ÐÂÉ繤¹¥»÷½èÓû§Ï°¹ßÈö²¥DarkGate¶ñÒâÈí¼þ

Ðû²¼Ê±¼ä 2025-12-19

1. ÐÂÉ繤¹¥»÷½èÓû§Ï°¹ßÈö²¥DarkGate¶ñÒâÈí¼þ


12ÔÂ17ÈÕ£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕÅû¶һÖÖÃûΪClickFixµÄÐÂÐÍÉç»á¹¤³Ì¹¥»÷ÊÖ·¨£¬£¬£¬¸Ã¹¥»÷ʹÓÃÓû§¶Ô³£¼ûÊÖÒÕÌáÐѵÄÐÅÈÎÐÄÀí£¬£¬£¬ÓÕÆ­ÆäÊÖ¶¯Ö´ÐжñÒâÏÂÁîÒÔÈö²¥DarkGateÔ¶³Ì»á¼û¶ñÒâÈí¼þ¡£¡£¡£¹¥»÷ʼÓÚÐéαÌáÐÑ£¬£¬£¬Óû§±»Îóµ¼ÒÔΪȱÉÙ"Word Online"ä¯ÀÀÆ÷À©Õ¹£¬£¬£¬µ±µã»÷"ÔõÑùÐÞ¸´"°´Å¥Ê±£¬£¬£¬ÍøÕ¾»áͨ¹ýJavaScript½«¶ñÒâPowerShellÏÂÁîÉñÃØ¸´ÖƵ½Óû§¼ôÌù°å¡£¡£¡£Ëæºó¹¥»÷ÕßÖ¸µ¼Óû§°´ÏÂWindows+R·­¿ªÔËÐжԻ°¿ò£¬£¬£¬²¢Í¨¹ýCtrl+VÕ³Ìù¸´ÖƵÄÎı¾Ö´ÐÐÏÂÁî¡£¡£¡£ÓÉÓڸòÙ×÷ÓÉÓû§×Ô¶¯´¥·¢£¬£¬£¬Çå¾²»úÖÆ¿ÉÄܲ»»á½«Æäʶ±ðΪÍþв¡£¡£¡£¹¥»÷Á´½øÒ»²½Õö¿ª£ºÖ´ÐкóµÄPowerShell¾ç±¾»áÅþÁ¬linktoxic34.comЧÀÍÆ÷ÏÂÔØnC.htaÎļþ£¬£¬£¬¸ÃÎļþÉúÑÄÔÚCÅ̹«¹²Ä¿Â¼¡£¡£¡£Í¨¹ý¶à²ãbase64±àÂëºÍ·´Ïòº¯Êý»ìÏý£¬£¬£¬ºÚ¿ÍÀÖªϰ±Ü¼ì²â¡£¡£¡£¾ç±¾ÔËÐкó»á×Ô¶¯½¨ÉèCÅÌĿ¼£¬£¬£¬°²ÅÅAutoIt¿ÉÖ´ÐÐÎļþºÍscript.a3x¾ç±¾£¬£¬£¬ÔÚÎÞÐèÓû§½»»¥µÄÇéÐÎϼÌÐø¹¥»÷Á÷³Ì¡£¡£¡£DarkGate¶ñÒâÈí¼þÒ»µ©ÔËÐУ¬£¬£¬½«½¨É賤ÆÚÐÔ»úÖÆÈ·ÕäÖØÆôºóÈÔ±£´æ£¬£¬£¬Í¬Ê±ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢²¢Íâй£¬£¬£¬Ê¹ÓÃDES¼ÓÃÜÒþ²Ø¶ñÒâÎļþ£¬£¬£¬µ¼ÖÂϵͳ·ºÆð¿¨¶Ù¡¢Í߽⡢δ¾­ÊÚȨ¹¤¾ßÀ¸¼°´ó×Úµ¯³ö¹ã¸æµÈÖ¢×´¡£¡£¡£


