ÐÂÐ͹©¸øÁ´¹¥»÷GlassWormͨ¹ýVS CodeÊг¡Ï°È¾¿ª·¢Õß

°ä²¼¹¦·ò 2025-10-22

1. ÐÂÐ͹©¸øÁ´¹¥»÷GlassWormͨ¹ýVS CodeÊг¡Ï°È¾¿ª·¢Õß


10ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬Ò»ÖÖÃûΪGlassWormµÄ×ÔÎÒ´«²¼¶ñÒâÈí¼þÕýͨ¹ýOpenVSXºÍMicrosoft Visual StudioÊг¡ÌáÒ鹩¸øÁ´¹¥»÷£¬ £¬£¬£¬£¬£¬ÒÑÔì³ÉÔ¼35,800´Î×°Ö㬠£¬£¬£¬£¬£¬³ÉΪÊ×ÀýÕë¶ÔVS CodeµÄÈä³æÊ½¹©¸øÁ´¹¥»÷°¸Àý¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÀûÓÃÒþÐÎUnicode×Ö·û°µ²Ø¶ñÒâ´úÂ룬 £¬£¬£¬£¬£¬Í¨¹ýÇÔÈ¡µÄÕË»§ÐÅÏ¢´«²¼ÖÁ¸ü¶à¿É½Ó¼ûµÄÀ©´ó·¨Ê½£¬ £¬£¬£¬£¬£¬²¢Ñ¡È¡SolanaÇø¿éÁ´½øÐп¹É¾³ýµÄºÅÁî½ÚÔ죬 £¬£¬£¬£¬£¬Í¬Ê±ÒÔGoogleÈÕÀú×÷Ϊ±¸ÓÃͨ·¡£¡£¡£ ¡£¡£¹¥»÷õè¾¶ÏÔʾ£¬ £¬£¬£¬£¬£¬GlassWormÔÚ×°Öúó»áÇÔÈ¡GitHub¡¢npm¡¢OpenVSXÕË»§Í´´¦¼°49¸öÀ©´óµÄ¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý£¬ £¬£¬£¬£¬£¬²¿ÊðSOCKS´úÀí·ÓɶñÒâÁ÷Á¿£¬ £¬£¬£¬£¬£¬²¢×°ÖÃVNC¿Í»§¶ËʵÏÖÒþÐÎÔ¶³Ì½Ó¼û¡£¡£¡£ ¡£¡£Æä×îÖÕÓÐÐ§ÔØºÉZOMBIͨ¹ýSolanaÇø¿éÁ´ÂòÂôÁ´½Ó·Ö·¢£¬ £¬£¬£¬£¬£¬½«ÊÜϰȾϵͳת»¯ÎªÍøÂç·¸×ï½Úµã¡£¡£¡£ ¡£¡£×êÑÐÖ¸³ö£¬ £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹ÀûÓÃBitTorrent DHT½øÐзÖÉ¢ºÅÁî·Ö·¢£¬ £¬£¬£¬£¬£¬²¢Ö§³ÖÖ±½ÓÏνÓIPµØÖ·µÄµÚÈý½»¸¶»úÔì¡£¡£¡£ ¡£¡£½ØÖÁ»ã±¨°ä²¼£¬ £¬£¬£¬£¬£¬OpenVSXÉÏÖÁÉÙ11¸öÀ©´ó¼°VS CodeÊг¡1¸öÀ©´ó±»Ï°È¾¡£¡£¡£ ¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬OpenVSXÉÏÈÔÓÐÖÁÉÙ4¸öÊÜϰȾÀ©´ó¿ÉÏÂÔØ£¬ £¬£¬£¬£¬£¬Î¢ÈíÒÑÒÆ³ý¶ñÒâÀ©´ó£¬ £¬£¬£¬£¬£¬²¿ÃŰ䲼ÕßÒѸüн¨¸´¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/self-spreading-glassworm-malware-hits-openvsx-vs-code-registries/


