NASCARÈ·ÈÏÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶

°ä²¼¹¦·ò 2025-07-29

1. NASCARÈ·ÈÏÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶


7ÔÂ26ÈÕ£¬×÷Ϊһ¸ö³ÉÁ¢ÓÚ1948ÄêµÄ»ú¹¹£¬ÃÀ¹úÈ«¹úÈü³µÐ­»á£¨NASCAR£©Ã¿ÄêÔÚÃÀ¹ú½øÐг¬¹ý1,500³¡½ÇÖð£¬ÊÇÈ«Çò³ÛÃûµÄÆû³µÈüÊÂÖÎÀí»ú¹¹¡£2025Äê3ÔÂ31ÈÕÖÁ4ÔÂ3ÈÕÆÚ¼ä£¬NASCARÔâ·êÁËÒ»´ÎÑϳÁµÄÍøÂç¹¥»÷£¬µ¼Ö²¿ÃÅÎļþ±»Î´¾­ÊÚȨµÄ¹¥»÷Õß»ñÈ¡¡£4ÔÂ3ÈÕ£¬NASCARµÄITÍŶӷ¢ÏÖÁËÕâ´ÎÈëÇÖ£¬²¢Ëæ¼´·¢Õ¹µ÷²é£¬Í¬Ê±Í¨ÖªÁË·¨Âɲ¿ÃŲ¢ÀñƸÁËÒ»¼ÒÍøÂ簲ȫ¹«Ë¾Ð­Öú·ÖÎö¡£µ÷²éÁ˾ÖÏÔʾ£¬¹¥»÷Õ߳ɹ¦ÇÔÈ¡ÁË´æ´¢ÔÚ¹«Ë¾ÍøÂçÖеÄijЩÎļþ¡£Ö±µ½6ÔÂÏÂÑ®£¬NASCAR²ÅÈ·ÈÏÕâЩÎļþÖÐÔ̺¬Óû§µÄÓ×ÎÒÃô¸ÐÐÅÏ¢£¬ÓÈÆäÊÇÉç»á±£ÏÕºÅÂ롣Ȼ¶ø£¬¹«Ë¾²¢Î´Ð¹Â©¾ßÌåÊÜÓ°ÏìµÄÈËÊý¡£ 7ÔÂ24ÈÕ£¬NASCARÏòÊܺ¦Õß·¢ËÍÁËÊý¾Ýй¶֪ͨÐÅ£¬²¢ÌṩÁËΪÆÚÒ»ÄêµÄÐÅÓþ¼à¿Ø·þÎñ×÷Ϊ²¹¾È´ëÊ©¡£´Ë±í£¬ÔçÔÚ4Ô£¬MedusaÀÕË÷Èí¼þÍÅ»ïÒѽ«NASCARÁÐÈëÆäÐ¹Â¶ÍøÕ¾Ãûµ¥£¬ÒªÇóÖ§¸¶400ÍòÃÀÔªÊê½ð£¬²¢Ðû³ÆÇÔÈ¡ÁË´óÁ¿¹«Ë¾Êý¾Ý¡£Ö»¹ÜÉ趨ÁË4ÔÂ19ÈÕµÄ×îºóÆÚÏÞ£¬µ«Éв»Ã÷ÏÔÕâЩÊý¾ÝÊÇ·ñ×îÖÕ±»¹«¿ª¡£ 


