BlueSkyÓû§¼¤Ôö°éÉúÕ©Æ­ÌôÕ½

Ðû²¼Ê±¼ä 2024-11-25

1. BlueSkyÓû§¼¤Ôö°éÉúÕ©Æ­ÌôÕ½


11ÔÂ21ÈÕ £¬Ëæ×ÅBlueSkyÕâһȥÖÐÐÄ»¯Î¢²©·þÎñµÄÓû§ÊýÄ¿¼¤Ôö £¬ÍþвÐÐΪÕßÒ²·×·×Ó¿Èë¸Ãƽ̨ ¡£½üÆÚ £¬BleepingComputer·¢Ã÷BlueSkyÉÏ·ºÆðÁ˼ÓÃÜÇ®±ÒȦÌ× £¬°üÀ¨Ê¹ÓÃMetaÆ·ÅÆ¾ÙÐÐÎóµ¼µÄÍÆ¹ãÌûºÍÐéα¿ÕͶ´ÙÏúµÈ ¡£ÕâЩȦÌײ»µ«Îóµ¼¹ÛÖÚ½«¹ã¸æ²úÆ·Óë¿Æ¼¼¾ÞÍ·Meta¼°Æä¿´·¨ÁªÏµÆðÀ´ £¬»¹Í¨¹ýÈ«ÐÄÉè¼ÆµÄÍøÕ¾ºÍÓòÃûÀ´Ä£ÄâMetaµÄÆ·ÅÆºÍ×ÖÌå £¬ÒÔÌá¸ßڲƭЧ¹û ¡£Í¬Ê± £¬BlueSkyÇå¾²ÍŶÓҲ֤ʵ £¬Ëæ×ÅÓû§ÊýÄ¿µÄÔöÌí £¬Æ½Ì¨ÊÕµ½ÁË´ó×Ú¹ØÓÚÀ¬»øÓʼþ¡¢Õ©Æ­ºÍ¶ñÒâ¹¥»÷»î¶¯µÄ±¨¸æ ¡£Ö»¹ÜBlueSkyµÄÈ¥ÖÐÐÄ»¯¼Ü¹¹ÎªÓû§ÌṩÁ˸ü´óµÄ×ÔÓɺͿØÖÆÈ¨ £¬µ«Ò²´øÀ´ÁËеÄÌôÕ½ ¡£ÓÉÓÚÈκÎÈ˶¼¿ÉÒÔÆô¶¯BlueSkyʵÀý £¬Õ©Æ­Õß¿ÉÒÔʹÓÃÕâÒ»ÌØµãÀ´ÉèÖÃ×Ô¼ºµÄʵÀý²¢Íƹã¿ÉÒɵÄÉúÒâÍýÏë ¡£±ðµÄ £¬ËÑË÷ÒýÇæÒ²¿ÉÄÜץȡ²¢Ë÷ÒýÀ´×ÔµÚÈý·½BlueSkyʵÀýµÄÌû×Ó £¬´Ó¶ø×ÊÖúÕ©Æ­ÕßÌá¸ßËÑË÷ÅÅÃûºÍSEOÆÈº¦ÓÎÏ· ¡£Òò´Ë £¬BlueSkyÐèÒª½â¾öÕâЩÌôÕ½ £¬ÒÔ±£»¤Óû§ÃâÊÜڲƭºÍ¶ñÒâ¹¥»÷µÄΣº¦ ¡£


https://www.bleepingcomputer.com/news/security/now-bluesky-hit-with-crypto-scams-as-it-crosses-20-million-users/


