SubstackÊý¾Ýй¶£º69ÍòÓû§ÐÅÏ¢ÔâÇÔ

°ä²¼¹¦·ò 2026-02-06

1. SubstackÊý¾Ýй¶£º69ÍòÓû§ÐÅÏ¢ÔâÇÔ


2ÔÂ5ÈÕ£¬ÐÂÎÅͨѶƽ̨SubstackÅû¶£¬ÆäϵͳÔÚ2025Äê10ÔÂÔâ·êÊý¾Ýй¶£¬¹¥»÷Õß·¸·¨½Ó¼ûÁËÔ̺¬µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¼°ÄÚ²¿ÔªÊý¾ÝÔÚÄÚµÄÓÐÏÞÓû§Êý¾Ý£¬µ«Î´»ñÊØÐÅÓþ¿¨ºÅ¡¢ÃÜÂëµÈÃô¸Ð²ÆÕþÐÅÏ¢¡£Ö»¹ÜÊÂÎñ²úÉúËĸöÔºó²Å±»·¢ÏÖ£¬Ê×ϯִÐйٿËÀï˹¡¤±´Ë¹ÌØÔÚ֪ͨÖÐÇ¿µ÷Òѽ¨¸´ÏµÍ³·ì϶£¬²¢ÖÒ¸æÓû§¾¯ÌèDZÔÚÍøÂç´¹µö¹¥»÷¡£¾ÝÍþвÐÐΪÕßÔÚBreachForumsºÚ¿ÍÂÛ̳¹«¿ªµÄÐÅÏ¢£¬Õâ´ÎÐ¹Â¶Éæ¼°697,313ÌõÊý¾Ý¼Í¼£¬¹¥»÷Õ߳ơ°×¥È¡²½Öè´æÔÚÔëÉùÇÒÒѼ±¾ç½¨¸´¡±¡£SubstackËäδ°ä²¼ÊÜÓ°ÏìÓû§×ÜÊý£¬µ«ÈϿɴæÔÚÊý¾Ýй¶·çÏÕ£¬²¢ºôÓõÓû§¶Ô¿ÉÒÉÓʼþ»ò¶ÌÐÅά³Ö¸ß¶È¾¯Ìè¡£¹«Ë¾°µÊ¾ÎÞÖ¤¾ÝÏÔʾ±»µÁÐÅÏ¢Òѱ»ÀÄÓ㬵«ÒѲÉÈ¡´ëÊ©¼Óǿϵͳ°²È«¡£Õâ²¢·ÇSubstack³õ´Î³öÏÖÊý¾Ý°²È«ÎÊÌâ¡£2020Äê7Ô£¬¸Ãƽ̨ÔÚ·¢ËÍÒþÖÔÕþ²ß¸üÐÂÓʼþʱ£¬ÒòÃýÎóʹÓá°ÊÕ¼þÈË¡±×ֶζø·Ç¡°ÃÜËÍ¡±£¬µ¼Ö²¿ÃÅÓû§ÓÊÏ䵨ַ±»¹«¿ªÐ¹Â¶¡£


