2025Äê¼ÙÈÕ¹ºÎï¼¾Ôâ·êÐéαÁãÊÛ´¹µö¹¥»÷
°ä²¼¹¦·ò 2025-12-221. 2025Äê¼ÙÈÕ¹ºÎï¼¾Ôâ·êÐéαÁãÊÛ´¹µö¹¥»÷
12ÔÂ18ÈÕ£¬2025Äê¼ÙÈÕ¹ºÎï¼¾ÆÚ¼ä£¬ÍþвÐÐΪÕßÌáÒé´ó¹æÄ£ÐéαÔÚÏßÁãÊÛÉ̵깥»÷£¬¶ÔÈ«ÇòÏû·ÑÕß×é³É³Á´óÍøÂ簲ȫÍþв¡£¸Ã»î¶¯Í¨¹ý·ÂðZalando¡¢Birkenstock¡¢IKEAµÈ³ÛÃûÆ·ÅÆµÄÓòÃû£¬ÀûÓÃ×Ô¶¯»¯¹¤¾ßÅúÁ¿ÌìÉú¸ß¶ÈÕæÇеÄÚ²ÆÍøÕ¾£¬Ì°Í¼ÔÚ¡°ÐþÉ«ÐÇÆÚÎ塱¡°Ë«Ê®Ò»¡±µÈ¹ºÎï¶¥·åÆÚÇÔÈ¡µÞ·ÑÕßÐÅÓþ¿¨ÐÅÏ¢»òÓÕµ¼ÏÂÔØ¶ñÒâÈí¼þ¡£¹¥»÷ÕßÒÀ¸½Öйú»ù´¡ÉèÊ©ÌṩÉÌ×¢²á³¬200¸öÐÂÓòÃû£¬Í¨¹ýTikTok¡¢FacebookµÈÉ罻ýÌåÆ½Ì¨ÍÆ¹ãÐéαµêÆÌÁ´½Ó¡£ÍøÕ¾Ñ¡È¡ÓëÕýÆ·¸ß¶ÈÀàËÆµÄÊÓ¾õÉè¼Æ£¬²¢Ç¶Èë·Âð½áÕËϵͳ£¬Óû§Ò»µ©ÊäÈëÖ§¸¶ÐÅÏ¢£¬Êý¾Ý½«±»Ö±½ÓÇÔÈ¡»ò³Á¶¨ÏòÖÁ¶ñÒâÔØºÉ¡£Bfore.ai·ÖÎöʦÓÚ2025Äê11Ô·¢ÏÖ£¬¸Ã»î¶¯ÒÀÀµÒþÖÔ±£»¤µÄWHOISÊý¾Ý°µ²Ø¹¥»÷ÕßÉí·Ý£¬³öÏÖ¡°¹¤Òµ»¯¡±Ú²ÆÌص㣬·ÖÆç¹¥»÷¼¯Èº¿É×·ÒäÖÁÌØ¶¨ÍйܷþÎñÌṩÉ̺Í×ÔÖÎϵͳ£¬Ê¹¹¥»÷ÕßÄÜÔÚ¾ÉÓòÃû±»·âºó¼±¾çÇл»ÐÂÓòÃûά³ÖÔËÓª¡£Ïû·ÑÕßÃæ¶ÔÖ±½Ó¾¼ÃËðʧºÍÉí·Ý͵ÇÔ·çÏÕ£¬»î¶¯¹æÄ£Åú×¢±³ºóÊÇ×ÊÔ´³ä×ãµÄ¾¼Ã¶¯»úÍŻ
https://cybersecuritynews.com/threats-actors-registering-fake-shopping-domains/
2. Ó¢¹úDXS InternationalÔâÍøÂçÈëÇÖ
