Gladinet¼ÓÃÜ·ì϶ÖÂ9¼Ò»ú¹¹±»Ô¶³Ì¹¥»÷

°ä²¼¹¦·ò 2025-12-15

1. Gladinet¼ÓÃÜ·ì϶ÖÂ9¼Ò»ú¹¹±»Ô¶³Ì¹¥»÷


12ÔÂ11ÈÕ£¬ºÚ¿ÍÕýÀûÓÃGladinet CentreStackºÍTriofox²úÆ·ÖÐδ¼Í¼µÄ¼ÓÃÜËã·¨·ì϶ִÐй¥»÷¡£¸Ã·ì϶ԴÓÚAES¼ÓÃÜËã·¨µÄ×Ô½ç˵ʵÏÖ´æÔÚÓ²±àÂëÃÜԿȱµã£¬GladCtrl64.dllÎļþÖд洢µÄ¼ÓÃÜÃÜÔ¿ºÍ³õʼ»¯ÏòÁ¿£¨IV£©Ô´×ÔÁ½¸ö¾²Ì¬µÄ100×Ö½ÚÖÐÎÄ×Ö·û´®£¬ÔÚËùÓвúÆ·×°ÖÃÖÐÆëȫһÑù¡£¹¥»÷Õß¿ÉÌáÈ¡ÕâЩÃÜÔ¿½âÃܽӼûµ¥¾Ýº¬Îļþõè¾¶¡¢Óû§Æ¾Ö¤µÈÐÅÏ¢£¬»òαÔìµ¥¾Ý¼ÙÒâÓû§»ñȡϵͳÎļþ¡£¾ßÌå¹¥»÷õè¾¶ÏÔʾ£¬ÍþвÐÐΪÕßͨ¹ý"filesvr.dn"´¦Ö÷¨Ê½ÀûÓ÷ì϶£¬½«½Ó¼ûµ¥¾ÝµÄ¹¦·ò´ÁÉèÖÃΪ9999ÄêʵÏÖÓÀÔ¶ÓÐЧ£¬ËæºóÒªÇóweb.configÎļþ»ñÈ¡machineKey£¬×îÖÕͨ¹ýViewState·´ÐòÁл¯´¥·¢Ô¶³Ì´úÂëÖ´ÐС£Huntress°²È«ÍŶӼà²â·¢ÏÖ£¬ÖÁÉÙ9¼ÒÒ½ÁÆ¡¢¼¼ÊõµÈÐÐÒµµÄ»ú¹¹Ôâ´Ë¹¥»÷£¬¹¥»÷Õß»¹½áºÏÁ˾ɷì϶CVE-2025-30406À©´ó·ÛËé¡£GladinetÒѰ䲼´¹Î£¸üУ¬²¢½¨ÒéÓû§Éý¼¶ºóµ±¼´ÂÖ»»»úеÃÜÔ¿¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-gladinet-centrestack-cryptographic-flaw-in-rce-attacks/


2. ConsentFix¹¥»÷ÈÆ¹ýMFA½Ù³Ö΢ÈíÕË»§


12ÔÂ11ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Push Security·¢ÏÖÒ»ÖÖÃûΪ¡°ConsentFix¡±µÄÐÂÐÍClickFix¹¥»÷±äÖÖ£¬¸Ã¹¥»÷ͨ¹ýÀÄÓÃAzure CLI OAuthÀûÓ÷¨Ê½£¬ÔÚÎÞÐèÃÜÂë»ò¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©µÄÇé¿öϽٳÖMicrosoftÕË»§¡£¹¥»÷ʼÓÚÊܺ¦Õß½Ó¼û±»ÈëÇֵĺϷ¨ÍøÕ¾£¬ÕâÐ©ÍøÕ¾Í¨¹ýGoogleËÑË÷Õë¶ÔÌØ¶¨¹Ø¼ü´ÊÅÅÃû¿¿Ç°¡£ÍøÕ¾Ò³Ãæ»áÏÔʾαÔìµÄCloudflare TurnstileÑéÖ¤ÂëÓײ¿¼þ£¬ÒªÇóÓû§ÊäÈëÓÐЧÆóÒµÓÊÏ䵨ַ£¬¹¥»÷Õ߾籾»á¹ýÂË»úеÈË¡¢·ÖÎöʦ¼°Î´ÁÐÈëÖ¸±êµÄÓû§¡£Í¨¹ýÑéÖ¤µÄÓû§½«¿´µ½ÀàËÆClickFixµÄ½»»¥Ò³Ã棬Êèµ¼ÆäÖ´ÐÓ×°ÑéÖ¤ÈËÀàÉí·Ý¡±µÄ²Ù×÷¡£Óû§µã»÷Ò³ÃæÖеġ°µÇ¼¡±°´Å¥ºó£¬»á±»³Á¶¨Ïòµ½ºÏ·¨µÄ΢ÈíAzureµÇÂ¼Ò³Ãæ¡£ÈôÓû§ÒѵǼ΢ÈíÕË»§£¬Ö»ÐèÑ¡Ôñ×Ô¼ºµÄÕË»§ £»ÈôδµÇ¼£¬ÔòÐèÔÚ΢Èí¹Ù·½Ò³ÃæÊµÏÖÕý³£Éí·ÝÑéÖ¤¡£ÊµÏֵǼºó£¬Î¢Èí»á½«Óû§³Á¶¨Ïòµ½±¾µØÖ÷»úÒ³Ãæ£¬´Ëʱä¯ÀÀÆ÷µØÖ·À¸»áÏÔʾÔ̺¬Azure CLI OAuthÊÚȨÂëµÄURL¡£µ±Óû§ÒÀÕÕÅúʾ½«¸ÃURLÕ³Ìùµ½¶ñÒâÒ³ÃæÊ±£¬¹¥»÷Õß¼´¿Éͨ¹ýAzure CLI OAuthÀûÓûñÈ¡ÆëÈ«µÄÕË»§½Ó¼ûȨÏÞ¡£


