ºÚ¿ÍÀÄÓà Amazon ºÍ GitHub ²¿Êð»ùÓÚ Java µÄ¶ñÒâÈí¼þ

°ä²¼¹¦·ò 2024-03-15
1. ºÚ¿ÍÀÄÓà Amazon ºÍ GitHub ²¿Êð»ùÓÚ Java µÄ¶ñÒâÈí¼þ


3ÔÂ14ÈÕ£¬£¬£¬ £¬£¬£¬£¬ºÚ¿Í¶Ô×¼ÕâЩƽ̨ÊÇÓÉÓÚËüÃÇÍйÜ׏óÖØµÄ×ÊÔ´ºÍÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£¡£³öÓÚ¾­¼ÃÀûÒæ»òÆäËû²»Á¼¶¯»ú£¬£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÈëÇÖÕâЩƽ̨ÇÔÈ¡Êý¾Ý¡¢²¿Êð¶ñÒâÈí¼þ»òÌáÒéÆäËûÍøÂç¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£¡£FortiGuard ³¢ÊÔÊÒµÄÍøÂ簲ȫ·ÖÎöʦ·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬ºÚ¿Í»ý¼«ÀÄÓà Amazon ºÍ GitHub À´²¿Êð»ùÓÚ Java µÄ¶ñÒâÈí¼þ¡£¡£ ¡£¡£¡£¡£¡£¡£FortiGuard ³¢ÊÔÊÒ·¢ÏÖÁËÒ»¸öÍøÂç´¹µö»î¶¯£¬£¬£¬ £¬£¬£¬£¬ÓÕÆ­Óû§ÏÂÔØ¶ñÒâ Java ÏÂÔØÆ÷£¬£¬£¬ £¬£¬£¬£¬ÆäÖ÷ÕÅÊÇ´«²¼Ð嵀 VCURMS ºÍ STRRAT RAT¡£¡£ ¡£¡£¡£¡£¡£¡£ÈËÃÇ·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬ÍйÜÔÚ AWS ºÍ GitHub ÉϵĶñÒâÈí¼þÒÑͨ¹ýóÒ×±£»£»£»£» £»¤·¨Ê½½øÐÐÁË»ìºÏ¡£¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÀûÓÃÊܺ¦Õß¶Ë×¢³ÁÒþÖ﵀ Proton Mail ·þÎñ£¬£¬£¬ £¬£¬£¬£¬Ê¹Óõç×ÓÓʼþ½øÐÐ C2¡£¡£ ¡£¡£¡£¡£¡£¡£ÍøÂç´¹µöµç×ÓÓʼþÒýÓÕÊܺ¦Õßµ¥»÷°´Å¥£¬£¬£¬ £¬£¬£¬£¬ÏÂÔØ´øÓÐÍÌÍÂ×Ö·û´®µÄ¶ñÒâ AWS ÍÐ¹Ü JAR ÏÂÔØ·¨Ê½¡£¡£ ¡£¡£¡£¡£¡£¡£ÏÂÔØÆ÷»ñÈ¡²¢ÔËÐÐÁí±íÁ½¸ö JAR£¬£¬£¬ £¬£¬£¬£¬ÕâЩ JAR ʹÓÃóÒס°Sense Shield Virbox Protector¡±»ìºÏÆ÷£¬£¬£¬ £¬£¬£¬£¬²¢¸½ÓÐÊÔÓÃÆÚµ½ÆÚ֪ͨ¡£¡£ ¡£¡£¡£¡£¡£¡£ 


