µÂ¿ËÈøË¹ÖÝÌdzÇÔâÍøÂç¹¥»÷Ö·þÎñÖжÏ
°ä²¼¹¦·ò 2025-10-131. µÂ¿ËÈøË¹ÖÝÌdzÇÔâÍøÂç¹¥»÷Ö·þÎñÖжÏ
10ÔÂ11ÈÕ£¬µÂ¿ËÈøË¹ÖÝÌdzǹÙÔ±´«µÝ³Æ£¬¸ÃÊÐÔâ·êÍøÂç¹¥»÷µ¼Ö¶àÏîÔÚÏß·þÎñÖжϣ¬Ô̺¬311ÁªÏµÖÐÐÄ¡¢¹«ÓÃÊÂÒµ¼Æ·Ñ¡¢Ðí¿É²é³ÆÌÅż°Ðí¿ÉÖ¤¸¶¿îµÈÖ°ÄÜÅö±Ú¡£Ö»¹Ü¹Ø¼ü»ù´¡ÉèÊ©È羯Ա¡¢Ïû·ÀºÍÒ½ÁÆ·þÎñÈÔͨ¹ý911ά³ÖÔË×÷£¬µ«Õ˵¥Ö§¸¶µÈ²¿ÃÅÔÚÏß·þÎñÒÑÊÜÓ°Ïì¡£Êи®ÒÑÆô¶¯Ó¦¼±»úÔ죬Ϊ·Ç´¹Î£Çé¿öÌṩ±¸ÓÃÁªÏµ·½Ê½£¬²¢½áºÏÖÝ¡¢Áª¹ú·¨Âɲ¿ÃÅ·¢Õ¹µ÷²é£¬³ÁµãÅŲéÄÚ²¿ÍøÂç»ù´¡ÉèÊ©ÊÜËðÇé¿ö¡£ÌdzÇÊÂÎñÔٴζ³ö´¦Ëùµ±¾ÖÔÚÍøÂ簲ȫ·À»¤ÖеĴàÈõÐÔ¡£Ö»¹ÜÊи®Ç¿µ÷¡°¹Ø¼üϵͳδÊÜÓ°Ï족£¬µ«·þÎñÖжÏÒѶԾÓÃñÈÕ³£ÊÂÎñ´¦ÖÃÔì³ÉÄÚÈÝÐÔ¹ÊÕÏ¡£Õâ´ÎÊÂÎñ²¢·Ç¹ÂÀý¡£¾Ýͳ¼Æ£¬2025ÄêÒÔÀ´£¬µÂ¿ËÈøË¹ÖÝ¶àµØÆµ·¢ÍøÂ簲ȫÊÂÎñ£ºÈýÖÜǰ£¬ÓÈÍß¶ûµÏÊй«Á¢Ñ§ÇøÒòÀÕË÷Èí¼þ¹¥»÷±»ÆÈÍ£¿ÎÒ»ÖÜ£¬¡°÷è÷롱ÍÅ»ïÒÑÐû³Æ¶Ô´ËÕÆ¹Ü£»ÂíËþ¸ç´ïÏØ¡¢Ã×Éê¡¢À²®¿Ë¼°°¢±ÈÁֵȳÇÊÐÒà»ã±¨ÀàËÆÊÂÎñ¡£½ñÄê6Ô£¬Öݽ»Í¨²¿ÕË»§ÔâºÚ¿ÍÈëÇÖ£¬½ü30Íò·ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢¼ÝÕÕºÅÂë¡¢³µÅƼ°±£ÏÕÐÅÏ¢µÄ½»Í¨±äÂһ㱨±»·¸·¨ÏÂÔØ£¬Òý·¢¹«¼Ò¶ÔÓ×ÎÒÐÅÏ¢°²È«µÄÓÇÓô¡£
https://therecord.media/houston-suburb-cyberattack-services
2. ºÚ¿ÍÀûÓÃGladinetÎļþ¹²ÏíÈí¼þµÄÁãÈÕ·ì϶
