ÃÀµÂ¼Ó½áºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç

°ä²¼¹¦·ò 2026-03-23

1. ÃÀµÂ¼Ó½áºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç


3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬ÃÀ¹ú¡¢µÂ¹úºÍ¼ÓÄôó·¨Âɲ¿ÃŽüÈÕ½áºÏ²ÉÈ¡Ðж¯£¬£¬£¬£¬£¬£¬ £¬£¬µ·»ÙÁËAisuru¡¢KimWolf¡¢JackSkidºÍMossadËÄ´ó½©Ê¬ÍøÂçÓÃÓÚϰȾÎïÁªÍø(IoT)É豸µÄºÅÁî½ÚÔì(C2)»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£Õâ´Î½áºÏ·¨ÂÉÐж¯»¹Õë¶ÔÐé¹¹·þÎñÆ÷¡¢»¥ÁªÍøÓòÃû¼°ÆäËû»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬ £¬£¬ÕâЩÉèÊ©±»ËÄ´ó½©Ê¬ÍøÂçÓÃÓÚ½ü¼¸¸öÔ¶ÔÈ«ÇòÊܺ¦ÕßÌáÒéÊýÊ®Íò´Î´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷¡£¡£¡£¡£¡£¡£ÃÀ¹ú˾·¨²¿°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬Õâ´ÎÐж¯Ö¼ÔÚ·ÛËéÓëËÄ´ó½©Ê¬ÍøÂçÓйصÄͨѶ£¬£¬£¬£¬£¬£¬ £¬£¬Ô¤·ÀÉ豸½øÒ»²½Ï°È¾£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÏÞ¶È»ò½â³ý½©Ê¬ÍøÂçÌáÒ齫À´¹¥»÷µÄÄÜÁ¦¡£¡£¡£¡£¡£¡£·¨ÔºÎļþÖ¸¿Ø£¬£¬£¬£¬£¬£¬ £¬£¬Aisuru½©Ê¬ÍøÂç°ä²¼Á˳¬¹ý20Íò´ÎDDoS¹¥»÷ºÅÁ£¬£¬£¬£¬£¬ £¬£¬KimWolf°ä²¼Á˳¬¹ý2.5Íò´Î£¬£¬£¬£¬£¬£¬ £¬£¬JackSkid°ä²¼Á˳¬¹ý9Íò´Î£¬£¬£¬£¬£¬£¬ £¬£¬Mossad°ä²¼Á˳¬¹ý1000´Î¡£¡£¡£¡£¡£¡£Æ¾¾ÝÃÀ¹ú˾·¨²¿Êý¾Ý£¬£¬£¬£¬£¬£¬ £¬£¬ÕâЩ½©Ê¬ÍøÂ繲ϰȾ²¢½ÚÔìÁ˳¬¹ý300Íǫ̀IoTÉ豸£¬£¬£¬£¬£¬£¬ £¬£¬Ô̺¬ÍøÂçÉãÏñÍ·¡¢Êý×ÖÊÓÆµÂ¼Ïñ»úºÍWiFi·ÓÉÆ÷£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÖкܶàÉ豸λÓÚÃÀ¹ú¡£¡£¡£¡£¡£¡£½©Ê¬ÍøÂçÔËÓªÕßÒÔÍøÂç·¸×ï¼´·þÎñģʽÏòÆäËûÍøÂç×ï·¸ÏúÊÛ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬ £¬£¬Ê¹Æä¿ÉÄÜÌáÒéDDoS¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬Ôì³ÉÊýÍòÃÀÔªËðʧºÍ²¹¾È³É±¾¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/aisuru-kimwolf-jackskid-and-mossad-botnets-disrupted-in-joint-action/


