TomirisÉý¼¶¶àÓïÑÔÎäÆ÷¿â  £¬¾«×¼¹¥»÷¶íÍâ½»»ú¹¹

Ðû²¼Ê±¼ä 2025-12-02

1. TomirisÉý¼¶¶àÓïÑÔÎäÆ÷¿â  £¬¾«×¼¹¥»÷¶íÍâ½»»ú¹¹


12ÔÂ1ÈÕ  £¬¿¨°Í˹»ù×îб¨¸æÕ¹ÏÖ  £¬ÃûΪTomirisµÄÍþвÐÐΪÕßÕý¶Ô¶íÂÞ˹Íâ½»²¿¡¢Õþ¸®¼ä×éÖ¯¼°ÖÐÑǹú¼Ò»ú¹¹ÌᳫսÂÔÐÔÍøÂç¹¥»÷  £¬Æä½¹µãÄ¿µÄÊÇͨ¹ýÓã²æÊ½´¹ÂÚÓʼþ°²ÅŶàÓïÑÔ±àдµÄ¶ñÒâÈí¼þÄ £¿é  £¬»ñȡԶ³Ì»á¼ûȨÏÞ²¢½¨É賤ÆÚ»¯¿ØÖÆ¡£¸Ã×éÖ¯2025Äê¹¥»÷Á´ÏÔʾ  £¬³¬50%µÄÓÕ¶üÎļþ½ÓÄɶíÓï¼°ÖÐÑǹú¼Ò¹Ù·½ÓïÑÔ¶¨ÖÆ  £¬¹¥»÷Õßͨ¹ý¼ÓÃÜRARÎļþ£¨½âѹÃÜÂëÖ±½ÓǶÈëÓʼþÕýÎÄ£©·Ö·¢Î±×°³ÉWordÎĵµµÄ¿ÉÖ´ÐÐÎļþ  £¬ÔËÐкóÊÍ·ÅC/C++·´ÏòShell  £¬ÅþÁ¬C2·þÎñÆ÷ÏÂÔØAdaptixC2¿ò¼Ü  £¬²¢Í¨¹ýÐÞ¸ÄWindows×¢²á±íʵÏÖ¶ñÒâÔØºÉ³¤ÆÚ»¯¡£TomirisµÄÕ½ÊõÑݱäÓÈΪÏÔÖø  £¬ÆäÈÕ񾮵ÈÔµØÊ¹ÓÃTelegram¡¢DiscordµÈ¹«¹²·þÎñ×÷ΪC2·þÎñÆ÷  £¬½«¶ñÒâÁ÷Á¿ÓëÕýµ±·þÎñÁ÷Á¿»ìÏýÒÔ¹æ±Ü¼ì²â¡£Æä¶ñÒâÈí¼þÎäÆ÷¿âº­¸ÇC#¡¢Rust¡¢Go¡¢PythonµÈ¶àÓïÑÔ±àдµÄ·´ÏòShell¡¢SOCKSÊðÀí¼°ºóÃųÌÐò¡£¶àÓïÑÔÄ £¿éµÄÎÞаÐÔ¡¢µÍ¿ÉÒÉÐÔÌØÕ÷¼°¶Ô¿ªÔ´¿ò¼ÜµÄʹÓà  £¬Ê¹TomirisÄܹ»ÊµÏÖÒþ²ØµÄºã¾Ã³¤ÆÚ»¯¹¥»÷¡£


