±±ÃÀ±ùÖÆÆ·¹©¸øÉÌÔâ÷è÷ëÀÕË÷Èí¼þÈëÇÖ£¬Ãô¸ÐÊý¾ÝÒÉй¶
°ä²¼¹¦·ò 2025-07-311. ±±ÃÀ±ùÖÆÆ·¹©¸øÉÌÔâ÷è÷ëÀÕË÷Èí¼þÈëÇÖ£¬Ãô¸ÐÊý¾ÝÒÉй¶
7ÔÂ29ÈÕ£¬±±ÃÀÖØÒª±ùÖÆÆ·¹©¸øÉ̱±¼«±ù´¨£¨Arctic Glacier£©½üÈÕ±»ÆØ³ÉΪ÷è÷루Qilin£©ÀÕË÷Èí¼þÍÅ»ïµÄ×îй¥»÷Ö¸±ê£¬ÆäÃô¸ÐÆóÒµÊý¾Ý¡¢Ô±¹¤ÐÅÏ¢¼°¸öÈË×ÊÁÏÔâÇÔ²¢ÔÚ°µÍøÕ¹Ê¾¡£×÷ΪÃÀ¹úºÍ¼ÓÄôó×î´óµÄ°ü×°±ù¼°Ëé±ù¹©¸øÉÌÖ®Ò»£¬±±¼«±ù´¨·þÎñ¶ÔÏóº¸Ç7-ElevenµÈ·½±ãµê¾ÞÍ·£¬ÔËÓª×ų¬¹ý100¸ö·ÖÏúÖÐÐÄ£¬Îª7.5Íò¼ÒÁãÊÛ¡¢Ã³Ò×¼°¹¤Òµ¿Í»§Ìṩ·þÎñ£¬È¥ÄêÓªÊÕ¿¿½ü3ÒÚÃÀÔª£¬Ô±¹¤¹æÄ£³¬Ç§ÈË¡£÷è÷ëÍÅ»ïÔÚÆä°µÍø²©¿ÍÐû³ÆÈëÇֳɹ¦£¬²¢°ä²¼Á˶àÕžݳÆÀ´×Ô±±¼«±ù´¨µÄй¶Êý¾Ý½ØÍ¼£¬ÄÚÈÝÔ̺¬»¤ÕÕ¡¢¼ÝÕÕ¸±±¾¡¢Ô±¹¤Ð½³ê¼Í¼¼°Ë¾·¨²ÆÕþÎļþ¡£Õâ´ÎÊý¾Ýй¶¿ÉÄÜÒý·¢¶à³Á·çÏÕ£º¹¥»÷Õß»òÀûÓÃÓ×ÎÒÐÅÏ¢Ö´ÐÐÉí·Ý͵ÇÔ¡¢Ú²ÆÐÔÕË»§×¢²á£¬»òͨ¹ý¼Ù×°³É¹«Ë¾¿Í»§/¹ÍÖ÷ÌáÒéÕë¶ÔÐÔ´¹µö¹¥»÷¡£¸üÑϳÁµÄÊÇ£¬Ð¹Â¶µÄ˾·¨Îļþ¿ÉÄܱ»ÓÃÓÚ·ÖÎöÆóÒ·ûÒæ¹ØÏµ£¬ÎªºóÐø¸ü¾ß·ÛËéÐԵĹ¥»÷Ìṩµý±¨Ö§³Ö¡£
https://cybernews.com/security/arctic-glacier-data-breach-claims/
2. PyPIÔâ·ê¸ßÒñ±ÎÐÔÍøÂç´¹µö¹¥»÷
7ÔÂ29ÈÕ£¬Python°üË÷Òý£¨PyPI£©ÊØ»¤Õß½üÈÕ·¢³ö´¹Î£ÖҸ棬³ÆÆäÓû§ÕýÔâ·êÒ»³¡¾«ÐIJ߶¯µÄÍøÂç´¹µö¹¥»÷¡£¹¥»÷Õßͨ¹ýαÔìÖ÷ÌâΪ¡°[PyPI] µç×ÓÓʼþÑéÖ¤¡±µÄÓʼþ£¬ÓÕµ¼Óû§µã»÷Á´½ÓÖÁÐéÎ±ÍøÕ¾£¬ÒÔÇÔÈ¡µÇ¼ƾ֤¡£Õâ´Î¹¥»÷µÄ¹ÖÒìÖ®´¦ÔÚÓÚ£¬Æä¼¼ÊõÊÖ·¨ÓµÓи߶ÈÒñ±ÎÐÔ£¬Óû§ÔÚÐéÎ±ÍøÕ¾ÊäÈëÐÅÏ¢ºó£¬ÒªÇó»á±»Â·ÓÉÖÁºÏ·¨PyPI·þÎñÆ÷£¬Ê¹Êܺ¦ÕßÎóÒÔΪ²Ù×÷Õý³££¬ÊµÔòƾ֤ÒÑÔâ½Ø»ñ¡£¾ÝPyPIÖÎÀíÔ±Mike