2. IntoxalockÔâÍøÂç¹¥»÷ÖÂÈ«ÃÀ˾»úÎÞ·¨Æô¶¯³µÁ¾


3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬ÃÀ¹ú³µÁ¾¾Æ¾«²âÊÔÒǹ«Ë¾Intoxalock½üÈÕÔâ·êÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬µ¼ÖÂÈ«ÃÀ¸÷µØË¾»úÎÞ·¨Æô¶¯³µÁ¾¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ3ÔÂ14ÈÕÔÚÆäÍøÕ¾ÉÏÈ·ÈÏÕý¾­ÀúÍ£»£»£»£»£»£»£»£»ú£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÏúÊ۵ľƾ«²âÊÔÒÇÉ豸Ðè×°ÖÃÔÚ³µÁ¾µã»ð¿ª¹ØÉÏ£¬£¬£¬£¬£¬£¬ £¬£¬±»ÒªÇóÌṩÒõÐԾƾ«ºôÆøÑù±¾ÄÜÁ¦Æô¶¯Æû³µµÄÓû§ÒÀÀµ¸ÃÉ豸¡£¡£¡£¡£¡£¡£Intoxalock½²»°ÈËRachael LarsonÏòýÌåÈ·ÈϹ«Ë¾Ôâ·êÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬²¢°µÊ¾ÒѲÉÈ¡´ëÊ©"ÁÙʱÔÝÍ£²¿ÃÅϵͳ×÷ΪԤ·À´ëÊ©"¡£¡£¡£¡£¡£¡£¹«Ë¾Î´Ð¹Â©¹¥»÷ÀàÐÍ£¬£¬£¬£¬£¬£¬ £¬£¬ÈçÊÇ·ñΪÀÕË÷Èí¼þ»òÊý¾Ýй¶£¬£¬£¬£¬£¬£¬ £¬£¬Ò²Î´×¢Ã÷ÊÇ·ñÊÕµ½ºÚ¿ÍͨѶ»òÊê½ðÒªÇ󡣡£¡£¡£¡£¡£ÕâЩ¾Æ¾«²âÊÔÒÇÉ豸Ðèÿ¸ô¼¸¸öÔÂУ׼һ´Î£¬£¬£¬£¬£¬£¬ £¬£¬µ«ÍøÂç¹¥»÷µ¼ÖÂIntoxalockÎÞ·¨Ö´ÐÐУ׼¡£¡£¡£¡£¡£¡£¹«Ë¾°µÊ¾±ØÒªÐ£×¼É豸µÄ¿Í»§ÔÚÆô¶¯³µÁ¾Ê±¿ÉÄÜÓöµ½ÑÓ³¤¡£¡£¡£¡£¡£¡£ÔÚRedditÉÏ·¢ÌûµÄ˾»ú°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬ÈôÊÇ´í¹ýУ׼£¬£¬£¬£¬£¬£¬ £¬£¬³µÁ¾½«ÎÞ·¨Æô¶¯£¬£¬£¬£¬£¬£¬ £¬£¬ÏÖʵ´ó½«Ë¾»úËøÔÚ³µ±í¡£¡£¡£¡£¡£¡£


https://techcrunch.com/2026/03/20/cyberattack-on-vehicle-breathalyzer-company-leaves-drivers-stranded-across-the-us/


