ÃÅÂÞ´óѧ32ÍòÈËÊý¾Ýй¶ÊÂÎñ

°ä²¼¹¦·ò 2026-01-16

1. ÃÅÂÞ´óѧ32ÍòÈËÊý¾Ýй¶ÊÂÎñ


1ÔÂ14ÈÕ £¬ÃÀ¹úÃÅÂÞ´óѧ2024Äê12ÔÂ9ÈÕÖÁ23ÈÕÔâ·êÑϳÁÍøÂç¹¥»÷ £¬ÍþвÐÐΪÕßÈëÇÔìäϵͳ £¬ÇÔÈ¡³¬¹ý32ÍòÈ˵ÄÓ×ÎÒ¡¢²ÆÕþ¼°½¡È«ÐÅÏ¢ ¡£¸ÃУÔÚ2025Äê9Ô¾­ÎļþÉó²éÈ·ÈÏ £¬ÊÜÓ°ÏìÕßÉæ¼°µ±Ç°¼°Íù½ìѧÉú¡¢½ÌÈËÔ±¹¤µÈ £¬Ð¹Â¶Êý¾Ýº­¸ÇÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£ÏÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢Ò½ÁÆÐÅÏ¢¡¢µç×ÓÕË»§ÃÜÂë¼°²ÆÕþÕË»§ÏêÇéµÈÃô¸ÐÄÚÈÝ ¡£×÷ΪӦ¶Ô´ëÊ© £¬Ñ§ÌÃ×Ô2026Äê1ÔÂ2ÈÕÆðÏòÊÜÓ°ÏìÓû§ÓʼÄ֪ͨ £¬ÌáÐÑ¼à¿ØÐÅÓþ»ã±¨¼°ÕË»§Òì³£ £¬²¢ÌṩCyberScoutÌṩµÄΪÆÚÒ»ÄêÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ ¡£ÃÅÂÞ´óѧº¹Çà¿É×·ÒäÖÁ1933Äê £¬ÏÖ·¢Õ¹ÎªÕ¼ÓÐŦԼ²¼ÀÊ¿Ë˹¡¢ÐÂÂÞл¶û¼°Ê¥Â¬Î÷ÑÇÈý´óÐ£ÇøµÄ˽Á¢´óѧ £¬ÔÚУÉú³¬9000ÈË ¡£ÃÅÂÞ´óѧËäÆô¶¯ÐÅÓþ¼à¿Ø·þÎñ £¬µ«¹Ø¼üÐÅÏ¢Èç¹¥»÷ÕßÉí·Ý¡¢¾ßÌå·ì϶ÀàÐÍÈÔδÅû¶ £¬Òý·¢¹«¼Ò¶ÔͨÃ÷¶ÈµÄÖÊÒÉ ¡£


https://www.bleepingcomputer.com/news/security/monroe-university-says-2024-data-breach-affects-320-000-people/


2. ÍøÂç×ï·¸ÇÔÈ¡FacebookÓû§Æ¾Ö¤Ð¼¿Á©


1ÔÂ13ÈÕ £¬ÍøÂç·¸×ï·Ö×ÓÕý´óÁ¿Ñ¡È¡¡°ä¯ÀÀÆ÷Ì×ä¯ÀÀÆ÷¡±¼¼Êõ¶ÔFacebookÓû§ÌáÒéÒñ±Î¹¥»÷ £¬Ì°Í¼ÇÔÈ¡ÆäµÇ¼ƾ֤²¢Ö´ÐкóÐøÚ²Æ­ ¡£¾ÝTrellixÍøÂ簲ȫÍŶÓ×êÑÐ £¬´ËÀ๥»÷ͨ¹ý´¹µöÓʼþ¼¤Ôö £¬Óʼþ³£¼Ù×°³ÉÂÉʦÊÂÎñËùÖҸ桢ÕË»§°²È«Í¨ÖªµÈ £¬ÀûÓÃÓû§¶Ô°æÈ¨ÇÖȨË÷Å⡢δÊÚȨµÇ¼ÌáÐÑ»òÕË»§¹Ø¹ØÖÒ¸æµÄ·¢¼±ÉúÀí £¬ÓÕʹÆäµã»÷¼Ù×°³ÉFacebook¹Ù·½Á´½ÓµÄÐéα¶ÌÁ´½Ó ¡£¹¥»÷µÄÖ÷ÌâÔÚÓÚ¡°ä¯ÀÀÆ÷Ì×ä¯ÀÀÆ÷¡±µ¯´°µÄÕæÇÐÐÔ£º¹¥»÷ÕßÔÚÊܺ¦Õßä¯ÀÀÆ÷ÄÚ´´½¨×Ô½ç˵ÐéαµÇ¼´°¿Ú £¬¸Ã´°¿ÚÔ̺¬Ó²±àÂëµÄÕæÊµFacebookµÇÂ¼Ò³ÃæURL £¬²¢Ô¤ÏȲ¿ÊðÐéαÑéÖ¤Âë´°¿Ú £¬Ê¹Õû¸öÁ÷³ÌÓëÓû§ÊìϤµÄFacebookÈÏÖ¤½çÃæ¸ß¶ÈÒ»Ö £¬ÊÓ¾õÉÏÄÑÒÔ¾õ²ìÒì³£ ¡£Êܺ¦ÕßÔÚ¡°ÉêÊö¡±Ò³ÃæÊ×Ïȱ»ÒªÇóÌîдÐÕÃû¡¢ÓÊÏä¡¢µç»°¡¢µ®ÉúÈÕÆÚµÈÓ×ÎÒÐÅÏ¢ £¬ËæºóÔÚµÚ¶þÒ³Ãæ¡°È·ÈÏ¡±ÃÜÂë £¬µ¼ÖÂÃô¸ÐÐÅÏ¢¼°Æ¾Ö¤±»ÇÔÈ¡ ¡£´ËÀ๥»÷µÄ¶¯»úÔ̺¬½Ù³ÖÕË»§¡¢ÇÔÈ¡Ó×ÎÒÊý¾Ý¡¢Ö´ÐÐÉí·Ýڲƭ»òÏòÓû§ÁªÏµÈË´«²¼Ú¿Æ­ ¡£


