ʥԼɪ·òÊÐÔâÑÏÖØÍøÂç¹¥»÷ÖÂÊý¾Ýй¶¼°·þÎṉ̃»¾

Ðû²¼Ê±¼ä 2025-09-11

1. ʥԼɪ·òÊÐÔâÑÏÖØÍøÂç¹¥»÷ÖÂÊý¾Ýй¶¼°·þÎṉ̃»¾


9ÔÂ8ÈÕ £¬ÃÜËÕÀïÖÝʥԼɪ·òÊÐ6Ô³õÔâÓöÖØ´óÍøÂç¹¥»÷ £¬µ¼ÖÂÍøÂç·þÎñºã¾Ã̱»¾²¢¿ÉÄÜй¶ÊýǧסÃñСÎÒ˽¼ÒÊý¾Ý¡£ÊÂÎñÓÚ6ÔÂ9ÈÕÆÆÏþ2:30Ê״α»·¢Ã÷ £¬ÊÐÕþ¸®Ëæ¼´¹Ø±ÕËùÓÐÍøÂç²¢Æô¶¯ÊÓ²ì £¬È·ÈϹ¥»÷Éæ¼°Êý¾Ýй¶ £¬Ó°Ïì°üÀ¨¾¯Ô±¾Ö¡¢ÎÀÉú²¿·Ö¼°ÊÐÃñ¸¶¿îϵͳµÈÒªº¦²¿·Ö¡£ÊÓ²ìÏÔʾ £¬¹¥»÷µ¼ÖÂÊÖ»úͨѶÖÐÖ¹¡¢µç×ÓÓʼþÎÞ·¨»á¼û¡¢Îļþϵͳ̱»¾ £¬Ô±¹¤±»ÆÈʹÓÃСÎÒ˽¼Ò×°±¸´¦Öóͷ£¹«Îñ £¬±£´æÑÏÖØÇå¾²Òþ»¼¡£¾­µç×ÓÊÓ²ìÈ·ÈÏ £¬Ô¼11,000ÃûסÃñµÄСÎÒ˽¼ÒÐÅÏ¢¿ÉÄܱ»Î´¾­ÊÚȨ»ñÈ¡ £¬ÊÐÕþ¸®ÒÑÆô¶¯Í¨Öª³ÌÐò £¬ÌṩÐÅÓÃ¼à¿Ø¼°Éí·Ý͵ÇÔ±£»¤·þÎñ £¬²¢ÉèÁ¢ºô½ÐÖÐÐÄЭÖúÊÜÓ°ÏìסÃñ¡£ÎªÓ¦¶ÔÊÂÎñ £¬ÊÐÕþ¸®Í¶È볬100ÍòÃÀÔªÉý¼¶ÍøÂçÇå¾²»ù´¡ÉèÊ©¡£Ö»¹ÜÊÂÎñδµ¼Ö¹«¹²·þÎñÖÐÖ¹ £¬µ«ÄÚ²¿ÔËÓªÔÓÂÒÒ»Á¬ÊýÖÜ £¬²¿·ÖÁ÷³ÌÖÁ½ñδÍêÈ«»Ö¸´¡£ÀýÈç £¬¾¯Ô±¾ÖÖðÈÕ°¸¼þ±¨¸æ×Ô6ÔÂ8ÈÕÆð×èÖ¹Ðû²¼ £¬Ó°Ï칫ÖÚÖªÇéȨ¡£±ðµÄ £¬Ô±¹¤Ê¹ÓÃСÎÒ˽¼Ò×°±¸´¦Öóͷ£¹«ÎñÒý·¢Êý¾ÝÇå¾²µ£ÐÄ £¬ÊÐÕþ¸®ÒÑեȡ´ËÀàÐÐΪ¡£


https://www.newspressnow.com/news/top-stories/2025/09/08/city-of-st-joseph-hit-by-cyberattack-data-potentially-acquired/


