ºÚ¿ÍÀûÓà Aiohttp ©¶´Ñ°ÕÒÒ×Êܹ¥»÷µÄÄ¿±ê
Ðû²¼Ê±¼ä 2024-03-183ÔÂ16ÈÕ£¬ÀÕË÷Èí¼þ¹¥»÷Õß¡°ShadowSyndicate¡±ÕýÔÚɨÃèÒ×ÊÜ CVE-2024-23334£¨aiohttp Python ¿âÖеÄĿ¼±éÀú©¶´£©Ó°ÏìµÄ·þÎñÆ÷¡£Aiohttp ÊÇÒ»¸ö¹¹½¨ÔÚ Python Òì²½ I/O ¿ò¼Ü Asyncio Ö®ÉϵĿªÔ´¿â£¬ÓÃÓÚ´¦ÖôóÁ¿²¢·¢ HTTP ÇëÇ󣬶øÎÞÐ贫ͳµÄ»ùÓÚÏ̵߳ÄÍøÂç¡£2024 Äê 1 Ô 28 ÈÕ£¬aiohttp Ðû²¼ÁË °æ±¾ 3.9.2£¬½â¾öÁË CVE-2024-23334£¬ÕâÊÇÒ»¸öÑÏÖصÄ·¾¶±éÀú©¶´£¬Ó°Ïì 3.9.1 ¼°¸üÔç°æ±¾µÄËùÓÐ aiohttp °æ±¾£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß·ÃÎÊÒ×Êܹ¥»÷µÄ·þÎñÆ÷ÉϵÄÎļþ¡£¸ÃȱÏÝÊÇÓÉÓÚµ±¾²Ì¬Â·Óɵġ°follow_symlinks¡±ÉèÖÃΪ¡°True¡±Ê±ÑéÖ¤²»³äʵ£¬´Ó¶øÔÊÐíδ¾ÊÚȨ·ÃÎÊ·þÎñÆ÷¾²Ì¬¸ùĿ¼֮ÍâµÄÎļþ¡£ShadowSyndicate ÊÇÒ»¸ö»ú»áÖ÷Òå¡¢ ¾¼Ã¶¯»úµÄÍþвÐÐΪÕߣ¬×Ô 2022 Äê 7 ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Óë Quantum¡¢Nokoyawa¡¢BlackCat/ALPHV¡¢Clop¡¢Royal¡¢Cactus ºÍ Play µÈÀÕË÷Èí¼þ¾úÖêÓвîÒìˮƽµÄÐÅÈΡ£Group-IB ÈÏΪÍþвÐÐΪÕßÊÇÓë¶à¸öÀÕË÷Èí¼þÔËÓª»ú¹¹ºÏ×÷µÄÁ¥Êô»ú¹¹¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-aiohttp-bug-to-find-vulnerable-networks/
2. ·¨¹ú TRAVAIL Êý¾Ýй¶ӰÏì 4300 ÍòÈË
3ÔÂ16ÈÕ£¬·¨¹úÍøÂç·¸×ïÔ¤·À¼Æ»®½øÐеÄÊÓ²ìÏÔʾ£¬ÍþвÐÐΪÕßÔÚ 2024 Äê 2 Ô 6 ÈÕÖÁ 3 Ô 5 ÈÕÆÚ¼äÇÔÈ¡ÁË 4300 ÍòÈ˵ĸöÈËÐÅÏ¢¡£2023 Äê 8 Ô£¬·¨¹úÕþ¸®¾ÍÒµ»ú¹¹ P?le emploiÔâÓöÊý¾Ýй¶£¬²¢Í¨ÖªÁËÊÜÄþ¾²Â©¶´Ó°ÏìµÄ 1000 ÍòÈË¡£´Ë´ÎÄþ¾²Â©¶´Ì»Â¶ÁËÊÜÓ°Ïì¸öÈ˵ÄÐÕÊÏ¡¢Ãû×ÖºÍÉç»áÄþ¾²ºÅÂë¡£µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÃÜÂëºÍ²ÆÕþÊý¾Ý²»»á±»Ð¹Â¶¡£¸Ã»ú¹¹½¨ÒéÇóÖ°Õ߶ÔÈκÎDZÔÚµÄÆÛÕ©»î¶¯±£³Ö¾¯Ì裬¸Ã»ú¹¹»¹Ôö²¹Ëµ£¬¸Ã»ú¹¹ÌṩµÄÅâ³¥ºÍÖ§³ÖÒÔ¼°·ÃÎÊ polo-emploi.frµÄ¸öÈ˿ռ䲻´æÔÚÈκηçÏÕ¡£·¨¹úÕþ¸®²¢Î´½«Õâ´Î¹¥»÷¹é¾ÌÓÚÒÑÖªµÄÀÕË÷Èí¼þÍŻ²»Í⣬Bleeping Computer ÊÓ²ì µ½£¬Äþ¾²¹«Ë¾Emsisoft ÔÚÆä MOVEitÒ³ÃæÉÏÁгöÁ˸÷¨¹úÕþ¸®»ú¹¹ £¬ÕâÒâζ×ÅËüºÜ¿ÉÄÜÊÇClop ÀÕË÷Èí¼þÍÅ»ï µÄÊܺ¦Õß¡£
https://securityaffairs.com/160556/data-breach/france-travail-data-breach-34m-people.html
3. ºÚ¿ÍÉù³ÆÒѾ¹¥ÆÆ Viber²¢ÇÔÈ¡ÁË 740GB Êý¾Ý
3ÔÂ16ÈÕ£¬Handala Hack ÔÚ Telegram Ìû×ÓÖÐÉù³ÆËûÃÇÇÔÈ¡ÁËÁè¼Ý 740GB µÄÊý¾Ý£¬ÆäÖаüÂÞ Viber µÄÔ´´úÂë¡£¸Ã×éÖ¯ÒªÇóΪ±»µÁÐÅÏ¢Ö§¸¶ 8 ±ÈÌرң¨¼´ 583,000 ÃÀÔª£©µÄÊê½ð¡£Viber ÊÇÒ»¿îÏûÏ¢Ó¦Ó÷¨Ê½£¬ÓÚ 2010 ÄêÍƳö£¬²¢ÓÚ 2014 Äê±»ÈÕ±¾¿ç¹ú¹«Ë¾ÀÖÌ칫˾ÒÔ 9 ÒÚÃÀÔªÊÕ¹º£¬¸ÃÓ¦Ó÷¨Ê½ÒѶԺڿ͵ÄÖ¸¿Ø×ö³öÁË»ØÓ¦¡£¸Ã¹«Ë¾·ñÈÏÓÐÈκÎÈëÇÖÆäϵͳ»òÊý¾Ý鶵ÄÖ¤¾Ý£¬µ«È·ÈÏÒÑÆô¶¯ÊÓ²ìÒÔºËʵÊÇ·ñ·¢ÉúÄþ¾²Â©¶´¡£Èç¹ûµÃµ½Ö¤Êµ£¬Õâ¿ÉÄÜÊǽü´úÀúÊ·ÉÏ×î´óµÄÊý¾Ýй¶Ê¼þÖ®Ò»¡£×¨¼ÒÈÏΪ£¬ÕâÖÖй¶¿ÉÄÜÉæ¼°¸öÈËÏûÏ¢¡¢Í¨»°¼Ç¼¡¢ÁªÏµ·½Ê½ºÍ²ÆÕþÐÅÏ¢£¬¿ÉÄÜ»á¶Ô Viber Óû§Ôì³É»ÙÃðÐÔ¹¥»÷¡£Handala Hack ÊÇÒ»¸öÓÐÕùÒéµÄ×éÖ¯£¬ÒÔÖ§³Ö°ÍÀÕ˹̹ÊÂÒµµÄÒÔÉ«ÁÐʵÌå¼°ÆäÃËÓÑΪĿ±ê¶øÎÅÃû¡£×Ô 2023 Äê 12 Ô½¨Á¢ Telegram ƵµÀ²¢Ëæºó¼ÓÈëÎ¥¹æÂÛ̳ÒÔÀ´£¬ËüÒ»Ö±ºÜ»îÔ¾¡£Óë´Ëͬʱ£¬Viber Óû§Ó¦½÷É÷ÐÐʲ¢¸ü¸ÄÃÜÂ룬¾¯ÌèÍøÂçµöÓãʵÑ飬²¢Í¨¹ý¼ì²é Viber µÄ¹Ù·½ÇþµÀËæʱÁ˽âÓйØÉæÏÓÊý¾Ý鶵ÄÈκθüС£
https://www.hackread.com/hackers-claim-740gb-of-data-viber-messaging-app/
4. ºÚ¿ÍÀûÓà GitHub ÉϵÄÆƽâÈí¼þÁ÷´« RisePro
