ÃÀµÂ¼ÓÁªºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç

Ðû²¼Ê±¼ä 2026-03-23

1. ÃÀµÂ¼ÓÁªºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç


3ÔÂ20ÈÕ£¬£¬£¬£¬ÃÀ¹ú¡¢µÂ¹úºÍ¼ÓÄôóÖ´·¨²¿·Ö¿ËÈÕÁªºÏ½ÓÄÉÐж¯£¬£¬£¬£¬µ·»ÙÁËAisuru¡¢KimWolf¡¢JackSkidºÍMossadËÄ´ó½©Ê¬ÍøÂçÓÃÓÚѬȾÎïÁªÍø(IoT)×°±¸µÄÏÂÁî¿ØÖÆ(C2)»ù´¡ÉèÊ©¡£¡£¡£¡£¡£´Ë´ÎÁªºÏÖ´·¨Ðж¯»¹Õë¶ÔÐéÄâЧÀÍÆ÷¡¢»¥ÁªÍøÓòÃû¼°ÆäËû»ù´¡ÉèÊ©£¬£¬£¬£¬ÕâЩÉèÊ©±»ËÄ´ó½©Ê¬ÍøÂçÓÃÓÚ½ü¼¸¸öÔ¶ÔÈ«ÇòÊܺ¦ÕßÌᳫÊýÊ®Íò´Î´ó¹æÄ£ÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷¡£¡£¡£¡£¡£ÃÀ¹ú˾·¨²¿ÌåÏÖ£¬£¬£¬£¬´Ë´ÎÐж¯Ö¼ÔÚÆÆËðÓëËÄ´ó½©Ê¬ÍøÂçÏà¹ØµÄͨѶ£¬£¬£¬£¬±ÜÃâ×°±¸½øÒ»²½Ñ¬È¾£¬£¬£¬£¬²¢ÏÞÖÆ»òÏû³ý½©Ê¬ÍøÂçÌᳫδÀ´¹¥»÷µÄÄÜÁ¦¡£¡£¡£¡£¡£·¨ÔºÎļþÖ¸¿Ø£¬£¬£¬£¬Aisuru½©Ê¬ÍøÂçÐû²¼ÁËÁè¼Ý20Íò´ÎDDoS¹¥»÷ÏÂÁ£¬£¬£¬KimWolfÐû²¼ÁËÁè¼Ý2.5Íò´Î£¬£¬£¬£¬JackSkidÐû²¼ÁËÁè¼Ý9Íò´Î£¬£¬£¬£¬MossadÐû²¼ÁËÁè¼Ý1000´Î¡£¡£¡£¡£¡£Æ¾Ö¤ÃÀ¹ú˾·¨²¿Êý¾Ý£¬£¬£¬£¬ÕâЩ½©Ê¬ÍøÂ繲ѬȾ²¢¿ØÖÆÁËÁè¼Ý300Íǫ̀IoT×°±¸£¬£¬£¬£¬°üÀ¨ÍøÂçÉãÏñÍ·¡¢Êý×ÖÊÓÆµÂ¼Ïñ»úºÍWiFi·ÓÉÆ÷£¬£¬£¬£¬ÆäÖÐÐí¶à×°±¸Î»ÓÚÃÀ¹ú¡£¡£¡£¡£¡£½©Ê¬ÍøÂçÔËÓªÕßÒÔÍøÂç·¸·¨¼´Ð§ÀÍģʽÏòÆäËûÍøÂç×ï·¸³öÊÛ»á¼ûȨÏÞ£¬£¬£¬£¬Ê¹ÆäÄܹ»ÌᳫDDoS¹¥»÷£¬£¬£¬£¬Ôì³ÉÊýÍòÃÀÔªËðʧºÍµ÷½â±¾Ç®¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/aisuru-kimwolf-jackskid-and-mossad-botnets-disrupted-in-joint-action/


