±¾ÖÜÈȵãʼþÍþвÇ鱨
1¡¢ShinyHunters¿ª·¢ÐÂÐÍÀÕË÷Èí¼þShinySp1d3r
ShinyHuntersÍþвÐÐΪÌåÕý¿ª·¢ÃûΪShinySp1d3rµÄÐÂÐÍÀÕË÷Èí¼þ¼´·þÎñƽ̨¡£¸Ã×éÖ¯´Ëǰ¹ßÓÃALPHV/BlackCat¡¢QilinµÈµÚÈý·½¼ÓÃÜÆ÷£¬´Ë´Î´ÓÁã¹¹½¨×ÔÓй¤¾ß£¬²ÉÓÃChaCha20Ëã·¨¼ÓÃÜÎļþ£¬RSA-2048±£»¤ÃÜÔ¿£¬Ã¿¸öÎļþÉú³É¶ÀÌØÀ©Õ¹Ãû¡£¸Ã¼ÓÃÜÆ÷¾ß±¸½ø³Ì¾ä±úÖÕÖ¹¡¢¿ÕÏпռäÌî³ä¡¢ÍøÂç¹²Ïí¼ÓÃÜ¡¢·´·ÖÎöȡ֤µÈ¸ß¼¶¹¦ÄÜ£¬¿Éͨ¹ý·þÎñ´´½¨¡¢WMI»òGPOʵÏÖºáÏò´«²¥¡£Ä¿Ç°Windows°æ±¾ÒÑÆØ¹â£¬LinuxÓëESXi°æ±¾ÕýÔÚ¿ª·¢ÖУ¬²¢¼Æ»®ÍƳö´¿»ã±à"ÉÁµç°æ"¡£ÀÕË÷ÐÅÓ²±àÂëÈýÌì̸ÅÐÆÚÏÞ£¬Ñо¿ÈËÔ±¾¯¸æ¸ÃRaaS¼´½«Í¶ÈëÔËÓª£¬È«ÇòÆóÒµÐèÌá¸ß¾¯Ìè¡£
²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters/
2¡¢Ó²¼þÅä¼þ¾ÞÍ·ÂÞ¼¼È·ÈÏÔâClopÀÕË÷¹¥»÷
Ó²¼þÅä¼þ¾ÞÍ·ÂÞ¼¼¹«Ë¾ÕýʽÏòSECÌá½»Îļþ£¬È·ÈÏÔâÊÜClopÀÕË÷ÍŻ﹥»÷£¬µ¼ÖÂÔ¼1.8TBÊý¾ÝÍâй¡£¾Ý11ÔÂ14ÈÕÅû¶µÄ8-K±í¸ñÏÔʾ£¬±»µÁÊý¾ÝÉæ¼°Ô±¹¤¡¢Ïû·ÑÕß¡¢¿Í»§¼°¹©Ó¦É̵ÄÓÐÏÞÐÅÏ¢£¬µ«¹Ù·½Ç¿µ÷δ°üº¬¹úÃñÉí·ÝÖ¤ºÅ»òÐÅÓÿ¨µÈºËÐÄÃô¸ÐÊý¾Ý¡£´Ë´Îʼþ¸ùÔ´ÓÚµÚÈý·½ÁãÈÕ©¶´£¬»Æ½ð³Ç¹ÙÍø½çÆÕ±éÍÆ²âÓë½ñÄê7ÔÂOracle E-Business Suite©¶´CVE-2025-61882Ïà¹Ø£¬¸Ã©¶´´ËǰÒÑÔâClop´ó¹æÄ£ÀûÓá£Clop×÷ΪÀÏÅÆÀÕË÷×éÖ¯£¬¹ßÓÃÁãÈÕ©¶´ÊµÊ©Êý¾ÝÇÔÈ¡£¬ÔøÖÆÔìAccellion¡¢MOVEitµÈÖØ´ó¹©Ó¦Á´Ê¼þ¡£
²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/security/logitech-confirms-data-breach-after-clop-extortion-attack/
3¡¢Ó¢¹ú¹ú¼ÒÒ½ÁÆ·þÎñÌåϵÔâClopÀÕË÷¹¥»÷
ÀÕË÷Èí¼þÍÅ»ïClopÀûÓÃOracle E-Business SuiteÁãÈÕ©¶´·¢¶¯¹¥»÷£¬Ó¢¹ú¹ú¼ÒÒ½ÁÆ·þÎñÌåϵ£¨NHS£©±»ÁÐÈëÊܺ¦ÕßÃûµ¥¡£¹¥»÷Õßͨ¹ýCVE-2025-53072ºÍCVE-2025-62481Á½¸öCVSS 9.8·ÖµÄÑÏÖØÂ©¶´£¬ÎÞÐèÈÏÖ¤¼´¿É½Ó¹ÜOracle Marketingϵͳ¡£¸Ã¹¥»÷×Ô2025Äê7Ô¿ªÊ¼£¬9Ôµ×ClopÏòÊܺ¦Õß·¢ËÍÀÕË÷Óʼþ£¬Ë÷Òª¸ß´ï5000ÍòÃÀÔªÊê½ð¡£NHSÓÚ10ÔÂÏÂÑ®·¢²¼»Æ½ð³Ç¹ÙÍø¹«¸æ£¬11ÔÂÈ·Èϱ»ÁÐÈë°µÍøÊܺ¦ÕßÃûµ¥£¬µ«Ä¿Ç°ÉÐδ·¢ÏÖÊý¾Ýй¶£¬ÕýÓë¹ú¼ÒÍøÂç»Æ½ð³Ç¹ÙÍøÖÐÐĺÏ×÷µ÷²é¡£
²Î¿¼Á´½Ó£º
https://www.govinfosecurity.com/uk-nhs-named-in-clop-gangs-exploits-oracle-zero-days-a-30030
4¡¢AkiraÀÕË÷Èí¼þ¹¥»÷À©Õ¹ÖÁNutanixƽ̨
ÃÀ¹úÍøÂç»Æ½ð³Ç¹ÙÍøºÍ»ù´¡ÉèÊ©»Æ½ð³Ç¹ÙÍø¾Ö£¨CISA£©ÁªºÏFBIµÈ»ú¹¹·¢²¼×îй«¸æ£¬¾¯¸æAkiraÀÕË÷Èí¼þÒѽ«¹¥»÷Ä¿±êÀ©Õ¹ÖÁNutanix AHVÐéÄâ»ú¡£Akira¶ÔNutanixÐéÄâ»ú²Éȡֱ½Ó¼ÓÃÜ·½Ê½£¬²»Ê¹ÓÃacli»òncliÃüÁî¹ØÍ£ÏµÍ³¡£¹¥»÷Õß³£ÀûÓÃÇÔÈ¡µÄVPN/SSHƾ֤»òSonicWall©¶´ÈëÇÖÍøÂ磬¼Ì¶ø¹¥»÷δÐÞ²¹µÄVeeam±¸·Ý·þÎñÆ÷¡£¹«¸æÅû¶£¬Akira³ÉԱʹÓÃnltest¡¢AnyDeskµÈ¹¤¾ßºáÏòÒÆ¶¯£¬²¢´´½¨¹ÜÀíÕË»§Î¬³Ö³Ö¾Ã»¯¡£CISA½¨Òé×é֯ʵʩÀëÏß±¸·Ý¡¢Ç¿ÖƶàÒòËØÈÏÖ¤£¬²¢Á¢¼´ÐÞ²¹ÒÑ֪©¶´¡£
²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/security/cisa-warns-of-akira-ransomware-linux-encryptor-targeting-nutanix-vms/