Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬Zscaler¿Í»§ÐÅÏ¢Íâй
Ðû²¼Ê±¼ä 2025-09-031. Salesloft DriftÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬Zscaler¿Í»§ÐÅÏ¢Íâй
9ÔÂ1ÈÕ£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾Zscaler¿ËÈÕÅû¶£¬£¬£¬£¬ÆäSalesforceʵÀýÒòµÚÈý·½¼¯³É¹¤¾ßÔâÈëÇÖÒý·¢Êý¾Ýй¶£¬£¬£¬£¬¿Í»§Ãô¸ÐÐÅÏ¢¼°²¿·ÖÖ§³Ö°¸ÀýÄÚÈݱ»ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£ÊÂÎñÔ´ÓÚSalesloft Drift±»¹¥»÷ÕßʹÓ㬣¬£¬£¬ÆäOAuthÁîÅÆºÍË¢ÐÂÁîÅÆÔâÇÔ£¬£¬£¬£¬µ¼ÖÂδ¾ÊÚȨµÄÐÐΪÕß»á¼ûZscalerµÄSalesforceÇéÐΡ£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨¿Í»§ÐÕÃû¡¢ÉÌÒµÓÊÏ䡢ְλ¡¢µç»°ºÅÂë¡¢ÇøÓòÐÅÏ¢¡¢²úÆ·ÔÊÐíÏêÇé¼°Ö§³Ö°¸ÀýÄÚÈÝ£¬£¬£¬£¬µ«ZscalerÇ¿µ÷´Ë´ÎÊÂÎñ䲨¼°¹«Ë¾×ÔÉí²úÆ·¡¢Ð§ÀÍ»ò»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¹È¸èÍþвÇ鱨С×飨GTIG£©½«´Ë´Î¹¥»÷¹éÒòÓÚ×·×ÙΪUNC6395µÄÍþв×éÖ¯£¬£¬£¬£¬²¢Ö¸³öÆäÄ¿µÄΪ»ñÈ¡¿Í»§ÔÚÖ§³Ö°¸ÀýÖзÖÏíµÄÃô¸Ðƾ֤£¬£¬£¬£¬ÈçAWS»á¼ûÃÜÔ¿¡¢ÃÜÂë¼°SnowflakeÏà¹ØÁîÅÆ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýɾ³ýÅÌÎÊ×÷ÒµÑÚÊκۼ££¬£¬£¬£¬µ«ÈÕ־δÊÜÓ°Ï죬£¬£¬£¬¹È¸è½¨ÒéÊÜÓ°Ïì×éÖ¯Éó²éÈÕÖ¾ÒÔÈ·ÈÏÊý¾Ý̻¶ÇéÐΡ£¡£¡£¡£¡£¡£¡£½øÒ»³ÌÐò²éÏÔʾ£¬£¬£¬£¬Salesloft¹©Ó¦Á´¹¥»÷²»µ«Ó°ÏìDriftÓëSalesforceµÄ¼¯³É£¬£¬£¬£¬»¹²¨¼°ÆäÓÃÓÚÖÎÀíÓʼþ»Ø¸´ºÍCRMÊý¾Ý¿âµÄDrift Email¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÉõÖÁʹÓÃÇÔÈ¡µÄOAuthÁîÅÆ»á¼ûGoogle WorkspaceÓÊÏä²¢¶ÁÈ¡Óʼþ£¬£¬£¬£¬´Ùʹ¹È¸èÓëSalesforceÔÝʱ½ûÓÃDrift¼¯³É¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise/
2. ¶ñÒânpm°üαװ³ÉÓʼþ¿âʵÑé¼ÓÃÜÇ®±ÒÇ®°üÇÔÈ¡¹¥»÷
