VeriSource Services´«µÝ400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡
°ä²¼¹¦·ò 2025-04-291. VeriSource Services´«µÝ400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡
4ÔÂ28ÈÕ£¬Ô±¹¤¸£ÀûÖÎÀí·þÎñÌṩÉÌVeriSource Services½üÈÕ֪ͨԼ400ÍòÈË£¬ÆäÓ×ÎÒÐÅÏ¢ÔÚÒ»ÄêǰÔâ·êºÚ¿Í¹¥»÷²¢±»ÇÔÈ¡¡£¸ÃÊÂÎñÓÚ2024Äê2ÔÂ28ÈÕ±»·¢ÏÖ£¬¼´ÍþвÐÐΪÕßÇÔÈ¡Êý¾ÝµÄ´ÎÈÕ¡£VeriSource¶ÔÊÜËðÊý¾ÝµÄÉó²é¹¤×÷ÓÚ2024Äê8ÔÂ12ÈÕʵÏÖ£¬ËæºóÔÚÒ»ÖܺóÆô¶¯Á˶ԿÉÄÜÊÜÓ°ÏìÓ×ÎÒµÄ֪ͨ·¨Ê½¡£¾Ý¸Ã¹«Ë¾°µÊ¾£¬±»µÁÐÅÏ¢Éæ¼°Ê¹ÓÃÆä·þÎñµÄ¹«Ë¾Ô±¹¤¼°Æä¾ìÊô£¬ÇÒ¹«Ë¾Ò»ÏòÓëÕâЩÆóÒµçÇÃܺÏ×÷£¬ÒÔÈ«ÃæÍøÂç±ØÒªÐÅÏ¢£¬½ø¶øÍ¨ÖªËùÓпÉÄÜÊÜ´ËÊÂÎñ²¨¼°µÄ¸ö±ð¡£¸ÃÁ÷³ÌÖ±ÖÁ2025Äê4ÔÂ17ÈÕ²ÅÐû¸æÊµÏÖ£¬Ö®ºóVeriSourceѸ¿ì²ÉÈ¡Ðж¯£¬Á¦Ç󾡿콫ÊÂÎñÏêÇé·î¸æÊÜÓ°ÏìÈËÔ±¡£VeriSourceÖ¸³ö£¬Ð¹Â¶ÐÅÏ¢ÒòÓ×ÎÒ¶øÒ죬µ«ÆÕ±éº¸ÇÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ðÐÅÏ¢ÒÔ¼°Éç»á°²È«ºÅÂëµÈÃô¸ÐÄÚÈÝ¡£Ö»¹ÜVeriSourceÐû³ÆÉÐδ·¢ÏÖÈκα»µÁÐÅÏ¢±»ÀÄÓõÄÊ·ý£¬µ«ÎªÔ¤·ÀDZÔÚ·çÏÕ£¬¸Ã¹«Ë¾ÒÑ×Ô¶¯ÎªÊÜÓ°ÏìÓ×ÎÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý±£»¤·þÎñ¡£Í¬Ê±£¬VeriSourceÔÚ֪ͨÖÐÌáÐÑÓû§£¬Ó¦×ÐϸºË²é½è¼Ç¿¨ºÍÐÅÓþ¿¨Õ˵¥£¬ÒÔ¼à²âÊÇ·ñ´æÔÚÒì³£»î¶¯¡£
https://www.securityweek.com/4-million-affected-by-data-breach-at-verisource-services/
2. ¹ú¼Ê½áºÏÐж¯Íß½âJokerOTPÍøÂç´¹µö¹¤¾ß
