VeriSource Servicesת´ï400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡

Ðû²¼Ê±¼ä 2025-04-29

1. VeriSource Servicesת´ï400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡


4ÔÂ28ÈÕ£¬ £¬£¬Ô±¹¤¸£ÀûÖÎÀíЧÀÍÌṩÉÌVeriSource Services¿ËÈÕ֪ͨԼ400ÍòÈË£¬ £¬£¬ÆäСÎÒ˽¼ÒÐÅÏ¢ÔÚÒ»ÄêǰÔâÓöºÚ¿Í¹¥»÷²¢±»ÇÔÈ¡¡£¡£¡£¡£¸ÃÊÂÎñÓÚ2024Äê2ÔÂ28ÈÕ±»·¢Ã÷£¬ £¬£¬¼´ÍþвÐÐΪÕßÇÔÈ¡Êý¾ÝµÄÔ½ÈÕ¡£¡£¡£¡£VeriSource¶ÔÊÜËðÊý¾ÝµÄÉó²éÊÂÇéÓÚ2024Äê8ÔÂ12ÈÕÍê³É£¬ £¬£¬ËæºóÔÚÒ»ÖܺóÆô¶¯Á˶ԿÉÄÜÊÜÓ°ÏìСÎÒ˽¼ÒµÄ֪ͨ³ÌÐò¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾ÌåÏÖ£¬ £¬£¬±»µÁÐÅÏ¢Éæ¼°Ê¹ÓÃÆäЧÀ͵Ĺ«Ë¾Ô±¹¤¼°Æä¾ìÊô£¬ £¬£¬ÇÒ¹«Ë¾Ò»Ö±ÓëÕâЩÆóҵϸÃÜÏàÖú£¬ £¬£¬ÒÔÖÜÈ«ÍøÂçÐëÒªÐÅÏ¢£¬ £¬£¬½ø¶øÍ¨ÖªËùÓпÉÄÜÊÜ´ËÊÂÎñ²¨¼°µÄ¸öÌå¡£¡£¡£¡£¸ÃÁ÷³ÌÖ±ÖÁ2025Äê4ÔÂ17ÈÕ²ÅÐû¸æÍê³É£¬ £¬£¬Ö®ºóVeriSourceѸËÙ½ÓÄÉÐж¯£¬ £¬£¬Á¦Õù¾¡¿ì½«ÊÂÎñÏêÇé¼û¸æÊÜÓ°ÏìÖ°Ô±¡£¡£¡£¡£VeriSourceÖ¸³ö£¬ £¬£¬Ð¹Â¶ÐÅÏ¢ÒòСÎÒ˽¼Ò¶øÒ죬 £¬£¬µ«ÆÕ±éº­¸ÇÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ðÐÅÏ¢ÒÔ¼°Éç»áÇå¾²ºÅÂëµÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£Ö»¹ÜVeriSourceÉù³ÆÉÐδ·¢Ã÷Èκα»µÁÐÅÏ¢±»ÀÄÓõÄʵÀý£¬ £¬£¬µ«ÎªÔ¤·ÀDZÔÚΣº¦£¬ £¬£¬¸Ã¹«Ë¾ÒÑ×Ô¶¯ÎªÊÜÓ°ÏìСÎÒ˽¼ÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓÃ¼à¿Ø¼°Éí·Ý±£»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£Í¬Ê±£¬ £¬£¬VeriSourceÔÚ֪ͨÖÐÌáÐÑÓû§£¬ £¬£¬Ó¦×ÐϸºË²é½è¼Ç¿¨ºÍÐÅÓÿ¨Õ˵¥£¬ £¬£¬ÒÔ¼à²âÊÇ·ñ±£´æÒì³£»£»£»£»£»£»î¶¯¡£¡£¡£¡£


https://www.securityweek.com/4-million-affected-by-data-breach-at-verisource-services/


