Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬Zscaler¿Í»§ÐÅÏ¢±íй
°ä²¼¹¦·ò 2025-09-031. Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬Zscaler¿Í»§ÐÅÏ¢±íй
9ÔÂ1ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Zscaler½üÈÕÅû¶£¬ÆäSalesforceÊ·ýÒòµÚÈý·½¼¯³É¹¤¾ßÔâÈëÇÖÒý·¢Êý¾Ýй¶£¬¿Í»§Ãô¸ÐÐÅÏ¢¼°²¿ÃÅÖ§³Ö°¸ÀýÄÚÈݱ»ÇÔÈ¡¡£ÊÂÎñÔ´ÓÚSalesloft Drift±»¹¥»÷ÕßÀûÓã¬ÆäOAuthÁîÅÆºÍË¢ÐÂÁîÅÆÔâÇÔ£¬µ¼ÖÂδ¾ÊÚȨµÄÐÐΪÕß½Ó¼ûZscalerµÄSalesforce»·¾³¡£Ð¹Â¶Êý¾ÝÔ̺¬¿Í»§ÐÕÃû¡¢Ã³Ò×ÓÊÏ䡢ְλ¡¢µç»°ºÅÂë¡¢ÇøÓòÐÅÏ¢¡¢²úÆ·Ðí¿ÉÏêÇé¼°Ö§³Ö°¸ÀýÄÚÈÝ£¬µ«ZscalerÇ¿µ÷Õâ´ÎÊÂÎñ䲨¼°¹«Ë¾×ÔÉí²úÆ·¡¢·þÎñ»ò»ù´¡ÉèÊ©¡£¹È¸èÍþвµý±¨Ó××飨GTIG£©½«Õâ´Î¹¥»÷¹éÒòÓÚ×·×ÙΪUNC6395µÄÍþв×éÖ¯£¬²¢Ö¸³öÆäÖ¸±êΪ»ñÈ¡¿Í»§ÔÚÖ§³Ö°¸ÀýÖзÖÏíµÄÃô¸Ðƾ֤£¬ÈçAWS½Ó¼ûÃÜÔ¿¡¢ÃÜÂë¼°SnowflakeÓйØÁîÅÆ¡£¹¥»÷Õßͨ¹ýɾ³ý²éÎÊ×÷Òµ¸²¸ÇºÛ¼££¬µ«ÈÕ־δÊÜÓ°Ï죬¹È¸è½¨ÒéÊÜÓ°Ïì×éÖ¯Éó²éÈÕÖ¾ÒÔÈ·ÈÏÊý¾Ý¶³öÇé¿ö¡£½øÒ»´ëÊ©²éÏÔʾ£¬Salesloft¹©¸øÁ´¹¥»÷²»½öÓ°ÏìDriftÓëSalesforceµÄ¼¯³É£¬»¹²¨¼°ÆäÓÃÓÚÖÎÀíÓʼþ»Ø¸´ºÍCRMÊý¾Ý¿âµÄDrift EmailÖ°ÄÜ¡£¹¥»÷ÕßÉõÖÁÀûÓÃÇÔÈ¡µÄOAuthÁîÅÆ½Ó¼ûGoogle WorkspaceÓÊÏä²¢¶ÁÈ¡Óʼþ£¬´Ùʹ¹È¸èÓëSalesforceÁÙʱ½ûÓÃDrift¼¯³É¡£
https://www.bleepingcomputer.com/news/security/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise/
2. ¶ñÒânpm°ü¼Ù×°³ÉÓʼþ¿âÖ´ÐмÓÃÜÇ®±ÒÇ®°üÇÔÈ¡¹¥»÷
