Cuckoo macOS¶ñÒâÈí¼þ¿É½ÚÔìMac²¢ÇÔÈ¡ÃÜÂë

°ä²¼¹¦·ò 2024-05-08
1. Cuckoo macOS¶ñÒâÈí¼þ¿É½ÚÔìMac²¢ÇÔÈ¡ÃÜÂë


5ÔÂ7ÈÕ£¬ºÚ¿ÍÔÚʹÓÃÐ嵀 Mac ¶ñÒâÈí¼þ¶ÔÔËÐÐ Apple Silicon µÄÐÂÐÍ Mac ÒÔ¼°»ùÓÚ Intel µÄ¾É Mac ÌáÒé¹¥»÷¡£¾Ý¡¶ºÚ¿ÍÐÂÎÅ¡·±¨Â·£¬Kandji µÄ°²È«×êÑÐÈËÔ±½«ÕâÖÖ¶ñÒâÈí¼þ³ÆÎª Cuckoo¡£³ýÁËÕë¶Ô½ÏÐÂºÍ½Ï¾ÉµÄ Mac µçÄÔ±í£¬Cuckoo µÄÒìºõѰ³£Ö®´¦»¹ÔÚÓÚËüµÄÐÐΪÀàËÆÓÚÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þºÍ¼äµýÈí¼þµÄ»ìºÏÌå¡£ÔÚһƪ²©¿ÍÎÄÕÂÖУ¬Kandji µÄ Adam Kohler ºÍ Christopher Lopez Ú¹ÊÍ˵£¬ËûÃÇÔÚ¶ñÒâÈí¼þ¸ú×ÙÍøÕ¾ VirusTotal ÉÏ·¢ÏÖÁËÒ»¸öÒÔǰδ¼ì²âµ½µÄ¶ñÒâ Mach-O ¶þ½øÔìÎļþ£¬ÆäÃû³ÆÎª¡°DumpMedia Spotify Music Converter¡±¡£¶øºó£¬ËûÃÇÔÚÍøÉϲéÕҸ÷¨Ê½µÄÃû³Æ£¬·¢Ïָ÷¨Ê½ÊÇ´ÓÒ»¸öÃûΪ dumpmedia[.]com µÄÍøÕ¾·Ö·¢µÄ£¬¸ÃÍøÕ¾Ìṩ¶à¸öÀûÓ÷¨Ê½£¬Äܹ»Ô®ÊÖÓû§½«Á÷ýÌå·þÎñÖеÄÒôÀÖת»»Îª MP3 Îļþ¡£


https://news.hitb.org/content/new-cuckoo-macos-malware-can-take-over-all-macs-and-steals-your-passwords-too


2. ×êÑÐÍŶÓÑÝʾÕë¶ÔËùÓÐVPN·¨Ê½µÄ¹¥»÷TunnelVision


5ÔÂ7ÈÕ£¬×êÑÐÈËÔ±Éè¼ÆÁËÒ»ÖÖÕë¶ÔÏÕЩËùÓÐÐ鹹רÓÃÍøÂçÀûÓ÷¨Ê½µÄ¹¥»÷£¬ÆÈʹËüÃÇÔÚ¼ÓÃÜËí·֮±í·¢Ëͺͽӹܲ¿ÃÅ»òÈ«ÊýÁ÷Á¿£¬Ö¼ÔÚ±£»¤ÆäÃâÔâ¿ú̽»ò´Û¸Ä¡£×êÑÐÈËÔ±½«Æä¹¥»÷¶¨ÃûΪ TunnelVision£¬½«´«ÈëºÍ´«³öµÄ»¥ÁªÍøÁ÷Á¿·â×°ÔÚ¼ÓÃÜËí·Öв¢°µ²ØÓû§µÄ IP µØÖ·¡£×êÑÐÈËÔ±ÒÔΪ£¬µ±ËùÓÐ VPN ÀûÓ÷¨Ê½Ïνӵ½¶ñÒâÍøÂçʱ£¬Ëü³ÇÊÐÓ°ÏìËüÃÇ£¬²¢ÇÒ³ýÁ˵±Óû§µÄ VPN ÔÚ Linux »ò Android ÉÏÔËÐÐʱ֮±í£¬Ã»ÓÐÆäËû²½ÖèÄܹ»Ô¤·À´ËÀ๥»÷¡£ËûÃÇ»¹°µÊ¾£¬ËûÃǵĹ¥»÷¼¼Êõ¿ÉÄÜ×Ô 2002 ÄêÒÔÀ´¾ÍÒѳÉΪ¿ÉÄÜ£¬²¢ÇÒ´ÓÄÇʱÆð¾ÍÒѾ­±»·¢ÏÖ²¢ÔÚÒ°±íʹÓá£Ò»¶ÎÊÓÆµÑÝʾڹÊÍ·£¬TunnelVision µÄ³ÉЧÊÇ¡°Êܺ¦ÕßµÄÁ÷Á¿´Ë¿ÌÒѱ»½Ò¿ª²¢Ö±½Óͨ¹ý¹¥»÷Õß½øÐзÓÉ¡±¡£¡°¹¥»÷ÕßÄܹ»¶ÁÈ¡¡¢É¾³ý»òÅú¸Äй¶µÄÁ÷Á¿£¬¶øÊܺ¦ÕßÔòά³ÖÓë VPN ºÍ»¥ÁªÍøµÄÏνÓ¡£¡±