2. ºÚ¿ÍÐû³Æ±íÂôƽ̨GetirÊý¾Ýй¶


10ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬ÍÁ¶úÆä±íÂôƽ̨Getir½üÈÕÏÝÈëÊý¾Ýй¶ÕùÒé¡£¡£¡£ ¡£¡£¹¥»÷ÕßÔÚÈȵãÊý¾Ýй¶ÂÛ̳°ä²¼Ìû×Ó£¬ £¬£¬£¬£¬£¬Ðû³ÆÒÑ¡°ÈëÇÖ¡±¸Ã¹«Ë¾ÄÚÍøÏµÍ³¡£¡£¡£ ¡£¡£¾Ý¹¥»÷ÕßÅû¶µÄÑù±¾Êý¾Ý£¬ £¬£¬£¬£¬£¬Ð¹Â¶ÄÚÈÝÖØÒªÎªGetirÄÚ²¿ÀûÓ÷¨Ê½ÔªÊý¾Ý£¬ £¬£¬£¬£¬£¬Ô̺¬Bitbucket´æ´¢¿âURL¡¢Óû§È¨ÏÞ¡¢ÏîÄ¿Ãû³Æ¡¢¹¤×÷ÇøID¼°Ô±¹¤µç×ÓÓʼþµØÖ·¡£¡£¡£ ¡£¡£×êÑÐÍŶӷÖÎöÒÔΪ£¬ £¬£¬£¬£¬£¬ÕâЩÊý¾Ý¸ü¿ÉÄÜͨ¹ýµÚÈý·½·þÎñÌṩÉÌ»ñÈ¡£¡£¡£ ¡£¡£¬ £¬£¬£¬£¬£¬¶ø·ÇÖ±½Ó½Ó¼û¹«Ë¾Ö÷Ìâϵͳ¡£¡£¡£ ¡£¡£Ö»¹ÜÈç´Ë£¬ £¬£¬£¬£¬£¬Ð¹Â¶µÄÔªÊý¾ÝÈÔ¿ÉÄÜ´øÀ´¶à³Á·çÏÕ£º¹¥»÷Õß¿ÉÀûÓÃÔ±¹¤µç×ÓÓʼþµØÖ·Ö´ÐÐÉç»á¹¤³Ì¹¥»÷£¬ £¬£¬£¬£¬£¬ÓÕµ¼Ô±¹¤Ð¹Â¼ûô¸ÐÐÅÏ¢»òµã»÷¶ñÒâÁ´½Ó£¬ £¬£¬£¬£¬£¬½ø¶ø»ñÈ¡¸üÉî²ãϵͳȨÏÞ£»£»£»£»£» £» £»Â¶³öµÄ´æ´¢¿âURLºÍ¹¤×÷ÇøIDÔò±ãÓÚ¹¥»÷ÕßÔÚÏîÄ¿ÖÐËÑË÷δÊܱ£»£»£»£»£» £» £»¤µÄAPI¶Ëµã»òÅäÖ÷ì϶£¬ £¬£¬£¬£¬£¬ÎªºóÐø¹¥»÷£¨ÈçÔ´´úÂëÇÔÈ¡¡¢ÏµÍ³ÈëÇÖ£©´´ÔìǰÌá¡£¡£¡£ ¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬GetirÉÐδ¶ÔÊÂÎñ×÷³öÕýʽ»ØÓ¦¡£¡£¡£ ¡£¡£


