KeePassľÂí°æ±¾·Ö·¢³¤´ï°ËÔ£¬ÇÔÃܲ¢²¿ÊðÀÕË÷Èí¼þ
°ä²¼¹¦·ò 2025-05-201. KeePassľÂí°æ±¾·Ö·¢³¤´ï°ËÔ£¬ÇÔÃܲ¢²¿ÊðÀÕË÷Èí¼þ
5ÔÂ19ÈÕ£¬WithSecureÍþвµý±¨ÍŶӵ÷²é·¢ÏÖ£¬ÍþвÐÐΪÕßÖÁÉٰ˸öÔÂÀ´Ò»ÏòÔÚ·Ö·¢KeePassÃÜÂëÖÎÀíÆ÷µÄľÂí°æ±¾KeeLoader£¬ÒÔÖ´ÐжñÒâ»î¶¯¡£KeePass×÷Ϊ¿ªÔ´Èí¼þ£¬ÆäÔ´´úÂë±»ÍþвÐÐΪÕßÅú¸Ä£¬¹¹½¨ÁËÔ̺¬Í¨ÀýÃÜÂëÖÎÀíÖ°ÄܵÄľÂí»¯°æ±¾¡£¸Ã°æ±¾²»½öÄÜ×°ÖÃCobalt StrikeÐű꣬»¹Äܽ«KeePassÃÜÂëÊý¾Ý¿âµ¼³öΪÃ÷ÎIJ¢Í¨¹ýÐűêÇÔÈ¡¡£Õâ´Î»î¶¯ÖÐʹÓõÄCobalt StrikeˮӡÓë³õʼ½Ó¼û´úÀí(IAB)ÓйØÁª£¬¸Ã´úÀí±»ÒÔΪÓë´ÓǰµÄBlack BastaÀÕË÷Èí¼þ¹¥»÷Óйء£Cobalt StrikeˮӡÊÇǶÈëÔÚÐűêÖеÄΨһ±êʶ·û£¬Í¨³£ÓëBlack BastaÀÕË÷Èí¼þÓйء£KeeLoaderÓжàÖÖ±äÖÖ£¬Ê¹ÓúϷ¨Ö¤ÊéÊðÃû£¬²¢Í¨¹ýÓòÃûÇÀ×¢½øÐд«²¼¡£ÕâЩ±»Ä¾ÂíϰȾµÄ·¨Ê½²»½öÓµÓÐÃÜÂëÇÔȡְÄÜ£¬»¹ÄÜÔÚÓû§´ò¿ªKeePassÊý¾Ý¿âʱ£¬½«Êý¾Ýµ¼³öΪCSVÌåʽ£¬±ãÓÚÍþвÐÐΪÕßÇÔÈ¡¡£×îÖÕ£¬WithSecureµ÷²éµÄ¹¥»÷µ¼Ö¹«Ë¾VMware ESXi·þÎñÆ÷±»ÀÕË÷Èí¼þ¼ÓÃÜ¡£½øÒ»´ëÊ©²é·¢ÏÖ£¬¸Ã»î¶¯ÒѳÉÁ¢ÖØ´ó»ù´¡ÉèÊ©£¬ÓÃÓÚ·Ö·¢¼Ù×°³ÉºÏ·¨¹¤¾ßµÄ¶ñÒⷨʽºÍÖ¼ÔÚÇÔȡƾ֤µÄÍøÂç´¹µöÒ³Ãæ¡£WithSecure½«´Ë»î¶¯¹é×ïÓÚUNC4696×éÖ¯£¬¸Ã×éÖ¯´ËǰÓëNitrogen Loader»î¶¯Óйأ¬¶øNitrogen»î¶¯ÓÖÓëBlackCat/ALPHVÀÕË÷Èí¼þÓйء£
https://www.bleepingcomputer.com/news/security/fake-keepass-password-manager-leads-to-esxi-ransomware-attack/
