·Ñ¶ûÃÉÌØÐÅÓÃÏàÖúÉçÔâ´ó¹æÄ£Êý¾Ýй¶
Ðû²¼Ê±¼ä 2025-09-161. ·Ñ¶ûÃÉÌØÐÅÓÃÏàÖúÉçÔâ´ó¹æÄ£Êý¾Ýй¶
9ÔÂ13ÈÕ£¬·Ñ¶ûÃÉÌØÁª°îÐÅÓÃÏàÖúÉ磨FFCU£©¿ËÈÕת´ïÒ»ÆðÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬Éæ¼°³¬18.7ÍòÃû¿Í»§£¬Ð¹Â¶ÐÅÏ¢º¸Ç´Ó»ù´¡Éí·ÝÐÅÏ¢µ½Ò½ÁÆ¿µ½¡Êý¾ÝµÄȫά¶ÈÃô¸ÐÄÚÈÝ¡£ÊÓ²ìÏÔʾ£¬¹¥»÷ÕßÔçÔÚ2023Äê9ÔÂ30ÈÕÖÁ10ÔÂ18ÈÕʱ´ú±ãÈëÇÖÆäϵͳ£¬µ«FFCUÖ±ÖÁ2024Äê1Ô²ŷ¢Ã÷й¶ÊÂÎñ£¬¸üÔÚ2025Äê8Ô²ÅÈ·ÈÏÏêϸй¶Êý¾ÝÀàÐÍ£¬Ì»Â¶³öÇå¾²ÏìÓ¦»úÖÆµÄÑÏÖØÖͺ󡣴˴Îй¶µÄÊý¾Ý¹æÄ£¾ªÈË£¬°üÀ¨È«Ãû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢»¤ÕÕºÅÂë¡¢¼ÝʻִÕÕ/ÖÝÉí·ÝÖ¤ºÅÂë¡¢½ðÈÚÕË»§¼°Â·ÓɺÅÂë¡¢ÐÅÓÿ¨/½è¼Ç¿¨ÍêÕûÐÅÏ¢£¨º¬Çå¾²Âë/PINÂë/µ½ÆÚÈÕ£©¡¢Ë°ÎñPINÂë¡¢Ò½ÁÆÕï¶Ï/´¦·½/ÌṩÕßÐÅÏ¢¡¢°ü¹Üµ¥ºÅ¡¢ÖÎÁÆÓöÈÏêÇ飬ÒÔ¼°Êý×ÖÊðÃûµÈ¡£FFCUÇ¿µ÷£¬²¢·ÇËùÓÐСÎÒ˽¼ÒÊý¾Ý¾ù±»Ð¹Â¶£¬µ«ÖØ´óÐÅÏ¢ÁбíÏÔʾ¹¥»÷ÕßÒÑ»ñȡҪº¦¿Í»§ÎļþµÄÆÕ±é»á¼ûȨÏÞ¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÐÅϢʵÑé½ðÈÚڲơ¢¾«×¼ÍøÂç´¹ÂÚ£¬ÉõÖÁÔ¶³ÌÑéÖ¤Éí·Ý¾ÙÐиüÉî¶ÈµÄÉøÍ¸¡£Ö»¹ÜFFCU³ÆÎ´·¢Ã÷Éí·Ý͵ÇÔ»ò½ðÈÚÚ²ÆÊÂÎñ£¬µ«ÒÑΪÊܺ¦ÕßÌṩÃâ·ÑÉí·Ý͵ÇÔÔ¤·À·þÎñ¡£°µÍø¼à¿ØÏÔʾ£¬ÒÑÇýÖðµÄÀÕË÷Èí¼þ¼¯ÍÅBlackBasta¿ÉÄÜÓë´Ë°¸Ïà¹Ø£¬Æä¹¥»÷ÈÕÆÚÓëFFCUת´ïµÄй¶ʱ¶Î¸ß¶ÈÎǺϡ£
https://cybernews.com/security/fairmont-federal-credit-union-data/
2. FinWiseÒøÐÐÄÚ²¿Ö°Ô±ÐÅϢй¶ÊÂÎñÓ°Ïì68.9ÍòÃû¿Í»§
