ÒÔÉ«ÁÐɳÃ×¶ûÒ½ÁÆÖÐÐÄÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
°ä²¼¹¦·ò 2025-10-101. ÒÔÉ«ÁÐɳÃ×¶ûÒ½ÁÆÖÐÐÄÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
10ÔÂ2ÈÕ£¬£¬ÒÔÉ«ÁÐɳÃ×¶ûÒ½ÁÆÖÐÐÄ£¨Assaf Harofeh£©ÔÚÊê×ïÈÕÆÚ¼äÔâ·ê¡°÷è÷롱ÀÕË÷Èí¼þ×éÖ¯´ó¹æÄ£ÍøÂç¹¥»÷¡£¸Ã×éÖ¯Ðû³ÆÒÑÆëÈ«ÉøÈëÒ½ÔºITϵͳ£¬£¬ÇÔȡԼ8TBÃô¸ÐÊý¾Ý£¬£¬Ô̺¬»¼Õ߸öÈ˽¡¿µ¼Í¼¡¢¡¢¡¢ÄÚ²¿Í¨Ñ¶¼°¹Ø¼üÔËÓªÐÅÏ¢£¬£¬²¢½öÌṩ4·ÝÑù±¾Îļþ×÷Ϊ֤¾Ý¡£ºÚ¿ÍÒªÇóÒ½ÔºÔÚ72СʱÄÚ»ØÓ¦²¢ÐÉÌÊê½ðÖ§¸¶£¬£¬²»È»½«¹«¿ªÈ«ÊýÊý¾Ý£¬£¬Íþв³ÆÈôÒýÈë·¨ÂÉ»ò°²È«»ú¹¹½«¼Ó¿ìй¶¹ý³Ì¡£É³Ã×¶ûÒ½ÁÆÖÐÐÄλÓÚÌØÀά·ò½¼Í⣬£¬Ä껼ÕßÈÝÁ¿´ï90%£¬£¬·þÎñÒÔÉ«ÁÐÖв¿³¬°ÙÍò¾ÓÃñ£¬£¬º¸ÇÃÅÕï¡¢¡¢¡¢¼±Õï¼°ÌØÊâÒ½ÁÆÐèÒª£¬£¬Æä·þÎñÉçÇøÔ̺¬¶àÔª×ڽ̡¢¡¢¡¢¾¼Ã²¼¾°ÈËȺ¡£Õâ´Î¹¥»÷Ç¡·êÓÌÌ«½ÌÖØÒªÊ¥ÈÕÊê×ïÈÕ£¨10ÔÂ1ÈÕ-2ÈÕ£©£¬£¬Òý·¢¶Ô¹¥»÷¶¯»úµÄ²Â²â¡£Ò½ÁÆÊý¾Ýй¶¿ÉÄÜÔì³ÉÑÏÖØºó¹û£º»¼ÕßÒþÖÔ¶³ö¿ÉÄܵ¼ÖÂÉí·Ý͵ÇÔ¡¢¡¢¡¢Ú²Æ¼°Éç»á¹¤³Ì¹¥»÷·çÏÕ£»£»Ò½ÁÆÁ÷³ÌÖжϻòÑÓÎóΣ¼°ÐÔÃü¾ÈÖΣ»£»»ú¹¹ÃûÓþ¼°²ÆÕþÊý¾ÝÊÜËð¡£
https://cybernews.com/news/israel-shamir-medical-center-ransowmare-attack-qilin-8t-patient-data-stolen/
2. IntelliloanµÖѺ´û¿îÎ¥¹æÊÂÎñ¶³ö¿Í»§Ãô¸ÐÊý¾Ý
