ˮʦÁª°îÐÅÓþºÏ×÷Éç·þÎñÆ÷ÅäÖÃÃýÎóÖÂÄÚ²¿Îļþй¶

°ä²¼¹¦·ò 2025-09-05

1. ˮʦÁª°îÐÅÓþºÏ×÷Éç·þÎñÆ÷ÅäÖÃÃýÎóÖÂÄÚ²¿Îļþй¶


9ÔÂ3ÈÕ£¬£¬ÍøÂ簲ȫ×êÑÐÔ±Jeremiah FowlerÔÚµ÷²éÖз¢ÏÖ£¬£¬ÃÀ¹úˮʦÁª°îÐÅÓþºÏ×÷É磨NFCU£©Ò»Ì¨ÅäÖÃÃýÎóµÄ·þÎñÆ÷¶³öÁË378GBÃô¸ÐÄÚ²¿Îļþ£¬£¬ÊÂÎñÓÉWebsite Planet×êÑÐÍŶÓÓëHackread.com½áºÏÅû¶¡£¡£¡£¡£¡£¸Ã·þÎñÆ÷δÉèÖÃÃÜÂë±£»£»£»¤£¬£¬ÈκÎÈ˾ù¿É½Ó¼ûδ¼ÓÃܵı¸·ÝÊý¾Ý¡£¡£¡£¡£¡£Ö»¹Üй¶ÄÚÈݲ»Ô̺¬¿Í»§ÐÅÏ¢£¬£¬µ«Â¶³öµÄÎļþÔ̺¬´óÁ¿Ç±ÔÚÃô¸ÐÊý¾Ý£ºÄÚ²¿Óû§Ãû¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢É¢ÁÐÃÜÂë¼°ÃÜÔ¿£¬£¬ÒÔ¼°ÓÉÊý¾Ý·ÖÎöƽ̨TableauÌìÉúµÄ¶à¸ö¹¤×÷²¾Îĵµ¡£¡£¡£¡£¡£ÕâЩÎĵµ¾ßÌå¼Í¼ÁËÓëÆäËûÄÚ²¿Êý¾Ý¿âµÄÏνÓÅäÖᢡ¢´û¿î¼¨Ð§ÓëÀûÈóÍÆËãµÄ²ÆÕþ¹«Ê½µÈÖ÷ÌâÔËÓªÐÅÏ¢£¬£¬×é³ÉÐÅÓþºÏ×÷ÉçÄÚ²¿ÏµÍ³µÄ¡°¼¼ÊõÀ¶Í¼¡±¡£¡£¡£¡£¡£FowlerÔÚºËʵ¹ý³ÌÖнØÈ¡µÄ½ØÍ¼ÏÔʾ£¬£¬Îļþ»¹Ô̺¬ÏµÍ³ÈÕÖ¾¡¢¡¢²úÆ·´úÂë¼°±¾Ó¦±£ÃܵÄÔªÊý¾Ý¡£¡£¡£¡£¡£ÊÂÎñ²úÉúºó£¬£¬NFCUѸËÙÏìÓ¦£¬£¬ÔÚÊýСʱÄÚ±£»£»£»¤ÁËÊý¾Ý¿â¡£¡£¡£¡£¡£È»¶ø£¬£¬Â¶³öʱ³¤¼°ÊÇ·ñ±»µÚÈý·½½Ó¼ûÈÔ²»Ã÷È·¡£¡£¡£¡£¡£FowlerÖ¸³ö£¬£¬±¸·ÝÊý¾Ý³£±»ÊÓΪ¡°³ö²úÊý¾ÝµÄ¾µÏñ¡±£¬£¬µ«Æä¹ØÁªµÄ³ö²úϵͳ½á¹¹»òÔªÊý¾ÝÈÔ¿ÉÄÜй¶¹Ø¼ü°²È«ÐÅÏ¢¡£¡£¡£¡£¡£


