Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬Zscaler¿Í»§ÐÅÏ¢Íâй

Ðû²¼Ê±¼ä 2025-09-03

1. Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬Zscaler¿Í»§ÐÅÏ¢Íâй


9ÔÂ1ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾Zscaler¿ËÈÕÅû¶£¬ÆäSalesforceʵÀýÒòµÚÈý·½¼¯³É¹¤¾ßÔâÈëÇÖÒý·¢Êý¾Ýй¶£¬¿Í»§Ãô¸ÐÐÅÏ¢¼°²¿·ÖÖ§³Ö°¸ÀýÄÚÈݱ»ÇÔÈ¡¡£ÊÂÎñÔ´ÓÚSalesloft Drift±»¹¥»÷ÕßʹÓã¬ÆäOAuthÁîÅÆºÍË¢ÐÂÁîÅÆÔâÇÔ£¬µ¼ÖÂδ¾­ÊÚȨµÄÐÐΪÕß»á¼ûZscalerµÄSalesforceÇéÐΡ£Ð¹Â¶Êý¾Ý°üÀ¨¿Í»§ÐÕÃû¡¢ÉÌÒµÓÊÏ䡢ְλ¡¢µç»°ºÅÂë¡¢ÇøÓòÐÅÏ¢¡¢²úÆ·ÔÊÐíÏêÇé¼°Ö§³Ö°¸ÀýÄÚÈÝ£¬µ«ZscalerÇ¿µ÷´Ë´ÎÊÂÎñ䲨¼°¹«Ë¾×ÔÉí²úÆ·¡¢·þÎñ»ò»ù´¡ÉèÊ©¡£¹È¸èÍþвÇ鱨С×飨GTIG£©½«´Ë´Î¹¥»÷¹éÒòÓÚ×·×ÙΪUNC6395µÄÍþв×éÖ¯£¬²¢Ö¸³öÆäÄ¿µÄΪ»ñÈ¡¿Í»§ÔÚÖ§³Ö°¸ÀýÖзÖÏíµÄÃô¸Ðƾ֤£¬ÈçAWS»á¼ûÃÜÔ¿¡¢ÃÜÂë¼°SnowflakeÏà¹ØÁîÅÆ¡£¹¥»÷Õßͨ¹ýɾ³ýÅÌÎÊ×÷ÒµÑÚÊκۼ££¬µ«ÈÕ־δÊÜÓ°Ï죬¹È¸è½¨ÒéÊÜÓ°Ïì×éÖ¯Éó²éÈÕÖ¾ÒÔÈ·ÈÏÊý¾Ý̻¶ÇéÐΡ£½øÒ»³ÌÐò²éÏÔʾ£¬Salesloft¹©Ó¦Á´¹¥»÷²»µ«Ó°ÏìDriftÓëSalesforceµÄ¼¯³É£¬»¹²¨¼°ÆäÓÃÓÚÖÎÀíÓʼþ»Ø¸´ºÍCRMÊý¾Ý¿âµÄDrift Email¹¦Ð§¡£¹¥»÷ÕßÉõÖÁʹÓÃÇÔÈ¡µÄOAuthÁîÅÆ»á¼ûGoogle WorkspaceÓÊÏä²¢¶ÁÈ¡Óʼþ£¬´Ùʹ¹È¸èÓëSalesforceÔÝʱ½ûÓÃDrift¼¯³É¡£


https://www.bleepingcomputer.com/news/security/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise/


