TalentHookÇóְϵͳÅäÖÃÃýÎóÖÂ2600Íò·Ý¼òÀúй¶

°ä²¼¹¦·ò 2025-07-07

1. TalentHookÇóְϵͳÅäÖÃÃýÎóÖÂ2600Íò·Ý¼òÀúй¶


7ÔÂ3ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÈËÁ¦×ÊÔ´·þÎñƽ̨TalentHookÒòAzure Blob´æ´¢ÈÝÆ÷ÅäÖÃÃýÎ󣬣¬£¬£¬£¬µ¼Ö½ü2600Íò·ÝÇóÖ°Õß¼òÀú±»¹«¿ªÂ¶³ö£¬£¬£¬£¬£¬Òý·¢ÑϳÁÊý¾Ý°²È«ÊÂÎñ¡£¡£¡£¡£¡£ ¡£¡£Â¶³öµÄÈÝÆ÷Öд洢×Å´óÁ¿ÃÀ¹úÇóÖ°ÕßµÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬Ô̺¬È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢½ÌÓý²¼¾°¡¢¹¤×÷¾­Àú¼°¼ÒͥסַµÈÖ÷ÌâÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÍŶÓÖ¸³ö£¬£¬£¬£¬£¬Ð¹Â¶Êý¾ÝµÄ¸ßÆëÈ«ÐÔʹ¹¥»÷Õß¿ÉÄÜÖ´Ðо«×¼Éç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿Í¿Éͨ¹ýÓʼþ¡¢¶ÌÐÅ·¢ËÍÐéα¹¤×÷Ô¼Çë»ò²¼¾°µ÷²éÒªÇ󣬣¬£¬£¬£¬ÓÕµ¼Êܺ¦ÕßÌá½»Éí·Ý֤ɨÃè¼þ¡¢ÒøÐÐÕË»§µÈ¸üÉî²ãÐÅÏ¢£¬£¬£¬£¬£¬ÉõÖÁ¼ÙÒâ¹ÍÖ÷ÊÕÈ¡ÐéαÉêÇëÓöÈ¡£¡£¡£¡£¡£ ¡£¡£¸üÑϳÁµÄÊÇ£¬£¬£¬£¬£¬¼ÒͥסַÓëÁªÏµ·½Ê½µÄ¶³ö´ó·ùÔö³¤ÁË"ÈËÈâËÑË÷"·çÏÕ£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÏÖʵÊÀ½çÖеÄɧÈÅ»ò¿ÖÏÅÐÐΪ¡£¡£¡£¡£¡£ ¡£¡£ÊÂÎñÆØ¹âºó£¬£¬£¬£¬£¬CybernewsÒÑÏòTalentHookĸ¹«Ë¾Resource Edge·¢³ö°²È«¾¯Ê¾£¬£¬£¬£¬£¬½¨ÒéÆäÁ¢¼´²ÉÈ¡ÎåÏ¸´´ëÊ©£ºÏÞ¶ÈÈÝÆ÷¹«¹²½Ó¼ûȨÏÞ¡¢ÆôÓ÷þÎñÆ÷¶Ë¼ÓÃÜ¡¢Í¨¹ýAzure Key VaultÖÎÀíÃÜÔ¿¡¢³ÉÁ¢½Ó¼ûÈÕÖ¾¼à¿Ø»úÔ죬£¬£¬£¬£¬²¢·¢Õ¹¶¨ÆÚ°²È«Éó¼ÆÓëÔ±¹¤Åàѵ¡£¡£¡£¡£¡£ ¡£¡£½ØÖÁ»ã±¨°ä²¼£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÉÐδ¹«¿ª»ØÓ¦´ëÖýøÕ¹¡£¡£¡£¡£¡£ ¡£¡£


