Robinhood·ì϶±»ÀÄÓ÷¢ËÍ´¹µöÓʼþ
°ä²¼¹¦·ò 2026-04-281. Robinhood·ì϶±»ÀÄÓ÷¢ËÍ´¹µöÓʼþ
4ÔÂ27ÈÕ£¬£¬ÔÚÏßÂòÂôƽ̨RobinhoodµÄÕË»§´´½¨¹ý³Ì½üÈÕ±»·¸·¨·Ö×ÓÀûÓ㬣¬ËûÃÇͨ¹ýÏòºÏ·¨µç×ÓÓʼþÖÐ×¢Èë¶ñÒâHTML´úÂ룬£¬ÏòÓû§·¢ËÍÁ˸߶ÈÕæÇеĴ¹µöÓʼþ£¬£¬ÓÕÆÓû§ÏàÐÅÆäÕË»§´æÔÚ¿ÉÒɻ¡£´Ó4ÔÂ26ÈÕÍí¼äÆðÍ·£¬£¬RobinhoodÓû§Â½ÐøÊÕµ½À´×Ô¹Ù·½µØÖ·µÄ¡°Äú×î½üµÇ¼Robinhood¡±Óʼþ¡£ÓʼþÐû³Æ¼ì²âµ½ÓëÕË»§¹ØÁªµÄδ¼ø±ðÉ豸£¬£¬Ô̺¬²»Ñ°³£µÄIPµØÖ·ºÍ²¿Ãŵ绰ºÅÂ룬£¬²¢ÉèÖÃÁËÒ»¸ö¡°Á¢¼´²é¿´»î¶¯¡±°´Å¥¡£µã»÷¸Ã°´Å¥»áÌø×ªÖÁÒѹرյĴ¹µöÍøÕ¾£¬£¬¸ÃÍøÕ¾±»ÓÃÀ´ÊÔͼÇÔÈ¡Óû§µÄRobinhoodƾ֤¡£ÕâЩÓʼþÖ®ËùÒÔ¼«¾ßºýŪÐÔ£¬£¬ÊÇÓÉÓÚËüÃÇͨ¹ýÁËSPFºÍDKIMµç×ÓÓʼþ°²È«²é³£¬£¬ÆëÈ«À´×ÔRobinhoodµÄ¹Ù·½·¢¼þÇþµÀ¡£¹¥»÷ÕßÀûÓÃÁËRobinhood×¢²áÁ÷³ÌÖеÄÒ»¸ö·ì϶¡£µ±×¢²áÐÂÕË»§Ê±£¬£¬Robinhood»á×Ô¶¯Ïò¹ØÁªÓÊÏä·¢ËÍ¡°Äú×î½üµÇ¼Robinhood¡±µÄÓʼþ£¬£¬ÆäÖÐÔ̺¬×¢²á¹¦·ò¡¢¡¢IPµØÖ·¡¢¡¢É豸ÐÅÏ¢ºÍ´óÌåµØÎ»¡£¹¥»÷Õßͨ¹ýÅú¸ÄÉ豸ԪÊý¾Ý×ֶΣ¬£¬ÔÚÆäÖÐ×¢ÈëǶÈëʽHTML´úÂ룬£¬¶øRobinhoodδÄÜ¶ÔÆä½øÐÐÊʵ±µÄËãÕÊ¡£Õâ¶Î¶ñÒâHTML±»×¢Èëµ½ÓʼþµÄ¡°É豸¡±×Ö¶ÎÖУ¬£¬ÏÔʾΪÐéαµÄ¡°ÄúµÄÕË»§¹ØÁªÁËÎÞ·¨Ê¶´ËÍâÉ豸¡±ÐÂÎÅ¡£
https://www.bleepingcomputer.com/news/security/robinhood-account-creation-flaw-abused-to-send-phishing-emails/
2. Glasswormй¥»÷²¨¶Ô×¼OpenVSX
