CISAÖÒ¸æOracle¸ßΣ·ì϶Õý±»»ý¼«ÀûÓÃ
°ä²¼¹¦·ò 2025-11-251. CISAÖÒ¸æOracle¸ßΣ·ì϶Õý±»»ý¼«ÀûÓÃ
11ÔÂ21ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼ÑϳÁÖҸ棬ҪÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹±ØÐëÔÚ2025Äê12ÔÂ12ÈÕǰ½¨¸´Oracle Identity ManagerµÄCVE-2025-61757·ì϶¡£¸Ã·ì϶±»×·×ÙΪ¡°ÁãÈÕ·ì϶¡±£¬Òѱ»ÏÖʵÓÃÓÚ¹¥»÷£¬´ºÁª¹úÆóÒµ×é³É³Á´ó·çÏÕ¡£CVE-2025-61757ÊÇOracle Identity Manager REST APIÖдæÔÚµÄÉí·ÝÑé֤ǰԶ³Ì´úÂëÖ´Ðзì϶£¬ÓÉSearchlight Cyber·ÖÎöʦAdam KuesºÍShubham Shahflaw·¢ÏÖ²¢Åû¶¡£·ì϶ԴÓÚ¹¥»÷Õß¿Éͨ¹ýÔÚURLõè¾¶ÖÐÔö³¤¡°--public-access¡±»òÀàËÆ²ÎÊý£¬ºýŪ°²È«¹ýÂËÆ÷½«Êܱ£»¤¶ËµãÊÓΪ¹«¿ª¿É½Ó¼û£¬´Ó¶øÈƹýÉí·ÝÑéÖ¤Ö±½Ó½Ó¼ûGroovy¾ç±¾±àÒë¶Ëµã¡£¹¥»÷Õß¿ÉÀûÓÃGroovyµÄ×¢½â´¦ÖÃÖ°ÄÜ£¬ÔÚ±àÒëʱעÈë¶ñÒâ´úÂëʵÏÖÔ¶³ÌÖ´ÐУ¬ÎÞÐèÈκÎÉí·ÝÑéÖ¤¡£OracleÒÑÓÚ2025Äê10ÔÂ21ÈÕ°ä²¼°²È«¸üн¨¸´¸Ã·ì϶£¬µ«CISAÇ¿µ÷£¬¸Ã·ì϶Òò¼¼ÊõÃż÷µÍ¡¢ÀûÓõ¥Ò»£¬¼«Ò×±»ÍþвÐÐΪÕß¼±¾ç¸´ÔìÀûÓá£
https://www.bleepingcomputer.com/news/security/cisa-warns-oracle-identity-manager-rce-flaw-is-being-actively-exploited/
2. ¶íÓйع¥»÷½è3DÊг¡´«StealC V2ÇÔÃÜÈí¼þ
11ÔÂ24ÈÕ£¬Óë¶íÂÞ˹ÓйصÄÍøÂç¹¥»÷»î¶¯Õýͨ¹ýCGTraderµÈ3DÄ£ÐÍÊг¡´«²¼StealC V2ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¹¥»÷ÕßÀûÓÃBlender¿ªÔ´3DÈí¼þ¸öÐÔ£¬½«¶ñÒâPython´úÂëǶÈë.blendÎļþÖС£µ±Óû§ÆôÓÃBlenderµÄ×Ô¶¯ÔËÐÐÖ°ÄÜʱ£¬´ò¿ªº¬¶ñÒâ¾ç±¾µÄ½ÇÉ«°ó¶¨Îļþ»á´¥·¢×Ô¶¯¼ÓÔØ£¬¸Ã¾ç±¾Í¨¹ýCloudflare