Steam¡¢Riot GamesÒÉÔâ´ó¹æÄ£DDoS¹¥»÷

°ä²¼¹¦·ò 2025-10-11

1. Steam¡¢Riot GamesÒÉÔâ´ó¹æÄ£DDoS¹¥»÷


10ÔÂ7ÈÕ £¬SteamÓëRiot GamesÔâ·ê´óÁìÓò¹ÊÕÏ £¬Íæ¼ÒÎÞ·¨ÔËÐÓ×¶·´¿Ö¾«Ó¢¡·¡¶DOTA2¡·¡¶ÎÞη×óȯ¡·¡¶Ó¢ÐÛͬÃË¡·µÈÈȵãÓÎÏ· £¬Downdetectorƽ̨ӿÈëÊýǧÌõ·þÎñÆ÷¶ÏÁ¬»ã±¨ £¬¹ÊÕϳʷ´¸´ÖжÏÌØµã¡£Riot Games¹Ù·½×´Ì¬Ò³ÃæÈ·ÈÏÎÊÌâ £¬¹Ø¹ØÅÅλÈü¶ÓÁв¢È«Á¦µ÷²é £¬¹ÊÕÏÓ°Ï츲¸ÇWindows¡¢macOS¡¢iOS¡¢Androidȫƽ̨¡£Õâ´Î¹ÊÕϲ¨¼°ÁìÓòÔ¶³¬ÓÎÏ·ÁìÓò £¬PlayStationÍøÂç¡¢Epic Games¡¢Hulu¡¢AWS¡¢Xfinity¡¢CoxµÈ·ÇÓÎÏ··þÎñÉÌÒàÊÜÖêÁ¬ £¬Óû§ÐÎÈÝ¡°ÍøÂç³¹µ×»ìÂÒ¡±¡£ÍøÂ簲ȫר¼Ò´§Ä¦ £¬¹ÊÕÏ»òÓÉ´ó¹æÄ£DDoS¹¥»÷Òý·¢ £¬ÌáÒéÕßÒÉËÆ¡°Aisuru¡±½©Ê¬ÍøÂç £¬¸ÃÍøÂçÔøÒÔ29.69Ì«±ÈÌØ/ÃëµÄ´ø¿í·åÖµ´´Ïº¹Çà¼Í¼ £¬Ô¶³¬´ËǰCloudflareÀ¹½ØµÄ22.2Tbps¹¥»÷¡£¡°Aisuru¡±½©Ê¬ÍøÂçÓÉXLabÓÚ2024Äê8Ô³õ´Î·¢ÏÖ £¬¹æÄ£³ÖÐøÀ©ÕÅ £¬ÒѽÚÔìÔ¼30Íò¸ö½Úµã £¬Ô̺¬A-MTKÉãÏñÍ·¡¢D-Link/Linksys·ÓÉÆ÷¡¢Íø¹ØÉ豸¡¢Êý×Ö¼Ïñ»úµÈ´æÔÚ·ì϶µÄÁªÍøÉ豸¡£Æä¹¥»÷ÌØµãΪ¸´ÔÓTCP¡°µØÌºÊ½ºäÕ¨¡± £¬·ÂÕպϷ¨Á÷Á¿¶ã±Ü¼ì²â £¬¼¼ÊõÏȽøÐÔ»ñÒµ½çÈÏ¿É £¬Óйز¹¶¡ÒÑÈ«ÇòÍÆËÍ¡£


https://cybernews.com/security/steam-riot-gaming-services-hit-by-disruptions-ddos-suspected/


