ÐÂÐ͹©¸øÁ´¹¥»÷GlassWormͨ¹ýVS CodeÊг¡Ï°È¾¿ª·¢Õß

°ä²¼¹¦·ò 2025-10-22

1. ÐÂÐ͹©¸øÁ´¹¥»÷GlassWormͨ¹ýVS CodeÊг¡Ï°È¾¿ª·¢Õß


10ÔÂ20ÈÕ£¬Ò»ÖÖÃûΪGlassWormµÄ×ÔÎÒ´«²¼¶ñÒâÈí¼þÕýͨ¹ýOpenVSXºÍMicrosoft Visual StudioÊг¡ÌáÒ鹩¸øÁ´¹¥»÷£¬ÒÑÔì³ÉÔ¼35,800´Î×°Ö㬳ÉΪÊ×ÀýÕë¶ÔVS CodeµÄÈä³æÊ½¹©¸øÁ´¹¥»÷°¸Àý¡£¡£¸Ã¶ñÒâÈí¼þÀûÓÃÒþÐÎUnicode×Ö·û°µ²Ø¶ñÒâ´úÂ룬ͨ¹ýÇÔÈ¡µÄÕË»§ÐÅÏ¢´«²¼ÖÁ¸ü¶à¿É½Ó¼ûµÄÀ©´ó·¨Ê½£¬²¢Ñ¡È¡SolanaÇø¿éÁ´½øÐп¹É¾³ýµÄºÅÁî½ÚÖÆ£¬Í¬Ê±ÒÔGoogleÈÕÀú×÷Ϊ±¸ÓÃͨµÀ¡£¡£¹¥»÷õè¾¶ÏÔʾ£¬GlassWormÔÚ×°Öúó»áÇÔÈ¡GitHub¡¢¡¢npm¡¢¡¢OpenVSXÕË»§Í´´¦¼°49¸öÀ©´óµÄ¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý£¬²¿ÊðSOCKS´úÀí·ÓɶñÒâÁ÷Á¿£¬²¢×°ÖÃVNC¿Í»§¶ËʵÏÖÒþÐÎÔ¶³Ì½Ó¼û¡£¡£Æä×îÖÕÓÐÐ§ÔØºÉZOMBIͨ¹ýSolanaÇø¿éÁ´ÂòÂôÁ´½Ó·Ö·¢£¬½«ÊÜϰȾϵͳת»¯ÎªÍøÂç·¸×ï½Úµã¡£¡£×êÑÐÖ¸³ö£¬¸Ã¶ñÒâÈí¼þ»¹ÀûÓÃBitTorrent DHT½øÐзÖÉ¢ºÅÁî·Ö·¢£¬²¢Ö§³ÖÖ±½ÓÏνÓIPµØÖ·µÄµÚÈý½»¸¶»úÖÆ¡£¡£½ØÖÁ»ã±¨°ä²¼£¬OpenVSXÉÏÖÁÉÙ11¸öÀ©´ó¼°VS CodeÊг¡1¸öÀ©´ó±»Ï°È¾¡£¡£Ä¿Ç°£¬OpenVSXÉÏÈÔÓÐÖÁÉÙ4¸öÊÜϰȾÀ©´ó¿ÉÏÂÔØ£¬Î¢ÈíÒÑÒÆ³ý¶ñÒâÀ©´ó£¬²¿ÃŰ䲼ÕßÒѸüÐÂÐÞ¸´¡£¡£


https://www.bleepingcomputer.com/news/security/self-spreading-glassworm-malware-hits-openvsx-vs-code-registries/


