ICAOÊÓ²ìDZÔÚÐÅÏ¢Äþ¾²Ê¼þ£¬Éæ¼°42,000·ÝÎļþй¶

Ðû²¼Ê±¼ä 2025-01-09

1. ICAOÊÓ²ìDZÔÚÐÅÏ¢Äþ¾²Ê¼þ£¬Éæ¼°42,000·ÝÎļþй¶


1ÔÂ7ÈÕ£¬ÁªºÏ¹ú¹ú¼ÊÃñÓú½¿Õ×éÖ¯£¨ICAO£©Ðû²¼ÕýÔÚÊÓ²ìÒ»ÆðDZÔÚµÄÐÅÏ¢Äþ¾²Ê¼þ¡£¸Ã×éÖ¯ÊÇÒ»¸ö½¨Á¢ÓÚ1944ÄêµÄÕþ¸®¼ä×éÖ¯£¬Óë193¸ö¹ú¼ÒºÏ×÷£¬ÖÂÁ¦ÓÚÖƶ¨Ï໥ÈϿɵļ¼Êõ³ß¶È¡£¾Ý³Æ£¬´Ë´ÎʼþÓëÒ»¸öÕë¶Ô¹ú¼Ê×éÖ¯µÄÍþвÐÐΪÕßÓйØ¡£¾¡¹ÜICAOδÌṩ¾ßÌåϸ½Ú£¬µ«´ËÉùÃ÷ÊÇÔÚÒ»¸öÃûΪ¡°natohub¡±µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳ÉÏй¶Á˾ݳƴÓICAOÇÔÈ¡µÄ42,000·ÝÎļþÁ½ÌìºóÐû²¼µÄ¡£±»µÁÎļþ¾Ý³Æ°üÂÞ¸öÈËÉí·ÝÐÅÏ¢£¬ÈçÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°½ÌÓýºÍ¾ÍÒµÐÅÏ¢¡£´ËÇ°£¬ÁªºÏ¹úÆäËû»ú¹¹Ò²ÔâÊܹýÍøÂç¹¥»÷ºÍÊý¾Ýй¶Ê¼þ£¬ÀýÈçÁªºÏ¹úÉú³¤¼Æ»®Êð£¨UNDP£©ºÍÁªºÏ¹ú»·¾³¹æ»®Êð£¨UNEP£©¡£ÁªºÏ¹úÍøÂçÒ²Ôø¶à´ÎÔâµ½¹¥»÷£¬µ¼ÖÂÔ±¹¤¼Ç¼¡¢½¡¿µ±£ÏÕºÍÉÌÒµºÏͬµÈÊý¾Ýй¶¡£´Ë´ÎICAOµÄÉùÃ÷±íÃ÷£¬¸Ã×éÖ¯ÕýÔÚ»ý¼«Ó¦¶ÔDZÔÚµÄÐÅÏ¢Äþ¾²Íþв£¬²¢½ÓÄÉÐëÒªµÄÄþ¾²´ëÊ©¡£


https://www.bleepingcomputer.com/news/security/un-aviation-agency-investigating-potential-security-breach/


