²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶

Ðû²¼Ê±¼ä 2025-09-12

1. ²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶


9ÔÂ10ÈÕ£¬ £¬£¬£¬ £¬²®Ã÷º²¶¼îì¸ñÀ¼ÆæÖÐѧ½üÆÚ±¬·¢Ò»ÆðÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬ £¬Ó°Ïì7ÖÁ11Äê¼¶£¨11-16Ë꣩Êý°ÙÃûѧÉú¡£¡£¡£¡£¾ÝѧУÏò¼Ò³¤·¢Ë͵ÄÓʼþ¼°ºóÐøÉùÃ÷£¬ £¬£¬£¬ £¬Ð¹Â¶Ô´ÓÚÒ»·Ý°üÀ¨Ñ§ÉúÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ¼°âïÊÑÁªÏµ·½·¨µÄµç×Ó±í¸ñ±»¹ýʧ¹²Ïí¡£¡£¡£¡£¸Ã±í¸ñ±¾ÓÃÓÚÁ÷¸ÐÒßÃç½ÓÖÖÔÞ³ÉÁ÷³Ì£¬ £¬£¬£¬ £¬µ«¼Ò³¤µã»÷ÓʼþÁ´½Óºó¿ÉÖ±½ÓÏÂÔØ£¬ £¬£¬£¬ £¬µ¼ÖÂÃô¸ÐÐÅϢ̻¶¡£¡£¡£¡£ÊÂÎñ±¬·¢ÓÚÍâµØÊ±¼ä9ÔÂ8ÈÕ9:50ÖÁ9:59ʱ´ú£¬ £¬£¬£¬ £¬½öÄÜͨ¹ýѧУBromcomÄÚÁªÍø»á¼û¸Ã±í¸ñµÄÖ°Ô±¿É¼û¡£¡£¡£¡£¾ÝÕþ¸®Í³¼Æ£¬ £¬£¬£¬ £¬¸ÃУ¹²ÓÐ1198ÃûѧÉú£¬ £¬£¬£¬ £¬µ«´Ë´Îй¶ÏêÏ¸Éæ¼°7-11Ä꼶ѧÉúÊý¾Ý¡£¡£¡£¡£Êܺ¦¼Ò³¤·´Ó¦£¬ £¬£¬£¬ £¬µç×Ó±í¸ñ¼Í¼ÁË"Õû¸öѧУµÄÐÅÏ¢"£¬ £¬£¬£¬ £¬Òý·¢¶Ôº¢×ÓÉí·Ý͵ÇÔ¡¢Õ©Æ­µÈÇ徲Σº¦µÄµ£ÐÄ¡£¡£¡£¡£Ñ§Ð£ÔÚÉùÃ÷ÖÐÌåÏÖÒѽÓÄɽôÆÈ²½·¥£ºÁ¬Ã¦ÁªÏµÖÎÀíÐÅϢϵͳ£¨MIS£©ÌṩÉ̳·»Ø²¢É¾³ýй¶ÐÅÏ¢£¬ £¬£¬£¬ £¬ÒªÇóÊÕµ½±í¸ñµÄ¼Ò³¤¾¡¿ìɾ³ýÊý¾Ý£¬ £¬£¬£¬ £¬²¢ÏòÐÅÍÐÊý¾Ý±£»£»£»£»£»£»£»¤¹Ù±¨¸æÊÂÎñ¡£¡£¡£¡£Êý¾Ý±£»£»£»£»£»£»£»¤¹ÙÕýÊÓ²ìÎ¥¹æÏ¸½Ú£¬ £¬£¬£¬ £¬ÐëҪʱ½«ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬ £¬£¬£¬ £¬Í¬Ê±Öƶ©Ô¤·À²½·¥×èÖ¹ÀàËÆÊÂÎñ¸´·¢¡£¡£¡£¡£