12ÔÂ18ÈÕ£¬Ó¢¹ú¼¼Êõ¹«Ë¾DXS International½üÈÕÅû¶һ·ӰÏìÆäÄÚ²¿ÏµÍ³µÄÍøÂ簲ȫÊÂÎñ¡£¸Ã¹«Ë¾×÷ΪNHS£¨Ó¢¹ú¹ú¶ÈÒ½ÁÆ·þÎñϵͳ£©ÁÙ´²¾ö²ßÖ§³ÖºÍתÕïÖÎÀí¹¤¾ßµÄÖ÷Ì⹩¸øÉÌ£¬ÆäÈí¼þ¸²¸ÇȫӢ¸ñÀ¼Ô¼10%µÄNHSתÕïÁ÷³Ì£¬Éæ¼°Êý°ÙÍò»¼ÕßÊý¾Ý¡£12ÔÂ14ÈÕ£¬DXS·¢Ïְ칫·þÎñÆ÷Ôâδ¾ÊÚȨ½Ó¼û£¬µ«ÁÙ´²·þÎñδÊÜÓ°ÏìÇÒά³ÖÔËÐС£Ä¿Ç°ÉÐÎÞNHS»¼ÕßÊý¾Ýй¶µÄÃ÷È·Ö¤¾Ý£¬¹«Ë¾ÒÑ֪ͨӢ¹úÊý¾Ý±£»¤¼à¹Ü»ú¹¹ICO£¬²¢ÕýÓëNHSÍøÂ簲ȫÍŶӼ°±í²¿×¨¼ÒºÏ×÷µ÷²éÊÂÎñÐÔÖÊÓëÁìÓò£¬³õ²½ÅжϲÆÕþÓ°ÏìÓÐÏÞ¡£Õâ´ÎÊÂÎñ²¢·Ç¹ÂÁ¢£¬½üÄêÀ´£¬Ó¢¹úÎÀÉú¼¼Êõ¹©¸øÉÌÆµÈÔ³ÉΪ¹¥»÷Ö¸±ê¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Ó¢¹úÏÖÐÐÍøÂ簲ȫÂÉÀýδǿÔìÒªÇóDXSµÈµÚÈý·½ÎÀÉúIT¹©¸øÉÌÂú×ãÌØ¶¨°²È«³ß¶È¡£È»¶ø£¬ÉÏÔÂÌá½»Òé»áµÄ¡¶ÍøÂ簲ȫÓëÈÍÐÔ·¨°¸¡·Äâ¶Ô¹Ø¼üÁìÓòIT·þÎñÉÌÖ´ÐиüÑϸñ¼à¹Ü£¬Ô̺¬¸ß¶î·£¿îÌõ¿î¡£Èô·¨°¸Í¨¹ý£¬´ËÀ๩¸øÉ̽«Ãæ¶Ô¸üÑÏ¿ÁµÄ°²È«ºÏ¹æÒªÇó¡£
https://therecord.media/uk-nhs-tech-provider-dxs-discloses-hack
3. ³¯ÏÊKimsuky¶þάÂë´«²¼DocSwap°²×¿¶ñÒâÈí¼þ
12ÔÂ18ÈÕ£¬º«¹úÍøÂ簲ȫ¹«Ë¾ENKIÅû¶£¬³¯ÏÊÍþвÐÐΪÕßKimsukyÕýͨ¹ý¼Ù×°³ÉCJ LogisticsµÄ´¹µöÍøÕ¾£¬ÀûÓöþάÂë·Ö·¢ÃûΪDocSwapµÄ°²×¿¶ñÒâÈí¼þбäÖÖ¡£¸Ã¹¥»÷ͨ¹ý¶ÌÐÅ´¹µö»ò´¹µöÓʼþÓÕµ¼Óû§µã»÷¶ñÒâÍøÖ·£¬µ±Óû§´Ó×ÀÃæ¶Ë½Ó¼ûʱ£¬Ò³Ãæ»áÌáÐÑɨÃè¶þάÂëÔÚ°²×¿É豸װÖá°°ü¹ü×·×ÙÀûÓᱡ£¶þάÂë³Á¶¨ÏòÖÁ¡°tracking.php¡±¾ç±¾£¬¸Ã¾ç±¾Í¨¹ý¼ì²âUser-Agent×Ö·û´®£¬ÒÔ¡°¹ú¼Êº£¹Ø°²È«Õþ²ß¡±ÎªÓɺýŪÓû§×°Öá°°²È«Ä£¿é¡±¡£¶ñÒâAPK»á½âÃܲ¢¼ÓÔØÇ¶ÈëµÄ¼ÓÃÜAPK£¬Æô¶¯DocSwapÔ¶³Ì½Ó¼ûľÂí¡£×°Öùý³ÌÖУ¬ÀûÓ÷¨Ê½»áÒªÇó¶ÁÈ¡´æ´¢¡¢½Ó¼ûÍøÂç¼°×°ÖÃÆäËûÈí¼þ°üµÄȨÏÞ¡£Ò»µ©È¨ÏÞ»ñÈ¡£¬Ä¾Âí½«×¢²á¡°com.delivery.security.MainService¡±·þÎñ£¬²¢Æô¶¯¼Ù×°³ÉOTPÈÏÖ¤½çÃæµÄAuthActivity£¬Ê¹ÓÃÓ²±àÂë¿ìµÝµ¥ºÅ¡°742938128549¡±ÑéÖ¤Éí·Ý¡£Óû§ÊäÈëËæ»úÑéÖ¤Âëºó£¬Ä¾Âíºó¶ÜÏνӹ¥»÷Õß·þÎñÆ÷£¬½Ó¹Ü¶à´ï57ÌõºÅÁʵÏÖ¼üÅ̼ͼ¡¢ÒôƵ²¶»ñ¡¢ÉãÏñÍ·½ÚÔì¡¢Îļþ²Ù×÷¡¢Î»ÏàÐÅÏ¢ÇÔÈ¡µÈÖ°ÄÜ£¬²¢ÉÏ´«¶ÌÐÅ¡¢ÁªÏµÈË¡¢Í¨»°¼Í¼µÈÃô¸ÐÊý¾Ý¡£
https://thehackernews.com/2025/12/kimsuky-spreads-docswap-android-malware.html
4. ¶àÆ·ÅÆÖ÷°åUEFI¹Ì¼þ·ì϶¶³öDMA¹¥»÷·çÏÕ
12ÔÂ19ÈÕ£¬½üÈÕ£¬»ªË¶¡¢¼¼¼Î¡¢Î¢ÐÇ¡¢»ªÇæµÈÖ÷°å³§É̵IJ¿ÃÅÐͺű»·¢ÏÖ´æÔÚUEFI¹Ì¼þ·ì϶CVE-2025-11901¡¢CVE-2025-14302ÖÁ14304£¬¸Ã·ì϶¿É±»ÀûÓýøÐÐÖ±½ÓÄÚ´æ½Ó¼û£¨DMA£©¹¥»÷£¬ÈƹýÔçÆÚÆô¶¯½×¶ÎµÄÄÚ´æ±£»¤»úÔì¡£·ì϶ԴÓÚUEFI¹Ì¼þÔÚ³õʼ»¯Ê±Î´ÄÜÕýÈ·ÅäÖÃÊäÈë/Êä³öÄÚ´æÖÎÀíµ¥Ôª£¨IOMMU£©£¬Ò»ÖÖÓ²¼þÇ¿ÔìµÄÄÚ´æ·À»ðǽ£¬µ¼ÖÂϵͳÔÚÆô¶¯³õÆÚ´¦ÓÚ¡°×î¸ßÌØÈ¨×´Ì¬¡±Ê±£¬¶ñÒâPCIeÉ豸£¨ÈçÏÔ¿¨¡¢Thunderbolt±íÉ裩¿ÉÈÆ¹ýIOMMUÏÞ¶È£¬Ö±½Ó¶ÁдϵͳÄڴ棬ÉõÖÁÅú¸Ä¹Ø¼üÊý¾Ý¡£Ö»¹Ü¹Ì¼þÐû³ÆDMA±£»¤ÒÑÆôÓ㬵«ÔÚÆô¶¯ÐòÁеÄÔçÆÚ½»´ú½×¶Î£¬IOMMUÏÖʵδ±»ÕýÈ·¼¤»î£¬Ê¹ÏµÍ³Â¶³öÓÚÎïÀí½Ó¼û¹¥»÷·çÏÕÖС£¿¨ÄÚ»ù÷¡´óѧCERTе÷ÖÐÐÄ£¨CERT/CC£©°ä²¼²¼¸æÖ¤Êµ£¬¸Ã·ì϶ӰÏìÉÏÊöÆ·ÅÆµÄ²¿ÃÅÖ÷°åÐͺţ¬ÇÒ¿ÉÄܲ¨¼°ÆäËû³§É̲úÆ·¡£¹¥»÷ÐèÎïÀí½Ó