²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ¶³ö

°ä²¼¹¦·ò 2025-09-12

1. ²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ¶³ö


9ÔÂ10ÈÕ£¬²®Ã÷º²¶¼îì¸ñÀ¼ÆæÖÐѧ½üÆÚ²úÉúһ·ÑϳÁÊý¾Ýй¶ÊÂÎñ£¬Ó°Ïì7ÖÁ11Äê¼¶£¨11-16Ë꣩Êý°ÙÃûѧÉú¡£¾ÝѧÌÃÏò¼Ò³¤·¢Ë͵ÄÓʼþ¼°ºóÐøÉêÃ÷£¬Ð¹Â¶Ô´ÓÚÒ»·ÝÔ̺¬Ñ§ÉúÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¼°¸¸Ä¸ÁªÏµ·½Ê½µÄµç×Ó±í¸ñ±»ÃýÎó¹²Ïí¡£¸Ã±í¸ñ±¾ÓÃÓÚÁ÷¸ÐÒßÃç½ÓÖÖÔÞ³ÉÁ÷³Ì£¬µ«¼Ò³¤µã»÷ÓʼþÁ´½Óºó¿ÉÖ±½ÓÏÂÔØ£¬µ¼ÖÂÃô¸ÐÐÅϢ¶³ö¡£ÊÂÎñ²úÉúÓÚ±¾µØ¹¦·ò9ÔÂ8ÈÕ9:50ÖÁ9:59ÆÚ¼ä£¬½öÄÜͨ¹ýѧÌÃBromcomÄÚÁªÍø½Ó¼û¸Ã±í¸ñµÄÈËÔ±¿É¼û¡£¾Ýµ±¾Öͳ¼Æ£¬¸ÃУ¹²ÓÐ1198ÃûѧÉú£¬µ«Õâ´Îй¶¾ßÌåÉæ¼°7-11Ä꼶ѧÉúÊý¾Ý¡£Êܺ¦¼Ò³¤·´Ó³£¬µç×Ó±í¸ñ¼Í¼ÁË"Õû¸öѧÌõÄÐÅÏ¢"£¬Òý·¢¶Ôº¢×ÓÉí·Ý͵ÇÔ¡¢Ú¿Æ­µÈ°²È«·çÏÕµÄÓÇÓô¡£Ñ§ÌÃÔÚÉêÃ÷ÖаµÊ¾ÒѲÉÈ¡´¹Î£´ëÊ©£ºµ±¼´ÁªÏµÖÎÀíÐÅϢϵͳ£¨MIS£©ÌṩÉ̳·»Ø²¢É¾³ýй¶ÐÅÏ¢£¬ÒªÇóÊÕµ½±í¸ñµÄ¼Ò³¤¾¡¿ìɾ³ýÊý¾Ý£¬²¢ÏòÐÅÈÎÊý¾Ý±£»¤¹Ù»ã±¨ÊÂÎñ¡£Êý¾Ý±£»¤¹ÙÕýµ÷²éÎ¥¹æÏ¸½Ú£¬±ØÒªÊ±½«ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬Í¬Ê±Ôì¶©Ô¤·À´ëʩԤ·ÀÀàËÆÊÂÎñ¸´·¢¡£


