ÀÕË÷Èí¼þÍÅ»ïÈôºÎ¼ÓÃÜÄÚ»ª´ïÖݵ±¾Öϵͳ
°ä²¼¹¦·ò 2025-11-101. ÀÕË÷Èí¼þÍÅ»ïÈôºÎ¼ÓÃÜÄÚ»ª´ïÖݵ±¾Öϵͳ
11ÔÂ6ÈÕ£¬ÄÚ»ª´ïÖÝ8ÔÂÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬Ó°Ïì60Óà¸öµ±¾Ö»ú¹¹£¬µ¼ÖÂÍøÕ¾¡¢µç»°ÏµÍ³¼°ÔÚÏ߯½Ì¨Öжϡ£Öݵ±¾Ö°ä²¼µÄ¾ßÌå¹ýºó»ã±¨ÆëÈ«Åû¶Á˹¥»÷ȫò£ººÚ¿Í×Ô5ÔÂ14ÈÕÆðͨ¹ý¶ñÒâ¸æ°×ÓÕµ¼Öݵ±¾Ö¹ÍÔ±ÏÂÔØ¼Ù×°³ÉϵͳÖÎÀí¹¤¾ß£¨ÈçWinSCP¡¢PuTTYµÈ£©µÄľÂí·¨Ê½£¬ÔÚÉ豸²¿ÊðºóÃÅ£»8ÔÂ24ÈÕÕýʽ²¿ÊðÀÕË÷Èí¼þǰ£¬ÒÑͨ¹ýÔ¶³Ì¼à¿ØÈí¼þ¡¢¼ÓÃÜËí·¹¤¾ßºáÏòÉøÈ룬ÇÔÈ¡26¸öÕË»§Í´´¦²¢¶Ï¸ùÊÂÎñÈÕÖ¾ÒÔ¸²¸ÇÐÐ×Ù¡£¹¥»÷Õß×îÖÕɾ³ý±¸·Ý¾í¡¢Åú¸ÄÐé¹¹»¯ÖÎÀí·þÎñÆ÷°²È«ÉèÖã¬ÔÚÍйÜÖÝÐé¹¹»úµÄËùÓзþÎñÆ÷Éϲ¿ÊðÀÕË÷Èí¼þ£¬µ¼ÖÂÈ«ÖÝ·þÎṉ̃»¾¡£Ãæ¶ÔΣ»ú£¬ÄÚ»ª´ïÖݻؾøÖ§¸¶Êê½ð£¬ÒÀ¸½50ÃûITÈËÔ±¼Ó°à4,212Ó×ʱ£¨¹¤×ʳɱ¾25.9ÍòÃÀÔª£©¼°±í²¿¹©¸øÉÌÖ§³Ö£¨×ÜÓöÈÔ¼130ÍòÃÀÔª£©£¬28ÌìÄÚ¸´Ô90%ÊÜÓ°ÏìÊý¾Ý¼°·þÎñ¡£Óë³ß¶È³Ð°üÉÌ·ÑÂÊÏà±È£¬´Ë¾Ù½Ú¼óÔ¼47.8ÍòÃÀÔª¡£ÊÂÎñÏìÓ¦ÆÚ¼ä£¬Î¢ÈíDART¡¢MandiantµÈ¹©¸øÉÌÌṩͳһ֧³Ö¡¢·¨Ö¤µ÷²é¡¢¹¤³Ì¸´ÔµÈ·þÎñ£¬³É±¾Ã÷ϸͨÃ÷¹«¿ª¡£
https://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/
2. ¶íSandwormºÚ¿Í×éÖ¯¶ÔÎڹؼüÐÐÒµ·¢ÆðÊý¾Ý²Á³ý¹¥»÷
11ÔÂ6ÈÕ£¬½üÆÚ£¬¶íÂÞ˹¹ú¶ÈÖ§³ÖµÄºÚ¿Í×éÖ¯Sandworm£¨±ðÃûAPT44£©¶ÔÎÚ¿ËÀ¼½ÌÓý¡¢µ±¾ÐİÁ¸Ê³²¿ÃÅÌáÒé¶àÂÖÊý¾Ý²Á³ý¶ñÒâÈí¼þ¹¥»÷£¬Ò»Á¬Æä×Ô2022ÄêÒÔÀ´Õë¶Ô¸Ã¹úµÄ·ÛËéÐÔÐж¯¡£ÍøÂ簲ȫ¹«Ë¾ESETÔÚ×îл㱨ÖÐÖ¸³ö£¬ÕâЩ¹¥»÷¼¯ÖÐÔÚ6ÔºÍ9Ô£¬Ö¸±êº¸Çµ±¾Ö¡¢ÄÜÔ´¡¢ÎïÁ÷¼°Á¸Ê³ÐÐÒµ£¬ÆäÖÐÁ¸Ê³²¿ÃÅ×÷ΪÎÚ¿ËÀ¼Õ½Ê±ÖØÒªÊÕÈëÆðÔ´³ÉΪн¹µã¡£Êý¾Ý²Á³ý¶ñÒâÈí¼þÈçPathWiper¡¢HermeticWiperµÈͨ¹ý·ÛËé»òɾ³ýÎļþ¡¢´ÅÅÌ·ÖÇø¼°Ö÷Êèµ¼¼Í¼ʵÏÖ³¹