¿¨µØÑÇϵͳÔâºÚ¿ÍÈëÇÖµ¼Ö¿ͻ§ÐÅϢй¶

°ä²¼¹¦·ò 2025-06-03

1. ¿¨µØÑÇϵͳÔâºÚ¿ÍÈëÇÖµ¼Ö¿ͻ§ÐÅϢй¶


6ÔÂ2ÈÕ£¬ÉݳÞʱÉÐÆ·ÅÆ¿¨µØÑǽüÈÕÏò¿Í»§·¢³öÖҸ棬³ÆÆäϵͳÔâºÚ¿ÍÈëÇÖ£¬µ¼Ö¿ͻ§Ð¡ÎÒÐÅϢй¶¡£¡£¡£ÔÚ֪ͨÐÅÖУ¬¿¨µØÑÇй©ºÚ¿Í»ñÈ¡ÁËÆäϵͳµÄһʱ½Ó¼ûȨÏÞ£¬²¢ÇÔÈ¡ÁËÓÐÏÞÊýÁ¿µÄ¿Í»§ÐÅÏ¢£¬Ô̺¬¿Í»§ÐÕÃû ¡¢¡¢µç×ÓÓʼþµØÖ·ºÍµØµã¹ú¶È£¬µ«Î´Éæ¼°ÃÜÂë ¡¢¡¢ÐÅÓþ¿¨ºÅ»òÒøÐоßÌåÐÅÏ¢µÈ¸üÃô¸ÐÊý¾Ý¡£¡£¡£¿£¿¨µØÑÇÇ¿µ÷ÒѽÚ֯סÎÊÌ⣬²¢¼ÓÇ¿ÁËϵͳºÍÊý¾ÝµÄ±£»£»¤£¬Í¬Ê±·î¸æ·¨Âɲ¿ÃÅ£¬ÕýÓëÍâ²¿ÍøÂ簲ȫ¹«Ë¾ºÏ×÷ÐÞ¸´·ì϶¡£¡£¡£Õâ´Î°²È«·ì϶²¢·Ç¸öÀý£¬´Óǰһ¸öÔÂÄÚ£¬ÆäËûʱÉÐÆ·ÅÆÒ²Åû¶ÁËÀàËÆ°²È«ÊÂÎñ¡£¡£¡£½ñÄê5Ô£¬µÏ°ÂÅû¶Êý¾Ýй¶ÊÂÎñ£¬ÍþвÐÐΪÕßÈëÇÖÆäϵͳ£¬ÇÔÈ¡Á˿ͻ§µÄÁªÏµ·½Ê½ ¡¢¡¢²É°ìº¹Çà¼Í¼ºÍÆ«ºÃÉèÖ㻣»Í¬ÑùÔÚÉϸöÔ£¬°¢µÏ´ï˹ÖÒ¸æ¿Í»§£¬ÆäÒ»¼ÒµÚÈý·½·þÎñÌṩÉÌÔâ·êÈëÇÖ£¬µ¼ÖÂÁªÏµÐÅϢй¶£¬µ«Î´»ñÈ¡¸¶¿îÏêÇé»òÕË»§Æ¾Ö¤£»£»ÉÏÖÜ£¬Î¬¶àÀûÑǵİÂÃØÒò³ÖÐø°²È«ÊÂÎñ¹Ø±ÕÁËÆäÍøÕ¾ºÍ²¿ÃÅÉ̵ê·þÎñ£¬²¢ÒÑÓëÍøÂ簲ȫר¼Ò·¢Õ¹µ÷²é¡£¡£¡£ÕâһϵÁÐÊÂÎñÅú×¢£¬Ê±ÉÐÆ·ÅÆÕýÃæ¶Ô×ÅÈÕÒæÑϸñµÄÍøÂ簲ȫÌôÕ½£¬Ðè¼ÓÇ¿°²È«·À»¤´ëÊ©£¬ÒÔ±£»£»¤¿Í»§ÐÅÏ¢²»±»Ð¹Â¶¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/


