·Ñ¶ûÃÉÌØÐÅÓþºÏ×÷ÉçÔâ´ó¹æÄ£Êý¾Ýй¶
°ä²¼¹¦·ò 2025-09-161. ·Ñ¶ûÃÉÌØÐÅÓþºÏ×÷ÉçÔâ´ó¹æÄ£Êý¾Ýй¶
9ÔÂ13ÈÕ£¬·Ñ¶ûÃÉÌØÁª¹úÐÅÓþºÏ×÷É磨FFCU£©½üÈÕ´«µÝһ·ÑϳÁÊý¾Ýй¶ÊÂÎñ£¬Éæ¼°³¬18.7ÍòÃû¿Í»§£¬Ð¹Â¶ÐÅÏ¢º¸Ç´Ó»ù´¡Éí·ÝÐÅÏ¢µ½Ò½Áƽ¡È«Êý¾ÝµÄȫά¶ÈÃô¸ÐÄÚÈÝ¡£µ÷²éÏÔʾ£¬¹¥»÷ÕßÔçÔÚ2023Äê9ÔÂ30ÈÕÖÁ10ÔÂ18ÈÕÆÚ¼ä±ãÈëÇÔìäϵͳ£¬µ«FFCUÖ±ÖÁ2024Äê1Ô²ŷ¢ÏÖй¶ÊÂÎñ£¬¸üÔÚ2025Äê8Ô²ÅÈ·ÈϾßÌåй¶Êý¾ÝÀàÐÍ£¬Â¶³ö³ö°²È«ÏìÓ¦»úÔìµÄÑϳÁÖͺó¡£Õâ´Îй¶µÄÊý¾ÝÁìÓò¾ªÈË£¬Ô̺¬È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢»¤ÕÕºÅÂë¡¢¼ÝÊ»ÅÆÕÕ/ÖÝÉí·ÝÖ¤ºÅÂë¡¢½ðÈÚÕË»§¼°Â·ÓɺÅÂë¡¢ÐÅÓþ¿¨/½è¼Ç¿¨ÆëÈ«ÐÅÏ¢£¨º¬°²È«Âë/PINÂë/µ½ÆÚÈÕ£©¡¢Ë°ÎñPINÂë¡¢Ò½ÁÆÕï¶Ï/´¦·½/ÌṩÕßÐÅÏ¢¡¢±£ÏÕµ¥ºÅ¡¢Ò½ÖÎÓöÈÏêÇ飬ÒÔ¼°Êý×ÖÊðÃûµÈ¡£FFCUÇ¿µ÷£¬²¢·ÇËùÓÐÓ×ÎÒÊý¾Ý¾ù±»Ð¹Â¶£¬µ«ÖØ´óÐÅÏ¢ÁбíÏÔʾ¹¥»÷ÕßÒÑ»ñÈ¡¹Ø¼ü¿Í»§ÎļþµÄ¿í·º½Ó¼ûȨÏÞ¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩÐÅÏ¢Ö´ÐнðÈÚڲơ¢¾«×¼ÍøÂç´¹µö£¬ÉõÖÁÔ¶³ÌÑéÖ¤Éí·Ý½øÐиüÉî¶ÈµÄÉøÈë¡£Ö»¹ÜFFCU³ÆÎ´·¢ÏÖÉí·Ý͵ÇÔ»ò½ðÈÚÚ²ÆÊÂÎñ£¬µ«ÒÑΪÊܺ¦ÕßÌṩÃâ·ÑÉí·Ý͵ÇÔÔ¤·À·þÎñ¡£°µÍø¼à¿ØÏÔʾ£¬ÒÑDzɢµÄÀÕË÷Èí¼þ¼¯ÍÅBlackBasta¿ÉÄÜÓë´Ë°¸Óйأ¬Æä¹¥»÷ÈÕÆÚÓëFFCU´«µÝµÄй¶ʱ¶Î¸ß¶ÈÎǺϡ£
https://cybernews.com/security/fairmont-federal-credit-union-data/
2. FinWiseÒøÐÐÄÚ²¿ÈËÔ±ÐÅϢй¶ÊÂÎñÓ°Ïì68.9ÍòÃû¿Í»§
