CISAºÍºÏ×÷»ï°éÐû²¼ÓйØBlack BastaµÄ×Éѯ
Ðû²¼Ê±¼ä 2024-05-135ÔÂ11ÈÕ£¬CISA ÓëÁª°îÊÓ²ì¾Ö (FBI)¡¢ÎÀÉúÓ빫ÖÚ·þÎñ²¿ (HHS) ÒÔ¼°¶àÖÝÐÅÏ¢¹²ÏíºÍ·ÖÎöÖÐÐÄ (MS-ISAC) ºÏ×÷Ðû²¼ÁËÁªºÏÍøÂçÄþ¾²×Éѯ (CSA) # StopRansomware£ºBlack BastaΪÍøÂçÄþ¾²·ÀÓùÕßÌṩսÊõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP) ÒÔ¼°ÒÑÖª Black Basta ÀÕË÷Èí¼þÁ¥Êô»ú¹¹Ê¹ÓõÄΣº¦Ö¸±ê (IOC)£¬²¢Í¨¹ý FBI ÊÓ²ìºÍµÚÈý·½³ÂËß½øÐÐʶ±ð¡£Black Basta ÊÇÒ»ÖÖÀÕË÷Èí¼þ¼´·þÎñ (RaaS) ±äÌ壬ÓÚ 2022 Äê 4 ÔÂÊ״η¢ÏÖ¡£Black Basta Á¥Êô¹«Ë¾ÒÑÕë¶Ô±±ÃÀ¡¢Å·Ö޺ͰĴóÀûÑÇµÄ 500 ¶à¸ö˽ӪÐÐÒµºÍÒªº¦»ù´¡ÉèʩʵÌ壬°üÂÞÒ½ÁƱ£½¡×éÖ¯¡£CISA ºÍºÏ×÷»ï°éÃãÀø×éÖ¯Éó²é²¢ÊµÊ©ÁªºÏ CSA ÖÐÌṩµÄ»º½â´ëÊ©£¬ÒÔ¼õÉÙ Black Basta ºÍÆäËûÀÕË÷Èí¼þʼþµÄ¿ÉÄÜÐÔºÍÓ°Ïì¡£
https://www.cisa.gov/news-events/alerts/2024/05/10/cisa-and-partners-release-advisory-black-basta-ransomware
2. Chrome½ô¼±¸üУ¬ÐÞ¸´ÑÏÖØ©¶´CVE-2024-4671
5ÔÂ11ÈÕ£¬¹È¸èÐû²¼ÁË Chrome ä¯ÀÀÆ÷µÄ½ô¼±¸üУ¬ÐÞ¸´ÁËÒ»¸öÑÏÖصÄÁãÈÕ©¶´CVE-2024-4671¡£¡°ÊͷźóʹÓá±Â©¶´Ó°Ïì Chrome µÄÊÓ¾õ×é¼þ£¬¸Ã×é¼þÂôÁ¦äÖȾºÍÏÔʾÄÚÈÝ¡£CVE-2024-4671 ÊÇÓÉһλÄäÃûÑо¿ÈËԱʶ±ð²¢Ïò Google ³ÂËߵġ£¸Ã¹«Ë¾Í¸Â¶£¬¸Ã©¶´¿ÉÄÜÕýÔÚ±»»ý¼«ÀûÓᣴ˩¶´ÀûÓÃÁË·¨Ê½ÔÚÊÍ·ÅÄÚ´æÖ¸Õëºó¼ÌÐøʹÓøÃÄÚ´æÖ¸ÕëµÄȱÏÝ£¬¿ÉÄܻᵼÖÂδ¾ÊÚȨµÄÊý¾Ý²Ù×÷»òÍ߽⡣ÓÉÓÚ¸üв¿ÊðÔÚÖÖÖÖƽ̨£¨°üÂÞ Mac¡¢Windows ºÍ Linux£©ÉÏ£¬Òò´ËÓû§Ó¦È·±£ËûÃÇÔËÐеÄÊÇ×îа汾µÄ Chrome¡£¿ÉÒÔͨ¹ýµ¼º½ÖÁ¡°ÉèÖá±>¡°¹ØÓÚ Chrome¡±À´¼ì²é¡£ÕâÖÖÖ÷¶¯´ëÊ©¿ÉÈ·Èϲ¹¶¡ÒÑÓ¦Ó㬴Ӷø±£»¤ÄúµÄϵͳÃâÊÜDZÔڵĹ¥»÷¡£Èç¹ûÄú·¢ÏÖÄúµÄä¯ÀÀÆ÷²»ÊÇ×îа汾£¬½¨ÒéÄúÁ¢¼´¸üС£
https://blog.qualys.com/vulnerabilities-threat-research/2024/05/10/get-weekends-back-put-chrome-cves-like-cve-2024-4671-on-auto-patching