https://news.hitb.org/content/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose


3. ¼Ù×°³ÉÖ¤ÊéµÄ LNK Îļþ·Ö·¢ RokRAT ¶ñÒâÈí¼þ


5ÔÂ7ÈÕ£¬AhnLab°²È«µý±¨ÖÐÐÄ£¨ASEC£©ÒÑÈ·ÈϳÖÐø´«²¼Òì³£´óÓ׵Ŀì½Ý·½Ê½Îļþ£¨*.LNK£©£¬ÓÃÓÚ´«²¼ºóÃÅÀàÐ͵ĶñÒâÈí¼þ¡£×î½üÈ·ÈϵĿì½Ý·½Ê½Îļþ£¨*.LNK£©±»·¢ÏÖÊÇÕë¶Ôº«¹úÓû§£¬³ö¸ñÊÇÓ볯ÏÊÓйصÄÓû§¡£È·ÈϵÄLNKÎļþÃûÈçÏ£º¹ú¶ÈÐÅϢѧԺµÚ°ËÆÚ×ۺϿγÌÖ¤Ê飨×îÖÕ£©.lnk¡¢ÃŽûÃû²á2024.lnk¡¢¶«±±ÏîÄ¿£¨ÃÀ¹ú¹ú»á×êÑзþÎñ´¦£¨CRS »ã±¨£©.lnkºÍÉèÊ©Çåµ¥.lnk¡£ÒÑÈ·ÈϵÄLNKÎļþÔ̺¬Í¨¹ýCMDÖ´ÐÐPowerShellµÄºÅÁÆäÀàÐÍÓëÈ¥Äê°ä²¼µÄ¡°RokRAT Malware Distributed Through LNK Files (*.lnk): RedEyes (ScarCruft)¡± [1]Öз¢ÏÖµÄÀàÐÍÀàËÆ¡£¹ØÓÚÕâÖÖÀàÐ͵ÄÒ»¸öÖµÍ×ÌùÐĵÄÊÂʵÊÇ£¬ËüÔÚ LNK ÎļþÖÐÔ̺¬ºÏ·¨ÎĵµÎļþ¡¢¾ç±¾´úÂëºÍ¶ñÒâ PE Êý¾Ý¡£


