TikTokÊÓÆµ³É¶ñÒâÈí¼þ´«²¼ÐÂÔØÌå

°ä²¼¹¦·ò 2025-10-21

1. TikTokÊÓÆµ³É¶ñÒâÈí¼þ´«²¼ÐÂÔØÌå


10ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓüÙ×°³ÉWindows¡¢Spotify¡¢NetflixµÈÊ¢ÐÐÈí¼þÃâ·Ñ¼¤»îÖ¸ÄϵÄTikTokÊÓÆµ´«²¼ÇÔÊØÐÅÏ¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ISC Handler Xavier Mertens·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÓëTrend Micro½ñÄê5Ô¹۲쵽µÄ¹¥»÷ģʽ¸ß¶ÈÀàËÆ£¬£¬£¬£¬£¬£¬£¬Í¨¹ý"ClickFix"Éç»á¹¤³Ì¼¼ÊõÖ´Ðй¥»÷£¬£¬£¬£¬£¬£¬£¬ÊÓÆµÖÐչʾ¼ò¶ÌÊÙÁ£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§ÒÔÖÎÀíÔ±Éí·ÝÔÚPowerShellÖ´ÐС£¡£¡£¡£¡£¡£µ±Óû§Ö´ÐкÅÁîºó£¬£¬£¬£¬£¬£¬£¬PowerShell»áÏνÓÔ¶³ÌÕ¾µã£¬£¬£¬£¬£¬£¬£¬ÏÂÔØ²¢Ö´ÐÐÁíÒ»¸ö¾ç±¾¡£¡£¡£¡£¡£¡£¸Ã¾ç±¾´ÓCloudflareÒ³Ãæ»ñÈ¡Á½¸ö¿ÉÖ´ÐÐÎļþ£ºµÚÒ»¸öÊÇupdater.exe£¬£¬£¬£¬£¬£¬£¬ÊµÎªAura StealerÐÅÏ¢ÇÔÈ¡Èí¼þµÄ±äÖÖ£¬£¬£¬£¬£¬£¬£¬×¨ÃÅÍøÂçä¯ÀÀÆ÷±£ÁôµÄÍ´´¦¡¢Éí·ÝÑéÖ¤cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢µÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢»Ø´«ÖÁ¹¥»÷Õß·þÎñÆ÷£»£»£»£» £»µÚ¶þ¸öÊÇsource.exe£¬£¬£¬£¬£¬£¬£¬»áͨ¹ý.NETÄÚÖõÄC#±àÒëÆ÷×Ô±àÒë´úÂë²¢×¢ÈëÄÚ´æÔËÐУ¬£¬£¬£¬£¬£¬£¬¾ßÌåÖ°ÄÜÈÔÔÚµ÷²éÖС£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁìÓò¿í·º£¬£¬£¬£¬£¬£¬£¬Éæ¼°Windows¡¢Microsoft 365¡¢Adobe Premiere¡¢Photoshop¡¢CapCut Pro¡¢Discord NitroµÈºÏ·¨Èí¼þ¼°Netflix¡¢Spotify PremiumµÈÐé¹¹·þÎñµÄ"¼¤»î½Ì³Ì"¡£¡£¡£¡£¡£¡£°²È«×¨¼ÒÇ¿µ÷£¬£¬£¬£¬£¬£¬£¬Ö´ÐдËÀàºÅÁîµÄÓû§Ó¦Á¢¼´³ÁÖÃËùÓÐÕË»§ÃÜÂ룬£¬£¬£¬£¬£¬£¬ÒòÍ´´¦¿ÉÄÜÒÑй¶¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/tiktok-videos-continue-to-push-infostealers-in-clickfix-attacks/


