¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷

°ä²¼¹¦·ò 2025-12-08

1. ¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷


12ÔÂ4ÈÕ£¬ £¬£¬£¬£¬ÒÔIJÀûΪÖ÷Õŵġ°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ï½üÆÚÒÔ¼Ù×°µ±¾Ö·þÎñ»ú¹¹µÄ·½Ê½£¬ £¬£¬£¬£¬ÏòÓ¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹úºÍÔ½ÄϵÄÒÆ¶¯Óû§ÌáÒéÐÂÒ»ÂÖ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2024Äê10ÔÂÆð£¬ £¬£¬£¬£¬Í¨¹ý´«²¼Ö²È밲׿¶ñÒâÈí¼þµÄ´Û¸Ä°æÒøÐÐÀûÓÃÖ´Ðй¥»÷£¬ £¬£¬£¬£¬×îÔçÔÚÌ©¹ú±»·¢ÏÖ£¬ £¬£¬£¬£¬ºóÊæÕ¹ÖÁÔ½ÄϺÍÓ¡Äá¡£¡£¡£¡£¡£¡£¡£¡£¾ÝÐÂ¼ÓÆÂIB¼¯Íż¼Êõ»ã±¨£¬ £¬£¬£¬£¬½öÓ¡Äá¾ÍÔì³É½ü2200ÆðÉ豸ϰȾ£¬ £¬£¬£¬£¬×ÜϰȾ°¸Àý³¬1.1ÍòÆð£¬ £¬£¬£¬£¬ÆäÖÐ63%µÄ´Û¸ÄÀûÓÃÕë¶ÔÓ¡ÄáÊг¡¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Á÷³Ì¼Ù×°³Éµ±¾Ö»ú¹¹»ò³ÛÃûÆ·ÅÆ£¬ £¬£¬£¬£¬Í¨¹ýµç»°Ú¿Æ­ÓÕµ¼Óû§µã»÷ZaloµÈͨѶÈí¼þÖеÄÁ´½Ó£¬ £¬£¬£¬£¬×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¶ñÒⷨʽͨ¹ý×¢Èë¶ñÒâ´úÂëµ½Õý¹æÒøÐÐÀûÓ㬠£¬£¬£¬£¬±£ÁôÕý³£Ö°ÄÜÒÔÈÆ¹ý°²È«·À»¤£¬ £¬£¬£¬£¬Ö÷±êÌâ±êÊÇÔ¶³Ì²Ù¿ØÉ豸¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÈýÀà½Ù³Ôì÷×é¼þ¡ª¡ª¡°¸¥Èð½Ù³Ôì÷¡±¡°Ìì¿Õ½Ù³Ôì÷¡±¡°Åɶ÷½Ù³Ôì÷¡±£¬ £¬£¬£¬£¬¿ÉʵÏÖ°µ²ØÀûÓᢶã±Ü¼ì²â¡¢Î±ÔìÊðÃû¡¢ÇÔÈ¡Óà¶îÐÅÏ¢µÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍŻﻹ¿ª·¢ÁË¡°¾ÞÐÍ»¨¡±²âÊÔ°æ¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬Ö§³Öʵʱ´«ÊäÉ豸»­Ãæ¡¢¼üÅ̼ͼ¡¢µ¯³öÐéα½çÃæÇÔÊØÐÅÏ¢£¬ £¬£¬£¬£¬²¢ÔÚ¿ª·¢¶þάÂëɨÃèÖ°ÄÜÒÔÌáȡԽÄÏÉí·ÝÖ¤ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2025/12/goldfactory-hits-southeast-asia-with.html


