΢Èí365ÕË»§ÔâOAuthÉ豸´úÂë´¹µö¹¥»÷¼¤Ôö
°ä²¼¹¦·ò 2025-12-231. ΢Èí365ÕË»§ÔâOAuthÉ豸´úÂë´¹µö¹¥»÷¼¤Ôö
12ÔÂ19ÈÕ£¬£¬×Ô9ÔÂÆð£¬£¬µç×ÓÓʼþ°²È«¹«Ë¾Proofpoint¼à²âµ½ÀûÓÃOAuthÉ豸´úÂëÊÚȨ»úÖÆµÄÍøÂç´¹µö¹¥»÷ÏÔÖøÔö³¤£¬£¬¹¥»÷Õßͨ¹ýÓÕÆÊܺ¦ÕßÔÚ΢ÈíºÏ·¨É豸µÇÂ¼Ò³ÃæÊäÈëÉ豸´úÂ룬£¬ÎÞÐèÇÔȡʹ´¦»òÈÆ¹ý¶àÖØÉí·ÝÑéÖ¤£¨MFA£©¼´¿É»ñÈ¡Microsoft 365ÕË»§½ÚÖÆÈ¨¡£´ËÀ๥»÷²»½öÉæ¼°¾¼ÃÀûÒæÇý¶¯µÄÍøÂç·¸×ï·Ö×ÓÈçTA2723£¬£¬»¹Ô̺¬¹ú¶È½áÃ˵ÄÍþвÐÐΪÕßÈçÒÉËÆ¶íÂÞ˹¹ØÁªµÄUNK_AcademicFlare¡£¹¥»÷Á´Í¨³£Í¨¹ý´¹µöÓʼþÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó½Ó¼û¹¥»÷Õß½ÚÖÆµÄÍøÕ¾£¬£¬ËæºóÒªÇóÊäÈë¡°É豸´úÂ롱ʵÏÖ¡°°²È«ÑéÖ¤¡±£¬£¬ÊµÔòÊÚȨ¶ñÒâÀûÓ÷¨Ê½½Ó¼ûÕË»§¡£Proofpoint¹Û²ìµ½¹¥»÷ÕßʹÓÃSquarePhish v1/v2ºÍGraphishµÈ¹¤¾ß¼ò»¯´¹µöÁ÷³Ì¡£ÀýÈ磬£¬Ð½×ʼν±¹¥»÷ÀûÓÃÎĵµ¹²Ïíµö¶üºÍ±¾µØ»¯Æ·ÅƱêʶÒýÓÕµã»÷£»£»£»TA2723×Ô10ÔÂÆðתÏò´ËÀ๥»÷£¬£¬ÔçÆÚʹÓÃSquarePhish2£¬£¬ºóÆÚ¿ÉÄÜÇл»ÖÁGraphish£»£»£»UNK_AcademicFlareÔòÀûÓñ»ÈëÇÖÈ·µ±¾Ö/¾ü·½ÓÊÏä³ÉÁ¢ÐÅÀµ£¬£¬Í¨¹ýαÔìOneDriveÁ´½ÓÓÕµ¼É豸´úÂëÊäÈ룬£¬ÖØÒªÕë¶ÔÃÀÅ·µ±¾Ö¡¢Ñ§Êõ¡¢Öǿ⼰½»Í¨²¿ÃÅ¡£
https://www.bleepingcomputer.com/news/security/microsoft-365-accounts-targeted-in-wave-of-oauth-phishing-attacks/
2. ºÓ´²¾º¼¼¾ãÀÖ²¿Ôâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
12ÔÂ21ÈÕ£¬£¬°¢¸ùÍ¢ºÓ´²¾º¼¼¾ãÀÖ²¿£¨CARP£©ÓÚÖÜÎåÔâ·ê÷è÷ëÀÕË÷Èí¼þ×éÖ¯¹¥»÷£¬£¬¸Ã×éÖ¯½«ÆäÁÐΪ¡°¹ÜÕÊ·þÎñ¡±Êܺ¦Õß²¢°ä²¼Ô̺¬Êýǧ·ÝÎļþµÄÑó´ÐÁ´½Ó¡£ÎļþÀàÐͺ¸ÇPDF¡¢Excel¡¢Word¡¢Í¼Ïñ¡¢µç×ÓÓʼþ¼°Ñ¹Ëõ´æµµ£¬£¬µ¥Îļþ¾Þϸ´Ó1KBÖÁ22MB²»µÈ£¬£¬¹¦·ò¿ç¶ÈΪ2021ÖÁ2025Ä꣬£¬Éæ¼°·¢Æ±¡¢ºÏͬ¡¢¼¼Êõ¹æ·¶¡¢¹