GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý
°ä²¼¹¦·ò 2026-02-031. GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý
2ÔÂ2ÈÕ£¬Ò»ÖÖÐÂÐÍGlassWorm¶ñÒâÈí¼þ¹¥»÷ͨ¹ý±»ÈëÇÖµÄOpenVSXÀ©´ó·¨Ê½£¬×¨ÃÅÕë¶ÔmacOSϵͳÇÔÈ¡ÃÜÂë¡¢¼ÓÃÜÇ®°üÊý¾Ý¡¢¿ª·¢ÕßÍ´´¦¼°ÅäÏàÐÅÏ¢¡£ÍþвÐÐΪÕß»ñÈ¡Á˺Ϸ¨¿ª·¢ÕßoorzcµÄÕË»§È¨ÏÞ£¬ÓÚ1ÔÂ30ÈÕÏòËĸö±»ÏÂÔØ22,000´ÎµÄÀ©´ó·¨Ê½ÍÆËͺ¬GlassWormÓÐÐ§ÔØºÉµÄ¶ñÒâ¸üС£ÕâЩÀ©´ó·¨Ê½´ËǰÁ½Äê¾ùÎÞº¦£¬Åú×¢oorzcÕË»§ÒÑÔâÈëÇÖ¡£¹¥»÷×îÔç³öÏÖÓÚ2025Äê10ÔÂÏÂÑ®£¬ÀûÓá°²»Ë½¼û¡±Unicode×Ö·û°µ²Ø¶ñÒâ´úÂ룬֧³Ö»ùÓÚVNCµÄÔ¶³Ì½Ó¼ûºÍSOCKS´úÀíÖ°ÄÜ¡£GlassWormרÃÅÕë¶ÔmacOSϵͳ£¬¿É´ÓSolanaÂòÂô±¸Íü¼ÌáȡָÁÇÒ¶íÓïϵͳδÊܹ¥»÷£¬°µÊ¾¹¥»÷Õß¿ÉÄÜÀ´×ԷǶíÓïÇø¡£¸Ã¶ñÒâÈí¼þ¼ÓÔØmacOSÐÅÏ¢ÇÔÈ¡·¨Ê½£¬Í¨¹ýLaunchAgent³ÉÁ¢ÓƾÃÐÔ£¬ÔÚÓû§µÇ¼ʱ×Ô¶¯Ö´ÐУ¬ÍøÂçFirefox¡¢Chromiumä¯ÀÀÆ÷Êý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÀûÓá¢macOSÔ¿³×´®¡¢Apple NotesÊý¾Ý¿â¡¢Safari cookie¡¢¿ª·¢ÕßÃÜÔ¿¼°±¾µØÎĵµ£¬²¢½«Ëùº±¼û¾Ýй¶ÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£
https://www.bleepingcomputer.com/news/security/new-glassworm-attack-targets-macos-via-compromised-openvsx-extensions/
2. ShinyHuntersй¶Panera Bread³¬1400ÍòÕË»§Êý¾Ý
2ÔÂ2ÈÕ£¬ShinyHunters·¸×ïÍÅ»ïÐû³ÆÇÔÈ¡ÁËPanera Bread³¬¹ý1400Íò¸öÕË»§µÄÊý¾Ý£¬²¢ÔÚÀÕË÷δ¹ûºó£¬ÓÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªÁËÒ»¸ö760MBµÄÊý¾Ý´æµµ¡£¾ÝHave I Been Pwned£¨HIBP£©±¨Â·£¬Õâ´ÎÐ¹Â¶Éæ¼°510Íò¸öΨһµç×ÓÓʼþµØÖ·¼°¹ØÁªµÄÕË»§ÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØÖ·µÈ¡£Panera