ICAOÊÓ²ìDZÔÚÐÅÏ¢Çå¾²ÊÂÎñ£¬£¬£¬Éæ¼°42,000·ÝÎļþй¶

Ðû²¼Ê±¼ä 2025-01-09

1. ICAOÊÓ²ìDZÔÚÐÅÏ¢Çå¾²ÊÂÎñ£¬£¬£¬Éæ¼°42,000·ÝÎļþй¶


1ÔÂ7ÈÕ£¬£¬£¬ÁªºÏ¹ú¹ú¼ÊÃñÓú½¿Õ×éÖ¯£¨ICAO£©Ðû²¼ÕýÔÚÊÓ²ìÒ»ÆðDZÔÚµÄÐÅÏ¢Çå¾²ÊÂÎñ¡£¡£¸Ã×éÖ¯ÊÇÒ»¸ö½¨ÉèÓÚ1944ÄêµÄÕþ¸®¼ä×éÖ¯£¬£¬£¬Óë193¸ö¹ú¼ÒÏàÖú£¬£¬£¬ÖÂÁ¦ÓÚÖÆ¶©Ï໥ÈϿɵÄÊÖÒÕ±ê×¼¡£¡£¾Ý³Æ£¬£¬£¬´Ë´ÎÊÂÎñÓëÒ»¸öÕë¶Ô¹ú¼Ê×éÖ¯µÄÍþвÐÐΪÕßÓйØ¡£¡£Ö»¹ÜICAOδÌṩÏêϸϸ½Ú£¬£¬£¬µ«´ËÉùÃ÷ÊÇÔÚÒ»¸öÃûΪ¡°natohub¡±µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳ÉÏй¶Á˾ݳƴÓICAOÇÔÈ¡µÄ42,000·ÝÎļþÁ½ÌìºóÐû²¼µÄ¡£¡£±»µÁÎļþ¾Ý³Æ°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¬£¬£¬ÈçÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµãÒÔ¼°½ÌÓýºÍ¾ÍÒµÐÅÏ¢¡£¡£´Ëǰ£¬£¬£¬ÁªºÏ¹úÆäËû»ú¹¹Ò²ÔâÊܹýÍøÂç¹¥»÷ºÍÊý¾Ýй¶ÊÂÎñ£¬£¬£¬ÀýÈçÁªºÏ¹úÉú³¤ÍýÏëÊð£¨UNDP£©ºÍÁªºÏ¹úÇéÐÎÍýÏëÊð£¨UNEP£©¡£¡£ÁªºÏ¹úÍøÂçÒ²Ôø¶à´ÎÔâµ½¹¥»÷£¬£¬£¬µ¼ÖÂÔ±¹¤¼Í¼¡¢¿µ½¡°ü¹ÜºÍÉÌÒµÌõÔ¼µÈÊý¾Ýй¶¡£¡£´Ë´ÎICAOµÄÉùÃ÷Åú×¢£¬£¬£¬¸Ã×éÖ¯ÕýÔÚÆð¾¢Ó¦¶ÔDZÔÚµÄÐÅÏ¢Çå¾²Íþв£¬£¬£¬²¢½ÓÄÉÐëÒªµÄÇå¾²²½·¥¡£¡£


https://www.bleepingcomputer.com/news/security/un-aviation-agency-investigating-potential-security-breach/