https://hackread.com/misconfigured-server-navy-federal-credit-union-data-leak/


2. αÔìAnyDesk×°Ö÷¨Ê½Í¨¹ýClickFixȦÌ×´«²¼MetaStealer


9ÔÂ3ÈÕ£¬£¬HuntressÍøÂ簲ȫÍŶӽüÈո淢һÖÖÐÂÐÍClickFixȦÌ×£¬£¬¹¥»÷Õßͨ¹ýαÔìºÏ·¨Ô¶³Ì½Ó¼û¹¤¾ßAnyDeskµÄ×°Ö÷¨Ê½£¬£¬½áºÏWindowsËÑË÷Ö°ÄÜÈÆ¹ý°²È«·À»¤£¬£¬×îÖÕÔÚÓû§É豸ÉϾ²Ä¬²¿ÊðMetaStealer¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã»î¶¯Ñ¡È¡Éý¼¶°æ¡°FileFix¡±¼¼Êõ£¬£¬Ïà½Ï´«Í³ClickFixȦÌ×£¨ÒªÇóÓû§¸´ÖÆÕ³ÌùºÅÁîµ½ÔËÐжԻ°¿ò£©£¬£¬ÆäΣÏÕÐÔÏÔÖøÌáÉý¡£¡£¡£¡£¡£¹¥»÷Á÷³ÌʼÓÚÓû§ÔÚÏßËÑË÷AnyDeskʱÎóÈëÐéÎ±ÍøÕ¾¡£¡£¡£¡£¡£¸ÃÒ³Ãæ¼Ù×°³ÉCloudflare CAPTCHAÑéÖ¤½çÃæ£¬£¬ÓÕµ¼Óû§µã»÷¡°ÑéÖ¤¡±°´Å¥¡£¡£¡£¡£¡£µã»÷ºó£¬£¬ÍøÕ¾´¥·¢WindowsÎļþ×ÊÔ´ÖÎÀíÆ÷Ö´ÐÐÌØÊâËÑË÷²éÎÊ£¬£¬½«Óû§ÍÆËã»úÏνÓÖÁºÚ¿Í½ÚÖÆµÄÔ¶³Ì·þÎñÆ÷£¬£¬²¢Ö±½ÓÍÆËͼÙ×°³É¡°Readme Anydesk.pdf¡±µÄ¶ñÒâ×°Öðü¡£¡£¡£¡£¡£¸ÃÎļþÀíÂÛΪPDFÎĵµ£¬£¬ÊµÔòÔ̺¬Ë«ÖزÙ×÷Âß¼­£ºÏÈÏÂÔØºÏ·¨AnyDeskÀûÓ÷¨Ê½ÒÔ½µµÍÓû§¾¯Ì裬£¬Ëæºó¾²Ä¬×°ÖÃMetaStealer¶ñÒâÈí¼þ¡£¡£¡£¡£¡£MetaStealer¾ß±¸¸ßÒñ±ÎÐÔÐÅÏ¢ÇÔÈ¡ÄÜÁ¦£¬£¬¿ÉµÁÈ¡µÇ¼ƾ֤¡¢¡¢Ãô¸ÐÎļþ¼°¼ÓÃÜÇ®°üÊý¾Ý£¬£¬×é³ÉÑÏÖØ°²È«Íþв¡£¡£¡£¡£¡£


