KeePassľÂí°æ±¾·Ö·¢³¤´ï°ËÔ£¬£¬ÇÔÃܲ¢²¿ÊðÀÕË÷Èí¼þ

°ä²¼¹¦·ò 2025-05-20

1. KeePassľÂí°æ±¾·Ö·¢³¤´ï°ËÔ£¬£¬ÇÔÃܲ¢²¿ÊðÀÕË÷Èí¼þ


5ÔÂ19ÈÕ£¬£¬WithSecureÍþвµý±¨ÍŶӵ÷²é·¢ÏÖ£¬£¬ÍþвÐÐΪÕßÖÁÉٰ˸öÔÂÀ´Ò»ÏòÔÚ·Ö·¢KeePassÃÜÂëÖÎÀíÆ÷µÄľÂí°æ±¾KeeLoader£¬£¬ÒÔÖ´ÐжñÒâ»î¶¯¡£KeePass×÷Ϊ¿ªÔ´Èí¼þ£¬£¬ÆäÔ´´úÂë±»ÍþвÐÐΪÕßÅú¸Ä£¬£¬¹¹½¨ÁËÔ̺¬Í¨ÀýÃÜÂëÖÎÀíÖ°ÄܵÄľÂí»¯°æ±¾¡£¸Ã°æ±¾²»½öÄÜ×°ÖÃCobalt StrikeÐű꣬£¬»¹Äܽ«KeePassÃÜÂëÊý¾Ý¿âµ¼³öΪÃ÷ÎIJ¢Í¨¹ýÐűêÇÔÈ¡¡£Õâ´Î»î¶¯ÖÐʹÓõÄCobalt StrikeˮӡÓë³õʼ½Ó¼û´úÀí(IAB)ÓйØÁª£¬£¬¸Ã´úÀí±»ÒÔΪÓë´ÓǰµÄBlack BastaÀÕË÷Èí¼þ¹¥»÷ÓйØ¡£Cobalt StrikeˮӡÊÇǶÈëÔÚÐűêÖеÄΨһ±êʶ·û£¬£¬Í¨³£ÓëBlack BastaÀÕË÷Èí¼þÓйØ¡£KeeLoaderÓжàÖÖ±äÖÖ£¬£¬Ê¹ÓúϷ¨Ö¤ÊéÊðÃû£¬£¬²¢Í¨¹ýÓòÃûÇÀ×¢½øÐд«²¼¡£ÕâЩ±»Ä¾ÂíϰȾµÄ·¨Ê½²»½öÓµÓÐÃÜÂëÇÔȡְÄÜ£¬£¬»¹ÄÜÔÚÓû§´ò¿ªKeePassÊý¾Ý¿âʱ£¬£¬½«Êý¾Ýµ¼³öΪCSVÌåʽ£¬£¬±ãÓÚÍþвÐÐΪÕßÇÔÈ¡¡£×îÖÕ£¬£¬WithSecureµ÷²éµÄ¹¥»÷µ¼Ö¹«Ë¾VMware ESXi·þÎñÆ÷±»ÀÕË÷Èí¼þ¼ÓÃÜ¡£½øÒ»´ëÊ©²é·¢ÏÖ£¬£¬¸Ã»î¶¯ÒѳÉÁ¢ÖØ´ó»ù´¡ÉèÊ©£¬£¬ÓÃÓÚ·Ö·¢¼Ù×°³ÉºÏ·¨¹¤¾ßµÄ¶ñÒⷨʽºÍÖ¼ÔÚÇÔȡƾ֤µÄÍøÂç´¹µöÒ³Ãæ¡£WithSecure½«´Ë»î¶¯¹é×ïÓÚUNC4696×éÖ¯£¬£¬¸Ã×éÖ¯´ËǰÓëNitrogen Loader»î¶¯ÓйØ£¬£¬¶øNitrogen»î¶¯ÓÖÓëBlackCat/ALPHVÀÕË÷Èí¼þÓйØ¡£


https://www.bleepingcomputer.com/news/security/fake-keepass-password-manager-leads-to-esxi-ransomware-attack/


