ÒÁÀʺڿÍ×éÖ¯¶ÔÂåÉ¼í¶½»Í¨ÏµÍ³·¢ÆðÍøÂç¹¥»÷

°ä²¼¹¦·ò 2026-05-28
1. ÒÁÀʺڿÍ×éÖ¯¶ÔÂåÉ¼í¶½»Í¨ÏµÍ³·¢ÆðÍøÂç¹¥»÷


5ÔÂ26ÈÕ £¬°²È«×êÑÐÈËÔ±½üÈÕÅû¶ £¬½ñÄê3ÔÂÕë¶ÔÂåɼí¶ÏØ´ó³ÇÊн»Í¨ÔËÊäÖÎÀí¾Ö£¨LACMTA£©µÄÍøÂç¹¥»÷ £¬ÆäÄ»ºóºÚÊÖÊÇÒÁÀÊÖ§³ÖµÄºÚ¿Í×éÖ¯¡£ÒÔÉ«Áвݴ´¹«Ë¾Gambit SecurityÖܶþ°ä²¼µÄÒ»·Ý»ã±¨Ã÷È·Ö¸³ö £¬ÕâЩºÚ¿Í´ÓÊôÓÚÒÁÀʵý±¨ºÍ¹ú¶È°²È«Êý£¨MOIS£©¡£Ò»¸öÃûΪ¡°Ã×Äɲ¼µÄ°¢°Í±ÈÀÕ¡±£¨Ababil of Minab£©µÄ×éÖ¯´ËǰÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü £¬³ÆÆäÇÔÈ¡²¢É¾³ýÁËÂåɼí¶Ïؽ»Í¨ÖÎÀí¾ÖϵͳÖеÄÊý¾Ý¡£È»¶ø £¬Gambit Security¶Ô¸Ã×éÖ¯µÄ×ÔÎÒÃèÊöÌá³öÁËÖÊÒÉ £¬ÒÔΪËûÃDz¢·ÇÏñÐû³ÆµÄÄÇÑùÊÇÒ»¸öȫеġ¢¶ÀÁ¢µÄºÚ¿ÍÐж¯Ö÷Ò弯Ìå¡£Gambit°µÊ¾ £¬ÆäÖ¸¿Ø»ùÓÚ·¨Ö¤Ö¤¾Ý £¬½«ÕâЩºÚ¿ÍÓë´ËǰÒѱ»È·ÈÏÓëÒÁÀÊÓйصÄÍøÂç¹¥»÷»î¶¯ÁªÏµÁËÆðÀ´¡£ÕâЩ֤¾ÝÉæ¼°ÒÔÉ«Áйú¶ÈÍøÂç¾ÖÈ϶¨ÎªÒÁÀʵý±¨×éÖ¯£¨MOIS£©ËùΪµÄ¶ñÒâ»î¶¯¡£´Ë±í £¬Gambit»¹µ÷²éÁ˸Ã×éÖ¯Õë¶ÔÒÔÉ«ÁÓ×¢É³ÌØ°¢À­²®ºÍÍÁ¶úÆä¹«Ë¾µÄÆäËû¹¥»÷ÊÂÎñ £¬½øÒ»²½¼áÈÍÁËÆäÓëÒÁÀʵ±¾Ö¹ØÁªµÄ½áÂÛ¡£ÈôÊÇGambitµÄÆÀ¹ÀÊôʵ £¬ÄÇô¡°Ã×Äɲ¼µÄ°¢°Í±ÈÀÕ¡±½«³ÉΪһϵÁÐΪÒÁÀʵ±¾ÖЧÁ¦µÄÐéαºÚ¿Í×éÖ¯ÖеÄ×îгÉÔ±¡£


https://techcrunch.com/2026/05/26/iranian-hackers-blamed-for-breach-of-los-angeles-transit-system-that-took-weeks-to-recover/


2. KnowledgeDeliver LMSÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓÃ


5ÔÂ26ÈÕ £¬°²È«¹«Ë¾Mandiant½üÈÕÅû¶ £¬ºÚ¿ÍÀûÓÃÔËÐÐKnowledgeDeliver½ø½¨ÖÎÀíϵͳ£¨LMS£©µÄ·þÎñÆ÷ÉÏÒ»¸öÑϳÁÁãÈÕ·ì϶ £¬³É¹¦²¿ÊðÁËGodzilla Web Shell¡£¸Ã·ì϶±»±àºÅΪCVE-2026-5426 £¬ÐÔÖÊÉÏÊÇÒ»¸ö·´ÐòÁл¯ÎÊÌâ £¬Æä±¾Ô­ÔÚÓÚËùÓÐKnowledgeDeliver¿Í»§²¿ÊðµÄWebÃÅ»§ÅäÖÃÖй²ÏíÁËͳһ¸öÓ²±àÂëµÄASP.NET»úеÃÜÔ¿¡£ÓÉÓڸ÷ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓà £¬¹¥»÷ÕßÒ»µ©»ñÈ¡Á˸ûúеÃÜÔ¿ £¬±ã¿É¶Ô¶ñÒâViewStateÓÐÐ§ÔØºÉ½øÐÐÊðÃû £¬´Ó¶øÔÚ²Ù×÷ϵͳ¼¶±ðʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¾ÝMandiantй© £¬ÔçÔÚ2025Ëêĺ £¬¸Ã¹«Ë¾¾ÍÒѶÔKnowledgeDeliver·þÎñÆ÷Ôâ·êµÄ¹¥»÷½øÐÐÁËÓ¦¼±ÏìÓ¦¡£×êÑз¢ÏÖ £¬¸Ã·ì϶×î³õ±»×÷ΪÁãÈÕ·ì϶ʹÓà £¬¹¥»÷ÕßÏòWebƽ̨עÈëÁ˶ñÒâ¾ç±¾¡£ÔÚ2026Äê2ÔÂ24ÈÕ֮ǰ²¿ÊðµÄKnowledgeDeliver×°Öð汾 £¬¾ùÒÀÀµÓÚ¹©¸øÉÌÌṩµÄ³ß¶È»¯web.configÎļþ £¬¸ÃÎļþÖÐÔ̺¬ÁËÓ²±àÂëµÄmachineKeyÖµ £¬¶øÕâЩֵ±¾Ó¦±»ÓÃÓÚ¼ÓÃܺÍÊðÃûÊý¾Ý£¨Ô̺¬ViewState¸ºÔØ£©¡£ÏÖʵÉÏ £¬¸Ãƽ̨ÉϵĶñÒâ´úÂë»á¡°ÓÕʹÓû§ÏÂÔØÐéαװÖ÷¨Ê½¡± £¬½ø¶øµ¼ÖÂÍÆËã»úϰȾCobalt StrikeÐűê £¬Ö²ÈëºóÃÅ¡£


https://www.bleepingcomputer.com/news/security/knowledgedeliver-flaw-exploited-as-a-zero-day-to-install-web-shells/


