÷è÷ëÀÕË÷Èí¼þ½è¡°Öµç״ʦ¡±¼°¶à¹¤¾ßÇ¿»¯Êê½ðʩѹ
Ðû²¼Ê±¼ä 2025-06-231. ÷è÷ëÀÕË÷Èí¼þ½è¡°Öµç״ʦ¡±¼°¶à¹¤¾ßÇ¿»¯Êê½ðʩѹ
6ÔÂ20ÈÕ£¬÷è÷ëÀÕË÷Èí¼þ·¸·¨·Ö×Ó½üÆÚÍÆ³öÐÂÓªÏúÕ½ÂÔ£¬Îª¹ØÁª¹«Ë¾Ìṩ¾«Èñ״ʦÍŶÓÒÔ¼Ó´óÊê½ð̸ÅÐѹÁ¦¡£CybereasonÑо¿Ö°Ô±·¢Ã÷£¬µØÏÂÍøÂç·¸·¨ÂÛ̳°æÖ÷Ðû²¼Ìû×Ó£¬Éù³ÆÔÚÁ¥ÊôÃæ°åÌí¼Ó¡°Öµç״ʦ¡±°´Å¥£¬µ¥»÷¼´¿ÉÕÙ»½Ö´·¨×¨¼Ò½øÈëÊê½ð̸ÅÐ̸Ìì´°¿Ú£¬¾ÍÊý¾ÝÖ´·¨ÆÀ¹À¡¢Êܺ¦ÕßÎ¥·¨Î¥¹æÇéÐμ°²»Ö§¸¶Êê½ðµÄDZÔÚÕûÀí±¾Ç®µÈÎÊÌâÌṩרҵ½¨Ò飬״ʦÉõÖÁ¿ÉÖ±½Ó½éÈë̸Åв¢¼û¸æÊܺ¦Õß²»Ö§¸¶Êê½ð½«ÃæÁٵġ°×î´óËðʧ¡±¡£±ðµÄ£¬÷è÷ëÍø»¹Éù³ÆÓµÓÐÄÚ²¿¼ÇÕßÍŶӣ¬¿ÉÓëÖ´·¨²¿·ÖÏàÖú׫д²©¿ÍÎÄÕ½øÒ»²½Ê©Ñ¹¡£È»¶ø£¬×¨¼Ò¶Ô´ËÌåÏÖÏÓÒÉ£¬TripwireÍøÂç·¸·¨Ñо¿Ô±Graham CluelyÒÔΪÕâ²»¹ýÊÇÓªÏúàåÍ·£¬Ö¼ÔÚÎüÒý¸ü¶àͬÃËÕß¡¢Ìá¸ßÀÕË÷Èí¼þ¹¥»÷ÀÖ³ÉÂʲ¢ÈÃÊܺ¦ÕßÐÅÍÐÆäÀÏÁ·Ë®Æ½¡£¾ÝCybereason³Æ£¬÷è÷뻹ΪͬÃËÃæ°åÌí¼ÓÁË1PB´æ´¢¿Õ¼ä¡¢µç×ÓÓʼþºÍµç»°À¬»øÓʼþ¹¦Ð§¡¢ÍøÂçÈö²¥¼°ÌᳫDDoS¹¥»÷µÄÑ¡ÏîµÈй¤¾ß¡£Ëæ×ÅÀÏÅÆÀÕË÷Èí¼þ×éÖ¯ÈçLockBit¡¢ALPHVµÈÒòÖÖÖÖÔµ¹ÊÔÓɵ¹Ï£¬÷è÷ëÕýÖð½¥³ÉΪ×îÖ÷ÒªµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯Ö®Ò»¡£¸Ã×éÖ¯×Ô2022ÄêÆð¾ÍÒѱ£´æ£¬²¢Í¨¹ý¸ßµ÷¹¥»÷Öð½¥½¨ÉèÉùÓþ¡£
https://www.theregister.com/2025/06/20/qilin_ransomware_top_dogs_treat/
