µÂ¿ËÈøË¹ÖÝÂÉʦЭ»áÔâINCÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶

°ä²¼¹¦·ò 2025-04-08

1. µÂ¿ËÈøË¹ÖÝÂÉʦЭ»áÔâINCÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶


4ÔÂ3ÈÕ £¬ÃÀ¹úµÚ¶þ´óÂÉʦЭ»á¡ª¡ªµÂ¿ËÈøË¹ÖÝÂÉʦЭ»áÔâ·ê³Á´óÊý¾Ýй¶ÊÂÎñ £¬²¨¼°³¬10ÍòÃûÖ´ÒµÂÉʦ ¡£¸ÃЭ»á³Ðµ£Ö´ÒµÐí¿É¼à¹Ü¡¢³ÖÐø½ÌÓýÖÎÀí¡¢Ö°ÒµÂ·µÂ¼à¶½µÈÖ÷ÌâÖ°ÄÜ £¬ÆäÍøÂçϵͳÓÚ2025Äê1ÔÂ28ÈÕÖÁ2ÔÂ9ÈÕ¼äÔâδ¾­ÊÚȨ½Ó¼û £¬µ«Ö±ÖÁ2ÔÂ12ÈÕ·½±»¾õ²ì ¡£Æ¾¾ÝЭ»áÏòÊÜÓ°Ïì³ÉÔ±°ä²¼µÄ֪ͨ £¬¹¥»÷ÕßÇÔÈ¡ÁËÔ̺¬È«ÃûµÄÃô¸ÐÐÅÏ¢ £¬¾ßÌåй¶ÁìÓòÉÐδÃ÷È· ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬INCÀÕË÷Èí¼þÍŻ﹫¿ªÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü £¬²¢ÓÚ3ÔÂ9ÈÕ½«¸ÃЭ»áÁÐÈë°µÍøÀÕË÷Ãûµ¥ £¬Í¬Ê±Åû¶Á˲¿ÃžݳÆÎªË¾·¨°¸¼þÎļþµÄ±»µÁÊý¾ÝÑù±¾ ¡£Ð­»áÒѲÉȡӦ¶Ô´ëÊ© £¬ÎªÊÜÓ°Ïì³ÉÔ±ÌṩÓÐЧÆÚÖÁ7ÔÂ31ÈÕµÄÃâ·ÑÐÅÓþ¼°Éí·Ý͵ÇÔ¼à¿Ø·þÎñ£¨ÓÉExperianÌṩ֧³Ö£© £¬²¢½¨Òé³ÉԱͨ¹ý¼¤»îÂë×¢²á¸Ã·þÎñ ¡£´Ë±í £¬Ð­»áÇ¿ÁÒ½¨Òé³ÉԱ˼¿¼Æô¶¯ÐÅÓþ¶³½á»òÔÚÐÅÓþµµ°¸ÖÐÉèÖÃڲƭ¾¯±¨ £¬ÒÔ×î´óÏ޶ȽµµÍDZÔÚ·çÏÕ ¡£


https://www.bleepingcomputer.com/news/security/texas-state-bar-warns-of-data-breach-after-inc-ransomware-claims-attack/


