΢Èí365ÕË»§ÔâOAuthÉ豸´úÂë´¹µö¹¥»÷¼¤Ôö

°ä²¼¹¦·ò 2025-12-23

1. ΢Èí365ÕË»§ÔâOAuthÉ豸´úÂë´¹µö¹¥»÷¼¤Ôö


12ÔÂ19ÈÕ£¬ £¬£¬ £¬£¬ £¬£¬×Ô9ÔÂÆð£¬ £¬£¬ £¬£¬ £¬£¬µç×ÓÓʼþ°²È«¹«Ë¾Proofpoint¼à²âµ½ÀûÓÃOAuthÉ豸´úÂëÊÚȨ»úÔìµÄÍøÂç´¹µö¹¥»÷ÏÔÖøÔö³¤£¬ £¬£¬ £¬£¬ £¬£¬¹¥»÷Õßͨ¹ýÓÕÆ­Êܺ¦ÕßÔÚ΢ÈíºÏ·¨É豸µÇÂ¼Ò³ÃæÊäÈëÉ豸´úÂ룬 £¬£¬ £¬£¬ £¬£¬ÎÞÐèÇÔȡʹ´¦»òÈÆ¹ý¶à³ÁÉí·ÝÑéÖ¤£¨MFA£©¼´¿É»ñÈ¡Microsoft 365ÕË»§½ÚÔìȨ¡£¡£¡£¡£¡£¡£´ËÀ๥»÷²»½öÉæ¼°¾­¼ÃÀûÒæÇý¶¯µÄÍøÂç·¸×ï·Ö×ÓÈçTA2723£¬ £¬£¬ £¬£¬ £¬£¬»¹Ô̺¬¹ú¶È½áÃ˵ÄÍþвÐÐΪÕßÈçÒÉËÆ¶íÂÞ˹¹ØÁªµÄUNK_AcademicFlare¡£¡£¡£¡£¡£¡£¹¥»÷Á´Í¨³£Í¨¹ý´¹µöÓʼþÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó½Ó¼û¹¥»÷Õß½ÚÔìµÄÍøÕ¾£¬ £¬£¬ £¬£¬ £¬£¬ËæºóÒªÇóÊäÈë¡°É豸´úÂ롱ʵÏÖ¡°°²È«ÑéÖ¤¡±£¬ £¬£¬ £¬£¬ £¬£¬ÊµÔòÊÚȨ¶ñÒâÀûÓ÷¨Ê½½Ó¼ûÕË»§¡£¡£¡£¡£¡£¡£Proofpoint¹Û²ìµ½¹¥»÷ÕßʹÓÃSquarePhish v1/v2ºÍGraphishµÈ¹¤¾ß¼ò»¯´¹µöÁ÷³Ì¡£¡£¡£¡£¡£¡£ÀýÈ磬 £¬£¬ £¬£¬ £¬£¬Ð½×ʼν±¹¥»÷ÀûÓÃÎĵµ¹²Ïíµö¶üºÍ±¾µØ»¯Æ·ÅƱêʶÒýÓÕµã»÷£» £» £»£»£»£»TA2723×Ô10ÔÂÆðתÏò´ËÀ๥»÷£¬ £¬£¬ £¬£¬ £¬£¬ÔçÆÚʹÓÃSquarePhish2£¬ £¬£¬ £¬£¬ £¬£¬ºóÆÚ¿ÉÄÜÇл»ÖÁGraphish£» £» £»£»£»£»UNK_AcademicFlareÔòÀûÓñ»ÈëÇÖÈ·µ±¾Ö/¾ü·½ÓÊÏä³ÉÁ¢ÐÅÀµ£¬ £¬£¬ £¬£¬ £¬£¬Í¨¹ýαÔìOneDriveÁ´½ÓÓÕµ¼É豸´úÂëÊäÈ룬 £¬£¬ £¬£¬ £¬£¬ÖØÒªÕë¶ÔÃÀÅ·µ±¾Ö¡¢Ñ§Êõ¡¢Öǿ⼰½»Í¨²¿ÃÅ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-365-accounts-targeted-in-wave-of-oauth-phishing-attacks/


