¸»Ê¿¿µ±±ÃÀÔâNitrogenÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2026-05-13

1.¸»Ê¿¿µ±±ÃÀÔâNitrogenÀÕË÷Èí¼þ¹¥»÷


5ÔÂ12ÈÕ £¬¸»Ê¿¿µ½üÈÕ֤ʵÆä±±ÃÀÒµÎñÔâ·êÍøÂç¹¥»÷¡£´Ëǰ £¬ÃûΪNitrogenµÄÀÕË÷Èí¼þÍÅ»ïÒѽ«¸Ãµç×Ó²úÆ·Ôì×÷ÉÌÁÐÈëÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¸»Ê¿¿µ½²»°È˰µÊ¾ £¬¹«Ë¾±±ÃÀ²¿Ãʤ³§Ôâ·ê¹¥»÷ºó £¬ÍøÂ簲ȫÍŶÓÁ¢¼´Æô¶¯Ó¦¼±»úÔì £¬²ÉÈ¡¶àÏîÔËÓª´ëʩȷ±£³ö²úºÍ½»¸¶Â½ÐøÐÔ £¬ÊÜÓ°Ï칤³§ÕýÖ𲽸´Ô­Õý³£³ö²ú¡£È»¶ø £¬¸üÁîÈËÓÇÓôµÄÊÇ £¬NitrogenÍÅ»ïÐû³ÆÒÑÈëÇÖÕâ¼Ǫ̀ÍåÆóÒµ £¬ÇÔÈ¡¶à´ï8TBµÄÊý¾Ý £¬º­¸Ç³¬¹ý1100Íò¸öÎļþ¡£¾Ý·¸·¨·Ö×Óй© £¬Ð¹Â¶ÄÚÈÝÔ̺¬»úÃÜÖ¸Áî¡¢ÄÚ²¿ÏîÄ¿ÎĵµÒÔ¼°ÓëÓ¢ÌØ¶û¡¢Æ»¹û¡¢¹È¸è¡¢´÷¶û¡¢Ó¢Î°´ïµÈ³ÛÃûÆóÒµÏîÄ¿Óйصļ¼Êõͼֽ¡£²»Íâ £¬¸»Ê¿¿µ»Ø¾øÖ¤ÊµÕâЩ¿Í»§ÐÅÏ¢ÊÇ·ñÈ·ÇÐʵÕâ´ÎÊý×ÖÈëÇÖÖб»ÇÔÈ¡¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Õâ²¢·Ç¸»Ê¿¿µ³õ´ÎÔâ·êÀÕË÷Èí¼þ¹¥»÷¡£2024Äê £¬LockBitÐû³ÆÏ°È¾Á˸»Ê¿¿µ¿Æ¼¼¼¯ÍÅÆìϰ뵼ÌåÉ豸Ôì×÷ÉÌFoxsemicon Integrated Technology£»2022Äê £¬Í³Ò»·¸×ïÍÅ»ï»¹Ôø¹¥»÷¸»Ê¿¿µÎ»ÓÚÄ«Î÷¸çµÄÒ»¼Ò×Ó¹«Ë¾¡£


