ÀÕË÷Èí¼þÍÅ»ïÈôºÎ¼ÓÃÜÄÚ»ª´ïÖݵ±¾Öϵͳ

°ä²¼¹¦·ò 2025-11-10

1. ÀÕË÷Èí¼þÍÅ»ïÈôºÎ¼ÓÃÜÄÚ»ª´ïÖݵ±¾Öϵͳ


11ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬ÄÚ»ª´ïÖÝ8ÔÂÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ó°Ïì60Óà¸öµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÍøÕ¾¡¢µç»°ÏµÍ³¼°ÔÚÏ߯½Ì¨ÖжÏ¡£¡£¡£¡£ ¡£¡£Öݵ±¾Ö°ä²¼µÄ¾ßÌå¹ýºó»ã±¨ÆëÈ«Åû¶Á˹¥»÷ȫò£ººÚ¿Í×Ô5ÔÂ14ÈÕÆðͨ¹ý¶ñÒâ¸æ°×ÓÕµ¼Öݵ±¾Ö¹ÍÔ±ÏÂÔØ¼Ù×°³ÉϵͳÖÎÀí¹¤¾ß£¨ÈçWinSCP¡¢PuTTYµÈ£©µÄľÂí·¨Ê½£¬£¬£¬£¬£¬£¬£¬ÔÚÉ豸²¿ÊðºóÃÅ£»£» £»£»£»8ÔÂ24ÈÕÕýʽ²¿ÊðÀÕË÷Èí¼þǰ£¬£¬£¬£¬£¬£¬£¬ÒÑͨ¹ýÔ¶³Ì¼à¿ØÈí¼þ¡¢¼ÓÃÜËí·¹¤¾ßºáÏòÉøÈ룬£¬£¬£¬£¬£¬£¬ÇÔÈ¡26¸öÕË»§Í´´¦²¢¶Ï¸ùÊÂÎñÈÕÖ¾ÒÔ¸²¸ÇÐÐ×Ù¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß×îÖÕɾ³ý±¸·Ý¾í¡¢Åú¸ÄÐé¹¹»¯ÖÎÀí·þÎñÆ÷°²È«ÉèÖ㬣¬£¬£¬£¬£¬£¬ÔÚÍйÜÖÝÐé¹¹»úµÄËùÓзþÎñÆ÷Éϲ¿ÊðÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈ«ÖÝ·þÎṉ̃»¾¡£¡£¡£¡£ ¡£¡£Ãæ¶ÔΣ»£» £»£»£»ú£¬£¬£¬£¬£¬£¬£¬ÄÚ»ª´ïÖݻؾøÖ§¸¶Êê½ð£¬£¬£¬£¬£¬£¬£¬ÒÀ¸½50ÃûITÈËÔ±¼Ó°à4,212Ó×ʱ£¨¹¤×ʳɱ¾25.9ÍòÃÀÔª£©¼°±í²¿¹©¸øÉÌÖ§³Ö£¨×ÜÓöÈÔ¼130ÍòÃÀÔª£©£¬£¬£¬£¬£¬£¬£¬28ÌìÄÚ¸´Ô­90%ÊÜÓ°ÏìÊý¾Ý¼°·þÎñ¡£¡£¡£¡£ ¡£¡£Óë³ß¶È³Ð°üÉÌ·ÑÂÊÏà±È£¬£¬£¬£¬£¬£¬£¬´Ë¾Ù½Ú¼óÔ¼47.8ÍòÃÀÔª¡£¡£¡£¡£ ¡£¡£ÊÂÎñÏìÓ¦ÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬Î¢ÈíDART¡¢MandiantµÈ¹©¸øÉÌÌṩͳһ֧³Ö¡¢·¨Ö¤µ÷²é¡¢¹¤³Ì¸´Ô­µÈ·þÎñ£¬£¬£¬£¬£¬£¬£¬³É±¾Ã÷ϸͨÃ÷¹«¿ª¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/


