ÒÔÉ«ÁÐɳÃ×¶ûÒ½ÁÆÖÐÐÄÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
°ä²¼¹¦·ò 2025-10-101. ÒÔÉ«ÁÐɳÃ×¶ûÒ½ÁÆÖÐÐÄÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
10ÔÂ2ÈÕ£¬ÒÔÉ«ÁÐɳÃ×¶ûÒ½ÁÆÖÐÐÄ£¨Assaf Harofeh£©ÔÚÊê×ïÈÕÆÚ¼äÔâ·ê¡°÷è÷롱ÀÕË÷Èí¼þ×éÖ¯´ó¹æÄ£ÍøÂç¹¥»÷¡£¸Ã×éÖ¯Ðû³ÆÒÑÆëÈ«ÉøÈëÒ½ÔºITϵͳ£¬ÇÔȡԼ8TBÃô¸ÐÊý¾Ý£¬Ô̺¬»¼Õ߸öÈ˽¡È«¼Í¼¡¢ÄÚ²¿Í¨Ñ¶¼°¹Ø¼üÔËÓªÐÅÏ¢£¬²¢½öÌṩ4·ÝÑù±¾Îļþ×÷Ϊ֤¾Ý¡£ºÚ¿ÍÒªÇóÒ½ÔºÔÚ72Ó×ʱÄÚ»ØÓ¦²¢ÐÉÌÊê½ðÖ§¸¶£¬²»È»½«¹«¿ªÈ«ÊýÊý¾Ý£¬Íþв³ÆÈôÒýÈë·¨ÂÉ»ò°²È«»ú¹¹½«¼Ó¿ìй¶¹ý³Ì¡£É³Ã×¶ûÒ½ÁÆÖÐÐÄλÓÚÌØÀά·ò½¼±í£¬Ä껼ÕßÈÝÁ¿´ï90%£¬·þÎñÒÔÉ«ÁÐÖв¿³¬°ÙÍò¾ÓÃñ£¬º¸ÇÃÅÕï¡¢¼¹Øï¼°ÌØÊâÒ½ÁÆÐèÒª£¬Æä·þÎñÉçÇøÔ̺¬¶àÔª×ڽ̡¢¾¼Ã²¼¾°ÈËȺ¡£Õâ´Î¹¥»÷Ç¡·êÓÌÌ«½Ì³ÁҪʥÈÕÊê×ïÈÕ£¨10ÔÂ1ÈÕ-2ÈÕ£©£¬Òý·¢¶Ô¹¥»÷¶¯»úµÄ²Â²â¡£Ò½ÁÆÊý¾Ýй¶¿ÉÄÜÔì³ÉÑϳÁºó¹û£º»¼ÕßÒþÖÔ¶³ö¿ÉÄܵ¼ÖÂÉí·Ý͵ÇÔ¡¢Ú²Æ¼°Éç»á¹¤³Ì¹¥»÷·çÏÕ£»Ò½ÁÆÁ÷³ÌÖжϻòÑÓÎóΣ¼°ÐÔÃü¾ÈÖΣ»»ú¹¹ÃûÓþ¼°²ÆÕþÊý¾ÝÊÜËð¡£
https://cybernews.com/news/israel-shamir-medical-center-ransowmare-attack-qilin-8t-patient-data-stolen/
2. IntelliloanµÖѺ´û¿îÎ¥¹æÊÂÎñ¶³ö¿Í»§Ãô¸ÐÊý¾Ý
10ÔÂ2ÈÕ£¬¼ÓÖݵÖѺ´û¿î»ú¹¹Intelliloan½üÈÕÏò¿Í»§·¢ËÍÎ¥¹æÍ¨ÖªÐÅ£¬Åû¶Æä2025Äê3ÔÂ29ÈÕ²úÉúµÄºÚ¿Í¹¥»÷ÊÂÎñµ¼Ö´óÁ¿Ãô¸ÐÊý¾Ýй¶¡£¸Ã¹«Ë¾×Ô1993Äê³ÉÁ¢ÒÔÀ´£¬ÒÑΪ¶àÖÝÊýÍò±Ê´û¿îÌṩ×ʽ𣬵«Õâ´ÎÊÂÎñÖÐδй©¾ßÌåÊÜÓ°ÏìÈËÊý£¬Òý·¢Êý¾Ýй¶ÂÉʦ¼°¹ú¶ÈÂÉʦÊÂÎñËùµ÷²é²¢ÌáÆð¼¯ÌåËßËÏ¡£Í¨ÖªÏÔʾ£¬ºÚ¿Í¿ÉÄÜ»ñÈ¡µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢¼ÝÕÕºÅÂë¡¢µ±¾ÖID¡¢Õ˺ż°ÐÅÓþ¿¨ÐÅÏ¢£¬ÉõÖÁÉæ¼°µÖѺ´û¿îÉêÇëÈ˵ÄÓ×ÎÒ½¡È«ÐÅÏ¢¡£ÕâЩÐÅϢʹ¿Í»§Ãæ¶Ô½ðÈÚڲơ¢Éí·Ý͵ÇÔ¼°Éç»á¹¤³Ì¹¥»÷·çÏÕ¡£IntelliloanÔÚ9ÔÂ26ÈÕµÄÐź¯Öгƣ¬¹«Ë¾ÓÚ5ÔÂÒÑÏòµÂ¿ËÈøË¹ÖÝ×ܼì²ì³¤°ì¹«Êһ㱨Υ¹æÐÐΪ£¬²¢³ÖÐøÓë·¨Âɲ¿ÃźÏ×÷£¬¼Óǿϵͳ°²È«£¬·¢Õ¹Ô±¹¤°²È«ÒâʶÅàѵ¼°Êý¾Ý°²È«ÆÀ¹À¡£Îª¼õÇá¿Í»§Ëðʧ£¬¹«Ë¾Í¨¹ýTransUnionÐÅÓþ¾ÖÌṩÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý¸´Ô·þÎñ£¬²¢½¨Òé¿Í»§Ç×êÇ¼à¿ØÕË»§»î¶¯£¬ÊµÊ±»ã±¨¿ÉÒÉÐÐΪ¡£
https://cybernews.com/news/intelliloan-mortgage-breach-customer-data-exposed-social-security-numbers-drivers-licenses/
3. LynxÀÕË÷Èí¼þ¹¥»÷Ò½ÁƾÞÍ·ºàÀû¡¤Ê©¶÷×Ó¹«Ë¾TriMed
10ÔÂ3ÈÕ£¬Óë¶íÂÞ˹¹ØÁªµÄLynxÀÕË÷Èí¼þÍÅ»ïÐû³Æ¹¥ÆÆÒ½ÁƱ£½¡¾ÞÍ·ºàÀû¡¤Ê©¶÷£¨Henry Schein£©ÆìÏÂ×Ó¹«Ë¾TriMedϵͳ£¬²¢½«Ãô¸ÐÊý¾Ýй¶ÖÁ°µÍø¡£ºàÀû¡¤Ê©¶÷×÷ΪÄêÊÕÈë126.7ÒÚÃÀÔªµÄÈ«Çò×î´óÒ½ÁƱ£½¡²úÆ··þÎñ·ÖÏúÉÌ£¬ÒµÎñ¸²¸Ç33¹ú£¬Æä×Ó¹«Ë¾TriMedÕâ´ÎÔâ·êÍøÂç¹¥»÷µ¼Ö²¿ÃÅITϵͳ̱»¾£¬¹«Ë¾ÒÑÏÂÏßÓйØÏµÍ³²¢ÀñƸ±í²¿×¨¼Òµ÷²éÊÂÎñÁìÓò¡£¾Ý°µÍøÊý¾ÝÑù±¾ÏÔʾ£¬LynxÇÔÈ¡ÁËÔ̺¬¸ß¹ÜͨѶ¡¢Ë¾·¨Îļþ¡¢ÖªÊ¶²úȨ£¨Èç±í¿Æ²úÆ·ÔÐÍÉè¼Æ£©¡¢Ó×ÎÒÉí·ÝÎļþ£¨¼ÝÕÕ¡¢»¤ÕÕ£©¼°²ÆÕþÐÅÏ¢£¨IBAN¡¢ÒøÐÐÕ˺ţ©µÈÃô¸ÐÊý¾Ý¡£ÆäÖÐÒ»·âй¶µÄ¸ß¹ÜÓʼþÅû¶ÁËÊý°ÙÍòÃÀÔª×ʽðÁ÷¶¯Ï¸½Ú£¬´ËÀàÐÅÏ¢¼«Ò×±»ÓÃÓÚÕë¶Ô¸ß²ãµÄÓã²æÊ½ÍøÂç´¹µö¹¥»÷¡£LynxÍÅ»ï×Ô2024ÄêÖÐÆðÒÔÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½ÔËÓª£¬ÖØÒª¹¥»÷½ðÈÚ¡¢¹¹Öþ¡¢Ôì×÷Òµ¼°ÄÜÔ´ÁãÊÛÐÐÒµ£¬ÒÑÁÐ196ÃûÊܺ¦Õߣ¬Ô̺¬Ó¢¹úDodd Group¡¢ÃÀ¹úTrue World GroupµÈ¡£
https://cybernews.com/security/lynx-ransomware-trimed-henry-schein/
4. DraftKingsÔâ·êƾ֤Ìî³ä¹¥»÷£¬ÉÙÁ¿¿Í»§ÕË»§ÊÜÓ°Ïì
