TomirisÉý¼¶¶à˵»°±øÆ÷¿â£¬£¬£¬£¬£¬¾«×¼½ø¹¥¶í±í½»»ú¹¹
°ä²¼¹¦·ò 2025-12-021. TomirisÉý¼¶¶à˵»°±øÆ÷¿â£¬£¬£¬£¬£¬¾«×¼½ø¹¥¶í±í½»»ú¹¹
12ÔÂ1ÈÕ£¬£¬£¬£¬£¬¿¨°Í˹»ù×îл㱨½Òʾ£¬£¬£¬£¬£¬ÃûΪTomirisµÄÍþвÐÐΪÕßÕý¶Ô¶íÂÞ˹±í½»²¿¡¢µ±¾ÐÄä×éÖ¯¼°ÖÐÑǹú¶È»ú¹¹ÌáÒéÕ½ÊõÐÔÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÆäÖ÷ÌâÖ¸±êÊÇͨ¹ýÓã²æÊ½´¹µöÓʼþ²¿Êð¶à˵»°±àдµÄ¶ñÒâÈí¼þÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬»ñȡԶ³Ì½Ó¼ûȨÏÞ²¢³ÉÁ¢Óƾû¯½ÚÔì¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯2025Äê¹¥»÷Á´ÏÔʾ£¬£¬£¬£¬£¬³¬50%µÄµö¶üÎļþѡȡ¶íÓï¼°ÖÐÑǹú¶È¹Ù·½Ëµ»°¶¨Ô죬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¼ÓÃÜRARÎļþ£¨½âѹÃÜÂëÖ±½ÓǶÈëÓʼþÕýÎÄ£©·Ö·¢¼Ù×°³ÉWordÎĵµµÄ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬ÔËÐкó¿ªÊÍC/C++·´ÏòShell£¬£¬£¬£¬£¬ÏνÓC2·þÎñÆ÷ÏÂÔØAdaptixC2¿ò¼Ü£¬£¬£¬£¬£¬²¢Í¨¹ýÅú¸ÄWindows×¢²á±íʵÏÖ¶ñÒâÔØºÉÓÆ¾Ã»¯¡£¡£¡£¡£¡£¡£¡£¡£TomirisµÄÕ½ÊõÑݱäÓÈΪÏÔÖø£¬£¬£¬£¬£¬ÆäÈÕ񾮵ÈÔµØÀûÓÃTelegram¡¢DiscordµÈ¹«¹²·þÎñ×÷ΪC2·þÎñÆ÷£¬£¬£¬£¬£¬½«¶ñÒâÁ÷Á¿ÓëºÏ·¨·þÎñÁ÷Á¿»ìºÏÒÔ¶ã±Ü¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£Æä¶ñÒâÈí¼þ±øÆ÷¿âº¸ÇC#¡¢Rust¡¢Go¡¢PythonµÈ¶à˵»°±àдµÄ·´ÏòShell¡¢SOCKS´úÀí¼°ºóÃÅ·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£¶à˵»°Ä£¿£¿£¿£¿£¿£¿£¿éµÄ½Ã½ÝÐÔ¡¢µÍ¿ÉÒÉÐÔÌØµã¼°¶Ô¿ªÔ´¿ò¼ÜµÄÀûÓ㬣¬£¬£¬£¬Ê¹Tomiris¿ÉÄÜʵÏÖÒñ±ÎµÄ³Ö¾ÃÓÆ¾Ã»¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html
2. ÈÕÀú¶©Ôݲȫäµã£ºBitSightÆØ347¸ö¶ñÒâÓòÃû·çÏÕ
