2024年2月7日星期三

釣魚警報 - 公眾應對利用AI Deepfake技術的偽造視像會議詐騙提高警惕

發佈日期: 2024年02月07日

類別: 網絡釣魚

網絡釣魚警告

現況及相關趨勢

近日,媒體報道警方首次發現有騙徒利用深度偽造(Deepfake)技術製作偽冒視像會議影片,冒充某跨國公司高層進行詐騙。該案涉及一名跨國公司的職員,這名職員最後被騙轉帳了港幣兩億元至五個本地帳戶。

 

警方表示,相信不法分子透過YouTube取得了該公司高層員工的公開影像和聲音。隨後,不法分子利用Deepfake技術製作了偽冒的視像會議影片片段,進行身份欺騙,冒充公司高層員工,然後對受害者下達指令,要求受害者將大筆資金轉帳至指定帳戶。同時以各種藉口迅速結束會議,使受害者無法提問,導致受害者誤信這些Deepfake的影片是即時的視像會議。

 

其實Deepfake是深度學習(Deep Learning)和偽造的混成詞。泛指以人工智能(AI)製作偽造訊息,如影像和聲音。常見於影片,影片中的人臉將被換成另一人面。這種技術亦可被用於偽造人聲,只需輸入字句便能假借受害者之聲線讀出,意味著製作深偽影片毋須配音員。然而在本次事件中,就有不法分子利用網上平台找到的臉部外觀和聲音來製作 Deepfake視像會議影片。

mickmick.net 呼籲公眾對此類利用AI Deepfake技術的詐騙提高警惕,並採取以下保安最佳實踐以保障自己:

 

  • 在進行視像會議前,應核實會議邀請者及會議連結的來源;
  • 對於任何影像和聲音,應該保持謹慎態度,向多方查證當中資訊的真偽;
  • 加謹留意影像和聲音,以分辨是否經由 Deepfake 技術製造。與真實的影像和聲音相比,大多數 Deepfake 影像和聲音會有聲畫不一致的細微缺陷;
  • 應對可疑視像會議時,可要求對方在鏡頭前做出點頭、揮手、掩面或移動鏡頭等動作;
  • 切勿在陌生對話中透露個人敏感訊息,如密碼、銀行賬戶號碼等;
  • 避免接聽來自不明來電的視像通話,騙徒可能會藉此收集你的樣貌影像用以製作Deepfake影片;
  • 避免在社交平台上分享過多個人資訊,尤其是臉部和語音等生物辨識資訊
  • 收到帶有緊急語調或有好處的資訊時要更加謹慎和警惕,網上騙徒通常會以這些伎倆來吸引更多的受害者跌入其陷阱;
  • 進行視像會議時,應檢查並核實與會者的身份,例如透過詢問只有你和該與會者知道的訊息來進行核實;及
  • 提防釣魚攻擊,切勿點擊或打開任何可疑連結或附件。

Phishing Alert - Public should be vigilant against fraudulent video conference scam using AI Deepfake technology

Release Date: 7 Feb 2024

Type: Phishing

Phishing Alert

Current Status and Related Trends

Recently, the media reported that for the first time, fraudsters have been discovered utilising deepfake technology to create counterfeit video conference footage, impersonating senior executives of a multinational corporation for fraudulent purposes. This case involved an employee of a multinational corporation who was ultimately deceived into transferring HK$200 million to five local accounts. 

 

Police believed that the attackers obtained publicly available footage and voice recordings of the company's senior executives through YouTube. Subsequently, they utilised deepfake technology to fabricate counterfeit video conference segments, engaging in identity deception by impersonating the company's senior executives. They then issued instructions to the victims, directing them to transfer large sums of money to designated accounts, and swiftly terminated the meetings under various pretexts, preventing the victims from raising questions, thereby leading them to mistakenly believe that these deepfake videos were authentic live video conferences. 

 

Deepfake is an amalgamated word of "deep learning" and "fake," referring to the use of artificial intelligence (AI) to fabricate content such as images and voices. It is commonly seen in videos where faces are replaced with those of other individuals. This technology can also be used to fabricate voices, requiring only input sentences to mimic the voice of the victim, eliminating the need for voice actors. However, in this case, the attackers utilised facial appearances and voices found on online platforms to create deepfake video conference footage. 

mickmick.net urges the public to be vigilant against scams that utilise AI Deepfake technology and recommends that users should:

 

  • Verify the source of conference invitations and links before joining video conferences.
  • Be cautious regarding any images and voices, verifying the authenticity of the information from multiple sources; 
  • Be attentive to discrepancies between images and voices to discern whether they have been produced using deepfake technology. Most deepfake images and voices will exhibit subtle defects in audio-visual consistency compared to genuine ones; 
  • Request the other party to perform actions such as nodding, waving, covering their face, or moving the camera when responding to a suspicious video conference; 
  • Refrain from disclosing personal sensitive information such as passwords and bank account numbers during unfamiliar conversations; 
  • Avoid answering video calls from unknown sources as scammers may use this to collect your facial images for deepfake videos; 
  • Limit the sharing of personal information on social media platforms, especially facial and voice recognition data; 
  • Be cautious when receiving messages with an urgent tone or offers of benefits, as online scammers often employ these tactics to lure more victims into their traps; 
  • Verify the identity of participants in video conferences, for example, by confirming information known only to you and the participant; 
  • Beware of phishing attacks and refrain from clicking on or opening any suspicious links or attachments. 

