BlueSkyÓû§¼¤Ôö°éÉúÕ©Æ­ÌôÕ½

Ðû²¼Ê±¼ä 2024-11-25

1. BlueSkyÓû§¼¤Ôö°éÉúÕ©Æ­ÌôÕ½


11ÔÂ21ÈÕ£¬Ëæ×ÅBlueSkyÕâһȥÖÐÐÄ»¯Î¢²©·þÎñµÄÓû§ÊýÄ¿¼¤Ôö£¬ÍþвÐÐΪÕßÒ²·×·×Ó¿Èë¸Ãƽ̨¡£½üÆÚ£¬BleepingComputer·¢Ã÷BlueSkyÉÏ·ºÆðÁ˼ÓÃÜÇ®±ÒȦÌ×£¬°üÀ¨Ê¹ÓÃMetaÆ·ÅƾÙÐÐÎóµ¼µÄÍƹãÌûºÍÐéα¿ÕͶ´ÙÏúµÈ¡£ÕâЩȦÌײ»µ«Îóµ¼¹ÛÖÚ½«¹ã¸æ²úÆ·Óë¿Æ¼¼¾ÞÍ·Meta¼°Æä¿´·¨ÁªÏµÆðÀ´£¬»¹Í¨¹ýÈ«ÐÄÉè¼ÆµÄÍøÕ¾ºÍÓòÃûÀ´Ä£ÄâMetaµÄÆ·ÅƺÍ×ÖÌ壬ÒÔÌá¸ßڲƭЧ¹û¡£Í¬Ê±£¬BlueSkyÇå¾²ÍŶÓҲ֤ʵ£¬Ëæ×ÅÓû§ÊýÄ¿µÄÔöÌí£¬Æ½Ì¨ÊÕµ½ÁË´ó×Ú¹ØÓÚÀ¬»øÓʼþ¡¢Õ©Æ­ºÍ¶ñÒâ¹¥»÷Ô˶¯µÄ±¨¸æ¡£Ö»¹ÜBlueSkyµÄÈ¥ÖÐÐÄ»¯¼Ü¹¹ÎªÓû§ÌṩÁ˸ü´óµÄ×ÔÓɺͿØÖÆȨ£¬µ«Ò²´øÀ´ÁËеÄÌôÕ½¡£ÓÉÓÚÈκÎÈ˶¼¿ÉÒÔÆô¶¯BlueSkyʵÀý£¬Õ©Æ­Õß¿ÉÒÔʹÓÃÕâÒ»ÌصãÀ´ÉèÖÃ×Ô¼ºµÄʵÀý²¢Íƹã¿ÉÒɵÄÉúÒâÍýÏë¡£±ðµÄ£¬ËÑË÷ÒýÇæÒ²¿ÉÄÜץȡ²¢Ë÷ÒýÀ´×ÔµÚÈý·½BlueSkyʵÀýµÄÌû×Ó£¬´Ó¶ø×ÊÖúÕ©Æ­ÕßÌá¸ßËÑË÷ÅÅÃûºÍSEOÆȺ¦ÓÎÏ·¡£Òò´Ë£¬BlueSkyÐèÒª½â¾öÕâЩÌôÕ½£¬ÒÔ± £»¤Óû§ÃâÊÜڲƭºÍ¶ñÒâ¹¥»÷µÄΣº¦¡£


https://www.bleepingcomputer.com/news/security/now-bluesky-hit-with-crypto-scams-as-it-crosses-20-million-users/


