Ç×¶íºÚ¿Íð³ä¹Ù·½»ú¹¹ÊµÑéÍøÂç´¹ÂÚ¹¥»÷

Ðû²¼Ê±¼ä 2026-04-02

1. Ç×¶íºÚ¿Íð³ä¹Ù·½»ú¹¹ÊµÑéÍøÂç´¹ÂÚ¹¥»÷


3ÔÂ31ÈÕ £¬£¬ £¬£¬£¬£¬ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±ÏìӦС×飨CERT-UA£©Ðû²¼±¨¸æ £¬£¬ £¬£¬£¬£¬½ÒÆÆÒ»¸ö±àºÅΪUAC-0255µÄÇ×¶íºÚ¿Í×é֯ð³ä¸Ã»ú¹¹ £¬£¬ £¬£¬£¬£¬Õë¶ÔÕþ¸®»ú¹¹¡¢ÆóÒµ¼°ÆäËû×éÖ¯¿ªÕ¹ÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¹¥»÷Õßͨ¹ýαÔì¹Ù·½Óʼþ £¬£¬ £¬£¬£¬£¬ÖÒÑÔÊÕ¼þÈ˶íÂÞ˹ÕýÍýÏë¶ÔÎÚ¿ËÀ¼Òªº¦»ù´¡ÉèÊ©·¢¶¯¡°´ó¹æÄ£ÍøÂç¹¥»÷¡± £¬£¬ £¬£¬£¬£¬²¢ÓÕµ¼Æä´ÓÎļþ¹²ÏíЧÀÍFiles.fmÏÂÔØÃÜÂë±£»£»£»£»£»£» £»¤µÄѹËõÎļþ £¬£¬ £¬£¬£¬£¬×°ÖÃËùνµÄ¡°Çå¾²·À»¤Èí¼þ¡±¡£¡£¡£¸ÃÎļþÏÖʵ°üÀ¨ÃûΪAgeWheezeµÄÔ¶³ÌÖÎÀí¹¤¾ß £¬£¬ £¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì¿ØÖÆÊÜѬȾװ±¸ £¬£¬ £¬£¬£¬£¬Ö´ÐÐÏÂÁî¡¢ÖÎÀíÎļþÀú³Ì¡¢´«ÊäÆÁÄ»ÄÚÈÝ¡¢Ä£ÄâÊó±ê¼üÅ̲Ù×÷¼°»á¼û¼ôÌù°åµÈ²Ù×÷¡£¡£¡£´Ë´Î¹¥»÷Ä¿µÄº­¸ÇÕþ¸®»ú¹¹¡¢Ò½ÁÆÖÐÐÄ¡¢½ðÈÚ¹«Ë¾¡¢Çå¾²¹«Ë¾¡¢´óѧ¼°Èí¼þ¿ª·¢É̵ȶà¸öÐÐÒµ¡£¡£¡£CERT-UAÆÀ¹ÀÒÔΪ £¬£¬ £¬£¬£¬£¬´Ë´Î´¹ÂڻÕûÌåЧ¹ûÓÐÏÞ £¬£¬ £¬£¬£¬£¬½öµ¼ÖÂÉÙÁ¿Ñ¬È¾ £¬£¬ £¬£¬£¬£¬Ö÷Òª¼¯ÖÐÓÚ½ÌÓý»ú¹¹Ô±¹¤µÄСÎÒ˽¼Ò×°±¸¡£¡£¡£ÊÓ²ìÏÔʾ £¬£¬ £¬£¬£¬£¬¹¥»÷Ðж¯¿ÉÄÜÓëÐÂÐËÍøÂçÍþв×éÖ¯CyberSerp±£´æ¹ØÁª £¬£¬ £¬£¬£¬£¬¸Ã×éÖ¯ËæºóÔÚTelegramƵµÀÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ £¬£¬ £¬£¬£¬£¬²¢Éù³ÆÒÑÏòÔ¼Ò»°ÙÍòUkr.netÓû§·¢ËͶñÒâÓʼþ £¬£¬ £¬£¬£¬£¬ÈëÇÖ³¬20Íǫ̀װ±¸ £¬£¬ £¬£¬£¬£¬µ«CERT-UAÉÐδ֤ʵÕâЩÊý×Ö¡£¡£¡£


