VeriSource Servicesת´ï400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡

Ðû²¼Ê±¼ä 2025-04-29

1. VeriSource Servicesת´ï400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡


4ÔÂ28ÈÕ£¬£¬£¬Ô±¹¤¸£ÀûÖÎÀíЧÀÍÌṩÉÌVeriSource Services¿ËÈÕ֪ͨԼ400ÍòÈË£¬£¬£¬ÆäСÎÒ˽¼ÒÐÅÏ¢ÔÚÒ»ÄêǰÔâÓöºÚ¿Í¹¥»÷²¢±»ÇÔÈ¡¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓÚ2024Äê2ÔÂ28ÈÕ±»·¢Ã÷£¬£¬£¬¼´ÍþвÐÐΪÕßÇÔÈ¡Êý¾ÝµÄÔ½ÈÕ¡£¡£¡£¡£¡£¡£VeriSource¶ÔÊÜËðÊý¾ÝµÄÉó²éÊÂÇéÓÚ2024Äê8ÔÂ12ÈÕÍê³É£¬£¬£¬ËæºóÔÚÒ»ÖܺóÆô¶¯Á˶ԿÉÄÜÊÜÓ°ÏìСÎÒ˽¼ÒµÄ֪ͨ³ÌÐò¡£¡£¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬±»µÁÐÅÏ¢Éæ¼°Ê¹ÓÃÆäЧÀ͵Ĺ«Ë¾Ô±¹¤¼°Æä¾ìÊô£¬£¬£¬ÇÒ¹«Ë¾Ò»Ö±ÓëÕâЩÆóҵϸÃÜÏàÖú£¬£¬£¬ÒÔÖÜÈ«ÍøÂçÐëÒªÐÅÏ¢£¬£¬£¬½ø¶øÍ¨ÖªËùÓпÉÄÜÊÜ´ËÊÂÎñ²¨¼°µÄ¸öÌå¡£¡£¡£¡£¡£¡£¸ÃÁ÷³ÌÖ±ÖÁ2025Äê4ÔÂ17ÈÕ²ÅÐû¸æÍê³É£¬£¬£¬Ö®ºóVeriSourceѸËÙ½ÓÄÉÐж¯£¬£¬£¬Á¦Õù¾¡¿ì½«ÊÂÎñÏêÇé¼û¸æÊÜÓ°ÏìÖ°Ô±¡£¡£¡£¡£¡£¡£VeriSourceÖ¸³ö£¬£¬£¬Ð¹Â¶ÐÅÏ¢ÒòСÎÒ˽¼Ò¶øÒ죬£¬£¬µ«ÆÕ±éº­¸ÇÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ðÐÅÏ¢ÒÔ¼°Éç»áÇå¾²ºÅÂëµÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£¡£¡£Ö»¹ÜVeriSourceÉù³ÆÉÐδ·¢Ã÷Èκα»µÁÐÅÏ¢±»ÀÄÓõÄʵÀý£¬£¬£¬µ«ÎªÔ¤·ÀDZÔÚΣº¦£¬£¬£¬¸Ã¹«Ë¾ÒÑ×Ô¶¯ÎªÊÜÓ°ÏìСÎÒ˽¼ÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓÃ¼à¿Ø¼°Éí·Ý± £»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬VeriSourceÔÚ֪ͨÖÐÌáÐÑÓû§£¬£¬£¬Ó¦×ÐϸºË²é½è¼Ç¿¨ºÍÐÅÓÿ¨Õ˵¥£¬£¬£¬ÒÔ¼à²âÊÇ·ñ±£´æÒì³ £»£»£»£»£»£»î¶¯¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/4-million-affected-by-data-breach-at-verisource-services/


