KeePassľÂí°æÌìÖ°·¢³¤´ï°ËÔ £¬ÇÔÃܲ¢°²ÅÅÀÕË÷Èí¼þ

Ðû²¼Ê±¼ä 2025-05-20

1. KeePassľÂí°æÌìÖ°·¢³¤´ï°ËÔ £¬ÇÔÃܲ¢°²ÅÅÀÕË÷Èí¼þ


5ÔÂ19ÈÕ £¬WithSecureÍþвÇ鱨ÍŶÓÊӲ췢Ã÷ £¬ÍþвÐÐΪÕßÖÁÉٰ˸öÔÂÀ´Ò»Ö±ÔÚ·Ö·¢KeePassÃÜÂë¹ÜÀíÆ÷µÄľÂí°æ±¾KeeLoader £¬ÒÔʵÑé¶ñÒâ»î¶¯¡£KeePass×÷Ϊ¿ªÔ´Èí¼þ £¬ÆäÔ´´úÂë±»ÍþвÐÐΪÕßÐÞ¸Ä £¬¹¹½¨Á˰üÀ¨Í¨ÀýÃÜÂë¹ÜÀí¹¦Ð§µÄľÂí»¯°æ±¾¡£¸Ã°æ±¾²»µ«ÄÜ×°ÖÃCobalt StrikeÐűê £¬»¹Äܽ«KeePassÃÜÂëÊý¾Ý¿âµ¼³öΪÃ÷ÎIJ¢Í¨¹ýÐűêÇÔÈ¡¡£´Ë´Î»î¶¯ÖÐʹÓõÄCobalt StrikeˮӡÓë³õʼ»á¼û´úÀí(IAB)Ïà¹ØÁª £¬¸Ã´úÀí±»ÒÔΪÓëÒÑÍùµÄBlack BastaÀÕË÷Èí¼þ¹¥»÷ÓйØ¡£Cobalt StrikeˮӡÊÇǶÈëÔÚÐűêÖеÄΨһ±êʶ·û £¬Í¨³£ÓëBlack BastaÀÕË÷Èí¼þÏà¹Ø¡£KeeLoaderÓжàÖÖ±äÖÖ £¬Ê¹ÓÃÕýµ±Ö¤ÊéÊðÃû £¬²¢Í¨¹ýÓòÃûÇÀ×¢¾ÙÐÐÈö²¥¡£ÕâЩ±»Ä¾ÂíѬȾµÄ³ÌÐò²»µ«¾ßÓÐÃÜÂëÇÔÈ¡¹¦Ð§ £¬»¹ÄÜÔÚÓû§·­¿ªKeePassÊý¾Ý¿âʱ £¬½«Êý¾Ýµ¼³öΪCSVÃûÌà £¬±ãÓÚÍþвÐÐΪÕßÇÔÈ¡¡£×îÖÕ £¬WithSecureÊÓ²ìµÄ¹¥»÷µ¼Ö¹«Ë¾VMware ESXi·þÎñÆ÷±»ÀÕË÷Èí¼þ¼ÓÃÜ¡£½øÒ»³ÌÐò²é·¢Ã÷ £¬¸Ã»î¶¯Òѽ¨ÉèÖØ´ó»ù´¡ÉèÊ© £¬ÓÃÓÚ·Ö·¢Î±×°³ÉÕýµ±¹¤¾ßµÄ¶ñÒâ³ÌÐòºÍÖ¼ÔÚÇÔȡƾ֤µÄÍøÂç´¹ÂÚÒ³Ãæ¡£WithSecure½«´Ë»î¶¯¹é×ïÓÚUNC4696×éÖ¯ £¬¸Ã×éÖ¯´ËǰÓëNitrogen Loader»î¶¯ÓÐ¹Ø £¬¶øNitrogen»î¶¯ÓÖÓëBlackCat/ALPHVÀÕË÷Èí¼þÓйØ¡£


https://www.bleepingcomputer.com/news/security/fake-keepass-password-manager-leads-to-esxi-ransomware-attack/


