TeamPCPÕë¶ÔÒÁÀÊϵͳ°²ÅŲÁ³ý¶ñÒâÈí¼þ

Ðû²¼Ê±¼ä 2026-03-25

1. TeamPCPÕë¶ÔÒÁÀÊϵͳ°²ÅŲÁ³ý¶ñÒâÈí¼þ


3ÔÂ23ÈÕ£¬£¬£¬£¬£¬Ó¦ÓÃÇå¾²¹«Ë¾Aikido¿ËÈÕ·¢Ã÷TeamPCPºÚ¿Í×éÖ¯Õë¶ÔKubernetes¼¯Èº·¢¶¯¹¥»÷£¬£¬£¬£¬£¬Ê¹ÓöñÒâ¾ç±¾ÔÚ¼ì²âµ½ÒÁÀÊÉèÖÃϵͳʱ²Á³ýËùÓлúе¡£¡£¡£¶ñÒâÈí¼þÉè¼ÆÓÃÓÚ´Ý»ÙÆ¥ÅäÒÁÀÊÊ±ÇøºÍÓïÑÔÇéÐεÄÈκλúе£¬£¬£¬£¬£¬ÎÞÂÛÊÇ·ñ±£´æKubernetes¡£¡£¡£ÈôÊÇÁ½¸öÌõ¼þ¶¼Öª×㣬£¬£¬£¬£¬¾ç±¾»áÔÚkube-systemÖа²ÅÅÃûΪHost-provisioner-iranµÄDaemonSet£¬£¬£¬£¬£¬Ê¹ÓÃÌØÈ¨ÈÝÆ÷²¢½«Ö÷»ú¸ùÎļþϵͳ¹ÒÔØµ½/mnt/host¡£¡£¡£Ã¿¸öpodÔËÐÐÃûΪkamikazeµÄAlpineÈÝÆ÷£¬£¬£¬£¬£¬É¾³ýÖ÷»úÎļþϵͳÉϵÄËùÓж¥¼¶Ä¿Â¼£¬£¬£¬£¬£¬È»ºóÇ¿ÖÆÖ÷»úÖØÆô¡£¡£¡£ÈôÊDZ£´æKubernetesµ«ÏµÍ³±»Ê¶±ðΪ·ÇÒÁÀÊϵͳ£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»á°²ÅÅÃûΪhost-provisioner-stdµÄDaemonSet£¬£¬£¬£¬£¬Ê¹ÓÃÌØÈ¨ÈÝÆ÷¹ÒÔØÖ÷»úÎļþϵͳ¡£¡£¡£Ã¿¸öpod½«PythonºóÃÅдÈëÖ÷»úÎļþϵͳ²¢×°ÖÃΪsystemdЧÀÍÒÔÔÚÿ¸ö½ÚµãÉϳ¤ÆÚ»¯¡£¡£¡£ÔÚûÓÐKubernetesµÄÒÁÀÊϵͳÉÏ£¬£¬£¬£¬£¬¶ñÒâÈí¼þɾ³ý»úеÉϵÄËùÓÐÎļþ£¬£¬£¬£¬£¬°üÀ¨ÏµÍ³Êý¾Ý¡£¡£¡£


https://www.bleepingcomputer.com/news/security/teampcp-deploys-iran-targeted-wiper-in-kubernetes-attacks/


