°ÍÄÃÂí¾­¼ÃºÍ²ÆÕþ²¿ÔâINCÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2025-09-15

1. °ÍÄÃÂí¾­¼ÃºÍ²ÆÕþ²¿ÔâINCÀÕË÷Èí¼þ¹¥»÷


9ÔÂ11ÈÕ £¬°ÍÄÃÂí¾­¼ÃºÍ²ÆÕþ²¿£¨MEF£©½üÈÕÅû¶ £¬Æäһ̨¹¤×÷Õ¾ÍÆËã»ú¿ÉÄÜÔâ·ê¶ñÒâÈí¼þ¹¥»÷ £¬µ±¾ÖÒÑÆô¶¯°²È«·¨Ê½²¢Ç¿µ÷ÊÂÎñÒѵõ½½ÚÔì £¬Î´Ó°ÏìÖ÷ÌâϵͳÔËÓª¡£MEFÔÚ¹Ù·½ÉêÃ÷ÖÐÖ¸³ö £¬¼ì²âµ½Òì³£ºóµ±¼´¼¤»î¼È¶¨°²È«ºÍ̸ £¬¼ÓÇ¿Õû¸öITϵͳµÄÔ¤·À´ëÊ© £¬²¢Ã÷È·ÖÐÑëϵͳ¼°Æ½Ì¨¾ùδÊÜË𠣬ĿǰÕý³£ÔËÐС£×÷Ϊ°ÍÄÃÂíÖ÷Ìâ²ÆÕþÖÎÀí»ú¹¹ £¬MEFÕÆ¹Ü²ÆÕþÕþ²ßÔì¶©¡¢¹«¹²Ö§³öµ÷¿Ø¡¢Õ®ÎñÖÎÀí¼°°ÍÄÃÂíÔ˺ÓÊÕÈëÖÎÀí¡£¸Ã²¿Ç¿µ÷ £¬Ó×ÎÒÓë»ú¹¹Êý¾Ý°²È« £¬²¢ÒÑÖ´ÐÐËùÓÐÐÐÒµ³ß¶È·À»¤´ëÊ©ÒÔ·À±¸ºóÐø·çÏÕ¡£È»¶ø £¬ÀÕË÷Èí¼þ×éÖ¯INC RansomÉÏÖÜÔÚ°µÍøÊý¾ÝÐ¹Â¶ÍøÕ¾°ä²¼ÉêÃ÷ £¬Ðû³Æ¶ÔMEFÌáÒé¹¥»÷²¢ÇÔÈ¡³¬¹ý1.5TBÊý¾Ý £¬Ô̺¬µç×ÓÓʼþ¡¢²ÆÕþÎļþ¡¢Ô¤ËãÃ÷ϸµÈÃô¸ÐÐÅÏ¢¡£¸Ã×éÖ¯ÓÚ9ÔÂ5ÈÕ½«MEFÁÐÈëÊܺ¦ÕßÃûµ¥ £¬²¢Ð¹Â¶ÄÚ²¿ÎļþÑù±¾×÷ΪΥ¹æÖ¤¾Ý¡£INC Ransom³ÉÁ¢ÓÚ2023ÄêÖÐÆÚ £¬ÒÔÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½ÔË×÷ £¬Ôø¹¥»÷¶à¼Ò³ÛÃûÆóÒµ¡£


https://www.bleepingcomputer.com/news/security/panama-ministry-of-economy-discloses-breach-claimed-by-inc-ransomware/