3ÔÂ16ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÐí¶à GitHub ´æ´¢¿âÌṩÆƽâÈí¼þ£¬ÕâЩÈí¼þÓÃÓÚÁ÷´«ÃûΪ RisePro µÄÐÅÏ¢ÇÔÈ¡·¨Ê½¡£¾Ý G DATA ³Æ£¬¸Ã»î¶¯´úºÅΪgitgub £¬°üÂÞÓë 11 ¸ö²îÒìÕË»§Ïà¹ØµÄ 17 ¸ö´æ´¢¿â¡£½ñºó£¬Ïà¹Ø´æ´¢¿âÒѱ»Î¢ÈíÆìÏÂ×Ó¹«Ë¾É¾³ý¡£Github ÉÏͨ³£Ê¹ÓÃÂÌÉ«ºÍºìɫԲȦÀ´ÏÔʾ×Ô¶¯¹¹½¨µÄ״̬¡£Gitgub Íþв¼ÓÈëÕßÔÚËûÃÇµÄ README.md ÖÐÌí¼ÓÁËËĸöÂÌÉ« Unicode ԲȦ£¬¼Ù×°ÔÚµ±Ç°ÈÕÆÚÅÔ±ßÏÔʾ״̬£¬²¢ÌṩºÏ·¨ÐÔºÍнü¶ÈµÄ¸ÐÊÜ¡£RAR ´æµµÒªÇóÊܺ¦ÕßÌṩ´æ´¢¿â README.md ÎļþÖÐÌáµ½µÄÃÜÂ룬ÆäÖаüÂÞÒ»¸ö°²×°·¨Ê½Îļþ£¬¸ÃÎļþ½âѹÏÂÒ»½×¶ÎµÄÓÐЧ¸ºÔØ£¬ÕâÊÇÒ»¸öÅòÕ͵½ 699 MB µÄ¿ÉÖ´ÐÐÎļþ£¬Ö¼ÔÚʹ·ÖÎö¹¤¾ßÍ߽⣬ÀýÈçIDA רҵ°æ¡£¸ÃÎļþµÄʵ¼ÊÄÚÈÝ£¨×ܼƽöΪ 3.43 MB£©³äµ±¼ÓÔØ·¨Ê½£¬½« RisePro£¨°æ±¾ 1.6£©×¢Èë AppLaunch.exe »ò RegAsm.exe ÖС£RisePro ÔÚ 2022 Äêµ×ͻȻ³ÉΪÈËÃǹØ×¢µÄ½¹µã£¬ÆäʱËüʹÓÃÃûΪ PrivateLoader µÄ°´°²×°¸¶·Ñ (PPI) ¶ñÒâÈí¼þÏÂÔØ·þÎñ½øÐзַ¢¡£
https://thehackernews.com/2024/03/hackers-using-cracked-software-on.html
5. ºÚ¿Íͨ¹ýÎäÆ÷»¯ PDF ÓÕÆÓû§°²×°¶ñÒâÈí¼þ
3ÔÂ16ÈÕ£¬ÔÚÒ»³¡ÅÓ´óµÄÍøÂç¹¥»÷»î¶¯ÖУ¬¶ñÒâÐÐΪÕßð³ä¸çÂ×±ÈÑÇÕþ¸®»ú¹¹£¬Õë¶ÔÀ¶¡ÃÀÖÞ¸÷µØµÄ¸öÈ˽øÐй¥»÷¡£¹¥»÷Õß·Ö·¢°üÂÞ PDF ¸½¼þµÄµç×ÓÓʼþ£¬´íÎóµØÖ¸¿ØÊÕ¼þÈËÎ¥·´½»Í¨¹æÔò»òÆäËûÎ¥·¨ÐÐΪ¡£ÕâЩÆÛÆÐÔͨÐÅÖ¼ÔÚÇ¿ÆÈÊܺ¦ÕßÏÂÔØ°üÂÞ VBS ½Å±¾µÄ´æµµ£¬´Ó¶øÆô¶¯¶à½×¶ÎѬȾ¹ý³Ì¡£Ö´Ðк󣬾¹ý»ìÏýµÄ VBS ½Å±¾»á´¥·¢ PowerShell ½Å±¾£¬Í¨¹ýÁ½²½ÇëÇó¹ý³Ì´ÓºÏ·¨ÔÚÏß´æ´¢·þÎñÖмìË÷×îÖյĶñÒâÈí¼þ¸ºÔØ¡£Æ¾¾Ý ANY.RUN Óë GBHackers ·ÖÏíµÄÄþ¾²³ÂËߣ»×î³õ£¬½Å±¾´Ó textbin.net