Ç×¶íºÚ¿Íð³ä¹Ù·½»ú¹¹ÊµÑéÍøÂç´¹ÂÚ¹¥»÷
Ðû²¼Ê±¼ä 2026-04-021. Ç×¶íºÚ¿Íð³ä¹Ù·½»ú¹¹ÊµÑéÍøÂç´¹ÂÚ¹¥»÷
3ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±ÏìӦС×飨CERT-UA£©Ðû²¼±¨¸æ£¬£¬£¬£¬£¬£¬½ÒÆÆÒ»¸ö±àºÅΪUAC-0255µÄÇ×¶íºÚ¿Í×é֯ð³ä¸Ã»ú¹¹£¬£¬£¬£¬£¬£¬Õë¶ÔÕþ¸®»ú¹¹¡¢ÆóÒµ¼°ÆäËû×éÖ¯¿ªÕ¹ÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¹¥»÷Õßͨ¹ýαÔì¹Ù·½Óʼþ£¬£¬£¬£¬£¬£¬ÖÒÑÔÊÕ¼þÈ˶íÂÞ˹ÕýÍýÏë¶ÔÎÚ¿ËÀ¼Òªº¦»ù´¡ÉèÊ©·¢¶¯¡°´ó¹æÄ£ÍøÂç¹¥»÷¡±£¬£¬£¬£¬£¬£¬²¢ÓÕµ¼Æä´ÓÎļþ¹²ÏíЧÀÍFiles.fmÏÂÔØÃÜÂë±£»£»£»£»£»£»£»¤µÄѹËõÎļþ£¬£¬£¬£¬£¬£¬×°ÖÃËùνµÄ¡°Çå¾²·À»¤Èí¼þ¡±¡£¡£¡£¸ÃÎļþÏÖʵ°üÀ¨ÃûΪAgeWheezeµÄÔ¶³ÌÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì¿ØÖÆÊÜѬȾװ±¸£¬£¬£¬£¬£¬£¬Ö´ÐÐÏÂÁî¡¢ÖÎÀíÎļþÀú³Ì¡¢´«ÊäÆÁÄ»ÄÚÈÝ¡¢Ä£ÄâÊó±ê¼üÅ̲Ù×÷¼°»á¼û¼ôÌù°åµÈ²Ù×÷¡£¡£¡£´Ë´Î¹¥»÷Ä¿µÄº¸ÇÕþ¸®»ú¹¹¡¢Ò½ÁÆÖÐÐÄ¡¢½ðÈÚ¹«Ë¾¡¢Çå¾²¹«Ë¾¡¢´óѧ¼°Èí¼þ¿ª·¢É̵ȶà¸öÐÐÒµ¡£¡£¡£CERT-UAÆÀ¹ÀÒÔΪ£¬£¬£¬£¬£¬£¬´Ë´Î´¹ÂڻÕûÌåЧ¹ûÓÐÏÞ£¬£¬£¬£¬£¬£¬½öµ¼ÖÂÉÙÁ¿Ñ¬È¾£¬£¬£¬£¬£¬£¬Ö÷Òª¼¯ÖÐÓÚ½ÌÓý»ú¹¹Ô±¹¤µÄСÎÒ˽¼Ò×°±¸¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬¹¥»÷Ðж¯¿ÉÄÜÓëÐÂÐËÍøÂçÍþв×éÖ¯CyberSerp±£´æ¹ØÁª£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ËæºóÔÚTelegramƵµÀÐû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬£¬£¬£¬²¢Éù³ÆÒÑÏòÔ¼Ò»°ÙÍòUkr.netÓû§·¢ËͶñÒâÓʼþ£¬£¬£¬£¬£¬£¬ÈëÇÖ³¬20Íǫ̀װ±¸£¬£¬£¬£¬£¬£¬µ«CERT-UAÉÐδ֤ʵÕâЩÊý×Ö¡£¡£¡£
https://therecord.media/pro-russian-hackers-posing-as-ukrainian-cyber-agency
2. WhatsApp·¢Ã÷ÐéαӦÓÃѬȾ200ÃûÓû§
4ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬WhatsAppÐû²¼ÒÑ֪ͨԼ200ÃûÓû§£¬£¬£¬£¬£¬£¬ËûÃǵÄ×°±¸Òò×°ÖôøÓÐÌØ¹¤Èí¼þµÄð³äWhatsAppÓ¦ÓöøÔâµ½ÈëÇÖ¡£¡£¡£¸ÃÐéαӦÓÃÓÉÒâ´óÀûÌØ¹¤Èí¼þÖÆÔìÉÌSIOרÃÅΪiPhoneÉè¼Æ£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Ö÷Òª¼¯ÖÐÔÚÒâ´óÀû¡£¡£¡£WhatsAppÌåÏÖ£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷²¢·ÇÔ´ÓÚÆä×ÔÉíÎó²î£¬£¬£¬£¬£¬£¬¶øÊÇÍþвÐÐΪÕßͨ¹ý¸ß¶ÈÕë¶ÔÐÔµÄÉç»á¹¤³ÌÊֶΣ¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÔÚ¹Ù·½Ó¦ÓÃÊÐËÁÖ®ÍâÏÂÔØ¶ñÒâÈí¼þ¡£¡£¡£WhatsAppµÄÇå¾²ÍŶÓ×Ô¶¯·¢Ã÷ÁËÕâÒ»ÐéαӦÓ㬣¬£¬£¬£¬£¬²¢½«Æä¹é×ïÓÚSIOµÄ×Ó¹«Ë¾ASIGINT¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬SIOºÍÆ»¹û¹«Ë¾¾ùδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£WhatsAppÒѽ«ÊÜÓ°ÏìµÄ200ÃûÓû§µÇ³ö£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÓû§ÏÂÔØ·Ç¹Ù·½¿Í»§¶Ë±£´æÒþ˽ºÍÇ徲Σº¦£¬£¬£¬£¬£¬£¬½¨Òéɾ³ýð³äÓ¦Óò¢×°Öùٷ½°æ±¾¡£¡£¡£SIOÔÚÆä¹ÙÍøÉÏ×Ô³ÆÊÇÖ´·¨²¿·Ö¡¢Õþ¸®»ú¹¹ÒÔ¼°¾¯Ô±ºÍÇ鱨»ú¹¹µÄ¡°ÏàÖúͬ°é¡±£¬£¬£¬£¬£¬£¬´ËǰÒÑÓÐÀàËÆÐÐΪ¼Í¼¡£¡£¡£È¥Ä꣬£¬£¬£¬£¬£¬TechCrunchÔø±¨µÀSIO¿ª·¢Á˶à¿îÖ²ÈëÌØ¹¤Èí¼þµÄ°²×¿Ó¦Óᣡ£¡£
https://therecord.media/whatsapp-warns-users-of-fake-app-used-for-spyware
3. CrystalRAT¶ñÒâÈí¼þ¼´Ð§ÀÍÉÏÏßTelegram
4ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬Ò»ÖÖÃûΪCrystalRATµÄÐÂÐͶñÒâÈí¼þ¼´Ð§ÀÍ£¨MaaS£©ÕýÔÚTelegramÉÏÍÆ¹ã£¬£¬£¬£¬£¬£¬ÌṩԶ³Ì»á¼û¡¢Êý¾ÝÇÔÈ¡¡¢¼üÅ̼ͼºÍ¼ôÌù°åÐ®ÖÆµÈ¹¦Ð§¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ1Ô·ºÆð£¬£¬£¬£¬£¬£¬½ÓÄÉ·Ö¼¶¶©ÔÄģʽ£¬£¬£¬£¬£¬£¬³ýÁËTelegramƵµÀÍ⣬£¬£¬£¬£¬£¬»¹Í¨¹ýרÃŵÄYouTubeÓªÏúƵµÀ¾ÙÐÐÍÆ¹ã¡£¡£¡£CrystalRATÌṩÁËÒ»¸öÓû§ÓѺõĿØÖÆÃæ°åºÍ×Ô¶¯»¯¹¹½¨¹¤¾ß£¬£¬£¬£¬£¬£¬Ö§³ÖµØÀí·â±Õ¡¢¿ÉÖ´ÐÐÎļþ×Ô½ç˵ºÍ·´ÆÊÎö¹¦Ð§¡£¡£¡£ÌìÉúµÄÓÐÓÃÔØºÉ¾ÓÉzlibѹËõ£