ÃÀ¹úÔËͨѶÓþ¿¨Ôâ·êµÚÈý·½Êý¾Ýй¶

°ä²¼¹¦·ò 2024-03-06
1. ÃÀ¹úÔËͨѶÓþ¿¨Ôâ·êµÚÈý·½Êý¾Ýй¶


3ÔÂ4ÈÕ  £¬ÃÀ¹úÔËͨÖÒ¸æ¿Í»§  £¬ÔÚÉÌ»§´¦ÖÃÆ÷Ôâµ½ºÚ¿Í¹¥»÷ºó  £¬ÐÅÓþ¿¨ÔÚµÚÈý·½Êý¾Ýй¶Öж³ö¡£¸ÃÊÂÎñ²¢·ÇÓÉÃÀ¹úÔËͨ¿¨µÄÊý¾Ýй¶Ôì³É  £¬¶øÊÇÓÉ´¦ÖÃÃÀ¹úÔËͨ¿¨»áÔ±Êý¾ÝµÄÉ̼Ҵ¦ÖÃÆ÷Ôì³É¡£Õâ´Îй¶µ¼Ö¿ͻ§µÄÃÀ¹úÔËͨ¿¨Õʺš¢ÐÕÃûºÍ¿¨¹ýÆÚÊý¾Ý±»ºÚ¿Í»ñÈ¡¡£Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡¢ÄĸöÉ̼Ҵ¦ÖÃÆ÷Ôâµ½·ÛËéÒÔ¼°¹¥»÷²úÉúµÄ¹¦·ò¡£µ± BleepingComputer ÏòÃÀ¹úÔËͨѯÎÊÓйØÕâ´Îй¶µÄ¸ü¶àÐÅϢʱ  £¬ÎÒÃDZ»·î¸æËûÃDz»»áй©ÆäÒµÎñ¹ØÏµºÍóÒ׺Ï×÷ͬ°éµÄ¾ßÌåÐÅÏ¢  £¬Ä¿Ç°Ò²Ã»Óиü¶àÐÅÏ¢¿É¹©·ÖÏí¡£²»Íâ  £¬ÃÀ¹úÔËͨµÄÈ·°µÊ¾  £¬ËûÃÇÒÑ֪ͨËùÐèµÄ¼à¹Ü»ú¹¹  £¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§·¢³ö¾¯±¨¡£


https://www.bleepingcomputer.com/news/security/american-express-credit-cards-exposed-in-third-party-data-breach/#google_vignette


2. JetBrains TeamCity ÑϳÁȱµã¿ÉÄܵ¼Ö·þÎñÆ÷±»ÊÕÊÜ


3ÔÂ5ÈÕ  £¬JetBrains TeamCity On-Premises Èí¼þÖÐÅû¶ÁËÒ»¶ÔÐµİ²È«·ì϶  £¬ÍþвÐÐΪÕß¿ÉÀûÓÃÕâЩ·ì϶À´½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£ÕâЩȱµã±àºÅΪ CVE-2024-27198£¨CVSS ÆÀ·Ö£º9.8£©ºÍ CVE-2024-27199£¨CVSS ÆÀ·Ö£º7.3£©  £¬ÒÑÔÚ°æ±¾ 2023.11.4 Öеõ½½â¾ö¡£ËüÃÇ»áÓ°Ïì 2023 Äê 11 Ô 3 ÈÕ֮ǰµÄËùÓÐ TeamCity On-Premises °æ±¾¡£JetBrainsÔÚÖÜÒ»°ä²¼µÄ²¼¸æÖаµÊ¾£º¡°ÕâЩ·ì϶¿ÉÄÜʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄÜͨ¹ý HTTP(S) ½Ó¼û TeamCity ·þÎñÆ÷À´ÈƹýÉí·ÝÑéÖ¤²é³­²¢»ñµÃ¶Ô¸Ã TeamCity ·þÎñÆ÷µÄÖÎÀí½ÚÔì¡£¡±TeamCity Cloud Ê·ýÒÑÕë¶ÔÕâÁ½¸öȱµã½øÐÐÁ˽¨²¹¡£ÍøÂ簲ȫ¹«Ë¾ Rapid7 ÓÚ 2024 Äê 2 Ô 20 ÈÕ·¢ÏÖ²¢»ã±¨ÁËÕâЩÎÊÌâ  £¬¸Ã¹«Ë¾°µÊ¾  £¬CVE-2024-27198 ÊÇÒ»ÖÖÉí·ÝÑéÖ¤ÈÆ¹ý°¸Àý  £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õ߯ëÈ«·ÛËéÒ×Êܹ¥»÷µÄ·þÎñÆ÷¡£