10ÔÂ2ÈÕ£¬£¬¼ÓÖݵÖѺ´û¿î»ú¹¹Intelliloan½üÈÕÏò¿Í»§·¢ËÍÎ¥¹æÍ¨ÖªÐÅ£¬£¬Åû¶Æä2025Äê3ÔÂ29ÈÕ²úÉúµÄºÚ¿Í¹¥»÷ÊÂÎñµ¼Ö´óÁ¿Ãô¸ÐÊý¾Ýй¶¡£¸Ã¹«Ë¾×Ô1993Äê³ÉÁ¢ÒÔÀ´£¬£¬ÒÑΪ¶àÖÝÊýÍò±Ê´û¿îÌṩ×ʽ𣬣¬µ«Õâ´ÎÊÂÎñÖÐδй©¾ßÌåÊÜÓ°ÏìÈËÊý£¬£¬Òý·¢Êý¾Ýй¶ÂÉʦ¼°¹ú¶ÈÂÉʦÊÂÎñËùµ÷²é²¢ÌáÆð¼¯ÌåËßËÏ¡£Í¨ÖªÏÔʾ£¬£¬ºÚ¿Í¿ÉÄÜ»ñÈ¡µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢¡¢¡¢Éç»á°²È«ºÅÂë¡¢¡¢¡¢µØÖ·¡¢¡¢¡¢µ®ÉúÈÕÆÚ¡¢¡¢¡¢¼ÝÕÕºÅÂë¡¢¡¢¡¢µ±¾ÖID¡¢¡¢¡¢Õ˺ż°ÐÅÓþ¿¨ÐÅÏ¢£¬£¬ÉõÖÁÉæ¼°µÖѺ´û¿îÉêÇëÈ˵ÄСÎÒ½¡¿µÐÅÏ¢¡£ÕâЩÐÅϢʹ¿Í»§Ãæ¶Ô½ðÈÚڲơ¢¡¢¡¢Éí·Ý͵ÇÔ¼°Éç»á¹¤³Ì¹¥»÷·çÏÕ¡£IntelliloanÔÚ9ÔÂ26ÈÕµÄÐź¯Öгƣ¬£¬¹«Ë¾ÓÚ5ÔÂÒÑÏòµÂ¿ËÈøË¹ÖÝ×ܼì²ì³¤°ì¹«Êһ㱨Υ¹æÐÐΪ£¬£¬²¢³ÖÐøÓë·¨Âɲ¿ÃźÏ×÷£¬£¬¼Óǿϵͳ°²È«£¬£¬·¢Õ¹Ô±¹¤°²È«ÒâʶÅàѵ¼°Êý¾Ý°²È«ÆÀ¹À¡£Îª¼õÇá¿Í»§Ëðʧ£¬£¬¹«Ë¾Í¨¹ýTransUnionÐÅÓþ¾ÖÌṩÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý¸´Ô·þÎñ£¬£¬²¢½¨Òé¿Í»§Ç×êÇ¼à¿ØÕË»§»î¶¯£¬£¬ÊµÊ±»ã±¨¿ÉÒÉÐÐΪ¡£
https://cybernews.com/news/intelliloan-mortgage-breach-customer-data-exposed-social-security-numbers-drivers-licenses/
3. LynxÀÕË÷Èí¼þ¹¥»÷Ò½ÁƾÞÍ·ºàÀû¡¤Ê©¶÷×Ó¹«Ë¾TriMed
10ÔÂ3ÈÕ£¬£¬Óë¶íÂÞ˹¹ØÁªµÄLynxÀÕË÷Èí¼þÍÅ»ïÐû³Æ¹¥ÆÆÒ½ÁƱ£½¡¾ÞÍ·ºàÀû¡¤Ê©¶÷£¨Henry Schein£©ÆìÏÂ×Ó¹«Ë¾TriMedϵͳ£¬£¬²¢½«Ãô¸ÐÊý¾Ýй¶ÖÁ°µÍø¡£ºàÀû¡¤Ê©¶÷×÷ΪÄêÊÕÈë126.7ÒÚÃÀÔªµÄÈ«Çò×î´óÒ½ÁƱ£½¡²úÆ··þÎñ·ÖÏúÉÌ£¬£¬ÒµÎñ¸²¸Ç33¹ú£¬£¬Æä×Ó¹«Ë¾TriMedÕâ´ÎÔâ·êÍøÂç¹¥»÷µ¼Ö²¿ÃÅITϵͳ̱»¾£¬£¬¹«Ë¾ÒÑÏÂÏßÓйØÏµÍ³²¢ÀñƸÍⲿר¼Òµ÷²éÊÂÎñÁìÓò¡£¾Ý°µÍøÊý¾ÝÑù±¾ÏÔʾ£¬£¬LynxÇÔÈ¡ÁËÔ̺¬¸ß¹ÜͨѶ¡¢