Strava½¡ÉíÀûÓñ»ÆØÐ¹Â¶¶à¹ú×Üͳ°²±£ÈËԱλÏàÐÅÏ¢

°ä²¼¹¦·ò 2024-10-31

1. Strava½¡ÉíÀûÓñ»ÆØÐ¹Â¶¶à¹ú×Üͳ°²±£ÈËԱλÏàÐÅÏ¢


10ÔÂ29ÈÕ£¬StravaÊÇÒ»¿îÈ«Çò¹ãÊÜÓ­½ÓµÄ½¡ÉíÀûÓ÷¨Ê½£¬Õ¼ÓÐ1.2ÒÚÓû§£¬¿ÉÄܼͼÅܲ½¡¢ÆïÐеȻ¹ì¼£¡£È»¶ø£¬·¨¹úýÌå¡¶ÊÀ½ç±¨¡··¢ÏÖ£¬Strava´æÔÚй¼ûô¸ÐλÏàÐÅÏ¢µÄ·çÏÕ£¬Ô̺¬ÃÀ¹ú×Üͳ¼°Æä¾ºÑ¡È˵ÄÌùÉí°²±£ÈËÔ±µØÎ»¡£¾Ý±¨Â·£¬ÖÁÉÙ26ÃûÃÀ¹ú¼éϸÔÚStravaÉÏÕ¼Óй«¹²ÕË»§£¬ÇÒÔÚÌØÀÊÆÕÔâ·ê°µËãδËìÊÂÎñºóÈÔ»îÔ¾ÓÚ¸ÃÆ½Ì¨¡£´Ë±í£¬·¨¹úºÍ¶íÂÞ˹µÄ×Üͳ°²±£ÈËÔ±Ò²±»·¢ÏÖʹÓøÃÀûÓã¬Éæ¼°12Ãû·¨¹úGSPR³ÉÔ±ºÍ6Ãû¶íÂÞ˹FSO³ÉÔ±¡£ÕâЩ°²È«ÈËÔ±ÔÚStravaÉϵÄÐж¯¿ÉÄܵ¼Ö°²È«·ì϶£¬ÓÉÓÚËûÃǵĻ¹ì¼£¿ÉÄܶ³ö¸¨µ¼ÈËÏÂ齺ͻáÒ鵨ַµÄÐÅÏ¢£¬ÉõÖÁÓ×ÎÒÉúÑÄϸ½ÚÒ²¿ÉÄܱ»¶ñÒâÀûÓá£Ö»¹ÜÃÀ¹úÌØÇھֺͷ¨¹ú×Üͳ¹Ù·½»ú¹¹¶Ô´Ë½øÐÐÁË»ØÓ¦£¬³ÆÊ¹ÓÃStrava²»»á¶Ô°²±£Ðж¯×é³ÉÍþв£¬µ«´ËǰStrava°ä²¼µÄÈ«Çò½¡ÉíÈÈÇøÍ¼¾ÍÔøÂ¶³öÃÀ¾üÔÚÖж«µØÓòµÄ»úÃܻµØÎ»£¬Òý·¢ÕùÒé¡£´Ë±í£¬½¡ÉíÀûÓ÷¨Ê½Êý¾Ý»¹¿ÉÄܱ»¹¥»÷ÕßÓÃÓÚ×·×ÙDZÔÚÊܺ¦Õߣ¬Ôö³¤¸ú×Ù¡¢Â°Âӵȷ¸×ï·çÏÕ¡£Òò¶ø£¬Ê¹ÓôËÀàÀûÓÃʱÐèÉóÉ÷£¬Ô¤·Àй¼ûô¸ÐÐÅÏ¢¡£