https://cybernews.com/security/talenthook-data-leak-exposes-millions/


2. ¹ú¼Ê·¨ÂÉÐж¯·ÛËé×Ãü°µÍø¶¾Æ·Êг¡Archetyp Market


7ÔÂ3ÈÕ£¬£¬£¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯Ôڵ¹úÖ÷µ¼µÄ¶à¹ú½áºÏÐж¯ÖУ¬£¬£¬£¬£¬³É¹¦¹Ø¹ØÁ˰µÍøº¹ÇàÉÏÔËÓª¹¦·ò×µÄ¶¾Æ·ÂòÂôƽ̨Archetyp Market£¬£¬£¬£¬£¬²¢¿ÛÁôÆäÖ÷Ìâ³ÉÔ±¡£¡£¡£¡£¡£ ¡£¡£Õâ´Î´úºÅ"Deep Sentinel"µÄרÏîÐж¯ÓÚ6ÔÂ11ÈÕÖÁ13ÈÕ·¢Õ¹£¬£¬£¬£¬£¬ºá¿çµÂ¹ú¡¢ºÉÀ¼¡¢ÂÞÂíÄáÑÇ¡¢Î÷°àÑÀ¡¢ÈðµäµÈÁù¹ú£¬£¬£¬£¬£¬Ô¼300Ãû·¨ÂÉÈËԱͬ²½Ö´ÐÐ×¥²¶ÓëÖ¤¾Ý±£È«£¬£¬£¬£¬£¬×îÖÕÔÚÎ÷°àÑÀ¾³ÄÚ×¥»ñ¸ÃÊг¡ÖÎÀíÔ±£¬£¬£¬£¬£¬Èðµä·½ÃæÍ¬²½½ø¹¥¶¥¼¶¹©¸øÉÌÍøÂç¡£¡£¡£¡£¡£ ¡£¡£×÷Ϊ°µÍø¶¾Æ·ÂòÂôÁìÓòµÄ"ÔªÀϼ¶"ƽ̨£¬£¬£¬£¬£¬Archetyp Market×Ô2019ÄêÆð³ÖÐøÔËÓª³¬¹ýÎåÄ꣬£¬£¬£¬£¬ÀÛ¼Æ×¢²áÓû§Í»ÆÆ60Íò£¬£¬£¬£¬£¬×ÜÂòÂô¶î¹ÀËã´ï2.5ÒÚÅ·Ôª¡£¡£¡£¡£¡£ ¡£¡£ÆäÉÌÆ·¿âÔ̺¬1.7ÍòÖÖ·¸·¨ÎïÆ·£¬£¬£¬£¬£¬ÓÈÆäÒÔÔÊÐíÂòÂô·ÒÌ«ÄáµÈ¸ß´¿¶ÈºÏ³É°¢Æ¬ÀàÒ©ÎïÖø³Æ£¬£¬£¬£¬£¬ÕâÀàÎïÖÊÒѳÉΪŷÖÞÉõÖÁÈ«ÇòÈÕÒæÑϸñµÄ¹«¹²ÎÀÉúÍþв¡£¡£¡£¡£¡£ ¡£¡£Æ½Ì¨¼¼Êõ¼Ü¹¹Ñ¡È¡¶à³ÁÄäÃû»¯Éè¼Æ£¬£¬£¬£¬£¬ÓëÒѹعصÄDream Market¡¢Silk RoadµÈ°µÍøÆ½Ì¨ÆëÃû£¬£¬£¬£¬£¬ÐÎ³ÉÆëÈ«µÄ·¸·¨¹©¸øÁ´¡£¡£¡£¡£¡£ ¡£¡£Ðж¯ÖУ¬£¬£¬£¬£¬·¨ÂÉ»ú¹¹Í¨¹ý³Ö¾Ã×ʽð×·×ÙÓëÊý×Öȡ֤£¬£¬£¬£¬£¬³É¹¦¶¨Î»¹Ø¼ü»ù´¡ÉèÊ©²¢¶³½á780ÍòÅ·ÔªÉæ°¸×ʲú¡£¡£¡£¡£¡£ ¡£¡£µÂ¹úÁª¹úÐÌʾ¯Ô±¾Ö£¨BKA£©ÓëÅ·ÖÞ˾·¨×éÖ¯£¨Eurojust£©Ð­µ÷¿ç¹úÖ¤¾ÝÁ´£¬£¬£¬£¬£¬×îÖÕʵÏÖ¼¼ÊõÍŶÓÓëÖÎÀí²ãµÄË«³ÁÍ»ÆÆ¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/179591/cyber-crime/europol-shuts-down-archetyp-market-longest-running-dark-web-drug-marketplace.html