http://hackread.com/clickfix-attack-fake-browser-install-darkgate-malware/


2. ÍòÍò¼¶ChromeÀ©Õ¹±»ÆØÇÔÈ¡AI¶Ô»°Êý¾Ý


12ÔÂ17ÈÕ£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾KoiÑо¿·¢Ã÷£¬£¬£¬Ò»¿îÃûΪUrban VPN ProxyµÄChromeÀ©Õ¹³ÌÐòÕýÉñÃØÇÔÈ¡Óû§ÓëAI̸Ìì»úеÈ˵ĶԻ°¼Í¼£¬£¬£¬Éæ¼°ChatGPT¡¢Claude¡¢GeminiµÈÖÁÉÙÊ®¸öÖ÷Á÷ƽ̨¡£¡£¡£¸ÃÀ©Õ¹ÓµÓг¬600ÍòÓû§£¬£¬£¬ÆÀ·ÖΪ4.7ÐÇ£¬£¬£¬²¢»ñµÃGoogle"¾«Ñ¡"»ÕÕÂÈÏÖ¤£¬£¬£¬×Ô³ÆÌṩÃâ·ÑVPNЧÀÍÒÔÔöÇ¿Òþ˽Çå¾²£¬£¬£¬ÊµÔòDZÔÚÊý¾ÝÍøÂçÄ£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬À©Õ¹³ÌÐòͨ¹ýÓ²±àÂëÉèÖñê¼ÇĬÈÏÆôÓÃÊý¾ÝÍøÂ繦Ч£¬£¬£¬Óû§ÎÞ·¨Í¨¹ýÉèÖýûÓ㬣¬£¬Ö»ÄÜͨ¹ýÐ¶ÔØÍ˳ö¡£¡£¡£¸Ã¹¦Ð§ÓÚ2025Äê7ÔÂ9ÈÕÐû²¼µÄ5.5.0°æ±¾ÖÐÒýÈ룬£¬£¬´Ëǰ°æ±¾ÎÞ´ËÐÐΪ¡£¡£¡£ÓÉÓÚChromeÀ©Õ¹×Ô¶¯¸üлúÖÆ£¬£¬£¬ÒÑ×°ÖÃÓû§»áÔÚÎÞÃ÷ȷ֪ͨµÄÇéÐÎÏ»ñµÃй¦Ð§¡£¡£¡£¸üÁîÈËÕ𾪵ÄÊÇ£¬£¬£¬Í³Ò»¿¯ÐÐÉÌÍÆ³öµÄÆäËûÆß¿îÀ©Õ¹³ÌÐò¾ù°üÀ¨ÏàͬµÄAIÊý¾ÝÊÕÂÞ¹¦Ð§£¬£¬£¬×ÜÓû§Êý´ï800Íò¡£¡£¡£ÕâЩÀ©Õ¹º­¸ÇVPN¡¢¹ã¸æ×èµ²Æ÷¡¢Çå¾²¹¤¾ßµÈ¶à¸öÖֱ𣬣¬£¬ÇÒ´ó¶¼´øÓÐGoogle»òMicrosoftµÄ"¾«Ñ¡"»ÕÕ£¬£¬£¬Åúעƽ̨ÉóºË»úÖÆ±£´æÑÏÖØÎó²î¡£¡£¡£


