¿¨µØÑÇϵͳÔâºÚ¿ÍÈëÇÖµ¼Ö¿ͻ§ÐÅϢй¶
°ä²¼¹¦·ò 2025-06-031. ¿¨µØÑÇϵͳÔâºÚ¿ÍÈëÇÖµ¼Ö¿ͻ§ÐÅϢй¶
6ÔÂ2ÈÕ£¬ÉݳÞʱÉÐÆ·ÅÆ¿¨µØÑǽüÈÕÏò¿Í»§·¢³öÖҸ棬³ÆÆäϵͳÔâºÚ¿ÍÈëÇÖ£¬µ¼Ö¿ͻ§Ó×ÎÒÐÅϢй¶¡£ÔÚ֪ͨÐÅÖУ¬¿¨µØÑÇй©ºÚ¿Í»ñÈ¡ÁËÆäϵͳµÄһʱ½Ó¼ûȨÏÞ£¬²¢ÇÔÈ¡ÁËÓÐÏÞÊýÁ¿µÄ¿Í»§ÐÅÏ¢£¬Ô̺¬¿Í»§ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµØµã¹ú¶È£¬µ«Î´Éæ¼°ÃÜÂë¡¢ÐÅÓþ¿¨ºÅ»òÒøÐоßÌåÐÅÏ¢µÈ¸üÃô¸ÐÊý¾Ý¡£¿¨µØÑÇÇ¿µ÷ÒѽÚÔìסÎÊÌ⣬²¢¼ÓÇ¿ÁËϵͳºÍÊý¾ÝµÄ±£»¤£¬Í¬Ê±·î¸æ·¨Âɲ¿ÃÅ£¬ÕýÓë±í²¿ÍøÂ簲ȫ¹«Ë¾ºÏ×÷½¨¸´·ì϶¡£Õâ´Î°²È«·ì϶²¢·Ç¸öÀý£¬´Óǰһ¸öÔÂÄÚ£¬ÆäËûʱÉÐÆ·ÅÆÒ²Åû¶ÁËÀàËÆ°²È«ÊÂÎñ¡£½ñÄê5Ô£¬µÏ°ÂÅû¶Êý¾Ýй¶ÊÂÎñ£¬ÍþвÐÐΪÕßÈëÇÔìäϵͳ£¬ÇÔÈ¡Á˿ͻ§µÄÁªÏµ·½Ê½¡¢²É°ìº¹Çà¼Í¼ºÍÆ«ºÃÉèÖã»Í¬ÑùÔÚÉϸöÔ£¬°¢µÏ´ï˹ÖÒ¸æ¿Í»§£¬ÆäÒ»¼ÒµÚÈý·½·þÎñÌṩÉÌÔâ·êÈëÇÖ£¬µ¼ÖÂÁªÏµÐÅϢй¶£¬µ«Î´»ñÈ¡¸¶¿îÏêÇé»òÕË»§Æ¾Ö¤£»ÉÏÖÜ£¬Î¬¶àÀûÑǵİÂÃØÒò³ÖÐø°²È«ÊÂÎñ¹Ø¹ØÁËÆäÍøÕ¾ºÍ²¿ÃÅÉ̵ê·þÎñ£¬²¢ÒÑÓëÍøÂ簲ȫר¼Ò·¢Õ¹µ÷²é¡£ÕâһϵÁÐÊÂÎñÅú×¢£¬Ê±ÉÐÆ·ÅÆÕýÃæ¶Ô×ÅÈÕÒæÑϸñµÄÍøÂ簲ȫÌôÕ½£¬Ðè¼ÓÇ¿°²È«·À»¤´ëÊ©£¬ÒÔ±£»¤¿Í»§ÐÅÏ¢²»±»Ð¹Â¶¡£
https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/
2. The North FaceÔâÆ¾Ö¤Ìî³ä¹¥»÷£¬¿Í»§ÐÅϢй¶
6ÔÂ2ÈÕ£¬»§±í·þ×°ÁãÊÛÉÌThe North FaceÖÒ¸æ¿Í»§£¬ÆäÓ×ÎÒÐÅÏ¢ÔÚ4ÔÂ·ÝµÄÆ¾Ö¤Ìî³ä¹¥»÷Öб»µÁ¡£The North Face×÷ΪÃÀ¹ú´óÐÍ»§±í·þ×°ºÍÉè±¸Æ·ÅÆ£¬ÄêÊÕÈ볬30ÒÚÃÀÔª£¬µç×ÓÉÌÎñÕ¼Æä×ÜÏúÊÛ¶îµÄ42%¡£Æ¾Ö¤Ìî³ä¹¥»÷ÖУ¬ÍþвÐÐΪÕßÀûÓÃÏÈǰÊý¾Ýй¶Öж³öµÄÓû§Ãû - ÃÜÂë¶Ô×Ô¶¯µÇ¼£¬ÊÔͼ»ñÈ¡Óû§ÕÊ»§Î´¾ÊÚȨµÄ½Ó¼û£¬´Ë¼¼ÊõµÃÒæÓÚ¡°Æ¾Ö¤»ØÊÕ¡±£¬¼´Óû§¶àƽ̨ʹÓÃÒ»ÑùÓû§ÃûºÍÃÜÂ룬µ«ÈôÕË»§Êܶà³É·ÖÉí·ÝÑéÖ¤£¨MFA£©±£»¤£¬¹¥»÷»áʧ°Ü¡£The North FaceÒÑÆðÍ·ÏòÊÜÓ°Ïì¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬²¢Ïò·ðÃÉÌØÖÝ×ܼì²ì³¤·ÖÏíʾÀý֪ͨ£¬·î¸æÆäÍøÕ¾ÔÚ2025Äê4ÔÂ23ÈÕ·¢ÏÖÒì³£»î¶¯£¬¾µ÷²é£¬µ±ÈÕ¹¥»÷Õß·¢ÆðÁËÓ×¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷¡£ÒѶ³öµÄÊý¾ÝÔ̺¬ÐÕÃû¡¢²É°ìº¹Çà¼Í¼¡¢ÊÕ¼þµØÖ·¡¢µç×ÓÓʼþ¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂëµÈ£¬²»Í⸶¿îÐÅϢδй¶£¬ÒòÍøÕ¾¸¶¿îÓÉ±í²¿ÌṩÉÌ´¦Öã¬The North Face½ö±£ÁôʵÏÖÁ÷³ÌËùÐèÁîÅÆ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬The North Face¾ö¶¨²»ºÏËùÓÐÕË»§Ç¿ÔìÖ´ÐÐMFA£¬µ¼ÖÂÆä¿Í»§ÈºËðʧ¾Þ´ó£¬ÕâÊÇ¸ÃÆ·ÅÆÍøÕ¾×Ô2020ÄêÒÔÀ´Ôâ·êµÄµÚËÄÆðƾ֤Ìî³äÊÂÎñ¡£
https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/
3. SentinelOneÒòÈí¼þȱµãÖÂÆßÓ×ʱȫÇò·þÎñÖжÏ
6ÔÂ2ÈÕ£¬ÃÀ¹úÍøÂ簲ȫ¹«Ë¾SentinelOneÉÏÖÜĩй©£¬ÒòÈí¼þ·ì϶µ¼ÖÂÆäÖÜËijöÏÖ³¤´ïÆßÓ×ʱµÄ¡°È«Çò·þÎñÖжϡ±£¬Ó°ÏìÁ˶à¸öÃæÏò¿Í»§µÄ·þÎñ¡£SentinelOneÔÚÖÜËİ䲼µÄÌû×ÓÖÐÈÏ¿ÉÁËÕâ´ÎÖжϣ¬²¢Ïò¿Í»§±£ÕÏÆäϵͳÈÔÊܱ£»¤£¬Ö»ÊÇÍйÜÏìÓ¦·þÎñÎÞ·¨»ñµÃ¿É¼ûÐÔ£¬ÍþвÊý¾Ý»ã±¨½öÑÓ³¤Î´ÃÔʧ£¬ÇÒ³õ²½·ÖÎöÅú×¢Õâ²»Êǰ²È«ÊÂÎñ¡£Á½Ììºó£¬¸Ã¹«Ë¾°ä²¼µ××ÓÔÒò·ÖÎö£¬È·ÈÏÊÂÎñ²¢·ÇÍøÂç¹¥»÷»ò°²È«·ì϶ËùÖ£¬¶øÊÇ»ù´¡ÉèÊ©½ÚÔìϵͳÖеÄÈí¼þȱµãÒý·¢¡£¸Ãȱµã×Ô¶¯É¾³ýÁ˹ؼüÍøÂç·ÓɺÍDNS½âÎöÆ÷¹æ¶¨£¬µ¼Ö·þÎñ´óÃæ»ýÖжϡ£¾ßÌå¶øÑÔ£¬Òò´«³öµÄÔÆÖÎÀíÖ°ÄÜ´æÔÚȱµã£¬AWS