Solana JavaScript SDKÔ⹩ӦÁ´¹¥»÷£¬¶ñÒâ´úÂëÇÔÈ¡¼ÓÃÜ»õ±Ò˽Կ
Ðû²¼Ê±¼ä 2024-12-061. Solana JavaScript SDKÔ⹩ӦÁ´¹¥»÷£¬¶ñÒâ´úÂëÇÔÈ¡¼ÓÃÜ»õ±Ò˽Կ
12ÔÂ4ÈÕ£¬SolanaµÄJavaScript SDK¡°@solana/web3.js¡±ÔÚ½üÆÚµÄÒ»´Î¹©Ó¦Á´¹¥»÷ÖÐÔâµ½ÔÝʱÈëÇÖ£¬¹¥»÷ÕßÐû²¼ÁËÁ½¸ö°üÂÞ¶ñÒâ´úÂëµÄºóÃÅ°æ±¾£¨1.95.6ºÍ1.95.7£©£¬Ö¼ÔÚÇÔÈ¡¼ÓÃÜ»õ±Ò˽Կ²¢ÌÍ¿ÕÇ®°ü¡£ÕâЩ±»ÈëÇֵİ汾ÔÚnpmÉÏÿÖÜÏÂÔØÁ¿Áè¼Ý350,000´Î£¬¶Ô¿ª·¢ÈËÔ±ºÍÓû§×é³ÉÁËÑÏÖØÍþв¡£Solana֤ʵÁËÕâһ©¶´£¬²¢ÌåÏÖÊÇÓÉÓÚÆäÐû²¼·ÃÎÊÕË»§±»ÈëÇÖËùÖ¡£¹¥»÷Õßͨ¹ýÐ޸ĿâÖеÄÒªº¦º¯Êý£¬½«¶ñÒâ´úÂëÌí¼Óµ½¿âÖУ¬ÒÔÇÔȡ˽Կ²¢½«Æä·¢Ë͵½¹¥»÷ÕߵķþÎñÆ÷¡£¾ÝDataDogÑо¿Ô±³Æ£¬ÍþвÐÐΪÕßÌí¼ÓÁËÒ»¸ö¶ñÒâµÄ¡°addToQueue¡±º¯Êý£¬¸Ãº¯Êýͨ¹ý¿´ËƺϷ¨µÄCloudFlare±êͷй¶˽Կ¡£´Ë´Î¹¥»÷ÒÑ×·Ëݵ½Ìض¨µÄSolanaµØÖ·£¬¸ÃµØÖ·°üÂÞ¶àÖÖ¼ÓÃÜ»õ±ÒºÍNFT£¬Ô¤¼Æ¼ÛֵΪ184,000ÃÀÔª¡£Solana¾¯¸æ»³ÒÉ×Ô¼ºÊܵ½¹¥»÷µÄ¿ª·¢ÈËÔ±Á¢¼´Éý¼¶µ½×îеÄv1.95.8°æ±¾²¢ÂÖ»»ËùÓÐÃÜÔ¿£¬Í¬Ê±½¨ÒéÇ®°ü±»µÁµÄÈËÁ¢¼´½«Ê£Óà×ʽðתÒƵ½ÐÂÇ®°ü£¬²¢Í£Ö¹Ê¹ÓþÉÇ®°ü¡£
https://www.bleepingcomputer.com/news/security/solana-web3js-library-backdoored-to-steal-secret-private-keys/
2. ¶íÂÞ˹ºÚ¿Í½Ù³Ö°Í»ù˹̹ºÚ¿Í·þÎñÆ÷½øÐй¥»÷
12ÔÂ4ÈÕ£¬¶íÂÞ˹ÍøÂç¼äµý×éÖ¯Turla£¬ÓÖÃû¡°ÃØÃܱ©Ñ©¡±£¬½üÆÚ½ÓÄÉÁËÒ»ÖÖÐµĹ¥»÷¼Æı£¬¼´¹¥»÷²¢½Ù³ÖÆäËûºÚ¿Í×éÖ¯µÄ»ù´¡ÉèÊ©£¬ÒÔÃØÃÜÈëÇÖÒѾÊܵ½¹¥»÷µÄÍøÂç¡£¸Ã×éÖ¯ÀֳɽٳÖÁË°Í»ù˹̹ºÚ¿Í×éÖ¯Storm-0156µÄ»ù´¡ÉèÊ©£¬²¢ÀûÓÃÆä·ÃÎÊÁËStorm-0156ÔøÈëÇÖ¹ýµÄ°¢¸»º¹ºÍÓ¡¶ÈÕþ¸®×éÖ¯ÍøÂ磬²¿ÊðÁ˶ñÒâÈí¼þ¹¤¾ß¡£¾ÝLumenµÄBlack