ÃÀµÂ¼Ó½áºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç

°ä²¼¹¦·ò 2026-03-23

1. ÃÀµÂ¼Ó½áºÏµ·»ÙËÄ´óÎïÁªÍø½©Ê¬ÍøÂç


3ÔÂ20ÈÕ£¬ÃÀ¹ú¡¢¡¢µÂ¹úºÍ¼ÓÄôó·¨Âɲ¿ÃŽüÈÕ½áºÏ²ÉÈ¡Ðж¯£¬µ·»ÙÁËAisuru¡¢¡¢KimWolf¡¢¡¢JackSkidºÍMossadËÄ´ó½©Ê¬ÍøÂçÓÃÓÚϰȾÎïÁªÍø(IoT)É豸µÄºÅÁî½ÚÖÆ(C2)»ù´¡ÉèÊ©¡£¡£¡£¡£Õâ´Î½áºÏ·¨ÂÉÐж¯»¹Õë¶ÔÐé¹¹·þÎñÆ÷¡¢¡¢»¥ÁªÍøÓòÃû¼°ÆäËû»ù´¡ÉèÊ©£¬ÕâЩÉèÊ©±»ËÄ´ó½©Ê¬ÍøÂçÓÃÓÚ½ü¼¸¸öÔ¶ÔÈ«ÇòÊܺ¦ÕßÌáÒéÊýÊ®Íò´Î´ó¹æÄ£É¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷¡£¡£¡£¡£ÃÀ¹ú˾·¨²¿°µÊ¾£¬Õâ´ÎÐж¯Ö¼ÔÚ·ÛËéÓëËÄ´ó½©Ê¬ÍøÂçÓйصÄͨѶ£¬Ô¤·ÀÉ豸½øÒ»²½Ï°È¾£¬²¢ÏÞ¶È»ò½â³ý½©Ê¬ÍøÂçÌáÒ齫À´¹¥»÷µÄÄÜÁ¦¡£¡£¡£¡£·¨ÔºÎļþÖ¸¿Ø£¬Aisuru½©Ê¬ÍøÂç°ä²¼Á˳¬¹ý20Íò´ÎDDoS¹¥»÷ºÅÁKimWolf°ä²¼Á˳¬¹ý2.5Íò´Î£¬JackSkid°ä²¼Á˳¬¹ý9Íò´Î£¬Mossad°ä²¼Á˳¬¹ý1000´Î¡£¡£¡£¡£Æ¾¾ÝÃÀ¹ú˾·¨²¿Êý¾Ý£¬ÕâЩ½©Ê¬ÍøÂ繲ϰȾ²¢½ÚÖÆÁ˳¬¹ý300Íǫ̀IoTÉ豸£¬Ô̺¬ÍøÂçÉãÏñÍ·¡¢¡¢Êý×ÖÊÓÆµÂ¼Ïñ»úºÍWiFi·ÓÉÆ÷£¬ÆäÖкܶàÉ豸λÓÚÃÀ¹ú¡£¡£¡£¡£½©Ê¬ÍøÂçÔËÓªÕßÒÔÍøÂç·¸×ï¼´·þÎñģʽÏòÆäËûÍøÂç×ï·¸ÏúÊÛ½Ó¼ûȨÏÞ£¬Ê¹Æä¿ÉÄÜÌáÒéDDoS¹¥»÷£¬Ôì³ÉÊýÍòÃÀÔªËðʧºÍ²¹¾È³É±¾¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/aisuru-kimwolf-jackskid-and-mossad-botnets-disrupted-in-joint-action/


