÷è÷ëÀÕË÷Èí¼þ½è¡°ÖµçÂÉʦ¡±¼°¶à¹¤¾ßÇ¿»¯Êê½ðʩѹ
°ä²¼¹¦·ò 2025-06-231. ÷è÷ëÀÕË÷Èí¼þ½è¡°ÖµçÂÉʦ¡±¼°¶à¹¤¾ßÇ¿»¯Êê½ðʩѹ
6ÔÂ20ÈÕ£¬÷è÷ëÀÕË÷Èí¼þ·¸×ï·Ö×Ó½üÆÚÍÆ³öÐÂÓªÏúÕ½Êõ£¬Îª¹ØÁª¹«Ë¾Ìṩ¾«ÈñÂÉʦÍŶÓÒÔ¼Ó´óÊê½ð½»ÉæÑ¹Á¦¡£Cybereason×êÑÐÈËÔ±·¢ÏÖ£¬µØÏÂÍøÂç·¸×ïÂÛ̳°æÖ÷°ä²¼Ìû×Ó£¬Ðû³ÆÔÚ´ÓÊôÃæ°åÔö³¤¡°ÖµçÂÉʦ¡±°´Å¥£¬µ¥»÷¼´¿Éºô»½Ë¾·¨×¨¼Ò½øÈëÊê½ð½»ÉæÌ¸Ìì´°¿Ú£¬¾ÍÊý¾Ý˾·¨ÆÀ¹À¡¢Êܺ¦ÕßÎ¥·¨Î¥¹æÇé¿ö¼°²»Ö§¸¶Êê½ðµÄDZÔÚËãÕʳɱ¾µÈÎÊÌâÌṩרҵ½¨Ò飬ÂÉʦÉõÖÁ¿ÉÖ±½ÓȾָ½»Éæ²¢·î¸æÊܺ¦Õß²»Ö§¸¶Êê½ð½«Ãæ¶ÔµÄ¡°×î´óËðʧ¡±¡£´Ë±í£¬÷è÷ëÍø»¹Ðû³ÆÕ¼ÓÐÄÚ²¿¼ÇÕßÍŶӣ¬¿ÉÓë˾·¨²¿ÃźÏ×÷׫д²©¿ÍÎÄÕ½øÒ»²½Ê©Ñ¹¡£È»¶ø£¬×¨¼Ò¶Ô´Ë°µÊ¾ÒÉ»ó£¬TripwireÍøÂç·¸×ï×êÑÐÔ±Graham CluelyÒÔΪÕâ²»ÍâÊÇÓªÏúàåÍ·£¬Ö¼ÔÚÎüÒý¸ü¶àͬÃËÕß¡¢Ìá¸ßÀÕË÷Èí¼þ¹¥»÷³É¹¦Âʲ¢ÈÃÊܺ¦ÕßÏàÐÅÆä¸ÉÁ·Ë®Æ½¡£¾ÝCybereason³Æ£¬÷è÷뻹ΪͬÃËÃæ°åÔö³¤ÁË1PB´æ´¢¿Õ¼ä¡¢µç×ÓÓʼþºÍµç»°À¬»øÓʼþÖ°ÄÜ¡¢ÍøÂç´«²¼¼°ÌáÒéDDoS¹¥»÷µÄÑ¡ÏîµÈй¤¾ß¡£Ëæ×ÅÀÏÅÆÀÕË÷Èí¼þ×éÖ¯ÈçLockBit¡¢ALPHVµÈÒò¸÷ÀàÔÒòµ¹Ï£¬÷è÷ëÕýÖð²½³ÉΪ×îÖØÒªµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯Ö®Ò»¡£¸Ã×éÖ¯×Ô2022ÄêÆð¾ÍÒÑ´æÔÚ£¬²¢Í¨¹ý¸ßµ÷¹¥»÷Öð²½³ÉÁ¢ÃûÓþ¡£
https://www.theregister.com/2025/06/20/qilin_ransomware_top_dogs_treat/
2. CoinMarketCapÔ⹩¸øÁ´¹¥»÷£º¶ñÒâ¾ç±¾ÇÔÈ¡¼ÓÃÜÇ®±Ò
6ÔÂ22ÈÕ£¬¼ÓÃÜÇ®±Ò¼ÛÖµ¸ú×ÙÍøÕ¾CoinMarketCapÔâ·êÍøÕ¾¹©¸øÁ´¹¥»÷£¬ÒÔÖÁ½Ó¼ûÕßÃæ¶Ô¼ÓÃÜÇ®±Ò±»µÁ·çÏÕ¡£1ÔÂ20ÈÕÍí£¬ÍøÕ¾·Ã¿Í¿´µ½ÒªÇóÏνÓÇ®°üµÄWeb3µ¯´°£¬ÏνӺó¶ñÒâ¾ç±¾ÇÔÈ¡Æä¼ÓÃÜÇ®±Ò¡£¸Ã¹«Ë¾ºóÐøÖ¤Êµ£¬ÍþвÐÐΪÕßÀûÓÃÍøÕ¾Ö÷Ò³¡°Í¿Ñ»¡±Í¼Ïñ·ì϶עÈë¶ñÒâJavaScript¡£°²È«ÍŶӷ¢ÏÖ£¬¸ÃͿѻͼÏñÔ̺¬µÄÁ´½Óͨ¹ýAPIŲÓô¥·¢¶ñÒâ´úÂ룬µ¼ÖÂÓû§½Ó¼ûÖ÷ҳʱ³öÏÖÒâ±íµ¯³ö´°¿Ú¡£·¢ÏÖÎÊÌâºó£¬CoinMarketCapµ±¼´²ÉÈ¡Ðж¯£¬É¾³ýÎÊÌâÄÚÈÝ¡¢ÕÒ³öµ××ÓÔÒò²¢²ÉÈ¡´ëÊ©¸ôÀ뻺ºÍ½âÎÊÌ⣬ĿǰËùÓÐϵͳÒÑÈ«ÃæÔËÐУ¬ÍøÕ¾¶ÔÓû§°²È«¿¿µÃס¡£ÍøÂ簲ȫ¹«Ë¾c/sideÚ¹ÊÍ£¬¹¥»÷ÕßÅú¸ÄÁËÍøÕ¾ÓÃÓÚ¼ìË÷ͿѻͼƬ²¢ÔÚÖ÷Ò³ÏÔʾµÄAPI£¬´Û¸ÄµÄJSON¸ºÔØÔ̺¬¶ñÒâ¾ç±¾±êÇ©£¬´Ó±í²¿ÍøÕ¾ÏòCoinMarketCap×¢ÈëÇ®°ü¿÷Ëð¾ç±¾£¬Ò³Ãæ½Ó¼ûʱ¾ç±¾Ö´ÐУ¬µ¯³öαÔìµÄÇ®°üÏνӵ¯´°£¬ÏÖʵΪǮ°ü¿÷ËðÆ÷£¬Ö¼ÔÚÇÔÈ¡ÒÑÏνÓÇ®°ü×ʲú¡£Õâ´ÎΪ¹©¸øÁ´¹¥»÷£¬ÀûÓÃÁËÆ½Ì¨µÄ¿ÉÐÅÔªËØ£¬ÄÑÒÔ±»·¢ÏÖ¡£ÍþвÐÐΪÕßReyй©£¬¹¥»÷ÕßÔÚTelegramƵ··ÖÏíºÄË®Æ÷Ãæ°å½ØÍ¼£¬Õâ´Î¹¥»÷µ¼ÖÂ110ÃûÊܺ¦Õß±»µÁÈ¡43,266ÃÀÔª¡£
https://www.bleepingcomputer.com/news/security/coinmarketcap-briefly-hacked-to-drain-crypto-wallets-via-fake-web3-popup/
3. Å£½òÊÐÒé»áÔâ·êÊý¾Ýй¶£¬Ð¹Â¶Á˶þÊ®ÄêµÄÊý¾Ý