2. ºÚ¿ÍÐû³ÆDiscordÊý¾Ýй¶ £¬550ÍòÓû§ÐÅÏ¢ÔâÆØ¹â


10ÔÂ8ÈÕ £¬Discord¾ÍÆäµÚÈý·½Ö§³ÖϵͳZendeskÊ·ýÊý¾Ýй¶ÊÂÎñ°ä²¼ÉêÃ÷ £¬Ã÷È·»Ø¾øÏòÍþвÐÐΪÕßÖ§¸¶Èκδó¾ÖµÄÊê½ð¡£¹¥»÷ÕßÐû³ÆÍ¨¹ý±í°üBPOÌṩÉÌÖ§³Ö´úÀíÕË»§ÈëÇÖϵͳ £¬ÔÚ58Ó×ʱÄÚÇÔÈ¡ÁË1.6TBÊý¾Ý £¬Éæ¼°550Íò¶ÀÁ¢Óû§ £¬Ô̺¬µ±¾ÖÉí·ÝÖ¤¡¢²¿ÃÅÖ§¸¶ÐÅÏ¢¼°¶à³É·ÖÉí·ÝÑéÖ¤Êý¾Ý¡£È»¶ø £¬Discord±ç²µ³ÆÏÖʵй¶ȷµ±¾ÖÉí·ÝÖ¤ÕÕÆ¬Ô¼7ÍòÕÅ £¬Ô¶µÍÓÚ¹¥»÷ÕßÐû³ÆµÄ210ÍòÕÅ £¬²¢Ç¿µ÷¸ÃÊÂÎñ²¢·ÇÖ±½ÓÕë¶ÔDiscordµÄÎ¥¹æÐÐΪ £¬¶øÊÇÉæ¼°¿Í»§Ö§³ÖµÄµÚÈý·½·þÎñ·ì϶¡£¾ÝÍþвÐÐΪÕßй© £¬ÈëÇÖÔ´ÓÚDiscord±í°üÒµÎñÁ÷³Ì±í°ü£¨BPO£©ÌṩÉ̹ÍÓõÄÖ§³Ö´úÀíÕË»§±»µÁÓà £¬Í¨¹ýZendeskÖ§³ÖÊ·ý½Ó¼ûÄÚ²¿ÏµÍ³ £¬Ö´ÐнûÓöà³É·ÖÉí·ÝÑéÖ¤¡¢²éÎÊÓû§µç»°ºÅÂë¼°µç×ÓÓʼþµØÖ·µÈ²Ù×÷¡£¹¥»÷ÕßÐû³ÆÇÔÈ¡ÁË1.5TBƱ֤¸½¼þºÍ³¬¹ý100GBƱ֤¼Í¼ £¬Éæ¼°840ÍòÕÅÆ±Ö¤ £¬ÆäÖÐÔ¼58ÍòÓû§Ô̺¬Ö§¸¶ÐÅÏ¢¡£ËûÃÇͨ¹ýZendeskÓëDiscordÄÚ²¿ÏµÍ³µÄ¼¯³É £¬Ö´ÐÐÁËÊý°ÙÍò´ÎAPI²éÎÊÒÔ¼ìË÷¸üÎÞÊý¾Ý¡£ºÚ¿ÍÔøÒªÇóÖ§¸¶500ÍòÃÀÔªÊê½ð £¬ºó½µÖÁ350ÍòÃÀÔª £¬ÓÚ9ÔÂ25ÈÕÖÁ10ÔÂ2ÈÕÆÚ¼äÓëDiscord½øÐаµÀï½»Éæ¡£½»Éæ·ÖÁѺó £¬¹¥»÷ÕßÍþв½«¹«¿ªÐ¹Â¶Êý¾Ý¡£


https://www.bleepingcomputer.com/news/security/hackers-claim-discord-breach-exposed-data-of-55-million-users/


