»ªÊ¢¶ÙÖÝÎ÷±±·ÅÉä¿ÆÒ½ÉúÕïËùÔâÊý¾Ýй¶£¬Ó°Ïì35ÍòסÃñ
Ðû²¼Ê±¼ä 2025-08-061. »ªÊ¢¶ÙÖÝÎ÷±±·ÅÉä¿ÆÒ½ÉúÕïËùÔâÊý¾Ýй¶£¬Ó°Ïì35ÍòסÃñ
8ÔÂ4ÈÕ£¬»ªÊ¢¶ÙÖÝÎ÷±±·ÅÉä¿ÆÒ½ÉúÕïËù¿ËÈÕ֤ʵ£¬ÆäÓÚ2025Äê1ÔÂÔâÓöÖØ´óÍøÂçÇå¾²ÊÂÎñ£¬µ¼ÖÂÔ¼348,118Ãû»ªÊ¢¶ÙסÃñµÄСÎÒ˽¼ÒÐÅϢй¶¡£´Ë´ÎÊÂÎñʼÓÚ1ÔÂ20ÈÕÖÁ25ÈÕʱ´ú£¬¹¥»÷Õßͨ¹ýδ¾ÊÚȨµÄ»á¼ûÇÖÈëÕïËùÍøÂ磬Ôì³ÉϵͳÖÐÖ¹¡£ÕïËù·¢Ã÷Òì³£ºóÁ¬Ã¦Æô¶¯Ó¦¼±ÏìÓ¦£¬ÁªÏµÁª°îÖ´·¨²¿·Ö²¢Ô¼ÇëµÚÈý·½ÍøÂçÇ徲ר¼ÒÐÖúÊӲ죬×îÖÕÈ·ÈÏ´æ´¢ÓÚÍøÂçÖеÄÃô¸ÐÊý¾ÝÔâÇÔÈ¡¡£Æ¾Ö¤ÕïËùÏò»ªÊ¢¶ÙÖÝ×ÜÉó²é³¤°ì¹«ÊÒÌá½»µÄ֪ͨ£¬Ð¹Â¶ÐÅÏ¢º¸Ç»¼ÕßÈ«Ãû¡¢µØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝÕÕ/ÖÝÉí·ÝÖ¤ºÅ¡¢Õï¶ÏÐÅÏ¢¡¢Ò½ÁÆ·þÎñÌṩÕßÐÕÃû¡¢²¡ÀúºÅ¡¢¿µ½¡°ü¹ÜÏêÇé¼°ÖÎÁÆÓöȵȽ¹µãСÎÒ˽¼ÒÊý¾Ý¡£Ö»¹ÜÕïËùÇ¿µ÷ÏÖÔÚÎÞÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»ÀÄÓ㬵«ÈÔΪÊÜÓ°Ïì¸öÌåÌṩÁËÃâ·ÑÐÅÓüà²âÓëÉí·Ý±£»¤·þÎñ¡£´Ë´Î¹¥»÷µÄÊÖÒÕϸ½ÚÉÐδÍêÈ«¹ûÕæ£¬µ«ÍøÂçÖÐÖ¹ÌØÕ÷ÓëÀÕË÷Èí¼þ¹¥»÷ģʽ¸ß¶ÈÎǺϡ£×èÖ¹±¨¸æÐû²¼£¬ÉÐÎÞÈκκڿÍ×éÖ¯Ðû³Æ¶Ô´ËÊÂÈÏÕæ¡£
https://securityaffairs.com/180772/data-breach/northwest-radiologists-data-breach-hits-350000-in-washington.html
2. ÐÂÐÍJSCEAL¶ñÒâÈí¼þͨ¹ýÐéα¼ÓÃÜÓ¦ÓÃ¹ã¸æ¹¥»÷Êý°ÙÍòÓû§
