ºÚ¿ÍÈëÇÖ°ÍÎ÷½¡È«ÐÅÏ¢¹«Ë¾£¬Ö°ÍÎ÷Ïܱø¶ÓÊý¾Ýй¶
°ä²¼¹¦·ò 2025-09-261. ºÚ¿ÍÈëÇÖ°ÍÎ÷½¡È«ÐÅÏ¢¹«Ë¾£¬Ö°ÍÎ÷Ïܱø¶ÓÊý¾Ýй¶
9ÔÂ22ÈÕ£¬ÍþвÐÐΪÕßÔÚµØÏÂÂÛ̳Ðû³ÆÈëÇÖ°ÍÎ÷½¡È«ÐÅÏ¢¹«Ë¾Maida.health£¬ÇÔÈ¡³¬2TB°ÍÎ÷Ïܱø¶ÓÃô¸ÐÊý¾Ý£¬º¸Ç¾ü¹Ù¼°Æä¼ÒÈ˽¡È«¼Í¼¡¢Éí·ÝÖ¤¡¢Ò½ÁÆ·¢Æ±¡¢Õï¶Ï»ã±¨£¨º¬ÐÄÔಡѧ¡¢¾«Éñ²¡Ñ§¡¢¸¾¿ÆÑ§µÈר¿ÆÐÅÏ¢£©¼°ÁÙ´²»¼ÕßÊý¾Ý¡£Êý¾ÝÈôÊôʵ£¬½«Òý·¢ÑϳÁÒþÖÔ·çÏÕ£¬Ò½ÁÆ·¢Æ±ÓëÌå¼ì»ã±¨Ô̺¬Õï¶ÏÁ˾֡¢Ó×ÎÒÉí·ÝÐÅÏ¢£¬¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ»òÒ½ÁÆÚ²Æ£¬ÀýÈç·¸×ï·Ö×Ó¼ÙÒâÊܺ¦Õß»ñÈ¡´¦·½Ò©»òÒ½ÁÆ·þÎñ¡£°ÍÎ÷Ïܱø×÷Ϊ¹ú¶ÈÔìʽ¶ÓÁУ¬Õƹܴ¦Ëù¹«¹²ÖÈÐòÊØ»¤£¬ÆäÊý¾ÝÐ¹Â¶Éæ¼°¾ü¹Ù¼°¾ìÊôÒþÖÔ£¬Ó°ÏìÁìÓò¿í·º¡£Maida.health×÷ΪÄêÓªÊÕ4590ÍòÃÀÔªµÄÒ½ÁÆÊý×Ö·þÎñÉÌ£¬Ìṩ±£ÏÕÀíÅâÖÎÀí¡¢Õ˵¥´¦Öá¢Ô¶³ÌÕ÷ѯµÈAI×Ô¶¯»¯·þÎñ£¬Õâ´ÎÊÂÎñ͹ÏÔµÚÈý·½·þÎñÌṩÉ̵ݲȫ·ì϶·çÏÕ¡£
https://cybernews.com/security/brazil-police-health-data-breach/
2. ÃÀ¹úÊÕÈëÈËÊÙ±£ÏÕAILÊýÊ®Íò¿Í»§¼Í¼±»µÁ
9ÔÂ22ÈÕ£¬ÃÀ¹ú´óÐͲ¹³ä±£ÏÕÌṩÉÌÃÀ¹úÊÕÈëÈËÊÙ£¨AIL£©Ôâ·êÊý¾Ýй¶£¬¹¥»÷ÕßÔÚÈȵãÊý¾Ýй¶ÂÛ̳Ðû³ÆÇÔÈ¡ÁËÊýÊ®ÍòÌõ¿Í»§¼Í¼£¬Éæ¼°È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÁªÏµÐÅÏ¢¼°±£µ¥×´Ì¬¡¢±£ÏÕ´òËãÃû³ÆµÈÃô¸ÐÐÅÏ¢¡£×êÑÐÍŶÓÑéÖ¤Êý¾ÝÑù±¾ºóÈ·ÈÏ£¬Ô¼15Íò±Ê¼Í¼Óë¹¥»÷ÕßÃèÊöÒ»Ö£¬ÐÅÏ¢ÕæÊµÐԽϸߡ£AIL×÷ΪȫÇòÈËÊÙ£¨ÄêÊÕÈ볬57ÒÚÃÀÔª£©ÆìÏÂ×Ó¹«Ë¾£¬×ܲ¿Î»Óڵ¿ËÈøË¹ÖÝ£¬ÊÇÃÀ¹ú×î´óµÄ²¹³ä±£ÏÕÌṩÉÌÖ®Ò»¡£Õâ´ÎÊÂÎñ¶³ö¶à³Á·çÏÕ£ºÓ×ÎÒÐÅÏ¢×éºÏ£¨ÈçÈ«Ãû+µ®ÉúÈÕÆÚ£©¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