https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html


2. ÈÕÀú¶©ÔÄÇ徲äµã£ºBitSightÆØ347¸ö¶ñÒâÓòÃûΣº¦


11ÔÂ28ÈÕ  £¬ÍøÂçÇå¾²¹«Ë¾BitSight×îÐÂÑо¿Õ¹ÏÖ  £¬ÍþвÐÐΪÕßÕýͨ¹ýʹÓÃÊý×ÖÈÕÀú¶©ÔÄ»ù´¡ÉèʩʵÑé´ó¹æÄ£Éç»á¹¤³Ì¹¥»÷¡£ÈÕÀú¶©ÔĹ¦Ð§±¾ÓÃÓÚºÏÐ̳¡¾°  £¬ÈçÁãÊÛÉÌÍÆËÍ´ÙÏúÈÕÆÚ¡¢ÌåÓýЭ»á¸üÐÂÈüÊÂÈÕ³Ì  £¬ÆäÔÊÐíµÚÈý·½·þÎñÆ÷Ö±½ÓÏòÓû§×°±¸Ìí¼ÓÊÂÎñ²¢·¢ËÍ֪ͨµÄÌØÕ÷  £¬È´±»¶ñÒâʹÓà  £¬¹¥»÷ÕߴÍйÜÓÚÓâÆÚ»ò±»Ð®ÖÆÓòÃûµÄÐéãåÈÕÀú¶©ÔÄ·þÎñ  £¬ÓÕÆ­Óû§¶©ÔĺóÍÆËͺ¬¶ñÒâÁ´½Ó¡¢¸½¼þµÄÈÕÀúÎļþ  £¬´¥·¢´¹ÂÚ¹¥»÷¡¢¶ñÒâÈí¼þ·Ö·¢¡¢JavaScript´úÂëÖ´ÐÐÉõÖÁAIÖúÊÖÀÄÓõÈΣº¦¡£Ñо¿Ê¼ÓÚÒ»¸ö±» ¡°Sinkhole¡± ÊÖÒÕ½ÓÊܵÄÓòÃû  £¬¸ÃÓòÃûÔ­ÓÃÓÚ·Ö·¢µÂ¹ú¹«¹²¼ÙÆÚICSÎļþ  £¬È´ÖðÈÕÎüÊÕ1.1Íò¸ö×ÔÁ¦IP»á¼û  £¬Òý·¢Ñо¿ÍŶӹØ×¢¡£½øÒ»³ÌÐò²é·¢Ã÷347¸ö¿ÉÒÉÈÕÀúÓòÃû  £¬Éæ¼°2018Ììϱ­¡¢ÒÁ˹À¼HijriÈÕÀúµÈÖ÷Ìâ  £¬ÖðÈÕÀÛ¼ÆÎüÊÕÔ¼400Íò´ÎÃÀ¹úΪÖ÷µÄÈ«ÃÀ»á¼ûÇëÇó¡£³Á¶´Êý¾ÝÏÔʾ  £¬ÕâЩ»á¼û¶àΪÒѶ©ÔÄÓû§µÄºǫ́ͬ²½ÇëÇó  £¬Òâζ׎ÓÊÜÓâÆÚÓòÃûµÄ¹¥»÷Õß¿ÉÖ±½ÓÏòÓû§×°±¸ÍÆËͶ¨ÖÆ»¯¶ñÒâÈÕÀúÊÂÎñ¡£


https://www.infosecurity-magazine.com/news/threat-actors-exploit-calendar-subs/


3. PlayÀÕË÷Èí¼þ¹¥»÷ADC Aerospace


11ÔÂ29ÈÕ  £¬ÃÀ¹úº½¿Õº½ÌìÓë¹ú·ÀÁìÓò¹¤³Ì²¿¼þÖÆÔìÉÌADC AerospaceÒò·þÎñŵ˹ÂÞÆÕ¡¤¸ñ³Âü¡¢¿ÂÁÖ˹º½¿Õº½Ìì¡¢»ôÄáΤ¶ûµÈ×ÅÃûÆóÒµ  £¬³ÉΪÀÕË÷Èí¼þ¹¥»÷ÖØµãÄ¿µÄ¡£´Ë´Î¹¥»÷ÓÉÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þ¼¯ÍÅÖ®Ò»PlayʵÑé  £¬¸Ã×éÖ¯ÒÔй¶¿Í»§Êý¾ÝΪҪЮÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð  £¬Èô¾Ü¾øÔòÐû²¼²¿·ÖÊý¾ÝƬ¶Ï¡£ºÚ¿ÍÉù³ÆÒÑ»ñÈ¡¿Í»§Îļþ¡¢Ô¤Ëã²ÆÎñÐÅÏ¢¡¢Ð½×ʼͼ¡¢Éí·Ý֤ʵµÈ˽ÃÜÊý¾Ý  £¬µ«Î´ÌṩÑù±¾  £¬ÕæÊµÐÔ´ýºË²é¡£ÈôÊý¾Ýй¶Êôʵ  £¬ADC½«ÃæÁÙ¶àÖØÎ£º¦£º°µÍø¶Ô¹ú·À³Ð°üÉÌÊý¾ÝµÄ¸ßÐèÇó¿ÉÄÜÍÆ¶¯±»µÁÐÅÏ¢ÉúÒ⣻н×ʼͼÖеÄСÎÒ˽¼ÒÐÅÏ¢¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£»ÆäËû˽ÃÜÊý¾ÝÔò¿ÉÄܳÉΪÉç»á¹¤³Ì¹¥»÷¹¤¾ß  £¬¹¥»÷Õßð³äÐÐÒµÏà¹Ø·½ÊµÑé¸ü¾ßÆÆËðÐÔµÄÕ©Æ­¡£Play¼¯ÍÅÈ¥ÄêõÒÉíÈ«Çò×î»îÔ¾ÀÕË÷Èí¼þǰÈý  £¬½ñÄê8Ô³õ¸ÕÈëÇÖΪÃÀ¹úˮʦ¡¢²¨Òô¹©»õµÄJamco Aerospace¡£


