GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý

°ä²¼¹¦·ò 2026-02-03

1. GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý


2ÔÂ2ÈÕ £¬Ò»ÖÖÐÂÐÍGlassWorm¶ñÒâÈí¼þ¹¥»÷ͨ¹ý±»ÈëÇÖµÄOpenVSXÀ©´ó·¨Ê½ £¬×¨ÃÅÕë¶ÔmacOSϵͳÇÔÈ¡ÃÜÂë¡¢¼ÓÃÜÇ®°üÊý¾Ý¡¢¿ª·¢ÕßÍ´´¦¼°ÅäÏàÐÅÏ¢  ¡£ÍþвÐÐΪÕß»ñÈ¡Á˺Ϸ¨¿ª·¢ÕßoorzcµÄÕË»§È¨ÏÞ £¬ÓÚ1ÔÂ30ÈÕÏòËĸö±»ÏÂÔØ22,000´ÎµÄÀ©´ó·¨Ê½ÍÆËͺ¬GlassWormÓÐÐ§ÔØºÉµÄ¶ñÒâ¸üР ¡£ÕâЩÀ©´ó·¨Ê½´ËǰÁ½Äê¾ùÎÞº¦ £¬Åú×¢oorzcÕË»§ÒÑÔâÈëÇÖ  ¡£¹¥»÷×îÔç³öÏÖÓÚ2025Äê10ÔÂÏÂÑ® £¬ÀûÓá°²»Ë½¼û¡±Unicode×Ö·û°µ²Ø¶ñÒâ´úÂë £¬Ö§³Ö»ùÓÚVNCµÄÔ¶³Ì½Ó¼ûºÍSOCKS´úÀíÖ°ÄÜ  ¡£GlassWormרÃÅÕë¶ÔmacOSϵͳ £¬¿É´ÓSolanaÂòÂô±¸Íü¼ÌáȡָÁî £¬ÇÒ¶íÓïϵͳδÊܹ¥»÷ £¬°µÊ¾¹¥»÷Õß¿ÉÄÜÀ´×ԷǶíÓïÇø  ¡£¸Ã¶ñÒâÈí¼þ¼ÓÔØmacOSÐÅÏ¢ÇÔÈ¡·¨Ê½ £¬Í¨¹ýLaunchAgent³ÉÁ¢ÓƾÃÐÔ £¬ÔÚÓû§µÇ¼ʱ×Ô¶¯Ö´ÐÐ £¬ÍøÂçFirefox¡¢Chromiumä¯ÀÀÆ÷Êý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÀûÓá¢macOSÔ¿³×´®¡¢Apple NotesÊý¾Ý¿â¡¢Safari cookie¡¢¿ª·¢ÕßÃÜÔ¿¼°±¾µØÎĵµ £¬²¢½«Ëùº±¼û¾Ýй¶ÖÁ¹¥»÷ÕߵķþÎñÆ÷  ¡£


https://www.bleepingcomputer.com/news/security/new-glassworm-attack-targets-macos-via-compromised-openvsx-extensions/


2. ShinyHuntersй¶Panera Bread³¬1400ÍòÕË»§Êý¾Ý


2ÔÂ2ÈÕ £¬ShinyHunters·¸×ïÍÅ»ïÐû³ÆÇÔÈ¡ÁËPanera Bread³¬¹ý1400Íò¸öÕË»§µÄÊý¾Ý £¬²¢ÔÚÀÕË÷δ¹ûºó £¬ÓÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªÁËÒ»¸ö760MBµÄÊý¾Ý´æµµ  ¡£¾ÝHave I Been Pwned£¨HIBP£©±¨Â· £¬Õâ´ÎÐ¹Â¶Éæ¼°510Íò¸öΨһµç×ÓÓʼþµØÖ·¼°¹ØÁªµÄÕË»§ÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØÖ·µÈ  ¡£Panera BreadËæºó֤ʵй¶Êý¾ÝΪÁªÏµÐÅÏ¢ £¬²¢ÒÑ֪ͨÓйز¿ÃÅ  ¡£BleepingComputer½øÒ»²½È·ÈÏÔ¼512Íò¸öÕË»§Êܵ½Ó°Ïì £¬µ«ÏÖʵÊÜÓ°ÏìÓû§ÊýÁ¿¿ÉÄܸüÉÙ £¬Òò´æÔÚͳһÓû§Ê¹Óöà¸öÕË»§µÄÇé¿ö  ¡£ShinyHuntersÍŻﰵʾ £¬Õâ´Î¹¥»÷ÊÇÕë¶Ô100¶à¼Ò»ú¹¹µÄÖØÒªÉí·ÝÌṩÉÌSSOÕË»§ÌáÒéµÄ¸ü´ó¹æÄ£ÍøÂç´¹µö¹¥»÷µÄÒ»²¿ÃÅ £¬ËûÃÇͨ¹ýMicrosoft Entra SSO´úÂë½Ó¼ûÁËPaneraµÄϵͳ  ¡£Panera×÷ΪÃÀ¹ú³ÛÃûºæ±º¿§·ÈÁ¬Ëøµê £¬³ÉÁ¢ÓÚ1987Äê £¬Óµº±¼ûǧ¼Ò·Öµê £¬×¨Ò»ÓÚ¿ì½ÝÐÝÏвÍÒûģʽ £¬Õâ´ÎÊý¾Ýй¶ÊÂÎñÔÙ´ÎÒý·¢ÁË¶ÔÆäÊý¾Ý°²È«ÖÎÀíµÄ¹Ø×¢  ¡£


