¸¥¼ªÄáÑÇÈý½ÇÖÞÑÀ¿Æ±£ÏÕÊý¾Ýй¶²¨¼°14.6ÍòÈË
°ä²¼¹¦·ò 2025-11-261. ¸¥¼ªÄáÑÇÈý½ÇÖÞÑÀ¿Æ±£ÏÕÊý¾Ýй¶²¨¼°14.6ÍòÈË
11ÔÂ24ÈÕ£¬£¬£¬¸¥¼ªÄáÑÇÖÝÈý½ÇÖÞÑÀ¿Æ±£ÏÕ¹«Ë¾£¨DDVA£©½üÈÕÅû¶£¬£¬£¬ÆäÔ¼14.6ÍòÃû¿Í»§µÄСÎÒ¼°½¡¿µÐÅÏ¢ÔÚ2025Äê3ÔÂ21ÈÕÖÁ4ÔÂ23ÈÕÆÚ¼äµÄÊý¾Ýй¶ÊÂÎñÖÐÔâÇÔÈ¡¡£¡£Æ¾¾ÝDDVAÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄ֪ͨÐÅ£¬£¬£¬Õâ´ÎÊÂÎñÔ´ÓÚÆäµç×ÓÓʼþÕË»§±»·¸·¨½Ó¼û£¬£¬£¬ÍþвÐÐΪÕß¿ÉÄÜÇÔÈ¡ÁËÔ̺¬»¼ÕßÊý¾ÝµÄµç×ÓÓʼþ¼°¸½¼þ¡£¡£Ð¹Â¶ÐÅÏ¢Éæ¼°Ãô¸ÐСÎÒÊý¾Ý£¬£¬£¬Ô̺¬ÐÕÃû¡¢¡¢Éç»á±£ÏÕºÅÂë¡¢¡¢µ±¾ÖÐû¸æµÄÉí·ÝÖ¤ºÅÂëÒÔ¼°Êܱ£»£»¤µÄ½¡¿µÐÅÏ¢£¨ÈçÒ½ÁƼͼµÈ£©¡£¡£¾¶ÀÁ¢ÍøÂ簲ȫר¼ÒÐÖúµ÷²éÈ·ÈÏ£¬£¬£¬¹²ÓÐ145,918ÈËÊÜÓ°Ï죬£¬£¬DDVAÒѽ«ÊÂÎñÏêÇé´«µÝ¼à¹Ü»ú¹¹¡£¡£Ö»¹ÜĿǰÉÐÎÞÖ¤¾ÝÅú×¢±»µÁÐÅÏ¢Òѱ»ÀÄÓûò´æÔÚÀÄÓÃ̰ͼ£¬£¬£¬µ«¸Ã¹«Ë¾ÈÔΪËùÓÐй¶Éç»á±£ÏÕºÅÂë»ò¼ÝÊ»ÅÆÕÕÐÅÏ¢µÄСÎÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÉí·Ý±£»£»¤¼°ÐÅÓþ¼à¿Ø·þÎñ¡£¡£
https://www.securityweek.com/146000-impacted-by-delta-dental-of-virginia-data-breach/
2. ÃÀ¸ÖÆó¿âçêÔâÀÕË÷¹¥»÷£¬£¬£¬330GBÖ÷ÌâÊý¾Ý±»ÊÛ
11ÔÂ24ÈÕ£¬£¬£¬½üÈÕ£¬£¬£¬ÍþвÐÐΪÕßÐû³ÆÒÑÈëÇÖÃÀ¹úÒ»¼¶½á¹¹¸ÖÖÆ×÷¾ÞÍ·¿âçê¸ÖÌúÖÆ×÷¹«Ë¾£¨Cooper Steel