¼ÓÄôóInstantelǧÓą̀¹¤Òµ¼à¿ØÉ豸´æÑϳÁ·ì϶

°ä²¼¹¦·ò 2025-06-05

1. ¼ÓÄôóInstantelǧÓą̀¹¤Òµ¼à¿ØÉ豸´æÑϳÁ·ì϶


6ÔÂ3ÈÕ £¬¼ÓÄôóInstantel¹«Ë¾³ö²úµÄ1000¶ą̀¹¤Òµ¼à¿ØÉè±¸Ãæ¶ÔÑϳÁ°²È«Íþв¡£ÍøÂ簲ȫ»ú¹¹CISA°ä²¼µÄÕ÷ѯ»ã±¨ÏÔʾ £¬InstantelµÄMicromate²úÆ·£¨ÓÃÓڼͼÕñ¶¯¡¢ÔëÒôºÍ¿ÕÆø¹ýѹ£©ÒòÓëÅäÖö˿ڲ»×ãÉí·ÝÑéÖ¤Óйصķì϶¶øÊÜÓ°Ïì £¬¸Ã·ì϶±àºÅΪCVE-2025-1907 £¬CVSSÆÀ·Ö¸ß´ï9.8 £¬¹¥»÷Õ߿ɽè´ËÔÚÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁî¡£·¢ÏÖ´Ë·ì϶µÄMicrosec×êÑÐÔ±Souvik Kandarй© £¬È«ÇòÓг¬¹ý1000̨¶³öÔÚ»¥ÁªÍøÉϵÄMicromateÉ豸¿ÉÄÜÒ×Êܹ¥»÷¡£ÕâЩÒ×ËðÉ豸¿í·ºÀûÓÃÓڲɿó¡¢Ëí·¡¢ÇÅÁº¼à²â¡¢¹¹ÖþºÍ»·¾³°²È«µÈ¶à¸öÁìÓò¡£¹¥»÷ÕßÈôÄÜÔÚMicromateÉ豸ÉÏÖ´ÐкÅÁî £¬²»½ö¿É¸ü¸Ä»ò½ûÓÃÆä¼à¿ØÖ°ÄÜ £¬µ¼ÖÂÊý¾ÝÃýÎó»ò²»ÆëÈ« £¬·ÛËéÊý¾ÝÆëÈ«ÐÔ £¬»¹¿ÉÄܸøÉ󼯡¢ºÏ¹æÐÔ»ò±£ÏÕË÷Åâ´øÀ´ÎÊÌâ¡£´Ë±í £¬É豸»¹¿ÉÄܱ»°Ü»µ»ò¹Ø¹Ø £¬ÒÔÖÁ±¬ÆÆºÍËí·ÍÚ¾òµÈ¹Ø¼ü²Ù×÷ÖжÏ¡£¸üÑϳÁµÄÊÇ £¬¹¥»÷Õß¿ÉÀûÓñ»ÈëÇÖÉ豸ºáÏòÒÆ¶¯µ½ÆäËûÏνӵÄIT»òOTϵͳ¡£CISAÔÚ²¼¸æÖÐÖ¸³ö £¬InstantelÔÚÕë¶Ô´Ë·ì϶½øÐй̼þ¸üР£¬ÔÚ²¹¶¡°ä²¼Ç° £¬½¨ÒéÓû§½«ÊÜÓ°ÏìÉ豸µÄ½Ó¼ûÏÞ¶ÈÔÚÊÜÐÅÀµµÄIPµØÖ·¡£


https://www.securityweek.com/1000-instantel-industrial-monitoring-devices-possibly-exposed-to-hacking/


