Mount RogersÐÄÀí¿µ½¡»ú¹¹ÔâINC RansomÀÕË÷ÍŻ﹥»÷
Ðû²¼Ê±¼ä 2025-06-131. Mount RogersÐÄÀí¿µ½¡»ú¹¹ÔâINC RansomÀÕË÷ÍŻ﹥»÷
6ÔÂ11ÈÕ£¬£¬£¬Mount RogersÉçÇøÐ§ÀÍ»ú¹¹£¨Ò»¼ÒÐÄÀí¿µ½¡Ð§ÀÍÌṩÉÌ£©¿ËÈÕ·ºÆðÔÚÀÕË÷ÍÅ»ïINC RansomµÄ°µÍøÐ¹ÃÜÍøÕ¾ÉÏ£¬£¬£¬¹¥»÷ÕßÐû³ÆÒÑ´ÓÆäϵͳÖÐÇÔÈ¡´ó×ÚÒþ˽Êý¾Ý¡£¡£¡£¡£Mount RogersÖ÷ÒªÌṩÐÄÀí¿µ½¡¡¢·¢ÓýÕϰ¼°Ò©ÎïÀÄÓÃÖÎÁÆÐ§ÀÍ¡£¡£¡£¡£ÎªÖ¤Êµ¹¥»÷µÄÓÐÓÃÐÔ£¬£¬£¬INC Ransom¹ûÕæÁ˲¿·ÖÑù±¾Êý¾Ý£¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢×¡Ö·¡¢Ð½×ʵ¥¡¢·¢Æ±Æ±¾Ý¡¢Ð¡ÎÒ˽¼ÒÓÊÏä¡¢ÄÚ²¿Í¨Ñ¶¼°±£ÃÜÐÒéµÈ¡£¡£¡£¡£Ö»¹ÜÕâЩÊý¾ÝµÄÃô¸ÐÐÔÓÐÏÞ£¬£¬£¬µ«¹¥»÷ÕßÈÔ¿ÉʹÓÃÆä¾ÙÐÐÍøÂç´¹ÂÚ»òÉí·Ý͵ÇÔ£¬£¬£¬Ð½×ʵ¥ºÍÄÚ²¿Îļþ¸ü¿ÉÄܱ»ÓÃÓÚÉç»á¹¤³Ì¹¥»÷£¬£¬£¬½øÒ»²½ÉøÍ¸Æóҵϵͳ¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶»ò½«ÑÏÖØËðº¦Mount RogersµÄÉùÓþ£¬£¬£¬²¢Òý·¢Ö´·¨Î£º¦¡£¡£¡£¡£INC Ransom×÷ΪĿ½ñ×î»îÔ¾µÄÀÕË÷×éÖ¯Ö®Ò»£¬£¬£¬×Ô2023Äê7ÔÂÊ×´ÎÏÖÉíÒÔÀ´£¬£¬£¬¹¥»÷Ä¿µÄÒ»Á¬Éý¼¶£¬£¬£¬Êܺ¦Õߺ¸Ç¶à¸öÁìÓò¡£¡£¡£¡£¾Ý°µÍø¼à²â¹¤¾ßͳ¼Æ£¬£¬£¬ÒÑÍù12¸öÔÂÄÚ£¬£¬£¬¸Ã×éÖ¯ÒÑÀۼƹ¥»÷163¼Ò»ú¹¹¡£¡£¡£¡£
https://cybernews.com/security/mount-rogers-ransomware-attack/
2. GonnaOrderƽ̨ÒòÉèÖùýʧµ¼ÖÂÊý¾Ýй¶
