°Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±

Ðû²¼Ê±¼ä 2025-07-02

1. °Äº½¿Í»§Êý¾Ýй¶ÊÂÎñÇ£³öScattered Spider×éÖ¯º½¿ÕÒµ¹¥»÷³±


7ÔÂ1ÈÕ£¬£¬£¬°Ä´óÀûÑÇ×î´óº½¿Õ¹«Ë¾°ÄÖÞº½¿Õ¿ËÈÕÅû¶£¬£¬£¬ÆäµÚÈý·½¿Í»§Ð§ÀÍÆ½Ì¨ÔâÓöÍøÂç¹¥»÷£¬£¬£¬µ¼ÖÂÔ¼600Íò¿Í»§µÄЧÀͼͼÊý¾Ý±»µÁ£¬£¬£¬³ÉΪȫÇòº½¿ÕÒµÍøÂçÇå¾²ÍþвÉý¼¶µÄ×îа¸Àý¡£¡£¡£´Ë´Î¹¥»÷ʼÓÚÍþвÐÐΪÕßÈëÇְĺ½ºô½ÐÖÐÐÄʹÓõĵÚÈý·½Æ½Ì¨£¬£¬£¬¹¥»÷Õß»ñÈ¡Á˰üÀ¨¿Í»§ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¼°³£ÓοͻáÔ±ºÅµÈÃô¸ÐÐÅÏ¢£¬£¬£¬µ«Î´Éæ¼°ÐÅÓÿ¨»ò²ÆÎñÊý¾Ý¡£¡£¡£°Äº½ÉùÃ÷³Æ£¬£¬£¬ÏµÍ³ÒÑÔÚ·¢Ã÷Òì³£ºóÁ¬Ã¦¸ôÀ룬£¬£¬²¢ÒÑת´ï°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ¡¢ÐÅϢרԱ°ì¹«ÊÒ¼°Áª°î¾¯Ô±¾ÖÕö¿ªÊӲ졣¡£¡£´Ë´ÎÊÂÎñ̻¶³öº½¿ÕÒµÕý³ÉΪºÚ¿Í×éÖ¯¡°Scattered Spider¡±µÄÖØµãÄ¿µÄ¡£¡£¡£¸Ã×éÖ¯ÒԸ߶ÈЭͬµÄÉç»á¹¤³Ì¹¥»÷ÖøÃû£¬£¬£¬ÉÆÓÚͨ¹ý´¹ÂÚ¡¢SIM¿¨½»Á÷¡¢¶àÒòËØÈÏÖ¤£¨MFA£©ºäÕ¨¼°Ã°³äÔ±¹¤µÈÊÖ¶ÎÇÔÈ¡Æóҵƾ֤¡£¡£¡£½üÆÚ£¬£¬£¬Æä¹¥»÷¹æÄ£ÒÑ´ÓÁãÊÛ¡¢°ü¹ÜÐÐÒµÀ©Õ¹ÖÁº½¿ÕÁìÓò£¬£¬£¬ÏÄÍþÒĺ½¿ÕºÍÎ÷½Ýº½¿ÕµÄÊý¾Ýй¶ÊÂÎñ¾ù±»ÏÓÒÉÓëÆäÓйØ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/qantas-discloses-cyberattack-amid-scattered-spider-aviation-breaches/


