FBIÖҸ淸·¨·Ö×ÓÔÚºýŪIC3ÍøÂç·¸×ï¾Ù±¨ÍøÕ¾
°ä²¼¹¦·ò 2025-09-231. FBIÖҸ淸·¨·Ö×ÓÔÚºýŪIC3ÍøÂç·¸×ï¾Ù±¨ÍøÕ¾
9ÔÂ19ÈÕ£¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©½üÈÕ°ä²¼´¹Î£ÖҸ棬ָ³öÍøÂç·¸×ï·Ö×ÓÕý´óÁ¿´´½¨»¥ÁªÍø·¸×ïͶËßÖÐÐÄ£¨IC3£©¹Ù·½ÍøÕ¾µÄÐéα°æ±¾£¬ÒÔÇÔÈ¡¹«¼ÒÓ×ÎÒÐÅÏ¢²¢Ö´Ðжþ´Î¹¥»÷¡£IC3×÷ΪFBIÔËÓªµÄ¹Ù·½Æ½Ì¨£¬Õƹܴ¦ÖÃÉí·Ý͵ÇÔ¡¢ÍøÂç´¹µö¡¢ÅÄÂôڲƵÈÍøÂç·¸×ïͶËß¡£¾ÝFBIÅû¶£¬2023Äê12ÔÂÖÁ2025Äê2ÔÂÆÚ¼ä£¬ÒÑÊÕµ½³¬100ÆðIC3¼ÙÒâڿƻ㱨¡£Ú¿ÆÕßͨ¹ýÉ罻ýÌå×Ô¶¯½Ó´¥Êܺ¦Õߣ¬»Ñ³ÆÐÖú×·»ØËðʧ×ʽð£¬ÓÕµ¼Æä½Ó¼ûαÔìÍøÕ¾¡£ÕâЩÐéÎ±ÍøÕ¾Í¨¹ýƴдÃýÎóURL£¨Èç¡°ic3.org¡±¡°ic3.com¡±£©¡¢´úÌæ¶¥¼¶ÓòÃû¡¢µÍÖÊÁ¿Í¼Ðλò²»×¨ÒµÅŰæºýŪÓû§£¬ÇÔÈ¡ÐÕÃû¡¢×¡Ö·¡¢µç»°¡¢ÒøÐÐÐÅÏ¢µÈÃô¸ÐÊý¾Ý£¬µ¼ÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚڿƼ°Éç»á¹¤³Ì¹¥»÷·çÏÕ¼¤Ôö¡£Îª·À±¸´ËÀàÚ¿Æ£¬FBI½¨Ò鹫¼ÒÖ±½Óͨ¹ýä¯ÀÀÆ÷ÊäÈë¡°http://www.ic3.gov¡±½Ó¼û¹Ù·½ÍøÕ¾£¬Ô¤·ÀʹÓÃËÑË÷ÒýÇæ£¬ÓÈÆä¾¯Ìè¡°ÔÞÖú¡±Á˾֣¬Ú¿ÆÕß³£ÀûÓø¶·Ñ¸æ°×½Ù³ÖºÏ·¨ÍøÕ¾Á÷Á¿¡£Í¬Ê±£¬½öÔÚÏÔÊ¾ËøÐÎͼ±ê»òHTTPSµÄ.govÍøÕ¾ÉϹ²ÏíÃô¸ÐÐÅÏ¢¡£IC3Ç¿µ÷£¬Æä¹Ù·½Çþ·²»»áͨ¹ýµç»°¡¢Óʼþ¡¢É罻ýÌå»ò¹«¹²ÂÛֱ̳½ÓÁªÏµÓ×ÎÒ£¬Ò²²»»áÒªÇóÖ§¸¶ÓöÈÒÔ×·»ØËðʧ×ʽð¡£
https://cybernews.com/security/fbi-warns-bad-actors-spoofing-ic3-internet-crime-reporting-website/