4ÔÂ27ÈÕ£¬£¬ÐÂÒ»²¨Glassworm¹©¸øÁ´¹¥»÷»î¶¯ÕýÒÔOpenVSXÉú̬ϵͳΪָ±ê£¬£¬ÆäÖÐÔ̺¬73¸ö¡°ÐÝÃß¡±À©´ó·¨Ê½£¬£¬ÕâЩÀ©´ó·¨Ê½ÔÚ¸üкó»áÔì³É¶ñÒâÈí¼þ¡£¾ÝÀûÓð²È«¹«Ë¾SocketÅû¶£¬£¬ÆäÖÐÁù¸öÀ©´ó·¨Ê½Òѱ»¼¤»î²¢´«²¼¶ñÒâÈí¼þ£¬£¬ÆäÓàÀ©´ó·¨Ê½¸ß¶È¿ÉÒÉ»ò´¦ÓÚ´ý¼¤»î״̬¡£×îÐÂÒ»²¨¹¥»÷Åú×¢£¬£¬¹¥»÷ÕßµÄÕ½Êõ²úÉúÁËÖØÒª±ä¶¯£¬£¬ËûÃDz»ÔÙ½«¶ñÒâÔØºÉÖ±½ÓǶÈëÀ©´ó·¨Ê½£¬£¬¶øÊÇÏÈÌá½»ÎÞº¦µÄÀ©´ó·¨Ê½£¬£¬ÔÚËæºó¸üÐÂÖÐÔÙÒýÈë¶ñÒâ´úÂë¡£Socket·¢ÏÖ£¬£¬Õâ73¸öÀ©´ó·¨Ê½¶¼ÊǺϷ¨ÈȵãÀ©´óµÄ¿Ë¡°æ±¾£¬£¬Ö¼ÔÚºýŪÄÇЩֻ¹ØÄýÊÓ¾õ³ÉЧ¶øºöÂÔϸ½ÚµÄ¿ª·¢Õß¡£ÕâЩÀ©´ó·¨Ê½²»ÔÙÖ±½ÓЯ´ø¶ñÒâÈí¼þ£¬£¬¶øÊÇ×÷ΪÇáÁ¿¼¶¼ÓÔØÆ÷£¬£¬Í¨¹ýÒÔÏ·½Ê½»ñÈ¡¶ñÒâÔØºÉ£º£º£ºÔÚÔËÐÐʱ´ÓGitHub»ñÈ¡¸¨ÖúVSIX°ü²¢Í¨¹ýCLI×°Ö㻣»¼ÓÔØÌØ¶¨Æ½Ì¨µÄ±àÒëÄ£¿£¿é£¨.nodeÎļþ£©»ñÈ¡ÔØºÉ£»£»»òÒÀ¸½¸ß¶È»ìºÏµÄJavaScriptÔÚÔËÐÐʱ½âÂëÒÔ×°ÖöñÒâÀ©´ó¡£´ËǰGlassworm¹¥»÷ÖØÒªÖ÷ÕÅÊÇÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý¡¢¡¢¿ª·¢Õ߯¾Ö¤¡¢¡¢½Ó¼ûÁîÅÆºÍSSHÃÜÔ¿¡£
https://www.bleepingcomputer.com/news/security/glassworm-malware-attacks-return-via-73-openvsx-sleeper-extensions/
3. ÃÀ¶ØÁ¦ÔâShinyHunters¹¥»÷£¬£¬±»ÇÔ³¬900Íò±Ê¼Í¼
4ÔÂ27ÈÕ£¬£¬Ò½ÁÆÉ豸¾ÞÍ·ÃÀ¶ØÁ¦¹«Ë¾Ö¤Êµ£¬£¬ÆäÆóÒµITϵͳÔâµ½ÍøÂç¹¥»÷£¬£¬ºÚ¿Í×éÖ¯ShinyHuntersÐû³ÆÒÑÇÔÈ¡³¬¹ý900Íò±Ê¼Í¼¡£¸Ã¹«Ë¾°µÊ¾£¬£¬Î´¾ÊÚȨµÄµÚÈý·½½Ó¼ûÁËÆä²¿ÃÅÆóÒµITϵͳÖеÄÊý¾Ý£¬£¬µ«ÉÐδ·¢ÏÖ¶Ô²úÆ·°²È«¡¢¡¢»¼Õß°²È«¡¢¡¢ÔËÓª¡¢¡¢²ÆÕþϵͳ»òÒ½ÁÆ·þÎñÔì³ÉÈκÎÓ°Ïì¡£ÃÀ¶ØÁ¦Ç¿µ÷£