°Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±
Ðû²¼Ê±¼ä 2025-07-021. °Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±
7ÔÂ1ÈÕ£¬°Ä´óÀûÑÇ×î´óº½¿Õ¹«Ë¾°ÄÖÞº½¿Õ¿ËÈÕÅû¶£¬ÆäµÚÈý·½¿Í»§·þÎñƽ̨ÔâÓöÍøÂç¹¥»÷£¬µ¼ÖÂÔ¼600Íò¿Í»§µÄ·þÎñ¼Í¼Êý¾Ý±»µÁ£¬³ÉΪȫÇòº½¿ÕÒµÍøÂçÇå¾²ÍþвÉý¼¶µÄ×îа¸Àý¡£´Ë´Î¹¥»÷ʼÓÚÍþвÐÐΪÕßÈëÇְĺ½ºô½ÐÖÐÐÄʹÓõĵÚÈý·½Æ½Ì¨£¬¹¥»÷Õß»ñÈ¡Á˰üÀ¨¿Í»§ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¼°³£ÓοͻáÔ±ºÅµÈÃô¸ÐÐÅÏ¢£¬µ«Î´Éæ¼°ÐÅÓÿ¨»ò²ÆÎñÊý¾Ý¡£°Äº½ÉùÃ÷³Æ£¬ÏµÍ³ÒÑÔÚ·¢Ã÷Òì³£ºóÁ¬Ã¦¸ôÀ룬²¢ÒÑת´ï°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ¡¢ÐÅϢרԱ°ì¹«ÊÒ¼°Áª°î¾¯Ô±¾ÖÕö¿ªÊӲ졣´Ë´ÎÊÂÎñ̻¶³öº½¿ÕÒµÕý³ÉΪºÚ¿Í×éÖ¯¡°Scattered Spider¡±µÄÖØµãÄ¿µÄ¡£¸Ã×éÖ¯ÒԸ߶ÈÐͬµÄÉç»á¹¤³Ì¹¥»÷ÖøÃû£¬ÉÆÓÚͨ¹ý´¹ÂÚ¡¢SIM¿¨½»Á÷¡¢¶àÒòËØÈÏÖ¤£¨MFA£©ºäÕ¨¼°Ã°³äÔ±¹¤µÈÊÖ¶ÎÇÔÈ¡Æóҵƾ֤¡£½üÆÚ£¬Æä¹¥»÷¹æÄ£ÒÑ´ÓÁãÊÛ¡¢°ü¹ÜÐÐÒµÀ©Õ¹ÖÁº½¿ÕÁìÓò£¬ÏÄÍþÒĺ½¿ÕºÍÎ÷½Ýº½¿ÕµÄÊý¾Ýй¶ÊÂÎñ¾ù±»ÏÓÒÉÓëÆäÓйء£
https://www.bleepingcomputer.com/news/security/qantas-discloses-cyberattack-amid-scattered-spider-aviation-breaches/
2. ¹ú¼ÊÐÌÊ·¨ÔºÔâÓöеÄÖØ´óÍøÂç¹¥»÷
