ÀÕË÷Èí¼þÍÅ»ïÔõÑù¼ÓÃÜÄÚ»ª´ïÖÝÕþ¸®ÏµÍ³
Ðû²¼Ê±¼ä 2025-11-101. ÀÕË÷Èí¼þÍÅ»ïÔõÑù¼ÓÃÜÄÚ»ª´ïÖÝÕþ¸®ÏµÍ³
11ÔÂ6ÈÕ£¬ÄÚ»ª´ïÖÝ8ÔÂÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬Ó°Ïì60Óà¸öÕþ¸®»ú¹¹£¬µ¼ÖÂÍøÕ¾¡¢µç»°ÏµÍ³¼°ÔÚÏ߯½Ì¨ÖÐÖ¹¡£ÖÝÕþ¸®Ðû²¼µÄÏêϸʺ󱨸æÍêÕûÅû¶Á˹¥»÷ȫò£ººÚ¿Í×Ô5ÔÂ14ÈÕÆðͨ¹ý¶ñÒâ¹ã¸æÓÕµ¼ÖÝÕþ¸®¹ÍÔ±ÏÂÔØÎ±×°³ÉϵͳÖÎÀí¹¤¾ß£¨ÈçWinSCP¡¢PuTTYµÈ£©µÄľÂí³ÌÐò£¬ÔÚ×°±¸°²ÅźóÃÅ£»8ÔÂ24ÈÕÕýʽ°²ÅÅÀÕË÷Èí¼þǰ£¬ÒÑͨ¹ýÔ¶³Ì¼à¿ØÈí¼þ¡¢¼ÓÃÜËíµÀ¹¤¾ßºáÏòÉøÍ¸£¬ÇÔÈ¡26¸öÕË»§Æ¾Ö¤²¢É¨³ýÊÂÎñÈÕÖ¾ÒÔÑÚÊÎÐÐ×Ù¡£¹¥»÷Õß×îÖÕɾ³ý±¸·Ý¾í¡¢ÐÞ¸ÄÐéÄ⻯ÖÎÀí·þÎñÆ÷Çå¾²ÉèÖã¬ÔÚÍйÜÖÝÐéÄâ»úµÄËùÓзþÎñÆ÷Éϰ²ÅÅÀÕË÷Èí¼þ£¬µ¼ÖÂÈ«ÖÝ·þÎṉ̃»¾¡£ÃæÁÙΣ»ú£¬ÄÚ»ª´ïÖݾܾøÖ§¸¶Êê½ð£¬ÒÀÀµ50ÃûITÖ°Ô±¼Ó°à4,212Сʱ£¨ÈËΪ±¾Ç®25.9ÍòÃÀÔª£©¼°Íⲿ¹©Ó¦ÉÌÖ§³Ö£¨×ÜÓöÈÔ¼130ÍòÃÀÔª£©£¬28ÌìÄÚ»Ö¸´90%ÊÜÓ°ÏìÊý¾Ý¼°·þÎñ¡£Óë±ê×¼³Ð°üÉÌ·ÑÂÊÏà±È£¬´Ë¾Ù½ÚÔ¼Ô¼47.8ÍòÃÀÔª¡£ÊÂÎñÏìӦʱ´ú£¬Î¢ÈíDART¡¢MandiantµÈ¹©Ó¦ÉÌÌṩͳһ֧³Ö¡¢·¨Ö¤ÊӲ졢¹¤³Ì»Ö¸´µÈ·þÎñ£¬±¾Ç®Ã÷ϸ͸Ã÷¹ûÕæ¡£
https://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/
2. ¶íSandwormºÚ¿Í×éÖ¯¶ÔÎÚÒªº¦ÐÐÒµ·¢¶¯Êý¾Ý²Á³ý¹¥»÷