https://hackread.com/fake-anydesk-installer-metastealer-clickfix-scam/


3. È«Çò¶à¹úÔâ·ê³¬2.5ÒÚ·ÝÉí·Ý¼Í¼´ó¹æÄ£Ð¹Â¶Î£»£»£»ú


9ÔÂ3ÈÕ£¬£¬½üÆÚ£¬£¬Ò»³¡Éæ¼°ÖÁÉÙÆß¸ö¹ú¶È¡¢¡¢³¬2.5ÒÚ·ÝÉí·Ý¼Í¼µÄ´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÒý·¢È«Çò¹Ø×¢¡£¡£¡£¡£¡£Õâ´Îй¶µÄ¹«ÃñÐÅÏ¢¸²¸ÇÍÁ¶úÆä¡¢¡¢°£¼°¡¢¡¢É³Ìذ¢À­²®¡¢¡¢°¢ÁªÇõ¡¢¡¢Ä«Î÷¸ç¡¢¡¢ÄϷǺͼÓÄô󣬣¬Ô̺¬Éí·ÝÖ¤ºÅÂë¡¢¡¢µ®ÉúÈÕÆÚ¡¢¡¢ÁªÏµ·½Ê½¼°¼ÒͥסַµÈµ±¾ÐĶÉí·Ýµµ°¸Ï¸½Ú¡£¡£¡£¡£¡£Èý̨ÅäÖÃÃýÎóµÄ·þÎñÆ÷£¨ÍйÜÓÚ°ÍÎ÷ºÍ°¢ÁªÇõIPµØÖ·£©³ÉΪй¶Դͷ£¬£¬ÆäÊý¾Ý¿â½á¹¹¸ß¶ÈÀàËÆ£¬£¬°µÊ¾¿ÉÄÜÔ´×ÔͳһÔËÓª·½£¬£¬µ«¾ßÌå½ÚÖÆÕßÈÔÎÞ·¨È·¶¨¡£¡£¡£¡£¡£Cybernews×êÑÐÈËÔ±Ö¸³ö£¬£¬ÍÁ¶úÆä¡¢¡¢°£¼°ºÍÄϷǹ«ÃñÊÜÓ°ÏìÓÈΪÑÏÖØ£¬£¬ÕâЩ¹ú¶ÈµÄÊý¾Ý¿âÔ̺¬È«ÃæÉí·ÝÐÅÏ¢£¬£¬Îª½ðÈÚڲƭ¡¢¡¢Éí·ÝðÓᢡ¢¶¨ÏòÍøÂç´¹µö¼°Ú¿Æ­µÈÀÄÓÃÐÐΪ´ò¿ªÁË´óÃÅ¡£¡£¡£¡£¡£ÊÂÎñÆØ¹âºó£¬£¬ÍйܷþÎñÌṩÉÌÒÑÏÞ¶ÈÊý¾Ý¹«¿ª½Ó¼û£¬£¬µ«Ð¹Â¶ÐÅÏ¢µÄDZÔÚÀÄÓ÷çÏÕÈÔ³ÖÐø´æÔÚ¡£¡£¡£¡£¡£


https://cybernews.com/security/identity-records-global-data-leak/


4. CISAÖÒ¸æTP-LinkÓëWhatsApp·ì϶Ôâ»îÔ¾ÀûÓÃ


9ÔÂ3ÈÕ£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£ÖҸ棬£¬Ö¸³öºÚ¿ÍÕý»ý¼«ÀûÓÃÁ½¸ö¸ßΣ·ì϶ÌáÒé¹¥»÷£¬£¬²¢Òѽ«¶þÕßÁÐÈë¡°ÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©¡±Ä¿Â¼£¬£¬Ç¿µ÷Æä´ºÁª°îÆóÒµ×é³ÉÖØ´óÍþв¡£¡£¡£¡£¡£Ê׸ö·ì϶ӰÏìTP-Link TL-WA855RE V5 WiFiÀ©´óÆ÷£¬£¬¸ÃÉ豸ÔÚÑÇÂíÑ·Õ¼Óг¬120,500ÌõÆÀÂÛ£¬£¬ÏÔʾÆä¿í·ºÊ¢ÐС£¡£¡£¡£¡£·ì϶´æÔÚÎåÄ꣬£¬ÑÏÖØÐÔÆÀ·Ö´ï8.8/10£¬£¬ÔÊÐíÍ³Ò»ÍøÂçϵÄδ¾­Éí·ÝÑéÖ¤¹¥»÷Õß·¢ËÍTDDP_RESET POSTÒªÇ󣬣¬´¥·¢É豸¹¤³§ÖØÖò¢ÖØÆô£¬£¬ËæºóÉèÖÃÐÂÖÎÀíÃÜÂëÒÔ»ñÈ¡½ÚÖÆÈ¨¡£¡£¡£¡£¡£CISAÖ¸³ö£¬£¬Î´´ò²¹¶¡ÇÒÓ²¼þ°æ±¾ÎªV5µÄÉ豸Ò×Êܹ¥»÷£¬£¬¹©¸øÉÌËäÒÑÌṩ¹Ì¼þ¸üУ¬£¬µ«²¿ÃÅÉ豸¿ÉÄÜÒÑ´ïÐÔÃüÖÜÆÚÖյ㣬£¬½¨ÒéÁª°î»ú¹¹Á¢¼´ÖÕ³¡Ê¹Óûò²ÉÈ¡Ñϸñ»º½â´ëÊ©¡£¡£¡£¡£¡£µÚ¶þÏî·ìÏ¶Éæ¼°WhatsApp iOS/Mac¿Í»§¶Ë£¬£¬ÓÉ¡°Á´½ÓÉ豸ͬ²½ÐÂÎÅÊÚȨ²»ÆëÈ«¡±Òý·¢£¬£¬¿ÉÄÜÔÊÐíÎÞ¹ØÓû§´¥·¢Ö¸±êÉ豸´¦ÖÃËÁÒâURLÄÚÈÝ£¬£¬Òѱ»ÓÃÓڸ߼¶¼äµýÈí¼þ»î¶¯¡£¡£¡£¡£¡£WhatsAppÓëÆ»¹ûÒѰ䲼´¹Î£¸üÐÂÐÞ¸´´ËÎÊÌ⣬£¬¹©¸øÉÌÆÀ¹ÀÒÔΪ¸Ã·ì϶¿ÉÄܱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ö¸±êÓû§µÄ¸´ÔÓ¹¥»÷¡£¡£¡£¡£¡£


