Ñо¿ÈËÔ±ÑÝʾÕë¶ÔÈ˹¤ÖÇÄÜϵͳµÄÈ˹¤ÖÇÄÜÈä³æ
Ðû²¼Ê±¼ä 2024-04-264ÔÂ24ÈÕ£¬Ñо¿ÈËÔ±ÑÝʾÁËÒ»ÖÖÇ°Ëùδ¼ûµÄÐÂÐͶñÒâÈí¼þ£¬³ÆΪ¡°Morris II¡±Èä³æ²¡¶¾£¬¸ÃÈä³æ²¡¶¾ÀûÓÃÁ÷ÐеÄÈ˹¤ÖÇÄÜ·þÎñ½øÐÐ×ÔÎÒÁ÷´«¡¢Ñ¬È¾ÐÂϵͳ²¢ÇÔÈ¡Êý¾Ý¡£¸ÃÃû³ÆÔ´×Ô 1988 ÄêÔÚ»¥ÁªÍøÉÏÔì³ÉÑÏÖØÆÆ»µµÄÔʼ Morris ¼ÆËã»úÈä³æ¡£¸ÃÈä³æ²¡¶¾Õ¹Ê¾ÁËÈ˹¤ÖÇÄÜÄþ¾²ÍþвµÄDZÔÚΣÏÕ£¬²¢Îª±£»¤È˹¤ÖÇÄÜÄ£ÐÍ´øÀ´ÁËеĽôÆÈÐÔ¡£À´×Ô¿µÄζûÀí¹¤´óѧ¡¢ÒÔÉ«ÁÐÀí¹¤Ñ§ÔººÍ Intuit µÄÑо¿ÈËԱʹÓÃËùνµÄ¡°·´¿¹ÐÔ×ÔÎÒ¸´ÖÆÌáʾ¡±À´´´½¨¸ÃÈä³æ²¡¶¾¡£ÕâÊÇÒ»¸öÌáʾ£¬µ±ÊäÈë´óÐÍÓïÑÔÄ£ÐÍ£¨LLM£©Ê±£¨ËûÃÇÔÚ OpenAI µÄ ChatGPT¡¢Google µÄ Gemini ÒÔ¼°Íþ˹¿µÐÇ´óѧÂóµÏÑ··ÖУ¡¢Î¢ÈíÑо¿ÔººÍ¸çÂ×±ÈÑÇ´óѧµÄÑо¿ÈËÔ±¿ª·¢µÄ¿ªÔ´ LLaVA Ä£ÐÍÉϽøÐÐÁ˲âÊÔ£© £¬ÆÛÆÄ£ÐÍ´´½¨ÌرðµÄÌáʾ¡£Ëü´¥·¢ÁÄÌì»úÆ÷ÈËÉú³É×Ô¼ºµÄ¶ñÒâÌáʾ£¬È»ºóͨ¹ýÖ´ÐÐÕâЩָÁîÀ´ÏìÓ¦£¨ÀàËÆÓÚ SQL ×¢ÈëºÍ»º³åÇøÒç³ö¹¥»÷£©¡£
https://securityintelligence.com/articles/malicious-ai-worm-targeting-generative-ai/
2. ArcaneDoor ºÚ¿ÍÀûÓÃ˼¿ÆÁãÈÕ©¶´¹¥»÷Õþ¸®»ú¹¹
4ÔÂ24ÈÕ£¬Ë¼¿Æ½ñÌ쾯¸æ³Æ£¬×Ô 2023 Äê 11 ÔÂÒÔÀ´£¬Ä³ºÚ¿Í×éÖ¯Ò»Ö±ÔÚÀûÓÃ×ÔÊÊÓ¦Äþ¾²É豸 (ASA) ºÍ Firepower Íþв·ÀÓù (FTD) ·À»ðǽÖеÄÁ½¸öÁãÈÕ©¶´À´¹¥»÷È«ÇòµÄÕþ¸®ÍøÂç¡£ÕâЩºÚ¿Í±»Ë¼¿Æ Talos ʶ±ðΪ UAT4356£¬±»Î¢Èíʶ±ðΪ STORM-1849£¬ËûÃÇÓÚ 2023 Äê 11 ÔÂÉÏÑ®¿ªÊ¼ÔÚÃûΪ ArcaneDoor µÄÍøÂç¼äµý»î¶¯ÖÐÉø͸Ò×Êܹ¥»÷µÄ±ßÔµÉ豸¡£¾¡¹Ü˼¿ÆÉÐδȷ¶¨×î³õµÄ¹¥»÷ÏòÁ¿£¬µ«Ëü·¢ÏÖ²¢ÐÞ¸´ÁËÁ½¸öÄþ¾²Â©¶´ - CVE-2024-20353£¨¾Ü¾ø·þÎñ£©ºÍCVE-2024-20359£¨³Ö¾Ãµ±µØ´úÂëÖ´ÐУ©¡£Ë¼¿ÆÓÚ 2024 Äê 1 ÔÂÉÏÑ®Òâʶµ½ ArcaneDoor »î¶¯£¬²¢·¢ÏÖÓÐÖ¤¾Ý±íÃ÷¹¥»÷ÕßÖÁÉÙ×Ô 2023 Äê 7 ÔÂÆð¾ÍÒѾ²âÊÔ²¢¿ª·¢ÁËÕë¶ÔÕâÁ½¸öÁãÈÕ©¶´µÄ©¶´¡£
https://www.bleepingcomputer.com/news/security/arcanedoor-hackers-exploit-cisco-zero-days-to-breach-govt-networks/
