NASCARÈ·ÈÏÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶
Ðû²¼Ê±¼ä 2025-07-291. NASCARÈ·ÈÏÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶
7ÔÂ26ÈÕ£¬£¬£¬£¬×÷Ϊһ¸ö½¨ÉèÓÚ1948ÄêµÄ»ú¹¹£¬£¬£¬£¬ÃÀ¹úÌìÏÂÈü³µÐ»á£¨NASCAR£©Ã¿ÄêÔÚÃÀ¹ú¾ÙÐÐÁè¼Ý1,500³¡½ÇÖ𣬣¬£¬£¬ÊÇÈ«Çò×ÅÃûµÄÆû³µÈüÊÂÖÎÀí»ú¹¹¡£¡£¡£¡£2025Äê3ÔÂ31ÈÕÖÁ4ÔÂ3ÈÕʱ´ú£¬£¬£¬£¬NASCARÔâÊÜÁËÒ»´ÎÑÏÖØµÄÍøÂç¹¥»÷£¬£¬£¬£¬µ¼Ö²¿·ÖÎļþ±»Î´¾ÊÚȨµÄ¹¥»÷Õß»ñÈ¡¡£¡£¡£¡£4ÔÂ3ÈÕ£¬£¬£¬£¬NASCARµÄITÍŶӷ¢Ã÷ÁË´Ë´ÎÈëÇÖ£¬£¬£¬£¬²¢Ëæ¼´Õö¿ªÊӲ죬£¬£¬£¬Í¬Ê±Í¨ÖªÁËÖ´·¨²¿·Ö²¢Ô¼ÇëÁËÒ»¼ÒÍøÂçÇå¾²¹«Ë¾ÐÖúÆÊÎö¡£¡£¡£¡£ÊÓ²ìЧ¹ûÏÔʾ£¬£¬£¬£¬¹¥»÷ÕßÀÖ³ÉÇÔÈ¡ÁË´æ´¢ÔÚ¹«Ë¾ÍøÂçÖеÄijЩÎļþ¡£¡£¡£¡£Ö±µ½6ÔÂÏÂÑ®£¬£¬£¬£¬NASCAR²ÅÈ·ÈÏÕâЩÎļþÖаüÀ¨Óû§µÄСÎÒ˽¼ÒÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ÓÈÆäÊÇÉç»á°ü¹ÜºÅÂë¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬¹«Ë¾²¢Î´Í¸Â¶ÏêϸÊÜÓ°ÏìµÄÈËÊý¡£¡£¡£¡£ 7ÔÂ24ÈÕ£¬£¬£¬£¬NASCARÏòÊܺ¦Õß·¢ËÍÁËÊý¾Ýй¶֪ͨÐÅ£¬£¬£¬£¬²¢ÌṩÁËΪÆÚÒ»ÄêµÄÐÅÓÃ¼à¿ØÐ§ÀÍ×÷Ϊµ÷½â²½·¥¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÔçÔÚ4Ô£¬£¬£¬£¬MedusaÀÕË÷Èí¼þÍÅ»ïÒѽ«NASCARÁÐÈëÆäÐ¹Â¶ÍøÕ¾Ãûµ¥£¬£¬£¬£¬ÒªÇóÖ§¸¶400ÍòÃÀÔªÊê½ð£¬£¬£¬£¬²¢Éù³ÆÇÔÈ¡ÁË´ó×Ú¹«Ë¾Êý¾Ý¡£¡£¡£¡£Ö»¹ÜÉ趨ÁË4ÔÂ19ÈÕµÄ×îºóÏÞÆÚ£¬£¬£¬£¬µ«Éв»ÇåÎúÕâЩÊý¾ÝÊÇ·ñ×îÖÕ±»¹ûÕæ¡£¡£¡£¡£
https://therecord.media/nascar-confirms-data-breach
2. ÎÚ¿ËÀ¼ºÚ¿ÍÈëÇÖ¶íº½£¬£¬£¬£¬ÖÂ40Óà´Îº½°à×÷·Ï
