ð³ä°ÍÁÖÕþ¸® Android Ó¦ÓóÌÐòÇÔÈ¡Êý¾ÝÓÃÓÚÕ©Æ­

Ðû²¼Ê±¼ä 2024-06-04
1. ð³ä°ÍÁÖÕþ¸® Android Ó¦ÓóÌÐòÇÔÈ¡Êý¾ÝÓÃÓÚÕ©Æ­


6ÔÂ2ÈÕ£¬£¬£¬Ðí¶àÕþ¸®»ú¹¹¶¼ÔÚÏßÌṩЧÀÍ£¬£¬£¬ÒÔÀû±ã¹«Ãñ¡£¡£¡£±ðµÄ£¬£¬£¬ÈôÊÇ¿ÉÒÔͨ¹ýÒÆ¶¯Ó¦ÓóÌÐòÌṩÕâÏîЧÀÍ£¬£¬£¬½«ºÜÊÇÀû±ãºÍ±ã½Ý¡£¡£¡£¿ÉÊÇ£¬£¬£¬µ±¶ñÒâÈí¼þαװ³ÉÕâЩЧÀÍʱ»á±¬·¢Ê²Ã´£¿£¿£¿£¿McAfee ÒÆ¶¯Ñо¿ÍŶӷ¢Ã÷ÁËÒ»¿îαװ³É°ÍÁÖÕþ¸®»ú¹¹Ð§À굀 InfoStealer Android ¶ñÒâÈí¼þ¡£¡£¡£¸Ã¶ñÒâÈí¼þαװ³É°ÍÁֵĹٷ½Ó¦ÓóÌÐò£¬£¬£¬²¢Ðû´«Óû§¿ÉÒÔÔÚÊÖ»úÉϸüлòÉêÇë¼ÝʻִÕÕ¡¢Ç©Ö¤ºÍÉí·ÝÖ¤¡£¡£¡£±»¹ã¸æÓÕÆ­µÄÓû§»á¾ø²»ÓÌÔ¥µØ»ñµÃÕâЩЧÀÍËùÐèµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£ËüÃÇͨ¹ýÖÖÖÖ·½·¨½Ó´¥Óû§£¬£¬£¬°üÀ¨ Facebook ºÍ¶ÌÐÅ¡£¡£¡£²»ÊìϤÕâЩ¹¥»÷µÄÓû§ºÜÈÝÒ×·¸Ï·¢ËÍСÎÒ˽¼ÒÐÅÏ¢µÄ¹ýʧ¡£¡£¡£°ÍÁÖÓÐÒ»¸öÕþ¸®»ú¹¹£¬£¬£¬ÃûΪÀͶ¯Á¦Êг¡î¿Ïµ¾Ö (LMRA)¡£¡£¡£¸Ã»ú¹¹ÔÚÓÉÀ͹¤²¿³¤µ£µ±Ö÷ϯµÄ¶­Ê»áÖ¸µ¼Ï£¬£¬£¬ÓµÓÐÍêÈ«µÄ²ÆÎñºÍÐÐÕþ×ÔÁ¦ÐÔ¡£¡£¡£ËûÃÇÌṩÖÖÖÖÒÆ¶¯Ð§ÀÍ£¬£¬£¬´ó´ó¶¼Ó¦ÓóÌÐòÖ»ÌṩһÏîЧÀÍ¡£¡£¡£È»¶ø£¬£¬£¬Õâ¸öð³äÓ¦ÓóÌÐòÈ´Ðû´«Ìṩ¶àÏîЧÀÍ¡£¡£¡£³ýÁË×î³£¼ûµÄð³ä LMRA µÄð³äÓ¦ÓÃÍ⣬£¬£¬ÉÐÓÐÖÖÖÖð³äÓ¦Ó㬣¬£¬°üÀ¨°ÍÁֺͿÆÍþÌØÒøÐÐ (BBK)¡¢°ÍÁÖ½ðÈڿƼ¼¹«Ë¾ BenefitPay£¬£¬£¬ÉõÖÁÉÐÓÐð³äÓë±ÈÌØ±Ò»ò´û¿îÏà¹ØµÄÓ¦Óᣡ£¡£ÕâЩӦÓÃʹÓÃÓë LMRA ð³äÓ¦ÓÃÏàͬµÄÊÖÒÕÀ´ÇÔȡСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/


