KelpDAOÔâ2.9ÒÚÃÀÔª¼ÓÃÜÇ®±Ò͵ÇÔ
°ä²¼¹¦·ò 2026-04-211. KelpDAOÔâ2.9ÒÚÃÀÔª¼ÓÃÜÇ®±Ò͵ÇÔ
4ÔÂ20ÈÕ£¬£¬DeFiÏîÄ¿KelpDAOÔâ·êÁ˼ÛÖµÔ¼2.9ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò͵ÇÔ°¸£¬£¬¾ÝÐÅÊdz¯Ïʹú¶ÈÖ§³ÖµÄºÚ¿ÍËùΪ¡£Õâ´Î¹¥»÷»¹Ó°ÏìÁËCompound¡¢¡¢¡¢EulerºÍAaveµÈ½è´ûºÍ̸£¬£¬ÆäÖÐAaveÒѰ䷢¶³½á²¢×èֹʹÓÃrsETH×÷ΪµÖѺƷµÄдæ¿î»ò¸æ´û¡£4ÔÂ18ÈÕ£¬£¬KelpDAO°ä·¢¼ì²âµ½Éæ¼°rsETHµÄ¡°¿ÉÒÉ¿çÁ´»î¶¯¡±£¬£¬Ëæ¼´ÔÝÍ£ÁËÒÔÌ«·»Ö÷ÍøºÍL2ÉϵÄrsETHºÏÔ¼£¬£¬²¢ÔÚLayerZero¡¢¡¢¡¢UnichainµÈºÏ×÷ͬ°éµÄÐÖúÏ·¢Õ¹µ÷²é¡£Çø¿éÁ´»î¶¯ÏÔʾ£¬£¬Ô¼ÓÐ116,500¸örsETH±»µÁ£¬£¬¼ÛÖµÔ¼2.93ÒÚÃÀÔª£¬£¬Ëæºó×ʽðͨ¹ýTornado Cash½øÐÐ×ªÒÆÒÔ¸²¸Ç×Ù¼£¡£¡£Æ¾¾ÝLayerZero·ÖÏíµÄϸ½Ú£¬£¬Õâ´Î¹¥»÷µÄÖ¸±êÊÇÓÃÓÚÑéÖ¤rsETH¿çÁ´ÐÂÎŵÄÑéÖ¤²ã£¨DVN£©¡£¹¥»÷ÕßÈëÇÖÁËÑéÖ¤Æ÷ʹÓõÄһЩRPC½Úµã£¬£¬ÏòÆäÌṩαÔìµÄÇø¿éÁ´Êý¾Ý£¬£¬Í¬Ê±¶Ô½¡¿µµÄRPC½ÚµãÌáÒéDDoS¹¥»÷£¬£¬ÆÈʹϵͳÒÀÀµÓÚ±»¡°´«È¾¡±µÄ½Úµã¡£ÕâʹµÃαÔìµÄ¿çÁ´ÐÂÎű»½ÓÊÜΪÓÐЧÐÂÎÅ£¬£¬ÏµÍ³È·ÈÏÁËÏÖʵÉÏ´ÓδÔÚÁ´ÉϲúÉúµÄÂòÂô£¬£¬²¢ÔÊÐíÔÚδ¾ÊÚȨµÄÇé¿öÏÂ×ªÒÆrsETH¡£
https://www.bleepingcomputer.com/news/security/kelpdao-suffers-290-million-heist-tied-to-lazarus-hackers/
2. ·¨¹úANTSƽ̨ÔâÍøÂç¹¥»÷£¬£¬½ü1900ÍòÌõСÎÒÊý¾Ýй¶
