SynnovisÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂNHS»¼ÕßÊý¾Ýй¶
Ðû²¼Ê±¼ä 2025-11-141. SynnovisÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ÖÂNHS»¼ÕßÊý¾Ýй¶
11ÔÂ12ÈÕ£¬£¬£¬£¬Ó¢¹ú²¡ÀíЧÀÍÌṩÉÌSynnovisÓÚ2024Äê6ÔÂÔâÊÜ÷è÷ëÀÕË÷Èí¼þÍŻ﹥»÷£¬£¬£¬£¬µ¼Ö²¿·Ö»¼ÕßÊý¾Ý±»µÁ£¬£¬£¬£¬Éæ¼°NHSºÅÂë¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¼°²¿·Ö¿ÉÆ¥ÅäµÄ¼ì²âЧ¹û¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾½¨ÉèÓÚ2021Ä꣬£¬£¬£¬Óɹú¼ÊÒ½ÁÆÕï¶ÏÉÌSYNLABÓë¸ÇÒÁºÍÊ¥ÍÐÂí˹NHS»ù½ð»áÐÅÍС¢¹úÍõѧԺҽԺNHS»ù½ð»áÐÅÍÐÏàÖúÔËÓª£¬£¬£¬£¬Îª°üÀ¨NHSÔÚÄÚµÄÓ¢¹úÒ½ÁÆ»ú¹¹Ìṩ²¡ÀíЧÀÍ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ôì³ÉÂ׶ضà¼ÒNHSÒ½ÔºÔËÓªÑÏÖØÊÜ×裬£¬£¬£¬°üÀ¨¹úÍõѧԺҽԺ¡¢Ê¥ÍÐÂí˹ҽԺµÈ£¬£¬£¬£¬µ¼Ö·ǽôÆÈ²¡Àí¼ì²éÔ¤Ô¼ºÍÊäѪЧÀÍ×÷·Ï»òÑÓ³Ù£¬£¬£¬£¬Òý·¢ÑªÒºÇ·È±£¬£¬£¬£¬³¬800ÀýÊÖÊõºÍ700ÀýÃÅÕïÔ¤Ô¼±»ÆÈ×÷·Ï¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔøÓÚ2024Äê6ÔÂ20ÈÕй¶²¿·ÖÊý¾Ý£¬£¬£¬£¬´ÙʹSynnovisÏòÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ±¨¸æ²¢»ñÖ´·¨½ûÁ£¬£¬£¬Õ¥È¡½øÒ»²½Ê¹Óñ»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Êý¾ÝÊÓ²ìÀúʱһÄê¶à£¬£¬£¬£¬ÓÉ·¨Ö¤×¨¼ÒÍŶÓÍê³É£¬£¬£¬£¬ÒòÊý¾Ý½á¹¹ÔÓÂÒ¡¢²»ÍêÕûÇÒÁãÐÇ£¬£¬£¬£¬Ðè¶¨ÖÆ»¯Á÷³Ì´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£SynnovisÌåÏÖ£¬£¬£¬£¬´ó²¿·Ö±»µÁÐÅÏ¢ÐèÁÙ´²ÖªÊ¶»òÔö²¹ÐÅÏ¢²Å»ª½â¶Á£¬£¬£¬£¬ÏÖÔÚÒÑÆô¶¯ÊÜÓ°Ïì»ú¹¹Í¨Öª³ÌÐò£¬£¬£¬£¬Ô¤¼Æ2025Äê11ÔÂ21ÈÕÍê³É£¬£¬£¬£¬µ«²»»áÖ±½ÓÁªÏµ»¼Õߣ¬£¬£¬£¬ÓÉNHS»ú¹¹ÈÏÕæ»¼Õß֪ͨ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/synnovis-notifies-of-data-breach-after-2024-ransomware-attack/