3. ¶à·½ÁªÊÖ·ÛËé¡°Glassworm¡±½©Ê¬ÍøÂç


5ÔÂ27ÈÕ £¬Ò»³¡Õë¶ÔÈí¼þ¿ª·¢ÕߵĴó¹æÄ£¹©¸øÁ´¹¥»÷Ðж¯¡°Glassworm¡±½üÈÕÔâµ½³ÁÃͽø¹¥¡£ÔÚCrowdStrike¡¢¹È¸èºÍShadowserver»ù½ð»á½áºÏÌáÒéµÄÒ»´ÎЭµ÷Ðж¯ÖÐ £¬¹¥»÷Õß¾«ÐĹ¹½¨µÄ¡¢¾ß±¸¸ß¶È¿¹·ÛËéÄÜÁ¦µÄºÅÁîÓë½ÚÔì»ù´¡ÉèÊ©±»³¹µ×¶Â½Ø¡£¸Ã½©Ê¬ÍøÂç×Ô2025Äê10ÔÂÒÔÀ´³ÖÐø»îÔ¾ £¬×î³õͨ¹ý¶ñÒâµÄOpenVSXºÍMicrosoft VS CodeÀ©´ó·¨Ê½ £¬×¨ÃÅÕë¶Ô¿ª·¢ÕßÖ´ÐмÓÃÜÇ®±ÒÇ®°üºÍµÇ¼ƾ֤ÇÔÈ¡¡£Ëæºó¹¥»÷ÁìÓòÀ©´óÖÁGitHub²Ö¿âºÍnpm°ü £¬½ö½ñÄê3ÔµÄÒ»´Î¹¥»÷¾ÍÓ°ÏìÁ˳¬¹ý400¸öÈí¼þ¹¤¼þ¡£ÔÚ×îÐÂÒ»²¨¹¥»÷ÖÐ £¬¹¥»÷ÕßÔÚOpenVSXÉÏÖ²ÈëÁËÊýÊ®¸ö´¦ÓÚÐÝÃß״̬µÄÀ©´ó·¨Ê½ £¬Ò»µ©¸üбã»á¼¤»î¶ñÒâ×é¼þ¡£GlasswormÖ®ËùÒÔÄܳ־ôæ»î £¬¹Ø¼üÔÚÓÚÆäÔËÓªÕßÉè¼ÆÁËÒ»Ì×¼«¾ßÈÍÐÔµÄC2¼Ü¹¹ £¬½«SolanaÇø¿éÁ´¡¢BitTorrentÉ¢²¼Ê½¹þÏ£±í¡¢¹«¹²ÈÕÀú·þÎñÓ봫ͳ·þÎñÆ÷½áºÏ £¬Ðγɶà²ã¼ä½ÓÑÚ»¤¡£¾ßÌå¶øÑÔ £¬C2·þÎñÆ÷µØÖ·±»±àÂëÔÚSolanaÇø¿éÁ´ÂòÂôµÄ±¸×¢×Ö¶ÎÖÐ £¬ÐγÉÎÞ·¨±»´«Í³¼¿Á©¹Ø¹ØµÄ²»³É´Û¸ÄËÀÐÅÏ䣻ͬʱ £¬¶ñÒâÈí¼þͨ¹ý²éÎÊBitTorrent DHTÍøÂç»ñÈ¡ÓëÓ²±àÂ빫Կ¹ØÁªµÄÅäÖÃÊý¾Ý £¬ÀûÓÃÈ«ÇòÈ¥ÖÐÐÄ»¯µÄµã¶ÔµãÍøÂç½â³ýµ¥µã¹ÊÕÏ£»´Ë±í £¬GoogleÈÕÀúÊÂÎñ±êÌ⻹±»ÓÃ×÷Base64±àÂëµÄC2õè¾¶ËÀÐÅÏä¡£


