TomirisÉý¼¶¶à˵»°±øÆ÷¿â£¬¾«×¼½ø¹¥¶í±í½»»ú¹¹
°ä²¼¹¦·ò 2025-12-021. TomirisÉý¼¶¶à˵»°±øÆ÷¿â£¬¾«×¼½ø¹¥¶í±í½»»ú¹¹
12ÔÂ1ÈÕ£¬¿¨°Í˹»ù×îл㱨½Òʾ£¬ÃûΪTomirisµÄÍþвÐÐΪÕßÕý¶Ô¶íÂÞ˹±í½»²¿¡¢µ±¾ÐÄä×éÖ¯¼°ÖÐÑǹú¶È»ú¹¹ÌáÒéÕ½ÊõÐÔÍøÂç¹¥»÷£¬ÆäÖ÷ÌâÖ¸±êÊÇͨ¹ýÓã²æÊ½´¹µöÓʼþ²¿Êð¶à˵»°±àдµÄ¶ñÒâÈí¼þÄ£¿é£¬»ñȡԶ³Ì½Ó¼ûȨÏÞ²¢³ÉÁ¢Óƾû¯½ÚÔì¡£¸Ã×éÖ¯2025Äê¹¥»÷Á´ÏÔʾ£¬³¬50%µÄµö¶üÎļþѡȡ¶íÓï¼°ÖÐÑǹú¶È¹Ù·½Ëµ»°¶¨Ô죬¹¥»÷Õßͨ¹ý¼ÓÃÜRARÎļþ£¨½âѹÃÜÂëÖ±½ÓǶÈëÓʼþÕýÎÄ£©·Ö·¢¼Ù×°³ÉWordÎĵµµÄ¿ÉÖ´ÐÐÎļþ£¬ÔËÐкó¿ªÊÍC/C++·´ÏòShell£¬ÏνÓC2·þÎñÆ÷ÏÂÔØAdaptixC2¿ò¼Ü£¬²¢Í¨¹ýÅú¸ÄWindows×¢²á±íʵÏÖ¶ñÒâÔØºÉÓÆ¾Ã»¯¡£TomirisµÄÕ½ÊõÑݱäÓÈΪÏÔÖø£¬ÆäÈÕ񾮵ÈÔµØÀûÓÃTelegram¡¢DiscordµÈ¹«¹²·þÎñ×÷ΪC2·þÎñÆ÷£¬½«¶ñÒâÁ÷Á¿ÓëºÏ·¨·þÎñÁ÷Á¿»ìºÏÒÔ¶ã±Ü¼ì²â¡£Æä¶ñÒâÈí¼þ±øÆ÷¿âº¸ÇC#¡¢Rust¡¢Go¡¢PythonµÈ¶à˵»°±àдµÄ·´ÏòShell¡¢SOCKS´úÀí¼°ºóÃÅ·¨Ê½¡£¶à˵»°Ä£¿éµÄ½Ã½ÝÐÔ¡¢µÍ¿ÉÒÉÐÔÌØµã¼°¶Ô¿ªÔ´¿ò¼ÜµÄÀûÓã¬Ê¹Tomiris¿ÉÄÜʵÏÖÒñ±ÎµÄ³Ö¾ÃÓÆ¾Ã»¯¹¥»÷¡£
https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html
2. ÈÕÀú¶©Ôݲȫäµã£ºBitSightÆØ347¸ö¶ñÒâÓòÃû·çÏÕ
11ÔÂ28ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾BitSight×îÐÂ×êÑнÒʾ£¬ÍþвÐÐΪÕßÕýͨ¹ý°Ñ³ÖÊý×ÖÈÕÀú¶©ÔÄ»ù´¡ÉèʩִÐдó¹æÄ£Éç»á¹¤³Ì¹¥»÷¡£ÈÕÀú¶©ÔÄÖ°Äܱ¾ÓÃÓÚºÏÐ̳¡¾°£¬ÈçÁãÊÛÉÌÍÆËÍ´ÙÏúÈÕÆÚ¡¢ÌåÓýлá¸üÐÂÈüÊÂÈճ̣¬ÆäÔÊÐíµÚÈý·½·þÎñÆ÷Ö±½ÓÏòÓû§É豸Ôö³¤ÊÂÎñ²¢·¢ËÍ֪ͨµÄ¸öÐÔ£¬È´±»¶ñÒâÀûÓ㬹¥»÷ÕߴÍйÜÓÚ¹ýÆÚ»ò±»½Ù³ÖÓòÃûµÄÐéαÈÕÀú¶©ÔÄ·þÎñ£¬ÓÕÆÓû§¶©ÔĺóÍÆËͺ¬¶ñÒâÁ´½Ó¡¢¸½¼þµÄÈÕÀúÎļþ£¬´¥·¢´¹µö¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢JavaScript´úÂëÖ´ÐÐÉõÖÁAI¸±ÊÖÀÄÓõȷçÏÕ¡£×êÑÐʼÓÚÒ»¸ö±» ¡°Sinkhole¡± ¼¼ÊõÊÕÊܵÄÓòÃû£¬¸ÃÓòÃûÔÓÃÓÚ·Ö·¢µÂ¹ú¹«¹²¼ÙÆÚICSÎļþ£¬È´ÖðÈÕ½Ó¹Ü1.1Íò¸ö¶ÀÁ¢IP½Ó¼û£¬Òý·¢×êÑÐÍŶӹØ×¢¡£½øÒ»´ëÊ©²é·¢ÏÖ347¸ö¿ÉÒÉÈÕÀúÓòÃû£¬Éæ¼°2018ÊÀ½ç±¡¢ÒÁ˹À¼HijriÈÕÀúµÈÖ÷Ì⣬ÖðÈÕÀۼƽµÜÔ¼400Íò´ÎÃÀ¹úΪÖ÷µÄÈ«ÃÀ½Ó¼ûÒªÇó¡£³Á¶´Êý¾ÝÏÔʾ£¬ÕâЩ½Ó¼û¶àΪÒѶ©ÔÄÓû§µÄºó¶Üͬ²½ÒªÇó£¬Òâζ×ÅÊÕÊܹýÆÚÓòÃûµÄ¹¥»÷Õß¿ÉÖ±½ÓÏòÓû§Éè±¸ÍÆËͶ¨Ô컯¶ñÒâÈÕÀúÊÂÎñ¡£
https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/
3. PlayÀÕË÷Èí¼þ¹¥»÷ADC Aerospace
11ÔÂ29ÈÕ£¬ÃÀ¹úº½¿Õº½ÌìÓë¹ú·ÀÁìÓò¹¤³Ì²¿¼þÔì×÷ÉÌADC AerospaceÒò·þÎñŵ˹ÂÞÆÕ¡¤¸ñ³Âü¡¢¿ÂÁÖ˹º½¿Õº½Ìì¡¢»ôÄáΤ¶ûµÈ³ÛÃûÆóÒµ£¬³ÉΪÀÕË÷Èí¼þ¹¥»÷³ÁµãÖ¸±ê¡£Õâ´Î¹¥»÷ÓÉÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þ¼¯ÍÅÖ®Ò»PlayÖ´ÐУ¬¸Ã×éÖ¯ÒÔй¶¿Í»§Êý¾ÝΪÍþвÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð£¬Èô»Ø¾øÔò°ä²¼²¿ÃÅÊý¾ÝƬ¶Î¡£ºÚ¿ÍÐû³ÆÒÑ»ñÈ¡¿Í»§Îļþ¡¢Ô¤Ëã²ÆÕþÐÅÏ¢¡¢Ð½×ʼͼ¡¢Éí·ÝÖ¤Ã÷µÈ˽ÃÜÊý¾Ý£¬µ«Î´ÌṩÑù±¾£¬ÕæÊµÐÔ´ýºË²é¡£ÈôÊý¾Ýй¶Êôʵ£¬ADC½«Ãæ¶Ô¶à³Á·çÏÕ£º°µÍø¶Ô¹ú·À³Ð°üÉÌÊý¾ÝµÄ¸ßÐèÒª¿ÉÄÜÍÆ¶¯±»µÁÐÅÏ¢ÂòÂô£»Ð½×ʼͼÖеÄÓ×ÎÒÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£»ÆäËû˽ÃÜÊý¾ÝÔò¿ÉÄܳÉΪÉç»á¹¤³Ì¹¥»÷¹¤¾ß£¬¹¥»÷Õß¼ÙÒâÐÐÒµÓйط½Ö´Ðиü¾ß·ÛËéÐÔµÄÚ¿Æ¡£Play¼¯ÍÅÈ¥ÄêõÒÉíÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þǰÈý£¬½ñÄê8Ô³õ¸ÕÈëÇÖΪÃÀ¹úˮʦ¡¢²¨Òô¹©»õµÄJamco Aerospace¡£
https://cybernews.com/security/adc-aerospace-breach-claims/
4. CoupangÔâ·êº«¹úÊ·ÉÏ×î´ó¹æÄ£¿Í»§Êý¾Ýй¶ÊÂÎñ
