FlickrÒòµÚÈý·½·þÎñ·ì϶ÖÂÓû§Êý¾Ýй¶

°ä²¼¹¦·ò 2026-02-09

1. FlickrÒòµÚÈý·½·þÎñ·ì϶ÖÂÓû§Êý¾Ýй¶


2ÔÂ9ÈÕ £¬×÷ΪSmugMugÆìÏÂÕ¼Óг¬1ÒÚ×¢²áÓû§¡¢Êý°ÙÍò»îÔ¾ÉãӰʦµÄÕÕÆ¬·ÖÏíÆ½Ì¨ £¬FlickrÓÚ2026Äê2ÔÂ5ÈÕ·¢ÏÔìäµÚÈý·½µç×ÓÓʼþ·þÎñÌṩÉÌ´æÔÚϵͳ·ì϶ £¬¿ÉÄÜÔì³É²¿ÃÅÓû§Ó×ÎÒÐÅÏ¢Ôâδ¾­ÊÚȨ½Ó¼û¡£¾Ý¹Ù·½´«µÝ £¬Õâ´ÎÊÂÎñ¿ÉÄÜй¶µÄÐÅÏ¢Ô̺¬Óû§ÐÕÃû¡¢µç×ÓÓÊÏ䵨ַ¡¢IPµØÖ·¼°ÕË»§»î¶¯¼Í¼ £¬µ«Î´Éæ¼°ÃÜÂë¡¢Ö§¸¶Êý¾ÝµÈÃô¸ÐÐÅÏ¢¡£FlickrÔÚ»ñϤ·ì϶ºóÊýÓ×ʱÄÚ¼´¹Ø¹ØÊÜÓ°Ïìϵͳ £¬¶Â½ØÓë´æÔÚ·ì϶µÄµÚÈý·½¶ËµãµÄÏνÓ £¬²¢Í¬²½Æô¶¯È«Ã氲ȫÉó²é¡£Ö»¹ÜFlickrδÅûÂ¶ÉæÊ·þÎñÌṩÉ̾ßÌåÉí·Ý¼°ÊÜÓ°ÏìÓû§¹æÄ£ £¬µ«ÒѲÉÈ¡¶àÏîÓ¦¼±´ëÊ©£ºÁ¢¼´Í¨ÖªµÚÈý·½·þÎñÉÌ·¢Õ¹Éî¶Èµ÷²é £¬Ç¿»¯¶ÔµÚÈý·½·þÎñµÄ¹Ü¿ØÁ÷³Ì £¬Í¬Ê±ÏòÓйØÊý¾Ý± £»¤»ú¹¹±¨±¸ÊÂÎñÏêÇ顣ƽ̨·½Ç¿µ÷ £¬ÒÑͨ¹ýɾ³ý´æÔÚ·ì϶µÄ¶ËµãÁ´½Ó¡¢Ö´ÐÐϵͳ¼Ü¹¹¼Ó¹ÌµÈ·½Ê½ÌáÉý°²È«·À»¤µÈ¼¶ £¬²¢³Ðŵ½«³ÖÐø¼à¿ØµÚÈý·½·þÎñÌṩÉ̵ĺϹæÐÔ¡£


https://securityaffairs.com/187753/data-breach/flickr-moves-to-contain-data-exposure-warns-users-of-phishing.html