2. ¹ú¼ÊÁªºÏÐж¯Íß½âJokerOTPÍøÂç´¹ÂÚ¹¤¾ß


4ÔÂ28ÈÕ£¬ £¬£¬ÔÚÒ»´Î¹ú¼ÊÁªºÏÖ´·¨Ðж¯ÖУ¬ £¬£¬Ó¢¹úÓëºÉÀ¼¾¯·½ÁªÊÖÆÆ»ñÒ»Æð´ó¹æÄ£ÍøÂçÕ©Æ­°¸£¬ £¬£¬¾Ð²¶Á½ÃûÓëJokerOTPÍøÂç´¹ÂÚ¹¤¾ßÏà¹ØµÄÏÓÒÉÈË¡£¡£¡£¡£¸Ã¹¤¾ßÖ¼ÔÚ×èµ²Ë«ÖØÉí·ÝÑéÖ¤£¨2FA£©´úÂëÒÔÇÔÈ¡×ʽ𣬠£¬£¬¾ÝÔ¤¼Æ£¬ £¬£¬Á½ÄêÄÚÖÁÉÙÔÚ13¸ö¹ú¼Ò±»Ê¹Óó¬2.8Íò´Î£¬ £¬£¬Ôì³É¾­¼ÃËðʧԼ750ÍòÓ¢°÷¡£¡£¡£¡£4ÔÂ22ÈÕ£¬ £¬£¬Ó¢¹ú¿ËÀû·òÀ¼¾¯Ô±¾ÖÍøÂç·¸·¨²¿·ÖÁªºÏºÉÀ¼¾¯·½½ÓÄÉÐж¯£¬ £¬£¬»®·ÖÔÚÓ¢¹úºÍºÉÀ¼¶«²¼À­°àÌØÊ¡¾Ð²¶Ò»Ãû24ËêºÍÒ»Ãû30ËêÄÐ×Ó¡£¡£¡£¡£´Ë´ÎÐж¯Ô´ÓÚÒ»ÏîΪÆÚÈýÄêµÄÊӲ죬 £¬£¬Ö¼ÔÚ²ð³ýJokerOTPÕâÒ»ÖØ´óÍøÂç´¹ÂÚ¹¤¾ß¡£¡£¡£¡£¾Ý¿ËÀû·òÀ¼¾¯·½ÐÂΟ壬 £¬£¬JokerOTPͨ¹ýÓÕÆ­Óû§Ð¹Â¶Òªº¦Éí·ÝÑéÖ¤ÂëµÈ˽ÈËÐÅÏ¢£¬ £¬£¬½ø¶ø¶ÔÊܺ¦ÕßÒøÐÐÕË»§ÊµÑéڲƭÐÔÉúÒâ¡£¡£¡£¡£ÏÓÒÉÈËʹÓá°spit¡±ºÍ¡°defone123¡±µÈ¼ÙÃû¾ÙÐÐÍøÂç¹¥»÷£¬ £¬£¬Ã°³äÒøÐлò¼ÓÃÜÇ®±ÒÉúÒâËù´ú±íÖµçÊܺ¦Õߣ¬ £¬£¬Æ­È¡Ò»´ÎÐÔÃÜÂë»òË«ÖØÈÏÖ¤Â룬 £¬£¬´Ó¶øÈƹýÇå¾²²½·¥²»·¨»á¼ûÕË»§¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬Õþ¸®ÒÑÆô¶¯²ð³ýթƭƽ̨ÔÚÏß»ù´¡ÉèÊ©µÄ³ÌÐò£¬ £¬£¬°üÀ¨ÓëÍйܹ«Ë¾ÏàÖú¹Ø±ÕJokerOTP»úеÈËÆ½Ì¨£¬ £¬£¬Ô¤¼ÆºóÐø½«½ÓÄɽøÒ»²½Ðж¯¡£¡£¡£¡£


