Mount RogersÉúÀí½¡È«»ú¹¹ÔâINC RansomÀÕË÷ÍŻ﹥»÷

°ä²¼¹¦·ò 2025-06-13

1. Mount RogersÉúÀí½¡È«»ú¹¹ÔâINC RansomÀÕË÷ÍŻ﹥»÷


6ÔÂ11ÈÕ £¬Mount RogersÉçÇø·þÎñ»ú¹¹£¨Ò»¼ÒÉúÀí½¡È«·þÎñÌṩÉÌ£©½üÈճʴ˿ÌÀÕË÷ÍÅ»ïINC RansomµÄ°µÍøÐ¹ÃÜÍøÕ¾ÉÏ £¬¹¥»÷ÕßÐû³ÆÒÑ´ÓÆäϵͳÖÐÇÔÈ¡´óÁ¿ÒþÖÔÊý¾Ý¡£Mount RogersÖØÒªÌṩÉúÀí½¡È«¡¢·¢Óý×è°­¼°Ò©ÎïÀÄÓÃÒ½ÖηþÎñ¡£ÎªÖ¤Ã÷¹¥»÷µÄÓÐЧÐÔ £¬INC Ransom¹«¿ªÁ˲¿ÃÅÑù±¾Êý¾Ý £¬Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢×¡Ö·¡¢Ð½×ʵ¥¡¢·¢Æ±µ¥¾Ý¡¢Ó×ÎÒÓÊÏä¡¢ÄÚ²¿Í¨Ñ¶¼°±£ÃܺÍ̸µÈ¡£Ö»¹ÜÕâЩÊý¾ÝµÄÃô¸ÐÐÔÓÐÏÞ £¬µ«¹¥»÷ÕßÈÔ¿ÉÀûÓÃÆä½øÐÐÍøÂç´¹µö»òÉí·Ý͵ÇÔ £¬Ð½×ʵ¥ºÍÄÚ²¿Îļþ¸ü¿ÉÄܱ»ÓÃÓÚÉç»á¹¤³Ì¹¥»÷ £¬½øÒ»²½ÉøÈëÆóҵϵͳ¡£Õâ´ÎÊý¾Ýй¶»ò½«ÑϳÁÇÖº¦Mount RogersµÄÃûÓþ £¬²¢Òý·¢Ë¾·¨·çÏÕ¡£INC Ransom×÷Ϊµ±Ç°×î»îÔ¾µÄÀÕË÷×éÖ¯Ö®Ò» £¬×Ô2023Äê7Ô³õ´ÎÏÖÉíÒÔÀ´ £¬¹¥»÷Ö¸±ê³ÖÐøÉý¼¶ £¬Êܺ¦Õߺ­¸Ç¶à¸öÁìÓò¡£¾Ý°µÍø¼à²â¹¤¾ßͳ¼Æ £¬´Óǰ12¸öÔÂÄÚ £¬¸Ã×éÖ¯ÒÑÀۼƹ¥»÷163¼Ò»ú¹¹¡£