https://therecord.media/pro-russian-hackers-posing-as-ukrainian-cyber-agency


2. WhatsApp·¢Ã÷ÐéαӦÓÃѬȾ200ÃûÓû§


4ÔÂ2ÈÕ £¬£¬ £¬£¬£¬£¬WhatsAppÐû²¼ÒÑ֪ͨԼ200ÃûÓû§ £¬£¬ £¬£¬£¬£¬ËûÃǵÄ×°±¸Òò×°ÖôøÓÐÌØ¹¤Èí¼þµÄð³äWhatsAppÓ¦ÓöøÔâµ½ÈëÇÖ¡£¡£¡£¸ÃÐéαӦÓÃÓÉÒâ´óÀûÌØ¹¤Èí¼þÖÆÔìÉÌSIOרÃÅΪiPhoneÉè¼Æ £¬£¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Ö÷Òª¼¯ÖÐÔÚÒâ´óÀû¡£¡£¡£WhatsAppÌåÏÖ £¬£¬ £¬£¬£¬£¬´Ë´Î¹¥»÷²¢·ÇÔ´ÓÚÆä×ÔÉíÎó²î £¬£¬ £¬£¬£¬£¬¶øÊÇÍþвÐÐΪÕßͨ¹ý¸ß¶ÈÕë¶ÔÐÔµÄÉç»á¹¤³ÌÊÖ¶Î £¬£¬ £¬£¬£¬£¬ÓÕʹÓû§ÔÚ¹Ù·½Ó¦ÓÃÊÐËÁÖ®ÍâÏÂÔØ¶ñÒâÈí¼þ¡£¡£¡£WhatsAppµÄÇå¾²ÍŶÓ×Ô¶¯·¢Ã÷ÁËÕâÒ»ÐéαӦÓà £¬£¬ £¬£¬£¬£¬²¢½«Æä¹é×ïÓÚSIOµÄ×Ó¹«Ë¾ASIGINT¡£¡£¡£ÏÖÔÚ £¬£¬ £¬£¬£¬£¬SIOºÍÆ»¹û¹«Ë¾¾ùδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£WhatsAppÒѽ«ÊÜÓ°ÏìµÄ200ÃûÓû§µÇ³ö £¬£¬ £¬£¬£¬£¬²¢ÌáÐÑÓû§ÏÂÔØ·Ç¹Ù·½¿Í»§¶Ë±£´æÒþ˽ºÍÇ徲Σº¦ £¬£¬ £¬£¬£¬£¬½¨Òéɾ³ýð³äÓ¦Óò¢×°Öùٷ½°æ±¾¡£¡£¡£SIOÔÚÆä¹ÙÍøÉÏ×Ô³ÆÊÇÖ´·¨²¿·Ö¡¢Õþ¸®»ú¹¹ÒÔ¼°¾¯Ô±ºÍÇ鱨»ú¹¹µÄ¡°ÏàÖúͬ°é¡± £¬£¬ £¬£¬£¬£¬´ËǰÒÑÓÐÀàËÆÐÐΪ¼Í¼¡£¡£¡£È¥Äê £¬£¬ £¬£¬£¬£¬TechCrunchÔø±¨µÀSIO¿ª·¢Á˶à¿îÖ²ÈëÌØ¹¤Èí¼þµÄ°²×¿Ó¦Óᣡ£¡£