2. ºÚ¿ÍÐû³ÆÍâÂôƽ̨GetirÊý¾Ýй¶


10ÔÂ20ÈÕ£¬ÍÁ¶úÆäÍâÂôƽ̨Getir½üÈÕÏÝÈëÊý¾Ýй¶ÕùÒé¡£¡£¹¥»÷ÕßÔÚÈȵãÊý¾Ýй¶ÂÛ̳°ä²¼Ìû×Ó£¬Ðû³ÆÒÑ¡°ÈëÇÖ¡±¸Ã¹«Ë¾ÄÚÍøÏµÍ³¡£¡£¾Ý¹¥»÷ÕßÅû¶µÄÑù±¾Êý¾Ý£¬Ð¹Â¶ÄÚÈÝÖØÒªÎªGetirÄÚ²¿ÀûÓ÷¨Ê½ÔªÊý¾Ý£¬Ô̺¬Bitbucket´æ´¢¿âURL¡¢¡¢Óû§È¨ÏÞ¡¢¡¢ÏîÄ¿Ãû³Æ¡¢¡¢¹¤×÷ÇøID¼°Ô±¹¤µç×ÓÓʼþµØÖ·¡£¡£×êÑÐÍŶӷÖÎöÒÔΪ£¬ÕâЩÊý¾Ý¸ü¿ÉÄÜͨ¹ýµÚÈý·½·þÎñÌṩÉÌ»ñÈ¡£¬¶ø·ÇÖ±½Ó½Ó¼û¹«Ë¾Ö÷Ìâϵͳ¡£¡£Ö»¹ÜÈç´Ë£¬Ð¹Â¶µÄÔªÊý¾ÝÈÔ¿ÉÄÜ´øÀ´¶àÖØ·çÏÕ£º¹¥»÷Õß¿ÉÀûÓÃÔ±¹¤µç×ÓÓʼþµØÖ·Ö´ÐÐÉç»á¹¤³Ì¹¥»÷£¬ÓÕµ¼Ô±¹¤Ð¹Â¶Ãô¸ÐÐÅÏ¢»òµã»÷¶ñÒâÁ´½Ó£¬½ø¶ø»ñÈ¡¸üÉî²ãϵͳȨÏÞ£»£»Â¶³öµÄ´æ´¢¿âURLºÍ¹¤×÷ÇøIDÔò±ãÓÚ¹¥»÷ÕßÔÚÏîÄ¿ÖÐËÑË÷δÊܱ£»£»¤µÄAPI¶Ëµã»òÅäÖ÷ì϶£¬ÎªºóÐø¹¥»÷£¨ÈçÔ´´úÂëÇÔÈ¡¡¢¡¢ÏµÍ³ÈëÇÖ£©´´ÖÆÇ°Ìá¡£¡£Ä¿Ç°£¬GetirÉÐδ¶ÔÊÂÎñ×÷³öÕýʽ»ØÓ¦¡£¡£


https://cybernews.com/security/getir-data-breach-claims/


3. VerisureÔâµÚÈý·½ºÏ×÷·½Êý¾Ýй¶£¬Ó°ÏìÈðµä3.5ÍòÓû§


10ÔÂ20ÈÕ£¬Èðµä°²È«¾ÞÍ·Verisure½üÈÕÅûÂ¶Ò»Â·Éæ¼°ÆìÏÂAlert Alarm²¿Ãſͻ§µÄÊý¾Ýй¶ÊÂÎñ¡£¡£¸Ã¹«Ë¾Ö¤Êµ£¬¹¥»÷Õßͨ¹ýÆäÈðµäÍⲿ·¢Æ±ºÏ×÷ͬ°éµÄ·þÎñÆ÷£¬·¸·¨½Ó¼ûÁËÓëAlert Alarm¿Í»§ÓйصÄÊý¾Ý¡£¡£¾­³õ´ëÊ©²é£¬Verisure×ÔÉíÍøÂç¼°Ö÷Ìâϵͳδ·¢ÏÖÈëÇÖºÛ¼££¬ÊÂÎñ½öÓ°ÏìµÚÈý·½¼Æ·Ñϵͳ£¬µ«ÒѲ¨¼°ÈðµäÔ¼3.5ÍòÃûAlert AlarmµÄÏÖÓм°Ç°Óû§¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬¿Í»§È«Ãû¡¢¡¢µØÖ·¡¢¡¢µç×ÓÓʼþµØÖ·¼°Éç»á°²È«ºÅÂëµÈÃô¸ÐÐÅÏ¢¡£¡£VerisureÇ¿µ÷£¬Ö»¹ÜÊý¾Ý½Ó¼ûȨÏÞ¡°ÓÐÏÞ¡±£¬µ«ÒÑÆô¶¯È«Ãæµ÷²é²¢Ó뾯·½¡¢¡¢¼à¹Ü²¿ÃźÏ×÷£¬ºóÐø½«ÊµÊ±ÏòÊÜÓ°Ïì¿Í»§´«µÝ½øÕ¹¡£¡£Alert Alarm×÷ΪVerisureÆìÏÂרһסլ¡¢¡¢¹«Ô¢¼°Ð¡ÐÍÆóÒµ°²È«·þÎñµÄ²¿ÃÅ£¬ÔÚÈðµäÕ¼Óв»µ½6000Ãû¶©ÔÄÓû§£¬µ«Õâ´ÎÊÂÎñÏÖʵӰÏìÁìÓò¸ü¹ã£¬Éæ¼°º¹ÇàÓû§Êý¾Ý¡£¡£Ä¿Ç°£¬VerisureÕýÓ밲ȫÕÕ·÷ºÏ×÷ÅŲé·ì϶£¬²¢ºôÓõ¿Í»§¾¯Ìè´¹µö¹¥»÷¼°Éí·Ýڲƭ¡£¡£


