¿ÆÌصÏÍߺ½¿ÕÔâINCÀÕË÷Èí¼þ¹¥»÷ÖÂÊý¾Ýй¶

°ä²¼¹¦·ò 2026-02-27

1. ¿ÆÌصÏÍߺ½¿ÕÔâINCÀÕË÷Èí¼þ¹¥»÷ÖÂÊý¾Ýй¶


2ÔÂ24ÈÕ£¬·þÎñÓÚÎ÷·Ç¹ú¶È¿ÆÌصÏÍßµÄÖØÒªº½¿Õ¹«Ë¾¿ÆÌصÏÍߺ½¿Õ¹«Ë¾Ôâ·êÍøÂç¹¥»÷£¬±»ÆÈÆô¶¯ÒµÎñÂ½ÐøÐÔ´òËã¡£¡£¡£¾Ý¹«Ë¾ÉêÃ÷֤ʵ£¬ºÚ¿ÍÓÚ2ÔÂ8ÈÕÈëÇÖÆäϵͳ£¬µ¼ÖÂÐÅϢϵͳ²¿ÃÅÄÚÈÝÊÜÓ°Ï죬¼¼ÊõÍŶӴ¹Î£Ð­Öúº½°à¼°ÆäËûÔËÓªÊØ»¤¡£¡£¡£Õâ´ÎÊÂÎñÖУ¬INCÀÕË÷Èí¼þÍÅ»ïÐû³ÆÇÔÈ¡ÁË208GBÊý¾Ý£¬Éæ¼°·þÎñÌṩÉÌ¡¢¡¢¡¢³Ë¿Í¼°Ô±¹¤Ãô¸ÐÐÅÏ¢£¬²¢ÍþвÔÚ2ÔÂ24ÈÕǰ֧¸¶Î´¹«¿ªÊê½ð£¬²»È»½«Ð¹Â¶Êý¾Ý¡£¡£¡£¿£¿£¿ÆÌصÏÍߺ½¿Õ¹«Ë¾°µÊ¾£¬Òѽ«ÊÂÎñ֪ͨ·¨¹ú¹ú¶ÈÐÅϢϵͳ°²È«¾Ö£¨ANSSI£©ºÍ¿ÆÌصÏÍßµçÐżà¹Ü¾Ö£¨ARTCI£©£¬²¢ÕÙ¼¯¿ÆÌصÏÍßÍÆËã»úÓ¦¼±ÏìӦС×飨CI-CERT£©¼°¹ú¼Êר¼Ò·¢Õ¹µ÷²é£¬ÒÔÈ·¶¨Êý¾Ýй¶ÁìÓò¡£¡£¡£¹«Ë¾Ç¿µ÷£¬Ö»¹ÜϵͳÊÜ´´£¬µ«º½°à´òËãά³Ö²»±ä£¬½«³ÖÐøÑϸñ×ñÊØ¹ú¼Ê°²È«³ß¶ÈÔËÐУ¬²¢¾¡ËùÓÐÖÂÁ¦¼õÇáÊÂÎñºó¹û¡£¡£¡£


https://therecord.media/air-cote-divoire-confirms-cyberattack


2. OptimizelyÔâÓïÒôÍøÂç´¹µö¹¥»÷ÖÂÊý¾Ýй¶


2ÔÂ23ÈÕ£¬×ܲ¿Î»ÓÚŦԼµÄ¸æ°×¼¼Êõ¹«Ë¾Optimizely½üÈÕÔâ·êÑÏÖØÊý¾Ýй¶ÊÂÎñ£¬ÍþвÐÐΪÕßͨ¹ý¸´ÔÓµÄÓïÒôÍøÂç´¹µö£¨vishing£©¹¥»÷ÈëÇÖÆä²¿ÃÅϵͳ£¬ÇÔÈ¡ÁË¡°¸ù»ùÒµÎñÁªÏµÐÅÏ¢¡±¡£¡£¡£OptimizelyÔÚÈ«ÇòÕ¼ÓÐ21¸ö´¦Ê´¦¡¢¡¢¡¢½ü1500ÃûÔ±¹¤£¬·þÎñ³¬¹ý10,000¼ÒÆóÒµ¿Í»§£¬Ô̺¬H&M¡¢¡¢¡¢PayPal¡¢¡¢¡¢Zoom¡¢¡¢¡¢·áÌï¡¢¡¢¡¢ÎÖ´ï·á¡¢¡¢¡¢¿ÇÅÆ¡¢¡¢¡¢SalesforceºÍÄͿ˵ȳÛÃûÆ·ÅÆ¡£¡£¡£¾ÝOptimizely·¢Ë͸øÊÜÓ°Ïì¿Í»§µÄÎ¥¹æÍ¨ÖªÐÅÏÔʾ£¬2ÔÂ11ÈÕ£¬¹¥»÷ÕßÁªÏµ¸Ã¹«Ë¾²¢Ðû³ÆÒÑ»ñµÃϵͳ½Ó¼ûȨÏÞ¡£¡£¡£¹«Ë¾ÉêÃ÷Ç¿µ÷£¬¹¥»÷ÕßËä³É¹¦ÈëÇÖ²¿ÃÅÄÚ²¿ÒµÎñϵͳ¡¢¡¢¡¢CRM¼Í¼¼°ºó¶ÜÔËÓªÎĵµ£¬µ«Î´ÄÜÌáÉýȨÏÞ¡¢¡¢¡¢×°ÖöñÒâÈí¼þ»ò´´½¨ºóÃÅ£¬ÇÒÎÞÖ¤¾ÝÅú×¢Æä½Ó¼ûÁËÃô¸Ð¿Í»§Êý¾Ý»òСÎÒÐÅÏ¢¡£¡£¡£Optimizely°µÊ¾£¬ÒµÎñÔËӪδÊÜ×ÌÈÅ£¬µ«ÖÒ¸æ¿Í»§¾¯ÌèÀûÓñ»µÁÊý¾ÝÌáÒéµÄ½øÒ»²½ÍøÂç´¹µö¹¥»÷¡£¡£¡£Õâ´ÎÊÂÎñ±»Ö¸ÓëShinyHuntersÀÕË÷×éÖ¯´æÔÚ¹ØÁª¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/