https://therecord.media/whatsapp-warns-users-of-fake-app-used-for-spyware


3. CrystalRAT¶ñÒâÈí¼þ¼´Ð§ÀÍÉÏÏßTelegram


4ÔÂ1ÈÕ £¬£¬ £¬£¬£¬£¬Ò»ÖÖÃûΪCrystalRATµÄÐÂÐͶñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©ÕýÔÚTelegramÉÏÍÆ¹ã £¬£¬ £¬£¬£¬£¬ÌṩԶ³Ì»á¼û¡¢Êý¾ÝÇÔÈ¡¡¢¼üÅ̼ͼºÍ¼ôÌù°åÐ®ÖÆµÈ¹¦Ð§¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ1Ô·ºÆð £¬£¬ £¬£¬£¬£¬½ÓÄÉ·Ö¼¶¶©ÔÄģʽ £¬£¬ £¬£¬£¬£¬³ýÁËTelegramƵµÀÍâ £¬£¬ £¬£¬£¬£¬»¹Í¨¹ýרÃŵÄYouTubeÓªÏúƵµÀ¾ÙÐÐÍÆ¹ã¡£¡£¡£CrystalRATÌṩÁËÒ»¸öÓû§ÓѺõĿØÖÆÃæ°åºÍ×Ô¶¯»¯¹¹½¨¹¤¾ß £¬£¬ £¬£¬£¬£¬Ö§³ÖµØÀí·â±Õ¡¢¿ÉÖ´ÐÐÎļþ×Ô½ç˵ºÍ·´ÆÊÎö¹¦Ð§¡£¡£¡£ÌìÉúµÄÓÐÓÃÔØºÉ¾­ÓÉzlibѹËõ £¬£¬ £¬£¬£¬£¬²¢Ê¹ÓÃChaCha20¶Ô³ÆÁ÷ÃÜÂë¾ÙÐмÓÃÜ¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýWebSocketÅþÁ¬µ½ÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷ £¬£¬ £¬£¬£¬£¬²¢·¢ËÍÖ÷»úÐÅÏ¢ÓÃÓÚѬȾ¸ú×Ù¡£¡£¡£ÏÖÔÚÆäÐÅÏ¢ÇÔÈ¡×é¼þÔÝʱ±»½ûÓà £¬£¬ £¬£¬£¬£¬ÕýÔÚ¾ÙÐÐÉý¼¶×¼±¸ £¬£¬ £¬£¬£¬£¬¸Ã×é¼þ¿Éͨ¹ýChromeElevator¹¤¾ßÒÔ¼°Yandex¡¢OperaµÈ»ùÓÚChromiumµÄä¯ÀÀÆ÷¾ÙÐй¥»÷ £¬£¬ £¬£¬£¬£¬Í¬Ê±´ÓSteam¡¢DiscordºÍTelegramµÈ×ÀÃæÓ¦ÓóÌÐòÍøÂçÊý¾Ý¡£¡£¡£Ô¶³Ì»á¼ûÄ£¿£¿£¿£¿éÖ§³Öͨ¹ýCMDÖ´ÐÐÏÂÁî¡¢ÉÏ´«/ÏÂÔØÎļþ¡¢ä¯ÀÀÎļþϵͳ £¬£¬ £¬£¬£¬£¬²¢Í¨¹ýÄÚÖÃVNCʵʱ¿ØÖÆ»úе¡£¡£¡£±ðµÄ £¬£¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹Äܲ¶»ñÂó¿Ë·çµÄÊÓÆµºÍÒôƵ £¬£¬ £¬£¬£¬£¬Å䱸µÄ¼üÅ̼ͼÆ÷¿É½«»÷¼üʵʱ´«ÊäÖÁC2ЧÀÍÆ÷ £¬£¬ £¬£¬£¬£¬¼ôÌù°å¹¤¾ßÔòʹÓÃÕýÔò±í´ïʽ¼ì²â¼ôÌù°åÖеÄÇ®°üµØµã²¢Ì滻Ϊ¹¥»÷ÕßÌṩµÄµØµã¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-crystalrat-malware-adds-rat-stealer-and-prankware-features/


