¹ú¼ÊÐ̾¯×éÖ¯¡°ÀÄ·×ÈÐж¯¡±ºáɨÖж«·Ç
°ä²¼¹¦·ò 2026-05-191. ¹ú¼ÊÐ̾¯×éÖ¯¡°ÀÄ·×ÈÐж¯¡±ºáɨÖж«·Ç
5ÔÂ18ÈÕ£¬¹ú¼ÊÐ̾¯×éÖ¯½üÈÕÔÚÕë¶ÔÖж«ºÍ±±·ÇµØÓò·¢Õ¹µÄ¡°ÀÄ·×ÈÐж¯¡±ÖлñµÃ³Á´ó³É¾Í£¬¹²¿ÛÁô200ÓàÃûÍøÂç·¸×ï»î¶¯ÈËÔ±£¬²¢ÔÚ13¸ö¹ú¶ÈÔ̺¬°¢¶û¼°ÀûÑÇ¡¢°ÍÁÖ¡¢°£¼°¡¢ÒÁÀ¿Ë¡¢Ô¼µ©¡¢Àè°ÍÄÛ¡¢Àû±ÈÑÇ¡¢Ä¦Âå¸ç¡¢°¢Âü¡¢°ÍÀÕ˹̹¡¢¿¨Ëþ¶û¡¢Í»Äá˹ºÍ°¢ÁªÇõÈ·ÈÏÁËÁí±í382ÃûÏÓÒÉÈË¡£³ý´ó¹æÄ£×¥²¶±í£¬·¨Âɵ±¾Ö»¹²é»ñÁË53̨ÓÃÓÚÍøÂç´¹µö¡¢¶ñÒâÈí¼þºÍÍøÂçڿƵķþÎñÆ÷£¬ÕâЩÉ豸ӰÏìÁËÖÁÉÙ3867ÃûÒÑÈ·ÈϵÄÊܺ¦Õߣ¬¸ÃÊý×ÖÊÇÆ¾¾Ý´ÓÉæ°¸É豸Öи´ÔµÄ½ü8000¸öµý±¨°üÈ·¶¨µÄ¡£¹ú¼ÊÐ̾¯×éÖ¯²¼¸æÖ¸³ö£¬Õâ´ÎÐж¯³Áµã½â³ýÍøÂç´¹µöºÍ¶ñÒâÈí¼þÍþв£¬²¢½ø¹¥¸ø¸ÃµØÓòÔì³ÉÑϳÁ¾¼ÃËðʧµÄÍøÂçÚ¿Æ¡£Ðж¯ÖУ¬¹ú¼ÊÐ̾¯×éÖ¯Óë¶à¼ÒË½ÓªÍøÂ簲ȫ¹«Ë¾ºÏ×÷×·×Ù¶ñÒâ»ù´¡ÉèÊ©£¬ºÏ×÷·½Ô̺¬¿¨°Í˹»ù¡¢Group-IB¡¢Shadowserver»ù½ð»á¡¢Team CymruºÍTrendAI¡£ÕâÊǹú¼ÊÐ̾¯×éÖ¯½ñÄêʵÏֵĵÚÈý´Î³Á´óÍøÂç·¸×ï½ø¹¥Ðж¯¡£
https://www.bleepingcomputer.com/news/security/interpol-operation-ramz-seizes-53-malware-phishing-servers/
2. ÐÂÐÍmacOS¶ñÒâÈí¼þ¡°Reaper¡±½èÐéα°²È«¸üÐÂÇÔÈ¡Êý¾Ý
5ÔÂ18ÈÕ£¬Ò»¿îÃûΪ¡°Reaper¡±µÄ¡°SHub¡±macOSÐÅÏ¢ÇÔÈ¡·¨Ê½Ð±äÖÖÔÚ»îÔ¾´«²¼£¬ËüÀûÓÃAppleScriptÏÔʾÐéαµÄ°²È«¸üÐÂÐÂÎÅ£¬½ø¶ø×°ÖúóÃÅ¡£Õâ¿î¶ñÒâÈí¼þ»áÇÔÈ¡Ãô¸ÐµÄä¯ÀÀÆ÷Êý¾Ý£¬ÍøÂç¿ÉÄÜÔ̺¬²ÆÕþÐÅÏ¢µÄÎĵµºÍÎļþ£¬²¢½Ù³Ö¼ÓÃÜÇ®°üÀûÓ÷¨Ê½¡£Óëǰ´úSHub¹¥»÷ÒÀÀµ¡°ClickFix¡±Õ½ÊõÓÕÆÓû§ÔÚÖÕ¶ËÖÐÕ³ÌùºÍÖ´ÐкÅÁî·ÖÆç£¬Reaperת¶øÑ¡È¡URL¹æ»®£¬Ö±½ÓÆô¶¯Ô¤×°Á˶ñÒâAppleScriptµÄmacOS¾ç±¾±à×ëÆ÷¡£ÕâÖÖ²½Öè³É¹¦ÈƹýÁËÆ»¹û¹«Ë¾ÔÚmacOS