https://cybernews.com/security/ai-chat-vpn-extension-spying/


3. ϤÄá´óѧÔâºÚ¿ÍÈëÇÖÖ³¬2.7ÍòÈËÊý¾Ýй¶


12ÔÂ18ÈÕ£¬£¬£¬¿ËÈÕ£¬£¬£¬°Ä´óÀûÑÇϤÄá´óѧÔâÓöÑÏÖØÍøÂçÇå¾²ÊÂÎñ£¬£¬£¬ºÚ¿ÍÈëÇÖÆäÔÚÏß´úÂë¿â²¢ÇÔÈ¡°üÀ¨½ÌÖ°Ô±¹¤¡¢Ñ§Éú¼°Ð£ÓÑСÎÒ˽¼ÒÐÅÏ¢µÄÎļþ¡£¡£¡£¸ÃÊÂÎñÓÚÉÏÖܱ»¼ì²âµ½£¬£¬£¬´óѧÁ¬Ã¦¹Ø±Õδ¾­ÊÚȨµÄ»á¼ûͨµÀ£¬£¬£¬²¢Í¬²½×ª´ïÐÂÄÏÍþ¶ûÊ¿ÖÝÒþ˽רԱ¡¢°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐļ°½ÌÓýî¿Ïµ»ú¹¹¡£¡£¡£¾­ºË²é£¬£¬£¬´Ë´ÎÐ¹Â¶Éæ¼°Áè¼Ý27,000ÃûÖ°Ô±£¬£¬£¬Ïêϸ°üÀ¨£º×èÖ¹2018Äê9ÔÂ4ÈÕµÄ10,000ÃûÏÖÔ±¹¤¼°Á¥Êô»ú¹¹Ö°Ô±¡¢12,500ÃûǰԱ¹¤¼°Á¥ÊôÖ°Ô±¡¢Ô¼2010ÄêÖÁ2019Äê¼äµÄ5,000ÃûѧÉúºÍУÓÑ£¬£¬£¬ÒÔ¼°6ÃûÖ§³ÖÕß¡£¡£¡£Ð¹Â¶Êý¾Ýº­¸ÇÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢¼Òͥסַ¡¢ÊÂÇéÏêÇéµÈÃô¸ÐÐÅÏ¢¡£¡£¡£´óѧǿµ÷£¬£¬£¬ËäÈ·ÈÏÊý¾ÝÒѱ»»á¼ûÏÂÔØ£¬£¬£¬µ«Î´·¢Ã÷¹ûÕæÈö²¥»òÀÄÓÃÖ¤¾Ý¡£¡£¡£×÷Ϊ°Ä´óÀûÑǹæÄ£×î´óµÄ¹«Á¢´óѧ֮һ£¬£¬£¬Ï¤Äá´óѧӵÓÐ7ÍòÃûѧÉúºÍ1ÍòÃû½ÌÖ°Ô±¹¤¡£¡£¡£ÏÖÔÚ£¬£¬£¬¸ÃУÒÑÆô¶¯¸öÐÔ»¯Í¨Öª³ÌÐò£¬£¬£¬Ô¤¼ÆÏÂÔÂÍê³É¶ÔÊÜÓ°ÏìÖ°Ô±µÄ¼û¸æÊÂÇ飬£¬£¬²¢ÉèÁ¢×¨ÃÅÖ§³ÖЧÀÍÌṩ×ÉѯԮÖú£¬£¬£¬Í¬Ê±Ðû²¼¶¯Ì¬¸üеij£¼ûÎÊÌâ½â´ðÒ³Ãæ¡£¡£¡£¹Ù·½½¨ÒéÊÜÓ°ÏìÕßСÐÄδÊÚȨͨѶ¡¢ÊµÊ±ÐÞ¸ÄÕ˺ÅÃÜÂë²¢ÆôÓöàÒòËØÈÏÖ¤¡£¡£¡£


https://www.bleepingcomputer.com/news/security/university-of-sydney-suffers-data-breach-exposing-student-and-staff-info/


