¼ÓÖݾ«×Ó¿âÊý¾Ýй¶ £¬¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢Ôâ²»·¨»á¼û

Ðû²¼Ê±¼ä 2025-03-19

1. ¼ÓÖݾ«×Ó¿âÊý¾Ýй¶ £¬¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢Ôâ²»·¨»á¼û


3ÔÂ18ÈÕ £¬ÃÀ¹ú¾«×Ó¾èÔù¾ÞÍ·¼ÓÖݾ«×ӿ⣨California Cryobank£©½üÆÚÏò¿Í»§·¢³öÖÒÑÔ £¬ÆäÔâÓöÁËÊý¾Ýй¶ÊÂÎñ £¬µ¼Ö¿ͻ§µÄСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶¡£¼ÓÖݾ«×Ó¿âÊÇÒ»¼ÒÌṩȫ·½Î»·þÎñµÄ¾«×Ó¿â £¬°üÀ¨À䶳ļ¾è¾«×ÓºÍרҵÉúÖ³·þÎñ £¬ÈçÂÑ×ÓºÍÅßÌ¥Öü´æ £¬ÊÇÃÀ¹ú×î´óµÄ¾«×Ó¿âÖ®Ò» £¬·þÎñ¹æÄ£ÁýÕÖÈ«ÃÀ50¸öÖݼ°È«Çò30¶à¸ö¹ú¼Ò¡£2024Äê4ÔÂ21ÈÕ £¬¸Ã»ú¹¹¼ì²âµ½ÍøÂç¿ÉÒÉÔ˶¯ £¬²¢Á¬Ã¦½ÓÄɲ½·¥¸ôÀëÁËÊÜÓ°ÏìµÄÅÌËã»úºÍITÍøÂç¡£¾­ÓÉÊÓ²ì £¬È·ÈÏÓÐδ¾­ÊÚȨµÄÒ»·½ÔÚ4ÔÂ20ÈÕÖÁ22ÈÕʱ´ú»á¼û²¢¿ÉÄÜ»ñÈ¡Á˲¿·ÖÅÌËã»úϵͳÉϵÄÎļþ¡£´Ë´ÎÐ¹Â¶Éæ¼°¿Í»§µÄ¶àÖÖСÎÒ˽¼ÒÊý¾Ý £¬°üÀ¨ÐÕÃû¡¢ÒøÐÐÕË»§ÐÅÏ¢¡¢Éç»á°ü¹ÜºÅ¡¢¼ÝÕպš¢Ö§¸¶¿¨ºÅºÍ¿µ½¡°ü¹ÜÐÅÏ¢µÈ¡£ÎªÓ¦¶Ô´ËÊÂÎñ £¬¼ÓÖݾ«×Ó¿âΪÊÜÓ°Ïì¿Í»§ÌṩÁËÒ»ÄêµÄÃâ·ÑÐÅÓÃ¼à¿Ø·þÎñ £¬²¢ÔöÇ¿ÁËÊý¾Ý°ü¹ÜºÍÇå¾²²½·¥¡£ËäȻļ¾è¾«×Óͨ³£ÊÇÄäÃûµÄ £¬µ«´Ë´ÎйÃÜÊÂÎñ¶ÔÒÑÍùÄäÃûļ¾è¾«×ÓµÄÈËÀ´Ëµ¿ÉÄÜ×é³ÉÑÏÖØµÄÒþ˽ÎÊÌâ £¬ÏÖÔÚÉв»ÇåÎúļ¾èÕßµÄÐÅÏ¢ÊÇ·ñ±»µÁ¡£¼ÓÖݾ«×Ó¿âÉÐδ»ØÓ¦¹ØÓÚ¾èÔùÕßÊý¾ÝÊÇ·ñй¶µÄѯÎÊ¡£


https://www.bleepingcomputer.com/news/security/sperm-donation-giant-california-cryobank-warns-of-a-data-breach/


