¸»Ê¿¿µ±±ÃÀÔâNitrogenÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2026-05-13

1.¸»Ê¿¿µ±±ÃÀÔâNitrogenÀÕË÷Èí¼þ¹¥»÷


5ÔÂ12ÈÕ£¬£¬¸»Ê¿¿µ½üÈÕ֤ʵÆä±±ÃÀÒµÎñÔâ·êÍøÂç¹¥»÷¡£¡£´Ëǰ£¬£¬ÃûΪNitrogenµÄÀÕË÷Èí¼þÍÅ»ïÒѽ«¸Ãµç×Ó²úÆ·ÖÆ×÷ÉÌÁÐÈëÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¡£¸»Ê¿¿µ½²»°È˰µÊ¾£¬£¬¹«Ë¾±±ÃÀ²¿Ãʤ³§Ôâ·ê¹¥»÷ºó£¬£¬ÍøÂ簲ȫÍŶÓÁ¢¼´Æô¶¯Ó¦¼±»úÖÆ£¬£¬²ÉÈ¡¶àÏîÔËÓª´ëʩȷ±£³ö²úºÍ½»¸¶Â½ÐøÐÔ£¬£¬ÊÜÓ°Ï칤³§ÕýÖ𲽸´Ô­Õý³£³ö²ú¡£¡£È»¶ø£¬£¬¸üÁîÈËÓÇÓôµÄÊÇ£¬£¬NitrogenÍÅ»ïÐû³ÆÒÑÈëÇÖÕâ¼Ǫ̀ÍåÆóÒµ£¬£¬ÇÔÈ¡¶à´ï8TBµÄÊý¾Ý£¬£¬º­¸Ç³¬¹ý1100Íò¸öÎļþ¡£¡£¾Ý·¸·¨·Ö×Óй©£¬£¬Ð¹Â¶ÄÚÈÝÔ̺¬»úÃÜÖ¸Áî¡¢¡¢¡¢ÄÚ²¿ÏîÄ¿ÎĵµÒÔ¼°ÓëÓ¢ÌØ¶û¡¢¡¢¡¢Æ»¹û¡¢¡¢¡¢¹È¸è¡¢¡¢¡¢´÷¶û¡¢¡¢¡¢Ó¢Î°´ïµÈ³ÛÃûÆóÒµÏîÄ¿Óйصļ¼Êõͼֽ¡£¡£²»Í⣬£¬¸»Ê¿¿µ»Ø¾øÖ¤ÊµÕâЩ¿Í»§ÐÅÏ¢ÊÇ·ñÈ·ÇÐʵÕâ´ÎÊý×ÖÈëÇÖÖб»ÇÔÈ¡¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬Õâ²¢·Ç¸»Ê¿¿µ³õ´ÎÔâ·êÀÕË÷Èí¼þ¹¥»÷¡£¡£2024Ä꣬£¬LockBitÐû³ÆÏ°È¾Á˸»Ê¿¿µ¿Æ¼¼¼¯ÍÅÆìϰ뵼ÌåÉè±¸ÖÆ×÷ÉÌFoxsemicon Integrated Technology£»2022Ä꣬£¬Í³Ò»·¸×ïÍÅ»ï»¹Ôø¹¥»÷¸»Ê¿¿µÎ»ÓÚÄ«Î÷¸çµÄÒ»¼Ò×Ó¹«Ë¾¡£¡£


