6K+ AI Ä£×Ó¿ÉÄÜÊܵ½ÑÏÖØ RCE Îó²îµÄÓ°Ïì

Ðû²¼Ê±¼ä 2024-05-21
1. 6K+ AI Ä£×Ó¿ÉÄÜÊܵ½ÑÏÖØ RCE Îó²îµÄÓ°Ïì


5ÔÂ17ÈÕ £¬£¬£¬ £¬ £¬£¬£¬ÓÃÓÚ´óÓïÑÔÄ£×Ó (LLM) µÄÊ¢ÐÐ Python °üÖеÄÒ»¸öÑÏÖØÎó²î¿ÉÄÜ»áÓ°Ïì 6,000 ¶à¸öÄ£×Ó £¬£¬£¬ £¬ £¬£¬£¬²¢¿ÉÄܵ¼Ö¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ªÔ´llama-cpp-python°ü±»·¢Ã÷ÈÝÒ×Êܵ½Ð§ÀÍÆ÷¶ËÄ£°å×¢ÈëµÄ¹¥»÷ £¬£¬£¬ £¬ £¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪ CVE-2024-34359 £¬£¬£¬ £¬ £¬£¬£¬ÓÉÇå¾²Ñо¿Ô±ºÍ¿ª·¢Ö°Ô± Patrick Peng ·¢Ã÷ £¬£¬£¬ £¬ £¬£¬£¬ËûµÄÔÚÏßÕ˺ÅΪ Retro0reg¡£¡£¡£¡£¡£llama-cpp-python °üΪÆÕ±éÊ¢ÐÐµÄ llama.cpp ¿âÌṩ Python °ó¶¨£»£»£»£»llama.cpp ÊÇÒ»¸ö C++ ¿â £¬£¬£¬ £¬ £¬£¬£¬ÓÃÓÚÔÚСÎÒ˽¼ÒÅÌËã»úÉÏÔËÐÐ Meta µÄ LLaMA µÈ LLM ºÍ Mitral AI µÄÄ£×Ó¡£¡£¡£¡£¡£llama-cpp-python °ü½øÒ»²½Ê¹¿ª·¢Ö°Ô±Äܹ»½«ÕâЩ¿ªÔ´Ä£×Ó¼¯³Éµ½ Python ÖС£¡£¡£¡£¡£CVE-2024-34359µÄ CVSS Òªº¦·ÖÊýΪ 9.7 £¬£¬£¬ £¬ £¬£¬£¬ÓÉÓÚ Jinja2 Ä£°åÒýÇæµÄʵÑé²»µ± £¬£¬£¬ £¬ £¬£¬£¬±£´æ RCE Σº¦¡£¡£¡£¡£¡£Peng ÔÚ²©¿ÍÎÄÕÂÖÐÚ¹ÊÍ˵ £¬£¬£¬ £¬ £¬£¬£¬¸ÃȱÏÝÔÊÐí Jinja2 ÆÊÎö´æ´¢ÔÚÔªÊý¾ÝÖеÄ̸ÌìÄ£°å £¬£¬£¬ £¬ £¬£¬£¬¶øÎÞÐè¾ÙÐÐÕûÀí»òɳÏä´¦Öóͷ£ £¬£¬£¬ £¬ £¬£¬£¬´Ó¶øÎª¹¥»÷Õß×¢Èë¶ñÒâÄ£°å´´Á¢ÁËʱ»ú¡£¡£¡£¡£¡£


https://www.scmagazine.com/news/6k-plus-ai-models-may-be-affected-by-critical-rce-vulnerability


