µÂ¿ËÈøË¹ÖÝÌdzÇÔâÍøÂç¹¥»÷Ö·þÎñÖжÏ

°ä²¼¹¦·ò 2025-10-13

1. µÂ¿ËÈøË¹ÖÝÌdzÇÔâÍøÂç¹¥»÷Ö·þÎñÖжÏ


10ÔÂ11ÈÕ £¬µÂ¿ËÈøË¹ÖÝÌdzǹÙÔ±´«µÝ³Æ £¬¸ÃÊÐÔâ·êÍøÂç¹¥»÷µ¼Ö¶àÏîÔÚÏß·þÎñÖÐ¶Ï £¬Ô̺¬311ÁªÏµÖÐÐÄ¡¢¹«ÓÃÊÂÒµ¼Æ·Ñ¡¢Ðí¿É²é³­ÆÌÅż°Ðí¿ÉÖ¤¸¶¿îµÈÖ°ÄÜÅö±Ú¡£Ö»¹Ü¹Ø¼ü»ù´¡ÉèÊ©È羯Ա¡¢Ïû·ÀºÍÒ½ÁÆ·þÎñÈÔͨ¹ý911ά³ÖÔË×÷ £¬µ«Õ˵¥Ö§¸¶µÈ²¿ÃÅÔÚÏß·þÎñÒÑÊÜÓ°Ïì¡£Êи®ÒÑÆô¶¯Ó¦¼±»úÔì £¬Îª·Ç´¹Î£Çé¿öÌṩ±¸ÓÃÁªÏµ·½Ê½ £¬²¢½áºÏÖÝ¡¢Áª¹ú·¨Âɲ¿ÃÅ·¢Õ¹µ÷²é £¬³ÁµãÅŲéÄÚ²¿ÍøÂç»ù´¡ÉèÊ©ÊÜËðÇé¿ö¡£ÌdzÇÊÂÎñÔٴζ³ö´¦Ëùµ±¾ÖÔÚÍøÂ簲ȫ·À»¤ÖеĴàÈõÐÔ¡£Ö»¹ÜÊи®Ç¿µ÷¡°¹Ø¼üϵͳδÊÜÓ°Ï족 £¬µ«·þÎñÖжÏÒѶԾÓÃñÈÕ³£ÊÂÎñ´¦ÖÃÔì³ÉÄÚÈÝÐÔ¹ÊÕÏ¡£Õâ´ÎÊÂÎñ²¢·Ç¹ÂÀý¡£¾Ýͳ¼Æ £¬2025ÄêÒÔÀ´ £¬µÂ¿ËÈøË¹ÖÝ¶àµØÆµ·¢ÍøÂ簲ȫÊÂÎñ£ºÈýÖÜǰ £¬ÓÈÍß¶ûµÏÊй«Á¢Ñ§ÇøÒòÀÕË÷Èí¼þ¹¥»÷±»ÆÈÍ£¿ÎÒ»ÖÜ £¬¡°÷è÷롱ÍÅ»ïÒÑÐû³Æ¶Ô´ËÕÆ¹Ü £»ÂíËþ¸ç´ïÏØ¡¢Ã×Éê¡¢À­²®¿Ë¼°°¢±ÈÁֵȳÇÊÐÒà»ã±¨ÀàËÆÊÂÎñ¡£½ñÄê6Ô £¬Öݽ»Í¨²¿ÕË»§ÔâºÚ¿ÍÈëÇÖ £¬½ü30Íò·ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢¼ÝÕÕºÅÂë¡¢³µÅƼ°±£ÏÕÐÅÏ¢µÄ½»Í¨±äÂһ㱨±»·¸·¨ÏÂÔØ £¬Òý·¢¹«¼Ò¶ÔÓ×ÎÒÐÅÏ¢°²È«µÄÓÇÓô¡£


