DiscordÔ¼ÇëÁ´½ÓÔâ½Ù³Ö £¬ºÚ¿ÍÀûÓ÷ì϶ÇÔ¼ÓÃÜÇ®±Ò

°ä²¼¹¦·ò 2025-06-17

1. DiscordÔ¼ÇëÁ´½ÓÔâ½Ù³Ö £¬ºÚ¿ÍÀûÓ÷ì϶ÇÔ¼ÓÃÜÇ®±Ò


6ÔÂ13ÈÕ £¬°²È«×êÑÐÈËÔ±ÖÒ¸æ £¬ºÚ¿ÍÕý½Ù³ÖÒѹýÆÚ»òÒÑɾ³ýµÄDiscordÔ¼ÇëÁ´½ÓÖ´Ðй¥»÷ ¡£ÕâЩÁ´½ÓËä²»ÔÙÊÜ×î²Ý´´½¨Õß½ÚÔì £¬µ«ÈÔ°ä²¼ÔÚ¸÷ƽ̨ÉÏ £¬Óû§½ÓÊÜÔ¼ÇëºóÉ豸¿ÉÄܱ»ÆëÈ«ÈëÇÖ £¬¼ÓÃÜÇ®±ÒÃæ¶Ô±»µÁ·çÏÕ ¡£Check Point Research»ã±¨Ö¸³ö £¬¹¥»÷ÕßÀûÓÃDiscordÔÊÐí³Á¸´Ê¹ÓùýÆÚ»òÒÑɾ³ýÔ¼ÇëÁ´½ÓµÄÖ°ÄÜ £¬Í¨¹ýÐéαÑéÖ¤»úеÈ˺ʹ¹µöÍøÕ¾ºýŪÓû§ £¬Ê¹ÆäÔÚ²»ÖªÇéÇé¿öÏÂÔËÐÐÓк¦ºÅÁî £¬½«¶ñÒâÈí¼þÏÂÔØµ½ÍÆËã»úÉÏ ¡£ºÚ¿Í»¹ÀÄÓÃÆäËûºÏ·¨·þÎñ°µ²Ø¶ñÒâÈí¼þ £¬Í¨¹ý¶à²½Öè´«²¼Ìӱܼì²â £¬ÖØÒªÖ¸±êÊǼÓÃÜÇ®°ü £¬ÇÔȡƾ֤ºÍÇ®°üÐÅÏ¢ £¬¸Ã¶ñÒâÈí¼þÒÑÔÚÃÀ¹ú¡¢Ô½ÄÏ¡¢·¨¹ú¡¢µÂ¹úµÈ¶à¹úÏÂÔØ³¬1300´Î ¡£DiscordÔ¼Çëϵͳ´æÔÚȱµã £¬ºÚ¿Í¿Éͨ¹ýÐéÈÙÁ´½Ó×¢²á½Ù³ÖÒѹýÆÚ»òÒÑɾ³ýÁ´½Ó £¬½«Óû§³Á¶¨ÏòÖÁ¶ñÒâ·þÎñÆ÷ ¡£¹¥»÷Õß»¹»áÔÚÈÈµãÆ½Ì¨Ñ°ÕÒ¹ýÆÚÁ´½Ó³ÁÐÂ×¢²á £¬»òÀûÓÃÔ¼ÇëÂë´óÓ×д²î¾à´´½¨ÐÂÁ´½Ó ¡£Óû§±»³Á¶¨Ïòµ½´¹µöÍøÕ¾ºó £¬»áÓÕÆ­ÆäÏÂÔØ¶ñÒâÈí¼þ»òÔËÐжñÒâºÅÁî ¡£½üÆÚÕæÊµ¹¥»÷ÀûÓÃAsyncRATºÍSkuld Stealer¶ñÒâÈí¼þÈëÇÖÓû§ £¬Ç°ÕßÌṩԶ³Ì½ÚÔìÄÜÁ¦ £¬ºóÕßÇÔÈ¡Ãô¸ÐÓû§Êý¾Ý ¡£Check PointÖÒ¸æÕâ´Î¹¥»÷»î¶¯²»ÐÝÑݱä £¬¹¥»÷Õ߻ᶨÆÚ¸üÐÂÏÂÔØÆ÷ £¬Õë¶Ô·ÖÆçÓû§ÈºÌåµ÷Õûµö¶üºÍ¹¤¾ß ¡£Ö»¹ÜDiscordÒѽûÓÃÌØ¶¨»î¶¯ÖÐʹÓõĶñÒâ»úеÈË £¬µ«Ö÷ÌâÕ½ÊõÈÔ¿ÉÐÐ ¡£


