ˮʦÁª°îÐÅÓÃÏàÖúÉç·þÎñÆ÷ÉèÖùýʧÖÂÄÚ²¿Îļþй¶
Ðû²¼Ê±¼ä 2025-09-051. ˮʦÁª°îÐÅÓÃÏàÖúÉç·þÎñÆ÷ÉèÖùýʧÖÂÄÚ²¿Îļþй¶
9ÔÂ3ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ô±Jeremiah FowlerÔÚÊÓ²ìÖз¢Ã÷£¬ÃÀ¹úˮʦÁª°îÐÅÓÃÏàÖúÉ磨NFCU£©Ò»Ì¨ÉèÖùýʧµÄ·þÎñÆ÷̻¶ÁË378GBÃô¸ÐÄÚ²¿Îļþ£¬ÊÂÎñÓÉWebsite PlanetÑо¿ÍŶÓÓëHackread.comÍŽáÅû¶¡£¸Ã·þÎñÆ÷δÉèÖÃÃÜÂë±£»¤£¬ÈκÎÈ˾ù¿É»á¼ûδ¼ÓÃܵı¸·ÝÊý¾Ý¡£Ö»¹Üй¶ÄÚÈݲ»°üÀ¨¿Í»§ÐÅÏ¢£¬µ«Ì»Â¶µÄÎļþ°üÀ¨´ó×ÚDZÔÚÃô¸ÐÊý¾Ý£ºÄÚ²¿Óû§Ãû¡¢µç×ÓÓʼþµØµã¡¢É¢ÁÐÃÜÂë¼°ÃÜÔ¿£¬ÒÔ¼°ÓÉÊý¾ÝÆÊÎöƽ̨TableauÌìÉúµÄ¶à¸öÊÂÇé²¾Îĵµ¡£ÕâЩÎĵµÏêϸ¼Í¼ÁËÓëÆäËûÄÚ²¿Êý¾Ý¿âµÄÅþÁ¬ÉèÖᢴû¿î¼¨Ð§ÓëÀûÈóÅÌËãµÄ²ÆÎñ¹«Ê½µÈ½¹µãÔËÓªÐÅÏ¢£¬×é³ÉÐÅÓÃÏàÖúÉçÄÚ²¿ÏµÍ³µÄ¡°ÊÖÒÕÀ¶Í¼¡±¡£FowlerÔÚºËʵÀú³ÌÖнØÈ¡µÄ½ØÍ¼ÏÔʾ£¬Îļþ»¹°üÀ¨ÏµÍ³ÈÕÖ¾¡¢²úÆ·´úÂë¼°±¾Ó¦±£ÃܵÄÔªÊý¾Ý¡£ÊÂÎñ±¬·¢ºó£¬NFCUѸËÙÏìÓ¦£¬ÔÚÊýСʱÄÚ±£»¤ÁËÊý¾Ý¿â¡£È»¶ø£¬Ì»Â¶Ê±³¤¼°ÊÇ·ñ±»µÚÈý·½»á¼ûÈÔ²»Ã÷È·¡£FowlerÖ¸³ö£¬±¸·ÝÊý¾Ý³£±»ÊÓΪ¡°Éú²úÊý¾ÝµÄ¾µÏñ¡±£¬µ«Æä¹ØÁªµÄÉú²úϵͳ½á¹¹»òÔªÊý¾ÝÈÔ¿ÉÄÜй¶Ҫº¦Çå¾²ÐÅÏ¢¡£
https://hackread.com/misconfigured-server-navy-federal-credit-union-data-leak/
2. αÔìAnyDesk×°ÖóÌÐòͨ¹ýClickFixȦÌ×Èö²¥MetaStealer
9ÔÂ3ÈÕ£¬HuntressÍøÂçÇå¾²ÍŶӿËÈÕ½ÒÆÆÒ»ÖÖÐÂÐÍClickFixȦÌ×£¬¹¥»÷Õßͨ¹ýαÔìÕýµ±Ô¶³Ì»á¼û¹¤¾ßAnyDeskµÄ×°ÖóÌÐò£¬ÍŽáWindowsËÑË÷¹¦Ð§ÈƹýÇå¾²·À»¤£¬×îÖÕÔÚÓû§×°±¸ÉϾ²Ä¬°²ÅÅMetaStealer¶ñÒâÈí¼þ¡£¸ÃÔ˶¯½ÓÄÉÉý¼¶°æ¡°FileFix¡±ÊÖÒÕ£¬Ïà½Ï¹Å°åClickFixȦÌ×£¨ÒªÇóÓû§¸´ÖÆÕ³ÌùÏÂÁîµ½ÔËÐжԻ°¿ò£©£¬ÆäΣÏÕÐÔÏÔÖøÌáÉý¡£¹¥»÷Á÷³ÌʼÓÚÓû§ÔÚÏßËÑË÷AnyDeskʱÎóÈëÐéÎ±ÍøÕ¾¡£¸ÃÒ³ÃæÎ±×°³ÉCloudflare