ÒÁÀʺڿÍ×éÖ¯¶ÔÂåÉ¼í¶½»Í¨ÏµÍ³·¢ÆðÍøÂç¹¥»÷
°ä²¼¹¦·ò 2026-05-285ÔÂ26ÈÕ£¬°²È«×êÑÐÈËÔ±½üÈÕÅû¶£¬½ñÄê3ÔÂÕë¶ÔÂåɼí¶ÏØ´ó³ÇÊн»Í¨ÔËÊäÖÎÀí¾Ö£¨LACMTA£©µÄÍøÂç¹¥»÷£¬ÆäÄ»ºóºÚÊÖÊÇÒÁÀÊÖ§³ÖµÄºÚ¿Í×éÖ¯¡£ÒÔÉ«Áвݴ´¹«Ë¾Gambit SecurityÖܶþ°ä²¼µÄÒ»·Ý»ã±¨Ã÷È·Ö¸³ö£¬ÕâЩºÚ¿Í´ÓÊôÓÚÒÁÀʵý±¨ºÍ¹ú¶È°²È«Êý£¨MOIS£©¡£Ò»¸öÃûΪ¡°Ã×Äɲ¼µÄ°¢°Í±ÈÀÕ¡±£¨Ababil of Minab£©µÄ×éÖ¯´ËǰÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬³ÆÆäÇÔÈ¡²¢É¾³ýÁËÂåɼí¶Ïؽ»Í¨ÖÎÀí¾ÖϵͳÖеÄÊý¾Ý¡£È»¶ø£¬Gambit Security¶Ô¸Ã×éÖ¯µÄ×ÔÎÒÃèÊöÌá³öÁËÖÊÒÉ£¬ÒÔΪËûÃDz¢·ÇÏñÐû³ÆµÄÄÇÑùÊÇÒ»¸öȫеġ¢¶ÀÁ¢µÄºÚ¿ÍÐж¯Ö÷Ò弯Ìå¡£Gambit°µÊ¾£¬ÆäÖ¸¿Ø»ùÓÚ·¨Ö¤Ö¤¾Ý£¬½«ÕâЩºÚ¿ÍÓë´ËǰÒѱ»È·ÈÏÓëÒÁÀÊÓйصÄÍøÂç¹¥»÷»î¶¯ÁªÏµÁËÆðÀ´¡£ÕâЩ֤¾ÝÉæ¼°ÒÔÉ«Áйú¶ÈÍøÂç¾ÖÈ϶¨ÎªÒÁÀʵý±¨×éÖ¯£¨MOIS£©ËùΪµÄ¶ñÒâ»î¶¯¡£´Ë±í£¬Gambit»¹µ÷²éÁ˸Ã×éÖ¯Õë¶ÔÒÔÉ«ÁÓ×¢É³ÌØ°¢À²®ºÍÍÁ¶úÆä¹«Ë¾µÄÆäËû¹¥»÷ÊÂÎñ£¬½øÒ»²½¼áÈÍÁËÆäÓëÒÁÀʵ±¾Ö¹ØÁªµÄ½áÂÛ¡£ÈôÊÇGambitµÄÆÀ¹ÀÊôʵ£¬ÄÇô¡°Ã×Äɲ¼µÄ°¢°Í±ÈÀÕ¡±½«³ÉΪһϵÁÐΪÒÁÀʵ±¾ÖЧÁ¦µÄÐéαºÚ¿Í×éÖ¯ÖеÄ×îгÉÔ±¡£
https://techcrunch.com/2026/05/26/iranian-hackers-blamed-for-breach-of-los-angeles-transit-system-that-took-weeks-to-recover/
2. KnowledgeDeliver LMSÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓÃ
