еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷
Ðû²¼Ê±¼ä 2024-08-271. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷
8ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ËüÓÉ×·Çó¾¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ£¬£¬£¬£¬£¬£¬½ÓÄÉÁËÒ»ÖÖÆæÒìµÄÕ½ÂÔÒÔʵÏÖºã¾ÃDZÔÚºÍÒþÃØ¹¥»÷¡£¡£¡£×Ô2022ÄêÆð£¬£¬£¬£¬£¬£¬¸Ã¸ß¼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä£¬£¬£¬£¬£¬£¬Îª¹¥»÷ÕßÌṩÁË·´ÏòshellͨµÀºÍ׿ԽµÄÒþ²ØÊֶΡ£¡£¡£Æä½¹µãÌØÉ«ÔÚÓÚʹÓÃudev¹æÔòÀ´Î¬³ÖÆäÔÚϵͳÄڵij¤ÆÚÐÔ£¬£¬£¬£¬£¬£¬ÕâÊÇͨ¹ý¼à²âϵͳ½¹µã×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ£¬£¬£¬£¬£¬£¬Ã¿µ±ÏµÍ³ÖØÆôʱ¼´×Ô¶¯¼¤»î¶ñÒâ³ÌÐò¡£¡£¡£sedexpͨ¹ýudevµÄÖØ´óÉèÖ㬣¬£¬£¬£¬£¬Äܹ»ÔÚ²»±»²ì¾õµÄÇéÐÎÏÂÖ´ÐжñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬²¢ÇÉÃîµØÐÞ¸ÄϵͳÄڴ棬£¬£¬£¬£¬£¬Òþ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ£¬£¬£¬£¬£¬£¬ÓÐÓùæ±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄÕì²é¡£¡£¡£¸üΪ½ÆÕ©µÄÊÇ£¬£¬£¬£¬£¬£¬ËüÒѱ»ÊӲ쵽ÓÃÓÚÔÚЧÀÍÆ÷ÉÏÒþÃØ°²ÅÅÐÅÓÿ¨Êý¾ÝÇÔÈ¡´úÂ룬£¬£¬£¬£¬£¬Í¹ÏÔÁËÆäÃ÷È·µÄ¾¼ÃÀûÒæµ¼Ïò¡£¡£¡£Stroz FriedbergÊÂÎñÏìÓ¦ÍŶÓÖ¸³ö£¬£¬£¬£¬£¬£¬ÔÚÒÑÊӲ참ÀýÖУ¬£¬£¬£¬£¬£¬sedexp²»µ«Òþ²ØÁËWeb ShellºÍÐ޻ڸĵÄApacheÉèÖÃÎļþ£¬£¬£¬£¬£¬£¬»¹×ÔÐÐÐÞ¸ÄÁËudev¹æÔò£¬£¬£¬£¬£¬£¬ÐγÉÁËÒ»¸ö±Õ»·µÄÒþ²ØÏµÍ³¡£¡£¡£ÕâÒ»·¢Ã÷Õ¹ÏÖÁ˳ýÀÕË÷Èí¼þÍ⣬£¬£¬£¬£¬£¬ÒÔ¾¼ÃΪĿµÄµÄÍøÂç¹¥»÷ÊÖ¶ÎÕýÈÕÒæÖØ´ó»¯¡£¡£¡£
https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html
2. Ê¢ÐÐPython¿âPandasÆØÇå¾²Îó²îCVE-2024-42992
8ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬ÆÕ±éʹÓÃµÄ Python ¿âpandasÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²îCVE-2024-42992£¬£¬£¬£¬£¬£¬¸ÃÎó²î²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï7.5£¬£¬£¬£¬£¬£¬Í¹ÏÔÁËÓû§ÃæÁÙµÄÖØ´óΣº¦¡£¡£¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î£¬£¬£¬£¬£¬£¬³ÉΪÊý¾Ý´¦Öóͷ£ÓëÆÊÎöµÄ½¹µã¹¤¾ß£¬£¬£¬£¬£¬£¬ÕâÒ»·¢Ã÷ÓÈΪÁîÈ˵£ÐÄ¡£¡£¡£´ËÎó²îΪí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬ÄÜÈù¥»÷ÕßÎÞÏÞÖÆµØ»á¼ûϵͳÄÚµÄí§ÒâÎļþ£¬£¬£¬£¬£¬£¬°üÀ¨Ãô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£¡£¡£ÆäȪԴÔÚÓÚpandasÔÚ´¦Öóͷ£Îļþ·¾¶ÊäÈëʱȱ·¦ÐëÒªµÄÏÞÖÆ£¬£¬£¬£¬£¬£¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨í§Òâ·¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