Óý±Ì¡¶²ÊºçÁùºÅ£ºÎ§¹¥¡·Óö°²È«·ì϶

°ä²¼¹¦·ò 2025-12-29

1. Óý±Ì¡¶²ÊºçÁùºÅ£ºÎ§¹¥¡·Óö°²È«·ì϶


12ÔÂ28ÈÕ £¬½üÈÕ £¬Óý±ÌÆìÏÂÈȵãÕ½ÊõÉä»÷ÓÎÏ·¡¶²ÊºçÁùºÅ£ºÎ§¹¥¡·£¨R6£©Ôâ·êÑϳÁ°²È«·ì϶ÊÂÎñ £¬Òý·¢È«ÇòÍæ¼Ò¼°°²È«½ç¿í·º¹Ø×¢¡£ºÚ¿ÍÀûÓ÷ì϶·¸·¨°Ñ³ÖÓÎÏ·ÄÚ²¿ÏµÍ³ £¬Ô̺¬ÉÃ×Ô·â½û/½â·âÍæ¼ÒÕË»§¡¢ÔÚ·â½û¹ö¶¯ÌõαÔìÐéαÐÅÏ¢¡¢ÏòËùÓÐÍæ¼Ò·¢·ÅÔ¼20ÒÚR6µãÊý£¨¼ÛÖµÔ¼1333ÍòÃÀÔª £¬°´Óý±ÌÉ̳Ƕ¨¼ÛÍÆË㣩¼°ÉùÍû £¬²¢½âËø¿ª·¢ÕßרÊôƤ·ôµÈËùÓбí¹Û·¾ß¡£ÊÂÎñ²úÉúºó £¬Óý±Ì¹Ù·½Ñ¸¿ìÏìÓ¦¡£ÖÜÁùÉÏÎç9µã10·Ö £¬¹Ù·½Õ˺Å֤ʵÎÊÌâ´æÔÚ²¢°µÊ¾ÍŶÓÕýÈ«Á¦½¨¸´¡£Ëæºó £¬Óý±Ì×Ô¶¯¹Ø¹ØÓÎÏ··þÎñÆ÷¼°ÄÚ¹ºÉ̳Ç £¬¼¯ÖÐ×ÊÔ´½â¾öÎÊÌâ¡£ÔÚ×îÖÕ¸üÐÂÖÐ £¬Óý±ÌÃ÷È·°µÊ¾²»»á³ÍÖÎÒò·ì϶»ñµÃ»ý·ÖµÄÍæ¼Ò £¬µ«½«»Ø¹öUTC¹¦·òÉÏÎç11µãºóµÄËùÓÐÂòÂô¡£Í¬Ê±Ç¿µ÷ £¬·â½û¹ö¶¯ÌõÖеÄÐÂÎŲ¢·Ç¹Ù·½ÌìÉú £¬¸ÃÖ°ÄÜ´ËǰÒѱ»½ûÓ᣽ØÖÁĿǰ £¬Óý±ÌÉÐδ°ä²¼ÕýʽÉêÃ÷Ú¹ÊÍ·ì϶³ÉÒò £¬Ò²Î´»ØÓ¦Ã½ÌåѯÎÊ¡£


https://www.bleepingcomputer.com/news/security/massive-rainbow-six-siege-breach-gives-players-billions-of-credits/


