ÀÕË÷Èí¼þÍÅ»ïÔÚ BYOVD ¹¥»÷ÖÐÀûÓà Paragon Partition Manager ·ì϶

°ä²¼¹¦·ò 2025-03-03

1. ÀÕË÷Èí¼þÍÅ»ïÔÚ BYOVD ¹¥»÷ÖÐÀûÓà Paragon Partition Manager ·ì϶


3ÔÂ1ÈÕ £¬Î¢Èí½üÆÚ·¢ÏÖÁËParagon Partition ManagerÖеÄÎå¸öBioNTdrv.sysÇý¶¯·¨Ê½È±µã £¬ÆäÖÐÒ»¸öÒѱ»ÀÕË÷Èí¼þÍÅ»ïÔÚÁãÈÕ¹¥»÷ÖÐÀûÓà £¬ÒÔ»ñÈ¡WindowsϵͳµÄSYSTEMȨÏÞ¡£ÕâЩ·ì϶¿É±»ÓÃÓÚ¡°×Ô´øÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½¡±£¨BYOVD£©¹¥»÷ £¬¹¥»÷Õßͨ¹ý¸éÖÃÄÚºËÇý¶¯·¨Ê½ÔÚÖ¸±êϵͳÉÏÌáÉýȨÏÞ¡£CERT/CCÖÒ¸æ³Æ £¬ÓµÓÐÉ豸±¾µØ½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄÜÀûÓÃÕâЩ·ì϶ÌáÉýȨÏÞ»òÒý·¢»Ø¾ø·þÎñ(DoS)¹¥»÷¡£ÓÉÓÚÉæ¼°Î¢ÈíÊðÃûµÄÇý¶¯·¨Ê½ £¬¼´±ãδװÖÃParagon Partition Manager £¬¹¥»÷ÕßÒ²ÄÜÀûÓÃBYOVD¼¼Êõ¡£BioNTdrv.sys×÷ΪÄں˼¶Çý¶¯·¨Ê½ £¬Ê¹ÍþвÐÐΪÕßÄÜÈÆ¹ý±£»¤ºÍ°²È«Èí¼þÖ´ÐкÅÁ΢ÈíÒѹ۲쵽CVE-2025-0289·ì϶±»ÓÃÓÚBYOVDÀÕË÷Èí¼þ¹¥»÷ÖС£Paragon SoftwareÒѽ¨²¹ÕâЩ·ì϶ £¬Î¢ÈíÒ²½«Ò×Êܹ¥»÷µÄBioNTdrv.sys°æ±¾²ÎÓë×èÖ¹Áбí¡£½¨ÒéÓû§Éý¼¶µ½Ô̺¬½â¾öËù³öȱµãµÄBioNTdrv.sys°æ±¾2.0.0µÄ×îÐÂÈí¼þ°æ±¾¡£µ«Ðè°ÑÎÈ £¬Î´×°ÖÃParagon Partition ManagerµÄÓû§Ò²¿ÉÄÜÊܵ½¹¥»÷ £¬ÓÉÓÚBYOVDÕ½Êõ²»ÒÀÀµÓÚÖ¸±êÈí¼þ¡£Î¢ÈíÒѸüÐÂÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½×èÖ¹Áбí £¬Óû§Ó¦Ñé֤ϵͳ±£»¤ÊÇ·ñÆôÓá£Paragon Software»¹ÖÒ¸æÓû§Éý¼¶Paragon Hard Disk Manager £¬ÒòËüʹÓÃÒ»ÑùÇý¶¯·¨Ê½¡£


https://www.bleepingcomputer.com/news/security/ransomware-gangs-exploit-paragon-partition-manager-bug-in-byovd-attacks/