2. Ò°ÊÞÏÈÉúÒòÎ¥¹æÍøÂç¶ùͯÐÅÏ¢ÔâÕû¸Ä
9ÔÂ20ÈÕ£¬ÃÀ¹ú³ÛÃûYouTube²©Ö÷¡°Ò°ÊÞÏÈÉú¡±£¨MrBeast£¬±¾Ãû¼ªÃס¤ÌÆÄÉÉ£©Òòδ»ñ¼Ò³¤ÔÞ³ÉÍøÂç13ËêÒÔ϶ùͯÓ×ÎÒÐÅÏ¢£¬±»ÃÀ¹úóÒ׸Ľø¾ÖÈ«¹úÏîÄ¿£¨BBB National Programs£©ÆìϵĶùͯ¸æ°×Éó²é×飨CARU£©È϶¨Î¥·´¡¶¶ùͯÔÚÏßÒþÖÔ±£»¤¹æ¶¨¡·£¨COPPA£©£¬²¢´¥·¢ÆäƵ·¼°¹ØÁªÆ·ÅÆ¡°Feastables¡±µÄÊý¾ÝÍøÂçÓë¸æ°×Ͷ·ÅÁ÷³ÌÕû¸Ä¡£CARUÖ¸³ö£¬ÌÆÄÉÉÔÚÁ½´Î³é½±»î¶¯ÖÐÒªÇóÓû§ÌṩȫÃû¡¢µç»°¡¢µØÖ·¼°ÓÊÏäµÈÃô¸ÐÐÅÏ¢£¬µ«Î´ÉèÖüҳ¤Ô޳ɻúÔ죬µ¼Ö¶ùͯÐÅÏ¢±»Ö±½Ó¹Ü¼¯¡£ÀýÈ磬Æäͨ¹ý¡°Feastables¡±ÇÉ¿ËÁ¦°ô¶þάÂëÆ¾Ö¤ÌáÒéµÄ³é½±»î¶¯£¬³ÐŵƵÈÔÌá½»Õ߿ɻñ1ÍòÃÀÔª½±½ð£¬È´Î´ÌṩÈκμҳ¤ÑéÖ¤Çþ·¡£´Ë±í£¬¡°Feastables¡±¹ÙÍø´æÔÚÂ½Ðøµ¯´°ÓÕµ¼Óû§ÌîдÓÊÏä¼°µç»°ºÅÂëµÄÐÐΪ£¬ÇÒÓйØÊý¾Ý±»´«ÊäÖÁµÚÈý·½£¬½øÒ»²½¼Ó¾çÁËÒþÖÔй¶·çÏÕ¡£Æ¾¾ÝCOPPA»®¶¨£¬ÃæÏò13ËêÒÔ϶ùͯµÄÔÚÏß·þÎñ±ØÐëͨ¹ý¿ÉÑéÖ¤µÄ¼Ò³¤Ô޳ɻúÔì·½¿ÉÍøÂçÓ×ÎÒÐÅÏ¢¡£CARUÇ¿µ÷£¬ÌÆÄÉɵÄ4.36ÒÚ¶©ÔÄÕßÖÐÔ̺¬´óÁ¿¶ùͯÓû§£¬ÆäÎ¥¹æÐÐΪÒÑ×é³ÉϵͳÐÔÒþÖÔ±£»¤È±Ê§¡£
https://therecord.media/watchdog-mrbeast-youtube-privacy-colection
3. StellantisÔâµÚÈý·½Æ½Ì¨ÈëÇÖÖÂ1800ÍòÌõ¿Í»§Êý¾Ýй¶
9ÔÂ22ÈÕ£¬Æû³µÔì×÷¾ÞÍ·StellantisÓÚ½üÈÕ֤ʵ£¬¹¥»÷Õßͨ¹ýÈëÇÔìä±±ÃÀ¿Í»§·þÎñÔËÓªµÄµÚÈý·½·þÎñÌṩÉÌÆ½Ì¨£¬ÇÔÈ¡Á˲¿Ãű±ÃÀ¿Í»§Êý¾Ý¡£StellantisÓɱêÖÂÑ©ÌúÁú¼¯ÍÅÓë·ÆÑÇÌØ¿ËÀ³Ë¹ÀÕÆû³µ¹«Ë¾ÓÚ2021Äê¹é²¢³ÉÁ¢£