GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý
°ä²¼¹¦·ò 2026-02-031. GlassWormͨ¹ýOpenVSXÀ©´óÇÔÈ¡macOSÃô¸ÐÊý¾Ý
2ÔÂ2ÈÕ£¬£¬Ò»ÖÖÐÂÐÍGlassWorm¶ñÒâÈí¼þ¹¥»÷ͨ¹ý±»ÈëÇÖµÄOpenVSXÀ©´ó·¨Ê½£¬£¬×¨ÃÅÕë¶ÔmacOSϵͳÇÔÈ¡ÃÜÂë¡¢¡¢¼ÓÃÜÇ®°üÊý¾Ý¡¢¡¢¿ª·¢ÕßÍ´´¦¼°ÅäÏàÐÅÏ¢¡£¡£ÍþвÐÐΪÕß»ñÈ¡Á˺Ϸ¨¿ª·¢ÕßoorzcµÄÕË»§È¨ÏÞ£¬£¬ÓÚ1ÔÂ30ÈÕÏòËĸö±»ÏÂÔØ22,000´ÎµÄÀ©´ó·¨Ê½ÍÆËͺ¬GlassWormÓÐÐ§ÔØºÉµÄ¶ñÒâ¸üС£¡£ÕâЩÀ©´ó·¨Ê½´ËǰÁ½Äê¾ùÎÞº¦£¬£¬Åú×¢oorzcÕË»§ÒÑÔâÈëÇÖ¡£¡£¹¥»÷×îÔç³öÏÖÓÚ2025Äê10ÔÂÏÂÑ®£¬£¬ÀûÓá°²»Ë½¼û¡±Unicode×Ö·û°µ²Ø¶ñÒâ´úÂ룬£¬Ö§³Ö»ùÓÚVNCµÄÔ¶³Ì½Ó¼ûºÍSOCKS´úÀíÖ°ÄÜ¡£¡£GlassWormרÃÅÕë¶ÔmacOSϵͳ£¬£¬¿É´ÓSolanaÂòÂô±¸Íü¼ÌáȡָÁ£¬ÇÒ¶íÓïϵͳδÊܹ¥»÷£¬£¬°µÊ¾¹¥»÷Õß¿ÉÄÜÀ´×ԷǶíÓïÇø¡£¡£¸Ã¶ñÒâÈí¼þ¼ÓÔØmacOSÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬Í¨¹ýLaunchAgent³ÉÁ¢ÓƾÃÐÔ£¬£¬ÔÚÓû§µÇ¼ʱ×Ô¶¯Ö´ÐУ¬£¬ÍøÂçFirefox¡¢¡¢Chromiumä¯ÀÀÆ÷Êý¾Ý¡¢¡¢¼ÓÃÜÇ®±ÒÇ®°üÀûÓᢡ¢macOSÔ¿³×´®¡¢¡¢Apple NotesÊý¾Ý¿â¡¢¡¢Safari cookie¡¢¡¢¿ª·¢ÕßÃÜÔ¿¼°±¾µØÎĵµ£¬£¬²¢½«Ëùº±¼û¾Ýй¶ÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£¡£
https://www.bleepingcomputer.com/news/security/new-glassworm-attack-targets-macos-via-compromised-openvsx-extensions/
2. ShinyHuntersй¶Panera Bread³¬1400ÍòÕË»§Êý¾Ý
2ÔÂ2ÈÕ£¬£¬ShinyHunters·¸×ïÍÅ»ïÐû³ÆÇÔÈ¡ÁËPanera Bread³¬¹ý1400Íò¸öÕË»§µÄÊý¾Ý£¬£¬²¢ÔÚÀÕË÷δ¹ûºó£¬£¬ÓÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªÁËÒ»¸ö760MBµÄÊý¾Ý´æµµ¡£¡£¾ÝHave I Been Pwned£¨HIBP£©±¨µÀ£¬£¬Õâ´ÎÐ¹Â¶Éæ¼°510Íò¸öΨһµç×ÓÓʼþµØÖ·¼°¹ØÁªµÄÕË»§ÐÅÏ¢£¬£¬Ô̺¬ÐÕÃû¡¢¡¢µç»°ºÅÂë¡¢¡¢ÏÖʵµØÖ·µÈ¡£¡£Panera