MetaÒòÃ÷ÎÄ´æ´¢6ÒÚÓû§ÃÜÂë±»·£1ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2024-09-30
1. MetaÒòÃ÷ÎÄ´æ´¢6ÒÚÓû§ÃÜÂë±»·£1ÒÚÃÀÔª


9ÔÂ27ÈÕ £¬°®¶ûÀ¼Êý¾Ý±£»¤Î¯Ô±»á£¨DPC£©¶ÔFacebookĸ¹«Ë¾Meta´¦ÒÔ9100ÍòÅ·Ôª£¨Ô¼1.01ÒÚÃÀÔª£©·£¿î £¬Ô­ÒòÊÇMetaÔÚ2019ÄêÒâÍ⽫6ÒÚÓû§µÄÃÜÂëÒÔÃ÷ÎÄÐÎʽ´æ´¢¡£ÕâÒ»´¦·£Ô´ÓÚÒ»ÆðÁ¬Ðø5ÄêµÄÊӲ졣2019Äê3Ô £¬Äþ¾²Ñо¿Ô±²¼Àµ¶÷¡¤¿ËÀײ¼Ë¹·¢ÏÖMetaÓû§ÃÜÂëÄþ¾²È±ÏÝ £¬MetaËæºóÈ·Èϲ¢ÔÚÄÚ²¿ÏµÍ³ÉÏ·¢ÏÖδ¼ÓÃܵÄÓû§ÃÜÂë £¬²¢ÏòDPCͨ±¨ £¬Í¬Ê±Ç¿µ÷ûÓÐÖ¤¾Ý±íÃ÷ÃÜÂë±»ÀÄÓà £¬²¢Á¢¼´ÐÞ¸´Á˸ôíÎó¡£È»¶ø £¬DPCÈ϶¨MetaÎ¥·´ÁË¡¶Í¨ÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©ÖеĶàÏîÄþ¾²ÒªÇó £¬°üÂÞδÄÜ֪ͨºÍ¼Ç¼Êý¾Ýй¶ £¬Î´Ê¹ÓÃÊʵ±µÄ¼¼Êõ»ò×éÖ¯´ëÊ©È·±£Óû§ÃÜÂëÄþ¾² £¬ÒÔ¼°Î´ÊµÊ©Êʵ±µÄÄþ¾²´ëÊ©È·±£Óû§ÃÜÂëÁ¬Ðø»úÃÜÐÔ¡£DPC¸±×¨Ô±¸ñÀ׶òÄ·¡¤¶àÒÁ¶ûÌåÏÖ £¬Óû§ÃÜÂë²»Ó¦ÒÔÃ÷ÎÄÐÎʽ´æ´¢ £¬¿¼Âǵ½·ÃÎÊ´ËÀàÊý¾ÝµÄÈË¿ÉÄÜ´øÀ´µÄÀÄÓ÷çÏÕ¡£ËäÈ»×î³õµÄ±¬ÁÏÕß¿ËÀײ¼Ë¹Ã»Óз¢ÏÖFacebookÔ±¹¤Æäʱ·ÃÎÊÁ˱»ÆعâÃÜÂëµÄÖ¤¾Ý £¬µ«Äþ¾²È±ÏÝ¿ÉÄÜÈÃFacebookµÄ20ÍòÔ±¹¤ÖеÄÈκÎÒ»ÈË¿´µ½Õâ¶à´ï6ÒÚ¸öÕË»§µÄÃ÷ÎÄÃÜÂë¡£´ËÍâ £¬Meta½üÆÚÒò¶à´ÎÎ¥·´GDPR¹æ¶¨¶ø±»·£¿î £¬°üÂÞÊý¾Ýץȡй¶¡¢Óû§Í¬ÒâºÍÊý¾Ý´¦ÖÃÎ¥¹æ £¬ÒÔ¼°ÏòÃÀ¹ú´«Êä¸öÈËÊý¾ÝµÄ·½Ê½µÈ £¬ÆäÖÐ×î´óµÄÒ»±Ê·£¿î¸ß´ï12ÒÚÅ·Ôª¡£MetaÕýÔÚ¶ÔDPCµÄÅоöÌá³öÉÏËß¡£


https://cybernews.com/security/meta-100m-fine-dpc-ireland-plaintext-passwords-facebook-leak/