3. Oracle°ä²¼´¹Î£²¹¶¡½¨¸´¹Ø¼üÔ¶³Ì´úÂëÖ´Ðзì϶


3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬Oracle½üÈÕ°ä²¼´ø±í°²È«¸üУ¬£¬£¬£¬£¬£¬ £¬£¬½¨¸´Éí·ÝÖÎÀíÆ÷ºÍWeb·þÎñÖÎÀíÆ÷ÖбàºÅΪCVE-2026-21992µÄ¹Ø¼üδÈÏÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶CVSSv3.1ÑϳÁÐÔÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìOracleIdentityManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0£¬£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°OracleWebServicesManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0¡£¡£¡£¡£¡£¡£OracleÔÚ×òÈÕ°ä²¼µÄ°²È«Õ÷ѯÖÐÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÀûÓò¹¶¡¡£¡£¡£¡£¡£¡£Õ÷ѯָ³ö£¬£¬£¬£¬£¬£¬ £¬£¬¸Ã·ì϶¿ÉÔ¶³ÌÀûÓÃÇÒÎÞÐèÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ £¬£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£·ì϶¸´ÔӶȵͣ¬£¬£¬£¬£¬£¬ £¬£¬¿Éͨ¹ýHTTPÔ¶³ÌÀûÓ㬣¬£¬£¬£¬£¬ £¬£¬ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥£¬£¬£¬£¬£¬£¬ £¬£¬Ôö³¤Á˶³ö·þÎñÆ÷±»ÀûÓõķçÏÕ¡£¡£¡£¡£¡£¡£OracleIdentityManagerÓÃÓÚÖÎÀíÆóÒµÄÚµÄÉí·ÝºÍ½Ó¼û£¬£¬£¬£¬£¬£¬ £¬£¬OracleWebServicesManagerΪWeb·þÎñÌṩ°²È«ºÍÖÎÀí½ÚÔì¡£¡£¡£¡£¡£¡£ÕâÁ½¿î²úÆ·¿í·ºÀûÓÃÓÚÆóÒµÉí·ÝÈÏÖ¤ºÍ½Ó¼ûÖÎÀí³¡¾°£¬£¬£¬£¬£¬£¬ £¬£¬·ì϶Èô±»ÀûÓÿÉÄܵ¼Ö¹¥»÷Õ߯ëÈ«½ÚÔìÊÜÓ°Ïìϵͳ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/


4. ¼ÓÖݸ£Ë¹ÌسÇÔâÀÕË÷¹¥»÷ÔÝÍ£¹«¹²·þÎñ


3ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬¼ÓÖݸ£Ë¹ÌسǽüÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬±»ÆÈÔÝÍ£³ý´¹Î£ÏìÓ¦±íµÄËùÓй«¹²·þÎñ¡£¡£¡£¡£¡£¡£Õâ×ùλÓھɽðɽÍåÇø¡¢Õ¼ÓÐÔ¼34,000È˶¡µÄ³ÇÊУ¬£¬£¬£¬£¬£¬ £¬£¬Æä³ÇÊо­Àí°ä·¢½øÈ봹Σ״̬£¬£¬£¬£¬£¬£¬ £¬£¬ÒÔ½âËøÀ´×Ô±í²¿»ú¹¹µÄ²¹³ä²ÆÕþÖ§³Ö¡£¡£¡£¡£¡£¡£³ÇÊо­ÀíStefan Chatwin°µÊ¾£º"¹«¼Ò°²ÂúÊÇ8827Ì«Ñô¼¯ÍÅ×î¸ßÓÅÏȼ¶£¬£¬£¬£¬£¬£¬ £¬£¬Òò¶øÎÒÃǼ¤ÀøÉçÇø³ÉÔ±²ÉÈ¡×îÄÜÈ·±£Ó×ÎÒÐÅÏ¢°²È«µÄÔ¤·À´ëÊ©¡£¡£¡£¡£¡£¡£"Êе±¾ÖÖÒ¸æºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡¹«¹²ÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬£¬¶½´ÙÈκÎÓëÊе±¾ÖÓÐÒµÎñÍùÀ´µÄÈËÔ±¸ü¸ÄÓ×ÎÒÃÜÂë²¢²ÉÈ¡´ëÊ©±£»£»£»£»£»£»£»£»¤Ó×ÎÒÊý¾Ý¡£¡£¡£¡£¡£¡£Êе±¾Ö°µÊ¾911ºÍ¾¯Ô±µ÷¶ÈµÈ´¹Î£·þÎñ"Ö°ÄÜÕý³£ÇÒδÊÜÓ°Ïì"£¬£¬£¬£¬£¬£¬ £¬£¬µ«¸£Ë¹ÌسǾ¯Ô±¾ÖÖÜÎåÍí¼ä·¢³ö֪ͨ³Æ£¬£¬£¬£¬£¬£¬ £¬£¬Æä·Ç´¹Î£ÈÈÏߺʹ¹Î£Ö±²¦Ïß·ÔÚÁÙʱÖжϺó"ÒѸ´Ô­ÔËÐÐ"¡£¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬ÊÐÒé»á»áÒ齫½öÒÔÏÖ³¡·½Ê½½øÐУ¬£¬£¬£¬£¬£¬ £¬£¬²»ÔÙͨ¹ýZoomÌṩ¡£¡£¡£¡£¡£¡£


