±±ÃÀ±ùÖÆÆ·¹©¸øÉÌÔâ÷è÷ëÀÕË÷Èí¼þÈëÇÖ£¬Ãô¸ÐÊý¾ÝÒÉй¶

°ä²¼¹¦·ò 2025-07-31

1. ±±ÃÀ±ùÖÆÆ·¹©¸øÉÌÔâ÷è÷ëÀÕË÷Èí¼þÈëÇÖ£¬Ãô¸ÐÊý¾ÝÒÉй¶


7ÔÂ29ÈÕ£¬±±ÃÀÖØÒª±ùÖÆÆ·¹©¸øÉ̱±¼«±ù´¨£¨Arctic Glacier£©½üÈÕ±»ÆØ³ÉΪ÷è÷루Qilin£©ÀÕË÷Èí¼þÍÅ»ïµÄ×îй¥»÷Ö¸±ê£¬ÆäÃô¸ÐÆóÒµÊý¾Ý¡¢Ô±¹¤ÐÅÏ¢¼°¸öÈË×ÊÁÏÔâÇÔ²¢ÔÚ°µÍøÕ¹Ê¾ ¡£×÷ΪÃÀ¹úºÍ¼ÓÄôó×î´óµÄ°ü×°±ù¼°Ëé±ù¹©¸øÉÌÖ®Ò»£¬±±¼«±ù´¨·þÎñ¶ÔÏóº­¸Ç7-ElevenµÈ·½±ãµê¾ÞÍ·£¬ÔËÓª×ų¬¹ý100¸ö·ÖÏúÖÐÐÄ£¬Îª7.5Íò¼ÒÁãÊÛ¡¢Ã³Ò×¼°¹¤Òµ¿Í»§Ìṩ·þÎñ£¬È¥ÄêÓªÊÕ¿¿½ü3ÒÚÃÀÔª£¬Ô±¹¤¹æÄ£³¬Ç§ÈË ¡£÷è÷ëÍÅ»ïÔÚÆä°µÍø²©¿ÍÐû³ÆÈëÇֳɹ¦£¬²¢°ä²¼Á˶àÕžݳÆÀ´×Ô±±¼«±ù´¨µÄй¶Êý¾Ý½ØÍ¼£¬ÄÚÈÝÔ̺¬»¤ÕÕ¡¢¼ÝÕÕ¸±±¾¡¢Ô±¹¤Ð½³ê¼Í¼¼°Ë¾·¨²ÆÕþÎļþ ¡£Õâ´ÎÊý¾Ýй¶¿ÉÄÜÒý·¢¶à³Á·çÏÕ£º¹¥»÷Õß»òÀûÓÃÓ×ÎÒÐÅÏ¢Ö´ÐÐÉí·Ý͵ÇÔ¡¢Ú²Æ­ÐÔÕË»§×¢²á£¬»òͨ¹ý¼Ù×°³É¹«Ë¾¿Í»§/¹ÍÖ÷ÌáÒéÕë¶ÔÐÔ´¹µö¹¥»÷ ¡£¸üÑϳÁµÄÊÇ£¬Ð¹Â¶µÄ˾·¨Îļþ¿ÉÄܱ»ÓÃÓÚ·ÖÎöÆóÒ·ûÒæ¹ØÏµ£¬ÎªºóÐø¸ü¾ß·ÛËéÐԵĹ¥»÷Ìṩµý±¨Ö§³Ö ¡£


