µÂ¿ËÈøË¹ÖÝÌdzÇÔâÍøÂç¹¥»÷Ö·þÎñÖÐÖ¹
Ðû²¼Ê±¼ä 2025-10-131. µÂ¿ËÈøË¹ÖÝÌdzÇÔâÍøÂç¹¥»÷Ö·þÎñÖÐÖ¹
10ÔÂ11ÈÕ£¬µÂ¿ËÈøË¹ÖÝÌdzǹÙԱת´ï³Æ£¬¸ÃÊÐÔâÓöÍøÂç¹¥»÷µ¼Ö¶àÏîÔÚÏß·þÎñÖÐÖ¹£¬°üÀ¨311ÁªÂçÖÐÐÄ¡¢¹«ÓÃÊÂÒµ¼Æ·Ñ¡¢ÔÊÐí¼ì²é°²Åż°ÔÊÐíÖ¤¸¶¿îµÈ¹¦Ð§ÊÜ×è¡£Ö»¹ÜÒªº¦»ù´¡ÉèÊ©È羯Ա¡¢Ïû·ÀºÍÒ½ÁÆ·þÎñÈÔͨ¹ý911¼á³ÖÔË×÷£¬µ«Õ˵¥Ö§¸¶µÈ²¿·ÖÔÚÏß·þÎñÒÑÊÜÓ°Ïì¡£Êи®ÒÑÆô¶¯Ó¦¼±»úÖÆ£¬Îª·Ç½ôÆÈÇéÐÎÌṩ±¸ÓÃÁªÏµ·½·¨£¬²¢ÍŽáÖÝ¡¢Áª°îÖ´·¨²¿·ÖÕö¿ªÊÓ²ì£¬ÖØµãÅŲéÄÚ²¿ÍøÂç»ù´¡ÉèÊ©ÊÜËðÇéÐΡ£ÌdzÇÊÂÎñÔÙ´Î̻¶µØ·½Õþ¸®ÔÚÍøÂçÇå¾²·À»¤ÖеÄųÈõÐÔ¡£Ö»¹ÜÊи®Ç¿µ÷¡°Òªº¦ÏµÍ³Î´ÊÜÓ°Ï족£¬µ«·þÎñÖÐÖ¹ÒѶÔסÃñÒ»Ñùƽ³£ÊÂÎñ´¦Öóͷ£Ôì³ÉʵÖÊÐÔ×è°¡£´Ë´ÎÊÂÎñ²¢·Ç¹ÂÀý¡£¾Ýͳ¼Æ£¬2025ÄêÒÔÀ´£¬µÂ¿ËÈøË¹ÖÝ¶àµØÆµ·¢ÍøÂçÇå¾²ÊÂÎñ£ºÈýÖÜǰ£¬ÓÈÍß¶ûµÏÊй«Á¢Ñ§ÇøÒòÀÕË÷Èí¼þ¹¥»÷±»ÆÈÍ£¿ÎÒ»ÖÜ£¬¡°÷è÷롱ÍÅ»ïÒÑÐû³Æ¶Ô´ËÈÏÕæ£»ÂíËþ¸ç´ïÏØ¡¢Ã×Éê¡¢À²®¿Ë¼°°¢±ÈÁֵȶ¼»áÒ౨¸æÀàËÆÊÂÎñ¡£½ñÄê6Ô£¬Öݽ»Í¨²¿ÕË»§ÔâºÚ¿ÍÈëÇÖ£¬½ü30Íò·Ý°üÀ¨ÐÕÃû¡¢µØµã¡¢¼ÝÕÕºÅÂë¡¢³µÅƼ°°ü¹ÜÐÅÏ¢µÄ½»Í¨Ê¹ʱ¨¸æ±»²»·¨ÏÂÔØ£¬Òý·¢¹«ÖÚ¶ÔСÎÒ˽¼ÒÐÅÏ¢Çå¾²µÄµ£ÐÄ¡£
https://therecord.media/houston-suburb-cyberattack-services
2. ºÚ¿ÍʹÓÃGladinetÎļþ¹²ÏíÈí¼þµÄÁãÈÕÎó²î
