ÀͰ£µÂÒøÐÐϵͳ¸üÐÂȱµãÖÂ44.8Íò¿Í»§Êý¾Ýй¶
°ä²¼¹¦·ò 2026-04-011. ÀͰ£µÂÒøÐÐϵͳ¸üÐÂȱµãÖÂ44.8Íò¿Í»§Êý¾Ýй¶
3ÔÂ30ÈÕ£¬ÀͰ£µÂÒøÐм¯ÍÅÔÚ3ÔÂ12ÖçÒ¹¼äϵͳ¸üйý³ÌÖÐÒòÒýÈëÈí¼þȱµã£¬µ¼Ö¶à´ï447,936Ãû¿Í»§µÄÓ×ÎÒÊý¾Ýй¶£¬Éæ¼°ÀͰ£µÂÒøÐÓ×¢¹þÀû·¨¿ËË¹ÒøÐкÍËÕ¸ñÀ¼ÒøÐÐʹÓÃÊÖ»úÒøÐÐÀûÓ÷¨Ê½µÄ¿Í»§¡£Õâ´ÎÊÂÎñÖУ¬²¿ÃÅÓû§¿É¶ÌÔݲ鿴ÆäËû¿Í»§µÄÂòÂô¼Í¼£¬Ô̺¬ÕË»§ÏêÇé¡¢¸¶¿î²Î¿¼ÐÅÏ¢¼°¹úÃñ±£ÏÕºÅÂëµÈÃô¸ÐÐÅÏ¢¡£¾Ýͳ¼Æ£¬Ô¼114,182Ãû¿Í»§µã»÷ÁËÏÔʾËûÈËÐÅÏ¢µÄÂòÂô£¬¶øÊý¾Ýй¶ÐèÂú×ãÓû§Í¬Ê±´ò¿ªÀûÓ÷¨Ê½µÄÌØ¶¨Ç°Ìá¡£ÀͰ£µÂÒøÐн«±äÂÒÔÒò¹é×ïÓÚÀýÐÐITϵͳ¸üÐÂÖеÄÈí¼þȱµã£¬²¢ÒÑÓÚ3ÔÂ12ÈÕÉÏÎçÏòÓ¢¹ú½ðÈÚÐÐΪ¼à¹Ü¾Ö£¨FCA£©»ã±¨£¬Í¬Ê±°´»®¶¨ÔÚ72Ó×ʱÄÚ֪ͨÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£ÒøÐÐÖÒ¸æ³Æ£¬Ð¹Â¶µÄÂòÂôÏêÇé¿ÉÄÜÉæ¼°·Ç±¾Ðпͻ§£¬ÈçÊÕ¿î·½Ó×ÎÒ¡£½ØÖÁĿǰ£¬ÒøÐÐÒÑÏò3625ÃûÊÜÓ°Ïì¿Í»§Ö§¸¶13.9ÍòÓ¢°÷£¨Ô¼18.3ÍòÃÀÔª£©Åâ³¥½ð£¬ÒÔÌí²¹À§ÈźͲ»±ã£¬²¢Ç¿µ÷ÎÞÖ¤¾ÝÅú×¢ÊÂÎñµ¼Ö²ÆÕþËðʧ»òÚ²ÆÐÐΪ£¬µ«½«³ÖÐø¼à¿Ø¡£
https://www.infosecurity-magazine.com/news/lloyds-glitch-exposed-500000/
2. DeepLoadÀûÓÃClickFixºÍWMIÓÆ¾Ã»¯ÇÔÈ¡ä¯ÀÀÆ÷ƾ֤
