ÐÂÐËShinySp1d3rÀÕË÷Èí¼þÊÖÒÕÔËÓªÕ½ÂÔÆØ¹â
Ðû²¼Ê±¼ä 2025-11-211. ÐÂÐËShinySp1d3rÀÕË÷Èí¼þÊÖÒÕÔËÓªÕ½ÂÔÆØ¹â
11ÔÂ19ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±Åû¶ÁËÃûΪ"ShinySp1d3r"µÄÐÂÐÍÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Æ½Ì¨¿ª·¢Ï¸½Ú¡£¸Ãƽ̨ÓÉÓëShinyHunters¡¢Scattered Spider¼°Lapsus$×éÖ¯¹ØÁªµÄÍþвÐÐΪÕß½¨É裬±ê¼Ç×ÅÕâЩÍÅ»ï´ÓʹÓõÚÈý·½¼ÓÃÜÆ÷תÏò×ÔÖ÷¿ª·¢¡£¿ª·¢°æ±¾ÏÔʾ£¬ShinySp1d3r½ÓÄÉÈ«×ÔÖ÷Ñз¢¼Ü¹¹£¬Î´¸´ÓÃLockBit»òBabukµÈÒÑÖª´úÂë¿â£¬¾ß±¸¶àÏîÁ¢Ò칦Ч¡£ÊÖÒÕ²ãÃæ£¬¸ÃÀÕË÷Èí¼þʹÓÃChaCha20¼ÓÃÜËã·¨ÅäºÏRSA-2048±£»¤Ë½Ô¿£¬Ã¿¸ö¼ÓÃÜÎļþÌìÉúÆæÒìÀ©Õ¹Ãû²¢Í¨¹ýÊýѧ¹«Ê½¶¯Ì¬ÌìÉú¡£ÎļþÍ·ÒÔ"SPDR"¿ªÍ·¡¢"ENDS"×îºó£¬°üÀ¨ÎļþÃû¡¢¼ÓÃÜ˽Կ¼°ÔªÊý¾Ý¡£ÆäÈö²¥»úÖÆÖ§³Öͨ¹ýSCM·þÎñ¡¢WMIÀú³Ì½¨Éè¼°GPO¾ç±¾°²ÅÅʵÏÖºáÏòÉøÍ¸£¬²¢¾ß±¸ËÑË÷¿ª·ÅÍøÂç¹²ÏíÖ÷»ú¾ÙÐжþ´Î¼ÓÃܵÄÄÜÁ¦¡£·´ÆÊÎöÌØÕ÷°üÀ¨¹Ò¹³EtwEventWriteº¯Êý×è¶ÏÈÕÖ¾¼Í¼¡¢ÁýÕÖÄڴ滺³åÇø·Àȡ֤£¬ÒÔ¼°Í¨¹ýдÈëËæ»ú.tmpÎļþÌî³ä´ÅÅ̿ռä×è°Êý¾Ý»Ö¸´¡£
https://www.bleepingcomputer.com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters/
2. ¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾IGTÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
11ÔÂ20ÈÕ£¬¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾£¨IGT£©×÷ΪȫÇòÁìÏȵĶij¡¼°ÔÚÏ߯½Ì¨Êý×ÖÓÎÏ·¡¢ÌåÓý²©²ÊºÍ½ðÈڿƼ¼¹©Ó¦ÉÌ£¬¿ËÈÕ±»Óë¶íÂÞ˹¹ØÁªµÄ÷è÷ëÀÕË÷Èí¼þ×éÖ¯ÈÏÁì¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶²©¿ÍÐû²¼IGTÌõÄ¿£¬Éù³ÆÇÔÈ¡ÁË10GBÊý¾Ý£¬21,683¸öÎļþ£¬º¸Ç´ÓÀÏ»¢»ú¡¢²ÊƱϵͳµ½PlaySportsÌåÓý²©²Êƽ̨µÈ½¹µãÓªÒµÊý¾Ý¡£IGT²úÆ·ÆÕ±éÓ¦ÓÃÓÚÈ«Çò100¶à¸ö¹ú¼Ò£¬ÖðÈÕ·þÎñÊý°ÙÍòÍæ¼Ò£¬Æä½ðÈڿƼ¼²¿·Ö´æ´¢´ó×Ú¿Í»§Éí·ÝÐÅÏ¢£¬ÃæÁÙÉí·Ý͵ÇÔΣº¦¡£×èÖ¹±¨µÀÐû²¼£¬IGTδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£÷è÷ë×éÖ¯×Ô2021ÄêÔ˶¯ÒÔÀ´£¬2025ÄêÒѳÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯£¬ÒÑÍùÁù¸öÔ·¢¶¯³¬500Æð¹¥»÷£¬×Ô2023ÄêÆðÒÑÁгö991ÃûÊܺ¦Õߣ¬°üÀ¨×ÅÃûÆóÒµ¡¢Ò½ÁÆ»ú¹¹¼°Õþ¸®»ú¹¹¡£Æä½ÓÄÉÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©ÉÌҵģʽ£¬³£Ê¹ÓÃË«ÖØÀÕË÷Õ½ÂÔ£ºÏÈË÷Òª½âÃÜÊê½ð£¬ÔÙÍþвй¶Êý¾Ý¡£
https://cybernews.com/news/igt-digital-gaming-leader-qilin-ransomware-attack-casino-fintech-sports-betting/
3. ¶íÂÞ˹VSK°ü¹Ü¹«Ë¾Ôâ´ó¹æÄ£ÍøÂç¹¥»÷
11ÔÂ19ÈÕ£¬×÷Ϊ¶íÂÞ˹×î´ó×ۺϰü¹Ü¹«Ë¾Ö®Ò»£¬×ܲ¿Î»ÓÚĪ˹¿ÆµÄVSK 11ÔÂ13ÈÕ¹ûÕæÈ·ÈÏÔâÓö¡°´ó¹æÄ£ÍøÂç¹¥»÷¡±£¬ÏÖÔÚÆä¹ÙÍø¡¢Òƶ¯Ó¦Óü°Êý°ÙÍòÓû§ÒÀÀµµÄ·þÎñÒÑÒ»Á¬ÏÂÏßÒ»ÖÜ¡£×÷Ϊ·þÎñÔ¼3300ÍòСÎÒ˽¼Ò¿Í»§ºÍ50¶àÍò¼ÒÆóÒµµÄÐÐÒµ¾ÞÍ·£¬VSKÓªÒµº¸Ç¹¤ÒµÏÕ¡¢½»Í¨ÏÕ¡¢¿µ½¡ÏյȶàÁìÓò£¬´Ë´ÎÊÂÎñµ¼Ö¿ͻ§ÎÞ·¨¹ºÖóµÏÕ¡¢Ð޸ı£µ¥¡¢»ñÈ¡µ£±£º¯»òÔ¤Ô¼Ò½ÁÆ·þÎñ£¬²¿·ÖÒ½ÁÆ»ú¹¹ÒòÎÞ·¨ºËʵ°ü¹ÜÁýÕÖ¹æÄ£¾Ü¾ø·þÎñ£¬¹«Ë¾ÓʼþϵͳÒàÖÐÖ¹£¬±»ÆÈ½¨Òé¿Í»§Í¨¹ýƽÐÅÌá½»×Éѯ¡£Ö»¹ÜVSKÇ¿µ÷¡°½öIT»ù´¡ÉèÊ©ÊÜÓ°Ï죬¿Í»§¼°ÏàÖúͬ°éÊý¾ÝÇå¾²ÎÞÓÝ¡±£¬µ«ÎÚ¿ËÀ¼ºÚ¿ÍÏà¹ØTelegramƵµÀÒÑÐû²¼¾Ý³ÆÐ¹Â¶µÄÐÅÏ¢¼°±¸·ÝÎļþ½ØÍ¼£¬ÕæÊµÐÔ´ýºËʵ¡£¹«Ë¾Í¬Ê±ÖÒÑÔ£¬ÆäÆóÒµÓòÃûÔâÐ®ÖÆ£¬»á¼ûÕß»á±»ÖØ¶¨ÏòÖÁÐéαTelegramƵµÀ¡£ÏÖÔÚ¹¥»÷ÕßÉí·Ý¼°ÄîͷδÃ÷£¬¶íÂÞË¹ÍøÂçÇ徲ר¼ÒÍÆ²âΪÀÕË÷Èí¼þ¹¥»÷¡£
https://therecord.media/russia-vsk-cyberattack-outages
