ÐÂÐËShinySp1d3rÀÕË÷Èí¼þÊÖÒÕÔËÓªÕ½ÂÔÆØ¹â
Ðû²¼Ê±¼ä 2025-11-211. ÐÂÐËShinySp1d3rÀÕË÷Èí¼þÊÖÒÕÔËÓªÕ½ÂÔÆØ¹â
11ÔÂ19ÈÕ£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±Åû¶ÁËÃûΪ"ShinySp1d3r"µÄÐÂÐÍÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©Æ½Ì¨¿ª·¢Ï¸½Ú¡£¡£¡£¡£¡£¸Ãƽ̨ÓÉÓëShinyHunters¡¢Scattered Spider¼°Lapsus$×éÖ¯¹ØÁªµÄÍþвÐÐΪÕß½¨É裬£¬£¬£¬£¬±ê¼Ç×ÅÕâЩÍÅ»ï´ÓʹÓõÚÈý·½¼ÓÃÜÆ÷תÏò×ÔÖ÷¿ª·¢¡£¡£¡£¡£¡£¿£¿£¿£¿ª·¢°æ±¾ÏÔʾ£¬£¬£¬£¬£¬ShinySp1d3r½ÓÄÉÈ«×ÔÖ÷Ñз¢¼Ü¹¹£¬£¬£¬£¬£¬Î´¸´ÓÃLockBit»òBabukµÈÒÑÖª´úÂë¿â£¬£¬£¬£¬£¬¾ß±¸¶àÏîÁ¢Ò칦Ч¡£¡£¡£¡£¡£ÊÖÒÕ²ãÃæ£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þʹÓÃChaCha20¼ÓÃÜËã·¨ÅäºÏRSA-2048±£»£»£»£»£»£»£»¤Ë½Ô¿£¬£¬£¬£¬£¬Ã¿¸ö¼ÓÃÜÎļþÌìÉúÆæÒìÀ©Õ¹Ãû²¢Í¨¹ýÊýѧ¹«Ê½¶¯Ì¬ÌìÉú¡£¡£¡£¡£¡£ÎļþÍ·ÒÔ"SPDR"¿ªÍ·¡¢"ENDS"×îºó£¬£¬£¬£¬£¬°üÀ¨ÎļþÃû¡¢¼ÓÃÜ˽Կ¼°ÔªÊý¾Ý¡£¡£¡£¡£¡£ÆäÈö²¥»úÖÆÖ§³Öͨ¹ýSCMЧÀÍ¡¢WMIÀú³Ì½¨Éè¼°GPO¾ç±¾°²ÅÅʵÏÖºáÏòÉøÍ¸£¬£¬£¬£¬£¬²¢¾ß±¸ËÑË÷¿ª·ÅÍøÂç¹²ÏíÖ÷»ú¾ÙÐжþ´Î¼ÓÃܵÄÄÜÁ¦¡£¡£¡£¡£¡£·´ÆÊÎöÌØÕ÷°üÀ¨¹Ò¹³EtwEventWriteº¯Êý×è¶ÏÈÕÖ¾¼Í¼¡¢ÁýÕÖÄڴ滺³åÇø·Àȡ֤£¬£¬£¬£¬£¬ÒÔ¼°Í¨¹ýдÈëËæ»ú.tmpÎļþÌî³ä´ÅÅ̿ռä×è°Êý¾Ý»Ö¸´¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters/
2. ¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾IGTÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
