Vultur ÒøÐжñÒâÈí¼þαװ³É McAfee Security Ó¦Ó÷¨Ê½
Ðû²¼Ê±¼ä 2024-04-013ÔÂ30ÈÕ£¬Äþ¾²Ñо¿ÈËÔ±·¢ÏÖÁË Android °æ Vultur ÒøÐÐľÂíµÄа汾£¬ÆäÖаüÂÞ¸üÏȽøµÄÔ¶³Ì¿ØÖƹ¦Ð§ºÍ¸ïеĹæ±Ü»úÖÆ¡£Ñо¿ÈËÔ±ÓÚ 2021 Äê 3 ÔÂÊ״μǼÁ˸öñÒâÈí¼þ£¬²¢ÔÚ 2022 Äêµ×·¢ÏָöñÒâÈí¼þͨ¹ýÖ²ÈëÓ¦Ó÷¨Ê½ÔÚ Google Play ÉÏÁ÷´«¡£2023 Äêµ×£¬Òƶ¯Äþ¾²Æ½Ì¨ Zimperium ½« Vultur ÁÐÈëÄê¶ÈÊ®´ó×î»îÔ¾ÒøÐÐľÂíÖ®ÁУ¬²¢Ö¸³öÆäÖÐ 9 ¸ö±äÖÖÕë¶Ô 15 ¸ö¹ú¼Ò/µØÓòµÄ 122 ¸öÒøÐÐÓ¦Ó÷¨Ê½¡£Ò»ÖÖеġ¢¸ü¾ß¹æ±ÜÐ﵀ Vultur °æ±¾Í¨¹ýÒ»ÖÖ»ìºÏ¹¥»÷Á÷´«¸øÊܺ¦Õߣ¬ÕâÖÖ¹¥»÷ÒÀÀµÓÚ¶ÌÐŵöÓ㣨¶ÌÐÅÍøÂçµöÓ㣩ºÍµç»°£¬ÓÕÆÄ¿±ê°²×°Ò»¸ö°æ±¾µÄ Vultur¡£Î±×°³É McAfee Security Ó¦Ó÷¨Ê½µÄ¶ñÒâÈí¼þ¡£Vultur ×îеÄѬȾÁ´Ê¼ÓÚÊܺ¦ÕßÊÕµ½Ò»Ìõ¶ÌÐÅ£¬ÌáÐÑδ¾ÊÚȨµÄ½»Ò×£¬²¢Ö¸Ê¾²¦´òÌṩµÄºÅÂëÑ°ÇóÖ¸µ¼¡£Õ©ÆÕß½ÓÌýµç»°£¬Ëµ·þÊܺ¦Õß´ò¿ªµÚ¶þÌõ¶ÌÐÅ·¢Ë͵ÄÁ´½Ó£¬¸ÃÁ´½ÓÖ¸ÏòÌṩ McAfee Security Ó¦Ó÷¨Ê½Ð޸İ汾µÄÍøÕ¾¡£
https://www.bleepingcomputer.com/news/security/vultur-banking-malware-for-android-poses-as-mcafee-security-app/
2. PyPI ÔÝÍ£ÐÂÓû§×¢²áÒÔ×èÖ¹¶ñÒâÈí¼þ»î¶¯
3ÔÂ28ÈÕ£¬PyPI ÊÇ Python ÏîÄ¿µÄË÷Òý£¬¿É×ÊÖú¿ª·¢ÈËÔ±²éÕҺͰ²×° Python °ü¡£¸Ã´æ´¢¿âÓµÓÐÊýǧ¸ö¿ÉÓÃÈí¼þ°ü£¬¶ÔÓÚÍþвÐÐΪÕßÀ´ËµÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÄ¿±ê£¬ËûÃǾ³£ÉÏ´«Æ´Ð´´íÎó»òαÔìµÄÈí¼þ°üÀ´Î£º¦Èí¼þ¿ª·¢ÈËÔ±ºÍDZÔڵĹ©Ó¦Á´¹¥»÷¡£´ËÀà»î¶¯ÆÈʹ PyPI ¹ÜÀíÔ±½ñÌìÔçЩʱºòÐû²¼ÔÝÍ£ËùÓÐÐÂÓû§×¢²á£¬ÒÔ¼õÉÙ¶ñÒâ»î¶¯¡£Checkmarx µÄÒ»·Ý³ÂËßÏÔʾ£¬ÍþвÐÐΪÕß×òÌ쿪ʼÏò PyPI 365 