°Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±

Ðû²¼Ê±¼ä 2025-07-02

1. °Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬°Ä´óÀûÑÇ×î´óº½¿Õ¹«Ë¾°ÄÖÞº½¿Õ¿ËÈÕÅû¶£¬£¬£¬£¬£¬ÆäµÚÈý·½¿Í»§Ð§ÀÍÆ½Ì¨ÔâÓöÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÔ¼600Íò¿Í»§µÄЧÀͼͼÊý¾Ý±»µÁ£¬£¬£¬£¬£¬³ÉΪȫÇòº½¿ÕÒµÍøÂçÇå¾²ÍþвÉý¼¶µÄ×îа¸Àý¡£¡£¡£¡£´Ë´Î¹¥»÷ʼÓÚÍþвÐÐΪÕßÈëÇְĺ½ºô½ÐÖÐÐÄʹÓõĵÚÈý·½Æ½Ì¨£¬£¬£¬£¬£¬¹¥»÷Õß»ñÈ¡Á˰üÀ¨¿Í»§ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¼°³£ÓοͻáÔ±ºÅµÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬µ«Î´Éæ¼°ÐÅÓÿ¨»ò²ÆÎñÊý¾Ý¡£¡£¡£¡£°Äº½ÉùÃ÷³Æ£¬£¬£¬£¬£¬ÏµÍ³ÒÑÔÚ·¢Ã÷Òì³£ºóÁ¬Ã¦¸ôÀ룬£¬£¬£¬£¬²¢ÒÑת´ï°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ¡¢ÐÅϢרԱ°ì¹«ÊÒ¼°Áª°î¾¯Ô±¾ÖÕö¿ªÊӲ졣¡£¡£¡£´Ë´ÎÊÂÎñ̻¶³öº½¿ÕÒµÕý³ÉΪºÚ¿Í×éÖ¯¡°Scattered Spider¡±µÄÖØµãÄ¿µÄ¡£¡£¡£¡£¸Ã×éÖ¯ÒԸ߶ÈЭͬµÄÉç»á¹¤³Ì¹¥»÷ÖøÃû£¬£¬£¬£¬£¬ÉÆÓÚͨ¹ý´¹ÂÚ¡¢SIM¿¨½»Á÷¡¢¶àÒòËØÈÏÖ¤£¨MFA£©ºäÕ¨¼°Ã°³äÔ±¹¤µÈÊÖ¶ÎÇÔÈ¡Æóҵƾ֤¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬Æä¹¥»÷¹æÄ£ÒÑ´ÓÁãÊÛ¡¢°ü¹ÜÐÐÒµÀ©Õ¹ÖÁº½¿ÕÁìÓò£¬£¬£¬£¬£¬ÏÄÍþÒĺ½¿ÕºÍÎ÷½Ýº½¿ÕµÄÊý¾Ýй¶ÊÂÎñ¾ù±»ÏÓÒÉÓëÆäÓйØ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/qantas-discloses-cyberattack-amid-scattered-spider-aviation-breaches/


