÷è÷ëÀÕË÷Èí¼þ×éÖ¯Éù³ÆÈëÇÖÎÚ¿ËÀ¼Íâ½»²¿

Ðû²¼Ê±¼ä 2025-03-07

1. ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Éù³ÆÈëÇÖÎÚ¿ËÀ¼Íâ½»²¿


3ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬ £¬÷è÷ëÀÕË÷Èí¼þ×éÖ¯Éù³ÆÒÑÀÖ³ÉÈëÇÖÎÚ¿ËÀ¼Íâ½»²¿£¬£¬£¬£¬£¬£¬ £¬ÕâÊÇÒ»´ÎÖØ´óµÄÍøÂçÇå¾²ÊÂÎñ¡£ ¡£¡£¡£¡£¸Ã×éÖ¯Ðû³ÆÇÔÈ¡Á˰üÀ¨Ë½ÈËͨѶ¡¢Ð¡ÎÒ˽¼ÒÐÅÏ¢ºÍ¹Ù·½Ö´·¨ÔÚÄÚµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬²¢Òѽ«²¿·ÖÊý¾Ý³öÊÛ¸øµÚÈý·½£¬£¬£¬£¬£¬£¬ £¬Í¬Ê±ÔÚÆäTorйÃÜÍøÕ¾ÉÏÐû²¼ÁËһϵÁб»µÁÎļþµÄͼÏñ×÷Ϊ֤¾Ý¡£ ¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ £¬ÎÚ¿ËÀ¼Íâ½»²¿ÉÐδ¶ÔÕâÒ»Êý¾Ýй¶ÊÂÎñ¾ÙÐÐ֤ʵ¡£ ¡£¡£¡£¡£´Ë´Î¹¥»÷±»ÊÓΪ¶íÂÞ˹ºÍÎÚ¿ËÀ¼Ò»Á¬³åÍ»ÖлìÏýÕ½ÕùÉý¼¶µÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬ £¬¿ÉÄÜÓë¿ËÀïÄ·ÁÖ¹¬Õ½ÂÔÒ»ÖµĺڿͻºÍÍøÂç·¸·¨¼¯ÍÅÓйء£ ¡£¡£¡£¡£÷è÷ëÀÕË÷Èí¼þ×éÖ¯×Ô2022ÄêÆð»îÔ¾£¬£¬£¬£¬£¬£¬ £¬ÔøÒò¹¥»÷Ó¢¹úÕþ¸®Ò½ÁÆÐ§ÀÍÌṩÉÌSynnovis¶øÊܵ½¹Ø×¢£¬£¬£¬£¬£¬£¬ £¬Í¨³£½ÓÄÉ¡°Ë«ÖØÀÕË÷¡±ÊֶΡ£ ¡£¡£¡£¡£×î½ü£¬£¬£¬£¬£¬£¬ £¬¸Ã×éÖ¯»¹Éù³Æ¶ÔÓ°ÏìÊýÊ®¼ÒÍâµØ±¨Ö½µÄÀîÊÏÆóÒµÍøÂç¹¥»÷ÈÏÕæ¡£ ¡£¡£¡£¡£ÀîÊÏÆóÒµÊÇÒ»¼ÒÉÏÊеÄÃÀ¹úýÌ幫˾£¬£¬£¬£¬£¬£¬ £¬ÔÚ¶à¸öÖݳöÊé´ó×Ú±¨Ö½ºÍÖÜ¿¯¡£ ¡£¡£¡£¡£´Ë´ÎÊÂÎñÔÙ´Î͹ÏÔÁËÍøÂçÇå¾²µÄÖ÷ÒªÐÔ£¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÀÕË÷Èí¼þ×éÖ¯¶ÔÈ«ÇòÆóÒµºÍÕþ¸®»ú¹¹×é³ÉµÄÍþв¡£ ¡£¡£¡£¡£


https://securityaffairs.com/175025/cyber-crime/qilin-ransomware-ministry-of-foreign-affairs-of-ukraine.html


