ÀÕË÷Èí¼þ×éÖ¯EverestÈëÇÖ°²µÂÂêÇÔÈ¡º£Á¿Êý¾Ý
Ðû²¼Ê±¼ä 2025-11-191. ÀÕË÷Èí¼þ×éÖ¯EverestÈëÇÖ°²µÂÂêÇÔÈ¡º£Á¿Êý¾Ý
11ÔÂ17ÈÕ£¬ÀÕË÷Èí¼þ×éÖ¯EverestÔÚÆä°µÍøÐ¹Â¶ÍøÕ¾Ðû³ÆÒÑÈëÇÖÃÀ¹úÔ˶¯´ò°ç¾ÞÍ·Under Armour£¨°²µÂÂ꣩£¬ÇÔÈ¡343GBÄÚ²¿Êý¾Ý£¬º¸ÇÔ±¹¤ÐÅÏ¢¼°¶à¹úÊý°ÙÍòÓû§Ð¡ÎÒ˽¼ÒÊý¾Ý¡£ÎªÖ¤ÊµÕæÊµÐÔ£¬¸Ã×éÖ¯Ðû²¼ÁËÑù±¾Êý¾Ý£¬°üÀ¨¿Í»§¹ºÎïÀúÊ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢¹ºÖÃʱ¼ä´Á¡¢²úÆ·SKU¡¢Ãû³Æ¡¢Öֱ𡢼ÛÇ®¡¢¿â´æ×´Ì¬¡¢ÆÀ·Ö¡¢ÍâµØ»¯ÐÎò¼°ÓªÏúÔ˶¯ÈÕÖ¾µÈÃô¸ÐÐÅÏ¢£¬ÉõÖÁÉæ¼°Óû§ÓïÑÔÆ«ºÃ¡¢ÔÞ³É״̬¼°ÕË»§¹ØÁª±êʶ·û¡£ÕâЩÊý¾ÝÉî¶ÈÈÚºÏÉÌÒµÇ鱨ÓëСÎÒ˽¼ÒÐÐΪ£¬Èô¾°²µÂÂê֤ʵ£¬½«×é³ÉÑÏÖØÊý¾Ýй¶ÊÂÎñ¡£EverestΪ°²µÂÂêÉ趨ÆßÈÕµ¹¼ÆÊ±ÏÞÆÚ£¬ÒªÇóͨ¹ýTox¼´Ê±Í¨Ñ¶¹¤¾ßÁªÏµ£¬ÖÒÑÔ¡°Ê±¼äºÄ¾¡Ç°¡±Ðè°´°ì·¨²Ù×÷£¬²»È»¿ÉÄÜй¶ÍêÕûÊý¾Ý¡£ÏÖÔÚ£¬°²µÂÂêÉÐδ¹Ù·½È·ÈÏ»ò·ñ¶¨´ËÖ¸¿Ø£¬µ«Ç徲ר¼Ò½¨ÒéÓû§½ÓÄÉÔ¤·À²½·¥£ºÇ×½ü¼à¿ØÕË»§ÓëÒøÐÐÔ˶¯£¬¸ü¸ÄËùÓйØÁªÃÜÂ룬ÔÚ°²µÂÂêÏà¹ØÕË»§ÆôÓÃË«ÒòËØÈÏÖ¤£¬²¢Ð¡ÐÄαװ³ÉÊý¾Ýй¶¾¯±¨µÄ´¹ÂÚÓʼþ¡£
https://hackread.com/everest-ransomware-under-armour-users-data/
2. RondoDox½©Ê¬ÍøÂçʹÓÃXWikiÎó²îÕö¿ª´ó¹æÄ£¹¥»÷