https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144


2. Ó¢¹úË®Îñ¹«Ë¾66ÍòÈËÐÅϢй¶±»·£96ÍòÓ¢°÷


5ÔÂ12ÈÕ£¬£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©½üÈÕ¶ÔÄÏ˹Ëþ¸£µÂ¿¤Ë®ÎñÓÐÏÞ¹«Ë¾¼°Æäĸ¹«Ë¾ÄÏ˹Ëþ¸£µÂ¿¤ÓÐÏÞ¹«Ë¾´¦ÒÔ96.39ÍòÓ¢°÷£¨Ô¼130ÍòÃÀÔª£©µÄ·£¿£¿î£¬£¬Ô­ÒòÊǸù«Ë¾ÒòÍøÂç¹¥»÷µ¼Ö³¬¹ý66ÍòÃû¿Í»§ºÍÔ±¹¤µÄСÎÒÊý¾Ýй¶¡£¡£Õâ¼ÒÿÌìÏò160ÍòÏû·ÑÕß¹©¸ø3.3ÒÚÉýÒûÓÃË®µÄ¹«Ë¾£¬£¬ÓÚ2022ÄêÅû¶³ÉÎªÍøÂç¹¥»÷Ö¸±ê²¢µ¼ÖÂITÔËÓªÖжÏ¡£¡£Æäʱ£¬£¬¹«Ë¾Ôø±ç²µCl0pÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹ÜµÄ˵·¨£¬£¬µ«¹ýºó֤ʵй¶µÄÊý¾ÝÑù±¾Êôʵ¡£¡£¹¥»÷¿É×·ÒäÖÁ2020Äê9Ô£¬£¬µ«ÖØÒª²úÉúÔÚ2022Äê5ÔÂÖÁ7ÔÂÖ®¼ä£¬£¬Â¶³öÁ˸ù«Ë¾ÔÚÊý¾Ý°²È«·½Ãæ´æÔÚµÄÖØ´óȱµã£¬£¬Ê¹¿Í»§ºÍÔ±¹¤ÔÚ½üÁ½Ä깦·òÀï´¦ÓÚÒ×Êܹ¥»÷״̬¡£¡£µ÷²éÏÔʾ£¬£¬Õâ´ÎÊÂÎñÊÇͨ¹ýÍøÂç´¹µö¹¥»÷Ôì³ÉµÄ£¬£¬¹¥»÷ÕßÀûÓô¹µö¼¿Á©ÔÚ¹«Ë¾ÏµÍ³ÖÐ×°ÖöñÒâÈí¼þ£¬£¬¸Ã¶ñÒâÈí¼þ³¤´ï20¸öÔÂδ±»·¢ÏÖ¡£¡£2022Äê5ÔÂÖÁ7ÔÂÆÚ¼ä£¬£¬¹¥»÷Õ߳ɹ¦ÌáÉýÍøÂçȨÏÞ²¢»ñµÃÓòÖÎÀíÔ±½Ó¼ûȨ£¬£¬Ö±µ½Îôʱ7ÔÂÒòIT»úÄÜÎÊÌâÒý·¢µ÷²éºó²Å±»·¢ÏÖ¡£¡£Ð¹Â¶µÄÊý¾Ý¼«ÎªÃô¸Ð£¬£¬Ô̺¬È«Ãû¡¢¡¢¡¢ÏÖʵµØÖ·¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢µ®ÉúÈÕÆÚ¡¢¡¢¡¢¿Í»§ÕË»§Æ¾Ö¤¡¢¡¢¡¢ÒøÐÐÕË»§¾ßÌåÐÅÏ¢£¬£¬ÒÔ¼°Ô±¹¤ÈËÁ¦×ÊÔ´Êý¾ÝÈç¹úÃñ±£ÏÕºÅÂëµÈ¡£¡£


https://www.bleepingcomputer.com/news/security/uk-fines-water-supplier-13m-for-exposing-data-of-664k-customers/