2. ºÚ¿Íй¶Wired.com 230ÍòÓû§Êý¾Ý


12ÔÂ27ÈÕ £¬½üÈÕ £¬»¯Ãû¡°Lovely¡±µÄºÚ¿ÍÔÚBreach StarsÂÛ̳й¶¾Ý³Æ³¬230ÍòWired.comÓû§Êý¾Ý £¬º­¸ÇÐÕÃû¡¢ÓÊÏä¡¢Óû§ID¡¢ÕË»§´´½¨/¸üй¦·ò´ÁµÈÐÅÏ¢ £¬²¿ÃżÍ¼º¬ÉϴλỰÈÕÆÚ¡£Êý¾Ý×îÔç×·ÒäÖÁ2011Äê £¬Éæ¼°ÕæÊµÓû§ÕË»§ £¬µ«ÎÞÃÜÂë»òÖ§¸¶ÐÅÏ¢¡£ºÚ¿ÍÔð¹Ö¿µÌ©ÄÉÊ˼¯ÍÅ£¨Wiredĸ¹«Ë¾£©ºöÊÓ°²È«ÖÒ¸æ £¬³Æ¡°ºÄʱһÔ²ÅÍÆ¶¯·ì϶½¨¸´¡± £¬²¢Íþв½«À´¼¸Öܽ«Ð¹Â¶³¬4000ÍòÓû§Êý¾Ý £¬Éæ¼°GQ¡¢Vogue¡¢Å¦Ô¼¿ÍµÈÆìÏÂÆ·ÅÆ¡£¾ÝºÚ¿ÍÅû¶µÄ¼Í¼Çåµ¥ £¬¿µÌ©ÄÉÊËÆì϶à¸öÆ·ÅÆÕË»§Êý¾Ý±»Ð¹Â¶£ºWired 236Íò¡¢Vogue 196Íò¡¢Å¦Ô¼¿Í680Íò¡¢Self 208ÍòµÈ £¬Áíº¬Î´ÖªÆ·ÅÆ¡°NIL¡±³¬947ÍòÕË»§¼°¹ú¼Ê×ÓÆ·ÅÆÊý¾Ý¡£²¿ÃżÍ¼ʹÓÃϵͳÌìÉúÓÊÏä £¬µ«ÎÞÊýΪGmail¡¢AOLµÈÓ×ÎÒÓÊÏä £¬Ö¤ÊµÊý¾ÝÔ´×Ôʵʱ»ò´æµµÓû§Êý¾Ý¿â £¬·Ç¾²Ì¬ÓªÏúÁбí £¬Ö§³ÖºÚ¿Í¡°Ö±½Ó½Ó¼ûÕË»§ÏµÍ³¡±µÄ˵·¨¡£Ä¿Ç° £¬Êý¾ÝÕæÊµÐÔÈÔÐè¹Ù·½ÑéÖ¤ £¬µ«É罻ýÌ屨·ÏÔʾÑù±¾Ô̺¬ÕæÊµÓû§ÐÅÏ¢¡£


https://hackread.com/hacker-leak-wired-com-records-conde-nast-breach/


3. EverestÀÕË÷Èí¼þ×éÖ¯ÈëÇÖ¿ËÀ³Ë¹ÀÕ


12ÔÂ25ÈÕ £¬EverestÀÕË÷Èí¼þ×éÖ¯ÔÚ°µÍøÐ¹Â¶ÍøÕ¾°ä²¼Ìû×Ó £¬Ðû³ÆÒÑÈëÇÖÃÀ¹úÆû³µÔì×÷ÉÌ¿ËÀ³Ë¹ÀÕϵͳ £¬ÇÔÈ¡1088GB£¨³¬1TB£©Êý¾Ý £¬º­¸Ç2021ÄêÖÁ2025ÄêÓëÔËÓªÓÐ¹ØµÄÆëÈ«Êý¾Ý¿â¡£¾Ý¹¥»÷Õß³Æ £¬ÆäÖÐÔ̺¬³¬105GBµÄSalesforceÐÅÏ¢ £¬Éæ¼°¿Í»§¡¢¾­ÏúÉ̼°ÄÚ²¿´úÀíµÄº£Á¿Ó×ÎÒÓëÔËÓª¼Í¼¡£Ð¹Â¶µÄÆÁÄ»½ØÍ¼¼°Ê¾ÀýÊý¾ÝÏÔʾ £¬Êý¾ÝÔ̺¬½á¹¹»¯Êý¾Ý¿â¡¢ÄÚ²¿µç×Ó±í¸ñ¡¢CRMµ¼³öÎļþµÈ¡£¿Í»§»¥¶¯ÈÕÖ¾ÏêÁÐÐÕÃû¡¢µç»°¡¢µØÖ·¡¢³µÁ¾ÐÅÏ¢¡¢Õٻذ¸Àý±¸×¢¼°Í¨»°Á˾Ö£»´úÀí¹¤×÷ÈÕÖ¾¼Í¼ºô½Ð³¢ÊÔ¡¢ÕÙ»ØÐ­µ÷¡¢Ô¤Ô¼´¦Öü°³µÁ¾×´Ì¬¸üС£´Ë±í £¬ÄÚ²¿Îļþ·þÎñÆ÷Ä¿Â¼Éæ¼°¾­ÏúÉÌÍøÂç¡¢Æû³µÆ·ÅÆ¡¢ÕٻشòËã¡¢FTPõè¾¶¼°ÄÚ²¿¹¤¾ß £¬»¹Ô̺¬Ô±¹¤ÐÕÃû¡¢¹ÍӶ״̬¡¢¹¦·ò´Á¼°Stellantis¹ØÁªÓÊÏäÓòÃûµÄÈËÁ¦×ÊÔ´¼Í¼¡£Ñù±¾ÖеÄÕٻذ¸ÀýÐðÊöÓëCRMÊý¾ÝÒ»Ö £¬ÇÐºÏÆû³µÕÙ»ØÖ§³Ö¼°¿Í»§·þÎñÁ÷³Ì¡£EverestÍþвµ¹¼ÆÊ±ÊµÏÖºó°ä²¼ÆëÈ«Êý¾Ý¼¯ £¬²¢´òËã°ä²¼¿Í»§·þÎñ»¥¶¯¹àÒôÒÔʩѹ¡£


