ÃÀ¹úÔËͨÐÅÓÿ¨ÔâÓöµÚÈý·½Êý¾Ýй¶

Ðû²¼Ê±¼ä 2024-03-06
1. ÃÀ¹úÔËͨÐÅÓÿ¨ÔâÓöµÚÈý·½Êý¾Ýй¶


3ÔÂ4ÈÕ £¬ÃÀ¹úÔËͨ¾¯¸æ¿Í»§ £¬ÔÚÉÌ»§´¦ÖÃÆ÷Ôâµ½ºÚ¿Í¹¥»÷ºó £¬ÐÅÓÿ¨ÔÚµÚÈý·½Êý¾Ýй¶ÖÐ̻¶¡£¸Ãʼþ²¢·ÇÓÉÃÀ¹úÔËͨ¿¨µÄÊý¾Ýй¶Ôì³É £¬¶øÊÇÓÉ´¦ÖÃÃÀ¹úÔËͨ¿¨»áÔ±Êý¾ÝµÄÉ̼Ҵ¦ÖÃÆ÷Ôì³É¡£´Ë´Î鶵¼Ö¿ͻ§µÄÃÀ¹úÔËͨ¿¨Õʺš¢ÐÕÃûºÍ¿¨¹ýÆÚÊý¾Ý±»ºÚ¿Í»ñÈ¡¡£Ä¿Ç°Éв»Çå³þÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡¢ÄĸöÉ̼Ҵ¦ÖÃÆ÷Ôâµ½ÆÆ»µÒÔ¼°¹¥»÷·¢ÉúµÄʱ¼ä¡£µ± BleepingComputer ÏòÃÀ¹úÔËͨѯÎÊÓйش˴Îй¶µÄ¸ü¶àÐÅϢʱ £¬ÎÒÃDZ»¼û¸æËûÃDz»»á͸¶ÆäÒµÎñ¹ØϵºÍÉÌÒµºÏ×÷»ï°éµÄÏêϸÐÅÏ¢ £¬Ä¿Ç°Ò²Ã»Óиü¶àÐÅÏ¢¿É¹©·ÖÏí¡£²»Íâ £¬ÃÀ¹úÔËͨȷʵÌåÏÖ £¬ËûÃÇÒÑ֪ͨËùÐèµÄ¼à¹Ü»ú¹¹ £¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§·¢³ö¾¯±¨¡£


https://www.bleepingcomputer.com/news/security/american-express-credit-cards-exposed-in-third-party-data-breach/#google_vignette


2. JetBrains TeamCity ÑÏÖØȱÏÝ¿ÉÄܵ¼Ö·þÎñÆ÷±»½Ó¹Ü


3ÔÂ5ÈÕ £¬JetBrains TeamCity On-Premises Èí¼þÖÐÅû¶ÁËÒ»¶ÔеÄÄþ¾²Â©¶´ £¬ÍþвÐÐΪÕß¿ÉÀûÓÃÕâЩ©¶´À´¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£ÕâЩȱÏݱàºÅΪ CVE-2024-27198£¨CVSS ÆÀ·Ö£º9.8£©ºÍ CVE-2024-27199£¨CVSS ÆÀ·Ö£º7.3£© £¬ÒÑÔÚ°æ±¾ 2023.11.4 Öеõ½½â¾ö¡£ËüÃÇ»áÓ°Ïì 2023 Äê 11 Ô 3 ÈÕ֮ǰµÄËùÓÐ TeamCity On-Premises °æ±¾¡£JetBrainsÔÚÖÜÒ»Ðû²¼µÄͨ¸æÖÐÌåÏÖ£º¡°ÕâЩ©¶´¿ÉÄÜʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý HTTP(S) ·ÃÎÊ TeamCity ·þÎñÆ÷À´ÈƹýÉí·ÝÑéÖ¤¼ì²é²¢»ñµÃ¶Ô¸Ã TeamCity ·þÎñÆ÷µÄ¹ÜÀí¿ØÖÆ¡£¡±TeamCity Cloud ʵÀýÒÑÕë¶ÔÕâÁ½¸öȱÏݽøÐÐÁËÐÞ²¹¡£ÍøÂçÄþ¾²¹«Ë¾ Rapid7 ÓÚ 2024 Äê 2 Ô 20 ÈÕ·¢ÏÖ²¢³ÂËßÁËÕâЩÎÊÌâ £¬¸Ã¹«Ë¾ÌåÏÖ £¬CVE-2024-27198 ÊÇÒ»ÖÖÉí·ÝÑéÖ¤Èƹý°¸Àý £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÍêÈ«ÆÆ»µÒ×Êܹ¥»÷µÄ·þÎñÆ÷¡£