2. ÌïÄÉÎ÷Öݬɪ¸£ÏØÑ§Ð£ÔâÍøÂç¹¥»÷£¬£¬£¬Ãô¸ÐÊý¾Ýй¶


1ÔÂ7ÈÕ£¬£¬£¬ÌïÄÉÎ÷Öݬɪ¸£ÏØÑ§Ð£½üÆÚÔâÓöÁËÍøÂç¹¥»÷ÊÂÎñ¡£¡£ÏÈÊÇ10ÔÂ19ÈÕ£¬£¬£¬Black SuitÀÕË÷Èí¼þ×éÖ¯Éù³ÆÏ®»÷Á˸ÃѧУ£¬£¬£¬µ«ËæºóѧУ·½Ãæ·ñ¶¨ÁËÕâÒ»Ö¸¿Ø£¬£¬£¬ÌåÏÖÊܹ¥»÷µÄÊÇÁíÒ»ËùѧУ¡£¡£È»¶ø£¬£¬£¬Á½¸ö¶àԺ󣬣¬£¬Rhysida×éÖ¯Ðû²¼È·ÊµÏ®»÷Áˬɪ¸£ÏØÑ§Ð££¬£¬£¬²¢Ð¹Â¶Á˰üÀ¨Ñ§ÉúºÍÔ±¹¤Ãô¸ÐÐÅÏ¢µÄ1.2TBÊý¾ÝÖеÄ60%¡£¡£Ð¹Â¶µÄÊý¾ÝÉæ¼°¿µ½¡¼Í¼¡¢ÌØÊâ½ÌÓý¼Í¼ÒÔ¼°ÈËÁ¦×ÊÔ´²¿Îļþ£¬£¬£¬°üÀ¨´ó×ÚСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¬£¬£¬ÈçÉç»áÇå¾²ºÅÂë¡¢Éí·ÝÖ¤ºÍЧ¹ûµ¥µÈ£¬£¬£¬¸øÑ§Éú¡¢¼Ò³¤ºÍÔ±¹¤´øÀ´ÁËÖØ´óÀ§ÈÅ¡£¡£ÏÖÔÚÉв»ÇåÎúÍþвÐÐΪÕßÊÇ·ñ³öÊÛÁËÊý¾Ý»òÊÇ·ñ»áй¶¸ü¶à¡£¡£Õë¶Ô´ËÇéÐΣ¬£¬£¬ÌáÐѹ«ÖÚ×¢ÖØ±£»£»£» £»¤Ð¡ÎÒ˽¼ÒÒþ˽£¬£¬£¬ÌØÊâÊÇÄêÂú18ËêµÄǰѧÉú¡¢ÏÖÈÎѧÉú¡¢¼Ò³¤ÒÔ¼°ÏÖÈκÍǰÈÎÔ±¹¤£¬£¬£¬Ó¦Á¬Ã¦¶ÔÐÅÓñ¨¸æ¾ÙÐÐÇå¾²¶³½á¡£¡£Í¬Ê±£¬£¬£¬ËùÓÐÈËӦ˼Á¿Ïò¾¯·½±¨°¸£¬£¬£¬²¢Í¨ÖªÒøÐкÍÐÅÓÿ¨¿¯ÐÐÉÌÐÅϢй¶ÇéÐΡ£¡£¸ÃÑ§ÇøÓÚ11ÔÂ25ÈÕÊ״η¢Ã÷ÍøÂçÎó²î£¬£¬£¬ÏÖÔÚÒÑÔÚµÚÈý·½ÍøÂçÇ徲ר¼ÒµÄЭÖúÏÂÕö¿ªÊӲ죬£¬£¬²¢½«Æ¾Ö¤ÊÊÓÃÖ´·¨Í¨ÖªÊÜÓ°ÏìµÄСÎÒ˽¼Ò¡£¡£


https://databreaches.net/2025/01/07/two-ransomware-groups-claimed-they-attacked-rutherford-county-schools-one-leaked-sensitive-records/


3. ÂÌÍå°ü×°¹¤¶Ó¹Ù·½ÁãÊÛµêÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¿Í»§Ö§¸¶ÐÅÏ¢ÔâÇÔÈ¡