2. ServiceaidÉèÖùýʧÖÂCatholic Health½ü50Íò»¼ÕßÐÅϢй¶


5ÔÂ19ÈÕ £¬ÆóÒµITÌṩÉÌServiceaideÒòÊý¾Ý¿âÉèÖùýʧ £¬µ¼ÖÂÓëŦԼ·ÇÓªÀûÐÔÒ½ÁƱ£½¡ÏµÍ³Catholic HealthÏà¹ØµÄÔ¼483,126Ãû»¼ÕßÃô¸Ð¿µ½¡ºÍСÎÒ˽¼ÒÐÅϢй¶¡£´Ë´Îй¶ԴÓÚÒ»¸öElasticsearchÊý¾Ý¿â±»ÎÞÒâÖйûÕæ £¬±¬·¢ÔÚ2024Äê9ÔÂ19ÈÕÖÁ11ÔÂ5ÈÕʱ´ú £¬ÓÚ11ÔÂ15ÈÕ±»·¢Ã÷ £¬ÖÜÈ«Éó²é²Å¸ÕÍê³É¡£Ö»¹ÜÎÞÈ·ÔäÖ¤¾ÝÅú×¢Êý¾Ý±»ÏÂÔØ»òÀÄÓà £¬µ«¹«Ë¾²»¿Éɨ³ýÕâÖÖ¿ÉÄÜÐÔ¡£Ð¹Â¶µÄÊý¾Ý¿â°üÀ¨´ó×ÚÃô¸ÐÐÅÏ¢ £¬ÈçÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢´¦·½Êý¾Ý¡¢Éç»áÇå¾²ºÅÂë¡¢¿µ½¡°ü¹ÜÏêÇé¡¢Ò½ÁƱ£½¡ÌṩÕßÐÅÏ¢¡¢ÖÎÁƺÍÁÙ´²ÐÅÏ¢¡¢Ò½ÁƼͼºÍÕ˺ÅÒÔ¼°µç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃÜÂëµÈ¡£ServiceaideÕý֪ͨÊÜÓ°ÏìСÎÒ˽¼Ò £¬²¢½ÓÄɲ½·¥±£»¤Ì»Â¶µÄÊý¾Ý¿â £¬Ìí¼ÓеÄÇ徲ЭÒéÒÔ½µµÍδÀ´Î£º¦¡£¸Ã¹«Ë¾»¹ÓëÁª°îî¿Ïµ»ú¹¹ºÏ×÷ £¬ÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿ÒÑÔÚÆäÃñȨ°ì¹«ÊÒÎ¥¹æÃÅ»§ÍøÕ¾ÉϹûÕæÁË´Ë´ÎÊý¾Ýй¶ÊÂÎñ¡£Serviceaide½¨ÒéÊÜÓ°ÏìÓû§¹Ø×¢ÐÅÓñ¨¸æ¡¢¸ü¸ÄÓëÒ½ÁÆÕË»§¹ØÁªµÄÃÜÂë £¬²¢Ë¼Á¿¶³½áÐÅÓá£