https://www.theregister.com/2025/09/10/birmingham_school_data_blunder/


2. AsyncRATʹÓÃConnectWise ScreenConnectÇÔȡƾ֤ºÍ¼ÓÃÜÇ®±Ò


9ÔÂ11ÈÕ£¬ £¬£¬£¬ £¬ÍøÂçÇå¾²¹«Ë¾LevelBlueÅû¶ÁËÒ»ÆðʹÓÃÕýµ±Ô¶³ÌÖÎÀí¹¤¾ßConnectWise ScreenConnectÌᳫµÄ¸ß½×ÎÞÎļþ¹¥»÷»î¶¯¡£¡£¡£¡£¸Ã¹¥»÷̫ͨ¹ý½×¶Î¾ç±¾Ö´ÐУ¬ £¬£¬£¬ £¬×îÖÕ°²ÅÅAsyncRATÔ¶³Ì»á¼ûľÂí£¬ £¬£¬£¬ £¬ÊµÏÖÃô¸ÐÊý¾ÝÇÔÈ¡Ó볤ÆÚ»¯¿ØÖÆ¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓô¹ÂÚÓʼþαװ³É²ÆÎñ/ÉÌÒµÎļþ£¬ £¬£¬£¬ £¬ÓÕµ¼Êܺ¦ÕßÏÂÔØ±»Ä¾ÂíѬȾµÄScreenConnect×°ÖóÌÐò¡£¡£¡£¡£Ò»µ©×°Ö㬠£¬£¬£¬ £¬¹¥»÷Õßͨ¹ýScreenConnect»ñȡԶ³Ì»á¼ûȨÏÞ£¬ £¬£¬£¬ £¬²¢Æô¶¯¼üÅ̼ͼ»î¶¯Ö´ÐÐVBScriptÓÐÓøºÔØ¡£¡£¡£¡£¸Ã¾ç±¾Í¨¹ýPowerShell´Ó¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷ÏÂÔØÁ½¸öÍâ²¿ÔØºÉ£º"logs.ldk"£¨DLLÎļþ£©ºÍ"logs.ldr"£¨»ìÏý×é¼þ£©¡£¡£¡£¡£DLLÎļþÈÏÕæ½«VB¾ç±¾Ð´Èë´ÅÅÌ£¬ £¬£¬£¬ £¬²¢Ê¹ÓÃÍýÏëʹÃüαװ³É"Skype¸üгÌÐò"£¬ £¬£¬£¬ £¬ÔÚÿ´ÎϵͳµÇ¼ʱ×Ô¶¯Ö´ÐУ¬ £¬£¬£¬ £¬ÊµÏÖÒþ²Ø³¤ÆÚ»¯¡£¡£¡£¡£½øÒ»²½ÆÊÎöÏÔʾ£¬ £¬£¬£¬ £¬PowerShell¾ç±¾½«"logs.ldk"¼ÓÔØÎª.NET³ÌÐò¼¯£¬ £¬£¬£¬ £¬²¢´«Èë"logs.ldr"×÷Ϊ²ÎÊý£¬ £¬£¬£¬ £¬×îÖÕÖ´ÐÐAsyncRATµÄ½¹µãÓÐÓøºÔØ"AsyncClient.exe"¡£¡£¡£¡£¸ÃľÂí¾ß±¸¶àÏî¸ßΣ¹¦Ð§£º¼Í¼»÷¼ü¡¢ÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢ÊÕÂÞÏµÍ³Ö¸ÎÆ¡¢É¨Ãè¼ÓÃÜÇ®±ÒÇ®°ü£¬ £¬£¬£¬ £¬²¢Í¨¹ýTCPÌ×½Ó×Ö½«Êý¾Ý»Ø´«ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£


