KelpDAOÔâ2.9ÒÚÃÀÔª¼ÓÃÜÇ®±Ò͵ÇÔ
°ä²¼¹¦·ò 2026-04-211. KelpDAOÔâ2.9ÒÚÃÀÔª¼ÓÃÜÇ®±Ò͵ÇÔ
4ÔÂ20ÈÕ£¬DeFiÏîÄ¿KelpDAOÔâ·êÁ˼ÛÖµÔ¼2.9ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò͵ÇÔ°¸£¬¾ÝÐÅÊdz¯Ïʹú¶ÈÖ§³ÖµÄºÚ¿ÍËùΪ¡£Õâ´Î¹¥»÷»¹Ó°ÏìÁËCompound¡¢EulerºÍAaveµÈ½è´ûºÍ̸£¬ÆäÖÐAaveÒѰ䷢¶³½á²¢×èֹʹÓÃrsETH×÷ΪµÖѺƷµÄдæ¿î»ò¸æ´û¡£4ÔÂ18ÈÕ£¬KelpDAO°ä·¢¼ì²âµ½Éæ¼°rsETHµÄ¡°¿ÉÒÉ¿çÁ´»î¶¯¡±£¬Ëæ¼´ÔÝÍ£ÁËÒÔÌ«·»Ö÷ÍøºÍL2ÉϵÄrsETHºÏÔ¼£¬²¢ÔÚLayerZero¡¢UnichainµÈºÏ×÷ͬ°éµÄÐÖúÏ·¢Õ¹µ÷²é¡£Çø¿éÁ´»î¶¯ÏÔʾ£¬Ô¼ÓÐ116,500¸örsETH±»µÁ£¬¼ÛÖµÔ¼2.93ÒÚÃÀÔª£¬Ëæºó×ʽðͨ¹ýTornado Cash½øÐÐ×ªÒÆÒÔ¸²¸Ç×ÙÓ°¡£Æ¾¾ÝLayerZero·ÖÏíµÄϸ½Ú£¬Õâ´Î¹¥»÷µÄÖ¸±êÊÇÓÃÓÚÑéÖ¤rsETH¿çÁ´ÐÂÎŵÄÑéÖ¤²ã£¨DVN£©¡£¹¥»÷ÕßÈëÇÖÁËÑéÖ¤Æ÷ʹÓõÄһЩRPC½Úµã£¬ÏòÆäÌṩαÔìµÄÇø¿éÁ´Êý¾Ý£¬Í¬Ê±¶Ô½¡È«µÄRPC½ÚµãÌáÒéDDoS¹¥»÷£¬ÆÈʹϵͳÒÀÀµÓÚ±»¡°´«È¾¡±µÄ½Úµã¡£ÕâʹµÃαÔìµÄ¿çÁ´ÐÂÎű»½ÓÊÜΪÓÐЧÐÂÎÅ£¬ÏµÍ³È·ÈÏÁËÏÖʵÉÏ´ÓδÔÚÁ´ÉϲúÉúµÄÂòÂô£¬²¢ÔÊÐíÔÚδ¾ÊÚȨµÄÇé¿öÏÂ×ªÒÆrsETH¡£
https://www.bleepingcomputer.com/news/security/kelpdao-suffers-290-million-heist-tied-to-lazarus-hackers/
2. ·¨¹úANTSƽ̨ÔâÍøÂç¹¥»÷£¬½ü1900ÍòÌõÓ×ÎÒÊý¾Ýй¶