10ÔÂ10ÈÕ£¬¿ËÈÕ£¬Gladinet¹«Ë¾µÄCentreStackºÍTriofoxÎļþ¹²Ïí¼°Ô¶³Ì»á¿´·¨¾ö¼Æ»®±»ÆØ±£´æÑÏÖØÁãÈÕÎó²îCVE-2025-11371£¬¸ÃÎó²îΪÍâµØÎļþ°üÀ¨£¨LFI£©Îó²î£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»á¼ûϵͳÎļþ¡£ÏÖÔÚÖÁÉÙÓÐÈý¼ÒÆóÒµÒò´ËÔâÊܹ¥»÷£¬ÇÒËùÓа汾²úÆ·¾ùÊÜÓ°Ï죬°üÀ¨×îа汾16.7.10368.56560¡£Îó²îʹÓÃÁ´ÏÔʾ£¬¹¥»÷ÕßÊ×ÏÈͨ¹ýLFI¶ÁÈ¡Web.configÎļþÌáÈ¡»úеÃÜÔ¿£¬ËæºóÍŽá´ËǰÒÑÖªµÄ·´ÐòÁл¯Îó²îCVE-2025-30406£¨Ô´ÓÚÓ²±àÂë»úеÃÜÔ¿£©£¬×îÖÕͨ¹ýViewStateʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£HuntressÑо¿Ö°Ô±ÓÚ9ÔÂ27ÈÕÊ״η¢Ã÷¸ÃÎó²î£¬²¢È·ÈÏÍþвÐÐΪÕßÒÑÀÖ³ÉʹÓôËÎó²î»ñÈ¡»úеÃÜÔ¿²¢Ö´ÐжñÒâ´úÂë¡£Gladinet¹«Ë¾ÒÑÈ·ÈÏÎó²î±£´æ£¬²¢ÌåÏÖÕýÔÚ֪ͨ¿Í»§½ÓÄÉÔÝʱ»º½â²½·¥£¬Ö±ÖÁ²¹¶¡Ðû²¼¡£CentreStack²úÆ·Éù³ÆÒѱ»49¸ö¹ú¼ÒµÄÊýǧ¼ÒÆóҵʹÓ㬶ø´Ë´ÎÊÂÎñÔÙ´Î̻¶ÁËÆóÒµ¼¶´æ´¢½â¾ö¼Æ»®µÄÇ徲Σº¦¡£
https://www.bleepingcomputer.com/news/security/hackers-exploiting-zero-day-in-gladinet-file-sharing-software/
3. Service FinderÖ÷Ìâ¸ßΣÎó²îÔâ´ó¹æÄ£Ê¹ÓÃ
10ÔÂ10ÈÕ£¬Service Finder WordPressÖ÷Ìâ¼°ÆäÀ¦°óµÄBookings²å¼þ±£´æÑÏÖØÇå¾²Îó²îCVE-2025-5947£¬¸ÃÎó²î±»ÆÀ·ÖΪ9.8·Ö£¬ÊôÓÚ¸ßΣÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î¡£¹¥»÷Õß¿ÉÎÞÐèÃÜÂëÖ±½Óͨ¹ýαÔìCookieð³äÖÎÀíÔ±µÇ¼£¬½ø¶øÍêÈ«¿ØÖÆÍøÕ¾£¬×¢Èë¶ñÒâ´úÂë¡¢Ð®ÖÆÁ÷Á¿»ò°²ÅŶñÒâÈí¼þ¡£Îó²îÔ´ÓÚ²å¼þ¶ÔÕË»§Çл»¹¦Ð§µÄ¹ýʧ´¦Öóͷ££¬Î´ÑéÖ¤CookieÊý¾ÝµÄÕæÊµÐÔ£¬