Hightower HoldingÊý¾Ýй¶ӰÏì13Íò¿Í»§Ó×ÎÒÐÅÏ¢

°ä²¼¹¦·ò 2026-03-27

1. Hightower HoldingÊý¾Ýй¶ӰÏì13Íò¿Í»§Ó×ÎÒÐÅÏ¢


3ÔÂ26ÈÕ £¬½ðÈÚÖÎÀí·þÎñÌṩÉÌHightower AdvisorsµÄĸ¹«Ë¾Hightower Holding½üÈÕ֪ͨ³¬¹ý13ÍòÃûÓ×ÎÒÓйØÊý¾Ýй¶ÊÂÎñ¡£Hightower Holding×÷Ϊһ¼Ò¿Ø¹É¹«Ë¾ £¬Í¨¹ýHightower Advisors¡¢Hightower SecuritiesºÍHightower Trust CompanyµÈ×Ó¹«Ë¾Ìṩ²ÆÕþÖÎÀí¡¢ÍËÐݹ滮¡¢²Æ¸»ºÍͶ×ÊÕ÷ѯÒÔ¼°ÆäËû·þÎñ¡£¸Ã¹«Ë¾±¾ÖÜÏòÊÜÓ°ÏìÓ×ÎÒ·¢ËÍÊéÃæÍ¨ÖªÐÅ £¬Ð¹Â©¹«Ë¾ÔÚ2026Äê1Ô³õÔâ·êÍøÂç¹¥»÷ £¬ºÚ¿ÍÔÚ1ÔÂ8ÈÕÖÁ9ÈÕÆÚ¼ä´ÓÆä»·¾³ÖÐÇÔȡijЩÎļþ¡£Hightower¹«Ë¾°µÊ¾ £¬ËûÃÇÓëµÚÈý·½×¨¼Òһ·Éó²éÁ˱»µÁÎļþ £¬È·¶¨ÆäÖÐÔ̺¬ÐÕÃû¡¢Éç»á±£ÏÕºÅÂëºÍ¼ÝÊ»ÅÆÕÕºÅÂëµÈÓ×ÎÒÐÅÏ¢¡£¸Ã¹«Ë¾°µÊ¾ £¬Õâ´ÎÊý¾Ýй¶ÊÇÓÉÓÚÓû§Æ¾Ö¤±»µÁÓÃÔì³ÉµÄ £¬¶ø²»ÊÇÆä»·¾³´æÔÚȱµã¡£±¾ÖÜ £¬¸Ã¹«Ë¾Í¨ÖªÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒ £¬¸ÃÊÂÎñÓ°ÏìÁË131,483ÈË¡£Hightower½«ÎªÊÜÓ°ÏìÓ×ÎÒÌṩ12¸öÔµÄÃâ·ÑÉí·Ý͵ÇÔºÍÐÅÓþ¼à¿Ø·þÎñ¡£


https://www.securityweek.com/hightower-holding-data-breach-impacts-130000/


2. ÍþвÐÐΪÕßÕë¶ÔTikTokÆóÒµÕË»§ÌáÒé´¹µö¹¥»÷


3ÔÂ26ÈÕ £¬ä¯ÀÀÆ÷Íþв¼ì²âºÍÏìÓ¦¹«Ë¾PushSecurity½üÈÕ·¢ÏÖÍþвÐÐΪÕßÕýÒÔTikTokÆóÒµ°æÕË»§ÎªÖ¸±êÌáÒéÍøÂç´¹µö»î¶¯¡£ÓÉÓÚTikTokóÒ×ÕË»§¼«Ò×±»ÀÄÓÃÓÚ¶ñÒâ¸æ°×»î¶¯¡¢¸æ°×ڲƭºÍ¶ñÒâÄÚÈÝ´«²¼ £¬Òò¶ø³ÉΪ¹¥»÷Ö¸±ê¡£Õâ´Î¹¥»÷ÓëÈ¥Äê¼Í¼ÔÚ°¸µÄÕë¶ÔGoogleAdManagerÕË»§µÄ¹¥»÷ÓйØÁª¡£Êܺ¦Õß±»ÓÕÆ­µ½CloudflareÍйܵĴ¹µöÒ³Ãæ £¬ÕâÐ©Ò³ÃæÓÚ3ÔÂ24ÈÕͨ¹ýNiceNIC×¢²á £¬¶øNiceNICÊÇÒ»¸öʱʱ±»ÍøÂ簲ȫ×êÑÐÈËÔ±¾Ù±¨ÓÃÓÚÍøÂç·¸×ï»î¶¯µÄ×¢²áÉÌ¡£³õʼÁ´½Óͨ¹ýºÏ·¨µÄGoogleStorageURL³Á¶¨Ïò £¬Ê¹ÓÃCloudflareTurnstile²é³­×èÖ¹»úеÈË £¬¶øºó³Á¶¨Ïòµ½¶ñÒâÒ³Ãæ¡£ÕâЩ¶ñÒâÒ³Ãæ¼ÙÒâTikTokforBusinessºÍGoogleCareersµÄÆÌÅÅͨ»°Ò³Ãæ £¬ÒªÇó½Ó¼ûÕßÔÚ±íµ¥ÖÐÊäÈë¸ù»ùÐÅÏ¢ £¬ÒÔÑéÖ¤ËûÃÇʹÓõÄÊÇÆóÒµµç×ÓÓʼþµØÖ·¡£ÊµÏִ˲½Öèºó £¬Êܺ¦Õ߻ῴµ½Ò»¸öαÔìµÄµÇÂ¼Ò³Ãæ £¬ÕâÊÇÒ»¸ö·´Ïò´úÀí £¬Ö¼ÔÚ²¶»ñÍ´´¦ºÍ»á»°cookie £¬²¢½«ËüÃÇй¶¸ø¹¥»÷Õß¡£


https://www.bleepingcomputer.com/news/security/tiktok-for-business-accounts-targeted-in-new-phishing-campaign/


3. Ç×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯Bearlyfy¶Ô¶í·¢Æð70Óà´Î¹¥»÷


3ÔÂ26ÈÕ £¬×êÑÐÈËÔ±½üÈÕ·¢ÏÖ £¬Ò»¸öÃûΪBearlyfyµÄÇ×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯ÔÚ´ÓǰһÄêÖжԶíÂÞ˹¹«Ë¾·¢ÆðÁË70ÂÅ´ÎÍøÂç¹¥»÷ £¬´Ë¿ÌÕýÀûÓÃпª·¢µÄÀÕË÷Èí¼þ¹¤¾ßÉý¼¶Æä¹¥»÷»î¶¯¡£BearlyfyÓÚ2025Äê1Ô³õ´Î³öÏÖ £¬×î³õµÄÖ¸±êÊǹæÄ£½ÏÓ׵ĶíÂÞ˹ÆóÒµ¡£¾Ý¶íÂÞË¹ÍøÂ簲ȫ¹«Ë¾F6µÄÒ»·Ý»ã±¨ÏÔʾ £¬ÔÚÆäÔçÆÚÐж¯ÖÐ £¬¹¥»÷Õߵļ¼ÊõˮƽÓÐÏÞ £¬Ë÷ÒªµÄÊê½ðÒ²Ïà¶Ô½ÏµÍ £¬½öΪ¼¸Ç§ÃÀÔª¡£×êÑÐÈËÔ±°µÊ¾£º¡°²»µ½Ò»Äê £¬Õâ¸ö×éÖ¯¾Í³ÉÁ˶íÂÞ˹´óÐÍÆóÒµµÄجÃΡ£¡±ËûÃÇ»¹²¹³ä˵ £¬¸Ã×éÖ¯ÔÚ×î½üµÄÏ®»÷ÖÐË÷ÒªµÄÊê½ðÒѾ­¸ß´ïÊýÊ®ÍòÃÀÔª¡£¸Ã×éÖ¯µÄÖØÒªÖ¸±ê¼Å×о­¼ÃÉϵÄ £¬Ò²ÓÐÕþÖÎÉϵÄ¡£ËûÃÇËÆºõÔÚ¶Ô¶íÂÞ˹¹«Ë¾Ôì³É¡°×î´óˮƽµÄÇÖº¦¡± £¬Í¬Ê±»¹Í¨¹ýÀÕË÷Èí¼þÖ§¸¶Êê½ðÀ´Ä²Àû¡£F6¹À¼Æ £¬Ô¼ÄªÎå·ÖÖ®Ò»µÄÊܺ¦Õß×îÖÕ»áÖ§¸¶Êê½ð¡£¸Ã×éÖ¯½üÆÚÆðÍ·²¿Êð×ÔÖ÷Ñз¢µÄ¶ñÒâÈí¼þ £¬±ê־ȡÆäÐж¯½øÈëÁËÒ»¸öеĽ׶Ρ£×Ô3Ô³õÒÔÀ´ £¬BearlyfyÒ»ÏòÔÚʹÓÃÒ»ÖÖÃûΪGenieLockerµÄ¶¨Ôì°æWindowsÀÕË÷Èí¼þ £¬×êÑÐÈËÔ±ÒÔΪ¸ÃÈí¼þÊÇÓɸÃ×éÖ¯×ÔÐпª·¢µÄ¡£