3ÔÂ30ÈÕ£¬ReliaQuest×êÑÐÈËÔ±Åû¶һ·ÀûÓÃClickFixÉç½»¹¤³Ì¼¿Á©·Ö·¢ÐÂÐͶñÒâÈí¼þ¼ÓÔØÆ÷DeepLoadµÄ¹¥»÷»î¶¯¡£¹¥»÷Á´Ê¼ÓÚClickFixµö¶ü£¬ÓÕÆÓû§ÔÚWindowsÔËÐжԻ°¿òÕ³ÌùPowerShellºÅÁî½â¾öÐé¹¹ÎÊÌâ£¬Ëæºóͨ¹ýºÏ·¨¹¤¾ßmshta.exeÏÂÔØ²¢Ö´ÐлìºÏµÄPowerShell¼ÓÔØÆ÷¡£¸Ã¼ÓÔØÆ÷½«Ö÷ÌâÖ°Äܰµ²ØÔÚÎÞÒâ˼±äÁ¿¸³ÖµÖУ¬¿ÉÄܽèÖúAI¹¤¾ß¿ª·¢»ìºÏ²ãÒÔºýŪ°²È«¹¤¾ß¡£DeepLoadÉî¶ÈÈÚÈëWindows»î¶¯ÊµÏÖÒñ±Î£ºÔغÉǶÈëËøÆÁÖÎÀí¹ý³ÌLockAppHost.exe£¬½ûÓÃPowerShellºÅÁÇֱ࣬½ÓŲÓÃÔÉúWindowsÖ÷Ì⺯ÊýÈÆ¹ý¼à¿Ø£¬²¢Í¨¹ýAdd-Type¶¯Ì¬ÌìÉúËæ»úÎļþÃûDLLÖÁTempĿ¼¶ã±Ü»ùÓÚÎļþµÄ¼ì²â¡£·ÀÓù¶ã±ÜÕ½Êõ·½Ã棬DeepLoadѡȡAPC×¢ÈëÔÚÊÜÐÅÀµ¹ý³ÌÄÚÔËÐÐÖ÷ÔØºÉ£¬ÎÞÐ轫½âÂëÔØºÉдÈë´ÅÅÌ£»ÀûÓÃWMIÊÂÎñ¶©ÔÄÔÚÈýÌìºóÎÞÐèÓû§²Ù×÷³ÁÐÂϰȾ"¸É¾»"Ö÷»ú£¬Í»ÆÆ´«Í³¸¸×Ó¹ý³ÌÁ´¼ì²âÂß¼¡£Æ¾Ö¤ÇÔȡģ¿éͨ¹ýÌáÈ¡ä¯ÀÀÆ÷ÃÜÂ롢Ͷ·Å¶ñÒâÀ©´óÀ¹½ØµÇ¼ƾ֤£¬²¢×Ô¶¯¼ì²âUÅ̵ȿÉÒÆ¶¯É豸£¬ÒÔ"ChromeSetup.lnk"µÈ¼Ù×°ÎļþʵÏÖ¶þ´Î´«²¼¡£
https://thehackernews.com/2026/03/deepload-malware-uses-clickfix-and-wmi.html
3. Axios NPM°üÔ⹩¸øÁ´¹¥»÷£¬¶ñÒâ´úÂë±»×¢Èë
3ÔÂ31ÈÕ£¬JavaScriptÉú̬Ö÷Ìâ×é¼þAxiosÔâ·ê¹©¸øÁ´¹¥»÷£¬¹¥»÷Õßͨ¹ýnpm×¢²á±í×¢Èë¶ñÒâ´«µÝÒÀÀµ£¬Òý·¢´ó¹æÄ£°²È«·çÏÕ¡£Axios×÷Ϊ¿í·º¼¯³ÉÓÚǰ¶Ë¿ò¼Ü¡¢ºó¶Ë΢·þÎñ¼°ÆóÒµÀûÓõÄHTTP¿Í»§¶Ë£¬Ã¿ÖÜnpmÏÂÔØÁ¿Ô¼8300Íò´Î£¬Õâ´ÎÊÂÎñDZÔÚÓ°ÏìÁìÓò¼«¹ã¡£¹¥»÷Õßѡȡ¡°Èƹý³ß¶È°ä²¼Á÷³Ì+¾«×¼ÒÀÀµ×¢È롱սÊõ£ºÎ´¾ÊÚȨ°ä²¼Ð°æAxios£¨Èç1.14.1¡¢0.30.4£©£¬×Ô¶¯ÒýÈ뺬¶ñÒâ´úÂëµÄplain-crypto-js@4.2.1°ü¡£¸Ã¶ñÒâ°üÓÚ3ÔÂ30ÈÕ23:59:12 