ÀÕË÷Èí¼þÍÅ»ïÈôºÎ¼ÓÃÜÄÚ»ª´ïÖݵ±¾Öϵͳ

°ä²¼¹¦·ò 2025-11-10

1. ÀÕË÷Èí¼þÍÅ»ïÈôºÎ¼ÓÃÜÄÚ»ª´ïÖݵ±¾Öϵͳ


11ÔÂ6ÈÕ £¬ÄÚ»ª´ïÖÝ8ÔÂÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬Ó°Ïì60Óà¸öµ±¾Ö»ú¹¹ £¬µ¼ÖÂÍøÕ¾¡¢µç»°ÏµÍ³¼°ÔÚÏ߯½Ì¨ÖÐ¶Ï ¡£Öݵ±¾Ö°ä²¼µÄ¾ßÌå¹ýºó»ã±¨ÆëÈ«Åû¶Á˹¥»÷ȫò£ººÚ¿Í×Ô5ÔÂ14ÈÕÆðͨ¹ý¶ñÒâ¸æ°×ÓÕµ¼Öݵ±¾Ö¹ÍÔ±ÏÂÔØ¼Ù×°³ÉϵͳÖÎÀí¹¤¾ß£¨ÈçWinSCP¡¢PuTTYµÈ£©µÄľÂí·¨Ê½ £¬ÔÚÉ豸²¿ÊðºóÃÅ£»8ÔÂ24ÈÕÕýʽ²¿ÊðÀÕË÷Èí¼þǰ £¬ÒÑͨ¹ýÔ¶³Ì¼à¿ØÈí¼þ¡¢¼ÓÃÜËí·¹¤¾ßºáÏòÉøÈë £¬ÇÔÈ¡26¸öÕË»§Í´´¦²¢¶Ï¸ùÊÂÎñÈÕÖ¾ÒÔ¸²¸ÇÐÐ×Ù ¡£¹¥»÷Õß×îÖÕɾ³ý±¸·Ý¾í¡¢Åú¸ÄÐé¹¹»¯ÖÎÀí·þÎñÆ÷°²È«ÉèÖà £¬ÔÚÍйÜÖÝÐé¹¹»úµÄËùÓзþÎñÆ÷Éϲ¿ÊðÀÕË÷Èí¼þ £¬µ¼ÖÂÈ«ÖÝ·þÎṉ̃»¾ ¡£Ãæ¶ÔΣ»ú £¬ÄÚ»ª´ïÖݻؾøÖ§¸¶Êê½ð £¬ÒÀ¸½50ÃûITÈËÔ±¼Ó°à4,212Ó×ʱ£¨¹¤×ʳɱ¾25.9ÍòÃÀÔª£©¼°±í²¿¹©¸øÉÌÖ§³Ö£¨×ÜÓöÈÔ¼130ÍòÃÀÔª£© £¬28ÌìÄÚ¸´Ô­90%ÊÜÓ°ÏìÊý¾Ý¼°·þÎñ ¡£Óë³ß¶È³Ð°üÉÌ·ÑÂÊÏà±È £¬´Ë¾Ù½Ú¼óÔ¼47.8ÍòÃÀÔª ¡£ÊÂÎñÏìÓ¦ÆÚ¼ä £¬Î¢ÈíDART¡¢MandiantµÈ¹©¸øÉÌÌṩͳһ֧³Ö¡¢·¨Ö¤µ÷²é¡¢¹¤³Ì¸´Ô­µÈ·þÎñ £¬³É±¾Ã÷ϸͨÃ÷¹«¿ª ¡£


https://www.bleepingcomputer.com/news/security/how-a-ransomware-gang-encrypted-nevada-governments-systems/


