CISA½«SysAid¸ßΣXXE·ì϶ÄÉÈëÒÑÖª±»ÀûÓÃĿ¼

°ä²¼¹¦·ò 2025-07-24

1. CISA½«SysAid¸ßΣXXE·ì϶ÄÉÈëÒÑÖª±»ÀûÓÃĿ¼


7ÔÂ23ÈÕ£¬ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«Ó°ÏìSysAid ITÖ§³ÖÈí¼þµÄÁ½¸ö¸ßΣ°²È«·ì϶ÁÐÈëÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ2025Äê8ÔÂ12ÈÕǰʵÏÖ½¨¸´¡£Õâ´ÎÉæ¼°µÄÁ½¸ö·ì϶£¨CVE-2025-2775ºÍCVE-2025-2776£©¾ùÓÉwatchTowr Labs×êÑÐÈËÔ±Sina KheirkhahºÍJake KnottÓÚ5ÔÂÅû¶£¬CVSSÆÀ·Ö´ï9.3¼¶£¬ÊôÓÚÑϳÁ¼¶±ð¡£Á½Õß¾ùÒòXML±í²¿ÊµÌ壨XXE£©ÒýÓÃÏ޶Ȳ»µ±£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ýCheckin´¦ÖÃÖ°ÄܺͷþÎñÆ÷URL´¦ÖÃÖ°ÄÜÖ´ÐÐÖÎÀíÔ¹ØË»§ÊÕÊܼ°Ãô¸ÐÎļþÇÔÈ¡¡£¼¼Êõ·ÖÎöÏÔʾ£¬ÕâЩ·ì϶ÔÊÐí¹¥»÷Õß×¢Èë¶ñÒâXMLʵÌ壬´¥·¢·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©¹¥»÷¡£¸üΣÏÕµÄÊÇ£¬µ±ÓëCyberArkÈ¥Äê·¢ÏֵĺÅÁî×¢Èë·ì϶£¨CVE-2024-36394£©½áӦʱ£¬¿ÉÄÜÉý¼¶ÎªÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£SysAidÒÑÔÚ3Ô³õ°ä²¼µÄ24.4.60 build 16°æ±¾Öн¨¸´ÕâÈý¸ö·ì϶£¬ÆäÖÐÔ̺¬ÁíÒ»¸öÔ¤ÈÏÖ¤XXE·ì϶£¨CVE-2025-2777£©¡£Ö»¹ÜĿǰÉÐδÃ÷È·CVE-2025-2775/2776µÄÏÖʵ¹¥»÷ϸ½Ú¼°ÍþвÐÐΪÕßÉí·Ý£¬CISAÈÔ»ùÓÚ×Ô¶¯ÀûÓÃÖ¤¾Ý½«ÆäÄÉÈëKEVĿ¼¡£


