½É×Ô¿ØÆðͷ֪ͨÊÜ2023ÄêÊý¾Ýй¶ÊÂÎñÓ°ÏìµÄÓû§
°ä²¼¹¦·ò 2025-07-031. ½É×Ô¿ØÆðͷ֪ͨÊÜ2023ÄêÊý¾Ýй¶ÊÂÎñÓ°ÏìµÄÓû§
7ÔÂ1ÈÕ£¬£¬£¬È«ÇòÂ¥Óî×Ô¶¯»¯¾ÞÍ·½É×ԿؽüÈÕÅû¶£¬£¬£¬Æä2023Äê9ÔÂÔâ·êµÄÀÕË÷Èí¼þ¹¥»÷µ¼Ö³¬¹ý27TBÃô¸ÐÊý¾Ý±»µÁ£¬£¬£¬¹¥»÷ÕßÒªÇóÖ§¸¶5100ÍòÃÀÔªÊê½ðÒÔ»»È¡Êý¾Ý½âÃܺÍɾ³ý¡£Õâ´ÎÊÂÎñʼÓÚ2023Äê2ÔÂÑÇÖÞ´¦Ê´¦ÍøÂç±»ÈëÇÖ£¬£¬£¬¹¥»÷Õßͨ¹ýºáÏòÒÆ¶¯ÉøÈëÖÁÖ÷Ìâϵͳ£¬£¬£¬×îÖÕÔÚ9Ô²¿Êð¶¨ÖÆ»¯ÀÕË÷Èí¼þ£¬£¬£¬¼ÓÃÜVMware ESXiÐé¹¹»ú²¢Ì±»¾¹Ø¼ü»ù´¡ÉèÊ©¡£×÷Ϊ¿ç¹ú¹¤Òµ¼¯ÍÅ£¬£¬£¬½É×Ô¿ØÔÚ150¸ö¹ú¶ÈÕ¼ÓÐ10ÍòÃûÔ±¹¤£¬£¬£¬Æä°²·À¡¢¡¢¡¢Å¯Í¨¿Õµ÷¼°Ïû·Àϵͳ¿í·ºÀûÓÃÓÚÈ«ÇòµØ±ê¹¹Öþ¡£Õâ´Î¹¥»÷µ¼ÖÂÆäÈ«ÇòITϵͳ´ó¹æÄ£å´»ú£¬£¬£¬¿Í»§¶©µ¥´¦Öᢡ¢¡¢Éè±¸ÊØ»¤µÈÖ÷ÌâÒµÎñÖжÏÊýÖÜ¡£¹«Ë¾ÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ìá½»µÄÎļþÏÔʾ£¬£¬£¬ÊÂÎñÏìÓ¦ÓëÐÞ¸´³É±¾ÒÑ´ï2700ÍòÃÀÔª£¬£¬£¬ÇÒÔ¤¼Æ½«³ÖÐøÅÊÉý¡£µ÷²é·¢ÏÖ£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ýº¸ÇÔ±¹¤ÐÅÏ¢¡¢¡¢¡¢¿Í»§ºÏͬ¡¢¡¢¡¢²úÆ·Ñз¢×ÊÁϼ°Ã³Ò×»úÃÜ£¬£¬£¬²¿ÃÅÎļþ±»ÉÏ´«ÖÁÃûΪ¡°Dunghill Leaks¡±µÄ°µÍøÐ¹ÃÜÆ½Ì¨¡£ÍøÂ簲ȫר¼Ò½«Õâ´Î¹¥»÷¹éÒòÓÚDark AngelsÀÕË÷×éÖ¯¡£¹«Ë¾Ç¿µ÷£¬£¬£¬Ö»¹ÜÖ§¸¶ÁË2700ÍòÃÀÔªÓ¦¼±Óöȣ¬£¬£¬µ«»Ø¾øÏòÀÕË÷ÕßÍ×У¬£¬£¬ËùÓÐϵͳÒÑͨ¹ý±¸·Ý¸´ÔÔËÐС£
https://www.bleepingcomputer.com/news/security/johnson-controls-starts-notifying-people-affected-by-2023-breach/
2. À¶ÑÀ¶ú»ú¸ßΣ·ìÏ¶ÆØ¹â£¬£¬£¬Ë÷ÄáµÈÆ·ÅÆÉè±¸Ãæ¶Ô¼àÌý·çÏÕ
