VeriSource Servicesת´ï400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡
Ðû²¼Ê±¼ä 2025-04-291. VeriSource Servicesת´ï400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡
4ÔÂ28ÈÕ£¬Ô±¹¤¸£ÀûÖÎÀí·þÎñÌṩÉÌVeriSource Services¿ËÈÕ֪ͨԼ400ÍòÈË£¬ÆäСÎÒ˽¼ÒÐÅÏ¢ÔÚÒ»ÄêǰÔâÓöºÚ¿Í¹¥»÷²¢±»ÇÔÈ¡¡£¸ÃÊÂÎñÓÚ2024Äê2ÔÂ28ÈÕ±»·¢Ã÷£¬¼´ÍþвÐÐΪÕßÇÔÈ¡Êý¾ÝµÄÔ½ÈÕ¡£VeriSource¶ÔÊÜËðÊý¾ÝµÄÉó²éÊÂÇéÓÚ2024Äê8ÔÂ12ÈÕÍê³É£¬ËæºóÔÚÒ»ÖܺóÆô¶¯Á˶ԿÉÄÜÊÜÓ°ÏìСÎÒ˽¼ÒµÄ֪ͨ³ÌÐò¡£¾Ý¸Ã¹«Ë¾ÌåÏÖ£¬±»µÁÐÅÏ¢Éæ¼°Ê¹ÓÃÆä·þÎñµÄ¹«Ë¾Ô±¹¤¼°Æä¾ìÊô£¬ÇÒ¹«Ë¾Ò»Ö±ÓëÕâЩÆóҵϸÃÜÏàÖú£¬ÒÔÖÜÈ«ÍøÂçÐëÒªÐÅÏ¢£¬½ø¶øÍ¨ÖªËùÓпÉÄÜÊÜ´ËÊÂÎñ²¨¼°µÄ¸öÌå¡£¸ÃÁ÷³ÌÖ±ÖÁ2025Äê4ÔÂ17ÈÕ²ÅÐû¸æÍê³É£¬Ö®ºóVeriSourceѸËÙ½ÓÄÉÐж¯£¬Á¦Õù¾¡¿ì½«ÊÂÎñÏêÇé¼û¸æÊÜÓ°ÏìÖ°Ô±¡£VeriSourceÖ¸³ö£¬Ð¹Â¶ÐÅÏ¢ÒòСÎÒ˽¼Ò¶øÒ죬µ«ÆÕ±éº¸ÇÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ðÐÅÏ¢ÒÔ¼°Éç»áÇå¾²ºÅÂëµÈÃô¸ÐÄÚÈÝ¡£Ö»¹ÜVeriSourceÉù³ÆÉÐδ·¢Ã÷Èκα»µÁÐÅÏ¢±»ÀÄÓõÄʵÀý£¬µ«ÎªÔ¤·ÀDZÔÚΣº¦£¬¸Ã¹«Ë¾ÒÑ×Ô¶¯ÎªÊÜÓ°ÏìСÎÒ˽¼ÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓÃ¼à¿Ø¼°Éí·Ý±£»¤·þÎñ¡£Í¬Ê±£¬VeriSourceÔÚ֪ͨÖÐÌáÐÑÓû§£¬Ó¦×ÐϸºË²é½è¼Ç¿¨ºÍÐÅÓÿ¨Õ˵¥£¬ÒÔ¼à²âÊÇ·ñ±£´æÒì³£Ô˶¯¡£
https://www.securityweek.com/4-million-affected-by-data-breach-at-verisource-services/
2. ¹ú¼ÊÍŽáÐж¯Íß½âJokerOTPÍøÂç´¹ÂÚ¹¤¾ß
