WarlockÀÕË÷Èí¼þ×éÖ¯£ºÐÂÐËÍþвµÄ¹¥»÷ÌØÕ÷ÓëÇå¾²¾¯Ê¾
Ðû²¼Ê±¼ä 2025-09-241. WarlockÀÕË÷Èí¼þ×éÖ¯£ºÐÂÐËÍþвµÄ¹¥»÷ÌØÕ÷ÓëÇå¾²¾¯Ê¾
9ÔÂ21ÈÕ£¬£¬£¬£¬SophosÑо¿ÍŶÓÕ¹ÏÖ£¬£¬£¬£¬ÃûΪWarlockµÄÀÕË÷Èí¼þ×éÖ¯£¨Î¢Èí³ÆStorm 2603£¬£¬£¬£¬Sophos×·×ÙΪGOLD SALEM£©ÕýÒÔ¸ßÃ÷ÊÖÒÕÊֶμӾçÈ«ÇòÍøÂç¹¥»÷¡£¡£¡£¡£¸Ã×éÖ¯×Ô2025Äê3ÔÂÆð»îÔ¾£¬£¬£¬£¬9ÔÂÒÑÔÚÆä"Warlock¿Í»§Êý¾Ýй¶Ðã"°µÍøÕ¾µãÐû²¼60ÃûÊܺ¦Õߣ¬£¬£¬£¬Ä¿µÄº¸Ç±±ÃÀ¡¢Å·ÖÞ¡¢ÄÏÃÀµÄСÐÍÉÌҵʵÌå¡¢Õþ¸®»ú¹¹¼°´óÐÍ¿ç¹ú¹«Ë¾¡£¡£¡£¡£Æä¹¥»÷ÌØÕ÷°üÀ¨Ê¹ÓÃSharePointÁãÈÕÎó²î¡¢°²ÅÅ×Ô½ç˵ToolShellÁ´¡¢Í¶·ÅWeb Shell¼°»ùÓÚGolangµÄWebSocketЧÀÍÆ÷¾ÙÐг¤ÆÚ»¯£¬£¬£¬£¬²¢ÀÄÓÃVelociraptorµÈÕýµ±¹¤¾ßʵÑéÒþ²ØËíµÀ¹¥»÷£¬£¬£¬£¬Í¬Ê±Á¬ÏµMimikatzƾ֤͵ÇÔ¡¢PsExecºáÏòÒÆ¶¯¼°GPOÍÆËÍÀÕË÷¸ºÔصȹŰåÊÖ·¨¡£¡£¡£¡£¸Ã×é֯йÃÜÄ£Ê½ÆæÒ죬£¬£¬£¬Ê¡ÂÔÐû²¼ÈÕÆÚÓëÊÓ¾õÑù±¾£¬£¬£¬£¬½öËæ»úÅû¶±»µÁÊý¾ÝÁ¿£¬£¬£¬£¬²¢Í¨¹ý×¢Êͱê×¢Êý¾Ý״̬£¨Ðû²¼/³öÊÛ/δ֧¸¶Êê½ð£©£¬£¬£¬£¬ÉõÖÁÌṩÏÖʵÊý¾ÝÁ´½Ó¡£¡£¡£¡£ÆäFAQÉùÃ÷ѵ³â"²»ÈÏÕæÈεĹ«Ë¾"£¬£¬£¬£¬³ÆÎ´ÁªÏµµÄ´ó¿Í»§Êý¾Ý½«Ãâ·Ñ¹ûÕæ£¬£¬£¬£¬µ«"¸ß¶ÈÃô¸ÐÊý¾Ý"µÄ´óÐÍÆóÒµ¿Í»§ÐÅÏ¢²»»áÍêÈ«Åû¶¡£¡£¡£¡£SophosÖ¸³ö£¬£¬£¬£¬WarlockÖ±ÖÁ6Ô²ÅÔÚ¶íÓïÂÛ̳Ramp¹ûÕæ»îÔ¾£¬£¬£¬£¬ÔøÕ÷¼¯Veeam¡¢ESXi¡¢SharePointÎó²îʹÓü°EDRÖÐÖ¹¹¤¾ß¡£¡£¡£¡£
https://cybernews.com/security/warlock-ransomware-group-attacks-surge-september/
2. Æ×ÓÀÄÓÃÈ˹¤ÖÇÄÜÔÉúƽ̨ÍйÜÐéαÑéÖ¤ÂëÒ³Ãæ
