RiteCheck CashingÊý¾Ýй¶ӰÏ쳬6.8ÍòÈË

°ä²¼¹¦·ò 2025-08-01

1. RiteCheck CashingÊý¾Ýй¶ӰÏ쳬6.8ÍòÈË


7ÔÂ30ÈÕ £¬Å¦Ô¼½ðÈÚ·þÎñÌṩÉÌRiteCheck Cashing½üÈÕÏò³¬¹ý6.8ÍòÃû¿Í»§¼°Ô±¹¤·¢³öÊý¾Ýй¶֪ͨ £¬Åû¶Æä·þÎñÆ÷ÓÚ2024Äê8Ôµ×Ô⡰δ¾­ÊÚȨÓû§¡±ÈëÇÖ £¬µ«ÊÜÓ°Ïì·½Ö±ÖÁ±¾ÖܲŻñϤ´ËÊ¡£Õâ´ÎÊÂÎñÒò֪ͨÑÓ³¤³¤´ï11¸öÔÂÒý·¢ÕùÒé £¬Â¶³ö³öÃô¸ÐÓ×ÎÒÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕպ𢵱¾ÖÉí·ÝÖ¤ºÅ¼°Ö§¸¶¿¨ºÅµÈ £¬¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ¡¢Ú²Æ­ÐÔ´û¿î»òÕË»§ÊÕÊܵȷ¸·¨»î¶¯¡£Æ¾¾ÝRiteCheckÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄÎļþ £¬Ð¹Â¶ÊÂÎñÔ´ÓÚ¹¥»÷Õß¶ÔÆä·þÎñÆ÷µÄ·¸·¨½Ó¼û¡£Ö»¹Ü֪ͨÖÐÇ¿µ÷¡°½ö²¿Ãſͻ§ºÍÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÊÜÓ°Ï족 £¬²¢³Æ¡°¿ÉÄÜй¶µÄΪÐÕÃû¼°Ò»Ïî»ò¶àÏîÆäËûÐÅÏ¢¡± £¬µ«ÏÖÊµÉæ¼°µÄÊý¾ÝÀàÐ;ùΪ¸ßÃô¸Ð×Ö¶Î £¬ÓÈÆäÊÇÖ§¸¶¿¨ºÅµÄй¶ £¬ÔÚÍøÂç·¸×ïÖÐÓµÓм«¸ßÀûÓüÛÖµ¡£¸üÑϸñµÄÊÇ £¬³¤´ï11¸öÔµĵ÷²éÖÜÆÚʹ¹¥»÷ÕßÕ¼Óгä×㹦·òÀÄÓñ»µÁÊý¾Ý £¬ÏÔÖø¼Ó¾çÁËÊܺ¦ÕßµÄÒþÖÔ·çÏÕ¡£ÎªÓ¦¶ÔÕâ´ÎÊÂÎñ £¬RiteCheck°µÊ¾ÒѲÉÈ¡¶àÏî²¹¾È´ëÊ© £¬Ô̺¬Ç¿Ôì¸ü¸ÄÓû§ÕË»§ÃÜÂë¡¢²¿ÊðÍþв¼ì²âÓë¶Ëµã¼à¿Ø¹¤¾ß £¬²¢ÎªÊÜÓ°Ïì·½Ìṩ12¸öÔµÄÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý±£»¤·þÎñ¡£