2. Grandoreiro ÒøÐÐľÂí´ø×ÅÖØ´ó¸üлعé


5ÔÂ20ÈÕ £¬£¬£¬ £¬ £¬£¬£¬¾Ý IBM ³Æ £¬£¬£¬ £¬ £¬£¬£¬Ò»ÖÖ¶à²úµÄÒøÐÐľÂíÔÚ¶à¸öлÖÐÖØÐ·ºÆð £¬£¬£¬ £¬ £¬£¬£¬ÆäÔöÇ¿µÄ¹¦Ð§Ö¼ÔÚʹÆä³ÉΪ¸üǿʢµÄÍþв¡£¡£¡£¡£¡£Õâ¼Ò¿Æ¼¼¾ÞÍ·µÄ X-Force ÍøÂçÇå¾²²¿·ÖÌåÏÖ £¬£¬£¬ £¬ £¬£¬£¬×Ô 3 Ô·ÝÒÔÀ´ £¬£¬£¬ £¬ £¬£¬£¬ËüÒ»Ö±ÔÚ×·×ÙÊýÆð´ó¹æÄ£ÍøÂç´¹Âڻ¡£¡£¡£¡£¡£ÆäÖаüÀ¨Ã°³äÄ«Î÷¸ç˰ÎñÖÎÀí¾Ö (SAT)¡¢Áª°îµçÁ¦Î¯Ô±»á (CFE) ºÍÐÐÕþºÍ²ÆÎñ²¿³¤¡¢ÒÔ¼°°¢¸ù͢˰Îñ¾ÖºÍÄÏ·Ç˰Îñ¾Ö (SARS) µÄ¹¥»÷¡£¡£¡£¡£¡£IBM X-Force ÌåÏÖ£º¡°ÔÚÿ´Î»î¶¯ÖÐ £¬£¬£¬ £¬ £¬£¬£¬ÎüÊÕÕß¶¼»á±»Ö¸Ê¾µã»÷Á´½ÓÀ´Éó²é·¢Æ±»òÓöȡ¢ÕË»§¶ÔÕ˵¥¡¢¸¶¿îµÈ £¬£¬£¬ £¬ £¬£¬£¬Ïêϸȡ¾öÓÚ±»Ã°³äµÄʵÌå¡£¡£¡£¡£¡£¡±¡°ÈôÊǵã»÷Á´½ÓµÄÓû§Î»ÓÚÌØ¶¨¹ú¼Ò/µØÇø£¨Ïêϸȡ¾öÓڻ £¬£¬£¬ £¬ £¬£¬£¬Ä«Î÷¸ç¡¢ÖÇÀû¡¢Î÷°àÑÀ¡¢¸ç˹´ïÀè¼Ó¡¢ÃØÂ³»ò°¢¸ùÍ¢£© £¬£¬£¬ £¬ £¬£¬£¬ËûÃǽ«±»Öض¨Ïòµ½ PDF ͼ±êͼÏñºÍ ZIP ÎļþÊÇÔÚºǫ́ÏÂÔØµÄ¡£¡£¡£¡£¡£ZIP Îļþ°üÀ¨Ò»¸öÓà PDF ͼ±êαװµÄ´óÐÍ¿ÉÖ´ÐÐÎļþ £¬£¬£¬ £¬ £¬£¬£¬·¢Ã÷ÊÇÔÚµç×ÓÓʼþ·¢Ë͵ÄǰһÌì»òµ±Ì콨ÉèµÄ¡£¡£¡£¡£¡£¡±


https://www.infosecurity-magazine.com/news/grandoreiro-banking-trojan-major/?&web_view=true


3. Kinsing ºÚ¿Í×é֯ʹÓøü¶àȱÏÝÀ´À©Õ¹Õë¶Ô½©Ê¬ÍøÂç


5ÔÂ17ÈÕ £¬£¬£¬ £¬ £¬£¬£¬ÃûΪKinsingµÄ¼ÓÃÜÐ®ÖÆ×éÖ¯ÒѾ­Õ¹ÏÖ³öÒ»Ö±Éú³¤ºÍ˳ӦµÄÄÜÁ¦ £¬£¬£¬ £¬ £¬£¬£¬Í¨¹ýѸËÙ½«ÐÂÅû¶µÄÎó²î¼¯³Éµ½Îó²îʹÓÿâÖв¢À©Õ¹Æä½©Ê¬ÍøÂç £¬£¬£¬ £¬ £¬£¬£¬ÊÂʵ֤ʵ¸Ã×éÖ¯ÊÇÒ»¸öÒ»Á¬µÄÍþв¡£¡£¡£¡£¡£¸ÃÊÓ²ìЧ¹ûÀ´×ÔÔÆÇå¾²¹«Ë¾ Aqua £¬£¬£¬ £¬ £¬£¬£¬¸Ã¹«Ë¾½«ÍþвÐÐΪÕßÐÎòΪ×Ô 2019 ÄêÒÔÀ´Æð¾¢²ß»®²»·¨¼ÓÃÜÇ®±ÒÍÚ¿ó»î¶¯¡£¡£¡£¡£¡£Kinsing£¨ÓÖÃûH2Miner£©ÊǶñÒâÈí¼þ¼°Æä±³ºóµÄµÐÊÖµÄÃû×Ö £¬£¬£¬ £¬ £¬£¬£¬ËüһֱʹÓÃеÄÎó²îÀ©Õ¹Æä¹¤¾ß°ü £¬£¬£¬ £¬ £¬£¬£¬½«ÊÜѬȾµÄϵͳע²áµ½¼ÓÃÜÍÚ¾ò½©Ê¬ÍøÂçÖС£¡£¡£¡£¡£TrustedSec ÓÚ 2020 Äê 1 ÔÂÊ״μͼÁËËü¡£¡£¡£¡£¡£½üÄêÀ´ £¬£¬£¬ £¬ £¬£¬£¬Éæ¼°»ùÓÚ Golang µÄ¶ñÒâÈí¼þµÄ»î¶¯Ê¹ÓÃÁËApache ActiveMQ¡¢Apache Log4j¡¢Apache NiFi¡¢Atlassian Confluence¡¢Citrix¡¢Liferay Portal¡¢Linux¡¢Openfire¡¢Oracle WebLogic ServerºÍSaltStackÖеÄÖÖÖÖȱÏÝÀ´ÆÆËðÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£


https://thehackernews.com/2024/05/kinsing-hacker-group-exploits-more.html?&web_view=true