6ÔÂ11ÈÕ£¬£¬£¬×ܲ¿Î»ÓÚÅ·ÖÞµÄʳÎïÅäËÍÆ½Ì¨GonnaOrderÒòKafka BrokerʵÀýÉèÖùýʧ£¬£¬£¬µ¼ÖÂÊýǧÈËСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£Ñо¿ÍŶӷ¢Ã÷£¬£¬£¬¸Ãƽ̨һ¸ö²»Êܱ£»£»£»£»£»£»£»¤µÄʵÀý½«ÊµÊ±¶©µ¥ÐÅϢ̻¶¸ø¹«ÖÚ£¬£¬£¬°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢¼Òͥסַ¼°¶©µ¥ÏêϸÐÅÏ¢µÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬£¬Áè¼ÝÁ½Ç§Ãû×ÔÁ¦¿Í»§µÄÏêϸÐÅÏ¢Ôڶ̶ÌһСʱÄھͱ»Ð¹Â¶£¬£¬£¬¶ø¸üÁîÈ˵£ÐĵÄÊÇ£¬£¬£¬¸ÃʵÀý×Ô2022Äê8ÔÂÆð¿ÉÄܾÍÒ»Ö±´¦ÓÚ¿ª·Å״̬£¬£¬£¬ÕâÒâζ×ŶñÒâÐÐΪÕß¿ÉÄÜÒÑ»ñÈ¡Êý°ÙÍò¿Í»§µÄÊý¾Ý¡£¡£¡£¡£´Ë´Îй¶ӰÏìÁËÅ·ÖÞ¶à¸ö¹ú¼ÒµÄ²Í¹Ý¡¢¾Æ°É¡¢ÂùݺÍСÊÐËÁµÄÖ÷¹Ë£¬£¬£¬Ö÷ҪλÓÚÓ¢¹ú¡¢±ÈÀûʱ¡¢Ï£À°¡¢µÂ¹úºÍºÉÀ¼µÈµØ¡£¡£¡£¡£Ö»¹ÜKafkaƽּ̨ÔÚÔö½øÊý¾Ý´«Êä¶ø·Çºã¾Ã´æ´¢£¬£¬£¬µ«¹¥»÷ÕßÈÔ¿Éͨ¹ýÉèÖá°ÍøÂçÆ÷¡±ºã¾Ãץȡй¶Êý¾Ý¡£¡£¡£¡£Ñо¿ÍŶÓÇ¿µ÷£¬£¬£¬Ð¹Â¶µÄÊý¾Ý°üÀ¨¿Í»§¶©µ¥¡¢²ÍÌüºÍÂùݶ©µ¥¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¼Òͥסַ¡¢½»»õµ¥¼°Ê¹Óõĸ¶¿î·½·¨µÈ£¬£¬£¬ÕâЩÐÅÏ¢¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ»òÔÚ°µÍøÉϳöÊÛ£¬£¬£¬¸øÊܺ¦Õß´øÀ´ÑÏÖØÎ£º¦¡£¡£¡£¡£ÔÚÑо¿Ö°Ô±¶à´ÎʵÑéÁªÏµºó£¬£¬£¬GonnaOrder×îÖÕÓÚ2025Äê5ÔÂÏÂÑ®¹Ø±ÕÁ˸ÃʵÀý¡£¡£¡£¡£
https://cybernews.com/security/gonnaorder-food-delivery-data-leak/
3. 4ÍòÁªÍøÉãÏñͷ̻¶£¬£¬£¬Óû§Òþ˽ÊÜÍþв
6ÔÂ11ÈÕ£¬£¬£¬Ç徲ר¼Ò¿ËÈÕ·¢³öÖÒÑÔ£¬£¬£¬±¾Ó¦°ü¹ÜÓû§Çå¾²µÄÇå¾²ÉãÏñÍ·È´ÒòÉèÖò»µ±£¬£¬£¬½«Óû§ÖÃÓÚΣÏÕÌïµØ¡£¡£¡£¡£¾ÝÃÀ¹úÍøÂçÇå¾²ÆÀ¼¶¹«Ë¾BitSightµÄ±¨¸æÏÔʾ£¬£¬£¬ÏÖÔÚÒÑÓÐ4Íò¸öÁªÍøÉãÏñͷ̻¶ÓÚÍøÂ磬£¬£¬ÆäÖÐÃÀ¹ú¾ÍÕ¼ÓÐÁË1.4Íò¸ö¡£¡£¡£¡£ÕâЩÉãÏñÍ·ÎÞÐèÃÜÂë»òÆäËû±£»£»£»£»£»£»£»¤²½·¥¼´¿ÉÔÚÏßÖ±²¥£¬£¬£¬ÈκÎÈËÖ»ÐèÕÆÎÕ׼ȷµÄIPµØµãºÍä¯ÀÀÆ÷£¬£¬£¬¾ÍÄÜÇáËɼàÊÓ¼ÒÍ¥»ò´óÐ͹«Ë¾¡£¡£¡£¡£ÓÉÓÚÎïÁªÍøËÑË÷ÒýÇæ»áÒ»Á¬Ì½²â»¥ÁªÍø²¢±ê¼ÇËùÓÐ̻¶µÄЧÀÍ£¬£¬£¬²éÕÒÕâЩÉãÏñÍ·µÄIPµØµã±äµÃÒì³£ÈÝÒס£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ÕâЩԱ¾ÓÃÓÚÇå¾²»òÀû±ãµÄÉãÏñÍ·£¬£¬£¬È´ÎÞÒâÖгÉΪÁËÃô¸Ð¿Õ¼äµÄ¹«¹²´°¿Ú£¬£¬£¬ÇÒÍùÍùÊÇÔÚÖ÷È˲»ÖªÇéµÄÇéÐÎÏ¡£¡£¡£¡£´ÓµØÇøÂþÑÜÀ´¿´£¬£¬£¬ÃÀ¹ú̻¶µÄÉãÏñÍ·ÊýÄ¿×î¶à£¬£¬£¬Æä´ÎÊÇÈÕ±¾¡¢°ÂµØÀû¡¢½Ý¿ËºÍº«¹ú¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬ËäÈ»²¢·ÇËùÓÐÍøÂçÉãÏñÍ·¶¼±£´æÎÊÌ⣬£¬£¬µ«Ì»Â¶µÄÉãÏñÍ·Öв»·¦¼à¿ØºâÓîÈë¿Ú¡¢Êý¾ÝÖÐÐÄ»ú·¿¡¢×Ô¶¯È¡¿î»ú¡¢Ò½Ôº²¡ÈËÒÔ¼°¹«¹²½»Í¨Âÿ͵ÄÃô¸Ð×°±¸¡£¡£¡£¡£¸üÁîÈ˵£ÐĵÄÊÇ£¬£¬£¬×ÝȻijЩÉãÏñ»úÐèÒªÃÜÂë²Å»ª»á¼ûÖÎÀíÃæ°å£¬£¬£¬ÆäAPIÒ²¿ÉÄܹûÕæÌ»Â¶ÊÓÆµÁ÷£¬£¬£¬Ê¹µÃÍøÂç·¸·¨·Ö×ÓÄܹ»Í¨¹ýÖÆ×÷ÌØ¶¨URLÀ´»á¼û¡£¡£¡£¡£ÔÚ°µÍøÂÛ̳ÉÏ£¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÉõÖÁ¹ûÕæÌÖÂÛ²éÕÒºÍÀÄÓôËÀàÉãÏñÍ·µÄ¹¤¾ßºÍ×ö·¨£¬£¬£¬²¢³öÊÛ»á¼ûȨÏÞ¡£¡£¡£¡£
https://cybernews.com/security/researchers-find-thousands-exposed-security-cameras/
4. CloudflareÓëGoogle CloudÔâÓö´ó¹æÄ£Ð§ÀÍÖÐÖ¹