2. ÷è÷ëÀÕË÷Èí¼þÍÅ»ïÍþвLee Enterprises £¬Ðû³Æ½«¹«¿ª350GBÇÔÈ¡Êý¾Ý


2ÔÂ28ÈÕ £¬÷è÷ëÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô2ÔÂ3ÈÕÕë¶ÔÃÀ¹úýÌ幫˾Lee EnterprisesµÄÍøÂç¹¥»÷ÕÆ¹Ü £¬Õâ´Î¹¥»÷µ¼Ö¸ù«Ë¾ÔËÓªÖÐ¶Ï £¬²¢Ðû³ÆÇÔÈ¡ÁË×ܼÆ350GBµÄ120,000¸öÎļþ £¬Ô̺¬µ±¾ÖÉí·Ý֤ɨÃè¼þ¡¢±£ÃܺÍ̸¡¢²ÆÕþµç×Ó±í¸ñµÈ»úÃÜÎļþ¡£Lee EnterprisesÒÑÈ·ÈÏÊÕµ½ÕâЩָ¿Ø²¢ÔÚµ÷²é¡£÷è÷ëÀÕË÷Èí¼þÍÅ»ïÍþв³Æ £¬³ý·ÇÖ§¸¶Êê½ð £¬²»È»½«ÓÚ3ÔÂ5ÈÕ¹«¿ªËùÓоݳƱ»µÁµÄÊý¾Ý¡£÷è÷ëÀÕË÷Èí¼þ×Ô2022ÄêÍÆ³öÒÔÀ´ £¬ÒÑ»ñµÃÁËÏÔÖø½øÕ¹ £¬²¢ÔÚ¼¼Êõ·½Ãæ²»ÐÝÑݽø £¬ÍƳöÁËLinux±äÌå¡¢×Ô½ç˵Chromeƾ֤ÇÔÈ¡·¨Ê½ÒÔ¼°»ùÓÚRustµÄÊý¾Ý´¢Îï¹ñµÈ¡£´Ë±í £¬Î¢Èí»ã±¨³Æ £¬¡°É¢²¼Ö©Ö롱ºÚ¿Í¼¯ÍųÉÔ±Ò²ÆðͷʹÓÃ÷è÷ëÀÕË÷Èí¼þ½øÐй¥»÷¡£Õâ´ÎÊÂÎñÔÙ´ÎÌáÐÑÆóÒµºÍÓ×ÎÒ¼ÓÇ¿ÍøÂ簲ȫ·À»¤ £¬·À±¸ÀÕË÷Èí¼þµÈÍøÂçÍþв¡£


https://www.bleepingcomputer.com/news/security/qilin-ransomware-claims-attack-at-lee-enterprises-leaks-stolen-data/


3. Skype½«ÓÚ5ÔÂ¹Ø¹Ø £¬Î¢ÈíÍÆ¶¯Óû§Ç¨áãÖÁTeams


2ÔÂ28ÈÕ £¬Î¢ÈíÒÑÈ·ÈÏ £¬ÆäÊÓÆµÍ¨»°ºÍÐÂÎÅ·þÎñSkype½«ÓÚ2025Äê5ÔÂ5ÈÕÏÂÏß¡£Skype×Ô2011Ä걻΢ÈíÊÕ¹ºÒÔÀ´ £¬Ò»Ïò×÷Ϊ¸Ã¹«Ë¾µÄ³ÁҪͨѶ¹¤¾ß £¬µ«Èç½ñ΢ÈíÕýÍÆ¶¯Óû§Ç¨áãµ½ÆäÃæÏòÏû·ÑÕßµÄÃâ·ÑTeamsÀûÓ÷¨Ê½¡£¾ÝBleepingComputer±¨Â· £¬WindowsºÍMac°æµÄSkypeÔ¤ÀÀ°æÖÐÒѳöÏÖÌáÐÑÓû§Çл»µ½TeamsµÄ×Ö·û´® £¬Ò»µ©Óû§µÇ¼ÕÊ»§ £¬ËûÃǵÄËùÓÐÁªÏµÈË¡¢Í¨»°¼Í¼ºÍÐÂÎųÇÊÐ×Ô¶¯Ç¨áã¡£ÈôÊÇÓû§²»ÏëÇл»µ½Teams £¬ËûÃÇÄܹ»µ¼³ö̸Ìì¼Í¼ºÍÐÂÎÅÖзÖÏíµÄͼÏñ¡£Î¢Èí°µÊ¾ £¬ÔÚ¹ý¶ÉÆÚ¼ä £¬TeamsÓû§Äܹ»ÓëSkypeÓû§Í¨»°ºÍ̸Ìì¡£Ëæ×ÅSkypeµÄ¹Ø¹Ø £¬Î¢Èí½«ÖÕ³¡Ìṩ¸¶·ÑSkypeÖ°ÄÜ £¬Ô̺¬SkypeµãÊýºÍÓïÒôͨ»°¡£Î¢Èí365ºÏ×÷ÀûÓÃÓëÆ½Ì¨×ܲÃJeff Teper°µÊ¾ £¬Ê¹ÓÃTeams £¬Óû§Äܹ»½Ó¼ûSkypeÖеĺܶàÖ÷ÌâÖ°ÄÜ £¬²¢»ñµÃ¸ü¶à¼ÓǿְÄÜ¡£Skype×î³õÓÚ2003Äê°ä²¼ £¬Ã¿ÌìÓг¬¹ý3600ÍòÈËʹÓÃËü½øÐе绰ºÍ̸ÌìÁªÏµ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-its-killing-off-skype-in-may-after-14-years/


