Á¢ÌÕÍðºÚ¿ÍÈö²¥KMSAuto¶ñÒâÈí¼þ±»²¶
Ðû²¼Ê±¼ä 2025-12-311. Á¢ÌÕÍðºÚ¿ÍÈö²¥KMSAuto¶ñÒâÈí¼þ±»²¶
12ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬Ò»Ãû29ËêÁ¢ÌÕÍð¼®¹«ÃñÒòÉæÏÓ¿ª·¢²¢Èö²¥Ñ¬È¾280Íǫ̀ϵͳµÄ¼ôÌù°å¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¾¹ú¼ÊÐ̾¯×é֯е÷´Ó¸ñ³¼ªÑÇÒý¶ÉÖÁº«¹úÊÜÉ󡣡£¡£¡£¡£¡£¡£¸Ã°¸¼þÉæ¼°Î±×°³ÉKMSAuto¹¤¾ßµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÆäÍâò¹¦Ð§Îª²»·¨¼¤»îWindowsºÍOfficeÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÊµÔòDZÔÚ¼ÓÃÜÇ®±ÒÐ®ÖÆÄ£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¡£¾Ýº«¹ú¹ú¼Ò¾¯Ô±Ìüת´ï£¬£¬£¬£¬£¬£¬£¬2020Äê4ÔÂÖÁ2023Äê1Ô¼䣬£¬£¬£¬£¬£¬£¬ÏÓÒÉÈËͨ¹ýKMSAuto¹¤¾ßÏòÈ«ÇòÓû§·Ö·¢280Íò·Ý¶ñÒâ³ÌÐò¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÔËÐÐʱ»á×Ô¶¯É¨ÃèÓû§¼ôÌù°åÖеļÓÃÜÇ®±ÒµØµã£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÌæ»»Îª¹¥»÷Õß¿ØÖƵĵص㣬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊܺ¦ÕßÔÚתÕËʱÎó½«×ʲúתÈëºÚ¿ÍÇ®°ü¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÀÖ³ÉÇÔÈ¡3100¸öÐéÄâ×ʲúµØµãÓû§µÄÔ¼17ÒÚº«Ôª£¨Ô¼120ÍòÃÀÔª£©×ʲú£¬£¬£¬£¬£¬£¬£¬Éæ¼°8400±ÊÉúÒ⣬£¬£¬£¬£¬£¬£¬²¢ÖÁÉÙ¹¥»÷ÁËÁù¼Ò¼ÓÃÜÇ®±ÒÉúÒâËù¡£¡£¡£¡£¡£¡£¡£°¸¼þÊÓ²ìʼÓÚ2020Äê8Ô£¬£¬£¬£¬£¬£¬£¬º«¹ú¾¯·½½Ó»ñ¼ÓÃÜÐ®ÖÆ°¸¼þ±¨¸æºó£¬£¬£¬£¬£¬£¬£¬·¢Ã÷KMSAuto¹¤¾ß±£´æ¶ñÒâ´úÂëÖ²Èë¡£¡£¡£¡£¡£¡£¡£Í¨¹ý×·×Ù±»µÁ×ʽðÁ÷Ïò£¬£¬£¬£¬£¬£¬£¬ÁªºÏ¹ú¼ÊÐ̾¯×éÖ¯Ëø¶¨ÏÓÒÉÈËÉí·Ý¡£¡£¡£¡£¡£¡£¡£2024Äê12Ô£¬£¬£¬£¬£¬£¬£¬º«·½ÔÚÁ¢ÌÕÍðʵÑéͻϮÐж¯£¬£¬£¬£¬£¬£¬£¬½É»ñÌõ¼Ç±¾µçÄÔ¡¢ÊÖ»úµÈ22¼þµç×Ó×°±¸£¬£¬£¬£¬£¬£¬£¬´ÓÖÐÌáÈ¡µ½Òªº¦·¸·¨Ö¤¾Ý¡£¡£¡£¡£¡£¡£¡£×îÖÕ£¬£¬£¬£¬£¬£¬£¬ÏÓÒÉÈËÔÚ2025Äê4ÔÂ×ÔÖ÷ÌÕÍðǰÍù¸ñ³¼ªÑÇ;Öб»²¶¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hacker-arrested-for-kmsauto-malware-campaign-with-28-million-downloads/
2. ºÚ¿ÍʹÓÃÒÅÁôÎó²îÌᳫ³¬250Íò´Î¶ñÒâÇëÇó
12ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬Ê¥µ®½Úʱ´ú£¬£¬£¬£¬£¬£¬£¬Ò»³¡Óɼòµ¥Íþв¹¥»÷ÕßÌᳫµÄ´ó¹æÄ£Ðͬ¹¥»÷ϯ¾íÈ«Çò¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÕßÒÀÍÐÈÕ±¾¾³ÄڵĻù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬Õë¶ÔAdobe ColdFusionЧÀÍÆ÷¼°ÆäËû47ÖÖÊÖÒÕÆ½Ì¨Ìᳫ³¬250Íò´Î¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬£¬Ä¿µÄº¸Ç½ü20Äê¼äµÄÒÅÁôÎó²î¼°2023-2024ÄêÅû¶µÄ10Óà¸ö¸ßΣCVEÎó²î¡£¡£¡£¡£¡£¡£¡£Ê¥µ®½Úµ±ÈÕ¹¥»÷Á÷Á¿·åÖµÕ¼±È¸ß´ï68%£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÏÔÈ»ÓÐÒâʹÓýÚãåÈÕÆóÒµÇå¾²ÍŶÓÈËÊÖȱ·¦¡¢·À»¤ÄÜÁ¦Ï½µµÄ¼à¿Ø¿ÕµµÆÚ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷²¨¼°È«Çò20¸ö¹ú¼ÒµÄColdFusionЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Ïà¹Ø¶ñÒâÇëÇóÔ¼5940´Î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÃÀ¹úµØÇø¹¥»÷»á»°Õ¼±È´ï68%¡£¡£¡£¡£¡£¡£¡£¹¥»÷Á÷Á¿Ö÷ÒªÔ´×ÔCTGЧÀÍÆ÷ÓÐÏÞ¹«Ë¾ÍйܵÄÁ½¸ö½¹µãIPµØµã¡£¡£¡£¡£¡£¡£¡£ÔÚÊÖÒÕϸ½ÚÉÏ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½èÖúProjectDiscovery Interactsh´øÍâ²âÊÔÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬°²ÅŽü1Íò¸ö×ÔÁ¦ÓòÃûÎüÊÕ¹¥»÷»Øµ÷ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýWDDX·´ÐòÁл¯Îó²î´¥·¢JNDI/LDAP×¢È룬£¬£¬£¬£¬£¬£¬×îÖÕ¹¥»÷com.sun.rowset.JdbcRowSetImpl×é¼þʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬Õë¶ÔColdFusionµÄ¹¥»÷½öÕ¼ÕûÌåÐж¯µÄ0.2%¡£¡£¡£¡£¡£¡£¡£
https://cybersecuritynews.com/coldfusion-servers-under-attack/
3. ÂÞÂíÄáÑÇ×î´óÄÜÔ´¹©Ó¦ÉÌÔâÀÕË÷Èí¼þ¹¥»÷
12ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬Ê¥µ®½ÚÔ½ÈÕ£¬£¬£¬£¬£¬£¬£¬ÂÞÂíÄáÑÇ×î´óú̿ÄÜÔ´Éú²úḚ́¶ûÌØÄáÑÇÄÜÔ´×ÛºÏÌåÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäIT»ù´¡ÉèÊ©ÑÏÖØÌ±»¾¡£¡£¡£¡£¡£¡£¡£ERPϵͳ¡¢ÎĵµÖÎÀíÓ¦Óá¢ÆóÒµÓʼþЧÀͼ°¹ÙÍøµÈÒªº¦ÏµÍ³ÔÝʱÎÞ·¨Ê¹Ó㬣¬£¬£¬£¬£¬£¬²¿·ÖÔËÓªÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬µ«¹ú¼ÒÄÜԴϵͳÕûÌåÔËÐÐδÊÜÍþв¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ºó£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Á¬Ã¦Æô¶¯Ó¦¼±ÏìÓ¦£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÏÖÓб¸·ÝÔÚлù´¡ÉèÊ©ÉÏÖØÐÞÊÜÓ°Ïìϵͳ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Óë¹ú¼ÒÍøÂçÇå¾²¾Ö¡¢ÄÜÔ´²¿¼°¹¥»÷ÓÐ×éÖ¯·¸·¨ºÍ¿Ö²ÀÖ÷Òå¾Ö£¨DIICOT£©ÏàÖú£¬£¬£¬£¬£¬£¬£¬ÖÜÈ«ÆÀ¹ÀÊÂÎñÓ°Ïì²¢ÆÊÎö¹¥»÷ÕßÊÇ·ñÔÚ¼ÓÃÜÊý¾ÝǰÇÔÈ¡ÁËÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÏòDIICOTÌáÆðÐÌÊÂËßËÏ£¬£¬£¬£¬£¬£¬£¬Ïà¹ØÊÓ²ìÕýÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÓÉGentlemenÀÕË÷Èí¼þÍÅ»ïʵÑ飬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÔÚÆäTorÊý¾ÝÐ¹Â¶ÍøÕ¾ÒÑÐÂÔö½ü50ÃûÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬µ«°Â¶ûÌØÄáÑÇÄÜÔ´×ÛºÏÌåÉÐδ±»ÁÐÈ룬£¬£¬£¬£¬£¬£¬¿ÉÄÜÈÔ´¦ÓÚÊê½ð̸Åн׶Ρ£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/romanian-energy-provider-hit-by-gentlemen-ransomware-attack/
