Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬Zscaler¿Í»§ÐÅÏ¢Íâй

°ä²¼¹¦·ò 2025-09-03

1. Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬Zscaler¿Í»§ÐÅÏ¢Íâй


9ÔÂ1ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Zscaler½üÈÕÅû¶£¬ÆäSalesforceʵÀýÒòµÚÈý·½¼¯³É¹¤¾ßÔâÈëÇÖÒý·¢Êý¾Ýй¶£¬¿Í»§Ãô¸ÐÐÅÏ¢¼°²¿ÃÅÖ§³Ö°¸ÀýÄÚÈݱ»ÇÔÈ¡¡£¡£ÊÂÎñÔ´ÓÚSalesloft Drift±»¹¥»÷ÕßÀûÓã¬ÆäOAuthÁîÅÆºÍË¢ÐÂÁîÅÆÔâÇÔ£¬µ¼ÖÂδ¾­ÊÚȨµÄÐÐΪÕß½Ó¼ûZscalerµÄSalesforce»·¾³¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬¿Í»§ÐÕÃû¡¢¡¢¡¢Ã³Ò×ÓÊÏä¡¢¡¢¡¢Ö°Î»¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢ÇøÓòÐÅÏ¢¡¢¡¢¡¢²úÆ·Ðí¿ÉÏêÇé¼°Ö§³Ö°¸ÀýÄÚÈÝ£¬µ«ZscalerÇ¿µ÷Õâ´ÎÊÂÎñ䲨¼°¹«Ë¾×ÔÉí²úÆ·¡¢¡¢¡¢·þÎñ»ò»ù´¡ÉèÊ©¡£¡£¹È¸èÍþвµý±¨Ð¡×飨GTIG£©½«Õâ´Î¹¥»÷¹éÒòÓÚ×·×ÙΪUNC6395µÄÍþв×éÖ¯£¬²¢Ö¸³öÆäÖ¸±êΪ»ñÈ¡¿Í»§ÔÚÖ§³Ö°¸ÀýÖзÖÏíµÄÃô¸Ðƾ֤£¬ÈçAWS½Ó¼ûÃÜÔ¿¡¢¡¢¡¢ÃÜÂë¼°SnowflakeÓйØÁîÅÆ¡£¡£¹¥»÷Õßͨ¹ýɾ³ý²éÎÊ×÷Òµ¸²¸ÇºÛ¼££¬µ«ÈÕ־δÊÜÓ°Ï죬¹È¸è½¨ÒéÊÜÓ°Ïì×éÖ¯Éó²éÈÕÖ¾ÒÔÈ·ÈÏÊý¾Ý¶³öÇé¿ö¡£¡£½øÒ»´ëÊ©²éÏÔʾ£¬Salesloft¹©¸øÁ´¹¥»÷²»½öÓ°ÏìDriftÓëSalesforceµÄ¼¯³É£¬»¹²¨¼°ÆäÓÃÓÚÖÎÀíÓʼþ»Ø¸´ºÍCRMÊý¾Ý¿âµÄDrift EmailÖ°ÄÜ¡£¡£¹¥»÷ÕßÉõÖÁÀûÓÃÇÔÈ¡µÄOAuthÁîÅÆ½Ó¼ûGoogle WorkspaceÓÊÏä²¢¶ÁÈ¡Óʼþ£¬´Ùʹ¹È¸èÓëSalesforceÁÙʱ½ûÓÃDrift¼¯³É¡£¡£


https://www.bleepingcomputer.com/news/security/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise/