2. °²µÂ³¡¤Ì©ÌØÔÚÏß´óѧÔâºÚ¿ÍÈëÇÖ£¬80ÍòÓû§Êý¾Ýй¶


11ÔÂ21ÈÕ£¬¼«ÓÒÒíÓ°ÏìÕß°²µÂ³¡¤Ì©ÌØ¿ª°ìµÄÔÚÏß´óѧ¡°ÕæʵÌìÏ¡±£¨Ô­Ãû¡°Hustler's University¡±£©ÔâÓöºÚ¿ÍÈëÇÖ£¬µ¼ÖÂÔ¼325,000ÃûÓû§µÄµç×ÓÓʼþµØµã±»Ð¹Â¶£¬Í¬Ê±Ô¼794,000¸öÓû§Ãû¼°Æä221¸ö¹«¹²ºÍ395¸ö˽ÈË̸Ìì·þÎñÆ÷µÄÄÚÈÝÒ²±»Æعâ¡£¸Ãƽ̨ÌṩÿÔÂÔ¼50ÃÀÔªµÄ¡°¸ß¼¶ÅàѵºÍÖ¸µ¼¡±£¬Ö÷ÒªÉæ¼°¿µ½¡¡¢½¡Éí¡¢½ðÈÚͶ×ʺ͵ç×ÓÉÌÎñµÈÖ÷Ìâ¡£ºÚ¿ÍÔÚÈëÇÖºóÓÚÌ©ÌصÄÖ±²¥½ÚÄ¿ÖÐÉÏ´«ÁË´ó×ÚÐÄÇé·ûºÅÒÔʾѰÐÆ£¬²¢Éù³ÆÄܹ»Ê¹ÓÃÎó²î¾ÙÐжàÏîÆÆËðÐÔ²Ù×÷¡£´Ë´ÎÈëÇÖµÄÄîÍ·±»ÒÔΪÊÇ¡°ºÚ¿ÍÐж¯Ö÷Ò塱£¬ÇÒ¸Ãƽ̨µÄÇå¾²ÐÔ±»Ö¸Îª¡°¼«¶Ë²»Çå¾²¡±¡£Ì¸Ìì¼Í¼º­¸ÇÁË´ÓÀøÖ¾Óï¼µ½¶Ô¡°LGBTQÒé³Ì¡±µÄËß¿àµÈÖÖÖÖÄÚÈÝ¡£Ì©ÌØÒòÕÅÑïÄÐ×ÓÆø¸ÅºÍ±áµÍÅ®ÐÔ¿´·¨¶øÖøÃû£¬ÏÖÔÚÃæÁÙÀ´×ÔÂÞÂíÄáÑǺÍÓ¢¹úµÄÎåÏîÖ´·¨ÊӲ졣ºÚ¿ÍÒѽ«Ð¹Â¶µÄµç×ÓÓʼþµØµãÌṩӦÓû§Æ¾Ö¤Ð¹Â¶¾¯±¨·þÎñHaveIBeenPwned£¬²¢½«Ì¸ÌìÊý¾Ý½»¸øÁËÐÂÎÅÕûÌåDDoSecretsÍйÜ¡£


https://www.dailydot.com/debug/andrew-tate-the-real-world-hack/


3. QNAP¹Ì¼þ¸üÐÂÒý·¢ÅþÁ¬ÎÊÌ⣬Òѳ·»Ø²¢½¨Òé½µ¼¶


11ÔÂ22ÈÕ£¬QNAP½üÆÚÐû²¼µÄ¹Ì¼þ¸üÐÂQTS 5.2.2.2950 build 20241114Ö¼ÔÚÐÞ²¹¶à¸öÇå¾²Îó²î²¢ÐÞ¸´ÒÑÖªÎÊÌ⣬µ«´ó×Ú¿Í»§±¨¸æ³Æ¸Ã¸üÐÂÆÆËðÁË×°±¸ÅþÁ¬²¢µ¼ÖÂÎÞ·¨»á¼û¡£¾ÝÓû§·´Ï죬¸üкó·ºÆðÎÞ·¨ÅþÁ¬µ½×°±¸¡¢µÇ¼ƾ֤¹ýʧ¡¢¼ì²âµ½Î´¾­ÊÚȨµÄ¸ü¸ÄÒÔ¼°ÄÚÖÃÓ¦ÓóÌÐòÒòδװÖÃPython2¶øÎÞ·¨Ê¹ÓõÈÎÊÌâ¡£QNAPÖ§³ÖÍŶÓÒÑÈ·ÈϸøüÐÂÒÑ´ÓÏÂÔØÒ³Ãæɾ³ý£¬²¢½¨Ò齫¹Ì¼þ½µ¼¶ÖÁQTS 5.2.1.2930 build 2024102ÒÔ½â¾öÅþÁ¬ºÍÓ¦ÓóÌÐòË𻵵ÄÎÊÌâ¡£Ö»¹ÜQNAPÉÐδ¾Í´ËÊÂÐû²¼¹ûÕæÉùÃ÷£¬µ«ÆäÖ§³ÖÍŶÓÒѻظ´²¿·ÖÊÜÓ°Ïì¿Í»§¡£BleepingComputerÌá³öµÄ̸ÂÛÇëÇóÉÐδ»ñµÃQNAPµÄ»Ø¸´¡£


https://www.bleepingcomputer.com/news/technology/qnap-pulls-buggy-qts-firmware-causing-widespread-nas-issues/


