WindowsÄÚ´æÐ¶ñÒâÈí¼þ£ººÚ¿Íʵʱ͵ȡÊý×Ö×ʲú

Ðû²¼Ê±¼ä 2026-02-02

1. WindowsÄÚ´æÐ¶ñÒâÈí¼þ£ººÚ¿Íʵʱ͵ȡÊý×Ö×ʲú


1ÔÂ31ÈÕ£¬£¬£¬ £¬Point WildÆìÏÂLat61ÍþвÇ鱨ÍŶӿËÈÕ·¢Ã÷Ò»ÖÖÒþ²ØµÄÐÂÐÍWindows¶ñÒâÈí¼þ»î¶¯£¬£¬£¬ £¬¸Ã»î¶¯Ê¹ÓÃPulsar RATºÍStealerv37¹¤¾ß£¬£¬£¬ £¬Í¨¹ýÄÚ´æ×¤Áô·½·¨ÊµÑéÖÜÈ«Êý×ÖÈëÇÖ¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬ £¬¹¥»÷ʼÓÚ%APPDATA%\MicrosoftĿ¼ÏÂÒþ²ØµÄ΢ÐÍÎļþ£¬£¬£¬ £¬Ëæºó½ÓÄÉ"½èÁ¦´òÁ¦"ÊÖÒÕÐ®ÖÆÏµÍ³¿ÉÐŹ¤¾ßÈçPowerShell£¬£¬£¬ £¬ÍêÈ«ÔÚÄÚ´æÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬ £¬×èÖ¹¹Å°åÓ²ÅÌÎļþ²ÐÁô£¬£¬£¬ £¬´Ó¶øÈƹý»ù´¡É±¶¾Èí¼þ¼ì²â¡£¡£¡£¸Ã¶ñÒâÈí¼þ¾ß±¸Ë«ÖØÆÆËðÌØÕ÷£ºÒ»·½ÃæÍ¨¹ýDonut¹¤¾ß½«¶ñÒâ´úÂë×¢Èëexplorer.exeµÈÒ»Ñùƽ³£Àú³Ì£¬£¬£¬ £¬¼´±ã±»×èµ²Ò²»áÆô¶¯¼àÊÓ³ÌÐòʵÏÖÃë¼¶×Ô¶¯ÖØÆô£»£»£»£»£»£»£»ÁíÒ»·½Ãæ×Ô¶¯½ûÓÃʹÃüÖÎÀíÆ÷ºÍUACÇå¾²ÌáÐÑ£¬£¬£¬ £¬×è¶ÏÓû§»¹»÷ÇþµÀ¡£¡£¡£Æä½¹µãÄ¿µÄ¾Û½¹ÓÚÐÅÏ¢ÇÔÈ¡£¬£¬£¬ £¬Pulsar RAT¿ÉÔ¶³Ì²Ù¿ØÉãÏñÍ·ºÍÂó¿Ë·çʵÑé¼à¿Ø£¬£¬£¬ £¬¶øStealerv37ÔòרÃÅɨÃè¼ÓÃÜÇ®±ÒÇ®°ü¡¢¼à¿Ø¼ôÌù°å²¢Ìæ»»Ö§¸¶µØµãʵÑé×ʽð͵ȡ£¬£¬£¬ £¬Í¬Ê±ÇÔÈ¡Chrome/Edgeä¯ÀÀÆ÷ÃÜÂë¼°Cookie¡¢NordVPNµÈVPNƾ֤¡¢¿ª·¢Õß¹¤¾ßÊý¾Ý¼°Steam/RobloxµÈÓÎÏ·Õ˺Å¡£¡£¡£ËùÓÐÔßÎïÊý¾Ý¾ùͨ¹ýDiscord/TelegramͨµÀ´«Ê䏸ºÚ¿Í¡£¡£¡£