https://cybernews.com/security/tp-link-whatsapp-vulnerabilities-exploited-by-hackers/


5. Chess.comÅû¶µÚÈý·½ÀûÓÃÊý¾Ýй¶ÊÂÎñ£¬£¬Ó°Ïì4500ÃûÓû§


9ÔÂ4ÈÕ£¬£¬È«Çò×î´óÔÚÏß¹ú¼ÊÏóÆåƽ̨Chess.com½üÈÕÅûÂ¶Ò»Â·Éæ¼°µÚÈý·½Îļþ´«ÊäÀûÓõÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¾Ý²¼¸æ£¬£¬2025Äê6ÔÂ5ÈÕÖÁ18ÈÕÆÚ¼ä£¬£¬ÍþвÐÐΪÕßδ¾­ÊÚȨ½Ó¼ûÁË¸ÃÆ½Ì¨Ê¹ÓõĵÚÈý·½Îļþ´«ÊäÀûÓ÷¨Ê½£¬£¬µ¼ÖÂÔ¼4,500ÃûÓû§µÄСÎÒÉí·ÝÐÅÏ¢£¨PII£©¿ÉÄܱ»Ð¹Â¶¡£¡£¡£¡£¡£Chess.comÓÚ6ÔÂ19ÈÕ·¢ÏÖÒì³£ºó£¬£¬Á¢¼´Æô¶¯µ÷²é²¢ÀñƸ¶¥¼â°²È«×¨¼Ò£¬£¬Í¬²½Í¨ÖªÁª°î·¨Âɲ¿ÃÅ£¬£¬²¢²ÉÈ¡´ëÊ©ÐÞ¸´·ì϶¡£¡£¡£¡£¡£¹«Ë¾Ç¿µ÷£¬£¬Õâ´ÎÊÂÎñ½öÓ°ÏìµÚÈý·½ÀûÓ÷¨Ê½£¬£¬Æä×ÔÉí»ù´¡ÉèÊ©¼°»áÔ±ÕË»§ÏµÍ³Î´Êܲ¨¼°¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÖØÒªÔ̺¬Óû§ÐÕÃû¼°ÆäËûPII£¬£¬µ«Î´Éæ¼°²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£Ä¿Ç°ÎÞÖ¤¾ÝÅú×¢±»µÁÊý¾ÝÒѱ»¹«¿ªÅû¶»òÀÄÓᣡ£¡£¡£¡£×÷Ϊ²¹¾È´ëÊ©£¬£¬Chess.comΪÊÜÓ°ÏìÓû§Ìṩ1-2ÄêÃâ·ÑÉí·Ý͵ÇÔÓëÐÅÓþ¼à¿Ø·þÎñ£¬£¬Óû§ÐèÔÚ2025Äê12ÔÂ3ÈÕǰʵÏÖ×¢²á¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/chesscom-discloses-recent-data-breach-via-file-transfer-app/