https://cybernews.com/security/mount-rogers-ransomware-attack/


2. GonnaOrderƽ̨ÒòÅäÖÃÃýÎóµ¼ÖÂÊý¾Ýй¶


6ÔÂ11ÈÕ £¬×ܲ¿Î»ÓÚÅ·ÖÞµÄʳƷÅäËÍÆ½Ì¨GonnaOrderÒòKafka BrokerÊ·ýÅäÖÃÃýÎó £¬µ¼ÖÂÊýǧÈËÓ×ÎÒÐÅϢй¶¡£×êÑÐÍŶӷ¢ÏÖ £¬¸Ãƽ̨һ¸ö²»Êܱ£»¤µÄÊ·ý½«ÊµÊ±¶©µ¥ÐÅϢ¶³ö¸ø¹«¼Ò £¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢¼Òͥסַ¼°¶©µ¥¾ßÌåÐÅÏ¢µÈÃô¸ÐÊý¾Ý¡£¾Ý¹À¼Æ £¬³¬¹ýÁ½Ç§Ãû¶ÀÁ¢¿Í»§µÄ¾ßÌåÐÅÏ¢Ôڶ̶ÌÒ»Ó×ʱÄھͱ»Ð¹Â¶ £¬¶ø¸üÁîÈËÓÇÓôµÄÊÇ £¬¸ÃÊ·ý×Ô2022Äê8ÔÂÆð¿ÉÄܾÍÒ»Ïò´¦ÓÚÊ¢¿ª×´Ì¬ £¬ÕâÒâζ×ŶñÒâÐÐΪÕß¿ÉÄÜÒÑ»ñÈ¡Êý°ÙÍò¿Í»§µÄÊý¾Ý¡£Õâ´Îй¶ӰÏìÁËÅ·ÖÞ¶à¸ö¹ú¶ÈµÄ²Í¹Ý¡¢¾Æ°É¡¢¾ÆµêºÍÓ×É̵êµÄ¹Ë¿Í £¬ÖØÒªÎ»ÓÚÓ¢¹ú¡¢±ÈÀûʱ¡¢Ï£À°¡¢µÂ¹úºÍºÉÀ¼µÈµØ¡£Ö»¹ÜKafkaƽּ̨ÔÚÍÆ½øÊý¾Ý´«Êä¶ø·Ç³Ö¾Ã´æ´¢ £¬µ«¹¥»÷ÕßÈÔ¿Éͨ¹ýÉèÖá°ÍøÂçÆ÷¡±³Ö¾Ãץȡй¶Êý¾Ý¡£×êÑÐÍŶÓÇ¿µ÷ £¬Ð¹Â¶µÄÊý¾ÝÔ̺¬¿Í»§¶©µ¥¡¢²ÍÌüºÍ¾Æµê¶©µ¥¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢¼Òͥסַ¡¢½»»õµ¥¼°Ê¹Óõĸ¶¿î·½Ê½µÈ £¬ÕâЩÐÅÏ¢¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ»òÔÚ°µÍøÉÏÏúÊÛ £¬¸øÊܺ¦Õß´øÀ´ÑϳÁ·çÏÕ¡£ÔÚ×êÑÐÈËÔ±ÂŴγ¢ÊÔÁªÏµºó £¬GonnaOrder×îÖÕÓÚ2025Äê5ÔÂÏÂÑ®¹Ø¹ØÁ˸ÃÊ·ý¡£


https://cybernews.com/security/gonnaorder-food-delivery-data-leak/


3. 4ÍòÁªÍøÉãÏñͷ¶³ö £¬Óû§ÒþÖÔÊÜÍþв


6ÔÂ11ÈÕ £¬°²È«×¨¼Ò½üÈÕ·¢³öÖÒ¸æ £¬±¾Ó¦±£ÏÕÓû§°²È«µÄ°²È«ÉãÏñÍ·È´ÒòÅäÖò»µ± £¬½«Óû§ÖÃÓÚΣÏÕ¾³½ç¡£¾ÝÃÀ¹úÍøÂ簲ȫÆÀ¼¶¹«Ë¾BitSightµÄ»ã±¨ÏÔʾ £¬Ä¿Ç°ÒÑÓÐ4Íò¸öÁªÍøÉãÏñͷ¶³öÓÚÍøÂç £¬ÆäÖÐÃÀ¹ú¾ÍÕ¼¾ÝÁË1.4Íò¸ö¡£ÕâЩÉãÏñÍ·ÎÞÐèÃÜÂë»òÆäËû±£»¤´ëÊ©¼´¿ÉÔÚÏßÖ±²¥ £¬ÈκÎÈËÖ»Ðè°ÑÎÕÕýÈ·µÄIPµØÖ·ºÍä¯ÀÀÆ÷ £¬¾ÍÄÜÇáËɼල¼ÒÍ¥»ò´óÐ͹«Ë¾¡£ÓÉÓÚÎïÁªÍøËÑË÷ÒýÇæ»á³ÖÐøÌ½²â»¥ÁªÍø²¢ÏóÕ÷ËùÓж³öµÄ·þÎñ £¬²éÕÒÕâЩÉãÏñÍ·µÄIPµØÖ·±äµÃÒì³£ÈÝÒס£»ã±¨Ö¸³ö £¬ÕâЩÕý±¾ÓÃÓÚ°²È«»ò·½±ãµÄÉãÏñÍ· £¬È´ÎÞÒâÖгÉΪÁËÃô¸Ð¿Õ¼äµÄ¹«¹²´°¿Ú £¬ÇÒÍùÍùÊÇÔÚÖ÷È˲»ÖªÇéµÄÇé¿öÏ¡£´ÓµØÓòÉ¢²¼À´¿´ £¬ÃÀ¹ú¶³öµÄÉãÏñÍ·ÊýÁ¿×î¶à £¬Æä´ÎÊÇÈÕ±¾¡¢°ÂµØÀû¡¢½Ý¿ËºÍº«¹ú¡£×êÑÐÈËÔ±°µÊ¾ £¬¹ÌÈ»²¢·ÇËùÓÐÍøÂçÉãÏñÍ·¶¼´æÔÚÎÊÌâ £¬µ«Â¶³öµÄÉãÏñÍ·Öв»·¦¼à¿Ø·¿ÎÝÈë¿Ú¡¢Êý¾ÝÖÐÐÄÀí·¿¡¢×Ô¶¯È¡¿î»ú¡¢Ò½Ôº²¡ÈËÒÔ¼°¹«¹²½»Í¨³Ë¿ÍµÄÃô¸ÐÉ豸¡£¸üÁîÈËÓÇÓôµÄÊÇ £¬¼´±ãijЩÉãÏñ»ú±ØÒªÃÜÂëÄÜÁ¦½Ó¼ûÖÎÀíÃæ°å £¬ÆäAPIÒ²¿ÉÄܹ«¿ªÂ¶³öÊÓÆµÁ÷ £¬Ê¹µÃÍøÂç·¸×ï·Ö×Ó¿ÉÄÜͨ¹ýÔì×÷ÌØ¶¨URLÀ´½Ó¼û¡£ÔÚ°µÍøÂÛ̳ÉÏ £¬ÍøÂç·¸×ï·Ö×ÓÉõ´ó¹«¿ª»áÉ̲éÕÒºÍÀÄÓôËÀàÉãÏñÍ·µÄ¹¤¾ßºÍ×ö·¨ £¬²¢ÏúÊÛ½Ó¼ûȨÏÞ¡£


