Bybit ÔâÊ·ÉÏ×î´ó¼ÓÃÜÇ®±Ò͵ÇÔ°¸£¬£¬£¬£¬£¬ºÚ¿ÍÉí·ÝÖ¸ÏòLazarus×éÖ¯
°ä²¼¹¦·ò 2025-02-241. Bybit ÔâÊ·ÉÏ×î´ó¼ÓÃÜÇ®±Ò͵ÇÔ°¸£¬£¬£¬£¬£¬ºÚ¿ÍÉí·ÝÖ¸ÏòLazarus×éÖ¯
2ÔÂ23ÈÕ£¬£¬£¬£¬£¬¼ÓÃÜÇ®±ÒÂòÂôËù Bybit ½üÆÚÔâ·êÁËÒ»´ÎǰËùδÓеĸ´ÔÓÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö¼ÛÖµÔ¼ 15 ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò±»µÁ£¬£¬£¬£¬£¬³ÉΪʷÉÏ×î´óµÄ¼ÓÃÜÇ®±Ò͵ÇÔ°¸¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý°Ñ³ÖÊðÃû½çÃæ£¬£¬£¬£¬£¬½« Bybit µÄ ETH ÀäÇ®°üÖеÄ×ʽð³Á¶¨Ïòµ½Î´ÖªµØÖ·¡£¡£¡£¡£¡£Ö»¹Ü Bybit µÄ°²È«ÍŶÓÔÚÓëÇø¿éÁ´È¡Ö¤×¨¼ÒºÍºÏ×÷ͬ°é»ý¼«µ÷²é´ËÊÂÎñ£¬£¬£¬£¬£¬µ«ÉÐδй©¾ßÌåµÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¾Ý´§Ä¦£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÁË Safe.global ƽ̨Óû§½çÃæÖеķì϶¡£¡£¡£¡£¡£Bybit Ê×ϯִÐйÙÏò¿Í»§±£ÕÏ£¬£¬£¬£¬£¬¼´±ã±»µÁ×ʽðÎÞ·¨×·»Ø£¬£¬£¬£¬£¬ÂòÂôËùÒ²½«Î¬³Ö³¥¸¶ÄÜÁ¦£¬£¬£¬£¬£¬²¢½«ÔÚ±ØÒªÊ±Ê¹ÓùýÇÅ´û¿îÈ·±£Óû§×ʽð¿ÉÓᣡ£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬Bybit Ç¿µ÷ËùÓÐÆäËûÀäÇ®°ü¾ù°²È«ÎÞÓÝ£¬£¬£¬£¬£¬ÔËÓª²»»áÖжϡ£¡£¡£¡£¡£ÍøÂ簲ȫ¹«Ë¾ Elliptic ºÍ Arkham Intelligence ¾ù½«Õâ´Î¹¥»÷¹é×ïÓÚÓ볯ÏÊÓÐ¹ØµÄ Lazarus APT ¼¯ÍÅ£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÔʹÓÃ×Ô½ç˵¶ñÒâÈí¼þ½øÐи´ÔÓ¹¥»÷¶øÎÅÃû£¬£¬£¬£¬£¬²¢ÉæÏÓ¶àÆðÕë¶ÔÒøÐкͼÓÃÜÇ®±ÒÂòÂôËùµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£Ö»¹Ü Bybit ÉÐδÕýʽȷÈϺڿÍÉí·Ý£¬£¬£¬£¬£¬µ«Õâ´ÎÊÂÎñÔÙ´Î͹ÏÔÁ˼ÓÃÜÇ®±ÒÁìÓòÃæ¶ÔµÄ°²È«ÌôÕ½¡£¡£¡£¡£¡£
https://securityaffairs.com/174514/cyber-crime/lazarus-stole-1-5b-from-bybit-cryptocurrency-heist.html
