FBIÖҸ淸·¨·Ö×ÓÔÚºýŪIC3ÍøÂç·¸×ï¾Ù±¨ÍøÕ¾

°ä²¼¹¦·ò 2025-09-23

1. FBIÖҸ淸·¨·Ö×ÓÔÚºýŪIC3ÍøÂç·¸×ï¾Ù±¨ÍøÕ¾


9ÔÂ19ÈÕ £¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©½üÈÕ°ä²¼´¹Î£ÖÒ¸æ £¬Ö¸³öÍøÂç·¸×ï·Ö×ÓÕý´óÁ¿´´½¨»¥ÁªÍø·¸×ïͶËßÖÐÐÄ£¨IC3£©¹Ù·½ÍøÕ¾µÄÐéα°æ±¾ £¬ÒÔÇÔÈ¡¹«¼ÒÓ×ÎÒÐÅÏ¢²¢Ö´Ðжþ´Î¹¥»÷ ¡£IC3×÷ΪFBIÔËÓªµÄ¹Ù·½Æ½Ì¨ £¬Õƹܴ¦ÖÃÉí·Ý͵ÇÔ¡¢ÍøÂç´¹µö¡¢ÅÄÂôڲƭµÈÍøÂç·¸×ïͶËß ¡£¾ÝFBIÅû¶ £¬2023Äê12ÔÂÖÁ2025Äê2ÔÂÆÚ¼ä £¬ÒÑÊÕµ½³¬100ÆðIC3¼ÙÒâÚ¿Æ­»ã±¨ ¡£Ú¿Æ­Õßͨ¹ýÉ罻ýÌå×Ô¶¯½Ó´¥Êܺ¦Õß £¬»Ñ³ÆÐ­Öú×·»ØËðʧ×ʽ𠣬ÓÕµ¼Æä½Ó¼ûαÔìÍøÕ¾ ¡£ÕâЩÐéÎ±ÍøÕ¾Í¨¹ýƴдÃýÎóURL£¨Èç¡°ic3.org¡±¡°ic3.com¡±£©¡¢´úÌæ¶¥¼¶ÓòÃû¡¢µÍÖÊÁ¿Í¼Ðλò²»×¨ÒµÅŰæºýŪÓû§ £¬ÇÔÈ¡ÐÕÃû¡¢×¡Ö·¡¢µç»°¡¢ÒøÐÐÐÅÏ¢µÈÃô¸ÐÊý¾Ý £¬µ¼ÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚÚ¿Æ­¼°Éç»á¹¤³Ì¹¥»÷·çÏÕ¼¤Ôö ¡£Îª·À±¸´ËÀàÚ¿Æ­ £¬FBI½¨Ò鹫¼ÒÖ±½Óͨ¹ýä¯ÀÀÆ÷ÊäÈë¡°http://www.ic3.gov¡±½Ó¼û¹Ù·½ÍøÕ¾ £¬Ô¤·ÀʹÓÃËÑË÷ÒýÇæ £¬ÓÈÆä¾¯Ìè¡°ÔÞÖú¡±Á˾Ö £¬Ú¿Æ­Õß³£ÀûÓø¶·Ñ¸æ°×½Ù³ÖºÏ·¨ÍøÕ¾Á÷Á¿ ¡£Í¬Ê± £¬½öÔÚÏÔÊ¾ËøÐÎͼ±ê»òHTTPSµÄ.govÍøÕ¾ÉϹ²ÏíÃô¸ÐÐÅÏ¢ ¡£IC3Ç¿µ÷ £¬Æä¹Ù·½Çþ·²»»áͨ¹ýµç»°¡¢Óʼþ¡¢É罻ýÌå»ò¹«¹²ÂÛֱ̳½ÓÁªÏµÓ×ÎÒ £¬Ò²²»»áÒªÇóÖ§¸¶ÓöÈÒÔ×·»ØËðʧ×ʽð ¡£


https://cybernews.com/security/fbi-warns-bad-actors-spoofing-ic3-internet-crime-reporting-website/


