΢Èí365ÕË»§ÔâOAuthÉ豸´úÂë´¹µö¹¥»÷¼¤Ôö
°ä²¼¹¦·ò 2025-12-231. ΢Èí365ÕË»§ÔâOAuthÉ豸´úÂë´¹µö¹¥»÷¼¤Ôö
12ÔÂ19ÈÕ£¬×Ô9ÔÂÆð£¬µç×ÓÓʼþ°²È«¹«Ë¾Proofpoint¼à²âµ½ÀûÓÃOAuthÉ豸´úÂëÊÚȨ»úÔìµÄÍøÂç´¹µö¹¥»÷ÏÔÖøÔö³¤£¬¹¥»÷Õßͨ¹ýÓÕÆÊܺ¦ÕßÔÚ΢ÈíºÏ·¨É豸µÇÂ¼Ò³ÃæÊäÈëÉ豸´úÂ룬ÎÞÐèÇÔȡʹ´¦»òÈÆ¹ý¶à³ÁÉí·ÝÑéÖ¤£¨MFA£©¼´¿É»ñÈ¡Microsoft 365ÕË»§½ÚÔìȨ¡£´ËÀ๥»÷²»½öÉæ¼°¾¼ÃÀûÒæÇý¶¯µÄÍøÂç·¸×ï·Ö×ÓÈçTA2723£¬»¹Ô̺¬¹ú¶È½áÃ˵ÄÍþвÐÐΪÕßÈçÒÉËÆ¶íÂÞ˹¹ØÁªµÄUNK_AcademicFlare¡£¹¥»÷Á´Í¨³£Í¨¹ý´¹µöÓʼþÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó½Ó¼û¹¥»÷Õß½ÚÔìµÄÍøÕ¾£¬ËæºóÒªÇóÊäÈë¡°É豸´úÂ롱ʵÏÖ¡°°²È«ÑéÖ¤¡±£¬ÊµÔòÊÚȨ¶ñÒâÀûÓ÷¨Ê½½Ó¼ûÕË»§¡£Proofpoint¹Û²ìµ½¹¥»÷ÕßʹÓÃSquarePhish v1/v2ºÍGraphishµÈ¹¤¾ß¼ò»¯´¹µöÁ÷³Ì¡£ÀýÈ磬н×ʼν±¹¥»÷ÀûÓÃÎĵµ¹²Ïíµö¶üºÍ±¾µØ»¯Æ·ÅƱêʶÒýÓÕµã»÷£»TA2723×Ô10ÔÂÆðתÏò´ËÀ๥»÷£¬ÔçÆÚʹÓÃSquarePhish2£¬ºóÆÚ¿ÉÄÜÇл»ÖÁGraphish£»UNK_AcademicFlareÔòÀûÓñ»ÈëÇÖÈ·µ±¾Ö/¾ü·½ÓÊÏä³ÉÁ¢ÐÅÀµ£¬Í¨¹ýαÔìOneDriveÁ´½ÓÓÕµ¼É豸´úÂëÊäÈë£¬ÖØÒªÕë¶ÔÃÀÅ·µ±¾Ö¡¢Ñ§Êõ¡¢Öǿ⼰½»Í¨²¿ÃÅ¡£
https://www.bleepingcomputer.com/news/security/microsoft-365-accounts-targeted-in-wave-of-oauth-phishing-attacks/
2. ºÓ´²¾º¼¼¾ãÀÖ²¿Ôâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
12ÔÂ21ÈÕ£¬°¢¸ùÍ¢ºÓ´²¾º¼¼¾ãÀÖ²¿£¨CARP£©ÓÚÖÜÎåÔâ·ê÷è÷ëÀÕË÷Èí¼þ×éÖ¯¹¥»÷£¬¸Ã×éÖ¯½«ÆäÁÐΪ¡°¹ÜÕÊ·þÎñ¡±Êܺ¦Õß²¢°ä²¼Ô̺¬Êýǧ·ÝÎļþµÄÑó´ÐÁ´½Ó¡£ÎļþÀàÐͺ¸ÇPDF¡¢Excel¡¢Word¡¢Í¼Ïñ¡¢µç×ÓÓʼþ¼°Ñ¹Ëõ´æµµ£¬µ¥Îļþ´óÓ×´Ó1KBÖÁ22MB²»µÈ£¬¹¦·ò¿ç¶ÈΪ2021ÖÁ2025Äê£¬Éæ¼°·¢