Ò½ÁƼ¯ÍÅHSGIÊý¾Ýй¶ӰÏ쳬60ÍòÈË
Ðû²¼Ê±¼ä 2025-08-291. Ò½ÁƼ¯ÍÅHSGIÊý¾Ýй¶ӰÏ쳬60ÍòÈË
8ÔÂ27ÈÕ£¬Ò½ÁƱ£½¡·þÎñ¼¯ÍÅ£¨HSGI£©¿ËÈÕÅû¶һÆðÖØ´óÊý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁè¼Ý60ÍòÃû¸öÌå¡£Õâ¼Ò×ܲ¿Î»ÓÚ±öϦ·¨ÄáÑÇÖݵÄÉÏÊй«Ë¾×¨ÎªÈ«ÃÀÒ½ÁÆ»ú¹¹Ìṩ֧³Ö·þÎñ£¬ÄêÊÕÈë´ï17ÒÚÃÀÔª£¬ÆäϵͳÇå¾²¶ÔÊýǧ¼ÒÒ½ÁÆ»ú¹¹µÄÔË×÷ÖÁ¹ØÖ÷Òª¡£ÊÂÎñʱ¼äÏßÏÔʾ£¬HSGIÓÚ2024Äê10ÔÂ7ÈÕ¼ì²âµ½ÍøÂçÔâÊÜδÊÚȨ»á¼û£¬ËæºóÈ·ÈÏÈëÇÖʼÓÚ9ÔÂ27ÈÕ£¬²¢ÓÚ10ÔÂ3ÈÕ¿¢Ê¡£ÊÓ²ìÏÔʾ£¬¹¥»÷ÕßÔÚ´Ëʱ´ú»á¼û²¢¸´ÖÆÁËϵͳÄڵIJ¿·ÖÎļþ¡£Ö»¹ÜÎó²î±¬·¢ÔÚ2024Äê9ÔÂÄ©£¬µ«ÊÜÓ°Ïì¸öÌåÖ±ÖÁ2025Äê8ÔÂ25ÈÕ²ÅÊÕµ½Í¨Öª£¬Õû¸öÊÓ²ìÀú³ÌºÄʱ½ü10¸öÔ¡£Ð¹Â¶Êý¾ÝÀàÐÍÒò¸öÌå¶øÒ죬¿ÉÄܰüÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢ÖÝʶ±ðÂë¡¢²ÆÎñÕË»§ÐÅÏ¢¼°ÕË»§»á¼ûƾ֤µÈÃô¸ÐÄÚÈÝ¡£HSGIÔÚͨ¸æÖÐÇ¿µ÷£¬ÏÖÔÚÉÐÎÞÖ¤¾ÝÅú×¢±»µÁÐÅÏ¢Òѱ»ÀÄÓ㬵«ÈÔ½¨ÒéÊÜÓ°ÏìÕßСÐÄÍøÂç´¹ÂÚ¡¢Õ©ÆÐÐΪ£¬²¢Ç×½ü¼à¿ØÒøÐÐÕË»§Òì³£Ô˶¯¡£×÷ΪӦ¶Ô²½·¥£¬HSGIΪÊý¾Ýй¶Êܺ¦ÕßÌṩ12ÖÁ24¸öÔµÄÃâ·ÑÐÅÓÃ¼à¿ØÓëÉí·Ý͵ÇÔ±£»¤·þÎñ£¬ÏêϸÏÞÆÚÈ¡¾öÓÚй¶Êý¾ÝµÄÑÏÖØË®Æ½¡£
https://www.bleepingcomputer.com/news/security/healthcare-services-group-data-breach-impacts-624-000-people/
2. Sangoma FreePBXÁãÈÕÎó²îÔâÆð¾¢Ê¹Ó㬶ą̀·þÎñÆ÷±»ÈëÇÖ