https://therecord.media/nascar-confirms-data-breach


2. ÎÚ¿ËÀ¼ºÚ¿ÍÈëÇÖ¶íº½£¬ÖÂ40Óà´Îº½°àÈ¡µÞ


7ÔÂ28ÈÕ£¬¶íÂÞ˹¹ú¶Èº½¿Õ¹«Ë¾¶íº½£¨Aeroflot£©ÒòÔâ·êÇ×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯"¹ÑÑÔÎÚÑ»"Óë°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓµÄ½áºÏÍøÂç¹¥»÷£¬±»ÆÈÈ¡µÞ40Óà¼Ü´Îº½°à£¬²¢µ¼ÖÂÊýÊ®¼Üº½°àÑÓÎó£¬È«ÇòÁìÍÁÃæ»ý×î´ó¹ú¶ÈµÄº½¿ÕÔËÊäÍøÂçÔÚÓÎÀÀÍú¼¾ÏÝÈë»ìÂÒ¡£Á½¸öºÚ¿Í×éÖ¯Ðû³ÆÐж¯ÊdzÖÐøÒ»ÄêÉøÈëµÄ³É¾Í£¬ÒÑ·ÛËé¶íº½7000̨·þÎñÆ÷²¢½ÚÔì¸ß¹Ü¼°Ô±¹¤µçÄÔ£¬Íþв½«Ð¹Â¶³Ë¿ÍÓ×ÎÒÐÅÏ¢¼°ÄÚ²¿Í¨Ñ¶¼Í¼¡£°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓÃ÷È·°µÊ¾£¬¹¥»÷Ö¼ÔÚЭÖúÎÚ¿ËÀ¼Æ¥µÐ"ÇÖÂÔÕß"£¬ÉêÃ÷ÒÔ"ÎÚ¿ËÀ¼ÍòË꣡°×¶íÂÞ˹×ÔÓɳ¤´æ£¡"½áβ¡£Ö»¹ÜÎÚ¿ËÀ¼¹Ù·½Î´»ØÓ¦£¬µ«"¹ÑÑÔÎÚÑ»"´ËÇ°ÔøÂÅ´ÎÐû³Æ¹¥»÷¶í²»¶¯²úÊý¾Ý¿â¡¢¹úÓеçÐŹ«Ë¾µÈÖ¸±ê£¬²¿ÃÅÐж¯µ¼Ö´ó¹æÄ£Êý¾Ýй¶¡£¿ËÀïÄ·ÁÖ¹¬½²»°ÈËÅå˹¿Æ·ò³ÆÊÂÎñ"ÁîÈËÓÇÓô"£¬Ç¿µ÷ÍøÂçÍþвÊÇ´óÐ͹«¹²·þÎñÆóÒµ³ÖÐøÃæ¶ÔµÄÒþ»¼£¬¶í¼ì·½ÒÑÆô¶¯ÐÌʵ÷²é¡£×ÊÉîÒéÔ±°²¶«¡¤¸êÁжû½ðÖ¸³ö£¬¹¥»÷ÏÔʾ"Êý×ÖÕ½ÏßÒѳÉÎªÈ«ÃæÆ¥µÐµÄÒ»²¿ÃÅ"£¬ÒªÇó³¹²é·À»¤Ê§Ö°ÔðÈη½¡£¶íº½Ëäδ°ä²¼ÏµÍ³¸´Ô­¹¦·ò£¬µ«°µÊ¾ÕýЭµ÷ÆäËûº½Ë¾Ð­ÖúתÔ˳˿Í£¬²¢³Ðŵ¸´Ô­ºó½â¾öÍ˸ÄÇ©¡£


https://cybernews.com/security/glory-ukraine-hackers-took-down-aeroflots-entire-system/


