Ò½ÁƼ¯ÍÅHSGIÊý¾Ýй¶ӰÏ쳬60ÍòÈË

Ðû²¼Ê±¼ä 2025-08-29

1. Ò½ÁƼ¯ÍÅHSGIÊý¾Ýй¶ӰÏ쳬60ÍòÈË


8ÔÂ27ÈÕ £¬£¬£¬£¬Ò½ÁƱ£½¡Ð§Àͼ¯ÍÅ£¨HSGI£©¿ËÈÕÅû¶һÆðÖØ´óÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬Ó°ÏìÁè¼Ý60ÍòÃû¸öÌå¡£¡£¡£¡£¡£Õâ¼Ò×ܲ¿Î»ÓÚ±öϦ·¨ÄáÑÇÖݵÄÉÏÊй«Ë¾×¨ÎªÈ«ÃÀÒ½ÁÆ»ú¹¹Ìṩ֧³ÖЧÀÍ £¬£¬£¬£¬ÄêÊÕÈë´ï17ÒÚÃÀÔª £¬£¬£¬£¬ÆäϵͳÇå¾²¶ÔÊýǧ¼ÒÒ½ÁÆ»ú¹¹µÄÔË×÷ÖÁ¹ØÖ÷Òª¡£¡£¡£¡£¡£ÊÂÎñʱ¼äÏßÏÔʾ £¬£¬£¬£¬HSGIÓÚ2024Äê10ÔÂ7ÈÕ¼ì²âµ½ÍøÂçÔâÊÜδÊÚȨ»á¼û £¬£¬£¬£¬ËæºóÈ·ÈÏÈëÇÖʼÓÚ9ÔÂ27ÈÕ £¬£¬£¬£¬²¢ÓÚ10ÔÂ3ÈÕ¿¢Ê¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ £¬£¬£¬£¬¹¥»÷ÕßÔÚ´Ëʱ´ú»á¼û²¢¸´ÖÆÁËϵͳÄڵIJ¿·ÖÎļþ¡£¡£¡£¡£¡£Ö»¹ÜÎó²î±¬·¢ÔÚ2024Äê9ÔÂÄ© £¬£¬£¬£¬µ«ÊÜÓ°Ïì¸öÌåÖ±ÖÁ2025Äê8ÔÂ25ÈÕ²ÅÊÕµ½Í¨Öª £¬£¬£¬£¬Õû¸öÊÓ²ìÀú³ÌºÄʱ½ü10¸öÔ¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÀàÐÍÒò¸öÌå¶øÒì £¬£¬£¬£¬¿ÉÄܰüÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢ÖÝʶ±ðÂë¡¢²ÆÎñÕË»§ÐÅÏ¢¼°ÕË»§»á¼ûƾ֤µÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£¡£HSGIÔÚͨ¸æÖÐÇ¿µ÷ £¬£¬£¬£¬ÏÖÔÚÉÐÎÞÖ¤¾ÝÅú×¢±»µÁÐÅÏ¢Òѱ»ÀÄÓà £¬£¬£¬£¬µ«ÈÔ½¨ÒéÊÜÓ°ÏìÕßСÐÄÍøÂç´¹ÂÚ¡¢Õ©Æ­ÐÐΪ £¬£¬£¬£¬²¢Ç×½ü¼à¿ØÒøÐÐÕË»§Òì³£»£»£»£»£»£»£»î¶¯¡£¡£¡£¡£¡£×÷ΪӦ¶Ô²½·¥ £¬£¬£¬£¬HSGIΪÊý¾Ýй¶Êܺ¦ÕßÌṩ12ÖÁ24¸öÔµÄÃâ·ÑÐÅÓÃ¼à¿ØÓëÉí·Ý͵ÇÔ±£»£»£»£»£»£»£»¤Ð§ÀÍ £¬£¬£¬£¬ÏêϸÏÞÆÚÈ¡¾öÓÚй¶Êý¾ÝµÄÑÏÖØË®Æ½¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/healthcare-services-group-data-breach-impacts-624-000-people/