¡¢¡¢Ë¾·¨Îļþ¡¢¡¢¡¢ÖªÊ¶²úȨ£¨ÈçÍâ¿Æ²úÆ·ÔÐÍÉè¼Æ£©¡¢¡¢¡¢Ð¡ÎÒÉí·ÝÎļþ£¨¼ÝÕÕ¡¢¡¢¡¢»¤ÕÕ£©¼°²ÆÕþÐÅÏ¢£¨IBAN¡¢¡¢¡¢ÒøÐÐÕ˺ţ©µÈÃô¸ÐÊý¾Ý¡£ÆäÖÐÒ»·âй¶µÄ¸ß¹ÜÓʼþÅû¶ÁËÊý°ÙÍòÃÀÔª×ʽðÁ÷¶¯Ï¸½Ú£¬£¬´ËÀàÐÅÏ¢¼«Ò×±»ÓÃÓÚÕë¶Ô¸ß²ãµÄÓã²æÊ½ÍøÂç´¹µö¹¥»÷¡£LynxÍÅ»ï×Ô2024ÄêÖÐÆðÒÔÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½ÔËÓª£¬£¬ÖØÒª¹¥»÷½ðÈÚ¡¢¡¢¡¢¹¹Öþ¡¢¡¢¡¢ÖÆ×÷Òµ¼°ÄÜÔ´ÁãÊÛÐÐÒµ£¬£¬ÒÑÁÐ196ÃûÊܺ¦Õߣ¬£¬Ô̺¬Ó¢¹úDodd Group¡¢¡¢¡¢ÃÀ¹úTrue World GroupµÈ¡£
https://cybernews.com/security/lynx-ransomware-trimed-henry-schein/
4. DraftKingsÔâ·êƾ֤Ìî³ä¹¥»÷£¬£¬ÉÙÁ¿¿Í»§ÕË»§ÊÜÓ°Ïì
10ÔÂ7ÈÕ£¬£¬ÌåÓý²©²Ê¾ÞÍ·DraftKingsÏò²¿Ãſͻ§·¢³öÊý¾Ýй¶֪ͨ£¬£¬³ÆÆäÕË»§ÔÚ½üÆÚƾ֤Ìî³ä¹¥»÷ÖÐÔâºÚ¿ÍÈëÇÖ¡£Õâ´Î¹¥»÷Ô´ÓÚ¹¥»÷ÕßÀûÓÃ×Ô¶¯»¯¹¤¾ß£¬£¬Í¨¹ýÇÔÈ¡ÆäËûÔÚÏß·þÎñµÄÓû§Ãû/ÃÜÂë¶ÔÖ´ÐÐÆ¾Ö¤Ìî³ä£¬£¬ÊÔͼÊÕÊÜÕË»§ÒÔÇÔÊØÐÅÏ¢¡£DraftKingsÇ¿µ÷£¬£¬¹¥»÷Õß½öÄܽӼû¡°ÓÐÏÞÁ¿¡±·ÇÃô¸ÐÊý¾Ý£¬£¬Ô̺¬¿Í»§ÐÕÃû¡¢¡¢¡¢µØÖ·¡¢¡¢¡¢µ®ÉúÈÕÆÚ¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢µç×ÓÓʼþ¡¢¡¢¡¢Ö§¸¶¿¨ºóËÄλ¡¢¡¢¡¢ÂòÂô¼Í¼¡¢¡¢¡¢ÕË»§Óà¶î¼°ÃÜÂëÅú¸ÄÈÕÆÚ£¬£¬µ«Î´´¥¼°µ±¾ÖÉí·ÝÖ¤ºÅ¡¢¡¢¡¢ÆëÈ«½ðÈÚÕË»§ÐÅÏ¢µÈ¿ÉÖÂÉí·Ý͵ÇÔ»òÒøÐÐÕË»§ÈëÇֵĹؼüÊý¾Ý¡£ÊÜÓ°Ïì¿Í»§²»¼°30ÈË£¬£¬ÇÒµ÷²éδ·¢ÏÖDraftKingsϵͳÔâÈëÇÖ»ò¿Í»§¾¼ÃËðʧ¡£×÷ΪӦ¶Ô´ëÊ©£¬£¬DraftKingsÒªÇóÊÜÓ°Ïì¿Í»§ÖØÖÃÕË»§ÃÜÂ룬£¬²¢ÆôÓöà³É·ÖÉí·ÝÑéÖ¤£¨ÈçDK