Space BearsÀÕË÷×éÖ¯½èQuasar·ì϶ÇÔÈ¡ComcastÊý¾Ý

°ä²¼¹¦·ò 2025-12-10

1. Space BearsÀÕË÷×éÖ¯½èQuasar·ì϶ÇÔÈ¡ComcastÊý¾Ý


12ÔÂ8ÈÕ£¬Space BearsÀÕË÷Èí¼þ×éÖ¯½üÈÕÔÚ°µÍøÐ¹ÃÜÍøÕ¾Ðû³Æ£¬Í¨¹ý×ôÖÎÑÇÖݵçÐŹ¤³Ì³Ð°üÉÌQuasar Inc.µÄ·ì϶»ñÈ¡ÁËComcastÄÚ²¿×ÊÁÏ£¬²¢Í¬²½½«QuasarÁÐΪ¶ÀÁ¢Êܺ¦Õߣ¬°µÊ¾Á½Æð¹ØÁªÊÂÎñ¡£¸Ã×éÖ¯2024Äê4Ô³öÏÖ£¬±»·ÖÎöΪÊý¾ÝÇÔÈ¡ÐÍÀÕË÷¼¯Ì壬³£Í¨¹ýɾ³ýÃô¸ÐÎļþ²¢Ë÷ÒªÊê½ð×èÖ¹°ä²¼£¬ÓëPhobosÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©·¨Ê½´æÔÚ¹ØÁª£¬ÆäйÃÜÍøÕ¾±»ÊÓΪÓйػ¹²Ïí°ä²¼µã¡£Õë¶ÔComcastµÄÖ¸¿ØÖУ¬Space BearsÐû³ÆQuasarΪComcast¼°GenesisÏîÄ¿Ôì×÷¼¼ÊõÎĵµ£¬´Ó¶ø»ñÈ¡Ô̺¬¶àµØ³ÇÊÐÉè¼ÆÎĵµºÍ¹«ÓÃÉèÊ©¹æ»®Í¼µÄÐÅÏ¢£¬²¢É趨6Ììµ¹¼ÆÊ±£¬ÓâÆÚ½«¹«¿ªÊý¾Ý£¬ÆÚ¼äÌṩÊý¾ÝÊÛÂô·þÎñ¡£È»¶ø£¬¸Ã×é֯δÌṩÎļþÑù±¾£¬¶ÀÁ¢ÑéÖ¤Ôݲ»³ÉÐС£Quasar Inc.ÓÚ2025Äê12ÔÂ4ÈÕ±»µ¥¶ÀÁÐΪÊܺ¦Õߣ¬Space BearsÐû³Æ»ñÈ¡ÆäÍøÂçÏîÄ¿¡¢³ÇÊй滮ͼ¡¢Í¨Ñ¶²¼¾ÖµÈÄÚ²¿Îĵµ£¬²¢¿ªÆôËÄÌìµ¹¼ÆÊ±ÊÛÂôÊý¾Ý¡£