https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/


2. Î÷°àÑÀ¿ÆÑ§²¿ÒòÍøÂç¹¥»÷²¿ÃŹعØITϵͳ


2ÔÂ5ÈÕ£¬Î÷°àÑÀ¿ÆÑ§¡¢´´Ðºʹóѧ²¿½üÈÕ°ä·¢²¿ÃÅ¹Ø¹ØÆäITϵͳ£¬´Ë¾Ù½«Ó°Ïì¶à¸öÃæÏò¹«ÃñºÍÆóÒµµÄ·þÎñ¡£×÷ÎªÕÆ¹Ü¿ÆÑ§Õþ²ß¡¢×êÑÓ×¢´´Ð¼°¸ßµµ½ÌÓýÈ·µ±¾Ö»ú¹¹£¬¸Ã²¿ÃÅ»¹ÊØ»¤×Å´¦ÖÃ×êÑÐÈËÔ±¡¢´óѧºÍѧÉúÃô¸ÐÐÅÏ¢µÄÐÐÕþϵͳ¡£Õâ´Î¹Ø¹ØÊǶÔһ·¡°¼¼ÊõÊÂÎñ¡±µÄ»ØÓ¦£¬µ«¹Ù·½Î´Ð¹Â©¸ü¶àϸ½Ú¡£¾ÝÍøÂç¹¥»÷Õß¡°¸êµÇ¡¤¸¥ÀïÂü¡±Ðû³Æ£¬ÆäÀûÓÃÑϳÁµÄ¡°²»°²È«Ö±½Ó¶ÔÏóÒýÓã¨IDOR£©¡±·ì϶ÈëÇÖÁ˸ò¿ÃÅϵͳ£¬²¢»ñµÃÁË¡°ÆëÈ«ÖÎÀíÔ±¼¶±ð½Ó¼ûȨÏÞ¡±¡£¸Ã¹¥»÷ÕßÔÚµØÏÂÂÛ̳¶µÏú¾Ý³Æ´ÓÎ÷°àÑÀ¿ÆÑ§²¿ÇÔÈ¡µÄÊý¾Ý£¬Ô̺¬Ó×ÎҼͼ¡¢µç×ÓÓʼþµØÖ·¡¢ÈëѧÉêÇë¼°¹Ù·½Îļþ½ØÍ¼¡£ÎªÖ¤Ã÷ÈëÇÖÊÂʵ£¬¹¥»÷Õß»¹°ä²¼ÁËÊý¾ÝÑù±¾¡£È»¶ø£¬ÓйØÂÛ̳ĿǰÒÑÏÂÏߣ¬ÇÒÊý¾ÝÉÐδ³Ê´Ë¿ÌÆäËûƽ̨¡£Î÷°àÑÀ¿ÆÑ§²¿ÍøÕ¾Ö÷Ò³²¼¸æÏÔʾ£¬ÓÉÓÚ¡°¼¼Êõ±äÂÒ¡±£¬Æäµç×Ó×ܲ¿ÒѲ¿ÃŹعØ£¬ËùÓÐÐÐÕþ·¨Ê½ÔÝÍ££¬µ«»á±£ÏÕÊÜÓ°ÏìÕßµÄÈ¨ÊÆºÍºÏ·¨È¨Àû¡£Î÷°àÑÀýÌ屨·³Æ£¬¸Ã²¿Ã޲»°ÈËÒÑ֤ʵÕâ´ÎITϵͳÖжÏÓëÍøÂç¹¥»÷ÓйØ¡£


https://www.bleepingcomputer.com/news/security/spains-ministry-of-science-shuts-down-systems-after-breach-claims/


3. ÀÕË÷Èí¼þÀÄÓúϷ¨Ð鹹ƽ̨ÍйܶñÒâÔØºÉ


2ÔÂ5ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾SophosÔÚµ÷²é"WantToCry"ÀÕË÷Èí¼þ¹¥»÷ʱ·¢ÏÖ£¬ÀÕË÷Èí¼þÔËÓªÕßÕý´ó¹æÄ£ÀÄÓúϷ¨Ðé¹¹»ù´¡ÉèÊ©ÖÎÀíÌṩÉÌISPsystemµÄÐé¹¹»ú£¨VM£©ÍйܺÍͶ·Å¶ñÒâÔØºÉ¡£×êÑÐÈËÔ±°ÑÎȵ½£¬¹¥»÷ÕßʹÓõÄWindowsÐé¹¹»úÖ÷»úÃû¸ß¶ÈÒ»Ö£¬Ö¸ÏòISPsystemÆìÏÂVMmanagerƽ̨µÄĬÈÏÄ£°å£¬¸Ãƽ̨ΪÖ÷»úÍйܷþÎñÉÌÌṩÐé¹¹·þÎñÆ÷ÖÎÀíÖ°ÄÜ£¬Ö§³Ö¼±¾ç²¿ÊðWindows»òLinuxÐé¹¹»ú¡£½øÒ»´ëÊ©²éÏÔʾ£¬LockBit¡¢Qilin¡¢Conti¡¢BlackCat/ALPHVµÈ³ÛÃûÀÕË÷Èí¼þ×éÖ¯£¬ÒÔ¼°RedLine¡¢LummarÐÅÏ¢ÇÔÈ¡·¨Ê½»î¶¯£¬¾ùÔÚÆä»ù´¡ÉèÊ©ÖÐʹÓÃÁËÒ»ÑùµÄVMmanagerĬÈÏÖ÷»úÃû¡£SophosÖ¸³ö£¬VMmanagerµÄĬÈÏWindowsÄ£°åÔÚÿ´Î²¿Êðʱ»á³Á¸´Ê¹ÓÃÒ»ÑùÖ÷»úÃûºÍϵͳ±êʶ·û£¬ÕâÒ»Éè¼Æ·ì϶±»²¿ÃÅÍйܷþÎñÉ̶ñÒâÀûÓã¬ËûÃÇÃ÷Öª¿Í»§´ÓÊÂÍøÂç·¸×ï»î¶¯£¬ÈÔÌṩ·þÎñ²¢ºöÊÓϼÜÒªÇ󣬽«¶ñÒâϵͳ°µ²ØÔÚ´óÁ¿ÎÞº¦Ðé¹¹»úÖУ¬Ê¹ËÝÔ´ºÍ¶Ï¸ù±äµÃÄÑÌâ¡£


https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-ispsystem-vms-for-stealthy-payload-delivery/