2. ¹ú¼ÊÐÌÊ·¨ÔºÔâÓöеÄÖØ´óÍøÂç¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬¹ú¼ÊÐÌÊ·¨Ôº£¨ICC£©ÖÜÒ»Åû¶£¬£¬£¬Æäϵͳ¿ËÈÕÔâÓöÐÂÒ»ÂÖ¡°ÖØ´óÇÒÓÐÕë¶ÔÐÔ¡±µÄÍøÂç¹¥»÷£¬£¬£¬ÕâÊǸûú¹¹½üÄêÀ´µÚ¶þ´ÎÔâÊÜÀàËÆÊÂÎñ¡£¡£¡£¾ÝICCÉùÃ÷£¬£¬£¬´Ë´Î¹¥»÷ÓÉÆäÄÚ²¿¼à²âϵͳ·¢Ã÷£¬£¬£¬·¨ÔºÑ¸ËÙÆô¶¯Ô¤¾¯ºÍÏìÓ¦»úÖÆ¿ØÖÆÊÂ̬£¬£¬£¬²¢ÒÑÕö¿ªÈ«Ôº¹æÄ£µÄÓ°ÏìÆÀ¹À¼°Î£º¦»º½â²½·¥¡£¡£¡£Ö»¹Ü·¨ÔºÇ¿µ÷ËùÓÐÒªº¦ÏµÍ³ÈÔÇå¾²ÔËÐУ¬£¬£¬µ«ÉÐδÐû²¼¹¥»÷ÏêϸÐÔ×Ó¡¢Ç±ÔÚÊý¾Ýй¶¹æÄ£»ò¹¥»÷ÕßÉí·Ý£¬£¬£¬½öÌåÏÖ½«Ïò¹«ÖÚ¼°µÞÔ¼¹úÒ»Á¬×ª´ïÏ£Íû¡£¡£¡£2023Äê9Ô£¬£¬£¬¸Ã»ú¹¹ÔøÔâÓöÒ»Æð±»¶¨ÐÔΪ¡°ÍøÂçÌØ¹¤Ðж¯¡±µÄÈëÇÖÊÂÎñ¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬¹¥»÷ÕßͨÏ꾡ÃÜÊÖÒÕÊÖ¶ÎÉøÍ¸ÏµÍ³£¬£¬£¬ÊÔͼÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬µ«Î´·¢Ã÷Êý¾Ýй¶»òÌØ¶¨Ìع¤×éÖ¯¼ÓÈëµÄÖ¤¾Ý¡£¡£¡£×÷ΪÈÏÕæÉóѶսÕù×ï¡¢ÖÖ×åÃð¾ø×ïµÈ×îÑÏÖØ¹ú¼Ê×ïÐеÄ˾·¨»ú¹¹£¬£¬£¬ICCµÄÍøÂç·ÀÓùÄÜÁ¦Ö±½Ó¹ØºõÈ«ÇòÐÌÊÂ˾·¨ÏµÍ³ÎȹÌ¡£¡£¡£Æäº£ÑÀ×ܲ¿ÏµÍ³´æ´¢×Å´ó×ÚÉñÃØÊÓ²ìÊý¾Ý¡¢Ö¤ÈËÐÅÏ¢¼°¿ç¹úÏàÖúÎļþ£¬£¬£¬Ò»µ©Ôâй¶¿ÉÄÜΣ¼°Ö¤ÈËÇå¾²¡¢×ÌÈÅÉóѶÀú³Ì£¬£¬£¬ÉõÖÁÒý·¢µØÔµÕþÖÎÁ¬Ëø·´Ó¦¡£¡£¡£


https://www.bleepingcomputer.com/news/security/international-criminal-court-hit-by-new-sophisticated-cyberattack/


