°Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±

Ðû²¼Ê±¼ä 2025-07-02

1. °Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬°Ä´óÀûÑÇ×î´óº½¿Õ¹«Ë¾°ÄÖÞº½¿Õ¿ËÈÕÅû¶£¬£¬£¬£¬£¬£¬ÆäµÚÈý·½¿Í»§Ð§ÀÍÆ½Ì¨ÔâÓöÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼600Íò¿Í»§µÄЧÀͼͼÊý¾Ý±»µÁ£¬£¬£¬£¬£¬£¬³ÉΪȫÇòº½¿ÕÒµÍøÂçÇå¾²ÍþвÉý¼¶µÄ×îа¸Àý¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ʼÓÚÍþвÐÐΪÕßÈëÇְĺ½ºô½ÐÖÐÐÄʹÓõĵÚÈý·½Æ½Ì¨£¬£¬£¬£¬£¬£¬¹¥»÷Õß»ñÈ¡Á˰üÀ¨¿Í»§ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¼°³£ÓοͻáÔ±ºÅµÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬µ«Î´Éæ¼°ÐÅÓÿ¨»ò²ÆÎñÊý¾Ý¡£¡£¡£¡£¡£°Äº½ÉùÃ÷³Æ£¬£¬£¬£¬£¬£¬ÏµÍ³ÒÑÔÚ·¢Ã÷Òì³£ºóÁ¬Ã¦¸ôÀ룬£¬£¬£¬£¬£¬²¢ÒÑת´ï°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ¡¢ÐÅϢרԱ°ì¹«ÊÒ¼°Áª°î¾¯Ô±¾ÖÕö¿ªÊӲ졣¡£¡£¡£¡£´Ë´ÎÊÂÎñ̻¶³öº½¿ÕÒµÕý³ÉΪºÚ¿Í×éÖ¯¡°Scattered Spider¡±µÄÖØµãÄ¿µÄ¡£¡£¡£¡£¡£¸Ã×éÖ¯ÒԸ߶ÈЭͬµÄÉç»á¹¤³Ì¹¥»÷ÖøÃû£¬£¬£¬£¬£¬£¬ÉÆÓÚͨ¹ý´¹ÂÚ¡¢SIM¿¨½»Á÷¡¢¶àÒòËØÈÏÖ¤£¨MFA£©ºäÕ¨¼°Ã°³äÔ±¹¤µÈÊÖ¶ÎÇÔÈ¡Æóҵƾ֤¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬£¬Æä¹¥»÷¹æÄ£ÒÑ´ÓÁãÊÛ¡¢°ü¹ÜÐÐÒµÀ©Õ¹ÖÁº½¿ÕÁìÓò£¬£¬£¬£¬£¬£¬ÏÄÍþÒĺ½¿ÕºÍÎ÷½Ýº½¿ÕµÄÊý¾Ýй¶ÊÂÎñ¾ù±»ÏÓÒÉÓëÆäÓйØ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/qantas-discloses-cyberattack-amid-scattered-spider-aviation-breaches/