2. CoinMarketCapÔ⹩ӦÁ´¹¥»÷£º¶ñÒâ¾ç±¾ÇÔÈ¡¼ÓÃÜÇ®±Ò
6ÔÂ22ÈÕ£¬¼ÓÃÜÇ®±Ò¼ÛÇ®¸ú×ÙÍøÕ¾CoinMarketCapÔâÓöÍøÕ¾¹©Ó¦Á´¹¥»÷£¬ÖÂʹ»á¼ûÕßÃæÁÙ¼ÓÃÜÇ®±Ò±»µÁΣº¦¡£1ÔÂ20ÈÕÍí£¬ÍøÕ¾·Ã¿Í¿´µ½ÒªÇóÅþÁ¬Ç®°üµÄWeb3µ¯´°£¬ÅþÁ¬ºó¶ñÒâ¾ç±¾ÇÔÈ¡Æä¼ÓÃÜÇ®±Ò¡£¸Ã¹«Ë¾ºóÐøÖ¤Êµ£¬ÍþвÐÐΪÕßʹÓÃÍøÕ¾Ö÷Ò³¡°Í¿Ñ»¡±Í¼ÏñÎó²î×¢Èë¶ñÒâJavaScript¡£Çå¾²ÍŶӷ¢Ã÷£¬¸ÃͿѻͼÏñ°üÀ¨µÄÁ´½Óͨ¹ýAPIŲÓô¥·¢¶ñÒâ´úÂ룬µ¼ÖÂÓû§»á¼ûÖ÷ҳʱ·ºÆðÒâÍⵯ³ö´°¿Ú¡£·¢Ã÷ÎÊÌâºó£¬CoinMarketCapÁ¬Ã¦½ÓÄÉÐж¯£¬É¾³ýÎÊÌâÄÚÈÝ¡¢ÕÒ³ö»ù´¡Ôµ¹ÊÔÓɲ¢½ÓÄɲ½·¥¸ôÀ뻺ºÍ½âÎÊÌ⣬ÏÖÔÚËùÓÐϵͳÒÑÖÜÈ«ÔËÐУ¬ÍøÕ¾¶ÔÓû§Çå¾²¿É¿¿¡£ÍøÂçÇå¾²¹«Ë¾c/sideÚ¹ÊÍ£¬¹¥»÷ÕßÐÞ¸ÄÁËÍøÕ¾ÓÃÓÚ¼ìË÷ͿѻͼƬ²¢ÔÚÖ÷Ò³ÏÔʾµÄAPI£¬¸Ä¶¯µÄJSON¸ºÔذüÀ¨¶ñÒâ¾ç±¾±êÇ©£¬´ÓÍâ²¿ÍøÕ¾ÏòCoinMarketCap×¢ÈëÇ®°üÏûºÄ¾ç±¾£¬Ò³Ãæ»á¼ûʱ¾ç±¾Ö´ÐУ¬µ¯³öαÔìµÄÇ®°üÅþÁ¬µ¯´°£¬ÏÖʵΪǮ°üÏûºÄÆ÷£¬Ö¼ÔÚÇÔÈ¡ÒÑÅþÁ¬Ç®°ü×ʲú¡£´Ë´ÎΪ¹©Ó¦Á´¹¥»÷£¬Ê¹ÓÃÁËÆ½Ì¨µÄ¿ÉÐÅÔªËØ£¬ÄÑÒÔ±»·¢Ã÷¡£ÍþвÐÐΪÕßRey͸¶£¬¹¥»÷ÕßÔÚTelegramƵµÀ·ÖÏíºÄË®Æ÷Ãæ°å½ØÍ¼£¬´Ë´Î¹¥»÷µ¼ÖÂ110ÃûÊܺ¦Õß±»ÍµÈ¡43,266ÃÀÔª¡£
https://www.bleepingcomputer.com/news/security/coinmarketcap-briefly-hacked-to-drain-crypto-wallets-via-fake-web3-popup/
3. Å£½òÊÐÒé»áÔâÓöÊý¾Ýй¶£¬Ð¹Â¶Á˶þÊ®ÄêµÄÊý¾Ý