https://therecord.media/ransomware-ukraine-russia-bearlyfy


4. Ó¢¹úÔì²Ã¶«ÄÏÑÇ·¸·¨ÂòÂôƽ̨Xinbi¼°8ºÅ¹«Ô°


3ÔÂ26ÈÕ £¬Ó¢¹ú±í½»¡¢Áª¹úºÍ·¢Õ¹ÊÂÎñ²¿(FCDO)½üÈÕ¶ÔXinbiÖ´ÐÐÔì²Ã £¬XinbiÊÇÒ»¸öÖÐÎÄÔÚÏßÊг¡ £¬Ïò¶«ÄÏÑǵÄÚ¿Æ­ÍøÂçÏúÊÛ±»µÁÊý¾ÝºÍÎÀÐÇ»¥ÁªÍøÉ豸¡£¾ÝÐÅ £¬»ùÓÚTelegramµÄÂòÂôƽ̨XinbiÒ²Ô®ÊÖ³¯ÏÊÍþвÐÐΪÕßÏ´Ç® £¬ÕâЩ¼ÓÃÜÇ®±ÒÊÇ´ÓÊÀ½ç¸÷µØµÄ¹«Ë¾ºÍÓ×ÎÒÔâ·êµÄ´ó¹æÄ£ÍµÇÔÖÐÇÔÈ¡µÄ¡£¾ÝÇø¿éÁ´·ÖÎö¹«Ë¾Chainalysis³Æ £¬2021ÄêÖÁ2025Äê¼ä £¬Xinbi´¦ÖÃÁ˳¬¹ý199ÒÚÃÀÔªµÄÂòÂô £¬´Ù³ÉÁË´ÓÎÞÅÆ³¡±íÂòÂôºÍÏ´Ç®µ½ÏúÊÛ±»µÁÓ×ÎÒÊý¾Ý¿âµÈ¸÷Àà»î¶¯¡£½ñÌìµÄÔì²Ã´ëÊ©»¹Õë¶Ô8ºÅ¹«Ô°£¨Çø¿éÁ´·ÖÎö¹«Ë¾EllipticÓëÍõ×Ó¼¯ÍÅ·¸×OÍÅÓйØÁªµÄ´ó¹æÄ£Ú¿Æ­ÏîÄ¿£©ºÍLegendInnovationCo£¨8ºÅ¹«Ô°µÄÔËÓªÉÌ£©¡£Ó¢¹ú±í½»¡¢Áª¹úºÍ·¢Õ¹ÊÂÎñ²¿ÖÜËݵʾ£º"½ñÌì £¬µ±¾ÐÄÓ´óÁ˽ø¹¥ÕâЩڿƭÖÐÐĵÄÁ¦¶È £¬Ö¸±êÊÇ×î½ü·¢ÏÖµÄÃûΪ'8ºÅ¹«Ô°'µÄÉèÊ©µÄËùÓÐÕߺ;­ÓªÕß £¬¸ÃÉèÊ©±»ÒÔΪÊǼíÆÒÕ¯×î´óµÄÚ¿Æ­Îѵã £¬¿É°üÈÝ2ÍòÃû±»··Ô˵ÄÀ͹¤¡£"