2. Gargle¹«Ë¾Êý¾Ý¿â´æÒþ»¼ÖÂ270Íò»¼ÕßÐÅϢ¶³ö


6ÔÂ3ÈÕ £¬Cybernews×êÑÐÈËÔ±·¢ÏÖÁËһ·ӰÏìÃÀ¹ú¹«ÃñÒ½ÁÆÊý¾ÝµÄ´ó¹æÄ£Ð¹Â¶ÊÂÎñ £¬Ô¼270ÍòÃû»¼Õß×ÊÁϺÍ880ÍòÌõÔ¤Ô¼¼Í¼Æëȫ¶³ö¡£Õâ´Îй¶ԴÓÚÒ»¸öδÉèÖð²È«·À»¤µÄMongoDBÊý¾Ý¿â £¬Êý¾ÝËùÓÐÕßËäδ»ñ¹Ù·½È·ÈÏ £¬µ«ÏßË÷Ö¸ÏòGargle¹«Ë¾¡£¸Ã¹«Ë¾ÎªÑÀ¿ÆÕïËùÌṩӪÏú¡¢SEOºÍÍøÕ¾¿ª·¢·þÎñ £¬Ëä·ÇÒ½ÁƱ£½¡ÌṩÕß £¬µ«ÒµÎñÄ£Ê½Éæ¼°´¦Öû¼ÕßÊý¾Ý¡£Ä¿Ç°Éв»Ã÷ÏÔÊý¾Ý¿â¶³öʱ³¤¼°½Ó¼ûÕß £¬ÔÚCybernews·î¸æºó £¬Êý¾Ý¼¯Òѱ»±£»¤ £¬µ«ÉÐδÊÕµ½¸Ã¹«Ë¾ÆÀÂÛ¡£Ð¹Â¶Êý¾Ýº­¸Ç»¼ÕßÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·¡¢×¡Ö·¡¢µç»°ºÅÂë¡¢ÐԱ𡢲¡ÀúID¡¢Ëµ»°Æ«ºÃ¡¢Õ˵¥ÏêÇé¼°Ô¤Ô¼¼Í¼µÈÃô¸ÐÐÅÏ¢¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Éî¶ÈÃô¸ÐÐÅÏ¢ £¬°ó¸¿ºó×é³ÉÓ×ÎÒÉí·ÝÈ«ÃæÀ¶Í¼ £¬ÎªÉí·Ý͵ÇÔ¡¢±£ÏÕڲƭ¡¢Ò½ÁÆÉí·Ý͵ÇÔ¼°´¹µö¹¥»÷µÈÀÄÓÃÐÐΪ´ò¿ª´óÃÅ £¬Òý·¢¶Ô¸Ã¹«Ë¾²»×ñÊØHIPAAÂÉÀýµÄÑϳÁÖÊÒÉ¡£


https://cybernews.com/security/dental-marketing-gargle-data-leak/


3. ÎÚ¿ËÀ¼GUR´Ó¶íͼ²¨Áзò¹«Ë¾ÇÔÈ¡4.4GB»úÃÜÊý¾Ý


6ÔÂ4ÈÕ £¬ÎÚ¿ËÀ¼¾üʵý±¨»ú¹¹GUR£¨±ðÃûHUR£©¶Ô¶íÂÞ˹º½¿Õº½ÌìºÍ¹ú·À¹«Ë¾Í¼²¨Áзò·¢ÆðÁ˺ڿ͹¥»÷ £¬ÇÔÈ¡Á˸߶ȻúÃÜÊý¾Ý¡£¾Ý±¨Â· £¬GURÈëÇÖÁ˶íÂÞ˹½áºÏ·É»ú¹«Ë¾£¨UAC£©Í¼²¨Áзò·Ö²¿ £¬¸Ã·Ö²¿×÷ΪËÕÁªÊ±ÆÚͼ²¨ÁзòÉè¼Æ¾ÖµÄ¼Ì³ÐÕß £¬ÊǶíÂÞ˹¾ü·½Õ½ÊõºäÕ¨»úµÄÖØÒª¿ª·¢ÉÌ¡£µý±¨½çÐÂÎÅÈËʿй© £¬Õâ´ÎÐж¯ÖÐ £¬ÎÚ¿ËÀ¼¼éϸ»ñÈ¡Á˳¬¹ý4.4GBÓµÓÐÕ½ÊõÒâ˼µÄ¸ß¶È»úÃÜÄÚ²¿Êý¾Ý¡£ÕâЩÊý¾Ýº­¸Ç¿í·º £¬Ô̺¬ÄÚ²¿Í¨Ñ¶¡¢Ô±¹¤Ó×ÎÒÐÅÏ¢¡¢¹¤³Ìʦ¼òÀú¡¢²É¹º¼Í¼ÒÔ¼°»úÃÜ»áÒé¼Í¼µÈ¡£ÎÚ¿ËÀ¼µý±¨²¿ÃÅÐÂÎÅÈËÊ¿°µÊ¾ £¬Õâ´ÎÊý¾Ýй¶ÏÕЩ¶³öÁËͼ²¨ÁзòµÄËùÓаÂÃØ £¬Ê¹ÎÚ¿ËÀ¼·½Ãæ¿ÉÄÜÈ«Ãæ°ÑÎÕ¶íÂÞ˹սÊõº½¿ÕµÄÈËÔ±ºÍÐж¯Çé¿ö¡£ÕâЩÊý¾Ý¶ÔÎÚ¿ËÀ¼µý±¨²¿ÃŶøÑÔ¼ÛÖµ¼«¸ß £¬Ê¹Æä¶Ôͼ²¨ÁзòµÄÔË×÷ÏÕЩÁËÈçÖ¸ÕÆ¡£´Ë±í £¬GUR»¹°ÂÃØ¼à¿ØÍ¼²¨Áзò¹«Ë¾ÄÚ²¿ÎļþÁ÷´ïÊýÔ £¬Éî¿ÌÏàʶ¹«Ë¾ÔËÓª £¬Îª½«À´½ø¹¥¶íÂÞ˹¹ú·À¹¤ÒµÍøÂçÖ¤¾Ý¡£ÎªÏóÕ÷ÐÔ½ø¹¥¶íÂÞ˹ £¬GUR»¹ÔÚͼ²¨Áзò¹«Ë¾ÍøÕ¾ÉÏͿѻ £¬»­ÉÏèͷӥץ×ŶíÂÞ˹ºäÕ¨»úµÄͼ°¸¡£Õâ´ÎÐж¯²¢·Ç¹ÂÁ¢ÊÂÎñ £¬ÎÚ¿ËÀ¼GURÒ»ÏòÔÚ²»Ðݹ¥»÷¶íÂÞ˹µÄ¾ü¹¤½áºÏÌå £¬ÈëÇÖÓë¹ú·À¡¢Õ½Êõº½¿Õ¡¢±øÆ÷³ö²úºÍÎïÁ÷ÓйصĶíÂÞ˹¹«Ë¾Êý¾Ý¿â¡£