6ÔÂ12ÈÕ£¬£¬£¬ÃÀ¹ú¶«²¿Ê±¼ä6ÔÂ12ÈÕ£¬£¬£¬CloudflareºÍGoogle CloudÔâÓö´ó¹æÄ£Ð§ÀÍÖÐÖ¹ÎÊÌ⣬£¬£¬Ó°Ïì¶à¸öµØÇøÍøÕ¾¼°ÖÖÖÖЧÀ͵Ļá¼û¡£¡£¡£¡£CloudflareÔÚ²»µ½30·ÖÖÓǰÊ×´ÎÈÏ¿ÉÎÊÌ⣬£¬£¬±¨¸æÁË»á¼ûÉí·ÝÑé֤ʧ°ÜºÍCloudflare Zero Trust WARPÅþÁ¬ÎÊÌ⣬£¬£¬²¢ÌåÏÖÐí¶àЧÀÍ·ºÆð¼äЪÐÔ¹ÊÕÏ£¬£¬£¬ÕýÔÚ¼ÌÐøÊӲ졣¡£¡£¡£ÆäÊÜÓ°ÏìµÄЧÀͰüÀ¨Ê¹ÓÃȨ¡¢³¤ÆÚ¹¤¾ß¡¢¹¤ÈËKV¡¢¼´Ê±¡¢¹¤ÈËÈ˹¤ÖÇÄÜ¡¢ÏªÁ÷¡¢ºòÕïÊÒ¡¢CloudflareÒDZí°åµÄ×é³É²¿·Ö¡¢È˹¤ÖÇÄÜÍø¹Ø¡¢×Ô¶¯RAGµÈ¡£¡£¡£¡£Cloudflare½²»°È˳ƣ¬£¬£¬ÕâÊÇÒ»´ÎGoogle CloudÖÐÖ¹£¬£¬£¬CloudflareÉÙÊýʹÓÃGoogle CloudµÄЧÀÍÊܵ½Ó°Ï죬£¬£¬µ«½¹µãЧÀÍδÊܲ¨¼°¡£¡£¡£¡£Ëæºó£¬£¬£¬CloudflareÌåÏÖЧÀÍÕýÔÚÈ«Çò¹æÄ£ÄÚ¿ìËÙ»Ö¸´£¬£¬£¬WARPºÍTurnstileÒѻָ´ÔËÐУ¬£¬£¬µ«ÈÔ±£´æÉÙÁ¿Ê£ÓàÓ°Ï죬£¬£¬½¹µãKVЧÀÍÒѻָ´£¬£¬£¬Ïà¹Ø²úÆ·Òѻָ´ÉÏÏߣ¬£¬£¬Ô¤¼Æ½ÓÏÂÀ´¼¸·ÖÖÓÄÚ½«½øÒ»²½»Ö¸´¡£¡£¡£¡£¹È¸è·½Ã棬£¬£¬×Ô̫ƽÑóÏÄÁîʱ¼ä6ÔÂ12ÈÕ10:51Æð£¬£¬£¬¶à¿îGCP²úÆ··ºÆðЧÀÍÎÊÌ⣬£¬£¬°üÀ¨Bigtable¡¢Console¡¢DataprocµÈ¡£¡£¡£¡£¹È¸èÔÚ15:20 EDT¸üÐÂÌåÏÖ£¬£¬£¬¶à¸öWorkspaceºÍËÑË÷ЧÀÍÒ²Êܴ˴δó¹æÄ£ÖÐÖ¹Ó°Ï죬£¬£¬Éæ¼°Gmail¡¢GoogleÈÕÀú¡¢Google ChatµÈ¡£¡£¡£¡£±ðµÄ£¬£¬£¬Google Lens¡¢DiscoverºÍÓïÒôËÑË÷Ч¹ûµÄÌṩҲ±£´æÒ»Á¬ÎÊÌâ¡£¡£¡£¡£¹È¸è³ÆÒÑÕÒµ½»ù´¡Ôµ¹ÊÔÓÉ£¬£¬£¬½ÓÄÉ»º½â²½·¥ºó£¬£¬£¬Æä»ù´¡ÉèÊ©ÔÚ³ýus-central1Ö®ÍâµÄËùÓеØÇø¶¼Òѻָ´£¬£¬£¬ÒÀÀµÊÜÓ°Ïì»ù´¡ÉèÊ©µÄ¹È¸èÔÆ²úÆ·ÕýÔÚ¶à¸öµØ·½»Ö¸´£¬£¬£¬Ô¤¼Æ¡°»Ö¸´½«ÔÚ²»µ½Ò»Ð¡Ê±ÄÚÍê³É¡±¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/technology/google-cloud-and-cloudflare-hit-by-widespread-service-outages/