https://cybernews.com/security/researchers-find-thousands-exposed-security-cameras/


4. CloudflareÓëGoogle CloudÔâ·ê´ó¹æÄ£·þÎñÖжÏ


6ÔÂ12ÈÕ £¬ÃÀ¹ú¶«²¿¹¦·ò6ÔÂ12ÈÕ £¬CloudflareºÍGoogle CloudÔâ·ê´ó¹æÄ£·þÎñÖжÏÎÊÌâ £¬Ó°Ïì¶à¸öµØÓòÍøÕ¾¼°¸÷Àà·þÎñµÄ½Ó¼û¡£CloudflareÔÚ²»µ½30·ÖÖÓǰ³õ´ÎÈÏ¿ÉÎÊÌâ £¬»ã±¨Á˽ӼûÉí·ÝÑé֤ʧ°ÜºÍCloudflare Zero Trust WARPÏνÓÎÊÌâ £¬²¢°µÊ¾ºÜ¶à·þÎñ³öÏÖ¼äЪÐÔ¹ÊÕÏ £¬ÔÚ³ÖÐøµ÷²é¡£ÆäÊÜÓ°ÏìµÄ·þÎñÔ̺¬Ê¹ÓÃȨ¡¢ÓƾöÔÏó¡¢¹¤ÈËKV¡¢¼´Ê±¡¢¹¤ÈËÈËΪÖÇÄÜ¡¢ÏªÁ÷¡¢ºòÕïÊÒ¡¢CloudflareÒDZí°åµÄ×é³É²¿ÃÅ¡¢ÈËΪÖÇÄÜÍø¹Ø¡¢×Ô¶¯RAGµÈ¡£Cloudflare½²»°ÈË³Æ £¬ÕâÊÇÒ»´ÎGoogle CloudÖÐ¶Ï £¬CloudflareÉÙÊýʹÓÃGoogle CloudµÄ·þÎñÊܵ½Ó°Ïì £¬µ«Ö÷Ìâ·þÎñδÊܲ¨¼°¡£Ëæºó £¬Cloudflare°µÊ¾·þÎñÔÚÈ«ÇòÁìÓòÄÚ¼±¾ç¸´Ô­ £¬WARPºÍTurnstileÒѸ´Ô­ÔËÐÐ £¬µ«ÈÔ´æÔÚÉÙÁ¿²Ð´æÓ°Ïì £¬Ö÷ÌâKV·þÎñÒѸ´Ô­ £¬ÓйزúÆ·ÒѸ´Ô­ÉÏÏß £¬Ô¤¼Æ½ÓÏÂÀ´¼¸·ÖÖÓÄÚ½«½øÒ»²½¸´Ô­¡£¹È¸è·½Ãæ £¬×ÔÉýƽÑóÏÄÁ·ò6ÔÂ12ÈÕ10:51Æð £¬¶à¿îGCP²úÆ·³öÏÖ·þÎñÎÊÌâ £¬Ô̺¬Bigtable¡¢Console¡¢DataprocµÈ¡£¹È¸èÔÚ15:20 EDT¸üаµÊ¾ £¬¶à¸öWorkspaceºÍËÑË÷·þÎñÒ²ÊÜÕâ´Î´ó¹æÄ£ÖжÏÓ°Ïì £¬Éæ¼°Gmail¡¢GoogleÈÕÀú¡¢Google ChatµÈ¡£´Ë±í £¬Google Lens¡¢DiscoverºÍÓïÒôËÑË÷Á˾ֵÄÌṩҲ´æÔÚ³ÖÐøÎÊÌâ¡£¹È¸è³ÆÒÑÕÒµ½µ××ÓÔ­Òò £¬²ÉÈ¡»º½â´ëÊ©ºó £¬Æä»ù´¡ÉèÊ©ÔÚ³ýus-central1Ö®±íµÄËùÓеØÓò¶¼ÒѸ´Ô­ £¬ÒÀÀµÊÜÓ°Ïì»ù´¡ÉèÊ©µÄ¹È¸èÔÆ²úÆ·ÔÚ¶à¸ö´¦Ëù¸´Ô­ £¬Ô¤¼Æ¡°¸´Ô­½«ÔÚ²»µ½Ò»Ó×ʱÄÚʵÏÖ¡±¡£


