ºÚ¿Í¶µÊÛÑÇÃÀÄáÑÇÕþ¸®800ÍòÌõ¹Ù·½¼Í¼

Ðû²¼Ê±¼ä 2026-01-14

1. ºÚ¿Í¶µÊÛÑÇÃÀÄáÑÇÕþ¸®800ÍòÌõ¹Ù·½¼Í¼


1ÔÂ13ÈÕ  £¬¿ËÈÕ  £¬ºÚ¿Í¡°dk0m¡±ÔÚµØÏÂÂÛ̳ÒÔ2500ÃÀÔª±ê¼Û¶µÊ۾ݳÆÀ´×ÔÑÇÃÀÄáÑÇÕþ¸®µÄº£Á¿Êý¾Ý  £¬°üÀ¨Ô¼800ÍòÌõ¹Ù·½Í¨Öª¼Í¼  £¬Éæ¼°¾¯·½¡¢Ë¾·¨»ú¹¹ÎÄÊé¼°µç×ÓÃñÊÂËßËÏÆ½Ì¨ÐÅÏ¢¡£ÑÇÃÀÄáÑǹ«¹²¹ØÏµÓëÐÅÏ¢ÖÐÐÄÖÜÁùÐû²¼ÉùÃ÷  £¬·ñ¶¨Õþ¸®ÓʼþϵͳÔâÈëÇÖ  £¬µ«ÆðÔ´ºË²éÏÔʾÊý¾Ý¿ÉÄÜÔ´×Ôµç×ÓÃñÊÂËßËÏÆ½Ì¨  £¬²¢ÒÑÆô¶¯ÄÚ²¿ÊÓ²ìÒÔÈ·ÈÏÊý¾ÝȪԴ¼°»á¼û·½·¨¡£·ÇÕþ¸®×éÖ¯ÑÇÃÀÄáÑÇÍøÂçÇå¾²ÖÐÐÄÖ¸³ö  £¬¡°dk0m¡±ÊǵØÏÂÂÛ̳ÎÛÃûÕÑÖøµÄÐÅÏ¢ÖÐÐÄÉÌ  £¬×Ô2024ÄêÆð±ãÓÐÊÛÂô¶à¹úÕþ¸®Êý¾ÝµÄǰ¿Æ  £¬°üÀ¨°¢¸ùÍ¢¡¢ÎÚ¿ËÀ¼¡¢°ÍÎ÷µÈ²¿Î¯Êý¾Ý¡£¸ÃºÚ¿Íͨ³£Í¨¹ýÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ  £¬´ÓÊÜѬȾװ±¸ÖÐÇÔÈ¡ÕË»§Æ¾Ö¤ºÍ»á»°Cookie  £¬½ø¶ø»ñÈ¡Ãô¸ÐÕþ¸®ÃÅ»§ÍøÕ¾µÄ»á¼ûȨÏÞ  £¬²¢½«ÇÔÈ¡Êý¾Ý´ò°üתÊÛ¡£ÎªÔöÇ¿¿ÉÐŶÈ  £¬Æä³£¶ÔÍâ·ÖÏíÊý¾ÝÑù±¾»òÊý¾Ý¿â½á¹¹¡£2024Äê8ÔÂÏà¹Ø½ØÍ¼ÏÔʾ  £¬¸ÃºÚ¿Í¿ÉÄÜÒÑÌáǰ»ñÈ¡ÑÇÃÀÄáÑÇÕþ¸®Êý¾Ý  £¬´Ë´Î¶µÊÛÐÐΪ»òΪ±äÏÖÔçǰÇÔÈ¡×ÊÁÏ¡£