https://hackread.com/space-bears-ransomware-comcast-quasar-breach/


2. WordPress²å¼þ¸ßΣ·ì϶Ôâ´ó¹æÄ£ÀûÓÃ


12ÔÂ8ÈÕ£¬Wordfence¼à²âÏÔʾ£¬WordPressƽ̨µÄSneeit Framework²å¼þ´æÔÚ¸ßΣԶ³Ì´úÂëÖ´Ðзì϶CVE-2025-6389£¨CVSSÆÀ·Ö9.8£©£¬Ó°Ïì8.3¼°ÒÔϰ汾£¬ÒÑͨ¹ý2025Äê8ÔÂ5ÈÕ°ä²¼µÄ8.4°æ±¾½¨¸´¡£¸Ã²å¼þ»îÔ¾×°ÖÃÁ¿³¬1700¸ö£¬·ì϶ԴÓÚº¯ÊýδÑéÖ¤Óû§ÊäÈëÖ±½ÓÖ´ÐдúÂ룬¹¥»÷Õ߿ɽè´Ë´´½¨¶ñÒâÖÎÀíÔ¹ØË»§¡¢Ö²ÈëºóÃÅ£¬»ò³Á¶¨Ïò·Ã¿ÍÖÁ´¹µö/¶ñÒâÕ¾µã¡£×Ô11ÔÂ24ÈÕ·ì϶¹«¿ªºó£¬WordfenceÒÑÀ¹½Ø³¬13.1Íò´Î¹¥»÷£¬24Ó×ʱÄÚ¼´¼Í¼15381´Î¡£¹¥»÷Õßͨ¹ý¡°/wp-admin/admin-ajax.php¡±¶Ëµã·¢ËÍÌØÔìÒªÇ󣬴´½¨¡°arudikadis¡±µÈ¶ñÒâÕË»§£¬ÉÏ´«¡°tijtewmg.php¡±µÈ¾ß±¸Ä¿Â¼É¨Ãè¡¢Îļþ²Ù×÷Ö°ÄܵĶñÒâÎļþ£¬²¢´Ó±í²¿·þÎñÆ÷ÏÂÔØ¡°.htaccess¡±ÎļþÈÆ¹ý½Ó¼ûÏÞ¶È¡£Í¬Ê±£¬VulnCheck¼à²âµ½¹¥»÷ÕßÀûÓÃICTBroadcast·ì϶CVE-2025-2611£¨CVSSÆÀ·Ö9.3£©£¬Í¨¹ýÏÂÔØShell¾ç±¾¼ÓÔØÆ÷´«²¼Frost DDoS½©Ê¬ÍøÂç¡£


https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html


3. ´¹µö¹¤¾ß°üGhostFrameÏòÈ«ÇòÊý°ÙÍòÓû§ÌáÒé¹¥»÷


12ÔÂ8ÈÕ£¬Barracuda°²È«×êÑÐÔ±ÓÚ2025Äê9Ô³õ´Î·¢ÏÖÃûΪGhostFrameµÄÐÂÐ͸߸´ÔÓ¶È´¹µö¹¤¾ß°ü£¬¸Ã¹¤¾ßÒÑÌáÒ鳬100Íò´Î¹¥»÷£¬±ê־ȡ´¹µö¼´·þÎñ£¨PaaS£©¼¼ÊõµÄΣÏÕÉý¼¶¡£ÆäÖ÷ÌâÍþвÔÚÓÚ½«¶ñÒâ²Ù×÷ÒþÄäÓÚÒþÐÎiframe¿ò¼ÜÖУ¬Í¨¹ýÌìÉú¿´ËÆÎÞº¦µÄHTMLÎļþ£¬ÔÚÒ³Ãæµ×²ã¼ÓÔØÀ´×Ô¶¯Ì¬×ÓÓòÃûµÄÕæÊµ´¹µöÄÚÈÝ£¬Ê¹°²È«¹¤¾ßÄÑÒÔ¼ì²â¡£¹¥»÷Á÷³Ì·ÖΪÁ½½×¶Î£ºÊ×ÏÈͨ¹ý¼Ù×°³É¡°±£ÃܺÏͬ¡±¡°ÃÜÂë³ÁÖá±µÈÖ÷ÌâµÄ´¹µöÓʼþÓÕµ¼Óû§µã»÷£»ËæºóÓû§½øÈë¿´ËÆ°²È«µÄÍøÒ³£¬µ×²ãiframe´Óʵʱµ÷»»µÄ×ÓÓòÃû¼ÓÔØ¹¥»÷ÄÚÈÝ¡£Îª¶ã±Ü¼ì²â£¬¹¥»÷ÕßΪÿ¸öÖ¸±êµ¥¶À´´½¨×¨Êô×ÓÓòÃû£¬²¢ÄÚÖ÷´·ÖÎöÖ°ÄÜ£¬Èç½ûÓÃÓÒ¼ü²Ëµ¥¡¢ÆÁ±Î¿ì½Ý¼ü¼°¹Ø¹Ø¿ª·¢Õß¹¤¾ß£¬¹ÊÕϰ²È«ºË²é¡£GhostFrame´îÔØ¶àÏî¸ßÒñ±Î¸öÐÔ£º´¹µö±íµ¥°µ²ØÔÚ´óÎļþͼÏñÁ÷ÖÐÈÆ¹ý´«Í³É¨Ã裻×ÓÓòÃû¶¯Ì¬ÂÖ»»¹²Í¬±¸ÓÃiframe¿ò¼Ü£¬Ó¦¶ÔJavaScriptÀ¹½Ø£»Ö§³Ö¶àÖ¸±ê½Ã½ÝÊÊÅ䣬ÎÞÐèÅú¸ÄÖ÷Ò³Ãæ¼´¿É´úÌæ´¹µöÄÚÈÝ£»Í¨¹ýÅú¸ÄÒ³Ãæ±êÌâºÍͼ±ê·ÂðºÏ·¨·þÎñ£¬¼ÓÇ¿¼Ù×°ÕæÊµÐÔ¡£


https://cybersecuritynews.com/new-ghostframe-super-stealthy-phishing-kit-attacks-millions-of-users-worldwide/