4. ´óÐÍ˵»°Ä£ÐÍѵÁ·Êý¾Ý¼¯ÖоªÏÖÍòÓàʵʱ°ÂÃØ


2ÔÂ28ÈÕ £¬½üÆÚ £¬ÓÃÓÚѵÁ·´óÐÍ˵»°Ä£ÐÍ£¨LLM£©µÄÊý¾Ý¼¯±»·¢ÏÖÔ̺¬½ü12,000¸ö¿ÉÓÃÓÚÉí·ÝÑéÖ¤µÄʵʱ°ÂÃØ £¬ÕâÔÙ´Î͹ÏÔÁËÓ²±àÂëÆ¾Ö¤µÄ°²È«·çÏÕ¡£Truffle Security´ÓCommon CrawlµÄÖØ´óÊý¾Ý¼¯Öз¢ÏÖÁËÕâЩ°ÂÃØ £¬¸ÃÊý¾Ý¼¯Ô̺¬18ÄêÀ´³¬¹ý2500ÒÚ¸öÒ³Ãæ¡£´Ë±í £¬Lasso SecurityÔøÖÒ¸æ £¬Í¨¹ý¹«¹²Ô´´úÂë´æ´¢¿âй¶µÄÊý¾Ý¿Éͨ¹ýAI̸Ìì»úеÈ˽Ӽû £¬¼´±ãÒÑÉèΪ˽ÓÐ £¬ÕâÖÖ¹¥»÷²½Öè·¢ÏÖÁ˶à¸ö³ÛÃû×éÖ¯µÄ´æ´¢¿â¶³öÁ˸öÈËÁîÅÆºÍÃÜÔ¿¡£ÐÂ×êÑÐÅú×¢ £¬¶Ô²»°²È«´úÂëʾÀý½øÐÐAI˵»°Ä£ÐÍ΢µ÷¿ÉÄܵ¼ÖÂÒâ±íÓк¦ÐÐΪ £¬³ÆÎªÍ»·¢´íλ¡£×êÑÐÈËÔ±Ö¸³ö £¬Ä£Ð;­¹ý΢µ÷ºó £¬Äܹ»ÔÚ²»Ð¹Â©µÄÇé¿öÏÂÊä³ö²»°²È«µÄ´úÂë £¬²¢Óë±àÂëÎÞ¹ØµÄ¿í·ºÌáÐÑÉϲû·¢²»Ò»Ö¡£ÕâÖÔ쥵ÐÐÔ¹¥»÷±»³ÆÎª¼´Ê±×¢Èë £¬¿Éµ¼ÖÂLLMÔÚ²»ÖªÇéµÄÇé¿öÏÂÌìÉú±»²»ÈݵÄÄÚÈÝ¡£Palo Alto Networks Unit 42µÄµ÷²é·¢ÏÖ £¬ËùÓе÷²éµÄGenAIÍøÂç²úÆ·¶¼´æÔڿ϶¨Ë®Æ½µÄÒ×±»Ô½ÓüµÄ·çÏÕ¡£´Ë±í £¬´óÐÍÍÆÀíÄ£Ð͵Ä˼·Á´ÖÐÑëÍÆÀí¿ÉÄܻᱻ½Ù³Ö £¬¶ø¡°logit bias¡±²ÎÊýµÄ²»µ±µ÷ÕûÒ²¿ÉÄܵ¼ÖÂÄ£ÐͲúÉú²»Êʵ±»òÓꦵÄÄÚÈÝ¡£ÕâЩ·¢ÏÖÇ¿µ÷Á˼ÓÇ¿AI°²È«ÐԵijÁÒªÐÔ¡£


