¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷
°ä²¼¹¦·ò 2025-12-081. ¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷
12ÔÂ4ÈÕ£¬£¬£¬£¬£¬ÒÔIJÀûΪÖ÷Õŵġ°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ï½üÆÚÒÔ¼Ù×°µ±¾Ö·þÎñ»ú¹¹µÄ·½Ê½£¬£¬£¬£¬£¬ÏòÓ¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹úºÍÔ½ÄϵÄÒÆ¶¯Óû§ÌáÒéÐÂÒ»ÂÖ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2024Äê10ÔÂÆð£¬£¬£¬£¬£¬Í¨¹ý´«²¼Ö²È밲׿¶ñÒâÈí¼þµÄ´Û¸Ä°æÒøÐÐÀûÓÃÖ´Ðй¥»÷£¬£¬£¬£¬£¬×îÔçÔÚÌ©¹ú±»·¢ÏÖ£¬£¬£¬£¬£¬ºóÊæÕ¹ÖÁÔ½ÄϺÍÓ¡Äá¡£¡£¡£¡£¡£¡£¡£¡£¾ÝÐÂ¼ÓÆÂIB¼¯Íż¼Êõ»ã±¨£¬£¬£¬£¬£¬½öÓ¡Äá¾ÍÔì³É½ü2200ÆðÉ豸ϰȾ£¬£¬£¬£¬£¬×ÜϰȾ°¸Àý³¬1.1ÍòÆð£¬£¬£¬£¬£¬ÆäÖÐ63%µÄ´Û¸ÄÀûÓÃÕë¶ÔÓ¡ÄáÊг¡¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Á÷³Ì¼Ù×°³Éµ±¾Ö»ú¹¹»ò³ÛÃûÆ·ÅÆ£¬£¬£¬£¬£¬Í¨¹ýµç»°Ú¿ÆÓÕµ¼Óû§µã»÷ZaloµÈͨѶÈí¼þÖеÄÁ´½Ó£¬£¬£¬£¬£¬×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¶ñÒⷨʽͨ¹ý×¢Èë¶ñÒâ´úÂëµ½Õý¹æÒøÐÐÀûÓ㬣¬£¬£¬£¬±£ÁôÕý³£Ö°ÄÜÒÔÈÆ¹ý°²È«·À»¤£¬£¬£¬£¬£¬Ö÷±êÌâ±êÊÇÔ¶³Ì²Ù¿ØÉ豸¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÈýÀà½Ù³Ôì÷×é¼þ¡ª¡ª¡°¸¥Èð½Ù³Ôì÷¡±¡°Ìì¿Õ½Ù³Ôì÷¡±¡°Åɶ÷½Ù³Ôì÷¡±£¬£¬£¬£¬£¬¿ÉʵÏÖ°µ²ØÀûÓᢶã±Ü¼ì²â¡¢Î±ÔìÊðÃû¡¢ÇÔÈ¡Óà¶îÐÅÏ¢µÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍŻﻹ¿ª·¢ÁË¡°¾ÞÐÍ»¨¡±²âÊÔ°æ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Ö§³Öʵʱ´«ÊäÉ豸»Ãæ¡¢¼üÅ̼ͼ¡¢µ¯³öÐéα½çÃæÇÔÊØÐÅÏ¢£¬£¬£¬£¬£¬²¢ÔÚ¿ª·¢¶þάÂëɨÃèÖ°ÄÜÒÔÌáȡԽÄÏÉí·ÝÖ¤ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/12/goldfactory-hits-southeast-asia-with.html
2. Ó¡¶ÈÆóÒµÔâ¼Ùװ˰Îñ²¿ÃÅ´¹µö¹¥»÷