´¥É豸£¬ÔÚ²Ù×÷ϵͳÆô¶¯Ç°ÏνӶñÒâPCIeÉ豸£¬´Ëʱ°²È«¹¤¾ßÎÞ·¨¼ì²â»ò×èÖ¹¹¥»÷ÐÐΪ£¬µ¼ÖÂÄÚ´æÊý¾Ý±»ÇÔÈ¡»ò´Û¸Ä£¬ÉõÖÁ¿ÉÄÜ·ÛËé²Ù×÷ϵͳÆëÈ«ÐÔ¡£Ä¿Ç°£¬¸÷³§ÉÌÒѰ䲼°²È«²¼¸æ¼°¹Ì¼þ¸üУ¬Ã÷È·ÁгöÊÜÓ°ÏìÐͺż°½¨¸´¹æ»®¡£
https://www.bleepingcomputer.com/news/security/new-uefi-flaw-enables-pre-boot-attacks-on-motherboards-from-gigabyte-msi-asus-asrock/
5. µ¤ÂóÖ¸¿Ø¶íÂÞ˹·¢Æð»ìºÏÕ½ÕùÍøÂç¹¥»÷
12ÔÂ19ÈÕ£¬µ¤Âó¹ú·Àµý±¨¾ÖÓÚÖÜËİ䲼ÉêÃ÷£¬Õýʽָ¿Ø¶íÂÞ˹¶Ô2024ÄêÕë¶Ô¸Ã¹ú×ÔÀ´Ë®¹«Ë¾µÄ¡°·ÛËéÐÔ¡±ÍøÂç¹¥»÷¼°11Ô´¦ËùÑ¡¾ÙǰϦµ¼Öµ¤ÂóÍøÕ¾Ì±»¾µÄ»Ø¾ø·þÎñ¹¥»÷£¨DDoS£©Õƹܡ£¾Ýµ¤Âó¹ã²¥¹«Ë¾DR±¨Â·£¬×ÔÀ´Ë®¹«Ë¾Ôâ¹¥»÷ºó¹Ü·±¬ÁÑ£¬Ôì³É¸ç±¾¹þ¸ùÒÔÄÏ35¹«Àï¿Æ¶òµØÓò²¿ÃžÓÃñ¶ÏË®£»¶øÑ¡¾ÙǰϦµÄDDoS¹¥»÷Ôòµ¼Ö¶à¸öµ±¾Ðݹ«¹²ÍøÕ¾ÎÞ·¨½Ó¼û£¬ÑϳÁ×ÌÈÅÑ¡¾Ù¹ý³Ì¡£µý±¨²¿ÃÅÇ¿µ÷£¬ÕâЩ¹¥»÷ÊǶíÂÞ˹¶ÔÎ÷·½·¢ÆðµÄ¡°»ìºÏÕ½Õù¡±×é³É²¿ÃÅ£¬Ö¼ÔÚͨ¹ý·ÛË鹨¼ü»ù´¡ÉèÊ©¡¢Ôì×÷Éç»á²»²»±äÀ´¼õÈõ²¢³ÍÖÎÖ§³ÖÎÚ¿ËÀ¼µÄ¹ú¶È¡£µ÷²éÏÔʾ£¬Ç×¶í×éÖ¯Z-PentestÖ´ÐÐÁË2024Äê¶ÔË®Îñ¹«Ë¾µÄ¹¥»÷£¬µ¼ÖÂˮѹÒì³£Òý·¢¹Ü··ÖÁÑ£»ÁíÒ»×éÖ¯NoName057(16)Ôò¶ÔÑ¡¾ÙǰϦµÄDDoS¹¥»÷ÕÆ¹Ü¡£µ¤Âóµý±¨²¿ÃÅÃ÷È·°µÊ¾£¬ÕâÁ½¸ö×éÖ¯¾ùÓë¶íÂÞ˹µ±¾Ö´æÔÚ¹ØÁª£¬ÊÇ¶í·½¶ÔÎ÷·½Ö´ÐлìºÏÕ½ÕùµÄ¡°¹¤¾ß¡±£¬ÆäÖ÷ÌâÖ¸±êÊÇÔì×÷²»°²È«¸Ð²¢·Ö»¯¹ú¼ÊÉç»á¶ÔÎÚÖ§³Ö¡£
