¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷

°ä²¼¹¦·ò 2025-12-08

1. ¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷


12ÔÂ4ÈÕ£¬£¬ÒÔIJÀûΪÖ÷Õŵġ°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ï½üÆÚÒÔ¼Ù×°µ±¾Ö·þÎñ»ú¹¹µÄ·½Ê½£¬£¬ÏòÓ¡¶ÈÄáÎ÷ÑÇ¡¢¡¢Ì©¹úºÍÔ½ÄϵÄÒÆ¶¯Óû§ÌáÒéÐÂÒ»ÂÖ¹¥»÷¡£¸ÃÍÅ»ï×Ô2024Äê10ÔÂÆð£¬£¬Í¨¹ý´«²¼Ö²È밲׿¶ñÒâÈí¼þµÄ´Û¸Ä°æÒøÐÐÀûÓÃÖ´Ðй¥»÷£¬£¬×îÔçÔÚÌ©¹ú±»·¢ÏÖ£¬£¬ºóÊæÕ¹ÖÁÔ½ÄϺÍÓ¡Äá¡£¾ÝÐÂ¼ÓÆÂIB¼¯Íż¼Êõ»ã±¨£¬£¬½öÓ¡Äá¾ÍÔì³É½ü2200ÆðÉ豸ϰȾ£¬£¬×ÜϰȾ°¸Àý³¬1.1ÍòÆð£¬£¬ÆäÖÐ63%µÄ´Û¸ÄÀûÓÃÕë¶ÔÓ¡ÄáÊг¡¡£¹¥»÷Á÷³Ì¼Ù×°³Éµ±¾Ö»ú¹¹»ò³ÛÃûÆ·ÅÆ£¬£¬Í¨¹ýµç»°Ú¿Æ­ÓÕµ¼Óû§µã»÷ZaloµÈͨѶÈí¼þÖеÄÁ´½Ó£¬£¬×°ÖöñÒâÈí¼þ¡£¶ñÒⷨʽͨ¹ý×¢Èë¶ñÒâ´úÂëµ½Õý¹æÒøÐÐÀûÓ㬣¬±£ÁôÕý³£Ö°ÄÜÒÔÈÆ¹ý°²È«·À»¤£¬£¬Ö÷±êÌâ±êÊÇÔ¶³Ì²Ù¿ØÉ豸¡£×êÑÐÈËÔ±·¢ÏÖÈýÀà½Ù³ÖÆ÷×é¼þ¡ª¡ª¡°¸¥Èð½Ù³ÖÆ÷¡±¡°Ìì¿Õ½Ù³ÖÆ÷¡±¡°Åɶ÷½Ù³ÖÆ÷¡±£¬£¬¿ÉʵÏÖ°µ²ØÀûÓᢡ¢¶ã±Ü¼ì²â¡¢¡¢Î±ÔìÊðÃû¡¢¡¢ÇÔÈ¡Óà¶îÐÅÏ¢µÈÖ°ÄÜ¡£¸ÃÍŻﻹ¿ª·¢ÁË¡°¾ÞÐÍ»¨¡±²âÊÔ°æ¶ñÒâÈí¼þ£¬£¬Ö§³Öʵʱ´«ÊäÉ豸»­Ãæ¡¢¡¢¼üÅ̼ͼ¡¢¡¢µ¯³öÐéα½çÃæÇÔÊØÐÅÏ¢£¬£¬²¢ÕýÔÚ¿ª·¢¶þάÂëɨÃèÖ°ÄÜÒÔÌáȡԽÄÏÉí·ÝÖ¤ÐÅÏ¢¡£


