MedusaÀÕË÷Èí¼þ¹¥»÷ÃÜÎ÷Î÷±È×î´óÒ½Ôº
°ä²¼¹¦·ò 2026-03-191. MedusaÀÕË÷Èí¼þ¹¥»÷ÃÜÎ÷Î÷±È×î´óÒ½Ôº
3ÔÂ18ÈÕ£¬MedusaÀÕË÷Èí¼þÍÅ»ï½üÈÕÐû³Æ¶ÔÃÜÎ÷Î÷±ÈÖÝ×î´óÒ½ÔºÃÜÎ÷Î÷±È´óѧҽѧÖÐÐÄ£¨UMMC£©¼°ÐÂÔóÎ÷ÖÝÅÁÈû¿ËÏØµÄÍøÂç¹¥»÷ÕÆ¹Ü¡£¸ÃÍŻﱻר¼ÒÒÔΪÔÚ¶íÂÞ˹¾³ÄÚÔËÓª£¬Ä¿Ç°ÒÑÏòÁ½¼Ò»ú¹¹±ðÀëË÷Òª80ÍòÃÀÔªÊê½ð¡£UMMCÊÇÃÜÎ÷Î÷±ÈÖÝ×î³ÁÒªµÄÒ½ÁÆ»ú¹¹£¬Õ¼ÓÐ1ÍòÃûÔ±¹¤£¬ÔËӪןÃÖÝΨһµÄ¶ùͯҽԺ¡¢Î¨ÖðÒ»¼¶´´ÉËÖÐÐÄ¡¢Î¨Ò»Ëļ¶ÐÂÉú¶ù³ÁÖ¢¼à»¤ÊÒÒÔ¼°Î¨Ò»µÄÆ÷¹ÙÒÆÖ²ÏîÄ¿¡£2Ôµף¬¸Ã»ú¹¹Ôâ·êÍøÂç¹¥»÷ºóÈ«ÃæÍ£°Ú9Ì죬ҽ»¤ÈËÔ±±»ÆÈʹÓ÷ÂÕÕ¹¤¾ß²Ù×÷¾«ÃÜϵͳ¡£°©Ö¢ÊäÒºÖÐÐIJ»µÃ²»³ÁÐÂÆÌÅÅ»¼ÕßÔ¤Ô¼£¬ÆäËû¿ÆÊÒÖ»ÄÜÒÀ¸½Ö½±ÊÖÎÀíÎï×ʺÍÒ½ÖΡ£UMMC¹Ø¹ØÁËÈ«Êý35¸öÕïËù£¬µ«Ò½ÔººÍ¼¹Øï²¿ÃÅά³ÖÔËÓª¡£ÃÀ¹úÁª¹úµ÷²é¾ÖºÍºÓɽ°²È«ÊýȾָÐÖú¸´Ô¹¤×÷¡£Ò½ÔºÓÚ3ÔÂ2ÈÕÈ«Ãæ³ÁÐÂÊ¢¿ª£¬MedusaÍÅ»ïËæºóÐû³Æ¶Ô´ËÕÆ¹Ü£¬ÍþвÓÚ3ÔÂ20ÈÕǰй¶´ÓÒ½ÔºÇÔÈ¡µÄÊý¾Ý¡£UMMC½²»°È˻ؾø¾ÍÊê½ðÍþв°ä·¢ÆÀÂÛ¡£ÅÁÈû¿ËÏØÕ¼Óнü60ÍòÈ˶¡£¬Á½ÖÜǰÔâ·ê¶ñÒâÈí¼þ¹¥»÷£¬µ±¾Ö°ì¹«Êҵ绰ÏߺÍITϵͳ̱»¾¡£MedusaÍÅ»ïͬÑùÐû³Æ¶Ô´ËÕÆ¹Ü²¢Ë÷Òª80ÍòÃÀÔªÊê½ð¡£
https://therecord.media/medusa-ransomware-mississippi-cyber
2. Éí·Ý±£»¤¹«Ë¾AuraÔâ´¹µö¹¥»÷й¶90ÍòÓû§Êý¾Ý
3ÔÂ18ÈÕ£¬Éí·Ý±£»¤¹«Ë¾Aura½üÈÕÈ·ÈÏ£¬Î´¾ÊÚȨµÄµÚÈý·½Í¨¹ýÕë¶ÔÔ±¹¤µÄÓïÒô´¹µö¹¥»÷»ñÈ¡Á˽ü90ÍòÌõ¿Í»§¼Í¼£¬Ô̺¬ÐÕÃûºÍµç×ÓÓʼþµØÖ·µÈÃô¸ÐÐÅÏ¢¡£¸Ã¹«Ë¾±¾ÖÜÏòÊÜÓ°ÏìÓû§·¢³ö֪ͨ£¬²¢°µÊ¾ÒÑ֪ͨ·¨Âɲ¿ÃÅ¡£AuraÊÇÒ»¼ÒÏû·ÑÊý×Ö°²È«¹«Ë¾£¬ÏúÊÛÉí·Ý͵ÇÔ±£»¤¡¢ÐÅÓþºÍÚ²Æ¼à¿ØÒÔ¼°ÔÚÏß°²È«¹¤¾ß¡£Õâ´Îй¶µÄÊý¾ÝÔ´×Ô2021ÄêÊÕ¹ºµÄÒ»¼Ò¹«Ë¾ËùʹÓõÄÓªÏú¹¤¾ß£¬Â¶³öÁËÔ¼20,000Ãûµ±Ç°¿Í»§ºÍ15,000Ãûǰ¿Í»§µÄÓÐÏÞÐÅÏ¢¡£ÊÜÓ°