4ÔÂ28ÈÕ£¬ÔÚÒ»´Î¹ú¼Ê½áºÏ·¨ÂÉÐж¯ÖУ¬Ó¢¹úÓëºÉÀ¼¾¯·½ÁªÊÔìÆ»ñһ·´ó¹æÄ£ÍøÂçڿư¸£¬¿ÛÁôÁ½ÃûÓëJokerOTPÍøÂç´¹µö¹¤ÓµÓйصÄÏÓÒÉÈË¡£¸Ã¹¤¾ßÖ¼ÔÚÀ¹½ØË«³ÁÉí·ÝÑéÖ¤£¨2FA£©´úÂëÒÔÇÔÈ¡×ʽ𣬾ݹÀ¼Æ£¬Á½ÄêÄÚÖÁÉÙÔÚ13¸ö¹ú¶È±»Ê¹Óó¬2.8Íò´Î£¬Ôì³É¾¼ÃËðʧԼ750ÍòÓ¢°÷¡£4ÔÂ22ÈÕ£¬Ó¢¹ú¿ËÀû·òÀ¼¾¯Ô±¾ÖÍøÂç·¸×ﲿÃŽáºÏºÉÀ¼¾¯·½²ÉÈ¡Ðж¯£¬±ðÀëÔÚÓ¢¹úºÍºÉÀ¼¶«²¼À°àÌØÊ¡¿ÛÁôÒ»Ãû24ËêºÍÒ»Ãû30ËêÄÐ×Ó¡£Õâ´ÎÐж¯Ô´ÓÚÒ»ÏîΪÆÚÈýÄêµÄµ÷²é£¬Ö¼ÔÚ²ð³ýJokerOTPÕâÒ»¸´ÔÓÍøÂç´¹µö¹¤¾ß¡£¾Ý¿ËÀû·òÀ¼¾¯·½ÐÂΟ壬JokerOTPͨ¹ýÓÕÆÓû§Ð¹Â¶¹Ø¼üÉí·ÝÑéÖ¤ÂëµÈ¸öÈËÐÅÏ¢£¬½ø¶ø¶ÔÊܺ¦ÕßÒøÐÐÕË»§Ö´ÐÐÚ²ÆÐÔÂòÂô¡£ÏÓÒÉÈËʹÓá°spit¡±ºÍ¡°defone123¡±µÈ»¯Ãû½øÐÐÍøÂç¹¥»÷£¬¼ÙÒâÒøÐлò¼ÓÃÜÇ®±ÒÂòÂôËù´ú±íÖµçÊܺ¦Õߣ¬ÆÈ¡Ò»´ÎÐÔÃÜÂë»òË«³ÁÈÏÖ¤Â룬´Ó¶øÈƹý°²È«´ëÊ©·¸·¨½Ó¼ûÕË»§¡£Ä¿Ç°£¬µ±¾ÖÒÑÆô¶¯²ð³ýÚ¿ÆÆ½Ì¨ÔÚÏß»ù´¡ÉèÊ©µÄ·¨Ê½£¬Ô̺¬ÓëÍйܹ«Ë¾ºÏ×÷¹Ø¹ØJokerOTP»úеÈËÆ½Ì¨£¬Ô¤¼ÆºóÐø½«²ÉÈ¡½øÒ»²½Ðж¯¡£
https://hackread.com/jokerotp-dismantled-28000-phishing-attacks-2-arrested/
3. ÍþвÐÐΪÕßÀûÓÃCraft CMSÁ½¸öÑϳÁ·ì϶·¢Æð¹¥»÷
4ÔÂ28ÈÕ£¬½üÈÕÍþвÐÐΪÕßÀûÓÃCraft CMSÖÐÁ½¸öÐÂÅû¶µÄÑϳÁ°²È«·ì϶ÌáÒéÁãÈÕ¹¥»÷£¬³É¹¦·ÛËé·þÎñÆ÷²¢»ñȡδ¾ÊÚȨµÄ½Ó¼ûȨÏÞ¡£Orange Cyberdefense SensePostÓÚ2025Äê2ÔÂ14ÈÕ³õ´Î¼à²âµ½´ËÀ๥»÷£¬¹¥»÷Éæ¼°CVE-2024-58136ÓëCVE-2025-32432Á½¸ö¸ßΣ·ì϶¡£ÆäÖУ¬CVE-2024-58136Ô´ÓÚCraft CMSʹÓõÄYii