https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/


3. PayPal¶©ÔÄÖ°ÄÜÔâÀÄÓÃÖÂÚ¿Æ­Óʼþ·ºÀÄ


12ÔÂ14ÈÕ£¬½üÆÚ£¬Ú¿Æ­·Ö×ÓÀÄÓÃPayPalµÄ¡°¶©ÔÄ¡±¼Æ·ÑÖ°ÄÜ£¬ÏòÓû§·¢ËͼÙ×°³ÉºÏ·¨PayPalÓʼþµÄÚ¿Æ­ÐÅÏ¢¡£ÕâÀàÓʼþÐû³Æ¡°×Ô¶¯¸¶¿îʧЧ¡±£¬ÊµÔòǶÈëÐéα²É°ì֪ͨ£¬ÈçÐû³ÆÓû§²É°ìÁËË÷ÄáÉ豸¡¢MacBook»òiPhoneµÈ°º¹óÉÌÆ·£¬²¢¸½ÓÐ1300ÖÁ1600ÃÀÔª²»µÈµÄ¸¶¿î¼Í¼¼°¡°¿Í·þµç»°¡±¡£Óʼþͨ¹ý¡°mailto:service@paypal.com¡±µØÖ··¢ËÍ£¬ÇÒͨ¹ýÁËDKIM¡¢SPF¼°DMARCµÅ×ʼþ°²È«ÈÏÖ¤£¬Ö±½ÓÀ´×ÔPayPal¹Ù·½·þÎñÆ÷£¬Òò¶øÄÜÈÆ¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£¬¼«¾ßºýŪÐÔ¡£Ú¿Æ­·Ö×Óͨ¹ýÅú¸Ä¿Í»§·þÎñURL×ֶΣ¬½«ÐéαÐÅϢǶÈëºÏ·¨ÓʼþÄ£°å¡£ÀýÈ磬URLÖпÉÄÜÔ̺¬ÓòÃû¡¢¸¶¿î½ð¶î¼°¡°È¡µÞ»òÕ÷ѯ¡±µç»°ºÅÂ룬²¢Í¬»¯Unicode×Ö·ûÒÔ´ÖÌå»òÌØÊâ×ÖÌåÏÔʾ£¬ÊÔͼ¶ã±Ü¹Ø¼ü´Ê¼ì²â¡£Í¨¹ý²âÊÔ·¢ÏÖ£¬µ±É̼ÒÔÝÍ£¶©ÔÄÓû§Ê±£¬PayPal»á×Ô¶¯·¢ËÍ֪ͨÓʼþ£¬¶øÚ¿Æ­Õß¿ÉÄÜÀûÓö©ÔÄÔªÊý¾Ý´¦Ö÷ì϶»ò¾Éƽ̨½Ó¿Ú£¬ÔÚURL×Ö¶ÎÖÐ×¢ÈëÎÞЧÎı¾£¬´Ó¶øÌìÉúÚ¿Æ­Óʼþ¡£ÕâЩÓʼþ¿ÉÄܱ»×ª·¢ÖÁδע²áPayPal¶©ÔĵÄÓû§¡£


https://www.bleepingcomputer.com/news/security/beware-paypal-subscriptions-abused-to-send-fake-purchase-emails/