2. 11¹úAPTʹÓöñÒâ.lnkÎļþʵÑéÌØ¹¤ÓëÊý¾ÝÇÔÈ¡Ô˶¯


3ÔÂ18ÈÕ £¬×Ô 2017 ÄêÒÔÀ´ £¬ÖÁÉÙ11¸ö¹ú¼ÒÖ§³ÖµÄAPT×éÖ¯±»ÆØÊ¹ÓöñÒâ.lnkÎļþ¾ÙÐÐÌØ¹¤Ô˶¯ºÍÊý¾ÝÇÔÈ¡¡£¾ÝÇ÷ÊÆ¿Æ¼¼ÁãÈÕÍýÏ루ZDI£©ÆÊÎö £¬Ñо¿Ö°Ô±·¢Ã÷ÁË1,000¸ö´ËÀàÎļþ £¬ÕâЩÎļþʹÓÃÎó²îZDI-CAN-25373ÔÚÊܺ¦Õß»úеÉÏÖ´ÐÐÒþ²Ø¶ñÒâÏÂÁî¡£¸ÃÎó²îÒѱ»À´×Ô³¯ÏÊ¡¢ÒÁÀÊ¡¢¶íÂÞ˹ºÍÖйúµÄAPT×é֯ʹÓà £¬¹¥»÷Ä¿µÄ°üÀ¨±±ÃÀ¡¢Å·ÖÞ¡¢ÑÇÖÞ¡¢ÄÏÃÀºÍ°Ä´óÀûÑǵÄÕþ¸®¡¢½ðÈÚ¡¢µçÐÅ¡¢¾üʺÍÄÜÔ´²¿·Ö×éÖ¯¡£ÆäÖÐ £¬³¯ÏʵÄAPT×éÖ¯Õ¼±È×î¸ß £¬´ï45.5% £¬ÇÒ70%רעÓÚÌØ¹¤Ô˶¯¡£ZDIÒÑÏò΢ÈíÌá½»Îó²î £¬µ«Î¢ÈíÉÐδ½â¾ö¡£¸ÃÎó²î±»ÓÃÓÚת´ïÖÖÖÖ¶ñÒâÈí¼þ¸ºÔØ £¬°üÀ¨MaaSºÍÉÌÆ·¶ñÒâÈí¼þ¡£ÍþвÐÐΪÕßͨ¹ýʹÓÃͼ±êºÍÎļþÃûÓÕÆ­Óû§·­¿ª.lnkÎļþ £¬²¢ÔÚÆäÖÐÌî³ä¿Õ¸ñÒþ²Ø¶ñÒâÏÂÁî £¬ÒÔ±ÜÃâÓû§¿´µ½ÒÑÖ´ÐеIJÎÊý¡£Ò»Ð©³¯ÏÊAPT×é֯ʹÓó¬´ó.lnkÎļþÌӱܼì²â¡£´ËÎó²îʹÕþ¸®ºÍ×éÖ¯ÈÝÒ×Êܵ½¹¥»÷ £¬±£´æÖØ´óΣº¦¡£


https://securityaffairs.com/175569/apt/nation-state-actors-and-cybercrime-gangs-abuse-malicious-lnk-files-for-espionage-and-data-theft.html