2. NVIDIA Container ToolkitÑÏÖØ©¶´Ó°ÏìAIÓ¦ÓÃÄþ¾²


9ÔÂ29ÈÕ £¬NVIDIA Container ToolkitÖдæÔÚÒ»¸ö±»×·×ÙΪCVE-2024-0132µÄÑÏÖØ©¶´ £¬¸Ã©¶´ÔÊÐí¹¥»÷ÕßÖ´ÐÐÈÝÆ÷ÌÓÒݹ¥»÷²¢»ñµÃ¶ÔÖ÷»úϵͳµÄÍêÈ«·ÃÎÊȨÏÞ £¬´Ó¶øÖ´ÐÐÃüÁî»òй¶Ãô¸ÐÐÅÏ¢¡£¸Ã©¶´Ó°ÏìNVIDIA Container Toolkit 1.16.1¼°¸üÔç°æ±¾ÒÔ¼°GPU Operator 24.6.1¼°¸üÔç°æ±¾ £¬¶øÇÒÓÉÓڸÿâԤװÔÚÐí¶àÒÔAIΪÖÐÐĵÄƽ̨ºÍÐéÄâ»úÓ³ÏñÖÐ £¬Áè¼Ý35%µÄÔÆ»·¾³ÃæÁÙÀûÓø鶴½øÐй¥»÷µÄ·çÏÕ¡£ÎÊÌâÔÚÓÚÈÝÆ÷»¯µÄGPUÓëÖ÷»úÖ®¼äȱ·¦Äþ¾²¸ôÀë £¬ÔÊÐíÈÝÆ÷¹ÒÔØÖ÷»úÎļþϵͳµÄÃô¸Ð²¿ÃÅ»ò·ÃÎÊÔËÐÐʱ×ÊÔ´¡£WizÑо¿ÈËÔ±·¢ÏÖÁ˸鶴 £¬²¢ÓÚ9ÔÂ1ÈÕÏòNVIDIA³ÂËß £¬NVIDIAÓÚ9ÔÂ26ÈÕÐû²¼ÁËÐÞ¸´·¨Ê½¡£½¨ÒéÊÜÓ°ÏìµÄÓû§Éý¼¶µ½NVIDIA Container Toolkit°æ±¾1.16.2ºÍNVIDIA GPU Operator 24.6.2¡£Ä¿Ç° £¬ÀûÓø鶴µÄ¼¼Êõϸ½ÚÈÔ´¦ÓÚ±£ÃÜ״̬ £¬ÒÔ±ãÊÜÓ°ÏìµÄ×éÖ¯ÓÐʱ¼äÔÚÆä»·¾³Öлº½â¸ÃÎÊÌâ¡£


https://www.bleepingcomputer.com/news/security/critical-flaw-in-nvidia-container-toolkit-allows-full-host-takeover/


3. °ÍÎ÷ÔâÅÓ´ó¶ñÒâÈí¼þѬȾÁ´¹¥»÷ £¬Éæ¼°BBTokÒøÐÐľÂí


9ÔÂ29ÈÕ £¬G DATA CyberDefense×î½ü·¢ÏÖÁËÒ»ÏîÕë¶Ô°ÍÎ÷ʵÌåµÄÅÓ´ó¶ñÒâÈí¼þѬȾÁ´ £¬¸ÃѬȾÁ´ÓëBBTokÒøÐÐľÂíÓÐ¹Ø £¬½ÓÄɶà½×¶ÎÒªÁì¡£¹¥»÷Õßͨ¹ýµöÓãµç×ÓÓʼþ·¢ËÍαװ³É°ÍÎ÷³£ÓÃÊý×Ö·¢Æ±µÄ¶ñÒâISOÓ³Ïñ £¬ÓÕʹÓû§Ö´ÐжñÒ⸺ÔØ¡£¸Ã¶ñÒâÈí¼þÀûÓÃMicrosoft Build Engine±àÒë¶ñÒâC#´úÂë £¬²¢Ê¹ÓÃAppDomain Manager×¢Èë¼¼ÊõʵÏָ߼¶Ö´ÐÐ £¬Í¬Ê±½ÓÄÉConfuserEx±äÌå»ìÏý.NET¼ÓÔØ·¨Ê½ÒÔÌӱܼì²â¡£´ËÍâ £¬¶ñÒâÈí¼þ»¹°üÂÞ¶àÖÖ³Ö¾ÃÐÔ»úÖÆ £¬²¢ÊµÑé½ûÓÃÄþ¾²¹¤¾ß¡£Ñ¬È¾Á´ÖÐʹÓúϷ¨ÊðÀí·þÎñÆ÷Ó¦Ó÷¨Ê½CCProxyαװ³ÉºÏ·¨µÄÍøÂç½ø³Ì £¬´Ù½øÓëÃüÁîºÍ¿ØÖÆ·þÎñÆ÷µÄͨÐÅ¡£½¨ÒéÆóҵʵʩÑϸñµÄµç×ÓÓʼþ¹ýÂË¡¢¶¨ÆÚ¸üÐÂÈí¼þ¡¢²¿Êð¸ß¼¶¶Ëµã±£»¤ £¬²¢½ÌÓýÔ±¹¤Á˽âµöÓãµç×ÓÓʼþµÄΣÏÕ £¬ÒÔ¼õÇá´ËÀà¸ß¼¶ÒøÐÐľÂí´øÀ´µÄ·çÏÕ¡£


https://securityonline.info/net-loaders-and-stealthy-persistence-bbtok-trojans-new-tricks/


