×êÑÐÈËÔ±ÑÝʾÕë¶ÔÈËΪÖÇÄÜϵͳµÄÈËΪÖÇÄÜÈ䳿

°ä²¼¹¦·ò 2024-04-26
1. ×êÑÐÈËÔ±ÑÝʾÕë¶ÔÈËΪÖÇÄÜϵͳµÄÈËΪÖÇÄÜÈ䳿


4ÔÂ24ÈÕ £¬×êÑÐÈËÔ±ÑÝʾÁËÒ»ÖÖǰËùδ¼ûµÄÐÂÐͶñÒâÈí¼þ £¬³ÆÎª¡°Morris II¡±È䳿²¡¶¾ £¬¸ÃÈ䳿²¡¶¾ÀûÓÃÊ¢ÐеÄÈËΪÖÇÄÜ·þÎñ½øÐÐ×ÔÎÒ´«²¼¡¢Ï°È¾ÐÂϵͳ²¢ÇÔÈ¡Êý¾Ý¡£¸ÃÃû³ÆÔ´×Ô 1988 ÄêÔÚ»¥ÁªÍøÉÏÔì³ÉÑϳÁ·ÛËéµÄԭʼ Morris ÍÆËã»úÈ䳿¡£¸ÃÈ䳿²¡¶¾Õ¹Ê¾ÁËÈËΪÖÇÄܰ²È«ÍþвµÄDZÔÚΣÏÕ £¬²¢Îª±£»¤ÈËΪÖÇÄÜÄ£ÐÍ´øÀ´ÁËеĽôÆÈÐÔ¡£À´×Ô¿µÄζûÀí¹¤´óѧ¡¢ÒÔÉ«ÁÐÀí¹¤Ñ§ÔººÍ Intuit µÄ×êÑÐÈËԱʹÓÃËùνµÄ¡°Æ¥µÐÐÔ×ÔÎÒ¸´ÔìÌáÐÑ¡±À´´´½¨¸ÃÈ䳿²¡¶¾¡£ÕâÊÇÒ»¸öÌáÐÑ £¬µ±ÊäÈë´óÐÍ˵»°Ä£ÐÍ£¨LLM£©Ê±£¨ËûÃÇÔÚ OpenAI µÄ ChatGPT¡¢Google µÄ Gemini ÒÔ¼°Íþ˹¿µÐÇ´óѧÂóµÏÑ··ÖУ¡¢Î¢Èí×êÑÐÔººÍ¸çÂ×±ÈÑÇ´óѧµÄ×êÑÐÈËÔ±¿ª·¢µÄ¿ªÔ´ LLaVA Ä£ÐÍÉϽøÐÐÁ˲âÊÔ£©  £¬ºýŪģÐÍ´´½¨¶î±íµÄÌáÐÑ¡£Ëü´¥·¢Ì¸Ìì»úеÈËÌìÉú×Ô¼ºµÄ¶ñÒâÌáÐÑ £¬¶øºóͨ¹ýÖ´ÐÐÕâЩָÁîÀ´ÏìÓ¦£¨ÀàËÆÓÚ SQL ×¢È뻺ºÍ³åÇøÒç³ö¹¥»÷£©¡£


https://securityintelligence.com/articles/malicious-ai-worm-targeting-generative-ai/


2. ArcaneDoor ºÚ¿ÍÀûÓÃ˼¿ÆÁãÈÕ·ì϶¹¥»÷µ±¾Ö»ú¹¹


4ÔÂ24ÈÕ £¬Ë¼¿Æ½ñÌìÖÒ¸æ³Æ £¬×Ô 2023 Äê 11 ÔÂÒÔÀ´ £¬Ä³ºÚ¿Í×éÖ¯Ò»ÏòÔÚÀûÓÃ×ÔÊÊÓ¦°²È«É豸 (ASA) ºÍ Firepower Íþв·ÀÓù (FTD) ·À»ðǽÖеÄÁ½¸öÁãÈÕ·ì϶À´¹¥»÷È«ÇòÈ·µ±¾ÖÍøÂç¡£ÕâЩºÚ¿Í±»Ë¼¿Æ Talos ¼ø±ðΪ UAT4356 £¬±»Î¢Èí¼ø±ðΪ STORM-1849 £¬ËûÃÇÓÚ 2023 Äê 11 ÔÂÉÏÑ®ÆðÍ·ÔÚÃûΪ ArcaneDoor µÄÍøÂç¼äµý»î¶¯ÖÐÉøÈëÒ×Êܹ¥»÷µÄ±ßÔµÉ豸¡£Ö»¹Ü˼¿ÆÉÐδȷ¶¨×î³õµÄ¹¥»÷ÏòÁ¿ £¬µ«Ëü·¢ÏÖ²¢½¨¸´ÁËÁ½¸ö°²È«·ì϶ - CVE-2024-20353£¨»Ø¾ø·þÎñ£©ºÍCVE-2024-20359£¨Óƾñ¾µØ´úÂëÖ´ÐУ©¡£Ë¼¿ÆÓÚ 2024 Äê 1 ÔÂÉÏÑ®Òâʶµ½ ArcaneDoor »î¶¯ £¬²¢·¢ÏÖÓÐÖ¤¾ÝÅú×¢¹¥»÷ÕßÖÁÉÙ×Ô 2023 Äê 7 ÔÂÆð¾ÍÒѾ­²âÊÔ²¢¿ª·¢ÁËÕë¶ÔÕâÁ½¸öÁãÈÕ·ì϶µÄ·ì϶¡£


https://www.bleepingcomputer.com/news/security/arcanedoor-hackers-exploit-cisco-zero-days-to-breach-govt-networks/


