·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­

Ðû²¼Ê±¼ä 2025-12-25

1. ·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­


12ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö¿ËÈÕÐû²¼ÖÒÑÔ£¬£¬£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×Ó×Ô2023ÄêÆðÒ»Á¬Ã°³äÖÝÕþ¸®¸ß¼¶¹ÙÔ±¡¢°×¹¬¹ÙÔ±¡¢ÄÚ¸ó³ÉÔ±¼°¹ú¾Û»áÔ±£¬£¬£¬£¬£¬£¬Ê¹ÓöÌÐÅÓëÈ˹¤ÖÇÄÜÌìÉúµÄÓïÒôÐÅÏ¢£¬£¬£¬£¬£¬£¬Õë¶Ô¹ÙÔ±¼ÒÈ˼°Ë½ÈËÊìÈËʵÑ龫׼թƭ¡£¡£¡£¡£ ¡£´ËÀ๥»÷ͨ¹ý¡°¶ÌÐÅ´¹ÂÚ+ÓïÒô¿Ë¡¡±Ë«ÖØÊÖ¶ÎÕö¿ª£º·¸·¨·Ö×ÓÊ×ÏÈ·¢ËÍ¿´ËÆÀ´×ÔȨÍþ»ú¹¹µÄڲƭ¶ÌÐÅ£¬£¬£¬£¬£¬£¬Ëæºó²¦´òAIÌìÉúµÄÓïÒôµç»°»òÁôÏÂÓïÒôÁôÑÔ£¬£¬£¬£¬£¬£¬ÒÔÌÖÂÛÊìϤ»°ÌâΪÓÕ¶ü£¬£¬£¬£¬£¬£¬Ñ¸ËÙÒªÇóÊܺ¦Õß×ªÒÆÖÁSignal¡¢Telegram¡¢WhatsAppµÈ¼ÓÃÜÒÆ¶¯Ó¦ÓþÙÐнøÒ»²½Ïàͬ¡£¡£¡£¡£ ¡£ÔÚ¼ÓÃÜÓ¦ÓÃÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õß»áͨ¹ý̸ÂÛÊ±ÊÆ¡¢Ë«±ß¹ØÏµ£¬£¬£¬£¬£¬£¬»òÐé¹¹¡°¶­Ê»áÌáÃû¡±¡°°²ÅÅÓë×ÜͳÅöÃæ¡±µÈ³¡¾°½¨ÉèÐÅÈΣ¬£¬£¬£¬£¬£¬½ø¶øË÷ÒªÑéÖ¤ÂëÒÔͬ²½ÁªÏµÈËÁÐ±í¡¢»ñÈ¡»¤ÕÕµÈÃô¸ÐÎļþ¸±±¾¡¢ÒªÇóÏòÍâÑó½ðÈÚ»ú¹¹»ã¿î£¬£¬£¬£¬£¬£¬»òÓÕµ¼ÏÈÈÝͬ»ï¡£¡£¡£¡£ ¡£GetReal SecurityÍþвÑо¿Ö÷¹ÜÌÀÄ·¡¤¿ËÂÞ˹ָ³ö£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýʹÓÃÉî¶ÈαÔìÊÖÒÕʵÑéÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬£¬£¬½öÐè30ÃëÓïÒôÑù±¾¼´¿Éͨ¹ýAIÓïÒô¿Ë¡¸ß¶È±ÆÕæÄ£ÄâËûÈË£¬£¬£¬£¬£¬£¬¶ø¹«Ö°Ö°Ô±ºÍ¸ß¹ÜµÄÓïÒôÑù±¾¼«Ò×ͨ¹ý¹ûÕæÇþµÀ»ñÈ¡¡£¡£¡£¡£ ¡£


https://cybernews.com/news/criminals-impersonate-senior-us-officials-in-messaging-scams/


