GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý

°ä²¼¹¦·ò 2026-02-03

1. GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý


2ÔÂ2ÈÕ  £¬Ò»ÖÖÐÂÐÍGlassWorm¶ñÒâÈí¼þ¹¥»÷ͨ¹ý±»ÈëÇÖµÄOpenVSXÀ©´ó·¨Ê½  £¬×¨ÃÅÕë¶ÔmacOSϵͳÇÔÈ¡ÃÜÂë¡¢¼ÓÃÜÇ®°üÊý¾Ý¡¢¿ª·¢ÕßÍ´´¦¼°ÅäÏàÐÅÏ¢ ¡£ÍþвÐÐΪÕß»ñÈ¡Á˺Ϸ¨¿ª·¢ÕßoorzcµÄÕË»§È¨ÏÞ  £¬ÓÚ1ÔÂ30ÈÕÏòËĸö±»ÏÂÔØ22,000´ÎµÄÀ©´ó·¨Ê½ÍÆËͺ¬GlassWormÓÐÐ§ÔØºÉµÄ¶ñÒâ¸üР¡£ÕâЩÀ©´ó·¨Ê½´ËǰÁ½Äê¾ùÎÞº¦  £¬Åú×¢oorzcÕË»§ÒÑÔâÈëÇÖ ¡£¹¥»÷×îÔç³öÏÖÓÚ2025Äê10ÔÂÏÂÑ®  £¬ÀûÓá°²»Ë½¼û¡±Unicode×Ö·û°µ²Ø¶ñÒâ´úÂë  £¬Ö§³Ö»ùÓÚVNCµÄÔ¶³Ì½Ó¼ûºÍSOCKS´úÀíÖ°ÄÜ ¡£GlassWormרÃÅÕë¶ÔmacOSϵͳ  £¬¿É´ÓSolanaÂòÂô±¸Íü¼ÌáȡָÁî  £¬ÇÒ¶íÓïϵͳδÊܹ¥»÷  £¬°µÊ¾¹¥»÷Õß¿ÉÄÜÀ´×ԷǶíÓïÇø ¡£¸Ã¶ñÒâÈí¼þ¼ÓÔØmacOSÐÅÏ¢ÇÔÈ¡·¨Ê½  £¬Í¨¹ýLaunchAgent³ÉÁ¢ÓƾÃÐÔ  £¬ÔÚÓû§µÇ¼ʱ×Ô¶¯Ö´ÐÐ  £¬ÍøÂçFirefox¡¢Chromiumä¯ÀÀÆ÷Êý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÀûÓá¢macOSÔ¿³×´®¡¢Apple NotesÊý¾Ý¿â¡¢Safari cookie¡¢¿ª·¢ÕßÃÜÔ¿¼°±¾µØÎĵµ  £¬²¢½«Ëùº±¼û¾Ýй¶ÖÁ¹¥»÷ÕߵķþÎñÆ÷ ¡£


https://www.bleepingcomputer.com/news/security/new-glassworm-attack-targets-macos-via-compromised-openvsx-extensions/


2. ShinyHuntersй¶Panera Bread³¬1400ÍòÕË»§Êý¾Ý


2ÔÂ2ÈÕ  £¬ShinyHunters·¸×ïÍÅ»ïÐû³ÆÇÔÈ¡ÁËPanera Bread³¬¹ý1400Íò¸öÕË»§µÄÊý¾Ý  £¬²¢ÔÚÀÕË÷δ¹ûºó  £¬ÓÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªÁËÒ»¸ö760MBµÄÊý¾Ý´æµµ ¡£¾ÝHave I Been Pwned£¨HIBP£©±¨Â·  £¬Õâ´ÎÐ¹Â¶Éæ¼°510Íò¸öΨһµç×ÓÓʼþµØÖ·¼°¹ØÁªµÄÕË»§ÐÅÏ¢  £¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØÖ·µÈ ¡£Panera BreadËæºó֤ʵй¶Êý¾ÝΪÁªÏµÐÅÏ¢  £¬²¢ÒÑ֪ͨÓйز¿ÃÅ ¡£BleepingComputer½øÒ»²½È·ÈÏÔ¼512Íò¸öÕË»§Êܵ½Ó°Ïì  £¬µ«ÏÖʵÊÜÓ°ÏìÓû§ÊýÁ¿¿ÉÄܸüÉÙ  £¬Òò´æÔÚͳһÓû§Ê¹Óöà¸öÕË»§µÄÇé¿ö ¡£ShinyHuntersÍŻﰵʾ  £¬Õâ´Î¹¥»÷ÊÇÕë¶Ô100¶à¼Ò»ú¹¹µÄÖØÒªÉí·ÝÌṩÉÌSSOÕË»§ÌáÒéµÄ¸ü´ó¹æÄ£ÍøÂç´¹µö¹¥»÷µÄÒ»²¿ÃÅ  £¬ËûÃÇͨ¹ýMicrosoft Entra SSO´úÂë½Ó¼ûÁËPaneraµÄϵͳ ¡£Panera×÷ΪÃÀ¹ú³ÛÃûºæ±º¿§·ÈÁ¬Ëøµê  £¬³ÉÁ¢ÓÚ1987Äê  £¬Óµº±¼ûǧ¼Ò·Öµê  £¬×¨Ò»ÓÚ¿ì½ÝÐÝÏвÍÒûģʽ  £¬Õâ´ÎÊý¾Ýй¶ÊÂÎñÔÙ´ÎÒý·¢ÁË¶ÔÆäÊý¾Ý°²È«ÖÎÀíµÄ¹Ø×¢ ¡£


