·Ñ¶ûÃÉÌØÐÅÓþºÏ×÷ÉçÔâ´ó¹æÄ£Êý¾Ýй¶

°ä²¼¹¦·ò 2025-09-16

1. ·Ñ¶ûÃÉÌØÐÅÓþºÏ×÷ÉçÔâ´ó¹æÄ£Êý¾Ýй¶


9ÔÂ13ÈÕ  £¬·Ñ¶ûÃÉÌØÁª¹úÐÅÓþºÏ×÷É磨FFCU£©½üÈÕ´«µÝһ·ÑϳÁÊý¾Ýй¶ÊÂÎñ  £¬Éæ¼°³¬18.7ÍòÃû¿Í»§  £¬Ð¹Â¶ÐÅÏ¢º­¸Ç´Ó»ù´¡Éí·ÝÐÅÏ¢µ½Ò½Áƽ¡È«Êý¾ÝµÄȫά¶ÈÃô¸ÐÄÚÈÝ¡£µ÷²éÏÔʾ  £¬¹¥»÷ÕßÔçÔÚ2023Äê9ÔÂ30ÈÕÖÁ10ÔÂ18ÈÕÆÚ¼ä±ãÈëÇÔìäϵͳ  £¬µ«FFCUÖ±ÖÁ2024Äê1Ô²ŷ¢ÏÖй¶ÊÂÎñ  £¬¸üÔÚ2025Äê8Ô²ÅÈ·ÈϾßÌåй¶Êý¾ÝÀàÐÍ  £¬Â¶³ö³ö°²È«ÏìÓ¦»úÔìµÄÑϳÁÖͺó¡£Õâ´Îй¶µÄÊý¾ÝÁìÓò¾ªÈË  £¬Ô̺¬È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢»¤ÕÕºÅÂë¡¢¼ÝÊ»ÅÆÕÕ/ÖÝÉí·ÝÖ¤ºÅÂë¡¢½ðÈÚÕË»§¼°Â·ÓɺÅÂë¡¢ÐÅÓþ¿¨/½è¼Ç¿¨ÆëÈ«ÐÅÏ¢£¨º¬°²È«Âë/PINÂë/µ½ÆÚÈÕ£©¡¢Ë°ÎñPINÂë¡¢Ò½ÁÆÕï¶Ï/´¦·½/ÌṩÕßÐÅÏ¢¡¢±£ÏÕµ¥ºÅ¡¢Ò½ÖÎÓöÈÏêÇé  £¬ÒÔ¼°Êý×ÖÊðÃûµÈ¡£FFCUÇ¿µ÷  £¬²¢·ÇËùÓÐÓ×ÎÒÊý¾Ý¾ù±»Ð¹Â¶  £¬µ«ÖØ´óÐÅÏ¢ÁбíÏÔʾ¹¥»÷ÕßÒÑ»ñÈ¡¹Ø¼ü¿Í»§ÎļþµÄ¿í·º½Ó¼ûȨÏÞ¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩÐÅÏ¢Ö´ÐнðÈÚڲƭ¡¢¾«×¼ÍøÂç´¹µö  £¬ÉõÖÁÔ¶³ÌÑéÖ¤Éí·Ý½øÐиüÉî¶ÈµÄÉøÈë¡£Ö»¹ÜFFCU³ÆÎ´·¢ÏÖÉí·Ý͵ÇÔ»ò½ðÈÚڲƭÊÂÎñ  £¬µ«ÒÑΪÊܺ¦ÕßÌṩÃâ·ÑÉí·Ý͵ÇÔÔ¤·À·þÎñ¡£°µÍø¼à¿ØÏÔʾ  £¬ÒÑDzɢµÄÀÕË÷Èí¼þ¼¯ÍÅBlackBasta¿ÉÄÜÓë´Ë°¸ÓйØ  £¬Æä¹¥»÷ÈÕÆÚÓëFFCU´«µÝµÄй¶ʱ¶Î¸ß¶ÈÎǺÏ¡£


