SynnovisÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂNHS»¼ÕßÊý¾Ýй¶

Ðû²¼Ê±¼ä 2025-11-14

1. SynnovisÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂNHS»¼ÕßÊý¾Ýй¶


11ÔÂ12ÈÕ£¬£¬ £¬£¬£¬£¬Ó¢¹ú²¡ÀíЧÀÍÌṩÉÌSynnovisÓÚ2024Äê6ÔÂÔâÊÜ÷è÷ëÀÕË÷Èí¼þÍŻ﹥»÷£¬£¬ £¬£¬£¬£¬µ¼Ö²¿·Ö»¼ÕßÊý¾Ý±»µÁ£¬£¬ £¬£¬£¬£¬Éæ¼°NHSºÅÂë¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¼°²¿·Ö¿ÉÆ¥ÅäµÄ¼ì²âЧ¹û¡£¡£¡£¸Ã¹«Ë¾½¨ÉèÓÚ2021Ä꣬£¬ £¬£¬£¬£¬Óɹú¼ÊÒ½ÁÆÕï¶ÏÉÌSYNLABÓë¸ÇÒÁºÍÊ¥ÍÐÂí˹NHS»ù½ð»áÐÅÍС¢¹úÍõѧԺҽԺNHS»ù½ð»áÐÅÍÐÏàÖúÔËÓª£¬£¬ £¬£¬£¬£¬Îª°üÀ¨NHSÔÚÄÚµÄÓ¢¹úÒ½ÁÆ»ú¹¹Ìṩ²¡ÀíЧÀÍ¡£¡£¡£´Ë´Î¹¥»÷Ôì³ÉÂ׶ضà¼ÒNHSÒ½ÔºÔËÓªÑÏÖØÊÜ×裬£¬ £¬£¬£¬£¬°üÀ¨¹úÍõѧԺҽԺ¡¢Ê¥ÍÐÂí˹ҽԺµÈ£¬£¬ £¬£¬£¬£¬µ¼Ö·ǽôÆÈ²¡Àí¼ì²éÔ¤Ô¼ºÍÊäѪЧÀÍ×÷·Ï»òÑÓ³Ù£¬£¬ £¬£¬£¬£¬Òý·¢ÑªÒºÇ·È±£¬£¬ £¬£¬£¬£¬³¬800ÀýÊÖÊõºÍ700ÀýÃÅÕïÔ¤Ô¼±»ÆÈ×÷·Ï¡£¡£¡£¹¥»÷ÕßÔøÓÚ2024Äê6ÔÂ20ÈÕй¶²¿·ÖÊý¾Ý£¬£¬ £¬£¬£¬£¬´ÙʹSynnovisÏòÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ±¨¸æ²¢»ñÖ´·¨½ûÁ£¬ £¬£¬£¬£¬Õ¥È¡½øÒ»²½Ê¹Óñ»µÁÊý¾Ý¡£¡£¡£Êý¾ÝÊÓ²ìÀúʱһÄê¶à£¬£¬ £¬£¬£¬£¬ÓÉ·¨Ö¤×¨¼ÒÍŶÓÍê³É£¬£¬ £¬£¬£¬£¬ÒòÊý¾Ý½á¹¹ÔÓÂÒ¡¢²»ÍêÕûÇÒÁãÐÇ£¬£¬ £¬£¬£¬£¬Ðè¶¨ÖÆ»¯Á÷³Ì´¦Öóͷ£¡£¡£¡£SynnovisÌåÏÖ£¬£¬ £¬£¬£¬£¬´ó²¿·Ö±»µÁÐÅÏ¢ÐèÁÙ´²ÖªÊ¶»òÔö²¹ÐÅÏ¢²Å»ª½â¶Á£¬£¬ £¬£¬£¬£¬ÏÖÔÚÒÑÆô¶¯ÊÜÓ°Ïì»ú¹¹Í¨Öª³ÌÐò£¬£¬ £¬£¬£¬£¬Ô¤¼Æ2025Äê11ÔÂ21ÈÕÍê³É£¬£¬ £¬£¬£¬£¬µ«²»»áÖ±½ÓÁªÏµ»¼Õߣ¬£¬ £¬£¬£¬£¬ÓÉNHS»ú¹¹ÈÏÕæ»¼Õß֪ͨ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/synnovis-notifies-of-data-breach-after-2024-ransomware-attack/