2. ¶íSandwormºÚ¿Í×éÖ¯¶ÔÎڹؼüÐÐÒµ·¢ÆðÊý¾Ý²Á³ý¹¥»÷


11ÔÂ6ÈÕ £¬½üÆÚ £¬¶íÂÞ˹¹ú¶ÈÖ§³ÖµÄºÚ¿Í×éÖ¯Sandworm£¨±ðÃûAPT44£©¶ÔÎÚ¿ËÀ¼½ÌÓý¡¢µ±¾ÐİÁ¸Ê³²¿ÃÅÌáÒé¶àÂÖÊý¾Ý²Á³ý¶ñÒâÈí¼þ¹¥»÷ £¬Ò»Á¬Æä×Ô2022ÄêÒÔÀ´Õë¶Ô¸Ã¹úµÄ·ÛËéÐÔÐж¯ ¡£ÍøÂ簲ȫ¹«Ë¾ESETÔÚ×îл㱨ÖÐÖ¸³ö £¬ÕâЩ¹¥»÷¼¯ÖÐÔÚ6ÔºÍ9Ô £¬Ö¸±êº­¸Çµ±¾Ö¡¢ÄÜÔ´¡¢ÎïÁ÷¼°Á¸Ê³ÐÐÒµ £¬ÆäÖÐÁ¸Ê³²¿ÃÅ×÷ΪÎÚ¿ËÀ¼Õ½Ê±ÖØÒªÊÕÈëÆðÔ´³ÉΪн¹µã ¡£Êý¾Ý²Á³ý¶ñÒâÈí¼þÈçPathWiper¡¢HermeticWiperµÈͨ¹ý·ÛËé»òɾ³ýÎļþ¡¢´ÅÅÌ·ÖÇø¼°Ö÷Êèµ¼¼Í¼ʵÏÖ³¹µ×Ïú»Ù £¬ÓëÀÕË÷Èí¼þ·ÖÆç £¬Æä´¿ÕýÒÔ·ÛËéΪÖ÷ÕÅ £¬µ¼ÖÂϵͳÄÑÒÔ¸´Ô­ ¡£Õâ´Î¹¥»÷ÖÐ £¬Sandworm²¿ÊðÁË¡°ZeroLot¡±ºÍ¡°Sting¡±µÈ±äÖÖ £¬ÆäÖÓ×°Sting¡±Í¨¹ýÒÔÐÙÑÀÀû´«Í³²Ëëȶ¨ÃûµÄWindows¹¤×÷Ö´ÐÐ £¬Í¹ÏÔ¹¥»÷µÄÒñ±ÎÐÔ ¡£³õʼ½Ó¼ûȨÏÞ¶àÓÉUAC-0099£¨×Ô2023ÄêÆð»îÔ¾µÄÍþвÐÐΪÌ壩»ñÈ¡ £¬Ëæºó×ªÒÆ¸øSandworm²¿Êð²Á³ýÆ÷ ¡£Á¸Ê³ÐÐÒµ³õ´Î³ÉÎªÖØÒª¹¥»÷Ö¸±ê £¬·´Ó³³ö¹¥»÷ÕßÊÔͼ¼õÈõÎÚ¿ËÀ¼Õ½Ê±¾­¼ÃµÄÕ½ÊõÒâͼ ¡£


https://www.bleepingcomputer.com/news/security/sandworm-hackers-use-data-wipers-to-disrupt-ukraines-grain-sector/