7ÔÂ28ÈÕ£¬£¬£¬£¬¶íÂÞ˹¹ú¼Òº½¿Õ¹«Ë¾¶íº½£¨Aeroflot£©ÒòÔâÓöÇ×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯"ĬȻÎÚÑ»"Óë°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓµÄÁªºÏÍøÂç¹¥»÷£¬£¬£¬£¬±»ÆÈ×÷·Ï40Óà¼Ü´Îº½°à£¬£¬£¬£¬²¢µ¼ÖÂÊýÊ®¼Üº½°àÑÓÎ󣬣¬£¬£¬È«ÇòÁìÍÁÃæ»ý×î´ó¹ú¼ÒµÄº½¿ÕÔËÊäÍøÂçÔÚÂÃÓÎÍú¼¾ÏÝÈëÔÓÂÒ¡£¡£¡£¡£Á½¸öºÚ¿Í×éÖ¯Ðû³ÆÐж¯ÊÇÒ»Á¬Ò»ÄêÉøÍ¸µÄЧ¹û£¬£¬£¬£¬ÒÑ´Ý»Ù¶íº½7000̨ЧÀÍÆ÷²¢¿ØÖƸ߹ܼ°Ô±¹¤µçÄÔ£¬£¬£¬£¬Íþв½«Ð¹Â¶ÂÿÍСÎÒ˽¼ÒÐÅÏ¢¼°ÄÚ²¿Í¨Ñ¶¼Í¼¡£¡£¡£¡£°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓÃ÷È·ÌåÏÖ£¬£¬£¬£¬¹¥»÷Ö¼ÔÚÐÖúÎÚ¿ËÀ¼¶Ô¿¹"ÇÖÂÔÕß"£¬£¬£¬£¬ÉùÃ÷ÒÔ"ÎÚ¿ËÀ¼ÍòË꣡°×¶íÂÞ˹×ÔÓÉÓÀ´æ£¡"×îºó¡£¡£¡£¡£Ö»¹ÜÎÚ¿ËÀ¼¹Ù·½Î´»ØÓ¦£¬£¬£¬£¬µ«"ĬȻÎÚÑ»"´ËÇ°Ôø¶à´ÎÐû³Æ¹¥»÷¶í²»¶¯²úÊý¾Ý¿â¡¢¹úÓеçÐŹ«Ë¾µÈÄ¿µÄ£¬£¬£¬£¬²¿·ÖÐж¯µ¼Ö´ó¹æÄ£Êý¾Ýй¶¡£¡£¡£¡£¿£¿£¿ËÀïÄ·ÁÖ¹¬½²»°ÈËÅå˹¿Æ·ò³ÆÊÂÎñ"ÁîÈ˵£ÐÄ"£¬£¬£¬£¬Ç¿µ÷ÍøÂçÍþвÊÇ´óÐ͹«¹²Ð§ÀÍÆóÒµÒ»Á¬ÃæÁÙµÄÒþ»¼£¬£¬£¬£¬¶í¼ì·½ÒÑÆô¶¯ÐÌÊÂÊӲ졣¡£¡£¡£×ÊÉîÒéÔ±°²¶«¡¤¸êÁжû½ðÖ¸³ö£¬£¬£¬£¬¹¥»÷ÏÔʾ"Êý×ÖÕ½ÏßÒѳÉΪÖÜÈ«¶Ô¿¹µÄÒ»²¿·Ö"£¬£¬£¬£¬ÒªÇó³¹²é·À»¤Ê§Ö°ÔðÈη½¡£¡£¡£¡£¶íº½ËäδÐû²¼ÏµÍ³»Ö¸´Ê±¼ä£¬£¬£¬£¬µ«ÌåÏÖÕýе÷ÆäËûº½Ë¾ÐÖúתÔËÂÿͣ¬£¬£¬£¬²¢ÔÊÐí»Ö¸´ºó°ìÀíÍ˸ÄÇ©¡£¡£¡£¡£
https://cybernews.com/security/glory-ukraine-hackers-took-down-aeroflots-entire-system/
3. GLOBAL GROUPÀÕË÷Èí¼þµ¼ÖÂýÌå¾ÞÍ·Albavisi¨®nÊý¾Ýй¶
7ÔÂ28ÈÕ£¬£¬£¬£¬ÐÂÐËÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©×éÖ¯GLOBAL GROUPÐû³Æ¶ÔÎ÷°àÑÀÓïýÌå¾ÞÍ·Albavisi¨®nµÄÊý¾Ýй¶ÊÂÎñÈÏÕæ£¬£¬£¬£¬ÇÔÈ¡400GBÊý¾Ý²¢ÍþвÈô15ÌìÄÚδÆô¶¯Ì¸ÅУ¬£¬£¬£¬½«¹ûÕæ±»µÁÐÅÏ¢¡£¡£¡£¡£¸Ã×éÖ¯×Ô2025Äê6Ô»îÔ¾ÒÔÀ´£¬£¬£¬£¬Òѽ«Ã½Ìå¡¢Ò½ÁƱ£½¡µÈ¶à¸öÐÐÒµµÄ29¼ÒÆóÒµÁÐΪÊܺ¦Õߣ¬£¬£¬£¬ÆäÖÐ18Æð°¸¼þµ¼ÖÂÍêÕûÊý¾Ý¼¯Ð¹Â¶£¬£¬£¬£¬°üÀ¨Ò»¼ÒÒ½Ôº£¬£¬£¬£¬Í¹ÏÔÆä¹¥»÷¹æÄ£µÄÆÕ±éÐÔÓëÆÆËðÁ¦¡£¡£¡£¡£GLOBAL