MUT-1244ÍþвÐÐΪÕß´ó¹æÄ£ÇÔÈ¡WordPressƾ֤¼°Ãô¸ÐÐÅÏ¢
°ä²¼¹¦·ò 2024-12-171. MUT-1244ÍþвÐÐΪÕß´ó¹æÄ£ÇÔÈ¡WordPressƾ֤¼°Ãô¸ÐÐÅÏ¢
12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬ÃûΪMUT-1244µÄÍþвÐÐΪÕßÔÚÒ»³¡³¤´ïÒ»ÄêµÄ´ó¹æÄ£»£»£»£»£»£»î¶¯ÖУ¬£¬£¬£¬£¬£¬Í¨¹ýľÂí²¡¶¾Ï°È¾µÄWordPressƾ֤²é³Æ÷ÇÔÈ¡Á˳¬¹ý390,000¸öWordPressƾ֤¡£¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬¸ÃÐÐΪÕß»¹´ÓÊý°ÙÃûÊܺ¦Õߣ¨Ô̺¬ºì¶Ó³ÉÔ±¡¢ÉøÈë²âÊÔÈËÔ±¡¢°²È«×êÑÐÈËÔ±ÒÔ¼°¶ñÒâÐÐΪÕߣ©µÄÊÜϰȾϵͳÖеÁÈ¡ÁËSSH˽ԿºÍAWS½Ó¼ûÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓñ»Ä¾Âí»¯µÄGitHub´æ´¢¿âÍÆËͶñÒâ¸ÅÏëÑéÖ¤·ì϶ºÍ½øÐÐÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬£¬ºýŪָ±ê×°ÖüÙ×°³ÉCPU΢Âë¸üеļÙÄÚºËÉý¼¶¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ´æ´¢¿âÔö³¤ÁËÆäºÏ·¨ÐÔ£¬£¬£¬£¬£¬£¬Ê¹µÃ°²È«×¨ÒµÈËÔ±ºÍÍþвÐÐΪÕ߸üÈÝÒ×ÔËÐÐËüÃÇ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýGitHub reposÒÔ¶àÖÖ·½Ê½Í¶·ÅÓÐÐ§ÔØºÉ£¬£¬£¬£¬£¬£¬Ô̺¬´øÓкóÃŵÄÅäÖñàÒëÎļþ¡¢¶ñÒâPDFÎļþ¡¢PythonͶ·ÅÆ÷ÒÔ¼°¶ñÒânpm°ü¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯ÓëÁíÒ»´Î³¤´ïÒ»ÄêµÄ¹©¸øÁ´¹¥»÷ÓгÁµþ£¬£¬£¬£¬£¬£¬ÆäÖÐÉæ¼°ÇÔÈ¡Êý¾ÝºÍÍÚ¾òÃÅÂÞ±Ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£¡£MUT-1244¿ÉÄܽӼû²¢Ð¹Â¶¸öÈËSSHÃÜÔ¿¡¢AWSƾ֤µÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÍøÂ簲ȫÉçÇøÄÚµÄÐÅÀµ£¬£¬£¬£¬£¬£¬ÔÚÖ¸±ê²»ÖªÇéµÄÇé¿öÏÂÖ´ÐжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÈëÇÖÁËÊýʮ̨»úе¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/390-000-wordpress-accounts-stolen-from-hackers-in-supply-chain-attack/
2. CISA½«Cleo·ì϶CVE-2024-50623Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖÐ
12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Ó°ÏìCleo²úÆ·µÄ·ì϶CVE-2024-50623£¨CVSSÆÀ·Ö8.8£©ÁÐÈëÆäÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ÖС£¡£¡£¡£¡£¡£¡£¡£Cleo¹«Ë¾·¢ÏÖÁËÒ»¸ö²»ÊÜÏ޶ȵÄÎļþÉÏ´«ºÍÏÂÔØ·ì϶£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬²¢½¨Òé¿Í»§Á¢¼´½«Harmony¡¢VLTraderºÍLexiComÊ·ýÉý¼¶µ½×îв¹¶¡°æ±¾5.8.0.21ÒÔ½â¾öDZÔÚ¹¥»÷ý½é¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Huntress»ã±¨³Æ£¬£¬£¬£¬£¬£¬¼´±ã×°ÖÃÁ˸ò¹¶¡£¬£¬£¬£¬£¬£¬ÔËÐÐ5.8.0.21µÄϵͳÈÔ¿ÉÄܱ»ÀûÓᣡ£¡£¡£¡£¡£¡£¡£Huntress·¢ÏÖÁËÕë¶ÔCleoÎļþ´«ÊäÈí¼þµÄ×Ô¶¯¹¥»÷£¬£¬£¬£¬£¬£¬²¢¹«¿ªÁËÉæ¼°ÈýÖÖCleo²úÆ·µÄ³ÖÐø¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Ê×ϯ°²È«×êÑÐÔ±Caleb Stewart¿ª·¢ÁËÀûÓÃËÁÒâÎļþдÈë·ì϶µÄPython¾ç±¾£¬£¬£¬£¬£¬£¬²¢Ö¤ÊµÁË·ì϶µÄÓÐЧÐÔ¡£¡£¡£¡£¡£¡£¡£¡£CISAÒªÇóÁª¹ú»ú¹¹ÔÚ2025Äê1ÔÂ3ÈÕ֮ǰ½¨¸´´Ë·ì϶£¬£¬£¬£¬£¬£¬×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²é¸ÃĿ¼²¢½â¾öÆä»ù´¡ÉèÊ©Öеķì϶£¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»¤ÍøÂçÃâÊܹ¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/171973/security/u-s-cisa-adds-cleo-harmony-vltrader-and-lexicom-flaw-to-its-known-exploited-vulnerabilities-catalog.html
3. ConnectOnCallÔ¶³ÌÒ½ÁÆÆ½Ì¨Ôâ³Á´óÊý¾Ýй¶
12ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬ConnectOnCallÊÇÒ»¸öרһÓÚ¼ÓǿҽÁÆ·þÎñÌṩÕßÓ뻼Õß¹µÍ¨µÄÔ¶³ÌÒ½ÁÆÆ½Ì¨£¬£¬£¬£¬£¬£¬½üÈÕÅû¶ÁËһ·³Á´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬Ó°Ï쳬¹ý900,000È˵ÄÓ×ÎÒÐÅÏ¢¼°Ò½ÁÆÐÅÏ¢°²È«¡£¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨Ìṩ×Ô¶¯»¼Õߺô½Ð¸ú×Ù¡¢HIPAAºÏ¹æÌ¸ÌìÖ°ÄÜ£¬£¬£¬£¬£¬£¬²¢Óëµç×Ó½¡È«¼Í¼ϵͳ¼¯³É¡£¡£¡£¡£¡£¡£¡£¡£5ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ConnectOnCall·¢ÏÖ°²È«·ì϶£¬£¬£¬£¬£¬£¬¾µ÷²éÈ·ÈÏ£¬£¬£¬£¬£¬£¬2024Äê2ÔÂ16ÈÕÖÁ5ÔÂ12ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬ÓÐδ֪µÚÈý·½½Ó¼ûÁËÆ½Ì¨¼°ÀûÓ÷¨Ê½ÄڵIJ¿ÃÅÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬Ò½»¼Í¨Ñ¶ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÊÂÎñÆØ¹âºó£¬£¬£¬£¬£¬£¬¹«Ë¾Ñ¸ËÙÀñÆ¸ÍøÂ簲ȫר¼Ò£¬£¬£¬£¬£¬£¬ÏÂÏß²úÆ·£¬£¬£¬£¬£¬£¬²¢ÔÚ°²È«»·¾³ÖнøÐÐÊý¾Ý¸´Ô£¬£¬£¬£¬£¬£¬Í¬Ê±Í¨ÖªÁËÁª¹ú·¨Âɲ¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£Ïպš¢Ò½ÁƼͼºÅ¼°½¡È«Çé¿öµÈ¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜĿǰδ·¢ÏÖÐÅÏ¢ÀÄÓûò»¼ÕßÊܺ¦Çé¿ö£¬£¬£¬£¬£¬£¬ConnectOnCallÈÔ½¨ÒéÊÜÓ°ÏìÓ×ÎÒά³Ö¾¯Ì裬£¬£¬£¬£¬£¬²¢»ã±¨¿ÉÒÉÉí·Ý͵ÇÔ»òÚ²ÆÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÒÑÏò·¨Âɲ¿ÃŻ㱨²¢Í¨ÖªÊÜÓ°ÏìÓ×ÎÒ£¬£¬£¬£¬£¬£¬ÎªÆäÖÐÓÐÏÞÊýÁ¿µÄÉç»á°²È«ºÅÂëÊÜÓ°ÏìÕßÌṩÉí·ÝºÍÐÅÓþ¼à¿Ø·þÎñ£¬£¬£¬£¬£¬£¬Í¨¹ýÓʼÄ֪ͨÐŵķ½Ê½·î¸æÓйØÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/172053/data-breach/connectoncall-data-breach-impacted-over-900000-individuals.html
