¸»Ê¿¿µ±±ÃÀÔâNitrogenÀÕË÷Èí¼þ¹¥»÷
°ä²¼¹¦·ò 2026-05-131.¸»Ê¿¿µ±±ÃÀÔâNitrogenÀÕË÷Èí¼þ¹¥»÷
5ÔÂ12ÈÕ£¬¸»Ê¿¿µ½üÈÕ֤ʵÆä±±ÃÀÒµÎñÔâ·êÍøÂç¹¥»÷¡£´Ëǰ£¬ÃûΪNitrogenµÄÀÕË÷Èí¼þÍÅ»ïÒѽ«¸Ãµç×Ó²úÆ·Ôì×÷ÉÌÁÐÈëÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¸»Ê¿¿µ½²»°È˰µÊ¾£¬¹«Ë¾±±ÃÀ²¿Ãʤ³§Ôâ·ê¹¥»÷ºó£¬ÍøÂ簲ȫÍŶÓÁ¢¼´Æô¶¯Ó¦¼±»úÔ죬²ÉÈ¡¶àÏîÔËÓª´ëʩȷ±£³ö²úºÍ½»¸¶Â½ÐøÐÔ£¬ÊÜÓ°Ï칤³§ÕýÖ𲽸´ÔÕý³£³ö²ú¡£È»¶ø£¬¸üÁîÈËÓÇÓôµÄÊÇ£¬NitrogenÍÅ»ïÐû³ÆÒÑÈëÇÖÕâ¼Ǫ̀ÍåÆóÒµ£¬ÇÔÈ¡¶à´ï8TBµÄÊý¾Ý£¬º¸Ç³¬¹ý1100Íò¸öÎļþ¡£¾Ý·¸·¨·Ö×Óй©£¬Ð¹Â¶ÄÚÈÝÔ̺¬»úÃÜÖ¸Áî¡¢ÄÚ²¿ÏîÄ¿ÎĵµÒÔ¼°ÓëÓ¢ÌØ¶û¡¢Æ»¹û¡¢¹È¸è¡¢´÷¶û¡¢Ó¢Î°´ïµÈ³ÛÃûÆóÒµÏîÄ¿Óйصļ¼Êõͼֽ¡£²»Í⣬¸»Ê¿¿µ»Ø¾øÖ¤ÊµÕâЩ¿Í»§ÐÅÏ¢ÊÇ·ñÈ·ÇÐʵÕâ´ÎÊý×ÖÈëÇÖÖб»ÇÔÈ¡¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ²¢·Ç¸»Ê¿¿µ³õ´ÎÔâ·êÀÕË÷Èí¼þ¹¥»÷¡£2024Ä꣬LockBitÐû³ÆÏ°È¾Á˸»Ê¿¿µ¿Æ¼¼¼¯ÍÅÆìϰ뵼ÌåÉ豸Ôì×÷ÉÌFoxsemicon Integrated Technology£»2022Ä꣬ͳһ·¸×ïÍÅ»ï»¹Ôø¹¥»÷¸»Ê¿¿µÎ»ÓÚÄ«Î÷¸çµÄÒ»¼Ò×Ó¹«Ë¾¡£
https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144
2. Ó¢¹úË®Îñ¹«Ë¾66ÍòÈËÐÅϢй¶±»·£96ÍòÓ¢°÷
5ÔÂ12ÈÕ£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©½üÈÕ¶ÔÄÏ˹Ëþ¸£µÂ¿¤Ë®ÎñÓÐÏÞ¹«Ë¾¼°Æäĸ¹«Ë¾ÄÏ˹Ëþ¸£µÂ¿¤ÓÐÏÞ¹«Ë¾´¦ÒÔ96.39ÍòÓ¢°÷£¨Ô¼130ÍòÃÀÔª£©µÄ·£¿î£¬ÔÒòÊǸù«Ë¾ÒòÍøÂç¹¥»÷µ¼Ö³¬¹ý66ÍòÃû¿Í»§ºÍÔ±¹¤µÄÓ×ÎÒÊý¾Ýй¶¡£Õâ¼ÒÿÌìÏò160ÍòÏû·ÑÕß¹©¸ø3.3ÒÚÉýÒûÓÃË®µÄ¹«Ë¾£¬ÓÚ2022ÄêÅû¶³ÉÎªÍøÂç¹¥»÷Ö¸±ê²¢µ¼ÖÂITÔËÓªÖжϡ£Æäʱ£¬¹«Ë¾Ôø±ç²µCl0pÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹ÜµÄ˵·¨£¬µ«¹ýºó֤ʵй¶µÄÊý¾ÝÑù±¾Êôʵ¡£¹¥»÷¿É×·ÒäÖÁ2020Äê9Ô£¬µ«ÖØÒª²úÉúÔÚ2022Äê5ÔÂÖÁ7ÔÂÖ®¼ä£¬Â¶³öÁ˸ù«Ë¾ÔÚÊý¾Ý°²È«·½Ãæ´æÔڵijÁ´óȱµã£¬Ê¹¿Í»§ºÍÔ±¹¤ÔÚ½üÁ½Ä깦·òÀï´¦ÓÚÒ×Êܹ¥»÷״̬¡£µ÷²éÏÔʾ£¬Õâ´ÎÊÂÎñÊÇͨ¹ýÍøÂç´¹µö¹¥»÷Ôì³ÉµÄ£¬¹¥»÷ÕßÀûÓô¹µö¼¿Á©ÔÚ¹«Ë¾ÏµÍ³ÖÐ×°ÖöñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þ³¤´ï20¸öÔÂδ±»·¢ÏÖ¡£2022Äê5ÔÂÖÁ7ÔÂÆÚ¼ä£¬¹¥»÷Õ߳ɹ¦ÌáÉýÍøÂçȨÏÞ²¢»ñµÃÓòÖÎÀíÔ±½Ó¼ûȨ£¬Ö±µ½Îôʱ7ÔÂÒòIT»úÄÜÎÊÌâÒý·¢µ÷²éºó²Å±»·¢ÏÖ¡£Ð¹Â¶µÄÊý¾Ý¼«ÎªÃô¸Ð£¬Ô̺¬È«Ãû¡¢ÏÖʵµØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢¿Í»§ÕË»§Æ¾Ö¤¡¢ÒøÐÐÕË»§¾ßÌåÐÅÏ¢£¬ÒÔ¼°Ô±¹¤ÈËÁ¦×ÊÔ´Êý¾ÝÈç¹úÃñ±£ÏÕºÅÂëµÈ¡£
https://www.bleepingcomputer.com/news/security/uk-fines-water-supplier-13m-for-exposing-data-of-664k-customers/
3. BWH¾Æµê¼¯ÍÅÔâ·ê³¤´ï°ëÄêÊý¾Ýй¶
5ÔÂ12ÈÕ£¬BWH¾Æµê¼¯ÍŽüÈÕÅû¶ÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬·¸·¨·Ö×ÓÔÚ³¬¹ýÁù¸öԵŦ·òÀï·¸·¨»ñÈ¡Á˾Ƶê¿ÍÈ˵ÄÔ¤Ô¼Êý¾Ý¡£×÷ΪȫÇò×î´óµÄ¾ÆµêÍøÂçÖ®Ò»£¬BWHÔÚ100¶à¸ö¹ú¶ÈÔËÓª×Å4000¶à¼Ò¾Æµê£¬ÆìÏÂÕ¼ÓÐBest Western Hotels & Resorts¡¢WorldHotelsºÍSure