2. ΢Èíɾ³ý¶ñÒâ¹ã¸æ»î¶¯ËùÓÃGitHub´æ´¢¿â£¬£¬£¬£¬£¬£¬ £¬½ü°ÙÍò×°±¸ÊÜÓ°Ïì


3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬ £¬Î¢ÈíÔÚ2024Äê12Ô³õ¼ì²âµ½Ò»´Î´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬£¬£¬£¬£¬£¬ £¬¸Ã»î¶¯Ó°ÏìÁËÈ«Çò½üÒ»°ÙÍǫ̀װ±¸¡£ ¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÔÚ²»·¨µÁ°æÁ÷ýÌåÍøÕ¾µÄÊÓÆµÖÐ×¢Èë¶ñÒâ¹ã¸æÖض¨ÏòÆ÷£¬£¬£¬£¬£¬£¬ £¬½«Ç±ÔÚÊܺ¦ÕßÖØ¶¨Ïòµ½ËûÃÇ¿ØÖƵĶñÒâGitHub´æ´¢¿â¡£ ¡£¡£¡£¡£ÕâЩ´æ´¢¿âÖеĶñÒâÈí¼þ»áѬȾÓû§ÏµÍ³£¬£¬£¬£¬£¬£¬ £¬Ö´ÐÐϵͳ·¢Ã÷¡¢ÍøÂçÏêϸµÄϵͳÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬²¢ÔÚ°²ÅÅÌØÁíÍâµÚ¶þ½×¶ÎÓÐÓÃÔØºÉʱÇÔÈ¡Êý¾Ý¡£ ¡£¡£¡£¡£ÔÚµÚÈý½×¶Î£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß»áÏÂÔØNetSupportÔ¶³Ì»á¼ûľÂí£¨RAT£©ºÍÆäËûÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ £¬ÈçLummaºÍDoenerium£¬£¬£¬£¬£¬£¬ £¬À´ÇÔÈ¡Óû§Êý¾ÝºÍä¯ÀÀÆ÷ƾ֤¡£ ¡£¡£¡£¡£ËäÈ»GitHubÊǴ˴λµÚÒ»½×¶Î½»¸¶ÓÐÓÃÔØºÉµÄÖ÷Ҫƽ̨£¬£¬£¬£¬£¬£¬ £¬µ«Microsoft Threat IntelligenceÒ²ÊӲ쵽ÔÚDropboxºÍDiscordÉÏÍйܵÄÓÐÓÃÔØºÉ¡£ ¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯¾ßÓÐÎÞ²î±ðÐÔ£¬£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËÆÕ±éµÄ×éÖ¯ºÍÐÐÒµ£¬£¬£¬£¬£¬£¬ £¬°üÀ¨ÏûºÄÕßºÍÆóÒµ×°±¸¡£ ¡£¡£¡£¡£Î¢ÈíÓá°Storm-0408¡±Õâ¸ö×ܳÆÀ´×·×ÙÕâÒ»»î¶¯£¬£¬£¬£¬£¬£¬ £¬²¢ÌṩÁËÓйش˴ÎÖØ´ó¶ñÒâ¹ã¸æ»î¶¯µÄ¶à½×¶Î¹¥»÷Á´Öй¥»÷µÄ¸÷¸ö½×¶ÎºÍËùʹÓõÄÓÐÓÃÔØºÉµÄÏêϸÐÅÏ¢¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-says-malvertising-campaign-impacted-1-million-pcs/


