6K+ AI Ä£ÐÍ¿ÉÄÜÊܵ½ÑÏÖØ RCE ©¶´µÄÓ°Ïì
Ðû²¼Ê±¼ä 2024-05-215ÔÂ17ÈÕ£¬ÓÃÓÚ´óÓïÑÔÄ£ÐÍ (LLM) µÄÁ÷ÐÐ Python °üÖеÄÒ»¸öÑÏÖØ©¶´¿ÉÄÜ»áÓ°Ïì 6,000 ¶à¸öÄ£ÐÍ£¬²¢¿ÉÄܵ¼Ö¹©Ó¦Á´¹¥»÷¡£¿ªÔ´llama-cpp-python°ü±»·¢ÏÖÈÝÒ×Êܵ½·þÎñÆ÷¶ËÄ£°å×¢ÈëµÄ¹¥»÷£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¸Ã©¶´±»×·×ÙΪ CVE-2024-34359£¬ÓÉÄþ¾²Ñо¿Ô±ºÍ¿ª·¢ÈËÔ± Patrick Peng ·¢ÏÖ£¬ËûµÄÔÚÏßÕ˺ÅΪ Retro0reg¡£llama-cpp-python °üΪ¹ã·ºÁ÷ÐÐµÄ llama.cpp ¿âÌṩ Python °ó¶¨£»llama.cpp ÊÇÒ»¸ö C++ ¿â£¬ÓÃÓÚÔÚ¸öÈ˼ÆËã»úÉÏÔËÐÐ Meta µÄ LLaMA µÈ LLM ºÍ Mitral AI µÄÄ£ÐÍ¡£llama-cpp-python °ü½øÒ»²½Ê¹¿ª·¢ÈËÔ±Äܹ»½«ÕâЩ¿ªÔ´Ä£Ðͼ¯³Éµ½ Python ÖС£CVE-2024-34359µÄ CVSS Òªº¦·ÖÊýΪ 9.7£¬ÓÉÓÚ Jinja2 Ä£°åÒýÇæµÄʵʩ²»Í×£¬´æÔÚ RCE ·çÏÕ¡£Peng ÔÚ²©¿ÍÎÄÕÂÖнâÊÍ˵£¬¸ÃȱÏÝÔÊÐí Jinja2 ½âÎö´æ´¢ÔÚÔªÊý¾ÝÖеÄÁÄÌìÄ£°å£¬¶øÎÞÐè½øÐÐÇåÀí»òɳÏä´¦Ö㬴ӶøΪ¹¥»÷Õß×¢Èë¶ñÒâÄ£°åµÞÔìÁË»ú»á¡£
https://www.scmagazine.com/news/6k-plus-ai-models-may-be-affected-by-critical-rce-vulnerability
2. Grandoreiro ÒøÐÐľÂí´ø×ÅÖØ´ó¸üлعé
5ÔÂ20ÈÕ£¬¾Ý IBM ³Æ£¬Ò»ÖÖ¶à²úµÄÒøÐÐľÂíÔÚ¶à¸öлÖÐÖØзºÆð£¬ÆäÔöÇ¿µÄ¹¦Ð§Ö¼ÔÚʹÆä³ÉΪ¸üÇ¿´óµÄÍþв¡£Õâ¼Ò¿Æ¼¼¾ÞÍ·µÄ X-Force ÍøÂçÄþ¾²²¿ÃÅÌåÏÖ£¬×Ô 3 Ô·ÝÒÔÀ´£¬ËüÒ»Ö±ÔÚ×·×ÙÊýÆð´ó¹æÄ£ÍøÂçµöÓã»î¶¯¡£ÆäÖаüÂÞð³äÄ«Î÷¸çË°Îñ¹ÜÀí¾Ö (SAT)¡¢Áª°îµçÁ¦Î¯Ô±»á (CFE) ºÍÐÐÕþºÍ²ÆÕþ²¿³¤¡¢ÒÔ¼°°¢¸ù͢˰Îñ¾ÖºÍÄÏ·ÇË°Îñ¾Ö (SARS) µÄ¹¥»÷¡£IBM X-Force ÌåÏÖ£º¡°ÔÚÿ´Î»î¶¯ÖУ¬½ÓÊÕÕ߶¼Êб»Ö¸Ê¾µã»÷Á´½ÓÀ´¼ì²ì·¢Æ±»òÓöȡ¢ÕË»§¶ÔÕ˵¥¡¢¸¶¿îµÈ£¬¾ßÌåÈ¡¾öÓÚ±»Ã°³äµÄʵÌå¡£¡±¡°Èç¹ûµã»÷Á´½ÓµÄÓû§Î»ÓÚÌض¨¹ú¼Ò/µØÓò£¨¾ßÌåÈ¡¾öÓڻ£¬Ä«Î÷¸ç¡¢ÖÇÀû¡¢Î÷°àÑÀ¡¢¸ç˹´ïÀè¼Ó¡¢Ãس»ò°¢¸ùÍ¢£©£¬ËûÃǽ«±»Öض¨Ïòµ½ PDF ͼ±êͼÏñºÍ ZIP ÎļþÊÇÔÚºǫ́ÏÂÔصġ£ZIP Îļþ°üÂÞÒ»¸öÓà PDF ͼ±êαװµÄ´óÐÍ¿ÉÖ´ÐÐÎļþ£¬·¢ÏÖÊÇÔÚµç×ÓÓʼþ·¢Ë͵ÄÇ°Ò»Ìì»òµ±Ìì´´½¨µÄ¡£¡±
