DiscordÔ¼ÇëÁ´½ÓÔâÐ®ÖÆ£¬ºÚ¿ÍʹÓÃÎó²îÇÔ¼ÓÃÜÇ®±Ò

Ðû²¼Ê±¼ä 2025-06-17

1. DiscordÔ¼ÇëÁ´½ÓÔâÐ®ÖÆ£¬ºÚ¿ÍʹÓÃÎó²îÇÔ¼ÓÃÜÇ®±Ò


6ÔÂ13ÈÕ£¬Çå¾²Ñо¿Ö°Ô±ÖÒÑÔ£¬ºÚ¿ÍÕýÐ®ÖÆÒÑÓâÆÚ»òÒÑɾ³ýµÄDiscordÔ¼ÇëÁ´½ÓʵÑé¹¥»÷¡£ÕâЩÁ´½ÓËä²»ÔÙÊÜ×î³õ½¨ÉèÕß¿ØÖÆ£¬µ«ÈÔÐû²¼ÔÚ¸÷ƽ̨ÉÏ£¬Óû§½ÓÊÜÔ¼Çëºó×°±¸¿ÉÄܱ»ÍêÈ«ÈëÇÖ£¬¼ÓÃÜÇ®±ÒÃæÁÙ±»µÁΣº¦¡£Check Point Research±¨¸æÖ¸³ö£¬¹¥»÷ÕßʹÓÃDiscordÔÊÐíÖØ¸´Ê¹ÓÃÓâÆÚ»òÒÑɾ³ýÔ¼ÇëÁ´½ÓµÄ¹¦Ð§£¬Í¨¹ýÐéαÑéÖ¤»úеÈ˺ʹ¹ÂÚÍøÕ¾ÓÕÆ­Óû§£¬Ê¹ÆäÔÚ²»ÖªÇéÇéÐÎÏÂÔËÐÐÓк¦ÏÂÁ½«¶ñÒâÈí¼þÏÂÔØµ½ÅÌËã»úÉÏ¡£ºÚ¿Í»¹ÀÄÓÃÆäËûÕýµ±·þÎñÒþ²Ø¶ñÒâÈí¼þ£¬Í¨¹ý¶à°ì·¨Èö²¥Ìӱܼì²â£¬Ö÷ҪĿµÄÊǼÓÃÜÇ®°ü£¬ÇÔȡƾ֤ºÍÇ®°üÐÅÏ¢£¬¸Ã¶ñÒâÈí¼þÒÑÔÚÃÀ¹ú¡¢Ô½ÄÏ¡¢·¨¹ú¡¢µÂ¹úµÈ¶à¹úÏÂÔØ³¬1300´Î¡£DiscordÔ¼Çëϵͳ±£´æÈ±ÏÝ£¬ºÚ¿Í¿Éͨ¹ýÐéÈÙÁ´½Ó×¢²áÐ®ÖÆÒÑÓâÆÚ»òÒÑɾ³ýÁ´½Ó£¬½«Óû§Öض¨ÏòÖÁ¶ñÒâ·þÎñÆ÷¡£¹¥»÷Õß»¹»áÔÚÈÈÃÅÆ½Ì¨Ñ°ÕÒÓâÆÚÁ´½ÓÖØÐÂ×¢²á£¬»òʹÓÃÔ¼ÇëÂë¾Þϸд²î±ð½¨ÉèÐÂÁ´½Ó¡£Óû§±»Öض¨Ïòµ½´¹ÂÚÍøÕ¾ºó£¬»áÓÕÆ­ÆäÏÂÔØ¶ñÒâÈí¼þ»òÔËÐжñÒâÏÂÁî¡£½üÆÚÕæÊµ¹¥»÷ʹÓÃAsyncRATºÍSkuld Stealer¶ñÒâÈí¼þÈëÇÖÓû§£¬Ç°ÕßÌṩԶ³Ì¿ØÖÆÄÜÁ¦£¬ºóÕßÇÔÈ¡Ãô¸ÐÓû§Êý¾Ý¡£Check PointÖÒÑԴ˴ι¥»÷Ô˶¯Ò»Ö±Ñݱ䣬¹¥»÷Õ߻ᰴÆÚ¸üÐÂÏÂÔØÆ÷£¬Õë¶Ô²î±ðÓû§ÈºÌåµ÷½âÓÕ¶üºÍ¹¤¾ß¡£Ö»¹ÜDiscordÒѽûÓÃÌØ¶¨Ô˶¯ÖÐʹÓõĶñÒâ»úеÈË£¬µ«½¹µãÕ½ÂÔÈÔ¿ÉÐС£


https://cybernews.com/security/hackers-steal-and-reanimate-discord-invite-links/


2. ºÚ¿ÍʹÓÃScattered SpiderÕ½ÂÔ¹¥»÷ÃÀ¹ú°ü¹Ü¹«Ë¾


6ÔÂ16ÈÕ£¬ÍþвÇ鱨Ñо¿Ö°Ô±·¢³öÖÒÑÔ£¬ºÚ¿Í¿ÉÄÜʹÓÃÔÚScattered SpiderÔ˶¯ÖÐÊӲ쵽µÄÕ½ÂÔÈëÇÖ¶à¼ÒÃÀ¹ú°ü¹ÜÒµ¹«Ë¾¡£¸ÃÍþв×é֯ͨ³£Õë¶ÔÌØ¶¨ÐÐÒµ£¬´Ëǰ´ÓÓ¢¹úÁãÊÛ»ú¹¹×ªÏòÃÀ¹úÙÉÐÐҵĿµÄ¡£¹È¸èÍþвÇ鱨¼¯ÍÅ£¨GTIG£©Ê×ϯÆÊÎöʦJohn HultquistÌåÏÖ£¬¹È¸èÍþвÇ鱨¼¯ÍÅÒÑ·¢Ã÷ÃÀ¹ú¾³ÄÚ¶àÆð¾ß±¸Scattered SpiderÔ˶¯ÌØÕ÷µÄÈëÇÖÊÂÎñ£¬°ü¹ÜÐÐÒµÒ²·ºÆðÀàËÆÇéÐΡ£ÓÉÓÚ¸Ã×é֯ÿ´ÎÖ»¹Ø×¢Ò»¸öÁìÓò£¬°ü¹ÜÒµÐè¼á³Ö¸ß¶ÈСÐÄ¡£GTIGÊ×ϯÑо¿Ô±Ö¸³ö£¬¹«Ë¾Ó¦ÌØÊâ×¢ÖØ·þÎñ̨ºÍºô½ÐÖÐÐÄ¿ÉÄÜÔâÓöµÄÉç»á¹¤³Ì¹¥»÷¡£Scattered SpiderÊÇһȺÁ÷¶¯µÄÍþвÐÐΪÕßͬÃË£¬½ÓÄÉÖØ´óÉç»á¹¤³Ì¹¥»÷ÈÆ¹ýÇå¾²³ÌÐò£¬»¹±»×·×ÙΪ0ktapus¡¢UNC3944µÈ¶à¸öÃû³Æ£¬Óë¶à¸ö×ÅÃû×éÖ¯ÈëÇÖÐÐΪÓйØ¡£ËûÃÇ»ìÏýʹÓÃÍøÂç´¹ÂÚ¡¢SIM¿¨½»Á÷ºÍMFAÆ£ÀÍ/ºäÕ¨µÈÊֶλñÈ¡³õʼ»á¼ûȨÏÞ£¬ºóÆÚͶ·ÅRansomHub¡¢QilinºÍDragonForceµÈÀÕË÷Èí¼þ¡£Îª·ÀÓù´ËÀ๥»÷£¬×éÖ¯Ó¦¸ôÀëÉí·Ý²¢Ê¹ÓÃǿʢÉí·ÝÑéÖ¤±ê×¼¼°ÑÏ¿áÉí·Ý¿ØÖÆÀ´ÖØÖÃÃÜÂëºÍMFA×¢²á¡£¼øÓÚScattered SpiderÒÀÀµÉç»á¹¤³Ìѧ£¬×éÖ¯Ðèͨ¹ý¶ÌÐÅ¡¢µç»°¡¢ÐÂÎÅÆ½Ì¨µÈÇþµÀ¶ÔÔ±¹¤ºÍÄÚ²¿Çå¾²ÍŶӾÙÐнÌÓý£¬±ÜÃâð³äÐÐΪ¡£


https://www.bleepingcomputer.com/news/security/google-warns-scattered-spider-hackers-now-target-us-insurance-companies/


3. ¡¶»ªÊ¢¶ÙÓʱ¨¡·µç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬¼ÇÕßÕË»§±»µÁ