2. ¹ú¼ÊÐÌÊ·¨ÔºÔâÓöеÄÖØ´óÍøÂç¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬¹ú¼ÊÐÌÊ·¨Ôº£¨ICC£©ÖÜÒ»Åû¶£¬£¬£¬£¬£¬Æäϵͳ¿ËÈÕÔâÓöÐÂÒ»ÂÖ¡°ÖØ´óÇÒÓÐÕë¶ÔÐÔ¡±µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÕâÊǸûú¹¹½üÄêÀ´µÚ¶þ´ÎÔâÊÜÀàËÆÊÂÎñ¡£¡£¡£¡£¾ÝICCÉùÃ÷£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÓÉÆäÄÚ²¿¼à²âϵͳ·¢Ã÷£¬£¬£¬£¬£¬·¨ÔºÑ¸ËÙÆô¶¯Ô¤¾¯ºÍÏìÓ¦»úÖÆ¿ØÖÆÊÂ̬£¬£¬£¬£¬£¬²¢ÒÑÕö¿ªÈ«Ôº¹æÄ£µÄÓ°ÏìÆÀ¹À¼°Î£º¦»º½â²½·¥¡£¡£¡£¡£Ö»¹Ü·¨ÔºÇ¿µ÷ËùÓÐÒªº¦ÏµÍ³ÈÔÇå¾²ÔËÐУ¬£¬£¬£¬£¬µ«ÉÐδÐû²¼¹¥»÷ÏêϸÐÔ×Ó¡¢Ç±ÔÚÊý¾Ýй¶¹æÄ£»ò¹¥»÷ÕßÉí·Ý£¬£¬£¬£¬£¬½öÌåÏÖ½«Ïò¹«ÖÚ¼°µÞÔ¼¹úÒ»Á¬×ª´ïÏ£Íû¡£¡£¡£¡£2023Äê9Ô£¬£¬£¬£¬£¬¸Ã»ú¹¹ÔøÔâÓöÒ»Æð±»¶¨ÐÔΪ¡°ÍøÂçÌØ¹¤Ðж¯¡±µÄÈëÇÖÊÂÎñ¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬¹¥»÷ÕßͨÏ꾡ÃÜÊÖÒÕÊÖ¶ÎÉøÍ¸ÏµÍ³£¬£¬£¬£¬£¬ÊÔͼÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬µ«Î´·¢Ã÷Êý¾Ýй¶»òÌØ¶¨Ìع¤×éÖ¯¼ÓÈëµÄÖ¤¾Ý¡£¡£¡£¡£×÷ΪÈÏÕæÉóѶսÕù×ï¡¢ÖÖ×åÃð¾ø×ïµÈ×îÑÏÖØ¹ú¼Ê×ïÐеÄ˾·¨»ú¹¹£¬£¬£¬£¬£¬ICCµÄÍøÂç·ÀÓùÄÜÁ¦Ö±½Ó¹ØºõÈ«ÇòÐÌÊÂ˾·¨ÏµÍ³ÎȹÌ¡£¡£¡£¡£Æäº£ÑÀ×ܲ¿ÏµÍ³´æ´¢×Å´ó×ÚÉñÃØÊÓ²ìÊý¾Ý¡¢Ö¤ÈËÐÅÏ¢¼°¿ç¹úÏàÖúÎļþ£¬£¬£¬£¬£¬Ò»µ©Ôâй¶¿ÉÄÜΣ¼°Ö¤ÈËÇå¾²¡¢×ÌÈÅÉóѶÀú³Ì£¬£¬£¬£¬£¬ÉõÖÁÒý·¢µØÔµÕþÖÎÁ¬Ëø·´Ó¦¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/international-criminal-court-hit-by-new-sophisticated-cyberattack/