11ÔÂ17ÈÕ£¬ÃÀ¹úÍøÂçÇå¾²ºÍÐÅÏ¢Çå¾²¾Ö£¨CISA£©ÓÚ10ÔÂ30ÈÕ½«XWikiƽ̨ÖеÄCVE-2025-24893Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î±ê¼ÇΪ"ÕýÔÚ±»Æð¾¢Ê¹ÓÃ"¡£Îó²îÇ鱨¹«Ë¾VulnCheck×îб¨¸æÏÔʾ£¬¸ÃÎó²îÒѱ»¶à¸öÍþвÐÐΪÕßʹÓ㬰üÀ¨RondoDox½©Ê¬ÍøÂçÔËÓªÉ̺ͼÓÃÜÇ®±Ò¿ó¹¤¡£RondoDox×÷Ϊ´ó¹æÄ£½©Ê¬ÍøÂç¶ñÒâÈí¼þ£¬×îÔçÓÉFortinetÓÚ2025Äê7Լͼ£¬Ç÷ÊÆ¿Æ¼¼ÔÚ10Ô³õÖÒÑÔÆä³ÊÖ¸Êý¼¶ÔöÌí£¬×îбäÖÖʹÓÃ56¸öÒÑÖªÎó²î¹¥»÷ÖÁÉÙ30̨װ±¸£¬²¿·ÖÎó²îÔ´×ÔPwn2OwnºÚ¿Í´óÈüÅû¶µÄÎó²î¡£¹¥»÷·¾¶ÏÔʾ£¬RondoDoxͨ¹ýÈ«ÐĽṹµÄHTTP GETÇëÇó£¬Ê¹ÓÃXWiki SolrSearch¶Ëµã×¢Èëbase64±àÂëµÄGroovy´úÂ룬´¥·¢·þÎñÆ÷ÏÂÔØ²¢Ö´ÐÐÔ¶³ÌshellÓÐÓÃÔØºÉ¡£µÚÒ»½×¶ÎÏÂÔØÆ÷¾ç±¾»á¼ìË÷²¢Ö´ÐÐÖ÷ÒªÓÐÓÃÔØºÉ¡£Ñо¿Ö°Ô±ÊӲ쵽£¬11ÔÂ7ÈÕ·ºÆð¼ÓÃÜÇ®±ÒÍÚ¿ó³ÌÐò°²ÅÅ£¬10ÔÂ31ÈÕºÍ11ÔÂ11ÈÕÔò±¬·¢½¨Éèbash·´ÏòshellµÄʵÑé¡£±ðµÄ£¬¹¥»÷Õß»¹Í¨¹ýNuclei¾ÙÐÐÆÕ±éɨÃ裬ʵÑéÖ´ÐÐÉó²éϵͳÓû§ÕË»§ÐÅÏ¢µÄÏÂÁî¼°»ùÓÚOASTµÄ̽²â¡£
https://www.bleepingcomputer.com/news/security/rondodox-botnet-malware-now-hacks-servers-using-xwiki-flaw/
3. Eurofiber FranceÔâºÚ¿ÍÈëÇÖÖÂÆ±ÎñϵͳÊý¾Ýй¶
11ÔÂ17ÈÕ£¬ºÉÀ¼µçÐż¯ÍÅEurofiber Group NVÆìÏ·¨¹ú×Ó¹«Ë¾Eurofiber France SAS¿ËÈÕÅû¶һÆðÊý¾Ýй¶ÊÂÎñ¡£¸Ã¹«Ë¾×¨×¢ÓÚΪÆóÒµÌṩÊý×Ö»ù´¡ÉèÊ©£¬ÔËÓªÁýÕÖºÉÀ¼¡¢±ÈÀûʱ¡¢·¨¹úºÍµÂ¹úµÄ76,000¹«Àï¹âÏËÍøÂç¡£ÊÂÎñ±¬·¢ÓÚÉÏÖÜÍíЩʱ¼ä£¬ºÚ¿ÍʹÓÃÎó²îÈëÇ֯䯱ÎñÖÎÀíϵͳ¼°ÔƲ¿·Ö£¨ATE