https://cybernews.com/news/fitness-app-strava-location-biden-trump-harris/


2. Metaƽ̨Ôâ¶ñÒâ¸æ°×»î¶¯ÇÖÏ®£¬SYS01ÐÅÏ¢ÇÔÈ¡·¨Ê½È«ÇòËÁŰ


10ÔÂ30ÈÕ£¬Ò»ÏîеĶñÒâ¸æ°×»î¶¯ÔÚÀûÓà Meta ƽ̨´«²¼ SYS01 ÐÅÏ¢ÇÔÈ¡·¨Ê½£¬¸Ã·¨Ê½×¨ÃÅÕë¶Ô 45 ËêÒÔÉϵÄÄÐÐÔÓû§£¬Í¨¹ý¼Ù×°³ÉÊ¢ÐÐÈí¼þ¡¢ÓÎÏ·ºÍÔÚÏß·þÎñµÄÐéα¸æ°×½øÐй¥»÷¡£¸Ã»î¶¯×Ô 2024 Äê 9 Ô³õ´Î±»·¢ÏÖÒÔÀ´£¬ÒÑÔÚÈ«ÇòÁìÓòÄÚÔì³É¿í·ºÓ°Ï죬Ô̺¬Å·ÃË¡¢±±ÃÀ¡¢°Ä´óÀûÑǺÍÑÇÖ޵ȵØ¡£SYS01 ·¨Ê½»áÇÔÈ¡ Facebook ƾ֤£¬³ö¸ñÊÇÖÎÀíóÒ×Ò³ÃæµÄÕË»§£¬²¢ÀûÓÃÕâЩÕË»§½øÒ»²½´«²¼¹¥»÷¡£¹¥»÷Õßͨ¹ý MediaFire Á´½ÓÌṩ¿´ËƺϷ¨µÄÈí¼þÏÂÔØ£¬ÕâЩÏÂÔØÄÚÈÝÔ̺¬¶ñÒâµÄ Electron ÀûÓ÷¨Ê½£¬Ò»µ©Ö´ÐУ¬¾Í»áÖ²Èë²¢ÔËÐÐ SYS01 ·¨Ê½¡£¸Ã·¨Ê½½áºÏÁË·´É³ºÐ²é³­ÒÔÌӱܼì²â£¬²¢»áÌáÈ¡Ô̺¬Ö÷Ìâ¶ñÒâÈí¼þ×é¼þµÄÊÜÃÜÂë± £»¤µÄ´æµµ¡£±»µÁÕË»§²»½öÓÃÓÚ½øÒ»²½¹¥»÷/Ú¿Æ­£¬»¹±»ÓÃÀ´Ôì×÷жñÒâ¸æ°×£¬Èƹý°²È«¹ýÂËÆ÷£¬ÐγÉÒ»¸ö×ÔÎÒά³ÖµÄÑ­»·¡£Òò¶ø£¬Óû§ÔÚ Facebook ÉÏ£¬ÓÈÆäÊÇÔËӪóÒ×Ò³ÃæµÄÓû§£¬±ØÐ뾯Ìè´ËÀàÍþв¡£


https://hackread.com/fake-meta-ads-hijacking-facebook-sys01-infostealer/


3. ÃØÂ³InterbankÔâÊý¾Ýй¶£¬ºÚ¿ÍÐû³ÆÇÔÈ¡300Íò¿Í»§ÐÅÏ¢


10ÔÂ30ÈÕ£¬ÃØÂ³³ÛÃû½ðÈÚ»ú¹¹Interbank½üÆÚÔâ·êÊý¾Ýй¶ÊÂÎñ£¬Ò»ÃûÍþвÐÐΪÕßÈëÇÔìäϵͳ²¢µÁÈ¡Á˿ͻ§Êý¾Ý£¬ËæºóÔÚÍøÉϽøÐÐй¶¡£Ö»¹ÜInterbankδй©¾ßÌåÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿£¬µ«Dark Web Informer·¢ÏÖ£¬Ò»ÃûʹÓá°kzoldyck¡±Óû§ÃûµÄºÚ¿ÍÔÚ¶à¸öÂÛ̳ÏúÊ۾ݳƴӸÃÒøÐÐÇÔÈ¡µÄÊý¾Ý¡£¾ÝºÚ¿ÍÐû³Æ£¬ËûÃÇ¿ÉÄÜ»ñÈ¡Interbank¿Í»§µÄÈ«Ãû¡¢ÕË»§ID¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ºÍIPµØÖ·µÈÃô¸ÐÐÅÏ¢£¬ÒÔ¼°ÐÅÓþ¿¨ÐÅÏ¢¡¢ÒøÐÐÂòÂôÊý¾ÝµÈ£¬×ÜÁ¿³¬¹ý3.7TB¡£´Ë±í£¬ºÚ¿Í»¹Ðû³ÆÕ¼Óпͻ§µÄÃ÷È·Óû§ÃûºÍÃÜÂëÐÅÏ¢£¬Äܹ»´ÓÃØÂ³IP¿é½Ó¼ûÒøÐÐÕË»§¡£ºÚ¿Í°µÊ¾£¬ËûÃÇÁ½ÖÜÇ°Ôø³¢ÊÔÓëInterbankÖÎÀí²ã½»É浫δ¹û£¬Òò¶ø¾ö¶¨¹«¿ªÐ¹Â¶Êý¾Ý¡£InterbankÒÑÈ·ÈϲúÉúÊý¾Ýй¶£¬²¢°µÊ¾ÒѲ¿Êð¶î±í°²È«´ëÊ©± £»¤¿Í»§ÐÅÏ¢ºÍÔËÓª£¬Í¬Ê±±£ÕϿͻ§´æ¿î°²È«£¬²¢Ö¸³ö´óÎÞÊýÒµÎñÇþ·ÒѸ´Ô­ÔÚÏß¡£


https://www.bleepingcomputer.com/news/security/interbank-confirms-data-breach-following-failed-extortion-data-leak/