3. Google Chrome ÖеĶà¸ö·ì϶¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐÐ


4ÔÂ24ÈÕ £¬Google Chrome Öз¢ÏÖÁ˶à¸ö·ì϶ £¬¿ÉÄܵ¼ÖÂÖ´ÐÐËÁÒâ´úÂë¡£Ô̺¬ANGLE ÖеÄÀàÐÍ»ìºÏ (CVE-2024-4058)¡¢V8 API ÖеĶÁȡԽ½ç (CVE-2024-4059)ºÍDawn ÖпªÊͺóʹÓà (CVE-2024-4060)¡£³É¹¦ÀûÓÃÕâЩ·ì϶¿ÉÄÜÔÊÐíÔڵǼÓû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ롣ƾ¾ÝÓëÓû§¹ØÁªµÄȨÏÞ £¬¹¥»÷ÕßÄܹ»×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ÓëÓµÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È £¬ÆäÕÊ»§ÅäÖÃΪÔÚϵͳÉÏÕ¼ÓнϺ±Óû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¿ÉÄܸüÓס£Ä¿Ç°»¹Ã»ÓйØÓÚÕâЩ·ì϶±»´ó¹æÄ£ÀûÓõĻ㱨¡£


https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2024-043


4. À³Ë¹ÌسǵÄ·µÆÒòÍøÂç¹¥»÷¶øÎÞ·¨¹Ø¹Ø


4ÔÂ24ÈÕ £¬À³Ë¹ÌØÊÐÒé»áÔâ·êÍøÂç¹¥»÷ £¬ÑϳÁÓ°ÏìÁ˵±¾ÖµÄ·þÎñ²¢µ¼Ö»úÃÜÎļþй¶ ¡£¹¥»÷±³ºóµÄÀÕË÷Èí¼þ×é֯й¶Á˶à·ÝÎļþ £¬Ô̺¬×â½ð±¨±íºÍ²É°ìÒé»á·¿ÎݵÄÉêÇë¡£Õâ´ÎÏ®»÷²úÉúÔÚ3 Ô 7 ÈÕ £¬µ¼ÖÂÊÐÒé»áµÄ IT ϵͳ̱»¾¡£ÓÉÓÚÍøÂç¹¥»÷ £¬Ò»Ð©µÆ³ÉÌì¶¼ÁÁ×Å £¬ÊÐÒé»áÎÞ·¨½«Æä¹Ø¹Ø¡£ÊÐÒé»á³ÆÊÇÓÉÓÚÓë×î½üµÄÍøÂç¹¥»÷Óйصļ¼ÊõÎÊÌâ £¬±»ÆÈ¹Ø¹ØÁË IT ϵͳ¡£ÕâÒâζ×ÅÎÒÃÇĿǰÎÞ·¨Ô¶³Ì¼ø±ð½Ö·ÕÕÃ÷ϵͳµÄ¹ÊÕÏ¡£ÊÐÒé»á½²»°ÈË˵¡£¹ÊÕϵÄĬÈÏģʽÊǵÆÎ¬³ÖÁÁÆð £¬ÒÔÈ·±£Â·Â·²»»áÆëȫϨÃð²¢³ÉΪ°²È«Òþ»¼¡£½â¾öÕâ¸öÎÊÌâ±ØÒª²ÉÈ¡ºÜ¶à²½Öè £¬ÔÚ¾¡¿ì½â¾öÕâЩÎÊÌâ¡£