6ÔÂ16ÈÕ£¬¿ËÈÕ£¬ÊýÃû¡¶»ªÊ¢¶ÙÓʱ¨¡·¼ÇÕߵĵç×ÓÓʼþÕË»§ÔÚÒ»´ÎÒÉËÆÓÉÍâ¹úÕþ¸®ÊµÑéµÄÍøÂç¹¥»÷Öб»µÁ¡£¸ÃÊÂÎñÓÚÖÜËÄÍí¼ä±»·¢Ã÷ºó£¬¡¶»ªÊ¢¶ÙÓʱ¨¡·Á¬Ã¦Õö¿ªÊӲ졣6ÔÂ15ÈÕ£¬Ò»·ÝÓÉÖ´ÐÐÖ÷±àÂíÌØ¡¤Ä¬ÀïÇ©ÊðµÄÄÚ²¿±¸Íü¼·¢Ë͸øÔ±¹¤£¬¼û¸æËûÃÇ¡°µç×ÓÓʼþϵͳ¿ÉÄÜÔâÓöδ¾­ÊÚȨµÄÓÐÕë¶ÔÐÔµÄÈëÇÖ¡±£¬ÇÒÓÐÏÞÊýÄ¿¼ÇÕßµÄ΢ÈíÕË»§Êܵ½Ó°Ïì¡£¡¶»ªÊ¢¶ÙÓʱ¨¡·ÓÉÑÇÂíÑ·Ê×´´È˽ܷò¡¤±´×ô˹ËùÓУ¬ÊÇÃÀ¹ú¼«¾ßÓ°ÏìÁ¦µÄ±¨Ö½Ö®Ò»¡£ÄÚ²¿ÐÂÎÅÈËʿ͸¶£¬´Ë´Î¹¥»÷Ä¿µÄΪ׫д¹ú¼ÒÇå¾²¡¢¾­¼ÃÕþ²ßÖ÷ÌâÎÄÕÂÒÔ¼°ÓйØÖйú±¨µÀµÄ¼ÇÕß¡£¸ß¼¶Ò»Á¬ÐÔÍþв£¨APT£©£¬¼´¹ú¼ÒÖ§³ÖµÄ¹¥»÷ÐÐΪÕߣ¬³£½«Microsoft ExchangeµÈµç×ÓÓʼþϵͳ×÷Ϊ¹¥»÷Ä¿µÄ¡£ÏÖÔÚ£¬¡¶»ªÊ¢¶ÙÓʱ¨¡·ÉÐδ¹ûÕæ·ÖÏí´Ë´ÎÏ®»÷µÄÈκÎϸ½Ú£¬´Ë´ÎÊÂÎñÔÙ´Î͹ÏÔÁ˵ç×ÓÓʼþÏµÍ³ÃæÁÙµÄÇ徲Σº¦£¬ÓÈÆäÊÇÕë¶ÔÌØ¶¨ÐÐÒµºÍÖ÷Ìâ¼ÇÕßµÄÕë¶ÔÐÔ¹¥»÷£¬¸øÐÂÎÅ»ú¹¹µÄÐÅÏ¢Çå¾²´øÀ´ÁËÑÏËàÌôÕ½¡£


https://www.bleepingcomputer.com/news/security/washington-posts-email-system-hacked-journalists-accounts-compromised/


4. ZoomcarÔâδÊÚȨ»á¼ûÖÂ840ÍòÓû§Êý¾Ýй¶


6ÔÂ16ÈÕ£¬ZoomcarÊÇÓ¡¶ÈÒ»¼Òµã¶ÔµãÆû³µ¹²ÏíÊг¡¹«Ë¾£¬½«³µÖ÷ÓëÑÇÖÞÐÂÐËÊг¡×â³µÕßÏàÁ¬£¬Ìṩ¶ÌÆÚºÍÖÐÆÚÆû³µ×âÁÞ·þÎñ¡£Zoomcarת´ï³Æ£¬6ÔÂ9ÈÕ·¢Ã÷Ò»ÆðÉæ¼°Î´¾­ÊÚȨ»á¼ûÆäÐÅϢϵͳµÄÍøÂçÇå¾²ÊÂÎñ¡£¹«Ë¾ÔÚ²¿·ÖÔ±¹¤ÊÕµ½ÍþвÐÐΪÕßÖ¸¿ØÎ´¾­ÊÚȨ»á¼û¹«Ë¾Êý¾ÝµÄÍⲿͨѶºó£¬²ÅÒâʶµ½ÕâÒ»ÊÂÎñ¡£³õ³ÌÐò²éÏÔʾ£¬840Íò¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢³µÁ¾¹ÒºÅºÅÂë¡¢¼Òͥסַ¡¢µç×ÓÓʼþµÈÊý¾ÝÒѱ»Ð¹Â¶¸øÎ´¾­ÊÚȨµÄÒ»·½¡£²»¹ý£¬ZoomcarÌåÏÖûÓÐÖ¤¾ÝÅú×¢Óû§²ÆÎñÐÅÏ¢¡¢Ã÷ÎÄÃÜÂë»òÆäËû¿ÉÄܵ¼ÖÂСÎÒ˽¼ÒÉí·Ýʶ±ðµÄÃô¸ÐÊý¾Ý±»Ð¹Â¶¡£ÏÖÔÚ£¬ZoomcarÈÔÔÚÆÀ¹À¸ÃÇå¾²ÊÂÎñµÄÏêϸ¹æÄ£ºÍDZÔÚÓ°Ï죬¹¥»÷ÀàÐÍÉÐδȷ¶¨£¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£ÖµµÃÒ»ÌáµÄÊÇ£¬2018ÄêZoomcar¾ÍÔâÓö¹ýÁíÒ»´ÎÖØ´óÊý¾Ýй¶£¬Ð¹Â¶Á˳¬350Íò¿Í»§¼Í¼£¬ÕâЩÊý¾Ý×îÖÕÓÚ2020ÄêÔÚµØÏÂÊг¡³öÊÛ£¬Ê¹¿Í»§ÃæÁÙ¸ü¸ßΣº¦¡£


