²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶

Ðû²¼Ê±¼ä 2025-09-12

1. ²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶


9ÔÂ10ÈÕ£¬£¬£¬£¬ £¬£¬²®Ã÷º²¶¼îì¸ñÀ¼ÆæÖÐѧ½üÆÚ±¬·¢Ò»ÆðÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ £¬£¬Ó°Ïì7ÖÁ11Äê¼¶£¨11-16Ë꣩Êý°ÙÃûѧÉú¡£¡£¡£¡£¡£¾ÝѧУÏò¼Ò³¤·¢Ë͵ÄÓʼþ¼°ºóÐøÉùÃ÷£¬£¬£¬£¬ £¬£¬Ð¹Â¶Ô´ÓÚÒ»·Ý°üÀ¨Ñ§ÉúÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ¼°âïÊÑÁªÏµ·½·¨µÄµç×Ó±í¸ñ±»¹ýʧ¹²Ïí¡£¡£¡£¡£¡£¸Ã±í¸ñ±¾ÓÃÓÚÁ÷¸ÐÒßÃç½ÓÖÖÔÞ³ÉÁ÷³Ì£¬£¬£¬£¬ £¬£¬µ«¼Ò³¤µã»÷ÓʼþÁ´½Óºó¿ÉÖ±½ÓÏÂÔØ£¬£¬£¬£¬ £¬£¬µ¼ÖÂÃô¸ÐÐÅϢ̻¶¡£¡£¡£¡£¡£ÊÂÎñ±¬·¢ÓÚÍâµØÊ±¼ä9ÔÂ8ÈÕ9:50ÖÁ9:59ʱ´ú£¬£¬£¬£¬ £¬£¬½öÄÜͨ¹ýѧУBromcomÄÚÁªÍø»á¼û¸Ã±í¸ñµÄÖ°Ô±¿É¼û¡£¡£¡£¡£¡£¾ÝÕþ¸®Í³¼Æ£¬£¬£¬£¬ £¬£¬¸ÃУ¹²ÓÐ1198ÃûѧÉú£¬£¬£¬£¬ £¬£¬µ«´Ë´Îй¶ÏêÏ¸Éæ¼°7-11Ä꼶ѧÉúÊý¾Ý¡£¡£¡£¡£¡£Êܺ¦¼Ò³¤·´Ó¦£¬£¬£¬£¬ £¬£¬µç×Ó±í¸ñ¼Í¼ÁË"Õû¸öѧУµÄÐÅÏ¢"£¬£¬£¬£¬ £¬£¬Òý·¢¶Ôº¢×ÓÉí·Ý͵ÇÔ¡¢Õ©Æ­µÈÇ徲Σº¦µÄµ£ÐÄ¡£¡£¡£¡£¡£Ñ§Ð£ÔÚÉùÃ÷ÖÐÌåÏÖÒѽÓÄɽôÆÈ²½·¥£ºÁ¬Ã¦ÁªÏµÖÎÀíÐÅϢϵͳ£¨MIS£©ÌṩÉ̳·»Ø²¢É¾³ýй¶ÐÅÏ¢£¬£¬£¬£¬ £¬£¬ÒªÇóÊÕµ½±í¸ñµÄ¼Ò³¤¾¡¿ìɾ³ýÊý¾Ý£¬£¬£¬£¬ £¬£¬²¢ÏòÐÅÍÐÊý¾Ý±£»£»£»£»£»£»¤¹Ù±¨¸æÊÂÎñ¡£¡£¡£¡£¡£Êý¾Ý±£»£»£»£»£»£»¤¹ÙÕýÊÓ²ìÎ¥¹æÏ¸½Ú£¬£¬£¬£¬ £¬£¬ÐëҪʱ½«ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬£¬£¬£¬ £¬£¬Í¬Ê±Öƶ©Ô¤·À²½·¥×èÖ¹ÀàËÆÊÂÎñ¸´·¢¡£¡£¡£¡£¡£