https://cybernews.com/security/getir-data-breach-claims/


3. VerisureÔâµÚÈý·½ºÏ×÷·½Êý¾Ýй¶£¬ £¬£¬£¬£¬£¬Ó°ÏìÈðµä3.5ÍòÓû§


10ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬Èðµä°²È«¾ÞÍ·Verisure½üÈÕÅûÂ¶Ò»Â·Éæ¼°ÆìÏÂAlert Alarm²¿Ãſͻ§µÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾Ö¤Êµ£¬ £¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÆäÈðµä±í²¿·¢Æ±ºÏ×÷ͬ°éµÄ·þÎñÆ÷£¬ £¬£¬£¬£¬£¬·¸·¨½Ó¼ûÁËÓëAlert Alarm¿Í»§ÓйصÄÊý¾Ý¡£¡£¡£ ¡£¡£¾­³õ´ëÊ©²é£¬ £¬£¬£¬£¬£¬Verisure×ÔÉíÍøÂç¼°Ö÷Ìâϵͳδ·¢ÏÖÈëÇÖºÛ¼££¬ £¬£¬£¬£¬£¬ÊÂÎñ½öÓ°ÏìµÚÈý·½¼Æ·Ñϵͳ£¬ £¬£¬£¬£¬£¬µ«ÒѲ¨¼°ÈðµäÔ¼3.5ÍòÃûAlert AlarmµÄÏÖÓм°Ç°Óû§¡£¡£¡£ ¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬¿Í»§È«Ãû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¼°Éç»á°²È«ºÅÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£VerisureÇ¿µ÷£¬ £¬£¬£¬£¬£¬Ö»¹ÜÊý¾Ý½Ó¼ûȨÏÞ¡°ÓÐÏÞ¡±£¬ £¬£¬£¬£¬£¬µ«ÒÑÆô¶¯È«Ãæµ÷²é²¢Ó뾯·½¡¢¼à¹Ü²¿ÃźÏ×÷£¬ £¬£¬£¬£¬£¬ºóÐø½«ÊµÊ±ÏòÊÜÓ°Ïì¿Í»§´«µÝ½øÕ¹¡£¡£¡£ ¡£¡£Alert Alarm×÷ΪVerisureÆìÏÂרһסլ¡¢¹«Ô¢¼°Ó×ÐÍÆóÒµ°²È«·þÎñµÄ²¿ÃÅ£¬ £¬£¬£¬£¬£¬ÔÚÈðµäÕ¼Óв»µ½6000Ãû¶©ÔÄÓû§£¬ £¬£¬£¬£¬£¬µ«Õâ´ÎÊÂÎñÏÖʵӰÏìÁìÓò¸ü¹ã£¬ £¬£¬£¬£¬£¬Éæ¼°º¹ÇàÓû§Êý¾Ý¡£¡£¡£ ¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬VerisureÕýÓ밲ȫÕÕ·÷ºÏ×÷ÅŲé·ì϶£¬ £¬£¬£¬£¬£¬²¢ºôÓõ¿Í»§¾¯Ìè´¹µö¹¥»÷¼°Éí·Ýڲƭ¡£¡£¡£ ¡£¡£