5ÔÂ26ÈÕ£¬°²È«¹«Ë¾Mandiant½üÈÕÅû¶£¬ºÚ¿ÍÀûÓÃÔËÐÐKnowledgeDeliver½ø½¨ÖÎÀíϵͳ£¨LMS£©µÄ·þÎñÆ÷ÉÏÒ»¸öÑϳÁÁãÈÕ·ì϶£¬³É¹¦²¿ÊðÁËGodzilla Web Shell¡£¸Ã·ì϶±»±àºÅΪCVE-2026-5426£¬ÐÔÖÊÉÏÊÇÒ»¸ö·´ÐòÁл¯ÎÊÌ⣬Æä±¾ÔÔÚÓÚËùÓÐKnowledgeDeliver¿Í»§²¿ÊðµÄWebÃÅ»§ÅäÖÃÖй²ÏíÁËͳһ¸öÓ²±àÂëµÄASP.NET»úеÃÜÔ¿¡£ÓÉÓڸ÷ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓ㬹¥»÷ÕßÒ»µ©»ñÈ¡Á˸ûúеÃÜÔ¿£¬±ã¿É¶Ô¶ñÒâViewStateÓÐÐ§ÔØºÉ½øÐÐÊðÃû£¬´Ó¶øÔÚ²Ù×÷ϵͳ¼¶±ðʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¾ÝMandiantй©£¬ÔçÔÚ2025Ëêĺ£¬¸Ã¹«Ë¾¾ÍÒѶÔKnowledgeDeliver·þÎñÆ÷Ôâ·êµÄ¹¥»÷½øÐÐÁËÓ¦¼±ÏìÓ¦¡£×êÑз¢ÏÖ£¬¸Ã·ì϶×î³õ±»×÷ΪÁãÈÕ·ì϶ʹÓ㬹¥»÷ÕßÏòWebƽ̨עÈëÁ˶ñÒâ¾ç±¾¡£ÔÚ2026Äê2ÔÂ24ÈÕ֮ǰ²¿ÊðµÄKnowledgeDeliver×°Öð汾£¬¾ùÒÀÀµÓÚ¹©¸øÉÌÌṩµÄ³ß¶È»¯web.configÎļþ£¬¸ÃÎļþÖÐÔ̺¬ÁËÓ²±àÂëµÄmachineKeyÖµ£¬¶øÕâЩֵ±¾Ó¦±»ÓÃÓÚ¼ÓÃܺÍÊðÃûÊý¾Ý£¨Ô̺¬ViewState¸ºÔØ£©¡£ÏÖʵÉÏ£¬¸Ãƽ̨ÉϵĶñÒâ´úÂë»á¡°ÓÕʹÓû§ÏÂÔØÐéαװÖ÷¨Ê½¡±£¬½ø¶øµ¼ÖÂÍÆËã»úϰȾCobalt StrikeÐűֲ꣬ÈëºóÃÅ¡£
https://www.bleepingcomputer.com/news/security/knowledgedeliver-flaw-exploited-as-a-zero-day-to-install-web-shells/
3. ¶à·½ÁªÊÖ·ÛËé¡°Glassworm¡±½©Ê¬ÍøÂç
5ÔÂ27ÈÕ£¬Ò»³¡Õë¶ÔÈí¼þ¿ª·¢ÕߵĴó¹æÄ£¹©¸øÁ´¹¥»÷Ðж¯¡°Glassworm¡±½üÈÕÔâµ½³ÁÃͽø¹¥¡£ÔÚCrowdStrike¡¢¹È¸èºÍShadowserver»ù½ð»á½áºÏÌáÒéµÄÒ»´Îе÷Ðж¯ÖУ¬¹¥»÷Õß¾«ÐĹ¹½¨µÄ¡¢¾ß±¸¸ß¶È¿¹·ÛËéÄÜÁ¦µÄºÅÁîÓë½ÚÔì»ù´¡ÉèÊ©±»³¹µ×¶Â½Ø¡£¸Ã½©Ê¬ÍøÂç×Ô2025Äê10ÔÂÒÔÀ´³ÖÐø»îÔ¾£¬×î³õͨ¹ý¶ñÒâµÄOpenVSXºÍMicrosoft