UTC°ä²¼£¬Êý·ÖÖÓºó±»ÈëÇÖµÄAxios°æ±¾¼´ÉÏÏß¡£Socket°²È«¹¤¾ßÔÚ31ÈÕ00:05:41 UTC¼ì²âµ½Òì³££¬Í¹ÏÔ¹¥»÷ÕßÊÔͼÔÚ°²È«¹¤¾ß·´Ó³Ç°ÊµÏÖ¼±¾ç´«²¼¡£Õâ´Î¹¥»÷Í»ÆÆÍ¨Àý°æ±¾½ÚÔìÂß¼£¬Õý³£Á÷³ÌÖÐAxiosÊØ»¤Õß»áÔÚGitHub´ò±êÇ©ºóͬ²½°ä²¼ÖÁnpm£¬µ«¶ñÒâ°æ±¾Î´¶ÔÓ¦GitHub±êÇ©£¬Åú×¢¹¥»÷ÕßÖ±½Ó²Ù¿Ønpm×¢²á±í¡£Í¨¹ýÓ×ÁìÓòŤת£¬¹¥»÷Õß¶ã±Ü´ó¹æÄ£´úÂëÉó²é£¬ÀûÓô«µÝÒÀÀµÖ´ÐÐËÁÒâ´úÂë¡£×¢²á±íÈÕÖ¾ÏÔʾ£¬¶ñÒâ°ü¹ØÁªnpmÕË»§jasonsaayman£¬Ö¸ÏòÕË»§ÊÕÊÜ»ò¿ª·¢Õ߯¾Ö¤Ð¹Â¶·çÏÕ¡£
https://cybersecuritynews.com/axios-npm-packages-compromised/
4. ºÉÀ¼²ÆÕþ²¿ÍøÂç¹¥»÷ÊÂÎñÖ¶àϵͳ̱»¾
3ÔÂ31ÈÕ£¬ºÉÀ¼²ÆÕþ²¿3ÔÂ19ÈÕÔâ·êÍøÂç¹¥»÷£¬µ¼Ö²¿ÃÅϵͳÏÂÏߣ¬Ô̺¬¹ú¿âÒøÐÐÊý×ÖÃÅ»§¡£²ÆÕþ²¿ÉÏÖÜÅû¶£¬Õâ´Î°²È«·ì϶䲨¼°Ë°ÊÕ¡¢²¹ÖúÖÎÀí¼°½ø³ö¿ÚÂÉÀýϵͳ£¬µ«²¿ÃÅÔ±¹¤Êý¾ÝÊÜÓ°Ï죬¾ßÌåÈËÊý¼°Ãô¸ÐÊý¾Ýй¶Çé¿öÉÐδ¹«¿ª£¬ÇÒÎÞÍþвÐÐΪÕß»ò·¸×ï×éÖ¯Ðû³Æ¶Ô´ËÕÆ¹Ü¡£Îª¶ôÔì·çÏÕ£¬²ÆÕþ²¿ÓÚ3ÔÂ23ÈÕ×Ô¶¯¹Ø¹Ø¶à¸öϵͳ£¬Ö±½ÓÓ°ÏìÔ¼1600¼ÒÒÀÀµ¹ú¿â×ʽðµÄ¹«¹²»ú¹¹£¬º¸Çµ±²¿ÃÅί¡¢½ÌÓý×éÖ¯¡¢Éç»á»ù½ð¼°´¦Ëùµ±¾Ö¡£¹ú¿âÒøÐÐÊý×ÖÃÅ»§ÀëÏߺó£¬Óйػú¹¹ÎÞ·¨ÔÚÏß²éÎÊÕË»§Óà¶î¡¢ÉêÇë´û¿î»òµ÷È«ÈÕÄÚÏ޶µ«×ʽðÏÖʵ½Ó¼ûÓëÊÕ¸¶¿îÈÔͨ¹ýͨÀýÒøÐÐÇþ·Õý³£ÔË×÷£¬±ØÒªÊ±½«²ÉÈ¡ÈËΪ·½Ê½Î¬³Ö¸ù»ùÁ÷³Ì¡£ºÉÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