µÂ¿ËÈøË¹ÖÝÂÉʦЭ»áÔâINCÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶

°ä²¼¹¦·ò 2025-04-08

1. µÂ¿ËÈøË¹ÖÝÂÉʦЭ»áÔâINCÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶


4ÔÂ3ÈÕ£¬£¬ÃÀ¹úµÚ¶þ´óÂÉʦЭ»á¡ª¡ªµÂ¿ËÈøË¹ÖÝÂÉʦЭ»áÔâ·êÖØ´óÊý¾Ýй¶ÊÂÎñ£¬£¬²¨¼°³¬10ÍòÃûÖ´ÒµÂÉʦ¡£¡£¸ÃЭ»á³Ðµ£Ö´ÒµÐí¿É¼à¹Ü¡¢³ÖÐø½ÌÓýÖÎÀí¡¢Ö°ÒµµÀµÂ¼à¶½µÈÖ÷ÌâÖ°ÄÜ£¬£¬ÆäÍøÂçϵͳÓÚ2025Äê1ÔÂ28ÈÕÖÁ2ÔÂ9ÈÕ¼äÔâδ¾­ÊÚȨ½Ó¼û£¬£¬µ«Ö±ÖÁ2ÔÂ12ÈÕ·½±»¾õ²ì¡£¡£Æ¾¾ÝЭ»áÏòÊÜÓ°Ïì³ÉÔ±°ä²¼µÄ֪ͨ£¬£¬¹¥»÷ÕßÇÔÈ¡ÁËÔ̺¬È«ÃûµÄÃô¸ÐÐÅÏ¢£¬£¬¾ßÌåй¶ÁìÓòÉÐδÃ÷È·¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬INCÀÕË÷Èí¼þÍŻ﹫¿ªÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬²¢ÓÚ3ÔÂ9ÈÕ½«¸ÃЭ»áÁÐÈë°µÍøÀÕË÷Ãûµ¥£¬£¬Í¬Ê±Åû¶Á˲¿ÃžݳÆÎªË¾·¨°¸¼þÎļþµÄ±»µÁÊý¾ÝÑù±¾¡£¡£Ð­»áÒѲÉȡӦ¶Ô´ëÊ©£¬£¬ÎªÊÜÓ°Ïì³ÉÔ±ÌṩÓÐЧÆÚÖÁ7ÔÂ31ÈÕµÄÃâ·ÑÐÅÓþ¼°Éí·Ý͵ÇÔ¼à¿Ø·þÎñ£¨ÓÉExperianÌṩ֧³Ö£©£¬£¬²¢½¨Òé³ÉԱͨ¹ý¼¤»îÂë×¢²á¸Ã·þÎñ¡£¡£´ËÍ⣬£¬Ð­»áÇ¿ÁÒ½¨Òé³ÉԱ˼¿¼Æô¶¯ÐÅÓþ¶³½á»òÔÚÐÅÓþµµ°¸ÖÐÉèÖÃڲƭ¾¯±¨£¬£¬ÒÔ×î´óÏ޶ȽµµÍDZÔÚ·çÏÕ¡£¡£


https://www.bleepingcomputer.com/news/security/texas-state-bar-warns-of-data-breach-after-inc-ransomware-claims-attack/


