ºÚ¿ÍÐû³Æ¹«¹²Æû³µÔâÈëÇÖ£¬µ«Î´ÄÜÌṩ֤¾Ý
°ä²¼¹¦·ò 2025-06-041. ºÚ¿ÍÐû³Æ¹«¹²Æû³µÔâÈëÇÖ£¬µ«Î´ÄÜÌṩ֤¾Ý
6ÔÂ2ÈÕ£¬µÂ¹úÆû³µ¾ÞÍ·¹«¹²Æû³µ¼¯Íųʴ˿ÌÀÕË÷Èí¼þ¼¯ÍÅStormousµÄ°µÍøÐ¹ÃÜÍøÕ¾ÉÏ£¬Òý·¢ÁË¶ÔÆäÊý¾Ý°²È«µÄ¹Ø×¢¡£¹«¹²Æû³µ¼¯ÍÅÓÚ5Ôµ×Åû¶ÁËÓë¸ÃÀÕË÷Èí¼þÍÅ»ïµÄÁªÏµ£¬²¢Ö¸³öÍþвÐÐΪÕßÐû³ÆÄܽӼûÓû§ÕÊ»§Êý¾Ý¡¢Éí·ÝÑéÖ¤ÁîÅÆµÈÃô¸ÐÐÅÏ¢¡£È»¶ø£¬×êÑÐÈËԱĿǰÎÞ·¨È·ÈϹ«¹²Æû³µ¼¯ÍŵÄÊý¾ÝÊÇ·ñ±»ÇÔÈ¡¡£StormousÀÕË÷Èí¼þÍÅ»ïÔÚ°µÍøÐû³Æ½«ÔÚ¼¸ÌìÄÚ°ä²¼¹«Ë¾Êý¾Ý£¬ÕâÊÇÆä¹ßÓõÄʩѹ¼¿Á©£¬Í¨³£ÍøÂç·¸×ï·Ö×Ó»á°ä²¼Êý¾ÝÑù±¾ÒÔÖ¤Ã÷Æä¿ÉÐŶȣ¬µ«Õâ´Î¸ÃÍÅ»ï½ö·ÖÏíÁËÎÞЧÁ´½Ó£¬Î´ÌṩÓмÛÖµÄÚÈÝ¡£Ö»¹ÜÈç´Ë£¬Stormous×÷ΪµØÏÂÀÕË÷Èí¼þÁìÓòµÄ³ÛÃû²Î¼ÓÕߣ¬Õâ´ÎÐÐΪ¿ÉÄÜÖ¼ÔÚÏò¹«¹²Æû³µ¼¯ÍÅʩѹ£¬ÆÈʹÆäÂú×ãÊê½ðÒªÇó¡£Ò»µ©Êý¾Ýй¶µÃµ½Ö¤Êµ£¬½«Î£¼°¹«Ë¾Óû§£¬¿ÉÄܵ¼ÖÂÕË»§±»µÁºÍδ¾ÊÚȨµÄ½Ó¼û³¢ÊÔ£¬Í¬Ê±ÉæÏÓй¶µÄÓ×ÎÒÐÅÏ¢Ò²¿ÉÄÜΣ¼°ÒþÖÔ¡£StormousÀÕË÷Èí¼þÍÅ»ï×Ô2022Äê³õ´Î±»·¢ÏÖÒÔÀ´£¬ÒѳÉΪ¸ÃÁìÓòµÄ¾Ñé·á˶²Î¼ÓÕߣ¬¸ÃÍÅ»ïÔÚ´Óǰ12¸öÔÂÄÚÖÁÉÙ¹¥»÷ÁË34¸ö×éÖ¯¡£Ä¿Ç°£¬¹«¹²Æû³µ¼¯ÍÅÉÐδ¾ÍÕâ´ÎÊÂÎñ°ä·¢½øÒ»²½ÉêÃ÷£¬¸÷¸ÕÕýÇ×êǹØ×¢ÊÂ̬·¢Õ¹¡£
https://cybernews.com/security/volkswagen-data-breach-claim-lacks-evidence/
2. MainStreetÒøÐй©¸øÉÌÔâ¹¥»÷Ö¿ͻ§ÐÅϢй¶