2. IntoxalockÔâÍøÂç¹¥»÷ÖÂÈ«ÃÀ˾»úÎÞ·¨Æô¶¯³µÁ¾


3ÔÂ20ÈÕ£¬ÃÀ¹ú³µÁ¾¾Æ¾«²âÊÔÒǹ«Ë¾Intoxalock½üÈÕÔâ·êÍøÂç¹¥»÷£¬µ¼ÖÂÈ«ÃÀ¸÷µØË¾»úÎÞ·¨Æô¶¯³µÁ¾¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ3ÔÂ14ÈÕÔÚÆäÍøÕ¾ÉÏÈ·ÈÏÕý¾­ÀúÍ£»ú£¬ÆäÏúÊ۵ľƾ«²âÊÔÒÇÉ豸Ðè×°ÖÃÔÚ³µÁ¾µã»ð¿ª¹ØÉÏ£¬±»ÒªÇóÌṩÒõÐԾƾ«ºôÆøÑù±¾ÄÜÁ¦Æô¶¯Æû³µµÄÓû§ÒÀÀµ¸ÃÉ豸¡£¡£¡£¡£Intoxalock½²»°ÈËRachael LarsonÏòýÌåÈ·ÈϹ«Ë¾Ôâ·êÍøÂç¹¥»÷£¬²¢°µÊ¾ÒѲÉÈ¡´ëÊ©"ÁÙʱÔÝÍ£²¿ÃÅϵͳ×÷ΪԤ·À´ëÊ©"¡£¡£¡£¡£¹«Ë¾Î´Ð¹Â©¹¥»÷ÀàÐÍ£¬ÈçÊÇ·ñΪÀÕË÷Èí¼þ»òÊý¾Ýй¶£¬Ò²Î´×¢Ã÷ÊÇ·ñÊÕµ½ºÚ¿ÍͨѶ»òÊê½ðÒªÇ󡣡£¡£¡£ÕâЩ¾Æ¾«²âÊÔÒÇÉ豸Ðèÿ¸ô¼¸¸öÔÂУ׼һ´Î£¬µ«ÍøÂç¹¥»÷µ¼ÖÂIntoxalockÎÞ·¨Ö´ÐÐУ׼¡£¡£¡£¡£¹«Ë¾°µÊ¾±ØÒªÐ£×¼É豸µÄ¿Í»§ÔÚÆô¶¯³µÁ¾Ê±¿ÉÄÜÓöµ½ÑÓ³¤¡£¡£¡£¡£ÔÚRedditÉÏ·¢ÌûµÄ˾»ú°µÊ¾£¬ÈôÊÇ´í¹ýУ׼£¬³µÁ¾½«ÎÞ·¨Æô¶¯£¬ÏÖʵ´ó½«Ë¾»úËøÔÚ³µÍâ¡£¡£¡£¡£


https://techcrunch.com/2026/03/20/cyberattack-on-vehicle-breathalyzer-company-leaves-drivers-stranded-across-the-us/


3. Oracle°ä²¼´¹Î£²¹¶¡ÐÞ¸´¹Ø¼üÔ¶³Ì´úÂëÖ´Ðзì϶


3ÔÂ20ÈÕ£¬Oracle½üÈÕ°ä²¼´øÍⰲȫ¸üУ¬ÐÞ¸´Éí·ÝÖÎÀíÆ÷ºÍWeb·þÎñÖÎÀíÆ÷ÖбàºÅΪCVE-2026-21992µÄ¹Ø¼üδÈÏÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¸Ã·ì϶CVSSv3.1ÑÏÖØÐÔÆÀ·ÖΪ9.8£¬Ó°ÏìOracleIdentityManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0£¬ÒÔ¼°OracleWebServicesManager°æ±¾12.2.1.4.0ºÍ14.1.2.1.0¡£¡£¡£¡£OracleÔÚ×òÈÕ°ä²¼µÄ°²È«Õ÷ѯÖÐÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÀûÓò¹¶¡¡£¡£¡£¡£Õ÷ѯָ³ö£¬¸Ã·ì϶¿ÉÔ¶³ÌÀûÓÃÇÒÎÞÐèÉí·ÝÑéÖ¤£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£·ì϶¸´ÔӶȵͣ¬¿Éͨ¹ýHTTPÔ¶³ÌÀûÓã¬ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥£¬Ôö³¤Á˶³ö·þÎñÆ÷±»ÀûÓõķçÏÕ¡£¡£¡£¡£OracleIdentityManagerÓÃÓÚÖÎÀíÆóÒµÄÚµÄÉí·ÝºÍ½Ó¼û£¬OracleWebServicesManagerΪWeb·þÎñÌṩ°²È«ºÍÖÎÀí½ÚÖÆ¡£¡£¡£¡£ÕâÁ½¿î²úÆ·¿í·ºÀûÓÃÓÚÆóÒµÉí·ÝÈÏÖ¤ºÍ½Ó¼ûÖÎÀí³¡¾°£¬·ì϶Èô±»ÀûÓÿÉÄܵ¼Ö¹¥»÷Õ߯ëÈ«½ÚÖÆÊÜÓ°Ïìϵͳ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/


