ÃÅÂÞ´óѧ32ÍòÈËÊý¾Ýй¶ÊÂÎñ
°ä²¼¹¦·ò 2026-01-161. ÃÅÂÞ´óѧ32ÍòÈËÊý¾Ýй¶ÊÂÎñ
1ÔÂ14ÈÕ£¬£¬ÃÀ¹úÃÅÂÞ´óѧ2024Äê12ÔÂ9ÈÕÖÁ23ÈÕÔâ·êÑÏÖØÍøÂç¹¥»÷£¬£¬ÍþвÐÐΪÕßÈëÇÖÆäϵͳ£¬£¬ÇÔÈ¡³¬¹ý32ÍòÈ˵ÄСÎÒ¡¢¡¢¡¢²ÆÕþ¼°½¡¿µÐÅÏ¢¡£¡£¸ÃУÔÚ2025Äê9Ô¾ÎļþÉó²éÈ·ÈÏ£¬£¬ÊÜÓ°ÏìÕßÉæ¼°µ±Ç°¼°Íù½ìѧÉú¡¢¡¢¡¢½ÌÈËÔ±¹¤µÈ£¬£¬Ð¹Â¶Êý¾Ýº¸ÇÐÕÃû¡¢¡¢¡¢µ®ÉúÈÕÆÚ¡¢¡¢¡¢Éç»á±£ÏÕºÅÂë¡¢¡¢¡¢»¤ÕÕºÅÂë¡¢¡¢¡¢Ò½ÁÆÐÅÏ¢¡¢¡¢¡¢µç×ÓÕË»§ÃÜÂë¼°²ÆÕþÕË»§ÏêÇéµÈÃô¸ÐÄÚÈÝ¡£¡£×÷ΪӦ¶Ô´ëÊ©£¬£¬Ñ§ÌÃ×Ô2026Äê1ÔÂ2ÈÕÆðÏòÊÜÓ°ÏìÓû§ÓʼÄ֪ͨ£¬£¬ÌáÐÑ¼à¿ØÐÅÓþ»ã±¨¼°ÕË»§Òì³££¬£¬²¢ÌṩCyberScoutÌṩµÄΪÆÚÒ»ÄêÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ¡£¡£ÃÅÂÞ´óѧº¹Çà¿É×·ÒäÖÁ1933Ä꣬£¬ÏÖ·¢Õ¹ÎªÕ¼ÓÐŦԼ²¼ÀÊ¿Ë˹¡¢¡¢¡¢ÐÂÂÞл¶û¼°Ê¥Â¬Î÷ÑÇÈý´óÐ£ÇøµÄ˽Á¢´óѧ£¬£¬ÔÚУÉú³¬9000ÈË¡£¡£ÃÅÂÞ´óѧËäÆô¶¯ÐÅÓþ¼à¿Ø·þÎñ£¬£¬µ«¹Ø¼üÐÅÏ¢Èç¹¥»÷ÕßÉí·Ý¡¢¡¢¡¢¾ßÌå·ì϶ÀàÐÍÈÔδÅû¶£¬£¬Òý·¢¹«¼Ò¶ÔͨÃ÷¶ÈµÄÖÊÒÉ¡£¡£
https://www.bleepingcomputer.com/news/security/monroe-university-says-2024-data-breach-affects-320-000-people/
2. ÍøÂç×ï·¸ÇÔÈ¡FacebookÓû§Æ¾Ö¤Ð¼¿Á©
