Vultur ÒøÐжñÒâÈí¼þαװ³É McAfee Security Ó¦ÓóÌÐò

Ðû²¼Ê±¼ä 2024-04-01
1. Vultur ÒøÐжñÒâÈí¼þαװ³É McAfee Security Ó¦ÓóÌÐò


3ÔÂ30ÈÕ £¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷ÁË Android °æ Vultur ÒøÐÐľÂíµÄа汾 £¬ÆäÖаüÀ¨¸üÏȽøµÄÔ¶³Ì¿ØÖƹ¦Ð§ºÍË¢ÐµĹæ±Ü»úÖÆ ¡£Ñо¿Ö°Ô±ÓÚ 2021 Äê 3 ÔÂÊ״μͼÁ˸öñÒâÈí¼þ £¬²¢ÔÚ 2022 Äêµ×·¢Ã÷¸Ã¶ñÒâÈí¼þͨ¹ýÖ²ÈëÓ¦ÓóÌÐòÔÚ Google Play ÉÏÈö²¥ ¡£2023 Äêµ× £¬Òƶ¯Ç徲ƽ̨ Zimperium ½« Vultur ÁÐÈëÄê¶ÈÊ®´ó×î»îÔ¾ÒøÐÐľÂíÖ®ÁÐ £¬²¢Ö¸³öÆäÖÐ 9 ¸ö±äÖÖÕë¶Ô 15 ¸ö¹ú¼Ò/µØÇøµÄ 122 ¸öÒøÐÐÓ¦ÓóÌÐò ¡£Ò»ÖÖеġ¢¸ü¾ß¹æ±ÜÐ﵀ Vultur °æ±¾Í¨¹ýÒ»ÖÖ»ìÏý¹¥»÷Èö²¥¸øÊܺ¦Õß £¬ÕâÖÖ¹¥»÷ÒÀÀµÓÚ¶ÌÐÅ´¹ÂÚ£¨¶ÌÐÅÍøÂç´¹ÂÚ£©ºÍµç»° £¬ÓÕÆ­Ä¿µÄ×°ÖÃÒ»¸ö°æ±¾µÄ Vultur ¡£Î±×°³É McAfee Security Ó¦ÓóÌÐòµÄ¶ñÒâÈí¼þ ¡£Vultur ×îеÄѬȾÁ´Ê¼ÓÚÊܺ¦ÕßÊÕµ½Ò»Ìõ¶ÌÐÅ £¬ÌáÐÑδ¾­ÊÚȨµÄÉúÒâ £¬²¢Ö¸Ê¾²¦´òÌṩµÄºÅÂë×·ÇóÖ¸µ¼ ¡£Õ©Æ­Õß½ÓÌýµç»° £¬Ëµ·þÊܺ¦Õß·­¿ªµÚ¶þÌõ¶ÌÐÅ·¢Ë͵ÄÁ´½Ó £¬¸ÃÁ´½ÓÖ¸ÏòÌṩ McAfee Security Ó¦ÓóÌÐòÐ޸İ汾µÄÍøÕ¾ ¡£


https://www.bleepingcomputer.com/news/security/vultur-banking-malware-for-android-poses-as-mcafee-security-app/