4. Ç×¶íVolkLockerÀÕË÷Èí¼þ·ì϶»òÖÂÃâ·Ñ½âÃÜ


12ÔÂ13ÈÕ£¬Ç×¶íºÚ¿Í×éÖ¯CyberVolkÍÆ³öµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©VolkLocker´æÔÚ³Á´óʵÏÖȱµã£¬Ê¹Êܺ¦Õß¿ÉÄÜÎÞÐèÖ§¸¶Êê½ð¼´¿É¸´Ô­Îļþ¡£¾ÝSentinelOne×êÑУ¬¸ÃÈí¼þÔÚ¶þ½øÔìÎļþÖÐÓ²±àÂëÁËÖ÷ÃÜÔ¿£¬ÇÒ¸ÃÃÜÔ¿ÒÔÃ÷ÎÄ´ó¾Ö´æ´¢ÓÚÊÜϰȾ»úеµÄ%TEMP%Îļþ¼ÐÖУ¬Êܺ¦Õß¿Éͨ¹ýÌáÈ¡¸ÃÃÜÔ¿³¢ÊÔ½âÃÜ¡£VolkLockerѡȡAES-256 GCM¼ÓÃÜ£¬Ã¿¸öÎļþʹÓÃËæ»ú12×Ö½Únonce×÷Ϊ³õʼ»¯ÏòÁ¿£¬¼ÓÃܺ󸽼Ó.locked»ò.cvolkÀ©´óÃû²¢É¾³ýԭʼÎļþ¡£È»¶ø£¬ÓÉÓÚËùÓÐÎļþ¹²ÏíͳһÖ÷ÃÜÔ¿ÇÒÃÜԿδ±»É¾³ý£¬¸Ã·ì϶ÏÔÖø¼õÈõÁËÆäÀÕË÷ÄÜÁ¦¡£CyberVolk×ܲ¿Î»ÓÚÓ¡¶È£¬×Ô2024ÄêÆð»îÔ¾£¬Ôø¶Ô·´¶í»òÖ§³ÖÎÚ¿ËÀ¼µÄʵÌåÌáÒéDDoSºÍÀÕË÷¹¥»÷¡£2025Äê8Ô£¬¸Ã×éÖ¯ÒÔVolkLocker 2.x°æ±¾»Ø¹é£¬Í¬Ê¹Øë¶ÔLinux/VMware ESXiºÍWindowsϵͳ£¬²¢ÒýÈëGolang°´Ê±Æ÷Ö°ÄÜ£¬Èô³¬Ê±»òÊäÈëÃýÎóÃÜÔ¿£¬½«²Á³ýÓû§Îĵµ¡¢ÏÂÔØ¡¢Í¼Æ¬ºÍ×ÀÃæÎļþ¼Ð¡£RaaS¶¨¼Û°´²Ù×÷ϵͳ¼Ü¹¹»®·Ö£ºµ¥Ò»ÏµÍ³800-1100ÃÀÔª£¬Ë«ÏµÍ³1600-2200ÃÀÔª£¬²É°ìÕß¿Éͨ¹ýTelegram¹¹½¨»úеÈ˶¨Ôì¼ÓÃÜÆ÷²¢»ñÈ¡ÓÐÐ§ÔØºÉ¡£Í¬Äê11Ô£¬¸Ã×éÖ¯»¹ÍƳö500ÃÀÔªµÄÔ¶³Ì½Ó¼ûľÂíºÍ¼üÅ̼ͼÆ÷¡£


https://www.bleepingcomputer.com/news/security/cybervolks-ransomware-debut-stumbles-on-cryptography-weakness/