ÉÏ´«¾ßÓÐÄ£·ÂºÏ·¨ÏîÄ¿Ãû³ÆµÄÈí¼þ°ü¡£ÕâЩÈí¼þ°üµÄ¡°setup.py¡±ÎļþÖаüÂÞ¶ñÒâ´úÂ룬¸Ã´úÂëÔÚ°²×°Ê±Ö´ÐУ¬ÊÔͼ´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÌرðµÄÓÐЧ¸ºÔØ¡£ÎªÁËÌӱܼì²â£¬¶ñÒâ´úÂëʹÓà Fernet Ä£¿é½øÐмÓÃÜ£¬²¢ÔÚÐèҪʱ¶¯Ì¬¹¹½¨Ô¶³Ì×ÊÔ´µÄ URL¡£×îÖÕµÄÓÐЧ¸ºÔØÊÇÒ»¸ö¾ßÓг־ÃÐÔ¹¦Ð§µÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬ÆäÄ¿±êÊÇ´æ´¢ÔÚÍøÂçä¯ÀÀÆ÷ÖеÄÊý¾Ý£¬ÀýÈçµÇ¼ÃÜÂë¡¢cookie ºÍ¼ÓÃÜ»õ±ÒµÈ¡£
https://www.bleepingcomputer.com/news/security/pypi-suspends-new-user-registration-to-block-malware-campaign/?&web_view=true
3. Ó¢¹úÈûÀ·Æ¶ûµÂºËµçÕ¾ÒòÍøÂçÄþ¾²¹ÊÕϱ»ÆðËß
3ÔÂ29ÈÕ£¬Ó¢¹ú¶ÀÁ¢ºËÄþ¾²¼à¹Ü»ú¹¹Ðû²¼£¬½«ÆðËß¹ÜÀíÈûÀ·Æ¶ûµÂºËµçÕ¾µÄ¹«Ë¾£¬Ö¸¿ØÆä¡°ÔÚ 2019 ÄêÖÁ 2023 Äê³õµÄËÄÄêÆÚ¼äÉæÏÓÐÅÏ¢¼¼ÊõÄþ¾²·¸×¡£Ä¿Ç°Éв»Çå³þ¹úÓÐÈûÀ·Æ¶ûµÂÓÐÏÞ¹«Ë¾µÄ¸ß¼¶¹ÜÀíÈËÔ±ÊÇ·ñ»áÃæÁÙÖ¸¿Ø¡£Æ¾¾Ý2003 Ä꡶ºË¹¤ÒµÄþ¾²ÌõÀý¡·£¬±»ÖÎ×ïµÄ¸öÈË¿ÉÃæÁÙ×î¸ßÁ½ÄêµÄ¼à½û¡£ÕýÈçÓ¢¹úÊ×ϯºË¼à²ìԱȥÄêµÄÄê¶È³ÂËßËùÅû¶µÄÄÇÑù£¬ÈûÀ·Æ¶ûµÂ´ËÇ°ÒòÆäÍøÂçÄþ¾²È±Ïݶø³ÉΪ¼à¹Ü»ú¹¹¼ÓÇ¿¹Ø×¢µÄ½¹µã¡£Óë´Ëͬʱ£¬ÔÚÓ¢¹úÔËÓªÊý×ùºËµçÕ¾µÄ·¨¹úµçÁ¦¹«Ë¾Ò²Êܵ½ÁËÀàËÆ´ëÊ©¡£ÕýÈçÓ¢¹úÃñÓúËÍøÂçÄþ¾²Õ½ÂÔËùÊö£¬¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ (NCSC) ÍþвÆÀ¹À¾¯¸æ³Æ£¬ÀÕË÷Èí¼þ¡°¼¸ºõ¿Ï¶¨ÊÇ×îÓпÉÄܵÄÆÆ»µÐÔÍþв¡±¡£¾¡¹Ü¹¤ÒµÏµÍ³Éè¼ÆÓжà¸ö¹ÊÕÏÄþ¾²×°ÖÃÀ´·ÀÖ¹·ÅÉäÐÔʹʣ¬µ«¶ÔºËµçվʹÓÃµÄ IT ϵͳµÄÀÕË÷Èí¼þ¹¥»÷¿ÉÄÜ»áÈÅÂÒÆäÔËÐС£ÈûÀ·Æ¶ûµÂµÄºË·´Ó³¶ÑÓÚ 2003 Äê¹Ø±Õ£¬µ«Õâ¸öÅÓ´óµÄ×ÛºÏÌåÈÔÈ»ÊÇÅ·ÖÞ×î´óµÄºËµçÕ¾£¬ONR ½«ÆäÃèÊöΪ¡°ÊÀ½çÉÏ×îÅÓ´ó¡¢×îΣÏյĺ˵çÕ¾Ö®Ò»¡±¡£