2. CISA½«WatchGuard FirewareÎó²îÄÉÈëÒÑ֪ʹÓÃĿ¼


11ÔÂ13ÈÕ£¬£¬ £¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ÓÚÖÜÈý½«Ó°ÏìWatchGuard FirewareµÄCVE-2025-9242ÑÏÖØÎó²îÌí¼ÓÖÁÆäÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÒѱ»Ö¤ÊµÔâµ½Æð¾¢Ê¹Óᣡ£¡£CVE-2025-9242ΪԽ½çдÈëÎó²î£¬£¬ £¬£¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.3£¬£¬ £¬£¬£¬£¬Ó°ÏìFireware OS 11.10.2ÖÁ11.12.4_Update1¡¢12.0ÖÁ12.11.3¼°2025.1°æ±¾¡£¡£¡£¾ÝCISAͨ¸æ£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÔÊÐíÔ¶³ÌδÊÚȨ¹¥»÷ÕßÔÚ²Ù×÷ϵͳÏà¹ØÀú³ÌÖÐÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬£¬£¬ÍþвÐÔ¼«¸ß¡£¡£¡£Îó²îȪԴÔÚÓÚIKEÎÕÊÖÀú³ÌÖÐÉí·Ý»º³åÇøÈ±·¦³¤¶È¼ì²é£¬£¬ £¬£¬£¬£¬ÇÒÖ¤ÊéÑéÖ¤ÔÚÒ×Êܹ¥»÷´úÂëÖ´Ðкó²Å¾ÙÐУ¬£¬ £¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÈÆ¹ýÈÏÖ¤Ö±½Ó´¥·¢Îó²î¡£¡£¡£Çå¾²Ñо¿Ô±McCaulay HudsonÖ¸³ö£¬£¬ £¬£¬£¬£¬ÕâÖÖÉè¼ÆÈ±ÏÝʹ¹¥»÷·¾¶ÔÚÉí·ÝÑé֤ǰ¼´¿É±»Ê¹Óᣡ£¡£×èÖ¹2025Äê11ÔÂ12ÈÕ£¬£¬ £¬£¬£¬£¬È«ÇòÈÔÓÐÁè¼Ý54,300¸öFirebox×°±¸±£´æ´ËÎó²î£¬£¬ £¬£¬£¬£¬½Ï10ÔÂ19ÈÕµÄ75,955̨ÓÐËùϽµ¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬ÃÀ¹úÒÔ18,500̨¾ÓÊ×£¬£¬ £¬£¬£¬£¬Òâ´óÀû£¨5,400̨£©¡¢Ó¢¹ú£¨4,000̨£©¡¢µÂ¹ú£¨3,600̨£©ºÍ¼ÓÄôó£¨3,000̨£©Î»ÁÐǰÎå¡£¡£¡£Áª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©ÒªÇó¸÷»ú¹¹ÔÚ2025Äê12ÔÂ3ÈÕǰÍê³ÉWatchGuard²¹¶¡×°Öᣡ£¡£


