ClopÀÕË÷Èí¼þ×éÖ¯¹¥»÷¹þ·ð´óѧ²¢Íþвй¶Êý¾Ý

Ðû²¼Ê±¼ä 2025-10-14

1. ClopÀÕË÷Èí¼þ×éÖ¯¹¥»÷¹þ·ð´óѧ²¢Íþвй¶Êý¾Ý


10ÔÂ12ÈÕ£¬ClopÀÕË÷Èí¼þ×éÖ¯ÔÚÆäTorÊý¾ÝÐ¹Â¶ÍøÕ¾Îª¹þ·ð´óѧ½¨ÉèרÊôÒ³Ãæ£¬Ðû³Æ½«Ð¹Â¶ÇÔÈ¡µÄÊý¾Ý£¬²¢Éù³Æ¡°Êý¾Ý´æµµ¾ÙÐÐÖУ¬ÖÖ×ÓÁ´½Ó¼´½«ÍƳö¡±£¬Í¬Ê±Ö¸Ôð¹þ·ðºöÊÓ¿Í»§Çå¾²¡£¸Ã×éÖ¯×÷Ϊ¶íÓïÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©µÄ´ú±í£¬×Ô2019Äê2ÔÂÊ״ηºÆðÒÔÀ´£¬ÒÀ¸½ÆäÔ´×ÔTA505·¸·¨¼¯ÍÅ£¨»îÔ¾×Ô2014Ä꣩µÄÅä¾°£¬×¨×¢ÓÚ¡°´óÐÍÁÔÎ¹¥»÷ÓëË«ÖØÀÕË÷Õ½ÂÔ£¬³ÉΪȫÇòÍøÂçÇå¾²ÖØ´óÍþв¡£ClopµÄÔË×÷ģʽ¼«¾ßϵͳÐÔ£ºÏÈͨ¹ýÁãÈÕÎó²î»òÒ×Êܹ¥»÷µÄµÚÈý·½Èí¼þ£¨ÈçMOVEit¡¢GoAnywhere¡¢Oracle EBS£©ÇÖÈëÄ¿µÄÍøÂ磬ÇÔÈ¡Ãô¸ÐÊý¾Ý²¢¼ÓÃÜϵͳ £»Ëæºó½«Êý¾ÝÐû²¼ÖÁ°µÍøÐ¹Â¶ÍøÕ¾£¬ÆÛѹÊܺ¦ÕßÖ§¸¶Êê½ð¡£ÆäÊÖÒÕÊֶΰüÀ¨Ê¹Óóõʼ»á¼ûÊðÀí¡¢×Ô¶¯»¯¹¤¾ß¼°ÖØ´óºáÏòÒÆÏÂÊÖÒÕÀ©´ó¹¥»÷¹æÄ££¬Í¬Ê±¹æ±Ü¶íÓïϵͳÒÔ×èÖ¹±¾ÍÁÖ´·¨¹¥»÷¡£ÖµµÃ×¢ÖØµÄÊÇ£¬¸Ã×éÖ¯ºã¾Ã±Ü¿ªÇ°ËÕÁª¹ú¼ÒÄ¿µÄ£¬ÇÒÆä¶ñÒâÈí¼þÔÚ¶íÓïÅÌËã»úÉÏÎÞ·¨¼¤»î¡£


https://securityaffairs.com/183282/cyber-crime/clop-ransomware-group-claims-the-hack-of-harvard-university.html