https://therecord.media/armenia-probes-alleged-sale-government-records


2. ºÚ¿ÍÉù³ÆÕÆÎÕ°üÀ¨7800Íò¸öÎļþµÄDiscordÊý¾Ý¼¯


1ÔÂ12ÈÕ  £¬¿ËÈÕ  £¬ÍþвÐÐΪÕßHawkSecÔÚÆäDiscord·þÎñÆ÷¡°Hello Hawks Community¡±ÖÐÐû³Æ  £¬ÕýÅÄÂôÒ»¸ö°üÀ¨78,541,207¸öÎļþµÄDiscordÊý¾Ý¼¯  £¬¸ÃÊý¾Ý¼¯°´ÐÂÎÅ¡¢ÓïÒô»á»°¡¢²Ù×÷ºÍ·þÎñÆ÷·ÖÀàÕûÀí  £¬Ô´ÓÚÒ»¸öÒÑ·ÅÆúµÄ¿ªÔ´Ç鱨ÏîÄ¿¡£HawkSecͨ¹ýÖ¸¶¨ÇþµÀÔ¼ÇëDZÔÚÂò¼Òѯ¼Û»ñÈ¡Ñù±¾  £¬µ«¹ûÕæÇþµÀδ͸¶Ïêϸ¼ÛÇ®¡£´Ë´ÎÊÂÎñ²¢·Ç¹ÂÀý¡£2025Äê  £¬ÍøÂç·¸·¨ÂÛÌ³Ôø·ºÆð³öÊÛ´Ó½ü1000¸ö¹«¹²·þÎñÆ÷ץȡµÄ3.48ÒÚÌõÐÂÎŵÄÇåµ¥£»Ñо¿Ö°Ô±Ò²ÔøÐû²¼¡°Discord Unveiled¡±Êý¾Ý¼¯  £¬°üÀ¨Í¨¹ýAPI´Ó3,167¸ö·þÎñÆ÷»ñÈ¡µÄ20ÒÚÌõÐÂÎÅ¡£±¾´Î7800ÍòÎļþµÄÊý¾Ý¼¯ÏÔʾ  £¬Êý¾Ýץȡ¹æÄ£¿ÉÄÜÕë¶ÔDiscord¡°Ì½Ë÷¡±ÁбíÖеĹ«¹²·þÎñÆ÷¡£Ö»¹Üδ¾­Ö¤Êµ°üÀ¨Ë½ÈËÊý¾Ý  £¬µ«¾ÛºÏµÄ¹ûÕæÈÕÖ¾ÔÚ½»Ö¯ÒýÓÃÆäËûȪԴʱ  £¬±£´æÓû§ÖØÐÂʶ±ðµÄΣº¦¡£Discord¼á³ÖÒÔΪ¹ûÕæÆµµÀÊÇ×ÔÓÉ»á¼ûµÄ  £¬ÒÔ´ËÇø·ÖÊý¾ÝץȡÓëÊý¾Ýй¶¡£