https://www.theregister.com/2025/09/10/birmingham_school_data_blunder/


2. AsyncRATʹÓÃConnectWise ScreenConnectÇÔȡƾ֤ºÍ¼ÓÃÜÇ®±Ò


9ÔÂ11ÈÕ£¬£¬£¬£¬ £¬£¬ÍøÂçÇå¾²¹«Ë¾LevelBlueÅû¶ÁËÒ»ÆðʹÓÃÕýµ±Ô¶³ÌÖÎÀí¹¤¾ßConnectWise ScreenConnectÌᳫµÄ¸ß½×ÎÞÎļþ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¸Ã¹¥»÷̫ͨ¹ý½×¶Î¾ç±¾Ö´ÐУ¬£¬£¬£¬ £¬£¬×îÖÕ°²ÅÅAsyncRATÔ¶³Ì»á¼ûľÂí£¬£¬£¬£¬ £¬£¬ÊµÏÖÃô¸ÐÊý¾ÝÇÔÈ¡Ó볤ÆÚ»¯¿ØÖÆ¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓô¹ÂÚÓʼþαװ³É²ÆÎñ/ÉÌÒµÎļþ£¬£¬£¬£¬ £¬£¬ÓÕµ¼Êܺ¦ÕßÏÂÔØ±»Ä¾ÂíѬȾµÄScreenConnect×°ÖóÌÐò¡£¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýScreenConnect»ñȡԶ³Ì»á¼ûȨÏÞ£¬£¬£¬£¬ £¬£¬²¢Æô¶¯¼üÅ̼ͼ»î¶¯Ö´ÐÐVBScriptÓÐÓøºÔØ¡£¡£¡£¡£¡£¸Ã¾ç±¾Í¨¹ýPowerShell´Ó¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷ÏÂÔØÁ½¸öÍâ²¿ÔØºÉ£º"logs.ldk"£¨DLLÎļþ£©ºÍ"logs.ldr"£¨»ìÏý×é¼þ£©¡£¡£¡£¡£¡£DLLÎļþÈÏÕæ½«VB¾ç±¾Ð´Èë´ÅÅÌ£¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃÍýÏëʹÃüαװ³É"Skype¸üгÌÐò"£¬£¬£¬£¬ £¬£¬ÔÚÿ´ÎϵͳµÇ¼ʱ×Ô¶¯Ö´ÐУ¬£¬£¬£¬ £¬£¬ÊµÏÖÒþ²Ø³¤ÆÚ»¯¡£¡£¡£¡£¡£½øÒ»²½ÆÊÎöÏÔʾ£¬£¬£¬£¬ £¬£¬PowerShell¾ç±¾½«"logs.ldk"¼ÓÔØÎª.NET³ÌÐò¼¯£¬£¬£¬£¬ £¬£¬²¢´«Èë"logs.ldr"×÷Ϊ²ÎÊý£¬£¬£¬£¬ £¬£¬×îÖÕÖ´ÐÐAsyncRATµÄ½¹µãÓÐÓøºÔØ"AsyncClient.exe"¡£¡£¡£¡£¡£¸ÃľÂí¾ß±¸¶àÏî¸ßΣ¹¦Ð§£º¼Í¼»÷¼ü¡¢ÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢ÊÕÂÞÏµÍ³Ö¸ÎÆ¡¢É¨Ãè¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬ £¬£¬²¢Í¨¹ýTCPÌ×½Ó×Ö½«Êý¾Ý»Ø´«ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£¡£


