¿¨µØÑÇϵͳÔâºÚ¿ÍÈëÇÖµ¼Ö¿ͻ§ÐÅϢй¶

°ä²¼¹¦·ò 2025-06-03

1. ¿¨µØÑÇϵͳÔâºÚ¿ÍÈëÇÖµ¼Ö¿ͻ§ÐÅϢй¶


6ÔÂ2ÈÕ £¬ÉݳÞʱÉÐÆ·ÅÆ¿¨µØÑǽüÈÕÏò¿Í»§·¢³öÖÒ¸æ £¬³ÆÆäϵͳÔâºÚ¿ÍÈëÇÖ £¬µ¼Ö¿ͻ§Ó×ÎÒÐÅϢй¶¡£ÔÚ֪ͨÐÅÖÐ £¬¿¨µØÑÇй©ºÚ¿Í»ñÈ¡ÁËÆäϵͳµÄһʱ½Ó¼ûȨÏÞ £¬²¢ÇÔÈ¡ÁËÓÐÏÞÊýÁ¿µÄ¿Í»§ÐÅÏ¢ £¬Ô̺¬¿Í»§ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµØµã¹ú¶È £¬µ«Î´Éæ¼°ÃÜÂë¡¢ÐÅÓþ¿¨ºÅ»òÒøÐоßÌåÐÅÏ¢µÈ¸üÃô¸ÐÊý¾Ý¡ £¿¨µØÑÇÇ¿µ÷ÒѽÚÔìסÎÊÌâ £¬²¢¼ÓÇ¿ÁËϵͳºÍÊý¾ÝµÄ±£»¤ £¬Í¬Ê±·î¸æ·¨Âɲ¿ÃÅ £¬ÕýÓë±í²¿ÍøÂ簲ȫ¹«Ë¾ºÏ×÷½¨¸´·ì϶¡£Õâ´Î°²È«·ì϶²¢·Ç¸öÀý £¬´Óǰһ¸öÔÂÄÚ £¬ÆäËûʱÉÐÆ·ÅÆÒ²Åû¶ÁËÀàËÆ°²È«ÊÂÎñ¡£½ñÄê5Ô £¬µÏ°ÂÅû¶Êý¾Ýй¶ÊÂÎñ £¬ÍþвÐÐΪÕßÈëÇÔìäϵͳ £¬ÇÔÈ¡Á˿ͻ§µÄÁªÏµ·½Ê½¡¢²É°ìº¹Çà¼Í¼ºÍÆ«ºÃÉèÖã»Í¬ÑùÔÚÉϸöÔ £¬°¢µÏ´ï˹ÖÒ¸æ¿Í»§ £¬ÆäÒ»¼ÒµÚÈý·½·þÎñÌṩÉÌÔâ·êÈëÇÖ £¬µ¼ÖÂÁªÏµÐÅϢй¶ £¬µ«Î´»ñÈ¡¸¶¿îÏêÇé»òÕË»§Æ¾Ö¤£»ÉÏÖÜ £¬Î¬¶àÀûÑǵİÂÃØÒò³ÖÐø°²È«ÊÂÎñ¹Ø¹ØÁËÆäÍøÕ¾ºÍ²¿ÃÅÉ̵ê·þÎñ £¬²¢ÒÑÓëÍøÂ簲ȫר¼Ò·¢Õ¹µ÷²é¡£ÕâһϵÁÐÊÂÎñÅú×¢ £¬Ê±ÉÐÆ·ÅÆÕýÃæ¶Ô×ÅÈÕÒæÑϸñµÄÍøÂ簲ȫÌôÕ½ £¬Ðè¼ÓÇ¿°²È«·À»¤´ëÊ© £¬ÒÔ±£»¤¿Í»§ÐÅÏ¢²»±»Ð¹Â¶¡£