2. ServiceaidÅäÖÃÃýÎóÖÂCatholic Health½ü50Íò»¼ÕßÐÅϢй¶
5ÔÂ19ÈÕ£¬ÆóÒµITÌṩÉÌServiceaideÒòÊý¾Ý¿âÅäÖÃÃýÎ󣬵¼ÖÂÓëŦԼ·ÇͶ»úÐÔÒ½ÁƱ£½¡ÏµÍ³Catholic HealthÓйصÄÔ¼483,126Ãû»¼ÕßÃô¸Ð½¡È«ºÍÓ×ÎÒÐÅϢй¶¡£Õâ´Îй¶ԴÓÚÒ»¸öElasticsearchÊý¾Ý¿â±»ÎÞÒâÖй«¿ª£¬²úÉúÔÚ2024Äê9ÔÂ19ÈÕÖÁ11ÔÂ5ÈÕÆÚ¼ä£¬ÓÚ11ÔÂ15ÈÕ±»·¢ÏÖ£¬È«ÃæÉó²é²Å¸ÕʵÏÖ¡£Ö»¹ÜÎÞÈ·ÔäÖ¤¾ÝÅú×¢Êý¾Ý±»ÏÂÔØ»òÀÄÓ㬵«¹«Ë¾²»ÄÜÅųýÕâÖÖ¿ÉÄÜÐÔ¡£Ð¹Â¶µÄÊý¾Ý¿âÔ̺¬´óÁ¿Ãô¸ÐÐÅÏ¢£¬ÈçÈ«Ãû¡¢µ®ÉúÈÕÆÚ¡¢´¦·½Êý¾Ý¡¢Éç»á°²È«ºÅÂë¡¢½¡È«±£ÏÕÏêÇé¡¢Ò½ÁƱ£½¡ÌṩÕßÐÅÏ¢¡¢Ò½ÖκÍÁÙ´²ÐÅÏ¢¡¢Ò½ÁƼͼºÍÕ˺ÅÒÔ¼°µç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃÜÂëµÈ¡£ServiceaideÕý֪ͨÊÜÓ°ÏìÓ×ÎÒ£¬²¢²ÉÈ¡´ëÊ©±£»¤Â¶³öµÄÊý¾Ý¿â£¬Ôö³¤Ðµİ²È«ºÍ̸ÒÔ½µµÍ½«À´·çÏÕ¡£¸Ã¹«Ë¾»¹ÓëÁª¹ú¼à¹Ü»ú¹¹ºÏ×÷£¬ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿ÒÑÔÚÆäÃñȨ°ì¹«ÊÒÎ¥¹æÃÅ»§ÍøÕ¾ÉϹ«¿ªÁËÕâ´ÎÊý¾Ýй¶ÊÂÎñ¡£Serviceaide½¨ÒéÊÜÓ°ÏìÓû§¹Ø×¢ÐÅÓþ»ã±¨¡¢¸ü¸ÄÓëÒ½ÁÆÕË»§¹ØÁªµÄÃÜÂ룬²¢Ë¼¿¼¶³½áÐÅÓþ¡£
https://hackread.com/serviceaide-leak-catholic-health-patients-records/
3. Arla FoodsµÂ¹ú¹¤³§ÔâÍøÂç¹¥»÷Ö³ö²úÖжÏ
5ÔÂ19ÈÕ£¬Arla Foods֤ʵ£¬ÆäλÓڵ¹úÎÚÅÁ¶ûµÄ³ö²ú²¿ÃÅÔâ·êÁËÍøÂç¹¥»÷£¬µ¼Ö³ö²úÔËÓªÖжϡ£Õâ¼Òµ¤ÂóʳƷ¾ÞÍ·°µÊ¾£¬Õâ´Î¹¥»÷½öÓ°ÏìÁ˸óö²ú²¿ÃÅ£¬µ«Ô¤¼Æ½«Òý·¢²úÆ·½»¸¶ÑÓ³¤ÉõÖÁÈ¡µÞ¡£Arla½²»°È˳ƣ¬ÔÚÎÚÅÁ¶ûµÄÈ鯷³§·¢ÏÖÁË¿ÉÒɻ£¬Ó°ÏìÁ˱¾µØµÄITÍøÂ磬³öÓÚ°²È«Ë¼¿¼£¬³ö²úÁÙʱÊܵ½Ó°Ïì¡£Arla