ºÚ¿ÍÈëÇÖ°ÍÎ÷½¡È«ÐÅÏ¢¹«Ë¾ £¬Ö°ÍÎ÷Ïܱø¶ÓÊý¾Ýй¶

°ä²¼¹¦·ò 2025-09-26

1. ºÚ¿ÍÈëÇÖ°ÍÎ÷½¡È«ÐÅÏ¢¹«Ë¾ £¬Ö°ÍÎ÷Ïܱø¶ÓÊý¾Ýй¶


9ÔÂ22ÈÕ £¬ÍþвÐÐΪÕßÔÚµØÏÂÂÛ̳Ðû³ÆÈëÇÖ°ÍÎ÷½¡È«ÐÅÏ¢¹«Ë¾Maida.health £¬ÇÔÈ¡³¬2TB°ÍÎ÷Ïܱø¶ÓÃô¸ÐÊý¾Ý £¬º­¸Ç¾ü¹Ù¼°Æä¼ÒÈ˽¡È«¼Í¼¡¢Éí·ÝÖ¤¡¢Ò½ÁÆ·¢Æ±¡¢Õï¶Ï»ã±¨£¨º¬ÐÄÔಡѧ¡¢¾«Éñ²¡Ñ§¡¢¸¾¿ÆÑ§µÈר¿ÆÐÅÏ¢£©¼°ÁÙ´²»¼ÕßÊý¾Ý ¡£Êý¾ÝÈôÊôʵ £¬½«Òý·¢ÑϳÁÒþÖÔ·çÏÕ £¬Ò½ÁÆ·¢Æ±ÓëÌå¼ì»ã±¨Ô̺¬Õï¶ÏÁ˾֡¢Ó×ÎÒÉí·ÝÐÅÏ¢ £¬¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ»òÒ½ÁÆÚ²Æ­ £¬ÀýÈç·¸×ï·Ö×Ó¼ÙÒâÊܺ¦Õß»ñÈ¡´¦·½Ò©»òÒ½ÁÆ·þÎñ ¡£°ÍÎ÷Ïܱø×÷Ϊ¹ú¶ÈÔìʽ¶ÓÁÐ £¬Õƹܴ¦Ëù¹«¹²ÖÈÐòÊØ»¤ £¬ÆäÊý¾ÝÐ¹Â¶Éæ¼°¾ü¹Ù¼°¾ìÊôÒþÖÔ £¬Ó°ÏìÁìÓò¿í·º ¡£Maida.health×÷ΪÄêÓªÊÕ4590ÍòÃÀÔªµÄÒ½ÁÆÊý×Ö·þÎñÉÌ £¬Ìṩ±£ÏÕÀíÅâÖÎÀí¡¢Õ˵¥´¦Öá¢Ô¶³ÌÕ÷ѯµÈAI×Ô¶¯»¯·þÎñ £¬Õâ´ÎÊÂÎñ͹ÏÔµÚÈý·½·þÎñÌṩÉ̵ݲȫ·ì϶·çÏÕ ¡£