https://www.infosecurity-magazine.com/news/phishing-scams-exploit-browser/


3. ΢Èí½áºÏ¶à¹úµ·»ÙRedVDSÍøÂç·¸×ïÆ½Ì¨


1ÔÂ15ÈÕ £¬Î¢Èí½üÈÕ°ä·¢³É¹¦Ì±»¾È«ÇòÍøÂç·¸×ïÆ½Ì¨RedVDS £¬¸Ãƽ̨×Ô2025Äê3ÔÂÒÔÀ´½öÔÚÃÀ¹ú¾ÍÔì³É³¬4000ÍòÃÀÔªËðʧ ¡£×÷Ϊ"ÍøÂç·¸×ï¼´·þÎñ"£¨CaaS£©µäÐÍ´ú±í £¬RedVDSͨ¹ýredvds[.]comµÅ×òÃûÏòStorm-0259µÈ·¸×OÍÅÌṩÿÔ½öÐè24ÃÀÔªµÄÐé¹¹Windows·þÎñÆ÷ £¬Ö§³ÖÎÞÏÞ¶ÈÖÎÀíÔ±½ÚÔì £¬Ê¹Ú²Æ­ÐÐΪʵÏֵͳɱ¾¡¢¹æÄ £»¯ÇÒÄÑÒÔ×·×Ù ¡£ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëµÂ¹úµ±¾Ö¹²Í¬Ï £¬Î¢ÈíÔÚÃÀ¹ú¡¢Ó¢¹úÌáÆðÃñÊÂËßËÏ £¬²é·âÆä¶ñÒâ»ù´¡ÉèÊ©²¢ÏÂÏßÊг¡ÃÅ»§ ¡£µ÷²éÏÔʾ £¬RedVDS×Ô2019ÄêÔËÓªÖÁ½ñ £¬ËùÓÐÐé¹¹»ú¾ùʹÓÿË¡µÄWindows Server 2022¾µÏñ £¬¹²ÏíÍÆËã»úÃû³Æ"WIN-BUNS25TD77J"µÄ¼¼ÊõÌØµã³ÉΪ׷×ٹؼü ¡£Æä·þÎñÆ÷×âÓÃ×ÔÃÀ¡¢Ó¢¡¢·¨µÈÁù¹úµÚÈý·½ÍйÜÉÌ £¬Ê¹·¸×ï·Ö×ÓÄÜ»ñȡָ±êµØÓòIPµØÖ· £¬ÇáËÉÈÆ¹ýµØÀí°²È«¹ýÂË ¡£¹¥»÷Õß½áºÏAI¹¤¾ßÌìÉú¸ß·ÂÕæ´¹µöÓʼþ £¬ÉõÖÁʹÓû»Á³¡¢ÓïÒô¿Ë¡¼ÙÒâ¿ÉÐÅ×éÖ¯ ¡£Êý¾ÝÏÔʾ £¬½ÚÔì2600̨Ðé¹¹»úµÄ·¸×ï·Ö×ÓÈÕ¾ù·¢ËͰÙÍò·â´¹µöÓʼþ £¬ËĸöÔÂÄÚ¹¥ÆÆ½ü20Íò΢ÈíÕË»§ £¬È«Çò³¬19.1Íò×éÖ¯Êܲ¨¼° ¡£


https://www.bleepingcomputer.com/news/security/microsoft-seizes-servers-disrupts-massive-redvds-cybercrime-platform/