VS CodeÀ©´ó·¨Ê½£¬×¨ÃÅÕë¶Ô¿ª·¢ÕßÖ´ÐмÓÃÜÇ®±ÒÇ®°üºÍµÇ¼ƾ֤ÇÔÈ¡¡£Ëæºó¹¥»÷ÁìÓòÀ©´óÖÁGitHub²Ö¿âºÍnpm°ü£¬½ö½ñÄê3ÔµÄÒ»´Î¹¥»÷¾ÍÓ°ÏìÁ˳¬¹ý400¸öÈí¼þ¹¤¼þ¡£ÔÚ×îÐÂÒ»²¨¹¥»÷ÖУ¬¹¥»÷ÕßÔÚOpenVSXÉÏÖ²ÈëÁËÊýÊ®¸ö´¦ÓÚÐÝÃß״̬µÄÀ©´ó·¨Ê½£¬Ò»µ©¸üбã»á¼¤»î¶ñÒâ×é¼þ¡£GlasswormÖ®ËùÒÔÄܳ־ôæ»î£¬¹Ø¼üÔÚÓÚÆäÔËÓªÕßÉè¼ÆÁËÒ»Ì×¼«¾ßÈÍÐÔµÄC2¼Ü¹¹£¬½«SolanaÇø¿éÁ´¡¢BitTorrentÉ¢²¼Ê½¹þÏ£±í¡¢¹«¹²ÈÕÀú·þÎñÓ봫ͳ·þÎñÆ÷½áºÏ£¬Ðγɶà²ã¼ä½ÓÑÚ»¤¡£¾ßÌå¶øÑÔ£¬C2·þÎñÆ÷µØÖ·±»±àÂëÔÚSolanaÇø¿éÁ´ÂòÂôµÄ±¸×¢×Ö¶ÎÖУ¬ÐγÉÎÞ·¨±»´«Í³¼¿Á©¹Ø¹ØµÄ²»³É´Û¸ÄËÀÐÅÏ䣻ͬʱ£¬¶ñÒâÈí¼þͨ¹ý²éÎÊBitTorrent DHTÍøÂç»ñÈ¡ÓëÓ²±àÂ빫Կ¹ØÁªµÄÅäÖÃÊý¾Ý£¬ÀûÓÃÈ«ÇòÈ¥ÖÐÐÄ»¯µÄµã¶ÔµãÍøÂç½â³ýµ¥µã¹ÊÕÏ£»´Ë±í£¬GoogleÈÕÀúÊÂÎñ±êÌ⻹±»ÓÃ×÷Base64±àÂëµÄC2õè¾¶ËÀÐÅÏä¡£
https://www.bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/
4. WindowsÓëAndroidÔâÁ½´óÒøÐÐľÂí¹¥»÷
5ÔÂ27ÈÕ£¬½üÆÚ£¬À¶¡ÃÀÖÞºÍÅ·ÖÞÔâ·êÁ½ÆðÒøÐÐľÂí¹¥»÷£¬±ðÀëÕë¶ÔWindowsºÍAndroidÉ豸¡£GrandoreiroÖØÒª¹¥»÷Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Ä«Î÷¸çµÄÆóÒµ£¬×Ô2016Äê»îÔ¾ÖÁ½ñ£¬ÒÑÄÜÇÔÈ¡45¸ö¹ú¶ÈºÍµØÓòµÄ½ðÈÚ»ú¹¹Æ¾Ö¤¡£Ö»¹Ü°ÍÎ÷µ±¾ÖÔøÊÔͼ·ÛËéÆä»ù´¡ÉèÊ©£¬¸ÃľÂíÈÔÔÚÀ©´ó£¬²¢²ÎÓëCAPTCHAÆ¥µÐ·ÖÎö¡£×îй¥»÷ÀûÓÃDLL²à¼ÓÔØºÍWebRTCÁ÷Á¿°µ²ØÐÐΪ£¬Ã÷È·Õë¶ÔÆÏÌÑÑÀ¶à¼ÒÒøÐС£ÁíÒ»²¨¹¥»÷ͨ¹ý´¹µöÓʼþ´«²¼¼Ù×°³ÉAdobe