2. EverestÀÕË÷Èí¼þÍÅ»ï°µÍøÐ¹ÃÜÍøÕ¾Ôâδ֪¹¥»÷ÏÂÏß


4ÔÂ7ÈÕ £¬½üÈÕ £¬Everest ÀÕË÷Èí¼þÍÅ»ïµÄ°µÍøÐ¹ÃÜÍøÕ¾Ôâ·êδ֪¹¥»÷ÕßÏ®»÷ £¬Ä¿Ç°ÒÑÏÂÏß ¡£¹¥»÷Õß½«ÍøÕ¾ÄÚÈÝ´úÌæÎª³°·íÐÅÏ¢£º¡°²»Òª·¸×ï £¬·¸×ïÊÇ»µÊ £¬À´×Ô²¼À­¸ñ ¡£¡±Ä¿Ç° £¬¸ÃÍøÕ¾ÏÔʾ¡°Î´ÕÒµ½Ñó´ÐÍøÕ¾¡±ÃýÎó £¬ÎÞ·¨¼ÓÔØ ¡£Ö»¹Ü¹¥»÷ÕßÈôºÎ½øÈëÍøÕ¾»òÍøÕ¾ÊÇ·ñ±»ºÚ¿Í¹¥»÷Éв»Ã÷È· £¬µ«°²È«×¨¼ÒÖ¸³ö £¬Everest ʹÓÃµÄ WordPress Ä£°å¿ÉÄÜ´æÔÚDZÔÚ·ì϶ £¬¸Ã·ì϶»ò±»ÀûÓÃÀ´ÆÆ»Â·ÕË÷Èí¼þ²Ù×÷µÄÐ¹Â©ÍøÕ¾ ¡£×Ô 2020 Äê³öÏÖÒÔÀ´ £¬Everest ÀÕË÷Èí¼þÐж¯Õ½ÊõÒѲúÉú±ä¶¯ £¬´Ó½öÇÔÈ¡Êý¾Ý¡¢ÀÕË÷Æóҵת±äΪÔÚ¹¥»÷ÖвÎÓëÀÕË÷Èí¼þ £¬¼ÓÃÜÊܺ¦Õßϵͳ ¡£´Ë±í £¬Everest ÔËÓªÉÌ»¹Òò³äÈÎÆäËûÍøÂç·¸×ïÍÅ»ïºÍÍþвÐÐΪÕߵijõʼ½Ó¼ûȨÏÞ¾­¼ÍÈ˶øÎÅÃû £¬ÏúÊÛ±»¹¥ÆÆµÄ¹«Ë¾ÍøÂç½Ó¼ûȨÏÞ ¡£ÔÚ´Óǰ 5 ÄêÖÐ £¬Everest µÄ°µÍøÐ¹ÃÜÍøÕ¾Ôö³¤ÁË 230 ¶àÃûÊܺ¦Õß £¬³ÉΪ˫³ÁÀÕË÷¹¥»÷µÄÒ»²¿ÃÅ £¬ÀÕË÷Èí¼þÍÅ»ïÊÔͼÒÔ°ä²¼Ãô¸ÐÐÅϢΪÍþв £¬ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð ¡£


https://www.bleepingcomputer.com/news/security/everest-ransomwares-dark-web-leak-site-defaced-now-offline/


3. VSCode¶ñÒâÀ©´óʾÉí΢ÈíÊг¡ £¬½èXMRigÍÚ¿óIJÀû


4ÔÂ7ÈÕ £¬½üÈÕ £¬ExtensionTotal×êÑÐÔ±Yuval Ronen·¢ÏÖ £¬2025Äê4ÔÂ4ÈÕ £¬Î¢ÈíÃÅ»§ÉÏÇÄÈ»°ä²¼Á˾Ÿö¼Ù×°³ÉºÏ·¨¿ª·¢¹¤¾ßµÄVSCodeÀ©´ó ¡£ÕâЩÀ©´óÒÔ¡°Discord Rich Presence for VS Code¡±¡°Rojo ¨C Roblox Studio Sync¡±µÈÃû³ÆÊ¾ÈË £¬×°ÖÃÁ¿³¬30Íò´Î £¬µ«Êý×Ö¿ÉÄܱ»±¨´ð¿ä´ó £¬Ö¼ÔÚÓªÔìºÏ·¨¼ÙÏó ¡£Ò»µ©×°Öü¤»î £¬ÕâЩ¶ñÒâÀ©´ó±ã´Ó±í²¿Ô´»ñÈ¡²¢Ö´ÐÐPowerShell¾ç±¾ £¬Í¬Ê±×°ÖÃÆä·ÂÕյĺϷ¨À©´óÒÔÑÚÈ˶úÄ¿ ¡£¶ñÒâÈí¼þ»á´´½¨¼Ù×°³É¡°OnedriveStartup¡±µÄ´òË㹤×÷ £¬²¢ÔÚWindows×¢²á±íÖÐ×¢Èë¾ç±¾ £¬È·±£ÏµÍ³Æô¶¯Ê±×Ô¶¯ÔËÐÐ ¡£Ëü»¹»á¹Ø¹Ø¹Ø¼üWindows·þÎñ £¬ÈçWindows Update £¬²¢½«×ÔÉíÔö³¤µ½Windows DefenderµÄÅųýÁбíÖÐ £¬ÒÔÌӱܼì²â ¡£ÈôδÒÔÖÎÀíԱȨÏÞÖ´ÐÐ £¬¶ñÒâÈí¼þ»á·ÂÕÕϵͳ¶þ½øÔìÎļþ £¬Ê¹ÓöñÒâMLANG.dllÖ´ÐÐDLL½Ù³Ö £¬ÌáÉýȨÏÞ²¢Ö´ÐÐÓÐЧ¸ºÔØ ¡£¸Ã¿ÉÖ´ÐÐÎļþѡȡbase64±àÂëÌåʽ £¬ÓÉPowerShell¾ç±¾½âÂëºóÏνӵ½¸¨Öú·þÎñÆ÷ £¬ÏÂÔØ²¢ÔËÐÐXMRig¼ÓÃÜÇ®±Ò¿ó¹¤ ¡£Ä¿Ç° £¬Ö»¹ÜExtensionTotalÒÑÏò΢Èí»ã±¨ÕâЩ¶ñÒâÀ©´ó £¬µ«ËüÃÇÈÔ¿ÉÓà ¡£