2. ¹ú¼ÊÁªºÏÐж¯Íß½âJokerOTPÍøÂç´¹ÂÚ¹¤¾ß


4ÔÂ28ÈÕ£¬£¬£¬ÔÚÒ»´Î¹ú¼ÊÁªºÏÖ´·¨Ðж¯ÖУ¬£¬£¬Ó¢¹úÓëºÉÀ¼¾¯·½ÁªÊÖÆÆ»ñÒ»Æð´ó¹æÄ£ÍøÂçÕ©Æ­°¸£¬£¬£¬¾Ð²¶Á½ÃûÓëJokerOTPÍøÂç´¹ÂÚ¹¤¾ßÏà¹ØµÄÏÓÒÉÈË¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßÖ¼ÔÚ×èµ²Ë«ÖØÉí·ÝÑéÖ¤£¨2FA£©´úÂëÒÔÇÔÈ¡×ʽ𣬣¬£¬¾ÝÔ¤¼Æ£¬£¬£¬Á½ÄêÄÚÖÁÉÙÔÚ13¸ö¹ú¼Ò±»Ê¹Óó¬2.8Íò´Î£¬£¬£¬Ôì³É¾­¼ÃËðʧԼ750ÍòÓ¢°÷¡£¡£¡£¡£¡£¡£4ÔÂ22ÈÕ£¬£¬£¬Ó¢¹ú¿ËÀû·òÀ¼¾¯Ô±¾ÖÍøÂç·¸·¨²¿·ÖÁªºÏºÉÀ¼¾¯·½½ÓÄÉÐж¯£¬£¬£¬»®·ÖÔÚÓ¢¹úºÍºÉÀ¼¶«²¼À­°àÌØÊ¡¾Ð²¶Ò»Ãû24ËêºÍÒ»Ãû30ËêÄÐ×Ó¡£¡£¡£¡£¡£¡£´Ë´ÎÐж¯Ô´ÓÚÒ»ÏîΪÆÚÈýÄêµÄÊӲ죬£¬£¬Ö¼ÔÚ²ð³ýJokerOTPÕâÒ»ÖØ´óÍøÂç´¹ÂÚ¹¤¾ß¡£¡£¡£¡£¡£¡£¾Ý¿ËÀû·òÀ¼¾¯·½ÐÂΟ壬£¬£¬JokerOTPͨ¹ýÓÕÆ­Óû§Ð¹Â¶Òªº¦Éí·ÝÑéÖ¤ÂëµÈ˽ÈËÐÅÏ¢£¬£¬£¬½ø¶ø¶ÔÊܺ¦ÕßÒøÐÐÕË»§ÊµÑéڲƭÐÔÉúÒâ¡£¡£¡£¡£¡£¡£ÏÓÒÉÈËʹÓá°spit¡±ºÍ¡°defone123¡±µÈ¼ÙÃû¾ÙÐÐÍøÂç¹¥»÷£¬£¬£¬Ã°³äÒøÐлò¼ÓÃÜÇ®±ÒÉúÒâËù´ú±íÖµçÊܺ¦Õߣ¬£¬£¬Æ­È¡Ò»´ÎÐÔÃÜÂë»òË«ÖØÈÏÖ¤Â룬£¬£¬´Ó¶øÈƹýÇå¾²²½·¥²»·¨»á¼ûÕË»§¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬Õþ¸®ÒÑÆô¶¯²ð³ýթƭƽ̨ÔÚÏß»ù´¡ÉèÊ©µÄ³ÌÐò£¬£¬£¬°üÀ¨ÓëÍйܹ«Ë¾ÏàÖú¹Ø±ÕJokerOTP»úеÈËÆ½Ì¨£¬£¬£¬Ô¤¼ÆºóÐø½«½ÓÄɽøÒ»²½Ðж¯¡£¡£¡£¡£¡£¡£


