Ò½ÁƼ¯ÍÅHSGIÊý¾Ýй¶ӰÏ쳬60ÍòÈË

°ä²¼¹¦·ò 2025-08-29

1. Ò½ÁƼ¯ÍÅHSGIÊý¾Ýй¶ӰÏ쳬60ÍòÈË


8ÔÂ27ÈÕ £¬Ò½ÁƱ£½¡·þÎñ¼¯ÍÅ£¨HSGI£©½üÈÕÅû¶һ·³Á´óÊý¾Ýй¶ÊÂÎñ £¬Ó°Ï쳬¹ý60ÍòÃû¸ö±ð¡£Õâ¼Ò×ܲ¿Î»ÓÚ±öϦ·¨ÄáÑÇÖݵÄÉÏÊй«Ë¾×¨ÎªÈ«ÃÀÒ½ÁÆ»ú¹¹Ìṩ֧³Ö·þÎñ £¬ÄêÊÕÈë´ï17ÒÚÃÀÔª £¬Æäϵͳ°²È«¶ÔÊýǧ¼ÒÒ½ÁÆ»ú¹¹µÄÔË×÷ÖÁ¹Ø³ÁÒª¡£ÊÂÎñ¹¦·òÏßÏÔʾ £¬HSGIÓÚ2024Äê10ÔÂ7ÈÕ¼ì²âµ½ÍøÂçÔâ·êδÊÚȨ½Ó¼û £¬ËæºóÈ·ÈÏÈëÇÖʼÓÚ9ÔÂ27ÈÕ £¬²¢ÓÚ10ÔÂ3ÈÕʵÏÖ¡£µ÷²éÏÔʾ £¬¹¥»÷ÕßÔÚ´ËÆÚ¼ä½Ó¼û²¢¸´ÔìÁËϵͳÄڵIJ¿ÃÅÎļþ¡£Ö»¹Ü·ì϶²úÉúÔÚ2024Äê9ÔÂÄ© £¬µ«ÊÜÓ°Ïì¸ö±ðÖ±ÖÁ2025Äê8ÔÂ25ÈÕ²ÅÊÕµ½Í¨Öª £¬Õû¸öµ÷²é¹ý³ÌºÄʱ½ü10¸öÔ¡£Ð¹Â¶Êý¾ÝÀàÐÍÒò¸ö±ð¶øÒì £¬¿ÉÄÜÔ̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢Öݼø±ðÂë¡¢²ÆÕþÕË»§ÐÅÏ¢¼°ÕË»§½Ó¼ûƾ֤µÈÃô¸ÐÄÚÈÝ¡£HSGIÔÚ²¼¸æÖÐÇ¿µ÷ £¬Ä¿Ç°ÉÐÎÞÖ¤¾ÝÅú×¢±»µÁÐÅÏ¢Òѱ»ÀÄÓà £¬µ«ÈÔ½¨ÒéÊÜÓ°ÏìÕß¾¯ÌèÍøÂç´¹µö¡¢Ú¿Æ­ÐÐΪ £¬²¢Ç×êÇ¼à¿ØÒøÐÐÕË»§Òì³£»î¶¯¡£×÷ΪӦ¶Ô´ëÊ© £¬HSGIΪÊý¾Ýй¶Êܺ¦ÕßÌṩ12ÖÁ24¸öÔµÄÃâ·ÑÐÅÓþ¼à¿ØÓëÉí·Ý͵ÇÔ±£»¤·þÎñ £¬¾ßÌåÆÚÏÞÈ¡¾öÓÚй¶Êý¾ÝµÄÑϳÁˮƽ¡£


https://www.bleepingcomputer.com/news/security/healthcare-services-group-data-breach-impacts-624-000-people/