9ÔÂ15ÈÕ£¬FinWiseÒøÐÐÓÚ2024Äê5ÔÂ31ÈÕ±¬·¢Ò»ÆðÓÉǰ¹ÍԱȥְºó»á¼ûÃô¸ÐÎļþÒý·¢µÄÊý¾Ýй¶ÊÂÎñ£¬Éæ¼°ÏàÖú·½ÃÀ¹úµÚÒ»½ðÈÚ£¨AFF£©µÄ68.9ÍòÃû¿Í»§Êý¾Ý¡£AFF×÷ΪÏûºÄ½ðÈÚ·þÎñÉÌ£¬Ìṩ·ÖÆÚ´û¿î¡¢ÏÈ×âºóÂòµÈ²úÆ·£¬Æä¿Í»§´û¿î·¢·ÅÓë×ÊÖú¾ùÒÀÀµFinWiseÒøÐС£Æ¾Ö¤ÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒÅû¶µÄÎļþ£¬´Ë´ÎÊÂÎñÔ´ÓÚFinWiseÒ»ÃûǰԱ¹¤ÔÚÈ¥Ö°ºó²»·¨»á¼ûÒøÐÐÊý¾Ý£¬µ¼Ö°üÀ¨¿Í»§È«Ãû¼°ÆäËûСÎÒ˽¼ÒÊý¾ÝµÄÎļþ±»Ð¹Â¶¡£Ö»¹ÜFinWiseδ¹ûÕæ¸ÃÔ±¹¤ÔõÑùÍ»ÆÆÈ¥Ö°ºó»á¼ûÏÞÖÆ£¬Ò²Î´Åû¶×ÜÊÜÓ°ÏìÈËÊý£¬µ«ÊÂÎñÒÑÒý·¢¶àÆðÕûÌåËßËÏ¡£Ð¹Â¶Êý¾ÝÉæ¼°AFF¿Í»§ÉêÇë¡¢ÕË»§ÖÎÀí¡¢»¹¿îÁ÷³ÌµÈÒªº¦ÐÅÏ¢¡£FinWiseÔÚ·¢Ã÷ºóÁ¬Ã¦Æô¶¯Íâ²¿ÍøÂçÇ徲ר¼ÒÊӲ죬ÆÀ¹ÀΣº¦¹æÄ££¬²¢ÔöÇ¿ÄÚ²¿¿ØÖÆÒÔÔ¤·ÀÀàËÆÊÂÎñ¡£ÎªÌî²¹¿Í»§Ëðʧ£¬ÒøÐÐΪÊÜÓ°ÏìÓû§Ìṩ12¸öÔÂÃâ·ÑÐÅÓÃ¼à¿ØÓëÉí·Ý͵ÇÔ±£»¤·þÎñ¡£ÏÖÔÚ£¬FinWiseÒÔ¡°Éæ¼°ÕýÔÚ¾ÙÐеÄËßËÏ¡±ÎªÓɾܾø½øÒ»²½»ØÓ¦Ï¸½Ú£¬µ«ÊÂÎñÒÑ̻¶½ðÈÚ»ú¹¹ÔÚÔ±¹¤È¥Ö°ºóÊý¾Ý»á¼ûȨÏÞÖÎÀí¡¢Ãô¸ÐÊý¾Ý±£»¤»úÖÆµÈ·½ÃæµÄÎó²î¡£
https://www.bleepingcomputer.com/news/security/finwise-insider-breach-impacts-689k-american-first-finance-customers/
3. ¹È¸èLERSϵͳÔâÚ²ÆÕË»§ÉøÍ¸£¬Íþв×éÖ¯¹ØÁª¿ç¹úÊý¾Ý͵ÇÔÁ´