Foods×÷Ϊ¹ú¼ÊÈéÖÆÆ·³ö²úÉ̺ÍÅ©·òºÏ×÷É磬ռÓÐ7600Ãû³ÉÔ±£¬ÔÚÈ«Çò39¸ö¹ú¶ÈÉèÓзÖÖ§»ú¹¹£¬Ô±¹¤´ï23000ÈË£¬ÄêÊÕÈë¸ß´ï138ÒÚÅ·Ôª£¬²úÆ·ÏúÍùÈ«Çò140¸ö¹ú¶È¡£¹«Ë¾ÕýÖÂÁ¦¸´ÔÊÜÓ°Ï칤³§µÄÔËÓª£¬²¢Ô¤¼Æ½«ÔÚ±¾ÖÜĩǰ»ñµÃ³É¾Í£¬ÆäËû¹¤³§µÄ³ö²úÔòδÊÜÓ°Ïì¡£ÓÉÓÚ³ö²úÖжϵÄÐÂÎÅÔÚÖÜÎ寨¹â£¬Ô¤¼ÆÄ³Ð©Çé¿öϽ«³öÏÖ²úƷǷȱ¡£ArlaÒÑ֪ͨÊÜÓ°ÏìµÄ¿Í»§¿ÉÄܳöÏÖ½»»õÑÓ³¤»òÈ¡µÞµÄÇé¿ö¡£µ±±»Îʼ°Õâ´Î¹¥»÷ÊÇ·ñÉæ¼°Êý¾Ý͵ÇÔ»ò¼ÓÃÜʱ£¬Arla»Ø¾ø·ÖÏí¸ü¶àÐÅÏ¢¡£Ä¿Ç°£¬ÀÕË÷Èí¼þÚ²ÆÃÅ»§ÍøÕ¾ÉÏÉÐδ°ä²¼¹ØÓÚArlaµÄ²¼¸æ£¬Òò¶ø¹¥»÷ÀàÐͺÍÖ´ÐÐÕßÒÀȻδ֪¡£
https://www.bleepingcomputer.com/news/security/arla-foods-confirms-cyberattack-disrupts-production-causes-delays/
4. Ó¢¹ú˾·¨ÔöÔ®»ú¹¹ÔâÍøÂç¹¥»÷ÖÂÃô¸ÐÊý¾Ýй¶
5ÔÂ19ÈÕ£¬Ó¢¹ú˾·¨ÔöÔ®»ú¹¹(LAA)È·ÈÏ£¬½üÆÚÔâ·êµÄÍøÂç¹¥»÷Ô¶±È×î³õÔ¤¼ûµÄÑϳÁ£¬ºÚ¿ÍÇÔÈ¡ÁË´óÁ¿Ãô¸ÐµÄÉêÇëÈËÊý¾Ý¡£LAA×÷ΪӢ¹ú˾·¨ÊÖÏÂÊôµÄÖ´Ðлú¹¹£¬ÕƹÜΪ¾¼ÃÄÑÌâÕßÌṩ˾·¨ÔöÔ®£¬Õâ´ÎÊý¾Ýй¶ÊÂÎñÉæ¼°¶à¶àÃô¸ÐÐÅÏ¢¡£±¾ÔÂÔçЩʱ³½£¬LAAÔøÅû¶²úÉú°²È«ÊÂÎñ£¬³ÆÓÐÏÞ²ÆÕþÐÅÏ¢¿ÉÄÜй¶£¬µ«×îÐÂÐÂÎÅÏÔʾ£¬Çé¿ö¸üΪÑϸñ£¬´óÁ¿×Ô2010ÄêÆðµÄÊý¾Ý¿ÉÄÜÒѱ»ºÚ¿Í»ñÈ¡¡£Ó¢¹úµ±¾ÖÒÑÈ·ÈÏÊý¾Ýй¶£¬²¢²Î¼Óµ÷²é¡£²¼¸æÖ¸³ö£¬ºÚ¿Í×éÖ¯»ñÈ¡ÁË´óÁ¿Óë˾·¨ÔöÔ®ÉêÇëÈËÓйصÄÐÅÏ¢£¬Ô̺¬ÁªÏµ·½Ê½¡¢µ®ÉúÈÕÆÚ¡¢¹úÃñÉí·ÝÖ¤ºÅÂë¡¢·¸×ïÊ·¡¢¾ÍÒµÇé¿ö¼°²ÆÕþϸ½ÚµÈ¡£Ó¢¹úµ±¾Ö½¨ÒéËùÓÐÉêÇëÈËά³Ö¾¯Ì裬½÷·ÀÚ¿Æ£¬²¢ÔÚ¹²ÏíÃô¸ÐÐÅϢǰºËʵͨѶÄÚÈÝ¡£LAAÊ×ϯִÐйټò¡¤¹þ²©Ìضû¶Ô´Ë°µÊ¾Ç¸Ò⣬²¢³Ðŵ½«¾¡¿ìÌṩ¸ü¶à×îÐÂÐÂÎÅ¡£Ä¿Ç°£¬ËùÓÐLAAϵͳÔÚ¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC)µÄÐÖúÏÂÒѵõ½±£»¤£¬ÔÚÏßÉêÇë·þÎñÁÙʱÏÂÏß¡£
https://www.bleepingcomputer.com/news/security/uk-legal-aid-agency-confirms-applicant-data-stolen-in-data-breach/
5. NRSÊý¾Ýй¶ÊÂÎñÓ°ÏìHarbinÕïËù³¬20Íò»¼Õß
5ÔÂ19ÈÕ£¬×ôÖÎÑÇÖÝÒ½ÁƱ£½¡ÌṩÉÌHarbinÕïËù½üÈÕ֪ͨ³¬¹ý20ÍòÈË£¬³ÆÆäÓ×ÎÒÐÅÏ¢ÔÚ2024Äê7ÔÂÕ®Îñ´ßÊÕ¹«Ë¾Nationwide Recovery Services£¨NRS£©µÄÊý¾Ýй¶ÊÂÎñÖб»µÁ¡£Õâ´ÎÊÂÎñÔ´ÓÚNRSÄÚ²¿ÏµÍ³³öÏÖ¿ÉÒɻ£¬µ¼ÖÂÍøÂçÖжϡ£µÚÈý·½´ßÊÕ»ú¹¹µ÷²é·¢ÏÖ£¬¹¥»÷ÕßÔÚ7ÔÂ5ÈÕÖÁ11ÈÕÆÚ¼ä½Ó¼ûÁËNRSÍøÂç²¢ÇÔÈ¡Á˲¿ÃÅÊý¾Ý¡£2025Äê2Ô£¬Õ®Îñ´ßÊÕ·þÎñÌṩÉÌ£¨ACCSCIENT×Ó¹«Ë¾£©Í¨ÖªHarbinÕïËù£¬²¿Ãű»µÁÊý¾ÝÉæ¼°Æä»¼Õߣ¬²¢ÓÚ3ÔÂÌṩÁË¿ÉÄÜÊÜÓ°ÏìµÄÓ×ÎÒÃûµ¥¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£Ïպš¢½ðÈÚÕË»§¾ßÌåÐÅÏ¢¡¢µ£±£È˾ßÌåÐÅÏ¢¼°Ò½ÁÆÐÅÏ¢µÈ¡£HarbinÕïµØµã֪ͨÐÅÖгƣ¬NRS»ã±¨Î´·¢ÏÖÉí·Ý͵ÇÔ»òÚ²ÆÐÐΪ֤¾Ý¡£¸ÃÕïËùÒÑÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«Êһ㱨£¬ÓÐ210,140ÈËÊÜÓ°Ï죬²¢ÎªËûÃÇÌṩ24¸öÔÂÃâ·ÑÉí·Ý¼à¿Ø·þÎñ¡£È»¶ø£¬Ç±ÔÚÊÜÓ°ÏìÈËÊý¿ÉÄܸü¸ß£¬ÒòÊÂÎñ»¹²¨¼°NRSÆäËû¿Í»§£¬Ô̺¬×ôÖÎÑÇÖݺÍÌïÄÉÎ÷Öݶà¼ÒÒ½ÁÆ»ú¹¹£¬ÇÒNRSÔÚÃÀ¹ú50¸öÖݾùÓÐÕ®Îñ´ßÊÕÅÆÕÕ¡£Ä¿Ç°£¬NRSÉÐδ¹«¿ªÅû¶ÊÜÓ°Ïì¿Í»§¼°ÈËÊý£¬Ò²Î´ÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£
