ÀïÊ¿Âú·ÅÉäѧЭ»áÅû¶³¬140ÍòÈËÊý¾Ýй¶ÊÂÎñ

°ä²¼¹¦·ò 2025-07-21

1. ÀïÊ¿Âú·ÅÉäѧЭ»áÅû¶³¬140ÍòÈËÊý¾Ýй¶ÊÂÎñ


7ÔÂ20ÈÕ £¬Õ¼ÓаÙÄ꺹ÇàµÄÃÀ¹ú¸¥¼ªÄáÑÇÖݸöÈË·ÅÉä¿ÆÕïËùÀïÊ¿Âú·ÅÉäѧЭ»á£¨Radiology Associates of Richmond, RAR£©¹«¿ªÅû¶ÁËһ·´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁìÓò¸²¸Ç³¬¹ý140ÍòÈ˵ÄÓ×ÎÒÐÅÏ¢¼°Êܱ£»¤½¡È«ÐÅÏ¢£¨PHI£©¡£¾Ýµ÷²é £¬ÍþвÐÐΪÕßÓÚ2024Äê4ÔÂ2ÈÕÖÁ6ÈÕÆÚ¼äÈëÇÖRARϵͳ £¬µ«Ö±ÖÁ2025Äê5ÔÂ2ÈÕͨ¹ý±í²¿ÍøÂ簲ȫר¼ÒЭÖúµÄȡ֤·ÖÎö £¬²ÅÈ·ÈÏÆäÍøÂç»·¾³ÖдæÔÚδ¾­ÊÚȨµÄ½Ó¼û £¬²¢µ¼ÖÂÔ̺¬Éç±£ºÅÂëµÈÃô¸ÐÊý¾ÝµÄй¶¡£RARÇ¿µ÷ £¬Ö»¹ÜĿǰÎÞÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»ÀÄÓà £¬µ«ÒÑ×Ô¶¯Í¨ÖªÊÜÓ°Ïì¸ö±ð £¬²¢ÎªÉç±£ºÅÂëй¶ÕßÌṩÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ £¬Í¬Ê±½¨ÒéÓйØÈËÔ±³ÖÐø¹Ø×¢²ÆÕþ¼°Ò½ÁƼͼÒì³£¡£×÷Ϊ¸¥¼ªÄáÑÇÖÝÖв¿³ÁÒªµÄÒ½ÁÆÓ°Ïñ·þÎñÌṩÉÌ £¬RAR×Ô1905Äê³ÉÁ¢ÒÔÀ´ £¬Ê¼ÖÕΪ¶à¼ÒÒ½ÔººÍÃÅÕï»ú¹¹ÌṩX¹â¡¢CT¡¢MRIµÈÕï¶Ï¼°È¾Ö¸ÊÖÊõÖ§³Ö¡£Õâ´ÎÊÂÎñ¶³ö³öÆäÍøÂ簲ȫ·ÀÓùµÄDZÔÚ·ì϶ £¬¹¥»÷Õßͨ¹ý³Ö¾ÃÂñ·üʵÏÖÁ˶ÔϵͳµÄÉî¶ÈÉøÈë £¬Í¹ÏÔÒ½ÁÆÐÐÒµÔÚÊý¾Ý±£»¤ÉÏÃæ¶ÔµÄÑϸñÌôÕ½¡£


https://securityaffairs.com/180128/data-breach/radiology-associates-of-richmond-data-breach-impacts-1-4-million-people.html


