NASCARÈ·ÈÏÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶
Ðû²¼Ê±¼ä 2025-07-291. NASCARÈ·ÈÏÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶
7ÔÂ26ÈÕ£¬£¬£¬×÷Ϊһ¸ö½¨ÉèÓÚ1948ÄêµÄ»ú¹¹£¬£¬£¬ÃÀ¹úÌìÏÂÈü³µÐ»á£¨NASCAR£©Ã¿ÄêÔÚÃÀ¹ú¾ÙÐÐÁè¼Ý1,500³¡½ÇÖ𣬣¬£¬ÊÇÈ«Çò×ÅÃûµÄÆû³µÈüÊÂÖÎÀí»ú¹¹¡£¡£¡£¡£¡£2025Äê3ÔÂ31ÈÕÖÁ4ÔÂ3ÈÕʱ´ú£¬£¬£¬NASCARÔâÊÜÁËÒ»´ÎÑÏÖØµÄÍøÂç¹¥»÷£¬£¬£¬µ¼Ö²¿·ÖÎļþ±»Î´¾ÊÚȨµÄ¹¥»÷Õß»ñÈ¡¡£¡£¡£¡£¡£4ÔÂ3ÈÕ£¬£¬£¬NASCARµÄITÍŶӷ¢Ã÷ÁË´Ë´ÎÈëÇÖ£¬£¬£¬²¢Ëæ¼´Õö¿ªÊӲ죬£¬£¬Í¬Ê±Í¨ÖªÁËÖ´·¨²¿·Ö²¢Ô¼ÇëÁËÒ»¼ÒÍøÂçÇå¾²¹«Ë¾ÐÖúÆÊÎö¡£¡£¡£¡£¡£ÊÓ²ìЧ¹ûÏÔʾ£¬£¬£¬¹¥»÷ÕßÀÖ³ÉÇÔÈ¡ÁË´æ´¢ÔÚ¹«Ë¾ÍøÂçÖеÄijЩÎļþ¡£¡£¡£¡£¡£Ö±µ½6ÔÂÏÂÑ®£¬£¬£¬NASCAR²ÅÈ·ÈÏÕâЩÎļþÖаüÀ¨Óû§µÄСÎÒ˽¼ÒÃô¸ÐÐÅÏ¢£¬£¬£¬ÓÈÆäÊÇÉç»á°ü¹ÜºÅÂë¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬¹«Ë¾²¢Î´Í¸Â¶ÏêϸÊÜÓ°ÏìµÄÈËÊý¡£¡£¡£¡£¡£ 7ÔÂ24ÈÕ£¬£¬£¬NASCARÏòÊܺ¦Õß·¢ËÍÁËÊý¾Ýй¶֪ͨÐÅ£¬£¬£¬²¢ÌṩÁËΪÆÚÒ»ÄêµÄÐÅÓÃ¼à¿ØÐ§ÀÍ×÷Ϊµ÷½â²½·¥¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ÔçÔÚ4Ô£¬£¬£¬MedusaÀÕË÷Èí¼þÍÅ»ïÒѽ«NASCARÁÐÈëÆäÐ¹Â¶ÍøÕ¾Ãûµ¥£¬£¬£¬ÒªÇóÖ§¸¶400ÍòÃÀÔªÊê½ð£¬£¬£¬²¢Éù³ÆÇÔÈ¡ÁË´ó×Ú¹«Ë¾Êý¾Ý¡£¡£¡£¡£¡£Ö»¹ÜÉ趨ÁË4ÔÂ19ÈÕµÄ×îºóÏÞÆÚ£¬£¬£¬µ«Éв»ÇåÎúÕâЩÊý¾ÝÊÇ·ñ×îÖÕ±»¹ûÕæ¡£¡£¡£¡£¡£
https://therecord.media/nascar-confirms-data-breach
2. ÎÚ¿ËÀ¼ºÚ¿ÍÈëÇÖ¶íº½£¬£¬£¬ÖÂ40Óà´Îº½°à×÷·Ï
