¼ÓÃÜÆ½Ì¨AbracadabraÔâºÚ¿Í¹¥»÷£¬½ü1300ÍòÃÀÔª±»µÁ
Ðû²¼Ê±¼ä 2025-03-261. ¼ÓÃÜÆ½Ì¨AbracadabraÔâºÚ¿Í¹¥»÷£¬½ü1300ÍòÃÀÔª±»µÁ
3ÔÂ26ÈÕ£¬¼ÓÃÜÇ®±Ò½è´ûƽ̨Abracadabra FinanceÓÚÖܶþÔ糿ÔâÊܺڿ͹¥»÷£¬ÆðÔ´¹ÀËãËðʧԼ1300ÍòÃÀÔªµÄÊý×Ö×ʲú¡£¾Ý¸Ã¹«Ë¾É罻ýÌåÉùÃ÷£¬´Ë´ÎÇå¾²Îó²îÔ´ÓÚÆä"cauldrons"ÁæØê½è´ûÊг¡²úÆ·£¬¸Ã²úÆ·ÔÊÐíÓû§ÒÔ¶àÀàÐͼÓÃÜ×ʲú×÷ΪµäÖʾÙÐнè´û²Ù×÷¡£Ö»¹Üÿ¸ö½è´ûºÏÔ¼¾ùͨ¹ýÇå¾²É󼯹«Ë¾GuardianÉóºË£¬ÇÒ°²ÅŶà²ã·À»¤»úÖÆ£¬µ«¹¥»÷ÕßÈÔͨ¹ýδÅû¶µÄÊÖÒÕÎó²îÍê³É¶à±Ê¶ñÒâÉúÒâ¡£ÏÖÔÚÆ½Ì¨ÊÖÒÕÍŶÓÕýÓëGuardian¼°Çø¿éÁ´ÆÊÎö»ú¹¹ChainalysisÏàÖú×·×Ù±»µÁ×ʽð£¬Í¬Ê±Ðû²¼Ç°¶Ë·þÎñÔÝÍ£²¢Æô¶¯Ó¦¼±ÏìÓ¦Á÷³Ì¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ºÚ¿Í¹¥»÷×ʽðȪԴ±»Ö¸ÓëÈ¥ÖÐÐÄ»¯ÉúÒâËùGMX±£´æ¹ØÁª£¬µ«GMXÒÑͨ¹ý¹Ù·½ÇþµÀ³ÎÇåÆäÖÇÄܺÏԼδÊÜÓ°Ï죬ǿµ÷±¾´ÎÊÂÎñÓëÆäµäÖÊÆ·´ú±Ò·þÎñÎ޹ء£Çå¾²ÆÊÎö»ú¹¹Ö¸³ö£¬ºÚ¿ÍʹÓà Tornado Cash »ìÏýÆ÷×ªÒÆÔ߿¶ø¸Ã·þÎñÉÏÖܸÕÒòÃÀ¹ú˾·¨²¿×÷·ÏÖÆ²Ã»Ö¸´ÔË×÷¡£Îª¾¡¿ì×·»Ø×ʽð£¬AbracadabraÐû²¼¶Ô·µ»¹±»µÁ×ʲúµÄ¹¥»÷ÕßÌṩ20%µÄÉͽð¼¤Àø£¬Õ¹ÏÖ³öÐÐÒµÓ¦¶ÔÇ徲Σ»úµÄµä·¶Õ½ÂÔ¡£
https://therecord.media/nearly-thirteen-million-stolen-abracadabra
2. Cloudflare R2·þÎñÖÐÖ¹£¬Òòƾ֤¹ýʧÖÂÈ«ÇòдÈëʧ°Ü