https://hackread.com/windows-malware-pulsar-rat-live-chats-steal-data/


2. StopICE³¬10ÍòÓû§ÐÅÏ¢ÔâÁª°î»ú¹¹»ñÈ¡


1ÔÂ31ÈÕ£¬£¬£¬ £¬·´ÒÆÃñÖ´·¨¾Ö£¨ICE£©»î¸ÐÈËʿƽ̨StopICE¿ËÈÕÔâÓöÖØ´óÇå¾²Îó²î£¬£¬£¬ £¬µ¼ÖÂÁè¼Ý10ÍòÃûÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¸ø°üÀ¨Áª°îÊÓ²ì¾Ö£¨FBI£©¡¢ÒÆÃñÖ´·¨¾Ö£¨ICE£©ºÍÁìÍÁÇå¾²ÊÓ²ì¾Ö£¨HSI£©ÔÚÄÚµÄÃÀ¹úÁª°î»ú¹¹¡£¡£¡£ºÚ¿ÍÉù³Æ»ñÈ¡ÁËÓû§µÄÐÕÃû¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢µç»°ºÅÂ뼰׼ȷGPS×ø±ê£¬£¬£¬ £¬²¢½«ÕâЩÊý¾ÝÖ±½Ó·¢Ë͸øÕþ¸®¡£¡£¡£´Ë´ÎÊÂÎñÒý·¢Óû§ºÍÇå¾²ÆÊÎöʦ¶ÔÊý¾Ý¹æÄ£¼°ÏêϸÐԵĵ£ÐÄ£¬£¬£¬ £¬Ð¹Â¶µÄGPS×ø±ê¿ÉÄÜ̻¶»î¸ÐÈËʿסËù»ò³£È¥ËùÔÚ£¬£¬£¬ £¬¶øµÇ¼ÐÅÏ¢Ôò¿ÉÄܱ»ÓÃÓÚ×·×ÙСÎÒ˽¼Ò»ò»á¼ûÆäËû¹ØÁªÕË»§£¬£¬£¬ £¬¼Ó¾ç·´ICE»î¸ÐÈËÊ¿ÃæÁÙµÄΣº¦¡£¡£¡£StopICEƽ̨ÓÉÖøÃûÎÞÕþ¸®Ö÷ÒåÕßл¶ûÂü¡¤°Â˹͡Ö÷µ¼ÔËÓª£¬£¬£¬ £¬¸Ãƽ̨¶¨Î»Îª¡°×èÖ¹ICEͻϮ¾¯±¨ÍøÂ硱£¬£¬£¬ £¬Í¨¹ýÖÚ°ü·½·¨ÍøÂç²¢Ðû²¼ICEÔÚÌìϹæÄ£ÄÚµÄÖ´·¨Ðж¯ÐÅÏ¢£¬£¬£¬ £¬°üÀ¨³µÁ¾ÑÛ¼û¼Í¼¡¢³µÅƺš¢Ê±¼ä´ÁºÍλÖ㬣¬£¬ £¬Ö¼ÔÚΪÈõÊÆÈºÌåÌṩִ·¨Ô¤¾¯¡¢Ö´·¨Ô®Öú¼°ÉçÇøÖ§³Ö×ÊÔ´¡£¡£¡£È»¶ø£¬£¬£¬ £¬Æ½Ì¨±£´æÐÅÈÎ¶ÈÆÀ·ÖµÍ¡¢ËùÓÐȨ²»Ã÷µÈÕùÒé¡£¡£¡£


https://www.ibtimes.co.uk/stopice-hacked-names-locations-over-100k-users-were-sent-fbi-ice-hsi-1775307