6ÔÂ22ÈÕ£¬Å£½òÊÐÒé»á¿ËÈÕ·¢³öÖÒÑÔ£¬³ÆÔâÓöÊý¾Ýй¶ÊÂÎñ£¬¹¥»÷Õß´Ó¾ÉϵͳÖлñÈ¡ÁËСÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡£´Ë´ÎÊÂÎñ»¹µ¼ÖÂICT·þÎñÖÐÖ¹£¬Ö»¹Ü´ó²¿·ÖÊÜÓ°ÏìϵͳÒѻָ´£¬µ«Ê£Óà»ýѹÊÂÇé¿ÉÄÜÈÔ»áÔì³ÉÑÓÎó¡£Å£½òÊÐÒé»á×÷ΪӢ¹úÅ£½òÈÏÕæÖÎÀíס·¿¡¢ÍýÏë¡¢À¬»øÍøÂçµÈÖ÷Òª¹«¹²·þÎñµÄµØ·½Õþ¸®»ú¹¹£¬·þÎñÓÚÔ¼155,000ÃûסÃñ£¬ÇÒÒòÅ£½ò´óѧ¡¢ÂÃÓÎÒµºÍÑо¿»ú¹¹µÄ¹ú¼Ê×ÅÃû¶È£¬ÆäÓ°ÏìÁ¦½øÒ»²½À©´ó¡£¾Ý¸Ã»ú¹¹ÍøÕ¾ÉùÃ÷£¬¹¥»÷Õßδ¾ÊÚȨ»á¼ûÁ˴洢СÎÒ˽¼ÒÐÅÏ¢µÄϵͳºÍÊý¾Ý¿â£¬³õ³ÌÐò²éÏÔʾ£¬ÊÜÓ°ÏìµÄϵͳ°üÀ¨2001ÄêÖÁ2022Äêʱ´úǰÈκÍÏÖÈÎÀíÊ»á¹ÙÔ±µÄÐÅÏ¢¡£ÉùÃ÷ÖÐÌáµ½£¬¹¥»÷ÕßÄܹ»»á¼ûÒÅÁôϵͳÉϵÄһЩÀúÊ·Êý¾Ý£¬¿ÉÄÜÉæ¼°ÔÚÅ£½òÊÐÒé»áÖÎÀíÑ¡¾ÙÖÐÊÂÇéµÄÖ°Ô±£¬°üÀ¨Í¶Æ±Õ¾ÊÂÇéÖ°Ô±ºÍ¼ÆÆ±Ô±µÄСÎÒ˽¼ÒÐÅÏ¢¡£²»¹ý£¬ÉùÃ÷Ò²Ö¸³ö£¬Ã»ÓÐÖ¤¾ÝÅúעй¶µÄÊý¾ÝÒѱ»½øÒ»²½Èö²¥£¬ÇÒδÌá¼°¹«ÃñÊý¾ÝÔ⵽й¶¡£Å£½òÊÐÒé»áÌåÏÖ£¬¶Ô¸ÃÊÂÎñµÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬ÉÐδ·¢Ã÷´ó¹æÄ£Êý¾ÝÌáÈ¡µÄ¼£Ïó¡£Í¬Ê±£¬¸Ã»ú¹¹ÒÑ×îÏȵ¥¶À֪ͨȷÈÏÊܵ½Ó°ÏìµÄÈË£¬ÌṩÊÂÎñÏêÇé¡¢Ö§³Ö×ÊÔ´£¬²¢ÔÊÐíÔöÇ¿Çå¾²²½·¥ÒÔ±ÜÃâδÀ´Î¥¹æÐÐΪ¡£±ðµÄ£¬Ïà¹ØÕþ¸®²¿·ÖºÍÖ´·¨»ú¹¹Ò²ÒÑÊÕµ½ÏìӦ֪ͨ¡£
https://www.bleepingcomputer.com/news/security/oxford-city-council-suffers-breach-exposing-two-decades-of-data/
