»ªÊ¢¶ÙÖÝÎ÷±±·ÅÉä¿ÆÒ½ÉúÕïËùÔâÊý¾Ýй¶£¬Ó°Ïì35Íò¾ÓÃñ

°ä²¼¹¦·ò 2025-08-06

1. »ªÊ¢¶ÙÖÝÎ÷±±·ÅÉä¿ÆÒ½ÉúÕïËùÔâÊý¾Ýй¶£¬Ó°Ïì35Íò¾ÓÃñ


8ÔÂ4ÈÕ£¬»ªÊ¢¶ÙÖÝÎ÷±±·ÅÉä¿ÆÒ½ÉúÕïËù½üÈÕ֤ʵ£¬ÆäÓÚ2025Äê1ÔÂÔâ·ê³Á´óÍøÂ簲ȫÊÂÎñ£¬µ¼ÖÂÔ¼348,118Ãû»ªÊ¢¶Ù¾ÓÃñµÄÓ×ÎÒÐÅϢй¶¡£Õâ´ÎÊÂÎñʼÓÚ1ÔÂ20ÈÕÖÁ25ÈÕÆÚ¼ä£¬¹¥»÷Õßͨ¹ýδ¾­ÊÚȨµÄ½Ó¼ûÇÖÈëÕïËùÍøÂ磬Ôì³ÉϵͳÖжÏ¡£ÕïËù·¢ÏÖÒì³£ºóµ±¼´Æô¶¯Ó¦¼±ÏìÓ¦£¬ÁªÏµÁª¹ú·¨Âɲ¿ÃŲ¢ÀñƸµÚÈý·½ÍøÂ簲ȫר¼ÒЭÖúµ÷²é£¬×îÖÕÈ·ÈÏ´æ´¢ÓÚÍøÂçÖеÄÃô¸ÐÊý¾ÝÔâÇÔÈ¡¡£Æ¾¾ÝÕïËùÏò»ªÊ¢¶ÙÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄ֪ͨ£¬Ð¹Â¶ÐÅÏ¢º­¸Ç»¼ÕßÈ«Ãû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÕÕ/ÖÝÉí·ÝÖ¤ºÅ¡¢Õï¶ÏÐÅÏ¢¡¢Ò½ÁÆ·þÎñÌṩÕßÐÕÃû¡¢²¡ÀúºÅ¡¢½¡È«±£ÏÕÏêÇé¼°Ò½ÖÎÓöȵÈÖ÷ÌâÓ×ÎÒÊý¾Ý¡£Ö»¹ÜÕïËùÇ¿µ÷ĿǰÎÞÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»ÀÄÓ㬵«ÈÔΪÊÜÓ°Ïì¸ö±ðÌṩÁËÃâ·ÑÐÅÓþ¼à²âÓëÉí·Ý± £»¤·þÎñ¡£Õâ´Î¹¥»÷µÄ¼¼Êõϸ½ÚÉÐδÆëÈ«¹«¿ª£¬µ«ÍøÂçÖжÏÌØµãÓëÀÕË÷Èí¼þ¹¥»÷ģʽ¸ß¶ÈÎǺÏ¡£½ØÖÁ»ã±¨°ä²¼£¬ÉÐÎÞÈκκڿÍ×éÖ¯Ðû³Æ¶Ô´ËÊÂÕÆ¹Ü¡£


https://securityaffairs.com/180772/data-breach/northwest-radiologists-data-breach-hits-350000-in-washington.html