3. GLOBAL GROUPÀÕË÷Èí¼þµ¼ÖÂýÌå¾ÞÍ·Albavisi¨®nÊý¾Ýй¶


7ÔÂ28ÈÕ£¬ÐÂÐËÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯GLOBAL GROUPÐû³Æ¶ÔÎ÷°àÑÀÓïýÌå¾ÞÍ·Albavisi¨®nµÄÊý¾Ýй¶ÊÂÎñÕÆ¹Ü£¬ÇÔÈ¡400GBÊý¾Ý²¢ÍþвÈô15ÌìÄÚδÆô¶¯½»É棬½«¹«¿ª±»µÁÐÅÏ¢¡£¸Ã×éÖ¯×Ô2025Äê6Ô»îÔ¾ÒÔÀ´£¬Òѽ«Ã½Ìå¡¢Ò½ÁƱ£½¡µÈ¶à¸öÐÐÒµµÄ29¼ÒÆóÒµÁÐΪÊܺ¦Õߣ¬ÆäÖÐ18Æð°¸¼þµ¼ÖÂÆëÈ«Êý¾Ý¼¯Ð¹Â¶£¬Ô̺¬Ò»¼ÒÒ½Ôº£¬Í¹ÏÔÆä¹¥»÷ÁìÓòµÄ¿í·ºÐÔÓë·ÛËéÁ¦¡£GLOBAL GROUPµÄ¹ÖÒìÖ®´¦ÔÚÓÚѡȡÈËΪÖÇÄÜÇý¶¯µÄ½»É湤¾ß£¬Í¨¹ý̸Ìì»úеÈËÓëÊܺ¦Õß¹µÍ¨£¬ÓÈÆäÕë¶Ô·ÇÓ¢ÓïʹÓÃÕߣ¬½µµÍÁË˵»°×è°­¶ÔÀÕË÷ЧÄܵÄÓ°Ïì¡£´Ëǰ°¸ÀýÖУ¬¸Ã×éÖ¯ÔøË÷Òª9.5±ÈÌØ±Ò£¨Ô¼ºÏ100ÍòÃÀÔª£©Êê½ð£¬µ«±¾´ÎÕë¶ÔAlbavisi¨®nµÄ¾ßÌå½ð¶îÉÐδ¹«¿ª¡£Albavisi¨®n×÷ΪÀ­¶¡ÃÀÖÞ¿ç¹úýÌ弯ÍÅ£¬ÒµÎñ¸²¸Ç14ÖÁ15¸öÎ÷°àÑÀÓï¹ú¶È£¬Õ¼ÓÐ45¸öµçÊÓÆµÂ·¡¢68¸ö¹ã²¥µç̨¼°65¼ÒµçÓ°Ôº£¬Ê×´´ÈËÀ×Ã×¼ª°Â¡¤°²ºÕ¶û¡¤¸ÔÈøÀ×˹Ó×ÎÒ×ʲúÔ¼20ÒÚÃÀÔª£¬ÆäÖØ´óµÄÓû§Êý¾ÝÓëóÒ×Ó°ÏìÁ¦³ÉΪÀÕË÷ÍÅ»ïµÄÖ¸±ê¡£


https://hackread.com/global-group-ransomware-media-giant-albavision-breach/


4. Ó¢¹ú¿Æ¼¼³Ð°üÉÌQdos֤ʵ¿Í»§Êý¾Ýй¶


7ÔÂ25ÈÕ£¬Ã³Ò×±£ÏÕ¼°IR35·þÎñר¼ÒQdos½üÈÕÈ·ÈÏÆäÍøÂçÀûÓ÷¨Ê½²úÉúÊý¾Ý°²È«ÊÂÎñ£¬²¿Ãſͻ§Ó×ÎÒÊý¾Ý±»Î´¾­ÊÚȨµÄµÚÈý·½ÇÔÈ¡¡£Æ¾¾ÝQdosÏò¿Í»§·¢Ë͵ĵç×ÓÓʼþ£¬¸Ã¹«Ë¾ÓÚ6ÔÂ19ÈÕÊÕµ½¹ØÓÚÆäWebÀûÓÃmygoqdos.comµÄ°²È«¾¯±¨£¬ËæºóÔÚµÚÈý·½ÍøÂ簲ȫר¼ÒЭÖúÏ·¢Õ¹µ÷²é¡£µ÷²éÈ·ÈÏ£¬¹¥»÷Õßͨ¹ý¸ÃÀûÓýӼû²¢ÏÂÔØÁËÔ̺¬¿Í»§ÐÕÃû¡¢Í¨Ñ¶µØÖ·£¨»ò×¢²á½»Ò×µØÖ·£©¡¢µç×ÓÓʼþµØÖ·¼°ÁªÏµ·½Ê½µÈÓ×ÎÒÊý¾Ý£¬ÒÔ¼°Óë¿Í»§±£ÏÕµ¥¡¢IR35·þÎñÓйصÄÎļþ£¬»¹Óвɹº»·½ÚµÄ·¢Æ±¡¢´û¼Çµ¥µÈÎĵµ¡£²»Í⣬QdosÇ¿µ÷ÐÅÓþ¿¨ÐÅÏ¢¡¢Éí·ÝÖ¤Ã÷Îļþ¼°±£ÏÕË÷ÅâÐÅϢδÊÜÓ°Ïì¡£ÊÂÎñ²úÉúºó£¬Qdosµ±¼´²ÉȡӦ¼±´ëÊ©£¬Ô̺¬ÔÚµ÷²éÆÚ¼ä½ûÓÿͻ§¶ÔÍøÕ¾µÄ½Ó¼ûȨÏÞ£¬²¢ÓÚ6ÔÂ26ÈÕ½¨¸´ÎÊÌâºó¸´Ô­·þÎñ¡£ÎªÓ¦¶ÔÕâ´Îй¶£¬¹«Ë¾ÎªÊÜÓ°Ïì¿Í»§ÌṩÁË12¸öÔµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ£¬¸Ã·þÎñ¿ÉÈ«Ììºò¼à²âÍøÂç¡¢É罻ƽ̨¼°¹«¹²Êý¾Ý¿â£¬ÊµÊ±Ô¤¾¯Ó×ÎÒÐÅϢй¶·çÏÕ¡£Í¬Ê±£¬Qdos½¨Òé¿Í»§¾¯Ìè¿ÉÒÉÓʼþ¡¢µç»°»ò¶ÌÐÅ£¬²¢³Ðŵ¿Í»§±£µ¥ÓÐЧÐÔ¼°ÔÚÏßÕË»§Ö°Äܲ»ÊÜÓ°Ïì¡£