9ÔÂ15ÈÕ£¬FinWiseÒøÐÐÓÚ2024Äê5ÔÂ31ÈÕ²úÉúһ·ÓÉǰ¹ÍԱȥְºó½Ó¼ûÃô¸ÐÎļþÒý·¢µÄÊý¾Ýй¶ÊÂÎñ£¬Éæ¼°ºÏ×÷·½ÃÀ¹úµÚÒ»½ðÈÚ£¨AFF£©µÄ68.9ÍòÃû¿Í»§Êý¾Ý¡£AFF×÷ΪÏû·Ñ½ðÈÚ·þÎñÉÌ£¬Ìṩ·ÔìÚ´û¿î¡¢ÏÈ×âºóÂòµÈ²úÆ·£¬Æä¿Í»§´û¿î·¢·ÅÓëÔÞÖú¾ùÒÀÀµFinWiseÒøÐС£Æ¾¾ÝÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÅû¶µÄÎļþ£¬Õâ´ÎÊÂÎñÔ´ÓÚFinWiseÒ»ÃûǰԱ¹¤ÔÚÈ¥Ö°ºó·¸·¨½Ó¼ûÒøÐÐÊý¾Ý£¬µ¼ÖÂÔ̺¬¿Í»§È«Ãû¼°ÆäËûÓ×ÎÒÊý¾ÝµÄÎļþ±»Ð¹Â¶¡£Ö»¹ÜFinWiseδ¹«¿ª¸ÃÔ±¹¤ÈôºÎÍ»ÆÆÈ¥Ö°ºó½Ó¼ûÏÞ¶È£¬Ò²Î´Åû¶×ÜÊÜÓ°ÏìÈËÊý£¬µ«ÊÂÎñÒÑÒý·¢¶àÆð¼¯ÌåËßËÏ¡£Ð¹Â¶Êý¾ÝÉæ¼°AFF¿Í»§ÉêÇë¡¢ÕË»§ÖÎÀí¡¢»¹¿îÁ÷³ÌµÈ¹Ø¼üÐÅÏ¢¡£FinWiseÔÚ·¢ÏÖºóµ±¼´Æô¶¯±í²¿ÍøÂ簲ȫר¼Òµ÷²é£¬ÆÀ¹À·çÏÕÁìÓò£¬²¢¼ÓÇ¿ÄÚ²¿½ÚÔìÒÔÔ¤·ÀÀàËÆÊÂÎñ¡£ÎªÌí²¹¿Í»§Ëðʧ£¬ÒøÐÐΪÊÜÓ°ÏìÓû§Ìṩ12¸öÔÂÃâ·ÑÐÅÓþ¼à¿ØÓëÉí·Ý͵ÇÔ±£»¤·þÎñ¡£Ä¿Ç°£¬FinWiseÒÔ¡°Éæ¼°ÔÚ½øÐеÄËßËÏ¡±ÎªÓɻؾø½øÒ»²½»ØÓ¦Ï¸½Ú£¬µ«ÊÂÎñÒѶ³ö½ðÈÚ»ú¹¹ÔÚÔ±¹¤È¥Ö°ºóÊý¾Ý½Ó¼ûȨÏÞÖÎÀí¡¢Ãô¸ÐÊý¾Ý±£»¤»úÔìµÈ·½ÃæµÄ·ì϶¡£
https://www.bleepingcomputer.com/news/security/finwise-insider-breach-impacts-689k-american-first-finance-customers/
3. ¹È¸èLERSϵͳÔâÚ²ÆÕË»§ÉøÈ룬Íþв×éÖ¯¹ØÁª¿ç¹úÊý¾Ý͵ÇÔÁ´