9ÔÂ15ÈÕ£¬¹È¸è֤ʵÆäÖ´·¨ÇëÇóϵͳ£¨LERS£©ÔâºÚ¿Í½¨ÉèÚ²ÆÕË»§£¬¸ÃÕË»§ËäδÏÖʵÌá½»ÇëÇó»ò»á¼ûÊý¾Ý£¬µ«Ì»Â¶ÁËÖ´·¨Êý¾ÝϵͳµÄÇå¾²Îó²î¡£´Ëǰ£¬Íþв×éÖ¯¡°Scattered Lapsus$ Hunters¡±ÔÚTelegramÐû³ÆÒÑÈëÇÖLERS¼°FBIµÄeCheckÅä¾°ÊÓ²ìϵͳ£¬²¢Ðû²¼ÏµÍ³»á¼û½ØÍ¼£¬Òý·¢È«ÇòÖ´·¨»ú¹¹¶ÔÃô¸ÐÊý¾ÝÇå¾²µÄµ£ÐÄ¡ª¡ª´ËÀàϵͳ±¾ÓÃÓÚÌá½»´«Æ±¡¢·¨ÔºÏÂÁîºÍ½ôÆÈÅû¶ÇëÇó£¬Î´¾ÊÚȨµÄ»á¼û¿ÉÄÜÔÊÐí¹¥»÷Õßð³äÖ´·¨Ö°Ô±»ñÈ¡Êܱ£»¤µÄÓû§Êý¾Ý¡£¸Ã×éÖ¯×Ô³ÆÎªShinyHunters¡¢ScatteredSpider¡¢LapsusµÈÀÕË÷×éÖ¯µÄ¹ØÁªÕûÌ壬½ñÄêÔøÍ¨¹ýÉç»á¹¤³ÌÓÕÆÔ±¹¤½«SalesforceÊý¾Ý¼ÓÔØÆ÷ÅþÁ¬ÆóҵʵÀý£¬ÇÔÈ¡¹È¸è¡¢°¢µÏ´ï˹¡¢°ÄÖÞº½¿Õ¡¢Ë¼¿ÆµÈÊýÊ®¼Ò¿ç¹úÆóÒµ¼°Õþ¸®»ú¹¹Êý¾Ý²¢ÊµÑéÀÕË÷¡£¹¥»÷·¾¶ÏÔʾ£¬ÆäÏȹ¥ÆÆSalesloftµÄGitHub´úÂë¿â£¬Ê¹ÓÃTrufflehog¹¤¾ßɨÃè˽ÓÐÔ´ÂëÖеÄ̻¶ÉñÃØ£¬»ñÈ¡Éí·ÝÑéÖ¤ÁîÅÆºó½øÒ»²½ÊµÑéSalesforceÊý¾ÝÇÔÈ¡¡£¹È¸èÍþвÇ鱨²¿·ÖMandiantÔøÂÊÏÈÅû¶´ËÀ๥»÷£¬ÖÒÑÔÆóÒµÔöÇ¿·ÀÓù¡£Ö»¹Ü¡°Scattered Lapsus$ Hunters¡±ÓÚ9ÔÂ14ÈÕÐû²¼¡°ÍËÐÝ¡±²¢Ðû²¼³¤Îijơ°Ä¬È»½«³ÉΪʵÁ¦¡±£¬µ«ÍøÂçÇå¾²Ñо¿Ö°Ô±ÒÔΪÆäÈÔÔÚÆáºÚÔ˶¯£¬Î´À´¿ÉÄÜͨ¹ýδÅû¶µÄÊý¾Ýй¶ÊÂÎñ¼ÌÐø¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/google-confirms-fraudulent-account-created-in-law-enforcement-portal/
4. ¿ªÔƼ¯ÍÅÔâShiny Hunters¹¥»÷ÖÂÊý°ÙÍò¿Í»§Êý¾Ýй¶
9ÔÂ15ÈÕ£¬È«ÇòÉÝ³ÞÆ·¾ÞÍ·¿ªÔƼ¯ÍÅ£¨Kering£©ÔâÓöÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬ÆìÏÂGucci¡¢Balenciaga¡¢Alexander McQueenµÈÆ·ÅÆµÄÊý°ÙÍò¿Í»§Ë½ÈËÊý¾Ý±»ºÚ¿Í×éÖ¯Shiny