2. ¶ñÒânpm°ü¼Ù×°³ÉÓʼþ¿âÖ´ÐмÓÃÜÇ®±ÒÇ®°üÇÔÈ¡¹¥»÷


9ÔÂ2ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶һ·Õë¶Ô¼ÓÃÜÇ®±ÒÓû§µÄ¹©¸øÁ´¹¥»÷ÊÂÎñ£º¶ñÒânpm°ü"nodejs-smtp"ͨ¹ý¼ÙÒâ³ÛÃûÓʼþ¿âNodemailer£¬³É¹¦½«¶ñÒâ´úÂë×¢ÈëAtomic¡¢¡¢¡¢ExodusµÈÖ÷Á÷¼ÓÃÜÇ®±ÒÇ®°üµÄWindows×ÀÃæÀûÓã¬ÇÔÈ¡Óû§ÂòÂô×ʽ𡣡£¸ÃÈí¼þ°üÓÉÓû§"nikotimon"ÓÚ2025Äê4ÔÂÉÏ´«ÖÁnpm×¢²á±í£¬ÀÛ¼ÆÏÂÔØ347´Îºó±»Ï¼Ü£¬Ä¿Ç°ÈÔ¿Éͨ¹ýº¹Çà°æ±¾»ñÈ¡¡£¡£Socket×êÑÐÔ±Kirill Boychenko½Òʾ£¬¸Ã¶ñÒâ°üÑ¡È¡Ë«ÖØ¼Ù×°Õ½Êõ£ºÀíÂÛÌṩÓëNodemailerÆëÈ«¼æÈݵÄSMTPÓʼþÖ°ÄÜ£¬ÏÖ×Åʵµ¼ÈëʱÀûÓÃElectron¹¤¾ß½âѹǮ°üÀûÓõÄapp.asarÎļþ£¬ÓÃÍþвÐÐΪÕß½ÚÖÆµÄÓ²±àÂëÇ®°üµØÖ·´úÌæÓû§ÊÕ¼þµØÖ·£¬ÊµÏÖ±ÈÌØ±Ò¡¢¡¢¡¢ÒÔÌ«·»¡¢¡¢¡¢USDT¡¢¡¢¡¢XRP¼°SolanaµÈÖ÷Á÷¼ÓÃÜÇ®±ÒµÄÂòÂô½Ù³Ö¡£¡£Æä¹¥»÷Á÷³ÌÉè¼Æ¾«Ãͨ¹ýÅú¸Ä×ÀÃæÀûÓÃÖ÷ÌâÎļþʵÏÖÓÆ¾Ã»¯´Û¸Ä£¬ÖØÆôºóÈÔ¿ÉÉúЧ£¬Í¬Ê±×Ô¶¯É¾³ý¹¤×÷Ŀ¼ºÛ¼££¬´ó·ù½µµÍ¶³ö·çÏÕ¡£¡£¼¼Êõ·ÖÎöÏÔʾ£¬nodejs-smtpµÄ¹¥»÷´úÂëǶÈëÔÚÓʼþÖ°ÄÜʵÏÖÖУ¬Í¨¹ýNodemailer¼æÈݽӿڽµµÍ¿ª·¢Õß¾¯ÌèÐÔ¡£¡£µ±Óû§ÔÚ¿ª·¢»·¾³Öе¼Èë¸Ã°üʱ£¬Æä¶ñÒâÄ£¿ £¿é»á×Ô¶¯¼ì²âϵͳÖÐÊÇ·ñ×°ÖÃAtomic»òExodusÇ®°ü£¬Ò»µ©·¢ÏÖ¼´Ö´Ðнâѹ-´úÌæ-´ò°ü²Ù×÷£¬½«ºÏ·¨Ç®°üÀûÓÃת»¯ÎªÇÔÈ¡¹¤¾ß¡£¡£


