ÐÂÐËShinySp1d3rÀÕË÷Èí¼þÊÖÒÕÔËÓªÕ½ÂÔÆØ¹â

Ðû²¼Ê±¼ä 2025-11-21

1. ÐÂÐËShinySp1d3rÀÕË÷Èí¼þÊÖÒÕÔËÓªÕ½ÂÔÆØ¹â


11ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±Åû¶ÁËÃûΪ"ShinySp1d3r"µÄÐÂÐÍÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©Æ½Ì¨¿ª·¢Ï¸½Ú ¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨ÓÉÓëShinyHunters¡¢Scattered Spider¼°Lapsus$×éÖ¯¹ØÁªµÄÍþвÐÐΪÕß½¨É裬 £¬£¬£¬£¬£¬£¬±ê¼Ç×ÅÕâЩÍÅ»ï´ÓʹÓõÚÈý·½¼ÓÃÜÆ÷תÏò×ÔÖ÷¿ª·¢ ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ª·¢°æ±¾ÏÔʾ£¬ £¬£¬£¬£¬£¬£¬ShinySp1d3r½ÓÄÉÈ«×ÔÖ÷Ñз¢¼Ü¹¹£¬ £¬£¬£¬£¬£¬£¬Î´¸´ÓÃLockBit»òBabukµÈÒÑÖª´úÂë¿â£¬ £¬£¬£¬£¬£¬£¬¾ß±¸¶àÏîÁ¢Ò칦Ч ¡£¡£¡£¡£¡£¡£¡£ÊÖÒÕ²ãÃæ£¬ £¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þʹÓÃChaCha20¼ÓÃÜËã·¨ÅäºÏRSA-2048±£» £»£»£»£»¤Ë½Ô¿£¬ £¬£¬£¬£¬£¬£¬Ã¿¸ö¼ÓÃÜÎļþÌìÉúÆæÒìÀ©Õ¹Ãû²¢Í¨¹ýÊýѧ¹«Ê½¶¯Ì¬ÌìÉú ¡£¡£¡£¡£¡£¡£¡£ÎļþÍ·ÒÔ"SPDR"¿ªÍ·¡¢"ENDS"×îºó£¬ £¬£¬£¬£¬£¬£¬°üÀ¨ÎļþÃû¡¢¼ÓÃÜ˽Կ¼°ÔªÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£ÆäÈö²¥»úÖÆÖ§³Öͨ¹ýSCMЧÀÍ¡¢WMIÀú³Ì½¨Éè¼°GPO¾ç±¾°²ÅÅʵÏÖºáÏòÉøÍ¸£¬ £¬£¬£¬£¬£¬£¬²¢¾ß±¸ËÑË÷¿ª·ÅÍøÂç¹²ÏíÖ÷»ú¾ÙÐжþ´Î¼ÓÃܵÄÄÜÁ¦ ¡£¡£¡£¡£¡£¡£¡£·´ÆÊÎöÌØÕ÷°üÀ¨¹Ò¹³EtwEventWriteº¯Êý×è¶ÏÈÕÖ¾¼Í¼¡¢ÁýÕÖÄڴ滺³åÇø·Àȡ֤£¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°Í¨¹ýдÈëËæ»ú.tmpÎļþÌî³ä´ÅÅ̿ռä×è°­Êý¾Ý»Ö¸´ ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters/


2. ¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾IGTÔâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷


11ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬£¬¹ú¼ÊÓÎÏ·¿Æ¼¼¹«Ë¾£¨IGT£©×÷ΪȫÇòÁìÏȵĶij¡¼°ÔÚÏ߯½Ì¨Êý×ÖÓÎÏ·¡¢ÌåÓý²©²ÊºÍ½ðÈڿƼ¼¹©Ó¦ÉÌ£¬ £¬£¬£¬£¬£¬£¬¿ËÈÕ±»Óë¶íÂÞ˹¹ØÁªµÄ÷è÷ëÀÕË÷Èí¼þ×éÖ¯ÈÏÁì ¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚ°µÍøÐ¹Â¶²©¿ÍÐû²¼IGTÌõÄ¿£¬ £¬£¬£¬£¬£¬£¬Éù³ÆÇÔÈ¡ÁË10GBÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬21,683¸öÎļþ£¬ £¬£¬£¬£¬£¬£¬º­¸Ç´ÓÀÏ»¢»ú¡¢²ÊƱϵͳµ½PlaySportsÌåÓý²©²Êƽ̨µÈ½¹µãÓªÒµÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£IGT²úÆ·ÆÕ±éÓ¦ÓÃÓÚÈ«Çò100¶à¸ö¹ú¼Ò£¬ £¬£¬£¬£¬£¬£¬ÖðÈÕЧÀÍÊý°ÙÍòÍæ¼Ò£¬ £¬£¬£¬£¬£¬£¬Æä½ðÈڿƼ¼²¿·Ö´æ´¢´ó×Ú¿Í»§Éí·ÝÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬ÃæÁÙÉí·Ý͵ÇÔΣº¦ ¡£¡£¡£¡£¡£¡£¡£×èÖ¹±¨µÀÐû²¼£¬ £¬£¬£¬£¬£¬£¬IGTδ¶Ô´ËÊÂ×÷³ö»ØÓ¦ ¡£¡£¡£¡£¡£¡£¡£÷è÷ë×éÖ¯×Ô2021Äê»î¶¯ÒÔÀ´£¬ £¬£¬£¬£¬£¬£¬2025ÄêÒѳÉΪ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯£¬ £¬£¬£¬£¬£¬£¬ÒÑÍùÁù¸öÔ·¢¶¯³¬500Æð¹¥»÷£¬ £¬£¬£¬£¬£¬£¬×Ô2023ÄêÆðÒÑÁгö991ÃûÊܺ¦Õߣ¬ £¬£¬£¬£¬£¬£¬°üÀ¨×ÅÃûÆóÒµ¡¢Ò½ÁÆ»ú¹¹¼°Õþ¸®»ú¹¹ ¡£¡£¡£¡£¡£¡£¡£Æä½ÓÄÉÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©ÉÌҵģʽ£¬ £¬£¬£¬£¬£¬£¬³£Ê¹ÓÃË«ÖØÀÕË÷Õ½ÂÔ£ºÏÈË÷Òª½âÃÜÊê½ð£¬ £¬£¬£¬£¬£¬£¬ÔÙÍþвй¶Êý¾Ý ¡£¡£¡£¡£¡£¡£¡£


https://cybernews.com/news/igt-digital-gaming-leader-qilin-ransomware-attack-casino-fintech-sports-betting/