LotusʵÑéÊÒ³ÂËߣ¬Turla×Ô2022Äê12Ô¿ªÊ¼½øÐд˴ÎÐж¯£¬²¢Ò»Ö±Á¬ÐøÖÁ2023Äê¡£TurlaÊÇÒ»¸öÊܶíÂÞ˹Õþ¸®Ö§³ÖµÄºÚ¿Í×éÖ¯£¬ºã¾ÃÕë¶ÔÈ«ÇòÕþ¸®¡¢×éÖ¯ºÍÑо¿»ú¹¹½øÐÐÍøÂç¼äµý»î¶¯¡£´Ë´Î£¬ËûÃÇÔÚStorm-0156µÄÍøÂçÖз¢ÏÖÁËÆæ¹ÖµÄÍøÂçÐÐΪ£¬²¢Àֳɹ¥ÆÆÆä¶à¸öC2½Úµã£¬²¿ÊðÁË°üÂÞTinyTurlaºóÃűäÖÖ¡¢TwoDashºóÃŵÈÔÚÄڵĶñÒâÈí¼þ¡£³ýÁË»ñÈ¡Storm-0156µÄ¶ñÒâÈí¼þ¹¤¾ßºÍ±»µÁÊý¾ÝÍ⣬Turla»¹½øÒ»²½½«Ä¿±êÃé×¼ÁËStorm-0156×Ô¼º£¬ºáÏò½øÈëÁËÆäÊÂÇéÕ¾¡£TurlaµÄÕâÖÖ¼ÆıʹËûÃÇÄܹ»ÃØÃÜÊÕ¼¯Ç鱨£¬ÖÆֹ̻¶×Ô¼º»ò¹¤¾ß¼¯£¬´Ó¶ø¼ò»¯¹éÒòÊÂÇé¡£
https://www.bleepingcomputer.com/news/security/russian-turla-hackers-hijack-pakistani-apt-servers-for-cyber-espionage-attacks/
3. ¸ç˹´ïÀè¼ÓRECOPE¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷Òý·¢È¼ÁϹ©Ó¦µ£ÓÇ
12ÔÂ4ÈÕ£¬¸ç˹´ïÀè¼ÓʯÓÍÁ¶Öƹ«Ë¾£¨RECOPE£©½üÆÚÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäÔËÓªÊܵ½Ó°Ï죬²¢Òý·¢¹«ÖÚ¶Ô¿ÉÄÜ·ºÆðȼÁ϶ÌȱµÄµ£ÓÇ¡£¸ÃʼþÓÚ11ÔÂ27ÈÕ±»·¢ÏÖ£¬ÆÈʹRECOPEʵʩÊÖ¶¯Á÷³Ì£¬Êý×ÖÖ§¸¶ÏµÍ³ÊÜ×裬ȼÁÏ·ÖÅäÒ²Êܵ½Ó°Ïì¡£RECOPEÂôÁ¦¹ÜÀíÈ«¹úȼÁϽø¿Ú¡¢ÌáÁ¶ºÍ·ÖÅ䣬°üÂÞÖØÒª¹ÜµÀ£¬´Ë´Î¹¥»÷¶ÔÆäÔËÓª´øÀ´ÁËÌôÕ½£¬ÓÈÆäÊÇÔÚÓ͹޳µÈ¼ÁÏÂëÍ·¡£¾¡¹ÜRECOPEÈ·ÈÏȼÁÏ´¢Ð×㣬µ«¹«ÖÚµ£Óǵ¼ÖÂȼÁÏÏúÊÛ¼¤Ôö£¬¹«Ë¾²»µÃ²»ÑÓ³¤ÔËӪʱ¼ä¡£ÔÚÃÀ¹úÍøÂçÄþ¾²×¨¼ÒµÄÐÖúÏ£¬RECOPEÒÑ¿ªÊ¼²¿ÃŻָ´ÏµÍ³£¬µ«ÔÚÈ«Ãæ»Ö¸´Ç°ÐèÈ·±£»ù´¡ÉèÊ©Äþ¾²¡£ÕâһʼþÊÇÕë¶Ô¸ç˹´ïÀè¼ÓÒªº¦»ù´¡ÉèÊ©ÍøÂç¹¥»÷Ç÷ÊƵÄÑÓÐø£¬Ö®Ç°ContiÀÕË÷Èí¼þ×éÖ¯ÒÑ·¢¶¯¹ýÀàËƹ¥»÷£¬µ¼Ö»ù±¾·þÎṉ̃»¾£¬ÆÈʹ×ÜͳÐû²¼½ô¼±×´Ì¬²¢»ñµÃÃÀ¹úÔ®Öú¡£¾¡¹ÜÓйز¿ÃÅ·ñÈϸü¶à¹¥»÷µÄÒ¥ÑÔ£¬µ«RECOPEʼþ͹ÏÔÁËÒªº¦»ù´¡ÉèÊ©Ò×ÊÜÍøÂçÍþвµÄÏÖ×´£¬Ïà¹Ø²¿ÃŽ«»ý¼«¼ÓÈëÖ§³ÖÆä»Ö¸´ÊÂÇé¡£
