²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶
Ðû²¼Ê±¼ä 2025-09-121. ²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶
9ÔÂ10ÈÕ£¬£¬£¬£¬£¬²®Ã÷º²¶¼îì¸ñÀ¼ÆæÖÐѧ½üÆÚ±¬·¢Ò»ÆðÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Ó°Ïì7ÖÁ11Äê¼¶£¨11-16Ë꣩Êý°ÙÃûѧÉú¡£¡£¡£¡£¾ÝѧУÏò¼Ò³¤·¢Ë͵ÄÓʼþ¼°ºóÐøÉùÃ÷£¬£¬£¬£¬£¬Ð¹Â¶Ô´ÓÚÒ»·Ý°üÀ¨Ñ§ÉúÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ¼°âïÊÑÁªÏµ·½·¨µÄµç×Ó±í¸ñ±»¹ýʧ¹²Ïí¡£¡£¡£¡£¸Ã±í¸ñ±¾ÓÃÓÚÁ÷¸ÐÒßÃç½ÓÖÖÔÞ³ÉÁ÷³Ì£¬£¬£¬£¬£¬µ«¼Ò³¤µã»÷ÓʼþÁ´½Óºó¿ÉÖ±½ÓÏÂÔØ£¬£¬£¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢ̻¶¡£¡£¡£¡£ÊÂÎñ±¬·¢ÓÚÍâµØÊ±¼ä9ÔÂ8ÈÕ9:50ÖÁ9:59ʱ´ú£¬£¬£¬£¬£¬½öÄÜͨ¹ýѧУBromcomÄÚÁªÍø»á¼û¸Ã±í¸ñµÄÖ°Ô±¿É¼û¡£¡£¡£¡£¾ÝÕþ¸®Í³¼Æ£¬£¬£¬£¬£¬¸ÃУ¹²ÓÐ1198ÃûѧÉú£¬£¬£¬£¬£¬µ«´Ë´Îй¶ÏêÏ¸Éæ¼°7-11Ä꼶ѧÉúÊý¾Ý¡£¡£¡£¡£Êܺ¦¼Ò³¤·´Ó¦£¬£¬£¬£¬£¬µç×Ó±í¸ñ¼Í¼ÁË"Õû¸öѧУµÄÐÅÏ¢"£¬£¬£¬£¬£¬Òý·¢¶Ôº¢×ÓÉí·Ý͵ÇÔ¡¢Õ©ÆµÈÇ徲Σº¦µÄµ£ÐÄ¡£¡£¡£¡£Ñ§Ð£ÔÚÉùÃ÷ÖÐÌåÏÖÒѽÓÄɽôÆÈ²½·¥£ºÁ¬Ã¦ÁªÏµÖÎÀíÐÅϢϵͳ£¨MIS£©ÌṩÉ̳·»Ø²¢É¾³ýй¶ÐÅÏ¢£¬£¬£¬£¬£¬ÒªÇóÊÕµ½±í¸ñµÄ¼Ò³¤¾¡¿ìɾ³ýÊý¾Ý£¬£¬£¬£¬£¬²¢ÏòÐÅÍÐÊý¾Ý±£»£»£»£»£»£»£»¤¹Ù±¨¸æÊÂÎñ¡£¡£¡£¡£Êý¾Ý±£»£»£»£»£»£»£»¤¹ÙÕýÊÓ²ìÎ¥¹æÏ¸½Ú£¬£¬£¬£¬£¬ÐëҪʱ½«ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬£¬£¬£¬£¬Í¬Ê±Öƶ©Ô¤·À²½·¥×èÖ¹ÀàËÆÊÂÎñ¸´·¢¡£¡£¡£¡£
https://www.theregister.com/2025/09/10/birmingham_school_data_blunder/
2. AsyncRATʹÓÃConnectWise ScreenConnectÇÔȡƾ֤ºÍ¼ÓÃÜÇ®±Ò
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾LevelBlueÅû¶ÁËÒ»ÆðʹÓÃÕýµ±Ô¶³ÌÖÎÀí¹¤¾ßConnectWise ScreenConnectÌᳫµÄ¸ß½×ÎÞÎļþ¹¥»÷»î¶¯¡£¡£¡£¡£¸Ã¹¥»÷̫ͨ¹ý½×¶Î¾ç±¾Ö´ÐУ¬£¬£¬£¬£¬×îÖÕ°²ÅÅAsyncRATÔ¶³Ì»á¼ûľÂí£¬£¬£¬£¬£¬ÊµÏÖÃô¸ÐÊý¾ÝÇÔÈ¡Ó볤ÆÚ»¯¿ØÖÆ¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓô¹ÂÚÓʼþαװ³É²ÆÎñ/ÉÌÒµÎļþ£¬£¬£¬£¬£¬ÓÕµ¼Êܺ¦ÕßÏÂÔØ±»Ä¾ÂíѬȾµÄScreenConnect×°ÖóÌÐò¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬£¬£¬¹¥»÷Õßͨ¹ýScreenConnect»ñȡԶ³Ì»á¼ûȨÏÞ£¬£¬£¬£¬£¬²¢Æô¶¯¼üÅ̼ͼ»î¶¯Ö´ÐÐVBScriptÓÐÓøºÔØ¡£¡£¡£¡£¸Ã¾ç±¾Í¨¹ýPowerShell´Ó¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷ÏÂÔØÁ½¸öÍâ²¿ÔØºÉ£º"logs.ldk"£¨DLLÎļþ£©ºÍ"logs.ldr"£¨»ìÏý×é¼þ£©¡£¡£¡£¡£DLLÎļþÈÏÕæ½«VB¾ç±¾Ð´Èë´ÅÅÌ£¬£¬£¬£¬£¬²¢Ê¹ÓÃÍýÏëʹÃüαװ³É"Skype¸üгÌÐò"£¬£¬£¬£¬£¬ÔÚÿ´ÎϵͳµÇ¼ʱ×Ô¶¯Ö´ÐУ¬£¬£¬£¬£¬ÊµÏÖÒþ²Ø³¤ÆÚ»¯¡£¡£¡£¡£½øÒ»²½ÆÊÎöÏÔʾ£¬£¬£¬£¬£¬PowerShell¾ç±¾½«"logs.ldk"¼ÓÔØÎª.NET³ÌÐò¼¯£¬£¬£¬£¬£¬²¢´«Èë"logs.ldr"×÷Ϊ²ÎÊý£¬£¬£¬£¬£¬×îÖÕÖ´ÐÐAsyncRATµÄ½¹µãÓÐÓøºÔØ"AsyncClient.exe"¡£¡£¡£¡£¸ÃľÂí¾ß±¸¶àÏî¸ßΣ¹¦Ð§£º¼Í¼»÷¼ü¡¢ÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢ÊÕÂÞÏµÍ³Ö¸ÎÆ¡¢É¨Ãè¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬£¬²¢Í¨¹ýTCPÌ×½Ó×Ö½«Êý¾Ý»Ø´«ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£
https://thehackernews.com/2025/09/asyncrat-exploits-connectwise.html
3. Vyro AIÊý¾Ýй¶£¬£¬£¬£¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì
9ÔÂ10ÈÕ£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬°Í»ù˹̹AI¹«Ë¾Vyro AIÒòδÊܱ£»£»£»£»£»£»£»¤µÄElasticsearchʵÀýй¶116GBÓû§ÈÕÖ¾£¬£¬£¬£¬£¬Éæ¼°Èý¿îÈÈÃÅÓ¦ÓãºGoogle PlayÏÂÔØÁ¿³¬1000Íò´ÎµÄImagineArt¡¢³¬10Íò´ÎÏÂÔØµÄChatly¼°Ô»á¼ûÔ¼5Íò´ÎµÄChatbotx¡£¡£¡£¡£¸Ã¹«Ë¾Ðû³Æ×ÜÏÂÔØÁ¿³¬1.5ÒڴΣ¬£¬£¬£¬£¬Ã¿ÖÜÌìÉú350ÍòÕÅͼƬ¡£¡£¡£¡£Ð¹Â¶Êý¾Ýº¸Ç2-7ÌìµÄÉú²úÓ뿪·¢ÈÕÖ¾£¬£¬£¬£¬£¬°üÀ¨Óû§AIÌáÐÑ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢Óû§ÊðÀíµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¸ÃÊý¾Ý¿â×Ô2ÔÂÖÐÑ®±»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬£¬£¬£¬£¬¿ÉÄÜÒѱ»¹¥»÷Õß·¢Ã÷ÊýÔ¡£¡£¡£¡£´Ë´Îй¶Σº¦ÏÔÖø£º¹¥»÷Õß¿ÉʹÓÃÁîÅÆÐ®ÖÆÓû§ÕË»§£¬£¬£¬£¬£¬»á¼û̸Ìì¼Í¼¡¢ÌìÉúͼÏñ£¬£¬£¬£¬£¬ÉõÖÁÀÄÓÃAI´ú±Ò¾ÙÐв»·¨ÉúÒ⣻£»£»£»£»£»£»Óû§ÓëAIµÄ˽ÃܶԻ°¿ÉÄÜ̻¶´Óδ¹ûÕæµÄÃô¸ÐÄÚÈÝ¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬ImagineArtµÄ3000Íò»îÔ¾Óû§Êý¾ÝÈô±»Ê¹Ó㬣¬£¬£¬£¬½«µ¼Ö´ó¹æÄ£ÕË»§½ÓÊÜΣº¦¡£¡£¡£¡£