4. ÂÞÂíLa Sapienza´óѧÔâÀÕË÷Èí¼þ¹¥»÷ÖÂϵͳ̱»¾


2ÔÂ5ÈÕ£¬ÂÞÂíLa Sapienza´óѧ½üÈÕÔâ·êÍøÂç¹¥»÷£¬ÆäITϵͳÔâ·êÑϳÁ·ÛË飬µ¼Ö½ÌÓý»ú¹¹ÔËÓª´óÁìÓòÖжÏ¡£×÷ΪŷÖÞÔÚУѧÉúÈËÊý×î¶àµÄ´óѧ£¬¸ÃУռÓг¬¹ý112,500Ãû×¢²áѧÉú£¬Õâ´ÎÊÂÎñ¶ÔÆä½²ÊÚ¡¢ÐÐÕþ¼°¿ÆÑлÔì³É³Á´óÓ°Ïì¡£¸ÃУ±¾ÖÜÔçЩʱ³½ÔÚÉ罻ýÌå³õ´ÎÅû¶ÊÂÎñ£¬³ÆÆäIT»ù´¡ÉèÊ©¡°ÒѳÉÎªÍøÂç¹¥»÷µÄÖ¸±ê¡±£¬²¢×÷ΪԤ·À´ëÊ©µ±¼´¹Ø¹ØÍøÂçϵͳÒÔ±£ÏÕÊý¾ÝÆëÈ«ÐԺͰ²È«ÐÔ¡£½ØÖÁ·¢¸åʱ£¬´óÑ§ÍøÕ¾ÈÔÎÞ·¨½Ó¼û£¬Instagram×îÐÂ״̬ÏÔʾѧÌöÔÈ«Á¦´Ó¹¥»÷Öи´Ô­£¬²¢ÉèÁ¢Ò»Ê±¡°ÐÅÏ¢µã¡±ÎªÑ§ÉúÌṩÎÞ·¨Í¨¹ýÊý×Öϵͳ½Ó¼ûµÄÐÅÏ¢¡£¾ÝÒâ´óÀû¡¶ÍíÓʱ¨¡·±¨Â·£¬Õâ´Î¹¥»÷ÓÉÇ×¶íÍþвÐÐΪÕßFemwar02Ö´ÐУ¬Ï·ÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ý¼ÓÃÜ¡£¸ÃÀÕË÷Èí¼þÌØµãÓëBablock/RorschachÀàËÆ£¬×îÔç³öÏÖÓÚ2023Ä꣬ÒÔ¼ÓÃÜ¿ìÂʿ졢×Ô½ç˵ѡÏî·áË¶Öø³Æ£¬ÓÉй¶µÄBabuk¡¢LockBit v2.0ºÍDarkSide²¿ÃÅÔ´´úÂë¹¹½¨¶ø³É¡£Ä¿Ç°£¬¸ÃУ¼¼ÊõÈËÔ¹ØýÓëÒâ´óÀûÍøÂ簲ȫÊÂÎñÏìÓ¦Ó××飨CSIRT£©¡¢¹ú¶ÈÍøÂ簲ȫ¾Ö£¨ACN£©¼°ÓÊÕþ¾¯Ô±×¨¼ÒºÏ×÷£¬´ÓδÊÜÓ°ÏìµÄ±¸·ÝÖи´Ô­ÏµÍ³¡£


https://www.bleepingcomputer.com/news/security/italian-university-la-sapienza-goes-offline-after-cyberattack/