11ÔÂ6ÈÕ£¬½üÆÚ£¬¶íÂÞ˹¹ú¼ÒÖ§³ÖµÄºÚ¿Í×éÖ¯Sandworm£¨ÓÖÃûAPT44£©¶ÔÎÚ¿ËÀ¼½ÌÓý¡¢Õþ¸®¼°Á¸Ê³²¿·ÖÌᳫ¶àÂÖÊý¾Ý²Á³ý¶ñÒâÈí¼þ¹¥»÷£¬ÑÓÐøÆä×Ô2022ÄêÒÔÀ´Õë¶Ô¸Ã¹úµÄÆÆËðÐÔÐж¯¡£ÍøÂçÇå¾²¹«Ë¾ESETÔÚ×îб¨¸æÖÐÖ¸³ö£¬ÕâЩ¹¥»÷¼¯ÖÐÔÚ6ÔºÍ9Ô£¬Ä¿µÄº¸ÇÕþ¸®¡¢ÄÜÔ´¡¢ÎïÁ÷¼°Á¸Ê³ÐÐÒµ£¬ÆäÖÐÁ¸Ê³²¿·Ö×÷ΪÎÚ¿ËÀ¼Õ½Ê±Ö÷ÒªÊÕÈëȪԴ³ÉΪн¹µã¡£Êý¾Ý²Á³ý¶ñÒâÈí¼þÈçPathWiper¡¢HermeticWiperµÈͨ¹ýÆÆËð»òɾ³ýÎļþ¡¢´ÅÅÌ·ÖÇø¼°Ö÷Ö¸µ¼¼Í¼ʵÏÖ³¹µ×Ïú»Ù£¬ÓëÀÕË÷Èí¼þ²î±ð£¬Æä´¿´âÒÔÆÆËðΪĿµÄ£¬µ¼ÖÂϵͳÄÑÒÔ»Ö¸´¡£´Ë´Î¹¥»÷ÖУ¬Sandworm°²ÅÅÁË¡°ZeroLot¡±ºÍ¡°Sting¡±µÈ±äÖÖ£¬ÆäÖС°Sting¡±Í¨¹ýÒÔÐÙÑÀÀû¹Å°å²ËëÈÃüÃûµÄWindowsʹÃüÖ´ÐУ¬Í¹ÏÔ¹¥»÷µÄÒþ²ØÐÔ¡£³õʼ»á¼ûȨÏÞ¶àÓÉUAC-0099£¨×Ô2023ÄêÆð»îÔ¾µÄÍþвÐÐΪÌ壩»ñÈ¡£¬Ëæºó×ªÒÆ¸øSandworm°²ÅŲÁ³ýÆ÷¡£Á¸Ê³ÐÐÒµÊ״γÉΪÖ÷Òª¹¥»÷Ä¿µÄ£¬·´Ó¦³ö¹¥»÷ÕßÊÔͼÏ÷ÈõÎÚ¿ËÀ¼Õ½Ê±¾¼ÃµÄÕ½ÂÔÒâͼ¡£
https://www.bleepingcomputer.com/news/security/sandworm-hackers-use-data-wipers-to-disrupt-ukraines-grain-sector/
3. Î÷°àÑÀKISS-FMÔâRhysidaÀÕË÷Èí¼þ¹¥»÷
11ÔÂ6ÈÕ£¬Î÷°àÑÀÓµÓаÙÍòÌýÖÚµÄÈÈÃŹ㲥µç̨KISS-FMÔâÓöÓë¶íÂÞ˹¹ØÁªµÄRhysidaÀÕË÷Èí¼þÍÅ»ïÏ®»÷¡£¸ÃÍÅ»ïÔÚ°µÍøÅÄÂô¾Ý³ÆÇÔÈ¡µÄÊý¾Ý£¬ÒªÇóÖ§¸¶3¸ö±ÈÌØ±Ò£¨Ô¼30ÍòÃÀÔª£©Êê½ð£¬²¢É趨7ÌìÏÞÆÚ£¬²»È»½«³öÊÛ»òй¶Êý¾Ý¡£RhysidaÒÔ¡°Ë«ÖØÀÕË÷¡±Õ½ÂÔÖøÃû£¬²»µ«ÓÃÀÕË÷Èí¼þËø¶¨Ãü¾Ý£¬»¹Íþвй¶ÒÔʩѹ¸¶¿î¡£¹¥»÷ÕßÌṩµÄ½ØÍ¼ÏÔʾ£¬±»µÁÊý¾Ý¿ÉÄܰüÀ¨¹ÛÖÚÆÀ·Ö¼Í¼¡¢ÓëÎ÷