6K+ AI Ä£ÐÍ¿ÉÄÜÊܵ½ÑϳÁ RCE ·ì϶µÄÓ°Ïì

°ä²¼¹¦·ò 2024-05-21
1. 6K+ AI Ä£ÐÍ¿ÉÄÜÊܵ½ÑϳÁ RCE ·ì϶µÄÓ°Ïì


5ÔÂ17ÈÕ £¬ÓÃÓÚ´ó˵»°Ä£ÐÍ (LLM) µÄÊ¢ÐÐ Python °üÖеÄÒ»¸öÑϳÁ·ì϶¿ÉÄÜ»áÓ°Ïì 6,000 ¶à¸öÄ£ÐÍ £¬²¢¿ÉÄܵ¼Ö¹©¸øÁ´¹¥»÷ ¡£¿ªÔ´llama-cpp-python°ü±»·¢ÏÖÈÝÒ×Êܵ½·þÎñÆ÷¶ËÄ£°å×¢ÈëµÄ¹¥»÷ £¬Õâ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ (RCE) ¡£¸Ã·ì϶±»×·×ÙΪ CVE-2024-34359 £¬Óɰ²È«×êÑÐÔ±ºÍ¿ª·¢ÈËÔ± Patrick Peng ·¢ÏÖ £¬ËûµÄÔÚÏßÕ˺ÅΪ Retro0reg ¡£llama-cpp-python °üΪ¿í·ºÊ¢ÐÐµÄ llama.cpp ¿âÌṩ Python °ó¶¨£»llama.cpp ÊÇÒ»¸ö C++ ¿â £¬ÓÃÓÚÔÚÓ×ÎÒÍÆËã»úÉÏÔËÐÐ Meta µÄ LLaMA µÈ LLM ºÍ Mitral AI µÄÄ£ÐÍ ¡£llama-cpp-python °ü½øÒ»²½Ê¹¿ª·¢ÈËÔ±¿ÉÄܽ«ÕâЩ¿ªÔ´Ä£Ðͼ¯³Éµ½ Python ÖÐ ¡£CVE-2024-34359µÄ CVSS ¹Ø¼ü·ÖÊýΪ 9.7 £¬ÓÉÓÚ Jinja2 Ä£°åÒýÇæµÄÖ´Ðв»µ± £¬´æÔÚ RCE ·çÏÕ ¡£Peng ÔÚ²©¿ÍÎÄÕÂÖÐÚ¹ÊÍ˵ £¬¸ÃȱµãÔÊÐí Jinja2 ½âÎö´æ´¢ÔÚÔªÊý¾ÝÖеÄ̸ÌìÄ£°å £¬¶øÎÞÐè½øÐÐËãÕÊ»òɳÏä´¦Öà £¬´Ó¶øÎª¹¥»÷Õß×¢Èë¶ñÒâÄ£°å´´ÔìÁË»úÓö ¡£


https://www.scmagazine.com/news/6k-plus-ai-models-may-be-affected-by-critical-rce-vulnerability


