¼Ùð°ÍÁÖÕþ¸® Android Ó¦Ó÷¨Ê½ÇÔÈ¡Êý¾ÝÓÃÓÚÕ©Æ­

Ðû²¼Ê±¼ä 2024-06-04
1. ¼Ùð°ÍÁÖÕþ¸® Android Ó¦Ó÷¨Ê½ÇÔÈ¡Êý¾ÝÓÃÓÚÕ©Æ­


6ÔÂ2ÈÕ £¬Ðí¶àÕþ¸®»ú¹¹¶¼ÔÚÏßÌṩ·þÎñ £¬ÒÔ·½±ã¹«Ãñ¡£´ËÍâ £¬Èç¹û¿ÉÒÔͨ¹ýÒƶ¯Ó¦Ó÷¨Ê½ÌṩÕâÏî·þÎñ £¬½«·Ç³£·½±ãºÍ±ã½Ý¡£µ«ÊÇ £¬µ±¶ñÒâÈí¼þαװ³ÉÕâЩ·þÎñʱ»á·¢Éúʲô£¿McAfee Òƶ¯Ñо¿ÍŶӷ¢ÏÖÁËÒ»¿îαװ³É°ÍÁÖÕþ¸®»ú¹¹·þÎñµÄ InfoStealer Android ¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þαװ³É°ÍÁֵĹٷ½Ó¦Ó÷¨Ê½ £¬²¢Ðû´«Óû§¿ÉÒÔÔÚÊÖ»úÉϸüлòÉêÇë¼ÝʻִÕÕ¡¢Ç©Ö¤ºÍÉí·ÝÖ¤¡£±»¹ã¸æÆÛÆ­µÄÓû§»áºÁ²»ÓÌÔ¥µØ»ñµÃÕâЩ·þÎñËùÐèµÄ¸öÈËÐÅÏ¢¡£ËüÃÇͨ¹ýÖÖÖÖ·½Ê½½Ó´¥Óû§ £¬°üÂÞ Facebook ºÍ¶ÌÐÅ¡£²»ÊìϤÕâЩ¹¥»÷µÄÓû§ºÜÈÝÒ×·¸Ï·¢Ë͸öÈËÐÅÏ¢µÄ´íÎó¡£°ÍÁÖÓÐÒ»¸öÕþ¸®»ú¹¹ £¬ÃûΪÀͶ¯Á¦Êг¡¼à¹Ü¾Ö (LMRA)¡£¸Ã»ú¹¹ÔÚÓÉÀ͹¤²¿³¤µ£ÈÎÖ÷ϯµÄ¶­Ê»áÖ¸µ¼Ï £¬ÓµÓÐÍêÈ«µÄ²ÆÕþºÍÐÐÕþ¶ÀÁ¢ÐÔ¡£ËûÃÇÌṩÖÖÖÖÒƶ¯·þÎñ £¬´ó¶àÊýÓ¦Ó÷¨Ê½Ö»ÌṩһÏî·þÎñ¡£È»¶ø £¬Õâ¸ö¼ÙðӦÓ÷¨Ê½È´Ðû´«Ìṩ¶àÏî·þÎñ¡£³ýÁË×î³£¼ûµÄð³ä LMRA µÄ¼ÙðӦÓÃÍâ £¬»¹ÓÐÖÖÖÖ¼ÙðӦÓà £¬°üÂÞ°ÍÁֺͿÆÍþÌØÒøÐÐ (BBK)¡¢°ÍÁÖ½ðÈڿƼ¼¹«Ë¾ BenefitPay £¬ÉõÖÁ»¹ÓмÙ×°Óë±ÈÌرһò´û¿îÏà¹ØµÄÓ¦Óá£ÕâЩӦÓÃʹÓÃÓë LMRA ¼ÙðӦÓÃÏàͬµÄ¼¼ÊõÀ´ÇÔÈ¡¸öÈËÐÅÏ¢¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/


