ʥԼɪ·òÊÐÔâÑϳÁÍøÂç¹¥»÷ÖÂÊý¾Ýй¶¼°·þÎṉ̃»¾
°ä²¼¹¦·ò 2025-09-111. ʥԼɪ·òÊÐÔâÑϳÁÍøÂç¹¥»÷ÖÂÊý¾Ýй¶¼°·þÎṉ̃»¾
9ÔÂ8ÈÕ£¬ÃÜËÕÀïÖÝʥԼɪ·òÊÐ6Ô³õÔâ·ê³Á´óÍøÂç¹¥»÷£¬µ¼ÖÂÍøÂç·þÎñ³Ö¾Ã̱»¾²¢¿ÉÄÜй¶Êýǧ¾ÓÃñÓ×ÎÒÊý¾Ý¡£ÊÂÎñÓÚ6ÔÂ9ÈÕÁ賿2:30³õ´Î±»·¢ÏÖ£¬Êе±¾ÖËæ¼´¹Ø¹ØËùÓÐÍøÂç²¢Æô¶¯µ÷²é£¬È·ÈϹ¥»÷Éæ¼°Êý¾Ýй¶£¬Ó°ÏìÔ̺¬¾¯Ô±¾Ö¡¢ÎÀÉú²¿Ãż°ÊÐÃñ¸¶¿îϵͳµÈ¹Ø¼ü²¿ÃÅ¡£µ÷²éÏÔʾ£¬¹¥»÷µ¼ÖÂÊÖ»úͨѶÖжϡ¢µç×ÓÓʼþÎÞ·¨½Ó¼û¡¢Îļþϵͳ̱»¾£¬Ô±¹¤±»ÆÈʹÓÃÓ×ÎÒÉ豸´¦Öù«Îñ£¬´æÔÚÑϳÁ°²È«Òþ»¼¡£¾µç×Óµ÷²éÈ·ÈÏ£¬Ô¼11,000Ãû¾ÓÃñµÄÓ×ÎÒÐÅÏ¢¿ÉÄܱ»Î´¾ÊÚȨ»ñÈ¡£¬Êе±¾ÖÒÑÆô¶¯Í¨Öª·¨Ê½£¬ÌṩÐÅÓþ¼à¿Ø¼°Éí·Ý͵ÇÔ±£»¤·þÎñ£¬²¢ÉèÁ¢ºô½ÐÖÐÐÄÐÖúÊÜÓ°Ïì¾ÓÃñ¡£ÎªÓ¦¶ÔÊÂÎñ£¬Êе±¾ÖͶÈ볬100ÍòÃÀÔªÉý¼¶ÍøÂ簲ȫ»ù´¡ÉèÊ©¡£Ö»¹ÜÊÂÎñδµ¼Ö¹«¹²·þÎñÖжϣ¬µ«ÄÚ²¿ÔËÓª»ìÂÒ³ÖÐøÊýÖÜ£¬²¿ÃÅÁ÷³ÌÖÁ½ñδÆëÈ«¸´Ô¡£ÀýÈ磬¾¯Ô±¾ÖÖðÈÕ°¸¼þ»ã±¨×Ô6ÔÂ8ÈÕÆðÖÕ³¡°ä²¼£¬Ó°Ï칫¼ÒÖªÇéȨ¡£´Ë±í£¬Ô±¹¤Ê¹ÓÃÓ×ÎÒÉ豸´¦Öù«ÎñÒý·¢Êý¾Ý°²È«ÓÇÓô£¬Êе±¾ÖÒѲ»ÈÝ´ËÀàÐÐΪ¡£
https://www.newspressnow.com/news/top-stories/2025/09/08/city-of-st-joseph-hit-by-cyberattack-data-potentially-acquired/
2. TenableÔâSalesforce¹©¸øÁ´¹¥»÷й¶¿Í»§Êý¾Ý
