Gladinet¼ÓÃÜ·ì϶ÖÂ9¼Ò»ú¹¹±»Ô¶³Ì¹¥»÷
°ä²¼¹¦·ò 2025-12-151. Gladinet¼ÓÃÜ·ì϶ÖÂ9¼Ò»ú¹¹±»Ô¶³Ì¹¥»÷
12ÔÂ11ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÕýÀûÓÃGladinet CentreStackºÍTriofox²úÆ·ÖÐδ¼Í¼µÄ¼ÓÃÜËã·¨·ì϶ִÐй¥»÷¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚAES¼ÓÃÜËã·¨µÄ×Ô½ç˵ʵÏÖ´æÔÚÓ²±àÂëÃÜԿȱµã£¬£¬£¬£¬£¬GladCtrl64.dllÎļþÖд洢µÄ¼ÓÃÜÃÜÔ¿ºÍ³õʼ»¯ÏòÁ¿£¨IV£©Ô´×ÔÁ½¸ö¾²Ì¬µÄ100×Ö½ÚÖÐÎÄ×Ö·û´®£¬£¬£¬£¬£¬ÔÚËùÓвúÆ·×°ÖÃÖÐÆëȫһÑù¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÌáÈ¡ÕâЩÃÜÔ¿½âÃܽӼûµ¥¾Ýº¬Îļþõè¾¶¡¢Óû§Æ¾Ö¤µÈÐÅÏ¢£¬£¬£¬£¬£¬»òαÔìµ¥¾Ý¼ÙÒâÓû§»ñȡϵͳÎļþ¡£¡£¡£¡£¡£¾ßÌå¹¥»÷õè¾¶ÏÔʾ£¬£¬£¬£¬£¬ÍþвÐÐΪÕßͨ¹ý"filesvr.dn"´¦Ö÷¨Ê½ÀûÓ÷ì϶£¬£¬£¬£¬£¬½«½Ó¼ûµ¥¾ÝµÄ¹¦·ò´ÁÉèÖÃΪ9999ÄêʵÏÖÓÀÔ¶ÓÐЧ£¬£¬£¬£¬£¬ËæºóÒªÇóweb.configÎļþ»ñÈ¡machineKey£¬£¬£¬£¬£¬×îÖÕͨ¹ýViewState·´ÐòÁл¯´¥·¢Ô¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Huntress°²È«ÍŶӼà²â·¢ÏÖ£¬£¬£¬£¬£¬ÖÁÉÙ9¼ÒÒ½ÁÆ¡¢¼¼ÊõµÈÐÐÒµµÄ»ú¹¹Ôâ´Ë¹¥»÷£¬£¬£¬£¬£¬¹¥»÷Õß»¹½áºÏÁ˾ɷì϶CVE-2025-30406À©´ó·ÛËé¡£¡£¡£¡£¡£GladinetÒѰ䲼´¹Î£¸üУ¬£¬£¬£¬£¬²¢½¨ÒéÓû§Éý¼¶ºóÁ¢¼´ÂÖ»»»úеÃÜÔ¿¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-gladinet-centrestack-cryptographic-flaw-in-rce-attacks/
2. ConsentFix¹¥»÷ÈÆ¹ýMFA½Ù³Ö΢ÈíÕË»§
12ÔÂ11ÈÕ£¬£¬£¬£¬£¬ÍøÂ簲ȫ¹«Ë¾Push Security·¢ÏÖÒ»ÖÖÃûΪ¡°ConsentFix¡±µÄÐÂÐÍClickFix¹¥»÷±äÖÖ£¬£¬£¬£¬£¬¸Ã¹¥»÷ͨ¹ýÀÄÓÃAzure CLI OAuthÀûÓ÷¨Ê½£¬£¬£¬£¬£¬ÔÚÎÞÐèÃÜÂë»ò¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©µÄÇé¿öϽٳÖMicrosoftÕË»§¡£¡£¡£¡£¡£¹¥»÷ʼÓÚÊܺ¦Õß½Ó¼û±»ÈëÇֵĺϷ¨ÍøÕ¾£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾Í¨¹ýGoogleËÑË÷Õë¶ÔÌØ¶¨¹Ø¼ü´ÊÅÅÃû¿¿Ç°¡£¡£¡£¡£¡£ÍøÕ¾Ò³Ãæ»áÏÔʾαÔìµÄCloudflare