2. ºÓ´²¾º¼¼¾ãÀÖ²¿Ôâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷


12ÔÂ21ÈÕ£¬ £¬£¬ £¬£¬ £¬£¬°¢¸ùÍ¢ºÓ´²¾º¼¼¾ãÀÖ²¿£¨CARP£©ÓÚÖÜÎåÔâ·ê÷è÷ëÀÕË÷Èí¼þ×éÖ¯¹¥»÷£¬ £¬£¬ £¬£¬ £¬£¬¸Ã×éÖ¯½«ÆäÁÐΪ¡°¹ÜÕÊ·þÎñ¡±Êܺ¦Õß²¢°ä²¼Ô̺¬Êýǧ·ÝÎļþµÄÑó´ÐÁ´½Ó¡£¡£¡£¡£¡£¡£ÎļþÀàÐͺ­¸ÇPDF¡¢Excel¡¢Word¡¢Í¼Ïñ¡¢µç×ÓÓʼþ¼°Ñ¹Ëõ´æµµ£¬ £¬£¬ £¬£¬ £¬£¬µ¥Îļþ´óÓ×´Ó1KBÖÁ22MB²»µÈ£¬ £¬£¬ £¬£¬ £¬£¬¹¦·ò¿ç¶ÈΪ2021ÖÁ2025Ä꣬ £¬£¬ £¬£¬ £¬£¬Éæ¼°·¢Æ±¡¢ºÏͬ¡¢¼¼Êõ¹æ·¶¡¢¹¹ÖþÆ½ÃæÍ¼µÈÃô¸ÐÄÚÈÝ£¬ £¬£¬ £¬£¬ £¬£¬ÉõÖÁÔ̺¬ÐÅÓþ¿¨Õ˵¥ºÍ²É¹º¶©µ¥Ñù±¾¡£¡£¡£¡£¡£¡£ºÓ´²×÷Ϊ°¢¸ùÍ¢×î³É¹¦×ãÇò¶Ó£¨72¹Ú£©£¬ £¬£¬ £¬£¬ £¬£¬Õ¼ÓÐ35Íò»áÔ±¼°ÄÏÃÀÖÞ×î´óÇò³¡£¬ £¬£¬ £¬£¬ £¬£¬ÆäÇàÉÙÄ겿ÃÅ×îÓ×¶ÓÔ±½ö7Ë꣬ £¬£¬ £¬£¬ £¬£¬Õâ´Î¹¥»÷¶³ö³öÌåÓý»ú¹¹ÍøÂ簲ȫ·ì϶¡£¡£¡£¡£¡£¡£÷è÷ëÀÕË÷Èí¼þ×Ô2021Äê»îÔ¾£¬ £¬£¬ £¬£¬ £¬£¬2022Äê³õ´Î¼Í¼¹¥»÷£¬ £¬£¬ £¬£¬ £¬£¬2025Äê³ÉΪ×î»îÔ¾ÍŻ £¬£¬ £¬£¬ £¬£¬´Óǰ°ëÄê·¢Æð³¬600Æð¹¥»÷¡£¡£¡£¡£¡£¡£¸Ã×é֯ѡȡ¡°ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©¡±Ä£Ê½£¬ £¬£¬ £¬£¬ £¬£¬³¢ÊÔË«³ÁÀÕË÷¡£¡£¡£¡£¡£¡£Æä¹¥»÷Ö¸±êº­¸ÇÔì×÷ÉÌ¡¢½ðÈÚ»ú¹¹¡¢Ò½ÁƱ£½¡¼°µ±¾Ö»ú¹¹£¬ £¬£¬ £¬£¬ £¬£¬ÒòÕâЩÐÐÒµ´æ´¢Ãô¸ÐÐÅÏ¢Ò×ÊÜÊý¾Ýй¶ӰÏì¡£¡£¡£¡£¡£¡£


https://cybernews.com/news/club-atletico-river-plate-football-club-qilin-ransomware/


