ÃÀ¹ú¾ü¹¤³Ð°üÉÌÊý¾Ýй¶ÊÂÎñÆØ¹âÔ±¹¤Êý¾Ý

°ä²¼¹¦·ò 2025-12-09

1. ÃÀ¹ú¾ü¹¤³Ð°üÉÌÊý¾Ýй¶ÊÂÎñÆØ¹âÔ±¹¤Êý¾Ý


12ÔÂ7ÈÕ£¬£¬£¬ÃÀ¹ú¾üʳаüÉÌMAG AerospaceÓÚ8ÔÂÏÂÑ®Ôâ·êÊý¾Ýй¶ÊÂÎñ£¬£¬£¬¸Ã¹«Ë¾ËæºóÆô¶¯Ó¦¼±ÏìÓ¦²¢Í¨ÖªÊýǧÃû¿ÉÄÜÊÜÓ°ÏìµÄСÎÒ¡£×÷ΪÄêÊÕÈ볬14ÒÚÃÀÔª¡¢¡¢Ô±¹¤³¬1400È˵ľü¹¤ÆóÒµ£¬£¬£¬MAG AerospaceΪÃÀ¹ú¾ü·½Ìṩµý±¨¡¢¡¢¼à¶½ºÍ¿úËÅ·þÎñ£¬£¬£¬Æä¿Í»§º­¸ÇÃÀ¹ú½¾ü¡¢¡¢Áª°î´¹Î£ÊÂÎñÖÎÀí¾Ö£¨FEMA£©¡¢¡¢¹ú·Àµý±¨¾Ö£¨DIA£©µÈÖ÷Ìâµ±¾Ö»ú¹¹¡£ÊÂÎñÆðÒòÓÚ¹«Ë¾ÍøÂçÄÚ³öÏÖ¿ÉÒɻ¾¯±¨¡£Îª½ÚÖÆÓ°Ï죬£¬£¬MAG AerospaceѸËÙ²ÉÈ¡¶àÏî´ëÊ©£º£º£º¸ôÀëÊÜÓ°Ïì×ʲú¡¢¡¢½ûÓÃÓйØÕË»§¼°ÓòÃû¡¢¡¢×èÖ¹Íⲿ½Ó¼û¡¢¡¢ÖØÖÃÃÜÂë²¢ÁªÏµ·¨Âɲ¿ÃÅ¡£º£º£ºóÐøµ÷²éÏÔʾ£¬£¬£¬¹¥»÷ÕßËä½Ó¼ûÁË¡°ÓÐÏ޵ĵç×Ӵ洢СÎÒÐÅÏ¢¡±£¬£¬£¬µ«Î´·¢ÏÖÊý¾Ý±»²»µ±´¦ÖõÄÖ¤¾Ý¡£È»¶ø£¬£¬£¬¹«Ë¾Î´Ã÷È·Åû¶¾ßÌåй¶µÄÊý¾ÝÀàÐÍ¡£Îª±£» £»¤ÊÜÓ°ÏìÈËÔ±£¬£¬£¬MAG AerospaceÌṩΪÆÚ24¸öÔµÄÃâ·Ñڲƭ¼ì²âºÍÉí·Ý͵ÇÔ±£» £»¤·þÎñ¡£¼øÓڸù«Ë¾Ëù´¦ÐÐÒµµÄÃô¸ÐÐÔ£¬£¬£¬Ð¹Â¶µÄСÎÒÊý¾Ý¶ÔÍþвÐÐΪÕߺ͹ú¶È¼¶¹¥»÷ÕßÓµÓм«¸ß¼ÛÖµ¡£


