÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÈëÇÖÎÚ¿ËÀ¼±í½»²¿
°ä²¼¹¦·ò 2025-03-071. ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÈëÇÖÎÚ¿ËÀ¼±í½»²¿
3ÔÂ7ÈÕ£¬÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÒѳɹ¦ÈëÇÖÎÚ¿ËÀ¼±í½»²¿£¬ÕâÊÇÒ»´Î³Á´óµÄÍøÂ簲ȫÊÂÎñ¡£¸Ã×éÖ¯Ðû³ÆÇÔÈ¡ÁËÔ̺¬¸öÈËͨѶ¡¢Ó×ÎÒÐÅÏ¢ºÍ¹Ù²½ÖèÁîÔÚÄÚµÄÃô¸ÐÊý¾Ý£¬²¢Òѽ«²¿ÃÅÊý¾ÝÏúÊÛ¸øµÚÈý·½£¬Í¬Ê±ÔÚÆäTorйÃÜÍøÕ¾Éϰ䲼ÁËһϵÁб»µÁÎļþµÄͼÏñ×÷Ϊ֤¾Ý¡£È»¶ø£¬ÎÚ¿ËÀ¼±í½»²¿ÉÐδ¶ÔÕâÒ»Êý¾Ýй¶ÊÂÎñ½øÐÐ֤ʵ¡£Õâ´Î¹¥»÷±»ÊÓΪ¶íÂÞ˹ºÍÎÚ¿ËÀ¼³ÖÐøÃ¬¶ÜÖлìºÏÕ½ÕùÉý¼¶µÄÒ»²¿ÃÅ£¬¿ÉÄÜÓë¿ËÀïÄ·ÁÖ¹¬Õ½ÊõÒ»ÖµĺڿͻºÍÍøÂç·¸×OÍÅÓйء£÷è÷ëÀÕË÷Èí¼þ×éÖ¯×Ô2022ÄêÆð»îÔ¾£¬ÔøÒò¹¥»÷Ó¢¹úµ±¾ÖÒ½ÁÆ·þÎñÌṩÉÌSynnovis¶øÊܵ½¹Ø×¢£¬Í¨³£Ñ¡È¡¡°Ë«³ÁÀÕË÷¡±¼¿Á©¡£×î½ü£¬¸Ã×éÖ¯»¹Ðû³Æ¶ÔÓ°ÏìÊýÊ®¼Ò±¾µØ±¨Ö½µÄÀîÊÏÆóÒµÍøÂç¹¥»÷ÕÆ¹Ü¡£ÀîÊÏÆóÒµÊÇÒ»¼ÒÉÏÊеÄÃÀ¹úýÌ幫˾£¬ÔÚ¶à¸öÖݳö°æ´óÁ¿±¨Ö½ºÍÖÜ¿¯¡£Õâ´ÎÊÂÎñÔÙ´Î͹ÏÔÁËÍøÂ簲ȫµÄ³ÁÒªÐÔ£¬ÒÔ¼°ÀÕË÷Èí¼þ×éÖ¯¶ÔÈ«ÇòÆóÒµºÍµ±¾Ö»ú¹¹×é³ÉµÄÍþв¡£
https://securityaffairs.com/175025/cyber-crime/qilin-ransomware-ministry-of-foreign-affairs-of-ukraine.html
2. ΢Èíɾ³ý¶ñÒâ¸æ°×»î¶¯ËùÓÃGitHub´æ´¢¿â£¬½ü°ÙÍòÉ豸ÊÜÓ°Ïì
3ÔÂ6ÈÕ£¬Î¢ÈíÔÚ2024Äê12Ô³õ¼ì²âµ½Ò»´Î´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬¸Ã»î¶¯Ó°ÏìÁËÈ«Çò½üÒ»°ÙÍǫ̀É豸¡£¹¥»÷Õßͨ¹ýÔÚ·¸·¨µÁ°æÁ÷ýÌåÍøÕ¾µÄÊÓÆµÖÐ×¢Èë¶ñÒâ¸æ°×³Á¶¨ÏòÆ÷£¬½«Ç±ÔÚÊܺ¦Õß³Á¶¨Ïòµ½ËûÃǽÚÔìµÄ¶ñÒâGitHub´æ´¢¿â¡£ÕâЩ´æ´¢¿âÖеĶñÒâÈí¼þ»áϰȾÓû§ÏµÍ³£¬Ö´ÐÐϵͳ·¢ÏÖ¡¢ÍøÂç¾ßÌåµÄϵͳÐÅÏ¢£¬²¢ÔÚ²¿Êð¶î±íµÄµÚ¶þ½×¶ÎÓÐÐ§ÔØºÉʱÇÔÈ¡Êý¾Ý¡£ÔÚµÚÈý½×¶Î£¬¹¥»÷Õß»áÏÂÔØNetSupportÔ¶³Ì½Ó¼ûľÂí£¨RAT£©ºÍÆäËûÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬ÈçLummaºÍDoenerium£¬À´ÇÔÈ¡Óû§Êý¾ÝºÍä¯ÀÀÆ÷Í´´¦¡£¹ÌÈ»GitHubÊÇÕâ´Î»î¶¯µÚÒ»½×¶Î½»¸¶ÓÐÐ§ÔØºÉµÄÖØÒªÆ½Ì¨£¬µ«Microsoft