7ÔÂ28ÈÕ£¬£¬£¬¶íÂÞ˹¹ú¼Òº½¿Õ¹«Ë¾¶íº½£¨Aeroflot£©ÒòÔâÓöÇ×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯"ĬȻÎÚÑ»"Óë°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓµÄÁªºÏÍøÂç¹¥»÷£¬£¬£¬±»ÆÈ×÷·Ï40Óà¼Ü´Îº½°à£¬£¬£¬²¢µ¼ÖÂÊýÊ®¼Üº½°àÑÓÎ󣬣¬£¬È«ÇòÁìÍÁÃæ»ý×î´ó¹ú¼ÒµÄº½¿ÕÔËÊäÍøÂçÔÚÂÃÓÎÍú¼¾ÏÝÈëÔÓÂÒ¡£¡£¡£¡£¡£Á½¸öºÚ¿Í×éÖ¯Ðû³ÆÐж¯ÊÇÒ»Á¬Ò»ÄêÉøÍ¸µÄЧ¹û£¬£¬£¬ÒÑ´Ý»Ù¶íº½7000̨ЧÀÍÆ÷²¢¿ØÖƸ߹ܼ°Ô±¹¤µçÄÔ£¬£¬£¬Íþв½«Ð¹Â¶ÂÿÍСÎÒ˽¼ÒÐÅÏ¢¼°ÄÚ²¿Í¨Ñ¶¼Í¼¡£¡£¡£¡£¡£°×¶íÂÞË¹ÍøÂçÓλ÷¶ÓÃ÷È·ÌåÏÖ£¬£¬£¬¹¥»÷Ö¼ÔÚÐÖúÎÚ¿ËÀ¼¶Ô¿¹"ÇÖÂÔÕß"£¬£¬£¬ÉùÃ÷ÒÔ"ÎÚ¿ËÀ¼ÍòË꣡°×¶íÂÞ˹×ÔÓÉÓÀ´æ£¡"×îºó¡£¡£¡£¡£¡£Ö»¹ÜÎÚ¿ËÀ¼¹Ù·½Î´»ØÓ¦£¬£¬£¬µ«"ĬȻÎÚÑ»"´ËÇ°Ôø¶à´ÎÐû³Æ¹¥»÷¶í²»¶¯²úÊý¾Ý¿â¡¢¹úÓеçÐŹ«Ë¾µÈÄ¿µÄ£¬£¬£¬²¿·ÖÐж¯µ¼Ö´ó¹æÄ£Êý¾Ýй¶¡£¡£¡£¡£¡£¿£¿£¿£¿ËÀïÄ·ÁÖ¹¬½²»°ÈËÅå˹¿Æ·ò³ÆÊÂÎñ"ÁîÈ˵£ÐÄ"£¬£¬£¬Ç¿µ÷ÍøÂçÍþвÊÇ´óÐ͹«¹²Ð§ÀÍÆóÒµÒ»Á¬ÃæÁÙµÄÒþ»¼£¬£¬£¬¶í¼ì·½ÒÑÆô¶¯ÐÌÊÂÊӲ졣¡£¡£¡£¡£×ÊÉîÒéÔ±°²¶«¡¤¸êÁжû½ðÖ¸³ö£¬£¬£¬¹¥»÷ÏÔʾ"Êý×ÖÕ½ÏßÒѳÉΪÖÜÈ«¶Ô¿¹µÄÒ»²¿·Ö"£¬£¬£¬ÒªÇó³¹²é·À»¤Ê§Ö°ÔðÈη½¡£¡£¡£¡£¡£¶íº½ËäδÐû²¼ÏµÍ³»Ö¸´Ê±¼ä£¬£¬£¬µ«ÌåÏÖÕýе÷ÆäËûº½Ë¾ÐÖúתÔËÂÿͣ¬£¬£¬²¢ÔÊÐí»Ö¸´ºó°ìÀíÍ˸ÄÇ©¡£¡£¡£¡£¡£
https://cybernews.com/security/glory-ukraine-hackers-took-down-aeroflots-entire-system/
3. GLOBAL GROUPÀÕË÷Èí¼þµ¼ÖÂýÌå¾ÞÍ·Albavisi¨®nÊý¾Ýй¶
7ÔÂ28ÈÕ£¬£¬£¬ÐÂÐËÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©×éÖ¯GLOBAL GROUPÐû³Æ¶ÔÎ÷°àÑÀÓïýÌå¾ÞÍ·Albavisi¨®nµÄÊý¾Ýй¶ÊÂÎñÈÏÕæ£¬£¬£¬ÇÔÈ¡400GBÊý¾Ý²¢ÍþвÈô15ÌìÄÚδÆô¶¯Ì¸ÅУ¬£¬£¬½«¹ûÕæ±»µÁÐÅÏ¢¡£¡£¡£¡£¡£¸Ã×éÖ¯×Ô2025Äê6Ô»îÔ¾ÒÔÀ´£¬£¬£¬Òѽ«Ã½Ìå¡¢Ò½ÁƱ£½¡µÈ¶à¸öÐÐÒµµÄ29¼ÒÆóÒµÁÐΪÊܺ¦Õߣ¬£¬£¬ÆäÖÐ18Æð°¸¼þµ¼ÖÂÍêÕûÊý¾Ý¼¯Ð¹Â¶£¬£¬£¬°üÀ¨Ò»¼ÒÒ½Ôº£¬£¬£¬Í¹ÏÔÆä¹¥»÷¹æÄ£µÄÆÕ±éÐÔÓëÆÆËðÁ¦¡£¡£¡£¡£¡£GLOBAL