2. ¹ú¼ÊÐÌÊ·¨ÔºÔâÓöеÄÖØ´óÍøÂç¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬¹ú¼ÊÐÌÊ·¨Ôº£¨ICC£©ÖÜÒ»Åû¶£¬£¬£¬£¬£¬£¬Æäϵͳ¿ËÈÕÔâÓöÐÂÒ»ÂÖ¡°ÖØ´óÇÒÓÐÕë¶ÔÐÔ¡±µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ÕâÊǸûú¹¹½üÄêÀ´µÚ¶þ´ÎÔâÊÜÀàËÆÊÂÎñ¡£¡£¡£¡£¡£¾ÝICCÉùÃ÷£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÓÉÆäÄÚ²¿¼à²âϵͳ·¢Ã÷£¬£¬£¬£¬£¬£¬·¨ÔºÑ¸ËÙÆô¶¯Ô¤¾¯ºÍÏìÓ¦»úÖÆ¿ØÖÆÊÂ̬£¬£¬£¬£¬£¬£¬²¢ÒÑÕö¿ªÈ«Ôº¹æÄ£µÄÓ°ÏìÆÀ¹À¼°Î£º¦»º½â²½·¥¡£¡£¡£¡£¡£Ö»¹Ü·¨ÔºÇ¿µ÷ËùÓÐÒªº¦ÏµÍ³ÈÔÇå¾²ÔËÐУ¬£¬£¬£¬£¬£¬µ«ÉÐδÐû²¼¹¥»÷ÏêϸÐÔ×Ó¡¢Ç±ÔÚÊý¾Ýй¶¹æÄ£»ò¹¥»÷ÕßÉí·Ý£¬£¬£¬£¬£¬£¬½öÌåÏÖ½«Ïò¹«ÖÚ¼°µÞÔ¼¹úÒ»Á¬×ª´ïÏ£Íû¡£¡£¡£¡£¡£2023Äê9Ô£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹ÔøÔâÓöÒ»Æð±»¶¨ÐÔΪ¡°ÍøÂçÌØ¹¤Ðж¯¡±µÄÈëÇÖÊÂÎñ¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßͨÏ꾡ÃÜÊÖÒÕÊÖ¶ÎÉøÍ¸ÏµÍ³£¬£¬£¬£¬£¬£¬ÊÔͼÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬µ«Î´·¢Ã÷Êý¾Ýй¶»òÌØ¶¨Ìع¤×éÖ¯¼ÓÈëµÄÖ¤¾Ý¡£¡£¡£¡£¡£×÷ΪÈÏÕæÉóѶսÕù×ï¡¢ÖÖ×åÃð¾ø×ïµÈ×îÑÏÖØ¹ú¼Ê×ïÐеÄ˾·¨»ú¹¹£¬£¬£¬£¬£¬£¬ICCµÄÍøÂç·ÀÓùÄÜÁ¦Ö±½Ó¹ØºõÈ«ÇòÐÌÊÂ˾·¨ÏµÍ³ÎȹÌ¡£¡£¡£¡£¡£Æäº£ÑÀ×ܲ¿ÏµÍ³´æ´¢×Å´ó×ÚÉñÃØÊÓ²ìÊý¾Ý¡¢Ö¤ÈËÐÅÏ¢¼°¿ç¹úÏàÖúÎļþ£¬£¬£¬£¬£¬£¬Ò»µ©Ôâй¶¿ÉÄÜΣ¼°Ö¤ÈËÇå¾²¡¢×ÌÈÅÉóѶÀú³Ì£¬£¬£¬£¬£¬£¬ÉõÖÁÒý·¢µØÔµÕþÖÎÁ¬Ëø·´Ó¦¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/international-criminal-court-hit-by-new-sophisticated-cyberattack/


