¼Ùð°ÍÁÖµ±¾Ö Android ÀûÓ÷¨Ê½ÇÔÈ¡Êý¾ÝÓÃÓÚÚ¿Æ­

°ä²¼¹¦·ò 2024-06-04
1. ¼Ùð°ÍÁÖµ±¾Ö Android ÀûÓ÷¨Ê½ÇÔÈ¡Êý¾ÝÓÃÓÚÚ¿Æ­


6ÔÂ2ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬ºÜ¶àµ±¾Ö»ú¹¹¶¼ÔÚÏßÌṩ·þÎñ£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ·½±ã¹«Ãñ¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬£¬£¬ÈôÊÇÄܹ»Í¨¹ýÒÆ¶¯ÀûÓ÷¨Ê½ÌṩÕâÏî·þÎñ£¬ £¬£¬£¬£¬£¬£¬£¬½«¼«¶È·½±ãºÍ±ã½Ý¡£¡£¡£¡£¡£µ«ÊÇ£¬ £¬£¬£¬£¬£¬£¬£¬µ±¶ñÒâÈí¼þ¼Ù×°³ÉÕâЩ·þÎñʱ»á²úÉúʲô£¿ £¿£¿£¿£¿McAfee ÒÆ¶¯×êÑÐÍŶӷ¢ÏÖÁËÒ»¿î¼Ù×°³É°ÍÁÖµ±¾Ö»ú¹¹·þÎñµÄ InfoStealer Android ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¼Ù×°³É°ÍÁֵĹٷ½ÀûÓ÷¨Ê½£¬ £¬£¬£¬£¬£¬£¬£¬²¢Ðû´«Óû§Äܹ»ÔÚÊÖ»úÉϸüлòÉêÇë¼ÝÊ»ÅÆÕÕ¡¢Ç©Ö¤ºÍÉí·ÝÖ¤¡£¡£¡£¡£¡£±»¸æ°×ºýŪµÄÓû§»á¾ø²»ÓÌÔ¥µØ»ñµÃÕâЩ·þÎñËùÐèµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£ËüÃÇͨ¹ý¸÷À෽ʽ½Ó´¥Óû§£¬ £¬£¬£¬£¬£¬£¬£¬Ô̺¬ Facebook ºÍ¶ÌÐÅ¡£¡£¡£¡£¡£²»ÊìϤÕâЩ¹¥»÷µÄÓû§ºÜÈÝÒ×·¸Ï·¢ËÍÓ×ÎÒÐÅÏ¢µÄÃýÎ󡣡£¡£¡£¡£°ÍÁÖÓÐÒ»¸öµ±¾Ö»ú¹¹£¬ £¬£¬£¬£¬£¬£¬£¬ÃûΪÀͶ¯Á¦Êг¡¼à¹Ü¾Ö (LMRA)¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔÚÓÉÀ͹¤²¿³¤µ£ÈÎÖ÷ϯµÄ¶­Ê»áÁ쵼ϣ¬ £¬£¬£¬£¬£¬£¬£¬Õ¼ÓÐÆëÈ«µÄ²ÆÕþºÍÐÐÕþ¶ÀÁ¢ÐÔ¡£¡£¡£¡£¡£ËûÃÇÌṩ¸÷ÀàÒÆ¶¯·þÎñ£¬ £¬£¬£¬£¬£¬£¬£¬´óÎÞÊýÀûÓ÷¨Ê½Ö»ÌṩһÏî·þÎñ¡£¡£¡£¡£¡£È»¶ø£¬ £¬£¬£¬£¬£¬£¬£¬Õâ¸ö¼ÙðÀûÓ÷¨Ê½È´Ðû´«Ìṩ¶àÏî·þÎñ¡£¡£¡£¡£¡£³ýÁË×î³£¼ûµÄ¼ÙÒâ LMRA µÄ¼ÙðÀûÓñí£¬ £¬£¬£¬£¬£¬£¬£¬»¹Óи÷Àà¼ÙðÀûÓ㬠£¬£¬£¬£¬£¬£¬£¬Ô̺¬°ÍÁֺͿÆÍþÌØÒøÐÐ (BBK)¡¢°ÍÁÖ½ðÈڿƼ¼¹«Ë¾ BenefitPay£¬ £¬£¬£¬£¬£¬£¬£¬ÉõÖÁ»¹ÓмÙ×°Óë±ÈÌØ±Ò»ò´û¿îÓйصÄÀûÓᣡ£¡£¡£¡£ÕâЩÀûÓÃʹÓÃÓë LMRA ¼ÙðÀûÓÃÒ»ÑùµÄ¼¼ÊõÀ´ÇÔÈ¡Ó×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/