FiedlerÅû¶£¬¹¥»÷Óʼþ·¢¼þµØÖ·Îªnoreply@pypj[.]org£¨°ÑÎÈÓòÃû²¢·Ç¹Ù·½pypi[.]org£©£¬ÓʼþÄÚÈÝÒªÇóÓû§ÑéÖ¤ÓÊÏ䵨ַ£¬²¢Êèµ¼ÖÁ·ÂðPyPI½çÃæµÄ´¹µöÍøÕ¾¡£Ö»¹Ü¹¥»÷δֱ½ÓÍ»ÆÆPyPIϵͳ°²È«£¬µ«ÀûÓÃÁËÓû§¶Ô¹Ù·½Æ½Ì¨µÄÐÅÀµ£¬ÊôÓÚµäÐ͵ÄÉç»á¹¤³Ì¹¥»÷¡£PyPIÍŶÓÇ¿µ÷£¬´ËÀàÐÐΪ¿ÉÄÜÕë¶ÔÖÎÀíÈȵãÈí¼þ°üµÄ¿ª·¢ÕßÕË»§£¬Ò»µ©µÃ³Ñ£¬¹¥»÷Õß»ò¿É°ä²¼¶ñÒâ°ü£¬À©´ó·çÏÕÁìÓò¡£
https://thehackernews.com/2025/07/pypi-warns-of-ongoing-phishing-campaign.html
3. ·ÇÖÞ×éÖ¯Ôâ·ê´ó¹æÄ£Microsoft SharePoint·ì϶¹¥»÷
7ÔÂ30ÈÕ£¬·ÇÖÞ¹ú¶ÈÕýÃæ¶ÔÍøÂç¹¥»÷µÄ¿Õǰ¼¤Ôö£¬»úÓöÖ÷ÒåÍþвÐÐΪÕßͨ¹ý´ó¹æÄ£É¨Ã軥ÁªÍø£¬ÀûÓÃδʵʱ½¨²¹µÄn-day°²È«·ì϶£¬¹¥»÷Æä¼±¾çÀ©Õŵ«°²È«·À»¤ÓÄ΢µÄÊý×Ö»ù´¡ÉèÊ©¡£½üÆÚ£¬ÄϷǹú¶È²ÆÕþ²¿¡¢Æû³µÔì×÷Òµ¡¢´óѧ¼°´¦Ëùµ±¾ÖµÈÖÁÉÙÁù¼Ò»ú¹¹Ôâ΢ÈíSharePointÈí¼þÖеÄToolShell·ì϶£¨CVE-2025-53770/53771£©¹¥»÷£¬ÊÂÎñ²¨¼°Ã«ÀïÇó˹¡¢Ô¼µ©µÈµØ£¬Í¹ÏÔ·ÇÖÞ³ÉΪȫÇòÍøÂç·¸×ïµÄÐÂÖ¸±ê¡£¹¥»÷ÕßÀûÓõķì϶×îÔçÔÚ2025Äê5ÔÂPwn2Own½ÏÁ¿Öб»·¢ÏÖ£¬Î¢ÈíËäÓÚ7Ô³õ°ä²¼²¹¶¡£¬µ«ÈýÌìºóÁãÈÕ±äÌå¼´±»ÓÃÓÚʵս¡£°²È«¹«Ë¾BitdefenderÖ¸³ö£¬·ÇÖ޵ĴàÈõÐÔÔ´ÓÚÆäÊý×Ö»¯¹ý³ÌÓëÍøÂ簲ȫÄÜÁ¦µÄ²»Æ¥Å䣺Ϊ½µµÍ³É±¾£¬´óÁ¿×é֯ѡȡ±¾µØ²¿ÊðÈí¼þ£¨Èç´æÔÚ·ì϶µÄSharePoint£©£¬µ«ÒòITÈËÁ¦ÓÐÏÞ£¬ÄÑÒÔÓÐЧÖÎÀí°²È«¸üС£ESET×êÑÐÔ±Anton Cherepanov²¹³ä³Æ£¬¹¥»÷ģʽ³öÏÖÁ½½×¶ÎÌØµã£¬·ì϶¸ÅÏëÑéÖ¤£¨PoC£©´úÂë°ä²¼ºó24Ó×ʱÄÚ£¬¹¥»÷Õß¼±¾ç³ÉÁ¢Ì²Í·Õ󵨣¬ÊýÖܺóÔÙ·¢Õ¹ÊÖ¶¯ÉøÈë¡£
https://www.darkreading.com/cyber-risk/african-orgs-mass-microsoft-sharepoint-exploits
4. ¶íÂÞ˹ҽÁÆÓëÃñÉúÁìÓòÔâ´ó¹æÄ£ÍøÂç¹¥»÷
