CISA½«D-Link·ÓÉÆ÷¸ßΣ·ì϶ÄÉÈëÒÑÖª±»ÀûÓÃĿ¼

°ä²¼¹¦·ò 2025-08-07

1. CISA½«D-Link·ÓÉÆ÷¸ßΣ·ì϶ÄÉÈëÒÑÖª±»ÀûÓÃĿ¼


8ÔÂ6ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½«Ó°ÏìD-Link·ÓÉÆ÷µÄÈý¸ö¾É°²È«·ì϶ÁÐÈëÆä¡°ÒÑÖª±»ÀûÓ÷ì϶¡±£¨KEV£©Ä¿Â¼£¬Ô­ÒòÊÇÕâЩ·ì϶ÔÚÒ°±í±»»ý¼«ÀûÓá£Õâ´ÎÄÉÈëµÄ·ìÏ¶Éæ¼°D-Link¶à¿îÉ豸£¬Ô̺¬DCS-2530L¡¢DCS-2670LºÍDNR-322LÐͺÅ£¬CVSSÆÀ·Ö¾ù´ï7.5ÖÁ8.8µÄ¸ßΣ¼¶±ð¡£¾ßÌå¶øÑÔ£¬CVE-2020-25078£¨CVSS 7.5£©¿ÉÄܵ¼ÖÂÔ¶³ÌÖÎÀíÔ±ÃÜÂëй¶ £»CVE-2020-25079£¨CVSS 8.8£©Îª¾­¹ýÉí·ÝÑéÖ¤µÄºÅÁî×¢Èë·ì϶£¬ÍþвÕ߿ɽè´ËÔÚÉ豸ÉÏÖ´ÐвÙ×÷ϵͳ¼¶ºÅÁî £»CVE-2020-40799£¨CVSS 8.8£©ÔòÒò²»×ã´úÂëÆëÈ«ÐԲ鳭£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÑéÖ¤Ö±½ÓÖ²Èë¶ñÒâÖ¸Áî¡£ÖµÍ×ÌùÐĵÄÊÇ£¬DNR-322LÉ豸×Ô2021Äê11ÔÂÆðÒÑʵÏÖÐÔÃüÖÜÆÚ£¨EoL£©£¬³§ÉÌδÌṩ²¹¶¡£¬CISA½¨ÒéÈÔÔÚʹÓøÃÐͺŵÄÓû§µ±¼´Í£Óò¢¸ü»»É豸¡£ÆäÓàÁ½¿îÉ豸µÄ·ì϶ÒÑÓÚ2020Äê°ä²¼½¨¸´·¨Ê½¡£CISAÒªÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÔÚ2025Äê8ÔÂ26ÈÕǰʵÏÖ»º½â´ëÊ©£¬Ô̺¬¸üÐÂÉ豸¡¢¸ôÀëÊÜÓ°Ïìϵͳ»ò´úÌæÍ£²úÐͺÅ¡£