2. ÌïÄÉÎ÷Öݬɪ¸£ÏØѧУÔâÍøÂç¹¥»÷£¬Ãô¸ÐÊý¾Ýй¶


1ÔÂ7ÈÕ£¬ÌïÄÉÎ÷Öݬɪ¸£ÏØѧУ½üÆÚÔâÓöÁËÍøÂç¹¥»÷ʼþ¡£ÏÈÊÇ10ÔÂ19ÈÕ£¬Black SuitÀÕË÷Èí¼þ×éÖ¯Éù³ÆÏ®»÷Á˸ÃѧУ£¬µ«ËæºóѧУ·½Ãæ·ñÈÏÁËÕâÒ»Ö¸¿Ø£¬ÌåÏÖÊܹ¥»÷µÄÊÇÁíÒ»ËùѧУ¡£È»¶ø£¬Á½¸ö¶àÔºó£¬Rhysida×éÖ¯Ðû²¼È·ÊµÏ®»÷Áˬɪ¸£ÏØѧУ£¬²¢Ð¹Â¶ÁË°üÂÞѧÉúºÍÔ±¹¤Ãô¸ÐÐÅÏ¢µÄ1.2TBÊý¾ÝÖеÄ60%¡£Ð¹Â¶µÄÊý¾ÝÉæ¼°½¡¿µ¼Ç¼¡¢ÌØÊâ½ÌÓý¼Ç¼ÒÔ¼°ÈËÁ¦×ÊÔ´²¿Îļþ£¬°üÂÞ´óÁ¿¸öÈËÉí·ÝÐÅÏ¢£¬ÈçÉç»áÄþ¾²ºÅÂë¡¢Éí·ÝÖ¤ºÍ½á¹ûµ¥µÈ£¬¸øѧÉú¡¢¼Ò³¤ºÍÔ±¹¤´øÀ´Á˾޴óÀ§ÈÅ¡£Ä¿Ç°Éв»Çå³þÍþвÐÐΪÕßÊÇ·ñ³öÊÛÁËÊý¾Ý»òÊÇ·ñ»áй¶¸ü¶à¡£Õë¶Ô´ËÇé¿ö£¬ÌáÐѹ«ÖÚ×¢Òâ±£»¤¸öÈËÒþ˽£¬ÌرðÊÇÄêÂú18ËêµÄǰѧÉú¡¢ÏÖÈÎѧÉú¡¢¼Ò³¤ÒÔ¼°ÏÖÈκÍÇ°ÈÎÔ±¹¤£¬Ó¦Á¢¼´¶ÔÐÅÓóÂËß½øÐÐÄþ¾²¶³½á¡£Í¬Ê±£¬ËùÓÐÈËÓ¦¿¼ÂÇÏò¾¯·½±¨°¸£¬²¢Í¨ÖªÒøÐкÍÐÅÓÿ¨¿¯ÐÐÉÌÐÅϢй¶Çé¿ö¡£¸ÃѧÇøÓÚ11ÔÂ25ÈÕÊ״η¢ÏÖÍøÂ究´£¬Ä¿Ç°ÒÑÔÚµÚÈý·½ÍøÂçÄþ¾²×¨¼ÒµÄЭÖúÏÂÕ¹¿ªÊӲ죬²¢½«Æ¾¾ÝÊÊÓÃÖ´·¨Í¨ÖªÊÜÓ°ÏìµÄ¸öÈË¡£


https://databreaches.net/2025/01/07/two-ransomware-groups-claimed-they-attacked-rutherford-county-schools-one-leaked-sensitive-records/