2. IntoxalockÔâÍøÂç¹¥»÷ÖÂÈ«ÃÀ˾»úÎÞ·¨Æô¶¯³µÁ¾


3ÔÂ20ÈÕ£¬£¬£¬£¬ÃÀ¹ú³µÁ¾¾Æ¾«²âÊÔÒǹ«Ë¾Intoxalock¿ËÈÕÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬µ¼ÖÂÈ«ÃÀ¸÷µØË¾»úÎÞ·¨Æô¶¯³µÁ¾¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ3ÔÂ14ÈÕÔÚÆäÍøÕ¾ÉÏÈ·ÈÏÕýÂÄÀúÍ£»£»£»£»£»£»£»ú£¬£¬£¬£¬ÆäÏúÊ۵ľƾ«²âÊÔÒÇ×°±¸Ðè×°ÖÃÔÚ³µÁ¾È¼ÉÕ¿ª¹ØÉÏ£¬£¬£¬£¬±»ÒªÇóÌṩÒõÐԾƾ«ºôÆøÑù±¾²Å»ªÆô¶¯Æû³µµÄÓû§ÒÀÀµ¸Ã×°±¸¡£¡£¡£¡£¡£Intoxalock½²»°ÈËRachael LarsonÏòýÌåÈ·ÈϹ«Ë¾ÔâÊÜÍøÂç¹¥»÷£¬£¬£¬£¬²¢ÌåÏÖÒѽÓÄɲ½·¥"ÔÝʱÔÝÍ£²¿·Öϵͳ×÷ΪԤ·À²½·¥"¡£¡£¡£¡£¡£¹«Ë¾Î´Í¸Â¶¹¥»÷ÀàÐÍ£¬£¬£¬£¬ÈçÊÇ·ñΪÀÕË÷Èí¼þ»òÊý¾Ýй¶£¬£¬£¬£¬Ò²Î´ËµÃ÷ÊÇ·ñÊÕµ½ºÚ¿ÍͨѶ»òÊê½ðÒªÇ󡣡£¡£¡£¡£ÕâЩ¾Æ¾«²âÊÔÒÇ×°±¸Ðèÿ¸ô¼¸¸öÔÂУ׼һ´Î£¬£¬£¬£¬µ«ÍøÂç¹¥»÷µ¼ÖÂIntoxalockÎÞ·¨Ö´ÐÐУ׼¡£¡£¡£¡£¡£¹«Ë¾ÌåÏÖÐèҪУ׼װ±¸µÄ¿Í»§ÔÚÆô¶¯³µÁ¾Ê±¿ÉÄÜÓöµ½ÑÓ³Ù¡£¡£¡£¡£¡£ÔÚRedditÉÏ·¢ÌûµÄ˾»úÌåÏÖ£¬£¬£¬£¬ÈôÊÇ´í¹ýУ׼£¬£¬£¬£¬³µÁ¾½«ÎÞ·¨Æô¶¯£¬£¬£¬£¬ÏÖʵÉϽ«Ë¾»úËøÔÚ³µÍâ¡£¡£¡£¡£¡£


https://techcrunch.com/2026/03/20/cyberattack-on-vehicle-breathalyzer-company-leaves-drivers-stranded-across-the-us/


