GhostPosterÒþд¹¥»÷£ºFirefoxÀ©Õ¹Ç±ÔÚΣ»£»£»£»£»ú
Ðû²¼Ê±¼ä 2025-12-181. GhostPosterÒþд¹¥»÷£ºFirefoxÀ©Õ¹Ç±ÔÚΣ»£»£»£»£»ú
12ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬Koi SecurityÑо¿Ö°Ô±½ÒÆÆÒ»ÏîÃûΪ"GhostPoster"µÄÐÂÐÍÍøÂç¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Í¨¹ý½«JavaScript´úÂëÒþ²ØÔÚÏÂÔØÁ¿³¬5Íò´ÎµÄFirefox¶ñÒâÀ©Õ¹³ÌÐòͼÏñ»Õ±êÖУ¬£¬£¬£¬£¬£¬ÊµÏÖä¯ÀÀÆ÷¼à¿ØÓëºóÃÅÖ²Èë¡£¡£¡£¡£¶ñÒâ´úÂ븶Óë¹¥»÷Õß³¤ÆÚ¸ßȨÏÞ»á¼ûÄÜÁ¦£¬£¬£¬£¬£¬£¬¿ÉÐ®ÖÆµçÉÌͬÃËÁ´½Ó¡¢×¢Èë¸ú×Ù´úÂ롢ʵÑéµã»÷¼°¹ã¸æÚ²Æ£¬£¬£¬£¬£¬£¬²¢ÒƳýHTTPÏìÓ¦ÖеÄÇå¾²±êÍ·¡£¡£¡£¡£¸Ã¹¥»÷½ÓÄÉÒþ²Ø¼ÓÔØÆ÷»úÖÆ£ºÒþ²Ø¾ç±¾Ã¿Ê®´ÎʵÑé½ö»ñȡһ´ÎÓÐÓÃÔØºÉ£¬£¬£¬£¬£¬£¬ÅäºÏ48Сʱ¼¤»îÑÓ³Ù¼°±¸ÓÃÓòÃûÉè¼Æ£¬£¬£¬£¬£¬£¬´ó·ù½µµÍ±»½»Í¨¼à¿Ø¹¤¾ß¼ì²âµÄΣº¦¡£¡£¡£¡£ÓÐÓÃÔØºÉ¾¾Þϸд½»Á÷¡¢Base64±àÂë¼°Òì»ò¼ÓÃÜ´¦Öóͷ££¬£¬£¬£¬£¬£¬ÐèʹÓÃÀ©Õ¹³ÌÐòÔËÐÐʱIDÅÉÉúÃÜÔ¿½âÂë¡£¡£¡£¡£×îÖÕÔØºÉ¾ß±¸¶àÖØ¶ñÒ⹦Ч£ºÔÚËùÓÐÒ³Ãæ×¢ÈëGoogle Analytics¸ú×Ù´úÂ룻£»£»£»£»Í¨¹ýÈýÖÖ»úÖÆÈÆ¹ýÑéÖ¤Â룻£»£»£»£»×¢Èë15Ãëºó×Ô¶¯É¾³ýµÄ²»¿É¼ûiframe¾ÙÐÐ¹ã¸æÚ²Æ£»£»£»£»£»Ð®ÖÆÍ¬ÃËÁ´½Ó½«Ó¶½ðÖØ¶¨ÏòÖÁ¹¥»÷Õß¡£¡£¡£¡£Ñо¿Ê¶±ð³ö17¸ö±»ÈëÇÖµÄFirefoxÀ©Õ¹³ÌÐò£¬£¬£¬£¬£¬£¬¾ùÀ´×ÔÈÈÃÅÖÖ±ðÈç"ÓÀÊÀÃâ·ÑVPN""×î¼ÑÌìÆøÔ¤¸æ""crxmouseÊÖÊÆ"µÈ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ghostposter-attacks-hide-malicious-javascript-in-firefox-addon-logos/
2. ÑÇÂíÑ·×è¶Ï¶íÂÞ˹GRUºÚ¿Í¹¥»÷
12ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·ÍþвÇ鱨ÍŶÓÀÖ³É×èÖ¹Á˶íÂÞ˹¶ÔÍâ¾üÊÂÇ鱨»ú¹¹GRUÆìϺڿÍÕë¶Ô¿Í»§ÔÆ»ù´¡ÉèÊ©µÄÒ»Á¬¹¥»÷»î¶¯¡£¡£¡£¡£¸ÃÐж¯×Ô2021ÄêÆð¾Û½¹Î÷·½Òªº¦»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬ÓÈÆäÊÇÄÜÔ´ÁìÓò£¬£¬£¬£¬£¬£¬²¢·ºÆðÕ½ÊõÑݱäÌØÕ÷£º¹¥»÷Õß´ÓÒÀÀµÁãÈÕÎó²îÓëÒÑÖªÎó²îתÏòÃé×¼ÉèÖùýʧµÄ±ßÑØ×°±¸£¬£¬£¬£¬£¬£¬ÈçÆóҵ·ÓÉÆ÷¡¢VPNÍø¹Ø¡¢ÍøÂçÖÎÀí×°±¸¼°ÔÆÐ×÷ƽ̨£¬£¬£¬£¬£¬£¬Í¨¹ý̻¶µÄÖÎÀí½Ó¿ÚʵÏÖ"µÍͶÈë¸ß»Ø±¨"µÄÒ»Á¬»á¼û¡£¡£¡£¡£ÑÇÂíÑ·Ê×ϯÐÅÏ¢Çå¾²¹ÙCJ MosesÖ¸³ö£¬£¬£¬£¬£¬£¬ÕâÖÖÕ½ÂÔµ÷½â·´Ó¦ÁËÍþвÐÐΪÕßµÄ"ЧÂÊÓÅÏÈ"תÏò£¬£¬£¬£¬£¬£¬2025Äê¹¥»÷ÕßÏÔÖøïÔ̶ÔÎó²îµÄͶ×Ê£¬£¬£¬£¬£¬£¬×ª¶øÊ¹Óÿͻ§ÍøÂçÖÐ"ÍÙÊֿɵÃ"µÄÉèÖÃȱÏÝ£¬£¬£¬£¬£¬£¬ÒÔ×îС̻¶Σº¦Íê³Éƾ֤ÇÔÈ¡ÓëºáÏòÒÆ¶¯¡£¡£¡£¡£Ö»¹ÜÕ½Êõת±ä£¬£¬£¬£¬£¬£¬¹¥»÷½¹µãÄ¿µÄδ±ä£ºÒ»Á¬ÉøÍ¸Òªº¦ÍøÂç²¢»ñȡƾ֤ÒÔ»á¼ûÔÚÏßЧÀÍ¡£¡£¡£¡£Í¨¹ý¹¥»÷ģʽÓë»ù´¡ÉèÊ©ÖØµþÆÊÎö£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·¸ß¶ÈȷПûÓëGRU¹ØÁªµÄSandworm£¨APT44£©¡¢Curly Comrades×éÖ¯Óйء£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬¹¥»÷δʹÓÃAWSЧÀÍÎó²î£¬£¬£¬£¬£¬£¬¶øÊÇÕë¶Ô¿Í»§ÍйÜÔÚAWS EC2ʵÀýÉϵÄÖÎÀí×°±¸¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/amazon-disrupts-russian-gru-hackers-attacking-edge-network-devices/
3. NoName057(16)×éÖ¯½èDDoSia¹¤¾ß¹¥»÷±±Ô¼
12ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬NoName057(16)£¬£¬£¬£¬£¬£¬ÓÖ³Æ05716nnm»òNoName05716£¬£¬£¬£¬£¬£¬ÊǶíÂÞ˹ÇàÄêÇéÐÎÑо¿ÓëÍøÂç¼à¿ØÖÐÐÄÄÚÔÐÓýµÄÉñÃØÏîÄ¿£¬£¬£¬£¬£¬£¬×Ô2022Äê3ÔÂÆðÒ»Á¬¶Ô±±Ô¼³ÉÔ±¹ú¼°Å·ÖÞ×éÖ¯ÌᳫÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷¡£¡£¡£¡£¸Ã×éÖ¯ÔÚ¶íÂÞ˹Áª°îÇàÄêËêÎñÊðÏòµ¼²ãÖ§³ÖÏÂÔË×÷£¬£¬£¬£¬£¬£¬Ã÷È·½«×ÔÉí¶¨Î»Îª×èµ²¶íÂÞ˹µØÔµÕþÖÎÄ¿µÄµÄÎ÷·½»ú¹¹Ö÷ÒªÍøÂçÍþв£¬£¬£¬£¬£¬£¬ÆäÐж¯Éî¶ÈÆõºÏ¶íÂÞ˹Õþ¸®ÀûÒæµ¼Ïò¡£¡£¡