4. ClopÍÅ»ïÃé×¼Gladinet CentreStackЧÀÍÆ÷ʵÑéÊý¾ÝÇÔÈ¡


12ÔÂ18ÈÕ£¬£¬£¬½üÆÚ£¬£¬£¬ClopÀÕË÷Èí¼þÍÅ»ïÕýÕë¶Ô̻¶ÓÚ»¥ÁªÍøµÄGladinet CentreStackÎļþЧÀÍÆ÷ÌᳫÐÂÒ»ÂÖÊý¾ÝÇÔÈ¡¹¥»÷¡£¡£¡£¸ÃЧÀÍÆ÷ÔÊÐíÆóҵͨ¹ýWebä¯ÀÀÆ÷¡¢Òƶ¯Ó¦ÓûòÓ³ÉäÇý¶¯Æ÷Çå¾²¹²ÏíÍâµØÎļþ£¬£¬£¬ÎÞÐèVPN£¬£¬£¬Òѱ»49¹úÊýǧ¼ÒÆóÒµ½ÓÄÉ¡£¡£¡£×Ô4ÔÂÆð£¬£¬£¬GladinetËäÒÑÐû²¼Çå¾²¸üÐÂÐÞ¸´¶à¸ö±»Ê¹ÓÃÎó²î£¬£¬£¬µ«ClopÈÔͨ¹ýɨÃè²¢ÈëÇÖδÊܱ£»£» £»£»£»£»¤µÄCentreStackЧÀÍÆ÷ʵÑé¹¥»÷£¬£¬£¬ÔÚÊÜѬȾЧÀÍÆ÷ÉÏÁôÏÂÀÕË÷ÐÅ¡£¡£¡£ÏÖÔÚ£¬£¬£¬¹¥»÷ÕßʹÓõÄÏêϸÎó²îÉÐδÃ÷È·£¬£¬£¬¿ÉÄÜÊÇÁãÈÕÎó²î»òδʵʱÐÞ¸´µÄÒÑÖªÎó²î¡£¡£¡£ÍþвÇ鱨»ú¹¹Curated IntelÅû¶£¬£¬£¬ÖÁÉÙ200¸öÔËÐС°CentreStack-Login¡±HTTPÇëÇóµÄIPµØµãÒѳÉΪDZÔÚÄ¿µÄ¡£¡£¡£ClopµÄ¹¥»÷ģʽÑÓÐøÆäÀúÊ·Õ½ÂÔ£¬£¬£¬ÏÈÇÔÈ¡Ãô¸ÐÊý¾Ý£¬£¬£¬ÔÙͨ¹ý°µÍøÐ¹Â¶ÍøÕ¾¼°TorrentÐû²¼£¬£¬£¬ÒÔ´ËÀÕË÷Êܺ¦Õß¡£¡£¡£


https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-gladinet-centrestack-servers-for-extortion/


5. GlobalProtectÓëCisco SSL VPNÔâ´ó¹æÄ£Æ¾Ö¤Ì½²â


12ÔÂ18ÈÕ£¬£¬£¬½üÆÚ£¬£¬£¬Ò»³¡Õë¶Ô¶à¸öVPNƽ̨µÄ×Ô¶¯»¯Æ¾Ö¤¹¥»÷»î¶¯Òý·¢¹Ø×¢¡£¡£¡£Íþв¼à¿ØÆ½Ì¨GreyNoiseÓÚ12ÔÂ11ÈÕÊӲ쵽£¬£¬£¬Õë¶ÔPalo Alto Networks GlobalProtectÃÅ»§µÄµÇ¼ʵÑéÔÚ16СʱÄÚ¼¤ÔöÖÁ170Íò´Î£¬£¬£¬Éæ¼°³¬10,000¸ö²î±ðIPµØµã£¬£¬£¬Ö÷Òª¹¥»÷Ä¿µÄλÓÚÃÀ¹ú¡¢Ä«Î÷¸çºÍ°Í»ù˹̹µÄ»ù´¡ÉèÊ©¡£¡£¡£¶ñÒâÁ÷Á¿ÏÕЩËùÓÐÔ´×Ե¹ú3xK GmbHµÄIPµØµã¿Õ¼ä£¬£¬£¬ÌåÏÖ±£´æ¼¯ÖÐÊ½ÔÆ»ù´¡Éèʩ֧³Ö¡£¡£¡£¹¥»÷ÌØÕ÷ÏÔʾ£¬£¬£¬ÍþвÐÐΪÕßÖØ¸´Ê¹Óó£¼ûÓû§ÃûºÍÃÜÂë×éºÏ£¬£¬£¬ÇÒ´ó¶¼ÇëÇóαװ³ÉFirefoxÓû§ÊðÀí¡£¡£¡£Óû§ÊðÀí¡¢ÇëÇó½á¹¹ÊµÊ±¼äµÄÒ»ÖÂÐÔÅú×¢£¬£¬£¬ÕâÊÇÖ¼ÔÚʶ±ð̻¶»ò±£»£» £»£»£»£»¤±¡ÈõµÄGlobalProtectÃÅ»§µÄ¾ç±¾»¯Æ¾Ö¤Ì½²â£¬£¬£¬¶ø·Ç½»»¥Ê½»á¼û»òÎó²îʹÓᣡ£¡£12ÔÂ12ÈÕ£¬£¬£¬Í³Ò»ÍйÜÌṩÉ̵Ĺ¥»÷תÏòCisco SSL VPN¶Ëµã£¬£¬£¬Î¨Ò»¹¥»÷IPµØµãÊýÄ¿´Óȱ·¦200¸öÔ¾ÉýÖÁ1,273¸ö£¬£¬£¬ÕâÊÇÒÑÍù12ÖÜÄÚÊ״δó¹æÄ£Ê¹ÓÃ3xKÍйÜIPÕë¶ÔCisco SSL VPNµÄ¹¥»÷¡£¡£¡£µÇ¼ÓÐÓÃÔØºÉ×ñÕÕÕý³£SSL VPNÉí·ÝÑéÖ¤Á÷³Ì£¬£¬£¬½øÒ»²½Ö¤ÊµÕâÊÇ×Ô¶¯»¯Æ¾Ö¤¹¥»÷¶ø·ÇÎó²îʹÓᣡ£¡£


