Óý±Ì¡¶²ÊºçÁùºÅ£ºÎ§¹¥¡·ÓöÇå¾²Îó²î

Ðû²¼Ê±¼ä 2025-12-29

1. Óý±Ì¡¶²ÊºçÁùºÅ£ºÎ§¹¥¡·ÓöÇå¾²Îó²î


12ÔÂ28ÈÕ£¬¿ËÈÕ£¬Óý±ÌÆìÏÂÈÈÃÅÕ½ÊõÉä»÷ÓÎÏ·¡¶²ÊºçÁùºÅ£ºÎ§¹¥¡·£¨R6£©ÔâÓöÑÏÖØÇå¾²Îó²îÊÂÎñ£¬Òý·¢È«ÇòÍæ¼Ò¼°Çå¾²½çÆÕ±é¹Ø×¢¡£ºÚ¿ÍʹÓÃÎó²î²»·¨Ê¹ÓÃÓÎÏ·ÄÚ²¿ÏµÍ³£¬°üÀ¨Ë½×Ô·â½û/½â·âÍæ¼ÒÕË»§¡¢ÔÚ·â½ûת¶¯ÌõαÔìÐéαÐÅÏ¢¡¢ÏòËùÓÐÍæ¼Ò·¢·ÅÔ¼20ÒÚR6µãÊý£¨¼ÛÖµÔ¼1333ÍòÃÀÔª£¬°´Óý±ÌÉ̳Ƕ¨¼ÛÅÌË㣩¼°ÉùÍû£¬²¢½âËø¿ª·¢ÕßרÊôƤ·ôµÈËùÓÐÍâ¹ÛµÀ¾ß¡£ÊÂÎñ±¬·¢ºó£¬Óý±Ì¹Ù·½Ñ¸ËÙÏìÓ¦¡£ÖÜÁùÉÏÎç9µã10·Ö£¬¹Ù·½Õ˺Å֤ʵÎÊÌâ±£´æ²¢ÌåÏÖÍŶÓÕýÈ«Á¦ÐÞ¸´¡£Ëæºó£¬Óý±Ì×Ô¶¯¹Ø±ÕÓÎÏ··þÎñÆ÷¼°ÄÚ¹ºÉ̳Ç£¬¼¯ÖÐ×ÊÔ´½â¾öÎÊÌâ¡£ÔÚ×îÖÕ¸üÐÂÖУ¬Óý±ÌÃ÷È·ÌåÏÖ²»»á´¦·ÖÒòÎó²î»ñµÃ»ý·ÖµÄÍæ¼Ò£¬µ«½«»Ø¹öUTCʱ¼äÉÏÎç11µãºóµÄËùÓÐÉúÒ⡣ͬʱǿµ÷£¬·â½ûת¶¯ÌõÖеÄÐÂÎŲ¢·Ç¹Ù·½ÌìÉú£¬¸Ã¹¦Ð§´ËǰÒѱ»½ûÓá£×èÖ¹ÏÖÔÚ£¬Óý±ÌÉÐδÐû²¼ÕýʽÉùÃ÷Ú¹ÊÍÎó²î³ÉÒò£¬Ò²Î´»ØÓ¦Ã½ÌåѯÎÊ¡£


https://www.bleepingcomputer.com/news/security/massive-rainbow-six-siege-breach-gives-players-billions-of-credits/