4ÔÂ20ÈÕ£¬£¬·¨¹úµÄANTSƽ̨½üÆÚÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬£¬¸ÃÆ½Ì¨ÕÆ¹Ü´¦Öû¤ÕÕ¡¢¡¢¡¢Éí·ÝÖ¤¡¢¡¢¡¢¾ÓÁôÐí¿ÉºÍ¼ÝÊ»ÅÆÕÕµÄÉêÇë¡£µ±¾ÖÓÚ4ÔÂ15ÈÕ·¢ÏÖÁËÕâÆð°²È«ÊÂÎñ£¬£¬²¢ÖÒ¸æ³Æ£¬£¬Õâ´Î·ì϶¿ÉÄܵ¼ÖÂСÎÒºÍרҵÈËÊ¿µÄСÎÒÊý¾Ýй¶¡£ÄÚÕþ²¿ÒÑÈ·ÈÏÕâ´Î°²È«·ì϶£¬£¬²¢ÕýÔÚµ÷²é·ì϶ÁìÓò¼°¶ÔÊÜÓ°ÏìÓû§µÄÓ°Ïì¡£ANTS°ä²¼µÄ²¼¸æÏÔʾ£¬£¬Õâ´Î°²È«·ì϶¿ÉÄÜй¶ÁËÓû§µÄµÇ¼ID¡¢¡¢¡¢ÐÕÃû¡¢¡¢¡¢ÓÊÏä¡¢¡¢¡¢µ®ÉúÈÕÆÚºÍÕË»§IDµÈ¾ßÌåÐÅÏ¢¡£ÔÚijЩÇé¿öÏ£¬£¬Ð¹Â¶µÄÐÅÏ¢»¹Ô̺¬µØÖ·¡¢¡¢¡¢µ®ÉúµØ»òµç»°ºÅÂë¡£Óйز¿ÃÅÕýÔÚ֪ͨÊÜÓ°ÏìµÄÓû§¡£Æ¾¾ÝÊý¾Ýй¶֪ͨ£¬£¬Ð¹Â¶µÄÊý¾Ý²»Ô̺¬ÒÑÉÏ´«µÄÎļþ£¬£¬Ò²ÎÞ·¨Ö±½Ó½Ó¼ûÓû§ÕË»§¡£µ±¾ÖÒѽ«´ËÊ»㱨¸ø·¨¹úÊý¾Ý±£»£»¤¾Ö£¨CNIL£©£¬£¬Í¨ÖªÁ˼ì²ì¹Ù£¬£¬²¢Ïò¹ú¶ÈÍøÂ簲ȫ»ú¹¹·¢³ö¾¯±¨¡£Óë´Ëͬʱ£¬£¬Ò»ÃûÍþвÐÐΪÕßÐû³ÆÕýÔÚÏúÊÛ´ÓANTSÇÔÈ¡µÄ´óÐÍÊý¾Ý¼¯£¬£¬ÆäÖÐÔ̺¬Ô¼1800ÍòÖÁ1900Íò±Ê¼Í¼£¬£¬Ô̺¬ÐÕÃû¡¢¡¢¡¢µç×ÓÓʼþ¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢µ®ÉúÏêÇé¡¢¡¢¡¢µØÖ·ºÍÕË»§ÔªÊý¾Ý¡£
https://securityaffairs.com/191069/data-breach/frances-ants-id-system-website-hit-by-cyberattack-possible-data-breach.html
3. GentlemenÀÕË÷Èí¼þ½èSystemBCϰȾ³¬1570¼ÒÆóÒµÖ÷»ú
4ÔÂ20ÈÕ£¬£¬ÔÚ¶Ôһ·ÓÉÍÅ»ï³ÉÔ±Ö´ÐеÄGentlemenÀÕË÷Èí¼þ¹¥»÷½øÐе÷²éºó£¬£¬Check Point×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÓɳ¬¹ý1570̨Ö÷»ú×é³ÉµÄSystemBC´úÀí¶ñÒâÈí¼þ½©Ê¬ÍøÂ磬£¬ÕâЩÖ÷»ú¾ÝÐÅÖØÒªÎªÆóÒµÊܺ¦Õß¡£GentlemenÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©ÔËӪԼĪÔÚ2025ÄêÖÐÆÚ³öÏÖ£¬£¬ÌṩÁ˿ɼÓÃÜWindows¡¢¡¢¡¢Linux¡¢¡¢¡¢NASºÍBSDϵͳµÄGo˵»°¼ÓÃÜÆ÷£¬£¬ÒÔ¼°Õë¶ÔESXiÐé¹¹»úÖÎÀí·¨Ê½µÄC˵»°¼ÓÃÜÆ÷¡£È¥Äê12Ô£¬£¬¸ÃÀÕË÷Èí¼þ¹¥»÷ÁËÂÞÂíÄáÑÇ×î´óµÄÄÜÔ´¹©¸øÉÌÖ®Ò»°Â¶ûÌØÄáÑÇÄÜÔ´×ÛºÏÌå¡£Ö»¹Ü¸ÃRaaSÐж¯¹«¿ªÐû³ÆÒÑÔì³ÉÔ¼320ÃûÊܺ¦Õߣ¬£¬ÆäÖдó²¿ÃŹ¥»÷²úÉúÔÚ½ñÄ꣬£¬µ«×êÑÐÈËÔ±·¢Ï֯乨Áª×éÖ¯ÕýÔÚѸËÙÀ©´ó¹¥»÷¹¤¾ß°üºÍ»ù´¡ÉèÊ©¡£ÔÚÒ»´ÎÊÂÎñÏìÓ¦¹ý³ÌÖУ¬£¬×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þÐж¯µÄÒ»¸ö¹ØÁª·½ÊÔͼ²¿ÊðSystemBC´úÀí¶ñÒâÈí¼þÒÔ½øÐÐÒñ±ÎµÄÓÐÐ§ÔØºÉͶ·Å¡£SystemBCÖÁÉÙ´Ó2019Äê¾ÍÒÑ´æÔÚ£¬£¬ÖØÒªÓÃÓÚSOCKS5ËíµÀ´«Ê䣬£¬ÒòÆä¿ÉÄÜ´«µÝ¶ñÒâÔØºÉ¶ø±»ÀÕË÷Èí¼þÍÅ»ï¿í·ºÑ¡È¡¡£¾ÝCheck Point¹Û²ì£¬£¬ÓëGentlemen²¿ÊðSystemBCÓйصĴóÎÞÊýÊܺ¦ÕßλÓÚÃÀ¹ú¡¢¡¢¡¢Ó¢¹ú¡¢¡¢¡¢µÂ¹ú¡¢¡¢¡¢°Ä´óÀûÑǺÍÂÞÂíÄáÑÇ¡£
https://www.bleepingcomputer.com/news/security/the-gentlemen-ransomware-now-uses-systembc-for-bot-powered-attacks/
4. ¾«¹¤ÃÀ¹ú¹ÙÍøÔâ´Û¸Ä£¬£¬¹¥»÷ÕßË÷ÒªÊê½ð
4ÔÂ20ÈÕ£¬£¬ÉÏÖÜÄ©£¬£¬¾«¹¤ÃÀ¹ú¹ÙÍøÔâµ½´Û¸Ä£¬£¬Æä¡°ÐÂÎŰ䲼Ìü¡±Ò³Ãæ±»´úÌæÎª¹¥»÷Õß°ä²¼µÄÐÂÎÅ£¬£¬Ðû³ÆÒÑÇÔÈ¡¸Ã¹«Ë¾µÄShopify¿Í»§Êý¾Ý¿â£¬£¬²¢Íþв³Æ³ý·ÇÖ§¸¶Êê½ð£¬£¬²»È»½«¹«¿ªÐ¹Â¶ÕâЩÊý¾Ý¡£±»´Û¸ÄµÄÍøÒ³ÒÔ¡°±»ºÚ¡±Îª±êÌ⣬£¬½«Õý³£ÄÚÈÝ´úÌæ³ÉÁËÒ»ÔòÀÕË÷¼°Êý¾Ýй¶֪ͨ¡£¹¥»÷ÕßÐû³ÆÒѳɹ¦ÈëÇÖ¾«¹¤ÃÀ¹úµÄShopifyÉ̵갲Õûϵͳ£¬£¬²¢ÏÂÔØÁËÕû¸ö¿Í»§Êý¾Ý¿â£¬£¬ÆäÖÐÔ̺¬µÄÐÅÏ¢Ô̺¬£º¿Í»§ÐÕÃû¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢¶©µ¥º¹Çà¼Í¼¡¢¡¢¡¢ÂòÂôÏêÇé