https://securityaffairs.com/187556/data-breach/panera-bread-breach-affected-5-1-million-accounts-hibp-confirms.html


3. ¶íAPT28ÀûÓÃOffice·ì϶¶¨Ïò¹¥»÷ÎÚÅ·


2ÔÂ2ÈÕ £¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT-UA£©Åû¶ £¬¶íÂÞ˹¹ú¶È¼¶ºÚ¿Í×éÖ¯APT28£¨±ðºÅFancy Bear¡¢Sofacy £¬Óë¶í×ÜÕÕ·÷²¿µý±¨×ܾÖGRU¹ØÁª£©ÕýÀûÓÃ΢ÈíOfficeµÄÁãÈÕ·ì϶CVE-2026-21509ÌáÒé¹¥»÷  ¡£Î¢ÈíÓÚ2026Äê1ÔÂ26ÈÕ°ä²¼´¹Î£´ø±í°²È«¸üР£¬ÏóÕ÷¸Ã·ì϶Ϊ¡°ÔÚ±»»ý¼«ÀûÓá±µÄÁãÈÕ·ì϶  ¡£½öÈýÌìºó £¬CERT-UA±ã¼ì²âµ½ÒÔ¡°Å·ÃËפÎÚ¿ËÀ¼³£×¤´ú±íίԱ»áЭÉÌ¡±ÎªÖ÷ÌâµÄ¶ñÒâDOCÎļþ £¬Í¬Ê±·¢ÏÖ¼ÙÒâÎÚ¿ËÀ¼Ë®ÎÄÐÎÏóÖÐÐĵĴ¹µöÓʼþ±»·¢ËÍÖÁ60Óà¸öµ±¾ÖÓйصØÖ·  ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬ÓйضñÒâÎļþµÄÔªÊý¾ÝÏÔʾÆä´´½¨¹¦·òÇ¡ÔÚ΢Èí¸üа䲼ºóÒ»ÈÕ  ¡£¹¥»÷¼¼ÊõÁ´ÏÔʾ £¬´ò¿ª¶ñÒâÎĵµ»á´¥·¢»ùÓÚWebDAVµÄÏÂÔØÁ´ £¬Í¨¹ýCOM½Ù³Ö¡¢¶ñÒâDLL¡¢°µ²ØÔÚͼÏñÎļþÖеÄshellcode¼°´òË㹤×÷×°ÖöñÒâÈí¼þ  ¡£CERT-UA»ã±¨Ö¸³ö £¬´òË㹤×÷Ö´ÐлᵼÖÂexplorer.exe¹ý³ÌÖÕÖ¹²¢³ÁÆô £¬È·±£¼ÓÔØ¶ñÒâDLL £¬½ø¶ø´ÓͼÏñÎļþÖÐÖ´ÐÐshellcodeÒÔÆô¶¯COVENANT¿ò¼Ü  ¡£¸Ã¿ò¼Ü´ËÇ°ÔøÔÚ2025Äê6ÔÂAPT28Õë¶ÔÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄ¹¥»÷Öб»Ê¹Óà  ¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-recently-patched-microsoft-office-bug-in-attacks/