2. Ó¡¶ÈÆóÒµÔâ¼Ùװ˰Îñ²¿ÃÅ´¹µö¹¥»÷


12ÔÂ4ÈÕ£¬ £¬£¬£¬£¬½üÆÚ£¬ £¬£¬£¬£¬Ò»³¡Õë¶ÔÓ¡¶ÈÆóÒµµÄ´ó¹æÄ£´¹µö¹¥»÷ÇÄÈ»·¢Õ¹¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼Ù×°³ÉÓ¡¶ÈËùµÃ˰²¿ÃÅ£¬ £¬£¬£¬£¬Í¨¹ý¸ß¶È·ÂÕæÈ·µ±¾Ö¹«º¯Ä£°å¼°Ó¡µØÓïÓëÓ¢ÓïË«ÓïͨѶ£¬ £¬£¬£¬£¬ÒýÓá¶ËùµÃ˰·¨¡·Ìõ¿îÔì×÷ºÏ·¨ÐÔÓë½ôÆÈ¸Ð£¬ £¬£¬£¬£¬»Ñ³ÆÊÕ¼þÈË´æÔÚ˰ÎñÎ¥¹æÐÐΪ£¬ £¬£¬£¬£¬ÒªÇó72Ó×ʱÄÚÌá½»Îļþ£¬ £¬£¬£¬£¬ÓÕÆ­Óû§´ò¿ª¶ñÒ⸽¼þ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ѡȡÁ½½×¶Î¶ñÒâÈí¼þÁ´£º³õÆÚÒÔÃÜÂë±£» £»£»£»£»¤µÄZIPÎļþ´îÔØshellcode¼ÓÔØÆ÷£¬ £¬£¬£¬£¬ºóÐø±äÌåÀûÓùȸèÎĵµÁ´½Ó½»¸¶¶þ¼¶Ôغɣ¬ £¬£¬£¬£¬×îÖÕͶ·ÅAsyncRATÔ¶³Ì½ÚÔìľÂí£¬ £¬£¬£¬£¬ÊµÏÔìÁÄ»¹²Ïí¡¢Îļþ´«Êä¼°Ô¶³ÌºÅÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Ö¸±êËø¶¨Ö¤È¯¹«Ë¾¡¢½ðÈÚ»ú¹¹¼°·ÇÒøÐнðÈÚ¹«Ë¾£¬ £¬£¬£¬£¬ÒòÕâЩ»ú¹¹Ð趨ÆÚÓëµ±²¿ÃÅÃÅ»¥»»¼à¹ÜÎļþ£¬ £¬£¬£¬£¬³ÉΪ³ÁµãÖ¸±ê¡£¡£¡£¡£¡£¡£¡£¡£Raven°²È«ÍŶÓͨ¹ý¼ø±ð¹¥»÷¼Ü¹¹ÖеĶà²ãì¶Üµã£¬ £¬£¬£¬£¬³É¹¦·¢ÏÖ²¢×èÖ¹ÁËÕâÒ»ÁãÈÕ¹¥»÷£¬ £¬£¬£¬£¬Ô¤·ÀÖ¸±ê»ú¹¹´ó¹æÄ£Ï°È¾¡£¡£¡£¡£¡£¡£¡£¡£ÓʼþÔ´×ԺϷ¨Ãâ·ÑÓÊÏäÕ˺ţ¬ £¬£¬£¬£¬Í¨¹ýSPF¡¢DKIM¼°DMARCÈÏÖ¤£¬ £¬£¬£¬£¬Èƹý´«Í³Óʼþ¹ýÂËÆ÷¡£¡£¡£¡£¡£¡£¡£¡£ÃÜÂë±£» £»£»£»£»¤¸½¼þÔ¤·À´«ÊäÖб»É±¶¾Èí¼þɨÃ裬 £¬£¬£¬£¬½âѹºó³öÏֵġ°NeededDocuments¡±¿ÉÖ´ÐÐÎļþÄÚÖÃshellcode£¬ £¬£¬£¬£¬shellcodeÓëAsyncRAT½ÚÔì·þÎñÆ÷³ÉÁ¢Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£¡£


https://cybersecuritynews.com/new-phishing-attack-mimic-as-income-tax-department/