2. ´ó¹æÄ£¿ç¹ú½©Ê¬ÍøÂçÃé×¼ÃÀ¹úRDP·þÎñ


10ÔÂ13ÈÕ£¬¿ËÈÕ£¬Ò»¸öÓÉÁè¼Ý10ÍòIPµØµã×é³ÉµÄ¿ç¶à¹ú½©Ê¬ÍøÂçÕý¶ÔÃÀ¹úÔ¶³Ì×ÀÃæÐ­Ò飨RDP£©·þÎñÌᳫ´ó¹æÄ£¹¥»÷¡£¸ÃÔ˶¯×Ô10ÔÂ8ÈÕÆô¶¯£¬Ñо¿Ö°Ô±Í¨¹ýIPȪԴÆÊÎöÈ·ÈϹ¥»÷Ô´×Ô¶à¹ú½©Ê¬ÍøÂ缯Ⱥ¡£RDP×÷ΪWindowsϵͳԶ³ÌÅþÁ¬µÄ½¹µãЭÒ飬³£±»ÖÎÀíÔ±¡¢·þÎñ̨¼°Ô¶³ÌÊÂÇéÕßʹÓ㬵«¿ª·Å¶Ë¿ÚÒ׳ÉΪ¹¥»÷Ä¿µÄ¡£¹¥»÷Õßͨ³£Í¨¹ýɨÃ迪·Å¶Ë¿Ú¡¢Ç¿ÖƵǼ¡¢Ê¹ÓÃÎó²î»òÖ´ÐÐ׼ʱ¹¥»÷ʵÑéÈëÇÖ¡£±¾´Î¹¥»÷ÖУ¬Íþв¼à¿ØÆ½Ì¨GreyNoise·¢Ã÷½©Ê¬ÍøÂçÖ÷Òª½ÓÄÉÁ½ÖÖRDPÏà¹Ø¹¥»÷ÊֶΣºÆäһΪ¡°RD Web»á¼û¼ÆÊ±¹¥»÷¡±£¬Í¨¹ý̽²âRD Web¶Ëµã²¢ÕÉÁ¿ÄäÃûÈÏÖ¤Á÷³ÌµÄÏìӦʱ¼ä²î±ð£¬ÍƶÏÓÐÓÃÓû§Ãû £»Æä¶þΪ¡°RDP Web¿Í»§¶ËµÇ¼ö¾Ù¡±£¬Í¨¹ýÊÓ²ì·þÎñÆ÷ÐÐΪ¼°ÏìÓ¦²î±ðö¾ÙÓû§ÕË»§¡ £Ô˶¯×î³õÔÚ°ÍÎ÷·ºÆðÒì³£Á÷Á¿¼¤Ôö£¬ËæºóѸËÙÀ©É¢ÖÁ°¢¸ùÍ¢¡¢ÒÁÀÊ¡¢Öйú¡¢Ä«Î÷¸ç¡¢¶íÂÞ˹¡¢ÄÏ·Ç¡¢¶ò¹Ï¶à¶ûµÈÈ«Çò¶à¹ú£¬Éæ¼°×°±¸ÊÜËð¹ú¼ÒÒѳ¬100¸ö¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ÏÕЩËùÓй¥»÷IPµØµã¾ù¹²ÏíͨÓÃTCPÖ¸ÎÆ£¬Ö»¹Ü×î´ó¶Î´óС£¨MSS£©±£´æ²î±ð£¬µ«Ñо¿Ö°Ô±ÒÔΪÕâÔ´ÓÚ½©Ê¬ÍøÂ缯ȺµÄ×é³ÉÌØÕ÷¡£


https://www.bleepingcomputer.com/news/security/massive-multi-country-botnet-targets-rdp-services-in-the-us/


