ÐÂÐËShinySp1d3rÀÕË÷Èí¼þ¼¼ÊõÔËÓªÕ½ÊõÆØ¹â

°ä²¼¹¦·ò 2025-11-21

1. ÐÂÐËShinySp1d3rÀÕË÷Èí¼þ¼¼ÊõÔËÓªÕ½ÊõÆØ¹â


11ÔÂ19ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±Åû¶ÁËÃûΪ"ShinySp1d3r"µÄÐÂÐÍÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Æ½Ì¨¿ª·¢Ï¸½Ú ¡£¸Ãƽ̨ÓÉÓëShinyHunters¡¢Scattered Spider¼°Lapsus$×éÖ¯¹ØÁªµÄÍþвÐÐΪÕß´´½¨ £¬±ê־ȡÕâЩÍÅ»ï´ÓʹÓõÚÈý·½¼ÓÃÜÆ÷תÏò×ÔÖ÷¿ª·¢ ¡£¿ª·¢°æ±¾ÏÔʾ £¬ShinySp1d3rѡȡȫ×ÔÖ÷Ñз¢¼Ü¹¹ £¬Î´¸´ÓÃLockBit»òBabukµÈÒÑÖª´úÂë¿â £¬¾ß±¸¶àÏî´´ÐÂÖ°ÄÜ ¡£¼¼Êõ²ãÃæ £¬¸ÃÀÕË÷Èí¼þʹÓÃChaCha20¼ÓÃÜËã·¨¹²Í¬RSA-2048±£»¤Ë½Ô¿ £¬Ã¿¸ö¼ÓÃÜÎļþÌìÉú¹ÖÒìÀ©´óÃû²¢Í¨¹ýÊýѧ¹«Ê½¶¯Ì¬ÌìÉú ¡£ÎļþÍ·ÒÔ"SPDR"¿ªÍ·¡¢"ENDS"½áβ £¬Ô̺¬ÎļþÃû¡¢¼ÓÃÜ˽Կ¼°ÔªÊý¾Ý ¡£Æä´«²¼»úÔìÖ§³Öͨ¹ýSCM·þÎñ¡¢WMI¹ý³Ì´´½¨¼°GPO¾ç±¾²¿ÊðʵÏÖºáÏòÉøÈë £¬²¢¾ß±¸ËÑË÷Ê¢¿ªÍøÂç¹²ÏíÖ÷»ú½øÐжþ´Î¼ÓÃܵÄÄÜÁ¦ ¡£·´·ÖÎö¸öÐÔÔ̺¬¹Ò¹³EtwEventWriteº¯Êý×è¶ÏÈÕÖ¾¼Í¼¡¢¸²¸ÇÄڴ滺³åÇø·Àȡ֤ £¬ÒÔ¼°Í¨¹ýдÈëËæ»ú.tmpÎļþÌî³ä´ÅÅ̿ռä¹ÊÕÏÊý¾Ý¸´Ô­ ¡£


https://www.bleepingcomputer.com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters/


2. ¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾IGTÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷


11ÔÂ20ÈÕ £¬¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾£¨IGT£©×÷ΪȫÇòµ±ÏȵĶij¡¼°ÔÚÏ߯½Ì¨Êý×ÖÓÎÏ·¡¢ÌåÓý²©²ÊºÍ½ðÈڿƼ¼¹©¸øÉÌ £¬½üÈÕ±»Óë¶íÂÞ˹¹ØÁªµÄ÷è÷ëÀÕË÷Èí¼þ×éÖ¯ÈÏÁì ¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶²©¿Í°ä²¼IGTÌõ¿î £¬Ðû³ÆÇÔÈ¡ÁË10GBÊý¾Ý £¬21,683¸öÎļþ £¬º­¸Ç´ÓÀÏ»¢»ú¡¢²ÊƱϵͳµ½PlaySportsÌåÓý²©²Êƽ̨µÈÖ÷ÌâÒµÎñÊý¾Ý ¡£IGT²úÆ·¿í·ºÀûÓÃÓÚÈ«Çò100¶à¸ö¹ú¶È £¬ÖðÈÕ·þÎñÊý°ÙÍòÍæ¼Ò £¬Æä½ðÈڿƼ¼²¿ÃÅ´æ´¢´óÁ¿¿Í»§Éí·ÝÐÅÏ¢ £¬Ãæ¶ÔÉí·Ý͵ÇÔ·çÏÕ ¡£½ØÖÁ±¨Â·°ä²¼ £¬IGTδ¶Ô´ËÊÂ×÷³ö»ØÓ¦ ¡£÷è÷ë×éÖ¯×Ô2021Äê»î¶¯ÒÔÀ´ £¬2025ÄêÒѳÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯ £¬´ÓǰÁù¸öÔ·¢Æð³¬500Æð¹¥»÷ £¬×Ô2023ÄêÆðÒÑÁгö991ÃûÊܺ¦Õß £¬Ô̺¬³ÛÃûÆóÒµ¡¢Ò½ÁÆ»ú¹¹¼°µ±¾Ö»ú¹¹ ¡£ÆäѡȡÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ã³Ò×ģʽ £¬³£Ê¹ÓÃË«³ÁÀÕË÷Õ½Êõ£ºÏÈË÷Òª½âÃÜÊê½ð £¬ÔÙÍþвй¶Êý¾Ý ¡£