2. PyPI ÔÝÍ£ÐÂÓû§×¢²áÒÔ×èÖ¹¶ñÒâÈí¼þ»î¶¯


3ÔÂ28ÈÕ £¬PyPI ÊÇ Python ÏîÄ¿µÄË÷Òý £¬¿É×ÊÖú¿ª·¢Ö°Ô±²éÕÒºÍ×°Öà Python °ü ¡£¸Ã´æ´¢¿âÓµÓÐÊýǧ¸ö¿ÉÓÃÈí¼þ°ü £¬¹ØÓÚÍþвÐÐΪÕßÀ´ËµÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÄ¿µÄ £¬ËûÃǾ­³£ÉÏ´«Æ´Ð´¹ýʧ»òαÔìµÄÈí¼þ°üÀ´Î£º¦Èí¼þ¿ª·¢Ö°Ô±ºÍDZÔڵũӦÁ´¹¥»÷ ¡£´ËÀà»î¶¯ÆÈʹ PyPI ¹ÜÀíÔ±½ñÌìÔçЩʱ¼äÐû²¼ÔÝÍ£ËùÓÐÐÂÓû§×¢²á £¬ÒÔïÔÌ­¶ñÒâ»î¶¯ ¡£Checkmarx µÄÒ»·Ý±¨¸æÏÔʾ £¬ÍþвÐÐΪÕß×òÌì×îÏÈÏò PyPI 365 ÉÏ´«¾ßÓÐÄ£ÄâÕýµ±ÏîÄ¿Ãû³ÆµÄÈí¼þ°ü ¡£ÕâЩÈí¼þ°üµÄ¡°setup.py¡±ÎļþÖаüÀ¨¶ñÒâ´úÂë £¬¸Ã´úÂëÔÚ×°ÖÃʱִÐÐ £¬ÊÔͼ´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÌØÁíÍâÓÐÓøºÔØ ¡£ÎªÁËÌӱܼì²â £¬¶ñÒâ´úÂëʹÓà Fernet Ä£¿é¾ÙÐмÓÃÜ £¬²¢ÔÚÐèҪʱ¶¯Ì¬¹¹½¨Ô¶³Ì×ÊÔ´µÄ URL ¡£×îÖÕµÄÓÐÓøºÔØÊÇÒ»¸ö¾ßÓг¤ÆÚÐÔ¹¦Ð§µÄÐÅÏ¢ÇÔÈ¡³ÌÐò £¬ÆäÄ¿µÄÊÇ´æ´¢ÔÚÍøÂçä¯ÀÀÆ÷ÖеÄÊý¾Ý £¬ÀýÈçµÇ¼ÃÜÂë¡¢cookie ºÍ¼ÓÃÜÇ®±ÒµÈ ¡£


https://www.bleepingcomputer.com/news/security/pypi-suspends-new-user-registration-to-block-malware-campaign/?&web_view=true


3. Ó¢¹úÈûÀ­·Æ¶ûµÂºËµçÕ¾ÒòÍøÂçÇå¾²¹ÊÕϱ»ÆðËß


3ÔÂ29ÈÕ £¬Ó¢¹ú×ÔÁ¦ºËÇå¾²î¿Ïµ»ú¹¹Ðû²¼ £¬½«ÆðËß¹ÜÀíÈûÀ­·Æ¶ûµÂºËµçÕ¾µÄ¹«Ë¾ £¬Ö¸¿ØÆä¡°ÔÚ 2019 ÄêÖÁ 2023 ÄêÍ·µÄËÄÄêʱ´úÉæÏÓÐÅÏ¢ÊÖÒÕÇå¾²·¸·¨¡± ¡£ÏÖÔÚÉв»ÇåÎú¹úÓÐÈûÀ­·Æ¶ûµÂÓÐÏÞ¹«Ë¾µÄ¸ß¼¶¹ÜÀíÖ°Ô±ÊÇ·ñÅöÃæÁÙÖ¸¿Ø ¡£Æ¾Ö¤2003 Äê¡¶ºË¹¤ÒµÇå¾²ÌõÀý¡· £¬±»ÖÎ×ïµÄСÎÒ˽¼Ò¿ÉÃæÁÙ×î¸ßÁ½ÄêµÄî¿Ïµ ¡£ÕýÈçÓ¢¹úÊ×ϯºË¼à²ìԱȥÄêµÄÄê¶È±¨¸æËùÅû¶µÄÄÇÑù £¬ÈûÀ­·Æ¶ûµÂ´ËǰÒòÆäÍøÂçÇ徲ȱÏݶø³ÉΪî¿Ïµ»ú¹¹ÔöÇ¿¹Ø×¢µÄ½¹µã ¡£Óë´Ëͬʱ £¬ÔÚÓ¢¹úÔËÓªÊý×ùºËµçÕ¾µÄ·¨¹úµçÁ¦¹«Ë¾Ò²Êܵ½ÁËÀàËÆ²½·¥ ¡£ÕýÈçÓ¢¹úÃñÓúËÍøÂçÇå¾²Õ½ÂÔËùÊö £¬¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ (NCSC) ÍþвÆÀ¹ÀÖÒÑÔ³Æ £¬ÀÕË÷Èí¼þ¡°ÏÕЩһ¶¨ÊÇ×îÓпÉÄܵįÆËðÐÔÍþв¡± ¡£Ö»¹Ü¹¤ÒµÏµÍ³Éè¼ÆÓжà¸ö¹ÊÕÏÇå¾²×°ÖÃÀ´±ÜÃâ·ÅÉäÐÔÊÂ¹Ê £¬µ«¶ÔºËµçվʹÓÃµÄ IT ϵͳµÄÀÕË÷Èí¼þ¹¥»÷¿ÉÄÜ»áÈÅÂÒÆäÔËÐÐ ¡£ÈûÀ­·Æ¶ûµÂµÄºË·´Ó¦¶ÑÓÚ 2003 Äê¹Ø±Õ £¬µ«Õâ¸öÖØ´óµÄ×ÛºÏÌåÈÔÈ»ÊÇÅ·ÖÞ×î´óµÄºËµçÕ¾ £¬ONR ½«ÆäÐÎòΪ¡°ÌìÏÂÉÏ×îÖØ´ó¡¢×îΣÏյĺ˵çÕ¾Ö®Ò»¡± ¡£


https://therecord.media/sellafield-site-prosecution-nuclear-facility-cybersecurity