HuntersÇÔÈ¡¡£Ð¹Â¶Êý¾Ýº¸ÇÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢¼Òͥסַ¼°È«ÇòÉÝ³ÞÆ·ÃŵêÏûºÄ¼Í¼£¬²¿·Ö¿Í»§µ¥±ÊÏûºÄ½ð¶î¸ß´ï8.6ÍòÃÀÔª£¬Òý·¢¶Ô¡°¸ßÏûºÄÈËȺ¡±¿ÉÄܳÉΪºóÐøÕ©ÆÄ¿µÄµÄµ£ÐÄ¡£¿ªÔƼ¯ÍÅÒÑÈ·ÈÏÇå¾²Îó²î²¢Í¨ÖªÊý¾Ý±£»¤²¿·Ö£¬µ«Î´Åû¶ÏêϸÊÜÓ°Ïì¿Í»§ÊýÄ¿£¬½öÇ¿µ÷δй¶ÈκβÆÎñÐÅÏ¢¡£¾ÝBBC±¨µÀ£¬Shiny HuntersÏòÆäÌṩÁ˰üÀ¨ÊýǧÃû¿Í»§ÏêϸÐÅÏ¢µÄÕæÊµÊý¾ÝÑù±¾£¬²¢Éù³ÆÕÆÎÕ740Íò¸ö×ÔÁ¦µç×ÓÓʼþµØµã¶ÔÓ¦µÄÊý¾Ý£¬ÌåÏÖÊܺ¦Õß×ÜÊý»ò¿¿½ü¸ÃÊý×Ö¡£¸Ã×éÖ¯×ÔÆØÓÚ2025Äê4ÔÂͨ¹ýÈëÇÖ¿ªÔƼ¯ÍÅϵͳʵÑé¹¥»÷£¬µ«Ì¸ÅÐÆÆËéºó¿ªÔƼ¯ÍžܾøÖ§¸¶Êê½ð¡£¼¯Í޲»°È˽øÒ»²½ËµÃ÷£¬2025Äê6Ô·¢Ã÷δ¾ÊÚȨµÄµÚÈý·½ÔÝʱ»á¼ûϵͳ£¬½ö»ñÈ¡²¿·ÖÆ·ÅÆµÄÓÐÏÞ¿Í»§Êý¾Ý£¬ÇÒÎ´Éæ¼°²ÆÎñÐÅÏ¢¡£
https://securityaffairs.com/182236/cyber-crime/hackers-steal-millions-of-gucci-balenciaga-and-alexander-mcqueen-customer-records.html
5. µÂÖÝÎÚÍß¶ûµÏÑ§ÇøÔâÀÕË÷Èí¼þ¹¥»÷Ö¹رÕ
9ÔÂ16ÈÕ£¬µÂ¿ËÈøË¹ÖÝÎÚÍß¶ûµÏÊй«Á¢Ñ§ÇøÒòÀÕË÷Èí¼þ¹¥»÷±»ÆÈ¹Ø±ÕËÄÌ죬ӰÏìÔ¼5000ÃûѧÉú¼°¶à¸öÒªº¦ÏµÍ³¡£Ñ§ÇøÍ¨Ñ¶Ö÷¹Ü°²ÄÝ¡¤ÂêÀö¡¤°£Ë¹Æ¤ÅµÈøÌåÏÖ£¬¹¥»÷µ¼Ö·þÎñÆ÷̱»¾£¬ÑÏÖØ×ÌÈŵ绰¡¢¿Õµ÷¿ØÖÆ¡¢ÉãÏñÍ·¼à¿Ø¡¢·Ã¿ÍÖÎÀí¼°½Ìѧϵͳ£¨ÈçSkyward£©ÔËÐС£¸ÃÑ§ÇøÊÇ2022ÄêÂÞ²¼Ð¡Ñ§Ç¹»÷ÊÂÎñ±¬·¢µØ£¬ÐÂУ¸ÕÆôÓò»¾Ã£¬´Ë´ÎÊÂÎñÔÙ´Î̻¶У԰Ç徲ϵͳµÄųÈõÐÔ¡£ÊÂÎñ±¬·¢ºó£¬Ñ§ÇøÒÑÏòÁª°îÊÓ²ì¾Ö¡¢°ü¹ÜÍøÂçÇå¾²ÍŶӵȻú¹¹±¨¸æ£¬²¢Æô¶¯ÖÜÈ«ÊÓ²ìÒÔ×·ËݶñÒâÈí¼þȪԴ¼°ÆÀ¹ÀÊý¾Ýй¶Σº¦¡£Îª°ü¹ÜÇå¾²£¬Ñ§Çø½«Í£¿ÎËÄÌìÓëУÀú·ÇÊÂÇéÈÕ½»Á÷£¬Ñ§Ð£ÍøÕ¾¹Ø±Õ£¬Ë«Ñ§·Ö¿Î³ÌÔÝÍ£¡£×èÖ¹ÖÜÒ»£¬ÉÐÎÞÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÔðÈΣ¬ÐÂѧÄê¸ÕÆô¶¯µÄÑ§ÇøÃæÁÙ¸ü´óÌôÕ½¡£