3. ÃÀ¹úҽѧ³ÉÏñ¾ÞÍ·SimonMedÔâMedusaÀÕË÷Èí¼þ¹¥»÷


10ÔÂ13ÈÕ£¬ÃÀ¹úҽѧ³ÉÏñÌṩÉÌSimonMed Imaging¿ËÈÕÏò³¬120ÍòÃûСÎÒ˽¼Ò·¢³öÊý¾Ýй¶֪ͨ£¬Õ¹ÏÖÆäÔâÓöµÄÑÏÖØÍøÂçÇå¾²ÊÂÎñ¡£¸Ã¹«Ë¾×÷ΪÃÀ¹ú11¸öÖÝÔ¼170¼ÒÒ½ÁÆÖÐÐĵÄÔËÓª·½£¬ÄêÊÕÈ볬5ÒÚÃÀÔª£¬ÌṩMRI¡¢CT¡¢XÉäÏßµÈȫϵÁÐҽѧӰÏñ·þÎñ¡£ÊÂÎñʼÓÚ2025Äê1ÔÂ21ÈÕÖÁ2ÔÂ5ÈÕʱ´ú£¬ºÚ¿ÍÈëÇÖSimonMedϵͳ²¢»á¼û¹«Ë¾ÍøÂç¡£1ÔÂ27ÈÕ£¬Æä¹©Ó¦ÉÌÊ×Ïȱ¨¸æÇå¾²ÊÂÎñ£¬Ô½ÈÕSimonMedÈ·ÈÏÍøÂç±£´æ¿ÉÒÉÔ˶¯¡£¹«Ë¾Ëæ¼´Æô¶¯Ó¦¼±ÏìÓ¦£¬°üÀ¨ÖØÖÃÃÜÂë¡¢°²ÅŶàÒòËØÈÏÖ¤£¨MFA£©¡¢Ìí¼Ó¶Ëµã¼ì²âÓëÏìÓ¦£¨EDR£©¼à¿Ø¡¢ÏÞÖÆµÚÈý·½»á¼ûȨÏÞ£¬²¢ÏÞÖÆÍøÂçÁ÷Á¿ÖÁ¿ÉÐÅÅþÁ¬¡£Í¬Ê±£¬¹«Ë¾ÏòÖ´·¨²¿·Ö¼°Êý¾ÝÇ徲ר¼Òת´ïÇéÐΡ£¾ÝMedusaÀÕË÷Èí¼þÉùÃ÷£¬ÆäÇÔÈ¡ÁË212GBÊý¾Ý£¬°üÀ¨Éí·Ý֤ɨÃè¼þ¡¢»¼ÕßÏêϸÐÅÏ¢¡¢¸¶¿î¼Í¼¡¢ÕË»§Óà¶î¡¢Ò½ÁƱ¨¸æ¼°Ô­Ê¼É¨Ãè¼þµÈÃô¸ÐÄÚÈÝ¡£¸ÃÍÅ»ïÒªÇóÖ§¸¶100ÍòÃÀÔªÊê½ð¼°ÖðÈÕ1ÍòÃÀÔªÑÓÆÚ·Ñ£¬²»È»½«¹ûÕæËùÓÐÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/


4. Unity Technologies SpeedTreeÍøÕ¾Ôâ¶ñÒâ´úÂë¹¥»÷


10ÔÂ13ÈÕ£¬ÊÓÆµÓÎÏ·Èí¼þ¿ª·¢¹«Ë¾Unity TechnologiesÅû¶ÆäSpeedTreeÍøÕ¾½áÕËÒ³Ãæ±£´æ¶ñÒâ´úÂ룬µ¼ÖÂÊý°ÙÃû¿Í»§Ãô¸ÐÐÅϢй¶¡£¾­ÊӲ죬¸Ã¶ñÒâ´úÂë×Ô2025Äê3ÔÂ13ÈÕÆð±ã±»Ö²ÈëÍøÕ¾£¬Ö±ÖÁ8ÔÂ26ÈÕ±»·¢Ã÷ºóÁ¬Ã¦É¾³ý£¬Ê±´úÒ»Á¬ÇÔÈ¡Óû§ÔÚ¹ºÖÃÀú³ÌÖÐÊäÈëµÄÃô¸ÐÊý¾Ý¡£´Ë´ÎÊÂÎñÓ°Ïì¹æÄ£Ã÷È·£¬Éæ¼°2025Äê3ÔÂ13ÈÕÖÁ8ÔÂ26ÈÕʱ´úͨ¹ýSpeedTreeÍøÕ¾¹ºÎïµÄ428Ãû¿Í»§¡£Ð¹Â¶ÐÅÏ¢°üÀ¨¿Í»§ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþ¡¢ÐÅÓÿ¨ºÅ¼°»á¼û´úÂëµÈ¸ß¶ÈÃô¸ÐÊý¾Ý¡£Æ¾Ö¤Unity TechnologiesÏòÃåÒòÖÝ×ÜÉó²é³¤Ìá½»µÄÊý¾Ýй¶֪ͨ£¬¸Ã¶ñÒâ´úÂëδ¾­ÊÚȨ£¬¿ÉÄÜÔÊÐí¹¥»÷Õß»ñÈ¡Óû§ÔÚ½áÕËÒ³ÃæÊäÈëµÄÉÏÊöÐÅÏ¢¡£ÎªÓ¦¶Ô´Ë´ÎÇå¾²ÊÂÎñ£¬Unity TechnologiesѸËÙ½ÓÄɶàÏî²½·¥£º¹Ø±ÕÊÜѬȾµÄSpeedTreeÍøÕ¾ÒÔ×è¶Ï¹¥»÷·¾¶£¬ÖÜÈ«Éó²éÊÜÓ°ÏìÎļþÒÔÆÀ¹ÀËðʧ¹æÄ££¬²¢×Ô¶¯Í¨ÖªÊÜÓ°Ïì¿Í»§¼°î¿Ïµ²¿·Ö¡£Í¬Ê±£¬¹«Ë¾ÔöÇ¿ÁËÍøÂçÇå¾²·À»¤²½·¥£¬ÒÔ±ÜÃâÀàËÆÊÂÎñÔٴα¬·¢¡£×÷Ϊµ÷½â²½·¥£¬Unity Technologiesͨ¹ýEquifaxΪÊÜÓ°ÏìСÎÒ˽¼ÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓÃ¼à¿ØºÍÉí·Ý± £»¤·þÎñ£¬ÒÔ½µµÍÉí·Ý͵ÇÔºÍڲƭΣº¦¡£


