
轉發國家資通安全研究院與TWCERT/CC漏洞警訊公告,請同仁儘速確認並進行更新或修補作業,以降低相關資安風險。
1.駭客偽冒財政部發動社交工程郵件攻擊
■國家資通安全研究院(NICS)近期發現攻擊者偽冒財政部名義,透過電子郵件發動社交工程攻擊。這些郵件以“稅務調查”為由,誘使收件者開啟並下載帶有惡意程式碼的附件。此類攻擊手段可能對企業與個人造成嚴重的資料外洩與系統入侵風險。
■處置建議:留意可疑電子郵件,注意郵件來源正確性,勿開啟不明來源之郵件與相關附檔。
2.駭客對Google日曆釣魚手法的調整
■Check Point資安團隊近期揭漏駭客新型社交工程攻擊手法,透過修改寄件標頭誘使受害者點擊Google日曆邀請連結,進而竊取個人或企業資料。在研究期間,該團隊觀察超過4,000封類似釣魚郵件,受害者涵蓋教育機構、醫療服務、建築公司及銀行等。
■處置建議:Google建議用戶啟用Google日曆中的「已知發件人」設置,當收到聯絡人名單以外或未曾互動的電子郵件地址邀請時,系統將發出告警。
3.利用SEO中毒(SEO Poisoning)導向使用者到詐騙網站
■近期觀察發現搜尋引擎最佳化中毒(SEO Poisoning)攻擊事件增加,當使用者搜尋特定關鍵字和網址時,可發現大量與賭博和投資相關可疑內容。初步調查,相關內容疑似源自攻擊者入侵合法網站,並透過操控搜尋引擎排名,將惡意網站推至搜尋結果頂端,誘導使用者誤點連結,最終可能導致下載惡意程式或洩露個人敏感資料。
■SEO Poisoning 是一種通過操控搜尋引擎排名的攻擊手法,攻擊者透過操控搜尋結果,當使用者搜尋特定關鍵字或網站時,會優先顯示與攻擊目的相關的轉址廣告,將使用者引導至惡意網站,進一步散佈惡意軟體或進行網路釣魚。常見的攻擊手法包括建立連結農場、植入惡意廣告、攻擊合法網站,以及採用內容遮蔽技術等。
■處置建議:
◆定期檢查網站內容、使用可信賴的網站工具及套件、強化網站安全性。
◆如發現SEO中毒時,請備份重要資料後,立即重新安裝作業系統。
4.ChatGPT爬蟲漏洞:AI武器化,你的網站恐成攻擊目標
■德國資安研究員Benjamin Flesch發現OpenAI的ChatGPT爬蟲存在一個嚴重安全漏洞,此漏洞可被利用發起分散式阻斷服務(DDoS)攻擊,對全球網站的運作造成威脅。目前研究員已向OpenAI回報此問題,但尚未收到回覆。
■此漏洞存在於ChatGPT的返回聊天機器人輸出,引用網路來源資訊的API端點,攻擊者可以提交多個不同的URL指向同一網站,使爬蟲訪問所有URL,造成DDoS攻擊。
■處置建議:在整合第三方 API 時,開發者或企業應更加注重嚴格的存取控制、定期進行漏洞掃描及滲透測試,並完善API端點的身份驗證和授權機制,以防止未經授權的存取和資料洩漏。
5.相關文章:
◆https://www.twcert.org.tw/tw/cp-104-8407-56dd3-1.html
◆https://www.twcert.org.tw/tw/cp-104-8342-8f940-1.html
◆https://www.twcert.org.tw/tw/cp-104-8349-91d56-1.html
◆https://www.twcert.org.tw/tw/cp-104-8412-5289c-1.html
如有資安相關問題,請洽電子計算機中心:
游順發組長 6209 rogeryu@mail.ntust.edu.tw
張云蘋 6929 applechang@mail.ntust.edu.tw
【Security】Vulnerability warning: social engineering email attack, SEO poisoning, ChatGPT crawler vulnerability
Hello everyone:
Forward the National Institute of Information and Communications Security and TWCERT/CC vulnerability warning announcement. Please confirm and update or patch as soon as possible to reduce related information security risks.
1.Hackers impersonate the Ministry of Finance to launch social engineering email attack
■The National Institute of Information and Communications Security (NICS) recently discovered that attackers impersonated the Ministry of Finance and launched social engineering attacks via email. These emails use the excuse of "tax investigation" to trick recipients into opening and downloading attachments containing malicious code. Such attacks may cause serious risks of data leakage and system intrusion to enterprises and individuals.
■Suggestions: Pay attention to suspicious emails, make sure the source of the email is correct, and do not open emails and related attachments from unknown sources.
2.Hackers adjust Google Calendar phishing tactics
■Check Point Security Team recently revealed a new social engineering attack method used by hackers, which modifies the email header to trick victims into clicking on Google Calendar invitation links, thereby stealing personal or corporate data. During the research period, the team observed more than 4,000 similar phishing emails, with victims including educational institutions, medical services, construction companies and banks.
■Suggestion: Google recommends that users enable the "Known Senders" setting in Google Calendar. When an invitation is received from an email address that is not in the contact list or has not been interacted with, the system will issue an alert.
3.Using SEO Poisoning to direct users to fraudulent websites
■Recent observations have found an increase in SEO poisoning attacks. When users search for specific keywords and URLs, they can find a large amount of suspicious content related to gambling and investment. Preliminary investigations revealed that the relevant content was suspected to have originated from attackers who hacked into legitimate websites and manipulated search engine rankings to push malicious websites to the top of search results, thereby inducing users to click on links by mistake, which could eventually lead to the downloading of malicious programs or the leakage of personal sensitive information.
■SEO Poisoning is an attack method that manipulates search engine rankings. Attackers manipulate search results so that when users search for specific keywords or websites, redirected ads related to the purpose of the attack will be displayed first, leading users to malicious websites to further spread malware or conduct phishing. Common attack methods include creating link farms, inserting malicious ads, attacking legitimate websites, and using content masking technology.
■Suggestions:
◆Regularly check website content, use reliable website tools and packages, and strengthen website security.
◆If you find that SEO is infected, please back up important data and reinstall the operating system immediately.
4.ChatGPT crawler vulnerability: AI weaponization, your website may become a target of attack
■German cybersecurity researcher Benjamin Flesch discovered a serious security vulnerability in OpenAI's ChatGPT crawler, which can be exploited to launch a distributed denial of service (DDoS) attack, posing a threat to the operation of websites around the world. The researcher has reported this issue to OpenAI, but has not received a response yet.
■This vulnerability exists in ChatGPT's returned chatbot output, which references the API endpoint of network source information. An attacker can submit multiple different URLs pointing to the same website, causing the crawler to access all URLs, causing a DDoS attack.
■Suggestions: When integrating third-party APIs, developers or enterprises should pay more attention to strict access control, conduct regular vulnerability scanning and penetration testing, and improve the authentication and authorization mechanisms of API endpoints to prevent unauthorized access and data leakage.
5.Related Articles:
◆https://www.twcert.org.tw/tw/cp-104-8407-56dd3-1.html
◆https://www.twcert.org.tw/tw/cp-104-8342-8f940-1.html
◆https://www.twcert.org.tw/tw/cp-104-8349-91d56-1.html
◆https://www.twcert.org.tw/tw/cp-104-8412-5289c-1.html
For more question about information security, please directly consult with Computer Center, at rogeryu@mail.ntust.edu.tw or applechang@mail.ntust.edu.tw