ÏìµÄ¿Í»§ÐÅÏ¢Ô̺¬È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒͥסַºÍµç»°ºÅÂë¡£¹«Ë¾Ç¿µ÷£¬Éç»á°²È«ºÅÂë¡¢ÕË»§ÃÜÂëºÍ²ÆÕþÐÅϢδÊÜÓ°Ïì¡£Íþв×éÖ¯ShinyHunters±¾ÖÜÔçЩʱ³½ÔÚÆäÊý¾ÝÀÕË÷ÍøÕ¾ÉÏÐû³Æ¶Ô´Ë¹¥»÷ÕÆ¹Ü£¬°µÊ¾ÇÔÈ¡ÁË12GBÔ̺¬¿Í»§Ó×ÎÒÉí·ÝÐÅÏ¢(PII)¼°ÆóÒµÊý¾ÝµÄÎļþ¡£HaveIBeenPwned(HIBP)·þÎñ·ÖÎöÁËй¶Êý¾Ý²¢½«ÆäÔö³¤µ½Êý¾Ý¿âÖУ¬Ö¸³ö¿Í»§·þÎñÆÀÂÛºÍIPµØÖ·Ò²±»Â¶³ö¡£HIBP°µÊ¾£¬Õâ´ÎÊÂÎñÖж³öµÄ90%µç×ÓÓʼþµØÖ·ÒÑ´æÔÚÓÚÆä´Óǰ°²È«ÊÂÎñÊý¾Ý¿âÖС£
https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/
3. CISA½«SharePointºÍZimbra·ì϶ÁÐÈëKEVĿ¼
3ÔÂ18ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö(CISA)½üÈÕ½«Î¢ÈíSharePointºÍSynacorZimbraºÏ×÷Ì×¼þµÄÁ½¸ö·ì϶Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶(KEV)Ŀ¼ÖС£Æ¾¾ÝÔ¼Êø²Ù×÷Ö¸ÁîBOD22-01£¬Áª¹úÃñÊ»ú¹¹±ØÐëÔÚ»®¶¨ÈÕÆÚǰ½¨¸´ÕâЩ·ì϶£¬ÒÔ±£»¤ÍøÂçÃâÊÜÀûÓÃÕâЩ·ì϶µÄ¹¥»÷¡£µÚÒ»¸ö·ì϶±àºÅΪCVE-2026-20963£¬CVSSÆÀ·ÖΪ8.8£¬ÊÇ΢ÈíOfficeSharePointÖеIJ»ÊÜÐÅÀµÊý¾Ý·´ÐòÁл¯·ì϶£¬ÔÊÐíÊÚȨ¹¥»÷ÕßÔÚÍøÂçÉÏÖ´ÐдúÂë¡£CISAÒѺÅÁîÁª¹ú»ú¹¹ÔÚ2026Äê3ÔÂ21ÈÕǰ½¨¸´´Ë·ì϶¡£µÚ¶þ¸ö·ì϶±àºÅΪCVE-2025-66376£¬CVSSÆÀ·ÖΪ7.2£¬ÊǾµäÓû§½çÃæÖеĴ洢ÐÍ¿çÕ¾¾ç±¾(XSS)·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓõç×ÓÓʼþHTMLÖеÄCSS@importÖ¸Áî½øÐй¥»÷¡£Áª¹ú»ú¹¹ÐèÔÚ2026Äê4ÔÂ1ÈÕǰ½¨¸´´Ë·ì϶¡£×¨¼Ò½¨Òé˽Ӫ×éÖ¯Ò²Ó¦Éó²éKEVĿ¼²¢½¨¸´Æä»ù´¡ÉèÊ©ÖеÄÓйطì϶¡£
https://securityaffairs.com/189628/security/u-s-cisa-adds-microsoft-sharepoint-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html
