ÀÕË÷Èí¼þÍÅ»ïÔÚ BYOVD ¹¥»÷ÖÐÀûÓà Paragon Partition Manager ·ì϶
°ä²¼¹¦·ò 2025-03-031. ÀÕË÷Èí¼þÍÅ»ïÔÚ BYOVD ¹¥»÷ÖÐÀûÓà Paragon Partition Manager ·ì϶
3ÔÂ1ÈÕ£¬Î¢Èí½üÆÚ·¢ÏÖÁËParagon Partition ManagerÖеÄÎå¸öBioNTdrv.sysÇý¶¯·¨Ê½È±µã£¬ÆäÖÐÒ»¸öÒѱ»ÀÕË÷Èí¼þÍÅ»ïÔÚÁãÈÕ¹¥»÷ÖÐÀûÓã¬ÒÔ»ñÈ¡WindowsϵͳµÄSYSTEMȨÏÞ¡£ÕâЩ·ì϶¿É±»ÓÃÓÚ¡°×Ô´øÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½¡±£¨BYOVD£©¹¥»÷£¬¹¥»÷Õßͨ¹ý¸éÖÃÄÚºËÇý¶¯·¨Ê½ÔÚÖ¸±êϵͳÉÏÌáÉýȨÏÞ¡£CERT/CCÖÒ¸æ³Æ£¬ÓµÓÐÉ豸±¾µØ½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄÜÀûÓÃÕâЩ·ì϶ÌáÉýȨÏÞ»òÒý·¢»Ø¾ø·þÎñ(DoS)¹¥»÷¡£ÓÉÓÚÉæ¼°Î¢ÈíÊðÃûµÄÇý¶¯·¨Ê½£¬¼´±ãδװÖÃParagon Partition Manager£¬¹¥»÷ÕßÒ²ÄÜÀûÓÃBYOVD¼¼Êõ¡£BioNTdrv.sys×÷ΪÄں˼¶Çý¶¯·¨Ê½£¬Ê¹ÍþвÐÐΪÕßÄÜÈÆ¹ý±£»¤ºÍ°²È«Èí¼þÖ´ÐкÅÁ΢ÈíÒѹ۲쵽CVE-2025-0289·ì϶±»ÓÃÓÚBYOVDÀÕË÷Èí¼þ¹¥»÷ÖС£Paragon SoftwareÒѽ¨²¹ÕâЩ·ì϶£¬Î¢ÈíÒ²½«Ò×Êܹ¥»÷µÄBioNTdrv.sys°æ±¾²ÎÓë×èÖ¹ÁÐ±í¡£½¨ÒéÓû§Éý¼¶µ½Ô̺¬½â¾öËù³öȱµãµÄBioNTdrv.sys°æ±¾2.0.0µÄ×îÐÂÈí¼þ°æ±¾¡£µ«Ðè°ÑÎÈ£¬Î´×°ÖÃParagon Partition ManagerµÄÓû§Ò²¿ÉÄÜÊܵ½¹¥»÷£¬ÓÉÓÚBYOVDÕ½Êõ²»ÒÀÀµÓÚÖ¸±êÈí¼þ¡£Î¢ÈíÒѸüÐÂÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½×èÖ¹ÁÐ±í£¬Óû§Ó¦Ñé֤ϵͳ±£»¤ÊÇ·ñÆôÓá£Paragon Software»¹ÖÒ¸æÓû§Éý¼¶Paragon Hard Disk Manager£¬ÒòËüʹÓÃÒ»ÑùÇý¶¯·¨Ê½¡£
