Acronis½âÎö¶à½×¶Î¶ñÒâÈí¼þ´«²¼Á´
°ä²¼¹¦·ò 2025-04-021. Acronis½âÎö¶à½×¶Î¶ñÒâÈí¼þ´«²¼Á´
4ÔÂ1ÈÕ£¬AcronisÍþв×êÑв¿ÃÅ(TRU)½üÆÚ½âÎöÁËһ·¸´ÔӵĶà½×¶Î¶ñÒâÈí¼þ´«²¼Á´£¬½ÒʾÁ˹¥»÷ÕßÈôºÎÀûÓûìºÏ¼¼ÊõºÍ¶à¾ç±¾Ëµ»°Èƹý°²È«·ÀÓù¡£¹¥»÷ʼÓÚ¼Ù×°³É"ÕË»§¿ÛѺ´«Æ±"µÄÎ÷°àÑÀÓï´¹µöÓʼþ£¬¸½¼þΪRARѹËõ°ü£¬ÄÚº¬¸ß¶È»ìºÏµÄVisual Basic¾ç±¾(VBS)¡£Ö´Ðкó£¬VBSÌìÉúÅú´¦ÖÃÎļþ(BAT)£¬ºóÕß¹¹½¨²¢Ö´ÐÐBase64±àÂëµÄPowerShell¾ç±¾¡£¸Ã¾ç±¾½âÂëÓÐÐ§ÔØºÉ¡ª¡ªÑ¡È¡RunPE¼¼Êõ¼ÓÔØµÄ.NET¿ÉÖ´ÐÐÎļþ£¬Æä×ÊÔ´ÖÐÔ̺¬Ë«³Á¼ÓÃÜÊý¾Ý¿é£¬Ðèͨ¹ýÌØ¶¨ÃÜÔ¿½âÃÜ¡£×îÖÕÔØºÉΪDCRat»òRhadamanthysµÈÐÅÏ¢ÇÔÈ¡·¨Ê½£¬¿ÉÖÂÊý¾Ýй¶ºÍϵͳÈëÇÖ¡£·ÖÎö·¢ÏÖ£¬¹¥»÷Á´µÄ¶à²ã»ìºÏÏÔÖøÔö³¤Á˼ì²âÄѶȣ¬µ«ÒàÒýÈë¸ü¶à¹ÊÕϵ㣬Ϊ·ÀÓùÌṩÁËÍ»ÆÆ¿Ú¡£AcronisÖ¸³ö£¬¶à²ã°²È«¹æ»®ÖÁ¹Ø³ÁÒª£º³õʼ½×¶ÎÐèÀ¹½Ø¶ñÒâÓʼþ¼°¸½¼þ£¬¸ß¼¶Æô·¢Ê½·ÖÎö¿É¼ø±ð¿ÉÒɾ籾ÐÐΪ£¬¶øÄÚ´æ±£»¤¼¼ÊõÄÜ×è¶Ï±àÂëÔØºÉÖ´ÐС£ÖµµÃÒ»ÌáµÄÊÇ£¬¹¥»÷ÕßÔÚPowerShell¾ç±¾ÖÐÖ²ÈëÄá²ÉÕÜѧÓï¼£¬ÊÔͼ»ìºÏÊÓÏߣ¬Í¹ÏÔ¶´ú¶ñÒâÈí¼þµÄ´´ÒâÓ븴ÔÓÐÔ¡£
https://www.bleepingcomputer.com/news/security/we-smell-a-dcrat-revealing-a-sophisticated-malware-delivery-chain/
2. ÎÞÎļþ¼ÓÃÜÍÚ¿ó¹¥»÷µ¼ÖÂ1500Óą̀PostgreSQL·þÎñÆ÷Ôâ¹¥»÷