https://therecord.media/sellafield-site-prosecution-nuclear-facility-cybersecurity
4. Õë¶ÔÓ¡¶È¹ú·ÀºÍÄÜÔ´²¿ÃŵĵöÓã¹¥»÷
3ÔÂ29ÈÕ£¬EclecticIQ ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÏîÃûΪ¡°Operation FlightNight¡±µÄÍøÂç¼äµý»î¶¯£¬Ä¿±êÊÇÓ¡¶ÈÕþ¸®ÊµÌåºÍÄÜÔ´¹«Ë¾¡£¹¥»÷Õß¿ÉÄÜÊÇÓɹú¼Ò×ÊÖúµÄ£¬ËûÃÇÀûÓÿªÔ´ÐÅÏ¢ÇÔÈ¡·¨Ê½ HackBrowserData µÄÐ޸İæÔÀ´ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£EclecticIQ ·¢ÏÖ¹¥»÷ÕßʹÓÃÁ÷ÐеÄͨÐÅƽ̨ Slack ͨµÀ×÷ΪÉø͸µã¡£¹¥»÷ÕßÀÖ³ÉÉø͸µ½¶à¸öÂôÁ¦Í¨ÐÅ¡¢IT ºÍ¹ú·ÀµÄÕþ¸®»ú¹¹¡£´ËÍ⣬˽ӪÄÜÔ´¹«Ë¾Ò²Êܵ½Ë𺦣¬ÓйزÆÕþÎļþ¡¢Ô±¹¤ÐÅÏ¢¡¢ÉõÖÁʯÓͺÍÌìÈ»Æø×ê̽»î¶¯µÄÏêϸÐÅÏ¢±»µÁ¡£¸ß´ï 8.81 GB µÄÊý¾Ý±»Ð¹Â¶£¬¿ÉÄÜÓÐÖúÓÚδÀ´µÄÈëÇÖ¡£¹¥»÷ÕßʹÓÃÁËÒ»ÖÖ¼¼ÇÉÀ´ÈÃÊܺ¦Õß°²×°¶ñÒâÈí¼þ¡£ËûÃÇ·¢ËÍαװ³ÉÓ¡¶È¿Õ¾üÑûÇëµÄµç×ÓÓʼþ¡£ÕâЩµç×ÓÓʼþ°üÂÞÒ»¸ö ISO Îļþ£¬¸ÃÎļþËƺõÊÇÎÞº¦µÄ´æµµ¡£µ±Êܺ¦Õß´ò¿ªISOÎļþʱ£¬Ëüʵ¼ÊÉÏÆô¶¯ÁËÒ»¸öαװ³ÉPDFÎĵµµÄ¿ì½Ý·½Ê½Îļþ£¨LNK£© ¡£µ¥»÷ LNK Îļþ»áÔÚ²»Öª²»¾õÖ줻î¶ñÒâÈí¼þ¡£È»ºó£¬¶ñÒâÈí¼þ»áÇÔÈ¡»úÃÜÎĵµ¡¢Ë½È˵ç×ÓÓʼþºÍ»º´æµÄÍøÂçä¯ÀÀÆ÷Êý¾Ý¡£
https://gbhackers.com/weaponized-air-force-invitation-pdf-indian-defense-energy/
5. Linux ©¶´¿ÉÄܵ¼ÖÂÓû§ÃÜÂëй¶ºÍ¼ôÌù°å½Ù³Ö
3ÔÂ28ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖLinux ²Ù×÷ϵͳÖеÄutil-linuxÈí¼þ°üµÄwallÃüÁîÖдæÔÚ©¶´£¬¿ÉÄܵ¼Ö·ÇÌØȨ¹¥»÷ÕßÇÔÈ¡ÃÜÂë»ò¸ü¸ÄÊܺ¦ÕߵļôÌù°å¡£¸ÃÄþ¾²ÎÊÌâ±»×·×ÙΪCVE-2024-28085£¬±»³ÆΪ WallEscape£¬¶øÇÒÔÚ¹ýÈ¥ 11 