7ÔÂ1ÈÕ£¬¹ú¼ÊÐÌÊ·¨Ôº£¨ICC£©ÖÜÒ»Åû¶£¬Æäϵͳ¿ËÈÕÔâÓöÐÂÒ»ÂÖ¡°ÖØ´óÇÒÓÐÕë¶ÔÐÔ¡±µÄÍøÂç¹¥»÷£¬ÕâÊǸûú¹¹½üÄêÀ´µÚ¶þ´ÎÔâÊÜÀàËÆÊÂÎñ¡£¾ÝICCÉùÃ÷£¬´Ë´Î¹¥»÷ÓÉÆäÄÚ²¿¼à²âϵͳ·¢Ã÷£¬·¨ÔºÑ¸ËÙÆô¶¯Ô¤¾¯ºÍÏìÓ¦»úÖÆ¿ØÖÆÊÂ̬£¬²¢ÒÑÕö¿ªÈ«Ôº¹æÄ£µÄÓ°ÏìÆÀ¹À¼°Î£º¦»º½â²½·¥¡£Ö»¹Ü·¨ÔºÇ¿µ÷ËùÓÐÒªº¦ÏµÍ³ÈÔÇå¾²ÔËÐУ¬µ«ÉÐδÐû²¼¹¥»÷ÏêϸÐÔ×Ó¡¢Ç±ÔÚÊý¾Ýй¶¹æÄ£»ò¹¥»÷ÕßÉí·Ý£¬½öÌåÏÖ½«Ïò¹«ÖÚ¼°µÞÔ¼¹úÒ»Á¬×ª´ïÏ£Íû¡£2023Äê9Ô£¬¸Ã»ú¹¹ÔøÔâÓöÒ»Æð±»¶¨ÐÔΪ¡°ÍøÂçÌØ¹¤Ðж¯¡±µÄÈëÇÖÊÂÎñ¡£ÊÓ²ìÏÔʾ£¬¹¥»÷ÕßͨÏ꾡ÃÜÊÖÒÕÊÖ¶ÎÉøÍ¸ÏµÍ³£¬ÊÔͼÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬µ«Î´·¢Ã÷Êý¾Ýй¶»òÌØ¶¨Ìع¤×éÖ¯¼ÓÈëµÄÖ¤¾Ý¡£×÷ΪÈÏÕæÉóѶսÕù×ï¡¢ÖÖ×åÃð¾ø×ïµÈ×îÑÏÖØ¹ú¼Ê×ïÐеÄ˾·¨»ú¹¹£¬ICCµÄÍøÂç·ÀÓùÄÜÁ¦Ö±½Ó¹ØºõÈ«ÇòÐÌÊÂ˾·¨ÏµÍ³Îȹ̡£Æäº£ÑÀ×ܲ¿ÏµÍ³´æ´¢×Å´ó×ÚÉñÃØÊÓ²ìÊý¾Ý¡¢Ö¤ÈËÐÅÏ¢¼°¿ç¹úÏàÖúÎļþ£¬Ò»µ©Ôâй¶¿ÉÄÜΣ¼°Ö¤ÈËÇå¾²¡¢×ÌÈÅÉóѶÀú³Ì£¬ÉõÖÁÒý·¢µØÔµÕþÖÎÁ¬Ëø·´Ó¦¡£
https://www.bleepingcomputer.com/news/security/international-criminal-court-hit-by-new-sophisticated-cyberattack/
3. Esse HealthÔâÍøÂç¹¥»÷Ö³¬26Íò»¼ÕßÊý¾Ýй¶
7ÔÂ1ÈÕ£¬ÃÀ¹úÃÜËÕÀïÖÝʥ·Ò×˹ÊÐ×î´ó×ÔÁ¦Ò½Ê¦ÕûÌåEsse Health¿ËÈÕÅû¶£¬Æäϵͳ½ñÄê4ÔÂÔâÓöÍøÂç¹¥»÷£¬µ¼ÖÂÁè¼Ý26.3ÍòÃû»¼ÕßµÄÃô¸Ð¿µ½¡Êý¾Ý±»µÁ¡£×÷Ϊ´óʥ·Ò×˹µØÇøÓµÓÐ50¼ÒÕïËùºÍ1200ÓàÃûÒ½»¤Ö°Ô±µÄÒ½ÁƾÞÍ·£¬¸Ã»ú¹¹ÔÚ4ÔÂ21ÈÕÊ״μì²âµ½¹¥»÷ÕßÈëÇÖÆä½¹µã»¼ÕßÖÎÀíϵͳ¼°µç»°ÍøÂ磬Ôì³ÉÒªº¦·þÎñÖÐÖ¹³¤´ïÊýÖÜ£¬Ö±ÖÁ6ÔÂ2ÈÕ²ÅÖÜÈ«»Ö¸´ÏßÉÏ·þÎñ¡£¾ÝEsse HealthÒþ˽¹ÙJaime