Fabricators£©£¬£¬£¬²¢½«¸Ã¹«Ë¾FTP·þÎñÆ÷µÄ¡°ÆëÈ«¾µÏñÊý¾Ý¡±ÒÔ2.85ÍòÃÀÔª¼ÓÃÜÇ®±ÒÀÕË÷ÏúÊÛ¡£¡£¾Ý°µÍøÌûÎÄÅû¶£¬£¬£¬±»µÁÊý¾Ý×ÜÁ¿´ï330GB£¬£¬£¬Ô̺¬¡°ÎÞÈκÎɾ³ý»òÎÞ¹ØÎļþ¡±µÄ¸ß¶È¾ßÌå¼¼ÊõÎĵµ¡¢¡¢×¨ÓÐÏîÄ¿ÐÅÏ¢¼°¹ýÍù/ÔÚÑÐÏîÖ÷ÕŸ÷ÀàÄ£ÐÍ¡¢¡¢¿ò¼ÜͼºÍÉè¼ÆÍ¼Ö½¡£¡£¾ßÌåÉæ¼°ÏîÄ¿Ô̺¬£º£º£º2022Äê¿¢¹¤µÄÆÕ²¼Àû¿Ë˹¸ñÁÖ˹²®ÀÕÀ䲨ÅäËÍÖÐÐÄÈ«Ì×ÐͬÉè¼ÆÍ¼Ö½£¨º¸Ç¹¹Öþ¡¢¡¢½á¹¹¡¢¡¢»úе¼°ÖÆÀä¹ÜµÀϵͳ£©£»£»ÑÇÂíÑ·¶íº¥¶íÖÝÊý¾ÝÖÐÐÄ£¨±ð³Æ¡°ÆßÒ¶Ê÷ÖÝ¡±ÊýÊ®×ùÊý¾ÝÖÐÐÄÖ®Ò»£©µÄ½á¹¹¹æ¸ñ²ÎÊý£»£»ÂíÈøÖîÈûÖÝÑÇÂíÑ··Ö¼ðÖÐÐĵĸֽṹʩ¹¤ÐÅÏ¢£»£»ÒÔ¼°ÎÖ¶ûÂêÅäËÍÖÐÐÄ¡¢¡¢À䲨²Ö´¢ÉèÊ©µÈÅäÌ×¹¹ÖþµÄÉè¼ÆÍ¼Ö½Óë3DÄ£ÐÍ¡£¡£Õâ´ÎÊÂÎñÖУ¬£¬£¬ÍþвÐÐΪÕßÇ¿µ÷Êý¾Ý¡°ÆëÈ«¾µÏñ¡±¸öÐÔ£¬£¬£¬ÊÔͼͨ¹ýй¶Ãô¸ÐÏîĿϸ½ÚʩѹÆóÒµÖ§¸¶Êê½ð¡£¡£
https://cybernews.com/security/cooper-steel-fabrication-data-breach-amazon/
3. Crisis24ÔâÍøÂç¹¥»÷Ö´¹Î£Í¨ÖªÏµÍ³Ì±»¾
11ÔÂ25ÈÕ£¬£¬£¬·çÏÕÖÎÀí¹«Ë¾Crisis24֤ʵÆäOnSolve CodeREDƽ̨ÔâÍøÂç¹¥»÷£¬£¬£¬µ¼ÖÂÃÀ¹ú¶àµØÖݵ±¾Ö¡¢¡¢¾¯Ïû»ú¹¹´¹Î£Í¨ÖªÏµÍ³Ì±»¾¡£¡£¸ÃÆ½Ì¨ÕÆ¹ÜÔÚ´¹Î£Çé¿öÏÂÏò¾ÓÃñ·¢Ë;¯±¨£¬£¬£¬Õâ´Î¹¥»÷ÆÈʹCrisis24Í£Óô«Í³»·¾³£¬£¬£¬Ôì³É´¹Î£Í¨Öª¡¢¡¢ÆøÏ󾯱¨µÈÖ°ÄÜÖжϡ£¡£µ÷²éÏÔʾ£¬£¬£¬¹¥»÷½öÓ°ÏìCodeRED»·¾³£¬£¬£¬Î´²¨¼°ÆäËûϵͳ£¬£¬£¬µ«Æ½Ì¨Êý¾ÝÔâÇÔ£¬£¬£¬Ô̺¬Óû§ÐÕÃû¡¢¡¢µØÖ·¡¢¡¢ÓÊÏä¡¢¡¢µç»°¼°ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£Crisis24Ç¿µ÷δ·¢ÏÖ±»µÁÊý¾Ý±»¹«¿ª£¬£¬£¬µ«µÂ¿ËÈøË¹ÖÝ´óѧ³ÇµÈ»ú¹¹ÖÒ¸æ´æÔÚÊý¾Ýй¶·çÏÕ¡£¡£Îª¸´Ô·þÎñ£¬£¬£¬Crisis24Õý½«2025Äê3ÔÂ31Èյı¸·ÝÊý¾ÝǨáãÖÁÐÂϵͳ£¬£¬£¬µ«²¿ÃÅÕË»§¿ÉÄÜȱʧ¡£¡£È«¹ú¶àµØ¹«¹²°²È«»ú¹¹»ã±¨ÖжÏÊÂÎñ£¬£¬£¬²¢»ý¼«¸´Ô¾¯±¨ÏµÍ³¡£¡£ÀÕË÷×éÖ¯INCÐû³Æ¶Ô´ËÕÆ¹Ü£¬£¬£¬ÆäTorÊý¾ÝÐ¹Â¶ÍøÕ¾ÏÔʾ£¬£¬£¬¸ÃÍÅ»ïÓÚ11ÔÂ1ÈÕÈëÇÖϵͳ£¬£¬£¬11ÔÂ10ÈÕ¼ÓÃÜÎļþ£¬£¬£¬Òòδ»ñÊê½ðת¶øÏúÊÛÊý¾Ý¡£¡£½ØÍ¼ÏÔʾ¿Í»§Êý¾Ýº¬Ã÷ÎÄÃÜÂ룬£¬£¬×¨¼Ò½¨ÒéÓû§Á¢¼´ÖØÖ÷´¸´Ê¹ÓõÄÃÜÂë¡£¡£
https://www.bleepingcomputer.com/news/security/onsolve-codered-cyberattack-disrupts-emergency-alert-systems-nationwide/
4. FlexibleFerret¶ñÒâÈí¼þÁ´ÀûÓÃGoºóÃŹ¥»÷macOS
11ÔÂ25ÈÕ£¬£¬£¬¾ÝJamf Threat Labs×îÐÂÅû¶£¬£¬£¬Ò»ÖÖÐÂÐÍmacOS¶ñÒâÈí¼þÁ´Õýͨ¹ý¶È½×¶Î¾ç±¾¡¢¡¢Æ¾Ö¤ÇÔÈ¡µö¶üºÍ»ùÓÚGoµÄÓÆ¾ÃºóÃÅ£¬£¬£¬ÈƹýÓû§°²È«´ëʩʵÏÖ³Ö¾Ãϵͳ½Ó¼û¡£¡£¸Ã¹¥»÷Á´Ô̺¬Èý½×¶Î²Ù×÷£º£º£ºµÚ¶þ½×¶Îshell¾ç±¾Æ¾¾ÝϵͳоƬÀàÐÍ£¨arm64»òIntel£©¶¯Ì¬»ñÈ¡ÓÐÐ§ÔØºÉ£¬£¬£¬Öؽ¨ÏÂÔØõè¾¶ºó½âѹÖÁһʱĿ¼²¢ºó¶ÜÆô¶¯£»£»Í¨¹ý´´½¨LaunchAgentʵÏֵǼʱ×Ô¶¯¼ÓÔØ£¬£¬£¬Í¬Ê±¼Ù×°ChromeȨÏÞÌáÐѵ¯´°£¬£¬£¬ÓÕµ¼Óû§ÊäÈëÍ´´¦ºóͨ¹ýÆ´½ÓDropboxÖ÷»úµØÖ·Ë鯬£¬£¬£¬ÀûÓúϷ¨APIÉÏ´«ÖÁÖ¸¶¨ÕË»§£¬£¬£¬²¢²éÎÊapi.ipify.org»ñÈ¡Êܺ¦Õß¹«ÍøIP¡£¡£µÚÈý½×¶ÎÆô¶¯ÃûΪCDriversµÄGo˵»°ºóÃÅ£¬£¬£¬ÌìÉúΨһ»úе±êʶ·ûÏνÓÓ²±àÂëºÅÁî·þÎñÆ÷£¬£¬£¬½øÈëÓÆ¾ÃÑ»·Ö´ÐÐϵͳÐÅÏ¢ÍøÂç¡¢¡¢ÎļþÉÏ´«ÏÂÔØ¡¢¡¢ShellºÅÁîÖ´ÐС¢¡¢ChromeÅäÖÃÎļþÌáÈ¡¼°×Ô¶¯Æ¾Ö¤ÇÔÈ¡µÈ¹¤×÷¡£¡£ÈôÓöÃýÎ󣬣¬£¬¶ñÒâÈí¼þ»á»ØÍËÖ´ÐÐϵͳÐÅÏ¢ºÅÁî²¢ÔÝÍ£Îå·ÖÖÓÔÙ¸´Ô£¬£¬£¬Ô¤·Àµ¥µã¹ÊÕϵ¼Ö²Ù×÷Öжϡ£¡£Jamf½«Õâ´Î¹¥»÷¹éÒòÓÚFlexibleFerretÔËÓªÉÌ£¬£¬£¬¸Ã×éÖ¯³ÖÐø¸Ä½øµö¶üÉè¼Æ£¬£¬£¬ÓÕʹָ±êÊÖ¶¯ÔËÐо籾¡£¡£
https://www.infosecurity-magazine.com/news/flexibleferret-malware-macos-go/
5. ÔÚÏß´úÂ빤¾ß¡°×î½üÁ´½Ó¡±Ö°ÄÜй¶³¬8ÍòÌõÃô¸ÐÊý¾Ý
11ÔÂ25ÈÕ£¬£¬£¬¾ÝÍøÂ簲ȫ×êÑÐÈËÔ±Åû¶£¬£¬£¬ÔÚÏß´úÂëÌåʽ»¯¹¤¾ßJSONFormatterºÍCodeBeautifyµÄ¡°×î½üÁ´½Ó¡±Ö°ÄÜÒò´æÔÚ¹«¿ª¿É½Ó¼û·ì϶£¬£¬£¬µ¼Ö³¬¹ý8ÍòÌõÓû§Õ³ÌùÄÚÈÝ£¨×ܼƳ¬5GB£©±»Ð¹Â¶£¬£¬£¬Éæ¼°µ±¾Ö¡¢¡¢¹Ø¼ü»ù´¡ÉèÊ©¡¢¡¢ÒøÐС¢¡¢±£ÏÕ¡¢¡¢º½¿Õº½Ìì¡¢¡¢Ò½ÁƱ£½¡¡¢¡¢½ÌÓý¡¢¡¢ÍøÂ簲ȫ¡¢¡¢µçÐŵȸ߷çÏÕÐÐÒµ¡£¡£ÕâЩÊý¾ÝÔ̺¬Active DirectoryÍ´´¦¡¢¡¢Êý¾Ý¿âºÍÔÆÆ¾Ö¤¡¢¡¢Ë½Ô¿¡¢¡¢´úÂë¿âÁîÅÆ¡¢¡¢CI/CD·¨ÃÅ¡¢¡¢Ö§¸¶Íø¹ØÃÜÔ¿¡¢¡¢APIÁîÅÆ¡¢¡¢SSH»á»°Â¼ÖƼ°´óÁ¿Ð¡ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍKYCÊý¾ÝµÈÃô¸ÐÐÅÏ¢¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬ÕâÁ½¸öƽ̨µÄ¡°×î½üÁ´½Ó¡±Ö°ÄÜÔÊÐíÓû§½Ó¼û±£ÁôÔÚ·þÎñ·þÎñÆ÷ÉϵÄJSONƬ¶Î£¬£¬£¬µã»÷¡°±£Áô¡±°´Å¥ºó£¬£¬£¬Æ½Ì¨»áÌìÉúÒ»¸öΨһURL²¢Ôö³¤µ½Óû§µÄ¡°×î½üÁ´½Ó¡±Ò³ÃæÖС£¡£ÓÉÓÚ¸ÃÒ³ÃæÃ»ÓÐÈκα£»£»¤²ã£¬£¬£¬ÇÒURL×ñѽṹ»¯¡¢¡¢¿ÉÔ¤²âµÄÌåʽ£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýµ¥Ò»ÅÀ³æ·¨Ê½ÇáËɼìË÷URL²¢ÌáÈ¡ÔʼÊý¾Ý¡£¡£×êÑл¹·¢ÏÖ£¬£¬£¬ÍþвÐÐΪÕßÒÑÆðͷɨÃ蹫¿ª¿É½Ó¼ûµÄJSONÊý¾Ý¡£¡£