https://cybernews.com/security/verisure-data-breach/


4. AWSÈ«Çò´ó¹æÄ£ÖжÏÖÂ¶àÆ½Ì¨Ì±»¾£¬ £¬£¬£¬£¬£¬·þÎñ¸´Ô­¹ý³Ì³ÖÐøÍÆ¶¯


10ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬ÑÇÂíÑ·AWSÔâ·êÈ«ÇòÐÔ´ó¹æÄ£ÖжÏÊÂÎñ£¬ £¬£¬£¬£¬£¬µ¼ÖÂÊý°ÙÍòÍøÕ¾¼°·þÎṉ̃»¾£¬ £¬£¬£¬£¬£¬Ó°ÏìÁìÓòº­¸ÇÃÀ¹ú¡¢Å·Ö޵ȶà¸öµØÓò¡£¡£¡£ ¡£¡£Õâ´ÎÖжÏʼÓÚÃÀ¹ú¶«²¿¹¦·òÁ賿4:30×óÓÒ£¬ £¬£¬£¬£¬£¬³ÖÐøÔ¼45·ÖÖÓºó²¿ÃÅ·þÎñÆðÍ·¸´Ô­£¬ £¬£¬£¬£¬£¬µ«ºóÐøÓÖÒòÍøÂç¸ºÔØÆ½ºâÆ÷ÎÊÌâ³öÏÖ·´¸´£¬ £¬£¬£¬£¬£¬½ØÖÁµ±ÈÕÏÂÎç12:06£¬ £¬£¬£¬£¬£¬AWS°ä·¢ÒÑͨ¹ý¶î±í»º½â´ëÊ©¸´Ô­ÏνÓÐÔ¼°APIÖ°ÄÜ£¬ £¬£¬£¬£¬£¬µ«ÐÂEC2Ê·ýÆô¶¯ÈÔÊÜÏÞ£¬ £¬£¬£¬£¬£¬Ô¤¼ÆÌ«Æ½ÑóÏÄÁîʱÉÏÎç10:00ǰ¸üнøÕ¹¡£¡£¡£ ¡£¡£¾ÝAWS½¡È«Ò³ÃæÅû¶£¬ £¬£¬£¬£¬£¬ÎÊÌâÖ÷ÌâÔ´ÓÚUS-EAST-1ÇøÓòDynamoDB API¶ËµãµÄDNS½âÎö¹ÊÕÏ£¬ £¬£¬£¬£¬£¬Òý·¢¶à¸ö·þÎñÃýÎóÂÊÓëÑÓ³¤¼¤Ôö£¬ £¬£¬£¬£¬£¬Ô̺¬Amazon.com¡¢Prime Video¡¢Perplexity AI¡¢CanvaµÈÖ÷ÌâÆ½Ì¨¾ùÊܲ¨¼°¡£¡£¡£ ¡£¡£¾ßÌåÊÜÓ°Ïì·þÎñÇåµ¥ÏÔʾ£¬ £¬£¬£¬£¬£¬³ýÑÇÂíÑ·×Ô½»Ò×Îñ±í£¬ £¬£¬£¬£¬£¬Epic GamesÆìÏ¡¶µï±¤Ö®Ò¹¡·£¨µÇ¼ְÄÜ̱»¾£©¡¢Roblox¡¢Hulu¡¢Snapchat¡¢Grammarly¡¢Roblox¼°½ÌÓýƽ̨CanvasµÈ15¸öÖØÒª·þÎñͨ¹ýDowndetectorÈ·ÈÏÖжϣ¬ £¬£¬£¬£¬£¬CanvaÔÚ×´Ì¬Ò³ÃæÃ÷È·Ö¸³öÃýÎóÂÊÏÔÖøÉÏÉýÓ°ÏìͼÏñ±à×ëµÈÖ°ÄÜ£¬ £¬£¬£¬£¬£¬Fortnite¡¢PerplexityÒà֤ʵ·þÎñÏÂÏß¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/technology/aws-outage-crashes-amazon-prime-video-fortnite-perplexity-and-more/


5. CISAÈ·ÈÏOracle E-Business Suite SSRF·ì϶ÔâÀûÓÃ


10ÔÂ21ÈÕ£¬ £¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Oracle E-Business SuiteµÄCVE-2025-61884·ì϶ÄÉÈëÒÑÖª±»ÀûÓ÷ì϶Ŀ¼£¬ £¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹ÓÚ2025Äê11ÔÂ10ÈÕǰʵÏÖ½¨²¹¡£¡£¡£ ¡£¡£¸Ã·ì϶ΪOracle ConfiguratorÔËÐÐʱ×é¼þÖеķþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬ £¬£¬£¬£¬£¬OracleÓÚ10ÔÂ11ÈÕÅû¶ʱ½«ÆäÑϳÁÐÔÆÀ¼¶Îª7.5£¬ £¬£¬£¬£¬£¬ÖÒ¸æÆäÒ×±»ÀûÓÃÒÔ¡°Î´¾­ÊÚȨ½Ó¼û¹Ø¼üÊý¾Ý»òÆëÈ«½Ó¼ûËùÓÐOracle Configurator¿É½Ó¼ûÊý¾Ý¡±¡£¡£¡£ ¡£¡£µ÷²éÏÔʾ£¬ £¬£¬£¬£¬£¬¸Ã·ì϶Óë7Ô¹¥»÷ÖÐй¶µÄ·ì϶ֱ½ÓÓйء£¡£¡£ ¡£¡£10Ô³õ£¬ £¬£¬£¬£¬£¬MandiantÅû¶ClopÀÕË÷Èí¼þÍÅ»ïÒÑÏòÆóÒµ·¢ËÍÀÕË÷Óʼþ£¬ £¬£¬£¬£¬£¬Ðû³ÆÀûÓÃÁãÈÕ·ì϶ÇÔÈ¡ÁËOracle EBSÊý¾Ý¡£¡£¡£ ¡£¡£Oracle»ØÓ¦³Æ£¬ £¬£¬£¬£¬£¬ÍþвÐÐΪÕßÀûÓÃÁË7ÔÂÒѽ¨²¹µÄ·ì϶¡£¡£¡£ ¡£¡£½øÒ»´ëÊ©²é½Òʾ£¬ £¬£¬£¬£¬£¬Oracle EBS³ÉΪÁ½Æð¶ÀÁ¢¹¥»÷µÄÖ¸±ê£º7Ô¹¥»÷Õë¶Ô¡°/configurator/UiServlet¡±¶ËµãµÄSSRF·ì϶£¨¼´CVE-2025-61884£©£¬ £¬£¬£¬£¬£¬¶ø8Ô¹¥»÷ÔòÀûÓá°/OA_HTML/SyncServlet¡±¶ËµãµÄÁíÒ»·ì϶£¨CVE-2025-61882£©£¬ £¬£¬£¬£¬£¬ºóÕß±»¹éÒòÓÚClopÍŻ¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-confirms-hackers-exploited-oracle-e-business-suite-ssrf-flaw/


