Microsoft Stream¾ÉÓòÃûÔâ½Ù³ÖÖÂSharePointÒ³ÃæÏÔʾ¶Ä³¡¸æ°×

°ä²¼¹¦·ò 2025-03-28

1. Microsoft Stream¾ÉÓòÃûÔâ½Ù³ÖÖÂSharePointÒ³ÃæÏÔʾ¶Ä³¡¸æ°×


3ÔÂ27ÈÕ£¬×÷Ϊ΢Èí365Éú̬µÄÆóÒµ¼¶ÊÓÆµ·þÎñ£¬Microsoft Stream¾­µä°æÓÚ2020ÄêÆô¶¯Ç¨áãÖÁSharePoint£¬Ô­ÓòÃûmicrosoftstream.com°´´òËãÓ¦ÓÚ2024ÄêÈ«ÃæÍËÒÛ¡£È»¶ø2025Äê3Ô£¬¸ÃÓòÃûÍ»Ôâ½Ù³Ö£¬¹¥»÷Õß´Û¸ÄDNS½âÎöʹÆäÖ¸Ïò·ÂðÑÇÂíÑ·½çÃæµÄÌ©¹ú¶Ä³¡´¹µöÒ³Ãæ£¬µ¼ÖÂÈÔǶÈë¾É°æÊÓÆµÁ´½ÓµÄSharePointÒ³Ãæ±»À¬»øÄÚÈÝ´«È¾¡£¼¼Êõµ÷²éÏÔʾ£¬ÓòÃû×¢²áÐÅÏ¢ÓÚÊ·¢µ±ÈÕ±»·¸·¨Åú¸Ä£¬¹¥»÷Õß¿ÉÄÜͨ¹ýÉç»á¹¤³Ìѧ»ò·ì϶ÀûÓûñÈ¡½ÚÔìȨ¡£Ö»¹Ü΢ÈíÒÑ´¹Î£¹Ø¹ØÓòÃû½âÎö£¬µ«Õâ´ÎÊÂÎñ¶ÔÓû§µÄDZÔÚ·çÏÕ²»ÈݺöÊÓ£ºÆóÒµÄÚÍøÓû§¿ÉÄÜÒò½Ó¼û±»½Ù³ÖÒ³Ãæµ¼ÖÂÃô¸ÐÊý¾Ýй¶£¬¶øSharePointÉú̬ÖвÐÁôµÄǶÈëÁ´½Ó¸ü³ÉΪ³ÖÐøÍþв¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¹¥»÷Õßδ½øÒ»²½Ö²Èë¶ñÒâÈí¼þ£¬ÖØÒª·çÏÕ¼¯ÖÐÔÚÍøÂç´¹µö²ãÃæ¡£°²È«×¨¼ÒÖ¸³ö£¬´ËÀàÊÂÎñ·´Ó³³öÆóÒµ¶ÔÍËÒÛÓòÃû´ëÖÃµÄÆÕ±éÊè©£ºÊµÊ±¸üÐÂǶÈë×ÊÔ´¡¢²»×ãDNS¼à¿Ø»úÔ졢δ²¿ÊðDNSSEC·À»¤µÈ·ì϶£¬¶¼¿ÉÄܱ»¹¥»÷ÕßÀûÓÃÖ´ÐÐÖÐÑëÈ˹¥»÷¡£


https://www.bleepingcomputer.com/news/microsoft/hijacked-microsoft-stream-classic-domain-spams-sharepoint-sites/