2. EverestÀÕË÷Èí¼þÍÅ»ï°µÍøÐ¹ÃÜÍøÕ¾Ôâδ֪¹¥»÷ÏÂÏß


4ÔÂ7ÈÕ£¬£¬½üÈÕ£¬£¬Everest ÀÕË÷Èí¼þÍÅ»ïµÄ°µÍøÐ¹ÃÜÍøÕ¾Ôâ·êδ֪¹¥»÷ÕßÏ®»÷£¬£¬Ä¿Ç°ÒÑÏÂÏß¡£¡£¹¥»÷Õß½«ÍøÕ¾ÄÚÈÝ´úÌæÎª³°·íÐÅÏ¢ £º¡°²»Òª·¸×£¬·¸×ïÊÇ»µÊ£¬£¬À´×Ô²¼À­¸ñ¡£¡£¡±Ä¿Ç°£¬£¬¸ÃÍøÕ¾ÏÔʾ¡°Î´ÕÒµ½Ñó´ÐÍøÕ¾¡±ÃýÎ󣬣¬ÎÞ·¨¼ÓÔØ¡£¡£Ö»¹Ü¹¥»÷ÕßÈôºÎ½øÈëÍøÕ¾»òÍøÕ¾ÊÇ·ñ±»ºÚ¿Í¹¥»÷Éв»Ã÷È·£¬£¬µ«°²È«×¨¼ÒÖ¸³ö£¬£¬Everest ʹÓÃµÄ WordPress Ä£°å¿ÉÄÜ´æÔÚDZÔÚ·ì϶£¬£¬¸Ã·ì϶»ò±»ÀûÓÃÀ´·ÛËéÀÕË÷Èí¼þ²Ù×÷µÄÐ¹Â©ÍøÕ¾¡£¡£×Ô 2020 Äê³öÏÖÒÔÀ´£¬£¬Everest ÀÕË÷Èí¼þÐж¯Õ½ÊõÒѲúÉú±ä¶¯£¬£¬´Ó½öÇÔÈ¡Êý¾Ý¡¢ÀÕË÷Æóҵת±äΪÔÚ¹¥»÷ÖвÎÓëÀÕË÷Èí¼þ£¬£¬¼ÓÃÜÊܺ¦Õßϵͳ¡£¡£´ËÍ⣬£¬Everest ÔËÓªÉÌ»¹Òò³äÈÎÆäËûÍøÂç·¸×ïÍÅ»ïºÍÍþвÐÐΪÕߵijõʼ½Ó¼ûȨÏÞ¾­¼ÍÈ˶øÎÅÃû£¬£¬ÏúÊÛ±»¹¥ÆÆµÄ¹«Ë¾ÍøÂç½Ó¼ûȨÏÞ¡£¡£ÔÚ´Óǰ 5 ÄêÖУ¬£¬Everest µÄ°µÍøÐ¹ÃÜÍøÕ¾Ôö³¤ÁË 230 ¶àÃûÊܺ¦Õߣ¬£¬³ÉÎªË«ÖØÀÕË÷¹¥»÷µÄÒ»²¿ÃÅ£¬£¬ÀÕË÷Èí¼þÍÅ»ïÊÔͼÒÔ°ä²¼Ãô¸ÐÐÅϢΪÍþв£¬£¬ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£


https://www.bleepingcomputer.com/news/security/everest-ransomwares-dark-web-leak-site-defaced-now-offline/