BreadËæºó֤ʵй¶Êý¾ÝΪÁªÏµÐÅÏ¢£¬£¬²¢ÒÑ֪ͨÓйز¿ÃÅ¡£¡£BleepingComputer½øÒ»²½È·ÈÏÔ¼512Íò¸öÕË»§Êܵ½Ó°Ï죬£¬µ«ÏÖʵÊÜÓ°ÏìÓû§ÊýÁ¿¿ÉÄܸüÉÙ£¬£¬Òò´æÔÚͳһÓû§Ê¹Óöà¸öÕË»§µÄÇé¿ö¡£¡£ShinyHuntersÍŻﰵʾ£¬£¬Õâ´Î¹¥»÷ÊÇÕë¶Ô100¶à¼Ò»ú¹¹µÄÖØÒªÉí·ÝÌṩÉÌSSOÕË»§ÌáÒéµÄ¸ü´ó¹æÄ£ÍøÂç´¹µö¹¥»÷µÄÒ»²¿ÃÅ£¬£¬ËûÃÇͨ¹ýMicrosoft Entra SSO´úÂë½Ó¼ûÁËPaneraµÄϵͳ¡£¡£Panera×÷ΪÃÀ¹ú³ÛÃûºæ±º¿§·ÈÁ¬Ëøµê£¬£¬³ÉÁ¢ÓÚ1987Ä꣬£¬Óµº±¼ûǧ¼Ò·Öµê£¬£¬×¨Ò»ÓÚ¿ì½ÝÐÝÏвÍÒûģʽ£¬£¬Õâ´ÎÊý¾Ýй¶ÊÂÎñÔÙ´ÎÒý·¢ÁË¶ÔÆäÊý¾Ý°²È«ÖÎÀíµÄ¹Ø×¢¡£¡£
https://securityaffairs.com/187556/data-breach/panera-bread-breach-affected-5-1-million-accounts-hibp-confirms.html
3. ¶íAPT28ÀûÓÃOffice·ì϶¶¨Ïò¹¥»÷ÎÚÅ·
2ÔÂ2ÈÕ£¬£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìӦС×飨CERT-UA£©Åû¶£¬£¬¶íÂÞ˹¹ú¶È¼¶ºÚ¿Í×éÖ¯APT28£¨±ðºÅFancy Bear¡¢¡¢Sofacy£¬£¬Óë¶í×ÜÕÕ·÷²¿µý±¨×ܾÖGRU¹ØÁª£©ÕýÀûÓÃ΢ÈíOfficeµÄÁãÈÕ·ì϶CVE-2026-21509ÌáÒé¹¥»÷¡£¡£Î¢ÈíÓÚ2026Äê1ÔÂ26ÈÕ°ä²¼´¹Î£´øÍⰲȫ¸üУ¬£¬ÏóÕ÷¸Ã·ì϶Ϊ¡°ÕýÔÚ±»»ý¼«ÀûÓá±µÄÁãÈÕ·ì϶¡£¡£½öÈýÌìºó£¬£¬CERT-UA±ã¼ì²âµ½ÒÔ¡°Å·ÃËפÎÚ¿ËÀ¼³£×¤´ú±íίԱ»áÐÉÌ¡±ÎªÖ÷ÌâµÄ¶ñÒâDOCÎļþ£¬£¬Í¬Ê±·¢ÏÖ¼ÙÒâÎÚ¿ËÀ¼Ë®ÎÄÐÎÏóÖÐÐĵĴ¹µöÓʼþ±»·¢ËÍÖÁ60Óà¸öµ±¾ÖÓйصØÖ·¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬ÓйضñÒâÎļþµÄÔªÊý¾ÝÏÔʾÆä´´½¨¹¦·òÇ¡ÔÚ΢Èí¸üа䲼ºóÒ»ÈÕ¡£¡£¹¥»÷¼¼ÊõÁ´ÏÔʾ£¬£¬´ò¿ª¶ñÒâÎĵµ»á´¥·¢»ùÓÚWebDAVµÄÏÂÔØÁ´£¬£¬Í¨¹ýCOM½Ù³Ö¡¢¡¢¶ñÒâDLL¡¢¡¢°µ²ØÔÚͼÏñÎļþÖеÄshellcode¼°´òË㹤×÷×°ÖöñÒâÈí¼þ¡£¡£CERT-UA»ã±¨Ö¸³ö£¬£¬´òË㹤×÷Ö´ÐлᵼÖÂexplorer.exe¹ý³ÌÖÕÖ¹²¢ÖØÆô£¬£¬È·±£¼ÓÔØ¶ñÒâDLL£¬£¬½ø¶ø´ÓͼÏñÎļþÖÐÖ´ÐÐshellcodeÒÔÆô¶¯COVENANT¿ò¼Ü¡£¡£¸Ã¿ò¼Ü´ËÇ°ÔøÔÚ2025Äê6ÔÂAPT28Õë¶ÔÎÚ¿ËÀ¼µ±¾Ö»ú¹¹µÄ¹¥»÷Öб»Ê¹Óᣡ£