2. PayPalÐÂÐ͵ç×ÓÓʼþÚ¿Æ£ºÀûÓõØÖ·ÉèÖÃÓÕÆÔ¶³Ì½Ó¼ûȨÏÞ
2ÔÂ22ÈÕ£¬£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬£¬Ò»ÖÖÀûÓÃPayPalµç×ÓÓʼþµØÖ·ÉèÖÃÖ°ÄܵÄڿƼ¿Á©ÔÚ·çÐÓ×£¡£¡£¡£¡£Ú¿ÆÕßͨ¹ýÏòPayPalÕË»§Ôö³¤Ô̺¬ÐéαMacBook²É°ìÈ·ÈÏÐÅÏ¢µÄеØÖ·£¬£¬£¬£¬£¬´¥·¢PayPal·¢ËÍÈ·ÈÏÓʼþ¡£¡£¡£¡£¡£ÕâЩ¿´ËƺϷ¨µÄÓʼþÓÉ¡°service@paypal.com¡±·¢ËÍ£¬£¬£¬£¬£¬ÓÕÆÓû§²¦´òڿƵ绰ºÅÂë¡£¡£¡£¡£¡£Ò»µ©Óû§²¦´ò£¬£¬£¬£¬£¬Ú¿ÆÕß»áÐû³ÆÕË»§±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¢ÓÕµ¼Óû§ÏÂÔØ²¢ÔËÐÐÌØ¶¨Èí¼þÒÔ»ñȡԶ³Ì½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬ÕâЩÓʼþÏÖʵÉÏÊÇ·¢Ë͸øÓëÚ¿ÆÕß¹ØÁªµÄµç×ÓÓʼþµØÖ·£¬£¬£¬£¬£¬¸ÃµØÖ·»á×Ô¶¯½«Óʼþת·¢¸øÓʼþÁбíÖеÄËùÓгÉÔ±£¬£¬£¬£¬£¬¼´Ú¿ÆÖ¸±ê¡£¡£¡£¡£¡£ÓÉÓÚPayPal²»Ï޶ȵØÖ·×Ö¶Î×Ö·ûÊý£¬£¬£¬£¬£¬Ú¿ÆÕß¿ÉÄÜ×¢ÈëÚ¿ÆÐÅÏ¢¡£¡£¡£¡£¡£ÎªÁË·À±¸´ËÀàÚ¿Æ£¬£¬£¬£¬£¬Óû§Ó¦ºöÂÔÔ̺¬Ðéα²É°ìÈ·ÈϵÄPayPalÓʼþ£¬£¬£¬£¬£¬²¢²»Òª²¦´òÆäÖÐÌṩµÄµç»°ºÅÂë¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬PayPal±ØÒª²ÉÈ¡´ëÊ©Ï޶ȵØÖ·×Ö¶Î×Ö·ûÊý£¬£¬£¬£¬£¬ÒÔÔ¤·À´ËÀàÚ¿ÆÐÐΪµÄ²úÉú¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/
3. CS2½ÇÖð³ÉÚ¿ÆÐ°г¡£¡£¡£¡£¡£ºÓÎÏ·Íæ¼ÒÐ辯ÌèSteamÕÊ»§±»µÁ·çÏÕ
2ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýÀûÓ÷´¿Ö¾«Ó¢ 2 (CS2) µÄ´óÐͽÇÖ𣬣¬£¬£¬£¬ÈçIEM¿¨ÍÐά×È2025ºÍPGL¿Ë¬ÈÕ-Äɲ¨¿¨2025£¬£¬£¬£¬£¬Õë¶ÔÓÎÏ·Íæ¼ÒÖ´ÐÐÚ¿Æ£¬£¬£¬£¬£¬ÒâͼÇÔÈ¡ËûÃǵÄSteamÕÊ»§ºÍ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£Ö»¹ÜCS2ÒÑÍÆ³ö¶àÄ꣬£¬£¬£¬£¬µ«ÆäÍæ¼ÒÉçÇøºÍÖ°Òµ½ÏÁ¿¸ñ¾ÖÒÀÈ»ÖØ´óÇÒ»îÔ¾¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬CS2ÔÚSteamÉϵÄͬʱÔÚÏßÍæ¼ÒÊýÁ¿´ïµ½ÁËÐµĶ¥·å¡£¡£¡£¡£¡£Bitdefender