PHP¿ò¼ÜÖб¸ÓÃõ辶ȱµãµÄ²»µ±±£»¤£»CVE-2025-32432ΪCraft CMSÄÚÖÃͼÏñת»»Ö°ÄÜÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¬¸Ã·ì϶ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§ÏòÕÆ¹ÜͼÏñת»»µÄ¶Ëµã·¢ËÍPOSTÒªÇ󣬷þÎñÆ÷»áÚ¹ÊÍÒªÇóÖеÄÊý¾Ý£¬½ø¶ø¿ÉÄܵ¼Ö¶ñÒâ´úÂëÖ´ÐС£ÓÉÓÚ·ÖÆç°æ±¾µÄCraft CMSÔÚ×ʲúID²é³Âß¼ÉÏ´æÔÚ²î¾à£¬ÍþвÐÐΪÕßÐèÕÒµ½ÓÐЧ×ʲúIDÄÜÁ¦ÀûÓ÷ì϶¡£¹¥»÷¹ý³ÌÖУ¬ÍþвÐÐΪÕß»áÔËÐжà¸öPOSTÒªÇóÊÔ̽ÓÐЧ×ʲúID£¬²¢Ö´ÐÐPython¾ç±¾Ì½²â·þÎñÆ÷·ì϶£¬Ò»µ©È·ÈÏ·ì϶´æÔÚ£¬±ã´ÓGitHub´æ´¢¿âÏÂÔØ·þÎñÆ÷ÉϵÄPHPÎļþ¡£½ØÖÁ2025Äê4ÔÂ18ÈÕ£¬ÒÑÓÐÔ¼13,000¸öCraft CMSÊ·ý¶³öÓÚ·çÏÕÖ®ÖУ¬ÆäÖнü300¸öÒѱ»ÈëÇÖ¡£
https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html
4. ÒÁ±ÈÀûÑǰ뵺ÒÉÒòÍøÂç¹¥»÷´ó¹æÄ£Í£µç
4ÔÂ28ÈÕ£¬ÒÁ±ÈÀûÑǰ뵺Ôâ·ê´ó¹æÄ£Í£µç£¬Î÷°àÑÀÓëÆÏÌÑÑÀµçÁ¦¹©¸øÖèÈ»Öжϣ¬Êý°ÙÍòÃñ¶àÉúÑÄÏÝÈëÒõÓô¡£µçÁ¦²¿ÃÅÐÂÎÅÈËʿй©£¬ÍøÂç¹¥»÷»òÊÇÕâ´ÎÊ·ÎÞǰÀýµçÁ¦¹ÊÕϵÄ×î¿ÉÄÜÓÕÒò£¬µ«µ±¾ÖÉÐδÕýʽȷÈÏ¡£Í£µçʼÓÚ±¾µØ¹¦·ò12:30×óÓÒ£¬±ËʱÎ÷°àÑÀµçÁ¦ÐèҪ˲¼ä´Ó25184Õ×Íß±©µøÖÁ12425Õ×Íߣ¬¼¼Êõר¼Ò½«ÆäÃèÊöΪ¡°cero energetico¡±£¬¼´µçÁ¦ÏµÍ³³¹µ×±ÀÀ£¡£µçÁ¦²¿ÃÅ·ñ¶¨Á˵¥Ò»¶Ì·µÄ¿ÉÄÜÐÔ£¬Ö¸³öRed