4ÔÂ20ÈÕ£¬·¨¹úµÄANTSƽ̨½üÆÚÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬¸ÃÆ½Ì¨ÕÆ¹Ü´¦Öû¤ÕÕ¡¢Éí·ÝÖ¤¡¢¾ÓÁôÐí¿ÉºÍ¼ÝÊ»ÅÆÕÕµÄÉêÇë¡£µ±¾ÖÓÚ4ÔÂ15ÈÕ·¢ÏÖÁËÕâÆð°²È«ÊÂÎñ£¬²¢ÖÒ¸æ³Æ£¬Õâ´Î·ì϶¿ÉÄܵ¼ÖÂÓ×ÎÒºÍרҵÈËÊ¿µÄÓ×ÎÒÊý¾Ýй¶¡£ÄÚÕþ²¿ÒÑÈ·ÈÏÕâ´Î°²È«·ì϶£¬²¢ÔÚµ÷²é·ì϶ÁìÓò¼°¶ÔÊÜÓ°ÏìÓû§µÄÓ°Ïì¡£ANTS°ä²¼µÄ²¼¸æÏÔʾ£¬Õâ´Î°²È«·ì϶¿ÉÄÜй¶ÁËÓû§µÄµÇ¼ID¡¢ÐÕÃû¡¢ÓÊÏä¡¢µ®ÉúÈÕÆÚºÍÕË»§IDµÈ¾ßÌåÐÅÏ¢¡£ÔÚijЩÇé¿öÏ£¬Ð¹Â¶µÄÐÅÏ¢»¹Ô̺¬µØÖ·¡¢µ®ÉúµØ»òµç»°ºÅÂë¡£Óйز¿ÃÅÔÚ֪ͨÊÜÓ°ÏìµÄÓû§¡£Æ¾¾ÝÊý¾Ýй¶֪ͨ£¬Ð¹Â¶µÄÊý¾Ý²»Ô̺¬ÒÑÉÏ´«µÄÎļþ£¬Ò²ÎÞ·¨Ö±½Ó½Ó¼ûÓû§ÕË»§¡£µ±¾ÖÒѽ«´ËÊ»㱨¸ø·¨¹úÊý¾Ý±£»¤¾Ö£¨CNIL£©£¬Í¨ÖªÁ˼ì²ì¹Ù£¬²¢Ïò¹ú¶ÈÍøÂ簲ȫ»ú¹¹·¢³ö¾¯±¨¡£Óë´Ëͬʱ£¬Ò»ÃûÍþвÐÐΪÕßÐû³ÆÔÚÏúÊÛ´ÓANTSÇÔÈ¡µÄ´óÐÍÊý¾Ý¼¯£¬ÆäÖÐÔ̺¬Ô¼1800ÍòÖÁ1900Íò±Ê¼Í¼£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢µ®ÉúÏêÇé¡¢µØÖ·ºÍÕË»§ÔªÊý¾Ý¡£
https://securityaffairs.com/191069/data-breach/frances-ants-id-system-website-hit-by-cyberattack-possible-data-breach.html
3. GentlemenÀÕË÷Èí¼þ½èSystemBCϰȾ³¬1570¼ÒÆóÒµÖ÷»ú
4ÔÂ20ÈÕ£¬ÔÚ¶Ôһ·ÓÉÍÅ»ï³ÉÔ±Ö´ÐеÄGentlemenÀÕË÷Èí¼þ¹¥»÷½øÐе÷²éºó£¬Check Point×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÓɳ¬¹ý1570̨Ö÷»ú×é³ÉµÄSystemBC´úÀí¶ñÒâÈí¼þ½©Ê¬ÍøÂ磬ÕâЩÖ÷»ú¾ÝÐÅÖØÒªÎªÆóÒµÊܺ¦Õß¡£GentlemenÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©ÔËӪԼĪÔÚ2025ÄêÖÐÆÚ³öÏÖ£¬ÌṩÁ˿ɼÓÃÜWindows¡¢Linux¡¢NASºÍBSDϵͳµÄGo˵»°¼ÓÃÜÆ÷£¬ÒÔ¼°Õë¶ÔESXiÐé¹¹»úÖÎÀí·¨Ê½µÄC˵»°¼ÓÃÜÆ÷¡£È¥Äê12Ô£¬¸ÃÀÕË÷Èí¼þ¹¥»÷ÁËÂÞÂíÄáÑÇ×î´óµÄÄÜÔ´¹©¸øÉÌÖ®Ò»°Â¶ûÌØÄáÑÇÄÜÔ´×ÛºÏÌå¡£Ö»¹Ü¸ÃRaaSÐж¯¹«¿ªÐû³ÆÒÑÔì³ÉÔ¼320ÃûÊܺ¦Õߣ¬ÆäÖдó²¿ÃŹ¥»÷²úÉúÔÚ½ñÄ꣬µ«×êÑÐÈËÔ±·¢ÏÔì乨Áª×éÖ¯ÔÚѸËÙÀ©´ó¹¥»÷¹¤¾ß°üºÍ»ù´¡ÉèÊ©¡£ÔÚÒ»´ÎÊÂÎñÏìÓ¦¹ý³ÌÖУ¬×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þÐж¯µÄÒ»¸ö¹ØÁª·½ÊÔͼ²¿ÊðSystemBC´úÀí¶ñÒâÈí¼þÒÔ½øÐÐÒñ±ÎµÄÓÐÐ§ÔØºÉͶ·Å¡£SystemBCÖÁÉÙ´Ó2019Äê¾ÍÒÑ´æÔÚ£¬ÖØÒªÓÃÓÚSOCKS5Ëí·´«Ê䣬ÒòÆä¿ÉÄÜ´«µÝ¶ñÒâÔØºÉ¶ø±»ÀÕË÷Èí¼þÍÅ»ï¿í·ºÑ¡È¡¡£¾ÝCheck Point¹Û²ì£¬ÓëGentlemen²¿ÊðSystemBCÓйصĴóÎÞÊýÊܺ¦ÕßλÓÚÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢°Ä´óÀûÑǺÍÂÞÂíÄáÑÇ¡£
https://www.bleepingcomputer.com/news/security/the-gentlemen-ransomware-now-uses-systembc-for-bot-powered-attacks/
4. ¾«¹¤ÃÀ¹ú¹ÙÍøÔâ´Û¸Ä£¬¹¥»÷ÕßË÷ÒªÊê½ð
4ÔÂ20ÈÕ£¬ÉÏÖÜÄ©£¬¾«¹¤ÃÀ¹ú¹ÙÍøÔâµ½´Û¸Ä£¬Æä¡°ÐÂÎŰ䲼Ìü¡±Ò³Ãæ±»´úÌæÎª¹¥»÷Õß°ä²¼µÄÐÂÎÅ£¬Ðû³ÆÒÑÇÔÈ¡¸Ã¹«Ë¾µÄShopify¿Í»§Êý¾Ý¿â£¬²¢Íþв³Æ³ý·ÇÖ§¸¶Êê½ð£¬²»È»½«¹«¿ªÐ¹Â¶ÕâЩÊý¾Ý¡£±»´Û¸ÄµÄÍøÒ³ÒÔ¡°±»ºÚ¡±Îª±êÌ⣬½«Õý³£ÄÚÈÝ´úÌæ³ÉÁËÒ»ÔòÀÕË÷¼°Êý¾Ýй¶֪ͨ¡£¹¥»÷ÕßÐû³ÆÒѳɹ¦ÈëÇÖ¾«¹¤ÃÀ¹úµÄShopifyÉ̵갲Õûϵͳ£¬²¢ÏÂÔØÁËÕû¸ö¿Í»§Êý¾Ý¿â£¬ÆäÖÐÔ̺¬µÄÐÅÏ¢Ô̺¬£º¿Í»§ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¶©µ¥º¹Çà¼Í¼¡¢ÂòÂôÏêÇé¡¢ÊÕ»õµØÖ·ÓëÆ«ºÃ¡¢ÕË»§´´½¨ÈÕÆÚÒÔ¼°¿Í»§±¸×¢µÈ¡£¹¥»÷ÕßÖÒ¸æ³Æ£¬³ý·Ç¾«¹¤ÃÀ¹ú¹«Ë¾²Î¼Ó½»É棬²»È»±»µÁÊý¾Ý½«±»¹«¿ª¡£×÷ΪҪÇóµÄÒ»²¿ÃÅ£¬ËûÃÇÅúʾ¸Ã¹«Ë¾ÔÚShopifyÖÎÀíºó¶ÜÖвéÕÒÒ»¸öÌØ¶¨¿Í»§ÕË»§£¨IDΪ8069776801871£©£¬²¢Ðû³Æ¸ÃÕË»§×ʲÂÖÐÔö³¤ÁËÒ»¸öÁªÏµÓÊÏ䵨ַ£¬Ó¦Ê¹ÓøÃÓÊÏäÌáÒ齻ɿ¡£´Ë±í£¬¹¥»÷Õß»¹ÒªÇ󾫹¤ÃÀ¹ú±ØÐëÔÚ72Ó×ʱÄÚÓëËûÃÇÁªÏµ£¬²»È»ËùνµÄÊý¾Ý¿â½«±»°ä²¼¡£
https://www.bleepingcomputer.com/news/security/seiko-usa-website-defaced-as-hacker-claims-customer-data-theft/
5. MastodonÆì½¢·þÎñÆ÷ÔâDDoS¹¥»÷
4ÔÂ20ÈÕ£¬Éç½»ÍøÂçÈí¼þÔì×÷ÉÌMastodonÖÜһ֤ʵ£¬ÆäÆì½¢·þÎñÆ÷mastodon.socialÔâ·êÁËÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬µ¼Ö¸ÃÊ·ýÔÚ²¿ÃÅʱ¶ÎÎÞ·¨Õý³£½Ó¼û¡£ÍøÕ¾´ó²¿ÃÅÄÚÈÝҪôÏÔʾÃýÎóÐÅÏ¢£¬ÒªÃ´³öÏÖÈ«ÆÁ¹ÊÕÏÖҸ档MastodonÓÚÃÀ¹ú¶«²¿¹¦·òÔçÉÏ7µã×óÓҰ䲼״̬¸üУ¬°µÊ¾ÔÚµ÷²éÕâ´Î¹¥»÷¡£ÉÏÎç9µã05·Ö£¬¸Ã¹«Ë¾³ÆÒѲÉȡӦ¶Ô´ëÊ©£¬ÍøÕ¾ÒѸ´Ô½Ó¼û£¬µ«ÓÉÓÚ¹¥»÷ÈÔÔÚ½øÐÐÖУ¬¿ÉÄÜÈÔ»á³öÏÖһЩ²»²»±äÇé¿ö¡£Mastodon°µÊ¾£¬Ä¿Ç°ÒÑÊÕµ½Êý°ÙÍò´Î¶ñÒâÒªÇó£¬ÇкÏDDoS¹¥»÷µÄģʽ¡£¹¥»÷Ŀǰ½öÕë¶Ômastodon.socialÕâÒ»¸öÊ·ý£¬ÆäÍŶÓÒÑÔÚ¹¥»÷ÆðÍ·ºóµÄ¼¸Ó×ʱÄÚ²¿ÊðÓ¦¶Ô´ëÊ©²¢¸´ÔÁ˽Ӽû¡£MastodonͨѶÖ÷¹ÜAndy PiperÖ¸³ö£¬ÔÚÕâÖÖÇé¿öÏ£¬Áª¹úÓîÖæµÄÈ¥ÖÐÐÄ»¯¸öÐÔµÄÈ·ÊÇÒ»ÏîÓÅÊÆ¡£ÔÚÆäËûMastodon·þÎñÆ÷»òÈÎºÎÆäËûÁª¹úÓîÖæ·þÎñÆ÷ÉÏÕ¼ÓÐÕË»§µÄÓû§ÆëÈ«²»ÊÜÓ°Ï죬ÔÚ´óÎÞÊýÇé¿öÏÂÉõÖÁµ××Ӹд¥²»µ½·þÎñÖжϣ¬ËûÃÇ¿ÉÄÜÏñƽ·²Ò»Ñù½Ó¼ûÍøÂç¡¢ÔĶÁºÍ·ÖÏíÌû×Ó¡£