3. Î÷°àÑÀKISS-FMÔâRhysidaÀÕË÷Èí¼þ¹¥»÷


11ÔÂ6ÈÕ £¬Î÷°àÑÀÕ¼ÓаÙÍòÌý¶àµÄÈȵã¹ã²¥µç̨KISS-FMÔâ·êÓë¶íÂÞ˹¹ØÁªµÄRhysidaÀÕË÷Èí¼þÍÅ»ïÏ®»÷ ¡£¸ÃÍÅ»ïÔÚ°µÍøÅÄÂô¾Ý³ÆÇÔÈ¡µÄÊý¾Ý £¬ÒªÇóÖ§¸¶3¸ö±ÈÌØ±Ò£¨Ô¼30ÍòÃÀÔª£©Êê½ð £¬²¢É趨7ÌìÆÚÏÞ £¬²»È»½«ÏúÊÛ»òй¶Êý¾Ý ¡£RhysidaÒÔ¡°Ë«³ÁÀÕË÷¡±Õ½ÊõÎÅÃû £¬²»½öÓÃÀÕË÷Èí¼þËø¶¨Êý¾Ý £¬»¹Íþвй¶ÒÔʩѹ¸¶¿î ¡£¹¥»÷ÕßÌṩµÄ½ØÍ¼ÏÔʾ £¬±»µÁÊý¾Ý¿ÉÄÜÔ̺¬¹Û¶àÆÀ·Ö¼Í¼¡¢ÓëÎ÷°àÑÀÊý×Ö»¯×ªÐͲ¿»¥»»µÄÎļþ¼°·¢Æ± £¬µ«Ô±¹¤Ó×ÎÒÊý¾Ýй¶Çé¿öÉÐδÃ÷È· ¡£Õâ´ÎÊÂÎñÒÑÒý·¢¶Ô¹«¼ÒÐÅÀµ¶È½µÂä¡¢GDPRºÏ¹æ·çÏÕ¼°Ã³Ò×¹ØÏµÇÖÈŵÄÓÇÓô ¡£RhysidaÍÅ»ï×Ô2023Äê5Ô³ÉÁ¢ÒÔÀ´ £¬ÒÑÐû³Æ¹¥»÷236¸öÖ¸±ê £¬¸²¸Ç½ÌÓý¡¢Ò½ÁÆ¡¢Ôì×÷Òµ¡¢´¦Ëùµ±¾ÖµÈÁìÓò ¡£Æä¹¥»÷¼¿Á©Ô̺¬ÀûÓÃMicrosoft Teams¡¢ZoomºÍPuttyƽ̨½øÐжñÒâ¸æ°×ÍøÂç´¹µö £¬Ï°È¾É豸²¢ÇÔÈ¡Êý¾Ý ¡£


https://cybernews.com/security/ransomware-kissfm-spain-radio/


4. GlassWorm¶ñÒâÈí¼þ¾íÍÁ³ÁÀ´ £¬OpenVSXÔÙÔâ¹¥»÷


11ÔÂ8ÈÕ £¬ÔøÓ°ÏìOpenVSXºÍVisual Studio CodeÀûÓÃÊг¡µÄGlassWorm¶ñÒâÈí¼þ»î¶¯ÔÙ¶È»îÔ¾ £¬´øÀ´Èý¿îÐÂVSCodeÀ©´ó·¨Ê½ £¬ÀÛ¼ÆÏÂÔØÁ¿Òѳ¬10,000´Î ¡£¸Ã¶ñÒâÈí¼þͨ¹ýSolanaÂòÂô»ñÈ¡ÓÐÐ§ÔØºÉ £¬Ö¸±êÖ±Ö¸GitHub¡¢NPM¼°OpenVSXÕË»§Í´´¦ £¬ÒÔ¼°49¸öÀ©´ó·¨Ê½µÄ¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý ¡£ÆäÖ÷Ìâ¹¥»÷¼¿Á©ÊÇÀûÓò»Ë½¼ûµÄUnicode×Ö·ûʵÏÖ¶ñÒâ²Ù×÷ £¬ÕâÖÖ»ìºÏ¼¼ÇÉÈÔÄÜÈÆ¹ýOpenVSXÐÂÒýÈëµÄ·ÀÓù»úÔì ¡£Õâ´Î¹¥»÷ÖÐ £¬GlassWormͨ¹ýOpenVSXƽ̨ÉÏ´«µÄÈý¿îÀ©´ó±ðÀëΪ£ºai-driven-dev.ai-driven-dev£¨3,400´ÎÏÂÔØ£©¡¢adhamu.history-in-sublime-merge£¨4,000´ÎÏÂÔØ£©¡¢yasuyuky.transient-emacs£¨2,400´ÎÏÂÔØ£© ¡£¾Ý°²È«»ú¹¹Koi Security×·×Ù £¬¹¥»÷ÕßʹÓÃÒ»ÑùµÄ»ù´¡ÉèÊ© £¬µ«¸üÐÂÁ˺ÅÁîÓë½ÚÔ죨C2£©¶ËµãºÍSolanaÂòÂôÕ½Êõ £¬²¢ÒÑתÏòGitHubºóÓֻعéOpenVSX £¬Åú×¢ÆäÓÐÒâÔÚ¶àÆ½Ì¨³ÖÐøÔËÓª ¡£½ØÖÁ·¢¸å £¬Èý¿îЯ´øGlassWormÓÐÐ§ÔØºÉµÄÀ©´óÈÔ¿É´ÓOpenVSXÏÂÔØ £¬°²È«×¨¼ÒÖÒ¸æÓû§Ð辯Ìè´ËÀàÒñ±Î¹¥»÷ ¡£