2. ¶íSandwormºÚ¿Í×éÖ¯¶ÔÎڹؼüÐÐÒµ·¢ÆðÊý¾Ý²Á³ý¹¥»÷


11ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹¹ú¶ÈÖ§³ÖµÄºÚ¿Í×éÖ¯Sandworm£¨±ðÃûAPT44£©¶ÔÎÚ¿ËÀ¼½ÌÓý¡¢µ±¾ÐİÁ¸Ê³²¿ÃÅÌáÒé¶àÂÖÊý¾Ý²Á³ý¶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ò»Á¬Æä×Ô2022ÄêÒÔÀ´Õë¶Ô¸Ã¹úµÄ·ÛËéÐÔÐж¯¡£¡£¡£¡£ ¡£¡£ÍøÂ簲ȫ¹«Ë¾ESETÔÚ×îл㱨ÖÐÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷¼¯ÖÐÔÚ6ÔºÍ9Ô£¬£¬£¬£¬£¬£¬£¬Ö¸±êº­¸Çµ±¾Ö¡¢ÄÜÔ´¡¢ÎïÁ÷¼°Á¸Ê³ÐÐÒµ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÁ¸Ê³²¿ÃÅ×÷ΪÎÚ¿ËÀ¼Õ½Ê±ÖØÒªÊÕÈëÆðÔ´³ÉΪн¹µã¡£¡£¡£¡£ ¡£¡£Êý¾Ý²Á³ý¶ñÒâÈí¼þÈçPathWiper¡¢HermeticWiperµÈͨ¹ý·ÛËé»òɾ³ýÎļþ¡¢´ÅÅÌ·ÖÇø¼°Ö÷Êèµ¼¼Í¼ʵÏÖ³¹µ×Ïú»Ù£¬£¬£¬£¬£¬£¬£¬ÓëÀÕË÷Èí¼þ·ÖÆç£¬£¬£¬£¬£¬£¬£¬Æä´¿ÕýÒÔ·ÛËéΪÖ÷ÕÅ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂϵͳÄÑÒÔ¸´Ô­¡£¡£¡£¡£ ¡£¡£Õâ´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬Sandworm²¿ÊðÁË¡°ZeroLot¡±ºÍ¡°Sting¡±µÈ±äÖÖ£¬£¬£¬£¬£¬£¬£¬ÆäÖÓ×°Sting¡±Í¨¹ýÒÔÐÙÑÀÀû´«Í³²Ëëȶ¨ÃûµÄWindows¹¤×÷Ö´ÐУ¬£¬£¬£¬£¬£¬£¬Í¹ÏÔ¹¥»÷µÄÒñ±ÎÐÔ¡£¡£¡£¡£ ¡£¡£³õʼ½Ó¼ûȨÏÞ¶àÓÉUAC-0099£¨×Ô2023ÄêÆð»îÔ¾µÄÍþвÐÐΪÌ壩»ñÈ¡£¡£¡£¡£ ¡£¡£¬£¬£¬£¬£¬£¬£¬Ëæºó×ªÒÆ¸øSandworm²¿Êð²Á³ýÆ÷¡£¡£¡£¡£ ¡£¡£Á¸Ê³ÐÐÒµ³õ´Î³ÉÎªÖØÒª¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬·´Ó³³ö¹¥»÷ÕßÊÔͼ¼õÈõÎÚ¿ËÀ¼Õ½Ê±¾­¼ÃµÄÕ½ÊõÒâͼ¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/sandworm-hackers-use-data-wipers-to-disrupt-ukraines-grain-sector/