2. CISA½«WatchGuard FirewareÎó²îÄÉÈëÒÑ֪ʹÓÃĿ¼
11ÔÂ13ÈÕ£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ÓÚÖÜÈý½«Ó°ÏìWatchGuard FirewareµÄCVE-2025-9242ÑÏÖØÎó²îÌí¼ÓÖÁÆäÒÑ֪ʹÓÃÎó²î£¨KEV£©Ä¿Â¼£¬£¬£¬£¬¸ÃÎó²îÒѱ»Ö¤ÊµÔâµ½Æð¾¢Ê¹Óᣡ£¡£¡£¡£¡£¡£CVE-2025-9242ΪԽ½çдÈëÎó²î£¬£¬£¬£¬CVSSÆÀ·Ö¸ß´ï9.3£¬£¬£¬£¬Ó°ÏìFireware OS 11.10.2ÖÁ11.12.4_Update1¡¢12.0ÖÁ12.11.3¼°2025.1°æ±¾¡£¡£¡£¡£¡£¡£¡£¾ÝCISAͨ¸æ£¬£¬£¬£¬¸ÃÎó²îÔÊÐíÔ¶³ÌδÊÚȨ¹¥»÷ÕßÔÚ²Ù×÷ϵͳÏà¹ØÀú³ÌÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬ÍþвÐÔ¼«¸ß¡£¡£¡£¡£¡£¡£¡£Îó²îȪԴÔÚÓÚIKEÎÕÊÖÀú³ÌÖÐÉí·Ý»º³åÇøÈ±·¦³¤¶È¼ì²é£¬£¬£¬£¬ÇÒÖ¤ÊéÑéÖ¤ÔÚÒ×Êܹ¥»÷´úÂëÖ´Ðкó²Å¾ÙÐУ¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÈÆ¹ýÈÏÖ¤Ö±½Ó´¥·¢Îó²î¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±McCaulay HudsonÖ¸³ö£¬£¬£¬£¬ÕâÖÖÉè¼ÆÈ±ÏÝʹ¹¥»÷·¾¶ÔÚÉí·ÝÑé֤ǰ¼´¿É±»Ê¹Óᣡ£¡£¡£¡£¡£¡£×èÖ¹2025Äê11ÔÂ12ÈÕ£¬£¬£¬£¬È«ÇòÈÔÓÐÁè¼Ý54,300¸öFirebox×°±¸±£´æ´ËÎó²î£¬£¬£¬£¬½Ï10ÔÂ19ÈÕµÄ75,955̨ÓÐËùϽµ¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬ÃÀ¹úÒÔ18,500̨¾ÓÊ×£¬£¬£¬£¬Òâ´óÀû£¨5,400̨£©¡¢Ó¢¹ú£¨4,000̨£©¡¢µÂ¹ú£¨3,600̨£©ºÍ¼ÓÄôó£¨3,000̨£©Î»ÁÐǰÎå¡£¡£¡£¡£¡£¡£¡£Áª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©ÒªÇó¸÷»ú¹¹ÔÚ2025Äê12ÔÂ3ÈÕǰÍê³ÉWatchGuard²¹¶¡×°Öᣡ£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/11/cisa-flags-critical-watchguard-fireware.html
3. ¹ú¼ÊÁªºÏÐж¯¡°ÖÕ¾ÖÐж¯¡±ÖØ´´¶ñÒâÈí¼þ