3. CISA½«CVE-2025-27915·ì϶ÁÐÈëKEVĿ¼


10ÔÂ7ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Synacor Zimbra Collaboration Suite£¨ZCS£©µÄCVE-2025-27915·ì϶ÄÉÈëÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¸Ã·ì϶Ϊ´æ´¢ÐÍXSS·ì϶ £¬Ô´ÓÚZCS 9.0-10.1°æ±¾ÖÐICSÎļþHTML¹ýÂËȱµã £¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâiCalendarÎļþ´¥·¢ £¬ÔÚÊܺ¦Õß´ò¿ªÔ̺¬¶ñÒâÌõ¿î±êÓʼþʱִÐÐJavaScript £¬ÊµÏֻỰ½Ù³Ö¡¢Óʼþ³Á¶¨Ïò¼°Êý¾ÝÇÔÈ¡¡£StrikeReady×êÑÐÈËÔ±Åû¶ £¬2025ËêÊ׸÷ì϶±»ÓÃÓÚÁãÈÕ¹¥»÷ £¬¹¥»÷ÕßαÔìÀ´×ÔÀû±ÈÑÇˮʦÀñ±ö°ì¹«ÊҵĶñÒâICSÎļþ £¬¶Ô×¼°ÍÎ÷¾ü·½¡£¶ñÒâ¾ç±¾Õë¶ÔZimbra Webmail £¬ÇÔȡƾ֤¡¢Óʼþ¡¢ÁªÏµÈ˼°¹²ÏíÎļþ¼ÐÄÚÈÝ £¬Êý¾Ýй¶ÖÁffrk.net¡£Ö»¹ÜStrikeReadyÎÞ·¨¹éÒò¾ßÌå×éÖ¯ £¬µ«Ö¸³ö¸Ã¹¥»÷Ðè×ÊÔ´³ä×ãµÄ¸ß¼¶ÍþвÐÐΪÕßÖ´ÐÐ £¬ÆäTTPÓë°×¶íÂÞ˹APT×éÖ¯UNC1151ÀàËÆ¡£Æ¾¾ÝCISAÔ¼ÊøÐÔÔËÓªÖ¸ÁBOD£©22-01 £¬Áª¹ú»ú¹¹ÐëÔÚ2025Äê10ÔÂ28ÈÕǰ½¨¸´´Ë·ì϶ £¬Í¬Ê±½¨Òé¸öÈË×éÖ¯Éó²éKEVĿ¼²¢½¨¸´»ù´¡ÉèÊ©·ì϶¡£


https://securityaffairs.com/183085/hacking/u-s-cisa-adds-synacor-zimbra-collaboration-suite-zcs-flaw-to-its-known-exploited-vulnerabilities-catalog.html