https://thehackernews.com/2025/09/asyncrat-exploits-connectwise.html


3. Vyro AIÊý¾Ýй¶£¬ £¬£¬£¬ £¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì


9ÔÂ10ÈÕ£¬ £¬£¬£¬ £¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬ £¬£¬£¬ £¬°Í»ù˹̹AI¹«Ë¾Vyro AIÒòδÊܱ£»£»£»£»£»£»£»¤µÄElasticsearchʵÀýй¶116GBÓû§ÈÕÖ¾£¬ £¬£¬£¬ £¬Éæ¼°Èý¿îÈÈÃÅÓ¦ÓãºGoogle PlayÏÂÔØÁ¿³¬1000Íò´ÎµÄImagineArt¡¢³¬10Íò´ÎÏÂÔØµÄChatly¼°Ô»á¼ûÔ¼5Íò´ÎµÄChatbotx¡£¡£¡£¡£¸Ã¹«Ë¾Ðû³Æ×ÜÏÂÔØÁ¿³¬1.5ÒڴΣ¬ £¬£¬£¬ £¬Ã¿ÖÜÌìÉú350ÍòÕÅͼƬ¡£¡£¡£¡£Ð¹Â¶Êý¾Ýº­¸Ç2-7ÌìµÄÉú²úÓ뿪·¢ÈÕÖ¾£¬ £¬£¬£¬ £¬°üÀ¨Óû§AIÌáÐÑ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢Óû§ÊðÀíµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¸ÃÊý¾Ý¿â×Ô2ÔÂÖÐÑ®±»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬ £¬£¬£¬ £¬¿ÉÄÜÒѱ»¹¥»÷Õß·¢Ã÷ÊýÔ¡£¡£¡£¡£´Ë´Îй¶Σº¦ÏÔÖø£º¹¥»÷Õß¿ÉʹÓÃÁîÅÆÐ®ÖÆÓû§ÕË»§£¬ £¬£¬£¬ £¬»á¼û̸Ìì¼Í¼¡¢ÌìÉúͼÏñ£¬ £¬£¬£¬ £¬ÉõÖÁÀÄÓÃAI´ú±Ò¾ÙÐв»·¨ÉúÒ⣻£»£»£»£»£»£»Óû§ÓëAIµÄ˽ÃܶԻ°¿ÉÄÜ̻¶´Óδ¹ûÕæµÄÃô¸ÐÄÚÈÝ¡£¡£¡£¡£ÀýÈ磬 £¬£¬£¬ £¬ImagineArtµÄ3000Íò»îÔ¾Óû§Êý¾ÝÈô±»Ê¹Ó㬠£¬£¬£¬ £¬½«µ¼Ö´ó¹æÄ£ÕË»§½ÓÊÜΣº¦¡£¡£¡£¡£


https://cybernews.com/security/ai-chatbots-vyro-data-leak/


4. Allegis GroupÔâEverestÀÕË÷¹¥»÷£¬ £¬£¬£¬ £¬°ÙÍò¼¶¿Í»§Êý¾Ýй¶


9ÔÂ10ÈÕ£¬ £¬£¬£¬ £¬È«Çò×î´óÈ˲ÅÖÎÀí¼¯ÍÅÖ®Ò»¡¢ÄêÊÕÈë½ü100ÒÚÃÀÔªµÄAllegis Group¿ËÈÕÔâÓöEverestÀÕË÷Èí¼þÍŻ﹥»÷¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÉÏÐû³Æ»ñÈ¡ÁËAllegisÄÚ²¿Îļþ¼°¿Í»§Ãûµ¥£¬ £¬£¬£¬ £¬²¢Ðû²¼Á½ÕÅExcelÎĵµ½ØÍ¼×÷Ϊ֤¾Ý£¬ £¬£¬£¬ £¬ÆäÖÐÒ»ÕŰüÀ¨13.5ÍòÌõ¿Í»§ÐÅÏ¢£ºÐÕÃû¡¢ÓÊÏä¡¢µç»°£¬ £¬£¬£¬ £¬ÁíÒ»ÕŰüÀ¨¶à´ï42.6ÍòÌõÀàËÆÊý¾Ý¡£¡£¡£¡£´ËÀàÐÅÏ¢¿ÉÄܱ»Ê¹ÓþÙÐÐÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£EverestÍÅ»ïÓë¶íÂÞ˹¹ØÁª£¬ £¬£¬£¬ £¬×Ô2021Äê»îÔ¾ÒÔÀ´ÒѳÉΪ×î·Å×ݵÄÀÕË÷×éÖ¯Ö®Ò»¡£¡£¡£¡£¾Ý°µÍø¼à¿Ø¹¤¾ßRansomlookerͳ¼Æ£¬ £¬£¬£¬ £¬¸ÃÍÅ»ïÒÑÍù12¸öÔ¹¥»÷Á˳¬°Ù¸ö×éÖ¯£¬ £¬£¬£¬ £¬·ÖÅúй¶Êý¾ÝÊÇÆäµä·¶Ê©Ñ¹ÊֶΣ¬ £¬£¬£¬ £¬Ö¼ÔÚÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£AllegisÆìÏÂÓµÓÐAerotek¡¢TEKsystems¡¢MarketSourceµÈ¶à¼ÒרҵÈ˲ÅÖÎÀí×Ó¹«Ë¾£¬ £¬£¬£¬ £¬Ð§ÀÍÍøÂçÁýÕÖÈ«Çò¡£¡£¡£¡£Ö»¹Ü¹«Ë¾ÒÑ»ØÓ¦³Æ½«¸üÐÂÏ£Íû£¬ £¬£¬£¬ £¬µ«¹¥»÷ÕßÌá¼°µÄ¡°ÖÖÀà·±¶àµÄСÎÒ˽¼ÒÎĵµ¡±ÉÐδ¹ûÕæÑù±¾£¬ £¬£¬£¬ £¬Ç±ÔÚΣº¦¿ÉÄÜÔ¶³¬ÒÑÆØ¹âµÄÁªÏµÐÅÏ¢¡£¡£¡£¡£