9ÔÂ22ÈÕ£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾Ç÷ÊÆ¿Æ¼¼×îб¨¸æÕ¹ÏÖ£¬£¬£¬£¬È˹¤ÖÇÄÜ¿ª·¢Æ½Ì¨Õý±»ÍøÂç·¸·¨·Ö×ÓʹÓ㬣¬£¬£¬³ÉΪÍйÜÐéαÑéÖ¤Â루CAPTCHA£©Ò³ÃæµÄÐÂÔØÌ壬£¬£¬£¬´Ó¶øÌÓ±ÜÇå¾²¼ì²â²¢ÓÕµ¼Óû§½øÈë´¹ÂÚÍøÕ¾¡£¡£¡£¡£×÷ΪÑéÖ¤ÕæÊÊÓû§µÄÒªº¦¹¤¾ß£¬£¬£¬£¬CAPTCHA±¾Ó¦µÖÓù»úеÈ˹¥»÷£¬£¬£¬£¬ÏÖÔÚÈ´±»·´ÏòʹÓ㬣¬£¬£¬³ÉÎªÍøÂç´¹ÂÚµÄ"צÑÀ"¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬×Ô2025Äê1ÔÂÆð£¬£¬£¬£¬Ê¹ÓÃLovable¡¢Netlify¡¢VercelµÈAIÔÉú¿ª·¢Æ½Ì¨ÍйÜÐéαÑéÖ¤ÂëÒ³ÃæµÄÍøÂç´¹Âڻ¼¤Ôö¡£¡£¡£¡£ÕâЩƽ̨Ðû³Æ"Áã´úÂë¼´¿É¹¹½¨Ó¦ÓÃ"£¬£¬£¬£¬½µµÍÁËÊÖÒÕÃż÷£¬£¬£¬£¬Ê¹·¸·¨·Ö×ÓÄÜ¿ìËÙ½¨Éè¿´ËÆÕý¹æµÄÑéÖ¤ÂëÌôÕ½Ò³Ãæ¡£¡£¡£¡£¹¥»÷Á÷³Ìͨ³£Ê¼ÓÚαװ³É"ÃÜÂëÖØÖÃ""USPSµØµã±ä»»"µÈ½ôÆÈÓʼþµÄ´¹ÂÚÁ´½Ó£¬£¬£¬£¬Óû§µã»÷ºóÊ×ÏÈ¿´µ½ÐéαCAPTCHAÒ³Ãæ£¬£¬£¬£¬ÒòÆä"¹Ù·½ÑéÖ¤"Íâ¹Û£¬£¬£¬£¬Êܺ¦ÕßÒ×ËÉ¿ªÐ¡ÐÄ£¬£¬£¬£¬¶ø×Ô¶¯É¨Ã蹤¾ßÒò½ö¼ì²âµ½ÑéÖ¤Âë¶ø·Çµ×²ãÆ¾Ö¤ÍøÂç±íµ¥£¬£¬£¬£¬ÄÑÒÔʶ±ð¶ñÒâÒ³Ãæ¡£¡£¡£¡£Íê³ÉÑéÖ¤ºó£¬£¬£¬£¬Óû§»á±»Öض¨ÏòÖÁÕæÕýµÄ´¹ÂÚÒ³Ãæ£¬£¬£¬£¬µ¼ÖÂÆ¾Ö¤¡¢Ãô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¸üÑÏËàµÄÊÇ£¬£¬£¬£¬¹¹½¨´ËÀàÒ³Ãæ½öÐè»ù´¡ÊÖÒÕÄÜÁ¦£¬£¬£¬£¬ÅäºÏAI±àÂëÖúÊÖ¼´¿ÉÍê³É¡£¡£¡£¡£
https://cybernews.com/security/ai-platforms-captcha-phishing/
3. µÂ¹úDCS³äµçÕ¾Êý¾Ýй¶£¬£¬£¬£¬¿Í»§Ð§ÀÍÉÌÎ¥¹æ»á¼ûÖÂÓû§ÐÅϢΣº¦
9ÔÂ23ÈÕ£¬£¬£¬£¬µÂ¹úÊý×Ö³äµç½â¾ö¼Æ»®¹«Ë¾£¨DCS£©¿ËÈÕÏòÓû§×ª´ïÒ»ÆðÊý¾ÝÇå¾²ÊÂÎñ£¬£¬£¬£¬Æä¿Í»§Ð§ÀÍÌṩÉÌÔÚ´¦Öóͷ£Êý¾Ýʱ±¬·¢Î¥¹æÐÐΪ£¬£¬£¬£¬µ¼Ö²¿·Ö¿Í»§ÐÅÏ¢ÃæÁÙй¶Σº¦¡£¡£¡£¡£DCS×÷ΪŷÖÞÖ÷Òªµç¶¯Æû³µ³äµçЧÀÍÉÌ£¬£¬£¬£¬ÖÎÀí×Å30¶à¸ö¹ú¼Ò³¬100ÍòÓû§¼°98Íò×ù³äµçÕ¾£¬£¬£¬£¬²¢Îª±¦Âí¡¢ÆðÑÇµÈÆ·ÅÆÌṩ¼Æ·ÑЧÀÍ¡£¡£¡£¡£ÊÂÎñÆðÔ´ÓÚDCS·¢Ã÷ÆäÏàÖúµÄЧÀÍÉÌÔÚÎÞºÏÀíÀíÓÉÇéÐÎÏ»á