9ÔÂ2ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶һ·Õë¶Ô¼ÓÃÜÇ®±ÒÓû§µÄ¹©¸øÁ´¹¥»÷ÊÂÎñ£º¶ñÒânpm°ü"nodejs-smtp"ͨ¹ý¼ÙÒâ³ÛÃûÓʼþ¿âNodemailer£¬³É¹¦½«¶ñÒâ´úÂë×¢ÈëAtomic¡¢ExodusµÈÖ÷Á÷¼ÓÃÜÇ®±ÒÇ®°üµÄWindows×ÀÃæÀûÓã¬ÇÔÈ¡Óû§ÂòÂô×ʽ𡣸ÃÈí¼þ°üÓÉÓû§"nikotimon"ÓÚ2025Äê4ÔÂÉÏ´«ÖÁnpm×¢²á±í£¬ÀÛ¼ÆÏÂÔØ347´Îºó±»Ï¼ܣ¬Ä¿Ç°ÈÔ¿Éͨ¹ýº¹Çà°æ±¾»ñÈ¡¡£Socket×êÑÐÔ±Kirill Boychenko½Òʾ£¬¸Ã¶ñÒâ°üѡȡ˫³Á¼Ù×°Õ½Êõ£º±í±íÌṩÓëNodemailerÆëÈ«¼æÈݵÄSMTPÓʼþÖ°ÄÜ£¬ÏÖ×Åʵµ¼ÈëʱÀûÓÃElectron¹¤¾ß½âѹǮ°üÀûÓõÄapp.asarÎļþ£¬ÓÃÍþвÐÐΪÕß½ÚÔìµÄÓ²±àÂëÇ®°üµØÖ·´úÌæÓû§ÊÕ¼þµØÖ·£¬ÊµÏÖ±ÈÌØ±Ò¡¢ÒÔÌ«·»¡¢USDT¡¢XRP¼°SolanaµÈÖ÷Á÷¼ÓÃÜÇ®±ÒµÄÂòÂô½Ù³Ö¡£Æä¹¥»÷Á÷³ÌÉè¼Æ¾«Ãͨ¹ýÅú¸Ä×ÀÃæÀûÓÃÖ÷ÌâÎļþʵÏÖÓÆ¾Ã»¯´Û¸Ä£¬³ÁÆôºóÈÔ¿ÉÉúЧ£¬Í¬Ê±×Ô¶¯É¾³ý¹¤×÷Ŀ¼ºÛ¼££¬´ó·ù½µµÍ¶³ö·çÏÕ¡£¼¼Êõ·ÖÎöÏÔʾ£¬nodejs-smtpµÄ¹¥»÷´úÂëǶÈëÔÚÓʼþÖ°ÄÜʵÏÖÖУ¬Í¨¹ýNodemailer¼æÈݽӿڽµµÍ¿ª·¢Õß¾¯ÌèÐÔ¡£µ±Óû§ÔÚ¿ª·¢»·¾³Öе¼Èë¸Ã°üʱ£¬Æä¶ñÒâÄ£¿é»á×Ô¶¯¼ì²âϵͳÖÐÊÇ·ñ×°ÖÃAtomic»òExodusÇ®°ü£¬Ò»µ©·¢ÏÖ¼´Ö´Ðнâѹ-´úÌæ-´ò°ü²Ù×÷£¬½«ºÏ·¨Ç®°üÀûÓÃת»¯ÎªÇÔÈ¡¹¤¾ß¡£
https://thehackernews.com/2025/09/malicious-npm-package-nodejs-smtp.html
3. CloudflareÔÚSalesforce¹©¸øÁ´¹¥»÷ÖÐÔâ·êÊý¾Ýй¶