2. SHINYHUNTERSÕýÔÚ³öÊÛ3000Íòɣ̹µÂÒøÐпͻ§µÄÊý¾Ý


6ÔÂ2ÈÕ£¬£¬£¬ÎÛÃûÕÑÖøµÄÍþвÐÐΪÕß ShinyHunters ÕýÔÚ³öÊ۾ݳƴÓɣ̹µÂÒøÐÐÇÔÈ¡µÄ´ó×ÚÊý¾Ý¡£¡£¡£ShinyHunters Éù³ÆÇÔÈ¡ÁË 3000 Íò¿Í»§¡¢Ô±¹¤ºÍÒøÐÐÕË»§Êý¾Ý¡£¡£¡£5 ÔÂÖÐÑ®£¬£¬£¬Î÷°àÑÀ½ðÈÚ»ú¹¹É£Ì¹µÂÒøÐÐÅû¶ÁËÒ»ÆðÉæ¼°µÚÈý·½ÌṩÉ̵ÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬Ó°ÏìÁËÖÇÀû¡¢Î÷°àÑÀºÍÎÚÀ­¹çµÄ¿Í»§¡£¡£¡£¸ÃÒøÐз¢Ã÷µÚÈý·½ÌṩÉÌÍÐ¹ÜµÄÆäÖÐÒ»¸öÊý¾Ý¿âÔ⵽δ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¸Ã¹«Ë¾Ðû²¼Á¬Ã¦½ÓÄɲ½·¥¿ØÖÆÊÂÎñ¡£¡£¡£¸Ã¹«Ë¾×èÖ¹Á˶ÔÊý¾Ý¿âµÄÈëÇÖ»á¼û£¬£¬£¬²¢½¨ÉèÁËÌØÁíÍâڲƭԤ·À¿ØÖƲ½·¥À´± £»£»£»£»£»£» £»¤ÊÜÓ°ÏìµÄ¿Í»§¡£¡£¡£±»µÁÊý¾Ý¿â°üÀ¨ËùÓÐÏÖÈκͲ¿·ÖǰÈÎÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¸ÃÒøÐÐÖ¸³ö£¬£¬£¬¸ÃÊý¾Ý¿â²»´æ´¢ÉúÒâÊý¾Ý¡¢ÍøÉÏÒøÐÐÏêϸÐÅÏ¢¡¢ÃÜÂë»òÆäËûÔÊÐíijÈ˾ÙÐÐÉúÒâµÄÊý¾Ý¡£¡£¡£¸Ã½ðÈÚ»ú¹¹ÉÐδÌṩ´Ë´ÎÊÂÎñµÄÊÖÒÕϸ½Ú»òй¶µÄÊý¾ÝÖÖÀà¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÓм¸¶àÈËÊܵ½Ó°Ïì¡£¡£¡£ShinyHunters Éù³Æ Ticketmaster Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬²¢ÒÔ 50 ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ 1.3 TB µÄÊý¾Ý£¬£¬£¬ÆäÖаüÀ¨ 5.6 ÒÚ¿Í»§µÄÍêÕûÏêϸÐÅÏ¢¡£¡£¡£±»µÁÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþ¡¢µØµã¡¢µç»°ºÅÂë¡¢ÃÅÆ±ÏúÊۺͶ©µ¥ÏêϸÐÅÏ¢¡£¡£¡£


https://securityaffairs.com/163956/data-breach/shinyhunters-claims-santander-breach.html


3. CISA ÖÒÑÔ³Æ Linux ÌØÈ¨ÌáÉýÎó²î¿ÉÄܱ»Æð¾¢Ê¹ÓÃ


6ÔÂ2ÈÕ£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö (CISA) ÔÚÆäÒÑ֪ʹÓÃÎó²î (KEV) Ŀ¼ÖÐÌí¼ÓÁËÁ½¸öÎó²î£¬£¬£¬ÆäÖаüÀ¨ Linux ÄÚºËȨÏÞÌáÉýÎó²î¡£¡£¡£¸Ã¸ßÑÏÖØÐÔÎó²î ( CVE-2024-1086)ÓÚ 2024 Äê 1 Ô 31 ÈÕÊ×´ÎÅû¶£¬£¬£¬ÊÇ netfilter£ºnf_tables ×é¼þÖеÄÊͷźóʹÓÃÎÊÌ⣬£¬£¬µ«×îÔçÊÇÔÚ 2014 Äê 2 ÔµÄÒ»´ÎÌá½»ÖÐÒýÈëµÄ¡£¡£¡£Netfilter ÊÇ Linux ÄÚºËÌṩµÄÒ»¸ö¿ò¼Ü£¬£¬£¬ÔÊÐíÖÖÖÖÓëÍøÂçÏà¹ØµÄ²Ù×÷£¬£¬£¬ÀýÈçÊý¾Ý°ü¹ýÂË¡¢ÍøÂçµØµãת»» (NAT) ºÍÊý¾Ý°üÐ޸ġ£¡£¡£¸ÃÎó²îÊÇÓÉÓÚ 'nft_verdict_init()' º¯ÊýÔÊÐí½«ÕýÖµÓÃ×÷¹³×ÓѶ¶ÏÖеÄɾ³ý¹ýʧ£¬£¬£¬´Ó¶øµ¼Ö 'nf_hook_slow()' º¯ÊýÔÚ NF_DROP ·¢³öÀàËÆÓÚ NF_ACCEPT µÄɾ³ý¹ýʧʱִÐÐË«ÖØÊÍ·Å¡£¡£¡£Ê¹Óà CVE-2024-1086 ¿ÉÈþßÓÐÍâµØ»á¼ûȨÏ޵Ĺ¥»÷ÕßÔÚÄ¿µÄϵͳÉÏʵÏÖȨÏÞÌáÉý£¬£¬£¬²¢¿ÉÄÜ»ñµÃ root ¼¶»á¼ûȨÏÞ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-linux-privilege-elevation-flaw/