3. ÃϼÓÀ­ECÍøÕ¾¹ÊÕÏÖÂ1.4Íò¼ÇÕßÃô¸ÐÐÅϢй¶


1ÔÂ31ÈÕ£¬£¬£¬ £¬ÃϼÓÀ­¹úÑ¡¾ÙίԱ»á£¨EC£©×¨ÓÃÃÅ»§ÍøÕ¾pr.ecs.gov.bd±¬·¢ÖØ´óÊÖÒÕ¹ÊÕÏ£¬£¬£¬ £¬µ¼ÖÂÔ¼14000Ãû¼ÇÕßµÄÃô¸ÐСÎÒ˽¼ÒÊý¾Ýй¶¡£¡£¡£´Ë´ÎÐ¹Â¶Éæ¼°¹úÃñÉí·ÝÖ¤ºÅÂë¡¢ÊÖ»úºÅÂ뼰ýÌå´ÓÒµÖ°Ô±µÄÍêÕûÉêÇë±í¸±±¾£¬£¬£¬ £¬ÕâЩ¼ÇÕß´ËǰÒÑÔÚÏß×¢²áÉêÇë¼ÇÕßÖ¤ºÍ³µÁ¾ÌùÖ½£¬£¬£¬ £¬ÒÔ±¸¼´½«µ½À´µÄµÚÊ®Èý½ìÌìÏÂÒé»áÑ¡¾ÙºÍÈ«Ãñ¹«Í¶Ö®Óᣡ£¡£¸ÃÍøÕ¾Ô­Ö¼ÔÚͨ¹ýÏÖ´ú»¯Êֶμò»¯¼ÇÕßÖ¤ÉêÇëÁ÷³Ì£¬£¬£¬ £¬µ«¹ÊÕÏ̻¶ÁËÑÏÖØÇå¾²Òþ»¼¡£¡£¡£Ïêϸ¶øÑÔ£¬£¬£¬ £¬Óû§µÇÂ¼ÍøÕ¾ºó£¬£¬£¬ £¬Ê×Ò³»áÁ¬Ã¦ÏÔʾËùÓÐÉêÇëÈ˵ÄÍêÕûÃûµ¥£¬£¬£¬ £¬ÏµÍ³ÔÊÐíÈκÎÈË»á¼û²¢·­¿ªÍêÕûµÄÉêÇëÎļþ£¬£¬£¬ £¬´Ó¶øÐ¹Â¶Ë½ÈËÁªÏµ·½·¨ºÍÉí·ÝÖ¤ºÅÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£Îó²î±»·¢Ã÷ºó£¬£¬£¬ £¬ÍøÕ¾Ñ¸ËÙ±»½ûÓÃÒÔ±ÜÃâ½øÒ»²½Î´¾­ÊÚȨ»á¼û¡£¡£¡£Ñ¡¾ÙίԱ»á¹«¹²¹ØÏµ²¿·ÖÖ÷Èγºú¶û¡¤°¢Ã÷¡¤ÂíÀû¿ËÌåÏÖ£¬£¬£¬ £¬¸ÃÔÚÏßϵͳ±¾Ó¦ÓÚÖÜÎåÍ£Ó㬣¬£¬ £¬µ«ÈÏÕæÍøÕ¾ÖÎÀíµÄ¹ÙÔ±ÖÜÁùÏÂÖç¶ÌÔÝ¿ªÆôÁ˸ÃÍøÕ¾£¬£¬£¬ £¬µ¼ÖÂÊý¾Ýй¶¡£¡£¡£ËûÈ·ÈÏÍøÕ¾ÏÖÔÚÒÑÏÂÏߣ¬£¬£¬ £¬²¢Ç¿µ÷ÕýÔÚÊÓ²ìϵͳΪºÎÄÜÔÚ·ÇÔ¤ÆÚʱ¼ä±»»á¼û¡£¡£¡£