El¨¦ctrica¾ß±¸¸ôÀëÊÜÓ°ÏìÇøÓò¡¢Ô¤·ÀÈ«¹úÐÔ¹ÊÕϵÄϵͳ¡£È»¶ø£¬ÒµÄÚר¼ÒÇ¿µ÷£¬µçÍøÈ«Ãæ±ÀÀ£ºóµÄ¸´Ô¹¤×÷¼«Îª¼è¾Þ£¬ÐèÖð¸ö½Úµã³Á½¨ÍøÂ磬ºÄʱ¿ÉÄܳ¤´ïÊýÓ×ʱÉõÖÁÊýÌì¡£Õâ´ÎÍ£µçÓ°ÏìÁìÓò¿í·º£¬²»½öÎ÷°àÑÀ±¾ÍÁÊÜÔÖÑϳÁ£¬ÆÏÌÑÑÀÈ«¾³¡¢·¨¹úÄϲ¿²¿ÃŵØÓò¼°°²Â·¶ûÒàÔⲨ¼°£¬½öÎ÷°àÑÀµÄ¼ÓÄÇÀûȺµººÍ°ÍÀû°¢ÀïȺµºÒò¶ÀÁ¢·¢µçϵͳ¶øÐÒÃâ¡£¹Ø¼ü»ù´¡Éèʩ˲¼äÊÜËð£¬ÂíµÂÀï°ÍÀ¹þ˹¹ú¼Ê»ú³¡ÔÝÍ£ÔËÓª£¬¸÷´ó³ÇÊеØÌúÍ£°Ú£¬µçÐÅÍøÂç̱»¾£¬½»Í¨Ñ¶ºÅµÆÊ§Á飬·¿ÚÖÈÐò´óÂÒ£¬¶àÈ˱»À§µçÌÝ¡£Red El¨¦ctricaÆô¶¯´¹Î£¸´Ô´òË㣬³õ²½»ã±¨ÏÔʾ°ëµº±±²¿ºÍÄϲ¿µçÁ¦ÕýÖ𲽸´Ô¡£¸´Ô¹ý³Ì¸ß¶ÈÒÀÀµË®Á¦·¢µç£¬Òò¿ÉÔÙÉúÄÜÔ´ÎÞ·¨±£ÏÕµçÍø²»±ä£¬¶øÌìÈ»ÆøºÍºËµçÕ¾³ÁÆôÐè½Ï³¤¹¦·ò¡£
https://cybersecuritynews.com/nationwide-power-outages-in-portugal-spain/
5. Hitachi VantaraÔâAkiraÀÕË÷Èí¼þ¹¥»÷
4ÔÂ28ÈÕ£¬Hitachi Vantara×÷ΪÈÕ±¾¿ç¹ú¼¯ÍÅÈÕÁ¢µÄ×Ó¹«Ë¾£¬ÉÏÖÜÄ©Ôâ·êÁËAkiraÀÕË÷Èí¼þ¹¥»÷£¬±»ÆÈ¹Ø¹Ø·þÎñÆ÷ÒÔ¶ôÔì¹¥»÷Ó°Ïì¡£¸Ã¹«Ë¾ÎªµÐÔÖʵÌå¼°±¦Âí¡¢Î÷°àÑÀµçÐÅ¡¢T-Mobile¡¢ÖйúµçÐŵÈÈ«Çò³ÛÃûÆ·ÅÆÌṩÊý¾Ý´æ´¢¡¢»ù´¡Éèʩϵͳ¡¢ÔÆÖÎÀíºÍÀÕË÷Èí¼þ¸´Ô·þÎñ¡£Hitachi Vantara³Æ2025Äê4ÔÂ26ÈÕ²¿ÃÅϵͳÖжϣ¬Ò»¼ì²âµ½¿ÉÒɻ£¬·½±ã¼´Æô¶¯ÊÂÎñÏìÓ¦ºÍ̸£¬ÀñƸµÚÈý·½×¨¼ÒÖ§³Öµ÷²éºÍ²¹¾ÈÁ÷³Ì£¬²¢×Ô¶¯ÏÂÏß·þÎñÆ÷½ÚÔìÊÂÎñ¡£Ä¿Ç°¹«Ë¾ÕýÓëר¼ÒºÏ×÷½¨¸´ÊÂÎñ£¬ÒÔ°²È«·½Ê½¸´Ôϵͳ£¬²¢¸Ð¼¤¿Í»§ºÍºÏ×÷ͬ°éµÄÄÍÐÄÓë½Ã½ÝÐÔ¡£Õâ´Î¹¥»÷ËäδӰÏì¹«Ë¾ÔÆ·þÎñ£¬µ«×÷Ϊ¶ôÔì´ëÊ©£¬Hitachi VantaraϵͳºÍÔì×÷ÒµÎñÊܵ½×ÌÈÅ£¬Ô¶³ÌºÍÖ§³ÖÔËÓªÖжϣ¬²»Íâ×ÔÍйܻ·¾³¿Í»§ÈÔ¿ÉÕý³£½Ó¼ûÊý¾Ý¡£´Ë±í£¬¹¥»÷»¹Ó°ÏìÁ˵ÐÔÖʵÌåÕ¼ÓеĶà¸öÏîÄ¿¡£AkiraÀÕË÷Èí¼þ×Ô2023Äê3Ô³öÏÖºóѸ¿ìÔÚÈ«ÇòÁìÓòÄÚÔì³É´óÁ¿Êܺ¦Õߣ¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏÔö³¤ÁË300¶à¸ö×éÖ¯£¬²¢Ðû³ÆÓÐ˹̹¸£´óѧºÍÈÕ²úÆû³µµÈ³ÛÃûÊܺ¦Õß¡£