https://cybernews.com/news/igt-digital-gaming-leader-qilin-ransomware-attack-casino-fintech-sports-betting/


3. ¶íÂÞ˹VSK±£ÏÕ¹«Ë¾Ôâ´ó¹æÄ£ÍøÂç¹¥»÷


11ÔÂ19ÈÕ £¬×÷Ϊ¶íÂÞ˹×î´ó×ۺϱ£ÏÕ¹«Ë¾Ö®Ò» £¬×ܲ¿Î»ÓÚĪ˹¿ÆµÄVSK 11ÔÂ13ÈÕ¹«¿ªÈ·ÈÏÔâ·ê¡°´ó¹æÄ£ÍøÂç¹¥»÷¡± £¬Ä¿Ç°Æä¹ÙÍø¡¢Òƶ¯ÀûÓü°Êý°ÙÍòÓû§ÒÀÀµµÄ·þÎñÒѳÖÐøÏÂÏßÒ»ÖÜ ¡£×÷Ϊ·þÎñÔ¼3300ÍòÓ×ÎÒ¿Í»§ºÍ50¶àÍò¼ÒÆóÒµµÄÐÐÒµ¾ÞÍ· £¬VSKÒµÎñº­¸Ç²Æ¸»ÏÕ¡¢½»Í¨ÏÕ¡¢½¡È«ÏյȶàÁìÓò £¬Õâ´ÎÊÂÎñµ¼Ö¿ͻ§ÎÞ·¨²É°ì³µÏÕ¡¢Åú¸Ä±£µ¥¡¢»ñÈ¡µ£±£º¯»òÔ¤Ô¼Ò½ÁÆ·þÎñ £¬²¿ÃÅÒ½ÁÆ»ú¹¹ÒòÎÞ·¨ºËʵ±£ÏÕ¸²¸ÇÁìÓò»Ø¾ø·þÎñ £¬¹«Ë¾ÓʼþϵͳÒàÖÐ¶Ï £¬±»ÆÈ½¨Òé¿Í»§Í¨¹ýƽÐÅÌá½»Õ÷ѯ ¡£Ö»¹ÜVSKÇ¿µ÷¡°½öIT»ù´¡ÉèÊ©ÊÜÓ°Ïì £¬¿Í»§¼°ºÏ×÷ͬ°éÊý¾Ý°²È«ÎÞÓÝ¡± £¬µ«ÎÚ¿ËÀ¼ºÚ¿ÍÓйØTelegramƵ·ÒѰ䲼¾Ý³ÆÐ¹Â¶µÄÐÅÏ¢¼°±¸·ÝÎļþ½ØÍ¼ £¬ÕæÊµÐÔ´ýºËʵ ¡£¹«Ë¾Í¬Ê±ÖÒ¸æ £¬ÆäÆóÒµÓòÃûÔâ½Ù³Ö £¬½Ó¼ûÕ߻ᱻ³Á¶¨ÏòÖÁÐéαTelegramƵ· ¡£Ä¿Ç°¹¥»÷ÕßÉí·Ý¼°¶¯»úδÃ÷ £¬¶íÂÞË¹ÍøÂ簲ȫר¼Ò´§Ä¦ÎªÀÕË÷Èí¼þ¹¥»÷ ¡£