3. VSCode¶ñÒâÀ©´óʾÉí΢ÈíÊг¡£¬£¬½èXMRigÍÚ¿óIJÀû


4ÔÂ7ÈÕ£¬£¬½üÈÕ£¬£¬ExtensionTotal×êÑÐÔ±Yuval Ronen·¢ÏÖ£¬£¬2025Äê4ÔÂ4ÈÕ£¬£¬Î¢ÈíÃÅ»§ÉÏÇÄÈ»°ä²¼Á˾Ÿö¼Ù×°³ÉºÏ·¨¿ª·¢¹¤¾ßµÄVSCodeÀ©´ó¡£¡£ÕâЩÀ©´óÒÔ¡°Discord Rich Presence for VS Code¡±¡°Rojo ¨C Roblox Studio Sync¡±µÈÃû³ÆÊ¾ÈË£¬£¬×°ÖÃÁ¿³¬30Íò´Î£¬£¬µ«Êý×Ö¿ÉÄܱ»±¨´ð¿ä´ó£¬£¬Ö¼ÔÚÓªÔìºÏ·¨¼ÙÏ󡣡£Ò»µ©×°Öü¤»î£¬£¬ÕâЩ¶ñÒâÀ©´ó±ã´ÓÍⲿԴ»ñÈ¡²¢Ö´ÐÐPowerShell¾ç±¾£¬£¬Í¬Ê±×°ÖÃÆä·ÂÕյĺϷ¨À©´óÒÔÑÚÈ˶úÄ¿¡£¡£¶ñÒâÈí¼þ»á´´½¨¼Ù×°³É¡°OnedriveStartup¡±µÄ´òË㹤×÷£¬£¬²¢ÔÚWindows×¢²á±íÖÐ×¢Èë¾ç±¾£¬£¬È·±£ÏµÍ³Æô¶¯Ê±×Ô¶¯ÔËÐС£¡£Ëü»¹»á¹Ø±Õ¹Ø¼üWindows·þÎñ£¬£¬ÈçWindows Update£¬£¬²¢½«×ÔÉíÔö³¤µ½Windows DefenderµÄÅųýÁбíÖУ¬£¬ÒÔÌӱܼì²â¡£¡£ÈôδÒÔÖÎÀíԱȨÏÞÖ´ÐУ¬£¬¶ñÒâÈí¼þ»á·ÂÕÕϵͳ¶þ½øÖÆÎļþ£¬£¬Ê¹ÓöñÒâMLANG.dllÖ´ÐÐDLL½Ù³Ö£¬£¬ÌáÉýȨÏÞ²¢Ö´ÐÐÓÐЧ¸ºÔØ¡£¡£¸Ã¿ÉÖ´ÐÐÎļþѡȡbase64±àÂëÌåʽ£¬£¬ÓÉPowerShell¾ç±¾½âÂëºóÏνӵ½¸¨Öú·þÎñÆ÷£¬£¬ÏÂÔØ²¢ÔËÐÐXMRig¼ÓÃÜÇ®±Ò¿ó¹¤¡£¡£Ä¿Ç°£¬£¬Ö»¹ÜExtensionTotalÒÑÏò΢Èí»ã±¨ÕâЩ¶ñÒâÀ©´ó£¬£¬µ«ËüÃÇÈÔ¿ÉÓᣡ£


https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/


4. ºÚ¿Í¼ÙÒâÎÚ»ú¹¹·¢Æð¹¥»÷£¬£¬ÇÔÃܶñÒâÈí¼þÍþв¼Ó¾ç


4ÔÂ8ÈÕ£¬£¬Æ¾¾Ýµ±¾Ö×îÐÂ×êÑУ¬£¬ºÚ¿ÍÕýÀûÓÃÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¶ÔÎÚ¿ËÀ¼¹Ø¼ü²¿ÃÅ·¢Æð¹¥»÷¡£¡£×Ô2ÔÂÒÔÀ´£¬£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìӦС×飨CERT-UA£©Ò»ÏòÔÚ×·×ÙÕâÒ»»î¶¯£¬£¬ÆäÄ»ºóÍþвÕß±»×·×ÙΪUAC-0226£¬£¬µ«ÉÐδ¹é×ïÓÚÈκÎÒÑÖªºÚ¿Í×éÖ¯¡£¡ £ºÚ¿Í´Ó±»ÈëÇÖµÄÕË»§·¢ËÍ´øÓжñÒâÎĵµ¸½¼þµÄµç×ÓÓʼþ£¬£¬ÎļþÃû»òÖ÷ÌâÐÐÉæ¼°µØÀ׶ϸù¡¢ÐÐÕþ·£¿£¿£¿î¡¢ÎÞÈË»ú³ö²ú»ò²Æ¸»ËðʧÅâ³¥µÈ»°Ì⣬£¬ÒÔϰȾÎÚ¿ËÀ¼Îä×°¶ÓÁС¢·¨ÂÉ»ú¹¹ºÍ´¦Ëùµ±¾Ö»ú¹¹µÈÖ¸±ê¡£¡£½ØÖÁ4Ô£¬£¬ºÚ¿ÍÒѲ¿ÊðÁ½ÖÖ¶ñÒâÈí¼þ£¬£¬Ò»ÖÖ»ùÓÚGitHub¹«¿ª´úÂ룬£¬ÁíÒ»ÖÖÃûΪGiftedCrook£¬£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷Êý¾Ý²¢·¢Ë͵½Telegramй¶¡£¡£´ËÍ⣬£¬3Ô·ݻ¹·¢ÏÖÁËÖÁÉÙÈýÆðÀûÓÃÐÂÐͼäµý¶ñÒâÈí¼þWrecksteelµÄÍøÂç¹¥»÷£¬£¬ºÚ¿Íͨ¹ý±»µÁÕË»§·¢ËÍÔ̺¬¹«¹²Îļþ¹²Ïí·þÎñÁ´½ÓµÄÐÂÎÅ£¬£¬Ö´ÐÐPowerShell¾ç±¾ºó£¬£¬¿ÉÌáÈ¡¶àÖÖÎļþ²¢½ØÈ¡ÆÁÄ»½ØÍ¼¡£¡£CERT-UAÌṩÁËÍøÂç´¹µöµç×ÓÓʼþʾÀý£¬£¬ÒÔ¾¯Ê¾¹«¼Ò°ÑÎÈ´ËÀ๥»÷¡£¡£


