À¶ÑÀÎó²îÓ°Ï쳬29¿î×°±¸£¬¿É±»ÓÃÓÚÇÔÌýÒþ˽
Ðû²¼Ê±¼ä 2025-06-301. À¶ÑÀÎó²îÓ°Ï쳬29¿î×°±¸£¬¿É±»ÓÃÓÚÇÔÌýÒþ˽
6ÔÂ29ÈÕ£¬¿ËÈÕ£¬À¶ÑÀоƬ×éÇå¾²Îó²îÒý·¢ÆÕ±éµ£ÐÄ£¬ÆäÓ°Ïì¹æÄ£Éõ¹ã£¬²¨¼°Ê®´óÒôÆµÆ·ÅÆµÄ29¿îÒÔÉÏ×°±¸£¬²úÆ·ÀàÐͰüÀ¨ÒôÏä¡¢¶úÈû¡¢¶ú»úÒÔ¼°ÎÞÏßÂó¿Ë·çµÈ¡£¹¥»÷ÕßÒ»µ©Ê¹ÓøÃÎó²î£¬±ã¿É¾ÙÐÐÇÔÌý¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢µÈ¶ñÒâ²Ù×÷£¬ÉõÖÁÔÚÌØ¶¨Ìõ¼þÏÂÇÔÈ¡ÊÖ»úͨ»°¼Í¼ÓëͨѶ¼£¬¶ÔÓû§Òþ˽Çå¾²×é³ÉÑÏÖØÍþв¡£Ôڵ¹úTROOPERSÇå¾²¾Û»áÉÏ£¬ÍøÂçÇå¾²¹«Ë¾ERNWÅû¶ÁĘ̈ÍåÂç´ïϵͳ¼¶Ð¾Æ¬£¨SoCs£©±£´æµÄÈý´óÎó²î¡£ÕâÀàоƬÔÚÕæÎÞÏßÁ¢ÌåÉù£¨TWS£©¶úÈûÖÐÓ¦ÓÃÆÕ±é¡£ËäÈ»Îó²î×Ô¼º²¢·ÇÖ±½ÓÖÂÃü£¬µ«Ê¹ÓÃÌõ¼þ¼«Îª¿Á¿Ì£¬¹¥»÷Õß²»µ«ÒªÔÚÀ¶ÑÀ¹æÄ£ÄÚÎïÀí¿¿½üÄ¿µÄ£¬»¹Ðè¾ß±¸¸ßˮƽÊÖÒÕÄÜÁ¦¡£ÏêϸÎó²îÓУºGATT·þÎñÉí·ÝÑé֤ȱʧ£¨CVE - 2025 - 20700£¬ÖÐΣ£©¡¢À¶ÑÀBR/EDRÐÒéÈÏ֤ȱʧ£¨CVE - 2025 - 20701£¬ÖÐΣ£©ÒÔ¼°×Ô½ç˵ÐÒéÒªº¦¹¦Ð§È±ÏÝ£¨CVE - 2025 - 20702£¬¸ßΣ£©¡£ERNWÑо¿Ö°Ô±ÒÑÀֳɿª·¢³ö¿´·¨ÑéÖ¤´úÂ룬Äܹ»¶ÁȡĿµÄ¶ú»ú²¥·ÅµÄÄÚÈÝ¡£ÏÖÔÚ£¬Âç´ïÒÑÐû²¼º¬ÐÞ¸´¼Æ»®µÄ¸üаæSDK£¬×°±¸ÖÆÔìÉÌÒ²ÔÚ¿ª·¢·Ö·¢²¹¶¡¡£µ«µÂ¹úHeiseýÌåÖ¸³ö£¬³¬°ëÊýÊÜÓ°Ïì×°±¸¹Ì¼þÈÔδ¸üУ¬Îó²îÉÐδ»ñµÃÏÖʵÐÞ¸´¡£
https://www.bleepingcomputer.com/news/security/bluetooth-flaws-could-let-hackers-spy-through-your-microphone/