2. ¡¶°×Ñ©¹«Ö÷¡·Î´ÉÏÏßDisney+£¬µÁ°æÏÝÚå°µ²Ø¶ñÒâÈí¼þ


3ÔÂ27ÈÕ£¬µÏÊ¿ÄáÕæÈ˰桶°×Ñ©¹«Ö÷¡·Î´Í¨¹ýµÏÊ¿Äá×ÔÓÐÁ÷ýÌåÆ½Ì¨Disney+¿¯ÐУ¬ÆÈʹ²¿ÃŹ۶àתÏòµÁ°æÇþ·£¬È´Òò¶øÏÝÈëÍøÂçÚ¿Æ­ÏÝÚå¡£ÍøÂ簲ȫ¹«Ë¾VeritiÅû¶£¬Ú¿Æ­·Ö×ÓÀûÓÃӰƬδÉÏÏßÕý¹æÆ½Ì¨µÄ¿ÕµµÆÚ£¬ÔÚ"TeamEsteem"ÍøÕ¾°ä²¼ÐéᲩ¿Í£¬¼Ù×°³É¹Ù·½×ÊÔ´Ìṩ2025°æ¡¶°×Ñ©¹«Ö÷¡·µÁ°æÏÂÔØ¡£¸Ã´ÅÁ¦ÖÖ×ÓÁ´½Ó¿´ËƺϷ¨£¬ÊµÔò°ó¸¿¶ñÒâÈí¼þ¡£ÒÑÓÐ45ÃûÓû§ÏÂÔØ²¢´«²¼¸ÃÖÖ×ÓÎļþ£¬ÆäÖÐÔ̺¬¼Ù×°³ÉÊÓÆµ±à½âÂëÆ÷µÄ"xmph_codec.exe"·¨Ê½¡£Ò»µ©Ö´ÐУ¬¸Ã·¨Ê½½«Ö´Ðжà³Á¶ñÒâ²Ù×÷£ºÊ×ÏȽûÓÃWindows DefenderµÈ°²È«·À»¤£¬ËæºóÖ²Èë±»50¿î°²È«¹¤¾ßÏóÕ÷Ϊ¶ñÒâµÄÎļþ£¬²¢¾²Ä¬×°ÖÃTORä¯ÀÀÆ÷³ÉÁ¢°µÍøÍ¨Ñ¶Í¨Â·£¬×îÖÕʹÉ豸¶³öÓÚÊý¾Ý͵ÇÔºÍÀÕË÷Èí¼þ¹¥»÷·çÏÕÖС£¹¥»÷Õß¿ÉÄÜͨ¹ýÁ½ÖÖ·½Ê½ÈëÇÖTeamEsteem¹ÙÍø£ºÒ»ÊÇÀûÓÃYoast SEO²å¼þ¾É°æ±¾·ì϶£¨CVE-2023-40680£©£¬¶þÊǵÁÈ¡ÖÎÀíԱƾֱ֤½Ó°ä²¼ÐéαÄÚÈÝ¡£°²È«×¨¼Ò½¨Ò飬¹Û¶àÓ¦Ô¤·ÀÏÂÔØÆðÔ´²»Ã÷µÄµÁ°æÄÚÈÝ£¬¶¨ÆÚ¸üз´¶ñÒâÈí¼þ£¬²¢¶ÔÒªÇó×°Ööî±í±à½âÂëÆ÷µÄ¿ÉÒÉÎļþά³Ö¾¯Ì裬ÒÔ·ÀÂäÈëÍøÂç·¸×ïÏÝÚå¡£


