Space BearsÀÕË÷×éÖ¯½èQuasar·ì϶ÇÔÈ¡ComcastÊý¾Ý
°ä²¼¹¦·ò 2025-12-101. Space BearsÀÕË÷×éÖ¯½èQuasar·ì϶ÇÔÈ¡ComcastÊý¾Ý
12ÔÂ8ÈÕ£¬£¬£¬£¬£¬Space BearsÀÕË÷Èí¼þ×éÖ¯½üÈÕÔÚ°µÍøÐ¹ÃÜÍøÕ¾Ðû³Æ£¬£¬£¬£¬£¬Í¨¹ý×ôÖÎÑÇÖݵçÐŹ¤³Ì³Ð°üÉÌQuasar Inc.µÄ·ì϶»ñÈ¡ÁËComcastÄÚ²¿×ÊÁÏ£¬£¬£¬£¬£¬²¢Í¬²½½«QuasarÁÐΪ¶ÀÁ¢Êܺ¦Õߣ¬£¬£¬£¬£¬°µÊ¾Á½Æð¹ØÁªÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯2024Äê4Ô³öÏÖ£¬£¬£¬£¬£¬±»·ÖÎöΪÊý¾ÝÇÔÈ¡ÐÍÀÕË÷¼¯Ì壬£¬£¬£¬£¬³£Í¨¹ýɾ³ýÃô¸ÐÎļþ²¢Ë÷ÒªÊê½ð×èÖ¹°ä²¼£¬£¬£¬£¬£¬ÓëPhobosÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©·¨Ê½´æÔÚ¹ØÁª£¬£¬£¬£¬£¬ÆäйÃÜÍøÕ¾±»ÊÓΪÓйػ¹²Ïí°ä²¼µã¡£¡£¡£¡£¡£¡£¡£¡£Õë¶ÔComcastµÄÖ¸¿ØÖУ¬£¬£¬£¬£¬Space BearsÐû³ÆQuasarΪComcast¼°GenesisÏîÄ¿Ôì×÷¼¼ÊõÎĵµ£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡Ô̺¬¶àµØ³ÇÊÐÉè¼ÆÎĵµºÍ¹«ÓÃÉèÊ©¹æ»®Í¼µÄÐÅÏ¢£¬£¬£¬£¬£¬²¢É趨6Ììµ¹¼ÆÊ±£¬£¬£¬£¬£¬ÓâÆÚ½«¹«¿ªÊý¾Ý£¬£¬£¬£¬£¬ÆÚ¼äÌṩÊý¾ÝÊÛÂô·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬¸Ã×é֯δÌṩÎļþÑù±¾£¬£¬£¬£¬£¬¶ÀÁ¢ÑéÖ¤Ôݲ»³ÉÐС£¡£¡£¡£¡£¡£¡£¡£Quasar Inc.ÓÚ2025Äê12ÔÂ4ÈÕ±»µ¥¶ÀÁÐΪÊܺ¦Õߣ¬£¬£¬£¬£¬Space BearsÐû³Æ»ñÈ¡ÆäÍøÂçÏîÄ¿¡¢³ÇÊй滮ͼ¡¢Í¨Ñ¶²¼¾ÖµÈÄÚ²¿Îĵµ£¬£¬£¬£¬£¬²¢¿ªÆôËÄÌìµ¹¼ÆÊ±ÊÛÂôÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
https://hackread.com/space-bears-ransomware-comcast-quasar-breach/
2. WordPress²å¼þ¸ßΣ·ì϶Ôâ´ó¹æÄ£ÀûÓÃ
12ÔÂ8ÈÕ£¬£¬£¬£¬£¬Wordfence¼à²âÏÔʾ£¬£¬£¬£¬£¬WordPressƽ̨µÄSneeit Framework²å¼þ´æÔÚ¸ßΣԶ³Ì´úÂëÖ´Ðзì϶CVE-2025-6389£¨CVSSÆÀ·Ö9.8£©£¬£¬£¬£¬£¬Ó°Ïì8.3¼°ÒÔϰ汾£¬£¬£¬£¬£¬ÒÑͨ¹ý2025Äê8ÔÂ5ÈÕ°ä²¼µÄ8.4°æ±¾½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²å¼þ»îÔ¾×°ÖÃÁ¿³¬1700¸ö£¬£¬£¬£¬£¬·ì϶ԴÓÚº¯ÊýδÑéÖ¤Óû§ÊäÈëÖ±½ÓÖ´ÐдúÂ룬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´Ë´´½¨¶ñÒâÖÎÀíÔ¹ØË»§¡¢Ö²ÈëºóÃÅ£¬£¬£¬£¬£¬»ò³Á¶¨Ïò·Ã¿ÍÖÁ´¹µö/¶ñÒâÕ¾µã¡£¡£¡£¡£¡£¡£¡£¡£×Ô11ÔÂ24ÈÕ·ì϶¹«¿ªºó£¬£¬£¬£¬£¬WordfenceÒÑÀ¹½Ø³¬13.1Íò´Î¹¥»÷£¬£¬£¬£¬£¬24Ó×ʱÄÚ¼´¼Í¼15381´Î¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¡°/wp-admin/admin-ajax.php¡±¶Ëµã·¢ËÍÌØÔìÒªÇ󣬣¬£¬£¬£¬´´½¨¡°arudikadis¡±µÈ¶ñÒâÕË»§£¬£¬£¬£¬£¬ÉÏ´«¡°tijtewmg.php¡±µÈ¾ß±¸Ä¿Â¼É¨Ãè¡¢Îļþ²Ù×÷Ö°ÄܵĶñÒâÎļþ£¬£¬£¬£¬£¬²¢´Ó±í²¿·þÎñÆ÷ÏÂÔØ¡°.htaccess¡±ÎļþÈÆ¹ý½Ó¼ûÏÞ¶È¡£¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬VulnCheck¼à²âµ½¹¥»÷ÕßÀûÓÃICTBroadcast·ì϶CVE-2025-2611£¨CVSSÆÀ·Ö9.3£©£¬£¬£¬£¬£¬Í¨¹ýÏÂÔØShell¾ç±¾¼ÓÔØÆ÷´«²¼Frost DDoS½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html
3. ´¹µö¹¤¾ß°üGhostFrameÏòÈ«ÇòÊý°ÙÍòÓû§ÌáÒé¹¥»÷
12ÔÂ8ÈÕ£¬£¬£¬£¬£¬Barracuda°²È«×êÑÐÔ±ÓÚ2025Äê9Ô³õ´Î·¢ÏÖÃûΪGhostFrameµÄÐÂÐ͸߸´ÔÓ¶È´¹µö¹¤¾ß°ü£¬£¬£¬£¬£¬¸Ã¹¤¾ßÒÑÌáÒ鳬100Íò´Î¹¥»÷£¬£¬£¬£¬£¬±ê־ȡ´¹µö¼´·þÎñ£¨PaaS£©¼¼ÊõµÄΣÏÕÉý¼¶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖ÷ÌâÍþвÔÚÓÚ½«¶ñÒâ²Ù×÷ÒþÄäÓÚÒþÐÎiframe¿ò¼ÜÖУ¬£¬£¬£¬£¬Í¨¹ýÌìÉú¿´ËÆÎÞº¦µÄHTMLÎļþ£¬£¬£¬£¬£¬ÔÚÒ³Ãæµ×²ã¼ÓÔØÀ´×Ô¶¯Ì¬×ÓÓòÃûµÄÕæÊµ´¹µöÄÚÈÝ£¬£¬£¬£¬£¬Ê¹°²È«¹¤¾ßÄÑÒÔ¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Á÷³Ì·ÖΪÁ½½×¶Î£ºÊ×ÏÈͨ¹ý¼Ù×°³É¡°±£ÃܺÏͬ¡±¡°ÃÜÂë³ÁÖá±µÈÖ÷ÌâµÄ´¹µöÓʼþÓÕµ¼Óû§µã»÷£»£»£»£»£»ËæºóÓû§½øÈë¿´ËÆ°²È«µÄÍøÒ³£¬£¬£¬£¬£¬µ×²ãiframe´Óʵʱµ÷»»µÄ×ÓÓòÃû¼ÓÔØ¹¥»÷ÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£Îª¶ã±Ü¼ì²â£¬£¬£¬£¬£¬¹¥»÷ÕßΪÿ¸öÖ¸±êµ¥¶À´´½¨×¨Êô×ÓÓòÃû£¬£¬£¬£¬£¬²¢ÄÚÖ÷´·ÖÎöÖ°ÄÜ£¬£¬£¬£¬£¬Èç½ûÓÃÓÒ¼ü²Ëµ¥¡¢ÆÁ±Î¿ì½Ý¼ü¼°¹Ø¹Ø¿ª·¢Õß¹¤¾ß£¬£¬£¬£¬£¬¹ÊÕϰ²È«ºË²é¡£¡£¡£¡£¡£¡£¡£¡£GhostFrame´îÔØ¶àÏî¸ßÒñ±Î¸öÐÔ£º´¹µö±íµ¥°µ²ØÔÚ´óÎļþͼÏñÁ÷ÖÐÈÆ¹ý´«Í³É¨Ã裻£»£»£»£»×ÓÓòÃû¶¯Ì¬ÂÖ»»¹²Í¬±¸ÓÃiframe¿ò¼Ü£¬£¬£¬£¬£¬Ó¦¶ÔJavaScriptÀ¹½Ø£»£»£»£»£»Ö§³Ö¶àÖ¸±ê½Ã½ÝÊÊÅ䣬£¬£¬£¬£¬ÎÞÐèÅú¸ÄÖ÷Ò³Ãæ¼´¿É´úÌæ´¹µöÄÚÈÝ£»£»£»£»£»Í¨¹ýÅú¸ÄÒ³Ãæ±êÌâºÍͼ±ê·ÂðºÏ·¨·þÎñ£¬£¬£¬£¬£¬¼ÓÇ¿¼Ù×°ÕæÊµÐÔ¡£¡£¡£¡£¡£¡£¡£¡£