3ÔÂ25ÈÕ£¬CloudflareÆìÏÂR2¹¤¾ß´æ´¢·þÎñ½üÆÚ±¬·¢Ò»Á¬1Сʱ7·ÖÖÓµÄÖÐÖ¹ÊÂÎñ£¬µ¼ÖÂÈ«Çò¹æÄ£ÄÚдÈë²Ù×÷Íêȫʧ°Ü£¬¶ÁÈ¡ÀÖ³ÉÂʽµÖÁ65%¡£×÷Ϊ¼æÈÝS3ÐÒéµÄ¿ÉÀ©Õ¹´æ´¢½â¾ö¼Æ»®£¬R2¼¯³ÉÃâ·ÑÊý¾Ý¼ìË÷Óë¶àÇøÓò¸´Öƹ¦Ð§£¬´Ë´Î¹ÊÕÏÖ÷ÒªÔ´ÓÚÆ¾Ö¤ÂÖ»»Á÷³ÌÖеÄÈËΪ²Ù×÷ʧÎó¡£ÊÖÒÕÊÓ²ìÏÔʾ£¬ÔËάÍŶÓÔÚ¸üÐÂÉí·ÝÑé֤ƾ֤ʱ£¬ÒòÒÅ©"--env production"ÏÂÁîÐвÎÊý£¬Îó½«ÐÂÆ¾Ö¤°²ÅÅÖÁ¿ª·¢ÇéÐζø·ÇÉú²úϵͳ¡£µ±¾Éƾ֤°´ÍýÏëʧЧºó£¬Éú²úÇéÐÎR2Íø¹ØÒòȱ·¦ÓÐÓÃÆ¾Ö¤Ëðʧ¶Ô´æ´¢»ù´¡ÉèÊ©µÄ»á¼ûȨÏÞ¡£ÓÉÓÚÆ¾Ö¤Ê§Ð§±£´æÈö²¥ÑÓ³Ù£¬·þÎñ½µ¼¶³õÆÚδ´¥·¢¼´Ê±¸æ¾¯£¬½øÒ»²½ÑÓ»ºÁ˹ÊÕÏ·¢Ã÷Óë´¦Öóͷ£Àú³Ì¡£´Ë´ÎÊÂÎñËäδÔì³ÉÊý¾Ýɥʧ£¬µ«Òý·¢Á¬Ëø·´Ó¦£º»º´æÔ¤Áô·þÎñÒò¶Áȡʧ°Üµ¼ÖÂÔ´Õ¾Á÷Á¿¼¤Ôö£¬Í¼Ïñ´«ÊäЧÂÊϽµ75%£¬Á÷ýÌå´«ÊäÂÊÖè½µÖÁ6%£¬ÓʼþÇå¾²¡¢ÈÕÖ¾´«ÊäµÈ¹ØÁª·þÎñ¾ù·ºÆð²î±ðˮƽ½µ¼¶¡£Õë¶Ô̻¶µÄÁ÷³ÌȱÏÝ£¬CloudflareÒѽÓÄÉˢв½·¥¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬ÕâÊÇR2·þÎñÄêÄÚµÚ¶þ´ÎÒòÈËΪ¹ýʧµ¼Ö·þÎñÖÐÖ¹¡£
https://www.bleepingcomputer.com/news/security/cloudflare-r2-service-outage-caused-by-password-rotation-error/
3. ÂíÀ´Î÷ÑÇ»ú³¡ÔâÍøÂç¹¥»÷ÀÕË÷£¬×ÜÀí¾Ü¸¶Êê½ðº´ÎÀÇå¾²
3ÔÂ26ÈÕ£¬ÂíÀ´Î÷ÑǼªÂ¡ÆÂ¹ú¼Ê»ú³¡£¨KLIA£©ÔâÓöµÄÍøÂçϵͳ¹ÊÕϱ»Ö¤ÊµÎªÍøÂç¹¥»÷ËùÖ£¬ÊÂÎñÒý·¢Õþ¸®¸ß²ã½éÈë¼°¹ú¼ÊÇå¾²¹Ø×¢¡£¾ÝÂíÀ´Î÷Ñǹú¼ÒÍøÂçÇå¾²¾Ö£¨NACSA£©Óë»ú³¡ÖÎÀí·½ÍŽáÉùÃ÷£¬¹¥»÷ʼÓÚ3ÔÂ23ÈÕ£¬Ä¿µÄÖ±Ö¸ÈÏÕæÌìÏ´󶼻ú³¡ÔËÓªµÄÂíÀ´Î÷ÑÇ»ú³¡¿Ø¹ÉÓÐÏÞ¹«Ë¾£¨MAHB£©£¬ºÚ¿ÍË÷Òª1000ÍòÃÀÔªÊê½ð¡£×ÜÀí°²Íß¶û¡¤Òײ·ÀÐÀÔÚ¹ûÕæÑݽ²ÖÐǿӲÁÁÏà¾Ü¾øÍ×У¬Ç¿µ÷"¹ú¼Ò¾ø²î³Ø·¸·¨Í×Ð"µÄ̬¶È£¬Í¬Ê±Î´Åû¶¹¥»÷×