ShinyHunters¹¥»÷Ô½ÄÏÐÅÓþ¾ÖÖÂ1.6ÒÚÌõÃô¸ÐÐÅÓþ¼Í¼й¶

°ä²¼¹¦·ò 2025-09-10

1. ShinyHunters¹¥»÷Ô½ÄÏÐÅÓþ¾ÖÖÂ1.6ÒÚÌõÃô¸ÐÐÅÓþ¼Í¼й¶


9ÔÂ8ÈÕ £¬ºÚ¿Í×éÖ¯ShinyHuntersÐû³Æ³É¹¦ÈëÇÖÔ½ÄÏÐÅÓþ¾Ö£¨Credit Institute of Vietnam£© £¬ÇÔÈ¡³¬¹ý1.6Òڱʼͼ £¬Éæ¼°Ô½ÄϹú¶ÈÐÅÓþÐÅÏ¢ÖÐÐÄ£¨NCIC£©ÖÎÀíµÄº£Á¿Ãô¸ÐÊý¾Ý¡£¸ÃÖÐÐÄ×÷ΪԽÄϹú¶ÈÒøÐÐÖ±ÊôµÄ¹«¹²·ÇóÒ××éÖ¯ £¬³Ðµ£¹ú¶ÈÐÅÓþµÇ¼ÇÖ°ÄÜ £¬ÕƹÜÍøÂç¡¢´¦Öᢴ洢ºÍ·ÖÎöÐÅÓþÐÅÏ¢ £¬²¢¶Ô·¨È˺ÍÌìÈ»È˽øÐÐÐÅÓþÆÀ·ÖÓëÆÀ¼¶¡£¾ÝShinyHuntersÔÚTelegram¼°ºÚ¿ÍÂÛ̳Åû¶ £¬±»µÁÊý¾ÝÔ̺¬¡°¼«ÆäÃô¸ÐµÄÐÅÏ¢¡± £¬º­¸ÇÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¡¢ÐÅÓþÖ§¸¶¼Í¼¡¢·çÏÕ·ÖÎö»ã±¨¡¢ÐÅÓþ¿¨Êý¾Ý£¨Ðè×ÔÐнâÃÜFDEËã·¨£©¡¢ÎäÊ¿Éí·ÝÖ¤¡¢µ±¾ÖÉí·ÝÖ¤¡¢Ë°ºÅ¡¢ËðÒæ±í¼°¸ºÕ®ÐÅÏ¢µÈ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Ô½ÄÏ×ÜÈ˶¡½öÔ¼1.02ÒÚ £¬¶øÊý¾Ý¼¯Ô̺¬º¹Çà¼Í¼ £¬×ÜÐÐÊý´ï30ÒÚÌõ £¬ShinyHuntersÐû³Æ»ñÈ¡ÁË¡°ÏÕЩȫÊýÈ˶¡µÄÊý¾Ý¡±¡£¹¥»÷¼¿Á©·½Ãæ £¬ShinyHuntersй©ͨ¹ý¡°n-day·ì϶¡±»ñÈ¡½Ó¼ûȨÏÞ £¬ÓÉÓÚÖ¸±êϵͳÈí¼þÒÑÍ£²ú £¬ÎÞ¿ÉÓò¹¶¡½¨¸´·ì϶¡£¸Ã×éÖ¯Ã÷È·°µÊ¾Î´ÌáÒéÀÕË÷³¢ÊÔ £¬ÒòÔ¤ÆÚ²»»áµÃµ½»ØÓ¦¡£Ä¿Ç°Ô½ÄÏÐÅÓþ¾ÖÉÐδ»Ø¸´ £¬ÊÂÎñÕæÊµÐÔÈÔ´ýÈ·ÈÏ¡£


https://databreaches.net/2025/09/08/vietnams-national-credit-registration-and-reporting-agency-hacked-most-of-the-population-affected/


