²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶

Ðû²¼Ê±¼ä 2025-09-12

1. ²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ̻¶


9ÔÂ10ÈÕ£¬£¬£¬£¬£¬ £¬£¬²®Ã÷º²¶¼îì¸ñÀ¼ÆæÖÐѧ½üÆÚ±¬·¢Ò»ÆðÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬ £¬£¬Ó°Ïì7ÖÁ11Äê¼¶£¨11-16Ë꣩Êý°ÙÃûѧÉú¡£¡£¡£¡£¡£¡£¡£¾ÝѧУÏò¼Ò³¤·¢Ë͵ÄÓʼþ¼°ºóÐøÉùÃ÷£¬£¬£¬£¬£¬ £¬£¬Ð¹Â¶Ô´ÓÚÒ»·Ý°üÀ¨Ñ§ÉúÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ¼°âïÊÑÁªÏµ·½·¨µÄµç×Ó±í¸ñ±»¹ýʧ¹²Ïí¡£¡£¡£¡£¡£¡£¡£¸Ã±í¸ñ±¾ÓÃÓÚÁ÷¸ÐÒßÃç½ÓÖÖÔÞ³ÉÁ÷³Ì£¬£¬£¬£¬£¬ £¬£¬µ«¼Ò³¤µã»÷ÓʼþÁ´½Óºó¿ÉÖ±½ÓÏÂÔØ£¬£¬£¬£¬£¬ £¬£¬µ¼ÖÂÃô¸ÐÐÅϢ̻¶¡£¡£¡£¡£¡£¡£¡£ÊÂÎñ±¬·¢ÓÚÍâµØÊ±¼ä9ÔÂ8ÈÕ9:50ÖÁ9:59ʱ´ú£¬£¬£¬£¬£¬ £¬£¬½öÄÜͨ¹ýѧУBromcomÄÚÁªÍø»á¼û¸Ã±í¸ñµÄÖ°Ô±¿É¼û¡£¡£¡£¡£¡£¡£¡£¾ÝÕþ¸®Í³¼Æ£¬£¬£¬£¬£¬ £¬£¬¸ÃУ¹²ÓÐ1198ÃûѧÉú£¬£¬£¬£¬£¬ £¬£¬µ«´Ë´Îй¶ÏêÏ¸Éæ¼°7-11Ä꼶ѧÉúÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Êܺ¦¼Ò³¤·´Ó¦£¬£¬£¬£¬£¬ £¬£¬µç×Ó±í¸ñ¼Í¼ÁË"Õû¸öѧУµÄÐÅÏ¢"£¬£¬£¬£¬£¬ £¬£¬Òý·¢¶Ôº¢×ÓÉí·Ý͵ÇÔ¡¢Õ©Æ­µÈÇ徲Σº¦µÄµ£ÐÄ¡£¡£¡£¡£¡£¡£¡£Ñ§Ð£ÔÚÉùÃ÷ÖÐÌåÏÖÒѽÓÄɽôÆÈ²½·¥£ºÁ¬Ã¦ÁªÏµÖÎÀíÐÅϢϵͳ£¨MIS£©ÌṩÉ̳·»Ø²¢É¾³ýй¶ÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬ÒªÇóÊÕµ½±í¸ñµÄ¼Ò³¤¾¡¿ìɾ³ýÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬²¢ÏòÐÅÍÐÊý¾Ý±£»£»£»£»¤¹Ù±¨¸æÊÂÎñ¡£¡£¡£¡£¡£¡£¡£Êý¾Ý±£»£»£»£»¤¹ÙÕýÊÓ²ìÎ¥¹æÏ¸½Ú£¬£¬£¬£¬£¬ £¬£¬ÐëҪʱ½«ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬£¬£¬£¬£¬ £¬£¬Í¬Ê±Öƶ©Ô¤·À²½·¥×èÖ¹ÀàËÆÊÂÎñ¸´·¢¡£¡£¡£¡£¡£¡£¡£