µ¼ÖÂí§ÒâÓû§£¨°üÀ¨ÎÞÕË»§Õߣ©¿Éð³äÖÎÀíÔ±Éí·Ý¡£¸ÃÎó²îÓ°ÏìËùÓÐ6.0¼°ÒÔϰ汾£¬Ö÷Ìâά»¤·½ÓÚ2025Äê7ÔÂ17ÈÕÐû²¼6.1°æ±¾ÐÞ¸´²¹¶¡£¬µ«¹¥»÷Õß×Ô8ÔÂ1ÈÕÆðÒÑÌᳫ³¬13,800´ÎʹÓÃʵÑé¡£ÏÖÔÚ£¬³¬6000Ãû¹ºÖøÃÖ÷ÌâµÄ¿Í»§ÖÐÈÔÓдó×ÚÍøÕ¾Î´¸üУ¬ÃæÁÙÒ»Á¬Î£º¦¡£Çå¾²¹«Ë¾Wordfenceͨ¹ýÎó²îÉͽðÍýÏëÐÖúÅû¶Á˸ÃÎó²î£¬Æä·À»ðǽ¿É×èµ²²¿·Ö¹¥»÷£¨Ê¶±ð¶ñÒâCookieÊý¾Ý£©£¬µ«¹Ù·½Ç¿µ÷¸üÐÂÖÁ6.1»ò¸ü¸ß°æ±¾²ÅÊÇ»ù´¡·ÀÓù²½·¥¡£
https://hackread.com/auth-bypass-service-finder-wordpress-plugin-exploit/
4. Stealit¶ñÒâÈí¼þ½èNode.js SEA¹¦Ð§Òþ²ØÈö²¥
10ÔÂ10ÈÕ£¬Fortinet FortiGuardʵÑéÊÒ¿ËÈÕÖÒÑÔ£¬Ò»ÖÖÃûΪStealitµÄΣÏÕÊý¾ÝÇÔÈ¡¶ñÒâÈí¼þÕýͨ¹ýMaaS£¨¶ñÒâÈí¼þ¼´·þÎñ£©Ä£Ê½»îÔ¾Èö²¥¡£¸Ã¶ñÒâÈí¼þÕë¶ÔWindowsÓû§£¬½ÓÄÉÖеÈÑÏÖØË®Æ½¹¥»÷£¬Í¨¹ýNode.jsµÄ"µ¥¿ÉÖ´ÐÐÓ¦ÓóÌÐò£¨SEA£©"¹¦Ð§½«ËùÓжñÒâÎļþ´ò°ü³É¼òµ¥³ÌÐò£¬ÎÞÐèԤװNode.js¼´¿ÉÔËÐУ¬ÏÔÖøÌáÉýÒþ²ØÐÔ¡£Æä´úÂë¾ÓÉÖØ¶È»ìÏý²¢Ç¶Èë·´ÆÊÎö¼ì²é£¬¿É×Ô¶¯¹æ±Üµ÷ÊÔÆ÷¡¢ÐéÄâÇéÐεÈÇå¾²¼ì²â¡£StealitµÄ½¹µã¹¦Ð§°üÀ¨Ô¶³ÌÎļþÌáÈ¡¡¢ÀÕË÷Èí¼þ°²ÅÅ¡¢ÊµÊ±ÆÁÄ»¼à¿Ø¡¢ÍøÂçÉãÏñÍ·¿ØÖƼ°ÏµÍ³ÖÎÀí£¬²¢¿ÉÍÆËÍÐéα¾¯±¨ÐÅÏ¢¡£¹¥»÷Õß½«Æä°üװΪ"רҵÊý¾ÝÌáÈ¡½â¾ö¼Æ»®"£¬Í¨¹ý¶©ÔÄÍýÏëÊÛÂô£¬Windows°æ¶¨¼ÛÔ¼500ÃÀÔª£¬Android°æ¸ß´ï2000ÃÀÔª¡£ÎªÌÓ±Ü×·×Ù£¬ÆäC2·þÎñÆ÷ÒÑ´Óstealituptaded.lolǨáãÖÁiloveanimals.shop¡£Èö²¥Õ½ÂÔ·½Ã棬¶ñÒâÈí¼þαװ³ÉÈÈÃÅÓÎÏ·ºÍVPN×°ÖóÌÐò£¬Í¨¹ýMediafire¡¢DiscordµÈƽ̨·Ö·¢¡£ÓÎÏ·Íæ¼ÒÒòƵÈÔ×°ÖõÚÈý·½Èí¼þ³ÉΪÖ÷ҪĿµÄȺÌå¡£