3. Î÷²¿Í¬ÃËÒøÐÐ2.2Íò¿Í»§Êý¾ÝÔâµÚÈý·½Èí¼þÈëÇÖй¶


3ÔÂ18ÈÕ £¬×ܲ¿Î»ÓÚÑÇÀûÉ£ÄÇÖݵÄÎ÷²¿Í¬ÃËÒøÐУ¨Western Alliance Bank£© £¬ÊÇWestern Alliance BancorporationµÄÈ«×Ê×Ó¹«Ë¾ £¬¿ËÈÕ֪ͨÁ˽ü22,000Ãû¿Í»§ £¬ËûÃǵÄСÎÒ˽¼ÒÐÅÏ¢ÔÚ2024Äê10ÔÂÒòµÚÈý·½¹©Ó¦É̵ÄÇå¾²Îļþ´«ÊäÈí¼þÔâµ½ÈëÇÖ¶ø±»ÇÔÈ¡¡£¹¥»÷ÕßʹÓÃÁ˸ÃÈí¼þÖеÄÁãÈÕÎó²î £¬¸ÃÎó²îÓɹ©Ó¦ÉÌÓÚ2024Äê10ÔÂ27ÈÕÅû¶¡£ÒøÐÐÔÚ2Ô·ÝÌá½»¸øÃÀ¹ú֤ȯÉúÒâίԱ»áµÄÎļþÖÐÊ×´ÎÅû¶ÁËÕâÒ»ÊÂÎñ £¬Ö¸³ö¹¥»÷ÕßÔÚ2024Äê10ÔÂ12ÈÕÖÁ24ÈÕʱ´úÈëÇÖÁËÓÐÏÞÊýÄ¿µÄÎ÷·½Í¬ÃËϵͳ £¬²¢ÇÔÈ¡ÁË´æ´¢ÔÚÊÜѬȾÉè±¹ØÁ¬ÄÎļþ¡£±»µÁÎļþ°üÀ¨¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢ £¬ÈçÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢½ðÈÚÕË»§ºÅÂë¡¢¼ÝʻִÕÕºÅÂ롢˰ÎñʶÓÖÃûÂëºÍ/»ò»¤ÕÕÐÅÏ¢¡£ËäÈ»ÒøÐÐÌåÏÖûÓÐÖ¤¾ÝÅú×¢ÕâЩÐÅÏ¢±»ÀÄÓÃÓÚڲƭ»òÉí·Ý͵ÇÔ £¬µ«ÎªÊÜÓ°ÏìµÄÓû§ÌṩÁËÒ»ÄêµÄExperian IdentityWorks Credit 3BÉí·Ý±£»¤·þÎñÃâ·Ñ»áÔ±×ʸñ¡£±ðµÄ £¬¸ÃÒøÐÐÊÇClopÀÕË÷Èí¼þÍÅ»ïÔÚÆäйÃÜÍøÕ¾ÉÏÁгöµÄ58¼Ò¹«Ë¾Ö®Ò» £¬µ«¸ÃÒøÐÐÔÚйÃÜ֪ͨº¯»ò2Ô·ݵÄÃÀ¹ú֤ȯÉúÒâίԱ»áÎļþÖв¢Î´Ìá¼°ÊÜËðµÄÇå¾²Îļþ´«ÊäÈí¼þ¡£


https://www.bleepingcomputer.com/news/security/western-alliance-bank-notifies-21-899-customers-of-data-breach/


4. Google PlayÏÖ300Óà¶ñÒâ¹ã¸æÚ²Æ­Ó¦Óà £¬ÏÂÔØ³¬6000Íò´Î


3ÔÂ18ÈÕ £¬BitdefenderµÄÍøÂçÇå¾²Ñо¿Ö°Ô±½ÒÆÆÁËÒ»¸öÔÚGoogle Play StoreÖа²ÅÅÁËÁè¼Ý300¸ö¶ñÒâÓ¦ÓóÌÐòµÄ¹ã¸æÚ²Æ­Ô˶¯ £¬ÕâЩӦÓóÌÐòµÄÏÂÔØÁ¿×ܼÆÁè¼Ý6000Íò´Î £¬Ê¹Óû§ÃæÁÙÇÖÈëÐÔ¹ã¸æºÍÍøÂç´¹ÂÚ¹¥»÷µÄΣº¦¡£ÕâЩ¶ñÒâÓ¦ÓóÌÐòαװ³ÉÎÞº¦µÄÊÊÓóÌÐò £¬Èç¶þάÂëɨÃèÒÇ¡¢Óöȸú×ÙÆ÷ºÍ¿µ½¡Ó¦ÓóÌÐòµÈ £¬²¢Ò»Ö±¸üÐÂÒÔ°üÀ¨¶ñÒâ´úÂë¡£¸ÃڲƭÔ˶¯×Ô2024ÄêµÚÈý¼¾¶ÈÒÔÀ´Ò»Ö±»îÔ¾ £¬Ã»ÓзŻºµÄ¼£Ïó £¬Ö±µ½2025Äê3Ô £¬ÈÔÓÐеĶñÒâÓ¦ÓÃÔÚÊÐËÁÖзºÆð¡£ÕâЩӦÓûáÒþ²ØÍ¼±ê¡¢¸ü¸üÃû³ÆÒÔÄ£ÄâÕýµ±·þÎñ £¬²¢ÔÚδ¾­Óû§Ô޳ɵÄÇéÐÎÏÂÏÔʾȫÆÁ¹ã¸æ £¬ÉõÖÁÌá³«ÍøÂç´¹ÂÚ¹¥»÷ £¬ÓÕÆ­Óû§Ð¹Â¶Ãô¸ÐÐÅÏ¢¡£Ñо¿Ö°Ô±»¹½ÒÆÆÁËÕâЩ¶ñÒâÓ¦ÓóÌÐòÌӱܼì²âµÄÊÖÒÕÕ½ÂÔ £¬ÈçÀÄÓÃÄÚÈÝÌṩÉ̺Íͨ¹ýAPIŲÓÃÆô¶¯Ô˶¯µÈ¡£ÎªÁ˱£»¤×°±¸ £¬½¨Òé×èÖ¹ÏÂÔØ²»ÐëÒªµÄÓ¦ÓóÌÐò £¬È·±£×°±¸¼á³Ö¸üР£¬²¢°´ÆÚÔËÐжñÒâÈí¼þɨÃè¡£ÈôÊÇ·¢Ã÷ÈκÎÒì³£ £¬ÇëÁ¬Ã¦É¾³ý¸ÃÓ¦ÓóÌÐò¡£