portal£©£¬²¢²¨¼°ÇøÓò×ÓÆ·ÅÆEurafibre¡¢FullSave¡¢NetiwanºÍAvelia¡£¹«Ë¾Ç¿µ÷£¬´æ´¢ÔÚÆäËûϵͳÖеÄÒøÐÐÏêϸÐÅÏ¢µÈ¡°Òªº¦Êý¾Ý¡±Î´ÊÜÓ°Ï죬µ«Î´Ïêϸ˵Ã÷±»µÁÊý¾ÝÀàÐÍ£¬½öÌåÏÖ½«Í¨ÖªÊÜÓ°Ïì¿Í»§¡£ÍþвÐÐΪÕß¡°ByteToBreach¡±ÔÚÊý¾Ýй¶ÂÛ̳Éù³Æ¶Ô´ËÈÏÕæ£¬Ðû³ÆÇÔÈ¡ÁË10,000¼ÒÆóÒµ¼°Õþ¸®ÊµÌåµÄÊý¾Ý£¬°üÀ¨ÆÁÄ»½ØÍ¼¡¢VPNÉèÖÃÎļþ¡¢Æ¾Ö¤¡¢Ô´´úÂë¡¢Ö¤Êé¡¢´æµµ¡¢µç×ÓÓʼþÕË»§ÎļþºÍSQL±¸·ÝÎļþ¡£¸Ã×éÖ¯ÒªÇóÖ§¸¶Êê½ð£¬²»È»½«¹ûÕæÐ¹Â¶Êý¾Ý¡£Eurofiber FranceÔÚ·¢Ã÷Îó²îºóÊýСʱÄÚ£¬ÒÑ¶ÔÆ±Îñƽ̨ºÍATEÃÅ»§ÊµÑéÔöÇ¿Çå¾²²½·¥²¢ÐÞ¸´Îó²î£¬Í¬Ê±½ÓÄÉÌØÊâ²½·¥±ÜÃâ½øÒ»²½Ð¹Â¶¡£¹«Ë¾ÒÑÏò·¨¹úÊý¾Ý±£»¤»ú¹¹CNIL¡¢ÍøÂçÇå¾²»ú¹¹ANSSIÌá½»ÀÕË÷±¨¸æ£¬²¢×ª´ïÊÂÎñÏêÇé¡£
https://www.bleepingcomputer.com/news/security/eurofiber-france-warns-of-breach-after-hacker-tries-to-sell-customer-data/
4. ÒÁÀÊAPT42×éÖ¯Ìᳫ¡°SpearSpecter¡±Ìع¤Ðж¯
11ÔÂ14ÈÕ£¬ÒÔÉ«Áйú¼ÒÊý×Ö»ú¹¹£¨INDA£©¿ËÈÕÅû¶£¬ÒÁÀʹú¼ÒÖ§³ÖµÄAPT42×éÖ¯£¨ÓÖÃûAPT35¡¢Charming Kitten£©×Ô2025Äê9Ô³õÆð£¬Õë¶ÔÒÁ˹À¼¸ïÃüÎÀ¶Ó£¨IRGC£©¹Ø×¢µÄ¸ß¼¶¹ú·ÀºÍÕþ¸®¹ÙÔ±¼°Æä¼ÒÍ¥³ÉÔ±£¬Ìᳫ´úºÅΪ¡°SpearSpecter¡±µÄÒ»Á¬ÐÔÌØ¹¤Ðж¯¡£¸ÃÐж¯ÒԸ߶ȸöÐÔ»¯µÄÉç½»¹¤³ÌΪ½¹µãÊֶΣ¬¹¥»÷Õßͨ¹ýαװ³ÉÄ¿µÄÊìʶµÄÁªÏµÈË£¬ÒÔÔ¼Çë¼ÓÈë×ÅÃû¾Û»á»ò°²ÅÅÖ÷Òª»áÎîΪÓɽ¨ÉèÐÅÍУ¬ÉõÖÁÑÓÉìÖÁÄ¿µÄ¼ÒÍ¥³ÉÔ±ÒÔÀ©´ó¹¥»÷Ãæ¡£Ñо¿ÏÔʾ£¬¹¥»÷Á´·ºÆðϸÃÜÉè¼Æ£º¹¥»÷Õßͨ¹ýWhatsApp·¢ËÍαװ³É¾Û»áËùÐèÎļþµÄ¶ñÒâÁ´½Ó£¬Ê¹Óá°search-ms:¡±ÐÒé´¦Öóͷ£³ÌÐò¶¨ÏòÖÁWebDAVÍйܵÄWindows¿ì½Ý·½·¨Îļþ¡£¸ÃLNKÎļþ»áÅþÁ¬Cloudflare