https://cybersecuritynews.com/discord-breach-claim/


3. TargetÔ±¹¤Ö¤ÊµÐ¹Â¶µÄÔ´´úÂëÊôʵ


1ÔÂ13ÈÕ  £¬¿ËÈÕ  £¬ºÚ¿ÍÔÚGiteaƽ̨Ðû²¼ÒÉËÆTargetÄÚ²¿Ô´´úÂëÑù±¾²¢Éù³Æ³öÊÛ  £¬Òý·¢Çå¾²¹Ø×¢¡£¶àÃûÏÖÈμ°Ç°ÈÎTargetÔ±¹¤Ëæºó֤ʵ  £¬Ð¹Â¶ÖÊÁÏÖеÄϵͳÃû³Æ£¨Èç¡°BigRED¡±¡°TAP [Provisioning]¡±£©¡¢ÊÖÒÕÕ»£¨ÈçHadoopÊý¾Ý¼¯¡¢»ùÓÚVelaµÄ¶¨ÖÆCI/CDƽ̨¡¢JFrog Artifactory£©¼°×¨ÓÐÏîÄ¿´úºÅ£¨Èç¡°blossom ID¡±£©¾ùÓëÕæÊµÄÚ²¿ÏµÍ³ÍêȫƥÅä  £¬URL½á¹¹¼°Ô±¹¤ÐÕÃûµÈϸ½ÚÒàÑéÖ¤ÁËÖÊÁϵÄÕæÊµÐÔ  £¬É¨³ýαÔì¿ÉÄÜ¡£ÎªÓ¦¶ÔDZÔÚΣº¦  £¬Target24СʱÄÚ½ôÆÈÍÆ³ö¡°¼ÓËÙ¡±Çå¾²±ä»»£º×Ô2026Äê1ÔÂ9ÈÕÆð  £¬»á¼ûÆóÒµGit·þÎñÆ÷£¨git.target.com£©Ðèͨ¹ýTargetÄÚ²¿ÍøÂç»òVPN  £¬´Ëǰ¸Ã·þÎñÆ÷¿Éͨ¹ý¹«¹²»¥ÁªÍø»á¼û¡£´Ë¾ÙÖ¼ÔÚ·â±ÕרÓÐÔ´´úÂëÇéÐÎ  £¬ÓëGitHub.comµÄ»á¼ûÖÎÀí·½·¨¼á³ÖÒ»Ö¡£¹¥»÷ÕßÉù³ÆÍêÕûÊý¾Ý¼¯Ô¼860GB¡£Çå¾²Ñо¿Ô±½öÉó²éÁË14MBµÄÑù±¾£¨º¬Îå¸ö´úÂë¿â£©  £¬µ«Ô±¹¤ÌåÏÖ×ÝÈ»¸Ã×Ó¼¯Ò²°üÀ¨ÕæÊµÄÚ²¿´úÂë  £¬Òý·¢¶Ô¸ü´óÊý¾Ý¼¯¹æÄ£¼°Ãô¸ÐÐԵĵ£ÐÄ¡£


https://www.bleepingcomputer.com/news/security/target-employees-confirm-leaked-source-code-is-authentic/


4. BettermentÔâºÚ¿ÍÈëÇÖÒý·¢¼ÓÃÜÇ®±ÒȦÌ×


1ÔÂ13ÈÕ  £¬ÃÀ¹úÖÇÄÜͶ¹ËÏÈÇýBetterment¿ËÈÕ֤ʵ  £¬ºÚ¿Íͨ¹ýÆäµÚÈý·½ÓªÏúƽ̨Ïò²¿·Ö¿Í»§·¢ËÍÐéα¼ÓÃÜÇ®±Ò½±ÀøÈ¦Ì×Óʼþ  £¬ÓÕÆ­Óû§¼ÓÈë"´æ¿î·­Èý±¶"´ÙÏúÔ˶¯¡£¸ÃÊÂÎñÉæ¼°Áè¼Ý°ÙÍò¿Í»§¼°650ÒÚÃÀÔª×ʲúÖÎÀí¹æÄ£  £¬Òý¿¯ÐÐÒµ¸ß¶È¹Ø×¢¡£1ÔÂ9ÈÕ  £¬¹¥»÷ÕßʹÓÃBettermentÓÃÓÚÓªÏúÔ˶¯µÄµÚÈý·½Èí¼þÎó²î  £¬ÒÔÕýµ±×ÓÓòÃû"mailto:support@e.betterment.com"·¢ËÍÖ÷ÌâΪ"ÎÒÃǽ«Ê¹ÄúµÄ¼ÓÃÜÇ®±Ò·­Èý±¶£¡£¨ÏÞʱ£©"µÄڲƭÓʼþ¡£ÓʼþÉù³ÆÔÚ"2025Äê1ÔÂ9ÈÕ20:45ǰ"´æÈë±ÈÌØ±Ò»òÒÔÌ«·»¿É»ñÈý±¶»Ø±¨  £¬²¢¸½ÓÐÎüÊÕÉÏÏÞ75ÍòÃÀÔªµÄ±ÈÌØ±ÒºÍÒÔÌ«·»Ç®°üµØµã¡£BettermentËæºó½ôÆÈÐû²¼ÉùÃ÷  £¬Ç¿µ÷Æä½¹µãÊÖÒÕ»ù´¡ÉèʩδÊÜÓ°Ïì  £¬¿Í»§ÕË»§Î´±»»á¼û  £¬µ«²¿·Ö¿Í»§È«Ãû¡¢ÓÊÏä¡¢ÎïÀíµØµã¡¢µç»°¼°³öÉúÈÕÆÚµÈÃô¸ÐÐÅÏ¢Òòϵͳ±»ÈëÇÖ¶øÐ¹Â¶¡£BettermentÔÚ1ÔÂ10ÈÕºóÐøÏàͬÖÐÈ·ÈÏ  £¬Î´¾­ÊÚȨ»á¼ûÒѱ»É¨³ý  £¬ÎÞÖ¤¾ÝÅú×¢¿Í»§ÕË»§±»»á¼û¡£È»¶ø  £¬¹«Ë¾ËæºóÔâÓöÀÕË÷¹¥»÷¼°ÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷  £¬µ¼Ö²¿·ÖÓû§µÇ¼×ÀÃæºÍÒÆ¶¯Ó¦ÓÃʱÓöµ½ÎÊÌâ¡£


