°Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±
°ä²¼¹¦·ò 2025-07-021. °Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±
7ÔÂ1ÈÕ£¬°Ä´óÀûÑÇ×î´óº½¿Õ¹«Ë¾°ÄÖÞº½¿Õ½üÈÕÅû¶£¬ÆäµÚÈý·½¿Í»§·þÎñƽ̨Ôâ·êÍøÂç¹¥»÷£¬µ¼ÖÂÔ¼600Íò¿Í»§µÄ·þÎñ¼Í¼Êý¾Ý±»µÁ£¬³ÉΪȫÇòº½¿ÕÒµÍøÂ簲ȫÍþвÉý¼¶µÄ×îа¸Àý¡£Õâ´Î¹¥»÷ʼÓÚÍþвÐÐΪÕßÈëÇְĺ½ºô½ÐÖÐÐÄʹÓõĵÚÈý·½Æ½Ì¨£¬¹¥»÷Õß»ñÈ¡ÁËÔ̺¬¿Í»§ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¼°³£´î¿Í»áÔ±ºÅµÈÃô¸ÐÐÅÏ¢£¬µ«Î´Éæ¼°ÐÅÓþ¿¨»ò²ÆÕþÊý¾Ý¡£°Äº½ÉêÃ÷³Æ£¬ÏµÍ³ÒÑÔÚ·¢ÏÖÒì³£ºóµ±¼´¸ôÀ룬²¢ÒÑ´«µÝ°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ¡¢ÐÅϢרԱ°ì¹«ÊÒ¼°Áª¹ú¾¯Ô±¾Ö·¢Õ¹µ÷²é¡£Õâ´ÎÊÂÎñ¶³ö³öº½¿ÕÒµÕý³ÉΪºÚ¿Í×éÖ¯¡°Scattered Spider¡±µÄ³ÁµãÖ¸±ê¡£¸Ã×éÖ¯ÒԸ߶ÈÐͬµÄÉç»á¹¤³Ì¹¥»÷ÎÅÃû£¬ÉÆÓÚͨ¹ý´¹µö¡¢SIM¿¨»¥»»¡¢¶à³É·ÖÈÏÖ¤£¨MFA£©ºäÕ¨¼°¼ÙÒâÔ±¹¤µÈ¼¿Á©ÇÔÈ¡Æóҵƾ֤¡£½üÆÚ£¬Æä¹¥»÷ÁìÓòÒÑ´ÓÁãÊÛ¡¢±£ÏÕÐÐÒ·©Õ¹ÖÁº½¿ÕÁìÓò£¬ÏÄÍþÒĺ½¿ÕºÍÎ÷½Ýº½¿ÕµÄÊý¾Ýй¶ÊÂÎñ¾ù±»ÒÉ»óÓëÆäÓйء£
https://www.bleepingcomputer.com/news/security/qantas-discloses-cyberattack-amid-scattered-spider-aviation-breaches/
2. ¹ú¼ÊÐÌÊ·¨ÔºÔâ·êеĸ´ÔÓÍøÂç¹¥»÷