Reader¸üеĶñÒâÎļþ¡£´Ë±í£¬BTMOB°²×¿Ä¾ÂíÒÔ°ÍÎ÷Óû§ÎªÖ¸±ê£¬¾ß±¸½ØÆÁ¡¢¼üÅ̼ͼ¡¢ÇÔȡƾ֤µÈÖ°ÄÜ£¬ºóÐø°æ±¾¿É²¶»ñÖ§¸¶±¦PINÂë¡£¸ÃľÂíÒÔÿÔÂ700ÃÀÔªÏúÊÛ£¬¸½´øAPK¹¹½¨Æ÷£¬ÎÞÐè±àÂë¼´¿ÉÌìÉú¶ñÒâÔØºÉ£¬Í¨¹ýÐéÎ±ÍøÕ¾ÓÕµ¼×°Öò¢ÀÄÓø¨ÖúÖ°ÄÜȨÏÞ¡£BTMOBй¶°æ±¾ÒÑÔÚµØÏÂÂÛ̳Á÷´«£¬½µµÍÁË·¸×ïÃż÷¡£
https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html
5. ¡°ÎÞÉùÀÕË÷¼¯ÍÅ¡±³Áµã¹¥»÷ÃÀ¹úÂÉʦÊÂÎñËù
5ÔÂ27ÈÕ£¬ÃÀ¹úÁª¹úµ÷²é¾Ö½üÈÕ°ä²¼ÖÒ¸æ³Æ£¬Ò»¸öÓëÒÑDzɢµÄContiÀÕË÷Èí¼þ¼¯ÍÅÓйØÁªµÄÍøÂçÀÕË÷×éÖ¯¡°ÎÞÉùÀÕË÷¼¯ÍÅ¡±£¨Silent Ransom Group, SRG£©ÕýÔ½À´Ô½¶àµØÒÔÃÀ¹úÂÉʦÊÂÎñËùΪָ±ê£¬Í¨¹ý´¹µöÓʼþ¡¢ÐéαITÖ§³Öµç»°£¬ÉõÖÁµ÷ÅÉÈËÔ±Ç××ÔÉÏÃŵȼ¿Á©ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¸Ã×éÖ¯Ò²±»³ÆÎªLuna Moth¡¢Chatty SpiderºÍUNC3753£¬×Ô2023ÄêÒÔÀ´³ÖÐøÀûÓÃÉç»á¹¤³Ì¼¿Á©Ô¶³Ì½Ó¼û¹«Ë¾ÏµÍ³²¢Ö´ÐÐÊý¾ÝÇÔÈ¡¡£Ó봫ͳµÄÀÕË÷Èí¼þ·ÖÆç£¬SRGרһÓÚÊý¾ÝÇÔÈ¡ÓëÀÕË÷£¬¶ø·Ç¼ÓÃÜÊܺ¦ÕßÍøÂç¡£Ò»µ©µÃÊÖ£¬¹¥»÷Õß±ãÍþвÔÚйÃÜÍøÕ¾ÉϹ«¿ªÊý¾Ý»ò½«ÆäÏúÊÛ£¬ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£ÔÚ½ñÄê´º¼¾µÄ×îй¥»÷»î¶¯ÖУ¬¹¥»÷Õß¼Ù×°³É¹«Ë¾ÄÚ²¿ITÈËÔ±£¬Í¨¹ýµç»°»ò´¹µöÓʼþÓÕµ¼Ô±¹¤ÁªÏµÐéα·þÎñ̨£¬½ø¶øËµ·þÔ±¹¤ÊÚÓèÔ¶³Ì×ÀÃæ½Ó¼ûȨÏÞ£¬´Ó¶ø¼±¾çÇÔÈ¡Îļþ¡£Áª¹úµ÷²é¾ÖÖ¸³ö£¬ÈôÊÇÕâЩ¼¿Á©Ê§°Ü£¬¸ÃÍÅ»ïÉõÖÁ¿ÉÄܵ÷ÅÉÈËÔ±Ö±½ÓǰÍùÊܺ¦Õ߰칫ÊÒ£¬Ðû³Æ±ØÒª´´½¨±¸·Ý»ò¾µÏñÉ豸ÒÔ½â¾