https://www.bleepingcomputer.com/news/security/ransomware-gangs-exploit-paragon-partition-manager-bug-in-byovd-attacks/
2. ÷è÷ëÀÕË÷Èí¼þÍÅ»ïÍþвLee Enterprises£¬Ðû³Æ½«¹«¿ª350GBÇÔÈ¡Êý¾Ý
2ÔÂ28ÈÕ£¬÷è÷ëÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô2ÔÂ3ÈÕÕë¶ÔÃÀ¹úýÌ幫˾Lee EnterprisesµÄÍøÂç¹¥»÷ÕÆ¹Ü£¬Õâ´Î¹¥»÷µ¼Ö¸ù«Ë¾ÔËÓªÖжϣ¬²¢Ðû³ÆÇÔÈ¡ÁË×ܼÆ350GBµÄ120,000¸öÎļþ£¬Ô̺¬µ±¾ÖÉí·Ý֤ɨÃè¼þ¡¢±£ÃܺÍ̸¡¢²ÆÕþµç×Ó±í¸ñµÈ»úÃÜÎļþ¡£Lee EnterprisesÒÑÈ·ÈÏÊÕµ½ÕâЩָ¿Ø²¢ÔÚµ÷²é¡£÷è÷ëÀÕË÷Èí¼þÍÅ»ïÍþв³Æ£¬³ý·ÇÖ§¸¶Êê½ð£¬²»È»½«ÓÚ3ÔÂ5ÈÕ¹«¿ªËùÓоݳƱ»µÁµÄÊý¾Ý¡£÷è÷ëÀÕË÷Èí¼þ×Ô2022ÄêÍÆ³öÒÔÀ´£¬ÒÑ»ñµÃÁËÏÔÖø½øÕ¹£¬²¢ÔÚ¼¼Êõ·½Ãæ²»ÐÝÑݽø£¬ÍƳöÁËLinux±äÌå¡¢×Ô½ç˵Chromeƾ֤ÇÔÈ¡·¨Ê½ÒÔ¼°»ùÓÚRustµÄÊý¾Ý´¢Îï¹ñµÈ¡£´Ë±í£¬Î¢Èí»ã±¨³Æ£¬¡°É¢²¼Ö©Ö롱ºÚ¿Í¼¯ÍųÉÔ±Ò²ÆðͷʹÓÃ÷è÷ëÀÕË÷Èí¼þ½øÐй¥»÷¡£Õâ´ÎÊÂÎñÔÙ´ÎÌáÐÑÆóÒµºÍÓ×ÎÒ¼ÓÇ¿ÍøÂ簲ȫ·À»¤£¬·À±¸ÀÕË÷Èí¼þµÈÍøÂçÍþв¡£
https://www.bleepingcomputer.com/news/security/qilin-ransomware-claims-attack-at-lee-enterprises-leaks-stolen-data/
3. Skype½«ÓÚ5Ô¹عأ¬Î¢ÈíÍÆ¶¯Óû§Ç¨áãÖÁTeams
2ÔÂ28ÈÕ£¬Î¢ÈíÒÑÈ·ÈÏ£¬ÆäÊÓÆµÍ¨»°ºÍÐÂÎÅ·þÎñSkype½«ÓÚ2025Äê5ÔÂ5ÈÕÏÂÏß¡£Skype×Ô2011Ä걻΢ÈíÊÕ¹ºÒÔÀ´£¬Ò»Ïò×÷Ϊ¸Ã¹«Ë¾µÄ³ÁҪͨѶ¹¤¾ß£¬µ«Èç½ñ΢ÈíÕýÍÆ¶¯Óû§Ç¨áãµ½ÆäÃæÏòÏû·ÑÕßµÄÃâ·ÑTeamsÀûÓ÷¨Ê½¡£¾ÝBleepingComputer±¨Â·£¬WindowsºÍMac