https://thehackernews.com/2025/08/cisa-adds-3-d-link-router-flaws-to-kev.html


2. Candiru¼äµýÈí¼þ½èлù´¡ÉèÊ©»îԾȫÇò


8ÔÂ6ÈÕ£¬ÍøÂ簲ȫ×êÑлú¹¹Recorded FutureÆìÏÂInsiktÓ××é½üÈÕ°ä²¼»ã±¨£¬¸æ·¢ÒÔÉ«ÁмäµýÈí¼þÔì×÷ÉÌCandiruͨ¹ýÉý¼¶ºóµÄ»ù´¡ÉèÊ©£¬³ÖÐøÀûÓÃÆäWindows¶ñÒâÈí¼þ¡°DevilsTongue¡±·¢Õ¹È«Çò¹¥»÷»î¶¯¡£×êÑмø±ð³öÓë¸Ã¼äµýÈí¼þ¹ØÁªµÄ°Ë¸ö²Ù×÷¼¯Èº£¬ÆäÖÐÎå¸öÈÔ´¦Óڸ߶ȻîԾ״̬£¬Éæ¼°ÐÙÑÀÀû¡¢É³Ìذ¢À­²®¼°Ó¡ÄáµÈ¹ú£¬ÁíÁ½¸öÓë°¢Èû°Ý½®Óйصļ¯Èº×´Ì¬²»Ã÷¡£»ã±¨Ö¸³ö£¬CandiruµÄлù´¡ÉèÊ©Ô̺¬ÃæÏòÊܺ¦ÕߵIJ¿Êð½ÚÔì×é¼þ¼°¼äµýÈí¼þ²Ù×÷ÕßʹÓõĸ߲ã¼Ü¹¹£¬²¿Ãż¯ÈºÖ±ÊÕÊÜÀí¹¥»÷ǰ¶Ë£¬ÆäÓàÔòͨ¹ýÖÐÑë²ã»òTor°µÍø½øÐÐÒñ±Î²Ù¿Ø¡£¡°DevilsTongue¡±×÷Ϊ΢Èí¶¨ÃûµÄWindows¼äµýÈí¼þ£¬Æä´«²¼õè¾¶Ô̺¬Óã²æÊ½ÍøÂç´¹µöÁ´½Ó¡¢Ë®¿Ó¹¥»÷¡¢ÖÐÑëÈ˹¥»÷¼°ÎïÀí½Ó´¥É豸µÈ·½Ê½£¬µ«ÆëÈ«ÊýÊðÊÖ·¨ÉÐδÆëÈ«¹«¿ª¡£ÖµÍ×ÌùÐĵÄÊÇ£¬CandiruÔÚ2021Äê±»ÃÀ¹úÉÌÎñ²¿ÁÐÈ롰ʵÌåÇåµ¥¡±ºó£¬Æä×ʲúÓÚ2025Äê4Ô±»ÃÀ¹úͶ×ʹ«Ë¾¡°³ÏÐÅͬ°é»ù½ð¡±£¨Integrity Partners£©ÒÔ3000ÍòÃÀÔªÊÕ¹º£¬²¢×ªÒÆÖÁгÉÁ¢µÄÒÔÉ«ÁÐ˽ӪʵÌå¡°Integrity Labs Ltd¡±¡£·ÖÎöÒÔΪ£¬Õâ´Î³Á×éÖ¼ÔÚ¶ã±ÜÃÀ¹úÔì²ÃÏÞ¶È¡£


https://therecord.media/candiru-spyware-active-infrastructure-hungary-saudi-arabia