9ÔÂ2ÈÕ£¬½üÆÚ£¬Ò»³¡ÒÔSalesforceƽ̨Ϊָ±êµÄ¹©¸øÁ´¹¥»÷Òý·¢¶àÆðÊý¾Ýй¶ÊÂÎñ£¬Cloudflare³ÉΪ×îÐÂÊÜÓ°ÏìÆóÒµ¡£Õâ´Î¹¥»÷Á´Ô´ÓÚÍþвÐÐΪÕßͨ¹ýÓïÒô´¹µö£¨vishing£©Éç»á¹¤³Ì¼¿Á©£¬ÓÕÆÆóÒµÔ±¹¤½«¶ñÒâOAuthÀûÓùØÁª´ó¹«Ë¾SalesforceÊ·ý£¬½ø¶øÇÔÈ¡Êý¾Ý¿â¡£8ÔÂ9ÈÕÖÁ17ÈÕÆÚ¼ä£¬¹¥»÷ÕßÊ×ÏȶÔCloudflareµÄSalesforceÊ·ý·¢Õ¹¿úËÅ£¬ËæºóÇÔÈ¡ÁËÆäÄÚ²¿¿Í»§°¸ÀýÖÎÀí¼°Ö§³ÖϵͳÖеÄÎı¾Êý¾Ý£¬Éæ¼°104¸öCloudflare APIÁîÅÆ¼°´óÁ¿¿Í»§Ö§³Ö¹¤µ¥ÄÚÈÝ¡£Ö»¹ÜĿǰδ·¢ÏÖÁîÅÆ±»ÀÄÓ㬵«Ð¹Â¶ÐÅÏ¢Ô̺¬¿Í»§ÁªÏµ×ÊÁÏ¡¢ÅäÖÃÏêÇé¼°¿ÉÄÜ´æÔڵĽӼûƾ֤µÈÃô¸ÐÊý¾Ý£¬CloudflareÒÑ´¹Î£ÂÖ»»È«ÊýÊÜÓ°ÏìÁîÅÆ²¢Í¨Öª¿Í»§£¬½¨ÒéÂÖ»»Í¨¹ýÖ§³ÖÇþ·¹²ÏíµÄÍ´´¦¡£Õâ´Î¹©¸øÁ´¹¥»÷¶³ö³öÆóÒµÒÀÀµµÚÈý·½SaaSƽ̨µÄ°²È«·çÏÕ¡£¹¥»÷Õßͨ¹ýµ¥Ò»Æ½Ì¨·ì϶¼´¿ÉºáÏò²¨¼°Êý°Ù¼Ò¿Í»§£¬ÇÔÈ¡µÄ¿Í»§Ö§³Ö¹¤µ¥Êý¾Ý£¨ÈçÈÕÖ¾¡¢ÁîÅÆ¡¢ÃÜÂ룩¿ÉÄܳÉΪºóÐøÕë¶ÔÐÔ¹¥»÷µÄÌø°å¡£Ö»¹ÜÊÜÓ°ÏìÆóÒµ¾ùÇ¿µ÷䲨¼°Ö÷Ìâϵͳ£¬µ«Ãô¸ÐÐÅϢй¶ÈÔ¿ÉÄÜÒý·¢¿Í»§ÐÅÀµÎ£»ú¼°ºÏ¹æ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/
4. ºÚ¿Í¹¥»÷Evertec°ÍÎ÷×Ó¹«Ë¾Sinqia£¬ÊÔͼÇÔÈ¡1.3ÒÚÃÀÔª
9ÔÂ2ÈÕ£¬À¶¡ÃÀÖÞ½ðÈڿƼ¼¾ÞÍ·EvertecµÄ°ÍÎ÷×Ó¹«Ë¾Sinqia S.A.½üÈÕÔâ·ê³Á´óÍøÂç¹¥»÷ÊÂÎñ£¬ºÚ¿Íͨ¹ýÇÔÈ¡µÄIT¹©¸øÉÌÕË»§Æ¾Ö¤£¬ÓÚ8ÔÂ29ÈÕ·¸·¨ÇÖÈëÆäÕÆ¹ÜÔËÓªµÄ°ÍÎ÷ÑëÐÐʵʱ֧¸¶ÏµÍ³£¨Pix£©»·¾³£¬ÊÔͼͨ¹ýÁ½¼Ò½ðÈÚ»ú¹¹¿Í»§ÌáÒé×ܶî´ï1.3ÒÚÃÀÔªµÄδ¾ÊÚȨÆóÒµ¼äתÕË¡£Ö»¹Ü²¿ÃÅ×ʽðÒѱ»×·»Ø£¬µ«¾ßÌå½ð¶îδ¹«¿ª£¬ÇÒÊÂÎñ¶ÔEvertec²ÆÕþ¼°ÃûÓþµÄDZÔÚÓ°ÏìÈÔ±»ÆÀ¹ÀΪ"¿ÉÄܳÁ´ó"¡£Æ¾¾ÝEvertecÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ìá½»µÄÎļþ£¬Õâ´Î¹¥»÷¶³öÁ˰ÍÎ÷¼´Ê±