ºÚ¿ÍʹÓà Aiohttp Îó²îÑ°ÕÒÒ×Êܹ¥»÷µÄÄ¿µÄ

Ðû²¼Ê±¼ä 2024-03-18
1. ºÚ¿ÍʹÓà Aiohttp Îó²îÑ°ÕÒÒ×Êܹ¥»÷µÄÄ¿µÄ


3ÔÂ16ÈÕ£¬ÀÕË÷Èí¼þ¹¥»÷Õß¡°ShadowSyndicate¡±ÕýÔÚɨÃèÒ×ÊÜ CVE-2024-23334£¨aiohttp Python ¿âÖеÄĿ¼±éÀúÎó²î£©Ó°ÏìµÄ·þÎñÆ÷¡£Aiohttp ÊÇÒ»¸ö¹¹½¨ÔÚ Python Òì²½ I/O ¿ò¼Ü Asyncio Ö®ÉϵĿªÔ´¿â£¬ÓÃÓÚ´¦Öóͷ£´ó×Ú²¢·¢ HTTP ÇëÇ󣬶øÎÞÐè¹Å°åµÄ»ùÓÚÏ̵߳ÄÍøÂç¡£2024 Äê 1 Ô 28 ÈÕ£¬aiohttp Ðû²¼ÁË °æ±¾ 3.9.2£¬½â¾öÁË CVE-2024-23334£¬ÕâÊÇÒ»¸öÑÏÖصÄ·¾¶±éÀúÎó²î£¬Ó°Ïì 3.9.1 ¼°¸üÔç°æ±¾µÄËùÓÐ aiohttp °æ±¾£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»á¼ûÒ×Êܹ¥»÷µÄ·þÎñÆ÷ÉϵÄÎļþ¡£¸ÃȱÏÝÊÇÓÉÓÚµ±¾²Ì¬Â·Óɵġ°follow_symlinks¡±ÉèÖÃΪ¡°True¡±Ê±ÑéÖ¤²»³ä·Ö£¬´Ó¶øÔÊÐíδ¾­ÊÚȨ»á¼û·þÎñÆ÷¾²Ì¬¸ùĿ¼֮ÍâµÄÎļþ¡£ShadowSyndicate ÊÇÒ»¸öʱ»úÖ÷Òå¡¢ ¾­¼ÃÄîÍ·µÄÍþвÐÐΪÕߣ¬×Ô 2022 Äê 7 ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Óë Quantum¡¢Nokoyawa¡¢BlackCat/ALPHV¡¢Clop¡¢Royal¡¢Cactus ºÍ Play µÈÀÕË÷Èí¼þ¾úÖêÓвî±ðˮƽµÄÐÅÍС£Group-IB ÒÔΪÍþвÐÐΪÕßÊÇÓë¶à¸öÀÕË÷Èí¼þÔËÓª»ú¹¹ÏàÖúµÄÁ¥Êô»ú¹¹¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-aiohttp-bug-to-find-vulnerable-networks/


2. ·¨¹ú TRAVAIL Êý¾Ýй¶ӰÏì 4300 ÍòÈË


3ÔÂ16ÈÕ£¬·¨¹úÍøÂç·¸·¨Ô¤·ÀÍýÏë¾ÙÐеÄÊÓ²ìÏÔʾ£¬ÍþвÐÐΪÕßÔÚ 2024 Äê 2 Ô 6 ÈÕÖÁ 3 Ô 5 ÈÕʱ´úÇÔÈ¡ÁË 4300 ÍòÈ˵ÄСÎÒ˽¼ÒÐÅÏ¢¡£2023 Äê 8 Ô£¬·¨¹úÕþ¸®¾ÍÒµ»ú¹¹ P?le emploiÔâÓöÊý¾Ýй¶£¬²¢Í¨ÖªÁËÊÜÇå¾²Îó²îÓ°ÏìµÄ 1000 ÍòÈË¡£´Ë´ÎÇå¾²Îó²î̻¶ÁËÊÜÓ°ÏìСÎÒ˽¼ÒµÄÐÕÊÏ¡¢Ãû×ÖºÍÉç»áÇå¾²ºÅÂë¡£µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÃÜÂëºÍ²ÆÎñÊý¾Ý²»»á±»Ð¹Â¶¡£¸Ã»ú¹¹½¨ÒéÇóÖ°Õ߶ÔÈκÎDZÔÚµÄڲƭÔ˶¯¼á³ÖСÐÄ£¬¸Ã»ú¹¹»¹Ôö²¹Ëµ£¬¸Ã»ú¹¹ÌṩµÄÅâ³¥ºÍÖ§³ÖÒÔ¼°»á¼û polo-emploi.frµÄСÎÒ˽¼Ò¿Õ¼ä²»±£´æÈκÎΣº¦¡£·¨¹úÕþ¸®²¢Î´½«Õâ´Î¹¥»÷¹é×ïÓÚÒÑÖªµÄÀÕË÷Èí¼þÍŻ²»¹ý£¬Bleeping Computer ÊÓ²ì µ½£¬Çå¾²¹«Ë¾Emsisoft ÔÚÆä MOVEitÒ³ÃæÉÏÁгöÁ˸÷¨¹úÕþ¸®»ú¹¹ £¬ÕâÒâζ×ÅËüºÜ¿ÉÄÜÊÇClop ÀÕË÷Èí¼þÍÅ»ï µÄÊܺ¦Õß¡£