https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144


2. Ó¢¹úË®Îñ¹«Ë¾66ÍòÈËÐÅϢй¶±»·£96ÍòÓ¢°÷


5ÔÂ12ÈÕ £¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©½üÈÕ¶ÔÄÏ˹Ëþ¸£µÂ¿¤Ë®ÎñÓÐÏÞ¹«Ë¾¼°Æäĸ¹«Ë¾ÄÏ˹Ëþ¸£µÂ¿¤ÓÐÏÞ¹«Ë¾´¦ÒÔ96.39ÍòÓ¢°÷£¨Ô¼130ÍòÃÀÔª£©µÄ·£¿î £¬Ô­ÒòÊǸù«Ë¾ÒòÍøÂç¹¥»÷µ¼Ö³¬¹ý66ÍòÃû¿Í»§ºÍÔ±¹¤µÄÓ×ÎÒÊý¾Ýй¶¡£Õâ¼ÒÿÌìÏò160ÍòÏû·ÑÕß¹©¸ø3.3ÒÚÉýÒûÓÃË®µÄ¹«Ë¾ £¬ÓÚ2022ÄêÅû¶³ÉÎªÍøÂç¹¥»÷Ö¸±ê²¢µ¼ÖÂITÔËÓªÖжÏ¡£Æäʱ £¬¹«Ë¾Ôø±ç²µCl0pÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹ÜµÄ˵·¨ £¬µ«¹ýºó֤ʵй¶µÄÊý¾ÝÑù±¾Êôʵ¡£¹¥»÷¿É×·ÒäÖÁ2020Äê9Ô £¬µ«ÖØÒª²úÉúÔÚ2022Äê5ÔÂÖÁ7ÔÂÖ®¼ä £¬Â¶³öÁ˸ù«Ë¾ÔÚÊý¾Ý°²È«·½Ãæ´æÔڵijÁ´óȱµã £¬Ê¹¿Í»§ºÍÔ±¹¤ÔÚ½üÁ½Ä깦·òÀï´¦ÓÚÒ×Êܹ¥»÷״̬¡£µ÷²éÏÔʾ £¬Õâ´ÎÊÂÎñÊÇͨ¹ýÍøÂç´¹µö¹¥»÷Ôì³ÉµÄ £¬¹¥»÷ÕßÀûÓô¹µö¼¿Á©ÔÚ¹«Ë¾ÏµÍ³ÖÐ×°ÖöñÒâÈí¼þ £¬¸Ã¶ñÒâÈí¼þ³¤´ï20¸öÔÂδ±»·¢ÏÖ¡£2022Äê5ÔÂÖÁ7ÔÂÆÚ¼ä £¬¹¥»÷Õ߳ɹ¦ÌáÉýÍøÂçȨÏÞ²¢»ñµÃÓòÖÎÀíÔ±½Ó¼ûȨ £¬Ö±µ½Îôʱ7ÔÂÒòIT»úÄÜÎÊÌâÒý·¢µ÷²éºó²Å±»·¢ÏÖ¡£Ð¹Â¶µÄÊý¾Ý¼«ÎªÃô¸Ð £¬Ô̺¬È«Ãû¡¢ÏÖʵµØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢¿Í»§ÕË»§Æ¾Ö¤¡¢ÒøÐÐÕË»§¾ßÌåÐÅÏ¢ £¬ÒÔ¼°Ô±¹¤ÈËÁ¦×ÊÔ´Êý¾ÝÈç¹úÃñ±£ÏÕºÅÂëµÈ¡£


https://www.bleepingcomputer.com/news/security/uk-fines-water-supplier-13m-for-exposing-data-of-664k-customers/