Ö§¸¶ÏµÍ³PixµÄ°²È«´àÈõÐÔ¡£×÷Ϊ°ÍÎ÷ÑëÐÐ2020ÄêÍÆ³öµÄÈ«Ììºò¼´Ê±×ªÕËϵͳ£¬PixÒѸ²¸ÇÈ«¹ú³¬¹ý°ëÊý³ÉÄêÈ˶¡£¬µ«ÆµÈÔ³ÉΪAndroidÒøÐжñÒâÈí¼þ¹¥»÷Ö¸±ê¡£Õâ´ÎÊÂÎñÖУ¬ºÚ¿ÍÀûÓõÚÈý·½¹©¸øÉÌÕË»§È¨ÏÞ£¬Í»ÆÆÁËSinqiaΪ24¼Ò°ÍÎ÷½ðÈÚ»ú¹¹ÌṩµÄPixÖ§¸¶´¦Öû·¾³£¬Ö»¹ÜEvertecÇ¿µ÷δ·¢ÏÖÓ×ÎÒÊý¾Ýй¶£¬µ«¹¥»÷ÕßÈÔÊÔͼͨ¹ý»ã·áÒøÐеȿͻ§ÌáÒé´ó¹æÄ£×ʽð×ªÒÆ¡£»ã·áÒøÐлØÓ¦³Æ¿Í»§×ʽðÓëÊý¾ÝδÊÜÓ°Ï죬µ«ÊÂÎñ͹ÏÔ½ðÈÚ»ú¹¹¶ÔµÚÈý·½·þÎñÉ̵ݲȫÒÀÀµ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/hackers-breach-fintech-firm-in-attempted-130m-bank-heist/
5. ½Ý±ªÂ·»¢ÔâÍøÂç¹¥»÷ÖÂϵͳ¹Ø¹Ø£¬³ö²úÁãÊÛÊÜÓ°Ïì
9ÔÂ2ÈÕ£¬½Ý±ªÂ·»¢£¨JLR£©½üÈÕÔâ·êÍøÂç¹¥»÷£¬±»ÆÈ¹Ø¹Ø²¿ÃÅϵͳÒÔ»º½âÓ°Ï죬µ¼ÖÂÆä³ö²úºÍÁãÊÛÒµÎñÊܵ½ÑϳÁ×ÌÈÅ¡£Æ¾¾Ý¹«Ë¾¹Ù·½ÉêÃ÷£¬Õâ´ÎÊÂÎñÖÐËäδ·¢ÏÖ¿Í»§Êý¾Ý±»µÁ¼£Ï󣬵«ÁãÊ۶˺ͳö²ú»·½Ú¾ù³öÏÖÏÔÖøÖжϡ£½Ý±ªÂ·»¢°µÊ¾£¬ÊÂÎñ²úÉúºóµ±¼´×Ô¶¯¹Ø¹ØÊÜÓ°Ïìϵͳ£¬Ä¿Ç°Õý°´´òËãÖð²½³ÁÆôÈ«ÇòÀûÓ÷¨Ê½£¬µ«ÉÐδÌṩ¸´ÔÕý³£ÔËÓªµÄ¾ßÌ幦·ò±í£¬Ò²Î´Åû¶¹¥»÷ÀàÐÍ»ò¼¼Êõϸ½Ú¡£×÷ΪËþËþÆû³µÆìÏÂ×Ó¹«Ë¾£¬½Ý±ªÂ·»¢ÄêÊÕÈ볬380ÒÚÃÀÔª£¬Äê²úÁ¿³¬40ÍòÁ¾£¬Õ¼ÓÐ3.9ÍòÃûÔ±¹¤£¬ÆäË÷Àû¹þ¶û¹¤³§Õƹܳö²ú·»¢·¢ÏÖ¡¢À¿Ê¤¼°À¿Ê¤»î¶¯°æµÈÈȵ㳵ÐÍ¡£Õâ´Î¹¥»÷µ¼ÖÂÓ¢¹ú¾ÏúÉÌÎÞ·¨×¢²áгµ»ò¹©¸øÁã¼þ£¬³ö²úϵͳҲһ¶ÈÍ£°Ú£¬µ«¹«Ë¾Ç¿µ÷¿Í»§Êý¾Ý°²È«ÐÔδÊÜÍþв¡£Õâ´Î¹¥»÷²úÉúÔÚÖÜÄ©£¬Õâһʱ¶Î³£±»ÍþвÐÐΪÕßÀûÓã¬ÒòÆóÒµÓ¦¼±ÏìÓ¦ÄÜÁ¦Ïà¶Ô½ÏÈõ¡£½ØÖÁĿǰÉÐδÓÐÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´ËÕÆ¹Ü¡£