https://www.bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/


4. WindowsÓëAndroidÔâÁ½´óÒøÐÐľÂí¹¥»÷


5ÔÂ27ÈÕ £¬½üÆÚ £¬À­¶¡ÃÀÖÞºÍÅ·ÖÞÔâ·êÁ½ÆðÒøÐÐľÂí¹¥»÷ £¬±ðÀëÕë¶ÔWindowsºÍAndroidÉ豸¡£GrandoreiroÖØÒª¹¥»÷Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Ä«Î÷¸çµÄÆóÒµ £¬×Ô2016Äê»îÔ¾ÖÁ½ñ £¬ÒÑÄÜÇÔÈ¡45¸ö¹ú¶ÈºÍµØÓòµÄ½ðÈÚ»ú¹¹Æ¾Ö¤¡£Ö»¹Ü°ÍÎ÷µ±¾ÖÔøÊÔͼ·ÛËéÆä»ù´¡ÉèÊ© £¬¸ÃľÂíÈÔÔÚÀ©´ó £¬²¢²ÎÓëCAPTCHAÆ¥µÐ·ÖÎö¡£×îй¥»÷ÀûÓÃDLL²à¼ÓÔØºÍWebRTCÁ÷Á¿°µ²ØÐÐΪ £¬Ã÷È·Õë¶ÔÆÏÌÑÑÀ¶à¼ÒÒøÐС£ÁíÒ»²¨¹¥»÷ͨ¹ý´¹µöÓʼþ´«²¼¼Ù×°³ÉAdobe Reader¸üеĶñÒâÎļþ¡£´Ë±í £¬BTMOB°²×¿Ä¾ÂíÒÔ°ÍÎ÷Óû§ÎªÖ¸±ê £¬¾ß±¸½ØÆÁ¡¢¼üÅ̼ͼ¡¢ÇÔȡƾ֤µÈÖ°ÄÜ £¬ºóÐø°æ±¾¿É²¶»ñÖ§¸¶±¦PINÂë¡£¸ÃľÂíÒÔÿÔÂ700ÃÀÔªÏúÊÛ £¬¸½´øAPK¹¹½¨Æ÷ £¬ÎÞÐè±àÂë¼´¿ÉÌìÉú¶ñÒâÔØºÉ £¬Í¨¹ýÐéÎ±ÍøÕ¾ÓÕµ¼×°Öò¢ÀÄÓø¨ÖúÖ°ÄÜȨÏÞ¡£BTMOBй¶°æ±¾ÒÑÔÚµØÏÂÂÛ̳Á÷´« £¬½µµÍÁË·¸×ïÃż÷¡£


https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html


5. ¡°ÎÞÉùÀÕË÷¼¯ÍÅ¡±³Áµã¹¥»÷ÃÀ¹úÂÉʦÊÂÎñËù


5ÔÂ27ÈÕ £¬ÃÀ¹úÁª¹úµ÷²é¾Ö½üÈÕ°ä²¼ÖÒ¸æ³Æ £¬Ò»¸öÓëÒÑDzɢµÄContiÀÕË÷Èí¼þ¼¯ÍÅÓйØÁªµÄÍøÂçÀÕË÷×éÖ¯¡°ÎÞÉùÀÕË÷¼¯ÍÅ¡±£¨Silent Ransom Group, SRG£©ÕýÔ½À´Ô½¶àµØÒÔÃÀ¹úÂÉʦÊÂÎñËùΪָ±ê £¬Í¨¹ý´¹µöÓʼþ¡¢ÐéαITÖ§³Öµç»° £¬ÉõÖÁµ÷ÅÉÈËÔ±Ç××ÔÉÏÃŵȼ¿Á©ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¸Ã×éÖ¯Ò²±»³ÆÎªLuna Moth¡¢Chatty SpiderºÍUNC3753 £¬×Ô2023ÄêÒÔÀ´³ÖÐøÀûÓÃÉç»á¹¤³Ì¼¿Á©Ô¶³Ì½Ó¼û¹«Ë¾ÏµÍ³²¢Ö´ÐÐÊý¾ÝÇÔÈ¡¡£Ó봫ͳµÄÀÕË÷Èí¼þ·ÖÆç £¬SRGרһÓÚÊý¾ÝÇÔÈ¡ÓëÀÕË÷ £¬¶ø·Ç¼ÓÃÜÊܺ¦ÕßÍøÂç¡£Ò»µ©µÃÊÖ £¬¹¥»÷Õß±ãÍþвÔÚйÃÜÍøÕ¾ÉϹ«¿ªÊý¾Ý»ò½«ÆäÏúÊÛ £¬ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£ÔÚ½ñÄê´º¼¾µÄ×îй¥»÷»î¶¯ÖÐ £¬¹¥»÷Õß¼Ù×°³É¹«Ë¾ÄÚ²¿ITÈËÔ± £¬Í¨¹ýµç»°»ò´¹µöÓʼþÓÕµ¼Ô±¹¤ÁªÏµÐéα·þÎñ̨ £¬½ø¶øËµ·þÔ±¹¤ÊÚÓèÔ¶³Ì×ÀÃæ½Ó¼ûȨÏÞ £¬´Ó¶ø¼±¾çÇÔÈ¡Îļþ¡£Áª¹úµ÷²é¾ÖÖ¸³ö £¬ÈôÊÇÕâЩ¼¿Á©Ê§°Ü £¬¸ÃÍÅ»ïÉõÖÁ¿ÉÄܵ÷ÅÉÈËÔ±Ö±½ÓǰÍùÊܺ¦Õ߰칫ÊÒ £¬Ðû³Æ±ØÒª´´½¨±¸·Ý»ò¾µÏñÉ豸ÒÔ½â¾ö°²È«ÎÊÌâ £¬ËæºóʹÓÃ±í²¿´æ´¢É豸¸´ÔìÊý¾Ý¡£¸Ã×éÖ¯µÄ»î¶¯¼«¾ßÒñ±ÎÐÔ £¬ÒòÆäÑϳÁÒÀÀµÆóÒµIT²¿Ãų£ÓõĺϷ¨Ô¶³ÌÖÎÀíºÍϵͳÖÎÀí¹¤¾ß £¬±»µÁÊý¾Ýͨ³£Í¨¹ý¹È¸èÔÆ¶ËÓ²Å̺Í΢ÈíOneDriveµÈ¿ÉÐÅÔÆÆ½Ì¨´«Êä £¬Ê¹µÃ¶ñÒâ»î¶¯ÓëÕý³£ÒµÎñÔËÓªÄÑÒԷֱ档