8ÔÂ4ÈÕ£¬Çå¾²Ñо¿¹«Ë¾Check Point Research£¨CPR£©¿ËÈÕÅû¶һÏî´úºÅ"JSCEAL"µÄ´óÐÍÍøÂç·¸·¨Ðж¯£¬¸ÃÔ˶¯×Ô2024Äê3ÔÂÆðÒ»Á¬Õë¶Ô¼ÓÃÜÇ®±ÒÓ¦ÓÃÓû§ÊµÑ龫׼´¹ÂÚ¹¥»÷¡£¾Ýͳ¼Æ£¬½ö2025ÄêÉϰëÄê¹¥»÷Õß¾ÍͶ·Å³¬3.5ÍòÌõÐéα¹ã¸æ£¬Å·Ã˾³ÄÚDZÔÚÊÜÓ°ÏìÓû§´ï350Íò£¬È«Çò¹æÄ£Ô¤¼Æ³¬1000Íò£¬ÐγɽüÄêÀ´¹æÄ£×î´óµÄ¼ÓÃÜÇ®±ÒÁìÓòÍøÂç´¹ÂÚÊÂÎñÖ®Ò»¡£¹¥»÷Á´½ÓÄÉ"¹ãÈöÍø+¾«É¸Ñ¡"Õ½ÂÔ£º·¸·¨ÍÅ»ïð³ä½ü50¸öÖ÷Á÷¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨£¨ÈçCoinbase¡¢BinanceµÈ£©£¬Í¨¹ýËÑË÷ÒýÇæÓÅ»¯£¨SEO£©ÊÖÒÕ½«Ðéα¹ã¸æÍÆËÍÖÁËÑË÷Ч¹ûǰÏß¡£µ±Óû§µã»÷ºó£¬»á±»Ö¸µ¼ÖÁÍâ¹Û¸ß¶È·ÂÕæµÄ´¹ÂÚÍøÕ¾£¬ÓÕµ¼ÏÂÔØ´øÓÐÕýµ±Êý×ÖÖ¤ÊéÊðÃûµÄ"¹Ù·½×°Öðü"¡£ÊÖÒÕÆÊÎöÏÔʾ£¬JSCEAL¹¥»÷·ºÆð¶à½×¶ÎÌØÕ÷£º³õʼװÖóÌÐòÊ×ÏÈÖ´ÐÐÐÅÏ¢ÍøÂç¾ç±¾£¬ÇÔȡװ±¸Ö¸ÎÆ¡¢µØÀíλÖü°¼ÓÃÜÇ®°üʹÓúۼ£µÈÊý¾Ý£¬ÉÏ´«ÖÁ¹¥»÷Õß·þÎñÆ÷¾ÙÐÐÄ¿µÄ¼ÛÖµÆÀ¹À¡£È·Èϸ߼ÛֵĿµÄºó£¬²Å»áÊͷ޹µã¶ñÒâÈí¼þ¡£Ò»µ©Àֳɰ²ÅÅ£¬JSCEAL½«ÊµÑéÈ«·½Î»Êý¾ÝÇÔÈ¡£º³ý¼ÓÃÜÇ®±ÒÇ®°üƾ֤¡¢Ë½Ô¿µÈ½¹µã×ʲúÐÅÏ¢Í⣬»¹¾ß±¸ÆÁÄ»½ØÍ¼¡¢¼üÅ̼ͼ¡¢ÍøÂçÁ÷Á¿Ð®ÖƵȸ߼¶¹¦Ð§¡£
https://hackread.com/jsceal-malware-targets-millions-fake-crypto-app-ads/
3. È«ÇòÖ鱦¾ÞÍ·PandoraÔâSalesforceÊý¾Ýй¶
8ÔÂ5ÈÕ£¬È«Çò×î´óÖé±¦Æ·ÅÆÖ®Ò»¡¢ÓµÓÐ2700¼ÒÃŵ꼰3.7ÍòÃûÔ±¹¤µÄµ¤ÂóÆóÒµPandoraÅû¶ÁËÒ»ÆðÖØ´óÊý¾Ýй¶ÊÂÎñ£¬Æä¿Í»§ÁªÏµÐÅÏ¢£¨°üÀ¨ÐÕÃû¡¢ÉúÈÕ¡¢µç×ÓÓÊÏ䣩ÒòµÚÈý·½Æ½Ì¨SalesforceÊý¾Ý¿âÔâ¹¥»÷±»µÁ£¬µ«ÃÜÂë¡¢Éí·ÝÖ¤¼þ¼°²ÆÎñÐÅϢδ±»Ð¹Â¶¡£¾ÝÊӲ죬´