GROUPµÄÆæÒìÖ®´¦ÔÚÓÚ½ÓÄÉÈ˹¤ÖÇÄÜÇý¶¯µÄ̸Åй¤¾ß£¬£¬£¬Í¨¹ý̸Ìì»úеÈËÓëÊܺ¦ÕßÏàͬ£¬£¬£¬ÓÈÆäÕë¶Ô·ÇÓ¢ÓïʹÓÃÕߣ¬£¬£¬½µµÍÁËÓïÑÔÕϰ¶ÔÀÕË÷ЧÂʵÄÓ°Ïì¡£¡£¡£¡£¡£´Ëǰ°¸ÀýÖУ¬£¬£¬¸Ã×éÖ¯ÔøË÷Òª9.5±ÈÌØ±Ò£¨Ô¼ºÏ100ÍòÃÀÔª£©Êê½ð£¬£¬£¬µ«±¾´ÎÕë¶ÔAlbavisi¨®nµÄÏêϸ½ð¶îÉÐδ¹ûÕæ¡£¡£¡£¡£¡£Albavisi¨®n×÷ΪÀ¶¡ÃÀÖÞ¿ç¹úýÌ弯ÍÅ£¬£¬£¬ÓªÒµÁýÕÖ14ÖÁ15¸öÎ÷°àÑÀÓï¹ú¼Ò£¬£¬£¬ÓµÓÐ45¸öµçÊÓÆµµÀ¡¢68¸ö¹ã²¥µç̨¼°65¼ÒÓ°Ï·Ôº£¬£¬£¬Ê×´´ÈËÀ×Ã×¼ª°Â¡¤°²ºÕ¶û¡¤¸ÔÈøÀ×˹СÎÒ˽¼Ò×ʲúÔ¼20ÒÚÃÀÔª£¬£¬£¬ÆäÖØ´óµÄÓû§Êý¾ÝÓëÉÌÒµÓ°ÏìÁ¦³ÉΪÀÕË÷ÍÅ»ïµÄÄ¿µÄ¡£¡£¡£¡£¡£
https://hackread.com/global-group-ransomware-media-giant-albavision-breach/
4. Ó¢¹ú¿Æ¼¼³Ð°üÉÌQdos֤ʵ¿Í»§Êý¾Ýй¶
7ÔÂ25ÈÕ£¬£¬£¬ÉÌÒµ°ü¹Ü¼°IR35ЧÀÍר¼ÒQdos¿ËÈÕÈ·ÈÏÆäÍøÂçÓ¦ÓóÌÐò±¬·¢Êý¾ÝÇå¾²ÊÂÎñ£¬£¬£¬²¿·Ö¿Í»§Ð¡ÎÒ˽¼ÒÊý¾Ý±»Î´¾ÊÚȨµÄµÚÈý·½ÇÔÈ¡¡£¡£¡£¡£¡£Æ¾Ö¤QdosÏò¿Í»§·¢Ë͵ĵç×ÓÓʼþ£¬£¬£¬¸Ã¹«Ë¾ÓÚ6ÔÂ19ÈÕÊÕµ½¹ØÓÚÆäWebÓ¦ÓÃmygoqdos.comµÄÇå¾²¾¯±¨£¬£¬£¬ËæºóÔÚµÚÈý·½ÍøÂçÇ徲ר¼ÒÐÖúÏÂÕö¿ªÊӲ졣¡£¡£¡£¡£ÊÓ²ìÈ·ÈÏ£¬£¬£¬¹¥»÷Õßͨ¹ý¸ÃÓ¦Óûá¼û²¢ÏÂÔØÁ˰üÀ¨¿Í»§ÐÕÃû¡¢Í¨Ñ¶µØµã£¨»ò×¢²áÓªÒµµØµã£©¡¢µç×ÓÓʼþµØµã¼°ÁªÏµ·½·¨µÈСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬ÒÔ¼°Óë¿Í»§°ü¹Üµ¥¡¢IR35ЧÀÍÏà¹ØµÄÎļþ£¬£¬£¬ÉÐÓвɹº»·½ÚµÄ·¢Æ±¡¢´û¼Çµ¥µÈÎĵµ¡£¡£¡£¡£¡£²»¹ý£¬£¬£¬QdosÇ¿µ÷ÐÅÓÿ¨ÐÅÏ¢¡¢Éí·Ý֤ʵÎļþ¼°°ü¹ÜË÷ÅâÐÅϢδÊÜÓ°Ïì¡£¡£¡£¡£¡£ÊÂÎñ±¬·¢ºó£¬£¬£¬QdosÁ¬Ã¦½ÓÄÉÓ¦¼±²½·¥£¬£¬£¬°üÀ¨ÔÚÊÓ²ìʱ´ú½ûÓÿͻ§¶ÔÍøÕ¾µÄ»á¼ûȨÏÞ£¬£¬£¬²¢ÓÚ6ÔÂ26ÈÕÐÞ¸´ÎÊÌâºó»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£ÎªÓ¦¶Ô´Ë´Îй¶£¬£¬£¬¹«Ë¾ÎªÊÜÓ°Ïì¿Í»§ÌṩÁË12¸öÔµÄÃâ·ÑÉí·Ý¼à¿ØÐ§ÀÍ£¬£¬£¬¸ÃЧÀÍ¿ÉÈ«Ììºò¼à²âÍøÂç¡¢É罻ƽ̨¼°¹«¹²Êý¾Ý¿â£¬£¬£¬ÊµÊ±Ô¤¾¯Ð¡ÎÒ˽¼ÒÐÅϢй¶Σº¦¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬Qdos½¨Òé¿Í»§Ð¡ÐÄ¿ÉÒÉÓʼþ¡¢µç»°»ò¶ÌÐÅ£¬£¬£¬²¢ÔÊÐí¿Í»§±£µ¥ÓÐÓÃÐÔ¼°ÔÚÏßÕË»§¹¦Ð§²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£
https://www.theregister.com/2025/07/25/ir35_advisor_qdos_confirms_data_breach/
5. Patchwork×éÖ¯Õë¶ÔÍÁ¶úÆä¹ú·À³Ð°üÉÌÌᳫÓã²æ´¹ÂÚ¹¥»÷
7ÔÂ25ÈÕ£¬£¬£¬ÍøÂçÇå¾²Íþв×éÖ¯Patchwork£¨ÓÖÃûAPT-C-09¡¢°×Ïó×éÖ¯£©½üÆÚ±»ÆØÕë¶ÔÍÁ¶úÆä¹ú·À³Ð°üÉÌÌᳫÐÂÒ»ÂÖÓã²æÊ½ÍøÂç¹¥»÷£¬£¬£¬Ä¿µÄÖ±Ö¸ÎÞÈËÔØ¾ßϵͳ£¨UAV£©¼°×¼È·ÖƵ¼µ¼µ¯ÁìÓò£¬£¬£¬Ö¼ÔÚÇÔȡսÂÔÇ鱨¡£¡£¡£¡£¡£¾ÝArctic WolfʵÑéÊÒÊÖÒÕ±¨¸æ£¬£¬£¬¹¥»÷Õßͨ¹ýαװ³É¡°¹ú¼ÊÎÞÈËÔØ¾ßϵͳ¾Û»áÔ¼Ç뺯¡±µÄ¶ñÒâLNKÎļþʵÑéÎå½×¶Î¹¥»÷Á´£¬£¬£¬¹¥»÷ʱ»úÇ¡·ê°Í»ù˹̹ÓëÍÁ¶úÆäÉ·ÀÎñÏàÖú¡¢Ó¡°Í¾üʳåÍ»Éý¼¶Ö®¼Ê£¬£¬£¬µØÔµÕþÖÎÄîÍ·ÏÔÖø¡£¡£¡£¡£¡£¹¥»÷Á÷³ÌʼÓÚ´¹ÂÚÓʼþÖеĶñÒâLNKÎļþ£¬£¬£¬¸ÃÎļþ´¥·¢PowerShellÏÂÁ£¬£¬´Ó2025Äê6ÔÂ25ÈÕ×¢²áµÄÓòÃû¡°expouav[.]org¡±ÏÂÔØÔØºÉ¡£¡£¡£¡£¡£Ð§ÀÍÆ÷ÍйܵķÂð¾Û»áPDFÎĵµ×÷ΪÊÓ¾õÓÕ¶üÊèÉ¢Óû§×¢ÖØÁ¦£¬£¬£¬¹¥»÷Á´ÔòÔÚºǫ́¾²Ä¬ÔËÐС£¡£¡£¡£¡£Òªº¦ÔغɰüÀ¨Í¨¹ýÍýÏëʹÃüÆô¶¯µÄ¶ñÒâDLL£¬£¬£¬½ÓÄÉDLL²à¼ÓÔØÊÖÒÕÖ´ÐÐshellcode£¬£¬£¬×îÖÕʵÏÖÖ÷»úÉî¶ÈÕì̽¡¢ÆÁÄ»½ØÍ¼¼°Êý¾Ý»Ø´«ÖÁC2ЧÀÍÆ÷¡£¡£¡£¡£¡£ÊÖÒÕÆÊÎöÏÔʾ£¬£¬£¬PatchworkÒÑ´Ó2024ÄêµÄx64 DLL±äÖÖ£¬£¬£¬Éú³¤Îª¾ß±¸ÔöÇ¿ÏÂÁî½á¹¹µÄx86 PE¿ÉÖ´ÐÐÎļþ£¬£¬£¬²¢½ÓÄÉ·ÂðÕýµ±ÍøÕ¾µÄC2ÐÒ飬£¬£¬ÏÔÖøÌáÉýÁ˹¥»÷Òþ²ØÐÔ¡£¡£¡£¡£¡£