4ÔÂ28ÈÕ£¬ÔÚÒ»´Î¹ú¼ÊÍŽáÖ´·¨Ðж¯ÖУ¬Ó¢¹úÓëºÉÀ¼¾¯·½ÁªÊÖÆÆ»ñÒ»Æð´ó¹æÄ£ÍøÂçթư¸£¬¾Ð²¶Á½ÃûÓëJokerOTPÍøÂç´¹ÂÚ¹¤¾ßÏà¹ØµÄÏÓÒÉÈË¡£¸Ã¹¤¾ßÖ¼ÔÚ×èµ²Ë«ÖØÉí·ÝÑéÖ¤£¨2FA£©´úÂëÒÔÇÔÈ¡×ʽ𣬾ÝÔ¤¼Æ£¬Á½ÄêÄÚÖÁÉÙÔÚ13¸ö¹ú¼Ò±»Ê¹Óó¬2.8Íò´Î£¬Ôì³É¾¼ÃËðʧԼ750ÍòÓ¢°÷¡£4ÔÂ22ÈÕ£¬Ó¢¹ú¿ËÀû·òÀ¼¾¯Ô±¾ÖÍøÂç·¸·¨²¿·ÖÍŽáºÉÀ¼¾¯·½½ÓÄÉÐж¯£¬»®·ÖÔÚÓ¢¹úºÍºÉÀ¼¶«²¼À°àÌØÊ¡¾Ð²¶Ò»Ãû24ËêºÍÒ»Ãû30ËêÄÐ×Ó¡£´Ë´ÎÐж¯Ô´ÓÚÒ»ÏîΪÆÚÈýÄêµÄÊӲ죬ּÔÚ²ð³ýJokerOTPÕâÒ»ÖØ´óÍøÂç´¹ÂÚ¹¤¾ß¡£¾Ý¿ËÀû·òÀ¼¾¯·½ÐÂΟ壬JokerOTPͨ¹ýÓÕÆÓû§Ð¹Â¶Òªº¦Éí·ÝÑéÖ¤ÂëµÈ˽ÈËÐÅÏ¢£¬½ø¶ø¶ÔÊܺ¦ÕßÒøÐÐÕË»§ÊµÑéÚ²ÆÐÔÉúÒâ¡£ÏÓÒÉÈËʹÓá°spit¡±ºÍ¡°defone123¡±µÈ¼ÙÃû¾ÙÐÐÍøÂç¹¥»÷£¬Ã°³äÒøÐлò¼ÓÃÜÇ®±ÒÉúÒâËù´ú±íÖµçÊܺ¦Õߣ¬ÆÈ¡Ò»´ÎÐÔÃÜÂë»òË«ÖØÈÏÖ¤Â룬´Ó¶øÈƹýÇå¾²²½·¥²»·¨»á¼ûÕË»§¡£ÏÖÔÚ£¬Õþ¸®ÒÑÆô¶¯²ð³ýÕ©ÆÆ½Ì¨ÔÚÏß»ù´¡ÉèÊ©µÄ³ÌÐò£¬°üÀ¨ÓëÍйܹ«Ë¾ÏàÖú¹Ø±ÕJokerOTP»úеÈËÆ½Ì¨£¬Ô¤¼ÆºóÐø½«½ÓÄɽøÒ»²½Ðж¯¡£
https://hackread.com/jokerotp-dismantled-28000-phishing-attacks-2-arrested/
3. ÍþвÐÐΪÕßʹÓÃCraft CMSÁ½¸öÑÏÖØÎó²î·¢¶¯¹¥»÷
4ÔÂ28ÈÕ£¬¿ËÈÕÍþвÐÐΪÕßʹÓÃCraft CMSÖÐÁ½¸öÐÂÅû¶µÄÑÏÖØÇå¾²Îó²îÌᳫÁãÈÕ¹¥»÷£¬ÀֳɯÆËð·þÎñÆ÷²¢»ñȡδ¾ÊÚȨµÄ»á¼ûȨÏÞ¡£Orange Cyberdefense SensePostÓÚ2025Äê2ÔÂ14ÈÕÊ״μà²âµ½´ËÀ๥»÷£¬¹¥»÷Éæ¼°CVE-2024-58136ÓëCVE-2025-32432Á½¸ö¸ßΣÎó²î¡£ÆäÖУ¬CVE-2024-58136Ô´ÓÚCraft CMSʹÓõÄYii