https://hackread.com/everest-ransomware-group-chrysler-data-breach/


4. Noname057Ðû³Æ¶Ô·¨¹úÓÊÕþ·þÎñ·¢ÆðÍøÂç¹¥»÷


12ÔÂ26ÈÕ £¬½üÈÕ £¬·¨¹ú¹ú¶ÈÓÊÕþ·þÎñ¹«Ë¾La Poste֤ʵÔâ·ê³Á´óÍøÂçÊÂÎñ £¬ÆäÐÅϢϵͳÒòDDoS¹¥»÷ÀëÏß £¬µ¼ÖÂÊý°ÙÍò¿Í»§µÄÊý×ÖÒøÐÓ×¢ÔÚÏß·þÎñ¼°²¿ÃÅÓʾַþÎñÖжÏ¡£¾ßÌåÊÜÓ°ÏìÆ½Ì¨Ô̺¬Ö÷ÍøÕ¾¡¢Òƶ¯ÀûÓá¢Êý×ÖÉí·Ý·þÎñ¡¢DigiposteÎļþ´æ´¢Æ½Ì¨¼°La Banque PostaleÍøÉÏÒøÐÐ £¬µ«¹ñ̨·þÎñÈԿɽâ¾öÒøÐкÍÓÊÕþÒµÎñ £¬¿Í»§¿Éͨ¹ý¶ÌÐÅÑé֤ʵÏÖÖ§¸¶¡¢ÌáÏֵȲÙ×÷¡£Ç×¶íºÚ¿Í×éÖ¯NoName057(16)Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü £¬·¨¹ú¼ì²ì¹Ù³Æ·¨¹úµý±¨»ú¹¹DGSIÒÑȾָµ÷²é¡£Õâ´Î¹¥»÷ÊǸÃ×éÖ¯½üÆÚ¶ÔÖ§³ÖÎÚ¿ËÀ¼¹ú¶È£¨¶àΪ±±Ô¼³ÉÔ±¹ú£©µÄDDoS¹¥»÷Éý¼¶µÄÒ»²¿ÃÅ £¬×Ô2023ÄêÆð £¬¸Ã×éÖ¯Òѹ¥»÷Èðµäµ±¾Ö¡¢µÂ¹ú250Óà¼ÒʵÌå £¬²¢×ÌÈÅÈðÊ¿ÎÚ¿ËÀ¼ºÍƽ·å»á¡¢±±Ô¼·å»áµÈ»î¶¯ £¬µ«¾ùδÔì³É³Á´óÓ°Ïì¡£ÖµÍ×ÌùÐĵÄÊÇ £¬7ÔÂÅ·ÖÞÓëÃÀ¹ú½áºÏ·¢Õ¹µÄ¡°ÒÁË¹ÌØÎéµÂÐÔ¶¯¡±ÒѳÁ´´NoName057(16)¡£¸Ã×éÖ¯Õ¼Óг¬4000ÃûÖ§³ÖÕß £¬ÒÀÀµ×Ô½¨½©Ê¬ÍøÂç¼°DDoSiaµÈµÍÃż÷ƽִ̨Ðй¥»÷¡£


https://securityaffairs.com/186157/hacktivism/pro-russian-group-noname057-claims-cyberattack-on-la-poste-services.html