¬£¬ÆäITϵͳ¡¢¡¢²úƷϵͳºÍÖÆ×÷ÍøÂçÏ໥¶ÀÁ¢£¬£¬Ò½ÔºÍøÂçҲά³Ö¶ÀÁ¢ÖÎÀí²¢Óɿͻ§ITÍŶÓÕÆ¹Ü°²È«ÊØ»¤¡£ÃÀ¶ØÁ¦ÔÚÐÂΟåÖÐÖ¸³ö£¬£¬Ö§³ÖÆóÒµITϵͳ¡¢¡¢²úÆ·ÒÔ¼°³ö²úºÍ·ÖÏúÒµÎñµÄÍøÂçÊÇÏ໥¸ôÀëµÄ£¬£¬Ò½Ôº¿Í»§ÍøÂçÓëÃÀ¶ØÁ¦ITÍøÂçÆëÈ«·ÖÀë¡£¹«Ë¾ÒѽÚ֯סÕâ´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬²¢ÔÚÍâ²¿ÍøÂ簲ȫר¼ÒµÄÐÖúÏÂÆô¶¯ÁËÊÂÎñÏìÓ¦»úÖÆ¡£Ä¿Ç°£¬£¬ÃÀ¶ØÁ¦ÕýÔÚÆÀ¹ÀÊÇ·ñÓÐСÎÒÊý¾Ý±»Ð¹Â¶£¬£¬²¢½«Í¨ÖªÊÜÓ°ÏìµÄСÎÒ²¢ÌṩÏàÓ¦Ö§³Ö¡£4ÔÂ18ÈÕ£¬£¬ShinyHunters½«ÃÀ¶ØÁ¦ÁÐÈëÆäTorÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬Ðû³Æ³¬¹ý900Íò±Ê¼Í¼±»µÁ£¬£¬ÆäÖÐÔ̺¬Ð¡ÎÒÊý¾ÝºÍÄÚ²¿Îļþ¡£¸Ã×éÖ¯×î³õÍþв³Æ£¬£¬ÈôÊÇÊê½ðδÔÚ4ÔÂ21ÈÕǰ֧¸¶£¬£¬ËûÃǽ«¹«¿ªÐ¹Â¶ÕâЩÊý¾Ý¡£¶ûºó£¬£¬¸Ã×éÖ¯µÄÓйØÒ³ÃæÒÑÒþû¡£
https://securityaffairs.com/191391/cyber-crime/medtronic-discloses-security-incident-after-shinyhunters-claimed-theft-of-9m-records.html
4. PyPI°üelementary-dataÔ⹩¸øÁ´¹¥»÷
4ÔÂ27ÈÕ£¬£¬¹¥»÷Õ߳ɹ¦ÍÆËÍÁËÊ¢ÐÐPyPI°üelementary-dataµÄ¶ñÒâ°æ±¾£¨0.23.3£©£¬£¬Ö¼ÔÚÇÔÈ¡Ãô¸ÐµÄ¿ª·¢ÕßÊý¾ÝºÍ¼ÓÃÜÇ®±ÒÇ®°ü¡£ÓÉÓڸðüµÄ¹¤×÷Á÷³ÌÉæ¼°´Ó´úÂë´´½¨¾µÏñ²¢ÉÏ´«ÖÁÈÝÆ÷×¢²á±í½øÐв¿Ê𣬣¬¶ñÒâ°æ±¾µÄÓ°ÏìÒ²À©´óµ½ÁËDocker¾µÏñ¡£ÉçÇø³ÉÔ±crisperik·¢ÏÖÁ˶ñÒâÉÏ´«£¬£¬²¢ÓÚÖÜÁùÔÚÏîÄ¿GitHubÉÏÌá½»ÎÊÌâÌáÐÑÊØ»¤Õߣ¬£¬´Ó¶øËõ¶ÌÁ˶³ö´°¿Ú¡£¸É¾»µÄ´úÌæ°æ±¾0.23.4ÒÑÍÆËÍ£¬£¬µ«ÒÑÏÂÔØ¶ñÒâ±äÖÖµÄÓû§ÈÔÊܵ½Ï°È¾¡£¾Ý·ÖÎö£¬£¬¹¥»÷ÕßÔÚÀȡҪÇóÖа䲼ÁËÒ»Ìõ¶ñÒâÆÀÂÛ£¬£¬ÀûÓÃGitHub Actions¾ç±¾×¢Èë·ì϶£¬£¬µ¼Ö¹¤×÷Á÷Ö´ÐÐÁ˹¥»÷Õß½ÚÖÆµÄshell´úÂë¡£ÕâÒ»¹ý³Ì¶³öÁ˹¤×÷Á÷µÄGITHUB_TOKEN£¬£¬¹¥»÷ÕßËæ¼´ÀûÓøÃÁîÅÆÎ±ÔìÁËÊðÃûÌá½»ºÍ±êÇ©£¨v0.23.3£©£¬£¬²¢´¥·¢ÁËÏîÖ÷ÕźϷ¨°ä²¼¹ÜµÀ¡£¸Ã¹ÜµÀËæºóÏòPyPI°ä²¼ÁË´øÓкóÃŵİü£¬£¬Í¬Ê±ÏòGitHubÈÝÆ÷×¢²á±íÍÆËÍÁ˶ñÒâ¾µÏñ£¬£¬Ê¹Æä¿´ÆðÀ´ÆëÈ«Ïñ¹Ù·½°æ±¾¡£ÓÉÓÚ¡°ÉÏ´«µ½PyPIµÄ°ä²¼°ü¹¤×÷Á÷Ò²Ô̺¬¹¹½¨ºÍÍÆËÍDocker¾µÏñµÄ¹¤×÷¡±£¬£¬Ò»ÑùµÄ¶ñÒâÔØºÉÒ²´ïµ½ÁËÏîÖ÷ÕÅDocker¾µÏñÖС£
https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/
5. ΢ÈíOutlook.com³ÖÐø¹ÊÕÏÖÂÓû§µÇ¼ʧ°Ü
4ÔÂ27ÈÕ£¬£¬Î¢ÈíÕýÔÚµ÷²éOutlook.com³ÖÐø³öÏֵĹÊÕÏ£¬£¬¸Ã¹ÊÕϵ¼Ö¼äЪÐԵǼÎÊÌâ²¢×èÖ¹Óû§½Ó¼ûÆäÓÊÏä¡£×ÔÊÂÎñ²úÉúÈý¸ö¶àСʱÒÔÀ´£¬£¬¹ÊÕÏ¼à¿Ø·þÎñDowndetectorÒÑÊÕµ½Êýǧ·ÝÓû§»ã±¨£¬£¬ÆäÖдóÎÞÊýÊÜÓ°ÏìÓû§»ã±¨Á˵ǼÎÊÌâºÍÏνÓÎÊÌ⡣΢ÈíÔÚÆä¹Ù·½·þÎñ½¡¿µÇé¿öÒ³ÃæÉϸüÐÂÐÂÎųƣ¬£¬ÊÜÓ°ÏìµÄ¿Í»§ÕýÔÚ±»Ç¿ÖÆÍ˳öÆäÕÊ»§£¬£¬²¢¿´µ½¡°ÒªÇó¹ý¶à¡±µÄÃýÎóÌáÐÑ¡£Î¢Èí°µÊ¾²¿ÃÅÓû§¿ÉÄÜ»áÓöµ½¼äЪÐԵǼʧ°ÜµÄÇé¿ö£¬£¬Ô̺¬¡°ÒªÇó¹ý¶à¡±ÃýÎó»ò²»²â×¢Ïú¡£Î¢ÈíµÄµ÷²éÏÔʾ£¬£¬¿Í»§¶ËµÇ¼³¡¾°¿ÉÄܵ¼ÖÂÁËËù»ã±¨µÄÐÐΪ£¬£¬¹«Ë¾ÕýרһÓÚÑéÖ¤¸÷¸ö·þÎñ×é¼þÖ®¼äµÄ½»»¥ÒÔÈ·¶¨ÏÂÒ»²½´ëÊ©¡£ÔÚ×îеĸüÐÂÖУ¬£¬Î¢Èí½«Outlook.com³ÖÐø´æÔڵĵǼÎÊÌâ¹é×ïÓÚ¡°×î½üÒýÈëµÄ¸ü¸Ä¡±¡£¹«Ë¾ÔÚ·þÎñ½¡¿µÇé¿ö¸üÐÂÖаµÊ¾£¬£¬ÕýÔÚ³·Ïú×î½üÍÆ³öµÄÒ»Ïîµ÷»»£¬£¬ÒÔÈ·¶¨´Ë¾ÙʵÏÖºóÊÇ·ñÄܼõÇáÓ°Ïì¡£Óë´Ëͬʱ£¬£¬Î¢Èí³ÖÐø·ÖÎö¿Í»§»ã±¨£¬£¬²¢Ç×êÇ¼à¿Ø·þÎñÒ£²âÊý¾ÝÒÔÈ·¶¨ÏÂÒ»²½´ëÊ©¡£Ä¿Ç°ÊÜÓ°ÏìµÄÓû§ÈÔÔÚÆÚ´ýÈ«Ãæ¸´Ô¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-says-outlookcom-outage-is-causing-sign-in-failures/
6. VidarбäÖÖ£º£º£º¶ñÒâ´úÂë²ØÉíJPEGͼÏñ¶ã±Ü¼ì²â
4ÔÂ27ÈÕ£¬£¬Point WildÆìÏÂLat61Íþвµý±¨ÍŶӵÄ×îÐÂ×êÑÐÅú×¢£¬£¬ºÚ¿Í´Ë¿Ì½«¶ñÒâ´úÂë°µ²ØÔÚJPEGͼÏñºÍÎı¾ÎĵµµÈÈÕ³£ÎļþÖУ¬£¬ÒÔ²¿Êð³ôÃûÔ¶ÑïµÄVidarÐÅÏ¢ÇÔÈ¡·¨Ê½µÄ×îа汾¡£Lat61µÄ×êÑз¢ÏÖ£¬£¬¸ÃϰȾÁ´Ê¼ÓÚVBScriptºÍPowerShell¾ç±¾£¬£¬×îÖÕµ¼Ö²¿ÊðÒ»¸öGo±àÒëµÄ¼ÓÔØÆ÷¡£·ÖÎöÖØµã´Ó³õʼÈëÇÖ½×¶Î×ªÒÆµ½ºóÉøÈë½×¶Î£¬£¬½ÒʾÁËÒ»¸ö¸´Ôӵġ¢¡¢¶à½×¶ÎµÄ¶ñÒâÈí¼þ¹¥»÷»î¶¯£¬£¬¸Ã»î¶¯ÀûÓ÷ֲã»ìºÏ¡¢¡¢·Ö½×¶ÎÓÐÐ§ÔØºÉ½»¸¶ºÍÊÜÐÅÀµµÄWindows×é¼þÀ´ÊµÏÖÒñ±ÎÖ´ÐкÍÓÆ¾Ã»¯¡£Vidar 2026°æµÄΣÏÕÖ®´¦ÔÚÓÚÆäÒñ±ÎÐÔ¡£Ò»µ©É豸±»Ï°È¾£¬£¬¸Ã¶ñÒâÈí¼þ»áÀûÓûùÓÚIPµÄ´«Êä»ù´¡ÉèÊ©ÏÂÔØ¿´ËÆÍ¨³£µÄJPEGͼÏñºÍTXTÎļþ£¬£¬ÕâЩÎļþÏÖʵÉÏÊÇǶÈëÁËBase64Êý¾ÝµÄÓÐÐ§ÔØºÉÈÝÆ÷¡£VidarµÄ×îÖÕÖ¸±êÊÇÊý¾ÝÇÔÈ¡¡£´Ë°æ±¾Äܹ»´Ó¹È¸èChromeä¯ÀÀÆ÷ºÍ΢ÈíEdgeä¯ÀÀÆ÷µÄ200¶à¸öÀ©´ó·¨Ê½ÖÐÇÔÈ¡Êý¾Ý£¬£¬ÓÈÆäÕë¶Ô¼ÓÃÜÇ®±ÒÇ®°ü¡¢¡¢µÇ¼ƾ֤ºÍ»á»°Êý¾Ý£¬£¬´Ó¶øÊ¹ºÚ¿Í¿ÉÄܽӼû¸öÈËÕË»§¡£
https://hackread.com/vidar-infostealer-fake-captchas-jpeg-txt-files/


¾©¹«Íø°²±¸11010802024551ºÅ