VeriSource Services´«µÝ400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡

°ä²¼¹¦·ò 2025-04-29

1. VeriSource Services´«µÝ400ÍòÈËÊý¾ÝÒ»ÄêǰÔâºÚ¿ÍÇÔÈ¡


4ÔÂ28ÈÕ £¬Ô±¹¤¸£ÀûÖÎÀí·þÎñÌṩÉÌVeriSource Services½üÈÕ֪ͨԼ400ÍòÈË £¬ÆäÓ×ÎÒÐÅÏ¢ÔÚÒ»ÄêǰÔâ·êºÚ¿Í¹¥»÷²¢±»ÇÔÈ¡ ¡£¸ÃÊÂÎñÓÚ2024Äê2ÔÂ28ÈÕ±»·¢ÏÖ £¬¼´ÍþвÐÐΪÕßÇÔÈ¡Êý¾ÝµÄ´ÎÈÕ ¡£VeriSource¶ÔÊÜËðÊý¾ÝµÄÉó²é¹¤×÷ÓÚ2024Äê8ÔÂ12ÈÕʵÏÖ £¬ËæºóÔÚÒ»ÖܺóÆô¶¯Á˶ԿÉÄÜÊÜÓ°ÏìÓ×ÎÒµÄ֪ͨ·¨Ê½ ¡£¾Ý¸Ã¹«Ë¾°µÊ¾ £¬±»µÁÐÅÏ¢Éæ¼°Ê¹ÓÃÆä·þÎñµÄ¹«Ë¾Ô±¹¤¼°Æä¾ìÊô £¬ÇÒ¹«Ë¾Ò»ÏòÓëÕâЩÆóÒµçÇÃܺÏ×÷ £¬ÒÔÈ«ÃæÍøÂç±ØÒªÐÅÏ¢ £¬½ø¶øÍ¨ÖªËùÓпÉÄÜÊÜ´ËÊÂÎñ²¨¼°µÄ¸ö±ð ¡£¸ÃÁ÷³ÌÖ±ÖÁ2025Äê4ÔÂ17ÈÕ²ÅÐû¸æÊµÏÖ £¬Ö®ºóVeriSourceѸËÙ²ÉÈ¡Ðж¯ £¬Á¦Ç󾡿콫ÊÂÎñÏêÇé·î¸æÊÜÓ°ÏìÈËÔ± ¡£VeriSourceÖ¸³ö £¬Ð¹Â¶ÐÅÏ¢ÒòÓ×ÎÒ¶øÒì £¬µ«ÆÕ±éº­¸ÇÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ðÐÅÏ¢ÒÔ¼°Éç»á°²È«ºÅÂëµÈÃô¸ÐÄÚÈÝ ¡£Ö»¹ÜVeriSourceÐû³ÆÉÐδ·¢ÏÖÈκα»µÁÐÅÏ¢±»ÀÄÓõÄÊ·ý £¬µ«ÎªÔ¤·ÀDZÔÚ·çÏÕ £¬¸Ã¹«Ë¾ÒÑ×Ô¶¯ÎªÊÜÓ°ÏìÓ×ÎÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý±£»¤·þÎñ ¡£Í¬Ê± £¬VeriSourceÔÚ֪ͨÖÐÌáÐÑÓû§ £¬Ó¦×ÐϸºË²é½è¼Ç¿¨ºÍÐÅÓþ¿¨Õ˵¥ £¬ÒÔ¼à²âÊÇ·ñ´æÔÚÒì³£»î¶¯ ¡£


https://www.securityweek.com/4-million-affected-by-data-breach-at-verisource-services/