https://asec.ahnlab.com/en/65076/


4. 2023ÄêµÚÈý·½Ôì³ÉµÄÊý¾Ýй¶Ôö³¤ÁË68%


5ÔÂ7ÈÕ£¬½üÄêÀ´¹©¸øÁ´Î¥¹æÊÂÎñÒ»Ïò³ÊÉÏÉýÇ÷Ïò¡£Æ¾¾Ý Verizon ×îеÄÊý¾Ýй¶µ÷²é»ã±¨ (DBIR)£¬½ü¼¸¸öÔÂÀ´ÕâÒ»Ôö³¤ÓÈΪ¼±¾ç¡£2023 ÄêËùÓÐÎ¥¹æÐÐΪÖÐÔ¼ÓÐ 15% Éæ¼°µÚÈý·½£¬±È 2022 ÄêµÄ 9% ÏÔ×ÅÔö³¤¡£²»Í⣬ÕâЩÊý×ÖÓë¹ÜÕʺ͹¥»÷µÄ¹ØÏµÍ¬Ñù³ÁÒª¡£ÊÂʵÉÏ£¬±»ÀûÓõķì϶ÊÇ DBIR ¹©¸øÁ´Ö¸±êÖÐ×î³£¼ûµÄÊÂÎñ¼Í¼ºÍÊÂÎñ¹²Ïí (VERIS) ÐÐΪ´Ê»ã£¬Æä´ÎÊǺóÃÅ/ºÅÁîÓë½ÚÔì (C2) ºÍÀÕË÷¡£Verizon Íþвµý±¨¸±×ܼà Alex Pinto °µÊ¾£ºÈ¥Ä꣬ÔÚÀÕË÷Èí¼þÁìÓò£¬ÎÒÃÇ¿´µ½£¬ÎÞÂÛÊÇ×Ô¼º×êÑл¹ÊDzɰ죬[ÍþвÐÐΪÕß]ÒѾ­°ÑÎÕÁËÈç´Ë¶àµÄÁãÈÕ·ì϶¡£¶ÔÓÚ DBIR ÍŶÓÀ´Ëµ£¬½â¾öÃýÎó²»½ö½öÊÇÔÚÃýÎó³öÏÖʱ½øÐн¨²¹¡£ÕâÊǹØÓÚ×éÖ¯ÈôºÎÑ¡Ôñ¹©¸øÉ̲¢ÓëÆäºÏ×÷µÄÎÊÌ⡣ûÓÐ×éÖ¯Äܹ»×èÖ¹ËûÃÇʹÓõÄÈí¼þÖеÄÿ¸öDZÔÚ·ì϶£¬µ«¹©¸øÉ̵ÄÈ·¡°Ð¹Â©¡±ÁËijЩ¿ÉÄÜÅú×¢Æä¼ÛÖµµÄÐźÅ¡£


https://www.darkreading.com/cyber-risk/supply-chain-breaches-up-68-yoy-according-to-dbir


5. TinyproxyÑϳÁ·ì϶µ¼Ö³¬¹ý5Íǫ̀Ö÷»ú¿ÉÖ´ÐÐÔ¶³Ì´úÂë


5ÔÂ6ÈÕ£¬90310 ̨Ö÷»úÖг¬¹ý 50% ±»·¢´Ë¿Ì»¥ÁªÍøÉ϶³öÁËTinyproxy ·þÎñ£¬¸Ã·þÎñÈÝÒ×Êܵ½ HTTP/HTTPS ´úÀí¹¤¾ßÖÐ佨²¹µÄÑϳÁ°²È«·ì϶µÄÓ°Ï졣ƾ¾Ý Cisco Talos £¬¸ÃÎÊÌâµÄ±àºÅΪCVE-2023-49606£¬CVSS ÆÀ·ÖΪ 9.8 ·Ö£¨Âú·Ö 10 ·Ö£©£¬¸ÃÎÊÌ⽫ÆäÃèÊöΪӰÏì°æ±¾ 1.10.0 ºÍ 1.11.1 µÄ¿ªÊͺóʹÓÃÃýÎó¡£TalosÔÚÒ»·Ý²¼¸æÖаµÊ¾£ºÌØÔìµÄ HTTP ±êÍ·¿ÉÄܻᴥ·¢ÏÈǰ¿ªÊ͵ÄÄÚ´æµÄ³ÁÓ㬴Ӷøµ¼ÖÂÄÚ´æ°Ü»µ²¢¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¹¥»÷Õß±ØÒª·¢³öδ¾­Éí·ÝÑéÖ¤µÄ HTTP ÒªÇóÄÜÁ¦´¥·¢´Ë·ì϶¡£»»¾ä»°Ëµ£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþв²Î¼ÓÕßÄܹ»·¢ËÍÌØÔìµÄHTTP ÏνӱêÍ·À´´¥·¢ÄÚ´æ°Ü»µ£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Æ¾¾Ý¹¥»÷ÃæÖÎÀí¹«Ë¾ Censys ¹²ÏíµÄÊý¾Ý£¬½ØÖÁ 2024 Äê 5 Ô 3 ÈÕ£¬ÔÚÏò¹«¹²»¥ÁªÍø¹«¿ª Tinyproxy ·þÎñµÄ 90,310 ̨Ö÷»úÖУ¬ÆäÖÐ 52,000 ̨£¨Ô¼ 57%£©ÔËÐÐ×Å´æÔÚ·ì϶µÄ Tinyproxy °æ±¾¡£´óÎÞÊý¿É¹«¿ª½Ó¼ûµÄÖ÷»úλÓÚÃÀ¹ú£¨32,846£©¡¢º«¹ú£¨18,358£©¡¢Öйú£¨7,808£©¡¢·¨¹ú£¨5,208£©ºÍµÂ¹ú£¨3,680£©¡£