3. ÂÌÍå°ü×°¹¤¶Ó¹Ù·½ÁãÊÛµêÔâºÚ¿ÍÈëÇÖ£¬¿Í»§Ö§¸¶ÐÅÏ¢ÔâÇÔÈ¡


1ÔÂ7ÈÕ£¬ÂÌÍå°ü×°¹¤¶ÓÃÀʽ×ãÇò¶Ó½üÆÚÔâÓöÍøÂç¹¥»÷£¬Ò»ÃûÍþвÐÐΪÕßÈëÇÖÁËÆä¹Ù·½ÔÚÏßÁãÊÛµêpackersproshop.com£¬²¢×¢ÈëÁË¿¨Æ¬µÁË¢½Å±¾£¬ÒÔÇÔÈ¡¿Í»§µÄ¸öÈ˺ÍÖ§¸¶ÐÅÏ¢¡£¸Ã¶ÓÔÚ10ÔÂ23ÈÕ·¢ÏÖÈëÇÖºó£¬Á¢¼´½ûÓÃÁËËùÓнáÕ˺͸¶¿î¹¦Ð§£¬²¢Æ¸ÇëÁËÍⲿÍøÂçÄþ¾²×¨¼Ò½øÐÐÊӲ졣ÊÓ²ìÏÔʾ£¬¶ñÒâ´úÂë¿ÉÄÜÔÚ2024Äê9ÔÂÏÂÑ®ÖÁ10ÔÂÉÏÑ®ÆÚ¼äÇÔÈ¡ÐÅÏ¢£¬µ«Ê¹ÓÃÌض¨Ö§¸¶·½Ê½µÄÐÅϢδ±»À¹½Ø¡£¾­ÊÓ²ìÈ·ÈÏ£¬¶ñÒâ´úÂë¿ÉÄÜÔÊÐíµÚÈý·½¼ì²ì»ò»ñÈ¡ÔÚÖ¸¶¨ÈÕÆÚ·¶Î§ÄÚʹÓÃÓÐÏÞ¸¶¿î·½Ê½½áÕËʱÊäÈëµÄijЩ¿Í»§ÐÅÏ¢¡£´Ë´Îй¶Ê¼þÉæ¼°µÄ¸öÈ˺ÍÖ§¸¶Êý¾Ý°üÂÞÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°ÐÅÓÿ¨ÏêÇéµÈ¡£°ü×°¹¤¶ÓÉÐδ͸¶ÊÜÓ°Ïì¿Í»§ÊýÁ¿ºÍÈëÇÖ·½Ê½£¬µ«ÎªÊÜÓ°ÏìÓû§ÌṩÈýÄêµÄÐÅÓüà¿ØºÍÉí·Ý͵ÇÔ»Ö¸´·þÎñ£¬²¢½¨ÒéËûÃǼà¿ØÕË»§±¨±íÒÔ·ÀÆÛÕ©¡£´ËÇ°£¬¾É½ðɽ49È˶ÓÒ²ÔøÔâÓöÀàËƹ¥»÷£¬Áè¼Ý20,000Ãû¸öÈËÐÅÏ¢±»µÁ¡£


https://www.bleepingcomputer.com/news/security/green-bay-packers-online-store-hacked-to-steal-credit-cards/


4. PowerSchoolÔâÓöÍøÂçÄþ¾²Ê¼þ£¬Ñ§Éú½ÌʦÊý¾ÝÔâÇÔ


1ÔÂ7ÈÕ£¬½ÌÓýÈí¼þ¾ÞÍ·PowerSchoolÔâÓöÁËÒ»ÆðÍøÂçÄþ¾²Ê¼þ£¬¹¥»÷ÕßÀûÓÃÆäPowerSchool SISƽ̨ÇÔÈ¡Á˲¿ÃÅѧÇøѧÉúºÍ½ÌʦµÄ¸öÈËÐÅÏ¢¡£PowerSchoolÊÇÒ»¼ÒΪK-12ѧУºÍѧÇøÌṩȫ·½Î»ÔÆÈí¼þ½â¾ö·½°¸µÄ¹«Ë¾£¬Æä·þÎñ°üÂÞÕÐÉú¡¢Í¨ÐÅ¡¢³öÇڵȶà¸ö·½Ãæ¡£´Ë´Î¹¥»÷·¢ÉúÔÚ2024Äê12ÔÂ28ÈÕ£¬¹¥»÷Õßͨ¹ýPowerSchoolµÄ¿Í»§Ö§³Öƽ̨PowerSource£¬Ê¹ÓÃ鶵Äƾ֤·ÃÎʲ¢µ¼³öÁË°üÂÞѧÉúºÍ½ÌʦÊý¾ÝµÄCSVÎļþ¡£±»µÁÊý¾ÝÖ÷Òª°üÂÞÐÕÃû¡¢µØÖ·µÈÁªÏµ·½Ê½£¬²¿ÃÅѧÇøµÄÊý¾Ý»¹¿ÉÄÜ°üÂÞÉç»áÄþ¾²ºÅÂë¡¢¸öÈËÉí·ÝÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢ºÍ½á¹û¡£PowerSchoolÇ¿µ÷£¬¿Í»§Æ±Ö¤¡¢Æ¾Ö¤»òÂÛ̳Êý¾ÝδÔÚ´Ë´ÎʼþÖÐй¶£¬ÇÒ²¢·ÇËùÓпͻ§¶¼ÊÜÓ°Ï졣ΪӦ¶Ô´ËÊ£¬PowerSchoolÓëµÚÈý·½ÍøÂçÄþ¾²×¨¼ÒºÏ×÷£¬ÂÖ»»ÁËËùÓÐPowerSourceÕÊ»§µÄÃÜÂ룬²¢ÊµÊ©Á˸üÑϸñµÄÃÜÂë¼Æı¡£Í¬Ê±£¬PowerSchoolÈ·ÈÏÕâ²»ÊÇÀÕË÷Èí¼þ¹¥»÷£¬µ«Ö§¸¶ÁËÊê½ðÒÔÈ·±£Êý¾Ý±»É¾³ý£¬²¢ÕýÔÚÁ¬Ðø¼à¿Ø°µÍøÒÔÈ·¶¨Êý¾ÝÊÇ·ñÒÑй¶¡£¶ÔÓÚÊÜÓ°ÏìµÄÈË£¬PowerSchoolÌṩÁËÐÅÓüà¿ØºÍÉí·Ý±£»¤·þÎñ¡£¾¡¹ÜÔâÓöÈëÇÖ£¬PowerSchoolµÄÔËÓª²¢Î´Êܵ½Ó°Ï죬·þÎñÈÔÕÕ³£½øÐС£