https://thehackernews.com/2025/09/asyncrat-exploits-connectwise.html


3. Vyro AIÊý¾Ýй¶£¬£¬£¬£¬ £¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì


9ÔÂ10ÈÕ£¬£¬£¬£¬ £¬£¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬ £¬£¬°Í»ù˹̹AI¹«Ë¾Vyro AIÒòδÊܱ£»£»£»£»£»£»¤µÄElasticsearchʵÀýй¶116GBÓû§ÈÕÖ¾£¬£¬£¬£¬ £¬£¬Éæ¼°Èý¿îÈÈÃÅÓ¦ÓãºGoogle PlayÏÂÔØÁ¿³¬1000Íò´ÎµÄImagineArt¡¢³¬10Íò´ÎÏÂÔØµÄChatly¼°Ô»á¼ûÔ¼5Íò´ÎµÄChatbotx¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ðû³Æ×ÜÏÂÔØÁ¿³¬1.5ÒڴΣ¬£¬£¬£¬ £¬£¬Ã¿ÖÜÌìÉú350ÍòÕÅͼƬ¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ýº­¸Ç2-7ÌìµÄÉú²úÓ뿪·¢ÈÕÖ¾£¬£¬£¬£¬ £¬£¬°üÀ¨Óû§AIÌáÐÑ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢Óû§ÊðÀíµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â×Ô2ÔÂÖÐÑ®±»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬£¬£¬£¬ £¬£¬¿ÉÄÜÒѱ»¹¥»÷Õß·¢Ã÷ÊýÔ¡£¡£¡£¡£¡£´Ë´Îй¶Σº¦ÏÔÖø£º¹¥»÷Õß¿ÉʹÓÃÁîÅÆÐ®ÖÆÓû§ÕË»§£¬£¬£¬£¬ £¬£¬»á¼û̸Ìì¼Í¼¡¢ÌìÉúͼÏñ£¬£¬£¬£¬ £¬£¬ÉõÖÁÀÄÓÃAI´ú±Ò¾ÙÐв»·¨ÉúÒ⣻£»£»£»£»£»Óû§ÓëAIµÄ˽ÃܶԻ°¿ÉÄÜ̻¶´Óδ¹ûÕæµÄÃô¸ÐÄÚÈÝ¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬ £¬£¬ImagineArtµÄ3000Íò»îÔ¾Óû§Êý¾ÝÈô±»Ê¹Ó㬣¬£¬£¬ £¬£¬½«µ¼Ö´ó¹æÄ£ÕË»§½ÓÊÜΣº¦¡£¡£¡£¡£¡£


https://cybernews.com/security/ai-chatbots-vyro-data-leak/


4. Allegis GroupÔâEverestÀÕË÷¹¥»÷£¬£¬£¬£¬ £¬£¬°ÙÍò¼¶¿Í»§Êý¾Ýй¶


9ÔÂ10ÈÕ£¬£¬£¬£¬ £¬£¬È«Çò×î´óÈ˲ÅÖÎÀí¼¯ÍÅÖ®Ò»¡¢ÄêÊÕÈë½ü100ÒÚÃÀÔªµÄAllegis Group¿ËÈÕÔâÓöEverestÀÕË÷Èí¼þÍŻ﹥»÷¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÉÏÐû³Æ»ñÈ¡ÁËAllegisÄÚ²¿Îļþ¼°¿Í»§Ãûµ¥£¬£¬£¬£¬ £¬£¬²¢Ðû²¼Á½ÕÅExcelÎĵµ½ØÍ¼×÷Ϊ֤¾Ý£¬£¬£¬£¬ £¬£¬ÆäÖÐÒ»ÕŰüÀ¨13.5ÍòÌõ¿Í»§ÐÅÏ¢£ºÐÕÃû¡¢ÓÊÏä¡¢µç»°£¬£¬£¬£¬ £¬£¬ÁíÒ»ÕŰüÀ¨¶à´ï42.6ÍòÌõÀàËÆÊý¾Ý¡£¡£¡£¡£¡£´ËÀàÐÅÏ¢¿ÉÄܱ»Ê¹ÓþÙÐÐÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£EverestÍÅ»ïÓë¶íÂÞ˹¹ØÁª£¬£¬£¬£¬ £¬£¬×Ô2021Äê»îÔ¾ÒÔÀ´ÒѳÉΪ×î·Å×ݵÄÀÕË÷×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¾Ý°µÍø¼à¿Ø¹¤¾ßRansomlookerͳ¼Æ£¬£¬£¬£¬ £¬£¬¸ÃÍÅ»ïÒÑÍù12¸öÔ¹¥»÷Á˳¬°Ù¸ö×éÖ¯£¬£¬£¬£¬ £¬£¬·ÖÅúй¶Êý¾ÝÊÇÆäµä·¶Ê©Ñ¹ÊֶΣ¬£¬£¬£¬ £¬£¬Ö¼ÔÚÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£AllegisÆìÏÂÓµÓÐAerotek¡¢TEKsystems¡¢MarketSourceµÈ¶à¼ÒרҵÈ˲ÅÖÎÀí×Ó¹«Ë¾£¬£¬£¬£¬ £¬£¬Ð§ÀÍÍøÂçÁýÕÖÈ«Çò¡£¡£¡£¡£¡£Ö»¹Ü¹«Ë¾ÒÑ»ØÓ¦³Æ½«¸üÐÂÏ£Íû£¬£¬£¬£¬ £¬£¬µ«¹¥»÷ÕßÌá¼°µÄ¡°ÖÖÀà·±¶àµÄСÎÒ˽¼ÒÎĵµ¡±ÉÐδ¹ûÕæÑù±¾£¬£¬£¬£¬ £¬£¬Ç±ÔÚΣº¦¿ÉÄÜÔ¶³¬ÒÑÆØ¹âµÄÁªÏµÐÅÏ¢¡£¡£¡£¡£¡£