4. OpenClaw¿ªÔ´AI¸±ÊÖÔâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷


2ÔÂ2ÈÕ £¬¿ªÔ´AI¸±ÊÖOpenClaw£¨Ô­³ÆMoltbotºÍClawdBot£©µÄ¹Ù·½×¢²á±íClawHub¼°GitHubƽ̨Ôâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷ £¬³¬230¸ö¼Ù×°³ÉºÏ·¨¹¤¾ßµÄ¶ñÒâÈí¼þ°ü±»°ä²¼  ¡£ÕâЩ±»³Æ×÷"¼¼Êõ"µÄ²å¼þÒÔ¼ÓÃÜÇ®±ÒÂòÂô×Ô¶¯»¯¡¢½ðÈÚ¹¤¾ßµÈºÏ·¨Ö°ÄÜΪ»Ï×Ó £¬ÏÖʵעÈë¶ñÒâÈí¼þÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý £¬Ô̺¬APIÃÜÔ¿¡¢Ç®°ü˽Կ¡¢SSHƾ֤¡¢ä¯ÀÀÆ÷ÃÜÂë¼°.envÎļþµÈ  ¡£°²È«×êÑÐÔ±Jamieson O'ReillyÖ¸³ö £¬´óÁ¿OpenClawÊ·ýÒòÅäÖò»µ±µ¼ÖÂÖÎÀí½çÃæÂ¶³öÓÚ¹«¹²ÍøÂç  ¡£¹¥»÷ÕßÀûÓô˷ì϶ £¬Í¨¹ýÃûΪ"AuthTool"µÄ¶ñÒâÈí¼þ´«²¼¹¤¾ßÖ´ÐÐϰȾ  ¡£ÉçÇø°²È«×éÖ¯OpenSourceMalware»ã±¨ÏÔʾ £¬Õâ´Î¹¥»÷³öÏÖ¹æÄ£»¯Ìصã £¬´óÁ¿¶ñÒâ¼¼Êõ¿âÃû³Æ¸ß¶ÈÀàËÆ £¬²¿ÃŰ汾ÏÂÔØÁ¿´ïÊýǧ´Î  ¡£Koi SecurityɨÃèClawHubÈ«Êý2857¸ö¼¼Êõ¿âºó £¬·¢ÏÖ341¸ö¶ñÒâ¼¼Êõ £¬²¢×·×Ùµ½29¸öÕë¶ÔClawHubÓòÃûµÄƴдÃýÎó´¹µöÍøÕ¾  ¡£ÎªÐ­ÖúÓû§·ÀÓù £¬Koi»¹°ä²¼ÁËÃâ·ÑÔÚÏßɨÃ蹤¾ß £¬¿Éͨ¹ýURL¼ì²â¼¼Êõ°²È«ÐÔ  ¡£


https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/


5.ÐÂÐÍÍøÂç´¹µöÚ¿Æ­ÀûÓÃPDF¸½¼þÇÔÈ¡Óû§Æ¾Ö¤


2ÔÂ2ÈÕ £¬ForcepointÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶һÖÖÐÂÐͶà½×¶ÎÍøÂç´¹µöÚ¿Æ­¼¿Á© £¬¸ÃÊÖ·¨Í¨¹ý¾«ÐÄÉè¼ÆµÄ¡°×¨ÒµÓʼþ+PDF¸½¼þ¡±×éºÏÈÆ¹ý´«Í³°²È«¹ýÂË £¬×îÖÕÇÔÈ¡Óû§µÇ¼ƾ֤  ¡£´ËÀàÚ¿Æ­Óʼþͨ³£¼Ù×°³ÉóÒ׺Ïͬ¡¢Õбê»ò²É²É°ìÂôÓйØÍ¨Öª £¬ÄÚÈÝ¿´ËÆÕý¹æÎÞº¦ £¬µ«¹Ø¼ü¶ñÒâÐÐΪ°µ²ØÔÚPDF¸½¼þÖÐ  ¡£×êÑÐÏÔʾ £¬Ú¿Æ­ÕßÀûÓÃPDFµÄAcroFormsºÍFlateDecode¼¼Êõ £¬ÔÚ¿´ËÆÍ¨³£µÄ°ì¹«º¯µµÖÐǶÈë¿Éµã»÷°´Å¥  ¡£Óû§µã»÷ºó £¬»á±»Êèµ¼ÖÁµÚ¶þ¸öÍйÜÔÚVercel BlobÔÆ´æ´¢Æ½Ì¨ÉϵÄÎĵµ  ¡£ÓÉÓÚVercelÊǺϷ¨ÔÆ·þÎñ £¬ÕâÖÖ¡°¿ÉÐÅ»ù´¡ÉèÊ©¡±ÀûÓ÷½Ê½ÓÐЧ¶ã±ÜÁ˰²È«Èí¼þµÄÀ¹½Ø  ¡£Ëæºó £¬¸ÃÔÆÎĵµ»áÌø×ªÖÁαÔìµÄDropboxµÇÂ¼Ò³Ãæ £¬Æä½çÃæÓëÕæÊµÒ³Ãæ¸ß¶ÈÀàËÆ £¬ÓÕµ¼Óû§ÊäÈëÓÊÏä¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢  ¡£ÔÚºó¶Ü £¬¶ñÒâ¾ç±¾²»½öÇÔÈ¡Óû§Æ¾Ö¤ £¬»¹»á¼Í¼¾«È·µÄIPµØÖ·¡¢µØÀíµØÎ»¡¢É豸ÀàÐ͵ÈÀ©´óÐÅÏ¢  ¡£±»µÁÊý¾Ýͨ¹ýÓ²±àÂ뷽ʽֱ½Ó·¢ËÍÖÁTelegramƽ̨µÄ¸öÈËÆµÂ· £¬ÓɺڿͽÚÔìµÄ»úеÈ˽ӹÜ  ¡£