https://www.bleepingcomputer.com/news/security/powerschool-hack-exposes-student-teacher-data-from-k-12-districts/


5. PayPal»ã¿îÇëÇó¹¦Ð§ÔâÐÂÐÍÍøÂçµöÓã¼¼ÊõÀûÓÃ


1ÔÂ8ÈÕ£¬Ò»ÖÖÐÂÐÍÍøÂçµöÓã¼¼ÊõÀûÓÃPayPal»ã¿îÇëÇó¹¦Ð§½øÐÐÕ©Æ­£¬¸Ã¼¼Êõͨ¹ý·¢ËÍ¿´ËÆÕæʵµÄºÏ·¨PayPal»ã¿îÇëÇóÀ´ÓÕÆ­ÊÕ¿îÈË¡£Õ©Æ­ÕßÀûÓÃMicrosoft 365²âÊÔÓò´´½¨·Ö·¢Áбí£¬²¢Í¨¹ýPayPalÏò¸ÃÁÐ±í·¢Ë͸¶¿îÇëÇó¡£ÓÉÓÚ΢ÈíµÄ·¢¼þÈËÖØд·½°¸ºÍPayPalµÄÄþ¾²¼ì²é£¬ÕâЩÇëÇóÔÚµç×ÓÓʼþ¡¢URLºÍ·¢¼þÈ˵ØÖ·É϶¼ÏԵúϷ¨¡£Ò»µ©ÊÕ¼þÈ˵ã»÷Á´½Ó²¢µÇ¼PayPalÕË»§£¬Õ©Æ­Õß¾ÍÄÜ»ñÈ¡ÕË»§·ÃÎÊȨÏÞ¡£Oasis SecurityÑо¿Ö÷¹ÜÖ¸³ö£¬ÕâÖÖÀûÓù©Ó¦É̹¦Ð§Í¨±¨ÏûÏ¢µÄ·½Ê½Ê¹µÃÓÊÏäÌṩÉÌÄÑÒÔÇø·ÖÕæ¼ÙͨÐÅ£¬PayPal¿ÉÄܳÉΪΨһÄܹ»»º½â´ËÎÊÌâµÄʵÌ塣ΪÁË·ÀÓù´ËÀàÍþв£¬FortinetÇ¿µ÷ѵÁ·ÓÐËصÄÈËÈâ·À»ðǽµÄÖØÒªÐÔ£¬½¨Òé½ÌÓýÔ±¹¤×ÐϸÉó²éËùÓÐÒâÍ⸶¿îÇëÇó¡£´ËÍ⣬ʹÓÃÊý¾Ý¶ªÊ§·À»¤¹æÔòºÍÏȽøµÄÈ˹¤ÖÇÄܼ¼ÊõÀ´·ÖÎöÓû§ÐÐΪҲÓÐÖúÓÚ·¢ÏÖºÍ×èÖ¹ÕâЩÍøÂçµöÓãʵÑé¡£