https://cybernews.com/security/hackers-steal-and-reanimate-discord-invite-links/


2. ºÚ¿ÍÀûÓÃScattered SpiderÕ½Êõ¹¥»÷ÃÀ¹ú±£ÏÕ¹«Ë¾


6ÔÂ16ÈÕ £¬Íþвµý±¨×êÑÐÈËÔ±·¢³öÖÒ¸æ £¬ºÚ¿Í¿ÉÄÜÀûÓÃÔÚScattered Spider»î¶¯Öй۲쵽µÄÕ½ÊõÈëÇÖ¶à¼ÒÃÀ¹ú±£ÏÕÒµ¹«Ë¾ ¡£¸ÃÍþв×é֯ͨ³£Õë¶ÔÌØ¶¨ÐÐÒµ £¬´Ëǰ´ÓÓ¢¹úÁãÊÛ»ú¹¹×ªÏòÃÀ¹úͬҵҵָ±ê ¡£¹È¸èÍþвµý±¨¼¯ÍÅ£¨GTIG£©Ê×ϯ·ÖÎöʦJohn Hultquist°µÊ¾ £¬¹È¸èÍþвµý±¨¼¯ÍÅÒÑ·¢ÏÖÃÀ¹ú¾³ÄÚ¶àÆð¾ß±¸Scattered Spider»î¶¯ÌصãµÄÈëÇÖÊÂÎñ £¬±£ÏÕÐÐÒµÒ²³öÏÖÀàËÆÇé¿ö ¡£ÓÉÓÚ¸Ã×é֯ÿ´ÎÖ»¹Ø×¢Ò»¸öÁìÓò £¬±£ÏÕÒµÐèά³Ö¸ß¶È¾¯Ìè ¡£GTIGÊ×ϯ×êÑÐÔ±Ö¸³ö £¬¹«Ë¾Ó¦³ö¸ñ°ÑÎÈ·þÎñ̨ºÍºô½ÐÖÐÐÄ¿ÉÄÜÔâ·êµÄÉç»á¹¤³Ì¹¥»÷ ¡£Scattered SpiderÊÇһȺÁ÷¶¯µÄÍþвÐÐΪÕßͬÃË £¬Ñ¡È¡¸´ÔÓÉç»á¹¤³Ì¹¥»÷ÈÆ¹ý°²È«·¨Ê½ £¬»¹±»×·×ÙΪ0ktapus¡¢UNC3944µÈ¶à¸öÃû³Æ £¬Óë¶à¸ö³ÛÃû×éÖ¯ÈëÇÖÐÐΪÓйØ ¡£ËûÃÇ»ìºÏʹÓÃÍøÂç´¹µö¡¢SIM¿¨»¥»»ºÍMFAί¶Ù/ºäÕ¨µÈ¼¿Á©»ñÈ¡³õʼ½Ó¼ûȨÏÞ £¬ºóÆÚͶ·ÅRansomHub¡¢QilinºÍDragonForceµÈÀÕË÷Èí¼þ ¡£Îª·ÀÓù´ËÀ๥»÷ £¬×éÖ¯Ó¦¸ôÀëÉí·Ý²¢Ê¹ÓÃ׳´óÉí·ÝÑéÖ¤³ß¶È¼°ÑϸñÉí·Ý½ÚÔìÀ´³ÁÖÃÃÜÂëºÍMFA×¢²á ¡£¼øÓÚScattered SpiderÒÀÀµÉç»á¹¤³Ìѧ £¬×éÖ¯Ðèͨ¹ý¶ÌÐÅ¡¢µç»°¡¢ÐÂÎÅÆ½Ì¨µÈÇþ·¶ÔÔ±¹¤ºÍÄÚ²¿°²È«ÍŶӽøÐнÌÓý £¬Ô¤·À¼ÙÒâÐÐΪ ¡£


https://www.bleepingcomputer.com/news/security/google-warns-scattered-spider-hackers-now-target-us-insurance-companies/


3. ¡¶»ªÊ¢¶ÙÓʱ¨¡·µç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷ £¬¼ÇÕßÕË»§±»µÁ