4. µÂ¿ËÈøË¹Àí¹¤´óѧ½¡È«¿ÆÑ§ÖÐÐÄÔâÍøÂç¹¥»÷
12ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬µÂ¿ËÈøË¹Àí¹¤´óѧ½¡È«¿ÆÑ§ÖÐÐļ°Æä°£¶ûÅÁË÷·ÖУ½üÆÚÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÍÆËã»úϵͳºÍÀûÓ÷¨Ê½Öжϣ¬£¬£¬£¬£¬£¬²¢¿ÉÄÜй¶ÁË140ÍòÃû»¼ÕßµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÊÇÒ»¼Ò¹«¹²Ñ§ÊõÒ½ÁÆ»ú¹¹£¬£¬£¬£¬£¬£¬ÕƹܽÌÓý¡¢ÅàѵºÍ»¼Õß»¤Àí·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷µ¼ÖÂ2024Äê9ÔÂ17ÈÕÖÁ9ÔÂ29ÈÕÆÚ¼ä´Ó¸Ã»ú¹¹ÍøÂçÖнӼû»òɾ³ýÁËijЩÎļþºÍÎļþ¼Ð¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ÉÄÜй¶¸øºÚ¿ÍµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢µ±¾ÖÉí·ÝÖ¤ºÅÂë¡¢²ÆÕþÕË»§ÐÅÏ¢¡¢½¡È«±£ÏÕÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢Õ˵¥/Ë÷ÅâÊý¾Ý¡¢Õï¶ÏºÍÒ½ÖÎÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÒÑ֪ͨÊÜÓ°ÏìµÄÈË£¬£¬£¬£¬£¬£¬²¢ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄÓ×ÎÒά³Ö¾¯Ì裬£¬£¬£¬£¬£¬·À±¸Ç±ÔÚµÄÍøÂç´¹µöºÍÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬£¬£¬²¢¼à¿ØËûÃǵÄÐÅÓþ»ã±¨ºÍ½¡È«±£ÏÕÕ˵¥¡£¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÓÉÃûΪInterlockµÄÀÕË÷Èí¼þ×éÖ¯ÕÆ¹Ü£¬£¬£¬£¬£¬£¬¸Ã×é֯й¶ÁË210Íò¸öÎļþ£¬£¬£¬£¬£¬£¬×ܼÆ2.6TBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬¾Ý³ÆÊǴӸûú¹¹ÇÔÈ¡µÄ¡£¡£¡£¡£¡£¡£¡£¡£InterlockË÷ÒªµÄÊê½ð½ð¶î´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/texas-tech-university-system-data-breach-impacts-14-million-patients/
5. ´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯´«²¼Lumma StealerÐÅÏ¢ÇÔÈ¡Èí¼þ
12ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬Ò»ÏîÃûΪ¡°DeceptionAds¡±µÄ´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯ÔÚÀûÓÃMonetag¸æ°×ÍøÂç´«²¼Lumma StealerÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Í¨¹ýÐéαµÄCAPTCHAÑéÖ¤Ò³ÃæÓÕÆÓû§ÔËÐжñÒâPowerShellºÅÁ£¬£¬£¬£¬£¬´Ó¶øÏ°È¾¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£Guardio LabsºÍInfobloxµÄ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬ÕâÒ»²Ù×÷ÓÉÃûΪ¡°Vane