4ÔÂ1ÈÕ£¬½üÆÚ£¬Õë¶Ô¶³öµÄPostgreSQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯Òý·¢°²È«½ç¹Ø×¢¡£Ôư²È«¹«Ë¾WizÅû¶£¬¸Ã¹¥»÷»î¶¯ÓëAqua SecurityÓÚ2024Äê8ÔÂÏóÕ÷µÄÈëÇÖ¼¯´æÔÚ¹ØÁª£¬¹¥»÷Õß±»×·×ÙΪJINX-0126£¬ÆäÀûÓÃÃûΪPG_MEMµÄ¶ñÒâÈí¼þÖ´Ðй¥»÷¡£×êÑÐÈËÔ±Ö¸³ö£¬¹¥»÷Õß³ÖÐø½ø»¯¹¥»÷ÊÖ·¨£¬Í¨¹ýΪÿ¸öÖ¸±ê²¿ÊðÓµÓÐΨһ¹þÏ£ÖµµÄ¶þ½øÔìÎļþ²¢Ñ¡È¡ÎÞÎļþ¼¼ÊõÖ´ÐÐÍÚ¿ó¸ºÔØ£¬ÓÐЧ¶ã±ÜÁËÒÀÀµÎļþ¹þÏ£¼ì²âµÄÔÆ°²È«½â¾ö¹æ»®¡£¾ÝWizÆÀ¹À£¬¸Ã»î¶¯Òѵ¼Ö³¬¹ý1,500ÃûÊܺ¦Õߣ¬Í¹ÏÔÁËÈõÃÜÂë»òĬÈÏÅäÖõÄPostgreSQLÊ·ý×÷Ϊ¹¥»÷Ö¸±êµÄÆÕ±éÐÔ¡£¹¥»÷ÕßÀûÓÃÈõÅäÖõÄPostgreSQL·þÎñ½øÐгõ²½ÉøÈ룬Ͷ·ÅBase64±àÂëµÄshell¾ç±¾£¬¸Ã¾ç±¾²»½ö¶Ï¸ù¾ºÕù¿ó¹¤£¬»¹²¿ÊðÃûΪPG_COREµÄ¶þ½øÔìÎļþ¡£½øÒ»²½£¬·þÎñÆ÷ÏÂÔØ¼Ù×°³ÉºÏ·¨PostgreSQL¹ý³ÌµÄGolang¶þ½øÔìÎļþ£¬Æäͨ¹ý´´½¨¸ßȨÏÞÓû§¡¢ÉèÖÃcronÓÆ¾Ã»¯¹¤×÷£¬ÖÕ´ÓGitHubÏÂÔØ×îаæXMRigÍÚ¿ó·¨Ê½£¬ÀûÓÃLinuxÎÞÎļþ¼¼ÊõÆô¶¯ÍÚ¿ó¹ý³Ì¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¹¥»÷ÕßΪÿ¸öÊܺ¦Õß·ÖÅä¶ÀÁ¢Ç®°üµØÖ·£¬WizÒѼø±ðÈý¸ö¹ØÁªÇ®°ü£¬Ã¿¸öÇ®°ü¹ØÁªÔ¼550¸öÍÚ¿ó½Úµã£¬×ܼƳ¬¹ý1,500̨É豸±»Ï°È¾¡£
https://thehackernews.com/2025/04/over-1500-postgresql-servers.html
3. Palo Alto Global ProtectɨÃ躣³±ÖÐÉæ¼°½ü24,000¸öIP
4ÔÂ1ÈÕ£¬Õë¶ÔPalo Alto Networks GlobalProtectµÇ¼ÃÅ»§µÄÍøÂçɨÃè»î¶¯½üÆÚÏÔÖøÉý¼¶£¬Òý·¢°²È«×êÑÐÈËÔ±¶ÔDZÔÚ¹¥»÷µÄÔ¤¾¯¡£Íþвµý±¨¹«Ë¾GreyNoise¼à²âÊý¾ÝÏÔʾ£¬¸ÃɨÃè»î¶¯Éæ¼°³¬¹ý24,000¸öΨһԴIPµØÖ·£¬ÓÚ2025Äê3ÔÂ17ÈÕ´ïµ½ÖðÈÕ20,000¸öΨһIPµÄ·åÖµ£¬²¢³ÖÐøÖÁ3ÔÂ26ÈÕ¡£IPµØÖ·ÖУ¬23,800¸ö±»ÏóÕ÷Ϊ"¿ÉÒÉ"£¬154¸ö±»È·ÒÔΪ"¶ñÒâ"£¬Í¹ÏԻÒì³£ÐÔ¡£É¨ÃèÆðÔ´ÖØÒª¼¯ÖÐÔÚ±±ÃÀ£¬Ö¸±êϵͳËäÒÔÃÀ¹úΪÖ÷£¬µ«³öÏÖÈ«Çò»¯Ìص㡣GreyNoiseÖ¸³ö£¬´ËÀàɨÃ輤Ôö³£Óë·ì϶ÀûÓÃǰµÄ¿úËÅÐж¯Óйأ¬º¹ÇàģʽÏÔʾ£¬É¨Ãè¶¥·åºó2-4ÖÜ¿ÉÄܳöÏÖзì϶Åû¶»ò¹¥»÷ÊÂÎñ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ´Î»î¶¯ÓëÁíÒ»ÏîÉæ¼°PAN-OSÅÀ³æµÄɨÃè´æÔÚ¹¦·ò¹ØÁªÐÔ£¬ºóÕßÔÚ3ÔÂ26ÈÕͬ²½´ïµ½2,580¸öIPµÄɨÃè·åÖµ¡£µ±Ç°£¬¹¥»÷ÕߵľßÌåÖ¸±êºÍ¶¯»úÉв»Ã÷È·£¬µ«Õë¶Ô¶³öÔÚ»¥ÁªÍøµÄPalo Alto Networksϵͳ£¬ÖÎÀíÔ±ÐèÌá¸ß¾¯Ìè¡£GreyNoise½¨Òéµ±¼´Éó²é3ÔÂÖÐÑ®ÒÔÀ´µÄϵͳÈÕÖ¾£¬ÅŲéÈëÇÖ¼£Ïó£¬Ç¿»¯µÇ¼ÃÅ»§°²È«·À»¤£¬²¢¹Ø±ÕÒÑÖª¶ñÒâIP¡£
https://www.bleepingcomputer.com/news/security/nearly-24-000-ips-behind-wave-of-palo-alto-global-protect-scans/
4. CrushFTP CVE-2025-2825·ì϶ÔÚ±»ÀûÓýøÐй¥»÷
4ÔÂ1ÈÕ£¬½üÆÚ£¬¹¥»÷ÕßÕý»ý¼«ÀûÓù«¿ªµÄ¸ÅÏëÑéÖ¤´úÂ루PoC£©¶ÔCrushFTPÎļþ´«ÊäÈí¼þÖеÄÒ»¸ö¸ßΣÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2025-2825£©Ö´Ðй¥»÷¡£¸Ã·ì϶ÓÉOutpost24»ã±¨£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÎÞÐèÈÏÖ¤¼´¿É½Ó¼û佨²¹µÄCrushFTP