TomirisÉý¼¶¶àÓïÑÔÎäÆ÷¿â£¬¾«×¼¹¥»÷¶íÍâ½»»ú¹¹
Ðû²¼Ê±¼ä 2025-12-021. TomirisÉý¼¶¶àÓïÑÔÎäÆ÷¿â£¬¾«×¼¹¥»÷¶íÍâ½»»ú¹¹
12ÔÂ1ÈÕ£¬¿¨°Í˹»ù×îб¨¸æÕ¹ÏÖ£¬ÃûΪTomirisµÄÍþвÐÐΪÕßÕý¶Ô¶íÂÞ˹Íâ½»²¿¡¢Õþ¸®¼ä×éÖ¯¼°ÖÐÑǹú¼Ò»ú¹¹ÌᳫսÂÔÐÔÍøÂç¹¥»÷£¬Æä½¹µãÄ¿µÄÊÇͨ¹ýÓã²æÊ½´¹ÂÚÓʼþ°²ÅŶàÓïÑÔ±àдµÄ¶ñÒâÈí¼þÄ£¿é£¬»ñȡԶ³Ì»á¼ûȨÏÞ²¢½¨É賤ÆÚ»¯¿ØÖÆ¡£¸Ã×éÖ¯2025Äê¹¥»÷Á´ÏÔʾ£¬³¬50%µÄÓÕ¶üÎļþ½ÓÄɶíÓï¼°ÖÐÑǹú¼Ò¹Ù·½ÓïÑÔ¶¨ÖÆ£¬¹¥»÷Õßͨ¹ý¼ÓÃÜRARÎļþ£¨½âѹÃÜÂëÖ±½ÓǶÈëÓʼþÕýÎÄ£©·Ö·¢Î±×°³ÉWordÎĵµµÄ¿ÉÖ´ÐÐÎļþ£¬ÔËÐкóÊÍ·ÅC/C++·´ÏòShell£¬ÅþÁ¬C2·þÎñÆ÷ÏÂÔØAdaptixC2¿ò¼Ü£¬²¢Í¨¹ýÐÞ¸ÄWindows×¢²á±íʵÏÖ¶ñÒâÔØºÉ³¤ÆÚ»¯¡£TomirisµÄÕ½ÊõÑݱäÓÈΪÏÔÖø£¬ÆäÈÕ񾮵ÈÔµØÊ¹ÓÃTelegram¡¢DiscordµÈ¹«¹²·þÎñ×÷ΪC2·þÎñÆ÷£¬½«¶ñÒâÁ÷Á¿ÓëÕýµ±·þÎñÁ÷Á¿»ìÏýÒÔ¹æ±Ü¼ì²â¡£Æä¶ñÒâÈí¼þÎäÆ÷¿âº¸ÇC#¡¢Rust¡¢Go¡¢PythonµÈ¶àÓïÑÔ±àдµÄ·´ÏòShell¡¢SOCKSÊðÀí¼°ºóÃųÌÐò¡£¶àÓïÑÔÄ£¿éµÄÎÞаÐÔ¡¢µÍ¿ÉÒÉÐÔÌØÕ÷¼°¶Ô¿ªÔ´¿ò¼ÜµÄʹÓã¬Ê¹TomirisÄܹ»ÊµÏÖÒþ²ØµÄºã¾Ã³¤ÆÚ»¯¹¥»÷¡£
https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html
2. ÈÕÀú¶©ÔÄÇ徲äµã£ºBitSightÆØ347¸ö¶ñÒâÓòÃûΣº¦
11ÔÂ28ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾BitSight×îÐÂÑо¿Õ¹ÏÖ£¬ÍþвÐÐΪÕßÕýͨ¹ýʹÓÃÊý×ÖÈÕÀú¶©ÔÄ»ù´¡ÉèʩʵÑé´ó¹æÄ£Éç»á¹¤³Ì¹¥»÷¡£ÈÕÀú¶©ÔĹ¦Ð§±¾ÓÃÓÚºÏÐ̳¡¾°£¬ÈçÁãÊÛÉÌÍÆËÍ´ÙÏúÈÕÆÚ¡¢ÌåÓýлá¸üÐÂÈüÊÂÈճ̣¬ÆäÔÊÐíµÚÈý·½·þÎñÆ÷Ö±½ÓÏòÓû§×°±¸Ìí¼ÓÊÂÎñ²¢·¢ËÍ֪ͨµÄÌØÕ÷£¬È´±»¶ñÒâʹÓ㬹¥»÷ÕߴÍйÜÓÚÓâÆÚ»ò±»Ð®ÖÆÓòÃûµÄÐéãåÈÕÀú¶©ÔÄ·þÎñ£¬ÓÕÆÓû§¶©ÔĺóÍÆËͺ¬¶ñÒâÁ´½Ó¡¢¸½¼þµÄÈÕÀúÎļþ£¬´¥·¢´¹ÂÚ¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢JavaScript´úÂëÖ´ÐÐÉõÖÁAIÖúÊÖÀÄÓõÈΣº¦¡£Ñо¿Ê¼ÓÚÒ»¸ö±» ¡°Sinkhole¡± ÊÖÒÕ½ÓÊܵÄÓòÃû£¬¸ÃÓòÃûÔÓÃÓÚ·Ö·¢µÂ¹ú¹«¹²¼ÙÆÚICSÎļþ£¬È´ÖðÈÕÎüÊÕ1.1Íò¸ö×ÔÁ¦IP»á¼û£¬Òý·¢Ñо¿ÍŶӹØ×¢¡£½øÒ»³ÌÐò²é·¢Ã÷347¸ö¿ÉÒÉÈÕÀúÓòÃû£¬Éæ¼°2018Ììϱ¡¢ÒÁ˹À¼HijriÈÕÀúµÈÖ÷Ì⣬ÖðÈÕÀÛ¼ÆÎüÊÕÔ¼400Íò´ÎÃÀ¹úΪÖ÷µÄÈ«ÃÀ»á¼ûÇëÇó¡£³Á¶´Êý¾ÝÏÔʾ£¬ÕâЩ»á¼û¶àΪÒѶ©ÔÄÓû§µÄºǫ́ͬ²½ÇëÇó£¬Òâζ׎ÓÊÜÓâÆÚÓòÃûµÄ¹¥»÷Õß¿ÉÖ±½ÓÏòÓû§×°±¸ÍÆËͶ¨ÖÆ»¯¶ñÒâÈÕÀúÊÂÎñ¡£
https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/
3. PlayÀÕË÷Èí¼þ¹¥»÷ADC Aerospace
11ÔÂ29ÈÕ£¬ÃÀ¹úº½¿Õº½ÌìÓë¹ú·ÀÁìÓò¹¤³Ì²¿¼þÖÆÔìÉÌADC AerospaceÒò·þÎñŵ˹ÂÞÆÕ¡¤¸ñ³Âü¡¢¿ÂÁÖ˹º½¿Õº½Ìì¡¢»ôÄáΤ¶ûµÈ×ÅÃûÆóÒµ£¬³ÉΪÀÕË÷Èí¼þ¹¥»÷ÖØµãÄ¿µÄ¡£´Ë´Î¹¥»÷ÓÉÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þ¼¯ÍÅÖ®Ò»PlayʵÑ飬¸Ã×éÖ¯ÒÔй¶¿Í»§Êý¾ÝΪҪЮÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð£¬Èô¾Ü¾øÔòÐû²¼²¿·ÖÊý¾ÝƬ¶Ï¡£ºÚ¿ÍÉù³ÆÒÑ»ñÈ¡¿Í»§Îļþ¡¢Ô¤Ëã²ÆÎñÐÅÏ¢¡¢Ð½×ʼͼ¡¢Éí·Ý֤ʵµÈ˽ÃÜÊý¾Ý£¬µ«Î´ÌṩÑù±¾£¬ÕæÊµÐÔ´ýºË²é¡£ÈôÊý¾Ýй¶Êôʵ£¬ADC½«ÃæÁÙ¶àÖØÎ£º¦£º°µÍø¶Ô¹ú·À³Ð°üÉÌÊý¾ÝµÄ¸ßÐèÇó¿ÉÄÜÍÆ¶¯±»µÁÐÅÏ¢ÉúÒ⣻н×ʼͼÖеÄСÎÒ˽¼ÒÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£»ÆäËû˽ÃÜÊý¾ÝÔò¿ÉÄܳÉΪÉç»á¹¤³Ì¹¥»÷¹¤¾ß£¬¹¥»÷Õßð³äÐÐÒµÏà¹Ø·½ÊµÑé¸ü¾ßÆÆËðÐÔµÄÕ©Æ¡£Play¼¯ÍÅÈ¥ÄêõÒÉíÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þǰÈý£¬½ñÄê8Ô³õ¸ÕÈëÇÖΪÃÀ¹úˮʦ¡¢²¨Òô¹©»õµÄJamco Aerospace¡£
https://cybernews.com/security/adc-aerospace-breach-claims/
4. CoupangÔâÓöº«¹úÊ·ÉÏ×î´ó¹æÄ£¿Í»§Êý¾Ýй¶ÊÂÎñ