9ÔÂ15ÈÕ£¬¹È¸è֤ʵÆä·¨ÂÉÒªÇóϵͳ£¨LERS£©ÔâºÚ¿Í´´½¨Ú²ÆÕË»§£¬¸ÃÕË»§ËäδÏÖʵÌá½»ÒªÇó»ò½Ó¼ûÊý¾Ý£¬µ«Â¶³öÁË·¨ÂÉÊý¾ÝϵͳµÄ°²È«·ì϶¡£´Ëǰ£¬Íþв×éÖ¯¡°Scattered Lapsus$ Hunters¡±ÔÚTelegramÐû³ÆÒÑÈëÇÖLERS¼°FBIµÄeCheck²¼¾°µ÷²éϵͳ£¬²¢°ä²¼ÏµÍ³½Ó¼û½ØÍ¼£¬Òý·¢È«Çò·¨ÂÉ»ú¹¹¶ÔÃô¸ÐÊý¾Ý°²È«µÄÓÇÓô¡ª¡ª´ËÀàϵͳ±¾ÓÃÓÚÌá½»´«Æ±¡¢·¨ÔººÅÁîºÍ´¹Î£Åû¶ҪÇó£¬Î´¾ÊÚȨµÄ½Ó¼û¿ÉÄÜÔÊÐí¹¥»÷Õß¼ÙÒâ·¨ÂÉÈËÔ±»ñÈ¡Êܱ£»¤µÄÓû§Êý¾Ý¡£¸Ã×éÖ¯×Ô³ÆÎªShinyHunters¡¢ScatteredSpider¡¢LapsusµÈÀÕË÷×éÖ¯µÄ¹ØÁª¼¯Ì壬½ñÄêÔøÍ¨¹ýÉç»á¹¤³ÌÓÕÆÔ±¹¤½«SalesforceÊý¾Ý¼ÓÔØÆ÷ÏÎ½ÓÆóҵʷý£¬ÇÔÈ¡¹È¸è¡¢°¢µÏ´ï˹¡¢°ÄÖÞº½¿Õ¡¢Ë¼¿ÆµÈÊýÊ®¼Ò¿ç¹úÆóÒµ¼°µ±¾Ö»ú¹¹Êý¾Ý²¢Ö´ÐÐÀÕË÷¡£¹¥»÷õè¾¶ÏÔʾ£¬ÆäÏȹ¥ÆÆSalesloftµÄGitHub´úÂë¿â£¬ÀûÓÃTrufflehog¹¤¾ßɨÃè˽ÓÐÔ´ÂëÖеͳö»úÃÜ£¬»ñÈ¡Éí·ÝÑéÖ¤ÁîÅÆºó½øÒ»²½Ö´ÐÐSalesforceÊý¾ÝÇÔÈ¡¡£¹È¸èÍþвµý±¨²¿ÃÅMandiantÔøÂÊÏÈÅû¶´ËÀ๥»÷£¬ÖÒ¸æÆóÒµ¼ÓÇ¿·ÀÓù¡£Ö»¹Ü¡°Scattered Lapsus$ Hunters¡±ÓÚ9ÔÂ14ÈÕ°ä·¢¡°ÍËÐÝ¡±²¢°ä²¼³¤Îijơ°¹ÑÑÔ½«³ÉΪÁ¦Á¿¡±£¬µ«ÍøÂ簲ȫ×êÑÐÈËÔ±ÒÔΪÆäÈÔÔÚ°µÖл£¬½«À´¿ÉÄÜͨ¹ýδÅû¶µÄÊý¾Ýй¶ÊÂÎñ³ÖÐø¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/google-confirms-fraudulent-account-created-in-law-enforcement-portal/
4. ¿ªÔƼ¯ÍÅÔâShiny Hunters¹¥»÷ÖÂÊý°ÙÍò¿Í»§Êý¾Ýй¶
9ÔÂ15ÈÕ£¬È«ÇòÉÝ³ÞÆ·¾ÞÍ·¿ªÔƼ¯ÍÅ£¨Kering£©Ôâ·êÑϳÁÊý¾Ýй¶ÊÂÎñ£¬ÆìÏÂGucci¡¢Balenciaga¡¢Alexander McQueenµÈÆ·ÅÆµÄÊý°ÙÍò¿Í»§¸öÈËÊý¾Ý±»ºÚ¿Í×éÖ¯Shiny