WorkersÓò»ñÈ¡¶ñÒâÈí¼þ¼ÓÔØÆ÷£¬½ø¶øÏÂÔØPowerShell¾ç±¾£¬×îÖÕ´Ó¹¥»÷Õß½ÚÔìµÄIPµØÖ·¼ìË÷Á½¸öZIP´æµµ¡£ÕâЩѹËõÎļþ½âѹÖÁ%TEMP%Îļþ¼Ð£¬²¢ÔÚÆô¶¯Ä¿Â¼¸éÖÃLNKÎļþʵÏÖÓÆ¾Ã»¯£¬Í¬Ê±²¿ÊðStealCÖ÷ÇÔÈ¡Æ÷¼°¸¨ÖúPythonÇÔÈ¡Æ÷ÐγÉÈßÓ౸·Ý¡£Morphisec¹«Ë¾Ö¸³ö£¬±¾´Î¹¥»÷ʹÓõÄStealCΪ½ñÄêÔçЩʱ³½Zscaler·ÖÎöµÄµÚ¶þ¸öÖØÒª°æ±¾µÄ×îбäÖÖ¡£Ð°æStealCÀ©´óÁËÊý¾ÝÇÔÈ¡ÄÜÁ¦£¬Ö§³Ö´Ó23ÖÖÒÔÉÏä¯ÀÀÆ÷¡¢100Óà¸ö¼ÓÃÜÇ®±ÒÇ®°üÀ©´ó/ÀûÓá¢Telegram¡¢DiscordµÈͨѶ¹¤¾ß¡¢VPN¼°Óʼþ¿Í»§¶ËÇÔÈ¡Êý¾Ý£¬²¢½¨Éè¸üеÄUACÈÆ¹ý»úÔì¡£
https://www.bleepingcomputer.com/news/security/malicious-blender-model-files-deliver-stealc-infostealing-malware/
3. ClickFix¹¥»÷ÀûÓÃͼÏñÒþдÊõ´«²¼¶ñÒâÈí¼þ
11ÔÂ24ÈÕ£¬½üÆÚ£¬×êÑÐÈËÔ±·¢ÏÖClickFix¹¥»÷³öÏÖбäÖÖ£¬¹¥»÷Õßͨ¹ýÕæÇеÄWindows¸üж¯»ºÍͼÏñÒþдÊõÔÚÈ«ÆÁä¯ÀÀÆ÷Ò³ÃæÖ´ÐÐÉç»á¹¤³Ì¹¥»÷¡£¸Ã¹¥»÷×Ô10ÔÂ1ÈÕÆð»îÔ¾£¬ÒÔʵÏÖ"¹Ø¼ü°²È«¸üÐÂ"»ò"ÈËΪÑéÖ¤"Ϊµö¶ü£¬ÓÕµ¼Óû§ÔÚWindowsºÅÁîÌáÐÑ·ûÖÐÕ³Ìù²¢Ö´Ðй¥»÷Õßͨ¹ýJavaScript×Ô¶¯¸´Ôìµ½¼ôÌù°åµÄ¶ñÒâºÅÁбäÖÖѡȡÏȽøÒþд¼¼Êõ£¬½«¶ñÒâÈí¼þÓÐÐ§ÔØºÉ±àÂëÓÚPNGͼÏñµÄÏñËØÊý¾ÝÖУ¬Í¨¹ýÌØ¶¨É«²Êͨ·ÔÚÄÚ´æÖгÁ½¨²¢½âÃÜ¡£¹¥»÷Á÷³ÌÔ̺¬¶à½×¶ÎÖ´ÐУºÊ×ÏÈʹÓÃmshtaÔÉú¶þ½øÔìÎļþÖ´ÐжñÒâJS´úÂë£¬Ëæºóͨ¹ýPowerShellºÍ.NET·¨Ê½¼¯´Ó¼ÓÃÜͼÏñÖÐÌáÈ¡shellcode¡£Stego LoaderµÄÇåµ¥×ÊÔ´ÖÐÔ̺¬AES¼ÓÃܵÄblob£¬ÐÔÖÊÊÇǶÈëPNGÎļþµÄshellcode£¬Ðèͨ¹ý×Ô½ç˵C#´úÂë³Á½¨¡£ÍþвÐÐΪÕß»¹Ñ¡È¡¶¯Ì¬¶ã±ÜÕ½Êõ"ctrampoline"£¬Í¨¹ýÈë¿Úµãº¯ÊýŲÓÃÍò¸ö¿Õº¯Êý×ÌÈÅ·ÖÎö¡£
