TomirisÉý¼¶¶à˵»°±øÆ÷¿â£¬¾«×¼½ø¹¥¶íÍâ½»»ú¹¹

°ä²¼¹¦·ò 2025-12-02

1. TomirisÉý¼¶¶à˵»°±øÆ÷¿â£¬¾«×¼½ø¹¥¶íÍâ½»»ú¹¹


12ÔÂ1ÈÕ£¬¿¨°Í˹»ù×îл㱨½Òʾ£¬ÃûΪTomirisµÄÍþвÐÐΪÕßÕý¶Ô¶íÂÞ˹Íâ½»²¿¡¢¡¢µ±¾ÐÄä×éÖ¯¼°ÖÐÑǹú¶È»ú¹¹ÌáÒéÕ½ÊõÐÔÍøÂç¹¥»÷£¬ÆäÖ÷ÌâÖ¸±êÊÇͨ¹ýÓã²æÊ½´¹µöÓʼþ²¿Êð¶à˵»°±àдµÄ¶ñÒâÈí¼þÄ£¿é£¬»ñȡԶ³Ì½Ó¼ûȨÏÞ²¢³ÉÁ¢Óƾû¯½ÚÖÆ¡£¸Ã×éÖ¯2025Äê¹¥»÷Á´ÏÔʾ£¬³¬50%µÄµö¶üÎļþѡȡ¶íÓï¼°ÖÐÑǹú¶È¹Ù·½Ëµ»°¶¨ÖÆ£¬¹¥»÷Õßͨ¹ý¼ÓÃÜRARÎļþ£¨½âѹÃÜÂëÖ±½ÓǶÈëÓʼþÕýÎÄ£©·Ö·¢¼Ù×°³ÉWordÎĵµµÄ¿ÉÖ´ÐÐÎļþ£¬ÔËÐкó¿ªÊÍC/C++·´ÏòShell£¬ÏνÓC2·þÎñÆ÷ÏÂÔØAdaptixC2¿ò¼Ü£¬²¢Í¨¹ýÅú¸ÄWindows×¢²á±íʵÏÖ¶ñÒâÔØºÉÓÆ¾Ã»¯¡£TomirisµÄÕ½ÊõÑݱäÓÈΪÏÔÖø£¬ÆäÈÕ񾮵ÈÔµØÀûÓÃTelegram¡¢¡¢DiscordµÈ¹«¹²·þÎñ×÷ΪC2·þÎñÆ÷£¬½«¶ñÒâÁ÷Á¿ÓëºÏ·¨·þÎñÁ÷Á¿»ìºÏÒÔ¶ã±Ü¼ì²â¡£Æä¶ñÒâÈí¼þ±øÆ÷¿âº­¸ÇC#¡¢¡¢Rust¡¢¡¢Go¡¢¡¢PythonµÈ¶à˵»°±àдµÄ·´ÏòShell¡¢¡¢SOCKS´úÀí¼°ºóÃÅ·¨Ê½¡£¶à˵»°Ä£¿éµÄ½Ã½ÝÐÔ¡¢¡¢µÍ¿ÉÒÉÐÔÌØµã¼°¶Ô¿ªÔ´¿ò¼ÜµÄÀûÓã¬Ê¹Tomiris¿ÉÄÜʵÏÖÒñ±ÎµÄ³Ö¾ÃÓÆ¾Ã»¯¹¥»÷¡£