GROUPµÄÆæÒìÖ®´¦ÔÚÓÚ½ÓÄÉÈ˹¤ÖÇÄÜÇý¶¯µÄ̸Åй¤¾ß£¬£¬£¬£¬Í¨¹ý̸Ìì»úеÈËÓëÊܺ¦ÕßÏàͬ£¬£¬£¬£¬ÓÈÆäÕë¶Ô·ÇÓ¢ÓïʹÓÃÕߣ¬£¬£¬£¬½µµÍÁËÓïÑÔÕϰ¶ÔÀÕË÷ЧÂʵÄÓ°Ïì¡£¡£¡£¡£´Ëǰ°¸ÀýÖУ¬£¬£¬£¬¸Ã×éÖ¯ÔøË÷Òª9.5±ÈÌØ±Ò£¨Ô¼ºÏ100ÍòÃÀÔª£©Êê½ð£¬£¬£¬£¬µ«±¾´ÎÕë¶ÔAlbavisi¨®nµÄÏêϸ½ð¶îÉÐδ¹ûÕæ¡£¡£¡£¡£Albavisi¨®n×÷ΪÀ¶¡ÃÀÖÞ¿ç¹úýÌ弯ÍÅ£¬£¬£¬£¬ÓªÒµÁýÕÖ14ÖÁ15¸öÎ÷°àÑÀÓï¹ú¼Ò£¬£¬£¬£¬ÓµÓÐ45¸öµçÊÓÆµµÀ¡¢68¸ö¹ã²¥µç̨¼°65¼ÒÓ°Ï·Ôº£¬£¬£¬£¬Ê×´´ÈËÀ×Ã×¼ª°Â¡¤°²ºÕ¶û¡¤¸ÔÈøÀ×˹СÎÒ˽¼Ò×ʲúÔ¼20ÒÚÃÀÔª£¬£¬£¬£¬ÆäÖØ´óµÄÓû§Êý¾ÝÓëÉÌÒµÓ°ÏìÁ¦³ÉΪÀÕË÷ÍÅ»ïµÄÄ¿µÄ¡£¡£¡£¡£
https://hackread.com/global-group-ransomware-media-giant-albavision-breach/
4. Ó¢¹ú¿Æ¼¼³Ð°üÉÌQdos֤ʵ¿Í»§Êý¾Ýй¶
7ÔÂ25ÈÕ£¬£¬£¬£¬ÉÌÒµ°ü¹Ü¼°IR35ЧÀÍר¼ÒQdos¿ËÈÕÈ·ÈÏÆäÍøÂçÓ¦ÓóÌÐò±¬·¢Êý¾ÝÇå¾²ÊÂÎñ£¬£¬£¬£¬²¿·Ö¿Í»§Ð¡ÎÒ˽¼ÒÊý¾Ý±»Î´¾ÊÚȨµÄµÚÈý·½ÇÔÈ¡¡£¡£¡£¡£Æ¾Ö¤QdosÏò¿Í»§·¢Ë͵ĵç×ÓÓʼþ£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ6ÔÂ19ÈÕÊÕµ½¹ØÓÚÆäWebÓ¦ÓÃmygoqdos.comµÄÇå¾²¾¯±¨£¬£¬£¬£¬ËæºóÔÚµÚÈý·½ÍøÂçÇ徲ר¼ÒÐÖúÏÂÕö¿ªÊӲ졣¡£¡£¡£ÊÓ²ìÈ·ÈÏ£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¸ÃÓ¦Óûá¼û²¢ÏÂÔØÁ˰üÀ¨¿Í»§ÐÕÃû¡¢Í¨Ñ¶µØµã£¨»ò×¢²áÓªÒµµØµã£©¡¢µç×ÓÓʼþµØµã¼°ÁªÏµ·½·¨µÈСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬ÒÔ¼°Óë¿Í»§°ü¹Üµ¥¡¢IR35ЧÀÍÏà¹ØµÄÎļþ£¬£¬£¬£¬ÉÐÓвɹº»·½ÚµÄ·¢Æ±¡¢´û¼Çµ¥µÈÎĵµ¡£¡£¡£¡£²»¹ý£¬£¬£¬£¬QdosÇ¿µ÷ÐÅÓÿ¨ÐÅÏ¢¡¢Éí·Ý֤ʵÎļþ¼°°ü¹ÜË÷ÅâÐÅϢδÊÜÓ°Ïì¡£¡£¡£¡£ÊÂÎñ±