3. ¿â¿Ëά¶ûÒ½ÁÆÖÐÐÄÔâRhysidaÀÕË÷¹¥»÷


8ÔÂ5ÈÕ£¬ÃÀ¹úÌïÄÉÎ÷ÖÝ¿â¿Ëά¶ûµØÓòÒ½ÁÆÖÐÐÄ£¨CRMC£©×Ô2025Äê7ÔÂ13ÈÕÔâ·êRhysidaÀÕË÷Èí¼þ¹¥»÷ÒÔÀ´£¬ÈÔÔÚÈ«Á¦¸´Ô­ÏµÍ³²¢Ó¦¶ÔÊý¾Ýй¶·çÏÕ¡£¸Ã»ú¹¹ÎªÌïÄÉÎ÷ÖÝÉÏ¿²²®À¼µØÓò¼°¿ÏËþ»ùÖÝÔ¼25ÍòÃû»¼ÕßÌṩ·þÎñ£¬Õ¼ÓÐ2500ÓàÃûÔ±¹¤ºÍ40Óà¸öÒ½ÁÆ×¨¿Æ£¬Õâ´Î¹¥»÷µ¼ÖÂÆäÍÆËã»úϵͳ̱»¾£¬²¿ÃÅ·þÎñÖжÏ¡£CRMCÔÚ·¢ÏÖ¡°Òì³£¼¼Êõ»î¶¯¡±ºóµ±¼´Æô¶¯Ó¦¼±ÏìÓ¦£¬ÆäÐÅÏ¢°²È«ÍŶÓÓë±í²¿×¨¼Ò¼°Áª¹ú·¨Âɲ¿ÃźÏ×÷µ÷²é¡£Ö»¹ÜÒ½ÔºÐû³Æ»¼Õß»¤ÀíδÊܵ××ÓÐÔÓ°Ï죬µ«ÏÖʵÔËÓªÖÐÈÔ³öÏÖX¹â²é³­Á˾ÖÑÓ³¤¡¢ÃÅÕïԤԼȡµÞ¼°ÊÖÊõÆÌÅÅÎÊÌ⣬Òý·¢»¼Õß¶Ô¹µÍ¨Ð§Äܵį·ÆÀ¡£Ò½Ôº³Ðŵ½«ÔÚÈ·ÈÏÊý¾Ýй¶ºó֪ͨÊÜÓ°Ï컼Õߣ¬²¢Ç¿µ÷¡°»¼ÕßÐÅÏ¢ÒþÖÔÊÇÊ×Òª¹¤×÷¡±¡£Õâ´Î¹¥»÷ÓÉÇ×¶íÂÞ˹µÄRhysidaÍÅ»ïÖ´ÐУ¬¸Ã×éÖ¯ÓÚ8ÔÂ2ÈÕ½«CRMCÁÐÈë°µÍøÐ¹ÃÜÍøÕ¾£¬ÒªÇóÆäÔÚËÄÌìÄÚÖ§¸¶Î´¹«¿ªÊê½ð£¬²»È»½«ÒÔ10±ÈÌØ±Ò£¨Ô¼115ÍòÃÀÔª£©ÏúÊÛ±»µÁÊý¾Ý¡£Ð¹Â¶Ñù±¾ÏÔʾ£¬Êý¾ÝÔ̺¬»¼ÕßÒ½ÁƵµ°¸¡¢Ô±¹¤Ë°ÎñÎļþ¼°¼ÝÕÕÐÅÏ¢£¬²¿ÃÅÎļþ¿É×·ÒäÖÁ2018Äê¡£


https://cybernews.com/news/tennessee-cookeville-regional-medical-center-rhysidia-ransomware-attack/


4. ÍþÄá˹µçÓ°½ÚÔâºÚ¿ÍÈëÇÖ£¬¶àÃû²Î¼ÓÕßÊý¾Ý±»Ð¹Â¶


8ÔÂ6ÈÕ£¬È«Çòº¹Çà×îÓÆ¾ÃµÄÍþÄá˹¹ú¼ÊµçÓ°½ÚÈÕǰȷÈϲúÉú³Á´óÊý¾Ýй¶ÊÂÎñ£¬Òý·¢¹ú¼ÊÓ°ÊÓÐÐÒµ¶ÔÍøÂ簲ȫµÄ¸ß¶È¹Ø×¢¡£¾Ý¡¶ºÃÀ³Î뱨·¡·Åû¶£¬Õâ´Î¹¥»÷²úÉúÓÚ2025Äê7ÔÂ7ÈÕ£¬ÕýÖµµÚ82½ìÍþÄá˹¹ú¼ÊµçÓ°½Ú³ï±¸¹Ø¼üÆÚ¡£ºÚ¿Íͨ¹ýδ¾­ÊÚȨµÄϵͳÈëÇÖ£¬³É¹¦¸´Ôì²¢ÇÔÈ¡Á˵çÓ°½Ú·þÎñÆ÷´æ´¢µÄÃô¸ÐÎļþ£¬µ¼ÖÂÔ̺¬Ã½Ìå¼ÇÕß¡¢ÐÐÒµ´ÓÒµÕßµÈÔÚÄڵIJμÓÕßÓ×ÎÒÐÅÏ¢±íй¡£Ð¹Â¶Êý¾Ýº­¸Ç¶àÏîÖ÷ÌâÓ×ÎÒÐÅÏ¢£¬¾ßÌåÔ̺¬ÐÕÃûÈ«³Æ¡¢µç×ÓÓÊÏ䵨ַ¡¢ÁªÏµµç»°ºÅÂ롢˰Îñ¼ø±ðºÅ¼°ÊµÌåÓʼĵØÖ·µÈÎåÀà¹Ø¼üÊý¾Ý¡£Ö»¹ÜÖ÷°ì·½Ç¿µ÷"±»µÁÊý¾ÝÁ¿½ÏÓ×"£¬µ«É漰˰ºÅµÈ¸ß¶ÈÃô¸ÐµÄ²ÆÕþÐÅÏ¢£¬ÈÔ¿ÉÄܶÔÊÜÓ°ÏìÈËÔ±Ôì³ÉDZÔÚ·çÏÕ¡£ÊÂÎñÆØ¹âÔ´ÓÚ¡¶ºÃÀ³Î뱨·¡·¼ÇÕßÊÕµ½µçÓ°½Ú¹Ù·½·¢³öµÄй¶֪ͨº¯£¬¸Ãº¯¼þ³õ´ÎÏò±í½ç֤ʵÁËÍøÂ簲ȫ±äÂҵĴæÔÚ¡£Ãæ¶ÔÍ»·¢Î £»ú£¬µçÓ°½Ú¼¼ÊõÍŶÓѸ¿ìÆô¶¯Ó¦¼±ÏìÓ¦»úÔì¡£½ØÖÁĿǰ£¬ÏµÍ³¸´Ô­¹¤×÷ÒѸù»ùʵÏÖ£¬µ«ÉÐδ°ä²¼¾ßÌåÊÜÓ°ÏìÈËÊý¼°Êý¾Ýй¶ÁìÓò¡£


https://cybernews.com/security/venice-film-festival-hack/


5. ·¨º½ÓëºÉº½Ôâ·êµÚÈý·½Êý¾Ýй¶£¬¿Í»§Ó×ÎÒÐÅÏ¢Ãæ¶Ô°²È«·çÏÕ


8ÔÂ6ÈÕ£¬·¨¹úº½¿Õ£¨Air France£©ÓëºÉÀ¼»Ê¼Òº½¿Õ£¨KLM Royal Dutch Airlines£©½üÈÕÈ·ÈϲúÉúµÚÈý·½Êý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÆä²¿Ãſͻ§Ó×ÎÒÐÅÏ¢¡£×÷ΪŷÖÞº½¿ÕÒµ³ÁÒª²Î¼ÓÕߣ¬Á½¼ÒͬÊô·¨º½-ºÉº½¿Ø¹É¹«Ë¾µÄº½¿Õ¾Þͷͨ¹ýй¶֪ͨÏòÊÜÓ°Ïì¿Í»§Åû¶ÁËÊÂÎñϸ½Ú¡£¾ÝºÉÀ¼¿Æ¼¼Ã½ÌåTweakers.com»ñÈ¡µÄ֪ͨÏÔʾ£¬¹¥»÷Õßͨ¹ýÈëÇÖµÚÈý·½·þÎñÌṩÉ̵Äϵͳ»ñÈ¡Á˺ɺ½¿Í»§Êý¾Ý¡£·¨º½ÓëºÉº½Ä¿Ç°Õý½áºÏµ÷²é¸÷×ÔÊý¾ÝÔâ·¸·¨½Ó¼ûµÄ¾ßÌåÇé¿ö¡£ºÉº½ÔÚÉêÃ÷ÖÐÖ¸³ö£¬Æä¿Í·þÖÐÐÄʹÓõĵÚÈý·½Æ½Ì¨¼ì²âµ½Òì³ £»î¶¯ºó£¬IT°²È«ÍŶӵ±¼´ÓëÓйصÚÈý·½ÏµÍ³ºÏ×÷Ö´ÐоÀÕý´ëÊ©ÒÔÖÕÖ¹ÊÂÎñ¡£Ð¹Â¶Êý¾ÝÉæ¼°¿Í»§¶àÏîÓ×ÎÒÉí·ÝÐÅÏ¢£¬Ô̺¬ÐÕÊÏ¡¢Ãû×Ö¡¢ÁªÏµ·½Ê½¡¢"À¶Ìì·ÉÐÐ"£¨Flying Blue Miles£©ÖҳϴòËã»áÔ±ºÅ¼°µÈ¼¶¡¢·þÎñÒªÇóÓʼþÖ÷ÌâÐС£µ«»¤ÕÕºÅÂë¡¢Ö§¸¶¿¨¾ßÌåÐÅÏ¢¡¢ÕË»§ÃÜÂë¼°Àï³ÌÓà¶îδÔÚÕâ´Î¹¥»÷ÖÐй¶¡£¹¥»÷Õß¿ÉÄÜÀûÓûñÈ¡µÄÐÅÏ¢Ö´ÐÐÉí·ÝµÁÓã¬ÀýÈ翪ÉèڲƭÕË»§£¬»òͨ¹ýÉç»á¹¤³Ì¹¥»÷¼ÙÒ⺽¿Õ¹«Ë¾´ú±í½øÐо«×¼Ú¿Æ­¡£