3. Google Chrome ÖеĶà¸ö©¶´¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëÖ´ÐÐ
4ÔÂ24ÈÕ£¬Google Chrome Öз¢ÏÖÁ˶à¸ö©¶´£¬¿ÉÄܵ¼ÖÂÖ´ÐÐÈÎÒâ´úÂë¡£°üÂÞANGLE ÖеÄÀàÐÍ»ìÏý (CVE-2024-4058)¡¢V8 API ÖеĶÁÈ¡Ô½½ç (CVE-2024-4059)ºÍDawn ÖÐÊͷźóʹÓà (CVE-2024-4060)¡£ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄÜÔÊÐíÔڵǼÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂ롣ƾ¾ÝÓëÓû§¹ØÁªµÄȨÏÞ£¬¹¥»÷Õß¿ÉÒÔ°²×°·¨Ê½£»¼ì²ì¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò´´½¨¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£Óë¾ßÓйÜÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ÆäÕÊ»§ÅäÖÃΪÔÚϵͳÉÏÓµÓнÏÉÙÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¿ÉÄܸüС¡£Ä¿Ç°»¹Ã»ÓйØÓÚÕâЩ©¶´±»´ó¹æÄ£ÀûÓõijÂËß¡£
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2024-043
4. À³Ë¹ÌسǵÄ·µÆÒòÍøÂç¹¥»÷¶øÎÞ·¨¹Ø±Õ
4ÔÂ24ÈÕ£¬À³Ë¹ÌØÊÐÒé»áÔâÓöÍøÂç¹¥»÷£¬ÑÏÖØÓ°ÏìÁËÕþ¸®µÄ·þÎñ²¢µ¼Ö»úÃÜÎļþй¶ ¡£¹¥»÷±³ºóµÄÀÕË÷Èí¼þ×é֯й¶Á˶à·ÝÎļþ£¬°üÂÞ×â½ð±¨±íºÍ¹ºÖÃÒé»áºâÓîµÄÉêÇë¡£Õâ´ÎÏ®»÷·¢ÉúÔÚ3 Ô 7 ÈÕ£¬µ¼ÖÂÊÐÒé»áµÄ IT ϵͳ̱»¾¡£ÓÉÓÚÍøÂç¹¥»÷£¬Ò»Ð©µÆÕûÌ춼ÁÁ×Å£¬ÊÐÒé»áÎÞ·¨½«Æä¹Ø±Õ¡£ÊÐÒé»á³ÆÊÇÓÉÓÚÓë×î½üµÄÍøÂç¹¥»÷Ïà¹ØµÄ¼¼ÊõÎÊÌ⣬±»ÆȹرÕÁË IT ϵͳ¡£ÕâÒâζ×ÅÎÒÃÇÄ¿Ç°ÎÞ·¨Ô¶³Ìʶ±ð½ÖµÀÕÕÃ÷ϵͳµÄ¹ÊÕÏ¡£ÊÐÒé»á·¢ÑÔÈË˵¡£¹ÊÕϵÄĬÈÏģʽÊǵƱ£³ÖÁÁÆð£¬ÒÔÈ·±£ÃÅ·²»»áÍêȫϨÃð²¢³ÉΪÄþ¾²Òþ»¼¡£½â¾öÕâ¸öÎÊÌâÐèÒª½ÓÄÉÐí¶à²½Ö裬ÕýÔÚ¾¡¿ì½â¾öÕâЩÎÊÌâ¡£
https://securityaffairs.com/162219/hacking/leicester-city-cyberattack.html
5. Áè¼Ý23Íò·ÝIDFµÄÎļþÔÚÉæÏÓÄäÃû¹¥»÷ÖÐй¶