https://techcrunch.com/2026/04/20/mastodon-says-its-flagship-server-was-hit-by-a-ddos-attack/
6. ¹¥»÷ÕßÀÄÓÃTeams¼ÙÒâITÈËÔ±ÓÕÆÔ¶³Ì½Ó¼û
4ÔÂ20ÈÕ£¬Î¢Èí½üÈÕ·¢³öÖҸ棬³ÆÍþвÐÐΪÕßÔÚÔ½À´Ô½¶àµØÀÄÓÃMicrosoft TeamsµÄ±í²¿ºÏ×÷Ö°ÄÜ£¬²¢ÒÀÀµºÏ·¨¹¤¾ß½Ó¼ûÆóÒµÍøÂç¡¢½øÐкáÏòÒÆ¶¯ºÍÊý¾ÝÇÔÈ¡¡£ÔÚÕâЩ¹¥»÷ÖУ¬ºÚ¿Í¼ÙÒâIT»ò·þÎñ̨ÈËÔ±£¬Í¨¹ý¿ç×⻧̸ÌìÁªÏµÔ±¹¤£¬ÓÕÆËûÃÇÌṩԶ³Ì½Ó¼ûȨÏÞ¡£Î¢Èí¹Û²ìµ½¶àÆðÈëÇÖÊÂÎñ¾ùѡȡÀàËÆµÄ¹¥»÷Á´£¬Ê¹ÓÃóÒ×Ô¶³ÌÖÎÀíÈí¼þ£¨ÈçQuick Assist£©ºÍRcloneʵÓ÷¨Ê½£¬½«Îļþ´«Êäµ½±í²¿ÔÆ´æ´¢·þÎñ¡£ÓÉÓÚ´óÁ¿Ê¹ÓúϷ¨ÀûÓ÷¨Ê½ºÍÔÉúÖÎÀíºÍ̸£¬ºóÐø¶ñÒâ»î¶¯ºÜÄÑÓëÕý³£²Ù×÷·Ö±æ¸ôÀ´¡£Î¢Èí°µÊ¾£¬¹¥»÷Õß´Ó³õʼ°²ÉíµãÆô³Ì£¬ÀûÓÃÊÜÐÅÀµµÄ¹¤¾ßºÍ±¾µØÖÎÀíºÍ̸ÔÚÆóÒµÄÚ²¿ºáÏòÒÆ¶¯£¬²¢³ï±¸Ãô¸ÐÊý¾ÝÒÔ½øÐÐÇÔÈ¡£¬Õû¸ö¹ý³ÌÍùÍùÈÚÈëµ½ÈÕ³£ITÖ§³Ö»î¶¯ÖС£ÔÚ×î½üµÄÒ»·Ý»ã±¨ÖУ¬Î¢Èí¾ßÌåÃèÊöÁËÒ»¸ö¾Å½×¶ÎµÄ¹¥»÷Á´¡£¸Ã¹¥»÷Á´Ê¼ÓÚÍþвÐÐΪÕßͨ¹ý±í²¿Teams̸ÌìÁªÏµÖ¸±ê£¬¼ÙÒ⹫˾ITÈËÔ±£¬Ðû³Æ±ØÒª½â¾öÕË»§ÎÊÌâ»òÖ´Ðа²È«¸üУ¬Ö÷ÕÅÊÇÓÕʹָ±êÓû§Æô¶¯Ô¶³ÌÖ§³Ö»á»°£¬Í¨³£ÊÇͨ¹ýQuick Assist£¬´Ó¶øÈù¥»÷ÕßÖ±½Ó½ÚÔìÔ±¹¤µÄÍÆËã»ú¡£
https://www.bleepingcomputer.com/news/security/microsoft-teams-increasingly-abused-in-helpdesk-impersonation-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