3. BWH¾Æµê¼¯ÍÅÔâ·ê³¤´ï°ëÄêÊý¾Ýй¶


5ÔÂ12ÈÕ£¬£¬BWH¾Æµê¼¯ÍŽüÈÕÅû¶ÁËһ·ÑÏÖØµÄÊý¾Ýй¶ÊÂÎñ£¬£¬·¸·¨·Ö×ÓÔÚ³¬¹ýÁù¸öԵŦ·òÀï·¸·¨»ñÈ¡Á˾Ƶê¿ÍÈ˵ÄÔ¤Ô¼Êý¾Ý¡£¡£×÷ΪȫÇò×î´óµÄ¾ÆµêÍøÂçÖ®Ò»£¬£¬BWHÔÚ100¶à¸ö¹ú¶ÈÔËÓª×Å4000¶à¼Ò¾Æµê£¬£¬ÆìÏÂÕ¼ÓÐBest Western Hotels & Resorts¡¢¡¢¡¢WorldHotelsºÍSure HotelsµÈÆ·ÅÆ£¬£¬º­¸Ç´Ó¾­¼ÃÐ͵½ºÀ»ªÐ͵ĸ÷Àà¾Æµê¡£¡£Æ¾¾Ý¸Ã¼¯ÍÅ·¢Ë͸øÊÜÓ°Ïì¿Í»§µÄÊý¾Ýй¶֪ͨ£¬£¬2026Äê4ÔÂ22ÈÕ£¬£¬¹«Ë¾·¢ÏÖ´æ´¢²¿ÃÅ¿ÍÈËÔ¤Ô¼Êý¾ÝµÄÍøÂçÀûÓ÷¨Ê½´æÔÚδ¾­ÊÚȨµÄ»î¶¯¡£¡£½øÒ»´ëÊ©²éÏÔʾ£¬£¬ÔÚ2025Äê10ÔÂ14ÈÕÖÁ2026Äê4ÔÂ22ÈÕÆÚ¼ä£¬£¬Ô̺¬¿ÍÈËÐÕÃû¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢¼ÒͥסַµÈÁªÏµÐÅÏ¢£¬£¬ÒÔ¼°Ô¤Ô¼±àºÅ¡¢¡¢¡¢ÈëסÈÕÆÚºÍÈκÎÌØÊâÒªÇóµÈÔ¤Ô¼ÏêÇ飬£¬±»Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼û¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬¸Ã¹«Ë¾Ã÷È·°µÊ¾£¬£¬ÊÜÓ°ÏìµÄϵͳÖв¢Î´´æ´¢Ö§¸¶ÐÅÏ¢ºÍÆäËû²ÆÕþÊý¾Ý£¬£¬Òò¶ø¿ÍÈ˵ÄÖ§¸¶ÐÅϢûÓÐй¶¡£¡£ÔÚ·¢ÏÖÈëÇֺ󣬣¬BWHѸËÙ½«ÊÜÓ°ÏìµÄÀûÓ÷¨Ê½ÏÂÏߣ¬£¬³·ÏúÁËÓйؽӼûȨÏÞ£¬£¬²¢ÀñƸÍâ²¿ÍøÂ簲ȫר¼ÒÖ§³Öµ÷²éºÍ¼ÓǿϵͳÕäÊÓ¡£¡£¾Æµê¼¯ÍÅ»¹Ïò¿ÍÈË·¢³öÖҸ棬£¬ÌáÐѾ¯ÌèÀûÓñ»µÁÔ¤Ô¼Êý¾ÝÌáÒéµÄÍøÂç´¹µöÓʼþ¡¢¡¢¡¢¶ÌÐÅ¡¢¡¢¡¢µç»°»òÐéαԤԼÐÅÏ¢Ú¿Æ­¡£¡£


https://securityaffairs.com/192038/data-breach/hackers-accessed-bwh-hotels-reservation-system-for-months.html


4. ˹¿Â´ïÆû³µÍøÉÏÉ̵êÔâ¹¥»÷£¬£¬¿Í»§Ð¡ÎÒÐÅϢй¶


5ÔÂ12ÈÕ£¬£¬¹«¹²Æû³µ¼¯ÍÅÈ«×Ê×Ó¹«Ë¾Ë¹¿Â´ïÆû³µ½üÈÕÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬£¬¹«Ë¾·¢ÏÖδ¾­ÊÚȨµÄÈËÔ±ÀûÓÃÔÚÏßÉ̵êʹÓõij߶ÈÈí¼þÖеķì϶£¬£¬ÁÙʱ·¸·¨½Ó¼ûÁËÉ̵êϵͳ¡£¡£·¢ÏÖÈëÇÖÊÂÎñºó£¬£¬¹«Ë¾ÒÑÏòÓйز¿ÃŻ㱨£¬£¬ÐÞ¸´Á˱»ÀûÓõݲȫ·ì϶£¬£¬²¢½«´ËÊÂÎñÒÆ½»¸ø×¨ÒµµÄITȡ֤ÍŶӽøÐм¼Êõ·ÖÎö£¬£¬Í¬Ê±»ã±¨¸øÓйصÄÊý¾ÝÕäÊÓ¼à¹Ü»ú¹¹¡£¡£±»ÇÔÈ¡µÄ¿Í»§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢¡¢¡¢µØÖ·¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢µç»°ºÅÂëµÈÁªÏµÐÅÏ¢£¬£¬ÒÔ¼°¶©µ¥ÐÅÏ¢ºÍµÇ¼ʹ´¦¡ª¡ªÔ̺¬µç×ÓÓʼþµØÖ·ºÍÃÜÂëµÄ¼ÓÃܹþÏ£Öµ¡£¡£Ë¹¿Â´ïÇ¿µ÷£¬£¬¹¥»÷ÕßÎÞ·¨½Ó¼ûÊÜÓ°Ïì¿Í»§µÄ²ÆÕþÐÅÏ¢£¬£¬ÓÉÓÚÆëÈ«µÄÐÅÓþ¿¨ÐÅÏ¢²¢Î´´æ´¢ÔÚÉ̵êϵͳÖУ¬£¬¶øÊÇÓÉÏàÓ¦µÄÖ§¸¶·þÎñÌṩÉÌȫȨ´¦Öᣡ£¹ÌȻ˹¿Â´ï°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢±»½Ó¼ûµÄÊý¾ÝÒѱ»ÀÄÓ㬣¬µ«¸Ã¹«Ë¾ÖÒ¸æÊÜÓ°ÏìµÄСÎÒ¾¯ÌèÕë¶ÔËûÃǵÄÍøÂç´¹µö¹¥»÷£¬£¬²¢³ö¸ñÖ¸³öÈôÊǿͻ§·´¸´Ê¹ÓÃÒ»ÑùµÄµÇ¼ʹ´¦£¬£¬ÍþвÐÐΪÕß¿ÉÄ᳢ܻÊԵǼËûÃÇµÄÆäËûÔÚÏßÕÊ»§¡£¡£Ä¿Ç°Ë¹¿Â´ïÉÐδÅû¶ÊÜÓ°ÏìµÄ¿Í»§×ÜÊýÒÔ¼°ÊÇ·ñÓë¹¥»÷ÕßÓйýÊê½ðÖ§¸¶ÁªÏµ¡£¡£


https://www.bleepingcomputer.com/news/security/skoda-warns-of-customer-data-breach-after-online-shop-hack/


5. ±öÖÝÖÆÒ©¾ÞÍ·West PharmaceuticalÔâÀÕË÷¹¥»÷


5ÔÂ12ÈÕ£¬£¬±öϦ·¨ÄáÑÇÖÝÖÆÒ©¾ÞÍ·West Pharmaceutical Services½üÈÕÅû¶£¬£¬¹«Ë¾ÓÚ5ÔÂ4ÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬Ä¿Ç°ÕýÔÚ´¹Î£¸´Ô­ÊÜÓ°ÏìµÄϵͳ¡£¡£¸Ã¹«Ë¾ÔÚÒ»·ÝÊÂÎñ֪ͨÖаµÊ¾£¬£¬¹¥»÷²úÉúºóÁ¢¼´×Ô¶¯¹Ø±Õ²¢¸ôÀëÁËÊÜÓ°ÏìµÄ±¾µØ»ù´¡ÉèÊ©¡£¡£Æ¾¾ÝÖÜÒ»Ìá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»áµÄÎļþ£¬£¬ÕâЩ¶ôÖÆ´ëÊ©Òѵ¼Ö¹«Ë¾È«ÇòÁìÓòÄÚµÄÒµÎñÔËÓªÊܵ½×ÌÈÅ¡£¡£ÆäËûÊÂÎñÓ¦¶Ô´ëÊ©Ô̺¬ÏÞ¶È¶ÔÆóҵϵͳµÄ½Ó¼ûºÍÆô¶¯Î£»úÖÎÀíºÍ̸¡£¡£ÎªÓ¦¶ÔÕâ´Î¹¥»÷£¬£¬Õâ¼ÒÖÆÒ©¾ÞÍ·ÀñƸÁËPalo Alto NetworksµÄUnit 42Íþвµý±¨ºÍÊÂÎñÏìÓ¦ÍŶÓЭÖú½øÐжôÖÆ¡¢¡¢¡¢ÏµÍ³¸´Ô­ºÍÊÂÎñµ÷²é£¬£¬Í¬Ê±ÒÑ֪ͨ·¨Âɲ¿ÃÅ¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬¹ÌÈ»Ö÷ÌâÆóҵϵͳÒѸ´Ô­£¬£¬²¿ÃÅÕ¾µãµÄ·¢»õ¡¢¡¢¡¢ÊÕ»õºÍÖÆ×÷µÈ¹Ø¼üÁ÷³ÌÒ²ÒÑÖØÐÂÆô¶¯£¬£¬ÆäÓàÕ¾µãµÄ¸´Ô­¹¤×÷ÈÔÔÚ½øÐÐÖУ¬£¬µ«È«Ã渴ԭµÄ¹¦·ò±íÉÐδ×îÖÕÈ·¶¨¡£¡£West PharmaceuticalÏòSECÅû¶£¬£¬¹¥»÷ÕßÔÚ²¿ÊðÎļþ¼ÓÃÜÀÕË÷Èí¼þ֮ǰ´ÓÆäϵͳÖÐÇÔÈ¡ÁËÊý¾Ý£¬£¬¹«Ë¾ÕýÔÚµ÷²éÊÜÓ°ÏìÊý¾ÝµÄÁìÓò¡£¡£¹ÌÈ»¸Ã¹«Ë¾Ã»ÓÐÖ¸Ã÷ÊÇÄĸöÀÕË÷Èí¼þ×éÖ¯·¢ÆðÁËÈëÇÖ£¬£¬µ«°µÊ¾¡°ÒѲÉÈ¡´ëÊ©£¬£¬Ö¼ÔÚ½µµÍй¶Êý¾Ý´«²¼µÄ·çÏÕ¡±£¬£¬Õⰵʾ¿ÉÄÜÒѾ­Óë¹¥»÷Õß½øÐÐÁ˽»Éæ¡£¡£