7ÔÂ1ÈÕ£¬£¬£¬µÂ¹úÍøÂ簲ȫ¹«Ë¾ERNW½üÈÕÅû¶£¬£¬£¬È«ÇòÊý°ÙÍǫ̀ʹÓÃAiroha SystemsоƬµÄÀ¶ÑÀ¶ú»ú´æÔÚÑÏÖØ°²È«·ì϶£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÎÞÐèÅä¶Ô»òÈÏÖ¤µÄÇé¿öÏÂÆëÈ«½ÚÖÆÉ豸£¬£¬£¬Ö±½ÓÍþвÓû§ÒþÖÔ°²È«¡£Õâ´Î·ì϶ӰÏìÁìÓò¿í·º£¬£¬£¬º¸ÇË÷Äá¡¢¡¢¡¢Bose¡¢¡¢¡¢Marshall¡¢¡¢¡¢Jabra¡¢¡¢¡¢JBLµÈÊ®Óà¸öÖ÷Á÷Æ·ÅÆµÄÊýÊ®¿îÈȵãÐͺţ¬£¬£¬Ô̺¬Ë÷ÄáWH-1000XMϵÁнµÔë¶ú»ú¡¢¡¢¡¢Bose QuietComfort¶úÈû¡¢¡¢¡¢Marshall STANMORE IIIÒôÏäµÈÊг¡³©Ïú²úÆ·¡£×êÑÐÏÔʾ£¬£¬£¬·ì϶Ö÷ÌâÔ´ÓÚAirohaÀ¶ÑÀоƬµÄ×Ô½ç˵ºÍ̸ȱµã£¨CVE-2025-20702£©¡£¹¥»÷Õß½öÐè´¦ÓÚÀ¶ÑÀÐźŸ²¸ÇÁìÓò£¨Ô¼10Ã×ÄÚ£©£¬£¬£¬¼´¿Éͨ¹ý¸ÃºÍ̸ֱ½Ó¶ÁдÉ豸ÄÚ´æ»ò¹Ì¼þ£¬£¬£¬ÊµÏÖ¶ñÒâ´úÂë×¢Èë¡¢¡¢¡¢¹Ì¼þ´Û¸ÄµÈ²Ù×÷¡£¸üÑϸñµÄÊÇ£¬£¬£¬ºÚ¿Í¿É¼ÙÒâÒÑÅä¶ÔÉ豸ÏòÓû§ÊÖ»ú·¢ËÍÖ¸Á£¬£¬ÀýÈçÇÔȡͨ»°¼Í¼¡¢¡¢¡¢ÁªÏµÈËÐÅÏ¢£¬£¬£¬ÉõÖÁÔ¶³Ì²Ù¿ØÂó¿Ë·ç½øÐÐʵʱ¼àÌý¡£Ö»¹ÜÏÖʵ¹¥»÷Ðè½Ï¸ß¼¼ÊõˮƽÇÒÒÀÀµÎïÀíÁÚ½üÐÔ£¬£¬£¬µ«Õë¶ÔÕþÒª¡¢¡¢¡¢¼ÇÕß¡¢¡¢¡¢ÆóÒµ¸ß¹ÜµÈ¸ß¼ÛÖµÖ¸±êµÄDZÔÚ·çÏÕÈÔÒý·¢ÓÇÓô¡£AirohaËäÒÑÓÚ2025Äê6ÔÂÏò³§ÉÌÌṩÐÞ¸´²¹¶¡£¬£¬£¬µ«Éè±¸ÖÆ×÷É̵Ĺ̼þ¸üнø¶È²Î²î²»Æë¡£
https://cybernews.com/security/millions-of-headphones-vulnerable-to-bluetooth-hacks/
3. ¶íÂÞ˹¹ú·À¾ÞÍ·NPO MarsÔâºÚ¿Í¹¥»÷£¬£¬£¬Ë®Ê¦»úÃÜÊý¾Ýй¶
7ÔÂ1ÈÕ£¬£¬£¬¶íÂÞ˹Áª°î¼¶¹ú·À³Ð°üÉÌNPO Mars½üÈÕÔâ·êÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬£¬£¬¹¥»÷ÕßÐû³ÆÇÔÈ¡ÁË250GBÃô¸Ð¾üÊÂÎļþ£¬£¬£¬Éæ¼°¶íÂÞ˹ˮʦÖ÷ÌâÖ¸»Ó½ÚÖÆÏµÍ³¡£Æ¾¾Ý×êÑÐÍŶӵĵ÷²é£¬£¬£¬Ð¹Â¶Êý¾ÝÔ̺¬´óÁ¿±êעΪ¡°¾øÃÜ¡±µÄPDFÎļþºÍ¼¼ÊõÊֲᣬ£¬£¬²¿ÃÅÎļþ¸üÐÂÖÁ2025Äê3Ô£¬£¬£¬Ö¤Êµ¹¥»÷ÓµÓи߶ÈʱЧÐÔ¡£ÆäÖУ¬£¬£¬ÃûΪ¡°SIGMA-20385¡±µÄ×÷Õ½ÐÅÏ¢Óë½ÚÖÆÏµÍ³ÊÖ²áÓÈΪ¹Ø¼ü£¬£¬£¬¸ÃÏµÍ³ÕÆ¹Ü¶íÂÞ˹ˮʦ½¢Í§µÄ»ú¶¯½ÚÖÆ¡¢¡¢¡¢·´Ç±·ÀÓù¼°µ¼µ¯±øÆ÷Ðͬ¡£¹¥»÷Õß°ä²¼µÄÊÓÆµ¸æ°×¸üÐû³ÆÒÑÈëÇÖ¡°TRASSA¡±×ÛºÏÖ¸»Óϵͳ¼°¡°DIEZ¡±É¨À×ͧ×Ô¶¯½ÚÖÆÏµÍ³£¬£¬£¬ÉõÖÁÑÝʾ´Û¸Ä¶í¾ü½¢Í§×ø±êÊý¾ÝµÄ²Ù×÷½çÃæ£¬£¬£¬°µÊ¾Æä¾ß±¸ÊµÊ±×ÌÈÅÄÜÁ¦¡£NPO Mars×÷Ϊ¶íÂÞ˹¾üÊ¿Ƽ¼Ö÷ÌâÆóÒµ£¬£¬£¬ÆäÒµÎñ¸²¸Ç×Ô¶¯»¯Ö¸»Óϵͳ¡¢¡¢¡¢×°¼×³µÁ¾½ÚÖÆÆ½Ì¨¼°Ë®Ê¦½¢Í§µç×ÓÉ豸Ñз¢£¬£¬£¬Ô±¹¤¹æÄ£³¬1100ÈË¡£¼¼Êõ·ÖÎöÏÔʾ£¬£¬£¬¹¥»÷Õß¿ÉÄÜͨ¹ý´¹µö¹¥»÷»ñÈ¡³õʼ½Ó¼ûȨÏÞ£¬£¬£¬¼Ì¶øÉøÈëÖÁÄÚÍøÇÔÈ¡»úÃÜÎĵµ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬Ð¹Â¶Êý¾ÝÑù±¾ÖмÈÔ̺¬2017ÄêµÄº¹ÇàÎļþ£¬£¬£¬Ò²º¸Ç2024Äê¸üеļ¼ÊõÊֲᣬ£¬£¬Åú×¢¹¥»÷Õ߾߱¸³Ö¾ÃÂñ·üÄÜÁ¦¡£
https://cybernews.com/security/russian-defense-contractor-mars-breach-navy/
4. CISA½«TeleMessage TM SGNL¸ßΣ·ì϶ÄÉÈëKEVĿ¼
7ÔÂ2ÈÕ£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Õýʽ½«TeleMessage TM SGNLͨѶƽ̨ÖеÄÁ½ÏîÑÏÖØ·ì϶£¨CVE-2025-48927¡¢¡¢¡¢CVE-2025-48928£©ÁÐÈë¡°ÒÑÖª±»ÀûÓ÷ì϶Ŀ¼¡±£¨KEV£©£¬£¬£¬ÒªÇóÁª°î»ú¹¹ÓÚ2025Äê7ÔÂ22ÈÕǰʵÏÖÐÞ¸´£¬£¬£¬²¢ºôÓõ˽Ӫ²¿ÃÅͬ²½×Բ顣CVE-2025-48927£¨CVSSÆÀ·Ö5.3£©Ô´ÓÚTeleMessage TM SGNLµÄSpring Boot Actuator×é¼þÅäÖÃÃýÎ󣬣¬£¬µ¼ÖÂÃô¸ÐµÄ/heapdump¶Ñת´¢¶Ëµã¶³ö¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ֱ½Ó½Ó¼ûÄÚ´æ¿ìÕÕ£¬£¬£¬ÇÔȡδ¼ÓÃܵį¾Ö¤¡¢¡¢¡¢»á»°ÁîÅÆµÈÃô¸ÐÊý¾Ý¡£CVE-2025-48928£¨CVSSÆÀ·Ö4.0£©ÔòÉæ¼°Ö÷Ìâת´¢Îļþ¶³öÎÊÌ⣬£¬£¬TeleMessage·þÎñµÄJSPÀûÓÃÔÚ´¦ÖÃHTTPÒªÇóʱ£¬£¬£¬½«Óû§ÃÜÂëµÈÃ÷ÎÄÐÅÏ¢Ö±½ÓдÈë¶ÑÄÚ´æ¿ìÕÕ£