¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷

°ä²¼¹¦·ò 2025-12-08

1. ¡°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ïÕë¶Ô¶«ÄÏÑÇÌáÒé¹¥»÷


12ÔÂ4ÈÕ £¬ÒÔIJÀûΪÖ÷Õŵġ°»Æ½ð¹¤³§¡±ÍøÂç·¸×ïÍÅ»ï½üÆÚÒÔ¼Ù×°µ±¾Ö·þÎñ»ú¹¹µÄ·½Ê½ £¬ÏòÓ¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹úºÍÔ½ÄϵÄÒÆ¶¯Óû§ÌáÒéÐÂÒ»ÂÖ¹¥»÷¡£¸ÃÍÅ»ï×Ô2024Äê10ÔÂÆð £¬Í¨¹ý´«²¼Ö²È밲׿¶ñÒâÈí¼þµÄ´Û¸Ä°æÒøÐÐÀûÓÃÖ´Ðй¥»÷ £¬×îÔçÔÚÌ©¹ú±»·¢ÏÖ £¬ºóÊæÕ¹ÖÁÔ½ÄϺÍÓ¡Äá¡£¾ÝÐÂ¼ÓÆÂIB¼¯Íż¼Êõ»ã±¨ £¬½öÓ¡Äá¾ÍÔì³É½ü2200ÆðÉ豸ϰȾ £¬×ÜϰȾ°¸Àý³¬1.1ÍòÆð £¬ÆäÖÐ63%µÄ´Û¸ÄÀûÓÃÕë¶ÔÓ¡ÄáÊг¡¡£¹¥»÷Á÷³Ì¼Ù×°³Éµ±¾Ö»ú¹¹»ò³ÛÃûÆ·ÅÆ £¬Í¨¹ýµç»°Ú¿Æ­ÓÕµ¼Óû§µã»÷ZaloµÈͨѶÈí¼þÖеÄÁ´½Ó £¬×°ÖöñÒâÈí¼þ¡£¶ñÒⷨʽͨ¹ý×¢Èë¶ñÒâ´úÂëµ½Õý¹æÒøÐÐÀûÓà £¬±£ÁôÕý³£Ö°ÄÜÒÔÈÆ¹ý°²È«·À»¤ £¬Ö÷±êÌâ±êÊÇÔ¶³Ì²Ù¿ØÉ豸¡£×êÑÐÈËÔ±·¢ÏÖÈýÀà½Ù³Ôì÷×é¼þ¡ª¡ª¡°¸¥Èð½Ù³Ôì÷¡±¡°Ìì¿Õ½Ù³Ôì÷¡±¡°Åɶ÷½Ù³Ôì÷¡± £¬¿ÉʵÏÖ°µ²ØÀûÓᢶã±Ü¼ì²â¡¢Î±ÔìÊðÃû¡¢ÇÔÈ¡Óà¶îÐÅÏ¢µÈÖ°ÄÜ¡£¸ÃÍŻﻹ¿ª·¢ÁË¡°¾ÞÐÍ»¨¡±²âÊÔ°æ¶ñÒâÈí¼þ £¬Ö§³Öʵʱ´«ÊäÉ豸»­Ãæ¡¢¼üÅ̼ͼ¡¢µ¯³öÐéα½çÃæÇÔÊØÐÅÏ¢ £¬²¢ÔÚ¿ª·¢¶þάÂëɨÃèÖ°ÄÜÒÔÌáȡԽÄÏÉí·ÝÖ¤ÐÅÏ¢¡£