6ÔÂ22ÈÕ£¬Å£½òÊÐÒé»á½üÈÕ·¢³öÖҸ棬³ÆÔâ·êÊý¾Ýй¶ÊÂÎñ£¬¹¥»÷Õß´Ó¾ÉϵͳÖлñÈ¡ÁËÓ×ÎÒÉí·ÝÐÅÏ¢¡£Õâ´ÎÊÂÎñ»¹µ¼ÖÂICT·þÎñÖжϣ¬Ö»¹Ü´ó²¿ÃÅÊÜÓ°ÏìϵͳÒѸ´Ô£¬µ«Ôü×Ò»ýѹ¹¤×÷¿ÉÄÜÈÔ»áÔì³ÉÑÓÎó¡£Å£½òÊÐÒé»á×÷ΪӢ¹úÅ£½òÕÆ¹ÜÖÎÀíס·¿¡¢¹æ»®¡¢À¬»øÍøÂçµÈ³ÁÒª¹«¹²·þÎñµÄ´¦Ëùµ±¾Ö»ú¹¹£¬·þÎñÓÚÔ¼155,000Ãû¾ÓÃñ£¬ÇÒÒòÅ£½ò´óѧ¡¢ÓÎÀÀÒµºÍ×êÑлú¹¹µÄ¹ú¼Ê³ÛÃû¶È£¬ÆäÓ°ÏìÁ¦½øÒ»²½À©´ó¡£¾Ý¸Ã»ú¹¹ÍøÕ¾ÉêÃ÷£¬¹¥»÷Õßδ¾ÊÚȨ½Ó¼ûÁË´æ´¢Ó×ÎÒÐÅÏ¢µÄϵͳºÍÊý¾Ý¿â£¬³õ´ëÊ©²éÏÔʾ£¬ÊÜÓ°ÏìµÄϵͳÔ̺¬2001ÄêÖÁ2022ÄêÆÚ¼äǰÈκÍÏÖÈÎÀíÊ»á¹ÙÔ±µÄÐÅÏ¢¡£ÉêÃ÷ÖÐÌáµ½£¬¹¥»÷Õß¿ÉÄܽӼûÒÅÁôϵͳÉϵÄһЩº¹ÇàÊý¾Ý£¬¿ÉÄÜÉæ¼°ÔÚÅ£½òÊÐÒé»áÖÎÀíÑ¡¾ÙÖй¤×÷µÄÈËÔ±£¬Ô̺¬Í¶Æ¹Ø¾¹¤×÷ÈËÔ±ºÍ¼ÆÆ±Ô±µÄÓ×ÎÒÐÅÏ¢¡£²»Í⣬ÉêÃ÷Ò²Ö¸³ö£¬Ã»ÓÐÖ¤¾ÝÅúעй¶µÄÊý¾ÝÒѱ»½øÒ»²½´«²¼£¬ÇÒδÌá¼°¹«ÃñÊý¾ÝÔ⵽й¶¡£Å£½òÊÐÒé»á°µÊ¾£¬¶Ô¸ÃÊÂÎñµÄµ÷²éÈÔÔÚ½øÐÐÖУ¬ÉÐδ·¢ÏÖ´ó¹æÄ£Êý¾ÝÌáÈ¡µÄ¼£Ïó¡£Í¬Ê±£¬¸Ã»ú¹¹ÒÑÆðÍ·µ¥¶À֪ͨȷÈÏÊܵ½Ó°ÏìµÄÈË£¬ÌṩÊÂÎñÏêÇé¡¢Ö§³Ö×ÊÔ´£¬²¢³Ðŵ¼ÓÇ¿°²È«´ëÊ©ÒÔÔ¤·À½«À´Î¥¹æÐÐΪ¡£´Ë±í£¬Óйص±²¿ÃÅÃźͷ¨ÂÉ»ú¹¹Ò²ÒÑÊÕµ½ÏàӦ֪ͨ¡£
https://www.bleepingcomputer.com/news/security/oxford-city-council-suffers-breach-exposing-two-decades-of-data/
4. WordPress Motors·ì϶ÔâÀûÓ㬵¼ÖÂÖÎÀíÔ¹ØË»§±»½Ù³Ö