Threat IntelligenceÒ²¹Û²ìµ½ÔÚDropboxºÍDiscordÉÏÍйܵÄÓÐÐ§ÔØºÉ¡£Õâ´Î¹¥»÷»î¶¯ÓµÓÐÎÞ²î¾àÐÔ£¬Ó°ÏìÁË¿í·ºµÄ×éÖ¯ºÍÐÐÒµ£¬Ô̺¬Ïû·ÑÕßºÍÆóÒµÉ豸¡£Î¢ÈíÓá°Storm-0408¡¹Øâ¸ö×ܳÆÀ´×·×ÙÕâÒ»»î¶¯£¬²¢ÌṩÁËÓйØÕâ´Î¸´ÔÓ¶ñÒâ¸æ°×»î¶¯µÄ¶à½×¶Î¹¥»÷Á´Öй¥»÷µÄ¸÷¸ö½×¶ÎºÍËùʹÓõÄÓÐÐ§ÔØºÉµÄ¾ßÌåÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/microsoft-says-malvertising-campaign-impacted-1-million-pcs/
3. AkiraÀÕË÷Èí¼þÍÅ»ïÀûÓÃÍøÂçÉãÏñÍ·ÈÆ¹ýEDRÌáÒé¹¥»÷
3ÔÂ6ÈÕ£¬AkiraÀÕË÷Èí¼þÍÅ»ïѡȡÁËÒ»ÖÖ²»Ñ°³£µÄ¹¥»÷²½Ö裬ÀûÓò»°²È«µÄÍøÂçÉãÏñÍ·¶ÔÊܺ¦ÕßÍøÂçÌáÒé¼ÓÃܹ¥»÷£¬³É¹¦ÈƹýÁËWindowsÖеĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©¹¤¾ß¡£ÍøÂ簲ȫ¹«Ë¾S-RMÔÚÒ»´ÎÊÂÎñÏìÓ¦Öз¢ÏÖÁËÕâÒ»¹¥»÷·½Ê½¡£AkiraÍÅ»ïÊ×ÏÈͨ¹ýÔ¶³Ì½Ó¼û½â¾ö¹æ»®½øÈë¹«Ë¾ÍøÂ磬²¿ÊðºÏ·¨µÄÔ¶³Ì½Ó¼û¹¤¾ßAnyDeskÇÔÈ¡Êý¾Ý£¬²¢Ê¹ÓÃÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©½øÐкáÏòÒÆ¶¯¡£È»¶ø£¬µ±ËûÃÇÔÚWindowsÉϲ¿ÊðÀÕË÷Èí¼þ¸ºÔØÊ±±»EDR¹¤¾ß×èÖ¹¡£Ëæºó£¬AkiraɨÃèÍøÂçѰÕÒÆäËûÉ豸£¬·¢ÏÖÁËÒ×Êܹ¥»÷µÄÍøÂçÉãÏñÍ·ºÍÖ¸ÎÆÉ¨ÃèÒÇ¡£ÓÉÓÚÍøÂçÉãÏñÍ·ÔËÐÐLinux²Ù×÷ϵͳÇÒûÓÐEDR´úÀí£¬AkiraÑ¡ÔñÀûÓÃËü¹ÒÔØ¹«Ë¾ÆäËûÉ豸µÄWindows SMBÍøÂç¹²Ïí£¬²¢ÔÚÍøÂçÉãÏñÍ·ÉÏÆô¶¯Linux¼ÓÃÜÆ÷£¬³É¹¦¼ÓÃÜÁËSMBÉϵÄÍøÂç¹²ÏíÎļþ¡£S-RMÖ¸³ö£¬ÒÑÓÐÕë¶ÔÍøÂçÉãÏñÍ··ì϶µÄ²¹¶¡£¬Åú×¢Õâ´Î¹¥»÷ÊÇ¿ÉÔ¤·ÀµÄ¡£´Ë°¸ÀýÇ¿µ÷ÁËEDR±£»¤²¢·ÇÈ«Ãæ°²È«½â¾ö¹æ»®£¬ÎïÁªÍøÉ豸ҲӦÓëÃô¸ÐÍøÂç¸ôÀë²¢¶¨ÆÚ¸üй̼þÒÔ½¨²¹·ì϶¡£
