TomirisÉý¼¶¶àÓïÑÔÎäÆ÷¿â£¬£¬£¬£¬£¬£¬¾«×¼¹¥»÷¶íÍâ½»»ú¹¹
Ðû²¼Ê±¼ä 2025-12-021. TomirisÉý¼¶¶àÓïÑÔÎäÆ÷¿â£¬£¬£¬£¬£¬£¬¾«×¼¹¥»÷¶íÍâ½»»ú¹¹
12ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù×îб¨¸æÕ¹ÏÖ£¬£¬£¬£¬£¬£¬ÃûΪTomirisµÄÍþвÐÐΪÕßÕý¶Ô¶íÂÞ˹Íâ½»²¿¡¢Õþ¸®¼ä×éÖ¯¼°ÖÐÑǹú¼Ò»ú¹¹ÌᳫսÂÔÐÔÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Æä½¹µãÄ¿µÄÊÇͨ¹ýÓã²æÊ½´¹ÂÚÓʼþ°²ÅŶàÓïÑÔ±àдµÄ¶ñÒâÈí¼þÄ£¿£¿£¿é£¬£¬£¬£¬£¬£¬»ñȡԶ³Ì»á¼ûȨÏÞ²¢½¨É賤ÆÚ»¯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯2025Äê¹¥»÷Á´ÏÔʾ£¬£¬£¬£¬£¬£¬³¬50%µÄÓÕ¶üÎļþ½ÓÄɶíÓï¼°ÖÐÑǹú¼Ò¹Ù·½ÓïÑÔ¶¨ÖÆ£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¼ÓÃÜRARÎļþ£¨½âѹÃÜÂëÖ±½ÓǶÈëÓʼþÕýÎÄ£©·Ö·¢Î±×°³ÉWordÎĵµµÄ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬ÔËÐкóÊÍ·ÅC/C++·´ÏòShell£¬£¬£¬£¬£¬£¬ÅþÁ¬C2ЧÀÍÆ÷ÏÂÔØAdaptixC2¿ò¼Ü£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÐÞ¸ÄWindows×¢²á±íʵÏÖ¶ñÒâÔØºÉ³¤ÆÚ»¯¡£¡£¡£¡£¡£¡£¡£TomirisµÄÕ½ÊõÑݱäÓÈΪÏÔÖø£¬£¬£¬£¬£¬£¬ÆäÈÕ񾮵ÈÔµØÊ¹ÓÃTelegram¡¢DiscordµÈ¹«¹²Ð§ÀÍ×÷ΪC2ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬½«¶ñÒâÁ÷Á¿ÓëÕýµ±Ð§ÀÍÁ÷Á¿»ìÏýÒÔ¹æ±Ü¼ì²â¡£¡£¡£¡£¡£¡£¡£Æä¶ñÒâÈí¼þÎäÆ÷¿âº¸ÇC#¡¢Rust¡¢Go¡¢PythonµÈ¶àÓïÑÔ±àдµÄ·´ÏòShell¡¢SOCKSÊðÀí¼°ºóÃųÌÐò¡£¡£¡£¡£¡£¡£¡£¶àÓïÑÔÄ£¿£¿£¿éµÄÎÞаÐÔ¡¢µÍ¿ÉÒÉÐÔÌØÕ÷¼°¶Ô¿ªÔ´¿ò¼ÜµÄʹÓ㬣¬£¬£¬£¬£¬Ê¹TomirisÄܹ»ÊµÏÖÒþ²ØµÄºã¾Ã³¤ÆÚ»¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html
2. ÈÕÀú¶©ÔÄÇ徲äµã£ºBitSightÆØ347¸ö¶ñÒâÓòÃûΣº¦
11ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾BitSight×îÐÂÑо¿Õ¹ÏÖ£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýͨ¹ýʹÓÃÊý×ÖÈÕÀú¶©ÔÄ»ù´¡ÉèʩʵÑé´ó¹æÄ£Éç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÈÕÀú¶©ÔĹ¦Ð§±¾ÓÃÓÚºÏÐ̳¡¾°£¬£¬£¬£¬£¬£¬ÈçÁãÊÛÉÌÍÆËÍ´ÙÏúÈÕÆÚ¡¢ÌåÓýлá¸üÐÂÈüÊÂÈճ̣¬£¬£¬£¬£¬£¬ÆäÔÊÐíµÚÈý·½Ð§ÀÍÆ÷Ö±½ÓÏòÓû§×°±¸Ìí¼ÓÊÂÎñ²¢·¢ËÍ֪ͨµÄÌØÕ÷£¬£¬£¬£¬£¬£¬È´±»¶ñÒâʹÓ㬣¬£¬£¬£¬£¬¹¥»÷ÕߴÍйÜÓÚÓâÆÚ»ò±»Ð®ÖÆÓòÃûµÄÐéãåÈÕÀú¶©ÔÄЧÀÍ£¬£¬£¬£¬£¬£¬ÓÕÆÓû§¶©ÔĺóÍÆËͺ¬¶ñÒâÁ´½Ó¡¢¸½¼þµÄÈÕÀúÎļþ£¬£¬£¬£¬£¬£¬´¥·¢´¹ÂÚ¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢JavaScript´úÂëÖ´ÐÐÉõÖÁAIÖúÊÖÀÄÓõÈΣº¦¡£¡£¡£¡£¡£¡£¡£Ñо¿Ê¼ÓÚÒ»¸ö±» ¡°Sinkhole¡± ÊÖÒÕ½ÓÊܵÄÓòÃû£¬£¬£¬£¬£¬£¬¸ÃÓòÃûÔÓÃÓÚ·Ö·¢µÂ¹ú¹«¹²¼ÙÆÚICSÎļþ£¬£¬£¬£¬£¬£¬È´ÖðÈÕÎüÊÕ1.1Íò¸ö×ÔÁ¦IP»á¼û£¬£¬£¬£¬£¬£¬Òý·¢Ñо¿ÍŶӹØ×¢¡£¡£¡£¡£¡£¡£¡£½øÒ»³ÌÐò²é·¢Ã÷347¸ö¿ÉÒÉÈÕÀúÓòÃû£¬£¬£¬£¬£¬£¬Éæ¼°2018Ììϱ¡¢ÒÁ˹À¼HijriÈÕÀúµÈÖ÷Ì⣬£¬£¬£¬£¬£¬ÖðÈÕÀÛ¼ÆÎüÊÕÔ¼400Íò´ÎÃÀ¹úΪÖ÷µÄÈ«ÃÀ»á¼ûÇëÇ󡣡£¡£¡£¡£¡£¡£³Á¶´Êý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬ÕâЩ»á¼û¶àΪÒѶ©ÔÄÓû§µÄºǫ́ͬ²½ÇëÇ󣬣¬£¬£¬£¬£¬Òâζ׎ÓÊÜÓâÆÚÓòÃûµÄ¹¥»÷Õß¿ÉÖ±½ÓÏòÓû§×°±¸ÍÆËͶ¨ÖÆ»¯¶ñÒâÈÕÀúÊÂÎñ¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/
3. PlayÀÕË÷Èí¼þ¹¥»÷ADC Aerospace
11ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úº½¿Õº½ÌìÓë¹ú·ÀÁìÓò¹¤³Ì²¿¼þÖÆÔìÉÌADC AerospaceÒòЧÀÍŵ˹ÂÞÆÕ¡¤¸ñ³Âü¡¢¿ÂÁÖ˹º½¿Õº½Ìì¡¢»ôÄáΤ¶ûµÈ×ÅÃûÆóÒµ£¬£¬£¬£¬£¬£¬³ÉΪÀÕË÷Èí¼þ¹¥»÷ÖØµãÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÓÉÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þ¼¯ÍÅÖ®Ò»PlayʵÑ飬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÔй¶¿Í»§Êý¾ÝΪҪЮÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð£¬£¬£¬£¬£¬£¬Èô¾Ü¾øÔòÐû²¼²¿·ÖÊý¾ÝƬ¶Ï¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÉù³ÆÒÑ»ñÈ¡¿Í»§Îļþ¡¢Ô¤Ëã²ÆÎñÐÅÏ¢¡¢Ð½×ʼͼ¡¢Éí·Ý֤ʵµÈ˽ÃÜÊý¾Ý£¬£¬£¬£¬£¬£¬µ«Î´ÌṩÑù±¾£¬£¬£¬£¬£¬£¬ÕæÊµÐÔ´ýºË²é¡£¡£¡£¡£¡£¡£¡£ÈôÊý¾Ýй¶Êôʵ£¬£¬£¬£¬£¬£¬ADC½«ÃæÁÙ¶àÖØÎ£º¦£º°µÍø¶Ô¹ú·À³Ð°üÉÌÊý¾ÝµÄ¸ßÐèÇó¿ÉÄÜÍÆ¶¯±»µÁÐÅÏ¢ÉúÒ⣻£»£»£»£»£»Ð½×ʼͼÖеÄСÎÒ˽¼ÒÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£»£»£»£»£»£»ÆäËû˽ÃÜÊý¾ÝÔò¿ÉÄܳÉΪÉç»á¹¤³Ì¹¥»÷¹¤¾ß£¬£¬£¬£¬£¬£¬¹¥»÷Õßð³äÐÐÒµÏà¹Ø·½ÊµÑé¸ü¾ßÆÆËðÐÔµÄÕ©Æ¡£¡£¡£¡£¡£¡£¡£Play¼¯ÍÅÈ¥ÄêõÒÉíÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þǰÈý£¬£¬£¬£¬£¬£¬½ñÄê8Ô³õ¸ÕÈëÇÖΪÃÀ¹úˮʦ¡¢²¨Òô¹©»õµÄJamco Aerospace¡£¡£¡£¡£¡£¡£¡£
https://cybernews.com/security/adc-aerospace-breach-claims/
4. CoupangÔâÓöº«¹úÊ·ÉÏ×î´ó¹æÄ£¿£¿£¿Í»§Êý¾Ýй¶ÊÂÎñ
11ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬±»ÓþΪ¡°º«¹úÑÇÂíÑ·¡±µÄº«¹úµçÉ̾ÞÍ·CoupangÓÚ11ÔÂ18ÈÕÅû¶һÆð´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬Ó°Ïì½ü3400Íò¸ö¿Í»§ÕË»§£¬£¬£¬£¬£¬£¬´´º«¹úµ¥´ÎÊý¾Ýй¶ӰÏì¹æÄ£Ö®×î¡£¡£¡£¡£¡£¡£¡£¾ÊӲ죬£¬£¬£¬£¬£¬¹¥»÷Õß×Ô6ÔÂ24ÈÕÆðͨ¹ýÍâÑóЧÀÍÆ÷Ìᳫδ¾ÊÚȨ»á¼û£¬£¬£¬£¬£¬£¬Öð²½À©´ó¹¥»÷¹æÄ££¬£¬£¬£¬£¬£¬×îÖÕµ¼Ö³¬3300Íòº«¹úÓû§Êý¾ÝÍâй¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç×ÓÓÊÏä¡¢µç»°ºÅÂë¡¢ÊÕ»õµØµã¼°²¿·Ö¶©µ¥¼Í¼£¬£¬£¬£¬£¬£¬µ«Ö§¸¶ÐÅÏ¢ÓëµÇ¼ƾ֤δ±»»ñÈ¡¡£¡£¡£¡£¡£¡£¡£CoupangÔÚ·¢Ã÷Òì³£ºóÁ¬Ã¦Ïòº«¹úСÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»£»£»¤Î¯Ô±»á¡¢¾¯·½¼°»¥ÁªÍøÇå¾²¾Ö±¨¸æ£¬£¬£¬£¬£¬£¬²¢Æô¶¯Ó¦¼±ÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¹«Ë¾×î³õÎóÅнöÔ¼4500ÈËÊÜÓ°Ï죬£¬£¬£¬£¬£¬ºóÐÞÕýΪ³¬3300ÍòÈË£¬£¬£¬£¬£¬£¬Í¹ÏÔ³õÆÚ¼ì²â