TurnstileÑéÖ¤ÂëÓײ¿¼þ£¬£¬£¬£¬£¬ÒªÇóÓû§ÊäÈëÓÐЧÆóÒµÓÊÏ䵨ַ£¬£¬£¬£¬£¬¹¥»÷Õ߾籾»á¹ýÂË»úеÈË¡¢·ÖÎöʦ¼°Î´ÁÐÈëÖ¸±êµÄÓû§¡£¡£¡£¡£¡£Í¨¹ýÑéÖ¤µÄÓû§½«¿´µ½ÀàËÆClickFixµÄ½»»¥Ò³Ã棬£¬£¬£¬£¬Êèµ¼ÆäÖ´ÐÓ×°ÑéÖ¤ÈËÀàÉí·Ý¡±µÄ²Ù×÷¡£¡£¡£¡£¡£Óû§µã»÷Ò³ÃæÖеġ°µÇ¼¡±°´Å¥ºó£¬£¬£¬£¬£¬»á±»³Á¶¨Ïòµ½ºÏ·¨µÄ΢ÈíAzureµÇÂ¼Ò³Ãæ¡£¡£¡£¡£¡£ÈôÓû§ÒѵǼ΢ÈíÕË»§£¬£¬£¬£¬£¬Ö»ÐèÑ¡Ôñ×Ô¼ºµÄÕË»§£»£»£»£»£»£»£»£»ÈôδµÇ¼£¬£¬£¬£¬£¬ÔòÐèÔÚ΢Èí¹Ù·½Ò³ÃæÊµÏÖÕý³£Éí·ÝÑéÖ¤¡£¡£¡£¡£¡£ÊµÏֵǼºó£¬£¬£¬£¬£¬Î¢Èí»á½«Óû§³Á¶¨Ïòµ½±¾µØÖ÷»úÒ³Ãæ£¬£¬£¬£¬£¬´Ëʱä¯ÀÀÆ÷µØÖ·À¸»áÏÔʾÔ̺¬Azure CLI OAuthÊÚȨÂëµÄURL¡£¡£¡£¡£¡£µ±Óû§ÒÀÕÕÅúʾ½«¸ÃURLÕ³Ìùµ½¶ñÒâÒ³ÃæÊ±£¬£¬£¬£¬£¬¹¥»÷Õß¼´¿Éͨ¹ýAzure CLI OAuthÀûÓûñÈ¡ÆëÈ«µÄÕË»§½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-consentfix-attack-hijacks-microsoft-accounts-via-azure-cli/
3. PayPal¶©ÔÄÖ°ÄÜÔâÀÄÓÃÖÂÚ¿ÆÓʼþ·ºÀÄ
12ÔÂ14ÈÕ£¬£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬£¬Ú¿Æ·Ö×ÓÀÄÓÃPayPalµÄ¡°¶©ÔÄ¡±¼Æ·ÑÖ°ÄÜ£¬£¬£¬£¬£¬ÏòÓû§·¢ËͼÙ×°³ÉºÏ·¨PayPalÓʼþµÄÚ¿ÆÐÅÏ¢¡£¡£¡£¡£¡£ÕâÀàÓʼþÐû³Æ¡°×Ô¶¯¸¶¿îʧЧ¡±£¬£¬£¬£¬£¬ÊµÔòǶÈëÐéα²É°ì֪ͨ£¬£¬£¬£¬£¬ÈçÐû³ÆÓû§²É°ìÁËË÷ÄáÉ豸¡¢MacBook»òiPhoneµÈ°º¹óÉÌÆ·£¬£¬£¬£¬£¬²¢¸½ÓÐ1300ÖÁ1600ÃÀÔª²»µÈµÄ¸¶¿î¼Í¼¼°¡°¿Í·þµç»°¡±¡£¡£¡£¡£¡£Óʼþͨ¹ý¡°mailto:service@paypal.com¡±µØÖ··¢ËÍ£¬£¬£¬£¬£¬ÇÒͨ¹ýÁËDKIM¡¢SPF¼°DMARCµÅ×ʼþ°²È«ÈÏÖ¤£¬£¬£¬£¬£¬Ö±½ÓÀ´×ÔPayPal¹Ù·½·þÎñÆ÷£¬£¬£¬£¬£¬Òò¶øÄÜÈÆ¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