https://gbhackers.com/hackers-abuse-amazon-github/


2. ºÚ¿ÍÀûÓà Windows SmartScreen ·ì϶Ͷ·Å DarkGate 


3ÔÂ13ÈÕ£¬£¬£¬ £¬£¬£¬£¬DarkGate ¶ñÒâÈí¼þ²Ù×÷ÌáÒéµÄÐÂÒ»²¨¹¥»÷ÀûÓÃÏÖÒѽ¨¸´µÄ Windows Defender SmartScreen ·ì϶À´Èƹý°²È«²é³­²¢×Ô¶¯×°ÖÃÐéαÈí¼þ×°Ö÷¨Ê½¡£¡£ ¡£¡£¡£¡£¡£¡£SmartScreen ÊÇÒ»Ïî Windows °²È«Ö°ÄÜ£¬£¬£¬ £¬£¬£¬£¬µ±Óû§³¢ÊÔÔËÐÐ´Ó Internet ÏÂÔØµÄÎÞ·¨¼ø±ð»ò¿ÉÒÉÎļþʱ£¬£¬£¬ £¬£¬£¬£¬Ëü»áÏÔʾÖҸ档¡£ ¡£¡£¡£¡£¡£¡£±»×·×ÙΪ CVE-2024-21412 µÄȱµãÊÇ Windows Defender SmartScreen ȱµã£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÌØÔìµÄÏÂÔØÎļþÈÆ¹ýÕâЩ°²È«ÖҸ档¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý´´½¨Ö¸ÏòÔ¶³Ì SMB ¹²ÏíÉÏÍйܵÄÁíÒ»¸ö .url ÎļþµÄ Windows Internet ¿ì½Ý·½Ê½£¨.url Îļþ£©À´ÀûÓøÃȱµã£¬£¬£¬ £¬£¬£¬£¬Õ⽫µ¼ÖÂ×îÖÕµØÎ»µÄÎļþ×Ô¶¯Ö´ÐÓ×£¡£ ¡£¡£¡£¡£¡£¡£Î¢ÈíÓÚ 2 ÔÂÖÐÑ®½¨¸´Á˸÷ì϶£¬£¬£¬ £¬£¬£¬£¬Ç÷Ïò¿Æ¼¼Ð¹Â©£¬£¬£¬ £¬£¬£¬£¬³öÓÚ¾­¼Ã¶¯»úµÄ Water Hydra ºÚ¿Í×éÖ¯´ËÇ°Ôø ÀûÓø÷ì϶×÷ΪÁãÈÕ·ì϶ £¬£¬£¬ £¬£¬£¬£¬½«Æä DarkMe ¶ñÒâÈí¼þÖ²ÈëÂòÂôÕßµÄϵͳÖÓ×£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-windows-smartscreen-flaw-to-drop-darkgate-malware/#google_vignette


3. HHS ½«µ÷²é UnitedHealth ºÍÕë¶Ô Change Healthcare µÄÀÕË÷¹¥»÷


3ÔÂ14ÈÕ£¬£¬£¬ £¬£¬£¬£¬ÃÀ¹úÎÀÉúÓ빫¹²·þÎñ²¿ (HHS) ÔÚ¶ÔÕë¶Ô Change Healthcare µÄÀÕË÷Èí¼þ¹¥»÷·¢Õ¹µ÷²é£¬£¬£¬ £¬£¬£¬£¬´Ëǰ¸Ã¹ú¸÷µØÒ½Ôº¡¢ÕïËùºÍÒ©·¿µÄÒ½ÁƱ£½¡ºÍ¼Æ·ÑÒµÎñÒÑÔâ·êÊýÖܵÄ×ÌÈÅ¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã²¿ÃŵÄÃñȨ°ì¹«ÊÒ (OCR)ÖÜÈý°ä·¢ÁËÒ»·âÐÅ£¬£¬£¬ £¬£¬£¬£¬°ä·¢·¢Õ¹µ÷²é£¬£¬£¬ £¬£¬£¬£¬Ö÷ÈÎ Melanie Fontes Rainer д·£¬£¬£¬ £¬£¬£¬£¬¡°¼øÓÚÕâ´ÎÍøÂç¹¥»÷µÄ¹æÄ£¿£¿ £¿£¿£¿£¿ÕǰÑϳÁ£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒΪÁË»¼Õߺͽ¡È«µÄ×î´óÀûÒæ£¬£¬£¬ £¬£¬£¬£¬ËûÃDZØÒªµ÷²éÕâÒ»Çé¿ö¡±»¤ÀíÌṩÕß¡£¡£ ¡£¡£¡£¡£¡£¡£¡± °×¹¬¹ÙÔ±¡¢Ò½ÁÆÐÐÒµ´ú±í¡¢ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿²¿³¤Ôóά¶û¡¤±´ÈûÀ­ (Xavier Becerra) ºÍ Change Healthcare ĸ¹«Ë¾½áºÏ½¡È«¼¯ÍÅ (UnitedHealth Group) Ê×ϯִÐйٰ²µÂ³¡¤ÍþµÙ (Andrew Witty) ÕÙ¿ªÁË»áÒ飬£¬£¬ £¬£¬£¬£¬»áÉ̽â¾öΣ»£»£»£» £»úÎÊÌâ¡£¡£ ¡£¡£¡£¡£¡£¡£Fontes Rainer °µÊ¾£¬£¬£¬ £¬£¬£¬£¬µ÷²é½«³Áµã¹Ø×¢Êܱ£»£»£»£» £»¤µÄ½¡È«ÐÅÏ¢ÊÇ·ñÊܵ½ÇÖº¦£¬£¬£¬ £¬£¬£¬£¬ÒÔ¼° Change Healthcare ºÍ UHG ÊÇ·ñ×ñÊØ½¡È«±£ÏÕÁ÷ͨºÍÔðÈη¨°¸ (HIPAA) ¹æ¶¨¡£¡£ ¡£¡£¡£¡£¡£¡£