https://cybernews.com/security/allegis-group-data-breach-claims/


5. AkiraÀÕË÷Èí¼þÍÅ»ïʹÓÃSonicWallÎó²îÌᳫÐÂÒ»ÂÖ¹¥»÷


9ÔÂ11ÈÕ£¬£¬£¬£¬ £¬£¬AkiraÀÕË÷Èí¼þÍÅ»ïÕýÆð¾¢Ê¹ÓÃCVE-2024-40766ÕâÒ»Òѱ£´æÒ»ÄêµÄÑÏÖØ»á¼û¿ØÖÆÎó²î£¬£¬£¬£¬ £¬£¬¶ÔδÐÞ²¹µÄSonicWall SSL VPN×°±¸Ìᳫ¹¥»÷¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾­ÊÚȨµÄ×ÊÔ´»á¼û£¬£¬£¬£¬ £¬£¬ÉõÖÁ¿ÉÄܵ¼Ö·À»ðǽÍ߽⡣¡£¡£¡£¡£SonicWallÔçÔÚ2024Äê8Ô±ãÐû²¼Á˲¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬£¬²¢Ç¿µ÷¸üÐÂʱÐèΪÍâµØÖÎÀíµÄSSLVPNÕË»§Óû§ÖØÖÃÃÜÂ룬£¬£¬£¬ £¬£¬µ«²¿·Ö×é֯δ³¹µ×Ö´Ðе÷½â²½·¥£¬£¬£¬£¬ £¬£¬µ¼ÖÂÍþвÐÐΪÕßÈÔÄÜʹÓÃ̻¶µÄƾ֤ÉèÖöàÒòËØÉí·ÝÑéÖ¤£¨MFA£©»ò»ùÓÚʱ¼äµÄÒ»´ÎÐÔÃÜÂ루TOTP£©ÏµÍ³£¬£¬£¬£¬ £¬£¬½ø¶ø»ñÈ¡»á¼ûȨÏÞ¡£¡£¡£¡£¡£°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©ÓÚ2025Äê9Ô·¢³ö¾¯±¨£¬£¬£¬£¬ £¬£¬Ö¸³ö°Ä´óÀûÑǾ³ÄÚÕë¶Ô¸ÃÎó²îµÄ×Ô¶¯Ê¹ÓûÏÔÖøÔöÌí£¬£¬£¬£¬ £¬£¬²¢Ã÷È·½«AkiraÀÕË÷Èí¼þÓëSonicWall SSL VPN¹¥»÷¹ØÁª¡£¡£¡£¡£¡£ÍøÂçÇå¾²¹«Ë¾Rapid7Ò²ÊӲ쵽ÀàËÆÇ÷ÊÆ£¬£¬£¬£¬ £¬£¬ÒÔΪ¹¥»÷¼¤Ôö¿ÉÄÜÓë²»ÍêÕûµÄµ÷½â²½·¥Óйأ¬£¬£¬£¬ £¬£¬ÏêϸÈëÇÖÊֶΰüÀ¨Ê¹ÓÃĬÈÏÓû§×éµÄÆÕ±é»á¼ûȨÏÞ¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬ £¬£¬ÒÔ¼°Í¨¹ýSonicWall×°±¸ÉÏÐéÄâ°ì¹«ÊÒÃÅ»§µÄĬÈϹ«¹²»á¼ûȨÏÞʵÑé¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/