https://hackread.com/scammers-ad-fraud-apps-google-play-60m-downloads/


5. Çø¿éÁ´ÓÎϷƽ̨WEMIXÔâºÚ¿Í¹¥»÷ £¬ÇÔÈ¡610ÍòÃÀÔª


3ÔÂ18ÈÕ £¬Çø¿éÁ´ÓÎϷƽ̨WEMIXÔÚÉÏÔÂÔâÓöÁËÍøÂç¹¥»÷ £¬µ¼ÖÂ8,654,860¸öWEMIX´ú±Ò±»µÁ £¬¼ÛÖµÔ¼6,100,000ÃÀÔª¡£ÔÚ×òÈÕµÄÐÂÎÅÐû²¼»áÉÏ £¬WEMIXÊ×ϯִÐйٽðÎý»À֤ʵÁËÕâÒ»ÊÂÎñ £¬²¢Ú¹ÊÍÁËÍÆ³ÙÐû²¼¹ûÕæÉùÃ÷µÄÔµ¹ÊÔ­ÓÉÊÇΪÁ˱£»¤Íæ¼ÒÃâÊܽøÒ»²½Ëðʧ¡£ËûÌáµ½ £¬ÔÚ·¢Ã÷ºÚ¿Í¹¥»÷ºó £¬WEMIXÁ¬Ã¦¹Ø±ÕÁËÊÜÓ°ÏìµÄ·þÎñÆ÷²¢Æô¶¯ÁËÏêϸÆÊÎö £¬²¢Ïò¾¯·½ÌáÆðÁËÐÌÊÂËßËÏ¡£ÓÉÓÚδȷ¶¨ÉøÍ¸ÒªÁìÇҴ󲿷ֱ»µÁ×ʲúÒѳöÊÛ £¬Á¬Ã¦¹ûÕæÅû¶¿ÉÄÜÒý·¢Êг¡¿Ö»Å¡£WEMIXÊǺ«¹úÓÎÏ·¹«Ë¾Wemade¿ª·¢µÄ»ùÓÚÇø¿éÁ´µÄÓÎϷƽ̨ £¬ÈÚºÏÁËÇø¿éÁ´ÊÖÒÕ £¬Ìṩ±ßÍæ±ß׬ģ×Ó¡¢NFTËùÓÐȨºÍDeFi¹¦Ð§¡£Æä×îÀֳɵÄÓÎÏ·MIR4ÔÚGoogle PlayÉϵÄÏÂÔØÁ¿Áè¼Ý500Íò´Î¡£¾ÝÍÆ²â £¬ºÚ¿Íͨ¹ý»ñÈ¡ÓÃÓÚ¼à¿ØNFTƽ̨¡°NILE¡±·þÎñµÄÈÏÖ¤ÃÜÔ¿ÈëÇÖÁËWEMIX £¬¸ÃÃÜÔ¿±»¿ª·¢Ö°Ô±ÉÏ´«µ½Á˹²Ïí´æ´¢¿âÖС£ºÚ¿Í²ß»®ÁËÁ½¸öÔµĹ¥»÷ £¬ÀֳɾÙÐÐÁË13´ÎÌá¿î £¬±»µÁ´ú±ÒѸËÙͨ¹ý¼ÓÃÜÇ®±ÒÉúÒâËù±»Ï´°×¡£ÏÖÔÚ £¬WEMIX´¦ÓÚÀëÏß״̬ £¬ÕýÔÚǨáãÖÁ¸üÇå¾²µÄÇéÐÎ £¬²¢ÍýÏëÔÚ3ÔÂ21ÈÕÖÜÈ«»Ö¸´·þÎñ¡£±ðµÄ £¬Êý×Ö×ʲúÉúÒâËùͬÃ˽«WEMIXÖ¸¶¨Îª¡°Í¶×ÊÖÒÑÔ¡±×ʲú²¢ÔÝÍ£´æ¿î £¬WEMIXÍýÏë¶Ô´ËÌá³öÉÏËß¡£