https://securityaffairs.com/187556/data-breach/panera-bread-breach-affected-5-1-million-accounts-hibp-confirms.html


3. ¶íAPT28ÀûÓÃOffice·ì϶¶¨Ïò¹¥»÷ÎÚÅ·


2ÔÂ2ÈÕ  £¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT-UA£©Åû¶  £¬¶íÂÞ˹¹ú¶È¼¶ºÚ¿Í×éÖ¯APT28£¨±ðºÅFancy Bear¡¢Sofacy  £¬Óë¶í×ÜÕÕ·÷²¿µý±¨×ܾÖGRU¹ØÁª£©ÕýÀûÓÃ΢ÈíOfficeµÄÁãÈÕ·ì϶CVE-2026-21509ÌáÒé¹¥»÷ ¡£Î¢ÈíÓÚ2026Äê1ÔÂ26ÈÕ°ä²¼´¹Î£´ø±í°²È«¸üР £¬ÏóÕ÷¸Ã·ì϶Ϊ¡°ÔÚ±»»ý¼«ÀûÓá±µÄÁãÈÕ·ì϶ ¡£½öÈýÌìºó  £¬CERT-UA±ã¼ì²âµ½ÒÔ¡°Å·ÃËפÎÚ¿ËÀ¼³£×¤´ú±íίԱ»áЭÉÌ¡±ÎªÖ÷ÌâµÄ¶ñÒâDOCÎļþ  £¬Í¬Ê±·¢ÏÖ¼ÙÒâÎÚ¿ËÀ¼Ë®ÎÄÐÎÏóÖÐÐĵĴ¹µöÓʼþ±»·¢ËÍÖÁ60Óà¸öµ±¾ÖÓйصØÖ· ¡£ÖµÍ×ÌùÐĵÄÊÇ  £¬ÓйضñÒâÎļþµÄÔªÊý¾ÝÏÔʾÆä´´½¨¹¦·òÇ¡ÔÚ΢Èí¸üа䲼ºóÒ»ÈÕ ¡£¹¥»÷¼¼ÊõÁ´ÏÔʾ  £¬´ò¿ª¶ñÒâÎĵµ»á´¥·¢»ùÓÚWebDAVµÄÏÂÔØÁ´  £¬Í¨¹ýCOM½Ù³Ö¡¢¶ñÒâDLL¡¢°µ²ØÔÚͼÏñÎļþÖеÄshellcode¼°´òË㹤×÷×°ÖöñÒâÈí¼þ ¡£CERT-UA»ã±¨Ö¸³ö  £¬´òË㹤×÷Ö´ÐлᵼÖÂexplorer.exe¹ý³ÌÖÕÖ¹²¢³ÁÆô  £¬È·±£¼ÓÔØ¶ñÒâDLL  £¬½ø¶ø´ÓͼÏñÎļþÖÐÖ´ÐÐshellcodeÒÔÆô¶¯COVENANT¿ò¼Ü ¡£¸Ã¿ò¼Ü´ËÇ°ÔøÔÚ2025Äê6ÔÂAPT28Õë¶ÔÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄ¹¥»÷Öб»Ê¹Óà ¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-recently-patched-microsoft-office-bug-in-attacks/