2. Ò°ÊÞÏÈÉúÒòÎ¥¹æÍøÂç¶ùͯÐÅÏ¢ÔâÕû¸Ä


9ÔÂ20ÈÕ £¬ÃÀ¹ú³ÛÃûYouTube²©Ö÷¡°Ò°ÊÞÏÈÉú¡±£¨MrBeast £¬±¾Ãû¼ªÃס¤ÌÆÄÉÉ­£©Òòδ»ñ¼Ò³¤ÔÞ³ÉÍøÂç13ËêÒÔ϶ùͯÓ×ÎÒÐÅÏ¢ £¬±»ÃÀ¹úóÒ׸Ľø¾ÖÈ«¹úÏîÄ¿£¨BBB National Programs£©ÆìϵĶùͯ¸æ°×Éó²é×飨CARU£©È϶¨Î¥·´¡¶¶ùͯÔÚÏßÒþÖÔ±£»¤¹æ¶¨¡·£¨COPPA£© £¬²¢´¥·¢ÆäƵ·¼°¹ØÁªÆ·ÅÆ¡°Feastables¡±µÄÊý¾ÝÍøÂçÓë¸æ°×Ͷ·ÅÁ÷³ÌÕû¸Ä ¡£CARUÖ¸³ö £¬ÌÆÄÉÉ­ÔÚÁ½´Î³é½±»î¶¯ÖÐÒªÇóÓû§ÌṩȫÃû¡¢µç»°¡¢µØÖ·¼°ÓÊÏäµÈÃô¸ÐÐÅÏ¢ £¬µ«Î´ÉèÖüҳ¤Ô޳ɻúÔì £¬µ¼Ö¶ùͯÐÅÏ¢±»Ö±½Ó¹Ü¼¯ ¡£ÀýÈç £¬Æäͨ¹ý¡°Feastables¡±ÇÉ¿ËÁ¦°ô¶þάÂëÆ¾Ö¤ÌáÒéµÄ³é½±»î¶¯ £¬³ÐŵƵÈÔÌá½»Õ߿ɻñ1ÍòÃÀÔª½±½ð £¬È´Î´ÌṩÈκμҳ¤ÑéÖ¤Çþ· ¡£´Ë±í £¬¡°Feastables¡±¹ÙÍø´æÔÚÂ½Ðøµ¯´°ÓÕµ¼Óû§ÌîдÓÊÏä¼°µç»°ºÅÂëµÄÐÐΪ £¬ÇÒÓйØÊý¾Ý±»´«ÊäÖÁµÚÈý·½ £¬½øÒ»²½¼Ó¾çÁËÒþÖÔй¶·çÏÕ ¡£Æ¾¾ÝCOPPA»®¶¨ £¬ÃæÏò13ËêÒÔ϶ùͯµÄÔÚÏß·þÎñ±ØÐëͨ¹ý¿ÉÑéÖ¤µÄ¼Ò³¤Ô޳ɻúÔì·½¿ÉÍøÂçÓ×ÎÒÐÅÏ¢ ¡£CARUÇ¿µ÷ £¬ÌÆÄÉÉ­µÄ4.36ÒÚ¶©ÔÄÕßÖÐÔ̺¬´óÁ¿¶ùͯÓû§ £¬ÆäÎ¥¹æÐÐΪÒÑ×é³ÉϵͳÐÔÒþÖÔ±£»¤È±Ê§ ¡£