https://securityaffairs.com/160556/data-breach/france-travail-data-breach-34m-people.html


3. ºÚ¿ÍÉù³ÆÒѾ­¹¥ÆÆ Viber²¢ÇÔÈ¡ÁË 740GB Êý¾Ý


3ÔÂ16ÈÕ£¬Handala Hack ÔÚ Telegram Ìû×ÓÖÐÉù³ÆËûÃÇÇÔÈ¡ÁËÁè¼Ý 740GB µÄÊý¾Ý£¬ÆäÖаüÀ¨ Viber µÄÔ´´úÂë¡£¸Ã×éÖ¯ÒªÇóΪ±»µÁÐÅÏ¢Ö§¸¶ 8 ±ÈÌرң¨¼´ 583,000 ÃÀÔª£©µÄÊê½ð¡£Viber ÊÇÒ»¿îÐÂÎÅÓ¦ÓóÌÐò£¬ÓÚ 2010 ÄêÍƳö£¬²¢ÓÚ 2014 Äê±»ÈÕ±¾¿ç¹ú¹«Ë¾ÀÖÌ칫˾ÒÔ 9 ÒÚÃÀÔªÊÕ¹º£¬¸ÃÓ¦ÓóÌÐòÒѶԺڿ͵ÄÖ¸¿Ø×ö³öÁË»ØÓ¦¡£¸Ã¹«Ë¾·ñ¶¨ÓÐÈκÎÈëÇÖÆäϵͳ»òÊý¾Ý鶵ÄÖ¤¾Ý£¬µ«È·ÈÏÒÑÆô¶¯ÊÓ²ìÒÔºËʵÊÇ·ñ±¬·¢Çå¾²Îó²î¡£ÈôÊÇ»ñµÃ֤ʵ£¬Õâ¿ÉÄÜÊǽü´úÀúÊ·ÉÏ×î´óµÄÊý¾Ýй¶ÊÂÎñÖ®Ò»¡£×¨¼ÒÒÔΪ£¬ÕâÖÖй¶¿ÉÄÜÉ漰СÎÒ˽¼ÒÐÂÎÅ¡¢Í¨»°¼Í¼¡¢ÁªÏµ·½·¨ºÍ²ÆÎñÐÅÏ¢£¬¿ÉÄÜ»á¶Ô Viber Óû§Ôì³Éɱ¾øÐÔ¹¥»÷¡£Handala Hack ÊÇÒ»¸öÓÐÕùÒéµÄ×éÖ¯£¬ÒÔÖ§³Ö°ÍÀÕ˹̹ÊÂÒµµÄÒÔÉ«ÁÐʵÌå¼°ÆäÃËÓÑΪĿµÄ¶øÖøÃû¡£×Ô 2023 Äê 12 Ô½¨Éè Telegram ƵµÀ²¢Ëæºó¼ÓÈëÎ¥¹æÂÛ̳ÒÔÀ´£¬ËüÒ»Ö±ºÜ»îÔ¾¡£Óë´Ëͬʱ£¬Viber Óû§Ó¦ÉóÉ÷ÐÐʲ¢¸ü¸ÄÃÜÂ룬СÐÄÍøÂç´¹ÂÚʵÑ飬²¢Í¨¹ý¼ì²é Viber µÄ¹Ù·½ÇþµÀËæʱÏàʶÓйØÉæÏÓÊý¾Ý鶵ÄÈκθüС£


