·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ
Ðû²¼Ê±¼ä 2025-12-251. ·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ
12ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö¿ËÈÕÐû²¼ÖÒÑÔ£¬£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×Ó×Ô2023ÄêÆðÒ»Á¬Ã°³äÖÝÕþ¸®¸ß¼¶¹ÙÔ±¡¢°×¹¬¹ÙÔ±¡¢ÄÚ¸ó³ÉÔ±¼°¹ú¾Û»áÔ±£¬£¬£¬£¬£¬Ê¹ÓöÌÐÅÓëÈ˹¤ÖÇÄÜÌìÉúµÄÓïÒôÐÅÏ¢£¬£¬£¬£¬£¬Õë¶Ô¹ÙÔ±¼ÒÈ˼°Ë½ÈËÊìÈËʵÑ龫׼թơ£¡£¡£¡£¡£´ËÀ๥»÷ͨ¹ý¡°¶ÌÐÅ´¹ÂÚ+ÓïÒô¿Ë¡¡±Ë«ÖØÊÖ¶ÎÕö¿ª£º·¸·¨·Ö×ÓÊ×ÏÈ·¢ËÍ¿´ËÆÀ´×ÔȨÍþ»ú¹¹µÄڲƶÌÐÅ£¬£¬£¬£¬£¬Ëæºó²¦´òAIÌìÉúµÄÓïÒôµç»°»òÁôÏÂÓïÒôÁôÑÔ£¬£¬£¬£¬£¬ÒÔÌÖÂÛÊìϤ»°ÌâΪÓÕ¶ü£¬£¬£¬£¬£¬Ñ¸ËÙÒªÇóÊܺ¦Õß×ªÒÆÖÁSignal¡¢Telegram¡¢WhatsAppµÈ¼ÓÃÜÒÆ¶¯Ó¦ÓþÙÐнøÒ»²½Ïàͬ¡£¡£¡£¡£¡£ÔÚ¼ÓÃÜÓ¦ÓÃÖУ¬£¬£¬£¬£¬¹¥»÷Õß»áͨ¹ý̸ÂÛÊ±ÊÆ¡¢Ë«±ß¹ØÏµ£¬£¬£¬£¬£¬»òÐé¹¹¡°¶Ê»áÌáÃû¡±¡°°²ÅÅÓë×ÜͳÅöÃæ¡±µÈ³¡¾°½¨ÉèÐÅÈΣ¬£¬£¬£¬£¬½ø¶øË÷ÒªÑéÖ¤ÂëÒÔͬ²½ÁªÏµÈËÁÐ±í¡¢»ñÈ¡»¤ÕÕµÈÃô¸ÐÎļþ¸±±¾¡¢ÒªÇóÏòÍâÑó½ðÈÚ»ú¹¹»ã¿î£¬£¬£¬£¬£¬»òÓÕµ¼ÏÈÈÝͬ»ï¡£¡£¡£¡£¡£GetReal SecurityÍþвÑо¿Ö÷¹ÜÌÀÄ·¡¤¿ËÂÞ˹ָ³ö£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýʹÓÃÉî¶ÈαÔìÊÖÒÕʵÑéÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬£¬½öÐè30ÃëÓïÒôÑù±¾¼´¿Éͨ¹ýAIÓïÒô¿Ë¡¸ß¶È±ÆÕæÄ£ÄâËûÈË£¬£¬£¬£¬£¬¶ø¹«Ö°Ö°Ô±ºÍ¸ß¹ÜµÄÓïÒôÑù±¾¼«Ò×ͨ¹ý¹ûÕæÇþµÀ»ñÈ¡¡£¡£¡£¡£¡£
https://cybernews.com/news/criminals-impersonate-senior-us-officials-in-messaging-scams/
2. ƴд¹ýʧÓòÃûÒý·¢Cosmali Loader¶ñÒâÈí¼þѬȾ
12ÔÂ24ÈÕ£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬ÍøÂçÇå¾²ÁìÓòÆØ³öÒ»ÒòÓÉÓòÃûƴд¹ýʧµ¼ÖµĶñÒâÈí¼þѬȾÊÂÎñ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÓû§ÊäÈëÊèºö£¬£¬£¬£¬£¬ÇÀ×¢Óë΢Èí¼¤»î¾ç±¾£¨MAS£©¹Ù·½ÓòÃû¸ß¶ÈÏàËÆµÄÓòÃû¡°get.activate[.]win¡±£¬£¬£¬£¬£¬½ö±È¹Ù·½ÓòÃû¡°get.activated.win¡±ÉÙÒ»¸ö×Öĸ¡°d¡±£¬£¬£¬£¬£¬ÓÕµ¼Óû§»á¼û²¢Ö´ÐжñÒâPowerShell¾ç±¾£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂWindowsϵͳ±»¡°Cosmali Loader¡±¶ñÒâÈí¼þѬȾ¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬£¬£¬¶àÃûMASÓû§ÒÑÔÚRedditƽ̨±¨¸æÏµÍ³·ºÆðCosmali