MedusaÀÕË÷Èí¼þ¹¥»÷ÃÜÎ÷Î÷±È×î´óÒ½Ôº

°ä²¼¹¦·ò 2026-03-19

1. MedusaÀÕË÷Èí¼þ¹¥»÷ÃÜÎ÷Î÷±È×î´óÒ½Ôº


3ÔÂ18ÈÕ£¬MedusaÀÕË÷Èí¼þÍÅ»ï½üÈÕÐû³Æ¶ÔÃÜÎ÷Î÷±ÈÖÝ×î´óÒ½ÔºÃÜÎ÷Î÷±È´óѧҽѧÖÐÐÄ£¨UMMC£©¼°ÐÂÔóÎ÷ÖÝÅÁÈû¿ËÏØµÄÍøÂç¹¥»÷ÕÆ¹Ü¡£¡£¸ÃÍŻﱻר¼ÒÒÔΪÔÚ¶íÂÞ˹¾³ÄÚÔËÓª£¬Ä¿Ç°ÒÑÏòÁ½¼Ò»ú¹¹±ðÀëË÷Òª80ÍòÃÀÔªÊê½ð¡£¡£UMMCÊÇÃÜÎ÷Î÷±ÈÖÝ×îÖØÒªµÄÒ½ÁÆ»ú¹¹£¬Õ¼ÓÐ1ÍòÃûÔ±¹¤£¬ÔËӪןÃÖÝΨһµÄ¶ùͯҽԺ¡¢¡¢¡¢Î¨ÖðÒ»¼¶´´ÉËÖÐÐÄ¡¢¡¢¡¢Î¨Ò»Ëļ¶ÐÂÉú¶ùÖØÖ¢¼à»¤ÊÒÒÔ¼°Î¨Ò»µÄÆ÷¹ÙÒÆÖ²ÏîÄ¿¡£¡£2Ôµ×£¬¸Ã»ú¹¹Ôâ·êÍøÂç¹¥»÷ºóÈ«ÃæÍ£°Ú9Ì죬ҽ»¤ÈËÔ±±»ÆÈʹÓ÷ÂÕÕ¹¤¾ß²Ù×÷¾«ÃÜϵͳ¡£¡£°©Ö¢ÊäÒºÖÐÐIJ»µÃ²»ÖØÐÂÆÌÅÅ»¼ÕßÔ¤Ô¼£¬ÆäËû¿ÆÊÒÖ»ÄÜÒÀ¸½Ö½±ÊÖÎÀíÎï×ʺÍÒ½ÖΡ£¡£UMMC¹Ø±ÕÁËÈ«Êý35¸öÕïËù£¬µ«Ò½ÔººÍ¼±ÕﲿÃÅά³ÖÔËÓª¡£¡£ÃÀ¹úÁª°îµ÷²é¾ÖºÍºÓɽ°²È«ÊýȾָЭÖú¸´Ô­¹¤×÷¡£¡£Ò½ÔºÓÚ3ÔÂ2ÈÕÈ«ÃæÖØÐÂÊ¢¿ª£¬MedusaÍÅ»ïËæºóÐû³Æ¶Ô´ËÕÆ¹Ü£¬ÍþвÓÚ3ÔÂ20ÈÕǰй¶´ÓÒ½ÔºÇÔÈ¡µÄÊý¾Ý¡£¡£UMMC½²»°È˻ؾø¾ÍÊê½ðÍþв°ä·¢ÆÀÂÛ¡£¡£ÅÁÈû¿ËÏØÕ¼Óнü60ÍòÈ˶¡£¬Á½ÖÜǰÔâ·ê¶ñÒâÈí¼þ¹¥»÷£¬µ±¾Ö°ì¹«Êҵ绰ÏߺÍITϵͳ̱»¾¡£¡£MedusaÍÅ»ïͬÑùÐû³Æ¶Ô´ËÕÆ¹Ü²¢Ë÷Òª80ÍòÃÀÔªÊê½ð¡£¡£