2. Ê¢ÐеÄnpm°ü±»ÍøÂç´¹µö½Ù³Ö £¬ÓÃÓÚÖ²Èë¶ñÒâÈí¼þ


7ÔÂ19ÈÕ £¬Ê¢ÐÐnpm°üeslint-config-prettier¼°Æä¹ØÁª¿âÒòÊØ»¤ÕßÔâ·êÍøÂç´¹µö¹¥»÷ £¬±»Ö²Èë¶ñÒâ´úÂë²¢°ä²¼ÖÁ¹Ù·½²Ö¿â £¬Ó°ÏìÊý°ÙÍò¿ª·¢Õß¡£Õâ´Î¹©¸øÁ´¹¥»÷ͨ¹ýÇÔÈ¡ÊØ»¤Õ߯¾Ö¤ÊµÏÖ £¬Í¹ÏÔ¿ªÔ´Éú̬ϵͳµÄ°²È«´àÈõÐÔ¡£¹¥»÷Ö¸±êÔ̺¬Ã¿ÖÜÏÂÔØÁ¿³¬3000Íò´ÎµÄeslint-config-prettier¼°ÆäËû¹ØÁª°ü¡£ÊØ»¤ÕßJounQinÈ·ÈÏ £¬ÆänpmÁîÅÆÒòµã»÷¼Ù×°³É¡°support@npmjs.com¡±µÄ´¹µöÓʼþ±»µÁ £¬µ¼Ö¹¥»÷Õß°ä²¼¶ñÒâ°æ±¾¡£ÕâЩ°æ±¾µÄºó×°Öþ籾£¨install.js£©Ô̺¬Òñ±Îº¯ÊýlogDiskSpace() £¬ÏÖʵͨ¹ýrundll32Ö´Ðа󸿵Änode-gyp.dllľÂí¡£¸ÃDLLÔÚVirusTotalÉϼì²âÂʽö19/72 £¬Åú×¢ÎÞÊýɱ¶¾Èí¼þδÄܼø±ð¡£ÊÂÎñÆØ¹âºó £¬¿ªÔ´ÉçÇøÑ¸ËÙÏìÓ¦£ºJounQinÒѳ·Ïú±»µÁÁîÅÆ²¢´òËã°ä²¼½¨¸´°æ±¾ £¬ÊÜÓ°Ïì°ü±»ÏóÕ÷Ϊ¡°ÒÑÆúÓᱡ£¿ª·¢Õß±»ÖÒ¸æÔ¤·ÀʹÓÃÌØ¶¨¶ñÒâ°æ±¾ £¬²¢Ðè²é³­package-lock.jsonµÈËøÎļþ¼°CIÈÕÖ¾ £¬ÓÈÆäÊÇWindows»·¾³ÏµÄÒì³£ÐÐΪ¡£´Ë±í £¬½¨ÒéÂÖ»»¿ÉÄܶ³öµÄÃÜÔ¿ £¬²¢¾¯ÌèÊØ»¤Õ߯äËû°üµÄDZÔڴ۸ġ£


