¼ÓÃÜÆ½Ì¨AbracadabraÔâºÚ¿Í¹¥»÷£¬½ü1300ÍòÃÀÔª±»µÁ

°ä²¼¹¦·ò 2025-03-26

1. ¼ÓÃÜÆ½Ì¨AbracadabraÔâºÚ¿Í¹¥»÷£¬½ü1300ÍòÃÀÔª±»µÁ


3ÔÂ26ÈÕ£¬¼ÓÃÜÇ®±Ò½è´ûƽ̨Abracadabra FinanceÓÚÖܶþÔ糿Ôâ·êºÚ¿Í¹¥»÷£¬³õ²½¹ÀËãËðʧԼ1300ÍòÃÀÔªµÄÊý×Ö×ʲú¡£¾Ý¸Ã¹«Ë¾É罻ýÌåÉêÃ÷£¬Õâ´Î°²È«·ì϶ԴÓÚÆä"cauldrons"¹ÂÁ¢½è´ûÊг¡²úÆ·£¬¸Ã²úÆ·ÔÊÐíÓû§ÒÔ¶àÀàÐͼÓÃÜ×ʲú×÷ΪµÖѺ½øÐнè´û²Ù×÷¡£Ö»¹Üÿ¸ö½è´ûºÏÔ¼¾ùͨ¹ý°²È«É󼯹«Ë¾GuardianÉóºË£¬ÇÒ²¿Êð¶à²ã·À»¤»úÔ죬µ«¹¥»÷ÕßÈÔͨ¹ýδÅû¶µÄ¼¼Êõ·ì϶ʵÏÖ¶à±Ê¶ñÒâÂòÂô¡£Ä¿Ç°Æ½Ì¨¼¼ÊõÍŶÓÕýÓëGuardian¼°Çø¿éÁ´·ÖÎö»ú¹¹ChainalysisºÏ×÷×·×Ù±»µÁ×ʽð£¬Í¬Ê±°ä·¢Ç°¶Ë·þÎñÔÝÍ£²¢Æô¶¯Ó¦¼±ÏìÓ¦Á÷³Ì¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ºÚ¿Í¹¥»÷×ʽðÆðÔ´±»Ö¸ÓëÈ¥ÖÐÐÄ»¯ÂòÂôËùGMX´æÔÚ¹ØÁª£¬µ«GMXÒÑͨ¹ý¹Ù·½Çþ·³ÎÇåÆäÖÇÄܺÏԼδÊÜÓ°Ï죬ǿµ÷±¾´ÎÊÂÎñÓëÆäµÖѺƷ´ú±Ò·þÎñÎ޹ء£°²È«·ÖÎö»ú¹¹Ö¸³ö£¬ºÚ¿ÍÀûÓà Tornado Cash »ìºÏÆ÷×ªÒÆÔ߿¶ø¸Ã·þÎñÉÏÖܸÕÒòÃÀ¹ú˾·¨²¿³·ÏúÔì²Ã¸´Ô­ÔË×÷¡£Îª¾¡¿ì×·»Ø×ʽð£¬Abracadabra°ä·¢¶Ô·µ»¹±»µÁ×ʲúµÄ¹¥»÷ÕßÌṩ20%µÄÉͽð¼¤Àø£¬Õ¹Ê¾³öÐÐÒµÓ¦¶Ô°²È«Î£»úµÄµäÐÍÕ½Êõ¡£