3. ·¨¹úÓÊÕþ¾ÖÊ¥µ®Ç°Ï¦ÔâDDoS¹¥»÷Ö¶àÒµÎṉ̃»¾


12ÔÂ23ÈÕ£¬ £¬£¬ £¬£¬ £¬£¬Ê¥µ®Ç°Ï¦£¬ £¬£¬ £¬£¬ £¬£¬·¨¹ú¹ú¶ÈÓÊÕþ¾Ö£¨La Poste£©Ôâ·ê´ó¹æÄ£DDoS¹¥»÷£¬ £¬£¬ £¬£¬ £¬£¬µ¼ÖÂÆäÍøÕ¾¡¢Òƶ¯ÀûÓü°Ö÷ÌâÊý×Öϵͳ̱»¾£¬ £¬£¬ £¬£¬ £¬£¬°ü¹üÅäËÍ·þÎñÏÔÖø·Å»º£¬ £¬£¬ £¬£¬ £¬£¬²¿ÃÅÔÚÏßÒµÎñÖжÏ¡£¡£¡£¡£¡£¡£¸Ã¾ÖÔÚÖÜÒ»ÉêÃ÷ÖÐÈ·ÈÏ£¬ £¬£¬ £¬£¬ £¬£¬Õâ´ÎÍøÂç¹¥»÷Ôì³ÉϵͳÐÔ¹ÊÕÏ£¬ £¬£¬ £¬£¬ £¬£¬µ«Ç¿µ÷ĿǰÎÞÖ¤¾ÝÏÔʾÓû§Êý¾Ýй¶£¬ £¬£¬ £¬£¬ £¬£¬½öÈÏ¿ÉÓÊÕþ¼°ÒøÐÐÒµÎñ£¨Èç°ü¹üÅäËÍ¡¢ÒøÐÐתÕË£©Êܲ¨¼°¡£¡£¡£¡£¡£¡£ÆìÏ·¨¹úÓÊÕþÒøÐУ¨La Banque Postale£©Í¬²½ÊÜÓ°Ï죬 £¬£¬ £¬£¬ £¬£¬Óû§·´Ó³ÍøÉÏÒøÐм°Òƶ¯ÀûÓýӼûÄÑÌ⣬ £¬£¬ £¬£¬ £¬£¬²»ÍâÒøÐз½Ãæ³ÎÇ壬 £¬£¬ £¬£¬ £¬£¬ÊµÌåÍøµãPOS»úË¢¿¨¡¢ATMÈ¡¿î¼°¶ÌÐÅÑéÖ¤µÄÔÚÏßÖ§¸¶Ö°ÄÜÈÔÕý³£ÔË×÷£¬ £¬£¬ £¬£¬ £¬£¬¹ñ̨ҵÎñÒà³ÖÐøÊ¢¿ª¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ç¡·êÓÊÕþÒµÎñ¶¥·åÆÚ£¬ £¬£¬ £¬£¬ £¬£¬Òý·¢Óû§Ç¿ÁÒ²»Âú¡£¡£¡£¡£¡£¡£É罻ýÌåÉÏ£¬ £¬£¬ £¬£¬ £¬£¬´óÁ¿Ãñ¶à±§Ô¹ÅäËÍÑÓ³¤¿ÉÄܵ¼ÖÂÊ¥µ®°ü¹üÎÞ·¨ÊµÊ±Í¶µÝ£¬ £¬£¬ £¬£¬ £¬£¬·¨¹úýÌåÒ౨·²¿ÃÅÓʾÖÒòϵͳ¹ÊÕϻؾøÓû§¼Ä¼þ»òÈ¡¼þÒªÇ󡣡£¡£¡£¡£¡£Ö»¹Ü²¿ÃÅÓʾÖÒÑËõ¼õÔËÓª¹æÄ££¬ £¬£¬ £¬£¬ £¬£¬µ«ÓÊÕþ¾ÖÇ¿µ÷¡°ÍŶÓȫԱ´øÍ·¼Ó¿ì·þÎñ¸´Ô­¡±£¬ £¬£¬ £¬£¬ £¬£¬Óû§ÈÔ¿Éͨ¹ý¹ñ̨°ìÀíÓÊÕþ¼°ÒøÐÐÒµÎñ¡£¡£¡£¡£¡£¡£