4. Ðéαä¯ÀÀÆ÷¸üлáÈö²¥BitRATºÍLumma Stealer¶ñÒâÈí¼þ


6ÔÂ3ÈÕ£¬£¬£¬ÐéαµÄÍøÂçä¯ÀÀÆ÷¸üб»ÓÃÓÚÈö²¥Ô¶³Ì»á¼ûľÂí (RAT) ºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬£¬£¬ÀýÈçBitRATºÍLumma Stealer£¨ÓÖÃû LummaC2£©¡£¡£¡£µ±Ç±ÔÚÄ¿µÄ»á¼ûÒ»¸ö´øÓÐÏÝÚåµÄÍøÕ¾Ê±£¬£¬£¬¹¥»÷Á´¾Í×îÏÈÁË£¬£¬£¬¸ÃÍøÕ¾°üÀ¨Ö¼ÔÚ½«Óû§Öض¨Ïòµ½Ðéαä¯ÀÀÆ÷¸üÐÂÒ³Ãæ£¨¡°chatgpt-app[.]cloud¡±£©µÄ JavaScript ´úÂë¡£¡£¡£Öض¨ÏòµÄÍøÒ³Ç¶ÈëÁËÖ¸Ïò ZIP ´æµµÎļþ£¨¡°Update.zip¡±£©µÄÏÂÔØÁ´½Ó£¬£¬£¬¸ÃÎļþÍйÜÔÚ Discord Éϲ¢×Ô¶¯ÏÂÔØµ½Êܺ¦ÕßµÄ×°±¸¡£¡£¡£ÖµµÃÖ¸³öµÄÊÇ£¬£¬£¬ÍþвÐÐΪÕß¾­³£Ê¹Óà Discord ×÷Ϊ¹¥»÷ǰÑÔ£¬£¬£¬ Bitdefender×î½üµÄÆÊÎö·¢Ã÷£¬£¬£¬ÔÚÒÑÍùÁù¸öÔÂÖУ¬£¬£¬ÓÐÁè¼Ý 50,000 ¸öΣÏÕÁ´½ÓÈö²¥¶ñÒâÈí¼þ¡¢ÍøÂç´¹ÂڻºÍÀ¬»øÓʼþ¡£¡£¡£ZIP ´æµµÎļþÖб£´æÁíÒ»¸ö JavaScript Îļþ£¨¡°Update.js¡±£©£¬£¬£¬Ëü»á´¥·¢ PowerShell ¾ç±¾µÄÖ´ÐУ¬£¬£¬¸Ã¾ç±¾ÈÏÕæ´ÓÔ¶³ÌЧÀÍÆ÷ÒÔ PNG ͼÏñÎļþµÄÐÎʽ¼ìË÷ÆäËûÓÐÓøºÔØ£¬£¬£¬°üÀ¨ BitRAT ºÍ Lumma Stealer¡£¡£¡£


