GlassWormͨ¹ýOpenVSXÀ©Õ¹ÇÔÈ¡macOSÃô¸ÐÊý¾Ý

Ðû²¼Ê±¼ä 2026-02-03

1. GlassWormͨ¹ýOpenVSXÀ©Õ¹ÇÔÈ¡macOSÃô¸ÐÊý¾Ý


2ÔÂ2ÈÕ £¬ £¬£¬Ò»ÖÖÐÂÐÍGlassWorm¶ñÒâÈí¼þ¹¥»÷ͨ¹ý±»ÈëÇÖµÄOpenVSXÀ©Õ¹³ÌÐò £¬ £¬£¬×¨ÃÅÕë¶ÔmacOSϵͳÇÔÈ¡ÃÜÂë¡¢¼ÓÃÜÇ®°üÊý¾Ý¡¢¿ª·¢Õ߯¾Ö¤¼°ÉèÖÃÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕß»ñÈ¡ÁËÕýµ±¿ª·¢ÕßoorzcµÄÕË»§È¨ÏÞ £¬ £¬£¬ÓÚ1ÔÂ30ÈÕÏòËĸö±»ÏÂÔØ22,000´ÎµÄÀ©Õ¹³ÌÐòÍÆËͺ¬GlassWormÓÐÓÃÔØºÉµÄ¶ñÒâ¸üС£¡£¡£¡£¡£¡£¡£ÕâЩÀ©Õ¹³ÌÐò´ËǰÁ½Äê¾ùÎÞº¦ £¬ £¬£¬Åú×¢oorzcÕË»§ÒÑÔâÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¹¥»÷×îÔç·ºÆðÓÚ2025Äê10ÔÂÏÂÑ® £¬ £¬£¬Ê¹Óá°²»¿É¼û¡±Unicode×Ö·ûÒþ²Ø¶ñÒâ´úÂë £¬ £¬£¬Ö§³Ö»ùÓÚVNCµÄÔ¶³Ì»á¼ûºÍSOCKSÊðÀí¹¦Ð§¡£¡£¡£¡£¡£¡£¡£GlassWormרÃÅÕë¶ÔmacOSϵͳ £¬ £¬£¬¿É´ÓSolanaÉúÒⱸÍü¼ÌáȡָÁî £¬ £¬£¬ÇÒ¶íÓïϵͳδÊܹ¥»÷ £¬ £¬£¬ÌåÏÖ¹¥»÷Õß¿ÉÄÜÀ´×ԷǶíÓïÇø¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¼ÓÔØmacOSÐÅÏ¢ÇÔÈ¡³ÌÐò £¬ £¬£¬Í¨¹ýLaunchAgent½¨É賤ÆÚÐÔ £¬ £¬£¬ÔÚÓû§µÇ¼ʱ×Ô¶¯Ö´ÐÐ £¬ £¬£¬ÍøÂçFirefox¡¢Chromiumä¯ÀÀÆ÷Êý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÓ¦Óá¢macOSÔ¿³×´®¡¢Apple NotesÊý¾Ý¿â¡¢Safari cookie¡¢¿ª·¢ÕßÃÜÔ¿¼°ÍâµØÎĵµ £¬ £¬£¬²¢½«ËùÓÐÊý¾Ýй¶ÖÁ¹¥»÷ÕßµÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-glassworm-attack-targets-macos-via-compromised-openvsx-extensions/