5. Trust Wallet ChromeÀ©´ó·ì϶ÖÂ700Íò¼ÓÃÜ×ʲú±»µÁ


12ÔÂ26ÈÕ £¬Trust Wallet Chromeä¯ÀÀÆ÷À©´ó·¨Ê½2.68.0°æ±¾¸üкó·¢×÷°²È«ÊÂÎñ £¬µ¼ÖÂÖÁÉÙ700ÍòÃÀÔª¼ÓÃÜÇ®±Ò±»µÁ¡£Óû§»ã±¨³Æ £¬¸üкóÇ®°ü×ʽð±»Çå¿Õ £¬¹¥»÷Õßͨ¹ý¹©¸øÁ´¹¥»÷ÔÚÀ©´ó·¨Ê½µÄ4482.jsÎļþÖÐÖ²Èë¶ñÒâ´úÂë £¬½«Ç®°üÖú¼Ç´Ê¡¢ÂòÂô¼Í¼µÈÃô¸ÐÊý¾Ýй¶ÖÁ±í²¿·þÎñÆ÷api.metrics-trustwallet[.]com¡£¸ÃÓòÃû×¢²á¹¦·ò½öÔçÓÚÊÂÎñÊýÈÕ £¬ÇÒÓë´¹µöÍøÕ¾fix-trustwallet[.]comÓÉͳһע²áÉ̲Ù×÷ £¬ÏÔʾ¹¥»÷ÕßÐîıÒѾá£ÊÂÎñ²úÉúºó £¬Trust WalletѸ¿ì°ä²¼½¨¸´°æ±¾2.69 £¬²¢½¨ÒéÓû§µ±¼´¸üС£¹Ù·½È·ÈϽöChromeÀ©´ó·¨Ê½2.68.0ÊÜÓ°Ïì £¬Òƶ¯¶Ë¼°ÆäËûä¯ÀÀÆ÷°æ±¾°²È«¡£Óë´Ëͬʱ £¬ÍþвÐÐΪÕßÀûÓ÷¢¼±¸ÐÇéÌáÒé´¹µö¹¥»÷ £¬Í¨¹ýfix-trustwallet[.]comµÈαÔìÍøÕ¾ÓÕµ¼Óû§ÊäÈëÖú¼Ç´Ê £¬½øÒ»²½µÁÈ¡×ʽð¡£°²È«·ÖÎöʦAkinatorÖÒ¸æ £¬¹¥»÷´úÂë¼Ù×°³É¡°·ÖÎö¹¤¾ß¡± £¬ÔÚÓû§µ¼ÈëÖú¼Ç´Êʱ´¥·¢Êý¾Ýй¶¡£


https://www.bleepingcomputer.com/news/security/trust-wallet-confirms-extension-hack-led-to-7-million-crypto-theft/


6. Sax¹ÜÕÊËùÊý¾Ýй¶18¸öÔºó֪ͨ22.8ÍòÊÜÓ°ÏìÕß


12ÔÂ26ÈÕ £¬ÃÀ¹úÐÂÔóÎ÷ÖݹÜÕÊÊÂÎñËùSax 2024Äê7ÔÂÏÂÑ®Ôâ·êÊý¾Ýй¶ £¬Ò»Öܺó·¢ÏÖϵͳ´æÔÚδ¾­ÊÚȨ»î¶¯¡£ÁîÈËÕ𾪵ÄÊÇ £¬ÊÜÓ°ÏìÕßÖ±ÖÁ2025Äê12ÔÂ1ÈÕµ÷²éʵÏÖ¡¢¾àÀëÊÂÎñ·¢ÏÖÒѽü18¸öÔºó £¬²ÅµÃÖªÓ×ÎÒÐÅϢй¶¡£¾ÝSaxÏòÃåÒòÖÝ×ܼì²ì³¤Åû¶µÄÐÅÏ¢ £¬Õâ´ÎÊÂÎñÓ°Ï쳬22.8ÍòÈË £¬Éæ¼°¿Í»§¼°¸ß¾»ÖµÈËÊ¿µÄÓ×ÎÒÐÅÏ¢¡£SaxÔÚÊý¾Ýй¶֪ͨÖÐÇ¿µ÷ £¬ÊÂÎñ²úÉúºó¹«Ë¾µ±¼´²ÉÈ¡´ëÊ©±£ÏÕϵͳ°²È« £¬²¢Æô¶¯µ÷²éÒÔÈ·¶¨ÊÂÎñÐÔÖÊÓëÁìÓò¡£¹«Ë¾ÀñÆ¸ÍøÂ簲ȫר¼ÒЭÖúµ÷²é £¬²¢Î¯ÍеÚÈý·½Éó²éй¶Êý¾Ý¡£¹«Ë¾ËäÐû³Æ¡°ÎÞÖ¤¾ÝÅú×¢´æÔÚÏÖʵ»ò̰ͼÀÄÓÃÐÅÏ¢µÄÐÐΪ¡± £¬µ«18¸öÔµÄÑÓ³¤Í¨ÖªÈÔÈÃÊÜÓ°ÏìÕßÄÑÒÔÔÚµÚÒ»¹¦·ò²ÉÈ¡±£»¤´ëÊ© £¬Èç¶³½áÐÅÓþ¡¢¼à¿ØÒì³£»î¶¯µÈ £¬ÆÚ¼ä¹¥»÷ÕßÓгä×㹦·òÀûÓÃÇÔÊØÐÅÏ¢Ö´Ðз¸·¨ÐÐΪ¡£ÎªÌí²¹Ëðʧ £¬SaxΪÊÜÓ°ÏìÕßÌṩ12¸öÔÂÃâ·ÑÐÅÓþºÍ°µÍø¼à¿Ø·þÎñ £¬ÒÔ¼°Éí·Ý¸´Ô­ºÍÐÅÓþ±£»¤·þÎñ¡£


https://cybernews.com/security/sax-data-breach-quarter-million-exposed/