Labs·¢ÏÖÁËÒ»ÏîÃûΪ¡°Streamjacking¡±µÄ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬Ú¿ÆÕßͨ¹ý¼ÙÒâ³ÛÃûCS2Íæ¼Ò£¬£¬£¬£¬£¬ÔÚYouTubeÖ±²¥ÖÐÐû´«¼ÙðµÄƤ·ôºÍ¼ÓÃÜÇ®±ÒÔùÆ·¡£¡£¡£¡£¡£ËûÃÇʹÓñ»½Ù³ÖµÄºÏ·¨YouTubeÕÊ»§£¬£¬£¬£¬£¬²¢Ñ»·²¥·Å¾ÉµÄÓÎÏ·»ÃæÒÔÓªÔìÖ±²¥·ÕΧ¡£¡£¡£¡£¡£ÕâЩÊÓÆµÖеĶþάÂë»òÁ´½Ó»á½«¹Û¶àµ¼Ïò¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬ÒªÇóËûÃÇʹÓÃSteamÕÊ»§µÇ¼ÒÔÁìÈ¡ÀñÎï»ò·¢ËͼÓÃÜÇ®±ÒÒÔ»ñÈ¡¸ß¶î»Ø±¨¡£¡£¡£¡£¡£Ò»µ©µÇ¼£¬£¬£¬£¬£¬Êܺ¦Õ߾ͻáÔÚ²»ÖªÇéµÄÇé¿öÏÂÊÚÓèÚ¿ÆÕß½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬µ¼ÖÂÓмÛÖµµÄƤ·ôºÍÎïÆ·±»µÁ£¬£¬£¬£¬£¬¼ÓÃÜÇ®±ÒÒ²»á±»Á¢¼´×ªÒÆÖÁÚ¿ÆÕß½ÚÔìµÄÇ®°ü¡£¡£¡£¡£¡£ÓÎÏ·Íæ¼ÒӦά³Ö¾¯Ì裬£¬£¬£¬£¬ºËʵÓë¹Ù·½µç×Ó¾º¼¼×éÖ¯µÄ¹ØÏµ£¬£¬£¬£¬£¬²¢¼¤»î¶à³ÁÉí·ÝÑéÖ¤¡¢ÆôÓÃSteam GuardŲ½âÀ·ÝÑéÖ¤Æ÷ÒÔ¼°¶¨ÆÚ²é³µÇ¼»î¶¯¡£¡£¡£¡£¡£ÔÚYouTubeÉÏ£¬£¬£¬£¬£¬Ö»ÅÔ¹Û¹Ù·½Ö°ÒµÇòÔ¹ØÊ»§µÄÊÓÆµ£¬£¬£¬£¬£¬²¢¶ÔÆäËûƵ·ÉϵÄÖ±²¥Î¬³ÖÒɻ󡣡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fake-cs2-tournament-streams-used-to-steal-crypto-steam-accounts/
4. SpyLend Android ¶ñÒâÈí¼þÔÚ Google Play ±»ÏÂÔØÁ˳¬ 10 Íò´Î
2ÔÂ21ÈÕ£¬£¬£¬£¬£¬Ò»¿îÃûΪSpyLend£¨ÓÖ³ÆFinance Simplified£©µÄAndroid¶ñÒâÈí¼þÀûÓ÷¨Ê½ÔÚGoogle PlayÉϱ»ÏÂÔØ³¬¹ý10Íò´Î£¬£¬£¬£¬£¬Ëü¼Ù×°³É½ðÈÚ¹¤¾ß£¬£¬£¬£¬£¬ÊµÔòÕë¶ÔÓ¡¶Å×û§Ö´Ðдò½ÙÐÔ´û¿î¡£¡£¡£¡£¡£¸ÃÀûÓÃÊôÓÚSpyLoan¶ñÒâÈí¼þ×飬£¬£¬£¬£¬Í¨¹ýÒªÇó¹ý¶àȨÏÞÇÔÈ¡Óû§Ó×ÎÒÊý¾Ý£¬£¬£¬£¬£¬ÈçÁªÏµÈË¡¢Í¨»°¼Í¼¡¢¶ÌÐÅ¡¢ÕÕÆ¬¡¢É豸µØÎ»µÈ¡£¡£¡£¡£¡£ÕâЩÊý¾Ý±»ÓÃÓÚɧÈÅ¡¢Ú²ÆºÍÀÕË÷Óû§£¬£¬£¬£¬£¬³ö¸ñÊǵ±Óû§Î´ÄÜÂú×㻹¿îÌõ¿îʱ¡£¡£¡£¡£¡£¸ÃÀûÓû¹Ðû³ÆÊÇ×¢²áµÄ·ÇÒøÐнðÈÚ¹«Ë¾£¬£¬£¬£¬£¬µ«ÊµÔò²»È»¡£¡£¡£¡£¡£ÎªÌӱܼì²â£¬£¬£¬£¬£¬Ëü¼ÓÔØWebView½«Óû§³Á¶¨Ïòµ½±í²¿ÍøÕ¾ÏÂÔØ´û¿îÀûÓÃAPK¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»î¶¯×¨ÃÅÕë¶ÔÓ¡¶Å×û§£¬£¬£¬£¬£¬²¢ÇÔÈ¡Ô̺¬Ãô¸ÐÓ×ÎÒÐÅÏ¢ÔÚÄڵĶàÖÖÊý¾Ý£¬£¬£¬£¬£¬ÓÃÓÚÚ²ÆÀÕË÷»ò½ðÈÚڲơ£¡£¡£¡£¡£Ö»¹Ü¸ÃÀûÓÃÒÑ´ÓGoogle PlayÒÆ³ý£¬£¬£¬£¬£¬µ«ÈÔ¿ÉÄܳÖÐøÔËÐв¢ÍøÂçÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ÈôÒÉ»óÉ豸±»Ï°È¾£¬£¬£¬£¬£¬ÇëÁ¢¼´É¾³ýÓйØÀûÓ㬣¬£¬£¬£¬³ÁÖÃȨÏÞ£¬£¬£¬£¬£¬¸ü¸ÄÃÜÂ룬£¬£¬£¬£¬²¢Ö´ÐÐÉ豸ɨÃè¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬È·±£GoogleµÄPlay Protect¹¤¾ß´¦Óڻ״̬£¬£¬£¬£¬£¬ÒÔ¼ì²â²¢×èÖ¹¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/spylend-android-malware-downloaded-100-000-times-from-google-play/
5. CISA½«Craft CMS¸ßÑϳÁÐÔ°²È«·ì϶CVE-2025-23209²ÎÓëKEVĿ¼
2ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Ó°ÏìCraftÄÚÈÝÖÎÀíϵͳ£¨CMS£©µÄ¸ßÑϳÁÐÔ°²È«·ì϶CVE-2025-23209Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ÖÓ×£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬£¬£¬£¬£¬Ó°ÏìCraft CMS°æ±¾4ºÍ5£¬£¬£¬£¬£¬¾ßÌåΪ°æ¼¼ÇÉÓòÔÚ>= 4.0.0-RC1, < 4.13.8ºÍ>= 5.0.0-RC1, < 5.5.5Ö®¼ä¡£¡£¡£¡£¡£CISAÖ¸³ö£¬£¬£¬£¬£¬ÓÉÓÚÒ×Êܹ¥»÷µÄ°æ±¾ÒѾΣ¼°Óû§°²È«ÃÜÔ¿£¬£¬£¬£¬£¬Craft CMS´æÔÚ´úÂë×¢Èë·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£ÏîÄ¿ÊØ»¤ÈËÔ±ÒÑÔÚ2024Äê12ÔÂÏÂÑ®°ä²¼µÄ°æ±¾4.13.8ºÍ5.5.8Öнâ¾öÁ˸÷ì϶¡£¡£¡£¡£¡£Craft