https://therecord.media/california-city-reports-ransomware-attack-la-metro


5. LAPSUS$Ðû³ÆÇÔÈ¡°¢Ë¹Àû¿µ3GBÄÚ²¿Êý¾Ý


3ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬×Ô³Æ"LAPSUS$"µÄÍþвÐÐΪÕß×éÖ¯½üÈÕÐû³Æ¶ÔÉæ¼°°¢Ë¹Àû¿µ(AstraZeneca)µÄÊý¾Ýй¶ÊÂÎñÕÆ¹Ü¡£¡£¡£¡£¡£¡£°¢Ë¹Àû¿µÊÇÈ«Çò×î´óµÄ¿ç¹úÔìÒ©ºÍÉúÎï¼¼Êõ¹«Ë¾Ö®Ò»¡£¡£¡£¡£¡£¡£Æ¾¾ÝÔÚºÚ¿ÍÂÛ̳ºÍ¸Ã×éÖ¯¹Ù·½ÍøÕ¾Éϰ䲼µÄÌû×Ó£¬£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÐû³Æ½Ó¼ûÁËÔ±¹¤ÓйØÊý¾Ý¼¯¡¢ÆëȫԴ´úÂë¡¢°ÂÃØºÍ½Ó¼ûÍ´´¦¡¢ÔÆ»ù´¡ÉèÊ©ÅäÖõÈ¡£¡£¡£¡£¡£¡£Ìû×ÓÔ̺¬¶Ô.tar.gzÌåʽ¿ÉÏÂÔØµµ°¸µÄÒýÓ㬣¬£¬£¬£¬£¬ £¬£¬×ÜÊý¾ÝÁ¿Ô¼3GB¡£¡£¡£¡£¡£¡£ºÚ¿ÍÕýÊÔͼ½«Êý¾ÝÏúÊÛ¸ø³ö¼Û×î¸ßÕߣ¬£¬£¬£¬£¬£¬ £¬£¬²¢·ÖÏíÁËÑù±¾ÎļþÒÔÖ§³ÔìäÐû³Æ¡£¡£¡£¡£¡£¡£Ñù±¾Êý¾Ý·ÖÎöÏÔʾ£¬£¬£¬£¬£¬£¬ £¬£¬Ð¹Â¶Êý¾ÝÖØÒª·ÖΪÈýÀࣺGitHubÓйØÊý¾Ý¡¢µÚÈý·½Êý¾ÝºÍ²ÆÕþÊý¾Ý¡£¡£¡£¡£¡£¡£GitHubÆóÒµÓû§Êý¾ÝÔ̺¬Ô±¹¤ÐÕÃû¡¢³É±¾ÖÐÐIJο¼¡¢Ðí¿ÉÖ¤ÀàÐÍ¡¢ÆóÒµ½ÇÉ«ºÍȨÏÞ¡¢Ë«³É·ÖÉí·ÝÑé֤״̬¡¢GitHubÓû§ÃûºÍÅäÖÃÎļþURL¡¢×éÖ¯½ÇÉ«µÈÐÅÏ¢¡£¡£¡£¡£¡£¡£µÚÈý·½Êý¾ÝËÆºõ¸ú×Ù±í²¿ºÏ×÷ÕߵĽӼûÒªÇóºÍÈëÖ°ÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬£¬Ô̺¬ÄÚ²¿Óû§ID¡¢È«ÃûºÍµç×ÓÓʼþµØÖ·¡¢ÄÚ²¿ÍŶӯÀÂÛ¡¢¹«Ë¾´ÓÊô¹ØÏµ¡¢ÄÚ²¿ÏµÍ³½Ó¼û״̬¡£¡£¡£¡£¡£¡£²ÆÕþÊý¾ÝÔ̺¬¸ß¼¶±ð²ÆÕþͳ¼Æ£¬£¬£¬£¬£¬£¬ £¬£¬±êΪ"ËùÓÐÐÐÒµ"£¬£¬£¬£¬£¬£¬ £¬£¬ËƺõÊǹ«¹²»òͨÓÃͳ¼ÆÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬£¬Ó밢˹Àû¿µÔËÓªÎÞÖ±½Ó¹ØÁª¡£¡£¡£¡£¡£¡£


