À×ŵ¼°´ïÆõÑǿͻ§Êý¾ÝÒòµÚÈý·½Ð¹Â¶ÔâÇÔ

°ä²¼¹¦·ò 2025-10-09

1. À×ŵ¼°´ïÆõÑǿͻ§Êý¾ÝÒòµÚÈý·½Ð¹Â¶ÔâÇÔ


10ÔÂ3ÈÕ  £¬Ó¢¹úÀ×ŵÓë´ïÆõÑǽüÈÕÏò¿Í»§·¢³ö֪ͨ  £¬³ÆÒòµÚÈý·½¹©¸øÉÌÔâ·êÍøÂç¹¥»÷  £¬µ¼Ö²¿Ãſͻ§Ãô¸ÐÐÅϢй¶¡£À×ŵ×÷ΪÄêÓªÊÕ³¬550ÒÚÃÀÔª¡¢Õ¼ÓÐ17ÍòÃûÔ±¹¤¡¢Äê²úÁ¿220ÍòÁ¾µÄ·¨¹úÆû³µ¾ÞÍ·  £¬Æä×Ó¹«Ë¾´ïÆõÑÇÒÔʵ»Ý¿¿µÃסµÄ³µÐÍÎÅÃû¡£Õâ´ÎÊÂÎñÔ´ÓÚδ¾ßÃûµÄµÚÈý·½¹©¸øÉÌϵͳ±»ÈëÇÖ  £¬Ð¹Â¶Êý¾ÝÔ̺¬¿Í»§ÐÕÃû¡¢ÐԱ𡢵绰ºÅÂë¡¢µç×ÓÓʼþ¡¢ÓÊÕþµØÖ·¡¢³µÁ¾¼ø±ðºÅÂë¼°µÇ¼ÇºÅÂëµÈ  £¬µ«ÒøÐлò²ÆÕþÐÅϢδÊܲ¨¼°¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢½øÐд¹µö¹¥»÷¡¢Ú¿Æ­»òÉç»á¹¤³Ì¹¥»÷¡£À×ŵǿµ÷  £¬Ö¸±ê¹«Ë¾ÒѸôÀëÊÂÎñ²¢¶Ï¸ùÍþв  £¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©µÈµ±¾ÖÒÑ»ñÖªÇé¿ö¡£À×ŵ°µÊ¾ÒòºÏͬÏÞ¶ÈÎÞ·¨Ð¹Â©¹©¸øÉÌÐÅÏ¢  £¬ÇÒÊÜÓ°Ïì¿Í»§ÊýÁ¿Ôݲ»Ã÷È·¡£À×ŵ½¨ÒéÊÜÓ°Ïì¿Í»§¾¯ÌèδҪÇóµÄµç»°ºÍÓʼþ  £¬ÇÐÎðй©ÃÜÂë¡£


https://www.bleepingcomputer.com/news/security/renault-and-dacia-uk-warn-of-data-breach-impacting-customers/