¬£¬£¬ÇÒÎļþȨÏÞ½ÚÖÆÈ±Ê§£¬£¬£¬Ê¹µÃδ¾ÊÚȨµÄ¹¥»÷Õß¾ù¿É»ñÈ¡ÕâЩÊý¾Ý¡£CISAÔÚ²¼¸æÖÐÇ¿µ÷£¬£¬£¬ÕâÁ½¸ö·ì϶µÄ×éºÏÀûÓÿÉÄÜÐÎ³ÉÆëÈ«¹¥»÷Á´£º£º¹¥»÷ÕßÊ×ÏÈͨ¹ýCVE-2025-48927»ñȡϵͳÄÚ´æÊý¾Ý£¬£¬£¬ÔÙÀûÓÃCVE-2025-48928ÌáÈ¡´æ´¢µÄÃÜÂ룬£¬£¬´Ó¶øºáÏòÉøÈëÖÁÄÚ²¿ÍøÂç¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬£¬£¬TeleMessage TM SGNL×÷ΪÆóÒµ¼¶Í¨Ñ¶Æ½Ì¨£¬£¬£¬±»¶à¼ÒÁª°î»ú¹¹ÓÃÓÚÃô¸ÐÐÅÏ¢´«Ê䣬£¬£¬·ì϶ÀûÓÿÉÄܵ¼Ö»úÃÜÊý¾Ýй¶»ò¹©¸øÁ´¹¥»÷¡£
https://securityaffairs.com/179542/hacking/u-s-cisa-adds-telemessage-tm-sgnl-flaws-to-its-known-exploited-vulnerabilities-catalog.html
5. ³¯ÏʺڿͲ¿ÊðNimDoor¸´ÔÓ¶ñÒâÈí¼þ
7ÔÂ2ÈÕ£¬£¬£¬³¯Ïʵ±¾Ö²¼¾°µÄºÚ¿Í×éÖ¯ÕýÀûÓÃÒ»¿îÃûΪNimDoorµÄÐÂÐÍmacOS¶ñÒâÈí¼þ£¬£¬£¬¶ÔÈ«Çòweb3¼°¼ÓÃÜÇ®±ÒÁìÓòÌáÒ龫׼¹¥»÷¡£ÍøÂ簲ȫ¹«Ë¾SentinelLabsÔÚ×îл㱨ÖÐÅû¶£¬£¬£¬¸Ã¹¥»÷Á´Í¨¹ýTelegramÉç½»¹¤³ÌÓÕÆÊܺ¦ÕßÔËÐмÙ×°³ÉZoom SDK¸üеĶñÒⷨʽ£¬£¬£¬Æä¼¼Êõ¸´ÔÓ¶ÈÓëÒñ±ÎÐÔ´ïµ½³¯Ïʺڿ͹¤¾ß¿âµÄȫи߶ȡ£×êÑÐÏÔʾ£¬£¬£¬NimDoorѡȡC++ÓëNim˵»°»ìºÏ±àÒëµÄ¶þ½øÖÆ×é¼þ£¬£¬£¬ÐγÉÄ£¿£¿é»¯¹¥»÷¿ò¼Ü¡£³õʼϰȾ½×¶Î£¬£¬£¬ÃûΪ"installer"µÄ¶þ½øÖÆÎļþÕÆ¹Üϵͳ»·¾³²¿Ê𣬣¬£¬Ö²Èë"GoogIe LLC"ºÍ"CoreKitAgent"Á½¸öÖ÷ÌâÄ£¿£¿é¡£×÷ΪÖ÷ÌâÔØºÉµÄCoreKitAgentչʾ³ö¶àÏîÍ»ÆÆÐÔ¼¼Êõ£º£ºÆäÒ»£¬£¬£¬Ñ¡È¡ÊÂÎñÇý¶¯¼Ü¹¹£¬£¬£¬Í¨¹ýmacOSµÄkqueue»úÖÆÊµÏÖÒì²½¹¤×÷ÖÎÀí£»Æä¶þ£¬£¬£¬ÄÚÖÃ10Àý״̬»ú½ÚÖÆÁ÷£¬£¬£¬¿Éƾ¾ÝÔËÐÐʱǰÌᶯ̬µ÷Õû¹¥»÷Âß¼£»ÆäÈý£¬£¬£¬¿ª´´ÐÔµØÊ¹ÓûùÓÚÐźŵÄÓÆ¾Ã»¯»úÖÆ¡£ÔÚÊý¾ÝÇÔÈ¡²ãÃæ£¬£¬£¬NimDoor¹¹½¨ÁË˫ͨµÀ¹¥»÷Á´¡£Ö÷Á´Í¨¹ý½âÂëÊ®Áù½øÖÆAppleScript£¬£¬£¬Ã¿30ÃëÏòC2·þÎñÆ÷·¢ËÍϵͳÐű꣬£¬£¬²¢Ö´ÐÐÔ¶³ÌosascriptºÅÁîʵÏÖÇáÁ¿¼¶ºóÃŽÚÖÆ¡£¸¨ÖúÁ´ÔòÀûÓÃ"zoom_sdk_support.scpt"¼ÓÔØÆ÷Æô¶¯WebSocketͨѶ£¬£¬£¬ÏÂÔØuplºÍtlgrmÁ½¸ö¾ç±¾£¬£¬£¬ÐγɴÓϵͳÐÅÏ¢µ½¼ÓÃÜÇ®±ÒÇ®°üµÄÆëÈ«ÇÔÈ¡Á´Â·¡£
https://www.bleepingcomputer.com/news/security/nimdoor-crypto-theft-macos-malware-revives-itself-when-killed/
6. Ò½ÁÆÆ÷е¹«Ë¾Surmodics»ã±¨Ôâ·êÍøÂç¹¥»÷
7ÔÂ3ÈÕ£¬£¬£¬ÃÀ¹úÒ½ÁÆÉè±¸ÖÆ×÷ÉÌSurmodics½üÈÕÅû¶£¬£¬£¬ÆäÓÚ6ÔÂ5ÈÕÔâ·êÍøÂç¹¥»÷µ¼Ö²¿ÃÅITϵͳ̱»¾£¬£¬£¬³ÉΪ½ñÄêµÚÈý¼ÒÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©»ã±¨´ËÀàÊÂÎñµÄÉÏÊÐÒ½ÁÆÆ÷е¹«Ë¾¡£Õâ¼Ò×ܲ¿Î»¾ÓÃ÷ÄáËÕ´ïÖÝµÄÆóÒµ×÷ΪȫÇò×î´óÍâ°üÇ×ˮͿ²ã¹©¸øÉÌ£¬£¬£¬Æä²úÆ·¿í·ºÀûÓÃÓÚѪ¹ÜÄÚÒ½ÁÆÆ÷еÒÔ½µµÍĦ²ÁϵÊý¡£¹¥»÷²úÉúºó£¬£¬£¬¹«Ë¾ITÍŶÓѸËÙ¼ì²âµ½Òì³£½Ó¼û²¢×Ô¶¯¶Â½ØÏµÍ³£¬£¬£¬×ª¶øÍ¨¹ýÊÖ¹¤Á÷³Ìά³Ö¿Í»§¶©µ¥´¦ÖÃÓë·¢»õ£¬£¬£¬µ«Õâ´ÎÊÂÎñÈÔ¶³ö³öÒ½Áƹ©¸øÁ´Êý×Ö»¯×ªÐÍÖеÄÉî²ã°²È«Òþ»¼¡£Æ¾¾ÝSECµÇ¼ÇÎļþ£¬£¬£¬SurmodicsÔÚÍøÂ簲ȫר¼ÒÐÖúÏÂÒѲ¿ÃŸ´Ô¹Ø¼üϵͳ£¬£¬£¬µ«ºÚ¿ÍÇÔÈ¡Êý¾ÝµÄ¾ßÌåÁìÓòÈÔÔÚÆÀ¹ÀÖС£¹«Ë¾Ê×ϯ²ÆÕþ¹ÙµÙĪÎ÷¡¤°¢Â×˹£¨Timothy Arens£©¾¯Ê¾£¬£¬£¬Õâ´ÎÊÂÎñ´øÀ´µÄ·çÏÕԶδ½â³ý£º£º³ý³ÖÐø½øÐеÄϵͳÐÞ¸´Í⣬£¬£¬ÖÎÀí²ãÐè·ÖÐÄÓ¦¶ÔDZÔÚËßËÏ¡¢¡¢¡¢¿Í»§ÐÅÀµÎ£»ú¼°¼à¹ÜÉó²é¡£Ö»¹Ü¹«Ë¾¼á³ÆÎ´·¢ÏÖ¿Í»§»òµÚÈý·½Êý¾Ýй¶£¬£¬£¬µ«Ò½ÁÆÐÐÒµ½üÆÚ¼¯ÌåËßËÏÆµ·¢£¬£¬£¬Ê¹µÃSurmodics¶Ô˾·¨·çÏÕά³Ö¸ß¶È¾¯Ìè¡£
https://therecord.media/surmodics-medical-device-company-reports-cybersecurity-incident


¾©¹«Íø°²±¸11010802024551ºÅ