ºÉÀ¼ÁÙ´²Õï¶ÏÖÐÐÄÔâ¹¥»÷ÖÂ85ÍòÈËÊý¾Ýй¶

°ä²¼¹¦·ò 2026-05-18

1.ºÉÀ¼ÁÙ´²Õï¶ÏÖÐÐÄÔâ¹¥»÷ÖÂ85ÍòÈËÊý¾Ýй¶


5ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬ºÉÀ¼ÎÀÉúºÍÇàÄ껤Àí¶½²ì¾Ö£¨IGJ£©½üÈÕ°ä²¼µÄÒ»Ïîµ÷²é½áÂÛÏÔʾ£¬£¬£¬£¬£¬£¬ÔÚ2025Äê7Ô²úÉúµÄ´ó¹æÄ£ÍøÂç¹¥»÷֮ǰ£¬£¬£¬£¬£¬£¬ÁÙ´²Õï¶ÏÖÐÐij־ÃδÇкÏÒ½ÁƱ£½¡ÐÐҵ˾ÂÉÀý¶¨µÄÐÅÏ¢°²È«³ß¶È¡£¡£¡£ ¡£¡£¡£¡£¡£¸ÃÖÐÐÄÒò²Î¼Ó¹¬¾±°©É¸²éÏîÄ¿£¬£¬£¬£¬£¬£¬³ÖÓдóÁ¿Ãô¸ÐÓ×ÎÒ½¡È«ÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÊÂÎñ²úÉúºó£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïNovaÈëÇÔìäITϵͳ£¬£¬£¬£¬£¬£¬×î³õ»ã±¨ÇÔÈ¡ÁË48.5ÍòÃû²Î¼ÓÕßµÄÊý¾Ý£¬£¬£¬£¬£¬£¬ºó¾­³¢ÊÔÊÒ½¨¸Ä£¬£¬£¬£¬£¬£¬ÏÖʵÊÜÓ°ÏìÈËÊý¸ß´ï85ÍòÈË¡£¡£¡£ ¡£¡£¡£¡£¡£Îª½â¾öÎÊÌ⣬£¬£¬£¬£¬£¬¸ÃÖÐÐÄÏòºÚ¿ÍÖ§¸¶ÁËÊý¶î²»ÏêµÄÊê½ð¡£¡£¡£ ¡£¡£¡£¡£¡£IGJÔÚ³¹µ×µ÷²éºó·¢ÏÖ£¬£¬£¬£¬£¬£¬¸Ã³¢ÊÔÊÒ´æÔÚ¶àÏî³Á´óȱµã¡£¡£¡£ ¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÒ»¸ö±»µÁÓõÄÓû§ÕË»§£¬£¬£¬£¬£¬£¬Í¨¹ýÔ¶³Ì×ÀÃæÏνӳɹ¦½Ó¼ûÁ˾ɰæ²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬µ«¸ÃÕË»§ÈôºÎ±»µÁÓÃÖÁ½ñÈÔÊÇδ½âÖ®ÃÕ¡£¡£¡£ ¡£¡£¡£¡£¡£Æä´Î£¬£¬£¬£¬£¬£¬ÓÉÓÚ±¨´ðÃýÎ󣬣¬£¬£¬£¬£¬ÒÅÁô»·¾³ÆëȫδÊÜ¼à¿Ø£¬£¬£¬£¬£¬£¬°²È«ÔËÓªÖÐÐÄ£¨SOC£©ÒòÐÅÏ¢ÃýÎóÎóÒÔΪÓйؾɻ·¾³ÒѲ»ÔÙÔËÐУ¬£¬£¬£¬£¬£¬Òò¶ø½ûÓÃÁË¶ÔÆäµÄ¼à¿Ø£¬£¬£¬£¬£¬£¬µ¼ÖÂÈÕÖ¾ÖеÄÒì³£ÐÐΪδÄܱ»ÊµÊ±·¢ÏÖ¡£¡£¡£ ¡£¡£¡£¡£¡£µÚÈý£¬£¬£¬£¬£¬£¬Ö»¹Ü±»µÁÓõÄÕË»§Ê¹ÓÃÁË16¸ö×Ö·ûµÄÃÜÂ룬£¬£¬£¬£¬£¬µ«¶à³É·ÖÉí·ÝÑéÖ¤Ö°ÄÜÔÚ¹¥»÷²úÉúʱÒѱ»½ûÓ㬣¬£¬£¬£¬£¬¼«´ó½µµÍÁ˹¥»÷Ãż÷¡£¡£¡£ ¡£¡£¡£¡£¡£×îΪÑϳÁµÄÊÇ£¬£¬£¬£¬£¬£¬ÔÚÊÂÎñ²úÉúǰµÄÕûÕûÈýÄêÀ£¬£¬£¬£¬£¬¸Ã³¢ÊÔÊÒ´Óδ½øÐйýÈκÎÉó¼ÆÀ´Éó²éÆäÍøÂ簲ȫºÍÊý¾Ý± £» £»£»£»£»£»£»£»¤Çé¿ö¡£¡£¡£ ¡£¡£¡£¡£¡£