https://hackread.com/jokerotp-dismantled-28000-phishing-attacks-2-arrested/


3. ÍþвÐÐΪÕßʹÓÃCraft CMSÁ½¸öÑÏÖØÎó²î·¢¶¯¹¥»÷


4ÔÂ28ÈÕ£¬ £¬£¬¿ËÈÕÍþвÐÐΪÕßʹÓÃCraft CMSÖÐÁ½¸öÐÂÅû¶µÄÑÏÖØÇå¾²Îó²îÌᳫÁãÈÕ¹¥»÷£¬ £¬£¬ÀֳɯÆËðЧÀÍÆ÷²¢»ñȡδ¾­ÊÚȨµÄ»á¼ûȨÏÞ¡£¡£¡£¡£Orange Cyberdefense SensePostÓÚ2025Äê2ÔÂ14ÈÕÊ״μà²âµ½´ËÀ๥»÷£¬ £¬£¬¹¥»÷Éæ¼°CVE-2024-58136ÓëCVE-2025-32432Á½¸ö¸ßΣÎó²î¡£¡£¡£¡£ÆäÖУ¬ £¬£¬CVE-2024-58136Ô´ÓÚCraft CMSʹÓõÄYii PHP¿ò¼ÜÖб¸Ó÷¾¶È±ÏݵIJ»µ±±£»£»£»£»£»£»¤£»£»£»£»£»£»CVE-2025-32432ΪCraft CMSÄÚÖÃͼÏñת»»¹¦Ð§ÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¬ £¬£¬¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§ÏòÈÏÕæÕùÏñת»»µÄ¶Ëµã·¢ËÍPOSTÇëÇó£¬ £¬£¬Ð§ÀÍÆ÷»áÚ¹ÊÍÇëÇóÖеÄÊý¾Ý£¬ £¬£¬½ø¶ø¿ÉÄܵ¼Ö¶ñÒâ´úÂëÖ´ÐС£¡£¡£¡£ÓÉÓÚ²î±ð°æ±¾µÄCraft CMSÔÚ×ʲúID¼ì²éÂß¼­Éϱ£´æ²î±ð£¬ £¬£¬ÍþвÐÐΪÕßÐèÕÒµ½ÓÐÓÃ×ʲúID²Å»ªÊ¹ÓÃÎó²î¡£¡£¡£¡£¹¥»÷Àú³ÌÖУ¬ £¬£¬ÍþвÐÐΪÕß»áÔËÐжà¸öPOSTÇëÇóÊÔ̽ÓÐÓÃ×ʲúID£¬ £¬£¬²¢Ö´ÐÐPython¾ç±¾Ì½²âЧÀÍÆ÷Îó²î£¬ £¬£¬Ò»µ©È·ÈÏÎó²î±£´æ£¬ £¬£¬±ã´ÓGitHub´æ´¢¿âÏÂÔØÐ§ÀÍÆ÷ÉϵÄPHPÎļþ¡£¡£¡£¡£×èÖ¹2025Äê4ÔÂ18ÈÕ£¬ £¬£¬ÒÑÓÐÔ¼13,000¸öCraft CMSʵÀý̻¶ÓÚΣº¦Ö®ÖУ¬ £¬£¬ÆäÖнü300¸öÒѱ»ÈëÇÖ¡£¡£¡£¡£