https://cybernews.com/security/mag-aerospace-military-contractor-data-breach/


2. ÀÕË÷Èí¼þÍÅ»ïÀÄÓÃShanya´ò°üƽ̨Ìӱܼì²â²¢½ûÓÃEDR


12ÔÂ8ÈÕ£¬£¬£¬¶à¸öÀÕË÷Èí¼þ×éÖ¯ÕýÀûÓÃÃûΪShanyaµÄ´ò°ü¼´·þÎñƽ̨²¿Êð¶ñÒâÔØºÉ£¬£¬£¬ÒÔÈÆ¹ý¶Ëµã¼ì²âÓëÏìÓ¦£¨EDR£©ÏµÍ³¡£¸Ãƽ̨ÓÚ2024Ëêĺ¹ÄÆð£¬£¬£¬Í¨¹ý¼ÓÃÜ¡¢¡¢Ñ¹Ëõ¼°×Ô½ç˵°ü×°Æ÷¼¼Êõ»ìºÏ¶ñÒâ´úÂ룬£¬£¬Ê¹ÓÐÐ§ÔØºÉÔÚÄÚ´æÖнâÃÜÖ´Ðжø²»´¥¼°´ÅÅÌ£¬£¬£¬´Ó¶ø¶ã±ÜÎÞÊý°²È«¹¤¾ß¼ì²â¡£Sophos Security¼à²âÏÔʾ£¬£¬£¬Í»Äá˹¡¢¡¢°¢ÁªÇõµÈ¶à¹úÒÑ·¢ÏÖº¬Shanya´ò°üºÛ¼£µÄ¶ñÒâÑù±¾£¬£¬£¬Medusa¡¢¡¢Qilin¡¢¡¢Crytox¼°AkiraµÈÀÕË÷Èí¼þ×éÖ¯¾ùÉæÆäÖУ¬£¬£¬ÆäÖÐAkiraʹÓÃÆµÂÊ×î¸ß¡£ShanyaµÄÔË×÷»úÖÆÔ̺¬£º£º£º½«Óû§Ìá½»µÄ¶ñÒâÔØºÉǶÈëWindowsϵͳÎļþshell32.dllµÄÄÚ´æÓ³É丱±¾£¬£¬£¬Í¨¹ý¸²¸ÇÆäÍ·²¿¼°.text²¿ÃÅʵÏÖÒñ±Î¼ÓÔØ£» £»Ñ¡È¡·Ç³ß¶ÈÄ£¿£¿éÄÚ´æ¼ÓÔØÓë¹ÖÒì¼ÓÃÜËã·¨£¬£¬£¬È·±£Ã¿¸ö¿Í»§»ñµÃ¡°Ïà¶ÔΨһ¡±µÄ´æ¸ù£¬£¬£¬¼ÓÇ¿¼ì²âÄѶÈ¡£¸Ãƽ̨»¹Í¨¹ýŲÓÃRtlDeleteFunctionTableº¯Êý´¥·¢Òì³££¬£¬£¬×ÌÈÅÓû§Ä£Ê½µ÷ÊÔÆ÷·ÖÎö£¬£¬£¬ÖжÏ×Ô¶¯»¯¼ì²âÁ÷³Ì¡£ÀÕË÷Èí¼þÔÚ¹¥»÷Êý¾ÝÇÔÈ¡Óë¼ÓÃܽ׶Îǰ£¬£¬£¬³£Í¨¹ýDLL²à¼ÓÔØ¼¼Êõ½ûÓÃEDR¡£³ýÀÕË÷Èí¼þÍ⣬£¬£¬ClickFix»î¶¯ÒàÀûÓÃShanya´ò°üCastleRAT¶ñÒâÈí¼þ¡£


https://www.bleepingcomputer.com/news/security/ransomware-gangs-turn-to-shanya-exe-packer-to-hide-edr-killers/