2. ·ðÂÞÀï´ïÒ½ÉúÓ°Ïñ¼¯Íų¬17ÍòÈËÊý¾Ýй¶


10ÔÂ6ÈÕ  £¬ÃÀ¹ú·ðÂÞÀï´ïÖÝÒ½ÉúÓ°Ïñ¼¯ÍÅ£¨Doctors Imaging Group£©½üÈÕÅû¶һ·´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ¡£¸Ã¼¯ÍÅÔÚÅÁÀ­ÌØ¿¨ºÍ¸Ç¶÷˹ά¶ûÉèÓд¦Ê´¦µÄ·ÅÉä¿ÆÕïËù  £¬ÓÚ2024Äê11ÔÂ5ÈÕÖÁ11ÈÕÆÚ¼äÔâºÚ¿ÍÈëÇÖÍøÂçϵͳ  £¬¹¥»÷Õ߳ɹ¦¸´Ô첿ÃÅÎļþ¡£¾­¹ý½üÒ»ÄêµÄµ÷²é  £¬¸Ã»ú¹¹ÓÚ2025Äê8ÔÂÏÂѮʵÏÖµ÷²é²¢´«µÝÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©  £¬È·ÈÏÕâ´ÎÊÂÎñÓ°Ï쳬¹ý17.1ÍòÈË¡£Ð¹Â¶Êý¾Ýº­¸Ç»¼ÕßÃô¸ÐÐÅÏ¢  £¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢½ðÈÚÕ˺𢲡ÀúºÅ¡¢½¡È«±£ÏÕÐÅÏ¢¼°Ò½ÁÆË÷Åâ¼Í¼µÈ¡£Ö»¹ÜĿǰÉÐÎÞÖ¤¾ÝÅú×¢ÒøÐлò²ÆÕþÐÅÏ¢±»ÇÔ  £¬µ«Éç»á°²È«ºÅÂëµÈÖ÷ÌâÉí·ÝÐÅÏ¢µÄй¶  £¬ÒÑʹÊÜÓ°ÏìÕßÃæ¶ÔÉí·Ý͵ÇÔ¡¢½ðÈÚÚ¿Æ­¼°¾«×¼Ò½ÁÆÚ¿Æ­µÄ³Á´ó·çÏÕ¡£ÖµÍ×ÌùÐĵÄÊÇ  £¬¸ÃÊÂÎñδÃ÷È·ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ¹¥»÷  £¬ÒàÎÞÒÑÖªÍøÂç·¸×ïÍÅ»ïÐû³Æ¶Ô´ËÕÆ¹Ü¡£Ò½ÉúÓ°Ïñ¼¯ÍÅÔÚ֪ͨÖÐÇ¿µ÷  £¬ÒѲÉÈ¡´ëÊ©¸ôÀëÊÜÓ°Ïìϵͳ²¢¶Ï¸ùÍþв  £¬µ«ÊÜÏÞÓÚºÏͬÌõ¿î¼°µ÷²é½øÕ¹  £¬ÔÝÎÞ·¨Åû¶¾ßÌåÊÜÓ°Ïì¿Í»§ÊýÁ¿¼°ÉæÊµÚÈý·½¹©¸øÉÌÉí·Ý¡£¼¯ÍލÒéÊÜÓ°Ïì¿Í»§Ç×êÇ¼à¿ØÓ×ÎÒÕË»§Òì³£  £¬¾¯Ìè´¹µöÓʼþ¼°Î´ÊÚȨͨѶ  £¬²¢¶¨ÆÚ¸üÐÂÃÜÂë¡£


https://www.securityweek.com/data-breach-at-doctors-imaging-group-impacts-171000-people/


3. Rainwalk³èÎï±£ÏÕй¶158 GBÃÀ¹ú¿Í»§ºÍ³èÎïÊý¾Ý


10ÔÂ6ÈÕ  £¬ÄÏ¿¨ÂÞÀ´ÄÉÖݳèÎï·þÎñ¹«Ë¾Rainwalk PetÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼Ö´ó¹æÄ£Êý¾Ýй¶  £¬ÍøÂ簲ȫ×êÑÐÔ±Jeremiah Fowler·¢ÏÖ¸ÃδÉèÃÜÂë±£»¤»ò¼ÓÃܵÄ158GBÊý¾Ý¿âºó  £¬Í¨¹ýWebsite Planet֤ʵÊÂÎñÕæÊµÐÔ¡£Õâ´ÎÐ¹Â¶Éæ¼°Ô¼8.5Íò·ÝÎļþ  £¬Ô̺¬³èÎï±£ÏÕË÷Åâ¡¢ÊÞÒ½Õ˵¥µÈÃô¸Ð¼Í¼  £¬¾ßÌå¶³ö¿Í»§ÐÕÃû¡¢µç»°¡¢µØÖ·¡¢ÓÊÏä¼°²¿ÃÅÐÅÓþ¿¨ºÅ  £¬ÒÔ¼°³èÎïÐÕÃû¡¢ÖÖÀà¡¢²¡Ê·¡¢Ð¾Æ¬ºÅÂëµÈÉî¶ÈÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ  £¬Êý¾Ý¿âÔÚ±»°²È«¼Ó¹ÌÇ°Ôø³ÖÐø¿É½Ó¼û½üÒ»¸öÔ  £¬ÏÖʵ¶³öʱ³¤¼°ÊÇ·ñÔâ¶ñÒâ½Ó¼ûÈÔ´ý²éÖ¤¡£Õâ´ÎÊÂÎñ͹ÏÔ³èÎïÊý¾ÝÓëÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¹ØÁªºóµÄ¸ß·çÏÕÐÔ  £¬³èÎïÐÅÏ¢²»×ãÖ±½Ó˾·¨±£»¤  £¬µ«µ±ÓëPII½áӦʱ  £¬È´³ÉÎªÍøÂç·¸×ï·Ö×ÓÑÛÖеġ°¸ß¼ÛÖµÖ¸±ê¡±¡£ÀýÈç  £¬·¸×ï·Ö×Ó¿ÉÀûÓÃй¶µÄ΢оƬºÅÂë·¢ËÍ¡°Ðø·Ñ¡¹Ø©Æ­Óʼþ  £¬»òͨ¹ýαÔìÊÞÒ½Õ˵¥Ö´Ðо«×¼Ú²Æ­£»±£ÏÕ¹«Ë¾ÒàÃæ¶ÔÐéαË÷Åâµ¼ÖµIJÆÕþËðʧ·çÏÕ¡£¸üÑϸñµÄÊÇ  £¬Rainwalk PetÔø½¨Òé¿Í»§Í¨¹ý·¢ËͶþάÂëÖÁVenmo»ñÈ¡ÍË¿î  £¬ÕâÒ»Á÷³Ì´æÔÚ±»·¸×ï·Ö×Ó½ØÁô¸¶¿îµÄ·çÏÕ¡£