2. ºÚ¿Íй¶Wired.com 230ÍòÓû§Êý¾Ý


12ÔÂ27ÈÕ£¬¿ËÈÕ£¬¼ÙÃû¡°Lovely¡±µÄºÚ¿ÍÔÚBreach StarsÂÛ̳й¶¾Ý³Æ³¬230ÍòWired.comÓû§Êý¾Ý£¬º­¸ÇÐÕÃû¡¢ÓÊÏä¡¢Óû§ID¡¢ÕË»§½¨Éè/¸üÐÂʱ¼ä´ÁµÈÐÅÏ¢£¬²¿·Ö¼Í¼º¬ÉϴλỰÈÕÆÚ¡£Êý¾Ý×îÔç×·ËÝÖÁ2011Äê£¬Éæ¼°ÕæÊÊÓû§ÕË»§£¬µ«ÎÞÃÜÂë»òÖ§¸¶ÐÅÏ¢¡£ºÚ¿ÍÖ¸Ôð¿µÌ©ÄÉÊ˼¯ÍÅ£¨Wiredĸ¹«Ë¾£©ºöÊÓÇå¾²ÖÒÑÔ£¬³Æ¡°ºÄʱһÔ²ÅÍÆ¶¯Îó²îÐÞ¸´¡±£¬²¢ÍþвδÀ´¼¸Öܽ«Ð¹Â¶³¬4000ÍòÓû§Êý¾Ý£¬Éæ¼°GQ¡¢Vogue¡¢Å¦Ô¼¿ÍµÈÆìÏÂÆ·ÅÆ¡£¾ÝºÚ¿ÍÅû¶µÄ¼Í¼Çåµ¥£¬¿µÌ©ÄÉÊËÆì϶à¸öÆ·ÅÆÕË»§Êý¾Ý±»Ð¹Â¶£ºWired 236Íò¡¢Vogue 196Íò¡¢Å¦Ô¼¿Í680Íò¡¢Self 208ÍòµÈ£¬Áíº¬Î´ÖªÆ·ÅÆ¡°NIL¡±³¬947ÍòÕË»§¼°¹ú¼Ê×ÓÆ·ÅÆÊý¾Ý¡£²¿·Ö¼Í¼ʹÓÃϵͳÌìÉúÓÊÏ䣬µ«´ó¶¼ÎªGmail¡¢AOLµÈСÎÒ˽¼ÒÓÊÏ䣬֤ʵÊý¾ÝÔ´×Ôʵʱ»ò´æµµÓû§Êý¾Ý¿â£¬·Ç¾²Ì¬ÓªÏúÁбí£¬Ö§³ÖºÚ¿Í¡°Ö±½Ó»á¼ûÕË»§ÏµÍ³¡±µÄ˵·¨¡£ÏÖÔÚ£¬Êý¾ÝÕæÊµÐÔÈÔÐè¹Ù·½ÑéÖ¤£¬µ«É罻ýÌ屨µÀÏÔʾÑù±¾°üÀ¨ÕæÊÊÓû§ÐÅÏ¢¡£


https://hackread.com/hacker-leak-wired-com-records-conde-nast-breach/


3. EverestÀÕË÷Èí¼þ×éÖ¯ÈëÇÖ¿ËÀ³Ë¹ÀÕ


12ÔÂ25ÈÕ£¬EverestÀÕË÷Èí¼þ×éÖ¯ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû²¼Ìû×Ó£¬Ðû³ÆÒÑÈëÇÖÃÀ¹úÆû³µÖÆÔìÉÌ¿ËÀ³Ë¹ÀÕϵͳ£¬ÇÔÈ¡1088GB£¨³¬1TB£©Êý¾Ý£¬º­¸Ç2021ÄêÖÁ2025ÄêÓëÔËÓªÏà¹ØµÄÍêÕûÊý¾Ý¿â¡£¾Ý¹¥»÷Õ߳ƣ¬ÆäÖаüÀ¨³¬105GBµÄSalesforceÐÅÏ¢£¬Éæ¼°¿Í»§¡¢¾­ÏúÉ̼°ÄÚ°²ÅÅÀíµÄº£Á¿Ð¡ÎÒ˽¼ÒÓëÔËÓª¼Í¼¡£Ð¹Â¶µÄÆÁÄ»½ØÍ¼¼°Ê¾ÀýÊý¾ÝÏÔʾ£¬Êý¾Ý°üÀ¨½á¹¹»¯Êý¾Ý¿â¡¢ÄÚ²¿µç×Ó±í¸ñ¡¢CRMµ¼³öÎļþµÈ¡£¿Í»§»¥¶¯ÈÕÖ¾ÏêÁÐÐÕÃû¡¢µç»°¡¢µØµã¡¢³µÁ¾ÐÅÏ¢¡¢Õٻذ¸Àý±¸×¢¼°Í¨»°Ð§¹û£»ÊðÀíÊÂÇéÈÕÖ¾¼Í¼ºô½ÐʵÑé¡¢ÕÙ»ØÐ­µ÷¡¢Ô¤Ô¼´¦Öóͷ£¼°³µÁ¾×´Ì¬¸üС£±ðµÄ£¬ÄÚ²¿Îļþ·þÎñÆ÷Ä¿Â¼Éæ¼°¾­ÏúÉÌÍøÂç¡¢Æû³µÆ·ÅÆ¡¢ÕÙ»ØÍýÏë¡¢FTP·¾¶¼°ÄÚ²¿¹¤¾ß£¬»¹°üÀ¨Ô±¹¤ÐÕÃû¡¢¹ÍӶ״̬¡¢Ê±¼ä´Á¼°Stellantis¹ØÁªÓÊÏäÓòÃûµÄÈËÁ¦×ÊÔ´¼Í¼¡£Ñù±¾ÖеÄÕٻذ¸ÀýÐðÊöÓëCRMÊý¾ÝÒ»Ö£¬ÇÐºÏÆû³µÕÙ»ØÖ§³Ö¼°¿Í»§·þÎñÁ÷³Ì¡£EverestÍþвµ¹¼ÆÊ±¿¢ÊºóÐû²¼ÍêÕûÊý¾Ý¼¯£¬²¢ÍýÏëÐû²¼¿Í»§·þÎñ»¥¶¯Â¼ÒôÒÔʩѹ¡£