4. OpenClaw¿ªÔ´AI¸±ÊÖÔâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷


2ÔÂ2ÈÕ  £¬¿ªÔ´AI¸±ÊÖOpenClaw£¨Ô­³ÆMoltbotºÍClawdBot£©µÄ¹Ù·½×¢²á±íClawHub¼°GitHubƽ̨Ôâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷  £¬³¬230¸ö¼Ù×°³ÉºÏ·¨¹¤¾ßµÄ¶ñÒâÈí¼þ°ü±»°ä²¼ ¡£ÕâЩ±»³Æ×÷"¼¼Êõ"µÄ²å¼þÒÔ¼ÓÃÜÇ®±ÒÂòÂô×Ô¶¯»¯¡¢½ðÈÚ¹¤¾ßµÈºÏ·¨Ö°ÄÜΪ»Ï×Ó  £¬ÏÖʵעÈë¶ñÒâÈí¼þÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý  £¬Ô̺¬APIÃÜÔ¿¡¢Ç®°ü˽Կ¡¢SSHƾ֤¡¢ä¯ÀÀÆ÷ÃÜÂë¼°.envÎļþµÈ ¡£°²È«×êÑÐÔ±Jamieson O'ReillyÖ¸³ö  £¬´óÁ¿OpenClawÊ·ýÒòÅäÖò»µ±µ¼ÖÂÖÎÀí½çÃæÂ¶³öÓÚ¹«¹²ÍøÂç ¡£¹¥»÷ÕßÀûÓô˷ì϶  £¬Í¨¹ýÃûΪ"AuthTool"µÄ¶ñÒâÈí¼þ´«²¼¹¤¾ßÖ´ÐÐϰȾ ¡£ÉçÇø°²È«×éÖ¯OpenSourceMalware»ã±¨ÏÔʾ  £¬Õâ´Î¹¥»÷³öÏÖ¹æÄ £»¯Ìصã  £¬´óÁ¿¶ñÒâ¼¼Êõ¿âÃû³Æ¸ß¶ÈÀàËÆ  £¬²¿ÃŰ汾ÏÂÔØÁ¿´ïÊýǧ´Î ¡£Koi SecurityɨÃèClawHubÈ«Êý2857¸ö¼¼Êõ¿âºó  £¬·¢ÏÖ341¸ö¶ñÒâ¼¼Êõ  £¬²¢×·×Ùµ½29¸öÕë¶ÔClawHubÓòÃûµÄƴдÃýÎó´¹µöÍøÕ¾ ¡£ÎªÐ­ÖúÓû§·ÀÓù  £¬Koi»¹°ä²¼ÁËÃâ·ÑÔÚÏßɨÃ蹤¾ß  £¬¿Éͨ¹ýURL¼ì²â¼¼Êõ°²È«ÐÔ ¡£


https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/


5.ÐÂÐÍÍøÂç´¹µöÚ¿Æ­ÀûÓÃPDF¸½¼þÇÔÈ¡Óû§Æ¾Ö¤


2ÔÂ2ÈÕ  £¬ForcepointÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶һÖÖÐÂÐͶà½×¶ÎÍøÂç´¹µöÚ¿Æ­¼¿Á©  £¬¸ÃÊÖ·¨Í¨¹ý¾«ÐÄÉè¼ÆµÄ¡°×¨ÒµÓʼþ+PDF¸½¼þ¡±×éºÏÈÆ¹ý´«Í³°²È«¹ýÂË  £¬×îÖÕÇÔÈ¡Óû§µÇ¼ƾ֤ ¡£´ËÀàÚ¿Æ­Óʼþͨ³£¼Ù×°³ÉóÒ׺Ïͬ¡¢Õбê»ò²É²É°ìÂôÓйØÍ¨Öª  £¬ÄÚÈÝ¿´ËÆÕý¹æÎÞº¦  £¬µ«¹Ø¼ü¶ñÒâÐÐΪ°µ²ØÔÚPDF¸½¼þÖÐ ¡£×êÑÐÏÔʾ  £¬Ú¿Æ­ÕßÀûÓÃPDFµÄAcroFormsºÍFlateDecode¼¼Êõ  £¬ÔÚ¿´ËÆÍ¨³£µÄ°ì¹«º¯µµÖÐǶÈë¿Éµã»÷°´Å¥ ¡£Óû§µã»÷ºó  £¬»á±»Êèµ¼ÖÁµÚ¶þ¸öÍйÜÔÚVercel BlobÔÆ´æ´¢Æ½Ì¨ÉϵÄÎĵµ ¡£ÓÉÓÚVercelÊǺϷ¨ÔÆ·þÎñ  £¬ÕâÖÖ¡°¿ÉÐÅ»ù´¡ÉèÊ©¡±ÀûÓ÷½Ê½ÓÐЧ¶ã±ÜÁ˰²È«Èí¼þµÄÀ¹½Ø ¡£Ëæºó  £¬¸ÃÔÆÎĵµ»áÌø×ªÖÁαÔìµÄDropboxµÇÂ¼Ò³Ãæ  £¬Æä½çÃæÓëÕæÊµÒ³Ãæ¸ß¶ÈÀàËÆ  £¬ÓÕµ¼Óû§ÊäÈëÓÊÏä¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢ ¡£ÔÚºó¶Ü  £¬¶ñÒâ¾ç±¾²»½öÇÔÈ¡Óû§Æ¾Ö¤  £¬»¹»á¼Í¼¾«È·µÄIPµØÖ·¡¢µØÀíµØÎ»¡¢É豸ÀàÐ͵ÈÀ©´óÐÅÏ¢ ¡£±»µÁÊý¾Ýͨ¹ýÓ²±àÂ뷽ʽֱ½Ó·¢ËÍÖÁTelegramƽ̨µÄ¸öÈËÆµÂ·  £¬ÓɺڿͽÚÔìµÄ»úеÈË½Ó¹Ü ¡£