3. ¶íÂÞ˹VSK°ü¹Ü¹«Ë¾Ôâ´ó¹æÄ£ÍøÂç¹¥»÷


11ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬×÷Ϊ¶íÂÞ˹×î´ó×ۺϰü¹Ü¹«Ë¾Ö®Ò»£¬ £¬£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚĪ˹¿ÆµÄVSK 11ÔÂ13ÈÕ¹ûÕæÈ·ÈÏÔâÓö¡°´ó¹æÄ£ÍøÂç¹¥»÷¡±£¬ £¬£¬£¬£¬£¬£¬ÏÖÔÚÆä¹ÙÍø¡¢Òƶ¯Ó¦Óü°Êý°ÙÍòÓû§ÒÀÀµµÄЧÀÍÒÑÒ»Á¬ÏÂÏßÒ»ÖÜ ¡£¡£¡£¡£¡£¡£¡£×÷ΪЧÀÍÔ¼3300ÍòСÎÒ˽¼Ò¿Í»§ºÍ50¶àÍò¼ÒÆóÒµµÄÐÐÒµ¾ÞÍ·£¬ £¬£¬£¬£¬£¬£¬VSKÓªÒµº­¸Ç¹¤ÒµÏÕ¡¢½»Í¨ÏÕ¡¢¿µ½¡ÏյȶàÁìÓò£¬ £¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñµ¼Ö¿ͻ§ÎÞ·¨¹ºÖóµÏÕ¡¢Ð޸ı£µ¥¡¢»ñÈ¡µ£±£º¯»òÔ¤Ô¼Ò½ÁÆÐ§ÀÍ£¬ £¬£¬£¬£¬£¬£¬²¿·ÖÒ½ÁÆ»ú¹¹ÒòÎÞ·¨ºËʵ°ü¹ÜÁýÕÖ¹æÄ£¾Ü¾øÐ§ÀÍ£¬ £¬£¬£¬£¬£¬£¬¹«Ë¾ÓʼþϵͳÒàÖÐÖ¹£¬ £¬£¬£¬£¬£¬£¬±»ÆÈ½¨Òé¿Í»§Í¨¹ýƽÐÅÌá½»×Éѯ ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜVSKÇ¿µ÷¡°½öIT»ù´¡ÉèÊ©ÊÜÓ°Ï죬 £¬£¬£¬£¬£¬£¬¿Í»§¼°ÏàÖúͬ°éÊý¾ÝÇå¾²ÎÞÓÝ¡±£¬ £¬£¬£¬£¬£¬£¬µ«ÎÚ¿ËÀ¼ºÚ¿ÍÏà¹ØTelegramƵµÀÒÑÐû²¼¾Ý³ÆÐ¹Â¶µÄÐÅÏ¢¼°±¸·ÝÎļþ½ØÍ¼£¬ £¬£¬£¬£¬£¬£¬ÕæÊµÐÔ´ýºËʵ ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾Í¬Ê±ÖÒÑÔ£¬ £¬£¬£¬£¬£¬£¬ÆäÆóÒµÓòÃûÔâÐ®ÖÆ£¬ £¬£¬£¬£¬£¬£¬»á¼ûÕß»á±»ÖØ¶¨ÏòÖÁÐéαTelegramƵµÀ ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ¹¥»÷ÕßÉí·Ý¼°ÄîͷδÃ÷£¬ £¬£¬£¬£¬£¬£¬¶íÂÞË¹ÍøÂçÇ徲ר¼ÒÍÆ²âΪÀÕË÷Èí¼þ¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/russia-vsk-cyberattack-outages


4. Òâ´óÀûFS¼¯ÍÅÒòAlmavivaÔâÈëÇÖÖÂ2.3TBÊý¾Ýй¶


11ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬£¬Òâ´óÀû¹ú¼ÒÌú·ÔËÓªÉÌFS Italiane¼¯ÍÅÒòITЧÀÍÌṩÉÌAlmavivaÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂ2.3TBÃô¸ÐÊý¾Ýй¶ÖÁ°µÍø ¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÉù³ÆÇÔÈ¡ÄÚÈݺ­¸ÇÉñÃØÎļþ¡¢ÊÖÒÕÎĵµ¡¢¹«¹²ÊµÌåÌõÔ¼¡¢ÈËÁ¦×ÊÔ´µµ°¸¡¢»á¼ÆÊý¾Ý¼°¶à¼ÒFS¼¯ÍŹ«Ë¾µÄÍêÕûÊý¾Ý¼¯£¬ £¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨2025ÄêµÚÈý¼¾¶ÈµÄ×îÐÂÎļþ ¡£¡£¡£¡£¡£¡£¡£D3LabÍøÂçÍþвÇ鱨Ö÷¹Ü°²µÂÁÒÑÇ¡¤µÂÀ­¸ÇµÙÃ÷ȷɨ³ý¸ÃÊý¾ÝΪ2022ÄêHiveÀÕË÷Èí¼þ¹¥»÷½ÓÄÉʹÓõĿÉÄÜÐÔ£¬ £¬£¬£¬£¬£¬£¬²¢Ö¸³öת´¢Îļþ°´²¿·Ö/¹«Ë¾×éÖ¯µÄѹËõ´æµµ½á¹¹Óë2024-2025Äê»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯¼°Êý¾Ý¾­¼ÍÈË×÷°¸ÊÖ·¨¸ß¶ÈÒ»Ö ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜAlmavivaÓëFS¼¯Ížùδ»ØÓ¦Ã½Ìå³õÆÚÎÊѯ£¬ £¬£¬£¬£¬£¬£¬µ«AlmavivaºóÐøÍ¨¹ýÍâµØÃ½ÌåÉùÃ÷֤ʵÊÂÎñ£ºÆäÇå¾²¼à¿Ø²¿·Ö½üÆÚ·¢Ã÷²¢¸ôÀëÁËÒ»ÆðÓ°Ï칫˾ϵͳµÄÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬µ¼Ö²¿·ÖÊý¾Ý±»µÁ ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÆô¶¯Çå¾²Ó¦¶Ô³ÌÐò£¬ £¬£¬£¬£¬£¬£¬È·±£Òªº¦Ð§ÀÍÔËÐУ¬ £¬£¬£¬£¬£¬£¬²¢Í¨Öª¾¯·½¡¢¹ú¼ÒÍøÂçÇå¾²»ú¹¹¼°Êý¾Ý±£» £»£»£»£»¤»ú¹¹£¬ £¬£¬£¬£¬£¬£¬ÏÖÔÚÊÓ²ìÈÔÔÚÕþ¸®»ú¹¹Ð­ÖúϾÙÐУ¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÒÔ͸Ã÷·½·¨¸üÐÂÏ£Íû ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬Êý¾Ýй¶ÊÇ·ñ°üÀ¨ÂÿÍÐÅÏ¢»òÓ°ÏìFS¼¯ÍÅÒÔÍâµÄÆäËû¿Í»§Éв»Ã÷È· ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-23tb-data-from-italian-rail-group-almavia/