µ×Ïú»Ù£¬ÓëÀÕË÷Èí¼þ·ÖÆç£¬Æä´¿ÕýÒÔ·ÛËéΪÖ÷ÕÅ£¬µ¼ÖÂϵͳÄÑÒÔ¸´Ô¡£Õâ´Î¹¥»÷ÖУ¬Sandworm²¿ÊðÁË¡°ZeroLot¡±ºÍ¡°Sting¡±µÈ±äÖÖ£¬ÆäÖÓ×°Sting¡±Í¨¹ýÒÔÐÙÑÀÀû´«Í³²Ëëȶ¨ÃûµÄWindows¹¤×÷Ö´ÐУ¬Í¹ÏÔ¹¥»÷µÄÒñ±ÎÐÔ¡£³õʼ½Ó¼ûȨÏÞ¶àÓÉUAC-0099£¨×Ô2023ÄêÆð»îÔ¾µÄÍþвÐÐΪÌ壩»ñÈ¡£¬Ëæºó×ªÒÆ¸øSandworm²¿Êð²Á³ýÆ÷¡£Á¸Ê³ÐÐÒµ³õ´Î³ÉÎªÖØÒª¹¥»÷Ö¸±ê£¬·´Ó³³ö¹¥»÷ÕßÊÔͼ¼õÈõÎÚ¿ËÀ¼Õ½Ê±¾¼ÃµÄÕ½ÊõÒâͼ¡£
https://www.bleepingcomputer.com/news/security/sandworm-hackers-use-data-wipers-to-disrupt-ukraines-grain-sector/
3. Î÷°àÑÀKISS-FMÔâRhysidaÀÕË÷Èí¼þ¹¥»÷
11ÔÂ6ÈÕ£¬Î÷°àÑÀÕ¼ÓаÙÍòÌý¶àµÄÈȵã¹ã²¥µç̨KISS-FMÔâ·êÓë¶íÂÞ˹¹ØÁªµÄRhysidaÀÕË÷Èí¼þÍÅ»ïÏ®»÷¡£¸ÃÍÅ»ïÔÚ°µÍøÅÄÂô¾Ý³ÆÇÔÈ¡µÄÊý¾Ý£¬ÒªÇóÖ§¸¶3¸ö±ÈÌØ±Ò£¨Ô¼30ÍòÃÀÔª£©Êê½ð£¬²¢É趨7ÌìÆÚÏÞ£¬²»È»½«ÏúÊÛ»òй¶Êý¾Ý¡£RhysidaÒÔ¡°Ë«³ÁÀÕË÷¡±Õ½ÊõÎÅÃû£¬²»½öÓÃÀÕË÷Èí¼þËø¶¨Êý¾Ý£¬»¹Íþвй¶ÒÔʩѹ¸¶¿î¡£¹¥»÷ÕßÌṩµÄ½ØÍ¼ÏÔʾ£¬±»µÁÊý¾Ý¿ÉÄÜÔ̺¬¹Û¶àÆÀ·Ö¼Í¼¡¢ÓëÎ÷°àÑÀÊý×Ö»¯×ªÐͲ¿»¥»»µÄÎļþ¼°·¢Æ±£¬µ«Ô±¹¤Ó×ÎÒÊý¾Ýй¶Çé¿öÉÐδÃ÷È·¡£Õâ´ÎÊÂÎñÒÑÒý·¢¶Ô¹«¼ÒÐÅÀµ¶È½µÂä¡¢GDPRºÏ¹æ·çÏÕ¼°Ã³Ò×¹ØÏµÇÖÈŵÄÓÇÓô¡£RhysidaÍÅ»ï×Ô2023Äê5Ô³ÉÁ¢ÒÔÀ´£¬ÒÑÐû³Æ¹¥»÷236¸öÖ¸±ê£¬¸²¸Ç½ÌÓý¡¢Ò½ÁÆ¡¢Ôì×÷Òµ¡¢´¦Ëùµ±¾ÖµÈÁìÓò¡£Æä¹¥»÷¼¿Á©Ô̺¬ÀûÓÃMicrosoft Teams¡¢ZoomºÍPuttyƽ̨½øÐжñÒâ¸æ°×ÍøÂç´¹µö£¬Ï°È¾É豸²¢ÇÔÈ¡Êý¾Ý¡£
https://cybernews.com/security/ransomware-kissfm-spain-radio/
4. GlassWorm¶ñÒâÈí¼þ¾íÍÁ³ÁÀ´£¬OpenVSXÔÙÔâ¹¥»÷