3. VS Code MarketplaceÏÖ¶ñÒâÀ©´óÇÔÈ¡¿ª·¢ÕßÃô¸ÐÐÅÏ¢


12ÔÂ8ÈÕ£¬£¬£¬Î¢ÈíVisual Studio Code Marketplace½üÈÕÆØ³öÁ½¸ö¶ñÒâÀ©´ó·¨Ê½Bitcoin BlackÓëCodo AI£¬£¬£¬Óɰ䲼Õß"BigBlack"ÒÔÉ«²ÊÖ÷ÌâºÍAIÖúÊÖ´ó¾Ö¼Ù×°ÉϼÜ£¬£¬£¬Ä¿Ç°ÒѶԿª·¢ÕßÍÆËã»ú°²È«×é³ÉÑÏÖØÍþв¡£¾Ý°²È«»ú¹¹Koi SecurityÅû¶£¬£¬£¬Bitcoin Blackͨ¹ý"*"¼¤»îÊÂÎñÔÚÿ´ÎVSCode²Ù×÷ʱ×Ô¶¯Ö´ÐУ¬£¬£¬ÔçÆÚ°æ±¾ÀûÓÃPowerShellÏÂÔØ¼ÓÃÜÓÐÐ§ÔØºÉ²¢´¥·¢¿É¼û´°¿Ú£¬£¬£¬Ð°æÔò¸ÄÓðµ²Ø´°¿ÚµÄÅú´¦Öþ籾ŲÓÃcurlÏÂÔØ¶ñÒâDLL£¬£¬£¬ÊµÏÖ¸üÒñ±ÎµÄ¹¥»÷¡£Codo AIËäÐû³ÆÌṩChatGPT/DeepSeek´úÂ븨ÖúÖ°ÄÜ£¬£¬£¬µ«ÏÖʵÔ̺¬¶ñÒâÄ£¿£¿é¡£ÕâÁ½¸öÀ©´ó¾ùѡȡDLL½Ù³Ö¼¼Êõ£¬£¬£¬½«ºÏ·¨Lightshot½ØÍ¼¹¤¾ßÓë¶ñÒâDLL°ó¸¿£¬£¬£¬ÒÔruntime.exeÃûÒ岿ÊðÐÅÏ¢ÇÔÈ¡·¨Ê½¡£¶ñÒâÈí¼þ»áÔÚ"%APPDATA%\Local\Evelyn"Ŀ¼´æ´¢ÇÔÈ¡Êý¾Ý£¬£¬£¬Ô̺¬¹ý³ÌÏêÇé¡¢¡¢¼ôÌù°åÄÚÈÝ¡¢¡¢WiFiÍ´´¦¡¢¡¢ÏµÍ³ÐÅÏ¢¡¢¡¢ÆÁÄ»½ØÍ¼¡¢¡¢ÒÑ×°Ö÷¨Ê½ÁÐ±í¼°¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý£¨ÈçPhantom¡¢¡¢Metamask¡¢¡¢Exodus£©¡£Îª½Ù³ÖÓû§»á»°£¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹»áÎÞÍ·Æô¶¯Chrome/Edgeä¯ÀÀÆ÷ÇÔÈ¡cookie£¬£¬£¬²¢Õë¶ÔÐÔËÑË÷ÃÜÂëÆ¾Ö¤¡£


https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-on-microsofts-registry-drop-infostealers/