https://hackread.com/fake-snow-white-movie-torrent-infects-device-malware/


3. COPAÊý¾Ýй¶ÊÂÎñ²¨¼°Á½Öݽü68,000Ãû»¼ÕßÃô¸ÐÐÅÏ¢


3ÔÂ27ÈÕ£¬È¥Äê11Ô£¬ºÚ¿Í×éÖ¯Everest Team½«ÃÀ¹ú¹Ç¿ÆÒ½ÁÆ»ú¹¹Concord Orthopaedics£¨COPA£©ÁÐÈë°µÍøÐ¹ÃÜÍøÕ¾£¬Ðû³Æ°ÑÎÕÆä×Ô2018ÄêÆðµÄËùÓл¼ÕßÒ½ÁƼͼ¼°Ó×ÎÒÊý¾Ý£¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢Ô¤Ô¼ÐÅÏ¢¡¢½¡È«±£ÏÕÏêÇé¼°²¿ÃżÝÊ»ÅÆÕÕͼÏñ¡£¸Ã»ú¹¹ÓÚ2025Äê3ÔÂ25ÈÕÏòÊÜÓ°ÏìÕß¼ÄËÍÊéÃæÍ¨Öª£¬È·ÈÏÆä»¼ÕߵǼÇÓëԤԼϵͳ¹©¸øÉÌÔâÍøÂçÈëÇÖ£¬µ«Ç¿µ÷ÄÚ²¿»·¾³Î´ÊÜÓ°Ï졣ƾ¾ÝCOPA²¼¸æ£¬Ð¹Â¶Ô´Í·ÎªµÚÈý·½¹©¸øÉ̵ÄÈí¼þ·ì϶£¬±íйÊý¾ÝÀàÐͺ­¸ÇÔ¤Ô¼¼Í¼£¨ÈçÊÖÊõÀàÐÍ¡¢Ò½ÉúÐÕÃû¡¢ÈÕÆÚµØÖ·£©¡¢½¡È«±£ÏÕÐÅÏ¢£¨º¬ÊÜÒæÈ˱àºÅ¡¢±£ÏÕ×ʸñ£©¼°²¿ÃÅÉí·ÝÎļþ¡£¹©¸øÉÌÓÚ2025Äê1ÔÂ28ÈÕÏòCOPAÌṩDZÔÚÓ°ÏìÊý¾ÝÁìÓò¡£Ðº±²¼Ê²¶ûÖÝ×ܼì²ì³¤°ì¹«ÊÒÅû¶£¬¸ÃÖݹ²ÓÐ67,835Ãû¾ÓÃñÐÅÏ¢ÉæÏÕ£¬ÂíÈøÖîÈûÖÝ»¹ÓÐ1,517ÈËÊÜÓ°Ïì¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Everest°ä²¼µÄ2.9GBй¶Êý¾Ý°üÏÖʵÔ̺¬2019-2024Äê¼ä¸ü¿í·ºµÄ»¼ÕßÐÅÏ¢£¬ÇÒDataBreaches·¢ÏÖ¹©¸øÉÌ·þÎñÆ÷´æ´¢´óÁ¿Î´¼ÓÃÜÃô¸ÐÊý¾Ý£¬Ô̺¬³¬¹ý3ÍòÕżÝÕÕͼÏñ¼°ÆäËûCSVÌåʽҽÁƼͼ£¬¹¦·ò¿ç¶ÈÔ¶³¬ºÚ¿Í×î³õÐû³ÆµÄ2018Äê¡£


https://databreaches.net/2025/03/27/four-months-after-learning-of-a-vendors-breach-concord-orthopaedics-notifies-almost-68000-patients/


4. Vroom by YouXÒòAWSÅäÖÃÃýÎóµ¼ÖÂÃô¸ÐÊý¾Ýй¶


3ÔÂ27ÈÕ£¬°Ä´óÀûÑǽðÈڿƼ¼¹«Ë¾Vroom by YouX½üÆÚÔâ·êÃô¸ÐÊý¾Ýй¶ÊÂÎñ£¬°²È«×êÑÐÔ±Jeremiah FowlerÔÚ¹«¿ª¿É½Ó¼ûµÄAmazon S3´æ´¢Í°Öз¢ÏÖÔ̺¬27,000±Ê¼Í¼µÄÎÞ±£»¤Êý¾Ý¿â£¬Ð¹Â¶ÐÅÏ¢º­¸Ç¼ÝÕÕ¡¢Ò½ÁƼͼ¡¢¾ÍÒµÖ¤Ã÷¼°º¬²¿ÃÅÐÅÓþ¿¨ºÅµÄÒøÐжÔÕ˵¥µÈ¸ß¶ÈÃô¸ÐÊý¾Ý¡£¸üÁîÈËÓÇÓôµÄÊÇ£¬ÄÚ²¿½ØÍ¼ÏÔʾ´æÔÚ±£Áô320Íò·ÝÎĵµµÄMongoDBÊ·ý£¬Æä¶³ö״̬¿ÉÄÜÐγÉÍøÂç¹¥»÷ÐÂÈë¿Ú¡£ÊÂÎñÆØ¹âºó£¬VroomѸ¿ìÏÞ¶ÈÊý¾Ý¿â½Ó¼ûȨÏÞ£¬ÈϿɰ²È«·ì϶²¢³Ðŵ·¢Õ¹¹ýºóÉó²é¡£×÷ΪÈËΪÖÇÄÜÇý¶¯µÄÆû³µÈÚ×ÊÆ½Ì¨£¬¸Ã¹«Ë¾×Ô2022ÄêÔËÓªÒÔÀ´³ÖÐø´¦ÖôóÁ¿¿Í»§Ãô¸ÐÐÅÏ¢£¬Õâ´Îй¶¼Í¼¹¦·ò¿ç¶È´ïÈýÄ꣬͹ÏÔÊý¾Ý´¦Öû·½ÚµÄ°²È«Òþ»¼¡£°²È«×¨¼ÒÖ¸³ö£¬´ËÀàÐÅϢй¶½«Ö±½Óµ¼ÖÂڲƭ·çÏÕ¼¤Ôö£¬Ô̺¬Éç»á¹¤³Ì¹¥»÷¡¢ÐéαÕË»§¿ªÉè¼°¾«×¼ÍøÂç´¹µöµÈ¡£ÆóҵӦѡȡMFAÉí·ÝÑéÖ¤¡¢RBACȨÏÞÖÎÀí¡¢¼ÓÃÜ´«ÊäÓë´æ´¢µÈÖ÷Ìâ´ëÊ©£¬½áºÏCloudTrailµÈ¼à¿Ø¹¤¾ßʵÏÖÍþвʵʱԤ¾¯£¬¶¨ÆÚ·¢Õ¹ÉøÈë²âÊÔ½¨²¹Èõµã£¬¹¹ÖþÈ«ÐÔÃüÖÜÆÚ°²È«·À»¤Á´Ìõ¡£