2. Sangoma FreePBXÁãÈÕÎó²îÔâÆð¾¢Ê¹Óà £¬£¬£¬£¬¶ą̀ЧÀÍÆ÷±»ÈëÇÖ


8ÔÂ27ÈÕ £¬£¬£¬£¬Sangoma FreePBXÇå¾²ÍŶӿËÈÕÖÒÑÔ £¬£¬£¬£¬Æä»ùÓÚAsteriskµÄ¿ªÔ´PBXƽ̨±£´æ±»Æð¾¢Ê¹ÓõÄÁãÈÕÎó²î £¬£¬£¬£¬Ó°Ïì̻¶ÔÚ¹«¹²»¥ÁªÍøÉϵÄÖÎÀíÔ±¿ØÖÆÃæ°å£¨ACP£©ÏµÍ³¡£¡£¡£¡£¡£FreePBXÆÕ±éÓ¦ÓÃÓÚÆóÒµ¡¢ºô½ÐÖÐÐļ°Ð§ÀÍÌṩÉÌÖÎÀíÓïÒôͨѶ¡¢SIPÖм̵Ƚ¹µãÓªÒµ £¬£¬£¬£¬´Ë´ÎÎó²î̻¶Òý·¢´ó¹æÄ£Ð§ÀÍÆ÷ÈëÇÖÊÂÎñ £¬£¬£¬£¬²¨¼°ÊýǧSIP·Ö»úÓëÖмÌÏß·¡£¡£¡£¡£¡£¾ÝÇ徲ͨ¸æ £¬£¬£¬£¬×Ô8ÔÂ21ÈÕÆð £¬£¬£¬£¬ºÚ¿Íͨ¹ýδÊܱ£»£»£»£»£»£»£»¤µÄFreePBXÖÎÀíÔ±½çÃæÌᳫ¹¥»÷¡£¡£¡£¡£¡£SangomaÒÑÐû²¼EDGEÄ £¿£¿£¿£¿éÐÞ¸´³ÌÐòÒÔ×è¶ÏÐÂ×°ÖÃѬȾ £¬£¬£¬£¬µ«ÈϿɸò¹¶¡ÎÞ·¨½â¾öÏÖÓÐϵͳÎÊÌâ £¬£¬£¬£¬½¨ÒéÓû§Í¨¹ý·À»ðǽÏÞÖÆACP»á¼û £¬£¬£¬£¬½öÔÊÔÊÐíÐÅÖ÷»úÅþÁ¬¡£¡£¡£¡£¡£Îó²îÓ°ÏìÔËÐÐv16/v17°æ±¾ÇÒ×°Öö˵ãÄ £¿£¿£¿£¿éµÄϵͳ £¬£¬£¬£¬²¿·ÖÓâÆÚÖ§³ÖÌõÔ¼µÄ×°±¸¿ÉÄÜÎÞ·¨×°ÖøüР£¬£¬£¬£¬ÐèÍêÈ«×è¶ÏACP»á¼ûÖ±ÖÁ±ê×¼Çå¾²°æ±¾Ðû²¼¡£¡£¡£¡£¡£¹¥»÷ÒÑÔì³ÉÏÖʵË𺦣º¶àÃûÓû§±¨¸æÐ§ÀÍÆ÷±»ÈëÇÖ £¬£¬£¬£¬Ä³ÆóÒµ»ù´¡ÉèÊ©Öг¬3000¸öSIP·Ö»ú¼°500ÌõÖмÌÏßÊÜÓ°Ïì £¬£¬£¬£¬¹¥»÷Õßͨ¹ýÎó²îÖ´ÐÐí§ÒâAsteriskÏÂÁî¡£¡£¡£¡£¡£Sangoma½¨ÒéÊÜÓ°ÏìÓû§´Ó8ÔÂ21ÈÕǰ±¸·Ý»Ö¸´ÏµÍ³ £¬£¬£¬£¬°²ÅÅÐÞ²¹Ä £¿£¿£¿£¿éºóÂÖ»»ËùÓÐSIPƾ֤ £¬£¬£¬£¬²¢ºË²éͨ»°¼Í¼ÓëÕ˵¥ÖеÄÒì³£¹ú¼Êͨ»°¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/freepbx-servers-hacked-via-zero-day-emergency-fix-released/