HuntersÇÔÈ¡¡£Ð¹Â¶Êý¾Ýº¸ÇÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¼Òͥסַ¼°È«ÇòÉÝ³ÞÆ·ÃŵêÏû·Ñ¼Í¼£¬²¿Ãſͻ§µ¥±ÊÏû·Ñ½ð¶î¸ß´ï8.6ÍòÃÀÔª£¬Òý·¢¶Ô¡°¸ßÏû·ÑÈËȺ¡±¿ÉÄܳÉΪºóÐøÚ¿ÆÖ¸±êµÄÓÇÓô¡£¿ªÔƼ¯ÍÅÒÑÈ·Èϰ²È«·ì϶²¢Í¨ÖªÊý¾Ý±£»¤²¿ÃÅ£¬µ«Î´Åû¶¾ßÌåÊÜÓ°Ïì¿Í»§ÊýÁ¿£¬½öÇ¿µ÷δй¶ÈκβÆÕþÐÅÏ¢¡£¾ÝBBC±¨Â·£¬Shiny HuntersÏòÆäÌṩÁËÔ̺¬ÊýǧÃû¿Í»§¾ßÌåÐÅÏ¢µÄÕæÊµÊý¾ÝÑù±¾£¬²¢Ðû³Æ°ÑÎÕ740Íò¸ö¶ÀÁ¢µç×ÓÓʼþµØÖ·¶ÔÓ¦µÄÊý¾Ý£¬°µÊ¾Êܺ¦Õß×ÜÊý»ò¿¿½ü¸ÃÊý×Ö¡£¸Ã×éÖ¯×ÔÆØÓÚ2025Äê4ÔÂͨ¹ýÈëÇÖ¿ªÔƼ¯ÍÅϵͳִÐй¥»÷£¬µ«½»Éæ·ÖÁѺó¿ªÔƼ¯ÍŻؾøÖ§¸¶Êê½ð¡£¼¯Í޲»°È˽øÒ»²½×¢Ã÷£¬2025Äê6Ô·¢ÏÖδ¾ÊÚȨµÄµÚÈý·½Ò»Ê±½Ó¼ûϵͳ£¬½ö»ñÈ¡²¿·Ôì·ÅƵÄÓÐÏÞ¿Í»§Êý¾Ý£¬ÇÒÎ´Éæ¼°²ÆÕþÐÅÏ¢¡£
https://securityaffairs.com/182236/cyber-crime/hackers-steal-millions-of-gucci-balenciaga-and-alexander-mcqueen-customer-records.html
5. µÂÖÝÎÚÍß¶ûµÏÑ§ÇøÔâÀÕË÷Èí¼þ¹¥»÷Ö¹عØ
9ÔÂ16ÈÕ£¬µÂ¿ËÈøË¹ÖÝÎÚÍß¶ûµÏÊй«Á¢Ñ§ÇøÒòÀÕË÷Èí¼þ¹¥»÷±»ÆÈ¹Ø¹ØËÄÌ죬ӰÏìÔ¼5000ÃûѧÉú¼°¶à¸ö¹Ø¼üϵͳ¡£Ñ§ÇøÍ¨Ñ¶Ö÷¹Ü°²ÄÝ¡¤ÂêÀö¡¤°£Ë¹Æ¤ÅµÈø°µÊ¾£¬¹¥»÷µ¼Ö·þÎñÆ÷̱»¾£¬ÑϳÁ×ÌÈŵ绰¡¢¿Õµ÷½ÚÔì¡¢ÉãÏñÍ·¼à¿Ø¡¢·Ã¿ÍÖÎÀí¼°½²ÊÚϵͳ£¨ÈçSkyward£©ÔËÐС£¸ÃÑ§ÇøÊÇ2022ÄêÂÞ²¼Ó×ѧǹ»÷ÊÂÎñ²úÉúµØ£¬ÐÂУ¸ÕÆôÓò»¾Ã£¬Õâ´ÎÊÂÎñÔٴζ³öУ԰°²ÕûϵͳµÄ´àÈõÐÔ¡£ÊÂÎñ²úÉúºó£¬Ñ§ÇøÒÑÏòÁª¹úµ÷²é¾Ö¡¢±£ÏÕÍøÂ簲ȫÍŶӵȻú¹¹»ã±¨£¬²¢Æô¶¯È«Ãæµ÷²éÒÔ×·Òä¶ñÒâÈí¼þÆðÔ´¼°ÆÀ¹ÀÊý¾Ýй¶·çÏÕ¡£Îª±£ÏÕ°²È«£¬Ñ§Çø½«Í£¿ÎËÄÌìÓëУÀú·Ç¹¤×÷ÈÕ»¥»»£¬Ñ§ÌÃÍøÕ¾¹Ø¹Ø£¬Ë«Ñ§·Ö¿Î³ÌÔÝÍ£¡£½ØÖÁÖÜÒ»£¬ÉÐÎÞÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÔðÈΣ¬ÐÂѧÄê¸ÕÆô¶¯µÄÑ§ÇøÃæ¶Ô¸ü´óÌôÕ½¡£