6. ÆÕÀû˾ͨ±±ÃÀ¹¤³§È·ÈÏÍøÂç¹¥»÷Ó°ÏìÁËÆä³ö²ú


9ÔÂ4ÈÕ£¬£¬È«Çò×î´óÂÖÌ¥ÖÆ×÷ÉÌÆÕÀû˾֤ͨʵ£¬£¬Æä±±ÃÀ·Ö¹«Ë¾ÆÕÀû˾ͨÃÀÖÞ¹«Ë¾£¨BSA£©Õýµ÷²éÓ°Ï첿ÃÅÖÆ×÷¹¤³§ÔËÓªµÄÍøÂç¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÓÚ2025Äê9ÔÂ2ÈÕ³õ´Î±»±¨µÀ£¬£¬Éæ¼°ÄÏ¿¨ÂÞÀ´ÄÉÖݰ¬¿ÏÏØÁ½¼Ò¹¤³§¼°¼ÓÄôó¿ý±±¿ËÊ¡ÇÇÀû°£¼éϸ³§£¬£¬Òý·¢³ö²úÖжÏ¡£¡£¡£¡£¡£BSA×÷ΪÆÕÀû˾ͨ¼¯ÍÅÖØÒª·ÖÖ§£¬£¬Õ¼ÓÐ50¼Ò¹¤³§¡¢¡¢5.5ÍòÃûÔ±¹¤£¬£¬Õ¼¼¯ÍÅ×ܹæÄ£43%£¬£¬2024ÄêÏúÊÛ¶î´ï120ÒÚÃÀÔª£¬£¬½»Ò×ÀûÈó12ÒÚÃÀÔª¡£¡£¡£¡£¡£ÆÕÀû˾ͨǿµ÷£¬£¬Æä¼±¾çÏìÓ¦»úÖÆÔÚÔçÆÚ½×¶ÎÓÐЧ¶ôÖÆÁ˹¥»÷ÊæÕ¹£¬£¬Ô¤·À¿Í»§Êý¾Ýй¶»òÉî¶ÈÍøÂçÉøÈë¡£¡£¡£¡£¡£¹«Ë¾ÉêÃ÷³Æ£¬£¬ÍŶÓÒѰ´¼È¶¨ºÍ̸½ÚÖÆÎÊÌ⣬£¬È¡Ö¤·ÖÎöÈÔÔÚ½øÐУ¬£¬µ«³õ²½ÅжÏÊÂÎñÓ°ÏìÓÐÏÞ£¬£¬Î´·¢ÏÖ¿Í»§Êý¾Ý»òϵͳ½Ó¿ÚÔâй¶¡£¡£¡£¡£¡£Îª¼õÇṩ¸øÁ´·çÏÕ£¬£¬Ô±¹¤Õý24Сʱ¹¤×÷ÒÔ¸´Ô­ÔËÓª£¬£¬È·±£Êг¡²úÆ·¹©¸ø²»±ä¡£¡£¡£¡£¡£ÆÕÀû˾ͨ½«¡°Î¬³ÖÒµÎñÂ½ÐøÐÔ¼°±£»£»£»¤Êý¾Ý½Ó¿Ú¡±ÁÐΪÊ×Òª¹¤×÷£¬£¬²¢³ÐÅµÍÆ¹ã¿Í»§Ê¹Ãü£¬£¬½â¾öDZÔÚºóÐøÓ°Ïì¡£¡£¡£¡£¡£Õë¶ÔýÌåѯÎÊÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ¹¥»÷£¬£¬¹«Ë¾ÉÐδ»ØÓ¦£¬£¬Ä¿Ç°Ò²ÎÞÈκÎÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´ÎÊÂÎñÕÆ¹Ü¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/tire-giant-bridgestone-confirms-cyberattack-impacts-manufacturing/