https://www.hackread.com/hackers-claim-740gb-of-data-viber-messaging-app/


4. ºÚ¿ÍʹÓà GitHub ÉϵÄÆƽâÈí¼þÈö²¥ RisePro


3ÔÂ16ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ðí¶à GitHub ´æ´¢¿âÌṩÆƽâÈí¼þ£¬ÕâЩÈí¼þÓÃÓÚÈö²¥ÃûΪ RisePro µÄÐÅÏ¢ÇÔÈ¡³ÌÐò¡£¾Ý G DATA ³Æ£¬¸ÃÔ˶¯´úºÅΪgitgub £¬°üÀ¨Óë 11 ¸ö²î±ðÕË»§Ïà¹ØµÄ 17 ¸ö´æ´¢¿â¡£ÒÔºó£¬Ïà¹Ø´æ´¢¿âÒѱ»Î¢ÈíÆìÏÂ×Ó¹«Ë¾É¾³ý¡£Github ÉÏͨ³£Ê¹ÓÃÂÌÉ«ºÍºìɫԲȦÀ´ÏÔʾ×Ô¶¯¹¹½¨µÄ״̬¡£Gitgub Íþв¼ÓÈëÕßÔÚËûÃÇµÄ README.md ÖÐÌí¼ÓÁËËĸöÂÌÉ« Unicode ԲȦ£¬Ã°³äÔÚÄ¿½ñÈÕÆÚÅÔ±ßÏÔʾ״̬£¬²¢ÌṩÕýµ±ÐÔºÍнü¶ÈµÄ¸ÐÊÜ¡£RAR ´æµµÒªÇóÊܺ¦ÕßÌṩ´æ´¢¿â README.md ÎļþÖÐÌáµ½µÄÃÜÂ룬ÆäÖаüÀ¨Ò»¸ö×°ÖóÌÐòÎļþ£¬¸ÃÎļþ½âѹÏÂÒ»½×¶ÎµÄÓÐÓøºÔØ£¬ÕâÊÇÒ»¸öÅòÕ͵½ 699 MB µÄ¿ÉÖ´ÐÐÎļþ£¬Ö¼ÔÚʹÆÊÎö¹¤¾ßÍ߽⣬ÀýÈçIDA רҵ°æ¡£¸ÃÎļþµÄÏÖʵÄÚÈÝ£¨×ܼƽöΪ 3.43 MB£©³äµ±¼ÓÔسÌÐò£¬½« RisePro£¨°æ±¾ 1.6£©×¢Èë AppLaunch.exe »ò RegAsm.exe ÖС£RisePro ÔÚ 2022 Äêµ×ͻȻ³ÉΪÈËÃǹØ×¢µÄ½¹µã£¬ÆäʱËüʹÓÃÃûΪ PrivateLoader µÄ°´×°Öø¶·Ñ (PPI) ¶ñÒâÈí¼þÏÂÔØ·þÎñ¾ÙÐзַ¢¡£


https://thehackernews.com/2024/03/hackers-using-cracked-software-on.html


5. ºÚ¿Íͨ¹ýÎäÆ÷»¯ PDF ÓÕÆ­Óû§×°ÖöñÒâÈí¼þ


3ÔÂ16ÈÕ£¬ÔÚÒ»³¡ÖØ´óµÄÍøÂç¹¥»÷Ô˶¯ÖУ¬¶ñÒâÐÐΪÕßð³ä¸çÂ×±ÈÑÇÕþ¸®»ú¹¹£¬Õë¶ÔÀ­¶¡ÃÀÖÞ¸÷µØµÄСÎÒ˽¼Ò¾ÙÐй¥»÷¡£¹¥»÷Õß·Ö·¢°üÀ¨ PDF ¸½¼þµÄµç×ÓÓʼþ£¬¹ýʧµØÖ¸¿ØÊÕ¼þÈËÎ¥·´½»Í¨¹æÔò»òÆäËûÎ¥·¨ÐÐΪ¡£ÕâЩÓÕÆ­ÐÔͨѶּÔÚÇ¿ÆÈÊܺ¦ÕßÏÂÔØ°üÀ¨ VBS ¾ç±¾µÄ´æµµ£¬´Ó¶øÆô¶¯¶à½×¶ÎѬȾÀú³Ì¡£Ö´Ðк󣬾­ÓÉ»ìÏýµÄ VBS ¾ç±¾»á´¥·¢ PowerShell ¾ç±¾£¬Í¨¹ýÁ½²½ÇëÇóÀú³Ì´ÓÕýµ±ÔÚÏß´æ´¢·þÎñÖмìË÷×îÖյĶñÒâÈí¼þ¸ºÔØ¡£Æ¾Ö¤ ANY.RUN Óë GBHackers ·ÖÏíµÄÇå¾²±¨¸æ £»×î³õ£¬¾ç±¾´Ó textbin.net µÈ×ÊÔ´»ñÈ¡ÓÐÓøºÔصĵص㡣Ȼºó£¬Ëü¼ÌÐø´ÓÌṩµÄµØµãÏÂÔز¢Ö´ÐÐÓÐÓøºÔØ£¬¸ÃÓÐÓøºÔØ¿ÉÒÔÍйÜÔÚÖÖÖÖƽ̨ÉÏ£¬°üÀ¨ cdn.discordapp(.)com¡¢pasteio(.)com¡¢hidrive.ionos.com ºÍ wtools.io¡£¹¥»÷ÕßµÄÖ´ÐÐÁ´×ñÕÕ´Ó PDF µ½ ZIP£¬È»ºóµ½ VBS ºÍ PowerShell£¬×îºóµ½¿ÉÖ´ÐÐÎļþ (EXE) µÄ˳Ðò¡£×îÖÕµÄÓÐÓøºÔر»Ê¶±ðΪ¼¸ÖÖÒÑÖªµÄÔ¶³Ì»á¼ûľÂí (RAT) Ö®Ò»£¬ÌØÊâÊÇAsyncRAT¡¢njRAT»òRemcos¡£ÕâЩ¶ñÒâ³ÌÐòÒòÆäÄܹ»¶ÔÊÜѬȾϵͳÌṩδ¾­ÊÚȨµÄÔ¶³Ì»á¼û¶øÎÛÃûÕÑÖø£¬¸øÊܺ¦ÕßµÄÒþ˽ºÍÊý¾ÝÇå¾²´øÀ´ÖØ´óΣº¦¡£