https://www.theregister.com/2025/07/25/ir35_advisor_qdos_confirms_data_breach/


5. Patchwork×éÖ¯Õë¶ÔÍÁ¶úÆä¹ú·À³Ð°üÉÌÌáÒéÓã²æ´¹µö¹¥»÷


7ÔÂ25ÈÕ£¬ÍøÂ簲ȫÍþв×éÖ¯Patchwork£¨±ðºÅAPT-C-09¡¢°×Ïó×éÖ¯£©½üÆÚ±»ÆØÕë¶ÔÍÁ¶úÆä¹ú·À³Ð°üÉÌÌáÒéÐÂÒ»ÂÖÓã²æÊ½ÍøÂç¹¥»÷£¬Ö¸±êÖ±Ö¸ÎÞÈËÔØ¾ßϵͳ£¨UAV£©¼°¾«È·Ôìµ¼µ¼µ¯ÁìÓò£¬Ö¼ÔÚÇÔȡսÊõµý±¨¡£¾ÝArctic Wolf³¢ÊÔÊÒ¼¼Êõ»ã±¨£¬¹¥»÷Õßͨ¹ý¼Ù×°³É¡°¹ú¼ÊÎÞÈËÔØ¾ßϵͳ»áÒéÔ¼Ç뺯¡±µÄ¶ñÒâLNKÎļþÖ´ÐÐÎå½×¶Î¹¥»÷Á´£¬¹¥»÷»úÓöÇ¡·ê°Í»ù˹̹ÓëÍÁ¶úÆäÉîÈë·ÀÎñºÏ×÷¡¢Ó¡°Í¾üÊÂì¶ÜÉý¼¶Ö®¼Ê£¬µØÔµÕþÖζ¯»úÏÔÖø¡£¹¥»÷Á÷³ÌʼÓÚ´¹µöÓʼþÖеĶñÒâLNKÎļþ£¬¸ÃÎļþ´¥·¢PowerShellºÅÁ´Ó2025Äê6ÔÂ25ÈÕ×¢²áµÄÓòÃû¡°expouav[.]org¡±ÏÂÔØÔØºÉ¡£·þÎñÆ÷ÍйܵķÂð»áÒéPDFÎĵµ×÷ΪÊÓ¾õµö¶ü·ÖÉ¢Óû§°ÑÎÈÁ¦£¬¹¥»÷Á´ÔòÔÚºó¶Ü¾²Ä¬ÔËÐС£¹Ø¼üÔØºÉÔ̺¬Í¨¹ý´òË㹤×÷Æô¶¯µÄ¶ñÒâDLL£¬Ñ¡È¡DLL²à¼ÓÔØ¼¼ÊõÖ´ÐÐshellcode£¬×îÖÕʵÏÖÖ÷»úÉî¶È¿úËÅ¡¢ÆÁÄ»½ØÍ¼¼°Êý¾Ý»Ø´«ÖÁC2·þÎñÆ÷¡£¼¼Êõ·ÖÎöÏÔʾ£¬PatchworkÒÑ´Ó2024ÄêµÄx64 DLL±äÖÖ£¬·¢Õ¹Îª¾ß±¸¼ÓÇ¿ºÅÁî½á¹¹µÄx86 PE¿ÉÖ´ÐÐÎļþ£¬²¢Ñ¡È¡·ÂðºÏ·¨ÍøÕ¾µÄC2ºÍ̸£¬ÏÔÖøÌáÉýÁ˹¥»÷Òñ±ÎÐÔ¡£