6ÔÂ16ÈÕ £¬½üÈÕ £¬ÊýÃû¡¶»ªÊ¢¶ÙÓʱ¨¡·¼ÇÕߵĵç×ÓÓʼþÕË»§ÔÚÒ»´ÎÒÉËÆÓɱí¹úµÐÔÖÖ´ÐеÄÍøÂç¹¥»÷Öб»µÁ ¡£¸ÃÊÂÎñÓÚÖÜËÄÍí¼ä±»·¢ÏÖºó £¬¡¶»ªÊ¢¶ÙÓʱ¨¡·Á¢¼´·¢Õ¹µ÷²é ¡£6ÔÂ15ÈÕ £¬Ò»·ÝÓÉÖ´ÐÐÖ÷±àÂíÌØ¡¤Ä¬ÀïÇ©ÊðµÄÄÚ²¿±¸Íü¼·¢Ë͸øÔ±¹¤ £¬·î¸æËûÃÇ¡°µç×ÓÓʼþϵͳ¿ÉÄÜÔâ·êδ¾­ÊÚȨµÄÓÐÕë¶ÔÐÔµÄÈëÇÖ¡± £¬ÇÒÓÐÏÞÊýÁ¿¼ÇÕßµÄ΢ÈíÕË»§Êܵ½Ó°Ïì ¡£¡¶»ªÊ¢¶ÙÓʱ¨¡·ÓÉÑÇÂíÑ·Ê×´´È˽ܷò¡¤±´×ô˹ËùÓÐ £¬ÊÇÃÀ¹ú¼«¾ßÓ°ÏìÁ¦µÄ±¨Ö½Ö®Ò» ¡£ÄÚ²¿ÐÂÎÅÈËʿй© £¬Õâ´Î¹¥»÷Ö¸±êΪ׫д¹ú¶È°²È«¡¢¾­¼ÃÕþ²ßÖ÷ÌâÎÄÕÂÒÔ¼°ÓйØÖйú±¨Â·µÄ¼ÇÕß ¡£¸ß¼¶³ÖÐøÐÔÍþв£¨APT£© £¬¼´¹ú¶ÈÖ§³ÖµÄ¹¥»÷ÐÐΪÕß £¬³£½«Microsoft ExchangeµÈµç×ÓÓʼþϵͳ×÷Ϊ¹¥»÷Ö¸±ê ¡£Ä¿Ç° £¬¡¶»ªÊ¢¶ÙÓʱ¨¡·ÉÐδ¹«¿ª·ÖÏíÕâ´ÎÏ®»÷µÄÈκÎϸ½Ú £¬Õâ´ÎÊÂÎñÔÙ´Î͹ÏÔÁ˵ç×ÓÓʼþÏµÍ³Ãæ¶ÔµÄ°²È«·çÏÕ £¬ÓÈÆäÊÇÕë¶ÔÌØ¶¨ÐÐÒµºÍÖ÷Ìâ¼ÇÕßµÄÕë¶ÔÐÔ¹¥»÷ £¬¸øÐÂÎÅ»ú¹¹µÄÐÅÏ¢°²È«´øÀ´ÁËÑϸñÌôÕ½ ¡£


https://www.bleepingcomputer.com/news/security/washington-posts-email-system-hacked-journalists-accounts-compromised/


4. ZoomcarÔâδÊÚȨ½Ó¼ûÖÂ840ÍòÓû§Êý¾Ýй¶


6ÔÂ16ÈÕ £¬ZoomcarÊÇÓ¡¶ÈÒ»¼Òµã¶ÔµãÆû³µ¹²ÏíÊг¡¹«Ë¾ £¬½«³µÖ÷ÓëÑÇÖÞÐÂÐËÊг¡×â³µÕßÏàÁ¬ £¬Ìṩ¶ÌÆÚºÍÖÐÆÚÆû³µ×âÁÞ·þÎñ ¡£Zoomcar´«µÝ³Æ £¬6ÔÂ9ÈÕ·¢ÏÖÒ»Â·Éæ¼°Î´¾­ÊÚȨ½Ó¼ûÆäÐÅϢϵͳµÄÍøÂ簲ȫÊÂÎñ ¡£¹«Ë¾ÔÚ²¿ÃÅÔ±¹¤ÊÕµ½ÍþвÐÐΪÕßÖ¸¿ØÎ´¾­ÊÚȨ½Ó¼û¹«Ë¾Êý¾ÝµÄ±í²¿Í¨Ñ¶ºó £¬²ÅÒâʶµ½ÕâÒ»ÊÂÎñ ¡£³õ´ëÊ©²éÏÔʾ £¬840Íò¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢³µÁ¾µÇ¼ÇºÅÂë¡¢¼Òͥסַ¡¢µç×ÓÓʼþµÈÊý¾ÝÒѱ»Ð¹Â¶¸øÎ´¾­ÊÚȨµÄÒ»·½ ¡£²»Íâ £¬Zoomcar°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢Óû§²ÆÕþÐÅÏ¢¡¢Ã÷ÎÄÃÜÂë»òÆäËû¿ÉÄܵ¼ÖÂÓ×ÎÒÉí·Ýʶ´ËÍâÃô¸ÐÊý¾Ý±»Ð¹Â¶ ¡£Ä¿Ç° £¬ZoomcarÈÔÔÚÆÀ¹À¸Ã°²È«ÊÂÎñµÄ¾ßÌåÁìÓòºÍDZÔÚÓ°Ïì £¬¹¥»÷ÀàÐÍÉÐδȷ¶¨ £¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü ¡£ÖµµÃÒ»ÌáµÄÊÇ £¬2018ÄêZoomcar¾ÍÔâ·ê¹ýÁíÒ»´Î³Á´óÊý¾Ýй¶ £¬Ð¹Â¶Á˳¬350Íò¿Í»§¼Í¼ £¬ÕâЩÊý¾Ý×îÖÕÓÚ2020ÄêÔÚµØÏÂÊг¡ÏúÊÛ £¬Ê¹¿Í»§Ãæ¶Ô¸ü¸ß·çÏÕ ¡£