2. The North FaceÔâÆ¾Ö¤Ìî³ä¹¥»÷£¬¿Í»§ÐÅϢй¶


6ÔÂ2ÈÕ£¬»§Íâ·þ×°ÁãÊÛÉÌThe North FaceÖÒ¸æ¿Í»§£¬ÆäСÎÒÐÅÏ¢ÔÚ4ÔÂ·ÝµÄÆ¾Ö¤Ìî³ä¹¥»÷Öб»µÁ¡£¡£¡£The North Face×÷ΪÃÀ¹ú´óÐÍ»§Íâ·þ×°ºÍÉè±¸Æ·ÅÆ£¬ÄêÊÕÈ볬30ÒÚÃÀÔª£¬µç×ÓÉÌÎñÕ¼Æä×ÜÏúÊÛ¶îµÄ42%¡£¡£¡£Æ¾Ö¤Ìî³ä¹¥»÷ÖУ¬ÍþвÐÐΪÕßÀûÓÃÏÈǰÊý¾Ýй¶Öж³öµÄÓû§Ãû - ÃÜÂë¶Ô×Ô¶¯µÇ¼£¬ÊÔͼ»ñÈ¡Óû§ÕÊ»§Î´¾­ÊÚȨµÄ½Ó¼û£¬´Ë¼¼ÊõµÃÒæÓÚ¡°Æ¾Ö¤»ØÊÕ¡±£¬¼´Óû§¶àƽ̨ʹÓÃÒ»ÑùÓû§ÃûºÍÃÜÂ룬µ«ÈôÕË»§Êܶà³É·ÖÉí·ÝÑéÖ¤£¨MFA£©±£»£»¤£¬¹¥»÷»áʧ°Ü¡£¡£¡£The North FaceÒÑÆðÍ·ÏòÊÜÓ°Ïì¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬²¢Ïò·ðÃÉÌØÖÝ×ܼì²ì³¤·ÖÏíʾÀý֪ͨ£¬·î¸æÆäÍøÕ¾ÔÚ2025Äê4ÔÂ23ÈÕ·¢ÏÖÒì³£»£»î¶¯£¬¾­µ÷²é£¬µ±ÈÕ¹¥»÷Õß·¢ÆðÁËС¹æÄ£Æ¾Ö¤Ìî³ä¹¥»÷¡£¡£¡£ÒѶ³öµÄÊý¾ÝÔ̺¬ÐÕÃû ¡¢¡¢²É°ìº¹Çà¼Í¼ ¡¢¡¢ÊÕ¼þµØÖ· ¡¢¡¢µç×ÓÓʼþ ¡¢¡¢µ®ÉúÈÕÆÚ ¡¢¡¢µç»°ºÅÂëµÈ£¬²»Í⸶¿îÐÅϢδй¶£¬ÒòÍøÕ¾¸¶¿îÓÉÍⲿÌṩÉÌ´¦Öã¬The North Face½ö±£ÁôʵÏÖÁ÷³ÌËùÐèÁîÅÆ¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬The North Face¾ö¶¨²»ºÏËùÓÐÕË»§Ç¿ÖÆÖ´ÐÐMFA£¬µ¼ÖÂÆä¿Í»§ÈºËðʧ¾Þ´ó£¬ÕâÊÇ¸ÃÆ·ÅÆÍøÕ¾×Ô2020ÄêÒÔÀ´Ôâ·êµÄµÚËÄÆðƾ֤Ìî³äÊÂÎñ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/