3. Esse HealthÔâÍøÂç¹¥»÷Ö³¬26Íò»¼ÕßÊý¾Ýй¶ 


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÃÜËÕÀïÖÝʥ·Ò×˹ÊÐ×î´ó×ÔÁ¦Ò½Ê¦ÕûÌåEsse Health¿ËÈÕÅû¶£¬£¬£¬£¬£¬£¬Æäϵͳ½ñÄê4ÔÂÔâÓöÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÁè¼Ý26.3ÍòÃû»¼ÕßµÄÃô¸Ð¿µ½¡Êý¾Ý±»µÁ¡£¡£¡£¡£¡£×÷Ϊ´óʥ·Ò×˹µØÇøÓµÓÐ50¼ÒÕïËùºÍ1200ÓàÃûÒ½»¤Ö°Ô±µÄÒ½ÁƾÞÍ·£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹ÔÚ4ÔÂ21ÈÕÊ״μì²âµ½¹¥»÷ÕßÈëÇÖÆä½¹µã»¼ÕßÖÎÀíϵͳ¼°µç»°ÍøÂ磬£¬£¬£¬£¬£¬Ôì³ÉÒªº¦Ð§ÀÍÖÐÖ¹³¤´ïÊýÖÜ£¬£¬£¬£¬£¬£¬Ö±ÖÁ6ÔÂ2ÈÕ²ÅÖÜÈ«»Ö¸´ÏßÉÏЧÀÍ¡£¡£¡£¡£¡£¾ÝEsse HealthÒþ˽¹ÙJaime L. BremerkampÐû²¼µÄ֪ͨ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀÖ³ÉÉøÍ¸ÍøÂçºó£¬£¬£¬£¬£¬£¬ÇÔÈ¡Á˰üÀ¨»¼ÕßÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Ò½Áưü¹ÜÐÅÏ¢¡¢Ò½ÁƼͼ±àºÅ¼°²¿·ÖÕïÁƼͼµÄµç×ÓÎļþ£¬£¬£¬£¬£¬£¬µ«É¨³ýÁËÉç»áÇå¾²ºÅÂëй¶Σº¦¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬Æä½¹µãµç×Ó²¡Àúϵͳ£¨NextGen EHR£©Î´ÔÚ´Ë´ÎÊÂÎñÖÐÔâÈëÇÖ¡£¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶¹æÄ£´´Ï¸õØÇøÒ½ÁÆÐÐÒµ½üÄêÖ®×£¬£¬£¬£¬£¬ÊÜÓ°ÏìÈËÊýÏ൱ÓÚÍâµØÃ¿10ÃûסÃñÖоÍÓÐ1ÈËÐÅϢ̻¶¡£¡£¡£¡£¡£Ö»¹ÜEsse HealthδÃ÷È·¹¥»÷ÀàÐÍ£¬£¬£¬£¬£¬£¬µ«ÍøÂçÇ徲ר¼ÒÆÊÎöÖ¸³ö£¬£¬£¬£¬£¬£¬³¤´ïÊýÔµÄϵͳ»Ö¸´ÖÜÆÚÓëµä·¶ÀÕË÷Èí¼þ¹¥»÷ÌØÕ÷¸ß¶ÈÎǺÏ¡£¡£¡£¡£¡£Esse HealthÒÑΪÊÜÓ°ÏìÕßÌṩΪÆÚ°ëÄêµÄÃâ·ÑÉí·Ý¼à¿ØÐ§ÀÍ£¨Í¨¹ýIDXƽ̨£©£¬£¬£¬£¬£¬£¬²¢½¨ÒéÇ×½ü¹Ø×¢Òì³£Ò½ÁÆÕ˵¥¼°ÐÅÓñ¨¸æ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/esse-health-says-recent-data-breach-affects-over-263-000-patients/


4. Kelly Benefits³ÆÊý¾Ýй¶ӰÏì55Íò¿Í»§


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÂíÀïÀ¼ÖÝ¿µ½¡ÓëÈËÊÙ°ü¹Ü¹«Ë¾Kelly & Associates Insurance Group£¨ÉÌÒµÃû³ÆÎªKelly Benefits£©¿ËÈÕÅû¶£¬£¬£¬£¬£¬£¬ÆäITϵͳÓÚ2024Äê12ÔÂ12ÈÕÖÁ17ÈÕʱ´úÔâδÊÚȨÈëÇÖ£¬£¬£¬£¬£¬£¬×îÖÕÈ·Èϳ¬55ÍòÃûÓû§Ð¡ÎÒ˽¼ÒÐÅϢй¶£¬£¬£¬£¬£¬£¬½Ï×î³õ±¨¸æµÄ3.2ÍòÈ˼¤Ôö17±¶¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÉæ¼°46¼ÒÏàÖúʵÌ壬£¬£¬£¬£¬£¬°üÀ¨ÁªºÏ¿µ½¡°ü¹Ü¡¢°²ÀÖÈËÊÙ£¨CVS Health£©¡¢CareFirst BlueCross BlueShieldµÈÒ½ÁÆÐÐÒµ¾ÞÍ·£¬£¬£¬£¬£¬£¬Ì»Â¶³ö°ü¹ÜЧÀ͹©Ó¦Á´µÄųÈõÐÔ¡£¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾4ÔÂ9ÈÕ¸üеÄÊÓ²ìЧ¹û£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÎļþ°üÀ¨È«Ãû¡¢Éç»áÇå¾²ºÅÂ롢˰ºÅ¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼͼ¡¢°ü¹ÜÐÅÏ¢¼°½ðÈÚÕË»§µÈ½¹µãÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ÕâÀàÐÅÏ¢µÄ×éºÏ¼«¾ß¼ÛÖµ£¬£¬£¬£¬£¬£¬¿ÉʹÊܺ¦ÕßÃæÁÙÍøÂç´¹ÂÚ¡¢Éç»á¹¤³ÌÕ©Æ­¼°¾«×¼½ðÈÚڲƭµÄ¶àÖØÎ£º¦¡£¡£¡£¡£¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬£¬£¬£¬£¬£¬Êý¾Ýй¶¹æÄ£¾­Óɶà´ÎÐÞÕý£¬£¬£¬£¬£¬£¬Í¹ÏÔÖØ´óЧÀÍÍøÂçÏÂÈ·¶¨Ó°Ïì¹æÄ£µÄÄѶÈ¡£¡£¡£¡£¡£×÷ΪÌṩ¸£Àû×Éѯ¡¢Ð½³êÖÎÀí¡¢ÈËÁ¦×ÊԴϵͳ¼°ºÏ¹æÖ§³ÖµÄ×ÛºÏÐÔЧÀÍÉÌ£¬£¬£¬£¬£¬£¬Kelly BenefitsµÄÌìÏÂÐÔÓªÒµÍøÂçµ¼ÖÂÊý¾Ý×·×ÙºÄʱÊýÔ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Í¨¹ýIDXƽ̨ΪËùÓÐÊÜÓ°ÏìÕßÌṩ12¸öÔÂÃâ·ÑÐÅÓÃ¼à¿ØÓëÉí·ÝµÁÓñ£»£»£»£»£»£»¤Ð§ÀÍ£¬£¬£¬£¬£¬£¬²¢½¨ÒéÓû§½ÓÄÉÇå¾²¶³½áÐÅÓñ¨¸æ¡¢ÆôÓÃÕË»§»î¶¯ÌáÐѵȷÀÓù²½·¥¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kelly-benefits-says-2024-data-breach-impacts-550-000-customers/