3. OracleÐû²¼½ôÆÈ²¹¶¡ÐÞ¸´Òªº¦Ô¶³Ì´úÂëÖ´ÐÐÎó²î


3ÔÂ20ÈÕ£¬£¬£¬£¬Oracle¿ËÈÕÐû²¼´øÍâÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´Éí·ÝÖÎÀíÆ÷ºÍWebЧÀÍÖÎÀíÆ÷ÖбàºÅΪCVE-2026-21992µÄÒªº¦Î´ÈÏÖ¤Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îCVSSv3.1ÑÏÖØÐÔÆÀ·ÖΪ9.8£¬£¬£¬£¬Ó°ÏìOracleIdentityManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0£¬£¬£¬£¬ÒÔ¼°OracleWebServicesManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0¡£¡£¡£¡£¡£OracleÔÚ×òÈÕÐû²¼µÄÇå¾²×ÉѯÖÐÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÓ¦Óò¹¶¡¡£¡£¡£¡£¡£×Éѯָ³ö£¬£¬£¬£¬¸ÃÎó²î¿ÉÔ¶³ÌʹÓÃÇÒÎÞÐèÉí·ÝÑéÖ¤£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Îó²îÖØÆ¯ºóµÍ£¬£¬£¬£¬¿Éͨ¹ýHTTPÔ¶³ÌʹÓ㬣¬£¬£¬ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥£¬£¬£¬£¬ÔöÌíÁË̻¶ЧÀÍÆ÷±»Ê¹ÓõÄΣº¦¡£¡£¡£¡£¡£OracleIdentityManagerÓÃÓÚÖÎÀíÆóÒµÄÚµÄÉí·ÝºÍ»á¼û£¬£¬£¬£¬OracleWebServicesManagerΪWebЧÀÍÌṩÇå¾²ºÍÖÎÀí¿ØÖÆ¡£¡£¡£¡£¡£ÕâÁ½¿î²úÆ·ÆÕ±éÓ¦ÓÃÓÚÆóÒµÉí·ÝÈÏÖ¤ºÍ»á¼ûÖÎÀí³¡¾°£¬£¬£¬£¬Îó²îÈô±»Ê¹ÓÿÉÄܵ¼Ö¹¥»÷ÕßÍêÈ«¿ØÖÆÊÜÓ°Ïìϵͳ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/


4. ¼ÓÖݸ£Ë¹ÌسÇÔâÀÕË÷¹¥»÷ÔÝÍ£¹«¹²Ð§ÀÍ


3ÔÂ21ÈÕ£¬£¬£¬£¬¼ÓÖݸ£Ë¹ÌسǿËÈÕÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬±»ÆÈÔÝÍ£³ý½ôÆÈÏìÓ¦ÍâµÄËùÓй«¹²Ð§ÀÍ¡£¡£¡£¡£¡£Õâ×ùλÓھɽðɽÍåÇø¡¢ÓµÓÐÔ¼34,000Éú³ÝµÄ¶¼»á£¬£¬£¬£¬Æä¶¼»á˾ÀíÐû²¼½øÈë½ôÆÈ״̬£¬£¬£¬£¬ÒÔ½âËøÀ´×ÔÍⲿ»ú¹¹µÄÔö²¹²ÆÎñÖ§³Ö¡£¡£¡£¡£¡£¶¼»á˾ÀíStefan ChatwinÌåÏÖ£º"¹«ÖÚÇå¾²ÊÇ918²©ÌìÌÃ×î¸ßÓÅÏȼ¶£¬£¬£¬£¬Òò´ËÎÒÃÇÃãÀøÉçÇø³ÉÔ±½ÓÄÉ×îÄÜÈ·±£Ð¡ÎÒ˽¼ÒÐÅÏ¢Çå¾²µÄÔ¤·À²½·¥¡£¡£¡£¡£¡£"ÊÐÕþ¸®ÖÒÑÔºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡¹«¹²ÐÅÏ¢£¬£¬£¬£¬±Þ²ßÈκÎÓëÊÐÕþ¸®ÓÐÓªÒµÍùÀ´µÄÖ°Ô±¸ü¸ÄСÎÒ˽¼ÒÃÜÂë²¢½ÓÄɲ½·¥±£»£»£»£»£»£»£»¤Ð¡ÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£ÊÐÕþ¸®ÌåÏÖ911ºÍ¾¯Ô±µ÷ÀíµÈ½ôÆÈЧÀÍ"¹¦Ð§Õý³£ÇÒδÊÜÓ°Ïì"£¬£¬£¬£¬µ«¸£Ë¹ÌسǾ¯Ô±¾ÖÖÜÎåÍí¼ä·¢³ö֪ͨ³Æ£¬£¬£¬£¬Æä·Ç½ôÆÈÈÈÏߺͽôÆÈÖ±²¦Ïß·ÔÚÔÝʱÖÐÖ¹ºó"Òѻָ´ÔËÐÐ"¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷£¬£¬£¬£¬ÊÐÒé»á¾Û»á½«½öÒÔÏÖ³¡·½·¨¾ÙÐУ¬£¬£¬£¬²»ÔÙͨ¹ýZoomÌṩ¡£¡£¡£¡£¡£