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-recently-patched-microsoft-office-bug-in-attacks/
4. OpenClaw¿ªÔ´AIÖúÊÖÔâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷
2ÔÂ2ÈÕ£¬£¬¿ªÔ´AIÖúÊÖOpenClaw£¨Ô³ÆMoltbotºÍClawdBot£©µÄ¹Ù·½×¢²á±íClawHub¼°GitHubƽ̨Ôâ·ê´ó¹æÄ£¶ñÒâ¼¼Êõ¹¥»÷£¬£¬³¬230¸ö¼Ù×°³ÉºÏ·¨¹¤¾ßµÄ¶ñÒâÈí¼þ°ü±»°ä²¼¡£¡£ÕâЩ±»³Æ×÷"¼¼Êõ"µÄ²å¼þÒÔ¼ÓÃÜÇ®±ÒÂòÂô×Ô¶¯»¯¡¢¡¢½ðÈÚ¹¤¾ßµÈºÏ·¨Ö°ÄÜΪ»Ï×Ó£¬£¬ÏÖʵעÈë¶ñÒâÈí¼þÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý£¬£¬Ô̺¬APIÃÜÔ¿¡¢¡¢Ç®°ü˽Կ¡¢¡¢SSHƾ֤¡¢¡¢ä¯ÀÀÆ÷ÃÜÂë¼°.envÎļþµÈ¡£¡£°²È«×êÑÐÔ±Jamieson O'ReillyÖ¸³ö£¬£¬´óÁ¿OpenClawʵÀýÒòÅäÖò»µ±µ¼ÖÂÖÎÀí½çÃæÂ¶³öÓÚ¹«¹²ÍøÂç¡£¡£¹¥»÷ÕßÀûÓô˷ì϶£¬£¬Í¨¹ýÃûΪ"AuthTool"µÄ¶ñÒâÈí¼þ´«²¼¹¤¾ßÖ´ÐÐϰȾ¡£¡£ÉçÇø°²È«×éÖ¯OpenSourceMalware»ã±¨ÏÔʾ£¬£¬Õâ´Î¹¥»÷³öÏÖ¹æÄ£»¯Ìص㣬£¬´óÁ¿¶ñÒâ¼¼Êõ¿âÃû³Æ¸ß¶ÈÀàËÆ£¬£¬²¿ÃŰ汾ÏÂÔØÁ¿´ïÊýǧ´Î¡£¡£Koi SecurityɨÃèClawHubÈ«Êý2857¸ö¼¼Êõ¿âºó£¬£¬·¢ÏÖ341¸ö¶ñÒâ¼¼Êõ£¬£¬²¢×·×Ùµ½29¸öÕë¶ÔClawHubÓòÃûµÄƴдÃýÎó´¹µöÍøÕ¾¡£¡£ÎªÐÖúÓû§·ÀÓù£¬£¬Koi»¹°ä²¼ÁËÃâ·ÑÔÚÏßɨÃ蹤¾ß£¬£¬¿Éͨ¹ýURL¼ì²â¼¼Êõ°²È«ÐÔ¡£¡£
https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/
5.ÐÂÐÍÍøÂç´¹µöÚ¿ÆÀûÓÃPDF¸½¼þÇÔÈ¡Óû§Æ¾Ö¤
2ÔÂ2ÈÕ£¬£¬ForcepointÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶һÖÖÐÂÐͶà½×¶ÎÍøÂç´¹µöڿƼ¿Á©£¬£¬¸ÃÊÖ·¨Í¨¹ý¾«ÐÄÉè¼ÆµÄ¡°×¨ÒµÓʼþ+PDF¸½¼þ¡±×éºÏÈÆ¹ý´«Í³°²È«¹ýÂË£¬£¬×îÖÕÇÔÈ¡Óû§µÇ¼ƾ֤¡£¡£´ËÀàÚ¿ÆÓʼþͨ³£¼Ù×°³ÉóÒ׺Ïͬ¡¢¡¢Õбê»ò²É²É°ìÂôÓйØÍ¨Öª£¬£¬ÄÚÈÝ¿´ËÆÕý¹æÎÞº¦£¬£¬µ«¹Ø¼ü¶ñÒâÐÐΪ°µ²ØÔÚPDF¸½¼þÖС£¡£×êÑÐÏÔʾ£¬£¬Ú¿ÆÕßÀûÓÃPDFµÄAcroFormsºÍFlateDecode¼¼Êõ£¬£¬ÔÚ¿´ËÆÍ¨³£µÄ°ì¹«º¯µµÖÐǶÈë¿Éµã»÷°´Å¥¡£¡£Óû§µã»÷ºó£¬£¬»á±»Êèµ¼ÖÁµÚ¶þ¸öÍйÜÔÚVercel