https://hackread.com/jokerotp-dismantled-28000-phishing-attacks-2-arrested/


3. ÍþвÐÐΪÕßʹÓÃCraft CMSÁ½¸öÑÏÖØÎó²î·¢¶¯¹¥»÷


4ÔÂ28ÈÕ£¬£¬£¬¿ËÈÕÍþвÐÐΪÕßʹÓÃCraft CMSÖÐÁ½¸öÐÂÅû¶µÄÑÏÖØÇå¾²Îó²îÌᳫÁãÈÕ¹¥»÷£¬£¬£¬ÀֳɯÆËðЧÀÍÆ÷²¢»ñȡδ¾­ÊÚȨµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£Orange Cyberdefense SensePostÓÚ2025Äê2ÔÂ14ÈÕÊ״μà²âµ½´ËÀ๥»÷£¬£¬£¬¹¥»÷Éæ¼°CVE-2024-58136ÓëCVE-2025-32432Á½¸ö¸ßΣÎó²î¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬CVE-2024-58136Ô´ÓÚCraft CMSʹÓõÄYii PHP¿ò¼ÜÖб¸Ó÷¾¶È±ÏݵIJ»µ±± £»£»£»£»£»£»¤ £»£»£»£»£»£»CVE-2025-32432ΪCraft CMSÄÚÖÃͼÏñת»»¹¦Ð§ÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¬£¬£¬¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§ÏòÈÏÕæÕùÏñת»»µÄ¶Ëµã·¢ËÍPOSTÇëÇ󣬣¬£¬Ð§ÀÍÆ÷»áÚ¹ÊÍÇëÇóÖеÄÊý¾Ý£¬£¬£¬½ø¶ø¿ÉÄܵ¼Ö¶ñÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£ÓÉÓÚ²î±ð°æ±¾µÄCraft CMSÔÚ×ʲúID¼ì²éÂß¼­Éϱ£´æ²î±ð£¬£¬£¬ÍþвÐÐΪÕßÐèÕÒµ½ÓÐÓÃ×ʲúID²Å»ªÊ¹ÓÃÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Àú³ÌÖУ¬£¬£¬ÍþвÐÐΪÕß»áÔËÐжà¸öPOSTÇëÇóÊÔ̽ÓÐÓÃ×ʲúID£¬£¬£¬²¢Ö´ÐÐPython¾ç±¾Ì½²âЧÀÍÆ÷Îó²î£¬£¬£¬Ò»µ©È·ÈÏÎó²î±£´æ£¬£¬£¬±ã´ÓGitHub´æ´¢¿âÏÂÔØÐ§ÀÍÆ÷ÉϵÄPHPÎļþ¡£¡£¡£¡£¡£¡£×èÖ¹2025Äê4ÔÂ18ÈÕ£¬£¬£¬ÒÑÓÐÔ¼13,000¸öCraft CMSʵÀý̻¶ÓÚΣº¦Ö®ÖУ¬£¬£¬ÆäÖнü300¸öÒѱ»ÈëÇÖ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html


4. ÒÁ±ÈÀûÑǰ뵺ÒÉÒòÍøÂç¹¥»÷´ó¹æÄ£Í£µç


4ÔÂ28ÈÕ£¬£¬£¬ÒÁ±ÈÀûÑǰ뵺ÔâÓö´ó¹æÄ£Í£µç£¬£¬£¬Î÷°àÑÀÓëÆÏÌÑÑÀµçÁ¦¹©Ó¦ÝëµØÖÐÖ¹£¬£¬£¬Êý°ÙÍòÃñÖÚÉúÑÄÏÝÈëÆáºÚ¡£¡£¡£¡£¡£¡£µçÁ¦²¿·ÖÐÂÎÅÈËʿ͸¶£¬£¬£¬ÍøÂç¹¥»÷»òÊÇ´Ë´ÎÊ·ÎÞǰÀýµçÁ¦¹ÊÕϵÄ×î¿ÉÄÜÓÕÒò£¬£¬£¬µ«Õþ¸®ÉÐδÕýʽȷÈÏ¡£¡£¡£¡£¡£¡£Í£µçʼÓÚÍâµØÊ±¼ä12:30×óÓÒ£¬£¬£¬±ËʱÎ÷°àÑÀµçÁ¦ÐèÇó˲¼ä´Ó25184Õ×Íß±©µøÖÁ12425Õ×Íߣ¬£¬£¬ÊÖÒÕר¼Ò½«ÆäÐÎòΪ¡°cero energetico¡±£¬£¬£¬¼´µçÁ¦ÏµÍ³³¹µ×Í߽⡣¡£¡£¡£¡£¡£µçÁ¦²¿·Ö·ñ¶¨Á˼òÆÓ¶Ì·µÄ¿ÉÄÜÐÔ£¬£¬£¬Ö¸³öRed El¨¦ctrica¾ß±¸¸ôÀëÊÜÓ°ÏìÇøÓò¡¢±ÜÃâÌìÏÂÐÔ¹ÊÕϵÄϵͳ¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬ÒµÄÚר¼ÒÇ¿µ÷£¬£¬£¬µçÍøÖÜÈ«Íß½âºóµÄ»Ö¸´ÊÂÇ鼫Ϊ¼èÄÑ£¬£¬£¬ÐèÖð¸ö½ÚµãÖØÐÞÍøÂ磬£¬£¬ºÄʱ¿ÉÄܳ¤´ïÊýСʱÉõÖÁÊýÌì¡£¡£¡£¡£¡£¡£´Ë´ÎÍ£Ó°Ï·Ïì¹æÄ£ÆÕ±é£¬£¬£¬²»µ«Î÷°àÑÀ±¾ÍÁÊÜÔÖÑÏÖØ£¬£¬£¬ÆÏÌÑÑÀÈ«¾³¡¢·¨¹úÄϲ¿²¿·ÖµØÇø¼°°²µÀ¶ûÒàÔⲨ¼°£¬£¬£¬½öÎ÷°àÑÀµÄ¼ÓÄÇÀûȺµººÍ°ÍÀû°¢ÀïȺµºÒò×ÔÁ¦·¢µçϵͳ¶øÐÒÃâ¡£¡£¡£¡£¡£¡£Òªº¦»ù´¡Éèʩ˲¼äÊÜË𣬣¬£¬ÂíµÂÀï°ÍÀ­¹þ˹¹ú¼Ê»ú³¡ÔÝÍ£ÔËÓª£¬£¬£¬¸÷´ó¶¼»áµØÌúÍ£°Ú£¬£¬£¬µçÐÅÍøÂç̱»¾£¬£¬£¬½»Í¨Ñ¶ºÅµÆÊ§Á飬£¬£¬Â·¿ÚÖÈÐò´óÂÒ£¬£¬£¬¶àÈ˱»À§µçÌÝ¡£¡£¡£¡£¡£¡£Red El¨¦ctricaÆô¶¯½ôÆÈ»Ö¸´ÍýÏ룬£¬£¬ÆðÔ´±¨¸æÏÔʾ°ëµº±±²¿ºÍÄϲ¿µçÁ¦ÕýÖð²½»Ö¸´¡£¡£¡£¡£¡£¡ £»£»£»£»£»£»Ö¸´Àú³Ì¸ß¶ÈÒÀÀµË®Á¦·¢µç£¬£¬£¬Òò¿ÉÔÙÉúÄÜÔ´ÎÞ·¨°ü¹ÜµçÍøÎȹ̣¬£¬£¬¶ø×ÔÈ»ÆøºÍºËµçÕ¾ÖØÆôÐè½Ï³¤Ê±¼ä¡£¡£¡£¡£¡£¡£