4. ²¨À¼´ì°ÜÕë¶ÔÄÜÔ´»ù´¡ÉèÊ©µÄÑϳÁÍøÂç¹¥»÷


1ÔÂ15ÈÕ £¬²¨À¼µ±¾Ö°ä·¢³É¹¦´ì°Üһ·Õë¶ÔÆäÄÜÔ´»ù´¡ÉèÊ©µÄ³Á´óÍøÂç¹¥»÷ £¬³ÆÕâÊǽüÄêÀ´¶Ô¸Ã¹úÄÜԴϵͳ×îÑϳÁµÄÍþв ¡£¾ÝÄÜÔ´²¿³¤Ã×ÎÖʲ¡¤ÄªµÙ¿¨Åû¶ £¬Õâ´Î¹¥»÷²úÉúÓÚ2025Äê12Ôµ× £¬ºÚ¿Í½«Ö¸±êËø¶¨ÔÚ²¨À¼È«¹ú´ó²¿ÃŵØÓò¿ÉÔÙÉúÄÜÔ´ÉèÊ©£¨Ô̺¬Ì«ÑôÄÜ·¢µç³¡Î¢·çÁ¦ÎÐÂÖ»ú£©ÓëµçÁ¦ÅäµçÔËÓªÉÌÖ®¼äµÄͨѶϵͳ £¬ÊÔͼͨ¹ý·ÛË鹨¼üͨѶÁ´Â·Òý·¢´ó¹æÄ£Í£µç ¡£Êý×Ö»¯ÊÂÎñ²¿³¤½üÈÕʲÍзò¡¤¼Ó¶û¿Æ·ò˹»ùÔÚ1ÔÂ13ÈÕµÄÐÂÎŰ䲼»áÉÏÇ¿µ÷ £¬¸ÃÊÂÎñ¡°¼«¶È¿¿½üµ¼ÖÂÈ«¹úÐÔÍ£µç¡± £¬ÇÒ¹¥»÷³öÏÖ¡°Ð­µ÷·ÛËéÐж¯µÄÏÔÖøÌØµã¡± ¡£Ëû½øÒ»²½Ö¸³ö £¬¹¥»÷µÄ¹æÄ£¡¢ÈëÇÖõè¾¶¼°Ä»ºó²ß¶¯¾ùÅú×¢ÕâÊÇÒ»´Î¡°ÐîÒâ¶Â½Ø²¨À¼¹«ÃñµçÁ¦¹©¸øµÄ·ÛËéÐÐΪ¡± £¬²¢Ö±Ö¸¶íÂÞ˹ΪĻºóºÚÊÖ ¡£ÓëÒÔÍùÕë¶Ô´óÐÍ·¢µç³§»òÊäµçÍøÂçµÄÍøÂç¹¥»÷·ÖÆç £¬±¾´ÎÊÂÎñ³õ´Îͬʱ¶Ô×¼¶à¸öÉ¢²¼Ê½Ó×ÐÍÄÜÔ´ÉèÊ© £¬ÕâÖÖÐÂÐ͹¥»÷ģʽÒý·¢²¨À¼¹Ù·½¸ß¶È¾¯Ìè ¡£


