BlueSkyÓû§¼¤Ôö°éÉúÕ©Æ­ÌôÕ½

Ðû²¼Ê±¼ä 2024-11-25

1. BlueSkyÓû§¼¤Ôö°éÉúÕ©Æ­ÌôÕ½


11ÔÂ21ÈÕ £¬Ëæ×ÅBlueSkyÕâһȥÖÐÐÄ»¯Î¢²©·þÎñµÄÓû§ÊýÁ¿¼¤Ôö £¬ÍþвÐÐΪÕßÒ²·×·×Ó¿Èë¸Ãƽ̨¡£½üÆÚ £¬BleepingComputer·¢ÏÖBlueSkyÉÏ·ºÆðÁ˼ÓÃÜ»õ±ÒÆ­¾Ö £¬°üÂÞÀûÓÃMetaÆ·ÅƽøÐÐÎóµ¼µÄÍƹãÌûºÍÐé¼Ù¿ÕͶ´ÙÏúµÈ¡£ÕâЩƭ¾Ö²»½öÎóµ¼¹ÛÖÚ½«¹ã¸æ²úÎïÓë¿Æ¼¼¾ÞÍ·Meta¼°Æä¿´·¨ÁªÏµÆðÀ´ £¬»¹Í¨¹ý¾«ÐÄÉè¼ÆµÄÍøÕ¾ºÍÓòÃûÀ´Ä£·ÂMetaµÄÆ·ÅƺÍ×ÖÌå £¬ÒÔÌá¸ßÆÛթЧ¹û¡£Í¬Ê± £¬BlueSkyÄþ¾²ÍŶÓҲ֤ʵ £¬Ëæ×ÅÓû§ÊýÁ¿µÄÔö¼Ó £¬Æ½Ì¨ÊÕµ½ÁË´óÁ¿¹ØÓÚÀ¬»øÓʼþ¡¢Õ©Æ­ºÍ¶ñÒâ¹¥»÷»î¶¯µÄ³ÂËß¡£¾¡¹ÜBlueSkyµÄÈ¥ÖÐÐÄ»¯¼Ü¹¹ÎªÓû§ÌṩÁ˸ü´óµÄ×ÔÓɺͿØÖÆȨ £¬µ«Ò²´øÀ´ÁËеÄÌôÕ½¡£ÓÉÓÚÈκÎÈ˶¼¿ÉÒÔÆô¶¯BlueSkyʵÀý £¬Õ©Æ­Õß¿ÉÒÔÀûÓÃÕâÒ»ÌصãÀ´ÉèÖÃ×Ô¼ºµÄʵÀý²¢Íƹã¿ÉÒɵĽ»Ò׼ƻ®¡£´ËÍâ £¬ËÑË÷ÒýÇæÒ²¿ÉÄÜץȡ²¢Ë÷ÒýÀ´×ÔµÚÈý·½BlueSkyʵÀýµÄÌû×Ó £¬´Ó¶ø×ÊÖúÕ©Æ­ÕßÌá¸ßËÑË÷ÅÅÃûºÍSEOÆȺ¦ÓÎÏ·¡£Òò´Ë £¬BlueSkyÐèÒª½â¾öÕâЩÌôÕ½ £¬ÒÔ±£»¤Óû§ÃâÊÜÆÛÕ©ºÍ¶ñÒâ¹¥»÷µÄΣº¦¡£


https://www.bleepingcomputer.com/news/security/now-bluesky-hit-with-crypto-scams-as-it-crosses-20-million-users/