https://hackread.com/rainwalk-pet-insurance-158-gb-customer-pet-data/


4. ÷è÷ëÀÕË÷Èí¼þ¹¥»÷÷¿ËÂ×±¤Ïع«Á¢Ñ§ÌÃ


10ÔÂ7ÈÕ  £¬½üÈÕ  £¬¶íÂÞË¹ÍøÂç·¸×ï×éÖ¯÷è÷ëÐû³Æ¶Ô¸¥¼ªÄáÑÇÖÝ÷¿ËÂ×±¤Ïع«Á¢Ñ§Ìã¨MCPS£©µÄÀÕË÷Èí¼þ¹¥»÷ÕÆ¹Ü¡£¸ÃÊÂÎñµ¼ÖÂѧÌÃÔËÓªÑϳÁÅö±Ú  £¬ÀÏʦ±»ÆÈʹÓÃÖ½±ÊºÍ°×°å½²ÊÚ  £¬»¥ÁªÍøÏµÍ³ÖжÏÒ»Öܺó¸´Ô­¡£÷è÷ëÐû³ÆÇÔÈ¡ÁË305GBÃô¸ÐÊý¾Ý  £¬º­¸Ç²ÆÕþ¼Í¼¡¢²¦¿îÎļþ¡¢Ô¤Ëã¼°¶ùͯҽÁƵµ°¸  £¬²¢°ä²¼Ñù±¾Í¼Æ¬×ôÖ¤¡£Ñ§ÇøÕƹÜÈË˹¿ÆÌØ¡¤ÎÖÄÉ֤ʵ¹¥»÷ÕßÉí·Ý  £¬µ«Ã÷È·°µÊ¾¡°²»³ïËãÖ§¸¶Êê½ð¡±  £¬×îÖÕ¾ö²ß½«È¡¾öÓÚµ÷²éÁ˾ּ°Îļþ¼ÓÃÜ/й¶ˮƽ¡£÷è÷ë×éÖ¯×Ô2022Äêµ×ÒÔ¡°ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©¡±Ä£Ê½ÔËÓª  £¬Í¨¹ý´¹µöÓʼþ´«²¼¶ñÒâÈí¼þ  £¬´ÓÊô³ÉÔ±¹Ï·ÖÊê½ð¡£2025Äê  £¬¸Ã×éÖ¯ÒÑÐû³Æ¶Ô103ÆðÈ·ÈÏÊÂÎñºÍ470Æðδ¾­Ö¤ÊµÊÂÎñÕÆ¹Ü  £¬½ÌÓý»ú×é³ÉÎªÖØÒªÖ¸±ê¡£³ýMCPS±í  £¬Î÷ÐÂÄ«Î÷¸ç´óѧ¡¢²©ÌØÍÐÌØÏØ¹«Á¢Ñ§ÌõÈÒ²Ôâ¹¥»÷¡£