1ÔÂ7ÈÕ£¬£¬£¬ÂÌÍå°ü×°¹¤¶ÓÃÀʽ×ãÇò¶Ó½üÆÚÔâÓöÍøÂç¹¥»÷£¬£¬£¬Ò»ÃûÍþвÐÐΪÕßÈëÇÖÁËÆä¹Ù·½ÔÚÏßÁãÊÛµêpackersproshop.com£¬£¬£¬²¢×¢ÈëÁË¿¨Æ¬µÁË¢¾ç±¾£¬£¬£¬ÒÔÇÔÈ¡¿Í»§µÄСÎÒ˽¼ÒºÍÖ§¸¶ÐÅÏ¢¡£¡£¸Ã¶ÓÔÚ10ÔÂ23ÈÕ·¢Ã÷ÈëÇֺ󣬣¬£¬Á¬Ã¦½ûÓÃÁËËùÓнáÕ˺͸¶¿î¹¦Ð§£¬£¬£¬²¢Ô¼ÇëÁËÍâ²¿ÍøÂçÇ徲ר¼Ò¾ÙÐÐÊӲ졣¡£ÊÓ²ìÏÔʾ£¬£¬£¬¶ñÒâ´úÂë¿ÉÄÜÔÚ2024Äê9ÔÂÏÂÑ®ÖÁ10ÔÂÉÏѮʱ´úÇÔÊØÐÅÏ¢£¬£¬£¬µ«Ê¹ÓÃÌØ¶¨Ö§¸¶·½·¨µÄÐÅϢδ±»×èµ²¡£¡£¾­ÊÓ²ìÈ·ÈÏ£¬£¬£¬¶ñÒâ´úÂë¿ÉÄÜÔÊÐíµÚÈý·½Éó²é»ò»ñÈ¡ÔÚÖ¸¶¨ÈÕÆÚ¹æÄ£ÄÚʹÓÃÓÐÏÞ¸¶¿î·½·¨½áÕËʱÊäÈëµÄijЩ¿Í»§ÐÅÏ¢¡£¡£´Ë´Îй¶ÊÂÎñÉæ¼°µÄСÎÒ˽¼ÒºÍÖ§¸¶Êý¾Ý°üÀ¨ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµãÒÔ¼°ÐÅÓÿ¨ÏêÇéµÈ¡£¡£°ü×°¹¤¶ÓÉÐδ͸¶ÊÜÓ°Ïì¿Í»§ÊýÄ¿ºÍÈëÇÖ·½·¨£¬£¬£¬µ«ÎªÊÜÓ°ÏìÓû§ÌṩÈýÄêµÄÐÅÓÃ¼à¿ØºÍÉí·Ý͵ÇÔ»Ö¸´Ð§ÀÍ£¬£¬£¬²¢½¨ÒéËûÃÇ¼à¿ØÕË»§±¨±íÒÔ·Àڲƭ¡£¡£´Ëǰ£¬£¬£¬¾É½ðɽ49È˶ÓÒ²ÔøÔâÓöÀàËÆ¹¥»÷£¬£¬£¬Áè¼Ý20,000ÃûСÎÒ˽¼ÒÐÅÏ¢±»µÁ¡£¡£


https://www.bleepingcomputer.com/news/security/green-bay-packers-online-store-hacked-to-steal-credit-cards/