2. ƴд¹ýʧÓòÃûÒý·¢Cosmali Loader¶ñÒâÈí¼þѬȾ


12ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²ÁìÓòÆØ³öÒ»ÒòÓÉÓòÃûƴд¹ýʧµ¼ÖµĶñÒâÈí¼þѬȾÊÂÎñ¡£¡£¡£¡£ ¡£¹¥»÷ÕßʹÓÃÓû§ÊäÈëÊèºö£¬£¬£¬£¬£¬£¬ÇÀ×¢Óë΢Èí¼¤»î¾ç±¾£¨MAS£©¹Ù·½ÓòÃû¸ß¶ÈÏàËÆµÄÓòÃû¡°get.activate[.]win¡±£¬£¬£¬£¬£¬£¬½ö±È¹Ù·½ÓòÃû¡°get.activated.win¡±ÉÙÒ»¸ö×Öĸ¡°d¡±£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§»á¼û²¢Ö´ÐжñÒâPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂWindowsϵͳ±»¡°Cosmali Loader¡±¶ñÒâÈí¼þѬȾ¡£¡£¡£¡£ ¡£¾Ý±¨µÀ£¬£¬£¬£¬£¬£¬¶àÃûMASÓû§ÒÑÔÚRedditƽ̨±¨¸æÏµÍ³·ºÆðCosmali LoaderѬȾµÄµ¯³öÖÒÑÔ¡£¡£¡£¡£ ¡£Çå¾²Ñо¿Ô±RussianPandaÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ØÖÆÃæ°å±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì»á¼ûÊܺ¦ÕßÅÌËã»ú£¬£¬£¬£¬£¬£¬²¢°²ÅżÓÃÜÇ®±ÒÍڿ󹤾߼°XWormÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£¡£¡£¡£ ¡£GDATA¶ñÒâÈí¼þÆÊÎöʦKarsten Hahn´ËǰҲ·¢Ã÷¹ýÀàËÆµ¯³ö֪ͨ£¬£¬£¬£¬£¬£¬½øÒ»²½Ö¤Êµ´Ë´ÎÊÂÎñÓ뿪ԴCosmali Loader¶ñÒâÈí¼þ±£´æ¹ØÁª¡£¡£¡£¡£ ¡£MAS×÷Ϊ¿ªÔ´PowerShell¾ç±¾ÜöÝÍ£¬£¬£¬£¬£¬£¬Í¨¹ýHWID¼¤»î¡¢KMSÄ£ÄâµÈÊÖÒÕʵÏÖWindows¼°OfficeµÄ×Ô¶¯¼¤»î£¬£¬£¬£¬£¬£¬µ«Î¢ÈíÃ÷È·½«ÆäÊÓΪµÁ°æ¹¤¾ß£¬£¬£¬£¬£¬£¬ÒòÆä½ÓÄÉδÊÚȨÊÖ¶ÎÈÆ¹ýÔÊÐíϵͳ¡£¡£¡£¡£ ¡£ÏîĿά»¤ÕßÒÑÏòÓû§·¢³öÖÒÑÔ£¬£¬£¬£¬£¬£¬Ç¿µ÷Ö´ÐÐÏÂÁîǰÐè×ÐϸºË¶ÔÓòÃûƴд£¬£¬£¬£¬£¬£¬×èÖ¹ÒòÊäÈë¹ýʧ»á¼û¶ñÒâÓòÃû¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/fake-mas-windows-activation-domain-used-to-spread-powershell-malware/