9ÔÂ8ÈÕ£¬Tenable¹«Ë¾½üÈÕÈ·ÈϲúÉúÊý¾Ýй¶ÊÂÎñ£¬²¿Ãſͻ§ÁªÏµÐÅÏ¢¼°Ö§³Ö°¸ÀýÊý¾ÝÔâδ¾ÊÚȨ½Ó¼û¡£Õâ´ÎÊÂÎñÔ´ÓÚÕë¶ÔSalesforceÓëSalesloft DriftÓªÏúÀûÓü¯³ÉµÄ¿í·ºÊý¾Ý͵ÇԻ£¬¸Ã·ì϶ÒÑÓ°Ïì¶à¼Ò³ÛÃûÆóÒµ¡£Ð¹Â¶Êý¾Ý½öÏÞÓÚTenableµÄSalesforce»·¾³£¬¾ßÌåÔ̺¬¿Í»§ÐÕÃû¡¢Ã³Ò×ÓÊÏä¡¢µç»°ºÅÂë¡¢ÕË»§ÇøÓòλÏàÐÅÏ¢£¬ÒÔ¼°Ö§³Ö°¸ÀýµÄÖ÷ÌâÐкͳõʼÃèÊö¡£TenableÇ¿µ÷ÆäÖ÷Ìâ²úÆ·¼°Êý¾ÝδÊÜÓ°Ï죬µ«ÊÂÎñ¶³öÁËÆóÒµÒµÎñƽ̨ÖеÚÈý·½ÀûÓü¯³É´æÔڵݲȫÒþ»¼¡£¾µ÷²é£¬Õâ´Î¹¥»÷Ó밲ȫר¼Ò×·×ٵĸ´ÔÓ¹¥»÷»î¶¯Óйأ¬¹¥»÷ÕßÀûÓÃSalesforceÓëSalesloft Drift¼¯³É·ì϶£¬ÇÔÈ¡¶à¼Ò¹«Ë¾µÄSalesforceÊ·ýÊý¾Ý¡£ÊÂÎñ²úÉúºó£¬TenableѸ¿ì²ÉȡӦ¶Ô´ëÊ©£º³·Ïú²¢ÂÖ»»¿ÉÄÜй¶µÄƾ֤£¬½ûÓÃSalesloft Drift¼°Óйؼ¯³ÉÀûÓã¬Ç¿»¯Salesforce»·¾³¼°ÆäËûÏνÓϵͳµÄ°²È«·À»¤£¬ÀûÓÃÒÑÖª·çÏÕÖ¸±ê£¨IoC£©¼ø±ð¶ñÒâ»î¶¯£¬²¢³ÖÐø¼à¿ØSaaS½â¾ö¹æ»®ÒÔ¼ì²âÒì³£¡£¹«Ë¾ºôÓõ¿Í»§Î¬³Ö¾¯Ì裬×ñѰ²È«×¨¼Ò½¨Òé±£»¤ÏµÍ³¡£
https://cybersecuritynews.com/tenable-confirms-data-breach/
3. DynatraceÔâSalesforce¹©¸øÁ´¹¥»÷Ö¿ͻ§Êý¾Ýй¶
9ÔÂ9ÈÕ£¬Èí¼þÖÇÄܾÞÍ·Dynatrace½üÈÕÈϿɣ¬ÔÚ2025Äê×î´ó¹æÄ£µÄ¹©¸øÁ´ºÚ¿Í¹¥»÷ÊÂÎñÖУ¬Æä¿Í»§Êý¾ÝÒòµÚÈý·½¹¤¾ß·ì϶Ô⵽й¶¡£Õâ´ÎÊÂÎñÔ´ÓÚÒ»¿î¿í·ºÊ¹ÓõÄÈËΪÖÇÄÜÓªÏú̸Ìì»úеÈËSalesloft DriftÓëSalesforce CRMϵͳµÄ¼¯³É·ì϶¡£ºÚ¿Íͨ¹ý¸Ã·ì϶·¸·¨½Ó¼ûÁËDynatraceµÄSalesforceÊ·ý£¬µ¼Ö¿ͻ§ÐÕÃû¡¢¹«Ë¾±êʶ·ûµÈÒµÎñÁªÏµÊý¾Ý±íй¡£DynatraceÇ¿µ÷£¬ÆäÖ÷Ìâ²úÆ·¼°·þÎñϵͳδÊÜÓ°Ï죬½öÉæ¼°¿Í»§ÖÎÀíºÍÓªÏúÓô¦µÄCRMƽ̨¡£×÷Ϊ×ܲ¿Î»ÓÚÃÀ¹úÓë°ÂµØÀûµÄ¿ç