https://securityaffairs.com/178641/hacking/ukraines-military-intelligence-agency-stole-4-4gb-of-highly-classified-internal-data-from-tupolev.html


4. FBIµÈ»ú¹¹¸üУºPlayÀÕË÷Èí¼þÒѹ¥»÷900¸ö×éÖ¯


6ÔÂ4ÈÕ £¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©¡¢CISA¼°°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐĽáºÏ°ä²¼µÄÕ÷ѯ¸üÐÂÅú×¢ £¬½ØÖÁ2025Äê5Ô £¬PlayÀÕË÷Èí¼þÍÅ»ïÒÑÈëÇÖÔ¼900¸ö×éÖ¯ £¬Êܺ¦ÕßÊýÁ¿ÊÇ2023Äê10Ô»㱨µÄÈý±¶¡£×Ô2022Äê6ÔÂÆð £¬PlayÀÕË÷Èí¼þ×éÖ¯¾Í¶Ô±±ÃÀ¡¢ÄÏÃÀºÍÅ·Ö޵Ķà¶àÆóÒµ¼°¹Ø¼ü»ù´¡ÉèÊ©Ôì³ÉÓ°Ïì £¬³ÉΪ2024Äê×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯Ö®Ò»¡£¸ÃÍÅ»ïÿ´Î¹¥»÷¾ùʹÓóÁбàÒëµÄ¶ñÒâÈí¼þ £¬Õâ´ó´óÔö³¤Á˰²È«½â¾ö¹æ»®¼ì²âºÍ×èÖ¹µÄÄѶÈ £¬²¿ÃÅÊܺ¦Õß»¹½Óµ½µç»°ÀÕË÷Êê½ð £¬ÒÔÔ¤·ÀÊý¾Ýй¶¡£½ñÄêËêÊ×ÒÔÀ´ £¬ÓëPlayÀÕË÷Èí¼þÔËÓªÉÌÓйصijõʼ½Ó¼û´úÀíÀûÓÃÔ¶³Ì¼à¿ØºÍÖÎÀí¹¤¾ßÖеĶà¸ö·ì϶ £¬¶ÔÃÀ¹ú×éÖ¯ÌáÒéÔ¶³Ì´úÂëÖ´Ðй¥»÷ £¬ÎªºóÐøµÄÀÕË÷Èí¼þ¹¥»÷×ö³ï±¸¡£PlayÀÕË÷Èí¼þÍÅ»ïÒÑ´æÔÚ½üÈýÄê £¬ÔÚ²¿ÊðÀÕË÷Èí¼þǰ»áÇÔÈ¡Ãô¸ÐÎļþ £¬ÒÔ´ËÏòÊܺ¦ÕßʩѹË÷ÒªÊê½ð £¬ÇÒѡȡµç×ÓÓʼþ×÷Ϊ½»ÉæÇþ· £¬²»ÌṩTor½»ÉæÒ³ÃæÁ´½Ó £¬»¹ÀûÓÃ×Ô½ç˵VSS¸´Ô칤¾ßÇÔÈ¡Îļþ¡£ÎªÓ¦¶ÔÕâÒ»Íþв £¬FBIµÈ»ú¹¹¶½´Ù°²È«ÍŶÓÓÅÏȽ«ÏµÍ³¡¢Èí¼þºÍ¹Ì¼þ¸üÐÂÖÁ×îа汾 £¬ÒÔ½µµÍ·ì϶±»ÀûÓõķçÏÕ£»ÔÚËùÓзþÎñÖÐÖ´Ðжà³É·ÖÉí·ÝÑéÖ¤£¨MFA£© £¬ÓÈÆäÒª³Áµã¹Ø×¢VPN¡¢ÍøÂçÓʼþµÈ¿É½Ó¼û×éÖ¯ÍøÂçÖйؼüϵͳµÄÕË»§£»Í¬Ê±ÒªÊØ»¤ÀëÏßÊý¾Ý±¸·Ý £¬²¢¿ª·¢ºÍ²âÊÔ¸´Ô­·¨Ê½ £¬½«Æä×÷Ϊ×éÖ¯³ß¶È°²È«Êµ¼ÊµÄÒ»²¿ÃÅ¡£


https://www.bleepingcomputer.com/news/security/fbi-play-ransomware-breached-900-victims-including-critical-orgs/


5. ³ö°æ¾ÞÍ·Lee Enterprises³ÆÊý¾Ýй¶ӰÏìÁ˽ü4ÍòÈË


6ÔÂ4ÈÕ £¬³ö°æ¾ÞÍ·Lee EnterprisesÔÚ֪ͨ½ü40,000ÃûÓ×ÎÒÐÅÏ¢ÔÚ2025Äê2ÔÂÀÕË÷Èí¼þ¹¥»÷Öб»µÁµÄÈËÔ±¡£×÷ΪÃÀ¹ú×î´óµÄ±¨Òµ¼¯ÍÅÖ®Ò» £¬Lee EnterprisesÔÚ26¸öÖݳö°æ¶à·ÝÈÕ±¨¡¢ÖÜ¿¯ºÍרҵ¿¯Îï £¬Õ¼ÓÐÖØ´óµÄ¶ÁÕßȺÌå¡£¸Ã¹«Ë¾±¾ÖÜÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄÎļþÏÔʾ £¬¹¥»÷ÕßÇÔÈ¡ÁËÔ̺¬39,779ÈËÓ×ÎÒÉí·ÝÐÅÏ¢µÄÎļþ £¬¿ÉÄÜÉæ¼°µÄÃû×Ö¡¢ÐÕÊÏÒÔ¼°Éç»á°²È«ºÅÂëµÈÃô¸ÐÐÅÏ¢ÔÚ2ÔÂ3ÈÕ±»Î´¾­ÊÚȨ½Ó¼û»ò»ñÈ¡¡£Õâ´Î¹¥»÷µ¼ÖÂLee EnterprisesÃÀ¹ú¸÷µØµÄÐÂÎűà×ëÊÒϵͳÖжÏ £¬ÆÈʹ³ö°æÉ̹عغܶàÍøÂç £¬Ôì³ÉÊýÊ®¼Ò±¨Ö½µÄÓ¡Ë¢ºÍµÝËÍ´óÃæ»ýÖжÏ £¬»¹Òý·¢ÁËÆóÒµVPNÖжÏÒÔ¼°ÎÞ·¨½Ó¼ûÄÚ²¿ÏµÍ³ºÍÔÆ´æ´¢µÈÑϳÁÎÊÌâ¡£Ò»Öܺó £¬¸Ã¹«Ë¾ÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»Îļþ £¬Åû¶ºÚ¿Í¡°¼ÓÃÜÁ˹ؼüÀûÓ÷¨Ê½²¢ÇÔÈ¡ÁËijЩÎļþ¡±¡£Ö»¹ÜLee EnterprisesÉÐδÃ÷È·¹é×ïÓÚ¾ßÌåÐж¯·½ £¬µ«÷è÷ëÀÕË÷Èí¼þÍÅ»ïÒÑÔÚ2Ôµװ䷢¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü £¬²¢Ðû³ÆÇÔÈ¡ÁË×ܼÆ350GBµÄ120,000·ÝÎļþ £¬Íþв½«ÓÚ3ÔÂ5ÈÕÈ«Êý°ä²¼¡£2ÔÂ28ÈÕ £¬÷è÷ëÀÕË÷Èí¼þÍŻォLee EnterprisesÔö³¤µ½Æä°µÍøÐ¹ÃÜÍøÕ¾ £¬·ÖÏíÁ˾ݳƴӸù«Ë¾ÊÜËðϵͳÖÐÇÔÈ¡µÄÊý¾ÝÑù±¾ £¬Ô̺¬µ±¾ÖÉí·Ý֤ɨÃè¼þ¡¢²ÆÕþµç×Ó±í¸ñµÈ»úÃÜÎļþ¡£