https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html


4. ÒÁ±ÈÀûÑǰ뵺ÒÉÒòÍøÂç¹¥»÷´ó¹æÄ£Í£µç


4ÔÂ28ÈÕ£¬ £¬£¬ÒÁ±ÈÀûÑǰ뵺ÔâÓö´ó¹æÄ£Í£µç£¬ £¬£¬Î÷°àÑÀÓëÆÏÌÑÑÀµçÁ¦¹©Ó¦ÝëµØÖÐÖ¹£¬ £¬£¬Êý°ÙÍòÃñÖÚÉúÑÄÏÝÈëÆáºÚ¡£¡£¡£¡£µçÁ¦²¿·ÖÐÂÎÅÈËʿ͸¶£¬ £¬£¬ÍøÂç¹¥»÷»òÊÇ´Ë´ÎÊ·ÎÞǰÀýµçÁ¦¹ÊÕϵÄ×î¿ÉÄÜÓÕÒò£¬ £¬£¬µ«Õþ¸®ÉÐδÕýʽȷÈÏ¡£¡£¡£¡£Í£µçʼÓÚÍâµØÊ±¼ä12:30×óÓÒ£¬ £¬£¬±ËʱÎ÷°àÑÀµçÁ¦ÐèÇó˲¼ä´Ó25184Õ×Íß±©µøÖÁ12425Õ×Íߣ¬ £¬£¬ÊÖÒÕר¼Ò½«ÆäÐÎòΪ¡°cero energetico¡±£¬ £¬£¬¼´µçÁ¦ÏµÍ³³¹µ×Í߽⡣¡£¡£¡£µçÁ¦²¿·Ö·ñ¶¨Á˼òÆÓ¶Ì·µÄ¿ÉÄÜÐÔ£¬ £¬£¬Ö¸³öRed El¨¦ctrica¾ß±¸¸ôÀëÊÜÓ°ÏìÇøÓò¡¢±ÜÃâÌìÏÂÐÔ¹ÊÕϵÄϵͳ¡£¡£¡£¡£È»¶ø£¬ £¬£¬ÒµÄÚר¼ÒÇ¿µ÷£¬ £¬£¬µçÍøÖÜÈ«Íß½âºóµÄ»Ö¸´ÊÂÇ鼫Ϊ¼èÄÑ£¬ £¬£¬ÐèÖð¸ö½ÚµãÖØÐÞÍøÂ磬 £¬£¬ºÄʱ¿ÉÄܳ¤´ïÊýСʱÉõÖÁÊýÌì¡£¡£¡£¡£´Ë´ÎÍ£Ó°Ï·Ïì¹æÄ£ÆÕ±é£¬ £¬£¬²»µ«Î÷°àÑÀ±¾ÍÁÊÜÔÖÑÏÖØ£¬ £¬£¬ÆÏÌÑÑÀÈ«¾³¡¢·¨¹úÄϲ¿²¿·ÖµØÇø¼°°²µÀ¶ûÒàÔⲨ¼°£¬ £¬£¬½öÎ÷°àÑÀµÄ¼ÓÄÇÀûȺµººÍ°ÍÀû°¢ÀïȺµºÒò×ÔÁ¦·¢µçϵͳ¶øÐÒÃâ¡£¡£¡£¡£Òªº¦»ù´¡Éèʩ˲¼äÊÜË𣬠£¬£¬ÂíµÂÀï°ÍÀ­¹þ˹¹ú¼Ê»ú³¡ÔÝÍ£ÔËÓª£¬ £¬£¬¸÷´ó¶¼»áµØÌúÍ£°Ú£¬ £¬£¬µçÐÅÍøÂç̱»¾£¬ £¬£¬½»Í¨Ñ¶ºÅµÆÊ§Á飬 £¬£¬Â·¿ÚÖÈÐò´óÂÒ£¬ £¬£¬¶àÈ˱»À§µçÌÝ¡£¡£¡£¡£Red El¨¦ctricaÆô¶¯½ôÆÈ»Ö¸´ÍýÏ룬 £¬£¬ÆðÔ´±¨¸æÏÔʾ°ëµº±±²¿ºÍÄϲ¿µçÁ¦ÕýÖð²½»Ö¸´¡£¡£¡£¡£»£»£»£»£»£»Ö¸´Àú³Ì¸ß¶ÈÒÀÀµË®Á¦·¢µç£¬ £¬£¬Òò¿ÉÔÙÉúÄÜÔ´ÎÞ·¨°ü¹ÜµçÍøÎȹ̣¬ £¬£¬¶ø×ÔÈ»ÆøºÍºËµçÕ¾ÖØÆôÐè½Ï³¤Ê±¼ä¡£¡£¡£¡£