4. WordPress MotorsÎó²îÔâʹÓ㬵¼ÖÂÖÎÀíÔ±ÕË»§±»Ð®ÖÆ
6ÔÂ21ÈÕ£¬ºÚ¿ÍÕýʹÓÃWordPressÖ÷Ìâ¡°Motors¡±ÖбàºÅΪCVE-2025-4322µÄÑÏÖØÈ¨ÏÞÌáÉýÎó²îÐ®ÖÆÖÎÀíÔ±ÕÊ»§²¢¿ØÖÆÄ¿µÄÍøÕ¾¡£´ËÎó²îÓÉWordfence·¢Ã÷²¢ÓÚÉÏÔÂÖÒÑÔÆäÑÏÖØÐÔ£¬±Þ²ßÓû§Éý¼¶¡£¡°Motors¡±ÓÉStylemixThemes¿ª·¢£¬ÔÚÆû³µÏà¹ØÍøÕ¾ÖйãÊܽӴý£¬ÏúÁ¿´ï22,460·ÝÇÒÓµÓлîÔ¾Óû§ÉçÇø¡£¸ÃÎó²îÓÚ2025Äê5ÔÂ2ÈÕ±»·¢Ã÷£¬5ÔÂ19ÈÕÓÉWordfenceÊ״α¨¸æ£¬Ó°Ïì5.6.67֮ǰµÄËùÓа汾£¬ÆäȪԴÔÚÓÚÃÜÂë¸üÐÂʱ´ú²»×¼È·µÄÓû§Éí·ÝÑéÖ¤£¬ÖÂʹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉËæÒâ¸ü¸ÄÖÎÀíÔ±ÃÜÂë¡£StylemixThemesÓÚ5ÔÂ14ÈÕÐû²¼5.6.68°æ±¾ÒÔ½â¾ö¸ÃÎó²î£¬µ«Ðí¶àÓû§Î´ÊµÊ±Ó¦ÓøüУ¬ÃæÁÙ¸ü¸ß±»Ê¹ÓÃΣº¦¡£Wordfence֤ʵ¹¥»÷ʼÓÚ5ÔÂ20ÈÕ£¬×èÖ¹6ÔÂ7ÈÕÒÑÊӲ쵽´ó¹æÄ£¹¥»÷£¬²¢×èÖ¹ÁË23,100´ÎÕë¶ÔÆä¿Í»§µÄ¹¥»÷ʵÑé¡£¸ÃÎó²î±£´æÓÚ¡°µÇ¼ע²á¡±Ð¡²¿¼þµÄÃÜÂë»Ö¸´¹¦Ð§ÖУ¬¹¥»÷Õßͨ¹ý̽²âÌØ¶¨Â·¾¶ÕÒµ½°²ÅÅС²¿¼þµÄURL£¬Ê¹ÓÃÌØÖÆPOSTÇëÇóÖеÄÎÞЧUTF-8×Ö·ûµ¼Ö¹þÏ£½ÏÁ¿¹ýʧÀֳɣ¬½ø¶øÖØÖÃÓû§ÃÜÂë¡£¹¥»÷ÕßÉèÖõÄÃÜÂë¶àÑù£¬Ò»µ©»ñµÃ»á¼ûȨÏÞ£¬±ã»áÒÔÖÎÀíÔ±Éí·ÝµÇ¼²¢½¨ÉèÐÂÖÎÀíÔ±ÕÊ»§ÒÔʵÏÖ³¤ÆÚÐÔ¡£´ËÀàÕË»§Í»È»·ºÆðÒÔ¼°ÏÖÓÐÖÎÀíÔ±±»Ëø¶¨ÊÇÊܵ½¹¥»÷µÄ¼£Ïó£¬Wordfence»¹ÁгöÁËÌᳫÕâЩ¹¥»÷µÄIPµØµã£¬½¨ÒéWordPressÍøÕ¾ËùÓÐÕß½«ÕâЩµØµãÁÐÈë×èÖ¹ÁÐ±í¡£