https://cybersecuritynews.com/new-ghostframe-super-stealthy-phishing-kit-attacks-millions-of-users-worldwide/
4. ºÚ¿ÍÀûÓÃReact2Shell·ì϶ÌáÒéEtherRAT¶ñÒâÈí¼þ¹¥»÷
12ÔÂ9ÈÕ£¬£¬£¬£¬£¬Ôư²È«¹«Ë¾SysdigÅû¶ÁËÒ»ÖÖÃûΪEtherRATµÄÐÂÐͶñÒâÈí¼þ£¬£¬£¬£¬£¬Æäͨ¹ýÀûÓÃReact/Next.js¿ò¼ÜÖеĸßΣ·ì϶CVE-2025-55182£¨React2Shell£©Ö´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚReact Server ComponentsµÄ¡°Flight¡±ºÍ̸·´ÐòÁл¯È±µã£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ý¶ñÒâHTTPÒªÇóÖ´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬£¬Ó°Ïì´óÁ¿ÔÆ»·¾³¡£¡£¡£¡£¡£¡£¡£¡£Sysdig×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬EtherRATÓ볯ÏÊ¡°´«È¾ÐÔ·Ã̸¡±»î¶¯Ê¹ÓõŤ¾ß´æÔÚ¹ØÁªÐÔ£¬£¬£¬£¬£¬µ«¾ß±¸¹ÖÒì¼¼ÊõÌØµã¡£¡£¡£¡£¡£¡£¡£¡£EtherRATѡȡ¶à½×¶Î¹¥»÷Á´£ºÊ×ÏÈͨ¹ýReact2Shell·ì϶ÔÚÖ¸±êϵͳִÐÐBase64±àÂëµÄshellºÅÁ£¬£¬£¬£¬ÏÂÔØ²¢ÔËÐжñÒâ¾ç±¾s.sh¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¾ç±¾»á´´½¨°µ²ØÄ¿Â¼£¬£¬£¬£¬£¬²¿ÊðºÏ·¨Node.jsÔËÐÐʱ¼°¼ÓÃÜÓÐÐ§ÔØºÉ£¬£¬£¬£¬£¬×îÖÕ½âÃܳöEtherRATÖ²È뷨ʽ¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖ÷Ìâ´´ÐÂÔÚÓÚ»ùÓÚÒÔÌ«·»ÖÇÄܺÏÔ¼µÄC2ͨѶ»úÔ죬£¬£¬£¬£¬Í¨¹ý²éÎÊ9¸ö¹«¹²ÒÔÌ«·»RPC½Úµã²¢Ñ¡È¡ÎÞÊýÏìÓ¦Õ½ÊõÕмܵ¥µã¹ÊÕÏ£¬£¬£¬£¬£¬ÊµÏֽýÝÇÒ¿¹×ÌÈŵÄÖ¸Áî´«Êä¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-react2shell-flaw-in-etherrat-malware-attacks/
5. ÐÂÐÍMirai±äÖÖÀûÓú£ÊÂDVR·ì϶ִÐи´ÔÓ¹¥»÷
12ÔÂ9ÈÕ£¬£¬£¬£¬£¬Cydome×êÑÐÈËÔ±·¢ÏÖÃûΪBroadsideµÄÐÂÐÍMirai½©Ê¬ÍøÂç±äÖÖ£¬£¬£¬£¬£¬¸Ã±äÖÖÕë¶Ôº£ÊÂÎïÊ¢ÐÐÒµ£¬£¬£¬£¬£¬ÀûÓô¬²°¼°É豸ʹÓõÄTBK DVRÉ豸ÖеĺÅÁî×¢Èë·ì϶CVE-2024-3721ÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓÚ2024Äê4ÔÂÅû¶²¢¸½´øPoC´úÂ룬£¬£¬£¬£¬ÖÁ2025ÄêÖÐÒѱ»¶à¸öDDoS½©Ê¬ÍøÂç¿í·ºÀûÓᣡ£¡£¡£¡£¡£¡£¡£Mirai½©Ê¬ÍøÂçÔ´´úÂëÔÚ½üÊ®Äêǰ¹«¿ªºó£¬£¬£¬£¬£¬³ÖÐø±»ÍøÂç·¸×ï·Ö×ÓÅú¸Ä³ÁÓÃÒÔÇý¶¯´ó¹æÄ£¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËԱǿµ÷£¬£¬£¬£¬£¬TBK