5. AsefaÔâ¡°÷è÷롱ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬210GBÊý¾Ýй¶
6ÔÂ12ÈÕ£¬£¬£¬¡°÷è÷롱ÀÕË÷Èí¼þÍŻォ·¨¹ú´óÐͰü¹Ü¼¯ÍÅSMABPTµÄÎ÷°àÑÀ×Ó¹«Ë¾AsefaÌí¼Óµ½Æä°µÍøÐ¹ÃÜÍøÕ¾£¬£¬£¬Éù³ÆÇÔÈ¡ÁË210GBÊý¾Ý¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬AsefaÈÏ¿ÉÕýÃæÁÙÍøÂç¹¥»÷£¬£¬£¬ÆäÍøÕ¾×Ô6Ô³õ¾ÍÏÔʾÓйØÈëÇÖµÄ֪ͨ£¬£¬£¬²¢ÔÚÐÅÖÐлл¿Í»§ÔÚ¼èÄÑʱÆÚµÄÄÍÐÄ¡¢Ã÷È·ºÍÐÅÈΡ£¡£¡£¡£AsefaÌåÏÖ£¬£¬£¬¹«Ë¾¡°½¹µãÓªÒµ¡±Î´ÊÜÓ°Ï죬£¬£¬ÈÔÔÚÕý³£ÔËÓª£¬£¬£¬Ô±¹¤»á¼û¹«Ë¾µç×ÓÓʼþµÄȨÏÞÒ²Òѻָ´£¬£¬£¬µ«ÍøÕ¾½«ÔÝʱ¹Ø±Õ£¬£¬£¬Ö±ÖÁÈ·±£ËùÓй¤¾ßºÍ¹¦Ð§ÍêÈ«Çå¾²ÇÒ¿ÉÕý³£ÔËÐС£¡£¡£¡£Ñо¿ÍŶÓÊӲ췢Ã÷£¬£¬£¬±»µÁÊý¾Ý°üÀ¨¹«Ë¾ÄÚ²¿Îļþ¡¢»¤ÕÕ¡¢ÊÕÌõºÍÖ´·¨ÐÒéµÈ£¬£¬£¬ÆäÖÐÒ»·ÝÉæ¼°°ÍÈûÂÞÄÇ×ãÇò¾ãÀÖ²¿Åµ¿²ÆÕÇò³¡ÖØÐ޵İü¹ÜÍýÏëÓÈΪÒýÈËעĿ¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬Ð¹Â¶µÄÃô¸ÐÎļþÈ绤ÕÕºÍÄÚ²¿ÐÒ飬£¬£¬»á´øÀ´ÑÏÖØµÄÉí·Ý͵ÇÔ»òÚ²ÆÎ£º¦£¬£¬£¬ÉõÖÁ¿ÉÄܵ¼ÖÂÉÌÒµÌØ¹¤»î¶¯£¬£¬£¬¶ø°ÍÈûÂÞÄÇ×ãÇò¾ãÀÖ²¿µÄ°ü¹ÜÍýÏëй¶£¬£¬£¬¿ÉÄÜ»á̻¶¸ß×ÅÃû¶È¿Í»§µÄ²ÆÎñ»òÔËÓªÎó²î¡£¡£¡£¡£´Ë´Î¹¥»÷µÄÄ»ºóºÚÊÖ¡°÷è÷롱ÀÕË÷Èí¼þÓ°ÏìÁ¦½ñÄêÎȲ½ÔöÌí£¬£¬£¬½ö4Ô·ݾÍÕë¶ÔÁË68¸öʵÌå¡£¡£¡£¡£
https://cybernews.com/security/asefa-spanish-insurer-qilin-ransomware/
6. ³¬8Íò¸öEntra IDÕÊ»§ÔâTeamFiltration¹¤¾ß¹¥»÷
