BTC $79,220.03 -0.85%
ETH $2,494.50 -0.16%
BNB $739.87 -1.53%
XRP $1.40 -1.58%
SOL $104.09 -1.55%
TRX $0.3345 -0.43%
DOGE $0.0906 +0.44%
ADA $0.2208 +0.05%
BCH $260.95 +1.22%
LINK $12.78 -2.27%
HYPE $85.30 -3.04%
AAVE $132.43 -0.73%
SUI $0.8299 +2.49%
XLM $0.1928 +4.11%
ZEC $1,155.60 -5.03%
BTC $79,220.03 -0.85%
ETH $2,494.50 -0.16%
BNB $739.87 -1.53%
XRP $1.40 -1.58%
SOL $104.09 -1.55%
TRX $0.3345 -0.43%
DOGE $0.0906 +0.44%
ADA $0.2208 +0.05%
BCH $260.95 +1.22%
LINK $12.78 -2.27%
HYPE $85.30 -3.04%
AAVE $132.43 -0.73%
SUI $0.8299 +2.49%
XLM $0.1928 +4.11%
ZEC $1,155.60 -5.03%

afa

Tất cả
Bài viết
Tin nhanh

Slow Mist: iOS Safari DarkSword tấn công có thể đánh cắp thông tin ví, kích hoạt chuỗi sáu lỗ hổng mà không cần nhấp chuột

Theo thông tin từ đội ngũ an ninh Slow Mist, họ đã phát hiện một hoạt động tấn công giả mạo dịch vụ VPS miễn phí, nhắm vào trình duyệt Safari trên iPhone chạy phiên bản iOS 18.4 đến 18.6.2.Kẻ tấn công đã lợi dụng sáu lỗ hổng mang mã DarkSword để hình thành chuỗi tấn công hoàn chỉnh, bao gồm thực thi mã từ xa WebKit, thoát khỏi sandbox và đọc/ghi kernel, có thể lấy được tệp container ứng dụng và dữ liệu chuỗi khóa mà người dùng không hề hay biết, đồng thời ghi lại các đầu vào từ bàn phím khi các ví như imToken, TokenPocket hoặc TronLink đang ở chế độ nền.Đội ngũ Slow Mist cho biết, sáu lỗ hổng trên hiện đã được Apple khắc phục, và cuộc tấn công hiện tại thuộc về việc tái sử dụng chuỗi lỗ hổng n-day. Chỉ việc truy cập vào trang web độc hại không thể chứng minh trực tiếp rằng cụm từ ghi nhớ hoặc khóa riêng đã bị đánh cắp, vẫn cần phải xác minh thông qua việc thu thập chứng cứ từ thiết bị. Khuyến nghị người dùng iOS/iPadOS nhanh chóng nâng cấp hệ thống lên phiên bản 18.7.3 hoặc 26.3 trở lên.

The security incidents at GitHub and Grafana are likely related to a large-scale "mini sandworm" supply chain attack

According to the threat intelligence released by Slow Fog, several high-frequency npm packages including AntV and Echarts-for-react, as well as the Python SDK durabletask, have recently been targeted by the Mini Shai-Hulud "mini sandworm" supply chain attack. The npm account atool was compromised, and the attacker automatically published 637 malicious versions within 22 minutes, affecting 317 packages. The attacker continuously uploaded durabletask versions 1.4.1, 1.4.2, and 1.4.3 within 35 minutes, bypassing normal release controls and impersonating an official Microsoft release.The large-scale leak of GitHub tokens and the ransomware attack on Grafana Labs are likely related to this supply chain attack. Affected components include high-frequency components such as AntV and Echarts-for-react in the npm ecosystem, as well as Python packages durabletask 1.4.1, 1.4.2, and 1.4.3. Attackers can steal cloud and local credentials, gain unauthorized access to internal repositories and sensitive cloud infrastructure, move laterally to developer machines and CI/CD pipelines, sell and exploit leaked GitHub tokens, and implement ransom and data leak threats.Slow Fog recommends immediately rotating all exposed credentials, replacing affected packages, isolating potentially infected systems, and implementing strict dependency review policies. Previously, it was reported that the "mini sandworm" worm had recently completed widespread infection in open-source code repositories, and developers should be vigilant in checking for issues.

Grafana: Investigation reveals that recent security incidents have not affected customer production systems and operations

The open-source data visualization tool Grafana has released the latest progress on the investigation of the security incident on May 16. The investigation found that this incident was limited to the GitHub environment of Grafana Labs, including both public and private source code as well as internal GitHub repositories, and did not affect customer production systems, operations, or the Grafana Cloud platform. The downloaded content, in addition to the source code, also included some repositories used by the team for collaboration and storage of internal operational information and business details, involving business contact names and email addresses, rather than data from production systems or the cloud platform.Grafana Labs has made it clear that the codebase was downloaded but not tampered with, and currently, customers and open-source users do not need to take any action. The incident originated from a TanStack npm supply chain attack conducted through the Mini Shai-Hulud campaign. Grafana Labs detected malicious activity on May 11 and initiated an emergency response, but a credential was overlooked, allowing the attacker to gain access. After receiving a ransom demand on May 16, the company decided not to pay the ransom and has rotated automated credentials, implemented enhanced monitoring, audited all commits since May 11, and significantly strengthened GitHub security configurations. The company has notified federal law enforcement, and the investigation is ongoing.
app_icon
ChainCatcher Building the Web3 world with innovations.