2. Sangoma FreePBXÁãÈÕ·ì϶Ôâ»ý¼«ÀûÓà £¬¶ą̀·þÎñÆ÷±»ÈëÇÖ


8ÔÂ27ÈÕ £¬Sangoma FreePBX°²È«ÍŶӽüÈÕÖÒ¸æ £¬Æä»ùÓÚAsteriskµÄ¿ªÔ´PBXƽ̨´æÔÚ±»»ý¼«ÀûÓõÄÁãÈÕ·ì϶ £¬Ó°Ïì¶³öÔÚ¹«¹²»¥ÁªÍøÉϵÄÖÎÀíÔ±½ÚÔìÃæ°å£¨ACP£©ÏµÍ³¡£FreePBX¿í·ºÀûÓÃÓÚÆóÒµ¡¢ºô½ÐÖÐÐļ°·þÎñÌṩÉÌÖÎÀíÓïÒôͨѶ¡¢SIPÖм̵ÈÖ÷ÌâÒµÎñ £¬Õâ´Î·ì϶¶³öÒý·¢´ó¹æÄ£·þÎñÆ÷ÈëÇÖÊÂÎñ £¬²¨¼°ÊýǧSIP·Ö»úÓëÖмÌÏß·¡£¾Ý°²È«²¼¸æ £¬×Ô8ÔÂ21ÈÕÆð £¬ºÚ¿Íͨ¹ýδÊܱ£»¤µÄFreePBXÖÎÀíÔ±½çÃæÌáÒé¹¥»÷¡£SangomaÒѰ䲼EDGEÄ£¿é½¨¸´·¨Ê½ÒÔ×è¶ÏÐÂ×°ÖÃϰȾ £¬µ«ÈϿɸò¹¶¡ÎÞ·¨½â¾öÏÖÓÐϵͳÎÊÌâ £¬½¨ÒéÓû§Í¨¹ý·À»ðǽÏÞ¶ÈACP½Ó¼û £¬½öÔÊÐí¿ÉÐÅÖ÷»úÏνÓ¡£·ì϶ӰÏìÔËÐÐv16/v17°æ±¾ÇÒ×°Öö˵ãÄ£¿éµÄϵͳ £¬²¿ÃŹýÆÚÖ§³ÖºÏͬµÄÉ豸¿ÉÄÜÎÞ·¨×°ÖøüР£¬ÐèÆëÈ«×è¶ÏACP½Ó¼ûÖ±ÖÁ³ß¶È°²È«°æ±¾°ä²¼¡£¹¥»÷ÒÑÔì³ÉÏÖʵÇÖº¦£º¶àÃûÓû§»ã±¨·þÎñÆ÷±»ÈëÇÖ £¬Ä³ÆóÒµ»ù´¡ÉèÊ©Öг¬3000¸öSIP·Ö»ú¼°500ÌõÖмÌÏßÊÜÓ°Ïì £¬¹¥»÷Õßͨ¹ý·ì϶ִÐÐËÁÒâAsteriskºÅÁî¡£Sangoma½¨ÒéÊÜÓ°ÏìÓû§´Ó8ÔÂ21ÈÕǰ±¸·Ý¸´Ô­ÏµÍ³ £¬²¿Ê𽨲¹Ä£¿éºóÂÖ»»È«ÊýSIPƾ֤ £¬²¢ºË²éͨ»°¼Í¼ÓëÕ˵¥ÖеÄÒì³£¹ú¼Êͨ»°¡£


https://www.bleepingcomputer.com/news/security/freepbx-servers-hacked-via-zero-day-emergency-fix-released/