4. Microsoft Power PagesÉèÖÃʧÎóÖÂNHSµÈÊý¾Ý´ó¹æģй¶


11ÔÂ23ÈÕ£¬¶¼°ØÁÖÍøÂçÇå¾²Ñо¿Ô±ÑÇÂס¤¿Æ˹ÌØÂå·¢Ã÷£¬ÓÉÓÚMicrosoft Power PagesÈí¼þƽ̨ÉèÖò»µ±£¬µ¼ÖÂ110Íò·ÝNHSÔ±¹¤¼Í¼±»Ð¹Â¶£¬°üÀ¨µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍ¼ÒͥסַµÈÃô¸ÐÐÅÏ¢¡£ÕâÒ»ÎÊÌâ²»µ«Ó°ÏìNHS£¬»¹²¨¼°È«Çò¶à¸ö×éÖ¯ºÍÕþ¸®ÊµÌå¡£¿Æ˹ÌØÂåÖ¸³ö£¬Ö»¹Ü΢ÈíÔÚPower PagesÖÎÀíÃæ°åÖÐÉèÖÃÁËÖÒÑÔºá·ùºÍ±ê¼Ç£¬µ«È±·¦¶ÔЧ¹ûµÄ³äÇå³þÈ·¡£ËûÒÔΪ£¬NHSÊý¾Ýй¶ÓëHSEÊý¾ÝÎÊÌâÏàËÆ£¬¶¼ÊǿɹûÕæ»á¼ûµÄÃÅ»§£¬ÓɳаüÉÌÉèÖúͰ²ÅÅ£¬ÇÒÇå¾²ÐÔ±»ºöÊÓ¡£¿Æ˹ÌØÂåºôÓõÏÂÒ»½ìÕþ¸®½«ÍøÂçÇå¾²×÷ΪÓÅÏÈÊÂÏ²¢Ñо¿Öƶ©¹ú¼Ò¿ò¼Ü£¬ÒÔÌá¸ß¹ú¼ÒÍøÂç·ÀÓùÄÜÁ¦¡£ËûÇ¿µ÷£¬Ô¤·À±ÈÏû³ýË𺦸üÖ÷Òª£¬²¢½¨Ò鿪չÌìÏÂÐÔÐû´«Ô˶¯£¬Ìá¸ß¹«ÖÚ¶ÔÍøÂçÇå¾²»ù´¡ÖªÊ¶µÄÏàʶ£¬Èç¶àÒòËØÉí·ÝÑéÖ¤ºÍ×èֹͨ¹ýµç»°ÌṩÒøÐÐÐÅÏ¢µÈ¡£¿Æ˹ÌØÂåÒÔΪ£¬°®¶ûÀ¼ÔÚÍøÂçÇå¾²·½ÃæµÄ×ʽðÑÏÖØȱ·¦£¬Ó¦¼Ó´óµÐÊÖÒÕÈ˲ŵÄͶ×Ê£¬ÒÔÌáÉý¹ú¼ÒÍøÂçÇ徲ˮƽ¡£


https://www.breakingnews.ie/ireland/irish-researcher-finds-1-1-million-nhs-employee-records-were-leaked-1698047.html


5. Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿ÀÎÓüÊý¾Ýй¶£¬Ë¾·¨²¿½ôÆÈÓ¦¶Ô