3. ³¯ÏÊLazarusÓÃMedusa¹¥»÷ÃÀÒ½ÁƼ°·ÇͶ»ú»ú¹¹


2ÔÂ24ÈÕ£¬SymantecÓëCarbon BlackÍþвÁÔÈËÍŶÓ×îл㱨ÏÔʾ£¬Ó볯ÏʹØÁªµÄLazarus Group£¨±ðºÅDiamond Sleet¡¢¡¢¡¢Pompilus£©ÔÚÖж«Ò»¼Òδ¾ßÃû»ú¹¹¹¥»÷Öв¿ÊðÁËMedusaÀÕË÷Èí¼þ£¬²¢ÊÔͼ¹¥»÷ÃÀ¹úÒ½ÁÆ»ú¹¹Î´Ëì¡£¡£¡£MedusaÓÉÍøÂç·¸×ï×éÖ¯SpearwingÓÚ2023ÄêÍÆ³ö£¬×÷ΪÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©ÏîÄ¿£¬ÒÑÐû³ÆÖ´Ðг¬366Æð¹¥»÷¡£¡£¡£·ÖÎöMedusaÊý¾Ýй¶վµã·¢ÏÖ£¬2025Äê11Ô³õÒÔÀ´£¬ÃÀ¹úËļÒÒ½ÁƼ°·ÇͶ»ú»ú¹¹ÔâÏ®£¬Ô̺¬ÉúÀí½¡¿µÁìÓò·ÇͶ»ú»ú¹¹ºÍ×Ô±ÕÖ¢¶ùͯ½ÌÓý»ú¹¹£¬¾ùÔÈÀÕË÷½ð¶î´ï26ÍòÃÀÔª¡£¡£¡£Õâ´Î¹¥»÷±ê־ȡLazarusÕ½Êõת±ä¡£¡£¡£¸Ã×éÖ¯´Óǰ³£Ê¹Óö¨ÖÆÀÕË÷Èí¼þ£¨ÈçSHATTEREDGLASS¡¢¡¢¡¢Maui¡¢¡¢¡¢H0lyGh0st£©£¬µ«2024Äê10ÔÂÆðתÏòÏֳɼÓÃܹ¤¾ß£¬ÈçMedusaºÍQilin¡£¡£¡£¹¥»÷ÖУ¬LazarusʹÓÃÁ˶àÖÖ¹¤¾ß£º£º¶¨ÖÆ´úÀí¹¤¾ßRP_Proxy¡¢¡¢¡¢Æ¾Ö¤ÇÔÈ¡·¨Ê½Mimikatz¡¢¡¢¡¢×¨ÓúóÃÅComebacker¡¢¡¢¡¢ÐÅÏ¢ÇÔÈ¡¹¤¾ßInfoHook¡¢¡¢¡¢Ô¶³Ì½Ó¼ûľÂíBLINDINGCAN£¨±ðºÅAIRDRY¡¢¡¢¡¢ZetaNile£©¼°ChromeÃÜÂëÌáÈ¡¹¤¾ßChromeStealer¡£¡£¡£


