Cuckoo macOS¶ñÒâÈí¼þ¿É¿ØÖÆMac²¢ÇÔÈ¡ÃÜÂë

Ðû²¼Ê±¼ä 2024-05-08
1. Cuckoo macOS¶ñÒâÈí¼þ¿É¿ØÖÆMac²¢ÇÔÈ¡ÃÜÂë


5ÔÂ7ÈÕ £¬ºÚ¿ÍÕýÔÚʹÓÃÐ嵀 Mac ¶ñÒâÈí¼þ¶ÔÔËÐÐ Apple Silicon µÄÐÂÐÍ Mac ÒÔ¼°»ùÓÚ Intel µÄ¾É Mac Ìᳫ¹¥»÷¡£¾Ý¡¶ºÚ¿ÍÐÂÎÅ¡·±¨µÀ £¬Kandji µÄÄþ¾²Ñо¿ÈËÔ±½«ÕâÖÖ¶ñÒâÈí¼þ³ÆΪ Cuckoo¡£³ýÁËÕë¶Ô½ÏÐÂºÍ½Ï¾ÉµÄ Mac µçÄÔÍâ £¬Cuckoo µÄÓëÖÚ²îÒìÖ®´¦»¹ÔÚÓÚËüµÄÐÐΪÀàËÆÓÚÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þºÍ¼äµýÈí¼þµÄ»ìºÏÌå¡£ÔÚһƪ²©¿ÍÎÄÕÂÖÐ £¬Kandji µÄ Adam Kohler ºÍ Christopher Lopez ½âÊÍ˵ £¬ËûÃÇÔÚ¶ñÒâÈí¼þ¸ú×ÙÍøÕ¾ VirusTotal ÉÏ·¢ÏÖÁËÒ»¸öÒÔǰδ¼ì²âµ½µÄ¶ñÒâ Mach-O ¶þ½øÖÆÎļþ £¬ÆäÃû³ÆΪ¡°DumpMedia Spotify Music Converter¡±¡£È»ºó £¬ËûÃÇÔÚÍøÉϲéÕҸ÷¨Ê½µÄÃû³Æ £¬·¢Ïָ÷¨Ê½ÊÇ´ÓÒ»¸öÃûΪ dumpmedia[.]com µÄÍøÕ¾·Ö·¢µÄ £¬¸ÃÍøÕ¾Ìṩ¶à¸öÓ¦Ó÷¨Ê½ £¬¿ÉÒÔ×ÊÖúÓû§½«Á÷ýÌå·þÎñÖеÄÒôÀÖת»»Îª MP3 Îļþ¡£


https://news.hitb.org/content/new-cuckoo-macos-malware-can-take-over-all-macs-and-steals-your-passwords-too


2. Ñо¿ÍŶÓÑÝʾÕë¶ÔËùÓÐVPN·¨Ê½µÄ¹¥»÷TunnelVision


5ÔÂ7ÈÕ £¬Ñо¿ÈËÔ±Éè¼ÆÁËÒ»ÖÖÕë¶Ô¼¸ºõËùÓÐÐéÄâרÓÃÍøÂçÓ¦Ó÷¨Ê½µÄ¹¥»÷ £¬ÆÈʹËüÃÇÔÚ¼ÓÃÜËíµÀÖ®Íâ·¢ËͺͽÓÊÕ²¿ÃÅ»òÈ«²¿Á÷Á¿ £¬Ö¼ÔÚ± £»¤ÆäÃâÔâ¿ú̽»ò¸Ä¶¯¡£Ñо¿ÈËÔ±½«Æä¹¥»÷ÃüÃûΪ TunnelVision £¬½«´«ÈëºÍ´«³öµÄ»¥ÁªÍøÁ÷Á¿·â×°ÔÚ¼ÓÃÜËíµÀÖв¢Òþ²ØÓû§µÄ IP µØÖ·¡£Ñо¿ÈËÔ±ÈÏΪ £¬µ±ËùÓÐ VPN Ó¦Ó÷¨Ê½Á¬½Óµ½¶ñÒâÍøÂçʱ £¬Ëü¶¼ÊÐÓ°ÏìËüÃÇ £¬¶øÇÒ³ýÁ˵±Óû§µÄ VPN ÔÚ Linux »ò Android ÉÏÔËÐÐʱ֮Íâ £¬Ã»ÓÐÆäËûÒªÁì¿ÉÒÔ·ÀÖ¹´ËÀ๥»÷¡£ËûÃÇ»¹ÌåÏÖ £¬ËûÃǵĹ¥»÷¼¼Êõ¿ÉÄÜ×Ô 2002 ÄêÒÔÀ´¾ÍÒѳÉΪ¿ÉÄÜ £¬¶øÇÒ´ÓÄÇʱÆð¾ÍÒѾ­±»·¢ÏÖ²¢ÔÚÒ°ÍâʹÓá£Ò»¶ÎÊÓƵÑÝʾ½âÊ͵À £¬TunnelVision µÄЧ¹ûÊÇ¡°Êܺ¦ÕßµÄÁ÷Á¿ÏÖÔÚÒѱ»½Ò¿ª²¢Ö±½Óͨ¹ý¹¥»÷Õß½øÐзÓÉ¡±¡£¡°¹¥»÷Õß¿ÉÒÔ¶ÁÈ¡¡¢É¾³ý»òÐÞ¸Ä鶵ÄÁ÷Á¿ £¬¶øÊܺ¦ÕßÔò±£³ÖÓë VPN ºÍ»¥ÁªÍøµÄÁ¬½Ó¡£¡±