https://thehackernews.com/2025/07/cisa-warns-sysaid-flaws-under-active.html


2. ºÚ¿ÍαÔìÃÀ¹úµ±¾ÖÍøÕ¾Ö´Ðд¹µö¹¥»÷Õë¶Ô½ÌÓý¹¤×÷Õß


7ÔÂ24ÈÕ£¬ÍøÂ簲ȫÁìÓòÆØ¹âһ·Õë¶ÔÃÀ¹ú½ÌÓýϵͳµÄÍøÂç´¹µö¹¥»÷»î¶¯£¬ºÚ¿Íͨ¹ýαÔìµ±¾ÖÍøÕ¾ÇÔÈ¡½ÌÓý¹¤×÷ÕßÃô¸ÐÐÅÏ¢£¬Òý¿¯ÐÐÒµ¸ß¶È¹Ø×¢¡£BforeAIÆìÏÂPreCrime³¢ÊÔÊÒµÄÍþв×êÑÐÈËÔ±·¢ÏÖ£¬¶à¸ö·ÂÕÕÃÀ¹ú½ÌÓý²¿G5²¦¿îÖÎÀíϵͳÖ÷Ò³ºÍµÇ¼ÃÅ»§µÄ¶ñÒâÓòÃûÔÚ»îÔ¾£¬ÕâЩÓòÃûͨ¹ýÊÓ¾õÉè¼Æ¿Ë¡¡¢ÐéαµÇ¼±íµ¥¼°JavaScriptƾ֤ÇÔÈ¡¼¼Êõ£¬ÊÔͼÓÕÆ­½ÌÓý»ú¹¹¡¢²¦¿îÖÎÀíÔ±¼°¹©¸øÉÌÊäÈëÕ˺ÅÃÜÂë¡£G5ϵͳ×÷ΪÁª¹ú²¦¿î×ʽð·ÖÅäµÄÖ÷ÌâÆ½Ì¨£¬É漰ѧÉúÔöÔ®µÈ¹Ø¼üÏîÄ¿£¬ÆäÓû§¸²¸ÇѧÌá¢Öݵ±¾Ö»ú¹¹¼°·ÇͶ»ú×éÖ¯¡£Õâ´Î¹¥»÷µÄÌØÊâÐÔÔÚÓÚ£¬¹¥»÷Õß²»½ö¸´ÔìÁ˹ٷ½ÍøÕ¾£¨g5.gov£©µÄ½çÃæ£¬»¹Í¨¹ýCloudflare CDN·þÎñ°µ²ØÓòÃûÕæÊµÐÔ£¬ÀûÓÃÆäÐû¸æµÄSSLÖ¤Êé¼ÓÇ¿´¹µöÒ³ÃæµÄºÏ·¨ÐÔ¡£×êÑÐÈËÔ±Ö¸³ö£¬ÕâЩÓòÃû×¢²áÓÚÒÔÀÄÓúϹæÕþ²ßÎÅÃûµÄHello Internet Corp£¬ÇÒѡȡanalytics.phpµÈ¾ç±¾·ÂÕյǼÁ÷³Ì£¬Í¨¹ýDOM²Ù×÷»ìºÏ×Ô¶¯»¯¼ì²â£¬×îÖÕ½«Êܺ¦ÕßÊèµ¼ÖÁ/verify/¶Ëµã½øÐжþ´Î´¹µö»òÈÆ¹ý¶à³É·ÖÈÏÖ¤¡£PreCrime³¢ÊÔÊÒÒÑÈ·ÈÏÁù¸öÓµÓкýŪÐÔµÄÓòÃû£¬²¢ÓÚ7ÔÂ15ÈÕÏòÃÀ¹úÄÜÔ´²¿£¨DOE£©Ìá½»»ã±¨¡£


https://www.darkreading.com/threat-intelligence/department-of-education-site-phishing-scheme