Tahoe 26.4ÖÐÒýÈëµÄ»ùÓÚÖն˵Ļº½â´ëÊ©¡£SentinelOneµÄ×êÑÐÈËÔ±·¢ÏÖ£¬Óû§ÊDZ»ÓÕÆÊ¹ÓÃ΢ÐźÍMiroÀûÓ÷¨Ê½µÄÐéαװÖ÷¨Ê½£¬ÕâЩ·¨Ê½ÍйÜÔÚ¿´ËƺϷ¨µÄÓòÃûÉÏ¡£Ä¿Ç°£¬¼ÙðµÄQQºÍ΢ÈíÓòÃûÈÔÔÚÌṩÐéα΢ÐÅ×°Ö÷¨Ê½£¬¶ø¼ÙÒâMiroµÄÓòÃûÔò»á³Á¶¨Ïòµ½ºÏ·¨ÍøÕ¾¡£¶ñÒâÍøÕ¾Ê×ÏȶԽӼûÕßÉ豸½øÐÐÖ¸ÎÆ¼ø±ð£¬²é³ÊÇ·ñ´æÔÚÐé¹¹»úºÍVPN£¬²¢ÁгöÒÑ×°ÖõÄÃÜÂëÖÎÀíÆ÷¡¢¼ÓÃÜÇ®±ÒÇ®°üµÈä¯ÀÀÆ÷À©´ó£¬ËùÓÐÒ£²âÊý¾Ýͨ¹ýTelegram»úеÈË·¢Ë͸ø¹¥»÷Õß¡£µ±Êܺ¦Õßµã»÷¡°ÔËÐÓ×±ºó£¬¾ç±¾»áÏÔʾһÌõαÔìµÄÆ»¹û°²È«¸üÐÂÐÂÎÅ£¬¶øºóʹÓÃcurlÏÂÔØshell¾ç±¾²¢Í¨¹ýzsh¾²Ä¬Ö´ÐС£
https://www.bleepingcomputer.com/news/security/shub-macos-infostealer-variant-spoofs-apple-security-updates/
3. Grafana LabsÔâÈëÇÖ£º±»µÁ´ú±ÒÖÂÔ´´úÂëй¶
5ÔÂ18ÈÕ£¬½üÈÕ£¬ÀÕË÷×éÖ¯Coinbase Cartel½«Grafana LabsÁÐÈëÆäÐ¹Â¶ÍøÕ¾²¢Ðû³ÆÊý¾Ý±»µÁ£¬ËæºóGrafana Labs֤ʵ²úÉúÁËһ·°²È«ÊÂÎñ¡£Õâ´Îй¶ÊÇÓÉÒ»¸ö±»µÁÓõĴú±Ò´¥·¢µÄ£¬¸Ã´ú±Òʹ¹¥»÷Õß¿ÉÄܽӼû¸Ã¹«Ë¾µÄGitHub»·¾³¡£Grafana LabsÊÇÒ»¼ÒÒÔ¹¹½¨¼à¿ØºÍ¿ÉÊÓ»¯ITϵͳ¡¢ÀûÓ÷¨Ê½¼°»ù´¡ÉèÊ©Êý¾ÝµÄ¿ªÔ´¹¤¾ß¶øÎÅÃûµÄÈí¼þ¹«Ë¾£¬ÆäÖ÷Ìâ²úÆ·Grafana±»¿í·ºÀûÓÃÓÚÔÆÍÆËã¡¢DevOpsºÍÍøÂ簲ȫ»·¾³¡£Coinbase