¼ûÁ˿ͻ§Êý¾Ý¡£¡£¡£¡£DCSÁ¬Ã¦Æô¶¯ÖÜÈ«ÊӲ죬£¬£¬£¬È·ÈÏÎ¥¹æÐÐÎªÉæ¼°¸öλÊý²¡Àý£¬£¬£¬£¬ÊÜÓ°ÏìÊý¾Ý½öÏÞÓÚÐÕÃûºÍµç×ÓÓʼþµØµã£¬£¬£¬£¬¶øÍêÕûÖ§¸¶ÐÅÏ¢Òòδ´æ´¢ÔÚÊÜÓ°ÏìÊý¾Ý¿âÖеÃÒÔ±£È«¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬DCSÒÑÓëЧÀÍÉÌÖÎÀí²ãÏàÖú²éÃ÷Ôµ¹ÊÔÓÉ£¬£¬£¬£¬ÊµÑéÌØÊâÇå¾²²½·¥£¬£¬£¬£¬²¢×ª´ïÖ´·¨¼°Êý¾Ý±£»£»£»£»¤²¿·Ö¡£¡£¡£¡£DCSÔÚ9ÔÂ19ÈÕÉèÁ¢µÄרÏîÒ³ÃæÖÐÇ¿µ÷£¬£¬£¬£¬³äµçЧÀͼ°¼Æ·ÑϵͳÈÔÇå¾²ÔËÐУ¬£¬£¬£¬Óû§ÎÞÐè½ÓÄÉÌØÊâ²Ù×÷£¬£¬£¬£¬µ«ÐèСÐÄDZÔÚ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¹«Ë¾ÖØÉ꣬£¬£¬£¬Ö»¹ÜÄ¿½ñ½öÈ·ÈÏÉÙÊý°¸Àý£¬£¬£¬£¬µ«ÎÞ·¨Íêȫɨ³ýÆäËû¿Í»§Êý¾Ý±»·ÇÊÚȨÉó²éµÄ¿ÉÄÜÐÔ£¬£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£
https://www.theregister.com/2025/09/23/dcs_data_breach/
4. ŦԼÁªºÏ¹ú´ó»áǰϦ´Ý»Ù´óÐ͵çÐÅÍøÂç
9ÔÂ23ÈÕ£¬£¬£¬£¬ÔÚÁªºÏ¹ú´ó»áÓÚÂü¹þ¶ÙÕÙ¿ªÇ°Ï¦£¬£¬£¬£¬Áª°îÊÓ²ìÖ°Ô±´Ý»ÙÁËÒ»¸öÒþ²ØÔÚŦԼµØÇøµÄ´óÐ͵çÐÅÍøÂç¡£¡£¡£¡£¸ÃÍøÂç°üÀ¨Áè¼Ý10ÍòÕÅSIM¿¨ºÍ300̨ЧÀÍÆ÷£¬£¬£¬£¬¿ÉÄܶÔŦԼÊÐͨѶϵͳÔì³ÉÔÖÄÑÐÔÆÆË𡣡£¡£¡£ÌØÇÚ¾ÖÖ¸³ö£¬£¬£¬£¬´ËÍøÂç¿É×ÌÈŽôÆÈÏìӦЧÀÍ¡¢¹Ø±Õ·äÎÑÍøÂç²¢·¢ËͼÓÃÜÐÅÏ¢£¬£¬£¬£¬Ç¡·ê150Óàλ¹ú¼ÊÏòµ¼ÈËÆë¾ÛŦԼʱ´ú¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬¸ÃÍøÂç×°±¸ÂþÑÜÓÚÁªºÏ¹ú×ܲ¿35Ó¢Àï°ë¾¶¹æÄ£ÄÚ£¬£¬£¬£¬¹æÄ£Óë×°±¸ÀàÐÍÌåÏÖÆä¿ÉÄÜΪÃñ×å¹ú¼Ò¼à¿ØÐж¯¡£¡£¡£¡£Í¨Ì«¹ýÎöSIM¿¨Êý¾Ý£¬£¬£¬£¬ÌØÇÚ¾Ö·¢Ã÷ÆäÓëÖÁÉÙÒ»¸öÍâ¹úÕþ¸®¼°··¶¾¼¯Íű£´æ¹ØÁª¡£¡£¡£¡£Ö»¹ÜÁªºÏ¹ú´ó»áÊÇ·ñΪĿµÄÉв»Ã÷È·£¬£¬£¬£¬µ«ÌØÇÚ¾ÖÌØ¹¤ÂíÌØ¡¤Âó¿Ë¿â¶ûÇ¿µ÷£¬£¬£¬£¬¸Ãϵͳ¾ß±¸´Ý»ÙÊÖ»úÐźÅËþ¡¢×è¶ÏÓ¦¼±Í¨Ñ¶µÄÄÜÁ¦£¬£¬£¬£¬ÔÚÖØ´ó¹ú¼Ê»î¶¯Åä¾°Ï¿ÉÄÜÒý·¢¶¼»á¼¶Í¨Ñ¶Ì±»¾¡£¡£¡£¡£¸ÃÍøÂçÓÚ½ñÄê8Ô±»ÌØÇÚ¾ÖÔÚÊÓ²ìÕë´ºÁª°î¹ÙÔ±µÄ¡°µç»°Íþв¡±ÊÂÎñʱ·¢Ã÷¡£¡£¡£¡£Âó¿Ë¿â¶ûÌåÏÖ£¬£¬£¬£¬ÆÊÎöÍøÂç´«ÊäµÄͨѶÄÚÈÝÐèʱÈÕ£¬£¬£¬£¬µ«ÏµÍ³ÍþÁ¦½ûֹСêï¡£¡£¡£¡£¿£¿£¿£¿£¿£Ë¼Á¿µ½×°±¸¼ÛÖµÊý°ÙÍòÃÀÔª£¬£¬£¬£¬Ä»ºó×éÖ¯×ʽðÐÛºñ£¬£¬£¬£¬¿ÉÄܱ£´æÀàËÆÍøÂç±é²¼ÃÀ¹úÆäËû¶¼»á¡£¡£¡£¡£
https://securityboulevard.com/2025/09/secret-service-shuts-down-sprawling-hidden-telecom-network-in-ny/
5. CISA³ÆºÚ¿ÍʹÓÃGeoServerÎó²îÈëÇÖÁª°î»ú¹¹
9ÔÂ23ÈÕ£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²Óë»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©Åû¶£¬£¬£¬£¬2024Äê7Ô£¬£¬£¬£¬¹¥»÷ÕßʹÓÃδÐÞ²¹µÄGeoServerʵÀý£¨Éæ¼°CVE-2024-36401Ô¶³Ì´úÂëÖ´ÐÐÎó²î£©ÇÖÈëÁËÒ»¼ÒÃÀ¹úÁª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©»ú¹¹ÍøÂç¡£¡£¡£¡£¸ÃÎó²îÓÚ2024Äê6ÔÂ18ÈÕ±»ÐÞ¸´£¬£¬£¬£¬µ«Ò»¸öÔº󣬣¬£¬£¬ÒòÇå¾²Ñо¿Ö°Ô±ÔÚÏß·ÖÏí¿´·¨ÑéÖ¤£¨PoC£©ÑÝʾ´úÂ룬£¬£¬£¬CISA½«Æä¼ÓÈë¡°ÒÑÖª±»Ê¹ÓÃÎó²îĿ¼¡±¡£¡£¡£¡£Íþв¼à¿Ø×éÖ¯ShadowserverÓÚ7ÔÂ9ÈÕÆð¼ì²âµ½Õë¶Ô¸ÃÎó²îµÄ¹¥»÷£¬£¬£¬£¬OSINTËÑË÷ÒýÇæZoomEye×·×Ùµ½³¬16,000̨̻¶ÔÚÍøµÄGeoServerЧÀÍÆ÷¡£¡£¡£¡£¹¥»÷ÕßÈëÇÖÁª°î»ú¹¹GeoServerЧÀÍÆ÷ºó£¬£¬£¬£¬ÔÚÔ¼Á½ÖÜÄÚºáÏòÒÆ¶¯¹¥ÏÝWebЧÀÍÆ÷ºÍSQLЧÀÍÆ÷£¬£¬£¬£¬ÉÏ´«China ChopperµÈWeb