ÍøÂç·¸×ï·Ö×ÓÀûÓÃAIÍøÕ¾¹¹½¨Æ÷LovableÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷
°ä²¼¹¦·ò 2025-08-221. ÍøÂç·¸×ï·Ö×ÓÀûÓÃAIÍøÕ¾¹¹½¨Æ÷LovableÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷
8ÔÂ20ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Proofpoint½üÈÕÅû¶£¬ÈËΪÖÇÄÜÍøÕ¾¹¹½¨Æ÷LovableÕý±»ÍøÂç·¸×ï·Ö×Ó´ó¹æÄ£ÀÄÓ㬳ÉΪÌáÒéÍøÂç´¹µö¡¢¶ñÒâÈí¼þ´«²¼¼°¼ÓÃÜÇ®±Ò͵ÇԵĹؼü¹¤¾ß¡£Lovable±¾ÊÇΪ·Ç¼¼ÊõÓû§Éè¼ÆµÄ¼±¾ç½¨Õ¾Æ½Ì¨£¬Óû§½öÐèÊäÈëÃèÊö¼´¿ÉÌìÉúÍйÜÓÚlovable.appÓòÃûµÄÍøÕ¾£¬Ãâ·ÑÕË»§º¬¡°Ê¹ÓÃLovable±à×롱»ÕÕ£¬¸¶ÓöȻ§¿É°µ²Ø»ÕÕ²¢°ó¶¨×Ô½ç˵ÓòÃû¡£È»¶ø£¬ÕâÒ»±ã½ÝÐÔ±»ÍþвÐÐΪÕßÀûÓ㬳ÉΪºýŪÓû§µÄ¡°ÃÀÂú¼Ù×°¡±¡£Proofpoint×êÑÐÈËÔ±»ã±¨³Æ£¬×Ô2025Äê2ÔÂÆð£¬Ã¿ÔÂÔÚµç×ÓÓʼþÊý¾ÝÖмì²âµ½ÊýÊ®Íò¸ö¶ñÒâLovable URL£¬¹¥»÷»î¶¯³ÊÔö³¤Ç÷Ïò¡£·¸×ï·Ö×Óͨ¹ý¸Ãƽ̨¼±¾ç´î½¨·ÂÕÕ΢Èí¡¢UPS¡¢AaveµÈ¿ÉÐÅÆ·ÅƵĴ¹µöÍøÕ¾£¬½áºÏTycoonµÈ¡°´¹µö¼´·þÎñ¡±¹¤¾ßÇÔȡƾ֤¡¢»á»°Cookie¼°¼ÓÃÜÇ®°ü×ʽð¡£ÊÂÎñÆØ¹âºó£¬LovableÓëProofpointºÏ×÷¹Ø¹ØÁËÊý°Ù¸ö´¹µöÓòÃû£¬²¢ÍƳöAIÇý¶¯µÄ±£»¤´ëÊ©£¬Ô̺¬ÊµÊ±¼ì²â¶ñÒ⽨վÌáÐÑ¡¢ÖðÈÕɨÃèÒѰ䲼ÏîÄ¿£¬²¢´òËãÄêÄÚÉÏÏßÕË»§ÀÄÓ÷À»¤Ö°ÄÜ¡£
https://hackread.com/ai-website-builder-lovable-phishing-malware-scams/
2. Orange BelgiumÔâÍøÂç¹¥»÷£¬85Íò¿Í»§Êý¾Ýй¶