6ÔÂ3ÈÕ£¬ÃÀ¹úMainStreetÒøÐÐÅû¶ÆäºÏ×÷¹©¸øÉÌÔâ·êÍøÂç¹¥»÷£¬µ¼ÖÂÔ¼5%µÄ¿Í»§Ãô¸ÐÐÅϢй¶¡£¸ÃÐÐÔÚÌá½»¸øÃÀ¹úÖ¤½»»á£¨SEC£©µÄÎļþÖаµÊ¾£¬3Ô»ñÖª¹©¸øÉÌϵͳ±»ÈëÇֺ󣬵±¼´ÖÕÖ¹ÁËÓë¸Ã¹©¸øÉ̵ÄÈ«ÊýºÏ×÷£¬²¢ÓÚ4ÔÂÏÂѮʵÏÖÊÂÎñÁìÓòÉó²é£¬µ«Î´»ØÓ¦¾ßÌåÊܺ¦ÈËÊý¼°ÐÅÏ¢ÀàÐ͵ÄÖÊѯ¡£µ÷²éÈ·ÈÏÒøÐÐ×ÔÉíϵͳδÊÜÈëÇÖ£¬¿Í»§ÕË»§×ʽð°²È«ÎÞÓÝ£¬ÒøÐÐÒÑÓÚ5ÔÂ26ÈÕ֪ͨ¼à¹Ü»ú¹¹¼°¿Í»§£¬²¢ÎªÊÜÓ°Ïì¿Í»§³ÉÁ¢¿ÉÒɻ¼à²âϵͳ¡£ÒøÐÐÉêÃ÷¸ÃÊÂÎñδ¶ÔÆäÔËÓª²úÉú³Á´óÓ°Ï죬´ÓÆä×îвƱ¨À´¿´£¬´æ¿îÔ¼19ÒÚÃÀÔª£¬¾»ÀûÈó250ÍòÃÀÔª£¬Óë2024Äê³Ô¿÷998ÍòÃÀÔªµÄÇé¿öÏà±ÈÒÑÓиÄÉÆ¡£Õâ´ÎÅû¶ÕýÖµÃÀ¹úÎå´óÒøÐÐлá½áºÏÖº¯SECÒªÇó°Î³ýÍøÂ簲ȫÊÂÎñÇ¿ÔìÅû¶»®¶¨Ö®¼Ê£¬¸Ã¹æÕÂ×Ô2023ÄêÉúЧÒÔÀ´£¬Ò»ÏòÊܵ½¹ú»áÓëÒøÐÐÒµµÄ±¨¸´£¬±»Ö¸Ôö³¤ºÏ¹æ·çÏճɱ¾£¬Î´ÄÜÌṩÓÐЧͶ×ʾö²ßÐÅÏ¢£¬·´¶ø¡°¹ÊÕϱ¾Ç®ÐγɻúÔ족¡£
https://therecord.media/Main-street-cyber-incident-bank
3. ºÏ¹æ×Ô¶¯»¯ÉÌVantaÈí¼þ·ì϶Ö¿ͻ§Êý¾Ýй¶
6ÔÂ3ÈÕ£¬ºÏ¹æ×Ô¶¯»¯ÌṩÉÌVantaÈ·ÈϲúÉúÁËһ·³Á´óÈí¼þ·ì϶µ¼ÖµÄÊý¾Ýй¶ÊÂÎñ£¬Êý°ÙÃû¿Í»§Êܵ½Ó°Ïì¡£VantaÒÔÔ®ÊÔìóÒµÖÎÀí°²È«ºÍºÏ¹æÐÔÖø³Æ£¬È»¶øÕâ´ÎÈ´ÒòÍøÂ簲ȫÎÊÌâÏÝÈë·çÀË¡£5ÔÂ26ÈÕ£¬VantaÍŶӷ¢ÏÖÕâÒ»ÑϳÁÎÊÌâ¡£ÓÉÓÚ²úÆ·µ÷»»ÒýÆðµÄ´úÂëÃýÎó£¬Ãô¸ÐÔ±¹¤Êý¾Ý¡¢ÕË»§ÉèÖ÷½Ê½¡¢Ë«³É·ÖÉí·ÝÑéÖ¤£¨MFA£©Ê¹ÓÃÏêÇé¼°¹¤¾ßÉèÏàÐÅÏ¢µÈ±»¡°ÃýÎ󵨵¼È롱µ½ÆäËû¿Í»§ÕË»§¡£Vanta°µÊ¾¡°Ö»Óв»µ½4%µÄ¿Í»§¡±Êܵ½Ó°Ï죬µ«ÕâÈÔÒâζ×ÅÊý°Ù¼ÒÆóÒµÊý¾Ýй¶¡£VantaÊ×ϯ²úÆ·¹ÙJeremy Epling֤ʵÁËÕâ´ÎÊý¾Ýй¶ÊÂÎñ£¬²¢Ö¸³ö¡°²»µ½20%µÄµÚÈý·½¼¯³ÉÊý¾Ý×Ó¼¯Â¶³ö¸øÁËÆäËûVanta¿Í»§¡±¡£VantaÒÑÆðͷ֪ͨÊÜÓ°Ïì¿Í»§£¬·î¸æÆäÔ±¹¤ÕÊ»§Êý¾Ý±»ÃýÎó²åÈëµ½ÆäËû¿Í»§Ê·ýÖС£·¢ÏÖ´ËÎÊÌâºó£¬Vantaµ±¼´»Ø¹öÁ˵÷»»²¢Æô¶¯½¨¸´¹¤×÷£¬´òËãÔÚ6ÔÂ4ÈÕǰʵÏÖ½¨¸´£¬ËùÓÐÊÜÓ°ÏìµÄ¿Í»§¶¼ÒÑÊÕµ½Í¨Öª£¬¿Í»§Ö§³ÖÍŶÓÔÚ½â´ðÒÉÄѺÍÒªÇó¡£ÎªÔ¤·ÀÀàËÆÊÂÎñÔٴβúÉú£¬VantaÔÚ¸üеÚÈý·½¼¯³ÉAPI²¢¸Ä½ø½Ó¼û½ÚÔì²âÊÔ¡£