CAPTCHAÑéÖ¤½çÃæ£¬ÓÕµ¼Óû§µã»÷¡°ÑéÖ¤¡±°´Å¥¡£µã»÷ºó£¬ÍøÕ¾´¥·¢WindowsÎļþ×ÊÔ´ÖÎÀíÆ÷Ö´ÐÐÌØÊâËÑË÷ÅÌÎÊ£¬½«Óû§ÅÌËã»úÅþÁ¬ÖÁºÚ¿Í¿ØÖƵÄÔ¶³Ì·þÎñÆ÷£¬²¢Ö±½ÓÍÆËÍαװ³É¡°Readme Anydesk.pdf¡±µÄ¶ñÒâ×°Öðü¡£¸ÃÎļþÍâòΪPDFÎĵµ£¬ÊµÔò°üÀ¨Ë«ÖزÙ×÷Âß¼£ºÏÈÏÂÔØÕýµ±AnyDeskÓ¦ÓóÌÐòÒÔ½µµÍÓû§Ð¡ÐÄ£¬Ëæºó¾²Ä¬×°ÖÃMetaStealer¶ñÒâÈí¼þ¡£MetaStealer¾ß±¸¸ßÒþ²ØÐÔÐÅÏ¢ÇÔÈ¡ÄÜÁ¦£¬¿É͵ȡµÇ¼ƾ֤¡¢Ãô¸ÐÎļþ¼°¼ÓÃÜÇ®°üÊý¾Ý£¬×é³ÉÑÏÖØÇå¾²Íþв¡£
https://hackread.com/fake-anydesk-installer-metastealer-clickfix-scam/
3. È«Çò¶à¹úÔâÓö³¬2.5ÒÚ·ÝÉí·Ý¼Í¼´ó¹æÄ£Ð¹Â¶Î£»ú
9ÔÂ3ÈÕ£¬½üÆÚ£¬Ò»³¡Éæ¼°ÖÁÉÙÆß¸ö¹ú¼Ò¡¢³¬2.5ÒÚ·ÝÉí·Ý¼Í¼µÄ´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÒý·¢È«Çò¹Ø×¢¡£´Ë´Îй¶µÄ¹«ÃñÐÅÏ¢ÁýÕÖÍÁ¶úÆä¡¢°£¼°¡¢É³Ìذ¢À²®¡¢°¢ÁªÇõ¡¢Ä«Î÷¸ç¡¢ÄϷǺͼÓÄô󣬰üÀ¨Éí·ÝÖ¤ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÁªÏµ·½·¨¼°¼ÒͥסַµÈÕþ¸®¼¶Éí·Ýµµ°¸Ï¸½Ú¡£Èý̨ÉèÖùýʧµÄ·þÎñÆ÷£¨ÍйÜÓÚ°ÍÎ÷ºÍ°¢ÁªÇõIPµØµã£©³ÉΪй¶Դͷ£¬ÆäÊý¾Ý¿â½á¹¹¸ß¶ÈÏàËÆ£¬ÌåÏÖ¿ÉÄÜÔ´×ÔͳһÔËÓª·½£¬µ«Ïêϸ¿ØÖÆÕßÈÔÎÞ·¨È·¶¨¡£CybernewsÑо¿Ö°Ô±Ö¸³ö£¬ÍÁ¶úÆä¡¢°£¼°ºÍÄϷǹ«ÃñÊÜÓ°ÏìÓÈΪÑÏÖØ£¬ÕâЩ¹ú¼ÒµÄÊý¾Ý¿â°üÀ¨ÖÜÈ«Éí·ÝÐÅÏ¢£¬Îª½ðÈÚڲơ¢Éí·ÝðÓᢶ¨ÏòÍøÂç´¹ÂÚ¼°Õ©ÆµÈÀÄÓÃÐÐΪ·¿ªÁË´óÃÅ¡£ÊÂÎñÆØ¹âºó£¬ÍйܷþÎñÌṩÉÌÒÑÏÞÖÆÊý¾Ý¹ûÕæ»á¼û£¬µ«Ð¹Â¶ÐÅÏ¢µÄDZÔÚÀÄÓÃΣº¦ÈÔÒ»Á¬±£´æ¡£
https://cybernews.com/security/identity-records-global-data-leak/
4. CISAÖÒÑÔTP-LinkÓëWhatsAppÎó²îÔâ»îԾʹÓÃ