£¡£Æä½¹µã¹¥»÷ÄÜÁ¦ÒÀÍÐDDoSiaÏîÄ¿£¬£¬£¬£¬£¬£¬Í¨¹ýTelegramƵµÀÕÐļ×ÔÔ¸Õߣ¬£¬£¬£¬£¬£¬ÌṩÒ×ÓõÄGoÓïÑÔ¹¥»÷¹¤¾ß²¢¸¨ÒÔ¼ÓÃÜÇ®±Ò½±Àø£¬£¬£¬£¬£¬£¬ÐγÉÖÚ°ü½©Ê¬ÍøÂç¡£¡£¡£¡£ÊÖÒÕ²ãÃæ£¬£¬£¬£¬£¬£¬DDoSia½ÓÄÉÁ½½×¶ÎͨѶÐÒ飺¿Í»§¶ËÊ×ÏÈÏòÏÂÁîÓë¿ØÖÆÐ§ÀÍÆ÷·¢ËͼÓÃÜϵͳÐÅÏ¢Íê³ÉÈÏÖ¤£¬£¬£¬£¬£¬£¬»ñÈ¡200 OKÏìÓ¦ºó½øÈëµÚ¶þ½×¶Î»ñȡĿµÄÉèÖᣡ£¡£¡£Æä»ù´¡ÉèÊ©½ÓÄɵ¯ÐÔ¶à²ã¼Ü¹¹£¬£¬£¬£¬£¬£¬µÚÒ»²ã¹«ÖÚЧÀÍÆ÷ƽ¾ùÊÙÃüÔ¼9Ì죬£¬£¬£¬£¬£¬Ö±½ÓÓë¿Í»§¶ËͨѶ£»£»£»£»£»µÚ¶þ²ãºó¶ËЧÀÍÆ÷ÑÏ¿áͨ¹ýACL¿ØÖÆ»á¼û£¬£¬£¬£¬£¬£¬½öÔÊÐíÊÚȨµÚÒ»²ãЧÀÍÆ÷ÅþÁ¬£¬£¬£¬£¬£¬£¬È·±£½¹µãÂß¼ÓëÄ¿µÄÁбíÇå¾²¡£¡£¡£¡£
https://cybersecuritynews.com/noname05716-hackers-using-ddosia-ddos-tool/
4. ¶íºÚ¿Í×éÖ¯Ò»Á¬¶ÔÎÚÍøÂçÓʼþƽ̨Ìᳫ´¹ÂÚ¹¥»÷
12ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±Åû¶£¬£¬£¬£¬£¬£¬ÓɶíÂÞ˹¹ú¼ÒÖ§³ÖµÄºÚ¿Í×éÖ¯BlueDelta£¨ÓÖÃûAPT28¡¢Fancy BearµÈ£©ÔÚ2024Äê6ÔÂÖÁ2025Äê4ÔÂʱ´ú£¬£¬£¬£¬£¬£¬Õë¶ÔÎÚ¿ËÀ¼ÈÈÃÅÍøÂçÓʼþ¼°ÐÂÎÅЧÀÍÍøÕ¾UKR.NETÌᳫÁË´ó¹æÄ£ÍøÂç´¹ÂÚÐж¯£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§Æ¾Ö¤²¢ÍøÂçÃô¸ÐÐÅÏ¢ÒÔÖ§³Ö¶íÂÞ˹Ç鱨ĿµÄ¡£¡£¡£¡£¾ÝRecorded FutureÆìÏÂInsikt Group±¨¸æ£¬£¬£¬£¬£¬£¬¸Ã×é֯ͨ¹ýαÔìUKR.NETÉí·ÝÑéÖ¤ÃÅ»§µÄÐéαµÇÂ¼Ò³ÃæÊµÑé¹¥»÷¡£¡£¡£¡£Êܺ¦Õß»áÊÕµ½°üÀ¨PDF¸½¼þµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬ÕâЩ¸½¼þǶÈëÁËÖ¸ÏòÚ²ÆÒ³ÃæµÄÁ´½Ó¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬£¬£¬£¬ÕâÖÖÕ½ÂÔ¿ÉÓÐÓÃÈÆ¹ý×Ô¶¯ÓʼþÇå¾²¹ýÂËϵͳ¡£¡£¡£¡£¹¥»÷»ù´¡ÉèÊ©ÆÊÎöÏÔʾ£¬£¬£¬£¬£¬£¬Áè¼Ý20¸ö¹ØÁªPDFÎļþ±»·Ö·¢ÖÁÄ¿µÄÓû§£¬£¬£¬£¬£¬£¬ÎļþÄÚÈݻѳÆÓû§ÕË»§±£´æ¿ÉÒɻ£¬£¬£¬£¬£¬£¬ÓÕµ¼Æäµã»÷Á´½ÓÖØÖÃÃÜÂë¡£¡£¡£¡£BlueDeltaºã¾Ã´ÓÊÂÍøÂçÌØ¹¤»î¶¯£¬£¬£¬£¬£¬£¬Ê®ÓàÄê¼äÕë¶ÔÕþ¸®»ú¹¹¡¢¹ú·À³Ð°üÉÌ¡¢ÎäÆ÷¹©Ó¦É̵ÈÄ¿µÄʵÑ鯾֤ÇÔÈ¡¡£¡£¡£¡£