Cartel×éÖ¯½«GrafanaÁÐÈëÊܺ¦ÕßÃûµ¥ºó£¬Grafana°µÊ¾¹¥»÷Õß½Ó¼ûÁËÆä²¿ÃÅÔ´´úÂ룬µ«Î´·¢ÏÖ¿Í»§Êý¾Ý±»µÁ¡¢Ó×ÎÒÊý¾Ýй¶»ò¶Ô¿Í»§ÏµÍ³¼°ÔËÓªÔì³ÉÓ°ÏìµÄÖ¤¾Ý¡£¸Ã¹«Ë¾Òѳ·Ïú²¢³ÁÖÃÁ˱»µÁÓÃµÄÆ¾Ö¤£¬Í¬Ê±Æô¶¯È¡Ö¤µ÷²éÒÔÈ·¶¨ÁîÅÆÈôºÎй¶¡¢ÄÄЩ´æ´¢¿â±»½Ó¼ûÒÔ¼°ÊÇ·ñ»¹ÓÐÆäËûϵͳÊܵ½Ó°Ï죬²¢³Ðŵµ÷²éʵÏÖºó°ä²¼¸ü¶àϸ½Ú¡£Grafana LabsÃ÷È·°µÊ¾²»»áÖ§¸¶¹¥»÷ÕßË÷ÒªµÄÊê½ðÒÔ×èÖ¹±»µÁÔ´´úÂ빫¿ª¡£½ØÖÁ·¢¸åʱ£¬Coinbase CartelÉÐδ°ä²¼GrafanaµÄÊý¾Ý£¬µ«¾Ý±¨Â·¸Ã×éÖ¯ÒÑ·¢³öÍþв£¬³ÆÈôÊÇÆäÒªÇ󱻺öÊÓ½«Ãæ¶ÔÑϳÁºó¹û¡£
https://securityaffairs.com/192347/breaking-news/grafana-confirms-github-token-breach-cybercrime-group-claims-the-attack.html
4. ŦԼ¹«¹²ÎÀ³¯Æø¹¹ÔâÈëÇÖ£¬180ÍòÈËÊý¾Ýй¶
5ÔÂ18ÈÕ£¬Å¦Ô¼¹«¹²ÎÀ³¯Æø¹¹NYC Health + HospitalsÅû¶ÁËһ·³ÖÐøÊýÔµijÁ´óÊý¾Ýй¶ÊÂÎñ£¬ÖÁÉÙÓ°Ïì180ÍòÈË¡£×÷ΪÃÀ¹ú×î´óµÄ¹«¹²ÎÀÉúϵͳ£¬¸Ã»ú¹¹Îª³¬¹ýÒ»°ÙÍòŦԼÊÐÃñÌṩҽÁÆ·þÎñ£¬ÆäÖÐÎÞÊýÈËûÓÐÒ½ÁƱ£ÏÕ»òÒÀÀµÒ½ÁƲ¹ÖúµÈµ±¾Ö¸£Àû¡£¸ÃÒ½ÁÆÏµÍ³ÒÑÏòÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿»ã±¨´ËÊ£¬Ê¹Æä³ÉΪ½ñÄêÆù½ñΪֹ¹æÄ£×î´óµÄÒ½ÁƱ£½¡ÓйØÊý¾Ýй¶ÊÂÎñÖ®Ò»¡£Æ¾¾Ý¸Ã»ú¹¹ÔÚÆäÍøÕ¾°ä²¼µÄ֪ͨ£¬NYC Health + HospitalsÓÚ2ÔÂ2ÈÕ¼ì²âµ½ÍøÂç¹¥»÷²¢²ÉÈ¡´ëÊ©±£»¤ÍøÂ磬µ«ºÚ¿Í×Ô2025Äê11ÔÂÖÁ2026Äê2ÔÂÆÚ¼äÒÑÈëÇÔìäÍøÂç²¢¸´ÔìÁËÎļþ¡£¸ÃÒ½ÁÆÏµÍ³°µÊ¾£¬ºÚ¿ÍÈëÇÖÊÇÓÉÒ»¼Òδй©Ãû³ÆµÄµÚÈý·½¹©¸øÉ̵ÄÊý¾Ýй¶Ôì³ÉµÄ¡£Ð¹Â¶µÄÊý¾ÝÒòÈ˶øÒ죬Ô̺¬»¼ÕߵĽ¡È«±£ÏÕ´òËãºÍ±£µ¥ÐÅÏ¢¡¢Õï¶Ï¡¢ÓÃÒ©¡¢²é³¼°Ó°Ïñ×ÊÁϵÈÒ½ÁÆÐÅÏ¢£¬ÒÔ¼°Õ˵¥¡¢ÀíÅâºÍÖ§¸¶ÐÅÏ¢¡£´Ë±í£¬Éç»á°²È«ºÅÂë¡¢»¤ÕÕ¡¢¼ÝÊ»ÅÆÕÕµÈÆäËûµ±¾ÖÇ©·¢µÄÉí·ÝÖ¤Ã÷ÎļþÒ²Ôâй¶¡£Í¨Öª»¹³ö¸ñÖ¸³ö£¬Ð¹Â¶ÊÂÎñÖлñÈ¡ÁË¡°¾«È·µÄµØÀíµØÎ»Êý¾Ý¡±£¬°µÊ¾Óû§ÉÏ´«µÄÉí·ÝÖ¤¼þÕÕÆ¬¿ÉÄÜÔ̺¬ÁËÅÄÉãÖ¤¼þ¼òÖ±ÇеØÎ»¡£Õâ´ÎÊý¾Ýй¶ÓÈΪÃô¸Ð£¬ÓÉÓÚºÚ¿ÍÇÔÈ¡ÁËÔ̺¬Ö¸ÎƺÍÕÆÎÆÔÚÄÚµÄÉúÎï¼ø±ðÐÅÏ¢¡£
https://techcrunch.com/2026/05/18/nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/
5. 7-ElevenÔâShinyHuntersÇÔÈ¡60ÍòSalesforce¼Í¼
5ÔÂ18ÈÕ£¬7-ElevenÒÑ֤ʵ²úÉúÊý¾Ýй¶ÊÂÎñ£¬´ËǰShinyHuntersºÚ¿Í×éÖ¯Ðû³ÆÇÔÈ¡Á˳¬¹ý60ÍòÌõÔ̺¬Ó×ÎҺ͹«Ë¾ÐÅÏ¢µÄSalesforce¼Í¼¡£¸ÃÍøÂç·¸×ï×éÖ¯ÔÚÆäTorÊý¾ÝÐ¹Â¶ÍøÕ¾ÉϰµÊ¾£¬Ö»¹ÜչʾÁ˼«´óµÄÄÍÐIJ¢Ìá³öÁ˸÷Àà»úÓöºÍ¹æ»®£¬µ«¹«Ë¾Ê¼ÖÕδÄÜÓëÆä´ï³ÉºÍ̸£¬²¢Íþв³ÆÈôÊÇÊê½ðÔÚ4ÔÂ21ÈÕ֮ǰ²»Ö§¸¶£¬½«°ä²¼±»µÁÊý¾Ý¡£7-ElevenÊÇÈ«Çò×î´óµÄ·½±ãµêÁ¬ËøÆóÒµ£¬ÔÚ±±ÃÀ¡¢ÑÇÖÞ¡¢Å·Ö޵ȵØÓòÓµº±¼ûǧ¼ÒÃŵ꣬¸Ã¹«Ë¾1927ÄêµÞÔìÓÚÃÀ¹ú£¬ÒÔ24Ó×ʱ½»Ò׺ÍÌṩÁãʳ¡¢ÒûÁÏ¡¢Ê³Æ·ÔÓ»õ¡¢È¼ÓÍ¡¢¼´Ê³Ê³Æ·¼°ÈÕ³£±ØÐëÆ·¶øÎÅÃû¡£7-Eleven°µÊ¾£¬2026Äê4ÔÂ8ÈÕ£¬Î´¾ÊÚȨµÄµÚÈý·½½Ó¼ûÁË´æ´¢¼ÓÃËÉÌÎļþµÄϵͳ£¬¹«Ë¾ÔÚ·¢ÏÖ°²È«·ì϶ºóÁ¢¼´·¢Õ¹µ÷²é¡£Æ¾¾ÝÊý¾Ýй¶֪ͨº¯£¬Ð¹Â¶µÄÎļþÔ̺¬Ó×ÎÒÔÚÌØÐí¾ÓªÉêÇë¹ý³ÌÖÐÌá½»µÄÐÅÏ¢£¬¹«Ë¾ÒÑÆðͷ֪ͨÊÜÓ°ÏìµÄÓ×ÎÒ£¬µ«Ä¿Ç°ÊÜÓ°ÏìµÄ×ÜÈËÊýÉв»Ã÷ÏÔ¡£×Ô2025ÄêÖÐÆÚÒÔÀ´£¬ShinyHuntersÒ»ÏòÒÔ´óÐÍ×éÖ¯µÄSalesforceÊ·ýΪָ±ê£¬ÒÑÇÔÈ¡ÁËÊý°ÙÍò±Ê¼Í¼¡£
https://securityaffairs.com/192336/data-breach/shinyhunters-hack-7-eleven-franchisee-data-and-salesforce-records-exposed.html