7ÔÂ1ÈÕ£¬¹ú¼ÊÐÌÊ·¨Ôº£¨ICC£©ÖÜÒ»Åû¶£¬Æäϵͳ½üÈÕÔâ·êÐÂÒ»ÂÖ¡°¸´ÔÓÇÒÓÐÕë¶ÔÐÔ¡±µÄÍøÂç¹¥»÷£¬ÕâÊǸûú¹¹½üÄêÀ´µÚ¶þ´ÎÔâ·êÀàËÆÊÂÎñ¡£¾ÝICCÉêÃ÷£¬Õâ´Î¹¥»÷ÓÉÆäÄÚ²¿¼à²âϵͳ·¢ÏÖ£¬·¨ÔºÑ¸¿ìÆô¶¯Ô¤¾¯ºÍÏìÓ¦»úÔì½ÚÔìÊÂ̬£¬²¢ÒÑ·¢Õ¹È«ÔºÁìÓòµÄÓ°ÏìÆÀ¹À¼°·çÏÕ»º½â´ëÊ©¡£Ö»¹Ü·¨ÔºÇ¿µ÷ËùÓйؼüϵͳÈÔ°²È«ÔËÐУ¬µ«ÉÐδ°ä²¼¹¥»÷¾ßÌåÐÔÖÊ¡¢Ç±ÔÚÊý¾Ýй¶ÁìÓò»ò¹¥»÷ÕßÉí·Ý£¬½ö°µÊ¾½«Ïò¹«¼Ò¼°µÞÔ¼¹ú³ÖÐø´«µÝ½øÕ¹¡£2023Äê9Ô£¬¸Ã»ú¹¹ÔøÔâ·êһ·±»¶¨ÐÔΪ¡°ÍøÂç¼äµýÐж¯¡±µÄÈëÇÖÊÂÎñ¡£µ÷²éÏÔʾ£¬¹¥»÷Õßͨ¹ý¾«Ãܼ¼Êõ¼¿Á©ÉøÈëϵͳ£¬ÊÔͼÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬µ«Î´·¢ÏÖÊý¾Ýй¶»òÌØ¶¨¼äµý×éÖ¯²Î¼ÓµÄÖ¤¾Ý¡£×÷ÎªÕÆ¹ÜÉóÅÐÕ½Õù×ï¡¢ÖÖ×åÃð¾ø×ïµÈ×îÑϳÁ¹ú¼Ê×ï×´µÄ˾·¨»ú¹¹£¬ICCµÄÍøÂç·ÀÓùÄÜÁ¦Ö±½Ó¹ØºõÈ«ÇòÐÌÊÂ˾·¨ÏµÍ³²»±ä¡£Æäº£ÑÀ×ܲ¿ÏµÍ³´æ´¢×Å´óÁ¿»úÃܵ÷²éÊý¾Ý¡¢Ö¤ÈËÐÅÏ¢¼°¿ç¹úºÏ×÷Îļþ£¬Ò»µ©Ôâй¶¿ÉÄÜΣ¼°Ö¤È˰²È«¡¢×ÌÈÅÉóÅйý³Ì£¬ÉõÖÁÒý·¢µØÔµÕþÖÎÁ¬Ëø·´Ó³¡£
https://www.bleepingcomputer.com/news/security/international-criminal-court-hit-by-new-sophisticated-cyberattack/
3. Esse HealthÔâÍøÂç¹¥»÷Ö³¬26Íò»¼ÕßÊý¾Ýй¶
7ÔÂ1ÈÕ£¬ÃÀ¹úÃÜËÕÀïÖÝʥ·Ò×˹ÊÐ×î´ó¶ÀÁ¢Ò½Ê¦¼¯ÌåEsse Health½üÈÕÅû¶£¬Æäϵͳ½ñÄê4ÔÂÔâ·êÍøÂç¹¥»÷£¬µ¼Ö³¬¹ý26.3ÍòÃû»¼ÕßµÄÃô¸Ð½¡È«Êý¾Ý±»µÁ¡£×÷Ϊ´óʥ·Ò×˹µØÓòÕ¼ÓÐ50¼ÒÕïËùºÍ1200ÓàÃûÒ½»¤ÈËÔ±µÄÒ½ÁƾÞÍ·£¬¸Ã»ú¹¹ÔÚ4ÔÂ21ÈÕ³õ´Î¼ì²âµ½¹¥»÷ÕßÈëÇÔìäÖ÷Ì⻼ÕßÖÎÀíϵͳ¼°µç»°ÍøÂ磬Ôì³É¹Ø¼ü·þÎñÖжϳ¤´ïÊýÖÜ£¬Ö±ÖÁ6ÔÂ2ÈÕ²ÅÈ«Ãæ¸´ÔÏßÉÏ·þÎñ¡£¾ÝEsse HealthÒþÖÔ¹ÙJaime