Ë´ÎÊÂÎñÔ´ÓÚÍþвÐÐΪÕß×Ô2025Äê1ÔÂÉõÖÁ¸üÔçʱ¼äÌᳫµÄÒ»Á¬Éç»á¹¤³ÌÓëÍøÂç´¹ÂÚ¹¥»÷£¬¹¥»÷Ä¿µÄÖ±Ö¸PandoraÔ±¹¤¼°·þÎñְ̨Ա£¬Í¨¹ýÇÔÈ¡Salesforceƾ֤»òÓÕÆÔ±¹¤ÊÚȨ¶ñÒâOAuthÓ¦ÓóÌÐò£¬×îÖÕ²»·¨»á¼û²¢ÏÂÔØÁ˹«Ë¾SalesforceÊý¾Ý¿â¡£¹¥»÷ÕßÉí·Ý±»È·ÒÔΪºÚ¿Í×éÖ¯ShinyHunters£¬¸Ã×éÖ¯ÏÖÔÚÕýÒÔ¹ûÕæÊý¾ÝΪÍþвÏòPandoraÀÕË÷Êê½ð£¬²¢ÖÒÑÔÈô²»Ö§¸¶½«Ð§·Â´ËǰSnowflake¹¥»÷ÊÂÎñ£¬Í¨¹ý´ó¹æÄ£³öÊÛ»òй¶Êý¾Ýʩѹ¡£Ö»¹ÜSalesforce¹Ù·½Ç¿µ÷Æäƽ̨δ·¢Ã÷ÒÑÖªÇå¾²Îó²î£¬²¢Ö¸³ö¿Í»§×ÔÉíÇå¾²²½·¥Êǰü¹ÜÊý¾ÝÇå¾²µÄÒªº¦£¬µ«ÊÂÎñÈÔ̻¶ÁËÆóÒµÒÀÀµµÚÈý·½ÔÆ·þÎñʱµÄDZÔÚΣº¦£¬×ÝȻƽ̨×Ô¼ºÇå¾²»úÖÆÍêÉÆ£¬Ô±¹¤Çå¾²Òâʶ±¡ÈõÈÔ¿ÉÄܳÉΪ¹¥»÷Í»ÆÆ¿Ú¡£
https://www.bleepingcomputer.com/news/security/pandora-confirms-data-breach-amid-ongoing-salesforce-data-theft-attacks/
4. PBSÔ±¹¤Êý¾Ýй¶ÖÁÇàÉÙÄê·ÛË¿ÉçÇø
8ÔÂ5ÈÕ£¬ÃÀ¹ú¹«¹²¹ã²¥¹«Ë¾£¨PBS£©¿ËÈÕÔâÓöÒ»ÆðÌØÊâµÄÊý¾Ýй¶ÊÂÎñ£¬ÆäÔ±¹¤¼°Á¥Êô»ú¹¹¹²¼Æ3,997È˵Ĺ«Ë¾ÁªÏµÐÅÏ¢±»Ð¹Â¶ÖÁ¡°PBS Kids¡±·Û˿Ⱥ¼¯µÄDiscord·þÎñÆ÷ÉÏ¡£±¾Ô³õ£¬Ò»·Ý°üÀ¨ÏêϸСÎÒ˽¼Ò¼°Ö°ÒµÐÅÏ¢µÄJSONÎļþÔÚDiscordÉçÇøÈö²¥£¬Éæ¼°Ô±¹¤ÐÕÃû¡¢ÓÊÏ䡢ְλ¡¢Ê±Çø¡¢²¿·Ö¡¢Ï²»¶¼°Ö÷¹ÜÐÕÃûµÈÃô¸ÐÄÚÈÝ¡£ÓëͨÀýÊý¾Ýй¶²î±ð£¬´Ë´ÎÊÂÎñ²¢·Ç³öÓÚ¾¼ÃÀûÒæÇý¶¯£¬¶øÊDZ»·ÖÏíÖÁÒÔÇàÉÙÄêΪÖ÷µÄ·Û˿ƽ̨£¬ÄîÍ·¸üÆ«Ïò¡°ÐÂÓ±¸Ð¡±¡°ÆðÒåºÃÆæ¡±»ò×·ÇóͬÁäÈËÖеġ°¿áìÅÒòËØ¡±¡£PBS½²»°ÈË֤ʵ£¬Ð¹Â