L. BremerkampÐû²¼µÄ֪ͨ£¬¹¥»÷ÕßÀÖ³ÉÉøÍ¸ÍøÂçºó£¬ÇÔÈ¡Á˰üÀ¨»¼ÕßÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Ò½Áưü¹ÜÐÅÏ¢¡¢Ò½ÁƼͼ±àºÅ¼°²¿·ÖÕïÁƼͼµÄµç×ÓÎļþ£¬µ«É¨³ýÁËÉç»áÇå¾²ºÅÂëй¶Σº¦¡£ÖµµÃ×¢ÖØµÄÊÇ£¬Æä½¹µãµç×Ó²¡Àúϵͳ£¨NextGen EHR£©Î´ÔÚ´Ë´ÎÊÂÎñÖÐÔâÈëÇÖ¡£´Ë´ÎÊý¾Ýй¶¹æÄ£´´Ï¸õØÇøÒ½ÁÆÐÐÒµ½üÄêÖ®×ÊÜÓ°ÏìÈËÊýÏ൱ÓÚÍâµØÃ¿10ÃûסÃñÖоÍÓÐ1ÈËÐÅϢ̻¶¡£Ö»¹ÜEsse HealthδÃ÷È·¹¥»÷ÀàÐÍ£¬µ«ÍøÂçÇ徲ר¼ÒÆÊÎöÖ¸³ö£¬³¤´ïÊýÔµÄϵͳ»Ö¸´ÖÜÆÚÓëµä·¶ÀÕË÷Èí¼þ¹¥»÷ÌØÕ÷¸ß¶ÈÎǺϡ£Esse HealthÒÑΪÊÜÓ°ÏìÕßÌṩΪÆÚ°ëÄêµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ£¨Í¨¹ýIDXƽ̨£©£¬²¢½¨ÒéÇ×½ü¹Ø×¢Òì³£Ò½ÁÆÕ˵¥¼°ÐÅÓñ¨¸æ¡£
https://www.bleepingcomputer.com/news/security/esse-health-says-recent-data-breach-affects-over-263-000-patients/
4. Kelly Benefits³ÆÊý¾Ýй¶ӰÏì55Íò¿Í»§
7ÔÂ1ÈÕ£¬ÃÀ¹úÂíÀïÀ¼ÖÝ¿µ½¡ÓëÈËÊÙ°ü¹Ü¹«Ë¾Kelly & Associates Insurance Group£¨ÉÌÒµÃû³ÆÎªKelly Benefits£©¿ËÈÕÅû¶£¬ÆäITϵͳÓÚ2024Äê12ÔÂ12ÈÕÖÁ17ÈÕʱ´úÔâδÊÚȨÈëÇÖ£¬×îÖÕÈ·Èϳ¬55ÍòÃûÓû§Ð¡ÎÒ˽¼ÒÐÅϢй¶£¬½Ï×î³õ±¨¸æµÄ3.2ÍòÈ˼¤Ôö17±¶¡£´Ë´ÎÊÂÎñÉæ¼°46¼ÒÏàÖúʵÌ壬°üÀ¨ÍŽ῵½¡°ü¹Ü¡¢°²ÀÖÈËÊÙ£¨CVS Health£©¡¢CareFirst BlueCross BlueShieldµÈÒ½ÁÆÐÐÒµ¾ÞÍ·£¬Ì»Â¶³ö°ü¹Ü·þÎñ¹©Ó¦Á´µÄųÈõÐÔ¡£¾Ý¸Ã¹«Ë¾4ÔÂ9ÈÕ¸üеÄÊÓ²ìЧ¹û£¬¹¥»÷ÕßÇÔÈ¡µÄÎļþ°üÀ¨È«Ãû¡¢Éç»áÇå¾²ºÅÂ롢˰ºÅ¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼͼ¡¢°ü¹