https://hackread.com/serviceaide-leak-catholic-health-patients-records/


3. Arla FoodsµÂ¹ú¹¤³§ÔâÍøÂç¹¥»÷ÖÂÉú²úÖÐÖ¹


5ÔÂ19ÈÕ £¬Arla Foods֤ʵ £¬ÆäλÓڵ¹úÎÚÅÁ¶ûµÄÉú²ú²¿·ÖÔâÊÜÁËÍøÂç¹¥»÷ £¬µ¼ÖÂÉú²úÔËÓªÖÐÖ¹¡£Õâ¼Òµ¤ÂóʳÎï¾ÞÍ·ÌåÏÖ £¬´Ë´Î¹¥»÷½öÓ°ÏìÁ˸ÃÉú²ú²¿·Ö £¬µ«Ô¤¼Æ½«Òý·¢²úÆ·½»¸¶ÑÓ³ÙÉõÖÁ×÷·Ï¡£Arla½²»°ÈË³Æ £¬ÔÚÎÚÅÁ¶ûµÄÈ鯷³§·¢Ã÷ÁË¿ÉÒɻ £¬Ó°ÏìÁËÍâµØµÄITÍøÂç £¬³öÓÚÇ徲˼Á¿ £¬Éú²úÔÝʱÊܵ½Ó°Ïì¡£Arla Foods×÷Ϊ¹ú¼ÊÈéÖÆÆ·Éú²úÉ̺ÍÅ©ÃñºÏ×÷Éç £¬ÓµÓÐ7600Ãû³ÉÔ± £¬ÔÚÈ«Çò39¸ö¹ú¼ÒÉèÓзÖÖ§»ú¹¹ £¬Ô±¹¤´ï23000ÈË £¬ÄêÊÕÈë¸ß´ï138ÒÚÅ·Ôª £¬²úÆ·ÏúÍùÈ«Çò140¸ö¹ú¼Ò¡£¹«Ë¾ÕýÆð¾¢»Ö¸´ÊÜÓ°Ï칤³§µÄÔËÓª £¬²¢Ô¤¼Æ½«ÔÚ±¾ÖÜĩǰȡµÃЧ¹û £¬ÆäËû¹¤³§µÄÉú²úÔòδÊÜÓ°Ïì¡£ÓÉÓÚÉú²úÖÐÖ¹µÄÐÂÎÅÔÚÖÜÎ寨¹â £¬Ô¤¼ÆÄ³Ð©ÇéÐÎϽ«·ºÆð²úƷǷȱ¡£ArlaÒÑ֪ͨÊÜÓ°ÏìµÄ¿Í»§¿ÉÄÜ·ºÆð½»»õÑÓ³Ù»ò×÷·ÏµÄÇéÐΡ£µ±±»Îʼ°´Ë´Î¹¥»÷ÊÇ·ñÉæ¼°Êý¾Ý͵ÇÔ»ò¼ÓÃÜʱ £¬Arla¾Ü¾ø·ÖÏí¸ü¶àÐÅÏ¢¡£ÏÖÔÚ £¬ÀÕË÷Èí¼þڲƭÃÅ»§ÍøÕ¾ÉÏÉÐδÐû²¼¹ØÓÚArlaµÄͨ¸æ £¬Òò´Ë¹¥»÷ÀàÐͺÍʵÑéÕßÈÔȻδ֪¡£


https://www.bleepingcomputer.com/news/security/arla-foods-confirms-cyberattack-disrupts-production-causes-delays/


4. Ó¢¹úÖ´·¨Ô®Öú»ú¹¹ÔâÍøÂç¹¥»÷ÖÂÃô¸ÐÊý¾Ýй¶


5ÔÂ19ÈÕ £¬Ó¢¹úÖ´·¨Ô®Öú»ú¹¹(LAA)È·ÈÏ £¬½üÆÚÔâÓöµÄÍøÂç¹¥»÷Ô¶±È×î³õÔ¤ÏëµÄÑÏÖØ £¬ºÚ¿ÍÇÔÈ¡ÁË´ó×ÚÃô¸ÐµÄÉêÇëÈËÊý¾Ý¡£LAA×÷ΪӢ¹ú˾·¨ÊÖÏÂÊôµÄÖ´Ðлú¹¹ £¬ÈÏÕæÎª¾­¼ÃÄÑÌâÕßÌṩִ·¨Ô®Öú £¬´Ë´ÎÊý¾Ýй¶ÊÂÎñÉæ¼°ÖÚ¶àÃô¸ÐÐÅÏ¢¡£±¾ÔÂÔçЩʱ¼ä £¬LAAÔøÅû¶±¬·¢Çå¾²ÊÂÎñ £¬³ÆÓÐÏÞ²ÆÎñÐÅÏ¢¿ÉÄÜй¶ £¬µ«×îÐÂÐÂÎÅÏÔʾ £¬ÇéÐθüΪÑÏËà £¬´ó×Ú×Ô2010ÄêÆðµÄÊý¾Ý¿ÉÄÜÒѱ»ºÚ¿Í»ñÈ¡¡£Ó¢¹úÕþ¸®ÒÑÈ·ÈÏÊý¾Ýй¶ £¬²¢¼ÓÈëÊӲ졣ͨ¸æÖ¸³ö £¬ºÚ¿Í×éÖ¯»ñÈ¡ÁË´ó×ÚÓëÖ´·¨Ô®ÖúÉêÇëÈËÏà¹ØµÄÐÅÏ¢ £¬°üÀ¨ÁªÏµ·½·¨¡¢³öÉúÈÕÆÚ¡¢¹úÃñÉí·ÝÖ¤ºÅÂë¡¢·¸·¨Ê·¡¢¾Íҵ״̬¼°²ÆÎñϸ½ÚµÈ¡£Ó¢¹úÕþ¸®½¨ÒéËùÓÐÉêÇëÈ˼á³ÖСÐÄ £¬½÷·ÀÕ©Æ­ £¬²¢ÔÚ¹²ÏíÃô¸ÐÐÅϢǰºËʵͨѶÄÚÈÝ¡£LAAÊ×ϯִÐйټò¡¤¹þ²©Ìضû¶Ô´ËÌåÏÖǸÒâ £¬²¢ÔÊÐí½«¾¡¿ìÌṩ¸ü¶à×îÐÂÐÂÎÅ¡£ÏÖÔÚ £¬ËùÓÐLAAϵͳÔÚ¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ(NCSC)µÄЭÖúÏÂÒÑ»ñµÃ±£»¤ £¬ÔÚÏßÉêÇë·þÎñÔÝʱÏÂÏß¡£