2. SHINYHUNTERSÕýÔÚ³öÊÛ3000Íòɣ̹µÂÒøÐпͻ§µÄÊý¾Ý


6ÔÂ2ÈÕ £¬ÎÛÃûÕÑÖøµÄÍþвÐÐΪÕß ShinyHunters ÕýÔÚ³öÊ۾ݳƴÓɣ̹µÂÒøÐÐÇÔÈ¡µÄ´óÁ¿Êý¾Ý¡£ShinyHunters Éù³ÆÇÔÈ¡ÁË 3000 Íò¿Í»§¡¢Ô±¹¤ºÍÒøÐÐÕË»§Êý¾Ý¡£5 ÔÂÖÐÑ® £¬Î÷°àÑÀ½ðÈÚ»ú¹¹É£Ì¹µÂÒøÐÐÅû¶ÁËÒ»ÆðÉæ¼°µÚÈý·½ÌṩÉ̵ÄÊý¾Ýй¶Ê¼þ £¬Ó°ÏìÁËÖÇÀû¡¢Î÷°àÑÀºÍÎÚÀ­¹çµÄ¿Í»§¡£¸ÃÒøÐз¢ÏÖµÚÈý·½ÌṩÉÌÍйܵÄÆäÖÐÒ»¸öÊý¾Ý¿âÔ⵽δ¾­ÊÚȨµÄ·ÃÎÊ¡£¸Ã¹«Ë¾Ðû²¼Á¢¼´½ÓÄÉ´ëÊ©¿ØÖÆʼþ¡£¸Ã¹«Ë¾×èÖ¹Á˶ÔÊý¾Ý¿âµÄÈëÇÖ·ÃÎÊ £¬²¢½¨Á¢ÁËÌرðµÄÆÛÕ©Ô¤·À¿ØÖÆ´ëÊ©À´± £»¤ÊÜÓ°ÏìµÄ¿Í»§¡£±»µÁÊý¾Ý¿â°üÂÞËùÓÐÏÖÈκͲ¿ÃÅÇ°ÈÎÔ±¹¤µÄÐÅÏ¢¡£¸ÃÒøÐÐÖ¸³ö £¬¸ÃÊý¾Ý¿â²»´æ´¢½»Ò×Êý¾Ý¡¢ÍøÉÏÒøÐÐÏêϸÐÅÏ¢¡¢ÃÜÂë»òÆäËûÔÊÐíijÈ˽øÐн»Ò×µÄÊý¾Ý¡£¸Ã½ðÈÚ»ú¹¹ÉÐδÌṩ´Ë´ÎʼþµÄ¼¼Êõϸ½Ú»ò鶵ÄÊý¾ÝÖÖÀࡣĿǰÉв»Çå³þÓм¸¶àÈËÊܵ½Ó°Ïì¡£ShinyHunters Éù³Æ Ticketmaster Ôâµ½ºÚ¿Í¹¥»÷ £¬²¢ÒÔ 50 ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛ 1.3 TB µÄÊý¾Ý £¬ÆäÖаüÂÞ 5.6 ÒÚ¿Í»§µÄÍêÕûÏêϸÐÅÏ¢¡£±»µÁÊý¾Ý°üÂÞÐÕÃû¡¢µç×ÓÓʼþ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÃÅƱÏúÊۺͶ©µ¥ÏêϸÐÅÏ¢¡£


https://securityaffairs.com/163956/data-breach/shinyhunters-claims-santander-breach.html