2. ShinyHuntersй¶Panera Bread³¬1400ÍòÕË»§Êý¾Ý


2ÔÂ2ÈÕ £¬ £¬£¬ShinyHunters·¸·¨ÍÅ»ïÉù³ÆÇÔÈ¡ÁËPanera BreadÁè¼Ý1400Íò¸öÕË»§µÄÊý¾Ý £¬ £¬£¬²¢ÔÚÀÕË÷δ¹ûºó £¬ £¬£¬ÓÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹ûÕæÁËÒ»¸ö760MBµÄÊý¾Ý´æµµ¡£¡£¡£¡£¡£¡£¡£¾ÝHave I Been Pwned£¨HIBP£©±¨µÀ £¬ £¬£¬´Ë´ÎÐ¹Â¶Éæ¼°510Íò¸öΨһµç×ÓÓʼþµØµã¼°¹ØÁªµÄÕË»§ÐÅÏ¢ £¬ £¬£¬°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØµãµÈ¡£¡£¡£¡£¡£¡£¡£Panera BreadËæºó֤ʵй¶Êý¾ÝΪÁªÏµÐÅÏ¢ £¬ £¬£¬²¢ÒÑ֪ͨÓйز¿·Ö¡£¡£¡£¡£¡£¡£¡£BleepingComputer½øÒ»²½È·ÈÏÔ¼512Íò¸öÕË»§Êܵ½Ó°Ïì £¬ £¬£¬µ«ÏÖʵÊÜÓ°ÏìÓû§ÊýÄ¿¿ÉÄܸüÉÙ £¬ £¬£¬Òò±£´æÍ³Ò»Óû§Ê¹Óöà¸öÕË»§µÄÇéÐΡ£¡£¡£¡£¡£¡£¡£ShinyHuntersÍÅ»ïÌåÏÖ £¬ £¬£¬´Ë´Î¹¥»÷ÊÇÕë¶Ô100¶à¼Ò»ú¹¹µÄÖ÷ÒªÉí·ÝÌṩÉÌSSOÕË»§ÌᳫµÄ¸ü´ó¹æÄ£ÍøÂç´¹ÂÚ¹¥»÷µÄÒ»²¿·Ö £¬ £¬£¬ËûÃÇͨ¹ýMicrosoft Entra SSO´úÂë»á¼ûÁËPaneraµÄϵͳ¡£¡£¡£¡£¡£¡£¡£Panera×÷ΪÃÀ¹ú×ÅÃûºæ±º¿§·ÈÁ¬Ëøµê £¬ £¬£¬½¨ÉèÓÚ1987Äê £¬ £¬£¬ÓµÓÐÊýǧ¼Ò·Öµê £¬ £¬£¬×¨×¢ÓÚ¿ì½ÝÐÝÏвÍÒûģʽ £¬ £¬£¬´Ë´ÎÊý¾Ýй¶ÊÂÎñÔÙ´ÎÒý·¢ÁË¶ÔÆäÊý¾ÝÇå¾²ÖÎÀíµÄ¹Ø×¢¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/187556/data-breach/panera-bread-breach-affected-5-1-million-accounts-hibp-confirms.html