https://therecord.media/la-poste-france-ddos-disruption-days-before-christmas


4. ÂÞÂíÄáÑǹú¶ÈË®Îñ»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷


12ÔÂ22ÈÕ£¬ £¬£¬ £¬£¬ £¬£¬ÂÞÂíÄáÑǹú¶ÈË®ÎñÖÎÀí»ú¹¹ÓÚ½üÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬ £¬£¬ £¬£¬µ¼ÖÂÔ¼1000Ì¨ÍÆËã»úϵͳ̱»¾£¬ £¬£¬ £¬£¬ £¬£¬¹¤×÷Õ¾Óë·þÎñÆ÷ÎÞ·¨Ê¹Ó㬠£¬£¬ £¬£¬ £¬£¬µ«Ö÷ÌâË®Àû¼¼Êõ»ù´¡ÉèÊ©Èç´ó°Ó¡¢·ÀºéÉèʩδÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÆÈʹԱ¹¤ÉÕ»Ùµç×ÓÓʼþͨѶ£¬ £¬£¬ £¬£¬ £¬£¬×ª¶øÊ¹Óõ绰ºÍÎÞÏßµç½øÐÐÄÚ²¿Ð­µ÷£¬ £¬£¬ £¬£¬ £¬£¬Í¹ÏÔÁËÍøÂç¹¥»÷¶ÔÈÕ³£ÔËÓªµÄ×ÌÈÅ¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ £¬£¬ £¬£¬ £¬£¬¹¥»÷ÕßѡȡÁËÓ봫ͳÀÕË÷Èí¼þ·ÖÆçµÄ¼¼Êõ¼¿Á©£¬ £¬£¬ £¬£¬ £¬£¬ÀûÓúϷ¨Windows¹¤¾ßBitLockerÖ´ÐмÓÃÜÀÕË÷¡£¡£¡£¡£¡£¡£ÕâÖÖ±»³ÆÎª¡°LOLBins¡±£¨Living-off-the-Land Binaries£©µÄÕ½Êõ£¬ £¬£¬ £¬£¬ £¬£¬Í¨¹ýŲÓÃϵͳ×Ô´ø¹¤¾ß£¨ÈçBitLocker£©ÔÚÊܺ¦ÕßÍøÂçÖкáÏòÒÆ¶¯²¢¶ã±Ü°²È«¼ì²â£¬ £¬£¬ £¬£¬ £¬£¬Ôö³¤ÁË·ÀÓùÄѶÈ¡£¡£¡£¡£¡£¡ £¿£¿ £¿£¿ £¿¨°Í˹»ù³¢ÊÔÊÒ2024Äê×êÑÐÏÔʾ£¬ £¬£¬ £¬£¬ £¬£¬Ä«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô¼µ©µÄ¸ÖÌúÆóÒµ¡¢ÒßÃçÔì×÷É̼°µ±¾Ö»ú¹¹ÔøÔâ·êÀàËÆ¹¥»÷£» £» £»£»£»£»ÍøÂ簲ȫ¹«Ë¾BitdefenderÒ²Ö¸³ö£¬ £¬£¬ £¬£¬ £¬£¬¡°ShrinkLocker¡±¶ñÒâÈí¼þÕý±»¶à¸öÍþв×éÖ¯ÓÃÓÚÕë¶ÔÀϾÉWindowsϵͳµÄµ¥Ò»¹¥»÷£¬ £¬£¬ £¬£¬ £¬£¬Í¨¹ý¾ç±¾»¯²Ù×÷ºÏ·¨¹¤¾ßʵÏÖÀÕË÷Ö÷ÕÅ¡£¡£¡£¡£¡£¡£