2. ServiceaidÅäÖÃÃýÎóÖÂCatholic Health½ü50Íò»¼ÕßÐÅϢй¶


5ÔÂ19ÈÕ£¬£¬ÆóÒµITÌṩÉÌServiceaideÒòÊý¾Ý¿âÅäÖÃÃýÎ󣬣¬µ¼ÖÂÓëŦԼ·ÇͶ»úÐÔÒ½ÁƱ£½¡ÏµÍ³Catholic HealthÓйصÄÔ¼483,126Ãû»¼ÕßÃô¸Ð½¡¿µºÍСÎÒÐÅϢй¶¡£Õâ´Îй¶ԴÓÚÒ»¸öElasticsearchÊý¾Ý¿â±»ÎÞÒâÖй«¿ª£¬£¬²úÉúÔÚ2024Äê9ÔÂ19ÈÕÖÁ11ÔÂ5ÈÕÆÚ¼ä£¬£¬ÓÚ11ÔÂ15ÈÕ±»·¢ÏÖ£¬£¬È«ÃæÉó²é²Å¸ÕʵÏÖ¡£Ö»¹ÜÎÞÈ·ÔäÖ¤¾ÝÅú×¢Êý¾Ý±»ÏÂÔØ»òÀÄÓ㬣¬µ«¹«Ë¾²»ÄÜÅųýÕâÖÖ¿ÉÄÜÐÔ¡£Ð¹Â¶µÄÊý¾Ý¿âÔ̺¬´óÁ¿Ãô¸ÐÐÅÏ¢£¬£¬ÈçÈ«Ãû¡¢µ®ÉúÈÕÆÚ¡¢´¦·½Êý¾Ý¡¢Éç»á°²È«ºÅÂë¡¢½¡¿µ±£ÏÕÏêÇé¡¢Ò½ÁƱ£½¡ÌṩÕßÐÅÏ¢¡¢Ò½ÖκÍÁÙ´²ÐÅÏ¢¡¢Ò½ÁƼͼºÍÕ˺ÅÒÔ¼°µç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃÜÂëµÈ¡£ServiceaideÕý֪ͨÊÜÓ°ÏìСÎÒ£¬£¬²¢²ÉÈ¡´ëÊ©±£»£»¤Â¶³öµÄÊý¾Ý¿â£¬£¬Ôö³¤Ðµİ²È«ºÍ̸ÒÔ½µµÍ½«À´·çÏÕ¡£¸Ã¹«Ë¾»¹ÓëÁª°î¼à¹Ü»ú¹¹ºÏ×÷£¬£¬ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿ÒÑÔÚÆäÃñȨ°ì¹«ÊÒÎ¥¹æÃÅ»§ÍøÕ¾ÉϹ«¿ªÁËÕâ´ÎÊý¾Ýй¶ÊÂÎñ¡£Serviceaide½¨ÒéÊÜÓ°ÏìÓû§¹Ø×¢ÐÅÓþ»ã±¨¡¢¸ü¸ÄÓëÒ½ÁÆÕË»§¹ØÁªµÄÃÜÂ룬£¬²¢Ë¼¿¼¶³½áÐÅÓþ¡£


