BlueSkyÓû§¼¤Ôö°éÉúÚ¿Æ­ÌôÕ½

°ä²¼¹¦·ò 2024-11-25

1. BlueSkyÓû§¼¤Ôö°éÉúÚ¿Æ­ÌôÕ½


11ÔÂ21ÈÕ £¬Ëæ×ÅBlueSkyÕâһȥÖÐÐÄ»¯Î¢²©·þÎñµÄÓû§ÊýÁ¿¼¤Ôö £¬ÍþвÐÐΪÕßÒ²·×·×Ó¿Èë¸Ãƽ̨ ¡£½üÆÚ £¬BleepingComputer·¢ÏÖBlueSkyÉϳöÏÖÁ˼ÓÃÜÇ®±ÒȦÌ× £¬Ô̺¬ÀûÓÃMetaÆ·ÅÆ½øÐÐÎóµ¼µÄÍÆ¹ãÌûºÍÐéα¿ÕͶ´ÙÏúµÈ ¡£ÕâЩȦÌײ»½öÎ󵼹۶ཫ¸æ°×²úÆ·Óë¿Æ¼¼¾ÞÍ·Meta¼°Æä¸ÅÏëÁªÏµÆðÀ´ £¬»¹Í¨¹ý¾«ÐÄÉè¼ÆµÄÍøÕ¾ºÍÓòÃûÀ´·ÂÕÕMetaµÄÆ·ÅÆºÍ×ÖÌå £¬ÒÔÌá¸ßڲƭ³ÉЧ ¡£Í¬Ê± £¬BlueSky°²È«ÍŶÓҲ֤ʵ £¬Ëæ×ÅÓû§ÊýÁ¿µÄÔö³¤ £¬Æ½Ì¨ÊÕµ½ÁË´óÁ¿¹ØÓÚÀ¬»øÓʼþ¡¢Ú¿Æ­ºÍ¶ñÒâ¹¥»÷»î¶¯µÄ»ã±¨ ¡£Ö»¹ÜBlueSkyµÄÈ¥ÖÐÐÄ»¯¼Ü¹¹ÎªÓû§ÌṩÁ˸ü´óµÄ×ÔÓɺͽÚÔìȨ £¬µ«Ò²´øÀ´ÁËеÄÌôÕ½ ¡£ÓÉÓÚÈκÎÈ˶¼Äܹ»Æô¶¯BlueSkyÊ·ý £¬Ú¿Æ­ÕßÄܹ»ÀûÓÃÕâÒ»ÌØµãÀ´ÉèÖÃ×Ô¼ºµÄÊ·ý²¢Íƹã¿ÉÒɵÄÂòÂô´òËã ¡£´Ë±í £¬ËÑË÷ÒýÇæÒ²¿ÉÄÜץȡ²¢Ë÷ÒýÀ´×ÔµÚÈý·½BlueSkyÊ·ýµÄÌû×Ó £¬´Ó¶øÔ®Ê¶à¿Æ­ÕßÌá¸ßËÑË÷ÅÅÃûºÍSEO¶¾º¦ÓÎÏ· ¡£Òò¶ø £¬BlueSky±ØÒª½â¾öÕâЩÌôÕ½ £¬ÒÔ± £»¤Óû§ÃâÊÜڲƭºÍ¶ñÒâ¹¥»÷µÄ·çÏÕ ¡£


https://www.bleepingcomputer.com/news/security/now-bluesky-hit-with-crypto-scams-as-it-crosses-20-million-users/


