÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÈëÇÖÎÚ¿ËÀ¼±í½»²¿
°ä²¼¹¦·ò 2025-03-071. ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÈëÇÖÎÚ¿ËÀ¼±í½»²¿
3ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÒѳɹ¦ÈëÇÖÎÚ¿ËÀ¼±í½»²¿£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»´Î³Á´óµÄÍøÂ簲ȫÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯Ðû³ÆÇÔÈ¡ÁËÔ̺¬¸öÈËͨѶ¡¢Ó×ÎÒÐÅÏ¢ºÍ¹Ù²½ÖèÁîÔÚÄÚµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢Òѽ«²¿ÃÅÊý¾ÝÏúÊÛ¸øµÚÈý·½£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÔÚÆäTorйÃÜÍøÕ¾Éϰ䲼ÁËһϵÁб»µÁÎļþµÄͼÏñ×÷Ϊ֤¾Ý¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼±í½»²¿ÉÐδ¶ÔÕâÒ»Êý¾Ýй¶ÊÂÎñ½øÐÐ֤ʵ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷±»ÊÓΪ¶íÂÞ˹ºÍÎÚ¿ËÀ¼³ÖÐøÃ¬¶ÜÖлìºÏÕ½ÕùÉý¼¶µÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÓë¿ËÀïÄ·ÁÖ¹¬Õ½ÊõÒ»ÖµĺڿͻºÍÍøÂç·¸×OÍÅÓйء£¡£¡£¡£¡£¡£¡£÷è÷ëÀÕË÷Èí¼þ×éÖ¯×Ô2022ÄêÆð»îÔ¾£¬£¬£¬£¬£¬£¬£¬ÔøÒò¹¥»÷Ó¢¹úµ±¾ÖÒ½ÁÆ·þÎñÌṩÉÌSynnovis¶øÊܵ½¹Ø×¢£¬£¬£¬£¬£¬£¬£¬Í¨³£Ñ¡È¡¡°Ë«³ÁÀÕË÷¡±¼¿Á©¡£¡£¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯»¹Ðû³Æ¶ÔÓ°ÏìÊýÊ®¼Ò±¾µØ±¨Ö½µÄÀîÊÏÆóÒµÍøÂç¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£¡£ÀîÊÏÆóÒµÊÇÒ»¼ÒÉÏÊеÄÃÀ¹úýÌ幫˾£¬£¬£¬£¬£¬£¬£¬ÔÚ¶à¸öÖݳö°æ´óÁ¿±¨Ö½ºÍÖÜ¿¯¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÔÙ´Î͹ÏÔÁËÍøÂ簲ȫµÄ³ÁÒªÐÔ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÀÕË÷Èí¼þ×éÖ¯¶ÔÈ«ÇòÆóÒµºÍµ±¾Ö»ú¹¹×é³ÉµÄÍþв¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/175025/cyber-crime/qilin-ransomware-ministry-of-foreign-affairs-of-ukraine.html
2. ΢Èíɾ³ý¶ñÒâ¸æ°×»î¶¯ËùÓÃGitHub´æ´¢¿â£¬£¬£¬£¬£¬£¬£¬½ü°ÙÍòÉ豸ÊÜÓ°Ïì
3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚ2024Äê12Ô³õ¼ì²âµ½Ò»´Î´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ó°ÏìÁËÈ«Çò½üÒ»°ÙÍǫ̀É豸¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÔÚ·¸·¨µÁ°æÁ÷ýÌåÍøÕ¾µÄÊÓÆµÖÐ×¢Èë¶ñÒâ¸æ°×³Á¶¨ÏòÆ÷£¬£¬£¬£¬£¬£¬£¬½«Ç±ÔÚÊܺ¦Õß³Á¶¨Ïòµ½ËûÃǽÚÔìµÄ¶ñÒâGitHub´æ´¢¿â¡£¡£¡£¡£¡£¡£¡£ÕâЩ´æ´¢¿âÖеĶñÒâÈí¼þ»áϰȾÓû§ÏµÍ³£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐϵͳ·¢ÏÖ¡¢ÍøÂç¾ßÌåµÄϵͳÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ²¿Êð¶î±íµÄµÚ¶þ½×¶ÎÓÐÐ§ÔØºÉʱÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£ÔÚµÚÈý½×¶Î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áÏÂÔØNetSupportÔ¶³Ì½Ó¼ûľÂí£¨RAT£©ºÍÆäËûÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÈçLummaºÍDoenerium£¬£¬£¬£¬£¬£¬£¬À´ÇÔÈ¡Óû§Êý¾ÝºÍä¯ÀÀÆ÷Í´´¦¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»GitHubÊÇÕâ´Î»î¶¯µÚÒ»½×¶Î½»¸¶ÓÐÐ§ÔØºÉµÄÖØÒªÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬µ«Microsoft