ºÚ¿Í¶µÏúÑÇÃÀÄáÑǵ±¾Ö800ÍòÌõ¹Ù·½¼Í¼

°ä²¼¹¦·ò 2026-01-14

1. ºÚ¿Í¶µÏúÑÇÃÀÄáÑǵ±¾Ö800ÍòÌõ¹Ù·½¼Í¼


1ÔÂ13ÈÕ £¬½üÈÕ £¬ºÚ¿Í¡°dk0m¡±ÔÚµØÏÂÂÛ̳ÒÔ2500ÃÀÔª±ê¼Û¶µÏú¾Ý³ÆÀ´×ÔÑÇÃÀÄáÑǵ±¾ÖµÄº£Á¿Êý¾Ý £¬Ô̺¬Ô¼800ÍòÌõ¹Ù·½Í¨Öª¼Í¼ £¬Éæ¼°¾¯·½¡¢Ë¾·¨»ú¹¹ÎÄÊé¼°µç×ÓÃñÊÂËßËÏÆ½Ì¨ÐÅÏ¢¡£ÑÇÃÀÄáÑǹ«¹²¹ØÏµÓëÐÅÏ¢ÖÐÐÄÖÜÁù°ä²¼ÉêÃ÷ £¬·ñ¶¨µ±¾ÖÓʼþϵͳÔâÈëÇÖ £¬µ«³õ²½ºË²éÏÔʾÊý¾Ý¿ÉÄÜÔ´×Ôµç×ÓÃñÊÂËßËÏÆ½Ì¨ £¬²¢ÒÑÆô¶¯ÄÚ²¿µ÷²éÒÔÈ·ÈÏÊý¾ÝÆðÔ´¼°½Ó¼û·½Ê½¡£·Çµ±¾Ö×éÖ¯ÑÇÃÀÄáÑÇÍøÂ簲ȫÖÐÐÄÖ¸³ö £¬¡°dk0m¡±ÊǵØÏÂÂÛ̳³ôÃûÔ¶ÑïµÄÐÅÏ¢ÖÐÑëÉÌ £¬×Ô2024ÄêÆð±ãÓÐÊÛÂô¶à¹úµÐÔÖÊý¾ÝµÄǰ¿Æ £¬Ô̺¬°¢¸ùÍ¢¡¢ÎÚ¿ËÀ¼¡¢°ÍÎ÷µÈ²¿Î¯Êý¾Ý¡£¸ÃºÚ¿Íͨ³£Í¨¹ýÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬´ÓÊÜϰȾÉ豸ÖÐÇÔÈ¡ÕË»§Æ¾Ö¤ºÍ»á»°Cookie £¬½ø¶ø»ñÈ¡Ãô¸Ðµ±¾ÖÃÅ»§ÍøÕ¾µÄ½Ó¼ûȨÏÞ £¬²¢½«ÇÔÈ¡Êý¾Ý´ò°üתÊÛ¡£Îª¼ÓÇ¿¿ÉÐÅ¶È £¬Æä³£¶Ô±í·ÖÏíÊý¾ÝÑù±¾»òÊý¾Ý¿â½á¹¹¡£2024Äê8ÔÂÓйؽØÍ¼ÏÔʾ £¬¸ÃºÚ¿Í¿ÉÄÜÒÑÌáǰ»ñÈ¡ÑÇÃÀÄáÑǵÐÔÖÊý¾Ý £¬Õâ´Î¶µÏúÐÐΪ»òΪ±äÏÖÔçǰÇÔÈ¡×ÊÁÏ¡£


