CybleÅû¶ÀûÓÃαÔìChatGPTÀûÓ÷ַ¢¶ñÒâÈí¼þµÄ»î¶¯
°ä²¼¹¦·ò 2023-02-241¡¢CybleÅû¶ÀûÓÃαÔìChatGPTÀûÓ÷ַ¢¶ñÒâÈí¼þµÄ»î¶¯
2ÔÂ22ÈÕ£¬Cyble³Æ»ùÓÚChatGPTµÄ´¹µö¹¥»÷µÄÍþвԽÀ´Ô½´ó¡£ChatGPT×Ô2022Äê11ÔÂÍÆ³öÒÔÀ´»ñµÃÁ˾޴óµÄ³É¹¦£¬µ½2023Äê1ÔÂÓû§Òѳ¬¹ý1ÒÚ¡£Cyble¼ì²âµ½Á˶à¸ö´¹µöÍøÕ¾£¬ËüÃÇÔÚͨ¹ýÚ²ÆÐÔµÄOpenAIÉ罻ýÌåÒ³Ãæ½øÐÐÍÆ¹ã£¬À´´«²¼¸÷ÖÖÀàÐ͵ĶñÒâÈí¼þ¡£´Ë±í£¬Ò»Ð©´¹µöÍøÕ¾ÔÚ¼ÙÒâChatGPTÇÔÊØÐÅÓþ¿¨ÐÅÏ¢¡£×êÑÐÈËÔ±»¹¼ì²âµ½50¶à¸öʹÓÃChatGPTͼ±êµÄ¼ÙðºÍ¶ñÒâÀûÓã¬ÈçÀ¬»ø·¨Ê½¡¢¸æ°×Èí¼þºÍ¼äµýÈí¼þµÈ¡£
https://blog.cyble.com/2023/02/22/the-growing-threat-of-chatgpt-based-phishing-attacks/
2¡¢ÐµÄS1deload Stealer½Ù³ÖYoutubeºÍFacebookÕÊ»§
BitdefenderÔÚ2ÔÂ22ÈÕÅû¶ÁËжñÒâÈí¼þS1deload StealerÕë¶ÔÈ«ÇòµÄ¹¥»÷»î¶¯¡£ÔÚ2022Äê7Ôµ½12Ô£¬Bitdefender¼ì²âµ½600¶à¸öÓû§Ï°È¾ÁËÕâÖÖ¶ñÒâÈí¼þ¡£S1deload StealerÒÀ¸½DLL²àÔØ¼¼ÊõÀ´ÔËÐÐÆä¶ñÒâ×é¼þ£¬Ê¹ÓÃÁËÒ»¸öºÏ·¨µÄ¡¢¾¹ýÊý×ÖÊðÃûµÄ¿ÉÖ´ÐÐÎļþ¡£Ò»µ©³É¹¦Ï°È¾£¬¸Ã¶ñÒâÈí¼þ¾Í»áÇÔÈ¡Óû§Æ¾Ö¤£¬·ÂÕÕÈËÀàÐÐΪÀ´Ìá¸ßÊÓÆµºÍÆäËüÄÚÈݵIJμӶȣ¬ÆÀ¹ÀÓ×ÎÒÕË»§µÄ¼ÛÖµ£¬ÍÚ¾òBEAM¼ÓÃÜÇ®±Ò£¬²¢½«¶ñÒâÁ´½Ó´«²¼¸øÓû§µÄ·ÛË¿¡£
https://www.bitdefender.com/blog/labs/s1deload-stealer-exploring-theeconomics-of-social-networkaccount-hijacking/
3¡¢OyeTalk»áй¶Óû§µÄ̸Ìì¼Í¼Òѱ»×°Öó¬¹ý500Íò´Î
¾ÝýÌå2ÔÂ22ÈÕ±¨Â·£¬AndroidÓïÒô̸ÌìÀûÓÃй¶ÁËÓû§µÄ̸Ìì¼Í¼¡£¸ÃÀûÓÃÔÚGoogle PlayÉϵÄÏÂÔØÁ¿³¬¹ý500Íò´Î£¬ÆäFirebaseÊ·ýй¶Á˳¬¹ý500MBµÄÊý¾Ý£¬Ô̺¬Î´¼ÓÃܵÄÓû§Ì¸Ìì¼Í¼¡¢Óû§ÃûºÍÊÖ»ú¹ú¼ÊÒÆ¶¯É豸¼ø±ðÂë(IMEI)ºÅÂëµÈ¡£×êÑÐÈËÔ±°µÊ¾£¬ÈôÊÇûÓжÔй¶µÄÊý¾Ý½øÐб¸·Ý£¬¹¥»÷Õß¿ÉÄÜ»áɾ³ýÊý¾Ý¿âµ¼ÖÂÓû§µÄÓ×ÎÒÐÅÏ¢ÓÀÔ¼ûÔʧ¡£ÀûÓõĿª·¢ÈËÔ±ÔÚ»ñϤÊý¾Ýй¶ºóÈÔδÄÜÏÞ¶ÈÊý¾Ý¿âµÄ½Ó¼û£¬¹È¸è²»µÃ²»È¾Ö¸Éè·¨±£»¤¸ÃÊý¾Ý¿â¡£