2. °²µÂ³¡¤Ì©ÌØÔÚÏß´óѧÔâºÚ¿ÍÈëÇÖ £¬80ÍòÓû§Êý¾Ýй¶


11ÔÂ21ÈÕ £¬¼«ÓÒÒíÓ°ÏìÕß°²µÂ³¡¤Ì©ÌØ¿ª°ìµÄÔÚÏß´óѧ¡°ÕæÊµÌìÏ¡±£¨Ô­Ãû¡°Hustler's University¡±£©ÔâÓöºÚ¿ÍÈëÇÖ £¬µ¼ÖÂÔ¼325,000ÃûÓû§µÄµç×ÓÓʼþµØÖ·±»Ð¹Â¶ £¬Í¬Ê±Ô¼794,000¸öÓû§Ãû¼°Æä221¸ö¹«¹²ºÍ395¸ö˽ÈË̸Ìì·þÎñÆ÷µÄÄÚÈÝÒ²±»ÆØ¹â ¡£¸Ãƽ̨ÌṩÿÔÂÔ¼50ÃÀÔªµÄ¡°¸ß¼¶ÅàѵºÍÖ¸µ¼¡± £¬Ö÷񻃾¼°¿µ½¡¡¢½¡Éí¡¢½ðÈÚͶ×ʺ͵ç×ÓÉÌÎñµÈÖ÷Ìâ ¡£ºÚ¿ÍÔÚÈëÇÖºóÓÚÌ©ÌØµÄÖ±²¥½ÚÄ¿ÖÐÉÏ´«ÁË´ó×ÚÐÄÇé·ûºÅÒÔÊ¾Ñ°ÐÆ £¬²¢Éù³ÆÄܹ»Ê¹ÓÃÎó²î¾ÙÐжàÏîÆÆËðÐÔ²Ù×÷ ¡£´Ë´ÎÈëÇÖµÄÄîÍ·±»ÒÔΪÊÇ¡°ºÚ¿ÍÐж¯Ö÷Ò塱 £¬ÇÒ¸ÃÆ½Ì¨µÄÇå¾²ÐÔ±»Ö¸Îª¡°¼«¶Ë²»Çå¾²¡± ¡£Ì¸Ìì¼Í¼º­¸ÇÁË´ÓÀøÖ¾Óï¼µ½¶Ô¡°LGBTQÒé³Ì¡±µÄËß¿àµÈÖÖÖÖÄÚÈÝ ¡£Ì©ÌØÒòÕÅÑïÄÐ×ÓÆø¸ÅºÍ±áµÍÅ®ÐÔ¿´·¨¶øÖøÃû £¬ÏÖÔÚÃæÁÙÀ´×ÔÂÞÂíÄáÑǺÍÓ¢¹úµÄÎåÏîÖ´·¨ÊÓ²ì ¡£ºÚ¿ÍÒѽ«Ð¹Â¶µÄµç×ÓÓʼþµØÖ·ÌṩӦÓû§Æ¾Ö¤Ð¹Â¶¾¯±¨·þÎñHaveIBeenPwned £¬²¢½«Ì¸ÌìÊý¾Ý½»¸øÁËÐÂÎÅÕûÌåDDoSecretsÍйÜ ¡£


https://www.dailydot.com/debug/andrew-tate-the-real-world-hack/


3. QNAP¹Ì¼þ¸üÐÂÒý·¢ÅþÁ¬ÎÊÌâ £¬Òѳ·»Ø²¢½¨Òé½µ¼¶


11ÔÂ22ÈÕ £¬QNAP½üÆÚÐû²¼µÄ¹Ì¼þ¸üÐÂQTS 5.2.2.2950 build 20241114Ö¼ÔÚÐÞ²¹¶à¸öÇå¾²Îó²î²¢ÐÞ¸´ÒÑÖªÎÊÌâ £¬µ«´ó×Ú¿Í»§±¨¸æ³Æ¸Ã¸üÐÂÆÆËðÁË×°±¸ÅþÁ¬²¢µ¼ÖÂÎÞ·¨»á¼û ¡£¾ÝÓû§·´Ïì £¬¸üÐ弗ἮðÎÞ·¨ÅþÁ¬µ½×°±¸¡¢µÇ¼ƾ֤¹ýʧ¡¢¼ì²âµ½Î´¾­ÊÚȨµÄ¸ü¸ÄÒÔ¼°ÄÚÖÃÓ¦ÓóÌÐòÒòδװÖÃPython2¶øÎÞ·¨Ê¹ÓõÈÎÊÌâ ¡£QNAPÖ§³ÖÍŶÓÒÑÈ·ÈϸøüÐÂÒÑ´ÓÏÂÔØÒ³ÃæÉ¾³ý £¬²¢½¨Ò齫¹Ì¼þ½µ¼¶ÖÁQTS 5.2.1.2930 build 2024102ÒÔ½â¾öÅþÁ¬ºÍÓ¦ÓóÌÐòË𻵵ÄÎÊÌâ ¡£Ö»¹ÜQNAPÉÐδ¾Í´ËÊÂÐû²¼¹ûÕæÉùÃ÷ £¬µ«ÆäÖ§³ÖÍŶÓÒѻظ´²¿·ÖÊÜÓ°Ïì¿Í»§ ¡£BleepingComputerÌá³öµÄ̸ÂÛÇëÇóÉÐδ»ñµÃQNAPµÄ»Ø¸´ ¡£


https://www.bleepingcomputer.com/news/technology/qnap-pulls-buggy-qts-firmware-causing-widespread-nas-issues/