4. TrueChaosÐж¯Ê¹ÓÃÁãÈÕÎó²î¹¥»÷TrueConfЧÀÍÆ÷


4ÔÂ1ÈÕ £¬£¬ £¬£¬£¬£¬ºÚ¿ÍʹÓñàºÅΪCVE-2026-3502µÄÁãÈÕÎó²î¹¥»÷TrueConf¾Û»áЧÀÍÆ÷ £¬£¬ £¬£¬£¬£¬´Ó¶øÔÚËùÓÐÅþÁ¬µÄ¶ËµãÉÏÖ´ÐÐí§ÒâÎļþ¡£¡£¡£¸ÃÎó²îÑÏÖØË®Æ½ÆÀ¼¶ÎªÖÐµÈ £¬£¬ £¬£¬£¬£¬Ô´ÓÚÈí¼þ¸üлúÖÆÖÐȱÉÙÍêÕûÐÔ¼ì²é £¬£¬ £¬£¬£¬£¬¹¥»÷Õ߿ɽ«Õýµ±¸üÐÂÌæ»»Îª¶ñÒâ±äÖÖ¡£¡£¡£TrueConfÊÇÒ»¸öÊÓÆµ¾Û»áƽ̨ £¬£¬ £¬£¬£¬£¬¿É×÷Ϊ×ÔÍйÜЧÀÍÆ÷ÔËÐÐ £¬£¬ £¬£¬£¬£¬Í¨³£Îª¹Ø±ÕµÄÀëÏßÇéÐÎÉè¼Æ¡£¡£¡£CheckPointÑо¿Ö°Ô±×·×Ùµ½Ò»¸öÃûΪTrueChaosµÄ»î¶¯ £¬£¬ £¬£¬£¬£¬×Ô½ñÄêÄêÍ·ÒÔÀ´ £¬£¬ £¬£¬£¬£¬¸Ã»î¶¯Ê¹ÓÃCVE-2026-3502Îó²î¶Ô¶«ÄÏÑÇÕþ¸®ÊµÌåÌᳫÁãÈÕ¹¥»÷¡£¡£¡£¹¥»÷ÕßÈô¿ØÖÆÁËÍâµØTrueConfЧÀÍÆ÷ £¬£¬ £¬£¬£¬£¬¿É½«Ô¤ÆÚ¸üаüÌæ»»Îªí§Òâ¿ÉÖ´ÐÐÎļþ²¢Î±×°³ÉÄ¿½ñÓ¦ÓóÌÐò°æ±¾ £¬£¬ £¬£¬£¬£¬·Ö·¢¸øËùÓÐÅþÁ¬µÄ¿Í»§¶Ë¡£¡£¡£ÓÉÓÚ¿Í»§¶Ëδ¾ÙÐÐÊʵ±ÑéÖ¤¼´ÐÅÈÎЧÀÍÆ÷ÌṩµÄ¸üР£¬£¬ £¬£¬£¬£¬¶ñÒâÎļþ¿Éαװ³ÉÕýµ±TrueConf¸üжø±»×ª´ïºÍÖ´ÐС£¡£¡£¸ÃÎó²îÓ°ÏìTrueConf°æ±¾8.1.0ÖÁ8.5.2 £¬£¬ £¬£¬£¬£¬ÐÞ¸´³ÌÐòÓÚ2026Äê3ÔÂÔÚ8.5.3°æ±¾ÖÐÐû²¼¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-trueconf-zero-day-to-push-malicious-software-updates/