L. Bremerkamp°ä²¼µÄ֪ͨ£¬¹¥»÷Õ߳ɹ¦ÉøÈëÍøÂçºó£¬ÇÔÈ¡ÁËÔ̺¬»¼ÕßÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁƱ£ÏÕÐÅÏ¢¡¢Ò½ÁƼͼ±àºÅ¼°²¿ÃÅÕïÁƼͼµÄµç×ÓÎļþ£¬µ«ÅųýÁËÉç»á°²È«ºÅÂëй¶·çÏÕ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÆäÖ÷Ìâµç×Ó²¡Àúϵͳ£¨NextGen EHR£©Î´ÔÚÕâ´ÎÊÂÎñÖÐÔâÈëÇÖ¡£Õâ´ÎÊý¾Ýй¶¹æÄ£´´Ï¸õØÓòÒ½ÁÆÐÐÒµ½üÄêÖ®×ÊÜÓ°ÏìÈËÊýÏ൱ÓÚ±¾µØÃ¿10Ãû¾ÓÃñÖоÍÓÐ1ÈËÐÅϢ¶³ö¡£Ö»¹ÜEsse HealthδÃ÷È·¹¥»÷ÀàÐÍ£¬µ«ÍøÂ簲ȫר¼Ò·ÖÎöÖ¸³ö£¬³¤´ïÊýÔµÄϵͳ¸´ÔÖÜÆÚÓëµäÐÍÀÕË÷Èí¼þ¹¥»÷ÌØµã¸ß¶ÈÎǺϡ£Esse HealthÒÑΪÊÜÓ°ÏìÕßÌṩΪÆÚ°ëÄêµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ£¨Í¨¹ýIDXƽ̨£©£¬²¢½¨ÒéÇ×êǹØ×¢Òì³£Ò½ÁÆÕ˵¥¼°ÐÅÓþ»ã±¨¡£
https://www.bleepingcomputer.com/news/security/esse-health-says-recent-data-breach-affects-over-263-000-patients/
4. Kelly Benefits³ÆÊý¾Ýй¶ӰÏì55Íò¿Í»§
7ÔÂ1ÈÕ£¬ÃÀ¹úÂíÀïÀ¼Öݽ¡È«ÓëÈËÊÙ±£ÏÕ¹«Ë¾Kelly & Associates Insurance Group£¨Ã³Ò×Ãû³ÆÎªKelly Benefits£©½üÈÕÅû¶£¬ÆäITϵͳÓÚ2024Äê12ÔÂ12ÈÕÖÁ17ÈÕÆÚ¼äÔâδÊÚȨÈëÇÖ£¬×îÖÕÈ·Èϳ¬55ÍòÃûÓû§Ó×ÎÒÐÅϢй¶£¬½Ï×î³õ»ã±¨µÄ3.2ÍòÈ˼¤Ôö17±¶¡£Õâ´ÎÊÂÎñÉæ¼°46¼ÒºÏ×÷ʵÌ壬Ô̺¬½áºÏ½¡È«±£ÏÕ¡¢°²Ì©ÈËÊÙ£¨CVS Health£©¡¢CareFirst BlueCross