https://www.bleepingcomputer.com/news/security/hitachi-vantara-takes-servers-offline-after-akira-ransomware-attack/
6. ÎÚ¿ËÀ¼ÔÆ·þÎñÉÌDe NovoÊý¾ÝÖÐÐÄÍ£µçÖ·þÎñÖжÏ
4ÔÂ28ÈÕ£¬ÎÚ¿ËÀ¼ÔÆÌṩÉÌDe NovoÉÏÖÜÄ©²úÉúÍ£µçÊÂÎñ£¬µ¼Öµ±¾Ö»ú¹¹ºÍ´ó¹«Ë¾µÈ¿Í»§ÔËÓªÖжϣ¬Ä¿Ç°·þÎñÒѸ´Ô¡£Õâ´ÎÍ£µçÔ´ÓÚDe NovoÊý¾ÝÖÐÐĵçÔ´¹ÊÕÏ£¬Ó°ÏìÁìÓò¿í·º£¬Ô̺¬ÎÚ¿ËÀ¼Diiaµ±¾ÖÀûÓ÷¨Ê½¡¢±¾µØÒøÐÓ×¢ÓÊÕþ¿ìµÝ¾ÞÍ·Nova PostÒÔ¼°Apple PayºÍGoogle PayµÈ·Ç½Ó´¥Ê½Ö§¸¶ÏµÍ³¾ùÁÙʱÏÂÏß¡£»ù¸¨¾ÓÃñ·´Ó³£¬ÔÚ½»Í¨ÖÐ¶ÏÆÚ¼äÎÞ·¨Ê¹ÓÃÒÆ¶¯Ö§¸¶³Ë×øµØÌú£¬²¿ÃŲÍÌüµç×ÓÖ§¸¶ÏµÍ³Ò²³öÏÖÎÊÌâ¡£De NovoºÄʱ½üÁùÓ×ʱ¸´Ô¿Í»§·þÎñ¡£¹«Ë¾Ê×ϯִÐйÙÂí¿ËÎ÷Ä·¡¤°¢Ï£Ò®·ò½«Í£µç¹é×ïÓÚ×Ô¶¯µçÔ´Çл»ÏµÍ³¡°Òâ±í¹ÊÕÏ¡±£¬µ¼Ö±¸ÓÃµç³ØºÍ²ñÓÍ·¢µç»úÎÞ·¨Æô¶¯£¬ÉèÊ©¶ÏµçÔ¼15·ÖÖÓ¡£ËûÅųýÁËÍøÂç¹¥»÷µÄ¿ÉÄÜÐÔ£¬²¢°µÊ¾¹«Ë¾ÈÔÔÚµ÷²é¹ÊÕÏÔÒò¡£×Ô¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´£¬¸Ã¹ú¶ÔÔÆ¼¼ÊõµÄÒÀÀµÈÕÒæÔö³¤£¬ºÜ¶àÆóÒµ½«Êý¾Ý×ªÒÆµ½ÔƶËÒÔÔ¤·ÀÎïÀí·ÛË顣Ϊȷ±£ÔÚÔâ·êÊý×ÖºÍÎïÀí¹¥»÷ʱѸ¿ì¸´Ô£¬Ô̺¬Diiaƽ̨ÔÚÄڵĺܶàÆóÒµºÍµ±¾Ö·þÎñ¶¼ÒÀÀµ¶à¼ÒÔÆÌṩÉÌ¡£
https://therecord.media/ukraine-state-and-banking-services-restored


¾©¹«Íø°²±¸11010802024551ºÅ