ˮʦÁª¹úÐÅÓþºÏ×÷Éç·þÎñÆ÷ÅäÖÃÃýÎóÖÂÄÚ²¿Îļþй¶
°ä²¼¹¦·ò 2025-09-051. ˮʦÁª¹úÐÅÓþºÏ×÷Éç·þÎñÆ÷ÅäÖÃÃýÎóÖÂÄÚ²¿Îļþй¶
9ÔÂ3ÈÕ£¬ÍøÂ簲ȫ×êÑÐÔ±Jeremiah FowlerÔÚµ÷²éÖз¢ÏÖ£¬ÃÀ¹úˮʦÁª¹úÐÅÓþºÏ×÷É磨NFCU£©Ò»Ì¨ÅäÖÃÃýÎóµÄ·þÎñÆ÷¶³öÁË378GBÃô¸ÐÄÚ²¿Îļþ£¬ÊÂÎñÓÉWebsite Planet×êÑÐÍŶÓÓëHackread.com½áºÏÅû¶¡£¸Ã·þÎñÆ÷δÉèÖÃÃÜÂë±£»¤£¬ÈκÎÈ˾ù¿É½Ó¼ûδ¼ÓÃܵı¸·ÝÊý¾Ý¡£Ö»¹Üй¶ÄÚÈݲ»Ô̺¬¿Í»§ÐÅÏ¢£¬µ«Â¶³öµÄÎļþÔ̺¬´óÁ¿Ç±ÔÚÃô¸ÐÊý¾Ý£ºÄÚ²¿Óû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢É¢ÁÐÃÜÂë¼°ÃÜÔ¿£¬ÒÔ¼°ÓÉÊý¾Ý·ÖÎöƽ̨TableauÌìÉúµÄ¶à¸ö¹¤×÷²¾Îĵµ¡£ÕâЩÎĵµ¾ßÌå¼Í¼ÁËÓëÆäËûÄÚ²¿Êý¾Ý¿âµÄÏνÓÅäÖᢴû¿î¼¨Ð§ÓëÀûÈóÍÆËãµÄ²ÆÕþ¹«Ê½µÈÖ÷ÌâÔËÓªÐÅÏ¢£¬×é³ÉÐÅÓþºÏ×÷ÉçÄÚ²¿ÏµÍ³µÄ¡°¼¼ÊõÀ¶Í¼¡±¡£FowlerÔÚºËʵ¹ý³ÌÖнØÈ¡µÄ½ØÍ¼ÏÔʾ£¬Îļþ»¹Ô̺¬ÏµÍ³ÈÕÖ¾¡¢²úÆ·´úÂë¼°±¾Ó¦±£ÃܵÄÔªÊý¾Ý¡£ÊÂÎñ²úÉúºó£¬NFCUѸ¿ìÏìÓ¦£¬ÔÚÊýÓ×ʱÄÚ±£»¤ÁËÊý¾Ý¿â¡£È»¶ø£¬Â¶³öʱ³¤¼°ÊÇ·ñ±»µÚÈý·½½Ó¼ûÈÔ²»Ã÷È·¡£FowlerÖ¸³ö£¬±¸·ÝÊý¾Ý³£±»ÊÓΪ¡°³ö²úÊý¾ÝµÄ¾µÏñ¡±£¬µ«Æä¹ØÁªµÄ³ö²úϵͳ½á¹¹»òÔªÊý¾ÝÈÔ¿ÉÄÜй¶¹Ø¼ü°²È«ÐÅÏ¢¡£
https://hackread.com/misconfigured-server-navy-federal-credit-union-data-leak/
2. αÔìAnyDesk×°Ö÷¨Ê½Í¨¹ýClickFixȦÌ×´«²¼MetaStealer
9ÔÂ3ÈÕ£¬HuntressÍøÂ簲ȫÍŶӽüÈո淢һÖÖÐÂÐÍClickFixȦÌ×£¬¹¥»÷Õßͨ¹ýαÔìºÏ·¨Ô¶³Ì½Ó¼û¹¤¾ßAnyDeskµÄ×°Ö÷¨Ê½£¬½áºÏWindowsËÑË÷Ö°ÄÜÈÆ¹ý°²È«·À»¤£¬×îÖÕÔÚÓû§É豸ÉϾ²Ä¬²¿ÊðMetaStealer¶ñÒâÈí¼þ¡£¸Ã»î¶¯Ñ¡È¡Éý¼¶°æ¡°FileFix¡±¼¼Êõ£¬Ïà½Ï´«Í³ClickFixȦÌ×£¨ÒªÇóÓû§¸´ÔìÕ³ÌùºÅÁîµ½ÔËÐжԻ°¿ò£©£¬ÆäΣÏÕÐÔÏÔÖøÌáÉý¡£¹¥»÷Á÷³ÌʼÓÚÓû§ÔÚÏßËÑË÷AnyDeskʱÎóÈëÐéÎ±ÍøÕ¾¡£¸ÃÒ³Ãæ¼Ù×°³ÉCloudflare