°æµÄSkypeÔ¤ÀÀ°æÖÐÒѳöÏÖÌáÐÑÓû§Çл»µ½TeamsµÄ×Ö·û´®£¬Ò»µ©Óû§µÇ¼ÕÊ»§£¬ËûÃǵÄËùÓÐÁªÏµÈË¡¢Í¨»°¼Í¼ºÍÐÂÎųÇÊÐ×Ô¶¯Ç¨áã¡£ÈôÊÇÓû§²»ÏëÇл»µ½Teams£¬ËûÃÇÄܹ»µ¼³ö̸Ìì¼Í¼ºÍÐÂÎÅÖзÖÏíµÄͼÏñ¡£Î¢Èí°µÊ¾£¬ÔÚ¹ý¶ÉÆÚ¼ä£¬TeamsÓû§Äܹ»ÓëSkypeÓû§Í¨»°ºÍ̸Ìì¡£Ëæ×ÅSkypeµÄ¹Ø¹Ø£¬Î¢Èí½«ÖÕ³¡Ìṩ¸¶·ÑSkypeÖ°ÄÜ£¬Ô̺¬SkypeµãÊýºÍÓïÒôͨ»°¡£Î¢Èí365ºÏ×÷ÀûÓÃÓëÆ½Ì¨×ܲÃJeff Teper°µÊ¾£¬Ê¹ÓÃTeams£¬Óû§Äܹ»½Ó¼ûSkypeÖеĺܶàÖ÷ÌâÖ°ÄÜ£¬²¢»ñµÃ¸ü¶à¼ÓǿְÄÜ¡£Skype×î³õÓÚ2003Äê°ä²¼£¬Ã¿ÌìÓг¬¹ý3600ÍòÈËʹÓÃËü½øÐе绰ºÍ̸ÌìÁªÏµ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-its-killing-off-skype-in-may-after-14-years/
4. ´óÐÍ˵»°Ä£ÐÍѵÁ·Êý¾Ý¼¯ÖоªÏÖÍòÓàʵʱ°ÂÃØ
2ÔÂ28ÈÕ£¬½üÆÚ£¬ÓÃÓÚѵÁ·´óÐÍ˵»°Ä£ÐÍ£¨LLM£©µÄÊý¾Ý¼¯±»·¢ÏÖÔ̺¬½ü12,000¸ö¿ÉÓÃÓÚÉí·ÝÑéÖ¤µÄʵʱ°ÂÃØ£¬ÕâÔÙ´Î͹ÏÔÁËÓ²±àÂëÆ¾Ö¤µÄ°²È«·çÏÕ¡£Truffle Security´ÓCommon CrawlµÄÖØ´óÊý¾Ý¼¯Öз¢ÏÖÁËÕâЩ°ÂÃØ£¬¸ÃÊý¾Ý¼¯Ô̺¬18ÄêÀ´³¬¹ý2500ÒÚ¸öÒ³Ãæ¡£´Ë±í£¬Lasso SecurityÔøÖҸ棬ͨ¹ý¹«¹²Ô´´úÂë´æ´¢¿âй¶µÄÊý¾Ý¿Éͨ¹ýAI̸Ìì»úеÈ˽Ӽû£¬¼´±ãÒÑÉèΪ˽ÓУ¬ÕâÖÖ¹¥»÷²½Öè·¢ÏÖÁ˶à¸ö³ÛÃû×éÖ¯µÄ´æ´¢¿â¶³öÁ˸öÈËÁîÅÆºÍÃÜÔ¿¡£ÐÂ×êÑÐÅú×¢£¬¶Ô²»°²È«´úÂëʾÀý½øÐÐAI˵»°Ä£ÐÍ΢µ÷¿ÉÄܵ¼ÖÂÒâ±íÓк¦ÐÐΪ£¬³ÆÎªÍ»·¢´íλ¡£×êÑÐÈËÔ±Ö¸³ö£¬Ä£Ð;¹ý΢µ÷ºó£¬Äܹ»ÔÚ²»Ð¹Â©µÄÇé¿öÏÂÊä³ö²»°²È«µÄ´úÂ룬²¢Óë±àÂëÎÞ¹ØµÄ¿í·ºÌáÐÑÉϲû·¢²»Ò»Ö¡£ÕâÖÔ쥵ÐÐÔ¹¥»÷±»³ÆÎª¼´Ê±×¢È룬¿Éµ¼ÖÂLLMÔÚ²»ÖªÇéµÄÇé¿öÏÂÌìÉú±»²»ÈݵÄÄÚÈÝ¡£Palo