£¬£¬£¬£¬£¬¼«¾ßºýŪÐÔ¡£¡£¡£¡£¡£Ú¿Æ·Ö×Óͨ¹ýÅú¸Ä¿Í»§·þÎñURL×ֶΣ¬£¬£¬£¬£¬½«ÐéαÐÅϢǶÈëºÏ·¨ÓʼþÄ£°å¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬URLÖпÉÄÜÔ̺¬ÓòÃû¡¢¸¶¿î½ð¶î¼°¡°È¡µÞ»òÕ÷ѯ¡±µç»°ºÅÂ룬£¬£¬£¬£¬²¢Í¬»¯Unicode×Ö·ûÒÔ´ÖÌå»òÌØÊâ×ÖÌåÏÔʾ£¬£¬£¬£¬£¬ÊÔͼ¶ã±Ü¹Ø¼ü´Ê¼ì²â¡£¡£¡£¡£¡£Í¨¹ý²âÊÔ·¢ÏÖ£¬£¬£¬£¬£¬µ±É̼ÒÔÝÍ£¶©ÔÄÓû§Ê±£¬£¬£¬£¬£¬PayPal»á×Ô¶¯·¢ËÍ֪ͨÓʼþ£¬£¬£¬£¬£¬¶øÚ¿ÆÕß¿ÉÄÜÀûÓö©ÔÄÔªÊý¾Ý´¦Ö÷ì϶»ò¾Éƽ̨½Ó¿Ú£¬£¬£¬£¬£¬ÔÚURL×Ö¶ÎÖÐ×¢ÈëÎÞЧÎı¾£¬£¬£¬£¬£¬´Ó¶øÌìÉúÚ¿ÆÓʼþ¡£¡£¡£¡£¡£ÕâЩÓʼþ¿ÉÄܱ»×ª·¢ÖÁδע²áPayPal¶©ÔĵÄÓû§¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/beware-paypal-subscriptions-abused-to-send-fake-purchase-emails/
4. Ç×¶íVolkLockerÀÕË÷Èí¼þ·ì϶»òÖÂÃâ·Ñ½âÃÜ
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬Ç×¶íºÚ¿Í×éÖ¯CyberVolkÍÆ³öµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©VolkLocker´æÔÚ³Á´óʵÏÖȱµã£¬£¬£¬£¬£¬Ê¹Êܺ¦Õß¿ÉÄÜÎÞÐèÖ§¸¶Êê½ð¼´¿É¸´ÔÎļþ¡£¡£¡£¡£¡£¾ÝSentinelOne×êÑУ¬£¬£¬£¬£¬¸ÃÈí¼þÔÚ¶þ½øÔìÎļþÖÐÓ²±àÂëÁËÖ÷ÃÜÔ¿£¬£¬£¬£¬£¬ÇÒ¸ÃÃÜÔ¿ÒÔÃ÷ÎÄ´ó¾Ö´æ´¢ÓÚÊÜϰȾ»úеµÄ%TEMP%Îļþ¼ÐÖУ¬£¬£¬£¬£¬Êܺ¦Õß¿Éͨ¹ýÌáÈ¡¸ÃÃÜÔ¿³¢ÊÔ½âÃÜ¡£¡£¡£¡£¡£VolkLockerѡȡAES-256 GCM¼ÓÃÜ£¬£¬£¬£¬£¬Ã¿¸öÎļþʹÓÃËæ»ú12×Ö½Únonce×÷Ϊ³õʼ»¯ÏòÁ¿£¬£¬£¬£¬£¬¼ÓÃܺ󸽼Ó.locked»ò.cvolkÀ©´óÃû²¢É¾³ýÔʼÎļþ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬ÓÉÓÚËùÓÐÎļþ¹²ÏíͳһÖ÷ÃÜÔ¿ÇÒÃÜԿδ±»É¾³ý£¬£¬£¬£¬£¬¸Ã·ì϶ÏÔÖø¼õÈõÁËÆäÀÕË÷ÄÜÁ¦¡£¡£¡£¡£¡£CyberVolk×ܲ¿Î»ÓÚÓ¡¶È£¬£¬£¬£¬£¬×Ô2024ÄêÆð»îÔ¾£¬£¬£¬£¬£¬Ôø¶Ô·´¶í»òÖ§³ÖÎÚ¿ËÀ¼µÄʵÌåÌáÒéDDoSºÍÀÕË÷¹¥»÷¡£¡£¡£¡£¡£2025Äê8Ô£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÔVolkLocker 