¹úÄÚÍâÊý¾Ý»Æ½ð³Ç¹ÙÍøÏà¹ØÊ¼þ
3.1.¹úÍâÊý¾Ý»Æ½ð³Ç¹ÙÍøÏà¹ØÊ¼þ
3.1.1.TicketToCashÊý¾Ý¿âÅäÖôíÎóÖÂ52Íò¿Í»§Êý¾Ýй¶
5ÔÂ1ÈÕ£¬ÍøÂç»Æ½ð³Ç¹ÙÍøÑо¿Ô±Jeremiah Fowler½üÈÕ·¢ÏÖ£¬»î¶¯ÃÅÆ±×ªÊÛÆ½Ì¨TicketToCashµÄÒ»¸öÅäÖôíÎó¡¢ÎÞÃÜÂë±£»¤µÄ200GB¹«¿ªÊý¾Ý¿âй¶¡£¸ÃÊý¾Ý¿â°üº¬³¬¹ý52ÍòÌõ¼Ç¼£¬Éæ¼°¿Í»§µÄÐÕÃûºÍµç×ÓÓʼþµØÖ·µÈ¸öÈËÉí·ÝÐÅÏ¢£¨PII£©¼°²¿·ÖÐÅÓÿ¨ºÅ¡¢Êµ¼ÊµØÖ·¡¢Æ±Ö¤¸±±¾µÈ²ÆÎñÏêϸÐÅÏ¢¡£
À´Ô´£º
https://hackread.com/ticket-resale-platform-tickettocash-exposed-user-data/
3.1.2.AscensionÊý¾Ýй¶ӰÏ쳬43ÍòÃû»¼Õß
5ÔÂ9ÈÕ£¬ÃÀ¹úAscensionÒ½ÁƱ£½¡ÏµÍ³½üÈÕ͸¶£¬ÉϸöÔ·¢ÉúÁËÒ»ÆðÖØ´óÊý¾Ýй¶Ê¼þ£¬³¬¹ý43ÍòÃû»¼ÕߵĸöÈ˺ÍÒ½ÁƱ£½¡ÐÅÏ¢Ô⵽й¶¡£¹¥»÷Õß»ñÈ¡ÁËÓ뻼ÕßסԺ¾ÍÕïÏà¹ØµÄ¸öÈ˽¡¿µÐÅÏ¢£¬ÈçÒ½ÉúÐÕÃû¡¢ÈëÔººÍ³öÔºÈÕÆÚ¡¢Õï¶ÏºÍÕ˵¥´úÂëµÈ£¬»¹°üÀ¨»¼ÕߵĸöÈËÐÅÏ¢£¬ÈçÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢³öÉúÈÕÆÚ¡¢ÖÖ×å¡¢ÐÔ±ðºÍÉç»á»Æ½ð³Ç¹ÙÍøºÅÂëµÈ¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/ascension-says-recent-data-breach-affects-over-430-000-patients/
3.1.3.PrepHeroÊý¾Ý¿âй¶300ÍòѧÉúºÍ½ÌÁ·Êý¾Ý
5ÔÂ13ÈÕ£¬´óѧÕÐÉúƽ̨PrepHeroÆØ³öÖØ´ó»Æ½ð³Ç¹ÙÍøÂ©¶´£¬³¬Èý°ÙÍòÌõδ¼ÓÃܼǼÔâй¶£¬É漰ѧÉúÔ˶¯Ô±¼°Æä½ÌÁ·Ãô¸ÐÐÅÏ¢¡£¸ÃÊý¾Ý¿âÓÉÖ¥¼Ó¸ç¹«Ë¾PrepHero£¨ÓÉEXACT SportsÔËÓª£©ËùÓУ¬ÓÃÓÚ°ïÖú¸ßÖÐÔ˶¯Ô±´´½¨ÕÐļµµ°¸²¢Óë´óѧ½ÌÁ·¹µÍ¨¡£Êý¾Ý¿â°üº¬315ÍòÓàÌõ¼Ç¼£¬×ܼÆÔ¼135GB£¬ÐÅÏ¢º¸ÇѧÉúÔ˶¯Ô±µÄÐÕÃû¡¢µç»°¡¢ÓÊÏä¡¢¼Òͥסַ¡¢»¤ÕÕÐÅÏ¢£¬ÒÔ¼°¼Ò³¤ºÍ½ÌÁ·ÁªÏµ·½Ê½£¬ÉõÖÁ°üº¬Ñ§ÉúÔ˶¯Ô±»¤ÕÕͼÏñÁ´½ÓµÄδÊܱ£»¤Îļþ¡£ÓÈΪÑÏÖØµÄÊÇ£¬Êý¾Ý¿âÖС°Óʼþ»º´æ¡±Îļþ¼Ð±£´æÁË2017ÄêÖÁ2025ÄêµÄ10GBµç×ÓÓʼþ£¬°üº¬¸öÐÔ»¯ÍøÒ³Á´½Ó£¬¿É¹«¿ª·ÃÎʸöÈËÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Ð½³êµÈÏêϸÐÅÏ¢£¬²¿·ÖÓʼþ»¹º¬ÓÐÁÙʱÃÜÂ룬½øÒ»²½¼Ó¾çÒþ˽·çÏÕ¡£´ËÍ⣬½ÌÁ·Ô±Â¼ÒôÒ²±»·¢ÏÖ£¬Éæ¼°½ÌÁ·ÐÕÃû¡¢ËùÔÚ´óѧ¼°¶ÔѧÉúÔ˶¯Ô±µÄÆÀ¹À¡£
À´Ô´£º
https://hackread.com/prephero-database-exposed-students-coaches-data/
3.1.4.ÕÐÆ¸Æ½Ì¨HireClick570Íò·Ý¼òÀúÔâй¶
5ÔÂ15ÈÕ£¬CybernewsÑо¿ÈËÔ±½üÈÕ·¢ÏÖÒ»Æð´ó¹æÄ£Êý¾Ýй¶Ê¼þ£¬¸ùÔ´Ö¸ÏòÃæÏòÖÐСÐÍÆóÒµµÄÕÐÆ¸Æ½Ì¨HireClick¡£ÓÉÓÚÑÇÂíÑ·AWS S3´æ´¢Í°ÅäÖôíÎó£¬¸ÃÆ½Ì¨³¬¹ý570Íò·ÝÎļþ±»±©Â¶ÔÚ»¥ÁªÍøÉÏ£¬ÆäÖÐÖ÷ÒªÊÇÇóÖ°ÕߵļòÀú£¬ÕâЩÎļþй¶ÁËÇóÖ°ÕßµÄÈ«Ãû¡¢¼Òͥסַ¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¼°¾ÍÒµÐÅÏ¢µÈÃô¸ÐºÍ˽ÈËÊý¾Ý¡£
À´Ô´£º
https://cybernews.com/security/hireclick-resume-database-data-leak/
3.1.5.ServiceaidÅäÖôíÎóÖÂCatholic Health½ü50Íò»¼ÕßÐÅϢй¶
5ÔÂ19ÈÕ£¬ÆóÒµITÌṩÉÌServiceaideÒòÊý¾Ý¿âÅäÖôíÎ󣬵¼ÖÂÓëŦԼ·ÇÓªÀûÐÔÒ½ÁƱ£½¡ÏµÍ³Catholic HealthÏà¹ØµÄÔ¼483126Ãû»¼ÕßÃô¸Ð½¡¿µºÍ¸öÈËÐÅϢй¶¡£Ð¹Â¶µÄÊý¾Ý¿â°üº¬´óÁ¿Ãô¸ÐÐÅÏ¢£¬ÈçÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢´¦·½Êý¾Ý¡¢Éç»á»Æ½ð³Ç¹ÙÍøºÅÂë¡¢½¡¿µ±£ÏÕÏêÇé¡¢Ò½ÁƱ£½¡ÌṩÕßÐÅÏ¢¡¢ÖÎÁƺÍÁÙ´²ÐÅÏ¢¡¢Ò½ÁƼǼºÍÕ˺ÅÒÔ¼°µç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃÜÂëµÈ¡£
À´Ô´£º
https://hackread.com/serviceaide-leak-catholic-health-patients-records/