https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data


6. CISA´¹Î£ÒªÇóËÄÌìÄÚ½¨¸´LiteSpeed¸ßΣ·ì϶


5ÔÂ27ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£Ö¸Áî £¬ÒªÇóÃÀ¹úÁª¹ú»ú¹¹ÔÚËÄÌìÄÚ½¨¸´Ò»¸ö±»»ý¼«ÀûÓõÄÑϳÁ·ì϶¡£¸Ã·ì϶±àºÅΪCVE-2026-48172 £¬´æÔÚÓÚLiteSpeedµÄcPanelÓû§¶Ë²å¼þÖÐ £¬ÊÇÒ»¸öȨÏÞÌáÉý·ì϶ £¬ÓëRedisÆôÓÃ/½ûÓÃÖ°ÄÜ´¦Öò»µ±ÓйØ £¬¾ßÌåλÓÚlsws.redisAbleº¯ÊýÖС£ÓÉÓÚȨÏÞ·ÖÅäÃýÎó £¬Î´ÊÚȨµÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÒÔrootȨÏÞÖ´ÐÐËÁÒâ¾ç±¾ £¬¶Ô·þÎñÆ÷×é³ÉÑϳÁÍþв¡£LiteSpeedÒÑÓÚÖÜËİ䲼´¹Î£°²È«¸üР£¬Ç¿ÁÒ½¨ÒéÓû§½«cPanelÓû§¶Ë²å¼þ£¨ÓëWHM²å¼þ°ó¸¿£©¸üÐÂÖÁ×îа汾 £¬ÊÜÓ°Ïì°æ±¾¸²¸Çv2.3ÖÁv2.4.4¡£LiteSpeedÍŶÓÌṩÁ˼ì²âºÅÁî £¬½¨ÒéÓû§²é³­·þÎñÆ÷ÈÕÖ¾ÖÐÊÇ·ñ´æÔÚ¿ÉÒÉIPµØÖ· £¬²¢ÆÀ¹À¿ÉÄÜÔì³ÉµÄÇÖº¦¡£CISAÓÚÖܶþ½«¸Ã·ì϶ÁÐÈë¡°ÒÑÔâ¹¥»÷ÀûÓõķì϶Ŀ¼¡± £¬²¢Æ¾¾ÝÔ¼ÊøÐÔ²Ù×÷Ö¸ÁîBOD 22-01 £¬ÒªÇóÁª¹ú»ú¹¹ÔÚ5ÔÂ29ÈÕÎçҹǰʵÏÖ½¨²¹¡£


https://www.bleepingcomputer.com/news/security/cisa-gives-feds-4-days-to-patch-actively-exploited-cpanel-plugin-flaw/