https://www.theregister.com/2025/09/10/birmingham_school_data_blunder/


2. AsyncRATÀûÓÃConnectWise ScreenConnectÇÔȡƾ֤ºÍ¼ÓÃÜÇ®±Ò


9ÔÂ11ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾LevelBlueÅû¶ÁËһ·ÀûÓúϷ¨Ô¶³ÌÖÎÀí¹¤¾ßConnectWise ScreenConnectÌáÒéµÄ¸ß½×ÎÞÎļþ¹¥»÷»î¶¯¡£¸Ã¹¥»÷ͨ¹ý¶È½×¶Î¾ç±¾Ö´ÐУ¬×îÖÕ²¿ÊðAsyncRATÔ¶³Ì½Ó¼ûľÂí£¬ÊµÏÖÃô¸ÐÊý¾ÝÇÔÈ¡ÓëÓÆ¾Ã»¯½ÚÔì¡£¹¥»÷ÕßÊ×ÏÈÀûÓô¹µöÓʼþ¼Ù×°³É²ÆÕþ/óÒ×Îļþ£¬ÓÕµ¼Êܺ¦ÕßÏÂÔØ±»Ä¾ÂíϰȾµÄScreenConnect×°Ö÷¨Ê½¡£Ò»µ©×°Ö㬹¥»÷Õßͨ¹ýScreenConnect»ñȡԶ³Ì½Ó¼ûȨÏÞ£¬²¢Æô¶¯¼üÅ̼ͼ»î¶¯Ö´ÐÐVBScriptÓÐЧ¸ºÔØ¡£¸Ã¾ç±¾Í¨¹ýPowerShell´Ó¹¥»÷Õß½ÚÔìµÄ·þÎñÆ÷ÏÂÔØÁ½¸ö±í²¿Ôغɣº"logs.ldk"£¨DLLÎļþ£©ºÍ"logs.ldr"£¨»ìºÏ×é¼þ£©¡£DLLÎļþÕÆ¹Ü½«VB¾ç±¾Ð´Èë´ÅÅÌ£¬²¢ÀûÓôòË㹤×÷¼Ù×°³É"Skype¸üз¨Ê½"£¬ÔÚÿ´ÎϵͳµÇ¼ʱ×Ô¶¯Ö´ÐУ¬ÊµÏÖÒñ±ÎÓÆ¾Ã»¯¡£½øÒ»²½·ÖÎöÏÔʾ£¬PowerShell¾ç±¾½«"logs.ldk"¼ÓÔØÎª.NET·¨Ê½¼¯£¬²¢´«Èë"logs.ldr"×÷Ϊ²ÎÊý£¬×îÖÕÖ´ÐÐAsyncRATµÄÖ÷ÌâÓÐЧ¸ºÔØ"AsyncClient.exe"¡£¸ÃľÂí¾ß±¸¶àÏî¸ßΣְÄÜ£º¼Í¼»÷¼ü¡¢ÇÔÈ¡ä¯ÀÀÆ÷Í´´¦¡¢²É¼¯ÏµÍ³Ö¸ÎÆ¡¢É¨Ãè¼ÓÃÜÇ®±ÒÇ®°ü£¬²¢Í¨¹ýTCPÌ×½Ó×Ö½«Êý¾Ý»Ø´«ÖÁC2·þÎñÆ÷¡£


https://thehackernews.com/2025/09/asyncrat-exploits-connectwise.html


3. Vyro AIÊý¾Ýй¶£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì


9ÔÂ10ÈÕ£¬°²È«×êÑÐÈËÔ±·¢ÏÖ£¬°Í»ù˹̹AI¹«Ë¾Vyro AIÒòδÊܱ£»¤µÄElasticsearchÊ·ýй¶116GBÓû§ÈÕÖ¾£¬Éæ¼°Èý¿îÈȵãÀûÓãºGoogle PlayÏÂÔØÁ¿³¬1000Íò´ÎµÄImagineArt¡¢³¬10Íò´ÎÏÂÔØµÄChatly¼°Ô½ӼûÔ¼5Íò´ÎµÄChatbotx¡£¸Ã¹«Ë¾Ðû³Æ×ÜÏÂÔØÁ¿³¬1.5ÒڴΣ¬Ã¿ÖÜÌìÉú350ÍòÕÅͼƬ¡£Ð¹Â¶Êý¾Ýº­¸Ç2-7ÌìµÄ³ö²úÓ뿪·¢ÈÕÖ¾£¬Ô̺¬Óû§AIÌáÐÑ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢Óû§´úÀíµÈÃô¸ÐÐÅÏ¢¡£¸ÃÊý¾Ý¿â×Ô2ÔÂÖÐÑ®±»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬¿ÉÄÜÒѱ»¹¥»÷Õß·¢ÏÖÊýÔ¡£Õâ´Îй¶·çÏÕÏÔÖø£º¹¥»÷Õß¿ÉÀûÓÃÁîÅÆ½Ù³ÖÓû§ÕË»§£¬½Ó¼û̸Ìì¼Í¼¡¢ÌìÉúͼÏñ£¬ÉõÖÁÀÄÓÃAI´ú±Ò½øÐз¸·¨ÂòÂô£»Óû§ÓëAIµÄ˽ÃܶԻ°¿ÉÄܶ³ö´Óδ¹«¿ªµÄÃô¸ÐÄÚÈÝ¡£ÀýÈ磬ImagineArtµÄ3000Íò»îÔ¾Óû§Êý¾ÝÈô±»ÀûÓ㬽«µ¼Ö´ó¹æÄ£ÕË»§ÊÕÊÜ·çÏÕ¡£