https://therecord.media/hhs-investigating-unitedhealth-after-ransomware-attack


4. PixPirate Android ¶ñÒâÈí¼þʹÓÃÐÂÕ½Êõ°µ²ØÔÚÊÖ»úÉÏ


3ÔÂ13ÈÕ£¬£¬£¬ £¬£¬£¬£¬ºÏÓÃÓÚ Android µÄ×îа汾µÄ PixPirate ÒøÐÐľÂíѡȡÁËÒ»ÖÖв½Ö裬£¬£¬ £¬£¬£¬£¬Äܹ»°µ²ØÔÚÊÖ»úÉÏ£¬£¬£¬ £¬£¬£¬£¬Í¬Ê±Î¬³Ö»î¶¯×´Ì¬£¬£¬£¬ £¬£¬£¬£¬¼´±ãÆäµÎ¹ÜÀûÓ÷¨Ê½Òѱ»É¾³ý¡£¡£ ¡£¡£¡£¡£¡£¡£PixPirate ÊÇÒ»ÖÖÐ嵀 Android ¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬ÓÉ Cleafy TIR ÍŶÓÉϸöÔ³õ´Î¼Í¼£¬£¬£¬ £¬£¬£¬£¬Õë¶ÔÀ­¶¡ÃÀÖÞÒøÐÓ×£¡£ ¡£¡£¡£¡£¡£¡£Ö»¹Ü Cleafy Ö¸³öÊÇÒ»¸öµ¥¶ÀµÄÏÂÔØÀûÓ÷¨Ê½Æô¶¯Á˸öñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬µ«¸Ã»ã±¨²¢Î´Éî¿Ì̽ÌÔìä´´Ðµİµ²Ø»òÓÆ¾Ã»úÔ죬£¬£¬ £¬£¬£¬£¬»òÕßÕâЩ»úÔìÊÇ×î½ü²ÅÒýÈëµÄ¡£¡£ ¡£¡£¡£¡£¡£¡£IBM µÄÒ»·Ýл㱨ڹÊÍ˵£¬£¬£¬ £¬£¬£¬£¬Óë¶ñÒâÈí¼þÊÔͼ°µ²ØÆäͼ±êµÄ³ß¶ÈÕ½Êõ£¨ÔÚ Android 9 ¼°ÒÔϰ汾ÖпÉÄÜ´æÔÚÕâÖÖÕ½Êõ£©Ïà·´£¬£¬£¬ £¬£¬£¬£¬PixPirate ²»Ê¹ÓÃÆô¶¯Æ÷ͼ±ê¡£¡£ ¡£¡£¡£¡£¡£¡£ÕâʹµÃ¶ñÒâÈí¼þ¿ÉÄÜÔÚËùÓÐ×îÐ嵀 Android °æ±¾£¨×î¸ß°æ±¾ 14£©ÖÐά³Ö°µ²Ø×´Ì¬¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/pixpirate-android-malware-uses-new-tactic-to-hide-on-phones/