3. ¶íAPT28ʹÓÃOfficeÎó²î¶¨Ïò¹¥»÷ÎÚÅ·


2ÔÂ2ÈÕ £¬ £¬£¬ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±ÏìӦС×飨CERT-UA£©Åû¶ £¬ £¬£¬¶íÂÞ˹¹ú¼Ò¼¶ºÚ¿Í×éÖ¯APT28£¨ÓÖÃûFancy Bear¡¢Sofacy £¬ £¬£¬Óë¶í×ÜÕÕÁϲ¿Ç鱨×ܾÖGRU¹ØÁª£©ÕýʹÓÃ΢ÈíOfficeµÄÁãÈÕÎó²îCVE-2026-21509Ìᳫ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÓÚ2026Äê1ÔÂ26ÈÕÐû²¼½ôÆÈ´øÍâÇå¾²¸üР£¬ £¬£¬±ê¼Ç¸ÃÎó²îΪ¡°ÕýÔÚ±»Æð¾¢Ê¹Óá±µÄÁãÈÕÎó²î¡£¡£¡£¡£¡£¡£¡£½öÈýÌìºó £¬ £¬£¬CERT-UA±ã¼ì²âµ½ÒÔ¡°Å·ÃËפÎÚ¿ËÀ¼³£×¤´ú±íίԱ»á̽ÌÖ¡±ÎªÖ÷ÌâµÄ¶ñÒâDOCÎļþ £¬ £¬£¬Í¬Ê±·¢Ã÷ð³äÎÚ¿ËÀ¼Ë®ÎÄÆøÏóÖÐÐĵĴ¹ÂÚÓʼþ±»·¢ËÍÖÁ60Óà¸öÕþ¸®Ïà¹ØµØµã¡£¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ £¬ £¬£¬Ïà¹Ø¶ñÒâÎļþµÄÔªÊý¾ÝÏÔʾÆä½¨Éèʱ¼äÇ¡ÔÚ΢Èí¸üÐÂÐû²¼ºóÒ»ÈÕ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÊÖÒÕÁ´ÏÔʾ £¬ £¬£¬·­¿ª¶ñÒâÎĵµ»á´¥·¢»ùÓÚWebDAVµÄÏÂÔØÁ´ £¬ £¬£¬Í¨¹ýCOMÐ®ÖÆ¡¢¶ñÒâDLL¡¢Òþ²ØÔÚͼÏñÎļþÖеÄshellcode¼°ÍýÏëʹÃü×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£CERT-UA±¨¸æÖ¸³ö £¬ £¬£¬ÍýÏëʹÃüÖ´ÐлᵼÖÂexplorer.exeÀú³ÌÖÕÖ¹²¢ÖØÆô £¬ £¬£¬È·±£¼ÓÔØ¶ñÒâDLL £¬ £¬£¬½ø¶ø´ÓͼÏñÎļþÖÐÖ´ÐÐshellcodeÒÔÆô¶¯COVENANT¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£¸Ã¿ò¼Ü´ËÇ°ÔøÔÚ2025Äê6ÔÂAPT28Õë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄ¹¥»÷Öб»Ê¹Óᣡ£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-recently-patched-microsoft-office-bug-in-attacks/


4. OpenClaw¿ªÔ´AIÖúÊÖÔâÓö´ó¹æÄ£¶ñÒâÊÖÒÕ¹¥»÷


2ÔÂ2ÈÕ £¬ £¬£¬¿ªÔ´AIÖúÊÖOpenClaw£¨Ô­³ÆMoltbotºÍClawdBot£©µÄ¹Ù·½×¢²á±íClawHub¼°GitHubƽ̨ÔâÓö´ó¹æÄ£¶ñÒâÊÖÒÕ¹¥»÷ £¬ £¬£¬³¬230¸öαװ³ÉÕýµ±¹¤¾ßµÄ¶ñÒâÈí¼þ°ü±»Ðû²¼¡£¡£¡£¡£¡£¡£¡£ÕâЩ±»³Æ×÷"ÊÖÒÕ"µÄ²å¼þÒÔ¼ÓÃÜÇ®±ÒÉúÒâ×Ô¶¯»¯¡¢½ðÈÚ¹¤¾ßµÈÕýµ±¹¦Ð§Îª»Ï×Ó £¬ £¬£¬ÏÖʵעÈë¶ñÒâÈí¼þÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý £¬ £¬£¬°üÀ¨APIÃÜÔ¿¡¢Ç®°ü˽Կ¡¢SSHƾ֤¡¢ä¯ÀÀÆ÷ÃÜÂë¼°.envÎļþµÈ¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Jamieson O'ReillyÖ¸³ö £¬ £¬£¬´ó×ÚOpenClawʵÀýÒòÉèÖò»µ±µ¼ÖÂÖÎÀí½çÃæÌ»Â¶ÓÚ¹«¹²ÍøÂç¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓôËÎó²î £¬ £¬£¬Í¨¹ýÃûΪ"AuthTool"µÄ¶ñÒâÈí¼þÈö²¥¹¤¾ßʵÑéѬȾ¡£¡£¡£¡£¡£¡£¡£ÉçÇøÇå¾²×éÖ¯OpenSourceMalware±¨¸æÏÔʾ £¬ £¬£¬´Ë´Î¹¥»÷·ºÆð¹æÄ £»£»£»£»£»£»¯ÌØÕ÷ £¬ £¬£¬´ó×Ú¶ñÒâÊÖÒÕ¿âÃû³Æ¸ß¶ÈÏàËÆ £¬ £¬£¬²¿·Ö°æ±¾ÏÂÔØÁ¿´ïÊýǧ´Î¡£¡£¡£¡£¡£¡£¡£Koi SecurityɨÃèClawHubËùÓÐ2857¸öÊÖÒÕ¿âºó £¬ £¬£¬·¢Ã÷341¸ö¶ñÒâÊÖÒÕ £¬ £¬£¬²¢×·×Ùµ½29¸öÕë¶ÔClawHubÓòÃûµÄƴд¹ýʧ´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ÎªÐ­ÖúÓû§·ÀÓù £¬ £¬£¬Koi»¹Ðû²¼ÁËÃâ·ÑÔÚÏßɨÃ蹤¾ß £¬ £¬£¬¿Éͨ¹ýURL¼ì²âÊÖÒÕÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/