BlueShieldµÈÒ½ÁÆÐÐÒµ¾ÞÍ·£¬Â¶³ö³ö±£ÏÕ·þÎñ¹©¸øÁ´µÄ´àÈõÐÔ¡£¾Ý¸Ã¹«Ë¾4ÔÂ9ÈÕ¸üеĵ÷²éÁ˾֣¬¹¥»÷ÕßÇÔÈ¡µÄÎļþÔ̺¬È«Ãû¡¢Éç»á°²È«ºÅÂ롢˰ºÅ¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁƼͼ¡¢±£ÏÕÐÅÏ¢¼°½ðÈÚÕË»§µÈÖ÷ÌâÃô¸ÐÊý¾Ý¡£ÕâÀàÐÅÏ¢µÄ×éºÏ¼«¾ß¼ÛÖµ£¬¿ÉʹÊܺ¦ÕßÃæ¶ÔÍøÂç´¹µö¡¢Éç»á¹¤³ÌڿƼ°¾«×¼½ðÈÚڲƵĶà³Á·çÏÕ¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬Êý¾Ýй¶¹æÄ£¾¹ýÂŴν¨¸Ä£¬Í¹ÏÔ¸´ÔÓ·þÎñÍøÂçÏÂÈ·¶¨Ó°ÏìÁìÓòµÄÄѶȡ£×÷ΪÌṩ¸£ÀûÕ÷ѯ¡¢Ð½³êÖÎÀí¡¢ÈËÁ¦×ÊԴϵͳ¼°ºÏ¹æÖ§³ÖµÄ×ÛºÏÐÔ·þÎñÉÌ£¬Kelly BenefitsµÄÈ«¹úÐÔÒµÎñÍøÂçµ¼ÖÂÊý¾Ý×·×ÙºÄʱÊýÔ¡£¸Ã¹«Ë¾Í¨¹ýIDXƽ̨ΪËùÓÐÊÜÓ°ÏìÕßÌṩ12¸öÔÂÃâ·ÑÐÅÓþ¼à¿ØÓëÉí·ÝµÁÓñ£»¤·þÎñ£¬²¢½¨ÒéÓû§²ÉÈ¡°²È«¶³½áÐÅÓþ»ã±¨¡¢ÆôÓÃÕË»§»î¶¯ÌáÐѵȷÀÓù´ëÊ©¡£
https://www.bleepingcomputer.com/news/security/kelly-benefits-says-2024-data-breach-impacts-550-000-customers/
5. ChromeÁãÈÕ·ì϶CVE-2025-6554Ôâ×Ô¶¯¹¥»÷
7ÔÂ1ÈÕ£¬¹È¸è½üÈÕ°ä²¼°²È«²¼¸æ£¬°ä·¢½¨¸´Chromeä¯ÀÀÆ÷ÖÐÒ»¸öÒѱ»¿í·ºÀûÓõÄÁãÈÕ·ì϶£¨CVE-2025-6554£©¡£¸Ã·ì϶´æÔÚÓÚChromeµÄV8 JavaScriptÓëWebAssemblyÒýÇæÖУ¬ÊôÓÚµäÐ͵ÄÀàÐÍ»ìºÏȱµã£¬ÔÊÐí¹¥»÷Õßͨ¹ý¾«ÐÄ»ú¹ØµÄ¶ñÒâÍøÒ³Ö´ÐÐËÁÒâ´úÂ룬Òý·¢·¨Ê½±ÀÀ£»òÊý¾ÝÇÔÈ¡¡£´ËÀà·ì϶µÄÁãÈÕ¸öÐÔÓÈΪΣÏÕ£¬¹¥»÷ÕßÍùÍùÔÚ²¹¶¡°ä²¼Ç°¾ÍÒÑ·¢Æð¾«×¼¹¥»÷£¬Óû§½öÐè½Ó¼û¶ñÒâÍøÕ¾¼´¿ÉÄܱ»Ö²Èë¼äµýÈí¼þ»òÀÕË÷·¨Ê½¡£¹È¸èÍþв·ÖÎöÓ××飨TAG£©×êÑÐÔ±Cl¨¦ment LecigneÓÚ6ÔÂ25ÈÕ³õ´Î¼à²âµ½Òì³£»î¶¯£¬°µÊ¾¸Ã·ì϶¿ÉÄܱ»ÓÃÓÚ¹ú¶È¼¶ÍøÂç¼äµýÐж¯¡£Ö»¹Ü¹È¸èδ°ä²¼·ì϶ÀûÓÃϸ½Ú£¬µ«ÈÏ¿ÉÆäÒѱ»¡°¿í·ºÀûÓᱡ£Õâ´Î½¨¸´Í¨¹ýÍÆËͲ»±ä°æÍ¨Â·¸üÐÂʵÏÖ£¬WindowsÓû§ÐèÉý¼¶ÖÁ138.0.7204.96/97£¬macOSÓû§¸üÐÂÖÁ138.0.7204.92/93£¬LinuxÓû§Í¬²½ÖÁ138.0.7204.96°æ±¾¡£ÆóÒµIT²¿ÃÅÐè³ö¸ñ¹Ø×¢Öն˺ϹæÐÔÖÎÀí£¬Ô¤·ÀÒò°æ±¾Öͺóµ¼ÖÂÊý¾Ýй¶¡£