https://www.bleepingcomputer.com/news/security/jaguar-land-rover-says-cyberattack-severely-disrupted-production/
6. Palo Alto NetworksÔâSalesforce¹©¸øÁ´¹¥»÷й¶¿Í»§Êý¾Ý
9ÔÂ2ÈÕ£¬Palo Alto Networks½üÈÕÈ·ÈÏ£¬Æä³ÉΪÉÏÖÜÅû¶µÄSalesloft Drift¹©¸øÁ´¹¥»÷ÊÂÎñÖеÄÊÜÓ°ÏìÆóÒµÖ®Ò»£¬¹¥»÷Õßͨ¹ýÇÔÈ¡µÄOAuthÁîÅÆ·¸·¨½Ó¼ûÆäSalesforce CRMϵͳ£¬µ¼Ö¿ͻ§ÁªÏµÐÅÏ¢¡¢ÄÚ²¿ÏúÊۼͼ¼°Ö§³Ö°¸ÀýÊý¾Ýй¶£¬µ«Î´²¨¼°¹«Ë¾Ö÷Ìâ²úÆ·¡¢ÏµÍ³»ò·þÎñ¡£Õâ´ÎÊÂÎñ¶³öÁËÍþвÐÐΪÕßÕë¶ÔSalesforceÉú̬µÄ¹æÄ£»¯Êý¾ÝÇÔȡսÊõ£¬¹¥»÷Õßͨ¹ýÀÄÓõÚÈý·½ÀûÓ÷ì϶£¬´ÓÊý°Ù¼ÒÆóÒµÖÐÅúÁ¿ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬Palo Alto NetworksÒÑ´¹Î£½ûÓÃÓйØÀûÓò¢ÂÖ»»Æ¾Ö¤£¬Í¬Ê±ÖÒ¸æ¿Í»§Ð辯ÌèºóÐøÕë¶ÔÐÔ¹¥»÷¡£Õâ´Î¹¥»÷Ô´ÓÚÍþвÐÐΪÕßÀûÓÃSalesloft DriftÀûÓ÷¨Ê½·ì϶»ñÈ¡µÄOAuthÁîÅÆ£¬½ø¶øÉøÈëÆäSalesforce»·¾³¡£Ö»¹Üй¶Êý¾Ý½öÏÞÓÚÁªÏµÐÅÏ¢¡¢Îı¾ÆÀÂÛ¼°»ù´¡°¸ÀýÊý¾Ý£¬Î´Ô̺¬¼¼Êõ¸½¼þ»òÎļþ£¬µ«¹¥»÷ÕßÈÔͨ¹ý×Ô¶¯»¯¹¤¾ß£¨Èç×Ô½ç˵Python¾ç±¾£©´ÓÕË»§¡¢ÁªÏµÈË¡¢°¸ÀýµÈSalesforce¶ÔÏóÖдó¹æÄ£ÌáÈ¡Êý¾Ý£¬²¢³ÁµãɨÃèAWSÃÜÔ¿¡¢SnowflakeÁîÅÆ¡¢VPN/SSOƾ֤µÈ¸ß¼ÛÖµÐÅÏ¢£¬Òâͼͨ¹ýÇÔÈ¡µÄÔÆÆ½Ì¨½Ó¼ûȨÏÞÖ´ÐÐÊý¾ÝÀÕË÷»òºáÏòÉøÈë¡£
https://www.bleepingcomputer.com/news/security/palo-alto-networks-data-breach-exposes-customer-info-support-cases/


¾©¹«Íø°²±¸11010802024551ºÅ