https://cybersecuritynews.com/nationwide-power-outages-in-portugal-spain/


5. Hitachi VantaraÔâAkiraÀÕË÷Èí¼þ¹¥»÷


4ÔÂ28ÈÕ£¬ £¬£¬Hitachi Vantara×÷ΪÈÕ±¾¿ç¹ú¼¯ÍÅÈÕÁ¢µÄ×Ó¹«Ë¾£¬ £¬£¬ÉÏÖÜÄ©ÔâÓöÁËAkiraÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬±»ÆÈ¹Ø±ÕЧÀÍÆ÷ÒÔ×èÖ¹¹¥»÷Ó°Ïì¡£¡£¡£¡£¸Ã¹«Ë¾ÎªÕþ¸®ÊµÌå¼°±¦Âí¡¢Î÷°àÑÀµçÐÅ¡¢T-Mobile¡¢ÖйúµçÐŵÈÈ«Çò×ÅÃûÆ·ÅÆÌṩÊý¾Ý´æ´¢¡¢»ù´¡Éèʩϵͳ¡¢ÔÆÖÎÀíºÍÀÕË÷Èí¼þ»Ö¸´Ð§ÀÍ¡£¡£¡£¡£Hitachi Vantara³Æ2025Äê4ÔÂ26ÈÕ²¿·ÖϵͳÖÐÖ¹£¬ £¬£¬Ò»¼ì²âµ½¿ÉÒɻ£¬ £¬£¬±ãÁ¬Ã¦Æô¶¯ÊÂÎñÏìӦЭÒ飬 £¬£¬Ô¼ÇëµÚÈý·½×¨¼ÒÖ§³ÖÊÓ²ìºÍµ÷½âÁ÷³Ì£¬ £¬£¬²¢×Ô¶¯ÏÂÏßЧÀÍÆ÷¿ØÖÆÊÂÎñ¡£¡£¡£¡£ÏÖÔÚ¹«Ë¾ÕýÓëר¼ÒÏàÖúÐÞ¸´ÊÂÎñ£¬ £¬£¬ÒÔÇå¾²·½·¨»Ö¸´ÏµÍ³£¬ £¬£¬²¢Ð»Ð»¿Í»§ºÍÏàÖúͬ°éµÄÄÍÐÄÓëÎÞаÐÔ¡£¡£¡£¡£´Ë´Î¹¥»÷ËäδӰÏì¹«Ë¾ÔÆÐ§ÀÍ£¬ £¬£¬µ«×÷Ϊ×èÖ¹²½·¥£¬ £¬£¬Hitachi VantaraϵͳºÍÖÆÔìÓªÒµÊܵ½×ÌÈÅ£¬ £¬£¬Ô¶³ÌºÍÖ§³ÖÔËÓªÖÐÖ¹£¬ £¬£¬²»¹ý×ÔÍйÜÇéÐοͻ§ÈÔ¿ÉÕý³£»á¼ûÊý¾Ý¡£¡£¡£¡£±ðµÄ£¬ £¬£¬¹¥»÷»¹Ó°ÏìÁËÕþ¸®ÊµÌåÓµÓеĶà¸öÏîÄ¿¡£¡£¡£¡£AkiraÀÕË÷Èí¼þ×Ô2023Äê3Ô·ºÆðºóѸËÙÔÚÈ«Çò¹æÄ£ÄÚÔì³É´ó×ÚÊܺ¦Õߣ¬ £¬£¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏÌí¼ÓÁË300¶à¸ö×éÖ¯£¬ £¬£¬²¢Éù³ÆÓÐ˹̹¸£´óѧºÍÈÕ²úÆû³µµÈ×ÅÃûÊܺ¦Õß¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hitachi-vantara-takes-servers-offline-after-akira-ransomware-attack/