https://cybernews.com/security/dutch-lab-security-standards-hackers-cancer-patients-data/


2. ºÚ¿Í×éÖ¯Ðû³ÆÈëÇÖÓ¢¹úº½¿Õ£¬£¬£¬£¬£¬£¬Ð¹Â¶»ú×é¼°Ò½ÁÆÊý¾Ý


5ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪ¡°»ù´¡ÉèÊ©·ÛËéÓ××顱µÄºÚ¿Í×éÖ¯½üÈÕÐû³Æ³É¹¦ÈëÇÖÁËÓ¢¹úº½¿Õ¹«Ë¾µÄÄÚ²¿ÏµÍ³£¬£¬£¬£¬£¬£¬²¢Ð¹Â¶ÁËÃô¸ÐµÄ»ú×éÈËÔ±ÐÅÏ¢¼°Ò½ÁÆÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚÆäTelegramƵ·Éϰ䲼ÐÂÎųƣ¬£¬£¬£¬£¬£¬ÒÑ»ñµÃÓ¢º½·þÎñÆ÷¡¢ÄÚ²¿ÏµÍ³¼°Ò½ÁÆ·þÎñÆ÷µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÔ̺¬¸ß¶ÈÃô¸ÐµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¡£¾Ý¹¥»÷ÕßÃèÊö£¬£¬£¬£¬£¬£¬ËûÃÇÇÖÈëÁËÔ±¹¤ÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬£¬»ú×éÈËÔ±ºÍ·ÉÐÐÔ±Ôڴ˼ͼÈÕ³ÌÆÌÅÅ¡¢²¡¼ÙÉêÇë¼°Ìá½»ÆäËûÓ빤×÷ÓйصÄÓ×ÎÒÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¡£ÎªÁË×ôÖ¤Æä˵·¨£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï°ä²¼ÁËÊý¾ÝÑù±¾£¬£¬£¬£¬£¬£¬Ô̺¬ÒÉËÆÓ¢º½ÄÚ²¿ÏµÍ³ÒDZíÅ̵ĽØÍ¼£¬£¬£¬£¬£¬£¬Èç»ú×éÈËÔ±ÃÅ»§ÍøÕ¾ºÍCognito AIÊý¾Ý·ÖÎöƽ̨µÄ½çÃæ¡£¡£¡£ ¡£¡£¡£¡£¡£Ñù±¾ÖÐÔ̺¬Ô±¹¤Ó×ÎÒÐÅÏ¢¼°²¡¼ÙÉêÇë¼Í¼£¬£¬£¬£¬£¬£¬¶øÆëÈ«Êý¾Ý¼¯¿ÉÄܽøÒ»²½º­¸Ç»ú×éÈËÔ±Ïò¹ÍÖ÷ÌṩµÄÒ½ÁÆÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßÐû³Æ£¬£¬£¬£¬£¬£¬ËûÃÇÊÇͨ¹ýÒ»¸ö±»µÁÓõÄÔ±¹¤ÕË»§ÊµÏÖÈëÇֵ쬣¬£¬£¬£¬£¬¸ÃÕË»§Õ¼ÓжÔÕû¸öÖÎÀíÔ±½ÚÔìÃæ°åµÄ½Ó¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸ÃÍŻﻹÐû³ÆÒѹ¥ÆÆÓ¢º½µÄÊý¾ÝÖÐÐÄ£¬£¬£¬£¬£¬£¬²¢ÌṩÁËײ¿â¹¥»÷µÄ½ØÍ¼×÷Ϊ֤¾Ý£¬£¬£¬£¬£¬£¬Ðû³ÆÊý¾ÝÖÐÐÄй¶ÁËÔ±¹¤²¡¼ÙÉêÇë¼°»ú×éÈËÔ±ÓëÖÎÀí²ãÖ®¼äµÄͨѶ¼Í¼¡£¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÍŶÓÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬´ËÀàÊý¾Ý¿ÉÓÃÓÚÍøÂçÓ¢¹úº½¿Õ¹«Ë¾µÄͨѶģʽ¼°º½°àÔËÓª·½Ê½£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¸ü¶àÔËÓªÖжϡ£¡£¡£ ¡£¡£¡£¡£¡£