3. Î÷°àÑÀKISS-FMÔâRhysidaÀÕË÷Èí¼þ¹¥»÷


11ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬Î÷°àÑÀÕ¼ÓаÙÍòÌý¶àµÄÈȵã¹ã²¥µç̨KISS-FMÔâ·êÓë¶íÂÞ˹¹ØÁªµÄRhysidaÀÕË÷Èí¼þÍÅ»ïÏ®»÷¡£¡£¡£¡£ ¡£¡£¸ÃÍÅ»ïÔÚ°µÍøÅÄÂô¾Ý³ÆÇÔÈ¡µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÒªÇóÖ§¸¶3¸ö±ÈÌØ±Ò£¨Ô¼30ÍòÃÀÔª£©Êê½ð£¬£¬£¬£¬£¬£¬£¬²¢É趨7ÌìÆÚÏÞ£¬£¬£¬£¬£¬£¬£¬²»È»½«ÏúÊÛ»òй¶Êý¾Ý¡£¡£¡£¡£ ¡£¡£RhysidaÒÔ¡°Ë«³ÁÀÕË÷¡±Õ½ÊõÎÅÃû£¬£¬£¬£¬£¬£¬£¬²»½öÓÃÀÕË÷Èí¼þËø¶¨Êý¾Ý£¬£¬£¬£¬£¬£¬£¬»¹Íþвй¶ÒÔʩѹ¸¶¿î¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÌṩµÄ½ØÍ¼ÏÔʾ£¬£¬£¬£¬£¬£¬£¬±»µÁÊý¾Ý¿ÉÄÜÔ̺¬¹Û¶àÆÀ·Ö¼Í¼¡¢ÓëÎ÷°àÑÀÊý×Ö»¯×ªÐͲ¿»¥»»µÄÎļþ¼°·¢Æ±£¬£¬£¬£¬£¬£¬£¬µ«Ô±¹¤Ó×ÎÒÊý¾Ýй¶Çé¿öÉÐδÃ÷È·¡£¡£¡£¡£ ¡£¡£Õâ´ÎÊÂÎñÒÑÒý·¢¶Ô¹«¼ÒÐÅÀµ¶È½µÂä¡¢GDPRºÏ¹æ·çÏÕ¼°Ã³Ò×¹ØÏµÇÖÈŵÄÓÇÓô¡£¡£¡£¡£ ¡£¡£RhysidaÍÅ»ï×Ô2023Äê5Ô³ÉÁ¢ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬ÒÑÐû³Æ¹¥»÷236¸öÖ¸±ê£¬£¬£¬£¬£¬£¬£¬¸²¸Ç½ÌÓý¡¢Ò½ÁÆ¡¢Ôì×÷Òµ¡¢´¦Ëùµ±¾ÖµÈÁìÓò¡£¡£¡£¡£ ¡£¡£Æä¹¥»÷¼¿Á©Ô̺¬ÀûÓÃMicrosoft Teams¡¢ZoomºÍPuttyƽ̨½øÐжñÒâ¸æ°×ÍøÂç´¹µö£¬£¬£¬£¬£¬£¬£¬Ï°È¾É豸²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£ ¡£¡£


https://cybernews.com/security/ransomware-kissfm-spain-radio/


4. GlassWorm¶ñÒâÈí¼þ¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬£¬OpenVSXÔÙÔâ¹¥»÷


11ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬ÔøÓ°ÏìOpenVSXºÍVisual Studio CodeÀûÓÃÊг¡µÄGlassWorm¶ñÒâÈí¼þ»î¶¯ÔÙ¶È»îÔ¾£¬£¬£¬£¬£¬£¬£¬´øÀ´Èý¿îÐÂVSCodeÀ©´ó·¨Ê½£¬£¬£¬£¬£¬£¬£¬ÀÛ¼ÆÏÂÔØÁ¿Òѳ¬10,000´Î¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýSolanaÂòÂô»ñÈ¡ÓÐÐ§ÔØºÉ£¬£¬£¬£¬£¬£¬£¬Ö¸±êÖ±Ö¸GitHub¡¢NPM¼°OpenVSXÕË»§Í´´¦£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°49¸öÀ©´ó·¨Ê½µÄ¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý¡£¡£¡£¡£ ¡£¡£ÆäÖ÷Ìâ¹¥»÷¼¿Á©ÊÇÀûÓò»Ë½¼ûµÄUnicode×Ö·ûʵÏÖ¶ñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬£¬ÕâÖÖ»ìºÏ¼¼ÇÉÈÔÄÜÈÆ¹ýOpenVSXÐÂÒýÈëµÄ·ÀÓù»úÔì¡£¡£¡£¡£ ¡£¡£Õâ´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬GlassWormͨ¹ýOpenVSXƽ̨ÉÏ´«µÄÈý¿îÀ©´ó±ðÀëΪ£ºai-driven-dev.ai-driven-dev£¨3,400´ÎÏÂÔØ£©¡¢adhamu.history-in-sublime-merge£¨4,000´ÎÏÂÔØ£©¡¢yasuyuky.transient-emacs£¨2,400´ÎÏÂÔØ£©¡£¡£¡£¡£ ¡£¡£¾Ý°²È«»ú¹¹Koi Security×·×Ù£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÒ»ÑùµÄ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬µ«¸üÐÂÁ˺ÅÁîÓë½ÚÔ죨C2£©¶ËµãºÍSolanaÂòÂôÕ½Êõ£¬£¬£¬£¬£¬£¬£¬²¢ÒÑתÏòGitHubºóÓֻعéOpenVSX£¬£¬£¬£¬£¬£¬£¬Åú×¢ÆäÓÐÒâÔÚ¶àÆ½Ì¨³ÖÐøÔËÓª¡£¡£¡£¡£ ¡£¡£½ØÖÁ·¢¸å£¬£¬£¬£¬£¬£¬£¬Èý¿îЯ´øGlassWormÓÐÐ§ÔØºÉµÄÀ©´óÈÔ¿É´ÓOpenVSXÏÂÔØ£¬£¬£¬£¬£¬£¬£¬°²È«×¨¼ÒÖÒ¸æÓû§Ð辯Ìè´ËÀàÒñ±Î¹¥»÷¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/