https://www.bleepingcomputer.com/news/technology/google-cloud-and-cloudflare-hit-by-widespread-service-outages/


5. AsefaÔâ¡°÷è÷롱ÀÕË÷Èí¼þ¹¥»÷ £¬210GBÊý¾Ýй¶


6ÔÂ12ÈÕ £¬¡°÷è÷롱ÀÕË÷Èí¼þÍŻォ·¨¹ú´óÐͱ£ÏÕ¼¯ÍÅSMABPTµÄÎ÷°àÑÀ×Ó¹«Ë¾AsefaÔö³¤µ½Æä°µÍøÐ¹ÃÜÍøÕ¾ £¬Ðû³ÆÇÔÈ¡ÁË210GBÊý¾Ý¡£Óë´Ëͬʱ £¬AsefaÈÏ¿ÉÕýÃæ¶ÔÍøÂç¹¥»÷ £¬ÆäÍøÕ¾×Ô6Ô³õ¾ÍÏÔʾÓйØÈëÇÖµÄ֪ͨ £¬²¢ÔÚÐÅÖим¤¿Í»§ÔÚ¼è¾ÞʱÆÚµÄÄÍÐÄ¡¢Àí½âºÍÐÅÀµ¡£Asefa°µÊ¾ £¬¹«Ë¾¡°Ö÷ÌâÒµÎñ¡±Î´ÊÜÓ°Ïì £¬ÈÔÔÚÕý³£ÔËÓª £¬Ô±¹¤½Ó¼û¹«Ë¾µç×ÓÓʼþµÄȨÏÞÒ²ÒѸ´Ô­ £¬µ«ÍøÕ¾½«ÁÙʱ¹Ø¹Ø £¬Ö±ÖÁÈ·±£ËùÓй¤¾ßºÍÖ°ÄÜÆëÈ«°²È«ÇÒ¿ÉÕý³£ÔËÐС£×êÑÐÍŶӵ÷²é·¢ÏÖ £¬±»µÁÊý¾ÝÔ̺¬¹«Ë¾ÄÚ²¿Îļþ¡¢»¤ÕÕ¡¢ÊÕÌõºÍ˾·¨ºÍ̸µÈ £¬ÆäÖÐÒ»·ÝÉæ¼°°ÍÈûÂÞÄÇ×ãÇò¾ãÀÖ²¿Åµ¿²ÆÕÇò³¡³Á½¨µÄ±£ÏÕ´òËãÓÈΪÒýÈËÖõÄ¿¡£×êÑÐÈËÔ±Ö¸³ö £¬Ð¹Â¶µÄÃô¸ÐÎļþÈ绤ÕÕºÍÄÚ²¿ºÍ̸ £¬»á´øÀ´ÑϳÁµÄÉí·Ý͵ÇÔ»òڲƭ·çÏÕ £¬ÉõÖÁ¿ÉÄܵ¼ÖÂóÒ×¼äµý»î¶¯ £¬¶ø°ÍÈûÂÞÄÇ×ãÇò¾ãÀÖ²¿µÄ±£ÏÕ´òËãй¶ £¬¿ÉÄܻᶳöÓâÔ½Ãû¶È¿Í»§µÄ²ÆÕþ»òÔËÓª·ì϶¡£Õâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ¡°÷è÷롱ÀÕË÷Èí¼þÓ°ÏìÁ¦½ñÄêÎȲ½Ôö³¤ £¬½ö4Ô·ݾÍÕë¶ÔÁË68¸öʵÌå¡£