https://www.bleepingcomputer.com/news/security/zoomcar-discloses-security-breach-impacting-84-million-users/


5. ¶à¹úÍŽáÐж¯µ·»Ù°µÍø¶¾Æ·ÉúÒâÊг¡Archetyp Market


6ÔÂ16ÈÕ£¬Óɵ¹ú¾¯·½Ç£Í·£¬Å·ÖÞÐ̾¯×éÖ¯ºÍÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖµÄ¡°Éî²ãÉÚ±øÐж¯¡±µ·»ÙÁËÎÛÃûÕÑÖøµÄ°µÍø¶¾Æ·ÉúÒâÊг¡Archetyp Market¡£¸ÃÊг¡×Ô2020Äê5ÔÂÔËÓª£¬Âô¼Òͨ¹ý3200¶à¼Ò×¢²á¹©Ó¦É̺ͳ¬17000¸öÇåµ¥£¬Îª612000¶àÃûÓû§Ìṩ¿É¿¨Òò¡¢°²·ÇËûÃ÷¡¢º£ÂåÒò¡¢´óÂé¡¢MDMAºÍ·ÒÌ«ÄáµÈ´ó×Ú¶¾Æ·£¬ÃÅÂÞ±Ò¼ÓÃÜÇ®±ÒÉúÒâ×ÜÉúÒâÁ¿³¬2.5ÒÚÅ·Ôª£¨Ô¼2.89ÒÚÃÀÔª£©¡£ÔÚÐж¯ÖУ¬ºÉÀ¼ÊÓ²ìÖ°Ô±´Ý»ÙÆä»ù´¡ÉèÊ©£¬Î÷°àÑÀ°ÍÈûÂÞÄǾв¶Ò»ÃûÉæÏÓµ£µ±Êг¡ÖÎÀíÔ±µÄ30ËêµÂ¹ú¹úÃñ£¬µÂ¹úºÍÈðµä»¹¾Ð²¶ÁËÒ»ÃûÖÎÀíÔ±ºÍÁùÃû×î¸ß¼¶±ð¹©Ó¦ÉÌ¡£Ö´·¨Ö°Ô±¹²½É»ñ47²¿ÖÇÄÜÊÖ»ú¡¢45̨µçÄÔ¡¢¶¾Æ·ÒÔ¼°¼ÛÖµ780ÍòÅ·ÔªµÄ×ʲú¡£Å·ÖÞÐ̾¯×éÖ¯³Æ£¬6ÔÂ11ÈÕÖÁ13ÈÕ£¬¶à¹ú½ÓÄÉЭÙÉÐж¯£¬Ô¼300Ãû¾¯Ô±¼ÓÈ룬ĿµÄÊÇÆ½Ì¨ÖÎÀíÔ±¡¢°æÖ÷¡¢Ö÷Òª¹©Ó¦É̺ÍÊÖÒÕ»ù´¡ÉèÊ©£¬´Ë´Î¹¥»÷´Ý»ÙÁ˰µÍøÉÏÒ»Á¬Ê±¼ä×µÄ¶¾Æ·Êг¡Ö®Ò»£¬ÇжÏÁËÖ÷Òª¹©Ó¦Ïß¡£±ðµÄ£¬5ÔÂÖ´·¨²¿·ÖÔÚ¡°RapTorÐж¯¡±ÖÐÓ־в¶270ÃûÏÓÒÉÈË£¬¸ÃÐж¯Õë¶ÔÀ´×Ô10¸ö¹ú¼ÒµÄ°µÍø¹©Ó¦É̼°Æä¿Í»§£¬Å·ÖÞ¡¢ÄÏÃÀ¡¢ÑÇÖÞºÍÃÀ¹úµÄ¾¯Ô±»¹½É»ñ³¬2¶Ö¶¾Æ·¡¢³¬1.84ÒÚÅ·ÔªÏÖ½ðºÍ¼ÓÃÜÇ®±ÒÒÔ¼°³¬180֧ǹ֧¡£ÊÓ²ìÖ°Ô±µ·»Ù¶à¸ö°µÍøÊг¡ºóÍøÂçÇ鱨£¬Ê¶±ð³öÐí¶àÔÚ²»·¨ÍøÉÏÊг¡¾ÙÐÐÊýǧ±ÊÏúÊÛµÄÏÓÒÉÈË¡£