CAPTCHAÑéÖ¤½çÃæ£¬ÓÕµ¼Óû§µã»÷¡°ÑéÖ¤¡±°´Å¥¡£µã»÷ºó£¬ÍøÕ¾´¥·¢WindowsÎļþ×ÊÔ´ÖÎÀíÆ÷Ö´ÐÐÌØÊâËÑË÷²éÎÊ£¬½«Óû§ÍÆËã»úÏνÓÖÁºÚ¿Í½ÚÔìµÄÔ¶³Ì·þÎñÆ÷£¬²¢Ö±½ÓÍÆËͼÙ×°³É¡°Readme Anydesk.pdf¡±µÄ¶ñÒâ×°Öðü¡£¸ÃÎļþ±í±íΪPDFÎĵµ£¬ÊµÔòÔ̺¬Ë«³Á²Ù×÷Âß¼£ºÏÈÏÂÔØºÏ·¨AnyDeskÀûÓ÷¨Ê½ÒÔ½µµÍÓû§¾¯Ìè£¬Ëæºó¾²Ä¬×°ÖÃMetaStealer¶ñÒâÈí¼þ¡£MetaStealer¾ß±¸¸ßÒñ±ÎÐÔÐÅÏ¢ÇÔÈ¡ÄÜÁ¦£¬¿ÉµÁÈ¡µÇ¼ƾ֤¡¢Ãô¸ÐÎļþ¼°¼ÓÃÜÇ®°üÊý¾Ý£¬×é³ÉÑϳÁ°²È«Íþв¡£
https://hackread.com/fake-anydesk-installer-metastealer-clickfix-scam/
3. È«Çò¶à¹úÔâ·ê³¬2.5ÒÚ·ÝÉí·Ý¼Í¼´ó¹æÄ£Ð¹Â¶Î£»ú
9ÔÂ3ÈÕ£¬½üÆÚ£¬Ò»³¡Éæ¼°ÖÁÉÙÆß¸ö¹ú¶È¡¢³¬2.5ÒÚ·ÝÉí·Ý¼Í¼µÄ´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÒý·¢È«Çò¹Ø×¢¡£Õâ´Îй¶µÄ¹«ÃñÐÅÏ¢¸²¸ÇÍÁ¶úÆä¡¢°£¼°¡¢É³Ìذ¢À²®¡¢°¢ÁªÇõ¡¢Ä«Î÷¸ç¡¢ÄϷǺͼÓÄôó£¬Ô̺¬Éí·ÝÖ¤ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢ÁªÏµ·½Ê½¼°¼ÒͥסַµÈµ±¾ÐĶÉí·Ýµµ°¸Ï¸½Ú¡£Èý̨ÅäÖÃÃýÎóµÄ·þÎñÆ÷£¨ÍйÜÓÚ°ÍÎ÷ºÍ°¢ÁªÇõIPµØÖ·£©³ÉΪй¶Դͷ£¬ÆäÊý¾Ý¿â½á¹¹¸ß¶ÈÀàËÆ£¬°µÊ¾¿ÉÄÜÔ´×ÔͳһÔËÓª·½£¬µ«¾ßÌå½ÚÔìÕßÈÔÎÞ·¨È·¶¨¡£Cybernews×êÑÐÈËÔ±Ö¸³ö£¬ÍÁ¶úÆä¡¢°£¼°ºÍÄϷǹ«ÃñÊÜÓ°ÏìÓÈΪÑϳÁ£¬ÕâЩ¹ú¶ÈµÄÊý¾Ý¿âÔ̺¬È«ÃæÉí·ÝÐÅÏ¢£¬Îª½ðÈÚڲơ¢Éí·ÝðÓᢶ¨ÏòÍøÂç´¹µö¼°Ú¿ÆµÈÀÄÓÃÐÐΪ´ò¿ªÁË´óÃÅ¡£ÊÂÎñÆØ¹âºó£¬ÍйܷþÎñÌṩÉÌÒÑÏÞ¶ÈÊý¾Ý¹«¿ª½Ó¼û£¬µ«Ð¹Â¶ÐÅÏ¢µÄDZÔÚÀÄÓ÷çÏÕÈÔ³ÖÐø´æÔÚ¡£
https://cybernews.com/security/identity-records-global-data-leak/
4. CISAÖÒ¸æTP-LinkÓëWhatsApp·ì϶Ôâ»îÔ¾ÀûÓÃ