https://therecord.media/california-city-reports-ransomware-attack-la-metro


5. LAPSUS$Éù³ÆÇÔÈ¡°¢Ë¹Àû¿µ3GBÄÚ²¿Êý¾Ý


3ÔÂ20ÈÕ£¬£¬£¬£¬×Ô³Æ"LAPSUS$"µÄÍþвÐÐΪÕß×éÖ¯¿ËÈÕÉù³Æ¶ÔÉæ¼°°¢Ë¹Àû¿µ(AstraZeneca)µÄÊý¾Ýй¶ÊÂÎñÈÏÕæ¡£¡£¡£¡£¡£°¢Ë¹Àû¿µÊÇÈ«Çò×î´óµÄ¿ç¹úÖÆÒ©ºÍÉúÎïÊÖÒÕ¹«Ë¾Ö®Ò»¡£¡£¡£¡£¡£Æ¾Ö¤ÔÚºÚ¿ÍÂÛ̳ºÍ¸Ã×éÖ¯¹Ù·½ÍøÕ¾ÉÏÐû²¼µÄÌû×Ó£¬£¬£¬£¬¹¥»÷ÕßÉù³Æ»á¼ûÁËÔ±¹¤Ïà¹ØÊý¾Ý¼¯¡¢ÍêÕûÔ´´úÂë¡¢ÉñÃØºÍ»á¼ûƾ֤¡¢ÔÆ»ù´¡ÉèÊ©ÉèÖõȡ£¡£¡£¡£¡£Ìû×Ó°üÀ¨¶Ô.tar.gzÃûÌÿÉÏÂÔØµµ°¸µÄÒýÓ㬣¬£¬£¬×ÜÊý¾ÝÁ¿Ô¼3GB¡£¡£¡£¡£¡£ºÚ¿ÍÕýÊÔͼ½«Êý¾Ý³öÊÛ¸ø³ö¼Û×î¸ßÕߣ¬£¬£¬£¬²¢·ÖÏíÁËÑù±¾ÎļþÒÔÖ§³ÖÆäÉù³Æ¡£¡£¡£¡£¡£Ñù±¾Êý¾ÝÆÊÎöÏÔʾ£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÖ÷Òª·ÖΪÈýÀࣺGitHubÏà¹ØÊý¾Ý¡¢µÚÈý·½Êý¾ÝºÍ²ÆÎñÊý¾Ý¡£¡£¡£¡£¡£GitHubÆóÒµÓû§Êý¾Ý°üÀ¨Ô±¹¤ÐÕÃû¡¢±¾Ç®ÖÐÐIJο¼¡¢ÔÊÐíÖ¤ÀàÐÍ¡¢ÆóÒµ½ÇÉ«ºÍȨÏÞ¡¢Ë«ÒòËØÉí·ÝÑé֤״̬¡¢GitHubÓû§ÃûºÍÉèÖÃÎļþURL¡¢×éÖ¯½ÇÉ«µÈÐÅÏ¢¡£¡£¡£¡£¡£µÚÈý·½Êý¾ÝËÆºõ¸ú×ÙÍⲿÏàÖúÕߵĻá¼ûÇëÇóºÍÈëÖ°ÐÅÏ¢£¬£¬£¬£¬°üÀ¨ÄÚ²¿Óû§ID¡¢È«ÃûºÍµç×ÓÓʼþµØµã¡¢ÄÚ²¿ÍŶÓ̸ÂÛ¡¢¹«Ë¾Á¥Êô¹ØÏµ¡¢ÄÚ²¿ÏµÍ³»á¼û״̬¡£¡£¡£¡£¡£²ÆÎñÊý¾Ý°üÀ¨¸ß¼¶±ð²ÆÎñͳ¼Æ£¬£¬£¬£¬±êΪ"ËùÓÐÐÐÒµ"£¬£¬£¬£¬ËƺõÊǹ«¹²»òͨÓÃͳ¼ÆÐÅÏ¢£¬£¬£¬£¬Ó밢˹Àû¿µÔËÓªÎÞÖ±½Ó¹ØÁª¡£¡£¡£¡£¡£