2. TenableÔâSalesforce¹©Ó¦Á´¹¥»÷й¶¿Í»§Êý¾Ý


9ÔÂ8ÈÕ £¬Tenable¹«Ë¾¿ËÈÕÈ·Èϱ¬·¢Êý¾Ýй¶ÊÂÎñ £¬²¿·Ö¿Í»§ÁªÏµÐÅÏ¢¼°Ö§³Ö°¸ÀýÊý¾ÝÔâδ¾­ÊÚȨ»á¼û¡£´Ë´ÎÊÂÎñÔ´ÓÚÕë¶ÔSalesforceÓëSalesloft DriftÓªÏúÓ¦Óü¯³ÉµÄÆÕ±éÊý¾Ý͵ÇÔÔ˶¯ £¬¸ÃÎó²îÒÑÓ°Ïì¶à¼Ò×ÅÃûÆóÒµ¡£Ð¹Â¶Êý¾Ý½öÏÞÓÚTenableµÄSalesforceÇéÐÎ £¬Ïêϸ°üÀ¨¿Í»§ÐÕÃû¡¢ÉÌÒµÓÊÏä¡¢µç»°ºÅÂë¡¢ÕË»§ÇøÓòλÖÃÐÅÏ¢ £¬ÒÔ¼°Ö§³Ö°¸ÀýµÄÖ÷ÌâÐкͳõʼÐÎò¡£TenableÇ¿µ÷Æä½¹µã²úÆ·¼°Êý¾ÝδÊÜÓ°Ïì £¬µ«ÊÂÎñ̻¶ÁËÆóҵӪҵƽ̨ÖеÚÈý·½Ó¦Óü¯³É±£´æµÄÇå¾²Òþ»¼¡£¾­ÊÓ²ì £¬´Ë´Î¹¥»÷ÓëÇ徲ר¼Ò×·×ÙµÄÖØ´ó¹¥»÷Ô˶¯Ïà¹Ø £¬¹¥»÷ÕßʹÓÃSalesforceÓëSalesloft Drift¼¯³ÉÎó²î £¬ÇÔÈ¡¶à¼Ò¹«Ë¾µÄSalesforceʵÀýÊý¾Ý¡£ÊÂÎñ±¬·¢ºó £¬TenableѸËÙ½ÓÄÉÓ¦¶Ô²½·¥£º×÷·Ï²¢ÂÖ»»¿ÉÄÜй¶µÄƾ֤ £¬½ûÓÃSalesloft Drift¼°Ïà¹Ø¼¯³ÉÓ¦Óà £¬Ç¿»¯SalesforceÇéÐμ°ÆäËûÅþÁ¬ÏµÍ³µÄÇå¾²·À»¤ £¬Ó¦ÓÃÒÑ֪Σº¦Ö¸±ê£¨IoC£©Ê¶±ð¶ñÒâÔ˶¯ £¬²¢Ò»Á¬¼à¿ØSaaS½â¾ö¼Æ»®ÒÔ¼ì²âÒì³£¡£¹«Ë¾ºôÓõ¿Í»§¼á³ÖСÐÄ £¬×ñÕÕÇ徲ר¼Ò½¨Òé±£»¤ÏµÍ³¡£