2. ˼¿ÆTalosÆØ¹âDKnife£ºÖÐÎÄÓû§LinuxÍø¹Ø¹¥»÷¿ò¼Ü


2ÔÂ8ÈÕ £¬Ë¼¿ÆTalosÓÚ½üÆÚÅû¼ûûΪ¡°DKnife¡±µÄLinux¶ñÒ⹤¾ß°ü £¬¸Ã¹¤¾ßÓɯߏö»ùÓÚLinuxµÄÖ²È뷨ʽ×é³É £¬×¨ÎªÂ·ÓÉÆ÷ºÍ±ßÔµÉ豸Éè¼Æ £¬¿ÉÖ´ÐÐÉî¶È°ü¼ì²â¡¢Á÷Á¿°Ñ³Ö¼°¶ñÒâÈí¼þ´«²¼¡£¾Ý»ã±¨ £¬DKnife×Ô2019ÄêÆð±»Ê¹Óà £¬ÆäC2·þÎñÆ÷ÖÁ2026Äê1ÔÂÈÔ»îÔ¾ £¬ÖØÒªÕë¶ÔÖÐÎÄÓû§ £¬Í¨¹ý½Ù³ÖÈí¼þÏÂÔØ¡¢°²×¿ÀûÓøüУ¨Èç΢ÐÅ¡¢Öйú³ö×â³µ/ÍøÔ¼³µÀûÓã©´«²¼ShadowPadºÍDarkNimbusºóÃÅ £¬ÇÔÈ¡Öйú·þÎñƾ֤¼°ÈȵãÀûÓÃÊý¾Ý¡£¼¼Êõ²ãÃæ £¬DKnifeÖ§³ÖÖÐÑëÈ˹¥»÷£¨AitM£© £¬¿ÉÀ¹½ØWindows¡¢Android¸üм°¶þ½øÔìÎļþÏÂÔØ £¬½«ºÏ·¨ÒªÇó³Á¶¨ÏòÖÁ¶ñÒâ·þÎñÆ÷ £¬´úÌæÎªº¬ShadowPad/DarkNimbusµÄ×°Ö÷¨Ê½¡£Æä¼ÓÃܹ涨ѡȡQQ TEAÃÜÔ¿½âÃÜ £¬Ê¹Óúó×Ô¶¯É¾³ý¡£¸Ã¹¤¾ß»¹¾ß±¸Á÷Á¿¼ì²âÄ£¿é £¬¿É¼ø±ð²¢×ÌÈÅ360°²È«Èí¼þ¡¢ÌÚѶ·þÎñµÈ°²È«²úÆ·µÄͨѶ £¬Í¨¹ýαÔìTCP RSTÊý¾Ý°ü×è¶ÏÁ÷Á¿ £¬½µµÍÊܺ¦ÕßÉ豸·À»¤ÄÜÁ¦¡£


https://securityaffairs.com/187716/malware/dknife-toolkit-abuses-routers-to-spy-and-deliver-malware-since-2019.html


3. BridgePayÖ§¸¶Íø¹ØÔâÀÕË÷Èí¼þ¹¥»÷ÖÂÈ«¹ú·þÎñÖжÏ


2ÔÂ6ÈÕ £¬ÃÀ¹ú´óÐÍÖ§¸¶Íø¹ØÌṩÉÌBridgePay Network SolutionsÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÆäÖ÷ÌâÖ§¸¶ÏµÍ³È«¹úÐÔ̱»¾ £¬Òý·¢´ó¹æÄ£·þÎñÖжÏ¡£ÊÂÎñʼÓÚÖÜÎåÁ賿 £¬¼à¿ØÏµÍ³ÂÊÏÈ·¢ÏÖ¡°Gateway.Itstgate.com - Ðé¹¹ÖÕ¶Ë¡¢»ã±¨¡¢API¡±µÈ¹Ø¼ü·þÎñ»úÄܽµÂä £¬Ëæºó¶à¸öÖ÷Ìâ³ö²úϵͳ£¨ÈçBridgePayÍø¹ØAPI¡¢PayGuardianÔÆAPI¡¢MyBridgePayÐé¹¹ÖÕ¶Ë¡¢ÍйÜÖ§¸¶Ò³Ãæ¼°PathwayLinkÃÅ»§£©³öÏÖ¼äЪÐÔ½µ¼¶ £¬×îÖÕÑݱäÎªÈ«ÃæÌ±»¾¡£BridgePayÔÚµ±ÈÕÍíЩʱ³½Ö¤Êµ £¬Õâ´ÎÖжÏÓÉÀÕË÷Èí¼þ¹¥»÷Òý·¢ £¬²¢ÒѽáºÏÁª¹úµ÷²é¾Ö¡¢ÃÀ¹úÌØÇÚ¾Ö¼°±í²¿È¡Ö¤ÍŶӷ¢Õ¹µ÷²é¡£¹«Ë¾Ç¿µ÷ £¬³õ²½È¡Ö¤ÏÔʾÎÞÖ§¸¶¿¨Êý¾Ýй¶ £¬±»½Ó¼ûÎļþ¾ùÒѼÓÃÜ £¬Ä¿Ç°¡°ÎÞÖ¤¾ÝÅú×¢´æÔÚ¿ÉÓÃÊý¾Ýй¶¡±¡£È»¶ø £¬ÀÕË÷Èí¼þ¹¥»÷ÒÑÔì³ÉÑϳÁÏÖʵӰÏì £¬È«¹ú¶àµØÉ̼ÒÒòÒøÐп¨´¦ÖÃϵͳ¹ÊÕϱ»ÆÈ½ö½ÓÊÜÏÖ½ðÖ§¸¶ £¬·ðÂÞÀï´ïÖÝרéµÍåÊе±¾ÖÔÚÏßÕ˵¥Ö§¸¼ûÅ»§Ì±»¾ £¬½¨ÒéÊÐÃñͨ¹ýÏÖ½ð¡¢ÒøÐп¨»ò֧ƱÏÖ³¡Ö§¸¶ £¬²¿ÃÅ»ú¹¹ÉõÖÁÐèµç»°Ö§¸¶¡£Lightspeed Commerce¡¢ThriftTrac¼°µÂ¿ËÈøË¹Öݸ¥Àï˹¿ÆÊÐµÈÆäËû×éÖ¯Òà»ã±¨·þÎñÊÜÓ°Ïì¡£


https://www.bleepingcomputer.com/news/security/payments-platform-bridgepay-confirms-ransomware-attack-behind-outage/