3. BWH¾Æµê¼¯ÍÅÔâ·ê³¤´ï°ëÄêÊý¾Ýй¶


5ÔÂ12ÈÕ £¬BWH¾Æµê¼¯ÍŽüÈÕÅû¶ÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ £¬·¸·¨·Ö×ÓÔÚ³¬¹ýÁù¸öԵŦ·òÀï·¸·¨»ñÈ¡Á˾Ƶê¿ÍÈ˵ÄÔ¤Ô¼Êý¾Ý¡£×÷ΪȫÇò×î´óµÄ¾ÆµêÍøÂçÖ®Ò» £¬BWHÔÚ100¶à¸ö¹ú¶ÈÔËÓª×Å4000¶à¼Ò¾Æµê £¬ÆìÏÂÕ¼ÓÐBest Western Hotels & Resorts¡¢WorldHotelsºÍSure HotelsµÈÆ·ÅÆ £¬º­¸Ç´Ó¾­¼ÃÐ͵½ÉÝ»ªÐ͵ĸ÷Àà¾Æµê¡£Æ¾¾Ý¸Ã¼¯ÍÅ·¢Ë͸øÊÜÓ°Ïì¿Í»§µÄÊý¾Ýй¶֪ͨ £¬2026Äê4ÔÂ22ÈÕ £¬¹«Ë¾·¢ÏÖ´æ´¢²¿ÃÅ¿ÍÈËÔ¤Ô¼Êý¾ÝµÄÍøÂçÀûÓ÷¨Ê½´æÔÚδ¾­ÊÚȨµÄ»î¶¯¡£½øÒ»´ëÊ©²éÏÔʾ £¬ÔÚ2025Äê10ÔÂ14ÈÕÖÁ2026Äê4ÔÂ22ÈÕÆÚ¼ä £¬Ô̺¬¿ÍÈËÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¼ÒͥסַµÈÁªÏµÐÅÏ¢ £¬ÒÔ¼°Ô¤Ô¼±àºÅ¡¢ÈëסÈÕÆÚºÍÈκÎÌØÊâÒªÇóµÈÔ¤Ô¼ÏêÇé £¬±»Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼û¡£ÖµÍ×ÌùÐĵÄÊÇ £¬¸Ã¹«Ë¾Ã÷È·°µÊ¾ £¬ÊÜÓ°ÏìµÄϵͳÖв¢Î´´æ´¢Ö§¸¶ÐÅÏ¢ºÍÆäËû²ÆÕþÊý¾Ý £¬Òò¶ø¿ÍÈ˵ÄÖ§¸¶ÐÅϢûÓÐй¶¡£ÔÚ·¢ÏÖÈëÇÖºó £¬BWHѸËÙ½«ÊÜÓ°ÏìµÄÀûÓ÷¨Ê½ÏÂÏß £¬³·ÏúÁËÓйؽӼûȨÏÞ £¬²¢ÀñƸ±í²¿ÍøÂ簲ȫר¼ÒÖ§³Öµ÷²éºÍ¼Óǿϵͳ±£»¤¡£¾Æµê¼¯ÍÅ»¹Ïò¿ÍÈË·¢³öÖÒ¸æ £¬ÌáÐѾ¯ÌèÀûÓñ»µÁÔ¤Ô¼Êý¾ÝÌáÒéµÄÍøÂç´¹µöÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òÐéαԤԼÐÅÏ¢Ú¿Æ­¡£


https://securityaffairs.com/192038/data-breach/hackers-accessed-bwh-hotels-reservation-system-for-months.html


4. ˹¿Â´ïÆû³µÍøÉÏÉ̵êÔâ¹¥»÷ £¬¿Í»§Ó×ÎÒÐÅϢй¶


5ÔÂ12ÈÕ £¬¹«¹²Æû³µ¼¯ÍÅÈ«×Ê×Ó¹«Ë¾Ë¹¿Â´ïÆû³µ½üÈÕÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ £¬¹«Ë¾·¢ÏÖδ¾­ÊÚȨµÄÈËÔ±ÀûÓÃÔÚÏßÉ̵êʹÓõij߶ÈÈí¼þÖеķì϶ £¬ÁÙʱ·¸·¨½Ó¼ûÁËÉ̵êϵͳ¡£·¢ÏÖÈëÇÖÊÂÎñºó £¬¹«Ë¾ÒÑÏòÓйز¿ÃŻ㱨 £¬½¨¸´Á˱»ÀûÓõݲȫ·ì϶ £¬²¢½«´ËÊÂÎñÒÆ½»¸ø×¨ÒµµÄITȡ֤ÍŶӽøÐм¼Êõ·ÖÎö £¬Í¬Ê±»ã±¨¸øÓйصÄÊý¾Ý±£»¤¼à¹Ü»ú¹¹¡£±»ÇÔÈ¡µÄ¿Í»§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëµÈÁªÏµÐÅÏ¢ £¬ÒÔ¼°¶©µ¥ÐÅÏ¢ºÍµÇ¼ʹ´¦¡ª¡ªÔ̺¬µç×ÓÓʼþµØÖ·ºÍÃÜÂëµÄ¼ÓÃܹþÏ£Öµ¡£Ë¹¿Â´ïÇ¿µ÷ £¬¹¥»÷ÕßÎÞ·¨½Ó¼ûÊÜÓ°Ïì¿Í»§µÄ²ÆÕþÐÅÏ¢ £¬ÓÉÓÚÆëÈ«µÄÐÅÓþ¿¨ÐÅÏ¢²¢Î´´æ´¢ÔÚÉ̵êϵͳÖÐ £¬¶øÊÇÓÉÏàÓ¦µÄÖ§¸¶·þÎñÌṩÉÌȫȨ´¦Ö᣹ÌȻ˹¿Â´ï°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢±»½Ó¼ûµÄÊý¾ÝÒѱ»ÀÄÓà £¬µ«¸Ã¹«Ë¾ÖÒ¸æÊÜÓ°ÏìµÄÓ×ÎÒ¾¯ÌèÕë¶ÔËûÃǵÄÍøÂç´¹µö¹¥»÷ £¬²¢³ö¸ñÖ¸³öÈôÊǿͻ§³Á¸´Ê¹ÓÃÒ»ÑùµÄµÇ¼ʹ´¦ £¬ÍþвÐÐΪÕß¿ÉÄ᳢ܻÊԵǼËûÃÇµÄÆäËûÔÚÏßÕÊ»§¡£Ä¿Ç°Ë¹¿Â´ïÉÐδÅû¶ÊÜÓ°ÏìµÄ¿Í»§×ÜÊýÒÔ¼°ÊÇ·ñÓë¹¥»÷ÕßÓйýÊê½ðÖ§¸¶ÁªÏµ¡£