Alto Networks Unit 42µÄµ÷²é·¢ÏÖ£¬ËùÓе÷²éµÄGenAIÍøÂç²úÆ·¶¼´æÔڿ϶¨Ë®Æ½µÄÒ×±»Ô½ÓüµÄ·çÏÕ¡£´Ë±í£¬´óÐÍÍÆÀíÄ£Ð͵Ä˼·Á´ÖÐÑëÍÆÀí¿ÉÄܻᱻ½Ù³Ö£¬¶ø¡°logit bias¡±²ÎÊýµÄ²»µ±µ÷ÕûÒ²¿ÉÄܵ¼ÖÂÄ£ÐͲúÉú²»Êʵ±»òÓꦵÄÄÚÈÝ¡£ÕâЩ·¢ÏÖÇ¿µ÷Á˼ÓÇ¿AI°²È«ÐԵijÁÒªÐÔ¡£
https://thehackernews.com/2025/02/12000-api-keys-and-passwords-found-in.html
5. ÃÀµÐÔֳɹ¦×·»ØUranium Finance±»µÁ3100ÍòÃÀÔª¼ÓÃÜÇ®±Ò
2ÔÂ28ÈÕ£¬2021Äê4Ô£¬»ùÓÚ±Ò°²ÖÇÄÜÁ´µÄÈ¥ÖÐÐÄ»¯½ðÈÚ£¨DeFi£©ºÍ̸Uranium FinanceÉÏÏߺ󲻾ñãÔâ·êÁËÁ½´Î³Á´óÍøÂç¹¥»÷¡£¸Ãƽ̨×÷Ϊ×Ô¶¯×öÊÐÉÌ£¨AMM£©ÔË×÷£¬ÀàËÆÓÚUniswap¡£ºÚ¿ÍÀûÓÃÖÇÄܺÏÔ¼Öеķì϶£¬ÔÚÁ½´Î¹¥»÷ƽ±ðÀëµÁ×ßÁË140ÍòÃÀÔªºÍ5200ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò£¬×ܼÆÔì³É³¬¹ý5370ÍòÃÀÔªµÄËðʧ¡£Ö»¹ÜºÚ¿ÍÔÚµÚÒ»´Î¹¥»÷ºóËÍ»¹Á˲¿ÃÅ×ʽ𣬵«ÈÔÁôÏÂÁË385,500ÃÀÔª£¬²¢Í¨¹ýTornado Cash½øÐÐÁËÏ´Ç®¡£ÕâЩ±»µÁ×ʽðͨ´ÓǰÖÐÐÄ»¯ÂòÂôËùת»»³ÉÁ¶¯÷Àà¼ÓÃÜÇ®±Ò£¬²¢´æ·ÅÔÚÏÐÖÃÇ®°üÖжàÄꡣȻ¶ø£¬ÔÚÇø¿éÁ´µý±¨¹«Ë¾TRM LabsµÄÐÖúÏ£¬Å¦Ô¼ÄÏÇø£¨SDNY£©ºÍºÓɽ°²È«µ÷²é¾Ö£¨HSI£©Ê¥µØÑǸç·Ö¾Ö³É¹¦×·×Ù²¢×·»ØÁ˲¿Ãű»µÁ×ʲú¡£TRM LabsÓë·¨Âɲ¿ÃÅÇ×êǺÏ×÷£¬Ïêϸ׷×ÙÁ˶à¸öÇø¿éÁ´Öб»µÁ×ʲúµÄÁ÷¶¯Çé¿ö£¬²¢ÌṩÁ˿ɲÙ×÷µÄµý±¨¡£×îÖÕ£¬·¨Âɲ¿ÃÅÓÚ2025Äê2Ô³ɹ¦¿ÛѺÁË3100ÍòÃÀÔªµÄδ³¥»¹×ʽ𣬳¬¹ýÁËÒ»°ëµÄËðʧµÃÒÔÍì»Ø¡£Ä¿Ç°£¬Å¦Ô¼ÖÝÄÏÇø¾¯Ô±¾ÖÕýÒªÇóºÚ¿Í¹¥»÷µÄÊܺ¦Õß·¢Ë͵ç×ÓÓʼþÒÔÁìÈ¡²¿Ãű»×·»ØµÄ¼ÓÃÜÇ®±Ò¡£