11ÔÂ23ÈÕ£¬Ó¢¹ú˾·¨²¿ÒÑÈ·Èϱ¬·¢ÁËÒ»ÆðÉæ¼°Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿ÀÎÓüµÄÊý¾Ýй¶ÊÂÎñ£¬¾Ý¡¶Ì©ÎîÊ¿±¨¡·±¨µÀ£¬ÒÑÍùÁ½ÖÜÄÚ£¬ÉñÃØÀÎÓü½á¹¹Í¼±»Ð¹Â¶ÖÁ°µÍø¡£ÕâЩ鶵ÄÀ¶Í¼°üÀ¨ÉãÏñÍ·ºÍ´«¸ÐÆ÷µÈÒªº¦Çå¾²¹¦Ð§µÄλÖ㬿ÉÄܻᱻÓÐ×éÖ¯·¸·¨¼¯ÍÅʹÓã¬ÒÔ½«¶¾Æ·»òÎäÆ÷×ß˽½øÀÎÓü£¬ÉõÖÁ²ß»®Ô½Óü¡£Ë¾·¨²¿ÒÑÁ¬Ã¦½ÓÄÉÐж¯È·±£ÀÎÓüÇå¾²£¬¶øÀÎÓüÕþ¸®ÏÓÒÉ´Ë´ÎйÃÜ¿ÉÄÜÓëÓÐ×éÖ¯·¸·¨¼¯ÍÅÊÔͼʹÓÃÎÞÈË»ú×ß˽¶¾Æ·ÓйØ¡£ÏÖÔÚÉв»ÇåÎúÄÄЩÀÎÓüÍýÏëÊܵ½ÁËÓ°Ï죬µ«ÄÚ¸ó°ì¹«ÊÒºÍÀÎÓüÖÎÀí¾ÖÕýÔÚÊÓ²ìÎ¥¹æÐÐΪµÄÔ´Í·£¬²¢ÆÀ¹ÀË­¿ÉÄÜ´ÓÕâЩÐÅÏ¢ÖÐÊÜÒæ¡£Ó¢¹ú¹ú¼Ò·¸·¨¾ÖÌåÏÖ£¬¸Ã¾ÖÕýÔÚÒÔÕÕÁÏÉí·ÝÌṩ֧³Ö¡£Ë¾·¨²¿½²»°ÈËÇ¿µ÷£¬ËûÃDz»»á¶Ô´ËÀàÇå¾²ÎÊÌâµÄÏêϸϸ½Ú½ÒÏþ̸ÂÛ£¬µ«ÒÑÁ¬Ã¦½ÓÄÉÐж¯Ó¦¶ÔDZÔÚй¶ÊÂÎñ£¬È·±£ÀÎÓüÇå¾²¡£


https://www.bbc.co.uk/news/articles/ce8y5jm4lyzo


6. ´ó¸£¿Ë˹¹«Á¢Ñ§Ð£ÔâÍøÂç´¹ÂÚÕ©Æ­£¬220ÍòÃÀÔª×ʽðÊÜÆ­×ß


11ÔÂ21ÈÕ£¬´ó¸£¿Ë˹¹«Á¢Ñ§Ð£½ñÄêÔçЩʱ¼äÔâÓöÁËÍøÂç´¹ÂÚÕ©Æ­£¬ÊÜÆ­È¡ÁË220ÍòÃÀÔª¡£ÕâÆðڲƭ°¸ÊÇÍøÂç´¹ÂÚ»òÉç»á¹¤³ÌȦÌ×µÄЧ¹û£¬¹¥»÷ÕßÓÕÆ­Ô±¹¤Ð¹Â¶Ãô¸ÐÐÅÏ¢»òÖ´ÐÐijЩ²Ù×÷£¬Èç»ã¿î»òÌṩÐÅÏ¢¡£Ñ§ÇøºÍ´ó¸£¿Ë˹¾¯Ô±¾ÖûÓÐÌṩÓйط¸·¨»òÊÓ²ìµÄÏêÇ飬µ«ÌØÇÚ¾ÖÕýÔÚЭÖúÊӲ졣ѧÇøIT×ܼàÌåÏÖ£¬Õâ´ÎÕ©Æ­ÊÇËûÂÄÀú¹ýµÄ×îÖØ´óµÄÍøÂç·¸·¨¡£±»µÁ×ʽðµÄÊý¶îÅú×¢ÇÔÔôÕÆÎÕÁËѧÇøµÄÄÚ²¿ÐÅÏ¢£¬Ê¹ÓÃÕâЩÐÅϢʹÉç»á¹¤³ÌÍýÏë¸ü¾ß˵·þÁ¦¡£Ö»¹ÜÖ´·¨ÒªÐÞÒµÇøÏò¹«ÖÚ·ÖÏíÆä´ó²¿·ÖÓªÒµ¼Í¼£¬µ«Ñ§Çø¹ÙÔ±ºÍÖ´·¨²¿·Ö¶¼Ã»ÓÐ͸¶Õâ200ÍòÃÀÔªÊÇÒ»´ÎÐÔתÕËÕվɷֶà´ÎתÕË¡£ÔÚڲƭÊÂÎñ±¬·¢Ç°µÄËÄÌìÀѧÇøÉÌÎñ°ì¹«ÊÒÖ§¸¶ÁË1000¶à±Ê¿î×Ó£¬ÆäÖаüÀ¨Ïò³Ð°üÉÌÖ§¸¶µÄÁ½±Ê´ó¶î¿î×Ó¡£Ñ§Çø¹ÙÔ±ÌåÏÖ£¬ÕâЩ¿î×Ó½«ÓÃÓÚÕýÔÚ¾ÙÐеÄÐÞ½¨ÏîÄ¿Ö®Ò»¡£


https://www.govtech.com/education/k-12/grand-forks-public-schools-loses-2-2m-to-phishing-scam