https://www.bleepingcomputer.com/news/security/new-password-spraying-attacks-target-cisco-pan-vpn-gateways/


6. ¸¥¼ªÄáÑÇÖÝRBHAÔâÀÕË÷¹¥»÷Ö³¬11ÍòÈËÊý¾Ýй¶


12ÔÂ18ÈÕ£¬£¬£¬¸¥¼ªÄáÑÇÖÝÀïÊ¿ÂúÐÐΪ¿µ½¡ÖÎÀí¾Ö£¨RBHA£©¿ËÈÕÅû¶£¬£¬£¬ÆäÓÚ9ÔÂ29ÈÕÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬µ¼Ö²¿·ÖÍøÂç±»¼ÓÃÜ£¬£¬£¬³¬11.3ÍòÈËСÎÒ˽¼ÒÐÅÏ¢ÃæÁÙй¶Σº¦¡£¡£¡£×÷ΪÀïÊ¿ÂúÊй«¹²»ú¹¹£¬£¬£¬RBHAÌṩÐÄÀí¿µ½¡Ö§³Ö¡¢Î£»£» £»£»£»£»úÕչ˻¤Ê¿¡¢Ò©ÎïÀÄÓÃÔ¤·ÀµÈÒªº¦Ð§ÀÍ¡£¡£¡£¹¥»÷Ô½ÈÕ£¬£¬£¬¸Ã»ú¹¹¼´·¢Ã÷ÊÂÎñ²¢Ñ¸ËÙÇýÖð¹¥»÷Õߣ¬£¬£¬µ«ÍþвÐÐΪÕß¿ÉÄÜÒÑ»ñÈ¡°üÀ¨ÐÕÃû¡¢Éç»á°ü¹ÜºÅÂë¡¢»¤ÕÕºÅÂë¡¢½ðÈÚÕË»§¼°¿µ½¡ÐÅÏ¢ÔÚÄÚµÄÃô¸ÐÊý¾Ý¡£¡£¡£¾ÝÃÀ¹úÎÀÉúÓ빫ÖÚЧÀͲ¿±¨¸æ£¬£¬£¬´Ë´ÎÊÂÎñÓ°Ïì113,232Ãû¸öÌå¡£¡£¡£RBHAÔÚ¹ÙÍøÐû²¼µÄÊÂÎñ֪ͨÖÐÇ¿µ÷£¬£¬£¬ËäÎÞÈ·ÔäÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»»á¼û£¬£¬£¬µ«³öÓÚÉóÉ÷ÈÔÌáÐÑÊÜÓ°ÏìÕßÔöǿСÐÄ£¬£¬£¬½¨Òé°´ÆÚºË²éÕË»§¶ÔÕ˵¥¡¢¼à¿ØÐÅÓñ¨¸æÒÔÌá·ÀÉí·Ý͵ÇÔ¼°Ú²Æ­ÐÐΪ¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬ÀÕË÷Èí¼þ×éÖ¯¡°÷è÷롱ÒÑÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬²¢½«RBHAÁÐÈëÆä»ùÓÚTorµÄй¶վµã¡£¡£¡£¸Ã×éÖ¯ËæºóÐû²¼Á˾ݳÆÇÔÈ¡µÄ192GBÊý¾Ý£¬£¬£¬º¬³¬39.3Íò·ÝÎļþ£¬£¬£¬½øÒ»²½¼Ó¾çÁËÊý¾ÝÀÄÓÃΣº¦¡£¡£¡£


https://www.securityweek.com/113000-impacted-by-data-breach-at-virginia-mental-health-authority/