¹úÆóÒµ£¬DynatraceµÄ¿Í»§ÈºÌ庸ǵ±¾Ö¡¢º½¿Õ¼°½ðÈÚÁìÓò£¬Ô̺¬¼ÓÄô󺽿ա¢°Ä´óÀûÑǵ±¾Ö¡¢Â·Ã÷ÒøÐеȳÛÃû»ú¹¹£¬ÄêÊÕÈë´ï15.1ÒÚÅ·Ôª¡£Õâ´ÎÊÂÎñ²¢·Ç¹ÂÁ¢°¸Àý£¬¶øÊǽüÆÚÕë¶ÔSalesforceÉú̬µÄÁ¬Ëø¹¥»÷º£³±µÄÒ»²¿ÃÅ¡£µ÷²éÏÔʾ£¬¹¥»÷Õßͨ¹ýÀÄÓÃSalesloft DriftÓëSalesforce¼°ÆäËûƽ̨µÄ¼¯³É½Ó¿Ú£¬ÊµÏÖÁ˶Զà×éÖ¯Ãô¸ÐÊý¾ÝµÄºáÏòÉøÈë¡£ºÚ¿Í×é֯ͬÃË¡°Scattered LapSus$ Hunters¡±Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£ÊÂÎñ²úÉúºó£¬SalesloftÒÑÁÙʱÏÂÏßDriftÀûÓ÷¨Ê½£¬DynatraceÔòѸ¿ì½ûÓÃÓйؼ¯³É²¢Ç¿»¯ÏµÍ³°²È«¡£
https://cybernews.com/security/dynatrace-salesloft-drift-breach/
4. KillSecÀÕË÷Èí¼þÒý·¢°ÍÎ÷Ò½Áƹ©¸øÁ´Êý¾Ýй¶Σ»ú
9ÔÂ10ÈÕ£¬KillSecÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô°ÍÎ÷Ò½ÁƱ£½¡Èí¼þÌṩÉÌMedicSolutionµÄÍøÂç¹¥»÷ÕÆ¹Ü£¬²¢ÍþвÈô²»µ±¼´½»É潫й¼ûô¸ÐÊý¾Ý¡£Õâ´ÎÊÂÎñ±¾ÔÔÚÓÚÒ½ÁÆ»ú¹¹AWS S3´æ´¢Í°ÅäÖò»µ±£¬µ¼ÖÂÊý¾Ýй¶´°¿Ú³¤´ïÊýÔ£¬±»ÊÓΪ°ÍÎ÷Ò½ÁÆÐÐÒµÊ×Àý³Á´ó¹©¸øÁ´°²È«ÊÂÎñ¡£¸Ã×éÖ¯´ËǰÒÑÂÅ´ÎÕë¶Ô°ÍÎ÷£ºÔøÐ¹Â¶µ±²¿ÃÅÃÅÓ×ÎÒ¼°ÆóÒµÊý¾Ý£¨º¬CNPJ/CPF±êʶ·û¡¢ÒøÐÐÐÅÏ¢£©£¬µ«Î´Ã÷È·È«ÊýÁìÓò¡£±¾´Î¹¥»÷ÖУ¬±»µÁÊý¾Ý³¬34GB£¬Ô̺¬94,818¸öÎļþ£¬Éæ¼°³¢ÊÔÊÒÁ˾֡¢XÉäÏßͼÏñ¡¢»¼Õßδɾ½ÚÕÕÆ¬¼°Î´³ÉÄêÈ˼ͼµÈÒþÖÔÐÅÏ¢¡£ResecurityÈ·ÈÏ»¼Õß¾ùδ¾õ²ìй¶£¬Í¹ÏÔÒñ±ÎÐÔ·çÏÕ¡£KillSecÔÚÏ®»÷°ÍÎ÷ǰ£¬ÒÑÈëÇÖ¸çÂ×±ÈÑÇ¡¢ÃØÂ³¡¢ÃÀ¹úµÈ¶à¸öÒ½ÁÆ»ú¹¹£¬Ò½ÁÆÊý¾ÝÒòÔ̺¬Éí·Ý¡¢²¡Ê·¡¢±£ÏÕ¼°Ö§¸¶ÐÅÏ¢£¬³ÉΪ¸ß¼ÛÖµÖ¸±ê¡£