https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/


4. ºÚ¿Í¼ÙÒâÎÚ»ú¹¹·¢Æð¹¥»÷ £¬ÇÔÃܶñÒâÈí¼þÍþв¼Ó¾ç


4ÔÂ8ÈÕ £¬Æ¾¾Ýµ±¾Ö×îÐÂ×êÑÐ £¬ºÚ¿ÍÕýÀûÓÃÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¶ÔÎÚ¿ËÀ¼¹Ø¼ü²¿ÃÅ·¢Æð¹¥»÷ ¡£×Ô2ÔÂÒÔÀ´ £¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT-UA£©Ò»ÏòÔÚ×·×ÙÕâÒ»»î¶¯ £¬ÆäÄ»ºóÍþвÕß±»×·×ÙΪUAC-0226 £¬µ«ÉÐδ¹é×ïÓÚÈκÎÒÑÖªºÚ¿Í×éÖ¯ ¡£ºÚ¿Í´Ó±»ÈëÇÖµÄÕË»§·¢ËÍ´øÓжñÒâÎĵµ¸½¼þµÄµç×ÓÓʼþ £¬ÎļþÃû»òÖ÷ÌâÐÐÉæ¼°µØÀ׶ϸù¡¢ÐÐÕþ· £¿î¡¢ÎÞÈË»ú³ö²ú»ò²Æ¸»ËðʧÅâ³¥µÈ»°Ìâ £¬ÒÔϰȾÎÚ¿ËÀ¼Îä×°¶ÓÁÓ×¢·¨ÂÉ»ú¹¹ºÍ´¦Ëùµ±¾Ö»ú¹¹µÈÖ¸±ê ¡£½ØÖÁ4Ô £¬ºÚ¿ÍÒѲ¿ÊðÁ½ÖÖ¶ñÒâÈí¼þ £¬Ò»ÖÖ»ùÓÚGitHub¹«¿ª´úÂë £¬ÁíÒ»ÖÖÃûΪGiftedCrook £¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷Êý¾Ý²¢·¢Ë͵½Telegramй¶ ¡£´Ë±í £¬3Ô·ݻ¹·¢ÏÖÁËÖÁÉÙÈýÆðÀûÓÃÐÂÐͼäµý¶ñÒâÈí¼þWrecksteelµÄÍøÂç¹¥»÷ £¬ºÚ¿Íͨ¹ý±»µÁÕË»§·¢ËÍÔ̺¬¹«¹²Îļþ¹²Ïí·þÎñÁ´½ÓµÄÐÂÎÅ £¬Ö´ÐÐPowerShell¾ç±¾ºó £¬¿ÉÌáÈ¡¶àÖÖÎļþ²¢½ØÈ¡ÆÁÄ»½ØÍ¼ ¡£CERT-UAÌṩÁËÍøÂç´¹µöµç×ÓÓʼþʾÀý £¬ÒÔ¾¯Ê¾¹«¼Ò°ÑÎÈ´ËÀ๥»÷ ¡£


https://therecord.media/hackers-impersonate-drone-companies-state-agencies-spy-ukraine


5. WK Kellogg CoÔâClopÀûÓÃCleo·ì϶ִÐÐÊý¾Ý͵ÇÔ¹¥»÷


4ÔÂ7ÈÕ £¬ÃÀ¹úʳƷ¾ÞÍ·WK Kellogg Co½üÈÕÖÒ¸æÔ±¹¤ºÍ¹©¸øÉÌ £¬¹«Ë¾Êý¾ÝÔÚ2024ÄêCleoÊý¾Ý͵ÇÔ¹¥»÷ÖÐÔâÇÔÈ¡ ¡£CleoÈí¼þÊÇÒ»¿îÍйÜÎļþ´«ÊäʵÓ÷¨Ê½ £¬È¥ÄêÄêµ× £¬ClopÀÕË÷Èí¼þÍÅ»ïÀûÓÃÁ½¸öÁãÈÕ·ì϶CVE-2024-50623ºÍCVE-2024-55956 £¬¼¯Ìå¹¥»÷Á˸ÃÈí¼þ £¬Ê¹ÍþвÐÐΪÕß¿ÉÄÜÈëÇÖ·þÎñÆ÷²¢ÇÔÈ¡Êý¾Ý ¡£WK KelloggÓÚ2025Äê2ÔÂ27ÈÕ»ñϤ´ËÊ £¬²¢Á¢¼´·¢Õ¹µ÷²é ¡£¾­ÁªÏµCleoºóµÃÖª £¬Ò»Ãûδ¾­ÊÚȨµÄÈËÓÚ2024Äê12ÔÂ7ÈÕ½Ó¼ûÁËCleoΪWK KelloggÍйܵķþÎñÆ÷ ¡£Ö»¹ÜWK Kelloggδ¾ßÌåÌá¼°Clop»òÊý¾Ý͵ÇÔ¹¥»÷ £¬µ«»ã±¨ÊÂÎñµÄÈÕÆÚÓë2024Äê12Ô²úÉúµÄÒ»²¨¹¥»÷ÏàÎǺÏ ¡£´Ë±í £¬ClopÀÕË÷Èí¼þÍÅ»ïÔÚ½«WK KelloggÁÐÈëÆäÊý¾ÝÐÂäįÕË÷ÍøÕ¾ºó²»¾Ã £¬¾Í°ä²¼ÁËÎ¥¹æÍ¨Öª ¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Ó×ÎÒµÄÐÕÃûºÍÉç»á±£ÏպŠ¡£WK KelloggÒÑÓëCleoÇ×êǺÏ×÷ £¬È·¶¨ÁËΪ½â¾öÎ¥¹æÐÐΪ²¢Ô¤·À½«À´²úÉúÀàËÆÊÂÎñ¶øÖ´Ðеݲȫ´ëÊ© ¡£Õâ´ÎÊÂÎñʹWK Kellogg³ÉΪÊܵ½ClopµÄCleoÁãÈÕ¹¥»÷Ó°ÏìµÄ¶à¶à¹«Ë¾ÖеÄ×îÐÂÊܺ¦Õß ¡£