https://www.observerbd.com/news/564449


4. Arsink°²×¿Ä¾Âíαװ50ÓàÆ·ÅÆÈ«ÇòѬȾ³¬4.5Íò×°±¸


1ÔÂ30ÈÕ£¬£¬£¬ £¬Zimperium zLabsÑо¿Ö°Ô±¿ËÈÕ·¢Ã÷ÃûΪArsinkµÄΣÏÕ°²×¿Ä¾Âí£¬£¬£¬ £¬¸ÃľÂíαװ³ÉWhatsApp¡¢TikTokµÈ50Óà¸ö×ÅÃûÆ·ÅÆ£¬£¬£¬ £¬Í¨¹ýTelegram¡¢Discord¼°MediaFireµÈ·Ç¹Ù·½ÇþµÀÈö²¥£¬£¬£¬ £¬ÔÚÈ«Çò143¸ö¹ú¼ÒѬȾ³¬4.5Íǫ̀װ±¸£¬£¬£¬ £¬ÆäÖа£¼°£¨Ô¼1.3Íò£©¡¢Ó¡¶ÈÄáÎ÷ÑÇ£¨7000£©¡¢ÒÁÀ­¿Ë£¨3000£©ÎªÖØÔÖÇø¡£¡£¡£¸ÃľÂí½ÓÄÉ¡°×¨Òµ°æ¡±Ó¦ÓÃÏÝÚåÕ½ÂÔ£¬£¬£¬ £¬ÒÔÌṩÕý°æÓ¦ÓÃȱʧµÄÌØÊ⹦ЧΪÓÕ¶ü£¬£¬£¬ £¬ÓÕµ¼Óû§ÏÂÔØ¡£¡£¡£×°Öú󣬣¬£¬ £¬Ó¦ÓÃÁ¬Ã¦ÒªÇóÓû§ÊÚÓè´ó×ÚȨÏÞ£¬£¬£¬ £¬ËæºóÒþ²Ø×ÔÉíͼ±ê²¢ÔÚºǫ́ÔËÐУ¬£¬£¬ £¬²¿·Ö°æ±¾ÉõÖÁÄÚÖõڶþ¸ö¡°ÓÐÓÃÔØºÉ¡±£¬£¬£¬ £¬ÊµÏÖÀëÏßѬȾ¡£¡£¡£ArsinkÆô¶¯¡°Ò»Á¬ºǫ́ЧÀÍ¡±È·±£ÓÀ²»¹Ø±Õ£¬£¬£¬ £¬¾ß±¸Ô¶³Ì¿ØÖÆ¡¢Â¼Òô¼àÌý¡¢¶ÌÐÅÇÔÈ¡¡¢ÕÕÆ¬ÍµÈ¡¡¢ÁªÏµÈ˼°Í¨»°¼Í¼¶ÁÈ¡¡¢¹È¸èÕË»§ÓÊÏä»á¼ûµÈ¶ñÒ⹦Ч£¬£¬£¬ £¬¸ü¿ÉÇ¿ÖÆÊÖ»ú²¦´òµç»°¡¢×·×Ù׼ȷλÖ㬣¬£¬ £¬ÉõÖÁ¶Ô´æ´¢¿Õ¼ä¾ÙÐС°ÆÆËðÐÔ²Á³ý¡±¡£¡£¡£ËùÓÐÇÔÈ¡Êý¾Ýͨ¹ý317¸öÊý¾Ý¿âÈë¿Ú°üÀ¨Firebase¡¢Telegram»úеÈ˼°GoogleÔÆ¶ËÓ²ÅÌÒþ²ØÎļþ¼Ð»Ø´«ÖÁºÚ¿Í¡£¡£¡£


https://hackread.com/arsink-spyware-whatsapp-youtube-instagram-tiktok/


5. È«ÇòÁªºÏÖ´·¨µ·»Ù¹¤Òµ¼¶²»·¨IPTV·¸·¨ÍøÂç


1ÔÂ30ÈÕ£¬£¬£¬ £¬Å·ÖÞÐ̾¯×éÖ¯¡¢Å·ÖÞ˾·¨×éÖ¯Óë¹ú¼ÊÐ̾¯×éÖ¯ÁªºÏЭµ÷£¬£¬£¬ £¬ÓÉÒâ´óÀû¿¨ËþÄáÑÇÉó²é¹Ù°ì¹«ÊҺ͹ú¼Ò¾¯Ô±Ö÷µ¼µÄÈ«ÇòÖ´·¨Ðж¯£¬£¬£¬ £¬ÔÚ11¸ö¶¼»á14¸ö¹ú¼ÒÕö¿ª×îн׶ι¥»÷£¬£¬£¬ £¬ÖصãÕë¶ÔÒâ´óÀûÃ×À¼¶¬°Â»áʱ´ú²»·¨ÌåÓýÈüÊÂת²¥ÎÊÌâ¡£¡£¡£Ðж¯²é»ñÈý¼Ò¹¤Òµ¼¶²»·¨IPTVЧÀÍÉÌIPTVItalia¡¢migliorIPTVºÍDarkTV£¬£¬£¬ £¬²ð½âÆäÁýÕÖ°ÙÍò¼¶ÖÕ¶ËÓû§µÄÐÅÏ¢ÊÖÒÕ»ù´¡ÉèÊ©£¬£¬£¬ £¬È·ÈÏ31ÃûÉæ°¸Ö°Ô±£¬£¬£¬ £¬ÆäÖÐ11ÈËλÓÚÒâ´óÀû£¬£¬£¬ £¬ÆäÓàÂþÑÜÔÚÓ¢¹ú¡¢Î÷°àÑÀ¡¢ÂÞÂíÄáÑÇ¡¢¿ÆË÷ÎֵȵØ¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬ £¬¸Ã·¸·¨×éÖ¯²ã¼¶Ã÷È·£¬£¬£¬ £¬Í¨¹ý¼ÓÃÜÇ®±ÒÖ§¸¶¡¢¿Õ¿Ç¹«Ë¾Ï´Ç®µÈÊÖ¶ÎÌÓ±Üî¿Ïµ£¬£¬£¬ £¬Ã¿Ô²»·¨×¬Ç®Êý°ÙÍòÅ·Ôª¡£¡£¡£Æä²»·¨½ØÈ¡²¢ÖØÐ´«ÊäSky¡¢DAZN¡¢Mediaset¡¢Amazon Prime¡¢Netflix¡¢Paramount¡¢Disney+µÈƽ̨ÄÚÈÝ£¬£¬£¬ £¬ÇÖÕ¼°æÈ¨µÄͬʱʵÑéÅÌËã»úڲƭ¡¢Ðéα×ʲú¹ÒºÅµÈ·¸·¨ÐÐΪ¡£¡£¡£Òâ´óÀû¾¯·½Åû¶£¬£¬£¬ £¬½ö¸Ã¹ú¾ÍÓÐÖÁÉÙ250¼Ò¾­ÏúÉ̺Í10ÍòÓû§ÊÜÓ°Ï죬£¬£¬ £¬ÂÞÂíÄáÑDzð³ý6̨ЧÀÍÆ÷£¬£¬£¬ £¬·ÇÖÞÒàÓÐһ̨ЧÀÍÆ÷±»²é·â¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/operation-switch-off-dismantles-major-pirate-tv-streaming-services/