https://hackread.com/phishing-scam-emails-pdfs-steal-dropbox-logins/


6. È«ÇòÔÆ´æ´¢¶©ÔÄÚ¿Æ­·ºÀÄ


1ÔÂ31ÈÕ £¬´ÓǰÊýÔ £¬Ò»³¡´ó¹æÄ£ÔÆ´æ´¢¶©ÔÄÚ¿Æ­»î¶¯ÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÊæÕ¹  ¡£Ú¿Æ­·Ö×Óͨ¹ý·¢ËÍ´óÁ¿¿ÖÏÅÓʼþ £¬»Ñ³ÆÓû§Òò¡°Ö§¸¶Ê§°Ü¡±»ò¡°´æ´¢¿Õ¼ä²»¼°¡±µ¼ÖÂÕË»§½«±»¹Ø±Õ¡¢Îļþ½«±»É¾³ý £¬ÒÔ´ËÔì×÷½ôÆÈ¸ÐÓÕµ¼Óû§µã»÷Á´½Ó  ¡£ÓʼþÖеÄÁ´½Ó¾ùÖ¸Ïò¹È¸èÔÆ´æ´¢·þÎñÍйܵľ²Ì¬³Á¶¨ÏòHTMLÎļþ £¬Óû§µã»÷ºó»á±»Ìø×ªÖÁËæ»úÓòÃûµÄ´¹µöÒ³Ãæ  ¡£ÕâÐ©Ò³Ãæ¸ß¶È·ÂÕÕÖ÷Á÷ÔÆ·þÎñÉÌ£¨Èç¹È¸èÔÆ¡¢Î¢ÈíOneDrive£©µÄ¹Ù·½½çÃæ £¬Ðû³ÆÓû§´æ´¢¿Õ¼äÒÑÂú £¬ÕÕÆ¬¡¢ÊÓÆµ¡¢ÎĵµµÈÊý¾Ý½«ÖÕ³¡±¸·Ý²¢Ãæ¶Ôɾ³ý·çÏÕ £¬ÓÕµ¼Óû§µã»÷¡°³ÖÐø¡±°´Å¥½øÈëÐéα´æ´¢¼ì²âÒ³Ãæ  ¡£¸ÃÒ³ÃæÊ¼ÖÕÏÔʾ´æ´¢¿Õ¼äÕ¼Âú £¬ÒªÇóÓû§Éý¼¶ÔÆ´æ´¢ÌײÍÒÔÏíÊÜ¡°ÀÏÓû§×¨Êô8ÕÛÓŻݡ± £¬µ«ÏÖʵµã»÷Éý¼¶°´Å¥ºó £¬Óû§»á±»³Á¶¨ÏòÖÁͬÃËÓªÏúÒ³Ãæ £¬ÍƹãVPN·þÎñ¡¢Ó׶లȫÈí¼þµÈÎ޹زúÆ· £¬×îÖÕÌø×ªÖÁ½áÕË±íµ¥ÍøÂçÓû§ÐÅÓþ¿¨ÐÅÏ¢ £¬Í¬Ê±ÎªÚ¿Æ­·Ö×Ó׬ȡͬÃËÓªÏúÓ¶½ð  ¡£


https://www.bleepingcomputer.com/news/security/cloud-storage-payment-scam-floods-inboxes-with-fake-renewals/