»úÖÆµÄȱ·¦¡£¡£¡£¡£¡£¡£¡£º«¹úÕþ¸®¶Ô´Ë¸ß¶ÈÖØÊÓ£¬£¬£¬£¬£¬£¬¿ÆÑ§ÊÖÒÕÐÅϢͨѶ²¿²¿³¤ÅᾩѫÖÜÈÕÖ÷³Ö½ôÆÈ¾Û»á£¬£¬£¬£¬£¬£¬ºË²éCoupangÊÇ·ñÎ¥·´¡¶Ð¡ÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»£»£»¤·¨¡·Çå¾²¹æ·¶¡£¡£¡£¡£¡£¡£¡£º«¹ú»¥ÁªÍøÇå¾²ÕñÐËÔº£¨KISA£©ÒÑÏòÊÜÓ°ÏìÓû§Ðû²¼·À´¹ÂÚÕ©ÆÖ¸ÄÏ£¬£¬£¬£¬£¬£¬½¨Òé°´ÆÚÐÞ¸ÄÃÜÂë¡¢ÆôÓÃË«ÒòËØÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÒÑÒý·¢Óû§ÕûÌåËßËÏΣº¦£¬£¬£¬£¬£¬£¬CoupangÕýÃæÁÙÖ´·¨×·ÔðÓëÐÅÓþÖØ´´µÄË«ÖØÑ¹Á¦¡£¡£¡£¡£¡£¡£¡£
https://cybernews.com/news/coupang-confirms-massive-data-breach-exposing-33-7-million-accounts/
5. ¾¯·½²é·âÁËCryptomixer¼ÓÃÜÇ®±Ò»ìÏýЧÀÍ
12ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ÈðÊ¿ÓëµÂ¹úÖ´·¨²¿·Ö¿ËÈÕÁªºÏ¿ªÕ¹¡°°ÂÁÖÆ¥ÑÇÐж¯¡±£¬£¬£¬£¬£¬£¬ÓÚ11ÔÂ24ÈÕÖÁ28ÈÕÔÚËÕÀèÊÀ²é·â¼ÓÃÜÇ®±Ò»ìÏýЧÀÍCryptomixer¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨×Ô2016ÄêÔËÓªÒÔÀ´£¬£¬£¬£¬£¬£¬±»Ö¸ÐÖúÍøÂç·¸·¨·Ö×ÓÏ´Ç®³¬13ÒÚÅ·Ôª±ÈÌØ±Ò£¬£¬£¬£¬£¬£¬³ÉΪÀÕË÷Èí¼þÍŻ°µÍøÊг¡¼°µØÏ¾¼ÃÂÛ̳»ìÏý·¸·¨×ʽðµÄ½¹µãÇþµÀ¡£¡£¡£¡£¡£¡£¡£Ðж¯ÖУ¬£¬£¬£¬£¬£¬Ö´·¨»ú¹¹ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖÏ£¬£¬£¬£¬£¬£¬²é»ñÈý̨ЧÀÍÆ÷¡¢12TBÊý¾Ý¡¢Ã÷Íø¼°Tor°µÍøÓòÃû£¬£¬£¬£¬£¬£¬²¢¿ÛѺ¼ÛÖµ2400ÍòÅ·Ôª±ÈÌØ±Ò¡£¡£¡£¡£¡£¡£¡£Cryptomixerͨ¹ý»ìÊÊÓû§¼ÓÃÜÇ®±ÒÖÁ×Ê½ð³Ø²¢·Ö·¢ÖÁÐÂÇ®°üµØµã£¬£¬£¬£¬£¬£¬ÓÐÓÃ×è¶ÏÇø¿éÁ´×ʽð×·×Ù£¬£¬£¬£¬£¬£¬³ÉΪ··¶¾¡¢ÎäÆ÷×ß˽¡¢ÀÕË÷¹¥»÷¼°Ö§¸¶¿¨Ú²ÆµÈ·¸·¨»î¶¯µÄÏ´Ç®Ê×Ñ¡¹¤¾ß¡£¡£¡£¡£¡£¡£¡£ÆäÔËӪģʽ»¹°üÀ¨¶ÔÏ´Ç®×ʽðÊÕȡӶ½ð£¬£¬£¬£¬£¬£¬ÔÙ×ªÒÆÖÁ¿Í»§Ö¸¶¨Ç®°ü£¬£¬£¬£¬£¬£¬×îÖÕͨ¹ýÒøÐлòATM½«²»·¨×ʲúת»»Îª·¨±Ò»òÆäËû¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£´ËÀàЧÀÍËä±£´æÕýµ±ÓÃ;£¬£¬£¬£¬£¬£¬µ«Ö÷Òª±»·¸·¨ÍÅ»ïÓÃÓÚÌÓ±Ü×·²é¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/police-takes-down-cryptomixer-cryptocurrency-mixing-service/