https://thehackernews.com/2025/12/goldfactory-hits-southeast-asia-with.html


2. Ó¡¶ÈÆóÒµÔâ¼Ùװ˰Îñ²¿ÃÅ´¹µö¹¥»÷


12ÔÂ4ÈÕ£¬£¬½üÆÚ£¬£¬Ò»³¡Õë¶ÔÓ¡¶ÈÆóÒµµÄ´ó¹æÄ£´¹µö¹¥»÷ÇÄÈ»·¢Õ¹¡£¹¥»÷Õß¼Ù×°³ÉÓ¡¶ÈËùµÃ˰²¿ÃÅ£¬£¬Í¨¹ý¸ß¶È·ÂÕæÈ·µ±¾Ö¹«º¯Ä£°å¼°Ó¡µØÓïÓëÓ¢ÓïË«ÓïͨѶ£¬£¬ÒýÓá¶ËùµÃ˰·¨¡·Ìõ¿îÖÆ×÷ºÏ·¨ÐÔÓë½ôÆÈ¸Ð£¬£¬»Ñ³ÆÊÕ¼þÈË´æÔÚ˰ÎñÎ¥¹æÐÐΪ£¬£¬ÒªÇó72СʱÄÚÌá½»Îļþ£¬£¬ÓÕÆ­Óû§´ò¿ª¶ñÒ⸽¼þ¡£Õâ´Î¹¥»÷ѡȡÁ½½×¶Î¶ñÒâÈí¼þÁ´£º£º£º³õÆÚÒÔÃÜÂë±£»¤µÄZIPÎļþ´îÔØshellcode¼ÓÔØÆ÷£¬£¬ºóÐø±äÌåÀûÓùȸèÎĵµÁ´½Ó½»¸¶¶þ¼¶ÔغÉ£¬£¬×îÖÕͶ·ÅAsyncRATÔ¶³Ì½Ú֯ľÂí£¬£¬ÊµÏÖÆÁÄ»¹²Ïí¡¢¡¢Îļþ´«Êä¼°Ô¶³ÌºÅÁîÖ´ÐС£¹¥»÷Ö¸±êËø¶¨Ö¤È¯¹«Ë¾¡¢¡¢½ðÈÚ»ú¹¹¼°·ÇÒøÐнðÈÚ¹«Ë¾£¬£¬ÒòÕâЩ»ú¹¹Ð趨ÆÚÓëµ±²¿ÃÅÃÅ»¥»»¼à¹ÜÎļþ£¬£¬³ÉÎªÖØµãÖ¸±ê¡£Raven°²È«ÍŶÓͨ¹ý¼ø±ð¹¥»÷¼Ü¹¹ÖеĶà²ãì¶Üµã£¬£¬³É¹¦·¢ÏÖ²¢×èÖ¹ÁËÕâÒ»ÁãÈÕ¹¥»÷£¬£¬Ô¤·ÀÖ¸±ê»ú¹¹´ó¹æÄ£Ï°È¾¡£ÓʼþÔ´×ԺϷ¨Ãâ·ÑÓÊÏäÕ˺Å£¬£¬Í¨¹ýSPF¡¢¡¢DKIM¼°DMARCÈÏÖ¤£¬£¬Èƹý´«Í³Óʼþ¹ýÂËÆ÷¡£ÃÜÂë±£»¤¸½¼þÔ¤·À´«ÊäÖб»É±¶¾Èí¼þɨÃ裬£¬½âѹºó³öÏֵġ°NeededDocuments¡±¿ÉÖ´ÐÐÎļþÄÚÖÃshellcode£¬£¬shellcodeÓëAsyncRAT½ÚÀñ·þÎñÆ÷³ÉÁ¢Í¨Ñ¶¡£


https://cybersecuritynews.com/new-phishing-attack-mimic-as-income-tax-department/


