ÃÀµÂ¼Ó½áºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç
°ä²¼¹¦·ò 2026-03-231. ÃÀµÂ¼Ó½áºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç
3ÔÂ20ÈÕ£¬ÃÀ¹ú¡¢µÂ¹úºÍ¼ÓÄôó·¨Âɲ¿ÃŽüÈÕ½áºÏ²ÉÈ¡Ðж¯£¬µ·»ÙÁËAisuru¡¢KimWolf¡¢JackSkidºÍMossadËÄ´ó½©Ê¬ÍøÂçÓÃÓÚϰȾÎïÁªÍø(IoT)É豸µÄºÅÁî½ÚÔì(C2)»ù´¡ÉèÊ©¡£Õâ´Î½áºÏ·¨ÂÉÐж¯»¹Õë¶ÔÐé¹¹·þÎñÆ÷¡¢»¥ÁªÍøÓòÃû¼°ÆäËû»ù´¡ÉèÊ©£¬ÕâЩÉèÊ©±»ËÄ´ó½©Ê¬ÍøÂçÓÃÓÚ½ü¼¸¸öÔ¶ÔÈ«ÇòÊܺ¦ÕßÌáÒéÊýÊ®Íò´Î´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷¡£ÃÀ¹ú˾·¨²¿°µÊ¾£¬Õâ´ÎÐж¯Ö¼ÔÚ·ÛËéÓëËÄ´ó½©Ê¬ÍøÂçÓйصÄͨѶ£¬Ô¤·ÀÉ豸½øÒ»²½Ï°È¾£¬²¢ÏÞ¶È»ò½â³ý½©Ê¬ÍøÂçÌáÒ齫À´¹¥»÷µÄÄÜÁ¦¡£·¨ÔºÎļþÖ¸¿Ø£¬Aisuru½©Ê¬ÍøÂç°ä²¼Á˳¬¹ý20Íò´ÎDDoS¹¥»÷ºÅÁKimWolf°ä²¼Á˳¬¹ý2.5Íò´Î£¬JackSkid°ä²¼Á˳¬¹ý9Íò´Î£¬Mossad°ä²¼Á˳¬¹ý1000´Î¡£Æ¾¾ÝÃÀ¹ú˾·¨²¿Êý¾Ý£¬ÕâЩ½©Ê¬ÍøÂ繲ϰȾ²¢½ÚÔìÁ˳¬¹ý300Íǫ̀IoTÉ豸£¬Ô̺¬ÍøÂçÉãÏñÍ·¡¢Êý×ÖÊÓÆµÂ¼Ïñ»úºÍWiFi·ÓÉÆ÷£¬ÆäÖкܶàÉ豸λÓÚÃÀ¹ú¡£½©Ê¬ÍøÂçÔËÓªÕßÒÔÍøÂç·¸×ï¼´·þÎñģʽÏòÆäËûÍøÂç×ï·¸ÏúÊÛ½Ó¼ûȨÏÞ£¬Ê¹Æä¿ÉÄÜÌáÒéDDoS¹¥»÷£¬Ôì³ÉÊýÍòÃÀÔªËðʧºÍ²¹¾È³É±¾¡£
https://www.bleepingcomputer.com/news/security/aisuru-kimwolf-jackskid-and-mossad-botnets-disrupted-in-joint-action/
2. IntoxalockÔâÍøÂç¹¥»÷ÖÂÈ«ÃÀ˾»úÎÞ·¨Æô¶¯³µÁ¾
3ÔÂ20ÈÕ£¬ÃÀ¹ú³µÁ¾¾Æ¾«²âÊÔÒǹ«Ë¾Intoxalock½üÈÕÔâ·êÍøÂç¹¥»÷£¬µ¼ÖÂÈ«ÃÀ¸÷µØË¾»úÎÞ·¨Æô¶¯³µÁ¾¡£¸Ã¹«Ë¾ÓÚ3ÔÂ14ÈÕÔÚÆäÍøÕ¾ÉÏÈ·ÈÏÕý¾ÀúÍ£»ú£¬ÆäÏúÊ۵ľƾ«²âÊÔÒÇÉ豸Ðè×°ÖÃÔÚ³µÁ¾µã»ð¿ª¹ØÉÏ£¬±»ÒªÇóÌṩÒõÐԾƾ«ºôÆøÑù±¾ÄÜÁ¦Æô¶¯Æû³µµÄÓû§ÒÀÀµ¸ÃÉ豸¡£Intoxalock½²»°ÈËRachael