https://www.bleepingcomputer.com/news/security/zoomcar-discloses-security-breach-impacting-84-million-users/


5. ¶à¹ú½áºÏÐж¯µ·»Ù°µÍø¶¾Æ·ÂòÂôÊг¡Archetyp Market


6ÔÂ16ÈÕ £¬Óɵ¹ú¾¯·½Ç£Í· £¬Å·ÖÞÐ̾¯×éÖ¯ºÍÅ·ÖÞ˾·¨×éÖ¯Ö§³ÖµÄ¡°Éî²ãÉÚ±øÐж¯¡±µ·»ÙÁ˳ôÃûÔ¶ÑïµÄ°µÍø¶¾Æ·ÂòÂôÊг¡Archetyp Market ¡£¸ÃÊг¡×Ô2020Äê5ÔÂÔËÓª £¬Âô¼Òͨ¹ý3200¶à¼Ò×¢²á¹©¸øÉ̺ͳ¬17000¸öÇåµ¥ £¬Îª612000¶àÃûÓû§Ìṩ¿É¿¨Òò¡¢°²·ÇËûÃ÷¡¢º£ÂåÒò¡¢´óÂé¡¢MDMAºÍ·ÒÌ«ÄáµÈ´óÁ¿¶¾Æ· £¬ÃÅÂÞ±Ò¼ÓÃÜÇ®±ÒÂòÂô×ÜÂòÂôÁ¿³¬2.5ÒÚÅ·Ôª£¨Ô¼2.89ÒÚÃÀÔª£© ¡£ÔÚÐж¯ÖÐ £¬ºÉÀ¼µ÷²éÈËÔ±·ÛËéÆä»ù´¡ÉèÊ© £¬Î÷°àÑÀ°ÍÈûÂÞÄÇ¿ÛÁôÒ»ÃûÉæÏÓµ£ÈÎÊг¡ÖÎÀíÔ±µÄ30ËêµÂ¹ú¹úÃñ £¬µÂ¹úºÍÈðµä»¹¿ÛÁôÁËÒ»ÃûÖÎÀíÔ±ºÍÁùÃûµÚÒ»Á÷±ð¹©¸øÉÌ ¡£·¨ÂÉÈËÔ±¹²½É»ñ47²¿ÖÇÄÜÊÖ»ú¡¢45̨µçÄÔ¡¢¶¾Æ·ÒÔ¼°¼ÛÖµ780ÍòÅ·ÔªµÄ×ʲú ¡£Å·ÖÞÐ̾¯×éÖ¯³Æ £¬6ÔÂ11ÈÕÖÁ13ÈÕ £¬¶à¹ú²ÉȡЭͬҵ¶¯ £¬Ô¼300Ãû¾¯Ô±²Î¼Ó £¬Ö¸±êÊÇÆ½Ì¨ÖÎÀíÔ±¡¢°æÖ÷¡¢ÖØÒª¹©¸øÉ̺ͼ¼Êõ»ù´¡ÉèÊ© £¬Õâ´Î½ø¹¥·ÛËéÁ˰µÍøÉϳÖÐø¹¦·ò×µÄ¶¾Æ·Êг¡Ö®Ò» £¬¶Â½ØÁËÖØÒª¹©¸øÏß ¡£´Ë±í £¬5Ô·¨Âɲ¿ÃÅÔÚ¡°RapTorÐж¯¡±ÖÐÓÖ¿ÛÁô270ÃûÏÓÒÉÈË £¬¸ÃÐж¯Õë¶ÔÀ´×Ô10¸ö¹ú¶ÈµÄ°µÍø¹©¸øÉ̼°Æä¿Í»§ £¬Å·ÖÞ¡¢ÄÏÃÀ¡¢ÑÇÖÞºÍÃÀ¹úµÄ¾¯Ô±»¹½É»ñ³¬2¶Ö¶¾Æ·¡¢³¬1.84ÒÚÅ·ÔªÏÖ½ðºÍ¼ÓÃÜÇ®±ÒÒÔ¼°³¬180֧ǹ֧ ¡£µ÷²éÈËÔ±µ·»Ù¶à¸ö°µÍøÊг¡ºóÍøÂçµý±¨ £¬¼ø±ð³öºÜ¶àÔÚ·¸·¨ÍøÉÏÊг¡½øÐÐÊýǧ±ÊÏúÊÛµÄÏÓÒÉÈË ¡£