2. ¹ú¼Ê½áºÏÐж¯Íß½âJokerOTPÍøÂç´¹µö¹¤¾ß


4ÔÂ28ÈÕ £¬ÔÚÒ»´Î¹ú¼Ê½áºÏ·¨ÂÉÐж¯ÖÐ £¬Ó¢¹úÓëºÉÀ¼¾¯·½ÁªÊÔìÆ»ñһ·´ó¹æÄ£ÍøÂçÚ¿Æ­°¸ £¬¿ÛÁôÁ½ÃûÓëJokerOTPÍøÂç´¹µö¹¤ÓµÓйصÄÏÓÒÉÈË ¡£¸Ã¹¤¾ßÖ¼ÔÚÀ¹½ØË«³ÁÉí·ÝÑéÖ¤£¨2FA£©´úÂëÒÔÇÔÈ¡×ʽ𠣬¾Ý¹À¼Æ £¬Á½ÄêÄÚÖÁÉÙÔÚ13¸ö¹ú¶È±»Ê¹Óó¬2.8Íò´Î £¬Ôì³É¾­¼ÃËðʧԼ750ÍòÓ¢°÷ ¡£4ÔÂ22ÈÕ £¬Ó¢¹ú¿ËÀû·òÀ¼¾¯Ô±¾ÖÍøÂç·¸×ﲿÃŽáºÏºÉÀ¼¾¯·½²ÉÈ¡Ðж¯ £¬±ðÀëÔÚÓ¢¹úºÍºÉÀ¼¶«²¼À­°àÌØÊ¡¿ÛÁôÒ»Ãû24ËêºÍÒ»Ãû30ËêÄÐ×Ó ¡£Õâ´ÎÐж¯Ô´ÓÚÒ»ÏîΪÆÚÈýÄêµÄµ÷²é £¬Ö¼ÔÚ²ð³ýJokerOTPÕâÒ»¸´ÔÓÍøÂç´¹µö¹¤¾ß ¡£¾Ý¿ËÀû·òÀ¼¾¯·½ÐÂΟå £¬JokerOTPͨ¹ýÓÕÆ­Óû§Ð¹Â¶¹Ø¼üÉí·ÝÑéÖ¤ÂëµÈ¸öÈËÐÅÏ¢ £¬½ø¶ø¶ÔÊܺ¦ÕßÒøÐÐÕË»§Ö´ÐÐڲƭÐÔÂòÂô ¡£ÏÓÒÉÈËʹÓá°spit¡±ºÍ¡°defone123¡±µÈ»¯Ãû½øÐÐÍøÂç¹¥»÷ £¬¼ÙÒâÒøÐлò¼ÓÃÜÇ®±ÒÂòÂôËù´ú±íÖµçÊܺ¦Õß £¬Æ­È¡Ò»´ÎÐÔÃÜÂë»òË«³ÁÈÏÖ¤Âë £¬´Ó¶øÈƹý°²È«´ëÊ©·¸·¨½Ó¼ûÕË»§ ¡£Ä¿Ç° £¬µ±¾ÖÒÑÆô¶¯²ð³ýڿƭƽ̨ÔÚÏß»ù´¡ÉèÊ©µÄ·¨Ê½ £¬Ô̺¬ÓëÍйܹ«Ë¾ºÏ×÷¹Ø¹ØJokerOTP»úеÈËÆ½Ì¨ £¬Ô¤¼ÆºóÐø½«²ÉÈ¡½øÒ»²½Ðж¯ ¡£


