²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ¶³ö

°ä²¼¹¦·ò 2025-09-12

1. ²®Ã÷º²ÖÐѧÊý¾Ýй¶ÊÂÎñ£ºÊý°ÙѧÉúÃô¸ÐÐÅϢ¶³ö


9ÔÂ10ÈÕ £¬²®Ã÷º²¶¼îì¸ñÀ¼ÆæÖÐѧ½üÆÚ²úÉúһ·ÑϳÁÊý¾Ýй¶ÊÂÎñ £¬Ó°Ïì7ÖÁ11Äê¼¶£¨11-16Ë꣩Êý°ÙÃûѧÉú¡£¾ÝѧÌÃÏò¼Ò³¤·¢Ë͵ÄÓʼþ¼°ºóÐøÉêÃ÷ £¬Ð¹Â¶Ô´ÓÚÒ»·ÝÔ̺¬Ñ§ÉúÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¼°¸¸Ä¸ÁªÏµ·½Ê½µÄµç×Ó±í¸ñ±»ÃýÎó¹²Ïí¡£¸Ã±í¸ñ±¾ÓÃÓÚÁ÷¸ÐÒßÃç½ÓÖÖÔÞ³ÉÁ÷³Ì £¬µ«¼Ò³¤µã»÷ÓʼþÁ´½Óºó¿ÉÖ±½ÓÏÂÔØ £¬µ¼ÖÂÃô¸ÐÐÅϢ¶³ö¡£ÊÂÎñ²úÉúÓÚ±¾µØ¹¦·ò9ÔÂ8ÈÕ9:50ÖÁ9:59ÆÚ¼ä £¬½öÄÜͨ¹ýѧÌÃBromcomÄÚÁªÍø½Ó¼û¸Ã±í¸ñµÄÈËÔ±¿É¼û¡£¾Ýµ±¾Öͳ¼Æ £¬¸ÃУ¹²ÓÐ1198ÃûѧÉú £¬µ«Õâ´Îй¶¾ßÌåÉæ¼°7-11Ä꼶ѧÉúÊý¾Ý¡£Êܺ¦¼Ò³¤·´Ó³ £¬µç×Ó±í¸ñ¼Í¼ÁË"Õû¸öѧÌõÄÐÅÏ¢" £¬Òý·¢¶Ôº¢×ÓÉí·Ý͵ÇÔ¡¢Ú¿Æ­µÈ°²È«·çÏÕµÄÓÇÓô¡£Ñ§ÌÃÔÚÉêÃ÷ÖаµÊ¾ÒѲÉÈ¡´¹Î£´ëÊ©£ºÁ¢¼´ÁªÏµÖÎÀíÐÅϢϵͳ£¨MIS£©ÌṩÉ̳·»Ø²¢É¾³ýй¶ÐÅÏ¢ £¬ÒªÇóÊÕµ½±í¸ñµÄ¼Ò³¤¾¡¿ìɾ³ýÊý¾Ý £¬²¢ÏòÐÅÈÎÊý¾Ý±£»¤¹Ù»ã±¨ÊÂÎñ¡£Êý¾Ý±£»¤¹ÙÕýµ÷²éÎ¥¹æÏ¸½Ú £¬±ØÒªÊ±½«ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£© £¬Í¬Ê±Ôì¶©Ô¤·À´ëʩԤ·ÀÀàËÆÊÂÎñ¸´·¢¡£


https://www.theregister.com/2025/09/10/birmingham_school_data_blunder/


2. AsyncRATÀûÓÃConnectWise ScreenConnectÇÔȡƾ֤ºÍ¼ÓÃÜÇ®±Ò


9ÔÂ11ÈÕ £¬ÍøÂ簲ȫ¹«Ë¾LevelBlueÅû¶ÁËһ·ÀûÓúϷ¨Ô¶³ÌÖÎÀí¹¤¾ßConnectWise ScreenConnectÌáÒéµÄ¸ß½×ÎÞÎļþ¹¥»÷»î¶¯¡£¸Ã¹¥»÷ͨ¹ý¶È½×¶Î¾ç±¾Ö´ÐÐ £¬×îÖÕ²¿ÊðAsyncRATÔ¶³Ì½Ó¼ûľÂí £¬ÊµÏÖÃô¸ÐÊý¾ÝÇÔÈ¡ÓëÓÆ¾Ã»¯½ÚÔì¡£¹¥»÷ÕßÊ×ÏÈÀûÓô¹µöÓʼþ¼Ù×°³É²ÆÕþ/óÒ×Îļþ £¬ÓÕµ¼Êܺ¦ÕßÏÂÔØ±»Ä¾ÂíϰȾµÄScreenConnect×°Ö÷¨Ê½¡£Ò»µ©×°Öà £¬¹¥»÷Õßͨ¹ýScreenConnect»ñȡԶ³Ì½Ó¼ûȨÏÞ £¬²¢Æô¶¯¼üÅ̼ͼ»î¶¯Ö´ÐÐVBScriptÓÐЧ¸ºÔØ¡£¸Ã¾ç±¾Í¨¹ýPowerShell´Ó¹¥»÷Õß½ÚÔìµÄ·þÎñÆ÷ÏÂÔØÁ½¸ö±í²¿Ôغɣº"logs.ldk"£¨DLLÎļþ£©ºÍ"logs.ldr"£¨»ìºÏ×é¼þ£©¡£DLLÎļþÕÆ¹Ü½«VB¾ç±¾Ð´Èë´ÅÅÌ £¬²¢ÀûÓôòË㹤×÷¼Ù×°³É"Skype¸üз¨Ê½" £¬ÔÚÿ´ÎϵͳµÇ¼ʱ×Ô¶¯Ö´ÐÐ £¬ÊµÏÖÒñ±ÎÓÆ¾Ã»¯¡£½øÒ»²½·ÖÎöÏÔʾ £¬PowerShell¾ç±¾½«"logs.ldk"¼ÓÔØÎª.NET·¨Ê½¼¯ £¬²¢´«Èë"logs.ldr"×÷Ϊ²ÎÊý £¬×îÖÕÖ´ÐÐAsyncRATµÄÖ÷ÌâÓÐЧ¸ºÔØ"AsyncClient.exe"¡£¸ÃľÂí¾ß±¸¶àÏî¸ßΣְÄÜ£º¼Í¼»÷¼ü¡¢ÇÔÈ¡ä¯ÀÀÆ÷Í´´¦¡¢²É¼¯ÏµÍ³Ö¸ÎÆ¡¢É¨Ãè¼ÓÃÜÇ®±ÒÇ®°ü £¬²¢Í¨¹ýTCPÌ×½Ó×Ö½«Êý¾Ý»Ø´«ÖÁC2·þÎñÆ÷¡£


https://thehackernews.com/2025/09/asyncrat-exploits-connectwise.html


3. Vyro AIÊý¾Ýй¶ £¬Êý°ÙÍòÓû§¿ÉÄÜÊܵ½Ó°Ïì


9ÔÂ10ÈÕ £¬°²È«×êÑÐÈËÔ±·¢ÏÖ £¬°Í»ù˹̹AI¹«Ë¾Vyro AIÒòδÊܱ£»¤µÄElasticsearchÊ·ýй¶116GBÓû§ÈÕÖ¾ £¬Éæ¼°Èý¿îÈȵãÀûÓãºGoogle PlayÏÂÔØÁ¿³¬1000Íò´ÎµÄImagineArt¡¢³¬10Íò´ÎÏÂÔØµÄChatly¼°Ô½ӼûÔ¼5Íò´ÎµÄChatbotx¡£¸Ã¹«Ë¾Ðû³Æ×ÜÏÂÔØÁ¿³¬1.5ÒÚ´Î £¬Ã¿ÖÜÌìÉú350ÍòÕÅͼƬ¡£Ð¹Â¶Êý¾Ýº­¸Ç2-7ÌìµÄ³ö²úÓ뿪·¢ÈÕÖ¾ £¬Ô̺¬Óû§AIÌáÐÑ¡¢Éí·ÝÑéÖ¤ÁîÅÆ¡¢Óû§´úÀíµÈÃô¸ÐÐÅÏ¢¡£¸ÃÊý¾Ý¿â×Ô2ÔÂÖÐÑ®±»ÎïÁªÍøËÑË÷ÒýÇæÊÕ¼ £¬¿ÉÄÜÒѱ»¹¥»÷Õß·¢ÏÖÊýÔ¡£Õâ´Îй¶·çÏÕÏÔÖø£º¹¥»÷Õß¿ÉÀûÓÃÁîÅÆ½Ù³ÖÓû§ÕË»§ £¬½Ó¼û̸Ìì¼Í¼¡¢ÌìÉúͼÏñ £¬ÉõÖÁÀÄÓÃAI´ú±Ò½øÐз¸·¨ÂòÂô£»Óû§ÓëAIµÄ˽ÃܶԻ°¿ÉÄܶ³ö´Óδ¹«¿ªµÄÃô¸ÐÄÚÈÝ¡£ÀýÈç £¬ImagineArtµÄ3000Íò»îÔ¾Óû§Êý¾ÝÈô±»ÀûÓà £¬½«µ¼Ö´ó¹æÄ£ÕË»§ÊÕÊÜ·çÏÕ¡£