https://cybernews.com/security/british-airways-crew-data-breach/


3. ÃÀ¹ú´û¿îÖÐÐÄÊý¾Ýй¶£¬£¬£¬£¬£¬£¬12.3ÍòÈËÐÅÏ¢ÔâÇÔ


5ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹ú´û¿îÖÐÐÄ£¨American Lending Center£©ÊÇÒ»¼ÒλÓÚ¼ÓÀû¸£ÄáÑÇÖݵķÇÒøÐдû¿î»ú¹¹£¬£¬£¬£¬£¬£¬ÖÎÀí×Å30ÒÚÃÀԪȷµ±¾Öµ£±£ÓׯóÒµ´û¿î×éºÏ¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã»ú¹¹ÓÚ2025Äê7Ô·¢ÏÖÁËһ·ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ«È¡Ö¤µ÷²éÖ±ÖÁ2026Äê4ÔÂ8ÈÕ²ÅʵÏÖ£¬£¬£¬£¬£¬£¬ºÄʱ½ü¾Å¸öÔ¡£¡£¡£ ¡£¡£¡£¡£¡£µ÷²éÈ·ÈÏ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÈëÇÖÁËALCÄÚ²¿ÍøÂ磬£¬£¬£¬£¬£¬½Ó¼ûÁËÔ̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚºÍÉç»á°²È«ºÅÂëµÈÓ×ÎÒÉí·ÝÐÅÏ¢µÄÎļþ¡£¡£¡£ ¡£¡£¡£¡£¡£Ö»¹ÜĿǰÎÞÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»ÀÄÓ㬣¬£¬£¬£¬£¬Ò²ÎÞÀÕË÷×éÖ¯¹«¿ªÐû³ÆÕƹܣ¬£¬£¬£¬£¬£¬¿ÉÄÜÒòÒÑÖ§¸¶Êê½ð»ò¸Ã×éÖ¯ÎÞ¹«¿ªÐ¹ÃÜÍøÕ¾£¬£¬£¬£¬£¬£¬µ«Õâ´ÎÊÂÎñÒѵ¼Ö³¬¹ý12.3ÍòÃûÓ×ÎÒÃæ¶ÔÐÅϢй¶·çÏÕ£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÕßÖØÒªÔ̺¬ÉêÇë»ò»ñÇе±¾Öµ£±£´û¿îµÄÓׯóÒµÖ÷¼°ÓйØÈËÊ¿¡£¡£¡£ ¡£¡£¡£¡£¡£´ÓÊ×ϯÐÅÏ¢°²È«¹ÙÊӽǿ´£¬£¬£¬£¬£¬£¬Õâ´ÎÅû¶ÖÐ×î¹Ø¼üµÄ²Ù×÷Òþ»¼ÔÚÓÚ¡°·¢ÏÖµ½µ÷²éʵÏÖ¡±µÄ¾Å¸öÔ¹¦·ò²î£ºÔÚ´ËÆÚ¼ä£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓ×ÎÒÎÞ·¨²ÉÈ¡Èκα £» £»£»£»£»£»£»£»¤´ëÊ©£¬£¬£¬£¬£¬£¬¶ø¼ÓÖݵȶàÖÝ˾·¨Ã÷È·»®¶¨Í¨ÖªÆÚÏÞÓ¦´Ó·¢ÏÖÖ®ÈÕÆðË㣬£¬£¬£¬£¬£¬¶ø·Çµ÷²éʵÏÖÖ®ÈÕ¡£¡£¡£ ¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬µ¢¸éµ÷²é²»½ö×é³É°²È«·çÏÕ£¬£¬£¬£¬£¬£¬¸ü´øÀ´¼à¹ÜÎ¥¹æ·çÏÕ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://securityboulevard.com/2026/05/american-lending-center-data-breach-affects-123000-individuals-after-nearly-year-long-investigation/