2. LovesacÈ·ÈÏÔÚÀÕË÷Èí¼þ¹¥»÷ºó²úÉúÊý¾Ýй¶


9ÔÂ8ÈÕ £¬ÃÀ¹ú³ÛÃû¼Ò¾ßÆ·ÅÆLovesac½üÈÕÅû¶һ·ÑϳÁÊý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁìÓò¼°¾ßÌåÈËÊýÉÐδÃ÷È·¡£¸Ã¹«Ë¾×÷ΪÄ£¿é»¯É³·¢¡°sactionals¡±ºÍ¶¹´ü¡°sacs¡±µÄÔì×÷ÉÌ £¬ÔÚÃÀ¹úÕ¼ÓÐ267¼ÒÕ¹Ìü £¬Äê¾»ÏúÊÛ¶î´ï7.5ÒÚÃÀÔª¡£¾Ý¹Ù·½Í¨Öª £¬2025Äê2ÔÂ12ÈÕÖÁ3ÔÂ3ÈÕÆÚ¼ä £¬ºÚ¿Íδ¾­ÊÚȨ½Ó¼ûLovesacÄÚ²¿ÏµÍ³²¢ÇÔÈ¡ÍйÜÊý¾Ý¡£¹«Ë¾ÓÚ2ÔÂ28ÈÕ·¢ÏÖ·ì϶ £¬ºÄʱÈýÌìʵÏÖ²¹¾È²¢×èÖ¹ÍþвÕß½øÒ»²½½Ó¼û¡£±»µÁÊý¾ÝÔ̺¬È«Ãû¼°ÆäËûδÅû¶µÄÓ×ÎÒÐÅÏ¢ £¬µ«LovesacδÃ÷È·ÊÜÓ°ÏìȺÌåÊǿͻ§¡¢Ô±¹¤»ò³Ð°üÉÌ £¬Òàδй©¾ßÌåÊÜÓ°ÏìÈËÊý¡£×÷Ϊ²¹¾È´ëÊ© £¬¹«Ë¾ÎªÊÜÓ°ÏìÓ×ÎÒÌṩͨ¹ýExperian×¢²áµÄ24¸öÔÂÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ £¬ÓÐЧÆÚÖÁ2025Äê11ÔÂ28ÈÕ £¬²¢ÌáÐÑÓû§¾¯ÌèÍøÂç´¹µö¹¥»÷¡£Ä¿Ç°ÉÐÎÞÖ¤¾ÝÅú×¢±»µÁÐÅÏ¢Òѱ»ÀÄÓá£ÖµÍ×ÌùÐĵÄÊÇ £¬ÀÕË÷Èí¼þÍÅ»ïRansomHubÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü £¬²¢ÓÚ3ÔÂ3ÈÕ½«LovesacÁÐÈëÆäÀÕË÷ÃÅ»§ÍøÕ¾ £¬ÍþвÈô²»Ö§¸¶Êê½ð½«¹«¿ªÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/lovesac-confirms-data-breach-after-ransomware-attack-claims/