LarsonÏòýÌåÈ·ÈϹ«Ë¾Ôâ·êÍøÂç¹¥»÷£¬²¢°µÊ¾ÒѲÉÈ¡´ëÊ©"ÁÙʱÔÝÍ£²¿ÃÅϵͳ×÷ΪԤ·À´ëÊ©"¡£¹«Ë¾Î´Ð¹Â©¹¥»÷ÀàÐÍ£¬ÈçÊÇ·ñΪÀÕË÷Èí¼þ»òÊý¾Ýй¶£¬Ò²Î´×¢Ã÷ÊÇ·ñÊÕµ½ºÚ¿ÍͨѶ»òÊê½ðÒªÇó¡£ÕâЩ¾Æ¾«²âÊÔÒÇÉ豸Ðèÿ¸ô¼¸¸öÔÂУ׼һ´Î£¬µ«ÍøÂç¹¥»÷µ¼ÖÂIntoxalockÎÞ·¨Ö´ÐÐУ׼¡£¹«Ë¾°µÊ¾±ØÒªÐ£×¼É豸µÄ¿Í»§ÔÚÆô¶¯³µÁ¾Ê±¿ÉÄÜÓöµ½ÑÓ³¤¡£ÔÚRedditÉÏ·¢ÌûµÄ˾»ú°µÊ¾£¬ÈôÊÇ´í¹ýУ׼£¬³µÁ¾½«ÎÞ·¨Æô¶¯£¬ÏÖʵ´ó½«Ë¾»úËøÔÚ³µ±í¡£
https://techcrunch.com/2026/03/20/cyberattack-on-vehicle-breathalyzer-company-leaves-drivers-stranded-across-the-us/
3. Oracle°ä²¼´¹Î£²¹¶¡½¨¸´¹Ø¼üÔ¶³Ì´úÂëÖ´Ðзì϶
3ÔÂ20ÈÕ£¬Oracle½üÈÕ°ä²¼´ø±í°²È«¸üУ¬½¨¸´Éí·ÝÖÎÀíÆ÷ºÍWeb·þÎñÖÎÀíÆ÷ÖбàºÅΪCVE-2026-21992µÄ¹Ø¼üδÈÏÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶¡£¸Ã·ì϶CVSSv3.1ÑϳÁÐÔÆÀ·ÖΪ9.8£¬Ó°ÏìOracleIdentityManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0£¬ÒÔ¼°OracleWebServicesManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0¡£OracleÔÚ×òÈÕ°ä²¼µÄ°²È«Õ÷ѯÖÐÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÀûÓò¹¶¡¡£Õ÷ѯָ³ö£¬¸Ã·ì϶¿ÉÔ¶³ÌÀûÓÃÇÒÎÞÐèÉí·ÝÑéÖ¤£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£·ì϶¸´ÔӶȵͣ¬¿Éͨ¹ýHTTPÔ¶³ÌÀûÓã¬ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥£¬Ôö³¤Á˶³ö·þÎñÆ÷±»ÀûÓõķçÏÕ¡£OracleIdentityManagerÓÃÓÚÖÎÀíÆóÒµÄÚµÄÉí·ÝºÍ½Ó¼û£¬OracleWebServicesManagerΪWeb·þÎñÌṩ°²È«ºÍÖÎÀí½ÚÔì¡£ÕâÁ½¿î²úÆ·¿í·ºÀûÓÃÓÚÆóÒµÉí·ÝÈÏÖ¤ºÍ½Ó¼ûÖÎÀí³¡¾°£¬·ì϶Èô±»ÀûÓÿÉÄܵ¼Ö¹¥»÷Õ߯ëÈ«½ÚÔìÊÜÓ°Ïìϵͳ¡£
https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/