https://hackread.com/serviceaide-leak-catholic-health-patients-records/


3. Arla FoodsµÂ¹ú¹¤³§ÔâÍøÂç¹¥»÷Ö³ö²úÖжÏ


5ÔÂ19ÈÕ£¬£¬Arla Foods֤ʵ£¬£¬ÆäλÓڵ¹úÎÚÅÁ¶ûµÄ³ö²ú²¿ÃÅÔâ·êÁËÍøÂç¹¥»÷£¬£¬µ¼Ö³ö²úÔËÓªÖжÏ¡£Õâ¼Òµ¤ÂóʳƷ¾ÞÍ·°µÊ¾£¬£¬Õâ´Î¹¥»÷½öÓ°ÏìÁ˸óö²ú²¿ÃÅ£¬£¬µ«Ô¤¼Æ½«Òý·¢²úÆ·½»¸¶ÑÓ³¤ÉõÖÁÈ¡µÞ¡£Arla½²»°È˳Æ£¬£¬ÔÚÎÚÅÁ¶ûµÄÈ鯷³§·¢ÏÖÁË¿ÉÒɻ£¬£¬Ó°ÏìÁ˱¾µØµÄITÍøÂ磬£¬³öÓÚ°²È«Ë¼¿¼£¬£¬³ö²úÁÙʱÊܵ½Ó°Ïì¡£Arla Foods×÷Ϊ¹ú¼ÊÈéÖÆÆ·³ö²úÉ̺ÍÅ©·òºÏ×÷É磬£¬Õ¼ÓÐ7600Ãû³ÉÔ±£¬£¬ÔÚÈ«Çò39¸ö¹ú¶ÈÉèÓзÖÖ§»ú¹¹£¬£¬Ô±¹¤´ï23000ÈË£¬£¬ÄêÊÕÈë¸ß´ï138ÒÚÅ·Ôª£¬£¬²úÆ·ÏúÍùÈ«Çò140¸ö¹ú¶È¡£¹«Ë¾ÕýÖÂÁ¦¸´Ô­ÊÜÓ°Ï칤³§µÄÔËÓª£¬£¬²¢Ô¤¼Æ½«ÔÚ±¾ÖÜĩǰ»ñµÃ³É¾Í£¬£¬ÆäËû¹¤³§µÄ³ö²úÔòδÊÜÓ°Ïì¡£ÓÉÓÚ³ö²úÖжϵÄÐÂÎÅÔÚÖÜÎ寨¹â£¬£¬Ô¤¼ÆÄ³Ð©Çé¿öϽ«³öÏÖ²úƷǷȱ¡£ArlaÒÑ֪ͨÊÜÓ°ÏìµÄ¿Í»§¿ÉÄܳöÏÖ½»»õÑÓ³¤»òÈ¡µÞµÄÇé¿ö¡£µ±±»Îʼ°Õâ´Î¹¥»÷ÊÇ·ñÉæ¼°Êý¾Ý͵ÇÔ»ò¼ÓÃÜʱ£¬£¬Arla»Ø¾ø·ÖÏí¸ü¶àÐÅÏ¢¡£Ä¿Ç°£¬£¬ÀÕË÷Èí¼þڲƭÃÅ»§ÍøÕ¾ÉÏÉÐδ°ä²¼¹ØÓÚArlaµÄ²¼¸æ£¬£¬Òò¶ø¹¥»÷ÀàÐͺÍÖ´ÐÐÕßÒÀȻδ֪¡£


https://www.bleepingcomputer.com/news/security/arla-foods-confirms-cyberattack-disrupts-production-causes-delays/


4. Ó¢¹ú˾·¨ÔöÔ®»ú¹¹ÔâÍøÂç¹¥»÷ÖÂÃô¸ÐÊý¾Ýй¶


5ÔÂ19ÈÕ£¬£¬Ó¢¹ú˾·¨ÔöÔ®»ú¹¹(LAA)È·ÈÏ£¬£¬½üÆÚÔâ·êµÄÍøÂç¹¥»÷Ô¶±È×î³õÔ¤¼ûµÄÑÏÖØ£¬£¬ºÚ¿ÍÇÔÈ¡ÁË´óÁ¿Ãô¸ÐµÄÉêÇëÈËÊý¾Ý¡£LAA×÷ΪӢ¹ú˾·¨ÊÖÏÂÊôµÄÖ´Ðлú¹¹£¬£¬ÕƹÜΪ¾­¼ÃÄÑÌâÕßÌṩ˾·¨ÔöÔ®£¬£¬Õâ´ÎÊý¾Ýй¶ÊÂÎñÉæ¼°ÖÚ¶àÃô¸ÐÐÅÏ¢¡£±¾ÔÂÔçЩʱ³½£¬£¬LAAÔøÅû¶²úÉú°²È«ÊÂÎñ£¬£¬³ÆÓÐÏÞ²ÆÕþÐÅÏ¢¿ÉÄÜй¶£¬£¬µ«×îÐÂÐÂÎÅÏÔʾ£¬£¬Çé¿ö¸üΪÑϸñ£¬£¬´óÁ¿×Ô2010ÄêÆðµÄÊý¾Ý¿ÉÄÜÒѱ»ºÚ¿Í»ñÈ¡¡£Ó¢¹úµ±¾ÖÒÑÈ·ÈÏÊý¾Ýй¶£¬£¬²¢²Î¼Óµ÷²é¡£²¼¸æÖ¸³ö£¬£¬ºÚ¿Í×éÖ¯»ñÈ¡ÁË´óÁ¿Óë˾·¨ÔöÔ®ÉêÇëÈËÓйصÄÐÅÏ¢£¬£¬Ô̺¬ÁªÏµ·½Ê½¡¢µ®ÉúÈÕÆÚ¡¢¹úÃñÉí·ÝÖ¤ºÅÂë¡¢·¸×ïÊ·¡¢¾ÍÒµÇé¿ö¼°²ÆÕþϸ½ÚµÈ¡£Ó¢¹úµ±¾Ö½¨ÒéËùÓÐÉêÇëÈËά³Ö¾¯Ì裬£¬½÷·ÀÚ¿Æ­£¬£¬²¢ÔÚ¹²ÏíÃô¸ÐÐÅϢǰºËʵͨѶÄÚÈÝ¡£LAAÊ×ϯִÐйټò¡¤¹þ²©Ìضû¶Ô´Ë°µÊ¾Ç¸Ò⣬£¬²¢³Ðŵ½«¾¡¿ìÌṩ¸ü¶à×îÐÂÐÂÎÅ¡£Ä¿Ç°£¬£¬ËùÓÐLAAϵͳÔÚ¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC)µÄЭÖúÏÂÒѵõ½±£»£»¤£¬£¬ÔÚÏßÉêÇë·þÎñÁÙʱÏÂÏß¡£