https://www.bleepingcomputer.com/news/security/uk-sanctions-xinbi-marketplace-linked-to-asian-scam-centers/


5. °¢¼Ö¿Ë˹×ãÇò¾ãÀÖ²¿ÔâºÚ¿ÍÈëÇÖÊý°ÙÈËÊý¾Ýй¶


3ÔÂ26ÈÕ £¬°¢¼Ö¿Ë˹×ãÇò¾ãÀÖ²¿ÊÇÊÀ½çÉÏ×î³É¹¦µÄ×ãÇò¾ãÀÖ²¿Ö®Ò» £¬ÔøËĴλñµÃÅ·ÖÞ¹Ú¾üÁªÈü¹Ú¾ü £¬²¢»ñµÃ¹ý36´ÎºÉ¼×ÁªÈü¹Ú¾ü¡£¾ãÀÖ²¿ÔÚÉêÃ÷ÖаµÊ¾£º"ÎÒÃǽüÈÕ·¢ÏÖ £¬Ò»ÃûºÉÀ¼ºÚ¿Í·¸·¨ÈëÇÖÁËÎÒÃDz¿ÃÅϵͳ £¬²¢²é¿´Á˲¿ÃÅÊý¾Ý¡£ÎÒÃÇ´Ë¿Ì֪· £¬Ö»Óм¸°ÙÈ˵ĵç×ÓÓʼþµØÖ·±»²é¿´ÁË¡£´Ë±í £¬¶ÔÓÚ²»µ½20Ãû±»²»ÈݽøÈëÔ˶¯³¡µÄÈË £¬ËûÃǵÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµ®ÉúÈÕÆÚÒ²±»»ñÈ¡¡£"RTL¼ÇÕß´ÓºÚ¿Í´¦»ñµÃÏßË÷ºó £¬¶ÀÁ¢ÑéÖ¤ÁËÕâЩ·ì϶ £¬²¢±¨Â·³Æ £¬ËûÃÇ¿ÉÄܽ«¼¾Æ±´Ó³ÖÓÐÕßÈöɸøËÁÒâÈË £¬½Ó¼ûºÍÅú¸ÄÔ˶¯³¡½ûÈë¼Í¼ £¬²¢Í¨¹ýAPIºÍ¹²ÏíÃÜÔ¿¿í·º½Ó¼ûÇòÃÔÊý¾Ý¡£ÔÚÒ»´ÎÑÝʾÖÐ £¬ËûÃǽöÓü¸ÃëÖӾͳÁзÖÅäÁËÒ»ÕÅVIP¼¾Æ±¡£RTLÐû³ÆËûÃÇÄܹ»²Ù¿Ø42000Õż¾Æ±¡¢538¸öÇòÃÔÇò³¡½ûÈëÁî £¬²¢²é¿´³¬¹ý30Íò¸öÕË»§µÄ¾ßÌåÐÅÏ¢¡£°¢¼Ö¿Ë˹×ãÇò¾ãÀÖ²¿°µÊ¾ £¬ËûÃÇÒÑÀñƸ±í²¿×¨¼ÒÀ´È·¶¨ÊÂÎñµÄÁìÓò²¢ÕÒ³öµ××ÓÔ­Òò £¬Í¬Ê±Ö¸³ö £¬Ð¹Â¶µÄÊý¾Ý²¢Î´±»Ð¹Â¶¡£ËùÓÐÒÑ·¢Ïֵķì϶¾ùÒѽ¨¸´ £¬²¢ÒѲÉÈ¡¶î±íµÄ°²È«´ëÊ©¡£ºÉÀ¼Êý¾Ý±£»¤»ú¹¹ºÍ¾¯·½Ò²Òѽӵ½ÏàӦ֪ͨ¡£