https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/


2. The North FaceÔâÆ¾Ö¤Ìî³ä¹¥»÷ £¬¿Í»§ÐÅϢй¶


6ÔÂ2ÈÕ £¬»§±í·þ×°ÁãÊÛÉÌThe North FaceÖÒ¸æ¿Í»§ £¬ÆäÓ×ÎÒÐÅÏ¢ÔÚ4ÔÂ·ÝµÄÆ¾Ö¤Ìî³ä¹¥»÷Öб»µÁ¡£The North Face×÷ΪÃÀ¹ú´óÐÍ»§±í·þ×°ºÍÉè±¸Æ·ÅÆ £¬ÄêÊÕÈ볬30ÒÚÃÀÔª £¬µç×ÓÉÌÎñÕ¼Æä×ÜÏúÊÛ¶îµÄ42%¡£Æ¾Ö¤Ìî³ä¹¥»÷ÖÐ £¬ÍþвÐÐΪÕßÀûÓÃÏÈǰÊý¾Ýй¶Öж³öµÄÓû§Ãû - ÃÜÂë¶Ô×Ô¶¯µÇ¼ £¬ÊÔͼ»ñÈ¡Óû§ÕÊ»§Î´¾­ÊÚȨµÄ½Ó¼û £¬´Ë¼¼ÊõµÃÒæÓÚ¡°Æ¾Ö¤»ØÊÕ¡± £¬¼´Óû§¶àƽ̨ʹÓÃÒ»ÑùÓû§ÃûºÍÃÜÂë £¬µ«ÈôÕË»§Êܶà³É·ÖÉí·ÝÑéÖ¤£¨MFA£©±£»¤ £¬¹¥»÷»áʧ°Ü¡£The North FaceÒÑÆðÍ·ÏòÊÜÓ°Ïì¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ £¬²¢Ïò·ðÃÉÌØÖÝ×ܼì²ì³¤·ÖÏíʾÀý֪ͨ £¬·î¸æÆäÍøÕ¾ÔÚ2025Äê4ÔÂ23ÈÕ·¢ÏÖÒì³£»î¶¯ £¬¾­µ÷²é £¬µ±ÈÕ¹¥»÷Õß·¢ÆðÁËÓ×¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷¡£ÒѶ³öµÄÊý¾ÝÔ̺¬ÐÕÃû¡¢²É°ìº¹Çà¼Í¼¡¢ÊÕ¼þµØÖ·¡¢µç×ÓÓʼþ¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂëµÈ £¬²»Í⸶¿îÐÅϢδй¶ £¬ÒòÍøÕ¾¸¶¿îÓÉ±í²¿ÌṩÉÌ´¦Öà £¬The North Face½ö±£ÁôʵÏÖÁ÷³ÌËùÐèÁîÅÆ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬The North Face¾ö¶¨²»ºÏËùÓÐÕË»§Ç¿ÔìÖ´ÐÐMFA £¬µ¼ÖÂÆä¿Í»§ÈºËðʧ¾Þ´ó £¬ÕâÊÇ¸ÃÆ·ÅÆÍøÕ¾×Ô2020ÄêÒÔÀ´Ôâ·êµÄµÚËÄÆðƾ֤Ìî³äÊÂÎñ¡£