4. Tycoon2FAÐÂÔöÉ豸´úÂë´¹µö½Ù³Ö΢ÈíÕË»§


5ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬Ö»¹Ü¹ú¼Ê·¨Âɲ¿ÃÅÔÚ3Ô¶ÔTycoon2FAÍøÂç´¹µöƽ̨·¢Õ¹ÁËÇÖÈÅÐж¯£¬£¬£¬£¬£¬£¬¸Ã¶ñÒ⹤¾ß°üȴѸËÙÔÚлù´¡ÉèÊ©ÉÏʵÏÖ³Á½¨£¬£¬£¬£¬£¬£¬²¢¸´Ô­µ½Õý³ £» £»£»£»£»£»£»£»î¶¯Ë®Æ½¡£¡£¡£ ¡£¡£¡£¡£¡£±¾Ô³õ£¬£¬£¬£¬£¬£¬Abnormal Security֤ʵTycoon2FA²»½öÒѸ´Ô­ÔËÓª£¬£¬£¬£¬£¬£¬»¹Ôö³¤ÁËеĻìºÏ²ãÒÔ¼ÓÇ¿¿¹·ÛËéÄÜÁ¦¡£¡£¡£ ¡£¡£¡£¡£¡£4ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢Ïָù¤¾ß°üÆðÍ·ÀûÓÃOAuth 2.0É豸ÊÚȨÊÚÓèÁ÷³Ì£¬£¬£¬£¬£¬£¬·¢ÆðÉ豸´úÂë´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬ÒÔ½Ù³ÖMicrosoft 365ÕË»§¡£¡£¡£ ¡£¡£¡£¡£¡£Tycoon2FAµÄÉ豸´úÂë´¹µö¹¥»÷ʼÓÚÊܺ¦Õßµã»÷µö¶üÓʼþÖеÄTrustifiµã»÷¸ú×ÙURL£¬£¬£¬£¬£¬£¬ÓʼþÒÔ·¢Æ±ÎªÖ÷Ì⣬£¬£¬£¬£¬£¬Ô̺¬Trustifi¸ú×ÙÁ´½Ó£¬£¬£¬£¬£¬£¬¸ÃÁ´½Ó¾­¹ýTrustifi¡¢Cloudflare Workers¼°¶à²ã»ìºÏJavaScriptºó£¬£¬£¬£¬£¬£¬×îÖÕ½«Êܺ¦ÕßÊèµ¼ÖÁαÔìµÄMicrosoft CAPTCHAÒ³Ãæ¡£¡£¡£ ¡£¡£¡£¡£¡£¸ÃÒ³Ãæ´Ó¹¥»÷Õߺó¶Ë»ñÈ¡É豸´úÂ룬£¬£¬£¬£¬£¬ÅúʾÊܺ¦Õ߸´Ô첢ǰÍù΢ÈíºÏ·¨É豸µÇÂ¼Ò³ÃæÊµÏÖMFA£¬£¬£¬£¬£¬£¬Ëæºó΢ÈíÏò¹¥»÷Õß½ÚÔìµÄÉ豸Ðû¸æOAuth½Ó¼ûÁîÅÆºÍË¢ÐÂÁîÅÆ¡£¡£¡£ ¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬Tycoon2FAÄÚÖÃÁËÕë¶Ô×êÑÐÈËÔ±ºÍ×Ô¶¯»¯É¨ÃèµÄ¿í·º·À»¤»úÔ죺¿É¼ì²âSelenium¡¢PuppeteerµÈ¹¤¾ß£¬£¬£¬£¬£¬£¬×èÖ¹°²È«³§ÉÌ¡¢VPN¡¢É³Ïä¡¢AIÅÀ³æºÍÔÆÌṩÉÌ£¬£¬£¬£¬£¬£¬²¢²¿Êðµ÷ÊÔÆ÷¼ÆÊ±ÏÝÚ壬£¬£¬£¬£¬£¬À´×Ô·ÖÎö»·¾³µÄÒªÇó»á±»×Ô¶¯³Á¶¨ÏòÖÁºÏ·¨Î¢ÈíÒ³Ãæ¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/