3. Clorox¸æ×´Cognizant´íÎóÖÂÍøÂç¹¥»÷£¬Ë÷Åⳬ3.8ÒÚÃÀÔª


7ÔÂ23ÈÕ£¬Ïû·ÑÆ·¾ÞÍ·¸ßÀÖÊÏ£¨Clorox£©½üÈÕ¶ÔÈ«ÇòIT·þÎñÌṩÉÌCognizantÌá¸æ×´ËÏ£¬Ö¸¿ØÆäÒò³Á´ó´íÎóµ¼ÖÂ2023Äê8Ô²úÉúÑϳÁÍøÂç¹¥»÷¡£Æ¾¾ÝËßËÏÎļþ£¬Cognizant×Ô2013ÄêÆðΪ¸ßÀÖÊÏÌṩITÔËÓªÖ§³Ö£¬Ô̺¬·þÎñ̨ÖÎÀíºÍÉí·ÝÑéÖ¤·þÎñ£¬µ«ÆäÔڹؼü°²È«Á÷³ÌÖдæÔÚϵͳÐÔʧְ¡£ÊÂÎñÆðÒòÓÚ2023Äê8ÔÂ11ÈÕ£¬ºÚ¿Íͨ¹ýÉç»á¹¤³Ì¹¥»÷ÂÅ´ÎÖµçCognizant·þÎñ̨£¬¼ÙÒâ¸ßÀÖÊÏÔ±¹¤ÒªÇó³ÁÖÃÃÜÂë¼°¶à³É·ÖÈÏÖ¤£¨MFA£©¡£Ö»¹Ü¸ßÀÖÊÏÃ÷È·ÒªÇó±ØÐëÑéÖ¤Éí·Ý·½¿ÉÖ´ÐвÙ×÷£¬Cognizant¿Í·þÈËԱȴδºËÊ·´µçÕßÉí·Ý£¬Ö±½Ó³ÁÖÃÁËÔ±¹¤ÕË»§¼°MFAƾ֤¡£¸üÑϳÁµÄÊÇ£¬¹¥»÷ÕßËæºóÒÔÒ»Ñù¼¿Á©Æ­È¡IT°²È«Ô±¹¤µÄÌØÈ¨ÕË»§½Ó¼ûȨÏÞ£¬µ¼Ö¹¥»÷À©É¢ÖÁÖ÷ÌâÍøÂç¡£Õâ´ÎÈëÇÖ±»¹éÒòÓÚÓë"Scattered Spider"×éÖ¯Óйصĺڿͼ¯Ì壬¸Ã¼¯ÌåÔøÒÔÀàËÆÊÖ·¨¹¥»÷Ó¢¹úÂêɯ°Ù»õµÈÆóÒµ¡£Õâ´Î¹¥»÷µ¼Ö¸ßÀÖÊϹ«Ë¾ÍøÂçÈ«ÃæÌ±»¾£¬³ö²úϵͳͣ°Ú£¬Òý·¢´ó¹æÄ£²úƷǷȱºÍ¹©¸øÁ´ÖжÏ¡£¾Ý¹ÀË㣬ֱ½Ó²¹¾ÈÓöȴï4900ÍòÃÀÔª£¬¶øÒµÎñÖжϡ¢ÏúÊÛ¶îËðʧ¼°ÃûÓþÇÖº¦µÈ×ÛºÏËðʧ¸ß´ï3.8ÒÚÃÀÔª¡£


https://www.bleepingcomputer.com/news/security/hackers-fooled-cognizant-help-desk-says-clorox-in-380m-cyberattack-lawsuit/


4. ÿÖÜÏÂÔØÁ¿´ï280Íò´ÎµÄNPMÈí¼þ°üÔâ¶ñÒâÈí¼þϰȾ


7ÔÂ23ÈÕ£¬Ê¢ÐÐNPM°ü"is"±»Ö¤ÊµÔâºÚ¿ÍÈëÇÖ²¢Ö²ÈëºóÃŶñÒâÈí¼þ¡£Õâ´Î¹¥»÷Ô´ÓÚÊØ»¤ÕßJohn HarbandµÄÕË»§Í¨¹ý´¹µö¹¥»÷±»½Ù³Ö£¬¹¥»÷ÕßÔÚ6Ó×ʱÄÚδ¾­ÊÚȨ°ä²¼ÁËÔ̺¬¶ñÒâ´úÂëµÄ3.3.1ÖÁ5.0.0°æ±¾£¬µ¼ÖÂÿÖܳ¬280Íò´ÎÏÂÔØµÄ¿ª·¢¹¤¾ßÂÙΪ¹¥»÷Ìø°å¡£¸Ã¶ñÒâÈí¼þ±»°²È«ÍŶÓSocket¼ø¶¨Îª¿çƽ̨JavaScript¼ÓÔØÆ÷£¬Í¨¹ýWebSocket³ÉÁ¢ÓƾúóÃÅ¡£¼¤»îºó£¬¶ñÒⷨʽ»áÇÔÈ¡Ö÷»úÃû¡¢²Ù×÷ϵͳÐÅÏ¢¡¢CPU¼Ü¹¹µÈÏµÍ³ÌØµã£¬²¢²¶»ñÈ«Êý»·¾³±äÁ¿¡£¸üΣÏÕµÄÊÇ£¬Æäͨ¹ý¶¯Ì¬µ¼Èë"ws"¿â³ÉÁ¢µÄWebSocketÏνӿɽ«Ã¿Ìõ½Ó¹ÜÖ¸ÁîÖ±½ÓÊÓΪ¿ÉÖ´ÐÐJavaScript£¬Ê¹¹¥»÷Õß»ñµÃ½»»¥Ê½Ô¶³ÌShellȨÏÞ£¬Ï൱ÓÚÆëÈ«½ÚÔìÊÜϰȾÉ豸¡£¹¥»÷²úÉúºó£¬NPM¹Ù·½´¹Î£É¾³ý¶ñÒâ°æ±¾£¬µ«×Ô¶¯¸üлúÔìµ¼Ö²¿ÃŸô·¢ÕßÔÚ6Ó×ʱ´°¿°¢ÚÄÚ±»¶¯½Ó¹ÜÁËÓж¾°æ±¾¡£°²È«×¨¼Ò½¨Ò鿪·¢ÍŶӵ±¼´¶³½áÒÀÀµ°æ±¾£¬¹Ø¹Ø×Ô¶¯¸üÐÂÖ°ÄÜ£¬²¢Í¨¹ýËøÎļþËø¶¨°²È«°æ±¾ £»ÊØ»¤ÕßÐèÈ«Ãæ³ÁÖÃÕË»§ÃÜÂë²¢ÂÖ»»ËùÓйØÁªÁîÅÆ¡£


https://www.bleepingcomputer.com/news/security/npm-package-is-with-28m-weekly-downloads-infected-devs-with-malware/


5. ·¨ÎÚ½áºÏÐж¯²é·â¶íÓïºÚ¿ÍÂÛ̳XSS.is


7ÔÂ23ÈÕ£¬Ó¦°ÍÀè¼ì²ìÔºÒªÇó£¬ÎÚ¿ËÀ¼¾¯·½ÔÚÅ·ÖÞÐ̾¯×é֯ЭÖúÏ£¬ÓÚ2025Äê7ÔÂ23ÈÕ¿ÛÁôÁ˶íÓïºÚ¿ÍÂÛ̳XSS.isµÄÒÉËÆÖÎÀíÔ±£¬²¢Õýʽ²é·â¸Ãƽ̨¡£ÕâÒ»Ðж¯±ê־ȡ³ÖÐøËÄÄêµÄ¿ç¹úÍøÂç·¸×ïµ÷²é»ñµÃ¹Ø¼üÍ»ÆÆ£¬Ò²·´Ó³³ö¹ú¼Ê·¨ÂÉ»ú¹¹¶Ô°µÍø·¸×ïÉú̬µÄ¾«×¼½ø¹¥ÄÜÁ¦¡£XSS.is×÷Ϊ¶íÓïÇø×î¾ßÓ°ÏìÁ¦µÄÍøÂç·¸×ïÂÛ̳֮һ£¬×Ô2013ÄêÔËÓªÒÔÀ´¶Ñ¼¯³¬5ÍòÃû×¢²áÓû§£¬³Ö¾Ã³äÈζñÒâÈí¼þÂòÂô¡¢ÀÕË÷Èí¼þ·þÎñ£¨RaaS£©Íƹ㼰ÊÜϰȾϵͳ½Ó¼ûȨÏÞ··ÂôµÄÊàŦ¡£Ö»¹Ü¸ÃÆ½Ì¨ÔøÓÚ2021Äê5Ô°䷢²»ÈÝÀÕË÷Èí¼þÓйػáÉÌ£¬µ«·¨¹ú˾·¨²¿Ãŵ÷²éÏÔʾ£¬Æä±³ºóÍÅ»ïÈÔͨ¹ý¼ÓÃÜͨѶÇþ·³ÖÐøÐ­µ÷·¸·¨»î¶¯£¬ËÄÄê¼ä»ñÈ¡ÖÁÉÙ700ÍòÃÀÔª·¸·¨ÀûÈó¡£Õâ´Îµ÷²éʼÓÚ2021Äê7Ô£¬ÓɰÍÀè¼ì²ìÔºÍøÂç·¸×ﲿÃÅǣͷ£¬°ÍÀ辯Ա¾ÖÍøÂç·¸×ï´ó¶Ó¾ßÌåÖ´ÐС£·¨·½Í¨¹ý¹¥ÆÆºÚ¿Í³£ÓõļÓÃÜͨѶƽ̨Jabber·þÎñÆ÷£¨thesecure.biz£©£¬¶Ô·¸×ïÍÅ»ïͨѶִÐÐ˾·¨¼àÌý£¬³É¹¦½Ø»ñ´óÁ¿Éæ¼°ÍøÂç¹¥»÷¡¢Êý¾ÝÀÕË÷µÄ·¸×ïÖ¤¾Ý¡ £»ùÓÚÕâЩÏßË÷£¬·¨ÂÉ»ú¹¹ÓÚ2021Äê11ÔÂÆô¶¯ÐÌʵ÷²é£¬²¢ÓÚ2024Äê9Ô²¿ÊðÏßÏÂÐж¯£¬×îÖÕÔÚÎÚ·½¹²Í¬ÏÂʵÏÖ¶ÔÂÛ̳ÖÎÀíÔ±µÄ×¥²¶¡£