BreadËæºó֤ʵй¶Êý¾ÝΪÁªÏµÐÅÏ¢£¬²¢ÒÑ֪ͨÓйز¿ÃÅ¡£BleepingComputer½øÒ»²½È·ÈÏÔ¼512Íò¸öÕË»§Êܵ½Ó°Ï죬µ«ÏÖʵÊÜÓ°ÏìÓû§ÊýÁ¿¿ÉÄܸüÉÙ£¬Òò´æÔÚͳһÓû§Ê¹Óöà¸öÕË»§µÄÇé¿ö¡£ShinyHuntersÍŻﰵʾ£¬Õâ´Î¹¥»÷ÊÇÕë¶Ô100¶à¼Ò»ú¹¹µÄÖØÒªÉí·ÝÌṩÉÌSSOÕË»§ÌáÒéµÄ¸ü´ó¹æÄ£ÍøÂç´¹µö¹¥»÷µÄÒ»²¿ÃÅ£¬ËûÃÇͨ¹ýMicrosoft Entra SSO´úÂë½Ó¼ûÁËPaneraµÄϵͳ¡£Panera×÷ΪÃÀ¹ú³ÛÃûºæ±º¿§·ÈÁ¬Ëøµê£¬³ÉÁ¢ÓÚ1987Ä꣬ӵº±¼ûǧ¼Ò·Öµê£¬×¨Ò»ÓÚ¿ì½ÝÐÝÏвÍÒûģʽ£¬Õâ´ÎÊý¾Ýй¶ÊÂÎñÔÙ´ÎÒý·¢ÁË¶ÔÆäÊý¾Ý°²È«ÖÎÀíµÄ¹Ø×¢¡£
https://securityaffairs.com/187556/data-breach/panera-bread-breach-affected-5-1-million-accounts-hibp-confirms.html
3. ¶íAPT28ÀûÓÃOffice·ì϶¶¨Ïò¹¥»÷ÎÚÅ·
2ÔÂ2ÈÕ£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT-UA£©Åû¶£¬¶íÂÞ˹¹ú¶È¼¶ºÚ¿Í×éÖ¯APT28£¨±ðºÅFancy Bear¡¢Sofacy£¬Óë¶í×ÜÕÕ·÷²¿µý±¨×ܾÖGRU¹ØÁª£©ÕýÀûÓÃ΢ÈíOfficeµÄÁãÈÕ·ì϶CVE-2026-21509ÌáÒé¹¥»÷¡£Î¢ÈíÓÚ2026Äê1ÔÂ26ÈÕ°ä²¼´¹Î£´ø±í°²È«¸üУ¬ÏóÕ÷¸Ã·ì϶Ϊ¡°ÔÚ±»»ý¼«ÀûÓá±µÄÁãÈÕ·ì϶¡£½öÈýÌìºó£¬CERT-UA±ã¼ì²âµ½ÒÔ¡°Å·ÃËפÎÚ¿ËÀ¼³£×¤´ú±íίԱ»áÐÉÌ¡±ÎªÖ÷ÌâµÄ¶ñÒâDOCÎļþ£¬Í¬Ê±·¢ÏÖ¼ÙÒâÎÚ¿ËÀ¼Ë®ÎÄÐÎÏóÖÐÐĵĴ¹µöÓʼþ±»·¢ËÍÖÁ60Óà¸öµ±¾ÖÓйصØÖ·¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÓйضñÒâÎļþµÄÔªÊý¾ÝÏÔʾÆä´´½¨¹¦·òÇ¡ÔÚ΢Èí¸üа䲼ºóÒ»ÈÕ¡£¹¥»÷¼¼ÊõÁ´ÏÔʾ£¬´ò¿ª¶ñÒâÎĵµ»á´¥·¢»ùÓÚWebDAVµÄÏÂÔØÁ´£¬Í¨¹ýCOM½Ù³Ö¡¢¶ñÒâDLL¡¢°µ²ØÔÚͼÏñÎļþÖеÄshellcode¼°´òË㹤×÷×°ÖöñÒâÈí¼þ¡£CERT-UA»ã±¨Ö¸³ö£¬´òË㹤×÷Ö´ÐлᵼÖÂexplorer.exe¹ý³ÌÖÕÖ¹²¢³ÁÆô£¬È·±£¼ÓÔØ¶ñÒâDLL£¬½ø¶ø´ÓͼÏñÎļþÖÐÖ´ÐÐshellcodeÒÔÆô¶¯COVENANT¿ò¼Ü¡£¸Ã¿ò¼Ü´ËÇ°ÔøÔÚ2025Äê6ÔÂAPT28Õë¶ÔÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄ¹¥»÷Öб»Ê¹Óá£