8ÔÂ27ÈÕ£¬Sangoma FreePBXÇå¾²ÍŶӿËÈÕÖÒÑÔ£¬Æä»ùÓÚAsteriskµÄ¿ªÔ´PBXƽ̨±£´æ±»Æð¾¢Ê¹ÓõÄÁãÈÕÎó²î£¬Ó°Ïì̻¶ÔÚ¹«¹²»¥ÁªÍøÉϵÄÖÎÀíÔ±¿ØÖÆÃæ°å£¨ACP£©ÏµÍ³¡£FreePBXÆÕ±éÓ¦ÓÃÓÚÆóÒµ¡¢ºô½ÐÖÐÐļ°·þÎñÌṩÉÌÖÎÀíÓïÒôͨѶ¡¢SIPÖм̵Ƚ¹µãÓªÒµ£¬´Ë´ÎÎó²î̻¶Òý·¢´ó¹æÄ£·þÎñÆ÷ÈëÇÖÊÂÎñ£¬²¨¼°ÊýǧSIP·Ö»úÓëÖмÌÏß·¡£¾ÝÇ徲ͨ¸æ£¬×Ô8ÔÂ21ÈÕÆð£¬ºÚ¿Íͨ¹ýδÊܱ£»¤µÄFreePBXÖÎÀíÔ±½çÃæÌᳫ¹¥»÷¡£SangomaÒÑÐû²¼EDGEÄ£¿éÐÞ¸´³ÌÐòÒÔ×è¶ÏÐÂ×°ÖÃѬȾ£¬µ«ÈϿɸò¹¶¡ÎÞ·¨½â¾öÏÖÓÐϵͳÎÊÌ⣬½¨ÒéÓû§Í¨¹ý·À»ðǽÏÞÖÆACP»á¼û£¬½öÔÊÔÊÐíÐÅÖ÷»úÅþÁ¬¡£Îó²îÓ°ÏìÔËÐÐv16/v17°æ±¾ÇÒ×°Öö˵ãÄ£¿éµÄϵͳ£¬²¿·ÖÓâÆÚÖ§³ÖÌõÔ¼µÄ×°±¸¿ÉÄÜÎÞ·¨×°ÖøüУ¬ÐèÍêÈ«×è¶ÏACP»á¼ûÖ±ÖÁ±ê×¼Çå¾²°æ±¾Ðû²¼¡£¹¥»÷ÒÑÔì³ÉÏÖʵË𺦣º¶àÃûÓû§±¨¸æ·þÎñÆ÷±»ÈëÇÖ£¬Ä³ÆóÒµ»ù´¡ÉèÊ©Öг¬3000¸öSIP·Ö»ú¼°500ÌõÖмÌÏßÊÜÓ°Ï죬¹¥»÷Õßͨ¹ýÎó²îÖ´ÐÐí§ÒâAsteriskÏÂÁî¡£Sangoma½¨ÒéÊÜÓ°ÏìÓû§´Ó8ÔÂ21ÈÕǰ±¸·Ý»Ö¸´ÏµÍ³£¬°²ÅÅÐÞ²¹Ä£¿éºóÂÖ»»ËùÓÐSIPƾ֤£¬²¢ºË²éͨ»°¼Í¼ÓëÕ˵¥ÖеÄÒì³£¹ú¼Êͨ»°¡£
https://www.bleepingcomputer.com/news/security/freepbx-servers-hacked-via-zero-day-emergency-fix-released/
3. ÀÕË÷Èí¼þPromptLockʹÓÃÈ˹¤ÖÇÄܼÓÃܺÍÇÔÈ¡Êý¾Ý
8ÔÂ27ÈÕ£¬ÍþвÑо¿Ö°Ô±¿ËÈÕÅû¶һ¿îÃûΪPromptLockµÄ¿çƽ̨ÀÕË÷Èí¼þ£¬¸Ã¶ñÒâÈí¼þͨ¹ý¼¯³ÉÈ˹¤ÖÇÄÜÊÖÒÕʵÏÖ¶¯Ì¬¾ç±¾ÌìÉú£¬³ÉΪÊ׸ö±»Ö¤ÊµµÄAIÇý¶¯ÐÍÀÕË÷Èí¼þ¡£¾ÝESET±¨¸æ£¬PromptLock½ÓÄÉGolang±àд£¬Ê¹ÓÃOllama