BlueSkyÓû§¼¤Ôö°éÉúÚ¿ÆÌôÕ½
°ä²¼¹¦·ò 2024-11-251. BlueSkyÓû§¼¤Ôö°éÉúÚ¿ÆÌôÕ½
11ÔÂ21ÈÕ£¬Ëæ×ÅBlueSkyÕâһȥÖÐÐÄ»¯Î¢²©·þÎñµÄÓû§ÊýÁ¿¼¤Ôö£¬ÍþвÐÐΪÕßÒ²·×·×Ó¿Èë¸Ãƽ̨¡£½üÆÚ£¬BleepingComputer·¢ÏÖBlueSkyÉϳöÏÖÁ˼ÓÃÜÇ®±ÒȦÌ×£¬Ô̺¬ÀûÓÃMetaÆ·ÅÆ½øÐÐÎóµ¼µÄÍÆ¹ãÌûºÍÐéα¿ÕͶ´ÙÏúµÈ¡£ÕâЩȦÌײ»½öÎ󵼹۶ཫ¸æ°×²úÆ·Óë¿Æ¼¼¾ÞÍ·Meta¼°Æä¸ÅÏëÁªÏµÆðÀ´£¬»¹Í¨¹ý¾«ÐÄÉè¼ÆµÄÍøÕ¾ºÍÓòÃûÀ´·ÂÕÕMetaµÄÆ·ÅÆºÍ×ÖÌ壬ÒÔÌá¸ßڲƳÉЧ¡£Í¬Ê±£¬BlueSky°²È«ÍŶÓҲ֤ʵ£¬Ëæ×ÅÓû§ÊýÁ¿µÄÔö³¤£¬Æ½Ì¨ÊÕµ½ÁË´óÁ¿¹ØÓÚÀ¬»øÓʼþ¡¢Ú¿ÆºÍ¶ñÒâ¹¥»÷»î¶¯µÄ»ã±¨¡£Ö»¹ÜBlueSkyµÄÈ¥ÖÐÐÄ»¯¼Ü¹¹ÎªÓû§ÌṩÁ˸ü´óµÄ×ÔÓɺͽÚÔìȨ£¬µ«Ò²´øÀ´ÁËеÄÌôÕ½¡£ÓÉÓÚÈκÎÈ˶¼Äܹ»Æô¶¯BlueSkyÊ·ý£¬Ú¿ÆÕßÄܹ»ÀûÓÃÕâÒ»ÌØµãÀ´ÉèÖÃ×Ô¼ºµÄÊ·ý²¢Íƹã¿ÉÒɵÄÂòÂô´òËã¡£´Ë±í£¬ËÑË÷ÒýÇæÒ²¿ÉÄÜץȡ²¢Ë÷ÒýÀ´×ÔµÚÈý·½BlueSkyÊ·ýµÄÌû×Ó£¬´Ó¶øÔ®Ê¶à¿ÆÕßÌá¸ßËÑË÷ÅÅÃûºÍSEO¶¾º¦ÓÎÏ·¡£Òò¶ø£¬BlueSky±ØÒª½â¾öÕâЩÌôÕ½£¬ÒÔ±£»¤Óû§ÃâÊÜڲƺͶñÒâ¹¥»÷µÄ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/now-bluesky-hit-with-crypto-scams-as-it-crosses-20-million-users/
2. °²µÂ³¡¤Ì©ÌØÔÚÏß´óѧÔâºÚ¿ÍÈëÇÖ£¬80ÍòÓû§Êý¾Ýй¶
11ÔÂ21ÈÕ£¬¼«ÓÒÒíÓ°ÏìÕß°²µÂ³¡¤Ì©ÌØ´´°ìµÄÔÚÏß´óѧ¡°ÕæÊµÊÀ½ç¡±£¨ÔÃû¡°Hustler's