9ÔÂ3ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ°ä²¼´¹Î£ÖҸ棬ָ³öºÚ¿ÍÕý»ý¼«ÀûÓÃÁ½¸ö¸ßΣ·ì϶ÌáÒé¹¥»÷£¬²¢Òѽ«¶þÕßÁÐÈë¡°ÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©¡±Ä¿Â¼£¬Ç¿µ÷Æä´ºÁª¹úÆóÒµ×é³É³Á´óÍþв¡£Ê׸ö·ì϶ӰÏìTP-Link TL-WA855RE V5 WiFiÀ©´óÆ÷£¬¸ÃÉ豸ÔÚÑÇÂíÑ·Õ¼Óг¬120,500ÌõÆÀÂÛ£¬ÏÔʾÆä¿í·ºÊ¢ÐС£·ì϶´æÔÚÎåÄ꣬ÑϳÁÐÔÆÀ·Ö´ï8.8/10£¬ÔÊÐíÍ³Ò»ÍøÂçϵÄδ¾Éí·ÝÑéÖ¤¹¥»÷Õß·¢ËÍTDDP_RESET POSTÒªÇ󣬴¥·¢É豸¹¤³§³ÁÖò¢³ÁÆô£¬ËæºóÉèÖÃÐÂÖÎÀíÃÜÂëÒÔ»ñÈ¡½ÚÔìȨ¡£CISAÖ¸³ö£¬Î´´ò²¹¶¡ÇÒÓ²¼þ°æ±¾ÎªV5µÄÉ豸Ò×Êܹ¥»÷£¬¹©¸øÉÌËäÒÑÌṩ¹Ì¼þ¸üУ¬µ«²¿ÃÅÉ豸¿ÉÄÜÒÑ´ïÐÔÃüÖÜÆÚÖյ㣬½¨ÒéÁª¹ú»ú¹¹µ±¼´ÖÕ³¡Ê¹Óûò²ÉÈ¡Ñϸñ»º½â´ëÊ©¡£µÚ¶þÏî·ìÏ¶Éæ¼°WhatsApp iOS/Mac¿Í»§¶Ë£¬ÓÉ¡°Á´½ÓÉ豸ͬ²½ÐÂÎÅÊÚȨ²»ÆëÈ«¡±Òý·¢£¬¿ÉÄÜÔÊÐíÎÞ¹ØÓû§´¥·¢Ö¸±êÉ豸´¦ÖÃËÁÒâURLÄÚÈÝ£¬Òѱ»ÓÃÓڸ߼¶¼äµýÈí¼þ»î¶¯¡£WhatsAppÓëÆ»¹ûÒѰ䲼´¹Î£¸üн¨¸´´ËÎÊÌ⣬¹©¸øÉÌÆÀ¹ÀÒÔΪ¸Ã·ì϶¿ÉÄܱ»ÓÃÓÚÕë¶ÔÌØ¶¨Ö¸±êÓû§µÄ¸´ÔÓ¹¥»÷¡£
https://cybernews.com/security/tp-link-whatsapp-vulnerabilities-exploited-by-hackers/
5. Chess.comÅû¶µÚÈý·½ÀûÓÃÊý¾Ýй¶ÊÂÎñ£¬Ó°Ïì4500ÃûÓû§
9ÔÂ4ÈÕ£¬È«Çò×î´óÔÚÏß¹ú¼ÊÏóÆåƽ̨Chess.com½üÈÕÅûÂ¶Ò»Â·Éæ¼°µÚÈý·½Îļþ´«ÊäÀûÓõÄÊý¾Ýй¶ÊÂÎñ¡£¾Ý²¼¸æ£¬2025Äê6ÔÂ5ÈÕÖÁ18ÈÕÆÚ¼ä£¬ÍþвÐÐΪÕßδ¾ÊÚȨ½Ó¼ûÁË¸ÃÆ½Ì¨Ê¹ÓõĵÚÈý·½Îļþ´«ÊäÀûÓ÷¨Ê½£¬µ¼ÖÂÔ¼4,500ÃûÓû§µÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¿ÉÄܱ»Ð¹Â¶¡£Chess.comÓÚ6ÔÂ19ÈÕ·¢ÏÖÒì³£ºó£¬µ±¼´Æô¶¯µ÷²é²¢ÀñƸ¶¥¼â°²È«×¨¼Ò£¬Í¬²½Í¨ÖªÁª¹ú·¨Âɲ¿ÃÅ£¬²¢²ÉÈ¡´ëÊ©½¨¸´·ì϶¡£¹«Ë¾Ç¿µ÷£¬Õâ´ÎÊÂÎñ½öÓ°ÏìµÚÈý·½ÀûÓ÷¨Ê½£¬Æä×ÔÉí»ù´¡ÉèÊ©¼°»áÔ¹ØË»