3. React2Shell·ì϶´ó¹æÄ£ÀûÓ㬠£¬£¬£¬£¬³¬7.7ÍòIPÊÜÓ°Ïì


12ÔÂ6ÈÕ£¬ £¬£¬£¬£¬React2ShellÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©Òý·¢È«Çò°²È«Î£» £»£»£»£»ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚReact·þÎñÆ÷×é¼þ¶Ô¿Í»§¶Ë½ÚÔìÊý¾ÝµÄ²»°²È«·´ÐòÁл¯»úÔ죬 £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýµ¥¸öHTTPÒªÇó´¥·¢Î´¾­Éí·ÝÑéÖ¤µÄËÁÒâºÅÁîÖ´ÐУ¬ £¬£¬£¬£¬Ó°ÏìËùÓÐʵÏÖReact·þÎñÆ÷×é¼þµÄ¿ò¼ÜÈçNext.js¡£¡£¡£¡£¡£¡£¡£¡£Shadowserver»ã±¨ÏÔʾ£¬ £¬£¬£¬£¬³¬77,000¸ö¶³öÔÚ»¥ÁªÍøµÄIPµØÖ·Ò×Êܹ¥»÷£¬ £¬£¬£¬£¬ÆäÖÐÔ¼23,700¸öλÓÚÃÀ¹ú£¬ £¬£¬£¬£¬Éæ¼°¶à¸öÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£·ì϶Åû¶ºó£¬ £¬£¬£¬£¬°²È«×êÑÐÔ±Maple3142°ä²¼¸ÅÏëÑéÖ¤£¬ £¬£¬£¬£¬Íƶ¯×Ô¶¯»¯É¨Ã蹤¾ßѸËÙÀ©É¢¡£¡£¡£¡£¡£¡£¡£¡£GreyNoise¼à²âµ½£¬ £¬£¬£¬£¬´Óǰ24Ó×ʱÄÚÓÐ181¸ö·ÖÆçIP³¢ÊÔÀûÓø÷ì϶£¬ £¬£¬£¬£¬Á÷Á¿ÖØÒªÀ´×ÔºÉÀ¼¡¢Öйú¡¢ÃÀ¹ú¡¢Ïã¸ÛµÈµØÓò£¬ £¬£¬£¬£¬¹¥»÷Õß¶àʹÓÃPowerShellºÅÁîÈç¡°40138*41979¡±²âÊÔ·ì϶£¬ £¬£¬£¬£¬È·ÈϺóͨ¹ýbase64±àÂëÏÂÔØµÚ¶þ½×¶Î¾ç±¾£¬ £¬£¬£¬£¬²¿ÊðCobalt StrikeÐűê»òSnowlight¡¢Vshell¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬ÊµÏÖÔ¶³Ì½Ó¼û¡¢ºáÏòÒÆ¶¯¼°Ãô¸ÐÐÅÏ¢ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable/