3. IntelBroker Éù³ÆÒÑÀÖ³ÉÇÖÈëÅ·ÃËÖ´·¨ºÏ×÷»ú¹¹
5ÔÂ10ÈÕ£¬ºÚ¿ÍÔÚBreachForumsÉÏÐû²¼ÁËÕâÒ»ÏûÏ¢£¬³Æ´Ë´Îй¶Ê¼þ·¢ÉúÔÚ±¾ÔÂÔçЩʱºò£¬Éæ¼°¸ß¶ÈÃô¸ÐºÍ»úÃÜÐÅÏ¢¡£¶øÇÒIntelBroker͸¶Êý¾ÝÒѱ»³öÊÛ¸øÄäÃûÂò¼Ò¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÁªÃËÔ±¹¤µÄ¸öÈËÐÅÏ¢¡¢½ö¹©¹Ù·½Ê¹Óà (FOUO) Ô´´úÂë¡¢×÷Õ½ÎļþºÍÊÜÓ°ÏìµÄ¾ßÌå»ú¹¹ÁбíµÈ¡£Èç¹ûÊôʵ£¬´ËÀàÒªº¦Êý¾ÝµÄ̻¶¿ÉÄÜ»á¶ÔÕâЩ»ú¹¹µÄÁ¬ÐøÔËÓªºÍ¸öÈËÄþ¾²×é³ÉÑÏÖØ·çÏÕ¡£¾Ý³ÆµÄÎ¥¹æÐÐΪ»¹¿ÉÄÜÆÆ»µÅ·ÖÞÐ̾¯×éÖ¯Ðж¯µÄÍêÕûÐÔºÍÄþ¾²ÐÔ¡£Å·ÖÞÐ̾¯×éÖ¯ÉÐδÐû²¼ÕýʽÉùÃ÷£¬Ïêϸ˵Ã÷ÊÇ·ñ·¢ÉúÁËÎ¥¹æÐÐΪ¡¢Î¥¹æˮƽÒÔ¼°Îª¼õÇáÆäÓ°Ïì¶ø½ÓÄɵĴëÊ©¡£
https://www.hackread.com/europol-hacked-intelbroker-claims-data-breach/
4. LLM ½Ù³Ö¹¥»÷ÈÃºÚ¿Í½Ù³Ö AI Ä£ÐÍÒÔ»ñÈ¡ÀûÈó
5ÔÂ10ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪ¡°LLMjacking¡±µÄÐÂÐÍÍøÂç¹¥»÷¼Æ»®£¬ÀûÓñ»µÁµÄÔÆƾ֤À´½Ù³ÖÇ¿´óµÄÈ˹¤ÖÇÄÜÄ£ÐÍ¡£ÍøÂç·¸×ï·Ö×ÓʹÓñ»µÁµÄÔÆƾ¾Ý£¨ºÜ¿ÉÄÜÊÇ´ÓÊÜËðµÄÔÆÕÊ»§»ñµÃµÄ£©À´Ãé×¼ÔËÐйýʱÈí¼þµÄϵͳ£¬ÒÔÉø͸ÔËÐÐ LLM µÄϵͳ£¬ÒÔ½âËøÆäÄÜÁ¦µÄ±¦¿â¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ÔÚËûÃǵÄÑо¿Ðû²¼Ö®Ç°£¬¹¥»÷ÕßÒѾ·ÃÎÊÁËÊ®ÖÖ²îÒìÈ˹¤ÖÇÄÜ·þÎñµÄ LLM Ä£ÐÍ£¬°üÂÞ Anthropic¡¢AWS Bedrock¡¢Google Cloud Vertex AI¡¢Mistral ºÍ OpenAI¡£Ñо¿ÈËÔ±·¢ÏÖ£¬¹¥»÷ÕßÕýÔڸĶ¯ÊÜѬȾϵͳÖеÄÈÕÖ¾ÉèÖã¬Õâ±íÃ÷ËûÃÇÔÚʹÓñ»µÁµÄ LLM ·ÃÎÊȨÏÞʱ¹ÊÒâÊÔͼÌӱܼì²â£¬Õâ͹ÏÔÁËÍøÂç·¸×ï·Ö×ÓµÄÈÕÒæ½Æ»«¡£
https://www.hackread.com/llmjacking-attack-hackers-hijack-ai-models/
5. ¶íº¥¶íÖݲÊƱÔâµ½DragonForce¹¥»÷Ó°ÏìÁè¼Ý50ÍòÈË