4. 240 ÍòÈËÊܵ½ WebTPA Êý¾Ýй¶µÄÓ°Ïì


5ÔÂ20ÈÕ £¬£¬£¬ £¬ £¬£¬£¬WebTPA ¹ÍÖ÷ЧÀ͹«Ë¾Åû¶ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ £¬£¬£¬ £¬ £¬£¬£¬Ó°ÏìÁËÁè¼Ý 240 ÍòÈ˵ÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£WebTPA ×ܲ¿Î»Óڵ¿ËÈøË¹ÖÝÅ·ÎÄ £¬£¬£¬ £¬ £¬£¬£¬ÊÇ GuideWell Mutual Holding Corporation µÄÈ«×Ê×Ó¹«Ë¾ £¬£¬£¬ £¬ £¬£¬£¬ÊÇÒ»¼ÒרÃÅ´ÓÊ¿µ½¡°ü¹ÜºÍ¸£ÀûÍýÏëµÄµÚÈý·½ÖÎÀí»ú¹¹ (TPA)¡£¡£¡£¡£¡£WebTPA ÔÚÆäÍøÕ¾ÉϵÄÒ»·Ý֪ͨÖÐÌåÏÖ £¬£¬£¬ £¬ £¬£¬£¬¸ÃÍøÂçÊÂÎñÊÇÔÚÆäÍøÂçÉϼì²âµ½¿ÉÒɻµÄÖ¤¾ÝºóÓÚ 2023 Äê 12 Ô 28 ÈÕ·¢Ã÷µÄ¡£¡£¡£¡£¡£¶Ô´ËʵÄÊÓ²ìÏÔʾ £¬£¬£¬ £¬ £¬£¬£¬Ò»ÃûÍþвÐÐΪÕßÔÚ 2023 Äê 4 Ô 18 ÈÕÖÁ 23 ÈÕʱ´ú´ÓÆäϵͳÖÐÇÔÈ¡ÁËСÎÒ˽¼ÒÐÅÏ¢ £¬£¬£¬ £¬ £¬£¬£¬°üÀ¨ÐÕÃû¡¢ÁªÏµÐÅÏ¢¡¢³öÉúÈÕÆÚ¡¢éæÃüÈÕÆÚ¡¢°ü¹ÜÐÅÏ¢ºÍÉç»áÇå¾²ºÅÂë¡£¡£¡£¡£¡£Æ¾Ö¤ TPA µÄ˵·¨ £¬£¬£¬ £¬ £¬£¬£¬Ì»Â¶µÄÊý¾ÝÒòÈ˶øÒì¡£¡£¡£¡£¡£²ÆÎñÐÅÏ¢¡¢ÐÅÓÿ¨ºÅÂëÒÔ¼°¿µ½¡ºÍÒ½ÁÆÐÅϢδÊܵ½¸ÃÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£