https://hackread.com/aussie-fintech-vroom-pii-records-aws-misconfiguration/


5. CoffeeLoader¶ñÒâÈí¼þÀûÓô´Ð¼¼Êõ¶ã±Ü¼ì²âÍþвWindowsÓû§


3ÔÂ27ÈÕ£¬ÐÂÐͶñÒâÈí¼þ¼Ò×å"CoffeeLoader"Õý¶ÔWindowsÓû§×é³ÉÑϳÁÍþв£¬Æä¸ß¶ÈÒñ±ÎÐÔʹµÃ´«Í³·À²¡¶¾Èí¼þÄÑÒÔ¼ì²â¡£¸Ã¶ñÒâÈí¼þ×îÔçÓÉZscaler°²È«ÍŶÓÓÚ2024Äê9Ô·¢ÏÖ£¬Æä¹¥»÷Á´Ê¼ÓÚ¼Ù×°³É»ªË¶Armoury Crateϵͳ¹¤¾ß£¬ÓÕµ¼Óû§ÏÂÔØºóÖ²ÈëÐÅÏ¢ÇÔȡģ¿é£¬ÒÑÖª¿É´îÔØRhadamanthysµÈ¸ßΣÇÔÃÜ·¨Ê½¡£CoffeeLoaderչʾ³ö¶àά¶È¶ã±Ü¼ì²â¼¼Êõ£ºÑ¡È¡Armoury Packer¼Ó¿Ç¼¼ÊõÖ´ÐгõʼºýŪ£¬¸ü´´Ðµؽ«²¿ÃŶñÒâ´úÂë×ªÒÆÖÁGPUÖ´ÐУ¬ÀûÓð²È«Èí¼þ¶ÔͼÐδ¦ÖÃÆ÷µÄ¼à²âÃ¤ÇøÊµÏÖ³Ö¾ÃÂñ·ü¡£ÆäŲÓòֿâ´Û¸Ä¼¼Êõ¿ÉαÔ캯ÊýŲÓÃÁ´£¬Ê¹°²È«·ÖÎö¹¤¾ßÎóÅз¨Ê½ÐÐΪÊôÐÔ¡£µ±¼ì²âµ½°²È«É¨Ãèʱ£¬¸Ã¶ñÒâÈí¼þ»áÆô¶¯"˯Ãß»ìºÏ"»úÔ죬½«×ÔÉí¼ÓÃÜ´æ´¢ÓÚÄÚ´æ·Ç»îÔ¾Çø¶Î£¬ÓÐЧ¶ã±Üʵʱ¼ì²â¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬CoffeeLoader´´ÔìÐÔµØÀûÓÃWindows FibersÇáÁ¿¼¶Ï̼߳¼Êõʩǰ¹ý³ÌÄڶ๤×÷µ÷¶È£¬ÕâÖַdz߶ÈÏß³ÌÖÎÀí·½Ê½ÍùÍùÈÆ¹ýͨÀý¼à¿ØÏµÍ³¡£Í¨¹ýÕâÖÖ¸´ºÏʽÌÓÒÝÕ½Êõ£¬¸Ã¶ñÒâÈí¼þÄÜÔÚÖ¸±êϵͳ³Ö¾ÃפÁô£¬³ÖÐøÖ´ÐÐδ¾­ÊÚȨµÄÊý¾Ý²É¼¯»òºáÏòÉøÈëµÈ¶ñÒâ²Ù×÷¡£°²È«×¨¼Ò½¨Òé¼ÓÇ¿ÖÕ¶ËÐÐΪ¼à¿Ø£¬²¿Êð»ùÓÚGPU»î¶¯·ÖÎöµÄ¼ì²â¹æ»®£¬²¢¶¨ÆÚÑé֤ϵͳ¹¤¾ßµÄÆëÈ«ÐÔÒÔ·À±¸´ËÀà¸ß¼¶³ÖÐøÐÔÍþв¡£