4.1.¹úÄÚÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.1.1.ÖÐÑëÍøÐŰìͨ±¨15¿îAppºÍ16¿îSDK¸öÈËÐÅÏ¢ÊÕ¼¯Ê¹ÓÃÎÊÌâ
¸ù¾ÝÖÐÑëÍøÐŰ졢¹¤ÒµºÍÐÅÏ¢»¯²¿¡¢¹«°²²¿¡¢Êг¡¼à¹Ü×ܾÖÁªºÏ·¢²¼µÄ¡¶¹ØÓÚ¿ªÕ¹2025Äê¸öÈËÐÅÏ¢±£»¤ÏµÁÐרÏîÐж¯µÄ¹«¸æ¡·£¬ÒÀ¾Ý¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶ÖлªÈËÃñ¹²ºÍ¹ú¸öÈËÐÅÏ¢±£»¤·¨¡·¡¶ÍøÂçÊý¾Ý»Æ½ð³Ç¹ÙÍø¹ÜÀíÌõÀý¡·¡¶AppÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢ÐÐΪÈ϶¨·½·¨¡·µÈ·¨ÂÉ·¨¹æºÍÓйع涨£¬ÖÐÑëÍøÐŰì×éÖ¯¶ÔApp¡¢SDKÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢ÐÐΪ½øÐмì²â£¬¶ÔÓйØÎÊÌâÓèÒÔͨ±¨¡£
À´Ô´£º
https://www.cac.gov.cn/2025-05/06/c_1748239411359045.htm
4.1.2.¹«°²²¿¼ÆËã»úÐÅϢϵͳ»Æ½ð³Ç¹ÙÍø²úÆ·ÖÊÁ¿¼à¶½¼ìÑéÖÐÐļì²â·¢ÏÖ35¿îÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢µÄÒÆ¶¯Ó¦ÓÃ
ÒÀ¾Ý¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶¸öÈËÐÅÏ¢±£»¤·¨¡·µÈ·¨ÂÉ·¨¹æ£¬°´ÕÕ¡¶ÖÐÑëÍøÐŰ졢¹¤ÒµºÍÐÅÏ¢»¯²¿¡¢¹«°²²¿¡¢Êг¡¼à¹Ü×ֹܾØÓÚ¿ªÕ¹2025Äê¸öÈËÐÅÏ¢±£»¤ÏµÁÐרÏîÐж¯µÄ¹«¸æ¡·ÒªÇ󣬾¹«°²²¿¼ÆËã»úÐÅϢϵͳ»Æ½ð³Ç¹ÙÍø²úÆ·ÖÊÁ¿¼à¶½¼ìÑéÖÐÐļì²â£¬ÔÚÓ¦Óñ¦ÖÐ35¿îÒÆ¶¯Ó¦ÓôæÔÚÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢Çé¿ö¡£
https://mp.weixin.qq.com/s/4JB4OJw3yDWKh_9Fe2-klQ
4.1.3.¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐļì²â·¢ÏÖ65¿îÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢µÄÒÆ¶¯Ó¦ÓÃ