https://therecord.media/houston-suburb-cyberattack-services


2. ºÚ¿ÍÀûÓÃGladinetÎļþ¹²ÏíÈí¼þµÄÁãÈÕ·ì϶


10ÔÂ10ÈÕ £¬½üÈÕ £¬Gladinet¹«Ë¾µÄCentreStackºÍTriofoxÎļþ¹²Ïí¼°Ô¶³Ì½Ó¼û½â¾ö¹æ»®±»ÆØ´æÔÚÑϳÁÁãÈÕ·ì϶CVE-2025-11371 £¬¸Ã·ì϶Ϊ±¾µØÎļþÔ̺¬£¨LFI£©·ì϶ £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½Ó¼ûϵͳÎļþ¡£Ä¿Ç°ÖÁÉÙÓÐÈý¼ÒÆóÒµÒò¶øÔâ·ê¹¥»÷ £¬ÇÒËùÓа汾²úÆ·¾ùÊÜÓ°Ïì £¬Ô̺¬×îа汾16.7.10368.56560¡£·ì϶ÀûÓÃÁ´ÏÔʾ £¬¹¥»÷ÕßÊ×ÏÈͨ¹ýLFI¶ÁÈ¡Web.configÎļþÌáÈ¡»úеÃÜÔ¿ £¬Ëæºó½áºÏ´ËǰÒÑÖªµÄ·´ÐòÁл¯·ì϶CVE-2025-30406£¨Ô´ÓÚÓ²±àÂë»úеÃÜÔ¿£© £¬×îÖÕͨ¹ýViewStateʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£Huntress×êÑÐÈËÔ±ÓÚ9ÔÂ27ÈÕ³õ´Î·¢Ïָ÷ì϶ £¬²¢È·ÈÏÍþвÐÐΪÕßÒѳɹ¦ÀûÓô˷ì϶»ñÈ¡»úеÃÜÔ¿²¢Ö´ÐжñÒâ´úÂë¡£Gladinet¹«Ë¾ÒÑÈ·ÈÏ·ì϶´æÔÚ £¬²¢°µÊ¾ÔÚ֪ͨ¿Í»§²Éȡһʱ»º½â´ëÊ© £¬Ö±ÖÁ²¹¶¡°ä²¼¡£CentreStack²úÆ·Ðû³ÆÒѱ»49¸ö¹ú¶ÈµÄÊýǧ¼ÒÆóҵʹÓà £¬¶øÕâ´ÎÊÂÎñÔٴζ³öÁËÆóÒµ¼¶´æ´¢½â¾ö¹æ»®µÄ°²È«·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/hackers-exploiting-zero-day-in-gladinet-file-sharing-software/


3. Service FinderÖ÷Ìâ¸ßΣ·ì϶Ôâ´ó¹æÄ£ÀûÓÃ


10ÔÂ10ÈÕ £¬Service Finder WordPressÖ÷Ìâ¼°Æä°ó¸¿µÄBookings²å¼þ´æÔÚÑϳÁ°²È«·ì϶CVE-2025-5947 £¬¸Ã·ì϶±»ÆÀ·ÖΪ9.8·Ö £¬ÊôÓÚ¸ßΣÉí·ÝÈÏÖ¤ÈÆ¹ý·ì϶¡£¹¥»÷Õß¿ÉÎÞÐèÃÜÂëÖ±½Óͨ¹ýαÔìCookie¼ÙÒâÖÎÀíÔ±µÇ¼ £¬½ø¶øÆëÈ«½ÚÔìÍøÕ¾ £¬×¢Èë¶ñÒâ´úÂë¡¢½Ù³ÖÁ÷Á¿»ò²¿Êð¶ñÒâÈí¼þ¡£·ì϶ԴÓÚ²å¼þ¶ÔÕË»§Çл»Ö°ÄܵÄÃýÎó´¦Öà £¬Î´ÑéÖ¤CookieÊý¾ÝµÄÕæÊµÐÔ £¬µ¼ÖÂËÁÒâÓû§£¨Ô̺¬ÎÞÕË»§Õߣ©¿É¼ÙÒâÖÎÀíÔ±Éí·Ý¡£¸Ã·ì϶ӰÏìËùÓÐ6.0¼°ÒÔϰ汾 £¬Ö÷ÌâÊØ»¤·½ÓÚ2025Äê7ÔÂ17ÈÕ°ä²¼6.1°æ±¾½¨¸´²¹¶¡ £¬µ«¹¥»÷Õß×Ô8ÔÂ1ÈÕÆðÒÑÌáÒ鳬13,800´ÎÀûÓó¢ÊÔ¡£Ä¿Ç° £¬³¬6000Ãû²É°ì¸ÃÖ÷ÌâµÄ¿Í»§ÖÐÈÔÓдóÁ¿ÍøÕ¾Î´¸üР£¬Ãæ¶Ô³ÖÐø·çÏÕ¡£°²È«¹«Ë¾Wordfenceͨ¹ý·ì϶Éͽð´òËãЭÖúÅû¶Á˸÷ì϶ £¬Æä·À»ðǽ¿ÉÀ¹½Ø²¿ÃŹ¥»÷£¨¼ø±ð¶ñÒâCookieÊý¾Ý£© £¬µ«¹Ù·½Ç¿µ÷¸üÐÂÖÁ6.1»ò¸ü¸ß°æ±¾²ÅÊǵ××Ó·ÀÓù´ëÊ©¡£