4. Microsoft Power PagesÉèÖÃʧÎóÖÂNHSµÈÊý¾Ý´ó¹æÄ£Ð¹Â¶


11ÔÂ23ÈÕ £¬¶¼°ØÁÖÍøÂçÇå¾²Ñо¿Ô±ÑÇÂס¤¿ÆË¹ÌØÂå·¢Ã÷ £¬ÓÉÓÚMicrosoft Power PagesÈí¼þƽ̨ÉèÖò»µ± £¬µ¼ÖÂ110Íò·ÝNHSÔ±¹¤¼Í¼±»Ð¹Â¶ £¬°üÀ¨µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍ¼ÒͥסַµÈÃô¸ÐÐÅÏ¢ ¡£ÕâÒ»ÎÊÌâ²»µ«Ó°ÏìNHS £¬»¹²¨¼°È«Çò¶à¸ö×éÖ¯ºÍÕþ¸®ÊµÌå ¡£¿ÆË¹ÌØÂåÖ¸³ö £¬Ö»¹Ü΢ÈíÔÚPower Pages¹ÜÀíÃæ°åÖÐÉèÖÃÁËÖÒÑÔºá·ùºÍ±ê¼Ç £¬µ«È±·¦¶ÔЧ¹ûµÄ³äÇå³þÈ· ¡£ËûÒÔΪ £¬NHSÊý¾Ýй¶ÓëHSEÊý¾ÝÎÊÌâÏàËÆ £¬¶¼ÊǿɹûÕæ»á¼ûµÄÃÅ»§ £¬ÓɳаüÉÌÉèÖúͰ²ÅÅ £¬ÇÒÇå¾²ÐÔ±»ºöÊÓ ¡£¿ÆË¹ÌØÂåºôÓõÏÂÒ»½ìÕþ¸®½«ÍøÂçÇå¾²×÷ΪÓÅÏÈÊÂÏî £¬²¢Ñо¿Öƶ©¹ú¼Ò¿ò¼Ü £¬ÒÔÌá¸ß¹ú¼ÒÍøÂç·ÀÓùÄÜÁ¦ ¡£ËûÇ¿µ÷ £¬Ô¤·À±ÈÏû³ýË𺦸üÖ÷Òª £¬²¢½¨Ò鿪չÌìÏÂÐÔÐû´«»î¶¯ £¬Ìá¸ß¹«ÖÚ¶ÔÍøÂçÇå¾²»ù´¡ÖªÊ¶µÄÏàʶ £¬Èç¶àÒòËØÉí·ÝÑéÖ¤ºÍ×èֹͨ¹ýµç»°Ìá¹©ÒøÐÐÐÅÏ¢µÈ ¡£¿ÆË¹ÌØÂåÒÔΪ £¬°®¶ûÀ¼ÔÚÍøÂçÇå¾²·½ÃæµÄ×ʽðÑÏÖØÈ±·¦ £¬Ó¦¼Ó´óµÐÊÖÒÕÈ˲ŵÄͶ×Ê £¬ÒÔÌáÉý¹ú¼ÒÍøÂçÇ徲ˮƽ ¡£


https://www.breakingnews.ie/ireland/irish-researcher-finds-1-1-million-nhs-employee-records-were-leaked-1698047.html


5. Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿ÀÎÓüÊý¾Ýй¶ £¬Ë¾·¨²¿½ôÆÈÓ¦¶Ô