https://cybernews.com/security/ai-chatbots-vyro-data-leak/
4. Allegis GroupÔâEverestÀÕË÷¹¥»÷£¬£¬£¬£¬£¬°ÙÍò¼¶¿Í»§Êý¾Ýй¶
9ÔÂ10ÈÕ£¬£¬£¬£¬£¬È«Çò×î´óÈ˲ÅÖÎÀí¼¯ÍÅÖ®Ò»¡¢ÄêÊÕÈë½ü100ÒÚÃÀÔªµÄAllegis Group¿ËÈÕÔâÓöEverestÀÕË÷Èí¼þÍŻ﹥»÷¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÉÏÐû³Æ»ñÈ¡ÁËAllegisÄÚ²¿Îļþ¼°¿Í»§Ãûµ¥£¬£¬£¬£¬£¬²¢Ðû²¼Á½ÕÅExcelÎĵµ½ØÍ¼×÷Ϊ֤¾Ý£¬£¬£¬£¬£¬ÆäÖÐÒ»ÕŰüÀ¨13.5ÍòÌõ¿Í»§ÐÅÏ¢£ºÐÕÃû¡¢ÓÊÏä¡¢µç»°£¬£¬£¬£¬£¬ÁíÒ»ÕŰüÀ¨¶à´ï42.6ÍòÌõÀàËÆÊý¾Ý¡£¡£¡£¡£´ËÀàÐÅÏ¢¿ÉÄܱ»Ê¹ÓþÙÐÐÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£EverestÍÅ»ïÓë¶íÂÞ˹¹ØÁª£¬£¬£¬£¬£¬×Ô2021Äê»îÔ¾ÒÔÀ´ÒѳÉΪ×î·Å×ݵÄÀÕË÷×éÖ¯Ö®Ò»¡£¡£¡£¡£¾Ý°µÍø¼à¿Ø¹¤¾ßRansomlookerͳ¼Æ£¬£¬£¬£¬£¬¸ÃÍÅ»ïÒÑÍù12¸öÔ¹¥»÷Á˳¬°Ù¸ö×éÖ¯£¬£¬£¬£¬£¬·ÖÅúй¶Êý¾ÝÊÇÆäµä·¶Ê©Ñ¹ÊֶΣ¬£¬£¬£¬£¬Ö¼ÔÚÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£AllegisÆìÏÂÓµÓÐAerotek¡¢TEKsystems¡¢MarketSourceµÈ¶à¼ÒרҵÈ˲ÅÖÎÀí×Ó¹«Ë¾£¬£¬£¬£¬£¬Ð§ÀÍÍøÂçÁýÕÖÈ«Çò¡£¡£¡£¡£Ö»¹Ü¹«Ë¾ÒÑ»ØÓ¦³Æ½«¸üÐÂÏ£Íû£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÌá¼°µÄ¡°ÖÖÀà·±¶àµÄСÎÒ˽¼ÒÎĵµ¡±ÉÐδ¹ûÕæÑù±¾£¬£¬£¬£¬£¬Ç±ÔÚΣº¦¿ÉÄÜÔ¶³¬ÒÑÆØ¹âµÄÁªÏµÐÅÏ¢¡£¡£¡£¡£
https://cybernews.com/security/allegis-group-data-breach-claims/
5. AkiraÀÕË÷Èí¼þÍÅ»ïʹÓÃSonicWallÎó²îÌᳫÐÂÒ»ÂÖ¹¥»÷
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬AkiraÀÕË÷Èí¼þÍÅ»ïÕýÆð¾¢Ê¹ÓÃCVE-2024-40766ÕâÒ»Òѱ£´æÒ»ÄêµÄÑÏÖØ»á¼û¿ØÖÆÎó²î£¬£¬£¬£¬£¬¶ÔδÐÞ²¹µÄSonicWall SSL VPN×°±¸Ìᳫ¹¥»÷¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾ÊÚȨµÄ×ÊÔ´»á¼û£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÄܵ¼Ö·À»ðǽÍ߽⡣¡£¡£¡£SonicWallÔçÔÚ2024Äê8Ô±ãÐû²¼Á˲¹¶¡£¡£¡£¡£¬£¬£¬£¬£¬²¢Ç¿µ÷¸üÐÂʱÐèΪÍâµØÖÎÀíµÄSSLVPNÕË»§Óû§ÖØÖÃÃÜÂ룬£¬£¬£¬£¬µ«²¿·Ö×é֯δ³¹µ×Ö´Ðе÷½â²½·¥£¬£¬£¬£¬£¬µ¼ÖÂÍþвÐÐΪÕßÈÔÄÜʹÓÃ̻¶µÄƾ֤ÉèÖöàÒòËØÉí·ÝÑéÖ¤£¨MFA£©»ò»ùÓÚʱ¼äµÄÒ»´ÎÐÔÃÜÂ루TOTP£©ÏµÍ³£¬£¬£¬£¬£¬½ø¶ø»ñÈ¡»á¼ûȨÏÞ¡£¡£¡£¡£°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©ÓÚ2025Äê9Ô·¢³ö¾¯±¨£¬£¬£¬£¬£¬Ö¸³ö°Ä´óÀûÑǾ³ÄÚÕë¶Ô¸ÃÎó²îµÄ×Ô¶¯Ê¹ÓûÏÔÖøÔöÌí£¬£¬£¬£¬£¬²¢Ã÷È·½«AkiraÀÕË÷Èí¼þÓëSonicWall