https://cybernews.com/security/fairmont-federal-credit-union-data/


2. FinWiseÒøÐÐÄÚ²¿ÈËÔ±ÐÅϢй¶ÊÂÎñÓ°Ïì68.9ÍòÃû¿Í»§


9ÔÂ15ÈÕ  £¬FinWiseÒøÐÐÓÚ2024Äê5ÔÂ31ÈÕ²úÉúһ·ÓÉǰ¹ÍԱȥְºó½Ó¼ûÃô¸ÐÎļþÒý·¢µÄÊý¾Ýй¶ÊÂÎñ  £¬Éæ¼°ºÏ×÷·½ÃÀ¹úµÚÒ»½ðÈÚ£¨AFF£©µÄ68.9ÍòÃû¿Í»§Êý¾Ý¡£AFF×÷ΪÏû·Ñ½ðÈÚ·þÎñÉÌ  £¬Ìṩ·ÔìÚ´û¿î¡¢ÏÈ×âºóÂòµÈ²úÆ·  £¬Æä¿Í»§´û¿î·¢·ÅÓëÔÞÖú¾ùÒÀÀµFinWiseÒøÐС£Æ¾¾ÝÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÅû¶µÄÎļþ  £¬Õâ´ÎÊÂÎñÔ´ÓÚFinWiseÒ»ÃûǰԱ¹¤ÔÚÈ¥Ö°ºó·¸·¨½Ó¼ûÒøÐÐÊý¾Ý  £¬µ¼ÖÂÔ̺¬¿Í»§È«Ãû¼°ÆäËûÓ×ÎÒÊý¾ÝµÄÎļþ±»Ð¹Â¶¡£Ö»¹ÜFinWiseδ¹«¿ª¸ÃÔ±¹¤ÈôºÎÍ»ÆÆÈ¥Ö°ºó½Ó¼ûÏÞ¶È  £¬Ò²Î´Åû¶×ÜÊÜÓ°ÏìÈËÊý  £¬µ«ÊÂÎñÒÑÒý·¢¶àÆð¼¯ÌåËßËÏ¡£Ð¹Â¶Êý¾ÝÉæ¼°AFF¿Í»§ÉêÇë¡¢ÕË»§ÖÎÀí¡¢»¹¿îÁ÷³ÌµÈ¹Ø¼üÐÅÏ¢¡£FinWiseÔÚ·¢ÏÖºóµ±¼´Æô¶¯±í²¿ÍøÂ簲ȫר¼Òµ÷²é  £¬ÆÀ¹À·çÏÕÁìÓò  £¬²¢¼ÓÇ¿ÄÚ²¿½ÚÔìÒÔÔ¤·ÀÀàËÆÊÂÎñ¡£ÎªÌí²¹¿Í»§Ëðʧ  £¬ÒøÐÐΪÊÜÓ°ÏìÓû§Ìṩ12¸öÔÂÃâ·ÑÐÅÓþ¼à¿ØÓëÉí·Ý͵ÇÔ±£»¤·þÎñ¡£Ä¿Ç°  £¬FinWiseÒÔ¡°Éæ¼°ÔÚ½øÐеÄËßËÏ¡±ÎªÓɻؾø½øÒ»²½»ØÓ¦Ï¸½Ú  £¬µ«ÊÂÎñÒѶ³ö½ðÈÚ»ú¹¹ÔÚÔ±¹¤È¥Ö°ºóÊý¾Ý½Ó¼ûȨÏÞÖÎÀí¡¢Ãô¸ÐÊý¾Ý±£»¤»úÔìµÈ·½ÃæµÄ·ì϶¡£


https://www.bleepingcomputer.com/news/security/finwise-insider-breach-impacts-689k-american-first-finance-customers/