11ÔÂ23ÈÕ £¬Ó¢¹ú˾·¨²¿ÒÑÈ·Èϱ¬·¢ÁËÒ»ÆðÉæ¼°Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿ÀÎÓüµÄÊý¾Ýй¶ÊÂÎñ £¬¾Ý¡¶Ì©ÎîÊ¿±¨¡·±¨µÀ £¬ÒÑÍùÁ½ÖÜÄÚ £¬ÉñÃØÀÎÓü½á¹¹Í¼±»Ð¹Â¶ÖÁ°µÍø ¡£ÕâЩй¶µÄÀ¶Í¼°üÀ¨ÉãÏñÍ·ºÍ´«¸ÐÆ÷µÈÒªº¦Çå¾²¹¦Ð§µÄλÖà £¬¿ÉÄܻᱻÓÐ×éÖ¯·¸·¨¼¯ÍÅʹÓà £¬ÒÔ½«¶¾Æ·»òÎäÆ÷×ß˽½øÀÎÓü £¬ÉõÖÁ²ß»®Ô½Óü ¡£Ë¾·¨²¿ÒÑÁ¬Ã¦½ÓÄÉÐж¯È·±£ÀÎÓüÇå¾² £¬¶øÀÎÓüÕþ¸®ÏÓÒÉ´Ë´ÎйÃÜ¿ÉÄÜÓëÓÐ×éÖ¯·¸·¨¼¯ÍÅÊÔͼʹÓÃÎÞÈË»ú×ß˽¶¾Æ·ÓйØ ¡£ÏÖÔÚÉв»ÇåÎúÄÄЩÀÎÓüÍýÏëÊܵ½ÁËÓ°Ïì £¬µ«ÄÚ¸ó°ì¹«ÊÒºÍÀÎÓü¹ÜÀí¾ÖÕýÔÚÊÓ²ìÎ¥¹æÐÐΪµÄÔ´Í· £¬²¢ÆÀ¹ÀË­¿ÉÄÜ´ÓÕâЩÐÅÏ¢ÖÐÊÜÒæ ¡£Ó¢¹ú¹ú¼Ò·¸·¨¾ÖÌåÏÖ £¬¸Ã¾ÖÕýÔÚÒÔÕÕÁÏÉí·ÝÌṩ֧³Ö ¡£Ë¾·¨²¿½²»°ÈËÇ¿µ÷ £¬ËûÃDz»»á¶Ô´ËÀàÇå¾²ÎÊÌâµÄÏêϸϸ½Ú½ÒÏþ̸ÂÛ £¬µ«ÒÑÁ¬Ã¦½ÓÄÉÐж¯Ó¦¶ÔDZÔÚй¶ÊÂÎñ £¬È·±£ÀÎÓüÇå¾² ¡£


https://www.bbc.co.uk/news/articles/ce8y5jm4lyzo


6. ´ó¸£¿Ë˹¹«Á¢Ñ§Ð£ÔâÍøÂç´¹ÂÚÕ©Æ­ £¬220ÍòÃÀÔª×ʽðÊÜÆ­×ß


11ÔÂ21ÈÕ £¬´ó¸£¿Ë˹¹«Á¢Ñ§Ð£½ñÄêÔçЩʱ¼äÔâÓöÁËÍøÂç´¹ÂÚÕ©Æ­ £¬ÊÜÆ­È¡ÁË220ÍòÃÀÔª ¡£ÕâÆðڲƭ°¸ÊÇÍøÂç´¹ÂÚ»òÉç»á¹¤³ÌȦÌ×µÄЧ¹û £¬¹¥»÷ÕßÓÕÆ­Ô±¹¤Ð¹Â¶Ãô¸ÐÐÅÏ¢»òÖ´ÐÐijЩ²Ù×÷ £¬Èç»ã¿î»òÌṩÐÅÏ¢ ¡£Ñ§ÇøºÍ´ó¸£¿Ë˹¾¯Ô±¾ÖûÓÐÌṩÓйط¸·¨»òÊÓ²ìµÄÏêÇé £¬µ«ÌØÇÚ¾ÖÕýÔÚЭÖúÊÓ²ì ¡£Ñ§ÇøIT×ܼàÌåÏÖ £¬Õâ´ÎÕ©Æ­ÊÇËûÂÄÀú¹ýµÄ×îÖØ´óµÄÍøÂç·¸·¨ ¡£±»µÁ×ʽðµÄÊý¶îÅú×¢ÇÔÔôÕÆÎÕÁËÑ§ÇøµÄÄÚ²¿ÐÅÏ¢ £¬Ê¹ÓÃÕâЩÐÅϢʹÉç»á¹¤³ÌÍýÏë¸ü¾ß˵·þÁ¦ ¡£Ö»¹ÜÖ´·¨ÒªÐÞ񵂿Ïò¹«ÖÚ·ÖÏíÆä´ó²¿·ÖÓªÒµ¼Í¼ £¬µ«Ñ§Çø¹ÙÔ±ºÍÖ´·¨²¿·Ö¶¼Ã»ÓÐ͸¶Õâ200ÍòÃÀÔªÊÇÒ»´ÎÐÔתÕËÕվɷֶà´ÎתÕË ¡£ÔÚڲƭÊÂÎñ±¬·¢Ç°µÄËÄÌìÀï £¬Ñ§ÇøÉÌÎñ°ì¹«ÊÒÖ§¸¶ÁË1000¶à±Ê¿î×Ó £¬ÆäÖаüÀ¨Ïò³Ð°üÉÌÖ§¸¶µÄÁ½±Ê´ó¶î¿î×Ó ¡£Ñ§Çø¹ÙÔ±ÌåÏÖ £¬ÕâЩ¿î×Ó½«ÓÃÓÚÕýÔÚ¾ÙÐеÄÐÞ½¨ÏîĿ֮һ ¡£


https://www.govtech.com/education/k-12/grand-forks-public-schools-loses-2-2m-to-phishing-scam