£¬·¸×ï·Ö×Ó¿ÉÄÜ¿ªÉèÚ²ÆÕË»§µ¼ÖÂÊܺ¦Õß¾¼ÃËðʧ»òÐÅÓþÆÀ·ÖÊÜËð£»Ò½Áƺͱ£ÏÕÊý¾ÝÒò²»³É¸´Ô¸öÐÔ£¨È粡ʷÎÞ·¨Åú¸Ä£©£¬³Ö¾ÃÃæ¶Ô±»ÀÄÓ÷çÏÕ£»¹¥»÷Õß»¹¿ÉÀûÓÃÓ×ÎÒÐÅÏ¢Ö´Ðо«×¼ÍøÂç´¹µö£¬¼ÙÒâ±£ÏÕ¹«Ë¾»ò½¡È«×¨¼ÒÓÕÆÊܺ¦Õßй¶¸ü¶àÃô¸ÐÐÅÏ¢¡£
https://cybernews.com/security/american-income-life-data-breach-claims/
3. ΢Èí¸æ·¢XCSSET macOS¶ñÒâÈí¼þбäÖÖ
9ÔÂ25ÈÕ£¬Î¢ÈíÍþвµý±¨ÖÐÐĽüÈÕ°ä²¼»ã±¨£¬Ö¸³öÔÚÓÐÏÞ¹¥»÷³¡¾°Öмì²âµ½XCSSET macOS¶ñÒâÈí¼þµÄбäÖÖ£¬¸Ã±äÖÖ¼¯³ÉÈý´óÖ÷ÌâÉý¼¶£º¼ÓÇ¿µÄä¯ÀÀÆ÷Êý¾Ý¶¨Î»ÄÜÁ¦¡¢¼ôÌù°å½Ù³ÖÄ£¿éÓÅ»¯¼°¸Ä½øµÄÓÆ¾ÃÐÔ»úÔì¡£×÷Ϊģ¿é»¯¶ñÒâÈí¼þ£¬XCSSET¼æ¾ßÐÅÏ¢ÇÔÈ¡Óë¼ÓÃÜÇ®±ÒµÁȡְÄÜ£¬¿ÉÇÔÈ¡ÊÜϰȾÉ豸µÄ±Ê¼Ç¡¢¼ÓÃÜÇ®±ÒÇ®°ü¼°ä¯ÀÀÆ÷º¹ÇàµÈÃô¸ÐÊý¾Ý£¬Æä¹ÖÒì´«²¼·½Ê½ÔÚÓÚͨ¹ýϰȾ¿ª·¢Õß³£ÓõÄXcodeÏîĿʵÏÖºáÏòÉøÈ룬µ±ÏîÄ¿¹¹½¨Ê±×Ô¶¯Ö´ÐжñÒâ´úÂ룬ÒÀÀµ¿ª·¢ÈËÔ±¹²ÏíÏîÄ¿ÎļþµÄºÏ×÷³¡¾°À©´óϰȾÁìÓò¡£Ð±äÖÖÔÚ¼¼Êõ²ãÃæ³öÏÖÏÔÖø½ø»¯£ºÆäÒ»£¬Í¨¹ýǶÈëÅú¸Ä°æ¿ªÔ´¹¤¾ßHackBrowserData£¬ÊµÏÖ¶ÔFirefoxä¯ÀÀÆ÷Êý¾ÝµÄ¶¨Ïò½âÃÜÓëµ¼³ö£»Æä¶þ£¬¼ôÌù°å½Ù³Ö×é¼þ¸üÐÂÖ§³Ö¼ø±ð¼ÓÃÜÇ®±ÒµØÖ·µÄÕýÔò±í°×ʽģʽ£¬¼ì²âµ½ÓйصØÖ·Ê±×Ô¶¯´úÌæÎª¹¥»÷ÕßÇ®°üµØÖ·£¬µ¼ÖÂÓû§ÂòÂô×ʽ𱻽ØÁ÷£»ÆäÈý£¬ÓƾÃÐÔ»úÔìѡȡ˫³Á¼Ù×°Õ½Êõ¡£
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-xcsset-macos-malware-variant-targeting-xcode-devs/
4. ¾¯Ìènpm"postmark-mcp"¶ñÒâ°ü°µ²ØÓʼþÇÔÈ¡´úÂë