https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/


3. еÄCrushFTPÁãÈÕ·ì϶±»ÀûÓÃÀ´½Ù³Ö·þÎñÆ÷


7ÔÂ18ÈÕ £¬ÆóÒµÎļþ´«Êä·þÎñÆ÷CrushFTPÅû¶һ·ÔÚ±»»ý¼«ÀûÓõÄÁãÈÕ·ì϶£¨CVE-2025-54309£© £¬¸Ã·ì϶ÔÊÐí¹¥»÷Õßͨ¹ýWeb½çÃæÖ±½Ó»ñÈ¡·þÎñÆ÷ÖÎÀíȨÏÞ¡£×÷Ϊ֧³ÖFTP¡¢SFTP¡¢HTTP/SµÈºÍ̸µÄ°²È«Îļþ¹²ÏíÆ½Ì¨ £¬CrushFTPµÄ·ì϶¶³öÒý·¢¶Ô¹Ø¼ü»ù´¡ÉèÊ©Êý¾Ýй¶·çÏÕµÄ¿í·º¹Ø×¢¡£¾ÝCrushFTPÊ×ϯִÐйÙBen Spink֤ʵ £¬ÍþвÐÐΪÕß×Ô7ÔÂ18ÈÕÆðÆðÍ·´ó¹æÄ£ÀûÓô˷ì϶ £¬µ«ÏÖʵ¹¥»÷¿ÉÄÜÔçÓÚ7ÔÂ1ÈÕ°ä²¼µÄ¾É°æ±¾£¨v10.8.5¼°v11.3.4_23֮ǰ£©¡£ÖµÍ×ÌùÐĵÄÊÇ £¬¸Ã¹«Ë¾´ËǰÕë¶ÔHTTP(S)ºÍ̸ÖÐAS2ÓйØÎÊÌâµÄ½¨¸´Òâ±í×è¶ÏÁËÕâ´ÎÁãÈÕ·ì϶µÄÀûÓÃõè¾¶ £¬Í¨¹ýĬÈϹعز¿ÃÅµÍÆµÖ°ÄÜ £¬¼ä½ÓÌáÉýÁËϵͳ°²È«ÐÔ¡£È»¶ø £¬¹¥»÷Õßͨ¹ýÄæÏò¹¤³Ì¼ø±ð³öδ±»ÆëÈ«½¨¸´µÄ·ì϶ £¬²¢Õë¶Ôδ¸üÐÂϵͳÌáÒ鶨Ïò¹¥»÷¡£CrushFTPÇ¿µ÷ £¬ÊµÊ±Éý¼¶ÖÁ×îа汾¿ÉÆëÈ«¶ã±Ü·çÏÕ £¬¶øÑ¡È¡DMZ¸ôÀëÖ÷·þÎñÆ÷µÄÆóÒµ¿Í»§Ôò²»ÊÜÓ°Ïì¡£¶ÔÓÚÒÑÔâÈëÇÖµÄϵͳ £¬ÖÎÀíÔ±Ðè²é³­MainUsers/default/user.XMLÎļþÊÇ·ñ´æÔÚÒì³£Åú¸Ä»òδ֪ÖÎÀíÔ¹ØË»§¡£´Ë±í £¬ÉÏ´«ÏÂÔØÈÕÖ¾ÖеÄÒì³£»î¶¯¡¢Ä¬ÈÏÓû§ÅäÖñ»´Û¸ÄµÈ¾ùΪ¹Ø¼üÈëÇÖÖ¸±ê¡£


https://www.bleepingcomputer.com/news/security/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers/