https://www.securityweek.com/2-4-million-impacted-by-webtpa-data-breach/


5. Singing River Ò½ÁÆÏµÍ³ÀÕË÷Èí¼þ¹¥»÷Ó°Ïì½ü 90 ÍòÈË


5ÔÂ20ÈÕ £¬£¬£¬ £¬ £¬£¬£¬Singing River Health System ÌåÏÖ £¬£¬£¬ £¬ £¬£¬£¬2023 Äê 8 ÔµÄÀÕË÷Èí¼þ¹¥»÷Ó°ÏìÁË 895,204 ÈË¡£¡£¡£¡£¡£Õâ¼Ò×ܲ¿Î»ÓÚÃÜÎ÷Î÷±ÈÖݵÄÒ½ÁƱ£½¡ÌṩÉÌÔÚÄ«Î÷¸çÍåÑØ°¶µØÇøÔËÓª×Ŷà¼ÒÒ½ÔººÍÒ½ÁÆÉèÊ©¡£¡£¡£¡£¡£Æ¾Ö¤Êý¾Ýй¶֪ͨ £¬£¬£¬ £¬ £¬£¬£¬Ì»Â¶µÄÐÅÏ¢°üÀ¨£ºÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢ÎïÀíµØµã¡¢Éç»áÇå¾²ºÅÂë (SSN)ºÍÒÔ¼°Ò½ÁƺͿµ½¡ÐÅÏ¢¡£¡£¡£¡£¡£Ö»¹Ü±£´æÊý¾Ý±»µÁµÄÇéÐÎ £¬£¬£¬ £¬ £¬£¬£¬µ«ÏÖÔÚûÓÐÖ¤¾ÝÅú×¢Éí·Ý±»µÁ»òڲƭ¡£¡£¡£¡£¡£¸Ã×é֯ͨ¹ý IDX ÏòÊÜÓ°ÏìµÄÈËÌṩ 24 ¸öÔµÄÐÅÓÃ¼à¿ØºÍÉí·Ý»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£Bleeping ComputerÚ¹ÊÍ˵ £¬£¬£¬ £¬ £¬£¬£¬¾Ý±¨µÀ £¬£¬£¬ £¬ £¬£¬£¬ËûÃÇй¶ÁËԼĪ 80% µÄ±»µÁÊý¾Ý £¬£¬£¬ £¬ £¬£¬£¬ÆäÖаüÀ¨ 420,766 ¸öÎļþ£¨754 GB£©µÄĿ¼¡£¡£¡£¡£¡£


https://heimdalsecurity.com/blog/singing-river-health-system-ransomware-attack-affects-nearly-900000/


6. ÍøÂç·¸·¨·Ö×ÓʹÓÃGitHubºÍFileZillaÈö²¥¶ñÒâÈí¼þ


5ÔÂ20ÈÕ £¬£¬£¬ £¬ £¬£¬£¬¾ÝÊÓ²ì £¬£¬£¬ £¬ £¬£¬£¬Ò»³¡¡°¶à·½ÃæµÄ»î¶¯¡±ÀÄÓà GitHub ºÍ FileZilla µÈÕýµ±Ð§ÀÍ £¬£¬£¬ £¬ £¬£¬£¬Í¨¹ýð³ä¿ÉÐÅÈí¼þ£¨Èç1Password¡¢Bartender 5 ºÍ Pixelmator Pro¡£¡£¡£¡£¡£Recorded Future µÄ Insikt GroupÔÚÒ»·Ý±¨¸æÖÐÌåÏÖ£º¡°¶àÖÖ¶ñÒâÈí¼þ±äÌåµÄ±£´æÅú×¢ÎúÆÕ±éµÄ¿çƽ̨ĿµÄÕ½ÂÔ £¬£¬£¬ £¬ £¬£¬£¬¶øÖصþµÄ C2 »ù´¡ÉèÊ©ÔòÅú×¢Îú¼¯ÖÐʽÏÂÁîÉèÖà £¬£¬£¬ £¬ £¬£¬£¬Õâ¿ÉÄÜ»áÌá¸ß¹¥»÷µÄЧÂÊ¡£¡£¡£¡£¡£¡±Õâ¼ÒÃûΪ GitCaught µÄÍøÂçÇå¾²¹«Ë¾ÕýÔÚ×·×ÙÕâÒ»»î¶¯ £¬£¬£¬ £¬ £¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ £¬£¬£¬ £¬ £¬£¬£¬¸Ã»î¶¯²»µ«Í¹ÏÔÁËÀÄÓÃÕæÊµ»¥ÁªÍøÐ§ÀÍÀ´²ß»®ÍøÂç¹¥»÷ £¬£¬£¬ £¬ £¬£¬£¬²¢ÇÒ»¹ÒÀÀµÓÚÕë¶Ô Android¡¢macOS ºÍ Windows µÄ¶àÖÖ¶ñÒâÈí¼þ±äÌåÀ´Ìá¸ßÀÖ³ÉÂÊ¡£¡£¡£¡£¡£ËÙÂÊ¡£¡£¡£¡£¡£¹¥»÷Á´ÐèҪʹÓà GitHub ÉϵÄÐéαÉèÖÃÎļþºÍ´æ´¢¿â £¬£¬£¬ £¬ £¬£¬£¬ÍйÜ×ÅÃûÈí¼þµÄð³ä°æ±¾ £¬£¬£¬ £¬ £¬£¬£¬Ä¿µÄÊÇ´ÓÊÜѬȾװ±¸»ñÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£È»ºó £¬£¬£¬ £¬ £¬£¬£¬ÕâЩ¶ñÒâÎļþµÄÁ´½Ó»áǶÈëµ½¼¸¸öÓòÖÐ £¬£¬£¬ £¬ £¬£¬£¬ÕâЩÓòͨ³£Í¨¹ý¶ñÒâ¹ã¸æºÍ SEO Öж¾»î¶¯¾ÙÐзַ¢¡£¡£¡£¡£¡£


https://thehackernews.com/2024/05/cyber-criminals-exploit-github-and.html