4. Õë¶ÔÓ¡¶È¹ú·ÀºÍÄÜÔ´²¿·ÖµÄ´¹ÂÚ¹¥»÷


3ÔÂ29ÈÕ £¬EclecticIQ ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÏîÃûΪ¡°Operation FlightNight¡±µÄÍøÂçÌØ¹¤»î¶¯ £¬Ä¿µÄÊÇÓ¡¶ÈÕþ¸®ÊµÌåºÍÄÜÔ´¹«Ë¾ ¡£¹¥»÷Õß¿ÉÄÜÊÇÓɹú¼Ò×ÊÖúµÄ £¬ËûÃÇʹÓÿªÔ´ÐÅÏ¢ÇÔÈ¡³ÌÐò HackBrowserData µÄÐ޸İæÔ­À´ÇÔÈ¡Ãô¸ÐÊý¾Ý ¡£EclecticIQ ·¢Ã÷¹¥»÷ÕßʹÓÃÊ¢ÐеÄͨѶƽ̨ Slack ͨµÀ×÷ÎªÉøÍ¸µã ¡£¹¥»÷ÕßÀÖ³ÉÉøÍ¸µ½¶à¸öÈÏÕæÍ¨Ñ¶¡¢IT ºÍ¹ú·ÀµÄÕþ¸®»ú¹¹ ¡£±ðµÄ £¬Ë½ÓªÄÜÔ´¹«Ë¾Ò²Êܵ½Ë𺦠£¬ÓйزÆÎñÎļþ¡¢Ô±¹¤ÐÅÏ¢¡¢ÉõÖÁʯÓͺÍ×ÔÈ»Æø×ê̽»î¶¯µÄÏêϸÐÅÏ¢±»µÁ ¡£¸ß´ï 8.81 GB µÄÊý¾Ý±»Ð¹Â¶ £¬¿ÉÄÜÓÐÖúÓÚδÀ´µÄÈëÇÖ ¡£¹¥»÷ÕßʹÓÃÁËÒ»ÖÖ¼¼ÇÉÀ´ÈÃÊܺ¦Õß×°ÖöñÒâÈí¼þ ¡£ËûÃÇ·¢ËÍαװ³ÉÓ¡¶È¿Õ¾üÔ¼ÇëµÄµç×ÓÓʼþ ¡£ÕâЩµç×ÓÓʼþ°üÀ¨Ò»¸ö ISO Îļþ £¬¸ÃÎļþËÆºõÊÇÎÞº¦µÄ´æµµ ¡£µ±Êܺ¦Õß·­¿ªISOÎļþʱ £¬ËüÏÖʵÉÏÆô¶¯ÁËÒ»¸öαװ³ÉPDFÎĵµµÄ¿ì½Ý·½·¨Îļþ£¨LNK£©  ¡£µ¥»÷ LNK Îļþ»áÔÚ²»Öª²»¾õÖ줻î¶ñÒâÈí¼þ ¡£È»ºó £¬¶ñÒâÈí¼þ»áÇÔÈ¡ÉñÃØÎĵµ¡¢Ë½È˵ç×ÓÓʼþ»ººÍ´æµÄÍøÂçä¯ÀÀÆ÷Êý¾Ý ¡£ 