5. PhotocallµÁ°æÆ½Ì¨Ôâ¹Ø±Õ£¬ £¬£¬£¬£¬£¬£¬³¬2600ÍòÓû§ÊÜÓ°Ïì


11ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬£¬ÓµÓг¬2600ÍòÓû§µÄµÁ°æµçÊÓÁ÷ýÌåÆ½Ì¨PhotocallÔÚ´´ÒâÓëÓéÀÖͬÃË£¨ACE£©ÓëDAZNÁªºÏÊÓ²ìºóÒÑ×èÖ¹ÔËÓª ¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨δ¾­ÊÚȨÌṩÀ´×Ô60¸ö¹ú¼ÒµÄ1127¸öµçÊÓÆµµÀ»á¼ûЧÀÍ£¬ £¬£¬£¬£¬£¬£¬º­¸ÇÌåÓýÈüÊÂÖ±²¥¡¢Òâ¼×ÁªÈü¡¢NFL/NHLÈüʼ°»Ê¼ÒÂíµÂÀï¡¢°ÍÈûÂÞÄǵȾãÀÖ²¿ÆµµÀ£¬ £¬£¬£¬£¬£¬£¬Óû§ÂþÑÜÒÔÎ÷°àÑÀ£¨30%£©¡¢Ä«Î÷¸ç£¨13%£©ÎªÖ÷£¬ £¬£¬£¬£¬£¬£¬µÂ¹ú¡¢Òâ´óÀû¡¢ÃÀ¹ú¸÷Õ¼6% ¡£¡£¡£¡£¡£¡£¡£Ö»¹Üδֱ½ÓÌṩDAZNƵµÀ£¬ £¬£¬£¬£¬£¬£¬µ«Æ½Ì¨ÖØÐ·ַ¢ÁËÆäÏàÖúͬ°éÄÚÈÝ£¨ÈçMotoGPºÍF1ÈüÊ£©£¬ £¬£¬£¬£¬£¬£¬×é³ÉÇÖȨ ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹Ø±ÕÔ´ÓÚÅ·ÖÞÐ̾¯×é֯Эµ÷µÄ¿ç¹úÖ´·¨Ðж¯£¬ £¬£¬£¬£¬£¬£¬Ðж¯Öвé·â69¸ö²»·¨ÍøÕ¾£¨Äê»á¼ûÁ¿³¬1180Íò£©£¬ £¬£¬£¬£¬£¬£¬25¸ö²»·¨IPTVЧÀͱ»Òƽ»¼ÓÃÜÇ®±ÒÌṩÉ̲é·â£¬ £¬£¬£¬£¬£¬£¬²é»ñ¼ÛÖµ5500ÍòÃÀÔª¼ÓÃÜÇ®±Ò£¬ £¬£¬£¬£¬£¬£¬²¢Æô¶¯44ÏîÐÂÊÓ²ì ¡£¡£¡£¡£¡£¡£¡£PhotocallÓòÃûÒÑ×ªÒÆÖÁACE²¢Öض¨ÏòÖÁÕýµ±Ô¢Ä¿ÍøÕ¾£¬ £¬£¬£¬£¬£¬£¬ÔËÓªÉÌÔÞ³É×èÖ¹ÔËÓª ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/tv-streaming-piracy-service-photocall-with-26m-yearly-visits-shut-down/