https://cybernews.com/security/ai-chatbots-vyro-data-leak/


4. Allegis GroupÔâEverestÀÕË÷¹¥»÷£¬°ÙÍò¼¶¿Í»§Êý¾Ýй¶


9ÔÂ10ÈÕ£¬È«Çò×î´óÈ˲ÅÖÎÀí¼¯ÍÅÖ®Ò»¡¢ÄêÊÕÈë½ü100ÒÚÃÀÔªµÄAllegis Group½üÈÕÔâ·êEverestÀÕË÷Èí¼þÍŻ﹥»÷¡£¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÉÏÐû³Æ»ñÈ¡ÁËAllegisÄÚ²¿Îļþ¼°¿Í»§Ãûµ¥£¬²¢°ä²¼Á½ÕÅExcelÎĵµ½ØÍ¼×÷Ϊ֤¾Ý£¬ÆäÖÐÒ»ÕÅÔ̺¬13.5ÍòÌõ¿Í»§ÐÅÏ¢£ºÐÕÃû¡¢ÓÊÏä¡¢µç»°£¬ÁíÒ»ÕÅÔ̺¬¶à´ï42.6ÍòÌõÀàËÆÊý¾Ý¡£´ËÀàÐÅÏ¢¿ÉÄܱ»ÀûÓýøÐÐÍøÂç´¹µö¹¥»÷¡£EverestÍÅ»ïÓë¶íÂÞ˹¹ØÁª£¬×Ô2021Äê»îÔ¾ÒÔÀ´ÒѳÉΪ×î·è¿ñµÄÀÕË÷×éÖ¯Ö®Ò»¡£¾Ý°µÍø¼à¿Ø¹¤¾ßRansomlookerͳ¼Æ£¬¸ÃÍÅ»ï´Óǰ12¸öÔ¹¥»÷Á˳¬°Ù¸ö×éÖ¯£¬·ÖÅúй¶Êý¾ÝÊÇÆäµäÐÍʩѹ¼¿Á©£¬Ö¼ÔÚÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£AllegisÆìÏÂÕ¼ÓÐAerotek¡¢TEKsystems¡¢MarketSourceµÈ¶à¼ÒרҵÈ˲ÅÖÎÀí×Ó¹«Ë¾£¬·þÎñÍøÂ縲¸ÇÈ«Çò¡£Ö»¹Ü¹«Ë¾ÒÑ»ØÓ¦³Æ½«¸üнøÕ¹£¬µ«¹¥»÷ÕßÌá¼°µÄ¡°ÖÖÀà·±¶àµÄÓ×ÎÒÎĵµ¡±ÉÐδ¹«¿ªÑù±¾£¬Ç±ÔÚ·çÏÕ¿ÉÄÜÔ¶³¬ÒÑÆØ¹âµÄÁªÏµÐÅÏ¢¡£