https://hackread.com/code-bug-compliance-vanta-data-leak-customer-clients/
4. µÂ¿ËÈøË¹Ïû»¯×¨¿ÆÒ½ÔºÔâInterLockÀÕË÷Èí¼þ¹¥»÷
6ÔÂ3ÈÕ£¬InterLockÀÕË÷Èí¼þÐ¹Â©ÍøÕ¾½üÆÚ½«Texas Digestive Specialists£¨µÂ¿ËÈøË¹Ïû»¯×¨¿ÆÒ½Éú¼¯ÍÅ£©ÁÐÈëÆäй©ÁÐ±í£¬Ðû³ÆÒÑÇÔÈ¡²¢Ð¹Â©Á˸ÃÒ½ÁƼ¯ÍÅ263GBµÄÊý¾Ý£¬Éæ¼°16920¸öÎļþ¼ÐºÍ215245¸öÎļþ¡£DataBreaches¶ÔÊý¾Ý¼¯½øÐÐÁ˳éÑùµ÷²é£¬ËäÔÚ¸ÃÒ½ÁƼ¯ÍŹÙÍøÎ´·¢ÏÖÒì³£»òй¶ÐÅÏ¢£¬µ«·¢ÏÖInterLockÒѼÓÃÜÎļþ£¬ÇҺܶàÔ̺¬Êܱ£»¤½¡È«ÐÅÏ¢£¨PHI£©µÄÎļþΪ³¢ÊÔÊÒ²¡Àí»ã±¨µÄ.pdfÎļþ¡£ÕâЩ³¢ÊÔÊһ㱨¾ßÌå¼Í¼ÁË»¼ÕßµÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢²é³ÈÕÆÚ¡¢Óйز¡Ê·ºÍ²é³Á˾֣¬ÔÚÒ»¸öѹËõµµ°¸Öоͷ¢ÏÖÁ˳¬¹ý2Íò·Ý´ËÀà»ã±¨£¬¹¦·ò¿ç¶È´Ó2023Äê8Ôµ½2025ËêÊ×£¬ÁíÒ»¸öµµ°¸»¹Ô̺¬375Ò³¹ØÓÚ2024Ä겿ÃŹ¦·òµãÖ¸¶¨»¼ÕߵIJ¡Àí»ã±¨£¬ÇÒËùÓл㱨¾ùÓ¡Óе¿ËÈøË¹Ïû»¯×¨¿ÆÒ½ÉúµÄÑöÃæ¡£µÂ¿ËÈøË¹Ïû»¯×¨¿ÆÒ½ÔºÎª³ÉÈ˺ͶùͯÌṩҽÁÆºÍ±í¿Æ·þÎñ£¬Ôڵ¿ËÈøË¹ÖÝÉèÓÐÈý¸öÕïËù¡£DataBreachesÒÑÏò¸ÃÒ½Ôº·¢ËÍÁªÏµ±í¸ñѯÎÊÆä¶ÔÒÉËÆÀÕË÷Èí¼þ¹¥»÷µÄ»ØÓ¦£¬µ«½ØÖÁ·¢¸å£¬Ò½ÔºÉÐδ»Ø¸´£¬Ò²Î´¾ÍÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©»òµÂ¿ËÈøË¹ÖÝ×ܼì²ì³¤°ì¹«ÊҵĹ«¹²Î¥¹æ¹¤¾ßÌá½»Èκλ㱨¡£
https://databreaches.net/2025/06/03/texas-gastroenterology-and-surgical-practice-victim-of-ransomware-attack/
5. Ó¡¶ÈÔÓ»õÅäËÍKiranaProÔâºÚ¿Í¹¥»÷ÖÂÊý¾Ý±»Çå
6ÔÂ3ÈÕ£¬Ó¡¶ÈÔÓ»õÅäËͲݴ´¹«Ë¾KiranaProÔâ·êºÚ¿Í¹¥»÷£¬Ëùº±¼û¾Ý±»¶Ï¸ù£¬ÆäÊ×´´ÈËDeepak Ravindran֤ʵÁËÕâÒ»ÐÂÎÅ¡£±»Ïú»ÙµÄÊý¾Ýº¸ÇÀûÓ÷¨Ê½´úÂë¡¢·þÎñÆ÷ÐÅÏ¢ÒÔ¼°´óÁ¿Ãô¸Ð¿Í»§ÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢ÓʼĵØÖ·ºÍ¸¶¿î¾ßÌåÐÅÏ¢¡£¸Ã¹«Ë¾µÄÀûÓ÷¨Ê½ËäÈÔÔÚÏߣ¬µ«ÒÑÎÞ·¨´¦Öö©µ¥¡£KiranaProÓÚ2024Äê12ÔÂÍÆ³ö£¬ÊÇÓ¡¶ÈµÐÔÖÊý×ÖÉÌÎñÊ¢¿ªÍøÂçÉϵÄÂò¼ÒÀûÓ÷¨Ê½£¬ÔÊÐí¿Í»§´Ó±¾µØÉ̵êºÍ×ó½ü³¬ÊвɰìÔÓ»õ£¬Õ¼ÓÐ5.5ÍòÃû¿Í»§£¬ÆäÖÐ3ÍòÖÁ3.5ÍòÃû»îÔ¾Âò¼Ò±é²¼50¸ö³ÇÊУ¬ÖðÈÕ×ܼÆÏµ¥2000±Ê¡£¸Ã¹«Ë¾Ìṩ»ùÓÚÓïÒôµÄ½çÃæ£¬Ö§³Ö¶àÖÖ˵»°Ïµ¥¡£È»¶ø£¬5ÔÂ26ÈÕ£¬KiranaPro¸ß¹ÜµÇ¼ÑÇÂíÑ·ÍøÂç·þÎñ£¨AWS£©ÕË»§Ê±·¢ÏÖÒì³££¬ºÚ¿Í³É¹¦½Ó¼ûÁËÆäÔÚAWSºÍGitHubÉϵĸùÕË»§¡£Ê×ϯ¼¼Êõ¹ÙSaurav KumarÖ¸³ö£¬¹¥»÷²úÉúÔÚ5ÔÂ24ÈÕÖÁ25ÈÕ×óÓÒ£¬ÆäʱAWSÕË»§µÄ¶à³É·ÖÉí·ÝÑéÖ¤´úÂë±»¸ü¸Ä£¬ËùÓÐÔÊÐí¿Í»§½Ó¼ûÐé¹¹ÍÆËã»úÔËÐÐÀûÓ÷¨Ê½µÄEC2·þÎñ±»É¾³ý£¬ÇÒ¹«Ë¾ÎÞ·¨»ñÈ¡ÈκÎÈÕÖ¾£¬ÓÉÓÚ²»×ã¸ùÕË»§È¨ÏÞ¡£Ravindran°µÊ¾£¬KiranaProÒÑÁªÏµGitHubÖ§³ÖÍŶӣ¬ÐÖú¼ø±ðºÚ¿ÍIPµØÖ·ºÍÆäËû¹¥»÷ºÛ¼££¬²¢ÔÚ¶Ôǰ¹ÍÔ±Ìá¸æ×´ËÏ£¬³ÆÆäδÌá½»´ú¼ûGitHubÕË»§µÄƾ֤¡£Ä¿Ç°£¬¹¥»÷¾ßÌ巽ʽÉв»Ã÷ÏÔ£¬µ«½üÄêÀ´Ò»Ð©´óÐÍÍøÂç¹¥»÷¶àÓÉÆ¾Ö¤ÍµÇÔÒýÆð¡£