5.ÐÂÐÍÍøÂç´¹ÂÚթƭʹÓÃPDF¸½¼þÇÔÈ¡Óû§Æ¾Ö¤


2ÔÂ2ÈÕ £¬ £¬£¬ForcepointÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕÅû¶һÖÖÐÂÐͶà½×¶ÎÍøÂç´¹ÂÚÕ©Æ­ÊÖ¶Î £¬ £¬£¬¸ÃÊÖ·¨Í¨¹ýÈ«ÐÄÉè¼ÆµÄ¡°×¨ÒµÓʼþ+PDF¸½¼þ¡±×éºÏÈÆ¹ý¹Å°åÇå¾²¹ýÂË £¬ £¬£¬×îÖÕÇÔÈ¡Óû§µÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£´ËÀàÕ©Æ­Óʼþͨ³£Î±×°³ÉÉÌÒµÌõÔ¼¡¢Õбê»ò²É¹ºÉúÒâÏà¹ØÍ¨Öª £¬ £¬£¬ÄÚÈÝ¿´ËÆÕý¹æÎÞº¦ £¬ £¬£¬µ«Òªº¦¶ñÒâÐÐΪÒþ²ØÔÚPDF¸½¼þÖС£¡£¡£¡£¡£¡£¡£Ñо¿ÏÔʾ £¬ £¬£¬Õ©Æ­ÕßʹÓÃPDFµÄAcroFormsºÍFlateDecodeÊÖÒÕ £¬ £¬£¬ÔÚ¿´ËÆÍ¨Ë׵İ칫빵µÖÐǶÈë¿Éµã»÷°´Å¥¡£¡£¡£¡£¡£¡£¡£Óû§µã»÷ºó £¬ £¬£¬»á±»Ö¸µ¼ÖÁµÚ¶þ¸öÍйÜÔÚVercel BlobÔÆ´æ´¢Æ½Ì¨ÉϵÄÎĵµ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚVercelÊÇÕýµ±ÔÆÐ§ÀÍ £¬ £¬£¬ÕâÖÖ¡°¿ÉÐÅ»ù´¡ÉèÊ©¡±Ê¹Ó÷½·¨ÓÐÓùæ±ÜÁËÇå¾²Èí¼þµÄ×èµ²¡£¡£¡£¡£¡£¡£¡£Ëæºó £¬ £¬£¬¸ÃÔÆÎĵµ»áÌø×ªÖÁαÔìµÄDropboxµÇÂ¼Ò³Ãæ £¬ £¬£¬Æä½çÃæÓëÕæÊµÒ³Ãæ¸ß¶ÈÏàËÆ £¬ £¬£¬ÓÕµ¼Óû§ÊäÈëÓÊÏä¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚºǫ́ £¬ £¬£¬¶ñÒâ¾ç±¾²»µ«ÇÔÈ¡Óû§Æ¾Ö¤ £¬ £¬£¬»¹»á¼Í¼׼ȷµÄIPµØµã¡¢µØÀíλÖá¢×°±¸ÀàÐ͵ÈÀ©Õ¹ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£±»µÁÊý¾Ýͨ¹ýÓ²±àÂë·½·¨Ö±½Ó·¢ËÍÖÁTelegramƽ̨µÄ˽ÈËÆµµÀ £¬ £¬£¬ÓɺڿͿØÖƵĻúеÈËÎüÊÕ¡£¡£¡£¡£¡£¡£¡£