5. CISA¸üÐÂKEVĿ¼£¬ÒªÇóÁª¹ú»ú¹¹2026ËêÊ×½¨¸´·ì϶


12ÔÂ13ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«CVE-2025-14174£¨Google ChromiumÔ½½çÄÚ´æ½Ó¼û·ì϶£©ºÍCVE-2018-4063£¨Sierra Wireless AirLink ALEOSÎÞÏÞ¶ÈÉÏ´«·ì϶£©²¹³äÖÁÒÑÖª¿ÉÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£CVE-2025-14174ÊÇGoogle Chrome 143.0.7499.110°æ±¾Ç°Macϵͳ´æÔÚµÄANlgeͼÐοâ·ì϶¡£¸Ã·ì϶ԴÓÚMetaläÖȾÆ÷¶ÔGL_UNPACK_IMAGE_HEIGHTÖµµÄÃýÎóÍÆË㣬µ±Í¼Ïñ¸ß¶È³¬¹ý»º³åÇøÈÝÁ¿Ê±£¬»á´¥·¢Ô½½çÄÚ´æ½Ó¼û£¬µ¼ÖÂÄÚ´æ°Ü»µ¡¢·¨Ê½±ÀÀ£ÉõÖÁËÁÒâ´úÂëÖ´ÐС£¹È¸èÒÑͨ¹ý°²È«¸üн¨¸´´Ë·ì϶£¬²¢È·Èϸ÷ì϶ÒÑÔÚÏÖʵ¹¥»÷Öб»ÀûÓá£ÖµÍ×ÌùÐĵÄÊÇ£¬¹È¸èδ¹«¿ª¼¼Êõϸ½Ú£¬µ«GitHubÌá½»¼Í¼ÏÔʾ·ì϶Ó뻺³åÇøÒç³öÖ±½ÓÓйØ¡£ÁíÒ»·ì϶CVE-2018-4063ÔòÓ°ÏìSierra Wireless AirLink ES450¹Ì¼þ4.9.3µÄupload.cgi×é¼þ¡£¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õ߿ɷ¢ËÍÌØÔìHTTPÒªÇó£¬ÔÚÉ豸Web·þÎñÆ÷ÉÏ´«²¢Ö´ÐжñÒâ´úÂ룬ʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¸Ã·ì϶×Ô2018ÄêÅû¶ÒÔÀ´£¬Òòδʵʱ½¨¸´ÈÔ±»CISAÄÉÈëĿ¼¡£


https://securityaffairs.com/185639/security/u-s-cisa-adds-google-chromium-and-sierra-wireless-airlink-aleos-flaws-to-its-known-exploited-vulnerabilities-catalog.html


6. ·´µÁ°æÍ¬ÃËACEµ·»ÙÓ¡¶È°ÙÍò¼¶·Ã¿ÍµÁ°æÆ½Ì¨


12ÔÂ12ÈÕ£¬ÓɵÏÊ¿Äá¡¢»ªÄÉÐֵܡ¢NetflixµÈ50Óà¼ÒÓ°ÊÓÍøÂç¾ÞÍ·Ö§³ÖµÄ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©½üÆÚÔÚÓ¡¶ÈÌáÒé´ó¹æÄ£·´µÁ°æÐж¯£¬³É¹¦µ·»Ù±¾µØ×îÊÜÓ­½ÓµÄÁ÷ýÌåµÁ°æ·þÎñÖ®Ò»MKVCinemas¼°Æä25¸öÓйØÓòÃû¡£¸Ãƽ̨ÔÚ2024-2025Äê¼äÎüÒý³¬1.424ÒڷÿÍ£¬ÎªÊý°ÙÍòÓû§ÌṩÃâ·ÑµçÓ°µçÊÓ×ÊÔ´¡£ACEͨ¹ýÐÌÊÂÒÆËÍ¡¢ÃñÊÂËßËϼ°ÖÕ³¡ÁîÐж¯£¬ÆÈʹλÓÚÓ¡¶È±È¹þ¶û¹úµÄÔËÓªÉÌÖÕ³¡ÔËÓª²¢Òƽ»ÓòÃû½ÚÔìȨ£¬ËùÓÐMKVCinemasÍøÕ¾ÏÖÒѳÁ¶¨ÏòÖÁACEµÄ¡°ºÏ·¨ÅÔ¹Û¡±ÃÅ»§£¬¶Â½ØµÁ°æÄÚÈÝ´«²¼õè¾¶¡£Õâ´ÎÐж¯»¹¹Ø¹ØÁËÒ»¿î¿í·ºÊ¹ÓõÄÎļþ¿Ë¡¹¤¾ß£¬¸Ã¹¤¾ßͨ¹ý°µ²ØÔƴ洢ýÌåÎļþÆðÔ´£¬Ô®ÊÖÓ¡¶È¼°Ó¡ÄáÓû§ÈƹýϼܴëÊ©£¬Á½ÄêÄÚ»ñ2.314ÒڴνӼû£¬³ÉΪµÁ°æÄÚÈÝ·Ö·¢µÄ¹Ø¼ü¼¼ÊõÖ§³Ö¡£ÃÀ¹úµçӰЭ»áÖ´Ðи±×ܲÃÀ­ÀïÈø¡¤¿ËÄÉÆÕÇ¿µ÷£¬ACE½«³ÖÐø²é¾¿·¸·¨ÔËÓª£¬ÊØ»¤°²È«¿É³ÖÐøµÄÊг¡»·¾³¡£


https://www.bleepingcomputer.com/news/security/mkvcinemas-streaming-piracy-service-with-142m-visits-shuts-down/