5. ÂÞÂíÄáÑÇConpetʯÓ͹Ü·Ôâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷


2ÔÂ5ÈÕ£¬ÂÞÂíÄáÑǹú¶ÈʯÓ͹Ü·ÔËÓªÉÌConpet½üÈÕÅû¶£¬Öܶþ²úÉúµÄÍøÂç¹¥»÷µ¼ÖÂÆäÆóÒµIT»ù´¡ÉèÊ©ÊÜËð¡¢ÍøÕ¾Ì±»¾£¬µ«Ö÷ÌâÒµÎñϵͳÈçSCADAºÍµçÐÅϵͳδÊÜÓ°Ï죬ԭÓͼ°ÆûÓÍÔËÊäµÈÖ÷ÌâÔËÓªÈÔÕý³£ÔË×÷¡£¸Ã¹«Ë¾ÔËÓª½ü4000¹«Àï¹ÜÂ·ÍøÂ磬ÏòÈ«¹úÁ¶Óͳ§¹©¸øÔ­Óͼ°ÆäÑÜÉúÎÊÂÎñδÖÐ¶ÏÆäºÏÍ¬ÍÆ¹ãÄÜÁ¦¡£ConpetÔÚÖÜÈýÐÂΟåÖаµÊ¾£¬ÕýÓë¹ú¶ÈÍøÂ簲ȫ»ú¹¹ºÏ×÷µ÷²éÊÂÎñ²¢¸´Ô­ÏµÍ³£¬Í¬Ê±ÒÑÏòÓÐ×éÖ¯·¸×ïºÍ¿Ö²ÀÖ÷Òåµ÷²é¾Ö£¨DIICOT£©ÌáÆðÐÌÊÂËßËÏ¡£Ö»¹ÜÔËÓª¼¼Êõϵͳ°²È«£¬µ«¹«Ë¾ÍøÕ¾www.conpet.roÈÔÎÞ·¨½Ó¼û£¬¸´Ô­¹¦·ò䶨¡£÷è÷ëÀÕË÷Èí¼þÍÅ»ïÒÑÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Öн«ConpetÁÐΪÊܺ¦Õß¡£ÍþвÐÐΪÕßÐû³ÆÇÔÈ¡½ü1TBÎļþ£¬Ô̺¬²ÆÕþÐÅÏ¢¡¢»¤ÕÕɨÃè¼þµÈÄÚ²¿ÎļþÕÕÆ¬×÷Ϊ֤¾Ý¡£ÈôÊý¾Ý±»½øÒ»²½´«²¼»òÏúÊÛ£¬¿ÉÄÜÒý·¢¶þ´Î°²È«·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/romanian-oil-pipeline-operator-conpet-discloses-cyberattack-qilin-ransomware/


6. SystemBC¶ñÒâÈí¼þ½©Ê¬ÍøÂç¾íÍÁ³ÁÀ´


2ÔÂ5ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Silent Push½üÈÕ·¢³öÖҸ棬SystemBC¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½ÔÚ·¨Âɲ¿ÃÅ¡°ÖÕ¾ÖÐж¯¡±½ø¹¥ºóÈÔ´æÐø£¬²¢Òѽ«³¬10,000Ì¨ÍÆËã»úÄÉÈë½©Ê¬ÍøÂç¡£¸Ã¶ñÒâÈí¼þ×Ô2019ÄêÆð»îÔ¾£¬±ðºÅCoroxyºÍDroxiDat£¬ÒÔ³äÈκóÃÅ¡¢ÀÄÓÃÊÜϰȾ»úе½øÐÐÁ÷Á¿´úÀí¼°´«²¼ÀÕË÷Èí¼þµÈ¶ñÒâÔØºÉÎÅÃû£¬ÔøÓÚ2024Äê5Ô³ÉΪ¹ú¼Ê·¨Âɲ¿ÃųÁµã½ø¹¥Ö¸±ê¡£Ö»¹Ü·¨Âɲ¿ÃÅЭµ÷Ðж¯£¬µ«SystemBC¿ª·¢ÕßÈÔÔÚ¶íÓïµØÏÂÂÛ̳°ä²¼¸üÐÂÐÅÏ¢£¬½©Ê¬ÍøÂç»î¶¯Î´ÖÕ³¡¡£µ±Ç°³¬1Íò¸öIPµØÖ·¹ØÁªSystemBCÁ÷Á¿£¬ÆäÖÐÃÀ¹úÕ¼±È×î¸ß£¨4300¸ö£©£¬µÂ¹ú£¨829¸ö£©¡¢·¨¹ú£¨448¸ö£©¡¢ÐÂ¼ÓÆÂ£¨419¸ö£©ºÍÓ¡¶È£¨294¸ö£©Òà·¢ÏÖ´óÁ¿Êܺ¦Õß¡£¸Ã¶ñÒâÈí¼þÖØÒªÕë¶ÔÍйܷþÎñÌṩÉÌ£¬²¼»ùÄÉ·¨Ë÷ºÍÔ½ÄϹٷ½ÓòÃûÍйܵÄIPµØÖ·ÖУ¬SystemBCϰȾÃܶÈÏÔÖø¡£¼¼Êõ²ãÃæ£¬SystemBCѡȡÂÖ»»¼Ü¹¹£¬¿Í»§¶ËÏνÓ¶³öÓÚ»¥ÁªÍøµÄC&C·þÎñÆ÷£¬Í¨¹ýÊÜϰȾÖ÷»ú´úÀíÁ÷Á¿£¬½«»úеת»¯ÎªSOCKS5´úÀíÒÔ°µ²Ø¶ñÒâ»ù´¡ÉèÊ©²¢»ñÈ¡¾­¼ÃÀûÒæ¡£


https://www.securityweek.com/systembc-infects-10000-devices-after-defying-law-enforcement-takedown/