https://thehackernews.com/2024/05/critical-tinyproxy-flaw-opens-over.html


6. ¶íÂÞ˹ BTC-e ¼ÓÃÜÇ®±ÒÂòÂôËùÔËÓªÉÌÈÏ¿ÉÏ´Ç®×ï


5ÔÂ6ÈÕ£¬Æ¾¾ÝÃÀ¹ú˾·¨²¿µÄÒ»·ÝÉêÃ÷£¬ÒѾ­ÊÇÊÀ½çÉÏ×î´óµÄÐ鹹Ǯ±ÒÂòÂôËùÖ®Ò»µÄ¶íÂÞ˹ÔËÓªÉÌ BTC-e ÈϿɲμÓÏ´Ç®´òËã¡£44 ËêµÄÑÇÀúɽ´ó¡¤ÎÄÄá¿Ë (Alexander Vinnik) ÔÚ 2011 ÄêÖÁ 2017 ÄêÆÚ¼äÔËÓª BTC-e£¬ºóÀ´¸Ã·þÎñ±»·¨Âɲ¿ÃŹعØ¡£ÔÚ´ËÆÚ¼ä£¬¸ÃÂòÂôËù´¦ÖÃÁ˳¬¹ý 90 ÒÚÃÀÔªµÄÂòÂô£¬²¢ÎªÈ«Çò³¬¹ý 100 ÍòÓû§Ìṩ·þÎñ£¬ÆäÖÐÔ̺¬¶à¶àÃÀ¹ú¿Í»§¡£Æ¾¾Ý·¨Í¥Îļþ£¬×÷Ϊ·¸·¨»î¶¯µÄÒ»²¿ÃÅ£¬Vinnik ͨ¹ý BTC-e Ôì³ÉÁËÖÁÉÙ 1.21 ÒÚÃÀÔªµÄËðʧ¡£Ëû»¹ÔÚÈ«ÇòÁìÓòÄÚÉèÁ¢Á˶à¶à¿Õ¿Ç¹«Ë¾ºÍ½ðÈÚÕË»§£¬ÒÔÔÊÐí BTC-e ÎÞÐ轫¸Ãƽ̨ע²áΪǮ±Ò·þÎñÒµÎñ¼´¿ÉÔËÓª¡£Ó¦ÃÀ¹úÒªÇó£¬ÎÄÄá¿Ë×î³õÓÚ 2017 ÄêÔÚÏ£À°±»²¶¡£2020 Ä꣬Ëû±»Òý¶Éµ½·¨¹ú£¬±¾µØ·¨ÔºÖ¸¿ØËûÈëÇÖÊýǧ¸öµç×ÓÓʼþÕÊ»§²¢ÏòÆäËùÓÐÕßÀÕË÷²Æ²¯¡£Ëæºó£¬Ëû±»Ç²·µ»ØÏ£À°£¬¶øºó±»Òý¶Éµ½ÃÀ¹ú¡£Óë´Ëͬʱ£¬¶íÂÞ˹»¹ÒªÇóÏ£À°µ±¾Ö½«ÎÄÄá¿ËDzËͻعú£¬ÒÔÖ¸¿ØËû·¸ÓнÏÓ×µÄڲƭ×ï¡£


https://therecord.media/btce-cryptocurrency-exchange-alexander-vinnik-money-laundering-guilty-plea