https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html


2. ÈÕÀú¶©Ôݲȫäµã£º£ºBitSightÆØ347¸ö¶ñÒâÓòÃû·çÏÕ


11ÔÂ28ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾BitSight×îÐÂ×êÑнÒʾ£¬ÍþвÐÐΪÕßÕýͨ¹ý°Ñ³ÖÊý×ÖÈÕÀú¶©ÔÄ»ù´¡ÉèʩִÐдó¹æÄ£Éç»á¹¤³Ì¹¥»÷¡£ÈÕÀú¶©ÔÄÖ°Äܱ¾ÓÃÓÚºÏÐ̳¡¾°£¬ÈçÁãÊÛÉÌÍÆËÍ´ÙÏúÈÕÆÚ¡¢¡¢ÌåÓýЭ»á¸üÐÂÈüÊÂÈճ̣¬ÆäÔÊÐíµÚÈý·½·þÎñÆ÷Ö±½ÓÏòÓû§É豸Ôö³¤ÊÂÎñ²¢·¢ËÍ֪ͨµÄ¸öÐÔ£¬È´±»¶ñÒâÀûÓ㬹¥»÷ÕߴÍйÜÓÚ¹ýÆÚ»ò±»½Ù³ÖÓòÃûµÄÐéαÈÕÀú¶©ÔÄ·þÎñ£¬ÓÕÆ­Óû§¶©ÔĺóÍÆËͺ¬¶ñÒâÁ´½Ó¡¢¡¢¸½¼þµÄÈÕÀúÎļþ£¬´¥·¢´¹µö¹¥»÷¡¢¡¢¶ñÒâÈí¼þ·Ö·¢¡¢¡¢JavaScript´úÂëÖ´ÐÐÉõÖÁAIÖúÊÖÀÄÓõȷçÏÕ¡£×êÑÐʼÓÚÒ»¸ö±» ¡°Sinkhole¡± ¼¼ÊõÊÕÊܵÄÓòÃû£¬¸ÃÓòÃûÔ­ÓÃÓÚ·Ö·¢µÂ¹ú¹«¹²¼ÙÆÚICSÎļþ£¬È´ÖðÈÕ½Ó¹Ü1.1Íò¸ö¶ÀÁ¢IP½Ó¼û£¬Òý·¢×êÑÐÍŶӹØ×¢¡£½øÒ»´ëÊ©²é·¢ÏÖ347¸ö¿ÉÒÉÈÕÀúÓòÃû£¬Éæ¼°2018ÊÀ½ç±­¡¢¡¢ÒÁ˹À¼HijriÈÕÀúµÈÖ÷Ì⣬ÖðÈÕÀۼƽµ­ÜÔ¼400Íò´ÎÃÀ¹úΪÖ÷µÄÈ«ÃÀ½Ó¼ûÒªÇó¡£³Á¶´Êý¾ÝÏÔʾ£¬ÕâЩ½Ó¼û¶àΪÒѶ©ÔÄÓû§µÄºó¶Üͬ²½ÒªÇó£¬Òâζ×ÅÊÕÊܹýÆÚÓòÃûµÄ¹¥»÷Õß¿ÉÖ±½ÓÏòÓû§Éè±¸ÍÆËͶ¨ÖÆ»¯¶ñÒâÈÕÀúÊÂÎñ¡£


https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/


3. PlayÀÕË÷Èí¼þ¹¥»÷ADC Aerospace


11ÔÂ29ÈÕ£¬ÃÀ¹úº½¿Õº½ÌìÓë¹ú·ÀÁìÓò¹¤³Ì²¿¼þÖÆ×÷ÉÌADC AerospaceÒò·þÎñŵ˹ÂÞÆÕ¡¤¸ñ³Âü¡¢¡¢¿ÂÁÖ˹º½¿Õº½Ìì¡¢¡¢»ôÄáΤ¶ûµÈ³ÛÃûÆóÒµ£¬³ÉΪÀÕË÷Èí¼þ¹¥»÷ÖØµãÖ¸±ê¡£Õâ´Î¹¥»÷ÓÉÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þ¼¯ÍÅÖ®Ò»PlayÖ´ÐУ¬¸Ã×éÖ¯ÒÔй¶¿Í»§Êý¾ÝΪÍþвÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð£¬Èô»Ø¾øÔò°ä²¼²¿ÃÅÊý¾ÝƬ¶Î¡£º£ºÚ¿ÍÐû³ÆÒÑ»ñÈ¡¿Í»§Îļþ¡¢¡¢Ô¤Ëã²ÆÕþÐÅÏ¢¡¢¡¢Ð½×ʼͼ¡¢¡¢Éí·ÝÖ¤Ã÷µÈ˽ÃÜÊý¾Ý£¬µ«Î´ÌṩÑù±¾£¬ÕæÊµÐÔ´ýºË²é¡£ÈôÊý¾Ýй¶Êôʵ£¬ADC½«Ãæ¶Ô¶àÖØ·çÏÕ£º£º°µÍø¶Ô¹ú·À³Ð°üÉÌÊý¾ÝµÄ¸ßÐèÒª¿ÉÄÜÍÆ¶¯±»µÁÐÅÏ¢ÂòÂô£»£»£»Ð½×ʼͼÖеÄСÎÒÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£»£»£»ÆäËû˽ÃÜÊý¾ÝÔò¿ÉÄܳÉΪÉç»á¹¤³Ì¹¥»÷¹¤¾ß£¬¹¥»÷Õß¼ÙÒâÐÐÒµÓйط½Ö´Ðиü¾ß·ÛËéÐÔµÄÚ¿Æ­¡£Play¼¯ÍÅÈ¥ÄêõÒÉíÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þǰÈý£¬½ñÄê8Ô³õ¸ÕÈëÇÖΪÃÀ¹úˮʦ¡¢¡¢²¨Òô¹©»õµÄJamco Aerospace¡£