https://securityaffairs.com/183349/data-breach/customer-payment-data-stolen-in-unity-technologiess-speedtree-website-compromise.html


5. SonicWall SSLVPNÕË»§Ôâ´ó¹æÄ£Æ¾Ö¤ÇÔÈ¡¹¥»÷


10ÔÂ13ÈÕ£¬Ñо¿Ö°Ô±¿ËÈÕÖÒÑÔ£¬ÍþвÐÐΪÕßͨ¹ýÇÔÈ¡µÄÓÐÓÃÆ¾Ö¤Ìᳫ´ó¹æÄ£¹¥»÷£¬ÈëÇÖÁËÁè¼Ý100¸öSonicWall SSLVPNÕË»§¡£´Ë´Î¹¥»÷Ô˶¯×Ô10ÔÂ4ÈÕÆðÔÚÍйÜÍøÂçÇ徲ƽ̨Huntress¼à²âµÄ16¸ö¿Í»§ÇéÐÎÖм¯Öб¬·¢£¬ÖÁ10ÔÂ10ÈÕÈÔÒ»Á¬¾ÙÐУ¬Éæ¼°100Óà¸öÕË»§µÄÒì³£»á¼û¡£¹¥»÷ÕßʹÓÃÇÔÈ¡µÄƾ֤¿ìËÙÑéÖ¤¶à¸öÕË»§Éí·Ý£¬ÔÚ²¿·Ö°¸ÀýÖÐ»á½øÒ»²½Ö´ÐÐÍøÂçɨÃ貢ʵÑé»á¼ûÍâµØWindowsÕË»§£¬ÊµÑéºáÏòÉøÍ¸¡£HuntressÑо¿Ö°Ô±Ö¸³ö£¬¹¥»÷µÄËÙÂÊÓë¹æÄ£Åú×¢¹¥»÷ÕßÕÆÎÕµÄÊÇÓÐÓÃÆ¾Ö¤¶ø·Çͨ¹ý±©Á¦ÆÆ½â»ñÈ¡¡£Ö»¹Ü¹¥»÷Õß¿ÉÄܽâÂëÁËSonicWallÔÆ±¸·ÝÖмÓÃܵķÀ»ðǽÉèÖÃÎļþ£¬µ«ÏÖʵ»ñÈ¡µÄƾ֤ºÍÃÜÔ¿ÈÔÒÔAES-256¼ÓÃÜÐÎʽ±£´æ£¬Ö±½ÓʹÓüÛÖµÊÜÏÞ¡£´Ë´ÎÊÂÎñÓëSonicWall½üÆÚ̻¶µÄÔÆ±¸·ÝÎó²îÎÞÖ±½Ó¹ØÁª£¬¸ÃÎó²îËäµ¼Ö·À»ðǽÉèÖÃÎļþй¶£¬µ«ÆäÖÐÆ¾Ö¤Òѵ¥¶À¼ÓÃÜ¡£È»¶ø£¬¹¥»÷ÈÔ̻¶³öSSLVPNÕË»§µÄÇå¾²Òþ»¼¡£