https://cybernews.com/security/verisure-data-breach/


4. AWSÈ«Çò´ó¹æÄ£ÖжÏÖÂ¶àÆ½Ì¨Ì±»¾£¬·þÎñ¸´Ô­¹ý³Ì³ÖÐøÍÆ¶¯


10ÔÂ20ÈÕ£¬ÑÇÂíÑ·AWSÔâ·êÈ«ÇòÐÔ´ó¹æÄ£ÖжÏÊÂÎñ£¬µ¼ÖÂÊý°ÙÍòÍøÕ¾¼°·þÎṉ̃»¾£¬Ó°ÏìÁìÓòº­¸ÇÃÀ¹ú¡¢¡¢Å·Ö޵ȶà¸öµØÓò¡£¡£Õâ´ÎÖжÏʼÓÚÃÀ¹ú¶«²¿¹¦·òÁ賿4:30×óÓÒ£¬³ÖÐøÔ¼45·ÖÖÓºó²¿ÃÅ·þÎñÆðÍ·¸´Ô­£¬µ«ºóÐøÓÖÒòÍøÂç¸ºÔØÆ½ºâÆ÷ÎÊÌâ³öÏÖ·´¸´£¬½ØÖÁµ±ÈÕÏÂÎç12:06£¬AWS°ä·¢ÒÑͨ¹ý¶îÍ⻺½â´ëÊ©¸´Ô­ÏνÓÐÔ¼°APIÖ°ÄÜ£¬µ«ÐÂEC2ʵÀýÆô¶¯ÈÔÊÜÏÞ£¬Ô¤¼ÆÌ«Æ½ÑóÏÄÁîʱÉÏÎç10:00ǰ¸üнøÕ¹¡£¡£¾ÝAWS½¡¿µÒ³ÃæÅû¶£¬ÎÊÌâÖ÷ÌâÔ´ÓÚUS-EAST-1ÇøÓòDynamoDB API¶ËµãµÄDNS½âÎö¹ÊÕÏ£¬Òý·¢¶à¸ö·þÎñÃýÎóÂÊÓëÑÓ³¤¼¤Ôö£¬Ô̺¬Amazon.com¡¢¡¢Prime Video¡¢¡¢Perplexity AI¡¢¡¢CanvaµÈÖ÷ÌâÆ½Ì¨¾ùÊܲ¨¼°¡£¡£¾ßÌåÊÜÓ°Ïì·þÎñÇåµ¥ÏÔʾ£¬³ýÑÇÂíÑ·×Ô½»Ò×ÎñÍ⣬Epic GamesÆìÏ¡¶µï±¤Ö®Ò¹¡·£¨µÇ¼ְÄÜ̱»¾£©¡¢¡¢Roblox¡¢¡¢Hulu¡¢¡¢Snapchat¡¢¡¢Grammarly¡¢¡¢Roblox¼°½ÌÓýƽ̨CanvasµÈ15¸öÖØÒª·þÎñͨ¹ýDowndetectorÈ·ÈÏÖжÏ£¬CanvaÔÚ×´Ì¬Ò³ÃæÃ÷È·Ö¸³öÃýÎóÂÊÏÔÖøÉÏÉýÓ°ÏìͼÏñ±à×ëµÈÖ°ÄÜ£¬Fortnite¡¢¡¢PerplexityÒà֤ʵ·þÎñÏÂÏß¡£¡£


https://www.bleepingcomputer.com/news/technology/aws-outage-crashes-amazon-prime-video-fortnite-perplexity-and-more/