https://cybernews.com/security/ai-chatbots-vyro-data-leak/


4. Allegis GroupÔâEverestÀÕË÷¹¥»÷ £¬°ÙÍò¼¶¿Í»§Êý¾Ýй¶


9ÔÂ10ÈÕ £¬È«Çò×î´óÈ˲ÅÖÎÀí¼¯ÍÅÖ®Ò»¡¢ÄêÊÕÈë½ü100ÒÚÃÀÔªµÄAllegis Group½üÈÕÔâ·êEverestÀÕË÷Èí¼þÍŻ﹥»÷¡£¸ÃÍÅ»ïÔÚ°µÍø²©¿ÍÉÏÐû³Æ»ñÈ¡ÁËAllegisÄÚ²¿Îļþ¼°¿Í»§Ãûµ¥ £¬²¢°ä²¼Á½ÕÅExcelÎĵµ½ØÍ¼×÷Ϊ֤¾Ý £¬ÆäÖÐÒ»ÕÅÔ̺¬13.5ÍòÌõ¿Í»§ÐÅÏ¢£ºÐÕÃû¡¢ÓÊÏä¡¢µç»° £¬ÁíÒ»ÕÅÔ̺¬¶à´ï42.6ÍòÌõÀàËÆÊý¾Ý¡£´ËÀàÐÅÏ¢¿ÉÄܱ»ÀûÓýøÐÐÍøÂç´¹µö¹¥»÷¡£EverestÍÅ»ïÓë¶íÂÞ˹¹ØÁª £¬×Ô2021Äê»îÔ¾ÒÔÀ´ÒѳÉΪ×î·è¿ñµÄÀÕË÷×éÖ¯Ö®Ò»¡£¾Ý°µÍø¼à¿Ø¹¤¾ßRansomlookerͳ¼Æ £¬¸ÃÍÅ»ï´Óǰ12¸öÔ¹¥»÷Á˳¬°Ù¸ö×éÖ¯ £¬·ÖÅúй¶Êý¾ÝÊÇÆäµäÐÍʩѹ¼¿Á© £¬Ö¼ÔÚÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£AllegisÆìÏÂÕ¼ÓÐAerotek¡¢TEKsystems¡¢MarketSourceµÈ¶à¼ÒרҵÈ˲ÅÖÎÀí×Ó¹«Ë¾ £¬·þÎñÍøÂ縲¸ÇÈ«Çò¡£Ö»¹Ü¹«Ë¾ÒÑ»ØÓ¦³Æ½«¸üнøÕ¹ £¬µ«¹¥»÷ÕßÌá¼°µÄ¡°ÖÖÀà·±¶àµÄÓ×ÎÒÎĵµ¡±ÉÐδ¹«¿ªÑù±¾ £¬Ç±ÔÚ·çÏÕ¿ÉÄÜÔ¶³¬ÒÑÆØ¹âµÄÁªÏµÐÅÏ¢¡£