10ÔÂ7ÈÕ£¬ÌåÓý²©²Ê¾ÞÍ·DraftKingsÏò²¿Ãſͻ§·¢³öÊý¾Ýй¶֪ͨ£¬³ÆÆäÕË»§ÔÚ½üÆÚƾ֤Ìî³ä¹¥»÷ÖÐÔâºÚ¿ÍÈëÇÖ¡£Õâ´Î¹¥»÷Ô´ÓÚ¹¥»÷ÕßÀûÓÃ×Ô¶¯»¯¹¤¾ß£¬Í¨¹ýÇÔÈ¡ÆäËûÔÚÏß·þÎñµÄÓû§Ãû/ÃÜÂë¶ÔÖ´ÐÐÆ¾Ö¤Ìî³ä£¬ÊÔͼÊÕÊÜÕË»§ÒÔÇÔÊØÐÅÏ¢¡£DraftKingsÇ¿µ÷£¬¹¥»÷Õß½öÄܽӼû¡°ÓÐÏÞÁ¿¡±·ÇÃô¸ÐÊý¾Ý£¬Ô̺¬¿Í»§ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢Ö§¸¶¿¨ºóËÄλ¡¢ÂòÂô¼Í¼¡¢ÕË»§Óà¶î¼°ÃÜÂëÅú¸ÄÈÕÆÚ£¬µ«Î´´¥¼°µ±¾ÖÉí·ÝÖ¤ºÅ¡¢ÆëÈ«½ðÈÚÕË»§ÐÅÏ¢µÈ¿ÉÖÂÉí·Ý͵ÇÔ»òÒøÐÐÕË»§ÈëÇֵĹؼüÊý¾Ý¡£ÊÜÓ°Ïì¿Í»§²»¼°30ÈË£¬ÇÒµ÷²éδ·¢ÏÖDraftKingsϵͳÔâÈëÇÖ»ò¿Í»§¾¼ÃËðʧ¡£×÷ΪӦ¶Ô´ëÊ©£¬DraftKingsÒªÇóÊÜÓ°Ïì¿Í»§³ÁÖÃÕË»§ÃÜÂ룬²¢ÆôÓöà³É·ÖÉí·ÝÑéÖ¤£¨ÈçDK HorseÕË»§£©¡£Í¬Ê±½¨ÒéÓû§×Ô¶¯¸ü¸ÄÕË»§ÃÜÂë¡¢²é³ÒøÐÐÕË»§ÓëÐÅÓþ»ã±¨¡¢¶³½áÐÅÓþµµ°¸²¢ÉèÖÃڲƾ¯±¨£¬ÒÔ·À±¸Ç±ÔÚ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/draftkings-warns-of-account-breaches-in-credential-stuffing-attacks/
5. Salesforce»Ø¾øÒò´ó¹æÄ£Êý¾Ý͵ÇÔ¹¥»÷Ö§¸¶Êê½ð
10ÔÂ7ÈÕ£¬2025Ä꣬SalesforceÔâ·ê´ó¹æÄ£Êý¾Ý͵ÇÔÊÂÎñ£¬Éæ¼°Á½´Î¶ÀÁ¢¹¥»÷¡£µÚÒ»´ÎʼÓÚ2024Äêµ×£¬Íþв×éÖ¯"Scattered Lapsus$ Hunters"ͨ¹ýÉç»á¹¤³Ì¹¥»÷¼ÙÒâITÖ§³ÖÈËÔ±£¬ÓÕÆÔ±¹¤ÏνӶñÒâOAuthÀûÓÃÖÁSalesforceÊ·ý£¬µ¼Ö¹ȸ衢˼¿Æ¡¢°¢µÏ´ï˹µÈÆóÒµÊý¾Ýй¶¡£µÚ¶þ´ÎʼÓÚ2025Äê8Ô£¬¹¥»÷ÕßÀûÓñ»µÁµÄSalesLoft Drift OAuthÁîÅÆÈëÇÖ¿Í»§CRM»·¾³£¬ÇÔȡ֧³Ôì±Ö¤Êý¾Ý¼°Æ¾Ö¤¡¢APIÁîÅÆµÈÃô¸ÐÐÅÏ¢£¬ShinyHuntersÐû³ÆÕâ´ÎÇÔÈ¡³¬760¼ÒÆóÒµÔ¼15Òڱʼͼ£¬Éæ¼°Google¡¢Cloudflare¡¢Palo Alto