°àÑÀÊý×Ö»¯×ªÐͲ¿½»Á÷µÄÎļþ¼°·¢Æ±£¬µ«Ô±¹¤Ð¡ÎÒ˽¼ÒÊý¾Ýй¶ÇéÐÎÉÐδÃ÷È·¡£´Ë´ÎÊÂÎñÒÑÒý·¢¶Ô¹«ÖÚÐÅÍжÈϽµ¡¢GDPRºÏ¹æÎ£º¦¼°ÉÌÒµ¹ØÏµÈÅÂҵĵ£ÐÄ¡£RhysidaÍÅ»ï×Ô2023Äê5Ô½¨ÉèÒÔÀ´£¬ÒÑÉù³Æ¹¥»÷236¸öÄ¿µÄ£¬ÁýÕÖ½ÌÓý¡¢Ò½ÁÆ¡¢ÖÆÔìÒµ¡¢µØ·½Õþ¸®µÈÁìÓò¡£Æä¹¥»÷ÊֶΰüÀ¨Ê¹ÓÃMicrosoft Teams¡¢ZoomºÍPuttyƽ̨¾ÙÐжñÒâ¹ã¸æÍøÂç´¹ÂÚ£¬Ñ¬È¾×°±¸²¢ÇÔÈ¡Êý¾Ý¡£
https://cybernews.com/security/ransomware-kissfm-spain-radio/
4. GlassWorm¶ñÒâÈí¼þ¾íÍÁÖØÀ´£¬OpenVSXÔÙÔâ¹¥»÷
11ÔÂ8ÈÕ£¬ÔøÓ°ÏìOpenVSXºÍVisual Studio CodeÓ¦ÓÃÊг¡µÄGlassWorm¶ñÒâÈí¼þÔ˶¯ÔÙ¶È»îÔ¾£¬´øÀ´Èý¿îÐÂVSCodeÀ©Õ¹³ÌÐò£¬ÀÛ¼ÆÏÂÔØÁ¿Òѳ¬10,000´Î¡£¸Ã¶ñÒâÈí¼þͨ¹ýSolanaÉúÒâ»ñÈ¡ÓÐÓÃÔØºÉ£¬Ä¿µÄÖ±Ö¸GitHub¡¢NPM¼°OpenVSXÕË»§Æ¾Ö¤£¬ÒÔ¼°49¸öÀ©Õ¹³ÌÐòµÄ¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý¡£Æä½¹µã¹¥»÷ÊÖ¶ÎÊÇʹÓò»¿É¼ûµÄUnicode×Ö·ûʵÏÖ¶ñÒâ²Ù×÷£¬ÕâÖÖ»ìÏý¼¼ÇÉÈÔÄÜÈÆ¹ýOpenVSXÐÂÒýÈëµÄ·ÀÓù»úÖÆ¡£´Ë´Î¹¥»÷ÖУ¬GlassWormͨ¹ýOpenVSXƽ̨ÉÏ´«µÄÈý¿îÀ©Õ¹»®·ÖΪ£ºai-driven-dev.ai-driven-dev£¨3,400´ÎÏÂÔØ£©¡¢adhamu.history-in-sublime-merge£¨4,000´ÎÏÂÔØ£©¡¢yasuyuky.transient-emacs£¨2,400´ÎÏÂÔØ£©¡£¾ÝÇå¾²»ú¹¹Koi