Ç×¶íºÚ¿ÍNoname057(16)Õë¶ÔÒâ´óÀû·¢Æð´ó¹æÄ£ÍøÂç¹¥»÷
°ä²¼¹¦·ò 2025-01-141. Ç×¶íºÚ¿ÍNoname057(16)Õë¶ÔÒâ´óÀû·¢Æð´ó¹æÄ£ÍøÂç¹¥»÷
1ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Ç×¶íºÚ¿Í×éÖ¯NoName057(16)¶ÔÒâ´óÀûÌáÒéÁËһϵÁÐÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Ö¸±êÔ̺¬¸÷²¿Î¯¡¢µ±¾Ö»ú¹¹¡¢¹Ø¼ü»ù´¡ÉèÊ©ÍøÕ¾ÒÔ¼°¸öÈË×éÖ¯£¬£¬£¬£¬£¬£¬Ç¡·êÎÚ¿ËÀ¼×ÜͳÔóÁ¬Ë¹»ù½Ó¼ûÒâ´óÀû¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯ÔÚÆäTelegramƵ·Éϰ䷢¶Ô´ËÕÆ¹Ü£¬£¬£¬£¬£¬£¬²¢Ö¸³ö¹¥»÷ÊÇÓÉÓÚÒâ´óÀû×ÜÀí÷ÂåÄáÔÚ»á¼ûÔóÁ¬Ë¹»ùʱ³ÁÉêÁ˶ÔÎÚ¿ËÀ¼µÄÈ«ÃæÖ§³Ö¡£¡£¡£¡£¡£¡£¹¥»÷´ÓÖÜÁùÆðÍ·£¬£¬£¬£¬£¬£¬Õë¶ÔÒâ´óÀû¸÷²¿Î¯ºÍµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬ÖÜÈÕÔò²¨¼°Òâ´óÀûÒøÐкÍ˽ӪÆóÒµ¡£¡£¡£¡£¡£¡£Ö»¹Ü´ËÀàºÚ¿Í»î¶¯²¢²»º±¼û£¬£¬£¬£¬£¬£¬µ«Õâ´Î¹¥»÷Ôì³ÉÁË·ÛËéºÍÁÙʱµÄ·þÎñÖжϡ£¡£¡£¡£¡£¡£¹ú¶ÈÍøÂ簲ȫ¾Ö(ACN)µÄר¼ÒѸËÙȾָ£¬£¬£¬£¬£¬£¬ÎªÊÜÓ°Ïì×éÖ¯Ìṩ֧³Ö¡£¡£¡£¡£¡£¡£×Ô2022Äê3ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Ò»Ïò»îÔ¾ÓÚÈ«Çò£¬£¬£¬£¬£¬£¬ÒÔµ±¾ÖºÍ¹Ø¼ü»ù´¡ÉèʩΪָ±ê£¬£¬£¬£¬£¬£¬Ê¹ÓöàÖÖ¹¤¾ß½øÐй¥»÷¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÔÚÊ¥µ®½Ú¼ÙÆÚÆÚ¼ä£¬£¬£¬£¬£¬£¬ÓµÓÐÕ½ÊõÒâ˼£¬£¬£¬£¬£¬£¬ÓÉÓÚ´Ëʱ×éÖ¯ÈËÔ±Ï÷¼õ£¬£¬£¬£¬£¬£¬ÏìÓ¦¹¦·ò±äÂý£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Ô½·¢ÄÑÒÔ±»·¢ÏÖ»ººÍ½â¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/172982/hacktivism/noname057-targets-italy.html
2. ΢Èí¸æ×´±í¹úºÚ¿Í×éÖ¯ÀÄÓÃAzure AI·þÎñÔì×÷Óк¦ÄÚÈÝ
1ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬Î¢Èí½üÈÕ°ä·¢¶ÔÒ»¸öÔËÓª¡°ºÚ¿Í¼´·þÎñ¡±»ù´¡ÉèÊ©µÄ±í¹úºÚ¿Í×éÖ¯Ìá¸æ×´ËÏ¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÈÆ¹ý΢ÈíÌìÉúʽAI·þÎñµÄ°²È«½ÚÔ죬£¬£¬£¬£¬£¬Ôì×÷³å·¸ÐÔºÍÓк¦ÄÚÈÝ¡£¡£¡£¡£¡£¡£¾Ý΢ÈíÊý×Ö·¸×ﲿÃÅ£¨DCU£©³Æ£