ÐÂÐËShinySp1d3rÀÕË÷Èí¼þ¼¼ÊõÔËÓªÕ½ÊõÆØ¹â
°ä²¼¹¦·ò 2025-11-211. ÐÂÐËShinySp1d3rÀÕË÷Èí¼þ¼¼ÊõÔËÓªÕ½ÊõÆØ¹â
11ÔÂ19ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±Åû¶ÁËÃûΪ"ShinySp1d3r"µÄÐÂÐÍÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Æ½Ì¨¿ª·¢Ï¸½Ú¡£¸Ãƽ̨ÓÉÓëShinyHunters¡¢Scattered Spider¼°Lapsus$×éÖ¯¹ØÁªµÄÍþвÐÐΪÕß´´½¨£¬±ê־ȡÕâЩÍÅ»ï´ÓʹÓõÚÈý·½¼ÓÃÜÆ÷תÏò×ÔÖ÷¿ª·¢¡£¿ª·¢°æ±¾ÏÔʾ£¬ShinySp1d3rѡȡȫ×ÔÖ÷Ñз¢¼Ü¹¹£¬Î´¸´ÓÃLockBit»òBabukµÈÒÑÖª´úÂë¿â£¬¾ß±¸¶àÏî´´ÐÂÖ°ÄÜ¡£¼¼Êõ²ãÃæ£¬¸ÃÀÕË÷Èí¼þʹÓÃChaCha20¼ÓÃÜËã·¨¹²Í¬RSA-2048±£»¤Ë½Ô¿£¬Ã¿¸ö¼ÓÃÜÎļþÌìÉú¹ÖÒìÀ©´óÃû²¢Í¨¹ýÊýѧ¹«Ê½¶¯Ì¬ÌìÉú¡£ÎļþÍ·ÒÔ"SPDR"¿ªÍ·¡¢"ENDS"½á⣬Ô̺¬ÎļþÃû¡¢¼ÓÃÜ˽Կ¼°ÔªÊý¾Ý¡£Æä´«²¼»úÔìÖ§³Öͨ¹ýSCM·þÎñ¡¢WMI¹ý³Ì´´½¨¼°GPO¾ç±¾²¿ÊðʵÏÖºáÏòÉøÈ룬²¢¾ß±¸ËÑË÷Ê¢¿ªÍøÂç¹²ÏíÖ÷»ú½øÐжþ´Î¼ÓÃܵÄÄÜÁ¦¡£·´·ÖÎö¸öÐÔÔ̺¬¹Ò¹³EtwEventWriteº¯Êý×è¶ÏÈÕÖ¾¼Í¼¡¢¸²¸ÇÄڴ滺³åÇø·Àȡ֤£¬ÒÔ¼°Í¨¹ýдÈëËæ»ú.tmpÎļþÌî³ä´ÅÅ̿ռä¹ÊÕÏÊý¾Ý¸´Ô¡£
https://www.bleepingcomputer.com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters/
2. ¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾IGTÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
11ÔÂ20ÈÕ£¬¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾£¨IGT£©×÷ΪȫÇòµ±ÏȵĶij¡¼°ÔÚÏ߯½Ì¨Êý×ÖÓÎÏ·¡¢ÌåÓý²©²ÊºÍ½ðÈڿƼ¼¹©¸øÉÌ£¬½üÈÕ±»Óë¶íÂÞ˹¹ØÁªµÄ÷è÷ëÀÕË÷Èí¼þ×éÖ¯ÈÏÁì¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶²©¿Í°ä²¼IGTÌõ¿î£¬Ðû³ÆÇÔÈ¡ÁË10GBÊý¾Ý£¬21,683¸öÎļþ£¬º¸Ç´ÓÀÏ»¢»ú¡¢²ÊƱϵͳµ½PlaySportsÌåÓý²©²Êƽ̨µÈÖ÷ÌâÒµÎñÊý¾Ý¡£IGT²úÆ·¿í·ºÀûÓÃÓÚÈ«Çò100¶à¸ö¹ú¶È£¬ÖðÈÕ·þÎñÊý°ÙÍòÍæ¼Ò£¬Æä½ðÈڿƼ¼²¿ÃÅ´æ´¢´óÁ¿¿Í»§Éí·ÝÐÅÏ¢£¬Ãæ¶ÔÉí·Ý͵ÇÔ·çÏÕ¡£½ØÖÁ±¨Â·°ä²¼£¬IGTδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£÷è÷ë×éÖ¯×Ô2021Äê»î¶¯ÒÔÀ´£¬2025ÄêÒѳÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯£¬´ÓǰÁù¸öÔ·¢Æð³¬500Æð¹¥»÷£¬×Ô2023ÄêÆðÒÑÁгö991ÃûÊܺ¦Õߣ¬Ô̺¬³ÛÃûÆóÒµ¡¢Ò½ÁÆ»ú¹¹¼°µ±¾Ö»ú¹¹¡£ÆäѡȡÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ã³Ò×ģʽ£¬³£Ê¹ÓÃË«³ÁÀÕË÷Õ½Êõ£ºÏÈË÷Òª½âÃÜÊê½ð£¬ÔÙÍþвй¶Êý¾Ý¡£
https://cybernews.com/news/igt-digital-gaming-leader-qilin-ransomware-attack-casino-fintech-sports-betting/
3. ¶íÂÞ˹VSK±£ÏÕ¹«Ë¾Ôâ´ó¹æÄ£ÍøÂç¹¥»÷
11ÔÂ19ÈÕ£¬×÷Ϊ¶íÂÞ˹×î´ó×ۺϱ£ÏÕ¹«Ë¾Ö®Ò»£¬×ܲ¿Î»ÓÚĪ˹¿ÆµÄVSK 11ÔÂ13ÈÕ¹«¿ªÈ·ÈÏÔâ·ê¡°´ó¹æÄ£ÍøÂç¹¥»÷¡±£¬Ä¿Ç°Æä¹ÙÍø¡¢Òƶ¯ÀûÓü°Êý°ÙÍòÓû§ÒÀÀµµÄ·þÎñÒѳÖÐøÏÂÏßÒ»ÖÜ¡£×÷Ϊ·þÎñÔ¼3300ÍòÓ×ÎÒ¿Í»§ºÍ50¶àÍò¼ÒÆóÒµµÄÐÐÒµ¾ÞÍ·£¬VSKÒµÎñº¸Ç²Æ¸»ÏÕ¡¢½»Í¨ÏÕ¡¢½¡È«ÏյȶàÁìÓò£¬Õâ´ÎÊÂÎñµ¼Ö¿ͻ§ÎÞ·¨²É°ì³µÏÕ¡¢Åú¸Ä±£µ¥¡¢»ñÈ¡µ£±£º¯»òÔ¤Ô¼Ò½ÁÆ·þÎñ£¬²¿ÃÅÒ½ÁÆ»ú¹¹ÒòÎÞ·¨ºËʵ±£ÏÕ¸²¸ÇÁìÓò»Ø¾ø·þÎñ£¬¹«Ë¾ÓʼþϵͳÒàÖжϣ¬±»ÆÈ½¨Òé¿Í»§Í¨¹ýƽÐÅÌá½»Õ÷ѯ¡£Ö»¹ÜVSKÇ¿µ÷¡°½öIT»ù´¡ÉèÊ©ÊÜÓ°Ï죬¿Í»§¼°ºÏ×÷ͬ°éÊý¾Ý°²È«ÎÞÓÝ¡±£¬µ«ÎÚ¿ËÀ¼ºÚ¿ÍÓйØTelegramƵ·ÒѰ䲼¾Ý³ÆÐ¹Â¶µÄÐÅÏ¢¼°±¸·ÝÎļþ½ØÍ¼£¬ÕæÊµÐÔ´ýºËʵ¡£¹«Ë¾Í¬Ê±ÖҸ棬ÆäÆóÒµÓòÃûÔâ½Ù³Ö£¬½Ó¼ûÕ߻ᱻ³Á¶¨ÏòÖÁÐéαTelegramƵ·¡£Ä¿Ç°¹¥»÷ÕßÉí·Ý¼°¶¯»úδÃ÷£¬¶íÂÞË¹ÍøÂ簲ȫר¼Ò´§Ä¦ÎªÀÕË÷Èí¼þ¹¥»÷¡£
https://therecord.media/russia-vsk-cyberattack-outages