https://therecord.media/armenia-probes-alleged-sale-government-records


2. ºÚ¿ÍÐû³Æ°ÑÎÕÔ̺¬7800Íò¸öÎļþµÄDiscordÊý¾Ý¼¯


1ÔÂ12ÈÕ £¬½üÈÕ £¬ÍþвÐÐΪÕßHawkSecÔÚÆäDiscord·þÎñÆ÷¡°Hello Hawks Community¡±ÖÐÐû³Æ £¬ÕýÅÄÂôÒ»¸öÔ̺¬78,541,207¸öÎļþµÄDiscordÊý¾Ý¼¯ £¬¸ÃÊý¾Ý¼¯°´ÐÂÎÅ¡¢ÓïÒô»á»°¡¢²Ù×÷ºÍ·þÎñÆ÷·ÖÀàÕû¶Ù £¬Ô´ÓÚÒ»¸öÒѰγýµÄ¿ªÔ´µý±¨ÏîÄ¿¡£HawkSecͨ¹ýÖ¸¶¨Çþ·ԼÇëDZÔÚÂò¼Òѯ¼Û»ñÈ¡Ñù±¾ £¬µ«¹«¿ªÇþ·δй©¾ßÌå¼ÛÖµ¡£Õâ´ÎÊÂÎñ²¢·Ç¹ÂÀý¡£2025Äê £¬ÍøÂç·¸×ïÂÛÌ³Ôø³öÏÖÏúÊÛ´Ó½ü1000¸ö¹«¹²·þÎñÆ÷ץȡµÄ3.48ÒÚÌõÐÂÎŵÄÇåµ¥ £»×êÑÐÈËÔ±Ò²Ôø°ä²¼¡°Discord Unveiled¡±Êý¾Ý¼¯ £¬Ô̺¬Í¨¹ýAPI´Ó3,167¸ö·þÎñÆ÷»ñÈ¡µÄ20ÒÚÌõÐÂÎÅ¡£±¾´Î7800ÍòÎļþµÄÊý¾Ý¼¯ÏÔʾ £¬Êý¾ÝץȡÁìÓò¿ÉÄÜÕë¶ÔDiscord¡°Ë÷Çó¡±ÁбíÖеĹ«¹²·þÎñÆ÷¡£Ö»¹Üδ¾­Ö¤ÊµÔ̺¬¸öÈËÊý¾Ý £¬µ«¾ÛºÏµÄ¹«¿ªÈÕÖ¾ÔÚ½»²æÒýÓÃÆäËûÆðԴʱ £¬´æÔÚÓû§³ÁÐÂʶ´ËÍâ·çÏÕ¡£Discord¶ÔÖÅÒÔΪ¹«¿ªÆµÂ·ÊÇ×ÔÓɽӼûµÄ £¬ÒÔ´Ë·Ö±æÊý¾ÝץȡÓëÊý¾Ýй¶¡£


