¾¯ÌèKali365ƽ̨£ºÐÂÐÍÍøÂç´¹µö¿ÉÈÆ¹ý΢ÈíMFA
°ä²¼¹¦·ò 2026-05-265ÔÂ25ÈÕ£¬ÃÀ¹úÁª¹úµ÷²é¾Ö£¨FBI£©½üÈÕ°ä²¼ÖҸ棬һÖÖÃûΪ¡°Kali365¡±µÄÍøÂç´¹µö¼´·þÎñƽ̨£¨PhaaS£©ÕýÀûÓÃOAuthÉ豸´úÂëÉí·ÝÑéÖ¤Á÷³Ì£¬´ó¹æÄ£½Ù³ÖMicrosoft 365ÕË»§¡£¸Ãƽ̨ÓÚ2026Äê4Ô³õ´Î³öÏÖ£¬Í¨¹ýTelegramƵ·´«²¼£¬ÆäÖ÷ÌâÌØµãÊÇÎÞÐèÇÔÈ¡Óû§ÃÜÂë»òÀ¹½Ø¶à³É·ÖÈÏÖ¤£¨MFA£©ÑéÖ¤Â룬¼´¿ÉÖ±½ÓµÁÈ¡»á»°ÁîÅÆ£¬´Ó¶øÈƹý¶à³É·ÖÈÏÖ¤µÄ±£»¤»úÔì¡£Kali365µÄ¹¥»÷¼¿Á©»ùÓÚ¶Ô΢ÈíºÏ·¨OAuth 2.0É豸ÊÚȨÊÚÓèÁ÷³ÌµÄÀÄÓ᣸ÃÁ÷³Ì±¾ÊÇΪÊäÈëÖ°ÄÜÓÐÏÞµÄÉ豸£¨ÈçÖÇÄܵçÊÓ¡¢´òÓ¡»ú¡¢ÎïÁªÍøÉ豸£©Éè¼ÆµÄ±ã½ÝµÇ¼·½Ê½£¬ÔÊÐíÓû§Í¨¹ýÁíһ̨É豸½Ó¼û΢ÈíÉ豸´úÂëµÇ¼ÃÅ»§£¬²¢ÊäÈë¶ÌÂëʵÏÖÉí·ÝÑéÖ¤¡£È»¶ø£¬¹¥»÷Õß×Ô¶¯Æô¶¯É豸ÊÚȨ¹ý³ÌÌìÉú´úÂ룬¶øºóÀûÓô¹µöÓʼþ¡¢Éç»á¹¤³ÌѧµÈ¼¿Á©ÓÕÆÊܺ¦ÕßÔÚ΢Èí¹Ù·½µÇÂ¼Ò³ÃæÊäÈë¸Ã´úÂë¡£Ò»µ©Êܺ¦ÕßʵÏÖMFAÑéÖ¤£¬Î¢Èí±ã»áÐû¸æOAuth½Ó¼ûÁîÅÆ£¬¹¥»÷ÕßËæ¼´»ñµÃÕË»§ÆëÈ«½Ó¼ûȨÏÞ£¬¿ÉµÇ¼Ô̺¬Microsoft 365¡¢SalesforceÔÚÄڵĸ÷ÀàÔÆSaaSƽ̨£¬ÇÔÈ¡Óʼþ¡¢Êý¾Ý£¬ÉõÖÁ´´½¨¶ñÒâÊÕ¼þÏ乿¶¨°µ²ØÐÐ×Ù»òÔÚÊܺ¦ÕßµÄ΢Èí»·¾³ÖÐ×¢²áÐÂÉ豸ÒÔÀ©´ó½Ó¼ûÁìÓò¡£
https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/
2. Ö×Áö×êÑÐËùÊý¾Ýй¶ȷÈÏÓ°Ï컼ÕßÐÅÏ¢
5ÔÂ25ÈÕ£¬ÃÀ¹úÖ×Áö×êÑÐËù£¨TOI£©½üÈÕÈ·ÈÏ£¬´ËǰÅû¶µÄÒ»Â·ÍøÂ簲ȫÊÂÎñÒÑÏÖʵӰÏ컼ÕßÊý¾Ý¡£TOIÊÇÒ»¼Ò³ÉÁ¢ÓÚ2007ÄêµÄÖ×ÁöÒ½Öλú¹¹£¬Í¨¹ý±é²¼Îå¸öÖݵÄ100¶à¼ÒÕïËùÍøÂçÌṩרҵ°©Ö¢Ò½ÖηþÎñ¡£¸Ã»ú¹¹ÓÚ2025Äê11ÔÂÏòÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