NucleiÎó²îɨÃè³ÌÐòÆØ³ö¸ßΣÇå¾²Îó²î£¬£¬£¬£¬£¬¿ÉÖ¶ñÒâ´úÂëÖ´ÐÐ
Ðû²¼Ê±¼ä 2025-01-071. NucleiÎó²îɨÃè³ÌÐòÆØ³ö¸ßΣÇå¾²Îó²î£¬£¬£¬£¬£¬¿ÉÖ¶ñÒâ´úÂëÖ´ÐÐ
1ÔÂ5ÈÕ£¬£¬£¬£¬£¬¿ªÔ´Îó²îɨÃ蹤¾ß Nuclei£¨ÓÉ ProjectDiscovery ¿ª·¢£©±£´æÒ»¸ö±àºÅΪ CVE-2024-43405 µÄ¸ßÑÏÖØÐÔÇå¾²Îó²î£¬£¬£¬£¬£¬CVSS ÆÀ·ÖΪ 7.4¡£¡£¸ÃÎó²îÓÉ Wiz ¹¤³ÌÍŶӷ¢Ã÷£¬£¬£¬£¬£¬Ô´ÓÚ»»Ðд¦Öóͷ£²î±ðºÍ¶àÖØÊðÃû´¦Öóͷ£»úÖÆ£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÊðÃû¼ì²é²¢ÔÚÄ£°åÖÐ×¢Èë¶ñÒâÄÚÈÝ£¬£¬£¬£¬£¬½ø¶øÖ´ÐжñÒâ´úÂë¡£¡£´ËÎó²îÓ°Ïì Nuclei 3.0.0 ¼°ÒÔÉϰ汾£¬£¬£¬£¬£¬Ö±ÖÁ v3.3.2 °æ±¾²Å»ñµÃ½â¾ö¡£¡£Nuclei ÔÚ GitHub ÉÏÓµÓÐ 21,000+ ÐDZêºÍÁè¼Ý 210 Íò´ÎÏÂÔØ£¬£¬£¬£¬£¬¶ÔÇå¾²ÉçÇøÖÁ¹ØÖ÷Òª¡£¡£Nuclei ÒÔÆä»ùÓÚ YAML µÄÎÞаģ°åÖø³Æ£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖÐÒé°üÀ¨ HTTP¡¢TCP¡¢DNS¡¢TLS ºÍ Code£¬£¬£¬£¬£¬ÆäÖÐ Code ÐÒéÔÊÐíÔÚÖ÷»úÉÏÖ´ÐÐÍⲿ´úÂ룬£¬£¬£¬£¬µ«Ò²¿ÉÄÜ´øÀ´ÑÏÖØÎ£º¦¡£¡£Îó²îÔ´ÓÚʹÓÃÕýÔò±í´ïʽºÍ YAML ÆÊÎöÆ÷¾ÙÐÐÊðÃûÑé֤ʱµÄ·×ÆçÖ£¬£¬£¬£¬£¬ÒÔ¼°¡°First-Signature Trust¡±ºÍÊðÃûÒÆ³ýµÄ·×ÆçÖ´¦Öóͷ££¬£¬£¬£¬£¬ÕâЩÈõµãÔÊÐí¹¥»÷Õß×¢ÈëδÂÄÀúÖ¤µÄ¶ñÒâÄÚÈÝ¡£¡£µ±×éÖ¯ÔËÐÐδ¾Êʵ±ÑéÖ¤»ò¸ôÀëµÄ²»ÊÜÐÅÈλòÉçÇøÐ¢Ë³µÄÄ£°åʱ£¬£¬£¬£¬£¬ÓÈÆäÈÝÒ×Êܵ½¹¥»÷£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂí§ÒâÏÂÁîÖ´ÐС¢Êý¾Ýй¶»òϵͳÈëÇÖ¡£¡£
https://securityaffairs.com/172692/security/nuclei-flaw-execute-malicious-code.html