4. Òâ´óÀûFS¼¯ÍÅÒòAlmavivaÔâÈëÇÖÖÂ2.3TBÊý¾Ýй¶
11ÔÂ20ÈÕ£¬Òâ´óÀû¹ú¶ÈÌú·ÔËÓªÉÌFS Italiane¼¯ÍÅÒòIT·þÎñÌṩÉÌAlmavivaÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂ2.3TBÃô¸ÐÊý¾Ýй¶ÖÁ°µÍø¡£ºÚ¿ÍÐû³ÆÇÔÈ¡ÄÚÈݺ¸Ç»úÃÜÎļþ¡¢¼¼ÊõÎĵµ¡¢¹«¹²ÊµÌåºÏͬ¡¢ÈËÁ¦×ÊÔ´µµ°¸¡¢¹ÜÕÊÊý¾Ý¼°¶à¼ÒFS¼¯ÍŹ«Ë¾µÄÆëÈ«Êý¾Ý¼¯£¬ÆäÖÐÔ̺¬2025ÄêµÚÈý¼¾¶ÈµÄ×îÐÂÎļþ¡£D3LabÍøÂçÍþвµý±¨Ö÷¹Ü°²µÂÁÒÑÇ¡¤µÂÀ¸ÇµÙÃ÷È·Åųý¸ÃÊý¾ÝΪ2022ÄêHiveÀÕË÷Èí¼þ¹¥»÷»ØÊÕÀûÓõĿÉÄÜÐÔ£¬²¢Ö¸³öת´¢Îļþ°´²¿ÃÅ/¹«Ë¾×éÖ¯µÄѹËõ´æµµ½á¹¹Óë2024-2025Äê»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯¼°Êý¾Ý¾¼ÍÈË×÷°¸ÊÖ·¨¸ß¶ÈÒ»Ö¡£Ö»¹ÜAlmavivaÓëFS¼¯Ížùδ»ØÓ¦Ã½Ìå³õÆÚÎÊѯ£¬µ«AlmavivaºóÐøÍ¨¹ý±¾µØÃ½ÌåÉêÃ÷֤ʵÊÂÎñ£ºÆä°²È«¼à¿Ø²¿ÃŽüÆÚ·¢ÏÖ²¢¸ôÀëÁËһ·ӰÏ칫˾ϵͳµÄÍøÂç¹¥»÷£¬µ¼Ö²¿ÃÅÊý¾Ý±»µÁ¡£¸Ã¹«Ë¾ÒÑÆô¶¯°²È«Ó¦¶Ô·¨Ê½£¬È·±£¹Ø¼ü·þÎñÔËÐУ¬²¢Í¨Öª¾¯·½¡¢¹ú¶ÈÍøÂ簲ȫ»ú¹¹¼°Êý¾Ý±£»¤»ú¹¹£¬Ä¿Ç°µ÷²éÈÔÔÚµ±¾Ö»ú¹¹ÐÖúϽøÐУ¬³ÐŵÒÔͨÃ÷·½Ê½¸üнøÕ¹¡£Ä¿Ç°£¬Êý¾Ýй¶ÊÇ·ñÔ̺¬³Ë¿ÍÐÅÏ¢»òÓ°ÏìFS¼¯ÍÅÒÔ±íµÄÆäËû¿Í»§Éв»Ã÷È·¡£
https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-23tb-data-from-italian-rail-group-almavia/
5. PhotocallµÁ°æÆ½Ì¨Ôâ¹Ø¹Ø£¬³¬2600ÍòÓû§ÊÜÓ°Ïì
11ÔÂ20ÈÕ£¬Õ¼Óг¬2600ÍòÓû§µÄµÁ°æµçÊÓÁ÷ýÌåÆ½Ì¨PhotocallÔÚ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©ÓëDAZN½áºÏµ÷²éºóÒÑÖÕ³¡ÔËÓª¡£¸Ãƽ̨δ¾ÊÚȨÌṩÀ´×Ô60¸ö¹ú¶ÈµÄ1127¸öµçÊÓÆµÂ·½Ó¼û·þÎñ£¬º¸ÇÌåÓýÈüÊÂÖ±²¥¡¢Òâ¼×ÁªÈü¡¢NFL/NHLÈüʼ°»Ê¼ÒÂíµÂÀï¡¢°ÍÈûÂÞÄǵȾãÀÖ²¿ÆµÂ·£¬Óû§É¢²¼ÒÔÎ÷°àÑÀ£¨30%£©¡¢Ä«Î÷¸ç£¨13%£©ÎªÖ÷£¬µÂ¹ú¡¢Òâ´óÀû¡¢ÃÀ¹ú¸÷Õ¼6%¡£Ö»¹Üδֱ½ÓÌṩDAZNƵ·£¬µ«Æ½Ì¨³Áзַ¢ÁËÆäºÏ×÷ͬ°éÄÚÈÝ£¨ÈçMotoGPºÍF1ÈüÊ£©£¬×é³ÉÇÖȨ¡£Õâ´Î¹Ø¹ØÔ´ÓÚÅ·ÖÞÐ̾¯×é֯е÷µÄ¿ç¹ú·¨ÂÉÐж¯£¬Ðж¯Öвé·â69¸ö·¸·¨ÍøÕ¾£¨Äê½Ó¼ûÁ¿³¬1180Íò£©£¬25¸ö·¸·¨IPTV·þÎñ±»Òƽ»¼ÓÃÜÇ®±ÒÌṩÉ̲é·â£¬²é»ñ¼ÛÖµ5500ÍòÃÀÔª¼ÓÃÜÇ®±Ò£¬²¢Æô¶¯44Ïîе÷²é¡£PhotocallÓòÃûÒÑ×ªÒÆÖÁACE²¢³Á¶¨ÏòÖÁºÏ·¨ÅÔ¹ÛÍøÕ¾£¬ÔËÓªÉÌÔÞ³ÉÖÕ³¡ÔËÓª¡£
https://www.bleepingcomputer.com/news/security/tv-streaming-piracy-service-photocall-with-26m-yearly-visits-shut-down/
6. SalesforceÓëGainsightÓ¦¶ÔÊý¾ÝÇÔÈ¡£º³·ÏúÁîÅÆÒÆ³ýÀûÓÃ
11ÔÂ20ÈÕ£¬SalesforceÔÚµ÷²é¿Í»§Êý¾ÝÇÔÈ¡¹¥»÷ʱ£¬·¢ÏÖÒì³£»î¶¯Ô´ÓÚGainsight°ä²¼µÄÀûÓ÷¨Ê½ÓëSalesforceµÄ±í²¿Ïνӣ¬¶ø·Ç×ÔÉíCRMƽ̨·ì϶¡£¸Ã¹«Ë¾Òѳ·ÏúËùÓÐÓë¸ÃÀûÓ÷¨Ê½¹ØÁªµÄ½Ó¼ûÁîÅÆºÍË¢ÐÂÁîÅÆ£¬²¢ÁÙʱ½«Æä´ÓAppExchangeÒÆ³ý£¬Í¬Ê±Í¨ÖªÊÜÓ°Ïì¿Í»§²¢ÌṩԮÊÖ¡£Õâ´ÎÊÂÎñÓë2025Äê8ÔÂSalesloftÊý¾Ýй¶ģʽÀàËÆ£¬ÆäʱÀÕË÷×éÖ¯¡°Scattered Lapsus$ Hunters¡±ÀûÓÃÇÔÈ¡µÄOAuthÁîÅÆ£¬´Ó¿Í»§SalesforceÊ·ýÖÐÇÔÈ¡ÁËÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬Ó°ÏìÔ¼760¼Ò¹«Ë¾£¬µ¼ÖÂ15ÒڱʼÍ¼й¶£¬Éæ¼°Google¡¢Cloudflare¡¢Palo Alto NetworksµÈ³ÛÃûÆóÒµ¡£ShinyHunters×éÖ¯Ðû³Æ£¬Í¨¹ýSalesloft Drift·ì϶ÖÐÇÔÈ¡µÄÃÜÔ¿ÈëÇÖGainsightºó£¬½øÒ»²½»ñÈ¡ÁË285¸öSalesforceÊ·ýµÄ½Ó¼ûȨÏÞ¡£Gainsight´ËǰÒÑ֤ʵ£¬¹¥»÷Õßͨ¹ýÓëSalesloft Drift¹ØÁªµÄ±»µÁOAuthÁîÅÆÈëÇÖ£¬Ð¹Â¶ÁËÆóÒµÁªÏµÐÅÏ¢¡£SalesforceÇ¿µ÷£¬ËùÓжñÒâ»î¶¯¾ùÓë±í²¿ÀûÓ÷¨Ê½ÏνÓÓйأ¬¶ø·Çƽ̨×ÔÉí·ì϶¡£
https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/


¾©¹«Íø°²±¸11010802024551ºÅ