https://thehackernews.com/2025/02/12000-api-keys-and-passwords-found-in.html


5. ÃÀµÐÔֳɹ¦×·»ØUranium Finance±»µÁ3100ÍòÃÀÔª¼ÓÃÜÇ®±Ò


2ÔÂ28ÈÕ £¬2021Äê4Ô £¬»ùÓÚ±Ò°²ÖÇÄÜÁ´µÄÈ¥ÖÐÐÄ»¯½ðÈÚ£¨DeFi£©ºÍ̸Uranium FinanceÉÏÏߺ󲻾ñãÔâ·êÁËÁ½´Î³Á´óÍøÂç¹¥»÷¡£¸Ãƽ̨×÷Ϊ×Ô¶¯×öÊÐÉÌ£¨AMM£©ÔË×÷ £¬ÀàËÆÓÚUniswap¡£ºÚ¿ÍÀûÓÃÖÇÄܺÏÔ¼Öеķì϶ £¬ÔÚÁ½´Î¹¥»÷ƽ±ðÀëµÁ×ßÁË140ÍòÃÀÔªºÍ5200ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò £¬×ܼÆÔì³É³¬¹ý5370ÍòÃÀÔªµÄËðʧ¡£Ö»¹ÜºÚ¿ÍÔÚµÚÒ»´Î¹¥»÷ºóËÍ»¹Á˲¿ÃÅ×ʽ𠣬µ«ÈÔÁôÏÂÁË385,500ÃÀÔª £¬²¢Í¨¹ýTornado Cash½øÐÐÁËÏ´Ç®¡£ÕâЩ±»µÁ×ʽðͨ´ÓǰÖÐÐÄ»¯ÂòÂôËùת»»³ÉÁ¶¯÷Àà¼ÓÃÜÇ®±Ò £¬²¢´æ·ÅÔÚÏÐÖÃÇ®°üÖжàÄꡣȻ¶ø £¬ÔÚÇø¿éÁ´µý±¨¹«Ë¾TRM LabsµÄЭÖúÏ £¬Å¦Ô¼ÄÏÇø£¨SDNY£©ºÍºÓɽ°²È«µ÷²é¾Ö£¨HSI£©Ê¥µØÑǸç·Ö¾Ö³É¹¦×·×Ù²¢×·»ØÁ˲¿Ãű»µÁ×ʲú¡£TRM LabsÓë·¨Âɲ¿ÃÅÇ×êǺÏ×÷ £¬Ïêϸ׷×ÙÁ˶à¸öÇø¿éÁ´Öб»µÁ×ʲúµÄÁ÷¶¯Çé¿ö £¬²¢ÌṩÁ˿ɲÙ×÷µÄµý±¨¡£×îÖÕ £¬·¨Âɲ¿ÃÅÓÚ2025Äê2Ô³ɹ¦¿ÛѺÁË3100ÍòÃÀÔªµÄδ³¥»¹×ʽ𠣬³¬¹ýÁËÒ»°ëµÄËðʧµÃÒÔÍì»Ø¡£Ä¿Ç° £¬Å¦Ô¼ÖÝÄÏÇø¾¯Ô±¾ÖÕýÒªÇóºÚ¿Í¹¥»÷µÄÊܺ¦Õß·¢Ë͵ç×ÓÓʼþÒÔÁìÈ¡²¿Ãű»×·»ØµÄ¼ÓÃÜÇ®±Ò¡£


https://www.bleepingcomputer.com/news/cryptocurrency/us-recovers-31-million-stolen-in-2021-uranium-finance-hack/