4. PetcoÊý¾Ýй¶ÊÂÎñ²¨¼°¶àÖÝ£¬£¬£¬Ãô¸ÐÐÅÏ¢ÔâÆØ¹â


12ÔÂ8ÈÕ£¬£¬£¬³èÎïÓÃÆ·¾ÞÍ·Petco֤ʵÉÏÖܲúÉúÖØ´ó¿Í»§Êý¾Ýй¶ÊÂÎñ£¬£¬£¬Éæ¼°ÐÕÃû¡¢¡¢Éç»á±£ÏÕºÅÂë¡¢¡¢¼ÝÕÕºÅÂë¡¢¡¢ÒøÐÐÕ˺𢡢ÐÅÓþ¿¨/½è¼Ç¿¨ÐÅÏ¢¼°µ®ÉúÈÕÆÚµÈÃô¸ÐÄÚÈÝ¡£Æ¾¾ÝµÂ¿ËÈøË¹ÖÝ¡¢¡¢¼ÓÖÝ¡¢¡¢ÂíÈøÖîÈûÖݺÍÃÉ´óÄÃÖÝ×ܼì²ì³¤°ì¹«ÊÒÅû¶µÄ˾·¨Í¨Öª£¬£¬£¬Õâ´ÎÊÂÎñÓ°ÏìÁìÓò¸²¸Ç¶àÖÝ£º£º£ºÂíÈøÖîÈûÖݽö1Ãû¾ÓÃñÊÜÓ°Ï죬£¬£¬ÃÉ´óÄÃÖÝ3Ãû£¬£¬£¬¶ø¼ÓÖÝÒò˾·¨ÒªÇóÏÔʾÊܺ¦ÕßÈËÊý¿ÉÄÜÔ¶³¬500ÈË£¬£¬£¬¾ßÌåÊý×ÖPetcoÉÐδ¹«¿ª¡£PetcoÔÚÉêÃ÷ÖÐй©£¬£¬£¬Ð¹Â¶Ô´ÓÚ¡°Ä³¿îÈí¼þÀûÓÃÅäÖÃÎÊÌâµ¼Ö²¿ÃÅÎļþÔÚÏ߿ɽӼû¡±£¬£¬£¬¹«Ë¾ÒÑ¡°Á¢¼´ÐÞ¸´·ì϶²¢Ö´ÐжîÍⰲȫ´ëÊ©¡±¡£Ö»¹ÜÈç´Ë£¬£¬£¬¸Ã¹«Ë¾Î´»ØÓ¦¹ØÓÚ¾ßÌåÊÜÓ°Ïì¿Í»§×ÜÊý¡¢¡¢¼¼ÊõËÝÔ´ÄÜÁ¦¡¢¡¢ÎÊÌâ·¢ÏÖ¹¦·ò¼°ÉæÊÂÀûÓõȹؼüÎÊÌâ¡£×÷ΪÄê·þÎñ³¬2400Íò¿Í»§µÄÐÐÒµ¾ÞÍ·£¬£¬£¬Petco½ö°µÊ¾ÒÑÏòÊÜÓ°ÏìСÎÒ¡°Ìṩ¸ü¶àÐÅÏ¢¡±¡£PetcoÕýΪ¼ÓÖÝ¡¢¡¢ÂíÈøÖîÈûÖݺÍÃÉ´óÄÃÖÝÊܺ¦ÕßÌṩÃâ·ÑÐÅÓþÓëÉí·Ý͵ÇÔ¼à¿Ø·þÎñ¡£


https://techcrunch.com/2025/12/08/petcos-security-lapse-affected-customers-ssns-drivers-licenses-and-more/


5. Tri-Century Eye CareÔâÀÕË÷¹¥»÷ÖÂ20ÍòÈËÊý¾Ýй¶


12ÔÂ8ÈÕ£¬£¬£¬½üÈÕ£¬£¬£¬ÃÀ¹ú±öϦ·¨ÄáÑÇÖݰͿËË¹ÏØÌṩÑÛ¿Æ»¤Àí·þÎñµÄTri-Century Eye CareÅûÂ¶ÖØ´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬Ó°ÏìÔ¼20ÍòÈË¡£¾ÝÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©Ò½ÁƱ£½¡Êý¾Ýй¶׷×ÙÆ÷ÏÔʾ£¬£¬£¬¸ÃÊÂÎñÔ´ÓÚ9ÔÂ3ÈÕ·¢Ïֵݲȫ·ì϶£¬£¬£¬¹«Ë¾ÓÚ10ÔÂÏÂѮͨ¹ý¹ÙÍø°ä²¼Í¨Öª£¬£¬£¬ÈϿɻ¼Õß¼°Ô±¹¤µÄСÎÒÓëÊܱ£» £»¤½¡¿µÐÅÏ¢¿ÉÄÜÔâй¶¡£µ÷²éÏÔʾ£¬£¬£¬Ö»¹Üµç×Ó²¡Àúϵͳδ±»Ö±½ÓÈëÇÖ£¬£¬£¬µ«¹¥»÷Õß»ñÈ¡ÁËÔ̺¬ÐÕÃû¡¢¡¢µ®ÉúÈÕÆÚ¡¢¡¢Éç»á±£ÏÕºÅÂë¡¢¡¢Ò½ÁÆÕï¶ÏÐÅÏ¢¡¢¡¢½¡¿µ±£ÏÕÏêÇé¡¢¡¢Ö§¸¶¼Í¼¼°Ë°Îñ²ÆÕþÐÅÏ¢µÈÃô¸ÐÎļþ¡£PearÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬Ðû³ÆÇÔÈ¡³¬3TBÊý¾Ý£¬£¬£¬º­¸ÇÈËÁ¦×ÊÔ´¡¢¡¢²ÆÕþ¡¢¡¢ÒµÎñÎļþ¡¢¡¢µç×ÓÓʼþ¼°Êý¾Ý¿âµÈ£¬£¬£¬²¢¹«¿ª²¿ÃÅÎļþ£¬£¬£¬°µÊ¾ÒòTri-Century»Ø¾øÖ§¸¶Êê½ð¶ø²ÉÈ¡ÆØ¹âÐж¯¡£Tri-Century Eye CareÔÚ֪ͨÖÐÇ¿µ÷ÒѲÉÈ¡²¹¾È´ëÊ©£¬£¬£¬µ«Î´¾ßÌå×¢Ã÷¾ßÌå¼¼ÊõÐÞ¸´Ï¸½Ú»òºóÐø·À»¤¹æ»®¡£