https://thehackernews.com/2026/02/lazarus-group-uses-medusa-ransomware-in.html


4. CarGurusÔâShinyHuntersй¶1200ÍòÕË»§Êý¾Ý


2ÔÂ25ÈÕ£¬ÃÀ¹úÊý×ÖÆû³µÂòÂôƽ̨CarGurusÔâ·ê´ó¹æÄ£Êý¾Ýй¶£¬³¬1240ÍòÕË»§Ãô¸ÐÐÅÏ¢±»ShinyHunters×é֯й¶¡£¡£¡£¸Ãƽ̨×÷ΪÏßÉϹº³µÁìÓòÖ÷Ìâ²Î¼ÓÕߣ¬Ã¿ÔÂÎüÒýÔ¼4000Íò·Ã¿Í£¬ÒµÎñ¸²¸ÇÃÀ¹ú¡¢¡¢¡¢¼ÓÄôóºÍÓ¢¹ú£¬Ìṩ³µÁ¾¶¨¼Û¡¢¡¢¡¢¾­ÏúÉÌÆÀ¼Û¼°º¹Çà¼Í¼µÈ¹¤¾ß¡£¡£¡£Õâ´Îй¶ԴÓÚÀÕË÷δË죬й¶Êý¾ÝÔ̺¬µç×ÓÓʼþ¡¢¡¢¡¢ÕË»§ID¡¢¡¢¡¢½ðÈÚÉêÇëÏêÇé¡¢¡¢¡¢¾­ÏúÉÌÐÅÏ¢¡¢¡¢¡¢ÐÕÃû¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢µØÖ·¡¢¡¢¡¢IPµØÖ·¼°Æû³µ½ðÈÚÉêÇëÁ˾Ö£¬ÎļþѹËõºó´ï6.1GB£¬Òѱ»Êý¾Ýй¶¼à¿Ø·þÎñHaveIBeenPwnedÊÕ¼¡£¡£¡£Ð¹Â¶ÊÂÎñ´øÀ´¶àÖØ·çÏÕ£º£ºÐÕÃû¡¢¡¢¡¢ÓÊÏä¡¢¡¢¡¢µç»°µÈСÎÒÐÅÏ¢¿É±»ÓÃÓڸ߷ÂÕæÍøÂç´¹µöºÍÉç»á¹¤³Ì¹¥»÷£»½ðÈÚÉêÇëÊý¾Ýй¶ΪÉí·Ý͵ÇԺͽðÈÚÚ¿Æ­Ìṩ·½±ã£»ÕË»§ÐÅϢй¶¼Ó¾çÕË»§µÁÓ÷çÏÕ£¬ÓÈÆäÊÇÃÜÂ븴Óó¡¾°£»ÎïÀíµØÖ·ºÍIPÊý¾Ýй¶Òý·¢ÒþÖÔÓÇÓô£¬¿ÉÄÜÕÐÖ¶¨ÏòÓªÏú¡¢¡¢¡¢¸ú×ÙɧÈŵȶñÒâÐÐΪ¡£¡£¡£ShinyHunters½üÆÚƵÈÔÕë¶Ô´óÐÍÆóÒµ·¢Æð¹¥»÷£¬ÍÅ»ïÖØÒªÀûÓÃÉç»á¹¤³Ì¼¿Á©£¬³ö¸ñÊÇÓïÒô´¹µö£¨vishing£©£¬ÇÔȡƾ֤²¢½Ó¼ûSalesforce¡¢¡¢¡¢Okta¡¢¡¢¡¢Microsoft 365µÈSaaSƽ̨¡£¡£¡£


https://securityaffairs.com/188491/cyber-crime/shinyhunters-cyberattack-on-cargurus-impacts-12-4-million-users.html