https://cybersecuritynews.com/discord-breach-claim/


3. TargetÔ±¹¤Ö¤ÊµÐ¹Â¶µÄÔ´´úÂëÊôʵ


1ÔÂ13ÈÕ £¬½üÈÕ £¬ºÚ¿ÍÔÚGiteaƽ̨°ä²¼ÒÉËÆTargetÄÚ²¿Ô´´úÂëÑù±¾²¢Ðû³ÆÏúÊÛ £¬Òý·¢°²È«¹Ø×¢¡£¶àÃûÏÖÈμ°Ç°ÈÎTargetÔ±¹¤Ëæºó֤ʵ £¬Ð¹Â¶×ʲÂÖеÄϵͳÃû³Æ£¨Èç¡°BigRED¡±¡°TAP [Provisioning]¡±£©¡¢¼¼ÊõÕ»£¨ÈçHadoopÊý¾Ý¼¯¡¢»ùÓÚVelaµÄ¶¨ÔìCI/CDƽ̨¡¢JFrog Artifactory£©¼°×¨ÓÐÏîÄ¿´úºÅ£¨Èç¡°blossom ID¡±£©¾ùÓëÕæÊµÄÚ²¿ÏµÍ³ÆëȫƥÅä £¬URL½á¹¹¼°Ô±¹¤ÐÕÃûµÈϸ½ÚÒàÑéÖ¤ÁË×ÊÁϵÄÕæÊµÐÔ £¬ÅųýαÔì¿ÉÄÜ¡£ÎªÓ¦¶ÔDZÔÚ·çÏÕ £¬Target24Ó×ʱÄÚ´¹Î£ÍƳö¡°¼Ó¿ì¡±°²È«µ÷»»£º×Ô2026Äê1ÔÂ9ÈÕÆð £¬½Ó¼ûÆóÒµGit·þÎñÆ÷£¨git.target.com£©Ðèͨ¹ýTargetÄÚ²¿ÍøÂç»òVPN £¬´Ëǰ¸Ã·þÎñÆ÷¿Éͨ¹ý¹«¹²»¥ÁªÍø½Ó¼û¡£´Ë¾ÙÖ¼ÔڹرÕרÓÐÔ´´úÂë»·¾³ £¬ÓëGitHub.comµÄ½Ó¼ûÖÎÀí·½Ê½Î¬³ÖÒ»Ö¡£¹¥»÷ÕßÐû³ÆÆëÈ«Êý¾Ý¼¯Ô¼860GB¡£°²È«×êÑÐÔ±½öÉó²éÁË14MBµÄÑù±¾£¨º¬Îå¸ö´úÂë¿â£© £¬µ«Ô±¹¤°µÊ¾¼´±ã¸Ã×Ó¼¯Ò²Ô̺¬ÕæÊµÄÚ²¿´úÂë £¬Òý·¢¶Ô¸ü´óÊý¾Ý¼¯ÁìÓò¼°Ãô¸ÐÐÔµÄÓÇÓô¡£


https://www.bleepingcomputer.com/news/security/target-employees-confirm-leaked-source-code-is-authentic/


4. BettermentÔâºÚ¿ÍÈëÇÖÒý·¢¼ÓÃÜÇ®±ÒȦÌ×


1ÔÂ13ÈÕ £¬ÃÀ¹úÖÇÄÜͶ¹ËÏÈÇýBetterment½üÈÕ֤ʵ £¬ºÚ¿Íͨ¹ýÆäµÚÈý·½ÓªÏúƽ̨Ïò²¿Ãſͻ§·¢ËÍÐéα¼ÓÃÜÇ®±Ò¼Î½±È¦Ì×Óʼþ £¬ÓÕÆ­Óû§²Î¼Ó"´æ¿î·­Èý±¶"´ÙÏú»î¶¯¡£¸ÃÊÂÎñÉæ¼°³¬¹ý°ÙÍò¿Í»§¼°650ÒÚÃÀÔª×ʲúÖÎÀí¹æÄ£ £¬Òý¿¯ÐÐÒµ¸ß¶È¹Ø×¢¡£1ÔÂ9ÈÕ £¬¹¥»÷ÕßÀûÓÃBettermentÓÃÓÚÓªÏú»î¶¯µÄµÚÈý·½Èí¼þ·ì϶ £¬ÒԺϷ¨×ÓÓòÃû"mailto:support@e.betterment.com"·¢ËÍÖ÷ÌâΪ"ÎÒÃǽ«Ê¹ÄúµÄ¼ÓÃÜÇ®±Ò·­Èý±¶£¡£¨ÏÞʱ£©"µÄڲƭÓʼþ¡£ÓʼþÐû³ÆÔÚ"2025Äê1ÔÂ9ÈÕ20:45ǰ"´æÈë±ÈÌØ±Ò»òÒÔÌ«·»¿É»ñÈý±¶»Ø±¨ £¬²¢¸½ÓнӹÜÉÏÏÞ75ÍòÃÀÔªµÄ±ÈÌØ±ÒºÍÒÔÌ«·»Ç®°üµØÖ·¡£BettermentËæºó´¹Î£°ä²¼ÉêÃ÷ £¬Ç¿µ÷ÆäÖ÷Ìâ¼¼Êõ»ù´¡ÉèʩδÊÜÓ°Ïì £¬¿Í»§ÕË»§Î´±»½Ó¼û £¬µ«²¿Ãſͻ§È«Ãû¡¢ÓÊÏä¡¢ÎïÀíµØÖ·¡¢µç»°¼°µ®ÉúÈÕÆÚµÈÃô¸ÐÐÅÏ¢Òòϵͳ±»ÈëÇÖ¶øÐ¹Â¶¡£BettermentÔÚ1ÔÂ10ÈÕºóÐø¹µÍ¨ÖÐÈ·ÈÏ £¬Î´¾­ÊÚȨ½Ó¼ûÒѱ»¶Ï¸ù £¬ÎÞÖ¤¾ÝÅú×¢¿Í»§ÕË»§±»½Ó¼û¡£È»¶ø £¬¹«Ë¾ËæºóÔâ·êÀÕË÷¹¥»÷¼°É¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷ £¬µ¼Ö²¿ÃÅÓû§µÇ¼×ÀÃæºÍÒÆ¶¯ÀûÓÃʱÓöµ½ÎÊÌâ¡£


https://www.bleepingcomputer.com/news/security/betterment-confirms-data-breach-after-wave-of-crypto-scam-emails/


5. ±ÈÀûʱAZ MonicaÒ½ÔºÔâÍøÂç¹¥»÷Ö³Á´ó·þÎñÖжÏ


1ÔÂ13ÈÕ £¬±ÈÀûʱ×ÛºÏÒ½ÔºÍøÂçAZ MonicaÒòÍøÂç¹¥»÷±»ÆÈ¹Ø¹ØËùÓзþÎñÆ÷ £¬µ¼Ö°²ÌØÎÀÆÕºÍµÂ¶ûÚ«Á½´¦ÔºÇøµÄÒ½ÁÆ·þÎñÑϳÁÅö±Ú¡£¸ÃÔº×÷Ϊ±¾µØ³ÁÒªµÄÒ½ÁÆÌṩ·½ £¬º­¸Ç¼¹Øï¡¢ÃÅÕPר¿Æ·þÎñ £¬Õâ´ÎÊÂÎñÒý·¢¿í·º¹Ø×¢¡£ÔçÉÏ6:32 £¬Ò½Ôº¼ì²âµ½ÏµÍ³Òì³£ºó £¬×Ô¶¯¶Â½ØËùÓзþÎñÆ÷ÏνÓ¡£×÷ΪԤ·À´ëÊ© £¬µ±ÈÕËùÓÐÔ¤Ô¼ÊÖÊõ±»È¡µÞ £¬»¼ÕßÒÑ»ñ֪ͨ¡£¼¹Øï¿ÆËäά³ÖÓÐÏÞ½ÓÕïÄÜÁ¦ £¬µ«¾È»¤³µÒÑÖÕ³¡Ïò¸Ã¿ÆÊäËͲ¡ÈË £¬½¨Òé¾ÓÃñÓÅÏÈÁªÏµ¼ÒÍ¥Ò½Éú¡¢Ò¹¼äÕïËù»òÆäËû¼¹Øï»ú¹¹¡£·Ç´¹Î£»áÕïÒòµç×Ó²¡ÀúÎÞ·¨½Ó¼û¶øÍƳ٠£¬ÃÅÕïÕ÷ѯÔòÕý³£½øÐС£ÔÚºìÊ®×Ö»áЭÖúÏ £¬Ò½ÔºÍ¨¹ý¾È»¤³µ°²È«×ªÒÆÆßÃûΣ³Á²¡ÈËÖÁÆäËû»ú¹¹ £¬ÆäÓ໼ÕßÈÔÔÚÔºÄÚ½ÓÊÜÒ½ÖΡ£Ôº·½Ç¿µ÷ £¬»¼Õß°²È«ÓëÒ½ÁÆÂ½ÐøÐÔΪÊ×Òª¹¤×÷ £¬½«³ÖÐø¼à²âÊÂ̬²¢¸üÐÂÐÅÏ¢¡£


https://securityaffairs.com/186882/cyber-crime/az-monica-hospital-in-belgium-shuts-down-servers-after-cyberattack.html