4. Storm-2657ÍÅ»ïÕë¶ÔÃÀ¹ú´óѧ¹¤×ÊϵͳµÄ¶¨Ïò¹¥»÷


10ÔÂ9ÈÕ £¬ÍøÂç·¸×ïÍÅ»ïStorm-2657×Ô2025Äê3ÔÂÆðÕë¶ÔÃÀ¹ú´óѧԱ¹¤ÌáÒé"º£µÁ¹¤×ʵ¥"¹¥»÷ £¬Í¨¹ý½Ù³Ö¹¤×ÊÖ§¸¶Ö´ÐÐóÒ×µç×ÓÓʼþй¶£¨BEC£©Ú¿Æ­¡£Î¢ÈíÍþвµý±¨ÖÐÐÄ×îл㱨ÏÔʾ £¬¸ÃÍÅ»ïÖØÒª¶Ô×¼WorkdayÈËÁ¦×ÊԴƽ̨ÕË»§ £¬µ«ÆäËûµÚÈý·½HR SaaSƽ̨ͬÑù´æÔÚ·çÏÕ¡£Ä¿Ç°ÒÑÈ·ÈÏÈýËù´óѧµÄ11¸öÕË»§±»ÈëÇÖ £¬²¢ÀûÓÃÕâЩÕË»§Ïò25Ëù´óѧµÄ½ü6000¸öÓÊÏä·¢ËÍ´¹µöÓʼþ¡£¹¥»÷Õßѡȡ¸ß¶¨Ô컯Éç»á¹¤³ÌÕ½Êõ £¬ÓʼþÖ÷Ì⺭¸ÇУ԰ÒßÇ龯±¨¡¢ÀÏʦ²»µ±ÐÐΪ¾Ù±¨¡¢¼ÙðУ³¤Ö¸Áн³ê¸£Àû¸üÐÂ֪ͨµÈ³¡¾° £¬ÓÕµ¼ÊÕ¼þÈ˵ã»÷º¬ÖÐÑëÈË£¨AITM£©¼¼ÊõµÄ´¹µöÁ´½Ó¡£Í¨¹ýÇÔÈ¡¶à³É·ÖÈÏÖ¤£¨MFA£©´úÂë £¬¹¥»÷Õ߳ɹ¦ÇÖÈëExchange OnlineÕË»§ £¬ËæºóÉèÖÃÊÕ¼þÏ乿¶¨ÆÁ±ÎWorkdayÔ¤¾¯Óʼþ £¬ÔÚµ¥µãµÇ¼£¨SSO£©½Ó¼ûÊܺ¦ÕßWorkdayÕË»§ºó £¬´Û¸Ä¹¤×ÊÖ§¸¶ÅäÖò¢½«¿î×Ó³Á¶¨ÏòÖÁ¹¥»÷Õß½ÚÔìÕË»§¡£¸üÒñ±ÎµÄÊÇ £¬ÍÅ»ïͨ¹ý×¢²á×ÔÉíµç»°ºÅÂëÖÁDuo MFAÉ豸³ÉÁ¢ÓƾýӼû £¬ÊµÏÖ¶ñÒâ²Ù×÷µÄÒñ±ÎÉóÅú¡£Î¢ÈíÇ¿µ÷ £¬´ËÀ๥»÷²¢·ÇÔ´ÓÚWorkdayƽ̨·ì϶ £¬¶øÊÇÀûÓò»×ã·À´¹µöMFAµÄÕË»§°²È«È±µã¡£


https://www.bleepingcomputer.com/news/security/hackers-target-university-hr-employees-in-payroll-pirate-attacks/


5. RondoDox½©Ê¬ÍøÂçÀûÓÃÈ«Çò56¸ön-day·ì϶ÌáÒé¹¥»÷


10ÔÂ9ÈÕ £¬Ò»¸öÃûΪRondoDoxµÄÐÂÐÍ´óÐͽ©Ê¬ÍøÂç³ÖÐø»îÔ¾ £¬×Ô6ÔÂÆðÕë¶Ô30ÓàÀàÉ豸ÌáÒé´ó¹æÄ£¹¥»÷ £¬ÀûÓÃ56¸öÒÑÖª¼°Î´·ÖÅäCVEµÄ·ì϶ִÐÐÉøÈë¡£¸ÃÍøÂçѡȡ¡°·ì϶ɢµ¯Ç¹¡±Õ½Êõ £¬Í¨¹ýͬʱ´¥·¢¶à¸ö·ì϶×î´ó»¯Ï°È¾ÁìÓò £¬¼´±ã¹¥»÷ÐÐΪÒ×±»¼ì²â¡£Æä¹¥»÷Ö¸±ê¾Û½¹Â¶³öÓÚ»¥ÁªÍøµÄDVR¡¢NVR¡¢CCTVϵͳ¡¢ÍøÂç·þÎñÆ÷¼°ÒÑÍ£²ú£¨EoL£©É豸 £¬ÕâЩÉ豸Òò¹Ì¼þ¸üÐÂÖͺó»òĬÈÏÍ´´¦Î´Åú¸Ä¶ø³ÉÎªÖØÒªÍ»ÆÆ¿Ú¡£RondoDoxµÄ±øÆ÷¿âÔ̺¬´óÁ¿n-day·ì϶ £¬ÈçTP-Link Archer AX21·ÓÉÆ÷µÄCVE-2023-1389¡¢CVE-2024-3721¡¢CVE-2024-12856µÈ £¬Éæ¼°Digiever¡¢QNAP¡¢D-Link¡¢TOTOLINKµÈÆ·ÅÆÉ豸¡£ÖµÍ×ÌùÐĵÄÊÇ £¬¸Ã½©Ê¬ÍøÂ翪·¢ÕßÇ×êÇ×·×ÙPwn2Own½ÏÁ¿ÖÐչʾµÄ·ì϶²¢¼±¾ç±øÆ÷»¯ £¬ÀýÈçCVE-2023-1389Ôø±»Mirai½©Ê¬ÍøÂçÔÚ2023ÄêÀûÓá£´Ë±í £¬Ç÷Ïò¿Æ¼¼·¢ÏÖRondoDox»¹Ô̺¬18¸öδ·ÖÅäCVEµÄºÅÁî×¢Èë·ì϶ £¬Ó°ÏìD-Link NAS¡¢TVT/LILIN DVR¡¢Linksys·ÓÉÆ÷µÈÉ豸 £¬Í¹ÏÔ¹©¸øÁ´°²È«·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/rondodox-botnet-targets-56-n-day-flaws-in-worldwide-attacks/