4. GiveWP¾èÔù²å¼þ·¢ÏÖÑÏÖØ©¶´ £¬10Íò¸öWordPressÍøÕ¾ÃæÁÙ·çÏÕ


9ÔÂ29ÈÕ £¬ÔÚÁ÷ÐÐµÄ WordPress GiveWP ¾èÔù²å¼þÖз¢ÏÖÁËÒ»¸öÑÏÖØ©¶´CVE-2024-8353 £¬¸Ã©¶´Ô´ÓÚPHP¹¤¾ß×¢Èë £¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄÍøÕ¾¡£Â©¶´×î¸ßÑÏÖØÐÔÆÀ·ÖΪ10 £¬ÓÉÓÚ´¦Öò»ÊÜÐÅÈεÄÊäÈë²»Í× £¬ÌرðÊÇÔÚ·´ÐòÁл¯¶à¸ö²ÎÊýÆڼ䷢Éú¡£¾¡¹ÜÔÚ°æ±¾3.16.1ÖÐÒѲ¿ÃÅÐÞ²¹ £¬µ«ËùÓа汾µÄGiveWP£¨°üÂÞ3.16.1£©¶¼´æÔÚ´Ë©¶´ £¬¸Ã²å¼þÄ¿Ç°ÒÑ°²×°Áè¼Ý10Íò´Î £¬¶Ô´óÁ¿ÒÀÀµ¸Ã²å¼þµÄWordPressÍøÕ¾×é³ÉÖØ´óÄþ¾²·çÏÕ¡£Òò´Ë £¬Á¢¼´½«GiveWP¸üÐÂÖÁ3.16.2»ò¸ü¸ß°æ±¾ÖÁ¹ØÖØÒª £¬Í¬Ê±ÍøÕ¾¹ÜÀíÔ±Ó¦¼à¿ØÈÕÖ¾ÖÐÊÇ·ñ´æÔÚ¿ÉÒɻ £¬²¢¿¼ÂǽÓÄÉÌرðµÄÄþ¾²²ãÒÔ½µµÍδÀ´Â©¶´µÄ·çÏÕ¡£


https://securityonline.info/cve-2024-8353-critical-givewp-flaw-100k-wordpress-sites-at-risk/


5. KimsukyʹÓÃжñÒâÈí¼þKLogEXEºÍFPSpy½øÐÐÍøÂç¼äµý»î¶¯


9ÔÂ29ÈÕ £¬Unit 42 Ñо¿ÈËÔ±·¢ÏÖ £¬ÎÛÃûÕÑÖøµÄ³¯Ïʸ߼¶Á¬ÐøÐÔÍþв×éÖ¯ Sparkling Pisces£¨ÓÖÃû Kimsuky£©ÕýÔÚʹÓÃÁ½¿îеĶñÒâÈí¼þÑù±¾£ºÎ´¼Ç¼µÄ¼üÅ̼ǼÆ÷ KLogEXE ºÍºóÃűäÖÖ FPSpy £¬½øÒ»²½À©Õ¹Æ乤¾ß°üºÍ¹¦Ð§¡£ÕâЩ¶ñÒâÈí¼þ±»ÓÃÓÚÕë¶Ôº«¹ú¡¢ÈÕ±¾µÈ¹ú¼ÒµÄÒªº¦²¿ÃŵÄÍøÂç¼äµý»î¶¯¡£KLogEXE Äܹ»¼à¿ØÊܺ¦ÕߵļüÅÌÊäÈëºÍÊó±êµã»÷ £¬ÊÕ¼¯Ãô¸ÐÐÅÏ¢ £¬²¢Í¨¹ý HTTP ·¢Ë͵½ Sparkling Pisces µÄÃüÁîºÍ¿ØÖÆ·þÎñÆ÷¡£ËüʹÓà HackingTeam й¶µÄ´úÂë»ìÏý API µ÷Óà £¬ÒÔÈƹý¾²Ì¬¼ì²âÒªÁì¡£FPSpy ÔòÊÇ»ùÓÚ Sparkling Pisces ֮ǰµÄ¶ñÒâÈí¼þ»î¶¯µÄ¸ß¼¶ºóÃÅ £¬ÌṩÁ˳ý¼üÅ̼Ǽ֮ÍâµÄһϵÁй¦Ð§ £¬°üÂÞÊý¾ÝÊÕ¼¯¡¢Ö´ÐÐÈÎÒâÃüÁîºÍÏÂÔØÆäËû¼ÓÃÜÄ£¿é¡£Á½¿î¶ñÒâÈí¼þÖ®¼ä´æÔÚ´óÁ¿»ù´¡ÉèÊ©Öصþ £¬¹²ÏíÏàͬµÄ C2 »ù´¡ÉèÊ©ºÍ´úÂë¿â £¬±íÃ÷ËüÃǶ¼ÊÇ Sparkling Pisces Эͬ»î¶¯µÄÒ»²¿ÃÅ¡£Sparkling Pisces µÄ»ù´¡ÉèÊ©ÅÓ´óÇÒÊÊÓ¦ÐÔÇ¿ £¬Ê¹Äþ¾²ÍŶÓÄÑÒÔ×·×ÙÆä»î¶¯¡£