2. Tycoon2FA ´¹ÂÚÆ½Ì¨±»µ·»ÙºóѸËÙ»Ö¸´ÔËÓª


3ÔÂ23ÈÕ£¬£¬£¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯ºÍÏàÖúͬ°éÓÚ3ÔÂ4ÈÕµ·»ÙµÄTycoon2FA´¹ÂÚ¼´Ð§ÀÍ£¨PhaaS£©Æ½Ì¨Òѻָ´ÖÁ´ËǰÊӲ쵽µÄ»î¶¯Ë®Æ½¡£¡£¡£Î¢ÈíÏòµ¼ÁË´Ë´ÎÊÖÒÕµ·»ÙÐж¯£¬£¬£¬£¬£¬½É»ñÁË330¸öÊôÓÚTycoon2FAÖ÷¸É»ù´¡ÉèÊ©µÄÓòÃû£¬£¬£¬£¬£¬°üÀ¨ÓÃÓÚ¹¥»÷µÄ¿ØÖÆÃæ°åºÍ´¹ÂÚÒ³Ãæ¡£¡£¡£Å·ÖÞÐ̾¯×éÖ¯ºÍÏàÖúͬ°éÓÚ3ÔÂ4ÈÕµ·»ÙµÄTycoon2FA´¹ÂÚ¼´Ð§ÀÍ£¨PhaaS£©Æ½Ì¨Òѻָ´ÖÁ´ËǰÊӲ쵽µÄ»î¶¯Ë®Æ½¡£¡£¡£Î¢ÈíÏòµ¼ÁË´Ë´ÎÊÖÒÕµ·»ÙÐж¯£¬£¬£¬£¬£¬½É»ñÁË330¸öÊôÓÚTycoon2FAÖ÷¸É»ù´¡ÉèÊ©µÄÓòÃû£¬£¬£¬£¬£¬°üÀ¨ÓÃÓÚ¹¥»÷µÄ¿ØÖÆÃæ°åºÍ´¹ÂÚÒ³Ãæ¡£¡£¡£Tycoon2FAÓÉSekoiaÔ¼Á½ÄêǰÊ״μͼ£¬£¬£¬£¬£¬×÷ΪרÃÅÕë¶ÔMicrosoft365ºÍGmailÕË»§µÄPhaaSƽ̨ÉÏÏߣ¬£¬£¬£¬£¬¾ßÓÐÖÐÐÄÈ˹¥»÷»úÖÆ£¬£¬£¬£¬£¬¿ÉÈÆ¹ýË«ÒòËØÉí·ÝÑéÖ¤£¨2FA£©±£»£»£»£»¤¡£¡£¡£Ò»¸öԺ󣬣¬£¬£¬£¬Trustwave±¨¸æTycoon2FAÔËÓªÕ߯ð¾¢Ë¢ÐÂÆ½Ì¨£¬£¬£¬£¬£¬Ìí¼Óеĸ߼¶¹¦Ð§£¬£¬£¬£¬£¬ÎüÒý¸ü¶àÍøÂç×ï·¸¹ºÖûá¼ûȨÏÞ¡£¡£¡£Tycoon2FAÊÇ´¹ÂÚÁìÓòµÄÖ÷Òª¼ÓÈëÕߣ¬£¬£¬£¬£¬Î¢Èí±¨¸æÆäÿÔÂÌìÉú3000Íò·â´¹ÂÚÓʼþ£¬£¬£¬£¬£¬Õ¼¸Ã¿Æ¼¼¹«Ë¾×èµ²µÄËùÓÐÓʼþµÄ62%¡£¡£¡£


https://www.bleepingcomputer.com/news/security/tycoon2fa-phishing-platform-returns-after-recent-police-disruption/