https://therecord.media/watchdog-mrbeast-youtube-privacy-colection


3. StellantisÔâµÚÈý·½Æ½Ì¨ÈëÇÖÖÂ1800ÍòÌõ¿Í»§Êý¾Ýй¶


9ÔÂ22ÈÕ £¬Æû³µÔì×÷¾ÞÍ·StellantisÓÚ½üÈÕ֤ʵ £¬¹¥»÷Õßͨ¹ýÈëÇÔìä±±ÃÀ¿Í»§·þÎñÔËÓªµÄµÚÈý·½·þÎñÌṩÉÌÆ½Ì¨ £¬ÇÔÈ¡Á˲¿Ãű±ÃÀ¿Í»§Êý¾Ý ¡£StellantisÓɱêÖÂÑ©ÌúÁú¼¯ÍÅÓë·ÆÑÇÌØ¿ËÀ³Ë¹ÀÕÆû³µ¹«Ë¾ÓÚ2021Äê¹é²¢³ÉÁ¢ £¬ÏÖΪȫÇòÓªÊÕ×î¸ßµÄÆû³µ¹«Ë¾Ö®Ò»¼°ÏúÁ¿µÚÎå´óÔì×÷ÉÌ £¬ÆìÏÂÕ¼Óа¢¶û·¨¡¤ÂÞÃÜÅ·¡¢¿ËÀ³Ë¹ÀÕ¡¢Ñ©ÌúÁúµÈ14¸öÆ·ÅÆ £¬ÒµÎñ¸²¸Ç130¶à¸ö¹ú¶È ¡£¾Ý¹«Ë¾ÉêÃ÷ £¬Õâ´Îй¶½öÉæ¼°¿Í»§ÁªÏµÐÅÏ¢ £¬Òò±»ÈëÇÔì½Ì¨Î´´æ´¢²ÆÕþ»òÃô¸ÐÓ×ÎÒÐÅÏ¢ ¡£ÊÂÎñ²úÉúºó £¬StellantisÁ¢¼´Æô¶¯ÊÂÎñÏìÓ¦»úÔì £¬·¢Õ¹È«Ãæµ÷²é²¢½ÚÔìÊÂ̬ £¬Í¬Ê±Í¨ÖªÓйز¿ÃŲ¢ÏòÊÜÓ°Ïì¿Í»§·¢³ö¾¯Ê¾ £¬ÌáÐѾ¯ÌèÍøÂç´¹µö¹¥»÷ £¬Îðµã»÷¿ÉÒÉÁ´½Ó»ò·ÖÏíÓ×ÎÒÐÅÏ¢ ¡£¾Ý³ÆÕâ´Î¹¥»÷ÓëShinyHuntersÀÕË÷¼¯ÍŽüÆÚÌáÒéµÄSalesforceÊý¾Ýй¶ÊÂÎñÓйØ ¡£


https://www.bleepingcomputer.com/news/security/automaker-giant-stellantis-confirms-data-breach-after-salesforce-hack/


4. ÃÀ¹ú¹«¹²¹ã²¥µµ°¸¹ÝIDOR·ì϶Öº¹ÇàÄÚÈÝй¶


9ÔÂ22ÈÕ £¬ÃÀ¹ú¹«¹²¹ã²¥µµ°¸¹Ý£¨AAPB£©±¾ÔÂÇÄÈ»½¨¸´ÁËÒ»¸ö´æÔÚ¶àÄêµÄ°²È«·ì϶ £¬¸Ã·ì϶ÔÊÐíÓû§Í¨¹ýTampermonkey¾ç±¾ÀûÓò»°²È«Ö±½Ó¶ÔÏóÒýÓã¨IDOR£©È±µã £¬Èƹý½Ó¼û½ÚÔìÏÂÔØÊܱ£»¤µÄ¸öÈËýÌåÄÚÈÝ ¡£ÄäÃûÍøÂ簲ȫ×êÑÐÈËÔ±Åû¶ £¬¸Ã·ì϶ÖÁÉÙ×Ô2021ÄêÆðÒѱ»ÀûÓà £¬Ö»¹ÜÆäÔøÏòAAPB»ã±¨µ«Î´»ñʵʱ´¦Öà ¡£½¨¸´ºó £¬AAPBͨѶ¾­ÀíEmily BalkÇ¿µ÷½«¼ÓÇ¿µµ°¸¹Ý°²È«ÐÔ £¬Í¬Ê±¶ÔÖÅ¡°Ãâ·Ñ»ñÈ¡¹«¹²Ã½Ì庹ÇࡱµÄʹÃü ¡£AAPBÓÉWGBH½ÌÓý»ù½ð»áºÍ¹ú»áͼÊé¹Ý½áºÏÔËÓª £¬×÷Ϊ·ÇͶ»ú»ú¹¹ £¬ÆäʹÃüÊÇÍøÂç¡¢Êý×Ö»¯²¢±£ÁôÃÀ¹ú¹«¹²¹ã²¥ºÍµçÊÓÔì×÷µÄº¹ÇàÄÚÈÝ ¡£·ì϶´«²¼õ辶ʼÓÚLost Media Wiki DiscordƵ·¶Ô¡¶Ö¥Âé½Ö¡·¡°Î÷·½Ð°¶ñÅ®Îס±¾ç¼¯Ð¹Â¶µÄ»áÉÌ £¬ºóÀ©É¢ÖÁDiscord±£ÁôÓ××é £¬µ¼ÖÂÊܱ£»¤ÄÚÈÝÔÚÊý¾Ý¶Ú»ýÕßÉçȺÖнøÒ»²½´«²¼ ¡£ÕâЩÉçȺÒÔ´æµµÈí¼þ¡¢Ã½ÌåµÈ´ó¾ÖΪÖ÷Ìâ £¬³£ÓÎ×ßÓÚ°æÈ¨»ÒÉ«µØ´ø £¬ÍÌÍÂÁ˺Ϸ¨±£ÁôÓëÊý×ÖµÁ°æµÄ½çÏÞ ¡£Ö»¹Ü·ì϶Òѽ¨¸´ £¬µ«Êý¾Ý¶Ú»ýÉçÇøÄÚ¹²ÏíµÄÄÚÈÝÁ¿ÈÔ²»Ã÷È· ¡£