©»ã±¨³Æ£¬ÆäµÚÈý·½Èí¼þ·þÎñÌṩÉÌÔâ·êÍøÂ簲ȫÊÂÎñ£¬ÆäʱÓÉÓÚ¹©¸øÉ̵÷²éÉÐδʵÏÖ£¬ÎÞ·¨È·¶¨»¼ÕßÐÅÏ¢ÊÇ·ñÒѱ»Ð¹Â¶¡£È»¶øÔÚ2026Äê5ÔÂ20ÈÕ£¬×÷Ϊ¹©¸øÉ̵ÚÈý·½ÖÎÀí»ú¹¹µÄKroll¹«Ë¾Í¨ÖªTOI£¬¼ì²âµ½ÓÐÈËδ¾ÊÚȨ½Ó¼ûÁËTOIµÄijЩÐÅϢϵͳ£¬ÆäÖÐÔ̺¬´æ´¢»¼ÕßÊý¾ÝµÄϵͳ¡£TOIÔÚÉÏÖÜÌá½»¸øSECµÄÐÂÎļþÖаµÊ¾£¬¸ÃÍøÂ簲ȫÊÂÎñÒÑÓ°Ïìµ½ÆäËû¶à¼ÒÒ½ÁÆ·þÎñÌṩÉÌ£¬¹©¸øÉÌÒѳÉÁ¢»¼ÕßÃÅ»§ÍøÕ¾£¬´òËãͨ¹ý¸ÃÍøÕ¾ÌṩÓйØÐÅÏ¢²¢»Ø¸´»¼ÕßÕ÷ѯ¡£¹ÌÈ»TOIδÃ÷È·Ö¸Ã÷ÉæÊµĵÚÈý·½Èí¼þ¹©¸øÉÌ£¬µ«Æ¾¾ÝÊÂÎñ¹¦·òÏßÒÔ¼°¸Ã·ì϶¶Ô¶à¼ÒÒ½ÁÆ»ú»ú¹Ø³ÉÓ°ÏìµÄÊÂʵ£¬Òµ½çÆÕ±éÒÔΪCognizantÆìϵÄÒ½ÁƼ¼Êõ¹«Ë¾TriZetto Provider SolutionsºÜ¿ÉÄܾÍÊÇÓйط½¡£Ä¿Ç°£¬KrollÔÚ´¦ÖÃTriZettoµÄÐÅÏ¢Åû¶ÊÂÒË¡£TriZetto½ñÄêÔçЩʱ³½Ôø»ã±¨ÆäÔâ·êÊý¾Ýй¶£¬Ó°ÏìÁ˶à¼Ò¿Í»§£¬Éæ¼°Ô¼340ÍòÈË¡£
https://www.securityweek.com/oncology-institute-discloses-third-party-data-breach/
3. ÀïÊ¿Âú·ÅÉäѧ»áÊý¾Ýй¶ӰÏì26.6ÍòÈË
5ÔÂ25ÈÕ£¬ÀïÊ¿Âú·ÅÉäѧ»á£¨RAR£©½üÈÕÅû¶ÁËһ·³Á´óÊý¾Ýй¶ÊÂÎñ£¬Ô¼26.6ÍòÃûÓ×ÎÒµÄÊܱ£»¤½¡È«ÐÅÏ¢Êܵ½Ó°Ï졣ƾ¾Ý¸ÃÒ½ÁÆ»ú¹¹°ä²¼µÄÊÂÎñ֪ͨ£¬Êý¾Ýй¶²úÉúÔÚ2025Äê7ÔÂ25ÈÕ×óÓÒ£¬ÆäʱºÚ¿Í³É¹¦ÇÖÈëÁËÆäÄÚ²¿ÏµÍ³¡£RARδй©¾ßÌåºÎʱ·¢ÏÖÕâ´ÎÈëÇÖ£¬µ«°µÊ¾ÒÑÁ¢¼´Óë±í²¿ÍøÂ簲ȫר¼ÒºÏ×÷£¬ÒÔ¶ôÔì¹¥»÷²¢µ÷²éÆäÓ°ÏìÁìÓò¡£¾¹ý¿í·ºµÄ·¨Ö¤µ÷²éºÍÈËΪÎļþÉó²é£¬RARµÄµ÷²éÓÚ2026Äê4ÔÂ6ÈÕ×óÓҵóö½áÂÛ£ºÓÉÓÚ¸ÃÊÂÎñ£¬Ô̺¬²¿ÃÅÓ×ÎÒÊܱ£»¤½¡È«ÐÅÏ¢µÄÎļþÒѱ»Î´¾ÊÚȨµÄ·½Ê½»ñÈ¡¡£2026Äê5ÔÂ21ÈÕ£¬RARÆðÍ·Ïò¿ÉÄÜÊÜÓ°ÏìµÄÓ×ÎÒ¼ÄËÍ֪ͨÐÅ¡£Æ¾¾Ý¸Ã×éÖ¯ÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄÎļþ£¬¹²ÓÐ266,183ÈËÊÕµ½ÁË´ËÀຯ¼þ¡£RAR°ä²¼µÄÊÂÎñ¹«¸æ¼°Ìá½»¸ø¶à¸öÖݵ±¾ÖµÄ¾±à×뺯¼þÑù±¾ÏÔʾ£¬Ð¹Â¶µÄÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃûºÍÉç»á°²È«ºÅÂ롣Ȼ¶ø£¬ÕâЩÎļþ²¢Î´ÌṩÊÜÓ°ÏìÊý¾ÝµÄÆëȫϸ½Ú¡£Æ¾¾ÝµÂ¿ËÈøË¹ÖÝ×ܼì²ì³¤ÍøÕ¾ÉϵÄÇåµ¥£¬Õâ´Î¹¥»÷ÖпÉÄܱ»µÁµÄÐÅÏ¢»¹Ô̺¬µ±¾ÖÐû¸æµÄÉí·ÝÖ¤ºÅÂë¡¢²ÆÕþÐÅÏ¢£¨º¬ÐÅÓþ¿¨»ò½è¼Ç¿¨ºÅÂ룩£¬ÒÔ¼°Ò½Áƺͽ¡È«±£ÏÕÏêÇé¡£
https://www.securityweek.com/266000-affected-by-data-breach-at-radiology-associates-of-richmond/
4. Lazarus GroupÀûÓÃRemotePE¹¥»÷½ðÈÚ»ú¹¹
5ÔÂ25ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈո淢ÁËÒ»ÖÖÃûΪRemotePEµÄ¿çƽ̨¶ñÒâÈí¼þ£¬¸ÃÈí¼þÒѱ»Ó볯ÏÊÓйصĺڿÍ×éÖ¯Lazarus GroupÓÃÓÚ¹¥»÷½ðÈںͼÓÃÜÇ®±Ò»ú¹¹¡£¾ÝNCC¼¯ÍÅÆìÏÂFox-IT¹«Ë¾µÄ°²È«×êÑÐÈËÔ±ÔÆÕý»¢ºÍÃ׿ˡ¤¿âÃÅÅû¶£¬RemotePEÊÇÒ»¸ö¶à½×¶Î¹¥»÷Á´µÄ×îÖÕÔØºÉ£¬Õû¸ö¹¥»÷¹ý³ÌÉæ¼°Á½¸ö¼ÓÔØÆ÷£¬±ðÀë±»¸ú×ÙΪDPAPILoaderºÍRemotePELoader¡£DPAPILoaderÀûÓÃWindowsÊý¾Ý±£»¤API´Ó´ÅÅ̽âÃܲ¢¼ÓÔØRemotePELoader£¬ºóÕßËæºóÏòºÅÁîÓë½ÚÔì·þÎñÆ÷·¢ËÍÐű꣬ÆÚ´ý½Ó¹Ü×îÖս׶εÄRemotePE¡£ÕâÊÇÒ»ÖÖÆëÈ«ÔÚÄÚ´æÖÐÖ´ÐÓ×¢²»Ð´Èë´ÅÅ̵ÄÔ¶³Ì½Ó¼ûľÂí£¬Òò¶ø²»»áÔÚÎļþϵͳÖÐÁôÏÂÈκκۼ£¡£RemotePE×îÔçÓÚ2025Äê9Ô±»°²È«³§É̹Ø×¢£¬ÆäʱËüÓëһ·Õë¶ÔÈ¥ÖÐÐÄ»¯½ðÈÚÁìÓòijδ¾ßÃû×éÖ¯µÄ¹¥»÷Óйأ¬ÄǴι¥»÷»¹²¿ÊðÁËPondRATºÍThemeForestRATÁ½¸ö¶ñÒâÈí¼þ¼Ò×å¡£ÈëÇÖͨ³£Ê¼ÓÚÉç½»¹¤³Ì¼¿Á©£º¹¥»÷Õß¼Ù×°³ÉÒµÎñ¹«Ë¾Ô±¹¤£¬Í¨¹ýTelegram¿¿½üÊܺ¦Õߣ¬²¢ÔÚÐéαµÄCalendlyºÍPicktimeÓòÃûÉÏÆÌÅÅ»áÒé¡£
https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html
5. Station CasinosÈ·ÈÏÊý¾Ýй¶
5ÔÂ22ÈÕ£¬À˹ά¼Ó˹×î´óµÄ¶Ä³¡ÔËÓªÉÌÖ®Ò»Station Casinos½üÈÕÔÚÒ»·Ý¼à¹ÜÎļþÖÐ֤ʵÁËÍøÂ簲ȫ·ì϶ÊÂÎñ£¬³ÉΪÓÖÒ»¼Ò±»ÍøÂç·¸×ï·Ö×ÓÁÐÈë¹¥»÷Ö¸±êÃûµ¥µÄ´óÐͲ©²ÊÔËÓªÉÌ¡£Æ¾¾Ý¸Ã¹«Ë¾ÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄÕýʽÊý¾Ýй¶֪ͨ£¬°²È«ÊÂÎñ²úÉúÓÚ2026Äê3ÔÂ5ÈÕ£¬²¢ÓÚµ±Ìì±»·¢ÏÖ¡£Ïû·ÑÕß֪ͨ¹¤×÷ÓÚ2026Äê5ÔÂ21ÈÕÆðÍ·¡£½ØÖÁĿǰ£¬Õâ´ÎÊý¾Ýй¶µÄ¾ßÌåÁìÓòÉв»Ã÷È·£¬¹«Ë¾ÉÐδ¹«¿ªÅû¶ÄÄЩϵͳÔâµ½ÈëÇÖ£¬Ò²Î´Ð¹Â©ÄÄЩÊý¾Ý¿ÉÄÜÒѱ»Ð¹Â¶¡£Ð¹Â¶Í¨ÖªÏÔʾ£¬ÖÁÉÙÓÐÒ»ÃûÃåÒòÖݾÓÃñµÄÊý¾ÝÊܵ½Ó°Ïì¡£Station Casinos°µÊ¾£¬Ò»ÃûÔ±¹¤µÄÕË»§Ô⵽δ¾ÊÚȨµÄµÚÈý·½½Ó¼û£¬¹¥»÷Õß»ñÈ¡Á˸ÃÕË»§¼°ÆäÓйØÎļþ¡£¹«Ë¾½²»°È˳ƣ¬Õâ´ÎÍøÂ簲ȫÊÂÎñ²¢Î´¶Ô¹«Ë¾µÄ²Æ¸»»òÒµÎñÔËÓªÔì³ÉÈκÎÓ°Ïì¡£ÊÂÎñ²úÉúºó£¬Station CasinosÁ¢¼´²ÉÈ¡´ëʩӦ¶Ô£¬µÃµ½ÁË±í²¿ÍøÂ簲ȫר¼ÒµÄÐÖú£¬²¢Óë·¨Âɲ¿ÃźÏ×÷¡£¹«Ë¾°µÊ¾ÒÑ֪ͨÊÜÓ°ÏìµÄÓ×ÎҺͼà¹Ü»ú¹¹£¬²¢ÎªËùÓпÉÄÜÊÜÓ°ÏìµÄÓ×ÎÒÌṩÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ±£»¤¡£¹«Ë¾ÒÔΪÕâ´ÎÊÂÎñ²»»á¶Ô²ÆÕþÇé¿ö»ò¾½»Ò×¼¨²úÉú³Á´ó²»ÀûÓ°Ïì¡£