4. ºÚ¿ÍÀûÓÃReact2Shell·ì϶ÌáÒéEtherRAT¶ñÒâÈí¼þ¹¥»÷


12ÔÂ9ÈÕ£¬Ôư²È«¹«Ë¾SysdigÅû¶ÁËÒ»ÖÖÃûΪEtherRATµÄÐÂÐͶñÒâÈí¼þ£¬Æäͨ¹ýÀûÓÃReact/Next.js¿ò¼ÜÖеĸßΣ·ì϶CVE-2025-55182£¨React2Shell£©Ö´Ðй¥»÷¡£¸Ã·ì϶ԴÓÚReact Server ComponentsµÄ¡°Flight¡±ºÍ̸·´ÐòÁл¯È±µã£¬ÔÊÐí¹¥»÷Õßͨ¹ý¶ñÒâHTTPÒªÇóÖ´ÐÐÔ¶³Ì´úÂ룬ӰÏì´óÁ¿ÔÆ»·¾³¡£Sysdig×êÑÐÈËÔ±Ö¸³ö£¬EtherRATÓ볯ÏÊ¡°´«È¾ÐÔ·Ã̸¡±»î¶¯Ê¹ÓõŤ¾ß´æÔÚ¹ØÁªÐÔ£¬µ«¾ß±¸¹ÖÒì¼¼ÊõÌØµã¡£EtherRATѡȡ¶à½×¶Î¹¥»÷Á´£ºÊ×ÏÈͨ¹ýReact2Shell·ì϶ÔÚÖ¸±êϵͳִÐÐBase64±àÂëµÄshellºÅÁÏÂÔØ²¢ÔËÐжñÒâ¾ç±¾s.sh¡£¸Ã¾ç±¾»á´´½¨°µ²ØÄ¿Â¼£¬²¿ÊðºÏ·¨Node.jsÔËÐÐʱ¼°¼ÓÃÜÓÐÐ§ÔØºÉ£¬×îÖÕ½âÃܳöEtherRATÖ²È뷨ʽ¡£ÆäÖ÷Ìâ´´ÐÂÔÚÓÚ»ùÓÚÒÔÌ«·»ÖÇÄܺÏÔ¼µÄC2ͨѶ»úÔ죬ͨ¹ý²éÎÊ9¸ö¹«¹²ÒÔÌ«·»RPC½Úµã²¢Ñ¡È¡ÎÞÊýÏìÓ¦Õ½ÊõÕмܵ¥µã¹ÊÕÏ£¬ÊµÏֽýÝÇÒ¿¹×ÌÈŵÄÖ¸Áî´«Êä¡£


https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-react2shell-flaw-in-etherrat-malware-attacks/