11ÔÂ10ÈÕÖÁ14ÈÕ£¬£¬£¬£¬ÓÉÅ·ÖÞÐ̾¯×éÖ¯ºÍÅ·ÖÞ˾·¨×é֯е÷¡¢¾Å¹úÖ´·¨²¿·ÖÁªºÏ¿ªÕ¹µÄ¡°ÖÕ¾ÖÐж¯¡±×îн׶ÎÈ¡µÃÍ»ÆÆÐÔЧ¹û£¬£¬£¬£¬´Ý»Ù1025̨ÓÃÓÚRhadamanthysÐÅÏ¢ÇÔÈ¡Æ÷¡¢VenomRAT¼°Elysium½©Ê¬ÍøÂçÔËÓªµÄЧÀÍÆ÷£¬£¬£¬£¬²é·â20¸öÓòÃû£¬£¬£¬£¬²¢ÔÚÏ£À°¾Ð²¶Ò»ÃûÓëVenomRATÏà¹ØµÄÏÓÒÉÈË¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐж¯»ñµÃCryptolaemus¡¢ShadowserverµÈ12¼Ò˽ÈË»ú¹¹Ö§³Ö£¬£¬£¬£¬Í¬²½¹¥»÷ÀÕË÷Èí¼þ¡¢AVCheckÍøÕ¾¼°SmokeloaderµÈ½©Ê¬ÍøÂç»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¾ÝÅ·ÖÞÐ̾¯×éÖ¯Åû¶£¬£¬£¬£¬±»´Ý»ÙµÄ¶ñÒâÈí¼þ»ù´¡ÉèÊ©Éæ¼°ÊýÊ®Íǫ̀ÊÜѬȾÅÌËã»ú£¬£¬£¬£¬°üÀ¨Êý°ÙÍòÌõ±»µÁƾ֤¡£¡£¡£¡£¡£¡£¡£Ö÷ÒªÏÓÒÉÈ˿ɻá¼û³¬10Íò¸ö¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬×ʲú¼ÛÖµ»ò´ïÊý°ÙÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£´ó¶¼Êܺ¦Õßδ²ì¾õϵͳÒÑÔâÈëÇÖ¡£¡£¡£¡£¡£¡£¡£Ö´·¨»ú¹¹½¨Ò鹫ÖÚͨ¹ýpolitie.nl/checkyourhackºÍhaveibeenpwned.comºË²éÊÇ·ñÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐж¯ÑÓÐøÁË¡°ÖÕ¾ÖÐж¯¡±¶Ô¿ç¹úÍøÂç·¸·¨µÄÒ»Á¬¹¥»÷Ì¬ÊÆ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/police-disrupts-rhadamanthys-venomrat-and-elysium-malware-operations/
4. AkiraÀÕË÷Èí¼þ¼ÓÃÜNutanixÐéÄâ»ú²¢À©Õ¹¹¥»÷ÄÜÁ¦
11ÔÂ13ÈÕ£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¡¢Áª°îÊÓ²ì¾Ö£¨FBI£©µÈ»ú¹¹ÁªºÏÐû²¼Í¨¸æ£¬£¬£¬£¬Ö¸³öAkiraÀÕË÷Èí¼þÒÑÀ©Õ¹¼ÓÃÜÄÜÁ¦ÖÁNutanix AHVÐéÄâ»ú´ÅÅÌÎļþ£¬£¬£¬£¬²¢Åû¶×îй¥»÷ϸ½Ú¡£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ×Ô2025Äê6ÔÂÆð×îÏÈÕë¶ÔNutanix AHVƽ̨µÄ.qcow2ÃûÌÃÐéÄâ´ÅÅÌÎļþʵÑé¼ÓÃÜ£¬£¬£¬£¬Í¨¹ýÀÄÓÃSonicWallÎó²î£¨CVE-2024-40766£©Í»ÆÆ»á¼û¿ØÖÆ£¬£¬£¬£¬½«¹¥»÷¹æÄ£´ÓVMware ESXiºÍHyper-VÀ©Õ¹ÖÁNutanix AHV¡£¡£¡£¡£¡£¡£¡£Nutanix