ÜÐÅÏ¢¼°½ðÈÚÕË»§µÈ½¹µãÃô¸ÐÊý¾Ý¡£ÕâÀàÐÅÏ¢µÄ×éºÏ¼«¾ß¼ÛÖµ£¬¿ÉʹÊܺ¦ÕßÃæÁÙÍøÂç´¹ÂÚ¡¢Éç»á¹¤³ÌթƼ°¾«×¼½ðÈÚڲƵĶàÖØÎ£º¦¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬Êý¾Ýй¶¹æÄ£¾Óɶà´ÎÐÞÕý£¬Í¹ÏÔÖØ´ó·þÎñÍøÂçÏÂÈ·¶¨Ó°Ïì¹æÄ£µÄÄѶȡ£×÷ΪÌṩ¸£Àû×Éѯ¡¢Ð½³êÖÎÀí¡¢ÈËÁ¦×ÊԴϵͳ¼°ºÏ¹æÖ§³ÖµÄ×ÛºÏÐÔ·þÎñÉÌ£¬Kelly BenefitsµÄÌìÏÂÐÔÓªÒµÍøÂçµ¼ÖÂÊý¾Ý×·×ÙºÄʱÊýÔ¡£¸Ã¹«Ë¾Í¨¹ýIDXƽ̨ΪËùÓÐÊÜÓ°ÏìÕßÌṩ12¸öÔÂÃâ·ÑÐÅÓÃ¼à¿ØÓëÉí·ÝµÁÓñ£»¤·þÎñ£¬²¢½¨ÒéÓû§½ÓÄÉÇå¾²¶³½áÐÅÓñ¨¸æ¡¢ÆôÓÃÕË»§Ô˶¯ÌáÐѵȷÀÓù²½·¥¡£
https://www.bleepingcomputer.com/news/security/kelly-benefits-says-2024-data-breach-impacts-550-000-customers/
5. ChromeÁãÈÕÎó²îCVE-2025-6554Ôâ×Ô¶¯¹¥»÷
7ÔÂ1ÈÕ£¬¹È¸è¿ËÈÕÐû²¼Ç徲ͨ¸æ£¬Ðû²¼ÐÞ¸´Chromeä¯ÀÀÆ÷ÖÐÒ»¸öÒѱ»ÆÕ±éʹÓõÄÁãÈÕÎó²î£¨CVE-2025-6554£©¡£¸ÃÎó²î±£´æÓÚChromeµÄV8 JavaScriptÓëWebAssemblyÒýÇæÖУ¬ÊôÓڵ䷶µÄÀàÐÍ»ìÏýȱÏÝ£¬ÔÊÐí¹¥»÷Õßͨ¹ýÈ«ÐĽṹµÄ¶ñÒâÍøÒ³Ö´ÐÐí§Òâ´úÂ룬Òý·¢³ÌÐò±ÀÀ£»òÊý¾ÝÇÔÈ¡¡£´ËÀàÎó²îµÄÁãÈÕÌØÕ÷ÓÈΪΣÏÕ£¬¹¥»÷ÕßÍùÍùÔÚ²¹¶¡Ðû²¼Ç°¾ÍÒÑ·¢¶¯¾«×¼¹¥»÷£¬Óû§½öÐè»á¼û¶ñÒâÍøÕ¾¼´¿ÉÄܱ»Ö²ÈëÌØ¹¤Èí¼þ»òÀÕË÷³ÌÐò¡£¹È¸èÍþвÆÊÎöС×飨TAG£©Ñо¿Ô±Cl¨¦ment LecigneÓÚ6ÔÂ25ÈÕÊ״μà²âµ½Òì³£Ô˶¯£¬ÌåÏÖ¸ÃÎó²î¿ÉÄܱ»ÓÃÓÚ¹ú¼Ò¼¶ÍøÂçÌØ¹¤Ðж¯¡£Ö»¹Ü¹È¸èδÐû²¼Îó²îʹÓÃϸ½Ú£¬µ«ÈÏ¿ÉÆäÒѱ»¡°ÆÕ±éʹÓᱡ£´Ë´ÎÐÞ¸´Í¨¹ýÍÆËÍÎȹ̰æÍ¨µÀ¸üÐÂÍê³É£¬WindowsÓû§ÐèÉý¼¶ÖÁ138.0.7204.96/97£¬macOSÓû§¸üÐÂÖÁ138.0.7204.92/93£¬LinuxÓû§Í¬²½ÖÁ138.0.7204.96°æ±¾¡£ÆóÒµIT²¿·ÖÐèÌØÊâ¹Ø×¢Öն˺ϹæÐÔÖÎÀí£¬×èÖ¹Òò°æ±¾Öͺóµ¼ÖÂÊý¾Ýй¶¡£