https://www.bleepingcomputer.com/news/security/ukraine-arrests-suspected-admin-of-xss-russian-hacking-forum/


6. ·¨¹ú¾ÍÒµ¾ÖÔÙÔâÊý¾Ýй¶£¬Ó°Ïì34ÍòÇóÖ°Õß


7ÔÂ23ÈÕ£¬·¨¹ú¾ÍÒµ¾Ö£¨France Travail£©ÓÚ2025Äê7ÔÂ13ÈÕ·¢ÏÔìä¡°¾ÍÒµ¡±ÃÅ»§ÍøÕ¾²úÉúÊý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÔ¼34ÍòÇóÖ°Õߣ¬³ÉΪ¸Ã»ú¹¹Á½ÄêÄÚµÚ¶þ´Î³Á´ó°²È«±äÂÒ¡£Õâ´Îй¶¶³öµÄÓû§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÓÊÕþµØÖ·¡¢µç×ÓÓÊÏä¡¢µç»°ºÅÂë¡¢»ú¹¹±êʶ·û¼°Çóְ״̬£¬µ«ÃÜÂëÓëÒøÐÐϸ½Úδ±»»ñÈ¡¡£·¨¹úÍøÂ簲ȫ»ú¹¹£¨ANSSI£©ÏÂÊôµÄÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT-FR£©ÓÚ7ÔÂ12ÈÕÂÊÏȼà²âµ½Òì³££¬·¨¹ú¾ÍÒµ¾ÖËæºóÓÚ7ÔÂ22ÈÕÏòÓû§·¢Ë;¯Ê¾Óʼþ£¬ÌáÐÑ·À±¸ÍøÂç´¹µö¹¥»÷¡£µ÷²éÏÔʾ£¬Ð¹Â¶Ô´ÓÚÒÁÔó¶ûʡijÅàѵ×éÖ¯¹ØÁªÕË»§ÔâÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¨infostealer£©ÈëÇÖ¡£¹¥»÷Õßͨ¹ý¸ÃÕË»§»ñÈ¡ÁËKairosÀûÓ÷¨Ê½µÄ½Ó¼ûȨÏÞ£¬¸Ãƽ̨ÓÃÓÚ×·×ÙÇóÖ°ÕßÅàѵ½ø¶È£¬×îÖÕµ¼ÖÂÊý¾Ý±íй¡£·¨¹ú¾ÍÒµ¾Ö½²»°ÈË֤ʵ£¬ÉæÊ·þÎñ£¨Ô̺¬¾ÍÒµÃÅ»§ÓëKairosϵͳ£©Òѵ±¼´¹Ø¹Ø£¬²¢´òËãÓÚ7ÔÂ24ÈÕ¸´Ô­ÔËÓª¡£×÷Ϊ²¹¾È´ëÊ©£¬Ô­¶¨2026Ä겿ÊðµÄË«³É·ÖÈÏÖ¤£¨2FA£©±»ÌáǰִÐУ¬ÒÔÇ¿»¯ÕË»§°²È«¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬2024Äê3Ô¸ûú¹¹ÔøÒòITϵͳÔâ¹¥»÷£¬µ¼Ö´Óǰ20ÄêÄÚ×¢²áµÄ4300ÍòÓû§Êý¾Ýй¶£¬´´Ï·¨¹ú¹«¹²²¿ÃÅÊý¾Ýй¶¹æÄ£Ö®×î¡£


https://www.infosecurity-magazine.com/news/france-data-breach-jobseekers/