11ÔÂ30ÈÕ£¬±»ÓþΪ¡°º«¹úÑÇÂíÑ·¡±µÄº«¹úµçÉ̾ÞÍ·CoupangÓÚ11ÔÂ18ÈÕÅû¶һ·´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬Ó°Ïì½ü3400Íò¸ö¿Í»§ÕË»§£¬´´º«¹úµ¥´ÎÊý¾Ýй¶ӰÏìÁìÓòÖ®×î¡£¾µ÷²é£¬¹¥»÷Õß×Ô6ÔÂ24ÈÕÆðͨ¹ýº£±í·þÎñÆ÷ÌáÒéδ¾ÊÚȨ½Ó¼û£¬Öð²½À©´ó¹¥»÷¹æÄ££¬×îÖÕµ¼Ö³¬3300Íòº«¹úÓû§Êý¾Ý±íй¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç×ÓÓÊÏä¡¢µç»°ºÅÂë¡¢ÊÕ»õµØÖ·¼°²¿ÃŶ©µ¥¼Í¼£¬µ«Ö§¸¶ÐÅÏ¢ÓëµÇ¼ƾ֤δ±»»ñÈ¡¡£CoupangÔÚ·¢ÏÖÒì³£ºóµ±¼´Ïòº«¹úÓ×ÎÒÐÅÏ¢±£»¤Î¯Ô±»á¡¢¾¯·½¼°»¥ÁªÍø°²È«¾Ö»ã±¨£¬²¢Æô¶¯Ó¦¼±ÏìÓ¦¡£¹«Ë¾×î³õÎóÅнöÔ¼4500ÈËÊÜÓ°Ï죬ºó½¨¸ÄΪ³¬3300ÍòÈË£¬Í¹ÏÔ³õÆÚ¼ì²â»úÔìµÄ²»¼°¡£º«¹úµ±¾Ö¶Ô´Ë¸ß¶ÈÆ÷³Á£¬¿ÆÑ§¼¼ÊõÐÅϢͨѶ²¿²¿³¤ÅᾩѫÖÜÈÕÖ÷³Ö´¹Î£»áÒ飬ºË²éCoupangÊÇ·ñÎ¥·´¡¶Ó×ÎÒÐÅÏ¢±£»¤·¨¡·°²È«¹æ·¶¡£º«¹ú»¥ÁªÍø°²È«ÕñÐËÔº£¨KISA£©ÒÑÏòÊÜÓ°ÏìÓû§°ä²¼·À´¹µöÚ¿ÆÖ¸ÄÏ£¬½¨Ò鶨ÆÚÅú¸ÄÃÜÂë¡¢ÆôÓÃË«³É·ÖÈÏÖ¤¡£Õâ´ÎÊÂÎñÒÑÒý·¢Óû§¼¯ÌåËßËÏ·çÏÕ£¬CoupangÕýÃæ¶Ô˾·¨×·ÔðÓëŵÑÔ³Á´´µÄË«³ÁѹÁ¦¡£
https://cybernews.com/news/coupang-confirms-massive-data-breach-exposing-33-7-million-accounts/
5. ¾¯·½²é·âÁËCryptomixer¼ÓÃÜÇ®±Ò»ìºÏ·þÎñ
12ÔÂ1ÈÕ£¬ÈðÊ¿ÓëµÂ¹ú·¨Âɲ¿ÃŽüÈÕ½áºÏ·¢Õ¹¡°°ÂÁÔì¥ÑÇÐж¯¡±£¬ÓÚ11ÔÂ24ÈÕÖÁ28ÈÕÔÚËÕÀèÊÀ²é·â¼ÓÃÜÇ®±Ò»ìºÏ·þÎñCryptomixer¡£¸Ãƽ̨×Ô2016ÄêÔËÓªÒÔÀ´£¬±»Ö¸ÐÖúÍøÂç·¸×ï·Ö×ÓÏ´Ç®³¬13ÒÚÅ·Ôª±ÈÌØ±Ò£¬³ÉΪÀÕË÷Èí¼þÍŻ°µÍøÊг¡¼°µØÏ¾¼ÃÂÛ̳»ìºÏ·¸×ï×ʽðµÄÖ÷ÌâÇþ·¡£Ðж¯ÖУ¬·¨ÂÉ»ú¹¹ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖÏ£¬²é»ñÈý̨·þÎñÆ÷¡¢12TBÊý¾Ý¡¢Ã÷Íø¼°Tor°µÍøÓòÃû£¬²¢¿ÛѺ¼ÛÖµ2400ÍòÅ·Ôª±ÈÌØ±Ò¡£Cryptomixerͨ¹ý»ìºÏÓû§¼ÓÃÜÇ®±ÒÖÁ×Ê½ð³Ø²¢·Ö·¢ÖÁÐÂÇ®°üµØÖ·£¬ÓÐЧ×è¶ÏÇø¿éÁ´×ʽð×·×Ù£¬³ÉΪ··¶¾¡¢±øÆ÷×ß˽¡¢ÀÕË÷¹¥»÷¼°Ö§¸¶¿¨Ú²ÆµÈ·¸×ï»î¶¯µÄÏ´Ç®Ê×Ñ¡¹¤¾ß¡£ÆäÔËӪģʽ»¹Ô̺¬¶ÔÏ´Ç®×ʽðÊÕȡӶ½ð£¬ÔÙ×ªÒÆÖÁ¿Í»§Ö¸¶¨Ç®°ü£¬×îÖÕͨ¹ýÒøÐлòATM½«·¸·¨×ʲúת»»Îª·¨±Ò»òÆäËû¼ÓÃÜÇ®±Ò¡£´ËÀà·þÎñËä´æÔںϷ¨Óô¦£¬µ«ÖØÒª±»·¸×ïÍÅ»ïÓÃÓÚÌӱܲ龿¡£
https://www.bleepingcomputer.com/news/security/police-takes-down-cryptomixer-cryptocurrency-mixing-service/
6. CISA½«OpenPLC ScadaBR·ì϶Ôö³¤µ½KEVĿ¼ÖÐ
12ÔÂ1ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«±àºÅΪCVE-2021-26829µÄOpenPLC ScadaBR·ì϶ÄÉÈëÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¸Ã·ì϶Ϊ¿çÕ¾¾ç±¾£¨XSS£©·ì϶£¬Í¨¹ýsystem_settings.shtmÎļþÓ°ÏìWindowsºÍLinux°æ±¾£¬¾ßÌåÉæ¼°Windows¶Ë1.12.4¼°¸üÔç°æ±¾¡¢Linux¶Ë0.9.1¼°¸üÔç°æ±¾£¬CVSSÆÀ·ÖΪ5.4¡£2025Äê9Ô£¬Ç×¶íºÚ¿Í×éÖ¯TwoNetÕë¶ÔÍøÂ簲ȫ¹«Ë¾ForescoutÔËÓªµÄICS/OTÃÛ¹ÞϵͳÌáÒé¹¥»÷£¬ÎóÅÐÆäΪˮ´¦Öó§¡£¹¥»÷ÕßÀûÓÃĬÈÏÆ¾Ö¤»ñȡϵͳ½Ó¼ûȨÏ޺󣬴´½¨ÃûΪ¡°BARLATI¡±µÄÕË»§£¬²¢Í¨¹ýCVE-2021-26829·ì϶´Û¸ÄÈË»ú½çÃæ£¨HMI£©µÇÂ¼Ò³Ãæ£¬Ã¿´Î½Ó¼û¸ÃÒ³ÃæÊ±£¬»á´¥·¢Ô̺¬Ôà»°µÄµ¯´°ÖҸ棬ͬʱ½ûÓÃÈÕÖ¾ºÍ¾¯±¨Ö°ÄÜ¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01£¬Áª¹úÃñÓûú¹¹£¨FCEB£©ÐëÔÚ2025Äê12ÔÂ19ÈÕǰ½¨¸´¸Ã·ì϶£¬ÒÔ½µµÍÂä´ó·çÏÕ¡£CISAͬʱ½¨Òé˽Ӫ»ú¹¹Éó²éKEVĿ¼£¬ÊµÊ±½¨²¹×ÔÉí»ù´¡ÉèÊ©ÖеÄͬÀà·ì϶£¬Ô¤·À±»ÀûÓá£
https://securityaffairs.com/185185/security/u-s-cisa-adds-an-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html


¾©¹«Íø°²±¸11010802024551ºÅ