https://hackread.com/phishing-scam-emails-pdfs-steal-dropbox-logins/


6. È«ÇòÔÆ´æ´¢¶©ÔÄÕ©Æ­ÂþÒç


1ÔÂ31ÈÕ £¬ £¬£¬ÒÑÍùÊýÔ £¬ £¬£¬Ò»³¡´ó¹æÄ£ÔÆ´æ´¢¶©ÔÄÕ©Æ­»î¶¯ÔÚÈ«Çò¹æÄ£ÄÚÒ»Á¬ÉìÕÅ¡£¡£¡£¡£¡£¡£¡£Õ©Æ­·Ö×Óͨ¹ý·¢ËÍ´ó×ÚÏÅ»£Óʼþ £¬ £¬£¬»Ñ³ÆÓû§Òò¡°Ö§¸¶Ê§°Ü¡±»ò¡°´æ´¢¿Õ¼äȱ·¦¡±µ¼ÖÂÕË»§½«±»·â±Õ¡¢Îļþ½«±»É¾³ý £¬ £¬£¬ÒÔ´ËÖÆÔì½ôÆÈ¸ÐÓÕµ¼Óû§µã»÷Á´½Ó¡£¡£¡£¡£¡£¡£¡£ÓʼþÖеÄÁ´½Ó¾ùÖ¸Ïò¹È¸èÔÆ´æ´¢Ð§ÀÍÍйܵľ²Ì¬Öض¨ÏòHTMLÎļþ £¬ £¬£¬Óû§µã»÷ºó»á±»Ìø×ªÖÁËæ»úÓòÃûµÄ´¹ÂÚÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£ÕâÐ©Ò³Ãæ¸ß¶ÈÄ£ÄâÖ÷Á÷ÔÆÐ§ÀÍÉÌ£¨Èç¹È¸èÔÆ¡¢Î¢ÈíOneDrive£©µÄ¹Ù·½½çÃæ £¬ £¬£¬Éù³ÆÓû§´æ´¢¿Õ¼äÒÑÂú £¬ £¬£¬ÕÕÆ¬¡¢ÊÓÆµ¡¢ÎĵµµÈÊý¾Ý½«×èÖ¹±¸·Ý²¢ÃæÁÙɾ³ýΣº¦ £¬ £¬£¬ÓÕµ¼Óû§µã»÷¡°¼ÌÐø¡±°´Å¥½øÈëÐéα´æ´¢¼ì²âÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³ÃæÊ¼ÖÕÏÔʾ´æ´¢¿Õ¼äÕ¼Âú £¬ £¬£¬ÒªÇóÓû§Éý¼¶ÔÆ´æ´¢ÌײÍÒÔÏíÊÜ¡°ÀÏÓû§×¨Êô8ÕÛÓŻݡ± £¬ £¬£¬µ«ÏÖʵµã»÷Éý¼¶°´Å¥ºó £¬ £¬£¬Óû§»á±»Öض¨ÏòÖÁͬÃËÓªÏúÒ³Ãæ £¬ £¬£¬ÍƹãVPNЧÀÍ¡¢Ð¡ÖÚÇå¾²Èí¼þµÈÎ޹زúÆ· £¬ £¬£¬×îÖÕÌø×ªÖÁ½áÕË±íµ¥ÍøÂçÓû§ÐÅÓÿ¨ÐÅÏ¢ £¬ £¬£¬Í¬Ê±ÎªÕ©Æ­·Ö×Ó׬ȡͬÃËÓªÏúÓ¶½ð¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cloud-storage-payment-scam-floods-inboxes-with-fake-renewals/