2. ÐÂÐÍJSCEAL¶ñÒâÈí¼þͨ¹ýÐéα¼ÓÃÜÀûÓøæ°×¹¥»÷Êý°ÙÍòÓû§


8ÔÂ4ÈÕ£¬°²È«×êÑй«Ë¾Check Point Research£¨CPR£©½üÈÕÅû¶һÏî´úºÅ"JSCEAL"µÄ´óÐÍÍøÂç·¸×ï×´¶¯£¬¸Ã»î¶¯×Ô2024Äê3ÔÂÆð³ÖÐøÕë¶Ô¼ÓÃÜÇ®±ÒÀûÓÃÓû§Ö´Ðо«×¼´¹µö¹¥»÷¡£¾Ýͳ¼Æ£¬½ö2025ÄêÉϰëÄê¹¥»÷Õß¾ÍͶ·Å³¬3.5ÍòÌõÐéα¸æ°×£¬Å·Ã˾³ÄÚDZÔÚÊÜÓ°ÏìÓû§´ï350Íò£¬È«ÇòÁìÓò¹À¼Æ³¬1000Íò£¬ÐγɽüÄêÀ´¹æÄ£×î´óµÄ¼ÓÃÜÇ®±ÒÁìÓòÍøÂç´¹µöÊÂÎñÖ®Ò»¡£¹¥»÷Á´Ñ¡È¡"¹ãÈöÍø+¾«É¸Ñ¡"Õ½Êõ£º·¸×ïÍÅ»ï¼ÙÒâ½ü50¸öÖ÷Á÷¼ÓÃÜÇ®±ÒÂòÂôƽ̨£¨ÈçCoinbase¡¢BinanceµÈ£©£¬Í¨¹ýËÑË÷ÒýÇæÓÅ»¯£¨SEO£©¼¼Êõ½«Ðéα¸æ°×ÍÆËÍÖÁËÑË÷Á˾ÖǰÁС£µ±Óû§µã»÷ºó£¬»á±»Êèµ¼ÖÁ±í¹Û¸ß¶È·ÂÕæµÄ´¹µöÍøÕ¾£¬ÓÕµ¼ÏÂÔØ´øÓкϷ¨Êý×ÖÖ¤ÊéÊðÃûµÄ"¹Ù·½×°Öðü"¡£¼¼Êõ·ÖÎöÏÔʾ£¬JSCEAL¹¥»÷³öÏÖ¶à½×¶ÎÌØµã£º³õʼװÖ÷¨Ê½Ê×ÏÈÖ´ÐÐÐÅÏ¢ÍøÂç¾ç±¾£¬ÇÔÈ¡Éè±¸Ö¸ÎÆ¡¢µØÀíµØÎ»¼°¼ÓÃÜÇ®°üʹÓúۼ£µÈÊý¾Ý£¬ÉÏ´«ÖÁ¹¥»÷Õß·þÎñÆ÷½øÐÐÖ¸±ê¼ÛÖµÆÀ¹À¡£È·Èϸ߼ÛÖµÖ¸±êºó£¬²Å»á¿ªÊÍÖ÷Ìâ¶ñÒâÈí¼þ¡£Ò»µ©³É¹¦²¿Êð£¬JSCEAL½«Ö´ÐÐÈ«·½Î»Êý¾ÝÇÔÈ¡£º³ý¼ÓÃÜÇ®±ÒÇ®°üƾ֤¡¢Ë½Ô¿µÈÖ÷Ìâ×ʲúÐÅÏ¢±í£¬»¹¾ß±¸ÆÁÄ»½ØÍ¼¡¢¼üÅ̼ͼ¡¢ÍøÂçÁ÷Á¿½Ù³ÖµÈ¸ß¼¶Ö°ÄÜ¡£