2. °²µÂ³¡¤Ì©ÌØÔÚÏß´óѧÔâºÚ¿ÍÈëÇÖ £¬80ÍòÓû§Êý¾Ýй¶


11ÔÂ21ÈÕ £¬¼«ÓÒÒíÓ°ÏìÕß°²µÂ³¡¤Ì©ÌØ¿ª°ìµÄÔÚÏß´óѧ¡°ÕæʵÊÀ½ç¡±£¨Ô­Ãû¡°Hustler's University¡±£©ÔâÓöºÚ¿ÍÈëÇÖ £¬µ¼ÖÂÔ¼325,000ÃûÓû§µÄµç×ÓÓʼþµØÖ·±»Ð¹Â¶ £¬Í¬Ê±Ô¼794,000¸öÓû§Ãû¼°Æä221¸ö¹«¹²ºÍ395¸ö˽ÈËÁÄÌì·þÎñÆ÷µÄÄÚÈÝÒ²±»Æعâ¡£¸Ãƽ̨ÌṩÿÔÂÔ¼50ÃÀÔªµÄ¡°¸ß¼¶ÅàѵºÍÖ¸µ¼¡± £¬Ö÷ÒªÉæ¼°½¡¿µ¡¢½¡Éí¡¢½ðÈÚͶ×ʺ͵ç×ÓÉÌÎñµÈÖ÷Ìâ¡£ºÚ¿ÍÔÚÈëÇÖºóÓÚÌ©ÌصÄÖ±²¥½ÚÄ¿ÖÐÉÏ´«ÁË´óÁ¿ÐÄÇé·ûºÅÒÔʾÌôÐÆ £¬²¢Éù³ÆÄܹ»ÀûÓ鶴½øÐжàÏîÆÆ»µÐÔ²Ù×÷¡£´Ë´ÎÈëÇֵĶ¯»ú±»ÈÏΪÊÇ¡°ºÚ¿ÍÐж¯Ö÷Ò塱 £¬ÇÒ¸Ãƽ̨µÄÄþ¾²ÐÔ±»Ö¸Îª¡°¼«¶È²»Äþ¾²¡±¡£ÁÄÌì¼Ç¼º­¸ÇÁË´ÓÀøÖ¾Óï¼µ½¶Ô¡°LGBTQÒé³Ì¡±µÄËß¿àµÈÖÖÖÖÄÚÈÝ¡£Ì©ÌØÒòÐûÑïÄÐ×ÓÆø¸ÅºÍ±áµÍÅ®ÐÔ¿´·¨¶øÎÅÃû £¬Ä¿Ç°ÃæÁÙÀ´×ÔÂÞÂíÄáÑǺÍÓ¢¹úµÄÎåÏîÖ´·¨ÊӲ졣ºÚ¿ÍÒѽ«Ð¹Â¶µÄµç×ÓÓʼþµØÖ·ÌṩӦÓû§Æ¾¾Ýй¶¾¯±¨·þÎñHaveIBeenPwned £¬²¢½«ÁÄÌìÊý¾Ý½»¸øÁËÐÂÎÅÍÅÌåDDoSecretsÍйÜ¡£


https://www.dailydot.com/debug/andrew-tate-the-real-world-hack/


3. QNAP¹Ì¼þ¸üÐÂÒý·¢Á¬½ÓÎÊÌâ £¬Òѳ·»Ø²¢½¨Òé½µ¼¶


11ÔÂ22ÈÕ £¬QNAP½üÆÚÐû²¼µÄ¹Ì¼þ¸üÐÂQTS 5.2.2.2950 build 20241114Ö¼ÔÚÐÞ²¹¶à¸öÄþ¾²Â©¶´²¢ÐÞ¸´ÒÑÖªÎÊÌâ £¬µ«´óÁ¿¿Í»§³ÂË߳ƸøüÐÂÆÆ»µÁËÉ豸Á¬½Ó²¢µ¼ÖÂÎÞ·¨·ÃÎÊ¡£¾ÝÓû§·´À¡ £¬¸üкó·ºÆðÎÞ·¨Á¬½Óµ½É豸¡¢µÇ¼ƾ¾Ý´íÎó¡¢¼ì²âµ½Î´¾­ÊÚȨµÄ¸ü¸ÄÒÔ¼°ÄÚÖÃÓ¦Ó÷¨Ê½Òòδ°²×°Python2¶øÎÞ·¨Ê¹ÓõÈÎÊÌâ¡£QNAPÖ§³ÖÍŶÓÒÑÈ·ÈϸøüÐÂÒÑ´ÓÏÂÔØÒ³Ãæɾ³ý £¬²¢½¨Ò齫¹Ì¼þ½µ¼¶ÖÁQTS 5.2.1.2930 build 2024102ÒÔ½â¾öÁ¬½ÓºÍÓ¦Ó÷¨Ê½Ë𻵵ÄÎÊÌâ¡£¾¡¹ÜQNAPÉÐδ¾Í´ËÊÂÐû²¼¹ûÈ»ÉùÃ÷ £¬µ«ÆäÖ§³ÖÍŶÓÒѻظ´²¿ÃÅÊÜÓ°Ïì¿Í»§¡£BleepingComputerÌá³öµÄÆÀÂÛÇëÇóÉÐδµÃµ½QNAPµÄ»Ø¸´¡£


https://www.bleepingcomputer.com/news/technology/qnap-pulls-buggy-qts-firmware-causing-widespread-nas-issues/