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯¿ª·¢Á˸´ÔÓÈí¼þ£¬£¬£¬£¬£¬£¬×¥È¡²¢ÀûÓö³öµÄ¿Í»§Í´´¦£¬£¬£¬£¬£¬£¬ÊÔͼ·¸·¨½Ó¼ûÕ¼ÓÐAI·þÎñµÄÕË»§£¬£¬£¬£¬£¬£¬²¢Å¤×ªÕâЩ·þÎñµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬£¬ËûÃǽ«½Ó¼ûȨÏÞÏúÊÛ¸øÆäËû¶ñÒâÐÐΪÕߣ¬£¬£¬£¬£¬£¬²¢Ìṩ¾ßÌå×¢Ã÷ÈôºÎÀûÓÃÕâЩ¹¤¾ßÌìÉúÓк¦ÄÚÈÝ¡£¡£¡£¡£¡£¡£Î¢ÈíÒѳ·Ïú¹¥»÷Õß½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬Ö´ÐÐÁËеÄÓ¦¶Ô´ëÊ©£¬£¬£¬£¬£¬£¬²¢Ç¿»¯Á˰²È«´ëÊ©¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Î¢Èí»¹»ñµÃÁËÒ»Ïî·¨ÔººÅÁ£¬£¬£¬£¬£¬²é·âÁ˹ؼüÍøÕ¾¡°aitism[.]net¡±¡£¡£¡£¡£¡£¡£¾Ý·¨Í¥ÎļþÏÔʾ£¬£¬£¬£¬£¬£¬ÖÁÉÙÓÐÈýÃûδ֪Ó×ÎҲμÓÁËÕâ´ÎÐж¯£¬£¬£¬£¬£¬£¬ÀûÓñ»µÁµÄAzure APIÃÜÔ¿ºÍ¿Í»§Éí·ÝÑéÖ¤ÐÅÏ¢ÇÖÈëϵͳ£¬£¬£¬£¬£¬£¬²¢Î¥·´Ê¹ÓÃÕþ²ß´´½¨Óк¦Í¼Ïñ¡£¡£¡£¡£¡£¡£Î¢ÈíÖ¸³ö£¬£¬£¬£¬£¬£¬±»¸æÊ¹Óö¨Ôì·´Ïò´úÀí·þÎñ£¬£¬£¬£¬£¬£¬Í¨¹ýAzure OpenAI Service APIŲÓ÷¸·¨ÌìÉúÊýǧÕÅÓк¦Í¼Ïñ¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬´ËÊÂÎñ²»½öÏÞÓÚ¶Ô΢ÈíµÄ¹¥»÷£¬£¬£¬£¬£¬£¬AzureÀÄÓÃÆóÒµÒ»ÏòÔÚÕë¶ÔÆäËûAI·þÎñÌṩÉ̲¢Ôâ·êÆäº¦¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2025/01/microsoft-sues-hacking-group-exploiting.html
3. Teton OrthopaedicsÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬»¼ÕßÓëÔ±¹¤Êý¾Ýй¶
1ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬2024Äê3ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬DataBreachesÍøÕ¾ÔÚÔ¶ȹ¤×÷±íÉϼͼÁËTeton OrthopaedicsÔâ·êÀÕË÷Èí¼þ¹¥»÷µÄÊÂÎñ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓÉÃûΪDragonForceµÄ×éÖ¯Ðû³ÆÕƹܣ¬£¬£¬£¬£¬£¬ËûÃÇÐû³ÆÒÑÇÔÈ¡²¢¼ÓÃÜÁ˸ÃÌṩÉ̵ÄÎļþ¡£¡£¡£¡£¡£¡£Ö»¹ÜDataBreachesͨ¹ýGoogleËÑË÷ÑéÖ¤Á˲¿ÃÅй¶µÄ²¡È˼ͼ£¬£¬£¬£¬£¬£¬µ«Ö±µ½2024Äê12Ô£¬£¬£¬£¬£¬£¬Teton