Daily Tech Briefing
AI 科技速览
每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。
Ars Technica · 2026/7/30 20:57:22
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
AI 中文解读
俄罗斯黑客又出手了!这次瞄准的是微软Outlook的Exchange Server,利用一个“最高严重级”漏洞,在用户毫无察觉的情况下给服务器装后门、偷账号密码。安全公司Proofpoint发现,攻击者是与克里姆林宫有关的组织TA488,他们之前还攻击过Zimbra邮件系统,这次改用Exchange漏洞搞“半点击”攻击——不用你点任何链接,只要打开邮件就中招了。更厉害的是,黑客还动用了一种叫“OWAReaper”的新型浏览器后门,专门用来长期潜伏在网页版邮箱里。通俗说,就是黑客把邮箱系统当成了自己的“后花园”,而受害者完全不知情。对普通人来说,虽然这种国家级黑客很少专门盯个人,但如果你所在的公司、学校或政府机构用了Exchange Server且没打补丁,那你的工作邮件、内部资料都可能被悄悄翻走。尤其是有价值的商业机密或个人信息,一旦泄露可能带来连锁损失。好消息是,微软已经发布补丁,IT管理员赶紧更新就能堵住漏洞。总之,这次“只要你敢打开邮箱,黑客就敢进你系统”的玩法,再次提醒我们:及时更新软件,别让旧漏洞成为黑客的免费入场券。
Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday.
The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday. Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email service from Zimbra. The revelation that TA488 is also exploiting the Exchange Server vulnerability to install advanced malware when a user does nothing other than open an email sent to an Outlook Web Access (OWA) account has elevated the group’s profile and assessments of its abilities.
Doubling down
“TA488 is doubling down on the use of ‘half-click’ exploits—where opening the email is enough to trigger compromise—with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group’s tradecraft and capability,” Proofpoint researchers wrote. “This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA.”Read full article
Comments
分享
阅读原文 ↗