https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/


3. SentinelOneÒòÈí¼þȱµãÖÂÆßÓ×ʱȫÇò·þÎñÖжÏ


6ÔÂ2ÈÕ £¬ÃÀ¹úÍøÂ簲ȫ¹«Ë¾SentinelOneÉÏÖÜĩй© £¬ÒòÈí¼þ·ì϶µ¼ÖÂÆäÖÜËijöÏÖ³¤´ïÆßÓ×ʱµÄ¡°È«Çò·þÎñÖжϡ± £¬Ó°ÏìÁ˶à¸öÃæÏò¿Í»§µÄ·þÎñ¡£SentinelOneÔÚÖÜËİ䲼µÄÌû×ÓÖÐÈÏ¿ÉÁËÕâ´ÎÖжÏ £¬²¢Ïò¿Í»§±£ÕÏÆäϵͳÈÔÊܱ£»¤ £¬Ö»ÊÇÍйÜÏìÓ¦·þÎñÎÞ·¨»ñµÃ¿É¼ûÐÔ £¬ÍþвÊý¾Ý»ã±¨½öÑÓ³¤Î´ÃÔʧ £¬ÇÒ³õ²½·ÖÎöÅú×¢Õâ²»Êǰ²È«ÊÂÎñ¡£Á½Ììºó £¬¸Ã¹«Ë¾°ä²¼µ××ÓÔ­Òò·ÖÎö £¬È·ÈÏÊÂÎñ²¢·ÇÍøÂç¹¥»÷»ò°²È«·ì϶ËùÖ £¬¶øÊÇ»ù´¡ÉèÊ©½ÚÔìϵͳÖеÄÈí¼þȱµãÒý·¢¡£¸Ãȱµã×Ô¶¯É¾³ýÁ˹ؼüÍøÂç·ÓɺÍDNS½âÎöÆ÷¹æ¶¨ £¬µ¼Ö·þÎñ´óÃæ»ýÖжÏ¡£¾ßÌå¶øÑÔ £¬Òò´«³öµÄÔÆÖÎÀíÖ°ÄÜ´æÔÚȱµã £¬AWS Transit Gateway·ÓɱíµÄ±¸·Ý¸´Ô­Îª¿Õ £¬ÔÚËùÓбØÐëµÄÏνӻù´¡ÉèÊ©¸´Ô­ºó £¬·þÎñÖжÏÈÔ³ÖÐø¡£SentinelOneÚ¹ÊͳÆ £¬¹«Ë¾ÔÚ½«³ö²úϵͳ¹ý¶Éµ½»ùÓÚ»ù´¡ÉèÊ©¼´´úÂ루IaC£©×¼Ôò¹¹½¨µÄÐÂÔÆ¼Ü¹¹ £¬Õâ´Îɾ³ý²Ù×÷Óɼ´½«ÆúÓõĽÚÔìϵͳÒò´´½¨ÐÂÕË»§´¥·¢¡£¸Ã½ÚÔìϵͳÅäÖñÈÁ¦Ö°ÄÜ´æÔÚÈí¼þȱµã £¬ÃýÎó¼ø±ð²î¾à²¢ÀûÓÃÁËËùνÕýÈ·µÄÅäÖÃ״̬ £¬¸²¸ÇÁËÏÈÇ°ÍøÂçÉèÖà £¬µ¼Ö¸´Ô­ÁËÒ»¸ö¿ÕµÄ·Óɱí¡£Õâ´ÎÖжϻ¹ÒÔÖÁ¶Ô¹«Ë¾·þÎñµÄ·¨Ê½½Ó¼ûÖжÏ £¬Í³Ò»×ʲúÖÎÀí/¿â´æºÍÉí·Ý·þÎñ¹Ø¹Ø £¬¿Í»§ÎÞ·¨²é¿´·ì϶»ò½Ó¼ûÉí·Ý½ÚÔį̀¡£´Ë±í £¬¿ÉÄÜ»¹Ó°ÏìÁËÀ´×Ô¸÷ÀàµÚÈý·½·þÎñµÄÊý¾ÝÌáÈ¡ÒÔ¼°Íйܼì²âºÍÏìÓ¦£¨MDR£©¾¯±¨¡£


https://www.bleepingcomputer.com/news/technology/sentinelone-last-weeks-7-hour-outage-caused-by-software-flaw/


4. ÍøÂç¹¥»÷Ï®»÷ÁËCovenant HealthÔËÓªµÄÒ½Ôº


6ÔÂ2ÈÕ £¬2025Äê5ÔÂ26ÈÕÆð £¬·ÇͶ»úÐÔÉϵ۽ÌÇøÓòÒ½ÁƱ£½¡ÏµÍ³Covenant HealthÔËÓªµÄÈý¼ÒÒ½ÔºÔâ·êÍøÂç¹¥»÷ £¬±»ÆÈ¹Ø¹ØËùÓÐϵͳÒÔ½ÚÔ찲ȫÊÂÎñ¡£Ê¥ÂêÀöÒ½ÁÆÏµÍ³³ÆÊ¥ÂêÀöÒ½ÔºÓöµ½Ò»Ê±ÏµÍ³¹ÊÕÏ £¬²¿Ãŵ绰ºÍÎĵµÏµÍ³ÊÜÓ°Ïì £¬Ò½ÁÆ·þÎñ³ÖÐøµ«ºòÕ﹦·ò¿ÉÄܵ¢¸é£»Ê¥Ô¼Éª·òÒ½Ôº°µÊ¾Òòϵͳһʱ¹ÊÕÏ £¬5ÔÂ27ÈÕµ÷ÕûÃÅÕﻯÑé·þÎñ £¬½öÔÚÔºÇøÄÚÊ¢¿ªÇÒÆ¾ÊµÌå¶©µ¥Ìṩ¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´Î¹¥»÷ÖÐÊý¾ÝÊDZ»µÁ»¹ÊÇÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬Covenant HealthÀñƸÁ˶¥¼¶ÍøÂ簲ȫר¼ÒÀ´½ÚÔìºÍµ÷²é¡£Ö»¹Ü²¿ÃÅϵͳºÍÃÅÕï³¢ÊÔÊÒÊÜÓ°Ïì £¬µ«·þÎñÈÔÔÚ³ÖÐø £¬ÖжÏˮƽ¼«Ó× £¬Ðº±²¼Ê²¶ûÖݵÄʥԼɪ·òÒ½ÔººÍÃåÒòÖݵÄÁ½¼ÒÒ½Ôº¾ùÊܲ¨¼° £¬²»Íâ¸Ã»ú¹¹½¨Ò黼Õß°´Ê±¾ÍÕï¡£5ÔÂ26ÈÕ·¢ÏÖÎ¥¹æÐÐΪӰÏìÕû¸ö×éÖ¯ÏνÓÐÔºó £¬³öÓÚÉóÉ÷˼¿¼ £¬Ò½Ôº¡¢ÕïËùºÍÒ½ÁÆ·þÎñÌṩÕßµÄËùº±¼û¾Ýϵͳ½Ó¼û±»µ±¼´ÖÕ³¡¡£½ØÖÁ׫д±¾ÎÄʱ £¬ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£