Æ±¡¢ºÏͬ¡¢¼¼Êõ¹æ·¶¡¢¹¹ÖþÆ½ÃæÍ¼µÈÃô¸ÐÄÚÈÝ£¬ÉõÖÁÔ̺¬ÐÅÓþ¿¨Õ˵¥ºÍ²É¹º¶©µ¥Ñù±¾¡£ºÓ´²×÷Ϊ°¢¸ùÍ¢×î³É¹¦×ãÇò¶Ó£¨72¹Ú£©£¬Õ¼ÓÐ35Íò»áÔ±¼°ÄÏÃÀÖÞ×î´óÇò³¡£¬ÆäÇàÉÙÄ겿ÃÅ×îÓ×¶ÓÔ±½ö7Ë꣬Õâ´Î¹¥»÷¶³ö³öÌåÓý»ú¹¹ÍøÂ簲ȫ·ì϶¡£÷è÷ëÀÕË÷Èí¼þ×Ô2021Äê»îÔ¾£¬2022Äê³õ´Î¼Í¼¹¥»÷£¬2025Äê³ÉΪ×î»îÔ¾ÍŻ´Óǰ°ëÄê·¢Æð³¬600Æð¹¥»÷¡£¸Ã×é֯ѡȡ¡°ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©¡±Ä£Ê½£¬³¢ÊÔË«³ÁÀÕË÷¡£Æä¹¥»÷Ö¸±êº¸ÇÔì×÷ÉÌ¡¢½ðÈÚ»ú¹¹¡¢Ò½ÁƱ£½¡¼°µ±¾Ö»ú¹¹£¬ÒòÕâЩÐÐÒµ´æ´¢Ãô¸ÐÐÅÏ¢Ò×ÊÜÊý¾Ýй¶ӰÏì¡£
https://cybernews.com/news/club-atletico-river-plate-football-club-qilin-ransomware/
3. ·¨¹úÓÊÕþ¾ÖÊ¥µ®Ç°Ï¦ÔâDDoS¹¥»÷Ö¶àÒµÎṉ̃»¾
12ÔÂ23ÈÕ£¬Ê¥µ®Ç°Ï¦£¬·¨¹ú¹ú¶ÈÓÊÕþ¾Ö£¨La Poste£©Ôâ·ê´ó¹æÄ£DDoS¹¥»÷£¬µ¼ÖÂÆäÍøÕ¾¡¢Òƶ¯ÀûÓü°Ö÷ÌâÊý×Öϵͳ̱»¾£¬°ü¹üÅäËÍ·þÎñÏÔÖø·Å»º£¬²¿ÃÅÔÚÏßÒµÎñÖжϡ£¸Ã¾ÖÔÚÖÜÒ»ÉêÃ÷ÖÐÈ·ÈÏ£¬Õâ´ÎÍøÂç¹¥»÷Ôì³ÉϵͳÐÔ¹ÊÕÏ£¬µ«Ç¿µ÷ĿǰÎÞÖ¤¾ÝÏÔʾÓû§Êý¾Ýй¶£¬½öÈÏ¿ÉÓÊÕþ¼°ÒøÐÐÒµÎñ£¨Èç°ü¹üÅäËÍ¡¢ÒøÐÐתÕË£©Êܲ¨¼°¡£ÆìÏ·¨¹úÓÊÕþÒøÐУ¨La Banque Postale£©Í¬²½ÊÜÓ°Ï죬Óû§·´Ó³ÍøÉÏÒøÐм°Òƶ¯ÀûÓýӼûÄÑÌ⣬²»ÍâÒøÐз½Ãæ³ÎÇ壬ʵÌåÍøµãPOS»úË¢¿¨¡¢ATMÈ¡¿î¼°¶ÌÐÅÑéÖ¤µÄÔÚÏßÖ§¸¶Ö°ÄÜÈÔÕý³£ÔË×÷£¬¹ñ̨ҵÎñÒà³ÖÐøÊ¢¿ª¡£Õâ´Î¹¥»÷Ç¡·êÓÊÕþÒµÎñ¶¥·åÆÚ£¬Òý·¢Óû§Ç¿ÁÒ²»Âú¡£É罻ýÌåÉÏ£¬´óÁ¿Ãñ¶à±§Ô¹ÅäËÍÑÓ³¤¿ÉÄܵ¼ÖÂÊ¥µ®°ü¹üÎÞ·¨ÊµÊ±Í¶µÝ£¬·¨¹úýÌåÒ౨·²¿ÃÅÓʾÖÒòϵͳ¹ÊÕϻؾøÓû§¼Ä¼þ»òÈ¡¼þÒªÇó¡£Ö»¹Ü²¿ÃÅÓʾÖÒÑËõ¼õÔËÓª¹æÄ££¬µ«ÓÊÕþ¾ÖÇ¿µ÷¡°ÍŶÓȫԱ´øÍ·¼Ó¿ì·þÎñ¸´Ô¡±£¬Óû§ÈÔ¿Éͨ¹ý¹ñ̨½â¾öÓÊÕþ¼°ÒøÐÐÒµÎñ¡£
https://therecord.media/la-poste-france-ddos-disruption-days-before-christmas