https://therecord.media/romania-national-water-agency-ransomware-attack


5. ÈÕ²úÆû³µÏݺìñÊý¾Ýй¶·çÀË£¬ £¬£¬ £¬£¬ £¬£¬2.1Íò¿Í»§ÐÅÏ¢ÔâÇÔ


12ÔÂ22ÈÕ£¬ £¬£¬ £¬£¬ £¬£¬ÈÕ²úÆû³µÓÐÏÞ¹«Ë¾½üÈÕ֤ʵ£¬ £¬£¬ £¬£¬ £¬£¬ÒòÃÀ¹úÆóÒµÈí¼þ¹«Ë¾ºìñ£¨Red Hat£©9Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬ £¬£¬ £¬£¬ÆäÔ¼21,000ÃûÈÕ±¾¸£¸ÔµØÓò¿Í»§ÐÅÏ¢±»ÇÔÈ¡£¬ £¬£¬ £¬£¬ £¬£¬Éæ¼°È«Ãû¡¢ÎïÀíµØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¼°ÏúÊÛÔËÓªÊý¾Ý£¬ £¬£¬ £¬£¬ £¬£¬µ«ÐÅÓþ¿¨µÈ²ÆÕþÐÅϢδÊܲ¨¼°¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÔ´ÓÚºìñ¹«Ë¾Êý¾Ý·þÎñÆ÷Ôâδ¾­ÊÚȨ½Ó¼û£¬ £¬£¬ £¬£¬ £¬£¬µ¼ÖÂÈÕ²úίÍÐÆä¿ª·¢µÄ¿Í»§ÖÎÀíϵͳÊý¾Ýй¶£¬ £¬£¬ £¬£¬ £¬£¬³ÉΪÈÕ²ú½ñÄêµÚ¶þÆðÍøÂ簲ȫÊÂÎñ£¬ £¬£¬ £¬£¬ £¬£¬´Ëǰ8Ô£¬ £¬£¬ £¬£¬ £¬£¬ÆäÉè¼Æ×Ó¹«Ë¾Creative Box Inc.ÔøÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£ºìñÊý¾Ýй¶ÊÂÎñÓ°ÏìÉîÔ¶£¬ £¬£¬ £¬£¬ £¬£¬Éæ¼°28,000¸ö˽ÓÐGitLab´æ´¢¿â£¬ £¬£¬ £¬£¬ £¬£¬Ãô¸ÐÊý¾Ý´ïÊý°ÙGB¡£¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯Crimson Collective×î³õÐû³Æ¶Ô´ËÕÆ¹Ü£¬ £¬£¬ £¬£¬ £¬£¬ËæºóShinyHuntersҲȾָÆäÖУ¬ £¬£¬ £¬£¬ £¬£¬ÔÚÀÕË÷ƽ̨Íйܱ»µÁÊý¾ÝÑù±¾ÒÔʩѹÊܺ¦¹«Ë¾¡£¡£¡£¡£¡£¡£ÈÕ²úÇ¿µ÷£¬ £¬£¬ £¬£¬ £¬£¬±»ÈëÇֵĺìñ»·¾³Î´´æ´¢ÆäËûÊý¾Ý£¬ £¬£¬ £¬£¬ £¬£¬ÇÒÎÞÖ¤¾ÝÅúעй¶ÐÅÏ¢Òѱ»ÀÄÓ㬠£¬£¬ £¬£¬ £¬£¬µ«ÒÑÒý·¢¿Í»§¶ÔÒþÖÔ°²È«µÄÓÇÓô¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/nissan-says-thousands-of-customers-exposed-in-red-hat-breach/