https://www.bleepingcomputer.com/news/security/skoda-warns-of-customer-data-breach-after-online-shop-hack/


5. ±öÖÝÔìÒ©¾ÞÍ·West PharmaceuticalÔâÀÕË÷¹¥»÷


5ÔÂ12ÈÕ £¬±öϦ·¨ÄáÑÇÖÝÔìÒ©¾ÞÍ·West Pharmaceutical Services½üÈÕÅû¶ £¬¹«Ë¾ÓÚ5ÔÂ4ÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬Ä¿Ç°ÔÚ´¹Î£¸´Ô­ÊÜÓ°ÏìµÄϵͳ¡£¸Ã¹«Ë¾ÔÚÒ»·ÝÊÂÎñ֪ͨÖаµÊ¾ £¬¹¥»÷²úÉúºóÁ¢¼´×Ô¶¯¹Ø¹Ø²¢¸ôÀëÁËÊÜÓ°ÏìµÄ±¾µØ»ù´¡ÉèÊ©¡£Æ¾¾ÝÖÜÒ»Ìá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»áµÄÎļþ £¬ÕâЩ¶ôÔì´ëÊ©Òѵ¼Ö¹«Ë¾È«ÇòÁìÓòÄÚµÄÒµÎñÔËÓªÊܵ½×ÌÈÅ¡£ÆäËûÊÂÎñÓ¦¶Ô´ëÊ©Ô̺¬ÏÞ¶È¶ÔÆóҵϵͳµÄ½Ó¼ûºÍÆô¶¯Î£»úÖÎÀíºÍ̸¡£ÎªÓ¦¶ÔÕâ´Î¹¥»÷ £¬Õâ¼ÒÔìÒ©¾ÞÍ·ÀñƸÁËPalo Alto NetworksµÄUnit 42Íþвµý±¨ºÍÊÂÎñÏìÓ¦ÍŶÓЭÖú½øÐжôÔ졢ϵͳ¸´Ô­ºÍÊÂÎñµ÷²é £¬Í¬Ê±ÒÑ֪ͨ·¨Âɲ¿ÃÅ¡£¸Ã¹«Ë¾°µÊ¾ £¬¹ÌÈ»Ö÷ÌâÆóҵϵͳÒѸ´Ô­ £¬²¿ÃÅÕ¾µãµÄ·¢»õ¡¢ÊÕ»õºÍÔì×÷µÈ¹Ø¼üÁ÷³ÌÒ²ÒѳÁÐÂÆô¶¯ £¬ÆäÓàÕ¾µãµÄ¸´Ô­¹¤×÷ÈÔÔÚ½øÐÐÖÐ £¬µ«È«Ã渴ԭµÄ¹¦·ò±íÉÐδ×îÖÕÈ·¶¨¡£West PharmaceuticalÏòSECÅû¶ £¬¹¥»÷ÕßÔÚ²¿ÊðÎļþ¼ÓÃÜÀÕË÷Èí¼þ֮ǰ´ÓÆäϵͳÖÐÇÔÈ¡ÁËÊý¾Ý £¬¹«Ë¾ÔÚµ÷²éÊÜÓ°ÏìÊý¾ÝµÄÁìÓò¡£¹ÌÈ»¸Ã¹«Ë¾Ã»ÓÐÖ¸Ã÷ÊÇÄĸöÀÕË÷Èí¼þ×éÖ¯·¢ÆðÁËÈëÇÖ £¬µ«°µÊ¾¡°ÒѲÉÈ¡´ëÊ© £¬Ö¼ÔÚ½µµÍй¶Êý¾Ý´«²¼µÄ·çÏÕ¡± £¬Õⰵʾ¿ÉÄÜÒѾ­Óë¹¥»÷Õß½øÐÐÁ˽»Éæ¡£