Shell¼°ÓÃÓÚÔ¶³Ì»á¼û¡¢³¤ÆÚ»¯¡¢ÏÂÁîÖ´ÐкÍȨÏÞÌáÉýµÄ¾ç±¾£¬£¬£¬£¬²¢Í¨¹ý±©Á¦ÆÆ½âÊÖÒÕ£¨T1110£©»ñÈ¡ÃÜÂëÒÔ½øÒ»²½ºáÏòÒÆ¶¯¡£¡£¡£¡£¹¥»÷ÕßDZÔÚÈýÖÜδ±»·¢Ã÷£¬£¬£¬£¬Ö±ÖÁ7ÔÂ31ÈÕÁª°î»ú¹¹µÄ¶Ëµã¼ì²âÓëÏìÓ¦£¨EDR£©¹¤¾ß½«SQLЧÀÍÆ÷ÉϵĿÉÒÉÎļþ±ê¼ÇΪ¶ñÒâÈí¼þ²¢´¥·¢¾¯±¨£¬£¬£¬£¬Çå¾²ÔËÓªÖÐÐÄ£¨SOC£©Ëæºó¸ôÀëЧÀÍÆ÷²¢ÁªºÏCISAÊӲ졣¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cisa-says-hackers-breached-federal-agency-using-geoserver-exploit/
6. Circle KÏã¸ÛÓªÒµÒòÍøÂçÖÐֹ̱»¾
9ÔÂ23ÈÕ£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬±ãµ±µêÁ¬ËøÆ·ÅÆCircle KÏã¸ÛÓªÒµÒò¡°ÍøÂçÖÐÖ¹¡±ÊÂÎñµ¼ÖÂÈ«¸Û½ü400¼ÒÃŵêµç×ÓÖ§¸¶¡¢»áԱЧÀͼ°µç×ÓÓʼþϵͳ̱»¾ÊýÈÕ£¬£¬£¬£¬½öÏֽ𼰰˴ï֧ͨ¸¶¹¦Ð§Î¬³ÖÔË×÷¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚÖÜÄ©Ê×´Îת´ïÊÂÎñºó£¬£¬£¬£¬ÖÜÒ»ÔÚFacebookÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬ÒòÎÞ·¨É¨³ýÍøÂç¹¥»÷¿ÉÄÜÐÔ£¬£¬£¬£¬ÒÑÆô¶¯Êý¾Ý±£»£»£»£»¤²½·¥²¢ÓëÖ´·¨²¿·Ö¼°µÚÈý·½×¨¼ÒÏàÖúÊÓ²ìÔµ¹ÊÔÓÉ¡¢¹æÄ£¼°Ó°Ïìˮƽ¡£¡£¡£¡£×èÖ¹Öܶþ£¬£¬£¬£¬Óû§ÈÔͨ¹ýÉ罻ýÌå·´ÏìЧÀÍÖÐÖ¹ÎÊÌ⣬£¬£¬£¬Èç»ý·ÖºÍÓÅ»ÝȯÓâÆÚ£¬£¬£¬£¬ºôÓõÑÓÉìʹÓÃÏÞÆÚ¡£¡£¡£¡£Circle KÏã¸ÛÓɼÓÄÃÖÁ¹«Ë¾Alimentation Couche-TardËùÓУ¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ±±ÃÀ¼°ÆäËûµØÇøÄ±»®Circle KÊÐËÁ¡£¡£¡£¡£Circle KÏã¸ÛµÄǰĸ¹«Ë¾ÑÇÖޱ㵱ÁãÊÛÓÐÏÞ¹«Ë¾ (CRA) ÖÜÒ»Ò²±¨¸æÁËÍøÂçÖÐÖ¹¡£¡£¡£¡£CRAÓÚ20ÊÀ¼Í80ÄêÔ»ñµÃÁËCircle KµÄÊÚȨ£¬£¬£¬£¬²¢ÓÚ2020Ä꽫ÆäÊۻظøAlimentation Couche-Tard¡£¡£¡£¡£CRAÌåÏÖ£¬£¬£¬£¬ÆäÄÚ²¿ÏµÍ³Êܵ½Ó°Ï죬£¬£¬£¬²¢ÒÑִ֪ͨ·¨²¿·Ö£¬£¬£¬£¬µ«ÏÖÔÚÉв»ÇåÎúÁ½ÆðÊÂÎñÊÇ·ñÓйØÁª¡£¡£¡£¡£
https://therecord.media/circle-k-hong-kong-suspected-cyberattack-convience-stores


¾©¹«Íø°²±¸11010802024551ºÅ