PulseAugur
实时 14:32:27
English(EN) "The "LLMShare" campaign, discovered by Push Security, uses Google ads to direct users searching for ChatGPT to a malicious shared ChatGPT page hosted on chatgp

恶意软件活动利用 ChatGPT 共享功能进行网络钓鱼

一项名为 LLMShare 的新恶意软件活动正在利用 ChatGPT 的内容共享功能分发恶意软件。攻击者在合法的 `chatgpt.com` 链接上创建虚假的宕机页面,然后提示用户下载有害的“桌面应用程序”。此策略通过使用受信任的 OpenAI 域名绕过安全过滤器,使其成为一种危险的网络钓鱼技术。 AI

影响 攻击者正在利用受信任的 AI 平台进行网络钓鱼,这凸显了加强围绕 AI 生成内容和共享功能的安全性措施的必要性。

排序理由 这是一个利用现有产品进行攻击的安全漏洞,而不是新产品发布或核心研究。

在 Mastodon — fosstodon.org 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

恶意软件活动利用 ChatGPT 共享功能进行网络钓鱼

报道来源 [2]

  1. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Push Security 发现的“LLMShare”活动利用谷歌广告将搜索 ChatGPT 的用户引导至托管在 chatgp 上的恶意共享 ChatGPT 页面

    "The "LLMShare" campaign, discovered by Push Security, uses Google ads to direct users searching for ChatGPT to a malicious shared ChatGPT page hosted on chatgpt.com, allowing the attack to be delivered through a legitimate OpenAI domain." https://www. bleepingcomputer.com/news/s…

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    一个名为LLMShare的复杂新活动正在利用ChatGPT的合法内容共享功能来传播恶意软件。攻击者正在托管虚假的OpenAI

    A sophisticated new campaign, dubbed LLMShare, is exploiting ChatGPT's legitimate content-sharing feature to deliver malware. Attackers are hosting fake OpenAI outage pages directly on `chatgpt.com/s/` links, then prompting users to download malicious "desktop apps." This bypasse…