https://cybernews.com/security/air-france-klm-customer-data-breach/


6. ·ðÂÞÀï´ïÊý¾Ý¹«Ë¾IMDataCenterÔâ·ê³Á´óй¶


8ÔÂ6ÈÕ£¬ÍøÂ簲ȫ×êÑÐÔ±½ÜÀïÂõÑÇ¡¤¸£ÀÕ½üÈÕ·¢ÏÖ£¬ÃÀ¹ú·ðÂÞÀï´ïÖÝÊý¾Ý½â¾ö¹æ»®ÌṩÉÌIMDataCenterÒòÊý¾Ý¿âÃýÎóÅäÖÃÒý·¢ÑϳÁÊý¾Ýй¶ÊÂÎñ£¬Â¶³öÁ˺£Á¿Ãô¸ÐÓû§ÐÅÏ¢¡£Õâ´Îй¶ԴÓÚÒ»¸öδÉèÃÜÂë± £»¤»ò¼ÓÃܵĹ«¿ªÊý¾Ý¿â£¬Ô̺¬10,820ÌõCSVºÍPDFÌåʽµÄ¼Í¼£¬×ÜÊý¾ÝÁ¿´ï38GB£¬º­¸ÇÐÕÃû¡¢ÏÖʵµØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·µÈÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬¸üÉæ¼°ÉúÑÄ·½Ê½¡¢·¿ÎÝ»ò³µÁ¾ËùÓÐȨµÈÉî¶ÈÒþÖÔÊý¾Ý¡£IMDataCenterµÄÒµÎñ¸²¸ÇÒ½ÁÆ¡¢±£ÏÕ¡¢ÕþÖλµÈ¶à¸öÐÐÒµ£¬ÆäÊý¾Ý¿âÐû³Æ´æ´¢³¬2.6ÒÚÓ×ÎÒ¼°6ÒÚµç×ÓÓʼþµØÖ·µÄ¾ßÌåÐÅÏ¢£¬±¾ÓÃÓÚ¾«×¼ÓªÏú¡£È»¶ø£¬Õâ´ÎÅäÖÃʧÎóʹÕâЩ¸ß¼ÛÖµÊý¾Ý¶³öÓÚ¹«¿ªÍøÂ磬³ÉÎªÍøÂç·¸×ïµÄDZÔÚ¹¤¾ß¡£¸£ÀÕÖ¸³ö£¬Òòµ¥¸öCSVÎļþ¼´º¬Êýǧ±Ê¼Í¼£¬ÏÖʵÊÜÓ°ÏìÈËÊý»òÔ¶³¬±í±íͳ¼Æ¡£IMDataCenterËäѸ¿ìÏÂÏßÊý¾Ý¿â²¢»ØÓ¦¡°¸ß¶ÈÆ÷³ÁÊý¾Ý°²È«¡±£¬µ«ºóÐø·¢Õ¹¸üΪ¸´ÔÓ¡£2025Äê7Ô£¬ºÚ¿ÍÂÛ̳Óû§ThinkingOneÐû³ÆÒÑÌáǰ½Ó¼û¸Ã¹«Ë¾µÄAWS´æ´¢Í°£¬ÏÂÔØÁËÔ̺¬2000ÍòΨһÓÊÏä¡¢3700Íòµç»°ºÅÂ룬ÒÔ¼°³¬5Íò¸öÉç±£ºÅÂë¡¢µ®ÉúÈÕÆÚµÈÃô¸ÐÊý¾ÝµÄÎļþ¡£


https://hackread.com/hacker-accesses-imdatacenter-records-exposed-aws-bucket/