3. SentinelOneÒòÈí¼þȱµãÖÂÆßСʱȫÇò·þÎñÖжÏ


6ÔÂ2ÈÕ£¬ÃÀ¹úÍøÂ簲ȫ¹«Ë¾SentinelOneÉÏÖÜĩй©£¬ÒòÈí¼þ·ì϶µ¼ÖÂÆäÖÜËijöÏÖ³¤´ïÆßСʱµÄ¡°È«Çò·þÎñÖжϡ±£¬Ó°ÏìÁ˶à¸öÃæÏò¿Í»§µÄ·þÎñ¡£¡£¡£SentinelOneÔÚÖÜËİ䲼µÄÌû×ÓÖÐÈÏ¿ÉÁËÕâ´ÎÖжÏ£¬²¢Ïò¿Í»§±£ÕÏÆäϵͳÈÔÊܱ£»£»¤£¬Ö»ÊÇÍйÜÏìÓ¦·þÎñÎÞ·¨»ñµÃ¿É¼ûÐÔ£¬ÍþвÊý¾Ý»ã±¨½öÑÓ³¤Î´ÃÔʧ£¬ÇÒ³õ²½·ÖÎöÅú×¢Õâ²»Êǰ²È«ÊÂÎñ¡£¡£¡£Á½Ììºó£¬¸Ã¹«Ë¾°ä²¼µ××ÓÔ­Òò·ÖÎö£¬È·ÈÏÊÂÎñ²¢·ÇÍøÂç¹¥»÷»ò°²È«·ì϶ËùÖ£¬¶øÊÇ»ù´¡ÉèÊ©½ÚÖÆÏµÍ³ÖеÄÈí¼þȱµãÒý·¢¡£¡£¡£¸Ãȱµã×Ô¶¯É¾³ýÁ˹ؼüÍøÂç·ÓɺÍDNS½âÎöÆ÷¹æ¶¨£¬µ¼Ö·þÎñ´óÃæ»ýÖжÏ¡£¡£¡£¾ßÌå¶øÑÔ£¬Òò´«³öµÄÔÆÖÎÀíÖ°ÄÜ´æÔÚȱµã£¬AWS Transit Gateway·ÓɱíµÄ±¸·Ý¸´Ô­Îª¿Õ£¬ÔÚËùÓбØÐëµÄÏνӻù´¡ÉèÊ©¸´Ô­ºó£¬·þÎñÖжÏÈÔ³ÖÐø¡£¡£¡£SentinelOneÚ¹ÊͳÆ£¬¹«Ë¾ÕýÔÚ½«³ö²úϵͳ¹ý¶Éµ½»ùÓÚ»ù´¡ÉèÊ©¼´´úÂ루IaC£©×¼Ôò¹¹½¨µÄÐÂÔÆ¼Ü¹¹£¬Õâ´Îɾ³ý²Ù×÷Óɼ´½«ÆúÓõĽÚÖÆÏµÍ³Òò´´½¨ÐÂÕË»§´¥·¢¡£¡£¡£¸Ã½ÚÖÆÏµÍ³ÅäÖñÈÁ¦Ö°ÄÜ´æÔÚÈí¼þȱµã£¬ÃýÎó¼ø±ð²î¾à²¢ÀûÓÃÁËËùνÕýÈ·µÄÅäÖÃ״̬£¬¸²¸ÇÁËÏÈÇ°ÍøÂçÉèÖ㬵¼Ö¸´Ô­ÁËÒ»¸ö¿ÕµÄ·Óɱí¡£¡£¡£Õâ´ÎÖжϻ¹ÒÔÖÁ¶Ô¹«Ë¾·þÎñµÄ·¨Ê½½Ó¼ûÖжÏ£¬Í³Ò»×ʲúÖÎÀí/¿â´æºÍÉí·Ý·þÎñ¹Ø±Õ£¬¿Í»§ÎÞ·¨²é¿´·ì϶»ò½Ó¼ûÉí·Ý½ÚÖÆÌ¨¡£¡£¡£´ËÍ⣬¿ÉÄÜ»¹Ó°ÏìÁËÀ´×Ô¸÷ÀàµÚÈý·½·þÎñµÄÊý¾ÝÌáÈ¡ÒÔ¼°Íйܼì²âºÍÏìÓ¦£¨MDR£©¾¯±¨¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/sentinelone-last-weeks-7-hour-outage-caused-by-software-flaw/


4. ÍøÂç¹¥»÷Ï®»÷ÁËCovenant HealthÔËÓªµÄÒ½Ôº


6ÔÂ2ÈÕ£¬2025Äê5ÔÂ26ÈÕÆð£¬·ÇͶ»úÐÔÉϵ۽ÌÇøÓòÒ½ÁƱ£½¡ÏµÍ³Covenant HealthÔËÓªµÄÈý¼ÒÒ½ÔºÔâ·êÍøÂç¹¥»÷£¬±»ÆÈ¹Ø±ÕËùÓÐϵͳÒÔ½ÚÖÆ°²È«ÊÂÎñ¡£¡£¡£Ê¥ÂêÀöÒ½ÁÆÏµÍ³³ÆÊ¥ÂêÀöÒ½ÔºÓöµ½Ò»Ê±ÏµÍ³¹ÊÕÏ£¬²¿Ãŵ绰ºÍÎĵµÏµÍ³ÊÜÓ°Ï죬ҽÁÆ·þÎñ³ÖÐøµ«ºòÕ﹦·ò¿ÉÄܵ¢¸é£»£»Ê¥Ô¼Éª·òÒ½Ôº°µÊ¾Òòϵͳһʱ¹ÊÕÏ£¬5ÔÂ27ÈÕµ÷ÕûÃÅÕﻯÑé·þÎñ£¬½öÔÚÔºÇøÄÚÊ¢¿ªÇÒÆ¾ÊµÌå¶©µ¥Ìṩ¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´Î¹¥»÷ÖÐÊý¾ÝÊDZ»µÁ»¹ÊÇÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Covenant HealthÀñƸÁ˶¥¼¶ÍøÂ簲ȫר¼ÒÀ´½ÚÖÆºÍµ÷²é¡£¡£¡£Ö»¹Ü²¿ÃÅϵͳºÍÃÅÕï³¢ÊÔÊÒÊÜÓ°Ï죬µ«·þÎñÈÔÔÚ³ÖÐø£¬ÖжÏˮƽ¼«Ð¡£¬Ðº±²¼Ê²¶ûÖݵÄʥԼɪ·òÒ½ÔººÍÃåÒòÖݵÄÁ½¼ÒÒ½Ôº¾ùÊܲ¨¼°£¬²»Íâ¸Ã»ú¹¹½¨Ò黼Õß°´Ê±¾ÍÕï¡£¡£¡£5ÔÂ26ÈÕ·¢ÏÖÎ¥¹æÐÐΪӰÏìÕû¸ö×éÖ¯ÏνÓÐԺ󣬳öÓÚÉóÉ÷˼¿¼£¬Ò½Ôº ¡¢¡¢ÕïËùºÍÒ½ÁÆ·þÎñÌṩÕßµÄËùº±¼û¾Ýϵͳ½Ó¼û±»Á¢¼´ÖÕ³¡¡£¡£¡£½ØÖÁ׫д±¾ÎÄʱ£¬ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¡£¡£