2.x°æ±¾»Ø¹é£¬£¬£¬£¬£¬Í¬Ê¹Øë¶ÔLinux/VMware ESXiºÍWindowsϵͳ£¬£¬£¬£¬£¬²¢ÒýÈëGolang°´Ê±Æ÷Ö°ÄÜ£¬£¬£¬£¬£¬Èô³¬Ê±»òÊäÈëÃýÎóÃÜÔ¿£¬£¬£¬£¬£¬½«²Á³ýÓû§Îĵµ¡¢ÏÂÔØ¡¢Í¼Æ¬ºÍ×ÀÃæÎļþ¼Ð¡£¡£¡£¡£¡£RaaS¶¨¼Û°´²Ù×÷ϵͳ¼Ü¹¹»®·Ö£ºµ¥Ò»ÏµÍ³800-1100ÃÀÔª£¬£¬£¬£¬£¬Ë«ÏµÍ³1600-2200ÃÀÔª£¬£¬£¬£¬£¬²É°ìÕß¿Éͨ¹ýTelegram¹¹½¨»úеÈ˶¨Ôì¼ÓÃÜÆ÷²¢»ñÈ¡ÓÐÐ§ÔØºÉ¡£¡£¡£¡£¡£Í¬Äê11Ô£¬£¬£¬£¬£¬¸Ã×éÖ¯»¹ÍƳö500ÃÀÔªµÄÔ¶³Ì½Ó¼ûľÂíºÍ¼üÅ̼ͼÆ÷¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cybervolks-ransomware-debut-stumbles-on-cryptography-weakness/
5. CISA¸üÐÂKEVĿ¼£¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹2026ËêÊ×½¨¸´·ì϶
12ÔÂ13ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«CVE-2025-14174£¨Google ChromiumÔ½½çÄÚ´æ½Ó¼û·ì϶£©ºÍCVE-2018-4063£¨Sierra Wireless AirLink ALEOSÎÞÏÞ¶ÈÉÏ´«·ì϶£©²¹³äÖÁÒÑÖª¿ÉÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¡£¡£¡£¡£CVE-2025-14174ÊÇGoogle Chrome 143.0.7499.110°æ±¾Ç°Macϵͳ´æÔÚµÄANlgeͼÐοâ·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚMetaläÖȾÆ÷¶ÔGL_UNPACK_IMAGE_HEIGHTÖµµÄÃýÎóÍÆË㣬£¬£¬£¬£¬µ±Í¼Ïñ¸ß¶È³¬¹ý»º³åÇøÈÝÁ¿Ê±£¬£¬£¬£¬£¬»á´¥·¢Ô½½çÄÚ´æ½Ó¼û£¬£¬£¬£¬£¬µ¼ÖÂÄÚ´æ°Ü»µ¡¢·¨Ê½±ÀÀ£ÉõÖÁËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¹È¸èÒÑͨ¹ý°²È«¸üн¨¸´´Ë·ì϶£¬£¬£¬£¬£¬²¢È·Èϸ÷ì϶ÒÑÔÚÏÖʵ¹¥»÷Öб»ÀûÓᣡ£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬¹È¸èδ¹«¿ª¼¼Êõϸ½Ú£¬£¬£¬£¬£¬µ«GitHubÌá½»¼Í¼ÏÔʾ·ì϶Ó뻺³åÇøÒç³öÖ±½ÓÓйء£¡£¡£¡£¡£ÁíÒ»·ì϶CVE-2018-4063ÔòÓ°ÏìSierra