5. WordPress Funnel Builder²å¼þÑϳÁ·ì϶Ôâ»ý¼«ÀûÓÃ


5ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬WordPressÉú̬ÖÐÒ»¿î×°ÖÃÁ¿³¬¹ý4ÍòµÄFunnel Builder²å¼þ£¨À´×ÔFunnelKit£©±»·¢ÏÖ´æÔÚÒ»¸öÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬ÇÒÕý±»¹¥»÷Õß»ý¼«ÀûÓᣡ£¡£ ¡£¡£¡£¡£¡£¾ÝSansec×êÑÐÈËÔ±»ã±¨£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÏòWooCommerce½áÕËÒ³Ãæ×¢Èë¶ñÒâJavaScript´úÂ룬£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡¹Ë¿ÍÔÚ¹ºÎï¹ý³ÌÖÐÊäÈëµÄÖ§¸¶ÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÁ˲å¼þÖÐÒ»¸ö²»×ãȨÏÞУÑéµÄ¶Ëµã£¬£¬£¬£¬£¬£¬Í¨¹ýÅú¸Ä²å¼þµÄÈ«¾ÖÉèÖÃÖеġ°±í²¿¾ç±¾¡±Ñ¡Ï£¬£¬£¬£¬£¬Ö±½ÓÖ²Èë¶ñÒâ<script>±êÇ©¡£¡£¡£ ¡£¡£¡£¡£¡£ÕâÒ»±êÇ©»áÔÚÿһ´Î½áÕËÂòÂôÖÐ×Ô¶¯ÔËÐУ¬£¬£¬£¬£¬£¬µ¼ÖÂËùÓÐͨ¹ý¸Ã²å¼þʵÏֵĸ¶¿î¶¼¿ÉÄܱ»Ð¹Â¶¡£¡£¡£ ¡£¡£¡£¡£¡£¾ßÌå¶øÑÔ£¬£¬£¬£¬£¬£¬¹¥»÷Õß×¢ÈëµÄÊÇαÔìµÄGoogle Tag Manager»òGoogle Analytics¾ç±¾£¬£¬£¬£¬£¬£¬Ê¹Æä¿´ÆðÀ´ÏñÊǺϷ¨µÄ·ÖÎö´úÂ룬£¬£¬£¬£¬£¬ÒÔÌÓ±ÜͨÀý¼ì²â¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã¼ÓÔØ·¨Ê½»á¾²Ä¬µØ´Ó¹¥»÷Õß½ÚÔìµÄÓòÏÂÔØµÚ¶þ½×¶Î¾ç±¾£¬£¬£¬£¬£¬£¬²¢Í¨¹ýWebSocketÏνÓÓëÔ¶³ÌC2·þÎñÆ÷³ÉÁ¢Í¨Ñ¶£¬£¬£¬£¬£¬£¬Ëæºó²¿ÊðÒ»¸ö¶¨Ô컯µÄÖ§¸¶ÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬£¬ÔÚ½áÕ˹ý³ÌÖÐÊµÊ±×¥ÊØÐÅÓþ¿¨ºÅ¡¢CVVÂë¡¢Õ˵¥µØÖ·¼°ÆäËû¿Í»§Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¡£FunnelKitÒÑÒâʶµ½¸Ã·ì϶µÄ´æÔÚ£¬£¬£¬£¬£¬£¬²¢¶½´ÙÓû§Á¢¼´½«Funnel Builder²å¼þ¸üÐÂÖÁ3.15.0.3°æ±¾¡£¡£¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.com/192260/cyber-crime/attackers-exploit-funnel-builder-bug-to-inject-e-skimmers-into-e-stores.html


