返回 7*24 快讯
重要来源MarsBit

More than 70 Microsoft open-source libraries were infected by the Miasma worm, and the worm was part of the same group that emptied GitHub in May.

According to Beating's monitoring, over 70 open-source code repositories hosted by Microsoft on GitHub were urgently shut down due to a Miasma worm attack. The infected repositories primarily included Azure Functions host processes and open-source versions of the Durable Task orchestration framework in multiple languages, including .NET, Java, Go, and JavaScript. This attack on Microsoft is linked to the internal GitHub code theft in mid-May. At that time, the hacker group TeamPCP released an infected VS Code extension on the Microsoft Store. A GitHub employee downloaded and became infected during the brief 11-minute upload window, resulting in the theft of all credentials and keys from their computer. The hackers used these credentials to bypass the security network and steal approximately 3,800 internal GitHub repositories. After the success, TeamPCP publicly released and open-sourced the self-replicating worm framework Mini Shai-Hulud on their forums. The Miasma worm that infiltrated Microsoft is a variant and upgraded version of Mini Shai-Hulud. The Miasma worm's operating mechanism is specifically designed for AI programming scenarios. Hackers use previously stolen Microsoft contributor tokens to inject malicious code into trusted official repositories. Developers only need to open or analyze these infected projects in AI assistants such as Claude Code, Cursor, or Gemini CLI, and the programming assistant will automatically trigger the malicious payload when parsing the configuration file. Once activated, the worm scans disks in the background, stealing AWS, GCP, and Azure cloud credentials, as well as SSH keys, npm/PyPI tokens, and Kubernetes keys from the developer's computer. It then uses the newly acquired credentials to find the next GitHub repository to infect, achieving automated self-replication. This is the second time in a few weeks that the Microsoft Durable Task open-source project has been compromised (it was previously injected with a malicious Python dependency package at the end of May). In response to the malicious commit in early June, GitHub's automated defense system reacted extremely quickly, automatically shutting down 73 infected repositories within 105 seconds of the code submission, successfully stopping the worm's spread. Microsoft has notified a small number of developers who pulled the compromised code to begin emergency credential rotation and to gradually restore the affected repositories following a security audit. Security agencies warn that as supply chain attacks evolve into automated worms targeting AI agent workflows, developers must carefully assess the risks of running unknown repositories directly within AI assistants.
免责声明:以上内容仅为作者观点,不代表 711BTC 的任何立场,不构成与 711BTC 相关的任何投资建议。

相关推荐

12undefined前重要

高盛预计核心PCE为0.23%,略高于核心CPI和市场共识

BlockBeats 消息,8 月 13 日,CPI 数据之后,市场焦点转向 8 月 26 日日公布的 7 月核心 PCE 数据。高盛预计 7 月核心 PCE 环比上涨 0.23%,略高于核心 CPI 和市场共识。其中,投资组合管理费预计将增加 8 个基点,反映第二季度股市收益。 高盛表示,即将到来的方法论变动可能导致 PCE 读数波动,并降低年度核心通胀率。该行预计 8 月核心通胀率接近 0.2%,并认为美联储将维持利率稳定至年底。

22undefined前

三菱日联金融集团拟利用区块链推出日本国债即时结算服务

Odaily星球日报讯 日本最大银行集团三菱日联金融集团(MUFG)计划利用区块链技术,为部分日本国债(JGB)交易提供即时结算服务。 报道称,MUFG 计划利用代币化货币市场基金及稳定币开展基于区块链的日本国债回购交易,以缩短传统证券交易的结算流程。(日本经济新闻)

25undefined前重要

数据:目前约 34.4% 的 ETH 处于质押状态,创历史新高

ChainCatcher 消息,Token Terminal 数据显示,目前约 34.4% 的 ETH 处于质押状态,创历史新高。今年年初以太坊质押比例约为 30%,此后持续上升至 34.4%。业内观点认为,大规模质押在限制 ETH 流通供给的同时,使更多 ETH 长期锁定于链上赚取收益。

27undefined前重要

Figure加密货币抵押贷款最高按抵押物价值75%放款

Odaily星球日报讯 加密借贷机构 Figure Lending LLC 提供加密货币抵押贷款,借款人可使用比特币、Ethereum 或 Solana 作为抵押物,最高可按抵押物价值的 75%获得现金,同时保留代币所有权。借款通常不构成出售,一般不会触发资本利得事件。 Figure Lending LLC 表示,借款人应比较最高贷款价值比、固定或浮动利率、监管许可及清算条款。该机构提供固定利率,贷款期限为 12 个月,最高年化利率为 12.62%,并支持当天放款且不要求信用评分,审批依据为抵押物。 Figure 提供可选的清算保护功能,适用于部分州,可因价格下跌推迟贷款期限内的清算;若贷款逾期,清算仍可能发生。该功能不适用于未付款、违约或违反贷款条款情形,加密资产价格下跌仍可能触发追加保证金要求。(Decrypt)

27undefined前

美国银行宣布 2500 亿美元基础设施投资计划,涵盖数据中心与算力、可再生能源发电等领域

火星财经消息,据 Fortune 报道,美国银行(Bank of America)于周三宣布一项 2500 亿美元的基础设施投资计划,承诺在未来一年内投入美国关键基础设施领域,投资范围涵盖数据中心与算力、可再生能源发电、储能、天然气、输电网络及关键矿产与采矿等多个领域,目标是支持能源安全、就业增长和经济竞争力。

30undefined前

数据:USDC Treasury 在 Solana 新增铸造 2.5 亿枚 USDC

火星财经消息,据 Whale Alert 监测,USDC Treasury 在 Solana 新增铸造 2.5 亿枚 USDC。