¹ÖþÆ½ÃæÍ¼µÈÃô¸ÐÄÚÈÝ£¬£¬ÉõÖÁÔ̺¬ÐÅÓþ¿¨Õ˵¥ºÍ²É¹º¶©µ¥Ñù±¾¡£º£º£ºÓ´²×÷Ϊ°¢¸ùÍ¢×î³É¹¦×ãÇò¶Ó£¨72¹Ú£©£¬£¬Õ¼ÓÐ35Íò»áÔ±¼°ÄÏÃÀÖÞ×î´óÇò³¡£¬£¬ÆäÇàÉÙÄ겿ÃÅ×îС¶ÓÔ±½ö7Ë꣬£¬Õâ´Î¹¥»÷¶³ö³öÌåÓý»ú¹¹ÍøÂ簲ȫ·ì϶¡£÷è÷ëÀÕË÷Èí¼þ×Ô2021Äê»îÔ¾£¬£¬2022Äê³õ´Î¼Í¼¹¥»÷£¬£¬2025Äê³ÉΪ×î»îÔ¾ÍŻ£¬´Óǰ°ëÄê·¢Æð³¬600Æð¹¥»÷¡£¸Ã×é֯ѡȡ¡°ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©¡±Ä£Ê½£¬£¬³¢ÊÔË«ÖØÀÕË÷¡£Æä¹¥»÷Ö¸±êº¸ÇÖÆ×÷ÉÌ¡¢½ðÈÚ»ú¹¹¡¢Ò½ÁƱ£½¡¼°µ±¾Ö»ú¹¹£¬£¬ÒòÕâЩÐÐÒµ´æ´¢Ãô¸ÐÐÅÏ¢Ò×ÊÜÊý¾Ýй¶ӰÏì¡£
https://cybernews.com/news/club-atletico-river-plate-football-club-qilin-ransomware/
3. ·¨¹úÓÊÕþ¾ÖÊ¥µ®Ç°Ï¦ÔâDDoS¹¥»÷Ö¶àÒµÎṉ̃»¾
12ÔÂ23ÈÕ£¬£¬Ê¥µ®Ç°Ï¦£¬£¬·¨¹ú¹ú¶ÈÓÊÕþ¾Ö£¨La Poste£©Ôâ·ê´ó¹æÄ£DDoS¹¥»÷£¬£¬µ¼ÖÂÆäÍøÕ¾¡¢Òƶ¯ÀûÓü°Ö÷ÌâÊý×Öϵͳ̱»¾£¬£¬°ü¹üÅäËÍ·þÎñÏÔÖø·Å»º£¬£¬²¿ÃÅÔÚÏßÒµÎñÖжϡ£¸Ã¾ÖÔÚÖÜÒ»ÉêÃ÷ÖÐÈ·ÈÏ£¬£¬Õâ´ÎÍøÂç¹¥»÷Ôì³ÉϵͳÐÔ¹ÊÕÏ£¬£¬µ«Ç¿µ÷ĿǰÎÞÖ¤¾ÝÏÔʾÓû§Êý¾Ýй¶£¬£¬½öÈÏ¿ÉÓÊÕþ¼°ÒøÐÐÒµÎñ£¨Èç°ü¹üÅäËÍ¡¢ÒøÐÐתÕË£©Êܲ¨¼°¡£ÆìÏ·¨¹úÓÊÕþÒøÐУ¨La Banque Postale£©Í¬²½ÊÜÓ°Ï죬£¬Óû§·´Ó³ÍøÉÏÒøÐм°Òƶ¯ÀûÓýӼûÄÑÌ⣬£¬²»ÍâÒøÐз½Ãæ³ÎÇ壬£¬ÊµÌåÍøµãPOS»úË¢¿¨¡¢ATMÈ¡¿î¼°¶ÌÐÅÑéÖ¤µÄÔÚÏßÖ§¸¶Ö°ÄÜÈÔÕý³£ÔË×÷£¬£¬¹ñ̨ҵÎñÒà³ÖÐøÊ¢¿ª¡£Õâ´Î¹¥»÷Ç¡·êÓÊÕþÒµÎñ¶¥·åÆÚ£¬£¬Òý·¢Óû§Ç¿ÁÒ²»Âú¡£É罻ýÌåÉÏ£¬£¬´óÁ¿ÃñÖÚ±§Ô¹ÅäËÍÑÓ³¤¿ÉÄܵ¼ÖÂÊ¥µ®°ü¹üÎÞ·¨ÊµÊ±Í¶µÝ£¬£¬·¨¹úýÌåÒ౨µÀ²¿ÃÅÓʾÖÒòϵͳ¹ÊÕϻؾøÓû§¼Ä¼þ»òÈ¡¼þÒªÇó¡£Ö»¹Ü²¿ÃÅÓʾÖÒÑËõ¼õÔËÓª¹æÄ££¬£¬µ«ÓÊÕþ¾ÖÇ¿µ÷¡°ÍŶÓȫԱ´øÍ·¼Ó¿ì·þÎñ¸´Ô¡±£¬£¬Óû§ÈÔ¿Éͨ¹ý¹ñ̨°ìÀíÓÊÕþ¼°ÒøÐÐÒµÎñ¡£
https://therecord.media/la-poste-france-ddos-disruption-days-before-christmas