1ÔÂ13ÈÕ£¬£¬ÍøÂç·¸×ï·Ö×ÓÕý´óÁ¿Ñ¡È¡¡°ä¯ÀÀÆ÷Ì×ä¯ÀÀÆ÷¡±¼¼Êõ¶ÔFacebookÓû§ÌáÒéÒñ±Î¹¥»÷£¬£¬Ì°Í¼ÇÔÈ¡ÆäµÇ¼ƾ֤²¢Ö´ÐкóÐøÚ²Æ¡£¡£¾ÝTrellixÍøÂ簲ȫÍŶÓ×êÑУ¬£¬´ËÀ๥»÷ͨ¹ý´¹µöÓʼþ¼¤Ôö£¬£¬Óʼþ³£¼Ù×°³ÉÂÉʦÊÂÎñËùÖҸ桢¡¢¡¢ÕË»§°²È«Í¨ÖªµÈ£¬£¬ÀûÓÃÓû§¶Ô°æÈ¨ÇÖȨË÷Åâ¡¢¡¢¡¢Î´ÊÚȨµÇ¼ÌáÐÑ»òÕË»§¹Ø±ÕÖÒ¸æµÄ·¢¼±ÉúÀí£¬£¬ÓÕʹÆäµã»÷¼Ù×°³ÉFacebook¹Ù·½Á´½ÓµÄÐéα¶ÌÁ´½Ó¡£¡£¹¥»÷µÄÖ÷ÌâÔÚÓÚ¡°ä¯ÀÀÆ÷Ì×ä¯ÀÀÆ÷¡±µ¯´°µÄÕæÇÐÐÔ£º£º¹¥»÷ÕßÔÚÊܺ¦Õßä¯ÀÀÆ÷ÄÚ´´½¨×Ô½ç˵ÐéαµÇ¼´°¿Ú£¬£¬¸Ã´°¿ÚÔ̺¬Ó²±àÂëµÄÕæÊµFacebookµÇÂ¼Ò³ÃæURL£¬£¬²¢Ô¤ÏȲ¿ÊðÐéαÑéÖ¤Âë´°¿Ú£¬£¬Ê¹Õû¸öÁ÷³ÌÓëÓû§ÊìϤµÄFacebookÈÏÖ¤½çÃæ¸ß¶ÈÒ»Ö£¬£¬ÊÓ¾õÉÏÄÑÒÔ¾õ²ìÒì³£¡£¡£¡£Êܺ¦ÕßÔÚ¡°ÉêÊö¡±Ò³ÃæÊ×Ïȱ»ÒªÇóÌîдÐÕÃû¡¢¡¢¡¢ÓÊÏä¡¢¡¢¡¢µç»°¡¢¡¢¡¢µ®ÉúÈÕÆÚµÈСÎÒÐÅÏ¢£¬£¬ËæºóÔÚµÚ¶þÒ³Ãæ¡°È·ÈÏ¡±ÃÜÂ룬£¬µ¼ÖÂÃô¸ÐÐÅÏ¢¼°Æ¾Ö¤±»ÇÔÈ¡¡£¡£´ËÀ๥»÷µÄ¶¯»úÔ̺¬½Ù³ÖÕË»§¡¢¡¢¡¢ÇÔȡСÎÒÊý¾Ý¡¢¡¢¡¢Ö´ÐÐÉí·ÝڲƻòÏòÓû§ÁªÏµÈË´«²¼Ú¿Æ¡£¡£
https://www.infosecurity-magazine.com/news/phishing-scams-exploit-browser/
3. ΢Èí½áºÏ¶à¹úµ·»ÙRedVDSÍøÂç·¸×ïÆ½Ì¨
1ÔÂ15ÈÕ£¬£¬Î¢Èí½üÈÕ°ä·¢³É¹¦Ì±»¾È«ÇòÍøÂç·¸×ïÆ½Ì¨RedVDS£¬£¬¸Ãƽ̨×Ô2025Äê3ÔÂÒÔÀ´½öÔÚÃÀ¹ú¾ÍÔì³É³¬4000ÍòÃÀÔªËðʧ¡£¡£×÷Ϊ"ÍøÂç·¸×ï¼´·þÎñ"£¨CaaS£©µäÐÍ´ú±í£¬£¬RedVDSͨ¹ýredvds[.]comµÈÓòÃûÏòStorm-0259µÈ·¸×OÍÅÌṩÿÔ½öÐè24ÃÀÔªµÄÐé¹¹Windows·þÎñÆ÷£¬£¬Ö§³ÖÎÞÏÞ¶ÈÖÎÀíÔ±½ÚÖÆ£¬£¬Ê¹Ú²ÆÐÐΪʵÏֵͳɱ¾¡¢¡¢¡¢¹æÄ£»£»£»¯ÇÒÄÑÒÔ×·×Ù¡£¡£ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëµÂ¹úµ±¾Ö¹²Í¬Ï£¬£¬Î¢ÈíÔÚÃÀ¹ú¡¢¡¢¡¢Ó¢¹úÌáÆðÃñÊÂËßËÏ£¬£¬²é·âÆä¶ñÒâ»ù´¡ÉèÊ©²¢ÏÂÏßÊг¡ÃÅ»§¡£¡£µ÷²éÏÔʾ£¬£¬RedVDS×Ô2019ÄêÔËÓªÖÁ½ñ£¬£¬ËùÓÐÐé¹¹»ú¾ùʹÓÿË¡µÄWindows Server 2022¾µÏñ£¬£¬¹²ÏíÍÆËã»úÃû³Æ"WIN-BUNS25TD77J"µÄ¼¼ÊõÌØµã³ÉΪ׷×ٹؼü¡£¡£Æä·þÎñÆ÷×âÓÃ×ÔÃÀ¡¢¡¢¡¢Ó¢¡¢¡¢¡¢·¨µÈÁù¹úµÚÈý·½ÍйÜÉÌ£¬£¬Ê¹·¸×ï·Ö×ÓÄÜ»ñȡָ±êµØÓòIPµØÖ·£¬£¬ÇáËÉÈÆ¹ýµØÀí°²È«¹ýÂË¡£¡£¹¥»÷Õß½áºÏAI¹¤¾ßÌìÉú¸ß·ÂÕæ´¹µöÓʼþ£¬£¬ÉõÖÁʹÓû»Á³¡¢¡¢¡¢ÓïÒô¿Ë¡¼ÙÒâ¿ÉÐÅ×éÖ¯¡£¡£Êý¾ÝÏÔʾ£¬£¬½ÚÖÆ2600̨Ðé¹¹»úµÄ·¸×ï·Ö×ÓÈÕ¾ù·¢ËͰÙÍò·â´¹µöÓʼþ£¬£¬ËĸöÔÂÄÚ¹¥ÆÆ½ü20Íò΢ÈíÕË»§£¬£¬È«Çò³¬19.1Íò×éÖ¯Êܲ¨¼°¡£¡£
https://www.bleepingcomputer.com/news/security/microsoft-seizes-servers-disrupts-massive-redvds-cybercrime-platform/
4. ²¨À¼´ì°ÜÕë¶ÔÄÜÔ´»ù´¡ÉèÊ©µÄÑÏÖØÍøÂç¹¥»÷
1ÔÂ15ÈÕ£¬£¬²¨À¼µ±¾Ö°ä·¢³É¹¦´ì°Üһ·Õë¶ÔÆäÄÜÔ´»ù´¡ÉèÊ©µÄÖØ´óÍøÂç¹¥»÷£¬£¬³ÆÕâÊǽüÄêÀ´¶Ô¸Ã¹úÄÜԴϵͳ×îÑÏÖØµÄÍþв¡£¡£¾ÝÄÜÔ´²¿³¤Ã×ÎÖʲ¡¤ÄªµÙ¿¨Åû¶£¬£¬Õâ´Î¹¥»÷²úÉúÓÚ2025Äê12Ôµף¬£¬ºÚ¿Í½«Ö¸±êËø¶¨ÔÚ²¨À¼È«¹ú´ó²¿ÃŵØÓò¿ÉÔÙÉúÄÜÔ´ÉèÊ©£¨Ô̺¬Ì«ÑôÄÜ·¢µç³¡Î¢·çÁ¦ÎÐÂÖ»ú£©ÓëµçÁ¦ÅäµçÔËÓªÉÌÖ®¼äµÄͨѶϵͳ£¬£¬ÊÔͼͨ¹ý·ÛË鹨¼üͨѶÁ´Â·Òý·¢´ó¹æÄ£Í£µç¡£¡£Êý×Ö»¯ÊÂÎñ²¿³¤½üÈÕʲÍзò¡¤¼Ó¶û¿Æ·ò˹»ùÔÚ1ÔÂ13ÈÕµÄÐÂÎŰ䲼»áÉÏÇ¿µ÷£¬£¬¸ÃÊÂÎñ¡