AHV×÷Ϊ»ùÓÚLinuxµÄÐéÄ⻯½â¾ö¼Æ»®£¬£¬£¬£¬ÆäÆÕ±é°²ÅÅʹÆä³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄÐÂÄ¿µÄ£¬£¬£¬£¬ÀàËÆ´Ëǰ¶ÔVMware ESXiºÍHyper-VµÄ¹¥»÷ģʽ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ³£Ê¹ÓÃ̻¶װ±¸µÄVPN/SSHƾ֤»ò·À»ðǽÎó²î£¨ÈçCVE-2024-40766£©ÈëÇÖÆóÒµÍøÂ磬£¬£¬£¬Ëæºóͨ¹ýδÐÞ²¹µÄVeeam±¸·ÝЧÀÍÆ÷Îó²î£¨CVE-2023-27532¡¢CVE-2024-40711£©É¾³ý±¸·ÝÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÔÚÉøÍ¸ºó£¬£¬£¬£¬¹¥»÷ÕßʹÓÃnltest¡¢AnyDesk¡¢LogMeIn¡¢ImpacketµÈ¹¤¾ß¾ÙÐÐÕì̽ºÍºáÏòÒÆ¶¯£¬£¬£¬£¬½¨ÉèÖÎÀíÕË»§ÊµÏÖ³¤ÆÚ»¯£¬£¬£¬£¬²¢ÒƳý¶Ëµã¼ì²â¹¤¾ßÒÔ¹æ±Ü·ÀÓù¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cisa-warns-of-akira-ransomware-linux-encryptor-targeting-nutanix-vms/
5. npm¡°IndonesianFoods¡±È䳿£¬£¬£¬£¬Ãë¼¶×ÔÈö²¥Íò°ü¹¥»÷¹©Ó¦Á´
11ÔÂ13ÈÕ£¬£¬£¬£¬npm×¢²á±íÔâÓöÃûΪ¡°IndonesianFoods¡±µÄ×ÔÈö²¥È䳿¹¥»÷£¬£¬£¬£¬¸ÃÈä³æÃ¿ÆßÃë×Ô¶¯ÌìÉúÐÂÈí¼þ°ü£¬£¬£¬£¬ÒÑÀÛ¼ÆÐû²¼³¬10Íò¸öÓ¡ÄáÓïÃüÃû£¨Èç¡°fajar-donat9-breki¡±£©µÄÀ¬»ø°ü£¬£¬£¬£¬ÇÒÊýÄ¿³ÊÖ¸Êý¼¶ÔöÌí¡£¡£¡£¡£¡£¡£¡£¾ÝSonatypeÆÊÎö£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¸ß×Ô¶¯»¯¾ç±¾Ò»Á¬ºäÕ¨¿ªÔ´Éú̬ϵͳ£¬£¬£¬£¬ËäÄ¿½ñ°üÌå맪¶ñÒâ×é¼þ£¬£¬£¬£¬µ«Î´À´¿ÉÄÜǶÈëÊý¾ÝÇÔÈ¡»òºóÃųÌÐò£¬£¬£¬£¬×é³ÉDZÔÚÍþв¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷·ºÆðÈý´óÌØÕ÷£ºÒ»ÊǹæÄ£»£»£»£»¯ÆÆË𣬣¬£¬£¬µ¥ÈÕ´¥·¢ÑÇÂíÑ·Îó²î¼ì²â¹¤¾ßÌìÉú7.2ÍòÌõÎó²î±¨¸æ£¬£¬£¬£¬¶à¸öÇ徲ϵͳÒòÊý¾ÝºéÁ÷±ôÁÙ̱»¾£»£»£»£»¶þÊǾ¼ÃÄîÍ·ÏÔ×Å£¬£¬£¬£¬¹¥»÷ÕßʹÓÃTEAÇø¿éÁ´ÐÒ飬£¬£¬£¬ÔÚ°üÖÐǶÈëtea.yamlÎļþ¹ØÁª´ú±ÒÇ®°ü£¬£¬£¬£¬Í¨¹ýÇ¿µ÷°ü¼ä¹ØÁª¶ÈÌáÉýÓ°Ïì·ÖÊýÒÔ׬ȡ´ú±ÒÊÕÒæ£»£»£»£»ÈýÊÇÀúÊ·ÑݽøÇåÎú£¬£¬£¬£¬×Ô2023ÄêÆðÒÑÀÛ¼ÆÐû²¼4.3Íò°ü£¬£¬£¬£¬2024ÄêÒýÈëTEAÇ®±Ò»¯»úÖÆ£¬£¬£¬£¬2025ÄêÉý¼¶ÎªÈä³æÊ½¸´ÖÆÑ»·¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-indonesianfoods-worm-floods-npm-with-100-000-packages/