https://www.bleepingcomputer.com/news/security/betterment-confirms-data-breach-after-wave-of-crypto-scam-emails/


5. ±ÈÀûʱAZ MonicaÒ½ÔºÔâÍøÂç¹¥»÷ÖÂÖØ´ó·þÎñÖÐÖ¹


1ÔÂ13ÈÕ  £¬±ÈÀûʱ×ÛºÏÒ½ÔºÍøÂçAZ MonicaÒòÍøÂç¹¥»÷±»ÆÈ¹Ø±ÕËùÓзþÎñÆ÷  £¬µ¼Ö°²ÌØÎÀÆÕºÍµÂ¶ûÚ«Á½´¦ÔºÇøµÄÒ½ÁÆ·þÎñÑÏÖØÊÜ×è¡£¸ÃÔº×÷ΪÍâµØÖ÷ÒªµÄÒ½ÁÆÌṩ·½  £¬º­¸Ç¼±Õï¡¢ÃÅÕPר¿Æ·þÎñ  £¬´Ë´ÎÊÂÎñÒý·¢ÆÕ±é¹Ø×¢¡£ÔçÉÏ6:32  £¬Ò½Ôº¼ì²âµ½ÏµÍ³Òì³£ºó  £¬×Ô¶¯ÇжÏËùÓзþÎñÆ÷ÅþÁ¬¡£×÷ΪԤ·À²½·¥  £¬µ±ÈÕËùÓÐÔ¤¶¨ÊÖÊõ±»×÷·Ï  £¬»¼ÕßÒÑ»ñ֪ͨ¡£¼±Õï¿ÆËäά³ÖÓÐÏÞ½ÓÕïÄÜÁ¦  £¬µ«¾È»¤³µÒÑ×èÖ¹Ïò¸Ã¿ÆÔËËͲ¡ÈË  £¬½¨ÒéסÃñÓÅÏÈÁªÏµ¼ÒÍ¥Ò½Éú¡¢Ò¹¼äÕïËù»òÆäËû¼±Õï»ú¹¹¡£·Ç½ôÆÈ»áÕïÒòµç×Ó²¡ÀúÎÞ·¨»á¼û¶øÍƳÙ  £¬ÃÅÕï×ÉѯÔòÕý³£¾ÙÐС£ÔÚºìÊ®×Ö»áЭÖúÏ  £¬Ò½ÔºÍ¨¹ý¾È»¤³µÇå¾²×ªÒÆÆßÃûÎ£ÖØ²¡ÈËÖÁÆäËû»ú¹¹  £¬ÆäÓ໼ÕßÈÔÔÚÔºÄÚ½ÓÊÜÖÎÁÆ¡£Ôº·½Ç¿µ÷  £¬»¼ÕßÇå¾²ÓëÒ½ÁÆÒ»Á¬ÐÔΪÖ÷ҪʹÃü  £¬½«Ò»Á¬¼à²âÊÂ̬²¢¸üÐÂÐÅÏ¢¡£


https://securityaffairs.com/186882/cyber-crime/az-monica-hospital-in-belgium-shuts-down-servers-after-cyberattack.html