2. Grandoreiro ÒøÐÐľÂí´ø×ųÁ´ó¸üлعé


5ÔÂ20ÈÕ £¬¾Ý IBM ³Æ £¬Ò»ÖÖ¶à²úµÄÒøÐÐľÂíÔÚ¶à¸öлÖгÁгöÏÖ £¬Æä¼ÓÇ¿µÄÖ°ÄÜÖ¼ÔÚʹÆä³ÉΪ¸ü׳´óµÄÍþв ¡£Õâ¼Ò¿Æ¼¼¾ÞÍ·µÄ X-Force ÍøÂ簲ȫÊýÃŰµÊ¾ £¬×Ô 3 Ô·ÝÒÔÀ´ £¬ËüÒ»ÏòÔÚ×·×ÙÊýÆð´ó¹æÄ£ÍøÂç´¹µö»î¶¯ ¡£ÆäÖÐÔ̺¬¼ÙÒâÄ«Î÷¸ç˰ÎñÖÎÀí¾Ö (SAT)¡¢Áª¹úµçÁ¦Î¯Ô±»á (CFE) ºÍÐÐÕþºÍ²ÆÕþ²¿³¤¡¢ÒÔ¼°°¢¸ù͢˰Îñ¾ÖºÍÄÏ·Ç˰Îñ¾Ö (SARS) µÄ¹¥»÷ ¡£IBM X-Force °µÊ¾£º¡°ÔÚÿ´Î»î¶¯ÖÐ £¬½Ó¹ÜÕß³ÇÊб»Åúʾµã»÷Á´½ÓÀ´²é¿´·¢Æ±»òÓöȡ¢ÕË»§¶ÔÕ˵¥¡¢¸¶¿îµÈ £¬¾ßÌåÈ¡¾öÓÚ±»¼ÙÒâµÄʵÌå ¡£¡±¡°ÈôÊǵã»÷Á´½ÓµÄÓû§Î»ÓÚÌØ¶¨¹ú¶È/µØÓò£¨¾ßÌåÈ¡¾öÓڻ £¬Ä«Î÷¸ç¡¢ÖÇÀû¡¢Î÷°àÑÀ¡¢¸ç˹´ïÀè¼Ó¡¢ÃØÂ³»ò°¢¸ùÍ¢£© £¬ËûÃǽ«±»³Á¶¨Ïòµ½ PDF ͼ±êͼÏñºÍ ZIP ÎļþÊÇÔÚºó¶ÜÏÂÔØµÄ ¡£ZIP ÎļþÔ̺¬Ò»¸öÓà PDF ͼ±ê¼Ù×°µÄ´óÐÍ¿ÉÖ´ÐÐÎļþ £¬·¢ÏÖÊÇÔÚµç×ÓÓʼþ·¢Ë͵ÄǰһÌì»òµ±Ìì´´½¨µÄ ¡£¡±


https://www.infosecurity-magazine.com/news/grandoreiro-banking-trojan-major/?&web_view=true


3. Kinsing ºÚ¿Í×éÖ¯ÀûÓøü¶àȱµãÀ´À©´óÕë¶Ô½©Ê¬ÍøÂç


5ÔÂ17ÈÕ £¬ÃûΪKinsingµÄ¼ÓÃܽٳÖ×éÖ¯ÒѾ­Õ¹Ê¾³ö²»ÐÝ·¢Õ¹ºÍÊÊÓ¦µÄÄÜÁ¦ £¬Í¨¹ýѸËÙ½«ÐÂÅû¶µÄ·ì϶¼¯³Éµ½·ì϶ÀûÓÿâÖв¢À©´óÆä½©Ê¬ÍøÂç £¬ÊÂʵ֤Ã÷¸Ã×éÖ¯ÊÇÒ»¸ö³ÖÐøµÄÍþв ¡£¸Ãµ÷²éÁ˾ÖÀ´×ÔÔÆ°²È«¹«Ë¾ Aqua £¬¸Ã¹«Ë¾½«ÍþвÐÐΪÕßÃèÊöΪ×Ô 2019 ÄêÒÔÀ´»ý¼«²ß¶¯·¸·¨¼ÓÃÜÇ®±ÒÍÚ¿ó»î¶¯ ¡£Kinsing£¨±ðÃûH2Miner£©ÊǶñÒâÈí¼þ¼°Æä±³ºóµÄµÐÊÖµÄÃû×Ö £¬Ëü²»ÐÝÀûÓÃеķì϶À©´óÆä¹¤¾ß°ü £¬½«ÊÜϰȾµÄϵͳע²áµ½¼ÓÃÜÍÚ¾ò½©Ê¬ÍøÂçÖÐ ¡£TrustedSec ÓÚ 2020 Äê 1 Ô³õ´Î¼Í¼ÁËËü ¡£½üÄêÀ´ £¬Éæ¼°»ùÓÚ Golang µÄ¶ñÒâÈí¼þµÄ»î¶¯ÀûÓÃÁËApache ActiveMQ¡¢Apache Log4j¡¢Apache NiFi¡¢Atlassian Confluence¡¢Citrix¡¢Liferay Portal¡¢Linux¡¢Openfire¡¢Oracle WebLogic ServerºÍSaltStackÖеĸ÷ÀàȱµãÀ´·ÛËéÒ×Êܹ¥»÷µÄϵͳ ¡£


https://thehackernews.com/2024/05/kinsing-hacker-group-exploits-more.html?&web_view=true


