Solana JavaScript SDKÔ⹩¸øÁ´¹¥»÷£¬¶ñÒâ´úÂëÇÔÈ¡¼ÓÃÜÇ®±Ò˽Կ
°ä²¼¹¦·ò 2024-12-061. Solana JavaScript SDKÔ⹩¸øÁ´¹¥»÷£¬¶ñÒâ´úÂëÇÔÈ¡¼ÓÃÜÇ®±Ò˽Կ
12ÔÂ4ÈÕ£¬SolanaµÄJavaScript SDK¡°@solana/web3.js¡±ÔÚ½üÆÚµÄÒ»´Î¹©¸øÁ´¹¥»÷ÖÐÔâµ½ÁÙʱÈëÇÖ£¬¹¥»÷Õß°ä²¼ÁËÁ½¸öÔ̺¬¶ñÒâ´úÂëµÄºóÃŰ汾£¨1.95.6ºÍ1.95.7£©£¬Ö¼ÔÚÇÔÈ¡¼ÓÃÜÇ®±Ò˽Կ²¢ÌÍ¿ÕÇ®°ü¡£ÕâЩ±»ÈëÇֵİ汾ÔÚnpmÉÏÿÖÜÏÂÔØÁ¿³¬¹ý350,000´Î£¬¶Ô¿ª·¢ÈËÔ±ºÍÓû§×é³ÉÁËÑϳÁÍþв¡£Solana֤ʵÁËÕâÒ»·ì϶£¬²¢°µÊ¾ÊÇÓÉÓÚÆä°ä²¼½Ó¼ûÕË»§±»ÈëÇÖËùÖ¡£¹¥»÷Õßͨ¹ýÅú¸Ä¿âÖеĹؼüº¯Êý£¬½«¶ñÒâ´úÂëÔö³¤µ½¿âÖУ¬ÒÔÇÔȡ˽Կ²¢½«Æä·¢Ë͵½¹¥»÷ÕߵķþÎñÆ÷¡£¾ÝDataDog×êÑÐÔ±³Æ£¬ÍþвÐÐΪÕßÔö³¤ÁËÒ»¸ö¶ñÒâµÄ¡°addToQueue¡±º¯Êý£¬¸Ãº¯Êýͨ¹ý¿´ËƺϷ¨µÄCloudFlare±êͷй¶˽Կ¡£Õâ´Î¹¥»÷ÒÑ×·Òäµ½ÌØ¶¨µÄSolanaµØÖ·£¬¸ÃµØÖ·Ô̺¬¶àÖÖ¼ÓÃÜÇ®±ÒºÍNFT£¬¹À¼Æ¼ÛֵΪ184,000ÃÀÔª¡£SolanaÖÒ¸æÒÉ»ó×Ô¼ºÊܵ½¹¥»÷µÄ¿ª·¢ÈËÔ±µ±¼´Éý¼¶µ½×îеÄv1.95.8°æ±¾²¢ÂÖ»»ËùÓÐÃÜÔ¿£¬Í¬Ê±½¨ÒéÇ®°ü±»µÁµÄÈ˵±¼´½«Ôü×Ò×ʽð×ªÒÆµ½ÐÂÇ®°ü£¬²¢ÖÕ³¡Ê¹ÓþÉÇ®°ü¡£
https://www.bleepingcomputer.com/news/security/solana-web3js-library-backdoored-to-steal-secret-private-keys/
2. ¶íÂÞ˹ºÚ¿Í½Ù³Ö°Í»ù˹̹ºÚ¿Í·þÎñÆ÷½øÐй¥»÷
12ÔÂ4ÈÕ£¬¶íÂÞË¹ÍøÂç¼äµý×éÖ¯Turla£¬±ðÃû¡°°ÂÃØ±©Ñ©¡±£¬½üÆÚ²ÉÈ¡ÁËÒ»ÖÖÐµĹ¥»÷Õ½Êõ£¬¼´¹¥»÷²¢½Ù³ÔìäËûºÚ¿Í×éÖ¯µÄ»ù´¡ÉèÊ©£¬ÒÔ°ÂÃØÈëÇÖÒѾÊܵ½¹¥»÷µÄÍøÂç¡£¸Ã×éÖ¯³É¹¦½Ù³ÖÁ˰ͻù˹̹ºÚ¿Í×éÖ¯Storm-0156µÄ»ù´¡ÉèÊ©£¬²¢ÀûÓÃÆä½Ó¼ûÁËStorm-0156ÔøÈëÇÖ¹ýµÄ°¢¸»º¹ºÍÓ¡¶Èµ±¾Ö×éÖ¯ÍøÂ磬²¿ÊðÁ˶ñÒâÈí¼þ¹¤¾ß¡£¾ÝLumenµÄBlack