DVR·ì϶ͬÑùÓ°ÏìÒÔCeNova¡¢Night Owl¡¢QSeeµÈÆ·ÅÆ³Áаü×°µÄÐͺţ¬£¬£¬£¬£¬¶Ôº½Ô˹«Ë¾×é³ÉÑϳÁÍþв¡£¡£¡£¡£¡£¡£¡£¡£ÈëÇÖÉ豸¿ÉÄÜʹ¹¥»÷Õß½Ó¼û¼ÝÊ»ÊÒ¡¢»õ²Õ»ò»ú²ÕµÄCCTV»Ã棬£¬£¬£¬£¬×ÌÈÅÎÀÐÇͨѶ£¬£¬£¬£¬£¬»òºáÏòÒÆ¶¯ÖÁ´¬²°¹Ø¼üÔËÓª¼¼Êõϵͳ¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬Broadside²»½öÏÞÓÚDDoS¹¥»÷£¬£¬£¬£¬£¬Æä×Ô¶¯ÇÔȡϵͳƾ֤ÎļþµÄÐÐΪÅú×¢£¬£¬£¬£¬£¬¹¥»÷ÕßÒâͼ½«ÊÜϰȾÉ豸´Óµ¥Ò»½©Ê¬ÍøÂç½Úµãת±äΪսÊõ°²Éíµã¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/185491/malware/broadside-botnet-hits-tbk-dvrs-raising-alarms-for-maritime-logistics.html
6. Vitas HealthcareÔâÍøÂç¹¥»÷Ö³¬30ÍòÈËÐÅϢй¶
12ÔÂ9ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©Ò½ÁƱ£½¡Êý¾Ýй¶׷×ÙÆ÷ÏÔʾ£¬£¬£¬£¬£¬ÃÀ¹ú×î´óͶ»úÐÔÁÙÖÕ¹ØÇÐÁ¬Ëø»ú¹¹Vitas Healthcare½üÆÚ²úÉú³Á´óÍøÂ簲ȫÊÂÎñ£¬£¬£¬£¬£¬Ó°ÏìÈËÊý´ï319,177ÈË¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹´ÓÊôÓÚChemed¼¯ÍÅ£¬£¬£¬£¬£¬ÆìÏÂVitas Hospice ServicesÓÚ10ÔÂ24ÈÕ·¢ÏÖϵͳÈëÇÖ£¬£¬£¬£¬£¬µ÷²éÏÔʾ¹¥»÷Õßͨ¹ý±»µÁÓõĹ©¸øÉÌÕË»§£¬£¬£¬£¬£¬ÔÚ9ÔÂ21ÈÕÖÁ10ÔÂ27ÈÕÆÚ¼ä³ÖÐø½Ó¼ûÆäϵͳ£¬£¬£¬£¬£¬²¢ÏÂÔØÁË´óÁ¿»¼Õß¼°½üÇ×µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾ÝÁìÓò¿í·º£¬£¬£¬£¬£¬Ô̺¬»¼Õß¼°Ç°»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢Éç»á±£ÏÕºÅÂë¡¢Ò½ÁƼͼ¡¢±£ÏÕÐÅÏ¢ÒÔ¼°Ç×ÊôÁªÏµ·½Ê½µÈÖ÷ÌâÓ×ÎÒÉí·ÝÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜĿǰÉÐδÃ÷È·Õâ´ÎÊÂÎñÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ÇÒÎÞÒÑÖªÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´ËÕÆ¹Ü£¬£¬£¬£¬£¬µ«ÊÂÎñµÄÑϳÁÐÔÒÑÒý¿¯ÐÐÒµ¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬VitasÒÑͨ¹ýרÃÅÊý¾ÝÐ¹Â¶Í¨ÖªÍøÕ¾Ïò¹«¼ÒÅû¶ÊÂÎñÏêÇ飬£¬£¬£¬£¬µ«¾ßÌå¼¼Êõϸ½Ú¼°ºóÐø²¹¾È´ëÊ©ÉÐδÆëÈ«¹«¿ª¡£¡£¡£¡£¡£¡£¡£¡£
https://www.securityweek.com/over-300000-individuals-impacted-by-vitas-hospice-data-breach/


¾©¹«Íø°²±¸11010802024551ºÅ