Orthopaedics²Å֪ͨÊÜÓ°ÏìµÄ»¼ÕߺÍÖݾÓÃñ¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ÔÚ·¢ÏÖ·ì϶ºóµÄ60ÌìÄÚ£¬£¬£¬£¬£¬£¬ËûÃDz¢Î´ÏòÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©·¢³ö֪ͨ£¬£¬£¬£¬£¬£¬Ö»¹ÜÍøÕ¾Í¨ÖªÈÏ¿ÉËûÃÇÔÚ3ÔÂ25ÈÕ·¢ÏÖÁË·ì϶¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Teton OrthopaedicsÓëDragonForceÖ®¼äµÄ½»ÉæËƺõҲδµÃµ½³É¹¦¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñ²»½öÓ°ÏìÁË»¼ÕßÊý¾Ý£¬£¬£¬£¬£¬£¬»¹Ó°ÏìÁËÔ±¹¤Êý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢½¡È«±£ÏÕÐÅÏ¢ºÍÒ½ÁÆÐÅÏ¢µÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£Teton OrthopaedicsÒѲÉÈ¡´ëÊ©¼ÓÇ¿°²È«ÐÔ£¬£¬£¬£¬£¬£¬µ«²¢Î´Îª»¼ÕßÌṩÃâ·ÑµÄ·þÎñ£¬£¬£¬£¬£¬£¬ÈçÐÅÓþ¼à¿Ø»òÉí·Ý͵ÇÔ¸´Ô·þÎñ¡£¡£¡£¡£¡£¡£
https://databreaches.net/2025/01/12/nine-months-after-discovering-a-ransomware-attack-teton-orthopaedics-notifies-patients/
4. Gravy AnalyticsÊý¾Ýй¶£ºÈ«ÇòÊý°ÙÍòÓû§ÒþÖÔÊÜÍþв
1ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬µØÎ»Êý¾Ý¾¼Í¹«Ë¾Gravy Analytics½üÆÚÔâ·êÁËÑϳÁµÄºÚ¿Í¹¥»÷ºÍÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬µ¼ÖÂÈ«ÇòÊý°ÙÍòÈ˵ÄÒþÖÔÊܵ½Íþв¡£¡£¡£¡£¡£¡£ºÚ¿Í´ÓÒ»¸ö·â¹ØµÄ¶íÓïÍøÂç·¸×ïÂÛ̳Éϰ䲼ÁË´óÁ¿µØÎ»Êý¾ÝÑù±¾£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ýº¸ÇÁ˽¡Éí¡¢½¡È«¡¢Ô¼»á¡¢½»Í¨ÀûÓÃÒÔ¼°ÈȵãÓÎÏ·µÈ¶à¸öÁìÓò£¬£¬£¬£¬£¬£¬´ú±íÁËÊýǧÍò¸öÓ×ÎÒµØÎ»Êý¾Ýµã¡£¡£¡£¡£¡£¡£¾ÝŲÍþ¹ã²¥¹«Ë¾NRK±¨Â·£¬£¬£¬£¬£¬£¬Gravy AnalyticsµÄĸ¹«Ë¾UnacastÒÑÏòŲÍþÊý¾Ý±£»£»£»£»£»£»£»£»¤»ú¹¹Åû¶ÁËÕâһΥ¹æÐÐΪ¡£¡£¡£¡£¡£¡£Unacast°µÊ¾£¬£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ýµÁÓÃÃÜÔ¿´ÓÆäÑÇÂíÑ·ÔÆ»·¾³ÖÐÇÔÈ¡ÁËÊýTBµÄÏû·ÑÕßÊý¾Ý¡£¡£¡£¡£¡£¡£½ØÖÁ±¨Â·Ê±£¬£¬£¬£¬£¬£¬Gravy