https://securityaffairs.com/178507/cyber-crime/a-cyberattack-hit-hospitals-operated-by-covenant-health.html


5. ºÚ¿ÍÕýÔÚÀûÓÃvBulletinÂÛ̳Èí¼þµÄÑÏÖØ·ì϶


5ÔÂ30ÈÕ£¬¿ªÔ´ÂÛ̳Èí¼þvBulletin±»·¢ÏÖ´æÔÚÁ½¸öÑÏÖØ·ì϶£¬±àºÅ±ðÀëΪCVE-2025-48827ºÍCVE-2025-48828£¬ÆÀ¼¶ÎªÑÏÖØ£¬CVSS v3ÆÀ·Ö±ðÀëΪ10.0ºÍ9.0¡£¡£¡£ÕâÁ½¸ö·ìÏ¶Éæ¼°Í¨¹ýÄ£°åÒýÇæÀÄÓ÷ì϶½øÐÐAPI²½ÖèŲÓúÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£µ±vBulletinÔÚPHP 8.1»ò¸ü¸ß°æ±¾ÉÏÔËÐÐʱ£¬°æ±¾5.0.0ÖÁ5.7.5ºÍ6.0.0ÖÁ6.0.3»áÊܵ½Ó°Ïì¡£¡£¡£ÕâЩ·ì϶¿ÉÄÜÔÚÈ¥ÄêÒÑÇÄÈ»ÐÞ¸´£¬µ«ÒòºÜ¶àÍøÕ¾Î´Éý¼¶£¬ÈÔ¶³öÔÚ·çÏÕ֮ϡ£¡£¡£2025Äê5ÔÂ23ÈÕ£¬°²È«×êÑÐÔ±Egidio RomanoÔÚÆä²©¿ÍÉϾßÌåÚ¹ÊÏçËÈôºÎÀûÓÃÕâЩ·ì϶£¬Ö¸³öÎÊÌâÔ´ÓÚvBulletin¶ÔPHP·´ÉäAPIµÄÀÄÓ㬸ÃAPIÔÚPHP 8.1ÖеÄÐÐΪ±ä¶¯ÔÊÐíŲÓÃÊܱ£»£»¤²½Öè¶øÎÞÐèÃ÷È·µ÷Õû¿É½Ó¼ûÐÔ¡£¡£¡£·ì϶Á´Ô̺¬Í¨¹ý¾«ÐÄÉè¼ÆµÄURLŲÓÃÊܱ£»£»¤²½Ö裬ÒÔ¼°ÀÄÓÃvBulletinÄ£°åÒýÇæÄÚµÄÄ£°åǰÌá¡£¡£¡£¹¥»÷Õß¿ÉÀûÓÃÒ×Êܹ¥»÷µÄ¡°replaceAdTemplate¡±²½Öè×¢Èë¶ñÒâÄ£°å´úÂ룬Èƹý¡°²»°²È«º¯Êý¡±¹ýÂËÆ÷£¬´Ó¶øÔڵײã·þÎñÆ÷ÉÏʵÏÖÆëȫԶ³Ì ¡¢¡¢Î´¾­Éí·ÝÑéÖ¤µÄ´úÂëÖ´ÐС£¡£¡£5ÔÂ26ÈÕ£¬°²È«×êÑÐÔ±Ryan Dewhurst»ã±¨³ÆÔÚÃÛ¹ÞÈÕÖ¾Öз¢ÏÖ¶Ô´æÔÚ·ì϶µÄ¶ËµãµÄÒªÇ󣬲¢×·×Ùµ½Ò»ÃûÀ´×Ô²¨À¼µÄ¹¥»÷ÕßÊÔͼ²¿ÊðPHPºóÃÅÖ´ÐÐϵͳºÅÁî¡£¡£¡£½¨ÌÖÂÛ̳ÖÎÀíÔ±¾¡¿ìÀûÓð²È«¸üлòÉý¼¶µ½×îа汾6.1.1ÒÔÔ¤·À·çÏÕ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-critical-flaw-in-vbulletin-forum-software/