2. Farmer Bros.ÔâÍøÂç¹¥»÷ÖÂ1.4ÍòÈËÊý¾Ýй¶


9ÔÂ10ÈÕ £¬×ܲ¿Î»Óڵ¿ËÈøË¹ÖݵĿ§·È¼°Ê³Æ··þÎñ¹«Ë¾Farmer Bros.½üÈÕÅû¶ £¬½ñÄê3Ô³õ²úÉúµÄÒ»Â·ÍøÂç¹¥»÷µ¼Ö³¬¹ý1.4ÍòÈËÊý¾Ýй¶¡£¾Ý¸Ã¹«Ë¾Ìá½»¸øÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒµÄ֪ͨ £¬¹¥»÷ÕßÔÚϵͳÄÚ¡°ÅÇ»²¡±½ü12Ììºó±»¾õ²ì £¬¹«Ë¾Ëæ¼´Æô¶¯µ÷²é²¢´«µÝ·¨Âɲ¿ÃÅЭÖú²é¾¿¡£Êý¾Ýй¶֪ͨÏÔʾ £¬¹¥»÷Õß»ñÈ¡Á˲¿ÃÅÓ×ÎÒÐÅÏ¢ £¬µ«¾ßÌåй¶×ֶα»Í¿ºÚδ¹«¿ª¡£×÷Ϊ²¹¾È´ëÊ© £¬Farmer Bros.ΪÊÜÓ°Ïì¸ö±ðÌṩÃâ·ÑÉí·Ý͵ÇÔ¼°ÐÅÓþ¼à¿Ø·þÎñ £¬´ËÀà·þÎñͨ³£Õë¶Ô¿ÉÄÜÔ̺¬ÐÕÃû¡¢ÓÊÏä¡¢Éç±£ºÅµÈÃô¸Ð±êʶ·ûµÄй¶³¡¾° £¬ÒÔ·À±¸Ú²Æ­·çÏÕ¡£¹«Ë¾ÌáÐÑÓû§¶¨ÆÚ²é³­ÕË»§¼°ÐÅÓþ»ã±¨ £¬¾¯ÌèÒì³ £»î¶¯¡£ÖµµÃ¹Ø×¢µÄÊÇ £¬ChaosÀÕË÷Èí¼þÍÅ»ïÔøÓÚ½ñÄê4Ô³õÐû³Æ°ÑÎոù«Ë¾Êý¾Ý £¬²¢Ðû³ÆÇÔÈ¡ÁË650GBÐÅÏ¢¡£Ä¿Ç°ÉÐÎÞ·¨È·ÈϸÃÉêÃ÷Óë±¾´Îй¶ÊÂÎñµÄÖ±½Ó¹ØÁª £¬µ«¹¦·òÏߵĸ߶ȳÁºÏÒý°ä·¢½ç¶ÔÀÕË÷ÍÅ»ï²Î¼ÓµÄ´§Ä¦¡£


https://cybernews.com/security/farmer-bros-data-breach-victims/


3. CISA½«´ïË÷ϵͳ¸ßΣ·ì϶ÄÉÈëKEVĿ¼


9ÔÂ12ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«´ïË÷ϵͳDELMIA AprisoÈí¼þµÄ¸ßΣ·ì϶£¨CVE-2025-5086 £¬CVSSÆÀ·Ö9.0£©ÁÐÈëÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¸Ã·ì϶Ϊ²»ÊÜÐÅÀµÊý¾Ý·´ÐòÁл¯ÎÊÌâ £¬Ó°ÏìDELMIA Apriso´Ó2020°æÖÁ2025°æµÄ¶à¸ö°æ±¾ £¬¹¥»÷Õß¿ÉÀûÓô˷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë £¬¶Ô¹¤ÒµÔì×÷ÔËÓª×é³ÉÑϳÁÍþв¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄÔËÓªÖ¸ÁBOD£©22-01ÒªÇó £¬Áª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹±ØÐëÔÚ2025Äê10ÔÂ2ÈÕǰʵÏÖ·ì϶½¨¸´ £¬ÒÔ½µµÍÂä´ó·çÏÕ¡£CISAͬʱ½¨Òé¸öÈË×éÖ¯Éó²éKEVĿ¼ £¬×Ô¶¯ÅŲ鲢½¨¸´×ÔÉí»ù´¡ÉèÊ©ÖеÄͬÀà·ì϶¡£´ïË÷ϵͳDELMIA Apriso×÷ΪÔì×÷ÔËÓªÖÎÀí£¨MOM£©Æ½Ì¨ £¬¿í·ºÀûÓÃÓÚÈ«Çò¹¤ÒµÆóÒµµÄ³ö²ú¼à¿ØÓëÓÅ»¯ £¬Æä°²È«ÐÔÖ±½Ó¹ØÏµµ½¹Ø¼ü»ù´¡ÉèÊ©²»±ä¡£±¾´Î·ì϶ÓÉHacktron AI»ã±¨ £¬CISAͨ¹ýKEVĿ¼»úÔìÍÆ¶¯¼±¾çÏìÓ¦ £¬ÌåÏÖ¡°·¢ÏÖ-´«µÝ-½¨¸´¡±µÄ¹Ø»·ÖÎÀíÂß¼­¡£