3. Esse HealthÔâÍøÂç¹¥»÷Ö³¬26Íò»¼ÕßÊý¾Ýй¶ 


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÃÜËÕÀïÖÝʥ·Ò×˹ÊÐ×î´ó×ÔÁ¦Ò½Ê¦ÕûÌåEsse Health¿ËÈÕÅû¶£¬£¬£¬£¬£¬Æäϵͳ½ñÄê4ÔÂÔâÓöÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÁè¼Ý26.3ÍòÃû»¼ÕßµÄÃô¸Ð¿µ½¡Êý¾Ý±»µÁ¡£¡£¡£¡£×÷Ϊ´óʥ·Ò×˹µØÇøÓµÓÐ50¼ÒÕïËùºÍ1200ÓàÃûÒ½»¤Ö°Ô±µÄÒ½ÁƾÞÍ·£¬£¬£¬£¬£¬¸Ã»ú¹¹ÔÚ4ÔÂ21ÈÕÊ״μì²âµ½¹¥»÷ÕßÈëÇÖÆä½¹µã»¼ÕßÖÎÀíϵͳ¼°µç»°ÍøÂ磬£¬£¬£¬£¬Ôì³ÉÒªº¦Ð§ÀÍÖÐÖ¹³¤´ïÊýÖÜ£¬£¬£¬£¬£¬Ö±ÖÁ6ÔÂ2ÈÕ²ÅÖÜÈ«»Ö¸´ÏßÉÏЧÀÍ¡£¡£¡£¡£¾ÝEsse HealthÒþ˽¹ÙJaime L. BremerkampÐû²¼µÄ֪ͨ£¬£¬£¬£¬£¬¹¥»÷ÕßÀÖ³ÉÉøÍ¸ÍøÂçºó£¬£¬£¬£¬£¬ÇÔÈ¡Á˰üÀ¨»¼ÕßÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Ò½Áưü¹ÜÐÅÏ¢¡¢Ò½ÁƼͼ±àºÅ¼°²¿·ÖÕïÁƼͼµÄµç×ÓÎļþ£¬£¬£¬£¬£¬µ«É¨³ýÁËÉç»áÇå¾²ºÅÂëй¶Σº¦¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬Æä½¹µãµç×Ó²¡Àúϵͳ£¨NextGen EHR£©Î´ÔÚ´Ë´ÎÊÂÎñÖÐÔâÈëÇÖ¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶¹æÄ£´´Ï¸õØÇøÒ½ÁÆÐÐÒµ½üÄêÖ®×£¬£¬£¬£¬ÊÜÓ°ÏìÈËÊýÏ൱ÓÚÍâµØÃ¿10ÃûסÃñÖоÍÓÐ1ÈËÐÅϢ̻¶¡£¡£¡£¡£Ö»¹ÜEsse HealthδÃ÷È·¹¥»÷ÀàÐÍ£¬£¬£¬£¬£¬µ«ÍøÂçÇ徲ר¼ÒÆÊÎöÖ¸³ö£¬£¬£¬£¬£¬³¤´ïÊýÔµÄϵͳ»Ö¸´ÖÜÆÚÓëµä·¶ÀÕË÷Èí¼þ¹¥»÷ÌØÕ÷¸ß¶ÈÎǺÏ¡£¡£¡£¡£Esse HealthÒÑΪÊÜÓ°ÏìÕßÌṩΪÆÚ°ëÄêµÄÃâ·ÑÉí·Ý¼à¿ØÐ§ÀÍ£¨Í¨¹ýIDXƽ̨£©£¬£¬£¬£¬£¬²¢½¨ÒéÇ×½ü¹Ø×¢Òì³£Ò½ÁÆÕ˵¥¼°ÐÅÓñ¨¸æ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/esse-health-says-recent-data-breach-affects-over-263-000-patients/


4. Kelly Benefits³ÆÊý¾Ýй¶ӰÏì55Íò¿Í»§


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÂíÀïÀ¼ÖÝ¿µ½¡ÓëÈËÊÙ°ü¹Ü¹«Ë¾Kelly & Associates Insurance Group£¨ÉÌÒµÃû³ÆÎªKelly Benefits£©¿ËÈÕÅû¶£¬£¬£¬£¬£¬ÆäITϵͳÓÚ2024Äê12ÔÂ12ÈÕÖÁ17ÈÕʱ´úÔâδÊÚȨÈëÇÖ£¬£¬£¬£¬£¬×îÖÕÈ·Èϳ¬55ÍòÃûÓû§Ð¡ÎÒ˽¼ÒÐÅϢй¶£¬£¬£¬£¬£¬½Ï×î³õ±¨¸æµÄ3.2ÍòÈ˼¤Ôö17±¶¡£¡£¡£¡£´Ë´ÎÊÂÎñÉæ¼°46¼ÒÏàÖúʵÌ壬£¬£¬£¬£¬°üÀ¨ÁªºÏ¿µ½¡°ü¹Ü¡¢°²ÀÖÈËÊÙ£¨CVS Health£©¡¢CareFirst BlueCross BlueShieldµÈÒ½ÁÆÐÐÒµ¾ÞÍ·£¬£¬£¬£¬£¬Ì»Â¶³ö°ü¹ÜЧÀ͹©Ó¦Á´µÄųÈõÐÔ¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾4ÔÂ9ÈÕ¸üеÄÊÓ²ìЧ¹û£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÎļþ°üÀ¨È«Ãû¡¢Éç»áÇå¾²ºÅÂ롢˰ºÅ¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼͼ¡¢°ü¹ÜÐÅÏ¢¼°½ðÈÚÕË»§µÈ½¹µãÃô¸ÐÊý¾Ý¡£¡£¡£¡£ÕâÀàÐÅÏ¢µÄ×éºÏ¼«¾ß¼ÛÖµ£¬£¬£¬£¬£¬¿ÉʹÊܺ¦ÕßÃæÁÙÍøÂç´¹ÂÚ¡¢Éç»á¹¤³ÌÕ©Æ­¼°¾«×¼½ðÈÚڲƭµÄ¶àÖØÎ£º¦¡£¡£¡£¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬£¬£¬£¬£¬Êý¾Ýй¶¹æÄ£¾­Óɶà´ÎÐÞÕý£¬£¬£¬£¬£¬Í¹ÏÔÖØ´óЧÀÍÍøÂçÏÂÈ·¶¨Ó°Ïì¹æÄ£µÄÄѶÈ¡£¡£¡£¡£×÷ΪÌṩ¸£Àû×Éѯ¡¢Ð½³êÖÎÀí¡¢ÈËÁ¦×ÊԴϵͳ¼°ºÏ¹æÖ§³ÖµÄ×ÛºÏÐÔЧÀÍÉÌ£¬£¬£¬£¬£¬Kelly BenefitsµÄÌìÏÂÐÔÓªÒµÍøÂçµ¼ÖÂÊý¾Ý×·×ÙºÄʱÊýÔ¡£¡£¡£¡£¸Ã¹«Ë¾Í¨¹ýIDXƽ̨ΪËùÓÐÊÜÓ°ÏìÕßÌṩ12¸öÔÂÃâ·ÑÐÅÓÃ¼à¿ØÓëÉí·ÝµÁÓñ£»£»£»£»£»¤Ð§ÀÍ£¬£¬£¬£¬£¬²¢½¨ÒéÓû§½ÓÄÉÇå¾²¶³½áÐÅÓñ¨¸æ¡¢ÆôÓÃÕË»§»î¶¯ÌáÐѵȷÀÓù²½·¥¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kelly-benefits-says-2024-data-breach-impacts-550-000-customers/