https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html
6. ÈðÊ¿·ÇÓªÀû×éÖ¯RadixÔâÀÕË÷Èí¼þ¹¥»÷
7ÔÂ1ÈÕ£¬ÈðÊ¿ËÕÀèÊÀ·ÇÓªÀû¿µ½¡»ù½ð»áRadix½üÆÚÔâÓöÑÏÖØÀÕË÷Èí¼þ¹¥»÷£¬ÃûΪSarcomaµÄºÚ¿Í×éÖ¯ÒÑÔÚÆä°µÍøÆ½Ì¨¹ûÕæ1.3TBÇÔÈ¡Êý¾Ý£¬Òý·¢ÈðÊ¿Áª°î»ú¹¹Êý¾ÝÇå¾²¾¯±¨¡£´Ë´ÎÊÂÎñ̻¶ÁË·ÇÕþ¸®×éÖ¯×÷ΪµÚÈý·½·þÎñÉ̵ÄÍøÂçÇå¾²±¡Èõ»·½Ú£¬Æä¿Í»§º¸Ç¶à¸öÁª°î²¿·Ö£¬Ö»¹ÜÈðÊ¿¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ç¿µ÷Áª°î½¹µãÐÐÕþϵͳδ±»Í»ÆÆ£¬µ«ÍâйÊý¾Ý¿ÉÄܰüÀ¨¹«Ãñ¿µ½¡ÐÅÏ¢¡¢²¿·ÖÐ×÷¼Í¼µÈÃô¸ÐÄÚÈÝ¡£RadixϵͳÓÚ2025Äê6ÔÂ16ÈÕÔâÈëÇÖ£¬¹¥»÷Õß½ÓÄÉË«ÖØÀÕË÷Õ½ÂÔ£ºÏÈÇÔÈ¡Êý¾Ý£¬ÔÙ¼ÓÃÜϵͳË÷ÒªÊê½ð¡£Òò»ú¹¹¾Ü¾øÖ§¸¶£¬ºÚ¿ÍÓÚ6ÔÂ29ÈÕÆô¶¯Êý¾ÝÇãµ¹£¬ÏÖÔÚÉв»ÇåÎúй¶ÎļþÊÇ·ñ°üÀ¨¼ÓÃÜÃÜÔ¿»òÄÚ²¿Í¨Ñ¶¼Í¼¡£RadixËäÉù³Æ¡°ÎÞ¼£ÏóÅú×¢ÏàÖúͬ°éÃô¸ÐÊý¾ÝÊÜÓ°Ï족£¬µ«Æä·þÎñ¹æÄ£ÁýÕÖ¿µ½¡½ÌÓý¡¢Õþ²ßÍÆ¹ãµÈÁìÓò£¬Ç±ÔÚй¶Êý¾Ý»òÉæ¼°¿ç²¿·ÖÏîĿϸ½Ú¡£Ä¿½ñ£¬1.3TBÍâйÊý¾ÝµÄÕæÊµÐÔÓëÍêÕûÐÔÉÐδ»ñµÃRadixÈ·ÈÏ£¬µ«Sarcoma×éÖ¯ÒÑÐû²¼²¿·ÖÎļþĿ¼½ØÍ¼£¬°üÀ¨±ê×¢¡°Áª°îÎÀÉú²¿¡±¡¢¡°Éç±£»ù½ð¡±µÈ×ÖÑùµÄÎļþ¼Ð¡£
https://cybernews.com/security/radix-cyberattack-exposes-swiss-federal-data/


¾©¹«Íø°²±¸11010802024551ºÅ