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-recently-patched-microsoft-office-bug-in-attacks/
4. OpenClaw¿ªÔ´AI¸±ÊÖÔâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷
2ÔÂ2ÈÕ£¬¿ªÔ´AI¸±ÊÖOpenClaw£¨Ô³ÆMoltbotºÍClawdBot£©µÄ¹Ù·½×¢²á±íClawHub¼°GitHubƽ̨Ôâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷£¬³¬230¸ö¼Ù×°³ÉºÏ·¨¹¤¾ßµÄ¶ñÒâÈí¼þ°ü±»°ä²¼¡£ÕâЩ±»³Æ×÷"¼¼Êõ"µÄ²å¼þÒÔ¼ÓÃÜÇ®±ÒÂòÂô×Ô¶¯»¯¡¢½ðÈÚ¹¤¾ßµÈºÏ·¨Ö°ÄÜΪ»Ï×Ó£¬ÏÖʵעÈë¶ñÒâÈí¼þÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý£¬Ô̺¬APIÃÜÔ¿¡¢Ç®°ü˽Կ¡¢SSHƾ֤¡¢ä¯ÀÀÆ÷ÃÜÂë¼°.envÎļþµÈ¡£°²È«×êÑÐÔ±Jamieson O'ReillyÖ¸³ö£¬´óÁ¿OpenClawÊ·ýÒòÅäÖò»µ±µ¼ÖÂÖÎÀí½çÃæÂ¶³öÓÚ¹«¹²ÍøÂç¡£¹¥»÷ÕßÀûÓô˷ì϶£¬Í¨¹ýÃûΪ"AuthTool"µÄ¶ñÒâÈí¼þ´«²¼¹¤¾ßÖ´ÐÐϰȾ¡£ÉçÇø°²È«×éÖ¯OpenSourceMalware»ã±¨ÏÔʾ£¬Õâ´Î¹¥»÷³öÏÖ¹æÄ£»¯Ìص㣬´óÁ¿¶ñÒâ¼¼Êõ¿âÃû³Æ¸ß¶ÈÀàËÆ£¬²¿ÃŰ汾ÏÂÔØÁ¿´ïÊýǧ´Î¡£Koi SecurityɨÃèClawHubÈ«Êý2857¸ö¼¼Êõ¿âºó£¬·¢ÏÖ341¸ö¶ñÒâ¼¼Êõ£¬²¢×·×Ùµ½29¸öÕë¶ÔClawHubÓòÃûµÄƴдÃýÎó´¹µöÍøÕ¾¡£ÎªÐÖúÓû§·ÀÓù£¬Koi»¹°ä²¼ÁËÃâ·ÑÔÚÏßɨÃ蹤¾ß£¬¿Éͨ¹ýURL¼ì²â¼¼Êõ°²È«ÐÔ¡£
https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/
5.ÐÂÐÍÍøÂç´¹µöÚ¿ÆÀûÓÃPDF¸½¼þÇÔÈ¡Óû§Æ¾Ö¤
2ÔÂ2ÈÕ£¬ForcepointÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶һÖÖÐÂÐͶà½×¶ÎÍøÂç´¹µöڿƼ¿Á©£¬¸ÃÊÖ·¨Í¨¹ý¾«ÐÄÉè¼ÆµÄ¡°×¨ÒµÓʼþ+PDF¸½¼þ¡±×éºÏÈÆ¹ý´«Í³°²È«¹ýÂË£¬×îÖÕÇÔÈ¡Óû§µÇ¼ƾ֤¡£´ËÀàÚ¿ÆÓʼþͨ³£¼Ù×°³ÉóÒ׺Ïͬ¡¢Õбê»ò²É²É°ìÂôÓйØÍ¨Öª£¬ÄÚÈÝ¿´ËÆÕý¹æÎÞº¦£¬µ«¹Ø¼ü¶ñÒâÐÐΪ°µ²ØÔÚPDF¸½¼þÖС£×êÑÐÏÔʾ£¬Ú¿ÆÕßÀûÓÃPDFµÄAcroFormsºÍFlateDecode¼¼Êõ£¬ÔÚ¿´ËÆÍ¨³£µÄ°ì¹«º¯µµÖÐǶÈë¿Éµã»÷°´Å¥¡£Óû§µã»÷ºó£¬»á±»Êèµ¼ÖÁµÚ¶þ¸öÍйÜÔÚVercel