5ÔÂ10ÈÕ£¬¶íº¥¶íÖݲÊƱ±¾ÖÜÌåÏÖ£¬ÀÕË÷Èí¼þ×é֯ȥÄêÌᳫµÄ¶íº¥¶íÖݲÊƱÍøÂç¹¥»÷ÒÑÓ°ÏìÁËÁè¼Ý 50 ÍòÈË¡£¸ÃʼþÓÚ 2023 Äê 12 ÔÂÏÂÑ®Æع⣬Æäʱ¶íº¥¶íÖݲÊƱ¹«Ë¾Ðû²¼¹Ø±ÕһЩϵͳÒÔֹͣΥ¹æÐÐΪ¡£Ô¼ÄªÔÚͬһʱ¼ä£¬Ò»¸öÃûΪ DragonForce µÄ¿´ËÆеÄÀÕË÷Èí¼þ×éÖ¯Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦¡£ ½ñºó£¬ºÚ¿ÍÌṩÁË¾Ý³Æ´Ó¶íº¥¶íÖݲÊƱ¹«Ë¾ÇÔÈ¡µÄÁè¼Ý 90 GB µÄÎļþ£¨ÒÔ .bak ±¸·Ý¸ñʽ£©¡£ËûÃÇÉù³ÆÒÑ»ñµÃÁè¼Ý 150 ÍòÌõÔ±¹¤ºÍÍæ¼ÒÐÅÏ¢¼Ç¼£¬°üÂÞÐÕÃû¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·¡¢½±½ð¡¢³öÉúÈÕÆÚºÍÉç»áÄþ¾²ºÅÂë¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¸ÃÀÕË÷Èí¼þ×éÖ¯×î³õÉù³ÆÇÔÈ¡ÁË 300 ÍòÌõ¼Ç¼¡£¶íº¥¶íÖݲÊƱ¸æËßÃåÒòÖÝ×ܼì²ì³¤£¬Ô¼ÄªÓÐ 538,000 ÈËÊܵ½Ó°Ïì¡£·¢Ë͸ø×ܼì²ì³¤µÄ³ÂËߺͷ¢Ë͸øÊÜÓ°Ïì¸öÈ˵ÄÐź¯Ö¤Êµ£¬È«ÃûºÍÉç»áÄþ¾²ºÅÂëÒѱ»Ð¹Â¶¡£
https://www.securityweek.com/500000-impacted-by-ohio-lottery-ransomware-attack/
6. HijackLoaderͨ¹ýÎäÆ÷»¯PNGͼƬ¹¥»÷Windows
5ÔÂ10ÈÕ£¬ÔÚ×î½üµÄÍøÂçÄþ¾²Í»ÆÆÖУ¬Ñо¿ÈËÔ±Ðû²¼ÁË HijackLoader ¶ñÒâÈí¼þµÄÖØ´ó¸üУ¬ÕâÊÇÒ»ÖÖÅÓ´óµÄÄ£¿é»¯¼ÓÔØ·¨Ê½£¬Òòͨ±¨ÖÖÖÖ¶ñÒ⸺ÔضøÎÛÃûÕÑÖø¡£¸Ã¶ñÒâÈí¼þÒѸüÐÂΪ¿É²¿Êð Amadey¡¢Lumma Stealer¡¢Racoon Stealer v2 ºÍRemcos RATµÈÍþв£¬Õ¹Ê¾ÁËÆä²Ù×÷µÄ¾ªÈ˶๦ЧÐÔ¡£HijackLoader ÒѾÉú³¤³ÉΪһÖÖм¼Êõ£¬É漰ʹÓÃPNG ͼÏñÀ´½âÃܲ¢Æô¶¯ºóÐø½×¶ÎµÄ¼ÓÔØ¡£´ËÒªÁìÊǸü¹ã·º¼ÆıµÄÒ»²¿ÃÅ£¬ÆäÖаüÂÞ¶¯Ì¬ API ½âÎö¡¢Ï¸ÖµÄ×èÖ¹Áбí½ø³Ì¼ì²éÒÔ¼°ÌÓ±ÜÓû§Ä£Ê½¹Ò¹³£¬Í¹ÏÔÁ˶ñÒâÈí¼þÔÚÌӱܼì²â·½ÃæµÄÈÕÒæÅÓ´óÐÔ¡£ÕâЩ¸üл¹ÒýÈëÁËÖ¼ÔÚÔöÇ¿¶ñÒâÈí¼þ¹¦Ð§µÄÐÂÄ£¿é¡£ÆäÖаüÂÞ´´½¨½ø³Ì¡¢ÈƹýÓû§ÕÊ»§¿ØÖÆ (UAC)¡¢Ïò Windows Defender Ìí¼ÓÅųýÏîÒÔ¼°Ð´ÈëÎļþµÄ¹¦Ð§£¬´Ó¶øÀ©Õ¹Á˶ñÒâÈí¼þΣº¦ºÍ¿ØÖÆÊÜѬȾϵͳµÄÄÜÁ¦¡£
https://gbhackers.com/hijackloader-malware/