https://therecord.media/medusa-ransomware-mississippi-cyber


2. Éí·Ý±£»£»£»¤¹«Ë¾AuraÔâ´¹µö¹¥»÷й¶90ÍòÓû§Êý¾Ý


3ÔÂ18ÈÕ£¬Éí·Ý±£»£»£»¤¹«Ë¾Aura½üÈÕÈ·ÈÏ£¬Î´¾­ÊÚȨµÄµÚÈý·½Í¨¹ýÕë¶ÔÔ±¹¤µÄÓïÒô´¹µö¹¥»÷»ñÈ¡Á˽ü90ÍòÌõ¿Í»§¼Í¼£¬Ô̺¬ÐÕÃûºÍµç×ÓÓʼþµØÖ·µÈÃô¸ÐÐÅÏ¢¡£¡£¸Ã¹«Ë¾±¾ÖÜÏòÊÜÓ°ÏìÓû§·¢³ö֪ͨ£¬²¢°µÊ¾ÒÑ֪ͨ·¨Âɲ¿ÃÅ¡£¡£AuraÊÇÒ»¼ÒÏû·ÑÊý×Ö°²È«¹«Ë¾£¬ÏúÊÛÉí·Ý͵ÇÔ±£»£»£»¤¡¢¡¢¡¢ÐÅÓþºÍڲƭ¼à¿ØÒÔ¼°ÔÚÏß°²È«¹¤¾ß¡£¡£Õâ´Îй¶µÄÊý¾ÝÔ´×Ô2021ÄêÊÕ¹ºµÄÒ»¼Ò¹«Ë¾ËùʹÓõÄÓªÏú¹¤¾ß£¬Â¶³öÁËÔ¼20,000Ãûµ±Ç°¿Í»§ºÍ15,000Ãûǰ¿Í»§µÄÓÐÏÞÐÅÏ¢¡£¡£ÊÜÓ°ÏìµÄ¿Í»§ÐÅÏ¢Ô̺¬È«Ãû¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢¼ÒͥסַºÍµç»°ºÅÂë¡£¡£¹«Ë¾Ç¿µ÷£¬Éç»á°²È«ºÅÂë¡¢¡¢¡¢ÕË»§ÃÜÂëºÍ²ÆÕþÐÅϢδÊÜÓ°Ïì¡£¡£Íþв×éÖ¯ShinyHunters±¾ÖÜÔçЩʱ³½ÔÚÆäÊý¾ÝÀÕË÷ÍøÕ¾ÉÏÐû³Æ¶Ô´Ë¹¥»÷ÕÆ¹Ü£¬°µÊ¾ÇÔÈ¡ÁË12GBÔ̺¬¿Í»§Ð¡ÎÒÉí·ÝÐÅÏ¢(PII)¼°ÆóÒµÊý¾ÝµÄÎļþ¡£¡£HaveIBeenPwned(HIBP)·þÎñ·ÖÎöÁËй¶Êý¾Ý²¢½«ÆäÔö³¤µ½Êý¾Ý¿âÖУ¬Ö¸³ö¿Í»§·þÎñÆÀÂÛºÍIPµØÖ·Ò²±»Â¶³ö¡£¡£HIBP°µÊ¾£¬Õâ´ÎÊÂÎñÖж³öµÄ90%µç×ÓÓʼþµØÖ·ÒÑ´æÔÚÓÚÆä´Óǰ°²È«ÊÂÎñÊý¾Ý¿âÖС£¡£


https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/


3. CISA½«SharePointºÍZimbra·ì϶ÁÐÈëKEVĿ¼


3ÔÂ18ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö(CISA)½üÈÕ½«Î¢ÈíSharePointºÍSynacorZimbraºÏ×÷Ì×¼þµÄÁ½¸ö·ì϶Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶(KEV)Ŀ¼ÖС£¡£Æ¾¾ÝÔ¼Êø²Ù×÷Ö¸ÁîBOD22-01£¬Áª°îÃñÊ»ú¹¹±ØÐëÔÚ»®¶¨ÈÕÆÚǰÐÞ¸´ÕâЩ·ì϶£¬ÒÔ±£»£»£»¤ÍøÂçÃâÊÜÀûÓÃÕâЩ·ì϶µÄ¹¥»÷¡£¡£µÚÒ»¸ö·ì϶±àºÅΪCVE-2026-20963£¬CVSSÆÀ·ÖΪ8.8£¬ÊÇ΢ÈíOfficeSharePointÖеIJ»ÊÜÐÅÀµÊý¾Ý·´ÐòÁл¯·ì϶£¬ÔÊÐíÊÚȨ¹¥»÷ÕßÔÚÍøÂçÉÏÖ´ÐдúÂë¡£¡£CISAÒѺÅÁîÁª°î»ú¹¹ÔÚ2026Äê3ÔÂ21ÈÕǰÐÞ¸´´Ë·ì϶¡£¡£µÚ¶þ¸ö·ì϶±àºÅΪCVE-2025-66376£¬CVSSÆÀ·ÖΪ7.2£¬ÊǾ­µäÓû§½çÃæÖеĴ洢ÐÍ¿çÕ¾¾ç±¾(XSS)·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓõç×ÓÓʼþHTMLÖеÄCSS@importÖ¸Áî½øÐй¥»÷¡£¡£Áª°î»ú¹¹ÐèÔÚ2026Äê4ÔÂ1ÈÕǰÐÞ¸´´Ë·ì϶¡£¡£×¨¼Ò½¨Òé˽Ӫ×éÖ¯Ò²Ó¦Éó²éKEVĿ¼²¢ÐÞ¸´Æä»ù´¡ÉèÊ©ÖеÄÓйطì϶¡£¡£


https://securityaffairs.com/189628/security/u-s-cisa-adds-microsoft-sharepoint-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html