https://thehackernews.com/2025/11/cisa-flags-critical-watchguard-fireware.html


3. ¹ú¼ÊÁªºÏÐж¯¡°ÖÕ¾ÖÐж¯¡±ÖØ´´¶ñÒâÈí¼þ


11ÔÂ10ÈÕÖÁ14ÈÕ£¬£¬ £¬£¬£¬£¬ÓÉÅ·ÖÞÐ̾¯×éÖ¯ºÍÅ·ÖÞ˾·¨×é֯Эµ÷¡¢¾Å¹úÖ´·¨²¿·ÖÁªºÏ¿ªÕ¹µÄ¡°ÖÕ¾ÖÐж¯¡±×îн׶ÎÈ¡µÃÍ»ÆÆÐÔЧ¹û£¬£¬ £¬£¬£¬£¬´Ý»Ù1025̨ÓÃÓÚRhadamanthysÐÅÏ¢ÇÔÈ¡Æ÷¡¢VenomRAT¼°Elysium½©Ê¬ÍøÂçÔËÓªµÄЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬²é·â20¸öÓòÃû£¬£¬ £¬£¬£¬£¬²¢ÔÚÏ£À°¾Ð²¶Ò»ÃûÓëVenomRATÏà¹ØµÄÏÓÒÉÈË¡£¡£¡£´Ë´ÎÐж¯»ñµÃCryptolaemus¡¢ShadowserverµÈ12¼Ò˽ÈË»ú¹¹Ö§³Ö£¬£¬ £¬£¬£¬£¬Í¬²½¹¥»÷ÀÕË÷Èí¼þ¡¢AVCheckÍøÕ¾¼°SmokeloaderµÈ½©Ê¬ÍøÂç»ù´¡ÉèÊ©¡£¡£¡£¾ÝÅ·ÖÞÐ̾¯×éÖ¯Åû¶£¬£¬ £¬£¬£¬£¬±»´Ý»ÙµÄ¶ñÒâÈí¼þ»ù´¡ÉèÊ©Éæ¼°ÊýÊ®Íǫ̀ÊÜѬȾÅÌËã»ú£¬£¬ £¬£¬£¬£¬°üÀ¨Êý°ÙÍòÌõ±»µÁƾ֤¡£¡£¡£Ö÷ÒªÏÓÒÉÈ˿ɻá¼û³¬10Íò¸ö¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬ £¬£¬£¬£¬×ʲú¼ÛÖµ»ò´ïÊý°ÙÍòÅ·Ôª¡£¡£¡£´ó¶¼Êܺ¦Õßδ²ì¾õϵͳÒÑÔâÈëÇÖ¡£¡£¡£Ö´·¨»ú¹¹½¨Ò鹫ÖÚͨ¹ýpolitie.nl/checkyourhackºÍhaveibeenpwned.comºË²éÊÇ·ñÊÜÓ°Ïì¡£¡£¡£´Ë´ÎÐж¯ÑÓÐøÁË¡°ÖÕ¾ÖÐж¯¡±¶Ô¿ç¹úÍøÂç·¸·¨µÄÒ»Á¬¹¥»÷Ì¬ÊÆ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/police-disrupts-rhadamanthys-venomrat-and-elysium-malware-operations/


4. AkiraÀÕË÷Èí¼þ¼ÓÃÜNutanixÐéÄâ»ú²¢À©Õ¹¹¥»÷ÄÜÁ¦


11ÔÂ13ÈÕ£¬£¬ £¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¡¢Áª°îÊÓ²ì¾Ö£¨FBI£©µÈ»ú¹¹ÁªºÏÐû²¼Í¨¸æ£¬£¬ £¬£¬£¬£¬Ö¸³öAkiraÀÕË÷Èí¼þÒÑÀ©Õ¹¼ÓÃÜÄÜÁ¦ÖÁNutanix AHVÐéÄâ»ú´ÅÅÌÎļþ£¬£¬ £¬£¬£¬£¬²¢Åû¶×îй¥»÷ϸ½Ú¡£¡£¡£¸ÃÀÕË÷Èí¼þ×Ô2025Äê6ÔÂÆð×îÏÈÕë¶ÔNutanix AHVƽ̨µÄ.qcow2ÃûÌÃÐéÄâ´ÅÅÌÎļþʵÑé¼ÓÃÜ£¬£¬ £¬£¬£¬£¬Í¨¹ýÀÄÓÃSonicWallÎó²î£¨CVE-2024-40766£©Í»ÆÆ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬£¬½«¹¥»÷¹æÄ£´ÓVMware ESXiºÍHyper-VÀ©Õ¹ÖÁNutanix AHV¡£¡£¡£Nutanix AHV×÷Ϊ»ùÓÚLinuxµÄÐéÄ⻯½â¾ö¼Æ»®£¬£¬ £¬£¬£¬£¬ÆäÆÕ±é°²ÅÅʹÆä³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄÐÂÄ¿µÄ£¬£¬ £¬£¬£¬£¬ÀàËÆ´Ëǰ¶ÔVMware ESXiºÍHyper-VµÄ¹¥»÷ģʽ¡£¡£¡£¹¥»÷Õßͨ³£Ê¹ÓÃ̻¶װ±¸µÄVPN/SSHƾ֤»ò·À»ðǽÎó²î£¨ÈçCVE-2024-40766£©ÈëÇÖÆóÒµÍøÂ磬£¬ £¬£¬£¬£¬Ëæºóͨ¹ýδÐÞ²¹µÄVeeam±¸·ÝЧÀÍÆ÷Îó²î£¨CVE-2023-27532¡¢CVE-2024-40711£©É¾³ý±¸·ÝÊý¾Ý¡£¡£¡£ÔÚÉøÍ¸ºó£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃnltest¡¢AnyDesk¡¢LogMeIn¡¢ImpacketµÈ¹¤¾ß¾ÙÐÐÕì̽ºÍºáÏòÒÆ¶¯£¬£¬ £¬£¬£¬£¬½¨ÉèÖÎÀíÕË»§ÊµÏÖ³¤ÆÚ»¯£¬£¬ £¬£¬£¬£¬²¢ÒƳý¶Ëµã¼ì²â¹¤¾ßÒÔ¹æ±Ü·ÀÓù¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-akira-ransomware-linux-encryptor-targeting-nutanix-vms/