2. ¶ñÒânpm°üαװ³ÉÓʼþ¿âʵÑé¼ÓÃÜÇ®±ÒÇ®°üÇÔÈ¡¹¥»÷


9ÔÂ2ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕÅû¶һÆðÕë¶Ô¼ÓÃÜÇ®±ÒÓû§µÄ¹©Ó¦Á´¹¥»÷ÊÂÎñ£º¶ñÒânpm°ü"nodejs-smtp"ͨ¹ýð³ä×ÅÃûÓʼþ¿âNodemailer£¬Àֳɽ«¶ñÒâ´úÂë×¢ÈëAtomic¡¢ExodusµÈÖ÷Á÷¼ÓÃÜÇ®±ÒÇ®°üµÄWindows×ÀÃæÓ¦Óã¬ÇÔÈ¡Óû§ÉúÒâ×ʽ𡣸ÃÈí¼þ°üÓÉÓû§"nikotimon"ÓÚ2025Äê4ÔÂÉÏ´«ÖÁnpm×¢²á±í£¬ÀÛ¼ÆÏÂÔØ347´Îºó±»Ï¼Ü£¬ÏÖÔÚÈÔ¿Éͨ¹ýÀúÊ·°æ±¾»ñÈ¡¡£SocketÑо¿Ô±Kirill BoychenkoÕ¹ÏÖ£¬¸Ã¶ñÒâ°ü½ÓÄÉË«ÖØÎ±×°Õ½ÂÔ£ºÍâòÌṩÓëNodemailerÍêÈ«¼æÈݵÄSMTPÓʼþ¹¦Ð§£¬ÏÖ×Åʵµ¼ÈëʱʹÓÃElectron¹¤¾ß½âѹǮ°üÓ¦ÓõÄapp.asarÎļþ£¬ÓÃÍþвÐÐΪÕß¿ØÖƵÄÓ²±àÂëÇ®°üµØµãÌæ»»Óû§ÊÕ¼þµØµã£¬ÊµÏÖ±ÈÌØ±Ò¡¢ÒÔÌ«·»¡¢USDT¡¢XRP¼°SolanaµÈÖ÷Á÷¼ÓÃÜÇ®±ÒµÄÉúÒâÐ®ÖÆ¡£Æä¹¥»÷Á÷³ÌÉè¼Æ¾«Ãͨ¹ýÐÞ¸Ä×ÀÃæÓ¦Óý¹µãÎļþʵÏÖ³¤ÆÚ»¯¸Ä¶¯£¬ÖØÆôºóÈÔ¿ÉÉúЧ£¬Í¬Ê±×Ô¶¯É¾³ýÊÂÇéĿ¼ºÛ¼££¬´ó·ù½µµÍ̻¶Σº¦¡£ÊÖÒÕÆÊÎöÏÔʾ£¬nodejs-smtpµÄ¹¥»÷´úÂëǶÈëÔÚÓʼþ¹¦Ð§ÊµÏÖÖУ¬Í¨¹ýNodemailer¼æÈݽӿڽµµÍ¿ª·¢ÕßСÐÄÐÔ¡£µ±Óû§ÔÚ¿ª·¢ÇéÐÎÖе¼Èë¸Ã°üʱ£¬Æä¶ñÒâÄ£¿é»á×Ô¶¯¼ì²âϵͳÖÐÊÇ·ñ×°ÖÃAtomic»òExodusÇ®°ü£¬Ò»µ©·¢Ã÷¼´Ö´Ðнâѹ-Ìæ»»-´ò°ü²Ù×÷£¬½«Õýµ±Ç®°üÓ¦ÓÃת»¯ÎªÇÔÈ¡¹¤¾ß¡£


https://thehackernews.com/2025/09/malicious-npm-package-nodejs-smtp.html


3. CloudflareÔÚSalesforce¹©Ó¦Á´¹¥»÷ÖÐÔâÓöÊý¾Ýй¶


9ÔÂ2ÈÕ£¬½üÆÚ£¬Ò»³¡ÒÔSalesforceƽ̨ΪĿµÄµÄ¹©Ó¦Á´¹¥»÷Òý·¢¶àÆðÊý¾Ýй¶ÊÂÎñ£¬Cloudflare³ÉΪ×îÐÂÊÜÓ°ÏìÆóÒµ¡£´Ë´Î¹¥»÷Á´Ô´ÓÚÍþвÐÐΪÕßͨ¹ýÓïÒô´¹ÂÚ£¨vishing£©Éç»á¹¤³ÌÊֶΣ¬ÓÕÆ­ÆóÒµÔ±¹¤½«¶ñÒâOAuthÓ¦ÓùØÁªÖÁ¹«Ë¾SalesforceʵÀý£¬½ø¶øÇÔÈ¡Êý¾Ý¿â¡£8ÔÂ9ÈÕÖÁ17ÈÕʱ´ú£¬¹¥»÷ÕßÊ×ÏȶÔCloudflareµÄSalesforceʵÀýÕö¿ªÕì̽£¬ËæºóÇÔÈ¡ÁËÆäÄÚ²¿¿Í»§°¸ÀýÖÎÀí¼°Ö§³ÖϵͳÖеÄÎı¾Êý¾Ý£¬Éæ¼°104¸öCloudflare APIÁîÅÆ¼°´ó×Ú¿Í»§Ö§³Ö¹¤µ¥ÄÚÈÝ¡£Ö»¹ÜÏÖÔÚδ·¢Ã÷ÁîÅÆ±»ÀÄÓ㬵«Ð¹Â¶ÐÅÏ¢°üÀ¨¿Í»§ÁªÏµ×ÊÁÏ¡¢ÉèÖÃÏêÇé¼°¿ÉÄܱ£´æµÄ»á¼ûƾ֤µÈÃô¸ÐÊý¾Ý£¬CloudflareÒѽôÆÈÂÖ»»ËùÓÐÊÜÓ°ÏìÁîÅÆ²¢Í¨Öª¿Í»§£¬½¨ÒéÂÖ»»Í¨¹ýÖ§³ÖÇþµÀ¹²ÏíµÄƾ֤¡£´Ë´Î¹©Ó¦Á´¹¥»÷̻¶³öÆóÒµÒÀÀµµÚÈý·½SaaSƽ̨µÄÇ徲Σº¦¡£¹¥»÷Õßͨ¹ý¼òµ¥Æ½Ì¨Îó²î¼´¿ÉºáÏò²¨¼°Êý°Ù¼Ò¿Í»§£¬ÇÔÈ¡µÄ¿Í»§Ö§³Ö¹¤µ¥Êý¾Ý£¨ÈçÈÕÖ¾¡¢ÁîÅÆ¡¢ÃÜÂ룩¿ÉÄܳÉΪºóÐøÕë¶ÔÐÔ¹¥»÷µÄÌø°å¡£Ö»¹ÜÊÜÓ°ÏìÆóÒµ¾ùÇ¿µ÷䲨¼°½¹µãϵͳ£¬µ«Ãô¸ÐÐÅϢй¶ÈÔ¿ÉÄÜÒý·¢¿Í»§ÐÅÍÐÎ £»ú¼°ºÏ¹æÎ£º¦¡£


https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/


4. ºÚ¿Í¹¥»÷Evertec°ÍÎ÷×Ó¹«Ë¾Sinqia£¬ÊÔͼÇÔÈ¡1.3ÒÚÃÀÔª


9ÔÂ2ÈÕ£¬À­¶¡ÃÀÖÞ½ðÈڿƼ¼¾ÞÍ·EvertecµÄ°ÍÎ÷×Ó¹«Ë¾Sinqia S.A.¿ËÈÕÔâÓöÖØ´óÍøÂç¹¥»÷ÊÂÎñ£¬ºÚ¿Íͨ¹ýÇÔÈ¡µÄIT¹©Ó¦ÉÌÕË»§Æ¾Ö¤£¬ÓÚ8ÔÂ29ÈÕ²»·¨ÇÖÈëÆäÈÏÕæÔËÓªµÄ°ÍÎ÷ÑëÐÐʵʱ֧¸¶ÏµÍ³£¨Pix£©ÇéÐΣ¬ÊÔͼͨ¹ýÁ½¼Ò½ðÈÚ»ú¹¹¿Í»§Ìᳫ×ܶî´ï1.3ÒÚÃÀÔªµÄδ¾­ÊÚȨÆóÒµ¼äתÕË¡£Ö»¹Ü²¿·Ö×ʽðÒѱ»×·»Ø£¬µ«Ïêϸ½ð¶îδ¹ûÕæ£¬ÇÒÊÂÎñ¶ÔEvertec²ÆÎñ¼°ÉùÓþµÄDZÔÚÓ°ÏìÈÔ±»ÆÀ¹ÀΪ"¿ÉÄÜÖØ´ó"¡£Æ¾Ö¤EvertecÏòÃÀ¹ú֤ȯÉúÒâίԱ»á£¨SEC£©Ìá½»µÄÎļþ£¬´Ë´Î¹¥»÷̻¶Á˰ÍÎ÷¼´Ê±Ö§¸¶ÏµÍ³PixµÄÇ徲ųÈõÐÔ¡£×÷Ϊ°ÍÎ÷ÑëÐÐ2020ÄêÍÆ³öµÄÈ«Ììºò¼´Ê±×ªÕËϵͳ£¬PixÒÑÁýÕÖÌìÏÂÁè¼Ý°ëÊý³ÉÄêÉú³Ý£¬µ«ÆµÈÔ³ÉΪAndroidÒøÐжñÒâÈí¼þ¹¥»÷Ä¿µÄ¡£´Ë´ÎÊÂÎñÖУ¬ºÚ¿ÍʹÓõÚÈý·½¹©Ó¦ÉÌÕË»§È¨ÏÞ£¬Í»ÆÆÁËSinqiaΪ24¼Ò°ÍÎ÷½ðÈÚ»ú¹¹ÌṩµÄPixÖ§¸¶´¦Öóͷ£ÇéÐΣ¬Ö»¹ÜEvertecÇ¿µ÷δ·¢Ã÷СÎÒ˽¼ÒÊý¾Ýй¶£¬µ«¹¥»÷ÕßÈÔÊÔͼͨ¹ý»ã·áÒøÐеȿͻ§Ìᳫ´ó¹æÄ£×ʽð×ªÒÆ¡ £»ã·áÒøÐлØÓ¦³Æ¿Í»§×ʽðÓëÊý¾ÝδÊÜÓ°Ï죬µ«ÊÂÎñ͹ÏÔ½ðÈÚ»ú¹¹¶ÔµÚÈý·½·þÎñÉ̵ÄÇå¾²ÒÀÀµÎ£º¦¡£