4. 240 ÍòÈËÊܵ½ WebTPA Êý¾Ýй¶µÄÓ°Ïì


5ÔÂ20ÈÕ £¬WebTPA ¹ÍÖ÷·þÎñ¹«Ë¾Åû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁ˳¬¹ý 240 ÍòÈ˵ÄÓ×ÎÒÐÅÏ¢ ¡£WebTPA ×ܲ¿Î»Óڵ¿ËÈøË¹ÖÝÅ·ÎÄ £¬ÊÇ GuideWell Mutual Holding Corporation µÄÈ«×Ê×Ó¹«Ë¾ £¬ÊÇÒ»¼ÒרÃÅ´Óʽ¡È«±£Ïպ͸£Àû´òËãµÄµÚÈý·½ÖÎÀí»ú¹¹ (TPA) ¡£WebTPA ÔÚÆäÍøÕ¾ÉϵÄÒ»·Ý֪ͨÖаµÊ¾ £¬¸ÃÍøÂçÊÂÎñÊÇÔÚÆäÍøÂçÉϼì²âµ½¿ÉÒɻµÄÖ¤¾ÝºóÓÚ 2023 Äê 12 Ô 28 ÈÕ·¢ÏÖµÄ ¡£¶Ô´Ëʵĵ÷²éÏÔʾ £¬Ò»ÃûÍþвÐÐΪÕßÔÚ 2023 Äê 4 Ô 18 ÈÕÖÁ 23 ÈÕÆÚ¼ä´ÓÆäϵͳÖÐÇÔÈ¡ÁËÓ×ÎÒÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢ÁªÏµÐÅÏ¢¡¢µ®ÉúÈÕÆÚ¡¢éæÃüÈÕÆÚ¡¢±£ÏÕÐÅÏ¢ºÍÉç»á°²È«ºÅÂë ¡£Æ¾¾Ý TPA µÄ˵·¨ £¬Â¶³öµÄÊý¾ÝÒòÈ˶øÒì ¡£²ÆÕþÐÅÏ¢¡¢ÐÅÓþ¿¨ºÅÂëÒÔ¼°½¡È«ºÍÒ½ÁÆÐÅϢδÊܵ½¸ÃÊÂÎñµÄÓ°Ïì ¡£