https://securityaffairs.com/182120/hacking/u-s-cisa-adds-dassault-systemes-delmia-apriso-flaw-to-its-known-exploited-vulnerabilities-catalog.html


4. FBIÖÒ¸æUNC6040¡¢UNC6395ºÚ¿ÍÇÔÈ¡SalesforceÊý¾Ý


9ÔÂ14ÈÕ £¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©°ä²¼FLASH¾¯±¨ £¬ÖÒ¸æÁ½¸öÍþв¼¯ÈºUNC6040ºÍUNC6395Õýͨ¹ý¹¥»÷×éÖ¯µÄSalesforce»·¾³ÇÔÈ¡Êý¾Ý²¢Ö´ÐÐÀÕË÷¡£²¼¸æÖ¸³ö £¬ÕâÁ½¸ö¼¯ÈºµÄ¶ñÒâ»î¶¯µ¼ÖÂÊý¾Ý͵ÇÔºÍÀÕË÷ÊÂÎñ¼¤Ôö £¬FBIµ«Ô¸Í¨¹ý°ä²¼ÈëÇÖÖ¸±ê£¨IOC£©ÌáÉý¹«¼Ò·ÀÓùÄÜÁ¦¡£UNC6040ÓÚ2024Äê6ÔÂÓÉGoogleÍþвµý±¨ÍŶӳõ´ÎÅû¶ £¬¸Ã¼¯Èº×Ô2024Äêµ×ÆðÀûÓÃÉç»á¹¤³ÌºÍÓïÒô´¹µö¹¥»÷ £¬ÓÕÆ­Ô±¹¤½«¶ñÒâSalesforce Data Loader OAuthÀûÓÃÏνÓÖÁÆóÒµÕË»§¡£¹¥»÷Õß³£¼ÙÒâITÖ§³ÖÈËÔ± £¬Ê¹Óá°Î񵀮±ÎñÃÅ»§¡±µÈ¼Ù×°ÀûÓà £¬Í¨¹ýOAuthÏνӴó¹æÄ£ÇÔÈ¡SalesforceÊý¾Ý £¬ËæºóÓÉShinyHuntersÀÕË÷×éÖ¯ÀûÓÃÕâЩÊý¾Ý½øÐÐÀÕË÷ £¬ÖØÒªÕë¶Ô´æ´¢¿Í»§Êý¾ÝµÄ¡°ÕË»§¡±ºÍ¡°ÁªÏµÈË¡±Êý¾Ý¿â¡£8Ô £¬ÁíÒ»¼¯ÈºUNC6395ͨ¹ý±»µÁµÄSalesloft Drift OAuthºÍË¢ÐÂÁîÅÆ¹¥»÷SalesforceÊ·ý £¬ÇÔȡ֧³Ö°¸ÀýÖеĻúÃÜÐÅÏ¢ £¬Ô̺¬AWSÃÜÔ¿¡¢ÃÜÂëºÍSnowflakeÁîÅÆ £¬½ø¶øÉøÈëÆäËûÔÆ»·¾³¡£SalesloftÒÑÓëSalesforceºÏ×÷³·ÏúËùÓÐDriftÁîÅÆ £¬²¢ÒªÇó¿Í»§³ÁÐÂÈÏÖ¤¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/