https://securityaffairs.com/178507/cyber-crime/a-cyberattack-hit-hospitals-operated-by-covenant-health.html


5. ºÚ¿ÍÔÚÀûÓÃvBulletinÂÛ̳Èí¼þµÄÑϳÁ·ì϶


5ÔÂ30ÈÕ £¬¿ªÔ´ÂÛ̳Èí¼þvBulletin±»·¢ÏÖ´æÔÚÁ½¸öÑϳÁ·ì϶ £¬±àºÅ±ðÀëΪCVE-2025-48827ºÍCVE-2025-48828 £¬ÆÀ¼¶ÎªÑϳÁ £¬CVSS v3ÆÀ·Ö±ðÀëΪ10.0ºÍ9.0¡£ÕâÁ½¸ö·ìÏ¶Éæ¼°Í¨¹ýÄ£°åÒýÇæÀÄÓ÷ì϶½øÐÐAPI²½ÖèŲÓúÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£µ±vBulletinÔÚPHP 8.1»ò¸ü¸ß°æ±¾ÉÏÔËÐÐʱ £¬°æ±¾5.0.0ÖÁ5.7.5ºÍ6.0.0ÖÁ6.0.3»áÊܵ½Ó°Ïì¡£ÕâЩ·ì϶¿ÉÄÜÔÚÈ¥ÄêÒÑÇÄÈ»½¨¸´ £¬µ«ÒòºÜ¶àÍøÕ¾Î´Éý¼¶ £¬ÈÔ¶³öÔÚ·çÏÕ֮ϡ£2025Äê5ÔÂ23ÈÕ £¬°²È«×êÑÐÔ±Egidio RomanoÔÚÆä²©¿ÍÉϾßÌåÚ¹ÊÏçËÈôºÎÀûÓÃÕâЩ·ì϶ £¬Ö¸³öÎÊÌâÔ´ÓÚvBulletin¶ÔPHP·´ÉäAPIµÄÀÄÓà £¬¸ÃAPIÔÚPHP 8.1ÖеÄÐÐΪ±ä¶¯ÔÊÐíŲÓÃÊܱ£»¤²½Öè¶øÎÞÐèÃ÷È·µ÷Õû¿É½Ó¼ûÐÔ¡£·ì϶Á´Ô̺¬Í¨¹ý¾«ÐÄÉè¼ÆµÄURLŲÓÃÊܱ£»¤²½Öè £¬ÒÔ¼°ÀÄÓÃvBulletinÄ£°åÒýÇæÄÚµÄÄ£°åǰÌá¡£¹¥»÷Õß¿ÉÀûÓÃÒ×Êܹ¥»÷µÄ¡°replaceAdTemplate¡±²½Öè×¢Èë¶ñÒâÄ£°å´úÂë £¬Èƹý¡°²»°²È«º¯Êý¡±¹ýÂËÆ÷ £¬´Ó¶øÔڵײã·þÎñÆ÷ÉÏʵÏÖÆëȫԶ³Ì¡¢Î´¾­Éí·ÝÑéÖ¤µÄ´úÂëÖ´ÐС£5ÔÂ26ÈÕ £¬°²È«×êÑÐÔ±Ryan Dewhurst»ã±¨³ÆÔÚÃÛ¹ÞÈÕÖ¾Öз¢ÏÖ¶Ô´æÔÚ·ì϶µÄ¶ËµãµÄÒªÇó £¬²¢×·×Ùµ½Ò»ÃûÀ´×Ô²¨À¼µÄ¹¥»÷ÕßÊÔͼ²¿ÊðPHPºóÃÅÖ´ÐÐϵͳºÅÁî¡£½¨ÌÖÂÛ̳ÖÎÀíÔ±¾¡¿ìÀûÓð²È«¸üлòÉý¼¶µ½×îа汾6.1.1ÒÔÔ¤·À·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-critical-flaw-in-vbulletin-forum-software/