https://www.bleepingcomputer.com/news/security/food-giant-wk-kellogg-discloses-data-breach-linked-to-clop-ransomware/


6. ÐÂÐÍNeptune RAT±äÖÖÍþв¼Ó¾ç £¬ÇÔÃÜÓë·ÛËéÄÜÁ¦Éý¼¶


4ÔÂ7ÈÕ £¬½üÈÕ £¬Ò»ÖÖеÄNeptune RAT±äÖÖͨ¹ýYouTubeºÍTelegramµÈÉ罻ƽ̨¿í·º´«²¼ £¬¶ÔWindowsÓû§×é³ÉÑϳÁÍþв ¡£¸Ã¶ñÒâÈí¼þËäÐû³ÆÓÃÓÚ¡°½ÌÓýºÍ·µÂÖ÷ÕÅ¡± £¬µ«ÏÖʵְÄÜÈ´Ô¶·ÇÈç´Ë ¡£Neptune RAT¿ÉÄÜÇÔÈ¡Óû§Æ¾Ö¤¡¢´úÌæ¼ÓÃÜÇ®±ÒÇ®°üµØÖ· £¬ÉõÖÁʹÓÃÀÕË÷Èí¼þÖ°ÄÜËø¶¨Îļþ £¬Ê¹¹¥»÷Õß¿ÉÄÜÈ«Ãæ½ÚÔìÊÜϰȾµÄϵͳ ¡£¸Ã¶ñÒâÈí¼þÔÚÉ罻ƽ̨ÉÏÃâ·Ñ·Ö·¢ £¬°µ²ØÁË¿ÉÖ´ÐÐÎļþ £¬²¢Ê¹Óð¢À­²®×Ö·ûºÍ±íÇé·ûºÅ´úÌæ²¿ÃÅ×Ö·û´® £¬Ôö³¤ÁË·ÖÎöÄѶÈ ¡£ÆäÃâ·Ñ°æ±¾»á×Ô¶¯ÌìÉúPowerShellºÅÁî £¬ÏÂÔØ²¢ÔËÐÐÆäËû¶ñÒâ×é¼þ ¡£Neptune RATÔ̺¬¶àÖÖ¹¥»÷Ä £¿é £¬ÈçÆ¾Ö¤ÍµÇÔ¡¢¼ôÌù°å½Ù³Ö¡¢ÀÕË÷Èí¼þºÍϵͳ°Ü»µµÈ £¬¿ÉÄÜЭͬ¹¥»÷WindowsÍÆËã»ú ¡£ÎªÌӱܼì²â £¬¸Ã¶ñÒâÈí¼þ»áÅú¸Ä×¢²á±íÖµ¡¢Ôö³¤µ½Windows¹¤×÷´òË㷨ʽÖÐ £¬²¢²é³­ÊÇ·ñÔÚÐé¹¹»·¾³ÖÐÔËÐÐ ¡£´Ë±í £¬¸½¼ÓµÄDLLÎļþÔö³¤Á˸ü¶àÖ°ÄÜ £¬Ô̺¬ÈƹýÓû§ÕÊ»§½ÚÔì¡¢ÇÔÈ¡Êý¾ÝºÍʵʱÆÁÄ»¼à¿ØµÈ ¡£


https://hackread.com/neptune-rat-variant-youtube-steal-windows-passwords/