SUSE Linux 內核多個漏洞

發佈日期: 2024年02月07日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及遠端執行任意程式碼。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 權限提升

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise High Performance Computing 15 SP4
  • SUSE Linux Enterprise High Performance Computing 15 SP5
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Live Patching 15-SP1
  • SUSE Linux Enterprise Live Patching 15-SP2
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Live Patching 15-SP4
  • SUSE Linux Enterprise Live Patching 15-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Micro 5.4
  • SUSE Linux Enterprise Micro 5.5
  • SUSE Linux Enterprise Real Time 15 SP4
  • SUSE Linux Enterprise Real Time 15 SP5
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server 15 SP4
  • SUSE Linux Enterprise Server 15 SP5
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • SUSE Linux Enterprise Server for SAP Applications 15 SP5
  • openSUSE Leap 15.3
  • openSUSE Leap 15.5

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 7 Feb 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and remote code execution on the targeted system.

 


Impact

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise High Performance Computing 15 SP4
  • SUSE Linux Enterprise High Performance Computing 15 SP5
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Live Patching 15-SP1
  • SUSE Linux Enterprise Live Patching 15-SP2
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Live Patching 15-SP4
  • SUSE Linux Enterprise Live Patching 15-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Micro 5.4
  • SUSE Linux Enterprise Micro 5.5
  • SUSE Linux Enterprise Real Time 15 SP4
  • SUSE Linux Enterprise Real Time 15 SP5
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server 15 SP4
  • SUSE Linux Enterprise Server 15 SP5
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • SUSE Linux Enterprise Server for SAP Applications 15 SP5
  • openSUSE Leap 15.3
  • openSUSE Leap 15.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年2月6日星期二

QNAP NAS 多個漏洞

發佈日期: 2024年02月05日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 QNAP NAS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • QTS 4.5.4.2627 build 20231225 之前版本
  • QTS 5.1.2.2533 build 20230926 之前版本
  • QTS 5.1.3.2578 build 20231110 之前版本
  • QTS 5.1.4.2596 build 20231128 之前版本
  • QTS 5.1.5.2645 build 20240116 之前版本
  • QuTS hero h4.5.4.2626 build 20231225 之前版本
  • QuTS hero h5.1.2.2534 build 20230927 之前版本
  • QuTS hero h5.1.3.2578 build 20231110 之前版本
  • QuTS hero h5.1.4.2596 build 20231128 之前版本
  • QuTS hero h5.1.5.2647 build 20240118 之前版本
  • QuTScloud c5.1.5.2651 之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

QNAP NAS Multiple Vulnerabilities

Release Date: 5 Feb 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in QNAP NAS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • QTS version prior 4.5.4.2627 build 20231225 and later
  • QTS version prior 5.1.2.2533 build 20230926 and later
  • QTS version prior 5.1.3.2578 build 20231110 and later
  • QTS version prior 5.1.4.2596 build 20231128 and later
  • QTS version prior 5.1.5.2645 build 20240116 and later
  • QuTS hero version prior h4.5.4.2626 build 20231225 and later
  • QuTS hero version prior h5.1.2.2534 build 20230927 and later
  • QuTS hero version prior h5.1.3.2578 build 20231110 and later
  • QuTS hero version prior h5.1.4.2596 build 20231128 and later
  • QuTS hero version prior h5.1.5.2647 build 20240118 and later
  • QuTScloud version prior c5.1.5.2651 and later

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

ChromeOS 多個漏洞

發佈日期: 2024年02月05日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • 114.0.5735.350 (平台版本: 15437.90.0) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式,詳情請參閱以下連結:


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 5 Feb 2024

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • Version prior to 114.0.5735.350 (Platform Version: 15437.90.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor. For detail, please refer to the link below:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 遠端執行程式碼漏洞

發佈日期: 2024年02月05日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Microsoft Edge (Stable) 121.0.2277.98 之前的版本
  • Microsoft Edge (Extended Stable) 120.0.2210.167 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 Microsoft Edge (Stable) 121.0.2277.98 或之後版本
  • 更新至 Microsoft Edge (Extended Stable) 120.0.2210.167 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Remote Code Execution Vulnerabilities

Release Date: 5 Feb 2024

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Edge (Stable) prior to 121.0.2277.98
  • Microsoft Edge (Extended Stable) prior to 120.0.2210.167

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 121.0.2277.98 or later
  • Update to Microsoft Edge (Extended Stable) version 120.0.2210.167 or later

Vulnerability Identifier


Source


Related Link

2024年1月31日星期三

GitLab 多個漏洞

發佈日期: 2024年01月31日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、權限提升、遠端執行任意程式碼、敏感資料洩露及資料篡改。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 篡改

受影響之系統或技術

  • GitLab Community Edition (CE) 16.8.1, 16.7.4, 16.6.6 及 16.5.8 以前的版本
  • GitLab Enterprise Edition (EE) 16.8.1, 16.7.4, 16.6.6 及 16.5.8 以前的版本
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...