2. SHINYHUNTERSÔÚÏúÊÛ3000Íòɣ̹µÂÒøÐпͻ§µÄÊý¾Ý


6ÔÂ2ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬³ôÃûÔ¶ÑïµÄÍþвÐÐΪÕß ShinyHunters ÔÚÏúÊ۾ݳƴÓɣ̹µÂÒøÐÐÇÔÈ¡µÄ´óÁ¿Êý¾Ý¡£¡£¡£¡£¡£ShinyHunters Ðû³ÆÇÔÈ¡ÁË 3000 Íò¿Í»§¡¢Ô±¹¤ºÍÒøÐÐÕË»§Êý¾Ý¡£¡£¡£¡£¡£5 ÔÂÖÐÑ®£¬ £¬£¬£¬£¬£¬£¬£¬Î÷°àÑÀ½ðÈÚ»ú¹¹É£Ì¹µÂÒøÐÐÅû¶ÁËÒ»Â·Éæ¼°µÚÈý·½ÌṩÉ̵ÄÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÖÇÀû¡¢Î÷°àÑÀºÍÎÚÀ­¹çµÄ¿Í»§¡£¡£¡£¡£¡£¸ÃÒøÐз¢ÏÖµÚÈý·½ÌṩÉÌÍÐ¹ÜµÄÆäÖÐÒ»¸öÊý¾Ý¿âÔ⵽δ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¸Ã¹«Ë¾°ä·¢Á¢¼´²ÉÈ¡´ëÊ©½ÚÔìÊÂÎñ¡£¡£¡£¡£¡£¸Ã¹«Ë¾×èÖ¹Á˶ÔÊý¾Ý¿âµÄÈëÇÖ½Ó¼û£¬ £¬£¬£¬£¬£¬£¬£¬²¢³ÉÁ¢Á˶î±íµÄڲƭԤ·À½ÚÔì´ëÊ©À´± £» £»£» £»£»£»£»¤ÊÜÓ°ÏìµÄ¿Í»§¡£¡£¡£¡£¡£±»µÁÊý¾Ý¿âÔ̺¬ËùÓÐÏÖÈκͲ¿ÃÅǰÈÎÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÒøÐÐÖ¸³ö£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â²»´æ´¢ÂòÂôÊý¾Ý¡¢ÍøÉÏÒøÐоßÌåÐÅÏ¢¡¢ÃÜÂë»òÆäËûÔÊÐíijÈ˽øÐÐÂòÂôµÄÊý¾Ý¡£¡£¡£¡£¡£¸Ã½ðÈÚ»ú¹¹ÉÐδÌṩÕâ´ÎÊÂÎñµÄ¼¼Êõϸ½Ú»òй¶µÄÊý¾ÝÖÖÀà¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶àÈËÊܵ½Ó°Ïì¡£¡£¡£¡£¡£ShinyHunters Ðû³Æ Ticketmaster Ôâµ½ºÚ¿Í¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÒÔ 50 ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛ 1.3 TB µÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ 5.6 ÒÚ¿Í»§µÄÆëÈ«¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£±»µÁÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÃÅÆ±ÏúÊۺͶ©µ¥¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£


https://securityaffairs.com/163956/data-breach/shinyhunters-claims-santander-breach.html