https://cybernews.com/security/adc-aerospace-breach-claims/


4. CoupangÔâ·êº«¹úÊ·ÉÏ×î´ó¹æÄ£¿Í»§Êý¾Ýй¶ÊÂÎñ


11ÔÂ30ÈÕ£¬±»ÓþΪ¡°º«¹úÑÇÂíÑ·¡±µÄº«¹úµçÉ̾ÞÍ·CoupangÓÚ11ÔÂ18ÈÕÅû¶һ·´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬Ó°Ïì½ü3400Íò¸ö¿Í»§ÕË»§£¬´´º«¹úµ¥´ÎÊý¾Ýй¶ӰÏìÁìÓòÖ®×î¡£¾­µ÷²é£¬¹¥»÷Õß×Ô6ÔÂ24ÈÕÆðͨ¹ýÍâÑó·þÎñÆ÷ÌáÒéδ¾­ÊÚȨ½Ó¼û£¬Öð²½À©´ó¹¥»÷¹æÄ££¬×îÖÕµ¼Ö³¬3300Íòº«¹úÓû§Êý¾ÝÍâй¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢¡¢µç×ÓÓÊÏä¡¢¡¢µç»°ºÅÂë¡¢¡¢ÊÕ»õµØÖ·¼°²¿ÃŶ©µ¥¼Í¼£¬µ«Ö§¸¶ÐÅÏ¢ÓëµÇ¼ƾ֤δ±»»ñÈ¡¡£CoupangÔÚ·¢ÏÖÒì³£º£ºóÁ¢¼´Ïòº«¹úСÎÒÐÅÏ¢±£»£»£»¤Î¯Ô±»á¡¢¡¢¾¯·½¼°»¥ÁªÍø°²È«¾Ö»ã±¨£¬²¢Æô¶¯Ó¦¼±ÏìÓ¦¡£¹«Ë¾×î³õÎóÅнöÔ¼4500ÈËÊÜÓ°Ï죬ºóÐÞ¸ÄΪ³¬3300ÍòÈË£¬Í¹ÏÔ³õÆÚ¼ì²â»úÖÆµÄ²»¼°¡£º£º«¹úµ±¾Ö¶Ô´Ë¸ß¶ÈÆ÷ÖØ£¬¿ÆÑ§¼¼ÊõÐÅϢͨѶ²¿²¿³¤ÅᾩѫÖÜÈÕÖ÷³Ö´¹Î£»áÒ飬ºË²éCoupangÊÇ·ñÎ¥·´¡¶Ð¡ÎÒÐÅÏ¢±£»£»£»¤·¨¡·°²È«¹æ·¶¡£º£º«¹ú»¥ÁªÍø°²È«ÕñÐËÔº£¨KISA£©ÒÑÏòÊÜÓ°ÏìÓû§°ä²¼·À´¹µöÚ¿Æ­Ö¸ÄÏ£¬½¨Ò鶨ÆÚÅú¸ÄÃÜÂë¡¢¡¢ÆôÓÃË«³É·ÖÈÏÖ¤¡£Õâ´ÎÊÂÎñÒÑÒý·¢Óû§¼¯ÌåËßËÏ·çÏÕ£¬CoupangÕýÃæ¶Ô˾·¨×·ÔðÓëŵÑÔÖØ´´µÄË«ÖØÑ¹Á¦¡£


https://cybernews.com/news/coupang-confirms-massive-data-breach-exposing-33-7-million-accounts/


5. ¾¯·½²é·âÁËCryptomixer¼ÓÃÜÇ®±Ò»ìºÏ·þÎñ


12ÔÂ1ÈÕ£¬ÈðÊ¿ÓëµÂ¹ú·¨Âɲ¿ÃŽüÈÕ½áºÏ·¢Õ¹¡°°ÂÁÖÆ¥ÑÇÐж¯¡±£¬ÓÚ11ÔÂ24ÈÕÖÁ28ÈÕÔÚËÕÀèÊÀ²é·â¼ÓÃÜÇ®±Ò»ìºÏ·þÎñCryptomixer¡£¸Ãƽ̨×Ô2016ÄêÔËÓªÒÔÀ´£¬±»Ö¸Ð­ÖúÍøÂç·¸×ï·Ö×ÓÏ´Ç®³¬13ÒÚÅ·Ôª±ÈÌØ±Ò£¬³ÉΪÀÕË÷Èí¼þÍŻ¡¢°µÍøÊг¡¼°µØÏ¾­¼ÃÂÛ̳»ìºÏ·¸×ï×ʽðµÄÖ÷ÌâÇþµÀ¡£Ðж¯ÖУ¬·¨ÂÉ»ú¹¹ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖÏ£¬²é»ñÈý̨·þÎñÆ÷¡¢¡¢12TBÊý¾Ý¡¢¡¢Ã÷Íø¼°Tor°µÍøÓòÃû£¬²¢¿ÛѺ¼ÛÖµ2400ÍòÅ·Ôª±ÈÌØ±Ò¡£Cryptomixerͨ¹ý»ìºÏÓû§¼ÓÃÜÇ®±ÒÖÁ×Ê½ð³Ø²¢·Ö·¢ÖÁÐÂÇ®°üµØÖ·£¬ÓÐЧ×è¶ÏÇø¿éÁ´×ʽð×·×Ù£¬³ÉΪ··¶¾¡¢¡¢±øÆ÷×ß˽¡¢¡¢ÀÕË÷¹¥»÷¼°Ö§¸¶¿¨Ú²Æ­µÈ·¸×ï»î¶¯µÄÏ´Ç®Ê×Ñ¡¹¤¾ß¡£ÆäÔËӪģʽ»¹Ô̺¬¶ÔÏ´Ç®×ʽðÊÕȡӶ½ð£¬ÔÙ×ªÒÆÖÁ¿Í»§Ö¸¶¨Ç®°ü£¬×îÖÕͨ¹ýÒøÐлòATM½«·¸·¨×ʲúת»»Îª·¨±Ò»òÆäËû¼ÓÃÜÇ®±Ò¡£´ËÀà·þÎñËä´æÔںϷ¨Óô¦£¬µ«ÖØÒª±»·¸×ïÍÅ»ïÓÃÓÚÌӱܲ龿¡£


https://www.bleepingcomputer.com/news/security/police-takes-down-cryptomixer-cryptocurrency-mixing-service/


6. CISA½«OpenPLC ScadaBR·ì϶Ôö³¤µ½KEVĿ¼ÖÐ


12ÔÂ1ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«±àºÅΪCVE-2021-26829µÄOpenPLC ScadaBR·ì϶ÄÉÈëÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¸Ã·ì϶Ϊ¿çÕ¾¾ç±¾£¨XSS£©·ì϶£¬Í¨¹ýsystem_settings.shtmÎļþÓ°ÏìWindowsºÍLinux°æ±¾£¬¾ßÌåÉæ¼°Windows¶Ë1.12.4¼°¸üÔç°æ±¾¡¢¡¢Linux¶Ë0.9.1¼°¸üÔç°æ±¾£¬CVSSÆÀ·ÖΪ5.4¡£2025Äê9Ô£¬Ç×¶íºÚ¿Í×éÖ¯TwoNetÕë¶ÔÍøÂ簲ȫ¹«Ë¾ForescoutÔËÓªµÄICS/OTÃÛ¹ÞϵͳÌáÒé¹¥»÷£¬ÎóÅÐÆäΪˮ´¦Öó§¡£¹¥»÷ÕßÀûÓÃĬÈÏÆ¾Ö¤»ñȡϵͳ½Ó¼ûȨÏ޺󣬴´½¨ÃûΪ¡°BARLATI¡±µÄÕË»§£¬²¢Í¨¹ýCVE-2021-26829·ì϶´Û¸ÄÈË»ú½çÃæ£¨HMI£©µÇÂ¼Ò³Ãæ£¬Ã¿´Î½Ó¼û¸ÃÒ³ÃæÊ±£¬»á´¥·¢Ô̺¬Ôà»°µÄµ¯´°ÖҸ棬ͬʱ½ûÓÃÈÕÖ¾ºÍ¾¯±¨Ö°ÄÜ¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01£¬Áª°îÃñÓûú¹¹£¨FCEB£©ÐëÔÚ2025Äê12ÔÂ19ÈÕǰÐÞ¸´¸Ã·ì϶£¬ÒÔ½µµÍÖØ´ó·çÏÕ¡£CISAͬʱ½¨Òé˽Ӫ»ú¹¹Éó²éKEVĿ¼£¬ÊµÊ±ÐÞ²¹×ÔÉí»ù´¡ÉèÊ©ÖеÄͬÀà·ì϶£¬Ô¤·À±»ÀûÓá£


https://securityaffairs.com/185185/security/u-s-cisa-adds-an-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html