https://therecord.media/russian-bluedelta-hackers-ran-phishing-ukraine-webmail
5. KimwolfѬȾ180Íò×°±¸£¬£¬£¬£¬£¬£¬·¢¶¯´ó¹æÄ£DDoS¹¥»÷
12ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬ÃûΪKimwolfµÄÐÂÐÍÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©½©Ê¬ÍøÂçÒÑѬȾÖÁÉÙ180Íǫ̀װ±¸£¬£¬£¬£¬£¬£¬°üÀ¨AndroidµçÊÓ¡¢»ú¶¥ºÐ¼°Æ½°åµçÄÔ£¬£¬£¬£¬£¬£¬Æä¿ÉÄܹØÁªÎÛÃûÕÑÖøµÄAISURU½©Ê¬ÍøÂç¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÓÉNDK±àÒ룬£¬£¬£¬£¬£¬¾ß±¸DDoS¹¥»÷¡¢ÊðÀíת·¢¡¢·´Ïòshell¼°ÎļþÖÎÀí¹¦Ð§¡£¡£¡£¡£2025Äê11ÔÂ19ÈÕÖÁ22ÈÕ£¬£¬£¬£¬£¬£¬ÆäÈýÌìÄÚ·¢³ö17ÒÚÌõ¹¥»÷ÏÂÁ£¬£¬£¬£¬£¬C2ÓòÃûÔøÓâÔ½GoogleλÁÐCloudflareǰ100ÓòÃû°ñÊס£¡£¡£¡£KimwolfÖ÷ҪѬȾ¼ÒÍ¥ÍøÂçÖеĵçÊӺУ¬£¬£¬£¬£¬£¬Éæ¼°TV BOX¡¢SuperBOX¡¢HiDPTAndroidµÈÐͺţ¬£¬£¬£¬£¬£¬Ñ¬È¾¼¯ÖÐÓÚ°ÍÎ÷¡¢Ó¡¶È¡¢ÃÀ¹ú¡¢°¢¸ùÍ¢¡¢ÄϷǺͷÆÂɱö£¬£¬£¬£¬£¬£¬µ«Èö²¥Í¾¾¶Éв»Ã÷È·¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçC2ÓòÃû12ÔÂÈý´Î±»¹Ø±Õºó£¬£¬£¬£¬£¬£¬×ªÏòÒÔÌ«·»Ãû³ÆÐ§ÀÍ£¨ENS£©Ç¿»¯»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬²¢½ÓÄÉEtherHidingÊÖÒÕ´ÓÖÇÄܺÏÔ¼»ñÈ¡C2 IPµØµã£¬£¬£¬£¬£¬£¬Í¨¹ýXOR²Ù×÷ÆÊÎöÏÖʵIP£¬£¬£¬£¬£¬£¬ÔöÇ¿¿¹¹¥»÷ÄÜÁ¦¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬£¬£¬KimwolfÓëAISURU±£´æ¹ØÁª£¬£¬£¬£¬£¬£¬Á½Õßͨ¹ýÏàͬѬȾ¾ç±¾Èö²¥£¬£¬£¬£¬£¬£¬ÇÒ¹²Ïí´úÂëÊðÃûÖ¤Ê飬£¬£¬£¬£¬£¬ÊôÓÚͳһºÚ¿Í×éÖ¯¡£¡£¡£¡£Kimwolf×îа汾ÒýÈëTLS¼ÓÃÜͨѶ£¬£¬£¬£¬£¬£¬Ö§³Ö13ÖÖ»ùÓÚUDP¡¢TCPºÍICMPµÄDDoS¹¥»÷ÒªÁ죬£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄÁýÕÖÃÀ¹ú¡¢Öйú¡¢·¨¹ú¡¢µÂ¹úºÍ¼ÓÄô󡣡£¡£¡£