¬ÏÖΪȫÇòÓªÊÕ×î¸ßµÄÆû³µ¹«Ë¾Ö®Ò»¼°ÏúÁ¿µÚÎå´óÔì×÷ÉÌ£¬ÆìÏÂÕ¼Óа¢¶û·¨¡¤ÂÞÃÜÅ·¡¢¿ËÀ³Ë¹ÀÕ¡¢Ñ©ÌúÁúµÈ14¸öÆ·ÅÆ£¬ÒµÎñ¸²¸Ç130¶à¸ö¹ú¶È¡£¾Ý¹«Ë¾ÉêÃ÷£¬Õâ´Îй¶½öÉæ¼°¿Í»§ÁªÏµÐÅÏ¢£¬Òò±»ÈëÇÔì½Ì¨Î´´æ´¢²ÆÕþ»òÃô¸ÐÓ×ÎÒÐÅÏ¢¡£ÊÂÎñ²úÉúºó£¬Stellantisµ±¼´Æô¶¯ÊÂÎñÏìÓ¦»úÔ죬·¢Õ¹È«Ãæµ÷²é²¢½ÚÔìÊÂ̬£¬Í¬Ê±Í¨ÖªÓйز¿ÃŲ¢ÏòÊÜÓ°Ïì¿Í»§·¢³ö¾¯Ê¾£¬ÌáÐѾ¯ÌèÍøÂç´¹µö¹¥»÷£¬Îðµã»÷¿ÉÒÉÁ´½Ó»ò·ÖÏíÓ×ÎÒÐÅÏ¢¡£¾Ý³ÆÕâ´Î¹¥»÷ÓëShinyHuntersÀÕË÷¼¯ÍŽüÆÚÌáÒéµÄSalesforceÊý¾Ýй¶ÊÂÎñÓйء£
https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/
4. ÃÀ¹ú¹«¹²¹ã²¥µµ°¸¹ÝIDOR·ì϶Öº¹ÇàÄÚÈÝй¶
9ÔÂ22ÈÕ£¬ÃÀ¹ú¹«¹²¹ã²¥µµ°¸¹Ý£¨AAPB£©±¾ÔÂÇÄÈ»½¨¸´ÁËÒ»¸ö´æÔÚ¶àÄêµÄ°²È«·ì϶£¬¸Ã·ì϶ÔÊÐíÓû§Í¨¹ýTampermonkey¾ç±¾ÀûÓò»°²È«Ö±½Ó¶ÔÏóÒýÓã¨IDOR£©È±µã£¬Èƹý½Ó¼û½ÚÔìÏÂÔØÊܱ£»¤µÄ¸öÈËýÌåÄÚÈÝ¡£ÄäÃûÍøÂ簲ȫ×êÑÐÈËÔ±Åû¶£¬¸Ã·ì϶ÖÁÉÙ×Ô2021ÄêÆðÒѱ»ÀûÓã¬Ö»¹ÜÆäÔøÏòAAPB»ã±¨µ«Î´»ñʵʱ´¦Ö᣽¨¸´ºó£¬AAPBͨѶ¾ÀíEmily BalkÇ¿µ÷½«¼ÓÇ¿µµ°¸¹Ý°²È«ÐÔ£¬Í¬Ê±¶ÔÖÅ¡°Ãâ·Ñ»ñÈ¡¹«¹²Ã½Ì庹ÇࡱµÄʹÃü¡£AAPBÓÉWGBH½ÌÓý»ù½ð»áºÍ¹ú»áͼÊé¹Ý½áºÏÔËÓª£¬×÷Ϊ·ÇͶ»ú»ú¹¹£¬ÆäʹÃüÊÇÍøÂç¡¢Êý×Ö»¯²¢±£ÁôÃÀ¹ú¹«¹²¹ã²¥ºÍµçÊÓÔì×÷µÄº¹ÇàÄÚÈÝ¡£·ì϶´«²¼õ辶ʼÓÚLost Media Wiki DiscordƵ·¶Ô¡¶Ö¥Âé½Ö¡·¡°Î÷·½Ð°¶ñÅ®Îס±¾ç¼¯Ð¹Â¶µÄ»áÉÌ£¬ºóÀ©É¢ÖÁDiscord±£ÁôÓ××飬µ¼ÖÂÊܱ£»¤ÄÚÈÝÔÚÊý¾Ý¶Ú»ýÕßÉçȺÖнøÒ»²½´«²¼¡£ÕâЩÉçȺÒÔ´æµµÈí¼þ¡¢Ã½ÌåµÈ´ó¾ÖΪÖ÷Ì⣬³£ÓÎ×ßÓÚ°æÈ¨»ÒÉ«µØ´ø£¬ÍÌÍÂÁ˺Ϸ¨±£ÁôÓëÊý×ÖµÁ°æµÄ½çÏÞ¡£Ö»¹Ü·ì϶Òѽ¨¸´£¬µ«Êý¾Ý¶Ú»ýÉçÇøÄÚ¹²ÏíµÄÄÚÈÝÁ¿ÈÔ²»Ã÷È·¡£