8ÔÂ20ÈÕ£¬±ÈÀûʱµçÐÅÔËÓªÉÌOrange BelgiumÓÚ7Ôµ׷¢ÏÖÒ»Â·ÍøÂç¹¥»÷ÊÂÎñ£¬µ¼ÖÂÔ¼85Íò¿Í»§ÕË»§ÐÅÏ¢±»ÇÔÈ¡¡£¸Ã¹«Ë¾ÖÜÈýÅû¶£¬Ö»¹Üδй¼ûÜÂë¡¢µç×ÓÓʼþµØÖ·»òÒøÐвÆÕþµÈ¹Ø¼üÊý¾Ý£¬µ«ºÚ¿Í»ñÈ¡ÁËÓû§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢SIM¿¨ºÅ¡¢PUKÂ루Ó×ÎÒ½âËøÃÜÔ¿£©¼°×Ê·Ñ´òËãµÈÃô¸ÐÐÅÏ¢¡£PUKÂë×÷Ϊ8λ°²È«´úÂ룬¿ÉÓÃÓÚ½âËøÒòÂÅ´ÎÊäÈëÃýÎóPINÂë¶ø±»Ëø¶¨µÄSIM¿¨£¬Æäй¶¿ÉÄÜÔö³¤Óû§É豸±»·¸·¨²Ù¿ØµÄ·çÏÕ¡£Orange BelgiumÔÚÉêÃ÷ÖÐÇ¿µ÷£¬ÊÂÎñ·¢ÏÖºóÍŶÓÒѵ±¼´¡°×èÖ¹¶ÔÊÜÓ°ÏìϵͳµÄ½Ó¼û²¢¼ÓÇ¿°²È«´ëÊ©¡±£¬Í¬Ê±Ïò¼à¹Ü²¿ÃŻ㱨²¢ÌáÆð˾·¨Í¶Ëß¡£È»¶ø£¬¹«Ë¾Î´»ØÓ¦¹ØÓÚ¹¥»÷·¢ÏÖÓëÅû¶¹¦·òÏߵľßÌåÎÊÌâ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ´Î¹¥»÷²úÉúǰһÖÜ£¨7ÔÂ25ÈÕ£©£¬Æäĸ¹«Ë¾·¨¹úOrange¼¯ÍÅÒ²¼ì²âµ½ÄÚ²¿ÏµÍ³ÔâÍøÂç¹¥»÷£¬µ«ÆäʱÉêÃ÷¡°ÎÞ¿Í»§Êý¾ÝÇÔȡ֤¾Ý¡±£¬ÇÒδ¸üÐÂÊÂÎñ¹ØÁªÐÔ×¢Ã÷¡£Á½Æð¹¥»÷µÄ¼¼Êõϸ½Ú¾ùδ¹«¿ª£¬ÊÇ·ñΪͳһÍþвÐÐΪÕßËùΪÉв»Ã÷È·¡£ÊÜÓ°Ïì¿Í»§½«Í¨¹ýµç×ÓÓʼþºÍ¶ÌÐÅÊÕµ½Í¨Öª£¬²¢±»½¨Ò龯ÌèÕë¶ÔרÓÃÍøÒ³µÄÍøÂç´¹µö¹¥»÷¡£
https://therecord.media/belgian-telecom-says-cyberattack-compromised-data-on-850000
3. Ç×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯¹¥»÷¶íÂÞ˹Ͷ×ÊÆ½Ì¨
8ÔÂ20ÈÕ£¬¶íÂÞ˹Ͷ×ʺͷÖÎöƽ̨¡°Í¶×ÊÏîÄ¿¡±£¨Investproject£©½üÆÚÔâ·êÇ×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯¡°ÍøÂçÎÞµ±¾ÖÓ×¶Ó¡±£¨Cyber Anarchy