12ÔÂ4ÈÕ£¬£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬£¬Ò»³¡Õë¶ÔÓ¡¶ÈÆóÒµµÄ´ó¹æÄ£´¹µö¹¥»÷ÇÄÈ»·¢Õ¹¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼Ù×°³ÉÓ¡¶ÈËùµÃ˰²¿ÃÅ£¬£¬£¬£¬£¬Í¨¹ý¸ß¶È·ÂÕæÈ·µ±¾Ö¹«º¯Ä£°å¼°Ó¡µØÓïÓëÓ¢ÓïË«ÓïͨѶ£¬£¬£¬£¬£¬ÒýÓá¶ËùµÃ˰·¨¡·Ìõ¿îÔì×÷ºÏ·¨ÐÔÓë½ôÆÈ¸Ð£¬£¬£¬£¬£¬»Ñ³ÆÊÕ¼þÈË´æÔÚ˰ÎñÎ¥¹æÐÐΪ£¬£¬£¬£¬£¬ÒªÇó72Ó×ʱÄÚÌá½»Îļþ£¬£¬£¬£¬£¬ÓÕÆÓû§´ò¿ª¶ñÒ⸽¼þ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ѡȡÁ½½×¶Î¶ñÒâÈí¼þÁ´£º³õÆÚÒÔÃÜÂë±£»£»£»£»£»¤µÄZIPÎļþ´îÔØshellcode¼ÓÔØÆ÷£¬£¬£¬£¬£¬ºóÐø±äÌåÀûÓùȸèÎĵµÁ´½Ó½»¸¶¶þ¼¶Ôغɣ¬£¬£¬£¬£¬×îÖÕͶ·ÅAsyncRATÔ¶³Ì½ÚÔìľÂí£¬£¬£¬£¬£¬ÊµÏÔìÁÄ»¹²Ïí¡¢Îļþ´«Êä¼°Ô¶³ÌºÅÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Ö¸±êËø¶¨Ö¤È¯¹«Ë¾¡¢½ðÈÚ»ú¹¹¼°·ÇÒøÐнðÈÚ¹«Ë¾£¬£¬£¬£¬£¬ÒòÕâЩ»ú¹¹Ð趨ÆÚÓëµ±²¿ÃÅÃÅ»¥»»¼à¹ÜÎļþ£¬£¬£¬£¬£¬³ÉΪ³ÁµãÖ¸±ê¡£¡£¡£¡£¡£¡£¡£¡£Raven°²È«ÍŶÓͨ¹ý¼ø±ð¹¥»÷¼Ü¹¹ÖеĶà²ãì¶Üµã£¬£¬£¬£¬£¬³É¹¦·¢ÏÖ²¢×èÖ¹ÁËÕâÒ»ÁãÈÕ¹¥»÷£¬£¬£¬£¬£¬Ô¤·ÀÖ¸±ê»ú¹¹´ó¹æÄ£Ï°È¾¡£¡£¡£¡£¡£¡£¡£¡£ÓʼþÔ´×ԺϷ¨Ãâ·ÑÓÊÏäÕ˺ţ¬£¬£¬£¬£¬Í¨¹ýSPF¡¢DKIM¼°DMARCÈÏÖ¤£¬£¬£¬£¬£¬Èƹý´«Í³Óʼþ¹ýÂËÆ÷¡£¡£¡£¡£¡£¡£¡£¡£ÃÜÂë±£»£»£»£»£»¤¸½¼þÔ¤·À´«ÊäÖб»É±¶¾Èí¼þɨÃ裬£¬£¬£¬£¬½âѹºó³öÏֵġ°NeededDocuments¡±¿ÉÖ´ÐÐÎļþÄÚÖÃshellcode£¬£¬£¬£¬£¬shellcodeÓëAsyncRAT½ÚÔì·þÎñÆ÷³ÉÁ¢Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£¡£
https://cybersecuritynews.com/new-phishing-attack-mimic-as-income-tax-department/
3. React2Shell·ì϶´ó¹æÄ£ÀûÓ㬣¬£¬£¬£¬³¬7.7ÍòIPÊÜÓ°Ïì
12ÔÂ6ÈÕ£¬£¬£¬£¬£¬React2ShellÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©Òý·¢È«Çò°²È«Î£»£»£»£»£»ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚReact·þÎñÆ÷×é¼þ¶Ô¿Í»§¶Ë½ÚÔìÊý¾ÝµÄ²»°²È«·´ÐòÁл¯»úÔ죬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýµ¥¸öHTTPÒªÇó´¥·¢Î´¾Éí·ÝÑéÖ¤µÄËÁÒâºÅÁîÖ´ÐУ¬£¬£¬£¬£¬Ó°ÏìËùÓÐʵÏÖReact·þÎñÆ÷×é¼þµÄ¿ò¼ÜÈçNext.js¡£¡£¡£¡£¡£¡£¡£¡£Shadowserver»ã±¨ÏÔʾ£¬£¬£¬£¬£¬³¬77,000¸ö¶³öÔÚ»¥ÁªÍøµÄIPµØÖ·Ò×Êܹ¥»÷£¬£¬£¬£¬£¬ÆäÖÐÔ¼23,700¸öλÓÚÃÀ¹ú£¬£¬£¬£¬£¬Éæ¼°¶à¸öÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£·ì϶Åû¶ºó£¬£¬£¬£¬£¬°²È«×êÑÐÔ±Maple3142°ä²¼¸ÅÏëÑéÖ¤£¬£¬£¬£¬£¬Íƶ¯×Ô¶¯»¯É¨Ã蹤¾ßѸËÙÀ©É¢¡£¡£¡£¡£¡£¡£¡£¡£GreyNoise¼à²âµ½£¬£¬£¬£¬£¬´Óǰ24Ó×ʱÄÚÓÐ181¸ö·ÖÆçIP³¢ÊÔÀûÓø÷ì϶£¬£¬£¬£¬£¬Á÷Á¿ÖØÒªÀ´×ÔºÉÀ¼¡¢Öйú¡¢ÃÀ¹ú¡¢Ïã¸ÛµÈµØÓò£¬£¬£¬£¬£¬¹¥»÷Õß¶àʹÓÃPowerShellºÅÁîÈç¡°40138*41979¡±²âÊÔ·ì϶£¬£¬£¬£¬£¬È·ÈϺóͨ¹ýbase64±àÂëÏÂÔØµÚ¶þ½×¶Î¾ç±¾£¬£¬£¬£¬£¬²¿ÊðCobalt StrikeÐűê»òSnowlight¡¢Vshell¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì½Ó¼û¡¢ºáÏòÒÆ¶¯¼°Ãô¸ÐÐÅÏ¢ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable/
4. Barts Health NHS TrustÔâClopÀÕË÷Èí¼þ¹¥»÷
12ÔÂ5ÈÕ£¬£¬£¬£¬£¬Ó¢¹úBarts Health NHS Trust½üÈÕ°ä·¢£¬£¬£¬£¬£¬ÆäOracle E-business SuiteÈí¼þ´æÔÚ·ì϶£¨CVE-2025-61882£©£¬£¬£¬£¬£¬±»ClopÀÕË÷Èí¼þÍÅ»ïÀûÓ㬣¬£¬£¬£¬µ¼ÖÂÊý¾Ý¿âÖÐÓâÔ½ÊýÄêµÄ·¢Æ±Îļþ±»µÁ¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÉæ¼°ÔڰʹĽ¡È«Ò½Ôº½ÓÊÜÒ½Öλò·þÎñÈËÔ±µÄÈ«Ãû¡¢µØÖ·£¬£¬£¬£¬£¬²¿ÃÅǰ¹ÍÔ±¼°Òѹ«¿ªÊý¾ÝµÄ¹©¸øÉÌÐÅÏ¢£¬£¬£¬£¬£¬ÒÔ¼°×Ô2024Äê4ÔÂÆð¸ÃÐÅÈÎÏòBarking¡¢HaveringºÍRedbridge´óѧҽԺNHSÐÅÈÎÌṩµÄ¹ÜÕÊ·þÎñÓйØÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ClopÒѽ«ÇÔÊØÐÅÏ¢ÉÏ´«ÖÁ°µÍøÐ¹Â¼ûÅ»§£¬£¬£¬£¬£¬µ«BartsÇ¿µ÷£¬£¬£¬£¬£¬Ä¿Ç°½öÏÞ¼ÓÃܰµÍøÓû§¿É½Ó¼ûѹËõÎļþ£¬£¬£¬£¬£¬Î´·¢ÏÖÊý¾ÝÔÚ¹«¿ª»¥ÁªÍø´«²¼¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÓÚ2025Äê8Ô£¬£¬£¬£¬£¬Ö±ÖÁ11ÔÂÎļþ±»°ä²¼ÖÁ°µÍøºó²ÅÈ·ÈÏÊý¾Ý·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£BartsÒÑÏò¹ú¶ÈÍøÂ簲ȫÖÐÐÄ¡¢Â׶ؾ¯Ô±Ìü¼°ÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©´«µÝÊÂÎñ£¬£¬£¬£¬£¬²¢ÉêÇë¸ßµµ·¨ÔººÅÁî²»ÈÝÊý¾ÝʹÓᢰ䲼»ò·ÖÏí£¬£¬£¬£¬£¬µ«´ËÀà½ûÁîÏÖʵЧÁ¦ÓÐÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔËÓªÂ×¶ØÎå¼ÒÒ½Ôº£¬£¬£¬£¬£¬Ô̺¬»Ê¼ÒÂ×¶ØÒ½Ôº¡¢Ê¥°ÍÈûÂåçÑÒ½ÔºµÈ£¬£¬£¬£¬£¬Æäµç×Ó²¡Àú¼°ÁÙ´²ÏµÍ³Î´ÊÜÓ°Ï죬£¬£¬£¬£¬Ö÷ÌâIT»ù´¡ÉèÊ©°²È«ÐÔÈÔ»ñ×¢¶¨¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/barts-health-nhs-discloses-data-breach-after-oracle-zero-day-hack/
5. InotivÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂ9500ÓàÈËÊý¾Ýй¶
12ÔÂ5ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÔìÒ©¹«Ë¾Inotiv½üÈÕÅû¶£¬£¬£¬£¬£¬2025Äê8ÔÂ5ÈÕÖÁ8ÈÕÆÚ¼ä£¬£¬£¬£¬£¬Æä²¿ÃÅÍøÂçºÍϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÊý¾Ý¿â¼°ÄÚ²¿ÀûÓ÷¨Ê½Ì±»¾£¬£¬£¬£¬£¬ÒµÎñÔËÓªÊÜÑϳÁÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ËæºóÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ìá½»ÎļþÈ·ÈÏ£¬£¬£¬£¬£¬ÒѸ´ÔÊÜÓ°Ïìϵͳ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬²¢ÕýÏò8ÔÂÊÂÎñÖÐÊý¾Ý±»µÁµÄ9,542ÃûÓ×ÎÒ·¢ËÍ֪ͨ£¬£¬£¬£¬£¬Éæ¼°ÏÖÈÎ/ǰÈÎÔ±¹¤¡¢¾ìÊô¼°ÓëÊÕ¹º¹«Ë¾Óйý»¥¶¯µÄÆäËûÈËÔ±¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÓÉ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÕƹܡ£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû³Æ£¬£¬£¬£¬£¬ÇÔÈ¡ÁËInotiv³¬16.2Íò¸öÎļþ£¬£¬£¬£¬£¬×ܼÆ176GB£¬£¬£¬£¬£¬µ«InotivδÃ÷È·¾ßÌåй¶Êý¾ÝÀàÐÍ£¬£¬£¬£¬£¬Ò²Î´È·ÈÏ÷è÷ëÉêÃ÷µÄÕæÊµÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Inotiv×ܲ¿Î»ÓÚÓ¡µÚ°²ÄÉÖÝ£¬£¬£¬£¬£¬ÊÇÒ»¼ÒÄêÊÕÈ볬5ÒÚÃÀÔªµÄºÏͬ×êÑлú¹¹£¬£¬£¬£¬£¬×¨Ò»Ò©Î↑·¢¡¢°²È«ÐÔÆÀ¹À¼°»îÌ嶯Îï×êÑÐÄ£Ð