4. PowerSchoolÔâÓöÍøÂçÇå¾²ÊÂÎñ£¬£¬£¬Ñ§ÉúÎ÷ϯÊý¾ÝÔâÇÔ


1ÔÂ7ÈÕ£¬£¬£¬½ÌÓýÈí¼þ¾ÞÍ·PowerSchoolÔâÓöÁËÒ»ÆðÍøÂçÇå¾²ÊÂÎñ£¬£¬£¬¹¥»÷ÕßʹÓÃÆäPowerSchool SISƽ̨ÇÔÈ¡Á˲¿·ÖÑ§ÇøÑ§ÉúºÍÎ÷ϯµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£PowerSchoolÊÇÒ»¼ÒΪK-12ѧУºÍÑ§ÇøÌṩȫ·½Î»ÔÆÈí¼þ½â¾ö¼Æ»®µÄ¹«Ë¾£¬£¬£¬ÆäЧÀͰüÀ¨ÕÐÉú¡¢Í¨Ñ¶¡¢³öÇڵȶà¸ö·½Ãæ¡£¡£´Ë´Î¹¥»÷±¬·¢ÔÚ2024Äê12ÔÂ28ÈÕ£¬£¬£¬¹¥»÷Õßͨ¹ýPowerSchoolµÄ¿Í»§Ö§³Öƽ̨PowerSource£¬£¬£¬Ê¹ÓÃй¶µÄƾ֤»á¼û²¢µ¼³öÁ˰üÀ¨Ñ§ÉúºÍÎ÷ϯÊý¾ÝµÄCSVÎļþ¡£¡£±»µÁÊý¾ÝÖ÷Òª°üÀ¨ÐÕÃû¡¢µØµãµÈÁªÏµ·½·¨£¬£¬£¬²¿·ÖÑ§ÇøµÄÊý¾Ý»¹¿ÉÄܰüÀ¨Éç»áÇå¾²ºÅÂ롢СÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢ºÍЧ¹û¡£¡£PowerSchoolÇ¿µ÷£¬£¬£¬¿Í»§Æ±Ö¤¡¢Æ¾Ö¤»òÂÛ̳Êý¾ÝδÔÚ´Ë´ÎÊÂÎñÖÐй¶£¬£¬£¬ÇÒ²¢·ÇËùÓпͻ§¶¼ÊÜÓ°Ïì¡£¡£ÎªÓ¦¶Ô´ËÊ£¬£¬£¬PowerSchoolÓëµÚÈý·½ÍøÂçÇ徲ר¼ÒÏàÖú£¬£¬£¬ÂÖ»»ÁËËùÓÐPowerSourceÕÊ»§µÄÃÜÂ룬£¬£¬²¢ÊµÑéÁ˸üÑÏ¿áµÄÃÜÂëÕ½ÂÔ¡£¡£Í¬Ê±£¬£¬£¬PowerSchoolÈ·ÈÏÕâ²»ÊÇÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬µ«Ö§¸¶ÁËÊê½ðÒÔÈ·±£Êý¾Ý±»É¾³ý£¬£¬£¬²¢ÕýÔÚÒ»Á¬¼à¿Ø°µÍøÒÔÈ·¶¨Ãü¾ÝÊÇ·ñÒÑй¶¡£¡£¹ØÓÚÊÜÓ°ÏìµÄÈË£¬£¬£¬PowerSchoolÌṩÁËÐÅÓÃ¼à¿ØºÍÉí·Ý±£»£»£» £»¤Ð§ÀÍ¡£¡£Ö»¹ÜÔâÓöÈëÇÖ£¬£¬£¬PowerSchoolµÄÔËÓª²¢Î´Êܵ½Ó°Ï죬£¬£¬Ð§ÀÍÈÔÕÕ³£¾ÙÐС£¡£


https://www.bleepingcomputer.com/news/security/powerschool-hack-exposes-student-teacher-data-from-k-12-districts/


5. PayPal»ã¿îÇëÇó¹¦Ð§ÔâÐÂÐÍÍøÂç´¹ÂÚÊÖÒÕʹÓÃ


1ÔÂ8ÈÕ£¬£¬£¬Ò»ÖÖÐÂÐÍÍøÂç´¹ÂÚÊÖÒÕʹÓÃPayPal»ã¿îÇëÇó¹¦Ð§¾ÙÐÐÕ©Æ­£¬£¬£¬¸ÃÊÖÒÕͨ¹ý·¢ËÍ¿´ËÆÕæÊµµÄÕýµ±PayPal»ã¿îÇëÇóÀ´ÓÕÆ­ÊÕ¿îÈË¡£¡£Õ©Æ­ÕßʹÓÃMicrosoft 365²âÊÔÓò½¨Éè·Ö·¢Áбí£¬£¬£¬²¢Í¨¹ýPayPalÏò¸ÃÁÐ±í·¢Ë͸¶¿îÇëÇ󡣡£ÓÉÓÚ΢ÈíµÄ·¢¼þÈËÖØÐ´¼Æ»®ºÍPayPalµÄÇå¾²¼ì²é£¬£¬£¬ÕâЩÇëÇóÔÚµç×ÓÓʼþ¡¢URLºÍ·¢¼þÈ˵صãÉ϶¼ÏÔµÃÕýµ±¡£¡£Ò»µ©ÊÕ¼þÈ˵ã»÷Á´½Ó²¢µÇ¼PayPalÕË»§£¬£¬£¬Õ©Æ­Õß¾ÍÄÜ»ñÈ¡ÕË»§»á¼ûȨÏÞ¡£¡£Oasis SecurityÑо¿Ö÷¹ÜÖ¸³ö£¬£¬£¬ÕâÖÖʹÓù©Ó¦É̹¦Ð§×ª´ïÐÂÎŵķ½·¨Ê¹µÃÓÊÏäÌṩÉÌÄÑÒÔÇø·ÖÕæ¼ÙͨѶ£¬£¬£¬PayPal¿ÉÄܳÉΪΨһÄܹ»»º½â´ËÎÊÌâµÄʵÌå¡£¡£ÎªÁË·ÀÓù´ËÀàÍþв£¬£¬£¬FortinetÇ¿µ÷ѵÁ·ÓÐËØµÄÈËÈâ·À»ðǽµÄÖ÷ÒªÐÔ£¬£¬£¬½¨Òé½ÌÓýÔ±¹¤×ÐϸÉó²éËùÓÐÒâÍ⸶¿îÇëÇ󡣡£±ðµÄ£¬£¬£¬Ê¹ÓÃÊý¾Ýɥʧ·À»¤¹æÔòºÍÏȽøµÄÈ˹¤ÖÇÄÜÊÖÒÕÀ´ÆÊÎöÓû§ÐÐΪҲÓÐÖúÓÚ·¢Ã÷ºÍ×èÖ¹ÕâÐ©ÍøÂç´¹ÂÚʵÑé¡£¡£


