ºÚ¿ÍÈëÇÖ°ÍÎ÷¿µ½¡ÐÅÏ¢¹«Ë¾£¬Ö°ÍÎ÷Ïܱø¶ÓÊý¾Ýй¶
Ðû²¼Ê±¼ä 2025-09-261. ºÚ¿ÍÈëÇÖ°ÍÎ÷¿µ½¡ÐÅÏ¢¹«Ë¾£¬Ö°ÍÎ÷Ïܱø¶ÓÊý¾Ýй¶
9ÔÂ22ÈÕ£¬ÍþвÐÐΪÕßÔÚµØÏÂÂÛ̳Ðû³ÆÈëÇÖ°ÍÎ÷¿µ½¡ÐÅÏ¢¹«Ë¾Maida.health£¬ÇÔÈ¡³¬2TB°ÍÎ÷Ïܱø¶ÓÃô¸ÐÊý¾Ý£¬º¸Ç¾ü¹Ù¼°Æä¼ÒÈË¿µ½¡¼Í¼¡¢Éí·ÝÖ¤¡¢Ò½ÁÆ·¢Æ±¡¢Õï¶Ï±¨¸æ£¨º¬ÐÄÔಡѧ¡¢Éñ¾²¡Ñ§¡¢¸¾¿ÆÑ§µÈר¿ÆÐÅÏ¢£©¼°ÁÙ´²»¼ÕßÊý¾Ý¡£Êý¾ÝÈôÊôʵ£¬½«Òý·¢ÑÏÖØÒþ˽Σº¦£¬Ò½ÁÆ·¢Æ±ÓëÌå¼ì±¨¸æ°üÀ¨Õï¶ÏЧ¹û¡¢Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¬¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ»òÒ½ÁÆÚ²Æ£¬ÀýÈç·¸·¨·Ö×Óð³äÊܺ¦Õß»ñÈ¡´¦·½Ò©»òÒ½ÁÆ·þÎñ¡£°ÍÎ÷Ïܱø×÷Ϊ¹ú¼ÒÖÆÊ½²½¶Ó£¬ÈÏÕæµØ·½¹«¹²ÖÈÐòά»¤£¬ÆäÊý¾ÝÐ¹Â¶Éæ¼°¾ü¹Ù¼°¾ìÊôÒþ˽£¬Ó°Ïì¹æÄ£ÆÕ±é¡£Maida.health×÷ΪÄêÓªÊÕ4590ÍòÃÀÔªµÄÒ½ÁÆÊý×Ö·þÎñÉÌ£¬Ìṩ°ü¹ÜÀíÅâÖÎÀí¡¢Õ˵¥´¦Öóͷ£¡¢Ô¶³Ì×ÉѯµÈAI×Ô¶¯»¯·þÎñ£¬´Ë´ÎÊÂÎñ͹ÏÔµÚÈý·½·þÎñÌṩÉ̵ÄÇå¾²Îó²îΣº¦¡£
https://cybernews.com/security/brazil-police-health-data-breach/
2. ÃÀ¹úÊÕÈëÈËÊÙ°ü¹ÜAILÊýÊ®Íò¿Í»§¼Í¼±»µÁ
9ÔÂ22ÈÕ£¬ÃÀ¹ú´óÐÍÔö²¹°ü¹ÜÌṩÉÌÃÀ¹úÊÕÈëÈËÊÙ£¨AIL£©ÔâÓöÊý¾Ýй¶£¬¹¥»÷ÕßÔÚÈÈÃÅÊý¾Ýй¶ÂÛ̳Ðû³ÆÇÔÈ¡ÁËÊýÊ®ÍòÌõ¿Í»§¼Í¼£¬Éæ¼°È«Ãû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢ÁªÏµÐÅÏ¢¼°±£µ¥×´Ì¬¡¢°ü¹ÜÍýÏëÃû³ÆµÈÃô¸ÐÐÅÏ¢¡£Ñо¿ÍŶÓÑéÖ¤Êý¾ÝÑù±¾ºóÈ·ÈÏ£¬Ô¼15ÍòÌõ¼Í¼Óë¹¥»÷ÕßÐÎòһÖ£¬ÐÅÏ¢ÕæÊµÐԽϸߡ£AIL×÷Ϊ¾ÙÖÚÈËÊÙ£¨ÄêÊÕÈ볬57ÒÚÃÀÔª£©ÆìÏÂ×Ó¹«Ë¾£¬×ܲ¿Î»Óڵ¿ËÈøË¹ÖÝ£¬ÊÇÃÀ¹ú×î´óµÄÔö²¹°ü¹ÜÌṩÉÌÖ®Ò»¡£´Ë´ÎÊÂÎñ̻¶¶àÖØÎ£º¦£ºÐ¡ÎÒ˽¼ÒÐÅÏ¢×éºÏ£¨ÈçÈ«Ãû+³öÉúÈÕÆÚ£©¿É±»ÓÃÓÚÉí·Ý͵ÇÔ£¬·¸·¨·Ö×Ó¿ÉÄÜ¿ªÉèÚ²ÆÕË»§µ¼ÖÂÊܺ¦Õß¾¼ÃËðʧ»òÐÅÓÃÆÀ·ÖÊÜËð£»Ò½ÁƺͰü¹ÜÊý¾ÝÒò²»¿É»Ö¸´ÌØÕ÷£¨È粡ʷÎÞ·¨Ð޸ģ©£¬ºã¾ÃÃæÁÙ±»ÀÄÓÃΣº¦£»¹¥»÷Õß»¹¿ÉʹÓÃСÎÒ˽¼ÒÐÅϢʵÑé¾«×¼ÍøÂç´¹ÂÚ£¬Ã°³ä°ü¹Ü¹«Ë¾»ò¿µ½¡×¨¼ÒÓÕÆÊܺ¦Õßй¶¸ü¶àÃô¸ÐÐÅÏ¢¡£
https://cybernews.com/security/american-income-life-data-breach-claims/
3. ΢Èí½ÒÆÆXCSSET macOS¶ñÒâÈí¼þбäÖÖ
9ÔÂ25ÈÕ£¬Î¢ÈíÍþвÇ鱨ÖÐÐÄ¿ËÈÕÐû²¼±¨¸æ£¬Ö¸³öÔÚÓÐÏÞ¹¥»÷³¡¾°Öмì²âµ½XCSSET macOS¶ñÒâÈí¼þµÄбäÖÖ£¬¸Ã±äÖÖ¼¯³ÉÈý´ó½¹µãÉý¼¶£ºÔöÇ¿µÄä¯ÀÀÆ÷Êý¾Ý¶¨Î»ÄÜÁ¦¡¢¼ôÌù°åÐ®ÖÆÄ£¿éÓÅ»¯¼°Ë¢Ðµij¤ÆÚÐÔ»úÖÆ¡£×÷Ϊģ¿é»¯¶ñÒâÈí¼þ£¬XCSSET¼æ¾ßÐÅÏ¢ÇÔÈ¡Óë¼ÓÃÜÇ®±Ò͵ȡ¹¦Ð§£¬¿ÉÇÔÈ¡ÊÜѬȾװ±¸µÄÌõ¼Ç¡¢¼ÓÃÜÇ®±ÒÇ®°ü¼°ä¯ÀÀÆ÷ÀúÊ·µÈÃô¸ÐÊý¾Ý£¬ÆäÆæÒìÈö²¥·½·¨ÔÚÓÚͨ¹ýѬȾ¿ª·¢Õß³£ÓõÄXcodeÏîĿʵÏÖºáÏòÉøÍ¸£¬µ±ÏîÄ¿¹¹½¨Ê±×Ô¶¯Ö´ÐжñÒâ´úÂ룬ÒÀÀµ¿ª·¢Ö°Ô±¹²ÏíÏîÄ¿ÎļþµÄÐ×÷³¡¾°À©´óѬȾ¹æÄ£¡£Ð±äÖÖÔÚÊÖÒÕ²ãÃæ·ºÆðÏÔÖø½ø»¯£ºÆäÒ»£¬Í¨¹ýǶÈëÐ޸İ濪Դ¹¤¾ßHackBrowserData£¬ÊµÏÖ¶ÔFirefoxä¯ÀÀÆ÷Êý¾ÝµÄ¶¨Ïò½âÃÜÓëµ¼³ö£»Æä¶þ£¬¼ôÌù°åÐ®ÖÆ×é¼þ¸üÐÂÖ§³Öʶ±ð¼ÓÃÜÇ®±ÒµØµãµÄÕýÔò±í´ïʽģʽ£¬¼ì²âµ½Ïà¹ØµØµãʱ×Ô¶¯Ì滻Ϊ¹¥»÷ÕßÇ®°üµØµã£¬µ¼ÖÂÓû§ÉúÒâ×ʽ𱻽ØÁ÷£»ÆäÈý£¬³¤ÆÚÐÔ»úÖÆ½ÓÄÉË«ÖØÎ±×°Õ½ÂÔ¡£
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-xcsset-macos-malware-variant-targeting-xcode-devs/
4. СÐÄnpm"postmark-mcp"¶ñÒâ°üDZÔÚÓʼþÇÔÈ¡´úÂë