¸ÃÎó²îÔÚ¶à¸öÔÚÏßÇéÐÎÖÐÒ×ÓÚ¸´ÏÖ£¬£¬£¬£¬£¬£¬ÇÒÆä¿´·¨ÑéÖ¤´úÂëÒÑÔÚGitHubÉϹûÕæ£¬£¬£¬£¬£¬£¬ÏÔÖøÔöÌíÁ˱»¶ñÒâʹÓõÄΣº¦¡£¡£¡£¼øÓÚpandasµÄÆÕ±éÓ¦Ó㬣¬£¬£¬£¬£¬´ËÎó²î¶ÔϵͳÉñÃØÐÔºÍÍêÕûÐÔ×é³ÉÁËÑÏÖØÍþв£¬£¬£¬£¬£¬£¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾ÊÚȨ»á¼ûµÄΣº¦ÖèÔö¡£¡£¡£ÃæÁÙÉÐÎÞ¹Ù·½²¹¶¡µÄÏÖ×´£¬£¬£¬£¬£¬£¬Óû§ÐèÁ¬Ã¦½ÓÄÉÔ¤·À²½·¥£¬£¬£¬£¬£¬£¬ÈçÏÞÖÆÔÚÃôÇéÐ÷ÐÎÖÐʹÓÃpandas£¬£¬£¬£¬£¬£¬²¢Ôöǿϵͳ¼à¿ØÓëÇå¾²²½·¥£¬£¬£¬£¬£¬£¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£¡£¡£
https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/
3. Cheana StealerÌᳫ¿çƽ̨VPN´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý
8ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬Cyble Ñо¿ÓëÇ鱨ʵÑéÊÒ ( CRIL ) ·¢Ã÷µÄ×îÐÂÍþвCheana Stealer£¬£¬£¬£¬£¬£¬¸Ã¶ñÒ⹤¾ßͨ¹ýαװ³É×ÅÃûVPNЧÀÍWarpVPNµÄÍøÂç´¹ÂÚÊֶΣ¬£¬£¬£¬£¬£¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£¡£¡£Cheana StealerʹÓÃÈ«ÐÄÉè¼ÆµÄ´¹ÂÚÍøÕ¾ÓÕÆÓû§ÏÂÔØ²¢×°ÖÃαװ³ÉÕýµ±VPNÈí¼þµÄÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬£¬Ò»µ©µ½ÊÖ£¬£¬£¬£¬£¬£¬±ãÇÄÎÞÉùÏ¢µØÍøÂç°üÀ¨ä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£¡£¡£Õë¶Ô²î±ð²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬Cheana Stealer½ÓÄɲî±ðµÄÊÖÒÕÊֶΣºÔÚWindowsÉÏ£¬£¬£¬£¬£¬£¬ËüʹÓÃPowerShellÖ´ÐжñÒâ¾ç±¾£»£»£»£»£»£»Linux°æÔòͨ¹ýαװCloudflare Warp VPNµÄshell¾ç±¾ÊµÑé¹¥»÷£»£»£»£»£»£»macOSÉÏÔòʹÓÃÐéαϵͳÌáÐÑÇÔÈ¡Keychain¼°¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬¸ÃÇÔÈ¡³ÌÐòµÄÈö²¥ÓëÒ»¸öÓµÓÐÊýÍò¶©ÔÄÕßµÄTelegramƵµÀϸÃÜÏà¹Ø£¬£¬£¬£¬£¬£¬ÆµµÀÄÚÆµÈÔÐû´«Ã°³äVPNЧÀÍ£¬£¬£¬£¬£¬£¬¼«´óÖú³¤Á˹¥»÷¹æÄ£¡£¡£¡£CRILµÄÑо¿Õ¹ÏÖ£¬£¬£¬£¬£¬£¬¹¥»÷Õß³õÆÚÌṩÕýµ±Ð§ÀÍÒÔ»ýÀÛÐÅÈΣ¬£¬£¬£¬£¬£¬ËæºóתÏò¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬Í¨¹ýTelegramµÈÐÅÓþƽ̨¼°¸ß¶È·ÂÕæµÄ´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬ÀÖ³ÉÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´ó×ÚÓû§ÏµÍ³£¬£¬£¬£¬£¬£¬Í¹ÏÔÁËÄ¿½ñÍøÂçÇå¾²ÌôÕ½µÄÑÏËàÐÔ¡£¡£¡£
https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/
4. Mirai½©Ê¬ÍøÂçÖз¢Ã÷ÑÏÖØÎó²îCVE-2024-45163
8ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ô±Jacob MasseÕ¹ÏÖÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑÏÖØÎó²îCVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNCЧÀÍÆ÷¾ÙÐÐÔ¶³ÌDoS¹¥»÷£¬£¬£¬£¬£¬£¬ÑÏÖØÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£¡£¡£Mirai×÷ΪһÖÖÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬×Ô2016ÄêÆð±ãÈÅÂÒÎïÁªÍøºÍЧÀÍÆ÷ÁìÓò£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃÈõÃÜÂëµÈÎó²î¿ØÖÆ´ó×Ú×°±¸£¬£¬£¬£¬£¬£¬ÐγÉÖØ´óµÄ½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Ö´ÐÐDDoS¹¥»÷µÈ¶ñÒâ»î¶¯¡£¡£¡£Jacob Masseͨ¹ýÉîÈëÑо¿CNCЧÀÍÆ÷µÄÔË×÷»úÖÆ£¬£¬£¬£¬£¬£¬·¢Ã÷ÁËÆäÔÚ´¦Öóͷ£²¢·¢ÅþÁ¬ÇëÇóʱµÄȱÏÝ£¬£¬£¬£¬£¬£¬ÌØÊâÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£¡£¡£ÕâÒ»Îó²îÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´ó×Ú¼òÆÓµÄÉí·ÝÑéÖ¤ÇëÇ󣬣¬£¬£¬£¬£¬Ê¹CNCЧÀÍÆ÷×ÊÔ´ºÄ¾¡²¢Í߽⣬£¬£¬£¬£¬£¬´Ó¶øÌ±»¾Õû¸ö½©Ê¬ÍøÂç¡£¡£¡£CVE-2024-45163µÄÅû¶²»µ«ÎªÖ´·¨»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß£¬£¬£¬£¬£¬£¬Ò²Òý·¢Á˹ØÓÚÆ·µÂʹÓõÄÌÖÂÛ£¬£¬£¬£¬£¬£¬ÓÉÓÚʹÓôËÎó²î¿ÉÄÜÒâÍâÖÐÖ¹Õýµ±²âÊÔÖеĽ©Ê¬ÍøÂç¡£¡£¡£Masseͨ¹ýPoCÑÝʾÁËÎó²îµÄÓÐÓÃÐÔ£¬£¬£¬£¬£¬£¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿ÉÀֳɹرÕCNCЧÀÍÆ÷µÄ³¡¾°¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ëû»¹¹ûÕæÁËÎó²î´úÂ룬£¬£¬£¬£¬£¬Ôö½øÁËÍøÂçÇå¾²ÉçÇøµÄÑо¿Óë·ÀÓùÊÂÇé¡£¡£¡£
https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/
5. Magentoƽ̨ÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µÁË¢³ÌÐòÇÔȡ֧¸¶Êý¾Ý
8ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬ÖÚ¶à½ÓÄÉMagentoƽ̨µÄÔÚÏßÊÐËÁ½üÆÚÔâÓöÁËÑÏÖØÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»²»·¨ÇÔÈ¡£¡£¡£¬£¬£¬£¬£¬£¬°üÀ¨¿¨ºÅ¡¢ÓÐÓÃÆÚ¼°Çå¾²ÂëµÈÖ÷ÒªÐÅÏ¢¡£¡£¡£Malwarebytesר¼ÒÖ¸³ö£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃMagentoϵͳÎó²î£¬£¬£¬£¬£¬£¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðо籾£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÄÜÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£¡£¡£Êý°Ù¼ÒµêËÁÒÑÈ·ÈÏÊÜÇÖ£¬£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÍøÂç±»µÁÊý¾Ý¡£¡£¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒþ²Ø£¬£¬£¬£¬£¬£¬Äܹ»ÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì£¬£¬£¬£¬£¬£¬ÄÑÒÔ±»Óû§²ì¾õ¡£¡£¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶»ñ²¢×ª·¢ÖÁºÚ¿ÍЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÉõÖÁÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬£¬Äܹ»ÈƹýµÚÈý·½Ö§¸¶´¦Öóͷ£Á÷³ÌÖ±½Ó×èµ²Êý¾Ý¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬£¬Ç徲ר¼ÒÒÑ×èµ²Áè¼Ý1,100´ÎÊý¾ÝÇÔȡʵÑ飬£¬£¬£¬£¬£¬Í¨¹ýʶ±ð²¢·â±ÕÊýÊ®¸ö¶ñÒâÓòÃûÓÐÓÃ×èÖ¹Á˲¿·Ö¹¥»÷¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄµêËÁËäÒѽÓÄÉɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ²½·¥£¬£¬£¬£¬£¬£¬µ«²¿·ÖÍøÕ¾ÈÔÃæÁÙÒ»Á¬Íþв¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Êý¾Ýй¶²»µ«ÏÞÓÚ²ÆÎñÐÅÏ¢£¬£¬£¬£¬£¬£¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈСÎÒ˽¼ÒÒþ˽¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬Óû§Èô·¢Ã÷Òì³££¬£¬£¬£¬£¬£¬Ó¦Á¬Ã¦ÁªÏµÒøÐÐÌæ»»¿¨Æ¬£¬£¬£¬£¬£¬£¬²¢Ë¼Á¿ÆôÓÃÉí·Ý±£»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£
https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/
6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬72.6Íò¿Í»§Êý¾Ýй¶
8ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬PatelcoÐÅÓÃÏàÖúÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇÓªÀûÐÔ½ðÈÚЧÀÍ»ú¹¹£¬£¬£¬£¬£¬£¬½üÆÚÔâÓöÑÏÖØÊý¾Ýй¶ÊÂÎñ¡£¡£¡£½ñÄêÔçЩʱ¼ä£¬£¬£¬£¬£¬£¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬Ö»¹ÜÆäʱδÁ¬Ã¦È·ÈÏÊý¾Ýй¶£¬£¬£¬£¬£¬£¬µ«ËæºóÊÓ²ìÕ¹ÏÖ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂ磬£¬£¬£¬£¬£¬²¢ÓÚ6ÔÂ29ÈÕ»á¼ûÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÁË´ó×Ú¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£ÕâЩÃô¸ÐÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢³öÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ£¬£¬£¬£¬£¬£¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾ÉÏÐû²¼µÄÊý¾ÝÒ»Ö£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÉù³ÆÔÚ̸ÅÐδ¹ûЧ¹ûÕæÁËÊý¾Ý¡£¡£¡£´Ë´ÎÊÂÎñ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£¡£¡£ÎªÓ¦¶Ô´Ë´ÎΣ»£»£»£»£»£»ú£¬£¬£¬£¬£¬£¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý±£»£»£»£»£»£»¤ºÍÐÅÓÃ¼à¿ØÐ§À͵ÄÑ¡Ï£¬£¬£¬£¬£¬×èÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøÎ»ÖÃÐû²¼ÖÒÑÔ£¬£¬£¬£¬£¬£¬ÌáÐÑ»áԱСÐÄÍøÂç´¹ÂÚ¡¢Éç»á¹¤³Ì¼°Õ©ÆÎ£º¦£¬£¬£¬£¬£¬£¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£¡£¡£
https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/