2. жñÒâÈí¼þPLAYFULGHOST±»·¢Ã÷£¬£¬£¬£¬£¬¾ßÓÐÆÕ±éÐÅÏ¢ÍøÂ繦Ч
1ÔÂ4ÈÕ£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪPLAYFULGHOSTµÄжñÒâÈí¼þ£¬£¬£¬£¬£¬Ëü¾ß±¸¶àÖÖÐÅÏ¢ÍøÂ繦Ч£¬£¬£¬£¬£¬Èç¼üÅ̼ͼ¡¢ÆÁÄ»²¶»ñ¡¢ÒôƵ²¶»ñ¡¢Ô¶³ÌshellÒÔ¼°Îļþ´«Êä/Ö´ÐС£¡£¸Ã¶ñÒâÈí¼þÓëÒÑÖªÔ¶³ÌÖÎÀí¹¤¾ßGh0st RATÔÚ¹¦Ð§Éϱ£´æÖصþ¡£¡£PLAYFULGHOSTͨ¹ýÍøÂç´¹ÂÚµç×ÓÓʼþ»òËÑË÷ÒýÇæÓÅ»¯Í¶¶¾ÊÖÒÕ·Ö·¢£¬£¬£¬£¬£¬ÓÕÆÊܺ¦Õß·¿ªÎ±×°³ÉͼÏñÎļþµÄ¶ñÒâRAR´æµµ»òÏÂÔØ´øÓжñÒâÈí¼þµÄLetsVPN×°ÖóÌÐò¡£¡£¸Ã¶ñÒâÈí¼þʹÓÃDLLËÑË÷˳ÐòÐ®ÖÆºÍ²àÔØµÈÒªÁìÆô¶¯¶ñÒâDLL£¬£¬£¬£¬£¬²¢ÔÚÖ÷»úÉÏÉèÖó¤ÆÚÐÔ£¬£¬£¬£¬£¬ÍøÂç´ó×ÚÊý¾Ý¡£¡£±ðµÄ£¬£¬£¬£¬£¬PLAYFULGHOST»¹ÄÜͶ·Å¸ü¶àÓÐÓÃÔØºÉ¡¢×èÖ¹Êó±êºÍ¼üÅÌÊäÈ롢ɨ³ýWindowsÊÂÎñÈÕÖ¾µÈ£¬£¬£¬£¬£¬²¢ÓëÆäËû¹¤¾ßÈçMimikatzºÍrootkitÒ»ÆðʹÓᣡ£Õë¶ÔËѹ·¡¢QQºÍ360Çå¾²µÈÓ¦ÓóÌÐòÒÔ¼°Ê¹ÓÃLetsVPNÓÕ¶ü£¬£¬£¬£¬£¬ÕâЩѬȾ¿ÉÄÜÕë¶ÔµÄÊǽ²ÖÐÎĵÄWindowsÓû§¡£¡£ÀàËÆµÄ»î¶¯Ò²ÔøÔÚ2024Äê7ÔÂÓɼÓÄôóÍøÂçÇå¾²¹©Ó¦ÉÌeSentireÅû¶£¬£¬£¬£¬£¬Ê¹ÓÃGoogle ChromeµÄÐéαװÖóÌÐòÈö²¥Gh0st RAT¡£¡£
https://thehackernews.com/2025/01/playfulghost-delivered-via-phishing-and.html
3. PhishWP£º¶íÂÞË¹ÍøÂç·¸·¨·Ö×ÓµÄÐÂÐÍWordPress´¹ÂÚ²å¼þÍþв