¬·¢ºó£¬£¬£¬£¬QdosÁ¬Ã¦½ÓÄÉÓ¦¼±²½·¥£¬£¬£¬£¬°üÀ¨ÔÚÊÓ²ìʱ´ú½ûÓÿͻ§¶ÔÍøÕ¾µÄ»á¼ûȨÏÞ£¬£¬£¬£¬²¢ÓÚ6ÔÂ26ÈÕÐÞ¸´ÎÊÌâºó»Ö¸´Ð§ÀÍ¡£¡£¡£¡£ÎªÓ¦¶Ô´Ë´Îй¶£¬£¬£¬£¬¹«Ë¾ÎªÊÜÓ°Ïì¿Í»§ÌṩÁË12¸öÔµÄÃâ·ÑÉí·Ý¼à¿ØÐ§ÀÍ£¬£¬£¬£¬¸ÃЧÀÍ¿ÉÈ«Ììºò¼à²âÍøÂç¡¢É罻ƽ̨¼°¹«¹²Êý¾Ý¿â£¬£¬£¬£¬ÊµÊ±Ô¤¾¯Ð¡ÎÒ˽¼ÒÐÅϢй¶Σº¦¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬Qdos½¨Òé¿Í»§Ð¡ÐÄ¿ÉÒÉÓʼþ¡¢µç»°»ò¶ÌÐÅ£¬£¬£¬£¬²¢ÔÊÐí¿Í»§±£µ¥ÓÐÓÃÐÔ¼°ÔÚÏßÕË»§¹¦Ð§²»ÊÜÓ°Ïì¡£¡£¡£¡£
https://www.theregister.com/2025/07/25/ir35_advisor_qdos_confirms_data_breach/
5. Patchwork×éÖ¯Õë¶ÔÍÁ¶úÆä¹ú·À³Ð°üÉÌÌᳫÓã²æ´¹ÂÚ¹¥»÷
7ÔÂ25ÈÕ£¬£¬£¬£¬ÍøÂçÇå¾²Íþв×éÖ¯Patchwork£¨ÓÖÃûAPT-C-09¡¢°×Ïó×éÖ¯£©½üÆÚ±»ÆØÕë¶ÔÍÁ¶úÆä¹ú·À³Ð°üÉÌÌᳫÐÂÒ»ÂÖÓã²æÊ½ÍøÂç¹¥»÷£¬£¬£¬£¬Ä¿µÄÖ±Ö¸ÎÞÈËÔØ¾ßϵͳ£¨UAV£©¼°×¼È·ÖƵ¼µ¼µ¯ÁìÓò£¬£¬£¬£¬Ö¼ÔÚÇÔȡսÂÔÇ鱨¡£¡£¡£¡£¾ÝArctic WolfʵÑéÊÒÊÖÒÕ±¨¸æ£¬£¬£¬£¬¹¥»÷Õßͨ¹ýαװ³É¡°¹ú¼ÊÎÞÈËÔØ¾ßϵͳ¾Û»áÔ¼Ç뺯¡±µÄ¶ñÒâLNKÎļþʵÑéÎå½×¶Î¹¥»÷Á´£¬£¬£¬£¬¹¥»÷ʱ»úÇ¡·ê°Í»ù˹̹ÓëÍÁ¶úÆäÉ·ÀÎñÏàÖú¡¢Ó¡°Í¾üʳåÍ»Éý¼¶Ö®¼Ê£¬£¬£¬£¬µØÔµÕþÖÎÄîÍ·ÏÔÖø¡£¡£¡£¡£¹¥»÷Á÷³ÌʼÓÚ´¹ÂÚÓʼþÖеĶñÒâLNKÎļþ£¬£¬£¬£¬¸ÃÎļþ´¥·¢PowerShellÏÂÁ£¬£¬£¬´Ó2025Äê6ÔÂ25ÈÕ×¢²áµÄÓòÃû¡°expouav[.]org¡±ÏÂÔØÔØºÉ¡£¡£¡£¡£Ð§ÀÍÆ÷ÍйܵķÂð¾Û»áPDFÎĵµ×÷ΪÊÓ¾õÓÕ¶üÊèÉ¢Óû§×¢ÖØÁ¦£¬£¬£¬£¬¹¥»÷Á´ÔòÔÚºǫ́¾²Ä¬ÔËÐС£¡£¡£¡£Òªº¦ÔغɰüÀ¨Í¨¹ýÍýÏëʹÃüÆô¶¯µÄ¶ñÒâDLL£¬£¬£¬£¬½ÓÄÉDLL²à¼ÓÔØÊÖÒÕÖ´ÐÐshellcode£¬£¬£¬£¬×îÖÕʵÏÖÖ÷»úÉî¶ÈÕì̽¡¢ÆÁÄ»½ØÍ¼¼°Êý¾Ý»Ø´«ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£ÊÖÒÕÆÊÎöÏÔʾ£¬£¬£¬£¬PatchworkÒÑ´Ó2024ÄêµÄx64 DLL±äÖÖ£¬£¬£¬£¬Éú³¤Îª¾ß±¸ÔöÇ¿ÏÂÁî½á¹¹µÄx86 PE¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬²¢½ÓÄÉ·ÂðÕýµ±ÍøÕ¾µÄC2ÐÒ飬£¬£¬£¬ÏÔÖøÌáÉýÁ˹¥»÷Òþ²ØÐÔ¡£¡£¡£¡£
