Ôâµ½ÈëÇÖ£¬ºÚ¿ÍµÃÒÔ»ñÈ¡Æä³ÉÔ±µÄÉí·ÝÑéÖ¤»úÃÜ¡£Hugging Face Spaces ÊÇÒ»¸öÓÉÉçÇøÓû§´´½¨ºÍÌá½»µÄ AI ÀûÓ÷¨Ê½¿â£¬ÔÊÐíÆäËû³ÉÔ±ÑÝʾËüÃÇ¡£Hugging Face °µÊ¾£¬ËûÃÇÒѾ³·ÏúÁËй¶»úÃÜÖеÄÉí·ÝÑéÖ¤ÁîÅÆ£¬²¢Í¨¹ýµç×ÓÓʼþ֪ͨÁËÊÜÓ°ÏìµÄÓû§¡£µ«ÊÇ£¬ËûÃǽ¨ÒéËùÓÐ Hugging Face Spaces Óû§Ë¢ÐÂËûÃǵÄÁîÅÆ²¢Çл»µ½ ϸÁ£¶È½Ó¼ûÁîÅÆ£¬ÕâʹµÃ×éÖ¯Äܹ»¸üÑϸñµØ½ÚÔìËÓÐȨ½Ó¼ûËûÃÇµÄ AI Ä£ÐÍ¡£¸Ã¹«Ë¾ÔÚÓë±í²¿ÍøÂ簲ȫר¼ÒºÏ×÷µ÷²éÕâ´ÎÎ¥¹æÐÐΪ£¬²¢Ïò·¨ÂɺÍÊý¾Ý±£»¤»ú¹¹»ã±¨¸ÃÊÂÎñ¡£
https://www.bleepingcomputer.com/news/security/ai-platform-hugging-face-says-hackers-stole-auth-tokens-from-spaces/


¾©¹«Íø°²±¸11010802024551ºÅ