https://cybernews.com/security/adc-aerospace-breach-claims/


4. CoupangÔâÓöº«¹úÊ·ÉÏ×î´ó¹æÄ £¿Í»§Êý¾Ýй¶ÊÂÎñ


11ÔÂ30ÈÕ  £¬±»ÓþΪ¡°º«¹úÑÇÂíÑ·¡±µÄº«¹úµçÉ̾ÞÍ·CoupangÓÚ11ÔÂ18ÈÕÅû¶һÆð´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ  £¬Ó°Ïì½ü3400Íò¸ö¿Í»§ÕË»§  £¬´´º«¹úµ¥´ÎÊý¾Ýй¶ӰÏì¹æÄ£Ö®×î¡£¾­ÊÓ²ì  £¬¹¥»÷Õß×Ô6ÔÂ24ÈÕÆðͨ¹ýÍâÑó·þÎñÆ÷Ìᳫδ¾­ÊÚȨ»á¼û  £¬Öð²½À©´ó¹¥»÷¹æÄ£  £¬×îÖÕµ¼Ö³¬3300Íòº«¹úÓû§Êý¾ÝÍâй¡£Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç×ÓÓÊÏä¡¢µç»°ºÅÂë¡¢ÊÕ»õµØµã¼°²¿·Ö¶©µ¥¼Í¼  £¬µ«Ö§¸¶ÐÅÏ¢ÓëµÇ¼ƾ֤δ±»»ñÈ¡¡£CoupangÔÚ·¢Ã÷Òì³£ºóÁ¬Ã¦Ïòº«¹úСÎÒ˽¼ÒÐÅÏ¢±£»¤Î¯Ô±»á¡¢¾¯·½¼°»¥ÁªÍøÇå¾²¾Ö±¨¸æ  £¬²¢Æô¶¯Ó¦¼±ÏìÓ¦¡£¹«Ë¾×î³õÎóÅнöÔ¼4500ÈËÊÜÓ°Ïì  £¬ºóÐÞÕýΪ³¬3300ÍòÈË  £¬Í¹ÏÔ³õÆÚ¼ì²â»úÖÆµÄȱ·¦¡£º«¹úÕþ¸®¶Ô´Ë¸ß¶ÈÖØÊÓ  £¬¿ÆÑ§ÊÖÒÕÐÅϢͨѶ²¿²¿³¤ÅᾩѫÖÜÈÕÖ÷³Ö½ôÆÈ¾Û»á  £¬ºË²éCoupangÊÇ·ñÎ¥·´¡¶Ð¡ÎÒ˽¼ÒÐÅÏ¢±£»¤·¨¡·Çå¾²¹æ·¶¡£º«¹ú»¥ÁªÍøÇå¾²ÕñÐËÔº£¨KISA£©ÒÑÏòÊÜÓ°ÏìÓû§Ðû²¼·À´¹ÂÚÕ©Æ­Ö¸ÄÏ  £¬½¨Òé°´ÆÚÐÞ¸ÄÃÜÂë¡¢ÆôÓÃË«ÒòËØÈÏÖ¤¡£´Ë´ÎÊÂÎñÒÑÒý·¢Óû§ÕûÌåËßËÏΣº¦  £¬CoupangÕýÃæÁÙÖ´·¨×·ÔðÓëÐÅÓþÖØ´´µÄË«ÖØÑ¹Á¦¡£


https://cybernews.com/news/coupang-confirms-massive-data-breach-exposing-33-7-million-accounts/