https://hackread.com/jokerotp-dismantled-28000-phishing-attacks-2-arrested/


3. ÍþвÐÐΪÕßÀûÓÃCraft CMSÁ½¸öÑϳÁ·ì϶·¢Æð¹¥»÷


4ÔÂ28ÈÕ £¬½üÈÕÍþвÐÐΪÕßÀûÓÃCraft CMSÖÐÁ½¸öÐÂÅû¶µÄÑϳÁ°²È«·ì϶ÌáÒéÁãÈÕ¹¥»÷ £¬³É¹¦·ÛËé·þÎñÆ÷²¢»ñȡδ¾­ÊÚȨµÄ½Ó¼ûȨÏÞ ¡£Orange Cyberdefense SensePostÓÚ2025Äê2ÔÂ14ÈÕ³õ´Î¼à²âµ½´ËÀ๥»÷ £¬¹¥»÷Éæ¼°CVE-2024-58136ÓëCVE-2025-32432Á½¸ö¸ßΣ·ì϶ ¡£ÆäÖÐ £¬CVE-2024-58136Ô´ÓÚCraft CMSʹÓõÄYii PHP¿ò¼ÜÖб¸ÓÃõ辶ȱµãµÄ²»µ±±£»¤£»CVE-2025-32432ΪCraft CMSÄÚÖÃͼÏñת»»Ö°ÄÜÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶ £¬¸Ã·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§ÏòÕÆ¹ÜͼÏñת»»µÄ¶Ëµã·¢ËÍPOSTÒªÇó £¬·þÎñÆ÷»áÚ¹ÊÍÒªÇóÖеÄÊý¾Ý £¬½ø¶ø¿ÉÄܵ¼Ö¶ñÒâ´úÂëÖ´ÐÐ ¡£ÓÉÓÚ·ÖÆç°æ±¾µÄCraft CMSÔÚ×ʲúID²é³­Âß¼­ÉÏ´æÔÚ²î¾à £¬ÍþвÐÐΪÕßÐèÕÒµ½ÓÐЧ×ʲúIDÄÜÁ¦ÀûÓ÷ì϶ ¡£¹¥»÷¹ý³ÌÖÐ £¬ÍþвÐÐΪÕß»áÔËÐжà¸öPOSTÒªÇóÊÔ̽ÓÐЧ×ʲúID £¬²¢Ö´ÐÐPython¾ç±¾Ì½²â·þÎñÆ÷·ì϶ £¬Ò»µ©È·ÈÏ·ì϶´æÔÚ £¬±ã´ÓGitHub´æ´¢¿âÏÂÔØ·þÎñÆ÷ÉϵÄPHPÎļþ ¡£½ØÖÁ2025Äê4ÔÂ18ÈÕ £¬ÒÑÓÐÔ¼13,000¸öCraft CMSÊ·ý¶³öÓÚ·çÏÕÖ®ÖÐ £¬ÆäÖнü300¸öÒѱ»ÈëÇÖ ¡£


https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html


4. ÒÁ±ÈÀûÑǰ뵺ÒÉÒòÍøÂç¹¥»÷´ó¹æÄ£Í£µç


4ÔÂ28ÈÕ £¬ÒÁ±ÈÀûÑǰ뵺Ôâ·ê´ó¹æÄ£Í£µç £¬Î÷°àÑÀÓëÆÏÌÑÑÀµçÁ¦¹©¸øÖèÈ»ÖжÏ £¬Êý°ÙÍòÃñ¶àÉúÑÄÏÝÈëÒõÓô ¡£µçÁ¦²¿ÃÅÐÂÎÅÈËʿй© £¬ÍøÂç¹¥»÷»òÊÇÕâ´ÎÊ·ÎÞǰÀýµçÁ¦¹ÊÕϵÄ×î¿ÉÄÜÓÕÒò £¬µ«µ±¾ÖÉÐδÕýʽȷÈÏ ¡£Í£µçʼÓÚ±¾µØ¹¦·ò12:30×óÓÒ £¬±ËʱÎ÷°àÑÀµçÁ¦ÐèҪ˲¼ä´Ó25184Õ×Íß±©µøÖÁ12425Õ×Íß £¬¼¼Êõר¼Ò½«ÆäÃèÊöΪ¡°cero energetico¡± £¬¼´µçÁ¦ÏµÍ³³¹µ×±ÀÀ£ ¡£µçÁ¦²¿ÃÅ·ñ¶¨Á˵¥Ò»¶Ì·µÄ¿ÉÄÜÐÔ £¬Ö¸³öRed El¨¦ctrica¾ß±¸¸ôÀëÊÜÓ°ÏìÇøÓò¡¢Ô¤·ÀÈ«¹úÐÔ¹ÊÕϵÄϵͳ ¡£È»¶ø £¬ÒµÄÚר¼ÒÇ¿µ÷ £¬µçÍøÈ«Ãæ±ÀÀ£ºóµÄ¸´Ô­¹¤×÷¼«Îª¼è¾Þ £¬ÐèÖð¸ö½Úµã³Á½¨ÍøÂç £¬ºÄʱ¿ÉÄܳ¤´ïÊýÓ×ʱÉõÖÁÊýÌì ¡£Õâ´ÎÍ£µçÓ°ÏìÁìÓò¿í·º £¬²»½öÎ÷°àÑÀ±¾ÍÁÊÜÔÖÑϳÁ £¬ÆÏÌÑÑÀÈ«¾³¡¢·¨¹úÄϲ¿²¿ÃŵØÓò¼°°²Â·¶ûÒàÔⲨ¼° £¬½öÎ÷°àÑÀµÄ¼ÓÄÇÀûȺµººÍ°ÍÀû°¢ÀïȺµºÒò¶ÀÁ¢·¢µçϵͳ¶øÐÒÃâ ¡£¹Ø¼ü»ù´¡Éèʩ˲¼äÊÜË𠣬ÂíµÂÀï°ÍÀ­¹þ˹¹ú¼Ê»ú³¡ÔÝÍ£ÔËÓª £¬¸÷´ó³ÇÊеØÌúÍ£°Ú £¬µçÐÅÍøÂç̱»¾ £¬½»Í¨Ñ¶ºÅµÆÊ§Áé £¬Â·¿ÚÖÈÐò´óÂÒ £¬¶àÈ˱»À§µçÌÝ ¡£Red El¨¦ctricaÆô¶¯´¹Î£¸´Ô­´òËã £¬³õ²½»ã±¨ÏÔʾ°ëµº±±²¿ºÍÄϲ¿µçÁ¦ÕýÖ𲽸´Ô­ ¡£¸´Ô­¹ý³Ì¸ß¶ÈÒÀÀµË®Á¦·¢µç £¬Òò¿ÉÔÙÉúÄÜÔ´ÎÞ·¨±£ÏÕµçÍø²»±ä £¬¶øÌìÈ»ÆøºÍºËµçÕ¾³ÁÆôÐè½Ï³¤¹¦·ò ¡£