https://thehackernews.com/2025/07/patchwork-targets-turkish-defense-firms.html


6. CISAÖÒ¸æPaperCut´òÓ¡Èí¼þ¸ßΣ·ì϶Ôâ»ý¼«ÀûÓÃ


7ÔÂ28ÈÕ£¬ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ·¢³ö´¹Î£ÖҸ棬³ÆÍþвÐÐΪÕßÕýÀûÓÃPaperCut NG/MF´òÓ¡ÖÎÀíÈí¼þÖеĸßΣ·ì϶£¨CVE-2023-2533£©ÌáÒé¿çÕ¾µãÒªÇóαÔ죨CSRF£©¹¥»÷£¬²¢½è´Ë»ñµÃÔ¶³Ì´úÂëÖ´ÐÐÄÜÁ¦¡£¸Ã·ì϶ÓÚ2023Äê6Ô±»½¨²¹£¬µ«Ä¿Ç°ÈÔ±»¶ñÒâÐÐΪÕß»ý¼«ÀûÓ㬹¥»÷Õßͨ³£Í¨¹ýÓÕÆ­ÓµÓÐÖÎÀíԱȨÏÞµÄÓû§µã»÷¶ñÒâÁ´½Ó£¬¼´¿É¸ü¸Äϵͳ°²È«ÉèÖûòÖ´ÐÐËÁÒâ´úÂë¡£PaperCutÈí¼þÔÚÈ«ÇòÕ¼ÓÐÖØ´óÓû§»ù´¡£¬¸²¸Ç³¬¹ý7Íò¸ö×éÖ¯µÄ1ÒÚ¶àÓû§£¬Éæ¼°½ÌÓý¡¢ÆóÒµµÈ¶àÁìÓò¡£Ö»¹ÜCISAδÅû¶µ±Ç°¹¥»÷µÄ¾ßÌåϸ½Ú£¬µ«Òѽ«¸Ã·ì϶ÄÉÈëÆä¡°ÒÑÖª±»ÀûÓ÷ì϶Ŀ¼¡±£¬²¢Æ¾¾Ý2021Äê11Ô°䲼µÄÓµÓÐÔ¼ÊøÁ¦µÄÔËÓªÖ¸ÁBOD 22-01£©£¬ÒªÇóÁª¹úÃñÊÂÐÐÕþ²¿ÃÅ£¨FCEB£©»ú¹¹ÔÚ2025Äê8ÔÂ18ÈÕǰʵÏÖϵͳ½¨²¹¡£CISAÇ¿µ÷£¬´ËÀà·ì϶ÊÇÍøÂç·¸×ï·Ö×ӵij£¼û¹¥»÷ý½é£¬´ºÁª¹úÆóÒµ×é³É³Á´ó·çÏÕ£¬²¢ºôÓõ˽Ӫ²¿ÃÅ×é֯ͬÑù¾¡¿ì²ÉÈ¡Ðж¯¡£


https://www.bleepingcomputer.com/news/security/cisa-flags-papercut-rce-bug-as-exploited-in-attacks-patch-now/