Acronis½âÎö¶à½×¶Î¶ñÒâÈí¼þ´«²¼Á´

°ä²¼¹¦·ò 2025-04-02

1. Acronis½âÎö¶à½×¶Î¶ñÒâÈí¼þ´«²¼Á´


4ÔÂ1ÈÕ £¬AcronisÍþв×êÑв¿ÃÅ(TRU)½üÆÚ½âÎöÁËһ·¸´ÔӵĶà½×¶Î¶ñÒâÈí¼þ´«²¼Á´ £¬½ÒʾÁ˹¥»÷ÕßÈôºÎÀûÓûìºÏ¼¼ÊõºÍ¶à¾ç±¾Ëµ»°Èƹý°²È«·ÀÓù¡£¹¥»÷ʼÓÚ¼Ù×°³É"ÕË»§¿ÛѺ´«Æ±"µÄÎ÷°àÑÀÓï´¹µöÓʼþ £¬¸½¼þΪRARѹËõ°ü £¬ÄÚº¬¸ß¶È»ìºÏµÄVisual Basic¾ç±¾(VBS)¡£Ö´Ðкó £¬VBSÌìÉúÅú´¦ÖÃÎļþ(BAT) £¬ºóÕß¹¹½¨²¢Ö´ÐÐBase64±àÂëµÄPowerShell¾ç±¾¡£¸Ã¾ç±¾½âÂëÓÐÐ§ÔØºÉ¡ª¡ªÑ¡È¡RunPE¼¼Êõ¼ÓÔØµÄ.NET¿ÉÖ´ÐÐÎļþ £¬Æä×ÊÔ´ÖÐÔ̺¬Ë«³Á¼ÓÃÜÊý¾Ý¿é £¬Ðèͨ¹ýÌØ¶¨ÃÜÔ¿½âÃÜ¡£×îÖÕÔØºÉΪDCRat»òRhadamanthysµÈÐÅÏ¢ÇÔÈ¡·¨Ê½ £¬¿ÉÖÂÊý¾Ýй¶ºÍϵͳÈëÇÖ¡£·ÖÎö·¢ÏÖ £¬¹¥»÷Á´µÄ¶à²ã»ìºÏÏÔÖøÔö³¤Á˼ì²âÄÑ¶È £¬µ«ÒàÒýÈë¸ü¶à¹ÊÕϵã £¬Îª·ÀÓùÌṩÁËÍ»ÆÆ¿Ú¡£AcronisÖ¸³ö £¬¶à²ã°²È«¹æ»®ÖÁ¹Ø³ÁÒª£º³õʼ½×¶ÎÐèÀ¹½Ø¶ñÒâÓʼþ¼°¸½¼þ £¬¸ß¼¶Æô·¢Ê½·ÖÎö¿É¼ø±ð¿ÉÒɾ籾ÐÐΪ £¬¶øÄÚ´æ±£»¤¼¼ÊõÄÜ×è¶Ï±àÂëÔØºÉÖ´ÐС£ÖµµÃÒ»ÌáµÄÊÇ £¬¹¥»÷ÕßÔÚPowerShell¾ç±¾ÖÐÖ²ÈëÄá²ÉÕÜѧÓï¼ £¬ÊÔͼ»ìºÏÊÓÏß £¬Í¹ÏÔ¶´ú¶ñÒâÈí¼þµÄ´´ÒâÓ븴ÔÓÐÔ¡£


https://www.bleepingcomputer.com/news/security/we-smell-a-dcrat-revealing-a-sophisticated-malware-delivery-chain/