6. CISA½«Ivanti EPMM¸ßΣÎó²î¼ÓÈëKEVĿ¼


1ÔÂ30ÈÕ£¬£¬£¬ £¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕ½«Ivanti Endpoint Manager Mobile£¨EPMM£©µÄ´úÂë×¢ÈëÎó²î£¨CVE-2026-1281£¬£¬£¬ £¬CVSSÆÀ·Ö9.8£©ÄÉÈëÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔ¶³ÌÖ´ÐдúÂ룬£¬£¬ £¬×é³ÉÑÏÖØÇå¾²Íþв¡£¡£¡£Ivanti¹«Ë¾Ö¤ÊµÒѼà²âµ½Õë¶Ô¸ÃÎó²îµÄ¹¥»÷ÐÐΪ£¬£¬£¬ £¬µ«ÌåÏÖ½öÓÐÉÙÉÙÊý¿Í»§ÔÚÎó²îÅû¶ʱÊܵ½ÏÖʵʹÓᣡ£¡£Æ¾Ö¤Ç徲ͨ¸æ£¬£¬£¬ £¬Îó²îÔ´ÓÚIvanti EPMMµÄ´úÂë×¢ÈëȱÏÝ£¬£¬£¬ £¬¹¥»÷Õ߿ɽè´ËʵÏÖδ¾­ÈÏÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£IvantiÇ¿µ÷£¬£¬£¬ £¬SentryºÍIvanti Neurons MDM²úÆ·²»ÊÜ´ËÎó²îÓ°Ï죬£¬£¬ £¬ÔÆÐ§ÀͿͻ§Ò²Î´²¨¼°¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬¹«Ë¾ÕýÒ»Á¬ÊÓ²ìÊÂÎñϸ½Ú£¬£¬£¬ £¬ËäÉÐδ·¢Ã÷¿É¿¿ÈëÇÖ¼£Ï󣬣¬£¬ £¬µ«ÒÑÐû²¼ÊÖÒÕ²¹¶¡¡¢À©´ó¿Í»§Ö§³Ö¹æÄ££¬£¬£¬ £¬²¢ÓëÇå¾²ÏàÖúͬ°é¼°Ö´·¨²¿·ÖÕö¿ªÐ­×÷¡£¡£¡£ÒÀ¾Ý¾ßÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01ÒªÇ󣬣¬£¬ £¬Áª°î»ú¹¹ÐèÔÚ2026Äê2ÔÂ2ÈÕǰÍê³ÉÎó²îÐÞ¸´£¬£¬£¬ £¬ÒÔ½µµÍÖØ´óΣº¦¡£¡£¡£


https://securityaffairs.com/187488/security/u-s-cisa-adds-a-flaw-in-ivanti-epmm-to-its-known-exploited-vulnerabilities-catalog.html