BlobÔÆ´æ´¢Æ½Ì¨ÉϵÄÎĵµ¡£ÓÉÓÚVercelÊǺϷ¨ÔÆ·þÎñ£¬ÕâÖÖ¡°¿ÉÐÅ»ù´¡ÉèÊ©¡±ÀûÓ÷½Ê½ÓÐЧ¶ã±ÜÁ˰²È«Èí¼þµÄÀ¹½Ø¡£Ëæºó£¬¸ÃÔÆÎĵµ»áÌø×ªÖÁαÔìµÄDropboxµÇÂ¼Ò³Ãæ£¬Æä½çÃæÓëÕæÊµÒ³Ãæ¸ß¶ÈÀàËÆ£¬ÓÕµ¼Óû§ÊäÈëÓÊÏä¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£ÔÚºó¶Ü£¬¶ñÒâ¾ç±¾²»½öÇÔÈ¡Óû§Æ¾Ö¤£¬»¹»á¼Í¼¾«È·µÄIPµØÖ·¡¢µØÀíµØÎ»¡¢É豸ÀàÐ͵ÈÀ©´óÐÅÏ¢¡£±»µÁÊý¾Ýͨ¹ýÓ²±àÂ뷽ʽֱ½Ó·¢ËÍÖÁTelegramƽ̨µÄ¸öÈËÆµÂ·£¬ÓɺڿͽÚÔìµÄ»úеÈ˽ӹܡ£
https://hackread.com/phishing-scam-emails-pdfs-steal-dropbox-logins/
6. È«ÇòÔÆ´æ´¢¶©ÔÄÚ¿Æ·ºÀÄ
1ÔÂ31ÈÕ£¬´ÓǰÊýÔ£¬Ò»³¡´ó¹æÄ£ÔÆ´æ´¢¶©ÔÄڿƻÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÊæÕ¹¡£Ú¿Æ·Ö×Óͨ¹ý·¢ËÍ´óÁ¿¿ÖÏÅÓʼþ£¬»Ñ³ÆÓû§Òò¡°Ö§¸¶Ê§°Ü¡±»ò¡°´æ´¢¿Õ¼ä²»¼°¡±µ¼ÖÂÕË»§½«±»¹Ø±Õ¡¢Îļþ½«±»É¾³ý£¬ÒÔ´ËÔì×÷½ôÆÈ¸ÐÓÕµ¼Óû§µã»÷Á´½Ó¡£ÓʼþÖеÄÁ´½Ó¾ùÖ¸Ïò¹È¸èÔÆ´æ´¢·þÎñÍйܵľ²Ì¬³Á¶¨ÏòHTMLÎļþ£¬Óû§µã»÷ºó»á±»Ìø×ªÖÁËæ»úÓòÃûµÄ´¹µöÒ³Ãæ¡£ÕâÐ©Ò³Ãæ¸ß¶È·ÂÕÕÖ÷Á÷ÔÆ·þÎñÉÌ£¨Èç¹È¸èÔÆ¡¢Î¢ÈíOneDrive£©µÄ¹Ù·½½çÃæ£¬Ðû³ÆÓû§´æ´¢¿Õ¼äÒÑÂú£¬ÕÕÆ¬¡¢ÊÓÆµ¡¢ÎĵµµÈÊý¾Ý½«ÖÕ³¡±¸·Ý²¢Ãæ¶Ôɾ³ý·çÏÕ£¬ÓÕµ¼Óû§µã»÷¡°³ÖÐø¡±°´Å¥½øÈëÐéα´æ´¢¼ì²âÒ³Ãæ¡£¸ÃÒ³ÃæÊ¼ÖÕÏÔʾ´æ´¢¿Õ¼äÕ¼Âú£¬ÒªÇóÓû§Éý¼¶ÔÆ´æ´¢ÌײÍÒÔÏíÊÜ¡°ÀÏÓû§×¨Êô8ÕÛÓŻݡ±£¬µ«ÏÖʵµã»÷Éý¼¶°´Å¥ºó£¬Óû§»á±»³Á¶¨ÏòÖÁͬÃËÓªÏúÒ³Ãæ£¬ÍƹãVPN·þÎñ¡¢Ó׶లȫÈí¼þµÈÎ޹زúÆ·£¬×îÖÕÌø×ªÖÁ½áÕË±íµ¥ÍøÂçÓû§ÐÅÓþ¿¨ÐÅÏ¢£¬Í¬Ê±ÎªÚ¿Æ·Ö×Ó׬ȡͬÃËÓªÏúÓ¶½ð¡£
https://www.bleepingcomputer.com/news/security/cloud-storage-payment-scam-floods-inboxes-with-fake-renewals/


¾©¹«Íø°²±¸11010802024551ºÅ