https://hackread.com/phishing-scam-emails-pdfs-steal-dropbox-logins/


6. È«ÇòÔÆ´æ´¢¶©ÔÄÚ¿Æ­·ºÀÄ


1ÔÂ31ÈÕ  £¬´ÓǰÊýÔ  £¬Ò»³¡´ó¹æÄ£ÔÆ´æ´¢¶©ÔÄÚ¿Æ­»î¶¯ÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÊæÕ¹ ¡£Ú¿Æ­·Ö×Óͨ¹ý·¢ËÍ´óÁ¿¿ÖÏÅÓʼþ  £¬»Ñ³ÆÓû§Òò¡°Ö§¸¶Ê§°Ü¡±»ò¡°´æ´¢¿Õ¼ä²»¼°¡±µ¼ÖÂÕË»§½«±»¹Ø±Õ¡¢Îļþ½«±»É¾³ý  £¬ÒÔ´ËÔì×÷½ôÆÈ¸ÐÓÕµ¼Óû§µã»÷Á´½Ó ¡£ÓʼþÖеÄÁ´½Ó¾ùÖ¸Ïò¹È¸èÔÆ´æ´¢·þÎñÍйܵľ²Ì¬³Á¶¨ÏòHTMLÎļþ  £¬Óû§µã»÷ºó»á±»Ìø×ªÖÁËæ»úÓòÃûµÄ´¹µöÒ³Ãæ ¡£ÕâÐ©Ò³Ãæ¸ß¶È·ÂÕÕÖ÷Á÷ÔÆ·þÎñÉÌ£¨Èç¹È¸èÔÆ¡¢Î¢ÈíOneDrive£©µÄ¹Ù·½½çÃæ  £¬Ðû³ÆÓû§´æ´¢¿Õ¼äÒÑÂú  £¬ÕÕÆ¬¡¢ÊÓÆµ¡¢ÎĵµµÈÊý¾Ý½«ÖÕ³¡±¸·Ý²¢Ãæ¶Ôɾ³ý·çÏÕ  £¬ÓÕµ¼Óû§µã»÷¡°³ÖÐø¡±°´Å¥½øÈëÐéα´æ´¢¼ì²âÒ³Ãæ ¡£¸ÃÒ³ÃæÊ¼ÖÕÏÔʾ´æ´¢¿Õ¼äÕ¼Âú  £¬ÒªÇóÓû§Éý¼¶ÔÆ´æ´¢ÌײÍÒÔÏíÊÜ¡°ÀÏÓû§×¨Êô8ÕÛÓŻݡ±  £¬µ«ÏÖʵµã»÷Éý¼¶°´Å¥ºó  £¬Óû§»á±»³Á¶¨ÏòÖÁͬÃËÓªÏúÒ³Ãæ  £¬ÍƹãVPN·þÎñ¡¢Ó׶లȫÈí¼þµÈÎ޹زúÆ·  £¬×îÖÕÌø×ªÖÁ½áÕË±íµ¥ÍøÂçÓû§ÐÅÓþ¿¨ÐÅÏ¢  £¬Í¬Ê±ÎªÚ¿Æ­·Ö×Ó׬ȡͬÃËÓªÏúÓ¶½ð ¡£


https://www.bleepingcomputer.com/news/security/cloud-storage-payment-scam-floods-inboxes-with-fake-renewals/