Lotus³¢ÊÔÊһ㱨£¬Turla×Ô2022Äê12ÔÂÆðÍ·½øÐÐÕâ´ÎÐж¯£¬²¢Ò»Ïò³ÖÐøÖÁ2023Äê¡£TurlaÊÇÒ»¸öÊܶíÂÞ˹µ±¾ÖÖ§³ÖµÄºÚ¿Í×éÖ¯£¬³Ö¾ÃÕë¶ÔÈ«Çòµ±¾Ö¡¢×éÖ¯ºÍ×êÑлú¹¹½øÐÐÍøÂç¼äµý»î¶¯¡£Õâ´Î£¬ËûÃÇÔÚStorm-0156µÄÍøÂçÖз¢ÏÖÁËÆæ¹ÖµÄÍøÂçÐÐΪ£¬²¢³É¹¦¹¥ÆÆÆä¶à¸öC2½Úµã£¬²¿ÊðÁËÔ̺¬TinyTurlaºóÃűäÖÖ¡¢TwoDashºóÃŵÈÔÚÄڵĶñÒâÈí¼þ¡£³ýÁË»ñÈ¡Storm-0156µÄ¶ñÒâÈí¼þ¹¤¾ßºÍ±»µÁÊý¾Ý±í£¬Turla»¹½øÒ»²½½«Ö¸±ê¶Ô×¼ÁËStorm-0156×ÔÉí£¬ºáÏò½øÈëÁËÆä¹¤×÷Õ¾¡£TurlaµÄÕâÖÖÕ½ÊõʹËûÃÇ¿ÉÄܰÂÃØÍøÂçµý±¨£¬Ô¤·À¶³ö×Ô¼º»ò¹¤¾ß¼¯£¬´Ó¶ø¼ò»¯¹éÒò¹¤×÷¡£
https://www.bleepingcomputer.com/news/security/russian-turla-hackers-hijack-pakistani-apt-servers-for-cyber-espionage-attacks/
3. ¸ç˹´ïÀè¼ÓRECOPE¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷Òý·¢È¼ÁϹ©¸øÓÇÓô
12ÔÂ4ÈÕ£¬¸ç˹´ïÀè¼ÓʯÓÍÁ¶Ô칫˾£¨RECOPE£©½üÆÚÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäÔËÓªÊܵ½Ó°Ï죬²¢Òý·¢¹«¼Ò¶Ô¿ÉÄܳöÏÖȼÁÏǷȱµÄÓÇÓô¡£¸ÃÊÂÎñÓÚ11ÔÂ27ÈÕ±»·¢ÏÖ£¬ÆÈʹRECOPEÖ´ÐÐÊÖ¶¯Á÷³Ì£¬Êý×ÖÖ§¸¶ÏµÍ³Åö±Ú£¬È¼ÁÏ·ÖÅäÒ²Êܵ½Ó°Ïì¡£RECOPEÕÆ¹ÜÖÎÀíÈ«¹úȼÁϽø¿Ú¡¢ÌáÁ¶ºÍ·ÖÅ䣬Ô̺¬³ÁÒª¹Ü·£¬Õâ´Î¹¥»÷¶ÔÆäÔËÓª´øÀ´ÁËÌôÕ½£¬ÓÈÆäÊÇÔÚÓ͹޳µÈ¼ÁÏ´¬²º¡£Ö»¹ÜRECOPEÈ·ÈÏȼÁÏ´¢Ðî³ä×㣬µ«¹«¼ÒÓÇÓôµ¼ÖÂȼÁÏÏúÊÛ¼¤Ôö£¬¹«Ë¾²»µÃ²»µ¢¸éÔËÓª¹¦·ò¡£ÔÚÃÀ¹úÍøÂ簲ȫר¼ÒµÄÐÖúÏ£¬RECOPEÒÑÆðÍ·²¿ÃŸ´Ôϵͳ£¬µ«ÔÚÈ«Ãæ¸´ÔǰÐèÈ·±£»ù´¡ÉèÊ©°²È«¡£ÕâÒ»ÊÂÎñÊÇÕë¶Ô¸ç˹´ïÀè¼Ó¹Ø¼ü»ù´¡ÉèÊ©ÍøÂç¹¥»÷Ç÷ÏòµÄÒ»Á¬£¬Ö®Ç°ContiÀÕË÷Èí¼þ×éÖ¯ÒÑ·¢Æð¹ýÀàËÆ¹¥»÷£¬µ¼Ö¸ù»ù·þÎṉ̃»¾£¬ÆÈʹ×Üͳ°ä·¢´¹Î£×´Ì¬²¢»ñµÃÃÀ¹úÔöÔ®¡£Ö»¹ÜÓйز¿ÃÅ·ñ¶¨¸ü¶à¹¥»÷µÄÒ¥ÑÔ£¬µ«RECOPEÊÂÎñ͹ÏÔÁ˹ؼü»ù´¡ÉèÊ©Ò×ÊÜÍøÂçÍþвµÄ½ü¿ö£¬Óйز¿ÃŽ«»ý¼«²Î¼ÓÖ§³Ôì临Թ¤×÷¡£