3. ÀÕË÷Èí¼þPromptLockʹÓÃÈ˹¤ÖÇÄܼÓÃܺÍÇÔÈ¡Êý¾Ý


8ÔÂ27ÈÕ £¬£¬£¬£¬ÍþвÑо¿Ö°Ô±¿ËÈÕÅû¶һ¿îÃûΪPromptLockµÄ¿çƽ̨ÀÕË÷Èí¼þ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þͨ¹ý¼¯³ÉÈ˹¤ÖÇÄÜÊÖÒÕʵÏÖ¶¯Ì¬¾ç±¾ÌìÉú £¬£¬£¬£¬³ÉΪÊ׸ö±»Ö¤ÊµµÄAIÇý¶¯ÐÍÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¾ÝESET±¨¸æ £¬£¬£¬£¬PromptLock½ÓÄÉGolang±àд £¬£¬£¬£¬Ê¹ÓÃOllama APIŲÓÃOpenAIµÄgpt-oss:20b´óÐÍÓïÑÔÄ£×Ó £¬£¬£¬£¬Í¨¹ýÊðÀíËíµÀÅþÁ¬Ô¶³ÌЧÀÍÆ÷ÉϵÄLLM £¬£¬£¬£¬»ùÓÚÓ²±àÂëÌáÐѶ¯Ì¬ÌìÉú¶ñÒâLua¾ç±¾ £¬£¬£¬£¬ÊµÏÖ¶ÔWindows¡¢macOSºÍLinuxϵͳµÄÎļþö¾Ù¡¢Êý¾ÝÇÔÈ¡¼°¼ÓÃܲÙ×÷¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄ½¹µãÁ¢ÒìÔÚÓÚÆäÊÂÇéÁ÷³Ì£ºÍ¨¹ýÔ¤ÉèÌáÐÑ´ÊÖ¸ÁîÄ£×ÓÌìÉú¾ß±¸ÍâµØÏµÍ³½»»¥ÄÜÁ¦µÄLua¾ç±¾ £¬£¬£¬£¬º­¸ÇÎļþϵͳɨÃè¡¢Ãô¸ÐÊý¾Ýʶ±ð¡¢¼ÓÃÜʵÑéµÈÄ £¿£¿£¿£¿é¡£¡£¡£¡£¡£Ö»¹Ü¾ß±¸Êý¾ÝÏú»Ù¹¦Ð§ £¬£¬£¬£¬µ«¸ÃÌØÕ÷ÉÐδÍêȫʵÏÖ¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ £¬£¬£¬£¬PromptLock½ÓÄÉÇáÁ¿¼¶SPECK 128λËã·¨¾ÙÐмÓÃÜ £¬£¬£¬£¬Õâһͨ³£ÓÃÓÚRFIDÁìÓòµÄË㷨ѡÔñ £¬£¬£¬£¬±»Ñо¿Ö°Ô±ÊÓΪÊÖÒÕ²»¿ÉÊìµÄÌåÏÖ¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ÆäÓ²±àÂëµÄ±ÈÌØ±ÒµØµãÓëÖб¾´Ï¹ØÁª £¬£¬£¬£¬½øÒ»²½×ôÖ¤Á˸ÃÈí¼þÈÔ´¦ÓÚ¿´·¨ÑéÖ¤½×¶Î¡£¡£¡£¡£¡£ESETÇ¿µ÷ £¬£¬£¬£¬PromptLockÉÐδÔÚÕæÊµ¹¥»÷³¡¾°Öб»ÊӲ쵽 £¬£¬£¬£¬ÆäÑù±¾½öͨ¹ýVirusTotal±»·¢Ã÷ £¬£¬£¬£¬»òΪÑо¿ÏîĿй¶ËùÖ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/experimental-promptlock-ransomware-uses-ai-to-encrypt-steal-data/


