BlueSkyÓû§¼¤Ôö°éÉúÕ©ÆÌôÕ½
Ðû²¼Ê±¼ä 2024-11-251. BlueSkyÓû§¼¤Ôö°éÉúÕ©ÆÌôÕ½
11ÔÂ21ÈÕ£¬Ëæ×ÅBlueSkyÕâһȥÖÐÐÄ»¯Î¢²©·þÎñµÄÓû§ÊýÁ¿¼¤Ôö£¬ÍþвÐÐΪÕßÒ²·×·×Ó¿Èë¸Ãƽ̨¡£½üÆÚ£¬BleepingComputer·¢ÏÖBlueSkyÉÏ·ºÆðÁ˼ÓÃÜ»õ±Òƾ֣¬°üÂÞÀûÓÃMetaÆ·ÅƽøÐÐÎóµ¼µÄÍƹãÌûºÍÐé¼Ù¿ÕͶ´ÙÏúµÈ¡£ÕâЩƾֲ»½öÎóµ¼¹ÛÖÚ½«¹ã¸æ²úÎïÓë¿Æ¼¼¾ÞÍ·Meta¼°Æä¿´·¨ÁªÏµÆðÀ´£¬»¹Í¨¹ý¾«ÐÄÉè¼ÆµÄÍøÕ¾ºÍÓòÃûÀ´Ä£·ÂMetaµÄÆ·ÅƺÍ×ÖÌ壬ÒÔÌá¸ßÆÛթЧ¹û¡£Í¬Ê±£¬BlueSkyÄþ¾²ÍŶÓҲ֤ʵ£¬Ëæ×ÅÓû§ÊýÁ¿µÄÔö¼Ó£¬Æ½Ì¨ÊÕµ½ÁË´óÁ¿¹ØÓÚÀ¬»øÓʼþ¡¢Õ©ÆºÍ¶ñÒâ¹¥»÷»î¶¯µÄ³ÂËß¡£¾¡¹ÜBlueSkyµÄÈ¥ÖÐÐÄ»¯¼Ü¹¹ÎªÓû§ÌṩÁ˸ü´óµÄ×ÔÓɺͿØÖÆȨ£¬µ«Ò²´øÀ´ÁËеÄÌôÕ½¡£ÓÉÓÚÈκÎÈ˶¼¿ÉÒÔÆô¶¯BlueSkyʵÀý£¬Õ©ÆÕß¿ÉÒÔÀûÓÃÕâÒ»ÌصãÀ´ÉèÖÃ×Ô¼ºµÄʵÀý²¢Íƹã¿ÉÒɵĽ»Ò׼ƻ®¡£´ËÍ⣬ËÑË÷ÒýÇæÒ²¿ÉÄÜץȡ²¢Ë÷ÒýÀ´×ÔµÚÈý·½BlueSkyʵÀýµÄÌû×Ó£¬´Ó¶ø×ÊÖúÕ©ÆÕßÌá¸ßËÑË÷ÅÅÃûºÍSEOÆȺ¦ÓÎÏ·¡£Òò´Ë£¬BlueSkyÐèÒª½â¾öÕâЩÌôÕ½£¬ÒÔ±£»¤Óû§ÃâÊÜÆÛÕ©ºÍ¶ñÒâ¹¥»÷µÄΣº¦¡£
https://www.bleepingcomputer.com/news/security/now-bluesky-hit-with-crypto-scams-as-it-crosses-20-million-users/
2. °²µÂ³¡¤Ì©ÌØÔÚÏß´óѧÔâºÚ¿ÍÈëÇÖ£¬80ÍòÓû§Êý¾Ýй¶
11ÔÂ21ÈÕ£¬¼«ÓÒÒíÓ°ÏìÕß°²µÂ³¡¤Ì©ÌØ¿ª°ìµÄÔÚÏß´óѧ¡°ÕæʵÊÀ½ç¡±£¨ÔÃû¡°Hustler's