2. ¹«¹²·¨¹ú¹«Ë¾Ôâ÷è÷ëÀÕË÷ÍŻ﹥»÷


10ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬µÂ¹ú¹«¹²Æû³µ¼¯ÍÅÆìÏ·¨¹ú×Ó¹«Ë¾¹«¹²Æû³µ¼¯ÍÅ·¨¹ú¹«Ë¾ÓÚ10ÔÂ14ÈÕÔâ÷è÷ëÍøÂç·¸×ïÍÅ»ïÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£÷è÷ëÐû³ÆÇÔȡԼ2000·ÝÎļþ¼°150GBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô̺¬¿Í»§¡¢Ô±¹¤¼°ÒµÎñÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼Áù·ÝÑù±¾Îļþ×ôÖ¤£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÄÚÈÝÉæ¼°³µÖ÷ÐÕÃû¡¢µØÖ·¡¢ÓÊÏä¡¢³µÐÍ¡¢VINÂë¼°³µÉ̱êµÈÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¹«¹²·¨¹ú¹«Ë¾³ÉÁ¢ÓÚ1960Ä꣬£¬£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚάÀ³¿ÆÌØÀ×£¬£¬£¬£¬£¬£¬£¬Õƹܰµϡ¢Î÷ÑÅÌØ¡¢CUPRA¡¢Ë¹¿Â´ï¼°¹«¹²ÉÌÓóµÔÚ·¨ÓªÏú·ÖÏú¡£¡£¡£¡£¡£¡£÷è÷ëÒѳÉΪ2025Äê×î»îÔ¾ÀÕË÷ÍŻ£¬£¬£¬£¬£¬£¬´Óǰ12¸öÔ¹¥»÷Ô¼585ÃûÊܺ¦Õß¡£¡£¡£¡£¡£¡£ÆäѡȡÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐË«³ÁÀÕË÷£ºÏÈÒªÇó½âÃÜÊê½ð£¬£¬£¬£¬£¬£¬£¬ÔÙÍþвй¶Êý¾Ý¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯»îÔ¾ÓÚ¶íÓïºÚ¿ÍÂÛ̳£¬£¬£¬£¬£¬£¬£¬Ô¤·À¹¥»÷¶ÀÁªÌå¹ú¶È£¬£¬£¬£¬£¬£¬£¬°µÊ¾Óë¿ËÀïÄ·ÁÖ¹¬¹ØÁª¡£¡£¡£¡£¡£¡£


https://cybernews.com/news/volkswagen-france-ransomware-attack-qilin-group-claims/