9ÔÂ25ÈÕ£¬Koi Security×êÑÐÈËÔ±½üÈÕÅû¶£¬npmƽ̨ÉÏÃûΪ"postmark-mcp"µÄ¶ñÒâÈí¼þ°üÔÚ1.0.16°æ±¾ÖÐÖ²ÈëÇÔÈ¡´úÂ룬¸Ã°ü¼Ù×°³ÉGitHub¹Ù·½ÏîÖ÷ÕźϷ¨¶Ë¿Ú£¬¾15´Îµü´úºóÓÚ1.0.16°æÔö³¤¶ñÒâÐо¶£¬½«Óû§ËùÓеç×ÓÓʼþת·¢ÖÁ¹ØÁªÓòÃûgiftshop[.]club¡£¸Ã¶ñÒâ°üÔÚnpm´æÔÚÒ»ÖÜÆÚ¼äÏÂÔØÁ¿´ï1500´Î£¬¿ÉÄÜÒÑÇÔÈ¡Êýǧ·âÔ̺¬ÃÜÂë³ÁÖá¢Ë«³É·ÖÑéÖ¤Âë¡¢²ÆÕþÐÅÏ¢¼°¿Í»§ÏêÇéµÈÃô¸ÐÓʼþ£¬×é³ÉÑϳÁÊý¾Ýй¶·çÏÕ¡£×÷Ϊ»ùÓÚÄ£Ð͸ߵÍÎĺÍ̸£¨MCP£©µÄ·þÎñÆ÷£¬Postmark MCP±¾Ó¦Í¨¹ý½á¹¹»¯¡¢Ô¤Ô¼ÒåµÄ°²È«½Ó¿ÚΪAI¸±ÊÖÌṩÓʼþ·¢ËÍÖ°ÄÜ¡£È»¶ø£¬Õâ´ÎÊÂÎñ¶³ö³öMCP°²È«Ä£Ð͵ÄÖÂÃüȱµã£º¸ßȨÏÞÔËÐеķþÎñÆ÷Ôڹؼü»·¾³Öв»×ãÓÐЧ¼à¶½ÓëɳºÐ¸ôÀ룬µ¼ÖÂAI¸±ÊÖ¿ÉÖ´ÐÐδ¹ýÂ˵ĶñÒâºÅÁî¡£Koi SecurityÇ¿µ÷£¬ÕâÖÖ"ÎÞɳºÐ"¼Ü¹¹Ê¹Èκηì϶»òÅäÖÃÃýÎ󶼿ÉÄÜÒý·¢¿àÄÑÐÔºó¹û¡£¹¥»÷Õßͨ¹ýαÔìÓë¹Ù·½°ü¸ß¶ÈÒ»ÖµĴúÂëºÍÃèÊöÖ´Ðй©¸øÁ´¹¥»÷£¬1.0.15¼°Ö®Ç°°æ±¾Î¬³ÖÇå½àÒÔ³ÉÁ¢ÐÅÀµ£¬1.0.16°æºöÈ»×¢ÈëÇÔÈ¡Âß¼¡£
https://www.bleepingcomputer.com/news/security/unofficial-postmark-mcp-npm-silently-stole-users-emails/
5. ˼¿Æ¶½´Ù¿Í»§½¨²¹Á½¸öÔÚ±»ÀûÓõÄÁãÈÕ·ì϶
9ÔÂ25ÈÕ£¬Ë¼¿Æ½üÈÕ°ä²¼´¹Î£°²È«²¼¸æ£¬¶½´Ù¿Í»§µ±¼´½¨²¹Á½¸öÔÚ±»¹¥»÷ÕßÀûÓõÄÁãÈÕ·ì϶£¨CVE-2025-20333ºÍCVE-2025-20362£©£¬ÕâÁ½¸ö·ì϶ӰÏìÆä×ÔÊÊÓ¦°²È«É豸£¨ASA£©ºÍ·À»ðǽÍþв·ÀÓù£¨FTD£©Èí¼þ¡£ÆäÖУ¬CVE-2025-20333ÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂ룬¶øCVE-2025-20362Ôòʹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄܽӼûÊÜÏÞURL¶Ëµã¡£Ë¼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÒÑ֤ʵ´æÔÚÕë¶ÔÕâЩ·ì϶µÄ¹¥»÷³¢ÊÔ£¬²¢Ç¿ÁÒ½¨ÒéÓû§Éý¼¶ÖÁ½¨¸´°æ±¾¡£Õâ´Î°²È«¸üл¹Í¬Ê±½¨²¹Á