2. ÎÞÎļþ¼ÓÃÜÍÚ¿ó¹¥»÷µ¼ÖÂ1500Óą̀PostgreSQL·þÎñÆ÷Ôâ¹¥»÷


4ÔÂ1ÈÕ £¬½üÆÚ £¬Õë¶Ô¶³öµÄPostgreSQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯Òý·¢°²È«½ç¹Ø×¢¡£Ôư²È«¹«Ë¾WizÅû¶ £¬¸Ã¹¥»÷»î¶¯ÓëAqua SecurityÓÚ2024Äê8ÔÂÏóÕ÷µÄÈëÇÖ¼¯´æÔÚ¹ØÁª £¬¹¥»÷Õß±»×·×ÙΪJINX-0126 £¬ÆäÀûÓÃÃûΪPG_MEMµÄ¶ñÒâÈí¼þÖ´Ðй¥»÷¡£×êÑÐÈËÔ±Ö¸³ö £¬¹¥»÷Õß³ÖÐø½ø»¯¹¥»÷ÊÖ·¨ £¬Í¨¹ýΪÿ¸öÖ¸±ê²¿ÊðÓµÓÐΨһ¹þÏ£ÖµµÄ¶þ½øÔìÎļþ²¢Ñ¡È¡ÎÞÎļþ¼¼ÊõÖ´ÐÐÍÚ¿ó¸ºÔØ £¬ÓÐЧ¶ã±ÜÁËÒÀÀµÎļþ¹þÏ£¼ì²âµÄÔÆ°²È«½â¾ö¹æ»®¡£¾ÝWizÆÀ¹À £¬¸Ã»î¶¯Òѵ¼Ö³¬¹ý1,500ÃûÊܺ¦Õß £¬Í¹ÏÔÁËÈõÃÜÂë»òĬÈÏÅäÖõÄPostgreSQLÊ·ý×÷Ϊ¹¥»÷Ö¸±êµÄÆÕ±éÐÔ¡£¹¥»÷ÕßÀûÓÃÈõÅäÖõÄPostgreSQL·þÎñ½øÐгõ²½ÉøÈë £¬Í¶·ÅBase64±àÂëµÄshell¾ç±¾ £¬¸Ã¾ç±¾²»½ö¶Ï¸ù¾ºÕù¿ó¹¤ £¬»¹²¿ÊðÃûΪPG_COREµÄ¶þ½øÔìÎļþ¡£½øÒ»²½ £¬·þÎñÆ÷ÏÂÔØ¼Ù×°³ÉºÏ·¨PostgreSQL¹ý³ÌµÄGolang¶þ½øÔìÎļþ £¬Æäͨ¹ý´´½¨¸ßȨÏÞÓû§¡¢ÉèÖÃcronÓÆ¾Ã»¯¹¤×÷ £¬ÖÕ´ÓGitHubÏÂÔØ×îаæXMRigÍÚ¿ó·¨Ê½ £¬ÀûÓÃLinuxÎÞÎļþ¼¼ÊõÆô¶¯ÍÚ¿ó¹ý³Ì¡£ÖµÍ×ÌùÐĵÄÊÇ £¬¹¥»÷ÕßΪÿ¸öÊܺ¦Õß·ÖÅä¶ÀÁ¢Ç®°üµØÖ· £¬WizÒѼø±ðÈý¸ö¹ØÁªÇ®°ü £¬Ã¿¸öÇ®°ü¹ØÁªÔ¼550¸öÍÚ¿ó½Úµã £¬×ܼƳ¬¹ý1,500̨É豸±»Ï°È¾¡£