https://www.bleepingcomputer.com/news/security/police-seizes-archetyp-market-drug-marketplace-arrests-admin/


6. ±±¿¨°¢Ê²Î¬¶ûÑÛ¿ÆÐ­»áÊý¾Ýй¶ £¬14.7ÍòÈËÐÅÏ¢±»µÁ


6ÔÂ16ÈÕ £¬±±¿¨ÂÞÀ´ÄÉÖݰ¢Ê²Î¬¶ûÑÛ¿ÆÐ­»á£¨AEA£©Í¨ÖªÔ¼147,000ÃûÓ×ÎÒ £¬ÆäÓ×ÎÒÐÅÏ¢ÔÚ2024Äê11ÔµÄÊý¾Ýй¶ÊÂÎñÖб»µÁ ¡£¸ÃÊÂÎñÓÚ11ÔÂ18ÈÕ±»·¢ÏÖ £¬ÆäʱÍþвÐÐΪÕß½øÈë¹«Ë¾ÍøÂç²¢ÇÔÈ¡ÁËijЩÎļþ ¡£AEAѸËÙÀñƸµÚÈý·½×¨¼ÒЭÖú±£»¤ÍøÂç»·¾³²¢µ÷²éÊÂÎñ ¡£¶Ô±»µÁÊý¾ÝµÄµ÷²éÓÚ2025Äê4ÔÂ14ÈÕʵÏÖ £¬È·¶¨ÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢Ò½ÖÎÏêÇéºÍ½¡È«±£ÏÕÐÅÏ¢µÈÓ×ÎÒÐÅÏ¢ÔÚÏ®»÷Öб»µÁ ¡£½ØÖÁ֪ͨ·¢³öʱ £¬AEAÉÐδÊÕµ½ÈκÎÓë´ËÊÂÎñÓйصÄÉí·Ý͵ÇԻ㱨 ¡£¸ÃÑÛ¿ÆÖÐÐÄ×î³õÓÚ1ÔÂ31ÈÕÏòÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿Åû¶ÁËÕâÒ»ÊÂÎñ £¬Æäʱ³ÆÓÐ193,306ÈËÊÜÓ°Ïì £¬ºó¸ÃÊý×Ö¸üÐÂΪ204,984ÈË ¡£Èç½ñ £¬AEA°µÊ¾ÒÑÈ·¶¨ÊÜÓ°Ïì¼Í¼ÖÐÔ̺¬¸ü¶àÓ×ÎÒÐÅÏ¢µÄÓ×ÎÒ £¬²¢Ïò147,116ÈË·¢ËÍÁË֪ͨÐÅ £¬»¹ÎªËûÃÇÌṩ12¸öÔµÄÃâ·ÑÉí·Ý͵ÇÔ±£»¤·þÎñ ¡£²»Íâ £¬AEAÉÐδй©ÆäÔâ·êµÄÍøÂç¹¥»÷ÀàÐ͵ľßÌåÐÅÏ¢ ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬DragonForceÀÕË÷Èí¼þÍÅ»ïÓÚ12Ô½«AEAÔö³¤µ½Æä»ùÓÚTorµÄйÃÜÍøÕ¾ £¬Ðû³ÆÇÔÈ¡Á˽ü540GBµÄÊý¾Ý £¬ÇÒ¸Ã×éÖ¯¶ûºóÒѽ«ÕâЩÊý¾Ý¹«¿ª ¡£


https://www.securityweek.com/asheville-eye-associates-says-147000-impacted-by-data-breach/