https://therecord.media/russia-vsk-cyberattack-outages


4. Òâ´óÀûFS¼¯ÍÅÒòAlmavivaÔâÈëÇÖÖÂ2.3TBÊý¾Ýй¶


11ÔÂ20ÈÕ £¬Òâ´óÀû¹ú¶ÈÌú·ÔËÓªÉÌFS Italiane¼¯ÍÅÒòIT·þÎñÌṩÉÌAlmavivaÔâºÚ¿ÍÈëÇÖ £¬µ¼ÖÂ2.3TBÃô¸ÐÊý¾Ýй¶ÖÁ°µÍø ¡£ºÚ¿ÍÐû³ÆÇÔÈ¡ÄÚÈݺ­¸Ç»úÃÜÎļþ¡¢¼¼ÊõÎĵµ¡¢¹«¹²ÊµÌåºÏͬ¡¢ÈËÁ¦×ÊÔ´µµ°¸¡¢¹ÜÕÊÊý¾Ý¼°¶à¼ÒFS¼¯ÍŹ«Ë¾µÄÆëÈ«Êý¾Ý¼¯ £¬ÆäÖÐÔ̺¬2025ÄêµÚÈý¼¾¶ÈµÄ×îÐÂÎļþ ¡£D3LabÍøÂçÍþвµý±¨Ö÷¹Ü°²µÂÁÒÑÇ¡¤µÂÀ­¸ÇµÙÃ÷È·Åųý¸ÃÊý¾ÝΪ2022ÄêHiveÀÕË÷Èí¼þ¹¥»÷»ØÊÕÀûÓõĿÉÄÜÐÔ £¬²¢Ö¸³öת´¢Îļþ°´²¿ÃÅ/¹«Ë¾×éÖ¯µÄѹËõ´æµµ½á¹¹Óë2024-2025Äê»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯¼°Êý¾Ý¾­¼ÍÈË×÷°¸ÊÖ·¨¸ß¶ÈÒ»Ö ¡£Ö»¹ÜAlmavivaÓëFS¼¯Ížùδ»ØÓ¦Ã½Ìå³õÆÚÎÊѯ £¬µ«AlmavivaºóÐøÍ¨¹ý±¾µØÃ½ÌåÉêÃ÷֤ʵÊÂÎñ£ºÆä°²È«¼à¿Ø²¿ÃŽüÆÚ·¢ÏÖ²¢¸ôÀëÁËһ·ӰÏ칫˾ϵͳµÄÍøÂç¹¥»÷ £¬µ¼Ö²¿ÃÅÊý¾Ý±»µÁ ¡£¸Ã¹«Ë¾ÒÑÆô¶¯°²È«Ó¦¶Ô·¨Ê½ £¬È·±£¹Ø¼ü·þÎñÔËÐÐ £¬²¢Í¨Öª¾¯·½¡¢¹ú¶ÈÍøÂ簲ȫ»ú¹¹¼°Êý¾Ý±£»¤»ú¹¹ £¬Ä¿Ç°µ÷²éÈÔÔÚµ±¾Ö»ú¹¹Ð­ÖúϽøÐÐ £¬³ÐŵÒÔͨÃ÷·½Ê½¸üнøÕ¹ ¡£Ä¿Ç° £¬Êý¾Ýй¶ÊÇ·ñÔ̺¬³Ë¿ÍÐÅÏ¢»òÓ°ÏìFS¼¯ÍÅÒÔ±íµÄÆäËû¿Í»§Éв»Ã÷È· ¡£


https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-23tb-data-from-italian-rail-group-almavia/