https://www.theregister.com/2025/09/10/birmingham_school_data_blunder/


2. AsyncRATʹÓÃConnectWise ScreenConnectÇÔȡƾ֤ºÍ¼ÓÃÜÇ®±Ò


9ÔÂ11ÈÕ£¬£¬£¬£¬£¬ £¬£¬ÍøÂçÇå¾²¹«Ë¾LevelBlueÅû¶ÁËÒ»ÆðʹÓÃÕýµ±Ô¶³ÌÖÎÀí¹¤¾ßConnectWise ScreenConnectÌᳫµÄ¸ß½×ÎÞÎļþ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷̫ͨ¹ý½×¶Î¾ç±¾Ö´ÐУ¬£¬£¬£¬£¬ £¬£¬×îÖÕ°²ÅÅAsyncRATÔ¶³Ì»á¼ûľÂí£¬£¬£¬£¬£¬ £¬£¬ÊµÏÖÃô¸ÐÊý¾ÝÇÔÈ¡Ó볤ÆÚ»¯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓô¹ÂÚÓʼþαװ³É²ÆÎñ/ÉÌÒµÎļþ£¬£¬£¬£¬£¬ £¬£¬ÓÕµ¼Êܺ¦ÕßÏÂÔØ±»Ä¾ÂíѬȾµÄScreenConnect×°ÖóÌÐò¡£¡£¡£¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýScreenConnect»ñȡԶ³Ì»á¼ûȨÏÞ£¬£¬£¬£¬£¬ £¬£¬²¢Æô¶¯¼üÅ̼ͼ»î¶¯Ö´ÐÐVBScriptÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£¡£¸Ã¾ç±¾Í¨¹ýPowerShell´Ó¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷ÏÂÔØÁ½¸öÍâ²¿ÔØºÉ£º"logs.ldk"£¨DLLÎļþ£©ºÍ"logs.ldr"£¨»ìÏý×é¼þ£©¡£¡£¡£¡£¡£¡£¡£DLLÎļþÈÏÕæ½«VB¾ç±¾Ð´Èë´ÅÅÌ£¬£¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃÍýÏëʹÃüαװ³É"Skype¸üгÌÐò"£¬£¬£¬£¬£¬ £¬£¬ÔÚÿ´ÎϵͳµÇ¼ʱ×Ô¶¯Ö´ÐУ¬£¬£¬£¬£¬ £¬£¬ÊµÏÖÒþ²Ø³¤ÆÚ»¯¡£¡£¡£¡£¡£¡£¡£½øÒ»²½ÆÊÎöÏÔʾ£¬£¬£¬£¬£¬ £¬£¬PowerShell¾ç±¾½«"logs.ldk"¼ÓÔØÎª.NET³ÌÐò¼¯£¬£¬£¬£¬£¬ £¬£¬²¢´«Èë"logs.ldr"×÷Ϊ²ÎÊý£¬£¬£¬£¬£¬ £¬£¬×îÖÕÖ´ÐÐAsyncRATµÄ½¹µãÓÐÓøºÔØ"AsyncClient.exe"¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí¾ß±¸¶àÏî¸ßΣ¹¦Ð§£º¼Í¼»÷¼ü¡¢ÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢ÊÕÂÞÏµÍ³Ö¸ÎÆ¡¢É¨Ãè¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬£¬ £¬£¬²¢Í¨¹ýTCPÌ×½Ó×Ö½«Êý¾Ý»Ø´«ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2025/09/asyncrat-exploits-connectwise.html