https://securityonline.info/recope-costa-ricas-state-owned-energy-provider-grapples-with-ransomware-attack-and-fuel-supply-disruption/
4. ÂÞÂíÄáÑÇÑ¡¾ÙϵͳÔâÊÜÁè¼Ý 85,000 ´ÎÍøÂç¹¥»÷
12ÔÂ5ÈÕ£¬ÂÞÂíÄáÑÇÇ鱨¾ÖµÄÒ»·Ý½âÃܳÂËßÖ¸³ö£¬¸Ã¹úÑ¡¾Ù»ù´¡ÉèÊ©ÔÚ×Üͳѡ¾ÙÆÚ¼äÔâÊÜÁËÁè¼Ý85,000´ÎÍøÂç¹¥»÷£¬¹¥»÷Ô´×Ô33¸ö¹ú¼Ò¡£¹¥»÷ÕßÈëÇÖÁËһ̨°üÂÞµØͼÊý¾ÝµÄ·þÎñÆ÷£¬²¢Ð¹Â¶ÁËÓëÑ¡¾ÙÏà¹ØµÄÍøÕ¾µÄÕË»§Æ¾Ö¤ÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳ÉÏ¡£ÕâЩ¹¥»÷Á¬Ðøµ½µÚÒ»ÂÖ×Üͳѡ¾ÙºóµÄµÚ¶þÌ죬Ŀ±ê°üÂÞÆÆ»µÑ¡¾Ù»ù´¡ÉèÊ©¡¢¸ü¸Ä¹«ÖÚÑ¡¾ÙÐÅÏ¢ºÍ¾Ü¾ø·ÃÎÊϵͳ¡£ÂÞÂíÄáÑÇÇ鱨»ú¹¹¾¯¸æ³Æ£¬Ñ¡¾Ù»ù´¡ÉèÊ©ÈÔ´æÔÚ©¶´£¬¿ÉÄܻᱻÀûÓýøÐÐÍøÂçºáÏòÒƶ¯ºÍ½¨Á¢³Ö¾ÃÐÔ¡£´ËÍ⣬³ÂËß»¹Ö¸³ö£¬Áè¼Ý100ÃûÂÞÂíÄáÑÇTikTokÓ°ÏìÕß±»ÀûÓÃÀ´·Ö·¢Ðû´«×ÜͳºòÑ¡ÈË¿¨ÁÖ¡¤ÇÇÖÎ˹¿âµÄÑ¡¾ÙÄÚÈÝ£¬ÕâЩÕË»§ÔÚÑ¡¾ÙÈÕÇ°Á½ÖܱäµÃ·Ç³£»îÔ¾£¬ÆäÖÐһЩÕË»§ÉõÖÁ´Ó2016Äê´´½¨µ«Ö±µ½½üÆڲſªÊ¼»îÔ¾¡£ÂÞÂíÄáÑǶÔÍâÇ鱨¾ÖÖ¸³ö£¬¶íÂÞ˹½üÆÚÓиÉÔ¤ÆäËû¹ú¼ÒÑ¡¾ÙµÄÀúÊ·£¬²¢½«ÂÞÂíÄáÑÇÊÓΪµÐ¹ú£¬ÒòΪÂÞÂíÄáÑÇÔÊÐí±±Ô¼ÔÚ±±Ô¼¶«²¿×¤¾ü¡£
https://www.bleepingcomputer.com/news/security/romanias-election-systems-targeted-in-over-85-000-cyberattacks/
5. ÀÕË÷Èí¼þ×éÖ¯Brain CipherÉù³ÆÈëÇÖµÂÇÚÓ¢¹ú