3. IdeaLabÔâ·êHunters InternationalÀÕË÷¹¥»÷£¬£¬£¬£¬£¬262GBÊý¾Ýй¶


7ÔÂ3ÈÕ£¬£¬£¬£¬£¬ÃÀ¹ú¼ÓÖÝÀÏÅÆ¿Æ¼¼·õ»¯Æ÷IdeaLab½üÈÕÏòÊÜ2024Äê10ÔÂÊý¾Ýй¶ÊÂÎñÓ°ÏìµÄÓ×ÎÒ·¢³ö֪ͨ£¬£¬£¬£¬£¬½ÒʾÆäÔâ·êHunters InternationalÀÕË÷Èí¼þ×éÖ¯¹¥»÷µÄϸ½Ú¡£¡£¡£¡£¡£ ¡£¡£¸ÃÊÂÎñµ¼Ö³¬¹ý13.7Íò·ÝÎļþ£¨×ÜÁ¿´ï262.8GB£©±»ÇÔÈ¡£¬£¬£¬£¬£¬Ó°ÏìÁìÓòº­¸ÇÏÖÈÎ/ǰÈÎÔ±¹¤¡¢³Ð°üÉ̼°Æä¾ìÊô¡£¡£¡£¡£¡£ ¡£¡£µ÷²éÏÔʾ£¬£¬£¬£¬£¬¹¥»÷ÕßÓÚ2024Äê10ÔÂ4ÈÕÇÖÈëϵͳ£¬£¬£¬£¬£¬ÈýÌìºó±»¼ì²âµ½Òì³£»£»£»£» £»£»î¶¯£¬£¬£¬£¬£¬µ«Ö±ÖÁ2025Äê6ÔÂ26ÈÕµÚÈý·½µ÷²éʵÏÖ²ÅÈ·ÈÏÊý¾ÝÔâÇÔ¡£¡£¡£¡£¡£ ¡£¡£Ö»¹Ü¾ßÌåй¶×Ö¶ÎδÆëÈ«¹«¿ª£¬£¬£¬£¬£¬µ«È·ÈÏÔ̺¬ÐÕÃûÓëÆäËûÃô¸ÐÐÅÏ¢×éºÏ£¬£¬£¬£¬£¬×ãÒÔÓÃÓÚÉí·Ý͵ÇÔ»ò¾«×¼Ú¿Æ­¡£¡£¡£¡£¡£ ¡£¡£ÀÕË÷Èí¼þ×éÖ¯Hunters InternationalÔÚ°µÍø¹«¿ªÊý¾Ýºó£¬£¬£¬£¬£¬ÓÚ2025Äê6ÔºöÈ»°ä·¢¹Ø¹ØÆäÀÕË÷ÃÅ»§£¬£¬£¬£¬£¬²¢É¾³ýËùÓÐÊܺ¦ÆóÒµÌõ¿î£¬£¬£¬£¬£¬×ª¶øÍÆÎÅÃûΪWorld LeaksµÄÐÂÆ½Ì¨³ÖÐøÖ´ÐÐÍøÂçڲƭ¡£¡£¡£¡£¡£ ¡£¡£ÕâÒ»Æ·ÅÆ³Á×éÕ½ÊõÓëÍøÂ簲ȫ¹«Ë¾Group-IB´ËǰµÄ·ÖÎöÒ»Ö£¬£¬£¬£¬£¬ÏÔʾ¸ÃÍÅ»ïÕýͨ¹ý±ä»»Éí·Ý¶ã±Ü·¨ÂÉ×·×Ù¡£¡£¡£¡£¡£ ¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬ºÚ¿ÍËäÐû³ÆÌṩÃâ·Ñ½âÃÜÃÜÔ¿£¬£¬£¬£¬£¬µ«ÏÂÔØÁ´½ÓÒÑʧЧ£¬£¬£¬£¬£¬°µÊ¾Êý¾Ý¿ÉÄÜÒѱ»¶à¸ö·¸×OÌå»ñÈ¡¡£¡£¡£¡£¡£ ¡£¡£ÎªÓ¦¶Ô·çÏÕ£¬£¬£¬£¬£¬IdeaLabΪÊÜÓ°ÏìÕßÌṩ24¸öÔÂÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ£¬£¬£¬£¬£¬×¢²á½ØÖ¹ÈÕΪ2025Äê10ÔÂ1ÈÕ¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/idealab-confirms-data-stolen-in-ransomware-attack-last-year/