°¼«¶È¿¿½üµ¼ÖÂÈ«¹úÐÔÍ£µç¡±£¬£¬ÇÒ¹¥»÷³öÏÖ¡°Ðµ÷·ÛËéÐж¯µÄÏÔÖøÌØµã¡±¡£¡£Ëû½øÒ»²½Ö¸³ö£¬£¬¹¥»÷µÄ¹æÄ£¡£¡¢¡¢¡¢ÈëÇÖõè¾¶¼°Ä»ºó²ß¶¯¾ùÅú×¢ÕâÊÇÒ»´Î¡°ÐîÒâ¶Â½Ø²¨À¼¹«ÃñµçÁ¦¹©¸øµÄ·ÛËéÐÐΪ¡±£¬£¬²¢Ö±Ö¸¶íÂÞ˹ΪĻºóºÚÊÖ¡£¡£ÓëÒÔÍùÕë¶Ô´óÐÍ·¢µç³§»òÊäµçÍøÂçµÄÍøÂç¹¥»÷·ÖÆç£¬£¬±¾´ÎÊÂÎñ³õ´Îͬʱ¶Ô×¼¶à¸öÉ¢²¼Ê½Ð¡ÐÍÄÜÔ´ÉèÊ©£¬£¬ÕâÖÖÐÂÐ͹¥»÷ģʽÒý·¢²¨À¼¹Ù·½¸ß¶È¾¯Ìè¡£¡£
https://therecord.media/poland-cyberattack-grid-russia
5. ÕùÒéÍøÕ¾¡°ICEÃûµ¥¡±ÔâDDoS¹¥»÷̱»¾
1ÔÂ15ÈÕ£¬£¬ÃÀ¹úºÓɽ°²È«ÊýÊý¾Ýй¶ÊÂÎñÑÜÉú³öµÄÕùÒéÐÔÍøÕ¾¡°ICEÃûµ¥¡±Òò³ÖÐøDDoS¹¥»÷±»ÆÈÏÂÏß¡£¡£¸ÃÍøÕ¾ÓÉÊ×´´È˶àÃ×Äá¿Ë¡¤Ë¹½ðÄÉÓÚ½üÈÕй©£¬£¬×ÔÖܶþÍí¼äÆðÔâ·ê¡°ÓƾÃÇÒ¸´ÔÓ¡±µÄÉ¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷£¬£¬µ¼Ö·þÎñÆ÷̱»¾£¬£¬Óû§ÎÞ·¨²éÎÊÃÀ¹úÒÆÃñºÍº£¹Ø·¨Âɾ֣¨ICE£©¼°±ßÚïѲÂß¶Ó4500Ãû̽ԱµÄÉí·ÝÐÅÏ¢¡£¡£Ë¹½ðÄɰµÊ¾£¬£¬¹¥»÷Á÷Á¿ÒÉËÆÀ´×Ô¶íÂÞ˹½©Ê¬ÍøÂçÅ©³¡£¬£¬µ«Í¨¹ý´úÀíIPÄÑÒÔ×·×ÙÕæÊµÆðÔ´¡£¡£ËûÇ¿µ÷£¬£¬´ËÀ೤¹¦·ò¡¢¡¢¡¢¸ß¸´ÔӶȵĹ¥»÷ÐèרҵÍŶӲ߶¯¡£¡£Ä¿Ç°ÍŶÓÕý³¢ÊÔ¸ü»»·þÎñÆ÷¸´ÔÍøÕ¾£¬£¬µ«ÈÏ¿ÉÆä½«³ÖÐø³ÉΪ¹¥»÷Ö¸±ê¡£¡£¸ÃÍøÕ¾³ÉÁ¢ÓÚDHSÄÚ²¿¾Ù±¨ÈËй¶Êý¾ÝÖ®ºó£¬£¬Ô̺¬Ì½Ô±µÄÐÕÃû¡¢¡¢¡¢¹¤×÷ÓÊÏä¡¢¡¢¡¢µç»°¡¢¡¢¡¢Ö°Î»Í·Ïμ°¼òÀúʽ²¼¾°ÐÅÏ¢¡£¡£Èô¸´ÔÉÏÏߣ¬£¬ÕâЩÊý¾Ý½«ÓëÏÖÓÐ2000ÃûÁª°îÒÆÃñ¹ÙÔ±ÐÅÏ¢¿â¹é²¢¡£¡£