https://thehackernews.com/2024/03/critical-jetbrains-teamcity-on-premises.html


3. ÄϺ«µý±¨»ú¹¹³Æ  £¬±±³¯ÏʺڿÍ͵ÇÔÁ˰뵼ÌåÐÅÏ¢


3ÔÂ5ÈÕ  £¬±±³¯ÏʺڿÍ×éÖ¯ÈëÇÖÁËÖÁÉÙÁ½¼ÒÄϺ«°ëµ¼ÌåÔì×÷É豸³ö²úÉÌ  £¬ÒÔÌÓ±ÜÔì²Ã²¢³ö²ú×Ô¼ºµÄ°ëµ¼Ìå  £¬ÓÃÓÚ±øÆ÷ÏîÄ¿¡£ÕâÒ»ÐÂÎÅ´«³öºó  £¬ÄϺ«×ÜͳÖÒ¸æËµ  £¬±±³¯ÏÊ¿ÉÄÜ»á²ÉÈ¡°áŪÐÐΪ  £¬Èç½øÐÐÍøÂç¹¥»÷»òÉ¢²¼ÐéαÐÂÎÅ  £¬×ÌÈÅËÄÔµÄÒé»áÑ¡¾Ù¡£µý±¨»ú¹¹°µÊ¾  £¬ÄϺ«¹«Ë¾×ÔÈ¥Äêµ×¾Í³ÉΪ±±³¯Ïʺڿ͵ijÁµãÖ¸±ê  £¬²¢ºôÓõ¼ÓÇ¿°²È«ÐÔ¡£µý±¨»ú¹¹°µÊ¾  £¬±±³¯ÏÊÔÚ12ÔºÍ2Ô±ðÀëÈëÇÖÁËÁ½¼Ò¹«Ë¾µÄ·þÎñÆ÷  £¬µÁÈ¡Á˲úÆ·Éè¼ÆÍ¼Ö½ºÍ¹¤³§ÕÕÆ¬¡£


https://news.hitb.org/content/seoul-spies-say-north-korea-hackers-stole-semiconductor-secrets


4. WogRAT ºóÃÅ£ºÂñ·üÔÚÔÚÏß¼Çʱ¾ÖеÄÒþÐζñÒâÈí¼þ

3ÔÂ4ÈÕ  £¬Ò»ÖÖз¢ÏÖµÄÃûΪ¡°WogRAT¡±µÄºóÃŶñÒâÈí¼þÔÚÏò Windows ºÍ Linux Óû§·¢³ö¾¯±¨¡£WogRAT ÓÉAhnLab °²È«µý±¨ÖÐÐÄ(ASEC)·¢ÏÖ  £¬ÒòÆä¿ÉÄÜÕë¶ÔÁ½ÖÖÊ¢ÐвÙ×÷ϵͳ¶øÍÑÓ±¶ø³ö¡£WogRAT ËÆºõ¼Ù×°³ÉÎļþ¹²ÏíÍøÕ¾ÉϵĺϷ¨ÊµÓù¤¾ß  £¬ºýŪºÁÎÞ½äÐĵÄÓû§ÏÂÔØËü¡£ÓÐȤµÄÊÇ  £¬¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉÓÕÈ˵ÄÃû³Æ  £¬ÀýÈç¡°BrowserFixup.exe¡±ºÍ¡°ChromeFixup.exe¡±¡£ASEC µÄ·ÖÎöÅú×¢  £¬WogRAT ×Ô 2022 Äêµ×ÒÔÀ´Ò»Ïò»îÔ¾  £¬ËƺõÖØÒª¹Ø×¢ÑÇÖÞ¹ú¶ÈµÄÖ¸±ê¡£Windows °æ±¾µÄ WogRAT ÆæÃîµØ½«×Ô¼º¼Ù×°³É Adobe ¹¤¾ß  £¬²¢Óà .NET ±àд¡£

https://securityonline.info/wograt-backdoor-the-stealthy-malware-lurking-in-online-notepads/