https://www.securityweek.com/200000-harbin-clinic-patients-impacted-by-nrs-data-breach/
6. ÈðÊ¿µ±¾ÖÖÒ¸æDDoS¹¥»÷Å·Ö޸質´óÈüÓйØÍøÕ¾
5ÔÂ16ÈÕ£¬ÈðÊ¿µ±¾Ö½üÈÕ·¢³öÖÒ¸æ£¬ÍøÂç·¸×ï·Ö×ÓÕë¶ÔÓëÅ·Ö޸質´óÈüÓйصÄÈðÊ¿¾³ÄÚ¶à¸öÍøÕ¾·¢ÆðÁ˶àÆðÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷¡£Ö»¹ÜÕâЩ¹¥»÷ÔÚÒâÁÏÖ®ÖУ¬µ«²¢Î´¶ÔÅ·Ö޸質´óÈüµÄÕý³£ÔËÓªÔì³É×ÌÈÅ¡£ÈðÊ¿¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©Ïò¸÷×éÖ¯·¢³ö¾¯±¨£¬Ö¸³ö¿ÉÄÜ»¹»áÓнøÒ»²½µÄ¹¥»÷£¬ÆäÖ÷ÕÅÖØÒªÊÇÎüÒýýÌ幨ע¡£NCSC°µÊ¾£¬ÔÚÅ·Ö޸質´óÈü¾öÈüǰ£¬Óйػú¹¹ÒÑÆðÍ·Ôâ·ê´ËÀ๥»÷£¬¹¥»÷Õßͨ¹ý·¢ËÍ´óÁ¿¶¨ÏòÒªÇóÊ¹ÍøÕ¾ºÍÀûÓ÷¨Ê½³¬ÔØ£¬µ¼ÖÂÆäÎÞ·¨½Ó¼û»ò½ö²¿ÃſɽӼû¡£²»Í⣬Õâ´Î¹¥»÷ÇкÏÔ¤ÆÚ£¬Ä¿Ç°ÉÐδ¶ÔÅ·Ö޸質´óÈüÔì³ÉÄÚÈÝÐÔÓ°Ïì¡£ÈðÊ¿µ±¾ÖÔ¤¼Æ£¬DDoS¹¥»÷½«³ÖÐøµ½Å·Ö޸質´óÈüʵÏÖ£¬×ܾöÈü¶¨ÓÚ5ÔÂ17ÈÕ½øÐС£Å·Ö޸質´óÈüÊÇÒ»ÏîÄê¶È¹ú¼ÊÒôÀÖ½ÇÖð£¬ÎüÒýÁËÀ´×ÔÅ·ÖÞºÍÆäËû¹ú¶ÈµÄ²ÎÈüÕß¡£NCSCÖ¸³ö£¬DDoS¹¥»÷Êǹ¥»÷ÕßÎüÒý°ÑÎÈÁ¦µÄÒ»ÖÖ³£Óü¿Á©£¬²¢ÒÑÏò¹Ø¼ü»ù´¡ÉèÊ©ÔËÓªÉ̺ͲμÓ×é֯ŷÖ޸質´óÈüµÄ×éÖ¯·¢³öÖҸ棬ºôÓõËûÃDzÉÈ¡Êʵ±´ëÊ©·À±¸´ËÀ๥»÷¡£
https://cybernews.com/security/ddos-attacks-target-eurovision-ncsc-says/


¾©¹«Íø°²±¸11010802024551ºÅ