11ÔÂ8ÈÕ£¬ÔøÓ°ÏìOpenVSXºÍVisual Studio CodeÀûÓÃÊг¡µÄGlassWorm¶ñÒâÈí¼þ»î¶¯ÔÙ¶È»îÔ¾£¬´øÀ´Èý¿îÐÂVSCodeÀ©´ó·¨Ê½£¬ÀÛ¼ÆÏÂÔØÁ¿Òѳ¬10,000´Î¡£¸Ã¶ñÒâÈí¼þͨ¹ýSolanaÂòÂô»ñÈ¡ÓÐÐ§ÔØºÉ£¬Ö¸±êÖ±Ö¸GitHub¡¢NPM¼°OpenVSXÕË»§Í´´¦£¬ÒÔ¼°49¸öÀ©´ó·¨Ê½µÄ¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý¡£ÆäÖ÷Ìâ¹¥»÷¼¿Á©ÊÇÀûÓò»Ë½¼ûµÄUnicode×Ö·ûʵÏÖ¶ñÒâ²Ù×÷£¬ÕâÖÖ»ìºÏ¼¼ÇÉÈÔÄÜÈÆ¹ýOpenVSXÐÂÒýÈëµÄ·ÀÓù»úÔì¡£Õâ´Î¹¥»÷ÖУ¬GlassWormͨ¹ýOpenVSXƽ̨ÉÏ´«µÄÈý¿îÀ©´ó±ðÀëΪ£ºai-driven-dev.ai-driven-dev£¨3,400´ÎÏÂÔØ£©¡¢adhamu.history-in-sublime-merge£¨4,000´ÎÏÂÔØ£©¡¢yasuyuky.transient-emacs£¨2,400´ÎÏÂÔØ£©¡£¾Ý°²È«»ú¹¹Koi Security×·×Ù£¬¹¥»÷ÕßʹÓÃÒ»ÑùµÄ»ù´¡ÉèÊ©£¬µ«¸üÐÂÁ˺ÅÁîÓë½ÚÔ죨C2£©¶ËµãºÍSolanaÂòÂôÕ½Êõ£¬²¢ÒÑתÏòGitHubºóÓֻعéOpenVSX£¬Åú×¢ÆäÓÐÒâÔÚ¶àÆ½Ì¨³ÖÐøÔËÓª¡£½ØÖÁ·¢¸å£¬Èý¿îЯ´øGlassWormÓÐÐ§ÔØºÉµÄÀ©´óÈÔ¿É´ÓOpenVSXÏÂÔØ£¬°²È«×¨¼ÒÖÒ¸æÓû§Ð辯Ìè´ËÀàÒñ±Î¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/
5. NuGet¶ñÒâÈí¼þ°üÂñ·ü¶àÄ꣬2027ÄêÆð¼¤»î·ÛËéÐÔ¹¥»÷
11ÔÂ7ÈÕ£¬´úÂ밲ȫ¹«Ë¾Socket×êÑÐÈËÔ±ÔÚNuGet¿ªÔ´°üÖÎÀíÆ½Ì¨·¢Ï־ŸöÓÉ¿ª·¢Õß"shanhai666"°ä²¼µÄ¶ñÒâÈí¼þ°ü£¬ÕâЩÈí¼þ°ü±í±í¾ß±¸ºÏ·¨Ö°ÄÜ£¬ÊµÔòÔ̺¬Òñ±ÎµÄ·ÛËéÐÔÓÐÐ§ÔØºÉ£¬´òËãÓÚ2027Äê8ÔÂÖÁ2028Äê11Ô¼伤»î¡£¸Ã¶ñÒâ´úÂëѡȡ¸ÅÂÊ´¥·¢»úÔ죬ÐèÂú×ãÌØ¶¨ÈÕÆÚǰÌá¼°Ëæ»úÊýãÐÖµ£¨´óÓÚ80ʱ´¥·¢£©£¬Í¨¹ýC#À©´ó²½Ö轫¶ñÒâÂ߼ͨÃ÷×¢ÈëÊý¾Ý¿âºÍPLC²Ù×÷Á÷³Ì¡£Õâ´Î¹¥»÷Õë¶ÔÈý´óÖ÷Á÷Êý¾Ý¿â£¨SQL Server¡¢PostgreSQL¡¢SQLite£©¼°Î÷ÃÅ×ÓS7¹¤Òµ½ÚÔìÉ豸£¬ÓÈÆäÒÔ¼Ù×°³ÉºÏ·¨Sharp7¿âµÄ"Sharp7Extend"Èí¼þ°ü×îΪΣÏÕ¡£¸Ã°üͨ¹ý¸½¼Ó"Extend"ºó׺ÓÕµ¼¿ª·¢ÕßÎóÏÂÔØ£¬µ±´¥·¢Ç°ÌáÂú×ãʱ£¬»áÒÔ20%¸ÅÂʵ±¼´ÖÕÖ¹Ö÷»ú¹ý³Ì£¬µ¼ÖÂPLC¿Í»§¶Ë²Ù×÷Öжϣ»»òͨ¹ýÑÓ³¤Ð´Èë»úÔ죨30-90·ÖÖÓ£©Ê¹PLCдÈë²Ù×÷ÓÐ80%¸ÅÂʰܻµ£¬Òý·¢Ö´ÐÐÆ÷ºÅÁîÃÔʧ¡¢°²ÕûϵͳʧЧµÈÑϳÁºó¹û¡£½ØÖÁÆØ¹âʱ£¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØ½ü9500´Î£¬Éæ¼°SqlUnicorn.Core¡¢SQLite´æ´¢¿âµÈ¾Å¸ö¶ñÒâ°ü¡£Ä¿Ç°£¬NuGetÒÑϼÜÓйØÈí¼þ°ü£¬µ«Ç±ÔÚÓ°ÏìÁìÓò¿í·º¡£
https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-drop-disruptive-time-bombs/
6. ÈýÐÇÁãÈÕ·ì϶ÔâÀûÓã¬LandFall¼äµýÈí¼þ¶¨Ïò¹¥»÷Öж«Óû§
11ÔÂ7ÈÕ£¬ÍþвÐÐΪÕß×Ô2024Äê7ÔÂÆðÀûÓÃÈýÐÇAndroidͼÏñ´¦ÖÿâÖеÄÁãÈÕ·ì϶CVE-2025-21042£¬Í¨¹ýWhatsApp·¢ËͶñÒâDNGÌåʽͼÏñÎļþ£¬²¿ÊðÃûΪ"LandFall"µÄ¼äµýÈí¼þ£¬¶¨Ïò¹¥»÷Öж«µØÓòÌØ¶¨ÈýÐÇGalaxyÓû§¡£¸Ã·ì϶Ϊlibimagecodec.quram.soÎļþÖеÄÔ½½çдÈë·ì϶£¬ÑϳÁ¼¶±ð´ï"ÑϳÁ"£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£Ö»¹ÜÈýÐÇÓÚ2025Äê4Ô½¨¸´´Ë·ì϶£¬µ«¹¥»÷»î¶¯ÒѳÖÐøÊýÔ£¬Ó°ÏìGalaxy S22¡¢S23¡¢S24¡¢Z Fold 4¼°Z Flip 4µÈÆì½¢»úÐÍ¡£LandFall¼äµýÈí¼þѡȡ˫³Á¼¼Êõ×é¼þ£º¼ÓÔØÆ÷b.soÕÆ¹Ü¼ìË÷ºÍ¼ÓÔØÆäËûÄ£¿é£¬SELinuxÕ½Êõ°Ñ³ÖÆ÷l.soÔòÅú¸ÄÉ豸°²È«ÉèÖÃÒÔÌáÉýȨÏÞ²¢³ÉÁ¢ÓƾÃÐÔ¡£¸ÃÈí¼þ¿É»ùÓÚÓ²¼þºÍSIM ID£¨ÈçIMEI¡¢IMSI£©¶ÔÉ豸½øÐÐÖ¸ÎÆ¼ø±ð£¬²¢¾ß±¸Âó¿Ë·ç¹àÒô¡¢Í¨»°¹àÒô¡¢µØÎ»×·×Ù¡¢½Ó¼ûÕÕÆ¬/ÁªÏµÈË/¶ÌÐÅ/ͨ»°¼Í¼/Îļþ¼°ä¯ÀÀº¹ÇàµÈ¼äµýÖ°ÄÜ£¬Í¬Ê±Ö§³ÖÄ£¿éÖ´ÐÓ×¢ÓÆ¾Ã»¯¡¢¼ì²âÌӱܺͱ£»¤Èƹý¡£¹¥»÷õè¾¶ÏÔʾ£¬¶ñÒâDNGÎļþĩβ¸½¼ÓZIPѹËõ°ü£¬Í¨¹ýWhatsApp´«²¼¡£×êÑÐÈËÔ±·ÖÎö·¢ÏÖ£¬ÒÁÀ¿Ë¡¢ÒÁÀÊ¡¢ÍÁ¶úÆäºÍĦÂå¸çΪDZÔÚÖ¸±ê¹ú¶È¡£
https://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/


¾©¹«Íø°²±¸11010802024551ºÅ