3. ÃÀ¹úºÍ¼ÓÄôó¶à¸ö»ú³¡¹«¹²¹ã²¥ÏµÍ³ÔâºÚ¿Í¹¥»÷


10ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÕë¶Ô¼ÓÄôóÓëÃÀ¹úµÄËĸöÖ§Ïß»ú³¡ÌáÒéЭͬ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÈëÇÖ¹«¹²¹ã²¥ÏµÍ³¡¢º½°àÐÅÏ¢ÏÔʾÆÁµÈÉèÊ©£¬£¬£¬£¬£¬£¬£¬²¥·ÅÔÞÑï¹þÂí˹¼°Æ·ÆÀÃÀ¹úǰ×ÜÍ³ÌØÀÊÆÕµÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ôì³É²¿ÃÅÔËÓª»ìÂÒ¡£¡£¡£¡£¡£¡£ÉæÊ»ú³¡Ô̺¬¼ÓÄôó²»Áе߸çÂ×±ÈÑÇÊ¡µÄ»ùÂåÄɹú¼Ê»ú³¡¡¢Î¬¶àÀûÑǹú¼Ê»ú³¡¡¢°²´ÖÂÔÊ¡ÎÂɯ¹ú¼Ê»ú³¡£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÃÀ¹ú±öϦ·¨ÄáÑÇÖݹþÀï˹±¤¹ú¼Ê»ú³¡¡£¡£¡£¡£¡£¡£¾Ý¼ÓÄôó»Ê¼ÒÆï¾¯´«µÝ£¬£¬£¬£¬£¬£¬£¬»ùÂåÄÉ»ú³¡µÄ¡°¸æ°×Á÷ýÌå·þÎñ¡±Ôø¶ÌÔݱ»Ö²Èëδ¾­ÊÚȨÄÚÈÝ£»£»£»£» £»Î¬¶àÀûÑÇ»ú³¡Ôòͨ¹ýµÚÈý·½Èí¼þ·ì϶ÔâÈëÇÖ£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í²¥·Å±íÓïÐÅÏ¢¼°ÒôÀÖ£¬£¬£¬£¬£¬£¬£¬»ú³¡ËæºóÇл»ÖÁÄÚ²¿ÏµÍ³¸´Ô­½ÚÔì¡£¡£¡£¡£¡£¡£ÎÂɯ»ú³¡º½°àÐÅÏ¢ÏÔʾÆÁÓë¹ã²¥ÏµÍ³Í¬Ñù±»ÇÖÈ룬£¬£¬£¬£¬£¬£¬ÏÔʾ¡°Î´¾­ÊÚȨµÄͼÏñºÍ²¼¸æ¡±£¬£¬£¬£¬£¬£¬£¬Æä»ùÓÚÔÆµÄÈí¼þÌṩÉ̳ÉΪ¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬ÏµÍ³Ôڶ̹¦·òÄÚ¸´Ô­Õý³£¡£¡£¡£¡£¡£¡£ÃÀ°î½»Í¨²¿³¤Ð¤¶÷¡¤´ï·ÆÖ¤Êµ£¬£¬£¬£¬£¬£¬£¬¹þÀï˹±¤»ú³¡¹ã²¥ÏµÍ³Òà±»ºÚ¿Í½ÚÔ죬£¬£¬£¬£¬£¬£¬ÃÀ¹úÁª¹úº½¿ÕÖÎÀí¾Ö£¨FAA£©Õý½áºÏ»ú³¡·½·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/us-canada-airport-hacked/


4. ¶íÂÞ˹LynxÈëÇÖÓ¢¹ú¹ú·À³Ð°üÉÌÖÂÃô¸Ð¾üÊÂÎļþй¶


10ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬¶íÂÞË¹ÍøÂç·¸×OÍÅLynx¶ÔÓ¢¹ú¹ú·À²¿³Ð°üÉ̶àµÂ¼¯ÍÅ£¨Dodd Group£©ÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡²¢Ð¹Â¶ÁËÓ¢¹ú»Ê¼Ò¿Õ¾ü¼°»Ê¼Òˮʦ°Ë¸ö»ùµØµÄÊý°Ù·ÝÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñ²úÉúÔÚ9ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬±»¡¶ÖðÈÕÓʱ¨¡·³ÆÎª¡°¿àÄÑÐÔ¡±ÊÂÎñ¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾Ýº­¸ÇÔ±¹¤ÐÕÃû¡¢µç×ÓÓʼþ¡¢³Ð°üÉÌÁªÏµ·½Ê½¡¢³µÁ¾ÐÅÏ¢¼°ÏóÕ÷Ϊ¡°Êܿء±»ò¡°¹Ù·½Ãô¸Ó×±µÄ¹ú·À²¿Ô±¹¤Í¨Ñ¶Â¼£¬£¬£¬£¬£¬£¬£¬Éæ¼°Ó¢¹ú¹Ø¼ü¾üÊÂÉèÊ©µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¶àµÂ¼¯ÍÅ×÷ΪӢ¹úµ±ÏȵÄ˽Ӫ¹¤³ÌÓëÉèÊ©ÖÎÀí¹«Ë¾£¬£¬£¬£¬£¬£¬£¬Õ¼Óг¬1100ÃûÔ±¹¤£¬£¬£¬£¬£¬£¬£¬³Ö¾Ã³Ð½Ó¹ú·À¡¢½ÌÓý¡¢Ò½ÁƵÈÁìÓòµÄ³Á´óÏîÄ¿£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÎªÓ¢¹ú¹ú·À²¿Ìá¹©ÊØ»¤Ó뽨É蹤³Ì¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þÍŻォÆäÁÐÈëTorÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬Ðû³ÆÇÔȡԼ4TBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ½»Éæ·ÖÁѺóÖð²½¹«¿ªÎļþ¡£¡£¡£¡£¡£¡£Ð¹Â¶ÄÚÈݾ۽¹ÓÚÈý¸öÕ½Êõ¸¹µØ£ºÈø¸£¿£¿£¿£¿ £¿£¿Ë¿¤À³¿Ïϣ˼»Ê¼Ò¿Õ¾ü»ùµØ£¨×¤ÔúÃÀ¹úF-35ÒþÐÎÕ½»ú²¢ÒÉËÆ´æ´¢ºËµ¯£©¡¢²¨ÌØÀï˹»ùµØ£¨±±Ô¼·À¿ÕÍøÂç¾øÃÜÀ×´ïÕ¾£©¼°ÆÕÀ×µ¤Äɿ˻ùµØ£¨Ó¢¹ú¹ú¶ÈÎÞÈË»úÖÐÐÄ£©¡£¡£¡£¡£¡£¡£¾ßÌåÎļþÔ̺¬³¬1000·Ý·Ã¿ÍÈÕÖ¾¡¢ÄÚ²¿Óʼþ¡¢°²È«Ö¸Äϼ°Ê©¹¤¼Í¼£¬£¬£¬£¬£¬£¬£¬¸æ·¢ÁË»ùµØµÄ²Ù×÷ϸ½ÚÓ밲ȫ·ì϶¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/183640/data-breach/russian-lynk-group-leaks-sensitive-uk-mod-files-including-info-on-eight-military-bases.html