https://securityonline.info/recope-costa-ricas-state-owned-energy-provider-grapples-with-ransomware-attack-and-fuel-supply-disruption/
4. ÂÞÂíÄáÑÇÑ¡¾ÙϵͳÔâ·ê³¬¹ý 85,000 ´ÎÍøÂç¹¥»÷
12ÔÂ5ÈÕ£¬ÂÞÂíÄáÑǵý±¨¾ÖµÄÒ»·Ý½âÃܻ㱨ָ³ö£¬¸Ã¹úÑ¡¾Ù»ù´¡ÉèÊ©ÔÚ×Üͳѡ¾ÙÆÚ¼äÔâ·êÁ˳¬¹ý85,000´ÎÍøÂç¹¥»÷£¬¹¥»÷Ô´×Ô33¸ö¹ú¶È¡£¹¥»÷ÕßÈëÇÖÁËһ̨Ô̺¬µØÍ¼Êý¾ÝµÄ·þÎñÆ÷£¬²¢Ð¹Â¶ÁËÓëÑ¡¾ÙÓйصÄÍøÕ¾µÄÕË»§Æ¾Ö¤ÔÚ¶íÂÞ˹ºÚ¿ÍÂÛ̳ÉÏ¡£ÕâЩ¹¥»÷³ÖÐøµ½µÚÒ»ÂÖ×Üͳѡ¾ÙºóµÄµÚ¶þÌ죬ָ±êÔ̺¬·ÛËéÑ¡¾Ù»ù´¡ÉèÊ©¡¢¸ü¸Ä¹«¼ÒÑ¡¾ÙÐÅÏ¢ºÍ»Ø¾ø½Ó¼ûϵͳ¡£ÂÞÂíÄáÑǵý±¨»ú¹¹ÖÒ¸æ³Æ£¬Ñ¡¾Ù»ù´¡ÉèÊ©ÈÔ´æÔÚ·ì϶£¬¿ÉÄܻᱻÀûÓýøÐÐÍøÂçºáÏòÒÆ¶¯ºÍ³ÉÁ¢ÓƾÃÐÔ¡£´Ë±í£¬»ã±¨»¹Ö¸³ö£¬³¬¹ý100ÃûÂÞÂíÄáÑÇTikTokÓ°ÏìÕß±»°Ñ³ÖÀ´·Ö·¢Ðû´«×ÜͳºòÑ¡ÈË¿¨ÁÖ¡¤ÇÇÖÎ˹¿âµÄÑ¡¾ÙÄÚÈÝ£¬ÕâЩÕË»§ÔÚÑ¡¾ÙÈÕǰÁ½ÖܱäµÃ·Ç³£»îÔ¾£¬ÆäÖÐһЩÕË»§ÉõÖÁ´Ó2016Äê´´½¨µ«Ö±µ½½üÆÚ²ÅÆðÍ·»îÔ¾¡£ÂÞÂíÄáÑǶԱíµý±¨¾ÖÖ¸³ö£¬¶íÂÞ˹½üÆÚÓйýÎÊÆäËû¹ú¶ÈÑ¡¾ÙµÄº¹Ç࣬²¢½«ÂÞÂíÄáÑÇÊÓΪµÐ¹ú£¬ÓÉÓÚÂÞÂíÄáÑÇÔÊÐí±±Ô¼ÔÚ±±Ô¼¶«²¿×¤¾ü¡£
https://www.bleepingcomputer.com/news/security/romanias-election-systems-targeted-in-over-85-000-cyberattacks/
5. ÀÕË÷Èí¼þ×éÖ¯Brain CipherÐû³ÆÈëÇÖµÂÇÚÓ¢¹ú
12ÔÂ4ÈÕ£¬³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þ×éÖ¯Brain CipherÐû³ÆÒѳɹ¦ÈëÇÖµÂÇÚÓ¢¹ú¹«Ë¾£¬²¢ÇÔÈ¡Á˳¬¹ý1TBµÄÃô¸ÐÊý¾Ý¡£¸Ã×éÖ¯ÓÚ2024Äê6Ô³öÏÖ£¬Ôø¶ÔÈ«Çò¶à¸ö×éÖ¯½øÐÐÍøÂç¹¥»÷£¬Ô̺¬¶ÔÓ¡¶ÈÄáÎ÷Ñǹú¶ÈÊý¾ÝÖÐÐĵijÁ´ó¹¥»÷¡£¾ÝBrain Cipher°ä²¼µÄÉêÃ÷£¬Õâ´Î¹¥»÷¶³öÁ˵ÂÇÚÓ¢¹úÍøÂ簲ȫ»ù´¡ÉèÊ©µÄ·ì϶¡£ËûÃÇ´òËã°ä²¼Õâ´ÎÈëÇֵľßÌåÐÅÏ¢£¬Ô̺¬ÉæÏÓÎ¥·´°²È«ºÍ̸µÄÖ¤¾Ý¡¢µÂÇÚÓë¿Í»§Ö®¼äµÄºÏͬºÍ̸·ÖÎö¡¢¼à¿ØÏµÍ³ºÍ°²È«¹¤¾ßµÄ¾ßÌåÐÅÏ¢ÒÔ¼°ÊÜËðÊý¾ÝµÄʾÀý¡£´Ë±í£¬¸Ã×éÖ¯ÒÑÔ¼ÇëµÂÇÚ´ú±í½øÐаµÀï»áÉÌ£¬Õâ¿ÉÄÜÅú×¢´æÔÚÊê½ð½»ÉæµÄ̰ͼ¡£Õâ´Îй¶ÊÂÎñ¿ÉÄÜÓ°ÏìµÂÇÚÓ¢¹úµÄÆóÒµ¿Í»§¡¢»úÃÜóÒ×ÐÅÏ¢¡¢¿Í»§Êý¾ÝºÍ²ÆÕþ¼Í¼ÒÔ¼°¸Ã¹«Ë¾µÄרҵÃûÓþ¡£È»¶ø£¬µÂÇÚÓ¢¹úÉÐδ¹«¿ªÈ·ÈÏ»ò·ñ¶¨Õâ´ÎÈëÇÖÊÂÎñ£¬ÍøÂ簲ȫÐÂÎÅÍŶÓÔÚÇ×êǹØ×¢ÊÂ̬·¢Õ¹¡£
https://cybersecuritynews.com/deloitte-hacked/
6. ¶íÂÞ˹·¨Ê½Ô±ÊÖ»ú±»FSBËÍ»¹ºó·¢ÏÖÔâ°ÂÃØ×°ÖÃмäµýÈí¼þ
12ÔÂ5ÈÕ£¬Ò»Ãû¶íÂÞ˹·¨Ê½Ô±Kirill ParubetsÔÚ±»¶íÂÞ˹Áª¹ú°²È«¾Ö£¨FSB£©¿ÛÁô15Ìì²¢³ä¹«ÊÖ»úºó£¬·¢ÏÖÉ豸ÔÚËÍ»¹ºó±»°ÂÃØ×°ÖÃÁËеļäµýÈí¼þ¡£¸Ã¼äµýÈí¼þ·ÂÕÕÁËÊ¢ÐеÄAndroidÀûÓ÷¨Ê½¡°Cube Call Recorder¡±£¬µ«Õ¼ÓÐ¿í·ºµÄȨÏÞ£¬Äܹ»²»ÊÜÏ޶ȵؽӼûÉ豸£¬²¢ÔÊÐí¹¥»÷Õ߼ලÊÖ»úÉϵĻ¡£¾¹ý¹«Ãñ³¢ÊÔÊÒµÄȡ֤·ÖÎö£¬È·ÈϸöñÒâÈí¼þÊÇMonokleµÄа汾»òÓÉÒ»Ñù´úÂë´´½¨µÄÐÂÈí¼þ¡£¸Ã¼äµýÈí¼þʹÓüÓÃܵÄÁ½½×¶Î¹ý³Ì£¬ÓµÓиú×ÙµØÎ»¡¢½Ó¼û¶ÌÐÅ¡¢ÁªÏµÈË¡¢ÈÕÀú¡¢¼Í¼µç»°ºÍÊÓÆµ¡¢ÌáÈ¡ÐÂÎÅ¡¢ÎļþºÍÃÜÂëµÈ¶àÖÖÖ°ÄÜ¡£´Ë±í£¬´úÂëÖз¢ÏÖÁ˶ÔiOSµÄÒýÓã¬Åú×¢¿ÉÄÜ´æÔÚ¿ÉÔÚApple iPhoneÉ豸ÉÏÔËÐеıäÌå¡£É豸±»·¨Âɲ¿Ãų乫ºóÓÖ±»ËÍ»¹µÄÈËÓ¦ÊÔÂÇ»»ÓÃÆäËûÉ豸»ò½»¸ø×¨¼Ò·ÖÎö£¬ÉúÑÄÔÚѹÆÈÐÔ¹ú¶ÈµÄÈËÓ¦²ÉÈ¡´ëÊ©±£»¤×Ô¼ºµÄÉ豸°²È«¡£
https://www.bleepingcomputer.com/news/security/new-android-spyware-found-on-phone-seized-by-russian-fsb/


¾©¹«Íø°²±¸11010802024551ºÅ