https://thehackernews.com/2025/09/malicious-npm-package-nodejs-smtp.html


3. CloudflareÔÚSalesforce¹©¸øÁ´¹¥»÷ÖÐÔâ·êÊý¾Ýй¶


9ÔÂ2ÈÕ£¬½üÆÚ£¬Ò»³¡ÒÔSalesforceƽ̨Ϊָ±êµÄ¹©¸øÁ´¹¥»÷Òý·¢¶àÆðÊý¾Ýй¶ÊÂÎñ£¬Cloudflare³ÉΪ×îÐÂÊÜÓ°ÏìÆóÒµ¡£¡£Õâ´Î¹¥»÷Á´Ô´ÓÚÍþвÐÐΪÕßͨ¹ýÓïÒô´¹µö£¨vishing£©Éç»á¹¤³Ì¼¿Á©£¬ÓÕÆ­ÆóÒµÔ±¹¤½«¶ñÒâOAuthÀûÓùØÁª´ó¹«Ë¾SalesforceʵÀý£¬½ø¶øÇÔÈ¡Êý¾Ý¿â¡£¡£8ÔÂ9ÈÕÖÁ17ÈÕÆÚ¼ä£¬¹¥»÷ÕßÊ×ÏȶÔCloudflareµÄSalesforceʵÀý·¢Õ¹¿úËÅ£¬ËæºóÇÔÈ¡ÁËÆäÄÚ²¿¿Í»§°¸ÀýÖÎÀí¼°Ö§³ÖϵͳÖеÄÎı¾Êý¾Ý£¬Éæ¼°104¸öCloudflare APIÁîÅÆ¼°´óÁ¿¿Í»§Ö§³Ö¹¤µ¥ÄÚÈÝ¡£¡£Ö»¹ÜĿǰδ·¢ÏÖÁîÅÆ±»ÀÄÓ㬵«Ð¹Â¶ÐÅÏ¢Ô̺¬¿Í»§ÁªÏµ×ÊÁÏ¡¢¡¢¡¢ÅäÖÃÏêÇé¼°¿ÉÄÜ´æÔڵĽӼûƾ֤µÈÃô¸ÐÊý¾Ý£¬CloudflareÒÑ´¹Î£ÂÖ»»È«ÊýÊÜÓ°ÏìÁîÅÆ²¢Í¨Öª¿Í»§£¬½¨ÒéÂÖ»»Í¨¹ýÖ§³ÖÇþµÀ¹²ÏíµÄÍ´´¦¡£¡£Õâ´Î¹©¸øÁ´¹¥»÷¶³ö³öÆóÒµÒÀÀµµÚÈý·½SaaSƽ̨µÄ°²È«·çÏÕ¡£¡£¹¥»÷Õßͨ¹ýµ¥Ò»Æ½Ì¨·ì϶¼´¿ÉºáÏò²¨¼°Êý°Ù¼Ò¿Í»§£¬ÇÔÈ¡µÄ¿Í»§Ö§³Ö¹¤µ¥Êý¾Ý£¨ÈçÈÕÖ¾¡¢¡¢¡¢ÁîÅÆ¡¢¡¢¡¢ÃÜÂ룩¿ÉÄܳÉΪºóÐøÕë¶ÔÐÔ¹¥»÷µÄÌø°å¡£¡£Ö»¹ÜÊÜÓ°ÏìÆóÒµ¾ùÇ¿µ÷䲨¼°Ö÷Ìâϵͳ£¬µ«Ãô¸ÐÐÅϢй¶ÈÔ¿ÉÄÜÒý·¢¿Í»§ÐÅÀµÎ£»£»£»ú¼°ºÏ¹æ·çÏÕ¡£¡£