https://www.infosecurity-magazine.com/news/qilin-ransomware-mecklenburg/


5. µç×Ó¾ÞÍ·°²¸»ÀûÈ·ÈÏÊý¾Ýй¶  £¬±»µÁÊý¾ÝÎÞ·¨¶ÁÈ¡


10ÔÂ7ÈÕ  £¬µç×ÓÔª¼þ·ÖÏúḚ́²¸»Àû½üÈÕ֤ʵÔâ·êÊý¾Ýй¶  £¬µ«Ç¿µ÷ÆäרÓÐÏúÊÛ¹¤¾ßδÊÜÓ°Ïì  £¬ÇÒδ¾­¸Ã¹¤¾ßÎÞ·¨¶ÁÈ¡´ó²¿Ãű»µÁÊý¾Ý¡£ÊÂÎñÔ´ÓÚ±í²¿ÍйÜÔÆ´æ´¢ÔâδÊÚȨ½Ó¼û  £¬¸Ã´æ´¢Ö§³ÖEMEA£¨Å·ÖÞ¡¢Öж«¡¢·ÇÖÞ£©µØÓòÄÚ²¿ÏúÊÛ¹¤¾ß¡£ÍþвÐÐΪÕßÐû³ÆÇÔÈ¡1.3TBѹËõÊý¾Ý£¨Ï൱ÓÚ7-12TBԭʼÊý¾Ý£©  £¬º­¸ÇEMEA¼°ÆäËûµØÓòÔËӪϸ½Ú  £¬Ô̺¬º¹ÇàÏúÊÛµã¼Í¼¡¢Ç±ÔÚÏúÊÛ»úÓö¡¢¿Í»§ÁªÏµ·½Ê½£¨ÈçÔ±¹¤ÓÊÏ䣩¼°²¿ÃÅÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¡£°²¸»ÀûÖ¸³ö  £¬ÈôÊý¾ÝÊôGDPR½ç˵µÄÃô¸ÐÐÅÏ¢Ôòδй¶  £¬´¿Îı¾Ñù±¾ÒÑ֤ʵ´æÔÚPII  £¬µ«ÕûÌåÓ°ÏìÓÐÏÞ¡£°²¸»ÀûÓÚ9ÔÂ26ÈÕ·¢ÏÖ·ì϶ºó  £¬Ñ¸¿ìÔÚAzure/Databricks»·¾³ÖÐÂÖ»»ËùÓлúÃÜ  £¬µ±ÍíʵÏÖ²Ù×÷ÇÒδ·¢ÏÖºóÐøÎ´ÊÚȨ»î¶¯¡£ÊÂÎñ½öÏÞEMEAµØÓòµ¥¸öϵͳ  £¬Î´ÇÖÈÅÈ«ÇòÔËÓª¡£ºÚ¿ÍÔÚ°µÍø³ÉÁ¢Ð¹ÃÜÍøÕ¾  £¬°ä²¼Ñù±¾Ê©Ñ¹Êê½ðÖ§¸¶  £¬°²¸»ÀûÃ÷È·»Ø¾ø²¢Ç¿µ÷¡°¾­¼ÃÀûÒæÇý¶¯¡±µÄ¹¥»÷ÐÔÖÊ¡£¹«Ë¾ÒÑÏò¼à¹Ü²¿ÃÅ´«µÝ  £¬²¢½«Ö±½ÓÁªÏµÊÜÓ°Ïì¿Í»§ºÍ¹©¸øÉÌ  £¬µ«ÊÜÓ°ÏìÈËÊýÉв»Ã÷È·¡£


https://www.bleepingcomputer.com/news/security/electronics-giant-avnet-confirms-breach-says-stolen-data-unreadable/


6. ClopÍÅ»ïÀûÓÃOracle EBSÁãÈÕ·ì϶ÌáÒéÊý¾Ý͵ÇÔ¹¥»÷


10ÔÂ7ÈÕ  £¬¾ÝÍøÂ簲ȫ¹«Ë¾CrowdStrikeÅû¶  £¬ClopÀÕË÷Èí¼þÍÅ»ï×Ô2025Äê8Ô³õÆð  £¬³ÖÐøÀûÓÃOracleµç×ÓÉÌÎñÌ×¼þ£¨EBS£©µÄ¹Ø¼üÁãÈÕ·ì϶CVE-2025-61882Ö´ÐÐÊý¾Ý͵ÇÔ¹¥»÷¡£¸Ã·ì϶λÓÚEBS²¢·¢´¦ÖÃ×é¼þµÄBI Publisher IntegrationÄ £¿é  £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýµ¥¸öHTTPÒªÇóʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ  £¬ÎÞÐèÓû§½»»¥ÇÒ¹¥»÷¸´ÔӶȵÍ¡£OracleÒÑÓÚÖÜÄ©°ä²¼²¹¶¡½¨¸´´Ë·ì϶  £¬µ«·ì϶Á´¸öÐÔʹÆäÈԾ߸ßΣÐÔ¡£CrowdStrikeÆÀ¹ÀÒÔΪ  £¬³ýClop±í  £¬Íþв×éÖ¯Graceful Spider¿ÉÄÜÒ²²Î¼ÓÁ˹¥»÷  £¬ÇÒ²»ÅųýÆäËûÊìϤOracle EBSµÄÍþвÐÐΪÕß²ÎÓë¡£³õ´ÎÒÑÖª¹¥»÷²úÉúÓÚ8ÔÂ9ÈÕ  £¬µ«µ÷²éÈÔÔÚ½øÐÐÖС£10ÔÂ3ÈÕ·ì϶¸ÅÏëÑéÖ¤£¨PoC£©Åû¶ºó  £¬ÍþвÐÐΪÕß¿ÉÄܼӿ쿪Ð˱øÆ÷»¯PoC  £¬Õë¶Ô¶³öÔÚ»¥ÁªÍøµÄEBSÀûÓÃÌáÒé¹¥»÷¡£OracleÒÑ´¹Î£¶½´Ù¿Í»§ÓÅÏȽ¨²¹·ì϶  £¬Ç¿µ÷³ÖÐøÊ¹ÓÃÊÜÖ§³Ö°æ±¾²¢µ±¼´ÀûÓð²È«¸üС£


https://www.bleepingcomputer.com/news/security/oracle-zero-day-exploited-in-clop-data-theft-attacks-since-early-august/