©Óë±í²¿È¡Ö¤×¨¼ÒÒÑȾָµ÷²é£¬²ÆÕþ²¿ÒÑÏòºÉÀ¼Êý¾Ý±£»¤¾Ö£¨AP£©´«µÝÊÂÎñ£¬²¢Ìá½»ÖÁ¹ú¶È¾¯Ô±¸ß¿Æ¼¼·¸×ïÓ××é¡£²ÆÕþ²¿³¤°£¶û¿Æ¡¤º£Äþ°µÊ¾£¬Òò·¨Ö¤µ÷²é¼°°²È«Ë¼¿¼£¬ÏµÍ³¸´Ô¹¦·ò±íÔÝÎÞ·¨È·¶¨£¬Ðè³ÖÐø¼à¿Ø½øÕ¹¡£
https://www.bleepingcomputer.com/news/security/dutch-finance-ministry-takes-treasury-banking-portal-offline-after-breach/
5. È«Çò»¯¹¤¾ÞÍ·ÌÕÊϹ«Ë¾Ôâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷
3ÔÂ31ÈÕ£¬È«Çò»¯¹¤¾ÞÍ·ÌÕÊϹ«Ë¾Ôâ÷è÷ëÀÕË÷Èí¼þ×éÖ¯ÈëÇÖ£¬¸Ã×éÖ¯Òѽ«ÆäÁÐÈëTorÊý¾ÝÐ¹Â¶ÍøÕ¾£¬µ«ÉÐδ°ä²¼¾ßÌå¹¥»÷Ö¤¾Ý¡£ÌÕÊÏ×÷ΪÄêÊÕÈëÔ¼400ÒÚÃÀÔª¡¢Ô±¹¤³¬3.6Íò¡¢ÒµÎñ¸²¸Ç160¶à¸ö¹ú¶ÈµÄ¿ç¹úÆóÒµ£¬Éæ¼°°ü×°¡¢»ù½¨¡¢½»Í¨¼°Ïû·ÑÆ·µÈ¶àÁìÓò×ÊÁϹ©¸ø£¬Õâ´ÎÊÂÎñÒý¿¯ÐÐÒµ¸ß¶È¹Ø×¢¡£÷è÷ëÀÕË÷Èí¼þ×Ô2022ÄêÆð»îÔ¾£¬2025ÄêÒÑÔ¾ÉýΪ×î»îÔ¾µÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯Ö®Ò»£¬Ã¿ÔÂÊܺ¦Õß³¬40¼Ò£¬6Ô¸ü´ï·åÖµ100¼Ò¡£Æäѡȡ¡°Ë«³ÁÀÕË÷¡±Õ½Êõ£º¼È¼ÓÃÜÊܺ¦ÕßÊý¾Ý£¬ÓÖÍþвͨ¹ýTorÃÅ»§Ð¹Â¼ûô¸ÐÐÅÏ¢£¬Í¨¹ý´¹µö¹¥»÷ºÍÒÑÖª·ìÏ¶ÉøÈëÒ½ÁÆ¡¢Ôì×÷¡¢½ðÈڵȶàÐÐÒµ¡£µ±Ç°£¬ÌÕÊϹ«Ë¾ÕýÃæ¶ÔÊý¾Ýй¶·çÏÕÓëϵͳ¸´ÔѹÁ¦£¬¶ø÷è÷ë×éÖ¯µÄÄäÃûÐÔ¼°RaaSģʽʹ¹¥»÷ËÝÔ´ÄѶȼӾ硣