https://www.infosecurity-magazine.com/news/ice-agent-doxxing-site-ddosed/
6. Gootloader¶ñÒâÈí¼þÉý¼¶·´¼ì²â¼¼Êõ
1ÔÂ15ÈÕ£¬£¬Gootloader¶ñÒâÈí¼þ×Ô2020ÄêÆð³ÖÐø»îÔ¾£¬£¬±»ÓÃÓÚÀÕË÷Èí¼þ²¿ÊðµÈÍøÂç·¸×ï»î¶¯¡£¡£½üÆÚ£¬£¬×êÑÐÈËÔ±·¢ÏÖÆäͨ¹ýÏνÓ500ÖÁ1000¸ö»ûÐÎZIP´æµµÊµÏÖ·´¼ì²âÉý¼¶£¬£¬ÕâÖֽṹµ¼ÖÂÒÀÀµ7-Zip¡¢¡¢¡¢WinRARµÈ¹¤¾ßµÄ·ÖÎö·¨Ê½±ÀÀ££¬£¬¶øWindowsĬÈϽâѹ¹¤¾ßÈÔ¿É´¦Öᣡ£¸Ã¶ñÒâÈí¼þµÄÖ÷ÌâÊÇÒ»¸ö¹éµµµÄJScriptÎļþ£¬£¬Í¨¹ýWindows Script Host£¨WScript£©Ö´ÐУ¬£¬²¢ÀûÓÃÏòÆô¶¯Îļþ¼ÐÔö³¤¿ì½Ý·½Ê½£¨.LNK£©ÊµÏÖÓÆ¾ÃÐÔ£¬£¬ÓÐÐ§ÔØºÉÔÚϵͳÆô¶¯Ê±Í¨¹ýNTFS¶ÌÃû³Æ´¥·¢CScript£¬£¬½ø¶øÌìÉúPowerShell¹ý³Ì¡£¡£ÎªÌӱܼì²â£¬£¬ÍþвÐÐΪÕßÖ´ÐÐÁ˶àÖØ»ìºÏ¼¼Êõ£º£ºÀûÓýâÎöÆ÷´ÓÎļþĩβ¶ÁÈ¡µÄ¸öÐÔÏνӶà¸öZIPÎļþ£»£»£»½Ø¶ÏÖÐÑëĿ¼ʵÏÖ·û£¨EOCD£©¶ÌȱÁ½¸ö±ØÐë×Ö½Ú£¬£¬µ¼Ö´óÎÞÊý¹¤¾ßÎÞ·¨½âÎö£»£»£»Ëæ»ú»¯´ÅÅ̱àºÅ×ֶηÂÕÕ²»´æÔڵĶà´ÅÅ̹鵵£»£»£»ÖÆ×÷±¾µØÎļþÍ·ÓëÖÐÑëĿ¼Ìõ¿î¼äµÄÔªÊý¾Ý²»Æ¥Å䣻£»£»ÎªÃ¿´ÎÏÂÔØÌìÉúΨһZIP/JScriptÑù±¾¶ã±Ü¾²Ì¬¼ì²â£»£»£»½«ZIP×÷ΪXOR±àÂëµÄblob´«µÝ£¬£¬ÔÚ¿Í»§¶Ë½âÂë²¢×·¼ÓÖÁËùÐè¾ÞϸÒÔ¶ã±ÜÍøÂç¼ì²â¡£¡£
https://www.bleepingcomputer.com/news/security/gootloader-now-uses-1-000-part-zip-archives-for-stealthy-delivery/


¾©¹«Íø°²±¸11010802024551ºÅ