University¡±£©ÔâÓöºÚ¿ÍÈëÇÖ£¬µ¼ÖÂÔ¼325,000ÃûÓû§µÄµç×ÓÓʼþµØÖ·±»Ð¹Â¶£¬Í¬Ê±Ô¼794,000¸öÓû§Ãû¼°Æä221¸ö¹«¹²ºÍ395¸ö˽ÈËÁÄÌì·þÎñÆ÷µÄÄÚÈÝÒ²±»Æع⡣¸Ãƽ̨ÌṩÿÔÂÔ¼50ÃÀÔªµÄ¡°¸ß¼¶ÅàѵºÍÖ¸µ¼¡±£¬Ö÷ÒªÉæ¼°½¡¿µ¡¢½¡Éí¡¢½ðÈÚͶ×ʺ͵ç×ÓÉÌÎñµÈÖ÷Ìâ¡£ºÚ¿ÍÔÚÈëÇÖºóÓÚÌ©ÌصÄÖ±²¥½ÚÄ¿ÖÐÉÏ´«ÁË´óÁ¿ÐÄÇé·ûºÅÒÔʾÌôÐÆ£¬²¢Éù³ÆÄܹ»ÀûÓ鶴½øÐжàÏîÆÆ»µÐÔ²Ù×÷¡£´Ë´ÎÈëÇֵĶ¯»ú±»ÈÏΪÊÇ¡°ºÚ¿ÍÐж¯Ö÷Ò塱£¬ÇÒ¸Ãƽ̨µÄÄþ¾²ÐÔ±»Ö¸Îª¡°¼«¶È²»Äþ¾²¡±¡£ÁÄÌì¼Ç¼º¸ÇÁË´ÓÀøÖ¾Óï¼µ½¶Ô¡°LGBTQÒé³Ì¡±µÄËß¿àµÈÖÖÖÖÄÚÈÝ¡£Ì©ÌØÒòÐûÑïÄÐ×ÓÆø¸ÅºÍ±áµÍÅ®ÐÔ¿´·¨¶øÎÅÃû£¬Ä¿Ç°ÃæÁÙÀ´×ÔÂÞÂíÄáÑǺÍÓ¢¹úµÄÎåÏîÖ´·¨ÊӲ졣ºÚ¿ÍÒѽ«Ð¹Â¶µÄµç×ÓÓʼþµØÖ·ÌṩӦÓû§Æ¾¾Ýй¶¾¯±¨·þÎñHaveIBeenPwned£¬²¢½«ÁÄÌìÊý¾Ý½»¸øÁËÐÂÎÅÍÅÌåDDoSecretsÍйܡ£
https://www.dailydot.com/debug/andrew-tate-the-real-world-hack/
3. QNAP¹Ì¼þ¸üÐÂÒý·¢Á¬½ÓÎÊÌ⣬Òѳ·»Ø²¢½¨Òé½µ¼¶
11ÔÂ22ÈÕ£¬QNAP½üÆÚÐû²¼µÄ¹Ì¼þ¸üÐÂQTS 5.2.2.2950 build 20241114Ö¼ÔÚÐÞ²¹¶à¸öÄþ¾²Â©¶´²¢ÐÞ¸´ÒÑÖªÎÊÌ⣬µ«´óÁ¿¿Í»§³ÂË߳ƸøüÐÂÆÆ»µÁËÉ豸Á¬½Ó²¢µ¼ÖÂÎÞ·¨·ÃÎÊ¡£¾ÝÓû§·´À¡£¬¸üкó·ºÆðÎÞ·¨Á¬½Óµ½É豸¡¢µÇ¼ƾ¾Ý´íÎó¡¢¼ì²âµ½Î´¾ÊÚȨµÄ¸ü¸ÄÒÔ¼°ÄÚÖÃÓ¦Ó÷¨Ê½Òòδ°²×°Python2¶øÎÞ·¨Ê¹ÓõÈÎÊÌâ¡£QNAPÖ§³ÖÍŶÓÒÑÈ·ÈϸøüÐÂÒÑ´ÓÏÂÔØÒ³Ãæɾ³ý£¬²¢½¨Ò齫¹Ì¼þ½µ¼¶ÖÁQTS 5.2.1.2930 build 2024102ÒÔ½â¾öÁ¬½ÓºÍÓ¦Ó÷¨Ê½Ë𻵵ÄÎÊÌâ¡£¾¡¹ÜQNAPÉÐδ¾Í´ËÊÂÐû²¼¹ûÈ»ÉùÃ÷£¬µ«ÆäÖ§³ÖÍŶÓÒѻظ´²¿ÃÅÊÜÓ°Ïì¿Í»§¡£BleepingComputerÌá³öµÄÆÀÂÛÇëÇóÉÐδµÃµ½QNAPµÄ»Ø¸´¡£
https://www.bleepingcomputer.com/news/technology/qnap-pulls-buggy-qts-firmware-causing-widespread-nas-issues/