https://gbhackers.com/hackers-trick-users-to-install-malware-via-weaponized-pdf/


6. TikTok±»Òâ´óÀûî¿Ïµ»ú¹¹· £¿î½ü1100ÍòÃÀÔª


3ÔÂ16ÈÕ£¬Æ¾Ö¤¸Ã¹ú¾ºÕùÖÎÀí¾Ö (AGCM) µÄÒ»·ÝÐÂΟ壬Òâ´óÀûÕþ¸®ÖÜËÄ¶Ô TikTok ´¦ÒÔ 1090 ÍòÃÀÔª· £¿î£¬Ôµ¹ÊÔ­ÓÉÊÇÆäÖú³¤ÁË¿ÉÄÜËðº¦Óû§¡°ÐÄÀíÈËÉíÇå¾²¡±µÄÊÓƵÈö²¥¡£Õâ±Ê· £¿îÊǾ­ÓÉÒ»ÄêÊÓ²ìµÄЧ¹û£¬Ò»ÌìÇ°ÃÀ¹úÖÚÒéԺͶƱ¾öÒéÓÐÓÃեȡ¸Ãƽ̨£¬¹ú¾Û»áÔ±ÒªÇó¸Ãƽ̨×Ö½ÚÌø¶¯³·×Ê£¬²»È»½«±»Õ¥È¡ÔÚÃÀ¹úÔËÓª¡£AGCM ÌØÊâ¹Ø×¢¸Ãƽ̨ÔõÑù¶Ôδ³ÉÄêÈ˺ÍÈõÊÆȺÌ屬·¢¸ºÃæÓ°Ï죬ÌåÏÖ¶Ô¸Ãƽ̨Ëã·¨µÄÊӲ첿·ÖÊÇΪÁË»ØÓ¦ÔÚ¸ÃÓ¦ÓóÌÐòÉÏ·è´«µÄËùν¡°·¨¹ú°ÌºÛ¡±ÌôÕ½¡£¸ÃÌôÕ½ÒªÇóÓ¦ÓóÌÐòÓû§·ÖÏíÃ沿°ÌºÛµÄÊÓƵ£¬µ¼ÖÂÐí¶àÈËƤ·ôÊÜÉ˼ÓÈëÆäÖС£±ðµÄ£¬AGCM ÌåÏÖ£¬¸Ãƽ̨µÄÖ¸µ¼Ä¿µÄÊDz»·óµÄ£¬²¢Ö¸³ö£¬ÕâЩָµ¼Ä¿µÄµÄÓ¦Óá°Ã»Óгä·Ö˼Á¿µ½ÇàÉÙÄêµÄÏêϸųÈõÐÔ£¬ÆäÌصãÊÇÌØÊâµÄÈÏÖª»úÖÆ¡£Å·ÃËίԱ»áÉϸöÔÂÐû²¼£¬ÒÑÆô¶¯ÊӲ죬ÒÔÈ·¶¨ TiKTok ÊÇ·ñÒòδÄÜÑéÖ¤Óû§ÄêËê¡¢± £»¤Óû§Òþ˽ºÍ±ÜÃâÓû§×ÅÃÔ¸ÃÓ¦ÓöøÎ¥·´ÁËÅ·ÖÞ´ó½µÄÊý×Ö·þÎñ·¨ (DSA)¡£¸ÃÊÓ²ìµÄÖص㻹ÔÚÓÚ¸Ãƽ̨ÊÇ·ñͨ¹ý²»Í¸Ã÷µÄ¹ã¸æÐÐΪÒÔ¼°Î´Äܱ £»¤Î´³ÉÄêÈ˶øÎ¥·´ÁË DSA¡£


https://therecord.media/tiktok-italy-fine-regulator