9ÔÂ25ÈÕ£¬Koi SecurityÑо¿Ö°Ô±¿ËÈÕÅû¶£¬npmƽ̨ÉÏÃûΪ"postmark-mcp"µÄ¶ñÒâÈí¼þ°üÔÚ1.0.16°æ±¾ÖÐÖ²ÈëÇÔÈ¡´úÂ룬¸Ã°üαװ³ÉGitHub¹Ù·½ÏîÄ¿µÄÕýµ±¶Ë¿Ú£¬¾15´Îµü´úºóÓÚ1.0.16°æÌí¼Ó¶ñÒâÐо¶£¬½«Óû§ËùÓеç×ÓÓʼþת·¢ÖÁ¹ØÁªÓòÃûgiftshop[.]club¡£¸Ã¶ñÒâ°üÔÚnpm±£´æÒ»ÖÜʱ´úÏÂÔØÁ¿´ï1500´Î£¬¿ÉÄÜÒÑÇÔÈ¡Êýǧ·â°üÀ¨ÃÜÂëÖØÖá¢Ë«ÒòËØÑéÖ¤Âë¡¢²ÆÎñÐÅÏ¢¼°¿Í»§ÏêÇéµÈÃô¸ÐÓʼþ£¬×é³ÉÑÏÖØÊý¾Ýй¶Σº¦¡£×÷Ϊ»ùÓÚÄ£×ÓÉÏÏÂÎÄÐÒ飨MCP£©µÄ·þÎñÆ÷£¬Postmark MCP±¾Ó¦Í¨¹ý½á¹¹»¯¡¢Ô¤½ç˵µÄÇå¾²½Ó¿ÚΪAIÖúÊÖÌṩÓʼþ·¢Ë͹¦Ð§¡£È»¶ø£¬´Ë´ÎÊÂÎñ̻¶³öMCPÇ徲ģ×ÓµÄÖÂÃüȱÏÝ£º¸ßȨÏÞÔËÐеķþÎñÆ÷ÔÚÒªº¦ÇéÐÎÖÐȱ·¦ÓÐÓüàÊÓÓëɳºÐ¸ôÀ룬µ¼ÖÂAIÖúÊÖ¿ÉÖ´ÐÐδ¹ýÂ˵ĶñÒâÏÂÁî¡£Koi SecurityÇ¿µ÷£¬ÕâÖÖ"ÎÞɳºÐ"¼Ü¹¹Ê¹ÈκÎÎó²î»òÉèÖùýʧ¶¼¿ÉÄÜÒý·¢ÔÖÄÑÐÔЧ¹û¡£¹¥»÷Õßͨ¹ýαÔìÓë¹Ù·½°ü¸ß¶ÈÒ»ÖµĴúÂëºÍÐÎòʵÑ鹩ӦÁ´¹¥»÷£¬1.0.15¼°Ö®Ç°°æ±¾¼á³ÖÇå½àÒÔ½¨ÉèÐÅÍУ¬1.0.16°æÍ»È»×¢ÈëÇÔÈ¡Âß¼¡£
https://www.bleepingcomputer.com/news/security/unofficial-postmark-mcp-npm-silently-stole-users-emails/
5. ˼¿Æ±Þ²ß¿Í»§ÐÞ²¹Á½¸öÕýÔÚ±»Ê¹ÓõÄÁãÈÕÎó²î
9ÔÂ25ÈÕ£¬Ë¼¿Æ¿ËÈÕÐû²¼½ôÆÈÇ徲ͨ¸æ£¬±Þ²ß¿Í»§Á¬Ã¦ÐÞ²¹Á½¸öÕýÔÚ±»¹¥»÷ÕßʹÓõÄÁãÈÕÎó²î£¨CVE-2025-20333ºÍCVE-2025-20362£©£¬ÕâÁ½¸öÎó²îÓ°ÏìÆä×Ô˳ӦÇå¾²×°±¸£¨ASA£©ºÍ·À»ðǽÍþв·ÀÓù£¨FTD£©Èí¼þ¡£ÆäÖУ¬CVE-2025-20333ÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂ룬¶øCVE-2025-20362Ôòʹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»»á¼ûÊÜÏÞURL¶Ëµã¡£Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÒÑ֤ʵ±£´æÕë¶ÔÕâЩÎó²îµÄ¹¥»÷ʵÑ飬²¢Ç¿ÁÒ½¨ÒéÓû§Éý¼¶ÖÁÐÞ¸´°æ±¾¡£´Ë´ÎÇå¾