3. React2Shell·ì϶´ó¹æÄ£ÀûÓ㬣¬³¬7.7ÍòIPÊÜÓ°Ïì


12ÔÂ6ÈÕ£¬£¬React2ShellÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©Òý·¢È«Çò°²È«Î£»ú¡£¸Ã·ì϶ԴÓÚReact·þÎñÆ÷×é¼þ¶Ô¿Í»§¶Ë½ÚÖÆÊý¾ÝµÄ²»°²È«·´ÐòÁл¯»úÖÆ£¬£¬¹¥»÷Õß¿Éͨ¹ýµ¥¸öHTTPÒªÇó´¥·¢Î´¾­Éí·ÝÑéÖ¤µÄËÁÒâºÅÁîÖ´ÐУ¬£¬Ó°ÏìËùÓÐʵÏÖReact·þÎñÆ÷×é¼þµÄ¿ò¼ÜÈçNext.js¡£Shadowserver»ã±¨ÏÔʾ£¬£¬³¬77,000¸ö¶³öÔÚ»¥ÁªÍøµÄIPµØÖ·Ò×Êܹ¥»÷£¬£¬ÆäÖÐÔ¼23,700¸öλÓÚÃÀ¹ú£¬£¬Éæ¼°¶à¸öÐÐÒµ¡£·ì϶Åû¶ºó£¬£¬°²È«×êÑÐÔ±Maple3142°ä²¼¸ÅÄîÑéÖ¤£¬£¬Íƶ¯×Ô¶¯»¯É¨Ã蹤¾ßѸËÙÀ©É¢¡£GreyNoise¼à²âµ½£¬£¬´Óǰ24СʱÄÚÓÐ181¸ö·ÖÆçIP³¢ÊÔÀûÓø÷ì϶£¬£¬Á÷Á¿ÖØÒªÀ´×ÔºÉÀ¼¡¢¡¢Öйú¡¢¡¢ÃÀ¹ú¡¢¡¢Ïã¸ÛµÈµØÓò£¬£¬¹¥»÷Õß¶àʹÓÃPowerShellºÅÁîÈç¡°40138*41979¡±²âÊÔ·ì϶£¬£¬È·ÈϺóͨ¹ýbase64±àÂëÏÂÔØµÚ¶þ½×¶Î¾ç±¾£¬£¬²¿ÊðCobalt StrikeÐűê»òSnowlight¡¢¡¢Vshell¶ñÒâÈí¼þ£¬£¬ÊµÏÖÔ¶³Ì½Ó¼û¡¢¡¢ºáÏòÒÆ¶¯¼°Ãô¸ÐÐÅÏ¢ÇÔÈ¡¡£