https://cybernews.com/security/ritecheck-data-breach-thousands-exposed/


2. FTX Japan¹Ø¹Øºóй¶³¬3.5ÍòÓû§Êý¾Ý


7ÔÂ30ÈÕ £¬¼ÓÃÜÆ½Ì¨FTX JapanÔڹعØÒ»Äê¶àºó £¬±»ÆØÐ¹Â¶³¬¹ý35,000ÃûÓû§µÄÓ×ÎÒ¼°²ÆÕþÊý¾Ý £¬Â¶³öÆäºó¶Ë»ù´¡ÉèÊ©¿ÉÄÜδ³¹µ×Í£ÔË¡£2025Äê5ÔÂ12ÈÕ £¬×êÑÐÈËÔ±·¢ÏÖÓëFTX JapanÓйصÄAmazon S3´æ´¢Í°´æÔÚÊý¾Ýй¶ £¬¸Ã´æ´¢Í°Ô̺¬³¬2600Íò¸öÎļþ £¬ÆäÖв¿ÃÅÎļþΪ2024Äê7ÔÂÌìÉúµÄHTMLÌåʽ²ÆÕþ»ã±¨¡¢ÈÕÖ¾¼°Óû§Êý¾Ý¡£ÕâÅú×¢ £¬Ö»¹ÜFTX JapanÔÚ2023ËêÊ×ʵÏÖÓû§Ìá¿î²¢ÊµÏÖÔËÓª £¬Æä×Ô¶¯»ã±¨ÏµÍ³µÈºó¶ËÁ÷³ÌÈÔÔÚ2024Äê³ÖÐøÔËÐÐ £¬Òý·¢¶Ôϵͳ¹Ø¹Ø²»³¹µ×µÄÖÊÒÉ¡£Õâ´Îй¶µÄÊý¾Ýº­¸Ç35,668¸öΨһÓû§±êʶ·û £¬ÕâЩ±êʶ·û°´µç×ÓÓʼþµØÖ·»òAuth0Óû§ID·ÖÀà £¬Éæ¼°Ãô¸ÐÐÅÏ¢Ô̺¬Óû§Ãû¡¢ÕæÊµÐÕÃû¡¢¾ÓסµØÖ·¡¢FTXÕË»§ID¼°¾ßÌåµÄÂòÂô¼Í¼£¨½è´ûº¹Çà¡¢¼ÓÃÜÇ®±ÒÀàÐÍ¡¢±£ÕϽðÂʵȣ© £¬²¿ÃÅÊý¾ÝÉõÖÁÔ̺¬ËãÕÊÖҸ桢±£ÕϽð·çÏÕ´¥·¢µÈÕË»§×´Ì¬Ö¸±ê¡£ÕâЩÐÅÏ¢Èô±»¶ñÒâÀûÓà £¬¿ÉÄÜÓÃÓÚÉí·Ý͵ÇÔ¡¢¾«×¼Ú¿Æ­»òÊг¡°Ñ³Ö £¬¶ÔÓû§ÒþÖÔ¼°²ÆÕþ°²È«×é³É³Á´óÍþв¡£