https://www.bleepingcomputer.com/news/security/wordpress-motors-theme-flaw-mass-exploited-to-hijack-admin-accounts/
5. AnubisÀÕË÷ÍŻォ°ÍÀèµÏÊ¿ÄáÀÖÔ°ÁÐΪÐÂÊܺ¦Õß
6ÔÂ20ÈÕ£¬ÎÛÃûÕÑÖøµÄAnubisÀÕË÷Èí¼þÍŻォ°ÍÀèµÏÊ¿ÄáÀÖÔ°ÁÐΪ×îÐÂÊܺ¦Õߣ¬Hackread.com֤ʵ¸Ã×éÖ¯ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾Ðû²¼Á˴˴ι¥»÷ÏêÇ飬³Æ±»µÁÊý¾Ýµµ°¸×ܼÆ64GB¡£Anubis×éÖ¯³ÆÆäΪ¡°µÏÊ¿ÄáÀÖÔ°ÀúÊ·ÉÏ×î´óµÄÊý¾Ýй¶ÊÂÎñ¡±£¬³Æ39000·ÝÓëÀÖÔ°½¨ÉèºÍ·ÐÂÔ˶¯Ïà¹ØµÄÎļþ±»µÁ£¬ÕâЩÊý¾ÝÊÇÔÚÉæ¼°µÏÊ¿ÄáÀÖÔ°Ò»¼ÒÏàÖú¹«Ë¾µÄÊý¾Ýй¶ÊÂÎñÖлñÈ¡µÄ¡£Îª×ô֤˵·¨£¬ÔËÓªÉÌÐû²¼½«ÔÚδÀ´ÎåСʱÄÚÐû²¼²¿·ÖÊý¾Ý£¬ÏÖÔÚÆäÍøÕ¾ÒÑÉÏ´«Í¼Æ¬ºÍÊÓÆµ£¬¾Ý³ÆÕ¹Ê¾¹«Ô°ÄÚ¸÷¾°µãÏêϸͼֽ£¬µµ°¸°üÀ¨¡¶±ùÑ©ÆæÔµ¡·µÈ¶à²¿Ö÷ÌâÏîÄ¿µÄÍýÏ룬ÉÐÓÐÆäËûͼƬչʾÏÖ³¡¹¤³ÌÏà¹ØÊÂÇé¡£¸Ã×éÖ¯Ö¸³öµÏÊ¿ÄáÀÖ԰ͨ³£ÓëÔ±¹¤Ç©Êð±£ÃÜÐÒ飬եȡ¹ûÕæ·ÖÏíÄÚ²¿×ÊÁÏ£¬ÒÔÇ¿µ÷´Ë´ÎÊý¾Ýй¶µÄÑÏÖØÐÔ¡£²»¹ý£¬¸ÃÌû×ÓδÏêϸ˵Ã÷ÎļþÖÐÊÇ·ñ°üÀ¨Ö÷¹Ë»ò·Ã¿ÍÐÅÏ¢£¬Ò²Î´Ìá¼°ÊÇ·ñÒÑÏò°ÍÀèµÏÊ¿ÄáÀÖÔ°·¢³öÊê½ðÒªÇ󣬸Ã×éÖ¯ÔøÔÚ¹Ù·½ÍÆÌØ£¨ÏÖΪX£©ÕË»§ÉÏ´µÅõÕâÆðÊÂÎñ¡£
https://hackread.com/anubis-ransomware-lists-disneyland-paris-new-victim/
6. Cloudflare»º½âÁË2025Äê5Ô´´¼Í¼µÄ7.3Tbps DDoS¹¥»÷