https://www.bleepingcomputer.com/news/security/akira-ransomware-encrypted-network-from-a-webcam-to-bypass-edr/
4. StubHubƱÎñÔ±¹¤µÁÊÛǧÓàÕÅÒôÀÖ»áÃÅÆ±Ôâ¸æ×´
3ÔÂ6ÈÕ£¬Å¦Ô¼¼ì²ì¹ÙÖ¸¿ØStubHubÔÚÏ߯±ÎñÊг¡µÄÁ½ÃûµÚÈý·½³Ð°üÉ̹¤×÷ÈËÔ±ÉæÏÓ͵ÇÔ²¢×ªÊÛ½ü1000ÕŸ߼ÛÖµÒôÀÖ»áÃÅÆ±£¬×¬È¡635,000ÃÀÔª¡£ÕâЩÃÅÆ±´óÎÞÊýÊÇÌ©ÀÕ¡¤Ë¹Íþ·òÌØµÄEras TourÃÅÆ±£¬ÒÔ¼°ÆäËû³ÛÃû»î¶¯ÈçEd Sheeran¡¢AdeleÑݳª»á¡¢NBA½ÇÖðºÍÃÀ¹úÍøÇò¹«¿ªÈüµÄÃÅÆ±¡£Á½Ãû±»ÎÕ±ðÀëÊÇ20ËêµÄ̩¡¡¤ÂÞ˹ºÍ31ËêµÄɯÂêÀ¡¤Î÷ÃÉ˹£¬ËûÃÇÔÚÑÀÂò¼ÓÈøÉªÀ¼È«Çò·þÎñ¹«Ë¾¹¤×÷£¬ÀûÓÃÀ밶ƱÎñ¹©¸øÉÌÆ½Ì¨µÄ·ì϶À¹½ØÁËÔ¼350·ÝStubHub¶©µ¥£¬ÇÔÈ¡ÃÅÆ±¡£ËûÃǾݳÆÍ¨¹ý½Ó¼ûStubHubÍÆËã»úϵͳ£¬ÕÒµ½ºóÃŽøÈëÍøÂç°²È«ÇøÓò£¬½«ÒÑÊÛ³öÃÅÆ±µÄURL³Á¶¨Ïòµ½Í¬Ä±µÄµç×ÓÓʼþÉÏ¡£Á½ÈËÒÑÔÚŦԼÊб»²¶£¬²¢Ãæ¶Ô¶àÏîÐÌÊÂÖ¸¿Ø£¬Ò»µ©×ïÃû³ÉÁ¢£¬½«Ãæ¶Ô×î¸ß15ÄêµÄ½ûïÀ¡£Õâ´Î½ø¹¥Ðж¯Í¹ÏÔÁË´¦Ëù¼ì²ì¹Ù°ì¹«ÊÒ¶ÔÍøÂç·¸×ïµÄ¾¯ÌèÐÔ£¬ÒÔ¼°ÓëÐÐÒµºÏ×÷ͬ°é½ø¹¥Ú²Æ»î¶¯ºÍÈ·±£Ïû·ÑÕß±£»¤µÄ³ÁÒªÐÔ¡£µ÷²éÈÔÔÚ½øÐÐÖУ¬ÒÔÈ·¶¨Õâ´ÎÐж¯µÄ¹æÄ£ºÍÆäËûDZÔÚͬı¡£
https://www.bleepingcomputer.com/news/security/cybercrime-crew-stole-635-000-in-taylor-swift-concert-tickets/
5. PyPIÉϵÄÒÔÌ«·»Ë½Ô¿ÇÔÈ¡·¨Ê½±»ÏÂÔØ³¬¹ý 1,000 ´Î
3ÔÂ6ÈÕ£¬Ò»¸öÃûΪ¡°set-utils¡±µÄ¶ñÒâPython°üÔÚPyPIÉϱ»·¢ÏÖ£¬¸Ã°ü¼Ù×°³ÉʵÓõŤ¾ß°ü£¬Í¨¹ýÀ¹½ØÒÔÌ«·»Ç®°ü´´½¨Ö°ÄÜÇÔȡ˽Կ£¬²¢Í¨¹ýPolygonÇø¿éÁ´½«Æäй¶¡£×Ô2025Äê1ÔÂ29ÈÕÌá½»ÒÔÀ´£¬¸Ã°üÒѱ»ÏÂÔØÒ»Ç§ÂŴΣ¬ÖØÒªÕë¶ÔÇø¿éÁ´¿ª·¢ÈËÔ±¡¢»ùÓÚPythonµÄDeFiÏîÄ¿¡¢Ö§³ÖÒÔÌ«·»µÄWeb3ÀûÓ÷¨Ê½ÒÔ¼°Ê¹ÓÃPython×Ô¶¯»¯µÄÓ×ÎÒÇ®°ü¡£¸Ã¶ñÒâ°üǶÈëÁ˹¥»÷ÕßµÄRSA¹«Ô¿£¬ÓÃÓÚ¼ÓÃܱ»µÁµÄ˽Կ£¬²¢½«ÆäǶÈëµ½ÒÔÌ«·»ÂòÂôµÄÊý¾Ý×Ö¶ÎÖУ¬Í¨¹ýPolygon