5. ChromeÁãÈÕÎó²îCVE-2025-6554Ôâ×Ô¶¯¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬¹È¸è¿ËÈÕÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬Ðû²¼ÐÞ¸´Chromeä¯ÀÀÆ÷ÖÐÒ»¸öÒѱ»ÆÕ±éʹÓõÄÁãÈÕÎó²î£¨CVE-2025-6554£©¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚChromeµÄV8 JavaScriptÓëWebAssemblyÒýÇæÖУ¬£¬£¬£¬£¬ÊôÓڵ䷶µÄÀàÐÍ»ìÏýȱÏÝ£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ýÈ«ÐĽṹµÄ¶ñÒâÍøÒ³Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬Òý·¢³ÌÐò±ÀÀ£»£»£»£»£»òÊý¾ÝÇÔÈ¡¡£¡£¡£¡£´ËÀàÎó²îµÄÁãÈÕÌØÕ÷ÓÈΪΣÏÕ£¬£¬£¬£¬£¬¹¥»÷ÕßÍùÍùÔÚ²¹¶¡Ðû²¼Ç°¾ÍÒÑ·¢¶¯¾«×¼¹¥»÷£¬£¬£¬£¬£¬Óû§½öÐè»á¼û¶ñÒâÍøÕ¾¼´¿ÉÄܱ»Ö²ÈëÌØ¹¤Èí¼þ»òÀÕË÷³ÌÐò¡£¡£¡£¡£¹È¸èÍþвÆÊÎöС×飨TAG£©Ñо¿Ô±Cl¨¦ment LecigneÓÚ6ÔÂ25ÈÕÊ״μà²âµ½Òì³£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬ÌåÏÖ¸ÃÎó²î¿ÉÄܱ»ÓÃÓÚ¹ú¼Ò¼¶ÍøÂçÌØ¹¤Ðж¯¡£¡£¡£¡£Ö»¹Ü¹È¸èδÐû²¼Îó²îʹÓÃϸ½Ú£¬£¬£¬£¬£¬µ«ÈÏ¿ÉÆäÒѱ»¡°ÆÕ±éʹÓᱡ£¡£¡£¡£´Ë´ÎÐÞ¸´Í¨¹ýÍÆËÍÎȹ̰æÍ¨µÀ¸üÐÂÍê³É£¬£¬£¬£¬£¬WindowsÓû§ÐèÉý¼¶ÖÁ138.0.7204.96/97£¬£¬£¬£¬£¬macOSÓû§¸üÐÂÖÁ138.0.7204.92/93£¬£¬£¬£¬£¬LinuxÓû§Í¬²½ÖÁ138.0.7204.96°æ±¾¡£¡£¡£¡£ÆóÒµIT²¿·ÖÐèÌØÊâ¹Ø×¢Öն˺ϹæÐÔÖÎÀí£¬£¬£¬£¬£¬×èÖ¹Òò°æ±¾Öͺóµ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£