4. ÂÞÂíÄáÑǹú¶ÈË®Îñ»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷
12ÔÂ22ÈÕ£¬ÂÞÂíÄáÑǹú¶ÈË®ÎñÖÎÀí»ú¹¹ÓÚ½üÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÔ¼1000Ì¨ÍÆËã»úϵͳ̱»¾£¬¹¤×÷Õ¾Óë·þÎñÆ÷ÎÞ·¨Ê¹Ó㬵«Ö÷ÌâË®Àû¼¼Êõ»ù´¡ÉèÊ©Èç´ó°Ó¡¢·ÀºéÉèʩδÊÜÓ°Ïì¡£Õâ´Î¹¥»÷ÆÈʹԱ¹¤ÉÕ»Ùµç×ÓÓʼþͨѶ£¬×ª¶øÊ¹Óõ绰ºÍÎÞÏßµç½øÐÐÄÚ²¿Ðµ÷£¬Í¹ÏÔÁËÍøÂç¹¥»÷¶ÔÈÕ³£ÔËÓªµÄ×ÌÈÅ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¹¥»÷ÕßѡȡÁËÓ봫ͳÀÕË÷Èí¼þ·ÖÆçµÄ¼¼Êõ¼¿Á©£¬ÀûÓúϷ¨Windows¹¤¾ßBitLockerÖ´ÐмÓÃÜÀÕË÷¡£ÕâÖÖ±»³ÆÎª¡°LOLBins¡±£¨Living-off-the-Land Binaries£©µÄÕ½Êõ£¬Í¨¹ýŲÓÃϵͳ×Ô´ø¹¤¾ß£¨ÈçBitLocker£©ÔÚÊܺ¦ÕßÍøÂçÖкáÏòÒÆ¶¯²¢¶ã±Ü°²È«¼ì²â£¬Ôö³¤ÁË·ÀÓùÄѶȡ£¿¨°Í˹»ù³¢ÊÔÊÒ2024Äê×êÑÐÏÔʾ£¬Ä«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô¼µ©µÄ¸ÖÌúÆóÒµ¡¢ÒßÃçÔì×÷É̼°µ±¾Ö»ú¹¹ÔøÔâ·êÀàËÆ¹¥»÷£»ÍøÂ簲ȫ¹«Ë¾BitdefenderÒ²Ö¸³ö£¬¡°ShrinkLocker¡±¶ñÒâÈí¼þÕý±»¶à¸öÍþв×éÖ¯ÓÃÓÚÕë¶ÔÀϾÉWindowsϵͳµÄµ¥Ò»¹¥»÷£¬Í¨¹ý¾ç±¾»¯²Ù×÷ºÏ·¨¹¤¾ßʵÏÖÀÕË÷Ö÷ÕÅ¡£
https://therecord.media/romania-national-water-agency-ransomware-attack
5. ÈÕ²úÆû³µÏݺìñÊý¾Ýй¶·çÀË£¬2.1Íò¿Í»§ÐÅÏ¢ÔâÇÔ
12ÔÂ22ÈÕ£¬ÈÕ²úÆû³µÓÐÏÞ¹«Ë¾½üÈÕ֤ʵ£¬ÒòÃÀ¹úÆóÒµÈí¼þ¹«Ë¾ºìñ£¨Red Hat£©9Ô²úÉúµÄÊý¾Ýй¶ÊÂÎñ£¬ÆäÔ¼21,000ÃûÈÕ±¾¸£¸ÔµØÓò¿Í»§ÐÅÏ¢±»ÇÔÈ¡£¬Éæ¼°È«Ãû¡¢ÎïÀíµØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¼°ÏúÊÛÔËÓªÊý¾Ý£¬µ«ÐÅÓþ¿¨µÈ²ÆÕþÐÅϢδÊܲ¨¼°¡£Õâ´ÎÊÂÎñÔ´ÓÚºìñ¹«Ë¾Êý¾Ý·þÎñÆ÷Ôâδ¾ÊÚȨ½Ó¼û£¬µ¼ÖÂÈÕ²úίÍÐÆä¿ª·¢µÄ¿Í»§ÖÎÀíϵͳÊý¾Ýй¶£¬³ÉΪÈÕ²ú½ñÄêµÚ¶þÆðÍøÂ簲ȫÊÂÎñ£¬´Ëǰ8Ô£¬ÆäÉè¼Æ×Ó¹«Ë¾Creative Box Inc.ÔøÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷¡£ºìñÊý¾Ýй¶ÊÂÎñÓ°ÏìÉîÔ¶£¬Éæ¼°28,000¸ö˽ÓÐGitLab´æ´¢¿â£¬Ãô¸ÐÊý¾Ý´ïÊý°ÙGB¡£ºÚ¿Í×éÖ¯Crimson Collective×î³õÐû³Æ¶Ô´ËÕÆ¹Ü£¬ËæºóShinyHuntersҲȾָÆäÖУ¬ÔÚÀÕË÷ƽ̨Íйܱ»µÁÊý¾ÝÑù±¾ÒÔʩѹÊܺ¦¹«Ë¾¡£ÈÕ²úÇ¿µ÷£¬±»ÈëÇֵĺìñ»·¾³Î´´æ´¢ÆäËûÊý¾Ý£¬ÇÒÎÞÖ¤¾ÝÅúעй¶ÐÅÏ¢Òѱ»ÀÄÓ㬵«ÒÑÒý·¢¿Í»§¶ÔÒþÖÔ°²È«µÄÓÇÓô¡£
https://www.bleepingcomputer.com/news/security/nissan-says-thousands-of-customers-exposed-in-red-hat-breach/
6. ÒÁÀÊAPT×éÖ¯InfyЯеĶñÒâÈí¼þ»î¶¯³ÁÏÖ
12ÔÂ21ÈÕ£¬Íþвµý±¨»ú¹¹SafeBreachÅû¶£¬ÒÁÀÊInfy£¨ÓÖ³ÆPrince of Persia£©APT×éÖ¯½üÆÚ³ÁÆô»îÔ¾£¬ÕâÊǸÃ×éÖ¯×Ô2020ÄêÕë¶ÔÈðµä¡¢ºÉÀ¼¡¢ÍÁ¶úÆäÖ¸±êºó³õ´Î´ó¹æÄ£ÏÖÉí¡£×÷ΪÏÖ´æ×î¹ÅÀϵÄAPTÖ®Ò»£¬Infy»î¶¯¿É×·ÒäÖÁ2004Äê12Ô£¬ÆäÒñ±ÎÐԳ־øßÓÚCharming KittenµÈ³ÛÃûÒÁÀÊ×éÖ¯£¬µ«Õâ´ÎÐж¯Õ¹Ê¾¸ü¸´ÔӵĹ¥»÷Á´Éý¼¶¡£×îй¥»÷ÖУ¬InfyʹÓÃÉý¼¶°æFoudreÏÂÔØÆ÷ÓëTonnerreÖ²È뷨ʽ£¬Í¨¹ý´¹µöÓʼþ´«²¼¡£¹¥»÷Á´´Ó´«Í³ExcelºêתÏòÎĵµÄÚǶ¿ÉÖ´ÐÐÎļþ£¬½áºÏÓòÃûÌìÉúËã·¨£¨DGA£©Ç¿»¯C2·þÎñÆ÷ÈÍÐÔ¡£ÓÈΪֵÍ×ÌùÐĵÄÊÇ£¬¶ñÒâÈí¼þͨ¹ýRSAÊðÃûÑéÖ¤C2ÓòÃûÕæÊµÐÔ¡£2025Äê9Ô¼ì²âTonnerre×îа汾ÐÂÔöTelegramȺ×éͨѶ»úÔ죬ÓйØÅäÖô洢ÔÚC2·þÎñÆ÷¡°t¡±Ä¿Â¼µÄtga.adrÎļþÖУ¬½ö¶ÔÌØ¶¨Êܺ¦ÕßGUID´¥·¢ÏÂÔØ¡£´Ë±í£¬C2·þÎñÆ÷´æÔÚδ֪Óô¦µÄ¡°download¡±Ä¿Â¼£¬´§Ä¦ÓÃÓÚ¶ñÒâÈí¼þÉý¼¶¡£
https://thehackernews.com/2025/12/iranian-infy-apt-resurfaces-with-new.html


¾©¹«Íø°²±¸11010802024551ºÅ