https://therecord.media/hackers-impersonate-drone-companies-state-agencies-spy-ukraine


5. WK Kellogg CoÔâClopÀûÓÃCleo·ì϶ִÐÐÊý¾Ý͵ÇÔ¹¥»÷


4ÔÂ7ÈÕ£¬£¬ÃÀ¹úʳƷ¾ÞÍ·WK Kellogg Co½üÈÕÖÒ¸æÔ±¹¤ºÍ¹©¸øÉÌ£¬£¬¹«Ë¾Êý¾ÝÔÚ2024ÄêCleoÊý¾Ý͵ÇÔ¹¥»÷ÖÐÔâÇÔÈ¡¡£¡£CleoÈí¼þÊÇÒ»¿îÍйÜÎļþ´«ÊäʵÓ÷¨Ê½£¬£¬È¥ÄêÄêµ×£¬£¬ClopÀÕË÷Èí¼þÍÅ»ïÀûÓÃÁ½¸öÁãÈÕ·ì϶CVE-2024-50623ºÍCVE-2024-55956£¬£¬¼¯Ìå¹¥»÷Á˸ÃÈí¼þ£¬£¬Ê¹ÍþвÐÐΪÕß¿ÉÄÜÈëÇÖ·þÎñÆ÷²¢ÇÔÈ¡Êý¾Ý¡£¡£WK KelloggÓÚ2025Äê2ÔÂ27ÈÕ»ñϤ´ËÊ£¬£¬²¢Á¢¼´·¢Õ¹µ÷²é¡£¡£¾­ÁªÏµCleoºóµÃÖª£¬£¬Ò»Ãûδ¾­ÊÚȨµÄÈËÓÚ2024Äê12ÔÂ7ÈÕ½Ó¼ûÁËCleoΪWK KelloggÍйܵķþÎñÆ÷¡£¡£Ö»¹ÜWK Kelloggδ¾ßÌåÌá¼°Clop»òÊý¾Ý͵ÇÔ¹¥»÷£¬£¬µ«»ã±¨ÊÂÎñµÄÈÕÆÚÓë2024Äê12Ô²úÉúµÄÒ»²¨¹¥»÷ÏàÎǺÏ¡£¡£´ËÍ⣬£¬ClopÀÕË÷Èí¼þÍÅ»ïÔÚ½«WK KelloggÁÐÈëÆäÊý¾ÝÐÂäįÕË÷ÍøÕ¾ºó²»¾Ã£¬£¬¾Í°ä²¼ÁËÎ¥¹æÍ¨Öª¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Ð¡ÎÒµÄÐÕÃûºÍÉç»á±£Ïպ𣡣WK KelloggÒÑÓëCleoÇ×êǺÏ×÷£¬£¬È·¶¨ÁËΪ½â¾öÎ¥¹æÐÐΪ²¢Ô¤·À½«À´²úÉúÀàËÆÊÂÎñ¶øÖ´Ðеݲȫ´ëÊ©¡£¡£Õâ´ÎÊÂÎñʹWK Kellogg³ÉΪÊܵ½ClopµÄCleoÁãÈÕ¹¥»÷Ó°ÏìµÄÖڶ๫˾ÖеÄ×îÐÂÊܺ¦Õß¡£¡£