6. ÎÚ¹ú·À¾üÔâ¶íºÚ¿Í´ÈÉÆ´¹ÂÚ¹¥»÷Ö²ÈëPluggyApeºóÃÅ


1ÔÂ13ÈÕ  £¬ÎÚ¿ËÀ¼¹ú·À¾ü¹ÙÔ±2025Äê10ÔÂÖÁ12Ô³ÉΪ¶íÂÞ˹Åä¾°Íþв×éÖ¯¡°Ðé¿Õ±©Ñ©¡±Óë¡°Ï´ÒÂÐÜ¡±ÌᳫµÄ¶¨ÏòÍøÂç¹¥»÷Ä¿µÄ¡£¾ÝÎÚ¿ËÀ¼CERT-UA±¨¸æ  £¬¹¥»÷Õßͨ¹ýSignal/WhatsApp·¢ËÍαװ³É´ÈÉÆÔ˶¯µÄ´¹ÂÚÐÂÎÅ  £¬ÓÕµ¼Ä¿µÄ»á¼ûÐéα´ÈÉÆÍøÕ¾²¢ÏÂÔØº¬ÃÜÂë±£»¤µÄѹËõÎļþ¡£ÕâЩÎļþʵΪ¶ñÒâ¿ÉÖ´ÐгÌÐò£¨Èç.docx.pif£©  £¬ÄÚº¬PluggyApeºóÃŶñÒâÈí¼þ  £¬¸ÃÈí¼þÓÉPyInstaller´ò°ü  £¬¿ÉÆÊÎöÖ÷»úÐÅÏ¢¡¢·¢ËÍΨһ±êʶ·ûÖÁ¹¥»÷Õß  £¬²¢Í¨¹ýÐÞ¸ÄWindows×¢²á±íʵÏÖ³¤ÆÚ»¯¡£¹¥»÷Á´ÏÔʾ  £¬ÔçÆÚ°æ±¾Ê¹ÓÃ.pdf.exeÀ©Õ¹Ãû×÷Ϊ¼ÓÔØÆ÷  £¬2025Äê12ÔÂÆðÉý¼¶ÎªPIFÃûÌü°PluggyApe v2°æ±¾  £¬¾ß±¸¸üÇ¿µÄ»ìÏýÄÜÁ¦¡¢»ùÓÚMQTTµÄͨѶ·½·¨¼°·´ÆÊÎö¼ì²é¡£ÆäC2µØµã´Órentry.co¡¢pastebin.comµÈÍⲿƽ̨ÒÔbase64±àÂ붯̬»ñÈ¡  £¬×èÖ¹Ó²±àÂëÎó²î¡£ÖµµÃ×¢ÖØµÄÊÇ  £¬¹¥»÷Õß³£Ê¹Óñ»µÁµÄÎÚ¿ËÀ¼µçÐÅÔËÓªÉÌÕË»§»òµç»°ºÅÂë  £¬ÍŽá¶ÔÄ¿µÄСÎÒ˽¼Ò¼°×éÖ¯µÄÉî¶ÈÏàʶ  £¬Í¨¹ýÎÚ¿ËÀ¼ÓïÒôƵ/ÊÓÆµÍ¨Ñ¶ÔöÇ¿¹¥»÷¿ÉÐŶÈ  £¬Ê¹Òƶ¯×°±¸³ÉΪÖ÷ÒªÉøÍ¸Ä¿µÄ  £¬´ËÀà×°±¸Òò·À»¤±¡Èõ¸üÒ×±»¹¥ÆÆ¡£


https://www.bleepingcomputer.com/news/security/ukraines-army-targeted-in-new-charity-themed-malware-campaign/