https://hackread.com/hacker-group-lapsus-astrazeneca-data-breach/


6. TrivyÎó²îɨÃèÆ÷Ô⹩ӦÁ´¹¥»÷·Ö·¢ÇÔÃܶñÒâÈí¼þ


3ÔÂ21ÈÕ£¬£¬£¬£¬×ÅÃûÎó²îɨÃèÆ÷Trivy¿ËÈÕÔâÊܹ©Ó¦Á´¹¥»÷£¬£¬£¬£¬ÍþвÐÐΪÕß×éÖ¯TeamPCPͨ¹ý¹Ù·½Ðû²¼°æ±¾ºÍGitHubActions·Ö·¢Æ¾Ö¤ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£´Ë´Îй¶ÓÉÇå¾²Ñо¿Ô±PaulMcCartyÊ×´ÎÅû¶£¬£¬£¬£¬ÖÒÑÔTrivy0.69.4°æ±¾±»Ö²ÈëºóÃÅ£¬£¬£¬£¬¶ñÒâÈÝÆ÷¾µÏñºÍGitHubÐû²¼°æ±¾±»·Ö·¢¸øÓû§¡£¡£¡£¡£¡£¹¥»÷Õß¹¥ÏÝÁËTrivyµÄGitHub¹¹½¨Á÷³Ì£¬£¬£¬£¬½«GitHubActionsÖеÄentrypoint.shÌæ»»Îª¶ñÒâ°æ±¾£¬£¬£¬£¬²¢ÔÚTrivyv0.69.4Ðû²¼°æ±¾ÖÐÐû²¼±»Ö²ÈëºóÃŵĶþ½øÖÆÎļþ¡£¡£¡£¡£¡£¹¥»÷ÕßÀÄÓþßÓпÍջдÈëȨÏÞµÄÊÜËðƾ֤Ðû²¼¶ñÒâÐû²¼°æ±¾£¬£¬£¬£¬ÕâЩƾ֤À´×Ô3ÔÂÔçЩʱ¼äµÄй¶ÊÂÎñ£¬£¬£¬£¬Æäʱƾ֤´ÓTrivyÇéÐα»ÍâйÇÒδÍêÈ«¿ØÖÆ¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÇ¿ÖÆÍÆËÍÁËaquasecurity/trivy-action¿ÍÕ»76¸ö±êÇ©ÖеÄ75¸ö£¬£¬£¬£¬½«ÆäÖØ¶¨Ïòµ½¶ñÒâÌá½»¡£¡£¡£¡£¡£Ê¹ÓÃÊÜÓ°Ïì±êÇ©µÄÍⲿÊÂÇéÁ÷»áÔÚÔËÐÐÕýµ±TrivyɨÃè֮ǰ×Ô¶¯Ö´ÐжñÒâ´úÂ룬£¬£¬£¬Ê¹ÈëÇÖÄÑÒÔ¼ì²â¡£¡£¡£¡£¡£¶ñÒâÈí¼þÍøÂçÕì̽Êý¾Ý²¢É¨ÃèϵͳÖд洢ƾ֤ºÍÈÏÖ¤ÉñÃØµÄÎļþ£¬£¬£¬£¬ÍøÂçµÄÊý¾Ý±»¼ÓÃÜ´æ´¢ÔÚÃûΪtpcp.tar.gzµÄµµ°¸ÖУ¬£¬£¬£¬ÍâйÖÁÓòÃûɨÃè.aquasecurtiy[.]org¡£¡£¡£¡£¡£ÈôÍâйʧ°Ü£¬£¬£¬£¬¶ñÒâÈí¼þ»áÔÚÊܺ¦ÕßGitHubÕË»§Öн¨ÉèÃûΪtpcp-docsµÄ¹«¹²¿ÍÕ»²¢ÉÏ´«ÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/trivy-vulnerability-scanner-breach-pushed-infostealer-via-github-actions/