https://techcrunch.com/2025/06/03/indian-grocery-startup-kiranapro-was-hacked-and-its-servers-deleted-ceo-confirms/
6. ¶ñÒâÈí¼þCrocodilusÔö³¤ÐéαÁªÏµÈ˺ýŪȫÇòÓû§
6ÔÂ3ÈÕ£¬×îа桰Crocodilus¡±Android¶ñÒâÈí¼þ½ø»¯£¬ÍþвÉý¼¶¡£¸Ã¶ñÒâÈí¼þÓÚ2025Äê3ÔÂÏÂÑ®±»Threat Fabric×êÑÐÈËÔ±³õ´Î¼Í¼£¬ÔçÆÚ°æ±¾ÒѾ߱¸¿í·ºÊý¾Ý͵ÇÔºÍÔ¶³Ì½ÚÔìÖ°ÄÜ£¬»¹Í¨¹ýÐéαÃýÎóÐÂÎŽøÐÐÉç»á¹¤³Ì³¢ÊÔ£¬ÓÕµ¼Óû§Ð¹Â¶¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿£¬Æäʱ½öÔÚÍÁ¶úÆäÓÐÓ×¹æÄ£»î¶¯¡£Èç½ñ£¬Threat Fabric³ÖÐø¼à¿Ø·¢ÏÖ£¬CrocodilusÒѽ«Ö¸±êÁìÓòÀ©´óÖÁÈ«Çò¡£×îа汾ÒýÈëлúÔ죬ÔÚÊÜϰȾÉ豸ÁªÏµÈËÁбíÖÐÔö³¤ÐéαÁªÏµÈË£¬µ±Êܺ¦Õß½Óµ½ÍþвÐÐΪÕߵ绰ʱ£¬É豸»áÏÔʾÐéαÁªÏµÈËÐÕÃû¶ø·ÇÀ´µçÕßID£¬ÍþвÐÐΪÕ߿ɽè´Ë¼ÙÒâÒøÐÓ×¢¹«Ë¾»òÇ×ÓÑ£¬Ê¹Í¨»°¸ü¾ß¹Æ»óÐÔ£¬´Ë²Ù×÷ÔÚÊÕµ½Ìض¨ÊýÁîʱ´¥·¢£¬Í¨¹ý±à³Ì·½Ê½´´½¨Ð±¾µØÁªÏµÈË¡£´Ë±í£¬Ð°汾»¹Í¨¹ý´úÂë´ò°üºÍ¶î±íXOR¼ÓÃÜÌáÉýÌӱܹ¥»÷ÄÜÁ¦£¬´úÂë¾í»ýºÍ¾À²øÊ¹ÄæÏò¹¤³Ì¸üÄÑÌ⣬»¹ÐÂÔö±¾µØ½âÎö±»µÁÊý¾ÝÖ°ÄÜ£¬ÒÔʵÏÖ¸ü¸ßÖÊÁ¿µÄÊý¾ÝÍøÂç¡£CrocodilusµÄ¼±¾ç½ø»¯ÏÔʾ³öÆä¶ÔÉç»á¹¤³ÌѧµÄÉî¶ÈʹÓ㬳ÉΪһÖÖ³ö¸ñΣÏյĶñÒâÈí¼þ¡£¼øÓÚÆäÍþв£¬½¨ÒéAndroidÓû§ÏÂÔØÈí¼þʱ¶ÔÖÅʹÓÃGoogle Play»ò¿ÉÐÅÈεİ䲼ÉÌ£¬È·±£Play ProtectʼÖÕ´¦ÓÚ¼¤»î״̬£¬²¢¾¡Á¿Ï÷¼õʹÓÃÀûÓ÷¨Ê½µÄÊýÁ¿£¬ÒÔ½µµÍϰȾ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/android-malware-crocodilus-adds-fake-contacts-to-spoof-trusted-callers/


¾©¹«Íø°²±¸11010802024551ºÅ