v10»òv11É豸¡£CrushFTPÔÚ3ÔÂ21ÈÕ´¹Î£°ä²¼²¹¶¡Ê±Ç¿µ÷£¬Â¶³öµÄHTTP(S)¶Ë¿Ú¿ÉÄÜÖ±½Óµ¼ÖÂδÊÚȨ½Ó¼û£¬²¢½¨ÒéÓû§µ±¼´Éý¼¶ÖÁ10.8.4»ò11.3.1ÒÔÉϰ汾¡£×÷Ϊһʱ·À»¤´ëÊ©£¬ÖÎÀíÔ±¿ÉÆôÓÃDMZ±íÎ§ÍøÂçÑ¡Ïî¼ÓÇ¿·À»¤¡£Ò»Öܺó£¬Shadowserver¼à²âÊý¾ÝÏÔʾ£¬ÆäÃÛ¹ÞϵͳÒѼì²âµ½ÊýÊ®´ÎÕë¶Ô¶³öÔÚ»¥ÁªÍøµÄCrushFTP·þÎñÆ÷µÄ¹¥»÷³¢ÊÔ£¬ÆäʱÈÔÓг¬¹ý1,500¸ö佨²¹Ê·ý´¦ÓÚ·çÏÕÖС£Õâ´Î·ì϶µÄ¹«¿ªPoCÓÉProjectDiscoveryÓÚ·ì϶Åû¶ǰÊýÈÕ°ä²¼£¬¼Ó¿ìÁ˹¥»÷ÕßµÄÀûÓùý³Ì¡£ÖµÍ×ÌùÐĵÄÊÇ£¬CrushFTP³Ö¾ÃλÁÐÀÕË÷Èí¼þÍŻÈçClop£©µÄ¸ß¼ÛÖµÖ¸±êÃûµ¥£¬´ËÇ°ÔøÔâ·êÂÅ´ÎÁãÈÕ·ì϶¹¥»÷£¬Ô̺¬2024Äê4Ô½¨²¹µÄCVE-2024-4040·ì϶£¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÌÓÒÝÐé¹¹Îļþϵͳ²¢ÇÔȡϵͳÎļþ¡£
https://www.bleepingcomputer.com/news/security/critical-auth-bypass-bug-in-crushftp-now-exploited-in-attacks/
5. VitenasÕûÐÎ±í¿Æ»¼ÕßÊý¾ÝÔâºÚ¿ÍÈëÇÖ²¢Ð¹Â¶
4ÔÂ1ÈÕ£¬ÃÀ¹úÐÝ˹¶Ù³ÛÃûÕûÐÎ±í¿Æ»ú¹¹VitenasÕûÐÎ±í¿ÆÔâ·ê³Á´óÍøÂç¹¥»÷£¬µ¼Ö´óÁ¿Ãô¸Ð»¼ÕßÊý¾Ýй¶¡£¸Ã»ú¹¹ÓÉ±í¿ÆÒ½Ê¦Ñ§»áԺʿPaul Vitenas, Jr.µÞÔ죬ÆìÏÂÔ̺¬Mirror Mirror Beauty Boutique¼°µÂ¿ËÈøË¹ÖÝÐÝ˹¶Ù±í¿ÆÖÐÐÄ¡£3ÔÂ5ÈÕ£¬Íþв×éÖ¯KairosÔÚÆä°µÍøÐ¹ÃÜÕ¾µã¹«¿ªÐû³ÆÒÑÈëÇÖVitenas²©Ê¿¹ÙÍø£¬²¢Õ¹Ê¾Î´¾±à×ëµÄ1.34GBй¶Îļþ¡£Ð¹Â¶Êý¾ÝÔ̺¬Î´¼ÓÃܵÄÊܱ£»¤½¡È«ÐÅÏ¢£¨PHI£©£¬Éæ¼°»¼ÕßÂãÕÕ¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÁªÏµ·½Ê½¡¢Éç±£ºÅ¡¢¼ÝÕÕÕÕÆ¬µÈÃô¸ÐÐÅÏ¢£¬Í¬Ê±Ô̺¬Ô±¹¤ÐÅÏ¢¼°ÕïËùÔËÓªÎļþ¡£¹¥»÷Õßͨ¹ý¶íÓïÂÛ̳¶µÏúÊý¾Ý£¬ÊÔͼѰÕÒÂò¼Ò¡£Kairos×éÖ¯Ðû³ÆÍ¨¹ý±©Á¦¹¥»÷ÓÚ2Ô³ɹ¦ÈëÇÖϵͳ£¬ÇÒÕïËùIT²¿ÃÅÒѾõ²ì¹¥»÷µ«Î´ÄÜ×èÖ¹Êý¾Ýй¶¡£¹¥»÷Õß°µÊ¾ÒÑÓëVitenas²©Ê¿½øÐÐÔ¼Ò»¸öÔµĽ»É棬ÍþвÈôÎÞ·¨¾¡¿ìÕÒµ½Êý¾ÝÂò¼Ò£¬½«¹«¿ª×îÃô¸ÐÐÅÏ¢¡£