https://hackread.com/auth-bypass-service-finder-wordpress-plugin-exploit/


4. Stealit¶ñÒâÈí¼þ½èNode.js SEAÖ°ÄÜÒñ±Î´«²¼


10ÔÂ10ÈÕ £¬Fortinet FortiGuard³¢ÊÔÊÒ½üÈÕÖÒ¸æ £¬Ò»ÖÖÃûΪStealitµÄΣÏÕÊý¾ÝÇÔÈ¡¶ñÒâÈí¼þÕýͨ¹ýMaaS£¨¶ñÒâÈí¼þ¼´·þÎñ£©Ä£Ê½»îÔ¾´«²¼¡£¸Ã¶ñÒâÈí¼þÕë¶ÔWindowsÓû§ £¬Ñ¡È¡ÖеÈÑϳÁˮƽ¹¥»÷ £¬Í¨¹ýNode.jsµÄ"µ¥¿ÉÖ´ÐÐÀûÓ÷¨Ê½£¨SEA£©"Ö°Äܽ«ËùÓжñÒâÎļþ´ò°ü³Éµ¥Ò»·¨Ê½ £¬ÎÞÐèԤװNode.js¼´¿ÉÔËÐÐ £¬ÏÔÖøÌáÉýÒñ±ÎÐÔ¡£Æä´úÂë¾­¹ý³Á¶È»ìºÏ²¢Ç¶Èë·´·ÖÎö²é³­ £¬¿É×Ô¶¯¶ã±Üµ÷ÊÔÆ÷¡¢Ðé¹¹»·¾³µÈ°²È«¼ì²â¡£StealitµÄÖ÷ÌâÖ°ÄÜÔ̺¬Ô¶³ÌÎļþÌáÈ¡¡¢ÀÕË÷Èí¼þ²¿Êð¡¢ÊµÊ±ÆÁÄ»¼à¿Ø¡¢ÍøÂçÉãÏñÍ·½ÚÔ켰ϵͳÖÎÀí £¬²¢¿ÉÍÆËÍÐéα¾¯±¨ÐÅÏ¢¡£¹¥»÷Õß½«Æä°üװΪ"רҵÊý¾ÝÌáÈ¡½â¾ö¹æ»®" £¬Í¨¹ý¶©ÔÄ´òËãÊÛÂô £¬Windows°æ¶¨¼ÛÔ¼500ÃÀÔª £¬Android°æ¸ß´ï2000ÃÀÔª¡£ÎªÌÓ±Ü×·×Ù £¬ÆäC2·þÎñÆ÷ÒÑ´Óstealituptaded.lolǨáãÖÁiloveanimals.shop¡£´«²¼Õ½Êõ·½Ãæ £¬¶ñÒâÈí¼þ¼Ù×°³ÉÈȵãÓÎÏ·ºÍVPN×°Ö÷¨Ê½ £¬Í¨¹ýMediafire¡¢DiscordµÈƽ̨·Ö·¢¡£ÓÎÏ·Íæ¼ÒÒòƵÈÔ×°ÖõÚÈý·½Èí¼þ³ÉÎªÖØÒªÖ¸±êȺÌå¡£