https://news.hitb.org/content/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose


3. αװ³ÉÖ¤ÊéµÄ LNK Îļþ·Ö·¢ RokRAT ¶ñÒâÈí¼þ


5ÔÂ7ÈÕ £¬AhnLabÄþ¾²Ç鱨ÖÐÐÄ£¨ASEC£©ÒÑÈ·ÈÏÁ¬ÐøÁ÷´«Òì³£¾ÞϸµÄ¿ì½Ý·½Ê½Îļþ£¨*.LNK£© £¬ÓÃÓÚÁ÷´«ºóÃÅÀàÐ͵ĶñÒâÈí¼þ¡£×î½üÈ·ÈϵĿì½Ý·½Ê½Îļþ£¨*.LNK£©±»·¢ÏÖÊÇÕë¶Ôº«¹úÓû§ £¬ÌرðÊÇÓ볯ÏÊÓйصÄÓû§¡£È·ÈϵÄLNKÎļþÃûÈçÏ£º¹ú¼ÒÐÅϢѧԺµÚ°ËÆÚ×ۺϿγÌÖ¤Ê飨×îÖÕ£©.lnk¡¢ÃŽûÃû²á2024.lnk¡¢¶«±±ÏîÄ¿£¨ÃÀ¹ú¹ú»áÑо¿·þÎñ´¦£¨CRS ³ÂËߣ©.lnkºÍÉèÊ©Çåµ¥.lnk¡£ÒÑÈ·ÈϵÄLNKÎļþ°üÂÞͨ¹ýCMDÖ´ÐÐPowerShellµÄÃüÁî £¬ÆäÀàÐÍÓëÈ¥ÄêÐû²¼µÄ¡°RokRAT Malware Distributed Through LNK Files (*.lnk): RedEyes (ScarCruft)¡± [1]Öз¢ÏÖµÄÀàÐÍÀàËÆ¡£¹ØÓÚÕâÖÖÀàÐ͵ÄÒ»¸öÖµµÃ×¢ÒâµÄÊÂʵÊÇ £¬ËüÔÚ LNK ÎļþÖаüÂ޺Ϸ¨ÎĵµÎļþ¡¢½Å±¾´úÂëºÍ¶ñÒâ PE Êý¾Ý¡£