4. Barts Health NHS TrustÔâClopÀÕË÷Èí¼þ¹¥»÷


12ÔÂ5ÈÕ£¬ £¬£¬£¬£¬Ó¢¹úBarts Health NHS Trust½üÈÕ°ä·¢£¬ £¬£¬£¬£¬ÆäOracle E-business SuiteÈí¼þ´æÔÚ·ì϶£¨CVE-2025-61882£©£¬ £¬£¬£¬£¬±»ClopÀÕË÷Èí¼þÍÅ»ïÀûÓ㬠£¬£¬£¬£¬µ¼ÖÂÊý¾Ý¿âÖÐÓâÔ½ÊýÄêµÄ·¢Æ±Îļþ±»µÁ¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÉæ¼°ÔڰʹĽ¡È«Ò½Ôº½ÓÊÜÒ½Öλò·þÎñÈËÔ±µÄÈ«Ãû¡¢µØÖ·£¬ £¬£¬£¬£¬²¿ÃÅǰ¹ÍÔ±¼°Òѹ«¿ªÊý¾ÝµÄ¹©¸øÉÌÐÅÏ¢£¬ £¬£¬£¬£¬ÒÔ¼°×Ô2024Äê4ÔÂÆð¸ÃÐÅÈÎÏòBarking¡¢HaveringºÍRedbridge´óѧҽԺNHSÐÅÈÎÌṩµÄ¹ÜÕÊ·þÎñÓйØÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ClopÒѽ«ÇÔÊØÐÅÏ¢ÉÏ´«ÖÁ°µÍøÐ¹Â¼ûÅ»§£¬ £¬£¬£¬£¬µ«BartsÇ¿µ÷£¬ £¬£¬£¬£¬Ä¿Ç°½öÏÞ¼ÓÃܰµÍøÓû§¿É½Ó¼ûѹËõÎļþ£¬ £¬£¬£¬£¬Î´·¢ÏÖÊý¾ÝÔÚ¹«¿ª»¥ÁªÍø´«²¼¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÓÚ2025Äê8Ô£¬ £¬£¬£¬£¬Ö±ÖÁ11ÔÂÎļþ±»°ä²¼ÖÁ°µÍøºó²ÅÈ·ÈÏÊý¾Ý·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£BartsÒÑÏò¹ú¶ÈÍøÂ簲ȫÖÐÐÄ¡¢Â׶ؾ¯Ô±Ìü¼°ÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©´«µÝÊÂÎñ£¬ £¬£¬£¬£¬²¢ÉêÇë¸ßµµ·¨ÔººÅÁî²»ÈÝÊý¾ÝʹÓᢰ䲼»ò·ÖÏí£¬ £¬£¬£¬£¬µ«´ËÀà½ûÁîÏÖʵЧÁ¦ÓÐÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔËÓªÂ×¶ØÎå¼ÒÒ½Ôº£¬ £¬£¬£¬£¬Ô̺¬»Ê¼ÒÂ×¶ØÒ½Ôº¡¢Ê¥°ÍÈûÂåçÑÒ½ÔºµÈ£¬ £¬£¬£¬£¬Æäµç×Ó²¡Àú¼°ÁÙ´²ÏµÍ³Î´ÊÜÓ°Ï죬 £¬£¬£¬£¬Ö÷ÌâIT»ù´¡ÉèÊ©°²È«ÐÔÈÔ»ñ×¢¶¨¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/barts-health-nhs-discloses-data-breach-after-oracle-zero-day-hack/


5. InotivÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂ9500ÓàÈËÊý¾Ýй¶


12ÔÂ5ÈÕ£¬ £¬£¬£¬£¬ÃÀ¹úÔìÒ©¹«Ë¾Inotiv½üÈÕÅû¶£¬ £¬£¬£¬£¬2025Äê8ÔÂ5ÈÕÖÁ8ÈÕÆÚ¼ä£¬ £¬£¬£¬£¬Æä²¿ÃÅÍøÂçºÍϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬£¬µ¼ÖÂÊý¾Ý¿â¼°ÄÚ²¿ÀûÓ÷¨Ê½Ì±»¾£¬ £¬£¬£¬£¬ÒµÎñÔËÓªÊÜÑϳÁÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ËæºóÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ìá½»ÎļþÈ·ÈÏ£¬ £¬£¬£¬£¬ÒѸ´Ô­ÊÜÓ°Ïìϵͳ½Ó¼ûȨÏÞ£¬ £¬£¬£¬£¬²¢ÕýÏò8ÔÂÊÂÎñÖÐÊý¾Ý±»µÁµÄ9,542ÃûÓ×ÎÒ·¢ËÍ֪ͨ£¬ £¬£¬£¬£¬Éæ¼°ÏÖÈÎ/ǰÈÎÔ±¹¤¡¢¾ìÊô¼°ÓëÊÕ¹º¹«Ë¾Óйý»¥¶¯µÄÆäËûÈËÔ±¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÓÉ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÕƹÜ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû³Æ£¬ £¬£¬£¬£¬ÇÔÈ¡ÁËInotiv³¬16.2Íò¸öÎļþ£¬ £¬£¬£¬£¬×ܼÆ176GB£¬ £¬£¬£¬£¬µ«InotivδÃ÷È·¾ßÌåй¶Êý¾ÝÀàÐÍ£¬ £¬£¬£¬£¬Ò²Î´È·ÈÏ÷è÷ëÉêÃ÷µÄÕæÊµÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Inotiv×ܲ¿Î»ÓÚÓ¡µÚ°²ÄÉÖÝ£¬ £¬£¬£¬£¬ÊÇÒ»¼ÒÄêÊÕÈ볬5ÒÚÃÀÔªµÄºÏͬ×êÑлú¹¹£¬ £¬£¬£¬£¬×¨Ò»Ò©Î↑·¢¡¢°²È«ÐÔÆÀ¹À¼°»îÌ嶯Îï×êÑÐÄ£Ð͹¹½¨£¬ £¬£¬£¬£¬Õ¼ÓÐÔ¼2000ÃûÔ±¹¤¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâ´Î¹¥»÷䲨¼°Ö÷ÌâÁÙ´²ÏµÍ³£¬ £¬£¬£¬£¬µ«Êý¾Ýй¶·çÏÕÈÔÒý·¢¼à¹Ü¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-discloses-data-breach-after-ransomware-attack/