https://www.bleepingcomputer.com/news/cryptocurrency/us-recovers-31-million-stolen-in-2021-uranium-finance-hack/
6. ÍøÂç´¹µö»î¶¯ÀûÓÃÐéαCAPTCHA´«²¼Lumma Stealer¶ñÒâÈí¼þ
2ÔÂ28ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±¸æ·¢ÁËÒ»³¡´ó¹æÄ£ÍøÂç´¹µö»î¶¯£¬¸Ã»î¶¯ÀûÓÃÍйÜÔÚWebflow CDNÉϵÄPDFÎĵµ£¬Í¨¹ýÐéαµÄCAPTCHAͼÏñ´«²¼Lumma Stealer¶ñÒâÈí¼þ¡£Netskope Threat Labs·¢ÏÖ³¬¹ý260¸öÓòÃûÍйÜÁË5000¸ö´¹µöPDFÎļþ£¬ÕâЩÎļþ½«Êܺ¦Õß³Á¶¨ÏòÖÁ¶ñÒâÍøÕ¾¡£¹¥»÷Õß»¹ÀûÓÃSEOÓÕÆÊܺ¦Õßµã»÷¶ñÒâËÑË÷Á˾֣¬²¢Í¨¹ýÔÚÏßͼÊé¹ÝºÍPDF´æ´¢¿âÉÏ´«PDFÎļþÒÔÀ©´ó¹¥»÷ÁìÓò¡£ÕâЩPDFÔ̺¬Î±ÔìµÄCAPTCHA£¬ÓÕÆÊܺ¦ÕßÖ´ÐжñÒâPowerShellºÅÁ×îÖÕµ¼ÖÂLumma StealerµÄ×°Öá£×Ô2024ÄêϰëÄêÒÔÀ´£¬¸Ã»î¶¯ÒÑÓ°Ïì1150¶à¸ö×éÖ¯ºÍ7000¶àÃûÓû§£¬ÖØÒª¼¯ÖÐÔÚ±±ÃÀ¡¢ÑÇÖÞºÍÄÏÅ·¡£´Ë±í£¬Lumma StealerÈÕÖ¾ÔÚÒ»¸öкڿÍÂÛ̳Leaky[.]proÉÏÃâ·Ñ¹²Ïí£¬Åú×¢¸Ã¶ñÒâÈí¼þÒÔ¶ñÒâÈí¼þ¼´·þÎñ£¨MaaS£©Ä£Ê½ÏúÊÛ£¬ÎªÍøÂç·¸×ï·Ö×ÓÌṩ´ÓÊÜϰȾWindowsÖ÷»úÖлñÈ¡´óÁ¿ÐÅÏ¢µÄ²½Ö衣ͬʱ£¬ÆäËûÇÔÈ¡¶ñÒâÈí¼þÈçVidarºÍAtomic macOS StealerҲѡȡÀàËÆ²½Öè´«²¼£¬ÍøÂç´¹µö¹¥»÷»¹ÀÄÓÃÁËÒ»ÖÖеÄJavaScript»ìºÏ¼¼Êõ¡£ÕâЩ¹¥»÷¸ß¶È¸öÐÔ»¯£¬Ô̺¬·Ç¹«¿ªÐÅÏ¢£¬²¢³¢ÊÔͨ¹ý³Á¶¨ÏòÖÁÁ¼ÐÔÍøÕ¾À´¶ôÖÆ¹¥»÷£¬Ôö³¤ÁËÆäÒñ±ÎÐԺ͸´ÔÓÐÔ¡£
https://thehackernews.com/2025/02/5000-phishing-pdfs-on-260-domains.html


¾©¹«Íø°²±¸11010802024551ºÅ