6. ¶í¹ØÁªÀÕË÷ÍÅ»ïINC RansomÍþв¹«¿ª¸ß¶û·ò¾ÞÍ·Êý¾Ý


10ÔÂ21ÈÕ£¬ £¬£¬£¬£¬£¬Óë¶íÂÞ˹ÓйصÄÀÕË÷Èí¼þÍÅ»ïINC Ransom 10ÔÂ16ÈÕÔÚ°µÍøÐ¹ÃÜÍøÕ¾Ðû³Æ£¬ £¬£¬£¬£¬£¬ÒÑÇÔÈ¡¸ß¶û·ò·þ×°¾ÞÍ·Summit Golf Brands47GBÊý¾Ý£¬ £¬£¬£¬£¬£¬²¢Æô¶¯Êý¾Ý¹«¿ªµ¹¼ÆÊ±£¬ £¬£¬£¬£¬£¬¾àËùν¡°Êý¾Ý°ä²¼¡±½öÊ£ÈýÌì¡£¡£¡£ ¡£¡£¸ÃÍÅ»ïÉÐδÌṩÊý¾ÝÑù±¾×ôÖ¤£¬ £¬£¬£¬£¬£¬´Ë¾Ù±»ÊÓΪÆÈʹÆóÒµÖ§¸¶Êê½ðµÄÕ½Êõ¼¿Á©¡£¡£¡£ ¡£¡£Summit Golf BrandsÆìÏÂÔ̺¬Zero Restriction¡¢B. DraddyµÈ³ÛÃûÆ·ÅÆ£¬ £¬£¬£¬£¬£¬ÄêÓªÊÕ2790ÍòÃÀÔª¡£¡£¡£ ¡£¡£INC Ransom³ÉÁ¢ÓÚ2023Äê7Ô£¬ £¬£¬£¬£¬£¬ÒÑÔì³É234ÃûÊܺ¦Õߣ¬ £¬£¬£¬£¬£¬ÒÔ¡°¶à³ÁÀÕË÷¡±Öø³Æ£º²»½ö¼ÓÃÜÎļþ£¬ £¬£¬£¬£¬£¬»¹ÇÔÈ¡Êý¾Ý²¢Íþвй¶£¬ £¬£¬£¬£¬£¬ÉõÖÁÒÔ¡°¸¶·Ñ¼´ÌáÉýϵͳ°²È«¡±µÄŤÇú˵´ÇÓÕÆ­Êê½ð¡£¡£¡£ ¡£¡£Õâ´ÎÕë¶ÔSummit Golf BrandsµÄ¹¥»÷£¬ £¬£¬£¬£¬£¬Â¶³öÁËÀÕË÷Èí¼þÍÅ»ï¶ÔóÒ×ʵÌåµÄ³ÖÐøÍþв¡£¡£¡£ ¡£¡£Ëæ×ŵ¹¼ÆÊ±ÁÚ½ü£¬ £¬£¬£¬£¬£¬ÆóÒµÃæ¶ÔÁ½ÄÑ£ºÖ§¸¶Êê½ð¿ÉÄÜÖú³¤·¸× £¬£¬£¬£¬£¬»Ø¾øÔò¿ÉÄÜÃæ¶ÔÊý¾Ýй¶·çÏÕ¼°ÃûÓþÇÖº¦¡£¡£¡£ ¡£¡£


https://cybernews.com/security/hackers-threaten-to-drop-47gb-of-top-golf-brands-secrets/