6ÔÂ12ÈÕ£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÏîÃûΪUNK_SneakyStrikeµÄÐÂÕÊ»§½ÓÊÜ£¨ATO£©»î¶¯£¬£¬£¬¸Ã»î¶¯Ê¹ÓÿªÔ´ÉøÍ¸²âÊÔ¿ò¼ÜTeamFiltrationÈëÇÖMicrosoft Entra ID£¨ÔAzure Active Directory£©Óû§ÕÊ»§¡£¡£¡£¡£×Ô2024Äê12Ô·¢Ã÷µÇ¼ʵÑé´ÎÊý¼¤ÔöÒÔÀ´£¬£¬£¬´Ë»î¶¯ÒѲ¨¼°Êý°Ù¼Ò×éÖ¯µÄ80,000¶à¸öÄ¿µÄÓû§ÕÊ»§£¬£¬£¬²¢Àֳɵ¼Ö²¿·ÖÕÊ»§±»½ÓÊÜ¡£¡£¡£¡£ProofpointÖ¸³ö£¬£¬£¬¹¥»÷Õß½èÖú²î±ðµØÀíÇøÓòµÄMicrosoft Teams APIºÍÑÇÂíÑ·ÍøÂçЧÀÍ£¨AWS£©Ð§ÀÍÆ÷£¬£¬£¬ÌᳫÓû§Ã¶¾ÙºÍÃÜÂëÅçÈ÷¹¥»÷£¬£¬£¬Ê¹ÓöÔMicrosoft Teams¡¢OneDrive¡¢OutlookµÈÌØ¶¨×ÊÔ´ºÍ±¾»úÓ¦ÓóÌÐòµÄ»á¼ûȨÏÞʵÑé¹¥»÷¡£¡£¡£¡£TeamFiltrationÓÉÑо¿Ô±Melvin¡°Flangvik¡±LangvikÓÚ2022Äê8ÔÂÔÚDEF CONÇå¾²¾Û»áÉÏÐû²¼£¬£¬£¬ÊÇÒ»¸ö¿çƽ̨¿ò¼Ü£¬£¬£¬¿ÉÓÃÓÚ¡°Ã¶¾Ù¡¢ÅçÈ÷¡¢Ð¹Â¶ºÍºóÃÅ¡±Entra IDÕÊ»§£¬£¬£¬Í¨¹ý½«¶ñÒâÎļþÉÏ´«µ½Ä¿µÄMicrosoft OneDriveÕÊ»§£¬£¬£¬Ê¹ÓÃÃÜÂëÅçÈ÷¹¥»÷¡¢Êý¾Ýй¶ºÍÒ»Á¬»á¼ûÀ´Ôö½øÕÊ»§½ÓÊÜ¡£¡£¡£¡£Ö»¹ÜʹÓøù¤¾ßÐèÒªAmazon Web Services£¨AWS£©ÕÊ»§ºÍÒ»´ÎÐÔMicrosoft 365ÕÊ»§£¬£¬£¬µ«ProofpointÊӲ쵽¶ñÒâ»î¶¯Ê¹ÓÃTeamFiltration¾ÙÐÐÕâЩ²Ù×÷µÄÖ¤¾Ý£¬£¬£¬ÇÒÿ´ÎÃÜÂëÅçÈ÷À˳±¶¼Ô´×ÔеØÀíλÖõIJî±ðЧÀÍÆ÷¡£¡£¡£¡£Óë¶ñÒâ»î¶¯Ïà¹ØµÄÈý¸öÖ÷ҪȪԴµØÇøÎªÃÀ¹ú£¨42%£©¡¢°®¶ûÀ¼£¨11%£©ºÍÓ¢¹ú£¨8%£©¡£¡£¡£¡£
https://thehackernews.com/2025/06/over-80000-microsoft-entra-id-accounts.htm