https://thehackernews.com/2025/04/over-1500-postgresql-servers.html


3. Palo Alto Global ProtectɨÃ躣³±ÖÐÉæ¼°½ü24,000¸öIP


4ÔÂ1ÈÕ £¬Õë¶ÔPalo Alto Networks GlobalProtectµÇ¼ÃÅ»§µÄÍøÂçɨÃè»î¶¯½üÆÚÏÔÖøÉý¼¶ £¬Òý·¢°²È«×êÑÐÈËÔ±¶ÔDZÔÚ¹¥»÷µÄÔ¤¾¯¡£Íþвµý±¨¹«Ë¾GreyNoise¼à²âÊý¾ÝÏÔʾ £¬¸ÃɨÃè»î¶¯Éæ¼°³¬¹ý24,000¸öΨһԴIPµØÖ· £¬ÓÚ2025Äê3ÔÂ17ÈÕ´ïµ½ÖðÈÕ20,000¸öΨһIPµÄ·åÖµ £¬²¢³ÖÐøÖÁ3ÔÂ26ÈÕ¡£IPµØÖ·ÖÐ £¬23,800¸ö±»ÏóÕ÷Ϊ"¿ÉÒÉ" £¬154¸ö±»È·ÒÔΪ"¶ñÒâ" £¬Í¹ÏԻÒì³£ÐÔ¡£É¨ÃèÆðÔ´ÖØÒª¼¯ÖÐÔÚ±±ÃÀ £¬Ö¸±êϵͳËäÒÔÃÀ¹úΪÖ÷ £¬µ«³öÏÖÈ«Çò»¯Ìصã¡£GreyNoiseÖ¸³ö £¬´ËÀàɨÃ輤Ôö³£Óë·ì϶ÀûÓÃǰµÄ¿úËÅÐж¯ÓÐ¹Ø £¬º¹ÇàģʽÏÔʾ £¬É¨Ãè¶¥·åºó2-4ÖÜ¿ÉÄܳöÏÖзì϶Åû¶»ò¹¥»÷ÊÂÎñ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Õâ´Î»î¶¯ÓëÁíÒ»ÏîÉæ¼°PAN-OSÅÀ³æµÄɨÃè´æÔÚ¹¦·ò¹ØÁªÐÔ £¬ºóÕßÔÚ3ÔÂ26ÈÕͬ²½´ïµ½2,580¸öIPµÄɨÃè·åÖµ¡£µ±Ç° £¬¹¥»÷ÕߵľßÌåÖ¸±êºÍ¶¯»úÉв»Ã÷È· £¬µ«Õë¶Ô¶³öÔÚ»¥ÁªÍøµÄPalo Alto Networksϵͳ £¬ÖÎÀíÔ±ÐèÌá¸ß¾¯Ìè¡£GreyNoise½¨Òéµ±¼´Éó²é3ÔÂÖÐÑ®ÒÔÀ´µÄϵͳÈÕÖ¾ £¬ÅŲéÈëÇÖ¼£Ïó £¬Ç¿»¯µÇ¼ÃÅ»§°²È«·À»¤ £¬²¢¹Ø±ÕÒÑÖª¶ñÒâIP¡£


https://www.bleepingcomputer.com/news/security/nearly-24-000-ips-behind-wave-of-palo-alto-global-protect-scans/