LoaderѬȾµÄµ¯³öÖÒÑÔ¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±RussianPandaÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ØÖÆÃæ°å±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì»á¼ûÊܺ¦ÕßÅÌËã»ú£¬£¬£¬£¬£¬²¢°²ÅżÓÃÜÇ®±ÒÍڿ󹤾߼°XWormÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£¡£¡£¡£¡£GDATA¶ñÒâÈí¼þÆÊÎöʦKarsten Hahn´ËǰҲ·¢Ã÷¹ýÀàËÆµ¯³ö֪ͨ£¬£¬£¬£¬£¬½øÒ»²½Ö¤Êµ´Ë´ÎÊÂÎñÓ뿪ԴCosmali Loader¶ñÒâÈí¼þ±£´æ¹ØÁª¡£¡£¡£¡£¡£MAS×÷Ϊ¿ªÔ´PowerShell¾ç±¾ÜöÝÍ£¬£¬£¬£¬£¬Í¨¹ýHWID¼¤»î¡¢KMSÄ£ÄâµÈÊÖÒÕʵÏÖWindows¼°OfficeµÄ×Ô¶¯¼¤»î£¬£¬£¬£¬£¬µ«Î¢ÈíÃ÷È·½«ÆäÊÓΪµÁ°æ¹¤¾ß£¬£¬£¬£¬£¬ÒòÆä½ÓÄÉδÊÚȨÊÖ¶ÎÈÆ¹ýÔÊÐíϵͳ¡£¡£¡£¡£¡£ÏîĿά»¤ÕßÒÑÏòÓû§·¢³öÖÒÑÔ£¬£¬£¬£¬£¬Ç¿µ÷Ö´ÐÐÏÂÁîǰÐè×ÐϸºË¶ÔÓòÃûƴд£¬£¬£¬£¬£¬×èÖ¹ÒòÊäÈë¹ýʧ»á¼û¶ñÒâÓòÃû¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fake-mas-windows-activation-domain-used-to-spread-powershell-malware/
3. FBI²é·âweb3adspanels[.]orgÓòÃû
12ÔÂ24ÈÕ£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©²é·âÁËÓòÃû¡°web3adspanels[.]org¡±¼°ÆäÊý¾Ý¿â£¬£¬£¬£¬£¬¸ÃÓòÃû±»·¸·¨ÍÅ»ïÓÃÓÚ´æ´¢ºÍ¸Ä¶¯´ÓÃÀ¹úÊܺ¦Õß´¦ÇÔÈ¡µÄÒøÐеǼƾ֤£¬£¬£¬£¬£¬½ø¶øÊµÑé´ó¹æÄ£ÒøÐÐÕË»§µÁÓÃÕ©Æ¡£¡£¡£¡£¡£¾Ý˾·¨²¿Åû¶£¬£¬£¬£¬£¬¸Ã·¸·¨ÍÅ»ïͨ¹ýÔڹȸ衢±ØÓ¦µÈËÑË÷ÒýÇæÍ¶·ÅÐéα¹ã¸æ£¬£¬£¬£¬£¬Ä£ÄâÕæÊµÒøÐÐ¹ã¸æÓÕµ¼Óû§µã»÷¡£¡£¡£¡£¡£Êܺ¦Õßµã»÷ºó»á±»Öض¨ÏòÖÁÓÉ·¸·¨·Ö×Ó¿ØÖƵÄÚ²ÆÍøÕ¾£¬£¬£¬£¬£¬µ±Óû§ÊäÈëÒøÐеǼƾ֤ʱ£¬£¬£¬£¬£¬ÍøÕ¾ÉϵĶñÒâÈí¼þ»áÁ¬Ã¦ÇÔÈ¡ÕâЩÐÅÏ¢¡£¡£¡£¡£¡£·¸·¨·Ö×ÓËæºóʹÓÃÇÔÈ¡µÄƾ֤µÇÂ¼ÕæÊµÒøÐÐÍøÕ¾£¬£¬£¬£¬£¬ÍµÈ¡ÕË»§×ʽ𡣡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬¸ÃÓòÃû×÷Ϊºó¶ËÍøÂçÃæ°å£¬£¬£¬£¬£¬ÍйÜÁËÊýǧ¸ö±»µÁµÄÒøÐеǼƾ֤£¬£¬£¬£¬£¬²¢Ò»Á¬ÔËÓªÖÁ2025Äê11Ô¡£¡£¡£¡£¡£°®É³ÄáÑÇÕþ¸®ÒÑÉúÑIJ¢ÍøÂçÁËÍйܴ¹ÂÚÒ³ÃæµÄЧÀÍÆ÷Êý¾Ý¼°±»µÁƾ֤£¬£¬£¬£¬£¬ÎªºóÐøÊÓ²ìÌṩҪº¦Ö¤¾Ý¡£¡£¡£¡£¡£FBIÈ·ÈÏ£¬£¬£¬£¬£¬ÖÁÉÙ19ÃûÃÀ¹úÊܺ¦ÕßÒò¸ÃȦÌ×ËðʧԼ1460ÍòÃÀÔª£¬£¬£¬£¬£¬²¢ÃæÁÙ2800ÍòÃÀÔªµÄδËìËðʧ¡£¡£¡£¡£¡£