3. CISA ÖÒ¸æ³Æ Linux ÌØÈ¨ÌáÉý·ì϶¿ÉÄܱ»»ý¼«ÀûÓÃ


6ÔÂ2ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) ÔÚÆäÒÑÖªÀûÓ÷ì϶ (KEV) Ŀ¼ÖÐÔö³¤ÁËÁ½¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ Linux ÄÚºËȨÏÞÌáÉý·ì϶¡£¡£¡£¡£¡£¸Ã¸ßÑϳÁÐÔ·ì϶ ( CVE-2024-1086)ÓÚ 2024 Äê 1 Ô 31 ÈÕ³õ´ÎÅû¶£¬ £¬£¬£¬£¬£¬£¬£¬ÊÇ netfilter£ºnf_tables ×é¼þÖеĿªÊͺóʹÓÃÎÊÌ⣬ £¬£¬£¬£¬£¬£¬£¬µ«×îÔçÊÇÔÚ 2014 Äê 2 ÔµÄÒ»´ÎÌá½»ÖÐÒýÈëµÄ¡£¡£¡£¡£¡£Netfilter ÊÇ Linux ÄÚºËÌṩµÄÒ»¸ö¿ò¼Ü£¬ £¬£¬£¬£¬£¬£¬£¬ÔÊÐí¸÷ÀàÓëÍøÂçÓйصIJÙ×÷£¬ £¬£¬£¬£¬£¬£¬£¬ÀýÈçÊý¾Ý°ü¹ýÂË¡¢ÍøÂçµØÖ·×ª»» (NAT) ºÍÊý¾Ý°üÅú¸Ä¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚ 'nft_verdict_init()' º¯ÊýÔÊÐí½«ÕýÖµÓÃ×÷¹³×ÓÅоöÖеÄɾ³ýÃýÎó£¬ £¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö 'nf_hook_slow()' º¯ÊýÔÚ NF_DROP ·¢³öÀàËÆÓÚ NF_ACCEPT µÄɾ³ýÃýÎóʱִÐÐË«³Á¿ªÊÍ¡£¡£¡£¡£¡£ÀûÓà CVE-2024-1086 ¿ÉÈÃÓµÓб¾µØ½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÔÚÖ¸±êϵͳÉÏʵÏÖȨÏÞÌáÉý£¬ £¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜ»ñµÃ root ¼¶½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-linux-privilege-elevation-flaw/


4. Ðéαä¯ÀÀÆ÷¸üлᴫ²¼BitRATºÍLumma Stealer¶ñÒâÈí¼þ


6ÔÂ3ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬ÐéαµÄÍøÂçä¯ÀÀÆ÷¸üб»ÓÃÓÚ´«²¼Ô¶³Ì½Ó¼ûľÂí (RAT) ºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬£¬ÀýÈçBitRATºÍLumma Stealer£¨±ðÃû LummaC2£©¡£¡£¡£¡£¡£µ±Ç±ÔÚÖ¸±ê½Ó¼ûÒ»¸ö´øÓÐÏÝÚåµÄÍøÕ¾Ê±£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Á´¾ÍÆðÍ·ÁË£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾Ô̺¬Ö¼ÔÚ½«Óû§³Á¶¨Ïòµ½Ðéαä¯ÀÀÆ÷¸üÐÂÒ³Ãæ£¨¡°chatgpt-app[.]cloud¡±£©µÄ JavaScript ´úÂë¡£¡£¡£¡£¡£³Á¶¨ÏòµÄÍøÒ³Ç¶ÈëÁËÖ¸Ïò ZIP ´æµµÎļþ£¨¡°Update.zip¡±£©µÄÏÂÔØÁ´½Ó£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÍйÜÔÚ Discord Éϲ¢×Ô¶¯ÏÂÔØµ½Êܺ¦ÕßµÄÉ豸¡£¡£¡£¡£¡£ÖµµÃÖ¸³öµÄÊÇ£¬ £¬£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßʱʱʹÓà Discord ×÷Ϊ¹¥»÷ý½é£¬ £¬£¬£¬£¬£¬£¬£¬ Bitdefender×î½üµÄ·ÖÎö·¢ÏÖ£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚ´ÓǰÁù¸öÔÂÖУ¬ £¬£¬£¬£¬£¬£¬£¬Óг¬¹ý 50,000 ¸öΣÏÕÁ´½Ó´«²¼¶ñÒâÈí¼þ¡¢ÍøÂç´¹µö»î¶¯ºÍÀ¬»øÓʼþ¡£¡£¡£¡£¡£ZIP ´æµµÎļþÖдæÔÚÁíÒ»¸ö JavaScript Îļþ£¨¡°Update.js¡±£©£¬ £¬£¬£¬£¬£¬£¬£¬Ëü»á´¥·¢ PowerShell ¾ç±¾µÄÖ´ÐУ¬ £¬£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÕƹܴÓÔ¶³Ì·þÎñÆ÷ÒÔ PNG ͼÏñÎļþµÄ´ó¾Ö¼ìË÷ÆäËûÓÐЧ¸ºÔØ£¬ £¬£¬£¬£¬£¬£¬£¬Ô̺¬ BitRAT ºÍ Lumma Stealer¡£¡£¡£¡£¡£