11ÔÂ28ÈÕ£¬£¬£¬£¬£¬ÍøÂ簲ȫ¹«Ë¾BitSight×îÐÂ×êÑнÒʾ£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýͨ¹ý°Ñ³ÖÊý×ÖÈÕÀú¶©ÔÄ»ù´¡ÉèʩִÐдó¹æÄ£Éç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÈÕÀú¶©ÔÄÖ°Äܱ¾ÓÃÓÚºÏÐ̳¡¾°£¬£¬£¬£¬£¬ÈçÁãÊÛÉÌÍÆËÍ´ÙÏúÈÕÆÚ¡¢ÌåÓýлá¸üÐÂÈüÊÂÈճ̣¬£¬£¬£¬£¬ÆäÔÊÐíµÚÈý·½·þÎñÆ÷Ö±½ÓÏòÓû§É豸Ôö³¤ÊÂÎñ²¢·¢ËÍ֪ͨµÄ¸öÐÔ£¬£¬£¬£¬£¬È´±»¶ñÒâÀûÓ㬣¬£¬£¬£¬¹¥»÷ÕߴÍйÜÓÚ¹ýÆÚ»ò±»½Ù³ÖÓòÃûµÄÐéαÈÕÀú¶©ÔÄ·þÎñ£¬£¬£¬£¬£¬ÓÕÆÓû§¶©ÔĺóÍÆËͺ¬¶ñÒâÁ´½Ó¡¢¸½¼þµÄÈÕÀúÎļþ£¬£¬£¬£¬£¬´¥·¢´¹µö¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢JavaScript´úÂëÖ´ÐÐÉõÖÁAI¸±ÊÖÀÄÓõȷçÏÕ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐʼÓÚÒ»¸ö±» ¡°Sinkhole¡± ¼¼ÊõÊÕÊܵÄÓòÃû£¬£¬£¬£¬£¬¸ÃÓòÃûÔÓÃÓÚ·Ö·¢µÂ¹ú¹«¹²¼ÙÆÚICSÎļþ£¬£¬£¬£¬£¬È´ÖðÈÕ½Ó¹Ü1.1Íò¸ö¶ÀÁ¢IP½Ó¼û£¬£¬£¬£¬£¬Òý·¢×êÑÐÍŶӹØ×¢¡£¡£¡£¡£¡£¡£¡£¡£½øÒ»´ëÊ©²é·¢ÏÖ347¸ö¿ÉÒÉÈÕÀúÓòÃû£¬£¬£¬£¬£¬Éæ¼°2018ÊÀ½ç±¡¢ÒÁ˹À¼HijriÈÕÀúµÈÖ÷Ì⣬£¬£¬£¬£¬ÖðÈÕÀۼƽµÜÔ¼400Íò´ÎÃÀ¹úΪÖ÷µÄÈ«ÃÀ½Ó¼ûÒªÇ󡣡£¡£¡£¡£¡£¡£¡£³Á¶´Êý¾ÝÏÔʾ£¬£¬£¬£¬£¬ÕâЩ½Ó¼û¶àΪÒѶ©ÔÄÓû§µÄºó¶Üͬ²½ÒªÇ󣬣¬£¬£¬£¬Òâζ×ÅÊÕÊܹýÆÚÓòÃûµÄ¹¥»÷Õß¿ÉÖ±½ÓÏòÓû§Éè±¸ÍÆËͶ¨Ô컯¶ñÒâÈÕÀúÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/
3. PlayÀÕË÷Èí¼þ¹¥»÷ADC Aerospace
11ÔÂ29ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úº½¿Õº½ÌìÓë¹ú·ÀÁìÓò¹¤³Ì²¿¼þÔì×÷ÉÌADC AerospaceÒò·þÎñŵ˹ÂÞÆÕ¡¤¸ñ³Âü¡¢¿ÂÁÖ˹º½¿Õº½Ìì¡¢»ôÄáΤ¶ûµÈ³ÛÃûÆóÒµ£¬£¬£¬£¬£¬³ÉΪÀÕË÷Èí¼þ¹¥»÷³ÁµãÖ¸±ê¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÓÉÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þ¼¯ÍÅÖ®Ò»PlayÖ´ÐУ¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÔй¶¿Í»§Êý¾ÝΪÍþвÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð£¬£¬£