https://cybernews.com/security/asefa-spanish-insurer-qilin-ransomware/


6. ³¬8Íò¸öEntra IDÕÊ»§ÔâTeamFiltration¹¤¾ß¹¥»÷


6ÔÂ12ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÏîÃûΪUNK_SneakyStrikeµÄÐÂÕÊ»§ÊÕÊÜ£¨ATO£©»î¶¯ £¬¸Ã»î¶¯ÀûÓÿªÔ´ÉøÈë²âÊÔ¿ò¼ÜTeamFiltrationÈëÇÖMicrosoft Entra ID£¨Ô­Azure Active Directory£©Óû§ÕÊ»§¡£×Ô2024Äê12Ô·¢ÏֵǼ³¢ÊÔ´ÎÊý¼¤ÔöÒÔÀ´ £¬´Ë»î¶¯ÒѲ¨¼°Êý°Ù¼Ò×éÖ¯µÄ80,000¶à¸öÖ¸±êÓû§ÕÊ»§ £¬²¢³É¹¦µ¼Ö²¿ÃÅÕÊ»§±»ÊÕÊÜ¡£ProofpointÖ¸³ö £¬¹¥»÷Õß½èÖú·ÖÆçµØÀíÇøÓòµÄMicrosoft Teams APIºÍÑÇÂíÑ·ÍøÂç·þÎñ£¨AWS£©·þÎñÆ÷ £¬ÌáÒéÓû§Ã¶¾ÙºÍÃÜÂëÅçÈ÷¹¥»÷ £¬ÀûÓöÔMicrosoft Teams¡¢OneDrive¡¢OutlookµÈÌØ¶¨×ÊÔ´ºÍ±¾»úÀûÓ÷¨Ê½µÄ½Ó¼ûȨÏÞÖ´Ðй¥»÷¡£TeamFiltrationÓÉ×êÑÐÔ±Melvin¡°Flangvik¡±LangvikÓÚ2022Äê8ÔÂÔÚDEF CON°²È«»áÒéÉϰ䲼 £¬ÊÇÒ»¸ö¿çƽ̨¿ò¼Ü £¬¿ÉÓÃÓÚ¡°Ã¶¾Ù¡¢ÅçÈ÷¡¢Ð¹Â¶ºÍºóÃÅ¡±Entra IDÕÊ»§ £¬Í¨¹ý½«¶ñÒâÎļþÉÏ´«µ½Ö¸±êMicrosoft OneDriveÕÊ»§ £¬ÀûÓÃÃÜÂëÅçÈ÷¹¥»÷¡¢Êý¾Ýй¶ºÍ³ÖÐø½Ó¼ûÀ´ÍƽøÕÊ»§ÊÕÊÜ¡£Ö»¹ÜʹÓøù¤¾ß±ØÒªAmazon Web Services£¨AWS£©ÕÊ»§ºÍÒ»´ÎÐÔMicrosoft 365ÕÊ»§ £¬µ«Proofpoint¹Û²ìµ½¶ñÒâ»î¶¯ÀûÓÃTeamFiltration½øÐÐÕâЩ²Ù×÷µÄÖ¤¾Ý £¬ÇÒÿ´ÎÃÜÂëÅçÈ÷º£³±¶¼Ô´×ÔеØÀíµØÎ»µÄ·ÖÆç·þÎñÆ÷¡£Óë¶ñÒâ»î¶¯ÓйصÄÈý¸öÖØÒªÆðÔ´µØÓòΪÃÀ¹ú£¨42%£©¡¢°®¶ûÀ¼£¨11%£©ºÍÓ¢¹ú£¨8%£©¡£


https://thehackernews.com/2025/06/over-80000-microsoft-entra-id-accounts.htm