4. ½ðÈÚ·þÎñÉÌMarquisÔâÀÕË÷¹¥»÷й¶67ÍòÓû§Êý¾Ý


3ÔÂ18ÈÕ£¬µÂ¿ËÈøË¹ÖݽðÈÚ·þÎñÌṩÉÌMarquis½üÈÕÅû¶£¬2025Äê8ÔÂÔâ·êµÄÀÕË÷Èí¼þ¹¥»÷µ¼Ö³¬¹ý67ÍòÈ˵ÄÊý¾Ý±»µÁ£¬¸ÃÊÂÎñ»¹Ó°ÏìÁËÃÀ¹ú74¼ÒÒøÐеÄÔËÓª¡£¡£MarquisΪÃÀ¹ú700¶à¼ÒÒøÐС¢¡¢¡¢ÐÅÓþºÏ×÷ÉçºÍµÖѺ´û¿î»ú¹¹ÌṩÊý×ÖÓªÏú¡¢¡¢¡¢Êý¾Ý·ÖÎö¡¢¡¢¡¢ºÏ¹æºÍ¿Í»§¹ØÏµÖÎÀí·þÎñ¡£¡£¸Ã¹«Ë¾ÔÚ12Ô³õÏòÃÀ¹ú˾·¨²¿Ìá½»µÄÊý¾Ýй¶֪ͨÖаµÊ¾£¬2025Äê8ÔÂ14ÈÕ£¬ÍþвÐÐΪÕß¹¥ÏÂSonicWall·À»ðǽºó¶ÔÆäÍøÂçÌáÒéÀÕË÷Èí¼þ¹¥»÷¡£¡£¹¥»÷ÕßÇÔÈ¡ÁË´óÁ¿Ð¡ÎҺͲÆÕþÐÅÏ¢£¬Ô̺¬Êܺ¦ÕßÐÕÃû¡¢¡¢¡¢µ®ÉúÈÕÆÚ¡¢¡¢¡¢µØÖ·¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢Éç»á°²È«ºÅÂë¡¢¡¢¡¢ÄÉ˰È˼ø±ðºÅÒÔ¼°²»º¬°²È«Âë»ò½Ó¼ûÂëµÄ²ÆÕþÕË»§ÐÅÏ¢¡£¡£MarquisÔÚ±¾ÖÜÏò672,075ÃûÊÜÓ°ÏìÕß·¢Ë͵ÄÊý¾Ýй¶֪ͨÐÅÖаµÊ¾£º"ÊÂÎñ½öÏÞÓÚMarquisϵͳ£¬Î´Ó°Ïì¿Í»§ÏµÍ³¡£¡£"¿Í»§ÓÚ2025Äê12ÔÂ10ÈÕÉó²éÁËÊÜÓ°ÏìÎļþ£¬ËæºóÖÂÁ¦ÑéÖ¤ºÍ¼ø±ðÐÅÏ¢¿ÉÄÜÊÜÊÂÎñÓ°ÏìµÄСÎÒ£¬²¢¾¡¿ì»ñȡСÎÒ×îÐÂÓʼĵØÖ·ÐÅÏ¢¡£¡£


https://www.bleepingcomputer.com/news/security/marquis-ransomware-gang-stole-data-of-672-000-people-in-2025-cyberattack/


5. DarkSword iOS·ì϶ÀûÓù¤¾ß°üÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý


3ÔÂ18ÈÕ£¬ÐÂÐÍiOSÉ豸·ì϶ÀûÓù¤¾ß°üºÍ½»¸¶¿ò¼Ü"DarkSword"½üÈÕ±»·¢ÏÖÓÃÓÚÇÔÈ¡¿í·ºÐ¡ÎÒÐÅÏ¢£¬Ô̺¬¼ÓÃÜÇ®±ÒÇ®°üÀûÓÃÊý¾Ý¡£¡£Òƶ¯°²È«¹«Ë¾Lookout×êÑÐÈËÔ±ÔÚµ÷²éCoruna¹¥»÷»ù´¡Éèʩʱ·¢ÏÖÁËDarkSword£¬¹È¸èÍþвµý±¨Ð¡×éºÍiVerifyÒ²²Î¼ÓÁ˶ÔÕâһδ֪ÍþвµÄ×ۺϷÖÎö¡£¡£DarkSwordÕë¶ÔÔËÐÐiOS18.4ÖÁ18.7°æ±¾µÄiPhone£¬Óë¶à¸öÍþвÐÐΪÕß¹ØÁª£¬Ô̺¬ÒÉËÆ¶íÂÞ˹µÄUNC6353¡£¡£¸Ã¹¤¾ß°üÀûÓÃÁù¸ö·ì϶£¬±àºÅ±ðÀëΪCVE-2025-31277¡¢¡¢¡¢CVE-2025-43529¡¢¡¢¡¢CVE-2026-20700¡¢¡¢¡¢CVE-2025-14174¡¢¡¢¡¢CVE-2025-43510ºÍCVE-2025-43520¡£¡£iVerify×êÑÐÁ˾ÖÅú×¢£¬¸Ã·ì϶Á´ÖÐÀûÓõÄËù³öȱµã¾ùΪÒÑÖª·ì϶£¬Æ»¹ûÒÑÔÚ×îÐÂiOS°æ±¾ÖÐÐÞ¸´¡£¡£¹È¸èÍþвµý±¨Ð¡×鰵ʾ£¬DarkSword×Ô2025Äê11ÔÂÒÔÀ´±»¶à¸öÍþвÐÐΪÕßʹÓ㬲¿ÊðÁËÈý¸ö¶ñÒâÈí¼þ¼Ò×壺GHOSTBLADEÊÇJavaScriptÊý¾ÝÇÔÈ¡·¨Ê½£»£»£»GHOSTKNIFEÊÇ¿Éй¶¸÷ÀàÊý¾ÝµÄºóÃÅ£»£»£»GHOSTSABERÊÇ¿Éö¾ÙÉ豸ºÍÕË»§¡¢¡¢¡¢Ö´ÐÐJavaScript´úÂëµÄJavaScriptºóÃÅ¡£¡£


https://www.bleepingcomputer.com/news/security/new-darksword-ios-exploit-used-in-infostealer-attack-on-iphones/


6. Nordstrom¹Ù·½ÓÊÏä·¢ËͼÓÃÜÇ®±Ò´¹µöÓʼþ


3ÔÂ18ÈÕ£¬ÃÀ¹ú¸ß¶Ë°Ù»õÁ¬ËøµêNordstromµÄ¿Í»§½üÈÕÊÕµ½À´×ԺϷ¨¹«Ë¾ÓÊÏ䵨ַµÄڲƭÓʼþ£¬Íƹã¼Ù×°³ÉÊ¥ÅÁÌØÀï¿Ë½Ú´ÙÏú»î¶¯µÄ¼ÓÃÜÇ®±ÒȦÌס£¡£¸ÃÓʼþ³ÐŵÊÕ¼þÈËÔÚÁ½Ð¡Ê±ÄÚ½«¼ÓÃÜÇ®±Ò´æÈëÌØ¶¨Ç®°üµØÖ·¿É»ñµÃË«±¶·µ»¹¡£¡£Ú²Æ­ÓʼþÐû³Æ£º"½«¼ÓÃÜÇ®±Ò·¢ËÍÖÁÄúµÄÈκÎΨһ´æ¿îµØÖ·£¬ÎÒÃǽ«Á¢¼´·µ»¹Äú·¢Ëͽð¶îµÄ200%¡£¡£"¶àÃû¿Í»§ÔÚÉ罻ýÌåÉϻ㱨ÊÕµ½´ËÀàÓʼþ£¬²¿Ãſͻ§°µÊ¾Óʼþ·¢Ë͵½ÁË´ÓδÔÚÏßй¶¹ýµÄµØÖ·¡£¡£ÍþвÐÐΪÕß½ö´ÍÓëÊÕ¼þÈËÁ½Ð¡Ê±Ðж¯¹¦·ò£¬ÖÆ×÷½ôÆÈ¸ÐʹNordstrom¿Í»§¸ü¿ÉÄܻſ²Î¼Ó"ÂòÂô"¶øºöÊÓȦÌ×¼£Ïó£¬Èç±êÌâÖй«Ë¾Ãû³ÆÆ´Ð´ÃýÎóΪ"Normstorm"¡£¡£È»¶ø£¬ÓÉÓÚÓʼþÀ´×Ômailto:nordstrom@eml.nordstrom.comÕâÒ»NordstromÓÃÓÚÓªÏú¡¢¡¢¡¢ÏúÊۺʹÙÏúͨѶµÄ¹Ù·½µØÖ·£¬ÈκκýŪ¼£Ï󶼿ÉÄܱ»ºöÊÓ£¬ÕâÅú×¢´æÔÚ°²È«·ì϶¡£¡£Nordstromδ»ØÓ¦ÖÃÆÀÒªÇ󣬵«¿Í»§»ã±¨¹«Ë¾·¢ËÍÁËÖÒ¸æÓʼþ£¬¶½´Ù³ÉÔ±ºöÂÔ֮ǰµÄ"δ¾­ÊÚȨ"Óʼþ¡£¡£


https://www.bleepingcomputer.com/news/security/nordstroms-email-system-abused-to-send-crypto-scams-to-customers/