5. ChatGPT ²å¼þ·ì϶¿ÉÄܶ³öÓû§ÕÊ»§Êý¾Ý


3ÔÂ13ÈÕ£¬£¬£¬ £¬£¬£¬£¬API °²È«¹«Ë¾ Salt Security ¶Ô ChatGPT ²å¼þ½øÐÐÁË·ÖÎö£¬£¬£¬ £¬£¬£¬£¬·¢ÏÖÁ˶àÖÖÀàÐ͵ķì϶£¬£¬£¬ £¬£¬£¬£¬ÕâЩ·ì϶¿ÉÄܱ»ÀûÓÃÀ´»ñȡDZÔÚµÄÃô¸ÐÊý¾Ý²¢ÊÕÊܵÚÈý·½ÍøÕ¾ÉϵÄÕÊ»§¡£¡£ ¡£¡£¡£¡£¡£¡£ChatGPT ²å¼þʹÓû§¿ÉÄܽӼû×îÐÂÐÅÏ¢£¨¶ø²»ÊÇ̸Ìì»úеÈËѵÁ·Ê±Ê¹ÓõÄÏà¶Ô½Ï¾ÉµÄÊý¾Ý£©£¬£¬£¬ £¬£¬£¬£¬ÒÔ¼°½« ChatGPT ÓëµÚÈý·½·þÎñ¼¯³É¡£¡£ ¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬ £¬£¬£¬£¬²å¼þÄܹ»ÔÊÐíÓû§ÓëÆä GitHub ºÍ Google Drive ÕÊ»§½øÐн»»¥¡£¡£ ¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬ £¬£¬£¬£¬µ±Ê¹Óòå¼þʱ£¬£¬£¬ £¬£¬£¬£¬ChatGPT ±ØÒª»ñµÃȨÏÞÄÜÁ¦½«Óû§µÄÊý¾Ý·¢Ë͵½Óë¸Ã²å¼þ¹ØÁªµÄÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬²¢ÇҸòå¼þ¿ÉÄܱØÒª½Ó¼ûÓëÆä½»»¥µÄ·þÎñÉϵÄÓû§ÕÊ»§¡£¡£ ¡£¡£¡£¡£¡£¡£ 


https://www.securityweek.com/chatgpt-plugin-vulnerabilities-exposed-data-accounts/


6. Á÷ýÌ幫˾ Roku³¬¹ý15000 ¸öÕË»§ÐÅϢй¶


3ÔÂ13ÈÕ£¬£¬£¬ £¬£¬£¬£¬Á÷ýÌ幫˾ Roku й©£¬£¬£¬ £¬£¬£¬£¬³¬¹ý 15,000 ¸ö¿Í»§µÄÕÊ»§Òò²»ÓйØÊý¾Ýй¶¶ø±»ÇÔÈ¡µÄµÇ¼ʹ´¦Ôâµ½ºÚ¿Í¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£¡£RokuÔÚÏòÃåÒòÖݺͼÓÀû¸£ÄáÑÇÖÝ×ܼì²ì³¤·¢³öµÄÊý¾Ýй¶֪ͨÖаµÊ¾£¬£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÔÚ´Ó 2023 Äê 12 Ô 28 ÈÕ³ÖÐøµ½ 2024 Äê 2 Ô 21 ÈյĻÖнӼûÁË 15,363 ÃûÃÀ¹ú¾ÓÃñµÄÕË»§¡£¡£ ¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷Ö®ËùÒÔÓÐЧ£¬£¬£¬ £¬£¬£¬£¬ÊÇÓÉÓÚһЩ Roku ÕÊ»§ËùÓÐÕßÃýÎóµØÔÚ Roku ÉÏʹÓÃÁËÓë¶à¸öÆäËûÍøÕ¾Ò»ÑùµÄÃÜÂë¡£¡£ ¡£¡£¡£¡£¡£¡£ÕâΪÄÇЩÒѾ­½Ó´¥¹ý´ÓǰÊý¾Ýй¶µÄÈËÌṩÁËÒ»ÖÖµ¥Ò»µÄ²½ÖèÀ´´³Èë Roku ÕÊ»§²¢Ëø¶¨ÕæÕýµÄÓû§¡£¡£ ¡£¡£¡£¡£¡£¡£Roku Ðû³Æ£¬£¬£¬ £¬£¬£¬£¬½Ó¼ûÊÜÓ°ÏìµÄ Roku ÕÊ»§²»ÔÊÐíºÚ¿Í½Ó¼ûÉç»á°²È«ºÅÂ롢ȫ¶î¸¶¿îÕʺ𢵮ÉúÈÕÆÚ»òÆäËûÀàËÆµÄÃô¸ÐÓ×ÎÒÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bitdefender.com/blog/hotforsecurity/hackers-target-roku-15-000-accounts-compromised-in-data-breach/