6. ÎÚ¹ú·À¾üÔâ¶íºÚ¿Í´È±¯´¹µö¹¥»÷Ö²ÈëPluggyApeºóÃÅ


1ÔÂ13ÈÕ £¬ÎÚ¿ËÀ¼¹ú·À¾ü¹ÙÔ±2025Äê10ÔÂÖÁ12Ô³ÉΪ¶íÂÞ˹²¼¾°Íþв×éÖ¯¡°Ðé¿Õ±©Ñ©¡±Óë¡°Ï´ÒÂÐÜ¡±ÌáÒéµÄ¶¨ÏòÍøÂç¹¥»÷Ö¸±ê¡£¾ÝÎÚ¿ËÀ¼CERT-UA»ã±¨ £¬¹¥»÷Õßͨ¹ýSignal/WhatsApp·¢ËͼÙ×°³É´È±¯»î¶¯µÄ´¹µöÐÂÎÅ £¬ÓÕµ¼Ö¸±ê½Ó¼ûÐéα´È±¯ÍøÕ¾²¢ÏÂÔØº¬ÃÜÂë± £»¤µÄѹËõÎļþ¡£ÕâЩÎļþʵΪ¶ñÒâ¿ÉÖ´Ðз¨Ê½£¨Èç.docx.pif£© £¬ÄÚº¬PluggyApeºóÃŶñÒâÈí¼þ £¬¸ÃÈí¼þÓÉPyInstaller´ò°ü £¬¿É·ÖÎöÖ÷»úÐÅÏ¢¡¢·¢ËÍΨһ±êʶ·ûÖÁ¹¥»÷Õß £¬²¢Í¨¹ýÅú¸ÄWindows×¢²á±íʵÏÖÓÆ¾Ã»¯¡£¹¥»÷Á´ÏÔʾ £¬ÔçÆÚ°æ±¾Ê¹ÓÃ.pdf.exeÀ©´óÃû×÷Ϊ¼ÓÔØÆ÷ £¬2025Äê12ÔÂÆðÉý¼¶ÎªPIFÌåʽ¼°PluggyApe v2°æ±¾ £¬¾ß±¸¸üÇ¿µÄ»ìºÏÄÜÁ¦¡¢»ùÓÚMQTTµÄͨѶ·½Ê½¼°·´·ÖÎö²é³­¡£ÆäC2µØÖ·´Órentry.co¡¢pastebin.comµÈ±í²¿Æ½Ì¨ÒÔbase64±àÂ붯̬»ñÈ¡ £¬Ô¤·ÀÓ²±àÂë·ì϶¡£ÖµÍ×ÌùÐĵÄÊÇ £¬¹¥»÷Õß³£ÀûÓñ»µÁµÄÎÚ¿ËÀ¼µçÐÅÔËÓªÉÌÕË»§»òµç»°ºÅÂë £¬½áºÏ¶ÔÖ¸±êÓ×ÎÒ¼°×éÖ¯µÄÉî¶ÈÏàʶ £¬Í¨¹ýÎÚ¿ËÀ¼ÓïÒôƵ/ÊÓÆµÍ¨Ñ¶¼ÓÇ¿¹¥»÷¿ÉÐÅ¶È £¬Ê¹Òƶ¯É豸³ÉÎªÖØÒªÉøÈëÖ¸±ê £¬´ËÀàÉ豸Òò·À»¤ÓÄ΢¸üÒ×±»¹¥ÆÆ¡£


https://www.bleepingcomputer.com/news/security/ukraines-army-targeted-in-new-charity-themed-malware-campaign/