https://hackread.com/everest-ransomware-group-chrysler-data-breach/


4. Noname057Éù³Æ¶Ô·¨¹úÓÊÕþ·þÎñ·¢¶¯ÍøÂç¹¥»÷


12ÔÂ26ÈÕ£¬¿ËÈÕ£¬·¨¹ú¹ú¼ÒÓÊÕþ·þÎñ¹«Ë¾La Poste֤ʵÔâÓöÖØ´óÍøÂçÊÂÎñ£¬ÆäÐÅϢϵͳÒòDDoS¹¥»÷ÀëÏߣ¬µ¼ÖÂÊý°ÙÍò¿Í»§µÄÊý×ÖÒøÐС¢ÔÚÏß·þÎñ¼°²¿·ÖÓʾַþÎñÖÐÖ¹¡£ÏêϸÊÜÓ°ÏìÆ½Ì¨°üÀ¨Ö÷ÍøÕ¾¡¢Òƶ¯Ó¦Óá¢Êý×ÖÉí·Ý·þÎñ¡¢DigiposteÎļþ´æ´¢Æ½Ì¨¼°La Banque PostaleÍøÉÏÒøÐУ¬µ«¹ñ̨·þÎñÈÔ¿ÉÖÎÀíÒøÐкÍÓÊÕþÓªÒµ£¬¿Í»§¿Éͨ¹ý¶ÌÐÅÑéÖ¤Íê³ÉÖ§¸¶¡¢ÌáÏֵȲÙ×÷¡£Ç×¶íºÚ¿Í×éÖ¯NoName057(16)Ðû³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬·¨¹úÉó²é¹Ù³Æ·¨¹úÇ鱨»ú¹¹DGSIÒѽéÈëÊӲ졣´Ë´Î¹¥»÷ÊǸÃ×éÖ¯½üÆÚ¶ÔÖ§³ÖÎÚ¿ËÀ¼¹ú¼Ò£¨¶àΪ±±Ô¼³ÉÔ±¹ú£©µÄDDoS¹¥»÷Éý¼¶µÄÒ»²¿·Ö£¬×Ô2023ÄêÆð£¬¸Ã×éÖ¯Òѹ¥»÷ÈðµäÕþ¸®¡¢µÂ¹ú250Óà¼ÒʵÌ壬²¢×ÌÈÅÈðÊ¿ÎÚ¿ËÀ¼Çå¾²·å»á¡¢±±Ô¼·å»áµÈÔ˶¯£¬µ«¾ùδÔì³ÉÖØ´óÓ°Ïì¡£ÖµµÃ×¢ÖØµÄÊÇ£¬7ÔÂÅ·ÖÞÓëÃÀ¹úÍŽῪչµÄ¡°ÒÁË¹ÌØÎ鯷Ðж¯¡±ÒÑÖØ´´NoName057(16)¡£¸Ã×éÖ¯ÓµÓг¬4000ÃûÖ§³ÖÕߣ¬ÒÀÀµ×Ô½¨½©Ê¬ÍøÂç¼°DDoSiaµÈµÍÃż÷ƽ̨ʵÑé¹¥»÷¡£


https://securityaffairs.com/186157/hacktivism/pro-russian-group-noname057-claims-cyberattack-on-la-poste-services.html