4. ¼ÓÖݸ£Ë¹ÌسÇÔâÀÕË÷¹¥»÷ÔÝÍ£¹«¹²·þÎñ
3ÔÂ21ÈÕ£¬¼ÓÖݸ£Ë¹ÌسǽüÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬±»ÆÈÔÝÍ£³ý´¹Î£ÏìÓ¦±íµÄËùÓй«¹²·þÎñ¡£Õâ×ùλÓھɽðɽÍåÇø¡¢Õ¼ÓÐÔ¼34,000È˶¡µÄ³ÇÊУ¬Æä³ÇÊоÀí°ä·¢½øÈ봹Σ״̬£¬ÒÔ½âËøÀ´×Ô±í²¿»ú¹¹µÄ²¹³ä²ÆÕþÖ§³Ö¡£³ÇÊоÀíStefan Chatwin°µÊ¾£º"¹«¼Ò°²ÂúÊDZ¦ÔËÀ³¹Ù·½ÍøÕ¾×î¸ßÓÅÏȼ¶£¬Òò¶øÎÒÃǼ¤ÀøÉçÇø³ÉÔ±²ÉÈ¡×îÄÜÈ·±£Ó×ÎÒÐÅÏ¢°²È«µÄÔ¤·À´ëÊ©¡£"Êе±¾ÖÖÒ¸æºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡¹«¹²ÐÅÏ¢£¬¶½´ÙÈκÎÓëÊе±¾ÖÓÐÒµÎñÍùÀ´µÄÈËÔ±¸ü¸ÄÓ×ÎÒÃÜÂë²¢²ÉÈ¡´ëÊ©±£»¤Ó×ÎÒÊý¾Ý¡£Êе±¾Ö°µÊ¾911ºÍ¾¯Ô±µ÷¶ÈµÈ´¹Î£·þÎñ"Ö°ÄÜÕý³£ÇÒδÊÜÓ°Ïì"£¬µ«¸£Ë¹ÌسǾ¯Ô±¾ÖÖÜÎåÍí¼ä·¢³ö֪ͨ³Æ£¬Æä·Ç´¹Î£ÈÈÏߺʹ¹Î£Ö±²¦Ïß·ÔÚÁÙʱÖжϺó"ÒѸ´ÔÔËÐÐ"¡£ÓÉÓÚ¹¥»÷£¬ÊÐÒé»á»áÒ齫½öÒÔÏÖ³¡·½Ê½½øÐУ¬²»ÔÙͨ¹ýZoomÌṩ¡£
https://therecord.media/california-city-reports-ransomware-attack-la-metro
5. LAPSUS$Ðû³ÆÇÔÈ¡°¢Ë¹Àû¿µ3GBÄÚ²¿Êý¾Ý
3ÔÂ20ÈÕ£¬×Ô³Æ"LAPSUS$"µÄÍþвÐÐΪÕß×éÖ¯½üÈÕÐû³Æ¶ÔÉæ¼°°¢Ë¹Àû¿µ(AstraZeneca)µÄÊý¾Ýй¶ÊÂÎñÕÆ¹Ü¡£°¢Ë¹Àû¿µÊÇÈ«Çò×î´óµÄ¿ç¹úÔìÒ©ºÍÉúÎï¼¼Êõ¹«Ë¾Ö®Ò»¡£Æ¾¾ÝÔÚºÚ¿ÍÂÛ̳ºÍ¸Ã×éÖ¯¹Ù·½ÍøÕ¾Éϰ䲼µÄÌû×Ó£¬¹¥»÷ÕßÐû³Æ½Ó¼ûÁËÔ±¹¤ÓйØÊý¾Ý¼¯¡¢ÆëȫԴ´úÂë¡¢°ÂÃØºÍ½Ó¼ûÍ´´¦¡¢ÔÆ»ù´¡ÉèÊ©ÅäÖõȡ£Ìû×ÓÔ̺¬¶Ô.tar.gzÌåʽ¿ÉÏÂÔØµµ°¸µÄÒýÓã¬×ÜÊý¾ÝÁ¿Ô¼3GB¡£ºÚ¿ÍÕýÊÔͼ½«Êý¾ÝÏúÊÛ¸ø³ö¼Û×î¸ßÕߣ¬²¢·ÖÏíÁËÑù±¾ÎļþÒÔÖ§³ÔìäÐû³Æ¡£Ñù±¾Êý¾Ý·ÖÎöÏÔʾ£¬Ð¹Â¶Êý¾ÝÖØÒª·ÖΪÈýÀࣺGitHubÓйØÊý¾Ý¡¢µÚÈý·½Êý¾ÝºÍ²ÆÕþÊý¾Ý¡£GitHubÆóÒµÓû§Êý¾ÝÔ̺¬Ô±¹¤ÐÕÃû¡¢³É±¾ÖÐÐIJο¼¡¢Ðí¿ÉÖ¤ÀàÐÍ¡¢ÆóÒµ½ÇÉ«ºÍȨÏÞ¡¢Ë«³É·ÖÉí·ÝÑé֤״̬¡¢GitHubÓû