https://thehackernews.com/2024/06/beware-fake-browser-updates-deliver.html


5. ¾¯·½µ·»ÙµÁ°æµçÊÓÁ÷ýÌåÍøÂçÒѾ­»ñÀû570ÍòÃÀÔª


6ÔÂ3ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬Î÷°àÑÀ¾¯·½µ·»ÙÁËÒ»¸ö·¸·¨Ã½ÌåÄÚÈÝ´«²¼ÍøÂ磬 £¬£¬£¬£¬£¬£¬£¬¸ÃÍøÂç×Ô 2015 ÄêÆðÍ·ÔËÓªÒÔÀ´ÒÑ»ñÀû³¬¹ý 570 ÍòÃÀÔª¡£¡£¡£¡£¡£¸Ãµ÷²éÓÚ 2022 Äê 11 ÔÂÆðÍ·£¬ £¬£¬£¬£¬£¬£¬£¬Æäʱ´´ÒâÓëÓéÀÖÁªÃË (ACE) Ìá½»ÁËÒ»·ÝͶËߣ¬ £¬£¬£¬£¬£¬£¬£¬¾Ù±¨Á½¸öÍøÒ³¼Óº¦ÁË֪ʶ²úȨ¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾ÍйÜ×Å·¸·¨ IPTV ·þÎñ¡°TVMucho¡±£¨Ò²³ÆÎª¡°Teeveeing¡±£©£¬ £¬£¬£¬£¬£¬£¬£¬¾Ý ACE ³Æ£¬ £¬£¬£¬£¬£¬£¬£¬¸Ã·þÎñÔÚ 2023 ÄêµÄ½Ó¼ûÁ¿³¬¹ý 400 Íò´Î¡£¡£¡£¡£¡£¾¯·½µ÷²éºó·¢ÏÖ£¬ £¬£¬£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾µÄËùÓÐÕß±³ºóÓÐÒ»¸ö´ó¹æÄ£µÄ IPTV Ðж¯£¬ £¬£¬£¬£¬£¬£¬£¬ÎªÔ¼Äª 14,000 ÃûÓû§Ìṩ 130 ¸ö¹ú¼ÊµçÊÓÆµÂ·ºÍÊýǧ²¿µçÓ°ºÍµçÊÓ¾çµÄ·¸·¨½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¸Ã·þÎñµÄÓû§Æ¾¾ÝÆä¶©Ôĵȼ¶Ö§¸¼û¿Ô 11 ÖÁ 20.5 ÃÀÔª»òÿÄê 97 ÖÁ 182.5 ÃÀÔª£¬ £¬£¬£¬£¬£¬£¬£¬ÕâʹµÃ IPTV ƽ̨ÔËÓªÉÌ×ܹ²»ñÀû 570 ÍòÃÀÔª¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/police-dismantle-pirated-tv-streaming-network-that-made-57-million/


6. Hugging Face ³ÆºÚ¿Í´Ó Spaces ÇÔÈ¡Éí·ÝÑéÖ¤ÁîÅÆ


6ÔÂ2ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬ÈËΪÖÇÄÜÆ½Ì¨ Hugging Face °µÊ¾Æä Spaces ƽ̨Ôâµ½ÈëÇÖ£¬ £¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍµÃÒÔ»ñÈ¡Æä³ÉÔ±µÄÉí·ÝÑéÖ¤»úÃÜ¡£¡£¡£¡£¡£Hugging Face Spaces ÊÇÒ»¸öÓÉÉçÇøÓû§´´½¨ºÍÌá½»µÄ AI ÀûÓ÷¨Ê½¿â£¬ £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÆäËû³ÉÔ±ÑÝʾËüÃÇ¡£¡£¡£¡£¡£Hugging Face °µÊ¾£¬ £¬£¬£¬£¬£¬£¬£¬ËûÃÇÒѾ­³·ÏúÁËй¶»úÃÜÖеÄÉí·ÝÑéÖ¤ÁîÅÆ£¬ £¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýµç×ÓÓʼþ֪ͨÁËÊÜÓ°ÏìµÄÓû§¡£¡£¡£¡£¡£µ«ÊÇ£¬ £¬£¬£¬£¬£¬£¬£¬ËûÃǽ¨ÒéËùÓÐ Hugging Face Spaces Óû§Ë¢ÐÂËûÃǵÄÁîÅÆ²¢Çл»µ½ ϸÁ£¶È½Ó¼ûÁîÅÆ£¬ £¬£¬£¬£¬£¬£¬£¬ÕâʹµÃ×éÖ¯Äܹ»¸üÑϸñµØ½ÚÔìË­ÓÐȨ½Ó¼ûËûÃÇµÄ AI Ä£ÐÍ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÓë±í²¿ÍøÂ簲ȫר¼ÒºÏ×÷µ÷²éÕâ´ÎÎ¥¹æÐÐΪ£¬ £¬£¬£¬£¬£¬£¬£¬²¢Ïò·¨ÂɺÍÊý¾Ý± £» £»£» £»£»£»£»¤»ú¹¹»ã±¨¸ÃÊÂÎñ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ai-platform-hugging-face-says-hackers-stole-auth-tokens-from-spaces/