University¡±£©Ôâ·êºÚ¿ÍÈëÇÖ£¬µ¼ÖÂÔ¼325,000ÃûÓû§µÄµç×ÓÓʼþµØÖ·±»Ð¹Â¶£¬Í¬Ê±Ô¼794,000¸öÓû§Ãû¼°Æä221¸ö¹«¹²ºÍ395¸ö¸öÈË̸Ìì·þÎñÆ÷µÄÄÚÈÝÒ²±»ÆØ¹â¡£¸Ãƽ̨ÌṩÿÔÂÔ¼50ÃÀÔªµÄ¡°¸ß¼¶ÅàѵºÍÁìµ¼¡±£¬ÖØÒªÉæ¼°½¡È«¡¢½¡Éí¡¢½ðÈÚͶ×ʺ͵ç×ÓÉÌÎñµÈÖ÷Ìâ¡£ºÚ¿ÍÔÚÈëÇÖºóÓÚÌ©ÌØµÄÖ±²¥½ÚÄ¿ÖÐÉÏ´«ÁË´óÁ¿±íÇé·ûºÅÒÔʾ°áŪ£¬²¢Ðû³Æ¿ÉÄÜÀûÓ÷ì϶½øÐжàÏî·ÛËéÐÔ²Ù×÷¡£Õâ´ÎÈëÇֵ͝»ú±»ÒÔΪÊÇ¡°ºÚ¿ÍÐж¯Ö÷Ò塱£¬ÇÒ¸ÃÆ½Ì¨µÄ°²È«ÐÔ±»Ö¸Îª¡°¼«¶Ë²»°²È«¡±¡£Ì¸Ìì¼Í¼º¸ÇÁË´ÓÀøÖ¾Óï¼µ½¶Ô¡°LGBTQÒé³Ì¡±µÄ±§Ô¹µÈ¸÷ÀàÄÚÈÝ¡£Ì©ÌØÒòÕÅÑïÄÐ×ÓÆø¸ÅºÍ±áµÍÅ®ÐÔ¸ÅÏë¶øÎÅÃû£¬Ä¿Ç°Ãæ¶ÔÀ´×ÔÂÞÂíÄáÑǺÍÓ¢¹úµÄÎåÏî˾·¨µ÷²é¡£ºÚ¿ÍÒѽ«Ð¹Â¶µÄµç×ÓÓʼþµØÖ·Ìṩ¸øÓû§Í´´¦Ð¹Â¶¾¯±¨·þÎñHaveIBeenPwned£¬²¢½«Ì¸ÌìÊý¾Ý½»¸øÁËÐÂÎż¯ÌåDDoSecretsÍйܡ£
https://www.dailydot.com/debug/andrew-tate-the-real-world-hack/
3. QNAP¹Ì¼þ¸üÐÂÒý·¢ÏνÓÎÊÌ⣬Òѳ·»Ø²¢½¨Òé½µ¼¶
11ÔÂ22ÈÕ£¬QNAP½üÆÚ°ä²¼µÄ¹Ì¼þ¸üÐÂQTS 5.2.2.2950 build 20241114Ö¼ÔÚ½¨²¹¶à¸ö°²È«·ì϶²¢½¨¸´ÒÑÖªÎÊÌ⣬µ«´óÁ¿¿Í»§»ã±¨³Æ¸Ã¸üзÛËéÁËÉ豸ÏνӲ¢µ¼ÖÂÎÞ·¨½Ó¼û¡£¾ÝÓû§·´À¡£¬¸üкó³öÏÖÎÞ·¨Ïνӵ½É豸¡¢µÇ¼ʹ´¦ÃýÎó¡¢¼ì²âµ½Î´¾ÊÚȨµÄ¸ü¸ÄÒÔ¼°ÄÚÖÃÀûÓ÷¨Ê½ÒòδװÖÃPython2¶øÎÞ·¨Ê¹ÓõÈÎÊÌâ¡£QNAPÖ§³ÖÍŶÓÒÑÈ·ÈϸøüÐÂÒÑ´ÓÏÂÔØÒ³ÃæÉ¾³ý£¬²¢½¨Ò齫¹Ì¼þ½µ¼¶ÖÁQTS 5.2.1.2930 build 2024102ÒÔ½â¾öÏνӺÍÀûÓ÷¨Ê½°Ü»µµÄÎÊÌâ¡£Ö»¹ÜQNAPÉÐδ¾Í´Ëʰ䲼¹«¿ªÉêÃ÷£¬µ«ÆäÖ§³ÖÍŶÓÒѻظ´²¿ÃÅÊÜÓ°Ïì¿Í»§¡£BleepingComputerÌá³öµÄÆÀÂÛÒªÇóÉÐδµÃµ½QNAPµÄ»Ø¸´¡£
https://www.bleepingcomputer.com/news/technology/qnap-pulls-buggy-qts-firmware-causing-widespread-nas-issues/