AnalyticsµÄÍøÕ¾ÈÔ´¦ÓÚ̱»¾×´Ì¬¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Õâ´Îй¶µÄÊý¾ÝµãÒѳ¬¹ý3000Íò£¬£¬£¬£¬£¬£¬Ô̺¬Î»ÓÚÃô¸ÐµØÖ·µÄÉ豸ÐÅÏ¢£¬£¬£¬£¬£¬£¬Èç°×¹¬¡¢¿ËÀïÄ·ÁÖ¹¬ºÍÈ«Çò¾üÊ»ùµØ¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý²»½ö¿ÉÄܶ³öͨ³£È˵ÄÐÐ×Ù£¬£¬£¬£¬£¬£¬»¹¿ÉÄܶÔLGBTQ+Óû§×é³É·çÏÕ¡£¡£¡£¡£¡£¡£°²È«×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý»¹Äܹ»ÇáËÉÈÃͨ³£Ó×ÎÒµÄÉí·Ý±»È¥ÄäÃû»¯¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ÃÀ¹úÁª¹úÒµÎñίԱ»á´ËǰÒѲ»ÈÝGravy Analytics¼°Æä×Ó¹«Ë¾Î´¾Ïû·ÑÕßÔÞ³ÉÍøÂçºÍÏúÊÛµØÎ»Êý¾Ý¡£¡£¡£¡£¡£¡£Gravy AnalyticsµÄµØÎ»Êý¾ÝÖØÒªÆðÔ´ÓÚÔÚÏ߸æ°×ÐÐÒµµÄʵʱ¾º¼Û¹ý³Ì£¬£¬£¬£¬£¬£¬µ«ÕâÒ»¹ý³ÌÖдæÔÚÊý¾Ýй¶µÄ·çÏÕ¡£¡£¡£¡£¡£¡£
https://techcrunch.com/2025/01/13/gravy-analytics-data-broker-breach-trove-of-location-data-threatens-privacy-millions/
5. Ó¢¹úÓòÃû¾ÞÍ·NominetÔâIvanti VPN·ì϶ºÚ¿Í¹¥»÷
1ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬Ó¢¹úÓòÃû×¢²á»ú¹¹Nominet½üÆÚÔâ·êÁËÒ»´ÎÍøÂ簲ȫÊÂÎñ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓëºÚ¿ÍÀûÓÃIvanti VPNÈí¼þµÄзì϶Óйء£¡£¡£¡£¡£¡£NominetÕÆ¹ÜÊØ»¤.co.ukÓòÃû£¬£¬£¬£¬£¬£¬ÆäÔÚ·¢¸ø¿Í»§µÄµç×ÓÓʼþÖÐÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬ÔÚµ÷²éһ·¡°ÔÚ²úÉúµÄ°²È«ÊÂÎñ¡±¡£¡£¡£¡£¡£¡£¾ÝNominetй©£¬£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ýIvantiÌṩµÄµÚÈý·½VPNÈí¼þ½Ó¼ûÁËÆäϵͳ£¬£¬£¬£¬£¬£¬ÇÒÕâ´ÎÈëÇÖÀûÓÃÁËÁãÈÕ·ì϶£¬£¬£¬£¬£¬£¬ÒÔÖÁNominetÎÞ·¨ÊµÊ±´ò²¹¶¡½øÐзÀÓù¡£¡£¡£¡£¡£¡£IvantiÉÏÖÜÒÑ֤ʵÆä¿í·ºÊ¹ÓÃµÄÆóÒµVPNÉ豸Connect Secure´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬²¢Ôâµ½ºÚ¿ÍÀûÓýøÐÐÈëÇÖ¡£¡£¡£¡£¡£¡£Ö»¹ÜIvantiδй©¾ßÌåÊÜÓ°Ïì¿Í»§ÊýÁ¿£¬£¬£¬£¬£¬£¬µ«ÍøÂ簲ȫ¹«Ë¾watchTowr LabsÒÑ·¢ÏÖ¡°¿í·º¡±µÄÈëÇÖÐÐΪ¡£¡£¡£¡£¡£¡£Nominet×÷ΪÊ×¼Ò¹«¿ªÈ·ÈÏÊÜIvanti·ì϶ӰÏìµÄ×éÖ¯£¬£¬£¬£¬£¬£¬°µÊ¾Ä¿Ç°¡°Ã»º±¼û¾Ýй¶»òй©µÄÖ¤¾Ý¡±£¬£¬£¬£¬£¬£¬²¢ÔÚµ÷²éÆÚ¼äÏÞ¶ÈÁ˶ÔVPNÈí¼þµÄ½Ó¼û¡£¡£¡£¡£¡£¡£