9ÔÂ3ÈÕ£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕÐû²¼½ôÆÈÖÒÑÔ£¬Ö¸³öºÚ¿ÍÕýÆð¾¢Ê¹ÓÃÁ½¸ö¸ßΣÎó²îÌᳫ¹¥»÷£¬²¢Òѽ«¶þÕßÁÐÈë¡°ÒÑÖª±»Ê¹ÓÃÎó²î£¨KEV£©¡±Ä¿Â¼£¬Ç¿µ÷Æä´ºÁª°îÆóÒµ×é³ÉÖØ´óÍþв¡£Ê׸öÎó²îÓ°ÏìTP-Link TL-WA855RE V5 WiFiÀ©Õ¹Æ÷£¬¸Ã×°±¸ÔÚÑÇÂíÑ·ÓµÓг¬120,500Ìõ̸ÂÛ£¬ÏÔʾÆäÆÕ±éÊ¢ÐС£Îó²î±£´æÎåÄ꣬ÑÏÖØÐÔÆÀ·Ö´ï8.8/10£¬ÔÊÐíÍ³Ò»ÍøÂçϵÄδ¾Éí·ÝÑéÖ¤¹¥»÷Õß·¢ËÍTDDP_RESET POSTÇëÇ󣬴¥·¢×°±¸¹¤³§ÖØÖò¢ÖØÆô£¬ËæºóÉèÖÃÐÂÖÎÀíÃÜÂëÒÔ»ñÈ¡¿ØÖÆÈ¨¡£CISAÖ¸³ö£¬Î´´ò²¹¶¡ÇÒÓ²¼þ°æ±¾ÎªV5µÄ×°±¸Ò×Êܹ¥»÷£¬¹©Ó¦ÉÌËäÒÑÌṩ¹Ì¼þ¸üУ¬µ«²¿·Ö×°±¸¿ÉÄÜÒÑ´ïÉúÃüÖÜÆÚÖյ㣬½¨ÒéÁª°î»ú¹¹Á¬Ã¦×èֹʹÓûò½ÓÄÉÑϿỺ½â²½·¥¡£µÚ¶þÏîÎó²îÉæ¼°WhatsApp iOS/Mac¿Í»§¶Ë£¬ÓÉ¡°Á´½Ó×°±¸Í¬²½ÐÂÎÅÊÚȨ²»ÍêÕû¡±Òý·¢£¬¿ÉÄÜÔÊÐíÎÞ¹ØÓû§´¥·¢Ä¿µÄ×°±¸´¦Öóͷ£í§ÒâURLÄÚÈÝ£¬Òѱ»ÓÃÓڸ߼¶Ìع¤Èí¼þÔ˶¯¡£WhatsAppÓëÆ»¹ûÒÑÐû²¼½ôÆÈ¸üÐÂÐÞ¸´´ËÎÊÌ⣬¹©Ó¦ÉÌÆÀ¹ÀÒÔΪ¸ÃÎó²î¿ÉÄܱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ä¿µÄÓû§µÄÖØ´ó¹¥»÷¡£
https://cybernews.com/security/tp-link-whatsapp-vulnerabilities-exploited-by-hackers/
5. Chess.comÅû¶µÚÈý·½Ó¦ÓÃÊý¾Ýй¶ÊÂÎñ£¬Ó°Ïì4500ÃûÓû§
9ÔÂ4ÈÕ£¬È«Çò×î´óÔÚÏß¹ú¼ÊÏóÆåƽ̨Chess.com¿ËÈÕÅû¶һÆðÉæ¼°µÚÈý·½Îļþ´«ÊäÓ¦ÓõÄÊý¾Ýй¶ÊÂÎñ¡£¾Ýͨ¸æ£¬2025Äê6ÔÂ5ÈÕÖÁ18ÈÕʱ´ú£¬ÍþвÐÐΪÕßδ¾ÊÚȨ»á¼ûÁË¸ÃÆ½Ì¨Ê¹ÓõĵÚÈý·½Îļþ´«ÊäÓ¦ÓóÌÐò£¬µ¼ÖÂÔ¼4,500ÃûÓû§µÄСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©¿ÉÄܱ»Ð¹Â¶¡£Chess.comÓÚ6ÔÂ19ÈÕ·¢Ã÷Òì³£ºó£¬Á¬Ã¦Æô¶¯ÊӲ첢ԼÇë¶¥¼âÇ徲ר¼Ò£¬Í¬²½Í¨ÖªÁª°îÖ´·¨²¿·Ö£¬²¢½ÓÄɲ½·¥ÐÞ¸´Îó²î¡£¹«Ë¾Ç¿µ÷£¬´Ë´ÎÊÂÎñ½öÓ°ÏìµÚÈý·½Ó¦ÓóÌÐò£¬Æä×ÔÉí»ù´¡ÉèÊ©¼°»áÔ±ÕË»§ÏµÍ³Î´Êܲ¨¼°¡£Ð¹Â¶Êý¾ÝÖ÷Òª°üÀ¨Óû§ÐÕÃû¼°ÆäËûPII£¬µ«Î´Éæ¼°²ÆÎñÐÅÏ¢¡£ÏÖÔÚÎÞÖ¤¾ÝÅú×¢±»µÁÊý¾ÝÒѱ»¹ûÕæÅû¶»òÀÄÓá£×÷Ϊµ÷½â²½·¥£¬Chess.comΪÊÜÓ°ÏìÓû§Ìṩ1-2ÄêÃâ·ÑÉí·Ý͵ÇÔÓëÐÅÓÃ¼à¿Ø·þÎñ£¬Óû§ÐèÔÚ2025Äê12ÔÂ3ÈÕǰÍê³É×¢²á¡£
https://www.bleepingcomputer.com/news/security/chesscom-discloses-recent-data-breach-via-file-transfer-app/
6. ÆÕÀû˾ͨ±±ÃÀ¹¤³§È·ÈÏÍøÂç¹¥»÷Ó°ÏìÁËÆäÉú²ú
9ÔÂ4ÈÕ£¬È«Çò×î´óÂÖÌ¥ÖÆÔìÉÌÆÕÀû˾֤ͨʵ£¬Æä±±ÃÀ·Ö¹«Ë¾ÆÕÀû˾ͨÃÀÖÞ¹«Ë¾£¨BSA£©ÕýÊÓ²ìÓ°Ï첿·ÖÖÆÔ칤³§ÔËÓªµÄÍøÂç¹¥»÷ÊÂÎñ¡£´Ë´Î¹¥»÷ÓÚ2025Äê9ÔÂ2ÈÕÊ״α»±¨µÀ£¬Éæ¼°ÄÏ¿¨ÂÞÀ´ÄÉÖݰ¬¿ÏÏØÁ½¼Ò¹¤³§¼°¼ÓÄôó¿ý±±¿ËÊ¡ÇÇÀû°£Ìع¤³§£¬Òý±¬·¢²úÖÐÖ¹¡£BSA×÷ΪÆÕÀû˾ͨ¼¯ÍÅÖ÷Òª·ÖÖ§£¬ÓµÓÐ50¼Ò¹¤³§¡¢5.5ÍòÃûÔ±¹¤£¬Õ¼¼¯ÍÅ×ܹæÄ£43%£¬2024ÄêÏúÊÛ¶î´ï120ÒÚÃÀÔª£¬ÓªÒµÀûÈó12ÒÚÃÀÔª¡£ÆÕÀû˾ͨǿµ÷£¬Æä¿ìËÙÏìÓ¦»úÖÆÔÚÔçÆÚ½×¶ÎÓÐÓÃ×èÖ¹Á˹¥»÷ÉìÕÅ£¬±ÜÃâ¿Í»§Êý¾Ýй¶»òÉî¶ÈÍøÂçÉøÍ¸¡£¹«Ë¾ÉùÃ÷³Æ£¬ÍŶÓÒѰ´¼È¶¨ÐÒé¿ØÖÆÎÊÌ⣬ȡ֤ÆÊÎöÈÔÔÚ¾ÙÐУ¬µ«ÆðÔ´ÅжÏÊÂÎñÓ°ÏìÓÐÏÞ£¬Î´·¢Ã÷¿Í»§Êý¾Ý»òϵͳ½Ó¿ÚÔâй¶¡£Îª¼õÇṩӦÁ´Î£º¦£¬Ô±¹¤Õý24Ð¡Ê±ÊÆÇéÒÔ»Ö¸´ÔËÓª£¬È·±£Êг¡²úÆ·¹©Ó¦Îȹ̡£ÆÕÀû˾ͨ½«¡°¼á³ÖÓªÒµÒ»Á¬ÐÔ¼°±£»¤Êý¾Ý½Ó¿Ú¡±ÁÐΪÖ÷ҪʹÃü£¬²¢ÔÊÐíÍÆÐпͻ§ÒåÎñ£¬½â¾öDZÔÚºóÐøÓ°Ïì¡£Õë¶ÔýÌåѯÎÊÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ¹¥»÷£¬¹«Ë¾ÉÐδ»ØÓ¦£¬ÏÖÔÚÒ²ÎÞÈκÎÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´Ë´ÎÊÂÎñÈÏÕæ¡£
https://www.bleepingcomputer.com/news/security/tire-giant-bridgestone-confirms-cyberattack-impacts-manufacturing/


¾©¹«Íø°²±¸11010802024551ºÅ