https://therecord.media/nearly-thirteen-million-stolen-abracadabra


2. Cloudflare R2·þÎñÖжÏ£¬Òòƾ֤ÃýÎóÖÂÈ«ÇòдÈëʧ°Ü


3ÔÂ25ÈÕ£¬CloudflareÆìÏÂR2¶ÔÏó´æ´¢·þÎñ½üÆÚ²úÉú³ÖÐø1Ó×ʱ7·ÖÖÓµÄÖжÏÊÂÎñ£¬µ¼ÖÂÈ«ÇòÁìÓòÄÚдÈë²Ù×÷Æëȫʧ°Ü£¬¶ÁÈ¡³É¹¦ÂʽµÖÁ65%¡£×÷Ϊ¼æÈÝS3ºÍ̸µÄ¿ÉÀ©´ó´æ´¢½â¾ö¹æ»®£¬R2¼¯³ÉÃâ·ÑÊý¾Ý¼ìË÷Óë¶àÇøÓò¸´ÔìÖ°ÄÜ£¬Õâ´Î¹ÊÕÏÖØÒªÔ´ÓÚÆ¾Ö¤ÂÖ»»Á÷³ÌÖеı¨´ð²Ù×÷ʧÎó¡£¼¼Êõµ÷²éÏÔʾ£¬ÔËάÍŶÓÔÚ¸üÐÂÉí·ÝÑé֤ƾ֤ʱ£¬ÒòÒÅ©"--env production"ºÅÁîÐвÎÊý£¬Îó½«ÐÂÆ¾Ö¤²¿ÊðÖÁ¿ª·¢»·¾³¶ø·Ç³ö²úϵͳ¡£µ±¾Éƾ֤°´´òËãʧЧºó£¬³ö²ú»·¾³R2Íø¹ØÒò²»×ãÓÐЧƾ֤ʧÂä¶Ô´æ´¢»ù´¡ÉèÊ©µÄ½Ó¼ûȨÏÞ¡£ÓÉÓÚÆ¾Ö¤Ê§Ð§´æÔÚ´«²¼ÑÓ³¤£¬·þÎñ½µ¼¶³õÆÚδ´¥·¢¼´Ê±¸æ¾¯£¬½øÒ»²½ÑÓ»ºÁ˹ÊÕÏ·¢ÏÖÓë´ëÖùý³Ì¡£Õâ´ÎÊÂÎñËäδÔì³ÉÊý¾ÝÃÔʧ£¬µ«Òý·¢Á¬Ëø·´Ó³£º»º´æÔ¤Áô·þÎñÒò¶Áȡʧ°Üµ¼ÖÂÔ´Õ¾Á÷Á¿¼¤Ôö£¬Í¼Ïñ´«ÊäЧÄܽµÂä75%£¬Á÷ýÌå´«ÊäÂÊÖè½µÖÁ6%£¬Óʼþ°²È«¡¢ÈÕÖ¾´«ÊäµÈ¹ØÁª·þÎñ¾ù³öÏÖ·ÖÆçˮƽ½µ¼¶¡£Õë¶Ô¶³öµÄÁ÷³Ìȱµã£¬CloudflareÒѲÉÈ¡¸Ä½ø´ëÊ©¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬ÕâÊÇR2·þÎñÄêÄÚµÚ¶þ´ÎÒò±¨´ðÃýÎóµ¼Ö·þÎñÖжÏ¡£


https://www.bleepingcomputer.com/news/security/cloudflare-r2-service-outage-caused-by-password-rotation-error/