https://securityaffairs.com/182063/cyber-crime/killsec-ransomware-is-attacking-healthcare-institutions-in-brazil.html
5. Å·ÖÞDDoS»º½â·þÎñÉÌÔâÊ·ÉÏ×î¸ßÊý¾Ý°ü¿ìÂʹ¥»÷
9ÔÂ10ÈÕ£¬Å·ÖÞÒ»¼ÒDDoS»º½â·þÎñÌṩÉÌÔâ·ê´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷£¬¹¥»÷¿ìÂʴﵽÿÃë15ÒÚ¸öÊý¾Ý°ü£¨1.5 Gpps£©£¬³ÉΪ¹«¿ªÅû¶µÄ×î´óÊý¾Ý°ü¿ìÂʺéË®¹¥»÷Ö®Ò»¡£Õâ´Î¹¥»÷Ô´×ÔÊýǧ̨ÊÜϰȾµÄÎïÁªÍøÉ豸ºÍMikroTik·ÓÉÆ÷£¬ÓÉÍøÂ簲ȫ¹«Ë¾FastNetMon³É¹¦»º½â¡£FastNetMonÔÚÐÂΟåÖÐÖ¸³ö£¬¶ñÒâÁ÷Á¿ÖØÒªÎªUDPºéË®¹¥»÷£¬Ó°ÏìÈ«Çò³¬¹ý11,000¸ö¹ÖÒìÍøÂç¡£¹¥»÷Ö¸±êËäδ¹«¿ª£¬µ«±»ÃèÊöΪһ¼ÒDDoSÏ´åªÌṩÉÌ£¬Æä·þÎñͨ¹ýÊý¾Ý°ü²é³¡¢¿ìÂÊÏÞ¶È¡¢ÑéÖ¤ÂëºÍÒì³£¼ì²âµÈ¼¼Êõ¹ýÂ˶ñÒâÁ÷Á¿¡£Õâ´Î¹¥»÷±»ÊµÊ±¼ì²âºó£¬Í¨¹ýÔÚ±ßԵ·ÓÉÆ÷²¿Êð½Ó¼û½ÚÔìÁÐ±í£¨ACL£©µÈ´ëʩʵÏÖ»º½â¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ´Î¹¥»÷²úÉúǰ¼¸ÈÕ£¬»¥ÁªÍø»ù´¡ÉèÊ©¾ÞÍ·Cloudflare°ä·¢×èÖ¹ÁËÊ·ÉÏ×î´ó¹æÄ£DDoS¹¥»÷£¬·åÖµ´ïÿÃë11.5Ì«±ÈÌØ£¨Tbps£©ºÍ51ÒÚ¸öÊý¾Ý°ü£¨Bpps£©¡£Á½´Î¹¥»÷¾ùÖ¼Ôںľ¡½Ó¹Ü¶Ë´¦ÖÃÄÜÁ¦£¬µ¼Ö·þÎñÖжϡ£FastNetMonÊ×´´ÈËPavel OdintsovÇ¿µ÷£¬´ËÀà´ó¹æÄ£¹¥»÷Ç÷ÏòÒѼ«¶ËΣÏÕ£¬ÐèÔÚ»¥ÁªÍø·þÎñÌṩÉÌ£¨ISP£©²ãÃæÖ´ÐйýÎÊ£¬×èÖ¹ÊÜϰȾÏû·Ñ¼¶Ó²¼þ±»´ó¹æÄ£±øÆ÷»¯¡£