https://www.bleepingcomputer.com/news/security/food-giant-wk-kellogg-discloses-data-breach-linked-to-clop-ransomware/


6. ÐÂÐÍNeptune RAT±äÖÖÍþв¼Ó¾ç£¬£¬ÇÔÃÜÓë·ÛËéÄÜÁ¦Éý¼¶


4ÔÂ7ÈÕ£¬£¬½üÈÕ£¬£¬Ò»ÖÖеÄNeptune RAT±äÖÖͨ¹ýYouTubeºÍTelegramµÈÉ罻ƽ̨¿í·º´«²¼£¬£¬¶ÔWindowsÓû§×é³ÉÑÏÖØÍþв¡£¡£¸Ã¶ñÒâÈí¼þËäÐû³ÆÓÃÓÚ¡°½ÌÓýºÍµÀµÂÖ÷ÕÅ¡±£¬£¬µ«ÏÖʵְÄÜÈ´Ô¶·ÇÈç´Ë¡£¡£Neptune RAT¿ÉÄÜÇÔÈ¡Óû§Æ¾Ö¤¡¢´úÌæ¼ÓÃÜÇ®±ÒÇ®°üµØÖ·£¬£¬ÉõÖÁʹÓÃÀÕË÷Èí¼þÖ°ÄÜËø¶¨Îļþ£¬£¬Ê¹¹¥»÷Õß¿ÉÄÜÈ«Ãæ½ÚÖÆÊÜϰȾµÄϵͳ¡£¡£¸Ã¶ñÒâÈí¼þÔÚÉ罻ƽ̨ÉÏÃâ·Ñ·Ö·¢£¬£¬°µ²ØÁË¿ÉÖ´ÐÐÎļþ£¬£¬²¢Ê¹Óð¢À­²®×Ö·ûºÍ±íÇé·ûºÅ´úÌæ²¿ÃÅ×Ö·û´®£¬£¬Ôö³¤ÁË·ÖÎöÄѶÈ¡£¡£ÆäÃâ·Ñ°æ±¾»á×Ô¶¯ÌìÉúPowerShellºÅÁ£¬ÏÂÔØ²¢ÔËÐÐÆäËû¶ñÒâ×é¼þ¡£¡£Neptune RATÔ̺¬¶àÖÖ¹¥»÷Ä£¿£¿£¿é£¬£¬ÈçÆ¾Ö¤ÍµÇÔ¡¢¼ôÌù°å½Ù³Ö¡¢ÀÕË÷Èí¼þºÍϵͳ°Ü»µµÈ£¬£¬¿ÉÄÜЭͬ¹¥»÷WindowsÍÆËã»ú¡£¡£ÎªÌӱܼì²â£¬£¬¸Ã¶ñÒâÈí¼þ»áÅú¸Ä×¢²á±íÖµ¡¢Ôö³¤µ½Windows¹¤×÷´òË㷨ʽÖУ¬£¬²¢²é³­ÊÇ·ñÔÚÐé¹¹»·¾³ÖÐÔËÐС£¡£´ËÍ⣬£¬¸½¼ÓµÄDLLÎļþÔö³¤Á˸ü¶àÖ°ÄÜ£¬£¬Ô̺¬ÈƹýÓû§ÕÊ»§½ÚÖÆ¡¢ÇÔÈ¡Êý¾ÝºÍʵʱÆÁÄ»¼à¿ØµÈ¡£¡£


https://hackread.com/neptune-rat-variant-youtube-steal-windows-passwords/