5. Õë¶ÔÒ½Áƹ«Ë¾ Change Healthcare µÄÀÕË÷¹¥»÷ÊÕµ½2200 ÍòÃÀÔªÊê½ð


3ÔÂ5ÈÕ  £¬Ò½Áƹ«Ë¾Change HealthcareµÄÀÕË÷Èí¼þ¹¥»÷ÊǶàÄêÀ´×î¾ß·ÛËéÐÔµÄÖ®Ò»  £¬Ê¹ÃÀ¹ú¸÷µØµÄÒ©µê£¨Ô̺¬Ò½ÔºÄÚµÄÒ©µê£©ÏÝÈë̱»¾×´Ì¬  £¬µ¼ÖÂÒ©ÎïÅäË͹úÄÚÊ®ÌìÒÔÉϵÄÑϳÁ×è°­¡£´Ë¿Ì  £¬·¸×ïÊÀ½çÄÚ²¿µÄÒ»³¡ÕùÖ´½ÒʾÁËÕâ¸ö²»ÐÝ·¢Õ¹µÄΣ»úµÄнøÕ¹£º¹¥»÷±³ºóµÄºÚ¿ÍµÄһλºÏ×÷ͬ°éÖ¸³ö  £¬ÕâЩºÚ¿Í  £¬Ò»¸öÃûΪAlphV»òBlackCatµÄ×éÖ¯  £¬ÊÕµ½ÁËÒ»±Ê¿´ÆðÀ´ÏñÊǾ޶îÊê½ðÖ§¸¶µÄ2200ÍòÃÀÔªÂòÂô¡£3ÔÂ1ÈÕ  £¬ÓëAlphVÓйØÁªµÄ±ÈÌØ±ÒµØÖ·ÔÚµ¥±ÊÂòÂôÖÐÊÕµ½ÁË350¸ö±ÈÌØ±Ò  £¬»òÕ߯¾¾ÝÆäʱµÄ»ãÂÊ¿¿½ü2200ÍòÃÀÔª¡£¶øºó  £¬Á½Ììºó  £¬Ä³ÈËÔÚRAMPÕâ¸ö°µÍøÂÛÌÓð»¯ù³Æ×Ô¼ºÊÇAlphVµÄ´ÓÊô³ÉÔ±Ö®Ò»  £¬²¢Ö¸¿ØAlphVºýŪÁËËûÃÇÓ¦µÃµÄChange HealthcareÊê½ðµÄ·Ý¶î  £¬²¢Ö¸Ïò±ÈÌØ±ÒÇø¿éÁ´ÉϹ«¿ª¿É¼ûµÄ2200ÍòÃÀÔªÂòÂô×÷Ϊ֤Ã÷¡£


https://news.hitb.org/content/hackers-behind-change-healthcare-ransomware-attack-just-received-22-million-payment


6. ×êÑÐÈËÔ±Ñз¢³öµÚÒ»¸ö GenAI È䳿


3ÔÂ4ÈÕ  £¬×êÑÐÈËÔ±ÒѾ­´´½¨Á˵ÚÒ»´úÈËΪÖÇÄÜÈ䳿  £¬ËüÄܹ»ÇÔÈ¡Êý¾Ý¡¢´«²¼¶ñÒâÈí¼þ²¢Í¨¹ýµç×ÓÓʼþ´«²¼¡£¿µÄζûÀí¹¤Ñ§ÔºµÄ Ben Nassi¡¢ÒÔÉ«ÁÐÀí¹¤Ñ§ÔºµÄ Stav Cohen ºÍ Intuit µÄ Ron Bitton ´´½¨ÁËÕâÖÖ×ÔÎÒ¸´ÔìÈ䳿  £¬²¢ÒÔ 1980 Äê´úϰȾϵͳµÄ³ôÃûÔ¶ÑïµÄÈ䳿¶¨ÃûΪ¡°Morris II¡±¡£ËûÃǵĴ´×÷Ö¸±êÊÇÈËΪÖÇÄÜÀûÓ÷¨Ê½ºÍÖ§³ÖÈËΪÖÇÄܵĵç×ÓÓʼþ¸±ÊÖ¡£ËûÃǰ䷢ÁËһƪ×êÑÐÂÛÎĺÍÊÓÆµ  £¬Õ¹Ê¾ÁËÇÔÈ¡Êý¾ÝºÍÓ°ÏìÆäËûµç×ÓÓʼþϵͳµÄ²½Öè¡£¸ÃÈ䳿²¡¶¾¸ù»ù´ó½«Æ¥µÐÐÔÀàÐ͵ÄÊý¾ÝǶÈëµ½¶ñÒâµç×ÓÓʼþÖÐ  £¬°Ñ³ÖÊܺ¦ÕßµÄϵͳÀ´´«²¼ÐÂÎÅ¡¢Ö´ÐжñÒâ»î¶¯²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£´ÓÕ½ÊõÉϽ²  £¬ÕâÒ»²»ÐÝ·¢Õ¹µÄÎÊÌâµÄ¹Ø¼üÔÚÓÚ  £¬ÎªÁË×êÓª GenAI ºÍ LLM ϵͳµÄ¸ü¶àÖ°ÄܺͺóÐø¼ÛÖµ  £¬ËüÃDZØÒª¸ü¶àµÄ½Ó¼ûºÍȨÏÞÄÜÁ¦ÔÚÆäµØµãµÄÊý×ÖÉú̬ϵͳÖÐ×öÊ¡£Òò¶ø  £¬ÈôÊÇÊܵ½¶ñÒâ·½µÄÅúʾ  £¬ËüÃǾͻá³ÉΪһ¸ö¼«Æä׳´óµÄ¹¤¾ß  £¬ÎÞÂÛÊǺõϹÊÇ»µµÄ¡£


https://securityboulevard.com/2024/03/researchers-give-birth-to-the-first-genai-worm/