6. Secret Blizzard½«KazuarºóÃÅÉý¼¶ÎªP2P½©Ê¬ÍøÂç


5ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿Í×éÖ¯Secret Blizzard½«ÆäÔËÐÐÒѾõÄKazuarºóÃÅ·¨Ê½¿ª·¢³ÉÁËÒ»¸öÄ£¿£¿£¿£¿£¿£¿£¿é»¯µÄµã¶Ôµã£¨P2P£©½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Ö¼ÔÚʵÏÖ³Ö¾ÃÓÆ¾ÃÐÔ¡¢¸ß¶ÈÒñ±ÎÐԺ͸ßЧÊý¾ÝÍøÂç¡£¡£¡£ ¡£¡£¡£¡£¡£Î¢Èí×êÑÐÈËÔ±×îзÖÎö·¢ÏÖ£¬£¬£¬£¬£¬£¬KazuarÏÖÓÉÈý¸öÖ÷ÌâÄ£¿£¿£¿£¿£¿£¿£¿é×é³É£ºÄÚºËÄ£¿£¿£¿£¿£¿£¿£¿é¡¢ÇŽÓÄ£¿£¿£¿£¿£¿£¿£¿éºÍ¹¤×÷Ä£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£ ¡£¡£¡£¡£¡£ÄÚºËÄ£¿£¿£¿£¿£¿£¿£¿éÊÇÖÐÑëЭµ÷Æ÷£¬£¬£¬£¬£¬£¬ÕƹÜÖÎÀí¹¤×÷¡¢½ÚÔìÆäËûÄ£¿£¿£¿£¿£¿£¿£¿é²¢Ð­µ÷Õû¸ö½©Ê¬ÍøÂçµÄͨѶÓëÊý¾ÝÁ÷¡£¡£¡£ ¡£¡£¡£¡£¡£ÇŽÓÄ£¿£¿£¿£¿£¿£¿£¿é³äÈÎ±í²¿Í¨Ñ¶´úÀí£¬£¬£¬£¬£¬£¬Ê¹ÓÃHTTP¡¢WebSockets»òExchange Web Services£¨EWS£©µÈºÍ̸ÔÚ¸¨µ¼ÕßÓëÔ¶³ÌC2Ö®¼äÖмÌÁ÷Á¿ £» £»£»£»£»£»£»£»ÄÚ²¿Í¨Ñ¶ÔòÒÀÀµ¹ý³Ì¼äͨѶ£¨IPC£©£¬£¬£¬£¬£¬£¬Ô̺¬WindowsÐÂÎÅ´«µÝ¡¢Óʼþ²ÛºÍ¶¨Ãû¹Ü·£¬£¬£¬£¬£¬£¬ÄÜÓÅÁ¼ÈÚÈëÕý³£ÏµÍ³ÔëÉù£¬£¬£¬£¬£¬£¬ÇÒËùÓÐÐÂΞù¾­AES¼ÓÃܲ¢Ê¹ÓÃGoogle Protocol Buffers£¨Protobuf£©ÐòÁл¯¡£¡£¡£ ¡£¡£¡£¡£¡£¹¤×÷Ä£¿£¿£¿£¿£¿£¿£¿éÕÆ¹ÜÖ´ÐÐÏÖʵ¼äµý»î¶¯£¬£¬£¬£¬£¬£¬Ô̺¬¼üÅ̼ͼ¡¢½ØÆÁ¡¢Îļþϵͳ²É¼¯¡¢ÏµÍ³ºÍÍøÂç¿úËÅ¡¢ÍøÂçµç×ÓÓʼþ¼°OutlookÊý¾Ý¡¢¼à¿Ø´°¿Ú¡¢ÇÔÈ¡×î½üÎļþµÈ¡£¡£¡£ ¡£¡£¡£¡£¡£ÍøÂçµÄÊý¾Ý¾­±¾µØ¼ÓÃÜ´æ´¢ºó£¬£¬£¬£¬£¬£¬Í¨¹ýÇŽÓÄ£¿£¿£¿£¿£¿£¿£¿éµ¼³ö¡£¡£¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-turn-kazuar-backdoor-into-modular-p2p-botnet/