4. CrushFTP CVE-2025-2825·ì϶ÔÚ±»ÀûÓýøÐй¥»÷


4ÔÂ1ÈÕ £¬½üÆÚ £¬¹¥»÷ÕßÕý»ý¼«ÀûÓù«¿ªµÄ¸ÅÏëÑéÖ¤´úÂ루PoC£©¶ÔCrushFTPÎļþ´«ÊäÈí¼þÖеÄÒ»¸ö¸ßΣÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2025-2825£©Ö´Ðй¥»÷¡£¸Ã·ì϶ÓÉOutpost24»ã±¨ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÎÞÐèÈÏÖ¤¼´¿É½Ó¼û佨²¹µÄCrushFTP v10»òv11É豸¡£CrushFTPÔÚ3ÔÂ21ÈÕ´¹Î£°ä²¼²¹¶¡Ê±Ç¿µ÷ £¬Â¶³öµÄHTTP(S)¶Ë¿Ú¿ÉÄÜÖ±½Óµ¼ÖÂδÊÚȨ½Ó¼û £¬²¢½¨ÒéÓû§µ±¼´Éý¼¶ÖÁ10.8.4»ò11.3.1ÒÔÉϰ汾¡£×÷Ϊһʱ·À»¤´ëÊ© £¬ÖÎÀíÔ±¿ÉÆôÓÃDMZ±íÎ§ÍøÂçÑ¡Ïî¼ÓÇ¿·À»¤¡£Ò»Öܺó £¬Shadowserver¼à²âÊý¾ÝÏÔʾ £¬ÆäÃÛ¹ÞϵͳÒѼì²âµ½ÊýÊ®´ÎÕë¶Ô¶³öÔÚ»¥ÁªÍøµÄCrushFTP·þÎñÆ÷µÄ¹¥»÷³¢ÊÔ £¬ÆäʱÈÔÓг¬¹ý1,500¸ö佨²¹Ê·ý´¦ÓÚ·çÏÕÖС£Õâ´Î·ì϶µÄ¹«¿ªPoCÓÉProjectDiscoveryÓÚ·ì϶Åû¶ǰÊýÈÕ°ä²¼ £¬¼Ó¿ìÁ˹¥»÷ÕßµÄÀûÓùý³Ì¡£ÖµÍ×ÌùÐĵÄÊÇ £¬CrushFTP³Ö¾ÃλÁÐÀÕË÷Èí¼þÍŻÈçClop£©µÄ¸ß¼ÛÖµÖ¸±êÃûµ¥ £¬´ËÇ°ÔøÔâ·êÂÅ´ÎÁãÈÕ·ì϶¹¥»÷ £¬Ô̺¬2024Äê4Ô½¨²¹µÄCVE-2024-4040·ì϶ £¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÌÓÒÝÐé¹¹Îļþϵͳ²¢ÇÔȡϵͳÎļþ¡£


https://www.bleepingcomputer.com/news/security/critical-auth-bypass-bug-in-crushftp-now-exploited-in-attacks/


5. VitenasÕûÐÎ±í¿Æ»¼ÕßÊý¾ÝÔâºÚ¿ÍÈëÇÖ²¢Ð¹Â¶


4ÔÂ1ÈÕ £¬ÃÀ¹úÐÝ˹¶Ù³ÛÃûÕûÐÎ±í¿Æ»ú¹¹VitenasÕûÐÎ±í¿ÆÔâ·ê³Á´óÍøÂç¹¥»÷ £¬µ¼Ö´óÁ¿Ãô¸Ð»¼ÕßÊý¾Ýй¶¡£¸Ã»ú¹¹ÓÉ±í¿ÆÒ½Ê¦Ñ§»áԺʿPaul Vitenas, Jr.µÞÔì £¬ÆìÏÂÔ̺¬Mirror Mirror Beauty Boutique¼°µÂ¿ËÈøË¹ÖÝÐÝ˹¶Ù±í¿ÆÖÐÐÄ¡£3ÔÂ5ÈÕ £¬Íþв×éÖ¯KairosÔÚÆä°µÍøÐ¹ÃÜÕ¾µã¹«¿ªÐû³ÆÒÑÈëÇÖVitenas²©Ê¿¹ÙÍø £¬²¢Õ¹Ê¾Î´¾­±à×ëµÄ1.34GBй¶Îļþ¡£Ð¹Â¶Êý¾ÝÔ̺¬Î´¼ÓÃܵÄÊܱ£»¤½¡È«ÐÅÏ¢£¨PHI£© £¬Éæ¼°»¼ÕßÂãÕÕ¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÁªÏµ·½Ê½¡¢Éç±£ºÅ¡¢¼ÝÕÕÕÕÆ¬µÈÃô¸ÐÐÅÏ¢ £¬Í¬Ê±Ô̺¬Ô±¹¤ÐÅÏ¢¼°ÕïËùÔËÓªÎļþ¡£¹¥»÷Õßͨ¹ý¶íÓïÂÛ̳¶µÏúÊý¾Ý £¬ÊÔͼѰÕÒÂò¼Ò¡£Kairos×éÖ¯Ðû³ÆÍ¨¹ý±©Á¦¹¥»÷ÓÚ2Ô³ɹ¦ÈëÇÖϵͳ £¬ÇÒÕïËùIT²¿ÃÅÒѾõ²ì¹¥»÷µ«Î´ÄÜ×èÖ¹Êý¾Ýй¶¡£¹¥»÷Õß°µÊ¾ÒÑÓëVitenas²©Ê¿½øÐÐÔ¼Ò»¸öÔµĽ»Éæ £¬ÍþвÈôÎÞ·¨¾¡¿ìÕÒµ½Êý¾ÝÂò¼Ò £¬½«¹«¿ª×îÃô¸ÐÐÅÏ¢¡£


https://databreaches.net/2025/04/01/vitenas-cosmetic-surgery-patient-data-hacked-and-leaked/