6. Netbird³ÉÓã²æÊ½´¹µöй¤¾ß£¬Õë¶Ô¶àµØ²ÆÕþ¸ß¹Ü


6ÔÂ2ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢³öÖҸ棬һ³¡ÀûÓúϷ¨Ô¶³Ì½Ó¼û¹¤¾ßNetbirdµÄÐÂÓã²æÊ½´¹µö¹¥»÷»î¶¯ÕýÔÚ½øÐУ¬Ö¸±êÕë¶ÔÅ·ÖÞ ¡¢¡¢·ÇÖÞ ¡¢¡¢¼ÓÄÃ´ó ¡¢¡¢Öж«ºÍÄÏÑǵØÓòÒøÐÐ ¡¢¡¢ÄÜÔ´ ¡¢¡¢±£ÏÕºÍͶ×ʹ«Ë¾µÄ²ÆÕþ¸ß¹Ü¡£¡£¡£¸Ã»î¶¯ÓÉTrellix¹«Ë¾ÓÚ2025Äê5ÔÂÖÐÑ®³õ´Î·¢ÏÖ£¬Ä¿Ç°ÉÐδ¹éÒòÓÚÈκÎÒÑÖªÍþвÐÐΪÕß¡£¡£¡£Õâ´Î¹¥»÷ÒÔÒ»·â¼ÙÒâRothschild&CoÕÐÆ¸ÈËÔ±µÄ´¹µöÓʼþΪ³õ²½£¬Í¨¹ýαÔìµÄPDF¸½¼þÁ´½ÓÓÕʹÊܺ¦Õßµã»÷£¬½ø¶ø±»Öض¨ÏòÖÁÍйÜÔÚFirebaseÀûÓÃÉϵÄURL¡£¡£¡£¹¥»÷ÕßÀûÓüÓÃܵÄÖØ¶¨ÏòURLºÍÑéÖ¤Âë¹Ø¿¨À´Èƹý·ÀÓùϵͳ£¬×îÖÕÊèµ¼Êܺ¦ÕßÏÂÔØÔ̺¬¶ñÒâVBScriptµÄZIPѹËõ°ü¡£¡£¡£¸ÃVBScriptÕÆ¹Ü¼ìË÷²¢Ö´ÐÐÏÂÒ»½×¶ÎVBScript£¬ºóÕß»á½øÒ»²½»ñÈ¡ÓÐÐ§ÔØºÉ£¬ÌáÈ¡²¢×°ÖÃNetBirdºÍOpenSSHÁ½¸ö·¨Ê½£¬´´½¨°µ²ØÕË»§ ¡¢¡¢ÆôÓÃÔ¶³Ì×ÀÃæ½Ó¼û£¬²¢Í¨¹ýÉèÖôòË㹤×÷ʹNetBirdÔÚÊÜϰȾϵͳÉÏÓÆ¾Ã»¯ÔËÐУ¬Í¬Ê±É¾³ý×ÀÃæ¿ì½Ý·½Ê½ÒÔ¸²¸ÇÈëÇÖÐÐΪ¡£¡£¡£´ËÍ⣬Trellix»¹·¢ÏÖÒ»¸öÒÑ»îÔ¾½üÒ»ÄêµÄÖØ¶¨ÏòURLÌṩһÑùµÄVBScriptÓÐÐ§ÔØºÉ£¬ÕâÅú×¢¸Ã¹¥»÷»î¶¯¿ÉÄÜÒѳÖÐøÒ»¶Î¹¦·ò¡£¡£¡£


https://thehackernews.com/2025/06/fake-recruiter-emails-target-cfos-using.html