https://hackread.com/stealit-malware-node-js-fake-game-vpn-installers/
5. ŦԼÖݾ¯ÃñÍŽṥ»÷¡°Í¨ÕÍÍË˰¡±´¹ÂÚÕ©Æ
10ÔÂ12ÈÕ£¬½üÆÚ£¬Å¦Ô¼Öݱ¬·¢Ò»ÆðÒÔ¡°Í¨»õÅòÕÍÍ˿Ϊ»Ï×ӵĶÌÐÅÍøÂç´¹ÂÚÕ©Æ£¬Ä¿µÄֱָŦԼסÃñ¡£Õ©Æ·Ö×Óð³äŦԼ˰ÎñºÍ²ÆÎñ²¿£¬Í¨¹ý¶ÌÐÅ¡¢Óʼþ¼°Ö±ÓÊ·½·¨£¬»Ñ³ÆÌṩ¡°Í¨ÕÍÍ˿²¢ÓÕµ¼Êܺ¦Õßµã»÷Á´½ÓÊäÈëСÎÒ˽¼ÒÐÅÏ¢¡£¸ÃÕ©ÆÊ¹ÓÃÁËŦԼÖÝÕæÊµ±£´æµÄͨÕÍÍË˰Õþ²ß£¬ÇкÏÌõ¼þµÄÄÉ˰ÈËÎÞÐèÉêÇë¼´¿É×Ô¶¯ÊÕµ½ÍË˰֧Ʊ£¬Õþ²ßº¸ÇÒÑÌá½»ÄÉ˰É걨¡¢µÖ´ïÊÕÈëÃż÷ÇÒδ±»É걨ΪÊܸ§ÓýÈ˵ÄסÃñ¡£Õ©Æ¶ÌÐÅÉù³Æ¡°ÍË¿îÇëÇóÒÑ´¦Öóͷ£²¢Åú×¼¡±£¬ÒªÇóÊÕ¼þÈËÔÚ2025Äê9ÔÂ29ÈÕÌõ¼þ½»¸¶¿îÐÅÏ¢£¬²»È»½«ÓÀÊÀËðʧÍË¿î×ʸñ£¬²¢Ô®Òý¡¶Å¦Ô¼ÐÞ¶©¹æÔò¡·µÚ5747.11Ìõʩѹ¡£µã»÷Á´½Óºó£¬Êܺ¦Õ߻ᱻָµ¼ÖÁαÔìµÄ¹Ù·½Ò³Ã棬±»ÒªÇóÊäÈëÐÕÃû¡¢µØµã¡¢µç»°¡¢Éç»áÇå¾²ºÅÂëµÈÃô¸ÐÐÅÏ¢£¬ÕâЩÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇԺͽðÈÚÕ©Æ¡£Å¦Ô¼ÖÝÕþ¸®Ñ¸ËÙ½ÓÄÉÐж¯¡£9ÔÂ28ÈÕ£¬Öݳ¤¿Î÷¡¤»ô³þ¶û°ì¹«ÊÒÐû²¼ÖÒÑÔ£¬Ç¿µ÷¡°³ý×ʸñÒªÇóÍ⣬ŦԼÈËÎÞÐè×öÈκÎʼ´¿É»ñµÃÍË˰֧Ʊ¡±£¬²¢Ã÷È·¡°Ë°Îñ²¿·Ö²»»áͨ¹ýµç»°¡¢¶ÌÐÅ»òÓʼþË÷ҪСÎÒ˽¼ÒÐÅÏ¢¡±¡£Å¦Ô¼Ë°ÎñºÍ²ÆÎñ²¿Í¬²½ÌáÐÑ£¬»ú¹¹¾ø²»»áͨ¹ýµç×ÓͨѶÁªÏµÄÉ˰ÈË´¦Öóͷ£ÍË˰ÊÂÒË¡£