éÖ¯Éí·Ý£¬ÒàÎÞÕûÌå¹ûÕæÈÏÔð¡£Ö»¹Ü¹Ù·½ÉùÃ÷³Æ»ú³¡ÔËÓª"δÊÜÓ°Ïì"£¬µ«Ç°ÒéÔ±»Æ×æÇ¿Åû¶µÄÕÕÆ¬ÏÔʾ£¬ÏµÍ³¹ÊÕÏÒ»Á¬³¬10Сʱ£¬µ¼Öº½°àÐÅÏ¢¡¢Öµ»ú¼°ÐÐÀîϵͳ̱»¾£¬ÊÂÇéÖ°Ô±±»ÆÈʹÓðװåÊÖ¹¤¼Í¼º½°àÐÅÏ¢¡£ÕâÖÖÔʼӦ¼±ÊÖ¶ÎÓë¹ú¼Ê»ú³¡µÄÏÖ´ú»¯¶¨Î»ÐγÉÇ¿ÁÒ·´²î£¬Òý·¢¹«ÖÚ¶ÔÊÂÎñ͸Ã÷¶ÈµÄÖÊÒÉ¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬´Ë´Î¹¥»÷ÓëÈ«ÇòÀÕË÷Èí¼þÍÅ»ï½üÆÚÕë¶Ô½»Í¨ÊàŦµÄ÷缯Ðж¯ÐγɺôÓ¦¡£¾Ý±¨µÀ£¬ÒÑÍù°ëÄêÄÚ£¬Î÷ÑÅͼ¡¢ÈÕ±¾¼°Ä«Î÷¸ç¹ú¼Ê»ú³¡½ÓÁ¬ÔâÀÕË÷Èí¼þÏ®»÷£¬·´Ó¦³öÒªº¦»ù´¡ÉèÊ©Õý³ÉÎªÍøÂç·¸·¨µÄ¸ß¼ÛֵĿµÄ¡£
https://therecord.media/malaysia-pm-says-country-rejected-ransom-demand-airport-cyberattack
4. ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯¶Ô¶íÂÞ˹»¥ÁªÍøÌṩÉÌLovitµÄÍøÂç¹¥»÷ÈÏÕæ
3ÔÂ25ÈÕ£¬ÎÚ¿ËÀ¼Ãñ¼äºÚ¿Í×éÖ¯¡°IT Army¡±Ðû³Æ¶Ô¶íÂÞ˹»¥ÁªÍø·þÎñÉÌLovitÌá³«ÍøÂç¹¥»÷£¬µ¼ÖÂĪ˹¿Æ¼°Ê¥±ËµÃ±¤µØÇøÒ»Á¬ÈýÌìµÄ·þÎṉ̃»¾¡£´Ë´ÎÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷ʼÓÚÉÏÖÜÎ壬²»µ«Ê¹ÒÀÀµLovitÍøÂçµÄ¹«Ô¢Â¥ÃŽûϵͳʧЧ£¬¸üµ¼ÖÂÉ̼ÒÖ§¸¶Öն˺ͻáԱϵͳÖÜÈ«¹ÊÕÏ¡£¶íÂÞË¹ÍøÂçî¿Ïµ»ú¹¹Roskomnadzor֤ʵ¹¥»÷Ô´Éæ¼°ÃÀ¡¢µÂ¡¢ÈðµäµÈ¶à¹ú·þÎñÆ÷¼°½©Ê¬ÍøÂ磬ֱָLovitÒªº¦»ù´¡ÉèÊ©£¬Ì»Â¶³ö¸Ã¹«Ë¾¶Ô´ó¹æÄ£ÍøÂç¹¥»÷µÄ·ÀÓù×¼±¸È±·¦¡£×÷Ϊ¶íÂÞ˹×î´óµØ²úÉÌPIKÆìÏÂ×¡Õ¬ÇøµÄ¶À¼ÒÍøÂ繩ӦÉÌ£¬Lovitºã¾Ã¢¶ÏְλÒý·¢ÃñÖÚ²»Âú¡£´Ë´Î¹¥»÷ºó£¬ÊÜÓ°ÏìסÃñÕý×¼±¸Ïò·´Â¢