https://hackread.com/jsceal-malware-targets-millions-fake-crypto-app-ads/


3. È«ÇòÖ鱦¾ÞÍ·PandoraÔâSalesforceÊý¾Ýй¶


8ÔÂ5ÈÕ£¬È«Çò×î´óÖé±¦Æ·ÅÆÖ®Ò»¡¢Õ¼ÓÐ2700¼ÒÃŵ꼰3.7ÍòÃûÔ±¹¤µÄµ¤ÂóÆóÒµPandoraÅû¶ÁËһ·³Á´óÊý¾Ýй¶ÊÂÎñ£¬Æä¿Í»§ÁªÏµÐÅÏ¢£¨Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢µç×ÓÓÊÏ䣩ÒòµÚÈý·½Æ½Ì¨SalesforceÊý¾Ý¿âÔâ¹¥»÷±»µÁ£¬µ«ÃÜÂë¡¢Éí·ÝÖ¤¼þ¼°²ÆÕþÐÅϢδ±»Ð¹Â¶¡£¾Ýµ÷²é£¬Õâ´ÎÊÂÎñÔ´ÓÚÍþвÐÐΪÕß×Ô2025Äê1ÔÂÉõÖÁ¸üÔ繦·òÌáÒéµÄ³ÖÐøÉç»á¹¤³ÌÓëÍøÂç´¹µö¹¥»÷£¬¹¥»÷Ö¸±êÖ±Ö¸PandoraÔ±¹¤¼°·þÎñ̨ÈËÔ±£¬Í¨¹ýÇÔÈ¡Salesforceƾ֤»òÓÕÆ­Ô±¹¤ÊÚȨ¶ñÒâOAuthÀûÓ÷¨Ê½£¬×îÖÕ·¸·¨½Ó¼û²¢ÏÂÔØÁ˹«Ë¾SalesforceÊý¾Ý¿â¡£¹¥»÷ÕßÉí·Ý±»È·ÒÔΪºÚ¿Í×éÖ¯ShinyHunters£¬¸Ã×é֯ĿǰÕýÒÔ¹«¿ªÊý¾ÝΪÍþвÏòPandoraÀÕË÷Êê½ð£¬²¢ÖÒ¸æÈô²»Ö§¸¶½«Ð§·Â´ËǰSnowflake¹¥»÷ÊÂÎñ£¬Í¨¹ý´ó¹æÄ£ÏúÊÛ»òй¶Êý¾Ýʩѹ¡£Ö»¹ÜSalesforce¹Ù·½Ç¿µ÷Æäƽ̨δ·¢ÏÖÒÑÖª°²È«·ì϶£¬²¢Ö¸³ö¿Í»§×ÔÉí°²È«´ëÊ©ÊDZ£ÏÕÊý¾Ý°²È«µÄ¹Ø¼ü£¬µ«ÊÂÎñÈÔ¶³öÁËÆóÒµÒÀÀµµÚÈý·½ÔÆ·þÎñʱµÄDZÔÚ·çÏÕ£¬¼´±ãƽ̨×ÔÉí°²È«»úÔìÃÀÂú£¬Ô±¹¤°²È«ÒâʶÓÄ΢ÈÔ¿ÉÄܳÉΪ¹¥»÷Í»ÆÆ¿Ú¡£


https://www.bleepingcomputer.com/news/security/pandora-confirms-data-breach-amid-ongoing-salesforce-data-theft-attacks/