https://cybernews.com/security/allegis-group-data-breach-claims/


5. AkiraÀÕË÷Èí¼þÍÅ»ïÀûÓÃSonicWall·ì϶ÌáÒéÐÂÒ»ÂÖ¹¥»÷


9ÔÂ11ÈÕ£¬AkiraÀÕË÷Èí¼þÍÅ»ïÕý»ý¼«ÀûÓÃCVE-2024-40766ÕâÒ»ÒÑ´æÔÚÒ»ÄêµÄÑϳÁ½Ó¼û½ÚÔì·ì϶£¬¶Ô佨²¹µÄSonicWall SSL VPNÉ豸ÌáÒé¹¥»÷¡£¸Ã·ì϶ÔÊÐíδ¾­ÊÚȨµÄ×ÊÔ´½Ó¼û£¬ÉõÖÁ¿ÉÄܵ¼Ö·À»ðǽ±ÀÀ£¡£SonicWallÔçÔÚ2024Äê8Ô±ã°ä²¼Á˲¹¶¡£¬²¢Ç¿µ÷¸üÐÂʱÐèΪ±¾µØÖÎÀíµÄSSLVPNÕË»§Óû§³ÁÖÃÃÜÂ룬µ«²¿ÃÅ×é֯δ³¹µ×Ö´Ðв¹¾È´ëÊ©£¬µ¼ÖÂÍþвÐÐΪÕßÈÔÄÜÀûÓö³öµÄÍ´´¦ÅäÖöà³É·ÖÉí·ÝÑéÖ¤£¨MFA£©»ò»ùÓÚ¹¦·òµÄÒ»´ÎÐÔÃÜÂ루TOTP£©ÏµÍ³£¬½ø¶ø»ñÈ¡½Ó¼ûȨÏÞ¡£°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©ÓÚ2025Äê9Ô·¢³ö¾¯±¨£¬Ö¸³ö°Ä´óÀûÑǾ³ÄÚÕë¶Ô¸Ã·ì϶µÄ×Ô¶¯ÀûÓûÏÔÖøÔö³¤£¬²¢Ã÷È·½«AkiraÀÕË÷Èí¼þÓëSonicWall SSL VPN¹¥»÷¹ØÁª¡£ÍøÂ簲ȫ¹«Ë¾Rapid7Ò²¹Û²ìµ½ÀàËÆÇ÷Ïò£¬ÒÔΪ¹¥»÷¼¤Ôö¿ÉÄÜÓë²»ÆëÈ«µÄ²¹¾È´ëÊ©ÓйØ£¬¾ßÌåÈëÇÖ¼¿Á©Ô̺¬ÀûÓÃĬÈÏÓû§×éµÄ¿í·º½Ó¼ûȨÏÞ½øÐÐÉí·ÝÑéÖ¤£¬ÒÔ¼°Í¨¹ýSonicWallÉ豸ÉÏÐé¹¹°ì¹«ÊÒÃÅ»§µÄĬÈϹ«¹²½Ó¼ûȨÏÞÖ´Ðй¥»÷¡£


https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/


6. LNERµÚÈý·½¹©¸øÉÌÔâÍøÂç¹¥»÷Ö³˿ÍÊý¾Ýй¶


9ÔÂ11ÈÕ£¬Ó¢¹úÁгµÔËÓªÉÌÂ׶ض«±±Ìú·¹«Ë¾£¨LNER£©ÓÚ9ÔÂ10ÈÕÈ·ÈÏ£¬ÆäµÚÈý·½¹©¸øÉÌÔâ·êÍøÂç¹¥»÷£¬µ¼Ö²¿Ãų˿͵ÄÁªÏµ·½Ê½¼°¹ýÍùÐгÌÊý¾Ýй¶£¬µ«Î´Éæ¼°²ÆÕþÐÅÏ¢¡¢ÃÜÂë»òÖ§¸¶¿¨Êý¾Ý¡£LNERÇ¿µ÷£¬ÆäÁгµ·þÎñ¡¢ÊÛÆ±ÏµÍ³ÊµÊ±¿Ì±í¾ùÕý³£ÔËÐУ¬²¢ÒÑÓëÍøÂ簲ȫר¼ÒºÍÓйع©¸øÉ̺Ï×÷µ÷²éÊÂÎñȫò£¬Í¬Ê±ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒÒÔÆÀ¹ÀÊÇ·ñÇкϡ¶Í¨ÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©µÄ»ã±¨ÒªÇó£¬Èô±£ÏÕ´ëÊ©²»¼°¿ÉÄÜÃæ¶Ô·£¿î¡£Ð¹Â¶µÄÓ×ÎÒÊý¾Ý¿ÉÄܱ»ÓÃÓÚ¹¹½¨¾ßÌåÓ×ÎÒ»­Ïñ£¬½ø¶øÌáÒé´¹µö¹¥»÷£¬Èçͨ¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òWhatsAppÓÕÆ­Óû§Ìṩ²ÆÕþ»òÓ×ÎÒÐÅÏ¢¡£LNERÒѶ½´Ù³Ë¿Í¶ÔÒâ±íͨѶά³Ö¾¯Ì裬ÓÈÆäÉæ¼°Ó×ÎÒÐÅÏ¢ÒªÇóµÄÓʼþ»òÐÅÏ¢£¬ÇÐÎðµÈÏлظ´¡£¹«Ë¾°µÊ¾½«¸ß¶ÈÆ÷³Á´ËÊ£¬³ÖÐøÓëר¼ÒºÏ×÷²¢²ÉÈ¡±£ÏÕ´ëÊ©£¬ºóÐø½«Ìṩ¸ü¶à¸üÐÂÐÅÏ¢¡£


https://hackread.com/uk-rail-operator-lner-cyber-attack-passenger-data/