https://www.bleepingcomputer.com/news/security/american-archive-of-public-broadcasting-fixes-bug-exposing-restricted-media/


5. ComicFormºÚ¿Í×éÖ¯Õë¶Ô¶«Å·¶à¹ú·¢ÆðÍøÂç´¹µö¹¥»÷


9ÔÂ22ÈÕ £¬ComicFormºÚ¿Í×éÖ¯4ÔÂÒÔÀ´Õë¶Ô°×¶íÂÞ˹¡¢¹þÈø¿Ë˹̹¼°¶íÂÞ˹µÄ¹¤Òµ¡¢½ðÈÚ¡¢ÓÎÀÀ¡¢ÉúÎï¼¼Êõ¡¢×êÑкÍÒµÎñÁìÓòÌáÒéÍøÂç´¹µö¹¥»÷ ¡£¾ÝÍøÂ簲ȫ¹«Ë¾F6·ÖÎö £¬¹¥»÷Á´ÒÔ¡°ÆÚ´ýÊðÃûÎļþ¡±¡°¸¶¿î·¢Æ±¡±µÈÖ÷ÌâÓʼþΪµö¶ü £¬ÓÕµ¼ÊÕ¼þÈË´ò¿ªÔ̺¬¶ñÒâ¿ÉÖ´ÐÐÎļþµÄRR´æµµ ¡£ÕâЩÓʼþʹÓöíÓï»òÓ¢ÓïÊéд £¬Ô´×Ô.ru¡¢.by¡¢.kzÓòÃû £¬×îÖÕͨ¹ý»ìºÏµÄ.NET¼ÓÔØ·¨Ê½Æô¶¯¡°MechMatrix Pro.dll¡± £¬²¢²¿ÊðFormbook¶ñÒâÈí¼þͶ·ÅÆ÷¡°Montero.dll¡± £¬Í¬Ê±´´½¨´òË㹤×÷¡¢ÅäÖÃMicrosoft DefenderÅųýÏîÒÔÌӱܼì²â ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬¶ñÒâ¶þ½øÔìÎļþÔ̺¬Ö¸ÏòòùòðÏÀµÈÂþ»­GIFµÄTumblrÁ´½Ó £¬Òò¶ø¸Ã×éÖ¯µÃÃû¡°ComicForm¡± ¡£F6×êÑÐÔ±Ö¸³ö £¬ÕâЩGIF½öΪ´úÂë¼Ù×° £¬Î´²Î¼ÓÏÖʵ¹¥»÷ ¡£Õâ´Î¹¥»÷ÓëÇ×¶í×éÖ¯SectorJ149Õë¶Ôº«¹úµÄ¹¥»÷´æÔÚ¹ØÁª ¡£¸Ã×éÖ¯2024Äê11ÔÂÆðÒÔº«¹úÔì×÷Òµ¡¢ÄÜÔ´¡¢°ëµ¼ÌåÐÐҵΪָ±ê £¬Í¨¹ýÓã²æÊ½´¹µöÓʼþ·Ö·¢Lumma Stealer¡¢Remcos RATµÈ¶ñÒâÈí¼þ £¬Æä¹¥»÷´Ó¾­¼ÃÀûÒæ×ªÏòÕþÖÎÖ÷ÕÅ ¡£