§ÏµÍ³Î´Êܲ¨¼°¡£Ð¹Â¶Êý¾ÝÖØÒªÔ̺¬Óû§ÐÕÃû¼°ÆäËûPII£¬µ«Î´Éæ¼°²ÆÕþÐÅÏ¢¡£Ä¿Ç°ÎÞÖ¤¾ÝÅú×¢±»µÁÊý¾ÝÒѱ»¹«¿ªÅû¶»òÀÄÓá£×÷Ϊ²¹¾È´ëÊ©£¬Chess.comΪÊÜÓ°ÏìÓû§Ìṩ1-2ÄêÃâ·ÑÉí·Ý͵ÇÔÓëÐÅÓþ¼à¿Ø·þÎñ£¬Óû§ÐèÔÚ2025Äê12ÔÂ3ÈÕǰʵÏÖ×¢²á¡£
https://www.bleepingcomputer.com/news/security/chesscom-discloses-recent-data-breach-via-file-transfer-app/
6. ÆÕÀû˾ͨ±±ÃÀ¹¤³§È·ÈÏÍøÂç¹¥»÷Ó°ÏìÁËÆä³ö²ú
9ÔÂ4ÈÕ£¬È«Çò×î´óÂÖÌ¥Ôì×÷ÉÌÆÕÀû˾֤ͨʵ£¬Æä±±ÃÀ·Ö¹«Ë¾ÆÕÀû˾ͨÃÀÖÞ¹«Ë¾£¨BSA£©Õýµ÷²éÓ°Ï첿ÃÅÔì×÷¹¤³§ÔËÓªµÄÍøÂç¹¥»÷ÊÂÎñ¡£Õâ´Î¹¥»÷ÓÚ2025Äê9ÔÂ2ÈÕ³õ´Î±»±¨Â·£¬Éæ¼°ÄÏ¿¨ÂÞÀ´ÄÉÖݰ¬¿ÏÏØÁ½¼Ò¹¤³§¼°¼ÓÄôó¿ý±±¿ËÊ¡ÇÇÀû°£¼éϸ³§£¬Òý·¢³ö²úÖжϡ£BSA×÷ΪÆÕÀû˾ͨ¼¯ÍųÁÒª·ÖÖ§£¬Õ¼ÓÐ50¼Ò¹¤³§¡¢5.5ÍòÃûÔ±¹¤£¬Õ¼¼¯ÍÅ×ܹæÄ£43%£¬2024ÄêÏúÊÛ¶î´ï120ÒÚÃÀÔª£¬ÓªÒ·ûÈó12ÒÚÃÀÔª¡£ÆÕÀû˾ͨǿµ÷£¬Æä¼±¾çÏìÓ¦»úÔìÔÚÔçÆÚ½×¶ÎÓÐЧ¶ôÔìÁ˹¥»÷ÊæÕ¹£¬Ô¤·À¿Í»§Êý¾Ýй¶»òÉî¶ÈÍøÂçÉøÈë¡£¹«Ë¾ÉêÃ÷³Æ£¬ÍŶÓÒѰ´¼È¶¨ºÍ̸½ÚÔìÎÊÌ⣬ȡ֤·ÖÎöÈÔÔÚ½øÐУ¬µ«³õ²½ÅжÏÊÂÎñÓ°ÏìÓÐÏÞ£¬Î´·¢ÏÖ¿Í»§Êý¾Ý»òϵͳ½Ó¿ÚÔâй¶¡£Îª¼õÇṩ¸øÁ´·çÏÕ£¬Ô±¹¤Õý24Ó×ʱ¹¤×÷ÒÔ¸´ÔÔËÓª£¬È·±£Êг¡²úÆ·¹©¸ø²»±ä¡£ÆÕÀû˾ͨ½«¡°Î¬³ÖÒµÎñÂ½ÐøÐÔ¼°±£»¤Êý¾Ý½Ó¿Ú¡±ÁÐΪÊ×Òª¹¤×÷£¬²¢³ÐÅµÍÆ¹ã¿Í»§Ê¹Ãü£¬½â¾öDZÔÚºóÐøÓ°Ïì¡£Õë¶ÔýÌåѯÎÊÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ¹¥»÷£¬¹«Ë¾ÉÐδ»ØÓ¦£¬Ä¿Ç°Ò²ÎÞÈκÎÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´ÎÊÂÎñÕÆ¹Ü¡£
https://www.bleepingcomputer.com/news/security/tire-giant-bridgestone-confirms-cyberattack-impacts-manufacturing/


¾©¹«Íø°²±¸11010802024551ºÅ