https://www.bleepingcomputer.com/news/security/uk-legal-aid-agency-confirms-applicant-data-stolen-in-data-breach/


5. NRSÊý¾Ýй¶ÊÂÎñÓ°ÏìHarbinÕïËù³¬20Íò»¼Õß


5ÔÂ19ÈÕ £¬×ôÖÎÑÇÖÝÒ½ÁƱ£½¡ÌṩÉÌHarbinÕïËù¿ËÈÕ֪ͨÁè¼Ý20ÍòÈË £¬³ÆÆäСÎÒ˽¼ÒÐÅÏ¢ÔÚ2024Äê7ÔÂÕ®Îñ´ßÊÕ¹«Ë¾Nationwide Recovery Services£¨NRS£©µÄÊý¾Ýй¶ÊÂÎñÖб»µÁ¡£´Ë´ÎÊÂÎñÔ´ÓÚNRSÄÚ²¿ÏµÍ³·ºÆð¿ÉÒɻ £¬µ¼ÖÂÍøÂçÖÐÖ¹¡£µÚÈý·½´ßÊÕ»ú¹¹ÊӲ췢Ã÷ £¬¹¥»÷ÕßÔÚ7ÔÂ5ÈÕÖÁ11ÈÕʱ´ú»á¼ûÁËNRSÍøÂç²¢ÇÔÈ¡Á˲¿·ÖÊý¾Ý¡£2025Äê2Ô £¬Õ®Îñ´ßÊÕ·þÎñÌṩÉÌ£¨ACCSCIENT×Ó¹«Ë¾£©Í¨ÖªHarbinÕïËù £¬²¿·Ö±»µÁÊý¾ÝÉæ¼°Æä»¼Õß £¬²¢ÓÚ3ÔÂÌṩÁË¿ÉÄÜÊÜÓ°ÏìµÄСÎÒ˽¼ÒÃûµ¥¡£Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅ¡¢½ðÈÚÕË»§ÏêϸÐÅÏ¢¡¢µ£±£ÈËÏêϸÐÅÏ¢¼°Ò½ÁÆÐÅÏ¢µÈ¡£HarbinÕïËùÔÚ֪ͨÐÅÖÐ³Æ £¬NRS±¨¸æÎ´·¢Ã÷Éí·Ý͵ÇÔ»òڲƭÐÐΪ֤¾Ý¡£¸ÃÕïËùÒÑÏòÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒ±¨¸æ £¬ÓÐ210,140ÈËÊÜÓ°Ïì £¬²¢ÎªËûÃÇÌṩ24¸öÔÂÃâ·ÑÉí·Ý¼à¿Ø·þÎñ¡£È»¶ø £¬Ç±ÔÚÊÜÓ°ÏìÈËÊý¿ÉÄܸü¸ß £¬ÒòÊÂÎñ»¹²¨¼°NRSÆäËû¿Í»§ £¬°üÀ¨×ôÖÎÑÇÖݺÍÌïÄÉÎ÷Öݶà¼ÒÒ½ÁÆ»ú¹¹ £¬ÇÒNRSÔÚÃÀ¹ú50¸öÖݾùÓÐÕ®Îñ´ßÊÕÖ´ÕÕ¡£ÏÖÔÚ £¬NRSÉÐδ¹ûÕæÅû¶ÊÜÓ°Ïì¿Í»§¼°ÈËÊý £¬Ò²Î´ÓÐÀÕË÷Èí¼þ×éÖ¯Éù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£