Viper¡±µÄÍþвÐÐΪÕßÖ´ÐУ¬£¬£¬£¬£¬£¬ÀûÓúϷ¨¸æ°×ÍøÂçÉϵĴó¹æÄ£¸æ°×½«Óû§´øµ½ÐéαµÄCAPTCHAÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£¡£CAPTCHAÒ³ÃæÔ̺¬JavaScript´úÂ룬£¬£¬£¬£¬£¬½«¶ñÒâPowerShellºÅÁÔìµ½Óû§¼ôÌù°å£¬£¬£¬£¬£¬£¬²¢ÓÕµ¼Óû§Ö´ÐС£¡£¡£¡£¡£¡£¡£¡£Lumma Stealer¿É´Óä¯ÀÀÆ÷ÖÐÇÔÈ¡cookie¡¢Í´´¦¡¢ÃÜÂë¡¢ÐÅÓþ¿¨ºÍä¯ÀÀº¹Çà¼Í¼£¬£¬£¬£¬£¬£¬ÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°ü¡¢Ë½Ô¿ºÍÃô¸ÐÎı¾Îļþ¡£¡£¡£¡£¡£¡£¡£¡£GuardioLabsÒÑÏòMonetagºÍBeMob»ã±¨´ËÀÄÓÃÐÐΪ£¬£¬£¬£¬£¬£¬²¢µÃµ½ÊµÊ±ÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÔÚ12Ô³öÏÖ¸´ËÕ£¬£¬£¬£¬£¬£¬Åú×¢ÍþвÐÐΪÕßÊÔͼͨ¹ý·ÖÆç¸æ°×ÍøÂ縴ÔÔËÓª¡£¡£¡£¡£¡£¡£¡£¡£Óû§Ó¦Ô¤·ÀÖ´ÐÐÍøÕ¾ÌáÐѵĺÅÁ£¬£¬£¬£¬£¬³ö¸ñÊÇÄÇЩ¼Ù×°½¨¸´»òÑéÖ¤ÂëµÄºÅÁ£¬£¬£¬£¬£¬²¢ÉóÉ÷ʹÓõÁ°æÈí¼þ»ò·¸·¨Á÷ýÌåÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/malicious-ads-push-lumma-infostealer-via-fake-captcha-pages/
6. Â޵µºÖÝRIBridgesϵͳÔâBrain CipherÀÕË÷Èí¼þ¹¥»÷
12ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬Â޵µºÖÝÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬ÆäÓɵÂÇÚÖÎÀíµÄRIBridgesϵͳÔâ·êÁËBrain CipherÀÕË÷Èí¼þÍÅ»ïµÄÈëÇÖ£¬£¬£¬£¬£¬£¬µ¼ÖÂÊý¾Ýй¶£¬£¬£¬£¬£¬£¬Â¶³öÁ˾ÓÃñµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£RIBridgesÊǸÃÖÝÓÃÓÚÖÎÀíºÍÌṩ¹«¹²ÔöÔ®´òËãµÄÏÖ´ú×ۺϻï¸ñϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÓÚ2024Äê12ÔÂ5ÈÕ±»·¢ÏÖ£¬£¬£¬£¬£¬£¬µÂÇÚÆÀ¹ÀºóÒÔΪºÚ¿Í¿ÉÄÜÇÔÈ¡ÁËÔ̺¬Ó×ÎÒÉí·ÝÐÅÏ¢ºÍÆäËûÊý¾ÝµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÏîÄ¿Ô̺¬Ò½ÁƲ¹Öú¡¢²¹³äÓªÑøÔöÔ®´òËã¡¢ÇîÀ§¼ÒͥһʱÔöÔ®µÈ¶à¸ö¹«¹²·þÎñÏîÄ¿¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Üй¶µÄÊý¾ÝÈÔÔÚÆÀ¹ÀÖУ¬£¬£¬£¬£¬£¬µ«¿ÉÄÜÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂëºÍÄ³Ð©ÒøÐÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¼ÒÍ¥½«Í¨¹ýÓʼþÊÕµ½Í¨Öª£¬£¬£¬£¬£¬£¬²¢¿ÉÖµçרÓúô½ÐÖÐÐÄ×·ÇóÖ§³Ö¡£¡£¡£¡£¡£¡£¡£¡£Â޵µºÖݵ±¾Ö½¨Òé¾ÓÃñ³ÁÖÃÃÜÂë¡¢ÉèÖÃڲƾ¯±¨ºÍÐÅÓþ¶³½á£¬£¬£¬£¬£¬£¬²¢Æô¶¯ÒøÐÐÌṩµÄ°²È«´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£µÂÇÚ½²»°ÈËÈ·ÈÏ£¬£¬£¬£¬£¬£¬Â޵µºÖݵÄϵͳÊÇÊܵ½Brain CipherÊý¾Ýй¶ӰÏìµÄ¡°µ¥Ò»¿Í»§¶Ëϵͳ¡±£¬£¬£¬£¬£¬£¬²¢°µÊ¾½«Óë¿Í»§ºÍ·¨ÂɹÙÔ±ºÏ×÷·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/rhode-island-confirms-data-breach-after-brain-cipher-ransomware-attack/


¾©¹«Íø°²±¸11010802024551ºÅ