4. PBSÔ±¹¤Êý¾Ýй¶ÖÁÇàÉÙÄê·ÛË¿ÉçÇø


8ÔÂ5ÈÕ£¬ÃÀ¹ú¹«¹²¹ã²¥¹«Ë¾£¨PBS£©½üÈÕÔâ·êÒ»Â·ÌØÊâµÄÊý¾Ýй¶ÊÂÎñ£¬ÆäÔ±¹¤¼°´ÓÊô»ú¹¹¹²¼Æ3,997È˵Ĺ«Ë¾ÁªÏµÐÅÏ¢±»Ð¹Â¶ÖÁ¡°PBS Kids¡±·ÛË¿ÜöÝ͵ÄDiscord·þÎñÆ÷ÉÏ¡£±¾Ô³õ£¬Ò»·ÝÔ̺¬¾ßÌåÓ×ÎÒ¼°Ö°ÒµÐÅÏ¢µÄJSONÎļþÔÚDiscordÉçÇøÁ÷´«£¬Éæ¼°Ô±¹¤ÐÕÃû¡¢ÓÊÏ䡢ְλ¡¢Ê±Çø¡¢²¿ÃÅ¡¢°®ºÃ¼°Ö÷¹ÜÐÕÃûµÈÃô¸ÐÄÚÈÝ¡£ÓëͨÀýÊý¾Ýй¶·ÖÆç£¬Õâ´ÎÊÂÎñ²¢·Ç³öÓÚ¾­¼ÃÀûÒæÇý¶¯£¬¶øÊDZ»·ÖÏíÖÁÒÔÇàÉÙÄêΪÖ÷µÄ·Û˿ƽ̨£¬¶¯»ú¸ü×óÌ»¡°±ðÖ¸Ó×±¡°±ä½ÚºÃÆæ¡±»ò×êӪͬÁäÈËÖеġ°¿áìųɷ֡±¡£PBS½²»°ÈË֤ʵ£¬Ð¹Â¶Êý¾ÝÔ´×ÔÄÚ²¿·þÎñ¹«¹²µçÊǪ́Ա¹¤×¨ÓÃÆ½Ì¨MyPBS.org£¬¹«Ë¾ÒÑ·¢Õ¹È«Ãæµ÷²é²¢Í¨ÖªÊÜÓ°ÏìÓû§£¬Ä¿Ç°ÎÞÖ¤¾ÝÅú×¢ÆäËûϵͳÔâÈëÇÖ¡£Ö»¹Üµ±Ç°Î´·¢ÏÖ¶ñÒâʹÓÃÊý¾ÝµÄÇé¿ö£¬µ«Ð¹Â¶Êý¾ÝÔÚDiscordÉçÇø³ÖÐøÁ÷´«ÖÁ±¾ÖÜÄ©£¬ÈÔÒý·¢¶ÔDZÔÚÀÄÓõÄÓÇÓô¡£ÐÂÎÅÈËʿָ³ö£¬´ËÀà·ÛË¿ÉçÇø±¾Îª»áÉ̶ùͯ½ÚÄ¿¶øÉè¼Æ£¬Êý¾Ýй¶¿ÉÄÜÎüÒý²»ÓÃÒªµÄ±í²¿¹Ø×¢£¬ÉõÖÁΪɧÈÅijÈËÈâËÑË÷Ìṩ·½±ã¡£


https://www.bleepingcomputer.com/news/security/pbs-confirms-data-breach-after-employee-info-leaked-on-discord-servers/


5. DaVita DialysisÔâÀÕË÷Èí¼þ¹¥»÷£¬³¬°ÙÍò»¼ÕßÐÅϢй¶


8ÔÂ5ÈÕ£¬ÃÀ¹úÉöÔ໤Àí¾ÞÍ·DaVita Dialysis½üÈÕÅû¶ÁËһ·ӰÏ쳬°ÙÍò»¼ÕßµÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬Æä·þÎñÆ÷ÔÚ2025Äê3ÔÂ24ÈÕÖÁ4ÔÂ12ÈÕÆÚ¼äÔâδ¾­ÊÚȨ½Ó¼û£¬¹¥»÷Õß×îÖÕ±»³É¹¦×èÖ¹¡£Õâ´ÎÊÂÎñÓÉÍþв×éÖ¯InterLockÂÊÏÈÆØ¹â£¬¸Ã×éÖ¯Ðû³Æ½«Ð¹Â¶1.5TBÊý¾Ý£¬²¢Òѽ«²¿ÃÅÐÅÏ¢ÉÏ´«ÖÁйÃÜÍøÕ¾£¬ÓëÍþвÄÚÈÝÒ»Ö¡£Æ¾¾ÝDaVitaµÄÉêÃ÷£¬Ð¹Â¶Êý¾Ýº­¸Ç»¼Õß¼°Ò½ÁÆ·þÎñÌṩÕßµÄÃô¸ÐÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç±£ºÅ¡¢½¡È«±£ÏÕÏêÇé¡¢ÁÙ´²ÐÅÏ¢£¬²¿ÃÅ»¼Õß»¹É漰˰Îñ¼ø±ðºÅ¼°Ö§Æ±Í¼Ïñ¡£Ö»¹ÜĿǰ½ö°ÑÎÕÄÏ¿¨ÂÞÀ´ÄÉÖÝ¡¢»ªÊ¢¶ÙÖÝ¡¢¶íÀÕ¸ÔÖÝ¡¢µÂ¿ËÈøË¹ÖݺÍÂíÈøÖîÈûÖÝÎ嵨µÄ³õ²½Êý¾Ý£¬×ܼÆ1,030,495ÈËÊÜÓ°Ï죬µ«ÏÖʵ²¨¼°ÁìÓòÔ¤¼Æ¸ü¹ã£¬ÇÒ¸ÃÊÂÎñÉÐδ±»Â¼ÈëÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©µÄ¹«¹²Î¥¹æ¹¤¾ß¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬Õâ´Î¹¥»÷²¢·ÇDaVita³õ´ÎÔâ·êÊý¾Ý°²È«Î £»ú¡£×Ô2008ÄêÒÔÀ´£¬¸Ã¹«Ë¾Òѻ㱨ÖÁÉÙÆßÆðÊý¾Ýй¶ÊÂÎñ¡£