https://cybersecuritynews.com/nationwide-power-outages-in-portugal-spain/


5. Hitachi VantaraÔâAkiraÀÕË÷Èí¼þ¹¥»÷


4ÔÂ28ÈÕ£¬£¬£¬Hitachi Vantara×÷ΪÈÕ±¾¿ç¹ú¼¯ÍÅÈÕÁ¢µÄ×Ó¹«Ë¾£¬£¬£¬ÉÏÖÜÄ©ÔâÓöÁËAkiraÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬±»ÆÈ¹Ø±ÕЧÀÍÆ÷ÒÔ×èÖ¹¹¥»÷Ó°Ïì¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÎªÕþ¸®ÊµÌå¼°±¦Âí¡¢Î÷°àÑÀµçÐÅ¡¢T-Mobile¡¢ÖйúµçÐŵÈÈ«Çò×ÅÃûÆ·ÅÆÌṩÊý¾Ý´æ´¢¡¢»ù´¡Éèʩϵͳ¡¢ÔÆÖÎÀíºÍÀÕË÷Èí¼þ»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£¡£Hitachi Vantara³Æ2025Äê4ÔÂ26ÈÕ²¿·ÖϵͳÖÐÖ¹£¬£¬£¬Ò»¼ì²âµ½¿ÉÒɻ£¬£¬£¬±ãÁ¬Ã¦Æô¶¯ÊÂÎñÏìӦЭÒ飬£¬£¬Ô¼ÇëµÚÈý·½×¨¼ÒÖ§³ÖÊÓ²ìºÍµ÷½âÁ÷³Ì£¬£¬£¬²¢×Ô¶¯ÏÂÏßЧÀÍÆ÷¿ØÖÆÊÂÎñ¡£¡£¡£¡£¡£¡£ÏÖÔÚ¹«Ë¾ÕýÓëר¼ÒÏàÖúÐÞ¸´ÊÂÎñ£¬£¬£¬ÒÔÇå¾²·½·¨»Ö¸´ÏµÍ³£¬£¬£¬²¢Ð»Ð»¿Í»§ºÍÏàÖúͬ°éµÄÄÍÐÄÓëÎÞаÐÔ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ËäδӰÏì¹«Ë¾ÔÆÐ§ÀÍ£¬£¬£¬µ«×÷Ϊ×èÖ¹²½·¥£¬£¬£¬Hitachi VantaraϵͳºÍÖÆÔìÓªÒµÊܵ½×ÌÈÅ£¬£¬£¬Ô¶³ÌºÍÖ§³ÖÔËÓªÖÐÖ¹£¬£¬£¬²»¹ý×ÔÍйÜÇéÐοͻ§ÈÔ¿ÉÕý³£»á¼ûÊý¾Ý¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬¹¥»÷»¹Ó°ÏìÁËÕþ¸®ÊµÌåÓµÓеĶà¸öÏîÄ¿¡£¡£¡£¡£¡£¡£AkiraÀÕË÷Èí¼þ×Ô2023Äê3Ô·ºÆðºóѸËÙÔÚÈ«Çò¹æÄ£ÄÚÔì³É´ó×ÚÊܺ¦Õߣ¬£¬£¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏÌí¼ÓÁË300¶à¸ö×éÖ¯£¬£¬£¬²¢Éù³ÆÓÐ˹̹¸£´óѧºÍÈÕ²úÆû³µµÈ×ÅÃûÊܺ¦Õß¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hitachi-vantara-takes-servers-offline-after-akira-ransomware-attack/