https://www.bleepingcomputer.com/news/security/clickfix-attack-uses-fake-windows-update-screen-to-push-malware/
4. SitusAMCÊý¾Ýй¶ÊÂÎñ²¨¼°¶¥¼¶ÒøÐпͻ§
11ÔÂ24ÈÕ£¬·¿µØ²úÈÚ×Ê·þÎñ¾ÞÍ·SitusAMCÓÚ2025Äê11ÔÂ12ÈÕ·¢ÏÖÊý¾Ýй¶ÊÂÎñ£¬¸Ã¹«Ë¾Îª»¨Æì¼¯ÍÅ¡¢Ä¦¸ùÊ¿µ¤Àû¡¢Ä¦¸ù´óͨµÈ1500¼Ò¿Í»§ÌṩµÖѺ´û¿î·¢·Å¡¢·þÎñ¼°ºÏ¹æµÈºó¶ÜÔËÓªÖ§³Ö£¬ÄêÓªÊÕÔ¼10ÒÚÃÀÔª¡£¾³õ´ëÊ©²éÈ·ÈÏ£¬Õâ´ÎÊÂÎñµ¼ÖÂÆóÒµ¿Í»§¼°ÖÕ¶ËÓû§Êý¾Ýй¶£¬¾ßÌåÔ̺¬ÓëÒµÎñ¹ØÏµÓйصĹÜÕʼͼ¡¢Ë¾·¨ºÍ̸µÈÆóÒµÊý¾Ý£¬ÒÔ¼°²¿Ãſͻ§µÄ¿Í»§Ó×ÎÒÐÅÏ¢¡£ÊÂÎñ¹¦·òÏßÏÔʾ£¬SitusAMCÔÚ11ÔÂ12ÈÕÊÕµ½°²È«¾¯±¨ºó£¬ÓÚ15ÈÕʵÏÖ³õ´ëÊ©²éÈ·ÈÏ·ì϶ÐÔÖÊ£¬16ÈÕÆðͷ֪ͨסլÓû§£¬ÖÁ22ÈÕÍêÓñ³ÉÊý¿Í»§·î¸æ¡£¹«Ë¾Ç¿µ÷ÒµÎñÔËӪδÊÜÓ°Ï죬ϵͳδ·¢ÏÖ¼ÓÃܶñÒâÈí¼þ²¿ÊðºÛ¼£¡£Ê×ϯִÐйÙÂõ¿Ë¶û¡¤¸¥À¼¿Æ°µÊ¾£¬¹«Ë¾Õýͨ¹ýÖ±½Ó¹µÍ¨Çþ·ÏòÊÜÓ°Ïì¿Í»§Ìṩ³ÖÐø¸üУ¬²¢×¨Ò»ÓÚ·ÖÎöÊÜÓ°ÏìÊý¾ÝÁìÓò¡£Õâ´ÎÊÂÎñÉæ¼°Êý¾Ý¸´ÔÓÐԽϸߣ¬¾ßÌåÊÜÓ°Ïì¿Í»§ÊýÁ¿¼°Êý¾Ý¹æÄ£ÈÔÔÚµ÷²éÖС£Ö»¹ÜÊÂÎñÉæ¼°¶à¼ÒÒøÐÐÒµ¾ÞÍ·£¬µ«¹«Ë¾Î´Åû¶¾ßÌåÊÜÓ°Ïì»ú¹¹Ãûµ¥¡£
https://www.bleepingcomputer.com/news/security/real-estate-finance-services-giant-situsamc-breach-exposes-client-data/
5. Shai-Hulud¹©¸øÁ´¹¥»÷³Á´´npmÉú̬
11ÔÂ24ÈÕ£¬½üÆÚ£¬Íþв×éÖ¯Shai-HuludÔÚnpm×¢²á±íÌáÒé´ó¹æÄ£¹©¸øÁ´¹¥»÷£¬Í¨¹ýľÂí»¯Zapier¡¢ENS Domains¡¢PostHogµÈ492¸ö³ÛÃûÈí¼þ°ü£¬ÇÔÈ¡¿ª·¢Õß¼°CI/CDÍŶӵĻúÃÜÐÅÏ¢²¢¼ÓÃÜÉÏ´«ÖÁGitHub¡£¹¥»÷ÀûÓñ»µÁÊØ»¤ÕßÕË»§Åú¸Äpackage.json×¢Èë¶ñÒâ¾ç±¾£¬½áºÏTruffleHog¹¤¾ßÖ´ÐÐÇÔÃÜ£¬GitHubÒѼì²âµ½27,600ÌõÓйØÌõ¿î¡£Õâ´Î¹¥»÷³öÏÖÖ¸Êý¼¶À©É¢Ìص㣺WizÔÆ°²È«Æ½Ì¨·¢ÏÖ350¸öÉæ°¸ÊØ»¤ÕßÕË»§£¬Ã¿30