APIŲÓÃOpenAIµÄgpt-oss:20b´óÐÍÓïÑÔÄ£×Ó£¬Í¨¹ýÊðÀíËíµÀÅþÁ¬Ô¶³Ì·þÎñÆ÷ÉϵÄLLM£¬»ùÓÚÓ²±àÂëÌáÐѶ¯Ì¬ÌìÉú¶ñÒâLua¾ç±¾£¬ÊµÏÖ¶ÔWindows¡¢macOSºÍLinuxϵͳµÄÎļþö¾Ù¡¢Êý¾ÝÇÔÈ¡¼°¼ÓÃܲÙ×÷¡£¸Ã¶ñÒâÈí¼þµÄ½¹µãÁ¢ÒìÔÚÓÚÆäÊÂÇéÁ÷³Ì£ºÍ¨¹ýÔ¤ÉèÌáÐÑ´ÊÖ¸ÁîÄ£×ÓÌìÉú¾ß±¸ÍâµØÏµÍ³½»»¥ÄÜÁ¦µÄLua¾ç±¾£¬º¸ÇÎļþϵͳɨÃè¡¢Ãô¸ÐÊý¾Ýʶ±ð¡¢¼ÓÃÜʵÑéµÈÄ£¿é¡£Ö»¹Ü¾ß±¸Êý¾ÝÏú»Ù¹¦Ð§£¬µ«¸ÃÌØÕ÷ÉÐδÍêȫʵÏÖ¡£ÖµµÃ×¢ÖØµÄÊÇ£¬PromptLock½ÓÄÉÇáÁ¿¼¶SPECK 128λËã·¨¾ÙÐмÓÃÜ£¬Õâһͨ³£ÓÃÓÚRFIDÁìÓòµÄË㷨ѡÔñ£¬±»Ñо¿Ö°Ô±ÊÓΪÊÖÒÕ²»¿ÉÊìµÄÌåÏÖ¡£±ðµÄ£¬ÆäÓ²±àÂëµÄ±ÈÌØ±ÒµØµãÓëÖб¾´Ï¹ØÁª£¬½øÒ»²½×ôÖ¤Á˸ÃÈí¼þÈÔ´¦ÓÚ¿´·¨ÑéÖ¤½×¶Î¡£ESETÇ¿µ÷£¬PromptLockÉÐδÔÚÕæÊµ¹¥»÷³¡¾°Öб»ÊӲ쵽£¬ÆäÑù±¾½öͨ¹ýVirusTotal±»·¢Ã÷£¬»òΪÑо¿ÏîĿй¶ËùÖ¡£
https://www.bleepingcomputer.com/news/security/experimental-promptlock-ransomware-uses-ai-to-encrypt-steal-data/
4. ÃÀºÉÍŽáÖ´·¨´Ý»Ù¿ç¹úαÔìÖ¤¼þƽ̨VerifTools
8ÔÂ28ÈÕ£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ÓëºÉÀ¼¾¯·½¿ËÈÕÕö¿ª¿ç¹úÍŽáÐж¯£¬ÀֳɹرÕÈ«Çò×ÅÃûαÔìÉí·ÝÖ¤¼þƽ̨VerifTools£¬²¢²é·âÆäλÓÚ°¢Ä·Ë¹Ìص¤µÄ·þÎñÆ÷¼¯Èº£¬±ê¼Ç׏ú¼ÊÖ´·¨»ú¹¹¶ÔÊý×ÖÉí·Ý·¸·¨µÄÖØÈ³ö»÷¡£¸Ãƽ̨×Ô2022ÄêÆðͨ¹ý¼ÓÃÜÇ®±ÒÉúÒ⣬ÒÔ9ÃÀÔªÖÁÊý°ÙÃÀÔª²»µÈµÄ¼ÛÇ®ÏòÈ«ÇòÓû§ÌṩαÔìµÄÃÀÅ·¸÷¹ú¼ÝʻִÕÕ¡¢»¤ÕÕµÈÖ¤¼þ£¬Ðγɼ¯ÖÆ×÷¡¢ÊðÀí¹ºÖÃÓëÉí·ÝðÓÃÓÚÒ»ÌåµÄÍêÕûÐþÉ«¹¤ÒµÁ´¡£Æ¾Ö¤ÃÀ¹úÐÂÄ«Î÷¸çÖÝÉó²é¹Ù°ì¹«ÊÒÅû