https://thehackernews.com/2025/07/patchwork-targets-turkish-defense-firms.html
6. CISAÖÒÑÔPaperCut´òÓ¡Èí¼þ¸ßΣÎó²îÔâÆð¾¢Ê¹ÓÃ
7ÔÂ28ÈÕ£¬£¬£¬ÃÀ¹úÍøÂçÇå¾²Óë»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©¿ËÈÕ·¢³ö½ôÆÈÖÒÑÔ£¬£¬£¬³ÆÍþвÐÐΪÕßÕýʹÓÃPaperCut NG/MF´òÓ¡ÖÎÀíÈí¼þÖеĸßΣÎó²î£¨CVE-2023-2533£©Ìᳫ¿çÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷£¬£¬£¬²¢½è´Ë»ñµÃÔ¶³Ì´úÂëÖ´ÐÐÄÜÁ¦¡£¡£¡£¡£¡£¸ÃÎó²îÓÚ2023Äê6Ô±»ÐÞ²¹£¬£¬£¬µ«ÏÖÔÚÈÔ±»¶ñÒâÐÐΪÕ߯ð¾¢Ê¹Ó㬣¬£¬¹¥»÷Õßͨ³£Í¨¹ýÓÕÆ¾ßÓÐÖÎÀíԱȨÏÞµÄÓû§µã»÷¶ñÒâÁ´½Ó£¬£¬£¬¼´¿É¸ü¸ÄϵͳÇå¾²ÉèÖûòÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£PaperCutÈí¼þÔÚÈ«ÇòÓµÓÐÖØ´óÓû§»ù´¡£¬£¬£¬ÁýÕÖÁè¼Ý7Íò¸ö×éÖ¯µÄ1ÒÚ¶àÓû§£¬£¬£¬Éæ¼°½ÌÓý¡¢ÆóÒµµÈ¶àÁìÓò¡£¡£¡£¡£¡£Ö»¹ÜCISAδÅû¶Ŀ½ñ¹¥»÷µÄÏêϸϸ½Ú£¬£¬£¬µ«Òѽ«¸ÃÎó²îÄÉÈëÆä¡°ÒÑÖª±»Ê¹ÓÃÎó²îĿ¼¡±£¬£¬£¬²¢ÒÀ¾Ý2021Äê11ÔÂÐû²¼µÄ¾ßÓÐÔ¼ÊøÁ¦µÄÔËÓªÖ¸ÁBOD 22-01£©£¬£¬£¬ÒªÇóÁª°îÃñÊÂÐÐÕþ²¿·Ö£¨FCEB£©»ú¹¹ÔÚ2025Äê8ÔÂ18ÈÕǰÍê³ÉϵͳÐÞ²¹¡£¡£¡£¡£¡£CISAÇ¿µ÷£¬£¬£¬´ËÀàÎó²îÊÇÍøÂç·¸·¨·Ö×ӵij£¼û¹¥»÷ǰÑÔ£¬£¬£¬´ºÁª°îÆóÒµ×é³ÉÖØ´óΣº¦£¬£¬£¬²¢ºôÓõ˽Ӫ²¿·Ö×é֯ͬÑù¾¡¿ì½ÓÄÉÐж¯¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cisa-flags-papercut-rce-bug-as-exploited-in-attacks-patch-now/


¾©¹«Íø°²±¸11010802024551ºÅ