https://www.bleepingcomputer.com/news/security/police-seizes-archetyp-market-drug-marketplace-arrests-admin/


6. ±±¿¨°¢Ê²Î¬¶ûÑÛ¿ÆÐ­»áÊý¾Ýй¶£¬14.7ÍòÈËÐÅÏ¢±»µÁ


6ÔÂ16ÈÕ£¬±±¿¨ÂÞÀ´ÄÉÖݰ¢Ê²Î¬¶ûÑÛ¿ÆÐ­»á£¨AEA£©Í¨ÖªÔ¼147,000ÃûСÎÒ˽¼Ò£¬ÆäСÎÒ˽¼ÒÐÅÏ¢ÔÚ2024Äê11ÔµÄÊý¾Ýй¶ÊÂÎñÖб»µÁ¡£¸ÃÊÂÎñÓÚ11ÔÂ18ÈÕ±»·¢Ã÷£¬ÆäʱÍþвÐÐΪÕß½øÈë¹«Ë¾ÍøÂç²¢ÇÔÈ¡ÁËijЩÎļþ¡£AEAѸËÙÔ¼ÇëµÚÈý·½×¨¼ÒЭÖú±£»¤ÍøÂçÇéÐβ¢ÊÓ²ìÊÂÎñ¡£¶Ô±»µÁÊý¾ÝµÄÊÓ²ìÓÚ2025Äê4ÔÂ14ÈÕ¿¢Ê£¬È·¶¨ÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢ÖÎÁÆÏêÇéºÍ¿µ½¡°ü¹ÜÐÅÏ¢µÈСÎÒ˽¼ÒÐÅÏ¢ÔÚÏ®»÷Öб»µÁ¡£×èֹ֪ͨ·¢³öʱ£¬AEAÉÐδÊÕµ½ÈκÎÓë´ËÊÂÎñÓйصÄÉí·Ý͵ÇÔ±¨¸æ¡£¸ÃÑÛ¿ÆÖÐÐÄ×î³õÓÚ1ÔÂ31ÈÕÏòÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿Åû¶ÁËÕâÒ»ÊÂÎñ£¬Æäʱ³ÆÓÐ193,306ÈËÊÜÓ°Ï죬ºó¸ÃÊý×Ö¸üÐÂΪ204,984ÈË¡£ÏÖÔÚ£¬AEAÌåÏÖÒÑÈ·¶¨ÊÜÓ°Ïì¼Í¼ÖаüÀ¨¸ü¶àСÎÒ˽¼ÒÐÅÏ¢µÄСÎÒ˽¼Ò£¬²¢Ïò147,116ÈË·¢ËÍÁË֪ͨÐÅ£¬»¹ÎªËûÃÇÌṩ12¸öÔµÄÃâ·ÑÉí·Ý͵ÇÔ±£»¤·þÎñ¡£²»¹ý£¬AEAÉÐδ͸¶ÆäÔâÊܵÄÍøÂç¹¥»÷ÀàÐ͵ÄÏêϸÐÅÏ¢¡£ÖµµÃ×¢ÖØµÄÊÇ£¬DragonForceÀÕË÷Èí¼þÍÅ»ïÓÚ12Ô½«AEAÌí¼Óµ½Æä»ùÓÚTorµÄйÃÜÍøÕ¾£¬Éù³ÆÇÔÈ¡Á˽ü540GBµÄÊý¾Ý£¬ÇÒ¸Ã×éÖ¯ÒÔºóÒѽ«ÕâЩÊý¾Ý¹ûÕæ¡£


https://www.securityweek.com/asheville-eye-associates-says-147000-impacted-by-data-breach/