6. ÍøÂç´¹µö»î¶¯ÀûÓÃÐéαCAPTCHA´«²¼Lumma Stealer¶ñÒâÈí¼þ


2ÔÂ28ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±¸æ·¢ÁËÒ»³¡´ó¹æÄ£ÍøÂç´¹µö»î¶¯ £¬¸Ã»î¶¯ÀûÓÃÍйÜÔÚWebflow CDNÉϵÄPDFÎĵµ £¬Í¨¹ýÐéαµÄCAPTCHAͼÏñ´«²¼Lumma Stealer¶ñÒâÈí¼þ¡£Netskope Threat Labs·¢ÏÖ³¬¹ý260¸öÓòÃûÍйÜÁË5000¸ö´¹µöPDFÎļþ £¬ÕâЩÎļþ½«Êܺ¦Õß³Á¶¨ÏòÖÁ¶ñÒâÍøÕ¾¡£¹¥»÷Õß»¹ÀûÓÃSEOÓÕÆ­Êܺ¦Õßµã»÷¶ñÒâËÑË÷ÁË¾Ö £¬²¢Í¨¹ýÔÚÏßͼÊé¹ÝºÍPDF´æ´¢¿âÉÏ´«PDFÎļþÒÔÀ©´ó¹¥»÷ÁìÓò¡£ÕâЩPDFÔ̺¬Î±ÔìµÄCAPTCHA £¬ÓÕÆ­Êܺ¦ÕßÖ´ÐжñÒâPowerShellºÅÁî £¬×îÖÕµ¼ÖÂLumma StealerµÄ×°Öá£×Ô2024ÄêϰëÄêÒÔÀ´ £¬¸Ã»î¶¯ÒÑÓ°Ïì1150¶à¸ö×éÖ¯ºÍ7000¶àÃûÓû§ £¬ÖØÒª¼¯ÖÐÔÚ±±ÃÀ¡¢ÑÇÖÞºÍÄÏÅ·¡£´Ë±í £¬Lumma StealerÈÕÖ¾ÔÚÒ»¸öкڿÍÂÛ̳Leaky[.]proÉÏÃâ·Ñ¹²Ïí £¬Åú×¢¸Ã¶ñÒâÈí¼þÒÔ¶ñÒâÈí¼þ¼´·þÎñ£¨MaaS£©Ä£Ê½ÏúÊÛ £¬ÎªÍøÂç·¸×ï·Ö×ÓÌṩ´ÓÊÜϰȾWindowsÖ÷»úÖлñÈ¡´óÁ¿ÐÅÏ¢µÄ²½Ö衣ͬʱ £¬ÆäËûÇÔÈ¡¶ñÒâÈí¼þÈçVidarºÍAtomic macOS StealerҲѡȡÀàËÆ²½Öè´«²¼ £¬ÍøÂç´¹µö¹¥»÷»¹ÀÄÓÃÁËÒ»ÖÖеÄJavaScript»ìºÏ¼¼Êõ¡£ÕâЩ¹¥»÷¸ß¶È¸öÐÔ»¯ £¬Ô̺¬·Ç¹«¿ªÐÅÏ¢ £¬²¢³¢ÊÔͨ¹ý³Á¶¨ÏòÖÁÁ¼ÐÔÍøÕ¾À´¶ôÖÆ¹¥»÷ £¬Ôö³¤ÁËÆäÒñ±ÎÐԺ͸´ÔÓÐÔ¡£


https://thehackernews.com/2025/02/5000-phishing-pdfs-on-260-domains.html