3. ¶à¹ú·¨ÂÉÁª¶¯¹Ø¹ØÈ«Çò×î´óµÁ°æÌåÓýƽ̨Calcio


9ÔÂ8ÈÕ £¬ÔÚ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©ÓëDAZNµÄ½áºÏÐж¯Ï £¬È«Çò³ÛÃûµÁ°æÌåÓýÁ÷ýÌåÆ½Ì¨Calcio±»Õýʽ¹Ø¹Ø¡£¸Ãƽ̨´Óǰ12¸öÔÂͨ¹ý134¸öÓòÃûÎüÒý³¬1.23ÒڴνӼû £¬ÆäÖÐÒâ´óÀûÔ½ӼûÁ¿Í»ÆÆ600Íò´Î £¬Õ¼Æä×ÜÁ÷Á¿80%ÒÔÉÏ £¬³ÉΪ¸Ã¹ú×îÊÜÓ­½ÓµÄÌåÓýÁ÷ýÌå·þÎñ £¬Óû§»¹¿í·ºÉ¢²¼ÓÚÎ÷°àÑÀ¡¢ÃÀ¹ú¡¢µÂ¹úºÍ·¨¹ú¡£Calcioͨ¹ý·¸·¨×ª²¥Ô̺¬Òâ¼×¡¢Ó¢³¬¡¢Å·¹Ú¡¢NBA¡¢F1¡¢ÍøÇòµÈ¶¥¼¶ÈüÊ £¬ÑϳÁ³å»÷ÌåÓý°æÈ¨Éú̬¡£ÆäλÓÚĦ¶û¶àÍßµÄÔËÓªÉÌÒÑÔÞ³ÉÖÕ³¡ÔËÓª £¬ËùÓÐÓòÃû±»×ªÒÆÖÁACE²¢³Á¶¨ÏòÖÁ¹Ù·½¡°ºÏ·¨¹ÛÈü¡±Æ½Ì¨¡£Õâ´ÎÐж¯²»½ö¶Â½ØÁ˵Á°æÄÚÈÝ´«²¼Á´ £¬¸ü±£»¤Á˹㲥¹«Ë¾¡¢ÌåÓýͬÃ˼°ÇòÃÔµÄȨÀû¡£×÷ΪÓÉ50Óà¼ÒýÌåÓéÀÖ¾ÞÍ·×é³ÉµÄ·´µÁ°æÍ¬ÃË £¬ACEÔø½áºÏÃÀ¹ú˾·¨²¿¡¢Å·ÖÞÐ̾¯×éÖ¯µÈ»ú¹¹½ø¹¥·¸·¨ÍøÂç £¬´ËǰÒѳɹ¦¹Ø¹ØStreameast¡¢Rare Breed TVµÈ´óÐ͵Á°æÆ½Ì¨ £¬²¢Íƶ¯JetflicksÍ·×Ó±»ÅÐÆßÄê½ûïÀ¡£


https://www.bleepingcomputer.com/news/security/massive-calcio-sports-streaming-piracy-service-with-123m-yearly-visits-shut-down/


4. ÃÀ¹ú¼¦µ°¾ÞÍ·Rose Acre FarmsÔâLynxÀÕË÷Èí¼þ¹¥»÷


9ÔÂ8ÈÕ £¬ÃÀ¹ú¶¥¼¶¼¦µ°³ö²úÉÌRose Acre Farms½üÈÕÔâÍøÂç·¸×OÍÅLynxÀÕË÷Èí¼þ¹¥»÷ £¬¹¥»÷ÕßÐû³ÆÒѼÓÃܸù«Ë¾Êý¾Ý¡£×÷ΪÄêÓªÊÕ½ü7ÒÚÃÀÔª¡¢Ô±¹¤³¬2000È˵ÄÐÐÒµ¾ÞÍ· £¬Rose Acre FarmsÔÚ¶à¸öÖÝÉèÓй¤³§ £¬Æä²úÆ·ÔøÍ¨¹ýÎÖ¶ûÂêÏúÊÛ £¬ÏÖ¿ÉÄܽøÈë°ÂÀÔì빩¸øÁ´¡£Õâ´Î¹¥»÷²úÉúÔÚÉÏÖÜÍíЩʱ³½ £¬LynxÔÚÆä°µÍø²©¿Í¹«¿ªÊܺ¦ÕßÐÅÏ¢ £¬µ«ÉÐδÌṩÊý¾ÝÑù±¾ £¬½öÇ¿µ÷Êý¾ÝÒѼÓÃܲ¢³ÐŵºóÐøÌṩ֤¾Ý¡£ÀÕË÷Èí¼þ¹¥»÷¶ÔÅ©²úÆ·³ö²úÉÌÍþвÓÈΪÑϳÁ¡£Cybernews×êÑÐÍŶÓÖ¸³ö £¬²»×㱸·ÝµÄÆóÒµ¿ÉÄÜÃæ¶ÔÔËÓªÖжÏ £¬Ê³Æ·Î´ÊµÊ±½»¸¶½«µ¼Ö±äÖÊ £¬Ôì³É³Á´ó¾­¼ÃËðʧ²¢Òý·¢Êг¡µßô¤¡£º¹Çà°¸ÀýÏÔʾ £¬2021ÄêJBSÈâÁª³§Ôâ¹¥»÷ÔøÍÆ¸ßÈâÀà¼ÛÖµ £¬Ö³ÃñÊäÓ͹Ü·¹¥»÷¸üµ¼ÖÂȼÓÍǷȱ¼°¼ÛÖµì­Éý¡£Õâ´Î¹¥»÷Èôµ¼Ö¼¦µ°¹©¸øÏ÷¼õ £¬¿ÉÄܳå»÷ÃÀ¹úʳƷ¹©¸øÁ´²¢Ó°ÏìÖն˼ÛÖµ¡£