5. ChromeÁãÈÕÎó²îCVE-2025-6554Ôâ×Ô¶¯¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬¹È¸è¿ËÈÕÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬Ðû²¼ÐÞ¸´Chromeä¯ÀÀÆ÷ÖÐÒ»¸öÒѱ»ÆÕ±éʹÓõÄÁãÈÕÎó²î£¨CVE-2025-6554£©¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚChromeµÄV8 JavaScriptÓëWebAssemblyÒýÇæÖУ¬£¬£¬£¬£¬£¬ÊôÓڵ䷶µÄÀàÐÍ»ìÏýȱÏÝ£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ýÈ«ÐĽṹµÄ¶ñÒâÍøÒ³Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬Òý·¢³ÌÐò±ÀÀ£»£»£»£»£»£»òÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£´ËÀàÎó²îµÄÁãÈÕÌØÕ÷ÓÈΪΣÏÕ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÍùÍùÔÚ²¹¶¡Ðû²¼Ç°¾ÍÒÑ·¢¶¯¾«×¼¹¥»÷£¬£¬£¬£¬£¬£¬Óû§½öÐè»á¼û¶ñÒâÍøÕ¾¼´¿ÉÄܱ»Ö²ÈëÌØ¹¤Èí¼þ»òÀÕË÷³ÌÐò¡£¡£¡£¡£¡£¹È¸èÍþвÆÊÎöС×飨TAG£©Ñо¿Ô±Cl¨¦ment LecigneÓÚ6ÔÂ25ÈÕÊ״μà²âµ½Òì³£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬ÌåÏÖ¸ÃÎó²î¿ÉÄܱ»ÓÃÓÚ¹ú¼Ò¼¶ÍøÂçÌØ¹¤Ðж¯¡£¡£¡£¡£¡£Ö»¹Ü¹È¸èδÐû²¼Îó²îʹÓÃϸ½Ú£¬£¬£¬£¬£¬£¬µ«ÈÏ¿ÉÆäÒѱ»¡°ÆÕ±éʹÓᱡ£¡£¡£¡£¡£´Ë´ÎÐÞ¸´Í¨¹ýÍÆËÍÎȹ̰æÍ¨µÀ¸üÐÂÍê³É£¬£¬£¬£¬£¬£¬WindowsÓû§ÐèÉý¼¶ÖÁ138.0.7204.96/97£¬£¬£¬£¬£¬£¬macOSÓû§¸üÐÂÖÁ138.0.7204.92/93£¬£¬£¬£¬£¬£¬LinuxÓû§Í¬²½ÖÁ138.0.7204.96°æ±¾¡£¡£¡£¡£¡£ÆóÒµIT²¿·ÖÐèÌØÊâ¹Ø×¢Öն˺ϹæÐÔÖÎÀí£¬£¬£¬£¬£¬£¬×èÖ¹Òò°æ±¾Öͺóµ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¡£