https://www.bleepingcomputer.com/news/security/uk-legal-aid-agency-confirms-applicant-data-stolen-in-data-breach/


5. NRSÊý¾Ýй¶ÊÂÎñÓ°ÏìHarbinÕïËù³¬20Íò»¼Õß


5ÔÂ19ÈÕ£¬£¬×ôÖÎÑÇÖÝÒ½ÁƱ£½¡ÌṩÉÌHarbinÕïËù½üÈÕ֪ͨ³¬¹ý20ÍòÈË£¬£¬³ÆÆäСÎÒÐÅÏ¢ÔÚ2024Äê7ÔÂÕ®Îñ´ßÊÕ¹«Ë¾Nationwide Recovery Services£¨NRS£©µÄÊý¾Ýй¶ÊÂÎñÖб»µÁ¡£Õâ´ÎÊÂÎñÔ´ÓÚNRSÄÚ²¿ÏµÍ³³öÏÖ¿ÉÒɻ£¬£¬µ¼ÖÂÍøÂçÖжÏ¡£µÚÈý·½´ßÊÕ»ú¹¹µ÷²é·¢ÏÖ£¬£¬¹¥»÷ÕßÔÚ7ÔÂ5ÈÕÖÁ11ÈÕÆÚ¼ä½Ó¼ûÁËNRSÍøÂç²¢ÇÔÈ¡Á˲¿ÃÅÊý¾Ý¡£2025Äê2Ô£¬£¬Õ®Îñ´ßÊÕ·þÎñÌṩÉÌ£¨ACCSCIENT×Ó¹«Ë¾£©Í¨ÖªHarbinÕïËù£¬£¬²¿Ãű»µÁÊý¾ÝÉæ¼°Æä»¼Õߣ¬£¬²¢ÓÚ3ÔÂÌṩÁË¿ÉÄÜÊÜÓ°ÏìµÄСÎÒÃûµ¥¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£Ïպš¢½ðÈÚÕË»§¾ßÌåÐÅÏ¢¡¢µ£±£È˾ßÌåÐÅÏ¢¼°Ò½ÁÆÐÅÏ¢µÈ¡£HarbinÕïµØµã֪ͨÐÅÖгÆ£¬£¬NRS»ã±¨Î´·¢ÏÖÉí·Ý͵ÇÔ»òڲƭÐÐΪ֤¾Ý¡£¸ÃÕïËùÒÑÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«Êһ㱨£¬£¬ÓÐ210,140ÈËÊÜÓ°Ï죬£¬²¢ÎªËûÃÇÌṩ24¸öÔÂÃâ·ÑÉí·Ý¼à¿Ø·þÎñ¡£È»¶ø£¬£¬Ç±ÔÚÊÜÓ°ÏìÈËÊý¿ÉÄܸü¸ß£¬£¬ÒòÊÂÎñ»¹²¨¼°NRSÆäËû¿Í»§£¬£¬Ô̺¬×ôÖÎÑÇÖݺÍÌïÄÉÎ÷Öݶà¼ÒÒ½ÁÆ»ú¹¹£¬£¬ÇÒNRSÔÚÃÀ¹ú50¸öÖݾùÓÐÕ®Îñ´ßÊÕÅÆÕÕ¡£Ä¿Ç°£¬£¬NRSÉÐδ¹«¿ªÅû¶ÊÜÓ°Ïì¿Í»§¼°ÈËÊý£¬£¬Ò²Î´ÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£