https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/


6. ÑÇÃÀÄáÑÇÏÓÒÉÈËÒòÖÎÀíRedLine¶ñÒâÈí¼þ±»Òý¶ÉÃÀ¹ú


3ÔÂ26ÈÕ £¬Ò»ÃûÑÇÃÀÄáÑÇÏÓÒÉÈ˽üÈÕ±»Òý¶Éµ½ÃÀ¹ú £¬Ãæ¶ÔÐÌÊÂÖ¸¿Ø £¬Ëû±»Ö¸¿ØÐ­ÖúÖÎÀíRedLine £¬ÕâÊǽüÄêÀ´×î·è¿ñµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÐж¯Ö®Ò»¡£HambardzumMinasyanÓÚ3ÔÂ23ÈÕ±»²¶ £¬²¢ÔÚ°Â˹͡ÁªÍõ·¨Ôº³öÍ¥¡£ÃÀ¹ú¼ì²ì¹ÙÖ¸¿ØËû×¢²áÁËRedLine»ù´¡ÉèÊ©µÄ²¿ÃÅÐ鹹רÓ÷þÎñÆ÷ÒÔ¼°RedLine¹¥»÷ÆÚ¼äʹÓõÄÁ½¸öÍøÕ¾ÓòÃû¡£¾Ý³Æ £¬Ëû»¹ÓÚ2021Äê11ÔÂ×¢²áÁËÒ»¸ö¼ÓÃÜÇ®±ÒÕË»§ £¬RedLineÍøÂç·¸×ïÍÅ»ïÀûÓøÃÕË»§½Ó¹ÜͬÃ˸¶¿î £¬²¢´´½¨ÁËÔÚÏßÎļþ¹²Ïí´æ´¢¿â £¬ÓÃÓÚÏòͬÃ˳ÉÔ±·Ö·¢¶ñÒâÈí¼þ¡£ÔÚÆäËûͬ»ïµÄÔ®ÊÖÏ £¬HambardzumMinasyanÖÎÀíןÃÐж¯µÄÊý×Ö»ù´¡ÉèÊ© £¬Ô̺¬ÖÎÀíÃæ°åºÍºÅÁîÓë½ÚÔì(C2)·þÎñÆ÷ £¬¹ØÁªÈËÔ±ÀûÓÃÕâЩ·þÎñÆ÷½«ÐÅÏ¢ÇÔÈ¡·¨Ê½²¿Êðµ½Êܺ¦ÕßµÄÊÜϰȾÉ豸ÉÏ¡£¾Ý³Æ £¬ÕâЩ¹²Ä¹Øß»¹ÏòRedLineµÄÏÖʵºÍDZÔڵĹØÁª·½Ìṩ֧³Ö £¬»Ø¸²ËûÃǵÄÎÊÌâºÍÒªÇó £¬²¢ºÏı´ÓÊÜϰȾµÄϵͳÖÐÇÔÈ¡²ÆÕþÐÅÏ¢ £¬Í¨¹ý¼ÓÃÜÇ®±ÒÂòÂôËùºÍÆäËû·½Ê½Ï´Ç®·¸·¨»ñµÃµÄ×ʽð¡£


https://www.bleepingcomputer.com/news/security/suspected-redline-infostealer-administrator-extradited-to-us/