Security×·×Ù£¬¹¥»÷ÕßʹÓÃÏàͬµÄ»ù´¡ÉèÊ©£¬µ«¸üÐÂÁËÏÂÁîÓë¿ØÖÆ£¨C2£©¶ËµãºÍSolanaÉúÒâÕ½ÂÔ£¬²¢ÒÑתÏòGitHubºóÓֻعéOpenVSX£¬Åú×¢ÆäÓÐÒâÔÚ¶àÆ½Ì¨Ò»Á¬ÔËÓª¡£×èÖ¹·¢¸å£¬Èý¿îЯ´øGlassWormÓÐÓÃÔØºÉµÄÀ©Õ¹ÈÔ¿É´ÓOpenVSXÏÂÔØ£¬Ç徲ר¼ÒÖÒÑÔÓû§ÐèСÐÄ´ËÀàÒþ²Ø¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/
5. NuGet¶ñÒâÈí¼þ°üDZÔÚ¶àÄ꣬2027ÄêÆð¼¤»îÆÆËðÐÔ¹¥»÷
11ÔÂ7ÈÕ£¬´úÂëÇå¾²¹«Ë¾SocketÑо¿Ö°Ô±ÔÚNuGet¿ªÔ´°ü¹ÜÀíÆ½Ì¨·¢Ã÷¾Å¸öÓÉ¿ª·¢Õß"shanhai666"Ðû²¼µÄ¶ñÒâÈí¼þ°ü£¬ÕâЩÈí¼þ°üÍâò¾ß±¸Õýµ±¹¦Ð§£¬ÊµÔò°üÀ¨Òþ²ØµÄÆÆËðÐÔÓÐÓÃÔØºÉ£¬ÍýÏëÓÚ2027Äê8ÔÂÖÁ2028Äê11Ô¼伤»î¡£¸Ã¶ñÒâ´úÂë½ÓÄɸÅÂÊ´¥·¢»úÖÆ£¬ÐèÖª×ãÌØ¶¨ÈÕÆÚÌõ¼þ¼°Ëæ»úÊýãÐÖµ£¨´óÓÚ80ʱ´¥·¢£©£¬Í¨¹ýC#À©Õ¹ÒªÁ콫¶ñÒâÂ߼͸Ã÷×¢ÈëÊý¾Ý¿âºÍPLC²Ù×÷Á÷³Ì¡£´Ë´Î¹¥»÷Õë¶ÔÈý´óÖ÷Á÷Êý¾Ý¿â£¨SQL Server¡¢PostgreSQL¡¢SQLite£©¼°Î÷ÃÅ×ÓS7¹¤Òµ¿ØÖÆ×°±¸£¬ÓÈÆäÒÔαװ³ÉÕýµ±Sharp7¿âµÄ"Sharp7Extend"Èí¼þ°ü×îΪΣÏÕ¡£¸Ã°üͨ¹ý¸½¼Ó"Extend"ºó׺ÓÕµ¼¿ª·¢ÕßÎóÏÂÔØ£¬µ±´¥·¢Ìõ¼þÖª×ãʱ£¬»áÒÔ20%¸ÅÂÊÁ¬Ã¦ÖÕÖ¹Ö÷»úÀú³Ì£¬µ¼ÖÂPLC¿Í»§¶Ë²Ù×÷ÖÐÖ¹£»»òͨ¹ýÑÓ³ÙдÈë»úÖÆ£¨30-90·ÖÖÓ£©Ê¹PLCдÈë²Ù×÷ÓÐ80%¸ÅÂÊË𻵣¬Òý·¢Ö´ÐÐÆ÷ÏÂÁîɥʧ¡¢Ç徲ϵͳʧЧµÈÑÏÖØÐ§¹û¡£×èÖ¹ÆØ¹âʱ£¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØ½ü9500´Î£¬Éæ¼°SqlUnicorn.Core¡¢SQLite´æ´¢¿âµÈ¾Å¸ö¶ñÒâ°ü¡£ÏÖÔÚ£¬NuGetÒÑϼÜÏà¹ØÈí¼þ°ü£¬µ«Ç±ÔÚÓ°Ïì¹æÄ£ÆÕ±é¡£