5. ÓÀÀû¶È¼Ù´åÔâShinyHuntersÊý¾Ýй¶


2ÔÂ25ÈÕ£¬ÓÀÀû¶È¼Ù´å֤ʵÆä·þÎñÆ÷ÔâÍøÂç·¸×ïÍÅ»ïShinyHunters¹¥»÷£¬µ¼ÖÂÔ±¹¤Ãô¸ÐÊý¾Ý±»µÁ¡£¡£¡£º£ºÚ¿ÍÐû³ÆÒÑɾ³ýÊý¾Ý£¬µ«ÓÀÀûÎÞ·¨ÑéÖ¤Õâһ˵·¨£¬Òý·¢¶ÔÀÕË÷½»Éæ¼°Êê½ðÖ§¸¶µÄ²Â²â¡£¡£¡£Õâ´ÎÊÂÎñÖУ¬ShinyHuntersÓÚ2ÔÂ20ÈÕÐû³Æ¹¥»÷£¬²¢Åû¶ÀûÓÃOracle PeopleSoft·ì϶¼°Ô±¹¤Æ¾Ö¤ÔÚ2025Äê9ÔÂÈëÇÖϵͳ£¬Ð¹Â¶Êý¾ÝÔ̺¬Ô±¹¤È«Ãû¡¢¡¢¡¢ÓÊÏä¡¢¡¢¡¢µç»°¡¢¡¢¡¢Ö°Î»¡¢¡¢¡¢Ð½Ë®¡¢¡¢¡¢ÈëÖ°ÈÕÆÚ¡¢¡¢¡¢µ®ÉúÈÕÆÚµÈСÎÒÐÅÏ¢¡£¡£¡£ÓÀÀû¶È¼Ù´å½²»°È˰µÊ¾£¬ÊÂÎñ²úÉúºóÁ¢¼´Æô¶¯ÏìÓ¦ºÍ̸£¬½áºÏÍâ²¿ÍøÂ簲ȫר¼Ò·¢Õ¹µ÷²é£¬²¢Ç¿µ÷¡°Êý¾Ý°²ÂúÊÇÊ×Òª¹¤×÷¡±¡£¡£¡£¹«Ë¾ÏòÔ±¹¤ÌṩÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý±£»¤·þÎñ£¬µ«»Ø¾øÆÀÂÛÊÇ·ñÖ§¸¶Êê½ð¡£¡£¡£Huntress°²È«×¨¼ÒDray AghaÖ¸³ö£¬ºÚ¿Í¡°É¾³ýÊý¾Ý¡±µÄ³Ðŵͨ³£ÊÇÀÕË÷½»ÉæÊµÏֵıêÖ¾£¬µ«²»³ÉÐÅ£¬Êý¾Ý¸±±¾¿ÉÄܱ»±£Áô¡¢¡¢¡¢¹²Ïí»òÏúÊÛ£¬ÎÞ·¨Í¨¹ý¼¼Êõ¼¿Á©ÑéÖ¤³¹µ×ɾ³ý¡£¡£¡£


https://www.theregister.com/2026/02/25/wynn_resorts_shinyhunters/


6. UFP TechnologiesÔâÍøÂç¹¥»÷ÖÂÎļþ±»µÁ¼°ÏµÍ³ÖжÏ


2ÔÂ25ÈÕ£¬ÂíÈøÖîÈûÖÝÒ½ÁÆÆ÷ÐµÖÆ×÷ÉÌUFP TechnologiesÓÚ2026Äê2ÔÂ14ÈÕ¼ì²âµ½ITϵͳÈëÇÖÊÂÎñ£¬ÖܶþÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»8-KÎļþÅû¶ϸ½Ú¡£¡£¡£×÷ΪרһÓÚÒ½ÁÆÆ÷е¡¢¡¢¡¢ÎÞ¾ú°ü×°¼°Ò½ÁƱ£½¡×é¼þµÄºÏÍ¬ÖÆ×÷ÉÌ£¬¸Ã¹«Ë¾Õâ´ÎÊÂÎñÉæ¼°Îļþ±»µÁ¡¢¡¢¡¢²¿ÃÅITϵͳÖжÏ£¬²¢Ó°Ïì¼Æ·Ñ¼°¿Í»§ËÍ»õ±êÇ©ÌìÉúϵͳ¡£¡£¡£µ÷²éÏÔʾ£¬¹¥»÷ÕßÇÔÈ¡ÁËÎļþ£¬µ«¾ßÌåй¶ÐÅÏ¢ÀàÐͼ°ÊÇ·ñÔ̺¬Ð¡ÎÒÐÅÏ¢ÈÔÔÚÈ·ÈÏÖС£¡£¡£UFPÇ¿µ÷£¬¹«Ë¾ÒÑÆô¶¯Ó¦¼±Ô¤°¸²¢ÒÀ¸½Êý¾Ý±¸·Ýϵͳ£¬×ÔÊÂÎñ·¢ÏÖÒÔÀ´£¬ÔËÓªÔÚËùÓÐÄÚÈÝÐÔ·½Ãæ¾ùÒѸ´Ô­£¬ÇÒÔ¤¼Æ´ó²¿ÃŽÚÖÆÓëµ÷²éÓöȽ«Óɱ£Ïճе££¬Î´¶Ô²ÆÕþÔì³ÉÄÚÈÝÐÔÓ°Ïì¡£¡£¡£Ö»¹ÜÊÂÎñÌØµãÇкÏÀÕË÷Èí¼þ¹¥»÷ģʽ£¨Êý¾ÝÇÔÈ¡ÓëÎļþ¼ÓÃܶñÒâÈí¼þ²¿Ê𣩣¬µ«½ØÖÁĿǰÉÐÎÞÒÑÖªÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´ËÕÆ¹Ü¡£¡£¡£¹«Ë¾°µÊ¾£¬Õâ´ÎÊÂÎñδµ¼Ö³־ÃÔËÓªÖжÏ£¬Ó¦¼±´ëÊ©ÓÐЧ±£ÏÕÁËÒµÎñÂ½ÐøÐÔ¡£¡£¡£


https://www.securityweek.com/medical-device-maker-ufp-technologies-hit-by-cyberattack/