CMSÔÚGitHubÉϰ䲼µÄ²¼¸æÖÐÌáµ½£¬£¬£¬£¬£¬ËùÓÐ佨²¹ÇÒ°²È«ÃÜÔ¿±»Ð¹Â¶µÄ°æ±¾³ÇÊÐÊܵ½¸Ã°²È«È±µãµÄÓ°Ï죬£¬£¬£¬£¬²¢½¨ÒéÎÞ·¨¸üе½½¨²¹°æ±¾µÄÓû§ÂÖ»»°²È«ÃÜÔ¿²¢È·±£ÆäÒþÖÔÒÔ»º½âÎÊÌâ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Áª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹±»½¨ÒéÔÚ2025Äê3ÔÂ13ÈÕ֮ǰÀûÓñØÒªµÄ½¨¸´·¨Ê½¡£¡£¡£¡£¡£
https://thehackernews.com/2025/02/cisa-flags-craft-cms-vulnerability-cve.html
6. CISA½«Microsoft Power Pages·ì϶CVE-2025-24989²ÎÓëKEVĿ¼
2ÔÂ23ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Microsoft Power PagesµÄÒ»¸ö¸ßÑϳÁÐÔ·ì϶£¨±àºÅΪCVE-2025-24989£¬£¬£¬£¬£¬CVSS·ÖÊýΪ8.2£©Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ÖÓ×£¡£¡£¡£¡£¸Ã·ì϶ÊôÓÚ²»µ±½Ó¼û½ÚÔì·ì϶£¬£¬£¬£¬£¬ÔÊÐíδ¾ÊÚȨµÄ¹¥»÷Õßͨ¹ýÍøÂçÌáÉýȨÏÞ£¬£¬£¬£¬£¬¿ÉÄÜÈÆ¹ýÓû§×¢²á½ÚÔì¡£¡£¡£¡£¡£´Ë·ì϶ÓÉ΢ÈíµÄRaj Kumar»ã±¨£¬£¬£¬£¬£¬Î¢ÈíÒÑÈ·ÈÏ´Ë·ì϶ÔÚ±»»ý¼«ÀûÓ㬣¬£¬£¬£¬²¢°ä²¼Á˲¼¸æÍ¨ÖªÊÜÓ°ÏìµÄ¿Í»§²é³ÍøÕ¾²¢²ÉÈ¡ËãÕÊ´ëÊ©¡£¡£¡£¡£¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸ÁBOD£©22-01£¬£¬£¬£¬£¬Áª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹±ØÐëÔÚ½ØÖ¹ÈÕÆÚǰ½â¾öÒÑ·¢Ïֵķì϶£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»¤ÆäÍøÂçÃâÊܹ¥»÷¡£¡£¡£¡£¡£CISAÒªÇóÁª¹ú»ú¹¹ÔÚ2025Äê3ÔÂ21ÈÕ֮ǰ½¨¸´´Ë·ì϶£¬£¬£¬£¬£¬Í¬Ê±×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²é¸ÃĿ¼²¢½â¾öÆä»ù´¡ÉèÊ©Öеķì϶£¬£¬£¬£¬£¬ÒÔ½µµÍ°²È«·çÏÕ¡£¡£¡£¡£¡£
https://securityaffairs.com/174541/hacking/u-s-cisa-adds-microsoft-power-pages-flaw-known-exploited-vulnerabilities-catalog.html


¾©¹«Íø°²±¸11010802024551ºÅ