https://cybersecuritynews.com/tenable-confirms-data-breach/


3. DynatraceÔâSalesforce¹©Ó¦Á´¹¥»÷Ö¿ͻ§Êý¾Ýй¶


9ÔÂ9ÈÕ £¬Èí¼þÖÇÄܾÞÍ·Dynatrace¿ËÈÕÈÏ¿É £¬ÔÚ2025Äê×î´ó¹æÄ£µÄ¹©Ó¦Á´ºÚ¿Í¹¥»÷ÊÂÎñÖÐ £¬Æä¿Í»§Êý¾ÝÒòµÚÈý·½¹¤¾ßÎó²îÔ⵽й¶¡£´Ë´ÎÊÂÎñÔ´ÓÚÒ»¿îÆÕ±éʹÓõÄÈ˹¤ÖÇÄÜÓªÏú̸Ìì»úеÈËSalesloft DriftÓëSalesforce CRMϵͳµÄ¼¯³ÉÎó²î¡£ºÚ¿Íͨ¹ý¸ÃÎó²î²»·¨»á¼ûÁËDynatraceµÄSalesforceʵÀý £¬µ¼Ö¿ͻ§ÐÕÃû¡¢¹«Ë¾±êʶ·ûµÈÓªÒµÁªÏµÊý¾ÝÍâй¡£DynatraceÇ¿µ÷ £¬Æä½¹µã²úÆ·¼°·þÎñϵͳδÊÜÓ°Ïì £¬½öÉæ¼°¿Í»§ÖÎÀíºÍÓªÏúÓÃ;µÄCRMƽ̨¡£×÷Ϊ×ܲ¿Î»ÓÚÃÀ¹úÓë°ÂµØÀûµÄ¿ç¹úÆóÒµ £¬DynatraceµÄ¿Í»§ÈºÌ庭¸ÇÕþ¸®¡¢º½¿Õ¼°½ðÈÚÁìÓò £¬°üÀ¨¼ÓÄô󺽿ա¢°Ä´óÀûÑÇÕþ¸®¡¢µÀÃ÷ÒøÐеÈ×ÅÃû»ú¹¹ £¬ÄêÊÕÈë´ï15.1ÒÚÅ·Ôª¡£´Ë´ÎÊÂÎñ²¢·ÇÁæØê°¸Àý £¬¶øÊǽüÆÚÕë¶ÔSalesforceÉú̬µÄÁ¬Ëø¹¥»÷À˳±µÄÒ»²¿·Ö¡£ÊÓ²ìÏÔʾ £¬¹¥»÷Õßͨ¹ýÀÄÓÃSalesloft DriftÓëSalesforce¼°ÆäËûƽ̨µÄ¼¯³É½Ó¿Ú £¬ÊµÏÖÁ˶Զà×éÖ¯Ãô¸ÐÊý¾ÝµÄºáÏòÉøÍ¸¡£ºÚ¿Í×é֯ͬÃË¡°Scattered LapSus$ Hunters¡±Ðû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£ÊÂÎñ±¬·¢ºó £¬SalesloftÒÑÔÝʱÏÂÏßDriftÓ¦ÓóÌÐò £¬DynatraceÔòѸËÙ½ûÓÃÏà¹Ø¼¯³É²¢Ç¿»¯ÏµÍ³Çå¾²¡£


https://cybernews.com/security/dynatrace-salesloft-drift-breach/


4. KillSecÀÕË÷Èí¼þÒý·¢°ÍÎ÷Ò½Áƹ©Ó¦Á´Êý¾Ýй¶Î£»ú


9ÔÂ10ÈÕ £¬KillSecÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô°ÍÎ÷Ò½ÁƱ£½¡Èí¼þÌṩÉÌMedicSolutionµÄÍøÂç¹¥»÷ÈÏÕæ £¬²¢ÍþвÈô²»Á¬Ã¦Ì¸Åн«Ð¹Â¶Ãô¸ÐÊý¾Ý¡£´Ë´ÎÊÂÎñȪԴÔÚÓÚÒ½ÁÆ»ú¹¹AWS S3´æ´¢Í°ÉèÖò»µ± £¬µ¼ÖÂÊý¾Ýй¶´°¿Ú³¤´ïÊýÔ £¬±»ÊÓΪ°ÍÎ÷Ò½ÁÆÐÐÒµÊ×ÀýÖØ´ó¹©Ó¦Á´Çå¾²ÊÂÎñ¡£¸Ã×éÖ¯´ËǰÒѶà´ÎÕë¶Ô°ÍÎ÷£ºÔøÐ¹Â¶Õþ¸®²¿·ÖСÎÒ˽¼Ò¼°ÆóÒµÊý¾Ý£¨º¬CNPJ/CPF±êʶ·û¡¢ÒøÐÐÐÅÏ¢£© £¬µ«Î´Ã÷È·ËùÓйæÄ£¡£±¾´Î¹¥»÷ÖÐ £¬±»µÁÊý¾Ý³¬34GB £¬°üÀ¨94,818¸öÎļþ £¬É漰ʵÑéÊÒЧ¹û¡¢XÉäÏßͼÏñ¡¢»¼Õßδɾ½ÚÕÕÆ¬¼°Î´³ÉÄêÈ˼ͼµÈÒþ˽ÐÅÏ¢¡£ResecurityÈ·ÈÏ»¼Õß¾ùδ²ì¾õй¶ £¬Í¹ÏÔÒþ²ØÐÔΣº¦¡£KillSecÔÚÏ®»÷°ÍÎ÷ǰ £¬ÒÑÈëÇÖ¸çÂ×±ÈÑÇ¡¢ÃØÂ³¡¢ÃÀ¹úµÈ¶à¸öÒ½ÁÆ»ú¹¹ £¬Ò½ÁÆÊý¾ÝÒò°üÀ¨Éí·Ý¡¢²¡Ê·¡¢°ü¹Ü¼°Ö§¸¶ÐÅÏ¢ £¬³ÉΪ¸ß¼ÛֵĿµÄ¡£