4. ÈÕ±¾½áºÏ¹ú¼Ê»ú¹¹°ä²¼PhobosºÍ8BaseÀÕË÷Èí¼þÃâ·Ñ½âÃÜÆ÷


7ÔÂ18ÈÕ £¬ÈÕ±¾¾¯·½½áºÏÅ·ÖÞÐ̾¯×éÖ¯µÈ»ú¹¹ £¬Õë¶Ô¿í·º´«²¼µÄPhobosºÍ8BaseÀÕË÷Èí¼þ¼Ò×å°ä²¼Ãâ·Ñ½âÃܹ¤¾ß £¬ÎªÈ«ÇòÊܺ¦ÕßÌṩÎÞÐèÖ§¸¶Êê½ðµÄÎļþ¸´Ô­¹æ»®¡£¸Ã½âÃÜÆ÷Ö§³Ö.phobos¡¢.8base¡¢.elbie¡¢.faust¡¢.LIZARDµÈ¶àÖÖÀ©´óÃûÎļþ £¬¿É´ÓÈÕ±¾¾¯·½¹ÙÍø¼°Å·ÖÞÐ̾¯×éÖ¯¡°NoMoreRansom¡±Æ½Ì¨ÏÂÔØ¡£Ö»¹Ü²¿ÃÅä¯ÀÀÆ÷Îó±¨Æä°²È«ÐÔ £¬µ«¾­²âÊԸù¤ÓµÓÐЧÇÒÎÞº¦ £¬Òѱ»ÃÀ¹úFBIµÈ»ú¹¹ÍƹãΪ¹Ù·½Êý¾Ý¸´Ô­½â¾ö¹æ»®¡£²»Íâ £¬NoMoreRansomÌáÐÑÓû§ £¬Ê¹ÓÃǰÐèÏÅ×ÿ¿µÃס·À²¡¶¾Èí¼þ¶Ï¸ùϵͳÄÚ¶ñÒâÈí¼þ £¬²»È»Îļþ¿ÉÄܱ»·´¸´¼ÓÃÜ¡£PhobosÀÕË÷Èí¼þ×Ô2019Äê5ÔÂÆðÒÔ¡°ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©¡±Ä£Ê½»îÔ¾ £¬Æä±äÖÖͨ¹ý´¹µöÓʼþ¡¢RDP¶Ë¿ÚɨÃèµÈ¼¿Á©ÈëÇÖÍøÂç £¬ÀûÓÃSmokeloader¡¢Cobalt StrikeµÈ¿ªÔ´¹¤¾ß´«²¼¡£2023Äê £¬¹ØÁª×éÖ¯8Base¸¡ÏÖ £¬Ñ¡È¡Ë«³ÁÀÕË÷Õ½Êõ £¬²¢½«ÀÕË÷Èí¼þ×é¼þǶÈë¼ÓÃÜÔØºÉ £¬Í¨¹ýSmokeLoaderÄÚ´æ¼ÓÔØÖ´Ðй¥»÷¡£¸Ã×éÖ¯×Ô2022Äê3ÔÂÆðÕë¶Ô½ðÈÚ¡¢Ôì×÷µÈÐÐÒµµÄÖÐÓ×ÐÍÆóÒµ £¬2023Äê5-6Ô»¼¤Ôö £¬2024Äê3Ô±»ÃÀ¹úCISA¡¢FBIµÈ»ú¹¹½áºÏÔ¤¾¯¡£


https://securityaffairs.com/180108/malware/authorities-released-free-decryptor-for-phobos-and-8base-ransomware.html


5. ¶íÂÞ˹×î´ó¾ÆÀàÁãÊÛÉÌWineLabÔâÍøÂç¹¥»÷ÖÂÃÅµê¹Ø¹Ø


7ÔÂ18ÈÕ £¬¶íÂÞ˹×î´ó¾ÆÀàרÂôÁ¬ËøµêWineLab¼°Æäĸ¹«Ë¾Novabev Group½üÈÕÔâ·ê´ó¹æÄ£ÍøÂç¹¥»÷ £¬µ¼ÖÂÆäITϵͳ̱»¾¡¢ÃÅµê¹Ø¹Ø¼°ÏßÉÏ·þÎñÖжÏ¡£Õâ´ÎÊÂÎñ±»Novabev³ÆÎª¡°Ç°ËùδÓеÄЭͬ¹¥»÷¡± £¬¹¥»÷Õßͨ¹ýÈëÇÖ¼¯ÍÅIT»ù´¡ÉèÊ© £¬ÁÙʱÖжÏÁ˲¿ÃŹؼü·þÎñºÍ¹¤¾ßµÄ¿ÉÓÃÐÔ £¬Ö±½ÓÓ°ÏìWineLabÊýǧ¼ÒʵÌåµê¼°ÏßÉÏÒµÎñµÄÕý³£ÔËÓª¡£½ØÖÁ±¨Â·°ä²¼Ê± £¬¸Ã¹«Ë¾ÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬ £¬Òƶ¯ÀûÓòɰìÖ°ÄÜÒàÊÜÏÞ £¬ITÍŶÓÕýÈ«Ììºò½¨¸´ÏµÍ³¡£Õâ´Î¹¥»÷µ¼ÖÂÈ«¹úÃŵê×Ô7ÔÂ14ÈÕÆð¹Ø¹Ø £¬ÏßÉÏÅäËÍϵͳ̱»¾ £¬³ÉΪ¶íÂÞ˹½üÄêÀ´Ó°Ïì×î¿í·ºµÄÆóÒµ¼¶ÍøÂç¹¥»÷ÊÂÎñÖ®Ò»¡£Novabev¼¯ÍÅÈ·ÈÏ £¬¹¥»÷ÕßÌá³öÊê½ðÒªÇó £¬µ«¹«Ë¾Ã÷È·»Ø¾øÖ§¸¶ £¬²¢Ç¿µ÷¡°²»»áÂú×ãÈκÎÍþвÐÐΪÕßµÄǰÌᡱ¡£Ö»¹Üµ÷²éÈÔÔÚ½øÐÐ £¬¸Ã¹«Ë¾°µÊ¾ÉÐδ·¢ÏÖ¿Í»§Ó×ÎÒÊý¾Ýй¶µÄÖ¤¾Ý¡£Ä¿Ç° £¬ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯¹«¿ªÈÏÁìÕâ´Î¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/russian-alcohol-retailer-winelab-closes-stores-after-ransomware-attack/