͹¹½¨£¬£¬£¬£¬£¬Õ¼ÓÐÔ¼2000ÃûÔ±¹¤¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâ´Î¹¥»÷䲨¼°Ö÷ÌâÁÙ´²ÏµÍ³£¬£¬£¬£¬£¬µ«Êý¾Ýй¶·çÏÕÈÔÒý·¢¼à¹Ü¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-discloses-data-breach-after-ransomware-attack/
6. ¶à½×¶Î¹¥»÷»î¶¯¶Ô×¼Palo AltoÓëSonicWall°²È«É豸
12ÔÂ6ÈÕ£¬£¬£¬£¬£¬ÍþвÐÐΪÕß12ÔÂ2ÈÕÆðÀûÓõ¹úÍйܷþÎñÌṩÉÌ3xK GmbHÔËÓªµÄBGPÍøÂ磨AS200373£©ÏÂ7000Óà¸öIPµØÖ·£¬£¬£¬£¬£¬ÌáÒéÕë¶ÔPalo Alto GlobalProtect VPNÃÅ»§¼°SonicWall SonicOS API¶ËµãµÄ¶à½×¶Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£GreyNoise»ã±¨ÏÔʾ£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈͨ¹ý±©Á¦ÆÆ½â³¢ÊԵǼPalo Alto·À»ðǽµÄÔ¶³Ì½Ó¼û×é¼þGlobalProtect£¬£¬£¬£¬£¬ËæºóתÏòɨÃèSonicOS API¶Ëµã¡ª¡ª¸Ã²Ù×÷ϵͳ½ÚÔìSonicWall·À»ðǽµÄÅäÖÃÓë¼à¿ØÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Óë11ÔÂÖÐÑ®¼Í¼µÄ230Íò´ÎGlobalProtectɨÃè´æÔÚ¹ØÁª£º62%µÄ¹¥»÷IPλÓڵ¹ú£¬£¬£¬£¬£¬¾ùʹÓÃÒ»ÑùTCP/JA4tÖ¸ÎÆ£¬£¬£¬£¬£¬ÇÒÔ´×Ô´ËǰÎÞ¶ñÒâ¼Í¼µÄËĸöASN¡£¡£¡£¡£¡£¡£¡£¡£º¹ÇàɨÃè»î¶¯ÔøÌìÉú³¬900Íò´Î²»³ÉαÔìµÄHTTP»á»°£¬£¬£¬£¬£¬Ö¸±êÖ±Ö¸GlobalProtect¡£¡£¡£¡£¡£¡£¡£¡£12ÔÂ3ÈÕ£¬£¬£¬£¬£¬Õë¶ÔSonicOS APIµÄɨÃèÖÐÔٴγöÏÖÒ»ÑùÈý¸ö¿Í»§Ö¸ÎÆ£¬£¬£¬£¬£¬GreyNoise¾Ý´ËÅж¨Á½½×¶Î¹¥»÷ͬԴ¡£¡£¡£¡£¡£¡£¡£¡£Palo Alto Networks»ØÓ¦³Æ£¬£¬£¬£¬£¬¼ì²âµ½µÄɨÃè»î¶¯ÊôÓÚ¡°Æ¾Ö¤¹¥»÷¶ø·Ç·ì϶ÀûÓá±£¬£¬£¬£¬£¬ÆäÄÚ²¿Ò£²â¼°Cortex XSIAM·À»¤ÏµÍ³È·ÈÏδ¶Ô²úÆ··þÎñÔì³ÉÇÖº¦£¬£¬£¬£¬£¬½¨Òé¿Í»§ÆôÓöà³É·ÖÈÏÖ¤£¨MFA£©·À±¸Æ¾Ö¤ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£SonicWall·½ÃæÉÐδ¹«¿ªÖÃÆÀ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-wave-of-vpn-login-attempts-targets-palo-alto-globalprotect-portals/


¾©¹«Íø°²±¸11010802024551ºÅ