Workers×ÓÓòÃû»ñÈ¡Åú´¦Öóͷ£¾ç±¾£¬×îÖÕ¼ÓÔØ¾ß±¸Ä£¿é»¯¹¦Ð§µÄPowerShellºóÃÅTAMECAT¡£¸ÃºóÃŽÓÄÉHTTPS¡¢DiscordºÍTelegramÈýÖØÍ¨Ñ¶ÐŵÀ£¬Ö§³ÖϵͳÕì̽¡¢ÎļþÇÔÈ¡¡¢ä¯ÀÀÆ÷Êý¾Ý͵ȡ¡¢OutlookÓÊÏäÄÚÈÝÍøÂç¼°15Ãë¾àÀëÒ»Á¬½ØÆÁ£¬ËùÓÐÊý¾Ýͨ¹ýHTTPS»òFTPÍâ´«¡£ÆäÒþÉíÊÖÒÕ°üÀ¨¼ÓÃÜÒ£²âÊý¾Ý¡¢»ìÏýÔ´´úÂ롢ʹÓÃÕýµ±ÏµÍ³¹¤¾ßÒþ²ØÐÐΪ£¬²¢Ö÷ÒªÔÚÄÚ´æÖÐÔËÐÐÒÔïÔÌ´ÅÅ̺ۼ£¡£
https://thehackernews.com/2025/11/iranian-hackers-launch-spearspecter-spy.html
5. È«Çòµç³Ø¾ÞÍ·LGÄÜÔ´ÔâAkiraÀÕË÷Èí¼þ¹¥»÷
11ÔÂ19ÈÕ£¬¿ËÈÕ£¬È«Çò×î´óµç³ØÖÆÔìÉÌÖ®Ò»º«¹úLGÄÜÔ´½â¾ö¼Æ»®¹«Ë¾Ö¤ÊµÔâÊÜÀÕË÷Èí¼þ¹¥»÷¡£¾Ý¹«Ë¾½²»°ÈË͸¶£¬´Ë´Î¹¥»÷Ä¿µÄΪÍâÑóij´¦Ìض¨ÉèÊ©£¬×ܲ¿¼°ÆäËû´óÖÞÉèʩδÊÜÓ°Ïì¡£ÊÜÓ°ÏìÉèÊ©ÔÚ½ÓÄɻָ´²½·¥ºóÒѻָ´Õý³£ÔËת£¬¹«Ë¾Õý¿ªÕ¹Çå¾²ÊÓ²ì×÷ΪԤ·À²½·¥¡£¸ÃÊÂÎñÓëAkiraÀÕË÷Èí¼þÍÅ»ïÖ±½ÓÏà¹Ø¡£¸ÃÍÅ»ïÉÏÖܱ»ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ÁÐÎªÖØµã¹Ø×¢¹¤¾ß¡£FBIÓÚ11ÔÂ13ÈÕÐû²¼×îÐÂ֪ͨ£¬Ö¸³öAkiraÍÅ»ïͨ¹ýÀÕË÷Èí¼þÒÑÀÕË÷³¬2.44ÒÚÃÀÔªÊê½ð£¬Æä¹¥»÷²»µ«ÇÔÈ¡¿î×Ó£¬¸üÆÆËðÒ½Ôº¡¢Ñ§Ð£¼°ÆóÒµÔËÐÐϵͳ¡£FBIÖÒÑÔ£¬¸Ã×éÖ¯ÕýÃé×¼ÖÆÔìÒµ¼°ÆäËû¶à¸öÐÐÒµ¡£¾ÝϤ£¬AkiraÍÅ»ïÒѽ«LGÄÜÔ´ÁÐÈëÆäÐ¹Â¶ÍøÕ¾£¬Éù³ÆÇÔÈ¡Á˰üÀ¨¹«Ë¾Îļþ¡¢Ô±¹¤ÐÅÏ¢Êý¾Ý¿âÔÚÄÚµÄ1.7TBÊý¾Ý¡£×÷Ϊº«¹ú¿ç¹ú¹«Ë¾LGµÄ×Ó¹«Ë¾£¬LGÄÜÔ´Ô¤¼Æ2024Ä꽫ͨ¹ýÏòÆû³µÖÆÔìÉ̹©Ó¦µç³Ø»ñµÃ175ÒÚÃÀÔªÊÕÈ룬ÆäÐÐҵְλʹÆä³ÉÎªÍøÂç·¸·¨Ä¿µÄ¡£