Squad£©µÄÍøÂç¹¥»÷£¬µ¼ÖÂÆäÍøÕ¾×ÔÖÜÈÕÒÔÀ´³ÖÐøÀëÏß¡£½ØÖÁÖÜÈý£¬¸Ãƽ̨ÈÔδÄܸ´Ô·þÎñ£¬²¢ÒÑÏò¶íÂÞ˹Öݼà¹Ü»ú¹¹»ã±¨ÊÂÎñ£¬³ÆÕýÈ«Á¦½¨¸´»ù´¡ÉèÊ©¡£Õâ´Î¹¥»÷͹ÏÔÁ˵ØÔµÃ¬¶Ü²¼¾°ÏÂÍøÂçÕ½µÄÉý¼¶£¬ºÚ¿Í×é֯ͨ¹ýÊý¾Ýй¶ÊÔͼ¶Ô¶í·½ÊµÌåÊ©¼ÓÕþÖÎÓë¾¼ÃѹÁ¦¡£¡°ÍøÂçÎÞµ±¾ÖÓ×¶Ó¡±Ðû³Æ³É¹¦·ÛËéÆ½Ì¨²¿ÃÅ»ù´¡ÉèÊ©£¬½Ó¼ûÁËÄÚ²¿Êý¾Ý¿â¼°Ô±¹¤Îļþ£¬²¢¹«¿ªÁËÒ»Åú¾Ý³Æ±»µÁµÄÎļþ¡£Ö»¹ÜRecorded Future NewsδÄܶÀÁ¢ÑéÖ¤ÎļþÕæÊµÐÔ£¬µ«¸Ã×éÖ¯Ã÷È·°µÊ¾£¬Ð¹Â¶Êý¾ÝÖ¼ÔÚÏò¶íÂÞ˹¼à¹Ü»ú¹¹Ê©Ñ¹£¬ÒªÇó¶Ô¡°Í¶×ÊÏîÄ¿¡±´¦ÒÔ·£¿î¡£Æ¾¾Ý¶íÂÞ˹˾·¨£¬ÆóÒµÈôδÄÜÓÐЧ±£»¤¿Í»§Êý¾Ý£¬×î¸ß¿ÉÃæ¶Ô2Íò¬²¼£¨Ô¼250ÃÀÔª£©µÄÐÐÕþ´¦·£¡£·ÖÎöÖ¸³ö£¬Ö»¹Ü·£¿î½ð¶î½ÏµÍ£¬µ«ÊÂÎñ¶Ôƽ̨ÃûÓþ¼°¿Í»§ÐÅÀµµÄÇÖº¦¿ÉÄܸüΪÉîÔ¶¡£
https://therecord.media/russia-cyberattack-investment-platform-ukraine
4. еÄDripDropper¶ñÒâÈí¼þÀûÓÃLinux·ì϶²¢½¨¸´·ì϶
8ÔÂ20ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Red Canary½üÈÕÅû¶һÖÖÃûΪDripDropperµÄÐÂÐÍLinux¶ñÒâÈí¼þ£¬Æä¹ÖÒìÕ½ÊõÒý¿¯ÐÐÒµ¹Ø×¢£º¹¥»÷ÕßÔÚÀûÓÃϵͳ·ì϶ÈëÇÖºó£¬×Ô¶¯½¨²¹·ì϶ÒÔ×èÖ¹ÆäËûºÚ¿ÍȾָ£¬´Ó¶øÊµÏÖ¶ÔÖ¸±êµÄ¡°¶À¼Ò½ÚÔ족¡£ÕâÒ»ÊÖ·¨µß¸²ÁË´«Í³¶ñÒâÈí¼þµÄ¹¥»÷ģʽ£¬Í¹ÏÔÍøÂçÍþвµÄ¸´ÔÓÐÔÓë¹¥»÷Õß¼¼ÊõµÄ½ø»¯¡£Æ¾¾ÝRed CanaryµÄ»ã±¨£¬DripDropperµÄ¹¥»÷Á´ÌõʼÓÚApache ActiveMQÖеĹؼü·ì϶CVE-2023-46604¡£Ö»¹Ü¸Ã·ì϶ÒÑÓнüÈýÄ꺹ÇàÇÒ²¹¶¡ÒѰ䲼£¬µ«ÒòÆä¸ß´ï94.44%µÄ½«À´30Ìì±»ÀûÓøÅÂÊ£¨EPSSÆÀ·Ö£©£¬ÈÔ±»¹¥»÷Õß¿í·ºÀûÓ᣺ڿÍͨ¹ý¸Ã·ì϶ֲÈëGodzilla