11ÔÂ30ÈÕ£¬±»ÓþΪ¡°º«¹úÑÇÂíÑ·¡±µÄº«¹úµçÉ̾ÞÍ·CoupangÓÚ11ÔÂ18ÈÕÅû¶һÆð´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬Ó°Ïì½ü3400Íò¸ö¿Í»§ÕË»§£¬´´º«¹úµ¥´ÎÊý¾Ýй¶ӰÏì¹æÄ£Ö®×î¡£¾ÊӲ죬¹¥»÷Õß×Ô6ÔÂ24ÈÕÆðͨ¹ýÍâÑó·þÎñÆ÷Ìᳫδ¾ÊÚȨ»á¼û£¬Öð²½À©´ó¹¥»÷¹æÄ££¬×îÖÕµ¼Ö³¬3300Íòº«¹úÓû§Êý¾ÝÍâй¡£Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç×ÓÓÊÏä¡¢µç»°ºÅÂë¡¢ÊÕ»õµØµã¼°²¿·Ö¶©µ¥¼Í¼£¬µ«Ö§¸¶ÐÅÏ¢ÓëµÇ¼ƾ֤δ±»»ñÈ¡¡£CoupangÔÚ·¢Ã÷Òì³£ºóÁ¬Ã¦Ïòº«¹úСÎÒ˽¼ÒÐÅÏ¢±£»¤Î¯Ô±»á¡¢¾¯·½¼°»¥ÁªÍøÇå¾²¾Ö±¨¸æ£¬²¢Æô¶¯Ó¦¼±ÏìÓ¦¡£¹«Ë¾×î³õÎóÅнöÔ¼4500ÈËÊÜÓ°Ï죬ºóÐÞÕýΪ³¬3300ÍòÈË£¬Í¹ÏÔ³õÆÚ¼ì²â»úÖÆµÄȱ·¦¡£º«¹úÕþ¸®¶Ô´Ë¸ß¶ÈÖØÊÓ£¬¿ÆÑ§ÊÖÒÕÐÅϢͨѶ²¿²¿³¤ÅᾩѫÖÜÈÕÖ÷³Ö½ôÆÈ¾Û»á£¬ºË²éCoupangÊÇ·ñÎ¥·´¡¶Ð¡ÎÒ˽¼ÒÐÅÏ¢±£»¤·¨¡·Çå¾²¹æ·¶¡£º«¹ú»¥ÁªÍøÇå¾²ÕñÐËÔº£¨KISA£©ÒÑÏòÊÜÓ°ÏìÓû§Ðû²¼·À´¹ÂÚÕ©ÆÖ¸ÄÏ£¬½¨Òé°´ÆÚÐÞ¸ÄÃÜÂë¡¢ÆôÓÃË«ÒòËØÈÏÖ¤¡£´Ë´ÎÊÂÎñÒÑÒý·¢Óû§ÕûÌåËßËÏΣº¦£¬CoupangÕýÃæÁÙÖ´·¨×·ÔðÓëÐÅÓþÖØ´´µÄË«ÖØÑ¹Á¦¡£
https://cybernews.com/news/coupang-confirms-massive-data-breach-exposing-33-7-million-accounts/
5. ¾¯·½²é·âÁËCryptomixer¼ÓÃÜÇ®±Ò»ìÏý·þÎñ
12ÔÂ1ÈÕ£¬ÈðÊ¿ÓëµÂ¹úÖ´·¨²¿·Ö¿ËÈÕÍŽῪչ¡°°ÂÁÖÆ¥ÑÇÐж¯¡±£¬ÓÚ11ÔÂ24ÈÕÖÁ28ÈÕÔÚËÕÀèÊÀ²é·â¼ÓÃÜÇ®±Ò»ìÏý·þÎñCryptomixer¡£¸Ãƽ̨×Ô2016ÄêÔËÓªÒÔÀ´£¬±»Ö¸ÐÖúÍøÂç·¸·¨·Ö×ÓÏ´Ç®³¬13ÒÚÅ·Ôª±ÈÌØ±Ò£¬³ÉΪÀÕË÷Èí¼þÍŻ°µÍøÊг¡¼°µØÏ¾¼ÃÂÛ̳»ìÏý·¸·¨×ʽðµÄ½¹µãÇþµÀ¡£Ðж¯ÖУ¬Ö´·¨»ú¹¹ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖÏ£¬²é»ñÈý̨·þÎñÆ÷¡¢12TBÊý¾Ý¡¢Ã÷Íø¼°Tor°µÍøÓòÃû£¬²¢¿ÛѺ¼ÛÖµ2400ÍòÅ·Ôª±ÈÌØ±Ò¡£Cryptomixerͨ¹ý»ìÊÊÓû§¼ÓÃÜÇ®±