·ÖÖÓÐÂÔöÔ¼1,000¸ö´æ´¢¿â¡£¶ñÒâÈí¼þÔ̺¬setup_bun.jsºÍ10MBµÄbun_environment.js£¬Ö´ÐÐÎå½×¶Î¹¥»÷Á÷³Ì£ºÇÔÈ¡GitHub/npmÁîÅÆ¡¢ÔÆÆ½Ì¨ÃÜÔ¿µÈ»úÃÜ£¬²¢ÔÚÂú×ãÌØ¶¨Ç°ÌᣨÈçÎÞ·¨ÈÏÖ¤GitHub¡¢»ñÈ¡ÁîÅÆÊ§°Ü£©Ê±¸²¸ÇÓû§Ö÷Ŀ¼¡£¹¥»÷Ó°ÏìÉîÔ¶£ºENS DomainsµÈ¹¤¾ß°ü±»ÈëÇÖ£¬Ó°ÏìÒÔÌ«·»µØÖ·½âÎö¡¢ENSÖÇÄܺÏÔ¼½»»¥µÈÖ÷ÌâÖ°ÄÜ¡£GitHubËä³ÖÐøÉ¾³ý¹¥»÷Õß´´½¨µÄSha1-Hulud£¬µ«ÍþвÐÐΪÕßÈÔ¼±¾ç³Á½¨¡£
https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/
6. ¹þ·ð´óѧÔâÓïÒô´¹µö¹¥»÷ÖÂУÓÑÊý¾Ýй¶
11ÔÂ24ÈÕ£¬¹þ·ð´óѧÌÃÓÑÊÂÎñºÍ·¢Õ¹ÏµÍ³11ÔÂ18ÈÕÔâ·êÓïÒôÍøÂç´¹µö¹¥»÷£¬µ¼ÖÂѧÉú¡¢Ð£ÓÑ¡¢¾èÔùÕß¡¢Ô±¹¤¼°½ÌÈËÔ±¹¤Ó×ÎÒÐÅϢй¶¡£¾Ý¸ÃУ¸±Ð£³¤¿ËÀÀ¡¤½ÜÁÖ¿ÆÍÞºÍУÓÑÊÂÎñÓë·¢Õ¹¸±Ð£³¤¼ªÄ·¡¤ºúÉÅû¶£¬Ð¹Â¶Êý¾Ýº¸Çµç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¼ÒÍ¥/°ì¹«µØÖ·¡¢»î¶¯³öϯ¼Í¼¡¢¾èÔùÏêÇé¼°Óë´óѧ³ï¿îºÍУÓѲμÓÓйصÄÓ×ÎÒÐÅÏ¢£¬µ«Î´Ô̺¬Éç»á±£ÏÕºÅÂë¡¢ÃÜÂë¡¢Ö§¸¶¿¨ÐÅÏ¢»ò²ÆÕþÐÅÏ¢¡£Õâ´ÎÊÂÎñÓ°ÏìÁìÓò¿í·º£¬É漰УÓѼ°ÆäÅäż/°éÂÂ/Òſס¢¾èÔùÕß¡¢ÔÚУÉú¼°±ÏÒµÉú¼Ò³¤¡¢²¿ÃÅÔÚУѧÉúºÍ½ÌÈËÔ±¹¤¡£¹þ·ð´óѧÒѵ±¼´²ÉÈ¡´ëÊ©½â³ý¹¥»÷Õßϵͳ½Ó¼ûȨÏÞ£¬²¢Óë·¨Âɲ¿Ãż°µÚÈý·½ÍøÂ簲ȫר¼ÒºÏ×÷µ÷²é¡£11ÔÂ22ÈÕ£¬Ñ§ÌÃÏò¿ÉÄÜÊÜÓ°ÏìµÄÓ×ÎÒ·¢ËÍÊý¾Ýй¶֪ͨ£¬ÌáÐѾ¯ÌèÒ쳣ͨѶ£¬³ö¸ñÊÇÒªÇóÌṩÃÜÂë¡¢Éç±£ºÅ»òÒøÐÐÐÅÏ¢µÄµç»°¡¢¶ÌÐÅ»òÓʼþ¡£ÕâÊǹþ·ð´óѧ½üÆÚµÚ¶þÆðÊý¾Ý°²È«ÊÂÎñ¡£10ÔÂÖÐÑ®£¬ClopÀÕË÷Èí¼þÍÅ»ïÔøÐû³ÆÀûÓÃOracle E-Business SuiteÁãÈÕ·ì϶ÈëÇÖ¸ÃУϵͳ¡£
https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/


¾©¹«Íø°²±¸11010802024551ºÅ