6. ÎÚ¿ËÀ¼ÔÆÐ§ÀÍÉÌDe NovoÊý¾ÝÖÐÐÄÍ£µçÖÂЧÀÍÖÐÖ¹


4ÔÂ28ÈÕ£¬£¬£¬ÎÚ¿ËÀ¼ÔÆÌṩÉÌDe NovoÉÏÖÜÄ©±¬·¢Í£µçÊÂÎñ£¬£¬£¬µ¼ÖÂÕþ¸®»ú¹¹ºÍÖÁ¹«Ë¾µÈ¿Í»§ÔËÓªÖÐÖ¹£¬£¬£¬ÏÖÔÚЧÀÍÒѻָ´¡£¡£¡£¡£¡£¡£´Ë´ÎÍ£µçÔ´ÓÚDe NovoÊý¾ÝÖÐÐĵçÔ´¹ÊÕÏ£¬£¬£¬Ó°Ïì¹æÄ£ÆÕ±é£¬£¬£¬°üÀ¨ÎÚ¿ËÀ¼DiiaÕþ¸®Ó¦ÓóÌÐò¡¢ÍâµØÒøÐС¢ÓÊÕþ¿ìµÝ¾ÞÍ·Nova PostÒÔ¼°Apple PayºÍGoogle PayµÈ·Ç½Ó´¥Ê½Ö§¸¶ÏµÍ³¾ùÔÝʱÏÂÏß¡£¡£¡£¡£¡£¡ £»£»£»£»£»£»ù¸¨×¡Ãñ·´Ó¦£¬£¬£¬ÔÚ½»Í¨ÖÐֹʱ´úÎÞ·¨Ê¹ÓÃÒÆ¶¯Ö§¸¶³Ë×øµØÌú£¬£¬£¬²¿·Ö²ÍÌüµç×ÓÖ§¸¶ÏµÍ³Ò²·ºÆðÎÊÌâ¡£¡£¡£¡£¡£¡£De NovoºÄʱ½üÁùСʱ»Ö¸´¿Í»§Ð§ÀÍ¡£¡£¡£¡£¡£¡£¹«Ë¾Ê×ϯִÐйÙÂí¿ËÎ÷Ä·¡¤°¢Ï£Ò®·ò½«Í£µç¹é×ïÓÚ×Ô¶¯µçÔÍÆÈ´»ÏµÍ³¡°ÒâÍâ¹ÊÕÏ¡±£¬£¬£¬µ¼Ö±¸ÓÃµç³ØºÍ²ñÓÍ·¢µç»úÎÞ·¨Æô¶¯£¬£¬£¬ÉèÊ©¶ÏµçÔ¼15·ÖÖÓ¡£¡£¡£¡£¡£¡£Ëûɨ³ýÁËÍøÂç¹¥»÷µÄ¿ÉÄÜÐÔ£¬£¬£¬²¢ÌåÏÖ¹«Ë¾ÈÔÔÚÊÓ²ì¹ÊÕÏÔµ¹ÊÔ­ÓÉ¡£¡£¡£¡£¡£¡£×Ô¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´£¬£¬£¬¸Ã¹ú¶ÔÔÆÊÖÒÕµÄÒÀÀµÈÕÒæÔöÌí£¬£¬£¬Ðí¶àÆóÒµ½«Êý¾Ý×ªÒÆµ½ÔƶËÒÔ±ÜÃâÎïÀíÆÆË𡣡£¡£¡£¡£¡£ÎªÈ·±£ÔÚÔâÊÜÊý×ÖºÍÎïÀí¹¥»÷ʱѸËÙ»Ö¸´£¬£¬£¬°üÀ¨Diiaƽ̨ÔÚÄÚµÄÐí¶àÆóÒµºÍÕþ¸®Ð§ÀͶ¼ÒÀÀµ¶à¼ÒÔÆÌṩÉÌ¡£¡£¡£¡£¡£¡£


https://therecord.media/ukraine-state-and-banking-services-restored