5. ÐÂÐÍMirai±äÖÖÀûÓú£ÊÂDVR·ì϶ִÐи´ÔÓ¹¥»÷


12ÔÂ9ÈÕ£¬Cydome×êÑÐÈËÔ±·¢ÏÖÃûΪBroadsideµÄÐÂÐÍMirai½©Ê¬ÍøÂç±äÖÖ£¬¸Ã±äÖÖÕë¶Ôº£ÊÂÎïÊ¢ÐÐÒµ£¬ÀûÓô¬²°¼°É豸ʹÓõÄTBK DVRÉ豸ÖеĺÅÁî×¢Èë·ì϶CVE-2024-3721ÌáÒé¹¥»÷¡£¸Ã·ì϶ÓÚ2024Äê4ÔÂÅû¶²¢¸½´øPoC´úÂ룬ÖÁ2025ÄêÖÐÒѱ»¶à¸öDDoS½©Ê¬ÍøÂç¿í·ºÀûÓá£Mirai½©Ê¬ÍøÂçÔ´´úÂëÔÚ½üÊ®Äêǰ¹«¿ªºó£¬³ÖÐø±»ÍøÂç·¸×ï·Ö×ÓÅú¸Ä³ÁÓÃÒÔÇý¶¯´ó¹æÄ£¹¥»÷¡£×êÑÐÈËԱǿµ÷£¬TBK DVR·ì϶ͬÑùÓ°ÏìÒÔCeNova¡¢Night Owl¡¢QSeeµÈÆ·ÅÆ³Áаü×°µÄÐͺÅ£¬¶Ôº½Ô˹«Ë¾×é³ÉÑϳÁÍþв¡£ÈëÇÖÉ豸¿ÉÄÜʹ¹¥»÷Õß½Ó¼û¼ÝÊ»ÊÒ¡¢»õ²Õ»ò»ú²ÕµÄCCTV»­Ã棬×ÌÈÅÎÀÐÇͨѶ£¬»òºáÏòÒÆ¶¯ÖÁ´¬²°¹Ø¼üÔËÓª¼¼Êõϵͳ¡£»ã±¨Ö¸³ö£¬Broadside²»½öÏÞÓÚDDoS¹¥»÷£¬Æä×Ô¶¯ÇÔȡϵͳƾ֤ÎļþµÄÐÐΪÅú×¢£¬¹¥»÷ÕßÒâͼ½«ÊÜϰȾÉ豸´Óµ¥Ò»½©Ê¬ÍøÂç½Úµãת±äΪսÊõ°²Éíµã¡£


https://securityaffairs.com/185491/malware/broadside-botnet-hits-tbk-dvrs-raising-alarms-for-maritime-logistics.html


6. Vitas HealthcareÔâÍøÂç¹¥»÷Ö³¬30ÍòÈËÐÅϢй¶


12ÔÂ9ÈÕ£¬ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©Ò½ÁƱ£½¡Êý¾Ýй¶׷×ÙÆ÷ÏÔʾ£¬ÃÀ¹ú×î´óͶ»úÐÔÁÙÖÕ¹ØÇÐÁ¬Ëø»ú¹¹Vitas Healthcare½üÆÚ²úÉú³Á´óÍøÂ簲ȫÊÂÎñ£¬Ó°ÏìÈËÊý´ï319,177ÈË¡£¸Ã»ú¹¹´ÓÊôÓÚChemed¼¯ÍÅ£¬ÆìÏÂVitas Hospice ServicesÓÚ10ÔÂ24ÈÕ·¢ÏÖϵͳÈëÇÖ£¬µ÷²éÏÔʾ¹¥»÷Õßͨ¹ý±»µÁÓõĹ©¸øÉÌÕË»§£¬ÔÚ9ÔÂ21ÈÕÖÁ10ÔÂ27ÈÕÆÚ¼ä³ÖÐø½Ó¼ûÆäϵͳ£¬²¢ÏÂÔØÁË´óÁ¿»¼Õß¼°½üÇ×µÄÃô¸ÐÐÅÏ¢¡£Õâ´Îй¶µÄÊý¾ÝÁìÓò¿í·º£¬Ô̺¬»¼Õß¼°Ç°»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢Éç»á±£ÏÕºÅÂë¡¢Ò½ÁƼͼ¡¢±£ÏÕÐÅÏ¢ÒÔ¼°Ç×ÊôÁªÏµ·½Ê½µÈÖ÷ÌâÓ×ÎÒÉí·ÝÐÅÏ¢¡£Ö»¹ÜĿǰÉÐδÃ÷È·Õâ´ÎÊÂÎñÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ¹¥»÷£¬ÇÒÎÞÒÑÖªÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´ËÕÆ¹Ü£¬µ«ÊÂÎñµÄÑϳÁÐÔÒÑÒý¿¯ÐÐÒµ¹Ø×¢¡£Ä¿Ç°£¬VitasÒÑͨ¹ýרÃÅÊý¾ÝÐ¹Â¶Í¨ÖªÍøÕ¾Ïò¹«¼ÒÅû¶ÊÂÎñÏêÇ飬µ«¾ßÌå¼¼Êõϸ½Ú¼°ºóÐø²¹¾È´ëÊ©ÉÐδÆëÈ«¹«¿ª¡£


https://www.securityweek.com/over-300000-individuals-impacted-by-vitas-hospice-data-breach/