¶£¬FBIÓÚ2022Äê8ÔÂÆô¶¯ÊӲ죬·¢Ã÷¸Ãƽ̨²»µ«±»ÓÃÓÚÒøÐÐÕ©Æ¡¢ÍøÂç´¹ÂÚ¡¢ÌÓ±Ü˾·¨×·Ôð¼°ÄäÃûÈÆ¹ý½ðÈÚÆ½Ì¨"ÏàʶÄãµÄ¿Í»§"£¨KYC£©ÉóºË£¬¸ü³ÉΪδ³ÉÄêÈ˹æ±ÜÄêËêÏÞÖÆµÄ»ÒɫͨµÀ¡£ºÉÀ¼¾¯·½Ö¤Êµ£¬Óû§½öÐèÉÏ´«ÕÕÆ¬²¢ÌîдÐéαÐÅÏ¢£¬¼´¿Éͨ¹ý×Ô¶¯»¯ÏµÍ³ÌìÉú¸ß·ÂÕæÖ¤¼þͼÏñ£¬Õû¸öÀú³ÌÓÌÈç"ÏßÉϵã²Í"°ã±ã½Ý¡£´Ë´ÎÐж¯ÖУ¬ÃÀºÉÖ´·¨»ú¹¹²é»ñ2̨ÎïÀí·þÎñÆ÷¼°21̨ÐéÄâ·þÎñÆ÷£¬³¹µ×¸´ÖÆÆäÍøÕ¾»ù´¡ÉèÊ©Êý¾Ý¡£
https://www.bleepingcomputer.com/news/security/police-seize-veriftools-fake-id-marketplace-servers-domains/
5. MathWorksÔâÓöÀÕË÷¹¥»÷ÖÂÍòÈËÊý¾Ýй¶
8ÔÂ28ÈÕ£¬È«ÇòÊýѧÅÌËãÓë·ÂÕæÈí¼þÁì¾üÆóÒµMathWorks¿ËÈÕÅû¶£¬ÆäÍøÂçϵͳÓÚ2024Äê4ÔÂÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÁè¼Ý1.04ÍòÃûÔ±¹¤¼°¿Í»§µÄÃô¸ÐÊý¾Ýй¶¡£ÕⳡһÁ¬ÓâÔµÄÇå¾²ÊÂÎñÒý·¢·þÎñ´ó¹æÄ£ÖÐÖ¹£¬²¢Ì»Â¶³ö¹¤ÒµÈí¼þÁìÓòÈÕÒæÑÏËàµÄÍøÂçÇå¾²ÌôÕ½¡£Æ¾Ö¤MathWorksÏòÃÀ¹úÃåÒòÖݺÍÂíÈøÖîÈûÖÝ×ÜÉó²é³¤Ìá½»µÄ±¨¸æ£¬¹¥»÷ÕßÓÚ4ÔÂÇÖÈëÆäÍøÂçºóºã¾ÃDZÔÚ£¬Ö±ÖÁ5ÔÂ18Èղű»¼ì²â·¢Ã÷¡£´Ë´ÎÈëÇÖµ¼ÖÂÔ±¹¤Óë¿Í»§ÎÞ·¨»á¼û¶àÒòËØÈÏÖ¤£¨MFA£©¡¢µ¥µãµÇ¼£¨SSO£©¡¢ÔÆÖÐÐÄ¡¢ÔÊÐíÖ¤ÖÎÀíµÈÒªº¦ÏµÍ³£¬Ö±½ÓÓ°ÏìÈ«Çò34¸ö·þÎñ´¦µÄÔËÓª¡£Ð¹Â¶Êý¾Ýº¸ÇÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂëµÈ¸ßÃô¸ÐÐÅÏ¢£¬Éæ¼°ÃÀ¹ú±¾ÍÁ¼°·ÇÃÀ¹ú¹«ÃñµÄ»ìÏýÊý¾Ý¼¯¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬Ö»¹ÜMathWorksÔÚ5ÔÂ27ÈÕ¹ûÕæÈÏ¿ÉÔâÓöÀÕË÷Èí¼þÊÂÎñ£¬µ«Ê¼ÖÕδÅû¶¹¥»÷ÍÅ»ïÃû³Æ¼°ÏêϸÊÖÒÕϸ½Ú¡£×èÖ¹ÏÖÔÚ£¬ÎÞÈκÎÒÑÖªÀÕË÷ÍÅ»ïÐû³Æ¶Ô´ËÊÂÈÏÕæ¡£