3. FBI²é·âweb3adspanels[.]orgÓòÃû


12ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©²é·âÁËÓòÃû¡°web3adspanels[.]org¡±¼°ÆäÊý¾Ý¿â£¬£¬£¬£¬£¬£¬¸ÃÓòÃû±»·¸·¨ÍÅ»ïÓÃÓÚ´æ´¢ºÍ¸Ä¶¯´ÓÃÀ¹úÊܺ¦Õß´¦ÇÔÈ¡µÄÒøÐеǼƾ֤£¬£¬£¬£¬£¬£¬½ø¶øÊµÑé´ó¹æÄ£ÒøÐÐÕË»§µÁÓÃÕ©Æ­¡£¡£¡£¡£ ¡£¾Ý˾·¨²¿Åû¶£¬£¬£¬£¬£¬£¬¸Ã·¸·¨ÍÅ»ïͨ¹ýÔڹȸ衢±ØÓ¦µÈËÑË÷ÒýÇæÍ¶·ÅÐéα¹ã¸æ£¬£¬£¬£¬£¬£¬Ä£ÄâÕæÊµÒøÐÐ¹ã¸æÓÕµ¼Óû§µã»÷¡£¡£¡£¡£ ¡£Êܺ¦Õßµã»÷ºó»á±»Öض¨ÏòÖÁÓÉ·¸·¨·Ö×Ó¿ØÖƵÄÚ²Æ­ÍøÕ¾£¬£¬£¬£¬£¬£¬µ±Óû§ÊäÈëÒøÐеǼƾ֤ʱ£¬£¬£¬£¬£¬£¬ÍøÕ¾ÉϵĶñÒâÈí¼þ»áÁ¬Ã¦ÇÔÈ¡ÕâЩÐÅÏ¢¡£¡£¡£¡£ ¡£·¸·¨·Ö×ÓËæºóʹÓÃÇÔÈ¡µÄƾ֤µÇÂ¼ÕæÊµÒøÐÐÍøÕ¾£¬£¬£¬£¬£¬£¬ÍµÈ¡ÕË»§×ʽ𡣡£¡£¡£ ¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬¸ÃÓòÃû×÷Ϊºó¶ËÍøÂçÃæ°å£¬£¬£¬£¬£¬£¬ÍйÜÁËÊýǧ¸ö±»µÁµÄÒøÐеǼƾ֤£¬£¬£¬£¬£¬£¬²¢Ò»Á¬ÔËÓªÖÁ2025Äê11Ô¡£¡£¡£¡£ ¡£°®É³ÄáÑÇÕþ¸®ÒÑÉúÑIJ¢ÍøÂçÁËÍйܴ¹ÂÚÒ³ÃæµÄЧÀÍÆ÷Êý¾Ý¼°±»µÁƾ֤£¬£¬£¬£¬£¬£¬ÎªºóÐøÊÓ²ìÌṩҪº¦Ö¤¾Ý¡£¡£¡£¡£ ¡£FBIÈ·ÈÏ£¬£¬£¬£¬£¬£¬ÖÁÉÙ19ÃûÃÀ¹úÊܺ¦ÕßÒò¸ÃȦÌ×ËðʧԼ1460ÍòÃÀÔª£¬£¬£¬£¬£¬£¬²¢ÃæÁÙ2800ÍòÃÀÔªµÄδËìËðʧ¡£¡£¡£¡£ ¡£


https://securityaffairs.com/186094/cyber-crime/fbi-seized-web3adspanels-org-hosting-stolen-logins.html