https://thehackernews.com/2025/09/comicform-and-sectorj149-hackers-deploy.html


6. LastPass¾¯Ê¾macOSÓû§·À±¸¼Ù×°Ê¢ÐÐÈí¼þµÄ¶ñÒâÈí¼þ¹¥»÷


9ÔÂ22ÈÕ £¬LastPass½üÈÕ°ä²¼ÖÒ¸æ £¬Ö¸³öÕë¶ÔmacOSÓû§µÄÍøÂç¹¥»÷»î¶¯Õýͨ¹ý¼Ù×°³ÉÊ¢ÐÐÈí¼þµÄ¶ñÒâÈí¼þ½øÐд«²¼ ¡£¹¥»÷ÕßÀûÓÃڲƭÐÔGitHub´æ´¢¿â £¬½áºÏËÑË÷ÒýÇæÓÅ»¯£¨SEO£©Õ½Êõ £¬ÔÚGoogleºÍBingÉÏÍÆ¹ãÕâЩÐéαÀûÓà ¡£ÕâЩÀûÓÃÔÚ"ClickFix"¹¥»÷ÖÐͶ·ÅAtomic£¨AMOS£©ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬¸Ã¶ñÒâÈí¼þ×÷Ϊ·þÎñÿÔÂÊÕ·Ñ1000ÃÀÔª £¬½üÆÚÐÂÔöºóÃÅ×é¼þ £¬ÔÊÐí¹¥»÷Õß³ÖÐø¡¢Òñ±ÎµØ½Ó¼ûÊÜϰȾϵͳ ¡£¹¥»÷Õß·ÂÕÕÁ˳¬¹ý100ÖÖÈí¼þ½â¾ö¹æ»® £¬Ô̺¬1Password¡¢Dropbox¡¢Confluence¡¢RobinhoodµÈ³ÛÃû²úÆ· £¬Í¨¹ý¶à¸öÕË»§´´½¨´óÁ¿ºýŪÐÔGitHub´æ´¢¿â £¬ÓÅ»¯ËÑË÷ÅÅÃûÒÔÌÓ±Üɾ³ý ¡£Óû§µã»÷´æ´¢¿âÖеÄ"ÏÂÔØ°´Å¥"»á±»Êèµ¼ÖÁ¸¨ÖúÕ¾µã £¬ÌáÐÑÕ³ÌùºÅÁîµ½ÖÕ¶ËÖ´ÐÐ×°Öà ¡£¸ÃºÅÁîͨ¹ýcurlÒªÇóbase64±àÂëµÄURL £¬½«AMOSÓÐЧ¸ºÔØ£¨install.sh£©ÏÂÔØÖÁ/tmpĿ¼ ¡£´ËÀ๥»÷ÀûÓÃÓû§¶ÔºÅÁîµÄ²»ÏàʶִÐй¥»÷ £¬ÊôÓÚµäÐ͵Ä"ClickFix"¹¥»÷ģʽ ¡£Ö»¹ÜLastPass³ÖÐø¼à¿Ø²¢»ã±¨Ðéα´æ´¢¿â £¬µ«ÐÂÕË»§×Ô¶¯»¯´´½¨µ¼ÖÂÎÊÌâ³ÖÐø´æÔÚ ¡£


https://www.bleepingcomputer.com/news/security/lastpass-fake-password-managers-infect-mac-users-with-malware/