3. Vyro AIÊý¾Ýй¶£¬£¬£¬£¬£¬ £¬£¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì


9ÔÂ10ÈÕ£¬£¬£¬£¬£¬ £¬£¬Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬ £¬£¬°Í»ù˹̹AI¹«Ë¾Vyro AIÒòδÊܱ£»£»£»£»¤µÄElasticsearchʵÀýй¶116GBÓû§ÈÕÖ¾£¬£¬£¬£¬£¬ £¬£¬Éæ¼°Èý¿îÈÈÃÅÓ¦ÓãºGoogle PlayÏÂÔØÁ¿³¬1000Íò´ÎµÄImagineArt¡¢³¬10Íò´ÎÏÂÔØµÄChatly¼°Ô»á¼ûÔ¼5Íò´ÎµÄChatbotx¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ðû³Æ×ÜÏÂÔØÁ¿³¬1.5ÒڴΣ¬£¬£¬£¬£¬ £¬£¬Ã¿ÖÜÌìÉú350ÍòÕÅͼƬ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ýº­¸Ç2-7ÌìµÄÉú²úÓ뿪·¢ÈÕÖ¾£¬£¬£¬£¬£¬ £¬£¬°üÀ¨Óû§AIÌáÐÑ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢Óû§ÊðÀíµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â×Ô2ÔÂÖÐÑ®±»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼£¬£¬£¬£¬£¬ £¬£¬¿ÉÄÜÒѱ»¹¥»÷Õß·¢Ã÷ÊýÔ¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶Σº¦ÏÔÖø£º¹¥»÷Õß¿ÉʹÓÃÁîÅÆÐ®ÖÆÓû§ÕË»§£¬£¬£¬£¬£¬ £¬£¬»á¼û̸Ìì¼Í¼¡¢ÌìÉúͼÏñ£¬£¬£¬£¬£¬ £¬£¬ÉõÖÁÀÄÓÃAI´ú±Ò¾ÙÐв»·¨ÉúÒ⣻£»£»£»Óû§ÓëAIµÄ˽ÃܶԻ°¿ÉÄÜ̻¶´Óδ¹ûÕæµÄÃô¸ÐÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬ £¬£¬ImagineArtµÄ3000Íò»îÔ¾Óû§Êý¾ÝÈô±»Ê¹Ó㬣¬£¬£¬£¬ £¬£¬½«µ¼Ö´ó¹æÄ£ÕË»§½ÓÊÜΣº¦¡£¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/ai-chatbots-vyro-data-leak/


4. Allegis GroupÔâEverestÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ £¬£¬°ÙÍò¼¶¿Í»§Êý¾Ýй¶


9ÔÂ10ÈÕ£¬£¬£¬£¬£¬ £¬£¬È«Çò×î´óÈ˲ÅÖÎÀí¼¯ÍÅÖ®Ò»¡¢ÄêÊÕÈë½ü100ÒÚÃÀÔªµÄAllegis Group¿ËÈÕÔâÓöEverestÀÕË÷Èí¼þÍŻ﹥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÉÏÐû³Æ»ñÈ¡ÁËAllegisÄÚ²¿Îļþ¼°¿Í»§Ãûµ¥£¬£¬£¬£¬£¬ £¬£¬²¢Ðû²¼Á½ÕÅExcelÎĵµ½ØÍ¼×÷Ϊ֤¾Ý£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÒ»ÕŰüÀ¨13.5ÍòÌõ¿Í»§ÐÅÏ¢£ºÐÕÃû¡¢ÓÊÏä¡¢µç»°£¬£¬£¬£¬£¬ £¬£¬ÁíÒ»ÕŰüÀ¨¶à´ï42.6ÍòÌõÀàËÆÊý¾Ý¡£¡£¡£¡£¡£¡£¡£´ËÀàÐÅÏ¢¿ÉÄܱ»Ê¹ÓþÙÐÐÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£EverestÍÅ»ïÓë¶íÂÞ˹¹ØÁª£¬£¬£¬£¬£¬ £¬£¬×Ô2021Äê»îÔ¾ÒÔÀ´ÒѳÉΪ×î·Å×ݵÄÀÕË÷×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¡£¡£¾Ý°µÍø¼à¿Ø¹¤¾ßRansomlookerͳ¼Æ£¬£¬£¬£¬£¬ £¬£¬¸ÃÍÅ»ïÒÑÍù12¸öÔ¹¥»÷Á˳¬°Ù¸ö×éÖ¯£¬£¬£¬£¬£¬ £¬£¬·ÖÅúй¶Êý¾ÝÊÇÆäµä·¶Ê©Ñ¹ÊֶΣ¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£AllegisÆìÏÂÓµÓÐAerotek¡¢TEKsystems¡¢MarketSourceµÈ¶à¼ÒרҵÈ˲ÅÖÎÀí×Ó¹«Ë¾£¬£¬£¬£¬£¬ £¬£¬Ð§ÀÍÍøÂçÁýÕÖÈ«Çò¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¹«Ë¾ÒÑ»ØÓ¦³Æ½«¸üÐÂÏ£Íû£¬£¬£¬£¬£¬ £¬£¬µ«¹¥»÷ÕßÌá¼°µÄ¡°ÖÖÀà·±¶àµÄСÎÒ˽¼ÒÎĵµ¡±ÉÐδ¹ûÕæÑù±¾£¬£¬£¬£¬£¬ £¬£¬Ç±ÔÚΣº¦¿ÉÄÜÔ¶³¬ÒÑÆØ¹âµÄÁªÏµÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/allegis-group-data-breach-claims/