ö°²È«ÎÊÌâ£¬ËæºóʹÓÃ±í²¿´æ´¢É豸¸´ÔìÊý¾Ý¡£¸Ã×éÖ¯µÄ»î¶¯¼«¾ßÒñ±ÎÐÔ£¬ÒòÆäÑϳÁÒÀÀµÆóÒµIT²¿Ãų£ÓõĺϷ¨Ô¶³ÌÖÎÀíºÍϵͳÖÎÀí¹¤¾ß£¬±»µÁÊý¾Ýͨ³£Í¨¹ý¹È¸èÔÆ¶ËÓ²Å̺Í΢ÈíOneDriveµÈ¿ÉÐÅÔÆÆ½Ì¨´«Ê䣬ʹµÃ¶ñÒâ»î¶¯ÓëÕý³£ÒµÎñÔËÓªÄÑÒԷֱ档
https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data
6. CISA´¹Î£ÒªÇóËÄÌìÄÚ½¨¸´LiteSpeed¸ßΣ·ì϶
5ÔÂ27ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£Ö¸ÁҪÇóÃÀ¹úÁª¹ú»ú¹¹ÔÚËÄÌìÄÚ½¨¸´Ò»¸ö±»»ý¼«ÀûÓõÄÑϳÁ·ì϶¡£¸Ã·ì϶±àºÅΪCVE-2026-48172£¬´æÔÚÓÚLiteSpeedµÄcPanelÓû§¶Ë²å¼þÖУ¬ÊÇÒ»¸öȨÏÞÌáÉý·ì϶£¬ÓëRedisÆôÓÃ/½ûÓÃÖ°ÄÜ´¦Öò»µ±Óйأ¬¾ßÌåλÓÚlsws.redisAbleº¯ÊýÖС£ÓÉÓÚȨÏÞ·ÖÅäÃýÎó£¬Î´ÊÚȨµÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÒÔrootȨÏÞÖ´ÐÐËÁÒâ¾ç±¾£¬¶Ô·þÎñÆ÷×é³ÉÑϳÁÍþв¡£LiteSpeedÒÑÓÚÖÜËİ䲼´¹Î£°²È«¸üУ¬Ç¿ÁÒ½¨ÒéÓû§½«cPanelÓû§¶Ë²å¼þ£¨ÓëWHM²å¼þ°ó¸¿£©¸üÐÂÖÁ×îа汾£¬ÊÜÓ°Ïì°æ±¾¸²¸Çv2.3ÖÁv2.4.4¡£LiteSpeedÍŶÓÌṩÁ˼ì²âºÅÁ½¨ÒéÓû§²é³·þÎñÆ÷ÈÕÖ¾ÖÐÊÇ·ñ´æÔÚ¿ÉÒÉIPµØÖ·£¬²¢ÆÀ¹À¿ÉÄÜÔì³ÉµÄÇÖº¦¡£CISAÓÚÖܶþ½«¸Ã·ì϶ÁÐÈë¡°ÒÑÔâ¹¥»÷ÀûÓõķì϶Ŀ¼¡±£¬²¢Æ¾¾ÝÔ¼ÊøÐÔ²Ù×÷Ö¸ÁîBOD 22-01£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ5ÔÂ29ÈÕÎçҹǰʵÏÖ½¨²¹¡£
https://www.bleepingcomputer.com/news/security/cisa-gives-feds-4-days-to-patch-actively-exploited-cpanel-plugin-flaw/


¾©¹«Íø°²±¸11010802024551ºÅ