https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/


4. ºÚ¿Í¹¥»÷Evertec°ÍÎ÷×Ó¹«Ë¾Sinqia£¬ÊÔͼÇÔÈ¡1.3ÒÚÃÀÔª


9ÔÂ2ÈÕ£¬À­¶¡ÃÀÖÞ½ðÈڿƼ¼¾ÞÍ·EvertecµÄ°ÍÎ÷×Ó¹«Ë¾Sinqia S.A.½üÈÕÔâ·êÖØ´óÍøÂç¹¥»÷ÊÂÎñ£¬ºÚ¿Íͨ¹ýÇÔÈ¡µÄIT¹©¸øÉÌÕË»§Æ¾Ö¤£¬ÓÚ8ÔÂ29ÈÕ·¸·¨ÇÖÈëÆäÕÆ¹ÜÔËÓªµÄ°ÍÎ÷ÑëÐÐʵʱ֧¸¶ÏµÍ³£¨Pix£©»·¾³£¬ÊÔͼͨ¹ýÁ½¼Ò½ðÈÚ»ú¹¹¿Í»§ÌáÒé×ܶî´ï1.3ÒÚÃÀÔªµÄδ¾­ÊÚȨÆóÒµ¼äתÕË¡£¡£Ö»¹Ü²¿ÃÅ×ʽðÒѱ»×·»Ø£¬µ«¾ßÌå½ð¶îδ¹«¿ª£¬ÇÒÊÂÎñ¶ÔEvertec²ÆÕþ¼°ÃûÓþµÄDZÔÚÓ°ÏìÈÔ±»ÆÀ¹ÀΪ"¿ÉÄÜÖØ´ó"¡£¡£Æ¾¾ÝEvertecÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ìá½»µÄÎļþ£¬Õâ´Î¹¥»÷¶³öÁ˰ÍÎ÷¼´Ê±Ö§¸¶ÏµÍ³PixµÄ°²È«´àÈõÐÔ¡£¡£×÷Ϊ°ÍÎ÷ÑëÐÐ2020ÄêÍÆ³öµÄÈ«Ììºò¼´Ê±×ªÕËϵͳ£¬PixÒѸ²¸ÇÈ«¹ú³¬¹ý°ëÊý³ÉÄêÈ˶¡£¬µ«ÆµÈÔ³ÉΪAndroidÒøÐжñÒâÈí¼þ¹¥»÷Ö¸±ê¡£¡£Õâ´ÎÊÂÎñÖУ¬ºÚ¿ÍÀûÓõÚÈý·½¹©¸øÉÌÕË»§È¨ÏÞ£¬Í»ÆÆÁËSinqiaΪ24¼Ò°ÍÎ÷½ðÈÚ»ú¹¹ÌṩµÄPixÖ§¸¶´¦Öû·¾³£¬Ö»¹ÜEvertecÇ¿µ÷δ·¢ÏÖСÎÒÊý¾Ýй¶£¬µ«¹¥»÷ÕßÈÔÊÔͼͨ¹ý»ã·áÒøÐеȿͻ§ÌáÒé´ó¹æÄ£×ʽð×ªÒÆ¡£¡£»£»£»ã·áÒøÐлØÓ¦³Æ¿Í»§×ʽðÓëÊý¾ÝδÊÜÓ°Ï죬µ«ÊÂÎñ͹ÏÔ½ðÈÚ»ú¹¹¶ÔµÚÈý·½·þÎñÉ̵ݲȫÒÀÀµ·çÏÕ¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-breach-fintech-firm-in-attempted-130m-bank-heist/


5. ½Ý±ªÂ·»¢ÔâÍøÂç¹¥»÷ÖÂϵͳ¹Ø±Õ£¬³ö²úÁãÊÛÊÜÓ°Ïì


9ÔÂ2ÈÕ£¬½Ý±ªÂ·»¢£¨JLR£©½üÈÕÔâ·êÍøÂç¹¥»÷£¬±»ÆÈ¹Ø±Õ²¿ÃÅϵͳÒÔ»º½âÓ°Ï죬µ¼ÖÂÆä³ö²úºÍÁãÊÛÒµÎñÊܵ½ÑÏÖØ×ÌÈÅ¡£¡£Æ¾¾Ý¹«Ë¾¹Ù·½ÉêÃ÷£¬Õâ´ÎÊÂÎñÖÐËäδ·¢ÏÖ¿Í»§Êý¾Ý±»µÁ¼£Ï󣬵«ÁãÊ۶˺ͳö²ú»·½Ú¾ù³öÏÖÏÔÖøÖжÏ¡£¡£½Ý±ªÂ·»¢°µÊ¾£¬ÊÂÎñ²úÉúºóÁ¢¼´×Ô¶¯¹Ø±ÕÊÜÓ°Ïìϵͳ£¬Ä¿Ç°Õý°´´òËãÖð²½ÖØÆôÈ«ÇòÀûÓ÷¨Ê½£¬µ«ÉÐδÌṩ¸´Ô­Õý³£ÔËÓªµÄ¾ßÌ幦·ò±í£¬Ò²Î´Åû¶¹¥»÷ÀàÐÍ»ò¼¼Êõϸ½Ú¡£¡£×÷ΪËþËþÆû³µÆìÏÂ×Ó¹«Ë¾£¬½Ý±ªÂ·»¢ÄêÊÕÈ볬380ÒÚÃÀÔª£¬Äê²úÁ¿³¬40ÍòÁ¾£¬Õ¼ÓÐ3.9ÍòÃûÔ±¹¤£¬ÆäË÷Àû¹þ¶û¹¤³§Õƹܳö²ú·»¢·¢ÏÖ¡¢¡¢¡¢À¿Ê¤¼°À¿Ê¤»î¶¯°æµÈÈȵ㳵ÐÍ¡£¡£Õâ´Î¹¥»÷µ¼ÖÂÓ¢¹ú¾­ÏúÉÌÎÞ·¨×¢²áгµ»ò¹©¸øÁã¼þ£¬³ö²úϵͳҲһ¶ÈÍ£°Ú£¬µ«¹«Ë¾Ç¿µ÷¿Í»§Êý¾Ý°²È«ÐÔδÊÜÍþв¡£¡£Õâ´Î¹¥»÷²úÉúÔÚÖÜÄ©£¬Õâһʱ¶Î³£±»ÍþвÐÐΪÕßÀûÓã¬ÒòÆóÒµÓ¦¼±ÏìÓ¦ÄÜÁ¦Ïà¶Ô½ÏÈõ¡£¡£½ØÖÁĿǰÉÐδÓÐÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´ËÕÆ¹Ü¡£¡£