4. ÂÞÂíÄáÑǹú¶ÈË®Îñ»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷
12ÔÂ22ÈÕ£¬£¬ÂÞÂíÄáÑǹú¶ÈË®ÎñÖÎÀí»ú¹¹ÓÚ½üÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬µ¼ÖÂÔ¼1000Ì¨ÍÆËã»úϵͳ̱»¾£¬£¬¹¤×÷Õ¾Óë·þÎñÆ÷ÎÞ·¨Ê¹Ó㬣¬µ«Ö÷ÌâË®Àû¼¼Êõ»ù´¡ÉèÊ©Èç´ó°Ó¡¢·ÀºéÉèʩδÊÜÓ°Ïì¡£Õâ´Î¹¥»÷ÆÈʹԱ¹¤ÉÕ»Ùµç×ÓÓʼþͨѶ£¬£¬×ª¶øÊ¹Óõ绰ºÍÎÞÏßµç½øÐÐÄÚ²¿Ðµ÷£¬£¬Í¹ÏÔÁËÍøÂç¹¥»÷¶ÔÈÕ³£ÔËÓªµÄ×ÌÈÅ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬¹¥»÷ÕßѡȡÁËÓ봫ͳÀÕË÷Èí¼þ·ÖÆçµÄ¼¼Êõ¼¿Á©£¬£¬ÀûÓúϷ¨Windows¹¤¾ßBitLockerÖ´ÐмÓÃÜÀÕË÷¡£ÕâÖÖ±»³ÆÎª¡°LOLBins¡±£¨Living-off-the-Land Binaries£©µÄÕ½Êõ£¬£¬Í¨¹ýŲÓÃϵͳ×Ô´ø¹¤¾ß£¨ÈçBitLocker£©ÔÚÊܺ¦ÕßÍøÂçÖкáÏòÒÆ¶¯²¢¶ã±Ü°²È«¼ì²â£¬£¬Ôö³¤ÁË·ÀÓùÄѶȡ£¿£¿£¿¨°Í˹»ù³¢ÊÔÊÒ2024Äê×êÑÐÏÔʾ£¬£¬Ä«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô¼µ©µÄ¸ÖÌúÆóÒµ¡¢ÒßÃçÖÆ×÷É̼°µ±¾Ö»ú¹¹ÔøÔâ·êÀàËÆ¹¥»÷£»£»£»ÍøÂ簲ȫ¹«Ë¾BitdefenderÒ²Ö¸³ö£¬£¬¡°ShrinkLocker¡±¶ñÒâÈí¼þÕý±»¶à¸öÍþв×éÖ¯ÓÃÓÚÕë¶ÔÀϾÉWindowsϵͳµÄµ¥Ò»¹¥»÷£¬£¬Í¨¹ý¾ç±¾»¯²Ù×÷ºÏ·¨¹¤¾ßʵÏÖÀÕË÷Ö÷ÕÅ¡£
https://therecord.media/romania-national-water-agency-ransomware-attack
5. ÈÕ²úÆû³µÏݺìñÊý¾Ýй¶·çÀË£¬£¬2.1Íò¿Í»§ÐÅÏ¢ÔâÇÔ
12ÔÂ22ÈÕ£¬£¬ÈÕ²úÆû³µÓÐÏÞ¹«Ë¾½üÈÕ֤ʵ£¬£¬ÒòÃÀ¹úÆóÒµÈí¼þ¹«Ë¾ºìñ£¨Red Hat£©9Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñ£¬£¬ÆäÔ¼21,000ÃûÈÕ±¾¸£¸ÔµØÓò¿Í»§ÐÅÏ¢±»ÇÔÈ¡£¬£¬Éæ¼°È«Ãû¡¢ÎïÀíµØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¼°ÏúÊÛÔËÓªÊý¾Ý£¬£¬µ«ÐÅÓþ¿¨µÈ²ÆÕþÐÅϢδÊܲ¨¼°¡£Õâ´ÎÊÂÎñÔ´ÓÚºìñ¹«Ë¾Êý¾Ý·þÎñÆ÷Ôâδ¾ÊÚȨ½Ó¼û£¬£¬µ¼ÖÂÈÕ²úίÍÐÆä¿ª·¢µÄ¿Í»§ÖÎÀíϵͳÊý¾Ýй¶£¬£¬³ÉΪÈÕ²ú½ñÄêµÚ¶þÆðÍøÂ簲ȫÊÂÎñ£¬£¬´Ëǰ8Ô£¬£¬ÆäÉè¼Æ×Ó¹«Ë¾Creative Box Inc.ÔøÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷¡£º£º£ºìñÊý¾Ýй¶ÊÂÎñÓ°ÏìÉîÔ¶£¬£¬Éæ¼°28,000¸ö˽ÓÐGitLab´æ´¢¿â£¬£¬Ãô¸ÐÊý¾Ý´ïÊý°ÙGB¡£º£º£ºÚ¿Í×éÖ¯Crimson Collective×î³õÐû³Æ¶Ô´ËÕÆ¹Ü£¬£¬ËæºóShinyHuntersҲȾָÆäÖУ¬£¬ÔÚÀÕË÷ƽ̨Íйܱ»µÁÊý¾ÝÑù±¾ÒÔʩѹÊܺ¦¹«Ë¾¡£ÈÕ²úÇ¿µ÷£¬£¬±»ÈëÇֵĺìñ»·¾³Î´´æ´¢ÆäËûÊý¾Ý£¬£¬ÇÒÎÞÖ¤¾ÝÅúעй¶ÐÅÏ¢Òѱ»ÀÄÓ㬣¬µ«ÒÑÒý·¢¿Í»§¶ÔÒþÖÔ°²È«µÄÓÇÓô¡£
https://www.bleepingcomputer.com/news/security/nissan-says-thousands-of-customers-exposed-in-red-hat-breach/
6. ÒÁÀÊAPT×éÖ¯InfyЯеĶñÒâÈí¼þ»î¶¯ÖØÏÖ
12ÔÂ21ÈÕ£¬£¬Íþвµý±¨»ú¹¹SafeBreachÅû¶£¬£¬ÒÁÀÊInfy£¨ÓÖ³ÆPrince of Persia£©APT×éÖ¯½üÆÚÖØÆô»îÔ¾£¬£¬ÕâÊǸÃ×éÖ¯×Ô2020ÄêÕë¶ÔÈðµä¡¢ºÉÀ¼¡¢ÍÁ¶úÆäÖ¸±êºó³õ´Î´ó¹æÄ£ÏÖÉí¡£×÷ΪÏÖ´æ×î¹ÅÀϵÄAPTÖ®Ò»£¬£¬Infy»î¶¯¿É×·ÒäÖÁ2004Äê12Ô£¬£¬ÆäÒñ±ÎÐԳ־øßÓÚCharming KittenµÈ³ÛÃûÒÁÀÊ×éÖ¯£¬£¬µ«Õâ´ÎÐж¯Õ¹Ê¾¸ü¸´ÔӵĹ¥»÷Á´Éý¼¶¡£×îй¥»÷ÖУ¬£¬InfyʹÓÃÉý¼¶°æFoudreÏÂÔØÆ÷ÓëTonnerreÖ²È뷨ʽ£¬£¬Í¨¹ý´¹µöÓʼþ´«²¼¡£¹¥»÷Á´´Ó´«Í³ExcelºêתÏòÎĵµÄÚǶ¿ÉÖ´ÐÐÎļþ£¬£¬½áºÏÓòÃûÌìÉúËã·¨£¨DGA£©Ç¿»¯C2·þÎñÆ÷ÈÍÐÔ¡£ÓÈΪֵÍ×ÌùÐĵÄÊÇ£¬£¬¶ñÒâÈí¼þͨ¹ýRSAÊðÃûÑéÖ¤C2ÓòÃûÕæÊµÐÔ¡£2025Äê9Ô¼ì²âTonnerre×îа汾ÐÂÔöTelegramȺ×éͨѶ»úÖÆ£¬£¬ÓйØÅäÖô洢ÔÚC2·þÎñÆ÷¡°t¡±Ä¿Â¼µÄtga.adrÎļþÖУ¬£¬½ö¶ÔÌØ¶¨Êܺ¦ÕßGUID´¥·¢ÏÂÔØ¡£´ËÍ⣬£¬C2·þÎñÆ÷´æÔÚδ֪Óô¦µÄ¡°download¡±Ä¿Â¼£¬£¬´§Ä¦ÓÃÓÚ¶ñÒâÈí¼þÉý¼¶¡£
https://thehackernews.com/2025/12/iranian-infy-apt-resurfaces-with-new.html


¾©¹«Íø°²±¸11010802024551ºÅ