https://therecord.media/lg-energy-solution-ransomware-incident-battery-maker
6. ·¨¹úPajemploiÊý¾Ýй¶ÊÂÎñ²¨¼°120ÍòÈË
11ÔÂ18ÈÕ£¬·¨¹úÉç»á°ü¹Ü·þÎñ»ú¹¹Pajemploi¿ËÈÕÔâÓöÖØ´óÊý¾Ýй¶ÊÂÎñ£¬¿ÉÄÜÓ°ÏìÔ¼120ÍòÃûʹÓÃÆä·þÎñµÄ˽Ӫ¹ÍÖ÷Ô±¹¤¼°×¨ÒµÕչ˻¤Ê¿Ö°Ô±¡£¾Ý¸Ã»ú¹¹Í¨¸æ£¬11ÔÂ14ÈÕ·¢Ã÷µÄÍøÂç¹¥»÷µ¼ÖÂÓû§È«Ãû¡¢³öÉúµØ¡¢ÓÊÕþµØµã¡¢Éç»áÇå¾²ºÅÂë¡¢ÒøÐлú¹¹Ãû³Æ¡¢PajemploiÕ˺ż°ÈÏÖ¤±àºÅµÈÃô¸ÐÐÅÏ¢±»µÁ£¬µ«ÒøÐÐÕ˺ţ¨IBAN£©¡¢µç×ÓÓÊÏä¡¢µç»°ºÅÂë¼°ÕË»§ÃÜÂëδ±»»ñÈ¡¡£´Ë´ÎÊÂÎñÖ÷񻃾¼°Í¨¹ýURSSAF£¨·¨¹úÉç»á°ü¹Ü½É¿î»ú¹¹£©Ê¹ÓÃPajemploi·þÎñµÄ¼Ò³¤¼°¼ÒÍ¥Íжù·þÎñÌṩÕß¡£PajemploiÇ¿µ÷£¬Ö»¹ÜÊý¾Ýй¶£¬µ«Æä½¹µãÔËӪδÊÜÓ°Ï죬É걨±í´¦Öóͷ£¼°ÈËΪ֧¸¶µÈ·þÎñÈÔÕý³£ÔË×÷¡£ÊÂÎñ±¬·¢ºó£¬»ú¹¹Á¬Ã¦Æô¶¯Ó¦¼±²½·¥×èÖ¹¹¥»÷£¬²¢ÒÑÏò·¨¹úÊý¾Ý±£»¤¾Ö£¨CNIL£©ºÍ¹ú¼ÒÐÅϢϵͳÇå¾²¾Ö£¨ANSSI£©±¨¸æ£¬Í¬Ê±ÔÊÐíµ¥¶À֪ͨÿλÊÜÓ°ÏìÖ°Ô±¡£URSSAFÒàÌáÐѹ«ÖÚСÐÄÕ©ÆÎ£º¦£¬Òòй¶ÐÅÏ¢¿ÉÄܱ»ÓÃÓÚ´¹ÂÚÓʼþ¡¢¶ÌÐÅ»òµç»°Õ©Æ¡£×èÖ¹ÏÖÔÚÉÐÎÞÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£
https://www.bleepingcomputer.com/news/security/french-agency-pajemploi-reports-data-breach-affecting-12m-people/


¾©¹«Íø°²±¸11010802024551ºÅ