4. ½ðÈÚ·þÎñÉÌMarquisÔâÀÕË÷¹¥»÷й¶67ÍòÓû§Êý¾Ý
3ÔÂ18ÈÕ£¬µÂ¿ËÈøË¹ÖݽðÈÚ·þÎñÌṩÉÌMarquis½üÈÕÅû¶£¬2025Äê8ÔÂÔâ·êµÄÀÕË÷Èí¼þ¹¥»÷µ¼Ö³¬¹ý67ÍòÈ˵ÄÊý¾Ý±»µÁ£¬¸ÃÊÂÎñ»¹Ó°ÏìÁËÃÀ¹ú74¼ÒÒøÐеÄÔËÓª¡£MarquisΪÃÀ¹ú700¶à¼ÒÒøÐÓ×¢ÐÅÓþºÏ×÷ÉçºÍµÖѺ´û¿î»ú¹¹ÌṩÊý×ÖÓªÏú¡¢Êý¾Ý·ÖÎö¡¢ºÏ¹æºÍ¿Í»§¹ØÏµÖÎÀí·þÎñ¡£¸Ã¹«Ë¾ÔÚ12Ô³õÏòÃÀ¹ú˾·¨²¿Ìá½»µÄÊý¾Ýй¶֪ͨÖаµÊ¾£¬2025Äê8ÔÂ14ÈÕ£¬ÍþвÐÐΪÕß¹¥ÏÂSonicWall·À»ðǽºó¶ÔÆäÍøÂçÌáÒéÀÕË÷Èí¼þ¹¥»÷¡£¹¥»÷ÕßÇÔÈ¡ÁË´óÁ¿Ó×ÎҺͲÆÕþÐÅÏ¢£¬Ô̺¬Êܺ¦ÕßÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢ÄÉ˰È˼ø±ðºÅÒÔ¼°²»º¬°²È«Âë»ò½Ó¼ûÂëµÄ²ÆÕþÕË»§ÐÅÏ¢¡£MarquisÔÚ±¾ÖÜÏò672,075ÃûÊÜÓ°ÏìÕß·¢Ë͵ÄÊý¾Ýй¶֪ͨÐÅÖаµÊ¾£º"ÊÂÎñ½öÏÞÓÚMarquisϵͳ£¬Î´Ó°Ïì¿Í»§ÏµÍ³¡£"¿Í»§ÓÚ2025Äê12ÔÂ10ÈÕÉó²éÁËÊÜÓ°ÏìÎļþ£¬ËæºóÖÂÁ¦ÑéÖ¤ºÍ¼ø±ðÐÅÏ¢¿ÉÄÜÊÜÊÂÎñÓ°ÏìµÄÓ×ÎÒ£¬²¢¾¡¿ì»ñÈ¡Ó×ÎÒ×îÐÂÓʼĵØÖ·ÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/marquis-ransomware-gang-stole-data-of-672-000-people-in-2025-cyberattack/
5. DarkSword iOS·ì϶ÀûÓù¤¾ß°üÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý
3ÔÂ18ÈÕ£¬ÐÂÐÍiOSÉ豸·ì϶ÀûÓù¤¾ß°üºÍ½»¸¶¿ò¼Ü"DarkSword"½üÈÕ±»·¢ÏÖÓÃÓÚÇÔÈ¡¿í·ºÓ×ÎÒÐÅÏ¢£¬Ô̺¬¼ÓÃÜÇ®±ÒÇ®°üÀûÓÃÊý¾Ý¡£Òƶ¯°²È«¹«Ë¾Lookout×êÑÐÈËÔ±ÔÚµ÷²éCoruna¹¥»÷»ù´¡Éèʩʱ·¢ÏÖÁËDarkSword£¬¹È¸èÍþвµý±¨Ó××éºÍiVerifyÒ²²Î¼ÓÁ˶ÔÕâһδ֪ÍþвµÄ×ۺϷÖÎö¡£DarkSwordÕë¶ÔÔËÐÐiOS18.4ÖÁ18.7°æ±¾µÄiPhone£¬Óë¶à¸öÍþвÐÐΪÕß¹ØÁª£¬Ô̺¬ÒÉËÆ¶íÂÞ˹µÄUNC6353¡£¸Ã¹¤¾ß°üÀûÓÃÁù¸ö·ì϶£¬±àºÅ±ðÀëΪCVE-2025-31277¡¢CVE-2025-43