5. npm¡°IndonesianFoods¡±È䳿£¬£¬ £¬£¬£¬£¬Ãë¼¶×ÔÈö²¥Íò°ü¹¥»÷¹©Ó¦Á´


11ÔÂ13ÈÕ£¬£¬ £¬£¬£¬£¬npm×¢²á±íÔâÓöÃûΪ¡°IndonesianFoods¡±µÄ×ÔÈö²¥È䳿¹¥»÷£¬£¬ £¬£¬£¬£¬¸ÃÈä³æÃ¿ÆßÃë×Ô¶¯ÌìÉúÐÂÈí¼þ°ü£¬£¬ £¬£¬£¬£¬ÒÑÀÛ¼ÆÐû²¼³¬10Íò¸öÓ¡ÄáÓïÃüÃû£¨Èç¡°fajar-donat9-breki¡±£©µÄÀ¬»ø°ü£¬£¬ £¬£¬£¬£¬ÇÒÊýÄ¿³ÊÖ¸Êý¼¶ÔöÌí¡£¡£¡£¾ÝSonatypeÆÊÎö£¬£¬ £¬£¬£¬£¬¹¥»÷Õßͨ¹ý¸ß×Ô¶¯»¯¾ç±¾Ò»Á¬ºäÕ¨¿ªÔ´Éú̬ϵͳ£¬£¬ £¬£¬£¬£¬ËäÄ¿½ñ°üÌå맪¶ñÒâ×é¼þ£¬£¬ £¬£¬£¬£¬µ«Î´À´¿ÉÄÜǶÈëÊý¾ÝÇÔÈ¡»òºóÃųÌÐò£¬£¬ £¬£¬£¬£¬×é³ÉDZÔÚÍþв¡£¡£¡£´Ë´Î¹¥»÷·ºÆðÈý´óÌØÕ÷£ºÒ»ÊǹæÄ£»£»£»¯ÆÆË𣬣¬ £¬£¬£¬£¬µ¥ÈÕ´¥·¢ÑÇÂíÑ·Îó²î¼ì²â¹¤¾ßÌìÉú7.2ÍòÌõÎó²î±¨¸æ£¬£¬ £¬£¬£¬£¬¶à¸öÇ徲ϵͳÒòÊý¾ÝºéÁ÷±ôÁÙ̱»¾£»£»£»¶þÊǾ­¼ÃÄîÍ·ÏÔ×Å£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃTEAÇø¿éÁ´Ð­Ò飬£¬ £¬£¬£¬£¬ÔÚ°üÖÐǶÈëtea.yamlÎļþ¹ØÁª´ú±ÒÇ®°ü£¬£¬ £¬£¬£¬£¬Í¨¹ýÇ¿µ÷°ü¼ä¹ØÁª¶ÈÌáÉýÓ°Ïì·ÖÊýÒÔ׬ȡ´ú±ÒÊÕÒæ£»£»£»ÈýÊÇÀúÊ·ÑݽøÇåÎú£¬£¬ £¬£¬£¬£¬×Ô2023ÄêÆðÒÑÀÛ¼ÆÐû²¼4.3Íò°ü£¬£¬ £¬£¬£¬£¬2024ÄêÒýÈëTEAÇ®±Ò»¯»úÖÆ£¬£¬ £¬£¬£¬£¬2025ÄêÉý¼¶ÎªÈä³æÊ½¸´ÖÆÑ­»·¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-indonesianfoods-worm-floods-npm-with-100-000-packages/