3. ¹È¸èLERSϵͳÔâڲƭÕË»§ÉøÈë  £¬Íþв×éÖ¯¹ØÁª¿ç¹úÊý¾Ý͵ÇÔÁ´


9ÔÂ15ÈÕ  £¬¹È¸è֤ʵÆä·¨ÂÉÒªÇóϵͳ£¨LERS£©ÔâºÚ¿Í´´½¨Ú²Æ­ÕË»§  £¬¸ÃÕË»§ËäδÏÖʵÌá½»ÒªÇó»ò½Ó¼ûÊý¾Ý  £¬µ«Â¶³öÁË·¨ÂÉÊý¾ÝϵͳµÄ°²È«·ì϶¡£´Ëǰ  £¬Íþв×éÖ¯¡°Scattered Lapsus$ Hunters¡±ÔÚTelegramÐû³ÆÒÑÈëÇÖLERS¼°FBIµÄeCheck²¼¾°µ÷²éϵͳ  £¬²¢°ä²¼ÏµÍ³½Ó¼û½ØÍ¼  £¬Òý·¢È«Çò·¨ÂÉ»ú¹¹¶ÔÃô¸ÐÊý¾Ý°²È«µÄÓÇÓô¡ª¡ª´ËÀàϵͳ±¾ÓÃÓÚÌá½»´«Æ±¡¢·¨ÔººÅÁîºÍ´¹Î£Åû¶ҪÇó  £¬Î´¾­ÊÚȨµÄ½Ó¼û¿ÉÄÜÔÊÐí¹¥»÷Õß¼ÙÒâ·¨ÂÉÈËÔ±»ñÈ¡Êܱ£»¤µÄÓû§Êý¾Ý¡£¸Ã×éÖ¯×Ô³ÆÎªShinyHunters¡¢ScatteredSpider¡¢LapsusµÈÀÕË÷×éÖ¯µÄ¹ØÁª¼¯Ìå  £¬½ñÄêÔøÍ¨¹ýÉç»á¹¤³ÌÓÕÆ­Ô±¹¤½«SalesforceÊý¾Ý¼ÓÔØÆ÷ÏÎ½ÓÆóҵʷý  £¬ÇÔÈ¡¹È¸è¡¢°¢µÏ´ï˹¡¢°ÄÖÞº½¿Õ¡¢Ë¼¿ÆµÈÊýÊ®¼Ò¿ç¹úÆóÒµ¼°µ±¾Ö»ú¹¹Êý¾Ý²¢Ö´ÐÐÀÕË÷¡£¹¥»÷õè¾¶ÏÔʾ  £¬ÆäÏȹ¥ÆÆSalesloftµÄGitHub´úÂë¿â  £¬ÀûÓÃTrufflehog¹¤¾ßɨÃè˽ÓÐÔ´ÂëÖеͳö»úÃÜ  £¬»ñÈ¡Éí·ÝÑéÖ¤ÁîÅÆºó½øÒ»²½Ö´ÐÐSalesforceÊý¾ÝÇÔÈ¡¡£¹È¸èÍþвµý±¨²¿ÃÅMandiantÔøÂÊÏÈÅû¶´ËÀ๥»÷  £¬ÖÒ¸æÆóÒµ¼ÓÇ¿·ÀÓù¡£Ö»¹Ü¡°Scattered Lapsus$ Hunters¡±ÓÚ9ÔÂ14ÈÕ°ä·¢¡°ÍËÐÝ¡±²¢°ä²¼³¤Îijơ°¹ÑÑÔ½«³ÉΪÁ¦Á¿¡±  £¬µ«ÍøÂ簲ȫ×êÑÐÈËÔ±ÒÔΪÆäÈÔÔÚ°µÖл  £¬½«À´¿ÉÄÜͨ¹ýδÅû¶µÄÊý¾Ýй¶ÊÂÎñ³ÖÐø¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/google-confirms-fraudulent-account-created-in-law-enforcement-portal/