https://hackread.com/hacker-group-lapsus-astrazeneca-data-breach/


6. Trivy·ì϶ɨÃèÆ÷Ô⹩¸øÁ´¹¥»÷·Ö·¢ÇÔÃܶñÒâÈí¼þ


3ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬³ÛÃû·ì϶ɨÃèÆ÷Trivy½üÈÕÔâ·ê¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬ÍþвÐÐΪÕß×éÖ¯TeamPCPͨ¹ý¹Ù·½°ä²¼°æ±¾ºÍGitHubActions·Ö·¢Æ¾Ö¤ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£Õâ´Îй¶Óɰ²È«×êÑÐÔ±PaulMcCarty³õ´ÎÅû¶£¬£¬£¬£¬£¬£¬ £¬£¬ÖÒ¸æTrivy0.69.4°æ±¾±»Ö²ÈëºóÃÅ£¬£¬£¬£¬£¬£¬ £¬£¬¶ñÒâÈÝÆ÷¾µÏñºÍGitHub°ä²¼°æ±¾±»·Ö·¢¸øÓû§¡£¡£¡£¡£¡£¡£¹¥»÷Õß¹¥ÏÂÁËTrivyµÄGitHub¹¹½¨Á÷³Ì£¬£¬£¬£¬£¬£¬ £¬£¬½«GitHubActionsÖеÄentrypoint.sh´úÌæÎª¶ñÒâ°æ±¾£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÔÚTrivyv0.69.4°ä²¼°æ±¾Öа䲼±»Ö²ÈëºóÃŵĶþ½øÔìÎļþ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀÄÆ÷ÓµÓвֿâдÈëȨÏÞµÄÊÜËðÍ´´¦°ä²¼¶ñÒâ°ä²¼°æ±¾£¬£¬£¬£¬£¬£¬ £¬£¬ÕâЩʹ´¦À´×Ô3ÔÂÔçЩʱ³½µÄй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬ £¬£¬Æäʱʹ´¦´ÓTrivy»·¾³±»±íйÇÒδÆëÈ«½ÚÔì¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÇ¿ÔìÍÆËÍÁËaquasecurity/trivy-action²Ö¿â76¸ö±êÇ©ÖеÄ75¸ö£¬£¬£¬£¬£¬£¬ £¬£¬½«Æä³Á¶¨Ïòµ½¶ñÒâÌá½»¡£¡£¡£¡£¡£¡£Ê¹ÓÃÊÜÓ°Ïì±êÇ©µÄ±í²¿¹¤×÷Á÷»áÔÚÔËÐкϷ¨TrivyɨÃè֮ǰ×Ô¶¯Ö´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬ £¬£¬Ê¹ÈëÇÖÄÑÒÔ¼ì²â¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þÍøÂç¿úËÅÊý¾Ý²¢É¨ÃèϵͳÖд洢ƾ֤ºÍÈÏÖ¤°ÂÃØµÄÎļþ£¬£¬£¬£¬£¬£¬ £¬£¬ÍøÂçµÄÊý¾Ý±»¼ÓÃÜ´æ´¢ÔÚÃûΪtpcp.tar.gzµÄµµ°¸ÖУ¬£¬£¬£¬£¬£¬ £¬£¬±íйÖÁÓòÃûɨÃè.aquasecurtiy[.]org¡£¡£¡£¡£¡£¡£Èô±íйʧ°Ü£¬£¬£¬£¬£¬£¬ £¬£¬¶ñÒâÈí¼þ»áÔÚÊܺ¦ÕßGitHubÕË»§Öд´½¨ÃûΪtpcp-docsµÄ¹«¹²²Ö¿â²¢ÉÏ´«ÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/trivy-vulnerability-scanner-breach-pushed-infostealer-via-github-actions/