5. AkiraÀÕË÷Èí¼þÍÅ»ïʹÓÃSonicWallÎó²îÌᳫÐÂÒ»ÂÖ¹¥»÷


9ÔÂ11ÈÕ£¬£¬£¬£¬£¬ £¬£¬AkiraÀÕË÷Èí¼þÍÅ»ïÕýÆð¾¢Ê¹ÓÃCVE-2024-40766ÕâÒ»Òѱ£´æÒ»ÄêµÄÑÏÖØ»á¼û¿ØÖÆÎó²î£¬£¬£¬£¬£¬ £¬£¬¶ÔδÐÞ²¹µÄSonicWall SSL VPN×°±¸Ìᳫ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíδ¾­ÊÚȨµÄ×ÊÔ´»á¼û£¬£¬£¬£¬£¬ £¬£¬ÉõÖÁ¿ÉÄܵ¼Ö·À»ðǽÍ߽⡣¡£¡£¡£¡£¡£¡£SonicWallÔçÔÚ2024Äê8Ô±ãÐû²¼Á˲¹¶¡£¬£¬£¬£¬£¬ £¬£¬²¢Ç¿µ÷¸üÐÂʱÐèΪÍâµØÖÎÀíµÄSSLVPNÕË»§Óû§ÖØÖÃÃÜÂ룬£¬£¬£¬£¬ £¬£¬µ«²¿·Ö×é֯δ³¹µ×Ö´Ðе÷½â²½·¥£¬£¬£¬£¬£¬ £¬£¬µ¼ÖÂÍþвÐÐΪÕßÈÔÄÜʹÓÃ̻¶µÄƾ֤ÉèÖöàÒòËØÉí·ÝÑéÖ¤£¨MFA£©»ò»ùÓÚʱ¼äµÄÒ»´ÎÐÔÃÜÂ루TOTP£©ÏµÍ³£¬£¬£¬£¬£¬ £¬£¬½ø¶ø»ñÈ¡»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©ÓÚ2025Äê9Ô·¢³ö¾¯±¨£¬£¬£¬£¬£¬ £¬£¬Ö¸³ö°Ä´óÀûÑǾ³ÄÚÕë¶Ô¸ÃÎó²îµÄ×Ô¶¯Ê¹ÓûÏÔÖøÔöÌí£¬£¬£¬£¬£¬ £¬£¬²¢Ã÷È·½«AkiraÀÕË÷Èí¼þÓëSonicWall SSL VPN¹¥»÷¹ØÁª¡£¡£¡£¡£¡£¡£¡£ÍøÂçÇå¾²¹«Ë¾Rapid7Ò²ÊӲ쵽ÀàËÆÇ÷ÊÆ£¬£¬£¬£¬£¬ £¬£¬ÒÔΪ¹¥»÷¼¤Ôö¿ÉÄÜÓë²»ÍêÕûµÄµ÷½â²½·¥ÓйØ£¬£¬£¬£¬£¬ £¬£¬ÏêϸÈëÇÖÊֶΰüÀ¨Ê¹ÓÃĬÈÏÓû§×éµÄÆÕ±é»á¼ûȨÏÞ¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°Í¨¹ýSonicWall×°±¸ÉÏÐéÄâ°ì¹«ÊÒÃÅ»§µÄĬÈϹ«¹²»á¼ûȨÏÞʵÑé¹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/