3. ÀÕË÷Èí¼þPromptLockʹÓÃÈËΪÖÇÄܼÓÃܺÍÇÔÈ¡Êý¾Ý


8ÔÂ27ÈÕ £¬Íþв×êÑÐÈËÔ±½üÈÕÅû¶һ¿îÃûΪPromptLockµÄ¿çƽ̨ÀÕË÷Èí¼þ £¬¸Ã¶ñÒâÈí¼þͨ¹ý¼¯³ÉÈËΪÖÇÄܼ¼ÊõʵÏÖ¶¯Ì¬¾ç±¾ÌìÉú £¬³ÉΪÊ׸ö±»Ö¤ÊµµÄAIÇý¶¯ÐÍÀÕË÷Èí¼þ¡£¾ÝESET»ã±¨ £¬PromptLockѡȡGolang±àд £¬ÀûÓÃOllama APIŲÓÃOpenAIµÄgpt-oss:20b´óÐÍ˵»°Ä£ÐÍ £¬Í¨¹ý´úÀíËí·ÏνÓÔ¶³Ì·þÎñÆ÷ÉϵÄLLM £¬»ùÓÚÓ²±àÂëÌáÐѶ¯Ì¬ÌìÉú¶ñÒâLua¾ç±¾ £¬ÊµÏÖ¶ÔWindows¡¢macOSºÍLinuxϵͳµÄÎļþö¾Ù¡¢Êý¾ÝÇÔÈ¡¼°¼ÓÃܲÙ×÷¡£¸Ã¶ñÒâÈí¼þµÄÖ÷Ìâ´´ÐÂÔÚÓÚÆä¹¤×÷Á÷³Ì£ºÍ¨¹ýÔ¤ÉèÌáÐÑ´ÊÖ¸ÁîÄ£ÐÍÌìÉú¾ß±¸±¾µØÏµÍ³½»»¥ÄÜÁ¦µÄLua¾ç±¾ £¬º­¸ÇÎļþϵͳɨÃè¡¢Ãô¸ÐÊý¾Ý¼ø±ð¡¢¼ÓÃÜÖ´ÐеÈÄ£¿é¡£Ö»¹Ü¾ß±¸Êý¾ÝÏú»ÙÖ°ÄÜ £¬µ«¸Ã¸öÐÔÉÐδÆëȫʵÏÖ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬PromptLockѡȡÇáÁ¿¼¶SPECK 128λËã·¨½øÐмÓÃÜ £¬Õâһͨ³£ÓÃÓÚRFIDÁìÓòµÄË㷨ѡÔñ £¬±»×êÑÐÈËÔ±ÊÓΪ¼¼Êõ²»³ÉÊìµÄÌåÏÖ¡£´Ë±í £¬ÆäÓ²±àÂëµÄ±ÈÌØ±ÒµØÖ·ÓëÖб¾´Ï¹ØÁª £¬½øÒ»²½×ôÖ¤Á˸ÃÈí¼þÈÔ´¦ÓÚ¸ÅÏëÑéÖ¤½×¶Î¡£ESETÇ¿µ÷ £¬PromptLockÉÐδÔÚÕæÊµ¹¥»÷³¡¾°Öб»¹Û²âµ½ £¬ÆäÑù±¾½öͨ¹ýVirusTotal±»·¢ÏÖ £¬»òΪ×êÑÐÏîĿй¶ËùÖ¡£


https://www.bleepingcomputer.com/news/security/experimental-promptlock-ransomware-uses-ai-to-encrypt-steal-data/