5. NuGet¶ñÒâÈí¼þ°üÂñ·ü¶àÄ꣬£¬£¬£¬£¬£¬£¬2027ÄêÆð¼¤»î·ÛËéÐÔ¹¥»÷


11ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬´úÂ밲ȫ¹«Ë¾Socket×êÑÐÈËÔ±ÔÚNuGet¿ªÔ´°üÖÎÀíÆ½Ì¨·¢Ï־ŸöÓÉ¿ª·¢Õß"shanhai666"°ä²¼µÄ¶ñÒâÈí¼þ°ü£¬£¬£¬£¬£¬£¬£¬ÕâЩÈí¼þ°ü±í±í¾ß±¸ºÏ·¨Ö°ÄÜ£¬£¬£¬£¬£¬£¬£¬ÊµÔòÔ̺¬Òñ±ÎµÄ·ÛËéÐÔÓÐÐ§ÔØºÉ£¬£¬£¬£¬£¬£¬£¬´òËãÓÚ2027Äê8ÔÂÖÁ2028Äê11Ô¼伤»î¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâ´úÂëѡȡ¸ÅÂÊ´¥·¢»úÔ죬£¬£¬£¬£¬£¬£¬ÐèÂú×ãÌØ¶¨ÈÕÆÚǰÌá¼°Ëæ»úÊýãÐÖµ£¨´óÓÚ80ʱ´¥·¢£©£¬£¬£¬£¬£¬£¬£¬Í¨¹ýC#À©´ó²½Ö轫¶ñÒâÂß¼­Í¨Ã÷×¢ÈëÊý¾Ý¿âºÍPLC²Ù×÷Á÷³Ì¡£¡£¡£¡£ ¡£¡£Õâ´Î¹¥»÷Õë¶ÔÈý´óÖ÷Á÷Êý¾Ý¿â£¨SQL Server¡¢PostgreSQL¡¢SQLite£©¼°Î÷ÃÅ×ÓS7¹¤Òµ½ÚÔìÉ豸£¬£¬£¬£¬£¬£¬£¬ÓÈÆäÒÔ¼Ù×°³ÉºÏ·¨Sharp7¿âµÄ"Sharp7Extend"Èí¼þ°ü×îΪΣÏÕ¡£¡£¡£¡£ ¡£¡£¸Ã°üͨ¹ý¸½¼Ó"Extend"ºó׺ÓÕµ¼¿ª·¢ÕßÎóÏÂÔØ£¬£¬£¬£¬£¬£¬£¬µ±´¥·¢Ç°ÌáÂú×ãʱ£¬£¬£¬£¬£¬£¬£¬»áÒÔ20%¸ÅÂÊÁ¢¼´ÖÕÖ¹Ö÷»ú¹ý³Ì£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂPLC¿Í»§¶Ë²Ù×÷ÖжÏ£»£» £»£»£»»òͨ¹ýÑÓ³¤Ð´Èë»úÔ죨30-90·ÖÖÓ£©Ê¹PLCдÈë²Ù×÷ÓÐ80%¸ÅÂʰܻµ£¬£¬£¬£¬£¬£¬£¬Òý·¢Ö´ÐÐÆ÷ºÅÁîÃÔʧ¡¢°²ÕûϵͳʧЧµÈÑϳÁºó¹û¡£¡£¡£¡£ ¡£¡£½ØÖÁÆØ¹âʱ£¬£¬£¬£¬£¬£¬£¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØ½ü9500´Î£¬£¬£¬£¬£¬£¬£¬Éæ¼°SqlUnicorn.Core¡¢SQLite´æ´¢¿âµÈ¾Å¸ö¶ñÒâ°ü¡£¡£¡£¡£ ¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬NuGetÒÑϼÜÓйØÈí¼þ°ü£¬£¬£¬£¬£¬£¬£¬µ«Ç±ÔÚÓ°ÏìÁìÓò¿í·º¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-drop-disruptive-time-bombs/