HotelsµÈÆ·ÅÆ£¬º¸Ç´Ó¾¼ÃÐ͵½ÉÝ»ªÐ͵ĸ÷Àà¾Æµê¡£Æ¾¾Ý¸Ã¼¯ÍÅ·¢Ë͸øÊÜÓ°Ïì¿Í»§µÄÊý¾Ýй¶֪ͨ£¬2026Äê4ÔÂ22ÈÕ£¬¹«Ë¾·¢ÏÖ´æ´¢²¿ÃÅ¿ÍÈËÔ¤Ô¼Êý¾ÝµÄÍøÂçÀûÓ÷¨Ê½´æÔÚδ¾ÊÚȨµÄ»î¶¯¡£½øÒ»´ëÊ©²éÏÔʾ£¬ÔÚ2025Äê10ÔÂ14ÈÕÖÁ2026Äê4ÔÂ22ÈÕÆÚ¼ä£¬Ô̺¬¿ÍÈËÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¼ÒͥסַµÈÁªÏµÐÅÏ¢£¬ÒÔ¼°Ô¤Ô¼±àºÅ¡¢ÈëסÈÕÆÚºÍÈκÎÌØÊâÒªÇóµÈÔ¤Ô¼ÏêÇ飬±»Î´¾ÊÚȨµÄµÚÈý·½½Ó¼û¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸Ã¹«Ë¾Ã÷È·°µÊ¾£¬ÊÜÓ°ÏìµÄϵͳÖв¢Î´´æ´¢Ö§¸¶ÐÅÏ¢ºÍÆäËû²ÆÕþÊý¾Ý£¬Òò¶ø¿ÍÈ˵ÄÖ§¸¶ÐÅϢûÓÐй¶¡£ÔÚ·¢ÏÖÈëÇÖºó£¬BWHѸËÙ½«ÊÜÓ°ÏìµÄÀûÓ÷¨Ê½ÏÂÏߣ¬³·ÏúÁËÓйؽӼûȨÏÞ£¬²¢ÀñƸ±í²¿ÍøÂ簲ȫר¼ÒÖ§³Öµ÷²éºÍ¼Óǿϵͳ±£»¤¡£¾Æµê¼¯ÍÅ»¹Ïò¿ÍÈË·¢³öÖҸ棬ÌáÐѾ¯ÌèÀûÓñ»µÁÔ¤Ô¼Êý¾ÝÌáÒéµÄÍøÂç´¹µöÓʼþ¡¢¶ÌÐÅ¡¢µç»°»òÐéαԤԼÐÅÏ¢Ú¿Æ¡£
https://securityaffairs.com/192038/data-breach/hackers-accessed-bwh-hotels-reservation-system-for-months.html
4. ˹¿Â´ïÆû³µÍøÉÏÉ̵êÔâ¹¥»÷£¬¿Í»§Ó×ÎÒÐÅϢй¶
5ÔÂ12ÈÕ£¬¹«¹²Æû³µ¼¯ÍÅÈ«×Ê×Ó¹«Ë¾Ë¹¿Â´ïÆû³µ½üÈÕÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬¹«Ë¾·¢ÏÖδ¾ÊÚȨµÄÈËÔ±ÀûÓÃÔÚÏßÉ̵êʹÓõij߶ÈÈí¼þÖеķì϶£¬ÁÙʱ·¸·¨½Ó¼ûÁËÉ̵êϵͳ¡£·¢ÏÖÈëÇÖÊÂÎñºó£¬¹«Ë¾ÒÑÏòÓйز¿ÃŻ㱨£¬½¨¸´Á˱»ÀûÓõݲȫ·ì϶£¬²¢½«´ËÊÂÎñÒÆ½»¸ø×¨ÒµµÄITȡ֤ÍŶӽøÐм¼Êõ·ÖÎö£¬Í¬Ê±»ã±¨¸øÓйصÄÊý¾Ý±£»¤¼à¹Ü»ú¹¹¡£±»ÇÔÈ¡µÄ¿Í»§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëµÈÁªÏµÐÅÏ¢£¬ÒÔ¼°¶©µ¥ÐÅÏ¢ºÍµÇ¼ʹ´¦¡ª¡ªÔ̺¬µç×ÓÓʼþµØÖ·ºÍÃÜÂëµÄ¼ÓÃܹþÏ£Öµ¡£Ë¹¿Â´ïÇ¿µ÷£¬¹¥»÷ÕßÎÞ·¨½Ó¼ûÊÜÓ°Ïì¿Í»§µÄ²ÆÕþÐÅÏ¢£¬ÓÉÓÚÆëÈ«µÄÐÅÓþ¿¨ÐÅÏ¢²¢Î´´æ´¢ÔÚÉ̵êϵͳÖУ¬¶øÊÇÓÉÏàÓ¦µÄÖ§¸¶·þÎñÌṩÉÌȫȨ´¦Ö᣹ÌȻ˹¿Â´ï°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢±»½Ó¼ûµÄÊý¾ÝÒѱ»ÀÄÓ㬵«¸Ã¹«Ë¾ÖÒ¸æÊÜÓ°ÏìµÄÓ×ÎÒ¾¯ÌèÕë¶ÔËûÃǵÄÍøÂç´¹µö¹¥»÷£¬²¢³ö¸ñÖ¸³öÈôÊǿͻ§³Á¸´Ê¹ÓÃÒ»ÑùµÄµÇ¼ʹ´¦£¬ÍþвÐÐΪÕß¿ÉÄ᳢ܻÊԵǼËûÃÇµÄÆäËûÔÚÏßÕÊ»§¡£Ä¿Ç°Ë¹¿Â´ïÉÐδÅû¶ÊÜÓ°ÏìµÄ¿Í»§×ÜÊýÒÔ¼°ÊÇ·ñÓë¹¥»÷ÕßÓйýÊê½ðÖ§¸¶ÁªÏµ¡£
https://www.bleepingcomputer.com/news/security/skoda-warns-of-customer-data-breach-after-online-shop-hack/
5. ±öÖÝÔìÒ©¾ÞÍ·West PharmaceuticalÔâÀÕË÷¹¥»÷
5ÔÂ12ÈÕ£¬±öϦ·¨ÄáÑÇÖÝÔìÒ©¾ÞÍ·West Pharmaceutical Services½üÈÕÅû¶£¬¹«Ë¾ÓÚ5ÔÂ4ÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬Ä¿Ç°ÔÚ´¹Î£¸´ÔÊÜÓ°ÏìµÄϵͳ¡£¸Ã¹«Ë¾ÔÚÒ»·ÝÊÂÎñ֪ͨÖаµÊ¾£¬¹¥»÷²úÉúºóÁ¢¼´×Ô¶¯¹Ø¹Ø²¢¸ôÀëÁËÊÜÓ°ÏìµÄ±¾µØ»ù´¡ÉèÊ©¡£Æ¾¾ÝÖÜÒ»Ìá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»áµÄÎļþ£¬ÕâЩ¶ôÔì´ëÊ©Òѵ¼Ö¹«Ë¾È«ÇòÁìÓòÄÚµÄÒµÎñÔËÓªÊܵ½×ÌÈÅ¡£ÆäËûÊÂÎñÓ¦¶Ô´ëÊ©Ô̺¬ÏÞ¶È¶ÔÆóҵϵͳµÄ½Ó¼ûºÍÆô¶¯Î£»úÖÎÀíºÍ̸¡£ÎªÓ¦¶ÔÕâ´Î¹¥»÷£¬Õâ¼ÒÔìÒ©¾ÞÍ·ÀñƸÁËPalo Alto NetworksµÄUnit 42Íþвµý±¨ºÍÊÂÎñÏìÓ¦ÍŶÓÐÖú½øÐжôÔ졢ϵͳ¸´ÔºÍÊÂÎñµ÷²é£¬Í¬Ê±ÒÑ֪ͨ·¨Âɲ¿ÃÅ¡£¸Ã¹«Ë¾°µÊ¾£¬¹ÌÈ»Ö÷ÌâÆóҵϵͳÒѸ´Ô£¬²¿ÃÅÕ¾µãµÄ·¢»õ¡¢ÊÕ»õºÍÔì×÷µÈ¹Ø¼üÁ÷³ÌÒ²ÒѳÁÐÂÆô¶¯£¬ÆäÓàÕ¾µãµÄ¸´Ô¹¤×÷ÈÔÔÚ½øÐÐÖУ¬µ«È«Ã渴ԵŦ·ò±íÉÐδ×îÖÕÈ·¶¨¡£West PharmaceuticalÏòSECÅû¶£¬¹¥»÷ÕßÔÚ²¿ÊðÎļþ¼ÓÃÜÀÕË÷Èí¼þ֮ǰ´ÓÆäϵͳÖÐÇÔÈ¡ÁËÊý¾Ý£¬¹«Ë¾ÔÚµ÷²éÊÜÓ°ÏìÊý¾ÝµÄÁìÓò¡£¹ÌÈ»¸Ã¹«Ë¾Ã»ÓÐÖ¸Ã÷ÊÇÄĸöÀÕË÷Èí¼þ×éÖ¯·¢ÆðÁËÈëÇÖ£¬µ«°µÊ¾¡°ÒѲÉÈ¡´ëÊ©£¬Ö¼ÔÚ½µµÍй¶Êý¾Ý´«²¼µÄ·çÏÕ¡±£¬Õⰵʾ¿ÉÄÜÒѾÓë¹¥»÷Õß½øÐÐÁ˽»Éæ¡£