4. ³¯ÏʺڿÍ×éÖ¯AndarielÉæÏӲμÓPlayÀÕË÷Èí¼þÐж¯²¢ÌÓ±ÜÔì²Ã


10ÔÂ30ÈÕ£¬³¯Ïʹú¶ÈÖ§³ÖµÄºÚ¿Í×éÖ¯Andariel±»×·×ÙÓëPlayÀÕË÷Èí¼þÐж¯ÓйØÁª£¬¾ÝPalo Alto Networks¼°ÆäUnit 42×êÑÐÈËÔ±µÄ»ã±¨³Æ£¬Andariel¿ÉÄÜÊÇPlayµÄ´ÓÊô»ú¹¹»ò³õʼ½Ó¼û´úÀí£¬Ð­ÖúÔÚÆäÈëÇÖµÄÍøÂçÉϲ¿Êð¶ñÒâÈí¼þ¡£AndarielÊÇÒ»¸öÊܳ¯Ïʵ±¾ÖÖ§³ÖµÄAPT×éÖ¯£¬Ó볯Ïʾüʵý±¨»ú¹¹¿úËÅ×ܾÖÓйØÁª£¬ÔøÒò¹¥»÷ÃÀ¹úÀûÒæ¶øÊܵ½ÃÀ¹úÔì²Ã¡£´Ëǰ£¬AndarielÒ²ÔøÓëMauiÀÕË÷Èí¼þÐж¯ÓйØ¡£ÔÚ2024Äê9ÔµÄÒ»´ÎPlayÀÕË÷Èí¼þÊÂÎñÏìÓ¦ÖУ¬Unit 42·¢ÏÖAndarielÔÚÆä¿Í»§µÄÊÜÏ°È¾ÍøÂçÖл£¬²¢ÔÚ¼¸¸öÔºóPlayÀÕË÷Èí¼þ²ÅÔÚÍøÂçÉÏÖ´ÐС£×êÑÐÈËÔ±ÒÔΪAndarielµÄ´æÔÚºÍPlayÔÚÍ³Ò»ÍøÂçÉϵIJ¿ÊðÓйØÁª£¬µ«²»È·¶¨AndarielÊÇ·ñ³äÈÎÁËPlay´ÓÊô»ú¹¹»òÏò¹¥»÷ÕßÏúÊÛÁËÊÜÏ°È¾ÍøÂçµÄ½Ó¼ûȨÏÞ¡£Í¨¹ýÓëÀÕË÷Èí¼þÍÅ»ïºÏ×÷£¬AndarielµÃÒÔÌӱܹú¼ÊÔì²Ã£¬ÕâÖÖÕ½ÊõÀàËÆÓÚ֮ǰÊܵ½Ôì²ÃµÄ¶íÂÞ˹ºÚ¿Í×éÖ¯Evil CorpºÍÒÁÀÊÍþвÐÐΪÕß¡£


https://www.bleepingcomputer.com/news/security/north-korean-govt-hackers-linked-to-play-ransomware-attack/


5. Android°æFakeCall¶ñÒâÈí¼þ½Ù³ÖÒøÐе绰£¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢


10ÔÂ30ÈÕ£¬Android°æFakeCall¶ñÒâÈí¼þµÄа汾ͨ¹ý½«×Ô¼ºÉèÖÃΪĬÈϺô½Ð´¦Ö÷¨Ê½£¬¿ÉÄܽٳÖÓû§²¦´òÒøÐе绰µÄºô½Ð£¬²¢½«Æä³Á¶¨Ïòµ½¹¥»÷Õߵĵ绰ºÅÂë¡£¸Ã¶ñÒâÈí¼þÒÔÓïÒôÍøÂç´¹µöΪ³Áµã£¬Ö¼ÔÚÇÔÈ¡ÈËÃǵÄÃô¸ÐÐÅÏ¢ºÍÒøÐÐÕË»§×ʽð¡£³ýÁËÓïÒôÍøÂç´¹µö£¬Ëü»¹Äܲ¶»ñʵʱÒôƵºÍÊÓÆµÁ÷¡£×îа汾µÄFakeCallÔö³¤Á˶àÏî¸Ä½øºÍ¹¥»÷»úÔ죬ÈçÀ¶ÑÀ¼àÌýÆ÷¡¢ÆÁĻ״̬¼à¶½Æ÷ºÍ¸¨ÖúÖ°ÄÜ·þÎñ£¬ÒÔ»ñµÃ¶ÔÓû§½çÃæµÄ¿í·º½ÚÔ죬²¢ÔÊÐí¹¥»÷ÕßÖ´Ðи÷Àà²Ù×÷£¬Èç»ñÈ¡É豸µØÎ»¡¢É¾³ýÀûÓ÷¨Ê½¡¢Â¼ÔìÒôƵ»òÊÓÆµÒÔ¼°±à×ëÁªÏµÈË¡£´Ë±í£¬¸Ã¶ñÒâÈí¼þ»¹ÔÚ»ý¼«¿ª·¢ÖУ¬Ôö³¤Á˽«¶ñÒâÈí¼þÅäÖÃΪĬÈϺô½Ð´¦Ö÷¨Ê½¡¢ÊµÊ±²¥·ÅÉ豸ÆÁÄ»ÄÚÈݵÈÐÂÖ°ÄÜ¡£Zimperium°ä²¼ÁËÈëÇÖÖ¸±êÁбíÒÔÔ®ÊÖÓû§±Ü¿ª¶ñÒâÀûÓ㬵«½¨ÒéÓû§´ÓGoogle Play×°ÖÃÀûÓÃÒÔÔ¤·À·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/android-malware-fakecall-now-reroutes-bank-calls-to-attackers/


6. EmeraldWhaleɨÃèGitÅäÖÃÎļþ£¬ÇÔÈ¡15,000¸öÔÆÕÊ»§Í´´¦


10ÔÂ30ÈÕ£¬ÃûΪ¡°EmeraldWhale¡±µÄ´ó¹æÄ£¶ñÒâ²Ù×÷ÀûÓÃ×Ô¶¯»¯¹¤¾ßɨÃè¶³öµÄGitÅäÖÃÎļþ£¬´ÓÊýǧ¸ö¸öÈË´æ´¢¿âÖÐÇÔÈ¡Á˳¬¹ý15,000¸öÔÆÕÊ»§Í´´¦¡£ÕâЩʹ´¦±»ÓÃÓÚÏÂÔØ´æ´¢ÔÚGitHub¡¢GitLabºÍBitBucketÉϵĴ洢¿â£¬²¢½øÒ»²½É¨ÃèÒÔ»ñÈ¡¸ü¶àƾ֤¡£±»µÁÊý¾Ý±»Ð¹Â¶ÖÁÆäËûÊܺ¦ÕßµÄAmazon S3´æ´¢Í°ÖУ¬²¢±»ÓÃÓÚÍøÂç´¹µö¡¢À¬»øÓʼþ»î¶¯»òÖ±½ÓÏúÊÛ¸øÆäËûÍøÂç·¸×ï·Ö×Ó¡£EmeraldWhale±³ºóµÄÍþвÐÐΪÕßʹÓÿªÔ´¹¤¾ßɨÃèÔ¼5ÒÚ¸öIPµØÖ·ÉϵÄÍøÕ¾£¬³ö¸ñÊDz鳭LaravelÀûÓ÷¨Ê½ÖеÄ/.git/configÎļþºÍ»·¾³Îļþ(.env)ÊÇ·ñ¶³ö¡£ÕâЩÎļþÖпÉÄÜÔ̺¬APIÃÜÔ¿¡¢ÔÆÆ¾Ö¤µÈÃô¸ÐÐÅÏ¢¡£Sysdig¹Û²ìµ½£¬ºÚ¿ÍʹÓÃÉÌÆ·¹¤¾ß¼¯¼ò»¯ÕâÒ»Á÷³Ì£¬²¢ÔÚ¶³öµÄS3´æ´¢Í°Öз¢ÏÖÁË´óÁ¿»úÃÜÐÅÏ¢¡£×êÑÐÈËÔ±Ö¸³ö£¬Õâ´Î»î¶¯ÒÀÀµÓÚÉÌÆ·¹¤¾ßºÍ×Ô¶¯»¯£¬µ«ÒÀÈ»³É¹¦ÇÔÈ¡ÁËÊýǧ¸ö¿ÉÄܵ¼Ö¿àÄÑÐÔÊý¾Ýй¶µÄ»úÃÜ¡£Èí¼þ¿ª·¢ÈËԱӦʹÓÃרÓõİÂÃØÖÎÀí¹¤¾ßÀ´½µµÍ·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/hackers-steal-15-000-cloud-credentials-from-exposed-git-config-files/