HorseÕË»§£©¡£Í¬Ê±½¨ÒéÓû§×Ô¶¯¸ü¸ÄÕË»§ÃÜÂë¡¢¡¢¡¢²é³ÒøÐÐÕË»§ÓëÐÅÓþ»ã±¨¡¢¡¢¡¢¶³½áÐÅÓþµµ°¸²¢ÉèÖÃڲƾ¯±¨£¬£¬ÒÔ·À±¸Ç±ÔÚ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/draftkings-warns-of-account-breaches-in-credential-stuffing-attacks/
5. Salesforce»Ø¾øÒò´ó¹æÄ£Êý¾Ý͵ÇÔ¹¥»÷Ö§¸¶Êê½ð
10ÔÂ7ÈÕ£¬£¬2025Ä꣬£¬SalesforceÔâ·ê´ó¹æÄ£Êý¾Ý͵ÇÔÊÂÎñ£¬£¬Éæ¼°Á½´Î¶ÀÁ¢¹¥»÷¡£µÚÒ»´ÎʼÓÚ2024Äêµ×£¬£¬Íþв×éÖ¯"Scattered Lapsus$ Hunters"ͨ¹ýÉç»á¹¤³Ì¹¥»÷¼ÙÒâITÖ§³ÖÈËÔ±£¬£¬ÓÕÆÔ±¹¤ÏνӶñÒâOAuthÀûÓÃÖÁSalesforceʵÀý£¬£¬µ¼Ö¹ȸ衢¡¢¡¢Ë¼¿Æ¡¢¡¢¡¢°¢µÏ´ï˹µÈÆóÒµÊý¾Ýй¶¡£µÚ¶þ´ÎʼÓÚ2025Äê8Ô£¬£¬¹¥»÷ÕßÀûÓñ»µÁµÄSalesLoft Drift OAuthÁîÅÆÈëÇÖ¿Í»§CRM»·¾³£¬£¬ÇÔȡ֧³ÖƱ֤Êý¾Ý¼°Æ¾Ö¤¡¢¡¢¡¢APIÁîÅÆµÈÃô¸ÐÐÅÏ¢£¬£¬ShinyHuntersÐû³ÆÕâ´ÎÇÔÈ¡³¬760¼ÒÆóÒµÔ¼15Òڱʼͼ£¬£¬Éæ¼°Google¡¢¡¢¡¢Cloudflare¡¢¡¢¡¢Palo Alto NetworksµÈ¿Æ¼¼¾ÞÍ·¡£ÍþвÐÐΪÕß³ÉÁ¢Êý¾ÝÐ¹Â¶ÍøÕ¾breachforums[.]hn£¬£¬ÀÕË÷39¼ÒÊÜÓ°ÏìÆóÒµ£¬£¬Ô̺¬Áª°î¿ìµÝ¡¢¡¢¡¢µÏÊ¿Äá/Hulu¡¢¡¢¡¢ÍòºÀ¡¢¡¢¡¢ÏãÄζùµÈ³ÛÃûÆ·ÅÆ£¬£¬Ðû³ÆÈô²»Ö§¸¶Êê½ð»òSalesforceÒ»´ÎÐÔÖ§¸¶ËùÓпͻ§Êê½ð£¬£¬½«¹«¿ª½ü10ÒÚÌõÊý¾Ý¼Í¼¡£SalesforceÃ÷È·»Ø¾ø½»Éæ»òÖ§¸¶Êê½ð£¬£¬²¢ÖÒ¸æ¿Í»§ÍþвÐÐΪÕßÕý´òËãй¶Êý¾Ý¡£Ä¿Ç°£¬£¬¸ÃÍøÕ¾ÓòÃûÒѱ»FBI²é·â£¬£¬ÓòÃû·þÎñÆ÷Ö¸ÏòÔø±»FBIÓÃÓÚ²é·âÓòÃûµÄCloudflare·þÎñÆ÷¡£