https://cybersecuritynews.com/nationwide-power-outages-in-portugal-spain/


5. Hitachi VantaraÔâAkiraÀÕË÷Èí¼þ¹¥»÷


4ÔÂ28ÈÕ £¬Hitachi Vantara×÷ΪÈÕ±¾¿ç¹ú¼¯ÍÅÈÕÁ¢µÄ×Ó¹«Ë¾ £¬ÉÏÖÜÄ©Ôâ·êÁËAkiraÀÕË÷Èí¼þ¹¥»÷ £¬±»ÆÈ¹Ø¹Ø·þÎñÆ÷ÒÔ¶ôÔì¹¥»÷Ó°Ïì ¡£¸Ã¹«Ë¾ÎªµÐÔÖʵÌå¼°±¦Âí¡¢Î÷°àÑÀµçÐÅ¡¢T-Mobile¡¢ÖйúµçÐŵÈÈ«Çò³ÛÃûÆ·ÅÆÌṩÊý¾Ý´æ´¢¡¢»ù´¡Éèʩϵͳ¡¢ÔÆÖÎÀíºÍÀÕË÷Èí¼þ¸´Ô­·þÎñ ¡£Hitachi Vantara³Æ2025Äê4ÔÂ26ÈÕ²¿ÃÅϵͳÖжÏ £¬Ò»¼ì²âµ½¿ÉÒɻ £¬±ãÁ¢¼´Æô¶¯ÊÂÎñÏìÓ¦ºÍ̸ £¬ÀñƸµÚÈý·½×¨¼ÒÖ§³Öµ÷²éºÍ²¹¾ÈÁ÷³Ì £¬²¢×Ô¶¯ÏÂÏß·þÎñÆ÷½ÚÔìÊÂÎñ ¡£Ä¿Ç°¹«Ë¾ÕýÓëר¼ÒºÏ×÷½¨¸´ÊÂÎñ £¬ÒÔ°²È«·½Ê½¸´Ô­ÏµÍ³ £¬²¢¸Ð¼¤¿Í»§ºÍºÏ×÷ͬ°éµÄÄÍÐÄÓë½Ã½ÝÐÔ ¡£Õâ´Î¹¥»÷ËäδӰÏì¹«Ë¾ÔÆ·þÎñ £¬µ«×÷Ϊ¶ôÔì´ëÊ© £¬Hitachi VantaraϵͳºÍÔì×÷ÒµÎñÊܵ½×ÌÈÅ £¬Ô¶³ÌºÍÖ§³ÖÔËÓªÖжÏ £¬²»Íâ×ÔÍйܻ·¾³¿Í»§ÈÔ¿ÉÕý³£½Ó¼ûÊý¾Ý ¡£´Ë±í £¬¹¥»÷»¹Ó°ÏìÁ˵ÐÔÖʵÌåÕ¼ÓеĶà¸öÏîÄ¿ ¡£AkiraÀÕË÷Èí¼þ×Ô2023Äê3Ô³öÏÖºóѸËÙÔÚÈ«ÇòÁìÓòÄÚÔì³É´óÁ¿Êܺ¦Õß £¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏÔö³¤ÁË300¶à¸ö×éÖ¯ £¬²¢Ðû³ÆÓÐ˹̹¸£´óѧºÍÈÕ²úÆû³µµÈ³ÛÃûÊܺ¦Õß ¡£