9ÔÂ2ÈÕ£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕÅû¶һÆðÕë¶Ô¼ÓÃÜÇ®±ÒÓû§µÄ¹©Ó¦Á´¹¥»÷ÊÂÎñ£º¶ñÒânpm°ü"nodejs-smtp"ͨ¹ýð³ä×ÅÃûÓʼþ¿âNodemailer£¬£¬£¬£¬Àֳɽ«¶ñÒâ´úÂë×¢ÈëAtomic¡¢ExodusµÈÖ÷Á÷¼ÓÃÜÇ®±ÒÇ®°üµÄWindows×ÀÃæÓ¦Ó㬣¬£¬£¬ÇÔÈ¡Óû§ÉúÒâ×ʽ𡣡£¡£¡£¡£¡£¡£¸ÃÈí¼þ°üÓÉÓû§"nikotimon"ÓÚ2025Äê4ÔÂÉÏ´«ÖÁnpm×¢²á±í£¬£¬£¬£¬ÀÛ¼ÆÏÂÔØ347´Îºó±»Ï¼ܣ¬£¬£¬£¬ÏÖÔÚÈÔ¿Éͨ¹ýÀúÊ·°æ±¾»ñÈ¡¡£¡£¡£¡£¡£¡£¡£SocketÑо¿Ô±Kirill BoychenkoÕ¹ÏÖ£¬£¬£¬£¬¸Ã¶ñÒâ°ü½ÓÄÉË«ÖØÎ±×°Õ½ÂÔ£ºÍâòÌṩÓëNodemailerÍêÈ«¼æÈݵÄSMTPÓʼþ¹¦Ð§£¬£¬£¬£¬ÏÖ×Åʵµ¼ÈëʱʹÓÃElectron¹¤¾ß½âѹǮ°üÓ¦ÓõÄapp.asarÎļþ£¬£¬£¬£¬ÓÃÍþвÐÐΪÕß¿ØÖƵÄÓ²±àÂëÇ®°üµØµãÌæ»»Óû§ÊÕ¼þµØµã£¬£¬£¬£¬ÊµÏÖ±ÈÌØ±Ò¡¢ÒÔÌ«·»¡¢USDT¡¢XRP¼°SolanaµÈÖ÷Á÷¼ÓÃÜÇ®±ÒµÄÉúÒâÐ®ÖÆ¡£¡£¡£¡£¡£¡£¡£Æä¹¥»÷Á÷³ÌÉè¼Æ¾«Ã£¬£¬£¬Í¨¹ýÐÞ¸Ä×ÀÃæÓ¦Óý¹µãÎļþʵÏÖ³¤ÆÚ»¯¸Ä¶¯£¬£¬£¬£¬ÖØÆôºóÈÔ¿ÉÉúЧ£¬£¬£¬£¬Í¬Ê±×Ô¶¯É¾³ýÊÂÇéĿ¼ºÛ¼££¬£¬£¬£¬´ó·ù½µµÍ̻¶Σº¦¡£¡£¡£¡£¡£¡£¡£ÊÖÒÕÆÊÎöÏÔʾ£¬£¬£¬£¬nodejs-smtpµÄ¹¥»÷´úÂëǶÈëÔÚÓʼþ¹¦Ð§ÊµÏÖÖУ¬£¬£¬£¬Í¨¹ýNodemailer¼æÈݽӿڽµµÍ¿ª·¢ÕßСÐÄÐÔ¡£¡£¡£¡£¡£¡£¡£µ±Óû§ÔÚ¿ª·¢ÇéÐÎÖе¼Èë¸Ã°üʱ£¬£¬£¬£¬Æä¶ñÒâÄ£¿£¿£¿£¿£¿£¿£¿é»á×Ô¶¯¼ì²âϵͳÖÐÊÇ·ñ×°ÖÃAtomic»òExodusÇ®°ü£¬£¬£¬£¬Ò»µ©·¢Ã÷¼´Ö´Ðнâѹ-Ìæ»»-´ò°ü²Ù×÷£¬£¬£¬£¬½«Õýµ±Ç®°üÓ¦ÓÃת»¯ÎªÇÔÈ¡¹¤¾ß¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/09/malicious-npm-package-nodejs-smtp.html
3. CloudflareÔÚSalesforce¹©Ó¦Á´¹¥»÷ÖÐÔâÓöÊý¾Ýй¶
9ÔÂ2ÈÕ£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬Ò»³¡ÒÔSalesforceƽ̨ΪĿµÄµÄ¹©Ó¦Á´¹¥»÷Òý·¢¶àÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬Cloudflare³ÉΪ×îÐÂÊÜÓ°ÏìÆóÒµ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Á´Ô´ÓÚÍþвÐÐΪÕßͨ¹ýÓïÒô´¹ÂÚ£¨vishing£©Éç»á¹¤³ÌÊֶΣ¬£¬£¬£¬ÓÕÆÆóÒµÔ±¹¤½«¶ñÒâOAuthÓ¦ÓùØÁªÖÁ¹«Ë¾SalesforceʵÀý£¬£¬£¬£¬½ø¶øÇÔÈ¡Êý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£8ÔÂ9ÈÕÖÁ17ÈÕʱ´ú£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏȶÔCloudflareµÄSalesforceʵÀýÕö¿ªÕì̽£¬£¬£¬£¬ËæºóÇÔÈ¡ÁËÆäÄÚ²¿¿Í»§°¸ÀýÖÎÀí¼°Ö§³ÖϵͳÖеÄÎı¾Êý¾Ý£¬£¬£¬£¬Éæ¼°104¸öCloudflare