Transit Gateway·ÓɱíµÄ±¸·Ý¸´ÔΪ¿Õ£¬ÔÚËùÓбØÐëµÄÏνӻù´¡ÉèÊ©¸´Ôºó£¬·þÎñÖжÏÈÔ³ÖÐø¡£SentinelOneÚ¹Êͳƣ¬¹«Ë¾ÔÚ½«³ö²úϵͳ¹ý¶Éµ½»ùÓÚ»ù´¡ÉèÊ©¼´´úÂ루IaC£©×¼Ôò¹¹½¨µÄÐÂÔÆ¼Ü¹¹£¬Õâ´Îɾ³ý²Ù×÷Óɼ´½«ÆúÓõĽÚÔìϵͳÒò´´½¨ÐÂÕË»§´¥·¢¡£¸Ã½ÚÔìϵͳÅäÖñÈÁ¦Ö°ÄÜ´æÔÚÈí¼þȱµã£¬ÃýÎó¼ø±ð²î¾à²¢ÀûÓÃÁËËùνÕýÈ·µÄÅäÖÃ״̬£¬¸²¸ÇÁËÏÈÇ°ÍøÂçÉèÖ㬵¼Ö¸´ÔÁËÒ»¸ö¿ÕµÄ·ÓÉ±í¡£Õâ´ÎÖжϻ¹ÒÔÖÁ¶Ô¹«Ë¾·þÎñµÄ·¨Ê½½Ó¼ûÖжϣ¬Í³Ò»×ʲúÖÎÀí/¿â´æºÍÉí·Ý·þÎñ¹Ø¹Ø£¬¿Í»§ÎÞ·¨²é¿´·ì϶»ò½Ó¼ûÉí·Ý½ÚÔį̀¡£´Ë±í£¬¿ÉÄÜ»¹Ó°ÏìÁËÀ´×Ô¸÷ÀàµÚÈý·½·þÎñµÄÊý¾ÝÌáÈ¡ÒÔ¼°Íйܼì²âºÍÏìÓ¦£¨MDR£©¾¯±¨¡£
https://www.bleepingcomputer.com/news/technology/sentinelone-last-weeks-7-hour-outage-caused-by-software-flaw/
4. ÍøÂç¹¥»÷Ï®»÷ÁËCovenant HealthÔËÓªµÄÒ½Ôº
6ÔÂ2ÈÕ£¬2025Äê5ÔÂ26ÈÕÆð£¬·ÇͶ»úÐÔÉϵ۽ÌÇøÓòÒ½ÁƱ£½¡ÏµÍ³Covenant HealthÔËÓªµÄÈý¼ÒÒ½ÔºÔâ·êÍøÂç¹¥»÷£¬±»ÆÈ¹Ø¹ØËùÓÐϵͳÒÔ½ÚÔ찲ȫÊÂÎñ¡£Ê¥ÂêÀöÒ½ÁÆÏµÍ³³ÆÊ¥ÂêÀöÒ½ÔºÓöµ½Ò»Ê±ÏµÍ³¹ÊÕÏ£¬²¿Ãŵ绰ºÍÎĵµÏµÍ³ÊÜÓ°Ï죬ҽÁÆ·þÎñ³ÖÐøµ«ºòÕ﹦·ò¿ÉÄܵ¢¸é£»Ê¥Ô¼Éª·òÒ½Ôº°µÊ¾Òòϵͳһʱ¹ÊÕÏ£¬5ÔÂ27ÈÕµ÷ÕûÃÅÕﻯÑé·þÎñ£¬½öÔÚÔºÇøÄÚÊ¢¿ªÇÒÆ¾ÊµÌå¶©µ¥Ìṩ¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´Î¹¥»÷ÖÐÊý¾ÝÊDZ»µÁ»¹ÊÇÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Covenant