https://databreaches.net/2025/08/05/more-than-1-million-patients-affected-by-davita-ransomware-attack-those-are-preliminary-numbers/


6. ˼¿ÆÔâÓïÒô´¹µö¹¥»÷ÖÂÓû§ÐÅϢй¶


8ÔÂ5ÈÕ£¬È«ÇòÍøÂçÉ豸¾Þͷ˼¿Æ£¨Cisco£©½üÈÕÅû¶һ·ÒòÓïÒôÍøÂç´¹µö£¨Vishing£©¹¥»÷Òý·¢µÄÊý¾Ýй¶ÊÂÎñ£¬¹¥»÷Õßͨ¹ýºýŪԱ¹¤»ñÈ¡µÚÈý·½¿Í»§¹ØÏµÖÎÀí£¨CRM£©ÏµÍ³½Ó¼ûȨÏÞ£¬µ¼ÖÂÔÚCisco.com×¢²áÓû§µÄ¸ù»ù×ÊÁÏÐÅÏ¢ÔâÇÔ¡£ÊÂÎñ²úÉúÓÚ2025Äê7ÔÂ24ÈÕ£¬Ë¼¿ÆÔÚ·¢ÏÖºóµ±¼´ÖÕÖ¹Á˹¥»÷Õß¶ÔCRMϵͳµÄ½Ó¼û£¬²¢·¢Õ¹µ÷²é¡£¾Ý˼¿ÆÉêÃ÷£¬Ð¹Â¶ÐÅÏ¢Ô̺¬Óû§ÐÕÃû¡¢×éÖ¯Ãû³Æ¡¢µØÖ·¡¢Ë¼¿Æ·ÖÅäµÄÓû§ID¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¼°ÕË»§ÔªÊý¾Ý£¨Èç´´½¨ÈÕÆÚ£©£¬µ«Î´Éæ¼°×éÖ¯¿Í»§µÄ»úÃÜÐÅÏ¢¡¢ÃÜÂë»òÆäËûÃô¸ÐÊý¾Ý¡£¹«Ë¾Ç¿µ÷£¬Õâ´ÎÊÂÎñδӰÏìÆä²úÆ·»ò·þÎñ£¬ÆäËûCRMϵͳÊ·ýҲδ±»²¨¼°¡£Ä¿Ç°£¬Ë¼¿ÆÒÑÆ¾¾Ý˾·¨ÒªÇó֪ͨÊÜÓ°ÏìÓû§£¬²¢ÓëÊý¾Ý± £»¤»ú¹¹½ÓÇ¢£¬Í¬Ê±¼ÓÇ¿°²È«´ëÊ©£¬Ô̺¬¶ÔÔ±¹¤½øÐÐÍøÂç´¹µö¹¥»÷¼ø±ðÓë·À±¸µÄÔÙÅàѵ¡£


https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/