https://techcrunch.com/2025/01/13/uk-domain-giant-nominet-confirms-cybersecurity-incident-linked-to-ivanti-vpn-hacks/
6. CISA¸üÐÂÒÑÖª±»ÀûÓ÷ì϶Ŀ¼£¬£¬£¬£¬£¬£¬ÒªÇó»ú¹¹ÊµÊ±½¨¸´
1ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÆÚ¸üÐÂÁËÆäÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼£¬£¬£¬£¬£¬£¬ÐÂÔöÁËÁ½¸ö³ÁÒª·ì϶¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2024-12686ÊÇÒ»¸ö´æÔÚÓÚBeyondTrustÌØÈ¨Ô¶³Ì½Ó¼û£¨PRA£©ºÍÔ¶³ÌÖ§³Ö£¨RS£©ÖеIJÙ×÷ϵͳºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.6¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐíÓµÓÐÖÎÀíȨÏ޵Ĺ¥»÷ÕßÉÏ´«¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬²¢ÔÚÕ¾µãÓû§¸ßµÍÎÄÖÐÖ´Ðеײã²Ù×÷ϵͳºÅÁî¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬BeyondTrust¹«Ë¾ÔøÔÚ2024Äê12Ô³õÔâ·êÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬²¿ÃÅÔ¶³ÌÖ§³ÖSaaSÊ·ý±»ÈëÇÖ£¬£¬£¬£¬£¬£¬¶øCVE-2024-12686ÕýÊÇÕâ´Î¹¥»÷Öз¢Ïֵķì϶֮һ¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö·ì϶ÊÇCVE-2023-48365£¬£¬£¬£¬£¬£¬ËüÊÇQlik SenseÖеÄHTTPËí··ì϶£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.6£¬£¬£¬£¬£¬£¬¿Éʹ¹¥»÷ÕßÌáÉýȨÏÞ²¢Ïòºó¶Ë·þÎñÆ÷·¢ËÍHTTPÒªÇ󡣡£¡£¡£¡£¡£Æ¾¾ÝCISA°ä²¼µÄÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Á£¬£¬£¬£¬£¬Áª¹ú»ú¹¹±ØÐëÔÚ2025Äê2ÔÂ3ÈÕ֮ǰ½â¾öÕâЩÒÑ·¢Ïֵķì϶£¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»£»£»¤ÆäÍøÂçÃâÊܹ¥»÷¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²éCISAµÄKEVĿ¼£¬£¬£¬£¬£¬£¬²¢ÊµÊ±½â¾öÆä»ù´¡ÉèÊ©ÖдæÔڵķì϶¡£¡£¡£¡£¡£¡£ÕâЩ´ëÊ©¶ÔÓÚÌá¸ßÍøÂ簲ȫ·À»¤ÄÜÁ¦ÓµÓгÁÒªÒâ˼¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/173031/security/u-s-cisa-adds-beyondtrust-pra-and-rs-and-qlik-sense-flaws-to-its-known-exploited-vulnerabilities-catalog.html


¾©¹«Íø°²±¸11010802024551ºÅ