11ÔÂ20ÈÕ£¬£¬£¬£¬£¬¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾£¨IGT£©×÷ΪȫÇòÁìÏȵĶij¡¼°ÔÚÏ߯½Ì¨Êý×ÖÓÎÏ·¡¢ÌåÓý²©²ÊºÍ½ðÈڿƼ¼¹©Ó¦ÉÌ£¬£¬£¬£¬£¬¿ËÈÕ±»Óë¶íÂÞ˹¹ØÁªµÄ÷è÷ëÀÕË÷Èí¼þ×éÖ¯ÈÏÁì¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶²©¿ÍÐû²¼IGTÌõÄ¿£¬£¬£¬£¬£¬Éù³ÆÇÔÈ¡ÁË10GBÊý¾Ý£¬£¬£¬£¬£¬21,683¸öÎļþ£¬£¬£¬£¬£¬º¸Ç´ÓÀÏ»¢»ú¡¢²ÊƱϵͳµ½PlaySportsÌåÓý²©²Êƽ̨µÈ½¹µãÓªÒµÊý¾Ý¡£¡£¡£¡£¡£IGT²úÆ·ÆÕ±éÓ¦ÓÃÓÚÈ«Çò100¶à¸ö¹ú¼Ò£¬£¬£¬£¬£¬ÖðÈÕЧÀÍÊý°ÙÍòÍæ¼Ò£¬£¬£¬£¬£¬Æä½ðÈڿƼ¼²¿·Ö´æ´¢´ó×Ú¿Í»§Éí·ÝÐÅÏ¢£¬£¬£¬£¬£¬ÃæÁÙÉí·Ý͵ÇÔΣº¦¡£¡£¡£¡£¡£×èÖ¹±¨µÀÐû²¼£¬£¬£¬£¬£¬IGTδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£÷è÷ë×éÖ¯×Ô2021Äê»î¶¯ÒÔÀ´£¬£¬£¬£¬£¬2025ÄêÒѳÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯£¬£¬£¬£¬£¬ÒÑÍùÁù¸öÔ·¢¶¯³¬500Æð¹¥»÷£¬£¬£¬£¬£¬×Ô2023ÄêÆðÒÑÁгö991ÃûÊܺ¦Õߣ¬£¬£¬£¬£¬°üÀ¨×ÅÃûÆóÒµ¡¢Ò½ÁÆ»ú¹¹¼°Õþ¸®»ú¹¹¡£¡£¡£¡£¡£Æä½ÓÄÉÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©ÉÌҵģʽ£¬£¬£¬£¬£¬³£Ê¹ÓÃË«ÖØÀÕË÷Õ½ÂÔ£ºÏÈË÷Òª½âÃÜÊê½ð£¬£¬£¬£¬£¬ÔÙÍþвй¶Êý¾Ý¡£¡£¡£¡£¡£
https://cybernews.com/news/igt-digital-gaming-leader-qilin-ransomware-attack-casino-fintech-sports-betting/
3. ¶íÂÞ˹VSK°ü¹Ü¹«Ë¾Ôâ´ó¹æÄ£ÍøÂç¹¥»÷
11ÔÂ19ÈÕ£¬£¬£¬£¬£¬×÷Ϊ¶íÂÞ˹×î´ó×ۺϰü¹Ü¹«Ë¾Ö®Ò»£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚĪ˹¿ÆµÄVSK 11ÔÂ13ÈÕ¹ûÕæÈ·ÈÏÔâÓö¡°´ó¹æÄ£ÍøÂç¹¥»÷¡±£¬£¬£¬£¬£¬ÏÖÔÚÆä¹ÙÍø¡¢Òƶ¯Ó¦Óü°Êý°ÙÍòÓû§ÒÀÀµµÄЧÀÍÒÑÒ»Á¬ÏÂÏßÒ»ÖÜ¡£¡£¡£¡£¡£×÷ΪЧÀÍÔ¼3300ÍòСÎÒ˽¼Ò¿Í»§ºÍ50¶àÍò¼ÒÆóÒµµÄÐÐÒµ¾ÞÍ·£¬£¬£¬£¬£¬VSKÓªÒµº¸Ç¹¤ÒµÏÕ¡¢½»Í¨ÏÕ¡¢¿µ½¡ÏյȶàÁìÓò£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñµ¼Ö¿ͻ§ÎÞ·¨¹ºÖóµÏÕ¡¢Ð޸ı£µ¥¡¢»ñÈ¡µ£±£º¯»òÔ¤Ô¼Ò½ÁÆÐ§ÀÍ£¬£¬£¬£¬£¬²¿·ÖÒ½ÁÆ»ú¹¹ÒòÎÞ·¨ºËʵ°ü¹ÜÁýÕÖ¹æÄ£¾Ü¾øÐ§ÀÍ£¬£¬£¬£¬£¬¹«Ë¾ÓʼþϵͳÒàÖÐÖ¹£¬£¬£¬£¬£¬±»ÆÈ½¨Òé¿Í»§Í¨¹ýƽÐÅÌá½»×Éѯ¡£¡£¡£¡£¡£Ö»¹ÜVSKÇ¿µ÷¡°½öIT»ù´¡ÉèÊ©ÊÜÓ°Ï죬£¬£¬£¬£¬¿Í»§¼°ÏàÖúͬ°éÊý¾ÝÇå¾²ÎÞÓÝ¡±£¬£¬£¬£¬£¬µ«ÎÚ¿ËÀ¼ºÚ¿ÍÏà¹ØTelegramƵµÀÒÑÐû²¼¾Ý³ÆÐ¹Â¶µÄÐÅÏ¢¼°±¸·ÝÎļþ½ØÍ¼£¬£¬£¬£¬£¬ÕæÊµÐÔ´ýºËʵ¡£¡£¡£¡£¡£¹«Ë¾Í¬Ê±ÖÒÑÔ£¬£¬£¬£¬£¬ÆäÆóÒµÓòÃûÔâÐ®ÖÆ£¬£¬£¬£¬£¬»á¼ûÕß»á±»ÖØ¶¨ÏòÖÁÐéαTelegramƵµÀ¡£¡£¡£¡£¡£ÏÖÔÚ¹¥»÷ÕßÉí·Ý¼°ÄîͷδÃ÷£¬£¬£¬£¬£¬¶íÂÞË¹ÍøÂçÇ徲ר¼ÒÍÆ²âΪÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£
https://therecord.media/russia-vsk-cyberattack-outages
4. Òâ´óÀûFS¼¯ÍÅÒòAlmavivaÔâÈëÇÖÖÂ2.3TBÊý¾Ýй¶
11ÔÂ20ÈÕ£¬£¬£¬£¬£¬Òâ´óÀû¹ú¼ÒÌú·ÔËÓªÉÌFS Italiane¼¯ÍÅÒòITЧÀÍÌṩÉÌAlmavivaÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬µ¼ÖÂ2.3TBÃô¸ÐÊý¾Ýй¶ÖÁ°µÍø¡£¡£¡£¡£¡£ºÚ¿ÍÉù³ÆÇÔÈ¡ÄÚÈݺ¸ÇÉñÃØÎļþ¡¢ÊÖÒÕÎĵµ¡¢¹«¹²ÊµÌåÌõÔ¼¡¢ÈËÁ¦×ÊÔ´µµ°¸¡¢»á¼ÆÊý¾Ý¼°¶à¼ÒFS¼¯ÍŹ«Ë¾µÄÍêÕûÊý¾Ý¼¯£¬£¬£¬£¬£¬ÆäÖаüÀ¨2025ÄêµÚÈý¼¾¶ÈµÄ×îÐÂÎļþ¡£¡£¡£¡£¡£D3LabÍøÂçÍþвÇ鱨Ö÷¹Ü°²µÂÁÒÑÇ¡¤µÂÀ¸ÇµÙÃ÷ȷɨ³ý¸ÃÊý¾ÝΪ2022ÄêHiveÀÕË÷Èí¼þ¹¥»÷½ÓÄÉʹÓõĿÉÄÜÐÔ£¬£¬£¬£¬£¬²¢Ö¸³öת´¢Îļþ°´²¿·Ö/¹«Ë¾×éÖ¯µÄѹËõ´æµµ½á¹¹Óë2024-2025Äê»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯¼°Êý¾Ý¾¼ÍÈË×÷°¸ÊÖ·¨¸ß¶ÈÒ»Ö¡£¡£¡£¡£¡£Ö»¹ÜAlmavivaÓëFS¼¯Ížùδ»ØÓ¦Ã½Ìå³õÆÚÎÊѯ£¬£¬£¬£¬£¬µ«AlmavivaºóÐøÍ¨¹ýÍâµØÃ½ÌåÉùÃ÷֤ʵÊÂÎñ£ºÆäÇå¾²¼à¿Ø²¿·Ö½üÆÚ·¢Ã÷²¢¸ôÀëÁËÒ»ÆðÓ°Ï칫˾ϵͳµÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö²¿·ÖÊý¾Ý±»µÁ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÆô¶¯Çå¾²Ó¦¶Ô³ÌÐò£¬£¬£¬£¬£¬È·±£Òªº¦Ð§ÀÍÔËÐУ¬£¬£¬£¬£¬²¢Í¨Öª¾¯·½¡¢¹ú¼ÒÍøÂçÇå¾²»ú¹¹¼°Êý¾Ý±£»£»£»£»£»£»£»¤»ú¹¹£¬£¬£¬£¬£¬ÏÖÔÚÊÓ²ìÈÔÔÚÕþ¸®»ú¹¹ÐÖúϾÙÐУ¬£¬£¬£¬£¬ÔÊÐíÒÔ͸Ã÷·½·¨¸üÐÂÏ£Íû¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬Êý¾Ýй¶ÊÇ·ñ°üÀ¨ÂÿÍÐÅÏ¢»òÓ°ÏìFS¼¯ÍÅÒÔÍâµÄÆäËû¿Í»§Éв»Ã÷È·¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-23tb-data-from-italian-rail-group-almavia/
5. PhotocallµÁ°æÆ½Ì¨Ôâ¹Ø±Õ£¬£¬£¬£¬£¬³¬2600ÍòÓû§ÊÜÓ°Ïì
11ÔÂ20ÈÕ£¬£¬£¬£¬£¬ÓµÓг¬2600ÍòÓû§µÄµÁ°æµçÊÓÁ÷ýÌåÆ½Ì¨PhotocallÔÚ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©ÓëDAZNÁªºÏÊÓ²ìºóÒÑ×èÖ¹ÔËÓª¡£¡£¡£¡£¡£¸Ãƽ̨δ¾ÊÚȨÌṩÀ´×Ô60¸ö¹ú¼ÒµÄ1127¸öµçÊÓÆµµÀ»á¼ûЧÀÍ£¬£¬£¬£¬£¬º¸ÇÌåÓýÈüÊÂÖ±²¥¡¢Òâ¼×ÁªÈü¡¢NFL/NHLÈüʼ°»Ê¼ÒÂíµÂÀï¡¢°ÍÈûÂÞÄǵȾãÀÖ²¿ÆµµÀ£¬£¬£¬£¬£¬Óû§ÂþÑÜÒÔÎ÷°àÑÀ£¨30%£©¡¢Ä«Î÷¸ç£¨13%£©ÎªÖ÷£¬£¬£¬£¬£¬µÂ¹ú¡¢Òâ´óÀû¡¢ÃÀ¹ú¸÷Õ¼6%¡£¡£¡£¡£¡£Ö»¹Üδֱ½ÓÌṩDAZNƵµÀ£¬£¬£¬£¬£¬µ«Æ½Ì¨ÖØÐ·ַ¢ÁËÆäÏàÖúͬ°éÄÚÈÝ£¨ÈçMotoGPºÍF1ÈüÊ£©£¬£¬£¬£¬£¬×é³ÉÇÖȨ¡£¡£¡£¡£¡£´Ë´Î¹Ø±ÕÔ´ÓÚÅ·ÖÞÐ̾¯×é֯е÷µÄ¿ç¹úÖ´·¨Ðж¯£¬£¬£¬£¬£¬Ðж¯Öвé·â69¸ö²»·¨ÍøÕ¾£¨Äê»á¼ûÁ¿³¬1180Íò£©£¬£¬£¬£¬£¬25¸ö²»·¨IPTVЧÀͱ»Òƽ»¼ÓÃÜÇ®±ÒÌṩÉ̲é·â£¬£¬£¬£¬£¬²é»ñ¼ÛÖµ5500ÍòÃÀÔª¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬²¢Æô¶¯44ÏîÐÂÊӲ졣¡£¡£¡£¡£PhotocallÓòÃûÒÑ×ªÒÆÖÁACE²¢Öض¨ÏòÖÁÕýµ±Ô¢Ä¿ÍøÕ¾£¬£¬£¬£¬£¬ÔËÓªÉÌÔÞ³É×èÖ¹ÔËÓª¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/tv-streaming-piracy-service-photocall-with-26m-yearly-visits-shut-down/