https://www.securityweek.com/denmark-blames-russia-for-cyberattacks-ahead-of-elections-and-on-water-utility/
6. WatchGuard Firebox RCE·ì϶±»»ý¼«ÀûÓÃ
12ÔÂ19ÈÕ£¬WatchGuard½üÈÕ°ä²¼´¹Î£°²È«²¼¸æ£¬Åû¶ÆäFirebox·À»ðǽ´æÔÚÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2025-14733£¬¸Ã·ì϶Òѱ»ÍþвÐÐΪÕß»ý¼«ÀûÓã¬Ðèµ±¼´½¨²¹¡£·ì϶ԴÓÚÔ½½çдÈëȱµã£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚÅäÖÃIKEv2 VPNµÄÉ豸ÉÏÔ¶³ÌÖ´ÐжñÒâ´úÂ룬¹¥»÷¸´ÔӶȵÍÇÒÎÞÐèÓû§½»»¥¡£ÊÜÓ°ÏìÁìÓòÔ̺¬ÔËÐÐFireware OS 11.xÖÁ11.12.4_Update1¡¢12.xÖÁ12.11.5¼°2025.1ÖÁ2025.1.3µÄ·À»ðǽÉ豸£¬¾ßÌåÐͺź¸ÇT15¡¢T35¡¢T115-W¡¢M570¡¢Firebox CloudµÈÊýÊ®ÖÖÐͺţ¬Éæ¼°È«Çò³¬¹ý250,000¼ÒÖÐÓׯóÒµÓû§¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¼´±ãÖÎÀíԱɾ³ýÁËIKEv2 VPNÅäÖã¬ÈôÈÔ´æÔÚÏνӵ½¾²Ì¬Íø¹Ø¶ÔµÈÌåµÄ·ÖÖ§»ú¹¹VPN£¨BOVPN£©£¬É豸ÈÔ¿ÉÄܶ³öÓÚ¹¥»÷·çÏÕÖС£WatchGuardÒÑÌṩһʱ»º½â´ëÊ©£ºÖÎÀíÔ±Ó¦½ûÓö¯Ì¬¶ÔµÈBOVPN£¬Ôö³¤ÐµķÀ»ðǽսÊõÒÔÏÞ¶ÈVPNÁ÷Á¿£¬²¢½ûÓô¦ÖÃVPNÁ÷Á¿µÄĬÈÏϵͳսÊõ¡£Í¬Ê±£¬¹«Ë¾½¨ÒéÓû§Ê¹ÓÃÌṩµÄÈëÇÖÖ¸±ê²é³É豸ÊÇ·ñÒѱ»ÈëÇÖ£¬²¢ÂÖ»»ËùÓб¾µØ´æ´¢µÄÃÜÔ¿¡£
https://www.bleepingcomputer.com/news/security/watchguard-warns-of-new-rce-flaw-in-firebox-firewalls-exploited-in-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