5. NoVoice°²×¿¶ñÒâÈí¼þ²ØÉíGoogle Play³¬50¿îÓ¦ÓÃ


4ÔÂ1ÈÕ £¬£¬ £¬£¬£¬£¬Ò»ÖÖÃûΪNoVoiceµÄÐÂÐͰ²×¿¶ñÒâÈí¼þÔÚGoogle PlayÉϱ»·¢Ã÷ £¬£¬ £¬£¬£¬£¬Òþ²ØÔÚ50¶à¿îÀÛ¼ÆÏÂÔØÁ¿´ï230Íò´ÎµÄÓ¦ÓóÌÐòÖС£¡£¡£ÕâЩӦÓðüÀ¨ÕûÀí¹¤¾ß¡¢Í¼Æ¬¿âºÍÓÎÏ· £¬£¬ £¬£¬£¬£¬ÍâòÉÏÎÞÐè¿ÉÒÉȨÏÞÇÒÌṩÕý³£¹¦Ð§¡£¡£¡£¾ÝMcAfeeÑо¿Ö°Ô±ÆÊÎö £¬£¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þʹÓÃ2016ÄêÖÁ2021Äê¼äÒÑÐÞ¸´µÄ¾É°æ°²×¿Îó²î £¬£¬ £¬£¬£¬£¬ÊÔͼ»ñȡװ±¸rootȨÏÞ¡£¡£¡£Æô¶¯ÊÜѬȾӦÓÃºó £¬£¬ £¬£¬£¬£¬¶ñÒâÈí¼þ½«¼ÓÃÜÓÐÓÃÔØºÉÒþ²ØÔÚPNGͼÏñÎļþÖÐ £¬£¬ £¬£¬£¬£¬ÌáÈ¡¼ÓÔØºóɨ³ýÖÐÐÄÎļþÒÔÏû³ýºÛ¼£¡£¡£¡£¹¥»÷Õß»á×èֹѬȾ±±¾©¡¢ÉîÛÚµÈÌØ¶¨µØÇø×°±¸ £¬£¬ £¬£¬£¬£¬²¢¶ÔÄ£ÄâÆ÷¡¢µ÷ÊÔÆ÷ºÍVPNʵÑé15Ïî¼ì²é¡£¡£¡£¶ñÒâÈí¼þÅþÁ¬ÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷ÍøÂç×°±¸ÐÅÏ¢ £¬£¬ £¬£¬£¬£¬Ã¿60ÃëÂÖѯһ´Î²¢ÏÂÔØÕë¶ÔÌØ¶¨×°±¸µÄÎó²îʹÓÃ×é¼þ¡£¡£¡£McAfee·¢Ã÷ÁË22¸öÎó²î £¬£¬ £¬£¬£¬£¬¹¥»÷Õ߿ɽè´Ë»ñÈ¡rootȨÏÞ²¢½ûÓÃSELinuxÇ¿ÖÆÖ´ÐÐ £¬£¬ £¬£¬£¬£¬Ï÷Èõ×°±¸»ù±¾Çå¾²±£»£»£»£»£»£» £»¤¡£¡£¡£×°±¸±»rootºó £¬£¬ £¬£¬£¬£¬Òªº¦ÏµÍ³¿â±»Ì滻Ϊhook°ü×°Æ÷ £¬£¬ £¬£¬£¬£¬×赲ϵͳŲÓò¢½«Ö´ÐÐÖØ¶¨ÏòÖÁ¹¥»÷´úÂë¡£¡£¡£ÔÚºóÉøÍ¸½×¶Î £¬£¬ £¬£¬£¬£¬¹¥»÷Õß½«¿ØÖÆ´úÂë×¢Èë×°±¸ÉÏÆô¶¯µÄÿ¸öÓ¦ÓóÌÐò £¬£¬ £¬£¬£¬£¬Ö÷Òª°²ÅÅÁ½¸ö×é¼þ£ºÒ»¸öÓÃÓÚ¾²Ä¬×°ÖûòÐ¶ÔØÓ¦Óà £¬£¬ £¬£¬£¬£¬ÁíÒ»¸öÔÚÈκÎÄÜ»á¼û»¥ÁªÍøµÄÓ¦ÓÃÖÐÔËÐÐ £¬£¬ £¬£¬£¬£¬×÷ΪÖ÷ÒªÕë¶ÔWhatsAppÊý¾ÝÇÔÈ¡»úÖÆ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/