https://www.bleepingcomputer.com/news/security/glassworm-malware-returns-on-openvsx-with-3-new-vscode-extensions/


5. NuGet¶ñÒâÈí¼þ°üÂñ·ü¶àÄê £¬2027ÄêÆð¼¤»î·ÛËéÐÔ¹¥»÷


11ÔÂ7ÈÕ £¬´úÂ밲ȫ¹«Ë¾Socket×êÑÐÈËÔ±ÔÚNuGet¿ªÔ´°üÖÎÀíÆ½Ì¨·¢Ï־ŸöÓÉ¿ª·¢Õß"shanhai666"°ä²¼µÄ¶ñÒâÈí¼þ°ü £¬ÕâЩÈí¼þ°ü±í±í¾ß±¸ºÏ·¨Ö°ÄÜ £¬ÊµÔòÔ̺¬Òñ±ÎµÄ·ÛËéÐÔÓÐÐ§ÔØºÉ £¬´òËãÓÚ2027Äê8ÔÂÖÁ2028Äê11Ô¼伤»î ¡£¸Ã¶ñÒâ´úÂëѡȡ¸ÅÂÊ´¥·¢»úÔì £¬ÐèÂú×ãÌØ¶¨ÈÕÆÚǰÌá¼°Ëæ»úÊýãÐÖµ£¨´óÓÚ80ʱ´¥·¢£© £¬Í¨¹ýC#À©´ó²½Ö轫¶ñÒâÂß¼­Í¨Ã÷×¢ÈëÊý¾Ý¿âºÍPLC²Ù×÷Á÷³Ì ¡£Õâ´Î¹¥»÷Õë¶ÔÈý´óÖ÷Á÷Êý¾Ý¿â£¨SQL Server¡¢PostgreSQL¡¢SQLite£©¼°Î÷ÃÅ×ÓS7¹¤Òµ½ÚÔìÉ豸 £¬ÓÈÆäÒÔ¼Ù×°³ÉºÏ·¨Sharp7¿âµÄ"Sharp7Extend"Èí¼þ°ü×îΪΣÏÕ ¡£¸Ã°üͨ¹ý¸½¼Ó"Extend"ºó׺ÓÕµ¼¿ª·¢ÕßÎóÏÂÔØ £¬µ±´¥·¢Ç°ÌáÂú×ãʱ £¬»áÒÔ20%¸ÅÂʵ±¼´ÖÕÖ¹Ö÷»ú¹ý³Ì £¬µ¼ÖÂPLC¿Í»§¶Ë²Ù×÷ÖжÏ£»»òͨ¹ýÑÓ³¤Ð´Èë»úÔ죨30-90·ÖÖÓ£©Ê¹PLCдÈë²Ù×÷ÓÐ80%¸ÅÂʰܻµ £¬Òý·¢Ö´ÐÐÆ÷ºÅÁîÃÔʧ¡¢°²ÕûϵͳʧЧµÈÑϳÁºó¹û ¡£½ØÖÁÆØ¹âʱ £¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØ½ü9500´Î £¬Éæ¼°SqlUnicorn.Core¡¢SQLite´æ´¢¿âµÈ¾Å¸ö¶ñÒâ°ü ¡£Ä¿Ç° £¬NuGetÒÑϼÜÓйØÈí¼þ°ü £¬µ«Ç±ÔÚÓ°ÏìÁìÓò¿í·º ¡£


https://www.bleepingcomputer.com/news/security/malicious-nuget-packages-drop-disruptive-time-bombs/