https://thehackernews.com/2025/12/kimwolf-botnet-hijacks-18-million.html
6. SonicWall SMA1000¸ßΣÎó²îÔâÁãÈÕ¹¥»÷ʹÓÃ
12ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²³§ÉÌSonicWall¿ËÈÕÐû²¼½ôÆÈÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬Åû¶ÆäSMA1000×°±¸ÖÎÀí¿ØÖÆÌ¨£¨AMC£©±£´æÒ»ÆäÖеÈÑÏÖØË®Æ½µÄÍâµØÈ¨ÏÞÌáÉýÎó²î£¨CVE-2025-40602£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒѱ»ÓÃÓÚÁãÈÕ¹¥»÷ÒÔÌáÉýϵͳȨÏÞ¡£¡£¡£¡£¾ÝSonicWall²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©×ª´ï£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓÉGoogleÍþвÇ鱨С×éµÄCl¨¦ment LecigneºÍZander Work±¨¸æ£¬£¬£¬£¬£¬£¬²»Ó°ÏìSonicWall·À»ðǽÔËÐеÄSSL-VPN¹¦Ð§£¬£¬£¬£¬£¬£¬µ«Ç¿ÁÒ½¨ÒéÓû§Éý¼¶ÖÁ×îÐÂÈÈÐÞ¸´°æ±¾ÒÔÐÞ¸´Îó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îÓëÁíÒ»¸öÑÏÖØ¼¶±ðµÄÔ¤Éí·ÝÑéÖ¤·´ÐòÁл¯Îó²î£¨CVE-2025-23006£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8£©×éºÏʹÓ㬣¬£¬£¬£¬£¬ÊµÏÖδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´Ðв¢»ñµÃrootȨÏÞ¡£¡£¡£¡£CVE-2025-23006ÒÑÔÚ2025Äê1ÔÂ22ÈÕÐû²¼µÄ12.4.3-02854ƽ̨ÈÈÐÞ¸´°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£»£»£»£»£»¥ÁªÍøî¿Ïµ»ú¹¹ShadowserverÏÖÔÚ×·×Ùµ½Áè¼Ý950̨̻¶ÔÚ¹«ÍøµÄSMA1000×°±¸£¬£¬£¬£¬£¬£¬Ö»¹Ü²¿·Ö×°±¸¿ÉÄÜÒÑÕë¶Ô´Ë¹¥»÷Á´¾ÙÐÐÐÞ²¹¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-new-sma1000-zero-day-exploited-in-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