https://www.bleepingcomputer.com/news/security/hackers-breach-fintech-firm-in-attempted-130m-bank-heist/


5. ½Ý±ªÂ·»¢ÔâÍøÂç¹¥»÷ÖÂϵͳ¹Ø±Õ£¬Éú²úÁãÊÛÊÜÓ°Ïì


9ÔÂ2ÈÕ£¬½Ý±ªÂ·»¢£¨JLR£©¿ËÈÕÔâÓöÍøÂç¹¥»÷£¬±»ÆÈ¹Ø±Õ²¿·ÖϵͳÒÔ»º½âÓ°Ï죬µ¼ÖÂÆäÉú²úºÍÁãÊÛÓªÒµÊܵ½ÑÏÖØ×ÌÈÅ¡£Æ¾Ö¤¹«Ë¾¹Ù·½ÉùÃ÷£¬´Ë´ÎÊÂÎñÖÐËäδ·¢Ã÷¿Í»§Êý¾Ý±»µÁ¼£Ï󣬵«ÁãÊ۶˺ÍÉú²ú»·½Ú¾ù·ºÆðÏÔÖøÖÐÖ¹¡£½Ý±ªÂ·»¢ÌåÏÖ£¬ÊÂÎñ±¬·¢ºóÁ¬Ã¦×Ô¶¯¹Ø±ÕÊÜÓ°Ïìϵͳ£¬ÏÖÔÚÕý°´ÍýÏëÖð²½ÖØÆôÈ«ÇòÓ¦ÓóÌÐò£¬µ«ÉÐδÌṩ»Ö¸´Õý³£ÔËÓªµÄÏêϸʱ¼ä±í£¬Ò²Î´Åû¶¹¥»÷ÀàÐÍ»òÊÖÒÕϸ½Ú¡£×÷ΪËþËþÆû³µÆìÏÂ×Ó¹«Ë¾£¬½Ý±ªÂ·»¢ÄêÊÕÈ볬380ÒÚÃÀÔª£¬Äê²úÁ¿³¬40ÍòÁ¾£¬ÓµÓÐ3.9ÍòÃûÔ±¹¤£¬ÆäË÷Àû¹þ¶û¹¤³§ÈÏÕæÉú²ú·»¢·¢Ã÷¡¢À¿Ê¤¼°À¿Ê¤Ô˶¯°æµÈÈÈÃųµÐÍ¡£´Ë´Î¹¥»÷µ¼ÖÂÓ¢¹ú¾­ÏúÉÌÎÞ·¨×¢²áгµ»ò¹©Ó¦Áã¼þ£¬Éú²úϵͳҲһ¶ÈÍ£°Ú£¬µ«¹«Ë¾Ç¿µ÷¿Í»§Êý¾ÝÇå¾²ÐÔδÊÜÍþв¡£´Ë´Î¹¥»÷±¬·¢ÔÚÖÜÄ©£¬Õâһʱ¶Î³£±»ÍþвÐÐΪÕßʹÓã¬ÒòÆóÒµÓ¦¼±ÏìÓ¦ÄÜÁ¦Ïà¶Ô½ÏÈõ¡£×èÖ¹ÏÖÔÚÉÐδÓÐÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´ËÈÏÕæ¡£