3. Esse HealthÔâÍøÂç¹¥»÷Ö³¬26Íò»¼ÕßÊý¾Ýй¶ 


7ÔÂ1ÈÕ£¬£¬£¬ÃÀ¹úÃÜËÕÀïÖÝʥ·Ò×˹ÊÐ×î´ó×ÔÁ¦Ò½Ê¦ÕûÌåEsse Health¿ËÈÕÅû¶£¬£¬£¬Æäϵͳ½ñÄê4ÔÂÔâÓöÍøÂç¹¥»÷£¬£¬£¬µ¼ÖÂÁè¼Ý26.3ÍòÃû»¼ÕßµÄÃô¸Ð¿µ½¡Êý¾Ý±»µÁ¡£¡£¡£×÷Ϊ´óʥ·Ò×˹µØÇøÓµÓÐ50¼ÒÕïËùºÍ1200ÓàÃûÒ½»¤Ö°Ô±µÄÒ½ÁƾÞÍ·£¬£¬£¬¸Ã»ú¹¹ÔÚ4ÔÂ21ÈÕÊ״μì²âµ½¹¥»÷ÕßÈëÇÖÆä½¹µã»¼ÕßÖÎÀíϵͳ¼°µç»°ÍøÂ磬£¬£¬Ôì³ÉÒªº¦Ð§ÀÍÖÐÖ¹³¤´ïÊýÖÜ£¬£¬£¬Ö±ÖÁ6ÔÂ2ÈÕ²ÅÖÜÈ«»Ö¸´ÏßÉÏЧÀÍ¡£¡£¡£¾ÝEsse HealthÒþ˽¹ÙJaime L. BremerkampÐû²¼µÄ֪ͨ£¬£¬£¬¹¥»÷ÕßÀÖ³ÉÉøÍ¸ÍøÂçºó£¬£¬£¬ÇÔÈ¡Á˰üÀ¨»¼ÕßÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Ò½Áưü¹ÜÐÅÏ¢¡¢Ò½ÁƼͼ±àºÅ¼°²¿·ÖÕïÁƼͼµÄµç×ÓÎļþ£¬£¬£¬µ«É¨³ýÁËÉç»áÇå¾²ºÅÂëй¶Σº¦¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬Æä½¹µãµç×Ó²¡Àúϵͳ£¨NextGen EHR£©Î´ÔÚ´Ë´ÎÊÂÎñÖÐÔâÈëÇÖ¡£¡£¡£´Ë´ÎÊý¾Ýй¶¹æÄ£´´Ï¸õØÇøÒ½ÁÆÐÐÒµ½üÄêÖ®×£¬£¬ÊÜÓ°ÏìÈËÊýÏ൱ÓÚÍâµØÃ¿10ÃûסÃñÖоÍÓÐ1ÈËÐÅϢ̻¶¡£¡£¡£Ö»¹ÜEsse HealthδÃ÷È·¹¥»÷ÀàÐÍ£¬£¬£¬µ«ÍøÂçÇ徲ר¼ÒÆÊÎöÖ¸³ö£¬£¬£¬³¤´ïÊýÔµÄϵͳ»Ö¸´ÖÜÆÚÓëµä·¶ÀÕË÷Èí¼þ¹¥»÷ÌØÕ÷¸ß¶ÈÎǺÏ¡£¡£¡£Esse HealthÒÑΪÊÜÓ°ÏìÕßÌṩΪÆÚ°ëÄêµÄÃâ·ÑÉí·Ý¼à¿ØÐ§ÀÍ£¨Í¨¹ýIDXƽ̨£©£¬£¬£¬²¢½¨ÒéÇ×½ü¹Ø×¢Òì³£Ò½ÁÆÕ˵¥¼°ÐÅÓñ¨¸æ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/esse-health-says-recent-data-breach-affects-over-263-000-patients/


4. Kelly Benefits³ÆÊý¾Ýй¶ӰÏì55Íò¿Í»§


7ÔÂ1ÈÕ£¬£¬£¬ÃÀ¹úÂíÀïÀ¼ÖÝ¿µ½¡ÓëÈËÊÙ°ü¹Ü¹«Ë¾Kelly & Associates Insurance Group£¨ÉÌÒµÃû³ÆÎªKelly Benefits£©¿ËÈÕÅû¶£¬£¬£¬ÆäITϵͳÓÚ2024Äê12ÔÂ12ÈÕÖÁ17ÈÕʱ´úÔâδÊÚȨÈëÇÖ£¬£¬£¬×îÖÕÈ·Èϳ¬55ÍòÃûÓû§Ð¡ÎÒ˽¼ÒÐÅϢй¶£¬£¬£¬½Ï×î³õ±¨¸æµÄ3.2ÍòÈ˼¤Ôö17±¶¡£¡£¡£´Ë´ÎÊÂÎñÉæ¼°46¼ÒÏàÖúʵÌ壬£¬£¬°üÀ¨ÁªºÏ¿µ½¡°ü¹Ü¡¢°²ÀÖÈËÊÙ£¨CVS Health£©¡¢CareFirst BlueCross BlueShieldµÈÒ½ÁÆÐÐÒµ¾ÞÍ·£¬£¬£¬Ì»Â¶³ö°ü¹ÜЧÀ͹©Ó¦Á´µÄųÈõÐÔ¡£¡£¡£¾Ý¸Ã¹«Ë¾4ÔÂ9ÈÕ¸üеÄÊÓ²ìЧ¹û£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÎļþ°üÀ¨È«Ãû¡¢Éç»áÇå¾²ºÅÂ롢˰ºÅ¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼͼ¡¢°ü¹ÜÐÅÏ¢¼°½ðÈÚÕË»§µÈ½¹µãÃô¸ÐÊý¾Ý¡£¡£¡£ÕâÀàÐÅÏ¢µÄ×éºÏ¼«¾ß¼ÛÖµ£¬£¬£¬¿ÉʹÊܺ¦ÕßÃæÁÙÍøÂç´¹ÂÚ¡¢Éç»á¹¤³ÌÕ©Æ­¼°¾«×¼½ðÈÚڲƭµÄ¶àÖØÎ£º¦¡£¡£¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬£¬£¬Êý¾Ýй¶¹æÄ£¾­Óɶà´ÎÐÞÕý£¬£¬£¬Í¹ÏÔÖØ´óЧÀÍÍøÂçÏÂÈ·¶¨Ó°Ïì¹æÄ£µÄÄѶÈ¡£¡£¡£×÷ΪÌṩ¸£Àû×Éѯ¡¢Ð½³êÖÎÀí¡¢ÈËÁ¦×ÊԴϵͳ¼°ºÏ¹æÖ§³ÖµÄ×ÛºÏÐÔЧÀÍÉÌ£¬£¬£¬Kelly BenefitsµÄÌìÏÂÐÔÓªÒµÍøÂçµ¼ÖÂÊý¾Ý×·×ÙºÄʱÊýÔ¡£¡£¡£¸Ã¹«Ë¾Í¨¹ýIDXƽ̨ΪËùÓÐÊÜÓ°ÏìÕßÌṩ12¸öÔÂÃâ·ÑÐÅÓÃ¼à¿ØÓëÉí·ÝµÁÓñ£»£»£»£»¤Ð§ÀÍ£¬£¬£¬²¢½¨ÒéÓû§½ÓÄÉÇå¾²¶³½áÐÅÓñ¨¸æ¡¢ÆôÓÃÕË»§»î¶¯ÌáÐѵȷÀÓù²½·¥¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kelly-benefits-says-2024-data-breach-impacts-550-000-customers/