3. CISA ¾¯¸æ³Æ Linux ÌØȨÌáÉý©¶´¿ÉÄܱ»»ý¼«ÀûÓÃ


6ÔÂ2ÈÕ £¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö (CISA) ÔÚÆäÒÑÖªÀûÓ鶴 (KEV) Ŀ¼ÖÐÌí¼ÓÁËÁ½¸ö©¶´ £¬ÆäÖаüÂÞ Linux ÄÚºËȨÏÞÌáÉý©¶´¡£¸Ã¸ßÑÏÖØÐÔ©¶´ ( CVE-2024-1086)ÓÚ 2024 Äê 1 Ô 31 ÈÕÊ×´ÎÅû¶ £¬ÊÇ netfilter£ºnf_tables ×é¼þÖеÄÊͷźóʹÓÃÎÊÌâ £¬µ«×îÔçÊÇÔÚ 2014 Äê 2 ÔµÄÒ»´ÎÌá½»ÖÐÒýÈëµÄ¡£Netfilter ÊÇ Linux ÄÚºËÌṩµÄÒ»¸ö¿ò¼Ü £¬ÔÊÐíÖÖÖÖÓëÍøÂçÏà¹ØµÄ²Ù×÷ £¬ÀýÈçÊý¾Ý°ü¹ýÂË¡¢ÍøÂçµØַת»» (NAT) ºÍÊý¾Ý°üÐ޸ġ£¸Ã©¶´ÊÇÓÉÓÚ 'nft_verdict_init()' º¯ÊýÔÊÐí½«ÕýÖµÓÃ×÷¹³×ÓÅоöÖеÄɾ³ý´íÎó £¬´Ó¶øµ¼Ö 'nf_hook_slow()' º¯ÊýÔÚ NF_DROP ·¢³öÀàËÆÓÚ NF_ACCEPT µÄɾ³ý´íÎóʱִÐÐË«ÖØÊÍ·Å¡£ÀûÓà CVE-2024-1086 ¿ÉÈþßÓе±µØ·ÃÎÊȨÏ޵Ĺ¥»÷ÕßÔÚÄ¿±êϵͳÉÏʵÏÖȨÏÞÌáÉý £¬²¢¿ÉÄÜ»ñµÃ root ¼¶·ÃÎÊȨÏÞ¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-linux-privilege-elevation-flaw/


4. Ðé¼Ùä¯ÀÀÆ÷¸üлáÁ÷´«BitRATºÍLumma Stealer¶ñÒâÈí¼þ


6ÔÂ3ÈÕ £¬Ðé¼ÙµÄÍøÂçä¯ÀÀÆ÷¸üб»ÓÃÓÚÁ÷´«Ô¶³Ì·ÃÎÊľÂí (RAT) ºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬ÀýÈçBitRATºÍLumma Stealer£¨ÓÖÃû LummaC2£©¡£µ±Ç±ÔÚÄ¿±ê·ÃÎÊÒ»¸ö´øÓÐÏÝÚåµÄÍøվʱ £¬¹¥»÷Á´¾Í¿ªÊ¼ÁË £¬¸ÃÍøÕ¾°üÂÞÖ¼ÔÚ½«Óû§Öض¨Ïòµ½Ðé¼Ùä¯ÀÀÆ÷¸üÐÂÒ³Ã棨¡°chatgpt-app[.]cloud¡±£©µÄ JavaScript ´úÂë¡£Öض¨ÏòµÄÍøҳǶÈëÁËÖ¸Ïò ZIP ´æµµÎļþ£¨¡°Update.zip¡±£©µÄÏÂÔØÁ´½Ó £¬¸ÃÎļþÍйÜÔÚ Discord Éϲ¢×Ô¶¯ÏÂÔص½Êܺ¦ÕßµÄÉ豸¡£ÖµµÃÖ¸³öµÄÊÇ £¬ÍþвÐÐΪÕß¾­³£Ê¹Óà Discord ×÷Ϊ¹¥»÷ý½é £¬ Bitdefender×î½üµÄ·ÖÎö·¢ÏÖ £¬ÔÚ¹ýÈ¥Áù¸öÔÂÖÐ £¬ÓÐÁè¼Ý 50,000 ¸öΣÏÕÁ´½ÓÁ÷´«¶ñÒâÈí¼þ¡¢ÍøÂçµöÓã»î¶¯ºÍÀ¬»øÓʼþ¡£ZIP ´æµµÎļþÖдæÔÚÁíÒ»¸ö JavaScript Îļþ£¨¡°Update.js¡±£© £¬Ëü»á´¥·¢ PowerShell ½Å±¾µÄÖ´ÐÐ £¬¸Ã½Å±¾ÂôÁ¦´ÓÔ¶³Ì·þÎñÆ÷ÒÔ PNG ͼÏñÎļþµÄÐÎʽ¼ìË÷ÆäËûÓÐЧ¸ºÔØ £¬°üÂÞ BitRAT ºÍ Lumma Stealer¡£