https://www.bleepingcomputer.com/news/security/american-archive-of-public-broadcasting-fixes-bug-exposing-restricted-media/
5. ComicFormºÚ¿Í×éÖ¯Õë¶Ô¶«Å·¶à¹ú·¢ÆðÍøÂç´¹µö¹¥»÷
9ÔÂ22ÈÕ£¬ComicFormºÚ¿Í×éÖ¯4ÔÂÒÔÀ´Õë¶Ô°×¶íÂÞ˹¡¢¹þÈø¿Ë˹̹¼°¶íÂÞ˹µÄ¹¤Òµ¡¢½ðÈÚ¡¢ÓÎÀÀ¡¢ÉúÎï¼¼Êõ¡¢×êÑкÍÒµÎñÁìÓòÌáÒéÍøÂç´¹µö¹¥»÷¡£¾ÝÍøÂ簲ȫ¹«Ë¾F6·ÖÎö£¬¹¥»÷Á´ÒÔ¡°ÆÚ´ýÊðÃûÎļþ¡±¡°¸¶¿î·¢Æ±¡±µÈÖ÷ÌâÓʼþΪµö¶ü£¬ÓÕµ¼ÊÕ¼þÈË´ò¿ªÔ̺¬¶ñÒâ¿ÉÖ´ÐÐÎļþµÄRR´æµµ¡£ÕâЩÓʼþʹÓöíÓï»òÓ¢ÓïÊéд£¬Ô´×Ô.ru¡¢.by¡¢.kzÓòÃû£¬×îÖÕͨ¹ý»ìºÏµÄ.NET¼ÓÔØ·¨Ê½Æô¶¯¡°MechMatrix Pro.dll¡±£¬²¢²¿ÊðFormbook¶ñÒâÈí¼þͶ·ÅÆ÷¡°Montero.dll¡±£¬Í¬Ê±´´½¨´òË㹤×÷¡¢ÅäÖÃMicrosoft DefenderÅųýÏîÒÔÌӱܼì²â¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¶ñÒâ¶þ½øÔìÎļþÔ̺¬Ö¸ÏòòùòðÏÀµÈÂþ»GIFµÄTumblrÁ´½Ó£¬Òò¶ø¸Ã×éÖ¯µÃÃû¡°ComicForm¡±¡£F6×êÑÐÔ±Ö¸³ö£¬ÕâЩGIF½öΪ´úÂë¼Ù×°£¬Î´²Î¼ÓÏÖʵ¹¥»÷¡£Õâ´Î¹¥»÷ÓëÇ×¶í×éÖ¯SectorJ149Õë¶Ôº«¹úµÄ¹¥»÷´æÔÚ¹ØÁª¡£¸Ã×éÖ¯2024Äê11ÔÂÆðÒÔº«¹úÔì×÷Òµ¡¢ÄÜÔ´¡¢°ëµ¼ÌåÐÐҵΪָ±ê£¬Í¨¹ýÓã²æÊ½´¹µöÓʼþ·Ö·¢Lumma Stealer¡¢Remcos RATµÈ¶ñÒâÈí¼þ£¬Æä¹¥»÷´Ó¾¼ÃÀûÒæ×ªÏòÕþÖÎÖ÷ÕÅ¡£