https://cybernews.com/security/arctic-glacier-data-breach-claims/


2. PyPIÔâ·ê¸ßÒñ±ÎÐÔÍøÂç´¹µö¹¥»÷


7ÔÂ29ÈÕ£¬Python°üË÷Òý£¨PyPI£©ÊØ»¤Õß½üÈÕ·¢³ö´¹Î£ÖҸ棬³ÆÆäÓû§ÕýÔâ·êÒ»³¡¾«ÐIJ߶¯µÄÍøÂç´¹µö¹¥»÷ ¡£¹¥»÷Õßͨ¹ýαÔìÖ÷ÌâΪ¡°[PyPI] µç×ÓÓʼþÑéÖ¤¡±µÄÓʼþ£¬ÓÕµ¼Óû§µã»÷Á´½ÓÖÁÐéÎ±ÍøÕ¾£¬ÒÔÇÔÈ¡µÇ¼ƾ֤ ¡£Õâ´Î¹¥»÷µÄ¹ÖÒìÖ®´¦ÔÚÓÚ£¬Æä¼¼ÊõÊÖ·¨ÓµÓи߶ÈÒñ±ÎÐÔ£¬Óû§ÔÚÐéÎ±ÍøÕ¾ÊäÈëÐÅÏ¢ºó£¬ÒªÇó»á±»Â·ÓÉÖÁºÏ·¨PyPI·þÎñÆ÷£¬Ê¹Êܺ¦ÕßÎóÒÔΪ²Ù×÷Õý³££¬ÊµÔòƾ֤ÒÑÔâ½Ø»ñ ¡£¾ÝPyPIÖÎÀíÔ±Mike FiedlerÅû¶£¬¹¥»÷Óʼþ·¢¼þµØÖ·Îªnoreply@pypj[.]org£¨°ÑÎÈÓòÃû²¢·Ç¹Ù·½pypi[.]org£©£¬ÓʼþÄÚÈÝÒªÇóÓû§ÑéÖ¤ÓÊÏ䵨ַ£¬²¢Êèµ¼ÖÁ·ÂðPyPI½çÃæµÄ´¹µöÍøÕ¾ ¡£Ö»¹Ü¹¥»÷δֱ½ÓÍ»ÆÆPyPIϵͳ°²È«£¬µ«ÀûÓÃÁËÓû§¶Ô¹Ù·½Æ½Ì¨µÄÐÅÀµ£¬ÊôÓÚµäÐ͵ÄÉç»á¹¤³Ì¹¥»÷ ¡£PyPIÍŶÓÇ¿µ÷£¬´ËÀàÐÐΪ¿ÉÄÜÕë¶ÔÖÎÀíÈȵãÈí¼þ°üµÄ¿ª·¢ÕßÕË»§£¬Ò»µ©µÃ³Ñ£¬¹¥»÷Õß»ò¿É°ä²¼¶ñÒâ°ü£¬À©´ó·çÏÕÁìÓò ¡£


https://thehackernews.com/2025/07/pypi-warns-of-ongoing-phishing-campaign.html


3. ·ÇÖÞ×éÖ¯Ôâ·ê´ó¹æÄ£Microsoft SharePoint·ì϶¹¥»÷


7ÔÂ30ÈÕ£¬·ÇÖÞ¹ú¶ÈÕýÃæ¶ÔÍøÂç¹¥»÷µÄ¿Õǰ¼¤Ôö£¬»úÓöÖ÷ÒåÍþвÐÐΪÕßͨ¹ý´ó¹æÄ£É¨Ã軥ÁªÍø£¬ÀûÓÃδʵʱ½¨²¹µÄn-day°²È«·ì϶£¬¹¥»÷Æä¼±¾çÀ©Õŵ«°²È«·À»¤ÓÄ΢µÄÊý×Ö»ù´¡ÉèÊ© ¡£½üÆÚ£¬ÄϷǹú¶È²ÆÕþ²¿¡¢Æû³µÔì×÷Òµ¡¢´óѧ¼°´¦Ëùµ±¾ÖµÈÖÁÉÙÁù¼Ò»ú¹¹Ôâ΢ÈíSharePointÈí¼þÖеÄToolShell·ì϶£¨CVE-2025-53770/53771£©¹¥»÷£¬ÊÂÎñ²¨¼°Ã«ÀïÇó˹¡¢Ô¼µ©µÈµØ£¬Í¹ÏÔ·ÇÖÞ³ÉΪȫÇòÍøÂç·¸×ïµÄÐÂÖ¸±ê ¡£¹¥»÷ÕßÀûÓõķì϶×îÔçÔÚ2025Äê5ÔÂPwn2Own½ÏÁ¿Öб»·¢ÏÖ£¬Î¢ÈíËäÓÚ7Ô³õ°ä²¼²¹¶¡£¬µ«ÈýÌìºóÁãÈÕ±äÌå¼´±»ÓÃÓÚʵս ¡£°²È«¹«Ë¾BitdefenderÖ¸³ö£¬·ÇÖ޵ĴàÈõÐÔÔ´ÓÚÆäÊý×Ö»¯¹ý³ÌÓëÍøÂ簲ȫÄÜÁ¦µÄ²»Æ¥Å䣺Ϊ½µµÍ³É±¾£¬´óÁ¿×é֯ѡȡ±¾µØ²¿ÊðÈí¼þ£¨Èç´æÔÚ·ì϶µÄSharePoint£©£¬µ«ÒòITÈËÁ¦ÓÐÏÞ£¬ÄÑÒÔÓÐЧÖÎÀí°²È«¸üР¡£ESET×êÑÐÔ±Anton Cherepanov²¹³ä³Æ£¬¹¥»÷ģʽ³öÏÖÁ½½×¶ÎÌØµã£¬·ì϶¸ÅÏëÑéÖ¤£¨PoC£©´úÂë°ä²¼ºó24Ó×ʱÄÚ£¬¹¥»÷Õß¼±¾ç³ÉÁ¢Ì²Í·Õ󵨣¬ÊýÖܺóÔÙ·¢Õ¹ÊÖ¶¯ÉøÈë ¡£


https://www.darkreading.com/cyber-risk/african-orgs-mass-microsoft-sharepoint-exploits