SSL VPN¹¥»÷¹ØÁª¡£¡£¡£¡£ÍøÂçÇå¾²¹«Ë¾Rapid7Ò²ÊӲ쵽ÀàËÆÇ÷ÊÆ£¬£¬£¬£¬£¬ÒÔΪ¹¥»÷¼¤Ôö¿ÉÄÜÓë²»ÍêÕûµÄµ÷½â²½·¥Óйأ¬£¬£¬£¬£¬ÏêϸÈëÇÖÊֶΰüÀ¨Ê¹ÓÃĬÈÏÓû§×éµÄÆÕ±é»á¼ûȨÏÞ¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬ÒÔ¼°Í¨¹ýSonicWall×°±¸ÉÏÐéÄâ°ì¹«ÊÒÃÅ»§µÄĬÈϹ«¹²»á¼ûȨÏÞʵÑé¹¥»÷¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/
6. LNERµÚÈý·½¹©Ó¦ÉÌÔâÍøÂç¹¥»÷ÖÂÂÿÍÊý¾Ýй¶
9ÔÂ11ÈÕ£¬£¬£¬£¬£¬Ó¢¹úÁгµÔËÓªÉÌÂ׶ض«±±Ìú·¹«Ë¾£¨LNER£©ÓÚ9ÔÂ10ÈÕÈ·ÈÏ£¬£¬£¬£¬£¬ÆäµÚÈý·½¹©Ó¦ÉÌÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö²¿·ÖÂÿ͵ÄÁªÏµ·½·¨¼°¹ýÍùÐгÌÊý¾Ýй¶£¬£¬£¬£¬£¬µ«Î´Éæ¼°²ÆÎñÐÅÏ¢¡¢ÃÜÂë»òÖ§¸¶¿¨Êý¾Ý¡£¡£¡£¡£LNERÇ¿µ÷£¬£¬£¬£¬£¬ÆäÁгµÐ§ÀÍ¡¢ÊÛÆ±ÏµÍ³ÊµÊ±¿Ì±í¾ùÕý³£ÔËÐУ¬£¬£¬£¬£¬²¢ÒÑÓëÍøÂçÇ徲ר¼ÒºÍÏà¹Ø¹©Ó¦ÉÌÏàÖúÊÓ²ìÊÂÎñȫò£¬£¬£¬£¬£¬Í¬Ê±ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒÒÔÆÀ¹ÀÊÇ·ñÇкϡ¶Í¨ÓÃÊý¾Ý±£»£»£»£»£»£»£»¤ÌõÀý¡·£¨GDPR£©µÄ±¨¸æÒªÇ󣬣¬£¬£¬£¬Èô°ü¹Ü²½·¥È±·¦¿ÉÄÜÃæÁÙ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£Ð¹Â¶µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÄܱ»ÓÃÓÚ¹¹½¨ÏêϸСÎÒ˽¼Ò»Ïñ£¬£¬£¬£¬£¬½ø¶øÌᳫ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬Èçͨ¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òWhatsAppÓÕÆÓû§Ìṩ²ÆÎñ»òСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£LNERÒѱ޲ßÂÿͶÔÒâÍâͨѶ¼á³ÖСÐÄ£¬£¬£¬£¬£¬ÓÈÆäÉæ¼°Ð¡ÎÒ˽¼ÒÐÅÏ¢ÇëÇóµÄÓʼþ»òÐÅÏ¢£¬£¬£¬£¬£¬ÇÐÎðÈÝÒ׻ظ´¡£¡£¡£¡£¹«Ë¾ÌåÏÖ½«¸ß¶ÈÖØÊÓ´ËÊ£¬£¬£¬£¬£¬Ò»Á¬Óëר¼ÒÏàÖú²¢½ÓÄɰü¹Ü²½·¥£¬£¬£¬£¬£¬ºóÐø½«Ìṩ¸ü¶à¸üÐÂÐÅÏ¢¡£¡£¡£¡£
https://hackread.com/uk-rail-operator-lner-cyber-attack-passenger-data/


¾©¹«Íø°²±¸11010802024551ºÅ