https://thehackernews.com/2025/09/comicform-and-sectorj149-hackers-deploy.html
6. LastPass¾¯Ê¾macOSÓû§·À±¸¼Ù×°Ê¢ÐÐÈí¼þµÄ¶ñÒâÈí¼þ¹¥»÷
9ÔÂ22ÈÕ£¬LastPass½üÈÕ°ä²¼ÖҸ棬ָ³öÕë¶ÔmacOSÓû§µÄÍøÂç¹¥»÷»î¶¯Õýͨ¹ý¼Ù×°³ÉÊ¢ÐÐÈí¼þµÄ¶ñÒâÈí¼þ½øÐд«²¼¡£¹¥»÷ÕßÀûÓÃÚ²ÆÐÔGitHub´æ´¢¿â£¬½áºÏËÑË÷ÒýÇæÓÅ»¯£¨SEO£©Õ½Êõ£¬ÔÚGoogleºÍBingÉÏÍÆ¹ãÕâЩÐéαÀûÓá£ÕâЩÀûÓÃÔÚ"ClickFix"¹¥»÷ÖÐͶ·ÅAtomic£¨AMOS£©ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þ×÷Ϊ·þÎñÿÔÂÊÕ·Ñ1000ÃÀÔª£¬½üÆÚÐÂÔöºóÃÅ×é¼þ£¬ÔÊÐí¹¥»÷Õß³ÖÐø¡¢Òñ±ÎµØ½Ó¼ûÊÜϰȾϵͳ¡£¹¥»÷Õß·ÂÕÕÁ˳¬¹ý100ÖÖÈí¼þ½â¾ö¹æ»®£¬Ô̺¬1Password¡¢Dropbox¡¢Confluence¡¢RobinhoodµÈ³ÛÃû²úÆ·£¬Í¨¹ý¶à¸öÕË»§´´½¨´óÁ¿ºýŪÐÔGitHub´æ´¢¿â£¬ÓÅ»¯ËÑË÷ÅÅÃûÒÔÌÓ±Üɾ³ý¡£Óû§µã»÷´æ´¢¿âÖеÄ"ÏÂÔØ°´Å¥"»á±»Êèµ¼ÖÁ¸¨ÖúÕ¾µã£¬ÌáÐÑÕ³ÌùºÅÁîµ½ÖÕ¶ËÖ´ÐÐ×°Ö᣸úÅÁîͨ¹ýcurlÒªÇóbase64±àÂëµÄURL£¬½«AMOSÓÐЧ¸ºÔØ£¨install.sh£©ÏÂÔØÖÁ/tmpĿ¼¡£´ËÀ๥»÷ÀûÓÃÓû§¶ÔºÅÁîµÄ²»ÏàʶִÐй¥»÷£¬ÊôÓÚµäÐ͵Ä"ClickFix"¹¥»÷ģʽ¡£Ö»¹ÜLastPass³ÖÐø¼à¿Ø²¢»ã±¨Ðéα´æ´¢¿â£¬µ«ÐÂÕË»§×Ô¶¯»¯´´½¨µ¼ÖÂÎÊÌâ³ÖÐø´æÔÚ¡£
https://www.bleepingcomputer.com/news/security/lastpass-fake-password-managers-infect-mac-users-with-malware/


¾©¹«Íø°²±¸11010802024551ºÅ