¶Ï»ú¹¹Ìá½»ÕûÌåËßËÏ£¬Ö¸¿ØÆä¶¨¼Û¹ý¸ßÇÒ×è°Êг¡¾ºÕù¡£ÍøÂçÇå¾²ÆóÒµVisumÆÊÎöÖ¸³ö£¬¹¥»÷Ñ¡ÔñLovit»òÒòÆäÁýÕ֯ձ飬¸ÃÍøÂçͬʱ·þÎñÒ½Ôº¡¢Ñ§Ð£µÈ¹«¹²ÉèÊ©£¬µ¼ÖÂÁ¬ËøÓ°Ïì¡£ÖµµÃ×¢ÖØµÄÊÇ£¬Õë¶Ô¶íÂÞ˹µçÐÅÐÐÒµµÄÍøÂç¹¥»÷½üÆÚ·ºÆðÕþÖλ¯¡¢¸ßƵ»¯Ç÷ÊÆ¡£´ËÀ๥»÷²»µ«Ä¥Á·Òªº¦ÐÅÏ¢»ù´¡ÉèÊ©·À»¤ÄÜÁ¦£¬¸ü·´Ó¦³öÍøÂç¿Õ¼äÒѳÉΪµØÔµ³åÍ»µÄÐÂÕ½³¡¡£
https://therecord.media/russia-isp-lovit-outages-claimed-ukraine-it-army
5. ¡¶·´¿Ö¾«Ó¢2¡·Íæ¼ÒÔâBitB´¹ÂÚ¹¥»÷£¬SteamÕË»§ÍµÈ¡Î£º¦Éý¼¶
3ÔÂ25ÈÕ£¬Õë¶ÔÈÈÃŵ羺ÓÎÏ·¡¶·´¿Ö¾«Ó¢2¡·Íæ¼ÒµÄÐÂÐÍÍøÂç´¹ÂÚ¹¥»÷½üÆÚ¸¡ÏÖ£¬¹¥»÷Õß½ÓÄÉ"ä¯ÀÀÆ÷ÄÚä¯ÀÀÆ÷"£¨BitB£©ÊÖÒÕ¹¹½¨¸ß·ÂÕæ´¹ÂÚÒ³Ãæ¡£¸Ã¹¥»÷ʹÓÃ2022ÄêÅû¶µÄBitB¿ò¼Ü£¬ÄÜÔÚÕæÊµä¯ÀÀÆ÷´°¿ÚÖÐǶÌ×ÐéαµÇ¼½çÃæ£¬¾«×¼Ä£ÄâSteam¹Ù·½µÇ¼ҳ£¬ÉõÖÁ¿É×Ô½ç˵URLºÍ´°¿ÚÎÊÌâÒÔÔöÇ¿ÓÕÆÐÔ¡£¹¥»÷Õßð³äÎÚ¿ËÀ¼¶¥¼¶µç¾ºÕ½¶ÓNaviʵÑ龫׼´¹ÂÚ£¬Í¨¹ýYouTubeÊÓÆµ¼°Î±×°³É"Ãâ·ÑCS2Ƥ·ôÁìÈ¡"µÄ¶ñÒâÍøÕ¾ÒýÁ÷¡£¾Çå¾²Ñо¿Ô±×·×Ù£¬¶à¸ö´¹ÂÚÍøÕ¾¹²ÏíÏàͬIPµØµã£¬Åú×¢±£´æ×éÖ¯»¯×÷°¸ÌØÕ÷¡£Êܺ¦Õß±»ÓÕµ¼ÔÚÐéαµÇ¼¿òÊäÈëÕË»§ÐÅϢʱ£¬¹¥»÷Õß¼´¿ÉʵʱÇÔȡƾ֤¼°Ò»´ÎÐÔÑéÖ¤Â루OTP£©£¬Ëæºó½«ÍµÈ¡µÄSteamÕË»§ÔÚµØÏÂÊг¡¸ß¼ÛתÊÛ£¬ÕË»§¼Ûֵȡ¾öÓÚ¿â´æÓÎÏ·¼°ÐéÄâÎïÆ·ÊýÄ¿¡£ÊÖÒÕÆÊÎöÏÔʾ£¬´ËÀàÐéα´°¿Ú¾ß±¸·´¼ì²âÌØÕ÷£ºÎÞ·¨µ÷½â¾Þϸ»òÍÏÀëÖ÷´°¿Ú£¬ÓëͨË×ä¯ÀÀÆ÷µ¯³ö´°¿ÚÐÐΪ¸ß¶ÈÏàËÆ£¬µ¼ÖÂÓû§ÄÑÒÔ²ì¾õÒì³£¡£Ç徲ר¼Ò½¨ÒéÍæ¼ÒÆôÓÃSteamË«ÖØÑéÖ¤£¨ÌØÊâÊÇÒÆ¶¯ÈÏÖ¤Æ÷£©£¬°´ÆÚºË²éµÇ¼¼Í¼£¬²¢Ð¡ÐÄÒªÇóÌṩÕË»§Æ¾Ö¤»ò¼ÓÃÜÇ®±ÒÇ®°üµÄµÚÈý·½ÍøÕ¾¡£