5. ÎÞÓ¡Á¼Æ·Òò¹©¸øÉÌÔâÀÕË÷Èí¼þ¹¥»÷ÖÂÈÕ±¾ÃŵêÎïÁ÷ÖжÏ


10ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬ÈÕ±¾ÁãÊÛ¾ÞÍ·ÎÞÓ¡Á¼Æ·ÒòÅäËͺÏ×÷ͬ°éAskulÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÈÕ±¾µØÓòÎïÁ÷ϵͳ̱»¾£¬£¬£¬£¬£¬£¬£¬±»ÆÈ¹Ø¹ØÃŵ겢ÔÝÍ£¶àÏîÔÚÏß·þÎñ¡£¡£¡£¡£¡£¡£ÊÂÎñʼÓÚÈÕ±¾Ê±ÇøÖÜÈÕÍí¼ä£¬£¬£¬£¬£¬£¬£¬ÎÞÓ¡Á¼Æ·°ä²¼ÉêÃ÷³Æ£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷µ¼ÖÂËùÓÐÁãÊÛ·þÎñÅö±Ú£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÍøÉÏÉ̵êä¯ÀÀ¡¢¹ºÎï¡¢¶©µ¥º¹Çà²éÎʼ°²¿ÃÅÍøÒ³ÄÚÈÝÏÔʾÒì³£¡£¡£¡£¡£¡£¡£Ö»¹Ü¹«Ë¾Î´Ã÷ȷϵͳ¸´Ô­¹¦·ò±í£¬£¬£¬£¬£¬£¬£¬µ«ÖÜÒ»ÏÂÎç¸üÐÂÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÔÚÏß¹ºÎïºÍ°üÔ·þÎñÈÔÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£ÎÞÓ¡Á¼Æ·×÷ΪȫÇò¼òÔ¼¼Ò¾ÓÓÃÆ·¡¢·þ×°¼°¼Ò¾ßÁãÊÛÉÌ£¬£¬£¬£¬£¬£¬£¬ÔÚÈÕ±¾¡¢Öйú¡¢ÐÂ¼ÓÆÂ¡¢Å·ÖÞ¡¢°Ä´óÀûÑǺͱ±ÃÀÕ¼Óг¬Ç§¼ÒÃŵ꣬£¬£¬£¬£¬£¬£¬ÄêÊÕÈëÔ¼40ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬£¬È«ÇòÔ±¹¤³¬24,500Ãû¡£¡£¡£¡£¡£¡£Õâ´ÎÖжϽöÓ°ÏìÈÕ±¾µØÓò£¬£¬£¬£¬£¬£¬£¬ÒòAskulÕÆ¹ÜÆäÈÕ±¾±¾ÍÁÎïÁ÷ÒµÎñ¡£¡£¡£¡£¡£¡£AskulΪÑÅ»¢ÈÕ±¾ÆìÏ´óÐÍB2B/B2C°ì¹«ÓÃÆ·¼°ÎïÁ÷µçÉÌÆóÒµ£¬£¬£¬£¬£¬£¬£¬Æä²¼¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þϰȾµ¼ÖÂϵͳ¹ÊÕÏ£¬£¬£¬£¬£¬£¬£¬ÒÑÔÝÍ£¶©µ¥´¦Öᢷ¢»õ¡¢²úÆ·ÍË»õ¡¢ÊÕÌõÓʼļ°Ä¿Â¼ÔËË͵ȷþÎñ£¬£¬£¬£¬£¬£¬£¬¿Í»§·þÎñ̨ÒàÎÞ·¨Í¨¹ýµç»°»òÍøÕ¾ÁªÏµ¡£¡£¡£¡£¡£¡£¹«Ë¾Õýµ÷²éÊý¾Ýй¶ÁìÓò£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ó×ÎÒÐÅÏ¢ºÍ¿Í»§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢³Ðŵʵʱ´«µÝ½øÕ¹¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/retail-giant-muji-halts-online-sales-after-ransomware-attack-on-supplier/