7ÔÂ30ÈÕ£¬±¾ÖܶíÂÞ˹ҽÁƼ°ÃñÉúÁìÓòÔâ·ê¶àÆðÑϳÁÍøÂç¹¥»÷ÊÂÎñ£¬µ¼ÖÂÈ«¹úÊý°Ù¼ÒÒ©µêÆÆ²ú¡¢Ò½ÁÆ»ú¹¹·þÎṉ̃»¾£¬Òý·¢Éç»á¿í·º¹Ø×¢¡£¶íÂÞ˹Á½´óÁ¬ËøÒ©µêStolichki£¨Ô¼1000¼ÒÃŵ꣩ºÍNeofarm£¨³¬110¼ÒÃŵ꣩Ïà¼Ì֤ʵ£¬ÖܶþÆðÒòºÚ¿Í¹¥»÷µ¼ÖÂÖ§¸¶ÏµÍ³¡¢Ò©Æ·Ô¤Ô¼¼°»áÔ±·þÎñÈ«ÃæÖжϡ£Ö»¹ÜStolichkiÖÜÈý¸´Ô°ëÊýÃŵêÔËÓª£¬µ«Á½¼ÒÆóÒµÔ±¹¤¾ù±»Ç²É¢£¬ÔÚÏß·þÎñÈÔ´¦Ì±»¾×´Ì¬¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÕâÁ½¼ÒÒ©µêͬÊôÒ»¼Ò¿Ø¹É¹«Ë¾£¬ÆäÏÖʵ½ÚÔìȨÒò2022ÄêԹɶ«¡¢Ç°¹ú¶È¶ÅÂíÒéÔ±Ò¶·ò¸ùÄᡤÄá·²µÙÒ®·òÊÜÎ÷·½Ôì²ÃÈöɹÉȨºó£¬ÈÔ´æ¼ä½Ó¹ØÁªÕùÒé¡£Õâ´Î¹¥»÷²¨¼°ÁìÓò³¬³öÒ½Ò©ÁìÓò¡£ÄªË¹¿Æ¼ÒÍ¥Ò½ÉúÕïËùÍøÂçͬÈÕ»ã±¨ÍøÂç¹ÊÕÏ£¬»¼ÕßÃÅ»§ÓëԤԼϵͳ̱»¾£¬½öÄÜÏÖ³¡¾ÍÕï¡£Ö»¹Ü¶íÂÞ˹»¥ÁªÍø¼à¹Ü»ú¹¹Roskomnadzor·ñ¶¨ÊÂÎñÉæ¼°É¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬µ«Î´°ä²¼¾ßÌåÊÖ·¨¼°ÆðÔ´£¬°µÍøÂÛ̳Ôò³öÏÖß³Ôð¹¥»÷"Î¥±³Â·µÂ"µÄÉùÒô£¬°µÊ¾µØÔµÕþÖζ¯»ú¡£
https://therecord.media/cyberattack-shuts-down-russian-pharmacies
5. ÃÀ¹úÁãÊÛ¾ÞÍ·Dollar TreeÔâÀÕË÷Èí¼þ¹¥»÷
7ÔÂ30ÈÕ£¬ÃÀ¹úÕÛ¿ÛÁãÊÛ¾ÞÍ·Dollar Tree½üÆÚ±»³ÛÃûÀÕË÷Èí¼þÍÅ»ïINC RansomÁÐΪ¹¥»÷Ö¸±ê£¬¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÐû³ÆÒÑ»ñÈ¡Æä³¬¹ý1.2TBµÄÃô¸ÐÊý¾Ý£¬²¢Íþв¹«¿ª¡£È»¶ø£¬Dollar TreeѸ¿ì»ØÓ¦³Æ£¬ÓйØÖ¸¿Ø½öÉæ¼°2024ÄêÊÕ¹ºµÄ99 Cents OnlyÁ¬ËøµêÒÅÁôϵͳ£¬Ç¿µ÷¹«Ë¾²¢Î´ÊÕ¹º¸ÃÆ·ÅÆµÄÆóҵʵÌå¡¢ÍøÂç»òÊý¾Ý£¬½ö±£Áô²¿ÃÅ·¿µØ²ú×âÁÞȨ£¬ÈκθÉÓÚÆäÖ±½Ó¾íÈëÊý¾Ýй¶µÄÖ¸¿Ø¾ù²»Êôʵ¡£Õâ´ÎÊÂÎñÔ´ÓÚINC Ransom½«Dollar TreeÁÐÈë°µÍøÐ¹ÃÜÍøÕ¾£¬²¢°ä²¼ÉÙÁ¿Îĵµ½ØÍ¼×÷Ϊ֤¾Ý¡£Ö»¹ÜĿǰÉÐδ¹«¿ªÆëÈ«Êý¾ÝÑù±¾£¬µ«¸ÃÍÅ»ïµÄ¡°¶à³ÁÀÕË÷¡±Ä£Ê½Í¨³£ÒÔй¶Êý¾ÝΪÍþв£¬ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Èô¹¥»÷Êôʵ£¬Õâ²¢·ÇDollar