4. MongoDB½ôÆÈͨ¸æ¸ßΣRCEÎó²îÐèÁ¬Ã¦ÐÞ¸´


12ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬MongoDB¿ËÈÕÐû²¼½ôÆÈÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÖÒÑÔITÖÎÀíÔ±±ØÐèÁ¬Ã¦ÐÞ¸´±àºÅΪCVE-2025-14847µÄ¸ßΣÎó²î¡£¡£¡£¡£ ¡£¸ÃÎó²îÓ°ÏìMongoDB 8.2.0ÖÁ8.2.3¡¢8.0.0ÖÁ8.0.16¡¢7.0.0ÖÁ7.0.26¡¢6.0.0ÖÁ6.0.26¡¢5.0.0ÖÁ5.0.31¡¢4.4.0ÖÁ4.4.29¼°ËùÓÐv4.2¡¢v4.0¡¢v3.6°æ±¾£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÌᳫµÍÖØÆ¯ºóÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£ ¡£Îó²îȪԴÔÚÓÚMongoDBЧÀÍÆ÷¶Ô³¤¶È²ÎÊýµÄ·×ÆçÖ´¦Öóͷ£»úÖÆ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸Ä¶¯zlibѹËõʵÏÖÖеÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬´¥·¢Î´³õʼ»¯µÄ¶ÑÄÚ´æ»á¼û£¬£¬£¬£¬£¬£¬½ø¶øÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£MongoDBÇå¾²ÍŶÓÇ¿µ÷£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒѾ߱¸±»´ó¹æÄ£Ê¹ÓõÄÌõ¼þ£¬£¬£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±Á¬Ã¦Éý¼¶ÖÁÒÑÐÞ¸´°æ±¾£º8.2.3¡¢8.0.17¡¢7.0.28¡¢6.0.27¡¢5.0.32»ò4.4.30¡£¡£¡£¡£ ¡£ÈôÎÞ·¨Á¬Ã¦Éý¼¶£¬£¬£¬£¬£¬£¬ÐèÔÚÆô¶¯mongod/mongosʱͨ¹ýnetworkMessageCompressors»ònet.compression.compressors²ÎÊýÏÔʽ½ûÓÃzlibѹËõ¹¦Ð§¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-rce-flaw-immediately/


5. MarquisÔâºÚ¿Í¹¥»÷Ö¶à¼ÒÒøÐпͻ§Êý¾Ýй¶


12ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬£¬Á½¼ÒÃÀ¹úÒøÐÐVeraBankºÍArtisans' BankÏà¼ÌÅû¶ÒòµÚÈý·½¹©Ó¦ÉÌMarquis Software SolutionsÔâÊܺڿ͹¥»÷£¬£¬£¬£¬£¬£¬µ¼Ö´ó×Ú¿Í»§ÐÅϢй¶¡£¡£¡£¡£ ¡£×ܲ¿Î»Óڵ¿ËÈøË¹ÖݵÄVeraBank͸¶£¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñÓ°Ïì37,318Ãû¿Í»§£¬£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¼°ÆäËûδÃ÷ȷ˵Ã÷µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬Ïêϸй¶ÄÚÈÝÒò¿Í»§¶øÒì¡£¡£¡£¡£ ¡£ÌØÀ­»ªÖݵÄArtisans' BankÔòÌåÏÖ£¬£¬£¬£¬£¬£¬32,344Ãû¿Í»§µÄÐÕÃûºÍÉç»á°ü¹ÜºÅÂë¿ÉÄÜÔâδ¾­ÊÚȨ»á¼û¡£¡£¡£¡£ ¡£Á½¼ÒÒøÐоùÇ¿µ÷£¬£¬£¬£¬£¬£¬¹¥»÷½öÏÞÓÚMarquisϵͳ£¬£¬£¬£¬£¬£¬Æä×ÔÉíϵͳδÊÜÓ°Ïì¡£¡£¡£¡£ ¡£Marquis·½ÃæÌåÏÖ£¬£¬£¬£¬£¬£¬ÒѾÍ8ÔÂ14ÈÕ±¬·¢µÄÊý¾Ýй¶ÊÂÎñÕö¿ªÄÚ²¿ÊӲ첢ִ֪ͨ·¨²¿·Ö¡£¡£¡£¡£ ¡£È»¶ø£¬£¬£¬£¬£¬£¬Artisans' BankÖ±ÖÁ10ÔÂÏÂÑ®²Å»ñϤ´ËÊ£¬£¬£¬£¬£¬£¬½üÆÚ²ÅÒâʶµ½¿Í»§ÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£ ¡£11Ô£¬£¬£¬£¬£¬£¬Å²Íþ´¢±¸ÒøÐУ¨NSB£©ÔøÒòMarquisÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂ51,000Ãû¿Í»§ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂ롢˰ÎñʶÓÖÃûÂë¼°²ÆÎñÕË»§ÐÅÏ¢µÈÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£ ¡£