3. ÂíÀ´Î÷ÑÇ»ú³¡ÔâÍøÂç¹¥»÷ÀÕË÷£¬×ÜÀí¾Ü¸¶Êê½ð±£ÎÀ°²È«


3ÔÂ26ÈÕ£¬ÂíÀ´Î÷ÑǼªÂ¡ÆÂ¹ú¼Ê»ú³¡£¨KLIA£©Ôâ·êµÄÍøÂçϵͳ¹ÊÕϱ»Ö¤ÊµÎªÍøÂç¹¥»÷ËùÖ£¬ÊÂÎñÒý·¢µ±¾Ö¸ß²ãȾָ¼°¹ú¼Ê°²È«¹Ø×¢¡£¾ÝÂíÀ´Î÷Ñǹú¶ÈÍøÂ簲ȫ¾Ö£¨NACSA£©Óë»ú³¡ÖÎÀí·½½áºÏÉêÃ÷£¬¹¥»÷ʼÓÚ3ÔÂ23ÈÕ£¬Ö¸±êÖ±Ö¸ÕÆ¹ÜÈ«¹úÎÞÊý»ú³¡ÔËÓªµÄÂíÀ´Î÷ÑÇ»ú³¡¿Ø¹ÉÓÐÏÞ¹«Ë¾£¨MAHB£©£¬ºÚ¿ÍË÷Òª1000ÍòÃÀÔªÊê½ð¡£×ÜÀí°²Íß¶û¡¤Òײ·À­ÐÀÔÚ¹«¿ªÑݽ²ÖÐǿӲ±í̬»Ø¾øÍ×Э£¬Ç¿µ÷"¹ú¶È¾ø²»ºÏ·¸×ïÍ×Э"µÄ̬¶È£¬Í¬Ê±Î´Åû¶¹¥»÷×éÖ¯Éí·Ý£¬ÒàÎÞ¼¯Ì幫¿ªÈÏÔð¡£Ö»¹Ü¹Ù·½ÉêÃ÷³Æ»ú³¡ÔËÓª"δÊÜÓ°Ïì"£¬µ«Ç°ÒéÔ±»Æ×æÇ¿Åû¶µÄÕÕÆ¬ÏÔʾ£¬ÏµÍ³¹ÊÕϳÖÐø³¬10Ó×ʱ£¬µ¼Öº½°àÐÅÏ¢¡¢Öµ»ú¼°ÐÐÀîϵͳ̱»¾£¬¹¤×÷ÈËÔ±±»ÆÈʹÓðװåÊÖ¹¤¼Í¼º½°àÐÅÏ¢¡£ÕâÖÖԭʼӦ¼±¼¿Á©Óë¹ú¼Ê»ú³¡µÄÏÖ´ú»¯¶¨Î»ÐγÉÇ¿ÁÒ·´²î£¬Òý·¢¹«¼Ò¶ÔÊÂÎñͨÃ÷¶ÈµÄÖÊÒÉ¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬Õâ´Î¹¥»÷ÓëÈ«ÇòÀÕË÷Èí¼þÍÅ»ï½üÆÚÕë¶Ô½»Í¨ÊàŦµÄÃܼ¯Ðж¯ÐγÉÏìÓ¦¡£¾Ý±¨Â·£¬´Óǰ°ëÄêÄÚ£¬Î÷ÑÅͼ¡¢ÈÕ±¾¼°Ä«Î÷¸ç¹ú¼Ê»ú³¡½ÓÁ¬ÔâÀÕË÷Èí¼þÏ®»÷£¬·´Ó³³ö¹Ø¼ü»ù´¡ÉèÊ©Õý³ÉÎªÍøÂç·¸×ïµÄ¸ß¼ÛÖµÖ¸±ê¡£


https://therecord.media/malaysia-pm-says-country-rejected-ransom-demand-airport-cyberattack


4. ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯¶Ô¶íÂÞ˹»¥ÁªÍøÌṩÉÌLovitµÄÍøÂç¹¥»÷ÕÆ¹Ü


3ÔÂ25ÈÕ£¬ÎÚ¿ËÀ¼Ãñ¼äºÚ¿Í×éÖ¯¡°IT Army¡±Ðû³Æ¶Ô¶íÂÞ˹»¥ÁªÍø·þÎñÉÌLovitÌáÒéÍøÂç¹¥»÷£¬µ¼ÖÂĪ˹¿Æ¼°Ê¥±ËµÃ±¤µØÓò³ÖÐøÈýÌìµÄ·þÎṉ̃»¾¡£Õâ´ÎÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷ʼÓÚÉÏÖÜÎ壬²»½öʹÒÀÀµLovitÍøÂçµÄ¹«Ô¢Â¥ÃŽûϵͳʧЧ£¬¸üµ¼ÖÂÉ̼ÒÖ§¸¶Öն˺ͻáÔ±ÏµÍ³È«Ãæ¹ÊÕÏ¡£¶íÂÞË¹ÍøÂç¼à¹Ü»ú¹¹Roskomnadzor֤ʵ¹¥»÷Ô´Éæ¼°ÃÀ¡¢µÂ¡¢ÈðµäµÈ¶à¹ú·þÎñÆ÷¼°½©Ê¬ÍøÂ磬ֱָLovit¹Ø¼ü»ù´¡ÉèÊ©£¬Â¶³ö³ö¸Ã¹«Ë¾¶Ô´ó¹æÄ£ÍøÂç¹¥»÷µÄ·ÀÓù³ï±¸²»¼°¡£×÷Ϊ¶íÂÞ˹×î´óµØ²úÉÌPIKÆìÏÂ×¡Õ¬ÇøµÄ¶À¼ÒÍøÂ繩¸øÉÌ£¬Lovit³Ö¾Ã¢¶ÏְλÒý·¢Ãñ¶à²»Âú¡£Õâ´Î¹¥»÷ºó£¬ÊÜÓ°Ïì¾ÓÃñÕý³ï±¸Ïò·´Â¢¶Ï»ú¹¹Ìá½»¼¯ÌåËßËÏ£¬Ö¸¿ØÆä¶¨¼Û¹ý¸ßÇÒ¹ÊÕÏÊг¡¾ºÕù¡£ÍøÂ簲ȫÆóÒµVisum·ÖÎöÖ¸³ö£¬¹¥»÷Ñ¡ÔñLovit»òÒòÆä¸²¸Ç¿í·º£¬¸ÃÍøÂçͬʱ·þÎñÒ½Ôº¡¢Ñ§Ìõȹ«¹²ÉèÊ©£¬µ¼ÖÂÁ¬ËøÓ°Ïì¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õë¶Ô¶íÂÞ˹µçÐÅÐÐÒµµÄÍøÂç¹¥»÷½üÆÚ³öÏÖÕþÖλ¯¡¢¸ßƵ»¯Ç÷Ïò¡£´ËÀ๥»÷²»½ö¿¼Ñ鹨¼üÐÅÏ¢»ù´¡ÉèÊ©·À»¤ÄÜÁ¦£¬¸ü·´Ó³³öÍøÂç¿Õ¼äÒѳÉΪµØÔµÃ¬¶ÜµÄÐÂÕ½³¡¡£