6. ÎÚ¿ËÀ¼ÔÆÐ§ÀÍÉÌDe NovoÊý¾ÝÖÐÐÄÍ£µçÖÂЧÀÍÖÐÖ¹


4ÔÂ28ÈÕ£¬ £¬£¬ÎÚ¿ËÀ¼ÔÆÌṩÉÌDe NovoÉÏÖÜÄ©±¬·¢Í£µçÊÂÎñ£¬ £¬£¬µ¼ÖÂÕþ¸®»ú¹¹ºÍÖÁ¹«Ë¾µÈ¿Í»§ÔËÓªÖÐÖ¹£¬ £¬£¬ÏÖÔÚЧÀÍÒѻָ´¡£¡£¡£¡£´Ë´ÎÍ£µçÔ´ÓÚDe NovoÊý¾ÝÖÐÐĵçÔ´¹ÊÕÏ£¬ £¬£¬Ó°Ïì¹æÄ£ÆÕ±é£¬ £¬£¬°üÀ¨ÎÚ¿ËÀ¼DiiaÕþ¸®Ó¦ÓóÌÐò¡¢ÍâµØÒøÐС¢ÓÊÕþ¿ìµÝ¾ÞÍ·Nova PostÒÔ¼°Apple PayºÍGoogle PayµÈ·Ç½Ó´¥Ê½Ö§¸¶ÏµÍ³¾ùÔÝʱÏÂÏß¡£¡£¡£¡£»£»£»£»£»£»ù¸¨×¡Ãñ·´Ó¦£¬ £¬£¬ÔÚ½»Í¨ÖÐֹʱ´úÎÞ·¨Ê¹ÓÃÒÆ¶¯Ö§¸¶³Ë×øµØÌú£¬ £¬£¬²¿·Ö²ÍÌüµç×ÓÖ§¸¶ÏµÍ³Ò²·ºÆðÎÊÌâ¡£¡£¡£¡£De NovoºÄʱ½üÁùСʱ»Ö¸´¿Í»§Ð§ÀÍ¡£¡£¡£¡£¹«Ë¾Ê×ϯִÐйÙÂí¿ËÎ÷Ä·¡¤°¢Ï£Ò®·ò½«Í£µç¹é×ïÓÚ×Ô¶¯µçÔÍÆÈ´»ÏµÍ³¡°ÒâÍâ¹ÊÕÏ¡±£¬ £¬£¬µ¼Ö±¸ÓÃµç³ØºÍ²ñÓÍ·¢µç»úÎÞ·¨Æô¶¯£¬ £¬£¬ÉèÊ©¶ÏµçÔ¼15·ÖÖÓ¡£¡£¡£¡£Ëûɨ³ýÁËÍøÂç¹¥»÷µÄ¿ÉÄÜÐÔ£¬ £¬£¬²¢ÌåÏÖ¹«Ë¾ÈÔÔÚÊÓ²ì¹ÊÕÏÔµ¹ÊÔ­ÓÉ¡£¡£¡£¡£×Ô¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´£¬ £¬£¬¸Ã¹ú¶ÔÔÆÊÖÒÕµÄÒÀÀµÈÕÒæÔöÌí£¬ £¬£¬Ðí¶àÆóÒµ½«Êý¾Ý×ªÒÆµ½ÔƶËÒÔ±ÜÃâÎïÀíÆÆË𡣡£¡£¡£ÎªÈ·±£ÔÚÔâÊÜÊý×ÖºÍÎïÀí¹¥»÷ʱѸËÙ»Ö¸´£¬ £¬£¬°üÀ¨Diiaƽ̨ÔÚÄÚµÄÐí¶àÆóÒµºÍÕþ¸®Ð§ÀͶ¼ÒÀÀµ¶à¼ÒÔÆÌṩÉÌ¡£¡£¡£¡£


https://therecord.media/ukraine-state-and-banking-services-restored