6. SalesforceÓëGainsightÓ¦¶ÔÊý¾ÝÇÔÈ¡£¡£¡£¡£¡£º×÷·ÏÁîÅÆÒÆ³ýÓ¦ÓÃ
11ÔÂ20ÈÕ£¬£¬£¬£¬£¬SalesforceÔÚÊÓ²ì¿Í»§Êý¾ÝÇÔÈ¡¹¥»÷ʱ£¬£¬£¬£¬£¬·¢Ã÷Òì³£»£»£»£»£»£»£»î¶¯Ô´ÓÚGainsightÐû²¼µÄÓ¦ÓóÌÐòÓëSalesforceµÄÍⲿÅþÁ¬£¬£¬£¬£¬£¬¶ø·Ç×ÔÉíCRMƽ̨Îó²î¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑ×÷·ÏËùÓÐÓë¸ÃÓ¦ÓóÌÐò¹ØÁªµÄ»á¼ûÁîÅÆºÍË¢ÐÂÁîÅÆ£¬£¬£¬£¬£¬²¢ÔÝʱ½«Æä´ÓAppExchangeÒÆ³ý£¬£¬£¬£¬£¬Í¬Ê±Í¨ÖªÊÜÓ°Ïì¿Í»§²¢Ìṩ×ÊÖú¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÓë2025Äê8ÔÂSalesloftÊý¾Ýй¶ģʽÏàËÆ£¬£¬£¬£¬£¬ÆäʱÀÕË÷×éÖ¯¡°Scattered Lapsus$ Hunters¡±Ê¹ÓÃÇÔÈ¡µÄOAuthÁîÅÆ£¬£¬£¬£¬£¬´Ó¿Í»§SalesforceʵÀýÖÐÇÔÈ¡ÁËÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬Ó°ÏìÔ¼760¼Ò¹«Ë¾£¬£¬£¬£¬£¬µ¼ÖÂ15ÒÚÌõ¼Í¼й¶£¬£¬£¬£¬£¬Éæ¼°Google¡¢Cloudflare¡¢Palo Alto NetworksµÈ×ÅÃûÆóÒµ¡£¡£¡£¡£¡£ShinyHunters×éÖ¯Éù³Æ£¬£¬£¬£¬£¬Í¨¹ýSalesloft DriftÎó²îÖÐÇÔÈ¡µÄÃÜÔ¿ÈëÇÖGainsightºó£¬£¬£¬£¬£¬½øÒ»²½»ñÈ¡ÁË285¸öSalesforceʵÀýµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£Gainsight´ËǰÒÑ֤ʵ£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÓëSalesloft Drift¹ØÁªµÄ±»µÁOAuthÁîÅÆÈëÇÖ£¬£¬£¬£¬£¬Ð¹Â¶ÁËÆóÒµÁªÏµÐÅÏ¢¡£¡£¡£¡£¡£SalesforceÇ¿µ÷£¬£¬£¬£¬£¬ËùÓжñÒâ»î¶¯¾ùÓëÍⲿӦÓóÌÐòÅþÁ¬Óйأ¬£¬£¬£¬£¬¶ø·Çƽ̨×Ô¼ºÎó²î¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/


¾©¹«Íø°²±¸11010802024551ºÅ