https://therecord.media/poland-cyberattack-grid-russia


5. ÕùÒéÍøÕ¾¡°ICEÃûµ¥¡±ÔâDDoS¹¥»÷̱»¾


1ÔÂ15ÈÕ £¬ÃÀ¹úºÓɽ°²È«ÊýÊý¾Ýй¶ÊÂÎñÑÜÉú³öµÄÕùÒéÐÔÍøÕ¾¡°ICEÃûµ¥¡±Òò³ÖÐøDDoS¹¥»÷±»ÆÈÏÂÏß ¡£¸ÃÍøÕ¾ÓÉÊ×´´È˶àÃ×Äá¿Ë¡¤Ë¹½ðÄÉÓÚ½üÈÕй© £¬×ÔÖܶþÍí¼äÆðÔâ·ê¡°ÓƾÃÇÒ¸´ÔÓ¡±µÄÉ¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷ £¬µ¼Ö·þÎñÆ÷̱»¾ £¬Óû§ÎÞ·¨²éÎÊÃÀ¹úÒÆÃñºÍº£¹Ø·¨Âɾ֣¨ICE£©¼°±ßÚïѲÂß¶Ó4500Ãû̽ԱµÄÉí·ÝÐÅÏ¢ ¡£Ë¹½ðÄɰµÊ¾ £¬¹¥»÷Á÷Á¿ÒÉËÆÀ´×Ô¶íÂÞ˹½©Ê¬ÍøÂçÅ©³¡ £¬µ«Í¨¹ý´úÀíIPÄÑÒÔ×·×ÙÕæÊ·´Ô´ ¡£ËûÇ¿µ÷ £¬´ËÀ೤¹¦·ò¡¢¸ß¸´ÔӶȵĹ¥»÷ÐèרҵÍŶӲ߶¯ ¡£Ä¿Ç°ÍŶÓÕý³¢ÊÔ¸ü»»·þÎñÆ÷¸´Ô­ÍøÕ¾ £¬µ«ÈÏ¿ÉÆä½«³ÖÐø³ÉΪ¹¥»÷Ö¸±ê ¡£¸ÃÍøÕ¾³ÉÁ¢ÓÚDHSÄÚ²¿¾Ù±¨ÈËй¶Êý¾ÝÖ®ºó £¬Ô̺¬Ì½Ô±µÄÐÕÃû¡¢¹¤×÷ÓÊÏä¡¢µç»°¡¢Ö°Î»Í·Ïμ°¼òÀúʽ²¼¾°ÐÅÏ¢ ¡£Èô¸´Ô­ÉÏÏß £¬ÕâЩÊý¾Ý½«ÓëÏÖÓÐ2000ÃûÁª¹úÒÆÃñ¹ÙÔ±ÐÅÏ¢¿â¹é²¢ ¡£


https://www.infosecurity-magazine.com/news/ice-agent-doxxing-site-ddosed/


6. Gootloader¶ñÒâÈí¼þÉý¼¶·´¼ì²â¼¼Êõ


1ÔÂ15ÈÕ £¬Gootloader¶ñÒâÈí¼þ×Ô2020ÄêÆð³ÖÐø»îÔ¾ £¬±»ÓÃÓÚÀÕË÷Èí¼þ²¿ÊðµÈÍøÂç·¸×ï»î¶¯ ¡£½üÆÚ £¬×êÑÐÈËÔ±·¢ÏÔìäͨ¹ýÏνÓ500ÖÁ1000¸ö»ûÐÎZIP´æµµÊµÏÖ·´¼ì²âÉý¼¶ £¬ÕâÖֽṹµ¼ÖÂÒÀÀµ7-Zip¡¢WinRARµÈ¹¤¾ßµÄ·ÖÎö·¨Ê½±ÀÀ£ £¬¶øWindowsĬÈϽâѹ¹¤¾ßÈÔ¿É´¦Öà ¡£¸Ã¶ñÒâÈí¼þµÄÖ÷ÌâÊÇÒ»¸ö¹éµµµÄJScriptÎļþ £¬Í¨¹ýWindows Script Host£¨WScript£©Ö´ÐÐ £¬²¢ÀûÓÃÏòÆô¶¯Îļþ¼ÐÔö³¤¿ì½Ý·½Ê½£¨.LNK£©ÊµÏÖÓÆ¾ÃÐÔ £¬ÓÐÐ§ÔØºÉÔÚϵͳÆô¶¯Ê±Í¨¹ýNTFS¶ÌÃû³Æ´¥·¢CScript £¬½ø¶øÌìÉúPowerShell¹ý³Ì ¡£ÎªÌӱܼì²â £¬ÍþвÐÐΪÕßÖ´ÐÐÁ˶à³Á»ìºÏ¼¼Êõ£ºÀûÓýâÎöÆ÷´ÓÎļþĩβ¶ÁÈ¡µÄ¸öÐÔÏνӶà¸öZIPÎļþ £»½Ø¶ÏÖÐÑëĿ¼ʵÏÖ·û£¨EOCD£©¶ÌȱÁ½¸ö±ØÐë×Ö½Ú £¬µ¼Ö´óÎÞÊý¹¤¾ßÎÞ·¨½âÎö £»Ëæ»ú»¯´ÅÅ̱àºÅ×ֶηÂÕÕ²»´æÔڵĶà´ÅÅ̹鵵 £»Ôì×÷±¾µØÎļþÍ·ÓëÖÐÑëĿ¼Ìõ¿î¼äµÄÔªÊý¾Ý²»Æ¥Åä £»ÎªÃ¿´ÎÏÂÔØÌìÉúΨһZIP/JScriptÑù±¾¶ã±Ü¾²Ì¬¼ì²â £»½«ZIP×÷ΪXOR±àÂëµÄblob´«µÝ £¬ÔÚ¿Í»§¶Ë½âÂë²¢×·¼ÓÖÁËùÐè´óÓ×ÒÔ¶ã±ÜÍøÂç¼ì²â ¡£


https://www.bleepingcomputer.com/news/security/gootloader-now-uses-1-000-part-zip-archives-for-stealthy-delivery/