6. ¡¶»ªÊ¢¶ÙÓʱ¨¡·Êý¾Ýй¶ÊÂÎñÓ°Ïì½üÍòÃûÔ±¹¤ºÍ³Ð°üÉÌ
11ÔÂ13ÈÕ£¬£¬£¬£¬¡¶»ªÊ¢¶ÙÓʱ¨¡·¿ËÈÕ֪ͨԼ9720ÃûÔ±¹¤¼°³Ð°üÉÌ£¬£¬£¬£¬ÆäСÎÒ˽¼ÒºÍ²ÆÎñÊý¾ÝÔÚOracle E-Business SuiteÁãÈÕÎó²î¹¥»÷ÖÐÔâй¶¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ±¬·¢ÓÚ2025Äê7ÔÂ10ÈÕÖÁ8ÔÂ22ÈÕ£¬£¬£¬£¬¹¥»÷ÕßʹÓøÃERPƽ̨µÄÈËÁ¦×ÊÔ´¡¢²ÆÎñºÍ¹©Ó¦Á´ÖÎÀí¹¦Ð§ÖеÄδÐÞ²¹Îó²î£¨ºó±»×·×ÙΪCVE-2025-61884£©£¬£¬£¬£¬ÇÔÈ¡Á˰üÀ¨È«Ãû¡¢ÒøÐÐÕ˺š¢Â·ÓɺÅÂë¡¢Éç»áÇå¾²ºÅÂ루SSN£©¡¢Ë°Îñ¼°Éí·ÝÖ¤ºÅÂëµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£9ÔÂÏÂÑ®£¬£¬£¬£¬ºÚ¿ÍÊÔͼÒÔ´ËÀÕË÷¸Ã±¨£¬£¬£¬£¬¶ø¼×¹ÇÎĹ«Ë¾ÔÚÊÓ²ìʱ´úÅû¶ÁËÕâÒ»ÆÕ±é±£´æµÄÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£×÷ΪÃÀ¹ú¿¯ÐÐÁ¿×î´óµÄÈÕ±¨Ö®Ò»£¬£¬£¬£¬¡¶»ªÊ¢¶ÙÓʱ¨¡·ÓµÓÐÔ¼250ÍòÊý×Ö¶©ÔÄÓû§¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃͳһÎó²îµÄÊܺ¦Õß»¹°üÀ¨¹þ·ð´óѧ¡¢ÃÀ¹úº½¿Õ×Ó¹«Ë¾Envoy Air¼°ÈÕÁ¢ÆìÏÂGlobalLogicµÈ»ú¹¹¡£¡£¡£¡£¡£¡£¡£ClopÀÕË÷Èí¼þ×éÖ¯±»Ö¸ÓëÕâЩ¹¥»÷Óйأ¬£¬£¬£¬ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÁгöÁ˸ü¶àÊÜÓ°Ïì×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡¶»ªÊ¢¶ÙÓʱ¨¡·µÄÊÓ²ìÓÚ10ÔÂ27ÈÕ¿¢Ê£¬£¬£¬£¬È·ÈÏÊý¾Ýй¶ºó£¬£¬£¬£¬ÊÜÓ°ÏìСÎÒ˽¼Òͨ¹ýIDX»ñµÃ12¸öÔÂÃâ·ÑÉí·Ý±£»£»£»£»¤Ð§ÀÍ£¬£¬£¬£¬²¢±»½¨Òé¶³½áÐÅÓõµ°¸¼°ÉèÖÃڲƾ¯±¨¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/washington-post-data-breach-impacts-nearly-10k-employees-contractors/


¾©¹«Íø°²±¸11010802024551ºÅ