§ÃûºÍÅäÖÃÎļþURL¡¢×éÖ¯½ÇÉ«µÈÐÅÏ¢¡£µÚÈý·½Êý¾ÝËÆºõ¸ú×Ù±í²¿ºÏ×÷ÕߵĽӼûÒªÇóºÍÈëÖ°ÐÅÏ¢£¬Ô̺¬ÄÚ²¿Óû§ID¡¢È«ÃûºÍµç×ÓÓʼþµØÖ·¡¢ÄÚ²¿ÍŶӯÀÂÛ¡¢¹«Ë¾´ÓÊô¹ØÏµ¡¢ÄÚ²¿ÏµÍ³½Ó¼û״̬¡£²ÆÕþÊý¾ÝÔ̺¬¸ß¼¶±ð²ÆÕþͳ¼Æ£¬±êΪ"ËùÓÐÐÐÒµ"£¬ËƺõÊǹ«¹²»òͨÓÃͳ¼ÆÐÅÏ¢£¬Ó밢˹Àû¿µÔËÓªÎÞÖ±½Ó¹ØÁª¡£
https://hackread.com/hacker-group-lapsus-astrazeneca-data-breach/
6. Trivy·ì϶ɨÃèÆ÷Ô⹩¸øÁ´¹¥»÷·Ö·¢ÇÔÃܶñÒâÈí¼þ
3ÔÂ21ÈÕ£¬³ÛÃû·ì϶ɨÃèÆ÷Trivy½üÈÕÔâ·ê¹©¸øÁ´¹¥»÷£¬ÍþвÐÐΪÕß×éÖ¯TeamPCPͨ¹ý¹Ù·½°ä²¼°æ±¾ºÍGitHubActions·Ö·¢Æ¾Ö¤ÇÔÈ¡¶ñÒâÈí¼þ¡£Õâ´Îй¶Óɰ²È«×êÑÐÔ±PaulMcCarty³õ´ÎÅû¶£¬ÖÒ¸æTrivy0.69.4°æ±¾±»Ö²ÈëºóÃÅ£¬¶ñÒâÈÝÆ÷¾µÏñºÍGitHub°ä²¼°æ±¾±»·Ö·¢¸øÓû§¡£¹¥»÷Õß¹¥ÏÂÁËTrivyµÄGitHub¹¹½¨Á÷³Ì£¬½«GitHubActionsÖеÄentrypoint.sh´úÌæÎª¶ñÒâ°æ±¾£¬²¢ÔÚTrivyv0.69.4°ä²¼°æ±¾Öа䲼±»Ö²ÈëºóÃŵĶþ½øÔìÎļþ¡£¹¥»÷ÕßÀÄÆ÷ÓµÓвֿâдÈëȨÏÞµÄÊÜËðÍ´´¦°ä²¼¶ñÒâ°ä²¼°æ±¾£¬ÕâЩʹ´¦À´×Ô3ÔÂÔçЩʱ³½µÄй¶ÊÂÎñ£¬Æäʱʹ´¦´ÓTrivy»·¾³±»±íйÇÒδÆëÈ«½ÚÔì¡£ÍþвÐÐΪÕßÇ¿ÔìÍÆËÍÁËaquasecurity/trivy-action²Ö¿â76¸ö±êÇ©ÖеÄ75¸ö£¬½«Æä³Á¶¨Ïòµ½¶ñÒâÌá½»¡£Ê¹ÓÃÊÜÓ°Ïì±êÇ©µÄ±í²¿¹¤×÷Á÷»áÔÚÔËÐкϷ¨TrivyɨÃè֮ǰ×Ô¶¯Ö´ÐжñÒâ´úÂ룬ʹÈëÇÖÄÑÒÔ¼ì²â¡£¶ñÒâÈí¼þÍøÂç¿úËÅÊý¾Ý²¢É¨ÃèϵͳÖд洢ƾ֤ºÍÈÏÖ¤°ÂÃØµÄÎļþ£¬ÍøÂçµÄÊý¾Ý±»¼ÓÃÜ´æ´¢ÔÚÃûΪtpcp.tar.gzµÄµµ°¸ÖУ¬±íйÖÁÓòÃûɨÃè.aquasecurtiy[.]org¡£Èô±íйʧ°Ü£¬¶ñÒâÈí¼þ»áÔÚÊܺ¦ÕßGitHubÕË»§Öд´½¨ÃûΪtpcp-docsµÄ¹«¹²²Ö¿â²¢ÉÏ´«ÇÔÈ¡µÄÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/trivy-vulnerability-scanner-breach-pushed-infostealer-via-github-actions/


¾©¹«Íø°²±¸11010802024551ºÅ