6. ¡¶»ªÊ¢¶ÙÓʱ¨¡·Êý¾Ýй¶ÊÂÎñÓ°Ïì½üÍòÃûÔ±¹¤ºÍ³Ð°üÉÌ


11ÔÂ13ÈÕ£¬£¬ £¬£¬£¬£¬¡¶»ªÊ¢¶ÙÓʱ¨¡·¿ËÈÕ֪ͨԼ9720ÃûÔ±¹¤¼°³Ð°üÉÌ£¬£¬ £¬£¬£¬£¬ÆäСÎÒ˽¼ÒºÍ²ÆÎñÊý¾ÝÔÚOracle E-Business SuiteÁãÈÕÎó²î¹¥»÷ÖÐÔâй¶¡£¡£¡£´Ë´ÎÊÂÎñ±¬·¢ÓÚ2025Äê7ÔÂ10ÈÕÖÁ8ÔÂ22ÈÕ£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓøÃERPƽ̨µÄÈËÁ¦×ÊÔ´¡¢²ÆÎñºÍ¹©Ó¦Á´ÖÎÀí¹¦Ð§ÖеÄδÐÞ²¹Îó²î£¨ºó±»×·×ÙΪCVE-2025-61884£©£¬£¬ £¬£¬£¬£¬ÇÔÈ¡Á˰üÀ¨È«Ãû¡¢ÒøÐÐÕ˺š¢Â·ÓɺÅÂë¡¢Éç»áÇå¾²ºÅÂ루SSN£©¡¢Ë°Îñ¼°Éí·ÝÖ¤ºÅÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£9ÔÂÏÂÑ®£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÊÔͼÒÔ´ËÀÕË÷¸Ã±¨£¬£¬ £¬£¬£¬£¬¶ø¼×¹ÇÎĹ«Ë¾ÔÚÊÓ²ìʱ´úÅû¶ÁËÕâÒ»ÆÕ±é±£´æµÄÇå¾²Îó²î¡£¡£¡£×÷ΪÃÀ¹ú¿¯ÐÐÁ¿×î´óµÄÈÕ±¨Ö®Ò»£¬£¬ £¬£¬£¬£¬¡¶»ªÊ¢¶ÙÓʱ¨¡·ÓµÓÐÔ¼250ÍòÊý×Ö¶©ÔÄÓû§¡£¡£¡£Ê¹ÓÃͳһÎó²îµÄÊܺ¦Õß»¹°üÀ¨¹þ·ð´óѧ¡¢ÃÀ¹úº½¿Õ×Ó¹«Ë¾Envoy Air¼°ÈÕÁ¢ÆìÏÂGlobalLogicµÈ»ú¹¹¡£¡£¡£ClopÀÕË÷Èí¼þ×éÖ¯±»Ö¸ÓëÕâЩ¹¥»÷ÓйØ£¬£¬ £¬£¬£¬£¬ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÁгöÁ˸ü¶àÊÜÓ°Ïì×éÖ¯¡£¡£¡£¡¶»ªÊ¢¶ÙÓʱ¨¡·µÄÊÓ²ìÓÚ10ÔÂ27ÈÕ¿¢Ê£¬£¬ £¬£¬£¬£¬È·ÈÏÊý¾Ýй¶ºó£¬£¬ £¬£¬£¬£¬ÊÜÓ°ÏìСÎÒ˽¼Òͨ¹ýIDX»ñµÃ12¸öÔÂÃâ·ÑÉí·Ý±£»£»£»¤Ð§ÀÍ£¬£¬ £¬£¬£¬£¬²¢±»½¨Òé¶³½áÐÅÓõµ°¸¼°ÉèÖÃڲƭ¾¯±¨¡£¡£¡£


https://www.bleepingcomputer.com/news/security/washington-post-data-breach-impacts-nearly-10k-employees-contractors/