6ÔÂ21ÈÕ£¬ºÚ¿ÍÕýÀûÓÃWordPressÖ÷Ìâ¡°Motors¡±ÖбàºÅΪCVE-2025-4322µÄÑϳÁȨÏÞÌáÉý·ì϶½Ù³ÖÖÎÀíÔ¹ØÊ»§²¢½ÚÔìÖ¸±êÍøÕ¾¡£´Ë·ì϶ÓÉWordfence·¢ÏÖ²¢ÓÚÉÏÔÂÖÒ¸æÆäÑϳÁÐÔ£¬¶½´ÙÓû§Éý¼¶¡£¡°Motors¡±ÓÉStylemixThemes¿ª·¢£¬ÔÚÆû³µÓйØÍøÕ¾ÖйãÊÜÓ½Ó£¬ÏúÁ¿´ï22,460·ÝÇÒÕ¼ÓлîÔ¾Óû§ÉçÇø¡£¸Ã·ì϶ÓÚ2025Äê5ÔÂ2ÈÕ±»·¢ÏÖ£¬5ÔÂ19ÈÕÓÉWordfence³õ´Î»ã±¨£¬Ó°Ïì5.6.67֮ǰµÄËùÓа汾£¬Æä±¾ÔÔÚÓÚÃÜÂë¸üÐÂÆÚ¼ä²»ÕýÈ·µÄÓû§Éí·ÝÑéÖ¤£¬ÒÔÖÁδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÇáÒ׸ü¸ÄÖÎÀíÔ±ÃÜÂë¡£StylemixThemesÓÚ5ÔÂ14ÈÕ°ä²¼5.6.68°æ±¾ÒÔ½â¾ö¸Ã·ì϶£¬µ«ºÜ¶àÓû§Î´ÊµÊ±ÀûÓøüУ¬Ãæ¶Ô¸ü¸ß±»ÀûÓ÷çÏÕ¡£Wordfence֤ʵ¹¥»÷ʼÓÚ5ÔÂ20ÈÕ£¬½ØÖÁ6ÔÂ7ÈÕÒѹ۲쵽´ó¹æÄ£¹¥»÷£¬²¢×èÖ¹ÁË23,100´ÎÕë¶ÔÆä¿Í»§µÄ¹¥»÷³¢ÊÔ¡£¸Ã·ì϶´æÔÚÓÚ¡°µÇ¼ע²á¡±Óײ¿¼þµÄÃÜÂ븴ÔÖ°ÄÜÖУ¬¹¥»÷Õßͨ¹ý̽²âÌØ¶¨õè¾¶ÕÒµ½¸éÖÃÓײ¿¼þµÄURL£¬ÀûÓÃÌØÔìPOSTÒªÇóÖеÄÎÞЧUTF-8×Ö·ûµ¼Ö¹þÏ£±ÈÁ¦ÃýÎó³É¹¦£¬½ø¶ø³ÁÖÃÓû§ÃÜÂë¡£¹¥»÷ÕßÉèÖõÄÃÜÂë¶àÑù£¬Ò»µ©»ñµÃ½Ó¼ûȨÏÞ£¬±ã»áÒÔÖÎÀíÔ±Éí·ÝµÇ¼²¢´´½¨ÐÂÖÎÀíÔ¹ØÊ»§ÒÔʵÏÖÓÆ¾ÃÐÔ¡£´ËÀàÕË»§ºöÈ»³öÏÖÒÔ¼°ÏÖÓÐÖÎÀíÔ±±»Ëø¶¨ÊÇÊܵ½¹¥»÷µÄ¼£Ïó£¬Wordfence»¹ÁгöÁËÌáÒéÕâЩ¹¥»÷µÄIPµØÖ·£¬½¨ÒéWordPressÍøÕ¾ËùÓÐÕß½«ÕâЩµØÖ·ÁÐÈë×èÖ¹ÁÐ±í¡£