https://www.infosecurity-magazine.com/news/grandoreiro-banking-trojan-major/?&web_view=true
3. Kinsing ºÚ¿Í×éÖ¯ÀûÓøü¶àȱÏÝÀ´À©Õ¹Õë¶Ô½©Ê¬ÍøÂç
5ÔÂ17ÈÕ£¬ÃûΪKinsingµÄ¼ÓÃܽٳÖ×éÖ¯ÒѾչÏÖ³ö²»Í£Éú³¤ºÍÊÊÓ¦µÄÄÜÁ¦£¬Í¨¹ýѸËÙ½«ÐÂÅû¶µÄ©¶´¼¯³Éµ½Â©¶´ÀûÓÿâÖв¢À©Õ¹Æ佩ʬÍøÂ磬ÊÂʵ֤Ã÷¸Ã×éÖ¯ÊÇÒ»¸öÁ¬ÐøµÄÍþв¡£¸ÃÊÓ²ì½á¹ûÀ´×ÔÔÆÄþ¾²¹«Ë¾ Aqua£¬¸Ã¹«Ë¾½«ÍþвÐÐΪÕßÃèÊöΪ×Ô 2019 ÄêÒÔÀ´»ý¼«³ïı·Ç·¨¼ÓÃÜ»õ±ÒÍÚ¿ó»î¶¯¡£Kinsing£¨ÓÖÃûH2Miner£©ÊǶñÒâÈí¼þ¼°Æä±³ºóµÄ¶ÔÊÖµÄÃû×Ö£¬Ëü²»Í£ÀûÓÃеĩ¶´À©Õ¹Æ乤¾ß°ü£¬½«ÊÜѬȾµÄϵͳע²áµ½¼ÓÃÜÍÚ¾ò½©Ê¬ÍøÂçÖС£TrustedSec ÓÚ 2020 Äê 1 ÔÂÊ״μǼÁËËü¡£½üÄêÀ´£¬Éæ¼°»ùÓÚ Golang µÄ¶ñÒâÈí¼þµÄ»î¶¯ÀûÓÃÁËApache ActiveMQ¡¢Apache Log4j¡¢Apache NiFi¡¢Atlassian Confluence¡¢Citrix¡¢Liferay Portal¡¢Linux¡¢Openfire¡¢Oracle WebLogic ServerºÍSaltStackÖеÄÖÖÖÖȱÏÝÀ´ÆÆ»µÒ×Êܹ¥»÷µÄϵͳ¡£
https://thehackernews.com/2024/05/kinsing-hacker-group-exploits-more.html?&web_view=true
4. 240 ÍòÈËÊܵ½ WebTPA Êý¾Ý鶵ÄÓ°Ïì
5ÔÂ20ÈÕ£¬WebTPA ¹ÍÖ÷·þÎñ¹«Ë¾Åû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Ó°ÏìÁËÁè¼Ý 240 ÍòÈ˵ĸöÈËÐÅÏ¢¡£WebTPA ×ܲ¿Î»Óڵ¿ËÈø˹ÖÝÅ·ÎÄ£¬ÊÇ GuideWell Mutual Holding Corporation µÄÈ«×Ê×Ó¹«Ë¾£¬ÊÇÒ»¼ÒרÃÅ´Óʽ¡¿µ±£Ïպ͸£Àû¼Æ»®µÄµÚÈý·½¹ÜÀí»ú¹¹ (TPA)¡£WebTPA ÔÚÆäÍøÕ¾ÉϵÄÒ»·Ý֪ͨÖÐÌåÏÖ£¬¸ÃÍøÂçʼþÊÇÔÚÆäÍøÂçÉϼì²âµ½¿ÉÒɻµÄÖ¤¾ÝºóÓÚ 2023 Äê 12 Ô 28 ÈÕ·¢Ïֵġ£¶Ô´ËʵÄÊÓ²ìÏÔʾ£¬Ò»ÃûÍþвÐÐΪÕßÔÚ 2023 Äê 4 Ô 18 ÈÕÖÁ 23 ÈÕÆÚ¼ä´ÓÆäϵͳÖÐÇÔÈ¡Á˸öÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢ÁªÏµÐÅÏ¢¡¢³öÉúÈÕÆÚ¡¢ËÀÍöÈÕÆÚ¡¢±£ÏÕÐÅÏ¢ºÍÉç»áÄþ¾²ºÅÂ롣ƾ¾Ý TPA µÄ˵·¨£¬Ì»Â¶µÄÊý¾ÝÒòÈ˶øÒì¡£²ÆÕþÐÅÏ¢¡¢ÐÅÓÿ¨ºÅÂëÒÔ¼°½¡¿µºÍÒ½ÁÆÐÅϢδÊܵ½¸ÃʼþµÄÓ°Ïì¡£