6. SalesforceÓëGainsightÓ¦¶ÔÊý¾ÝÇÔÈ ¡£¡£¡£¡£¡£¡£¡£º×÷·ÏÁîÅÆÒÆ³ýÓ¦ÓÃ


11ÔÂ20ÈÕ£¬ £¬£¬£¬£¬£¬£¬SalesforceÔÚÊÓ²ì¿Í»§Êý¾ÝÇÔÈ¡¹¥»÷ʱ£¬ £¬£¬£¬£¬£¬£¬·¢Ã÷Òì³£» £»£»£»£»î¶¯Ô´ÓÚGainsightÐû²¼µÄÓ¦ÓóÌÐòÓëSalesforceµÄÍⲿÅþÁ¬£¬ £¬£¬£¬£¬£¬£¬¶ø·Ç×ÔÉíCRMƽ̨Îó²î ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑ×÷·ÏËùÓÐÓë¸ÃÓ¦ÓóÌÐò¹ØÁªµÄ»á¼ûÁîÅÆºÍË¢ÐÂÁîÅÆ£¬ £¬£¬£¬£¬£¬£¬²¢ÔÝʱ½«Æä´ÓAppExchangeÒÆ³ý£¬ £¬£¬£¬£¬£¬£¬Í¬Ê±Í¨ÖªÊÜÓ°Ïì¿Í»§²¢Ìṩ×ÊÖú ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÓë2025Äê8ÔÂSalesloftÊý¾Ýй¶ģʽÏàËÆ£¬ £¬£¬£¬£¬£¬£¬ÆäʱÀÕË÷×éÖ¯¡°Scattered Lapsus$ Hunters¡±Ê¹ÓÃÇÔÈ¡µÄOAuthÁîÅÆ£¬ £¬£¬£¬£¬£¬£¬´Ó¿Í»§SalesforceʵÀýÖÐÇÔÈ¡ÁËÃÜÂë¡¢AWSÃÜÔ¿µÈÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÔ¼760¼Ò¹«Ë¾£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂ15ÒÚÌõ¼Í¼й¶£¬ £¬£¬£¬£¬£¬£¬Éæ¼°Google¡¢Cloudflare¡¢Palo Alto NetworksµÈ×ÅÃûÆóÒµ ¡£¡£¡£¡£¡£¡£¡£ShinyHunters×éÖ¯Éù³Æ£¬ £¬£¬£¬£¬£¬£¬Í¨¹ýSalesloft DriftÎó²îÖÐÇÔÈ¡µÄÃÜÔ¿ÈëÇÖGainsightºó£¬ £¬£¬£¬£¬£¬£¬½øÒ»²½»ñÈ¡ÁË285¸öSalesforceʵÀýµÄ»á¼ûȨÏÞ ¡£¡£¡£¡£¡£¡£¡£Gainsight´ËǰÒÑ֤ʵ£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÓëSalesloft Drift¹ØÁªµÄ±»µÁOAuthÁîÅÆÈëÇÖ£¬ £¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÆóÒµÁªÏµÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£SalesforceÇ¿µ÷£¬ £¬£¬£¬£¬£¬£¬ËùÓжñÒâ»î¶¯¾ùÓëÍⲿӦÓóÌÐòÅþÁ¬ÓйØ£¬ £¬£¬£¬£¬£¬£¬¶ø·Çƽ̨×Ô¼ºÎó²î ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/