HealthÀñƸÁ˶¥¼¶ÍøÂ簲ȫר¼ÒÀ´½ÚÔìºÍµ÷²é¡£Ö»¹Ü²¿ÃÅϵͳºÍÃÅÕï³¢ÊÔÊÒÊÜÓ°Ï죬µ«·þÎñÈÔÔÚ³ÖÐø£¬ÖжÏˮƽ¼«Ó×£¬Ðº±²¼Ê²¶ûÖݵÄʥԼɪ·òÒ½ÔººÍÃåÒòÖݵÄÁ½¼ÒÒ½Ôº¾ùÊܲ¨¼°£¬²»Íâ¸Ã»ú¹¹½¨Ò黼Õß°´Ê±¾ÍÕï¡£5ÔÂ26ÈÕ·¢ÏÖÎ¥¹æÐÐΪӰÏìÕû¸ö×éÖ¯ÏνÓÐԺ󣬳öÓÚÉóÉ÷˼¿¼£¬Ò½Ôº¡¢ÕïËùºÍÒ½ÁÆ·þÎñÌṩÕßµÄËùº±¼û¾Ýϵͳ½Ó¼û±»µ±¼´ÖÕ³¡¡£½ØÖÁ׫д±¾ÎÄʱ£¬ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£
https://securityaffairs.com/178507/cyber-crime/a-cyberattack-hit-hospitals-operated-by-covenant-health.html
5. ºÚ¿ÍÔÚÀûÓÃvBulletinÂÛ̳Èí¼þµÄÑϳÁ·ì϶
5ÔÂ30ÈÕ£¬¿ªÔ´ÂÛ̳Èí¼þvBulletin±»·¢ÏÖ´æÔÚÁ½¸öÑϳÁ·ì϶£¬±àºÅ±ðÀëΪCVE-2025-48827ºÍCVE-2025-48828£¬ÆÀ¼¶ÎªÑϳÁ£¬CVSS v3ÆÀ·Ö±ðÀëΪ10.0ºÍ9.0¡£ÕâÁ½¸ö·ìÏ¶Éæ¼°Í¨¹ýÄ£°åÒýÇæÀÄÓ÷ì϶½øÐÐAPI²½ÖèŲÓúÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£µ±vBulletinÔÚPHP 8.1»ò¸ü¸ß°æ±¾ÉÏÔËÐÐʱ£¬°æ±¾5.0.0ÖÁ5.7.5ºÍ6.0.0ÖÁ6.0.3»áÊܵ½Ó°Ïì¡£ÕâЩ·ì϶¿ÉÄÜÔÚÈ¥ÄêÒÑÇÄÈ»½¨¸´£¬µ«ÒòºÜ¶àÍøÕ¾Î´Éý¼¶£¬ÈÔ¶³öÔÚ·çÏÕ֮ϡ£2025Äê5ÔÂ23ÈÕ£¬°²È«×êÑÐÔ±Egidio RomanoÔÚÆä²©¿ÍÉϾßÌåÚ¹ÊÏçËÈôºÎÀûÓÃÕâЩ·ì϶£¬Ö¸³öÎÊÌâÔ´ÓÚvBulletin¶ÔPHP·´ÉäAPIµÄÀÄÓ㬸ÃAPIÔÚPHP 8.1ÖеÄÐÐΪ±ä¶¯ÔÊÐíŲÓÃÊܱ£»¤²½Öè¶øÎÞÐèÃ÷È·µ÷Õû¿É½Ó¼ûÐÔ¡£·ì϶Á´Ô̺¬Í¨¹ý¾«ÐÄÉè¼ÆµÄURLŲÓÃÊܱ£»¤²½Ö裬ÒÔ¼°ÀÄÓÃvBulletinÄ£°åÒýÇæÄÚµÄÄ£°åǰÌá¡£¹¥»÷Õß¿ÉÀûÓÃÒ×Êܹ¥»÷µÄ¡°replaceAdTemplate¡±²½Öè×¢Èë¶ñÒâÄ£°å´úÂë£¬ÈÆ¹ý¡°²»°²È«º¯Êý¡±¹ýÂËÆ÷£¬´Ó¶øÔڵײã·þÎñÆ÷ÉÏʵÏÖÆëȫԶ³Ì¡¢Î´¾Éí·ÝÑéÖ¤µÄ´úÂëÖ´ÐС£5ÔÂ26ÈÕ£¬°²È«×êÑÐÔ±Ryan