6. ÈýÐÇÁãÈÕ·ì϶ÔâÀûÓà £¬LandFall¼äµýÈí¼þ¶¨Ïò¹¥»÷Öж«Óû§


11ÔÂ7ÈÕ £¬ÍþвÐÐΪÕß×Ô2024Äê7ÔÂÆðÀûÓÃÈýÐÇAndroidͼÏñ´¦ÖÿâÖеÄÁãÈÕ·ì϶CVE-2025-21042 £¬Í¨¹ýWhatsApp·¢ËͶñÒâDNGÌåʽͼÏñÎļþ £¬²¿ÊðÃûΪ"LandFall"µÄ¼äµýÈí¼þ £¬¶¨Ïò¹¥»÷Öж«µØÓòÌØ¶¨ÈýÐÇGalaxyÓû§ ¡£¸Ã·ì϶Ϊlibimagecodec.quram.soÎļþÖеÄÔ½½çдÈë·ì϶ £¬ÑϳÁ¼¶±ð´ï"ÑϳÁ" £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë ¡£Ö»¹ÜÈýÐÇÓÚ2025Äê4Ô½¨¸´´Ë·ì϶ £¬µ«¹¥»÷»î¶¯ÒѳÖÐøÊýÔ £¬Ó°ÏìGalaxy S22¡¢S23¡¢S24¡¢Z Fold 4¼°Z Flip 4µÈÆì½¢»úÐÍ ¡£LandFall¼äµýÈí¼þѡȡ˫³Á¼¼Êõ×é¼þ£º¼ÓÔØÆ÷b.soÕÆ¹Ü¼ìË÷ºÍ¼ÓÔØÆäËûÄ£¿é £¬SELinuxÕ½Êõ°Ñ³ÖÆ÷l.soÔòÅú¸ÄÉ豸°²È«ÉèÖÃÒÔÌáÉýȨÏÞ²¢³ÉÁ¢ÓƾÃÐÔ ¡£¸ÃÈí¼þ¿É»ùÓÚÓ²¼þºÍSIM ID£¨ÈçIMEI¡¢IMSI£©¶ÔÉ豸½øÐÐÖ¸ÎÆ¼ø±ð £¬²¢¾ß±¸Âó¿Ë·ç¹àÒô¡¢Í¨»°¹àÒô¡¢µØÎ»×·×Ù¡¢½Ó¼ûÕÕÆ¬/ÁªÏµÈË/¶ÌÐÅ/ͨ»°¼Í¼/Îļþ¼°ä¯ÀÀº¹ÇàµÈ¼äµýÖ°ÄÜ £¬Í¬Ê±Ö§³ÖÄ£¿éÖ´ÐÓ×¢ÓÆ¾Ã»¯¡¢¼ì²âÌӱܺͱ£»¤Èƹý ¡£¹¥»÷õè¾¶ÏÔʾ £¬¶ñÒâDNGÎļþĩβ¸½¼ÓZIPѹËõ°ü £¬Í¨¹ýWhatsApp´«²¼ ¡£×êÑÐÈËÔ±·ÖÎö·¢ÏÖ £¬ÒÁÀ­¿Ë¡¢ÒÁÀÊ¡¢ÍÁ¶úÆäºÍĦÂå¸çΪDZÔÚÖ¸±ê¹ú¶È ¡£


https://www.bleepingcomputer.com/news/security/new-landfall-spyware-exploited-samsung-zero-day-via-whatsapp-messages/