https://thehackernews.com/2024/03/critical-jetbrains-teamcity-on-premises.html


3. ÄϺ«Ç鱨»ú¹¹³Æ £¬±±³¯ÏʺڿÍ͵ÇÔÁË°ëµ¼ÌåÐÅÏ¢


3ÔÂ5ÈÕ £¬±±³¯ÏʺڿÍ×éÖ¯ÈëÇÖÁËÖÁÉÙÁ½¼ÒÄϺ«°ëµ¼ÌåÖÆÔìÉ豸Éú²úÉÌ £¬ÒÔÌÓ±ÜÖƲò¢Éú²ú×Ô¼ºµÄ°ëµ¼Ìå £¬ÓÃÓÚÎäÆ÷ÏîÄ¿¡£ÕâÒ»ÏûÏ¢´«³öºó £¬ÄϺ«×Üͳ¾¯¸æ˵ £¬±±³¯ÏÊ¿ÉÄÜ»á½ÓÄÉÌôÐÆÐÐΪ £¬Èç½øÐÐÍøÂç¹¥»÷»òÉ¢²¼Ðé¼ÙÐÂÎÅ £¬×ÌÈÅËÄÔµÄÒé»áÑ¡¾Ù¡£Ç鱨»ú¹¹ÌåÏÖ £¬ÄϺ«¹«Ë¾×ÔÈ¥Äêµ×¾Í³ÉΪ±±³¯Ïʺڿ͵ÄÖصãÄ¿±ê £¬²¢ºôÓõ¼ÓÇ¿Äþ¾²ÐÔ¡£Ç鱨»ú¹¹ÌåÏÖ £¬±±³¯ÏÊÔÚ12ÔºÍ2Ô·ֱðÈëÇÖÁËÁ½¼Ò¹«Ë¾µÄ·þÎñÆ÷ £¬ÍµÈ¡Á˲úÎïÉè¼ÆͼֽºÍ¹¤³§ÕÕƬ¡£


https://news.hitb.org/content/seoul-spies-say-north-korea-hackers-stole-semiconductor-secrets


4. WogRAT ºóÃÅ£ºÇ±·üÔÚÔÚÏß¼Çʱ¾ÖеÄÒþÐζñÒâÈí¼þ

3ÔÂ4ÈÕ £¬Ò»ÖÖз¢ÏÖµÄÃûΪ¡°WogRAT¡±µÄºóÃŶñÒâÈí¼þÕýÔÚÏò Windows ºÍ Linux Óû§·¢³ö¾¯±¨¡£WogRAT ÓÉAhnLab Äþ¾²Ç鱨ÖÐÐÄ(ASEC)·¢ÏÖ £¬ÒòÆäÄܹ»Õë¶ÔÁ½ÖÖÁ÷ÐвÙ×÷ϵͳ¶øÍÑÓ±¶ø³ö¡£WogRAT Ëƺõαװ³ÉÎļþ¹²ÏíÍøÕ¾ÉϵĺϷ¨ÊµÓù¤¾ß £¬ÆÛÆ­ºÁÎÞ½äÐĵÄÓû§ÏÂÔØËü¡£ÓÐȤµÄÊÇ £¬¸Ã¶ñÒâÈí¼þαװ³ÉÓÕÈ˵ÄÃû³Æ £¬ÀýÈç¡°BrowserFixup.exe¡±ºÍ¡°ChromeFixup.exe¡±¡£ASEC µÄ·ÖÎö±íÃ÷ £¬WogRAT ×Ô 2022 Äêµ×ÒÔÀ´Ò»Ö±»îÔ¾ £¬ËƺõÖ÷Òª¹Ø×¢ÑÇÖÞ¹ú¼ÒµÄÄ¿±ê¡£Windows °æ±¾µÄ WogRAT ÇÉÃîµØ½«×Ô¼ºÎ±×°³É Adobe ¹¤¾ß £¬²¢Óà .NET ±àд¡£

https://securityonline.info/wograt-backdoor-the-stealthy-malware-lurking-in-online-notepads/