https://cybernews.com/news/bank-marquis-software-vendor-attack/


6. Evasive PandaÕë¶Ô¶à¹úʵÑé¾«×¼ÉøÍ¸


12ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬¿¨°Í˹»ùʵÑéÊÒ¿ËÈÕÐû²¼±¨¸æ£¬£¬£¬£¬£¬£¬½ÒÆÆÎÛÃûÕÑÖøµÄÍøÂçÌØ¹¤×éÖ¯Evasive PandaÔÚ2022Äê11ÔÂÖÁ2024Äê11ÔÂʱ´ú£¬£¬£¬£¬£¬£¬Õë¶ÔÖйú¡¢Ó¡¶È¼°ÍÁ¶úÆäÌᳫÐÂÒ»ÂÖÖØ´ó¹¥»÷¡£¡£¡£¡£ ¡£¸Ã×éÖ¯×Ô2012ÄêÆð»îÔ¾£¬£¬£¬£¬£¬£¬Í¨¹ýDNSÐ®ÖÆ¡¢ÖÐÐÄÈ˹¥»÷£¨AitM£©¼°Î±×°Èí¼þ¸üеÈÊֶΣ¬£¬£¬£¬£¬£¬Èö²¥±ê¼ÇÐÔºóÃųÌÐòMgBot£¬£¬£¬£¬£¬£¬ÊµÏÖºã¾ÃϵͳפÁôÓëÊý¾ÝÇÔÈ¡¡£¡£¡£¡£ ¡£¹¥»÷Á´ÌõʼÓÚÈ«ÐÄÉè¼ÆµÄ¡°Õýµ±Î±×°¡±£º¹¥»÷Õßð³äËѺüÊÓÆµ¡¢°®ÆæÒÕÊÓÆµ¡¢IObit Smart Defrag¼°ÌÚѶQQµÈÈÈÃÅÈí¼þµÄ¸üгÌÐò£¬£¬£¬£¬£¬£¬ÔÚÕýµ±×°ÖÃÎļþ¼ÐÖÐÖ²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬ÓÉÊÜÐÅÈÎϵͳЧÀÍÖ´ÐС£¡£¡£¡£ ¡£¸üÒþ²ØµÄÊÇ£¬£¬£¬£¬£¬£¬×é֯ʹÓÃAitMÊÖÒÕÐ®ÖÆÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬£¬Í¨¹ý¸Ä¶¯DNSÏìÓ¦£¬£¬£¬£¬£¬£¬½«Óû§¶Ôdictionary.comµÄ»á¼ûÖØ¶¨ÏòÖÁ¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÒÔαװ³ÉPNGÎļþµÄ¼ÓÃÜshellcodeÐÎʽ¼ÓÔØµÚ¶þ½×¶ÎÓÐÓÃÔØºÉ¡£¡£¡£¡£ ¡£ÕâÖÖ»ùÓÚµØÀíλÖúÍISPµÄ¶¨ÏòͶ·ÅÕ½ÂÔ£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷¼«¾ßÕë¶ÔÐÔÇÒÄÑÒÔÔÚʵÑéÊÒ¸´ÏÖ¡£¡£¡£¡£ ¡£Ð¿ª·¢µÄ¼ÓÔØÆ÷αװ³ÉWindows¿âÎļþ£¬£¬£¬£¬£¬£¬Í¨¹ýDLL²à¼ÓÔØÊÖÒÕ½«MgBot×¢Èësvchost.exeµÈϵͳÀú³Ì£¬£¬£¬£¬£¬£¬ÉõÖÁʹÓÃÊ®ÄêǰµÄÊðÃû¿ÉÖ´ÐÐÎļþÌӱܼì²â¡£¡£¡£¡£ ¡£


https://securityonline.info/evasive-panda-apt-hijacks-dictionary-com-and-app-updates-in-two-year-spree/