4. ÃÀºÉÁªºÏÖ´·¨´Ý»Ù¿ç¹úαÔìÖ¤¼þƽ̨VerifTools


8ÔÂ28ÈÕ £¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©ÓëºÉÀ¼¾¯·½¿ËÈÕÕö¿ª¿ç¹úÁªºÏÐж¯ £¬£¬£¬£¬ÀֳɹرÕÈ«Çò×ÅÃûαÔìÉí·ÝÖ¤¼þƽ̨VerifTools £¬£¬£¬£¬²¢²é·âÆäλÓÚ°¢Ä·Ë¹Ìص¤µÄЧÀÍÆ÷¼¯Èº £¬£¬£¬£¬±ê¼Ç׏ú¼ÊÖ´·¨»ú¹¹¶ÔÊý×ÖÉí·Ý·¸·¨µÄÖØÈ­³ö»÷¡£¡£¡£¡£¡£¸Ãƽ̨×Ô2022ÄêÆðͨ¹ý¼ÓÃÜÇ®±ÒÉúÒâ £¬£¬£¬£¬ÒÔ9ÃÀÔªÖÁÊý°ÙÃÀÔª²»µÈµÄ¼ÛÇ®ÏòÈ«ÇòÓû§ÌṩαÔìµÄÃÀÅ·¸÷¹ú¼ÝʻִÕÕ¡¢»¤ÕÕµÈÖ¤¼þ £¬£¬£¬£¬Ðγɼ¯ÖÆ×÷¡¢ÊðÀí¹ºÖÃÓëÉí·ÝðÓÃÓÚÒ»ÌåµÄÍêÕûÐþÉ«¹¤ÒµÁ´¡£¡£¡£¡£¡£Æ¾Ö¤ÃÀ¹úÐÂÄ«Î÷¸çÖÝÉó²é¹Ù°ì¹«ÊÒÅû¶ £¬£¬£¬£¬FBIÓÚ2022Äê8ÔÂÆô¶¯ÊÓ²ì £¬£¬£¬£¬·¢Ã÷¸Ãƽ̨²»µ«±»ÓÃÓÚÒøÐÐÕ©Æ­¡¢ÍøÂç´¹ÂÚ¡¢ÌÓ±Ü˾·¨×·Ôð¼°ÄäÃûÈÆ¹ý½ðÈÚÆ½Ì¨"ÏàʶÄãµÄ¿Í»§"£¨KYC£©ÉóºË £¬£¬£¬£¬¸ü³ÉΪδ³ÉÄêÈ˹æ±ÜÄêËêÏÞÖÆµÄ»ÒɫͨµÀ¡£¡£¡£¡£¡£ºÉÀ¼¾¯·½Ö¤Êµ £¬£¬£¬£¬Óû§½öÐèÉÏ´«ÕÕÆ¬²¢ÌîдÐéαÐÅÏ¢ £¬£¬£¬£¬¼´¿Éͨ¹ý×Ô¶¯»¯ÏµÍ³ÌìÉú¸ß·ÂÕæÖ¤¼þͼÏñ £¬£¬£¬£¬Õû¸öÀú³ÌÓÌÈç"ÏßÉϵã²Í"°ã±ã½Ý¡£¡£¡£¡£¡£´Ë´ÎÐж¯ÖÐ £¬£¬£¬£¬ÃÀºÉÖ´·¨»ú¹¹²é»ñ2̨ÎïÀíЧÀÍÆ÷¼°21̨ÐéÄâЧÀÍÆ÷ £¬£¬£¬£¬³¹µ×¸´ÖÆÆäÍøÕ¾»ù´¡ÉèÊ©Êý¾Ý¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/police-seize-veriftools-fake-id-marketplace-servers-domains/


5. MathWorksÔâÓöÀÕË÷¹¥»÷ÖÂÍòÈËÊý¾Ýй¶


8ÔÂ28ÈÕ £¬£¬£¬£¬È«ÇòÊýѧÅÌËãÓë·ÂÕæÈí¼þÁì¾üÆóÒµMathWorks¿ËÈÕÅû¶ £¬£¬£¬£¬ÆäÍøÂçϵͳÓÚ2024Äê4ÔÂÔâÊÜÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬µ¼ÖÂÁè¼Ý1.04ÍòÃûÔ±¹¤¼°¿Í»§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£ÕⳡһÁ¬ÓâÔµÄÇå¾²ÊÂÎñÒý·¢Ð§ÀÍ´ó¹æÄ£ÖÐÖ¹ £¬£¬£¬£¬²¢Ì»Â¶³ö¹¤ÒµÈí¼þÁìÓòÈÕÒæÑÏËàµÄÍøÂçÇå¾²ÌôÕ½¡£¡£¡£¡£¡£Æ¾Ö¤MathWorksÏòÃÀ¹úÃåÒòÖݺÍÂíÈøÖîÈûÖÝ×ÜÉó²é³¤Ìá½»µÄ±¨¸æ £¬£¬£¬£¬¹¥»÷ÕßÓÚ4ÔÂÇÖÈëÆäÍøÂçºóºã¾ÃDZÔÚ £¬£¬£¬£¬Ö±ÖÁ5ÔÂ18Èղű»¼ì²â·¢Ã÷¡£¡£¡£¡£¡£´Ë´ÎÈëÇÖµ¼ÖÂÔ±¹¤Óë¿Í»§ÎÞ·¨»á¼û¶àÒòËØÈÏÖ¤£¨MFA£©¡¢µ¥µãµÇ¼£¨SSO£©¡¢ÔÆÖÐÐÄ¡¢ÔÊÐíÖ¤ÖÎÀíµÈÒªº¦ÏµÍ³ £¬£¬£¬£¬Ö±½ÓÓ°ÏìÈ«Çò34¸öЧÀÍ´¦µÄÔËÓª¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ýº­¸ÇÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç±£ºÅÂëµÈ¸ßÃô¸ÐÐÅÏ¢ £¬£¬£¬£¬Éæ¼°ÃÀ¹ú±¾ÍÁ¼°·ÇÃÀ¹ú¹«ÃñµÄ»ìÏýÊý¾Ý¼¯¡£¡£¡£¡£¡£ÖµµÃ¹Ø×¢µÄÊÇ £¬£¬£¬£¬Ö»¹ÜMathWorksÔÚ5ÔÂ27ÈÕ¹ûÕæÈÏ¿ÉÔâÓöÀÕË÷Èí¼þÊÂÎñ £¬£¬£¬£¬µ«Ê¼ÖÕδÅû¶¹¥»÷ÍÅ»ïÃû³Æ¼°ÏêϸÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ £¬£¬£¬£¬ÎÞÈκÎÒÑÖªÀÕË÷ÍÅ»ïÐû³Æ¶Ô´ËÊÂÈÏÕæ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/matlab-dev-says-ransomware-gang-stole-data-of-over-10-000-people/