https://www.securityweek.com/west-pharmaceutical-services-hit-by-disruptive-ransomware-attack/


6. ´ó¹æÄ£¹©¸øÁ´¹¥»÷ÈëÇÖnpmºÍPyPIÊý°Ù¸öÈí¼þ°ü


5ÔÂ12ÈÕ£¬£¬Ò»³¡ÃûΪShai-HuludµÄÐÂÐ͹©¸øÁ´¹¥»÷»î¶¯Òѵ¼ÖÂnpmºÍPyPIÉϵÄÊý°Ù¸öÈí¼þ°üÔâµ½ÈëÇÖ£¬£¬¹¥»÷ÕßÖ²ÈëÇÔȡƾ֤µÄ¶ñÒâÈí¼þ£¬£¬Ö¸±êÖ±Ö¸¿ª·¢Õß¡£¡£Õâ´Î¹¥»÷±»ÒÔΪÊÇÓÉÍþв×éÖ¯TeamPCPËùΪ£¬£¬¹¥»÷Õß½Ù³ÖÁËÓÐЧµÄOpenID ConnectÁîÅÆ£¬£¬°ä²¼ÁË´øÓпÉÑéÖ¤ÆðÔ´Ö¤Ã÷µÄ¶ñÒâÈí¼þ°ü°æ±¾¡£¡£Shai-Hulud¹¥»÷»î¶¯ÓÚÈ¥Äê9Ô³öÏÖ²¢¾­ÀúÁËÂŴεü´ú£¬£¬ÆäÖÐһЩµü´úÒÑй¶ÁË×Ô¶¯ÌìÉúµÄGitHub´úÂë¿âÖÐÊýÊ®Íò¸ö¿ª·¢Õß»úÃÜÐÅÏ¢¡£¡£×îÐÂÒ»²¨¹¥»÷²úÉúÔÚ×òÌ죬£¬¹¥»÷ÕßÔÚnpmµÄTanStack¶¨Ãû¿Õ¼äÖа䲼Á˶à¸ö¶ñÒâÈí¼þ°ü£¬£¬¶øºóÀûÓÃÇÔÈ¡µÄCI/CDƾ֤´«²¼µ½ÆäËûÏîÄ¿¡£¡£Æ¾¾Ý°²È«³§É̵Ļ㱨£¬£¬npmÉÏÓг¬¹ý160¸öÊÜϰȾµÄÈí¼þ°ü£¬£¬PyPIÉÏÒ²·¢ÏÖÁË´óÁ¿¶ñÒâÈí¼þ°ü¡£¡£¶ñÒâÈí¼þµÄÖ¸±êÔ̺¬ÇÔÈ¡GitHub Actions OIDCÁîÅÆ¡¢¡¢¡¢GitÍ´´¦¡¢¡¢¡¢npm°ä²¼ÁîÅÆ¡¢¡¢¡¢AWSƾ֤¡¢¡¢¡¢Kubernetes·þÎñÕÊ»§ÁîÅÆ¡¢¡¢¡¢HashiCorp VaultÁîÅÆ¡¢¡¢¡¢SSHÃÜÔ¿¡¢¡¢¡¢Claude CodeÅäÖü°.envÎļþµÈ¡£¡£¸ÃÓÐÐ§ÔØºÉ»á¶ÁÈ¡GitHub Actions¹ý³ÌÄڴ棬£¬´ÓÓëÔÆÌṩÉÌ¡¢¡¢¡¢¼ÓÃÜÇ®±Ò´ú±ÒºÍÐÂÎÅ´«µÝÀûÓ÷¨Ê½¹ØÁªµÄ100¶à¸öÎļþõè¾¶ÖÐÍøÂçÍ´´¦¡£¡£


https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/