https://thehackernews.com/2025/12/goldfactory-hits-southeast-asia-with.html


2. Ó¡¶ÈÆóÒµÔâ¼Ùװ˰Îñ²¿ÃÅ´¹µö¹¥»÷


12ÔÂ4ÈÕ £¬½üÆÚ £¬Ò»³¡Õë¶ÔÓ¡¶ÈÆóÒµµÄ´ó¹æÄ£´¹µö¹¥»÷ÇÄÈ»·¢Õ¹¡£¹¥»÷Õß¼Ù×°³ÉÓ¡¶ÈËùµÃ˰²¿ÃÅ £¬Í¨¹ý¸ß¶È·ÂÕæÈ·µ±¾Ö¹«º¯Ä£°å¼°Ó¡µØÓïÓëÓ¢ÓïË«ÓïͨѶ £¬ÒýÓá¶ËùµÃ˰·¨¡·Ìõ¿îÔì×÷ºÏ·¨ÐÔÓë½ôÆÈ¸Ð £¬»Ñ³ÆÊÕ¼þÈË´æÔÚ˰ÎñÎ¥¹æÐÐΪ £¬ÒªÇó72Ó×ʱÄÚÌá½»Îļþ £¬ÓÕÆ­Óû§´ò¿ª¶ñÒ⸽¼þ¡£Õâ´Î¹¥»÷ѡȡÁ½½×¶Î¶ñÒâÈí¼þÁ´£º³õÆÚÒÔÃÜÂë± £»¤µÄZIPÎļþ´îÔØshellcode¼ÓÔØÆ÷ £¬ºóÐø±äÌåÀûÓùȸèÎĵµÁ´½Ó½»¸¶¶þ¼¶ÔØºÉ £¬×îÖÕͶ·ÅAsyncRATÔ¶³Ì½ÚÔìľÂí £¬ÊµÏÔìÁÄ»¹²Ïí¡¢Îļþ´«Êä¼°Ô¶³ÌºÅÁîÖ´ÐС£¹¥»÷Ö¸±êËø¶¨Ö¤È¯¹«Ë¾¡¢½ðÈÚ»ú¹¹¼°·ÇÒøÐнðÈÚ¹«Ë¾ £¬ÒòÕâЩ»ú¹¹Ð趨ÆÚÓëµ±²¿ÃÅÃÅ»¥»»¼à¹ÜÎļþ £¬³ÉΪ³ÁµãÖ¸±ê¡£Raven°²È«ÍŶÓͨ¹ý¼ø±ð¹¥»÷¼Ü¹¹ÖеĶà²ãì¶Üµã £¬³É¹¦·¢ÏÖ²¢×èÖ¹ÁËÕâÒ»ÁãÈÕ¹¥»÷ £¬Ô¤·ÀÖ¸±ê»ú¹¹´ó¹æÄ£Ï°È¾¡£ÓʼþÔ´×ԺϷ¨Ãâ·ÑÓÊÏäÕ˺Š£¬Í¨¹ýSPF¡¢DKIM¼°DMARCÈÏÖ¤ £¬Èƹý´«Í³Óʼþ¹ýÂËÆ÷¡£ÃÜÂë± £»¤¸½¼þÔ¤·À´«ÊäÖб»É±¶¾Èí¼þɨÃè £¬½âѹºó³öÏֵġ°NeededDocuments¡±¿ÉÖ´ÐÐÎļþÄÚÖÃshellcode £¬shellcodeÓëAsyncRAT½ÚÔì·þÎñÆ÷³ÉÁ¢Í¨Ñ¶¡£


https://cybersecuritynews.com/new-phishing-attack-mimic-as-income-tax-department/


3. React2Shell·ì϶´ó¹æÄ£ÀûÓà £¬³¬7.7ÍòIPÊÜÓ°Ïì


12ÔÂ6ÈÕ £¬React2ShellÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©Òý·¢È«Çò°²È«Î £»ú¡£¸Ã·ì϶ԴÓÚReact·þÎñÆ÷×é¼þ¶Ô¿Í»§¶Ë½ÚÔìÊý¾ÝµÄ²»°²È«·´ÐòÁл¯»úÔì £¬¹¥»÷Õß¿Éͨ¹ýµ¥¸öHTTPÒªÇó´¥·¢Î´¾­Éí·ÝÑéÖ¤µÄËÁÒâºÅÁîÖ´ÐÐ £¬Ó°ÏìËùÓÐʵÏÖReact·þÎñÆ÷×é¼þµÄ¿ò¼ÜÈçNext.js¡£Shadowserver»ã±¨ÏÔʾ £¬³¬77,000¸ö¶³öÔÚ»¥ÁªÍøµÄIPµØÖ·Ò×Êܹ¥»÷ £¬ÆäÖÐÔ¼23,700¸öλÓÚÃÀ¹ú £¬Éæ¼°¶à¸öÐÐÒµ¡£·ì϶Åû¶ºó £¬°²È«×êÑÐÔ±Maple3142°ä²¼¸ÅÏëÑéÖ¤ £¬Íƶ¯×Ô¶¯»¯É¨Ã蹤¾ßѸËÙÀ©É¢¡£GreyNoise¼à²âµ½ £¬´Óǰ24Ó×ʱÄÚÓÐ181¸ö·ÖÆçIP³¢ÊÔÀûÓø÷ì϶ £¬Á÷Á¿ÖØÒªÀ´×ÔºÉÀ¼¡¢Öйú¡¢ÃÀ¹ú¡¢Ïã¸ÛµÈµØÓò £¬¹¥»÷Õß¶àʹÓÃPowerShellºÅÁîÈç¡°40138*41979¡±²âÊÔ·ì϶ £¬È·ÈϺóͨ¹ýbase64±àÂëÏÂÔØµÚ¶þ½×¶Î¾ç±¾ £¬²¿ÊðCobalt StrikeÐűê»òSnowlight¡¢Vshell¶ñÒâÈí¼þ £¬ÊµÏÖÔ¶³Ì½Ó¼û¡¢ºáÏòÒÆ¶¯¼°Ãô¸ÐÐÅÏ¢ÇÔÈ¡¡£