5. ChromeÁãÈÕÎó²îCVE-2025-6554Ôâ×Ô¶¯¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬¹È¸è¿ËÈÕÐû²¼Ç徲ͨ¸æ£¬£¬£¬Ðû²¼ÐÞ¸´Chromeä¯ÀÀÆ÷ÖÐÒ»¸öÒѱ»ÆÕ±éʹÓõÄÁãÈÕÎó²î£¨CVE-2025-6554£©¡£¡£¡£¸ÃÎó²î±£´æÓÚChromeµÄV8 JavaScriptÓëWebAssemblyÒýÇæÖУ¬£¬£¬ÊôÓڵ䷶µÄÀàÐÍ»ìÏýȱÏÝ£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ýÈ«ÐĽṹµÄ¶ñÒâÍøÒ³Ö´ÐÐí§Òâ´úÂ룬£¬£¬Òý·¢³ÌÐò±ÀÀ£»£»£»£»òÊý¾ÝÇÔÈ¡¡£¡£¡£´ËÀàÎó²îµÄÁãÈÕÌØÕ÷ÓÈΪΣÏÕ£¬£¬£¬¹¥»÷ÕßÍùÍùÔÚ²¹¶¡Ðû²¼Ç°¾ÍÒÑ·¢¶¯¾«×¼¹¥»÷£¬£¬£¬Óû§½öÐè»á¼û¶ñÒâÍøÕ¾¼´¿ÉÄܱ»Ö²ÈëÌØ¹¤Èí¼þ»òÀÕË÷³ÌÐò¡£¡£¡£¹È¸èÍþвÆÊÎöС×飨TAG£©Ñо¿Ô±Cl¨¦ment LecigneÓÚ6ÔÂ25ÈÕÊ״μà²âµ½Òì³£»£»£»£»î¶¯£¬£¬£¬ÌåÏÖ¸ÃÎó²î¿ÉÄܱ»ÓÃÓÚ¹ú¼Ò¼¶ÍøÂçÌØ¹¤Ðж¯¡£¡£¡£Ö»¹Ü¹È¸èδÐû²¼Îó²îʹÓÃϸ½Ú£¬£¬£¬µ«ÈÏ¿ÉÆäÒѱ»¡°ÆÕ±éʹÓᱡ£¡£¡£´Ë´ÎÐÞ¸´Í¨¹ýÍÆËÍÎȹ̰æÍ¨µÀ¸üÐÂÍê³É£¬£¬£¬WindowsÓû§ÐèÉý¼¶ÖÁ138.0.7204.96/97£¬£¬£¬macOSÓû§¸üÐÂÖÁ138.0.7204.92/93£¬£¬£¬LinuxÓû§Í¬²½ÖÁ138.0.7204.96°æ±¾¡£¡£¡£ÆóÒµIT²¿·ÖÐèÌØÊâ¹Ø×¢Öն˺ϹæÐÔÖÎÀí£¬£¬£¬×èÖ¹Òò°æ±¾Öͺóµ¼ÖÂÊý¾Ýй¶¡£¡£¡£


https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html


6. ÈðÊ¿·ÇÓªÀû×éÖ¯RadixÔâÀÕË÷Èí¼þ¹¥»÷


7ÔÂ1ÈÕ£¬£¬£¬ÈðÊ¿ËÕÀèÊÀ·ÇÓªÀû¿µ½¡»ù½ð»áRadix½üÆÚÔâÓöÑÏÖØÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ÃûΪSarcomaµÄºÚ¿Í×éÖ¯ÒÑÔÚÆä°µÍøÆ½Ì¨¹ûÕæ1.3TBÇÔÈ¡Êý¾Ý£¬£¬£¬Òý·¢ÈðÊ¿Áª°î»ú¹¹Êý¾ÝÇå¾²¾¯±¨¡£¡£¡£´Ë´ÎÊÂÎñ̻¶ÁË·ÇÕþ¸®×éÖ¯×÷ΪµÚÈý·½Ð§ÀÍÉ̵ÄÍøÂçÇå¾²±¡Èõ»·½Ú£¬£¬£¬Æä¿Í»§º­¸Ç¶à¸öÁª°î²¿·Ö£¬£¬£¬Ö»¹ÜÈðÊ¿¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ç¿µ÷Áª°î½¹µãÐÐÕþϵͳδ±»Í»ÆÆ£¬£¬£¬µ«ÍâйÊý¾Ý¿ÉÄܰüÀ¨¹«Ãñ¿µ½¡ÐÅÏ¢¡¢²¿·ÖЭ×÷¼Í¼µÈÃô¸ÐÄÚÈÝ¡£¡£¡£RadixϵͳÓÚ2025Äê6ÔÂ16ÈÕÔâÈëÇÖ£¬£¬£¬¹¥»÷Õß½ÓÄÉË«ÖØÀÕË÷Õ½ÂÔ£ºÏÈÇÔÈ¡Êý¾Ý£¬£¬£¬ÔÙ¼ÓÃÜϵͳË÷ÒªÊê½ð¡£¡£¡£Òò»ú¹¹¾Ü¾øÖ§¸¶£¬£¬£¬ºÚ¿ÍÓÚ6ÔÂ29ÈÕÆô¶¯Êý¾ÝÇãµ¹£¬£¬£¬ÏÖÔÚÉв»ÇåÎúй¶ÎļþÊÇ·ñ°üÀ¨¼ÓÃÜÃÜÔ¿»òÄÚ²¿Í¨Ñ¶¼Í¼¡£¡£¡£RadixËäÉù³Æ¡°ÎÞ¼£ÏóÅú×¢ÏàÖúͬ°éÃô¸ÐÊý¾ÝÊÜÓ°Ï족£¬£¬£¬µ«ÆäЧÀ͹æÄ£ÁýÕÖ¿µ½¡½ÌÓý¡¢Õþ²ßÍÆ¹ãµÈÁìÓò£¬£¬£¬Ç±ÔÚй¶Êý¾Ý»òÉæ¼°¿ç²¿·ÖÏîĿϸ½Ú¡£¡£¡£Ä¿½ñ£¬£¬£¬1.3TBÍâйÊý¾ÝµÄÕæÊµÐÔÓëÍêÕûÐÔÉÐδ»ñµÃRadixÈ·ÈÏ£¬£¬£¬µ«Sarcoma×éÖ¯ÒÑÐû²¼²¿·ÖÎļþĿ¼½ØÍ¼£¬£¬£¬°üÀ¨±ê×¢¡°Áª°îÎÀÉú²¿¡±¡¢¡°Éç±£»£»£»£»ù½ð¡±µÈ×ÖÑùµÄÎļþ¼Ð¡£¡£¡£


https://cybernews.com/security/radix-cyberattack-exposes-swiss-federal-data/