https://www.bleepingcomputer.com/news/security/media-giant-lee-enterprises-says-data-breach-affects-39-000-people/


6. À­½Ü¹ûµÂÊÐÕþ¹«Ë¾ÒÉÔâÍøÂç¹¥»÷ £¬³¬400GBÊý¾Ý»òй¶


6ÔÂ4ÈÕ £¬À­½Ü¹ûµÂÊÐÕþ¹«Ë¾£¨RMC£©ÍøÕ¾ÒÉËÆÔâ·êÍøÂç¹¥»÷ £¬Òý·¢¹«¼Ò¶ÔÃô¸Ð¹«ÃñÊý¾Ý¿ÉÄܱ»µÁµÄÓÇÓô £¬½üÆÚ¸ÃÊý¾Ýй¶ÊÂÎñÆØ¹âºó £¬Òý·¢¾ÓÃñ·¢¼±¡£¾ÝÐÂÎÅÈËÊ¿³Æ £¬Õâ´Îй¶µÄÊý¾Ý¿ÉÄÜÔ̺¬À­½Ü¹ûµÂÊе±¾Ö¹¹ÖþºÍ¹«¹²»ù´¡ÉèÊ©µÄ¹Ø¼üÐÅÏ¢ £¬ÈçѧÌá¢Ò½Ôº¡¢ÇÅÁººÍ°ì¹«ÊÒµÈ £¬¹ÙÔ±Òɻ󳬹ý400GBµÄÊý¾Ý¿ÉÄÜÔ⵽й¶¡£ÊÂÎñ²úÉúºó £¬RMCÖÎÀí²¿ÃÅѸËÙ֪ͨÁËÓ¡¶È¹ú¶ÈµçÐÅÓÐÏÞ¹«Ë¾£¨BSNL£©µÄÍøÂ簲ȫÍŶÓ¡£BSNLÍŶÓÁ¢¼´½«GIS£¨µØÀíÐÅϢϵͳ£©ÍøÕ¾´ÓÍøÂçÖиôÀë £¬²¢¶ÔÕâ´ÎÊý¾Ýй¶ÊÂÎñ·¢Õ¹¾ßÌåµ÷²é £¬Ä¿Ç°ÕýÖÂÁ¦È·¶¨Êý¾Ýй¶ˮƽ¼°ÕÒ³öµ¼Ö¹¥»÷µÄ·ì϶¡£³õ²½ÆÀ¹ÀÏÔʾ £¬¸ÃÍøÕ¾¿ÉÄÜÔÚ¡°ÐÁ¶à¶ûÐж¯¡±£¨Ó¡¶È½üÆÚÕë¶ÔÅÁ¹þ¶û¼ÓÄ·¿Ö²ÀÏ®»÷µÄ¾üÊ»ØÓ¦£©ÆÚ¼äÔâµ½ÈëÇÖ £¬²»ÍâÕâÒ»¹ØÁªÉÐδµÃµ½Ö¤Êµ¡£Ö»¹ÜRMCÔÚÍøÂ簲ȫ´ëÊ©ÉÏͶÈëÁËÔ¼1ÒÚ¬±È £¬µ«´ÓÇ°Ò²ÔøÔâ·ê¹ýÀàËÆÊÂÎñ¡£µ±¾Ö°µÊ¾ £¬ÒªÈ«ÃæÏàʶÕâ´ÎÍøÂç¹¥»÷µÄÓ°Ïì £¬»¹ÐèÆÚ´ýÔÚ½øÐеÄȡ֤µ÷²éʵÏÖ¡£


https://www.news9live.com/crime/rajkot-civic-bodys-gis-website-hit-by-cyber-attack-over-400-gb-data-feared-stolen-2862626