PHP¿ò¼ÜÖб¸Ó÷¾¶È±ÏݵIJ»µ±±£»¤£»CVE-2025-32432ΪCraft CMSÄÚÖÃͼÏñת»»¹¦Ð§ÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¬¸ÃÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§ÏòÈÏÕæÕùÏñת»»µÄ¶Ëµã·¢ËÍPOSTÇëÇ󣬷þÎñÆ÷»áÚ¹ÊÍÇëÇóÖеÄÊý¾Ý£¬½ø¶ø¿ÉÄܵ¼Ö¶ñÒâ´úÂëÖ´ÐС£ÓÉÓÚ²î±ð°æ±¾µÄCraft CMSÔÚ×ʲúID¼ì²éÂß¼Éϱ£´æ²î±ð£¬ÍþвÐÐΪÕßÐèÕÒµ½ÓÐÓÃ×ʲúID²Å»ªÊ¹ÓÃÎó²î¡£¹¥»÷Àú³ÌÖУ¬ÍþвÐÐΪÕß»áÔËÐжà¸öPOSTÇëÇóÊÔ̽ÓÐÓÃ×ʲúID£¬²¢Ö´ÐÐPython¾ç±¾Ì½²â·þÎñÆ÷Îó²î£¬Ò»µ©È·ÈÏÎó²î±£´æ£¬±ã´ÓGitHub´æ´¢¿âÏÂÔØ·þÎñÆ÷ÉϵÄPHPÎļþ¡£×èÖ¹2025Äê4ÔÂ18ÈÕ£¬ÒÑÓÐÔ¼13,000¸öCraft CMSʵÀý̻¶ÓÚΣº¦Ö®ÖУ¬ÆäÖнü300¸öÒѱ»ÈëÇÖ¡£
https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html
4. ÒÁ±ÈÀûÑǰ뵺ÒÉÒòÍøÂç¹¥»÷´ó¹æÄ£Í£µç
4ÔÂ28ÈÕ£¬ÒÁ±ÈÀûÑǰ뵺ÔâÓö´ó¹æÄ£Í£µç£¬Î÷°àÑÀÓëÆÏÌÑÑÀµçÁ¦¹©Ó¦ÝëµØÖÐÖ¹£¬Êý°ÙÍòÃñÖÚÉúÑÄÏÝÈëÆáºÚ¡£µçÁ¦²¿·ÖÐÂÎÅÈËʿ͸¶£¬ÍøÂç¹¥»÷»òÊÇ´Ë´ÎÊ·ÎÞǰÀýµçÁ¦¹ÊÕϵÄ×î¿ÉÄÜÓÕÒò£¬µ«Õþ¸®ÉÐδÕýʽȷÈÏ¡£Í£µçʼÓÚÍâµØÊ±¼ä12:30×óÓÒ£¬±ËʱÎ÷°àÑÀµçÁ¦ÐèÇó˲¼ä´Ó25184Õ×Íß±©µøÖÁ12425Õ×Íߣ¬ÊÖÒÕר¼Ò½«ÆäÐÎòΪ¡°cero energetico¡±£¬¼´µçÁ¦ÏµÍ³³¹µ×Í߽⡣µçÁ¦²¿·Ö·ñ¶¨Á˼òÆÓ¶Ì·µÄ¿ÉÄÜÐÔ£¬Ö¸³öRed El¨¦ctrica¾ß±¸¸ôÀëÊÜÓ°ÏìÇøÓò¡¢±ÜÃâÌìÏÂÐÔ¹ÊÕϵÄϵͳ¡£È»¶ø£¬ÒµÄÚר¼ÒÇ¿µ÷£¬µçÍøÖÜÈ«Íß½âºóµÄ»Ö¸´ÊÂÇ鼫Ϊ¼èÄÑ£¬ÐèÖð¸ö½ÚµãÖØÐÞÍøÂ磬ºÄʱ¿ÉÄܳ¤´ïÊýСʱÉõÖÁÊýÌì¡£´Ë´ÎÍ£Ó°Ï·Ïì¹æÄ£ÆÕ±é£¬²»µ«Î÷°àÑÀ±¾ÍÁÊÜÔÖÑÏÖØ£¬ÆÏÌÑÑÀÈ«¾³¡¢·¨¹úÄϲ¿²¿·ÖµØÇø¼°°²µÀ¶ûÒàÔⲨ¼°£¬½öÎ÷°àÑÀµÄ¼ÓÄÇÀûȺµººÍ°ÍÀû°¢ÀïȺµºÒò×ÔÁ¦·¢µçϵͳ¶øÐÒÃâ¡£Òªº¦»ù´¡Éèʩ˲¼äÊÜËð£¬ÂíµÂÀï°ÍÀ¹þ˹¹ú¼Ê»ú³¡ÔÝÍ£ÔËÓª£¬¸÷´ó¶¼»áµØÌúÍ£°Ú£¬µçÐÅÍøÂç̱»¾£¬½»Í¨Ñ¶ºÅµÆÊ§Á飬·¿ÚÖÈÐò´óÂÒ£¬¶àÈ˱»À§µçÌÝ¡£Red El¨¦ctricaÆô¶¯½ôÆÈ»Ö¸´ÍýÏ룬ÆðÔ´±¨¸æÏÔʾ°ëµº±±²¿ºÍÄϲ¿µçÁ¦ÕýÖð²½»Ö¸´¡£»Ö¸´Àú³Ì¸ß¶ÈÒÀÀµË®Á¦·¢µç£¬Òò¿ÉÔÙÉúÄÜÔ´ÎÞ·¨°ü¹ÜµçÍøÎȹ̣¬¶ø×ÔÈ»ÆøºÍºËµçÕ¾ÖØÆôÐè½Ï³¤Ê±¼ä¡£
https://cybersecuritynews.com/nationwide-power-outages-in-portugal-spain/
5. Hitachi VantaraÔâAkiraÀÕË÷Èí¼þ¹¥»÷
4ÔÂ28ÈÕ£¬Hitachi Vantara×÷ΪÈÕ±¾¿ç¹ú¼¯ÍÅÈÕÁ¢µÄ×Ó¹«Ë¾£¬ÉÏÖÜÄ©ÔâÓöÁËAkiraÀÕË÷Èí¼þ¹¥»÷£¬±»ÆÈ¹Ø±Õ·þÎñÆ÷ÒÔ×èÖ¹¹¥»÷Ó°Ïì¡£¸Ã¹«Ë¾ÎªÕþ¸®ÊµÌå¼°±¦Âí¡¢Î÷°àÑÀµçÐÅ¡¢T-Mobile¡¢ÖйúµçÐŵÈÈ«Çò×ÅÃûÆ·ÅÆÌṩÊý¾Ý´æ´¢¡¢»ù´¡Éèʩϵͳ¡¢ÔÆÖÎÀíºÍÀÕË÷Èí¼þ»Ö¸´·þÎñ¡£Hitachi Vantara³Æ2025Äê4ÔÂ26ÈÕ²¿·ÖϵͳÖÐÖ¹£¬Ò»¼ì²âµ½¿ÉÒÉÔ˶¯£¬±ãÁ¬Ã¦Æô¶¯ÊÂÎñÏìÓ¦ÐÒ飬ԼÇëµÚÈý·½×¨¼ÒÖ§³ÖÊÓ²ìºÍµ÷½âÁ÷³Ì£¬²¢×Ô¶¯ÏÂÏß·þÎñÆ÷¿ØÖÆÊÂÎñ¡£ÏÖÔÚ¹«Ë¾ÕýÓëר¼ÒÏàÖúÐÞ¸´ÊÂÎñ£¬ÒÔÇå¾²·½·¨»Ö¸´ÏµÍ³£¬²¢Ð»Ð»¿Í»§ºÍÏàÖúͬ°éµÄÄÍÐÄÓëÎÞаÐÔ¡£´Ë´Î¹¥»÷ËäδӰÏì¹«Ë¾ÔÆ·þÎñ£¬µ«×÷Ϊ×èÖ¹²½·¥£¬Hitachi VantaraϵͳºÍÖÆÔìÓªÒµÊܵ½×ÌÈÅ£¬Ô¶³ÌºÍÖ§³ÖÔËÓªÖÐÖ¹£¬²»¹ý×ÔÍйÜÇéÐοͻ§ÈÔ¿ÉÕý³£»á¼ûÊý¾Ý¡£±ðµÄ£¬¹¥»÷»¹Ó°ÏìÁËÕþ¸®ÊµÌåÓµÓеĶà¸öÏîÄ¿¡£AkiraÀÕË÷Èí¼þ×Ô2023Äê3Ô·ºÆðºóѸËÙÔÚÈ«Çò¹æÄ£ÄÚÔì³É´ó×ÚÊܺ¦Õߣ¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏÌí¼ÓÁË300¶à¸ö×éÖ¯£¬²¢Éù³ÆÓÐ˹̹¸£´óѧºÍÈÕ²úÆû³µµÈ×ÅÃûÊܺ¦Õß¡£