4. ¼ÓÖݸ£Ë¹ÌسÇÔâÀÕË÷¹¥»÷ÔÝÍ£¹«¹²·þÎñ


3ÔÂ21ÈÕ£¬¼ÓÖݸ£Ë¹ÌسǽüÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬±»ÆÈÔÝÍ£³ý´¹Î£ÏìÓ¦ÍâµÄËùÓй«¹²·þÎñ¡£¡£¡£¡£Õâ×ùλÓھɽðɽÍåÇø¡¢¡¢Õ¼ÓÐÔ¼34,000È˶¡µÄ³ÇÊУ¬Æä³ÇÊо­Àí°ä·¢½øÈ봹Σ״̬£¬ÒÔ½âËøÀ´×ÔÍⲿ»ú¹¹µÄ²¹³ä²ÆÕþÖ§³Ö¡£¡£¡£¡£³ÇÊо­ÀíStefan Chatwin°µÊ¾£º£º"¹«¼Ò°²ÂúÊÇOG¶«·½Ìü×î¸ßÓÅÏȼ¶£¬Òò¶øÎÒÃǼ¤ÀøÉçÇø³ÉÔ±²ÉÈ¡×îÄÜÈ·±£Ð¡ÎÒÐÅÏ¢°²È«µÄÔ¤·À´ëÊ©¡£¡£¡£¡£"Êе±¾ÖÖÒ¸æºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡¹«¹²ÐÅÏ¢£¬¶½´ÙÈκÎÓëÊе±¾ÖÓÐÒµÎñÍùÀ´µÄÈËÔ±¸ü¸ÄСÎÒÃÜÂë²¢²ÉÈ¡´ëÊ©±£»¤Ð¡ÎÒÊý¾Ý¡£¡£¡£¡£Êе±¾Ö°µÊ¾911ºÍ¾¯Ô±µ÷¶ÈµÈ´¹Î£·þÎñ"Ö°ÄÜÕý³£ÇÒδÊÜÓ°Ïì"£¬µ«¸£Ë¹ÌسǾ¯Ô±¾ÖÖÜÎåÍí¼ä·¢³ö֪ͨ³Æ£¬Æä·Ç´¹Î£ÈÈÏߺʹ¹Î£Ö±²¦Ïß·ÔÚÁÙʱÖжϺó"ÒѸ´Ô­ÔËÐÐ"¡£¡£¡£¡£ÓÉÓÚ¹¥»÷£¬ÊÐÒé»á»áÒ齫½öÒÔÏÖ³¡·½Ê½½øÐУ¬²»ÔÙͨ¹ýZoomÌṩ¡£¡£¡£¡£


https://therecord.media/california-city-reports-ransomware-attack-la-metro


5. LAPSUS$Ðû³ÆÇÔÈ¡°¢Ë¹Àû¿µ3GBÄÚ²¿Êý¾Ý


3ÔÂ20ÈÕ£¬×Ô³Æ"LAPSUS$"µÄÍþвÐÐΪÕß×éÖ¯½üÈÕÐû³Æ¶ÔÉæ¼°°¢Ë¹Àû¿µ(AstraZeneca)µÄÊý¾Ýй¶ÊÂÎñÕÆ¹Ü¡£¡£¡£¡£°¢Ë¹Àû¿µÊÇÈ«Çò×î´óµÄ¿ç¹úÖÆÒ©ºÍÉúÎï¼¼Êõ¹«Ë¾Ö®Ò»¡£¡£¡£¡£Æ¾¾ÝÔÚºÚ¿ÍÂÛ̳ºÍ¸Ã×éÖ¯¹Ù·½ÍøÕ¾Éϰ䲼µÄÌû×Ó£¬¹¥»÷ÕßÐû³Æ½Ó¼ûÁËÔ±¹¤ÓйØÊý¾Ý¼¯¡¢¡¢ÆëȫԴ´úÂë¡¢¡¢°ÂÃØºÍ½Ó¼ûÍ´´¦¡¢¡¢ÔÆ»ù´¡ÉèÊ©ÅäÖõÈ¡£¡£¡£¡£Ìû×ÓÔ̺¬¶Ô.tar.gzÌåʽ¿ÉÏÂÔØµµ°¸µÄÒýÓã¬×ÜÊý¾ÝÁ¿Ô¼3GB¡£¡£¡£¡£º£ºÚ¿ÍÕýÊÔͼ½«Êý¾ÝÏúÊÛ¸ø³ö¼Û×î¸ßÕߣ¬²¢·ÖÏíÁËÑù±¾ÎļþÒÔÖ§³ÖÆäÐû³Æ¡£¡£¡£¡£Ñù±¾Êý¾Ý·ÖÎöÏÔʾ£¬Ð¹Â¶Êý¾ÝÖØÒª·ÖΪÈýÀࣺ£ºGitHubÓйØÊý¾Ý¡¢¡¢µÚÈý·½Êý¾ÝºÍ²ÆÕþÊý¾Ý¡£¡£¡£¡£GitHubÆóÒµÓû§Êý¾ÝÔ̺¬Ô±¹¤ÐÕÃû¡¢¡¢³É±¾ÖÐÐIJο¼¡¢¡¢Ðí¿ÉÖ¤ÀàÐÍ¡¢¡¢ÆóÒµ½ÇÉ«ºÍȨÏÞ¡¢¡¢Ë«³É·ÖÉí·ÝÑé֤״̬¡¢¡¢GitHubÓû§ÃûºÍÅäÖÃÎļþURL¡¢¡¢×éÖ¯½ÇÉ«µÈÐÅÏ¢¡£¡£¡£¡£µÚÈý·½Êý¾ÝËÆºõ¸ú×ÙÍⲿºÏ×÷ÕߵĽӼûÒªÇóºÍÈëÖ°ÐÅÏ¢£¬Ô̺¬ÄÚ²¿Óû§ID¡¢¡¢È«ÃûºÍµç×ÓÓʼþµØÖ·¡¢¡¢ÄÚ²¿ÍŶӯÀÂÛ¡¢¡¢¹«Ë¾´ÓÊô¹ØÏµ¡¢¡¢ÄÚ²¿ÏµÍ³½Ó¼û״̬¡£¡£¡£¡£²ÆÕþÊý¾ÝÔ̺¬¸ß¼¶±ð²ÆÕþͳ¼Æ£¬±êΪ"ËùÓÐÐÐÒµ"£¬ËƺõÊǹ«¹²»òͨÓÃͳ¼ÆÐÅÏ¢£¬Ó밢˹Àû¿µÔËÓªÎÞÖ±½Ó¹ØÁª¡£¡£¡£¡£