https://www.bleepingcomputer.com/news/security/blockchain-gaming-platform-wemix-hacked-to-steal-61-million/


6. AIÐËÆðÒý·¢Õ©Æ­ÐÂÇ÷ÊÆ£º¶ñÒâÈí¼þ½èDeepSeekµÈ¹¤¾ßÈö²¥


3ÔÂ18ÈÕ £¬È˹¤ÖÇÄܵÄÐËÆð´ßÉúÁËChatGPT¡¢DeepSeekºÍGeminiµÈ×ÅÃû¹¤¾ß £¬µ«Í¬Ê±Ò²ÎªÕ©Æ­ÕßÌṩÁËеĿɳËÖ®»ú¡£McAfee Labs·¢Ã÷ £¬¶ñÒâÐÐΪÕßÕýʹÓÃÈ˹¤ÖÇÄܹ¤¾ßµÄÊ¢ÐоÙÐÐSEOͶ¶¾ £¬ÓÕµ¼Óû§»á¼û¶ñÒâÍøÕ¾²¢ÏÂÔØ¶ñÒâÈí¼þ¡£ÒÔDeepSeek-R1ΪÀý £¬Æä×÷Ϊ±¾Ç®Ð§Òæ¸ßµÄÈ˹¤ÖÇÄÜÄ£×Ó±¸ÊܹØ×¢ £¬µ«ÆäÊ¢ÐÐҲΪƭ×Ó´´ÔìÁË»ú»á¡£ËûÃÇʹÓÃÓû§µÄÐ˷ܺͲ»ÄÍÐÄÇéÐ÷ £¬Í¨¹ýð³äµÄDeepSeek×°ÖóÌÐò¡¢ÍøÕ¾ºÍÓ¦ÓóÌÐòÈö²¥¶ñÒâÈí¼þ £¬Èç¼üÅ̼ͼÆ÷¡¢¼ÓÃÜÍÚ¾òÆ÷ºÍÃÜÂëÇÔÈ¡³ÌÐò¡£ÕâЩ¶ñÒâÔ˶¯°üÀ¨½«Õýµ±Èí¼þÓë²»ÐèÒªµÄµÚÈý·½Ó¦ÓóÌÐòÀ¦°óÔÚÒ»Æð £¬ÒÔ¼°Ê¹ÓÃÐéαµÄÑéÖ¤ÂëÒ³ÃæÓÕÆ­Óû§ÏÂÔØ²¢Ö´ÐжñÒâÈí¼þ¡£ÊÖÒÕÆÊÎö·¢Ã÷ £¬ÕâЩ¶ñÒâÈí¼þ×°Öúó»áÓëÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷ͨѶ £¬ÏÂÔØ²¢Ö´ÐÐPowerShell¾ç±¾ £¬½ø¶øÆô¶¯MoneroÍÚ¿ó²Ù×÷¡£Õ©Æ­ÕßÑ¡ÔñÃÅÂÞ±Ò¿ÉÄÜÊÇÒòÆäÄäÃûÐÔ £¬Ê¹µÃ×ʽðÁ÷ÏòÄÑÒÔ×·×Ù¡£McAfee LabsÇ¿µ÷ £¬ÔÚÐÂÐËÊÖÒÕ³´×÷ÖÜÆÚʱ´ú £¬Óû§Ó¦¼á³ÖСÐĺÍÖªÇé £¬²¢ÔÚ·­¿ª»òÖ´ÐпÉÒÉÁ´½ÓºÍÎļþ֮ǰʹÓÃVirusTotalµÈ¹¤¾ß¾ÙÐÐɨÃè £¬ÒÔÈ·±£Çå¾²¡£


https://hackread.com/fake-deepseek-ai-installers-websites-apps-malware/