5. Õë¶ÔÒ½Áƹ«Ë¾ Change Healthcare µÄÀÕË÷¹¥»÷ÊÕµ½2200 ÍòÃÀÔªÊê½ð


3ÔÂ5ÈÕ £¬Ò½Áƹ«Ë¾Change HealthcareµÄÀÕË÷Èí¼þ¹¥»÷ÊǶàÄêÀ´×î¾ßÆÆ»µÐÔµÄÖ®Ò» £¬Ê¹ÃÀ¹ú¸÷µØµÄÒ©µê£¨°üÂÞÒ½ÔºÄÚµÄÒ©µê£©ÏÝÈë̱»¾×´Ì¬ £¬µ¼ÖÂÒ©ÎïÅäË͹úÄÚÊ®ÌìÒÔÉϵÄÑÏÖØÕÏ°­¡£ÏÖÔÚ £¬·¸×ïÊÀ½çÄÚ²¿µÄÒ»³¡ÕùÖ´½ÒʾÁËÕâ¸ö²»Í£Éú³¤µÄΣ»úµÄнøÕ¹£º¹¥»÷±³ºóµÄºÚ¿ÍµÄһλºÏ×÷»ï°éÖ¸³ö £¬ÕâЩºÚ¿Í £¬Ò»¸öÃûΪAlphV»òBlackCatµÄ×éÖ¯ £¬ÊÕµ½ÁËÒ»±Ê¿´ÆðÀ´ÏñÊǾ޶îÊê½ðÖ§¸¶µÄ2200ÍòÃÀÔª½»Òס£3ÔÂ1ÈÕ £¬ÓëAlphVÏà¹ØÁªµÄ±ÈÌرҵØÖ·ÔÚµ¥±Ê½»Ò×ÖÐÊÕµ½ÁË350¸ö±ÈÌØ±Ò £¬»òÕßƾ¾ÝÆäʱµÄ»ãÂʽӽü2200ÍòÃÀÔª¡£È»ºó £¬Á½Ììºó £¬Ä³ÈËÔÚRAMPÕâ¸ö°µÍøÂÛ̳ÉÏÉù³Æ×Ô¼ºÊÇAlphVµÄÁ¥Êô³ÉÔ±Ö®Ò» £¬²¢Ö¸¿ØAlphVÆÛÆ­ÁËËûÃÇÓ¦µÃµÄChange HealthcareÊê½ðµÄ·Ý¶î £¬²¢Ö¸Ïò±ÈÌرÒÇø¿éÁ´ÉϹûÈ»¿É¼ûµÄ2200ÍòÃÀÔª½»Ò××÷Ϊ֤Ã÷¡£


https://news.hitb.org/content/hackers-behind-change-healthcare-ransomware-attack-just-received-22-million-payment


6. Ñо¿ÈËÔ±Ñз¢³öµÚÒ»¸ö GenAI Èä³æ


3ÔÂ4ÈÕ £¬Ñо¿ÈËÔ±ÒѾ­´´½¨Á˵ÚÒ»´úÈ˹¤ÖÇÄÜÈä³æ £¬Ëü¿ÉÒÔÇÔÈ¡Êý¾Ý¡¢Á÷´«¶ñÒâÈí¼þ²¢Í¨¹ýµç×ÓÓʼþÁ÷´«¡£¿µÄζûÀí¹¤Ñ§ÔºµÄ Ben Nassi¡¢ÒÔÉ«ÁÐÀí¹¤Ñ§ÔºµÄ Stav Cohen ºÍ Intuit µÄ Ron Bitton ´´½¨ÁËÕâÖÖ×ÔÎÒ¸´ÖÆÈä³æ £¬²¢ÒÔ 1980 Äê´úѬȾϵͳµÄÎÛÃûÕÑÖøµÄÈä³æÃüÃûΪ¡°Morris II¡±¡£ËûÃǵĴ´×÷Ä¿±êÊÇÈ˹¤ÖÇÄÜÓ¦Ó÷¨Ê½ºÍÖ§³ÖÈ˹¤ÖÇÄܵĵç×ÓÓʼþÖúÊÖ¡£ËûÃÇ·¢±íÁËһƪÑо¿ÂÛÎĺÍÊÓƵ £¬Õ¹Ê¾ÁËÇÔÈ¡Êý¾ÝºÍÓ°ÏìÆäËûµç×ÓÓʼþϵͳµÄÒªÁì¡£¸ÃÈä³æ²¡¶¾»ù±¾ÉϽ«·´¿¹ÐÔÀàÐ͵ÄÊý¾ÝǶÈëµ½¶ñÒâµç×ÓÓʼþÖÐ £¬ÀûÓÃÊܺ¦ÕßµÄϵͳÀ´Á÷´«ÏûÏ¢¡¢Ö´ÐжñÒâ»î¶¯²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£´ÓÕ½ÂÔÉϽ² £¬ÕâÒ»²»Í£Éú³¤µÄÎÊÌâµÄÒªº¦ÔÚÓÚ £¬ÎªÁË×·Çó GenAI ºÍ LLM ϵͳµÄ¸ü¶à¹¦Ð§ºÍºóÐø¼ÛÖµ £¬ËüÃÇÐèÒª¸ü¶àµÄ·ÃÎʺÍȨÏÞ²ÅÆøÔÚÆäËùÔÚµÄÊý×ÖÉú̬ϵͳÖÐ×öÊ¡£Òò´Ë £¬Èç¹ûÊܵ½¶ñÒâ·½µÄָʾ £¬ËüÃǾͻá³ÉΪһ¸ö¼«ÆäÇ¿´óµÄ¹¤¾ß £¬ÎÞÂÛÊǺõĻ¹ÊÇ»µµÄ¡£


https://securityboulevard.com/2024/03/researchers-give-birth-to-the-first-genai-worm/