https://www.securityweek.com/west-pharmaceutical-services-hit-by-disruptive-ransomware-attack/
6. ´ó¹æÄ£¹©¸øÁ´¹¥»÷ÈëÇÖnpmºÍPyPIÊý°Ù¸öÈí¼þ°ü
5ÔÂ12ÈÕ£¬Ò»³¡ÃûΪShai-HuludµÄÐÂÐ͹©¸øÁ´¹¥»÷»î¶¯Òѵ¼ÖÂnpmºÍPyPIÉϵÄÊý°Ù¸öÈí¼þ°üÔâµ½ÈëÇÖ£¬¹¥»÷ÕßÖ²ÈëÇÔȡƾ֤µÄ¶ñÒâÈí¼þ£¬Ö¸±êÖ±Ö¸¿ª·¢Õß¡£Õâ´Î¹¥»÷±»ÒÔΪÊÇÓÉÍþв×éÖ¯TeamPCPËùΪ£¬¹¥»÷Õß½Ù³ÖÁËÓÐЧµÄOpenID ConnectÁîÅÆ£¬°ä²¼ÁË´øÓпÉÑéÖ¤ÆðÔ´Ö¤Ã÷µÄ¶ñÒâÈí¼þ°ü°æ±¾¡£Shai-Hulud¹¥»÷»î¶¯ÓÚÈ¥Äê9Ô³öÏÖ²¢¾ÀúÁËÂŴεü´ú£¬ÆäÖÐһЩµü´úÒÑй¶ÁË×Ô¶¯ÌìÉúµÄGitHub´úÂë¿âÖÐÊýÊ®Íò¸ö¿ª·¢Õß»úÃÜÐÅÏ¢¡£×îÐÂÒ»²¨¹¥»÷²úÉúÔÚ×òÌ죬¹¥»÷ÕßÔÚnpmµÄTanStack¶¨Ãû¿Õ¼äÖа䲼Á˶à¸ö¶ñÒâÈí¼þ°ü£¬¶øºóÀûÓÃÇÔÈ¡µÄCI/CDƾ֤´«²¼µ½ÆäËûÏîÄ¿¡£Æ¾¾Ý°²È«³§É̵Ļ㱨£¬npmÉÏÓг¬¹ý160¸öÊÜϰȾµÄÈí¼þ°ü£¬PyPIÉÏÒ²·¢ÏÖÁË´óÁ¿¶ñÒâÈí¼þ°ü¡£¶ñÒâÈí¼þµÄÖ¸±êÔ̺¬ÇÔÈ¡GitHub Actions OIDCÁîÅÆ¡¢GitÍ´´¦¡¢npm°ä²¼ÁîÅÆ¡¢AWSƾ֤¡¢Kubernetes·þÎñÕÊ»§ÁîÅÆ¡¢HashiCorp VaultÁîÅÆ¡¢SSHÃÜÔ¿¡¢Claude CodeÅäÖü°.envÎļþµÈ¡£¸ÃÓÐÐ§ÔØºÉ»á¶ÁÈ¡GitHub Actions¹ý³ÌÄڴ棬´ÓÓëÔÆÌṩÉÌ¡¢¼ÓÃÜÇ®±Ò´ú±ÒºÍÐÂÎÅ´«µÝÀûÓ÷¨Ê½¹ØÁªµÄ100¶à¸öÎļþõè¾¶ÖÐÍøÂçÍ´´¦¡£
https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/


¾©¹«Íø°²±¸11010802024551ºÅ