¡¢¡¢¡¢ÊÕ»õµØÖ·ÓëÆ«ºÃ¡¢¡¢¡¢ÕË»§´´½¨ÈÕÆÚÒÔ¼°¿Í»§±¸×¢µÈ¡£¹¥»÷ÕßÖÒ¸æ³Æ£¬£¬³ý·Ç¾«¹¤ÃÀ¹ú¹«Ë¾²Î¼Ó½»É棬£¬²»È»±»µÁÊý¾Ý½«±»¹«¿ª¡£×÷ΪҪÇóµÄÒ»²¿ÃÅ£¬£¬ËûÃÇÅúʾ¸Ã¹«Ë¾ÔÚShopifyÖÎÀíºó¶ÜÖвéÕÒÒ»¸öÌØ¶¨¿Í»§ÕË»§£¨IDΪ8069776801871£©£¬£¬²¢Ðû³Æ¸ÃÕË»§×ʲÂÖÐÔö³¤ÁËÒ»¸öÁªÏµÓÊÏ䵨ַ£¬£¬Ó¦Ê¹ÓøÃÓÊÏäÌáÒ齻ɿ¡£´ËÍ⣬£¬¹¥»÷Õß»¹ÒªÇ󾫹¤ÃÀ¹ú±ØÐëÔÚ72СʱÄÚÓëËûÃÇÁªÏµ£¬£¬²»È»ËùνµÄÊý¾Ý¿â½«±»°ä²¼¡£
https://www.bleepingcomputer.com/news/security/seiko-usa-website-defaced-as-hacker-claims-customer-data-theft/
5. MastodonÆì½¢·þÎñÆ÷ÔâDDoS¹¥»÷
4ÔÂ20ÈÕ£¬£¬Éç½»ÍøÂçÈí¼þÖÆ×÷ÉÌMastodonÖÜһ֤ʵ£¬£¬ÆäÆì½¢·þÎñÆ÷mastodon.socialÔâ·êÁËÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬£¬µ¼Ö¸ÃʵÀýÔÚ²¿ÃÅʱ¶ÎÎÞ·¨Õý³£½Ó¼û¡£ÍøÕ¾´ó²¿ÃÅÄÚÈÝҪôÏÔʾÃýÎóÐÅÏ¢£¬£¬ÒªÃ´³öÏÖÈ«ÆÁ¹ÊÕÏÖҸ档MastodonÓÚÃÀ¹ú¶«²¿¹¦·òÔçÉÏ7µã×óÓҰ䲼״̬¸üУ¬£¬°µÊ¾ÕýÔÚµ÷²éÕâ´Î¹¥»÷¡£ÉÏÎç9µã05·Ö£¬£¬¸Ã¹«Ë¾³ÆÒѲÉȡӦ¶Ô´ëÊ©£¬£¬ÍøÕ¾ÒѸ´Ô½Ó¼û£¬£¬µ«ÓÉÓÚ¹¥»÷ÈÔÔÚ½øÐÐÖУ¬£¬¿ÉÄÜÈÔ»á³öÏÖһЩ²»²»±äÇé¿ö¡£Mastodon°µÊ¾£¬£¬Ä¿Ç°ÒÑÊÕµ½Êý°ÙÍò´Î¶ñÒâÒªÇ󣬣¬ÇкÏDDoS¹¥»÷µÄģʽ¡£¹¥»÷Ŀǰ½öÕë¶Ômastodon.socialÕâÒ»¸öʵÀý£¬£¬ÆäÍŶÓÒÑÔÚ¹¥»÷ÆðÍ·ºóµÄ¼¸Ð¡Ê±ÄÚ²¿ÊðÓ¦¶Ô´ëÊ©²¢¸´ÔÁ˽Ӽû¡£MastodonͨѶÖ÷¹ÜAndy PiperÖ¸³ö£¬£¬ÔÚÕâÖÖÇé¿öÏ£¬£¬Áª°îÓîÖæµÄÈ¥ÖÐÐÄ»¯¸öÐÔµÄÈ·ÊÇÒ»ÏîÓÅÊÆ¡£ÔÚÆäËûMastodon·þÎñÆ÷»òÈÎºÎÆäËûÁª°îÓîÖæ·þÎñÆ÷ÉÏÕ¼ÓÐÕË»§µÄÓû§ÆëÈ«²»ÊÜÓ°Ï죬£¬ÔÚ´óÎÞÊýÇé¿öÏÂÉõÖÁµ××Ӹд¥²»µ½·þÎñÖжϣ¬£¬ËûÃÇ¿ÉÄÜÏñƽ·²Ò»Ñù½Ó¼ûÍøÂç¡¢¡¢¡¢ÔĶÁºÍ·ÖÏíÌû×Ó¡£