https://securityaffairs.com/190186/cyber-crime/qilin-ransomware-allegedly-breached-chemical-manufacturer-giant-dow-inc.html
6. AnthropicÒâ±íй¶Claude CodeÔ´´úÂë
3ÔÂ31ÈÕ£¬ÈËΪÖÇÄܹ«Ë¾AnthropicÒò±¨´ð²Ù×÷ʧÎóµ¼Ö¹ØÔ´Èí¼þClaude CodeµÄÔ´´úÂëÒâ±íй¶£¬Òý¿¯ÐÐÒµ¹Ø×¢¡£3ÔÂ31ÈÕ°ä²¼µÄClaude Code°æ±¾2.1.88ÖÐÃýÎóÔ̺¬ÁËÄÚ²¿µ÷ÊÔÎļþcli.js.map£¬¸ÃÎļþͨ¹ý¡°sourcesContent¡±×Ö¶ÎÆëȫ¶³öÁËÔ¼1900¸öÎļþ¡¢50ÍòÐдúÂ룬º¸ÇClaude¶àÏî¶À¼ÒÖ°ÄܵÄʵÏÖϸ½Ú¡£Ð¹Â¶ÊÂÎñÓÉ¿ª·¢ÕßChaofan ShouÔÚGitHubµÈƽ̨³õ´Î·¢ÏÖºóѸËÙ´«²¼£¬Ö»¹ÜAnthropicÇ¿µ÷δй¶¿Í»§Êý¾Ý»òƾ֤£¬µ«ÒÑÆô¶¯DMCAÇÖȨ֪ͨÁ÷³ÌÒÔɾ³ýÍøÉÏÁ÷´«µÄ´úÂë¡£Õâ´Îй¶Òâ±í¸æ·¢ÁËAnthropicÔÚ²âÊÔµÄÁ½´ó´´ÐÂÖ°ÄÜ£ºÈ«Ììºò±àÂëµÄ¡°×Ô¶¯Ä£Ê½¡±ºÍºó¶Ü³ÖÐøË¼Âǵġ°ÍýÏëģʽ¡±£¬Òý·¢¿ª·¢ÕßÉçÇø¶Ôδ¹«¿ªÖ°ÄܵķÖÎöÈȳ±¡£È»¶ø£¬°éËæÐ¹Â¶ÊÂÎñµÄÊÇÓû§¶ÔClaude·þÎñÁ÷Á¿ÏÞ¶ÈÒì³£µÄ¼¯Öз´À¡¡£¶àλPro¼°MaxÌײÍÓû§»ã±¨£¬ÔÚµ¥Ò»½»»¥ºóʹÓÃÂʼ±¾çìÉýÖÁ100%£¬Ô¶³¬Õý³£¿÷ËðËÙ¶È¡£Anthropic Games¹Ù·½È·ÈÏÔÚµ÷²é¸ÃÎÊÌ⣬¼¼ÊõÕÆ¹ÜÈËLydia HallieÔÚXƽ̨°µÊ¾£º¡°Óû§Ê¹ÓÃÁ¿Òì³£¼¤ÔöÒѳÉÍŶÓÊ×Òª½â¾ö¹¤×÷£¬ÎÒÃǽ«³ÖÐø¸üнøÕ¹¡£¡±½ØÖÁ3ÔÂ31ÈÕÏÂÎ磬¸ÃÁ÷Á¿Òì³£ÎÊÌâÈÔδÆëÈ«½â¾ö¡£
https://www.bleepingcomputer.com/news/artificial-intelligence/claude-code-source-code-accidentally-leaked-in-npm-package/


¾©¹«Íø°²±¸11010802024551ºÅ