https://cybernews.com/security/brazil-police-health-data-breach/


2. ÃÀ¹úÊÕÈëÈËÊÙ±£ÏÕAILÊýÊ®Íò¿Í»§¼Í¼±»µÁ


9ÔÂ22ÈÕ £¬ÃÀ¹ú´óÐͲ¹³ä±£ÏÕÌṩÉÌÃÀ¹úÊÕÈëÈËÊÙ£¨AIL£©Ôâ·êÊý¾Ýй¶ £¬¹¥»÷ÕßÔÚÈȵãÊý¾Ýй¶ÂÛ̳Ðû³ÆÇÔÈ¡ÁËÊýÊ®ÍòÌõ¿Í»§¼Í¼ £¬Éæ¼°È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÁªÏµÐÅÏ¢¼°±£µ¥×´Ì¬¡¢±£ÏÕ´òËãÃû³ÆµÈÃô¸ÐÐÅÏ¢ ¡£×êÑÐÍŶÓÑéÖ¤Êý¾ÝÑù±¾ºóÈ·ÈÏ £¬Ô¼15Íò±Ê¼Í¼Óë¹¥»÷ÕßÃèÊöÒ»Ö £¬ÐÅÏ¢ÕæÊµÐԽϸß ¡£AIL×÷ΪȫÇòÈËÊÙ£¨ÄêÊÕÈ볬57ÒÚÃÀÔª£©ÆìÏÂ×Ó¹«Ë¾ £¬×ܲ¿Î»Óڵ¿ËÈøË¹ÖÝ £¬ÊÇÃÀ¹ú×î´óµÄ²¹³ä±£ÏÕÌṩÉÌÖ®Ò» ¡£Õâ´ÎÊÂÎñ¶³ö¶à³Á·çÏÕ£ºÓ×ÎÒÐÅÏ¢×éºÏ£¨ÈçÈ«Ãû+µ®ÉúÈÕÆÚ£©¿É±»ÓÃÓÚÉí·Ý͵ÇÔ £¬·¸×ï·Ö×Ó¿ÉÄÜ¿ªÉèڲƭÕË»§µ¼ÖÂÊܺ¦Õß¾­¼ÃËðʧ»òÐÅÓþÆÀ·ÖÊÜËð £»Ò½Áƺͱ£ÏÕÊý¾ÝÒò²»³É¸´Ô­¸öÐÔ£¨È粡ʷÎÞ·¨Åú¸Ä£© £¬³Ö¾ÃÃæ¶Ô±»ÀÄÓ÷çÏÕ £»¹¥»÷Õß»¹¿ÉÀûÓÃÓ×ÎÒÐÅÏ¢Ö´Ðо«×¼ÍøÂç´¹µö £¬¼ÙÒâ±£ÏÕ¹«Ë¾»ò½¡È«×¨¼ÒÓÕÆ­Êܺ¦Õßй¶¸ü¶àÃô¸ÐÐÅÏ¢ ¡£


https://cybernews.com/security/american-income-life-data-breach-claims/


3. ΢Èí¸æ·¢XCSSET macOS¶ñÒâÈí¼þбäÖÖ


9ÔÂ25ÈÕ £¬Î¢ÈíÍþвµý±¨ÖÐÐĽüÈÕ°ä²¼»ã±¨ £¬Ö¸³öÔÚÓÐÏÞ¹¥»÷³¡¾°Öмì²âµ½XCSSET macOS¶ñÒâÈí¼þµÄбäÖÖ £¬¸Ã±äÖÖ¼¯³ÉÈý´óÖ÷ÌâÉý¼¶£º¼ÓÇ¿µÄä¯ÀÀÆ÷Êý¾Ý¶¨Î»ÄÜÁ¦¡¢¼ôÌù°å½Ù³ÖÄ£¿éÓÅ»¯¼°¸Ä½øµÄÓÆ¾ÃÐÔ»úÔì ¡£×÷ΪÄ£¿é»¯¶ñÒâÈí¼þ £¬XCSSET¼æ¾ßÐÅÏ¢ÇÔÈ¡Óë¼ÓÃÜÇ®±ÒµÁȡְÄÜ £¬¿ÉÇÔÈ¡ÊÜϰȾÉ豸µÄ±Ê¼Ç¡¢¼ÓÃÜÇ®±ÒÇ®°ü¼°ä¯ÀÀÆ÷º¹ÇàµÈÃô¸ÐÊý¾Ý £¬Æä¹ÖÒì´«²¼·½Ê½ÔÚÓÚͨ¹ýϰȾ¿ª·¢Õß³£ÓõÄXcodeÏîĿʵÏÖºáÏòÉøÈë £¬µ±ÏîÄ¿¹¹½¨Ê±×Ô¶¯Ö´ÐжñÒâ´úÂë £¬ÒÀÀµ¿ª·¢ÈËÔ±¹²ÏíÏîÄ¿ÎļþµÄºÏ×÷³¡¾°À©´óϰȾÁìÓò ¡£Ð±äÖÖÔÚ¼¼Êõ²ãÃæ³öÏÖÏÔÖø½ø»¯£ºÆäÒ» £¬Í¨¹ýǶÈëÅú¸Ä°æ¿ªÔ´¹¤¾ßHackBrowserData £¬ÊµÏÖ¶ÔFirefoxä¯ÀÀÆ÷Êý¾ÝµÄ¶¨Ïò½âÃÜÓëµ¼³ö £»Æä¶þ £¬¼ôÌù°å½Ù³Ö×é¼þ¸üÐÂÖ§³Ö¼ø±ð¼ÓÃÜÇ®±ÒµØÖ·µÄÕýÔò±í°×ʽģʽ £¬¼ì²âµ½ÓйصØÖ·Ê±×Ô¶¯´úÌæÎª¹¥»÷ÕßÇ®°üµØÖ· £¬µ¼ÖÂÓû§ÂòÂô×ʽ𱻽ØÁ÷ £»ÆäÈý £¬ÓƾÃÐÔ»úÔìѡȡ˫³Á¼Ù×°Õ½Êõ ¡£


https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-xcsset-macos-malware-variant-targeting-xcode-devs/