6. º¢Ö®±¦ÔâÍøÂç¹¥»÷ÖÂÓªÒµÖÐÖ¹


4ÔÂ1ÈÕ £¬£¬ £¬£¬£¬£¬Íæ¾ßºÍÓÎÏ·¾ÞÍ·º¢Ö®±¦ÖÜÈý±¨¸æ³Æ £¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾ÔâÊÜÍøÂç¹¥»÷ £¬£¬ £¬£¬£¬£¬µ¼Ö²¿·ÖÓªÒµÁ÷³ÌÖÐÖ¹¡£¡£¡£Æ¾Ö¤Ìá½»¸øÃÀ¹ú֤ȯÉúÒâίԱ»áµÄÎļþ £¬£¬ £¬£¬£¬£¬º¢Ö®±¦ÓÚ3ÔÂ28ÈÕ¼ì²âµ½ÆäÍøÂçÔ⵽δ¾­ÊÚȨµÄ»á¼û £¬£¬ £¬£¬£¬£¬×÷ΪÊÂÎñÏìÓ¦²½·¥µÄÒ»²¿·Ö £¬£¬ £¬£¬£¬£¬²¿·ÖϵͳÒѱ»ÀëÏß¡£¡£¡£ÏÖÔÚ £¬£¬ £¬£¬£¬£¬¹«Ë¾Õý½èÖúÍâ²¿ÍøÂçÇ徲ר¼ÒµÄʵÁ¦Õö¿ªÊÓ²ì £¬£¬ £¬£¬£¬£¬Ä¿µÄÖ®Ò»ÊÇÈ·¶¨´Ë´ÎÊÂÎñµÄËùÓÐÓ°Ïì¹æÄ£ £¬£¬ £¬£¬£¬£¬°üÀ¨ÊÇ·ñÓÐÈκÎÎļþÔ⵽й¶¡£¡£¡£º¢Ö®±¦ÌåÏÖ £¬£¬ £¬£¬£¬£¬¹«Ë¾ÒÑʵÑé²¢½«¼ÌÐøÊµÑéÓªÒµÒ»Á¬ÐÔÍýÏë £¬£¬ £¬£¬£¬£¬ÒÔÈ·±£ÔÚ½â¾öÄ¿½ñÇéÐεÄͬʱÄܹ»¼ÌÐø½ÓÊܶ©µ¥¡¢·¢»õºÍ¿ªÕ¹ÆäËûÒªº¦ÓªÒµ¡£¡£¡£ÉùÃ÷Ôö²¹³Æ £¬£¬ £¬£¬£¬£¬ÔÚÇéÐÎÍêÈ«½â¾ö֮ǰ £¬£¬ £¬£¬£¬£¬¿ÉÄÜÐèÒªÒ»Á¬ÊýÖÜʱ¼äʵÑéÕâЩÔÝʱ²½·¥ £¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܻᵼÖÂһЩÑÓÎ󡣡£¡£×èÖ¹ÏÖÔÚ £¬£¬ £¬£¬£¬£¬ÉÐÎÞÍøÂç·¸·¨ÍÅ»ïÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£º¢Ö®±¦ÌåÏÖ £¬£¬ £¬£¬£¬£¬¹«Ë¾ÕýÔÚÆð¾¢ÔöǿϵͳÇå¾² £¬£¬ £¬£¬£¬£¬²¢½«Æ¾Ö¤ÊÓ²ìЧ¹û½ÓÄÉÆäËû²½·¥ £¬£¬ £¬£¬£¬£¬°üÀ¨Ðû²¼ÐëÒªµÄ֪ͨ¡£¡£¡£


https://www.securityweek.com/toy-giant-hasbro-hit-by-cyberattack/