Wireless AirLink ES450¹Ì¼þ4.9.3µÄupload.cgi×é¼þ¡£¡£¡£¡£¡£¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õ߿ɷ¢ËÍÌØÔìHTTPÒªÇ󣬣¬£¬£¬£¬ÔÚÉ豸Web·þÎñÆ÷ÉÏ´«²¢Ö´ÐжñÒâ´úÂ룬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¸Ã·ì϶×Ô2018ÄêÅû¶ÒÔÀ´£¬£¬£¬£¬£¬Òòδʵʱ½¨¸´ÈÔ±»CISAÄÉÈëĿ¼¡£¡£¡£¡£¡£
https://securityaffairs.com/185639/security/u-s-cisa-adds-google-chromium-and-sierra-wireless-airlink-aleos-flaws-to-its-known-exploited-vulnerabilities-catalog.html
6. ·´µÁ°æÁªÃËACEµ·»ÙÓ¡¶È°ÙÍò¼¶·Ã¿ÍµÁ°æÆ½Ì¨
12ÔÂ12ÈÕ£¬£¬£¬£¬£¬ÓɵÏÊ¿Äá¡¢»ªÄÉÐֵܡ¢NetflixµÈ50Óà¼ÒÓ°ÊÓÍøÂç¾ÞÍ·Ö§³ÖµÄ´´ÒâÓëÓéÀÖÁªÃË£¨ACE£©½üÆÚÔÚÓ¡¶ÈÌáÒé´ó¹æÄ£·´µÁ°æÐж¯£¬£¬£¬£¬£¬³É¹¦µ·»Ù±¾µØ×îÊÜ»¶ÓµÄÁ÷ýÌåµÁ°æ·þÎñÖ®Ò»MKVCinemas¼°Æä25¸öÓйØÓòÃû¡£¡£¡£¡£¡£¸Ãƽ̨ÔÚ2024-2025Äê¼äÎüÒý³¬1.424Òڷÿͣ¬£¬£¬£¬£¬ÎªÊý°ÙÍòÓû§ÌṩÃâ·ÑµçÓ°µçÊÓ×ÊÔ´¡£¡£¡£¡£¡£ACEͨ¹ýÐÌÊÂÒÆËÍ¡¢ÃñÊÂËßËϼ°ÖÕ³¡ÁîÐж¯£¬£¬£¬£¬£¬ÆÈʹλÓÚÓ¡¶È±È¹þ¶û¹úµÄÔËÓªÉÌÖÕ³¡ÔËÓª²¢Òƽ»ÓòÃû½ÚÔìȨ£¬£¬£¬£¬£¬ËùÓÐMKVCinemasÍøÕ¾ÏÖÒѳÁ¶¨ÏòÖÁACEµÄ¡°ºÏ·¨ÅÔ¹Û¡±ÃÅ»§£¬£¬£¬£¬£¬¶Â½ØµÁ°æÄÚÈÝ´«²¼õè¾¶¡£¡£¡£¡£¡£Õâ´ÎÐж¯»¹¹Ø¹ØÁËÒ»¿î¿í·ºÊ¹ÓõÄÎļþ¿Ë¡¹¤¾ß£¬£¬£¬£¬£¬¸Ã¹¤¾ßͨ¹ý°µ²ØÔƴ洢ýÌåÎļþÆðÔ´£¬£¬£¬£¬£¬Ô®ÊÖÓ¡¶È¼°Ó¡ÄáÓû§ÈƹýϼܴëÊ©£¬£¬£¬£¬£¬Á½ÄêÄÚ»ñ2.314ÒڴνӼû£¬£¬£¬£¬£¬³ÉΪµÁ°æÄÚÈÝ·Ö·¢µÄ¹Ø¼ü¼¼ÊõÖ§³Ö¡£¡£¡£¡£¡£ÃÀ¹úµçӰлáÖ´Ðи±×ܲÃÀÀïÈø¡¤¿ËÄÉÆÕÇ¿µ÷£¬£¬£¬£¬£¬ACE½«³ÖÐø²é¾¿·¸·¨ÔËÓª£¬£¬£¬£¬£¬ÊØ»¤°²È«¿É³ÖÐøµÄÊг¡»·¾³¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/mkvcinemas-streaming-piracy-service-with-142m-visits-shuts-down/


¾©¹«Íø°²±¸11010802024551ºÅ