6. ÃÀ¹ú°²Äݰ¢Â׵¶ûƤ·ô¿ÆÕïËùÊý¾Ýй¶ӰÏì190ÍòÈË


7ÔÂ18ÈÕ £¬2025Äê2ÔÂ14ÈÕÖÁ5ÔÂ13ÈÕÆÚ¼ä £¬ÃÀ¹úÖдóÎ÷Ñó¼°¶«Äϲ¿×î´óµÄƤ·ô¿ÆÒ½ÁÆ»ú¹¹Ö®Ò»°²Äݰ¢Â׵¶ûƤ·ô¿ÆÕïËù£¨AAD£©Ôâ·êÑϳÁÊý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁìÓò¸²¸Ç³¬¹ý190ÍòÈË¡£¸ÃÕïËù³ÉÁ¢ÓÚ50¶àÄêǰ £¬×ܲ¿Î»ÓÚÂíÀïÀ¼ÖÝ £¬ÔÚÆß¸öÖÝÔËÓª×Å100Óà¼ÒÕïËù £¬Õ¼ÓÐ275ÃûÁÙ´²Ò½Éú £¬ÌṩÄÚ¿Æ¡¢±í¿Æ¡¢ÃÀÈݼ°Æ¤·ô²¡ÀíѧµÈÈ«¿Æ·þÎñ¡£ÊÂÎñ²úÉúºó £¬AADѸËÙ¼ì²âµ½ÏµÍ³Òì³£²¢Æô¶¯·À»¤´ëÊ© £¬·¢Õ¹È«Ãæµ÷²é¡£5ÔÂ20ÈÕ £¬Éó²éÈ·ÈÏÈëÇÖÕß½Ó¼ûÁËÔ̺¬Ó×ÎÒÐÅÏ¢»ò½¡È«ÐÅÏ¢µÄÎļþ£»6ÔÂ27ÈÕ £¬ÕïËùÕýʽ֪ͨÊÜÓ°Ïì¸ö±ð £¬³Æ¡°¿ÉÄÜÉæ¼°ÐÕÃû¡¢ÁªÏµ·½Ê½¡¢Ò½ÁƼͼµÈÃô¸ÐÊý¾Ý¡± £¬µ«Ç¿µ÷Ŀǰδ·¢ÏÖÐÅÏ¢±»ÏÖʵÀÄÓûòڲƭµÄÖ¤¾Ý¡£Îª½µµÍ·çÏÕ £¬AADΪÊÜÓ°ÏìÕßÌṩ24¸öÔµÄÃâ·ÑÉí·Ý±£»¤·þÎñ £¬²¢½¨Ò鶨ÆÚ¼à¿ØÕË»§ÂòÂô¼°ÐÅÓþ»ã±¨¡£


https://securityaffairs.com/180100/data-breach/anne-arundel-dermatology-data-breach-impacts-1-9-million-people.html