https://www.bleepingcomputer.com/news/security/jaguar-land-rover-says-cyberattack-severely-disrupted-production/


6. Palo Alto NetworksÔâSalesforce¹©¸øÁ´¹¥»÷й¶¿Í»§Êý¾Ý


9ÔÂ2ÈÕ£¬Palo Alto Networks½üÈÕÈ·ÈÏ£¬Æä³ÉΪÉÏÖÜÅû¶µÄSalesloft Drift¹©¸øÁ´¹¥»÷ÊÂÎñÖеÄÊÜÓ°ÏìÆóÒµÖ®Ò»£¬¹¥»÷Õßͨ¹ýÇÔÈ¡µÄOAuthÁîÅÆ·¸·¨½Ó¼ûÆäSalesforce CRMϵͳ£¬µ¼Ö¿ͻ§ÁªÏµÐÅÏ¢¡¢¡¢¡¢ÄÚ²¿ÏúÊۼͼ¼°Ö§³Ö°¸ÀýÊý¾Ýй¶£¬µ«Î´²¨¼°¹«Ë¾Ö÷Ìâ²úÆ·¡¢¡¢¡¢ÏµÍ³»ò·þÎñ¡£¡£Õâ´ÎÊÂÎñ¶³öÁËÍþвÐÐΪÕßÕë¶ÔSalesforceÉú̬µÄ¹æÄ£»£»£»¯Êý¾ÝÇÔȡսÊõ£¬¹¥»÷Õßͨ¹ýÀÄÓõÚÈý·½ÀûÓ÷ì϶£¬´ÓÊý°Ù¼ÒÆóÒµÖÐÅúÁ¿ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬Palo Alto NetworksÒÑ´¹Î£½ûÓÃÓйØÀûÓò¢ÂÖ»»Æ¾Ö¤£¬Í¬Ê±ÖÒ¸æ¿Í»§Ð辯ÌèºóÐøÕë¶ÔÐÔ¹¥»÷¡£¡£Õâ´Î¹¥»÷Ô´ÓÚÍþвÐÐΪÕßÀûÓÃSalesloft DriftÀûÓ÷¨Ê½·ì϶»ñÈ¡µÄOAuthÁîÅÆ£¬½ø¶øÉøÈëÆäSalesforce»·¾³¡£¡£Ö»¹Üй¶Êý¾Ý½öÏÞÓÚÁªÏµÐÅÏ¢¡¢¡¢¡¢Îı¾ÆÀÂÛ¼°»ù´¡°¸ÀýÊý¾Ý£¬Î´Ô̺¬¼¼Êõ¸½¼þ»òÎļþ£¬µ«¹¥»÷ÕßÈÔͨ¹ý×Ô¶¯»¯¹¤¾ß£¨Èç×Ô½ç˵Python¾ç±¾£©´ÓÕË»§¡¢¡¢¡¢ÁªÏµÈË¡¢¡¢¡¢°¸ÀýµÈSalesforce¶ÔÏóÖдó¹æÄ£ÌáÈ¡Êý¾Ý£¬²¢ÖصãɨÃèAWSÃÜÔ¿¡¢¡¢¡¢SnowflakeÁîÅÆ¡¢¡¢¡¢VPN/SSOƾ֤µÈ¸ß¼ÛÖµÐÅÏ¢£¬Òâͼͨ¹ýÇÔÈ¡µÄÔÆÆ½Ì¨½Ó¼ûȨÏÞÖ´ÐÐÊý¾ÝÀÕË÷»òºáÏòÉøÈë¡£¡£


https://www.bleepingcomputer.com/news/security/palo-alto-networks-data-breach-exposes-customer-info-support-cases/