https://www.bleepingcomputer.com/news/security/code-beautifiers-expose-credentials-from-banks-govt-tech-orgs/
6. ´ïÌØÃ©Ë¹Ñ§ÔºÔâClopÍÅ»ïÁãÈÕ¹¥»÷ÖÂ1494ÈËÊý¾Ýй¶
11ÔÂ25ÈÕ£¬£¬£¬ÃÀ¹ú´ïÌØÃ©Ë¹Ñ§ÔºÅûÂ¶ÖØ´óÊý¾Ýй¶ÊÂÎñ£º£º£ºClopÀÕË÷ÍÅ»ïͨ¹ý°µÍøÐ¹Â¶¸ÃУOracle E-Business Suite·þÎñÆ÷ÇÔÈ¡µÄÃô¸ÐÊý¾Ý£¬£¬£¬Éæ¼°1494ÃûʦÉú¼°Ð£ÓѵÄÐÕÃû¡¢¡¢Éç»á±£ÏÕºÅÂë¼°²ÆÕþÕË»§ÐÅÏ¢¡£¡£¾µ÷²é£¬£¬£¬¹¥»÷ÕßÀûÓÃCVE-2025-61882ÁãÈÕ·ì϶£¬£¬£¬ÓÚ8ÔÂ9ÈÕÖÁ12ÈÕÆÚ¼äÇÔÈ¡Îļþ£¬£¬£¬Ñ§ÔºÔÚ10ÔÂ30ÈÕÈ·ÈÏÊý¾ÝÔ̺¬Ð¡ÎÒÃô¸ÐÐÅÏ¢²¢Æô¶¯Í¨Öª·¨Ê½¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬¸ÃУËäÏòÃåÒòÖÝ×ܼì²ì³¤ÌύΥ¹æ»ã±¨£¬£¬£¬µ«Î´Ïò×ܲ¿µØµãµÄк±²¼Ê²¶ûÖÝÌá½»£¬£¬£¬ÏÖʵÊÜÓ°ÏìÈËÊý¿ÉÄÜÔ¶³¬1494ÈË¡£¡£Õâ´ÎÊÂÎñÊÇClopÍÅ»ïÕë¶ÔOracle EBSƽ̨µÄ´ó¹æÄ£¹¥»÷µÄÒ»²¿ÃÅ¡£¡£×Ô2025Äê8ÔÂÆð£¬£¬£¬¸ÃÍÅ»ïÒÑÀûÓÃͳһ·ì϶ÈëÇÖÊýÊ®¼Ò»ú¹¹£¬£¬£¬Ô̺¬¹þ·ð´óѧ¡¢¡¢¡¶»ªÊ¢¶ÙÓʱ¨¡·¡¢¡¢ÂÞ¼¼¡¢¡¢GlobalLogic¼°ÃÀ¹úº½¿Õ¹«Ë¾×Ó¹«Ë¾Envoy Air£¬£¬£¬ÓйØÊý¾ÝÒÑͨ¹ýTorrent¹«¿ªÏÂÔØ¡£¡£
https://www.bleepingcomputer.com/news/security/dartmouth-college-confirms-data-breach-after-clop-extortion-attack/


¾©¹«Íø°²±¸11010802024551ºÅ