https://hackread.com/hacker-group-lapsus-astrazeneca-data-breach/


6. Trivy·ì϶ɨÃèÆ÷Ô⹩¸øÁ´¹¥»÷·Ö·¢ÇÔÃܶñÒâÈí¼þ


3ÔÂ21ÈÕ£¬³ÛÃû·ì϶ɨÃèÆ÷Trivy½üÈÕÔâ·ê¹©¸øÁ´¹¥»÷£¬ÍþвÐÐΪÕß×éÖ¯TeamPCPͨ¹ý¹Ù·½°ä²¼°æ±¾ºÍGitHubActions·Ö·¢Æ¾Ö¤ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£Õâ´Îй¶Óɰ²È«×êÑÐÔ±PaulMcCarty³õ´ÎÅû¶£¬ÖÒ¸æTrivy0.69.4°æ±¾±»Ö²ÈëºóÃÅ£¬¶ñÒâÈÝÆ÷¾µÏñºÍGitHub°ä²¼°æ±¾±»·Ö·¢¸øÓû§¡£¡£¡£¡£¹¥»÷Õß¹¥ÏÂÁËTrivyµÄGitHub¹¹½¨Á÷³Ì£¬½«GitHubActionsÖеÄentrypoint.sh´úÌæÎª¶ñÒâ°æ±¾£¬²¢ÔÚTrivyv0.69.4°ä²¼°æ±¾Öа䲼±»Ö²ÈëºóÃŵĶþ½øÖÆÎļþ¡£¡£¡£¡£¹¥»÷ÕßÀÄÆ÷ÓµÓвֿâдÈëȨÏÞµÄÊÜËðÍ´´¦°ä²¼¶ñÒâ°ä²¼°æ±¾£¬ÕâЩʹ´¦À´×Ô3ÔÂÔçЩʱ³½µÄй¶ÊÂÎñ£¬Æäʱʹ´¦´ÓTrivy»·¾³±»ÍâйÇÒδÆëÈ«½ÚÖÆ¡£¡£¡£¡£ÍþвÐÐΪÕßÇ¿ÖÆÍÆËÍÁËaquasecurity/trivy-action²Ö¿â76¸ö±êÇ©ÖеÄ75¸ö£¬½«ÆäÖØ¶¨Ïòµ½¶ñÒâÌá½»¡£¡£¡£¡£Ê¹ÓÃÊÜÓ°Ïì±êÇ©µÄÍⲿ¹¤×÷Á÷»áÔÚÔËÐкϷ¨TrivyɨÃè֮ǰ×Ô¶¯Ö´ÐжñÒâ´úÂ룬ʹÈëÇÖÄÑÒÔ¼ì²â¡£¡£¡£¡£¶ñÒâÈí¼þÍøÂç¿úËÅÊý¾Ý²¢É¨ÃèϵͳÖд洢ƾ֤ºÍÈÏÖ¤°ÂÃØµÄÎļþ£¬ÍøÂçµÄÊý¾Ý±»¼ÓÃÜ´æ´¢ÔÚÃûΪtpcp.tar.gzµÄµµ°¸ÖУ¬ÍâйÖÁÓòÃûɨÃè.aquasecurtiy[.]org¡£¡£¡£¡£ÈôÍâйʧ°Ü£¬¶ñÒâÈí¼þ»áÔÚÊܺ¦ÕßGitHubÕË»§Öд´½¨ÃûΪtpcp-docsµÄ¹«¹²²Ö¿â²¢ÉÏ´«ÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/trivy-vulnerability-scanner-breach-pushed-infostealer-via-github-actions/