4. Microsoft Power PagesÅäÖÃʧÎóÖÂNHSµÈÊý¾Ý´ó¹æÄ£Ð¹Â¶
11ÔÂ23ÈÕ£¬¶¼°ØÁÖÍøÂ簲ȫ×êÑÐÔ±ÑÇÂס¤¿ÆË¹ÌØÂå·¢ÏÖ£¬ÓÉÓÚMicrosoft Power PagesÈí¼þƽ̨ÅäÖò»µ±£¬µ¼ÖÂ110Íò·ÝNHSÔ±¹¤¼Í¼±»Ð¹Â¶£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍ¼ÒͥסַµÈÃô¸ÐÐÅÏ¢¡£ÕâÒ»ÎÊÌâ²»½öÓ°ÏìNHS£¬»¹²¨¼°È«Çò¶à¸ö×éÖ¯ºÍµÐÔÖʵÌå¡£¿ÆË¹ÌØÂåÖ¸³ö£¬Ö»¹Ü΢ÈíÔÚPower PagesÖÎÀíÃæ°åÖÐÉèÖÃÁËÖÒ¸æºá·ùºÍ±êÖ¾£¬µ«²»×ã¶Ôºó¹ûµÄ³ä·ÖÀí½â¡£ËûÒÔΪ£¬NHSÊý¾Ýй¶ÓëHSEÊý¾ÝÎÊÌâÀàËÆ£¬¶¼Êǿɹ«¿ª½Ó¼ûµÄÃÅ»§£¬ÓɳаüÉÌÅäÖúͲ¿Êð£¬ÇÒ°²È«ÐÔ±»ºöÊÓ¡£¿ÆË¹ÌØÂåºôÓõÏÂÒ»½ìµ±¾Ö½«ÍøÂ簲ȫ×÷ΪÓÅÏÈÊÂÏ²¢×êÑÐÔì¶©¹ú¶È¿ò¼Ü£¬ÒÔÌá¸ß¹ú¶ÈÍøÂç·ÀÓùÄÜÁ¦¡£ËûÇ¿µ÷£¬Ô¤·À±È½â³ýÇÖº¦¸ü³ÁÒª£¬²¢½¨Ò鷢չȫ¹úÐÔÐû´«»î¶¯£¬Ìá¸ß¹«¼Ò¶ÔÍøÂ簲ȫ»ù´¡ÖªÊ¶µÄÏàʶ£¬Èç¶à³É·ÖÉí·ÝÑéÖ¤ºÍÔ¤·Àͨ¹ýµç»°Ìá¹©ÒøÐÐÐÅÏ¢µÈ¡£¿ÆË¹ÌØÂåÒÔΪ£¬°®¶ûÀ¼ÔÚÍøÂ簲ȫ·½ÃæµÄ×ʽðÑϳÁ²»¼°£¬Ó¦¼Ó´ó¶Ô¼¼ÊõÈ˲ŵÄͶ×Ê£¬ÒÔÌáÉý¹ú¶ÈÍøÂ簲ȫˮƽ¡£
https://www.breakingnews.ie/ireland/irish-researcher-finds-1-1-million-nhs-employee-records-were-leaked-1698047.html
5. Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüÊý¾Ýй¶£¬Ë¾·¨²¿´¹Î£Ó¦¶Ô
11ÔÂ23ÈÕ£¬Ó¢¹ú˾·¨²¿ÒÑÈ·ÈϲúÉúÁËÒ»Â·Éæ¼°Ó¢¸ñÀ¼ºÍÍþ¶ûÊ¿¼àÓüµÄÊý¾Ýй¶ÊÂÎñ£¬¾Ý¡¶Ì©ÎîÊ¿±¨¡·±¨Â·£¬´ÓǰÁ½ÖÜÄÚ£¬»úÃܼàÓü²¼¾Öͼ±»Ð¹Â¶ÖÁ°µÍø¡£ÕâЩй¶µÄÀ¶Í¼Ô̺¬ÉãÏñÍ·ºÍ´«¸ÐÆ÷µÈ¹Ø¼ü°²È«Ö°ÄܵĵØÎ»£¬¿ÉÄܻᱻÓÐ×éÖ¯·¸×OÍÅÀûÓã¬ÒÔ½«¶¾Æ·»ò±øÆ÷×ß˽½ø¼àÓü£¬ÉõÖÁ²ß¶¯Ô½Óü¡£Ë¾·¨²¿Òѵ±¼´²ÉÈ¡Ðж¯È·±£¼àÓü°²È«£¬¶ø¼àÓüµ±¾ÖÒÉ»óÕâ´ÎйÃÜ¿ÉÄÜÓëÓÐ×éÖ¯·¸×OÍÅÊÔIJÀûÓÃÎÞÈË»ú×ß˽¶¾Æ·Óйء£Ä¿Ç°Éв»Ã÷ÏÔÄÄЩ¼àÓü´òËãÊܵ½ÁËÓ°Ï죬µ«ÄÚ¸ó°ì¹«ÊҺͼàÓüÖÎÀí¾ÖÔÚµ÷²éÎ¥¹æÐÐΪµÄÔ´Í·£¬²¢ÆÀ¹ÀË¿ÉÄÜ´ÓÕâЩÐÅÏ¢ÖÐÊÜÒæ¡£Ó¢¹ú¹ú¶È·¸×ï¾Ö°µÊ¾£¬¸Ã¾ÖÔÚÒÔÕÕ·÷Éí·ÝÌṩ֧³Ö¡£Ë¾·¨²¿½²»°ÈËÇ¿µ÷£¬ËûÃDz»»á¶Ô´ËÀలȫÎÊÌâµÄ¾ßÌåϸ½Ú°ä·¢ÆÀÂÛ£¬µ«Òѵ±¼´²ÉÈ¡Ðж¯Ó¦¶ÔDZÔÚй¶ÊÂÎñ£¬È·±£¼àÓü°²È«¡£
https://www.bbc.co.uk/news/articles/ce8y5jm4lyzo
6. ´ó¸£¿Ë˹¹«Á¢Ñ§ÌÃÔâÍøÂç´¹µöÚ¿Æ£¬220ÍòÃÀÔª×Ê½ð±»Æ×ß
11ÔÂ21ÈÕ£¬´ó¸£¿Ë˹¹«Á¢Ñ§ÌýñÄêÔçЩʱ³½Ôâ·êÁËÍøÂç´¹µöÚ¿Æ£¬±»ÆÈ¡ÁË220ÍòÃÀÔª¡£ÕâÆðڲư¸ÊÇÍøÂç´¹µö»òÉç»á¹¤³ÌȦÌ×µÄÁ˾֣¬¹¥»÷ÕߺýŪԱ¹¤Ð¹Â¼ûô¸ÐÐÅÏ¢»òÖ´ÐÐijЩ²Ù×÷£¬Èç»ã¿î»òÌṩÐÅÏ¢¡£Ñ§ÇøºÍ´ó¸£¿Ë˹¾¯Ô±¾ÖûÓÐÌṩÓйط¸×ï»òµ÷²éµÄÏêÇ飬µ«ÌØÇÚ¾ÖÔÚÐÖúµ÷²é¡£Ñ§ÇøIT×ܼవʾ£¬Õâ´ÎÚ¿ÆÊÇËû¾Àú¹ýµÄ×ÔÓµÄÍøÂç·¸×ï¡£±»µÁ×ʽðµÄÊý¶îÅú×¢ÇÔÔô°ÑÎÕÁËÑ§ÇøµÄÄÚ²¿ÐÅÏ¢£¬ÀûÓÃÕâЩÐÅϢʹÉç»á¹¤³Ì´òËã¸ü¾ß˵·þÁ¦¡£Ö»¹Ü˾·¨ÒªÒÞ񵂿Ïò¹«¼Ò·ÖÏíÆä´ó²¿ÃÅÒµÎñ¼Í¼£¬µ«Ñ§Çø¹ÙÔ±ºÍ·¨Âɲ¿ÃŶ¼Ã»ÓÐй©Õâ200ÍòÃÀÔªÊÇÒ»´ÎÐÔתÕË»¹ÊÇ·ÖÂÅ´ÎתÕË¡£ÔÚÚ²ÆÊÂÎñ²úÉúǰµÄËÄÌìÀï£¬Ñ§ÇøÉÌÎñ°ì¹«ÊÒÖ§¸¶ÁË1000¶à±Ê¿î×Ó£¬ÆäÖÐÔ̺¬Ïò³Ð°üÉÌÖ§¸¶µÄÁ½±Ê´ó¶î¿î×Ó¡£Ñ§Çø¹ÙÔ±°µÊ¾£¬ÕâЩ¿î×Ó½«ÓÃÓÚÔÚ½øÐеĹ¹ÖþÏîĿ֮һ¡£
https://www.govtech.com/education/k-12/grand-forks-public-schools-loses-2-2m-to-phishing-scam


¾©¹«Íø°²±¸11010802024551ºÅ