2. ÏÄÍþÒĺ½¿ÕÔâÍøÂç¹¥»÷£¬¶à²¿·ÖÐ×÷Ó¦¶Ô
6ÔÂ27ÈÕ£¬¿ËÈÕ£¬ÃÀ¹úµÚÊ®´óÉÌÒµº½¿Õ¹«Ë¾ÏÄÍþÒĺ½¿ÕÕýÊÓ²ìÒ»Æðµ¼Ö²¿·ÖϵͳÖÐÖ¹µÄÍøÂç¹¥»÷ÊÂÎñ¡£ÏÄÍþÒĺ½¿Õ¹æÄ£ÖØ´ó£¬ÓµÓг¬7000ÃûÔ±¹¤¡¢ÈÕ¾ù235¸öº½°àÒÔ¼°³¬60¼Ü·É»úµÄ»ú¶Ó£¬º½ÏßÅþÁ¬ÏÄÍþÒÄÓë15¸öÃÀ¹ú´ó½¶¼»á¼°ÑÇÌ«µØÇø10¸öÄ¿µÄµØ¡£ÖÜËÄÉÏÎ磬ÏÄÍþÒĺ½¿Õ½ÒÏþÉùÃ÷£¬³Æ´Ë´ÎÊÂÎñδӰÏ캽ÐÐÇå¾²£¬ÒÑÁªÏµÏà¹Ø²¿·ÖÐÖúÊӲ죬»¹Ô¼ÇëÍâ²¿ÍøÂçÇ徲ר¼ÒÆÀ¹À¹¥»÷Ó°Ïì¡¢ÖúÁ¦ÏµÍ³»Ö¸´¡£¹«Ë¾ÌåÏÖ£¬Õý´¦Öóͷ£Ó°Ï첿·ÖITϵͳµÄÍøÂçÇå¾²ÊÂÎñ£¬Ö÷ҪʹÃüÊǰü¹ÜÂÿͺÍÔ±¹¤Çå¾²£¬ÒѽÓÄɲ½·¥È·±£ÔËÓªÇå¾²£¬ÏÖÔÚº½°àÕýÇå¾²°´ÍýÏëÔËÐС£¸Ãº½¿Õ¹«Ë¾ÍøÕ¾ºá·ùÏÔʾ£¬ÊÂÎñδ¶Ôº½°àºÍÂÃÐÐÔì³ÉÓ°Ïì¡£ÏÖÔÚ£¬Éв»ÇåÎúÏÄÍþÒĺ½¿ÕϵͳÊÇ·ñÊÜÀÕË÷Èí¼þ¹¥»÷Ó°Ï죬»òÊÇÒò×èֹΥ¹æÐÐΪ¶ø¹Ø±Õ¡£º½¿Õ¹«Ë¾Î´Í¸Â¶¹¥»÷ÐÔ×Ó£¬Ò²ÎÞÀÕË÷Èí¼þ×éÖ¯Éù³ÆÈÏÕæ¡£
https://www.bleepingcomputer.com/news/security/hawaiian-airlines-discloses-cyberattack-flights-not-affected/
3. NorthernLightHealth»¼ÕßÊܵ½CompumedicsÇå¾²ÊÂÎñÓ°Ïì
6ÔÂ27ÈÕ£¬¾ÝLeelaStockley±¨µÀ£¬NorthernLightHealthµÄ¹©Ó¦ÉÌCompumedics±¬·¢Êý¾ÝÇå¾²ÊÂÎñ£¬²¿·Ö»¼ÕßÐÅÏ¢»òÔâй¶¡£CompumedicsΪ±±¼«¹â¶«ÃåÒòÒ½ÁÆÖÐÐÄ¡¢±±¼«¹âARGouldºÍ±±¼«¹âÈû°Í˹µÙ¿â¿Ë¹ÈÒ½ÔºµÄ»¼ÕßÌṩ˯ÃßÕϰÕï¶Ï·þÎñ¡£CompumedicsÍøÕ¾ÉÏδעÃ÷ÈÕÆÚµÄ֪ͨÌṩÁ˸ü¶àϸ½Ú¡£ÈëÇÖÊÂÎñ±¬·¢ÔÚ2ÔÂ15ÈÕÖÁ3ÔÂ23ÈÕÖ®¼ä£¬2025Äê3ÔÂ22ÈÕÊ״α»·¢Ã÷£¬Ê±´úÎļþ±»»á¼û»òй¶£¬µ«Î´ËµÃ÷ÈëÇÖÕßÔõÑù»ñµÃ»á¼ûȨÏÞ£¬Ò²Î´Ìá¼°ÊÇ·ñ±£´æÀÕË÷ÒªÇó¡£ÉæÊ»¼ÕßµÄÒ½ÁƱ£½¡ÌṩÉ̿ͻ§ÒÑÓÚ2025Äê4ÔÂ29ÈÕÊÕµ½Í¨Öª¡£ÕâЩÎļþ°üÀ¨»¼ÕßÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éú³Ýͳ¼ÆÐÅÏ¢¡¢²¡Àú±àºÅ¡¢ÖÎÁƺÍÕï¶ÏÐÅÏ¢¡¢ÖÎÁÆÈÕÆÚ¡¢Ò½ÁÆ·þÎñÌṩÕßÐÕÃûÒÔ¼°Ë¯ÃßÑо¿ÏêÇéºÍЧ¹ûµÈ¡£²¿·ÖÉæ°¸Ö°Ô±Îļþ¿ÉÄÜ»¹°üÀ¨Éç»áÇå¾²ºÅÂëºÍ/»òÒ½Áưü¹ÜÐÅÏ¢¡£µ«NorthernLightHealth¹ÙÔ±ÌåÏÖ£¬»¼ÕßÉç»áÇå¾²ºÅÂë¡¢Ò½Áưü¹Ü»ò²ÆÎñÐÅϢδÊÜÓ°Ïì¡£´Ë´ÎÊÂÎñÉæ¼°¶à¼ÒÒ½ÁÆ·þÎñÌṩÕߣ¨¿Í»§£©µÄ»¼Õߣ¬°üÀ¨°ÙĽ´ó˯ÃßÓëÌØÉ«·þÎñ/Ï£ÍûÒ½ÁƱ£½¡¡¢²¼ÀÊÉÒ½ÁƼ¯Íŵȡ£
https://databreaches.net/2025/06/27/northern-light-health-patients-affected-by-security-incident-at-compumedics-10-healthcare-entities-affected/
4. Òþ˽רԱÕýÔÚÉó²éOntarioHealthatHomeÊý¾Ýй¶ÊÂÎñ
6ÔÂ27ÈÕ£¬°²¼òªʡÒþ˽רԱÓë°²¼òªʡÎÀÉú¾ÖÕý¶ÔÓ°Ïì¼ÒÍ¥Õչ˻¤Ê¿Ðµ÷·þÎñ»ú¹¹OntarioHealthatHomeµÄÊý¾Ýй¶ÊÂÎñÕö¿ªÊӲ졣°²¼òªʡ×ÔÓɵ³ÔÚÖÜÎåÐÂÎÅÐû²¼»áÉϳƣ¬½ñÄê3ÔÂ17ÈÕ×óÓÒ±¬·¢µÄ´Ë´ÎÎ¥¹æÐÐΪ£¬¿ÉÄÜй¶ÖÁÉÙ20ÍòÃû¼ÒÍ¥Õչ˻¤Ê¿»¼ÕßµÄСÎÒ˽¼Ò¿µ½¡ÐÅÏ¢£¬ÇÒÆäʱ²¢Î´¹ûÕæ¡£ÕâЩÊý¾ÝÒ»µ©Ð¹Â¶£¬¿ÉÄÜÒý·¢Éí·Ý͵ÇÔ¡¢°ü¹Üڲơ¢ÆçÊÓ¡¢ÎÛÃû»¯¡¢ÍøÂç´¹ÂÚºÍÀÕË÷µÈһϵÁÐÎÊÌâ¡£°²¼òªʡÎÀÉú²¿³¤Î÷¶ûά櫡¤Çí˹ÌåÏÖ£¬ÊÂÎñÉæ¼°µÚÈý·½¹©Ó¦ÉÌ£¬°²¼òªʡÎÀÉú¾ÖºÍ°²¼òªʡ¼ÒÍ¥¿µ½¡¾ÖÕýÔÚÊӲ죬²¢½«°´Ðè֪ͨ¸öÌ廼Õß¡£¸Ã²¿½²»°È˰£Âꡤ²¨²¨Î¬Ææ³Æ£¬OntarioHealthatHomeÒѱ»Ö¸Ê¾½ÓÄɲ½·¥±ÜÃâÀàËÆÊÂÎñÔٴα¬·¢£¬Õþ¸®ÆÚÍû·þÎñÌṩÉ̱ü³Ö×î¸ß±ê×¼£¬ÊµÊ±Ê¶±ð²¢Í¨ÖªÍøÂç¹¥»÷ÊÂÎñ£¬Î´×ñÕÕ³ÌÐòµÄ×ö·¨²»¿É½ÓÊÜ¡£
https://ca.news.yahoo.com/privacy-commissioner-reviewing-reported-ontario-152358162.html
5. OneClik¶ñÒâÈí¼þʹÓÃClickOnceºÍGolangºóÃŹ¥»÷ÄÜÔ´ÐÐÒµ
6ÔÂ27ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±Õ¹ÏÖÁËÒ»ÏîÃûΪOneClikµÄй¥»÷Ô˶¯£¬¸ÃÔ˶¯Ê¹ÓÃ΢ÈíClickOnceÈí¼þ°²ÅÅÊÖÒÕÓë¶¨ÖÆGolangºóÃÅ£¬×¨ÃÅÕë¶ÔÄÜÔ´¡¢Ê¯ÓͺÍ×ÔÈ»ÆøÐÐÒµ×éÖ¯Ìᳫ¹¥»÷¡£¹¥»÷Á´Ê¼ÓÚÍøÂç´¹ÂÚÓʼþ£¬ÆäÖаüÀ¨Ö¸ÏòÐéαӲ¼þÆÊÎöÍøÕ¾µÄÁ´½Ó£¬¸ÃÍøÕ¾×÷Ϊת´ïClickOnceÓ¦ÓóÌÐòµÄÇþµÀ¡£ClickOnceÊÖÒÕËä±ãÓÚÕýµ±Èí¼þ×°ÖøüУ¬È´Ò²±»¹¥»÷ÕßʹÓã¬Í¨¹ýÊÜÐÅÍеÄWindows¶þ½øÖÆÎļþ¡°dfsvc.exe¡±ÔËÐжñÒâ´úÂ룬ÎÞÐèÖÎÀíȨÏÞ¼´¿É×°Öã¬Îª¶ñÒâ¸ºÔØµÄÖ´ÐÐÌṩÁ˱㵱¡£¶ñÒâ´úÂëͨ¹ýAppDomainManager×¢ÈëÊÖÒÕÆô¶¯£¬×îÖÕÔÚÄÚ´æÖÐÖ´ÐмÓÃÜshellcodeÒÔ¼ÓÔØRunnerBeaconºóÃÅ¡£¸ÃºóÃŽÓÄÉGolang±àд£¬¾ß±¸Ç¿Ê¢µÄͨѶÄÜÁ¦£¬¿Éͨ¹ý¶àÖÖÐÒéÓëC2·þÎñÆ÷ͨѶ£¬Ö´ÐÐÎļþ²Ù×÷¡¢Àú³Ìö¾Ù¡¢È¨ÏÞÌáÉý¼°ºáÏòÒÆ¶¯µÈ¶ñÒâÐÐΪ¡£±ðµÄ£¬RunnerBeacon»¹°üÀ¨·´ÆÊÎö¹¦Ð§ÒÔÌӱܼì²â£¬²¢Ö§³Ö¶àÖÖÍøÂç²Ù×÷ÒÔÔö½øÊðÀíºÍ·Óɹ¦Ð§¡£OneClikÔ˶¯ÉÐδ±»Õýʽ¹é×ïÓÚÈκÎÒÑÖª×éÖ¯¡£