https://securityaffairs.com/186094/cyber-crime/fbi-seized-web3adspanels-org-hosting-stolen-logins.html
4. MongoDB½ôÆÈͨ¸æ¸ßΣRCEÎó²îÐèÁ¬Ã¦ÐÞ¸´
12ÔÂ24ÈÕ£¬£¬£¬£¬£¬MongoDB¿ËÈÕÐû²¼½ôÆÈÇ徲ͨ¸æ£¬£¬£¬£¬£¬ÖÒÑÔITÖÎÀíÔ±±ØÐèÁ¬Ã¦ÐÞ¸´±àºÅΪCVE-2025-14847µÄ¸ßΣÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìMongoDB 8.2.0ÖÁ8.2.3¡¢8.0.0ÖÁ8.0.16¡¢7.0.0ÖÁ7.0.26¡¢6.0.0ÖÁ6.0.26¡¢5.0.0ÖÁ5.0.31¡¢4.4.0ÖÁ4.4.29¼°ËùÓÐv4.2¡¢v4.0¡¢v3.6°æ±¾£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÌᳫµÍÖØÆ¯ºóÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£¡£Îó²îȪԴÔÚÓÚMongoDBЧÀÍÆ÷¶Ô³¤¶È²ÎÊýµÄ·×ÆçÖ´¦Öóͷ£»úÖÆ£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸Ä¶¯zlibѹËõʵÏÖÖеÄÊý¾Ý°ü£¬£¬£¬£¬£¬´¥·¢Î´³õʼ»¯µÄ¶ÑÄÚ´æ»á¼û£¬£¬£¬£¬£¬½ø¶øÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£MongoDBÇå¾²ÍŶÓÇ¿µ÷£¬£¬£¬£¬£¬¸ÃÎó²îÒѾ߱¸±»´ó¹æÄ£Ê¹ÓõÄÌõ¼þ£¬£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±Á¬Ã¦Éý¼¶ÖÁÒÑÐÞ¸´°æ±¾£º8.2.3¡¢8.0.17¡¢7.0.28¡¢6.0.27¡¢5.0.32»ò4.4.30¡£¡£¡£¡£¡£ÈôÎÞ·¨Á¬Ã¦Éý¼¶£¬£¬£¬£¬£¬ÐèÔÚÆô¶¯mongod/mongosʱͨ¹ýnetworkMessageCompressors»ònet.compression.compressors²ÎÊýÏÔʽ½ûÓÃzlibѹËõ¹¦Ð§¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-rce-flaw-immediately/
5. MarquisÔâºÚ¿Í¹¥»÷Ö¶à¼ÒÒøÐпͻ§Êý¾Ýй¶
12ÔÂ24ÈÕ£¬£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬£¬Á½¼ÒÃÀ¹úÒøÐÐVeraBankºÍArtisans' BankÏà¼ÌÅû¶ÒòµÚÈý·½¹©Ó¦ÉÌMarquis Software SolutionsÔâÊܺڿ͹¥»÷£¬£¬£¬£¬£¬µ¼Ö´ó×Ú¿Í»§ÐÅϢй¶¡£¡£¡£¡£¡£×ܲ¿Î»Óڵ¿ËÈøË¹ÖݵÄVeraBank͸¶£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñÓ°Ïì37,318Ãû¿Í»§£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¼°ÆäËûδÃ÷ȷ˵Ã÷µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬Ïêϸй¶ÄÚÈÝÒò¿Í»§¶øÒì¡£¡£¡£¡£¡£ÌØÀ»ªÖݵÄArtisans' BankÔòÌåÏÖ£¬£¬£¬£¬£¬32,344Ãû¿Í»§µÄÐÕÃûºÍÉç»á°ü¹ÜºÅÂë¿ÉÄÜÔâδ¾ÊÚȨ»á¼û¡£¡£¡£¡£¡£Á½¼ÒÒøÐоùÇ¿µ÷£¬£¬£¬£¬£¬¹¥»÷½öÏÞÓÚMarquisϵͳ£¬£¬£¬£¬£¬Æä×ÔÉíϵͳδÊÜÓ°Ïì¡£¡£¡£¡£¡£Marquis·½ÃæÌåÏÖ£¬£¬£¬£¬£¬ÒѾÍ8ÔÂ14ÈÕ±¬·¢µÄÊý¾Ýй¶ÊÂÎñÕö¿ªÄÚ²¿ÊӲ첢ִ֪ͨ·¨²¿·Ö¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Artisans' BankÖ±ÖÁ10ÔÂÏÂÑ®²Å»ñϤ´ËÊ£¬£¬£¬£¬£¬½üÆÚ²ÅÒâʶµ½¿Í»§ÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£11Ô£¬£¬£¬£¬£¬Å²Íþ´¢±¸ÒøÐУ¨NSB£©ÔøÒòMarquisÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂ51,000Ãû¿Í»§ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂ롢˰ÎñʶÓÖÃûÂë¼°²ÆÎñÕË»§ÐÅÏ¢µÈÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£
https://cybernews.com/news/bank-marquis-software-vendor-attack/
6. Evasive PandaÕë¶Ô¶à¹úʵÑé¾«×¼ÉøÍ¸
12ÔÂ25ÈÕ£¬£¬£¬£¬£¬¿¨°Í˹»ùʵÑéÊÒ¿ËÈÕÐû²¼±¨¸æ£¬£¬£¬£¬£¬½ÒÆÆÎÛÃûÕÑÖøµÄÍøÂçÌØ¹¤×éÖ¯Evasive PandaÔÚ2022Äê11ÔÂÖÁ2024Äê11ÔÂʱ´ú£¬£¬£¬£¬£¬Õë¶ÔÖйú¡¢Ó¡¶È¼°ÍÁ¶úÆäÌᳫÐÂÒ»ÂÖÖØ´ó¹¥»÷¡£¡£¡£¡£¡£¸Ã×éÖ¯×Ô2012ÄêÆð»îÔ¾£¬£¬£¬£¬£¬Í¨¹ýDNSÐ®ÖÆ¡¢ÖÐÐÄÈ˹¥»÷£¨AitM£©¼°Î±×°Èí¼þ¸üеÈÊֶΣ¬£¬£¬£¬£¬Èö²¥±ê¼ÇÐÔºóÃųÌÐòMgBot£¬£¬£¬£¬£¬ÊµÏÖºã¾ÃϵͳפÁôÓëÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£¹¥»÷Á´ÌõʼÓÚÈ«ÐÄÉè¼ÆµÄ¡°Õýµ±Î±×°¡±£º¹¥»÷Õßð³äËѺüÊÓÆµ¡¢°®ÆæÒÕÊÓÆµ¡¢IObit Smart Defrag¼°ÌÚѶQQµÈÈÈÃÅÈí¼þµÄ¸üгÌÐò£¬£¬£¬£¬£¬ÔÚÕýµ±×°ÖÃÎļþ¼ÐÖÐÖ²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬ÓÉÊÜÐÅÈÎϵͳЧÀÍÖ´ÐС£¡£¡£¡£¡£¸üÒþ²ØµÄÊÇ£¬£¬£¬£¬£¬×é֯ʹÓÃAitMÊÖÒÕÐ®ÖÆÍøÂçÁ÷Á¿£¬£¬£¬£¬£¬Í¨¹ý¸Ä¶¯DNSÏìÓ¦£¬£¬£¬£¬£¬½«Óû§¶Ôdictionary.comµÄ»á¼ûÖØ¶¨ÏòÖÁ¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷£¬£¬£¬£¬£¬ÒÔαװ³ÉPNGÎļþµÄ¼ÓÃÜshellcodeÐÎʽ¼ÓÔØµÚ¶þ½×¶ÎÓÐÓÃÔØºÉ¡£¡£¡£¡£¡£ÕâÖÖ»ùÓÚµØÀíλÖúÍISPµÄ¶¨ÏòͶ·ÅÕ½ÂÔ£¬£¬£¬£¬£¬Ê¹¹¥»÷¼«¾ßÕë¶ÔÐÔÇÒÄÑÒÔÔÚʵÑéÊÒ¸´ÏÖ¡£¡£¡£¡£¡£Ð¿ª·¢µÄ¼ÓÔØÆ÷αװ³ÉWindows¿âÎļþ£¬£¬£¬£¬£¬Í¨¹ýDLL²à¼ÓÔØÊÖÒÕ½«MgBot×¢Èësvchost.exeµÈϵͳÀú³Ì£¬£¬£¬£¬£¬ÉõÖÁʹÓÃÊ®ÄêǰµÄÊðÃû¿ÉÖ´ÐÐÎļþÌӱܼì²â¡£¡£¡£¡£¡£
https://securityonline.info/evasive-panda-apt-hijacks-dictionary-com-and-app-updates-in-two-year-spree/


¾©¹«Íø°²±¸11010802024551ºÅ