https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable/


4. Barts Health NHS TrustÔâClopÀÕË÷Èí¼þ¹¥»÷


12ÔÂ5ÈÕ£¬£¬Ó¢¹úBarts Health NHS Trust½üÈÕ°ä·¢£¬£¬ÆäOracle E-business SuiteÈí¼þ´æÔÚ·ì϶£¨CVE-2025-61882£©£¬£¬±»ClopÀÕË÷Èí¼þÍÅ»ïÀûÓ㬣¬µ¼ÖÂÊý¾Ý¿âÖÐÓâÔ½ÊýÄêµÄ·¢Æ±Îļþ±»µÁ¡£Ð¹Â¶Êý¾ÝÉæ¼°ÔڰʹĽ¡¿µÒ½Ôº½ÓÊÜÒ½Öλò·þÎñÈËÔ±µÄÈ«Ãû¡¢¡¢µØÖ·£¬£¬²¿ÃÅǰ¹ÍÔ±¼°Òѹ«¿ªÊý¾ÝµÄ¹©¸øÉÌÐÅÏ¢£¬£¬ÒÔ¼°×Ô2024Äê4ÔÂÆð¸ÃÐÅÈÎÏòBarking¡¢¡¢HaveringºÍRedbridge´óѧҽԺNHSÐÅÈÎÌṩµÄ¹ÜÕÊ·þÎñÓйØÎļþ¡£ClopÒѽ«ÇÔÊØÐÅÏ¢ÉÏ´«ÖÁ°µÍøÐ¹Â¶ÃÅ»§£¬£¬µ«BartsÇ¿µ÷£¬£¬Ä¿Ç°½öÏÞ¼ÓÃܰµÍøÓû§¿É½Ó¼ûѹËõÎļþ£¬£¬Î´·¢ÏÖÊý¾ÝÔÚ¹«¿ª»¥ÁªÍø´«²¼¡£Õâ´Î¹¥»÷²úÉúÓÚ2025Äê8Ô£¬£¬Ö±ÖÁ11ÔÂÎļþ±»°ä²¼ÖÁ°µÍøºó²ÅÈ·ÈÏÊý¾Ý·çÏÕ¡£BartsÒÑÏò¹ú¶ÈÍøÂ簲ȫÖÐÐÄ¡¢¡¢Â׶ؾ¯Ô±Ìü¼°ÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©´«µÝÊÂÎñ£¬£¬²¢ÉêÇë¸ßµµ·¨ÔººÅÁî²»ÈÝÊý¾ÝʹÓᢡ¢°ä²¼»ò·ÖÏí£¬£¬µ«´ËÀà½ûÁîÏÖʵЧÁ¦ÓÐÏÞ¡£¸Ã»ú¹¹ÔËÓªÂ×¶ØÎå¼ÒÒ½Ôº£¬£¬Ô̺¬»Ê¼ÒÂ×¶ØÒ½Ôº¡¢¡¢Ê¥°ÍÈûÂåçÑÒ½ÔºµÈ£¬£¬Æäµç×Ó²¡Àú¼°ÁÙ´²ÏµÍ³Î´ÊÜÓ°Ï죬£¬Ö÷ÌâIT»ù´¡ÉèÊ©°²È«ÐÔÈÔ»ñ×¢¶¨¡£


https://www.bleepingcomputer.com/news/security/barts-health-nhs-discloses-data-breach-after-oracle-zero-day-hack/


5. InotivÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂ9500ÓàÈËÊý¾Ýй¶


12ÔÂ5ÈÕ£¬£¬ÃÀ¹úÖÆÒ©¹«Ë¾Inotiv½üÈÕÅû¶£¬£¬2025Äê8ÔÂ5ÈÕÖÁ8ÈÕÆÚ¼ä£¬£¬Æä²¿ÃÅÍøÂçºÍϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬µ¼ÖÂÊý¾Ý¿â¼°ÄÚ²¿ÀûÓ÷¨Ê½Ì±»¾£¬£¬ÒµÎñÔËÓªÊÜÑÏÖØÓ°Ïì¡£¸Ã¹«Ë¾ËæºóÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ìá½»ÎļþÈ·ÈÏ£¬£¬ÒѸ´Ô­ÊÜÓ°Ïìϵͳ½Ó¼ûȨÏÞ£¬£¬²¢ÕýÏò8ÔÂÊÂÎñÖÐÊý¾Ý±»µÁµÄ9,542ÃûСÎÒ·¢ËÍ֪ͨ£¬£¬Éæ¼°ÏÖÈÎ/ǰÈÎÔ±¹¤¡¢¡¢¾ìÊô¼°ÓëÊÕ¹º¹«Ë¾Óйý»¥¶¯µÄÆäËûÈËÔ±¡£Õâ´Î¹¥»÷ÓÉ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÕƹÜ¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû³Æ£¬£¬ÇÔÈ¡ÁËInotiv³¬16.2Íò¸öÎļþ£¬£¬×ܼÆ176GB£¬£¬µ«InotivδÃ÷È·¾ßÌåй¶Êý¾ÝÀàÐÍ£¬£¬Ò²Î´È·ÈÏ÷è÷ëÉêÃ÷µÄÕæÊµÐÔ¡£Inotiv×ܲ¿Î»ÓÚÓ¡µÚ°²ÄÉÖÝ£¬£¬ÊÇÒ»¼ÒÄêÊÕÈ볬5ÒÚÃÀÔªµÄºÏͬ×êÑлú¹¹£¬£¬×¨Ò»Ò©Î↑·¢¡¢¡¢°²È«ÐÔÆÀ¹À¼°»îÌ嶯Îï×êÑÐÄ£Ð͹¹½¨£¬£¬Õ¼ÓÐÔ¼2000ÃûÔ±¹¤¡£Ö»¹ÜÕâ´Î¹¥»÷䲨¼°Ö÷ÌâÁÙ´²ÏµÍ³£¬£¬µ«Êý¾Ýй¶·çÏÕÈÔÒý·¢¼à¹Ü¹Ø×¢¡£