https://www.securityweek.com/west-pharmaceutical-services-hit-by-disruptive-ransomware-attack/


6. ´ó¹æÄ£¹©¸øÁ´¹¥»÷ÈëÇÖnpmºÍPyPIÊý°Ù¸öÈí¼þ°ü


5ÔÂ12ÈÕ £¬Ò»³¡ÃûΪShai-HuludµÄÐÂÐ͹©¸øÁ´¹¥»÷»î¶¯Òѵ¼ÖÂnpmºÍPyPIÉϵÄÊý°Ù¸öÈí¼þ°üÔâµ½ÈëÇÖ £¬¹¥»÷ÕßÖ²ÈëÇÔȡƾ֤µÄ¶ñÒâÈí¼þ £¬Ö¸±êÖ±Ö¸¿ª·¢Õß¡£Õâ´Î¹¥»÷±»ÒÔΪÊÇÓÉÍþв×éÖ¯TeamPCPËùΪ £¬¹¥»÷Õß½Ù³ÖÁËÓÐЧµÄOpenID ConnectÁîÅÆ £¬°ä²¼ÁË´øÓпÉÑéÖ¤ÆðÔ´Ö¤Ã÷µÄ¶ñÒâÈí¼þ°ü°æ±¾¡£Shai-Hulud¹¥»÷»î¶¯ÓÚÈ¥Äê9Ô³öÏÖ²¢¾­ÀúÁËÂŴεü´ú £¬ÆäÖÐһЩµü´úÒÑй¶ÁË×Ô¶¯ÌìÉúµÄGitHub´úÂë¿âÖÐÊýÊ®Íò¸ö¿ª·¢Õß»úÃÜÐÅÏ¢¡£×îÐÂÒ»²¨¹¥»÷²úÉúÔÚ×òÌì £¬¹¥»÷ÕßÔÚnpmµÄTanStack¶¨Ãû¿Õ¼äÖа䲼Á˶à¸ö¶ñÒâÈí¼þ°ü £¬¶øºóÀûÓÃÇÔÈ¡µÄCI/CDƾ֤´«²¼µ½ÆäËûÏîÄ¿¡£Æ¾¾Ý°²È«³§É̵Ļ㱨 £¬npmÉÏÓг¬¹ý160¸öÊÜϰȾµÄÈí¼þ°ü £¬PyPIÉÏÒ²·¢ÏÖÁË´óÁ¿¶ñÒâÈí¼þ°ü¡£¶ñÒâÈí¼þµÄÖ¸±êÔ̺¬ÇÔÈ¡GitHub Actions OIDCÁîÅÆ¡¢GitÍ´´¦¡¢npm°ä²¼ÁîÅÆ¡¢AWSƾ֤¡¢Kubernetes·þÎñÕÊ»§ÁîÅÆ¡¢HashiCorp VaultÁîÅÆ¡¢SSHÃÜÔ¿¡¢Claude CodeÅäÖü°.envÎļþµÈ¡£¸ÃÓÐÐ§ÔØºÉ»á¶ÁÈ¡GitHub Actions¹ý³ÌÄÚ´æ £¬´ÓÓëÔÆÌṩÉÌ¡¢¼ÓÃÜÇ®±Ò´ú±ÒºÍÐÂÎÅ´«µÝÀûÓ÷¨Ê½¹ØÁªµÄ100¶à¸öÎļþõè¾¶ÖÐÍøÂçÍ´´¦¡£


https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/