https://cybernews.com/security/allegis-group-data-breach-claims/


5. AkiraÀÕË÷Èí¼þÍÅ»ïʹÓÃSonicWallÎó²îÌᳫÐÂÒ»ÂÖ¹¥»÷


9ÔÂ11ÈÕ£¬ £¬£¬£¬ £¬AkiraÀÕË÷Èí¼þÍÅ»ïÕýÆð¾¢Ê¹ÓÃCVE-2024-40766ÕâÒ»Òѱ£´æÒ»ÄêµÄÑÏÖØ»á¼û¿ØÖÆÎó²î£¬ £¬£¬£¬ £¬¶ÔδÐÞ²¹µÄSonicWall SSL VPN×°±¸Ìᳫ¹¥»÷¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾­ÊÚȨµÄ×ÊÔ´»á¼û£¬ £¬£¬£¬ £¬ÉõÖÁ¿ÉÄܵ¼Ö·À»ðǽÍ߽⡣¡£¡£¡£SonicWallÔçÔÚ2024Äê8Ô±ãÐû²¼Á˲¹¶¡£¡£¡£¡£¬ £¬£¬£¬ £¬²¢Ç¿µ÷¸üÐÂʱÐèΪÍâµØÖÎÀíµÄSSLVPNÕË»§Óû§ÖØÖÃÃÜÂ룬 £¬£¬£¬ £¬µ«²¿·Ö×é֯δ³¹µ×Ö´Ðе÷½â²½·¥£¬ £¬£¬£¬ £¬µ¼ÖÂÍþвÐÐΪÕßÈÔÄÜʹÓÃ̻¶µÄƾ֤ÉèÖöàÒòËØÉí·ÝÑéÖ¤£¨MFA£©»ò»ùÓÚʱ¼äµÄÒ»´ÎÐÔÃÜÂ루TOTP£©ÏµÍ³£¬ £¬£¬£¬ £¬½ø¶ø»ñÈ¡»á¼ûȨÏÞ¡£¡£¡£¡£°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©ÓÚ2025Äê9Ô·¢³ö¾¯±¨£¬ £¬£¬£¬ £¬Ö¸³ö°Ä´óÀûÑǾ³ÄÚÕë¶Ô¸ÃÎó²îµÄ×Ô¶¯Ê¹ÓûÏÔÖøÔöÌí£¬ £¬£¬£¬ £¬²¢Ã÷È·½«AkiraÀÕË÷Èí¼þÓëSonicWall SSL VPN¹¥»÷¹ØÁª¡£¡£¡£¡£ÍøÂçÇå¾²¹«Ë¾Rapid7Ò²ÊӲ쵽ÀàËÆÇ÷ÊÆ£¬ £¬£¬£¬ £¬ÒÔΪ¹¥»÷¼¤Ôö¿ÉÄÜÓë²»ÍêÕûµÄµ÷½â²½·¥Óйأ¬ £¬£¬£¬ £¬ÏêϸÈëÇÖÊֶΰüÀ¨Ê¹ÓÃĬÈÏÓû§×éµÄÆÕ±é»á¼ûȨÏÞ¾ÙÐÐÉí·ÝÑéÖ¤£¬ £¬£¬£¬ £¬ÒÔ¼°Í¨¹ýSonicWall×°±¸ÉÏÐéÄâ°ì¹«ÊÒÃÅ»§µÄĬÈϹ«¹²»á¼ûȨÏÞʵÑé¹¥»÷¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/