https://thehackernews.com/2025/06/oneclik-malware-targets-energy-sector.html
6. ºÚ¿Í³Æ´ÓÁª°îÀÎÓü¾ÖÇÔÈ¡ÁË320GBµÄÃô¸ÐÊý¾Ý
6ÔÂ27ÈÕ£¬ÃÀ¹úÁª°îÀÎÓü¾Ö£¨BOP£©ÔâÓöÁËÒ»ÆðÑÏÖØµÄÉæÏӺڿ͹¥»÷ÊÂÎñ£¬¹¥»÷ÕßÐû³Æ´ÓBOPÇÔÈ¡ÁËÊý°ÙGB¼«ÆäÃô¸ÐµÄÊý¾Ý£¬ÕâЩÊý¾ÝÉæ¼°Çô·¸ºÍÊÂÇéÖ°Ô±µÄÖî¶àÒªº¦ÐÅÏ¢¡£¹¥»÷ÕßÔÚÒ»¸öÈÈÃÅÊý¾Ýй¶ÂÛ̳ÉÏ·¢Ìû£¬³ÆÊý¾ÝÀ´×ÔBOPµÄÒ»¸ö·þÎñÆ÷£¬°üÀ¨¶à¸öÊý¾Ý¿â£¬×ÜÁ¿³¬320GB£¬ÇÒÐÅϢʮ·Öнü£¬×î½ü¸üÐÂÖÁ6ÔÂ20ÈÕ¡£ÃÀ¹úÁª°îÀÎÓüÖÎÀí¾Ö×÷ΪÃÀ¹úÖ´·¨»ú¹¹£¬ÖÎÀí×ÅÃÀ¹úËùÓÐÁª°îÀÎÓü£¬ÓµÓг¬3.5ÍòÃûÔ±¹¤£¬¹ØÑº×ÅÔ¼16ÍòÃûÇô·¸¡£ÃæÁÙ´Ë´ÎÊÂÎñ£¬BOPÌåÏÖÒÑ×¢ÖØµ½¹¥»÷ÕßµÄÖ¸¿Ø£¬²¢ÕýÔÚÊÓ²ìÆäÕýµ±ÐÔ¡£¹¥»÷ÕßÉù³Æ£¬±»µÁÊý¾Ý¿â°üÀ¨´ó×ÚÏêϸÐÅÏ¢£¬º¸ÇÈ«Ãû¡¢×¢²áºÅÂë¡¢Éç»áÇå¾²ºÅÂë¡¢ÐÔ±ð¡¢ÖÖ×å¡¢Ò½ÁÆÏêÇ顢Σº¦ÒòËØ¡¢ËùÔÚÀÎÓü¡¢Ê¹ʱ¨¸æ¡¢ÊÍ·ÅÍýÏëµÈÖî¶àÄÚÈÝ¡£Ò»µ©ÕâЩָ¿Ø»ñµÃ֤ʵ£¬´Ë´ÎйÃÜÊÂÎñ¶ÔÇô·¸ºÍÊÂÇéÖ°Ô±¶øÑÔ¶¼½«¼«ÆäΣÏÕ¡£²»·¨·Ö×ÓÈô»ñÈ¡ÍêÕûÊý¾Ý¼¯£¬¿ÉÄÜ»áʹÓÃÕâЩÐÅÏ¢¾ÙÐÐÉí·Ý͵ÇÔºÍÚ²ÆÔ˶¯¡£Çô·¸Ò²¿ÉÄÜÒòÐÅϢй¶¶ø³ÉΪ·¸·¨·Ö×Ó»ò»³ÓÐÅê»÷ÐÄÀíÕßµÄÄ¿µÄ¡£
https://cybernews.com/security/federal-bureau-prisons-alleged-breach/


¾©¹«Íø°²±¸11010802024551ºÅ