µÈ×ÊÔ´»ñÈ¡ÓÐЧ¸ºÔصĵØÖ·¡£È»ºó£¬Ëü¼ÌÐø´ÓÌṩµÄµØÖ·ÏÂÔز¢Ö´ÐÐÓÐЧ¸ºÔØ£¬¸ÃÓÐЧ¸ºÔØ¿ÉÒÔÍйÜÔÚÖÖÖÖƽ̨ÉÏ£¬°üÂÞ cdn.discordapp(.)com¡¢pasteio(.)com¡¢hidrive.ionos.com ºÍ wtools.io¡£¹¥»÷ÕßµÄÖ´ÐÐÁ´×ñÑ´Ó PDF µ½ ZIP£¬È»ºóµ½ VBS ºÍ PowerShell£¬×îºóµ½¿ÉÖ´ÐÐÎļþ (EXE) µÄ˳Ðò¡£×îÖÕµÄÓÐЧ¸ºÔر»Ê¶±ðΪ¼¸ÖÖÒÑÖªµÄÔ¶³Ì·ÃÎÊľÂí (RAT) Ö®Ò»£¬ÌرðÊÇAsyncRAT¡¢njRAT»òRemcos¡£ÕâЩ¶ñÒⷨʽÒòÆäÄܹ»¶ÔÊÜѬȾϵͳÌṩδ¾ÊÚȨµÄÔ¶³Ì·ÃÎʶøÎÛÃûÕÑÖø£¬¸øÊܺ¦ÕßµÄÒþ˽ºÍÊý¾ÝÄþ¾²´øÀ´ÖØ´ó·çÏÕ¡£
https://gbhackers.com/hackers-trick-users-to-install-malware-via-weaponized-pdf/
6. TikTok±»Òâ´óÀû¼à¹Ü»ú¹¹·£¿î½ü1100ÍòÃÀÔª
3ÔÂ16ÈÕ£¬Æ¾¾Ý¸Ã¹ú¾ºÕù¹ÜÀí¾Ö (AGCM) µÄÒ»·ÝÐÂΟ壬Òâ´óÀûÕþ¸®ÖÜËÄ¶Ô TikTok ´¦ÒÔ 1090 ÍòÃÀÔª·£¿î£¬ÔÒòÊÇÆäÖú³¤ÁË¿ÉÄÜËðº¦Óû§¡°ÐÄÀíÈËÉíÄþ¾²¡±µÄÊÓƵÁ÷´«¡£Õâ±Ê·£¿îÊǾ¹ýÒ»ÄêÊÓ²ìµÄ½á¹û£¬Ò»ÌìÇ°ÃÀ¹úÖÚÒéԺͶƱ¾ö¶¨ÓÐЧ½ûÖ¹¸Ãƽ̨£¬¹ú»áÒéÔ±ÒªÇó¸Ãƽ̨×Ö½ÚÌø¶¯³·×Ê£¬·ñÔò½«±»½ûÖ¹ÔÚÃÀ¹úÔËÓª¡£AGCM Ìرð¹Ø×¢¸Ãƽ̨ÈçºÎ¶Ôδ³ÉÄêÈ˺ÍÈõÊÆȺÌå·¢Éú¸ºÃæÓ°Ï죬ÌåÏÖ¶Ô¸Ãƽ̨Ëã·¨µÄÊӲ첿ÃÅÊÇΪÁË»ØÓ¦ÔÚ¸ÃÓ¦Ó÷¨Ê½ÉÏ·è´«µÄËùν¡°·¨¹ú°ÌºÛ¡±ÌôÕ½¡£¸ÃÌôÕ½ÒªÇóÓ¦Ó÷¨Ê½Óû§·ÖÏíÃ沿°ÌºÛµÄÊÓƵ£¬µ¼ÖÂÐí¶àÈËƤ·ôÊÜÉ˼ÓÈëÆäÖС£´ËÍ⣬AGCM ÌåÏÖ£¬¸Ãƽ̨µÄÖ¸µ¼Ä¿±êÊDz»¹»µÄ£¬²¢Ö¸³ö£¬ÕâЩָµ¼Ä¿±êµÄÓ¦Óá°Ã»Óгäʵ¿¼Âǵ½ÇàÉÙÄêµÄ¾ßÌå´àÈõÐÔ£¬ÆäÌصãÊÇÌØÊâµÄÈÏÖª»úÖÆ¡£Å·ÃËίԱ»áÉϸöÔÂÐû²¼£¬ÒÑÆô¶¯ÊӲ죬ÒÔÈ·¶¨ TiKTok ÊÇ·ñÒòδÄÜÑéÖ¤Óû§ÄêÁä¡¢±£»¤Óû§Òþ˽ºÍ·ÀÖ¹Óû§×ÅÃÔ¸ÃÓ¦ÓöøÎ¥·´ÁËÅ·ÖÞ´ó½µÄÊý×Ö·þÎñ·¨ (DSA)¡£¸ÃÊÓ²ìµÄÖص㻹ÔÚÓÚ¸Ãƽ̨ÊÇ·ñͨ¹ý²»Í¸Ã÷µÄ¹ã¸æÐÐΪÒÔ¼°Î´Äܱ£»¤Î´³ÉÄêÈ˶øÎ¥·´ÁË DSA¡£
https://therecord.media/tiktok-italy-fine-regulator