https://cybernews.com/security/ftx-japan-data-leak-2025/


3. Ó¢¹úÀ×´ïϵͳ¹ÊÕÏÖ°ÙÓຽ°àÈ¡µÞ


7ÔÂ30ÈÕ £¬Ó¢¹ú¹ú¶È¿ÕÖн»Í¨·þÎñ¾Ö£¨NATS£©ÒòÀ×´ïϵͳ³öÏÖ¡°¼¼ÊõÎÊÌ⡱ £¬µ¼ÖÂÂ×¶Ø¡¢°®¶¡±¤µÈ¶àµØ»ú³¡¿ÕÖн»Í¨ÑϳÁÖжÏ £¬Ó¢¹úº½¿Õ¹«Ë¾±»ÆÈÈ¡µÞ³¬100¸öº½°à £¬´óÁ¿³Ë¿ÍÔâ·ê³¤¹¦·òÑÓÎó¡£Õâ´Î¹ÊÕÏÔ´ÓÚNATS˹ÍúÍþ¿Ë¿ÕÖн»Í¨¹ÜÔìÖÐÐĵÄÀ×´ïϵͳÒì³£ £¬ÎªÈ·±£°²È« £¬¸Ã»ú¹¹ÏÞ¶ÈÁËÂ׶عÜÔìÇøÄڵķɻúÊýÁ¿ £¬²¢ÔÝÍ£²¿Ãź½°àÆð½µ¡£º½°à×·×ÙÆ½Ì¨Flightradar24ÏÔʾ £¬Â׶عÜÔìÇøÒ»¶ÈÆëÈ«¹Ø¹Ø £¬Å·ÖÞ×î´óº½¿ÕÊàŦµÄÔË×÷ÏÝÈëÖͰ­¡£NATS½²»°ÈËÏòBBC֤ʵ £¬¹ÊÕÏÓëÀ×´ïϵͳֱ½ÓÓйØ £¬µ«Î´Ã÷È·¼¼Êõϸ½Ú¡£ÒµÄÚÈËÊ¿´§Ä¦ £¬Õâ´ÎÖжϿÉÄÜÓÉÖ÷À×´ïϵͳ¹ÊÕÏÒý·¢ £¬¶ø·Ç±¸ÓÃ¼à¿ØÏµÍ³Ê§Ð§ £¬µ«¾ßÌåÔ­ÒòÈÔÔÚµ÷²éÖС£½ØÖÁÓ¢¹ú¹¦·òÍí7µã £¬NATS°ä·¢ËùÓлú³¡Æô³Ìº½°à¸´Ô­ £¬²¢ÆðÍ·Ó뺽¿Õ¹«Ë¾¡¢»ú³¡ºÏ×÷´¦Öûýѹº½°à £¬Í¬Ê±ÏòÊÜÓ°Ïì´î¿ÍÖÂǸ¡£·ÖÎöÖ¸³ö £¬À×´ïϵͳ×÷Ϊ¿ÕÖн»Í¨¹ÜÔìµÄÖ÷Ìâ £¬Æä²»±äÐÔÖ±½Ó¹ØÏµµ½º½°à°²È«ÓëЧÄÜ¡£


https://www.theregister.com/2025/07/30/uk_airspace_outage/


4. ×êÑÐÈËÔ±°ä²¼ÁËFunkSecÀÕË÷Èí¼þµÄ½âÃÜÆ÷


7ÔÂ31ÈÕ £¬AvastºÍGen DigitalµÄ×êÑÐÈËÔ±°ä·¢¿ª·¢²¢°ä²¼ÁËÕë¶ÔFunkSecÀÕË÷Èí¼þµÄ½âÃܹ¤¾ß £¬ÔÊÐíÊܺ¦ÕßÃâ·Ñ¸´Ô­±»¼ÓÃܵÄÎļþ¡£¾ÝGen Digital»ã±¨³Æ £¬ÕâÒ»½âÃܹ¤¾ßµÄ°ä²¼ÊÇ»ùÓÚÓë·¨ÂÉ»ú¹¹µÄºÏ×÷ £¬ÇÒÓÉÓÚFunkSecÀÕË÷Èí¼þ±»ÒÔΪÒѾ­¡°éæÃü¡± £¬Òò¶ø¾ö¶¨½«Æä¹«¿ª¹©¹«¼ÒÏÂÔØ¡£FunkSecÀÕË÷Èí¼þ×éÖ¯×Ô2024Äê12ÔÂÆðÍ·»îÔ¾ £¬ÆäÐ¹Â¶ÍøÕ¾ÁгöÁË113ÃûÊܺ¦Õß¡£Æ¾¾Ý¹¦·òÏß·ÖÎö £¬¸Ã×éÖ¯×î³õÒÔÊý¾ÝÇÔÈ¡ºÍÀÕË÷ΪÖ÷ £¬Ëæºó²ÅÔö³¤ÁËÎļþ¼ÓÃÜÖ°ÄÜ¡£Check Point°ä²¼µÄ·ÖÎö»ã±¨ÏÔʾ £¬Ö»¹ÜFunkSecÐû³ÆÕ¼ÓдóÁ¿Êܺ¦Õß £¬µ«ÕâЩÊý×Ö¿ÉÄܸ²¸ÇÁ˸üΪÓÐÏÞµÄÏÖʵÍþвˮƽ¡£×êÑÐÈËÔ±ÒÔΪ £¬¸Ã×éÖ¯µÄÖ÷ÌâÔËÓªÕß¿ÉÄÜÊǾ­Ñé²»¼°µÄ¹¥»÷Õß £¬ÇҺܶàй¶µÄÊý¾Ý¼¯ÊÇ´ÓÒÔÍùºÚ¿Í»î¶¯ÓйØÊÂÎñÖлØÊÕ¶øÀ´ £¬ÕæÊµÐÔ´æÒÉ¡£´Ë±í £¬ÓëÆäËûÀÕË÷Èí¼þÍÅ»ï·ÖÆçµÄÊÇ £¬FunkSecÒªÇóµÄÊê½ð½ÏµÍ £¬²¿ÃÅÇé¿öϽöΪ1ÍòÃÀÔª £¬²¢½«±»µÁÊý¾ÝÁ®¼ÛÏúÊÛ¸øµÚÈý·½¡£¼¼Êõ·ÖÎöÏÔʾ £¬FunkSecÀÕË÷Èí¼þÓÉÒ»ÃûλÓÚ°¢¶û¼°ÀûÑǵĿª·¢ÕßʹÓÃRust˵»°±àд £¬Õý´¦ÓÚ»ý¼«¿ª·¢½×¶Î £¬¸Ã×éÖ¯¿í·ºÀûÓÃÈËΪÖÇÄÜ£¨AI£©À´¼ÓÇ¿ÄÜÁ¦¡£