https://databreaches.net/2025/04/01/vitenas-cosmetic-surgery-patient-data-hacked-and-leaked/
6. Å·ÖÞ·þÎñƽ̨Yoojoй¶ǧÍòÃô¸ÐÎļþ
4ÔÂ1ÈÕ£¬Å·ÖÞ·þÎñÊг¡Æ½Ì¨YoojoÒòÔÆ´æ´¢Í°ÅäÖÃÃýÎ󣬵¼Ö³¬1450Íò·ÝÃô¸ÐÎļþ¶³ö£¬º¸ÇÓû§»¤ÕÕ¡¢Í¨Ñ¶¼Í¼¡¢µç»°ºÅÂëµÈÖ÷ÌâÒþÖÔÊý¾Ý¡£×÷ΪÏνÓÓ×ÎÒÓë·þÎñÌṩÉ̵ÄÊ¢ÐÐÆ½Ì¨£¬Yoojo£¨Ç°ÉíΪYoupijobs£©ÔÚÓ¢·¨Î÷ºÉµÈ¶à¹úÔËÓª£¬ÆäÀûÓÃÏÂÔØÁ¿³¬50Íò´Î£¬·þÎñÁìÓò¸²¸Ç¼ÒÕþ¡¢³èÎﻤÀíµÈ¶àÁìÓò¡£Õâ´Îй¶µÄ´æ´¢Í°ÖÁÉÙ¹«¿ª½Ó¼û´ï10Ì죬¹ÌÈ»ÔÝÎÞÀÄÓü£Ï󣬵«×êÑÐÈËÔ±ÖÒ¸æÇ±ÔÚ·çÏÕÏÔÖø£º¹¥»÷Õß¿ÉÀûÓÃй¶µÄÉí·ÝÖ¤¼þÖ´ÐÐÉí·Ý͵ÇÔ£¬Í¨¹ýÕæÊµµç»°ºÅÂë¹¹½¨Ðéα·þÎñÊշѳ¡¾°£¬ÉõÖÁÌáÒé¾«×¼ÍøÂç´¹µö¹¥»÷¡£Ó×ÎÒÐÅϢ¶³ö»¹ÏÔÖøÔö³¤Óû§±»¸ú×ÙÀÕË÷µÄ·çÏÕ¡£ÔÚÍøÂ簲ȫÍŶӴ«µÝºó£¬YoojoÒѽ¨¸´ÅäÖ÷ì϶²¢ÊµÏÖÊý¾Ý±£»¤¡£ÎªÔ¤·ÀÀàËÆÊÂÎñ£¬×¨¼Ò½¨Òé²ÉÈ¡¶à³Á°²È«´ëÊ©£¬Ô̺¬Ç¿»¯½Ó¼û½ÚÔì¡¢ÆôÓüÓÃÜ´«ÊäÓë´æ´¢¡¢²¿ÊðÃÜÔ¿ÖÎÀí·þÎñ¡¢Ö´ÐÐSSL/TLSºÍ̸£¬²¢¼ÓÇ¿°²È«Éó¼ÆÓëÔ±¹¤Åàѵ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ´ÎÐ¹Â¶Éæ¼°´óÁ¿µ±¾ÖÇ©·¢Ö¤¼þ¼°Óû§Í¨Ñ¶ÄÚÈÝ£¬ÆäÃô¸ÐˮƽԶ³¬Í¨³£Êý¾Ýй¶ÊÂÎñ¡£
https://cybernews.com/security/yoojo-data-leak-exposed-passports/


¾©¹«Íø°²±¸11010802024551ºÅ