https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-drop-disruptive-time-bombs/
6. ÈýÐÇÁãÈÕÎó²îÔâʹÓã¬LandFallÌØ¹¤Èí¼þ¶¨Ïò¹¥»÷Öж«Óû§
11ÔÂ7ÈÕ£¬ÍþвÐÐΪÕß×Ô2024Äê7ÔÂÆðʹÓÃÈýÐÇAndroidͼÏñ´¦Öóͷ£¿âÖеÄÁãÈÕÎó²îCVE-2025-21042£¬Í¨¹ýWhatsApp·¢ËͶñÒâDNGÃûÌÃͼÏñÎļþ£¬°²ÅÅÃûΪ"LandFall"µÄÌØ¹¤Èí¼þ£¬¶¨Ïò¹¥»÷Öж«µØÇøÌض¨ÈýÐÇGalaxyÓû§¡£¸ÃÎó²îΪlibimagecodec.quram.soÎļþÖеÄÔ½½çдÈëÎó²î£¬ÑÏÖØ¼¶±ð´ï"ÑÏÖØ"£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë¡£Ö»¹ÜÈýÐÇÓÚ2025Äê4ÔÂÐÞ¸´´ËÎó²î£¬µ«¹¥»÷Ô˶¯ÒÑÒ»Á¬ÊýÔ£¬Ó°ÏìGalaxy S22¡¢S23¡¢S24¡¢Z Fold 4¼°Z Flip 4µÈÆì½¢»úÐÍ¡£LandFallÌØ¹¤Èí¼þ½ÓÄÉË«ÖØÊÖÒÕ×é¼þ£º¼ÓÔØÆ÷b.soÈÏÕæ¼ìË÷ºÍ¼ÓÔØÆäËûÄ£¿é£¬SELinuxÕ½ÂÔʹÓÃÆ÷l.soÔòÐÞ¸Ä×°±¸Çå¾²ÉèÖÃÒÔÌáÉýȨÏÞ²¢½¨É賤ÆÚÐÔ¡£¸ÃÈí¼þ¿É»ùÓÚÓ²¼þºÍSIM ID£¨ÈçIMEI¡¢IMSI£©¶Ô×°±¸¾ÙÐÐÖ¸ÎÆÊ¶±ð£¬²¢¾ß±¸Âó¿Ë·ç¼Òô¡¢Í¨»°Â¼Òô¡¢Î»ÖÃ×·×Ù¡¢»á¼ûÕÕÆ¬/ÁªÏµÈË/¶ÌÐÅ/ͨ»°¼Í¼/Îļþ¼°ä¯ÀÀÀúÊ·µÈÌØ¹¤¹¦Ð§£¬Í¬Ê±Ö§³ÖÄ£¿éÖ´ÐС¢³¤ÆÚ»¯¡¢¼ì²âÌӱܺͱ£»¤Èƹý¡£¹¥»÷·¾¶ÏÔʾ£¬¶ñÒâDNGÎļþĩβ¸½¼ÓZIPѹËõ°ü£¬Í¨¹ýWhatsAppÈö²¥¡£Ñо¿Ö°Ô±ÆÊÎö·¢Ã÷£¬ÒÁÀ¿Ë¡¢ÒÁÀÊ¡¢ÍÁ¶úÆäºÍĦÂå¸çΪDZÔÚÄ¿µÄ¹ú¼Ò¡£
https://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/


¾©¹«Íø°²±¸11010802024551ºÅ