4. BMW½ðÈÚ·þÎñ¹«Ë¾ÒòµÚÈý·½Êý¾Ýй¶ÊÂÎñÊÜÓÐÏÞÓ°Ïì


7ÔÂ4ÈÕ£¬£¬£¬£¬£¬2025Äê2Ô£¬£¬£¬£¬£¬BMW½ðÈÚ·þÎñ¹«Ë¾ÒòµÚÈý·½ºÏ×÷ͬ°éAISÔâ·êÊý¾Ýй¶ÊÂÎñ¶ø¼ä½ÓÊܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£¡£Õâ´ÎÊÂÎñÔ´ÓÚ×ܲ¿Î»ÓڵÿËÈøË¹ÖݵĽðÈڿƼ¼¹«Ë¾AISϵͳ±»¶ñÒâÐÐΪÕßÈëÇÖ£¬£¬£¬£¬£¬¸Ã¹«Ë¾µ±Ê¹ØýΪBMW¼°ÆäÕË»§³ÖÓÐÈËÌṩ¼à¿Ø´¦ÖÃÓë˾·¨¼à¿Ø·þÎñ¡£¡£¡£¡£¡£ ¡£¡£AISÔÚ·¢ÏÖÍøÂçÄÚ¿ÉÒɻºó£¬£¬£¬£¬£¬½áºÏȡ֤ר¼ÒÆô¶¯µ÷²é£¬£¬£¬£¬£¬È·ÈϺڿÍÓÚ2ÔÂ16ÈÕÇÖÈëϵͳ²¢ÇÔÈ¡ÉÙÁ¿Êý¾Ý£¬£¬£¬£¬£¬µ«¾ßÌåй¶ÄÚÈÝÉв»Ã÷È·£¬£¬£¬£¬£¬Î¥¹æÍ¨Öª½öÌá¼°ÐÕÃûÐÅÏ¢£¬£¬£¬£¬£¬Î´Éæ¼°ÆäËûÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£ÊÂÎñÓ°ÏìÁìÓòÓÐÏÞ£¬£¬£¬£¬£¬³¬¹ý1950ÈËÊܲ¨¼°£¬£¬£¬£¬£¬ÆäÖнöÁ½ÃûÃåÒòÖݾÓÃñ¡£¡£¡£¡£¡£ ¡£¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚAISϵͳÄÚÂñ·ü¹¦·ò´ïÁ½Ì죬£¬£¬£¬£¬Ö±ÖÁ2ÔÂ18Èղű»¼ì²â·¢ÏÖ¡£¡£¡£¡£¡£ ¡£¡£AISÇ¿µ÷£¬£¬£¬£¬£¬Õâ´ÎÈëÇÖδ´¥¼°BMW½ðÈÚ·þÎñ¹«Ë¾×ÔÉíµÄϵͳÓëÊý¾Ý¿â£¬£¬£¬£¬£¬ÆäÖ÷ÌâÊý¾Ý°²È«Î´ÊÜÍþв¡£¡£¡£¡£¡£ ¡£¡£ÎªÓ¦¶ÔDZÔÚ·çÏÕ£¬£¬£¬£¬£¬AISÒѳÐŵΪÊÜÓ°ÏìÓû§ÌṩΪÆÚ12¸öÔµÄEquifaxÐÅÓþ¼à¿Ø¼°Éí·Ý͵ÇÔÔ¤·À·þÎñ£¬£¬£¬£¬£¬Á¦Çó½«Ëðʧ½µÖÁ×îµÍ¡£¡£¡£¡£¡£ ¡£¡£


https://cybernews.com/security/bmw-financial-services-third-party-breach/


5. Ingram MicroÈ·ÈÏÔâ·êSafePayÀÕË÷Èí¼þ¹¥»÷


7ÔÂ5ÈÕ£¬£¬£¬£¬£¬2025Äê7Ô£¬£¬£¬£¬£¬È«ÇòIT¾ÞÍ·Ingram Micro£¨Ó¢Âõ¹ú¼Ê£©È·ÈÏÔâ·êSafePayÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÆäÄÚ²¿ÏµÍ³¹Ø¹Ø¼°ÍøÕ¾¡¢ÔÚÏß¶©¹ºÆ½Ì¨Ì±»¾¡£¡£¡£¡£¡£ ¡£¡£Õâ´Î¹¥»÷²úÉúÓÚÖÜËÄÁ賿£¬£¬£¬£¬£¬Ô±¹¤É豸³öÏÖÀÕË÷ÐÅ£¬£¬£¬£¬£¬µ«¼ÓÃÜÇé¿öÉÐδÃ÷È·¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷õè¾¶ÒÉËÆÍ¨¹ýGlobalProtect VPNƽ̨£¬£¬£¬£¬£¬ÀûÓÃй¶ƾ֤»òÃÜÂëÅçÈ÷¹¥»÷ÇÖÈëÍøÂç¡£¡£¡£¡£¡£ ¡£¡£ÊÜÓ°ÏìϵͳÔ̺¬»ùÓÚAIµÄXvantage·Ö·¢Æ½Ì¨ºÍImpulseÐí¿ÉÖ¤ÅäÖÃÆ½Ì¨£¬£¬£¬£¬£¬¶øMicrosoft 365¡¢TeamsµÈ·þÎñÈÔÕý³£ÔËÐС£¡£¡£¡£¡£ ¡£¡£ÊÂÎñÒý·¢²¿ÃŵØÓòÔ±¹¤Ô¶³Ì°ì¹«£¬£¬£¬£¬£¬¹«Ë¾×Ô¶¯ÏÂÏß²¿ÃÅϵͳ²¢¹Ø¹ØVPN½Ó¼û£¬£¬£¬£¬£¬µ«Î´ÊµÊ±¹«¿ªÐÅÏ¢£¬£¬£¬£¬£¬½öÒÔ"ITÎÊÌâ"¶Ô±í×¢Ã÷¡£¡£¡£¡£¡£ ¡£¡£SafePayÍÅ»ï×Ô2024Äê11Ô³öÏÖºóÒѹ¥»÷³¬220¼ÒÆóÒµ£¬£¬£¬£¬£¬ÆäÀÕË÷֪ͨ³£º¬Í¨ÓÃÐÔÊý¾ÝÇÔÈ¡ÉêÃ÷£¬£¬£¬£¬£¬²»¶¨Õë¶ÔÌØ¶¨Êܺ¦Õß¡£¡£¡£¡£¡£ ¡£¡£7ÔÂ6ÈÕ£¬£¬£¬£¬£¬Ingram MicroÕýʽÈϿɹ¥»÷£¬£¬£¬£¬£¬Æô¶¯µ÷²é²¢Í¨Öª·¨Âɲ¿ÃÅ£¬£¬£¬£¬£¬Í¬Ê±ÖÂǸ¿Í»§¼°ºÏ×÷ͬ°é£¬£¬£¬£¬£¬Ä¿Ç°ÕýÖÂÁ¦¸´Ô­ÏµÍ³¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/ingram-micro-outage-caused-by-safepay-ransomware-attack/