4. ¶íÂÞ˹ҽÁÆÓëÃñÉúÁìÓòÔâ´ó¹æÄ£ÍøÂç¹¥»÷


7ÔÂ30ÈÕ£¬±¾ÖܶíÂÞ˹ҽÁƼ°ÃñÉúÁìÓòÔâ·ê¶àÆðÑϳÁÍøÂç¹¥»÷ÊÂÎñ£¬µ¼ÖÂÈ«¹úÊý°Ù¼ÒÒ©µêÆÆ²ú¡¢Ò½ÁÆ»ú¹¹·þÎṉ̃»¾£¬Òý·¢Éç»á¿í·º¹Ø×¢ ¡£¶íÂÞ˹Á½´óÁ¬ËøÒ©µêStolichki£¨Ô¼1000¼ÒÃŵ꣩ºÍNeofarm£¨³¬110¼ÒÃŵ꣩Ïà¼Ì֤ʵ£¬ÖܶþÆðÒòºÚ¿Í¹¥»÷µ¼ÖÂÖ§¸¶ÏµÍ³¡¢Ò©Æ·Ô¤Ô¼¼°»áÔ±·þÎñÈ«ÃæÖжÏ ¡£Ö»¹ÜStolichkiÖÜÈý¸´Ô­°ëÊýÃŵêÔËÓª£¬µ«Á½¼ÒÆóÒµÔ±¹¤¾ù±»Ç²É¢£¬ÔÚÏß·þÎñÈÔ´¦Ì±»¾×´Ì¬ ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÕâÁ½¼ÒÒ©µêͬÊôÒ»¼Ò¿Ø¹É¹«Ë¾£¬ÆäÏÖʵ½ÚÔìȨÒò2022ÄêÔ­¹É¶«¡¢Ç°¹ú¶È¶ÅÂíÒéÔ±Ò¶·ò¸ùÄᡤÄá·²µÙÒ®·òÊÜÎ÷·½Ôì²ÃÈöɹÉȨºó£¬ÈÔ´æ¼ä½Ó¹ØÁªÕùÒé ¡£Õâ´Î¹¥»÷²¨¼°ÁìÓò³¬³öÒ½Ò©ÁìÓò ¡£ÄªË¹¿Æ¼ÒÍ¥Ò½ÉúÕïËùÍøÂçͬÈÕ»ã±¨ÍøÂç¹ÊÕÏ£¬»¼ÕßÃÅ»§ÓëԤԼϵͳ̱»¾£¬½öÄÜÏÖ³¡¾ÍÕï ¡£Ö»¹Ü¶íÂÞ˹»¥ÁªÍø¼à¹Ü»ú¹¹Roskomnadzor·ñ¶¨ÊÂÎñÉæ¼°É¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬µ«Î´°ä²¼¾ßÌåÊÖ·¨¼°ÆðÔ´£¬°µÍøÂÛ̳Ôò³öÏÖß³Ôð¹¥»÷"Î¥±³Â·µÂ"µÄÉùÒô£¬°µÊ¾µØÔµÕþÖζ¯»ú ¡£


https://therecord.media/cyberattack-shuts-down-russian-pharmacies


5. ÃÀ¹úÁãÊÛ¾ÞÍ·Dollar TreeÔâÀÕË÷Èí¼þ¹¥»÷


7ÔÂ30ÈÕ£¬ÃÀ¹úÕÛ¿ÛÁãÊÛ¾ÞÍ·Dollar Tree½üÆÚ±»³ÛÃûÀÕË÷Èí¼þÍÅ»ïINC RansomÁÐΪ¹¥»÷Ö¸±ê£¬¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÐû³ÆÒÑ»ñÈ¡Æä³¬¹ý1.2TBµÄÃô¸ÐÊý¾Ý£¬²¢Íþв¹«¿ª ¡£È»¶ø£¬Dollar TreeѸ¿ì»ØÓ¦³Æ£¬ÓйØÖ¸¿Ø½öÉæ¼°2024ÄêÊÕ¹ºµÄ99 Cents OnlyÁ¬ËøµêÒÅÁôϵͳ£¬Ç¿µ÷¹«Ë¾²¢Î´ÊÕ¹º¸ÃÆ·ÅÆµÄÆóҵʵÌå¡¢ÍøÂç»òÊý¾Ý£¬½ö±£Áô²¿ÃÅ·¿µØ²ú×âÁÞȨ£¬ÈκθÉÓÚÆäÖ±½Ó¾íÈëÊý¾Ýй¶µÄÖ¸¿Ø¾ù²»Êôʵ ¡£Õâ´ÎÊÂÎñÔ´ÓÚINC Ransom½«Dollar TreeÁÐÈë°µÍøÐ¹ÃÜÍøÕ¾£¬²¢°ä²¼ÉÙÁ¿Îĵµ½ØÍ¼×÷Ϊ֤¾Ý ¡£Ö»¹ÜĿǰÉÐδ¹«¿ªÆëÈ«Êý¾ÝÑù±¾£¬µ«¸ÃÍÅ»ïµÄ¡°¶à³ÁÀÕË÷¡±Ä£Ê½Í¨³£ÒÔй¶Êý¾ÝΪÍþв£¬ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Èô¹¥»÷Êôʵ£¬Õâ²¢·ÇDollar Tree³õ´ÎÔâ·êÊý¾Ý°²È«ÎÊÌ⣬2023ÄêÆäÔøÒòµÚÈý·½¹©¸øÉÌϵͳÔâÈëÇÖ£¬µ¼ÖÂÔ±¹¤¼°¿Í»§Î´¼ÓÃÜÐÅϢй¶ ¡£Ö»¹ÜDollar TreeÇ¿µ÷Õâ´ÎÊÂÎñÓë×ÔÉíÖ÷ÌâϵͳÎ޹أ¬µ«ÊÕ¹ººóµÄÊý¾ÝÖÎÀí·ì϶ÈÔÒý·¢¹Ø×¢ ¡£


https://cybernews.com/security/dollar-tree-data-breach-claims/


6. ºÚ¿Í»ý¼«ÀûÓÃWordPress AloneÖ÷ÌâÖеĹؼüRCE·ì϶


7ÔÂ30ÈÕ£¬WordPress¸ß¼¶Ö÷ÌâAlone½üÈÕ±»ÆØ´æÔÚδ¾­Éí·ÝÑéÖ¤µÄËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2025-5394£©£¬ÍþвÐÐΪÕßͨ¹ý¸Ã·ì϶ʵÏÖÔ¶³Ì´úÂëÖ´Ðм°Õ¾µãÊÕÊÜ ¡£¾Ý°²È«³§ÉÌWordfenceͳ¼Æ£¬ÆäÒÑÀ¹½Ø³¬¹ý12Íò´ÎÕë¶Ô¸Ã·ì϶µÄ¹¥»÷³¢ÊÔ£¬¹¥»÷ÕßÀûÓÃÖ÷ÌâÖ÷Ì⺯Êý"alone_import_pack_install_plugin()"µÄȱµã£¬Í¨¹ýAJAX½Ó¿Ú½Ó¹ÜÔ¶³ÌURLÉÏ´«¶ñÒâZIP°ü£¬½ø¶øÖ²ÈëWebshell¡¢PHPºóÃÅ»ò´´½¨°µ²ØÖÎÀíÔ¹ØË»§£¬ÉõÖÁ²¿ÊðÆëÈ«ÎļþÖÎÀíÆ÷ÒÔÆëÈ«½ÚÔìÊý¾Ý¿â ¡£Õâ´Î¹¥»÷³öÏÖÏÔÖøÁãÈÕ·ìÏ¶ÌØµã£ºWordfence·¢ÏÖ¹¥»÷»î¶¯ÔçÓÚ¹Ù·½²¹¶¡°ä²¼ÖÁÉÙËÄÌ죬Åú×¢¹¥»÷Õßͨ¹ý¼à¿Ø°æ±¾¸üÐÂÈÕÖ¾ÌáÇ°Ëø¶¨Ö¸±ê ¡£·ì϶ӰÏìAlone 7.8.3¼°ÒÔÉϰ汾£¬¸ÃÖ÷ÌâÖØÒª·þÎñÓڴȱ¯»ú¹¹¡¢·Çµ±¾Ö×éÖ¯µÈ·ÇͶ»úʵÌ壬ÆäÓû§ÈºÌåÌØÊâÐÔ¼Ó¾çÁËÊý¾Ýй¶·çÏÕ ¡£¹¥»÷¼£ÏóÔ̺¬ÐÂÔöÖÎÀíÔ¹ØË»§¡¢¿ÉÒÉZIP/²å¼þÎļþ¼°¶Ô"admin-ajax.php?action=alone_import_pack_install_plugin"õè¾¶µÄÒì³£ÒªÇó ¡£Wordfence³ö¸ñÖ¸³ö£¬À´×ÔËĸöÔ´IPµÄ¹¥»÷Á÷Á¿Õ¼±ÈÁ¦¸ß£¬½¨Òéµ±¼´¹Ø±Õ ¡£


https://www.bleepingcomputer.com/news/security/hackers-actively-exploit-critical-rce-in-wordpress-alone-theme/