https://www.bleepingcomputer.com/news/security/sonicwall-vpn-accounts-breached-using-stolen-creds-in-widespread-attacks/


6. NPM»ù´¡ÉèÊ©ÔâÀÄÓÃÒý·¢´ó¹æÄ£ÍøÂç´¹ÂÚ¹¥»÷


10ÔÂ13ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕ½ÒÆÆ£¬ÍþвÐÐΪÕßÕýͨ¹ýÀÄÓÃÕýµ±µÄNPMÈí¼þ°ü»ù´¡ÉèÊ©ÌᳫÐÂÐÍÍøÂç´¹ÂÚ¹¥»÷£¬¸ÃÔ˶¯Í»ÆÆ¹Å°å¹©Ó¦Á´¹¥»÷ģʽ£¬ÒѲ¨¼°È«Çò135¸öÄÜÔ´¡¢¹¤Òµ×°±¸¼°ÊÖÒÕÁìÓò×éÖ¯¡£´Ë´Î¹¥»÷ÒÔ¡°Beamglea¡±Ô˶¯Îª½¹µã£¬¶ñÒâÈí¼þ°ü½ÓÄÉ¡°redirect-[a-z0-9]{6}¡±ÃûÌÃÃüÃû£¬Í¨¹ýNPMÐû²¼ºó£¬ÓÉCDN·þÎñunpkg.comÌṩ¶ñÒâHTMLÎļþ·Ö·¢¡£¹¥»÷Á´ÌõÉè¼ÆÏ¸ÃÜ£ºÍþвÐÐΪÕßÊ×ÏÈÏòÄ¿µÄÊܺ¦Õß·¢ËÍαװ³É²É¹º¶©µ¥¡¢ÊÖÒÕÎĵµµÄHTML¸½¼þ£¬µ±Êܺ¦ÕßÔÚä¯ÀÀÆ÷Öз­¿ªÎļþʱ£¬ÄÚǶµÄ¶ñÒâJavaScript´úÂë»á´Óunpkg.com¼ÓÔØ£¬²¢Á¬Ã¦½«Óû§Öض¨ÏòÖÁ´¹ÂÚÒ³Ãæ¡£¸ÃÒ³Ãæ»áÔ¤ÏÈÌîдÊܺ¦ÕßÓÊÏ䵨µã£¬ÓªÔì¡°Õýµ±µÇ¼ÃÅ»§¡±¼ÙÏóÒÔÓÕÆ­Æ¾Ö¤ÊäÈë¡£Çå¾²¹«Ë¾Socket¼à²âÏÔʾ£¬´ËÀà¶ñÒâÈí¼þ°üÊýÄ¿Òѳ¬175¸ö£¬ÀÛ¼ÆÏÂÔØÁ¿³¬26,000´Î£¬Ö»¹Ü²¿·ÖÏÂÔØÀ´×ÔÇå¾²Ñо¿Ö°Ô±»ò×Ô¶¯»¯É¨Ã蹤¾ß¡£Ä¿µÄ×éÖ¯°üÀ¨ArcelorMittal¡¢ThyssenKrupp Nucera¡¢D-LinkµÈ¿ç¹úÆóÒµ£¬¹¥»÷¹æÄ£¼¯ÖÐÔÚÎ÷Å·¹ú¼Ò£¬Í¬Ê±ÑÓÉìÖÁ±±Å·ºÍÑÇÌ«µØÇø¡£


https://www.securityweek.com/npm-infrastructure-abused-in-phishing-campaign-aimed-at-industrial-and-electronics-firms/