4. Microsoft Power PagesÅäÖÃʧÎóÖÂNHSµÈÊý¾Ý´ó¹æģй¶
11ÔÂ23ÈÕ£¬¶¼°ØÁÖÍøÂçÄþ¾²Ñо¿Ô±ÑÇÂס¤¿Æ˹ÌØÂå·¢ÏÖ£¬ÓÉÓÚMicrosoft Power PagesÈí¼þƽ̨ÅäÖò»Í×£¬µ¼ÖÂ110Íò·ÝNHSÔ±¹¤¼Ç¼±»Ð¹Â¶£¬°üÂÞµç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍ¼ÒͥסַµÈÃô¸ÐÐÅÏ¢¡£ÕâÒ»ÎÊÌâ²»½öÓ°ÏìNHS£¬»¹²¨¼°È«Çò¶à¸ö×éÖ¯ºÍÕþ¸®ÊµÌå¡£¿Æ˹ÌØÂåÖ¸³ö£¬¾¡¹Ü΢ÈíÔÚPower Pages¹ÜÀíÃæ°åÖÐÉèÖÃÁ˾¯¸æºá·ùºÍ±êÖ¾£¬µ«È±·¦¶Ôºó¹ûµÄ³äʵÀí½â¡£ËûÈÏΪ£¬NHSÊý¾Ýй¶ÓëHSEÊý¾ÝÎÊÌâÏàËÆ£¬¶¼ÊǿɹûÈ»·ÃÎʵÄÃÅ»§£¬ÓɳаüÉÌÅäÖúͲ¿Êð£¬ÇÒÄþ¾²ÐÔ±»ºöÊÓ¡£¿Æ˹ÌØÂåºôÓõÏÂÒ»½ìÕþ¸®½«ÍøÂçÄþ¾²×÷ΪÓÅÏÈÊÂÏ²¢Ñо¿Öƶ¨¹ú¼Ò¿ò¼Ü£¬ÒÔÌá¸ß¹ú¼ÒÍøÂç·ÀÓùÄÜÁ¦¡£ËûÇ¿µ÷£¬Ô¤·À±ÈÏû³ýË𺦸üÖØÒª£¬²¢½¨Ò鿪չȫ¹úÐÔÐû´«»î¶¯£¬Ìá¸ß¹«ÖÚ¶ÔÍøÂçÄþ¾²»ù´¡ÖªÊ¶µÄÁ˽⣬Èç¶àÒòËØÉí·ÝÑéÖ¤ºÍÖÆֹͨ¹ýµç»°ÌṩÒøÐÐÐÅÏ¢µÈ¡£¿Æ˹ÌØÂåÈÏΪ£¬°®¶ûÀ¼ÔÚÍøÂçÄþ¾²·½ÃæµÄ×ʽðÑÏÖز»×㣬Ӧ¼Ó´ó¶Ô¼¼ÊõÈ˲ŵÄͶ×Ê£¬ÒÔÌáÉý¹ú¼ÒÍøÂçÄþ¾²Ë®Æ½¡£
https://www.breakingnews.ie/ireland/irish-researcher-finds-1-1-million-nhs-employee-records-were-leaked-1698047.html
5. Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüÊý¾Ýй¶£¬Ë¾·¨²¿½ô¼±Ó¦¶Ô
11ÔÂ23ÈÕ£¬Ó¢¹ú˾·¨²¿ÒÑÈ·ÈÏ·¢ÉúÁËÒ»ÆðÉæ¼°Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüµÄÊý¾Ýй¶Ê¼þ£¬¾Ý¡¶Ì©ÎîÊ¿±¨¡·±¨µÀ£¬¹ýÈ¥Á½ÖÜÄÚ£¬»úÃܼàÓü½á¹¹Í¼±»Ð¹Â¶ÖÁ°µÍø¡£ÕâЩ鶵ÄÀ¶Í¼°üÂÞÉãÏñÍ·ºÍ´«¸ÐÆ÷µÈÒªº¦Äþ¾²¹¦Ð§µÄλÖ㬿ÉÄܻᱻÓÐ×éÖ¯·¸×OÍÅÀûÓã¬ÒÔ½«¶¾Æ·»òÎäÆ÷×ß˽½ø¼àÓü£¬ÉõÖÁ³ïıԽÓü¡£Ë¾·¨²¿ÒÑÁ¢¼´½ÓÄÉÐж¯È·±£¼àÓüÄþ¾²£¬¶ø¼àÓüÕþ¸®»³ÒÉ´Ë´ÎйÃÜ¿ÉÄÜÓëÓÐ×éÖ¯·¸×OÍÅÊÔͼÀûÓÃÎÞÈË»ú×ß˽¶¾Æ·Óйء£Ä¿Ç°Éв»Çå³þÄÄЩ¼àÓü¼Æ»®Êܵ½ÁËÓ°Ï죬µ«ÄÚ¸ó°ì¹«ÊҺͼàÓü¹ÜÀí¾ÖÕýÔÚÊÓ²ìÎ¥¹æÐÐΪµÄÔ´Í·£¬²¢ÆÀ¹ÀË¿ÉÄÜ´ÓÕâЩÐÅÏ¢ÖÐÊÜÒæ¡£Ó¢¹ú¹ú¼Ò·¸×ï¾ÖÌåÏÖ£¬¸Ã¾ÖÕýÔÚÒÔÕÕÁÏÉí·ÝÌṩ֧³Ö¡£Ë¾·¨²¿·¢ÑÔÈËÇ¿µ÷£¬ËûÃDz»»á¶Ô´ËÀàÄþ¾²ÎÊÌâµÄ¾ßÌåϸ½Ú·¢±íÆÀÂÛ£¬µ«ÒÑÁ¢¼´½ÓÄÉÐж¯Ó¦¶ÔDZÔÚй¶Ê¼þ£¬È·±£¼àÓüÄþ¾²¡£
https://www.bbc.co.uk/news/articles/ce8y5jm4lyzo
6. ´ó¸£¿Ë˹¹«Á¢Ñ§Ð£ÔâÍøÂçµöÓãÕ©Æ£¬220ÍòÃÀÔª×ʽðÊÜÆ×ß
11ÔÂ21ÈÕ£¬´ó¸£¿Ë˹¹«Á¢Ñ§Ð£½ñÄêÔçЩʱºòÔâÓöÁËÍøÂçµöÓãÕ©Æ£¬ÊÜÆÈ¡ÁË220ÍòÃÀÔª¡£ÕâÆðÆÛÕ©°¸ÊÇÍøÂçµöÓã»òÉç»á¹¤³ÌƾֵĽá¹û£¬¹¥»÷ÕßÆÛÆÔ±¹¤Ð¹Â¶Ãô¸ÐÐÅÏ¢»òÖ´ÐÐijЩ²Ù×÷£¬Èç»ã¿î»òÌṩÐÅÏ¢¡£Ñ§ÇøºÍ´ó¸£¿Ë˹¾¯²ì¾ÖûÓÐÌṩÓйط¸×ï»òÊÓ²ìµÄÏêÇ飬µ«ÌØÇÚ¾ÖÕýÔÚÐÖúÊӲ졣ѧÇøIT×ܼàÌåÏÖ£¬Õâ´ÎÕ©ÆÊÇËû¾Àú¹ýµÄ×îÅÓ´óµÄÍøÂç·¸×ï¡£±»µÁ×ʽðµÄÊý¶î±íÃ÷ÇÔÔôÕÆÎÕÁËѧÇøµÄÄÚ²¿ÐÅÏ¢£¬ÀûÓÃÕâЩÐÅϢʹÉç»á¹¤³Ì¼Æ»®¸ü¾ß˵·þÁ¦¡£¾¡¹ÜÖ´·¨ÒªÇóѧÇøÏò¹«ÖÚ·ÖÏíÆä´ó²¿ÃÅÒµÎñ¼Ç¼£¬µ«Ñ§Çø¹ÙÔ±ºÍÖ´·¨²¿ÃŶ¼Ã»ÓÐ͸¶Õâ200ÍòÃÀÔªÊÇÒ»´ÎÐÔתÕË»¹ÊÇ·Ö¶à´ÎתÕË¡£ÔÚÆÛթʼþ·¢ÉúÇ°µÄËÄÌìÀѧÇøÉÌÎñ°ì¹«ÊÒÖ§¸¶ÁË1000¶à±Ê¿îÏÆäÖаüÂÞÏò³Ð°üÉÌÖ§¸¶µÄÁ½±Ê´ó¶î¿îÏѧÇø¹ÙÔ±ÌåÏÖ£¬ÕâЩ¿îÏÓÃÓÚÕýÔÚ½øÐеĽ¨ÖþÏîÄ¿Ö®Ò»¡£
https://www.govtech.com/education/k-12/grand-forks-public-schools-loses-2-2m-to-phishing-scam