10ÔÂ10ÈÕ£¬½üÈÕ£¬Gladinet¹«Ë¾µÄCentreStackºÍTriofoxÎļþ¹²Ïí¼°Ô¶³Ì½Ó¼û½â¾ö¹æ»®±»ÆØ´æÔÚÑϳÁÁãÈÕ·ì϶CVE-2025-11371£¬¸Ã·ì϶Ϊ±¾µØÎļþÔ̺¬£¨LFI£©·ì϶£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½Ó¼ûϵͳÎļþ¡£Ä¿Ç°ÖÁÉÙÓÐÈý¼ÒÆóÒµÒò¶øÔâ·ê¹¥»÷£¬ÇÒËùÓа汾²úÆ·¾ùÊÜÓ°Ï죬Ô̺¬×îа汾16.7.10368.56560¡£·ì϶ÀûÓÃÁ´ÏÔʾ£¬¹¥»÷ÕßÊ×ÏÈͨ¹ýLFI¶ÁÈ¡Web.configÎļþÌáÈ¡»úеÃÜÔ¿£¬Ëæºó½áºÏ´ËǰÒÑÖªµÄ·´ÐòÁл¯·ì϶CVE-2025-30406£¨Ô´ÓÚÓ²±àÂë»úеÃÜÔ¿£©£¬×îÖÕͨ¹ýViewStateʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£Huntress×êÑÐÈËÔ±ÓÚ9ÔÂ27ÈÕ³õ´Î·¢Ïָ÷ì϶£¬²¢È·ÈÏÍþвÐÐΪÕßÒѳɹ¦ÀûÓô˷ì϶»ñÈ¡»úеÃÜÔ¿²¢Ö´ÐжñÒâ´úÂë¡£Gladinet¹«Ë¾ÒÑÈ·ÈÏ·ì϶´æÔÚ£¬²¢°µÊ¾ÔÚ֪ͨ¿Í»§²Éȡһʱ»º½â´ëÊ©£¬Ö±ÖÁ²¹¶¡°ä²¼¡£CentreStack²úÆ·Ðû³ÆÒѱ»49¸ö¹ú¶ÈµÄÊýǧ¼ÒÆóҵʹÓ㬶øÕâ´ÎÊÂÎñÔٴζ³öÁËÆóÒµ¼¶´æ´¢½â¾ö¹æ»®µÄ°²È«·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/hackers-exploiting-zero-day-in-gladinet-file-sharing-software/
3. Service FinderÖ÷Ìâ¸ßΣ·ì϶Ôâ´ó¹æÄ£ÀûÓÃ
10ÔÂ10ÈÕ£¬Service Finder WordPressÖ÷Ìâ¼°Æä°ó¸¿µÄBookings²å¼þ´æÔÚÑϳÁ°²È«·ì϶CVE-2025-5947£¬¸Ã·ì϶±»ÆÀ·ÖΪ9.8·Ö£¬ÊôÓÚ¸ßΣÉí·ÝÈÏÖ¤ÈÆ¹ý·ì϶¡£¹¥»÷Õß¿ÉÎÞÐèÃÜÂëÖ±½Óͨ¹ýαÔìCookie¼ÙÒâÖÎÀíÔ±µÇ¼£¬½ø¶øÆëÈ«½ÚÔìÍøÕ¾£¬×¢Èë¶ñÒâ´úÂë¡¢½Ù³ÖÁ÷Á¿»ò²¿Êð¶ñÒâÈí¼þ¡£·ì϶ԴÓÚ²å¼þ¶ÔÕË»§Çл»Ö°ÄܵÄÃýÎó´¦Öã¬Î´ÑéÖ¤CookieÊý¾ÝµÄÕæÊµÐÔ£¬µ¼ÖÂËÁÒâÓû§£¨Ô̺¬ÎÞÕË»§Õߣ©¿É¼ÙÒâÖÎÀíÔ±Éí·Ý¡£¸Ã·ì϶ӰÏìËùÓÐ6.0¼°ÒÔϰ汾£¬Ö÷ÌâÊØ»¤·½ÓÚ2025Äê7ÔÂ17ÈÕ°ä²¼6.1°æ±¾½¨¸´²¹¶¡£¬µ«¹¥»÷Õß×Ô8ÔÂ1ÈÕÆðÒÑÌáÒ鳬13,800´ÎÀûÓó¢ÊÔ¡£Ä¿Ç°£¬³¬6000Ãû²É°ì¸ÃÖ÷ÌâµÄ¿Í»§ÖÐÈÔÓдóÁ¿ÍøÕ¾Î´¸üУ¬Ãæ¶Ô³ÖÐø·çÏÕ¡£°²È«¹«Ë¾Wordfenceͨ¹ý·ì϶Éͽð´òËãÐÖúÅû¶Á˸÷ì϶£¬Æä·À»ðǽ¿ÉÀ¹½Ø²¿ÃŹ¥»÷£¨¼ø±ð¶ñÒâCookieÊý¾Ý£©£¬µ«¹Ù·½Ç¿µ÷¸üÐÂÖÁ6.1»ò¸ü¸ß°æ±¾²ÅÊǵ××Ó·ÀÓù´ëÊ©¡£
https://hackread.com/auth-bypass-service-finder-wordpress-plugin-exploit/
4. Stealit¶ñÒâÈí¼þ½èNode.js SEAÖ°ÄÜÒñ±Î´«²¼
10ÔÂ10ÈÕ£¬Fortinet FortiGuard³¢ÊÔÊÒ½üÈÕÖҸ棬һÖÖÃûΪStealitµÄΣÏÕÊý¾ÝÇÔÈ¡¶ñÒâÈí¼þÕýͨ¹ýMaaS£¨¶ñÒâÈí¼þ¼´·þÎñ£©Ä£Ê½»îÔ¾´«²¼¡£¸Ã¶ñÒâÈí¼þÕë¶ÔWindowsÓû§£¬Ñ¡È¡ÖеÈÑϳÁˮƽ¹¥»÷£¬Í¨¹ýNode.jsµÄ"µ¥¿ÉÖ´ÐÐÀûÓ÷¨Ê½£¨SEA£©"Ö°Äܽ«ËùÓжñÒâÎļþ´ò°ü³Éµ¥Ò»·¨Ê½£¬ÎÞÐèԤװNode.js¼´¿ÉÔËÐУ¬ÏÔÖøÌáÉýÒñ±ÎÐÔ¡£Æä´úÂë¾¹ý³Á¶È»ìºÏ²¢Ç¶Èë·´·ÖÎö²é³£¬¿É×Ô¶¯¶ã±Üµ÷ÊÔÆ÷¡¢Ðé¹¹»·¾³µÈ°²È«¼ì²â¡£StealitµÄÖ÷ÌâÖ°ÄÜÔ̺¬Ô¶³ÌÎļþÌáÈ¡¡¢ÀÕË÷Èí¼þ²¿Êð¡¢ÊµÊ±ÆÁÄ»¼à¿Ø¡¢ÍøÂçÉãÏñÍ·½ÚÔ켰ϵͳÖÎÀí£¬²¢¿ÉÍÆËÍÐéα¾¯±¨ÐÅÏ¢¡£¹¥»÷Õß½«Æä°üװΪ"רҵÊý¾ÝÌáÈ¡½â¾ö¹æ»®"£¬Í¨¹ý¶©ÔÄ´òËãÊÛÂô£¬Windows°æ¶¨¼ÛÔ¼500ÃÀÔª£¬Android°æ¸ß´ï2000ÃÀÔª¡£ÎªÌÓ±Ü×·×Ù£¬ÆäC2·þÎñÆ÷ÒÑ´Óstealituptaded.lolǨáãÖÁiloveanimals.shop¡£´«²¼Õ½Êõ·½Ã棬¶ñÒâÈí¼þ¼Ù×°³ÉÈȵãÓÎÏ·ºÍVPN×°Ö÷¨Ê½£¬Í¨¹ýMediafire¡¢DiscordµÈƽ̨·Ö·¢¡£ÓÎÏ·Íæ¼ÒÒòƵÈÔ×°ÖõÚÈý·½Èí¼þ³ÉÎªÖØÒªÖ¸±êȺÌå¡£