6. Netbird³ÉÓã²æÊ½´¹µöй¤¾ß £¬Õë¶Ô¶àµØ²ÆÕþ¸ß¹Ü


6ÔÂ2ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢³öÖÒ¸æ £¬Ò»³¡ÀûÓúϷ¨Ô¶³Ì½Ó¼û¹¤¾ßNetbirdµÄÐÂÓã²æÊ½´¹µö¹¥»÷»î¶¯ÔÚ½øÐÐ £¬Ö¸±êÕë¶ÔÅ·ÖÞ¡¢·ÇÖÞ¡¢¼ÓÄôó¡¢Öж«ºÍÄÏÑǵØÓòÒøÐÓ×¢ÄÜÔ´¡¢±£ÏÕºÍͶ×ʹ«Ë¾µÄ²ÆÕþ¸ß¹Ü¡£¸Ã»î¶¯ÓÉTrellix¹«Ë¾ÓÚ2025Äê5ÔÂÖÐÑ®³õ´Î·¢ÏÖ £¬Ä¿Ç°ÉÐδ¹éÒòÓÚÈκÎÒÑÖªÍþвÐÐΪÕß¡£Õâ´Î¹¥»÷ÒÔÒ»·â¼ÙÒâRothschild&CoÕÐÆ¸ÈËÔ±µÄ´¹µöÓʼþΪ³õ²½ £¬Í¨¹ýαÔìµÄPDF¸½¼þÁ´½ÓÓÕʹÊܺ¦Õßµã»÷ £¬½ø¶ø±»³Á¶¨ÏòÖÁÍйÜÔÚFirebaseÀûÓÃÉϵÄURL¡£¹¥»÷ÕßÀûÓüÓÃܵijÁ¶¨ÏòURLºÍÑéÖ¤Âë¹Ø¿¨À´Èƹý·ÀÓùϵͳ £¬×îÖÕÊèµ¼Êܺ¦ÕßÏÂÔØÔ̺¬¶ñÒâVBScriptµÄZIPѹËõ°ü¡£¸ÃVBScriptÕÆ¹Ü¼ìË÷²¢Ö´ÐÐÏÂÒ»½×¶ÎVBScript £¬ºóÕß»á½øÒ»²½»ñÈ¡ÓÐÐ§ÔØºÉ £¬ÌáÈ¡²¢×°ÖÃNetBirdºÍOpenSSHÁ½¸ö·¨Ê½ £¬´´½¨°µ²ØÕË»§¡¢ÆôÓÃÔ¶³Ì×ÀÃæ½Ó¼û £¬²¢Í¨¹ýÉèÖôòË㹤×÷ʹNetBirdÔÚÊÜϰȾϵͳÉÏÓÆ¾Ã»¯ÔËÐÐ £¬Í¬Ê±É¾³ý×ÀÃæ¿ì½Ý·½Ê½ÒÔ¸²¸ÇÈëÇÖÐÐΪ¡£´Ë±í £¬Trellix»¹·¢ÏÖÒ»¸öÒÑ»îÔ¾½üÒ»ÄêµÄ³Á¶¨ÏòURLÌṩһÑùµÄVBScriptÓÐÐ§ÔØºÉ £¬ÕâÅú×¢¸Ã¹¥»÷»î¶¯¿ÉÄÜÒѳÖÐøÒ»¶Î¹¦·ò¡£


https://thehackernews.com/2025/06/fake-recruiter-emails-target-cfos-using.html