https://www.bleepingcomputer.com/news/security/hitachi-vantara-takes-servers-offline-after-akira-ransomware-attack/
6. ÎÚ¿ËÀ¼ÔÆ·þÎñÉÌDe NovoÊý¾ÝÖÐÐÄÍ£µçÖ·þÎñÖÐÖ¹
4ÔÂ28ÈÕ£¬ÎÚ¿ËÀ¼ÔÆÌṩÉÌDe NovoÉÏÖÜÄ©±¬·¢Í£µçÊÂÎñ£¬µ¼ÖÂÕþ¸®»ú¹¹ºÍÖÁ¹«Ë¾µÈ¿Í»§ÔËÓªÖÐÖ¹£¬ÏÖÔÚ·þÎñÒѻָ´¡£´Ë´ÎÍ£µçÔ´ÓÚDe NovoÊý¾ÝÖÐÐĵçÔ´¹ÊÕÏ£¬Ó°Ïì¹æÄ£ÆÕ±é£¬°üÀ¨ÎÚ¿ËÀ¼DiiaÕþ¸®Ó¦ÓóÌÐò¡¢ÍâµØÒøÐС¢ÓÊÕþ¿ìµÝ¾ÞÍ·Nova PostÒÔ¼°Apple PayºÍGoogle PayµÈ·Ç½Ó´¥Ê½Ö§¸¶ÏµÍ³¾ùÔÝʱÏÂÏß¡£»ù¸¨×¡Ãñ·´Ó¦£¬ÔÚ½»Í¨ÖÐֹʱ´úÎÞ·¨Ê¹ÓÃÒÆ¶¯Ö§¸¶³Ë×øµØÌú£¬²¿·Ö²ÍÌüµç×ÓÖ§¸¶ÏµÍ³Ò²·ºÆðÎÊÌâ¡£De NovoºÄʱ½üÁùСʱ»Ö¸´¿Í»§·þÎñ¡£¹«Ë¾Ê×ϯִÐйÙÂí¿ËÎ÷Ä·¡¤°¢Ï£Ò®·ò½«Í£µç¹é×ïÓÚ×Ô¶¯µçÔÍÆÈ´»ÏµÍ³¡°ÒâÍâ¹ÊÕÏ¡±£¬µ¼Ö±¸ÓÃµç³ØºÍ²ñÓÍ·¢µç»úÎÞ·¨Æô¶¯£¬ÉèÊ©¶ÏµçÔ¼15·ÖÖÓ¡£Ëûɨ³ýÁËÍøÂç¹¥»÷µÄ¿ÉÄÜÐÔ£¬²¢ÌåÏÖ¹«Ë¾ÈÔÔÚÊÓ²ì¹ÊÕÏÔµ¹ÊÔÓÉ¡£×Ô¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´£¬¸Ã¹ú¶ÔÔÆÊÖÒÕµÄÒÀÀµÈÕÒæÔöÌí£¬Ðí¶àÆóÒµ½«Êý¾Ý×ªÒÆµ½ÔƶËÒÔ±ÜÃâÎïÀíÆÆËð¡£ÎªÈ·±£ÔÚÔâÊÜÊý×ÖºÍÎïÀí¹¥»÷ʱѸËÙ»Ö¸´£¬°üÀ¨Diiaƽ̨ÔÚÄÚµÄÐí¶àÆóÒµºÍÕþ¸®·þÎñ¶¼ÒÀÀµ¶à¼ÒÔÆÌṩÉÌ¡£
https://therecord.media/ukraine-state-and-banking-services-restored


¾©¹«Íø°²±¸11010802024551ºÅ