https://cybernews.com/security/rose-acre-farms-alleged-data-breach/


5. Docker¹¥»÷½øÉý¼¶£º´Ó¼ÓÃܿ󹤵½¸´ÔÓ½©Ê¬ÍøÂçµÄÑݽø


9ÔÂ9ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ £¬Õë¶Ô¶³öµÄDocker APIµÄÍþвÐÐΪÕßÒÑ¶ÔÆä¶ñÒ⹤¾ß½øÐгÁ´óÉý¼¶ £¬ÐÂÔö¶àÏîΣÏÕÖ°ÄÜ £¬»òΪ¸´ÔÓ½©Ê¬ÍøÂçµì¶¨»ù´¡¡£¾ÝÇ÷Ïò¿Æ¼¼½ñÄê6ÔÂÊ×¶ÈÅû¶ £¬¸Ã»î¶¯ÀûÓÃÖ²Èë¼ÓÃܿ󹤵ľ籾¼°TorÍøÂç°µ²ØÉí·Ý£»¶øAkamai×îÐÂ×êÑÐÔò½ÒʾÁ˸ü¸´ÔӵĹ¥»÷Á´ £¬Ð¹¤¾ß²»ÔÙµ¥´¿²¿Êð¿ó¹¤ £¬¶øÊÇͨ¹ý¶à½×¶Î²Ù×÷ʵÏÖÓÆ¾Ã»¯½ÚÔìÓëºáÏò´«²¼¡£¹¥»÷Á´Ê¼ÓÚÍþвÐÐΪÕßɨÃè¶³öµÄDocker API£¨¶Ë¿Ú2375£© £¬ÀûÓÃÅú¸ÄºóµÄAlpine Linux¾µÏñ·¢ËÍÈÝÆ÷´´½¨ÒªÇó¡£ÈÝÆ÷Ö´ÐнâÂëºóµÄshellºÅÁî £¬×°ÖÃcurlºÍTor £¬Æô¶¯TorÊØ»¤¹ý³Ì²¢Í¨¹ýSOCKS5´úÀíÑéÖ¤ÏνÓ¡£È·ÈÏTor»îÔ¾ºó £¬ÈÝÆ÷´ÓTor°µ²Ø·þÎñÏÂÔØµÚ¶þ½×¶Î¾ç±¾£¨docker-init.sh£© £¬¸Ã¾ç±¾ÊµÏÖÓÆ¾ÃSSH½Ó¼û £¬Í¬Ê±Ð´Èëbase64±àÂëµÄcron×÷ҵÿ·ÖÖÓÖ´ÐÐ £¬²¢ÀûÓ÷À»ðǽ¹¤¾ß£¨iptables¡¢nftablesµÈ£©¹Ø±Õ¶Ë¿Ú2375µÄ±í²¿½Ó¼û¡£´Ë±í £¬¾ç±¾×°ÖÃmasscan¡¢zstd¡¢torsocksµÈ¹¤¾ßÖ§³ÖɨÃèÓë¶ã±Ü¡£Ëæºó £¬¶ñÒâÈí¼þÏÂÔØZstandardѹËõµÄGo¶þ½øÔìÎļþ £¬½âѹÖÁ/tmp/system²¢Ö´ÐС£ÆäÖ÷ÌâÖ°ÄÜÊÇɨÃèÆäËû¶³öµÄDocker API £¬Í¨¹ýÒ»ÑùÈÝÆ÷´´½¨²½ÖèϰȾнڵã £¬²¢É¾³ý¾ºÕùµÐÊÖÈÝÆ÷ £¬ÐγÉ×ÔÎÒ¸´ÔìµÄ½©Ê¬ÍøÂç´úÀíÌØµã¡£


https://www.bleepingcomputer.com/news/security/hackers-hide-behind-tor-in-exposed-docker-api-breaches/