¬£¬£¬Èô»Ø¾øÔò°ä²¼²¿ÃÅÊý¾ÝƬ¶Î¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÐû³ÆÒÑ»ñÈ¡¿Í»§Îļþ¡¢Ô¤Ëã²ÆÕþÐÅÏ¢¡¢Ð½×ʼͼ¡¢Éí·ÝÖ¤Ã÷µÈ˽ÃÜÊý¾Ý£¬£¬£¬£¬£¬µ«Î´ÌṩÑù±¾£¬£¬£¬£¬£¬ÕæÊµÐÔ´ýºË²é¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊý¾Ýй¶Êôʵ£¬£¬£¬£¬£¬ADC½«Ãæ¶Ô¶à³Á·çÏÕ£º°µÍø¶Ô¹ú·À³Ð°üÉÌÊý¾ÝµÄ¸ßÐèÒª¿ÉÄÜÍÆ¶¯±»µÁÐÅÏ¢ÂòÂô£»£»£»£»£»£»Ð½×ʼͼÖеÄÓ×ÎÒÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£»£»£»£»£»£»ÆäËû˽ÃÜÊý¾ÝÔò¿ÉÄܳÉΪÉç»á¹¤³Ì¹¥»÷¹¤¾ß£¬£¬£¬£¬£¬¹¥»÷Õß¼ÙÒâÐÐÒµÓйط½Ö´Ðиü¾ß·ÛËéÐÔµÄÚ¿Æ¡£¡£¡£¡£¡£¡£¡£¡£Play¼¯ÍÅÈ¥ÄêõÒÉíÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þǰÈý£¬£¬£¬£¬£¬½ñÄê8Ô³õ¸ÕÈëÇÖΪÃÀ¹úˮʦ¡¢²¨Òô¹©»õµÄJamco Aerospace¡£¡£¡£¡£¡£¡£¡£¡£
https://cybernews.com/security/adc-aerospace-breach-claims/
4. CoupangÔâ·êº«¹úÊ·ÉÏ×î´ó¹æÄ£¿£¿£¿£¿£¿£¿£¿Í»§Êý¾Ýй¶ÊÂÎñ
11ÔÂ30ÈÕ£¬£¬£¬£¬£¬±»ÓþΪ¡°º«¹úÑÇÂíÑ·¡±µÄº«¹úµçÉ̾ÞÍ·CoupangÓÚ11ÔÂ18ÈÕÅû¶һ·´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Ó°Ïì½ü3400Íò¸ö¿Í»§ÕË»§£¬£¬£¬£¬£¬´´º«¹úµ¥´ÎÊý¾Ýй¶ӰÏìÁìÓòÖ®×î¡£¡£¡£¡£¡£¡£¡£¡£¾µ÷²é£¬£¬£¬£¬£¬¹¥»÷Õß×Ô6ÔÂ24ÈÕÆðͨ¹ýº£±í·þÎñÆ÷ÌáÒéδ¾ÊÚȨ½Ó¼û£¬£¬£¬£¬£¬Öð²½À©´ó¹¥»÷¹æÄ££¬£¬£¬£¬£¬×îÖÕµ¼Ö³¬3300Íòº«¹úÓû§Êý¾Ý±íй¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç×ÓÓÊÏä¡¢µç»°ºÅÂë¡¢ÊÕ»õµØÖ·¼°²¿ÃŶ©µ¥¼Í¼£¬£¬£¬£¬£¬µ«Ö§¸¶ÐÅÏ¢ÓëµÇ¼ƾ֤δ±»»ñÈ¡¡£¡£¡£¡£¡£¡£¡£¡£CoupangÔÚ·¢ÏÖÒì³£ºóÁ¢¼´Ïòº«¹úÓ×ÎÒÐÅÏ¢±£»£»£»£»£»£»¤Î¯Ô±»á¡¢¾¯·½¼°»¥ÁªÍø°²È«¾Ö»ã±¨£¬£¬£¬£¬£¬²¢Æô¶¯Ó¦¼±ÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¡£¹«Ë¾×î³õÎóÅнöÔ¼4500ÈËÊÜÓ°Ï죬£¬£¬£¬£¬ºó½¨¸ÄΪ³¬3300ÍòÈË£¬£¬£¬£¬£¬Í¹ÏÔ³õÆÚ¼ì²â»úÔìµÄ²»¼°¡£¡£¡£¡£¡£¡£¡£¡£º«¹úµ±¾Ö¶Ô´Ë¸ß¶ÈÆ÷³Á£¬£¬£¬£¬£¬¿ÆÑ§¼¼ÊõÐÅϢͨѶ²¿²¿³¤ÅᾩѫÖÜÈÕÖ÷³Ö´¹Î£»áÒ飬£¬£¬£¬£¬ºË²éCoupangÊÇ·ñÎ¥·´¡¶Ó×ÎÒÐÅÏ¢±£»£»£»£»£»£»¤·¨¡·°²È«¹æ·¶¡£¡£¡£¡£¡£¡£¡£¡£º«¹ú»¥ÁªÍø°²È«ÕñÐËÔº£¨KISA£©ÒÑÏòÊÜÓ°ÏìÓû§°ä²¼·À´¹µöÚ¿ÆÖ¸ÄÏ£¬£¬£¬£¬£¬½¨Ò鶨ÆÚÅú¸ÄÃÜÂë¡¢ÆôÓÃË«³É·ÖÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÒÑÒý·¢Óû§¼¯ÌåËßËÏ·çÏÕ£¬£¬£¬£¬£¬CoupangÕýÃæ¶Ô˾·¨×·ÔðÓëŵÑÔ³Á´´µÄË«³ÁѹÁ¦¡£¡£¡£¡£¡£¡£¡£¡£
https://cybernews.com/news/coupang-confirms-massive-data-breach-exposing-33-7-million-accounts/
5. ¾¯·½²é·âÁËCryptomixer¼ÓÃÜÇ®±Ò»ìºÏ·þÎñ
12ÔÂ1ÈÕ£¬£¬£¬£¬£¬ÈðÊ¿ÓëµÂ¹ú·¨Âɲ¿ÃŽüÈÕ½áºÏ·¢Õ¹¡°°ÂÁÔì¥ÑÇÐж¯¡±£¬£¬£¬£¬£¬ÓÚ11ÔÂ24ÈÕÖÁ28ÈÕÔÚËÕÀèÊÀ²é·â¼ÓÃÜÇ®±Ò»ìºÏ·þÎñCryptomixer¡£¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨×Ô2016ÄêÔËÓªÒÔÀ´£¬£¬£¬£¬£¬±»Ö¸ÐÖúÍøÂç·¸×ï·Ö×ÓÏ´Ç®³¬13ÒÚÅ·Ôª±ÈÌØ±Ò£¬£¬£¬£¬£¬³ÉΪÀÕË÷Èí¼þÍŻ°µÍøÊг¡¼°µØÏ¾¼ÃÂÛ̳»ìºÏ·¸×ï×ʽðµÄÖ÷ÌâÇþ·¡£¡£¡£¡£¡£¡£¡£¡£Ðж¯ÖУ¬£¬£¬£¬£¬·¨ÂÉ»ú¹¹ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖÏ£¬£¬£¬£¬£¬²é»ñÈý̨·þÎñÆ÷¡¢12TBÊý¾Ý¡¢Ã÷Íø¼°Tor°µÍøÓòÃû£¬£¬£¬£¬£¬²¢¿ÛѺ¼ÛÖµ2400ÍòÅ·Ôª±ÈÌØ±Ò¡£¡£¡£¡£¡£¡£¡£¡£Cryptomixerͨ¹ý»ìºÏÓû§¼ÓÃÜÇ®±ÒÖÁ×Ê½ð³Ø²¢·Ö·¢ÖÁÐÂÇ®°üµØÖ·£¬£¬£¬£¬£¬ÓÐЧ×è¶ÏÇø¿éÁ´×ʽð×·×Ù£¬£¬£¬£¬£¬³ÉΪ··¶¾¡¢±øÆ÷×ß˽¡¢ÀÕË÷¹¥»÷¼°Ö§¸¶¿¨Ú²ÆµÈ·¸×ï»î¶¯µÄÏ´Ç®Ê×Ñ¡¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£ÆäÔËӪģʽ»¹Ô̺¬¶ÔÏ´Ç®×ʽðÊÕȡӶ½ð£¬£¬£¬£¬£¬ÔÙ×ªÒÆÖÁ¿Í»§Ö¸¶¨Ç®°ü£¬£¬£¬£¬£¬×îÖÕͨ¹ýÒøÐлòATM½«·¸·¨×ʲúת»»Îª·¨±Ò»òÆäËû¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£¡£´ËÀà·þÎñËä´æÔںϷ¨Óô¦£¬£¬£¬£¬£¬µ«ÖØÒª±»·¸×ïÍÅ»ïÓÃÓÚÌӱܲ龿¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/police-takes-down-cryptomixer-cryptocurrency-mixing-service/