3. AkiraÀÕË÷Èí¼þÍÅ»ïʹÓÃÍøÂçÉãÏñÍ·ÈÆ¹ýEDRÌᳫ¹¥»÷


3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬ £¬AkiraÀÕË÷Èí¼þÍÅ»ï½ÓÄÉÁËÒ»ÖÖ²»Ñ°³£µÄ¹¥»÷ÒªÁ죬£¬£¬£¬£¬£¬ £¬Ê¹Óò»Çå¾²µÄÍøÂçÉãÏñÍ·¶ÔÊܺ¦ÕßÍøÂçÌᳫ¼ÓÃܹ¥»÷£¬£¬£¬£¬£¬£¬ £¬ÀÖ³ÉÈÆ¹ýÁËWindowsÖеĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©¹¤¾ß¡£ ¡£¡£¡£¡£ÍøÂçÇå¾²¹«Ë¾S-RMÔÚÒ»´ÎÊÂÎñÏìÓ¦Öз¢Ã÷ÁËÕâÒ»¹¥»÷·½·¨¡£ ¡£¡£¡£¡£AkiraÍÅ»ïÊ×ÏÈͨ¹ýÔ¶³Ì»á¿´·¨¾ö¼Æ»®½øÈë¹«Ë¾ÍøÂ磬£¬£¬£¬£¬£¬ £¬°²ÅÅÕýµ±µÄÔ¶³Ì»á¼û¹¤¾ßAnyDeskÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬ £¬²¢Ê¹ÓÃÔ¶³Ì×ÀÃæÐ­Ò飨RDP£©¾ÙÐкáÏòÒÆ¶¯¡£ ¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ £¬µ±ËûÃÇÔÚWindowsÉϰ²ÅÅÀÕË÷Èí¼þ¸ºÔØÊ±±»EDR¹¤¾ß×èÖ¹¡£ ¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬£¬ £¬AkiraɨÃèÍøÂçѰÕÒÆäËû×°±¸£¬£¬£¬£¬£¬£¬ £¬·¢Ã÷ÁËÒ×Êܹ¥»÷µÄÍøÂçÉãÏñÍ·ºÍÖ¸ÎÆÉ¨ÃèÒÇ¡£ ¡£¡£¡£¡£ÓÉÓÚÍøÂçÉãÏñÍ·ÔËÐÐLinux²Ù×÷ϵͳÇÒûÓÐEDRÊðÀí£¬£¬£¬£¬£¬£¬ £¬AkiraÑ¡ÔñʹÓÃËü¹ÒÔØ¹«Ë¾ÆäËû×°±¸µÄWindows SMBÍøÂç¹²Ïí£¬£¬£¬£¬£¬£¬ £¬²¢ÔÚÍøÂçÉãÏñÍ·ÉÏÆô¶¯Linux¼ÓÃÜÆ÷£¬£¬£¬£¬£¬£¬ £¬ÀֳɼÓÃÜÁËSMBÉϵÄÍøÂç¹²ÏíÎļþ¡£ ¡£¡£¡£¡£S-RMÖ¸³ö£¬£¬£¬£¬£¬£¬ £¬ÒÑÓÐÕë¶ÔÍøÂçÉãÏñÍ·Îó²îµÄ²¹¶¡£ ¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ £¬Åú×¢´Ë´Î¹¥»÷ÊÇ¿É×èÖ¹µÄ¡£ ¡£¡£¡£¡£´Ë°¸ÀýÇ¿µ÷ÁËEDR±£»£»£»£»£»£»£»¤²¢·ÇÖÜÈ«Çå¾²½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬ £¬ÎïÁªÍø×°±¸Ò²Ó¦ÓëÃô¸ÐÍøÂç¸ôÀë²¢°´ÆÚ¸üй̼þÒÔÐÞ²¹Îó²î¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/akira-ransomware-encrypted-network-from-a-webcam-to-bypass-edr/


4. StubHubƱÎñÔ±¹¤µÁÊÛǧÓàÕÅÒôÀÖ»áÃÅÆ±ÔâÆðËß


3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬ £¬Å¦Ô¼Éó²é¹ÙÖ¸¿ØStubHubÔÚÏ߯±ÎñÊг¡µÄÁ½ÃûµÚÈý·½³Ð°üÉÌÊÂÇéÖ°Ô±ÉæÏÓ͵ÇÔ²¢×ªÊÛ½ü1000ÕŸ߼ÛÖµÒôÀÖ»áÃÅÆ±£¬£¬£¬£¬£¬£¬ £¬×¬È¡635,000ÃÀÔª¡£ ¡£¡£¡£¡£ÕâЩÃÅÆ±´ó´ó¶¼ÊÇÌ©ÀÕ¡¤Ë¹Íþ·òÌØµÄEras TourÃÅÆ±£¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÆäËû×ÅÃû»î¶¯ÈçEd Sheeran¡¢AdeleÑݳª»á¡¢NBA½ÇÖðºÍÃÀ¹úÍøÇò¹ûÕæÈüµÄÃÅÆ±¡£ ¡£¡£¡£¡£Á½Ãû±»¸æ»®·ÖÊÇ20ËêµÄ̩¡¡¤ÂÞ˹ºÍ31ËêµÄɯÂêÀ­¡¤Î÷ÃÉ˹£¬£¬£¬£¬£¬£¬ £¬ËûÃÇÔÚÑÀÂò¼ÓÈøÉªÀ¼È«ÇòЧÀ͹«Ë¾ÊÂÇ飬£¬£¬£¬£¬£¬ £¬Ê¹ÓÃÀ밶ƱÎñ¹©Ó¦ÉÌÆ½Ì¨µÄÎó²î×èµ²ÁËÔ¼350·ÝStubHub¶©µ¥£¬£¬£¬£¬£¬£¬ £¬ÇÔÈ¡ÃÅÆ±¡£ ¡£¡£¡£¡£ËûÃǾݳÆÍ¨¹ý»á¼ûStubHubÅÌËã»úϵͳ£¬£¬£¬£¬£¬£¬ £¬ÕÒµ½ºóÃŽøÈëÍøÂçÇå¾²ÇøÓò£¬£¬£¬£¬£¬£¬ £¬½«ÒÑÊÛ³öÃÅÆ±µÄURLÖØ¶¨Ïòµ½Í¬Ä±µÄµç×ÓÓʼþÉÏ¡£ ¡£¡£¡£¡£Á½ÈËÒÑÔÚŦԼÊб»²¶£¬£¬£¬£¬£¬£¬ £¬²¢ÃæÁÙ¶àÏîÐÌÊÂÖ¸¿Ø£¬£¬£¬£¬£¬£¬ £¬Ò»µ©×ïÃû½¨É裬£¬£¬£¬£¬£¬ £¬½«ÃæÁÙ×î¸ß15ÄêµÄî¿Ïµ¡£ ¡£¡£¡£¡£´Ë´Î¹¥»÷Ðж¯Í¹ÏÔÁ˵ط½Éó²é¹Ù°ì¹«ÊÒ¶ÔÍøÂç·¸·¨µÄСÐÄÐÔ£¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÓëÐÐÒµÏàÖúͬ°é¹¥»÷ڲƭ»î¶¯ºÍÈ·±£ÏûºÄÕß±£»£»£»£»£»£»£»¤µÄÖ÷ÒªÐÔ¡£ ¡£¡£¡£¡£ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬ £¬ÒÔÈ·¶¨´Ë´ÎÐж¯µÄ¹æÄ£ºÍÆäËûDZÔÚͬı¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cybercrime-crew-stole-635-000-in-taylor-swift-concert-tickets/