²¸üл¹Í¬Ê±ÐÞ²¹Á˵ÚÈý¸öÑÏÖØÎó²î£¨CVE-2025-20363£©£¬¸ÃÎó²îͬÑùÔÊÐíδ¾ÊÚȨµÄÔ¶³Ì¹¥»÷ÕßÔÚδ´ò²¹¶¡µÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂ롣˼¿ÆÌØÊâлл°Ä´óÀûÑÇ¡¢¼ÓÄôó¡¢Ó¢¹ú¼°ÃÀ¹úÍøÂçÇå¾²»ú¹¹ÐÖúÊÓ²ìÕâЩÁãÈÕ¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-firewall-zero-days-exploited-in-attacks/
6. ÎÖ¶ûÎÖ±±ÃÀ¹©Ó¦ÉÌÔâÀÕË÷¹¥»÷ÖÂ87ÍòÕË»§Êý¾Ýй¶
9ÔÂ25ÈÕ£¬ÎÖ¶ûÎÖ±±ÃÀ¹«Ë¾Åû¶£¬ÆäµÚÈý·½ÈËÁ¦×ÊÔ´Èí¼þ¹©Ó¦ÉÌMilj?dataÓÚ2025Äê8ÔÂ20ÈÕÔâÊÜÀÕË÷Èí¼þ×éÖ¯DataCarry¹¥»÷£¬µ¼ÖÂÖÁÉÙ25¼ÒÆóÒµ¼°200¸öÈðµäÊÐÕþ»ú¹¹µÄÔ±¹¤Êý¾Ýй¶¡£´Ë´Î¹¥»÷Ó°ÏìÁËÓÃÓÚ´¦Öóͷ£Ò½ÁÆÖ¤Êµ¡¢¹¤É˱¨¸æ¼°¿µ¸´ÊÂÒ˵ÄÖÎÀíϵͳ£¬Ð¹Â¶Êý¾ÝÉæ¼°87Íò¸öÕË»§£¬°üÀ¨µç×ÓÓʼþµØµã¡¢ÐÕÃû¡¢ÏÖʵµØµã¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢³öÉúÈÕÆÚ¼°ÐÔ±ðµÈÃô¸ÐÐÅÏ¢¡£¾ÝÎÖ¶ûÎÖÏòÂíÈøÖîÈûÖÝÉó²é×ܳ¤Ìá½»µÄ±¨¸æÏÔʾ£¬Ö»¹ÜÎÖ¶ûÎÖ×ÔÉíϵͳδÊÜË𺦣¬µ«Í¨¹ýMilj?data´¦Öóͷ£µÄÔ±¹¤ÐÕÃûºÍÉç»á°ü¹ÜºÅÂëµÈСÎÒ˽¼ÒÐÅÏ¢ÒÑÔâй¶¡£ÊÂÎñʱ¼äÏßÏÔʾ£¬Milj?dataÓÚ8ÔÂ23ÈÕÊ״μì²âµ½ÀÕË÷Èí¼þ¹¥»÷£¬9ÔÂ2ÈÕÈ·ÈÏÊý¾Ýй¶²¢Í¨ÖªÎÖ¶ûÎÖ¼¯ÍÅ£¬ËæºóÏòÊÜÓ°ÏìСÎÒ˽¼Ò·¢ËÍ֪ͨÐÅ£¬²¢Ìṩ18¸öÔµÄAllstate Identity Protection Pro+Ãâ·Ñ¶©ÔÄ·þÎñ£¬°üÀ¨ÐÅÓÃ¼à¿Ø¹¦Ð§¡£ÀÕË÷Èí¼þ×éÖ¯DataCarryÒÑÔÚÆäTor×ßÂ©ÍøÕ¾Ðû²¼±»µÁÊý¾Ý¡£
https://securityaffairs.com/182577/data-breach/volvo-north-america-disclosed-a-data-breach-following-a-ransomware-attack-on-it-provider-miljodata.html


¾©¹«Íø°²±¸11010802024551ºÅ