5. CISAÈ·ÈÏOracle E-Business Suite SSRF·ì϶ÔâÀûÓÃ


10ÔÂ21ÈÕ£¬ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Oracle E-Business SuiteµÄCVE-2025-61884·ì϶ÄÉÈëÒÑÖª±»ÀûÓ÷ì϶Ŀ¼£¬ÒªÇóÁª°î»ú¹¹ÓÚ2025Äê11ÔÂ10ÈÕǰʵÏÖÐÞ²¹¡£¡£¸Ã·ì϶ΪOracle ConfiguratorÔËÐÐʱ×é¼þÖеķþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬OracleÓÚ10ÔÂ11ÈÕÅû¶ʱ½«ÆäÑÏÖØÐÔÆÀ¼¶Îª7.5£¬ÖÒ¸æÆäÒ×±»ÀûÓÃÒÔ¡°Î´¾­ÊÚȨ½Ó¼û¹Ø¼üÊý¾Ý»òÆëÈ«½Ó¼ûËùÓÐOracle Configurator¿É½Ó¼ûÊý¾Ý¡±¡£¡£µ÷²éÏÔʾ£¬¸Ã·ì϶Óë7Ô¹¥»÷ÖÐй¶µÄ·ì϶ֱ½ÓÓйØ¡£¡£10Ô³õ£¬MandiantÅû¶ClopÀÕË÷Èí¼þÍÅ»ïÒÑÏòÆóÒµ·¢ËÍÀÕË÷Óʼþ£¬Ðû³ÆÀûÓÃÁãÈÕ·ì϶ÇÔÈ¡ÁËOracle EBSÊý¾Ý¡£¡£Oracle»ØÓ¦³Æ£¬ÍþвÐÐΪÕßÀûÓÃÁË7ÔÂÒÑÐÞ²¹µÄ·ì϶¡£¡£½øÒ»´ëÊ©²é½Òʾ£¬Oracle EBS³ÉΪÁ½Æð¶ÀÁ¢¹¥»÷µÄÖ¸±ê£º7Ô¹¥»÷Õë¶Ô¡°/configurator/UiServlet¡±¶ËµãµÄSSRF·ì϶£¨¼´CVE-2025-61884£©£¬¶ø8Ô¹¥»÷ÔòÀûÓá°/OA_HTML/SyncServlet¡±¶ËµãµÄÁíÒ»·ì϶£¨CVE-2025-61882£©£¬ºóÕß±»¹éÒòÓÚClopÍŻ¡£


https://www.bleepingcomputer.com/news/security/cisa-confirms-hackers-exploited-oracle-e-business-suite-ssrf-flaw/


6. ¶í¹ØÁªÀÕË÷ÍÅ»ïINC RansomÍþв¹«¿ª¸ß¶û·ò¾ÞÍ·Êý¾Ý


10ÔÂ21ÈÕ£¬Óë¶íÂÞ˹ÓйصÄÀÕË÷Èí¼þÍÅ»ïINC Ransom 10ÔÂ16ÈÕÔÚ°µÍøÐ¹ÃÜÍøÕ¾Ðû³Æ£¬ÒÑÇÔÈ¡¸ß¶û·ò·þ×°¾ÞÍ·Summit Golf Brands47GBÊý¾Ý£¬²¢Æô¶¯Êý¾Ý¹«¿ªµ¹¼ÆÊ±£¬¾àËùν¡°Êý¾Ý°ä²¼¡±½öÊ£ÈýÌì¡£¡£¸ÃÍÅ»ïÉÐδÌṩÊý¾ÝÑù±¾×ôÖ¤£¬´Ë¾Ù±»ÊÓΪÆÈʹÆóÒµÖ§¸¶Êê½ðµÄÕ½Êõ¼¿Á©¡£¡£Summit Golf BrandsÆìÏÂÔ̺¬Zero Restriction¡¢¡¢B. DraddyµÈ³ÛÃûÆ·ÅÆ£¬ÄêÓªÊÕ2790ÍòÃÀÔª¡£¡£INC Ransom³ÉÁ¢ÓÚ2023Äê7Ô£¬ÒÑÔì³É234ÃûÊܺ¦Õߣ¬ÒÔ¡°¶àÖØÀÕË÷¡±Öø³Æ£º²»½ö¼ÓÃÜÎļþ£¬»¹ÇÔÈ¡Êý¾Ý²¢Íþвй¶£¬ÉõÖÁÒÔ¡°¸¶·Ñ¼´ÌáÉýϵͳ°²È«¡±µÄŤÇú˵´ÇÓÕÆ­Êê½ð¡£¡£Õâ´ÎÕë¶ÔSummit Golf BrandsµÄ¹¥»÷£¬Â¶³öÁËÀÕË÷Èí¼þÍÅ»ï¶ÔóÒ×ʵÌåµÄ³ÖÐøÍþв¡£¡£Ëæ×ŵ¹¼ÆÊ±ÁÚ½ü£¬ÆóÒµÃæ¶ÔÁ½ÄÑ£ºÖ§¸¶Êê½ð¿ÉÄÜÖú³¤·¸×»Ø¾øÔò¿ÉÄÜÃæ¶ÔÊý¾Ýй¶·çÏÕ¼°ÃûÓþÇÖº¦¡£¡£


https://cybernews.com/security/hackers-threaten-to-drop-47gb-of-top-golf-brands-secrets/