6. CISA½«OpenPLC ScadaBR·ì϶Ôö³¤µ½KEVĿ¼ÖÐ
12ÔÂ1ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«±àºÅΪCVE-2021-26829µÄOpenPLC ScadaBR·ì϶ÄÉÈëÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶Ϊ¿çÕ¾¾ç±¾£¨XSS£©·ì϶£¬£¬£¬£¬£¬Í¨¹ýsystem_settings.shtmÎļþÓ°ÏìWindowsºÍLinux°æ±¾£¬£¬£¬£¬£¬¾ßÌåÉæ¼°Windows¶Ë1.12.4¼°¸üÔç°æ±¾¡¢Linux¶Ë0.9.1¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ5.4¡£¡£¡£¡£¡£¡£¡£¡£2025Äê9Ô£¬£¬£¬£¬£¬Ç×¶íºÚ¿Í×éÖ¯TwoNetÕë¶ÔÍøÂ簲ȫ¹«Ë¾ForescoutÔËÓªµÄICS/OTÃÛ¹ÞϵͳÌáÒé¹¥»÷£¬£¬£¬£¬£¬ÎóÅÐÆäΪˮ´¦Öó§¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃĬÈÏÆ¾Ö¤»ñȡϵͳ½Ó¼ûȨÏ޺󣬣¬£¬£¬£¬´´½¨ÃûΪ¡°BARLATI¡±µÄÕË»§£¬£¬£¬£¬£¬²¢Í¨¹ýCVE-2021-26829·ì϶´Û¸ÄÈË»ú½çÃæ£¨HMI£©µÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬Ã¿´Î½Ó¼û¸ÃÒ³ÃæÊ±£¬£¬£¬£¬£¬»á´¥·¢Ô̺¬Ôà»°µÄµ¯´°ÖҸ棬£¬£¬£¬£¬Í¬Ê±½ûÓÃÈÕÖ¾ºÍ¾¯±¨Ö°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01£¬£¬£¬£¬£¬Áª¹úÃñÓûú¹¹£¨FCEB£©ÐëÔÚ2025Äê12ÔÂ19ÈÕǰ½¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬ÒÔ½µµÍÂä´ó·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£CISAͬʱ½¨Òé˽Ӫ»ú¹¹Éó²éKEVĿ¼£¬£¬£¬£¬£¬ÊµÊ±½¨²¹×ÔÉí»ù´¡ÉèÊ©ÖеÄͬÀà·ì϶£¬£¬£¬£¬£¬Ô¤·À±»ÀûÓᣡ£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/185185/security/u-s-cisa-adds-an-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html


¾©¹«Íø°²±¸11010802024551ºÅ