https://hackread.com/stealit-malware-node-js-fake-game-vpn-installers/
5. ŦԼÖݾ¯Ãñ½áºÏ½ø¹¥¡°Í¨ÕÍÍË˰¡±´¹µöÚ¿Æ
10ÔÂ12ÈÕ£¬½üÆÚ£¬Å¦Ô¼ÖݲúÉúһ·ÒÔ¡°Í¨»õÅòÕÍÍ˿Ϊ»Ï×ӵĶÌÐÅÍøÂç´¹µöÚ¿Æ£¬Ö¸±êֱָŦԼ¾ÓÃñ¡£Ú¿Æ·Ö×Ó¼ÙÒâŦԼ˰ÎñºÍ²ÆÕþ²¿£¬Í¨¹ý¶ÌÐÅ¡¢Óʼþ¼°Ö±ÓÊ·½Ê½£¬»Ñ³ÆÌṩ¡°Í¨ÕÍÍ˿²¢ÓÕµ¼Êܺ¦Õßµã»÷Á´½ÓÊäÈëÓ×ÎÒÐÅÏ¢¡£¸ÃÚ¿ÆÀûÓÃÁËŦԼÖÝÕæÊµ´æÔÚµÄͨÕÍÍË˰Õþ²ß£¬ÇкÏǰÌáµÄÄÉ˰ÈËÎÞÐèÉêÇë¼´¿É×Ô¶¯ÊÕµ½ÍË˰֧Ʊ£¬Õþ²ßº¸ÇÒÑÌá½»ÄÉ˰É걨¡¢´ïµ½ÊÕÈëÃż÷ÇÒδ±»É걨ΪÊÜ·öÑøÈ˵ľÓÃñ¡£Ú¿Æ¶ÌÐÅÐû³Æ¡°ÍË¿îÒªÇóÒÑ´¦Öò¢ºË×¼¡±£¬ÒªÇóÊÕ¼þÈËÔÚ2025Äê9ÔÂ29ÈÕǰÌá½»¸¶¿îÐÅÏ¢£¬²»È»½«ÓÀԶʧÂäÍË¿î×ʸñ£¬²¢Ô®Òý¡¶Å¦Ô¼¶©ÕýÂÉÀý¡·µÚ5747.11Ìõʩѹ¡£µã»÷Á´½Óºó£¬Êܺ¦Õ߻ᱻÊèµ¼ÖÁαÔìµÄ¹Ù·½Ò³Ã棬±»ÒªÇóÊäÈëÐÕÃû¡¢µØÖ·¡¢µç»°¡¢Éç»á°²È«ºÅÂëµÈÃô¸ÐÐÅÏ¢£¬ÕâЩÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇԺͽðÈÚÚ¿Æ¡£Å¦Ô¼Öݵ±¾ÖѸ¿ì²ÉÈ¡Ðж¯¡£9ÔÂ28ÈÕ£¬Öݳ¤¿Î÷¡¤»ô³þ¶û°ì¹«ÊÒ°ä²¼ÖҸ棬ǿµ÷¡°³ý×ʸñÒªÇó±í£¬Å¦Ô¼ÈËÎÞÐè×öÈκÎʼ´¿É»ñµÃÍË˰֧Ʊ¡±£¬²¢Ã÷È·¡°Ë°Îñ²¿ÃŲ»»áͨ¹ýµç»°¡¢¶ÌÐÅ»òÓʼþË÷ÒªÓ×ÎÒÐÅÏ¢¡±¡£Å¦Ô¼Ë°ÎñºÍ²ÆÕþ²¿Í¬²½ÌáÐÑ£¬»ú¹¹¾ø²»»áͨ¹ýµç×ÓͨѶÁªÏµÄÉ˰ÈË´¦ÖÃÍË˰ÊÂÒË¡£
https://www.bleepingcomputer.com/news/security/fake-inflation-refund-texts-target-new-yorkers-in-new-scam/