3. Âí×Ô´ïÔâÍøÂç¹¥»÷692ÌõÔ±¹¤ºÍÏàÖúͬ°éÊý¾Ýй¶


3ÔÂ23ÈÕ£¬£¬£¬£¬£¬ÈÕ±¾Æû³µÖÆÔìÉÌÂí×Դ﹫˾¿ËÈÕÐû²¼£¬£¬£¬£¬£¬ÔÚÈ¥Äê12Ô·¢Ã÷µÄÒ»ÆðÇå¾²ÊÂÎñÖУ¬£¬£¬£¬£¬ÆäÔ±¹¤ºÍÓªÒµÏàÖúͬ°éµÄÐÅÏ¢±»Ì»Â¶¡£¡£¡£Âí×Ô´ïÊÇÈÕ±¾×î´óµÄÆû³µÖÆÔìÉÌÖ®Ò»£¬£¬£¬£¬£¬Äê²úÁ¿120ÍòÁ¾Æû³µ£¬£¬£¬£¬£¬ÊÕÈë½ü240ÒÚÃÀÔª¡£¡£¡£¹«Ë¾ÌåÏÖ¹¥»÷ÕßʹÓÃÁËÓëÌ©¹ú²É¹ºÁã¼þ¿ÍÕ»ÖÎÀíϵͳÏà¹ØµÄÎó²î¡£¡£¡£¸Ãϵͳ²»°üÀ¨Èκοͻ§Êý¾Ý¡£¡£¡£Ð¹Â¶½öÏÞÓÚ692Ìõ¼Í¼¡£¡£¡£Âí×Ô´ïÔÚͨ¸æÖÐÌåÏÖ£º"Âí×Դ﹫˾ÒÑʶ±ðµ½ÓëÌ©¹ú²É¹ºÁã¼þ¿ÍÕ»ÔËÓªÏà¹ØµÄÖÎÀíϵͳ±£´æÎ´¾­ÊÚȨÍⲿ»á¼ûµÄºÛ¼£¡£¡£¡£·¢Ã÷ºó£¬£¬£¬£¬£¬¹«Ë¾Á¬Ã¦ÏòСÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»¤Î¯Ô±»á£¨ÈÕ±¾ÄÚ¸ó¸®Íⲿ»ú¹¹£©±¨¸æ£¬£¬£¬£¬£¬²¢ÓëÍⲿרҵ×éÖ¯ÏàÖúʵÑéÊʵ±Çå¾²²½·¥²¢¾ÙÐÐÊӲ졣¡£¡£"ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬¿ÉÄÜ̻¶µÄÐÅÏ¢°üÀ¨Óû§ID¡¢È«Ãû¡¢µç×ÓÓʼþµØµã¡¢¹«Ë¾Ãû³ÆºÍÓªÒµÏàÖúͬ°éID¡£¡£¡£Ö»¹ÜÂí×Ô´ïÌåÏÖδ¼ì²âµ½¸ÃÐÅÏ¢µÄÀÄÓ㬣¬£¬£¬£¬µ«¹«Ë¾½¨ÒéÊÜÓ°ÏìСÎÒ˽¼Ò¼á³ÖСÐÄ£¬£¬£¬£¬£¬ÓÉÓÚÕë¶ÔËûÃǵĴ¹ÂÚ¹¥»÷ºÍթƭΣº¦ÏÔÖø¡£¡£¡£³ý֪ͨÕþ¸®Í⣬£¬£¬£¬£¬Âí×Դﻹ¶ÔÆäITϵͳʵÑéÁËÌØÊâÇå¾²²½·¥£¬£¬£¬£¬£¬°üÀ¨ïÔÌ­»¥ÁªÍøÌ»Â¶¡¢Ó¦ÓÃÇå¾²²¹¶¡¡¢ÔöÌí¶Ô¿ÉÒɻµÄ¼à¿ØÒÔ¼°ÒýÈë¸üÑÏ¿áµÄ»á¼ûÕ½ÂÔ¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯¹ûÕæÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/


4. ³¯ÏÊTeam 8ʹÓÃVSCodeÈö²¥StoatWaffle¶ñÒâÈí¼þ


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬NTT Security¿ËÈÕ·¢Ã÷£¬£¬£¬£¬£¬Ó볯ÏÊÏà¹ØµÄÍþвÐÐΪÕßTeam 8ÔÚ"Contagious Interview"»î¶¯ÖÐͨ¹ý¶ñÒâMicrosoft Visual Studio CodeÏîÄ¿Èö²¥StoatWaffle¶ñÒâÈí¼þ¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬£¬Team 8Ö÷ҪʹÓÃOtterCookie¡£¡£¡£´Ó2025Äê12ÔÂ×óÓÒ×îÏÈ£¬£¬£¬£¬£¬Team 8×îÏÈʹÓÃжñÒâÈí¼þ£¬£¬£¬£¬£¬ÎÒÃǽ«ÆäÃüÃûΪStoatWaffle¡£¡£¡£Team 8ʹÓÃÓëÇø¿éÁ´Ïà¹ØµÄÏîÄ¿×÷ΪÓÕ¶ü¡£¡£¡£¸Ã¶ñÒâ¿ÍÕ»°üÀ¨.vscodeĿ¼£¬£¬£¬£¬£¬ÆäÖаüÀ¨tasks.jsonÎļþ¡£¡£¡£ÈôÊÇÓû§Ê¹ÓÃVSCode·­¿ª²¢ÐÅÈδ˶ñÒâ¿ÍÕ»£¬£¬£¬£¬£¬Ëü»á¶ÁÈ¡´Ëtasks.jsonÎļþ¡£¡£¡£"¸ÃʹÃü´ÓVercelÏÂÔØÓÐÓÃÔØºÉ²¢Í¨¹ýcmd.exeÔËÐУ¬£¬£¬£¬£¬´Ó¼òÆÓÏÂÔØÆ÷×îÏÈ¡£¡£¡£È»ºó×°ÖÃNode.js²¢»ñÈ¡ÌØÊâÎļþ£¬£¬£¬£¬£¬ÊµÏÖ¿ç²Ù×÷ϵͳµÄ½øÒ»²½¶ñÒâÈí¼þÖ´ÐС£¡£¡£StoatWaffle¶ñÒâÈí¼þʹÓöà½×¶ÎѬȾÁ´¡£¡£¡£´ÓNode.js¼ÓÔØÆ÷×îÏÈ£¬£¬£¬£¬£¬Öظ´ÅþÁ¬ÏÂÁî¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷²¢Ö´ÐÐÎüÊÕµ½µÄÈκδúÂë¡£¡£¡£È»ºó°²Åŵڶþ¸öÏÂÔØÆ÷£¬£¬£¬£¬£¬¼ÌÐø´ËͨѶ²¢¿ìËÙת´ïÌØÊâ¶ñÒâÈí¼þÄ£¿£¿£¿£¿£¿é¡£¡£¡£