https://www.securityweek.com/200000-harbin-clinic-patients-impacted-by-nrs-data-breach/


6. ÈðÊ¿Õþ¸®ÖÒÑÔDDoS¹¥»÷Å·ÖÞÔÞÃÀ´óÈüÏà¹ØÍøÕ¾


5ÔÂ16ÈÕ £¬ÈðÊ¿Õþ¸®¿ËÈÕ·¢³öÖÒÑÔ £¬ÍøÂç·¸·¨·Ö×ÓÕë¶ÔÓëÅ·ÖÞÔÞÃÀ´óÈüÏà¹ØµÄÈðÊ¿¾³ÄÚ¶à¸öÍøÕ¾·¢¶¯Á˶àÆðÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷¡£Ö»¹ÜÕâЩ¹¥»÷ÔÚÒâÁÏÖ®ÖÐ £¬µ«²¢Î´¶ÔÅ·ÖÞÔÞÃÀ´óÈüµÄÕý³£ÔËÓªÔì³É×ÌÈÅ¡£ÈðÊ¿¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ïò¸÷×éÖ¯·¢³ö¾¯±¨ £¬Ö¸³ö¿ÉÄÜ»¹»áÓнøÒ»²½µÄ¹¥»÷ £¬ÆäÄ¿µÄÖ÷ÒªÊÇÎüÒýýÌ幨ע¡£NCSCÌåÏÖ £¬ÔÚÅ·ÖÞÔÞÃÀ´óÈü¾öÈüǰ £¬Ïà¹Ø»ú¹¹ÒÑ×îÏÈÔâÊÜ´ËÀ๥»÷ £¬¹¥»÷Õßͨ¹ý·¢ËÍ´ó×Ú¶¨ÏòÇëÇóÊ¹ÍøÕ¾ºÍÓ¦ÓóÌÐò³¬ÔØ £¬µ¼ÖÂÆäÎÞ·¨»á¼û»ò½ö²¿·Ö¿É»á¼û¡£²»¹ý £¬´Ë´Î¹¥»÷ÇкÏÔ¤ÆÚ £¬ÏÖÔÚÉÐδ¶ÔÅ·ÖÞÔÞÃÀ´óÈüÔì³ÉʵÖÊÐÔÓ°Ïì¡£ÈðÊ¿Õþ¸®Ô¤¼Æ £¬DDoS¹¥»÷½«Ò»Á¬µ½Å·ÖÞÔÞÃÀ´óÈü¿¢Ê £¬×ܾöÈü¶¨ÓÚ5ÔÂ17ÈÕ¾ÙÐС£Å·ÖÞÔÞÃÀ´óÈüÊÇÒ»ÏîÄê¶È¹ú¼ÊÒôÀÖ½ÇÖ𠣬ÎüÒýÁËÀ´×ÔÅ·ÖÞºÍÆäËû¹ú¼ÒµÄ²ÎÈüÕß¡£NCSCÖ¸³ö £¬DDoS¹¥»÷Êǹ¥»÷ÕßÎüÒý×¢ÖØÁ¦µÄÒ»ÖÖ³£ÓÃÊÖ¶Î £¬²¢ÒÑÏòÒªº¦»ù´¡ÉèÊ©ÔËÓªÉ̺ͼÓÈë×é֯ŷÖÞÔÞÃÀ´óÈüµÄ×éÖ¯·¢³öÖÒÑÔ £¬ºôÓõËûÃǽÓÄÉÊʵ±²½·¥Ìá·À´ËÀ๥»÷¡£


https://cybernews.com/security/ddos-attacks-target-eurovision-ncsc-says/