4. CISAÒªÇóÃÀÕþ¸®»ú¹¹ÐÞ¸´MongoBleed¸ßΣÎó²î
12ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ÒÑÇ¿ÖÆÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©»ú¹¹ÔÚ2026Äê1ÔÂ19ÈÕǰÐÞ¸´MongoDB¸ßΣÎó²îCVE-2025-14847£¨ÃüÃû¡°MongoBleed¡±£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î×Ô2025Äê12ÔÂ19ÈÕÐÞ¸´ºóÈÔ±»Æð¾¢Ê¹Óᣡ£¡£¡£¡£¡£¡£MongoBleedÔ´ÓÚMongoDBЧÀÍÆ÷ʹÓÃzlib¿â´¦Öóͷ£ÍøÂçÊý¾Ý°üµÄ·½·¨È±ÏÝ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýµÍÖØÆ¯ºó¡¢ÎÞÐèÓû§½»»¥µÄÔ¶³Ì¹¥»÷ÇÔÈ¡Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬°üÀ¨API/ÔÆÃÜÔ¿¡¢»á»°ÁîÅÆ¡¢ÄÚ²¿ÈÕÖ¾¼°Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©¡£¡£¡£¡£¡£¡£¡£ElasticÇå¾²Ñо¿Ô±Joe DesimoneÐû²¼µÄ¿´·¨ÑéÖ¤£¨PoC£©³ÌÐòÒÑ֤ʵ¿Éй¶δ´ò²¹¶¡Ö÷»úµÄÄÚ´æÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾ÝShadowserver¼à²â£¬£¬£¬£¬£¬£¬£¬È«Çò³¬7.4Íò¸ö̻¶ÔÚ»¥ÁªÍøµÄMongoDBʵÀý¿ÉÄܱ£´æ¸ÃÎó²î£»£»£»Censys×·×Ùµ½³¬8.7Íò¸öIPµØµãµÄÖ¸ÎÆÐÅÏ¢ÏÔʾÆäÔËÐÐδ´ò²¹¶¡°æ±¾¡£¡£¡£¡£¡£¡£¡£ÔÆÇ徲ƽ̨WizµÄÒ£²âÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÔÆÇéÐÎÖÐ42%µÄ¿É¼ûϵͳÖÁÉÙÓÐÒ»¸ö±£´æÎó²îµÄMongoDBʵÀý£¬£¬£¬£¬£¬£¬£¬ÇÒ¸ÃÎó²îÒѱ»±ê¼ÇΪ¡°Òѱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies-to-patch-mongobleed-flaw-actively-exploited-in-attacks/
5. ·¨¹úÁ½Ëù´óѧÔâÍøÂç¹¥»÷Ö´ó¹æÄ£Ñ§ÉúÊý¾Ýй¶
12ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬½ÚÈÕʱ´ú£¬£¬£¬£¬£¬£¬£¬·¨¹úÀï¶û´óѧºÍ¸ñÀÕŵ²¼¶û¸ßµÈÉÌѧԺÏà¼ÌÔâÓöÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊýǧÃûѧÉúСÎÒ˽¼ÒÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¾ÝºÚ¿ÍÂÛ̳Åû¶£¬£¬£¬£¬£¬£¬£¬12ÔÂ29ÈÕÁ½Ð£Ãû×Ö·ºÆðÔÚ×ÅÃû·¸·¨ÂÛ̳£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßCZXÉù³Æ11ÔÂÈëÇÖ¸ñÀÕŵ²¼¶û¸ßµÈÉÌѧԺϵͳ£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡1.35GBÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬º¸ÇÐÕÃû¡¢ÓÊÏä¡¢µç»°¡¢µØµã¡¢Ñ§ÊõÅä¾°¡¢IPµØµãµÈ£¬£¬£¬£¬£¬£¬£¬Ó°Ï쳬40ÍòÈË£¬£¬£¬£¬£¬£¬£¬Êý¾ÝÒÉËÆÔ´×ÔCRM»òÓªÏúϵͳÓʼþÁÐ±í£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ñ§Éú¼°Íⲿ¶©ÔÄÕßÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Í¬ÆÚ£¬£¬£¬£¬£¬£¬£¬LAPSUS$ GroupÐû³ÆÈëÇÖÀï¶û´óѧ£¬£¬£¬£¬£¬£¬£¬¸Ã´óѧӵÓг¬8ÍòѧÉú£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÄÚ²¿±êʶ·û¡¢³öÉúÈÕÆÚ¡¢ÐÐÕþÊý¾ÝµÈ£¬£¬£¬£¬£¬£¬£¬Ó°Ïì½ü2000ÃûѧÉú¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔøÓëScatteredSpider¡¢ShinyHuntersºÏ²¢ÎªScattered LAPSUS$ Hunters£¬£¬£¬£¬£¬£¬£¬½ñÄê±»Ö¸¼ÓÈëÕë¶ÔPalo Alto Networks¡¢CloudflareµÈÆóÒµµÄSalesforce¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢Éù³Æµ¼Ö´÷¶û¡¢VerizonµÈ¶à¼Ò»ú¹¹Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£
https://cybernews.com/security/french-universities-student-data-hacked/
6. ErrTraffic½è¡°Ðéα¹ÊÕÏ¡±×Ô¶¯»¯ÊµÑéClickFix¹¥»÷
12ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖÃûΪErrTrafficµÄÐÂÐÍÍøÂç·¸·¨Æ½Ì¨ÔÚ¶íÓïºÚ¿ÍÂÛ̳ÐËÆð£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔÚ±»ÈëÇÖÍøÕ¾ÌìÉú¡°Ðéα¹ÊÕÏ¡±×Ô¶¯»¯Ö´ÐÐClickFixÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬£¬£¬£¬×ª»¯Âʸߴï60%¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßÓɼÙÃûLenAIµÄ¿ª·¢ÕßÒÔ800ÃÀÔªÒ»´ÎÐÔ¼ÛÇ®³öÊÛ£¬£¬£¬£¬£¬£¬£¬½ÓÄÉ×ÔÍйÜÁ÷Á¿·Ö·¢ÏµÍ³£¨TDS£©¼Ü¹¹£¬£¬£¬£¬£¬£¬£¬ÌṩÓû§ÓѺÃÃæ°å¡¢ÉèÖÃÑ¡Ïʵʱ»î¶¯Êý¾Ý¼à¿Ø¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ClickFixÊÖÒÕͨ¹ýαÔì¿ÉÐų¡¾°£¨ÈçϵͳÐÞ¸´¡¢Éí·ÝÑéÖ¤£©ÓÕÆÓû§Ö´ÐÐΣÏÕÏÂÁ£¬£¬£¬£¬£¬£¬ÓÐÓÃÈÆ¹ý±ê×¼Çå¾²¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬½üÄêÒѱ»ÍøÂç·¸·¨·Ö×Ó¼°¹ú¼ÒÖ§³ÖÐж¯Õ߯ձé½ÓÄÉ¡£¡£¡£¡£¡£¡£¡£ErrTrafficÒªÇó¹¥»÷ÕßÔ¤ÏÈ¿ØÖÆ»òÏòÕýµ±ÍøÕ¾×¢Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬Í¨¹ýHTML´úÂëÐм¯³É¡£¡£¡£¡£¡£¡£¡£¶Ô²»Çк϶¨Î»Ìõ¼þµÄͨË׷ÿͣ¬£¬£¬£¬£¬£¬£¬ÍøÕ¾ÐÐΪ¼á³ÖÕý³££»£»£»µ±·Ã¿ÍµØÀíλÖᢲÙ×÷ÏµÍ³Ö¸ÎÆÇкÏÔ¤ÉèÌõ¼þʱ£¬£¬£¬£¬£¬£¬£¬Ò³ÃæDOM»á±»Ð޸쬣¬£¬£¬£¬£¬£¬ÏÔʾÎı¾Ë𻵡¢×ÖÌå·ûºÅÌæ»»¡¢ChromeÐéα¸üÐÂÌáÐÑ»òϵͳ×ÖÌåȱʧ¹ýʧµÈ¡°ÊÓ¾õ¹ÊÕÏ¡±£¬£¬£¬£¬£¬£¬£¬ÖÆÔìÒ³Ãæ¡°Ë𻵡±¼ÙÏ󡣡£¡£¡£¡£¡£¡£Êܺ¦ÕßÈô°´¡°½â¾ö¼Æ»®¡±²Ù×÷Èç×°ÖÃä¯ÀÀÆ÷¸üС¢ÏÂÔØÏµÍ³×ÖÌå¡¢Õ³ÌùÏÂÁîÌáÐÑ·ûÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬½«´¥·¢JavaScript´úÂëÏò¼ôÌù°åдÈëPowerShellÏÂÁ£¬£¬£¬£¬£¬£¬Ö´ÐкóÏÂÔØ¶ñÒâÓÐÓÃÔØºÉ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-errtraffic-service-enables-clickfix-attacks-via-fake-browser-glitches/


¾©¹«Íø°²±¸11010802024551ºÅ