6. ¿ý±±¿ËѧÌÃÀûÓ÷¨Ê½HopHopй¶¶ùͯÊý¾Ý


10ÔÂ8ÈÕ £¬¼ÓÄôó¿ý±±¿ËÊ¡Êý°ÙËùѧÌü°ÍжùËùʹÓõÄHopHopÀûÓ÷¨Ê½ÒòÊý¾Ýй¶ÊÂÎñÒý·¢ÑϳÁ¶ùͯ°²È«·çÏÕ¡£¸ÃÀûÓÃ×Ô2016ÄêÍÆ³ö £¬Ö¼ÔÚͨ¹ýGPS¶¨Î»»òÊÖ¶¯ÊäÈëЭµ÷¶ùͯ½ÓË͹¦·ò £¬µ«ÏÖʵÔËÐÐÖж³öÑϳÁ°²È«·ì϶ £¬µ¼Ö¶ùͯ¼°¼Ò³¤Ãô¸ÐÐÅϢй¶ £¬Ô̺¬È«Ãû¡¢ÕÕÆ¬¡¢Ñ§ÌÃÃû³ÆµÈ £¬ÉõÖÁ´æÔÚ¶ñÒâÈËÔ±¼ÙÒâ¼Ò³¤½Óº¢×ÓµÄDZÔÚ·çÏÕ¡£ÊÂÎñÖ÷ÌâÎÊÌâÔÚÓÚ¼à¹ÜȱʧÓëÔðÈÎÍÆÚá£HopHopÀûÓÃδ»ñ¿ý±±¿Ë½ÌÓý²¿ºË×¼ £¬²»ÔÚÆäÈÏÖ¤µÄÈýÊ®ÖÖÊý×Ö¹¤¾ßÇåµ¥ÖÐ £¬ÊôÓÚδ¾­ÑéÖ¤µÄ¡°ºÚÀûÓᱡ£¼ÓÄôó¹ã²¥¹«Ë¾µ÷²éÏÔʾ £¬µ±¾ÖÔçÔÚÊý¾Ýй¶²úÉúÁ½ÖÜǰÒÑÖªÇé²¢·¢Õ¹Éó¼Æ £¬È´½«ÔðÈÎת¼Þ¸ø½ÌÓý»ú¹¹ £¬µ¼ÖÂѧÌü°ÍжùËù³ÖÐøÊ¹Óò»°²È«ÀûÓó¤´ïÊýÖÜ¡£Ö±ÖÁ10ÔÂ7ÈÕ £¬ÔÚýÌ寨¹âѹÁ¦Ï £¬µ±¾Ö²ÅÒªÇóÖÕ³¡Ê¹ÓøÃÀûÓà £¬µ«´ËʱÒѺ±¼ûǧÃû¶ùͯÊý¾Ý¶³ö¡£


https://cybernews.com/security/hophop-app-quebec-data-leak/