https://securityaffairs.com/189880/security/north-korea-linked-threat-actors-abuse-vs-code-auto-run-to-spread-stoatwaffle-malware.html


5. QualDerm PartnersÊý¾Ýй¶ӰÏì310Íò»¼ÕßÐÅÏ¢


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬Ò½ÁƱ£½¡ÖÎÀíЧÀÍÌṩÉÌQualDerm Partners¿ËÈÕ֪ͨÁè¼Ý310ÍòÈË£¬£¬£¬£¬£¬ÆäСÎÒ˽¼Ò¡¢Ò½ÁƺͿµ½¡°ü¹ÜÐÅÏ¢ÔÚ2025Äê12ÔµÄÊý¾Ýй¶Öб»ÇÔÈ¡¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬ÊÂÎñÓÚ12ÔÂ24ÈÕ·¢Ã÷£¬£¬£¬£¬£¬Éæ¼°¹¥»÷Õßδ¾­ÊÚȨ»á¼ûÆäÍøÂçÁ½Ìì¡£¡£¡£ÔÚ´Ëʱ´ú£¬£¬£¬£¬£¬¹¥»÷Õß´Ó±»¹¥ÏݵÄ"ÓÐÏÞÊýĿϵͳ"ÖÐÍâйÁËijЩÐÅÏ¢¡£¡£¡£±»µÁÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþµØµã¡¢²¡ÀúºÅ¡¢Ò½ÉúÐÕÃû¡¢ÖÎÁƺÍÕï¶ÏÐÅÏ¢¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢éæÃüÈÕÆÚ£¬£¬£¬£¬£¬ÒÔ¼°ÔÚijЩÇéÐÎϵÄÕþ¸®Ç©·¢Éí·ÝÖ¤¼þÐÅÏ¢¡£¡£¡£QualDermÌåÏÖ¶ÔÊý¾Ýй¶µÄÊÓ²ìÈÔÔÚ¼ÌÐø£¬£¬£¬£¬£¬ÒѾöÒé֪ͨÆù½ñÒÑʶ±ðµÄ»öÕß¡£¡£¡£×÷Ϊ¶Ô¹¥»÷µÄÏìÓ¦£¬£¬£¬£¬£¬¹«Ë¾Á¬Ã¦¼¤»îÏìÓ¦ÍýÏ룬£¬£¬£¬£¬½ÓÄɲ½·¥¿ØÖÆÎ´¾­ÊÚȨµÄ»î¶¯£¬£¬£¬£¬£¬ÆÀ¹ÀϵͳÇå¾²ÐÔ£¬£¬£¬£¬£¬²¢Í¨ÖªÖ´·¨²¿·ÖºÍî¿Ïµ»ú¹¹¡£¡£¡£QualDermÏòÃÀ¹úÎÀÉúÓ빫ÖÚЧÀͲ¿±¨¸æ£¬£¬£¬£¬£¬3,117,874ÈËÊܹ¥»÷Ó°Ïì¡£¡£¡£¸ÃÊÂÎñÓÚÉÏÔ±¨¸æ£¬£¬£¬£¬£¬µ«±¾Öܲű»Ìí¼Óµ½HHSµÄй¶ÃÅ»§¡£¡£¡£¹«Ë¾ÕýÏòÊÜÓ°ÏìСÎÒ˽¼ÒÌṩ12¸öÔµÄÃâ·ÑÉí·Ý͵ÇÔºÍÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£