https://thehackernews.com/2024/06/beware-fake-browser-updates-deliver.html


5. ¾¯·½µ·»ÙµÁ°æµçÊÓÁ÷ýÌåÍøÂçÒѾ­×¬Ç®570ÍòÃÀÔª


6ÔÂ3ÈÕ£¬£¬£¬Î÷°àÑÀ¾¯·½µ·»ÙÁËÒ»¸ö²»·¨Ã½ÌåÄÚÈÝÈö²¥ÍøÂ磬£¬£¬¸ÃÍøÂç×Ô 2015 Äê×îÏÈÔËÓªÒÔÀ´ÒÑ׬ǮÁè¼Ý 570 ÍòÃÀÔª¡£¡£¡£¸ÃÊÓ²ìÓÚ 2022 Äê 11 ÔÂ×îÏÈ£¬£¬£¬Æäʱ´´ÒâÓëÓéÀÖͬÃË (ACE) Ìá½»ÁËÒ»·ÝͶËߣ¬£¬£¬¾Ù±¨Á½¸öÍøÒ³ÇÖÕ¼ÁË֪ʶ²úȨ¡£¡£¡£ÕâÐ©ÍøÕ¾ÍйÜ×Ų»·¨ IPTV ЧÀÍ¡°TVMucho¡±£¨Ò²³ÆÎª¡°Teeveeing¡±£©£¬£¬£¬¾Ý ACE ³Æ£¬£¬£¬¸ÃЧÀÍÔÚ 2023 ÄêµÄ»á¼ûÁ¿Áè¼Ý 400 Íò´Î¡£¡£¡£¾¯·½ÊÓ²ìºó·¢Ã÷£¬£¬£¬ÕâÐ©ÍøÕ¾µÄËùÓÐÕß±³ºóÓÐÒ»¸ö´ó¹æÄ£µÄ IPTV Ðж¯£¬£¬£¬ÎªÔ¼Äª 14,000 ÃûÓû§Ìṩ 130 ¸ö¹ú¼ÊµçÊÓÆµµÀºÍÊýǧ²¿Ó°Ï·ºÍµçÊÓ¾çµÄ²»·¨»á¼ûȨÏÞ¡£¡£¡£¸ÃЧÀ͵ÄÓû§Æ¾Ö¤Æä¶©ÔÄÆ·¼¶Ö§¸¶Ã¿Ô 11 ÖÁ 20.5 ÃÀÔª»òÿÄê 97 ÖÁ 182.5 ÃÀÔª£¬£¬£¬ÕâʹµÃ IPTV ƽ̨ÔËÓªÉÌ×ܹ²×¬Ç® 570 ÍòÃÀÔª¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/police-dismantle-pirated-tv-streaming-network-that-made-57-million/


6. Hugging Face ³ÆºÚ¿Í´Ó Spaces ÇÔÈ¡Éí·ÝÑéÖ¤ÁîÅÆ


6ÔÂ2ÈÕ£¬£¬£¬È˹¤ÖÇÄÜÆ½Ì¨ Hugging Face ÌåÏÖÆä Spaces ƽ̨Ôâµ½ÈëÇÖ£¬£¬£¬ºÚ¿ÍµÃÒÔ»ñÈ¡Æä³ÉÔ±µÄÉí·ÝÑéÖ¤ÉñÃØ¡£¡£¡£Hugging Face Spaces ÊÇÒ»¸öÓÉÉçÇøÓû§½¨ÉèºÍÌá½»µÄ AI Ó¦ÓóÌÐò¿â£¬£¬£¬ÔÊÐíÆäËû³ÉÔ±ÑÝʾËüÃÇ¡£¡£¡£Hugging Face ÌåÏÖ£¬£¬£¬ËûÃÇÒѾ­×÷·ÏÁËй¶ÉñÃØÖеÄÉí·ÝÑéÖ¤ÁîÅÆ£¬£¬£¬²¢Í¨¹ýµç×ÓÓʼþ֪ͨÁËÊÜÓ°ÏìµÄÓû§¡£¡£¡£¿ÉÊÇ£¬£¬£¬ËûÃǽ¨ÒéËùÓÐ Hugging Face Spaces Óû§Ë¢ÐÂËûÃǵÄÁîÅÆ²¢Çл»µ½ ϸÁ£¶È»á¼ûÁîÅÆ£¬£¬£¬ÕâʹµÃ×éÖ¯¿ÉÒÔ¸üÑÏ¿áµØ¿ØÖÆË­ÓÐȨ»á¼ûËûÃÇµÄ AI Ä£×Ó¡£¡£¡£¸Ã¹«Ë¾ÕýÔÚÓëÍâ²¿ÍøÂçÇ徲ר¼ÒÏàÖúÊÓ²ì´Ë´ÎÎ¥¹æÐÐΪ£¬£¬£¬²¢ÏòÖ´·¨ºÍÊý¾Ý± £»£»£»£»£»£» £»¤»ú¹¹±¨¸æ¸ÃÊÂÎñ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ai-platform-hugging-face-says-hackers-stole-auth-tokens-from-spaces/