5. PyPIÉϵÄÒÔÌ«·»Ë½Ô¿ÇÔÈ¡³ÌÐò±»ÏÂÔØÁè¼Ý 1,000 ´Î


3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬ £¬Ò»¸öÃûΪ¡°set-utils¡±µÄ¶ñÒâPython°üÔÚPyPIÉϱ»·¢Ã÷£¬£¬£¬£¬£¬£¬ £¬¸Ã°üαװ³ÉÊÊÓõŤ¾ß°ü£¬£¬£¬£¬£¬£¬ £¬Í¨¹ý×èµ²ÒÔÌ«·»Ç®°ü´´Á¢¹¦Ð§ÇÔȡ˽Կ£¬£¬£¬£¬£¬£¬ £¬²¢Í¨¹ýPolygonÇø¿éÁ´½«Æäй¶¡£ ¡£¡£¡£¡£×Ô2025Äê1ÔÂ29ÈÕÌá½»ÒÔÀ´£¬£¬£¬£¬£¬£¬ £¬¸Ã°üÒѱ»ÏÂÔØÒ»Ç§¶à´Î£¬£¬£¬£¬£¬£¬ £¬Ö÷ÒªÕë¶ÔÇø¿éÁ´¿ª·¢Ö°Ô±¡¢»ùÓÚPythonµÄDeFiÏîÄ¿¡¢Ö§³ÖÒÔÌ«·»µÄWeb3Ó¦ÓóÌÐòÒÔ¼°Ê¹ÓÃPython×Ô¶¯»¯µÄСÎÒ˽¼ÒÇ®°ü¡£ ¡£¡£¡£¡£¸Ã¶ñÒâ°üǶÈëÁ˹¥»÷ÕßµÄRSA¹«Ô¿£¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚ¼ÓÃܱ»µÁµÄ˽Կ£¬£¬£¬£¬£¬£¬ £¬²¢½«ÆäǶÈëµ½ÒÔÌ«·»ÉúÒâµÄÊý¾Ý×Ö¶ÎÖУ¬£¬£¬£¬£¬£¬ £¬Í¨¹ýPolygon RPC¶Ëµã·¢Ë͵½¹¥»÷ÕßµÄÕÊ»§¡£ ¡£¡£¡£¡£ÕâÖÖÒªÁìÏà¶ÔÒþ²Ø£¬£¬£¬£¬£¬£¬ £¬²»Ò×±»·À»ðǽºÍ·À²¡¶¾¹¤¾ß¼ì²âµ½¡£ ¡£¡£¡£¡£Ò»µ©Êý¾ÝÐÁæØêú³ÌÍê³É£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔËæÊ±¼ìË÷±»µÁÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬ÓÉÓÚ±»µÁÐÅÏ¢»áÓÀÊÀ´æ´¢ÔÚÇø¿éÁ´ÉÏ¡£ ¡£¡£¡£¡£Ö»¹Ü¸Ã°üÒѱ»´ÓPyPIÖÐɾ³ý£¬£¬£¬£¬£¬£¬ £¬µ«Òѽ«ÆäÄÉÈëÏîÄ¿µÄÓû§ºÍÈí¼þ¿ª·¢Ö°Ô±Ó¦Á¬Ã¦Ð¶ÔØËü£¬£¬£¬£¬£¬£¬ £¬²¢¼ÙÉ轨ÉèµÄÈκÎÒÔÌ«·»Ç®°ü¶¼ÒÑÊܵ½Íþв£¬£¬£¬£¬£¬£¬ £¬¾¡¿ì×ªÒÆ×ʽðÒÔ×èÖ¹±»µÁΣº¦¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ethereum-private-key-stealer-on-pypi-downloaded-over-1-000-times/


6. Áè¼Ý1000¸öWordPressÍøÕ¾Ôâ¶ñÒâJavaScript´úÂë¹¥»÷


3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬ £¬Áè¼Ý1000¸öÓÉWordPressÖ§³ÖµÄÍøÕ¾±»µÚÈý·½JavaScript´úÂëѬȾ£¬£¬£¬£¬£¬£¬ £¬¸Ã´úÂëÖ²ÈëÁËËĸö×ÔÁ¦ºóÃÅ£¬£¬£¬£¬£¬£¬ £¬Îª¹¥»÷ÕßÌṩ¶àÖØÈëÇÖ;¾¶¡£ ¡£¡£¡£¡£ÕâЩºóÃŰüÀ¨Ò»¸öÃûΪ¡°Ultra SEO Processor¡±µÄÐéα²å¼þ£¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚÖ´Ðй¥»÷ÕßÏÂÁ£»£»£»£»£»£»Ïòwp-config.php×¢Èë¶ñÒâJavaScript£»£»£»£»£»£»£»Ïò~/.ssh/authorized_keysÌí¼ÓSSHÃÜÔ¿ÒÔʵÏÖÔ¶³Ì»á¼û£»£»£»£»£»£»£»ÒÔ¼°´Ógsocket[.]io»ñÈ¡ÔØºÉÒÔ·­¿ª·´Ïòshell¡£ ¡£¡£¡£¡£Îª½µµÍΣº¦£¬£¬£¬£¬£¬£¬ £¬Óû§±»½¨Òéɾ³ýδÊÚȨSSHÃÜÔ¿¡¢Ìæ»»WordPressÖÎÀíÔ±ÃÜÂ룬£¬£¬£¬£¬£¬ £¬²¢¼à¿ØÈÕÖ¾¡£ ¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬£¬ £¬ÒÑÓÐÁè¼Ý35000¸öÍøÕ¾Ôâ¶ñÒâJavaScriptÈëÇÖ£¬£¬£¬£¬£¬£¬ £¬µ¼Ö»á¼ûÕß±»Öض¨ÏòÖÁÖÐÎĶIJ©Æ½Ì¨¡£ ¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬ £¬ÃûΪScreamedJungleµÄÍþвÐÐΪÕßͨ¹ý×¢ÈëBablosoft JS¾ç±¾£¬£¬£¬£¬£¬£¬ £¬Ó°ÏìÁË115¸öÒÔÉϵÄMagentoÍøÕ¾£¬£¬£¬£¬£¬£¬ £¬ÍøÂçÓû§Ö¸ÎÆÐÅÏ¢¡£ ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÒÑÖªÎó²î£¬£¬£¬£¬£¬£¬ £¬ÈçCVE-2024-34102ºÍCVE-2024-20720£¬£¬£¬£¬£¬£¬ £¬¾ÙÐÐÍøÕ¾ÈëÇÖ¡£ ¡£¡£¡£¡£Group-IBÖ¸³ö£¬£¬£¬£¬£¬£¬ £¬ä¯ÀÀÆ÷Ö¸ÎÆÊ¶±ðÊÖÒÕËä³£ÓÃÓÚÓû§¸ú×ÙºÍÓªÏúÕ½ÂÔ£¬£¬£¬£¬£¬£¬ £¬µ«Ò²±»·¸·¨·Ö×ÓÓÃÓÚÄ£ÄâÕýµ±Óû§¡¢ÌÓ±ÜÇå¾²²½·¥¼°ÊµÑéڲƭ¡£ ¡£¡£¡£¡£


https://thehackernews.com/2025/03/over-1000-wordpress-sites-infected-with.html