6. LNERµÚÈý·½¹©Ó¦ÉÌÔâÍøÂç¹¥»÷ÖÂÂÿÍÊý¾Ýй¶


9ÔÂ11ÈÕ£¬£¬£¬£¬ £¬£¬Ó¢¹úÁгµÔËÓªÉÌÂ׶ض«±±Ìú·¹«Ë¾£¨LNER£©ÓÚ9ÔÂ10ÈÕÈ·ÈÏ£¬£¬£¬£¬ £¬£¬ÆäµÚÈý·½¹©Ó¦ÉÌÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬µ¼Ö²¿·ÖÂÿ͵ÄÁªÏµ·½·¨¼°¹ýÍùÐгÌÊý¾Ýй¶£¬£¬£¬£¬ £¬£¬µ«Î´Éæ¼°²ÆÎñÐÅÏ¢¡¢ÃÜÂë»òÖ§¸¶¿¨Êý¾Ý¡£¡£¡£¡£¡£LNERÇ¿µ÷£¬£¬£¬£¬ £¬£¬ÆäÁгµÐ§ÀÍ¡¢ÊÛÆ±ÏµÍ³ÊµÊ±¿Ì±í¾ùÕý³£ÔËÐУ¬£¬£¬£¬ £¬£¬²¢ÒÑÓëÍøÂçÇ徲ר¼ÒºÍÏà¹Ø¹©Ó¦ÉÌÏàÖúÊÓ²ìÊÂÎñȫò£¬£¬£¬£¬ £¬£¬Í¬Ê±ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒÒÔÆÀ¹ÀÊÇ·ñÇкϡ¶Í¨ÓÃÊý¾Ý±£»£»£»£»£»£»¤ÌõÀý¡·£¨GDPR£©µÄ±¨¸æÒªÇ󣬣¬£¬£¬ £¬£¬Èô°ü¹Ü²½·¥È±·¦¿ÉÄÜÃæÁÙ·£¿£¿£¿î¡£¡£¡£¡£¡£Ð¹Â¶µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÄܱ»ÓÃÓÚ¹¹½¨ÏêϸСÎÒ˽¼Ò»­Ïñ£¬£¬£¬£¬ £¬£¬½ø¶øÌᳫ´¹ÂÚ¹¥»÷£¬£¬£¬£¬ £¬£¬Èçͨ¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òWhatsAppÓÕÆ­Óû§Ìṩ²ÆÎñ»òСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£LNERÒѱ޲ßÂÿͶÔÒâÍâͨѶ¼á³ÖСÐÄ£¬£¬£¬£¬ £¬£¬ÓÈÆäÉæ¼°Ð¡ÎÒ˽¼ÒÐÅÏ¢ÇëÇóµÄÓʼþ»òÐÅÏ¢£¬£¬£¬£¬ £¬£¬ÇÐÎðÈÝÒ׻ظ´¡£¡£¡£¡£¡£¹«Ë¾ÌåÏÖ½«¸ß¶ÈÖØÊÓ´ËÊ£¬£¬£¬£¬ £¬£¬Ò»Á¬Óëר¼ÒÏàÖú²¢½ÓÄɰü¹Ü²½·¥£¬£¬£¬£¬ £¬£¬ºóÐø½«Ìṩ¸ü¶à¸üÐÂÐÅÏ¢¡£¡£¡£¡£¡£


https://hackread.com/uk-rail-operator-lner-cyber-attack-passenger-data/