RPC¶Ëµã·¢Ë͵½¹¥»÷ÕßµÄÕÊ»§¡£ÕâÖÖ²½ÖèÏà¶ÔÒñ±Î£¬²»Ò×±»·À»ðǽºÍ·À²¡¶¾¹¤¾ß¼ì²âµ½¡£Ò»µ©Êý¾Ýй¶¹ý³ÌʵÏÖ£¬¹¥»÷ÕßÄܹ»ËæÊ±¼ìË÷±»µÁÊý¾Ý£¬ÓÉÓÚ±»µÁÐÅÏ¢»áÓÀÔ¶´æ´¢ÔÚÇø¿éÁ´ÉÏ¡£Ö»¹Ü¸Ã°üÒѱ»´ÓPyPIÖÐɾ³ý£¬µ«Òѽ«ÆäÄÉÈëÏîÖ÷ÕÅÓû§ºÍÈí¼þ¿ª·¢ÈËÔ±¸Ãµ±¼´Ð¶ÔØËü£¬²¢Èç¹û´´½¨µÄÈκÎÒÔÌ«·»Ç®°ü¶¼ÒÑÊܵ½Íþв£¬¾¡¿ì×ªÒÆ×ʽðÒÔÔ¤·À±»µÁ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/ethereum-private-key-stealer-on-pypi-downloaded-over-1-000-times/
6. ³¬¹ý1000¸öWordPressÍøÕ¾Ôâ¶ñÒâJavaScript´úÂë¹¥»÷
3ÔÂ6ÈÕ£¬³¬¹ý1000¸öÓÉWordPressÖ§³ÖµÄÍøÕ¾±»µÚÈý·½JavaScript´úÂëϰȾ£¬¸Ã´úÂëÖ²ÈëÁËËĸö¶ÀÁ¢ºóÃÅ£¬Îª¹¥»÷ÕßÌṩ¶à³ÁÈëÇÖõè¾¶¡£ÕâЩºóÃÅÔ̺¬Ò»¸öÃûΪ¡°Ultra SEO Processor¡±µÄÐéα²å¼þ£¬ÓÃÓÚÖ´Ðй¥»÷ÕߺÅÁÏòwp-config.php×¢Èë¶ñÒâJavaScript£»Ïò~/.ssh/authorized_keysÔö³¤SSHÃÜÔ¿ÒÔʵÏÖÔ¶³Ì½Ó¼û£»ÒÔ¼°´Ógsocket[.]io»ñÈ¡ÔØºÉÒÔ´ò¿ª·´Ïòshell¡£Îª½µµÍ·çÏÕ£¬Óû§±»½¨Òéɾ³ýδÊÚȨSSHÃÜÔ¿¡¢¸ü»»WordPressÖÎÀíÔ±ÃÜÂ룬²¢¼à¿ØÈÕÖ¾¡£´Ëǰ£¬ÒÑÓг¬¹ý35000¸öÍøÕ¾Ôâ¶ñÒâJavaScriptÈëÇÖ£¬µ¼Ö½ӼûÕß±»³Á¶¨ÏòÖÁÖÐÎÄ´ò¶Äƽ̨¡£Í¬Ê±£¬ÃûΪScreamedJungleµÄÍþвÐÐΪÕßͨ¹ý×¢ÈëBablosoft JS¾ç±¾£¬Ó°ÏìÁË115¸öÒÔÉϵÄMagentoÍøÕ¾£¬ÍøÂçÓû§Ö¸ÎÆÐÅÏ¢¡£¹¥»÷ÕßÀûÓÃÒÑÖª·ì϶£¬ÈçCVE-2024-34102ºÍCVE-2024-20720£¬½øÐÐÍøÕ¾ÈëÇÖ¡£Group-IBÖ¸³ö£¬ä¯ÀÀÆ÷Ö¸ÎÆ¼ø±ð¼¼ÊõËä³£ÓÃÓÚÓû§¸ú×ÙºÍÓªÏúÕ½Êõ£¬µ«Ò²±»·¸×ï·Ö×ÓÓÃÓÚ·ÂÕպϷ¨Óû§¡¢Ìӱܰ²È«´ëÊ©¼°Ö´ÐÐڲơ£
https://thehackernews.com/2025/03/over-1000-wordpress-sites-infected-with.html


¾©¹«Íø°²±¸11010802024551ºÅ