https://www.hackread.com/android-voice-chat-app-data-leak/
4¡¢×êÑÐÈËÔ±¼ì²âµ½41¸ö¼Ù×°³ÉHTTP¿âµÄ¶ñÒâPyPI°ü
¾Ý2ÔÂ22ÈÕ±¨Â·£¬ReversingLabs×êÑÐÈËÔ±ÔÚPyPI´æ´¢¿âÖмì²âµ½41¸ö¼Ù×°³ÉHTTP¿âµÄ¶ñÒâ°ü¡£ÕâЩαÔìµÄHTTP¿âÖÐÔ̺¬Á½ÖÖ·ÖÆçÀàÐ͵ĶñÒâÄ£¿é£ºÏÂÔØ·¨Ê½£¬ÓÃÓÚÏò±»¹¥»÷µÄϵͳÌṩµÚ¶þ½×¶ÎµÄ¶ñÒâÈí¼þ£»ÐÅÏ¢ÇÔÈ¡·¨Ê½£¬Ô̺¬ÓÃÓÚÊý¾Ýй¶µÄ¶ñÒâÖ°ÄÜ¡£ÀýÈ磬ÐÅÏ¢ÇÔÈ¡·¨Ê½httpxv2¿ÉÍøÂçÃÜÂëºÍÁîÅÆµÈÃô¸ÐÊý¾Ý²¢·¢Ë͸ø¹¥»÷Õߣ¬ÏÂÔØ·¨Ê½httpsus½«¿ÉÒɵÄpayload°µ²ØÆðÀ´¡£
https://www.reversinglabs.com/blog/beware-impostor-http-libraries-lurk-on-pypi
5¡¢ÐºóÃÅWinorDLL64»ò±»LazarusÓÃÓÚÇÔÈ¡Ãô¸ÐÐÅÏ¢
¾ÝESET 2ÔÂ23ÈÕ±¨Â·£¬Lazarus Group¿ÉÄÜʹÓÃÁËÓëWslinkÓйصÄкóÃÅWinorDLL64¡£WinorDLL64ÊÇÒ»¸öÖ°ÄÜÆëÈ«µÄÖ²È뷨ʽ£¬Äܹ»Ð¹Â¶¡¢¸²¸ÇºÍɾ³ýÎļþ£¬Ö´ÐÐPowerShellºÅÁ²¢»ñÈ¡´óÁ¿ÏµÍ³ÓйØÐÅÏ¢¡£×êÑÐÈËÔ±°µÊ¾£¬ÓÉÓÚWinorDLL64ÔÚ¿ª·¢»·¾³¡¢ÐÐΪºÍ´úÂëÖÐÓë¶à¸öLazarusµÄÑù±¾ÓÐËù³Áµþ£¬ÕâÅú×¢Ëü¿ÉÄÜÊÇÕâ¸öAPT×éÖ¯µÄ±øÆ÷¿âÖеÄÒ»²¿ÃÅ¡£
https://www.welivesecurity.com/2023/02/23/winordll64-backdoor-vast-lazarus-arsenal/
6¡¢Synopsys°ä²¼2023Ä꿪Դ°²È«Î¢·çÏյķÖÎö»ã±¨
ýÌå2ÔÂ22Èճƣ¬Synopsysµ÷²éÁË17¸öÐÐÒµÖÐÔ¼1700¸ö´úÂë¿âÖз¢Ïֵķì϶ºÍÐí¿Éì¶Ü£¬°ä²¼Á˹ØÓÚ2023Ä꿪Դ°²È«Î¢·çÏյķÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬84%µÄ´úÂë¿âÔ̺¬ÖÁÉÙÒ»¸öÒÑÖªµÄ¿ªÔ´·ì϶£¬ÓëÈ¥ÄêÏà±ÈÔö³¤Á˽ü4%¡£¹ÌÈ»×ÜÌå·ì϶ÂÔÓÐÉÏÉý£¬µ«ÓµÓи߷çÏÕ·ì϶µÄ´úÂë¿âµÄÕ¼±ÈÁ¦Ö®È¥Äê½µÂäÁË2%£¬½µÖÁ48%¡£½ÌÓý¿Æ¼¼ÐÐҵѡȡ¿ªÔ´´úÂëµÄ±ÈÀýÔö³¤ÁË163%£¬Æä´ÎÊǺ½¿Õº½Ìì¡¢º½¿Õ¡¢Æû³µ¡¢ÔËÊäºÍÎïÊ¢ÐÐÒµ(97%)ÒÔ¼°Ôì×÷ÒµºÍ»úеÈ˼¼Êõ(74%)¡£
https://www.synopsys.com/software-integrity/resources/analyst-reports/open-source-security-risk-analysis.html


¾©¹«Íø°²±¸11010802024551ºÅ