https://www.bleepingcomputer.com/news/security/browser-in-the-browser-attacks-target-cs2-players-steam-accounts/
6. Android¶ñÒâÈí¼þʹÓÃ.NET MAUI¿ò¼ÜαװÕýµ±·þÎñÇÔÈ¡Êý¾Ý
3ÔÂ25ÈÕ£¬ÐÂÐÍAndroid¶ñÒâÈí¼þʹÓÃ΢Èí.NET MAUI¿ò¼ÜʵÑéÒþ²Ø¹¥»÷£¬ÆäÊÖÒÕÌØµãÓëÇå¾²ÍþвÒý·¢Òµ½ç¹Ø×¢¡£Âõ¿Ë·ÆÒƶ¯Ñо¿ÍŶӼà²âµ½£¬¹¥»÷Õßͨ¹ý¸Ã¿çƽ̨¿ª·¢¿ò¼Ü¹¹½¨¶ñÒâÓ¦Óã¬Î±×°³É½ðÈÚ¡¢Éç½»µÈÕýµ±·þÎñʵÑéÊý¾ÝÇÔÈ¡£¬Ä¿µÄ¼¯ÖÐÔÚÖйúºÍÓ¡¶ÈµÈGoogle Play»á¼ûÊÜÏÞµØÇø¡£ÊÖÒÕ²ãÃæ£¬¹¥»÷ÕßÍ»ÆÆ¹Å°åAndroidÓ¦Óüì²â»úÖÆ£º.NET MAUIÔÊÐíÒÔC#¿ª·¢Ó¦Óò¢½«½¹µãÂß¼·â×°ÓÚ¶þ½øÖÆblobÎļþ£¬¶øÖ÷Á÷Çå¾²¹¤¾ßÖ÷ҪɨÃèDEXÃûÌÃÎļþ£¬µ¼Ö¶ñÒâ´úÂëµÃÒÔÈÆ¹ý¼ì²â¡£ÍŽá¶à²ã¼ÓÃÜ¡¢¶¯Ì¬´úÂë¼ÓÔØ¼°TCPÒþ²ØÍ¨Ñ¶µÈÊÖÒÕ£¬¸Ã¶ñÒâÈí¼þÐγÉ"µÍÌØÕ÷DZÔÚ-·Ö½×¶Î¼¤»î"µÄ¹¥»÷Á´¡£Ã°³äÓ¦ÓÃÀàÐÍÁýÕÖÒøÐпͻ§¶Ë¡¢Éç½»Èí¼þµÈ¸ßƵ³¡¾°£¬Í¨¹ý´¹ÂÚ½çÃæÓÕµ¼Óû§Ìá½»Ãô¸ÐÐÅÏ¢£¬Í¬Ê±ÇÔȡͨѶ¼¡¢¶ÌÐż°¶àýÌåÎļþ¡£ÖµµÃ×¢ÖØµÄÊÇ£¬¹¥»÷ÕßʹÓÃGoogle PlayµØÇøÏÞÖÆ£¬Í¨¹ýµÚÈý·½ÇþµÀ·Ö·¢¶ñÒâAPK£¬ÏÔÖøÀ©´óѬȾ¹æÄ£¡£Ç徲ר¼Ò½¨Ò飬Óû§Ó¦×èÖ¹×°ÖÃȪԴ²»Ã÷µÄÓ¦Óá£ÔÚGoogle Play²»¿ÉÓÃÇøÓò£¬ÐèʹÓÃÇå¾²Èí¼þɨÃèAPK£¬²¢ÓÅÏÈÑ¡Óùٷ½»ò¿ÉÐÅ·Ö·¢Æ½Ì¨¡£
https://www.bleepingcomputer.com/news/security/new-android-malware-uses-microsofts-net-maui-to-evade-detection/


¾©¹«Íø°²±¸11010802024551ºÅ