https://hackread.com/stealit-malware-node-js-fake-game-vpn-installers/


5. ŦԼÖݾ¯Ãñ½áºÏ½ø¹¥¡°Í¨ÕÍÍË˰¡±´¹µöÚ¿Æ­


10ÔÂ12ÈÕ £¬½üÆÚ £¬Å¦Ô¼ÖݲúÉúһ·ÒÔ¡°Í¨»õÅòÕÍÍ˿Ϊ»Ï×ӵĶÌÐÅÍøÂç´¹µöÚ¿Æ­ £¬Ö¸±êֱָŦԼ¾ÓÃñ¡£Ú¿Æ­·Ö×Ó¼ÙÒâŦԼ˰ÎñºÍ²ÆÕþ²¿ £¬Í¨¹ý¶ÌÐÅ¡¢Óʼþ¼°Ö±ÓÊ·½Ê½ £¬»Ñ³ÆÌṩ¡°Í¨ÕÍÍ˿²¢ÓÕµ¼Êܺ¦Õßµã»÷Á´½ÓÊäÈëÓ×ÎÒÐÅÏ¢¡£¸ÃÚ¿Æ­ÀûÓÃÁËŦԼÖÝÕæÊµ´æÔÚµÄͨÕÍÍË˰Õþ²ß £¬ÇкÏǰÌáµÄÄÉ˰ÈËÎÞÐèÉêÇë¼´¿É×Ô¶¯ÊÕµ½ÍË˰֧Ʊ £¬Õþ²ßº­¸ÇÒÑÌá½»ÄÉ˰É걨¡¢´ïµ½ÊÕÈëÃż÷ÇÒδ±»É걨ΪÊÜ·öÑøÈ˵ľÓÃñ¡£Ú¿Æ­¶ÌÐÅÐû³Æ¡°ÍË¿îÒªÇóÒÑ´¦Öò¢ºË×¼¡± £¬ÒªÇóÊÕ¼þÈËÔÚ2025Äê9ÔÂ29ÈÕǰÌá½»¸¶¿îÐÅÏ¢ £¬²»È»½«ÓÀԶʧÂäÍË¿î×ʸñ £¬²¢Ô®Òý¡¶Å¦Ô¼¶©ÕýÂÉÀý¡·µÚ5747.11Ìõʩѹ¡£µã»÷Á´½Óºó £¬Êܺ¦Õ߻ᱻÊèµ¼ÖÁαÔìµÄ¹Ù·½Ò³Ãæ £¬±»ÒªÇóÊäÈëÐÕÃû¡¢µØÖ·¡¢µç»°¡¢Éç»á°²È«ºÅÂëµÈÃô¸ÐÐÅÏ¢ £¬ÕâЩÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇԺͽðÈÚÚ¿Æ­¡£Å¦Ô¼Öݵ±¾ÖѸ¿ì²ÉÈ¡Ðж¯¡£9ÔÂ28ÈÕ £¬Öݳ¤¿­Î÷¡¤»ô³þ¶û°ì¹«ÊÒ°ä²¼ÖÒ¸æ £¬Ç¿µ÷¡°³ý×ʸñÒªÇó±í £¬Å¦Ô¼ÈËÎÞÐè×öÈκÎʼ´¿É»ñµÃÍË˰֧Ʊ¡± £¬²¢Ã÷È·¡°Ë°Îñ²¿ÃŲ»»áͨ¹ýµç»°¡¢¶ÌÐÅ»òÓʼþË÷ÒªÓ×ÎÒÐÅÏ¢¡±¡£Å¦Ô¼Ë°ÎñºÍ²ÆÕþ²¿Í¬²½ÌáÐÑ £¬»ú¹¹¾ø²»»áͨ¹ýµç×ÓͨѶÁªÏµÄÉ˰ÈË´¦ÖÃÍË˰ÊÂÒË¡£


https://www.bleepingcomputer.com/news/security/fake-inflation-refund-texts-target-new-yorkers-in-new-scam/