https://www.securityweek.com/2-4-million-impacted-by-webtpa-data-breach/
5. Singing River Ò½ÁÆϵͳÀÕË÷Èí¼þ¹¥»÷Ó°Ïì½ü 90 ÍòÈË
5ÔÂ20ÈÕ£¬Singing River Health System ÌåÏÖ£¬2023 Äê 8 ÔµÄÀÕË÷Èí¼þ¹¥»÷Ó°ÏìÁË 895,204 ÈË¡£Õâ¼Ò×ܲ¿Î»ÓÚÃÜÎ÷Î÷±ÈÖݵÄÒ½ÁƱ£½¡ÌṩÉÌÔÚÄ«Î÷¸çÍåÑØ°¶µØÓòÔËÓª×Ŷà¼ÒÒ½ÔººÍÒ½ÁÆÉèÊ©¡£Æ¾¾ÝÊý¾Ýй¶֪ͨ£¬Ì»Â¶µÄÐÅÏ¢°üÂÞ£ºÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢ÎïÀíµØÖ·¡¢Éç»áÄþ¾²ºÅÂë (SSN)ºÍÒÔ¼°Ò½Áƺͽ¡¿µÐÅÏ¢¡£¾¡¹Ü´æÔÚÊý¾Ý±»µÁµÄÇé¿ö£¬µ«Ä¿Ç°Ã»ÓÐÖ¤¾Ý±íÃ÷Éí·Ý±»µÁ»òÆÛÕ©¡£¸Ã×é֯ͨ¹ý IDX ÏòÊÜÓ°ÏìµÄÈËÌṩ 24 ¸öÔµÄÐÅÓüà¿ØºÍÉí·Ý»Ö¸´·þÎñ¡£Bleeping Computer½âÊÍ˵£¬¾Ý±¨µÀ£¬ËûÃÇй¶ÁËԼĪ 80% µÄ±»µÁÊý¾Ý£¬ÆäÖаüÂÞ 420,766 ¸öÎļþ£¨754 GB£©µÄĿ¼¡£
https://heimdalsecurity.com/blog/singing-river-health-system-ransomware-attack-affects-nearly-900000/
6. ÍøÂç·¸×ï·Ö×ÓÀûÓÃGitHubºÍFileZillaÁ÷´«¶ñÒâÈí¼þ
5ÔÂ20ÈÕ£¬¾ÝÊӲ죬һ³¡¡°¶à·½ÃæµÄ»î¶¯¡±ÀÄÓà GitHub ºÍ FileZilla µÈºÏ·¨·þÎñ£¬Í¨¹ýð³ä¿ÉÐÅÈí¼þ£¨Èç1Password¡¢Bartender 5 ºÍ Pixelmator Pro¡£Recorded Future µÄ Insikt GroupÔÚÒ»·Ý³ÂËßÖÐÌåÏÖ£º¡°¶àÖÖ¶ñÒâÈí¼þ±äÌåµÄ´æÔÚ±íÃ÷Á˹㷺µÄ¿çƽ̨Ŀ±ê¼Æı£¬¶øÖصþµÄ C2 »ù´¡ÉèÊ©Ôò±íÃ÷Á˼¯ÖÐʽÃüÁîÉèÖã¬Õâ¿ÉÄÜ»áÌá¸ß¹¥»÷µÄЧÂÊ¡£¡±Õâ¼ÒÃûΪ GitCaught µÄÍøÂçÄþ¾²¹«Ë¾ÕýÔÚ×·×ÙÕâÒ»»î¶¯£¬¸Ã¹«Ë¾ÌåÏÖ£¬¸Ã»î¶¯²»½ö͹ÏÔÁËÀÄÓÃÕæʵ»¥ÁªÍø·þÎñÀ´³ïıÍøÂç¹¥»÷£¬¶øÇÒ»¹ÒÀÀµÓÚÕë¶Ô Android¡¢macOS ºÍ Windows µÄ¶àÖÖ¶ñÒâÈí¼þ±äÌåÀ´Ìá¸ßÀÖ³ÉÂÊ¡£Ëٶȡ£¹¥»÷Á´ÐèҪʹÓà GitHub ÉϵÄÐé¼ÙÅäÖÃÎļþºÍ´æ´¢¿â£¬ÍйÜÖªÃûÈí¼þµÄ¼Ùð°æ±¾£¬Ä¿µÄÊÇ´ÓÊÜѬȾÉ豸»ñÈ¡Ãô¸ÐÊý¾Ý¡£È»ºó£¬ÕâЩ¶ñÒâÎļþµÄÁ´½Ó»áǶÈëµ½¼¸¸öÓòÖУ¬ÕâЩÓòͨ³£Í¨¹ý¶ñÒâ¹ã¸æºÍ SEO Öж¾»î¶¯½øÐзַ¢¡£
https://thehackernews.com/2024/05/cyber-criminals-exploit-github-and.html