https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html


6. ÈðÊ¿·ÇÓªÀû×éÖ¯RadixÔâÀÕË÷Èí¼þ¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬ÈðÊ¿ËÕÀèÊÀ·ÇÓªÀû¿µ½¡»ù½ð»áRadix½üÆÚÔâÓöÑÏÖØÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ÃûΪSarcomaµÄºÚ¿Í×éÖ¯ÒÑÔÚÆä°µÍøÆ½Ì¨¹ûÕæ1.3TBÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬Òý·¢ÈðÊ¿Áª°î»ú¹¹Êý¾ÝÇå¾²¾¯±¨¡£¡£¡£¡£´Ë´ÎÊÂÎñ̻¶ÁË·ÇÕþ¸®×éÖ¯×÷ΪµÚÈý·½Ð§ÀÍÉ̵ÄÍøÂçÇå¾²±¡Èõ»·½Ú£¬£¬£¬£¬£¬Æä¿Í»§º­¸Ç¶à¸öÁª°î²¿·Ö£¬£¬£¬£¬£¬Ö»¹ÜÈðÊ¿¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ç¿µ÷Áª°î½¹µãÐÐÕþϵͳδ±»Í»ÆÆ£¬£¬£¬£¬£¬µ«ÍâйÊý¾Ý¿ÉÄܰüÀ¨¹«Ãñ¿µ½¡ÐÅÏ¢¡¢²¿·ÖЭ×÷¼Í¼µÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£RadixϵͳÓÚ2025Äê6ÔÂ16ÈÕÔâÈëÇÖ£¬£¬£¬£¬£¬¹¥»÷Õß½ÓÄÉË«ÖØÀÕË÷Õ½ÂÔ£ºÏÈÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬ÔÙ¼ÓÃÜϵͳË÷ÒªÊê½ð¡£¡£¡£¡£Òò»ú¹¹¾Ü¾øÖ§¸¶£¬£¬£¬£¬£¬ºÚ¿ÍÓÚ6ÔÂ29ÈÕÆô¶¯Êý¾ÝÇãµ¹£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúй¶ÎļþÊÇ·ñ°üÀ¨¼ÓÃÜÃÜÔ¿»òÄÚ²¿Í¨Ñ¶¼Í¼¡£¡£¡£¡£RadixËäÉù³Æ¡°ÎÞ¼£ÏóÅú×¢ÏàÖúͬ°éÃô¸ÐÊý¾ÝÊÜÓ°Ï족£¬£¬£¬£¬£¬µ«ÆäЧÀ͹æÄ£ÁýÕÖ¿µ½¡½ÌÓý¡¢Õþ²ßÍÆ¹ãµÈÁìÓò£¬£¬£¬£¬£¬Ç±ÔÚй¶Êý¾Ý»òÉæ¼°¿ç²¿·ÖÏîĿϸ½Ú¡£¡£¡£¡£Ä¿½ñ£¬£¬£¬£¬£¬1.3TBÍâйÊý¾ÝµÄÕæÊµÐÔÓëÍêÕûÐÔÉÐδ»ñµÃRadixÈ·ÈÏ£¬£¬£¬£¬£¬µ«Sarcoma×éÖ¯ÒÑÐû²¼²¿·ÖÎļþĿ¼½ØÍ¼£¬£¬£¬£¬£¬°üÀ¨±ê×¢¡°Áª°îÎÀÉú²¿¡±¡¢¡°Éç±£»£»£»£»£»ù½ð¡±µÈ×ÖÑùµÄÎļþ¼Ð¡£¡£¡£¡£


https://cybernews.com/security/radix-cyberattack-exposes-swiss-federal-data/