6. ŦԼѪҺÖÐÐÄÔâÀÕË÷¹¥»÷Ö´ó¹æÄ£Êý¾Ýй¶ £¬³¬ÍòÈËÊÜÓ°Ïì


9ÔÂ10ÈÕ £¬ÃÀ¹ú×î´ó¶ÀÁ¢ÑªÒºÖÐÐÄ֮һŦԼѪҺÖÐÐÄÔÚ2025Äê1ÔÂÔâ·êÀÕË÷Èí¼þ¹¥»÷ºó £¬ÓÚ9ÔÂ5ÈÕÆô¶¯Êܺ¦ÕßÊý¾Ýй¶֪ͨ·¨Ê½¡£¸ÃÖÐÐÄ·þÎñÈ«ÃÀ³¬7500ÍòÈË £¬ÖðÈÕÏò400Óà¼ÒÒ½Ôº¹©¸øÔ¼4000µ¥ÔªÑªÒºÖÆÆ·¡£¾Ý¼à¹ÜÎļþÅû¶ £¬¹¥»÷ÓÚ1ÔÂ26ÈÕ³õ´Î±»·¢ÏÖ £¬ºÚ¿ÍÔÚ1ÔÂ20ÈÕÖÁ26ÈÕÆÚ¼äÇÖÈëÆäÍøÂç £¬¸´ÔìÎļþºóÖ´ÐÐÀÕË÷¡£Õâ´ÎÊÂÎñµ¼Ö¶àÖÝ»¼Õß¼°Ô±¹¤ÐÅϢй¶ £¬Ô̺¬ÐÕÃû¡¢½¡È«Êý¾Ý¡¢¼ì²âÁ˾֡¢Éç±£ºÅÂë¡¢¼ÝÕÕ/Éí·ÝÖ¤ºÅ¼°½ðÈÚÕË»§ÐÅÏ¢¡£¾ßÌåÀ´¿´ £¬µÂ¿ËÈøË¹ÖÝ10,557ÈËÊÜÓ°Ïì £¬ÃåÒòÖÝ¡¢Ðº±²¼Ê²¶ûÖÝ¡¢¼ÓÀû¸£ÄáÑÇÖÝÒàÓÐÊܺ¦Õß £¬×ÜÈËÊýδÆëÈ«¹«¿ª¡£×÷Ϊ³ÉÁ¢ÓÚ1964ÄêµÄ·ÇͶ»ú»ú¹¹ £¬Å¦Ô¼ÑªÒºÖÐÐÄÆìÏÂÕ¼Óжà¼ÒѪҺÓйØÊµÌå £¬ÒµÎñº­¸ÇÁÙ´²·þÎñ¡¢ÑªÒº·ÖÀ롢ϸ°ûÁÆ·¨¼°Õï¶Ï¼ì²â £¬ÕâЩ·þÎñ¾ùÐè´¦ÖÃÃô¸ÐÒ½ÁÆÐÅÏ¢¡£µ÷²éÏÔʾ £¬¹¥»÷Õßͨ¹ý¸´ÔìÎļþ»ñÈ¡Á˲¿ÃÅÁÙ´²ÐÅÏ¢ £¬µ÷²éÓÚ6ÔÂ30ÈÕʵÏÖ £¬8ÔÂ12ÈÕÈ·¶¨×îÖÕÊܺ¦ÕßÃûµ¥¡£ÎªÓ¦¶ÔÊÂÎñ £¬¸ÃÖÐÐÄÒÑÆô¶¯Í¨ÖªÁ÷³Ì£ºÍ¨¹ýÓʼÄÐź¯¡¢ÍøÕ¾²¼¸æ¼°ÉèÁ¢ºô½ÐÖÐÐÄÏòÊܺ¦Õß´«µÝÇé¿ö¡£


https://therecord.media/blood-center-discloses-details-on--january-ransomware-attack