5. VoidProxyÍøÂç´¹µöƽ̨ÀûÓÃÖÐÑëÈ˹¥»÷ÇÔȡ΢Èí¹È¸èÕË»§Æ¾Ö¤


9ÔÂ14ÈÕ £¬½üÈÕ £¬Ò»¸öÃûΪVoidProxyµÄÐÂÐÍÍøÂç´¹µö¼´·þÎñ£¨PhaaS£©Æ½Ì¨±»ÆØ¹â £¬ÆäÕë¶ÔMicrosoft 365¡¢GoogleÕË»§¼°ÊÜOktaµÈµÚÈýµØÆõµãµÇ¼£¨SSO£©± £»¤µÄÕË»§ÌáÒé¹¥»÷¡£¸Ãƽ̨ÓÉOktaÍþвµý±¨ÍŶӷ¢ÏÖ £¬±»ÃèÊöΪ¡°¿ÉÀ©´ó¡¢¿É¶ã±ÜÇÒ¸´ÔÓ¡± £¬Ñ¡È¡ÖÐÑëÈË£¨AitM£©Õ½ÊõʵʱÇÔÈ¡Óû§Æ¾Ö¤¡¢¶à³É·ÖÈÏÖ¤£¨MFA£©´úÂë¼°»á»°cookie¡£¹¥»÷ʼÓÚÊÜϰȾµÄµç×ÓÓʼþ·þÎñÕË»§·¢ËÍÔ̺¬Ëõ¶ÌÁ´½ÓµÄ´¹µöÓʼþ¡£ÊÕ¼þÈ˵ã»÷Á´½Óºó £¬»á¾­ÀúÂŴγÁ¶¨Ïò £¬×îÖÕ½Ó¼ûÍйÜÔÚ.icu¡¢.sbs¡¢.xyzµÈµÍ³É±¾ÓòÃûÉϵĴ¹µöÍøÕ¾¡£ÕâÐ©ÍøÕ¾ÀûÓÃCloudflare± £»¤°µ²ØÕæÊµIP £¬²¢Í¨¹ýCloudflare Worker»·¾³¹ýÂËÁ÷Á¿¡¢¼ÓÔØÒ³Ãæ¡£½Ó¼ûÕßÐèÏÈͨ¹ýCloudflare CAPTCHAÑéÖ¤ÒÔÅųý»úеÈË £¬Ôö³¤Ò³Ãæ¿ÉÐŶÈ¡£´¹µöÒ³Ãæ·ÂÕÕMicrosoft»òGoogleµÇ¼½çÃæ £¬²¿ÃÅÖ¸±ê»á±»Êèµ¼ÖÁÎÞº¦µÄ¡°Ó­½Ó¡±Ò³ÃæÒÔ»ìºÏ¼ì²â¡£µ±Óû§ÊäÈëÆ¾Ö¤Ê± £¬ÒªÇó»áͨ¹ýVoidProxy´úÀíÖÁGoogle»òMicrosoft·þÎñÆ÷¡£¶ÔÓÚʹÓÃOkta SSOµÄ½áºÏÕË»§ £¬¹¥»÷»á½øÈëµÚ¶þ½×¶Î £¬¼ÙÒâOktaµÄSSOÁ÷³ÌÒ³Ãæ £¬½øÒ»²½ÇÔÊØÐÅÏ¢¡£VoidProxyµÄ´úÀí·þÎñÆ÷ÔÚÊܺ¦ÕßÓëºÏ·¨·þÎñ¼äÖмÌÁ÷Á¿ £¬Í¬Ê±²¶»ñ´«ÊäÖеÄÓû§Ãû¡¢ÃÜÂë¡¢MFA´úÂë £¬²¢À¹½ØºÏ·¨·þÎñ·¢·ÅµÄ»á»°cookie £¬¹©¹¥»÷ÕßÔÚÖÎÀíÃæ°åÖ±½ÓʹÓá£


https://www.bleepingcomputer.com/news/security/new-voidproxy-phishing-service-targets-microsoft-365-google-accounts/