https://www.securityweek.com/2-4-million-impacted-by-webtpa-data-breach/


5. Singing River Ò½ÁÆÏµÍ³ÀÕË÷Èí¼þ¹¥»÷Ó°Ïì½ü 90 ÍòÈË


5ÔÂ20ÈÕ £¬Singing River Health System °µÊ¾ £¬2023 Äê 8 ÔµÄÀÕË÷Èí¼þ¹¥»÷Ó°ÏìÁË 895,204 ÈË ¡£Õâ¼Ò×ܲ¿Î»ÓÚÃÜÎ÷Î÷±ÈÖݵÄÒ½ÁƱ£½¡ÌṩÉÌÔÚÄ«Î÷¸çÍåÑØ°¶µØÓòÔËÓª×Ŷà¼ÒÒ½ÔººÍÒ½ÁÆÉèÊ© ¡£Æ¾¾ÝÊý¾Ýй¶֪ͨ £¬Â¶³öµÄÐÅÏ¢Ô̺¬£ºÈ«Ãû¡¢µ®ÉúÈÕÆÚ¡¢ÎïÀíµØÖ·¡¢Éç»á°²È«ºÅÂë (SSN)ºÍÒÔ¼°Ò½Áƺͽ¡È«ÐÅÏ¢ ¡£Ö»¹Ü´æÔÚÊý¾Ý±»µÁµÄÇé¿ö £¬µ«Ä¿Ç°Ã»ÓÐÖ¤¾ÝÅú×¢Éí·Ý±»µÁ»òڲƭ ¡£¸Ã×é֯ͨ¹ý IDX ÏòÊÜÓ°ÏìµÄÈËÌṩ 24 ¸öÔµÄÐÅÓþ¼à¿ØºÍÉí·Ý¸´Ô­·þÎñ ¡£Bleeping ComputerÚ¹ÊÍ˵ £¬¾Ý±¨Â· £¬ËûÃÇй¶ÁËԼĪ 80% µÄ±»µÁÊý¾Ý £¬ÆäÖÐÔ̺¬ 420,766 ¸öÎļþ£¨754 GB£©µÄĿ¼ ¡£


https://heimdalsecurity.com/blog/singing-river-health-system-ransomware-attack-affects-nearly-900000/


6. ÍøÂç·¸×ï·Ö×ÓÀûÓÃGitHubºÍFileZilla´«²¼¶ñÒâÈí¼þ


5ÔÂ20ÈÕ £¬¾Ý¹Û²ì £¬Ò»³¡¡°¶à·½ÃæµÄ»î¶¯¡±ÀÄÓà GitHub ºÍ FileZilla µÈºÏ·¨·þÎñ £¬Í¨¹ý¼ÙÒâ¿ÉÐÅÈí¼þ£¨Èç1Password¡¢Bartender 5 ºÍ Pixelmator Pro ¡£Recorded Future µÄ Insikt GroupÔÚÒ»·Ý»ã±¨ÖаµÊ¾£º¡°¶àÖÖ¶ñÒâÈí¼þ±äÌåµÄ´æÔÚ½²ÁËÈ»¿í·ºµÄ¿çƽָ̨±êÕ½Êõ £¬¶ø³ÁµþµÄ C2 »ù´¡ÉèÊ©Ôò½²ÁËÈ»¼¯ÖÐʽºÅÁîÉèÖà £¬Õâ¿ÉÄÜ»áÌá¸ß¹¥»÷µÄЧÄÜ ¡£¡¹Øâ¼ÒÃûΪ GitCaught µÄÍøÂ簲ȫ¹«Ë¾ÔÚ×·×ÙÕâÒ»»î¶¯ £¬¸Ã¹«Ë¾°µÊ¾ £¬¸Ã»î¶¯²»½ö͹ÏÔÁËÀÄÓÃÕæÊµ»¥ÁªÍø·þÎñÀ´²ß¶¯ÍøÂç¹¥»÷ £¬²¢ÇÒ»¹ÒÀÀµÓÚÕë¶Ô Android¡¢macOS ºÍ Windows µÄ¶àÖÖ¶ñÒâÈí¼þ±äÌåÀ´Ìá¸ß³É¹¦ÂÊ ¡£ËÙ¶È ¡£¹¥»÷Á´±ØÒªÊ¹Óà GitHub ÉϵÄÐéαÅäÖÃÎļþºÍ´æ´¢¿â £¬ÍйܳÛÃûÈí¼þµÄ¼Ùð°æ±¾ £¬Ö÷ÕÅÊÇ´ÓÊÜϰȾÉ豸»ñÈ¡Ãô¸ÐÊý¾Ý ¡£¶øºó £¬ÕâЩ¶ñÒâÎļþµÄÁ´½Ó»áǶÈëµ½¼¸¸öÓòÖÐ £¬ÕâЩÓòͨ³£Í¨¹ý¶ñÒâ¸æ°×ºÍ SEO Öж¾»î¶¯½øÐзַ¢ ¡£


https://thehackernews.com/2024/05/cyber-criminals-exploit-github-and.html