6. Å·ÖÞ·þÎñƽ̨Yoojoй¶ǧÍòÃô¸ÐÎļþ


4ÔÂ1ÈÕ £¬Å·ÖÞ·þÎñÊг¡Æ½Ì¨YoojoÒòÔÆ´æ´¢Í°ÅäÖÃÃýÎó £¬µ¼Ö³¬1450Íò·ÝÃô¸ÐÎļþ¶³ö £¬º­¸ÇÓû§»¤ÕÕ¡¢Í¨Ñ¶¼Í¼¡¢µç»°ºÅÂëµÈÖ÷ÌâÒþÖÔÊý¾Ý¡£×÷ΪÏνÓÓ×ÎÒÓë·þÎñÌṩÉ̵ÄÊ¢ÐÐÆ½Ì¨ £¬Yoojo£¨Ç°ÉíΪYoupijobs£©ÔÚÓ¢·¨Î÷ºÉµÈ¶à¹úÔËÓª £¬ÆäÀûÓÃÏÂÔØÁ¿³¬50Íò´Î £¬·þÎñÁìÓò¸²¸Ç¼ÒÕþ¡¢³èÎﻤÀíµÈ¶àÁìÓò¡£Õâ´Îй¶µÄ´æ´¢Í°ÖÁÉÙ¹«¿ª½Ó¼û´ï10Ìì £¬¹ÌÈ»ÔÝÎÞÀÄÓü£Ïó £¬µ«×êÑÐÈËÔ±ÖÒ¸æÇ±ÔÚ·çÏÕÏÔÖø£º¹¥»÷Õß¿ÉÀûÓÃй¶µÄÉí·ÝÖ¤¼þÖ´ÐÐÉí·Ý͵ÇÔ £¬Í¨¹ýÕæÊµµç»°ºÅÂë¹¹½¨Ðéα·þÎñÊշѳ¡¾° £¬ÉõÖÁÌáÒé¾«×¼ÍøÂç´¹µö¹¥»÷¡£Ó×ÎÒÐÅϢ¶³ö»¹ÏÔÖøÔö³¤Óû§±»¸ú×ÙÀÕË÷µÄ·çÏÕ¡£ÔÚÍøÂ簲ȫÍŶӴ«µÝºó £¬YoojoÒѽ¨¸´ÅäÖ÷ì϶²¢ÊµÏÖÊý¾Ý±£»¤¡£ÎªÔ¤·ÀÀàËÆÊÂÎñ £¬×¨¼Ò½¨Òé²ÉÈ¡¶à³Á°²È«´ëÊ© £¬Ô̺¬Ç¿»¯½Ó¼û½ÚÔì¡¢ÆôÓüÓÃÜ´«ÊäÓë´æ´¢¡¢²¿ÊðÃÜÔ¿ÖÎÀí·þÎñ¡¢Ö´ÐÐSSL/TLSºÍ̸ £¬²¢¼ÓÇ¿°²È«Éó¼ÆÓëÔ±¹¤Åàѵ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Õâ´ÎÐ¹Â¶Éæ¼°´óÁ¿µ±¾ÖÇ©·¢Ö¤¼þ¼°Óû§Í¨Ñ¶ÄÚÈÝ £¬ÆäÃô¸ÐˮƽԶ³¬Í¨³£Êý¾Ýй¶ÊÂÎñ¡£


https://cybernews.com/security/yoojo-data-leak-exposed-passports/