https://cybernews.com/security/coffeeloader-malware-asus-windows/


6. Ê®¿înpm°üÔâ¶ñÒâ´Û¸Ä£¬¼ÓÃÜÇ®±Ò¿ª·¢ÕßÃô¸ÐÊý¾Ý±»µÁÈ¡


3ÔÂ27ÈÕ£¬½üÈÕ£¬Ê®¿înpmÈí¼þ°üÍ»·¢¶ñÒâ´úÂëÖ²ÈëÊÂÎñ£¬Õë¶Ô¼ÓÃÜÇ®±ÒÁìÓò¿ª·¢ÕßÖ´Ðй©¸øÁ´¹¥»÷¡£°²È«³§ÉÌSonatypeµÄ×êÑÐÔ±°¢À°£¶ûɳ¿²»ùÀïÂÊÏÈ·¢ÏÖ£¬¹¥»÷ÕßÀûÓûìºÏ¾ç±¾ÔÚÈí¼þ°ü×°ÖÃʱÇÔȡϵͳ»·¾³±äÁ¿£¬Ãô¸ÐÊý¾Ý±»»Ø´«ÖÁÔ¶³Ì·þÎñÆ÷¡£ÊÜÓ°ÏìÈí¼þ°üÖУ¬Èȵã¿â"country-currency-map"ÿÖÜÏÂÔØÁ¿´ïÊýǧ´Î£¬Æä2.1.8°æ±¾±»Ö²Èë¶ñÒâ´úÂ룬ÀÛ¼ÆÏÂÔØ288´Î¡£¶ñÒâ´úÂëÒþÄäÓÚÁ½¸ö¾­¹ý¸ß¶È»ìºÏµÄ¾ç±¾Îļþ£¬Í¨¹ýnpm°ü×°ÖûúÔì×Ô¶¯Ö´ÐУ¬×¨ÃŲ¶»ñÔ̺¬APIÃÜÔ¿¡¢Êý¾Ý¿âƾ֤µÈÃô¸ÐÐÅÏ¢µÄϵͳ»·¾³±äÁ¿¡£°²È«×¨¼Ò·ÖÎöÖ¸³ö£¬Õâ´Î¹¥»÷¼«ÓпÉÄÜÊÇͨ¹ýÊÕÊܳ־Ãδ»îÔ¾µÄÊØ»¤ÕßÕË»§Ö´ÐУ¬¹¥»÷Õß¿ÉÄÜÀûÓôËǰй¶µÄƾ֤½øÐÐ"ײ¿â"¹¥»÷£¬»òÀûÓùýÆÚÓòÃû½ÚÔìȨÏÞ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ËùÓб»´Û¸ÄµÄ²Ö¿âÖжñÒâ´úÂë°æ±¾ÆëȫһÖ£¬ÇÒÎÞÊý²Ö¿âÒÑÊýÄêδ¸üУ¬½øÒ»²½×ôÖ¤ÁËÕË»§½Ù³ÖµÄ´§Ä¦¡£Ä¿Ç°£¬³ý"country-currency-map"ÒÑÆúÓöñÒâ°æ±¾²¢Êèµ¼Óû§½µ¼¶ÖÁ2.1.7°²È«°æ±¾±í£¬ÆäÓà±»´Û¸ÄÈí¼þ°üÈÔЯ´ø¶ñÒâ´úÂëÔÚnpmƽ̨Á÷ͨ¡£Ö»¹ÜnpmÒѶԻîÔ¾ÏîĿǿÔìÆôÓÃË«³É·ÖÈÏÖ¤£¬µ«Õâ´ÎÉæÊÂÈí¼þ°ü¶àΪÀϾÉÏîÄ¿£¬ÊØ»¤Õß¿ÉÄÜÒÑÍÑÀëÖÎÀí£¬Ðγɰ²È«·À»¤Ã¤Çø¡£


https://www.bleepingcomputer.com/news/security/infostealer-campaign-compromises-10-npm-packages-targets-devs/