AI Security AI安全 14h ago Updated 9h ago 更新于 9小时前 39

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug 其他新闻:僵尸卡攻击、T-Mobile剪线阻止黑客、GitHub否认AI导致Bug

CISA mandates federal agencies prioritize patching CVE-2025-62593, an actively exploited code injection flaw in Ray-Project, weaponized by the RondoDox botnet using 174 distinct exploits against edge devices Wiz's autonomous AI agent discovered and exploited a critical GitHub Actions workflow vulnerability in Snowflake's public repo, though GitHub clarified the vulnerable code was human-authored, not AI-generated Medusa ransomware affiliates are rapidly exploiting vulnerabilities in Fortra GoAny CISA将Ray项目CVE-2025-62593代码注入漏洞列入已知被利用漏洞目录,联邦机构需优先修复,该漏洞正被RondoDox僵尸网络(Mirai衍生,含174种利用方式)主动利用 Wiz自主AI工具发现Snowflake仓库GitHub Actions工作流漏洞并获取Jira访问权限,GitHub澄清漏洞代码由人类编写而非GitHub Copilot引入 Medusa勒索软件团伙快速利用Fortra GoAnywhere和BeyondTrust新披露漏洞攻击关键基础设施,已影响超500家机构,采用Minidump凭证窃取和Interactsh动态URL验证等新型规避技术 学术研究者展示Z

55
Hot 热度
62
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • CISA mandates federal agencies prioritize patching CVE-2025-62593, an actively exploited code injection flaw in Ray-Project, weaponized by the RondoDox botnet using 174 distinct exploits against edge devices
  • Wiz's autonomous AI agent discovered and exploited a critical GitHub Actions workflow vulnerability in Snowflake's public repo, though GitHub clarified the vulnerable code was human-authored, not AI-generated
  • Medusa ransomware affiliates are rapidly exploiting vulnerabilities in Fortra GoAnywhere and BeyondTrust, with over 500 critical infrastructure organizations compromised and an evolving evasion toolkit including Minidump credential theft
  • Academic researchers demonstrated the "Zombie Card" attack, bypassing cryptographic checks on contactless Visa payments by using a smartphone relay to alter expiration dates fed to POS terminals
  • Crypto4A became the first company globally to achieve FIPS 140-3 Level 3 validation for a hardware security module supporting all NIST-approved post-quantum cryptographic algorithms

Why It Matters

This roundup underscores the accelerating convergence of AI capabilities with offensive cybersecurity operations, as autonomous AI agents now successfully identify and exploit complex infrastructure vulnerabilities—a capability that will only grow more sophisticated. The persistent exploitation of supply chain and third-party software vulnerabilities (GoAnywhere, BeyondTrust, Ray-Project) highlights the critical need for proactive threat monitoring and rapid patch management in enterprise environments. Meanwhile, the emergence of post-quantum cryptography certification and novel payment card attacks signals that both defensive and offensive security landscapes are undergoing rapid transformation.

Technical Details

  • CVE-2025-62593 (Ray-Project): A severe code injection vulnerability in the Ray distributed computing framework, added to CISA's Known Exploited Vulnerabilities catalog after active exploitation by RondoDox, a Mirai-inspired botnet employing 174 distinct exploit vectors against edge devices
  • Wiz autonomous AI agent: An AI-driven security tool that successfully identified a critical GitHub Actions workflow vulnerability in Snowflake's public repository, chaining it to gain unauthorized access to internal Jira tickets; GitHub confirmed the vulnerable code was human-authored
  • Medusa ransomware evasion toolkit: Affiliates now utilize Minidump for credential theft and Interactsh dynamic URLs to verify successful network exploitation, targeting vulnerabilities in Fortra GoAnywhere and BeyondTrust products across critical infrastructure
  • Zombie Card attack: A relay-based attack exploiting a communication gap between POS terminal hardware and issuing banks, using a smartphone to modify the expiration date transmitted to the terminal, bypassing cryptographic validation on select Visa cards
  • Crypto4A QASM module: The first HSM to achieve FIPS 140-3 Level 3 validation with support for all NIST-approved post-quantum cryptographic algorithms, providing tamper-resistant key storage against future quantum computing threats