12ÔÂ4ÈÕ£¬ÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ×éÖ¯Brain CipherÉù³ÆÒÑÀÖ³ÉÈëÇÖµÂÇÚÓ¢¹ú¹«Ë¾£¬²¢ÇÔÈ¡ÁËÁè¼Ý1TBµÄÃô¸ÐÊý¾Ý¡£¸Ã×éÖ¯ÓÚ2024Äê6Ô·ºÆð£¬Ôø¶ÔÈ«Çò¶à¸ö×éÖ¯½øÐÐÍøÂç¹¥»÷£¬°üÂÞ¶ÔÓ¡¶ÈÄáÎ÷Ñǹú¼ÒÊý¾ÝÖÐÐĵÄÖØ´ó¹¥»÷¡£¾ÝBrain CipherÐû²¼µÄÉùÃ÷£¬´Ë´Î¹¥»÷̻¶Á˵ÂÇÚÓ¢¹úÍøÂçÄþ¾²»ù´¡ÉèÊ©µÄ©¶´¡£ËûÃǼƻ®Ðû²¼´Ë´ÎÈëÇÖµÄÏêϸÐÅÏ¢£¬°üÂÞÉæÏÓÎ¥·´Äþ¾²ÐÒéµÄÖ¤¾Ý¡¢µÂÇÚÓë¿Í»§Ö®¼äµÄºÏͬÐÒé·ÖÎö¡¢¼à¿ØϵͳºÍÄþ¾²¹¤¾ßµÄÏêϸÐÅÏ¢ÒÔ¼°ÊÜËðÊý¾ÝµÄʾÀý¡£´ËÍ⣬¸Ã×éÖ¯ÒÑÑûÇëµÂÇÚ´ú±í½øÐÐ˽ÏÂÌÖÂÛ£¬Õâ¿ÉÄܱíÃ÷´æÔÚÊê½ð̸ÅеÄÆóͼ¡£´Ë´Îй¶Ê¼þ¿ÉÄÜÓ°ÏìµÂÇÚÓ¢¹úµÄÆóÒµ¿Í»§¡¢»úÃÜÉÌÒµÐÅÏ¢¡¢¿Í»§Êý¾ÝºÍ²ÆÕþ¼Ç¼ÒÔ¼°¸Ã¹«Ë¾µÄרҵÉùÓþ¡£È»¶ø£¬µÂÇÚÓ¢¹úÉÐδ¹ûȻȷÈÏ»ò·ñÈÏ´Ë´ÎÈëÇÖʼþ£¬ÍøÂçÄþ¾²ÐÂÎÅÍŶÓÕýÔÚÃÜÇйØ×¢ÊÂ̬Éú³¤¡£
https://cybersecuritynews.com/deloitte-hacked/
6. ¶íÂÞ˹·¨Ê½Ô±ÊÖ»ú±»FSB¹é»¹ºó·¢ÏÖÔâÃØÃÜ°²×°Ð¼äµýÈí¼þ
12ÔÂ5ÈÕ£¬Ò»Ãû¶íÂÞ˹·¨Ê½Ô±Kirill ParubetsÔÚ±»¶íÂÞ˹Áª°îÄþ¾²¾Ö£¨FSB£©¾ÐÁô15Ì첢ûÊÕÊÖ»úºó£¬·¢ÏÖÉ豸Ôڹ黹ºó±»ÃØÃÜ°²×°ÁËеļäµýÈí¼þ¡£¸Ã¼äµýÈí¼þÄ£·ÂÁËÁ÷ÐеÄAndroidÓ¦Ó÷¨Ê½¡°Cube Call Recorder¡±£¬µ«ÓµÓй㷺µÄȨÏÞ£¬¿ÉÒÔ²»ÊÜÏÞÖƵطÃÎÊÉ豸£¬²¢ÔÊÐí¹¥»÷Õß¼àÊÓÊÖ»úÉϵĻ¡£¾¹ý¹«ÃñʵÑéÊÒµÄÈ¡Ö¤·ÖÎö£¬È·ÈϸöñÒâÈí¼þÊÇMonokleµÄа汾»òÓÉÏàͬ´úÂë´´½¨µÄÐÂÈí¼þ¡£¸Ã¼äµýÈí¼þʹÓüÓÃܵÄÁ½½×¶Î¹ý³Ì£¬¾ßÓиú×ÙλÖᢷÃÎʶÌÐÅ¡¢ÁªÏµÈË¡¢ÈÕÀú¡¢¼Ç¼µç»°ºÍÊÓƵ¡¢ÌáÈ¡ÏûÏ¢¡¢ÎļþºÍÃÜÂëµÈ¶àÖÖ¹¦Ð§¡£´ËÍ⣬´úÂëÖз¢ÏÖÁ˶ÔiOSµÄÒýÓ㬱íÃ÷¿ÉÄÜ´æÔÚ¿ÉÔÚApple iPhoneÉ豸ÉÏÔËÐеıäÌå¡£É豸±»Ö´·¨²¿ÃÅûÊÕºóÓÖ±»¹é»¹µÄÈËÓ¦¿¼ÂÇ»»ÓÃÆäËûÉ豸»ò½»¸øר¼Ò·ÖÎö£¬Éú»îÔÚѹÆÈÐÔ¹ú¼ÒµÄÈËÓ¦½ÓÄÉ´ëÊ©±£»¤×Ô¼ºµÄÉ豸Äþ¾²¡£
https://www.bleepingcomputer.com/news/security/new-android-spyware-found-on-phone-seized-by-russian-fsb/