6. CISA½«OpenPLC ScadaBRÎó²îÌí¼Óµ½KEVĿ¼ÖÐ
12ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕ½«±àºÅΪCVE-2021-26829µÄOpenPLC ScadaBRÎó²îÄÉÈëÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îΪ¿çÕ¾¾ç±¾£¨XSS£©Îó²î£¬£¬£¬£¬£¬£¬Í¨¹ýsystem_settings.shtmÎļþÓ°ÏìWindowsºÍLinux°æ±¾£¬£¬£¬£¬£¬£¬ÏêÏ¸Éæ¼°Windows¶Ë1.12.4¼°¸üÔç°æ±¾¡¢Linux¶Ë0.9.1¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ5.4¡£¡£¡£¡£¡£¡£¡£2025Äê9Ô£¬£¬£¬£¬£¬£¬Ç×¶íºÚ¿Í×éÖ¯TwoNetÕë¶ÔÍøÂçÇå¾²¹«Ë¾ForescoutÔËÓªµÄICS/OTÃÛ¹ÞϵͳÌᳫ¹¥»÷£¬£¬£¬£¬£¬£¬ÎóÅÐÆäΪˮ´¦Öóͷ£³§¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃĬÈÏÆ¾Ö¤»ñȡϵͳ»á¼ûȨÏ޺󣬣¬£¬£¬£¬£¬½¨ÉèÃûΪ¡°BARLATI¡±µÄÕË»§£¬£¬£¬£¬£¬£¬²¢Í¨¹ýCVE-2021-26829Îó²î¸Ä¶¯ÈË»ú½çÃæ£¨HMI£©µÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬Ã¿´Î»á¼û¸ÃÒ³ÃæÊ±£¬£¬£¬£¬£¬£¬»á´¥·¢°üÀ¨Ôà»°µÄµ¯´°ÖÒÑÔ£¬£¬£¬£¬£¬£¬Í¬Ê±½ûÓÃÈÕÖ¾ºÍ¾¯±¨¹¦Ð§¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¾ßÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01£¬£¬£¬£¬£¬£¬Áª°îÃñÓûú¹¹£¨FCEB£©ÐëÔÚ2025Äê12ÔÂ19ÈÕǰÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬ÒÔ½µµÍÖØ´óΣº¦¡£¡£¡£¡£¡£¡£¡£CISAͬʱ½¨Òé˽Ӫ»ú¹¹Éó²éKEVĿ¼£¬£¬£¬£¬£¬£¬ÊµÊ±ÐÞ²¹×ÔÉí»ù´¡ÉèÊ©ÖеÄͬÀàÎó²î£¬£¬£¬£¬£¬£¬±ÜÃⱻʹÓᣡ£¡£¡£¡£¡£¡£
https://securityaffairs.com/185185/security/u-s-cisa-adds-an-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html


¾©¹«Íø°²±¸11010802024551ºÅ