https://asec.ahnlab.com/en/65076/


4. 2023ÄêµÚÈý·½Ôì³ÉµÄÊý¾Ýй¶Ôö¼ÓÁË68%


5ÔÂ7ÈÕ £¬½üÄêÀ´¹©Ó¦Á´Î¥¹æʼþÒ»Ö±³ÊÉÏÉýÇ÷ÊÆ¡£Æ¾¾Ý Verizon ×îеÄÊý¾Ýй¶ÊÓ²ì³ÂËß (DBIR) £¬½ü¼¸¸öÔÂÀ´ÕâÒ»Ôö³¤ÓÈΪ¼±¾ç¡£2023 ÄêËùÓÐÎ¥¹æÐÐΪÖÐÔ¼ÓÐ 15% Éæ¼°µÚÈý·½ £¬±È 2022 ÄêµÄ 9% ÏÔ×ÅÔö¼Ó¡£²»Íâ £¬ÕâЩÊý×ÖÓë»á¼ÆºÍ¹¥»÷µÄ¹ØϵͬÑùÖØÒª¡£ÊÂʵÉÏ £¬±»ÀûÓõÄ©¶´ÊÇ DBIR ¹©Ó¦Á´Ö¸±êÖÐ×î³£¼ûµÄʼþ¼Ç¼ºÍʼþ¹²Ïí (VERIS) ÐÐΪ´Ê»ã £¬Æä´ÎÊǺóÃÅ/ÃüÁîÓë¿ØÖÆ (C2) ºÍÀÕË÷¡£Verizon ÍþвÇ鱨¸±×ܼà Alex Pinto ÌåÏÖ£ºÈ¥Äê £¬ÔÚÀÕË÷Èí¼þÁìÓò £¬ÎÒÃÇ¿´µ½ £¬ÎÞÂÛÊÇ×Ô¼ºÑо¿»¹ÊǹºÖà £¬[ÍþвÐÐΪÕß]ÒѾ­ÕÆÎÕÁËÈç´Ë¶àµÄÁãÈÕ©¶´¡£¶ÔÓÚ DBIR ÍŶÓÀ´Ëµ £¬½â¾ö´íÎó²»½ö½öÊÇÔÚ´íÎó·ºÆðʱ½øÐÐÐÞ²¹¡£ÕâÊǹØÓÚ×éÖ¯ÈçºÎÑ¡Ôñ¹©Ó¦É̲¢ÓëÆäºÏ×÷µÄÎÊÌ⡣ûÓÐ×éÖ¯¿ÉÒÔ×èÖ¹ËûÃÇʹÓõÄÈí¼þÖеÄÿ¸öDZÔÚ©¶´ £¬µ«¹©Ó¦ÉÌȷʵ¡°Ð¹Â©¡±ÁËijЩ¿ÉÄܱíÃ÷Æä¼ÛÖµµÄÐźÅ¡£


https://www.darkreading.com/cyber-risk/supply-chain-breaches-up-68-yoy-according-to-dbir


5. TinyproxyÑÏÖØ©¶´µ¼ÖÂÁè¼Ý5Íǫ̀Ö÷»ú¿ÉÖ´ÐÐÔ¶³Ì´úÂë


5ÔÂ6ÈÕ £¬90310 ̨Ö÷»úÖÐÁè¼Ý 50% ±»·¢ÏÖÔÚ»¥ÁªÍøÉÏ̻¶ÁËTinyproxy ·þÎñ £¬¸Ã·þÎñÈÝÒ×Êܵ½ HTTP/HTTPS ÊðÀí¹¤¾ßÖÐδÐÞ²¹µÄÑÏÖØÄþ¾²Â©¶´µÄÓ°Ï졣ƾ¾Ý Cisco Talos £¬¸ÃÎÊÌâµÄ±àºÅΪCVE-2023-49606 £¬CVSS ÆÀ·ÖΪ 9.8 ·Ö£¨Âú·Ö 10 ·Ö£© £¬¸ÃÎÊÌ⽫ÆäÃèÊöΪӰÏì°æ±¾ 1.10.0 ºÍ 1.11.1 µÄÊͷźóʹÓôíÎó¡£TalosÔÚÒ»·Ýͨ¸æÖÐÌåÏÖ£ºÌØÖÆµÄ HTTP ±êÍ·¿ÉÄܻᴥ·¢ÏÈÇ°ÊͷŵÄÄÚ´æµÄÖØÓà £¬´Ó¶øµ¼ÖÂÄÚ´æË𻵲¢¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¹¥»÷ÕßÐèÒª·¢³öδ¾­Éí·ÝÑéÖ¤µÄ HTTP ÇëÇó²ÅÆø´¥·¢´Ë©¶´¡ £»»¾ä»°Ëµ £¬Î´¾­Éí·ÝÑéÖ¤µÄÍþв¼ÓÈëÕß¿ÉÒÔ·¢ËÍÌØÖƵÄHTTP Á¬½Ó±êÍ·À´´¥·¢ÄÚ´æË𻵠£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Æ¾¾Ý¹¥»÷Ãæ¹ÜÀí¹«Ë¾ Censys ¹²ÏíµÄÊý¾Ý £¬½ØÖÁ 2024 Äê 5 Ô 3 ÈÕ £¬ÔÚÏò¹«¹²»¥ÁªÍø¹ûÈ» Tinyproxy ·þÎñµÄ 90,310 ̨Ö÷»úÖÐ £¬ÆäÖÐ 52,000 ̨£¨Ô¼ 57%£©ÔËÐÐ×Å´æÔÚ©¶´µÄ Tinyproxy °æ±¾¡£´ó¶àÊý¿É¹ûÈ»·ÃÎʵÄÖ÷»úλÓÚÃÀ¹ú£¨32,846£©¡¢º«¹ú£¨18,358£©¡¢Öйú£¨7,808£©¡¢·¨¹ú£¨5,208£©ºÍµÂ¹ú£¨3,680£©¡£