https://therecord.media/russia-isp-lovit-outages-claimed-ukraine-it-army


5. ¡¶·´¿Ö¾«Ó¢2¡·Íæ¼ÒÔâBitB´¹µö¹¥»÷£¬SteamÕË»§µÁÈ¡·çÏÕÉý¼¶


3ÔÂ25ÈÕ£¬Õë¶ÔÈȵãµç¾ºÓÎÏ·¡¶·´¿Ö¾«Ó¢2¡·Íæ¼ÒµÄÐÂÐÍÍøÂç´¹µö¹¥»÷½üÆÚ¸¡ÏÖ£¬¹¥»÷Õßѡȡ"ä¯ÀÀÆ÷ÄÚä¯ÀÀÆ÷"£¨BitB£©¼¼Êõ¹¹½¨¸ß·ÂÕæ´¹µöÒ³Ãæ¡£¸Ã¹¥»÷ÀûÓÃ2022ÄêÅû¶µÄBitB¿ò¼Ü£¬ÄÜÔÚÕæÊµä¯ÀÀÆ÷´°¿ÚÖÐǶÌ×ÐéαµÇ¼½çÃæ£¬¾«×¼·ÂÕÕSteam¹Ù·½µÇ¼ҳ£¬ÉõÖÁ¿É×Ô½ç˵URLºÍ´°¿Ú±êÌâÒÔ¼ÓÇ¿ºýŪÐÔ¡£¹¥»÷Õß¼ÙÒâÎÚ¿ËÀ¼¶¥¼¶µç¾ºÕ½¶ÓNaviÖ´Ðо«×¼´¹µö£¬Í¨¹ýYouTubeÊÓÆµ¼°¼Ù×°³É"Ãâ·ÑCS2Ƥ·ôÁìÈ¡"µÄ¶ñÒâÍøÕ¾ÒýÁ÷¡£¾­°²È«×êÑÐÔ±×·×Ù£¬¶à¸ö´¹µöÍøÕ¾¹²ÏíÒ»ÑùIPµØÖ·£¬Åú×¢´æÔÚ×éÖ¯»¯×÷°¸Ìصã¡£Êܺ¦Õß±»ÓÕµ¼ÔÚÐéαµÇ¼¿òÊäÈëÕË»§ÐÅϢʱ£¬¹¥»÷Õß¼´¿ÉʵʱÇÔȡƾ֤¼°Ò»´ÎÐÔÑéÖ¤Â루OTP£©£¬Ëæºó½«µÁÈ¡µÄSteamÕË»§ÔÚµØÏÂÊг¡¸ß¼ÛתÊÛ£¬ÕË»§¼Ûֵȡ¾öÓÚ¿â´æÓÎÏ·¼°Ðé¹¹ÎïÆ·ÊýÁ¿¡£¼¼Êõ·ÖÎöÏÔʾ£¬´ËÀàÐéα´°¿Ú¾ß±¸·´¼ì²âÌØµã£ºÎÞ·¨µ÷Õû´óÓ×»òÍÏÀëÖ÷´°¿Ú£¬Óëͨ³£ä¯ÀÀÆ÷µ¯³ö´°¿ÚÐÐΪ¸ß¶ÈÀàËÆ£¬µ¼ÖÂÓû§ÄÑÒÔ¾õ²ìÒì³£¡£°²È«×¨¼Ò½¨ÒéÍæ¼ÒÆôÓÃSteamË«³ÁÑéÖ¤£¨³ö¸ñÊÇÒÆ¶¯ÈÏÖ¤Æ÷£©£¬¶¨ÆÚºË²éµÇ¼¼Í¼£¬²¢¾¯ÌèÒªÇóÌṩÕË»§Æ¾Ö¤»ò¼ÓÃÜÇ®±ÒÇ®°üµÄµÚÈý·½ÍøÕ¾¡£