https://securityaffairs.com/180616/malware/researchers-released-a-decryptor-for-the-funksec-ransomware.html


5. ¶íÂÞ˹ºÚ¿ÍÀûÓÃISP½Ó¼ûȨÏÞ¹¥»÷Ī˹¿Æ±í½»»ú¹¹


7ÔÂ31ÈÕ £¬Î¢Èí½üÈÕÅû¶ £¬Óë¶íÂÞ˹´æÔÚ¹ØÁªµÄ¸ß¼¶³ÖÐøÐÔÍþв£¨APT£©×éÖ¯Secret Blizzard£¨±ðºÅTurla¡¢Snake¡¢UroburosµÈ£©ÕýÕë¶ÔפĪ˹¿Æ±í¹ú´óʹ¹Ý¼°Ãô¸Ð»ú¹¹ÌáÒéÍøÂç¼äµýÐж¯¡£¸Ã×éÖ¯ÀûÓÃÆäÔÚ¶íÂÞ˹±¾ÍÁ»¥ÁªÍø·þÎñÌṩÉÌ£¨ISP£©²ãÃæµÄÖÐÑëÈ˹¥»÷£¨AiTM£©ÄÜÁ¦ £¬²¿Êð¶¨Ôì¶ñÒâÈí¼þApolloShadow £¬Í¨¹ýαÔ쿨°Í˹»ù·´²¡¶¾Èí¼þ¸ùÖ¤ÊéʵÏÖ³Ö¾Ãϵͳ½ÚÔì¡£¹¥»÷Á÷³ÌʼÓÚÖ¸±êÉ豸ÏνÓÍøÂçʱ±»³Á¶¨ÏòÖÁ¹¥»÷Õß½ÚÔìµÄÐéαǿÔìÃÅ»§ £¬ÓÕÆ­Óû§ÏÂÔØ¼Ù×°³É¿¨°Í˹»ù×°Ö÷¨Ê½µÄ¶ñÒâÈí¼þ¡£ApolloShadow»áƾ¾ÝÉ豸ȨÏÞµ÷ÕûÖ´ÐÐÕ½Êõ£ºÈôȨÏ޽ϵÍ £¬ÔòÍøÂçIPÊý¾Ý²¢Í¨¹ýαÔìDigicertÓòÃûÓë½ÚÔì·þÎñÆ÷ͨѶ £¬ÍÆË͵ڶþ½×¶ÎÔØºÉ£»Èô»ñµÃÖÎÀíԱȨÏÞ £¬ÔòÖ´ÐÐϵͳ¼¶Åú¸Ä £¬Ô̺¬½«ÍøÂçÉèΪ˽ÓÐÒÔ¼õÈõ·À»ðǽ¡¢ÆôÓÃÎļþ¹²Ïí¡¢×°ÖöñÒâ¸ùÖ¤Êé¼°´´½¨°µ²ØÖÎÀíÔ¹ØË»§ £¬´Ó¶ø³ÉÁ¢Óƾû¯ºóÃÅ¡£Î¢ÈíÍþвµý±¨ÖÐÐÄÇ¿µ÷ £¬Õâ´Î»î¶¯×Ô2024ÄêÆð³ÖÐøÔË×÷ £¬¶ÔÒÀÀµ±¾µØISP·þÎñµÄ±í½»»ú¹¹×é³É"¸ß¶È·çÏÕ"¡£Ö»¹Ü¼¼Êõ¼ì²âÏÔʾ¹¥»÷¿É×·ÒäÖÁ2024Äê £¬µ«Î¢ÈíÖ±ÖÁ2025Äê2Ô²ÅÍêÓñ³ÉÁ´ÌõÈ·ÈÏ¡£