https://www.securityweek.com/tri-century-eye-care-data-breach-impacts-200000-individuals/


6. ÃÀ¹ú¶àËù´óѧÔâÍøÂç´¹µö¹¥»÷


12ÔÂ8ÈÕ£¬£¬£¬°²È«¹«Ë¾Infoblox×îл㱨Åû¶£¬£¬£¬2025Äê4ÔÂÖÁ11ÔÂÆÚ¼ä£¬£¬£¬ÖÁÉÙ18ËùÃÀ¹ú´óѧÔâ·êÓÐ×éÖ¯ÍøÂç´¹µö¹¥»÷£¬£¬£¬¹¥»÷ÕßÀûÓÿªÔ´¹¤¾ßEvilginx³É¹¦Èƹý¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©£¬£¬£¬ÇÔȡѧÉú¼°½ÌÖ°¹¤ÕË»§ÐÅÏ¢¡£¸Ã¹¤¾ßͨ¹ýÖÐÑëÈ˹¥»÷£¨AiTM£©Õ½Êõ£¬£¬£¬ÔÚÊܺ¦Õßµã»÷´¹µöÁ´½ÓºóȾָÆäÓë´óÑ§ÕæÊµµÇÂ¼Ò³ÃæÖ®¼ä£¬£¬£¬·ÂÕյǼÁ÷³Ì²¢ÇÔÈ¡Óû§Ãû¡¢¡¢ÃÜÂ뼰ʵÏÖMFAºóµÄ»á»°cookie£¬£¬£¬´Ó¶øÆëÈ«½ÚÖÆÕË»§¡£¹¥»÷Á´½Ó¶àѡȡ¶ÌʱTinyURL¼Ù×°³ÉѧÌõ¥µãµÇ¼£¨SSO£©ÃÅ»§£¬£¬£¬¼ÓÇ¿ºýŪÐÔ¡£Îª¸²¸Ç×ÙÓ°£¬£¬£¬¹¥»÷Õ߯µÈÔ¸ü»»¹¥»÷ÓòÃû£¬£¬£¬²¢ÀûÓÃCloudflareµÈ·þÎñ°µ²Ø·þÎñÆ÷µØÎ»¡£Infobloxͨ¹ý¶ÈÎöDNSģʽ£¬£¬£¬×·×Ùµ½¸Ã¹î¼ÆÖÐʹÓõĽü70¸ö·ÖÆçÓòÃû£¬£¬£¬³õ´Î¹¥»÷²úÉúÓÚ2025Äê4ÔÂ12ÈÕ£¬£¬£¬Ö¸±êΪʥµØÑǸç´óѧ¡£¾Ý¹¥»÷Á¿Í³¼Æ£¬£¬£¬ÊÜÓ°Ïì×îÑÏÖØµÄǰÎåËùѧÌÃΪ¼ÓÖÝ´óѧʥ¿Ë³×È·ÖУ¡£¡¢¡¢¼ÓÖÝ´óѧʥ°Í°ÍÀ­·ÖУ¡£¡¢¡¢Ê¥µØÑǸç´óѧ¡¢¡¢¸¥¼ªÄáÑÇÁª°î´óѧºÍÃÜЪ¸ù´óѧ¡£


https://hackread.com/us-universities-domains-phishing-attacks/