https://thehackernews.com/2025/07/patchwork-targets-turkish-defense-firms.html
6. CISAÖÒÑÔPaperCut´òÓ¡Èí¼þ¸ßΣÎó²îÔâÆð¾¢Ê¹ÓÃ
7ÔÂ28ÈÕ£¬£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²Óë»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕ·¢³ö½ôÆÈÖÒÑÔ£¬£¬£¬£¬³ÆÍþвÐÐΪÕßÕýʹÓÃPaperCut NG/MF´òÓ¡ÖÎÀíÈí¼þÖеĸßΣÎó²î£¨CVE-2023-2533£©Ìᳫ¿çÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷£¬£¬£¬£¬²¢½è´Ë»ñµÃÔ¶³Ì´úÂëÖ´ÐÐÄÜÁ¦¡£¡£¡£¡£¸ÃÎó²îÓÚ2023Äê6Ô±»ÐÞ²¹£¬£¬£¬£¬µ«ÏÖÔÚÈÔ±»¶ñÒâÐÐΪÕ߯ð¾¢Ê¹Ó㬣¬£¬£¬¹¥»÷Õßͨ³£Í¨¹ýÓÕÆ¾ßÓÐÖÎÀíԱȨÏÞµÄÓû§µã»÷¶ñÒâÁ´½Ó£¬£¬£¬£¬¼´¿É¸ü¸ÄϵͳÇå¾²ÉèÖûòÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£PaperCutÈí¼þÔÚÈ«ÇòÓµÓÐÖØ´óÓû§»ù´¡£¬£¬£¬£¬ÁýÕÖÁè¼Ý7Íò¸ö×éÖ¯µÄ1ÒÚ¶àÓû§£¬£¬£¬£¬Éæ¼°½ÌÓý¡¢ÆóÒµµÈ¶àÁìÓò¡£¡£¡£¡£Ö»¹ÜCISAδÅû¶Ŀ½ñ¹¥»÷µÄÏêϸϸ½Ú£¬£¬£¬£¬µ«Òѽ«¸ÃÎó²îÄÉÈëÆä¡°ÒÑÖª±»Ê¹ÓÃÎó²îĿ¼¡±£¬£¬£¬£¬²¢ÒÀ¾Ý2021Äê11ÔÂÐû²¼µÄ¾ßÓÐÔ¼ÊøÁ¦µÄÔËÓªÖ¸ÁBOD 22-01£©£¬£¬£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©»ú¹¹ÔÚ2025Äê8ÔÂ18ÈÕǰÍê³ÉϵͳÐÞ²¹¡£¡£¡£¡£CISAÇ¿µ÷£¬£¬£¬£¬´ËÀàÎó²îÊÇÍøÂç·¸·¨·Ö×ӵij£¼û¹¥»÷ǰÑÔ£¬£¬£¬£¬´ºÁª°îÆóÒµ×é³ÉÖØ´óΣº¦£¬£¬£¬£¬²¢ºôÓõ˽Ӫ²¿·Ö×é֯ͬÑù¾¡¿ì½ÓÄÉÐж¯¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cisa-flags-papercut-rce-bug-as-exploited-in-attacks-patch-now/


¾©¹«Íø°²±¸11010802024551ºÅ