https://securityaffairs.com/180638/apt/russia-linked-apt-secret-blizzard-targets-foreign-embassies-in-moscow-with-apolloshadow-malware.html


6. SafePayÀÕË÷Èí¼þÍŻ﹫¿ªÈÏ¿ÉIngram Micro¹¥»÷


7ÔÂ31ÈÕ £¬ÐÂÐËÀÕË÷Èí¼þ×éÖ¯SafePay½üÈÕ¹«¿ªÈϿɶԼ¼Êõ·ÖÏú¾ÞÍ·Ó¢Âõ¹ú¼Ê£¨Ingram Micro£©ÌáÒéÍøÂç¹¥»÷ £¬²¢ÍþвÈôδÔÚÖ¸¶¨½ØÖ¹ÈÕÆÚǰ֧¸¶Êê½ð £¬½«¹«¿ª¾Ý³ÆÇÔÈ¡µÄ3.5TBÃô¸ÐÊý¾Ý¡£Õâ´Î¹¥»÷²úÉúÓÚ7ÔÂ4ÈÕÃÀ¹ú¶ÀÁ¢ÈÕǰϦ £¬µ¼ÖÂIngram MicroÈ«Çò·þÎñÖжÏ £¬Æä¶à¸ö¹Ù·½ÍøÕ¾ÏÂÏß £¬½â¾ö¹æ»®ÌṩÉÌ¡¢¾­ÏúÉ̼°ÍйܷþÎñÌṩÉÌ£¨MSP£©¿Í»§µÄ¶©¹ºÏµÍ³±»ÆÈÖжÏ¡£Ö»¹Ü¹«Ë¾´ÎÖÜÐû³ÆÒµÎñÒÑÈ«Ãæ¸´Ô­ £¬µ«¹Ù·½°ä²¼µÄÍøÂç¹¥»÷¸üÐÂÒ³Ãæ¼°Ìá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©µÄ8-KÎļþÖÐ £¬¾ùδÌá¼°Êý¾Ýй¶Çé¿ö¡¢Êê½ðÒªÇó»ò¹¥»÷ÕßÉí·Ý £¬Òý°ä·¢½ç¶ÔÆäÐÅϢͨÃ÷¶ÈµÄÖÊÒÉ¡£SafePayÍŻォIngram MicroÁÐÈëÆä°µÍøÊý¾ÝÐ¹Â¶ÍøÕ¾µÄÊܺ¦ÕßÃûµ¥ £¬É趨Êê½ðÖ§¸¶½ØÖ¹ÈÕÆÚΪ´ÎÈÕÏÂÎç £¬µ«Î´¹«¿ª¾ßÌå½ð¶î¡£¸ÃÍÅ»ïµÄйÃÜÍøÕ¾ÏÔʾÊýÊ®¸öÊܺ¦×éÖ¯¼Í¼ £¬²¢Îª»Ø¾øÖ§¸¶Êê½ðµÄÊܺ¦ÕßÌṩËùν"±»µÁÊý¾Ý"µÄÏÂÔØÁ´½Ó¡£


https://www.darkreading.com/cyberattacks-data-breaches/safepay-ingram-micro-breach-ransom-deadline