Dewhurst»ã±¨³ÆÔÚÃÛ¹ÞÈÕÖ¾Öз¢ÏÖ¶Ô´æÔÚ·ì϶µÄ¶ËµãµÄÒªÇ󣬲¢×·×Ùµ½Ò»ÃûÀ´×Ô²¨À¼µÄ¹¥»÷ÕßÊÔͼ²¿ÊðPHPºóÃÅÖ´ÐÐϵͳºÅÁî¡£½¨ÌÖÂÛ̳ÖÎÀíÔ±¾¡¿ìÀûÓð²È«¸üлòÉý¼¶µ½×îа汾6.1.1ÒÔÔ¤·À·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-critical-flaw-in-vbulletin-forum-software/
6. Netbird³ÉÓã²æÊ½´¹µöй¤¾ß£¬Õë¶Ô¶àµØ²ÆÕþ¸ß¹Ü
6ÔÂ2ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢³öÖҸ棬һ³¡ÀûÓúϷ¨Ô¶³Ì½Ó¼û¹¤¾ßNetbirdµÄÐÂÓã²æÊ½´¹µö¹¥»÷»î¶¯ÔÚ½øÐУ¬Ö¸±êÕë¶ÔÅ·ÖÞ¡¢·ÇÖÞ¡¢¼ÓÄôó¡¢Öж«ºÍÄÏÑǵØÓòÒøÐÓ×¢ÄÜÔ´¡¢±£ÏÕºÍͶ×ʹ«Ë¾µÄ²ÆÕþ¸ß¹Ü¡£¸Ã»î¶¯ÓÉTrellix¹«Ë¾ÓÚ2025Äê5ÔÂÖÐÑ®³õ´Î·¢ÏÖ£¬Ä¿Ç°ÉÐδ¹éÒòÓÚÈκÎÒÑÖªÍþвÐÐΪÕß¡£Õâ´Î¹¥»÷ÒÔÒ»·â¼ÙÒâRothschild&CoÕÐÆ¸ÈËÔ±µÄ´¹µöÓʼþΪ³õ²½£¬Í¨¹ýαÔìµÄPDF¸½¼þÁ´½ÓÓÕʹÊܺ¦Õßµã»÷£¬½ø¶ø±»³Á¶¨ÏòÖÁÍйÜÔÚFirebaseÀûÓÃÉϵÄURL¡£¹¥»÷ÕßÀûÓüÓÃܵijÁ¶¨ÏòURLºÍÑéÖ¤Âë¹Ø¿¨À´Èƹý·ÀÓùϵͳ£¬×îÖÕÊèµ¼Êܺ¦ÕßÏÂÔØÔ̺¬¶ñÒâVBScriptµÄZIPѹËõ°ü¡£¸ÃVBScriptÕÆ¹Ü¼ìË÷²¢Ö´ÐÐÏÂÒ»½×¶ÎVBScript£¬ºóÕß»á½øÒ»²½»ñÈ¡ÓÐÐ§ÔØºÉ£¬ÌáÈ¡²¢×°ÖÃNetBirdºÍOpenSSHÁ½¸ö·¨Ê½£¬´´½¨°µ²ØÕË»§¡¢ÆôÓÃÔ¶³Ì×ÀÃæ½Ó¼û£¬²¢Í¨¹ýÉèÖôòË㹤×÷ʹNetBirdÔÚÊÜϰȾϵͳÉÏÓÆ¾Ã»¯ÔËÐУ¬Í¬Ê±É¾³ý×ÀÃæ¿ì½Ý·½Ê½ÒÔ¸²¸ÇÈëÇÖÐÐΪ¡£´Ë±í£¬Trellix»¹·¢ÏÖÒ»¸öÒÑ»îÔ¾½üÒ»ÄêµÄ³Á¶¨ÏòURLÌṩһÑùµÄVBScriptÓÐÐ§ÔØºÉ£¬ÕâÅú×¢¸Ã¹¥»÷»î¶¯¿ÉÄÜÒѳÖÐøÒ»¶Î¹¦·ò¡£
https://thehackernews.com/2025/06/fake-recruiter-emails-target-cfos-using.html


¾©¹«Íø°²±¸11010802024551ºÅ