https://www.bleepingcomputer.com/news/security/matlab-dev-says-ransomware-gang-stole-data-of-over-10-000-people/
6. TransUnionÒòSalesforceÕË»§ÈëÇÖÖÂ440ÍòÓû§Êý¾Ýй¶
8ÔÂ28ÈÕ£¬ÃÀ¹úÈý´óÐÅÓñ¨¸æ»ú¹¹Ö®Ò»TransUnion¿ËÈÕÅû¶£¬ÆäSalesforceÕË»§ÓÚ2025Äê7ÔÂ28ÈÕÔâÓöδ¾ÊÚȨ»á¼û£¬µ¼ÖÂÔ¼440ÍòÃÀ¹úÓû§µÄÃô¸ÐСÎÒ˽¼ÒÐÅϢй¶¡£´Ë´ÎÊÂÎñÔÙ´Î̻¶ÁËÈ«ÇòÐÅÓÃÊý¾Ý¾ÞÍ·µÄÍøÂçÇå¾²¶Ì°å£¬²¢Òý·¢¶ÔµÚÈý·½·þÎñÒÀÀµÎ£º¦µÄÆÕ±é¹Ø×¢¡£×÷ΪÄêÊÕÈë30ÒÚÃÀÔª¡¢ÓªÒµÁýÕÖ30¹úµÄÐÅÓÃÊý¾Ý¾ÞÍ·£¬TransUnionÕÆÎÕ×ÅÈ«ÇòÁè¼Ý10ÒÚÏûºÄÕßµÄÐÅÓÃÐÅÏ¢£¬ÆäÖÐÃÀ¹ú±¾ÍÁÓû§Ô¼2ÒÚ¡£´Ë´Îй¶µÄÊý¾ÝԴΪÆäÏûºÄÕßÖ§³ÖӪҵʹÓõÄSalesforceµÚÈý·½Ó¦Ó㬹¥»÷Õßͨ¹ý¸ÃÎó²îÇÔÈ¡ÁËÓû§ÐÕÃû¡¢µØµã¡¢µç»°¡¢ÓÊÏä¡¢³öÉúÈÕÆÚ¼°Î´±à¼µÄÉç»áÇå¾²ºÅÂ루SSN£©µÈ½¹µãÉí·ÝÐÅÏ¢£¬ÉõÖÁ°üÀ¨¿Í»§ÇëÇóÃâ·ÑÐÅÓñ¨¸æµÄÉúÒâ¼Í¼¡£Ö»¹ÜTransUnionÇ¿µ÷δй¶½¹µãÐÅÓñ¨¸æÊý¾Ý£¬µ«Ñù±¾ÖÐÏÔʾµÄÍêÕûSSNµÈÃô¸Ð×ֶΣ¬ÈÔ×ãÒÔÈÃÊܺ¦ÕßÃæÁÙÉí·ÝµÁÓᢽðÈÚթƵÈÖØ´óΣº¦¡£¹«Ë¾ÒÑÏòÊÜÓ°ÏìÓû§Ìṩ24¸öÔÂÃâ·ÑÐÅÓÃ¼à¿Ø·þÎñ£¬µ«Î´Åû¶Ïêϸй¶¹æÄ£Óë¹¥»÷ÍÅ»ïÃû³Æ¡£
https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/


¾©¹«Íø°²±¸11010802024551ºÅ