2. °²µÂ³¡¤Ì©ÌØÔÚÏß´óѧÔâºÚ¿ÍÈëÇÖ £¬80ÍòÓû§Êý¾Ýй¶


11ÔÂ21ÈÕ £¬¼«ÓÒÒíÓ°ÏìÕß°²µÂ³¡¤Ì©ÌØ´´°ìµÄÔÚÏß´óѧ¡°ÕæÊµÊÀ½ç¡±£¨Ô­Ãû¡°Hustler's University¡±£©Ôâ·êºÚ¿ÍÈëÇÖ £¬µ¼ÖÂÔ¼325,000ÃûÓû§µÄµç×ÓÓʼþµØÖ·±»Ð¹Â¶ £¬Í¬Ê±Ô¼794,000¸öÓû§Ãû¼°Æä221¸ö¹«¹²ºÍ395¸ö¸öÈË̸Ìì·þÎñÆ÷µÄÄÚÈÝÒ²±»ÆØ¹â ¡£¸Ãƽ̨ÌṩÿÔÂÔ¼50ÃÀÔªµÄ¡°¸ß¼¶ÅàѵºÍÁìµ¼¡± £¬ÖØÒªÉæ¼°½¡È«¡¢½¡Éí¡¢½ðÈÚͶ×ʺ͵ç×ÓÉÌÎñµÈÖ÷Ìâ ¡£ºÚ¿ÍÔÚÈëÇÖºóÓÚÌ©ÌØµÄÖ±²¥½ÚÄ¿ÖÐÉÏ´«ÁË´óÁ¿±íÇé·ûºÅÒÔʾ°áŪ £¬²¢Ðû³Æ¿ÉÄÜÀûÓ÷ì϶½øÐжàÏî·ÛËéÐÔ²Ù×÷ ¡£Õâ´ÎÈëÇֵ͝»ú±»ÒÔΪÊÇ¡°ºÚ¿ÍÐж¯Ö÷Ò塱 £¬ÇÒ¸ÃÆ½Ì¨µÄ°²È«ÐÔ±»Ö¸Îª¡°¼«¶Ë²»°²È«¡± ¡£Ì¸Ìì¼Í¼º­¸ÇÁË´ÓÀøÖ¾Óï¼µ½¶Ô¡°LGBTQÒé³Ì¡±µÄ±§Ô¹µÈ¸÷ÀàÄÚÈÝ ¡£Ì©ÌØÒòÕÅÑïÄÐ×ÓÆø¸ÅºÍ±áµÍÅ®ÐÔ¸ÅÏë¶øÎÅÃû £¬Ä¿Ç°Ãæ¶ÔÀ´×ÔÂÞÂíÄáÑǺÍÓ¢¹úµÄÎåÏî˾·¨µ÷²é ¡£ºÚ¿ÍÒѽ«Ð¹Â¶µÄµç×ÓÓʼþµØÖ·Ìṩ¸øÓû§Í´´¦Ð¹Â¶¾¯±¨·þÎñHaveIBeenPwned £¬²¢½«Ì¸ÌìÊý¾Ý½»¸øÁËÐÂÎż¯ÌåDDoSecretsÍйÜ ¡£


https://www.dailydot.com/debug/andrew-tate-the-real-world-hack/


3. QNAP¹Ì¼þ¸üÐÂÒý·¢ÏνÓÎÊÌâ £¬Òѳ·»Ø²¢½¨Òé½µ¼¶


11ÔÂ22ÈÕ £¬QNAP½üÆÚ°ä²¼µÄ¹Ì¼þ¸üÐÂQTS 5.2.2.2950 build 20241114Ö¼ÔÚ½¨²¹¶à¸ö°²È«·ì϶²¢½¨¸´ÒÑÖªÎÊÌâ £¬µ«´óÁ¿¿Í»§»ã±¨³Æ¸Ã¸üзÛËéÁËÉ豸ÏνӲ¢µ¼ÖÂÎÞ·¨½Ó¼û ¡£¾ÝÓû§·´À¡ £¬¸üкó³öÏÖÎÞ·¨Ïνӵ½É豸¡¢µÇ¼ʹ´¦ÃýÎó¡¢¼ì²âµ½Î´¾­ÊÚȨµÄ¸ü¸ÄÒÔ¼°ÄÚÖÃÀûÓ÷¨Ê½ÒòδװÖÃPython2¶øÎÞ·¨Ê¹ÓõÈÎÊÌâ ¡£QNAPÖ§³ÖÍŶÓÒÑÈ·ÈϸøüÐÂÒÑ´ÓÏÂÔØÒ³ÃæÉ¾³ý £¬²¢½¨Ò齫¹Ì¼þ½µ¼¶ÖÁQTS 5.2.1.2930 build 2024102ÒÔ½â¾öÏνӺÍÀûÓ÷¨Ê½°Ü»µµÄÎÊÌâ ¡£Ö»¹ÜQNAPÉÐδ¾Í´Ëʰ䲼¹«¿ªÉêÃ÷ £¬µ«ÆäÖ§³ÖÍŶÓÒѻظ´²¿ÃÅÊÜÓ°Ïì¿Í»§ ¡£BleepingComputerÌá³öµÄÆÀÂÛÒªÇóÉÐδµÃµ½QNAPµÄ»Ø¸´ ¡£


https://www.bleepingcomputer.com/news/technology/qnap-pulls-buggy-qts-firmware-causing-widespread-nas-issues/