6. Î÷°àÑÀµ·»Ù¿ç¹úÍøÂç·¸×ïÆ½Ì¨GXC Team
10ÔÂ11ÈÕ£¬Î÷°àÑÀ¹úÃñ¾¯ÎÀ¶Ó½üÆÚ³É¹¦·ÛËéÃûΪ¡°GXC Team¡±µÄ¿ç¹úÍøÂç·¸×ï×éÖ¯£¬¿ÛÁôÆä25Ëê°ÍÎ÷¼®Í·×Ó¡°GoogleXcoder¡±¼°¶àÃûͬ»ï¡£¸Ã×éÖ¯ÔËÓª¡°·¸×ï¼´·þÎñ¡±£¨CaaS£©Æ½Ì¨£¬Í¨¹ýTelegramºÍ¶íÓïºÚ¿ÍÂÛ̳ÏòÈ«Çò¿Í»§Ìṩ¶¨Ôì»¯ÍøÂç¹¥»÷¹¤¾ß£¬Ô̺¬ÈËΪÖÇÄÜ´¹µö¹¤¾ß°ü¡¢Android¶ñÒâÈí¼þ¼°ÓïÒôڿƹ¤¾ß£¬ÐγÉרҵ¼¶¸ßÊÕÒæ·¸×ïÉú̬¡£¾Ýµ÷²é£¬GXC TeamÖØÒªÕë¶ÔÎ÷°àÑÀ¡¢Ë¹Âå·¥¿Ë¡¢Ó¢¹ú¡¢ÃÀ¹úºÍ°ÍÎ÷µÄÒøÐÓ×¢ÔËÊä¼°µç×ÓÉÌÇóʵÌåÖ´Ðй¥»÷¡£Æä´¹µö¹¤¾ß°ü¾«×¼¸´ÔìÊýÊ®¼Ò¹ú¼Ê»ú¹¹ÍøÕ¾£¬Ö§³ÖÖÁÉÙ250¸ö´¹µöÍøÕ¾ÔËÐУ»¿ª·¢µÄ9ÖÖAndroid¶ñÒâÈí¼þ¿ÉÀ¹½Ø¶ÌÐźÍÒ»´ÎÐÔÃÜÂ루OTP£©£¬ÓÃÓÚ½Ù³ÖÕË»§¼°ÑéÖ¤Ú²ÆÂòÂô¡£¸Ã×éÖ¯»¹Ìṩ¼¼ÊõÖ§³ÖºÍ»î¶¯¶¨Ôì·þÎñ£¬ÐÎ³ÉÆëÈ«·¸×ï²úÒµÁ´¡£5ÔÂ20ÈÕ£¬Î÷°àÑÀ¾¯·½ÔÚ¿²Ëþ²¼ÀïÑÇ¡¢°ÍÈûÂÞÄÇµÈ¶àµØ·¢Õ¹Ðµ÷Í»»÷ËѲ飬²é»ñÔ̺¬´¹µö¹¤¾ß°üÔ´´úÂë¡¢¿Í»§Í¨Ñ¶¼Í¼¼°²ÆÕþÊý¾ÝµÄµç×ÓÉ豸£¬×·»Ø±»µÁ¼ÓÃÜÇ®±Ò£¬²¢¹Ø¹ØÃûΪ¡°´Ó׿ďÄÇÀï͵×ßËùÓÓ×±µÄÚ¿ÆÍƹãTelegramƵ·¡£Õâ´ÎÐж¯»ùÓÚ¶Ô¡°GoogleXcoder¡±É豸¼°¼ÓÃÜÇ®±ÒÂòÂôµÄ³ÖÐøÒ»Äê¶àµÄȡ֤·ÖÎö£¬³É¹¦³Á½¨·¸×ïÍøÂç²¢Ëø¶¨6Ãû¹ØÁªÈËÔ±¡£
https://www.bleepingcomputer.com/news/security/spain-dismantles-gxc-team-cybercrime-syndicate-arrests-leader/


¾©¹«Íø°²±¸11010802024551ºÅ