Webshell»òRansomhubÀÕË÷Èí¼þµÈÔØºÉ£¬»ñÈ¡³õʼ½Ó¼ûȨÏÞºó£¬Ñ¸¿ì²¿ÊðÁ½¿îÖ÷Ì⹤¾ß£ºSliver¶ñÒâÈí¼þºÍDripDropperÏÂÔØÆ÷¡£¹¥»÷ÖÐ×î¾ß´´ÐÂÐԵIJÙ×÷³Ê´Ë¿ÌÓÆ¾Ã»¯½×¶Î£ººÚ¿ÍÔÚÕ¾ÎȽŸúºó£¬¾¹ÏÂÔØ¹Ù·½²¹¶¡½¨¸´±»ÀûÓõķì϶£¬¹Ø¹Ø×ÔÉíÈëÇֵġ°ºóÃÅ¡±¡£´Ë¾Ù¼È×èÖ¹ÁËÆäËû¹¥»÷Õßͨ¹ýͳһ·ì϶ÈëÇÖ£¬ÓÖ¸²¸ÇÁ˳õʼÈëÇÖõè¾¶£¬Ê¹·ÀÓùÕßÄÑÒÔ×·Òä¹¥»÷Ô´Í·¡£
https://hackread.com/dripdropper-malware-exploits-linux-flaw-patche-lock-out/
5. Ö÷Á÷ÃÜÂëÖÎÀíÆ÷¿ÉÄÜ»áÔÚµã»÷½Ù³Ö¹¥»÷ÖÐй¶µÇ¼ÐÅÏ¢
8ÔÂ20ÈÕ£¬ÊýǧÍòÓû§ÒÀÀµµÄÁù´óÖ÷Á÷ÃÜÂëÖÎÀíÆ÷£¨1Password¡¢Bitwarden¡¢Enpass¡¢iCloud Passwords¡¢LastPass¡¢LogMeOnce£©½üÆÚ±»ÆØ´æÔÚ佨²¹µÄµã»÷½Ù³Ö·ì϶£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâÍøÒ³ÓÕµ¼Óû§´¥·¢×Ô¶¯Ìî³ä²Ù×÷£¬ÇÔÈ¡ÕË»§Í´´¦¡¢Ë«³É·ÖÈÏÖ¤£¨2FA£©´úÂë¼°ÐÅÓþ¿¨ÐÅÏ¢¡£¶ÀÁ¢×êÑÐÔ±Marek T¨®thÔÚDEF CON 33ºÚ¿Í´ó»áÉϳõ´ÎÅû¶¸Ã·ì϶£¬ÍøÂ簲ȫ¹«Ë¾SocketËæºóÑéÖ¤²¢Ðµ÷¹©¸øÉÌÅû¶£¬½Òʾ¹¥»÷ÕßÀûÓÿçÕ¾¾ç±¾£¨XSS£©»ò»º´æÖж¾ÍøÕ¾¸²¸Ç²»Ë½¼ûHTMLÔªËØ£¬¼Ù×°ÎÞº¦½»»¥£¬ÏÖʵ´¥·¢ÃÜÂëÖÎÀíÆ÷µÄÃô¸ÐÐÅÏ¢×Ô¶¯Ìî³ä¡£¹¥»÷»úÔìµÄÖ÷ÌâÔÚÓڰѳÖä¯ÀÀÆ÷ÖÐÃÜÂëÖÎÀíÆ÷½çÃæÔªËØµÄ²»Í¨Ã÷¶È»ò²¼¾Ö£¬ÀýÈçͨ¹ý½µµÍ×Ô¶¯Ìî³äÏÂÀ²Ëµ¥µÄͨÃ÷¶È£¬»òʹUI×·ËæÊó±ê¹â±ê£¬È·±£Óû§µã»÷ÐéÎ±ÔªËØÊ±Òâ±í´¥·¢Êý¾Ýй¶¡£×êÑи²¸Ç11¿îÖ÷Á÷ÃÜÂëÖÎÀíÆ÷£¬Á˾ÖÏÔʾËùÓÐÊܲâ²úÆ·¾ùÖÁÉÙ´æÔÚÒ»ÖÖ¹¥»÷²½Öè¡£SocketÐÖú֪ͨ¹©¸øÉ̺󣬲¿·ÔìóÒµÒÑÍÆ³ö½¨¸´¡£½ØÖÁÅû¶ʱ£¬Ô¼4000ÍòÓû§Ê¹ÓõÄÃÜÂëÖÎÀíÆ÷°æ±¾ÈÔÒ×Êܹ¥»÷¡£