6. ¶à½×¶Î¹¥»÷»î¶¯¶Ô×¼Palo AltoÓëSonicWall°²È«É豸


12ÔÂ6ÈÕ£¬ £¬£¬£¬£¬ÍþвÐÐΪÕß12ÔÂ2ÈÕÆðÀûÓõ¹úÍйܷþÎñÌṩÉÌ3xK GmbHÔËÓªµÄBGPÍøÂ磨AS200373£©ÏÂ7000Óà¸öIPµØÖ·£¬ £¬£¬£¬£¬ÌáÒéÕë¶ÔPalo Alto GlobalProtect VPNÃÅ»§¼°SonicWall SonicOS API¶ËµãµÄ¶à½×¶Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£GreyNoise»ã±¨ÏÔʾ£¬ £¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈͨ¹ý±©Á¦ÆÆ½â³¢ÊԵǼPalo Alto·À»ðǽµÄÔ¶³Ì½Ó¼û×é¼þGlobalProtect£¬ £¬£¬£¬£¬ËæºóתÏòɨÃèSonicOS API¶Ëµã¡ª¡ª¸Ã²Ù×÷ϵͳ½ÚÔìSonicWall·À»ðǽµÄÅäÖÃÓë¼à¿ØÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Óë11ÔÂÖÐÑ®¼Í¼µÄ230Íò´ÎGlobalProtectɨÃè´æÔÚ¹ØÁª£º62%µÄ¹¥»÷IPλÓڵ¹ú£¬ £¬£¬£¬£¬¾ùʹÓÃÒ»ÑùTCP/JA4tÖ¸ÎÆ£¬ £¬£¬£¬£¬ÇÒÔ´×Ô´ËǰÎÞ¶ñÒâ¼Í¼µÄËĸöASN¡£¡£¡£¡£¡£¡£¡£¡£º¹ÇàɨÃè»î¶¯ÔøÌìÉú³¬900Íò´Î²»³ÉαÔìµÄHTTP»á»°£¬ £¬£¬£¬£¬Ö¸±êÖ±Ö¸GlobalProtect¡£¡£¡£¡£¡£¡£¡£¡£12ÔÂ3ÈÕ£¬ £¬£¬£¬£¬Õë¶ÔSonicOS APIµÄɨÃèÖÐÔٴγöÏÖÒ»ÑùÈý¸ö¿Í»§Ö¸ÎÆ£¬ £¬£¬£¬£¬GreyNoise¾Ý´ËÅж¨Á½½×¶Î¹¥»÷ͬԴ¡£¡£¡£¡£¡£¡£¡£¡£Palo Alto Networks»ØÓ¦³Æ£¬ £¬£¬£¬£¬¼ì²âµ½µÄɨÃè»î¶¯ÊôÓÚ¡°Æ¾Ö¤¹¥»÷¶ø·Ç·ì϶ÀûÓá±£¬ £¬£¬£¬£¬ÆäÄÚ²¿Ò£²â¼°Cortex XSIAM·À»¤ÏµÍ³È·ÈÏδ¶Ô²úÆ··þÎñÔì³ÉÇÖº¦£¬ £¬£¬£¬£¬½¨Òé¿Í»§ÆôÓöà³É·ÖÈÏÖ¤£¨MFA£©·À±¸Æ¾Ö¤ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£SonicWall·½ÃæÉÐδ¹«¿ªÖÃÆÀ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-wave-of-vpn-login-attempts-targets-palo-alto-globalprotect-portals/