Threat IntelligenceÒ²¹Û²ìµ½ÔÚDropboxºÍDiscordÉÏÍйܵÄÓÐÐ§ÔØºÉ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯ÓµÓÐÎÞ²î¾àÐÔ£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË¿í·ºµÄ×éÖ¯ºÍÐÐÒµ£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ïû·ÑÕßºÍÆóÒµÉ豸¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÓá°Storm-0408¡¹Øâ¸ö×ܳÆÀ´×·×ÙÕâÒ»»î¶¯£¬£¬£¬£¬£¬£¬£¬²¢ÌṩÁËÓйØÕâ´Î¸´ÔÓ¶ñÒâ¸æ°×»î¶¯µÄ¶à½×¶Î¹¥»÷Á´Öй¥»÷µÄ¸÷¸ö½×¶ÎºÍËùʹÓõÄÓÐÐ§ÔØºÉµÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/microsoft-says-malvertising-campaign-impacted-1-million-pcs/
3. AkiraÀÕË÷Èí¼þÍÅ»ïÀûÓÃÍøÂçÉãÏñÍ·ÈÆ¹ýEDRÌáÒé¹¥»÷
3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬AkiraÀÕË÷Èí¼þÍÅ»ïѡȡÁËÒ»ÖÖ²»Ñ°³£µÄ¹¥»÷²½Ö裬£¬£¬£¬£¬£¬£¬ÀûÓò»°²È«µÄÍøÂçÉãÏñÍ·¶ÔÊܺ¦ÕßÍøÂçÌáÒé¼ÓÃܹ¥»÷£¬£¬£¬£¬£¬£¬£¬³É¹¦ÈƹýÁËWindowsÖеĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©¹¤¾ß¡£¡£¡£¡£¡£¡£¡£ÍøÂ簲ȫ¹«Ë¾S-RMÔÚÒ»´ÎÊÂÎñÏìÓ¦Öз¢ÏÖÁËÕâÒ»¹¥»÷·½Ê½¡£¡£¡£¡£¡£¡£¡£AkiraÍÅ»ïÊ×ÏÈͨ¹ýÔ¶³Ì½Ó¼û½â¾ö¹æ»®½øÈë¹«Ë¾ÍøÂ磬£¬£¬£¬£¬£¬£¬²¿ÊðºÏ·¨µÄÔ¶³Ì½Ó¼û¹¤¾ßAnyDeskÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©½øÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬µ±ËûÃÇÔÚWindowsÉϲ¿ÊðÀÕË÷Èí¼þ¸ºÔØÊ±±»EDR¹¤¾ß×èÖ¹¡£¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬£¬£¬AkiraɨÃèÍøÂçѰÕÒÆäËûÉ豸£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÁËÒ×Êܹ¥»÷µÄÍøÂçÉãÏñÍ·ºÍÖ¸ÎÆÉ¨ÃèÒÇ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÍøÂçÉãÏñÍ·ÔËÐÐLinux²Ù×÷ϵͳÇÒûÓÐEDR´úÀí£¬£¬£¬£¬£¬£¬£¬AkiraÑ¡ÔñÀûÓÃËü¹ÒÔØ¹«Ë¾ÆäËûÉ豸µÄWindows SMBÍøÂç¹²Ïí£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÍøÂçÉãÏñÍ·ÉÏÆô¶¯Linux¼ÓÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬³É¹¦¼ÓÃÜÁËSMBÉϵÄÍøÂç¹²ÏíÎļþ¡£¡£¡£¡£¡£¡£¡£S-RMÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÒÑÓÐÕë¶ÔÍøÂçÉãÏñÍ··ì϶µÄ²¹¶¡£¬£¬£¬£¬£¬£¬£¬Åú×¢Õâ´Î¹¥»÷ÊÇ¿ÉÔ¤·ÀµÄ¡£¡£¡£¡£¡£¡£¡£´Ë°¸ÀýÇ¿µ÷ÁËEDR±£»£»£»£»£»¤²¢·ÇÈ«Ãæ°²È«½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬£¬ÎïÁªÍøÉ豸ҲӦÓëÃô¸ÐÍøÂç¸ôÀë²¢¶¨ÆÚ¸üй̼þÒÔ½¨²¹·ì϶¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/akira-ransomware-encrypted-network-from-a-webcam-to-bypass-edr/