¶Êý¾ÝÔ´×ÔÄÚ²¿·þÎñ¹«¹²µçÊǪ́Ա¹¤×¨ÓÃÆ½Ì¨MyPBS.org£¬¹«Ë¾ÒÑÕö¿ªÖÜÈ«ÊӲ첢֪ͨÊÜÓ°ÏìÓû§£¬ÏÖÔÚÎÞÖ¤¾ÝÅú×¢ÆäËûϵͳÔâÈëÇÖ¡£Ö»¹ÜÄ¿½ñδ·¢Ã÷¶ñÒâʹÓÃÊý¾ÝµÄÇéÐΣ¬µ«Ð¹Â¶Êý¾ÝÔÚDiscordÉçÇøÒ»Á¬Èö²¥ÖÁ±¾ÖÜÄ©£¬ÈÔÒý·¢¶ÔDZÔÚÀÄÓõĵ£ÐÄ¡£ÐÂÎÅÈËʿָ³ö£¬´ËÀà·ÛË¿ÉçÇø±¾ÎªÌÖÂÛ¶ùͯ½ÚÄ¿¶øÉè¼Æ£¬Êý¾Ýй¶¿ÉÄÜÎüÒý²»ÐëÒªµÄÍⲿ¹Ø×¢£¬ÉõÖÁΪɧÈÅijÈËÈâËÑË÷Ìṩ±ãµ±¡£
https://www.bleepingcomputer.com/news/security/pbs-confirms-data-breach-after-employee-info-leaked-on-discord-servers/
5. DaVita DialysisÔâÀÕË÷Èí¼þ¹¥»÷£¬³¬°ÙÍò»¼ÕßÐÅϢй¶
8ÔÂ5ÈÕ£¬ÃÀ¹úÉöÔàÕչ˻¤Ê¿¾ÞÍ·DaVita Dialysis¿ËÈÕÅû¶ÁËÒ»ÆðÓ°Ï쳬°ÙÍò»¼ÕßµÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬Æä·þÎñÆ÷ÔÚ2025Äê3ÔÂ24ÈÕÖÁ4ÔÂ12ÈÕʱ´úÔâδ¾ÊÚȨ»á¼û£¬¹¥»÷Õß×îÖÕ±»ÀÖ³É×èÖ¹¡£´Ë´ÎÊÂÎñÓÉÍþв×éÖ¯InterLockÂÊÏÈÆØ¹â£¬¸Ã×éÖ¯Éù³Æ½«Ð¹Â¶1.5TBÊý¾Ý£¬²¢Òѽ«²¿·ÖÐÅÏ¢ÉÏ´«ÖÁйÃÜÍøÕ¾£¬ÓëÍþвÄÚÈÝÒ»Ö¡£Æ¾Ö¤DaVitaµÄÉùÃ÷£¬Ð¹Â¶Êý¾Ýº¸Ç»¼Õß¼°Ò½ÁÆ·þÎñÌṩÕßµÄÃô¸ÐÐÅÏ¢£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅ¡¢¿µ½¡°ü¹ÜÏêÇé¡¢ÁÙ´²ÐÅÏ¢£¬²¿·Ö»¼Õß»¹É漰˰ÎñʶÓÖÃû¼°Ö§Æ±Í¼Ïñ¡£Ö»¹ÜÏÖÔÚ½öÕÆÎÕÄÏ¿¨ÂÞÀ´ÄÉÖÝ¡¢»ªÊ¢¶ÙÖÝ¡¢¶íÀÕ¸ÔÖÝ¡¢µÂ¿ËÈøË¹ÖݺÍÂíÈøÖîÈûÖÝÎ嵨µÄÆðÔ´Êý¾Ý£¬×ܼÆ1,030,495ÈËÊÜÓ°Ï죬µ«ÏÖʵ²¨¼°¹æÄ£Ô¤¼Æ¸ü¹ã£¬ÇÒ¸ÃÊÂÎñÉÐδ±»Â¼ÈëÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿£¨HHS£©µÄ¹«¹²Î¥¹æ¹¤¾ß¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬´Ë´Î¹¥»÷²¢·ÇDaVitaÊ×´ÎÔâÓöÊý¾ÝÇ徲Σ»ú¡£×Ô2008ÄêÒÔÀ´£¬¸Ã¹«Ë¾Òѱ¨¸æÖÁÉÙÆßÆðÊý¾Ýй¶ÊÂÎñ¡£
https://databreaches.net/2025/08/05/more-than-1-million-patients-affected-by-davita-ransomware-attack-those-are-preliminary-numbers/
6. ˼¿ÆÔâÓïÒô´¹ÂÚ¹¥»÷ÖÂÓû§ÐÅϢй¶
8ÔÂ5ÈÕ£¬È«ÇòÍøÂç×°±¸¾Þͷ˼¿Æ£¨Cisco£©¿ËÈÕÅû¶һÒòÓÉÓïÒôÍøÂç´¹ÂÚ£¨Vishing£©¹¥»÷Òý·¢µÄÊý¾Ýй¶ÊÂÎñ£¬¹¥»÷Õßͨ¹ýÓÕÆÔ±¹¤»ñÈ¡µÚÈý·½¿Í»§¹ØÏµÖÎÀí£¨CRM£©ÏµÍ³»á¼ûȨÏÞ£¬µ¼ÖÂÔÚCisco.com×¢²áÓû§µÄ»ù±¾×ÊÁÏÐÅÏ¢ÔâÇÔ¡£ÊÂÎñ±¬·¢ÓÚ2025Äê7ÔÂ24ÈÕ£¬Ë¼¿ÆÔÚ·¢Ã÷ºóÁ¬Ã¦ÖÕÖ¹Á˹¥»÷Õß¶ÔCRMϵͳµÄ»á¼û£¬²¢Õö¿ªÊӲ졣¾Ý˼¿ÆÉùÃ÷£¬Ð¹Â¶ÐÅÏ¢°üÀ¨Óû§ÐÕÃû¡¢×éÖ¯Ãû³Æ¡¢µØµã¡¢Ë¼¿Æ·ÖÅɵÄÓû§ID¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¼°ÕË»§ÔªÊý¾Ý£¨È罨ÉèÈÕÆÚ£©£¬µ«Î´Éæ¼°×éÖ¯¿Í»§µÄÉñÃØÐÅÏ¢¡¢ÃÜÂë»òÆäËûÃô¸ÐÊý¾Ý¡£¹«Ë¾Ç¿µ÷£¬´Ë´ÎÊÂÎñδӰÏìÆä²úÆ·»ò·þÎñ£¬ÆäËûCRMϵͳʵÀýҲδ±»²¨¼°¡£ÏÖÔÚ£¬Ë¼¿ÆÒÑÒÀ¾ÝÖ´·¨ÒªÇó֪ͨÊÜÓ°ÏìÓû§£¬²¢ÓëÊý¾Ý±£»¤»ú¹¹ÁªÏµ£¬Í¬Ê±ÔöÇ¿Çå¾²²½·¥£¬°üÀ¨¶ÔÔ±¹¤¾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷ʶ±ðÓëÌá·ÀµÄÔÙÅàѵ¡£
https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/


¾©¹«Íø°²±¸11010802024551ºÅ