6. LNERµÚÈý·½¹©Ó¦ÉÌÔâÍøÂç¹¥»÷ÖÂÂÿÍÊý¾Ýй¶


9ÔÂ11ÈÕ£¬ £¬£¬£¬ £¬Ó¢¹úÁгµÔËÓªÉÌÂ׶ض«±±Ìú·¹«Ë¾£¨LNER£©ÓÚ9ÔÂ10ÈÕÈ·ÈÏ£¬ £¬£¬£¬ £¬ÆäµÚÈý·½¹©Ó¦ÉÌÔâÊÜÍøÂç¹¥»÷£¬ £¬£¬£¬ £¬µ¼Ö²¿·ÖÂÿ͵ÄÁªÏµ·½·¨¼°¹ýÍùÐгÌÊý¾Ýй¶£¬ £¬£¬£¬ £¬µ«Î´Éæ¼°²ÆÎñÐÅÏ¢¡¢ÃÜÂë»òÖ§¸¶¿¨Êý¾Ý¡£¡£¡£¡£LNERÇ¿µ÷£¬ £¬£¬£¬ £¬ÆäÁгµÐ§ÀÍ¡¢ÊÛÆ±ÏµÍ³ÊµÊ±¿Ì±í¾ùÕý³£ÔËÐУ¬ £¬£¬£¬ £¬²¢ÒÑÓëÍøÂçÇ徲ר¼ÒºÍÏà¹Ø¹©Ó¦ÉÌÏàÖúÊÓ²ìÊÂÎñȫò£¬ £¬£¬£¬ £¬Í¬Ê±ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒÒÔÆÀ¹ÀÊÇ·ñÇкϡ¶Í¨ÓÃÊý¾Ý±£»£»£»£»£»£»£»¤ÌõÀý¡·£¨GDPR£©µÄ±¨¸æÒªÇó£¬ £¬£¬£¬ £¬Èô°ü¹Ü²½·¥È±·¦¿ÉÄÜÃæÁÙ·£¿£¿£¿£¿ £¿î¡£¡£¡£¡£Ð¹Â¶µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÄܱ»ÓÃÓÚ¹¹½¨ÏêϸСÎÒ˽¼Ò»­Ïñ£¬ £¬£¬£¬ £¬½ø¶øÌᳫ´¹ÂÚ¹¥»÷£¬ £¬£¬£¬ £¬Èçͨ¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òWhatsAppÓÕÆ­Óû§Ìṩ²ÆÎñ»òСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£LNERÒѱ޲ßÂÿͶÔÒâÍâͨѶ¼á³ÖСÐÄ£¬ £¬£¬£¬ £¬ÓÈÆäÉæ¼°Ð¡ÎÒ˽¼ÒÐÅÏ¢ÇëÇóµÄÓʼþ»òÐÅÏ¢£¬ £¬£¬£¬ £¬ÇÐÎðÈÝÒ׻ظ´¡£¡£¡£¡£¹«Ë¾ÌåÏÖ½«¸ß¶ÈÖØÊÓ´ËÊ£¬ £¬£¬£¬ £¬Ò»Á¬Óëר¼ÒÏàÖú²¢½ÓÄɰü¹Ü²½·¥£¬ £¬£¬£¬ £¬ºóÐø½«Ìṩ¸ü¶à¸üÐÂÐÅÏ¢¡£¡£¡£¡£


https://hackread.com/uk-rail-operator-lner-cyber-attack-passenger-data/