4. StubHubƱÎñÔ±¹¤µÁÊÛǧÓàÕÅÒôÀÖ»áÃÅÆ±Ôâ¸æ×´
3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬Å¦Ô¼¼ì²ì¹ÙÖ¸¿ØStubHubÔÚÏ߯±ÎñÊг¡µÄÁ½ÃûµÚÈý·½³Ð°üÉ̹¤×÷ÈËÔ±ÉæÏÓ͵ÇÔ²¢×ªÊÛ½ü1000ÕŸ߼ÛÖµÒôÀÖ»áÃÅÆ±£¬£¬£¬£¬£¬£¬£¬×¬È¡635,000ÃÀÔª¡£¡£¡£¡£¡£¡£¡£ÕâЩÃÅÆ±´óÎÞÊýÊÇÌ©ÀÕ¡¤Ë¹Íþ·òÌØµÄEras TourÃÅÆ±£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû³ÛÃû»î¶¯ÈçEd Sheeran¡¢AdeleÑݳª»á¡¢NBA½ÇÖðºÍÃÀ¹úÍøÇò¹«¿ªÈüµÄÃÅÆ±¡£¡£¡£¡£¡£¡£¡£Á½Ãû±»ÎÕ±ðÀëÊÇ20ËêµÄ̩¡¡¤ÂÞ˹ºÍ31ËêµÄɯÂêÀ¡¤Î÷ÃÉ˹£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚÑÀÂò¼ÓÈøÉªÀ¼È«Çò·þÎñ¹«Ë¾¹¤×÷£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÀ밶ƱÎñ¹©¸øÉÌÆ½Ì¨µÄ·ì϶À¹½ØÁËÔ¼350·ÝStubHub¶©µ¥£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÃÅÆ±¡£¡£¡£¡£¡£¡£¡£ËûÃǾݳÆÍ¨¹ý½Ó¼ûStubHubÍÆËã»úϵͳ£¬£¬£¬£¬£¬£¬£¬ÕÒµ½ºóÃŽøÈëÍøÂç°²È«ÇøÓò£¬£¬£¬£¬£¬£¬£¬½«ÒÑÊÛ³öÃÅÆ±µÄURL³Á¶¨Ïòµ½Í¬Ä±µÄµç×ÓÓʼþÉÏ¡£¡£¡£¡£¡£¡£¡£Á½ÈËÒÑÔÚŦԼÊб»²¶£¬£¬£¬£¬£¬£¬£¬²¢Ãæ¶Ô¶àÏîÐÌÊÂÖ¸¿Ø£¬£¬£¬£¬£¬£¬£¬Ò»µ©×ïÃû³ÉÁ¢£¬£¬£¬£¬£¬£¬£¬½«Ãæ¶Ô×î¸ß15ÄêµÄ½ûïÀ¡£¡£¡£¡£¡£¡£¡£Õâ´Î½ø¹¥Ðж¯Í¹ÏÔÁË´¦Ëù¼ì²ì¹Ù°ì¹«ÊÒ¶ÔÍøÂç·¸×ïµÄ¾¯ÌèÐÔ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓëÐÐÒµºÏ×÷ͬ°é½ø¹¥Ú²Æ»î¶¯ºÍÈ·±£Ïû·ÑÕß±£»£»£»£»£»¤µÄ³ÁÒªÐÔ¡£¡£¡£¡£¡£¡£¡£µ÷²éÈÔÔÚ½øÐÐÖУ¬£¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨Õâ´ÎÐж¯µÄ¹æÄ£ºÍÆäËûDZÔÚͬı¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cybercrime-crew-stole-635-000-in-taylor-swift-concert-tickets/
5. PyPIÉϵÄÒÔÌ«·»Ë½Ô¿ÇÔÈ¡·¨Ê½±»ÏÂÔØ³¬¹ý 1,000 ´Î
3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪ¡°set-utils¡±µÄ¶ñÒâPython°üÔÚPyPIÉϱ»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬¸Ã°ü¼Ù×°³ÉʵÓõŤ¾ß°ü£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÀ¹½ØÒÔÌ«·»Ç®°ü´´½¨Ö°ÄÜÇÔȡ˽Կ£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýPolygonÇø¿éÁ´½«Æäй¶¡£¡£¡£¡£¡£¡£¡£×Ô2025Äê1ÔÂ29ÈÕÌá½»ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬¸Ã°üÒѱ»ÏÂÔØÒ»Ç§ÂŴΣ¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÇø¿éÁ´¿ª·¢ÈËÔ±¡¢»ùÓÚPythonµÄDeFiÏîÄ¿¡¢Ö§³ÖÒÔÌ«·»µÄWeb3ÀûÓ÷¨Ê½ÒÔ¼°Ê¹ÓÃPython×Ô¶¯»¯µÄÓ×ÎÒÇ®°ü¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ°üǶÈëÁ˹¥»÷ÕßµÄRSA¹«Ô¿£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¼ÓÃܱ»µÁµÄ˽Կ£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäǶÈëµ½ÒÔÌ«·»ÂòÂôµÄÊý¾Ý×Ö¶ÎÖУ¬£¬£¬£¬£¬£¬£¬Í¨¹ýPolygon