https://www.securityweek.com/3-1-million-impacted-by-qualderm-data-breach/


6. Infinite CampusÔâShinyHunters¹¥»÷Íþвй¶Êý¾Ý


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬ÆÕ±éʹÓõÄK-12ѧÉúÐÅϢϵͳInfinite Campus¿ËÈÕÖÒÑÔ¿Í»§£¬£¬£¬£¬£¬ÔÚÍþвÐÐΪÕßÀÕË÷ÍýÏëºó±¬·¢Êý¾Ýй¶¡£¡£¡£ÔÚ·¢Ë͸ø¿Í»§µÄ֪ͨÖУ¬£¬£¬£¬£¬Infinite CampusÌåÏÖºÚ¿Í»á¼ûÁËÔ±¹¤µÄSalesforceÕË»§£¬£¬£¬£¬£¬Ì»Â¶Á˴󲿷ֿɹûÕæ»ñÈ¡µÄÐÅÏ¢¡£¡£¡£¸Ã¹«Ë¾Î´Ðû²¼¹Ù·½ÉùÃ÷£¬£¬£¬£¬£¬µ«¿Í»§ÔÚÖÖÖÖ¹ûÕæÆ½Ì¨±¨¸æÁËÊÂÎñ¡£¡£¡£Í¨ÖªÐû²¼Ç°²»¾Ã£¬£¬£¬£¬£¬Êý¾ÝÀÕË÷×éÖ¯ShinyHuntersÉù³Æ·¢¶¯Á˹¥»÷£¬£¬£¬£¬£¬²¢ÔÚÆä°µÍøÍøÕ¾Ðû²¼"×îºóÖÒÑÔ"£¬£¬£¬£¬£¬Íþвй¶¾Ý³Æ´ÓInfinite CampusÇÔÈ¡µÄËùÓÐÊý¾Ý¡£¡£¡£ºÚ¿Í¸øÓ蹫˾×èÖ¹3ÔÂ25ÈÕµÄʱ¼äÁªÏµ²¢Ð­ÉÌÊê½ðÒÔ±ÜÃâÊý¾Ýй¶£¬£¬£¬£¬£¬µ«Infinite CampusÌåÏÖ²»»áÓë¹¥»÷Õß½Ó´¥¡£¡£¡£Infinite CampusÌåÏÖ£¬£¬£¬£¬£¬Æ¾Ö¤ÊӲ죬£¬£¬£¬£¬¿Í»§Êý¾Ý¿âδ±»»á¼û¡£¡£¡£Ì»Â¶Êý¾Ý°üÀ¨Ñ§Ð£Ô±¹¤µÄÐÕÃûºÍÁªÏµÏêÇ飬£¬£¬£¬£¬ÒÔ¼°Í¨³£¿£¿£¿£¿£¿É¹ûÕæ»ñÈ¡µÄÐÅÏ¢¡£¡£¡£×÷ΪÏìÓ¦£¬£¬£¬£¬£¬¹«Ë¾ÒѶÔÎÞIPµØµãÏÞÖÆµÄÓû§½ûÓÃÄ³Ð©ÃæÏò¿Í»§µÄЧÀÍ£¬£¬£¬£¬£¬ÒÔ×î´óÏ޶ȽµµÍÃô¸ÐÊý¾ÝDZÔÚ̻¶Σº¦¡£¡£¡£Í¬Ê±ÕýÔÚɨÃèËùÓпÉÄÜÊÜËðµÄSalesforceÊý¾Ý£¬£¬£¬£¬£¬²¢ÁªÏµ¿ÉÄÜÊÜÓ°ÏìµÄÑ§ÇøÌṩָµ¼¡£¡£¡£


https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/