4. Òâ´óÀûFS¼¯ÍÅÒòAlmavivaÔâÈëÇÖÖÂ2.3TBÊý¾Ýй¶
11ÔÂ20ÈÕ£¬Òâ´óÀû¹ú¼ÒÌú·ÔËÓªÉÌFS Italiane¼¯ÍÅÒòIT·þÎñÌṩÉÌAlmavivaÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂ2.3TBÃô¸ÐÊý¾Ýй¶ÖÁ°µÍø¡£ºÚ¿ÍÉù³ÆÇÔÈ¡ÄÚÈݺ¸ÇÉñÃØÎļþ¡¢ÊÖÒÕÎĵµ¡¢¹«¹²ÊµÌåÌõÔ¼¡¢ÈËÁ¦×ÊÔ´µµ°¸¡¢»á¼ÆÊý¾Ý¼°¶à¼ÒFS¼¯ÍŹ«Ë¾µÄÍêÕûÊý¾Ý¼¯£¬ÆäÖаüÀ¨2025ÄêµÚÈý¼¾¶ÈµÄ×îÐÂÎļþ¡£D3LabÍøÂçÍþвÇ鱨Ö÷¹Ü°²µÂÁÒÑÇ¡¤µÂÀ¸ÇµÙÃ÷ȷɨ³ý¸ÃÊý¾ÝΪ2022ÄêHiveÀÕË÷Èí¼þ¹¥»÷½ÓÄÉʹÓõĿÉÄÜÐÔ£¬²¢Ö¸³öת´¢Îļþ°´²¿·Ö/¹«Ë¾×éÖ¯µÄѹËõ´æµµ½á¹¹Óë2024-2025Äê»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯¼°Êý¾Ý¾¼ÍÈË×÷°¸ÊÖ·¨¸ß¶ÈÒ»Ö¡£Ö»¹ÜAlmavivaÓëFS¼¯Ížùδ»ØÓ¦Ã½Ìå³õÆÚÎÊѯ£¬µ«AlmavivaºóÐøÍ¨¹ýÍâµØÃ½ÌåÉùÃ÷֤ʵÊÂÎñ£ºÆäÇå¾²¼à¿Ø²¿·Ö½üÆÚ·¢Ã÷²¢¸ôÀëÁËÒ»ÆðÓ°Ï칫˾ϵͳµÄÍøÂç¹¥»÷£¬µ¼Ö²¿·ÖÊý¾Ý±»µÁ¡£¸Ã¹«Ë¾ÒÑÆô¶¯Çå¾²Ó¦¶Ô³ÌÐò£¬È·±£Òªº¦·þÎñÔËÐУ¬²¢Í¨Öª¾¯·½¡¢¹ú¼ÒÍøÂçÇå¾²»ú¹¹¼°Êý¾Ý±£»¤»ú¹¹£¬ÏÖÔÚÊÓ²ìÈÔÔÚÕþ¸®»ú¹¹ÐÖúϾÙÐУ¬ÔÊÐíÒÔ͸Ã÷·½·¨¸üÐÂÏ£Íû¡£ÏÖÔÚ£¬Êý¾Ýй¶ÊÇ·ñ°üÀ¨ÂÿÍÐÅÏ¢»òÓ°ÏìFS¼¯ÍÅÒÔÍâµÄÆäËû¿Í»§Éв»Ã÷È·¡£
https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-23tb-data-from-italian-rail-group-almavia/
5. PhotocallµÁ°æÆ½Ì¨Ôâ¹Ø±Õ£¬³¬2600ÍòÓû§ÊÜÓ°Ïì
11ÔÂ20ÈÕ£¬ÓµÓг¬2600ÍòÓû§µÄµÁ°æµçÊÓÁ÷ýÌåÆ½Ì¨PhotocallÔÚ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©ÓëDAZNÍŽáÊÓ²ìºóÒÑ×èÖ¹ÔËÓª¡£¸Ãƽ̨δ¾ÊÚȨÌṩÀ´×Ô60¸ö¹ú¼ÒµÄ1127¸öµçÊÓÆµµÀ»á¼û·þÎñ£¬º¸ÇÌåÓýÈüÊÂÖ±²¥¡¢Òâ¼×ÁªÈü¡¢NFL/NHLÈüʼ°»Ê¼ÒÂíµÂÀï¡¢°ÍÈûÂÞÄǵȾãÀÖ²¿ÆµµÀ£¬Óû§ÂþÑÜÒÔÎ÷°àÑÀ£¨30%£©¡¢Ä«Î÷¸ç£¨13%£©ÎªÖ÷£¬µÂ¹ú¡¢Òâ´óÀû¡¢ÃÀ¹ú¸÷Õ¼6%¡£Ö»¹Üδֱ½ÓÌṩDAZNƵµÀ£¬µ«Æ½Ì¨ÖØÐ·ַ¢ÁËÆäÏàÖúͬ°éÄÚÈÝ£¨ÈçMotoGPºÍF1ÈüÊ£©£¬×é³ÉÇÖȨ¡£´Ë´Î¹Ø±ÕÔ´ÓÚÅ·ÖÞÐ̾¯×é֯е÷µÄ¿ç¹úÖ´·¨Ðж¯£¬Ðж¯Öвé·â69¸ö²»·¨ÍøÕ¾£¨Äê»á¼ûÁ¿³¬1180Íò£©£¬25¸ö²»·¨IPTV·þÎñ±»Òƽ»¼ÓÃÜÇ®±ÒÌṩÉ̲é·â£¬²é»ñ¼ÛÖµ5500ÍòÃÀÔª¼ÓÃÜÇ®±Ò£¬²¢Æô¶¯44ÏîÐÂÊӲ졣PhotocallÓòÃûÒÑ×ªÒÆÖÁACE²¢Öض¨ÏòÖÁÕýµ±Ô¢Ä¿ÍøÕ¾£¬ÔËÓªÉÌÔÞ³É×èÖ¹ÔËÓª¡£
https://www.bleepingcomputer.com/news/security/tv-streaming-piracy-service-photocall-with-26m-yearly-visits-shut-down/
6. SalesforceÓëGainsightÓ¦¶ÔÊý¾ÝÇÔÈ¡£º×÷·ÏÁîÅÆÒÆ³ýÓ¦ÓÃ
11ÔÂ20ÈÕ£¬SalesforceÔÚÊÓ²ì¿Í»§Êý¾ÝÇÔÈ¡¹¥»÷ʱ£¬·¢Ã÷Òì³£Ô˶¯Ô´ÓÚGainsightÐû²¼µÄÓ¦ÓóÌÐòÓëSalesforceµÄÍⲿÅþÁ¬£¬¶ø·Ç×ÔÉíCRMƽ̨Îó²î¡£¸Ã¹«Ë¾ÒÑ×÷·ÏËùÓÐÓë¸ÃÓ¦ÓóÌÐò¹ØÁªµÄ»á¼ûÁîÅÆºÍË¢ÐÂÁîÅÆ£¬²¢ÔÝʱ½«Æä´ÓAppExchangeÒÆ³ý£¬Í¬Ê±Í¨ÖªÊÜÓ°Ïì¿Í»§²¢Ìṩ×ÊÖú¡£´Ë´ÎÊÂÎñÓë2025Äê8ÔÂSalesloftÊý¾Ýй¶ģʽÏàËÆ£¬ÆäʱÀÕË÷×éÖ¯¡°Scattered Lapsus$ Hunters¡±Ê¹ÓÃÇÔÈ¡µÄOAuthÁîÅÆ£¬´Ó¿Í»§SalesforceʵÀýÖÐÇÔÈ¡ÁËÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬Ó°ÏìÔ¼760¼Ò¹«Ë¾£¬µ¼ÖÂ15ÒÚÌõ¼Í¼й¶£¬Éæ¼°Google¡¢Cloudflare¡¢Palo Alto NetworksµÈ×ÅÃûÆóÒµ¡£ShinyHunters×éÖ¯Éù³Æ£¬Í¨¹ýSalesloft DriftÎó²îÖÐÇÔÈ¡µÄÃÜÔ¿ÈëÇÖGainsightºó£¬½øÒ»²½»ñÈ¡ÁË285¸öSalesforceʵÀýµÄ»á¼ûȨÏÞ¡£Gainsight´ËǰÒÑ֤ʵ£¬¹¥»÷Õßͨ¹ýÓëSalesloft Drift¹ØÁªµÄ±»µÁOAuthÁîÅÆÈëÇÖ£¬Ð¹Â¶ÁËÆóÒµÁªÏµÐÅÏ¢¡£SalesforceÇ¿µ÷£¬ËùÓжñÒâÔ˶¯¾ùÓëÍⲿӦÓóÌÐòÅþÁ¬Óйأ¬¶ø·Çƽ̨×Ô¼ºÎó²î¡£
https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/


¾©¹«Íø°²±¸11010802024551ºÅ