6. TabiqÅäÖÃÃýÎóÖ°ÙÍò·Ý»¤ÕÕ¼ÝÕÕµÈй¶
5ÔÂ18ÈÕ£¬Reqrea¹«Ë¾ÆìϵÄTabiq¾ÆµêÈëסϵͳ³öÏÖ°²È«·ì϶£¬µ¼Ö³¬¹ý100Íò·Ý»¤ÕÕ¡¢¼ÝÕÕºÍ×ÔÅÄÕÕÑéÖ¤ÐÅϢй¶µ½ÍøÉÏ¡£ÎÊÌâÔ´ÓÚÒ»¸öÅäÖÃÃýÎóµÄÑÇÂíÑ·ÔÆ´æ´¢Í°£¬¸Ã´æ´¢Í°±»ÉèÖÃΪ¹«¿ª½Ó¼û£¬Òâζ×ÅÈκÎÕ¼ÓÐÍøÂçä¯ÀÀÆ÷²¢ÖªÂ·´æ´¢Í°Ãû³Æ¡°tabiq¡±µÄÈ˶¼Äܹ»ÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öϲ黤ÀíÕÕ¡¢Éí·ÝÖ¤¼°ÆäËû¿Í»§Êý¾Ý¡£ÍøÂ簲ȫ×êÑÐÔ±°¢Å¬À¸ñ¡¤É·¢ÏÖÁËÕâÒ»·ì϶£¬²¢ÔÚ·¢ÏÖÒ»¼Ò¾ÆµêµÄÈëסϵͳй¶ÁËÈ«ÇòÁìÓòÄÚ¿ÍÈ˵ÄÃô¸ÐÎļþºóÏòTechCrunch·¢³ö¾¯±¨¡£É»ã±¨´ËÎÊÌâÊÇΪÁË´ÙʹÓйز¿ÃŲÉÈ¡Ðж¯¡£ÔÚTechCrunch֪ͨ¾ÆµêºÍÈÕ±¾ÍøÂ簲ȫе÷Ó××éJPCERTºó£¬¸ÃϵͳµÃµ½½¨¸´£¬Ð¹Â¶µÄÊý¾Ý´æ´¢Í°Ò²±»Ëø¶¨¡£¾ÝTechCrunch±¨Â·£¬Ð¹Â¶µÄ´æ´¢Í°ÖÐÔ̺¬´Ó2020ËêÊ×µ½±¾ÔµÄÎļþ£¬º¸ÇÀ´×ÔÊÀ½ç¸÷µØ¶à¸ö¹ú¶È/µØÓòµÄ¾Æµê¿ÍÈ˵ÄÉí·ÝÖ¤Ã÷Îļþ¡£Reqrea×ܼàÇű¾ÕýТ°µÊ¾£¬¹«Ë¾ÔÚ±í²¿Ë¾·¨ÕÕ·÷ºÍÆäËûÕÕ·÷µÄÖ§³ÖϽøÐÐÈ«ÃæÉó²é£¬ÒÔÈ·¶¨·çÏÕ³¨¿ÚµÄÈ«ÊýÁìÓò¡£Reqrea³Æ£¬ËûÃÇÉв»Ã÷ÏԴ洢ͰÊÇÈôºÎ±»¹«¿ªµÄ£¬²¢Ö¸³öÑÇÂíÑ·S3´æ´¢Í°Ä¬ÈÏÊÇ˽Óеģ¬ÇÒ´Ë¿ÌÒÑÔö³¤Á˶î±íÖÒ¸æÒÔÔ¤·ÀÒâ±íй¶¡£Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖУ¬¹«Ë¾´òËãÔÚµ÷²éʵÏÖºó֪ͨÊÜÓ°ÏìµÄÓû§¡£
https://securityaffairs.com/192302/data-breach/public-amazon-bucket-leaks-sensitive-guest-data-from-japanese-hotel-platform-tabiq.html


¾©¹«Íø°²±¸11010802024551ºÅ