4. ¾¯Ìènpm"postmark-mcp"¶ñÒâ°ü°µ²ØÓʼþÇÔÈ¡´úÂë


9ÔÂ25ÈÕ £¬Koi Security×êÑÐÈËÔ±½üÈÕÅû¶ £¬npmƽ̨ÉÏÃûΪ"postmark-mcp"µÄ¶ñÒâÈí¼þ°üÔÚ1.0.16°æ±¾ÖÐÖ²ÈëÇÔÈ¡´úÂë £¬¸Ã°ü¼Ù×°³ÉGitHub¹Ù·½ÏîÖ÷ÕźϷ¨¶Ë¿Ú £¬¾­15´Îµü´úºóÓÚ1.0.16°æÔö³¤¶ñÒâÐо¶ £¬½«Óû§ËùÓеç×ÓÓʼþת·¢ÖÁ¹ØÁªÓòÃûgiftshop[.]club ¡£¸Ã¶ñÒâ°üÔÚnpm´æÔÚÒ»ÖÜÆÚ¼äÏÂÔØÁ¿´ï1500´Î £¬¿ÉÄÜÒÑÇÔÈ¡Êýǧ·âÔ̺¬ÃÜÂë³ÁÖá¢Ë«³É·ÖÑéÖ¤Âë¡¢²ÆÕþÐÅÏ¢¼°¿Í»§ÏêÇéµÈÃô¸ÐÓʼþ £¬×é³ÉÑϳÁÊý¾Ýй¶·çÏÕ ¡£×÷Ϊ»ùÓÚÄ£Ð͸ߵÍÎĺÍ̸£¨MCP£©µÄ·þÎñÆ÷ £¬Postmark MCP±¾Ó¦Í¨¹ý½á¹¹»¯¡¢Ô¤Ô¼ÒåµÄ°²È«½Ó¿ÚΪAI¸±ÊÖÌṩÓʼþ·¢ËÍÖ°ÄÜ ¡£È»¶ø £¬Õâ´ÎÊÂÎñ¶³ö³öMCP°²È«Ä£Ð͵ÄÖÂÃüȱµã£º¸ßȨÏÞÔËÐеķþÎñÆ÷Ôڹؼü»·¾³Öв»×ãÓÐЧ¼à¶½ÓëɳºÐ¸ôÀë £¬µ¼ÖÂAI¸±ÊÖ¿ÉÖ´ÐÐδ¹ýÂ˵ĶñÒâºÅÁî ¡£Koi SecurityÇ¿µ÷ £¬ÕâÖÖ"ÎÞɳºÐ"¼Ü¹¹Ê¹Èκηì϶»òÅäÖÃÃýÎ󶼿ÉÄÜÒý·¢¿àÄÑÐÔºó¹û ¡£¹¥»÷Õßͨ¹ýαÔìÓë¹Ù·½°ü¸ß¶ÈÒ»ÖµĴúÂëºÍÃèÊöÖ´Ðй©¸øÁ´¹¥»÷ £¬1.0.15¼°Ö®Ç°°æ±¾Î¬³ÖÇå½àÒÔ³ÉÁ¢ÐÅÀµ £¬1.0.16°æºöÈ»×¢ÈëÇÔÈ¡Âß¼­ ¡£


https://www.bleepingcomputer.com/news/security/unofficial-postmark-mcp-npm-silently-stole-users-emails/