https://securityaffairs.com/162219/hacking/leicester-city-cyberattack.html


5. ³¬¹ý23Íò·ÝIDFµÄÎļþÔÚÉæÏÓÄäÃû¹¥»÷ÖÐй¶


4ÔÂ24ÈÕ £¬ÓÉÓÚÓëÄäÃûÕß×éÖ¯ÓйصĺڿÍ×é֝ɿÏÓÖ´ÐÐÍøÂç¹¥»÷ £¬ÒÔÉ«Áйú·À¾ü (IDF) Ãæ¶Ô»úÃÜÊý¾Ýй¶µÄÖ¸¿Ø¡£¾ÝºÚ¿Í³Æ £¬ËûÃǽӼûÁË 20 GB µÄÐÅÏ¢ £¬ÆäÖÐÔ̺¬³¬¹ý 233,000 ·Ý¸÷ÀàÌåʽµÄ¾üÊÂÎĵµ £¬Èç PDF Îļþ¡¢Word ÎĵµºÍÑÝʾÎĸå¡£Ïà±È֮Ϡ£¬¹ú·À²¿·ñ¶¨ÓÐÈκα»ÈëÇֵĹ¥»÷ÊÂÎñ £¬Ç¿µ÷Æä¶à²ã°²È«ÍÆËã»úϵͳ²»Ì«¿ÉÄÜÖ±½ÓÊܵ½¹¥»÷¡£ËûÃÇÒÔΪ £¬ÈôÊǵÄÈ·²úÉúÈκκڿ͹¥»÷ £¬ºÜ¿ÉÄÜÉæ¼°ÃñÓÃϵͳ¡£ºÚ¿Í°ä²¼ÁËÒ»¶ÎÊÓÆµ £¬¾Ý³ÆÕ¹Ê¾ÁËÒÔÉ«Áйú·À¾üÑÝʾµÄÕæÊµÆ¬¶Î £¬µ«¸Ã²¿ÃÅÒÔΪÕâÊÇDZÔÚµÄÉúÀíÕ½ÐÐΪ £¬Ê¹È˶Ô×ÊÁϵÄÕæÊµÐÔ²úÉúÒɻ󡣱¾ÔÂÔçЩʱ³½ £¬¸Ã×éÖ¯¾Ý³Æ¶ÔÒÔÉ«ÁÐ˾·¨²¿µÄ IT »ù´¡ÉèÊ©½øÐÐÁËÍøÂç¹¥»÷ £¬Ðû³ÆÒÑÉøÈë¸Ã²¿µÄ°²Õûϵͳ²¢ÏÂÔØÁ˳¬¹ý 300 GB µÄÊý¾Ý¡£¾ÝºÚ¿Í³Æ £¬Êý¾Ý»º´æÔ̺¬ 800 Íò¸öÎļþ £¬ÆäÖÐÔ̺¬Ãô¸ÐµÄÓ×ÎÒÐÅÏ¢¡£


https://meterpreter.org/over-233000-idf-documents-compromised-in-alleged-anonymous-attack/


6. ×êÑÐÍŶӷ¢ÏÖ¿ÉÇÔÈ¡DiscordÊý¾ÝµÄPyPI°ü


4ÔÂ24ÈÕ £¬FortinetµÄÍøÂ簲ȫר¼ÒÔÚ PyPI ÖÐΪ¿ª·¢ÈËÔ±¼ø±ð³öÒ»¸öеĶñÒâ°ü £¬Ö¼ÔÚ´Ó Discord ÇÔÈ¡Óû§Êý¾Ý¡£¸ÃÈí¼þ°üÃûΪ¡°discordpy_bypass-1.7¡± £¬ÓÚ 2024 Äê 3 Ô 10 ÈÕ°ä²¼ £¬²¢ÔÚÁ½Ììºó±»¼ì²âµ½¡£¸ÃÈí¼þ°üÓÉÃûΪ¡°Theaos¡±µÄÓû§¿ª·¢ £¬Ô̺¬Æß¸öÓµÓÐÀàËÆÌØµãµÄ°æ±¾¡£ÆäÖØÒªÖ¸±êÊÇͨ¹ýÔÚÊܺ¦ÕßϵͳÖгÉÁ¢ÓƾÃÐԵļ¼ÊõÀ´ÌáÈ¡»úÃÜÐÅÏ¢¡¢´Óä¯ÀÀÆ÷ÖÐÌáÈ¡Êý¾Ý²¢ÍøÂçÁîÅÆ¡£¼¼Êõ·ÖÎöÏÔʾ £¬¸ÃÈí¼þ°üѡȡÁ˶à²ã¶ã±Ü´ëÊ© £¬Ô̺¬Ê¹Óà base64 ¶Ô¸ù»ù Python ´úÂë½øÐбàÂë¡¢¸½¼Ó»ìºÏ²½Öè £¬ÒÔ¼°½«Æä±àÒëΪ´ÓÔ¶³Ì URL ÏÂÔØµÄ¿ÉÖ´ÐÐÎļþ¡£´Ë±í £¬¹¥»÷Õß»¹½áºÏÁ˶àÏî²é³­ £¬ÔÊÐí¶ñÒâÈí¼þ¼ì²âɳÏä»·¾³ÖеÄÖ´ÐÐÇé¿ö²¢ÖÕ³¡²Ù×÷¡£´Ë±í £¬¸Ã·¨Ê½»¹Äܹ»¼ø±ð²¢×èÖ¹ÁÐÈëºÚÃûµ¥µÄ IP ºÍ MAC µØÖ·¡£¸Ã¶ñÒâÈí¼þ³ö¸ñ¹Ø×¢ Discord Éí·ÝÑéÖ¤Êý¾Ý £¬´Óä¯ÀÀÆ÷ÖÐÌáÈ¡ÃÜÂë¡¢cookie ÎļþºÍÍøÂçËÑË÷º¹Çà¼Í¼¡£ÔÚ½«ËüÃÇ·¢Ë͵½Ô¶³Ì·þÎñÆ÷֮ǰ £¬ÌáÈ¡µÄÁîÅÆ½«±»½âÃܺÍÑéÖ¤¡£


https://meterpreter.org/pypi-package-exposed-fortinet-warns-of-discord-data-theft/