4ÔÂ24ÈÕ£¬ÓÉÓÚÓëÄäÃûÕß×éÖ¯Ïà¹ØµÄºÚ¿Í×éÖ¯ÉæÏÓʵʩÍøÂç¹¥»÷£¬ÒÔÉ«Áйú·À¾ü (IDF) ÃæÁÙ»úÃÜÊý¾Ý鶵ÄÖ¸¿Ø¡£¾ÝºÚ¿Í³Æ£¬ËûÃÇ·ÃÎÊÁË 20 GB µÄÐÅÏ¢£¬ÆäÖаüÂÞÁè¼Ý 233,000 ·ÝÖÖÖÖ¸ñʽµÄ¾üÊÂÎĵµ£¬Èç PDF Îļþ¡¢Word ÎĵµºÍÑÝʾÎĸ塣Ïà±È֮ϣ¬¹ú·À²¿·ñÈÏÓÐÈκα»ÈëÇֵĹ¥»÷ʼþ£¬Ç¿µ÷Æä¶à²ãÄþ¾²¼ÆËã»úϵͳ²»Ì«¿ÉÄÜÖ±½ÓÊܵ½¹¥»÷¡£ËûÃÇÈÏΪ£¬Èç¹ûȷʵ·¢ÉúÈκκڿ͹¥»÷£¬ºÜ¿ÉÄÜÉæ¼°ÃñÓÃϵͳ¡£ºÚ¿ÍÐû²¼ÁËÒ»¶ÎÊÓƵ£¬¾Ý³ÆչʾÁËÒÔÉ«Áйú·À¾üÑÝʾµÄÕæʵƬ¶Î£¬µ«¸Ã²¿ÃÅÈÏΪÕâÊÇDZÔÚµÄÐÄÀíÕ½ÐÐΪ£¬Ê¹È˶ÔÖÊÁϵÄÕæʵÐÔ·¢Éú»³ÒÉ¡£±¾ÔÂÔçЩʱºò£¬¸Ã×éÖ¯¾Ý³Æ¶ÔÒÔÉ«ÁÐ˾·¨²¿µÄ IT »ù´¡ÉèÊ©½øÐÐÁËÍøÂç¹¥»÷£¬Éù³ÆÒÑÉø͸¸Ã²¿µÄÄþ¾²ÏµÍ³²¢ÏÂÔØÁËÁè¼Ý 300 GB µÄÊý¾Ý¡£¾ÝºÚ¿Í³Æ£¬Êý¾Ý»º´æ°üÂÞ 800 Íò¸öÎļþ£¬ÆäÖаüÂÞÃô¸ÐµÄ¸öÈËÐÅÏ¢¡£
https://meterpreter.org/over-233000-idf-documents-compromised-in-alleged-anonymous-attack/
6. Ñо¿ÍŶӷ¢ÏÖ¿ÉÇÔÈ¡DiscordÊý¾ÝµÄPyPI°ü
4ÔÂ24ÈÕ£¬FortinetµÄÍøÂçÄþ¾²×¨¼ÒÔÚ PyPI ÖÐΪ¿ª·¢ÈËԱʶ±ð³öÒ»¸öеĶñÒâ°ü£¬Ö¼ÔÚ´Ó Discord ÇÔÈ¡Óû§Êý¾Ý¡£¸ÃÈí¼þ°üÃûΪ¡°discordpy_bypass-1.7¡±£¬ÓÚ 2024 Äê 3 Ô 10 ÈÕÐû²¼£¬²¢ÔÚÁ½Ììºó±»¼ì²âµ½¡£¸ÃÈí¼þ°üÓÉÃûΪ¡°Theaos¡±µÄÓû§¿ª·¢£¬°üÂÞÆ߸ö¾ßÓÐÏàËÆÌØÕ÷µÄ°æ±¾¡£ÆäÖ÷ҪĿ±êÊÇͨ¹ýÔÚÊܺ¦ÕßϵͳÖн¨Á¢³Ö¾ÃÐԵļ¼ÊõÀ´ÌáÈ¡»úÃÜÐÅÏ¢¡¢´Óä¯ÀÀÆ÷ÖÐÌáÈ¡Êý¾Ý²¢ÊÕ¼¯ÁîÅÆ¡£¼¼Êõ·ÖÎöÏÔʾ£¬¸ÃÈí¼þ°ü½ÓÄÉÁ˶à²ã¹æ±Ü´ëÊ©£¬°üÂÞʹÓà base64 ¶Ô»ù±¾ Python ´úÂë½øÐбàÂë¡¢¸½¼Ó»ìÏýÒªÁ죬ÒÔ¼°½«Æä±àÒëΪ´ÓÔ¶³Ì URL ÏÂÔصĿÉÖ´ÐÐÎļþ¡£´ËÍ⣬¹¥»÷Õß»¹½áºÏÁ˶àÏî¼ì²é£¬ÔÊÐí¶ñÒâÈí¼þ¼ì²âɳÏä»·¾³ÖеÄÖ´ÐÐÇé¿ö²¢Í£Ö¹²Ù×÷¡£´ËÍ⣬¸Ã·¨Ê½»¹¿ÉÒÔʶ±ð²¢×èÖ¹ÁÐÈëºÚÃûµ¥µÄ IP ºÍ MAC µØÖ·¡£¸Ã¶ñÒâÈí¼þÌرð¹Ø×¢ Discord Éí·ÝÑéÖ¤Êý¾Ý£¬´Óä¯ÀÀÆ÷ÖÐÌáÈ¡ÃÜÂë¡¢cookie ÎļþºÍÍøÂçËÑË÷ÀúÊ·¼Ç¼¡£ÔÚ½«ËüÃÇ·¢Ë͵½Ô¶³Ì·þÎñÆ÷֮ǰ£¬ÌáÈ¡µÄÁîÅƽ«±»½âÃܺÍÑéÖ¤¡£
https://meterpreter.org/pypi-package-exposed-fortinet-warns-of-discord-data-theft/