4. ¿ªÔƼ¯ÍÅÔâShiny Hunters¹¥»÷ÖÂÊý°ÙÍò¿Í»§Êý¾Ýй¶


9ÔÂ15ÈÕ  £¬È«ÇòÉÝ³ÞÆ·¾ÞÍ·¿ªÔƼ¯ÍÅ£¨Kering£©Ôâ·êÑϳÁÊý¾Ýй¶ÊÂÎñ  £¬ÆìÏÂGucci¡¢Balenciaga¡¢Alexander McQueenµÈÆ·ÅÆµÄÊý°ÙÍò¿Í»§¸öÈËÊý¾Ý±»ºÚ¿Í×éÖ¯Shiny HuntersÇÔÈ¡¡£Ð¹Â¶Êý¾Ýº­¸ÇÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¼Òͥסַ¼°È«ÇòÉÝ³ÞÆ·ÃŵêÏû·Ñ¼Í¼  £¬²¿Ãſͻ§µ¥±ÊÏû·Ñ½ð¶î¸ß´ï8.6ÍòÃÀÔª  £¬Òý·¢¶Ô¡°¸ßÏû·ÑÈËȺ¡±¿ÉÄܳÉΪºóÐøÚ¿Æ­Ö¸±êµÄÓÇÓô¡ £¿ªÔƼ¯ÍÅÒÑÈ·Èϰ²È«·ì϶²¢Í¨ÖªÊý¾Ý±£»¤²¿ÃÅ  £¬µ«Î´Åû¶¾ßÌåÊÜÓ°Ïì¿Í»§ÊýÁ¿  £¬½öÇ¿µ÷δй¶ÈκβÆÕþÐÅÏ¢¡£¾ÝBBC±¨Â·  £¬Shiny HuntersÏòÆäÌṩÁËÔ̺¬ÊýǧÃû¿Í»§¾ßÌåÐÅÏ¢µÄÕæÊµÊý¾ÝÑù±¾  £¬²¢Ðû³Æ°ÑÎÕ740Íò¸ö¶ÀÁ¢µç×ÓÓʼþµØÖ·¶ÔÓ¦µÄÊý¾Ý  £¬°µÊ¾Êܺ¦Õß×ÜÊý»ò¿¿½ü¸ÃÊý×Ö¡£¸Ã×éÖ¯×ÔÆØÓÚ2025Äê4ÔÂͨ¹ýÈëÇÖ¿ªÔƼ¯ÍÅϵͳִÐй¥»÷  £¬µ«½»Éæ·ÖÁѺó¿ªÔƼ¯ÍŻؾøÖ§¸¶Êê½ð¡£¼¯Í޲»°È˽øÒ»²½×¢Ã÷  £¬2025Äê6Ô·¢ÏÖδ¾­ÊÚȨµÄµÚÈý·½Ò»Ê±½Ó¼ûϵͳ  £¬½ö»ñÈ¡²¿·Ôì·ÅƵÄÓÐÏÞ¿Í»§Êý¾Ý  £¬ÇÒÎ´Éæ¼°²ÆÕþÐÅÏ¢¡£


https://securityaffairs.com/182236/cyber-crime/hackers-steal-millions-of-gucci-balenciaga-and-alexander-mcqueen-customer-records.html


5. µÂÖÝÎÚÍß¶ûµÏÑ§ÇøÔâÀÕË÷Èí¼þ¹¥»÷Ö¹عØ


9ÔÂ16ÈÕ  £¬µÂ¿ËÈøË¹ÖÝÎÚÍß¶ûµÏÊй«Á¢Ñ§ÇøÒòÀÕË÷Èí¼þ¹¥»÷±»ÆÈ¹Ø¹ØËÄÌì  £¬Ó°ÏìÔ¼5000ÃûѧÉú¼°¶à¸ö¹Ø¼üϵͳ¡£Ñ§ÇøÍ¨Ñ¶Ö÷¹Ü°²ÄÝ¡¤ÂêÀö¡¤°£Ë¹Æ¤ÅµÈø°µÊ¾  £¬¹¥»÷µ¼Ö·þÎñÆ÷̱»¾  £¬ÑϳÁ×ÌÈŵ绰¡¢¿Õµ÷½ÚÔì¡¢ÉãÏñÍ·¼à¿Ø¡¢·Ã¿ÍÖÎÀí¼°½²ÊÚϵͳ£¨ÈçSkyward£©ÔËÐС£¸ÃÑ§ÇøÊÇ2022ÄêÂÞ²¼Ó×ѧǹ»÷ÊÂÎñ²úÉúµØ  £¬ÐÂУ¸ÕÆôÓò»¾Ã  £¬Õâ´ÎÊÂÎñÔٴζ³öУ԰°²ÕûϵͳµÄ´àÈõÐÔ¡£ÊÂÎñ²úÉúºó  £¬Ñ§ÇøÒÑÏòÁª¹úµ÷²é¾Ö¡¢±£ÏÕÍøÂ簲ȫÍŶӵȻú¹¹»ã±¨  £¬²¢Æô¶¯È«Ãæµ÷²éÒÔ×·Òä¶ñÒâÈí¼þÆðÔ´¼°ÆÀ¹ÀÊý¾Ýй¶·çÏÕ¡£Îª±£ÏÕ°²È«  £¬Ñ§Çø½«Í £¿ÎËÄÌìÓëУÀú·Ç¹¤×÷ÈÕ»¥»»  £¬Ñ§ÌÃÍøÕ¾¹Ø¹Ø  £¬Ë«Ñ§·Ö¿Î³ÌÔÝÍ£¡£½ØÖÁÖÜÒ»  £¬ÉÐÎÞÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÔðÈÎ  £¬ÐÂѧÄê¸ÕÆô¶¯µÄÑ§ÇøÃæ¶Ô¸ü´óÌôÕ½¡£