1ÔÂ6ÈÕ£¬£¬£¬£¬£¬¶íÂÞË¹ÍøÂç·¸·¨·Ö×Ó¿ª·¢ÁËÒ»¿îÃûΪPhishWPµÄ¶ñÒâWordPress²å¼þ£¬£¬£¬£¬£¬¸Ã²å¼þͨ¹ý½¨Éè¸ß·ÂÕæµÄÐéα֧¸¶Ò³ÃæÀ´ÇÔÈ¡Óû§µÄÐÅÓÿ¨ÐÅÏ¢¡¢CVVÇå¾²ÂëºÍ3DSÒ»´ÎÐÔÃÜÂ루OTP£©µÈÃô¸ÐÊý¾Ý¡£¡£ÕâÐ©Ò³ÃæÄ£ÄâÕýµ±Ö§¸¶Ð§ÀÍÈçStripe£¬£¬£¬£¬£¬ÓÕÆÓû§ÊäÈëСÎÒ˽¼ÒÐÅÏ¢¡£¡£PhishWP²»µ«¾ß±¸¸ß¶È¿É¶¨ÖƵĽáÕËÒ³Ãæ£¬£¬£¬£¬£¬»¹¼¯³ÉÁËä¯ÀÀÆ÷ÆÊÎö¹¦Ð§ºÍ×Ô¶¯»Ø¸´µç×ÓÓʼþ£¬£¬£¬£¬£¬ÒÔÔöÇ¿ÆäÓÕÆÐÔºÍÈÆ¹ýÇå¾²ÑéÖ¤µÄÄÜÁ¦¡£¡£¸üΪÏȽøµÄÊÇ£¬£¬£¬£¬£¬¸Ã²å¼þÄܹ»ÊµÊ±Í¨¹ýTelegram½«ÇÔÈ¡µÄÐÅÏ¢´«Ê䏸¹¥»÷Õߣ¬£¬£¬£¬£¬±ãÓÚËûÃÇÔÚ°µÍøÉÏÁ¬Ã¦¾ÙÐÐδ¾ÊÚȨµÄÉúÒâ»òÏúÊÛ¡£¡£PhishWPµÄ¶àÓïÑÔÖ§³ÖºÍ»ìÏý¹¦Ð§Ê¹µÃ¹¥»÷ÕßÄÜÔÚÈ«Çò¹æÄ£ÄÚÌᳫÕë¶ÔÐÔµÄÍøÂç´¹Âڻ£¬£¬£¬£¬£¬Ôì³ÉÖØ´ó²ÆÎñËðʧºÍСÎÒ˽¼ÒÊý¾Ýй¶¡£¡£ÎªÁËÓ¦¶ÔÕâÒ»Íþв£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾SlashNext±Þ²ßÓû§½ÓÄÉÆð¾¢µÄÍøÂçÇå¾²²½·¥£¬£¬£¬£¬£¬ÈçʹÓÃÍøÂç´¹ÂÚ±£»£»£»¤¹¤¾ß£¬£¬£¬£¬£¬¼á³Ö¸ß¶ÈСÐÄ£¬£¬£¬£¬£¬ÒÔÓÐÓõÖÓù´ËÀàÖØ´ó¹¥»÷¡£¡£
https://hackread.com/phishwp-plugin-russian-hacker-forum-phishing-sites/
4. Moxa·¢³ö¸ßΣÎó²îÖÒÑÔ£¬£¬£¬£¬£¬Ó°Ïì¶à¿î·ÓÉÆ÷ºÍÍøÂçÇå¾²×°±¸
1ÔÂ6ÈÕ£¬£¬£¬£¬£¬¹¤ÒµÍøÂçºÍͨѶ¹©Ó¦ÉÌMoxa·¢³ö½ôÆÈÖÒÑÔ£¬£¬£¬£¬£¬Ö¸³öÆä·äÎÑ·ÓÉÆ÷¡¢Ç徲·ÓÉÆ÷ºÍÍøÂçÇå¾²×°±¸µÄ¶à¸öÐͺű£´æ¸ßΣÎó²î¡£¡£ÕâЩÎó²î°üÀ¨CVE-2024-9138ºÍCVE-2024-9140£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß»ñÈ¡rootȨÏÞ²¢Ö´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬µ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£Moxa×°±¸ÆÕ±éÓ¦ÓÃÓÚ½»Í¨ÔËÊä¡¢¹«ÓÃÊÂÒµ¡¢ÄÜÔ´ºÍµçÐÅÁìÓòµÄ¹¤Òµ×Ô¶¯»¯ºÍ¿ØÖÆÏµÍ³ÇéÐΡ£¡£ÊÜÓ°ÏìµÄ×°±¸°üÀ¨EDR-8010ϵÁС¢EDR-G9004ϵÁС¢EDR-G9010ϵÁС¢EDF-G1002-BPϵÁС¢NAT-102ϵÁС¢OnCell