Industry Insight

  • Organizations must treat autonomous AI security tools as both defensive assets and potential threat multipliers; the Wiz-Snowflake incident demonstrates that AI agents can now perform complex, multi-step exploitation chains that previously required skilled human operators
  • The Medusa ransomware advisory signals an urgent need for inventory and patch management of Fortra GoAnywhere and BeyondTrust products, particularly for critical infrastructure operators who are primary targets
  • The Zombie Card attack reveals that payment ecosystem security depends on assumptions about communication integrity between terminals and issuing banks; card networks and merchants should audit relay attack surface and implement transaction binding mechanisms
  • Crypto4A's post-quantum HSM certification marks a practical milestone for organizations planning quantum-resistant cryptography migration, providing a validated hardware foundation for key protection in the post-quantum era

TL;DR

  • CISA将Ray项目CVE-2025-62593代码注入漏洞列入已知被利用漏洞目录,联邦机构需优先修复,该漏洞正被RondoDox僵尸网络(Mirai衍生,含174种利用方式)主动利用
  • Wiz自主AI工具发现Snowflake仓库GitHub Actions工作流漏洞并获取Jira访问权限,GitHub澄清漏洞代码由人类编写而非GitHub Copilot引入
  • Medusa勒索软件团伙快速利用Fortra GoAnywhere和BeyondTrust新披露漏洞攻击关键基础设施,已影响超500家机构,采用Minidump凭证窃取和Interactsh动态URL验证等新型规避技术
  • 学术研究者展示Zombie Card攻击,通过智能手机中继篡改POS终端接收的过期日期,绕过Visa非接触式支付加密验证,但攻击不适用于Mastercard、Amex、Discover及所有银行
  • Crypto4A成为全球首家获得FIPS 140-3 Level 3认证的HSM厂商,支持所有NIST批准的后量子密码算法,为量子计算时代密钥保护提供硬件级保障

为什么值得看

本文汇总了当前网络安全领域的关键威胁动态,涵盖国家级APT攻击、勒索软件演进、AI安全验证、支付系统漏洞及后量子密码学进展,为安全从业者和企业决策者提供全面的威胁态势感知。

技术解析

  • Ray漏洞利用链:CVE-2025-62593为Ray-Project的严重代码注入漏洞,RondoDox僵尸网络采用174种不同利用方式针对边缘设备,体现多漏洞组合攻击的复杂化趋势
  • AI辅助安全测试验证:Wiz自主AI工具成功识别GitHub Actions工作流中的关键漏洞,证明AI在自动化漏洞发现领域的有效性,同时澄清AI引入安全问题的误解
  • Medusa勒索软件技术栈:采用Minidump进行内存凭证窃取,利用Interactsh动态URL验证网络渗透成功,展现勒索软件团伙向专业化、工具化方向演进
  • Zombie Card支付攻击:利用Visa非接触式支付中本地POS终端与发卡行之间的通信间隙,通过智能手机中继篡改过期日期字段绕过加密检查,暴露支付协议层设计缺陷
  • 后量子密码学硬件认证:Crypto4A QASM模块实现FIPS 140-3 Level 3验证,支持所有NIST后量子密码算法,为量子计算威胁到来前的密钥保护提供合规硬件基础

行业启示

  • 供应链安全需端到端覆盖:从GitHub Actions工作流到企业数据目录(Alation),攻击者持续利用第三方组件和集成漏洞渗透,企业需建立覆盖整个软件供应链的安全验证机制
  • 国家级APT攻击持续升级:Salt Typhoon针对电信基础设施的间谍活动及T-Mobile的物理切断响应,表明关键基础设施已成为国家支持黑客的首要目标,物理隔离与快速响应能力至关重要
  • 后量子迁移进入硬件落地阶段:Crypto4A认证标志着后量子密码学从标准制定迈向产品化,金融机构和关键基础设施运营商应启动密钥管理和加密算法迁移规划

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 LLM 大模型 Policy 政策