529¡¢CVE-2026-20700¡¢CVE-2025-14174¡¢CVE-2025-43510ºÍCVE-2025-43520¡£iVerify×êÑÐÁ˾ÖÅú×¢£¬¸Ã·ì϶Á´ÖÐÀûÓõÄËù³öȱµã¾ùΪÒÑÖª·ì϶£¬Æ»¹ûÒÑÔÚ×îÐÂiOS°æ±¾Öн¨¸´¡£¹È¸èÍþвµý±¨Ó××鰵ʾ£¬DarkSword×Ô2025Äê11ÔÂÒÔÀ´±»¶à¸öÍþвÐÐΪÕßʹÓ㬲¿ÊðÁËÈý¸ö¶ñÒâÈí¼þ¼Ò×壺GHOSTBLADEÊÇJavaScriptÊý¾ÝÇÔÈ¡·¨Ê½£»GHOSTKNIFEÊÇ¿Éй¶¸÷ÀàÊý¾ÝµÄºóÃÅ£»GHOSTSABERÊÇ¿Éö¾ÙÉ豸ºÍÕË»§¡¢Ö´ÐÐJavaScript´úÂëµÄJavaScriptºóÃÅ¡£
https://www.bleepingcomputer.com/news/security/new-darksword-ios-exploit-used-in-infostealer-attack-on-iphones/
6. Nordstrom¹Ù·½ÓÊÏä·¢ËͼÓÃÜÇ®±Ò´¹µöÓʼþ
3ÔÂ18ÈÕ£¬ÃÀ¹ú¸ß¶Ë°Ù»õÁ¬ËøµêNordstromµÄ¿Í»§½üÈÕÊÕµ½À´×ԺϷ¨¹«Ë¾ÓÊÏ䵨ַµÄÚ²ÆÓʼþ£¬Íƹã¼Ù×°³ÉÊ¥ÅÁÌØÀï¿Ë½Ú´ÙÏú»î¶¯µÄ¼ÓÃÜÇ®±ÒȦÌס£¸ÃÓʼþ³ÐŵÊÕ¼þÈËÔÚÁ½Ó×ʱÄÚ½«¼ÓÃÜÇ®±Ò´æÈëÌØ¶¨Ç®°üµØÖ·¿É»ñµÃË«±¶·µ»¹¡£Ú²ÆÓʼþÐû³Æ£º"½«¼ÓÃÜÇ®±Ò·¢ËÍÖÁÄúµÄÈκÎΨһ´æ¿îµØÖ·£¬ÎÒÃǽ«Á¢¼´·µ»¹Äú·¢Ëͽð¶îµÄ200%¡£"¶àÃû¿Í»§ÔÚÉ罻ýÌåÉϻ㱨ÊÕµ½´ËÀàÓʼþ£¬²¿Ãſͻ§°µÊ¾Óʼþ·¢Ë͵½ÁË´ÓδÔÚÏßй¶¹ýµÄµØÖ·¡£ÍþвÐÐΪÕß½ö´ÍÓëÊÕ¼þÈËÁ½Ó×ʱÐж¯¹¦·ò£¬Ôì×÷½ôÆÈ¸ÐʹNordstrom¿Í»§¸ü¿ÉÄܻſ²Î¼Ó"ÂòÂô"¶øºöÊÓȦÌ×¼£Ïó£¬Èç±êÌâÖй«Ë¾Ãû³ÆÆ´Ð´ÃýÎóΪ"Normstorm"¡£È»¶ø£¬ÓÉÓÚÓʼþÀ´×Ômailto:nordstrom@eml.nordstrom.comÕâÒ»NordstromÓÃÓÚÓªÏú¡¢ÏúÊۺʹÙÏúͨѶµÄ¹Ù·½µØÖ·£¬ÈκκýŪ¼£Ï󶼿ÉÄܱ»ºöÊÓ£¬ÕâÅú×¢´æÔÚ°²È«·ì϶¡£Nordstromδ»ØÓ¦ÖÃÆÀÒªÇ󣬵«¿Í»§»ã±¨¹«Ë¾·¢ËÍÁËÖÒ¸æÓʼþ£¬¶½´Ù³ÉÔ±ºöÂÔ֮ǰµÄ"δ¾ÊÚȨ"Óʼþ¡£
https://www.bleepingcomputer.com/news/security/nordstroms-email-system-abused-to-send-crypto-scams-to-customers/


¾©¹«Íø°²±¸11010802024551ºÅ