G4302-LTE4ϵÁкÍTN-4900ϵÁеȣ¬£¬£¬£¬£¬ÏêϸÊÜÓ°ÏìµÄÊÇÕâЩϵÁеÄijЩ¹Ì¼þ°æ±¾¡£¡£MoxaÒÑÐû²¼¹Ì¼þ¸üÐÂÒÔÐÞ¸´ÕâЩÎó²î£¬£¬£¬£¬£¬²¢Ç¿ÁÒ½¨ÒéÓû§Á¬Ã¦Éý¼¶ÒÔ×èֹDZÔÚΣº¦¡£¡£¹ØÓÚNAT-102ϵÁУ¬£¬£¬£¬£¬ÏÖÔÚûÓпÉÓò¹¶¡£¬£¬£¬£¬£¬½¨Òé½ÓÄÉ»º½â²½·¥¡£¡£Moxa»¹½¨ÒéÏÞ֯װ±¸ÍøÂç̻¶ºÍSSH»á¼û£¬£¬£¬£¬£¬²¢Ê¹Ó÷À»ðǽ¡¢IDS»òIPSÀ´¼à¿ØºÍ×èÖ¹¹¥»÷ʵÑé¡£¡£Í¬Ê±£¬£¬£¬£¬£¬Í¨¸æÖ¸³öMRC-1002ϵÁС¢TN-5900ϵÁкÍOnCell 3120-LTE-1ϵÁÐ×°±¸²»ÊÜÕâÁ½¸öÎó²îÓ°Ïì¡£¡£
https://www.bleepingcomputer.com/news/security/vulnerable-moxa-devices-expose-industrial-networks-to-attacks/
5. ¶íÂÞ˹½«´ó¹æÄ£»£»£»¥ÁªÍøÖÐÖ¹¹é×ïÓÚµçÐÅÍøÂçʹÊ
1ÔÂ6ÈÕ£¬£¬£¬£¬£¬¶íÂÞ˹»¥ÁªÍøî¿Ïµ»ú¹¹±¨¸æ³Æ£¬£¬£¬£¬£¬ÓÉÓÚµçÐÅÔËÓªÉÌÖ÷ÍøÂç¹ÊÕÏ£¬£¬£¬£¬£¬µ¼Ö¸ùú¶àÏîÔÚÏßЧÀÍÔâÓö´ó¹æÄ£ÖÐÖ¹£¬£¬£¬£¬£¬°üÀ¨ÈÈÃÅÔÚÏ߯½Ì¨¹È¸è¡¢Yandex¡¢Rutube¡¢VKontakteºÍDiscord£¬£¬£¬£¬£¬ÒÔ¼°ÍâµØÒøÐкÍÒÆ¶¯ÔËÓªÉÌMTSµÈЧÀÍ¡£¡£¾Ý»¥ÁªÍø¼à¿ØÐ§ÀÍDowndetectorµÄÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬´ó´ó¶¼Í¶ËßÀ´×ÔĪ˹¿Æ£¬£¬£¬£¬£¬Éæ¼°MTSÌṩµÄЧÀÍ£¬£¬£¬£¬£¬µ«MTSδ¾ÍÖÐÖ¹Ôµ¹ÊÔÓɽÒÏþ̸ÂÛ¡£¡£Ö»¹Ü¸ÃÊÂÎñÒÑ»ñµÃ½â¾öÇÒЧÀÍÕýÔÚ»Ö¸´£¬£¬£¬£¬£¬µ«×èֹ׫дʱÈÔÓв¿·ÖÓû§ÎÞ·¨»á¼ûЧÀÍ¡£¡£¶íÂÞ˹¾³£±¬·¢»¥ÁªÍøÖÐÖ¹£¬£¬£¬£¬£¬ÓÐʱÊÇÍâµØÕþ¸®¾ÓÐÄΪ֮£¬£¬£¬£¬£¬ÈçÈ¥Äê12Ô²âÊÔ¡°Ö÷Ȩ»¥ÁªÍø¡±»ù´¡Éèʩʱµ¼Ö¶à¸öµØÇø×¡ÃñÎÞ·¨»á¼ûһЩÍâ¹úºÍÍâµØÓ¦ÓóÌÐòºÍÍøÕ¾¡£¡£±ðµÄ£¬£¬£¬£¬£¬¶íÂÞ˹»¹Òò¹È¸è¾Ü¾ø×ñÊØÊÖÒÕ¹æÔò¶ø¾ÓÐĽµµÍYouTube¼ÓÔØËÙÂÊ£¬£¬£¬£¬£¬²¢·â±ÕÁËViber¡¢SignalºÍDiscordµÈͨѶӦÓóÌÐòµÄ»á¼û¡£¡£