https://securityaffairs.com/182063/cyber-crime/killsec-ransomware-is-attacking-healthcare-institutions-in-brazil.html


5. Å·ÖÞDDoS»º½â·þÎñÉÌÔâÊ·ÉÏ×î¸ßÊý¾Ý°üËÙÂʹ¥»÷


9ÔÂ10ÈÕ £¬Å·ÖÞÒ»¼ÒDDoS»º½â·þÎñÌṩÉÌÔâÓö´ó¹æÄ£ÂþÑÜʽ¾Ü¾ø·þÎñ¹¥»÷ £¬¹¥»÷ËÙÂʵִïÿÃë15ÒÚ¸öÊý¾Ý°ü£¨1.5 Gpps£© £¬³ÉΪ¹ûÕæÅû¶µÄ×î´óÊý¾Ý°üËÙÂʺéË®¹¥»÷Ö®Ò»¡£´Ë´Î¹¥»÷Ô´×ÔÊýǧ̨ÊÜѬȾµÄÎïÁªÍø×°±¸ºÍMikroTik·ÓÉÆ÷ £¬ÓÉÍøÂçÇå¾²¹«Ë¾FastNetMonÀֳɻº½â¡£FastNetMonÔÚÐÂΟåÖÐÖ¸³ö £¬¶ñÒâÁ÷Á¿Ö÷ҪΪUDPºéË®¹¥»÷ £¬Ó°ÏìÈ«ÇòÁè¼Ý11,000¸öÆæÒìÍøÂç¡£¹¥»÷Ä¿µÄËäδ¹ûÕæ £¬µ«±»ÐÎòΪһ¼ÒDDoSÏ´åªÌṩÉÌ £¬Æä·þÎñͨ¹ýÊý¾Ý°ü¼ì²é¡¢ËÙÂÊÏÞÖÆ¡¢ÑéÖ¤ÂëºÍÒì³£¼ì²âµÈÊÖÒÕ¹ýÂ˶ñÒâÁ÷Á¿¡£´Ë´Î¹¥»÷±»ÊµÊ±¼ì²âºó £¬Í¨¹ýÔÚ±ßÑØÂ·ÓÉÆ÷°²ÅÅ»á¼û¿ØÖÆÁÐ±í£¨ACL£©µÈ²½·¥ÊµÏÖ»º½â¡£ÖµµÃ×¢ÖØµÄÊÇ £¬´Ë´Î¹¥»÷±¬·¢Ç°¼¸ÈÕ £¬»¥ÁªÍø»ù´¡ÉèÊ©¾ÞÍ·CloudflareÐû²¼×èÖ¹ÁËÊ·ÉÏ×î´ó¹æÄ£DDoS¹¥»÷ £¬·åÖµ´ïÿÃë11.5Ì«±ÈÌØ£¨Tbps£©ºÍ51ÒÚ¸öÊý¾Ý°ü£¨Bpps£©¡£Á½´Î¹¥»÷¾ùÖ¼Ôںľ¡ÎüÊÕ¶Ë´¦Öóͷ£ÄÜÁ¦ £¬µ¼Ö·þÎñÖÐÖ¹¡£FastNetMonÊ×´´ÈËPavel OdintsovÇ¿µ÷ £¬´ËÀà´ó¹æÄ£¹¥»÷Ç÷ÊÆÒѼ«¶ËΣÏÕ £¬ÐèÔÚ»¥ÁªÍø·þÎñÌṩÉÌ£¨ISP£©²ãÃæÊµÑé¸ÉÔ¤ £¬×èÖ¹ÊÜѬȾÏûºÄ¼¶Ó²¼þ±»´ó¹æÄ£ÎäÆ÷»¯¡£