RPC¶Ëµã·¢Ë͵½¹¥»÷ÕßµÄÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ²½ÖèÏà¶ÔÒñ±Î£¬£¬£¬£¬£¬£¬£¬²»Ò×±»·À»ðǽºÍ·À²¡¶¾¹¤¾ß¼ì²âµ½¡£¡£¡£¡£¡£¡£¡£Ò»µ©Êý¾Ýй¶¹ý³ÌʵÏÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ËæÊ±¼ìË÷±»µÁÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ±»µÁÐÅÏ¢»áÓÀÔ¶´æ´¢ÔÚÇø¿éÁ´ÉÏ¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã°üÒѱ»´ÓPyPIÖÐɾ³ý£¬£¬£¬£¬£¬£¬£¬µ«Òѽ«ÆäÄÉÈëÏîÖ÷ÕÅÓû§ºÍÈí¼þ¿ª·¢ÈËÔ±Ó¦Á¢¼´Ð¶ÔØËü£¬£¬£¬£¬£¬£¬£¬²¢Èç¹û´´½¨µÄÈκÎÒÔÌ«·»Ç®°ü¶¼ÒÑÊܵ½Íþв£¬£¬£¬£¬£¬£¬£¬¾¡¿ì×ªÒÆ×ʽðÒÔÔ¤·À±»µÁ·çÏÕ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ethereum-private-key-stealer-on-pypi-downloaded-over-1-000-times/
6. ³¬¹ý1000¸öWordPressÍøÕ¾Ôâ¶ñÒâJavaScript´úÂë¹¥»÷
3ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬³¬¹ý1000¸öÓÉWordPressÖ§³ÖµÄÍøÕ¾±»µÚÈý·½JavaScript´úÂëϰȾ£¬£¬£¬£¬£¬£¬£¬¸Ã´úÂëÖ²ÈëÁËËĸö¶ÀÁ¢ºóÃÅ£¬£¬£¬£¬£¬£¬£¬Îª¹¥»÷ÕßÌṩ¶à³ÁÈëÇÖõè¾¶¡£¡£¡£¡£¡£¡£¡£ÕâЩºóÃÅÔ̺¬Ò»¸öÃûΪ¡°Ultra SEO Processor¡±µÄÐéα²å¼þ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÖ´Ðй¥»÷ÕߺÅÁ£»£»£»£»Ïòwp-config.php×¢Èë¶ñÒâJavaScript£»£»£»£»£»Ïò~/.ssh/authorized_keysÔö³¤SSHÃÜÔ¿ÒÔʵÏÖÔ¶³Ì½Ó¼û£»£»£»£»£»ÒÔ¼°´Ógsocket[.]io»ñÈ¡ÔØºÉÒÔ´ò¿ª·´Ïòshell¡£¡£¡£¡£¡£¡£¡£Îª½µµÍ·çÏÕ£¬£¬£¬£¬£¬£¬£¬Óû§±»½¨Òéɾ³ýδÊÚȨSSHÃÜÔ¿¡¢¸ü»»WordPressÖÎÀíÔ±ÃÜÂ룬£¬£¬£¬£¬£¬£¬²¢¼à¿ØÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬£¬£¬ÒÑÓг¬¹ý35000¸öÍøÕ¾Ôâ¶ñÒâJavaScriptÈëÇÖ£¬£¬£¬£¬£¬£¬£¬µ¼Ö½ӼûÕß±»³Á¶¨ÏòÖÁÖÐÎÄ´ò¶Äƽ̨¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬ÃûΪScreamedJungleµÄÍþвÐÐΪÕßͨ¹ý×¢ÈëBablosoft JS¾ç±¾£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË115¸öÒÔÉϵÄMagentoÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÍøÂçÓû§Ö¸ÎÆÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÒÑÖª·ì϶£¬£¬£¬£¬£¬£¬£¬ÈçCVE-2024-34102ºÍCVE-2024-20720£¬£¬£¬£¬£¬£¬£¬½øÐÐÍøÕ¾ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£Group-IBÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ä¯ÀÀÆ÷Ö¸ÎÆ¼ø±ð¼¼ÊõËä³£ÓÃÓÚÓû§¸ú×ÙºÍÓªÏúÕ½Êõ£¬£¬£¬£¬£¬£¬£¬µ«Ò²±»·¸×ï·Ö×ÓÓÃÓÚ·ÂÕպϷ¨Óû§¡¢Ìӱܰ²È«´ëÊ©¼°Ö´ÐÐڲơ£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/03/over-1000-wordpress-sites-infected-with.html


¾©¹«Íø°²±¸11010802024551ºÅ