https://www.infosecurity-magazine.com/news/scammers-exploit-microsoft365/


6. Öж«ÍË¿îÕ©Æ­£ºÍøÂç·¸·¨·Ö×ÓʹÓÃÔ¶³Ì»á¼û¹¤¾ßÇÔÊØÐÅÏ¢


1ÔÂ8ÈÕ£¬£¬£¬Öж«µØÇø½üÆÚ·ºÆðÁËÒ»ÖÖÖØ´óµÄÍøÂçÕ©Æ­£¬£¬£¬Õ©Æ­Õßð³äÕþ¸®¹ÙÔ±£¬£¬£¬Í¨¹ýµç»°ÁªÏµÄÇÐ©ÔøÏòÕþ¸®Ð§ÀÍÃÅ»§ÍøÕ¾ÌύͶËßµÄСÎÒ˽¼Ò£¬£¬£¬ÒÔ×ÊÖúËûÃÇ»ñÈ¡²»Öª×ãµÄ¹ºÎïÍ˿¡£Õ©Æ­ÕßÒªÇóÊܺ¦ÕßÏÂÔØÕýµ±µÄÔ¶³Ì»á¼ûÈí¼þÈçAnyDesk»òTeamViewer£¬£¬£¬²¢ÔÚÊܺ¦Õß²»ÖªÇéµÄÇéÐÎÏ»ñÈ¡Æä×°±¸µÄ»á¼ûȨÏÞ£¬£¬£¬´Ó¶øÇÔȡСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢£¬£¬£¬°üÀ¨ÐÅÓÿ¨ÏêϸÐÅÏ¢ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£¡£¾ÝÔ¤¼Æ£¬£¬£¬Ã¿±ÊÉúÒâµÄƽ¾ùËðʧԼΪ1,300ÃÀÔª£¬£¬£¬ÓÐЩÊܺ¦ÕßÉõÖÁËðʧ¸ß´ï5,000ÃÀÔª¡£¡£¸ÃȦÌ×µÄÓÐÓÃÐÔÅú×¢¿ÉÄÜÓÐÄÚ²¿Ö°Ô±¼ÓÈ룬£¬£¬ÓÉÓÚÕ©Æ­ÕßËÆºõÄܹ»»á¼ûÕþ¸®Í¶ËßÊý¾Ý¡£¡£ÎªÌá·À´ËÀàÕ©Æ­£¬£¬£¬Ð¡ÎÒ˽¼ÒÓ¦ÉóÉ÷¿´´ýÕþ¸®¹ÙÔ±µÄδ¾­ÇëÇóµÄµç»°£¬£¬£¬×èÖ¹ÏÂÔØÔ¶³Ì»á¼ûÈí¼þ»ò·ÖÏíÃô¸ÐÐÅÏ¢¡£¡£Í¬Ê±£¬£¬£¬Õþ¸®ºÍ½ðÈÚ»ú¹¹Ò²Ó¦ÔöÇ¿Çå¾²²½·¥£¬£¬£¬½ÌÓý¹«ÖÚÏàʶÉç»á¹¤³ÌΣº¦¡£¡£AnyDeskºÍTeamViewerµÈ¹¤¾ßËäÔ­±¾ÓÃÓÚÕýµ±Ô®Öú£¬£¬£¬µ«ÂäÈëÕ©Æ­ÕßÊÖÖкó³ÉÎªÖØ´óÍþв£¬£¬£¬Òò´ËÐèÌá¸ßСÐÄ¡£¡£


https://hackread.com/scammers-impersonate-swipe-otps-remote-access-apps/