https://www.bleepingcomputer.com/news/security/jaguar-land-rover-says-cyberattack-severely-disrupted-production/


6. Palo Alto NetworksÔâSalesforce¹©Ó¦Á´¹¥»÷й¶¿Í»§Êý¾Ý


9ÔÂ2ÈÕ£¬Palo Alto Networks¿ËÈÕÈ·ÈÏ£¬Æä³ÉΪÉÏÖÜÅû¶µÄSalesloft Drift¹©Ó¦Á´¹¥»÷ÊÂÎñÖеÄÊÜÓ°ÏìÆóÒµÖ®Ò»£¬¹¥»÷Õßͨ¹ýÇÔÈ¡µÄOAuthÁîÅÆ²»·¨»á¼ûÆäSalesforce CRMϵͳ£¬µ¼Ö¿ͻ§ÁªÏµÐÅÏ¢¡¢ÄÚ²¿ÏúÊۼͼ¼°Ö§³Ö°¸ÀýÊý¾Ýй¶£¬µ«Î´²¨¼°¹«Ë¾½¹µã²úÆ·¡¢ÏµÍ³»ò·þÎñ¡£´Ë´ÎÊÂÎñ̻¶ÁËÍþвÐÐΪÕßÕë¶ÔSalesforceÉú̬µÄ¹æÄ £»¯Êý¾ÝÇÔȡսÂÔ£¬¹¥»÷Õßͨ¹ýÀÄÓõÚÈý·½Ó¦ÓÃÎó²î£¬´ÓÊý°Ù¼ÒÆóÒµÖÐÅúÁ¿ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬Palo Alto NetworksÒѽôÆÈ½ûÓÃÏà¹ØÓ¦Óò¢ÂÖ»»Æ¾Ö¤£¬Í¬Ê±ÖÒÑÔ¿Í»§ÐèСÐĺóÐøÕë¶ÔÐÔ¹¥»÷¡£´Ë´Î¹¥»÷Ô´ÓÚÍþвÐÐΪÕßʹÓÃSalesloft DriftÓ¦ÓóÌÐòÎó²î»ñÈ¡µÄOAuthÁîÅÆ£¬½ø¶øÉøÍ¸ÆäSalesforceÇéÐΡ£Ö»¹Üй¶Êý¾Ý½öÏÞÓÚÁªÏµÐÅÏ¢¡¢Îı¾Ì¸ÂÛ¼°»ù´¡°¸ÀýÊý¾Ý£¬Î´°üÀ¨ÊÖÒÕ¸½¼þ»òÎļþ£¬µ«¹¥»÷ÕßÈÔͨ¹ý×Ô¶¯»¯¹¤¾ß£¨Èç×Ô½ç˵Python¾ç±¾£©´ÓÕË»§¡¢ÁªÏµÈË¡¢°¸ÀýµÈSalesforce¹¤¾ßÖдó¹æÄ£ÌáÈ¡Êý¾Ý£¬²¢ÖصãɨÃèAWSÃÜÔ¿¡¢SnowflakeÁîÅÆ¡¢VPN/SSOƾ֤µÈ¸ß¼ÛÖµÐÅÏ¢£¬Òâͼͨ¹ýÇÔÈ¡µÄÔÆÆ½Ì¨»á¼ûȨÏÞʵÑéÊý¾ÝÀÕË÷»òºáÏòÉøÍ¸¡£


https://www.bleepingcomputer.com/news/security/palo-alto-networks-data-breach-exposes-customer-info-support-cases/