NetworksµÈ¿Æ¼¼¾ÞÍ·¡£ÍþвÐÐΪÕß³ÉÁ¢Êý¾ÝÐ¹Â¶ÍøÕ¾breachforums[.]hn£¬ÀÕË÷39¼ÒÊÜÓ°ÏìÆóÒµ£¬Ô̺¬Áª¹ú¿ìµÝ¡¢µÏÊ¿Äá/Hulu¡¢ÍòºÀ¡¢ÏãÄζùµÈ³ÛÃûÆ·ÅÆ£¬Ðû³ÆÈô²»Ö§¸¶Êê½ð»òSalesforceÒ»´ÎÐÔÖ§¸¶ËùÓпͻ§Êê½ð£¬½«¹«¿ª½ü10ÒÚÌõÊý¾Ý¼Í¼¡£SalesforceÃ÷È·»Ø¾ø½»Éæ»òÖ§¸¶Êê½ð£¬²¢ÖÒ¸æ¿Í»§ÍþвÐÐΪÕßÕý´òËãй¶Êý¾Ý¡£Ä¿Ç°£¬¸ÃÍøÕ¾ÓòÃûÒѱ»FBI²é·â£¬ÓòÃû·þÎñÆ÷Ö¸ÏòÔø±»FBIÓÃÓÚ²é·âÓòÃûµÄCloudflare·þÎñÆ÷¡£
https://www.bleepingcomputer.com/news/security/salesforce-refuses-to-pay-ransom-over-widespread-data-theft-attacks/
6. Crimson CollectiveºÚ¿Í¶Ô×¼AWSÔÆÊ·ýÇÔÈ¡Êý¾Ý
10ÔÂ8ÈÕ£¬´ÓǰÊýÖÜ£¬Íþв×éÖ¯¡°Crimson Collective¡±³ÖÐøÕë¶ÔAWSÔÆ»·¾³ÌáÒé¹¥»÷£¬ÒÔÇÔÈ¡Êý¾Ý²¢Ö´ÐÐÀÕË÷¡£¸Ã×éÖ¯Ðû³Æ¶ÔRed HatÊÂÎñÕÆ¹Ü£¬³Æ´ÓÊýǧ¸ö˽ÓÐGitLab²Ö¿âÇÔÈ¡570GBÊý¾Ý£¬²¢Í¨¹ýÓëScattered Lapsus$ HuntersºÏ×÷¼Ó´óÀÕË÷Á¦¶È¡£Rapid7×êÑÐÏÔʾ£¬¹¥»÷ÕßÀûÓÃTruffleHog¿ªÔ´¹¤¾ßɨÃè¶³öµÄAWSƾ֤£¬Í¨¹ý·ÛËé³Ö¾Ã½Ó¼ûÃÜÔ¿ºÍIAMÕË»§ÌáÉýȨÏÞ¡£¾ßÌåÊÖ·¨Ô̺¬£ºÍ¨¹ýAPI´´½¨ÐÂIAMÓû§²¢¸½¼Ó¡°AdministratorAccess¡±Õ½Êõ»ñÈ¡ÆëÈ«½ÚÔìȨ£¬Ëæºóö¾ÙÓû§¡¢Ê·ý¡¢´æ´¢Í°¡¢Êý¾Ý¿â¼¯ÈºµÈ×ÊÔ´£¬¹æ»®Êý¾ÝÇÔÈ¡õè¾¶¡£¹¥»÷ÕßÅú¸ÄRDSÖ÷ÃÜÂë»ñÈ¡Êý¾Ý¿â½Ó¼ûȨ£¬´´½¨¿ìÕÕµ¼³öÖÁS3´æ´¢Í°£»¶ÔEBS¾í¿ìÕÕºóÆô¶¯EC2Ê·ý£¬¸½¼ÓÖÁÔÊÐí°²È«×éʵÏÖÊý¾Ý´«Ê䡣ʵÏÖÊý¾ÝÇÔÈ¡ºó£¬Í¨¹ýAWS SES¼°±í²¿ÓÊÏä·¢ËÍÀÕË÷ÐÅ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Crimson CollectiveÔÚÐж¯ÖгÁ¸´Ê¹Óò¿ÃÅIPµØÖ·£¬Ëä±ãÓÚ×·×Ùµ«Í¹ÏÔÆä³ÖÐø»îÔ¾ÐÔ¡£AWS¹Ù·½½¨Òé¿Í»§Ñ¡È¡¶ÌÆÚ¡¢×îµÍȨÏÞÆ¾Ö¤²¢Ö´ÐÐÏÞ¶ÈÐÔIAMÕ½Êõ£¬ÈôÒÉ»óƾ֤й¶¿É°´Ö¸Òý²Ù×÷»òÁªÏµÖ§³ÖÍŶӡ£
https://www.bleepingcomputer.com/news/security/crimson-collective-hackers-target-aws-cloud-instances-for-data-theft/


¾©¹«Íø°²±¸11010802024551ºÅ