https://www.bleepingcomputer.com/news/security/fake-inflation-refund-texts-target-new-yorkers-in-new-scam/
6. Î÷°àÑÀµ·»Ù¿ç¹úÍøÂç·¸·¨Æ½Ì¨GXC Team
10ÔÂ11ÈÕ£¬Î÷°àÑÀ¹úÃñ¾¯ÎÀ¶Ó½üÆÚÀֳɴݻÙÃûΪ¡°GXC Team¡±µÄ¿ç¹úÍøÂç·¸·¨×éÖ¯£¬¾Ð²¶Æä25Ëê°ÍÎ÷¼®Í·Ä¿¡°GoogleXcoder¡±¼°¶àÃûͬ»ï¡£¸Ã×éÖ¯ÔËÓª¡°·¸·¨¼´·þÎñ¡±£¨CaaS£©Æ½Ì¨£¬Í¨¹ýTelegramºÍ¶íÓïºÚ¿ÍÂÛ̳ÏòÈ«Çò¿Í»§Ìṩ¶¨ÖÆ»¯ÍøÂç¹¥»÷¹¤¾ß£¬°üÀ¨È˹¤ÖÇÄÜ´¹ÂÚ¹¤¾ß°ü¡¢Android¶ñÒâÈí¼þ¼°ÓïÒôթƹ¤¾ß£¬ÐγÉרҵ¼¶¸ßÊÕÒæ·¸·¨Éú̬¡£¾ÝÊӲ죬GXC TeamÖ÷ÒªÕë¶ÔÎ÷°àÑÀ¡¢Ë¹Âå·¥¿Ë¡¢Ó¢¹ú¡¢ÃÀ¹úºÍ°ÍÎ÷µÄÒøÐС¢ÔËÊä¼°µç×ÓÉÌÎñʵÌåʵÑé¹¥»÷¡£Æä´¹ÂÚ¹¤¾ß°ü¾«×¼¸´ÖÆÊýÊ®¼Ò¹ú¼Ê»ú¹¹ÍøÕ¾£¬Ö§³ÖÖÁÉÙ250¸ö´¹ÂÚÍøÕ¾ÔËÐУ»¿ª·¢µÄ9ÖÖAndroid¶ñÒâÈí¼þ¿É×èµ²¶ÌÐźÍÒ»´ÎÐÔÃÜÂ루OTP£©£¬ÓÃÓÚÐ®ÖÆÕË»§¼°ÑéÖ¤Ú²ÆÉúÒâ¡£¸Ã×éÖ¯»¹ÌṩÊÖÒÕÖ§³ÖºÍÔ˶¯¶¨ÖÆ·þÎñ£¬ÐγÉÍêÕû·¸·¨¹¤ÒµÁ´¡£5ÔÂ20ÈÕ£¬Î÷°àÑÀ¾¯·½ÔÚ¿²Ëþ²¼ÀïÑÇ¡¢°ÍÈûÂÞÄÇµÈ¶àµØÕö¿ªÐµ÷Í»»÷ËѲ飬²é»ñ°üÀ¨´¹ÂÚ¹¤¾ß°üÔ´´úÂë¡¢¿Í»§Í¨Ñ¶¼Í¼¼°²ÆÎñÊý¾ÝµÄµç×Ó×°±¸£¬×·»Ø±»µÁ¼ÓÃÜÇ®±Ò£¬²¢¹Ø±ÕÃûΪ¡°´Ó׿ďÄÇÀï͵×ßÒ»ÇС±µÄÕ©ÆÍƹãTelegramƵµÀ¡£´Ë´ÎÐж¯»ùÓÚ¶Ô¡°GoogleXcoder¡±×°±¸¼°¼ÓÃÜÇ®±ÒÉúÒâµÄÒ»Á¬Ò»Äê¶àµÄȡ֤ÆÊÎö£¬ÀÖ³ÉÖØÐÞ·¸·¨ÍøÂç²¢Ëø¶¨6Ãû¹ØÁªÖ°Ô±¡£
https://www.bleepingcomputer.com/news/security/spain-dismantles-gxc-team-cybercrime-syndicate-arrests-leader/


¾©¹«Íø°²±¸11010802024551ºÅ