https://www.bleepingcomputer.com/news/security/hitachi-vantara-takes-servers-offline-after-akira-ransomware-attack/


6. ÎÚ¿ËÀ¼ÔÆ·þÎñÉÌDe NovoÊý¾ÝÖÐÐÄÍ£µçÖ·þÎñÖжÏ


4ÔÂ28ÈÕ £¬ÎÚ¿ËÀ¼ÔÆÌṩÉÌDe NovoÉÏÖÜÄ©²úÉúÍ£µçÊÂÎñ £¬µ¼Öµ±¾Ö»ú¹¹ºÍ´ó¹«Ë¾µÈ¿Í»§ÔËÓªÖжÏ £¬Ä¿Ç°·þÎñÒѸ´Ô­ ¡£Õâ´ÎÍ£µçÔ´ÓÚDe NovoÊý¾ÝÖÐÐĵçÔ´¹ÊÕÏ £¬Ó°ÏìÁìÓò¿í·º £¬Ô̺¬ÎÚ¿ËÀ¼Diiaµ±¾ÖÀûÓ÷¨Ê½¡¢±¾µØÒøÐÓ×¢ÓÊÕþ¿ìµÝ¾ÞÍ·Nova PostÒÔ¼°Apple PayºÍGoogle PayµÈ·Ç½Ó´¥Ê½Ö§¸¶ÏµÍ³¾ùÁÙʱÏÂÏß ¡£»ù¸¨¾ÓÃñ·´Ó³ £¬ÔÚ½»Í¨ÖÐ¶ÏÆÚ¼äÎÞ·¨Ê¹ÓÃÒÆ¶¯Ö§¸¶³Ë×øµØÌú £¬²¿ÃŲÍÌüµç×ÓÖ§¸¶ÏµÍ³Ò²³öÏÖÎÊÌâ ¡£De NovoºÄʱ½üÁùÓ×ʱ¸´Ô­¿Í»§·þÎñ ¡£¹«Ë¾Ê×ϯִÐйÙÂí¿ËÎ÷Ä·¡¤°¢Ï£Ò®·ò½«Í£µç¹é×ïÓÚ×Ô¶¯µçÔ´Çл»ÏµÍ³¡°Òâ±í¹ÊÕÏ¡± £¬µ¼Ö±¸ÓÃµç³ØºÍ²ñÓÍ·¢µç»úÎÞ·¨Æô¶¯ £¬ÉèÊ©¶ÏµçÔ¼15·ÖÖÓ ¡£ËûÅųýÁËÍøÂç¹¥»÷µÄ¿ÉÄÜÐÔ £¬²¢°µÊ¾¹«Ë¾ÈÔÔÚµ÷²é¹ÊÕÏÔ­Òò ¡£×Ô¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´ £¬¸Ã¹ú¶ÔÔÆ¼¼ÊõµÄÒÀÀµÈÕÒæÔö³¤ £¬ºÜ¶àÆóÒµ½«Êý¾Ý×ªÒÆµ½ÔƶËÒÔÔ¤·ÀÎïÀí·ÛËé ¡£ÎªÈ·±£ÔÚÔâ·êÊý×ÖºÍÎïÀí¹¥»÷ʱѸËÙ¸´Ô­ £¬Ô̺¬Diiaƽ̨ÔÚÄڵĺܶàÆóÒµºÍµ±¾Ö·þÎñ¶¼ÒÀÀµ¶à¼ÒÔÆÌṩÉÌ ¡£


https://therecord.media/ukraine-state-and-banking-services-restored