https://www.bleepingcomputer.com/news/security/wordpress-motors-theme-flaw-mass-exploited-to-hijack-admin-accounts/
5. AnubisÀÕË÷ÍŻォ°ÍÀèµÏÊ¿ÄáÀÖÔ°ÁÐΪÐÂÊܺ¦Õß
6ÔÂ20ÈÕ£¬³ôÃûÔ¶ÑïµÄAnubisÀÕË÷Èí¼þÍŻォ°ÍÀèµÏÊ¿ÄáÀÖÔ°ÁÐΪ×îÐÂÊܺ¦Õߣ¬Hackread.com֤ʵ¸Ã×éÖ¯ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾°ä²¼ÁËÕâ´Î¹¥»÷ÏêÇ飬³Æ±»µÁÊý¾Ýµµ°¸×ܼÆ64GB¡£Anubis×éÖ¯³ÆÆäΪ¡°µÏÊ¿ÄáÀÖÔ°º¹ÇàÉÏ×î´óµÄÊý¾Ýй¶ÊÂÎñ¡±£¬³Æ39000·ÝÓëÀÖÔ°½¨ÉèºÍ·Ð»ÓйصÄÎļþ±»µÁ£¬ÕâЩÊý¾ÝÊÇÔÚÉæ¼°µÏÊ¿ÄáÀÖÔ°Ò»¼ÒºÏ×÷¹«Ë¾µÄÊý¾Ýй¶ÊÂÎñÖлñÈ¡µÄ¡£Îª×ô֤˵·¨£¬ÔËÓªḚ́䷢½«ÔÚ½«À´ÎåÓ×ʱÄÚ°ä²¼²¿ÃÅÊý¾Ý£¬Ä¿Ç°ÆäÍøÕ¾ÒÑÉÏ´«Í¼Æ¬ºÍÊÓÆµ£¬¾Ý³ÆÕ¹Ê¾¹«Ô°ÄÚ¸÷¾°µã¾ßÌåͼֽ£¬µµ°¸Ô̺¬¡¶±ùÑ©ÆæÔµ¡·µÈ¶à²¿Ö÷ÌâÏîÖ÷ÕÅ´òË㣬»¹ÓÐÆäËûͼƬչʾÏÖ³¡¹¤³ÌÓйع¤×÷¡£¸Ã×éÖ¯Ö¸³öµÏÊ¿ÄáÀÖ԰ͨ³£ÓëÔ±¹¤Ç©Êð±£ÃܺÍ̸£¬²»Èݹ«¿ª·ÖÏíÄÚ²¿×ÊÁÏ£¬ÒÔÇ¿µ÷Õâ´ÎÊý¾Ýй¶µÄÑϳÁÐÔ¡£²»Í⣬¸ÃÌû×Óδ¾ßÌå×¢Ã÷ÎļþÖÐÊÇ·ñÔ̺¬¹Ë¿Í»ò·Ã¿ÍÐÅÏ¢£¬Ò²Î´Ìá¼°ÊÇ·ñÒÑÏò°ÍÀèµÏÊ¿ÄáÀÖÔ°·¢³öÊê½ðÒªÇ󣬸Ã×éÖ¯ÔøÔÚ¹Ù·½ÍÆÌØ£¨ÏÖΪX£©ÕË»§ÉÏ´µÅ£ÕâÆðÊÂÎñ¡£
https://hackread.com/anubis-ransomware-lists-disneyland-paris-new-victim/
6. Cloudflare»º½âÁË2025Äê5Ô´´¼Í¼µÄ7.3Tbps DDoS¹¥»÷
6ÔÂ20ÈÕ£¬Cloudflare°µÊ¾£¬ÆäÔÚ2025Äê5Ô³ɹ¦»º½âÁËһ·Õë¶ÔÍйܷþÎñÌṩÉ̵Ĵ´¼Í¼ɢ²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬¸Ã¹¥»÷·åÖµ¸ß´ï7.3 Tbps£¬½Ï֮ǰ¼Í¼Ôö³¤12%£¬ÔÚ45ÃëÄÚ´«ÊäÁË37.4 TBÊý¾Ý£¬Ï൱ÓÚÔ¼7500Ó×ʱ¸ßÇåÁ÷ýÌå»ò1250ÍòÕÅjpegÕÕÆ¬¡£Cloudflare×÷ΪרһÓÚDDoS»º½âµÄÍøÂç»ù´¡ÉèÊ©ºÍÍøÂ簲ȫ¾ÞÍ·£¬ÆäÖ¸±ê¿Í»§Ê¹ÓÃÁË¡°Magic Transit¡±ÍøÂç²ã±£»¤·þÎñ¡£Õâ´Î¹¥»÷Ô´×Ô161¸ö¹ú¶ÈµÄ122145¸öÔ´IPµØÖ·£¬ÖØÒªÎ»ÓÚ°ÍÎ÷¡¢Ô½ÄÏ¡¢Ì¨Íå¡¢Öйú¡¢Ó¡¶ÈÄáÎ÷ÑǺÍÎÚ¿ËÀ¼¡£¹¥»÷ͨ¹ý¶à¸öÖ¸±ê¶Ë¿Ú´«ËÍ¡°À¬»ø¡±Êý¾Ý°ü£¬¾ùÔÈÿÃë21925¸ö¶Ë¿Ú£¬·åÖµ´ïÿÃë34517¸ö¶Ë¿Ú£¬·ÖÉ¢Á÷Á¿µÄÕ½ÊõÖ¼ÔÚѹ¿å·À»ðǽ»òÈëÇÖ¼ì²âϵͳ¡£È»¶ø£¬CloudflareÀûÓÃÈβ¥ÍøÂ罫¹¥»÷Á÷Á¿·ÖÉ¢µ½293¸öµØÖ·µÄ477¸öÊý¾ÝÖÐÐÄ£¬Í¨¹ýÊµÊ±Ö¸ÎÆ¼ø±ðºÍÊý¾ÝÖÐÐÄÄÚ²¿Í¨Ñ¶µÈ¼¼ÊõʵÏÖʵʱµý±¨¹²ÏíºÍ×Ô¶¯¹æ¶¨±àÒ룬×îÖÕÔÚÎÞÐèÈËΪ¹ýÎʵÄÇé¿öÏ»º½âÁ˹¥»÷¡£Ö»¹Ü¹¥»÷ÖØÒªÀ´×ÔUDPºéË®¹¥»÷£¬Õ¼×ÜÁ÷Á¿µÄ99.996%£¬µ«»¹Éæ¼°QOTD·´Ë¼¡¢»ØÉù·´Éä¡¢NTPÀ©Ôö¡¢Mirai½©Ê¬ÍøÂçUDPºéË®¹¥»÷¡¢¶Ë¿ÚÓ³ÉäºéË®¡¢RIPv1À©ÔöµÈ¶à¸öÔØÌ壬ÿ¸ö¹¥»÷ÏòÁ¿¶¼ÀûÓÃÁËÒÅÁô»òÅäÖò»µ±µÄ·þÎñ¡£CloudflareÒѽ«Õâ´Î¹¥»÷ÖÐÓмÛÖµµÄIoCÄÉÈëÆäDDoS½©Ê¬ÍøÂçÍþвԴÖС£
https://www.bleepingcomputer.com/news/security/cloudflare-blocks-record-73-tbps-ddos-attack-against-hosting-provider/


¾©¹«Íø°²±¸11010802024551ºÅ