https://techcrunch.com/2026/04/20/mastodon-says-its-flagship-server-was-hit-by-a-ddos-attack/
6. ¹¥»÷ÕßÀÄÓÃTeams¼ÙÒâITÈËÔ±ÓÕÆÔ¶³Ì½Ó¼û
4ÔÂ20ÈÕ£¬£¬Î¢Èí½üÈÕ·¢³öÖҸ棬£¬³ÆÍþвÐÐΪÕßÕýÔÚÔ½À´Ô½¶àµØÀÄÓÃMicrosoft TeamsµÄÍⲿºÏ×÷Ö°ÄÜ£¬£¬²¢ÒÀÀµºÏ·¨¹¤¾ß½Ó¼ûÆóÒµÍøÂç¡¢¡¢¡¢½øÐкáÏòÒÆ¶¯ºÍÊý¾ÝÇÔÈ¡¡£ÔÚÕâЩ¹¥»÷ÖУ¬£¬ºÚ¿Í¼ÙÒâIT»ò·þÎñ̨ÈËÔ±£¬£¬Í¨¹ý¿ç×⻧̸ÌìÁªÏµÔ±¹¤£¬£¬ÓÕÆËûÃÇÌṩԶ³Ì½Ó¼ûȨÏÞ¡£Î¢Èí¹Û²ìµ½¶àÆðÈëÇÖÊÂÎñ¾ùѡȡÀàËÆµÄ¹¥»÷Á´£¬£¬Ê¹ÓÃóÒ×Ô¶³ÌÖÎÀíÈí¼þ£¨ÈçQuick Assist£©ºÍRcloneʵÓ÷¨Ê½£¬£¬½«Îļþ´«Êäµ½Íâ²¿ÔÆ´æ´¢·þÎñ¡£ÓÉÓÚ´óÁ¿Ê¹ÓúϷ¨ÀûÓ÷¨Ê½ºÍÔÉúÖÎÀíºÍ̸£¬£¬ºóÐø¶ñÒâ»î¶¯ºÜÄÑÓëÕý³£²Ù×÷·Ö±æ¸ôÀ´¡£Î¢Èí°µÊ¾£¬£¬¹¥»÷Õß´Ó³õʼ°²ÉíµãÆô³Ì£¬£¬ÀûÓÃÊÜÐÅÀµµÄ¹¤¾ßºÍ±¾µØÖÎÀíºÍ̸ÔÚÆóÒµÄÚ²¿ºáÏòÒÆ¶¯£¬£¬²¢³ï±¸Ãô¸ÐÊý¾ÝÒÔ½øÐÐÇÔÈ¡£¬£¬Õû¸ö¹ý³ÌÍùÍùÈÚÈëµ½ÈÕ³£ITÖ§³Ö»î¶¯ÖС£ÔÚ×î½üµÄÒ»·Ý»ã±¨ÖУ¬£¬Î¢Èí¾ßÌåÃèÊöÁËÒ»¸ö¾Å½×¶ÎµÄ¹¥»÷Á´¡£¸Ã¹¥»÷Á´Ê¼ÓÚÍþвÐÐΪÕßͨ¹ýÍⲿTeams̸ÌìÁªÏµÖ¸±ê£¬£¬¼ÙÒ⹫˾ITÈËÔ±£¬£¬Ðû³Æ±ØÒª½â¾öÕË»§ÎÊÌâ»òÖ´Ðа²È«¸üУ¬£¬Ö÷ÕÅÊÇÓÕʹָ±êÓû§Æô¶¯Ô¶³ÌÖ§³Ö»á»°£¬£¬Í¨³£ÊÇͨ¹ýQuick Assist£¬£¬´Ó¶øÈù¥»÷ÕßÖ±½Ó½ÚÖÆÔ±¹¤µÄÍÆËã»ú¡£
https://www.bleepingcomputer.com/news/security/microsoft-teams-increasingly-abused-in-helpdesk-impersonation-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