4. Microsoft Power PagesÅäÖÃʧÎóÖÂNHSµÈÊý¾Ý´ó¹æÄ£Ð¹Â¶


11ÔÂ23ÈÕ £¬¶¼°ØÁÖÍøÂ簲ȫ×êÑÐÔ±ÑÇÂס¤¿ÆË¹ÌØÂå·¢ÏÖ £¬ÓÉÓÚMicrosoft Power PagesÈí¼þƽ̨ÅäÖò»µ± £¬µ¼ÖÂ110Íò·ÝNHSÔ±¹¤¼Í¼±»Ð¹Â¶ £¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍ¼ÒͥסַµÈÃô¸ÐÐÅÏ¢ ¡£ÕâÒ»ÎÊÌâ²»½öÓ°ÏìNHS £¬»¹²¨¼°È«Çò¶à¸ö×éÖ¯ºÍµÐÔÖʵÌå ¡£¿ÆË¹ÌØÂåÖ¸³ö £¬Ö»¹Ü΢ÈíÔÚPower PagesÖÎÀíÃæ°åÖÐÉèÖÃÁËÖÒ¸æºá·ùºÍ±êÖ¾ £¬µ«²»×ã¶Ôºó¹ûµÄ³ä·ÖÀí½â ¡£ËûÒÔΪ £¬NHSÊý¾Ýй¶ÓëHSEÊý¾ÝÎÊÌâÀàËÆ £¬¶¼Êǿɹ«¿ª½Ó¼ûµÄÃÅ»§ £¬ÓɳаüÉÌÅäÖúͲ¿Ê𠣬ÇÒ°²È«ÐÔ±»ºöÊÓ ¡£¿ÆË¹ÌØÂåºôÓõÏÂÒ»½ìµ±¾Ö½«ÍøÂ簲ȫ×÷ΪÓÅÏÈÊÂÏî £¬²¢×êÑÐÔì¶©¹ú¶È¿ò¼Ü £¬ÒÔÌá¸ß¹ú¶ÈÍøÂç·ÀÓùÄÜÁ¦ ¡£ËûÇ¿µ÷ £¬Ô¤·À±È½â³ýÇÖº¦¸ü³ÁÒª £¬²¢½¨Ò鷢չȫ¹úÐÔÐû´«»î¶¯ £¬Ìá¸ß¹«¼Ò¶ÔÍøÂ簲ȫ»ù´¡ÖªÊ¶µÄÏàʶ £¬Èç¶à³É·ÖÉí·ÝÑéÖ¤ºÍÔ¤·Àͨ¹ýµç»°Ìá¹©ÒøÐÐÐÅÏ¢µÈ ¡£¿ÆË¹ÌØÂåÒÔΪ £¬°®¶ûÀ¼ÔÚÍøÂ簲ȫ·½ÃæµÄ×ʽðÑϳÁ²»¼° £¬Ó¦¼Ó´ó¶Ô¼¼ÊõÈ˲ŵÄͶ×Ê £¬ÒÔÌáÉý¹ú¶ÈÍøÂ簲ȫˮƽ ¡£


https://www.breakingnews.ie/ireland/irish-researcher-finds-1-1-million-nhs-employee-records-were-leaked-1698047.html


5. Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüÊý¾Ýй¶ £¬Ë¾·¨²¿´¹Î£Ó¦¶Ô


11ÔÂ23ÈÕ £¬Ó¢¹ú˾·¨²¿ÒÑÈ·ÈϲúÉúÁËÒ»Â·Éæ¼°Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüµÄÊý¾Ýй¶ÊÂÎñ £¬¾Ý¡¶Ì©ÎîÊ¿±¨¡·±¨Â· £¬´ÓǰÁ½ÖÜÄÚ £¬»úÃܼàÓü²¼¾Öͼ±»Ð¹Â¶ÖÁ°µÍø ¡£ÕâЩй¶µÄÀ¶Í¼Ô̺¬ÉãÏñÍ·ºÍ´«¸ÐÆ÷µÈ¹Ø¼ü°²È«Ö°ÄܵĵØÎ» £¬¿ÉÄܻᱻÓÐ×éÖ¯·¸×OÍÅÀûÓà £¬ÒÔ½«¶¾Æ·»ò±øÆ÷×ß˽½ø¼àÓü £¬ÉõÖÁ²ß¶¯Ô½Óü ¡£Ë¾·¨²¿ÒÑÁ¢¼´²ÉÈ¡Ðж¯È·±£¼àÓü°²È« £¬¶ø¼àÓüµ±¾ÖÒÉ»óÕâ´ÎйÃÜ¿ÉÄÜÓëÓÐ×éÖ¯·¸×OÍÅÊÔIJÀûÓÃÎÞÈË»ú×ß˽¶¾Æ·ÓйØ ¡£Ä¿Ç°Éв»Ã÷ÏÔÄÄЩ¼àÓü´òËãÊܵ½ÁËÓ°Ïì £¬µ«ÄÚ¸ó°ì¹«ÊҺͼàÓüÖÎÀí¾ÖÔÚµ÷²éÎ¥¹æÐÐΪµÄÔ´Í· £¬²¢ÆÀ¹ÀË­¿ÉÄÜ´ÓÕâЩÐÅÏ¢ÖÐÊÜÒæ ¡£Ó¢¹ú¹ú¶È·¸×ï¾Ö°µÊ¾ £¬¸Ã¾ÖÔÚÒÔÕÕ·÷Éí·ÝÌṩ֧³Ö ¡£Ë¾·¨²¿½²»°ÈËÇ¿µ÷ £¬ËûÃDz»»á¶Ô´ËÀలȫÎÊÌâµÄ¾ßÌåϸ½Ú°ä·¢ÆÀÂÛ £¬µ«ÒÑÁ¢¼´²ÉÈ¡Ðж¯Ó¦¶ÔDZÔÚй¶ÊÂÎñ £¬È·±£¼àÓü°²È« ¡£


https://www.bbc.co.uk/news/articles/ce8y5jm4lyzo


6. ´ó¸£¿Ë˹¹«Á¢Ñ§ÌÃÔâÍøÂç´¹µöÚ¿Æ­ £¬220ÍòÃÀÔª×Ê½ð±»Æ­×ß


11ÔÂ21ÈÕ £¬´ó¸£¿Ë˹¹«Á¢Ñ§ÌýñÄêÔçЩʱ³½Ôâ·êÁËÍøÂç´¹µöÚ¿Æ­ £¬±»Æ­È¡ÁË220ÍòÃÀÔª ¡£ÕâÆðڲƭ°¸ÊÇÍøÂç´¹µö»òÉç»á¹¤³ÌȦÌ×µÄÁ˾Ö £¬¹¥»÷ÕߺýŪԱ¹¤Ð¹Â¼ûô¸ÐÐÅÏ¢»òÖ´ÐÐijЩ²Ù×÷ £¬Èç»ã¿î»òÌṩÐÅÏ¢ ¡£Ñ§ÇøºÍ´ó¸£¿Ë˹¾¯Ô±¾ÖûÓÐÌṩÓйط¸×ï»òµ÷²éµÄÏêÇé £¬µ«ÌØÇÚ¾ÖÔÚЭÖúµ÷²é ¡£Ñ§ÇøIT×ܼవʾ £¬Õâ´ÎÚ¿Æ­ÊÇËû¾­Àú¹ýµÄ×ÔÓµÄÍøÂç·¸×ï ¡£±»µÁ×ʽðµÄÊý¶îÅú×¢ÇÔÔô°ÑÎÕÁËÑ§ÇøµÄÄÚ²¿ÐÅÏ¢ £¬ÀûÓÃÕâЩÐÅϢʹÉç»á¹¤³Ì´òËã¸ü¾ß˵·þÁ¦ ¡£Ö»¹Ü˾·¨ÒªÒÞ񵂿Ïò¹«¼Ò·ÖÏíÆä´ó²¿ÃÅÒµÎñ¼Í¼ £¬µ«Ñ§Çø¹ÙÔ±ºÍ·¨Âɲ¿ÃŶ¼Ã»ÓÐй©Õâ200ÍòÃÀÔªÊÇÒ»´ÎÐÔתÕË»¹ÊÇ·ÖÂÅ´ÎתÕË ¡£ÔÚڲƭÊÂÎñ²úÉúǰµÄËÄÌìÀï £¬Ñ§ÇøÉÌÎñ°ì¹«ÊÒÖ§¸¶ÁË1000¶à±Ê¿î×Ó £¬ÆäÖÐÔ̺¬Ïò³Ð°üÉÌÖ§¸¶µÄÁ½±Ê´ó¶î¿î×Ó ¡£Ñ§Çø¹ÙÔ±°µÊ¾ £¬ÕâЩ¿î×Ó½«ÓÃÓÚÔÚ½øÐеĹ¹ÖþÏîĿ֮һ ¡£


https://www.govtech.com/education/k-12/grand-forks-public-schools-loses-2-2m-to-phishing-scam