APIÁîÅÆ¼°´ó×Ú¿Í»§Ö§³Ö¹¤µ¥ÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÏÖÔÚδ·¢Ã÷ÁîÅÆ±»ÀÄÓ㬣¬£¬£¬µ«Ð¹Â¶ÐÅÏ¢°üÀ¨¿Í»§ÁªÏµ×ÊÁÏ¡¢ÉèÖÃÏêÇé¼°¿ÉÄܱ£´æµÄ»á¼ûƾ֤µÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬CloudflareÒѽôÆÈÂÖ»»ËùÓÐÊÜÓ°ÏìÁîÅÆ²¢Í¨Öª¿Í»§£¬£¬£¬£¬½¨ÒéÂÖ»»Í¨¹ýÖ§³ÖÇþµÀ¹²ÏíµÄƾ֤¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹©Ó¦Á´¹¥»÷̻¶³öÆóÒµÒÀÀµµÚÈý·½SaaSƽ̨µÄÇ徲Σº¦¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¼òµ¥Æ½Ì¨Îó²î¼´¿ÉºáÏò²¨¼°Êý°Ù¼Ò¿Í»§£¬£¬£¬£¬ÇÔÈ¡µÄ¿Í»§Ö§³Ö¹¤µ¥Êý¾Ý£¨ÈçÈÕÖ¾¡¢ÁîÅÆ¡¢ÃÜÂ룩¿ÉÄܳÉΪºóÐøÕë¶ÔÐÔ¹¥»÷µÄÌø°å¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÊÜÓ°ÏìÆóÒµ¾ùÇ¿µ÷䲨¼°½¹µãϵͳ£¬£¬£¬£¬µ«Ãô¸ÐÐÅϢй¶ÈÔ¿ÉÄÜÒý·¢¿Í»§ÐÅÈÎΣ»£»£»£»ú¼°ºÏ¹æÎ£º¦¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/
4. ºÚ¿Í¹¥»÷Evertec°ÍÎ÷×Ó¹«Ë¾Sinqia£¬£¬£¬£¬ÊÔͼÇÔÈ¡1.3ÒÚÃÀÔª
9ÔÂ2ÈÕ£¬£¬£¬£¬À¶¡ÃÀÖÞ½ðÈڿƼ¼¾ÞÍ·EvertecµÄ°ÍÎ÷×Ó¹«Ë¾Sinqia S.A.¿ËÈÕÔâÓöÖØ´óÍøÂç¹¥»÷ÊÂÎñ£¬£¬£¬£¬ºÚ¿Íͨ¹ýÇÔÈ¡µÄIT¹©Ó¦ÉÌÕË»§Æ¾Ö¤£¬£¬£¬£¬ÓÚ8ÔÂ29ÈÕ²»·¨ÇÖÈëÆäÈÏÕæÔËÓªµÄ°ÍÎ÷ÑëÐÐʵʱ֧¸¶ÏµÍ³£¨Pix£©ÇéÐΣ¬£¬£¬£¬ÊÔͼͨ¹ýÁ½¼Ò½ðÈÚ»ú¹¹¿Í»§Ìᳫ×ܶî´ï1.3ÒÚÃÀÔªµÄδ¾ÊÚȨÆóÒµ¼äתÕË¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü²¿·Ö×ʽðÒѱ»×·»Ø£¬£¬£¬£¬µ«Ïêϸ½ð¶îδ¹ûÕæ£¬£¬£¬£¬ÇÒÊÂÎñ¶ÔEvertec²ÆÎñ¼°ÉùÓþµÄDZÔÚÓ°ÏìÈÔ±»ÆÀ¹ÀΪ"¿ÉÄÜÖØ´ó"¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤EvertecÏòÃÀ¹ú֤ȯÉúÒâίԱ»á£¨SEC£©Ìá½»µÄÎļþ£¬£¬£¬£¬´Ë´Î¹¥»÷̻¶Á˰ÍÎ÷¼´Ê±Ö§¸¶ÏµÍ³PixµÄÇ徲ųÈõÐÔ¡£¡£¡£¡£¡£¡£¡£×÷Ϊ°ÍÎ÷ÑëÐÐ2020ÄêÍÆ³öµÄÈ«Ììºò¼´Ê±×ªÕËϵͳ£¬£¬£¬£¬PixÒÑÁýÕÖÌìÏÂÁè¼Ý°ëÊý³ÉÄêÉú³Ý£¬£¬£¬£¬µ«ÆµÈÔ³ÉΪAndroidÒøÐжñÒâÈí¼þ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÖУ¬£¬£¬£¬ºÚ¿ÍʹÓõÚÈý·½¹©Ó¦ÉÌÕË»§È¨ÏÞ£¬£¬£¬£¬Í»ÆÆÁËSinqiaΪ24¼Ò°ÍÎ÷½ðÈÚ»ú¹¹ÌṩµÄPixÖ§¸¶´¦Öóͷ£ÇéÐΣ¬£¬£¬£¬Ö»¹ÜEvertecÇ¿µ÷δ·¢Ã÷СÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬£¬µ«¹¥»÷ÕßÈÔÊÔͼͨ¹ý»ã·áÒøÐеȿͻ§Ìᳫ´ó¹æÄ£×ʽð×ªÒÆ¡£¡£¡£¡£¡£¡£¡£»£»£»£»ã·áÒøÐлØÓ¦³Æ¿Í»§×ʽðÓëÊý¾ÝδÊÜÓ°Ï죬£¬£¬£¬µ«ÊÂÎñ͹ÏÔ½ðÈÚ»ú¹¹¶ÔµÚÈý·½Ð§ÀÍÉ̵ÄÇå¾²ÒÀÀµÎ£º¦¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-breach-fintech-firm-in-attempted-130m-bank-heist/
5. ½Ý±ªÂ·»¢ÔâÍøÂç¹¥»÷ÖÂϵͳ¹Ø±Õ£¬£¬£¬£¬Éú²úÁãÊÛÊÜÓ°Ïì
9ÔÂ2ÈÕ£¬£¬£¬£¬½Ý±ªÂ·»¢£¨JLR£©¿ËÈÕÔâÓöÍøÂç¹¥»÷£¬£¬£¬£¬±»ÆÈ¹Ø±Õ²¿·ÖϵͳÒÔ»º½âÓ°Ï죬£¬£¬£¬µ¼ÖÂÆäÉú²úºÍÁãÊÛÓªÒµÊܵ½ÑÏÖØ×ÌÈÅ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¹«Ë¾¹Ù·½ÉùÃ÷£¬£¬£¬£¬´Ë´ÎÊÂÎñÖÐËäδ·¢Ã÷¿Í»§Êý¾Ý±»µÁ¼£Ï󣬣¬£¬£¬µ«ÁãÊ۶˺ÍÉú²ú»·½Ú¾ù·ºÆðÏÔÖøÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£½Ý±ªÂ·»¢ÌåÏÖ£¬£¬£¬£¬ÊÂÎñ±¬·¢ºóÁ¬Ã¦×Ô¶¯¹Ø±ÕÊÜÓ°Ïìϵͳ£¬£¬£¬£¬ÏÖÔÚÕý°´ÍýÏëÖð²½ÖØÆôÈ«ÇòÓ¦ÓóÌÐò£¬£¬£¬£¬µ«ÉÐδÌṩ»Ö¸´Õý³£ÔËÓªµÄÏêϸʱ¼ä±í£¬£¬£¬£¬Ò²Î´Åû¶¹¥»÷ÀàÐÍ»òÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£¡£×÷ΪËþËþÆû³µÆìÏÂ×Ó¹«Ë¾£¬£¬£¬£¬½Ý±ªÂ·»¢ÄêÊÕÈ볬380ÒÚÃÀÔª£¬£¬£¬£¬Äê²úÁ¿³¬40ÍòÁ¾£¬£¬£¬£¬ÓµÓÐ3.9ÍòÃûÔ±¹¤£¬£¬£¬£¬ÆäË÷Àû¹þ¶û¹¤³§ÈÏÕæÉú²ú·»¢·¢Ã÷¡¢À¿Ê¤¼°À¿Ê¤Ô˶¯°æµÈÈÈÃųµÐÍ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µ¼ÖÂÓ¢¹ú¾ÏúÉÌÎÞ·¨×¢²áгµ»ò¹©Ó¦Áã¼þ£¬£¬£¬£¬Éú²úϵͳҲһ¶ÈÍ£°Ú£¬£¬£¬£¬µ«¹«Ë¾Ç¿µ÷¿Í»§Êý¾ÝÇå¾²ÐÔδÊÜÍþв¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚÖÜÄ©£¬£¬£¬£¬Õâһʱ¶Î³£±»ÍþвÐÐΪÕßʹÓ㬣