https://securityonline.info/klogexe-fpspy-kimsukys-evolving-cyber-espionage-arsenal/


6. ¼ÙðӢÐÛÁªÃËÏÂÔعã¸æÁ÷´«Lumma Stealer¶ñÒâÈí¼þ


9ÔÂ26ÈÕ £¬Ëæ×ÅÓ¢ÐÛÁªÃË£¨LoL£©È«Çò×ܾöÈüµÄÈȶȲ»Í£ÅÊÉý £¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓÃÕâÒ»»ú»á £¬Í¨¹ý¶ñÒâÈí¼þ»î¶¯¶ÔÓÎÏ··ÛË¿Óû§ÊµÊ©¹¥»÷¡£¾ÝBitdefender Labs×î½ü³ÂËß £¬Ò»ÖÖÕë¶ÔÅ·ÖÞÍæ¼ÒµÄÐÂÐÍÍøÂçÍþвÒѵ¼ÖÂÔ¼4000ÃûÊܺ¦Õß £¬ÆäÖжàΪ³ÉÄêÄÐÐÔ¡£ÕâÖÖ¶ñÒâ»î¶¯Í¨¹ý¾«ÐÄÉè¼ÆµÄÉ罻ýÌåÓÎÏ·¹ã¸æ £¬ÓÕµ¼·ÛË¿ÏÂÔØ¿´ËƺϷ¨µÄÓ¢ÐÛÁªÃËÓÎÏ· £¬ÊµÔò°²×°ÁËLumma Stealer¶ñÒâÈí¼þ¡£¸ÃÈí¼þÄܹ»ÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢¡¢ÃÜÂë¡¢¼ÓÃÜÇ®°ü¼°ä¯ÀÀÆ÷»á»°cookieµÈÃô¸ÐÐÅÏ¢¡£Êܺ¦Õ߻ᱻÒýµ¼ÖÁÒ»¸öÄ£·Â¾É°æÓ¢ÐÛÁªÃËÏÂÔØÒ³ÃæµÄÍøÕ¾ £¬¸ÃÒ³Ãæ½ÓÄÉ´í±ð×ÖÇÀ×¢¼¼Êõ £¬Ôö¼ÓÁ˼ì²âÄѶÈ¡£Ò»µ©µã»÷ÏÂÔØÁ´½Ó £¬Êܺ¦Õß½«±»Öض¨ÏòÖÁ°üÂÞ¶ñÒâ´æµµµÄBitbucket´æ´¢¿â £¬ÏÂÔصÄѹËõ°üÖаüÂÞLumma StealerµÄÏÂÔØÆ÷¡£Lumma Stealer¹¦Ð§Ç¿´ó £¬Äܽ«×ÔÉí×¢ÈëºÏ·¨µÄWindows½ø³ÌÒÔÌӱܼì²â £¬²¢½«ÇÔÈ¡µÄÊý¾ÝÔÚµØÏÂÊг¡³öÊÛ £¬½ø¶ø´Ù½øÉí·Ý͵ÇÔºÍÍøÂçµöÓã¹¥»÷¡£Äþ¾²×¨¼ÒÌáÐÑÓû§ £¬ÔÚÏÂÔØÓÎϷʱÎñ±Ø×Ðϸ¼ì²éÍøÕ¾URL £¬½¨Òé´Ó¹Ù·½ÇþµÀÏÂÔØ £¬²¢¾¯Ìè¹ýÓÚÓÕÈ˵ÄÔÚÏß¹ã¸æ £¬ÒÔ±£»¤×Ô¼ºµÄ¸öÈËÐÅÏ¢Äþ¾²¡£


https://hackread.com/fake-league-of-legends-download-ads-lumma-stealer/#google_vignette