6. Telef¨®nicaÔâHellcatºÚ¿Í×éÖ¯Êý¾Ýй¶Íþв£¬£¬£¬£¬£¬¹«Ë¾·ñ¶¨ÊÂÎñ


7ÔÂ4ÈÕ£¬£¬£¬£¬£¬Î÷°àÑÀµçÐŹ«Ë¾Telef¨®nica½üÆÚÔâ·êHellcatÀÕË÷Èí¼þ×éÖ¯³ÉÔ±ReyµÄÊý¾Ýй¶Íþв£¬£¬£¬£¬£¬ºÚ¿ÍÐû³ÆÇÔÈ¡ÁË106GBÊý¾Ý²¢ÒÑй¶5GBÑù±¾£¬£¬£¬£¬£¬µ«¹«Ë¾Ê¼ÖÕδÈÏ¿ÉÊÂÎñÕæÊµÐÔ¡£¡£¡£¡£¡£ ¡£¡£Õâ´ÎÈëÇ־ݳƲúÉúÓÚ5ÔÂ30ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓÃJira·þÎñÆ÷ÅäÖÃÃýÎóÇÖÈ룬£¬£¬£¬£¬³ÖÐø12Ó×ʱ»ñÈ¡Ô̺¬¿Í»§·¢Æ±¡¢Ô±¹¤ÓÊÏäµÈÎļþ£¬£¬£¬£¬£¬Éæ¼°ÐÙÑÀÀû¡¢µÂ¹úµÈ¶à¹úÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÑù±¾ÖÐ×îÐÂÎļþΪ2021Ä꣬£¬£¬£¬£¬ÓëO2Ô±¹¤Ðû³ÆµÄ"¹ýÆÚÐÅϢڲƭ"´æÔÚì¶Ü£¬£¬£¬£¬£¬µ«²¿ÃÅÔÚÈËÔ±¹¤ÓÊÏäÈ·³Ê´Ë¿Ìй¶Êý¾ÝÖУ¬£¬£¬£¬£¬°µÊ¾¿ÉÄÜ´æÔÚзì϶¡£¡£¡£¡£¡£ ¡£¡£Reyͨ¹ýPixelDrainºÍKotizada°ä²¼Êý¾Ý£¬£¬£¬£¬£¬ºóÕß±»ChromeÏóÕ÷ΪΣÏÕÍøÕ¾¡£¡£¡£¡£¡£ ¡£¡£Telef¨®nica¶ÔÂÅ´ÎÁªÏµÎ¬³Ö¹ÑÑÔ£¬£¬£¬£¬£¬½öO2Æ·ÅÆ´ú±í·ñ¶¨ÊÂÎñ¡£¡£¡£¡£¡£ ¡£¡£Hellcat×éÖ¯ÒÔ¹¥»÷Jira·þÎñÆ÷Öø³Æ£¬£¬£¬£¬£¬Ôø¹¥»÷¹ýAscom¡¢½Ý±ªÂ·»¢µÈÆóÒµ£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñÔÙ´Î͹ÏÔ¹©¸øÁ´°²È«·çÏÕ¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/hacker-leaks-telef-nica-data-allegedly-stolen-in-a-new-breach/