https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html


6. ÈðÊ¿·ÇÓªÀû×éÖ¯RadixÔâÀÕË÷Èí¼þ¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ÈðÊ¿ËÕÀèÊÀ·ÇÓªÀû¿µ½¡»ù½ð»áRadix½üÆÚÔâÓöÑÏÖØÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬ÃûΪSarcomaµÄºÚ¿Í×éÖ¯ÒÑÔÚÆä°µÍøÆ½Ì¨¹ûÕæ1.3TBÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬Òý·¢ÈðÊ¿Áª°î»ú¹¹Êý¾ÝÇå¾²¾¯±¨¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ̻¶ÁË·ÇÕþ¸®×éÖ¯×÷ΪµÚÈý·½Ð§ÀÍÉ̵ÄÍøÂçÇå¾²±¡Èõ»·½Ú£¬£¬£¬£¬£¬£¬Æä¿Í»§º­¸Ç¶à¸öÁª°î²¿·Ö£¬£¬£¬£¬£¬£¬Ö»¹ÜÈðÊ¿¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ç¿µ÷Áª°î½¹µãÐÐÕþϵͳδ±»Í»ÆÆ£¬£¬£¬£¬£¬£¬µ«ÍâйÊý¾Ý¿ÉÄܰüÀ¨¹«Ãñ¿µ½¡ÐÅÏ¢¡¢²¿·ÖЭ×÷¼Í¼µÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£¡£RadixϵͳÓÚ2025Äê6ÔÂ16ÈÕÔâÈëÇÖ£¬£¬£¬£¬£¬£¬¹¥»÷Õß½ÓÄÉË«ÖØÀÕË÷Õ½ÂÔ£ºÏÈÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬ÔÙ¼ÓÃÜϵͳË÷ÒªÊê½ð¡£¡£¡£¡£¡£Òò»ú¹¹¾Ü¾øÖ§¸¶£¬£¬£¬£¬£¬£¬ºÚ¿ÍÓÚ6ÔÂ29ÈÕÆô¶¯Êý¾ÝÇãµ¹£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúй¶ÎļþÊÇ·ñ°üÀ¨¼ÓÃÜÃÜÔ¿»òÄÚ²¿Í¨Ñ¶¼Í¼¡£¡£¡£¡£¡£RadixËäÉù³Æ¡°ÎÞ¼£ÏóÅú×¢ÏàÖúͬ°éÃô¸ÐÊý¾ÝÊÜÓ°Ï족£¬£¬£¬£¬£¬£¬µ«ÆäЧÀ͹æÄ£ÁýÕÖ¿µ½¡½ÌÓý¡¢Õþ²ßÍÆ¹ãµÈÁìÓò£¬£¬£¬£¬£¬£¬Ç±ÔÚй¶Êý¾Ý»òÉæ¼°¿ç²¿·ÖÏîĿϸ½Ú¡£¡£¡£¡£¡£Ä¿½ñ£¬£¬£¬£¬£¬£¬1.3TBÍâйÊý¾ÝµÄÕæÊµÐÔÓëÍêÕûÐÔÉÐδ»ñµÃRadixÈ·ÈÏ£¬£¬£¬£¬£¬£¬µ«Sarcoma×éÖ¯ÒÑÐû²¼²¿·ÖÎļþĿ¼½ØÍ¼£¬£¬£¬£¬£¬£¬°üÀ¨±ê×¢¡°Áª°îÎÀÉú²¿¡±¡¢¡°Éç±£»£»£»£»£»£»ù½ð¡±µÈ×ÖÑùµÄÎļþ¼Ð¡£¡£¡£¡£¡£


https://cybernews.com/security/radix-cyberattack-exposes-swiss-federal-data/