¬£¬£¬ÒòÆóÒµÓ¦¼±ÏìÓ¦ÄÜÁ¦Ïà¶Ô½ÏÈõ¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚÉÐδÓÐÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô´ËÈÏÕæ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/jaguar-land-rover-says-cyberattack-severely-disrupted-production/
6. Palo Alto NetworksÔâSalesforce¹©Ó¦Á´¹¥»÷й¶¿Í»§Êý¾Ý
9ÔÂ2ÈÕ£¬£¬£¬£¬Palo Alto Networks¿ËÈÕÈ·ÈÏ£¬£¬£¬£¬Æä³ÉΪÉÏÖÜÅû¶µÄSalesloft Drift¹©Ó¦Á´¹¥»÷ÊÂÎñÖеÄÊÜÓ°ÏìÆóÒµÖ®Ò»£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÇÔÈ¡µÄOAuthÁîÅÆ²»·¨»á¼ûÆäSalesforce CRMϵͳ£¬£¬£¬£¬µ¼Ö¿ͻ§ÁªÏµÐÅÏ¢¡¢ÄÚ²¿ÏúÊۼͼ¼°Ö§³Ö°¸ÀýÊý¾Ýй¶£¬£¬£¬£¬µ«Î´²¨¼°¹«Ë¾½¹µã²úÆ·¡¢ÏµÍ³»òЧÀÍ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ̻¶ÁËÍþвÐÐΪÕßÕë¶ÔSalesforceÉú̬µÄ¹æÄ£»£»£»£»¯Êý¾ÝÇÔȡսÂÔ£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÀÄÓõÚÈý·½Ó¦ÓÃÎó²î£¬£¬£¬£¬´ÓÊý°Ù¼ÒÆóÒµÖÐÅúÁ¿ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬Palo Alto NetworksÒѽôÆÈ½ûÓÃÏà¹ØÓ¦Óò¢ÂÖ»»Æ¾Ö¤£¬£¬£¬£¬Í¬Ê±ÖÒÑÔ¿Í»§ÐèСÐĺóÐøÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ô´ÓÚÍþвÐÐΪÕßʹÓÃSalesloft DriftÓ¦ÓóÌÐòÎó²î»ñÈ¡µÄOAuthÁîÅÆ£¬£¬£¬£¬½ø¶øÉøÍ¸ÆäSalesforceÇéÐΡ£¡£¡£¡£¡£¡£¡£Ö»¹Üй¶Êý¾Ý½öÏÞÓÚÁªÏµÐÅÏ¢¡¢Îı¾Ì¸ÂÛ¼°»ù´¡°¸ÀýÊý¾Ý£¬£¬£¬£¬Î´°üÀ¨ÊÖÒÕ¸½¼þ»òÎļþ£¬£¬£¬£¬µ«¹¥»÷ÕßÈÔͨ¹ý×Ô¶¯»¯¹¤¾ß£¨Èç×Ô½ç˵Python¾ç±¾£©´ÓÕË»§¡¢ÁªÏµÈË¡¢°¸ÀýµÈSalesforce¹¤¾ßÖдó¹æÄ£ÌáÈ¡Êý¾Ý£¬£¬£¬£¬²¢ÖصãɨÃèAWSÃÜÔ¿¡¢SnowflakeÁîÅÆ¡¢VPN/SSOƾ֤µÈ¸ß¼ÛÖµÐÅÏ¢£¬£¬£¬£¬Òâͼͨ¹ýÇÔÈ¡µÄÔÆÆ½Ì¨»á¼ûȨÏÞʵÑéÊý¾ÝÀÕË÷»òºáÏòÉøÍ¸¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/palo-alto-networks-data-breach-exposes-customer-info-support-cases/


¾©¹«Íø°²±¸11010802024551ºÅ