6ÔÂ20ÈÕ£¬CloudflareÌåÏÖ£¬ÆäÔÚ2025Äê5ÔÂÀֳɻº½âÁËÒ»ÆðÕë¶ÔÍйܷþÎñÌṩÉ̵Ĵ´¼Í¼ÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷£¬¸Ã¹¥»÷·åÖµ¸ß´ï7.3 Tbps£¬½Ï֮ǰ¼Í¼ÔöÌí12%£¬ÔÚ45ÃëÄÚ´«ÊäÁË37.4 TBÊý¾Ý£¬Ï൱ÓÚÔ¼7500Сʱ¸ßÇåÁ÷ýÌå»ò1250ÍòÕÅjpegÕÕÆ¬¡£Cloudflare×÷ΪרעÓÚDDoS»º½âµÄÍøÂç»ù´¡ÉèÊ©ºÍÍøÂçÇå¾²¾ÞÍ·£¬ÆäÄ¿µÄ¿Í»§Ê¹ÓÃÁË¡°Magic Transit¡±ÍøÂç²ã±£»¤·þÎñ¡£´Ë´Î¹¥»÷Ô´×Ô161¸ö¹ú¼ÒµÄ122145¸öÔ´IPµØµã£¬Ö÷ҪλÓÚ°ÍÎ÷¡¢Ô½ÄÏ¡¢Ì¨Íå¡¢Öйú¡¢Ó¡¶ÈÄáÎ÷ÑǺÍÎÚ¿ËÀ¼¡£¹¥»÷ͨ¹ý¶à¸öÄ¿µÄ¶Ë¿Ú´«ËÍ¡°À¬»ø¡±Êý¾Ý°ü£¬Æ½¾ùÿÃë21925¸ö¶Ë¿Ú£¬·åÖµ´ïÿÃë34517¸ö¶Ë¿Ú£¬ÊèÉ¢Á÷Á¿µÄÕ½ÂÔÖ¼ÔÚѹ¿å·À»ðǽ»òÈëÇÖ¼ì²âϵͳ¡£È»¶ø£¬CloudflareʹÓÃÈβ¥ÍøÂ罫¹¥»÷Á÷Á¿ÊèÉ¢µ½293¸öËùÔÚµÄ477¸öÊý¾ÝÖÐÐÄ£¬Í¨¹ýÊµÊ±Ö¸ÎÆÊ¶±ðºÍÊý¾ÝÖÐÐÄÄÚ²¿Í¨Ñ¶µÈÊÖÒÕʵÏÖʵʱÇ鱨¹²ÏíºÍ×Ô¶¯¹æÔò±àÒ룬×îÖÕÔÚÎÞÐèÈ˹¤¸ÉÔ¤µÄÇéÐÎÏ»º½âÁ˹¥»÷¡£Ö»¹Ü¹¥»÷Ö÷ÒªÀ´×ÔUDPºéË®¹¥»÷£¬Õ¼×ÜÁ÷Á¿µÄ99.996%£¬µ«»¹Éæ¼°QOTD·´Ë¼¡¢»ØÉù·´Éä¡¢NTPÀ©Ôö¡¢Mirai½©Ê¬ÍøÂçUDPºéË®¹¥»÷¡¢¶Ë¿ÚÓ³ÉäºéË®¡¢RIPv1À©ÔöµÈ¶à¸öÔØÌ壬ÿ¸ö¹¥»÷ÏòÁ¿¶¼Ê¹ÓÃÁËÒÅÁô»òÉèÖò»µ±µÄ·þÎñ¡£CloudflareÒѽ«´Ë´Î¹¥»÷ÖÐÓмÛÖµµÄIoCÄÉÈëÆäDDoS½©Ê¬ÍøÂçÍþвԴÖС£
https://www.bleepingcomputer.com/news/security/cloudflare-blocks-record-73-tbps-ddos-attack-against-hosting-provider/


¾©¹«Íø°²±¸11010802024551ºÅ