https://thehackernews.com/2024/05/critical-tinyproxy-flaw-opens-over.html


6. ¶íÂÞ˹ BTC-e ¼ÓÃÜ»õ±Ò½»Ò×ËùÔËÓªÉÌÈÏ¿ÉÏ´Ç®×ï


5ÔÂ6ÈÕ £¬Æ¾¾ÝÃÀ¹ú˾·¨²¿µÄÒ»·ÝÉùÃ÷ £¬Ôø¾­ÊÇÊÀ½çÉÏ×î´óµÄÐéÄâ»õ±Ò½»Ò×ËùÖ®Ò»µÄ¶íÂÞ˹ÔËÓªÉÌ BTC-e ÈϿɼÓÈëÏ´Ç®¼Æ»®¡£44 ËêµÄÑÇÀúɽ´ó¡¤ÎÄÄá¿Ë (Alexander Vinnik) ÔÚ 2011 ÄêÖÁ 2017 ÄêÆÚ¼äÔËÓª BTC-e £¬ºóÀ´¸Ã·þÎñ±»Ö´·¨²¿ÃŹرÕ¡£ÔÚ´ËÆÚ¼ä £¬¸Ã½»Ò×Ëù´¦ÖÃÁËÁè¼Ý 90 ÒÚÃÀÔªµÄ½»Ò× £¬²¢ÎªÈ«ÇòÁè¼Ý 100 ÍòÓû§Ìṩ·þÎñ £¬ÆäÖаüÂÞÖÚ¶àÃÀ¹ú¿Í»§¡£Æ¾¾Ý·¨Í¥Îļþ £¬×÷Ϊ·Ç·¨»î¶¯µÄÒ»²¿ÃÅ £¬Vinnik ͨ¹ý BTC-e Ôì³ÉÁËÖÁÉÙ 1.21 ÒÚÃÀÔªµÄËðʧ¡£Ëû»¹ÔÚÈ«Çò·¶Î§ÄÚÉèÁ¢ÁËÖÚ¶à¿Õ¿Ç¹«Ë¾ºÍ½ðÈÚÕË»§ £¬ÒÔÔÊÐí BTC-e ÎÞÐ轫¸Ãƽ̨ע²áΪ»õ±Ò·þÎñÒµÎñ¼´¿ÉÔËÓª¡£Ó¦ÃÀ¹úÒªÇó £¬ÎÄÄá¿Ë×î³õÓÚ 2017 ÄêÔÚÏ£À°±»²¶¡£2020 Äê £¬Ëû±»Òý¶Éµ½·¨¹ú £¬µ±µØ·¨ÔºÖ¸¿ØËûÈëÇÖÊýǧ¸öµç×ÓÓʼþÕÊ»§²¢ÏòÆäËùÓÐÕßÀÕË÷Ç®²Æ¡£Ëæºó £¬Ëû±»Ç²·µ»ØÏ£À° £¬È»ºó±»Òý¶Éµ½ÃÀ¹ú¡£Óë´Ëͬʱ £¬¶íÂÞ˹»¹ÒªÇóÏ£À°Õþ¸®½«ÎÄÄá¿ËDzËͻعú £¬ÒÔÖ¸¿ØËû·¸ÓнÏСµÄÆÛÕ©×ï¡£


https://therecord.media/btce-cryptocurrency-exchange-alexander-vinnik-money-laundering-guilty-plea