6. LNERµÚÈý·½¹©Ó¦ÉÌÔâÍøÂç¹¥»÷ÖÂÂÿÍÊý¾Ýй¶


9ÔÂ11ÈÕ£¬£¬£¬£¬£¬ £¬£¬Ó¢¹úÁгµÔËÓªÉÌÂ׶ض«±±Ìú·¹«Ë¾£¨LNER£©ÓÚ9ÔÂ10ÈÕÈ·ÈÏ£¬£¬£¬£¬£¬ £¬£¬ÆäµÚÈý·½¹©Ó¦ÉÌÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬£¬ £¬£¬µ¼Ö²¿·ÖÂÿ͵ÄÁªÏµ·½·¨¼°¹ýÍùÐгÌÊý¾Ýй¶£¬£¬£¬£¬£¬ £¬£¬µ«Î´Éæ¼°²ÆÎñÐÅÏ¢¡¢ÃÜÂë»òÖ§¸¶¿¨Êý¾Ý¡£¡£¡£¡£¡£¡£¡£LNERÇ¿µ÷£¬£¬£¬£¬£¬ £¬£¬ÆäÁгµÐ§ÀÍ¡¢ÊÛÆ±ÏµÍ³ÊµÊ±¿Ì±í¾ùÕý³£ÔËÐУ¬£¬£¬£¬£¬ £¬£¬²¢ÒÑÓëÍøÂçÇ徲ר¼ÒºÍÏà¹Ø¹©Ó¦ÉÌÏàÖúÊÓ²ìÊÂÎñȫò£¬£¬£¬£¬£¬ £¬£¬Í¬Ê±ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒÒÔÆÀ¹ÀÊÇ·ñÇкϡ¶Í¨ÓÃÊý¾Ý±£»£»£»£»¤ÌõÀý¡·£¨GDPR£©µÄ±¨¸æÒªÇ󣬣¬£¬£¬£¬ £¬£¬Èô°ü¹Ü²½·¥È±·¦¿ÉÄÜÃæÁÙ·£¿£¿ £¿£¿£¿ £¿î¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÄܱ»ÓÃÓÚ¹¹½¨ÏêϸСÎÒ˽¼Ò»­Ïñ£¬£¬£¬£¬£¬ £¬£¬½ø¶øÌᳫ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Èçͨ¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òWhatsAppÓÕÆ­Óû§Ìṩ²ÆÎñ»òСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£LNERÒѱ޲ßÂÿͶÔÒâÍâͨѶ¼á³ÖСÐÄ£¬£¬£¬£¬£¬ £¬£¬ÓÈÆäÉæ¼°Ð¡ÎÒ˽¼ÒÐÅÏ¢ÇëÇóµÄÓʼþ»òÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬ÇÐÎðÈÝÒ׻ظ´¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÌåÏÖ½«¸ß¶ÈÖØÊÓ´ËÊ£¬£¬£¬£¬£¬ £¬£¬Ò»Á¬Óëר¼ÒÏàÖú²¢½ÓÄɰü¹Ü²½·¥£¬£¬£¬£¬£¬ £¬£¬ºóÐø½«Ìṩ¸ü¶à¸üÐÂÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://hackread.com/uk-rail-operator-lner-cyber-attack-passenger-data/