5. Trust Wallet ChromeÀ©Õ¹Îó²îÖÂ700Íò¼ÓÃÜ×ʲú±»µÁ


12ÔÂ26ÈÕ£¬Trust Wallet Chromeä¯ÀÀÆ÷À©Õ¹³ÌÐò2.68.0°æ±¾¸üк󱬷¢Çå¾²ÊÂÎñ£¬µ¼ÖÂÖÁÉÙ700ÍòÃÀÔª¼ÓÃÜÇ®±Ò±»µÁ¡£Óû§±¨¸æ³Æ£¬¸üкóÇ®°ü×ʽð±»Çå¿Õ£¬¹¥»÷Õßͨ¹ý¹©Ó¦Á´¹¥»÷ÔÚÀ©Õ¹³ÌÐòµÄ4482.jsÎļþÖÐÖ²Èë¶ñÒâ´úÂ룬½«Ç®°üÖú¼Ç´Ê¡¢ÉúÒâ¼Í¼µÈÃô¸ÐÊý¾Ýй¶ÖÁÍⲿ·þÎñÆ÷api.metrics-trustwallet[.]com¡£¸ÃÓòÃû×¢²áʱ¼ä½öÔçÓÚÊÂÎñÊýÈÕ£¬ÇÒÓë´¹ÂÚÍøÕ¾fix-trustwallet[.]comÓÉͳһע²áÉ̲Ù×÷£¬ÏÔʾ¹¥»÷ÕßÐîıÒѾá£ÊÂÎñ±¬·¢ºó£¬Trust WalletѸËÙÐû²¼ÐÞ¸´°æ±¾2.69£¬²¢½¨ÒéÓû§Á¬Ã¦¸üС£¹Ù·½È·ÈϽöChromeÀ©Õ¹³ÌÐò2.68.0ÊÜÓ°Ï죬Òƶ¯¶Ë¼°ÆäËûä¯ÀÀÆ÷°æ±¾Çå¾²¡£Óë´Ëͬʱ£¬ÍþвÐÐΪÕßʹÓÿֻÅÇéÐ÷Ìᳫ´¹ÂÚ¹¥»÷£¬Í¨¹ýfix-trustwallet[.]comµÈαÔìÍøÕ¾ÓÕµ¼Óû§ÊäÈëÖú¼Ç´Ê£¬½øÒ»²½ÍµÈ¡×ʽð¡£Çå¾²ÆÊÎöʦAkinatorÖÒÑÔ£¬¹¥»÷´úÂëαװ³É¡°ÆÊÎö¹¤¾ß¡±£¬ÔÚÓû§µ¼ÈëÖú¼Ç´Êʱ´¥·¢Êý¾Ýй¶¡£


https://www.bleepingcomputer.com/news/security/trust-wallet-confirms-extension-hack-led-to-7-million-crypto-theft/


6. Sax»á¼ÆËùÊý¾Ýй¶18¸öÔºó֪ͨ22.8ÍòÊÜÓ°ÏìÕß


12ÔÂ26ÈÕ£¬ÃÀ¹úÐÂÔóÎ÷ÖÝ»á¼ÆÊÂÎñËùSax 2024Äê7ÔÂÏÂÑ®ÔâÓöÊý¾Ýй¶£¬Ò»Öܺó·¢Ã÷ϵͳ±£´æÎ´¾­ÊÚȨÔ˶¯¡£ÁîÈËÕ𾪵ÄÊÇ£¬ÊÜÓ°ÏìÕßÖ±ÖÁ2025Äê12ÔÂ1ÈÕÊӲ쿢Ê¡¢¾àÀëÊÂÎñ·¢Ã÷Òѽü18¸öԺ󣬲ŵÃ֪СÎÒ˽¼ÒÐÅϢй¶¡£¾ÝSaxÏòÃåÒòÖÝ×ÜÉó²é³¤Åû¶µÄÐÅÏ¢£¬´Ë´ÎÊÂÎñÓ°Ï쳬22.8ÍòÈË£¬Éæ¼°¿Í»§¼°¸ß¾»ÖµÈËÊ¿µÄСÎÒ˽¼ÒÐÅÏ¢¡£SaxÔÚÊý¾Ýй¶֪ͨÖÐÇ¿µ÷£¬ÊÂÎñ±¬·¢ºó¹«Ë¾Á¬Ã¦½ÓÄɲ½·¥°ü¹ÜϵͳÇå¾²£¬²¢Æô¶¯ÊÓ²ìÒÔÈ·¶¨ÊÂÎñÐÔ×ÓÓë¹æÄ£¡£¹«Ë¾Ô¼ÇëÍøÂçÇ徲ר¼ÒЭÖúÊӲ죬²¢Î¯ÍеÚÈý·½Éó²éй¶Êý¾Ý¡£¹«Ë¾ËäÉù³Æ¡°ÎÞÖ¤¾ÝÅú×¢±£´æÏÖʵ»òÍýÏëÀÄÓÃÐÅÏ¢µÄÐÐΪ¡±£¬µ«18¸öÔµÄÑÓ³Ù֪ͨÈÔÈÃÊÜÓ°ÏìÕßÄÑÒÔÔÚµÚһʱ¼ä½ÓÄÉÑÚ»¤²½·¥£¬Èç¶³½áÐÅÓá¢¼à¿ØÒì³£Ô˶¯µÈ£¬Ê±´ú¹¥»÷ÕßÓи»×ãʱ¼äʹÓÃÇÔÊØÐÅϢʵÑé²»·¨ÐÐΪ¡£ÎªÌî²¹Ëðʧ£¬SaxΪÊÜÓ°ÏìÕßÌṩ12¸öÔÂÃâ·ÑÐÅÓúͰµÍø¼à¿Ø·þÎñ£¬ÒÔ¼°Éí·Ý»Ö¸´ºÍÐÅÓÃÑÚ»¤·þÎñ¡£


https://cybernews.com/security/sax-data-breach-quarter-million-exposed/