https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html
6. ÈðÊ¿·ÇͶ»ú×éÖ¯RadixÔâÀÕË÷Èí¼þ¹¥»÷
7ÔÂ1ÈÕ£¬ÈðÊ¿ËÕÀèÊÀ·ÇͶ»ú½¡È«»ù½ð»áRadix½üÆÚÔâ·êÑϳÁÀÕË÷Èí¼þ¹¥»÷£¬ÃûΪSarcomaµÄºÚ¿Í×éÖ¯ÒÑÔÚÆä°µÍøÆ½Ì¨¹«¿ª1.3TBÇÔÈ¡Êý¾Ý£¬Òý·¢ÈðÊ¿Áª¹ú»ú¹¹Êý¾Ý°²È«¾¯±¨¡£Õâ´ÎÊÂÎñ¶³öÁ˷ǵ±¾Ö×éÖ¯×÷ΪµÚÈý·½·þÎñÉ̵ÄÍøÂ簲ȫÓÄ΢»·½Ú£¬Æä¿Í»§º¸Ç¶à¸öÁª¹ú²¿ÃÅ£¬Ö»¹ÜÈðÊ¿¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©Ç¿µ÷Áª¹úÖ÷ÌâÐÐÕþϵͳδ±»Í»ÆÆ£¬µ«±íйÊý¾Ý¿ÉÄÜÔ̺¬¹«Ãñ½¡È«ÐÅÏ¢¡¢²¿ÃźÏ×÷¼Í¼µÈÃô¸ÐÄÚÈÝ¡£RadixϵͳÓÚ2025Äê6ÔÂ16ÈÕÔâÈëÇÖ£¬¹¥»÷Õßѡȡ˫³ÁÀÕË÷Õ½Êõ£ºÏÈÇÔÈ¡Êý¾Ý£¬ÔÙ¼ÓÃÜϵͳË÷ÒªÊê½ð¡£Òò»ú¹¹»Ø¾øÖ§¸¶£¬ºÚ¿ÍÓÚ6ÔÂ29ÈÕÆô¶¯Êý¾ÝÇãµ¹£¬Ä¿Ç°Éв»Ã÷ÏÔй¶ÎļþÊÇ·ñÔ̺¬¼ÓÃÜÃÜÔ¿»òÄÚ²¿Í¨Ñ¶¼Í¼¡£RadixËäÐû³Æ¡°ÎÞ¼£ÏóÅú×¢ºÏ×÷ͬ°éÃô¸ÐÊý¾ÝÊÜÓ°Ï족£¬µ«Æä·þÎñÁìÓò¸²¸Ç½¡È«½ÌÓý¡¢Õþ²ßÍÆ¹ãµÈÁìÓò£¬Ç±ÔÚй¶Êý¾Ý»òÉæ¼°¿ç²¿ÃÅÏîĿϸ½Ú¡£µ±Ç°£¬1.3TB±íйÊý¾ÝµÄÕæÊµÐÔÓëÆëÈ«ÐÔÉÐδµÃµ½RadixÈ·ÈÏ£¬µ«Sarcoma×éÖ¯ÒѰ䲼²¿ÃÅÎļþĿ¼½ØÍ¼£¬Ô̺¬±ê×¢¡°Áª¹úÎÀÉú²¿¡±¡¢¡°Éç±£»ù½ð¡±µÈ×ÖÑùµÄÎļþ¼Ð¡£
https://cybernews.com/security/radix-cyberattack-exposes-swiss-federal-data/


¾©¹«Íø°²±¸11010802024551ºÅ