5. ˼¿Æ¶½´Ù¿Í»§½¨²¹Á½¸öÔÚ±»ÀûÓõÄÁãÈÕ·ì϶


9ÔÂ25ÈÕ £¬Ë¼¿Æ½üÈÕ°ä²¼´¹Î£°²È«²¼¸æ £¬¶½´Ù¿Í»§Á¢¼´½¨²¹Á½¸öÔÚ±»¹¥»÷ÕßÀûÓõÄÁãÈÕ·ì϶£¨CVE-2025-20333ºÍCVE-2025-20362£© £¬ÕâÁ½¸ö·ì϶ӰÏìÆä×ÔÊÊÓ¦°²È«É豸£¨ASA£©ºÍ·À»ðǽÍþв·ÀÓù£¨FTD£©Èí¼þ ¡£ÆäÖÐ £¬CVE-2025-20333ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë £¬¶øCVE-2025-20362Ôòʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄܽӼûÊÜÏÞURL¶Ëµã ¡£Ë¼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©ÒÑ֤ʵ´æÔÚÕë¶ÔÕâЩ·ì϶µÄ¹¥»÷³¢ÊÔ £¬²¢Ç¿ÁÒ½¨ÒéÓû§Éý¼¶ÖÁ½¨¸´°æ±¾ ¡£Õâ´Î°²È«¸üл¹Í¬Ê±½¨²¹Á˵ÚÈý¸öÑϳÁ·ì϶£¨CVE-2025-20363£© £¬¸Ã·ì϶ͬÑùÔÊÐíδ¾­ÊÚȨµÄÔ¶³Ì¹¥»÷ÕßÔÚδ´ò²¹¶¡µÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë ¡£Ë¼¿Æ³ö¸ñ¸Ð¼¤°Ä´óÀûÑÇ¡¢¼ÓÄôó¡¢Ó¢¹ú¼°ÃÀ¹úÍøÂ簲ȫ»ú¹¹Ð­Öúµ÷²éÕâЩÁãÈÕ¹¥»÷ ¡£


https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-firewall-zero-days-exploited-in-attacks/


6. ÎÖ¶ûÎÖ±±ÃÀ¹©¸øÉÌÔâÀÕË÷¹¥»÷ÖÂ87ÍòÕË»§Êý¾Ýй¶


9ÔÂ25ÈÕ £¬ÎÖ¶ûÎÖ±±ÃÀ¹«Ë¾Åû¶ £¬ÆäµÚÈý·½ÈËÁ¦×ÊÔ´Èí¼þ¹©¸øÉÌMilj?dataÓÚ2025Äê8ÔÂ20ÈÕÔâ·êÀÕË÷Èí¼þ×éÖ¯DataCarry¹¥»÷ £¬µ¼ÖÂÖÁÉÙ25¼ÒÆóÒµ¼°200¸öÈðµäÊÐÕþ»ú¹¹µÄÔ±¹¤Êý¾Ýй¶ ¡£Õâ´Î¹¥»÷Ó°ÏìÁËÓÃÓÚ´¦ÖÃÒ½ÁÆÖ¤Ã÷¡¢¹¤É˻㱨¼°¿µ¸´Êºú˵ÄÖÎÀíϵͳ £¬Ð¹Â¶Êý¾ÝÉæ¼°87Íò¸öÕË»§ £¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÏÖʵµØÖ·¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢µ®ÉúÈÕÆÚ¼°ÐÔ±ðµÈÃô¸ÐÐÅÏ¢ ¡£¾ÝÎÖ¶ûÎÖÏòÂíÈøÖîÈûÖݼì²ì×ܳ¤Ìá½»µÄ»ã±¨ÏÔʾ £¬Ö»¹ÜÎÖ¶ûÎÖ×ÔÉíϵͳδÊÜÇÖº¦ £¬µ«Í¨¹ýMilj?data´¦ÖõÄÔ±¹¤ÐÕÃûºÍÉç»á±£ÏÕºÅÂëµÈÓ×ÎÒÐÅÏ¢ÒÑÔâй¶ ¡£ÊÂÎñ¹¦·òÏßÏÔʾ £¬Milj?dataÓÚ8ÔÂ23ÈÕ³õ´Î¼ì²âµ½ÀÕË÷Èí¼þ¹¥»÷ £¬9ÔÂ2ÈÕÈ·ÈÏÊý¾Ýй¶²¢Í¨ÖªÎÖ¶ûÎÖ¼¯ÍÅ £¬ËæºóÏòÊÜÓ°ÏìÓ×ÎÒ·¢ËÍ֪ͨÐÅ £¬²¢Ìṩ18¸öÔµÄAllstate Identity Protection Pro+Ãâ·Ñ¶©ÔÄ·þÎñ £¬Ô̺¬ÐÅÓþ¼à¿ØÖ°ÄÜ ¡£ÀÕË÷Èí¼þ×éÖ¯DataCarryÒÑÔÚÆäTorÐ¹Â©ÍøÕ¾°ä²¼±»µÁÊý¾Ý ¡£


https://securityaffairs.com/182577/data-breach/volvo-north-america-disclosed-a-data-breach-following-a-ransomware-attack-on-it-provider-miljodata.html