4. CISA½«React Native¼°SmarterMail·ì϶ÌíÖÁKEVĿ¼


2ÔÂ6ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«SmarterTools SmarterMailºÍReact Native Community CLIµÄÁ½¸ö¸ßΣ·ì϶CVE-2025-11953ÓëCVE-2026-24423Ôö³¤ÖÁÒÑÖª¿ÉÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ £¬²¢ÒªÇóÁª¹ú»ú¹¹ÔÚ2026Äê2ÔÂ26ÈÕǰʵÏÖ½¨¸´¡£CVE-2025-11953ÊÇReact Native Community CLIµÄMetro¿ª·¢·þÎñÆ÷´æÔڵIJÙ×÷ϵͳºÅÁî×¢Èë·ì϶¡£¸Ã·þÎñÆ÷ĬÈÏ°ó¶¨±í²¿½Ó¿Ú £¬Â¶³öÒ×Êܹ¥»÷µÄ¶Ëµã £¬Î´¾­ÈÏÖ¤µÄ¹¥»÷Õ߿ɷ¢ËÍPOSTÒªÇóÔÚWindowsϵͳÉÏÖ´ÐÐËÁÒâºÅÁî £¬ÉõÖÁÔËÐÐÆëÈ«¿É¿ØµÄshell¾ç±¾¡£VulnCheck×êÑÐÏÔʾ £¬¸Ã·ì϶×Ô2025Äê12ÔÂÆðÒѱ»³ÖÐøÀûÓà £¬¹¥»÷Õßͨ¹ý¶à½×¶ÎBase64±àÂëµÄPowerShell¼ÓÔØÆ÷½ûÓð²È«Èí¼þ¡¢ÏÂÔØ²¢Ö´ÐжñÒâ¶þ½øÔìÎļþ¡£CVE-2026-24423ÊÇSmarterTools SmarterMail£¨9511°æ±¾Ç°£©µÄConnectToHub API²½ÖèÖдæÔÚµÄδÈÏÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶ £¬CVSSÆÀ·Ö¸ß´ï9.3¡£¹¥»÷Õß¿ÉÊèµ¼SmarterMailÏνӶñÒâHTTP·þÎñÆ÷ £¬´¥·¢¶ñÒâºÅÁîÖ´ÐС£¸Ã·ì϶ÓɶàÍŶӽáºÏ»ã±¨ £¬SmarterToolsÒÑÔÚBuild 9511°æ±¾Öн¨¸´¡£


https://securityaffairs.com/187675/security/u-s-cisa-adds-smartertools-smartermail-and-react-native-community-cli-flaws-to-its-known-exploited-vulnerabilities-catalog.html


5. Ó¢¹ú¹¹Öþ¹«Ë¾ÔâPrometei½©Ê¬ÍøÂç¹¥»÷


2ÔÂ8ÈÕ £¬Ò»¼ÒÓ¢¹ú¹¹Öþ¹«Ë¾ÔÚÆäWindows·þÎñÆ÷ÉÏ·¢ÏÖÃûΪ"Êý×ÖµØÓü×â»§"µÄÒñ±ÎÈëÇÖÕß¡£¾­eSentireÍþвÏìÓ¦²¿ÃÅ£¨TRU£©¼ø¶¨ £¬ÈëÇÖÕßΪÓë¶íÂÞ˹¹ØÁªµÄPrometei½©Ê¬ÍøÂç £¬×Ô2016ÄêÆð³ÖÐø»îÔ¾µÄ¶ñÒⷨʽ £¬ÆäÖ÷ÌâÖ°ÄÜËäΪÍÚ¾òÃÅÂÞ±Ò¼ÓÃÜÇ®±Ò £¬µ«TRU×êÑÐ֤ʵÆäͬÑùÉÆÓÚÃÜÂëÇÔÈ¡ÓëÔ¶³Ì½ÚÔìϵͳ¡£¸Ã¹¥»÷µÄÏÔÖøÌØµãÔÚÓڵͼ¼ÊõÃż÷£º¹¥»÷Õß½öͨ¹ý²Â²âÈõÃÜÂë»òĬÈÏÃÜÂë £¬·½±ãÓÃÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©ÇáËÉ»ñȡϵͳ½Ó¼ûȨÏÞ £¬Ó¡Ö¤ÁË"ÈõÃÜÂëÈ糨ÃÅ"µÄ°²È«¾¯Ê¾¡£PrometeiʵΪÆëÈ«¹¤¾ß°ü £¬×°ÖúóÔËÐÐUPlugPlay·þÎñ²¢´´½¨sqhost.exeÎļþ £¬È·±£¿ª»ú×ÔÆô¡£Æä³õʼÓÐÐ§ÔØºÉzsvc.exe´ÓPrimesoftex Ltd.¹ØÁª·þÎñÆ÷ÏÂÔØ £¬¾­¸ß¶È¼ÓÃܼÙ×° £¬¾ß±¸Òñ±ÎÐÔ¡£Îª¶ã±Ü¼ì²â £¬¸Ã¶ñÒâÈí¼þѡȡ˫³ÁÕ½Êõ£ºÒ»·½ÃæÍ¨¹ýWindowsÄÚÖù¤¾ßÍøÂçÍÆËã»úÃû³ÆÓë¼¼Êõϸ½Ú £¬²¿ÊðMimikatz£¨ÏóÕ÷ΪmiWalk£©ÇÔÈ¡ÍøÂçÃÜÂë £¬²¢ÀûÓÃTORÄäÃûÍøÂç·ÓÉÁ÷Á¿ £»ÁíÒ»·½ÃæÖ´ÐÐ"ɳÏäÈÆ¹ý" £¬ÈôÎÞ·¨ÕÒµ½mshlpda32.dll½â°üÎļþ £¬ÔòÖ´ÐÐÐéαϵͳ¹¤×÷¼Ù×°ÎÞº¦ÐÐΪ¡£


https://hackread.com/uk-construction-firm-prometei-botnet-windows-server/


6. ¡°Ó°×ÓÐж¯¡±½ÒÃØ£º¹ú¶ÈÖ§³Ö×é֝ɸÈë¶à¹ú¹Ø¼üÉèÊ©


2ÔÂ7ÈÕ £¬Óɹú¶ÈÖ§³ÖµÄÍþв×éÖ¯TGR-STA-1030/UNC6619ÌáÒéµÄ¡°Ó°×ÓÐж¯¡±ÒÑÔÚÈ«ÇòÁìÓòÄÚ·¢Õ¹´ó¹æÄ£ÍøÂç¹¥»÷ £¬ÉøÈë37¸ö¹ú¶ÈµÄ70Óà¸öµ±¾Ðݹؼü»ù´¡ÉèʩʵÌå¡£¾ÝPalo Alto Networks Unit 42²¿ÃÅÅû¶ £¬¸Ã×éÖ¯×Ô2024Äê1ÔÂÆð»îÔ¾ÓÚÑÇÖÞ £¬Æä¹¥»÷Ö¸±êº­¸Çµ±¾Ö¡¢·¨ÂÉ¡¢±ßÚï¹ÜÔì¡¢ÄÜÔ´¡¢½ðÈÚ¡¢±í½»µÈÕ½ÊõÁìÓò £¬Ô̺¬ÃÀÖÞÒµÎñÕþ²ß»ú¹¹¡¢Å·ÖÞ¶à¹úÒé»á¡¢°Ä´óÀûÑDzÆÕþ²¿¼°Ì¨ÍåµçÁ¦É豸¹©¸øÉ̵È¡£¹¥»÷¼¿Á©³öÏָ߶ȶ¨Ô컯Óë¶àά¶ÈÌØµã¡£ÔçÆÚͨ¹ý´¹µöÓʼþͶµÝº¬±¾µØ»¯Ãû³ÆµÄ¶ñÒâѹËõÎļþ £¬ÀûÓÃMega.nz´æ´¢·þÎñÓÕµ¼Ö¸±êÏÂÔØ £¬½áºÏ»·¾³²é³­¶ã±ÜɳÏä¼ì²â £¬²¢¼ÓÔØCobalt Strike¼°VShell¿ò¼ÜÖ´ÐкÅÁî½ÚÔì¡£×éÖ¯»¹ÀûÓÃ15¸öÒÑÖª·ì϶»ñÈ¡³õʼ½Ó¼ûȨÏÞ £¬²¢²¿Êð¶¨ÔìLinux rootkit¡°ShadowGuard¡± £¬¸Ã¹¤¾ß»ùÓÚeBPFÄں˼¼Êõ £¬¿É°µ²Ø×î¶à32¸öPID¼°¡°swsecret¡±Îļþ £¬Í¨¹ýϵͳŲÓÃÀ¹½ØÌÓ±Ü¼à¿Ø £¬Í¬Ê±ÔÊÐí²Ù×÷Õß½ç˵¿É¼û¹ý³ÌÒÔ»ìºÏµ÷²é¡£


https://www.bleepingcomputer.com/news/security/state-actor-targets-155-countries-in-shadow-campaigns-espionage-op/