https://therecord.media/uvalde-texas-school-district-temporarily-closing-ransomware
6. ³¯ÏÊKimsuky×éÖ¯½èAIαÔ캫¾ü·½Éí·Ý֤ʵÑé¾«×¼ÍøÂç´¹ÂÚ
9ÔÂ15ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾Genians¿ËÈÕÅû¶£¬³¯ÏÊÕþ¸®Åä¾°µÄÍþвÐÐΪÕßKimsuky×é֯ʹÓÃÈ˹¤ÖÇÄܹ¤¾ßChatGPTÌìÉúαÔìµÄº«¹ú¾üÊ»ú¹¹Éí·Ý֤ͼÏñ£¬ÓÃÓÚÉý¼¶Óã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷¡£¸Ã×é֯ð³äº«¹ú¹ú·ÀÏà¹Ø»ú¹¹£¬ÒÔÖÎÀí¾ü·½¹ÙÔ±Éí·ÝÖ¤·¢·ÅʹÃüΪÓÉ£¬Í¨¹ýµç×ÓÓʼþ·¢ËͰüÀ¨Î±ÔìÉí·ÝÖ¤Ñù±¾µÄ´¹ÂÚÁ´½Ó£¬ÓÕµ¼Ä¿µÄµã»÷ºó°²ÅŶñÒâÈí¼þ£¬ÊµÏÖÊý¾Ý͵ÇÔºÍÔ¶³Ì¿ØÖÆ¡£´Ë´Î¹¥»÷ÓÚ2025Äê7ÔÂ17ÈÕÊ״α»GeniansÇå¾²ÖÐÐÄ·¢Ã÷£¬ÏµKimsuky×éÖ¯6ÔÂClickFix´¹ÂÚÔ˶¯µÄºóÐøÐж¯¡£Á½´Î¹¥»÷¾ùʹÓÃÏàͬ¶ñÒâÈí¼þ£¬Ö÷ÒªÕë¶Ô³¯ÏÊÑо¿Ö°Ô±¡¢ÈËȨÔ˶¯¼Ò¼°¼ÇÕß¡£Î±ÔìÉí·Ý֤ͼÏñ¾¼ì²âΪÉî¶ÈαÔìµÄ¸ÅÂÊ´ï98%£¬ÆäÕæÊµÐÔÔöÇ¿ÏÔÖøÌáÉýÁË´¹ÂÚÓʼþµÄ¿ÉÐŶȣ¬Ê¹Êܺ¦Õ߸üÒ×ËÉ¿ªÐ¡ÐÄ¡£´Ë´ÎÊÂÎñÕ¹ÏÖÁ˹ú¼ÒÖ§³ÖÐÍÍþв×éÖ¯¶ÔAIÊÖÒÕµÄÀÄÓÃÇ÷ÊÆ¡£Kimsukyͨ¹ýÍŽáÉç»á¹¤³ÌѧÓëAIÌìÉúÄÚÈÝ£¬¹¹½¨Á˸üÒþ²ØµÄ¹¥»÷Á´£º´Ó·Âð¹Ù·½ÓòÃû¡¢Î±Ôì¸ß·ÂÕæÖ¤¼þ£¬µ½Ö²Èë¶ñÒâ¾ç±¾£¬ÐγÉÍêÕûÉøÍ¸Â·¾¶¡£
https://www.infosecurity-magazine.com/news/ai-military-ids-north-korea/


¾©¹«Íø°²±¸11010802024551ºÅ