4. Microsoft Power PagesÅäÖÃʧÎóÖÂNHSµÈÊý¾Ý´ó¹æģй¶


11ÔÂ23ÈÕ £¬¶¼°ØÁÖÍøÂçÄþ¾²Ñо¿Ô±ÑÇÂס¤¿Æ˹ÌØÂå·¢ÏÖ £¬ÓÉÓÚMicrosoft Power PagesÈí¼þƽ̨ÅäÖò»Í× £¬µ¼ÖÂ110Íò·ÝNHSÔ±¹¤¼Ç¼±»Ð¹Â¶ £¬°üÂÞµç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍ¼ÒͥסַµÈÃô¸ÐÐÅÏ¢¡£ÕâÒ»ÎÊÌâ²»½öÓ°ÏìNHS £¬»¹²¨¼°È«Çò¶à¸ö×éÖ¯ºÍÕþ¸®ÊµÌå¡£¿Æ˹ÌØÂåÖ¸³ö £¬¾¡¹Ü΢ÈíÔÚPower Pages¹ÜÀíÃæ°åÖÐÉèÖÃÁ˾¯¸æºá·ùºÍ±êÖ¾ £¬µ«È±·¦¶Ôºó¹ûµÄ³äʵÀí½â¡£ËûÈÏΪ £¬NHSÊý¾Ýй¶ÓëHSEÊý¾ÝÎÊÌâÏàËÆ £¬¶¼ÊǿɹûÈ»·ÃÎʵÄÃÅ»§ £¬ÓɳаüÉÌÅäÖúͲ¿Ê𠣬ÇÒÄþ¾²ÐÔ±»ºöÊÓ¡£¿Æ˹ÌØÂåºôÓõÏÂÒ»½ìÕþ¸®½«ÍøÂçÄþ¾²×÷ΪÓÅÏÈÊÂÏî £¬²¢Ñо¿Öƶ¨¹ú¼Ò¿ò¼Ü £¬ÒÔÌá¸ß¹ú¼ÒÍøÂç·ÀÓùÄÜÁ¦¡£ËûÇ¿µ÷ £¬Ô¤·À±ÈÏû³ýË𺦸üÖØÒª £¬²¢½¨Ò鿪չȫ¹úÐÔÐû´«»î¶¯ £¬Ìá¸ß¹«ÖÚ¶ÔÍøÂçÄþ¾²»ù´¡ÖªÊ¶µÄÁ˽â £¬Èç¶àÒòËØÉí·ÝÑéÖ¤ºÍÖÆֹͨ¹ýµç»°ÌṩÒøÐÐÐÅÏ¢µÈ¡£¿Æ˹ÌØÂåÈÏΪ £¬°®¶ûÀ¼ÔÚÍøÂçÄþ¾²·½ÃæµÄ×ʽðÑÏÖز»×ã £¬Ó¦¼Ó´ó¶Ô¼¼ÊõÈ˲ŵÄͶ×Ê £¬ÒÔÌáÉý¹ú¼ÒÍøÂçÄþ¾²Ë®Æ½¡£


https://www.breakingnews.ie/ireland/irish-researcher-finds-1-1-million-nhs-employee-records-were-leaked-1698047.html


5. Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüÊý¾Ýй¶ £¬Ë¾·¨²¿½ô¼±Ó¦¶Ô


11ÔÂ23ÈÕ £¬Ó¢¹ú˾·¨²¿ÒÑÈ·ÈÏ·¢ÉúÁËÒ»ÆðÉæ¼°Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüµÄÊý¾Ýй¶Ê¼þ £¬¾Ý¡¶Ì©ÎîÊ¿±¨¡·±¨µÀ £¬¹ýÈ¥Á½ÖÜÄÚ £¬»úÃܼàÓü½á¹¹Í¼±»Ð¹Â¶ÖÁ°µÍø¡£ÕâЩ鶵ÄÀ¶Í¼°üÂÞÉãÏñÍ·ºÍ´«¸ÐÆ÷µÈÒªº¦Äþ¾²¹¦Ð§µÄλÖà £¬¿ÉÄܻᱻÓÐ×éÖ¯·¸×OÍÅÀûÓà £¬ÒÔ½«¶¾Æ·»òÎäÆ÷×ß˽½ø¼àÓü £¬ÉõÖÁ³ïıԽÓü¡£Ë¾·¨²¿ÒÑÁ¢¼´½ÓÄÉÐж¯È·±£¼àÓüÄþ¾² £¬¶ø¼àÓüÕþ¸®»³ÒÉ´Ë´ÎйÃÜ¿ÉÄÜÓëÓÐ×éÖ¯·¸×OÍÅÊÔͼÀûÓÃÎÞÈË»ú×ß˽¶¾Æ·ÓйØ¡£Ä¿Ç°Éв»Çå³þÄÄЩ¼àÓü¼Æ»®Êܵ½ÁËÓ°Ïì £¬µ«ÄÚ¸ó°ì¹«ÊҺͼàÓü¹ÜÀí¾ÖÕýÔÚÊÓ²ìÎ¥¹æÐÐΪµÄÔ´Í· £¬²¢ÆÀ¹ÀË­¿ÉÄÜ´ÓÕâЩÐÅÏ¢ÖÐÊÜÒæ¡£Ó¢¹ú¹ú¼Ò·¸×ï¾ÖÌåÏÖ £¬¸Ã¾ÖÕýÔÚÒÔÕÕÁÏÉí·ÝÌṩ֧³Ö¡£Ë¾·¨²¿·¢ÑÔÈËÇ¿µ÷ £¬ËûÃDz»»á¶Ô´ËÀàÄþ¾²ÎÊÌâµÄ¾ßÌåϸ½Ú·¢±íÆÀÂÛ £¬µ«ÒÑÁ¢¼´½ÓÄÉÐж¯Ó¦¶ÔDZÔÚй¶Ê¼þ £¬È·±£¼àÓüÄþ¾²¡£


https://www.bbc.co.uk/news/articles/ce8y5jm4lyzo


6. ´ó¸£¿Ë˹¹«Á¢Ñ§Ð£ÔâÍøÂçµöÓãÕ©Æ­ £¬220ÍòÃÀÔª×ʽðÊÜÆ­×ß


11ÔÂ21ÈÕ £¬´ó¸£¿Ë˹¹«Á¢Ñ§Ð£½ñÄêÔçЩʱºòÔâÓöÁËÍøÂçµöÓãÕ©Æ­ £¬ÊÜÆ­È¡ÁË220ÍòÃÀÔª¡£ÕâÆðÆÛÕ©°¸ÊÇÍøÂçµöÓã»òÉç»á¹¤³ÌÆ­¾ÖµÄ½á¹û £¬¹¥»÷ÕßÆÛÆ­Ô±¹¤Ð¹Â¶Ãô¸ÐÐÅÏ¢»òÖ´ÐÐijЩ²Ù×÷ £¬Èç»ã¿î»òÌṩÐÅÏ¢¡£Ñ§ÇøºÍ´ó¸£¿Ë˹¾¯²ì¾ÖûÓÐÌṩÓйط¸×ï»òÊÓ²ìµÄÏêÇé £¬µ«ÌØÇÚ¾ÖÕýÔÚЭÖúÊӲ졣ѧÇøIT×ܼàÌåÏÖ £¬Õâ´ÎÕ©Æ­ÊÇËû¾­Àú¹ýµÄ×îÅÓ´óµÄÍøÂç·¸×ï¡£±»µÁ×ʽðµÄÊý¶î±íÃ÷ÇÔÔôÕÆÎÕÁËѧÇøµÄÄÚ²¿ÐÅÏ¢ £¬ÀûÓÃÕâЩÐÅϢʹÉç»á¹¤³Ì¼Æ»®¸ü¾ß˵·þÁ¦¡£¾¡¹ÜÖ´·¨ÒªÇóѧÇøÏò¹«ÖÚ·ÖÏíÆä´ó²¿ÃÅÒµÎñ¼Ç¼ £¬µ«Ñ§Çø¹ÙÔ±ºÍÖ´·¨²¿ÃŶ¼Ã»ÓÐ͸¶Õâ200ÍòÃÀÔªÊÇÒ»´ÎÐÔתÕË»¹ÊÇ·Ö¶à´ÎתÕË¡£ÔÚÆÛթʼþ·¢ÉúÇ°µÄËÄÌìÀï £¬Ñ§ÇøÉÌÎñ°ì¹«ÊÒÖ§¸¶ÁË1000¶à±Ê¿îÏî £¬ÆäÖаüÂÞÏò³Ð°üÉÌÖ§¸¶µÄÁ½±Ê´ó¶î¿îÏѧÇø¹ÙÔ±ÌåÏÖ £¬ÕâЩ¿îÏÓÃÓÚÕýÔÚ½øÐеĽ¨ÖþÏîÄ¿Ö®Ò»¡£


https://www.govtech.com/education/k-12/grand-forks-public-schools-loses-2-2m-to-phishing-scam