https://thehackernews.com/2024/06/beware-fake-browser-updates-deliver.html


5. ¾¯·½µ·»ÙµÁ°æµçÊÓÁ÷ýÌåÍøÂçÒѾ­»ñÀû570ÍòÃÀÔª


6ÔÂ3ÈÕ £¬Î÷°àÑÀ¾¯·½µ·»ÙÁËÒ»¸ö·Ç·¨Ã½ÌåÄÚÈÝÁ÷´«ÍøÂç £¬¸ÃÍøÂç×Ô 2015 Ä꿪ʼÔËÓªÒÔÀ´ÒÑ»ñÀûÁè¼Ý 570 ÍòÃÀÔª¡£¸ÃÊÓ²ìÓÚ 2022 Äê 11 Ô¿ªÊ¼ £¬Æäʱ´´ÒâÓëÓéÀÖÁªÃË (ACE) Ìá½»ÁËÒ»·ÝͶËß £¬¾Ù±¨Á½¸öÍøÒ³ÇÖ·¸ÁË֪ʶ²úȨ¡£ÕâЩÍøÕ¾ÍйÜ×Å·Ç·¨ IPTV ·þÎñ¡°TVMucho¡±£¨Ò²³ÆΪ¡°Teeveeing¡±£© £¬¾Ý ACE ³Æ £¬¸Ã·þÎñÔÚ 2023 ÄêµÄ·ÃÎÊÁ¿Áè¼Ý 400 Íò´Î¡£¾¯·½ÊÓ²ìºó·¢ÏÖ £¬ÕâЩÍøÕ¾µÄËùÓÐÕß±³ºóÓÐÒ»¸ö´ó¹æÄ£µÄ IPTV Ðж¯ £¬ÎªÔ¼Äª 14,000 ÃûÓû§Ìṩ 130 ¸ö¹ú¼ÊµçÊÓƵµÀºÍÊýǧ²¿Ó°Ï·ºÍµçÊÓ¾çµÄ·Ç·¨·ÃÎÊȨÏÞ¡£¸Ã·þÎñµÄÓû§Æ¾¾ÝÆ䶩ÔÄÆ·¼¶Ö§¸¶Ã¿Ô 11 ÖÁ 20.5 ÃÀÔª»òÿÄê 97 ÖÁ 182.5 ÃÀÔª £¬ÕâʹµÃ IPTV ƽ̨ÔËÓªÉÌ×ܹ²»ñÀû 570 ÍòÃÀÔª¡£


https://www.bleepingcomputer.com/news/legal/police-dismantle-pirated-tv-streaming-network-that-made-57-million/


6. Hugging Face ³ÆºÚ¿Í´Ó Spaces ÇÔÈ¡Éí·ÝÑéÖ¤ÁîÅÆ


6ÔÂ2ÈÕ £¬È˹¤ÖÇÄÜƽ̨ Hugging Face ÌåÏÖÆä Spaces ƽ̨Ôâµ½ÈëÇÖ £¬ºÚ¿ÍµÃÒÔ»ñÈ¡Æä³ÉÔ±µÄÉí·ÝÑéÖ¤»úÃÜ¡£Hugging Face Spaces ÊÇÒ»¸öÓÉÉçÇøÓû§´´½¨ºÍÌá½»µÄ AI Ó¦Ó÷¨Ê½¿â £¬ÔÊÐíÆäËû³ÉÔ±ÑÝʾËüÃÇ¡£Hugging Face ÌåÏÖ £¬ËûÃÇÒѾ­È¡ÏûÁË鶻úÃÜÖеÄÉí·ÝÑéÖ¤ÁîÅÆ £¬²¢Í¨¹ýµç×ÓÓʼþ֪ͨÁËÊÜÓ°ÏìµÄÓû§¡£µ«ÊÇ £¬ËûÃǽ¨ÒéËùÓÐ Hugging Face Spaces Óû§Ë¢ÐÂËûÃǵÄÁîÅƲ¢Çл»µ½ ϸÁ£¶È·ÃÎÊÁîÅÆ £¬ÕâʹµÃ×éÖ¯¿ÉÒÔ¸üÑϸñµØ¿ØÖÆË­ÓÐȨ·ÃÎÊËûÃÇµÄ AI Ä£ÐÍ¡£¸Ã¹«Ë¾ÕýÔÚÓëÍⲿÍøÂçÄþ¾²×¨¼ÒºÏ×÷ÊÓ²ì´Ë´ÎÎ¥¹æÐÐΪ £¬²¢ÏòÖ´·¨ºÍÊý¾Ý± £»¤»ú¹¹³ÂË߸Ãʼþ¡£


https://www.bleepingcomputer.com/news/security/ai-platform-hugging-face-says-hackers-stole-auth-tokens-from-spaces/