https://therecord.media/uvalde-texas-school-district-temporarily-closing-ransomware
6. ³¯ÏÊKimsuky×éÖ¯½èAIαÔ캫¾ü·½Éí·ÝÖ¤Ö´Ðо«×¼ÍøÂç´¹µö
9ÔÂ15ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Genians½üÈÕÅû¶£¬³¯Ïʵ±¾Ö²¼¾°µÄÍþвÐÐΪÕßKimsuky×éÖ¯ÀûÓÃÈËΪÖÇÄܹ¤¾ßChatGPTÌìÉúαÔìµÄº«¹ú¾üÊ»ú¹¹Éí·Ý֤ͼÏñ£¬ÓÃÓÚÉý¼¶Óã²æÊ½ÍøÂç´¹µö¹¥»÷¡£¸Ã×éÖ¯¼ÙÒ⺫¹ú¹ú·ÀÓйػú¹¹£¬ÒÔ½â¾ö¾ü·½¹ÙÔ±Éí·ÝÖ¤·¢·Å¹¤×÷ΪÓÉ£¬Í¨¹ýµç×ÓÓʼþ·¢ËÍÔ̺¬Î±ÔìÉí·ÝÖ¤Ñù±¾µÄ´¹µöÁ´½Ó£¬ÓÕµ¼Ö¸±êµã»÷ºó²¿Êð¶ñÒâÈí¼þ£¬ÊµÏÖÊý¾Ý͵ÇÔºÍÔ¶³Ì½ÚÔì¡£Õâ´Î¹¥»÷ÓÚ2025Äê7ÔÂ17ÈÕ³õ´Î±»Genians°²È«ÖÐÐÄ·¢ÏÖ£¬ÏµKimsuky×éÖ¯6ÔÂClickFix´¹µö»î¶¯µÄºóÐøÐж¯¡£Á½´Î¹¥»÷¾ùʹÓÃÒ»Ñù¶ñÒâÈí¼þ£¬ÖØÒªÕë¶Ô³¯ÏÊ×êÑÐÈËÔ±¡¢ÈËȨ»î¶¯¼Ò¼°¼ÇÕß¡£Î±ÔìÉí·Ý֤ͼÏñ¾¼ì²âΪÉî¶ÈαÔìµÄ¸ÅÂÊ´ï98%£¬ÆäÕæÊµÐÔ¼ÓÇ¿ÏÔÖøÌáÉýÁË´¹µöÓʼþµÄ¿ÉÐŶȣ¬Ê¹Êܺ¦Õ߸üÒ×·ÅËɾ¯Ìè¡£Õâ´ÎÊÂÎñ½ÒʾÁ˹ú¶ÈÖ§³ÖÐÍÍþв×éÖ¯¶ÔAI¼¼ÊõµÄÀÄÓÃÇ÷Ïò¡£Kimsukyͨ¹ý½áºÏÉç»á¹¤³ÌѧÓëAIÌìÉúÄÚÈÝ£¬¹¹½¨Á˸üÒñ±ÎµÄ¹¥»÷Á´£º´Ó·Âð¹Ù·½ÓòÃû¡¢Î±Ôì¸ß·ÂÕæÖ¤¼þ£¬µ½Ö²Èë¶ñÒâ¾ç±¾£¬ÐÎ³ÉÆëÈ«ÉøÈëõè¾¶¡£
https://www.infosecurity-magazine.com/news/ai-military-ids-north-korea/


¾©¹«Íø°²±¸11010802024551ºÅ