https://www.bleepingcomputer.com/news/security/ddos-defender-targeted-in-15-bpps-denial-of-service-attack/


6. Hello GymÊý¾Ý¿âй¶ÊÂÎñ£º°ÙÍò»áԱ¼Òô̻¶


9ÔÂ10ÈÕ £¬Ã÷ÄáËÕ´ïÖݽ¡ÉíÊÖÒÕ·þÎñ¹«Ë¾Hello GymÖÎÀíµÄδÊÜÃÜÂë±£»¤Êý¾Ý¿â±¬·¢ÑÏÖØÊý¾Ýй¶ £¬ÆäÖаüÀ¨2020ÄêÖÁ2025Ä곬160Íò·Ý½¡Éí·¿»áÔ±µÄµç»°Â¼ÒôºÍÓïÒôÓʼþ¡£Ñо¿Ô±Jeremiah Fowler·¢Ã÷ £¬¸ÃÊý¾Ý¿â´æ´¢ÓÚÎÞ±£»¤ÇøÓò £¬ÎÞÐèÈÏÖ¤¼´¿É»ñÈ¡°üÀ¨Ö÷¹ËÐÕÃû¡¢µç»°ºÅÂë¼°ÖµçÔµ¹ÊÔ­ÓɵÈСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©µÄ1,605,345¸öÒôƵÎļþ £¬Éæ¼°ÃÀ¹ú¡¢¼ÓÄôó¶àµØ½¡Éí·¿ £¬²¿·Ö¼Í¼Ìá¼°×ÅÃû½¡ÉíÆ·ÅÆ¡£´Ë´Îй¶ԴÓÚµÚÈý·½³Ð°üÉÌHello GymµÄÇå¾²Êè© £¬Ö»¹Ü¹«Ë¾×ÔÉí²»Ö±½Ó¼Òô £¬µ«×ÔÁ¦¼ÓÃËÉÌʹÓõĵÚÈý·½·þÎñÓÉÆäÖÎÀí £¬µ¼ÖÂÃô¸ÐÊý¾Ý̻¶¡£ÊÂÎñÔÚÑо¿Ö°Ô±Åû¶ºóÊýСʱÄÚ±»ÐÞ¸´ £¬µ«Ì»Â¶Ê±³¤¼°ÊÇ·ñ±»ËûÈË»á¼ûÈÔδ֪¡£Ð¹Â¶µÄÒôƵÊý¾Ý¾ßÓм«¸ßΣº¦¼ÛÖµ¡£Õ©Æ­Õß¿ÉʹÓüÒôÖеÄÏêϸϸ½ÚʵÑéÓã²æÊ½ÍøÂç´¹ÂÚ £¬Ã°³ä½¡Éí·¿ÊÂÇéÖ°Ô±ÓÕÆ­»áԱй¶֧¸¶ÐÅÏ¢»òÃô¸ÐÊý¾Ý£»ÓïÒôÓʼþÖеÄСÎÒ˽¼ÒÐÅÏ¢¿É±»ÓÃÓÚÉç»á¹¤³Ì¹¥»÷ £¬½¨ÉèÐÅÍкóÆ­È¡¸ü¶àÒþ˽£»¸üÑÏÖØµÄÊÇ £¬ÈËÉù¼Òô¿É±»ÓÃÓÚÖÆ×÷¡°Éî¶ÈαÔ족ÒôƵ £¬ÊµÑéÉí·Ýð³ä»ò½ðÈÚÕ©Æ­¡£


https://hackread.com/hello-gym-data-leak-audio-files-of-gym-members/