6. CISAÖÒ¸æWindows SMBȨÏÞÌáÉý·ì϶Õý±»»îÔ¾ÀûÓÃ


10ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬Ö¸³öÍþвÐÐΪÕßÕý»ý¼«ÀûÓøßÑϳÁÐÔµÄWindows SMBȨÏÞÌáÉý·ì϶CVE-2025-33073¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìËùÓÐWindows Server°æ±¾¡¢Windows 10¼°×î¸ßÖÁWindows 11 24H2µÄWindows 11ϵͳ£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÔÚ佨²¹µÄϵͳÉÏ»ñÈ¡SYSTEMȨÏÞ£¬£¬£¬£¬£¬£¬£¬×é³É³Á´ó°²È«Íþв¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚ2025Äê6Ô²¹¶¡ÐÇÆÚ¶þÆÚ¼äÒѽ¨¸´´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬²¢Åû¶Æä±¾Ô­ÔÚÓÚ²»µ±µÄ½Ó¼û½ÚÔìÈõµã£¬£¬£¬£¬£¬£¬£¬Ê¹ÊÚȨ¹¥»÷Õß¿Éͨ¹ýÍøÂçÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¾ßÌå¹¥»÷õ辶Ϊ£º¹¥»÷ÕßÓÕʹÊܺ¦ÕßÏνÓÖÁ¶ñÒâ½ÚÔìµÄSMB·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐÌØÔì¾ç±¾Ç¿ÔìÊܺ¦ÕßÍÆËã»ú³ÁÐÂÏνӲ¢ÑéÖ¤Éí·Ý£¬£¬£¬£¬£¬£¬£¬×îÖÕʵÏÖȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£CISAÒѽ«CVE-2025-33073ÁÐÈë¡°ÒÑÖª±»ÀûÓ÷ì϶Ŀ¼¡±£¬£¬£¬£¬£¬£¬£¬²¢Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄÔËÓªÖ¸ÁîBOD 22-01£¬£¬£¬£¬£¬£¬£¬ÒªÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÔÚ2025Äê11ÔÂ10ÈÕǰʵÏÖϵͳ½¨²¹¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-high-severity-windows-smb-flaw-now-exploited-in-attacks/