ÒÀ¾Ý¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶¸öÈËÐÅÏ¢±£»¤·¨¡·µÈ·¨ÂÉ·¨¹æ£¬°´ÕÕ¡¶ÖÐÑëÍøÐŰ졢¹¤ÒµºÍÐÅÏ¢»¯²¿¡¢¹«°²²¿¡¢Êг¡¼à¹Ü×ֹܾØÓÚ¿ªÕ¹2025Äê¸öÈËÐÅÏ¢±£»¤ÏµÁÐרÏîÐж¯µÄ¹«¸æ¡·ÒªÇ󣬾¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐļì²â£¬65¿îÒÆ¶¯Ó¦ÓôæÔÚÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢Çé¿ö¡£
https://www.cverc.org.cn/zxdt/report20250513.htm
4.2.¹úÍâÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.2.1.Èý¿îÊÖ»ú¼à¿ØÈí¼þ»òÒòй¶Êý¾Ý¼¯ÌåÏÂÏß
½üÈÕ£¬Èý¿î¼¸ºõÏàͬµ«Æ·ÅƲ»Í¬µÄÊÖ»ú¼à¿ØÓ¦ÓóÌÐòCocospy¡¢SpyicºÍSpyzieÒÑÈ«ÃæÏÂÏß¡£ÕâЩӦÓóÌÐò½ñÄêÔçЩʱºò±»ÆØ³ö¼àÊÓÁËÊý°ÙÍòÓû§ÊÖ»ú£¬ÔÊÐí°²×°ÕßÔÚÄ¿±ê²»ÖªÇéµÄÇé¿öÏ·ÃÎÊÆä¸öÈËÊý¾Ý£¬°üÀ¨¶ÌÐÅ¡¢ÕÕÆ¬¡¢Í¨»°¼Ç¼ºÍʵʱλÖÃÐÅÏ¢¡£Ñо¿ÈËÔ±½Òʾ£¬ÕâЩӦÓôæÔÚ¹²Í¬µÄ»Æ½ð³Ç¹ÙÍøÂ©¶´£¬ÔÊÐíÈκÎÈË·ÃÎʰ²×°ÁËÕâЩӦÓõÄÉ豸ÉϵĸöÈËÊý¾Ý¡£¸Ã©¶´»¹±©Â¶ÁË320Íò×¢²áÓû§µÄµç×ÓÓʼþµØÖ·£¬ÕâЩÊý¾ÝÒѱ»Ìṩ¸øÊý¾ÝÐ¹Â¶Í¨ÖªÍøÕ¾Have I Been Pwned¡£
À´Ô´£º
https://techcrunch.com/2025/05/19/cocospy-stalkerware-apps-go-offline-after-data-breach/
4.2.2.³¬4ÍòiOSÓ¦ÓÃÀÄÓÃ˽ÓÐȨÏÞ£¬´øÀ´»Æ½ð³Ç¹ÙÍøÒþ»¼
Zimperium×îÐÂÑо¿½Òʾ£¬iOSÉè±¸ÃæÁÙÈÕÒæÔö³¤µÄ»Æ½ð³Ç¹ÙÍøÍþв£¬ÌرðÊÇÀ´×Ôδ¾ÉóºËºÍ²àÔØµÄÒÆ¶¯Ó¦Ó᣾¡¹ÜiPhoneͨ³£±»ÊÓΪÉè¼Æ»Æ½ð³Ç¹ÙÍøµÄÉ豸£¬µ«·ÖÎöÏÔʾijЩӦÓÃÄÜÇÄÈ»ÈÆ¹ýÆ»¹ûµÄ±£»¤»úÖÆ£¬Ê¹Óû§ºÍÆóÒµÃæÁÙ·çÏÕ¡£Ñо¿ÈËÔ±·¢ÏÖ£¬³¬¹ý4Íò¸öÓ¦ÓóÌÐòʹÓÃ˽ÓÐȨÏÞ£¬800¶à¸öÒÀÀµË½ÓÐAPI¡£¹¥»÷ÕßÖ÷Ҫͨ¹ýȨÏÞÌáÉý¡¢ÀÄÓÃ˽ÓÐAPIºÍÈÆ¹ýÆ»¹ûÓ¦ÓÃÉóºËµÄ²àÔØÂ©¶´À´¹¥»÷iOSÉ豸¡£
À´Ô´£º
https://hackread.com/40000-ios-apps-found-exploiting-private-entitlements/