https://therecord.media/uvalde-texas-school-district-temporarily-closing-ransomware


6. ³¯ÏÊKimsuky×éÖ¯½èAIαÔ캫¾ü·½Éí·ÝÖ¤Ö´Ðо«×¼ÍøÂç´¹µö


9ÔÂ15ÈÕ  £¬ÍøÂ簲ȫ¹«Ë¾Genians½üÈÕÅû¶  £¬³¯Ïʵ±¾Ö²¼¾°µÄÍþвÐÐΪÕßKimsuky×éÖ¯ÀûÓÃÈËΪÖÇÄܹ¤¾ßChatGPTÌìÉúαÔìµÄº«¹ú¾üÊ»ú¹¹Éí·Ý֤ͼÏñ  £¬ÓÃÓÚÉý¼¶Óã²æÊ½ÍøÂç´¹µö¹¥»÷¡£¸Ã×éÖ¯¼ÙÒ⺫¹ú¹ú·ÀÓйػú¹¹  £¬ÒÔ½â¾ö¾ü·½¹ÙÔ±Éí·ÝÖ¤·¢·Å¹¤×÷ΪÓÉ  £¬Í¨¹ýµç×ÓÓʼþ·¢ËÍÔ̺¬Î±ÔìÉí·ÝÖ¤Ñù±¾µÄ´¹µöÁ´½Ó  £¬ÓÕµ¼Ö¸±êµã»÷ºó²¿Êð¶ñÒâÈí¼þ  £¬ÊµÏÖÊý¾Ý͵ÇÔºÍÔ¶³Ì½ÚÔì¡£Õâ´Î¹¥»÷ÓÚ2025Äê7ÔÂ17ÈÕ³õ´Î±»Genians°²È«ÖÐÐÄ·¢ÏÖ  £¬ÏµKimsuky×éÖ¯6ÔÂClickFix´¹µö»î¶¯µÄºóÐøÐж¯¡£Á½´Î¹¥»÷¾ùʹÓÃÒ»Ñù¶ñÒâÈí¼þ  £¬ÖØÒªÕë¶Ô³¯ÏÊ×êÑÐÈËÔ±¡¢ÈËȨ»î¶¯¼Ò¼°¼ÇÕß¡£Î±ÔìÉí·Ý֤ͼÏñ¾­¼ì²âΪÉî¶ÈαÔìµÄ¸ÅÂÊ´ï98%  £¬ÆäÕæÊµÐÔ¼ÓÇ¿ÏÔÖøÌáÉýÁË´¹µöÓʼþµÄ¿ÉÐŶÈ  £¬Ê¹Êܺ¦Õ߸üÒ×·ÅËɾ¯Ìè¡£Õâ´ÎÊÂÎñ½ÒʾÁ˹ú¶ÈÖ§³ÖÐÍÍþв×éÖ¯¶ÔAI¼¼ÊõµÄÀÄÓÃÇ÷Ïò¡£Kimsukyͨ¹ý½áºÏÉç»á¹¤³ÌѧÓëAIÌìÉúÄÚÈÝ  £¬¹¹½¨Á˸üÒñ±ÎµÄ¹¥»÷Á´£º´Ó·Âð¹Ù·½ÓòÃû¡¢Î±Ôì¸ß·ÂÕæÖ¤¼þ  £¬µ½Ö²Èë¶ñÒâ¾ç±¾  £¬ÐÎ³ÉÆëÈ«ÉøÈëõè¾¶¡£


https://www.infosecurity-magazine.com/news/ai-military-ids-north-korea/