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃChaCha20¶Ô³ÆÁ÷ÃÜÂë¾ÙÐмÓÃÜ¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýWebSocketÅþÁ¬µ½ÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬²¢·¢ËÍÖ÷»úÐÅÏ¢ÓÃÓÚѬȾ¸ú×Ù¡£¡£¡£ÏÖÔÚÆäÐÅÏ¢ÇÔÈ¡×é¼þÔÝʱ±»½ûÓ㬣¬£¬£¬£¬£¬ÕýÔÚ¾ÙÐÐÉý¼¶×¼±¸£¬£¬£¬£¬£¬£¬¸Ã×é¼þ¿Éͨ¹ýChromeElevator¹¤¾ßÒÔ¼°Yandex¡¢OperaµÈ»ùÓÚChromiumµÄä¯ÀÀÆ÷¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬Í¬Ê±´ÓSteam¡¢DiscordºÍTelegramµÈ×ÀÃæÓ¦ÓóÌÐòÍøÂçÊý¾Ý¡£¡£¡£Ô¶³Ì»á¼ûÄ£¿£¿£¿£¿éÖ§³Öͨ¹ýCMDÖ´ÐÐÏÂÁî¡¢ÉÏ´«/ÏÂÔØÎļþ¡¢ä¯ÀÀÎļþϵͳ£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÄÚÖÃVNCʵʱ¿ØÖÆ»úе¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹Äܲ¶»ñÂó¿Ë·çµÄÊÓÆµºÍÒôƵ£¬£¬£¬£¬£¬£¬Å䱸µÄ¼üÅ̼ͼÆ÷¿É½«»÷¼üʵʱ´«ÊäÖÁC2ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬¼ôÌù°å¹¤¾ßÔòʹÓÃÕýÔò±í´ïʽ¼ì²â¼ôÌù°åÖеÄÇ®°üµØµã²¢Ì滻Ϊ¹¥»÷ÕßÌṩµÄµØµã¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-crystalrat-malware-adds-rat-stealer-and-prankware-features/
4. TrueChaosÐж¯Ê¹ÓÃÁãÈÕÎó²î¹¥»÷TrueConfЧÀÍÆ÷
4ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓñàºÅΪCVE-2026-3502µÄÁãÈÕÎó²î¹¥»÷TrueConf¾Û»áЧÀÍÆ÷£¬£¬£¬£¬£¬£¬´Ó¶øÔÚËùÓÐÅþÁ¬µÄ¶ËµãÉÏÖ´ÐÐí§ÒâÎļþ¡£¡£¡£¸ÃÎó²îÑÏÖØË®Æ½ÆÀ¼¶ÎªÖеȣ¬£¬£¬£¬£¬£¬Ô´ÓÚÈí¼þ¸üлúÖÆÖÐȱÉÙÍêÕûÐÔ¼ì²é£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽ«Õýµ±¸üÐÂÌæ»»Îª¶ñÒâ±äÖÖ¡£¡£¡£TrueConfÊÇÒ»¸öÊÓÆµ¾Û»áƽ̨£¬£¬£¬£¬£¬£¬¿É×÷Ϊ×ÔÍйÜЧÀÍÆ÷ÔËÐУ¬£¬£¬£¬£¬£¬Í¨³£Îª¹Ø±ÕµÄÀëÏßÇéÐÎÉè¼Æ¡£¡£¡£CheckPointÑо¿Ö°Ô±×·×Ùµ½Ò»¸öÃûΪTrueChaosµÄ»î¶¯£¬£¬£¬£¬£¬£¬×Ô½ñÄêÄêÍ·ÒÔÀ´£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹ÓÃCVE-2026-3502Îó²î¶Ô¶«ÄÏÑÇÕþ¸®ÊµÌåÌᳫÁãÈÕ¹¥»÷¡£¡£¡£¹¥»÷ÕßÈô¿ØÖÆÁËÍâµØTrueConfЧÀÍÆ÷£¬£¬£¬£¬£¬£¬¿É½«Ô¤ÆÚ¸üаüÌæ»»Îªí§Òâ¿ÉÖ´ÐÐÎļþ²¢Î±×°³ÉÄ¿½ñÓ¦ÓóÌÐò°æ±¾£¬£¬£¬£¬£¬£¬·Ö·¢¸øËùÓÐÅþÁ¬µÄ¿Í»§¶Ë¡£¡£¡£ÓÉÓÚ¿Í»§¶Ëδ¾ÙÐÐÊʵ±ÑéÖ¤¼´ÐÅÈÎЧÀÍÆ÷ÌṩµÄ¸üУ¬£¬£¬£¬£¬£¬¶ñÒâÎļþ¿Éαװ³ÉÕýµ±TrueConf¸üжø±»×ª´ïºÍÖ´ÐС£¡£¡£¸ÃÎó²îÓ°ÏìTrueConf°æ±¾8.1.0ÖÁ8.5.2£¬£¬£¬£¬£¬£¬ÐÞ¸´³ÌÐòÓÚ2026Äê3ÔÂÔÚ8.5.3°æ±¾ÖÐÐû²¼¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-trueconf-zero-day-to-push-malicious-software-updates/
5. NoVoice°²×¿¶ñÒâÈí¼þ²ØÉíGoogle Play³¬50¿îÓ¦ÓÃ
4ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬Ò»ÖÖÃûΪNoVoiceµÄÐÂÐͰ²×¿¶ñÒâÈí¼þÔÚGoogle PlayÉϱ»·¢Ã÷£¬£¬£¬£¬£¬£¬Òþ²ØÔÚ50¶à¿îÀÛ¼ÆÏÂÔØÁ¿´ï230Íò´ÎµÄÓ¦ÓóÌÐòÖС£¡£¡£ÕâЩӦÓðüÀ¨ÕûÀí¹¤¾ß¡¢Í¼Æ¬¿âºÍÓÎÏ·£¬£¬£¬£¬£¬£¬ÍâòÉÏÎÞÐè¿ÉÒÉȨÏÞÇÒÌṩÕý³£¹¦Ð§¡£¡£¡£¾ÝMcAfeeÑо¿Ö°Ô±ÆÊÎö£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þʹÓÃ2016ÄêÖÁ2021Äê¼äÒÑÐÞ¸´µÄ¾É°æ°²×¿Îó²î£¬£¬£¬£¬£¬£¬ÊÔͼ»ñȡװ±¸rootȨÏÞ¡£¡£¡£Æô¶¯ÊÜѬȾӦÓú󣬣¬£¬£¬£¬£¬¶ñÒâÈí¼þ½«¼ÓÃÜÓÐÓÃÔØºÉÒþ²ØÔÚPNGͼÏñÎļþÖУ¬£¬£¬£¬£¬£¬ÌáÈ¡¼ÓÔØºóɨ³ýÖÐÐÄÎļþÒÔÏû³ýºÛ¼£¡£¡£¡£¹¥»÷Õß»á×èֹѬȾ±±¾©¡¢ÉîÛÚµÈÌØ¶¨µØÇø×°±¸£¬£¬£¬£¬£¬£¬²¢¶ÔÄ£ÄâÆ÷¡¢µ÷ÊÔÆ÷ºÍVPNʵÑé15Ïî¼ì²é¡£¡£¡£¶ñÒâÈí¼þÅþÁ¬ÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷ÍøÂç×°±¸ÐÅÏ¢£¬£¬£¬£¬£¬£¬Ã¿60ÃëÂÖѯһ´Î²¢ÏÂÔØÕë¶ÔÌØ¶¨×°±¸µÄÎó²îʹÓÃ×é¼þ¡£¡£¡£McAfee·¢Ã÷ÁË22¸öÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´Ë»ñÈ¡rootȨÏÞ²¢½ûÓÃSELinuxÇ¿ÖÆÖ´ÐУ¬£¬£¬£¬£¬£¬Ï÷Èõ×°±¸»ù±¾Çå¾²±£»£»£»£»£»£»£»¤¡£¡£¡£×°±¸±»rootºó£¬£¬£¬£¬£¬£¬Òªº¦ÏµÍ³¿â±»Ì滻Ϊhook°ü×°Æ÷£¬£¬£¬£¬£¬£¬×赲ϵͳŲÓò¢½«Ö´ÐÐÖØ¶¨ÏòÖÁ¹¥»÷´úÂë¡£¡£¡£ÔÚºóÉøÍ¸½×¶Î£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«¿ØÖÆ´úÂë×¢Èë×°±¸ÉÏÆô¶¯µÄÿ¸öÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬Ö÷Òª°²ÅÅÁ½¸ö×é¼þ£ºÒ»¸öÓÃÓÚ¾²Ä¬×°ÖûòÐ¶ÔØÓ¦Ó㬣¬£¬£¬£¬£¬ÁíÒ»¸öÔÚÈκÎÄÜ»á¼û»¥ÁªÍøµÄÓ¦ÓÃÖÐÔËÐУ¬£¬£¬£¬£¬£¬×÷ΪÖ÷ÒªÕë¶ÔWhatsAppÊý¾ÝÇÔÈ¡»úÖÆ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/
6. º¢Ö®±¦ÔâÍøÂç¹¥»÷ÖÂÓªÒµÖÐÖ¹
4ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬Íæ¾ßºÍÓÎÏ·¾ÞÍ·º¢Ö®±¦ÖÜÈý±¨¸æ³Æ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µ¼Ö²¿·ÖÓªÒµÁ÷³ÌÖÐÖ¹¡£¡£¡£Æ¾Ö¤Ìá½»¸øÃÀ¹ú֤ȯÉúÒâίԱ»áµÄÎļþ£¬£¬£¬£¬£¬£¬º¢Ö®±¦ÓÚ3ÔÂ28ÈÕ¼ì²âµ½ÆäÍøÂçÔ⵽δ¾ÊÚȨµÄ»á¼û£¬£¬£¬£¬£¬£¬×÷ΪÊÂÎñÏìÓ¦²½·¥µÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬²¿·ÖϵͳÒѱ»ÀëÏß¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¹«Ë¾Õý½èÖúÍâ²¿ÍøÂçÇ徲ר¼ÒµÄʵÁ¦Õö¿ªÊӲ죬£¬£¬£¬£¬£¬Ä¿µÄÖ®Ò»ÊÇÈ·¶¨´Ë´ÎÊÂÎñµÄËùÓÐÓ°Ïì¹æÄ££¬£¬£¬£¬£¬£¬°üÀ¨ÊÇ·ñÓÐÈκÎÎļþÔ⵽й¶¡£¡£¡£º¢Ö®±¦ÌåÏÖ£¬£¬£¬£¬£¬£¬¹«Ë¾ÒÑʵÑé²¢½«¼ÌÐøÊµÑéÓªÒµÒ»Á¬ÐÔÍýÏ룬£¬£¬£¬£¬£¬ÒÔÈ·±£ÔÚ½â¾öÄ¿½ñÇéÐεÄͬʱÄܹ»¼ÌÐø½ÓÊܶ©µ¥¡¢·¢»õºÍ¿ªÕ¹ÆäËûÒªº¦ÓªÒµ¡£¡£¡£ÉùÃ÷Ôö²¹³Æ£¬£¬£¬£¬£¬£¬ÔÚÇéÐÎÍêÈ«½â¾ö֮ǰ£¬£¬£¬£¬£¬£¬¿ÉÄÜÐèÒªÒ»Á¬ÊýÖÜʱ¼äʵÑéÕâЩÔÝʱ²½·¥£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܻᵼÖÂһЩÑÓÎ󡣡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÉÐÎÞÍøÂç·¸·¨ÍÅ»ïÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£º¢Ö®±¦ÌåÏÖ£¬£¬£¬£¬£¬£¬¹«Ë¾ÕýÔÚÆð¾¢ÔöǿϵͳÇå¾²£¬£¬£¬£¬£¬£¬²¢½«Æ¾Ö¤ÊÓ²ìЧ¹û½ÓÄÉÆäËû²½·¥£¬£¬£¬£¬£¬£¬°üÀ¨Ðû²¼ÐëÒªµÄ֪ͨ¡£¡£¡£
https://www.securityweek.com/toy-giant-hasbro-hit-by-cyberattack/


¾©¹«Íø°²±¸11010802024551ºÅ