https://www.bleepingcomputer.com/news/security/ddos-defender-targeted-in-15-bpps-denial-of-service-attack/
6. Hello GymÊý¾Ý¿âй¶ÊÂÎñ£º°ÙÍò»áÔ±¹àÒô¶³ö
9ÔÂ10ÈÕ£¬Ã÷ÄáËÕ´ïÖݽ¡Éí¼¼Êõ·þÎñ¹«Ë¾Hello GymÖÎÀíµÄδÊÜÃÜÂë±£»¤Êý¾Ý¿â²úÉúÑϳÁÊý¾Ýй¶£¬ÆäÖÐÔ̺¬2020ÄêÖÁ2025Ä곬160Íò·Ý½¡Éí·¿»áÔ±µÄµç»°¹àÒôºÍÓïÒôÓʼþ¡£×êÑÐÔ±Jeremiah Fowler·¢ÏÖ£¬¸ÃÊý¾Ý¿â´æ´¢ÓÚÎÞ±£»¤ÇøÓò£¬ÎÞÐèÈÏÖ¤¼´¿É»ñÈ¡Ô̺¬¹Ë¿ÍÐÕÃû¡¢µç»°ºÅÂë¼°ÖµçÔÒòµÈÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©µÄ1,605,345¸öÒôƵÎļþ£¬Éæ¼°ÃÀ¹ú¡¢¼ÓÄôó¶àµØ½¡Éí·¿£¬²¿ÃżÍ¼Ìá¼°³ÛÃû½¡ÉíÆ·ÅÆ¡£Õâ´Îй¶ԴÓÚµÚÈý·½³Ð°üÉÌHello GymµÄ°²È«Êè©£¬Ö»¹Ü¹«Ë¾×ÔÉí²»Ö±½Ó¹àÒô£¬µ«¶ÀÁ¢¼ÓÃËÉÌʹÓõĵÚÈý·½·þÎñÓÉÆäÖÎÀí£¬µ¼ÖÂÃô¸ÐÊý¾Ý¶³ö¡£ÊÂÎñÔÚ×êÑÐÈËÔ±Åû¶ºóÊýÓ×ʱÄÚ±»½¨¸´£¬µ«Â¶³öʱ³¤¼°ÊÇ·ñ±»ËûÈ˽ӼûÈÔδ֪¡£Ð¹Â¶µÄÒôƵÊý¾ÝÓµÓм«¸ß·çÏÕ¼ÛÖµ¡£Ú¿ÆÕß¿ÉÀûÓùàÒôÖеľßÌåϸ½ÚÖ´ÐÐÓã²æÊ½ÍøÂç´¹µö£¬¼ÙÒ⽡Éí·¿¹¤×÷ÈËÔ±ÓÕÆ»áԱй¶֧¸¶ÐÅÏ¢»òÃô¸ÐÊý¾Ý£»ÓïÒôÓʼþÖеÄÓ×ÎÒÐÅÏ¢¿É±»ÓÃÓÚÉç»á¹¤³Ì¹¥»÷£¬³ÉÁ¢ÐÅÀµºóÆÈ¡¸ü¶àÒþÖÔ£»¸üÑϳÁµÄÊÇ£¬ÈËÉù¹àÒô¿É±»ÓÃÓÚÔì×÷¡°Éî¶ÈαÔ족ÒôƵ£¬Ö´ÐÐÉí·Ý¼ÙÒâ»ò½ðÈÚÚ¿Æ¡£
https://hackread.com/hello-gym-data-leak-audio-files-of-gym-members/


¾©¹«Íø°²±¸11010802024551ºÅ