https://www.bleepingcomputer.com/news/security/salesforce-refuses-to-pay-ransom-over-widespread-data-theft-attacks/
6. Crimson CollectiveºÚ¿Í¶Ô×¼AWSÔÆÊµÀýÇÔÈ¡Êý¾Ý
10ÔÂ8ÈÕ£¬£¬´ÓǰÊýÖÜ£¬£¬Íþв×éÖ¯¡°Crimson Collective¡±³ÖÐøÕë¶ÔAWSÔÆ»·¾³ÌáÒé¹¥»÷£¬£¬ÒÔÇÔÈ¡Êý¾Ý²¢Ö´ÐÐÀÕË÷¡£¸Ã×éÖ¯Ðû³Æ¶ÔRed HatÊÂÎñÕÆ¹Ü£¬£¬³Æ´ÓÊýǧ¸ö˽ÓÐGitLab²Ö¿âÇÔÈ¡570GBÊý¾Ý£¬£¬²¢Í¨¹ýÓëScattered Lapsus$ HuntersºÏ×÷¼Ó´óÀÕË÷Á¦¶È¡£Rapid7×êÑÐÏÔʾ£¬£¬¹¥»÷ÕßÀûÓÃTruffleHog¿ªÔ´¹¤¾ßɨÃè¶³öµÄAWSƾ֤£¬£¬Í¨¹ý·ÛËé³Ö¾Ã½Ó¼ûÃÜÔ¿ºÍIAMÕË»§ÌáÉýȨÏÞ¡£¾ßÌåÊÖ·¨Ô̺¬£ºÍ¨¹ýAPI´´½¨ÐÂIAMÓû§²¢¸½¼Ó¡°AdministratorAccess¡±Õ½Êõ»ñÈ¡ÆëÈ«½ÚÖÆÈ¨£¬£¬Ëæºóö¾ÙÓû§¡¢¡¢¡¢ÊµÀý¡¢¡¢¡¢´æ´¢Í°¡¢¡¢¡¢Êý¾Ý¿â¼¯ÈºµÈ×ÊÔ´£¬£¬¹æ»®Êý¾ÝÇÔÈ¡õè¾¶¡£¹¥»÷ÕßÅú¸ÄRDSÖ÷ÃÜÂë»ñÈ¡Êý¾Ý¿â½Ó¼ûȨ£¬£¬´´½¨¿ìÕÕµ¼³öÖÁS3´æ´¢Í°£»£»¶ÔEBS¾í¿ìÕÕºóÆô¶¯EC2ʵÀý£¬£¬¸½¼ÓÖÁÔÊÐí°²È«×éʵÏÖÊý¾Ý´«Ê䡣ʵÏÖÊý¾ÝÇÔÈ¡ºó£¬£¬Í¨¹ýAWS SES¼°ÍⲿÓÊÏä·¢ËÍÀÕË÷ÐÅ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬Crimson CollectiveÔÚÐж¯Öз´¸´Ê¹Óò¿ÃÅIPµØÖ·£¬£¬Ëä±ãÓÚ×·×Ùµ«Í¹ÏÔÆä³ÖÐø»îÔ¾ÐÔ¡£AWS¹Ù·½½¨Òé¿Í»§Ñ¡È¡¶ÌÆÚ¡¢¡¢¡¢×îµÍȨÏÞÆ¾Ö¤²¢Ö´ÐÐÏÞ¶ÈÐÔIAMÕ½Êõ£¬£¬ÈôÒÉ»óƾ֤й¶¿É°´Ö¸Òý²Ù×÷»òÁªÏµÖ§³ÖÍŶӡ£
https://www.bleepingcomputer.com/news/security/crimson-collective-hackers-target-aws-cloud-instances-for-data-theft/


¾©¹«Íø°²±¸11010802024551ºÅ