https://gbhackers.com/weaponized-air-force-invitation-pdf-indian-defense-energy/


5. Linux Îó²î¿ÉÄܵ¼ÖÂÓû§ÃÜÂëй¶ºÍ¼ôÌù°åÐ®ÖÆ


3ÔÂ28ÈÕ £¬Ñо¿Ö°Ô±·¢Ã÷Linux ²Ù×÷ϵͳÖеÄutil-linuxÈí¼þ°üµÄwallÏÂÁîÖб£´æÎó²î £¬¿ÉÄܵ¼Ö·ÇÌØÈ¨¹¥»÷ÕßÇÔÈ¡ÃÜÂë»ò¸ü¸ÄÊܺ¦ÕߵļôÌù°å ¡£¸ÃÇå¾²ÎÊÌâ±»×·×ÙΪCVE-2024-28085 £¬±»³ÆÎª WallEscape £¬²¢ÇÒÔÚÒÑÍù 11 ÄêÖÐÒ»Ö±±£´æÓÚ¸ÃÈí¼þ°üµÄÿ¸ö°æ±¾ÖÐ £¬Ö±µ½×î½üÐû²¼µÄ2.40 ¡£Ö»¹Ü¸ÃÎó²îÊǹ¥»÷ÕßÔõÑùÓÕÆ­Óû§Ìṩ¹ÜÀíÔ±ÃÜÂëµÄÒ»¸öÓÐȤʾÀý £¬µ«Ê¹ÓøÃÎó²î¿ÉÄܽöÏÞÓÚijЩÇéÐÎ ¡£¹¥»÷ÕßÐèÒª»á¼ûÒѾ­Óжà¸öÓû§Í¨¹ýÖÕ¶ËͬʱÅþÁ¬µÄ Linux ·þÎñÆ÷ ¡£WallEscape Ó°Ïì¡°wall¡±ÏÂÁî £¬¸ÃÏÂÁîͨ³£ÔÚ Linux ϵͳÖÐÓÃÓÚÏòµÇ¼µ½Í³Ò»ÏµÍ³£¨ÀýÈç·þÎñÆ÷£©µÄËùÓÐÓû§µÄÖն˹㲥ÐÂÎÅ ¡£ÓÉÓÚÔÚͨ¹ýÏÂÁîÐвÎÊý´¦Öóͷ£ÊäÈëʱδ׼ȷ¹ýÂËתÒåÐòÁÐ £¬Òò´Ë·ÇÌØÈ¨Óû§¿ÉÒÔʹÓÃתÒå¿ØÖÆ×Ö·ûʹÓøÃÎó²îÔÚÆäËûÓû§µÄÖÕ¶ËÉϽ¨ÉèÐéαµÄ SUDO ÌáÐÑ·û £¬²¢ÓÕÆ­ËûÃÇÊäÈë¹ÜÀíÔ±ÃÜÂë ¡£Ñо¿Ö°Ô±Ö¸³ö £¬ÕâÁ½ÖÖÇéÐÎÔÚ Ubuntu 22.04 LTS (Jammy Jellyfish) ºÍ Debian 12.5 (Bookworm) É϶¼±£´æ £¬µ«ÔÚ CentOS Éϲ»±£´æ ¡£


https://www.bleepingcomputer.com/news/security/decade-old-linux-wall-bug-helps-make-fake-sudo-prompts-steal-passwords/?&web_view=true


6. ÂíÈøÖîÈûÖÝ¿µ½¡°ü¹Ü¹«Ë¾Êý¾Ýй¶ӰÏì 280 ÍòÈË


3ÔÂ29ÈÕ £¬ÂíÈøÖîÈûÖݵڶþ´ó¿µ½¡°ü¹Ü¹«Ë¾ Point32Health ͸¶ £¬Áè¼Ý 280 ÍòÈ˵ÄСÎÒ˽¼ÒÐÅÏ¢ÔÚ2023 Äê 4 ÔµÄÀÕË÷Èí¼þ¹¥»÷Öб»µÁ ¡£´Ë´Î¹¥»÷Ó°ÏìÁËÓë Point32Health µÄ¹þ·ð Pilgrim Ò½ÁƱ£½¡Æ·ÅÆÏà¹ØµÄϵͳ £¬°üÀ¨Îª¹þ·ð Pilgrim Ò½ÁƱ£½¡ÉÌÒµºÍ Medicare Advantage Stride ÍýÏëÌṩ·þÎñµÄϵͳ £¬ÒÔ¼°¡°ÓÃÓÚΪ»áÔ±¡¢ÕË»§¡¢¾­¼ÍÈ˺ÍÌṩÉÌÌṩ·þÎñ¡±µÄϵͳ ¡£ÊӲ췢Ã÷ £¬Óм£ÏóÅú×¢Êý¾ÝÔÚ 2023 Äê 3 Ô 28 ÈÕÖÁ 2023 Äê 4 Ô 17 ÈÕʱ´ú´Ó¹þ·ð Pilgrim ϵͳÖб»¸´ÖƺͻñÈ¡ ¡£±»µÁÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢Éç»áÇå¾²ºÅÂë¡¢¿µ½¡°ü¹ÜÕË»§ÐÅÏ¢¡¢²ÆÎñÕË»§ÐÅÏ¢¡¢²¡Ê·¡¢Õï¶ÏºÍÖÎÁÆÐÅÏ¢µÈ ¡£


https://www.securityweek.com/massachusetts-health-insurer-data-breach-impacts-2-8-million/