˵ÚÈý¸öÑϳÁ·ì϶£¨CVE-2025-20363£©£¬¸Ã·ì϶ͬÑùÔÊÐíδ¾ÊÚȨµÄÔ¶³Ì¹¥»÷ÕßÔÚδ´ò²¹¶¡µÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂ롣˼¿Æ³ö¸ñ¸Ð¼¤°Ä´óÀûÑÇ¡¢¼ÓÄôó¡¢Ó¢¹ú¼°ÃÀ¹úÍøÂ簲ȫ»ú¹¹ÐÖúµ÷²éÕâЩÁãÈÕ¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-firewall-zero-days-exploited-in-attacks/
6. ÎÖ¶ûÎÖ±±ÃÀ¹©¸øÉÌÔâÀÕË÷¹¥»÷ÖÂ87ÍòÕË»§Êý¾Ýй¶
9ÔÂ25ÈÕ£¬ÎÖ¶ûÎÖ±±ÃÀ¹«Ë¾Åû¶£¬ÆäµÚÈý·½ÈËÁ¦×ÊÔ´Èí¼þ¹©¸øÉÌMilj?dataÓÚ2025Äê8ÔÂ20ÈÕÔâ·êÀÕË÷Èí¼þ×éÖ¯DataCarry¹¥»÷£¬µ¼ÖÂÖÁÉÙ25¼ÒÆóÒµ¼°200¸öÈðµäÊÐÕþ»ú¹¹µÄÔ±¹¤Êý¾Ýй¶¡£Õâ´Î¹¥»÷Ó°ÏìÁËÓÃÓÚ´¦ÖÃÒ½ÁÆÖ¤Ã÷¡¢¹¤É˻㱨¼°¿µ¸´Êºú˵ÄÖÎÀíϵͳ£¬Ð¹Â¶Êý¾ÝÉæ¼°87Íò¸öÕË»§£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÏÖʵµØÖ·¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢µ®ÉúÈÕÆÚ¼°ÐÔ±ðµÈÃô¸ÐÐÅÏ¢¡£¾ÝÎÖ¶ûÎÖÏòÂíÈøÖîÈûÖݼì²ì×ܳ¤Ìá½»µÄ»ã±¨ÏÔʾ£¬Ö»¹ÜÎÖ¶ûÎÖ×ÔÉíϵͳδÊÜÇÖº¦£¬µ«Í¨¹ýMilj?data´¦ÖõÄÔ±¹¤ÐÕÃûºÍÉç»á±£ÏÕºÅÂëµÈÓ×ÎÒÐÅÏ¢ÒÑÔâй¶¡£ÊÂÎñ¹¦·òÏßÏÔʾ£¬Milj?dataÓÚ8ÔÂ23ÈÕ³õ´Î¼ì²âµ½ÀÕË÷Èí¼þ¹¥»÷£¬9ÔÂ2ÈÕÈ·ÈÏÊý¾Ýй¶²¢Í¨ÖªÎÖ¶ûÎÖ¼¯ÍÅ£¬ËæºóÏòÊÜÓ°ÏìÓ×ÎÒ·¢ËÍ֪ͨÐÅ£¬²¢Ìṩ18¸öÔµÄAllstate Identity Protection Pro+Ãâ·Ñ¶©ÔÄ·þÎñ£¬Ô̺¬ÐÅÓþ¼à¿ØÖ°ÄÜ¡£ÀÕË÷Èí¼þ×éÖ¯DataCarryÒÑÔÚÆäTorÐ¹Â©ÍøÕ¾°ä²¼±»µÁÊý¾Ý¡£
https://securityaffairs.com/182577/data-breach/volvo-north-america-disclosed-a-data-breach-following-a-ransomware-attack-on-it-provider-miljodata.html


¾©¹«Íø°²±¸11010802024551ºÅ