6. Î÷°àÑÀµ·»Ù¿ç¹úÍøÂç·¸×ïÆ½Ì¨GXC Team


10ÔÂ11ÈÕ £¬Î÷°àÑÀ¹úÃñ¾¯ÎÀ¶Ó½üÆÚ³É¹¦·ÛËéÃûΪ¡°GXC Team¡±µÄ¿ç¹úÍøÂç·¸×ï×éÖ¯ £¬¿ÛÁôÆä25Ëê°ÍÎ÷¼®Í·×Ó¡°GoogleXcoder¡±¼°¶àÃûͬ»ï¡£¸Ã×éÖ¯ÔËÓª¡°·¸×ï¼´·þÎñ¡±£¨CaaS£©Æ½Ì¨ £¬Í¨¹ýTelegramºÍ¶íÓïºÚ¿ÍÂÛ̳ÏòÈ«Çò¿Í»§Ìṩ¶¨Ôì»¯ÍøÂç¹¥»÷¹¤¾ß £¬Ô̺¬ÈËΪÖÇÄÜ´¹µö¹¤¾ß°ü¡¢Android¶ñÒâÈí¼þ¼°ÓïÒôÚ¿Æ­¹¤¾ß £¬ÐγÉרҵ¼¶¸ßÊÕÒæ·¸×ïÉú̬¡£¾Ýµ÷²é £¬GXC TeamÖØÒªÕë¶ÔÎ÷°àÑÀ¡¢Ë¹Âå·¥¿Ë¡¢Ó¢¹ú¡¢ÃÀ¹úºÍ°ÍÎ÷µÄÒøÐÓ×¢ÔËÊä¼°µç×ÓÉÌÇóʵÌåÖ´Ðй¥»÷¡£Æä´¹µö¹¤¾ß°ü¾«×¼¸´ÔìÊýÊ®¼Ò¹ú¼Ê»ú¹¹ÍøÕ¾ £¬Ö§³ÖÖÁÉÙ250¸ö´¹µöÍøÕ¾ÔËÐÐ £»¿ª·¢µÄ9ÖÖAndroid¶ñÒâÈí¼þ¿ÉÀ¹½Ø¶ÌÐźÍÒ»´ÎÐÔÃÜÂ루OTP£© £¬ÓÃÓÚ½Ù³ÖÕË»§¼°Ñé֤ڲƭÂòÂô¡£¸Ã×éÖ¯»¹Ìṩ¼¼ÊõÖ§³ÖºÍ»î¶¯¶¨Ôì·þÎñ £¬ÐÎ³ÉÆëÈ«·¸×ï²úÒµÁ´¡£5ÔÂ20ÈÕ £¬Î÷°àÑÀ¾¯·½ÔÚ¿²Ëþ²¼ÀïÑÇ¡¢°ÍÈûÂÞÄÇµÈ¶àµØ·¢Õ¹Ð­µ÷Í»»÷ËѲé £¬²é»ñÔ̺¬´¹µö¹¤¾ß°üÔ´´úÂë¡¢¿Í»§Í¨Ñ¶¼Í¼¼°²ÆÕþÊý¾ÝµÄµç×ÓÉ豸 £¬×·»Ø±»µÁ¼ÓÃÜÇ®±Ò £¬²¢¹Ø¹ØÃûΪ¡°´Ó׿ďÄÇÀï͵×ßËùÓÓ×±µÄÚ¿Æ­ÍÆ¹ãTelegramƵ·¡£Õâ´ÎÐж¯»ùÓÚ¶Ô¡°GoogleXcoder¡±É豸¼°¼ÓÃÜÇ®±ÒÂòÂôµÄ³ÖÐøÒ»Äê¶àµÄȡ֤·ÖÎö £¬³É¹¦³Á½¨·¸×ïÍøÂç²¢Ëø¶¨6Ãû¹ØÁªÈËÔ±¡£


https://www.bleepingcomputer.com/news/security/spain-dismantles-gxc-team-cybercrime-syndicate-arrests-leader/