4. ÃÀºÉ½áºÏ·¨ÂÉ·ÛËé¿ç¹úαÔìÖ¤¼þƽ̨VerifTools


8ÔÂ28ÈÕ £¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©ÓëºÉÀ¼¾¯·½½üÈÕ·¢Õ¹¿ç¹ú½áºÏÐж¯ £¬³É¹¦¹Ø¹ØÈ«Çò³ÛÃûαÔìÉí·ÝÖ¤¼þƽ̨VerifTools £¬²¢²é·âÆäλÓÚ°¢Ä·Ë¹Ìص¤µÄ·þÎñÆ÷¼¯Èº £¬±ê־ȡ¹ú¼Ê·¨ÂÉ»ú¹¹¶ÔÊý×ÖÉí·Ý·¸×ïµÄ³ÁÈ­³ö»÷¡£¸Ãƽ̨×Ô2022ÄêÆðͨ¹ý¼ÓÃÜÇ®±ÒÂòÂô £¬ÒÔ9ÃÀÔªÖÁÊý°ÙÃÀÔª²»µÈµÄ¼ÛÖµÏòÈ«ÇòÓû§ÌṩαÔìµÄÃÀÅ·Áйú¼ÝÊ»ÅÆÕÕ¡¢»¤ÕÕµÈÖ¤¼þ £¬Ðγɼ¯Ôì×÷¡¢´úÀí²É°ìÓëÉí·ÝðÓÃÓÚÒ»ÌåµÄÆëÈ«ÐþÉ«²úÒµÁ´¡£Æ¾¾ÝÃÀ¹úÐÂÄ«Î÷¸çÖݼì²ì¹Ù°ì¹«ÊÒÅû¶ £¬FBIÓÚ2022Äê8ÔÂÆô¶¯µ÷²é £¬·¢ÏÖ¸ÃÆ½Ì¨²»½ö±»ÓÃÓÚÒøÐÐÚ¿Æ­¡¢ÍøÂç´¹µö¡¢ÌÓ±Ü˾·¨×·Ôð¼°ÄäÃûÈÆ¹ý½ðÈÚÆ½Ì¨"ÏàʶÄãµÄ¿Í»§"£¨KYC£©ÉóºË £¬¸ü³ÉΪδ³ÉÄêÈ˶ã±Ü´ºÇïÏ޶ȵĻÒɫͨ·¡£ºÉÀ¼¾¯·½Ö¤Êµ £¬Óû§½öÐèÉÏ´«ÕÕÆ¬²¢ÌîдÐéαÐÅÏ¢ £¬¼´¿Éͨ¹ý×Ô¶¯»¯ÏµÍ³ÌìÉú¸ß·ÂÕæÖ¤¼þͼÏñ £¬Õû¸ö¹ý³ÌÈçͬ"ÏßÉϵã²Í"°ã±ã½Ý¡£Õâ´ÎÐж¯ÖÐ £¬ÃÀºÉ·¨ÂÉ»ú¹¹²é»ñ2̨ÎïÀí·þÎñÆ÷¼°21̨Ðé¹¹·þÎñÆ÷ £¬³¹µ×¸´ÔìÆäÍøÕ¾»ù´¡ÉèÊ©Êý¾Ý¡£


https://www.bleepingcomputer.com/news/security/police-seize-veriftools-fake-id-marketplace-servers-domains/


5. MathWorksÔâ·êÀÕË÷¹¥»÷ÖÂÍòÈËÊý¾Ýй¶


8ÔÂ28ÈÕ £¬È«ÇòÊýÑ§ÍÆËãÓë·ÂÕæÈí¼þÁì¾üÆóÒµMathWorks½üÈÕÅû¶ £¬ÆäÍøÂçϵͳÓÚ2024Äê4ÔÂÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬µ¼Ö³¬¹ý1.04ÍòÃûÔ±¹¤¼°¿Í»§µÄÃô¸ÐÊý¾Ýй¶¡£Õⳡ³ÖÐøÓâԵݲȫÊÂÎñÒý·¢·þÎñ´ó¹æÄ£ÖÐ¶Ï £¬²¢Â¶³ö³ö¹¤ÒµÈí¼þÁìÓòÈÕÒæÑϸñµÄÍøÂ簲ȫÌôÕ½¡£Æ¾¾ÝMathWorksÏòÃÀ¹úÃåÒòÖݺÍÂíÈøÖîÈûÖÝ×ܼì²ì³¤Ìá½»µÄ»ã±¨ £¬¹¥»÷ÕßÓÚ4ÔÂÇÖÈëÆäÍøÂçºó³Ö¾ÃÂñ·ü £¬Ö±ÖÁ5ÔÂ18Èղű»¼ì²â·¢ÏÖ¡£Õâ´ÎÈëÇÖµ¼ÖÂÔ±¹¤Óë¿Í»§ÎÞ·¨½Ó¼û¶à³É·ÖÈÏÖ¤£¨MFA£©¡¢µ¥µãµÇ¼£¨SSO£©¡¢ÔÆÖÐÐÄ¡¢Ðí¿ÉÖ¤ÖÎÀíµÈ¹Ø¼üϵͳ £¬Ö±½ÓÓ°ÏìÈ«Çò34¸ö´¦Ê´¦µÄÔËÓª¡£Ð¹Â¶Êý¾Ýº­¸ÇÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç±£ºÅÂëµÈ¸ßÃô¸ÐÐÅÏ¢ £¬Éæ¼°ÃÀ¹ú±¾ÍÁ¼°·ÇÃÀ¹ú¹«ÃñµÄ»ìºÏÊý¾Ý¼¯¡£ÖµµÃ¹Ø×¢µÄÊÇ £¬Ö»¹ÜMathWorksÔÚ5ÔÂ27ÈÕ¹«¿ªÈÏ¿ÉÔâ·êÀÕË÷Èí¼þÊÂÎñ £¬µ«Ê¼ÖÕδÅû¶¹¥»÷ÍÅ»ïÃû³Æ¼°¾ßÌå¼¼Êõϸ½Ú¡£½ØÖÁĿǰ £¬ÎÞÈκÎÒÑÖªÀÕË÷ÍÅ»ïÐû³Æ¶Ô´ËÊÂÕÆ¹Ü¡£