ÒÖÁ×Ê½ð³Ø²¢·Ö·¢ÖÁÐÂÇ®°üµØµã£¬ÓÐÓÃ×è¶ÏÇø¿éÁ´×ʽð×·×Ù£¬³ÉΪ··¶¾¡¢ÎäÆ÷×ß˽¡¢ÀÕË÷¹¥»÷¼°Ö§¸¶¿¨Ú²ÆµÈ·¸·¨Ô˶¯µÄÏ´Ç®Ê×Ñ¡¹¤¾ß¡£ÆäÔËӪģʽ»¹°üÀ¨¶ÔÏ´Ç®×ʽðÊÕȡӶ½ð£¬ÔÙ×ªÒÆÖÁ¿Í»§Ö¸¶¨Ç®°ü£¬×îÖÕͨ¹ýÒøÐлòATM½«²»·¨×ʲúת»»Îª·¨±Ò»òÆäËû¼ÓÃÜÇ®±Ò¡£´ËÀà·þÎñËä±£´æÕýµ±ÓÃ;£¬µ«Ö÷Òª±»·¸·¨ÍÅ»ïÓÃÓÚÌÓ±Ü×·²é¡£
https://www.bleepingcomputer.com/news/security/police-takes-down-cryptomixer-cryptocurrency-mixing-service/
6. CISA½«OpenPLC ScadaBRÎó²îÌí¼Óµ½KEVĿ¼ÖÐ
12ÔÂ1ÈÕ£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕ½«±àºÅΪCVE-2021-26829µÄOpenPLC ScadaBRÎó²îÄÉÈëÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼¡£¸ÃÎó²îΪ¿çÕ¾¾ç±¾£¨XSS£©Îó²î£¬Í¨¹ýsystem_settings.shtmÎļþÓ°ÏìWindowsºÍLinux°æ±¾£¬ÏêÏ¸Éæ¼°Windows¶Ë1.12.4¼°¸üÔç°æ±¾¡¢Linux¶Ë0.9.1¼°¸üÔç°æ±¾£¬CVSSÆÀ·ÖΪ5.4¡£2025Äê9Ô£¬Ç×¶íºÚ¿Í×éÖ¯TwoNetÕë¶ÔÍøÂçÇå¾²¹«Ë¾ForescoutÔËÓªµÄICS/OTÃÛ¹ÞϵͳÌᳫ¹¥»÷£¬ÎóÅÐÆäΪˮ´¦Öóͷ£³§¡£¹¥»÷ÕßʹÓÃĬÈÏÆ¾Ö¤»ñȡϵͳ»á¼ûȨÏ޺󣬽¨ÉèÃûΪ¡°BARLATI¡±µÄÕË»§£¬²¢Í¨¹ýCVE-2021-26829Îó²î¸Ä¶¯ÈË»ú½çÃæ£¨HMI£©µÇÂ¼Ò³Ãæ£¬Ã¿´Î»á¼û¸ÃÒ³ÃæÊ±£¬»á´¥·¢°üÀ¨Ôà»°µÄµ¯´°ÖÒÑÔ£¬Í¬Ê±½ûÓÃÈÕÖ¾ºÍ¾¯±¨¹¦Ð§¡£Æ¾Ö¤¾ßÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01£¬Áª°îÃñÓûú¹¹£¨FCEB£©ÐëÔÚ2025Äê12ÔÂ19ÈÕǰÐÞ¸´¸ÃÎó²î£¬ÒÔ½µµÍÖØ´óΣº¦¡£CISAͬʱ½¨Òé˽Ӫ»ú¹¹Éó²éKEVĿ¼£¬ÊµÊ±ÐÞ²¹×ÔÉí»ù´¡ÉèÊ©ÖеÄͬÀàÎó²î£¬±ÜÃⱻʹÓá£
https://securityaffairs.com/185185/security/u-s-cisa-adds-an-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html


¾©¹«Íø°²±¸11010802024551ºÅ