BlobÔÆ´æ´¢Æ½Ì¨ÉϵÄÎĵµ¡£¡£ÓÉÓÚVercelÊǺϷ¨ÔÆ·þÎñ£¬£¬ÕâÖÖ¡°¿ÉÐÅ»ù´¡ÉèÊ©¡±ÀûÓ÷½Ê½ÓÐЧ¶ã±ÜÁ˰²È«Èí¼þµÄÀ¹½Ø¡£¡£Ëæºó£¬£¬¸ÃÔÆÎĵµ»áÌø×ªÖÁαÔìµÄDropboxµÇÂ¼Ò³Ãæ£¬£¬Æä½çÃæÓëÕæÊµÒ³Ãæ¸ß¶ÈÀàËÆ£¬£¬ÓÕµ¼Óû§ÊäÈëÓÊÏä¡¢¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£ÔÚºó¶Ü£¬£¬¶ñÒâ¾ç±¾²»½öÇÔÈ¡Óû§Æ¾Ö¤£¬£¬»¹»á¼Í¼¾«È·µÄIPµØÖ·¡¢¡¢µØÀíµØÎ»¡¢¡¢É豸ÀàÐ͵ÈÀ©´óÐÅÏ¢¡£¡£±»µÁÊý¾Ýͨ¹ýÓ²±àÂ뷽ʽֱ½Ó·¢ËÍÖÁTelegramƽ̨µÄ¸öÈËÆµµÀ£¬£¬ÓɺڿͽÚÖÆµÄ»úеÈ˽ӹܡ£¡£
https://hackread.com/phishing-scam-emails-pdfs-steal-dropbox-logins/
6. È«ÇòÔÆ´æ´¢¶©ÔÄÚ¿Æ·ºÀÄ
1ÔÂ31ÈÕ£¬£¬´ÓǰÊýÔ£¬£¬Ò»³¡´ó¹æÄ£ÔÆ´æ´¢¶©ÔÄڿƻÔÚÈ«ÇòÁìÓòÄÚ³ÖÐøÊæÕ¹¡£¡£Ú¿Æ·Ö×Óͨ¹ý·¢ËÍ´óÁ¿¿ÖÏÅÓʼþ£¬£¬»Ñ³ÆÓû§Òò¡°Ö§¸¶Ê§°Ü¡±»ò¡°´æ´¢¿Õ¼ä²»¼°¡±µ¼ÖÂÕË»§½«±»¹Ø±Õ¡¢¡¢Îļþ½«±»É¾³ý£¬£¬ÒÔ´ËÖÆ×÷½ôÆÈ¸ÐÓÕµ¼Óû§µã»÷Á´½Ó¡£¡£ÓʼþÖеÄÁ´½Ó¾ùÖ¸Ïò¹È¸èÔÆ´æ´¢·þÎñÍйܵľ²Ì¬Öض¨ÏòHTMLÎļþ£¬£¬Óû§µã»÷ºó»á±»Ìø×ªÖÁËæ»úÓòÃûµÄ´¹µöÒ³Ãæ¡£¡£ÕâÐ©Ò³Ãæ¸ß¶È·ÂÕÕÖ÷Á÷ÔÆ·þÎñÉÌ£¨Èç¹È¸èÔÆ¡¢¡¢Î¢ÈíOneDrive£©µÄ¹Ù·½½çÃæ£¬£¬Ðû³ÆÓû§´æ´¢¿Õ¼äÒÑÂú£¬£¬ÕÕÆ¬¡¢¡¢ÊÓÆµ¡¢¡¢ÎĵµµÈÊý¾Ý½«ÖÕ³¡±¸·Ý²¢Ãæ¶Ôɾ³ý·çÏÕ£¬£¬ÓÕµ¼Óû§µã»÷¡°³ÖÐø¡±°´Å¥½øÈëÐéα´æ´¢¼ì²âÒ³Ãæ¡£¡£¸ÃÒ³ÃæÊ¼ÖÕÏÔʾ´æ´¢¿Õ¼äÕ¼Âú£¬£¬ÒªÇóÓû§Éý¼¶ÔÆ´æ´¢ÌײÍÒÔÏíÊÜ¡°ÀÏÓû§×¨Êô8ÕÛÓŻݡ±£¬£¬µ«ÏÖʵµã»÷Éý¼¶°´Å¥ºó£¬£¬Óû§»á±»Öض¨ÏòÖÁÁªÃËÓªÏúÒ³Ãæ£¬£¬ÍƹãVPN·þÎñ¡¢¡¢Ð¡ÖÚ°²È«Èí¼þµÈÎ޹زúÆ·£¬£¬×îÖÕÌø×ªÖÁ½áÕË±íµ¥ÍøÂçÓû§ÐÅÓþ¿¨ÐÅÏ¢£¬£¬Í¬Ê±ÎªÚ¿Æ·Ö×Ó׬ȡÁªÃËÓªÏúÓ¶½ð¡£¡£
https://www.bleepingcomputer.com/news/security/cloud-storage-payment-scam-floods-inboxes-with-fake-renewals/


¾©¹«Íø°²±¸11010802024551ºÅ