6. ÐÂÐÍHybridPetyaÀÕË÷Èí¼þÍ»ÆÆUEFI°²È«Æô¶¯Ö´Ðй¥»÷


9ÔÂ12ÈÕ £¬ÍøÂ簲ȫ¹«Ë¾ESET½üÈÕÔÚVirusTotalƽ̨·¢ÏÖÃûΪHybridPetyaµÄÐÂÐÍÀÕË÷Èí¼þÑù±¾ £¬¸Ã¶ñÒâÈí¼þ¿ÉÈÆ¹ýUEFI°²È«Æô¶¯Ö°ÄÜ £¬ÔÚEFIϵͳ·ÖÇø²¿Êð¶ñÒⷨʽ¡£HybridPetyaÏÔÖøÊÜ2016-2017ÄêPetya/NotPetya¶ñÒâÈí¼þÆô·¢ £¬ºóÕßÔøÔìÓñ³ÉÇò´ó¹æÄ£ÏµÍ³Ì±»¾ÇÒÎÞ¸´Ô­Ñ¡Ïî £¬¶øHybridPetyaÔòÈÚºÏÁ½ÕßÌØµã £¬¼È±£ÁôÊÓ¾õ·ç¸ñºÍ¹¥»÷Á´Ìصã £¬ÓÖÐÂÔö¹Ø¼ü¼¼ÊõÍ»ÆÆ¡£×êÑÐÏÔʾ £¬HybridPetyaÀûÓÃCVE-2024-7344·ì϶ʵÏÖ°²È«Æô¶¯Èƹý £¬¸Ã·ì϶´æÔÚÓÚ΢ÈíÊðÃûÀûÓÃÖÐ £¬¼´±ãϵͳÆôÓð²È«Æô¶¯± £»¤ÈԿɱ»ÀûÓ᣹¥»÷ʱ £¬¶ñÒâÈí¼þÊ×Ïȼì²âÖ÷»úÊÇ·ñѡȡUEFI+GPT·ÖÇø×éºÏ £¬Ëæºó½«Ô̺¬config¡¢verify¡¢counterµÈÎļþµÄÆô¶¯¹¤¾ß°üÖ²ÈëEFIϵͳ·ÖÇø¡£ÆäÖÐ £¬configÎļþ´æ´¢¼ÓÃܱêÖ¾¡¢ÃÜÔ¿¡¢Ëæ»úÊý¼°Êܺ¦ÕßID £¬verifyÎļþÓÃÓÚÃÜÔ¿ÑéÖ¤ £¬counterÔò¸ú×Ù¼ÓÃܽø¶È¡£¸ÃÈí¼þ»á´úÌæÔ­Ê¼bootmgfw.efiΪ´æÔÚ·ì϶µÄreloader.efi £¬²¢É¾³ýbootx64.efi £¬Í¬Ê±±¸·ÝԭʼÊèµ¼·¨Ê½ÒÔ±ãÊê½ðÖ§¸¶ºó¸´Ô­ÏµÍ³¡£¹¥»÷Á÷³ÌÖÐ £¬HybridPetya´¥·¢À¶ÆÁÃýÎóÇ¿Ôìϵͳ³ÁÆô £¬Ê¹¶ñÒâbootkitÔÚÆô¶¯½×¶ÎÖ´ÐС£ËæºóʹÓÃSalsa20Ëã·¨¼ÓÃÜËùÓÐMFT¼¯Èº £¬ÆÚ¼äÏÔʾÐéαCHKDSKÐÂÎÅÎóµ¼Óû§¡£¼ÓÃÜʵÏÖºóÔٴγÁÆô £¬ÏòÊܺ¦ÕßË÷Òª1000ÃÀÔª±ÈÌØ±ÒÊê½ð £¬»»È¡32×Ö·ûÃÜÔ¿ÒÔ¸´Ô­Êèµ¼·¨Ê½ºÍ½âÃÜÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/new-hybridpetya-ransomware-can-bypass-uefi-secure-boot/