https://cybernews.com/security/allegis-group-data-breach-claims/


5. AkiraÀÕË÷Èí¼þÍÅ»ïÀûÓÃSonicWall·ì϶ÌáÒéÐÂÒ»ÂÖ¹¥»÷


9ÔÂ11ÈÕ £¬AkiraÀÕË÷Èí¼þÍÅ»ïÕý»ý¼«ÀûÓÃCVE-2024-40766ÕâÒ»ÒÑ´æÔÚÒ»ÄêµÄÑϳÁ½Ó¼û½ÚÔì·ì϶ £¬¶Ô佨²¹µÄSonicWall SSL VPNÉ豸ÌáÒé¹¥»÷¡£¸Ã·ì϶ÔÊÐíδ¾­ÊÚȨµÄ×ÊÔ´½Ó¼û £¬ÉõÖÁ¿ÉÄܵ¼Ö·À»ðǽ±ÀÀ£¡£SonicWallÔçÔÚ2024Äê8Ô±ã°ä²¼Á˲¹¶¡ £¬²¢Ç¿µ÷¸üÐÂʱÐèΪ±¾µØÖÎÀíµÄSSLVPNÕË»§Óû§³ÁÖÃÃÜÂë £¬µ«²¿ÃÅ×é֯δ³¹µ×Ö´Ðв¹¾È´ëÊ© £¬µ¼ÖÂÍþвÐÐΪÕßÈÔÄÜÀûÓö³öµÄÍ´´¦ÅäÖöà³É·ÖÉí·ÝÑéÖ¤£¨MFA£©»ò»ùÓÚ¹¦·òµÄÒ»´ÎÐÔÃÜÂ루TOTP£©ÏµÍ³ £¬½ø¶ø»ñÈ¡½Ó¼ûȨÏÞ¡£°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©ÓÚ2025Äê9Ô·¢³ö¾¯±¨ £¬Ö¸³ö°Ä´óÀûÑǾ³ÄÚÕë¶Ô¸Ã·ì϶µÄ×Ô¶¯ÀûÓûÏÔÖøÔö³¤ £¬²¢Ã÷È·½«AkiraÀÕË÷Èí¼þÓëSonicWall SSL VPN¹¥»÷¹ØÁª¡£ÍøÂ簲ȫ¹«Ë¾Rapid7Ò²¹Û²ìµ½ÀàËÆÇ÷Ïò £¬ÒÔΪ¹¥»÷¼¤Ôö¿ÉÄÜÓë²»ÆëÈ«µÄ²¹¾È´ëÊ©ÓйØ £¬¾ßÌåÈëÇÖ¼¿Á©Ô̺¬ÀûÓÃĬÈÏÓû§×éµÄ¿í·º½Ó¼ûȨÏÞ½øÐÐÉí·ÝÑéÖ¤ £¬ÒÔ¼°Í¨¹ýSonicWallÉ豸ÉÏÐé¹¹°ì¹«ÊÒÃÅ»§µÄĬÈϹ«¹²½Ó¼ûȨÏÞÖ´Ðй¥»÷¡£


https://www.bleepingcomputer.com/news/security/akira-ransomware-exploiting-critical-sonicwall-sslvpn-bug-again/


6. LNERµÚÈý·½¹©¸øÉÌÔâÍøÂç¹¥»÷Ö³˿ÍÊý¾Ýй¶


9ÔÂ11ÈÕ £¬Ó¢¹úÁгµÔËÓªÉÌÂ׶ض«±±Ìú·¹«Ë¾£¨LNER£©ÓÚ9ÔÂ10ÈÕÈ·ÈÏ £¬ÆäµÚÈý·½¹©¸øÉÌÔâ·êÍøÂç¹¥»÷ £¬µ¼Ö²¿Ãų˿͵ÄÁªÏµ·½Ê½¼°¹ýÍùÐгÌÊý¾Ýй¶ £¬µ«Î´Éæ¼°²ÆÕþÐÅÏ¢¡¢ÃÜÂë»òÖ§¸¶¿¨Êý¾Ý¡£LNERÇ¿µ÷ £¬ÆäÁгµ·þÎñ¡¢ÊÛÆ±ÏµÍ³ÊµÊ±¿Ì±í¾ùÕý³£ÔËÐÐ £¬²¢ÒÑÓëÍøÂ簲ȫר¼ÒºÍÓйع©¸øÉ̺Ï×÷µ÷²éÊÂÎñȫò £¬Í¬Ê±ÁªÏµÓ¢¹úÐÅϢרԱ°ì¹«ÊÒÒÔÆÀ¹ÀÊÇ·ñÇкϡ¶Í¨ÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©µÄ»ã±¨ÒªÇó £¬Èô±£ÏÕ´ëÊ©²»¼°¿ÉÄÜÃæ¶Ô·£¿î¡£Ð¹Â¶µÄÓ×ÎÒÊý¾Ý¿ÉÄܱ»ÓÃÓÚ¹¹½¨¾ßÌåÓ×ÎÒ»­Ïñ £¬½ø¶øÌáÒé´¹µö¹¥»÷ £¬Èçͨ¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òWhatsAppÓÕÆ­Óû§Ìṩ²ÆÕþ»òÓ×ÎÒÐÅÏ¢¡£LNERÒѶ½´Ù³Ë¿Í¶ÔÒâ±íͨѶά³Ö¾¯Ìè £¬ÓÈÆäÉæ¼°Ó×ÎÒÐÅÏ¢ÒªÇóµÄÓʼþ»òÐÅÏ¢ £¬ÇÐÎðµÈÏлظ´¡£¹«Ë¾°µÊ¾½«¸ß¶ÈÆ÷³Á´ËÊ £¬³ÖÐøÓëר¼ÒºÏ×÷²¢²ÉÈ¡±£ÏÕ´ëÊ© £¬ºóÐø½«Ìṩ¸ü¶à¸üÐÂÐÅÏ¢¡£


https://hackread.com/uk-rail-operator-lner-cyber-attack-passenger-data/