ÄêÖÐÒ»Ö±´æÔÚÓÚ¸ÃÈí¼þ°üµÄÿ¸ö°æ±¾ÖУ¬Ö±µ½×î½üÐû²¼µÄ2.40¡£¾¡¹Ü¸Ã©¶´Êǹ¥»÷ÕßÈçºÎÆÛÆÓû§Ìṩ¹ÜÀíÔ±ÃÜÂëµÄÒ»¸öÓÐȤʾÀý£¬µ«ÀûÓø鶴¿ÉÄܽöÏÞÓÚijЩÇé¿ö¡£¹¥»÷ÕßÐèÒª·ÃÎÊÒѾÓжà¸öÓû§Í¨¹ýÖÕ¶ËͬʱÁ¬½ÓµÄ Linux ·þÎñÆ÷¡£WallEscape Ó°Ïì¡°wall¡±ÃüÁ¸ÃÃüÁîͨ³£ÔÚ Linux ϵͳÖÐÓÃÓÚÏòµÇ¼µ½Í¬Ò»ÏµÍ³£¨ÀýÈç·þÎñÆ÷£©µÄËùÓÐÓû§µÄÖն˹㲥ÏûÏ¢¡£ÓÉÓÚÔÚͨ¹ýÃüÁîÐвÎÊý´¦ÖÃÊäÈëʱδÕýÈ·¹ýÂËתÒåÐòÁУ¬Òò´Ë·ÇÌØȨÓû§¿ÉÒÔʹÓÃתÒå¿ØÖÆ×Ö·ûÀûÓø鶴ÔÚÆäËûÓû§µÄÖÕ¶ËÉÏ´´½¨Ðé¼ÙµÄ SUDO Ìáʾ·û£¬²¢ÓÕÆËûÃÇÊäÈë¹ÜÀíÔ±ÃÜÂë¡£Ñо¿ÈËÔ±Ö¸³ö£¬ÕâÁ½ÖÖÇé¿öÔÚ Ubuntu 22.04 LTS (Jammy Jellyfish) ºÍ Debian 12.5 (Bookworm) É϶¼´æÔÚ£¬µ«ÔÚ CentOS Éϲ»´æÔÚ¡£
https://www.bleepingcomputer.com/news/security/decade-old-linux-wall-bug-helps-make-fake-sudo-prompts-steal-passwords/?&web_view=true
6. ÂíÈøÖîÈûÖݽ¡¿µ±£ÏÕ¹«Ë¾Êý¾Ýй¶ӰÏì 280 ÍòÈË
3ÔÂ29ÈÕ£¬ÂíÈøÖîÈûÖݵڶþ´ó½¡¿µ±£ÏÕ¹«Ë¾ Point32Health ͸¶£¬Áè¼Ý 280 ÍòÈ˵ĸöÈËÐÅÏ¢ÔÚ2023 Äê 4 ÔµÄÀÕË÷Èí¼þ¹¥»÷Öб»µÁ¡£´Ë´Î¹¥»÷Ó°ÏìÁËÓë Point32Health µÄ¹þ·ð Pilgrim Ò½ÁƱ£½¡Æ·ÅÆÏà¹ØµÄϵͳ£¬°üÂÞΪ¹þ·ð Pilgrim Ò½ÁƱ£½¡ÉÌÒµºÍ Medicare Advantage Stride ¼Æ»®Ìṩ·þÎñµÄϵͳ£¬ÒÔ¼°¡°ÓÃÓÚΪ»áÔ±¡¢ÕË»§¡¢¾¼ÍÈ˺ÍÌṩÉÌÌṩ·þÎñ¡±µÄϵͳ¡£ÊӲ췢ÏÖ£¬Óм£Ïó±íÃ÷Êý¾ÝÔÚ 2023 Äê 3 Ô 28 ÈÕÖÁ 2023 Äê 4 Ô 17 ÈÕÆÚ¼ä´Ó¹þ·ð Pilgrim ϵͳÖб»¸´ÖƺͻñÈ¡¡£±»µÁÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢Éç»áÄþ¾²ºÅÂë¡¢½¡¿µ±£ÏÕÕË»§ÐÅÏ¢¡¢²ÆÕþÕË»§ÐÅÏ¢¡¢²¡Ê·¡¢Õï¶ÏºÍÖÎÁÆÐÅÏ¢µÈ¡£
https://www.securityweek.com/massachusetts-health-insurer-data-breach-impacts-2-8-million/