5. PhotocallµÁ°æÆ½Ì¨Ôâ¹Ø¹Ø £¬³¬2600ÍòÓû§ÊÜÓ°Ïì


11ÔÂ20ÈÕ £¬Õ¼Óг¬2600ÍòÓû§µÄµÁ°æµçÊÓÁ÷ýÌåÆ½Ì¨PhotocallÔÚ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©ÓëDAZN½áºÏµ÷²éºóÒÑÖÕ³¡ÔËÓª ¡£¸Ãƽ̨δ¾­ÊÚȨÌṩÀ´×Ô60¸ö¹ú¶ÈµÄ1127¸öµçÊÓÆµÂ·½Ó¼û·þÎñ £¬º­¸ÇÌåÓýÈüÊÂÖ±²¥¡¢Òâ¼×ÁªÈü¡¢NFL/NHLÈüʼ°»Ê¼ÒÂíµÂÀï¡¢°ÍÈûÂÞÄǵȾãÀÖ²¿ÆµÂ· £¬Óû§É¢²¼ÒÔÎ÷°àÑÀ£¨30%£©¡¢Ä«Î÷¸ç£¨13%£©ÎªÖ÷ £¬µÂ¹ú¡¢Òâ´óÀû¡¢ÃÀ¹ú¸÷Õ¼6% ¡£Ö»¹Üδֱ½ÓÌṩDAZNƵ· £¬µ«Æ½Ì¨³Áзַ¢ÁËÆäºÏ×÷ͬ°éÄÚÈÝ£¨ÈçMotoGPºÍF1ÈüÊ£© £¬×é³ÉÇÖȨ ¡£Õâ´Î¹Ø¹ØÔ´ÓÚÅ·ÖÞÐ̾¯×é֯Эµ÷µÄ¿ç¹ú·¨ÂÉÐж¯ £¬Ðж¯Öвé·â69¸ö·¸·¨ÍøÕ¾£¨Äê½Ó¼ûÁ¿³¬1180Íò£© £¬25¸ö·¸·¨IPTV·þÎñ±»Òƽ»¼ÓÃÜÇ®±ÒÌṩÉ̲é·â £¬²é»ñ¼ÛÖµ5500ÍòÃÀÔª¼ÓÃÜÇ®±Ò £¬²¢Æô¶¯44Ïîе÷²é ¡£PhotocallÓòÃûÒÑ×ªÒÆÖÁACE²¢³Á¶¨ÏòÖÁºÏ·¨ÅÔ¹ÛÍøÕ¾ £¬ÔËÓªÉÌÔÞ³ÉÖÕ³¡ÔËÓª ¡£


https://www.bleepingcomputer.com/news/security/tv-streaming-piracy-service-photocall-with-26m-yearly-visits-shut-down/


6. SalesforceÓëGainsightÓ¦¶ÔÊý¾ÝÇÔÈ ¡£º³·ÏúÁîÅÆÒÆ³ýÀûÓÃ


11ÔÂ20ÈÕ £¬SalesforceÔÚµ÷²é¿Í»§Êý¾ÝÇÔÈ¡¹¥»÷ʱ £¬·¢ÏÖÒì³£»î¶¯Ô´ÓÚGainsight°ä²¼µÄÀûÓ÷¨Ê½ÓëSalesforceµÄ±í²¿ÏÎ½Ó £¬¶ø·Ç×ÔÉíCRMƽ̨·ì϶ ¡£¸Ã¹«Ë¾Òѳ·ÏúËùÓÐÓë¸ÃÀûÓ÷¨Ê½¹ØÁªµÄ½Ó¼ûÁîÅÆºÍË¢ÐÂÁîÅÆ £¬²¢ÁÙʱ½«Æä´ÓAppExchangeÒÆ³ý £¬Í¬Ê±Í¨ÖªÊÜÓ°Ïì¿Í»§²¢ÌṩԮÊÖ ¡£Õâ´ÎÊÂÎñÓë2025Äê8ÔÂSalesloftÊý¾Ýй¶ģʽÀàËÆ £¬ÆäʱÀÕË÷×éÖ¯¡°Scattered Lapsus$ Hunters¡±ÀûÓÃÇÔÈ¡µÄOAuthÁîÅÆ £¬´Ó¿Í»§SalesforceÊ·ýÖÐÇÔÈ¡ÁËÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÐÅÏ¢ £¬Ó°ÏìÔ¼760¼Ò¹«Ë¾ £¬µ¼ÖÂ15ÒڱʼÍ¼й¶ £¬Éæ¼°Google¡¢Cloudflare¡¢Palo Alto NetworksµÈ³ÛÃûÆóÒµ ¡£ShinyHunters×éÖ¯Ðû³Æ £¬Í¨¹ýSalesloft Drift·ì϶ÖÐÇÔÈ¡µÄÃÜÔ¿ÈëÇÖGainsightºó £¬½øÒ»²½»ñÈ¡ÁË285¸öSalesforceÊ·ýµÄ½Ó¼ûȨÏÞ ¡£Gainsight´ËǰÒÑ֤ʵ £¬¹¥»÷Õßͨ¹ýÓëSalesloft Drift¹ØÁªµÄ±»µÁOAuthÁîÅÆÈëÇÖ £¬Ð¹Â¶ÁËÆóÒµÁªÏµÐÅÏ¢ ¡£SalesforceÇ¿µ÷ £¬ËùÓжñÒâ»î¶¯¾ùÓë±í²¿ÀûÓ÷¨Ê½ÏνÓÓÐ¹Ø £¬¶ø·Çƽ̨×ÔÉí·ì϶ ¡£


https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/