https://www.securityweek.com/200000-harbin-clinic-patients-impacted-by-nrs-data-breach/


6. ÈðÊ¿µ±¾ÖÖÒ¸æDDoS¹¥»÷Å·Ö޸質´óÈüÓйØÍøÕ¾


5ÔÂ16ÈÕ£¬£¬ÈðÊ¿µ±¾Ö½üÈÕ·¢³öÖҸ棬£¬ÍøÂç·¸×ï·Ö×ÓÕë¶ÔÓëÅ·Ö޸質´óÈüÓйصÄÈðÊ¿¾³ÄÚ¶à¸öÍøÕ¾·¢ÆðÁ˶àÆðÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷¡£Ö»¹ÜÕâЩ¹¥»÷ÔÚÒâÁÏÖ®ÖУ¬£¬µ«²¢Î´¶ÔÅ·Ö޸質´óÈüµÄÕý³£ÔËÓªÔì³É×ÌÈÅ¡£ÈðÊ¿¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©Ïò¸÷×éÖ¯·¢³ö¾¯±¨£¬£¬Ö¸³ö¿ÉÄÜ»¹»áÓнøÒ»²½µÄ¹¥»÷£¬£¬ÆäÖ÷ÕÅÖØÒªÊÇÎüÒýýÌ幨ע¡£NCSC°µÊ¾£¬£¬ÔÚÅ·Ö޸質´óÈü¾öÈüǰ£¬£¬Óйػú¹¹ÒÑÆðÍ·Ôâ·ê´ËÀ๥»÷£¬£¬¹¥»÷Õßͨ¹ý·¢ËÍ´óÁ¿¶¨ÏòÒªÇóÊ¹ÍøÕ¾ºÍÀûÓ÷¨Ê½³¬ÔØ£¬£¬µ¼ÖÂÆäÎÞ·¨½Ó¼û»ò½ö²¿ÃſɽӼû¡£²»Í⣬£¬Õâ´Î¹¥»÷ÇкÏÔ¤ÆÚ£¬£¬Ä¿Ç°ÉÐδ¶ÔÅ·Ö޸質´óÈüÔì³ÉÄÚÈÝÐÔÓ°Ïì¡£ÈðÊ¿µ±¾ÖÔ¤¼Æ£¬£¬DDoS¹¥»÷½«³ÖÐøµ½Å·Ö޸質´óÈüʵÏÖ£¬£¬×ܾöÈü¶¨ÓÚ5ÔÂ17ÈÕ½øÐС£Å·Ö޸質´óÈüÊÇÒ»ÏîÄê¶È¹ú¼ÊÒôÀÖ½ÇÖ𣬣¬ÎüÒýÁËÀ´×ÔÅ·ÖÞºÍÆäËû¹ú¶ÈµÄ²ÎÈüÕß¡£NCSCÖ¸³ö£¬£¬DDoS¹¥»÷Êǹ¥»÷ÕßÎüÒý°ÑÎÈÁ¦µÄÒ»ÖÖ³£Óü¿Á©£¬£¬²¢ÒÑÏò¹Ø¼ü»ù´¡ÉèÊ©ÔËÓªÉ̺ͲμÓ×é֯ŷÖ޸質´óÈüµÄ×éÖ¯·¢³öÖҸ棬£¬ºôÓõËûÃDzÉÈ¡Êʵ±´ëÊ©·À±¸´ËÀ๥»÷¡£


https://cybernews.com/security/ddos-attacks-target-eurovision-ncsc-says/