6. ÒÁÀÊAPT×éÖ¯InfyЯеĶñÒâÈí¼þ»î¶¯³ÁÏÖ


12ÔÂ21ÈÕ£¬ £¬£¬ £¬£¬ £¬£¬Íþвµý±¨»ú¹¹SafeBreachÅû¶£¬ £¬£¬ £¬£¬ £¬£¬ÒÁÀÊInfy£¨ÓÖ³ÆPrince of Persia£©APT×éÖ¯½üÆÚ³ÁÆô»îÔ¾£¬ £¬£¬ £¬£¬ £¬£¬ÕâÊǸÃ×éÖ¯×Ô2020ÄêÕë¶ÔÈðµä¡¢ºÉÀ¼¡¢ÍÁ¶úÆäÖ¸±êºó³õ´Î´ó¹æÄ£ÏÖÉí¡£¡£¡£¡£¡£¡£×÷ΪÏÖ´æ×î¹ÅÀϵÄAPTÖ®Ò»£¬ £¬£¬ £¬£¬ £¬£¬Infy»î¶¯¿É×·ÒäÖÁ2004Äê12Ô£¬ £¬£¬ £¬£¬ £¬£¬ÆäÒñ±ÎÐԳ־øßÓÚCharming KittenµÈ³ÛÃûÒÁÀÊ×éÖ¯£¬ £¬£¬ £¬£¬ £¬£¬µ«Õâ´ÎÐж¯Õ¹Ê¾¸ü¸´ÔӵĹ¥»÷Á´Éý¼¶¡£¡£¡£¡£¡£¡£×îй¥»÷ÖУ¬ £¬£¬ £¬£¬ £¬£¬InfyʹÓÃÉý¼¶°æFoudreÏÂÔØÆ÷ÓëTonnerreÖ²È뷨ʽ£¬ £¬£¬ £¬£¬ £¬£¬Í¨¹ý´¹µöÓʼþ´«²¼¡£¡£¡£¡£¡£¡£¹¥»÷Á´´Ó´«Í³ExcelºêתÏòÎĵµÄÚǶ¿ÉÖ´ÐÐÎļþ£¬ £¬£¬ £¬£¬ £¬£¬½áºÏÓòÃûÌìÉúËã·¨£¨DGA£©Ç¿»¯C2·þÎñÆ÷ÈÍÐÔ¡£¡£¡£¡£¡£¡£ÓÈΪֵÍ×ÌùÐĵÄÊÇ£¬ £¬£¬ £¬£¬ £¬£¬¶ñÒâÈí¼þͨ¹ýRSAÊðÃûÑéÖ¤C2ÓòÃûÕæÊµÐÔ¡£¡£¡£¡£¡£¡£2025Äê9Ô¼ì²âTonnerre×îа汾ÐÂÔöTelegramȺ×éͨѶ»úÔ죬 £¬£¬ £¬£¬ £¬£¬ÓйØÅäÖô洢ÔÚC2·þÎñÆ÷¡°t¡±Ä¿Â¼µÄtga.adrÎļþÖУ¬ £¬£¬ £¬£¬ £¬£¬½ö¶ÔÌØ¶¨Êܺ¦ÕßGUID´¥·¢ÏÂÔØ¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬ £¬£¬ £¬£¬C2·þÎñÆ÷´æÔÚδ֪Óô¦µÄ¡°download¡±Ä¿Â¼£¬ £¬£¬ £¬£¬ £¬£¬´§Ä¦ÓÃÓÚ¶ñÒâÈí¼þÉý¼¶¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2025/12/iranian-infy-apt-resurfaces-with-new.html