https://www.bleepingcomputer.com/news/security/major-password-managers-can-leak-logins-in-clickjacking-attacks/
6. ¶íÂÞ˹¼äµý×éÖ¯ÀûÓÃ7Äê¾É·ì϶³ÖÐøÉøÈëÈ«ÇòÍøÂçÉ豸
8ÔÂ20ÈÕ£¬Ë¼¿ÆTalos°²È«ÍŶӽüÈÕÅû¶£¬Ò»¸öÓë¶íÂÞ˹Áª¹ú°²È«¾Ö£¨FSB£©µÚ16ÖÐÐĹØÁªµÄ¼äµý×éÖ¯¡°¾²Ì¬Ì¦Ô¡±£¨Static Tundra£©ÔÚ´ÓǰʮÓàÄê¼ä³ÖÐøÀûÓÃ2018ÄêÒѽ¨²¹µÄCVE-2018-0171·ì϶£¬ÈëÇÖÈ«ÇòÍøÂçÉ豸²¢ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¸Ã×éÖ¯±»ÊÓΪ¸ü¿í·ºÍþв×éÖ¯¡°ÄÜÁ¿ÐÜ¡±£¨Energetic Bear£©µÄ·ÖÖ§£¬ÆäÐж¯Òò¶íÎÚì¶ÜÏÔÖøÉý¼¶£¬Ö¸±ê¸²¸Ç±±ÃÀ¡¢ÑÇÖÞ¡¢·ÇÖÞ¼°Å·Ö޵ĵçÐÅ¡¢¸ßµµ½ÌÓýºÍÔì×÷Òµ»ú¹¹£¬ÓÈÆä½«ÎÚ¿ËÀ¼ÊµÌåÁÐΪ³Áµã¶ÔÏó¡£Ö»¹ÜCVE-2018-0171·ì϶µÄ²¹¶¡ÔçÔÚÆßÄêǰ°ä²¼£¬µ«´óÁ¿Î´Éý¼¶É豸»òÔËÐб¨·ÏÉ豸µÄ×éÖ¯ÈԳɹ¥»÷Ö¸±ê¡£¹¥»÷Õßͨ¹ýShodanµÈÍøÂçɨÃ蹤¾ß¼ø±ð´àÈõÉ豸£¬ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë»ò´¥·¢»Ø¾ø·þÎñ£¬Ëæºóͨ¹ýTFTP·þÎñÆ÷ºÍSNMP¹¤¾ßÌáÈ¡É豸ÅäÖá¢Æ¾Ö¤¼°ÍøÂçÐÅÏ¢£¬³ÉÁ¢³Ö¾ÃÒñ±Î½Ó¼û¡£Ë¼¿ÆTalosÖ¸³ö£¬Static TundraÒÑ¿ª·¢×Ô¶¯»¯¹¤¾ßʵÏÖ´ó¹æÄ£¹¥»÷£¬ÆäÕ½ÊõÓë¶íÂÞ˹¹ú¶ÈÀûÒæ¸ß¶È·ûºÏ£¬ÀýÈçÔÚ¶íÎÚì¶Ü·¢×÷ºóѸ¿ìÀ©´ó¶ÔÎÚ¿ËÀ¼Ö¸±êµÄ¹¥»÷ÁìÓò¡£
https://cyberscoop.com/russian-static-tundra-hacks-cisco-network-devices-cve-2018-0171/


¾©¹«Íø°²±¸11010802024551ºÅ