https://www.bleepingcomputer.com/news/security/matlab-dev-says-ransomware-gang-stole-data-of-over-10-000-people/


6. TransUnionÒòSalesforceÕË»§ÈëÇÖÖÂ440ÍòÓû§Êý¾Ýй¶


8ÔÂ28ÈÕ £¬ÃÀ¹úÈý´óÐÅÓþ»ã±¨»ú¹¹Ö®Ò»TransUnion½üÈÕÅû¶ £¬ÆäSalesforceÕË»§ÓÚ2025Äê7ÔÂ28ÈÕÔâ·êδ¾­ÊÚȨ½Ó¼û £¬µ¼ÖÂÔ¼440ÍòÃÀ¹úÓû§µÄÃô¸ÐÓ×ÎÒÐÅϢй¶¡£Õâ´ÎÊÂÎñÔٴζ³öÁËÈ«ÇòÐÅÓþÊý¾Ý¾ÞÍ·µÄÍøÂ簲ȫ¶Ì°å £¬²¢Òý·¢¶ÔµÚÈý·½·þÎñÒÀÀµ·çÏÕµÄ¿í·º¹Ø×¢¡£×÷ΪÄêÊÕÈë30ÒÚÃÀÔª¡¢ÒµÎñ¸²¸Ç30¹úµÄÐÅÓþÊý¾Ý¾ÞÍ· £¬TransUnion°ÑÎÕ×ÅÈ«Çò³¬¹ý10ÒÚÏû·ÑÕßµÄÐÅÓþÐÅÏ¢ £¬ÆäÖÐÃÀ¹ú±¾ÍÁÓû§Ô¼2ÒÚ¡£Õâ´Îй¶µÄÊý¾ÝԴΪÆäÏû·ÑÕßÖ§³ÖÒµÎñʹÓõÄSalesforceµÚÈý·½ÀûÓà £¬¹¥»÷Õßͨ¹ý¸Ã·ì϶ÇÔÈ¡ÁËÓû§ÐÕÃû¡¢µØÖ·¡¢µç»°¡¢ÓÊÏä¡¢µ®ÉúÈÕÆÚ¼°Î´±à×ëµÄÉç»á°²È«ºÅÂ루SSN£©µÈÖ÷ÌâÉí·ÝÐÅÏ¢ £¬ÉõÖÁÔ̺¬¿Í»§ÒªÇóÃâ·ÑÐÅÓþ»ã±¨µÄÂòÂô¼Í¼¡£Ö»¹ÜTransUnionÇ¿µ÷δй¶Ö÷ÌâÐÅÓþ»ã±¨Êý¾Ý £¬µ«Ñù±¾ÖÐÏÔʾµÄÆëÈ«SSNµÈÃô¸Ð×Ö¶Î £¬ÈÔ×ãÒÔÈÃÊܺ¦ÕßÃæ¶ÔÉí·ÝµÁÓᢽðÈÚÚ¿Æ­µÈ³Á´ó·çÏÕ¡£¹«Ë¾ÒÑÏòÊÜÓ°ÏìÓû§Ìṩ24¸öÔÂÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ £¬µ«Î´Åû¶¾ßÌåй¶¹æÄ£Óë¹¥»÷ÍÅ»ïÃû³Æ¡£


https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/