https://www.bleepingcomputer.com/news/security/browser-in-the-browser-attacks-target-cs2-players-steam-accounts/


6. Android¶ñÒâÈí¼þÀûÓÃ.NET MAUI¿ò¼Ü¼Ù×°ºÏ·¨·þÎñÇÔÈ¡Êý¾Ý


3ÔÂ25ÈÕ£¬ÐÂÐÍAndroid¶ñÒâÈí¼þÀûÓÃ΢Èí.NET MAUI¿ò¼ÜÖ´ÐÐÒñ±Î¹¥»÷£¬Æä¼¼ÊõÌØµãÓ밲ȫÍþвÒý·¢Òµ½ç¹Ø×¢¡£Âõ¿Ë·ÆÒƶ¯×êÑÐÍŶӼà²âµ½£¬¹¥»÷Õßͨ¹ý¸Ã¿çƽ̨¿ª·¢¿ò¼Ü¹¹½¨¶ñÒâÀûÓ㬼Ù×°³É½ðÈÚ¡¢Éç½»µÈºÏ·¨·þÎñÖ´ÐÐÊý¾ÝÇÔÈ¡£¬Ö¸±ê¼¯ÖÐÔÚÖйúºÍÓ¡¶ÈµÈGoogle Play½Ó¼ûÊÜÏÞµØÓò¡£¼¼Êõ²ãÃæ£¬¹¥»÷ÕßÍ»ÆÆ´«Í³AndroidÀûÓüì²â»úÔ죺.NET MAUIÔÊÐíÒÔC#¿ª·¢ÀûÓò¢½«Ö÷ÌâÂß¼­·â×°ÓÚ¶þ½øÔìblobÎļþ£¬¶øÖ÷Á÷°²È«¹¤¾ßÖØÒªÉ¨ÃèDEXÌåʽÎļþ£¬µ¼Ö¶ñÒâ´úÂëµÃÒÔÈÆ¹ý¼ì²â¡£½áºÏ¶à²ã¼ÓÃÜ¡¢¶¯Ì¬´úÂë¼ÓÔØ¼°TCPÒñ±ÎͨѶµÈ¼¼Êõ£¬¸Ã¶ñÒâÈí¼þÐγÉ"µÍÌØµãÂñ·ü-·Ö½×¶Î¼¤»î"µÄ¹¥»÷Á´¡£¼ÙðÀûÓÃÀàÐ͸²¸ÇÒøÐпͻ§¶Ë¡¢Éç½»Èí¼þµÈ¸ßƵ³¡¾°£¬Í¨¹ý´¹µö½çÃæÓÕµ¼Óû§Ìá½»Ãô¸ÐÐÅÏ¢£¬Í¬Ê±ÇÔȡͨѶ¼¡¢¶ÌÐż°¶àýÌåÎļþ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¹¥»÷ÕßÀûÓÃGoogle PlayµØÓòÏÞ¶È£¬Í¨¹ýµÚÈý·½Çþ··Ö·¢¶ñÒâAPK£¬ÏÔÖøÀ©´óϰȾÁìÓò¡£°²È«×¨¼Ò½¨Ò飬Óû§Ó¦Ô¤·À×°ÖÃÆðÔ´²»Ã÷µÄÀûÓá£ÔÚGoogle Play²»³ÉÓÃÇøÓò£¬ÐèʹÓð²È«Èí¼þɨÃèAPK£¬²¢ÓÅÏÈÑ¡Óùٷ½»ò¿ÉÐÅ·Ö·¢Æ½Ì¨¡£

https://www.bleepingcomputer.com/news/security/new-android-malware-uses-microsofts-net-maui-to-evade-detection/