5. ¾¯·½²é·âÁËCryptomixer¼ÓÃÜÇ®±Ò»ìÏý·þÎñ


12ÔÂ1ÈÕ  £¬ÈðÊ¿ÓëµÂ¹úÖ´·¨²¿·Ö¿ËÈÕÍŽῪչ¡°°ÂÁÖÆ¥ÑÇÐж¯¡±  £¬ÓÚ11ÔÂ24ÈÕÖÁ28ÈÕÔÚËÕÀèÊÀ²é·â¼ÓÃÜÇ®±Ò»ìÏý·þÎñCryptomixer¡£¸Ãƽ̨×Ô2016ÄêÔËÓªÒÔÀ´  £¬±»Ö¸Ð­ÖúÍøÂç·¸·¨·Ö×ÓÏ´Ç®³¬13ÒÚÅ·Ôª±ÈÌØ±Ò  £¬³ÉΪÀÕË÷Èí¼þÍŻ°µÍøÊг¡¼°µØÏ¾­¼ÃÂÛ̳»ìÏý·¸·¨×ʽðµÄ½¹µãÇþµÀ¡£Ðж¯ÖÐ  £¬Ö´·¨»ú¹¹ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÓëÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖÏ  £¬²é»ñÈý̨·þÎñÆ÷¡¢12TBÊý¾Ý¡¢Ã÷Íø¼°Tor°µÍøÓòÃû  £¬²¢¿ÛѺ¼ÛÖµ2400ÍòÅ·Ôª±ÈÌØ±Ò¡£Cryptomixerͨ¹ý»ìÊÊÓû§¼ÓÃÜÇ®±ÒÖÁ×Ê½ð³Ø²¢·Ö·¢ÖÁÐÂÇ®°üµØµã  £¬ÓÐÓÃ×è¶ÏÇø¿éÁ´×ʽð×·×Ù  £¬³ÉΪ··¶¾¡¢ÎäÆ÷×ß˽¡¢ÀÕË÷¹¥»÷¼°Ö§¸¶¿¨Ú²Æ­µÈ·¸·¨Ô˶¯µÄÏ´Ç®Ê×Ñ¡¹¤¾ß¡£ÆäÔËӪģʽ»¹°üÀ¨¶ÔÏ´Ç®×ʽðÊÕȡӶ½ð  £¬ÔÙ×ªÒÆÖÁ¿Í»§Ö¸¶¨Ç®°ü  £¬×îÖÕͨ¹ýÒøÐлòATM½«²»·¨×ʲúת»»Îª·¨±Ò»òÆäËû¼ÓÃÜÇ®±Ò¡£´ËÀà·þÎñËä±£´æÕýµ±ÓÃ;  £¬µ«Ö÷Òª±»·¸·¨ÍÅ»ïÓÃÓÚÌÓ±Ü×·²é¡£


https://www.bleepingcomputer.com/news/security/police-takes-down-cryptomixer-cryptocurrency-mixing-service/


6. CISA½«OpenPLC ScadaBRÎó²îÌí¼Óµ½KEVĿ¼ÖÐ


12ÔÂ1ÈÕ  £¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕ½«±àºÅΪCVE-2021-26829µÄOpenPLC ScadaBRÎó²îÄÉÈëÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼¡£¸ÃÎó²îΪ¿çÕ¾¾ç±¾£¨XSS£©Îó²î  £¬Í¨¹ýsystem_settings.shtmÎļþÓ°ÏìWindowsºÍLinux°æ±¾  £¬ÏêÏ¸Éæ¼°Windows¶Ë1.12.4¼°¸üÔç°æ±¾¡¢Linux¶Ë0.9.1¼°¸üÔç°æ±¾  £¬CVSSÆÀ·ÖΪ5.4¡£2025Äê9Ô  £¬Ç×¶íºÚ¿Í×éÖ¯TwoNetÕë¶ÔÍøÂçÇå¾²¹«Ë¾ForescoutÔËÓªµÄICS/OTÃÛ¹ÞϵͳÌᳫ¹¥»÷  £¬ÎóÅÐÆäΪˮ´¦Öóͷ£³§¡£¹¥»÷ÕßʹÓÃĬÈÏÆ¾Ö¤»ñȡϵͳ»á¼ûȨÏÞºó  £¬½¨ÉèÃûΪ¡°BARLATI¡±µÄÕË»§  £¬²¢Í¨¹ýCVE-2021-26829Îó²î¸Ä¶¯ÈË»ú½çÃæ£¨HMI£©µÇÂ¼Ò³Ãæ  £¬Ã¿´Î»á¼û¸ÃÒ³ÃæÊ±  £¬»á´¥·¢°üÀ¨Ôà»°µÄµ¯´°ÖÒÑÔ  £¬Í¬Ê±½ûÓÃÈÕÖ¾ºÍ¾¯±¨¹¦Ð§¡£Æ¾Ö¤¾ßÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01  £¬Áª°îÃñÓûú¹¹£¨FCEB£©ÐëÔÚ2025Äê12ÔÂ19ÈÕǰÐÞ¸´¸ÃÎó²î  £¬ÒÔ½µµÍÖØ´óΣº¦¡£CISAͬʱ½¨Òé˽Ӫ»ú¹¹Éó²éKEVĿ¼  £¬ÊµÊ±ÐÞ²¹×ÔÉí»ù´¡ÉèÊ©ÖеÄͬÀàÎó²î  £¬±ÜÃⱻʹÓá£


https://securityaffairs.com/185185/security/u-s-cisa-adds-an-openplc-scadabr-flaw-to-its-known-exploited-vulnerabilities-catalog.html