https://therecord.media/russia-widespread-accident-outage-wifi
6. Eagerbee¶ñÒâÈí¼þбäÖÖÕë¶ÔÖж«Õþ¸®×éÖ¯¼°ISP¾ÙÐÐÈ«ÇòÐÔ¹¥»÷
1ÔÂ6ÈÕ£¬£¬£¬£¬£¬Eagerbee¶ñÒâÈí¼þ¿ò¼ÜµÄбäÖÖÕýÔÚÕë¶ÔÖж«µÄÕþ¸®×éÖ¯ºÍ»¥ÁªÍøÐ§ÀÍÌṩÉ̾ÙÐа²ÅÅ£¬£¬£¬£¬£¬´Ëǰ¸Ã¶ñÒâÈí¼þÒѱ»·¢Ã÷ÓëÖйúÕþ¸®Ö§³ÖµÄÍþвÐÐΪÕßÓйء£¡£¿£¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓëÃûΪ¡°CoughingDown¡±µÄÍþв×éÖ¯±£´æÇ±ÔÚÁªÏµ¡£¡£¹¥»÷Õßͨ¹ýÔÚsystem32Ŀ¼Öа²ÅÅ×¢ÈëÆ÷À´¼ÓÔØÓÐÓÃÔØºÉÎļþ£¬£¬£¬£¬£¬ÀÄÓÃWindowsЧÀͲ¢ÔÚÄÚ´æÖÐдÈëºóßºÔØ¡£¡£¸ÃºóÃÅ¿ÉÒÔÈ«ÌìºòÔËÐУ¬£¬£¬£¬£¬ÍøÂçϵͳÐÅÏ¢²¢ÓëÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷½¨ÉèTCP/SSLͨµÀ£¬£¬£¬£¬£¬ÎüÊÕ¸½¼Ó²å¼þÒÔÀ©Õ¹Æä¹¦Ð§¡£¡£ÕâЩ²å¼þ°üÀ¨ÎļþÖÎÀíÆ÷¡¢Àú³ÌÖÎÀíÆ÷¡¢Ô¶³Ì»á¼ûÖÎÀíÆ÷¡¢Ð§ÀÍÖÎÀíÆ÷ºÍÍøÂçÖÎÀíÆ÷£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉϾßÓÐÆÕ±éµÄÄÜÁ¦¡£¡£Í¬ÑùµÄºóÃżÓÔØÁ´Ò²ÔÚÈÕ±¾±»·¢Ã÷£¬£¬£¬£¬£¬Åú×¢´Ë´Î¹¥»÷ÊÇÈ«ÇòÐԵġ£¡£×éÖ¯Ó¦ÐÞ²¹ExchangeЧÀÍÆ÷ÉϵÄProxyLogonÎó²î£¬£¬£¬£¬£¬²¢Ê¹Óÿ¨°Í˹»ù±¨¸æÖÐÁгöµÄΣº¦Ö¸±ê¾¡Ôç·¢Ã÷Íþв¡£¡£
https://www.bleepingcomputer.com/news/security/eagerbee-backdoor-deployed-against-middle-eastern-govt-orgs-isps/