https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable/


4. Barts Health NHS TrustÔâClopÀÕË÷Èí¼þ¹¥»÷


12ÔÂ5ÈÕ £¬Ó¢¹úBarts Health NHS Trust½üÈÕ°ä·¢ £¬ÆäOracle E-business SuiteÈí¼þ´æÔÚ·ì϶£¨CVE-2025-61882£© £¬±»ClopÀÕË÷Èí¼þÍÅ»ïÀûÓà £¬µ¼ÖÂÊý¾Ý¿âÖÐÓâÔ½ÊýÄêµÄ·¢Æ±Îļþ±»µÁ¡£Ð¹Â¶Êý¾ÝÉæ¼°ÔڰʹĽ¡È«Ò½Ôº½ÓÊÜÒ½Öλò·þÎñÈËÔ±µÄÈ«Ãû¡¢µØÖ· £¬²¿ÃÅǰ¹ÍÔ±¼°Òѹ«¿ªÊý¾ÝµÄ¹©¸øÉÌÐÅÏ¢ £¬ÒÔ¼°×Ô2024Äê4ÔÂÆð¸ÃÐÅÈÎÏòBarking¡¢HaveringºÍRedbridge´óѧҽԺNHSÐÅÈÎÌṩµÄ¹ÜÕÊ·þÎñÓйØÎļþ¡£ClopÒѽ«ÇÔÊØÐÅÏ¢ÉÏ´«ÖÁ°µÍøÐ¹Â¼ûÅ»§ £¬µ«BartsÇ¿µ÷ £¬Ä¿Ç°½öÏÞ¼ÓÃܰµÍøÓû§¿É½Ó¼ûѹËõÎļþ £¬Î´·¢ÏÖÊý¾ÝÔÚ¹«¿ª»¥ÁªÍø´«²¼¡£Õâ´Î¹¥»÷²úÉúÓÚ2025Äê8Ô £¬Ö±ÖÁ11ÔÂÎļþ±»°ä²¼ÖÁ°µÍøºó²ÅÈ·ÈÏÊý¾Ý·çÏÕ¡£BartsÒÑÏò¹ú¶ÈÍøÂ簲ȫÖÐÐÄ¡¢Â׶ؾ¯Ô±Ìü¼°ÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©´«µÝÊÂÎñ £¬²¢ÉêÇë¸ßµµ·¨ÔººÅÁî²»ÈÝÊý¾ÝʹÓᢰ䲼»ò·ÖÏí £¬µ«´ËÀà½ûÁîÏÖʵЧÁ¦ÓÐÏÞ¡£¸Ã»ú¹¹ÔËÓªÂ×¶ØÎå¼ÒÒ½Ôº £¬Ô̺¬»Ê¼ÒÂ×¶ØÒ½Ôº¡¢Ê¥°ÍÈûÂåçÑÒ½ÔºµÈ £¬Æäµç×Ó²¡Àú¼°ÁÙ´²ÏµÍ³Î´ÊÜÓ°Ïì £¬Ö÷ÌâIT»ù´¡ÉèÊ©°²È«ÐÔÈÔ»ñ×¢¶¨¡£


https://www.bleepingcomputer.com/news/security/barts-health-nhs-discloses-data-breach-after-oracle-zero-day-hack/


5. InotivÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂ9500ÓàÈËÊý¾Ýй¶


12ÔÂ5ÈÕ £¬ÃÀ¹úÔìÒ©¹«Ë¾Inotiv½üÈÕÅû¶ £¬2025Äê8ÔÂ5ÈÕÖÁ8ÈÕÆÚ¼ä £¬Æä²¿ÃÅÍøÂçºÍϵͳÔâÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÊý¾Ý¿â¼°ÄÚ²¿ÀûÓ÷¨Ê½Ì±»¾ £¬ÒµÎñÔËÓªÊÜÑϳÁÓ°Ïì¡£¸Ã¹«Ë¾ËæºóÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ìá½»ÎļþÈ·ÈÏ £¬ÒѸ´Ô­ÊÜÓ°Ïìϵͳ½Ó¼ûȨÏÞ £¬²¢ÕýÏò8ÔÂÊÂÎñÖÐÊý¾Ý±»µÁµÄ9,542ÃûÓ×ÎÒ·¢ËÍ֪ͨ £¬Éæ¼°ÏÖÈÎ/ǰÈÎÔ±¹¤¡¢¾ìÊô¼°ÓëÊÕ¹º¹«Ë¾Óйý»¥¶¯µÄÆäËûÈËÔ±¡£Õâ´Î¹¥»÷ÓÉ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÕƹÜ¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû³Æ £¬ÇÔÈ¡ÁËInotiv³¬16.2Íò¸öÎļþ £¬×ܼÆ176GB £¬µ«InotivδÃ÷È·¾ßÌåй¶Êý¾ÝÀàÐÍ £¬Ò²Î´È·ÈÏ÷è÷ëÉêÃ÷µÄÕæÊµÐÔ¡£Inotiv×ܲ¿Î»ÓÚÓ¡µÚ°²ÄÉÖÝ £¬ÊÇÒ»¼ÒÄêÊÕÈ볬5ÒÚÃÀÔªµÄºÏͬ×êÑлú¹¹ £¬×¨Ò»Ò©Î↑·¢¡¢°²È«ÐÔÆÀ¹À¼°»îÌ嶯Îï×êÑÐÄ£Ð͹¹½¨ £¬Õ¼ÓÐÔ¼2000ÃûÔ±¹¤¡£Ö»¹ÜÕâ´Î¹¥»÷䲨¼°Ö÷ÌâÁÙ´²ÏµÍ³ £¬µ«Êý¾Ýй¶·çÏÕÈÔÒý·¢¼à¹Ü¹Ø×¢¡£


https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-discloses-data-breach-after-ransomware-attack/


6. ¶à½×¶Î¹¥»÷»î¶¯¶Ô×¼Palo AltoÓëSonicWall°²È«É豸


12ÔÂ6ÈÕ £¬ÍþвÐÐΪÕß12ÔÂ2ÈÕÆðÀûÓõ¹úÍйܷþÎñÌṩÉÌ3xK GmbHÔËÓªµÄBGPÍøÂ磨AS200373£©ÏÂ7000Óà¸öIPµØÖ· £¬ÌáÒéÕë¶ÔPalo Alto GlobalProtect VPNÃÅ»§¼°SonicWall SonicOS API¶ËµãµÄ¶à½×¶Î¹¥»÷¡£GreyNoise»ã±¨ÏÔʾ £¬¹¥»÷ÕßÊ×ÏÈͨ¹ý±©Á¦ÆÆ½â³¢ÊԵǼPalo Alto·À»ðǽµÄÔ¶³Ì½Ó¼û×é¼þGlobalProtect £¬ËæºóתÏòɨÃèSonicOS API¶Ëµã¡ª¡ª¸Ã²Ù×÷ϵͳ½ÚÔìSonicWall·À»ðǽµÄÅäÖÃÓë¼à¿ØÖ°ÄÜ¡£Õâ´Î»î¶¯Óë11ÔÂÖÐÑ®¼Í¼µÄ230Íò´ÎGlobalProtectɨÃè´æÔÚ¹ØÁª£º62%µÄ¹¥»÷IPλÓڵ¹ú £¬¾ùʹÓÃÒ»ÑùTCP/JA4tÖ¸ÎÆ £¬ÇÒÔ´×Ô´ËǰÎÞ¶ñÒâ¼Í¼µÄËĸöASN¡£º¹ÇàɨÃè»î¶¯ÔøÌìÉú³¬900Íò´Î²»³ÉαÔìµÄHTTP»á»° £¬Ö¸±êÖ±Ö¸GlobalProtect¡£12ÔÂ3ÈÕ £¬Õë¶ÔSonicOS APIµÄɨÃèÖÐÔٴγöÏÖÒ»ÑùÈý¸ö¿Í»§Ö¸ÎÆ £¬GreyNoise¾Ý´ËÅж¨Á½½×¶Î¹¥»÷ͬԴ¡£Palo Alto Networks»ØÓ¦³Æ £¬¼ì²âµ½µÄɨÃè»î¶¯ÊôÓÚ¡°Æ¾Ö¤¹¥»÷¶ø·Ç·ì϶ÀûÓá± £¬ÆäÄÚ²¿Ò£²â¼°Cortex XSIAM·À»¤ÏµÍ³È·ÈÏδ¶Ô²úÆ··þÎñÔì³ÉÇÖº¦ £¬½¨Òé¿Í»§ÆôÓöà³É·ÖÈÏÖ¤£¨MFA£©·À±¸Æ¾Ö¤ÀÄÓá£SonicWall·½ÃæÉÐδ¹«¿ªÖÃÆÀ¡£


https://www.bleepingcomputer.com/news/security/new-wave-of-vpn-login-attempts-targets-palo-alto-globalprotect-portals/