6. TransUnionÒòSalesforceÕË»§ÈëÇÖÖÂ440ÍòÓû§Êý¾Ýй¶


8ÔÂ28ÈÕ £¬£¬£¬£¬ÃÀ¹úÈý´óÐÅÓñ¨¸æ»ú¹¹Ö®Ò»TransUnion¿ËÈÕÅû¶ £¬£¬£¬£¬ÆäSalesforceÕË»§ÓÚ2025Äê7ÔÂ28ÈÕÔâÓöδ¾­ÊÚȨ»á¼û £¬£¬£¬£¬µ¼ÖÂÔ¼440ÍòÃÀ¹úÓû§µÄÃô¸ÐСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÔÙ´Î̻¶ÁËÈ«ÇòÐÅÓÃÊý¾Ý¾ÞÍ·µÄÍøÂçÇå¾²¶Ì°å £¬£¬£¬£¬²¢Òý·¢¶ÔµÚÈý·½Ð§ÀÍÒÀÀµÎ£º¦µÄÆÕ±é¹Ø×¢¡£¡£¡£¡£¡£×÷ΪÄêÊÕÈë30ÒÚÃÀÔª¡¢ÓªÒµÁýÕÖ30¹úµÄÐÅÓÃÊý¾Ý¾ÞÍ· £¬£¬£¬£¬TransUnionÕÆÎÕ×ÅÈ«ÇòÁè¼Ý10ÒÚÏûºÄÕßµÄÐÅÓÃÐÅÏ¢ £¬£¬£¬£¬ÆäÖÐÃÀ¹ú±¾ÍÁÓû§Ô¼2ÒÚ¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾ÝԴΪÆäÏûºÄÕßÖ§³ÖӪҵʹÓõÄSalesforceµÚÈý·½Ó¦Óà £¬£¬£¬£¬¹¥»÷Õßͨ¹ý¸ÃÎó²îÇÔÈ¡ÁËÓû§ÐÕÃû¡¢µØµã¡¢µç»°¡¢ÓÊÏä¡¢³öÉúÈÕÆÚ¼°Î´±à¼­µÄÉç»áÇå¾²ºÅÂ루SSN£©µÈ½¹µãÉí·ÝÐÅÏ¢ £¬£¬£¬£¬ÉõÖÁ°üÀ¨¿Í»§ÇëÇóÃâ·ÑÐÅÓñ¨¸æµÄÉúÒâ¼Í¼¡£¡£¡£¡£¡£Ö»¹ÜTransUnionÇ¿µ÷δй¶½¹µãÐÅÓñ¨¸æÊý¾Ý £¬£¬£¬£¬µ«Ñù±¾ÖÐÏÔʾµÄÍêÕûSSNµÈÃô¸Ð×Ö¶Î £¬£¬£¬£¬ÈÔ×ãÒÔÈÃÊܺ¦ÕßÃæÁÙÉí·ÝµÁÓᢽðÈÚÕ©Æ­µÈÖØ´óΣº¦¡£¡£¡£¡£¡£¹«Ë¾ÒÑÏòÊÜÓ°ÏìÓû§Ìṩ24¸öÔÂÃâ·ÑÐÅÓÃ¼à¿ØÐ§ÀÍ £¬£¬£¬£¬µ«Î´Åû¶Ïêϸй¶¹æÄ£Óë¹¥»÷ÍÅ»ïÃû³Æ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/