Tree³õ´ÎÔâ·êÊý¾Ý°²È«ÎÊÌ⣬2023ÄêÆäÔøÒòµÚÈý·½¹©¸øÉÌϵͳÔâÈëÇÖ£¬µ¼ÖÂÔ±¹¤¼°¿Í»§Î´¼ÓÃÜÐÅϢй¶¡£Ö»¹ÜDollar TreeÇ¿µ÷Õâ´ÎÊÂÎñÓë×ÔÉíÖ÷ÌâϵͳÎ޹أ¬µ«ÊÕ¹ººóµÄÊý¾ÝÖÎÀí·ì϶ÈÔÒý·¢¹Ø×¢¡£
https://cybernews.com/security/dollar-tree-data-breach-claims/
6. ºÚ¿Í»ý¼«ÀûÓÃWordPress AloneÖ÷ÌâÖеĹؼüRCE·ì϶
7ÔÂ30ÈÕ£¬WordPress¸ß¼¶Ö÷ÌâAlone½üÈÕ±»ÆØ´æÔÚδ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2025-5394£©£¬ÍþвÐÐΪÕßͨ¹ý¸Ã·ì϶ʵÏÖÔ¶³Ì´úÂëÖ´Ðм°Õ¾µãÊÕÊÜ¡£¾Ý°²È«³§ÉÌWordfenceͳ¼Æ£¬ÆäÒÑÀ¹½Ø³¬¹ý12Íò´ÎÕë¶Ô¸Ã·ì϶µÄ¹¥»÷³¢ÊÔ£¬¹¥»÷ÕßÀûÓÃÖ÷ÌâÖ÷Ì⺯Êý"alone_import_pack_install_plugin()"µÄȱµã£¬Í¨¹ýAJAX½Ó¿Ú½Ó¹ÜÔ¶³ÌURLÉÏ´«¶ñÒâZIP°ü£¬½ø¶øÖ²ÈëWebshell¡¢PHPºóÃÅ»ò´´½¨°µ²ØÖÎÀíÔ¹ØË»§£¬ÉõÖÁ²¿ÊðÆëÈ«ÎļþÖÎÀíÆ÷ÒÔÆëÈ«½ÚÔìÊý¾Ý¿â¡£Õâ´Î¹¥»÷³öÏÖÏÔÖøÁãÈÕ·ìÏ¶ÌØµã£ºWordfence·¢ÏÖ¹¥»÷»î¶¯ÔçÓÚ¹Ù·½²¹¶¡°ä²¼ÖÁÉÙËÄÌ죬Åú×¢¹¥»÷Õßͨ¹ý¼à¿Ø°æ±¾¸üÐÂÈÕÖ¾ÌáÇ°Ëø¶¨Ö¸±ê¡£·ì϶ӰÏìAlone 7.8.3¼°ÒÔÉϰ汾£¬¸ÃÖ÷ÌâÖØÒª·þÎñÓڴȱ¯»ú¹¹¡¢·Çµ±¾Ö×éÖ¯µÈ·ÇͶ»úʵÌ壬ÆäÓû§ÈºÌåÌØÊâÐÔ¼Ó¾çÁËÊý¾Ýй¶·çÏÕ¡£¹¥»÷¼£ÏóÔ̺¬ÐÂÔöÖÎÀíÔ¹ØË»§¡¢¿ÉÒÉZIP/²å¼þÎļþ¼°¶Ô"admin-ajax.php?action=alone_import_pack_install_plugin"õè¾¶µÄÒì³£ÒªÇó¡£Wordfence³ö¸ñÖ¸³ö£¬À´×ÔËĸöÔ´IPµÄ¹¥»÷Á÷Á¿Õ¼±ÈÁ¦¸ß£¬½¨Òéµ±¼´¹Ø±Õ¡£
https://www.bleepingcomputer.com/news/security/hackers-actively-exploit-critical-rce-in-wordpress-alone-theme/


¾©¹«Íø°²±¸11010802024551ºÅ