6. ÈýÐÇÁãÈÕ·ì϶ÔâÀûÓ㬣¬£¬£¬£¬£¬£¬LandFall¼äµýÈí¼þ¶¨Ïò¹¥»÷Öж«Óû§


11ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕß×Ô2024Äê7ÔÂÆðÀûÓÃÈýÐÇAndroidͼÏñ´¦ÖÿâÖеÄÁãÈÕ·ì϶CVE-2025-21042£¬£¬£¬£¬£¬£¬£¬Í¨¹ýWhatsApp·¢ËͶñÒâDNGÌåʽͼÏñÎļþ£¬£¬£¬£¬£¬£¬£¬²¿ÊðÃûΪ"LandFall"µÄ¼äµýÈí¼þ£¬£¬£¬£¬£¬£¬£¬¶¨Ïò¹¥»÷Öж«µØÓòÌØ¶¨ÈýÐÇGalaxyÓû§¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶Ϊlibimagecodec.quram.soÎļþÖеÄÔ½½çдÈë·ì϶£¬£¬£¬£¬£¬£¬£¬ÑϳÁ¼¶±ð´ï"ÑϳÁ"£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÈýÐÇÓÚ2025Äê4Ô½¨¸´´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷»î¶¯ÒѳÖÐøÊýÔ£¬£¬£¬£¬£¬£¬£¬Ó°ÏìGalaxy S22¡¢S23¡¢S24¡¢Z Fold 4¼°Z Flip 4µÈÆì½¢»úÐÍ¡£¡£¡£¡£ ¡£¡£LandFall¼äµýÈí¼þѡȡ˫³Á¼¼Êõ×é¼þ£º¼ÓÔØÆ÷b.soÕÆ¹Ü¼ìË÷ºÍ¼ÓÔØÆäËûÄ£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬SELinuxÕ½Êõ°Ñ³ÖÆ÷l.soÔòÅú¸ÄÉ豸°²È«ÉèÖÃÒÔÌáÉýȨÏÞ²¢³ÉÁ¢ÓƾÃÐÔ¡£¡£¡£¡£ ¡£¡£¸ÃÈí¼þ¿É»ùÓÚÓ²¼þºÍSIM ID£¨ÈçIMEI¡¢IMSI£©¶ÔÉ豸½øÐÐÖ¸ÎÆ¼ø±ð£¬£¬£¬£¬£¬£¬£¬²¢¾ß±¸Âó¿Ë·ç¹àÒô¡¢Í¨»°¹àÒô¡¢µØÎ»×·×Ù¡¢½Ó¼ûÕÕÆ¬/ÁªÏµÈË/¶ÌÐÅ/ͨ»°¼Í¼/Îļþ¼°ä¯ÀÀº¹ÇàµÈ¼äµýÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ö§³ÖÄ£¿£¿£¿£¿£¿£¿éÖ´ÐÓ×¢ÓÆ¾Ã»¯¡¢¼ì²âÌӱܺͱ£»£» £»£»£»¤Èƹý¡£¡£¡£¡£ ¡£¡£¹¥»÷õè¾¶ÏÔʾ£¬£¬£¬£¬£¬£¬£¬¶ñÒâDNGÎļþĩβ¸½¼ÓZIPѹËõ°ü£¬£¬£¬£¬£¬£¬£¬Í¨¹ýWhatsApp´«²¼¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±·ÖÎö·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÒÁÀ­¿Ë¡¢ÒÁÀÊ¡¢ÍÁ¶úÆäºÍĦÂå¸çΪDZÔÚÖ¸±ê¹ú¶È¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/