https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-discloses-data-breach-after-ransomware-attack/


6. ¶à½×¶Î¹¥»÷»î¶¯¶Ô×¼Palo AltoÓëSonicWall°²È«É豸


12ÔÂ6ÈÕ£¬£¬ÍþвÐÐΪÕß12ÔÂ2ÈÕÆðÀûÓõ¹úÍйܷþÎñÌṩÉÌ3xK GmbHÔËÓªµÄBGPÍøÂ磨AS200373£©ÏÂ7000Óà¸öIPµØÖ·£¬£¬ÌáÒéÕë¶ÔPalo Alto GlobalProtect VPNÃÅ»§¼°SonicWall SonicOS API¶ËµãµÄ¶à½×¶Î¹¥»÷¡£GreyNoise»ã±¨ÏÔʾ£¬£¬¹¥»÷ÕßÊ×ÏÈͨ¹ý±©Á¦ÆÆ½â³¢ÊԵǼPalo Alto·À»ðǽµÄÔ¶³Ì½Ó¼û×é¼þGlobalProtect£¬£¬ËæºóתÏòɨÃèSonicOS API¶Ëµã¡ª¡ª¸Ã²Ù×÷ϵͳ½ÚÖÆSonicWall·À»ðǽµÄÅäÖÃÓë¼à¿ØÖ°ÄÜ¡£Õâ´Î»î¶¯Óë11ÔÂÖÐÑ®¼Í¼µÄ230Íò´ÎGlobalProtectɨÃè´æÔÚ¹ØÁª£º£º£º62%µÄ¹¥»÷IPλÓڵ¹ú£¬£¬¾ùʹÓÃÒ»ÑùTCP/JA4tÖ¸ÎÆ£¬£¬ÇÒÔ´×Ô´ËǰÎÞ¶ñÒâ¼Í¼µÄËĸöASN¡£º¹ÇàɨÃè»î¶¯ÔøÌìÉú³¬900Íò´Î²»³ÉαÔìµÄHTTP»á»°£¬£¬Ö¸±êÖ±Ö¸GlobalProtect¡£12ÔÂ3ÈÕ£¬£¬Õë¶ÔSonicOS APIµÄɨÃèÖÐÔٴγöÏÖÒ»ÑùÈý¸ö¿Í»§Ö¸ÎÆ£¬£¬GreyNoise¾Ý´ËÅж¨Á½½×¶Î¹¥»÷ͬԴ¡£Palo Alto Networks»ØÓ¦³Æ£¬£¬¼ì²âµ½µÄɨÃè»î¶¯ÊôÓÚ¡°Æ¾Ö¤¹¥»÷¶ø·Ç·ì϶ÀûÓá±£¬£¬ÆäÄÚ²¿Ò£²â¼°Cortex XSIAM·À»¤ÏµÍ³È·ÈÏδ¶Ô²úÆ··þÎñÔì³ÉÇÖº¦£¬£¬½¨Òé¿Í»§ÆôÓöà³É·ÖÈÏÖ¤£¨MFA£©·À±¸Æ¾Ö¤ÀÄÓá£SonicWall·½ÃæÉÐδ¹«¿ªÖÃÆÀ¡£


https://www.bleepingcomputer.com/news/security/new-wave-of-vpn-login-attempts-targets-palo-alto-globalprotect-portals/