https://cybernews.com/security/station-casinos-data-breach-las-vegas-hacking/
6. ºÚ¿ÍÐû³ÆÈëÇÖ·¨¹úÒ½ÁÆÖ§¸¶¾ÞÍ·Almerys
5ÔÂ22ÈÕ£¬Ò»ÃûºÚ¿ÍÐû³ÆÒÑÈëÇÖ·¨¹úÖØÒªÒ½ÁƱ£½¡Ö§¸¶ÔËÓªÉÌAlmerysµÄϵͳ£¬²¢ÔÚ³ÛÃûÍøÂç·¸×ïÊг¡ÉÏÏúÊÛ´óÁ¿Êý¾Ý£¬¾Ý³ÆÔ̺¬³¬¹ý4400Íò±Ê¼Í¼ºÍ1500¶àÍò¸ö·¨¹ú¹«ÃñµÄΨһÉç»á±£ÏÕºÅÂë¡£Almerys³ÉÁ¢ÓÚ2000Ä꣬×ܲ¿Î»ÓÚ¿ËÀ³ÃÉ·ÑÀÊ£¬ÊÇ·¨¹úÖØÒªµÄÒ½ÁÆÖ§¸¶ÔËÓªÉÌÖ®Ò»£¬Í¨¹ý84¸öÒ½ÁÆ»ú¹¹×é³ÉµÄÍøÂçΪ2000Íò²Î±£ÈËÔ±´¦ÖÃÒ½ÁÆÖ§¸¶Êý¾Ý¡£ÍøÂçÐÂÎÅ×êÑÐÈËÔ±¶ÔÍþвÐÐΪÕß°ä²¼µÄÌû×ÓºÍÊý¾ÝÑù±¾½øÐÐÁËÉó²é£¬Ñù±¾¼Í¼ÖÐÔ̺¬È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢²¿ÃÅÉç»á°²È«ºÅÂëÒÔ¼°¹ÍÖ÷»ò×éÖ¯ÏêÇéµÈÓ×ÎÒÉí·ÝÐÅÏ¢¡£È»¶ø£¬×êÑÐÈËÔ±Ö¸³ö£¬Ñù±¾ÖеÄÉç»á±£ÏÕºÅÂë½öÏÔʾÁË13λ»ùÊý£¬È±Ê§ÁË×îºóÁ½Î»ÃÜÔ¿£¬ÕâÒý·¢Á˹ØÓÚÊý¾ÝÕæÊµÐÔºÍÆëÈ«ÐÔµÄÒÉÄÑ¡£Ñù±¾¿ÉÄܱ»¹¥»÷ÕßÓÐÒâɾ¼õ£¬»òÊÇΪÁ˱£ÁôÊý¾Ý¼ÛÖµÒÔ¹©ÏúÊÛ£¬»òÊÇΪÁ˽µµÍÁ¢¼´Ê¶´ËÍâ¿ÉÄÜÐÔ¡£Ä¿Ç°£¬¸ÃÊý¾Ý¼¯µÄÕæÊµÐÔÉÐδµÃµ½¶ÀÁ¢ÑéÖ¤£¬Éв»Ã÷ÏÔÊÇ·ñµÄÈ·Ô̺¬Ðû³ÆµÄ4400Íò±Ê¼Í¼¡£×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬ÈôÊÇй¶Êý¾ÝµÄÈ·Ô̺¬¿ÉÆ´´Õ³öÓ×ÎÒÆëÈ«ÐÅÏ¢µÄÏêÇ飬ÊÜÓ°ÏìµÄÓ×ÎÒ½«Ãæ¶ÔÉí·Ý͵ÇÔ·çÏÕ£¬´Ë±í¹¤×÷³¡ËùÒ²´æÔÚ±»¿úËŵķçÏÕ¡£
https://cybernews.com/security/almerys-french-healthcare-data-leak/


¾©¹«Íø°²±¸11010802024551ºÅ