https://www.infosecurity-magazine.com/news/scammers-exploit-microsoft365/


6. Öж«ÍË¿îÕ©Æ­£ºÍøÂç·¸×ï·Ö×ÓÀûÓÃÔ¶³Ì·ÃÎʹ¤¾ßÇÔÈ¡ÐÅÏ¢


1ÔÂ8ÈÕ£¬Öж«µØÓò½üÆÚ·ºÆðÁËÒ»ÖÖÅÓ´óµÄÍøÂçÕ©Æ­£¬Õ©Æ­Õßð³äÕþ¸®¹ÙÔ±£¬Í¨¹ýµç»°ÁªÏµÄÇЩÔøÏòÕþ¸®·þÎñÃÅ»§ÍøÕ¾ÌύͶËߵĸöÈË£¬ÒÔ×ÊÖúËûÃÇ»ñÈ¡²»ÂúÒâµÄ¹ºÎïÍË¿î¡£Õ©Æ­ÕßÒªÇóÊܺ¦ÕßÏÂÔغϷ¨µÄÔ¶³Ì·ÃÎÊÈí¼þÈçAnyDesk»òTeamViewer£¬²¢ÔÚÊܺ¦Õß²»ÖªÇéµÄÇé¿öÏ»ñÈ¡ÆäÉ豸µÄ·ÃÎÊȨÏÞ£¬´Ó¶øÇÔÈ¡¸öÈ˺ͲÆÕþÐÅÏ¢£¬°üÂÞÐÅÓÿ¨ÏêϸÐÅÏ¢ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£¾ÝÔ¤¼Æ£¬Ã¿±Ê½»Ò×µÄƽ¾ùËðʧԼΪ1,300ÃÀÔª£¬ÓÐЩÊܺ¦ÕßÉõÖÁËðʧ¸ß´ï5,000ÃÀÔª¡£¸ÃÆ­¾ÖµÄÓÐЧÐÔ±íÃ÷¿ÉÄÜÓÐÄÚ²¿ÈËÔ±¼ÓÈ룬ÒòΪթƭÕßËƺõÄܹ»·ÃÎÊÕþ¸®Í¶ËßÊý¾Ý¡£Îª·À·¶´ËÀàÕ©Æ­£¬¸öÈËÓ¦½÷É÷¿´´ýÕþ¸®¹ÙÔ±µÄδ¾­ÇëÇóµÄµç»°£¬ÖÆÖ¹ÏÂÔØÔ¶³Ì·ÃÎÊÈí¼þ»ò·ÖÏíÃô¸ÐÐÅÏ¢¡£Í¬Ê±£¬Õþ¸®ºÍ½ðÈÚ»ú¹¹Ò²Ó¦¼ÓÇ¿Äþ¾²´ëÊ©£¬½ÌÓý¹«ÖÚÁ˽âÉç»á¹¤³Ì·çÏÕ¡£AnyDeskºÍTeamViewerµÈ¹¤¾ßËäÔ­±¾ÓÃÓںϷ¨Ô®Öú£¬µ«ÂäÈëÕ©Æ­ÕßÊÖÖкó³ÉΪÖØ´óÍþв£¬Òò´ËÐèÌá¸ß¾¯Ìè¡£


https://hackread.com/scammers-impersonate-swipe-otps-remote-access-apps/